Reviewers: Toon Verwaest,

Message:
PTAL

Description:
Map::ReconfigureProperty() should mark map as unstable when there is an element
kind transition somewhere in the middle of the transition tree.

BUG=chromium:485548
LOG=N

Please review this at https://codereview.chromium.org/1128043005/

Base URL: https://chromium.googlesource.com/v8/v8.git@master

Affected files (+77, -1 lines):
  M src/objects.cc
  A test/mjsunit/regress/regress-crbug-485548-1.js
  A test/mjsunit/regress/regress-crbug-485548-2.js


Index: src/objects.cc
diff --git a/src/objects.cc b/src/objects.cc
index 9a5353fe630eaba44fecc4d3ce558c1babd343d5..03e6994a42b87b5e5abefd722decd437889f3cc7 100644
--- a/src/objects.cc
+++ b/src/objects.cc
@@ -1406,7 +1406,8 @@ void HeapObject::HeapObjectShortPrint(std::ostream& os) { // NOLINT
   }
   switch (map()->instance_type()) {
     case MAP_TYPE:
-      os << "<Map(elements=" << Map::cast(this)->elements_kind() << ")>";
+ os << "<Map(" << ElementsKindToString(Map::cast(this)->elements_kind())
+         << ")>";
       break;
     case FIXED_ARRAY_TYPE:
       os << "<FixedArray[" << FixedArray::cast(this)->length() << "]>";
@@ -2958,6 +2959,13 @@ Handle<Map> Map::ReconfigureProperty(Handle<Map> old_map, int modify_index,
       split_kind, old_descriptors->GetKey(split_nof), split_attributes,
       *new_descriptors, *new_layout_descriptor);

+  if (from_kind != to_kind) {
+ // There was an elements kind change in the middle of transition tree and
+    // we reconstructed the tree so that all elements kind transitions are
+    // done at the beginning, therefore the |old_map| is no longer stable.
+    old_map->NotifyLeafMapLayoutChange();
+  }
+
   // If |transition_target_deprecated| is true then the transition array
// already contains entry for given descriptor. This means that the transition // could be inserted regardless of whether transitions array is full or not.
Index: test/mjsunit/regress/regress-crbug-485548-1.js
diff --git a/test/mjsunit/regress/regress-crbug-485548-1.js b/test/mjsunit/regress/regress-crbug-485548-1.js
new file mode 100644
index 0000000000000000000000000000000000000000..035ca5a4ce514441ef51980c40e56a860672f75f
--- /dev/null
+++ b/test/mjsunit/regress/regress-crbug-485548-1.js
@@ -0,0 +1,34 @@
+// Copyright 2015 the V8 project authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+// Flags: --allow-natives-syntax --expose-gc
+
+var inner = new Array();
+inner.a = {x:1};
+assertTrue(%HasFastSmiElements(inner));
+inner[0] = 1.5;
+inner.b = {x:2};
+assertTrue(%HasFastDoubleElements(inner));
+
+function foo(o) {
+  return o.field.a.x;
+}
+
+var outer = {};
+outer.field = inner;
+foo(outer);
+foo(outer);
+foo(outer);
+%OptimizeFunctionOnNextCall(foo);
+foo(outer);
+
+// Generalize representation of field "a" of inner object.
+var v = { get x() { return 0x7fffffff; } };
+inner.a = v;
+
+gc();
+
+var boom = foo(outer);
+print(boom);
+assertEquals(0x7fffffff, boom);
Index: test/mjsunit/regress/regress-crbug-485548-2.js
diff --git a/test/mjsunit/regress/regress-crbug-485548-2.js b/test/mjsunit/regress/regress-crbug-485548-2.js
new file mode 100644
index 0000000000000000000000000000000000000000..89aaab76e47af19dc0fc2343de17fef7aee9b5be
--- /dev/null
+++ b/test/mjsunit/regress/regress-crbug-485548-2.js
@@ -0,0 +1,34 @@
+// Copyright 2015 the V8 project authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+// Flags: --allow-natives-syntax --expose-gc
+
+var inner = new Array();
+inner.a = {x:1};
+assertTrue(%HasFastSmiElements(inner));
+inner[0] = 1.5;
+inner.b = {x:2};
+assertTrue(%HasFastDoubleElements(inner));
+
+function foo(o) {
+  return o.field.b.x;
+}
+
+var outer = {};
+outer.field = inner;
+foo(outer);
+foo(outer);
+foo(outer);
+%OptimizeFunctionOnNextCall(foo);
+foo(outer);
+
+// Generalize representation of field "b" of inner object.
+var v = { get x() { return 0x7fffffff; } };
+inner.b = v;
+
+gc();
+
+var boom = foo(outer);
+print(boom);
+assertEquals(0x7fffffff, boom);


--
--
v8-dev mailing list
[email protected]
http://groups.google.com/group/v8-dev
--- You received this message because you are subscribed to the Google Groups "v8-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to