Changeset 286228 in webkit
- Timestamp:
- Nov 29, 2021, 11:10:22 AM (5 years ago)
- Location:
- trunk
- Files:
-
- 1 added
- 6 edited
-
JSTests/ChangeLog (modified) (1 diff)
-
JSTests/stress/get-typed-array-length-as-int52-generic.js (added)
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGClobberize.h (modified) (2 diffs)
-
Source/JavaScriptCore/dfg/DFGFixupPhase.cpp (modified) (2 diffs)
-
Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp (modified) (1 diff)
-
Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
trunk/JSTests/ChangeLog
r286153 r286228 1 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 2 3 [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode 4 https://bugs.webkit.org/show_bug.cgi?id=233571 5 rdar://85812164 6 7 Reviewed by Mark Lam. 8 9 * stress/get-typed-array-length-as-int52-generic.js: Added. 10 (foo.bar): 11 (foo): 12 1 13 2021-11-24 Michael Catanzaro <mcatanzaro@gnome.org> 2 14 -
trunk/Source/JavaScriptCore/ChangeLog
r286212 r286228 1 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 2 3 [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode 4 https://bugs.webkit.org/show_bug.cgi?id=233571 5 rdar://85812164 6 7 Reviewed by Mark Lam. 8 9 If speculation is not populated enough, then GetTypedArrayLengthAsInt52 can get Array::Generic. 10 In that case, we should convert it to Array::ForceExit as it is done in GetArrayLength. 11 And blessArrayOperation inserts ForceOSRExit. So GetTypedArrayLengthAsInt52 won't be compiled. 12 13 * dfg/DFGClobberize.h: 14 (JSC::DFG::clobberize): 15 * dfg/DFGFixupPhase.cpp: 16 (JSC::DFG::FixupPhase::fixupNode): 17 * dfg/DFGSpeculativeJIT64.cpp: 18 (JSC::DFG::SpeculativeJIT::compileGetTypedArrayLengthAsInt52): 19 * ftl/FTLLowerDFGToB3.cpp: 20 (JSC::FTL::DFG::LowerDFGToB3::compileGetTypedArrayLengthAsInt52): 21 1 22 2021-11-29 Zan Dobersek <zdobersek@igalia.com> 2 23 -
trunk/Source/JavaScriptCore/dfg/DFGClobberize.h
r285651 r286228 1457 1457 1458 1458 default: 1459 ASSERT(mode.isSomeTypedArrayView());1459 DFG_ASSERT(graph, node, mode.isSomeTypedArrayView()); 1460 1460 read(MiscFields); 1461 1461 def(HeapLocation(ArrayLengthLoc, MiscFields, node->child1()), LazyNode(node)); … … 1466 1466 case GetTypedArrayLengthAsInt52: { 1467 1467 ArrayMode mode = node->arrayMode(); 1468 RELEASE_ASSERT(mode.isSomeTypedArrayView()); 1469 read(MiscFields); 1470 def(HeapLocation(TypedArrayLengthInt52Loc, MiscFields, node->child1()), LazyNode(node)); 1471 return; 1468 DFG_ASSERT(graph, node, mode.isSomeTypedArrayView() || mode.type() == Array::ForceExit); 1469 switch (mode.type()) { 1470 case Array::ForceExit: 1471 write(SideState); 1472 return; 1473 default: 1474 read(MiscFields); 1475 def(HeapLocation(TypedArrayLengthInt52Loc, MiscFields, node->child1()), LazyNode(node)); 1476 return; 1477 } 1472 1478 } 1473 1479 -
trunk/Source/JavaScriptCore/dfg/DFGFixupPhase.cpp
r285651 r286228 2155 2155 if (arrayMode.type() == Array::Generic) 2156 2156 arrayMode = arrayMode.withType(Array::ForceExit); 2157 ASSERT(arrayMode.isSpecific() || arrayMode.type() == Array::ForceExit);2157 DFG_ASSERT(m_graph, node, arrayMode.isSpecific() || arrayMode.type() == Array::ForceExit); 2158 2158 node->setArrayMode(arrayMode); 2159 2159 blessArrayOperation(node->child1(), Edge(), node->child2(), lengthNeedsStorage); … … 2165 2165 case GetTypedArrayLengthAsInt52: { 2166 2166 ArrayMode arrayMode = node->arrayMode().refine(m_graph, node, node->child1()->prediction(), ArrayMode::unusedIndexSpeculatedType); 2167 ASSERT(arrayMode.isSomeTypedArrayView()); 2167 if (arrayMode.type() == Array::Generic) 2168 arrayMode = arrayMode.withType(Array::ForceExit); 2169 DFG_ASSERT(m_graph, node, arrayMode.isSomeTypedArrayView() || arrayMode.type() == Array::ForceExit); 2168 2170 node->setArrayMode(arrayMode); 2169 2171 blessArrayOperation(node->child1(), Edge(), node->child2(), lengthNeedsStorage); -
trunk/Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp
r285795 r286228 2909 2909 void SpeculativeJIT::compileGetTypedArrayLengthAsInt52(Node* node) 2910 2910 { 2911 RELEASE_ASSERT(node->arrayMode().isSomeTypedArrayView()); 2911 // If arrayMode is ForceExit, we would not compile this node and hence, should not have arrived here. 2912 DFG_ASSERT(m_graph, node, node->arrayMode().isSomeTypedArrayView()); 2912 2913 SpeculateCellOperand base(this, node->child1()); 2913 2914 GPRTemporary result(this, Reuse, base); -
trunk/Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp
r285850 r286228 5108 5108 void compileGetTypedArrayLengthAsInt52() 5109 5109 { 5110 // If arrayMode is ForceExit, we would not compile this node and hence, should not have arrived here. 5110 5111 RELEASE_ASSERT(m_node->arrayMode().isSomeTypedArrayView()); 5111 5112 // The preprocessor chokes on RELEASE_ASSERT(USE(LARGE_TYPED_ARRAYS)), this is equivalent.
Note:
See TracChangeset
for help on using the changeset viewer.