Improve ASAN poisoning logic in mj_freeStack.

When freeing a stack frame, only poison the newly-freed memory region
`[old_top, new_top)` instead of the entire region `[limit, top)`. The old
code redundantly re-poisoned already-poisoned memory on every
`mj_freeStack` call.

Benchmarking `engine_forward_test` under ASAN:
- Before: 99.3s
- After:  75.6s  (~24% faster)

PiperOrigin-RevId: 885035750
Change-Id: Ib195661ca337d13c5ff6094bcc107c4c0a617b9b
This commit is contained in:
Yuval Tassa
2026-03-17 08:25:41 -07:00
committed by Copybara-Service
parent c420a6e1ca
commit 9d3ee5a948
+2 -1
View File
@@ -298,6 +298,7 @@ static inline void freestackinternal(mjStackInfo* stack_info) {
mj__getPcDebugInfo(s->pc),
mj__getPcDebugInfo(__sanitizer_return_address()));
}
uintptr_t old_top = stack_info->top;
#endif
// restore pbase and pstack
@@ -306,7 +307,7 @@ static inline void freestackinternal(mjStackInfo* stack_info) {
// if running under asan, poison the newly freed memory region
#ifdef ADDRESS_SANITIZER
ASAN_POISON_MEMORY_REGION((char*)stack_info->limit, stack_info->top - stack_info->limit);
ASAN_POISON_MEMORY_REGION((char*)old_top, stack_info->top - old_top);
#endif
}