Changeset 254558 in webkit
- Timestamp:
- Jan 14, 2020, 10:02:48 PM (7 years ago)
- Location:
- trunk
- Files:
-
- 26 edited
-
JSTests/ChangeLog (modified) (1 diff)
-
JSTests/stress/dfg-compare-eq-via-nonSpeculativeNonPeepholeCompareNullOrUndefined.js (modified) (1 diff)
-
JSTests/stress/getter-setter-inlining-should-emit-movhint.js (modified) (1 diff)
-
JSTests/stress/make-dictionary-repatch.js (modified) (1 diff)
-
JSTests/stress/merging-ic-variants-should-bail-if-structures-overlap.js (modified) (1 diff)
-
JSTests/stress/proxy-getter-stack-overflow.js (modified) (1 diff)
-
JSTests/stress/racy-gc-cleanup-of-identifier-after-mutator-stops-running.js (modified) (1 diff)
-
JSTests/stress/regress-192717.js (modified) (1 diff)
-
JSTests/stress/retry-cache-later.js (modified) (1 diff)
-
Source/JavaScriptCore/API/tests/ExecutionTimeLimitTest.cpp (modified) (1 diff)
-
Source/JavaScriptCore/API/tests/PingPongStackOverflowTest.cpp (modified) (3 diffs)
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/bytecode/CodeBlock.cpp (modified) (7 diffs)
-
Source/JavaScriptCore/bytecode/CodeBlock.h (modified) (5 diffs)
-
Source/JavaScriptCore/dfg/DFGDriver.cpp (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGOSRExitCompilerCommon.cpp (modified) (7 diffs)
-
Source/JavaScriptCore/dfg/DFGOSRExitCompilerCommon.h (modified) (1 diff)
-
Source/JavaScriptCore/heap/CodeBlockSet.cpp (modified) (1 diff)
-
Source/JavaScriptCore/heap/CodeBlockSet.h (modified) (1 diff)
-
Source/JavaScriptCore/heap/Heap.cpp (modified) (2 diffs)
-
Source/JavaScriptCore/llint/LLIntSlowPaths.cpp (modified) (1 diff)
-
Source/JavaScriptCore/runtime/Options.cpp (modified) (4 diffs)
-
Source/JavaScriptCore/runtime/OptionsList.h (modified) (2 diffs)
-
Source/JavaScriptCore/runtime/ScriptExecutable.cpp (modified) (1 diff)
-
Tools/ChangeLog (modified) (1 diff)
-
Tools/Scripts/run-jsc-stress-tests (modified) (8 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/JSTests/ChangeLog
r254496 r254558 1 2020-01-14 Commit Queue <commit-queue@webkit.org> 2 3 Unreviewed, rolling out r254480, r254496, and r254517. 4 https://bugs.webkit.org/show_bug.cgi?id=206278 5 6 "It regressed JetStream2 and Speedometer2" (Requested by 7 saamyjoon on #webkit). 8 9 Reverted changesets: 10 11 "Throw away baseline code if there is an optimized 12 replacement" 13 https://bugs.webkit.org/show_bug.cgi?id=202503 14 https://trac.webkit.org/changeset/254480 15 16 "Unreviewed. Change useLLInt=0 to forceBaseline=1" 17 https://trac.webkit.org/changeset/254496 18 19 "Add an option that enables/disables throwing away baseline 20 JIT code" 21 https://bugs.webkit.org/show_bug.cgi?id=206244 22 https://trac.webkit.org/changeset/254517 23 1 24 2020-01-13 Saam Barati <sbarati@apple.com> 2 25 -
trunk/JSTests/stress/dfg-compare-eq-via-nonSpeculativeNonPeepholeCompareNullOrUndefined.js
r254480 r254558 1 //@ runDefault("--collectContinuously=true", "--collectContinuouslyPeriodMS=0.15", "-- forceBaseline=true", "--useFTLJIT=false", "--jitPolicyScale=0")1 //@ runDefault("--collectContinuously=true", "--collectContinuouslyPeriodMS=0.15", "--useLLInt=false", "--useFTLJIT=false", "--jitPolicyScale=0") 2 2 3 3 // This test exercises DFG::SpeculativeJIT::nonSpeculativeNonPeepholeCompareNullOrUndefined(). -
trunk/JSTests/stress/getter-setter-inlining-should-emit-movhint.js
r254480 r254558 1 //@ runDefault("--useRandomizingFuzzerAgent=1", "--usePolymorphicCallInliningForNonStubStatus=1", "--seedOfRandomizingFuzzerAgent=2896922505", "-- forceBaseline=1", "--useConcurrentJIT=0")1 //@ runDefault("--useRandomizingFuzzerAgent=1", "--usePolymorphicCallInliningForNonStubStatus=1", "--seedOfRandomizingFuzzerAgent=2896922505", "--useLLInt=0", "--useConcurrentJIT=0") 2 2 function foo(o) { 3 3 o.f = 0; -
trunk/JSTests/stress/make-dictionary-repatch.js
r254480 r254558 1 //@ if $jitTests then runNoCJIT("--useDFGJIT=false", "-- forceBaseline=true") else skip end1 //@ if $jitTests then runNoCJIT("--useDFGJIT=false", "--useLLInt=false") else skip end 2 2 3 3 function foo(o) { -
trunk/JSTests/stress/merging-ic-variants-should-bail-if-structures-overlap.js
r254480 r254558 1 //@ runDefault("--validateGraphAtEachPhase=1", "-- forceBaseline=1")1 //@ runDefault("--validateGraphAtEachPhase=1", "--useLLInt=0") 2 2 3 3 let items = []; -
trunk/JSTests/stress/proxy-getter-stack-overflow.js
r254480 r254558 1 //@ if $jitTests then runDefault("-- forceBaseline=1") else skip end1 //@ if $jitTests then runDefault("--useLLInt=0") else skip end 2 2 3 3 const o = {}; -
trunk/JSTests/stress/racy-gc-cleanup-of-identifier-after-mutator-stops-running.js
r254496 r254558 1 //@ runDefault("--numberOfGCMarkers=1", "--useDFGJIT=false", "-- forceBaseline=true")1 //@ runDefault("--numberOfGCMarkers=1", "--useDFGJIT=false", "--useLLInt=false") 2 2 3 3 function foo() { -
trunk/JSTests/stress/regress-192717.js
r254480 r254558 1 1 //@ skip if $memoryLimited or $buildType == "debug" 2 //@ runDefault("-- forceBaseline=true", "--forceCodeBlockToJettisonDueToOldAge=true", "--maxPerThreadStackUsage=200000", "--exceptionStackTraceLimit=1", "--defaultErrorStackTraceLimit=1")2 //@ runDefault("--useLLInt=false", "--forceCodeBlockToJettisonDueToOldAge=true", "--maxPerThreadStackUsage=200000", "--exceptionStackTraceLimit=1", "--defaultErrorStackTraceLimit=1") 3 3 4 4 let foo = 'let a'; -
trunk/JSTests/stress/retry-cache-later.js
r254480 r254558 1 //@ runNoCJIT("-- forceBaseline=true", "--useDFGJIT=false")1 //@ runNoCJIT("--useLLInt=false", "--useDFGJIT=false") 2 2 3 3 function foo(o) { -
trunk/Source/JavaScriptCore/API/tests/ExecutionTimeLimitTest.cpp
r254514 r254558 120 120 { 121 121 static const TierOptions tierOptionsList[] = { 122 { "LLINT", 0_ms, "--useConcurrentJIT=false --use JIT=false" },123 { "Baseline", 0_ms, "--useConcurrentJIT=false --use JIT=true --useDFGJIT=false" },124 { "DFG", 200_ms, "--useConcurrentJIT=false --use JIT=true --useDFGJIT=true --useFTLJIT=false" },122 { "LLINT", 0_ms, "--useConcurrentJIT=false --useLLInt=true --useJIT=false" }, 123 { "Baseline", 0_ms, "--useConcurrentJIT=false --useLLInt=true --useJIT=true --useDFGJIT=false" }, 124 { "DFG", 200_ms, "--useConcurrentJIT=false --useLLInt=true --useJIT=true --useDFGJIT=true --useFTLJIT=false" }, 125 125 #if ENABLE(FTL_JIT) 126 { "FTL", 500_ms, "--useConcurrentJIT=false --use JIT=true --useDFGJIT=true --useFTLJIT=true" },126 { "FTL", 500_ms, "--useConcurrentJIT=false --useLLInt=true --useJIT=true --useDFGJIT=true --useFTLJIT=true" }, 127 127 #endif 128 128 }; -
trunk/Source/JavaScriptCore/API/tests/PingPongStackOverflowTest.cpp
r254480 r254558 123 123 auto origSoftReservedZoneSize = Options::softReservedZoneSize(); 124 124 auto origReservedZoneSize = Options::reservedZoneSize(); 125 auto orig ForceBaseline = Options::forceBaseline();125 auto origUseLLInt = Options::useLLInt(); 126 126 auto origMaxPerThreadStackUsage = Options::maxPerThreadStackUsage(); 127 127 … … 132 132 // reproducing the regression in https://bugs.webkit.org/show_bug.cgi?id=148749. However, we only 133 133 // want to do this if the LLINT isn't the only available execution engine. 134 Options:: forceBaseline() = true;134 Options::useLLInt() = false; 135 135 #endif 136 136 … … 179 179 Options::softReservedZoneSize() = origSoftReservedZoneSize; 180 180 Options::reservedZoneSize() = origReservedZoneSize; 181 Options:: forceBaseline() = origForceBaseline;181 Options::useLLInt() = origUseLLInt; 182 182 Options::maxPerThreadStackUsage() = origMaxPerThreadStackUsage; 183 183 -
trunk/Source/JavaScriptCore/ChangeLog
r254549 r254558 1 2020-01-14 Commit Queue <commit-queue@webkit.org> 2 3 Unreviewed, rolling out r254480, r254496, and r254517. 4 https://bugs.webkit.org/show_bug.cgi?id=206278 5 6 "It regressed JetStream2 and Speedometer2" (Requested by 7 saamyjoon on #webkit). 8 9 Reverted changesets: 10 11 "Throw away baseline code if there is an optimized 12 replacement" 13 https://bugs.webkit.org/show_bug.cgi?id=202503 14 https://trac.webkit.org/changeset/254480 15 16 "Unreviewed. Change useLLInt=0 to forceBaseline=1" 17 https://trac.webkit.org/changeset/254496 18 19 "Add an option that enables/disables throwing away baseline 20 JIT code" 21 https://bugs.webkit.org/show_bug.cgi?id=206244 22 https://trac.webkit.org/changeset/254517 23 1 24 2020-01-14 Keith Miller <keith_miller@apple.com> 2 25 -
trunk/Source/JavaScriptCore/bytecode/CodeBlock.cpp
r254517 r254558 443 443 HandlerInfo& handler = m_rareData->m_exceptionHandlers[i]; 444 444 #if ENABLE(JIT) 445 auto& instruction = *instructions().at(unlinkedHandler.target).ptr(); 446 MacroAssemblerCodePtr<BytecodePtrTag> codePtr = LLInt::getCodePtr<BytecodePtrTag>(instruction); 445 auto instruction = instructions().at(unlinkedHandler.target); 446 MacroAssemblerCodePtr<BytecodePtrTag> codePtr; 447 if (instruction->isWide32()) 448 codePtr = LLInt::getWide32CodePtr<BytecodePtrTag>(op_catch); 449 else if (instruction->isWide16()) 450 codePtr = LLInt::getWide16CodePtr<BytecodePtrTag>(op_catch); 451 else 452 codePtr = LLInt::getCodePtr<BytecodePtrTag>(op_catch); 447 453 handler.initialize(unlinkedHandler, CodeLocationLabel<ExceptionHandlerPtrTag>(codePtr.retagged<ExceptionHandlerPtrTag>())); 448 454 #else … … 1383 1389 1384 1390 updateAllPredictions(); 1385 1386 #if ENABLE(JIT)1387 // If BaselineJIT code is not executing, and an optimized replacement exists, we attempt1388 // to discard baseline JIT code and reinstall LLInt code to save JIT memory.1389 if (!Options::forceBaseline() && Options::enableThrowingAwayBaselineCode() && jitType() == JITType::BaselineJIT && !m_vm->heap.codeBlockSet().isCurrentlyExecuting(this)) {1390 if (CodeBlock* optimizedCodeBlock = optimizedReplacement()) {1391 if (!optimizedCodeBlock->m_osrExitCounter) {1392 m_jitCode = nullptr;1393 LLInt::setEntrypoint(this);1394 RELEASE_ASSERT(jitType() == JITType::InterpreterThunk);1395 1396 for (size_t i = 0; i < m_unlinkedCode->numberOfExceptionHandlers(); i++) {1397 const UnlinkedHandlerInfo& unlinkedHandler = m_unlinkedCode->exceptionHandler(i);1398 HandlerInfo& handler = m_rareData->m_exceptionHandlers[i];1399 auto& instruction = *instructions().at(unlinkedHandler.target).ptr();1400 MacroAssemblerCodePtr<BytecodePtrTag> codePtr = LLInt::getCodePtr<BytecodePtrTag>(instruction);1401 handler.initialize(unlinkedHandler, CodeLocationLabel<ExceptionHandlerPtrTag>(codePtr.retagged<ExceptionHandlerPtrTag>()));1402 }1403 1404 unlinkIncomingCalls();1405 1406 // It's safe to clear these out here because in finalizeUnconditionally all compiler threads1407 // are safepointed, meaning they're running either before or after bytecode parser, and bytecode1408 // parser is the only data structure pointing into the various *infos.1409 resetJITData();1410 }1411 }1412 }1413 1414 #endif1415 1391 1416 1392 if (JITCode::couldBeInterpreted(jitType())) … … 1540 1516 } 1541 1517 1518 StructureStubInfo* CodeBlock::findStubInfo(CodeOrigin codeOrigin) 1519 { 1520 ConcurrentJSLocker locker(m_lock); 1521 if (auto* jitData = m_jitData.get()) { 1522 for (StructureStubInfo* stubInfo : jitData->m_stubInfos) { 1523 if (stubInfo->codeOrigin == codeOrigin) 1524 return stubInfo; 1525 } 1526 } 1527 return nullptr; 1528 } 1529 1542 1530 ByValInfo* CodeBlock::addByValInfo() 1543 1531 { … … 1550 1538 ConcurrentJSLocker locker(m_lock); 1551 1539 return ensureJITData(locker).m_callLinkInfos.add(); 1540 } 1541 1542 CallLinkInfo* CodeBlock::getCallLinkInfoForBytecodeIndex(BytecodeIndex index) 1543 { 1544 ConcurrentJSLocker locker(m_lock); 1545 if (auto* jitData = m_jitData.get()) { 1546 for (CallLinkInfo* callLinkInfo : jitData->m_callLinkInfos) { 1547 if (callLinkInfo->codeOrigin() == CodeOrigin(index)) 1548 return callLinkInfo; 1549 } 1550 } 1551 return nullptr; 1552 1552 } 1553 1553 … … 1599 1599 // link infos, or by val infos if we don't have JIT code. Attempts to query these data 1600 1600 // structures using the concurrent API (getICStatusMap and friends) will return nothing if we 1601 // don't have JIT code. So it's safe to call this if we fail a baseline JIT compile. 1602 // 1603 // We also call this from finalizeUnconditionally when we degrade from baseline JIT to LLInt 1604 // code. This is safe to do since all compiler threads are safepointed in finalizeUnconditionally, 1605 // which means we've made it past bytecode parsing. Only the bytecode parser will hold onto 1606 // references to these various *infos via its use of ICStatusMap. 1607 1608 for (StructureStubInfo* stubInfo : jitData->m_stubInfos) { 1609 stubInfo->aboutToDie(); 1610 stubInfo->deref(); 1611 } 1612 1601 // don't have JIT code. 1602 jitData->m_stubInfos.clear(); 1603 jitData->m_callLinkInfos.clear(); 1604 jitData->m_byValInfos.clear(); 1613 1605 // We can clear this because the DFG's queries to these data structures are guarded by whether 1614 1606 // there is JIT code. 1615 1616 m_jitData = nullptr; 1607 jitData->m_rareCaseProfiles.clear(); 1617 1608 } 1618 1609 } … … 1746 1737 1747 1738 #if ENABLE(JIT) 1748 CodeBlock* CodeBlock::optimizedReplacement(JITType typeToReplace)1739 bool CodeBlock::hasOptimizedReplacement(JITType typeToReplace) 1749 1740 { 1750 1741 CodeBlock* replacement = this->replacement(); 1751 if (!replacement) 1752 return nullptr; 1753 if (JITCode::isHigherTier(replacement->jitType(), typeToReplace)) 1754 return replacement; 1755 return nullptr; 1756 } 1757 1758 CodeBlock* CodeBlock::optimizedReplacement() 1759 { 1760 return optimizedReplacement(jitType()); 1761 } 1762 1763 bool CodeBlock::hasOptimizedReplacement(JITType typeToReplace) 1764 { 1765 return !!optimizedReplacement(typeToReplace); 1742 return replacement && JITCode::isHigherTier(replacement->jitType(), typeToReplace); 1766 1743 } 1767 1744 … … 2825 2802 { 2826 2803 ASSERT(JITCode::isOptimizingJIT(jitType())); 2827 ASSERT( JITCode::isBaselineCode(alternative()->jitType()));2804 ASSERT(alternative()->jitType() == JITType::BaselineJIT); 2828 2805 2829 2806 CodeBlock* profiledBlock = alternative(); -
trunk/Source/JavaScriptCore/bytecode/CodeBlock.h
r254480 r254558 259 259 Optional<BytecodeIndex> bytecodeIndexFromCallSiteIndex(CallSiteIndex); 260 260 261 // Because we might throw out baseline JIT code and all its baseline JIT data (m_jitData),262 // you need to be careful about the lifetime of when you use the return value of this function.263 // The return value may have raw pointers into this data structure that gets thrown away.264 // Specifically, you need to ensure that no GC can be finalized (typically that means no265 // allocations) between calling this and the last use of it.266 261 void getICStatusMap(const ConcurrentJSLocker&, ICStatusMap& result); 267 262 void getICStatusMap(ICStatusMap& result); … … 283 278 std::unique_ptr<PCToCodeOriginMap> m_pcToCodeOriginMap; 284 279 std::unique_ptr<RegisterAtOffsetList> m_calleeSaveRegisters; 285 // FIXME: Now that we unconditionally OSR exit to the LLInt, we might be able to prune286 // the number of entries we have in this to contain entries only for opcodes we use287 // it for. Today, that's only for loop OSR entry.288 // https://bugs.webkit.org/show_bug.cgi?id=206207289 280 JITCodeMap m_jitCodeMap; 290 281 }; … … 317 308 StructureStubInfo* addStubInfo(AccessType); 318 309 310 // O(n) operation. Use getStubInfoMap() unless you really only intend to get one 311 // stub info. 312 StructureStubInfo* findStubInfo(CodeOrigin); 313 319 314 ByValInfo* addByValInfo(); 320 315 321 316 CallLinkInfo* addCallLinkInfo(); 317 318 // This is a slow function call used primarily for compiling OSR exits in the case 319 // that there had been inlining. Chances are if you want to use this, you're really 320 // looking for a CallLinkInfoMap to amortize the cost of calling this. 321 CallLinkInfo* getCallLinkInfoForBytecodeIndex(BytecodeIndex); 322 322 323 323 void setJITCodeMap(JITCodeMap&& jitCodeMap) … … 413 413 void setJITCode(Ref<JITCode>&& code) 414 414 { 415 ASSERT(heap()->isDeferred()); 415 416 if (!code->isShared()) 416 417 heap()->reportExtraMemoryAllocated(code->size()); … … 444 445 DFG::CapabilityLevel capabilityLevelState() { return static_cast<DFG::CapabilityLevel>(m_capabilityLevelState); } 445 446 446 CodeBlock* optimizedReplacement(JITType typeToReplace);447 CodeBlock* optimizedReplacement(); // the typeToReplace is my JITType448 447 bool hasOptimizedReplacement(JITType typeToReplace); 449 448 bool hasOptimizedReplacement(); // the typeToReplace is my JITType -
trunk/Source/JavaScriptCore/dfg/DFGDriver.cpp
r254480 r254558 82 82 ASSERT(codeBlock); 83 83 ASSERT(codeBlock->alternative()); 84 ASSERT( JITCode::isBaselineCode(codeBlock->alternative()->jitType()));84 ASSERT(codeBlock->alternative()->jitType() == JITType::BaselineJIT); 85 85 ASSERT(!profiledDFGCodeBlock || profiledDFGCodeBlock->jitType() == JITType::DFGJIT); 86 86 -
trunk/Source/JavaScriptCore/dfg/DFGOSRExitCompilerCommon.cpp
r254480 r254558 143 143 } 144 144 145 static MacroAssemblerCodePtr<JSEntryPtrTag> callerReturnPC(CodeBlock* baselineCodeBlockForCaller, BytecodeIndex callBytecodeIndex, InlineCallFrame::Kind trueCallerCallKind) 146 { 145 MacroAssemblerCodePtr<JSEntryPtrTag> callerReturnPC(CodeBlock* baselineCodeBlockForCaller, BytecodeIndex callBytecodeIndex, InlineCallFrame::Kind trueCallerCallKind, bool& callerIsLLInt) 146 { 147 callerIsLLInt = Options::forceOSRExitToLLInt() || baselineCodeBlockForCaller->jitType() == JITType::InterpreterThunk; 148 147 149 if (callBytecodeIndex.checkpoint()) 148 150 return LLInt::getCodePtr<JSEntryPtrTag>(checkpoint_osr_exit_from_inlined_call_trampoline); … … 150 152 MacroAssemblerCodePtr<JSEntryPtrTag> jumpTarget; 151 153 152 const Instruction& callInstruction = *baselineCodeBlockForCaller->instructions().at(callBytecodeIndex).ptr(); 154 if (callerIsLLInt) { 155 const Instruction& callInstruction = *baselineCodeBlockForCaller->instructions().at(callBytecodeIndex).ptr(); 153 156 #define LLINT_RETURN_LOCATION(name) (callInstruction.isWide16() ? LLInt::getWide16CodePtr<JSEntryPtrTag>(name##_return_location) : (callInstruction.isWide32() ? LLInt::getWide32CodePtr<JSEntryPtrTag>(name##_return_location) : LLInt::getCodePtr<JSEntryPtrTag>(name##_return_location))) 154 157 155 switch (trueCallerCallKind) { 156 case InlineCallFrame::Call: 157 jumpTarget = LLINT_RETURN_LOCATION(op_call); 158 break; 159 case InlineCallFrame::Construct: 160 jumpTarget = LLINT_RETURN_LOCATION(op_construct); 161 break; 162 case InlineCallFrame::CallVarargs: 163 jumpTarget = LLINT_RETURN_LOCATION(op_call_varargs_slow); 164 break; 165 case InlineCallFrame::ConstructVarargs: 166 jumpTarget = LLINT_RETURN_LOCATION(op_construct_varargs_slow); 167 break; 168 case InlineCallFrame::GetterCall: { 169 if (callInstruction.opcodeID() == op_get_by_id) 170 jumpTarget = LLINT_RETURN_LOCATION(op_get_by_id); 171 else if (callInstruction.opcodeID() == op_get_by_val) 172 jumpTarget = LLINT_RETURN_LOCATION(op_get_by_val); 173 else 158 switch (trueCallerCallKind) { 159 case InlineCallFrame::Call: 160 jumpTarget = LLINT_RETURN_LOCATION(op_call); 161 break; 162 case InlineCallFrame::Construct: 163 jumpTarget = LLINT_RETURN_LOCATION(op_construct); 164 break; 165 case InlineCallFrame::CallVarargs: 166 jumpTarget = LLINT_RETURN_LOCATION(op_call_varargs_slow); 167 break; 168 case InlineCallFrame::ConstructVarargs: 169 jumpTarget = LLINT_RETURN_LOCATION(op_construct_varargs_slow); 170 break; 171 case InlineCallFrame::GetterCall: { 172 if (callInstruction.opcodeID() == op_get_by_id) 173 jumpTarget = LLINT_RETURN_LOCATION(op_get_by_id); 174 else if (callInstruction.opcodeID() == op_get_by_val) 175 jumpTarget = LLINT_RETURN_LOCATION(op_get_by_val); 176 else 177 RELEASE_ASSERT_NOT_REACHED(); 178 break; 179 } 180 case InlineCallFrame::SetterCall: { 181 if (callInstruction.opcodeID() == op_put_by_id) 182 jumpTarget = LLINT_RETURN_LOCATION(op_put_by_id); 183 else if (callInstruction.opcodeID() == op_put_by_val) 184 jumpTarget = LLINT_RETURN_LOCATION(op_put_by_val); 185 else 186 RELEASE_ASSERT_NOT_REACHED(); 187 break; 188 } 189 default: 174 190 RELEASE_ASSERT_NOT_REACHED(); 175 break; 176 } 177 case InlineCallFrame::SetterCall: { 178 if (callInstruction.opcodeID() == op_put_by_id) 179 jumpTarget = LLINT_RETURN_LOCATION(op_put_by_id); 180 else if (callInstruction.opcodeID() == op_put_by_val) 181 jumpTarget = LLINT_RETURN_LOCATION(op_put_by_val); 182 else 191 } 192 193 #undef LLINT_RETURN_LOCATION 194 195 } else { 196 switch (trueCallerCallKind) { 197 case InlineCallFrame::Call: 198 case InlineCallFrame::Construct: 199 case InlineCallFrame::CallVarargs: 200 case InlineCallFrame::ConstructVarargs: { 201 CallLinkInfo* callLinkInfo = 202 baselineCodeBlockForCaller->getCallLinkInfoForBytecodeIndex(callBytecodeIndex); 203 RELEASE_ASSERT(callLinkInfo); 204 205 jumpTarget = callLinkInfo->callReturnLocation().retagged<JSEntryPtrTag>(); 206 break; 207 } 208 209 case InlineCallFrame::GetterCall: 210 case InlineCallFrame::SetterCall: { 211 StructureStubInfo* stubInfo = 212 baselineCodeBlockForCaller->findStubInfo(CodeOrigin(callBytecodeIndex)); 213 RELEASE_ASSERT(stubInfo); 214 215 jumpTarget = stubInfo->doneLocation.retagged<JSEntryPtrTag>(); 216 break; 217 } 218 219 default: 183 220 RELEASE_ASSERT_NOT_REACHED(); 184 break; 185 } 186 default: 187 RELEASE_ASSERT_NOT_REACHED(); 188 } 189 190 #undef LLINT_RETURN_LOCATION 221 } 222 } 191 223 192 224 return jumpTarget; … … 222 254 CodeOrigin* trueCaller = inlineCallFrame->getCallerSkippingTailCalls(&trueCallerCallKind); 223 255 GPRReg callerFrameGPR = GPRInfo::callFrameRegister; 256 257 bool callerIsLLInt = false; 224 258 225 259 if (!trueCaller) { … … 238 272 CodeBlock* baselineCodeBlockForCaller = jit.baselineCodeBlockFor(*trueCaller); 239 273 auto callBytecodeIndex = trueCaller->bytecodeIndex(); 240 MacroAssemblerCodePtr<JSEntryPtrTag> jumpTarget = callerReturnPC(baselineCodeBlockForCaller, callBytecodeIndex, trueCallerCallKind );274 MacroAssemblerCodePtr<JSEntryPtrTag> jumpTarget = callerReturnPC(baselineCodeBlockForCaller, callBytecodeIndex, trueCallerCallKind, callerIsLLInt); 241 275 242 276 if (trueCaller->inlineCallFrame()) { … … 269 303 GPRInfo::regT2); 270 304 271 if (trueCaller) { 272 // Set up LLInt registers for our caller in our callee saves. 305 if (callerIsLLInt) { 273 306 CodeBlock* baselineCodeBlockForCaller = jit.baselineCodeBlockFor(*trueCaller); 274 307 jit.storePtr(CCallHelpers::TrustedImmPtr(baselineCodeBlockForCaller->metadataTable()), calleeSaveSlot(inlineCallFrame, baselineCodeBlock, LLInt::Registers::metadataTableGPR)); … … 356 389 ASSERT(JITCode::isBaselineCode(codeBlockForExit->jitType())); 357 390 358 auto bytecodeIndex = exit.m_codeOrigin.bytecodeIndex(); 359 const Instruction& currentInstruction = *codeBlockForExit->instructions().at(bytecodeIndex).ptr(); 360 MacroAssemblerCodePtr<JSEntryPtrTag> destination; 361 if (bytecodeIndex.checkpoint()) 362 destination = LLInt::getCodePtr<JSEntryPtrTag>(checkpoint_osr_exit_trampoline); 363 else 364 destination = LLInt::getCodePtr<JSEntryPtrTag>(currentInstruction); 365 366 if (exit.isExceptionHandler()) { 367 jit.move(CCallHelpers::TrustedImmPtr(¤tInstruction), GPRInfo::regT2); 368 jit.storePtr(GPRInfo::regT2, &vm.targetInterpreterPCForThrow); 369 } 370 371 jit.move(CCallHelpers::TrustedImmPtr(codeBlockForExit->metadataTable()), LLInt::Registers::metadataTableGPR); 391 void* jumpTarget; 392 bool exitToLLInt = Options::forceOSRExitToLLInt() || codeBlockForExit->jitType() == JITType::InterpreterThunk; 393 if (exitToLLInt) { 394 auto bytecodeIndex = exit.m_codeOrigin.bytecodeIndex(); 395 const Instruction& currentInstruction = *codeBlockForExit->instructions().at(bytecodeIndex).ptr(); 396 MacroAssemblerCodePtr<JSEntryPtrTag> destination; 397 if (bytecodeIndex.checkpoint()) 398 destination = LLInt::getCodePtr<JSEntryPtrTag>(checkpoint_osr_exit_trampoline); 399 else 400 destination = LLInt::getCodePtr<JSEntryPtrTag>(currentInstruction); 401 402 if (exit.isExceptionHandler()) { 403 jit.move(CCallHelpers::TrustedImmPtr(¤tInstruction), GPRInfo::regT2); 404 jit.storePtr(GPRInfo::regT2, &vm.targetInterpreterPCForThrow); 405 } 406 407 jit.move(CCallHelpers::TrustedImmPtr(codeBlockForExit->metadataTable()), LLInt::Registers::metadataTableGPR); 372 408 #if USE(JSVALUE64) 373 jit.move(CCallHelpers::TrustedImmPtr(codeBlockForExit->instructionsRawPointer()), LLInt::Registers::pbGPR);374 jit.move(CCallHelpers::TrustedImm32(bytecodeIndex.offset()), LLInt::Registers::pcGPR);409 jit.move(CCallHelpers::TrustedImmPtr(codeBlockForExit->instructionsRawPointer()), LLInt::Registers::pbGPR); 410 jit.move(CCallHelpers::TrustedImm32(bytecodeIndex.offset()), LLInt::Registers::pcGPR); 375 411 #else 376 jit.move(CCallHelpers::TrustedImmPtr(¤tInstruction), LLInt::Registers::pcGPR); 377 #endif 412 jit.move(CCallHelpers::TrustedImmPtr(¤tInstruction), LLInt::Registers::pcGPR); 413 #endif 414 jumpTarget = destination.retagged<OSRExitPtrTag>().executableAddress(); 415 } else { 416 BytecodeIndex exitIndex = exit.m_codeOrigin.bytecodeIndex(); 417 MacroAssemblerCodePtr<JSEntryPtrTag> destination; 418 if (exitIndex.checkpoint()) 419 destination = LLInt::getCodePtr<JSEntryPtrTag>(checkpoint_osr_exit_trampoline); 420 else { 421 ASSERT(codeBlockForExit->bytecodeIndexForExit(exitIndex) == exitIndex); 422 destination = codeBlockForExit->jitCodeMap().find(exitIndex); 423 } 424 425 ASSERT(destination); 426 427 jumpTarget = destination.retagged<OSRExitPtrTag>().executableAddress(); 428 } 378 429 379 430 jit.addPtr(AssemblyHelpers::TrustedImm32(JIT::stackPointerOffsetFor(codeBlockForExit) * sizeof(Register)), GPRInfo::callFrameRegister, AssemblyHelpers::stackPointerRegister); … … 383 434 } 384 435 385 jit.move(AssemblyHelpers::TrustedImmPtr( destination.retagged<OSRExitPtrTag>().executableAddress()), GPRInfo::regT2);436 jit.move(AssemblyHelpers::TrustedImmPtr(jumpTarget), GPRInfo::regT2); 386 437 jit.farJump(GPRInfo::regT2, OSRExitPtrTag); 387 438 } -
trunk/Source/JavaScriptCore/dfg/DFGOSRExitCompilerCommon.h
r254480 r254558 40 40 void reifyInlinedCallFrames(CCallHelpers&, const OSRExitBase&); 41 41 void adjustAndJumpToTarget(VM&, CCallHelpers&, const OSRExitBase&); 42 MacroAssemblerCodePtr<JSEntryPtrTag> callerReturnPC(CodeBlock* baselineCodeBlockForCaller, BytecodeIndex callBytecodeIndex, InlineCallFrame::Kind callerKind, bool& callerIsLLInt); 42 43 CCallHelpers::Address calleeSaveSlot(InlineCallFrame*, CodeBlock* baselineCodeBlock, GPRReg calleeSave); 43 44 -
trunk/Source/JavaScriptCore/heap/CodeBlockSet.cpp
r254480 r254558 56 56 } 57 57 58 bool CodeBlockSet::isCurrentlyExecuting(CodeBlock* codeBlock)59 {60 return m_currentlyExecuting.contains(codeBlock);61 }62 63 58 void CodeBlockSet::dump(PrintStream& out) const 64 59 { -
trunk/Source/JavaScriptCore/heap/CodeBlockSet.h
r254480 r254558 57 57 Lock& getLock() { return m_lock; } 58 58 59 // This is expected to run only when we're not adding to the set for now. If60 // this needs to run concurrently in the future, we'll need to lock around this.61 bool isCurrentlyExecuting(CodeBlock*);62 63 59 // Visits each CodeBlock in the heap until the visitor function returns true 64 60 // to indicate that it is done iterating, or until every CodeBlock has been -
trunk/Source/JavaScriptCore/heap/Heap.cpp
r254480 r254558 614 614 finalizeMarkedUnconditionalFinalizers<FunctionExecutable>(vm().functionExecutableSpace.space); 615 615 finalizeMarkedUnconditionalFinalizers<SymbolTable>(vm().symbolTableSpace); 616 finalizeMarkedUnconditionalFinalizers<ExecutableToCodeBlockEdge>(vm().executableToCodeBlockEdgesWithFinalizers); // We run this before CodeBlock's unconditional finalizer since CodeBlock looks at the owner executable's installed CodeBlock in its finalizeUnconditionally.617 616 vm().forEachCodeBlockSpace( 618 617 [&] (auto& space) { 619 618 this->finalizeMarkedUnconditionalFinalizers<CodeBlock>(space.set); 620 619 }); 620 finalizeMarkedUnconditionalFinalizers<ExecutableToCodeBlockEdge>(vm().executableToCodeBlockEdgesWithFinalizers); 621 621 finalizeMarkedUnconditionalFinalizers<StructureRareData>(vm().structureRareDataSpace); 622 622 finalizeMarkedUnconditionalFinalizers<UnlinkedFunctionExecutable>(vm().unlinkedFunctionExecutableSpace.set); … … 1523 1523 sweepArrayBuffers(); 1524 1524 snapshotUnswept(); 1525 finalizeUnconditionalFinalizers(); // We rely on these unconditional finalizers running before clearCurrentlyExecuting since CodeBlock's finalizer relies on querying currently executing.1525 finalizeUnconditionalFinalizers(); 1526 1526 removeDeadCompilerWorklistEntries(); 1527 1527 notifyIncrementalSweeper(); -
trunk/Source/JavaScriptCore/llint/LLIntSlowPaths.cpp
r254480 r254558 1994 1994 { 1995 1995 RELEASE_ASSERT(!codeBlock->vm().exceptionForInspection()); 1996 const Instruction* nextPC = pc.next().ptr(); 1997 auto nextBytecode = LLInt::getCodePtr<JSEntryPtrTag>(*pc.next().ptr()); 1998 return encodeResult(nextPC, nextBytecode.executableAddress()); 1996 if (Options::forceOSRExitToLLInt() || codeBlock->jitType() == JITType::InterpreterThunk) { 1997 const Instruction* nextPC = pc.next().ptr(); 1998 auto nextBytecode = LLInt::getCodePtr<JSEntryPtrTag>(*pc.next().ptr()); 1999 return encodeResult(nextPC, nextBytecode.executableAddress()); 2000 } 2001 2002 #if ENABLE(JIT) 2003 ASSERT(codeBlock->jitType() == JITType::BaselineJIT); 2004 BytecodeIndex nextBytecodeIndex = pc.next().index(); 2005 auto nextBytecode = codeBlock->jitCodeMap().find(nextBytecodeIndex); 2006 return encodeResult(nullptr, nextBytecode.executableAddress()); 2007 #endif 2008 RELEASE_ASSERT_NOT_REACHED(); 1999 2009 } 2000 2010 -
trunk/Source/JavaScriptCore/runtime/Options.cpp
r254514 r254558 388 388 #endif 389 389 #if !ENABLE(JIT) 390 Options:: forceBaseline() = false;390 Options::useLLInt() = true; 391 391 Options::useJIT() = false; 392 392 Options::useBaselineJIT() = false; … … 420 420 421 421 if (!jitEnabledByDefault() && !Options::useJIT()) 422 Options:: forceBaseline() = false;422 Options::useLLInt() = true; 423 423 424 424 if (!Options::useWebAssembly()) … … 547 547 RELEASE_ASSERT(Options::addressOfOption(gcMaxHeapSizeID) == &Options::gcMaxHeapSize()); 548 548 RELEASE_ASSERT(Options::addressOfOptionDefault(gcMaxHeapSizeID) == &Options::gcMaxHeapSizeDefault()); 549 RELEASE_ASSERT(Options::addressOfOption(forceOSRExitToLLIntID) == &Options::forceOSRExitToLLInt()); 550 RELEASE_ASSERT(Options::addressOfOptionDefault(forceOSRExitToLLIntID) == &Options::forceOSRExitToLLIntDefault()); 549 551 550 552 #ifndef NDEBUG … … 944 946 { 945 947 bool coherent = true; 946 if ( forceBaseline() && !useJIT()) {948 if (!(useLLInt() || useJIT())) { 947 949 coherent = false; 948 dataLog("INCOHERENT OPTIONS: forceBaseline can't be true if useJIT is false\n");950 dataLog("INCOHERENT OPTIONS: at least one of useLLInt or useJIT must be true\n"); 949 951 } 950 952 if (!coherent) -
trunk/Source/JavaScriptCore/runtime/OptionsList.h
r254517 r254558 82 82 v(OptionString, configFile, nullptr, Normal, "file to configure JSC options and logging location") \ 83 83 \ 84 v(Bool, forceBaseline, false, Normal, "If true, we'll start running code in the baseline JIT and skip starting in the LLInt") \84 v(Bool, useLLInt, true, Normal, "allows the LLINT to be used if true") \ 85 85 v(Bool, useJIT, jitEnabledByDefault(), Normal, "allows the executable pages to be allocated for JIT and thunks if true") \ 86 86 v(Bool, useBaselineJIT, true, Normal, "allows the baseline JIT to be used if true") \ … … 495 495 v(Double, dumpJITMemoryFlushInterval, 10, Restricted, "Maximum time in between flushes of the JIT memory dump in seconds.") \ 496 496 v(Bool, useUnlinkedCodeBlockJettisoning, false, Normal, "If true, UnlinkedCodeBlock can be jettisoned.") \ 497 v(Bool, forceOSRExitToLLInt, false, Normal, "If true, we always exit to the LLInt. If false, we exit to whatever is most convenient.") \ 497 498 v(Unsigned, getByValICMaxNumberOfIdentifiers, 4, Normal, "Number of identifiers we see in the LLInt that could cause us to bail on generating an IC for get_by_val.") \ 498 v(Bool, enableThrowingAwayBaselineCode, false, Normal, nullptr) \499 499 500 500 enum OptionEquivalence { -
trunk/Source/JavaScriptCore/runtime/ScriptExecutable.cpp
r254480 r254558 427 427 codeBlock->validate(); 428 428 429 if (Options::forceBaseline()) 429 if (Options::useLLInt()) 430 setupLLInt(codeBlock); 431 else 430 432 setupJIT(vm, codeBlock); 431 else432 setupLLInt(codeBlock);433 433 434 434 installCode(vm, codeBlock, codeBlock->codeType(), codeBlock->specializationKind()); -
trunk/Tools/ChangeLog
r254556 r254558 1 2020-01-14 Commit Queue <commit-queue@webkit.org> 2 3 Unreviewed, rolling out r254480, r254496, and r254517. 4 https://bugs.webkit.org/show_bug.cgi?id=206278 5 6 "It regressed JetStream2 and Speedometer2" (Requested by 7 saamyjoon on #webkit). 8 9 Reverted changesets: 10 11 "Throw away baseline code if there is an optimized 12 replacement" 13 https://bugs.webkit.org/show_bug.cgi?id=202503 14 https://trac.webkit.org/changeset/254480 15 16 "Unreviewed. Change useLLInt=0 to forceBaseline=1" 17 https://trac.webkit.org/changeset/254496 18 19 "Add an option that enables/disables throwing away baseline 20 JIT code" 21 https://bugs.webkit.org/show_bug.cgi?id=206244 22 https://trac.webkit.org/changeset/254517 23 1 24 2020-01-14 Chris Dumez <cdumez@apple.com> 2 25 -
trunk/Tools/Scripts/run-jsc-stress-tests
r254480 r254558 499 499 B3O0_OPTIONS = ["--maxDFGNodesInBasicBlockForPreciseAnalysis=100", "--defaultB3OptLevel=0"] 500 500 FTL_OPTIONS = ["--useFTLJIT=true"] 501 FORCE_LLINT_EXIT_OPTIONS = ["--forceOSRExitToLLInt=true"] 501 502 502 503 require_relative "webkitruby/jsc-stress-test-writer-#{$testWriter}" … … 655 656 def runNoLLInt(*optionalTestSpecificOptions) 656 657 if $jitTests 657 run("no-llint", "-- forceBaseline=true", *optionalTestSpecificOptions)658 run("no-llint", "--useLLInt=false", *optionalTestSpecificOptions) 658 659 end 659 660 end … … 708 709 709 710 def runFTLNoCJITB3O0(*optionalTestSpecificOptions) 710 run("ftl-no-cjit-b3o0", "--useArrayAllocationProfiling=false", "--forcePolyProto=true", *(FTL_OPTIONS + NO_CJIT_OPTIONS + B3O0_OPTIONS + optionalTestSpecificOptions))711 run("ftl-no-cjit-b3o0", "--useArrayAllocationProfiling=false", "--forcePolyProto=true", *(FTL_OPTIONS + NO_CJIT_OPTIONS + B3O0_OPTIONS + FORCE_LLINT_EXIT_OPTIONS + optionalTestSpecificOptions)) 711 712 end 712 713 … … 728 729 729 730 def runDFGEager(*optionalTestSpecificOptions) 730 run("dfg-eager", *(EAGER_OPTIONS + COLLECT_CONTINUOUSLY_OPTIONS + optionalTestSpecificOptions))731 run("dfg-eager", *(EAGER_OPTIONS + COLLECT_CONTINUOUSLY_OPTIONS + FORCE_LLINT_EXIT_OPTIONS + optionalTestSpecificOptions)) 731 732 end 732 733 … … 745 746 746 747 def runFTLEagerNoCJITValidate(*optionalTestSpecificOptions) 747 run("ftl-eager-no-cjit", "--validateGraph=true", "--airForceIRCAllocator=true", *(FTL_OPTIONS + NO_CJIT_OPTIONS + EAGER_OPTIONS + COLLECT_CONTINUOUSLY_OPTIONS + optionalTestSpecificOptions))748 run("ftl-eager-no-cjit", "--validateGraph=true", "--airForceIRCAllocator=true", *(FTL_OPTIONS + NO_CJIT_OPTIONS + EAGER_OPTIONS + COLLECT_CONTINUOUSLY_OPTIONS + FORCE_LLINT_EXIT_OPTIONS + optionalTestSpecificOptions)) 748 749 end 749 750 … … 1060 1061 end 1061 1062 1062 run("no-llint-modules", "-m", "-- forceBaseline=true") if noLLInt1063 run("no-llint-modules", "-m", "--useLLInt=false") if noLLInt 1063 1064 run("no-cjit-validate-phases-modules", "-m", "--validateBytecode=true", "--validateGraphAtEachPhase=true", *NO_CJIT_OPTIONS) 1064 1065 run("dfg-eager-modules", "-m", *EAGER_OPTIONS) … … 1261 1262 1262 1263 def runLayoutTestNoLLInt 1263 runLayoutTest("no-llint", "-- forceBaseline=true")1264 runLayoutTest("no-llint", "--useLLInt=false") 1264 1265 end 1265 1266 … … 1427 1428 1428 1429 def runMozillaTestBaselineJIT(mode, *extraFiles) 1429 runMozillaTest("baseline", mode, extraFiles, "-- forceBaseline=true", "--useDFGJIT=false")1430 runMozillaTest("baseline", mode, extraFiles, "--useLLInt=false", "--useDFGJIT=false") 1430 1431 end 1431 1432
Note:
See TracChangeset
for help on using the changeset viewer.