⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 287623 in webkit


Ignore:
Timestamp:
Jan 5, 2022, 10:20:50 AM (5 years ago)
Author:
Russell Epstein
Message:

Cherry-pick r286228. rdar://problem/87125189

[JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode
​https://bugs.webkit.org/show_bug.cgi?id=233571
rdar://85812164

Reviewed by Mark Lam.

JSTests:

  • stress/get-typed-array-length-as-int52-generic.js: Added. (foo.bar): (foo):

Source/JavaScriptCore:

If speculation is not populated enough, then GetTypedArrayLengthAsInt52 can get Array::Generic.
In that case, we should convert it to Array::ForceExit as it is done in GetArrayLength.
And blessArrayOperation inserts ForceOSRExit. So GetTypedArrayLengthAsInt52 won't be compiled.

  • dfg/DFGClobberize.h: (JSC::DFG::clobberize):
  • dfg/DFGFixupPhase.cpp: (JSC::DFG::FixupPhase::fixupNode):
  • dfg/DFGSpeculativeJIT64.cpp: (JSC::DFG::SpeculativeJIT::compileGetTypedArrayLengthAsInt52):
  • ftl/FTLLowerDFGToB3.cpp: (JSC::FTL::DFG::LowerDFGToB3::compileGetTypedArrayLengthAsInt52):

git-svn-id: ​https://svn.webkit.org/repository/webkit/trunk@286228 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Location:
branches/safari-612-branch
Files:
1 added
6 edited

Legend:

Unmodified
Added
Removed
  • branches/safari-612-branch/JSTests/ChangeLog

    r287622 r287623  
     12022-01-05  Russell Epstein  <repstein@apple.com>
     2
     3        Cherry-pick r286228. rdar://problem/87125189
     4
     5    [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode
     6    https://bugs.webkit.org/show_bug.cgi?id=233571
     7    rdar://85812164
     8   
     9    Reviewed by Mark Lam.
     10   
     11    JSTests:
     12   
     13    * stress/get-typed-array-length-as-int52-generic.js: Added.
     14    (foo.bar):
     15    (foo):
     16   
     17    Source/JavaScriptCore:
     18   
     19    If speculation is not populated enough, then GetTypedArrayLengthAsInt52 can get Array::Generic.
     20    In that case, we should convert it to Array::ForceExit as it is done in GetArrayLength.
     21    And blessArrayOperation inserts ForceOSRExit. So GetTypedArrayLengthAsInt52 won't be compiled.
     22   
     23    * dfg/DFGClobberize.h:
     24    (JSC::DFG::clobberize):
     25    * dfg/DFGFixupPhase.cpp:
     26    (JSC::DFG::FixupPhase::fixupNode):
     27    * dfg/DFGSpeculativeJIT64.cpp:
     28    (JSC::DFG::SpeculativeJIT::compileGetTypedArrayLengthAsInt52):
     29    * ftl/FTLLowerDFGToB3.cpp:
     30    (JSC::FTL::DFG::LowerDFGToB3::compileGetTypedArrayLengthAsInt52):
     31   
     32    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286228 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     33
     34    2021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     35
     36            [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode
     37            https://bugs.webkit.org/show_bug.cgi?id=233571
     38            rdar://85812164
     39
     40            Reviewed by Mark Lam.
     41
     42            * stress/get-typed-array-length-as-int52-generic.js: Added.
     43            (foo.bar):
     44            (foo):
     45
    1462022-01-05  Russell Epstein  <repstein@apple.com>
    247
  • branches/safari-612-branch/Source/JavaScriptCore/ChangeLog

    r287621 r287623  
     12022-01-05  Russell Epstein  <repstein@apple.com>
     2
     3        Cherry-pick r286228. rdar://problem/87125189
     4
     5    [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode
     6    https://bugs.webkit.org/show_bug.cgi?id=233571
     7    rdar://85812164
     8   
     9    Reviewed by Mark Lam.
     10   
     11    JSTests:
     12   
     13    * stress/get-typed-array-length-as-int52-generic.js: Added.
     14    (foo.bar):
     15    (foo):
     16   
     17    Source/JavaScriptCore:
     18   
     19    If speculation is not populated enough, then GetTypedArrayLengthAsInt52 can get Array::Generic.
     20    In that case, we should convert it to Array::ForceExit as it is done in GetArrayLength.
     21    And blessArrayOperation inserts ForceOSRExit. So GetTypedArrayLengthAsInt52 won't be compiled.
     22   
     23    * dfg/DFGClobberize.h:
     24    (JSC::DFG::clobberize):
     25    * dfg/DFGFixupPhase.cpp:
     26    (JSC::DFG::FixupPhase::fixupNode):
     27    * dfg/DFGSpeculativeJIT64.cpp:
     28    (JSC::DFG::SpeculativeJIT::compileGetTypedArrayLengthAsInt52):
     29    * ftl/FTLLowerDFGToB3.cpp:
     30    (JSC::FTL::DFG::LowerDFGToB3::compileGetTypedArrayLengthAsInt52):
     31   
     32    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286228 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     33
     34    2021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     35
     36            [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode
     37            https://bugs.webkit.org/show_bug.cgi?id=233571
     38            rdar://85812164
     39
     40            Reviewed by Mark Lam.
     41
     42            If speculation is not populated enough, then GetTypedArrayLengthAsInt52 can get Array::Generic.
     43            In that case, we should convert it to Array::ForceExit as it is done in GetArrayLength.
     44            And blessArrayOperation inserts ForceOSRExit. So GetTypedArrayLengthAsInt52 won't be compiled.
     45
     46            * dfg/DFGClobberize.h:
     47            (JSC::DFG::clobberize):
     48            * dfg/DFGFixupPhase.cpp:
     49            (JSC::DFG::FixupPhase::fixupNode):
     50            * dfg/DFGSpeculativeJIT64.cpp:
     51            (JSC::DFG::SpeculativeJIT::compileGetTypedArrayLengthAsInt52):
     52            * ftl/FTLLowerDFGToB3.cpp:
     53            (JSC::FTL::DFG::LowerDFGToB3::compileGetTypedArrayLengthAsInt52):
     54
    1552022-01-05  Russell Epstein  <repstein@apple.com>
    256
  • branches/safari-612-branch/Source/JavaScriptCore/dfg/DFGClobberize.h

    r285298 r287623  
    14451445
    14461446        default:
    1447             ASSERT(mode.isSomeTypedArrayView());
     1447            DFG_ASSERT(graph, node, mode.isSomeTypedArrayView());
    14481448            read(MiscFields);
    14491449            def(HeapLocation(ArrayLengthLoc, MiscFields, node->child1()), LazyNode(node));
    … …  
    14541454    case GetTypedArrayLengthAsInt52: {
    14551455        ArrayMode mode = node->arrayMode();
    1456         RELEASE_ASSERT(mode.isSomeTypedArrayView());
    1457         read(MiscFields);
    1458         def(HeapLocation(TypedArrayLengthInt52Loc, MiscFields, node->child1()), LazyNode(node));
    1459         return;
     1456        DFG_ASSERT(graph, node, mode.isSomeTypedArrayView() || mode.type() == Array::ForceExit);
     1457        switch (mode.type()) {
     1458        case Array::ForceExit:
     1459            write(SideState);
     1460            return;
     1461        default:
     1462            read(MiscFields);
     1463            def(HeapLocation(TypedArrayLengthInt52Loc, MiscFields, node->child1()), LazyNode(node));
     1464            return;
     1465        }
    14601466    }
    14611467
  • branches/safari-612-branch/Source/JavaScriptCore/dfg/DFGFixupPhase.cpp

    r285453 r287623  
    21602160            if (arrayMode.type() == Array::Generic)
    21612161                arrayMode = arrayMode.withType(Array::ForceExit);
    2162             ASSERT(arrayMode.isSpecific() || arrayMode.type() == Array::ForceExit);
     2162            DFG_ASSERT(m_graph, node, arrayMode.isSpecific() || arrayMode.type() == Array::ForceExit);
    21632163            node->setArrayMode(arrayMode);
    21642164            blessArrayOperation(node->child1(), Edge(), node->child2(), lengthNeedsStorage);
    … …  
    21702170        case GetTypedArrayLengthAsInt52: {
    21712171            ArrayMode arrayMode = node->arrayMode().refine(m_graph, node, node->child1()->prediction(), ArrayMode::unusedIndexSpeculatedType);
    2172             ASSERT(arrayMode.isSomeTypedArrayView());
     2172            if (arrayMode.type() == Array::Generic)
     2173                arrayMode = arrayMode.withType(Array::ForceExit);
     2174            DFG_ASSERT(m_graph, node, arrayMode.isSomeTypedArrayView() || arrayMode.type() == Array::ForceExit);
    21732175            node->setArrayMode(arrayMode);
    21742176            blessArrayOperation(node->child1(), Edge(), node->child2(), lengthNeedsStorage);
  • branches/safari-612-branch/Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp

    r285542 r287623  
    26332633void SpeculativeJIT::compileGetTypedArrayLengthAsInt52(Node* node)
    26342634{
    2635     RELEASE_ASSERT(node->arrayMode().isSomeTypedArrayView());
     2635    // If arrayMode is ForceExit, we would not compile this node and hence, should not have arrived here.
     2636    DFG_ASSERT(m_graph, node, node->arrayMode().isSomeTypedArrayView());
    26362637    SpeculateCellOperand base(this, node->child1());
    26372638    GPRTemporary result(this, Reuse, base);
  • branches/safari-612-branch/Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp

    r285541 r287623  
    50915091    void compileGetTypedArrayLengthAsInt52()
    50925092    {
     5093        // If arrayMode is ForceExit, we would not compile this node and hence, should not have arrived here.
    50935094        RELEASE_ASSERT(m_node->arrayMode().isSomeTypedArrayView());
    50945095        // The preprocessor chokes on RELEASE_ASSERT(USE(LARGE_TYPED_ARRAYS)), this is equivalent.
Note: See TracChangeset for help on using the changeset viewer.