Changeset 197641 in webkit
- Timestamp:
- Mar 6, 2016, 12:11:09 PM (11 years ago)
- Location:
- trunk
- Files:
-
- 5 added
- 33 edited
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/js/regress/regexp-exec-expected.txt (added)
-
LayoutTests/js/regress/regexp-exec.html (added)
-
LayoutTests/js/regress/script-tests/regexp-exec.js (added)
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h (modified) (2 diffs)
-
Source/JavaScriptCore/dfg/DFGByteCodeParser.cpp (modified) (5 diffs)
-
Source/JavaScriptCore/dfg/DFGClobberize.h (modified) (2 diffs)
-
Source/JavaScriptCore/dfg/DFGDoesGC.cpp (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGFixupPhase.cpp (modified) (2 diffs)
-
Source/JavaScriptCore/dfg/DFGNodeType.h (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGOperations.cpp (modified) (5 diffs)
-
Source/JavaScriptCore/dfg/DFGOperations.h (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGPredictionPropagationPhase.cpp (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGSafeToExecute.h (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGSpeculativeJIT.h (modified) (6 diffs)
-
Source/JavaScriptCore/dfg/DFGSpeculativeJIT32_64.cpp (modified) (11 diffs)
-
Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp (modified) (9 diffs)
-
Source/JavaScriptCore/dfg/DFGStructureRegistrationPhase.cpp (modified) (1 diff)
-
Source/JavaScriptCore/ftl/FTLCapabilities.cpp (modified) (1 diff)
-
Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp (modified) (3 diffs)
-
Source/JavaScriptCore/jit/JITOperations.h (modified) (2 diffs)
-
Source/JavaScriptCore/runtime/JSGlobalObject.cpp (modified) (4 diffs)
-
Source/JavaScriptCore/runtime/JSGlobalObject.h (modified) (2 diffs)
-
Source/JavaScriptCore/runtime/JSObject.h (modified) (1 diff)
-
Source/JavaScriptCore/runtime/JSString.h (modified) (5 diffs)
-
Source/JavaScriptCore/runtime/RegExpCachedResult.cpp (modified) (2 diffs)
-
Source/JavaScriptCore/runtime/RegExpMatchesArray.cpp (modified) (3 diffs)
-
Source/JavaScriptCore/runtime/RegExpMatchesArray.h (modified) (2 diffs)
-
Source/JavaScriptCore/runtime/RegExpObject.cpp (modified) (2 diffs)
-
Source/JavaScriptCore/runtime/RegExpObject.h (modified) (2 diffs)
-
Source/JavaScriptCore/runtime/RegExpPrototype.cpp (modified) (3 diffs)
-
Source/JavaScriptCore/runtime/StringPrototype.cpp (modified) (2 diffs)
-
Source/JavaScriptCore/runtime/Structure.cpp (modified) (2 diffs)
-
Source/JavaScriptCore/runtime/Structure.h (modified) (2 diffs)
-
Source/JavaScriptCore/tests/stress/regexp-matches-array-bad-time.js (added)
-
Source/JavaScriptCore/tests/stress/regexp-matches-array-slow-put.js (added)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r197639 r197641 1 2016-03-06 Filip Pizlo <fpizlo@apple.com> 2 3 RegExpMatchesArray doesn't know how to have a bad time 4 https://bugs.webkit.org/show_bug.cgi?id=155069 5 6 Reviewed by Yusuke Suzuki. 7 8 * js/regress/regexp-exec-expected.txt: Added. 9 * js/regress/regexp-exec.html: Added. 10 * js/regress/script-tests/regexp-exec.js: Added. 11 1 12 2016-03-06 Zalan Bujtas <zalan@apple.com> 2 13 -
trunk/Source/JavaScriptCore/ChangeLog
r197640 r197641 1 2016-03-06 Filip Pizlo <fpizlo@apple.com> 2 3 RegExpMatchesArray doesn't know how to have a bad time 4 https://bugs.webkit.org/show_bug.cgi?id=155069 5 6 Reviewed by Yusuke Suzuki. 7 8 In trunk if we are having a bad time, the regexp matches array is still allocated with a 9 non-slow-put indexing shape, which makes it have the wrong behavior on indexed setters on 10 the prototype chain. 11 12 Getting this to work right requires introducing bad time code paths into the regexp matches 13 array. It also requires something more drastic: making this code not play games with the 14 global object. The code that creates the matches array needs to have the actual global 15 object of the regexp native function that it's logically created by. 16 17 This is totally different from how we've handled global objects in the past because it means 18 that the global object is not a constant. Normally we can make it a constant because a 19 script executable will know its global object. But with native functions, it's the function 20 instance that knows the global object - not the native executable. When we inline a native 21 intrinsic, we are guaranteed to know the native executable but we're not guaranteed to know 22 the functon instance. This means that the global object may be a variable that gets computed 23 by looking at the instance at run-time. So, the RegExpExec/RegExpTest nodes in DFG IR now 24 take a global object child. That also meant adding a new node type, GetGlobalObject, which 25 does the thing to the callee that CallFrame::lexicalGlobalObject() would have done. 26 Eventually, we'll probably have to make other native intrinsics also use GetGlobalObject. It 27 turns out that this really isn't so bad because usually it's constant-folded anyway, since 28 although the intrinsic code supports executable-based inlining (which leaves the callee 29 instance as an unknown), it happens rarely for intrinsics. So, conveying the global object 30 via a child isn't any worse than conveying it via meta-data, and it's probably better than 31 telling the inliner not to do executable-based inlining of native intrinsics. That would 32 have been a confusing special-case. 33 34 This is perf-neutral on my machines but it fixes a bug and it unlocks some interesting 35 possibilities. For example, RegExpExec can now make a firm promise about the type of array 36 it's creating. 37 38 This also contains some other changes: 39 40 - We are now using Structure::addPropertyTransition() in a lot of places even though it was 41 meant to be an internal method with a quirky contract - for example if only works if you 42 know that there is not existing transition. This relaxes this constraint. 43 44 - Restores the use of "*" for heap references in JSString.h. It's very unusual to have heap 45 references pointed at with "&", since we don't currently do that anywhere. The fact that 46 it was using the wrong reference type also meant that the code couldn't elegantly make use 47 of some our GC pointer helpers like jsCast<>. 48 49 * dfg/DFGAbstractInterpreterInlines.h: 50 (JSC::DFG::AbstractInterpreter<AbstractStateType>::executeEffects): 51 * dfg/DFGByteCodeParser.cpp: 52 (JSC::DFG::ByteCodeParser::attemptToInlineCall): 53 (JSC::DFG::ByteCodeParser::handleMinMax): 54 (JSC::DFG::ByteCodeParser::handleIntrinsicCall): 55 * dfg/DFGClobberize.h: 56 (JSC::DFG::clobberize): 57 * dfg/DFGDoesGC.cpp: 58 (JSC::DFG::doesGC): 59 * dfg/DFGFixupPhase.cpp: 60 (JSC::DFG::FixupPhase::fixupNode): 61 * dfg/DFGNodeType.h: 62 * dfg/DFGOperations.cpp: 63 * dfg/DFGOperations.h: 64 * dfg/DFGPredictionPropagationPhase.cpp: 65 (JSC::DFG::PredictionPropagationPhase::propagate): 66 * dfg/DFGSafeToExecute.h: 67 (JSC::DFG::safeToExecute): 68 * dfg/DFGSpeculativeJIT.cpp: 69 (JSC::DFG::SpeculativeJIT::compileSkipScope): 70 (JSC::DFG::SpeculativeJIT::compileGetGlobalObject): 71 (JSC::DFG::SpeculativeJIT::compileGetArrayLength): 72 * dfg/DFGSpeculativeJIT.h: 73 (JSC::DFG::SpeculativeJIT::callOperation): 74 * dfg/DFGSpeculativeJIT32_64.cpp: 75 (JSC::DFG::SpeculativeJIT::compile): 76 * dfg/DFGSpeculativeJIT64.cpp: 77 (JSC::DFG::SpeculativeJIT::compile): 78 * ftl/FTLCapabilities.cpp: 79 (JSC::FTL::canCompile): 80 * ftl/FTLLowerDFGToB3.cpp: 81 (JSC::FTL::DFG::LowerDFGToB3::compileNode): 82 (JSC::FTL::DFG::LowerDFGToB3::compileSkipScope): 83 (JSC::FTL::DFG::LowerDFGToB3::compileGetGlobalObject): 84 (JSC::FTL::DFG::LowerDFGToB3::compileGetClosureVar): 85 (JSC::FTL::DFG::LowerDFGToB3::compileRegExpExec): 86 (JSC::FTL::DFG::LowerDFGToB3::compileRegExpTest): 87 (JSC::FTL::DFG::LowerDFGToB3::compileNewRegexp): 88 * jit/JITOperations.h: 89 * runtime/JSGlobalObject.cpp: 90 (JSC::JSGlobalObject::init): 91 (JSC::JSGlobalObject::haveABadTime): 92 (JSC::JSGlobalObject::visitChildren): 93 * runtime/JSGlobalObject.h: 94 * runtime/JSObject.h: 95 (JSC::JSObject::putDirectInternal): 96 * runtime/JSString.h: 97 (JSC::jsString): 98 (JSC::jsSubstring): 99 * runtime/RegExpCachedResult.cpp: 100 (JSC::RegExpCachedResult::lastResult): 101 * runtime/RegExpMatchesArray.cpp: 102 (JSC::tryCreateUninitializedRegExpMatchesArray): 103 (JSC::createRegExpMatchesArray): 104 (JSC::createStructureImpl): 105 (JSC::createRegExpMatchesArrayStructure): 106 (JSC::createRegExpMatchesArraySlowPutStructure): 107 * runtime/RegExpMatchesArray.h: 108 * runtime/RegExpObject.cpp: 109 (JSC::RegExpObject::put): 110 (JSC::RegExpObject::exec): 111 (JSC::RegExpObject::match): 112 * runtime/RegExpObject.h: 113 (JSC::RegExpObject::getLastIndex): 114 (JSC::RegExpObject::test): 115 * runtime/RegExpPrototype.cpp: 116 (JSC::regExpProtoFuncTest): 117 (JSC::regExpProtoFuncExec): 118 (JSC::regExpProtoFuncCompile): 119 * runtime/StringPrototype.cpp: 120 (JSC::stringProtoFuncMatch): 121 * runtime/Structure.cpp: 122 (JSC::Structure::suggestedArrayStorageTransition): 123 (JSC::Structure::addPropertyTransition): 124 (JSC::Structure::addNewPropertyTransition): 125 * runtime/Structure.h: 126 * tests/stress/regexp-matches-array-bad-time.js: Added. 127 * tests/stress/regexp-matches-array-slow-put.js: Added. 128 1 129 2016-03-06 Yusuke Suzuki <utatane.tea@gmail.com> 2 130 -
trunk/Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h
r197622 r197641 1555 1555 1556 1556 case RegExpExec: 1557 if (node->child 1().useKind() == RegExpObjectUse1558 && node->child 2().useKind() == StringUse) {1557 if (node->child2().useKind() == RegExpObjectUse 1558 && node->child3().useKind() == StringUse) { 1559 1559 // This doesn't clobber the world since there are no conversions to perform. 1560 1560 } else 1561 1561 clobberWorld(node->origin.semantic, clobberLimit); 1562 forNode(node).makeHeapTop(); 1562 if (JSValue globalObjectValue = forNode(node->child1()).m_value) { 1563 if (JSGlobalObject* globalObject = jsDynamicCast<JSGlobalObject*>(globalObjectValue)) { 1564 if (!globalObject->isHavingABadTime()) { 1565 m_graph.watchpoints().addLazily(globalObject->havingABadTimeWatchpoint()); 1566 Structure* structure = globalObject->regExpMatchesArrayStructure(); 1567 m_graph.registerStructure(structure); 1568 forNode(node).set(m_graph, structure); 1569 forNode(node).merge(SpecOther); 1570 break; 1571 } 1572 } 1573 } 1574 forNode(node).setType(m_graph, SpecOther | SpecArray); 1563 1575 break; 1564 1576 1565 1577 case RegExpTest: 1566 if (node->child 1().useKind() == RegExpObjectUse1567 && node->child 2().useKind() == StringUse) {1578 if (node->child2().useKind() == RegExpObjectUse 1579 && node->child3().useKind() == StringUse) { 1568 1580 // This doesn't clobber the world since there are no conversions to perform. 1569 1581 } else … … 1879 1891 break; 1880 1892 } 1893 forNode(node).setType(m_graph, SpecObjectOther); 1894 break; 1895 } 1896 1897 case GetGlobalObject: { 1898 JSValue child = forNode(node->child1()).value(); 1899 if (child) { 1900 setConstant(node, *m_graph.freeze(JSValue(asObject(child)->globalObject()))); 1901 break; 1902 } 1903 1904 if (forNode(node->child1()).m_structure.isFinite()) { 1905 JSGlobalObject* globalObject = nullptr; 1906 bool ok = true; 1907 forNode(node->child1()).m_structure.forEach( 1908 [&] (Structure* structure) { 1909 if (!globalObject) 1910 globalObject = structure->globalObject(); 1911 else if (globalObject != structure->globalObject()) 1912 ok = false; 1913 }); 1914 if (globalObject && ok) { 1915 setConstant(node, *m_graph.freeze(JSValue(globalObject))); 1916 break; 1917 } 1918 } 1919 1881 1920 forNode(node).setType(m_graph, SpecObjectOther); 1882 1921 break; -
trunk/Source/JavaScriptCore/dfg/DFGByteCodeParser.cpp
r197520 r197641 203 203 // Handle intrinsic functions. Return true if it succeeded, false if we need to plant a call. 204 204 template<typename ChecksFunctor> 205 bool handleIntrinsicCall( int resultOperand, Intrinsic, int registerOffset, int argumentCountIncludingThis, SpeculatedType prediction, const ChecksFunctor& insertChecks);205 bool handleIntrinsicCall(Node* callee, int resultOperand, Intrinsic, int registerOffset, int argumentCountIncludingThis, SpeculatedType prediction, const ChecksFunctor& insertChecks); 206 206 template<typename ChecksFunctor> 207 207 bool handleIntrinsicGetter(int resultOperand, const GetByIdVariant& intrinsicVariant, Node* thisNode, const ChecksFunctor& insertChecks); … … 1602 1602 Intrinsic intrinsic = callee.intrinsicFor(specializationKind); 1603 1603 if (intrinsic != NoIntrinsic) { 1604 if (handleIntrinsicCall( resultOperand, intrinsic, registerOffset, argumentCountIncludingThis, prediction, insertChecksWithAccounting)) {1604 if (handleIntrinsicCall(callTargetNode, resultOperand, intrinsic, registerOffset, argumentCountIncludingThis, prediction, insertChecksWithAccounting)) { 1605 1605 RELEASE_ASSERT(didInsertChecks); 1606 1606 addToGraph(Phantom, callTargetNode); … … 1992 1992 1993 1993 template<typename ChecksFunctor> 1994 bool ByteCodeParser::handleIntrinsicCall( int resultOperand, Intrinsic intrinsic, int registerOffset, int argumentCountIncludingThis, SpeculatedType prediction, const ChecksFunctor& insertChecks)1994 bool ByteCodeParser::handleIntrinsicCall(Node* callee, int resultOperand, Intrinsic intrinsic, int registerOffset, int argumentCountIncludingThis, SpeculatedType prediction, const ChecksFunctor& insertChecks) 1995 1995 { 1996 1996 switch (intrinsic) { … … 2173 2173 2174 2174 insertChecks(); 2175 Node* regExpExec = addToGraph(RegExpExec, OpInfo(0), OpInfo(prediction), get(virtualRegisterForArgument(0, registerOffset)), get(virtualRegisterForArgument(1, registerOffset)));2175 Node* regExpExec = addToGraph(RegExpExec, OpInfo(0), OpInfo(prediction), addToGraph(GetGlobalObject, callee), get(virtualRegisterForArgument(0, registerOffset)), get(virtualRegisterForArgument(1, registerOffset))); 2176 2176 set(VirtualRegister(resultOperand), regExpExec); 2177 2177 … … 2184 2184 2185 2185 insertChecks(); 2186 Node* regExpExec = addToGraph(RegExpTest, OpInfo(0), OpInfo(prediction), get(virtualRegisterForArgument(0, registerOffset)), get(virtualRegisterForArgument(1, registerOffset)));2186 Node* regExpExec = addToGraph(RegExpTest, OpInfo(0), OpInfo(prediction), addToGraph(GetGlobalObject, callee), get(virtualRegisterForArgument(0, registerOffset)), get(virtualRegisterForArgument(1, registerOffset))); 2187 2187 set(VirtualRegister(resultOperand), regExpExec); 2188 2188 -
trunk/Source/JavaScriptCore/dfg/DFGClobberize.h
r197622 r197641 135 135 case GetScope: 136 136 case SkipScope: 137 case GetGlobalObject: 137 138 case StringCharCodeAt: 138 139 case CompareStrictEq: … … 1079 1080 case RegExpExec: 1080 1081 case RegExpTest: 1081 if (node->child 1().useKind() == RegExpObjectUse1082 && node->child 2().useKind() == StringUse) {1082 if (node->child2().useKind() == RegExpObjectUse 1083 && node->child3().useKind() == StringUse) { 1083 1084 read(RegExpState); 1084 1085 write(RegExpState); -
trunk/Source/JavaScriptCore/dfg/DFGDoesGC.cpp
r197549 r197641 112 112 case GetScope: 113 113 case SkipScope: 114 case GetGlobalObject: 114 115 case GetClosureVar: 115 116 case PutClosureVar: -
trunk/Source/JavaScriptCore/dfg/DFGFixupPhase.cpp
r197622 r197641 880 880 case RegExpExec: 881 881 case RegExpTest: { 882 if (node->child1()->shouldSpeculateRegExpObject()) { 883 fixEdge<RegExpObjectUse>(node->child1()); 884 885 if (node->child2()->shouldSpeculateString()) 886 fixEdge<StringUse>(node->child2()); 882 fixEdge<KnownCellUse>(node->child1()); 883 884 if (node->child2()->shouldSpeculateRegExpObject()) { 885 fixEdge<RegExpObjectUse>(node->child2()); 886 887 if (node->child3()->shouldSpeculateString()) 888 fixEdge<StringUse>(node->child3()); 887 889 } 888 890 break; … … 1050 1052 case GetScope: 1051 1053 case GetGetter: 1052 case GetSetter: { 1054 case GetSetter: 1055 case GetGlobalObject: { 1053 1056 fixEdge<KnownCellUse>(node->child1()); 1054 1057 break; -
trunk/Source/JavaScriptCore/dfg/DFGNodeType.h
r197549 r197641 213 213 macro(GetScope, NodeResultJS) \ 214 214 macro(SkipScope, NodeResultJS) \ 215 macro(GetGlobalObject, NodeResultJS) \ 215 216 macro(GetClosureVar, NodeResultJS) \ 216 217 macro(PutClosureVar, NodeMustGenerate) \ -
trunk/Source/JavaScriptCore/dfg/DFGOperations.cpp
r197622 r197641 620 620 } 621 621 622 EncodedJSValue JIT_OPERATION operationRegExpExecString(ExecState* exec, RegExpObject* regExpObject, JSString* argument)623 { 624 VM& vm = exec->vm();625 NativeCallFrameTracer tracer(&vm, exec); 626 627 return JSValue::encode(regExpObject->exec(exec, argument));622 EncodedJSValue JIT_OPERATION operationRegExpExecString(ExecState* exec, JSGlobalObject* globalObject, RegExpObject* regExpObject, JSString* argument) 623 { 624 VM& vm = globalObject->vm(); 625 NativeCallFrameTracer tracer(&vm, exec); 626 627 return JSValue::encode(regExpObject->exec(exec, globalObject, argument)); 628 628 } 629 629 630 EncodedJSValue JIT_OPERATION operationRegExpExec(ExecState* exec, RegExpObject* regExpObject, EncodedJSValue encodedArgument)631 { 632 VM& vm = exec->vm();630 EncodedJSValue JIT_OPERATION operationRegExpExec(ExecState* exec, JSGlobalObject* globalObject, RegExpObject* regExpObject, EncodedJSValue encodedArgument) 631 { 632 VM& vm = globalObject->vm(); 633 633 NativeCallFrameTracer tracer(&vm, exec); 634 634 … … 638 638 if (!input) 639 639 return JSValue::encode(jsUndefined()); 640 return JSValue::encode(regExpObject->exec(exec, input));640 return JSValue::encode(regExpObject->exec(exec, globalObject, input)); 641 641 } 642 642 643 EncodedJSValue JIT_OPERATION operationRegExpExecGeneric(ExecState* exec, EncodedJSValue encodedBase, EncodedJSValue encodedArgument)644 { 645 VM& vm = exec->vm();643 EncodedJSValue JIT_OPERATION operationRegExpExecGeneric(ExecState* exec, JSGlobalObject* globalObject, EncodedJSValue encodedBase, EncodedJSValue encodedArgument) 644 { 645 VM& vm = globalObject->vm(); 646 646 NativeCallFrameTracer tracer(&vm, exec); 647 647 … … 655 655 if (!input) 656 656 return JSValue::encode(jsUndefined()); 657 return JSValue::encode(asRegExpObject(base)->exec(exec, input));657 return JSValue::encode(asRegExpObject(base)->exec(exec, globalObject, input)); 658 658 } 659 659 660 size_t JIT_OPERATION operationRegExpTestString(ExecState* exec, RegExpObject* regExpObject, JSString* input)661 { 662 VM& vm = exec->vm();663 NativeCallFrameTracer tracer(&vm, exec); 664 665 return regExpObject->test(exec, input);666 } 667 668 size_t JIT_OPERATION operationRegExpTest(ExecState* exec, RegExpObject* regExpObject, EncodedJSValue encodedArgument)669 { 670 VM& vm = exec->vm();660 size_t JIT_OPERATION operationRegExpTestString(ExecState* exec, JSGlobalObject* globalObject, RegExpObject* regExpObject, JSString* input) 661 { 662 VM& vm = globalObject->vm(); 663 NativeCallFrameTracer tracer(&vm, exec); 664 665 return regExpObject->test(exec, globalObject, input); 666 } 667 668 size_t JIT_OPERATION operationRegExpTest(ExecState* exec, JSGlobalObject* globalObject, RegExpObject* regExpObject, EncodedJSValue encodedArgument) 669 { 670 VM& vm = globalObject->vm(); 671 671 NativeCallFrameTracer tracer(&vm, exec); 672 672 … … 676 676 if (!input) 677 677 return false; 678 return regExpObject->test(exec, input);679 } 680 681 size_t JIT_OPERATION operationRegExpTestGeneric(ExecState* exec, EncodedJSValue encodedBase, EncodedJSValue encodedArgument)682 { 683 VM& vm = exec->vm();678 return regExpObject->test(exec, globalObject, input); 679 } 680 681 size_t JIT_OPERATION operationRegExpTestGeneric(ExecState* exec, JSGlobalObject* globalObject, EncodedJSValue encodedBase, EncodedJSValue encodedArgument) 682 { 683 VM& vm = globalObject->vm(); 684 684 NativeCallFrameTracer tracer(&vm, exec); 685 685 … … 695 695 if (!input) 696 696 return false; 697 return asRegExpObject(base)->test(exec, input);697 return asRegExpObject(base)->test(exec, globalObject, input); 698 698 } 699 699 -
trunk/Source/JavaScriptCore/dfg/DFGOperations.h
r197622 r197641 102 102 EncodedJSValue JIT_OPERATION operationArrayPop(ExecState*, JSArray*) WTF_INTERNAL; 103 103 EncodedJSValue JIT_OPERATION operationArrayPopAndRecoverLength(ExecState*, JSArray*) WTF_INTERNAL; 104 EncodedJSValue JIT_OPERATION operationRegExpExecString(ExecState*, RegExpObject*, JSString*) WTF_INTERNAL;105 EncodedJSValue JIT_OPERATION operationRegExpExec(ExecState*, RegExpObject*, EncodedJSValue) WTF_INTERNAL;106 EncodedJSValue JIT_OPERATION operationRegExpExecGeneric(ExecState*, EncodedJSValue, EncodedJSValue) WTF_INTERNAL;104 EncodedJSValue JIT_OPERATION operationRegExpExecString(ExecState*, JSGlobalObject*, RegExpObject*, JSString*) WTF_INTERNAL; 105 EncodedJSValue JIT_OPERATION operationRegExpExec(ExecState*, JSGlobalObject*, RegExpObject*, EncodedJSValue) WTF_INTERNAL; 106 EncodedJSValue JIT_OPERATION operationRegExpExecGeneric(ExecState*, JSGlobalObject*, EncodedJSValue, EncodedJSValue) WTF_INTERNAL; 107 107 // These comparisons return a boolean within a size_t such that the value is zero extended to fill the register. 108 size_t JIT_OPERATION operationRegExpTestString(ExecState*, RegExpObject*, JSString*) WTF_INTERNAL;109 size_t JIT_OPERATION operationRegExpTest(ExecState*, RegExpObject*, EncodedJSValue) WTF_INTERNAL;110 size_t JIT_OPERATION operationRegExpTestGeneric(ExecState*, EncodedJSValue, EncodedJSValue) WTF_INTERNAL;108 size_t JIT_OPERATION operationRegExpTestString(ExecState*, JSGlobalObject*, RegExpObject*, JSString*) WTF_INTERNAL; 109 size_t JIT_OPERATION operationRegExpTest(ExecState*, JSGlobalObject*, RegExpObject*, EncodedJSValue) WTF_INTERNAL; 110 size_t JIT_OPERATION operationRegExpTestGeneric(ExecState*, JSGlobalObject*, EncodedJSValue, EncodedJSValue) WTF_INTERNAL; 111 111 size_t JIT_OPERATION operationCompareStrictEqCell(ExecState*, EncodedJSValue encodedOp1, EncodedJSValue encodedOp2) WTF_INTERNAL; 112 112 size_t JIT_OPERATION operationCompareStrictEq(ExecState*, EncodedJSValue encodedOp1, EncodedJSValue encodedOp2) WTF_INTERNAL; -
trunk/Source/JavaScriptCore/dfg/DFGPredictionPropagationPhase.cpp
r197549 r197641 551 551 } 552 552 553 case SkipScope: { 553 case SkipScope: 554 case GetGlobalObject: { 554 555 changed |= setPrediction(SpecObjectOther); 555 556 break; -
trunk/Source/JavaScriptCore/dfg/DFGSafeToExecute.h
r197549 r197641 208 208 case GetScope: 209 209 case SkipScope: 210 case GetGlobalObject: 210 211 case GetClosureVar: 211 212 case PutClosureVar: -
trunk/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp
r197549 r197641 5343 5343 } 5344 5344 5345 void SpeculativeJIT::compileGetGlobalObject(Node* node) 5346 { 5347 SpeculateCellOperand object(this, node->child1()); 5348 GPRTemporary result(this); 5349 GPRTemporary scratch(this); 5350 m_jit.emitLoadStructure(object.gpr(), result.gpr(), scratch.gpr()); 5351 m_jit.loadPtr(JITCompiler::Address(result.gpr(), Structure::globalObjectOffset()), result.gpr()); 5352 cellResult(result.gpr(), node); 5353 } 5354 5345 5355 void SpeculativeJIT::compileGetArrayLength(Node* node) 5346 5356 { -
trunk/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.h
r197622 r197641 1218 1218 } 1219 1219 1220 JITCompiler::Call callOperation(J_JITOperation_E ReoJ operation, GPRReg result, GPRReg arg1, GPRReg arg2)1221 { 1222 m_jit.setupArgumentsWithExecState(arg1, arg2 );1223 return appendCallSetResult(operation, result); 1224 } 1225 1226 JITCompiler::Call callOperation(J_JITOperation_E ReoJss operation, GPRReg result, GPRReg arg1, GPRReg arg2)1227 { 1228 m_jit.setupArgumentsWithExecState(arg1, arg2 );1220 JITCompiler::Call callOperation(J_JITOperation_EGReoJ operation, GPRReg result, GPRReg arg1, GPRReg arg2, GPRReg arg3) 1221 { 1222 m_jit.setupArgumentsWithExecState(arg1, arg2, arg3); 1223 return appendCallSetResult(operation, result); 1224 } 1225 1226 JITCompiler::Call callOperation(J_JITOperation_EGReoJss operation, GPRReg result, GPRReg arg1, GPRReg arg2, GPRReg arg3) 1227 { 1228 m_jit.setupArgumentsWithExecState(arg1, arg2, arg3); 1229 1229 return appendCallSetResult(operation, result); 1230 1230 } … … 1447 1447 return appendCallSetResult(operation, result); 1448 1448 } 1449 JITCompiler::Call callOperation(S_JITOperation_EReoJ operation, GPRReg result, GPRReg arg1, GPRReg arg2) 1449 JITCompiler::Call callOperation(S_JITOperation_EGJJ operation, GPRReg result, GPRReg arg1, GPRReg arg2, GPRReg arg3) 1450 { 1451 m_jit.setupArgumentsWithExecState(arg1, arg2, arg3); 1452 return appendCallSetResult(operation, result); 1453 } 1454 JITCompiler::Call callOperation(S_JITOperation_EGReoJ operation, GPRReg result, GPRReg arg1, GPRReg arg2, GPRReg arg3) 1455 { 1456 m_jit.setupArgumentsWithExecState(arg1, arg2, arg3); 1457 return appendCallSetResult(operation, result); 1458 } 1459 JITCompiler::Call callOperation(S_JITOperation_EGReoJss operation, GPRReg result, GPRReg arg1, GPRReg arg2, GPRReg arg3) 1460 { 1461 m_jit.setupArgumentsWithExecState(arg1, arg2, arg3); 1462 return appendCallSetResult(operation, result); 1463 } 1464 1465 JITCompiler::Call callOperation(J_JITOperation_EPP operation, GPRReg result, GPRReg arg1, GPRReg arg2) 1450 1466 { 1451 1467 m_jit.setupArgumentsWithExecState(arg1, arg2); 1452 1468 return appendCallSetResult(operation, result); 1453 1469 } 1454 JITCompiler::Call callOperation( S_JITOperation_EReoJssoperation, GPRReg result, GPRReg arg1, GPRReg arg2)1470 JITCompiler::Call callOperation(J_JITOperation_EJJ operation, GPRReg result, GPRReg arg1, GPRReg arg2) 1455 1471 { 1456 1472 m_jit.setupArgumentsWithExecState(arg1, arg2); 1457 1473 return appendCallSetResult(operation, result); 1458 1474 } 1459 1460 JITCompiler::Call callOperation(J_JITOperation_EPP operation, GPRReg result, GPRReg arg1, GPRReg arg2) 1461 { 1462 m_jit.setupArgumentsWithExecState(arg1, arg2); 1463 return appendCallSetResult(operation, result); 1464 } 1465 JITCompiler::Call callOperation(J_JITOperation_EJJ operation, GPRReg result, GPRReg arg1, GPRReg arg2) 1466 { 1467 m_jit.setupArgumentsWithExecState(arg1, arg2); 1475 JITCompiler::Call callOperation(J_JITOperation_EGJJ operation, GPRReg result, GPRReg arg1, GPRReg arg2, GPRReg arg3) 1476 { 1477 m_jit.setupArgumentsWithExecState(arg1, arg2, arg3); 1468 1478 return appendCallSetResult(operation, result); 1469 1479 } … … 1723 1733 return appendCallSetResult(operation, result); 1724 1734 } 1725 JITCompiler::Call callOperation(J_JITOperation_E ReoJ operation, GPRReg resultTag, GPRReg resultPayload, GPRReg arg1, GPRReg arg2Tag, GPRReg arg2Payload)1726 { 1727 m_jit.setupArgumentsWithExecState(arg1, arg2 Payload, arg2Tag);1728 return appendCallSetResult(operation, resultPayload, resultTag); 1729 } 1730 JITCompiler::Call callOperation(J_JITOperation_E ReoJss operation, GPRReg resultTag, GPRReg resultPayload, GPRReg arg1, GPRReg arg2)1731 { 1732 m_jit.setupArgumentsWithExecState(arg1, arg2 );1735 JITCompiler::Call callOperation(J_JITOperation_EGReoJ operation, GPRReg resultTag, GPRReg resultPayload, GPRReg arg1, GPRReg arg2, GPRReg arg3Tag, GPRReg arg3Payload) 1736 { 1737 m_jit.setupArgumentsWithExecState(arg1, arg2, arg3Payload, arg3Tag); 1738 return appendCallSetResult(operation, resultPayload, resultTag); 1739 } 1740 JITCompiler::Call callOperation(J_JITOperation_EGReoJss operation, GPRReg resultTag, GPRReg resultPayload, GPRReg arg1, GPRReg arg2, GPRReg arg3) 1741 { 1742 m_jit.setupArgumentsWithExecState(arg1, arg2, arg3); 1733 1743 return appendCallSetResult(operation, resultPayload, resultTag); 1734 1744 } … … 1830 1840 return appendCallSetResult(operation, result); 1831 1841 } 1832 JITCompiler::Call callOperation(S_JITOperation_EReoJ operation, GPRReg result, GPRReg arg1, GPRReg arg2Tag, GPRReg arg2Payload) 1833 { 1834 m_jit.setupArgumentsWithExecState(arg1, arg2Payload, arg2Tag); 1835 return appendCallSetResult(operation, result); 1836 } 1837 JITCompiler::Call callOperation(S_JITOperation_EReoJss operation, GPRReg result, GPRReg arg1, GPRReg arg2) 1838 { 1839 m_jit.setupArgumentsWithExecState(arg1, arg2); 1842 JITCompiler::Call callOperation(S_JITOperation_EGJJ operation, GPRReg result, GPRReg arg1, GPRReg arg2Tag, GPRReg arg2Payload, GPRReg arg3Tag, GPRReg arg3Payload) 1843 { 1844 m_jit.setupArgumentsWithExecState(arg1, arg2Payload, arg2Tag, SH4_32BIT_DUMMY_ARG arg3Payload, arg3Tag); 1845 return appendCallSetResult(operation, result); 1846 } 1847 JITCompiler::Call callOperation(S_JITOperation_EGReoJ operation, GPRReg result, GPRReg arg1, GPRReg arg2, GPRReg arg3Tag, GPRReg arg3Payload) 1848 { 1849 m_jit.setupArgumentsWithExecState(arg1, arg2, arg3Payload, arg3Tag); 1850 return appendCallSetResult(operation, result); 1851 } 1852 JITCompiler::Call callOperation(S_JITOperation_EGReoJss operation, GPRReg result, GPRReg arg1, GPRReg arg2, GPRReg arg3) 1853 { 1854 m_jit.setupArgumentsWithExecState(arg1, arg2, arg3); 1840 1855 return appendCallSetResult(operation, result); 1841 1856 } … … 1843 1858 { 1844 1859 m_jit.setupArgumentsWithExecState(EABI_32BIT_DUMMY_ARG arg1Payload, arg1Tag, SH4_32BIT_DUMMY_ARG arg2Payload, arg2Tag); 1860 return appendCallSetResult(operation, resultPayload, resultTag); 1861 } 1862 JITCompiler::Call callOperation(J_JITOperation_EGJJ operation, GPRReg resultTag, GPRReg resultPayload, GPRReg arg1, GPRReg arg2Tag, GPRReg arg2Payload, GPRReg arg3Tag, GPRReg arg3Payload) 1863 { 1864 m_jit.setupArgumentsWithExecState(arg1, arg2Payload, arg2Tag, SH4_32BIT_DUMMY_ARG arg3Payload, arg3Tag); 1845 1865 return appendCallSetResult(operation, resultPayload, resultTag); 1846 1866 } … … 2310 2330 void compileGetScope(Node*); 2311 2331 void compileSkipScope(Node*); 2332 void compileGetGlobalObject(Node*); 2312 2333 2313 2334 void compileGetArrayLength(Node*); -
trunk/Source/JavaScriptCore/dfg/DFGSpeculativeJIT32_64.cpp
r197622 r197641 2837 2837 2838 2838 case RegExpExec: { 2839 if (node->child1().useKind() == RegExpObjectUse) { 2840 if (node->child2().useKind() == StringUse) { 2841 SpeculateCellOperand base(this, node->child1()); 2842 SpeculateCellOperand argument(this, node->child2()); 2839 SpeculateCellOperand globalObject(this, node->child1()); 2840 GPRReg globalObjectGPR = globalObject.gpr(); 2841 2842 if (node->child2().useKind() == RegExpObjectUse) { 2843 if (node->child3().useKind() == StringUse) { 2844 SpeculateCellOperand base(this, node->child2()); 2845 SpeculateCellOperand argument(this, node->child3()); 2843 2846 GPRReg baseGPR = base.gpr(); 2844 2847 GPRReg argumentGPR = argument.gpr(); 2845 speculateRegExpObject(node->child 1(), baseGPR);2846 speculateString(node->child 2(), argumentGPR);2848 speculateRegExpObject(node->child2(), baseGPR); 2849 speculateString(node->child3(), argumentGPR); 2847 2850 2848 2851 flushRegisters(); … … 2850 2853 GPRFlushedCallResult resultPayload(this); 2851 2854 callOperation( 2852 operationRegExpExecString, resultTag.gpr(), resultPayload.gpr(), baseGPR,2853 argumentGPR);2855 operationRegExpExecString, resultTag.gpr(), resultPayload.gpr(), 2856 globalObjectGPR, baseGPR, argumentGPR); 2854 2857 m_jit.exceptionCheck(); 2855 2858 … … 2858 2861 } 2859 2862 2860 SpeculateCellOperand base(this, node->child 1());2861 JSValueOperand argument(this, node->child 2());2863 SpeculateCellOperand base(this, node->child2()); 2864 JSValueOperand argument(this, node->child3()); 2862 2865 GPRReg baseGPR = base.gpr(); 2863 2866 GPRReg argumentTagGPR = argument.tagGPR(); 2864 2867 GPRReg argumentPayloadGPR = argument.payloadGPR(); 2865 speculateRegExpObject(node->child 1(), baseGPR);2868 speculateRegExpObject(node->child2(), baseGPR); 2866 2869 2867 2870 flushRegisters(); … … 2869 2872 GPRFlushedCallResult resultPayload(this); 2870 2873 callOperation( 2871 operationRegExpExec, resultTag.gpr(), resultPayload.gpr(), baseGPR, argumentTagGPR,2872 argument PayloadGPR);2874 operationRegExpExec, resultTag.gpr(), resultPayload.gpr(), globalObjectGPR, baseGPR, 2875 argumentTagGPR, argumentPayloadGPR); 2873 2876 m_jit.exceptionCheck(); 2874 2877 … … 2877 2880 } 2878 2881 2879 JSValueOperand base(this, node->child 1());2880 JSValueOperand argument(this, node->child 2());2882 JSValueOperand base(this, node->child2()); 2883 JSValueOperand argument(this, node->child3()); 2881 2884 GPRReg baseTagGPR = base.tagGPR(); 2882 2885 GPRReg basePayloadGPR = base.payloadGPR(); … … 2887 2890 GPRFlushedCallResult2 resultTag(this); 2888 2891 GPRFlushedCallResult resultPayload(this); 2889 callOperation(operationRegExpExecGeneric, resultTag.gpr(), resultPayload.gpr(), baseTagGPR, basePayloadGPR, argumentTagGPR, argumentPayloadGPR); 2892 callOperation( 2893 operationRegExpExecGeneric, resultTag.gpr(), resultPayload.gpr(), globalObjectGPR, 2894 baseTagGPR, basePayloadGPR, argumentTagGPR, argumentPayloadGPR); 2890 2895 m_jit.exceptionCheck(); 2891 2896 … … 2895 2900 2896 2901 case RegExpTest: { 2897 if (node->child1().useKind() == RegExpObjectUse) { 2898 if (node->child2().useKind() == StringUse) { 2899 SpeculateCellOperand base(this, node->child1()); 2900 SpeculateCellOperand argument(this, node->child2()); 2902 SpeculateCellOperand globalObject(this, node->child1()); 2903 GPRReg globalObjectGPR = globalObject.gpr(); 2904 2905 if (node->child2().useKind() == RegExpObjectUse) { 2906 if (node->child3().useKind() == StringUse) { 2907 SpeculateCellOperand base(this, node->child2()); 2908 SpeculateCellOperand argument(this, node->child3()); 2901 2909 GPRReg baseGPR = base.gpr(); 2902 2910 GPRReg argumentGPR = argument.gpr(); 2903 speculateRegExpObject(node->child 1(), baseGPR);2904 speculateString(node->child 2(), argumentGPR);2911 speculateRegExpObject(node->child2(), baseGPR); 2912 speculateString(node->child3(), argumentGPR); 2905 2913 2906 2914 flushRegisters(); 2907 2915 GPRFlushedCallResult result(this); 2908 callOperation(operationRegExpTestString, result.gpr(), baseGPR, argumentGPR); 2916 callOperation( 2917 operationRegExpTestString, result.gpr(), globalObjectGPR, baseGPR, argumentGPR); 2909 2918 m_jit.exceptionCheck(); 2910 2919 … … 2913 2922 } 2914 2923 2915 SpeculateCellOperand base(this, node->child 1());2916 JSValueOperand argument(this, node->child 2());2924 SpeculateCellOperand base(this, node->child2()); 2925 JSValueOperand argument(this, node->child3()); 2917 2926 GPRReg baseGPR = base.gpr(); 2918 2927 GPRReg argumentTagGPR = argument.tagGPR(); 2919 2928 GPRReg argumentPayloadGPR = argument.payloadGPR(); 2920 speculateRegExpObject(node->child 1(), baseGPR);2929 speculateRegExpObject(node->child2(), baseGPR); 2921 2930 2922 2931 flushRegisters(); 2923 2932 GPRFlushedCallResult result(this); 2924 2933 callOperation( 2925 operationRegExpTest, result.gpr(), baseGPR, argumentTagGPR, argumentPayloadGPR); 2934 operationRegExpTest, result.gpr(), globalObjectGPR, baseGPR, argumentTagGPR, 2935 argumentPayloadGPR); 2926 2936 m_jit.exceptionCheck(); 2927 2937 … … 2930 2940 } 2931 2941 2932 JSValueOperand base(this, node->child 1());2933 JSValueOperand argument(this, node->child 2());2942 JSValueOperand base(this, node->child2()); 2943 JSValueOperand argument(this, node->child3()); 2934 2944 GPRReg baseTagGPR = base.tagGPR(); 2935 2945 GPRReg basePayloadGPR = base.payloadGPR(); … … 2939 2949 flushRegisters(); 2940 2950 GPRFlushedCallResult result(this); 2941 callOperation(operationRegExpTestGeneric, result.gpr(), baseTagGPR, basePayloadGPR, argumentTagGPR, argumentPayloadGPR); 2951 callOperation( 2952 operationRegExpTestGeneric, result.gpr(), globalObjectGPR, baseTagGPR, basePayloadGPR, 2953 argumentTagGPR, argumentPayloadGPR); 2942 2954 m_jit.exceptionCheck(); 2943 2955 … … 3902 3914 break; 3903 3915 3916 case GetGlobalObject: 3917 compileGetGlobalObject(node); 3918 break; 3919 3904 3920 case GetClosureVar: { 3905 3921 SpeculateCellOperand base(this, node->child1()); -
trunk/Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp
r197622 r197641 2963 2963 2964 2964 case RegExpExec: { 2965 if (node->child1().useKind() == RegExpObjectUse) { 2966 if (node->child2().useKind() == StringUse) { 2967 SpeculateCellOperand base(this, node->child1()); 2968 SpeculateCellOperand argument(this, node->child2()); 2965 SpeculateCellOperand globalObject(this, node->child1()); 2966 GPRReg globalObjectGPR = globalObject.gpr(); 2967 2968 if (node->child2().useKind() == RegExpObjectUse) { 2969 if (node->child3().useKind() == StringUse) { 2970 SpeculateCellOperand base(this, node->child2()); 2971 SpeculateCellOperand argument(this, node->child3()); 2969 2972 GPRReg baseGPR = base.gpr(); 2970 2973 GPRReg argumentGPR = argument.gpr(); 2971 speculateRegExpObject(node->child 1(), baseGPR);2972 speculateString(node->child 2(), argumentGPR);2974 speculateRegExpObject(node->child2(), baseGPR); 2975 speculateString(node->child3(), argumentGPR); 2973 2976 2974 2977 flushRegisters(); 2975 2978 GPRFlushedCallResult result(this); 2976 callOperation(operationRegExpExecString, result.gpr(), baseGPR, argumentGPR);2979 callOperation(operationRegExpExecString, result.gpr(), globalObjectGPR, baseGPR, argumentGPR); 2977 2980 m_jit.exceptionCheck(); 2978 2981 … … 2981 2984 } 2982 2985 2983 SpeculateCellOperand base(this, node->child 1());2984 JSValueOperand argument(this, node->child 2());2986 SpeculateCellOperand base(this, node->child2()); 2987 JSValueOperand argument(this, node->child3()); 2985 2988 GPRReg baseGPR = base.gpr(); 2986 2989 GPRReg argumentGPR = argument.gpr(); 2987 speculateRegExpObject(node->child 1(), baseGPR);2990 speculateRegExpObject(node->child2(), baseGPR); 2988 2991 2989 2992 flushRegisters(); 2990 2993 GPRFlushedCallResult result(this); 2991 callOperation(operationRegExpExec, result.gpr(), baseGPR, argumentGPR);2994 callOperation(operationRegExpExec, result.gpr(), globalObjectGPR, baseGPR, argumentGPR); 2992 2995 m_jit.exceptionCheck(); 2993 2996 … … 2996 2999 } 2997 3000 2998 JSValueOperand base(this, node->child 1());2999 JSValueOperand argument(this, node->child 2());3001 JSValueOperand base(this, node->child2()); 3002 JSValueOperand argument(this, node->child3()); 3000 3003 GPRReg baseGPR = base.gpr(); 3001 3004 GPRReg argumentGPR = argument.gpr(); … … 3003 3006 flushRegisters(); 3004 3007 GPRFlushedCallResult result(this); 3005 callOperation(operationRegExpExecGeneric, result.gpr(), baseGPR, argumentGPR);3008 callOperation(operationRegExpExecGeneric, result.gpr(), globalObjectGPR, baseGPR, argumentGPR); 3006 3009 m_jit.exceptionCheck(); 3007 3010 … … 3011 3014 3012 3015 case RegExpTest: { 3013 if (node->child1().useKind() == RegExpObjectUse) { 3014 if (node->child2().useKind() == StringUse) { 3015 SpeculateCellOperand base(this, node->child1()); 3016 SpeculateCellOperand argument(this, node->child2()); 3016 SpeculateCellOperand globalObject(this, node->child1()); 3017 GPRReg globalObjectGPR = globalObject.gpr(); 3018 3019 if (node->child2().useKind() == RegExpObjectUse) { 3020 if (node->child3().useKind() == StringUse) { 3021 SpeculateCellOperand base(this, node->child2()); 3022 SpeculateCellOperand argument(this, node->child3()); 3017 3023 GPRReg baseGPR = base.gpr(); 3018 3024 GPRReg argumentGPR = argument.gpr(); 3019 speculateRegExpObject(node->child 1(), baseGPR);3020 speculateString(node->child 2(), argumentGPR);3025 speculateRegExpObject(node->child2(), baseGPR); 3026 speculateString(node->child3(), argumentGPR); 3021 3027 3022 3028 flushRegisters(); 3023 3029 GPRFlushedCallResult result(this); 3024 callOperation(operationRegExpTestString, result.gpr(), baseGPR, argumentGPR);3030 callOperation(operationRegExpTestString, result.gpr(), globalObjectGPR, baseGPR, argumentGPR); 3025 3031 m_jit.exceptionCheck(); 3026 3032 … … 3030 3036 } 3031 3037 3032 SpeculateCellOperand base(this, node->child 1());3033 JSValueOperand argument(this, node->child 2());3038 SpeculateCellOperand base(this, node->child2()); 3039 JSValueOperand argument(this, node->child3()); 3034 3040 GPRReg baseGPR = base.gpr(); 3035 3041 GPRReg argumentGPR = argument.gpr(); 3036 speculateRegExpObject(node->child 1(), baseGPR);3042 speculateRegExpObject(node->child2(), baseGPR); 3037 3043 3038 3044 flushRegisters(); 3039 3045 GPRFlushedCallResult result(this); 3040 callOperation(operationRegExpTest, result.gpr(), baseGPR, argumentGPR);3046 callOperation(operationRegExpTest, result.gpr(), globalObjectGPR, baseGPR, argumentGPR); 3041 3047 m_jit.exceptionCheck(); 3042 3048 … … 3046 3052 } 3047 3053 3048 JSValueOperand base(this, node->child 1());3049 JSValueOperand argument(this, node->child 2());3054 JSValueOperand base(this, node->child2()); 3055 JSValueOperand argument(this, node->child3()); 3050 3056 GPRReg baseGPR = base.gpr(); 3051 3057 GPRReg argumentGPR = argument.gpr(); … … 3053 3059 flushRegisters(); 3054 3060 GPRFlushedCallResult result(this); 3055 callOperation(operationRegExpTestGeneric, result.gpr(), baseGPR, argumentGPR);3061 callOperation(operationRegExpTestGeneric, result.gpr(), globalObjectGPR, baseGPR, argumentGPR); 3056 3062 m_jit.exceptionCheck(); 3057 3063 … … 3931 3937 compileSkipScope(node); 3932 3938 break; 3939 3940 case GetGlobalObject: 3941 compileGetGlobalObject(node); 3942 break; 3933 3943 3934 3944 case GetClosureVar: { -
trunk/Source/JavaScriptCore/dfg/DFGStructureRegistrationPhase.cpp
r194835 r197641 150 150 registerStructure(m_graph.globalObjectFor(node->origin.semantic)->generatorFunctionStructure()); 151 151 break; 152 152 153 153 default: 154 154 break; -
trunk/Source/JavaScriptCore/ftl/FTLCapabilities.cpp
r197549 r197641 112 112 case LoopHint: 113 113 case SkipScope: 114 case GetGlobalObject: 114 115 case CreateActivation: 115 116 case NewArrowFunction: -
trunk/Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp
r197622 r197641 748 748 case SkipScope: 749 749 compileSkipScope(); 750 break; 751 case GetGlobalObject: 752 compileGetGlobalObject(); 750 753 break; 751 754 case GetClosureVar: … … 4476 4479 setJSValue(m_out.loadPtr(lowCell(m_node->child1()), m_heaps.JSScope_next)); 4477 4480 } 4481 4482 void compileGetGlobalObject() 4483 { 4484 LValue structure = loadStructure(lowCell(m_node->child1())); 4485 setJSValue(m_out.loadPtr(structure, m_heaps.Structure_globalObject)); 4486 } 4478 4487 4479 4488 void compileGetClosureVar() … … 6441 6450 void compileRegExpExec() 6442 6451 { 6443 if (m_node->child1().useKind() == RegExpObjectUse) { 6444 LValue base = lowRegExpObject(m_node->child1()); 6445 6446 if (m_node->child2().useKind() == StringUse) { 6447 LValue argument = lowString(m_node->child2()); 6452 LValue globalObject = lowCell(m_node->child1()); 6453 6454 if (m_node->child2().useKind() == RegExpObjectUse) { 6455 LValue base = lowRegExpObject(m_node->child2()); 6456 6457 if (m_node->child3().useKind() == StringUse) { 6458 LValue argument = lowString(m_node->child3()); 6448 6459 LValue result = vmCall( 6449 Int64, m_out.operation(operationRegExpExecString), m_callFrame, base, argument); 6460 Int64, m_out.operation(operationRegExpExecString), m_callFrame, globalObject, 6461 base, argument); 6450 6462 setJSValue(result); 6451 6463 return; 6452 6464 } 6453 6465 6454 LValue argument = lowJSValue(m_node->child2()); 6455 setJSValue( 6456 vmCall(Int64, m_out.operation(operationRegExpExec), m_callFrame, base, argument)); 6457 return; 6458 } 6459 6460 LValue base = lowJSValue(m_node->child1()); 6461 LValue argument = lowJSValue(m_node->child2()); 6462 setJSValue( 6463 vmCall(Int64, m_out.operation(operationRegExpExecGeneric), m_callFrame, base, argument)); 6466 LValue argument = lowJSValue(m_node->child3()); 6467 LValue result = vmCall( 6468 Int64, m_out.operation(operationRegExpExec), m_callFrame, globalObject, base, 6469 argument); 6470 setJSValue(result); 6471 return; 6472 } 6473 6474 LValue base = lowJSValue(m_node->child2()); 6475 LValue argument = lowJSValue(m_node->child3()); 6476 LValue result = vmCall( 6477 Int64, m_out.operation(operationRegExpExecGeneric), m_callFrame, globalObject, base, 6478 argument); 6479 setJSValue(result); 6464 6480 } 6465 6481 6466 6482 void compileRegExpTest() 6467 6483 { 6468 if (m_node->child1().useKind() == RegExpObjectUse) { 6469 LValue base = lowRegExpObject(m_node->child1()); 6470 6471 if (m_node->child2().useKind() == StringUse) { 6472 LValue argument = lowString(m_node->child2()); 6484 LValue globalObject = lowCell(m_node->child1()); 6485 6486 if (m_node->child2().useKind() == RegExpObjectUse) { 6487 LValue base = lowRegExpObject(m_node->child2()); 6488 6489 if (m_node->child3().useKind() == StringUse) { 6490 LValue argument = lowString(m_node->child3()); 6473 6491 LValue result = vmCall( 6474 Int32, m_out.operation(operationRegExpTestString), m_callFrame, base, argument); 6492 Int32, m_out.operation(operationRegExpTestString), m_callFrame, globalObject, 6493 base, argument); 6475 6494 setBoolean(result); 6476 6495 return; 6477 6496 } 6478 6497 6479 LValue argument = lowJSValue(m_node->child2()); 6480 setBoolean( 6481 vmCall(Int32, m_out.operation(operationRegExpTest), m_callFrame, base, argument)); 6482 return; 6483 } 6484 6485 LValue base = lowJSValue(m_node->child1()); 6486 LValue argument = lowJSValue(m_node->child2()); 6487 setBoolean( 6488 vmCall(Int32, m_out.operation(operationRegExpTestGeneric), m_callFrame, base, argument)); 6498 LValue argument = lowJSValue(m_node->child3()); 6499 LValue result = vmCall( 6500 Int32, m_out.operation(operationRegExpTest), m_callFrame, globalObject, base, 6501 argument); 6502 setBoolean(result); 6503 return; 6504 } 6505 6506 LValue base = lowJSValue(m_node->child2()); 6507 LValue argument = lowJSValue(m_node->child3()); 6508 LValue result = vmCall( 6509 Int32, m_out.operation(operationRegExpTestGeneric), m_callFrame, globalObject, base, 6510 argument); 6511 setBoolean(result); 6489 6512 } 6490 6513 -
trunk/Source/JavaScriptCore/jit/JITOperations.h
r197622 r197641 123 123 typedef EncodedJSValue JIT_OPERATION (*J_JITOperation_EDA)(ExecState*, double, JSArray*); 124 124 typedef EncodedJSValue JIT_OPERATION (*J_JITOperation_EE)(ExecState*, ExecState*); 125 typedef EncodedJSValue JIT_OPERATION (*J_JITOperation_EGReoJ)(ExecState*, JSGlobalObject*, RegExpObject*, EncodedJSValue); 126 typedef EncodedJSValue JIT_OPERATION (*J_JITOperation_EGReoJss)(ExecState*, JSGlobalObject*, RegExpObject*, JSString*); 127 typedef EncodedJSValue JIT_OPERATION (*J_JITOperation_EGJJ)(ExecState*, JSGlobalObject*, EncodedJSValue, EncodedJSValue); 125 128 typedef EncodedJSValue JIT_OPERATION (*J_JITOperation_EI)(ExecState*, UniquedStringImpl*); 126 129 typedef EncodedJSValue JIT_OPERATION (*J_JITOperation_EJ)(ExecState*, EncodedJSValue); … … 202 205 typedef size_t JIT_OPERATION (*S_JITOperation_ECC)(ExecState*, JSCell*, JSCell*); 203 206 typedef size_t JIT_OPERATION (*S_JITOperation_EGC)(ExecState*, JSGlobalObject*, JSCell*); 207 typedef size_t JIT_OPERATION (*S_JITOperation_EGJJ)(ExecState*, JSGlobalObject*, EncodedJSValue, EncodedJSValue); 208 typedef size_t JIT_OPERATION (*S_JITOperation_EGReoJ)(ExecState*, JSGlobalObject*, RegExpObject*, EncodedJSValue); 209 typedef size_t JIT_OPERATION (*S_JITOperation_EGReoJss)(ExecState*, JSGlobalObject*, RegExpObject*, JSString*); 204 210 typedef size_t JIT_OPERATION (*S_JITOperation_EJ)(ExecState*, EncodedJSValue); 205 211 typedef size_t JIT_OPERATION (*S_JITOperation_EJJ)(ExecState*, EncodedJSValue, EncodedJSValue); -
trunk/Source/JavaScriptCore/runtime/JSGlobalObject.cpp
r197536 r197641 1 1 /* 2 * Copyright (C) 2007, 2008, 2009, 2014 , 2015Apple Inc. All rights reserved.2 * Copyright (C) 2007, 2008, 2009, 2014-2016 Apple Inc. All rights reserved. 3 3 * Copyright (C) 2008 Cameron Zwarich (cwzwarich@uwaterloo.ca) 4 4 * … … 365 365 m_regExpPrototype.set(vm, this, RegExpPrototype::create(vm, this, RegExpPrototype::createStructure(vm, this, m_objectPrototype.get()), emptyRegex)); 366 366 m_regExpStructure.set(vm, this, RegExpObject::createStructure(vm, this, m_regExpPrototype.get())); 367 m_regExpMatchesArrayStructure.set(vm, this, createRegExpMatchesArrayStructure(vm, *this)); 367 m_regExpMatchesArrayStructure.set(vm, this, createRegExpMatchesArrayStructure(vm, this)); 368 m_regExpMatchesArraySlowPutStructure.set(vm, this, createRegExpMatchesArraySlowPutStructure(vm, this)); 368 369 369 370 m_moduleRecordStructure.set(vm, this, JSModuleRecord::createStructure(vm, this, m_objectPrototype.get())); … … 762 763 for (unsigned i = 0; i < NumberOfIndexingShapes; ++i) 763 764 m_arrayStructureForIndexingShapeDuringAllocation[i].set(vm, this, originalArrayStructureForIndexingType(ArrayWithSlowPutArrayStorage)); 765 766 // Same for any special array structures. 767 m_regExpMatchesArrayStructure.set(vm, this, m_regExpMatchesArraySlowPutStructure.get()); 764 768 765 769 // Make sure that all objects that have indexed storage switch to the slow kind of … … 901 905 visitor.append(&thisObject->m_iteratorResultObjectStructure); 902 906 visitor.append(&thisObject->m_regExpMatchesArrayStructure); 907 visitor.append(&thisObject->m_regExpMatchesArraySlowPutStructure); 903 908 visitor.append(&thisObject->m_moduleRecordStructure); 904 909 visitor.append(&thisObject->m_moduleNamespaceObjectStructure); -
trunk/Source/JavaScriptCore/runtime/JSGlobalObject.h
r197261 r197641 1 1 /* 2 2 * Copyright (C) 2007 Eric Seidel <eric@webkit.org> 3 * Copyright (C) 2007, 2008, 2009, 2014 , 2015Apple Inc. All rights reserved.3 * Copyright (C) 2007, 2008, 2009, 2014-2016 Apple Inc. All rights reserved. 4 4 * 5 5 * This library is free software; you can redistribute it and/or … … 279 279 WriteBarrier<Structure> m_iteratorResultObjectStructure; 280 280 WriteBarrier<Structure> m_regExpMatchesArrayStructure; 281 WriteBarrier<Structure> m_regExpMatchesArraySlowPutStructure; 281 282 WriteBarrier<Structure> m_moduleRecordStructure; 282 283 WriteBarrier<Structure> m_moduleNamespaceObjectStructure; -
trunk/Source/JavaScriptCore/runtime/JSObject.h
r197614 r197641 1377 1377 DeferredStructureTransitionWatchpointFire deferredWatchpointFire; 1378 1378 1379 newStructure = Structure::add PropertyTransition(1379 newStructure = Structure::addNewPropertyTransition( 1380 1380 vm, structure, propertyName, attributes, offset, slot.context(), &deferredWatchpointFire); 1381 1381 newStructure->willStoreValueForNewTransition( -
trunk/Source/JavaScriptCore/runtime/JSString.h
r197485 r197641 2 2 * Copyright (C) 1999-2001 Harri Porten (porten@kde.org) 3 3 * Copyright (C) 2001 Peter Kelly (pmk@post.com) 4 * Copyright (C) 2003, 2004, 2005, 2006, 2007, 2008, 2014 Apple Inc. All rights reserved.4 * Copyright (C) 2003, 2004, 2005, 2006, 2007, 2008, 2014, 2016 Apple Inc. All rights reserved. 5 5 * 6 6 * This library is free software; you can redistribute it and/or … … 294 294 } 295 295 296 void finishCreation(ExecState& exec, JSString& base, unsigned offset, unsigned length) 297 { 298 VM& vm = exec.vm(); 296 void finishCreation(VM& vm, ExecState* exec, JSString* base, unsigned offset, unsigned length) 297 { 299 298 Base::finishCreation(vm); 300 299 ASSERT(!sumOverflows<int32_t>(offset, length)); 301 ASSERT(offset + length <= base .length());300 ASSERT(offset + length <= base->length()); 302 301 m_length = length; 303 setIs8Bit(base .is8Bit());302 setIs8Bit(base->is8Bit()); 304 303 setIsSubstring(true); 305 if (base .isSubstring()) {306 JSRopeString & baseRope = static_cast<JSRopeString&>(base);307 substringBase().set(vm, this, baseRope .substringBase().get());308 substringOffset() = baseRope .substringOffset() + offset;304 if (base->isSubstring()) { 305 JSRopeString* baseRope = jsCast<JSRopeString*>(base); 306 substringBase().set(vm, this, baseRope->substringBase().get()); 307 substringOffset() = baseRope->substringOffset() + offset; 309 308 } else { 310 substringBase().set(vm, this, &base);309 substringBase().set(vm, this, base); 311 310 substringOffset() = offset; 312 311 … … 314 313 // Resolve non-substring rope bases so we don't have to deal with it. 315 314 // FIXME: Evaluate if this would be worth adding more branches. 316 if (base .isRope())317 static_cast<JSRopeString&>(base).resolveRope(&exec);315 if (base->isRope()) 316 jsCast<JSRopeString*>(base)->resolveRope(exec); 318 317 } 319 318 } … … 357 356 } 358 357 359 static JSString* create( ExecState& exec, JSString&base, unsigned offset, unsigned length)360 { 361 JSRopeString* newString = new (NotNull, allocateCell<JSRopeString>( exec.vm().heap)) JSRopeString(exec.vm());362 newString->finishCreation( exec, base, offset, length);358 static JSString* create(VM& vm, ExecState* exec, JSString* base, unsigned offset, unsigned length) 359 { 360 JSRopeString* newString = new (NotNull, allocateCell<JSRopeString>(vm.heap)) JSRopeString(vm); 361 newString->finishCreation(vm, exec, base, offset, length); 363 362 return newString; 364 363 } … … 543 542 } 544 543 545 inline JSString* jsSubstring( ExecState* exec, JSString* s, unsigned offset, unsigned length)544 inline JSString* jsSubstring(VM& vm, ExecState* exec, JSString* s, unsigned offset, unsigned length) 546 545 { 547 546 ASSERT(offset <= static_cast<unsigned>(s->length())); 548 547 ASSERT(length <= static_cast<unsigned>(s->length())); 549 548 ASSERT(offset + length <= static_cast<unsigned>(s->length())); 550 VM& vm = exec->vm();551 549 if (!length) 552 550 return vm.smallStrings.emptyString(); 553 551 if (!offset && length == s->length()) 554 552 return s; 555 return JSRopeString::create(*exec, *s, offset, length); 553 return JSRopeString::create(vm, exec, s, offset, length); 554 } 555 556 inline JSString* jsSubstring(ExecState* exec, JSString* s, unsigned offset, unsigned length) 557 { 558 return jsSubstring(exec->vm(), exec, s, offset, length); 556 559 } 557 560 -
trunk/Source/JavaScriptCore/runtime/RegExpCachedResult.cpp
r175372 r197641 1 1 /* 2 * Copyright (C) 2012 Apple Inc. All rights reserved.2 * Copyright (C) 2012, 2016 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 46 46 if (!m_reified) { 47 47 m_reifiedInput.set(exec->vm(), owner, m_lastInput.get()); 48 m_reifiedResult.set(exec->vm(), owner, createRegExpMatchesArray(exec, m_lastInput.get(), m_lastRegExp.get(), m_result));48 m_reifiedResult.set(exec->vm(), owner, createRegExpMatchesArray(exec, exec->lexicalGlobalObject(), m_lastInput.get(), m_lastRegExp.get(), m_result)); 49 49 m_reified = true; 50 50 } -
trunk/Source/JavaScriptCore/runtime/RegExpMatchesArray.cpp
r185597 r197641 1 1 /* 2 * Copyright (C) 2012-201 5Apple Inc. All rights reserved.2 * Copyright (C) 2012-2016 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 51 51 } 52 52 53 JSArray* createRegExpMatchesArray(ExecState* exec, JSString* input, RegExp* regExp, MatchResult result) 53 JSArray* createRegExpMatchesArray( 54 ExecState* exec, JSGlobalObject* globalObject, JSString* input, RegExp* regExp, 55 MatchResult result) 54 56 { 57 SamplingRegion samplingRegion("createRegExpMatchesArray"); 58 55 59 ASSERT(result); 56 VM& vm = exec->vm(); 57 JSArray* array = tryCreateUninitializedRegExpMatchesArray(vm, exec->lexicalGlobalObject()->regExpMatchesArrayStructure(), regExp->numSubpatterns() + 1); 58 RELEASE_ASSERT(array); 60 VM& vm = globalObject->vm(); 59 61 60 SamplingRegion samplingRegion("Reifying substring properties"); 61 62 array->initializeIndex(vm, 0, jsSubstring(exec, input, result.start, result.end - result.start), ArrayWithContiguous); 63 64 if (unsigned numSubpatterns = regExp->numSubpatterns()) { 65 Vector<int, 32> subpatternResults; 66 int position = regExp->match(vm, input->value(exec), result.start, subpatternResults); 67 ASSERT_UNUSED(position, position >= 0 && static_cast<size_t>(position) == result.start); 68 ASSERT(result.start == static_cast<size_t>(subpatternResults[0])); 69 ASSERT(result.end == static_cast<size_t>(subpatternResults[1])); 70 71 for (unsigned i = 1; i <= numSubpatterns; ++i) { 72 int start = subpatternResults[2 * i]; 73 if (start >= 0) 74 array->initializeIndex(vm, i, jsSubstring(exec, input, start, subpatternResults[2 * i + 1] - start), ArrayWithContiguous); 75 else 76 array->initializeIndex(vm, i, jsUndefined(), ArrayWithContiguous); 62 JSArray* array; 63 if (UNLIKELY(globalObject->isHavingABadTime())) { 64 array = JSArray::tryCreateUninitialized(vm, globalObject->regExpMatchesArrayStructure(), regExp->numSubpatterns() + 1); 65 66 array->initializeIndex(vm, 0, jsSubstring(vm, exec, input, result.start, result.end - result.start)); 67 68 if (unsigned numSubpatterns = regExp->numSubpatterns()) { 69 Vector<int, 32> subpatternResults; 70 int position = regExp->match(vm, input->value(exec), result.start, subpatternResults); 71 ASSERT_UNUSED(position, position >= 0 && static_cast<size_t>(position) == result.start); 72 ASSERT(result.start == static_cast<size_t>(subpatternResults[0])); 73 ASSERT(result.end == static_cast<size_t>(subpatternResults[1])); 74 75 for (unsigned i = 1; i <= numSubpatterns; ++i) { 76 int start = subpatternResults[2 * i]; 77 if (start >= 0) 78 array->initializeIndex(vm, i, jsSubstring(vm, exec, input, start, subpatternResults[2 * i + 1] - start)); 79 else 80 array->initializeIndex(vm, i, jsUndefined()); 81 } 82 } 83 } else { 84 array = tryCreateUninitializedRegExpMatchesArray(vm, globalObject->regExpMatchesArrayStructure(), regExp->numSubpatterns() + 1); 85 RELEASE_ASSERT(array); 86 87 array->initializeIndex(vm, 0, jsSubstring(vm, exec, input, result.start, result.end - result.start), ArrayWithContiguous); 88 89 if (unsigned numSubpatterns = regExp->numSubpatterns()) { 90 Vector<int, 32> subpatternResults; 91 int position = regExp->match(vm, input->value(exec), result.start, subpatternResults); 92 ASSERT_UNUSED(position, position >= 0 && static_cast<size_t>(position) == result.start); 93 ASSERT(result.start == static_cast<size_t>(subpatternResults[0])); 94 ASSERT(result.end == static_cast<size_t>(subpatternResults[1])); 95 96 for (unsigned i = 1; i <= numSubpatterns; ++i) { 97 int start = subpatternResults[2 * i]; 98 if (start >= 0) 99 array->initializeIndex(vm, i, jsSubstring(vm, exec, input, start, subpatternResults[2 * i + 1] - start), ArrayWithContiguous); 100 else 101 array->initializeIndex(vm, i, jsUndefined(), ArrayWithContiguous); 102 } 77 103 } 78 104 } … … 84 110 } 85 111 86 Structure* createRegExpMatchesArrayStructure(VM& vm, JSGlobalObject& globalObject)112 static Structure* createStructureImpl(VM& vm, JSGlobalObject* globalObject, IndexingType indexingType) 87 113 { 88 Structure* structure = globalObject .arrayStructureForIndexingTypeDuringAllocation(ArrayWithContiguous);114 Structure* structure = globalObject->arrayStructureForIndexingTypeDuringAllocation(indexingType); 89 115 PropertyOffset offset; 90 structure = structure->addPropertyTransition(vm, structure, vm.propertyNames->index, 0, offset);116 structure = Structure::addPropertyTransition(vm, structure, vm.propertyNames->index, 0, offset); 91 117 ASSERT(offset == indexPropertyOffset); 92 structure = structure->addPropertyTransition(vm, structure, vm.propertyNames->input, 0, offset);118 structure = Structure::addPropertyTransition(vm, structure, vm.propertyNames->input, 0, offset); 93 119 ASSERT(offset == inputPropertyOffset); 94 120 return structure; 95 121 } 96 122 123 Structure* createRegExpMatchesArrayStructure(VM& vm, JSGlobalObject* globalObject) 124 { 125 return createStructureImpl(vm, globalObject, ArrayWithContiguous); 126 } 127 128 Structure* createRegExpMatchesArraySlowPutStructure(VM& vm, JSGlobalObject* globalObject) 129 { 130 return createStructureImpl(vm, globalObject, ArrayWithSlowPutArrayStorage); 131 } 132 97 133 } // namespace JSC -
trunk/Source/JavaScriptCore/runtime/RegExpMatchesArray.h
r185597 r197641 1 1 /* 2 * Copyright (C) 2008 Apple Inc. All Rights Reserved.2 * Copyright (C) 2008, 2016 Apple Inc. All Rights Reserved. 3 3 * 4 4 * This library is free software; you can redistribute it and/or … … 27 27 namespace JSC { 28 28 29 JSArray* createRegExpMatchesArray(ExecState*, JSString*, RegExp*, MatchResult); 30 Structure* createRegExpMatchesArrayStructure(VM&, JSGlobalObject&); 29 JSArray* createRegExpMatchesArray(ExecState*, JSGlobalObject*, JSString*, RegExp*, MatchResult); 30 Structure* createRegExpMatchesArrayStructure(VM&, JSGlobalObject*); 31 Structure* createRegExpMatchesArraySlowPutStructure(VM&, JSGlobalObject*); 31 32 32 33 } -
trunk/Source/JavaScriptCore/runtime/RegExpObject.cpp
r197640 r197641 1 1 /* 2 2 * Copyright (C) 1999-2000 Harri Porten (porten@kde.org) 3 * Copyright (C) 2003, 2007, 2008, 2012 Apple Inc. All Rights Reserved.3 * Copyright (C) 2003, 2007, 2008, 2012, 2016 Apple Inc. All Rights Reserved. 4 4 * 5 5 * This library is free software; you can redistribute it and/or … … 160 160 } 161 161 162 JSValue RegExpObject::exec(ExecState* exec, JS String* string)163 { 164 if (MatchResult result = match(exec, string))165 return createRegExpMatchesArray(exec, string, regExp(), result);162 JSValue RegExpObject::exec(ExecState* exec, JSGlobalObject* globalObject, JSString* string) 163 { 164 if (MatchResult result = match(exec, globalObject, string)) 165 return createRegExpMatchesArray(exec, globalObject, string, regExp(), result); 166 166 return jsNull(); 167 167 } 168 168 169 169 // Shared implementation used by test and exec. 170 MatchResult RegExpObject::match(ExecState* exec, JS String* string)170 MatchResult RegExpObject::match(ExecState* exec, JSGlobalObject* globalObject, JSString* string) 171 171 { 172 172 RegExp* regExp = this->regExp(); 173 RegExpConstructor* regExpConstructor = exec->lexicalGlobalObject()->regExpConstructor();173 RegExpConstructor* regExpConstructor = globalObject->regExpConstructor(); 174 174 String input = string->value(exec); 175 VM& vm = exec->vm();175 VM& vm = globalObject->vm(); 176 176 if (!regExp->global()) 177 177 return regExpConstructor->performMatch(vm, regExp, string, input, 0); -
trunk/Source/JavaScriptCore/runtime/RegExpObject.h
r197640 r197641 67 67 } 68 68 69 bool test(ExecState* exec, JS String* string) { return match(exec, string); }70 JSValue exec(ExecState*, JS String*);69 bool test(ExecState* exec, JSGlobalObject* globalObject, JSString* string) { return match(exec, globalObject, string); } 70 JSValue exec(ExecState*, JSGlobalObject*, JSString*); 71 71 72 72 static bool getOwnPropertySlot(JSObject*, ExecState*, PropertyName, PropertySlot&); … … 103 103 104 104 private: 105 MatchResult match(ExecState*, JS String*);105 MatchResult match(ExecState*, JSGlobalObject*, JSString*); 106 106 107 107 WriteBarrier<RegExp> m_regExp; -
trunk/Source/JavaScriptCore/runtime/RegExpPrototype.cpp
r197485 r197641 1 1 /* 2 2 * Copyright (C) 1999-2000 Harri Porten (porten@kde.org) 3 * Copyright (C) 2003, 2007, 2008 Apple Inc. All Rights Reserved.3 * Copyright (C) 2003, 2007, 2008, 2016 Apple Inc. All Rights Reserved. 4 4 * 5 5 * This library is free software; you can redistribute it and/or … … 103 103 if (!string) 104 104 return JSValue::encode(jsUndefined()); 105 return JSValue::encode(jsBoolean(asRegExpObject(thisValue)->test(exec, string)));105 return JSValue::encode(jsBoolean(asRegExpObject(thisValue)->test(exec, exec->lexicalGlobalObject(), string))); 106 106 } 107 107 … … 114 114 if (!string) 115 115 return JSValue::encode(jsUndefined()); 116 return JSValue::encode(asRegExpObject(thisValue)->exec(exec, string));116 return JSValue::encode(asRegExpObject(thisValue)->exec(exec, exec->lexicalGlobalObject(), string)); 117 117 } 118 118 -
trunk/Source/JavaScriptCore/runtime/StringPrototype.cpp
r197614 r197641 1036 1036 JSString* string = thisValue.toString(exec); 1037 1037 String s = string->value(exec); 1038 VM* vm = &exec->vm(); 1038 JSGlobalObject* globalObject = exec->lexicalGlobalObject(); 1039 VM* vm = &globalObject->vm(); 1039 1040 1040 1041 JSValue a0 = exec->argument(0); … … 1068 1069 return throwVMError(exec, createSyntaxError(exec, regExp->errorMessage())); 1069 1070 } 1070 RegExpConstructor* regExpConstructor = exec->lexicalGlobalObject()->regExpConstructor();1071 RegExpConstructor* regExpConstructor = globalObject->regExpConstructor(); 1071 1072 MatchResult result = regExpConstructor->performMatch(*vm, regExp, string, s, 0); 1072 1073 // case without 'g' flag is handled like RegExp.prototype.exec 1073 1074 if (!global) 1074 return JSValue::encode(result ? createRegExpMatchesArray(exec, string, regExp, result) : jsNull());1075 return JSValue::encode(result ? createRegExpMatchesArray(exec, globalObject, string, regExp, result) : jsNull()); 1075 1076 1076 1077 // return array of matches -
trunk/Source/JavaScriptCore/runtime/Structure.cpp
r197539 r197641 1 1 /* 2 * Copyright (C) 2008, 2009, 2013-201 5Apple Inc. All rights reserved.2 * Copyright (C) 2008, 2009, 2013-2016 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 444 444 } 445 445 446 Structure* Structure::addPropertyTransition(VM& vm, Structure* structure, PropertyName propertyName, unsigned attributes, PropertyOffset& offset, PutPropertySlot::Context context, DeferredStructureTransitionWatchpointFire* deferred) 446 Structure* Structure::addPropertyTransition(VM& vm, Structure* structure, PropertyName propertyName, unsigned attributes, PropertyOffset& offset) 447 { 448 Structure* newStructure = addPropertyTransitionToExistingStructure( 449 structure, propertyName, attributes, offset); 450 if (newStructure) 451 return newStructure; 452 453 return addNewPropertyTransition( 454 vm, structure, propertyName, attributes, offset, PutPropertySlot::UnknownContext); 455 } 456 457 Structure* Structure::addNewPropertyTransition(VM& vm, Structure* structure, PropertyName propertyName, unsigned attributes, PropertyOffset& offset, PutPropertySlot::Context context, DeferredStructureTransitionWatchpointFire* deferred) 447 458 { 448 459 ASSERT(!structure->isDictionary()); -
trunk/Source/JavaScriptCore/runtime/Structure.h
r197563 r197641 169 169 static void dumpStatistics(); 170 170 171 JS_EXPORT_PRIVATE static Structure* addPropertyTransition(VM&, Structure*, PropertyName, unsigned attributes, PropertyOffset&, PutPropertySlot::Context = PutPropertySlot::UnknownContext, DeferredStructureTransitionWatchpointFire* = nullptr); 171 JS_EXPORT_PRIVATE static Structure* addPropertyTransition(VM&, Structure*, PropertyName, unsigned attributes, PropertyOffset&); 172 JS_EXPORT_PRIVATE static Structure* addNewPropertyTransition(VM&, Structure*, PropertyName, unsigned attributes, PropertyOffset&, PutPropertySlot::Context = PutPropertySlot::UnknownContext, DeferredStructureTransitionWatchpointFire* = nullptr); 172 173 static Structure* addPropertyTransitionToExistingStructureConcurrently(Structure*, UniquedStringImpl* uid, unsigned attributes, PropertyOffset&); 173 174 JS_EXPORT_PRIVATE static Structure* addPropertyTransitionToExistingStructure(Structure*, PropertyName, unsigned attributes, PropertyOffset&); … … 246 247 247 248 JSGlobalObject* globalObject() const { return m_globalObject.get(); } 249 250 // NOTE: This method should only be called during the creation of structures, since the global 251 // object of a structure is presumed to be immutable in a bunch of places. 248 252 void setGlobalObject(VM& vm, JSGlobalObject* globalObject) { m_globalObject.set(vm, this, globalObject); } 249 253
Note:
See TracChangeset
for help on using the changeset viewer.