Changeset 285167 in webkit
- Timestamp:
- Nov 2, 2021, 10:25:46 AM (5 years ago)
- Location:
- trunk
- Files:
-
- 1 added
- 4 edited
-
JSTests/ChangeLog (modified) (1 diff)
-
JSTests/stress/enumerator-get-by-val-needs-to-recover-property-name.js (added)
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp (modified) (5 diffs)
-
Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp (modified) (4 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/JSTests/ChangeLog
r285123 r285167 1 2021-11-02 Saam Barati <sbarati@apple.com> 2 3 EnumeratorGetByVal for IndexedMode+OwnStructureMode doesn't always recover the property name 4 https://bugs.webkit.org/show_bug.cgi?id=231321 5 <rdar://problem/84211697> 6 7 Reviewed by Yusuke Suzuki. 8 9 * stress/enumerator-get-by-val-needs-to-recover-property-name.js: Added. 10 1 11 2021-11-01 Saam Barati <sbarati@apple.com> 2 12 -
trunk/Source/JavaScriptCore/ChangeLog
r285164 r285167 1 2021-11-02 Saam Barati <sbarati@apple.com> 2 3 EnumeratorGetByVal for IndexedMode+OwnStructureMode doesn't always recover the property name 4 https://bugs.webkit.org/show_bug.cgi?id=231321 5 <rdar://problem/84211697> 6 7 Reviewed by Yusuke Suzuki. 8 9 When running an EnumeratorGetByVal in IndexedMode+OwnStructureMode, we may 10 go to the slow path. However, we were incorrectly going to the slow path 11 before recovering the actual property name. Instead, we were passing in 12 the integer index value to the get by val. 13 14 * dfg/DFGSpeculativeJIT.cpp: 15 (JSC::DFG::SpeculativeJIT::compileEnumeratorGetByVal): 16 * ftl/FTLLowerDFGToB3.cpp: 17 (JSC::FTL::DFG::LowerDFGToB3::compileCompareStrictEq): 18 1 19 2021-11-02 Patrick Angle <pangle@apple.com> 2 20 -
trunk/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp
r285078 r285167 15876 15876 GPRReg indexGPR; 15877 15877 GPRReg enumeratorGPR; 15878 MacroAssembler::Jump badStructureSlowPath;15878 MacroAssembler::JumpList recoverGenericCase; 15879 15879 15880 15880 compileGetByVal(node, scopedLambda<std::tuple<JSValueRegs, DataFormat, CanUseFlush>(DataFormat)>([&] (DataFormat) { … … 15905 15905 15906 15906 MacroAssembler::JumpList notFastNamedCases; 15907 // FIXME: Maybe we should have a better way to represent IndexedMode+OwnStructureMode? 15908 bool indexedAndOwnStructureMode = m_graph.varArgChild(node, 1).node() == m_graph.varArgChild(node, 3).node(); 15909 MacroAssembler::JumpList& genericOrRecoverCase = indexedAndOwnStructureMode ? recoverGenericCase : notFastNamedCases; 15907 15910 15908 15911 // FIXME: We shouldn't generate this code if we know base is not an object. … … 15910 15913 { 15911 15914 if (!m_state.forNode(baseEdge).isType(SpecCell)) 15912 notFastNamedCases.append(m_jit.branchIfNotCell(baseRegs));15915 genericOrRecoverCase.append(m_jit.branchIfNotCell(baseRegs)); 15913 15916 15914 15917 // Check the structure … … 15921 15924 MacroAssembler::Address( 15922 15925 enumeratorGPR, JSPropertyNameEnumerator::cachedStructureIDOffset())); 15923 15924 // FIXME: Maybe we should have a better way to represent Indexed+Named? 15925 if (m_graph.varArgChild(node, 1).node() == m_graph.varArgChild(node, 3).node()) 15926 badStructureSlowPath = badStructure; 15927 else 15928 notFastNamedCases.append(badStructure); 15926 genericOrRecoverCase.append(badStructure); 15929 15927 15930 15928 // Compute the offset … … 15958 15956 ASSERT(generationInfo(node).jsValueRegs() == resultRegs && generationInfo(node).registerFormat() == DataFormatJS); 15959 15957 15960 if ( badStructureSlowPath.isSet()) {15958 if (!recoverGenericCase.empty()) { 15961 15959 if (baseRegs.tagGPR() == InvalidGPRReg) 15962 addSlowPathGenerator(slowPathCall( badStructureSlowPath, this, operationEnumeratorRecoverNameAndGetByVal, resultRegs, TrustedImmPtr::weakPointer(m_graph, m_graph.globalObjectFor(node->origin.semantic)), CCallHelpers::CellValue(baseRegs.payloadGPR()), indexGPR, enumeratorGPR));15960 addSlowPathGenerator(slowPathCall(recoverGenericCase, this, operationEnumeratorRecoverNameAndGetByVal, resultRegs, TrustedImmPtr::weakPointer(m_graph, m_graph.globalObjectFor(node->origin.semantic)), CCallHelpers::CellValue(baseRegs.payloadGPR()), indexGPR, enumeratorGPR)); 15963 15961 else 15964 addSlowPathGenerator(slowPathCall( badStructureSlowPath, this, operationEnumeratorRecoverNameAndGetByVal, resultRegs, TrustedImmPtr::weakPointer(m_graph, m_graph.globalObjectFor(node->origin.semantic)), baseRegs, indexGPR, enumeratorGPR));15962 addSlowPathGenerator(slowPathCall(recoverGenericCase, this, operationEnumeratorRecoverNameAndGetByVal, resultRegs, TrustedImmPtr::weakPointer(m_graph, m_graph.globalObjectFor(node->origin.semantic)), baseRegs, indexGPR, enumeratorGPR)); 15965 15963 } 15966 15964 -
trunk/Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp
r285078 r285167 13682 13682 LBasicBlock genericICBlock = m_out.newBlock(); 13683 13683 LBasicBlock continuation = m_out.newBlock(); 13684 LBasicBlock genericOrRecover; 13685 13686 // FIXME: This is not the cleanest way to say we're using IndexedMode+OwnStructureMode mode. 13687 bool indexedAndOwnStructureMode = indexEdge.node() == propertyNameEdge.node(); 13688 if (indexedAndOwnStructureMode) 13689 genericOrRecover = m_out.newBlock(); 13690 else 13691 genericOrRecover = genericICBlock; 13684 13692 13685 13693 Vector<ValueFromBlock, 4> results; … … 13689 13697 13690 13698 m_out.appendTo(checkIsCellBlock); 13691 m_out.branch(isCell(base, provenType(baseEdge)), usually(checkStructureBlock), rarely(generic ICBlock));13699 m_out.branch(isCell(base, provenType(baseEdge)), usually(checkStructureBlock), rarely(genericOrRecover)); 13692 13700 13693 13701 m_out.appendTo(checkStructureBlock); … … 13701 13709 LValue hasEnumeratorStructure = m_out.equal(structureID, m_out.load32(enumerator, m_heaps.JSPropertyNameEnumerator_cachedStructureID)); 13702 13710 13703 if (indexEdge.node() == propertyNameEdge.node()) { 13704 JSGlobalObject* globalObject = m_graph.globalObjectFor(m_origin.semantic); 13705 LBasicBlock badStructureSlowPath = m_out.newBlock(); 13706 m_out.branch(hasEnumeratorStructure, usually(checkInlineOrOutOfLineBlock), rarely(genericICBlock)); 13707 13708 m_out.appendTo(badStructureSlowPath); 13709 results.append(m_out.anchor(vmCall(Int64, operationEnumeratorRecoverNameAndGetByVal, weakPointer(globalObject), base, index, enumerator))); 13710 } else 13711 m_out.branch(hasEnumeratorStructure, usually(checkInlineOrOutOfLineBlock), rarely(genericICBlock)); 13711 m_out.branch(hasEnumeratorStructure, usually(checkInlineOrOutOfLineBlock), rarely(genericOrRecover)); 13712 13712 13713 13713 m_out.appendTo(checkInlineOrOutOfLineBlock); … … 13753 13753 results.append(m_out.anchor(genericResult)); 13754 13754 m_out.jump(continuation); 13755 13756 if (indexedAndOwnStructureMode) { 13757 m_out.appendTo(genericOrRecover); 13758 results.append(m_out.anchor(vmCall(Int64, operationEnumeratorRecoverNameAndGetByVal, weakPointer(m_graph.globalObjectFor(m_origin.semantic)), base, index, enumerator))); 13759 m_out.jump(continuation); 13760 } 13755 13761 13756 13762 m_out.appendTo(continuation);
Note:
See TracChangeset
for help on using the changeset viewer.