Changeset 287623 in webkit
- Timestamp:
- Jan 5, 2022, 10:20:50 AM (5 years ago)
- Location:
- branches/safari-612-branch
- Files:
-
- 1 added
- 6 edited
-
JSTests/ChangeLog (modified) (1 diff)
-
JSTests/stress/get-typed-array-length-as-int52-generic.js (added)
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGClobberize.h (modified) (2 diffs)
-
Source/JavaScriptCore/dfg/DFGFixupPhase.cpp (modified) (2 diffs)
-
Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp (modified) (1 diff)
-
Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
branches/safari-612-branch/JSTests/ChangeLog
r287622 r287623 1 2022-01-05 Russell Epstein <repstein@apple.com> 2 3 Cherry-pick r286228. rdar://problem/87125189 4 5 [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode 6 https://bugs.webkit.org/show_bug.cgi?id=233571 7 rdar://85812164 8 9 Reviewed by Mark Lam. 10 11 JSTests: 12 13 * stress/get-typed-array-length-as-int52-generic.js: Added. 14 (foo.bar): 15 (foo): 16 17 Source/JavaScriptCore: 18 19 If speculation is not populated enough, then GetTypedArrayLengthAsInt52 can get Array::Generic. 20 In that case, we should convert it to Array::ForceExit as it is done in GetArrayLength. 21 And blessArrayOperation inserts ForceOSRExit. So GetTypedArrayLengthAsInt52 won't be compiled. 22 23 * dfg/DFGClobberize.h: 24 (JSC::DFG::clobberize): 25 * dfg/DFGFixupPhase.cpp: 26 (JSC::DFG::FixupPhase::fixupNode): 27 * dfg/DFGSpeculativeJIT64.cpp: 28 (JSC::DFG::SpeculativeJIT::compileGetTypedArrayLengthAsInt52): 29 * ftl/FTLLowerDFGToB3.cpp: 30 (JSC::FTL::DFG::LowerDFGToB3::compileGetTypedArrayLengthAsInt52): 31 32 git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286228 268f45cc-cd09-0410-ab3c-d52691b4dbfc 33 34 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 35 36 [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode 37 https://bugs.webkit.org/show_bug.cgi?id=233571 38 rdar://85812164 39 40 Reviewed by Mark Lam. 41 42 * stress/get-typed-array-length-as-int52-generic.js: Added. 43 (foo.bar): 44 (foo): 45 1 46 2022-01-05 Russell Epstein <repstein@apple.com> 2 47 -
branches/safari-612-branch/Source/JavaScriptCore/ChangeLog
r287621 r287623 1 2022-01-05 Russell Epstein <repstein@apple.com> 2 3 Cherry-pick r286228. rdar://problem/87125189 4 5 [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode 6 https://bugs.webkit.org/show_bug.cgi?id=233571 7 rdar://85812164 8 9 Reviewed by Mark Lam. 10 11 JSTests: 12 13 * stress/get-typed-array-length-as-int52-generic.js: Added. 14 (foo.bar): 15 (foo): 16 17 Source/JavaScriptCore: 18 19 If speculation is not populated enough, then GetTypedArrayLengthAsInt52 can get Array::Generic. 20 In that case, we should convert it to Array::ForceExit as it is done in GetArrayLength. 21 And blessArrayOperation inserts ForceOSRExit. So GetTypedArrayLengthAsInt52 won't be compiled. 22 23 * dfg/DFGClobberize.h: 24 (JSC::DFG::clobberize): 25 * dfg/DFGFixupPhase.cpp: 26 (JSC::DFG::FixupPhase::fixupNode): 27 * dfg/DFGSpeculativeJIT64.cpp: 28 (JSC::DFG::SpeculativeJIT::compileGetTypedArrayLengthAsInt52): 29 * ftl/FTLLowerDFGToB3.cpp: 30 (JSC::FTL::DFG::LowerDFGToB3::compileGetTypedArrayLengthAsInt52): 31 32 git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286228 268f45cc-cd09-0410-ab3c-d52691b4dbfc 33 34 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 35 36 [JSC] GetTypedArrayLengthAsInt52 can get Array::Generic ArrayMode 37 https://bugs.webkit.org/show_bug.cgi?id=233571 38 rdar://85812164 39 40 Reviewed by Mark Lam. 41 42 If speculation is not populated enough, then GetTypedArrayLengthAsInt52 can get Array::Generic. 43 In that case, we should convert it to Array::ForceExit as it is done in GetArrayLength. 44 And blessArrayOperation inserts ForceOSRExit. So GetTypedArrayLengthAsInt52 won't be compiled. 45 46 * dfg/DFGClobberize.h: 47 (JSC::DFG::clobberize): 48 * dfg/DFGFixupPhase.cpp: 49 (JSC::DFG::FixupPhase::fixupNode): 50 * dfg/DFGSpeculativeJIT64.cpp: 51 (JSC::DFG::SpeculativeJIT::compileGetTypedArrayLengthAsInt52): 52 * ftl/FTLLowerDFGToB3.cpp: 53 (JSC::FTL::DFG::LowerDFGToB3::compileGetTypedArrayLengthAsInt52): 54 1 55 2022-01-05 Russell Epstein <repstein@apple.com> 2 56 -
branches/safari-612-branch/Source/JavaScriptCore/dfg/DFGClobberize.h
r285298 r287623 1445 1445 1446 1446 default: 1447 ASSERT(mode.isSomeTypedArrayView());1447 DFG_ASSERT(graph, node, mode.isSomeTypedArrayView()); 1448 1448 read(MiscFields); 1449 1449 def(HeapLocation(ArrayLengthLoc, MiscFields, node->child1()), LazyNode(node)); … … 1454 1454 case GetTypedArrayLengthAsInt52: { 1455 1455 ArrayMode mode = node->arrayMode(); 1456 RELEASE_ASSERT(mode.isSomeTypedArrayView()); 1457 read(MiscFields); 1458 def(HeapLocation(TypedArrayLengthInt52Loc, MiscFields, node->child1()), LazyNode(node)); 1459 return; 1456 DFG_ASSERT(graph, node, mode.isSomeTypedArrayView() || mode.type() == Array::ForceExit); 1457 switch (mode.type()) { 1458 case Array::ForceExit: 1459 write(SideState); 1460 return; 1461 default: 1462 read(MiscFields); 1463 def(HeapLocation(TypedArrayLengthInt52Loc, MiscFields, node->child1()), LazyNode(node)); 1464 return; 1465 } 1460 1466 } 1461 1467 -
branches/safari-612-branch/Source/JavaScriptCore/dfg/DFGFixupPhase.cpp
r285453 r287623 2160 2160 if (arrayMode.type() == Array::Generic) 2161 2161 arrayMode = arrayMode.withType(Array::ForceExit); 2162 ASSERT(arrayMode.isSpecific() || arrayMode.type() == Array::ForceExit);2162 DFG_ASSERT(m_graph, node, arrayMode.isSpecific() || arrayMode.type() == Array::ForceExit); 2163 2163 node->setArrayMode(arrayMode); 2164 2164 blessArrayOperation(node->child1(), Edge(), node->child2(), lengthNeedsStorage); … … 2170 2170 case GetTypedArrayLengthAsInt52: { 2171 2171 ArrayMode arrayMode = node->arrayMode().refine(m_graph, node, node->child1()->prediction(), ArrayMode::unusedIndexSpeculatedType); 2172 ASSERT(arrayMode.isSomeTypedArrayView()); 2172 if (arrayMode.type() == Array::Generic) 2173 arrayMode = arrayMode.withType(Array::ForceExit); 2174 DFG_ASSERT(m_graph, node, arrayMode.isSomeTypedArrayView() || arrayMode.type() == Array::ForceExit); 2173 2175 node->setArrayMode(arrayMode); 2174 2176 blessArrayOperation(node->child1(), Edge(), node->child2(), lengthNeedsStorage); -
branches/safari-612-branch/Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp
r285542 r287623 2633 2633 void SpeculativeJIT::compileGetTypedArrayLengthAsInt52(Node* node) 2634 2634 { 2635 RELEASE_ASSERT(node->arrayMode().isSomeTypedArrayView()); 2635 // If arrayMode is ForceExit, we would not compile this node and hence, should not have arrived here. 2636 DFG_ASSERT(m_graph, node, node->arrayMode().isSomeTypedArrayView()); 2636 2637 SpeculateCellOperand base(this, node->child1()); 2637 2638 GPRTemporary result(this, Reuse, base); -
branches/safari-612-branch/Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp
r285541 r287623 5091 5091 void compileGetTypedArrayLengthAsInt52() 5092 5092 { 5093 // If arrayMode is ForceExit, we would not compile this node and hence, should not have arrived here. 5093 5094 RELEASE_ASSERT(m_node->arrayMode().isSomeTypedArrayView()); 5094 5095 // The preprocessor chokes on RELEASE_ASSERT(USE(LARGE_TYPED_ARRAYS)), this is equivalent.
Note:
See TracChangeset
for help on using the changeset viewer.