⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 286228 in webkit


Ignore:
Timestamp:
Nov 29, 2021, 11:10:22 AM (5 years ago)
Author:
ysuzuki@apple.com
Message:

[JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode
​https://bugs.webkit.org/show_bug.cgi?id=233571
rdar://85812164

Reviewed by Mark Lam.

JSTests:

  • stress/get-typed-array-length-as-int52-generic.js: Added.

(foo.bar):
(foo):

Source/JavaScriptCore:

If speculation is not populated enough, then GetTypedArrayLengthAsInt52 can get Array::Generic.
In that case, we should convert it to Array::ForceExit as it is done in GetArrayLength.
And blessArrayOperation inserts ForceOSRExit. So GetTypedArrayLengthAsInt52 won't be compiled.

  • dfg/DFGClobberize.h:

(JSC::DFG::clobberize):

  • dfg/DFGFixupPhase.cpp:

(JSC::DFG::FixupPhase::fixupNode):

  • dfg/DFGSpeculativeJIT64.cpp:

(JSC::DFG::SpeculativeJIT::compileGetTypedArrayLengthAsInt52):

  • ftl/FTLLowerDFGToB3.cpp:

(JSC::FTL::DFG::LowerDFGToB3::compileGetTypedArrayLengthAsInt52):

Location:
trunk
Files:
1 added
6 edited

Legend:

Unmodified
Added
Removed
  • trunk/JSTests/ChangeLog

    r286153 r286228  
     12021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     2
     3        [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode
     4        https://bugs.webkit.org/show_bug.cgi?id=233571
     5        rdar://85812164
     6
     7        Reviewed by Mark Lam.
     8
     9        * stress/get-typed-array-length-as-int52-generic.js: Added.
     10        (foo.bar):
     11        (foo):
     12
    1132021-11-24  Michael Catanzaro  <mcatanzaro@gnome.org>
    214
  • trunk/Source/JavaScriptCore/ChangeLog

    r286212 r286228  
     12021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     2
     3        [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode
     4        https://bugs.webkit.org/show_bug.cgi?id=233571
     5        rdar://85812164
     6
     7        Reviewed by Mark Lam.
     8
     9        If speculation is not populated enough, then GetTypedArrayLengthAsInt52 can get Array::Generic.
     10        In that case, we should convert it to Array::ForceExit as it is done in GetArrayLength.
     11        And blessArrayOperation inserts ForceOSRExit. So GetTypedArrayLengthAsInt52 won't be compiled.
     12
     13        * dfg/DFGClobberize.h:
     14        (JSC::DFG::clobberize):
     15        * dfg/DFGFixupPhase.cpp:
     16        (JSC::DFG::FixupPhase::fixupNode):
     17        * dfg/DFGSpeculativeJIT64.cpp:
     18        (JSC::DFG::SpeculativeJIT::compileGetTypedArrayLengthAsInt52):
     19        * ftl/FTLLowerDFGToB3.cpp:
     20        (JSC::FTL::DFG::LowerDFGToB3::compileGetTypedArrayLengthAsInt52):
     21
    1222021-11-29  Zan Dobersek  <zdobersek@igalia.com>
    223
  • trunk/Source/JavaScriptCore/dfg/DFGClobberize.h

    r285651 r286228  
    14571457
    14581458        default:
    1459             ASSERT(mode.isSomeTypedArrayView());
     1459            DFG_ASSERT(graph, node, mode.isSomeTypedArrayView());
    14601460            read(MiscFields);
    14611461            def(HeapLocation(ArrayLengthLoc, MiscFields, node->child1()), LazyNode(node));
    … …  
    14661466    case GetTypedArrayLengthAsInt52: {
    14671467        ArrayMode mode = node->arrayMode();
    1468         RELEASE_ASSERT(mode.isSomeTypedArrayView());
    1469         read(MiscFields);
    1470         def(HeapLocation(TypedArrayLengthInt52Loc, MiscFields, node->child1()), LazyNode(node));
    1471         return;
     1468        DFG_ASSERT(graph, node, mode.isSomeTypedArrayView() || mode.type() == Array::ForceExit);
     1469        switch (mode.type()) {
     1470        case Array::ForceExit:
     1471            write(SideState);
     1472            return;
     1473        default:
     1474            read(MiscFields);
     1475            def(HeapLocation(TypedArrayLengthInt52Loc, MiscFields, node->child1()), LazyNode(node));
     1476            return;
     1477        }
    14721478    }
    14731479
  • trunk/Source/JavaScriptCore/dfg/DFGFixupPhase.cpp

    r285651 r286228  
    21552155            if (arrayMode.type() == Array::Generic)
    21562156                arrayMode = arrayMode.withType(Array::ForceExit);
    2157             ASSERT(arrayMode.isSpecific() || arrayMode.type() == Array::ForceExit);
     2157            DFG_ASSERT(m_graph, node, arrayMode.isSpecific() || arrayMode.type() == Array::ForceExit);
    21582158            node->setArrayMode(arrayMode);
    21592159            blessArrayOperation(node->child1(), Edge(), node->child2(), lengthNeedsStorage);
    … …  
    21652165        case GetTypedArrayLengthAsInt52: {
    21662166            ArrayMode arrayMode = node->arrayMode().refine(m_graph, node, node->child1()->prediction(), ArrayMode::unusedIndexSpeculatedType);
    2167             ASSERT(arrayMode.isSomeTypedArrayView());
     2167            if (arrayMode.type() == Array::Generic)
     2168                arrayMode = arrayMode.withType(Array::ForceExit);
     2169            DFG_ASSERT(m_graph, node, arrayMode.isSomeTypedArrayView() || arrayMode.type() == Array::ForceExit);
    21682170            node->setArrayMode(arrayMode);
    21692171            blessArrayOperation(node->child1(), Edge(), node->child2(), lengthNeedsStorage);
  • trunk/Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp

    r285795 r286228  
    29092909void SpeculativeJIT::compileGetTypedArrayLengthAsInt52(Node* node)
    29102910{
    2911     RELEASE_ASSERT(node->arrayMode().isSomeTypedArrayView());
     2911    // If arrayMode is ForceExit, we would not compile this node and hence, should not have arrived here.
     2912    DFG_ASSERT(m_graph, node, node->arrayMode().isSomeTypedArrayView());
    29122913    SpeculateCellOperand base(this, node->child1());
    29132914    GPRTemporary result(this, Reuse, base);
  • trunk/Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp

    r285850 r286228  
    51085108    void compileGetTypedArrayLengthAsInt52()
    51095109    {
     5110        // If arrayMode is ForceExit, we would not compile this node and hence, should not have arrived here.
    51105111        RELEASE_ASSERT(m_node->arrayMode().isSomeTypedArrayView());
    51115112        // The preprocessor chokes on RELEASE_ASSERT(USE(LARGE_TYPED_ARRAYS)), this is equivalent.
Note: See TracChangeset for help on using the changeset viewer.