Closed Bug 1028345 Opened 6 years ago Closed 1 year ago
Allocate DOM nodes in a separate heap partition
Apparently both IE and Chrome allocate DOM nodes into some kind of separate heap partition. This is a weaker mitigation measure than frame poisoning, because things with different vtables can still get allocated to the same location, but I suppose it reduces problems where a typed array buffer gets allocated in the former location of a DOM node. The main drawback would presumably be increased heap fragmentation.
We sort of tried this before FF 3, because of perf reasons. And it was good for perf, but bad for memory consumption. See bug 403830.
2 years ago
Depends on: 1364359
Summary: Considering allocating DOM nodes in a separate heap partition → Allocate DOM nodes in a separate heap partition
Component: DOM → DOM: Core & HTML
Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → DUPLICATE
Duplicate of bug: 1377999
You need to log in before you can comment on or make changes to this bug.