⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 254558 in webkit


Ignore:
Timestamp:
Jan 14, 2020, 10:02:48 PM (7 years ago)
Author:
commit-queue@webkit.org
Message:

Unreviewed, rolling out r254480, r254496, and r254517.
​https://bugs.webkit.org/show_bug.cgi?id=206278

"It regressed JetStream2 and Speedometer2" (Requested by
saamyjoon on #webkit).

Reverted changesets:

"Throw away baseline code if there is an optimized
replacement"
​https://bugs.webkit.org/show_bug.cgi?id=202503
​https://trac.webkit.org/changeset/254480

"Unreviewed. Change useLLInt=0 to forceBaseline=1"
​https://trac.webkit.org/changeset/254496

"Add an option that enables/disables throwing away baseline
JIT code"
​https://bugs.webkit.org/show_bug.cgi?id=206244
​https://trac.webkit.org/changeset/254517

Location:
trunk
Files:
26 edited

Legend:

Unmodified
Added
Removed
  • trunk/JSTests/ChangeLog

    r254496 r254558  
     12020-01-14  Commit Queue  <commit-queue@webkit.org>
     2
     3        Unreviewed, rolling out r254480, r254496, and r254517.
     4        https://bugs.webkit.org/show_bug.cgi?id=206278
     5
     6        "It regressed JetStream2 and Speedometer2" (Requested by
     7        saamyjoon on #webkit).
     8
     9        Reverted changesets:
     10
     11        "Throw away baseline code if there is an optimized
     12        replacement"
     13        https://bugs.webkit.org/show_bug.cgi?id=202503
     14        https://trac.webkit.org/changeset/254480
     15
     16        "Unreviewed. Change useLLInt=0 to forceBaseline=1"
     17        https://trac.webkit.org/changeset/254496
     18
     19        "Add an option that enables/disables throwing away baseline
     20        JIT code"
     21        https://bugs.webkit.org/show_bug.cgi?id=206244
     22        https://trac.webkit.org/changeset/254517
     23
    1242020-01-13  Saam Barati  <sbarati@apple.com>
    225
  • trunk/JSTests/stress/dfg-compare-eq-via-nonSpeculativeNonPeepholeCompareNullOrUndefined.js

    r254480 r254558  
    1 //@ runDefault("--collectContinuously=true", "--collectContinuouslyPeriodMS=0.15", "--forceBaseline=true", "--useFTLJIT=false", "--jitPolicyScale=0")
     1//@ runDefault("--collectContinuously=true", "--collectContinuouslyPeriodMS=0.15", "--useLLInt=false", "--useFTLJIT=false", "--jitPolicyScale=0")
    22
    33// This test exercises DFG::SpeculativeJIT::nonSpeculativeNonPeepholeCompareNullOrUndefined().
  • trunk/JSTests/stress/getter-setter-inlining-should-emit-movhint.js

    r254480 r254558  
    1 //@ runDefault("--useRandomizingFuzzerAgent=1", "--usePolymorphicCallInliningForNonStubStatus=1", "--seedOfRandomizingFuzzerAgent=2896922505", "--forceBaseline=1", "--useConcurrentJIT=0")
     1//@ runDefault("--useRandomizingFuzzerAgent=1", "--usePolymorphicCallInliningForNonStubStatus=1", "--seedOfRandomizingFuzzerAgent=2896922505", "--useLLInt=0", "--useConcurrentJIT=0")
    22function foo(o) {
    33    o.f = 0;
  • trunk/JSTests/stress/make-dictionary-repatch.js

    r254480 r254558  
    1 //@ if $jitTests then runNoCJIT("--useDFGJIT=false", "--forceBaseline=true") else skip end
     1//@ if $jitTests then runNoCJIT("--useDFGJIT=false", "--useLLInt=false") else skip end
    22
    33function foo(o) {
  • trunk/JSTests/stress/merging-ic-variants-should-bail-if-structures-overlap.js

    r254480 r254558  
    1 //@ runDefault("--validateGraphAtEachPhase=1", "--forceBaseline=1")
     1//@ runDefault("--validateGraphAtEachPhase=1", "--useLLInt=0")
    22
    33let items = [];
  • trunk/JSTests/stress/proxy-getter-stack-overflow.js

    r254480 r254558  
    1 //@ if $jitTests then runDefault("--forceBaseline=1") else skip end
     1//@ if $jitTests then runDefault("--useLLInt=0") else skip end
    22
    33const o = {};
  • trunk/JSTests/stress/racy-gc-cleanup-of-identifier-after-mutator-stops-running.js

    r254496 r254558  
    1 //@ runDefault("--numberOfGCMarkers=1", "--useDFGJIT=false", "--forceBaseline=true")
     1//@ runDefault("--numberOfGCMarkers=1", "--useDFGJIT=false", "--useLLInt=false")
    22
    33function foo() {
  • trunk/JSTests/stress/regress-192717.js

    r254480 r254558  
    11//@ skip if $memoryLimited or $buildType == "debug"
    2 //@ runDefault("--forceBaseline=true", "--forceCodeBlockToJettisonDueToOldAge=true", "--maxPerThreadStackUsage=200000", "--exceptionStackTraceLimit=1", "--defaultErrorStackTraceLimit=1")
     2//@ runDefault("--useLLInt=false", "--forceCodeBlockToJettisonDueToOldAge=true", "--maxPerThreadStackUsage=200000", "--exceptionStackTraceLimit=1", "--defaultErrorStackTraceLimit=1")
    33
    44let foo = 'let a';
  • trunk/JSTests/stress/retry-cache-later.js

    r254480 r254558  
    1 //@ runNoCJIT("--forceBaseline=true", "--useDFGJIT=false")
     1//@ runNoCJIT("--useLLInt=false", "--useDFGJIT=false")
    22
    33function foo(o) {
  • trunk/Source/JavaScriptCore/API/tests/ExecutionTimeLimitTest.cpp

    r254514 r254558  
    120120{
    121121    static const TierOptions tierOptionsList[] = {
    122         { "LLINT",    0_ms,   "--useConcurrentJIT=false --useJIT=false" },
    123         { "Baseline", 0_ms,   "--useConcurrentJIT=false --useJIT=true --useDFGJIT=false" },
    124         { "DFG",      200_ms,   "--useConcurrentJIT=false --useJIT=true --useDFGJIT=true --useFTLJIT=false" },
     122        { "LLINT",    0_ms,   "--useConcurrentJIT=false --useLLInt=true --useJIT=false" },
     123        { "Baseline", 0_ms,   "--useConcurrentJIT=false --useLLInt=true --useJIT=true --useDFGJIT=false" },
     124        { "DFG",      200_ms,   "--useConcurrentJIT=false --useLLInt=true --useJIT=true --useDFGJIT=true --useFTLJIT=false" },
    125125#if ENABLE(FTL_JIT)
    126         { "FTL",      500_ms, "--useConcurrentJIT=false --useJIT=true --useDFGJIT=true --useFTLJIT=true" },
     126        { "FTL",      500_ms, "--useConcurrentJIT=false --useLLInt=true --useJIT=true --useDFGJIT=true --useFTLJIT=true" },
    127127#endif
    128128    };
  • trunk/Source/JavaScriptCore/API/tests/PingPongStackOverflowTest.cpp

    r254480 r254558  
    123123    auto origSoftReservedZoneSize = Options::softReservedZoneSize();
    124124    auto origReservedZoneSize = Options::reservedZoneSize();
    125     auto origForceBaseline = Options::forceBaseline();
     125    auto origUseLLInt = Options::useLLInt();
    126126    auto origMaxPerThreadStackUsage = Options::maxPerThreadStackUsage();
    127127
    … …  
    132132    // reproducing the regression in https://bugs.webkit.org/show_bug.cgi?id=148749. However, we only
    133133    // want to do this if the LLINT isn't the only available execution engine.
    134     Options::forceBaseline() = true;
     134    Options::useLLInt() = false;
    135135#endif
    136136
    … …  
    179179    Options::softReservedZoneSize() = origSoftReservedZoneSize;
    180180    Options::reservedZoneSize() = origReservedZoneSize;
    181     Options::forceBaseline() = origForceBaseline;
     181    Options::useLLInt() = origUseLLInt;
    182182    Options::maxPerThreadStackUsage() = origMaxPerThreadStackUsage;
    183183
  • trunk/Source/JavaScriptCore/ChangeLog

    r254549 r254558  
     12020-01-14  Commit Queue  <commit-queue@webkit.org>
     2
     3        Unreviewed, rolling out r254480, r254496, and r254517.
     4        https://bugs.webkit.org/show_bug.cgi?id=206278
     5
     6        "It regressed JetStream2 and Speedometer2" (Requested by
     7        saamyjoon on #webkit).
     8
     9        Reverted changesets:
     10
     11        "Throw away baseline code if there is an optimized
     12        replacement"
     13        https://bugs.webkit.org/show_bug.cgi?id=202503
     14        https://trac.webkit.org/changeset/254480
     15
     16        "Unreviewed. Change useLLInt=0 to forceBaseline=1"
     17        https://trac.webkit.org/changeset/254496
     18
     19        "Add an option that enables/disables throwing away baseline
     20        JIT code"
     21        https://bugs.webkit.org/show_bug.cgi?id=206244
     22        https://trac.webkit.org/changeset/254517
     23
    1242020-01-14  Keith Miller  <keith_miller@apple.com>
    225
  • trunk/Source/JavaScriptCore/bytecode/CodeBlock.cpp

    r254517 r254558  
    443443                HandlerInfo& handler = m_rareData->m_exceptionHandlers[i];
    444444#if ENABLE(JIT)
    445                 auto& instruction = *instructions().at(unlinkedHandler.target).ptr();
    446                 MacroAssemblerCodePtr<BytecodePtrTag> codePtr = LLInt::getCodePtr<BytecodePtrTag>(instruction);
     445                auto instruction = instructions().at(unlinkedHandler.target);
     446                MacroAssemblerCodePtr<BytecodePtrTag> codePtr;
     447                if (instruction->isWide32())
     448                    codePtr = LLInt::getWide32CodePtr<BytecodePtrTag>(op_catch);
     449                else if (instruction->isWide16())
     450                    codePtr = LLInt::getWide16CodePtr<BytecodePtrTag>(op_catch);
     451                else
     452                    codePtr = LLInt::getCodePtr<BytecodePtrTag>(op_catch);
    447453                handler.initialize(unlinkedHandler, CodeLocationLabel<ExceptionHandlerPtrTag>(codePtr.retagged<ExceptionHandlerPtrTag>()));
    448454#else
    … …  
    13831389
    13841390    updateAllPredictions();
    1385 
    1386 #if ENABLE(JIT)
    1387     // If BaselineJIT code is not executing, and an optimized replacement exists, we attempt
    1388     // to discard baseline JIT code and reinstall LLInt code to save JIT memory.
    1389     if (!Options::forceBaseline() && Options::enableThrowingAwayBaselineCode() && jitType() == JITType::BaselineJIT && !m_vm->heap.codeBlockSet().isCurrentlyExecuting(this)) {
    1390         if (CodeBlock* optimizedCodeBlock = optimizedReplacement()) {
    1391             if (!optimizedCodeBlock->m_osrExitCounter) {
    1392                 m_jitCode = nullptr;
    1393                 LLInt::setEntrypoint(this);
    1394                 RELEASE_ASSERT(jitType() == JITType::InterpreterThunk);
    1395 
    1396                 for (size_t i = 0; i < m_unlinkedCode->numberOfExceptionHandlers(); i++) {
    1397                     const UnlinkedHandlerInfo& unlinkedHandler = m_unlinkedCode->exceptionHandler(i);
    1398                     HandlerInfo& handler = m_rareData->m_exceptionHandlers[i];
    1399                     auto& instruction = *instructions().at(unlinkedHandler.target).ptr();
    1400                     MacroAssemblerCodePtr<BytecodePtrTag> codePtr = LLInt::getCodePtr<BytecodePtrTag>(instruction);
    1401                     handler.initialize(unlinkedHandler, CodeLocationLabel<ExceptionHandlerPtrTag>(codePtr.retagged<ExceptionHandlerPtrTag>()));
    1402                 }
    1403 
    1404                 unlinkIncomingCalls();
    1405 
    1406                 // It's safe to clear these out here because in finalizeUnconditionally all compiler threads
    1407                 // are safepointed, meaning they're running either before or after bytecode parser, and bytecode
    1408                 // parser is the only data structure pointing into the various *infos.
    1409                 resetJITData();
    1410             }
    1411         }
    1412     }
    1413 
    1414 #endif
    14151391   
    14161392    if (JITCode::couldBeInterpreted(jitType()))
    … …  
    15401516}
    15411517
     1518StructureStubInfo* CodeBlock::findStubInfo(CodeOrigin codeOrigin)
     1519{
     1520    ConcurrentJSLocker locker(m_lock);
     1521    if (auto* jitData = m_jitData.get()) {
     1522        for (StructureStubInfo* stubInfo : jitData->m_stubInfos) {
     1523            if (stubInfo->codeOrigin == codeOrigin)
     1524                return stubInfo;
     1525        }
     1526    }
     1527    return nullptr;
     1528}
     1529
    15421530ByValInfo* CodeBlock::addByValInfo()
    15431531{
    … …  
    15501538    ConcurrentJSLocker locker(m_lock);
    15511539    return ensureJITData(locker).m_callLinkInfos.add();
     1540}
     1541
     1542CallLinkInfo* CodeBlock::getCallLinkInfoForBytecodeIndex(BytecodeIndex index)
     1543{
     1544    ConcurrentJSLocker locker(m_lock);
     1545    if (auto* jitData = m_jitData.get()) {
     1546        for (CallLinkInfo* callLinkInfo : jitData->m_callLinkInfos) {
     1547            if (callLinkInfo->codeOrigin() == CodeOrigin(index))
     1548                return callLinkInfo;
     1549        }
     1550    }
     1551    return nullptr;
    15521552}
    15531553
    … …  
    15991599        // link infos, or by val infos if we don't have JIT code. Attempts to query these data
    16001600        // structures using the concurrent API (getICStatusMap and friends) will return nothing if we
    1601         // don't have JIT code. So it's safe to call this if we fail a baseline JIT compile.
    1602         //
    1603         // We also call this from finalizeUnconditionally when we degrade from baseline JIT to LLInt
    1604         // code. This is safe to do since all compiler threads are safepointed in finalizeUnconditionally,
    1605         // which means we've made it past bytecode parsing. Only the bytecode parser will hold onto
    1606         // references to these various *infos via its use of ICStatusMap.
    1607 
    1608         for (StructureStubInfo* stubInfo : jitData->m_stubInfos) {
    1609             stubInfo->aboutToDie();
    1610             stubInfo->deref();
    1611         }
    1612 
     1601        // don't have JIT code.
     1602        jitData->m_stubInfos.clear();
     1603        jitData->m_callLinkInfos.clear();
     1604        jitData->m_byValInfos.clear();
    16131605        // We can clear this because the DFG's queries to these data structures are guarded by whether
    16141606        // there is JIT code.
    1615 
    1616         m_jitData = nullptr;
     1607        jitData->m_rareCaseProfiles.clear();
    16171608    }
    16181609}
    … …  
    17461737
    17471738#if ENABLE(JIT)
    1748 CodeBlock* CodeBlock::optimizedReplacement(JITType typeToReplace)
     1739bool CodeBlock::hasOptimizedReplacement(JITType typeToReplace)
    17491740{
    17501741    CodeBlock* replacement = this->replacement();
    1751     if (!replacement)
    1752         return nullptr;
    1753     if (JITCode::isHigherTier(replacement->jitType(), typeToReplace))
    1754         return replacement;
    1755     return nullptr;
    1756 }
    1757 
    1758 CodeBlock* CodeBlock::optimizedReplacement()
    1759 {
    1760     return optimizedReplacement(jitType());
    1761 }
    1762 
    1763 bool CodeBlock::hasOptimizedReplacement(JITType typeToReplace)
    1764 {
    1765     return !!optimizedReplacement(typeToReplace);
     1742    return replacement && JITCode::isHigherTier(replacement->jitType(), typeToReplace);
    17661743}
    17671744
    … …  
    28252802{
    28262803    ASSERT(JITCode::isOptimizingJIT(jitType()));
    2827     ASSERT(JITCode::isBaselineCode(alternative()->jitType()));
     2804    ASSERT(alternative()->jitType() == JITType::BaselineJIT);
    28282805   
    28292806    CodeBlock* profiledBlock = alternative();
  • trunk/Source/JavaScriptCore/bytecode/CodeBlock.h

    r254480 r254558  
    259259    Optional<BytecodeIndex> bytecodeIndexFromCallSiteIndex(CallSiteIndex);
    260260
    261     // Because we might throw out baseline JIT code and all its baseline JIT data (m_jitData),
    262     // you need to be careful about the lifetime of when you use the return value of this function.
    263     // The return value may have raw pointers into this data structure that gets thrown away.
    264     // Specifically, you need to ensure that no GC can be finalized (typically that means no
    265     // allocations) between calling this and the last use of it.
    266261    void getICStatusMap(const ConcurrentJSLocker&, ICStatusMap& result);
    267262    void getICStatusMap(ICStatusMap& result);
    … …  
    283278        std::unique_ptr<PCToCodeOriginMap> m_pcToCodeOriginMap;
    284279        std::unique_ptr<RegisterAtOffsetList> m_calleeSaveRegisters;
    285         // FIXME: Now that we unconditionally OSR exit to the LLInt, we might be able to prune
    286         // the number of entries we have in this to contain entries only for opcodes we use
    287         // it for. Today, that's only for loop OSR entry.
    288         // https://bugs.webkit.org/show_bug.cgi?id=206207
    289280        JITCodeMap m_jitCodeMap;
    290281    };
    … …  
    317308    StructureStubInfo* addStubInfo(AccessType);
    318309
     310    // O(n) operation. Use getStubInfoMap() unless you really only intend to get one
     311    // stub info.
     312    StructureStubInfo* findStubInfo(CodeOrigin);
     313
    319314    ByValInfo* addByValInfo();
    320315
    321316    CallLinkInfo* addCallLinkInfo();
     317
     318    // This is a slow function call used primarily for compiling OSR exits in the case
     319    // that there had been inlining. Chances are if you want to use this, you're really
     320    // looking for a CallLinkInfoMap to amortize the cost of calling this.
     321    CallLinkInfo* getCallLinkInfoForBytecodeIndex(BytecodeIndex);
    322322   
    323323    void setJITCodeMap(JITCodeMap&& jitCodeMap)
    … …  
    413413    void setJITCode(Ref<JITCode>&& code)
    414414    {
     415        ASSERT(heap()->isDeferred());
    415416        if (!code->isShared())
    416417            heap()->reportExtraMemoryAllocated(code->size());
    … …  
    444445    DFG::CapabilityLevel capabilityLevelState() { return static_cast<DFG::CapabilityLevel>(m_capabilityLevelState); }
    445446
    446     CodeBlock* optimizedReplacement(JITType typeToReplace);
    447     CodeBlock* optimizedReplacement(); // the typeToReplace is my JITType
    448447    bool hasOptimizedReplacement(JITType typeToReplace);
    449448    bool hasOptimizedReplacement(); // the typeToReplace is my JITType
  • trunk/Source/JavaScriptCore/dfg/DFGDriver.cpp

    r254480 r254558  
    8282    ASSERT(codeBlock);
    8383    ASSERT(codeBlock->alternative());
    84     ASSERT(JITCode::isBaselineCode(codeBlock->alternative()->jitType()));
     84    ASSERT(codeBlock->alternative()->jitType() == JITType::BaselineJIT);
    8585    ASSERT(!profiledDFGCodeBlock || profiledDFGCodeBlock->jitType() == JITType::DFGJIT);
    8686   
  • trunk/Source/JavaScriptCore/dfg/DFGOSRExitCompilerCommon.cpp

    r254480 r254558  
    143143}
    144144
    145 static MacroAssemblerCodePtr<JSEntryPtrTag> callerReturnPC(CodeBlock* baselineCodeBlockForCaller, BytecodeIndex callBytecodeIndex, InlineCallFrame::Kind trueCallerCallKind)
    146 {
     145MacroAssemblerCodePtr<JSEntryPtrTag> callerReturnPC(CodeBlock* baselineCodeBlockForCaller, BytecodeIndex callBytecodeIndex, InlineCallFrame::Kind trueCallerCallKind, bool& callerIsLLInt)
     146{
     147    callerIsLLInt = Options::forceOSRExitToLLInt() || baselineCodeBlockForCaller->jitType() == JITType::InterpreterThunk;
     148
    147149    if (callBytecodeIndex.checkpoint())
    148150        return LLInt::getCodePtr<JSEntryPtrTag>(checkpoint_osr_exit_from_inlined_call_trampoline);
    … …  
    150152    MacroAssemblerCodePtr<JSEntryPtrTag> jumpTarget;
    151153
    152     const Instruction& callInstruction = *baselineCodeBlockForCaller->instructions().at(callBytecodeIndex).ptr();
     154    if (callerIsLLInt) {
     155        const Instruction& callInstruction = *baselineCodeBlockForCaller->instructions().at(callBytecodeIndex).ptr();
    153156#define LLINT_RETURN_LOCATION(name) (callInstruction.isWide16() ? LLInt::getWide16CodePtr<JSEntryPtrTag>(name##_return_location) : (callInstruction.isWide32() ? LLInt::getWide32CodePtr<JSEntryPtrTag>(name##_return_location) : LLInt::getCodePtr<JSEntryPtrTag>(name##_return_location)))
    154157
    155     switch (trueCallerCallKind) {
    156     case InlineCallFrame::Call:
    157         jumpTarget = LLINT_RETURN_LOCATION(op_call);
    158         break;
    159     case InlineCallFrame::Construct:
    160         jumpTarget = LLINT_RETURN_LOCATION(op_construct);
    161         break;
    162     case InlineCallFrame::CallVarargs:
    163         jumpTarget = LLINT_RETURN_LOCATION(op_call_varargs_slow);
    164         break;
    165     case InlineCallFrame::ConstructVarargs:
    166         jumpTarget = LLINT_RETURN_LOCATION(op_construct_varargs_slow);
    167         break;
    168     case InlineCallFrame::GetterCall: {
    169         if (callInstruction.opcodeID() == op_get_by_id)
    170             jumpTarget = LLINT_RETURN_LOCATION(op_get_by_id);
    171         else if (callInstruction.opcodeID() == op_get_by_val)
    172             jumpTarget = LLINT_RETURN_LOCATION(op_get_by_val);
    173         else
     158        switch (trueCallerCallKind) {
     159        case InlineCallFrame::Call:
     160            jumpTarget = LLINT_RETURN_LOCATION(op_call);
     161            break;
     162        case InlineCallFrame::Construct:
     163            jumpTarget = LLINT_RETURN_LOCATION(op_construct);
     164            break;
     165        case InlineCallFrame::CallVarargs:
     166            jumpTarget = LLINT_RETURN_LOCATION(op_call_varargs_slow);
     167            break;
     168        case InlineCallFrame::ConstructVarargs:
     169            jumpTarget = LLINT_RETURN_LOCATION(op_construct_varargs_slow);
     170            break;
     171        case InlineCallFrame::GetterCall: {
     172            if (callInstruction.opcodeID() == op_get_by_id)
     173                jumpTarget = LLINT_RETURN_LOCATION(op_get_by_id);
     174            else if (callInstruction.opcodeID() == op_get_by_val)
     175                jumpTarget = LLINT_RETURN_LOCATION(op_get_by_val);
     176            else
     177                RELEASE_ASSERT_NOT_REACHED();
     178            break;
     179        }
     180        case InlineCallFrame::SetterCall: {
     181            if (callInstruction.opcodeID() == op_put_by_id)
     182                jumpTarget = LLINT_RETURN_LOCATION(op_put_by_id);
     183            else if (callInstruction.opcodeID() == op_put_by_val)
     184                jumpTarget = LLINT_RETURN_LOCATION(op_put_by_val);
     185            else
     186                RELEASE_ASSERT_NOT_REACHED();
     187            break;
     188        }
     189        default:
    174190            RELEASE_ASSERT_NOT_REACHED();
    175         break;
    176     }
    177     case InlineCallFrame::SetterCall: {
    178         if (callInstruction.opcodeID() == op_put_by_id)
    179             jumpTarget = LLINT_RETURN_LOCATION(op_put_by_id);
    180         else if (callInstruction.opcodeID() == op_put_by_val)
    181             jumpTarget = LLINT_RETURN_LOCATION(op_put_by_val);
    182         else
     191        }
     192
     193#undef LLINT_RETURN_LOCATION
     194
     195    } else {
     196        switch (trueCallerCallKind) {
     197        case InlineCallFrame::Call:
     198        case InlineCallFrame::Construct:
     199        case InlineCallFrame::CallVarargs:
     200        case InlineCallFrame::ConstructVarargs: {
     201            CallLinkInfo* callLinkInfo =
     202                baselineCodeBlockForCaller->getCallLinkInfoForBytecodeIndex(callBytecodeIndex);
     203            RELEASE_ASSERT(callLinkInfo);
     204
     205            jumpTarget = callLinkInfo->callReturnLocation().retagged<JSEntryPtrTag>();
     206            break;
     207        }
     208
     209        case InlineCallFrame::GetterCall:
     210        case InlineCallFrame::SetterCall: {
     211            StructureStubInfo* stubInfo =
     212                baselineCodeBlockForCaller->findStubInfo(CodeOrigin(callBytecodeIndex));
     213            RELEASE_ASSERT(stubInfo);
     214
     215            jumpTarget = stubInfo->doneLocation.retagged<JSEntryPtrTag>();
     216            break;
     217        }
     218
     219        default:
    183220            RELEASE_ASSERT_NOT_REACHED();
    184         break;
    185     }
    186     default:
    187         RELEASE_ASSERT_NOT_REACHED();
    188     }
    189 
    190 #undef LLINT_RETURN_LOCATION
     221        }
     222    }
    191223
    192224    return jumpTarget;
    … …  
    222254        CodeOrigin* trueCaller = inlineCallFrame->getCallerSkippingTailCalls(&trueCallerCallKind);
    223255        GPRReg callerFrameGPR = GPRInfo::callFrameRegister;
     256
     257        bool callerIsLLInt = false;
    224258
    225259        if (!trueCaller) {
    … …  
    238272            CodeBlock* baselineCodeBlockForCaller = jit.baselineCodeBlockFor(*trueCaller);
    239273            auto callBytecodeIndex = trueCaller->bytecodeIndex();
    240             MacroAssemblerCodePtr<JSEntryPtrTag> jumpTarget = callerReturnPC(baselineCodeBlockForCaller, callBytecodeIndex, trueCallerCallKind);
     274            MacroAssemblerCodePtr<JSEntryPtrTag> jumpTarget = callerReturnPC(baselineCodeBlockForCaller, callBytecodeIndex, trueCallerCallKind, callerIsLLInt);
    241275
    242276            if (trueCaller->inlineCallFrame()) {
    … …  
    269303            GPRInfo::regT2);
    270304
    271         if (trueCaller) {
    272             // Set up LLInt registers for our caller in our callee saves.
     305        if (callerIsLLInt) {
    273306            CodeBlock* baselineCodeBlockForCaller = jit.baselineCodeBlockFor(*trueCaller);
    274307            jit.storePtr(CCallHelpers::TrustedImmPtr(baselineCodeBlockForCaller->metadataTable()), calleeSaveSlot(inlineCallFrame, baselineCodeBlock, LLInt::Registers::metadataTableGPR));
    … …  
    356389    ASSERT(JITCode::isBaselineCode(codeBlockForExit->jitType()));
    357390
    358     auto bytecodeIndex = exit.m_codeOrigin.bytecodeIndex();
    359     const Instruction& currentInstruction = *codeBlockForExit->instructions().at(bytecodeIndex).ptr();
    360     MacroAssemblerCodePtr<JSEntryPtrTag> destination;
    361     if (bytecodeIndex.checkpoint())
    362         destination = LLInt::getCodePtr<JSEntryPtrTag>(checkpoint_osr_exit_trampoline);
    363     else
    364         destination = LLInt::getCodePtr<JSEntryPtrTag>(currentInstruction);
    365 
    366     if (exit.isExceptionHandler()) {
    367         jit.move(CCallHelpers::TrustedImmPtr(&currentInstruction), GPRInfo::regT2);
    368         jit.storePtr(GPRInfo::regT2, &vm.targetInterpreterPCForThrow);
    369     }
    370 
    371     jit.move(CCallHelpers::TrustedImmPtr(codeBlockForExit->metadataTable()), LLInt::Registers::metadataTableGPR);
     391    void* jumpTarget;
     392    bool exitToLLInt = Options::forceOSRExitToLLInt() || codeBlockForExit->jitType() == JITType::InterpreterThunk;
     393    if (exitToLLInt) {
     394        auto bytecodeIndex = exit.m_codeOrigin.bytecodeIndex();
     395        const Instruction& currentInstruction = *codeBlockForExit->instructions().at(bytecodeIndex).ptr();
     396        MacroAssemblerCodePtr<JSEntryPtrTag> destination;
     397        if (bytecodeIndex.checkpoint())
     398            destination = LLInt::getCodePtr<JSEntryPtrTag>(checkpoint_osr_exit_trampoline);
     399        else
     400            destination = LLInt::getCodePtr<JSEntryPtrTag>(currentInstruction);
     401
     402        if (exit.isExceptionHandler()) {
     403            jit.move(CCallHelpers::TrustedImmPtr(&currentInstruction), GPRInfo::regT2);
     404            jit.storePtr(GPRInfo::regT2, &vm.targetInterpreterPCForThrow);
     405        }
     406
     407        jit.move(CCallHelpers::TrustedImmPtr(codeBlockForExit->metadataTable()), LLInt::Registers::metadataTableGPR);
    372408#if USE(JSVALUE64)
    373     jit.move(CCallHelpers::TrustedImmPtr(codeBlockForExit->instructionsRawPointer()), LLInt::Registers::pbGPR);
    374     jit.move(CCallHelpers::TrustedImm32(bytecodeIndex.offset()), LLInt::Registers::pcGPR);
     409        jit.move(CCallHelpers::TrustedImmPtr(codeBlockForExit->instructionsRawPointer()), LLInt::Registers::pbGPR);
     410        jit.move(CCallHelpers::TrustedImm32(bytecodeIndex.offset()), LLInt::Registers::pcGPR);
    375411#else
    376     jit.move(CCallHelpers::TrustedImmPtr(&currentInstruction), LLInt::Registers::pcGPR);
    377 #endif
     412        jit.move(CCallHelpers::TrustedImmPtr(&currentInstruction), LLInt::Registers::pcGPR);
     413#endif
     414        jumpTarget = destination.retagged<OSRExitPtrTag>().executableAddress();
     415    } else {
     416        BytecodeIndex exitIndex = exit.m_codeOrigin.bytecodeIndex();
     417        MacroAssemblerCodePtr<JSEntryPtrTag> destination;
     418        if (exitIndex.checkpoint())
     419            destination = LLInt::getCodePtr<JSEntryPtrTag>(checkpoint_osr_exit_trampoline);
     420        else {
     421            ASSERT(codeBlockForExit->bytecodeIndexForExit(exitIndex) == exitIndex);
     422            destination = codeBlockForExit->jitCodeMap().find(exitIndex);
     423        }
     424
     425        ASSERT(destination);
     426
     427        jumpTarget = destination.retagged<OSRExitPtrTag>().executableAddress();
     428    }
    378429
    379430    jit.addPtr(AssemblyHelpers::TrustedImm32(JIT::stackPointerOffsetFor(codeBlockForExit) * sizeof(Register)), GPRInfo::callFrameRegister, AssemblyHelpers::stackPointerRegister);
    … …  
    383434    }
    384435   
    385     jit.move(AssemblyHelpers::TrustedImmPtr(destination.retagged<OSRExitPtrTag>().executableAddress()), GPRInfo::regT2);
     436    jit.move(AssemblyHelpers::TrustedImmPtr(jumpTarget), GPRInfo::regT2);
    386437    jit.farJump(GPRInfo::regT2, OSRExitPtrTag);
    387438}
  • trunk/Source/JavaScriptCore/dfg/DFGOSRExitCompilerCommon.h

    r254480 r254558  
    4040void reifyInlinedCallFrames(CCallHelpers&, const OSRExitBase&);
    4141void adjustAndJumpToTarget(VM&, CCallHelpers&, const OSRExitBase&);
     42MacroAssemblerCodePtr<JSEntryPtrTag> callerReturnPC(CodeBlock* baselineCodeBlockForCaller, BytecodeIndex callBytecodeIndex, InlineCallFrame::Kind callerKind, bool& callerIsLLInt);
    4243CCallHelpers::Address calleeSaveSlot(InlineCallFrame*, CodeBlock* baselineCodeBlock, GPRReg calleeSave);
    4344
  • trunk/Source/JavaScriptCore/heap/CodeBlockSet.cpp

    r254480 r254558  
    5656}
    5757
    58 bool CodeBlockSet::isCurrentlyExecuting(CodeBlock* codeBlock)
    59 {
    60     return m_currentlyExecuting.contains(codeBlock);
    61 }
    62 
    6358void CodeBlockSet::dump(PrintStream& out) const
    6459{
  • trunk/Source/JavaScriptCore/heap/CodeBlockSet.h

    r254480 r254558  
    5757    Lock& getLock() { return m_lock; }
    5858
    59     // This is expected to run only when we're not adding to the set for now. If
    60     // this needs to run concurrently in the future, we'll need to lock around this.
    61     bool isCurrentlyExecuting(CodeBlock*);
    62 
    6359    // Visits each CodeBlock in the heap until the visitor function returns true
    6460    // to indicate that it is done iterating, or until every CodeBlock has been
  • trunk/Source/JavaScriptCore/heap/Heap.cpp

    r254480 r254558  
    614614    finalizeMarkedUnconditionalFinalizers<FunctionExecutable>(vm().functionExecutableSpace.space);
    615615    finalizeMarkedUnconditionalFinalizers<SymbolTable>(vm().symbolTableSpace);
    616     finalizeMarkedUnconditionalFinalizers<ExecutableToCodeBlockEdge>(vm().executableToCodeBlockEdgesWithFinalizers); // We run this before CodeBlock's unconditional finalizer since CodeBlock looks at the owner executable's installed CodeBlock in its finalizeUnconditionally.
    617616    vm().forEachCodeBlockSpace(
    618617        [&] (auto& space) {
    619618            this->finalizeMarkedUnconditionalFinalizers<CodeBlock>(space.set);
    620619        });
     620    finalizeMarkedUnconditionalFinalizers<ExecutableToCodeBlockEdge>(vm().executableToCodeBlockEdgesWithFinalizers);
    621621    finalizeMarkedUnconditionalFinalizers<StructureRareData>(vm().structureRareDataSpace);
    622622    finalizeMarkedUnconditionalFinalizers<UnlinkedFunctionExecutable>(vm().unlinkedFunctionExecutableSpace.set);
    … …  
    15231523    sweepArrayBuffers();
    15241524    snapshotUnswept();
    1525     finalizeUnconditionalFinalizers(); // We rely on these unconditional finalizers running before clearCurrentlyExecuting since CodeBlock's finalizer relies on querying currently executing.
     1525    finalizeUnconditionalFinalizers();
    15261526    removeDeadCompilerWorklistEntries();
    15271527    notifyIncrementalSweeper();
  • trunk/Source/JavaScriptCore/llint/LLIntSlowPaths.cpp

    r254480 r254558  
    19941994{
    19951995    RELEASE_ASSERT(!codeBlock->vm().exceptionForInspection());
    1996     const Instruction* nextPC = pc.next().ptr();
    1997     auto nextBytecode = LLInt::getCodePtr<JSEntryPtrTag>(*pc.next().ptr());
    1998     return encodeResult(nextPC, nextBytecode.executableAddress());
     1996    if (Options::forceOSRExitToLLInt() || codeBlock->jitType() == JITType::InterpreterThunk) {
     1997        const Instruction* nextPC = pc.next().ptr();
     1998        auto nextBytecode = LLInt::getCodePtr<JSEntryPtrTag>(*pc.next().ptr());
     1999        return encodeResult(nextPC, nextBytecode.executableAddress());
     2000    }
     2001
     2002#if ENABLE(JIT)
     2003    ASSERT(codeBlock->jitType() == JITType::BaselineJIT);
     2004    BytecodeIndex nextBytecodeIndex = pc.next().index();
     2005    auto nextBytecode = codeBlock->jitCodeMap().find(nextBytecodeIndex);
     2006    return encodeResult(nullptr, nextBytecode.executableAddress());
     2007#endif
     2008    RELEASE_ASSERT_NOT_REACHED();
    19992009}
    20002010
  • trunk/Source/JavaScriptCore/runtime/Options.cpp

    r254514 r254558  
    388388#endif
    389389#if !ENABLE(JIT)
    390     Options::forceBaseline() = false;
     390    Options::useLLInt() = true;
    391391    Options::useJIT() = false;
    392392    Options::useBaselineJIT() = false;
    … …  
    420420
    421421    if (!jitEnabledByDefault() && !Options::useJIT())
    422         Options::forceBaseline() = false;
     422        Options::useLLInt() = true;
    423423
    424424    if (!Options::useWebAssembly())
    … …  
    547547            RELEASE_ASSERT(Options::addressOfOption(gcMaxHeapSizeID) ==  &Options::gcMaxHeapSize());
    548548            RELEASE_ASSERT(Options::addressOfOptionDefault(gcMaxHeapSizeID) ==  &Options::gcMaxHeapSizeDefault());
     549            RELEASE_ASSERT(Options::addressOfOption(forceOSRExitToLLIntID) ==  &Options::forceOSRExitToLLInt());
     550            RELEASE_ASSERT(Options::addressOfOptionDefault(forceOSRExitToLLIntID) ==  &Options::forceOSRExitToLLIntDefault());
    549551
    550552#ifndef NDEBUG
    … …  
    944946{
    945947    bool coherent = true;
    946     if (forceBaseline() && !useJIT()) {
     948    if (!(useLLInt() || useJIT())) {
    947949        coherent = false;
    948         dataLog("INCOHERENT OPTIONS: forceBaseline can't be true if useJIT is false\n");
     950        dataLog("INCOHERENT OPTIONS: at least one of useLLInt or useJIT must be true\n");
    949951    }
    950952    if (!coherent)
  • trunk/Source/JavaScriptCore/runtime/OptionsList.h

    r254517 r254558  
    8282    v(OptionString, configFile, nullptr, Normal, "file to configure JSC options and logging location") \
    8383    \
    84     v(Bool, forceBaseline, false, Normal, "If true, we'll start running code in the baseline JIT and skip starting in the LLInt") \
     84    v(Bool, useLLInt,  true, Normal, "allows the LLINT to be used if true") \
    8585    v(Bool, useJIT, jitEnabledByDefault(), Normal, "allows the executable pages to be allocated for JIT and thunks if true") \
    8686    v(Bool, useBaselineJIT, true, Normal, "allows the baseline JIT to be used if true") \
    … …  
    495495    v(Double, dumpJITMemoryFlushInterval, 10, Restricted, "Maximum time in between flushes of the JIT memory dump in seconds.") \
    496496    v(Bool, useUnlinkedCodeBlockJettisoning, false, Normal, "If true, UnlinkedCodeBlock can be jettisoned.") \
     497    v(Bool, forceOSRExitToLLInt, false, Normal, "If true, we always exit to the LLInt. If false, we exit to whatever is most convenient.") \
    497498    v(Unsigned, getByValICMaxNumberOfIdentifiers, 4, Normal, "Number of identifiers we see in the LLInt that could cause us to bail on generating an IC for get_by_val.") \
    498     v(Bool, enableThrowingAwayBaselineCode, false, Normal, nullptr) \
    499499
    500500enum OptionEquivalence {
  • trunk/Source/JavaScriptCore/runtime/ScriptExecutable.cpp

    r254480 r254558  
    427427        codeBlock->validate();
    428428   
    429     if (Options::forceBaseline())
     429    if (Options::useLLInt())
     430        setupLLInt(codeBlock);
     431    else
    430432        setupJIT(vm, codeBlock);
    431     else
    432         setupLLInt(codeBlock);
    433433   
    434434    installCode(vm, codeBlock, codeBlock->codeType(), codeBlock->specializationKind());
  • trunk/Tools/ChangeLog

    r254556 r254558  
     12020-01-14  Commit Queue  <commit-queue@webkit.org>
     2
     3        Unreviewed, rolling out r254480, r254496, and r254517.
     4        https://bugs.webkit.org/show_bug.cgi?id=206278
     5
     6        "It regressed JetStream2 and Speedometer2" (Requested by
     7        saamyjoon on #webkit).
     8
     9        Reverted changesets:
     10
     11        "Throw away baseline code if there is an optimized
     12        replacement"
     13        https://bugs.webkit.org/show_bug.cgi?id=202503
     14        https://trac.webkit.org/changeset/254480
     15
     16        "Unreviewed. Change useLLInt=0 to forceBaseline=1"
     17        https://trac.webkit.org/changeset/254496
     18
     19        "Add an option that enables/disables throwing away baseline
     20        JIT code"
     21        https://bugs.webkit.org/show_bug.cgi?id=206244
     22        https://trac.webkit.org/changeset/254517
     23
    1242020-01-14  Chris Dumez  <cdumez@apple.com>
    225
  • trunk/Tools/Scripts/run-jsc-stress-tests

    r254480 r254558  
    499499B3O0_OPTIONS = ["--maxDFGNodesInBasicBlockForPreciseAnalysis=100", "--defaultB3OptLevel=0"]
    500500FTL_OPTIONS = ["--useFTLJIT=true"]
     501FORCE_LLINT_EXIT_OPTIONS = ["--forceOSRExitToLLInt=true"]
    501502
    502503require_relative "webkitruby/jsc-stress-test-writer-#{$testWriter}"
    … …  
    655656def runNoLLInt(*optionalTestSpecificOptions)
    656657    if $jitTests
    657         run("no-llint", "--forceBaseline=true", *optionalTestSpecificOptions)
     658        run("no-llint", "--useLLInt=false", *optionalTestSpecificOptions)
    658659    end
    659660end
    … …  
    708709
    709710def runFTLNoCJITB3O0(*optionalTestSpecificOptions)
    710     run("ftl-no-cjit-b3o0", "--useArrayAllocationProfiling=false", "--forcePolyProto=true", *(FTL_OPTIONS + NO_CJIT_OPTIONS + B3O0_OPTIONS + optionalTestSpecificOptions))
     711    run("ftl-no-cjit-b3o0", "--useArrayAllocationProfiling=false", "--forcePolyProto=true", *(FTL_OPTIONS + NO_CJIT_OPTIONS + B3O0_OPTIONS + FORCE_LLINT_EXIT_OPTIONS + optionalTestSpecificOptions))
    711712end
    712713
    … …  
    728729
    729730def runDFGEager(*optionalTestSpecificOptions)
    730     run("dfg-eager", *(EAGER_OPTIONS + COLLECT_CONTINUOUSLY_OPTIONS + optionalTestSpecificOptions))
     731    run("dfg-eager", *(EAGER_OPTIONS + COLLECT_CONTINUOUSLY_OPTIONS + FORCE_LLINT_EXIT_OPTIONS + optionalTestSpecificOptions))
    731732end
    732733
    … …  
    745746
    746747def runFTLEagerNoCJITValidate(*optionalTestSpecificOptions)
    747     run("ftl-eager-no-cjit", "--validateGraph=true", "--airForceIRCAllocator=true", *(FTL_OPTIONS + NO_CJIT_OPTIONS + EAGER_OPTIONS + COLLECT_CONTINUOUSLY_OPTIONS + optionalTestSpecificOptions))
     748    run("ftl-eager-no-cjit", "--validateGraph=true", "--airForceIRCAllocator=true", *(FTL_OPTIONS + NO_CJIT_OPTIONS + EAGER_OPTIONS + COLLECT_CONTINUOUSLY_OPTIONS + FORCE_LLINT_EXIT_OPTIONS + optionalTestSpecificOptions))
    748749end
    749750
    … …  
    10601061    end
    10611062
    1062     run("no-llint-modules", "-m", "--forceBaseline=true") if noLLInt
     1063    run("no-llint-modules", "-m", "--useLLInt=false") if noLLInt
    10631064    run("no-cjit-validate-phases-modules", "-m", "--validateBytecode=true", "--validateGraphAtEachPhase=true", *NO_CJIT_OPTIONS)
    10641065    run("dfg-eager-modules", "-m", *EAGER_OPTIONS)
    … …  
    12611262
    12621263def runLayoutTestNoLLInt
    1263     runLayoutTest("no-llint", "--forceBaseline=true")
     1264    runLayoutTest("no-llint", "--useLLInt=false")
    12641265end
    12651266
    … …  
    14271428
    14281429def runMozillaTestBaselineJIT(mode, *extraFiles)
    1429     runMozillaTest("baseline", mode, extraFiles, "--forceBaseline=true", "--useDFGJIT=false")
     1430    runMozillaTest("baseline", mode, extraFiles, "--useLLInt=false", "--useDFGJIT=false")
    14301431end
    14311432
Note: See TracChangeset for help on using the changeset viewer.