Reviewers: Toon Verwaest,
Message:
PTAL
Description:
Map::ReconfigureProperty() should mark map as unstable when there is an
element
kind transition somewhere in the middle of the transition tree.
BUG=chromium:485548
LOG=N
Please review this at https://codereview.chromium.org/1128043005/
Base URL: https://chromium.googlesource.com/v8/v8.git@master
Affected files (+77, -1 lines):
M src/objects.cc
A test/mjsunit/regress/regress-crbug-485548-1.js
A test/mjsunit/regress/regress-crbug-485548-2.js
Index: src/objects.cc
diff --git a/src/objects.cc b/src/objects.cc
index
9a5353fe630eaba44fecc4d3ce558c1babd343d5..03e6994a42b87b5e5abefd722decd437889f3cc7
100644
--- a/src/objects.cc
+++ b/src/objects.cc
@@ -1406,7 +1406,8 @@ void HeapObject::HeapObjectShortPrint(std::ostream&
os) { // NOLINT
}
switch (map()->instance_type()) {
case MAP_TYPE:
- os << "<Map(elements=" << Map::cast(this)->elements_kind() << ")>";
+ os << "<Map(" <<
ElementsKindToString(Map::cast(this)->elements_kind())
+ << ")>";
break;
case FIXED_ARRAY_TYPE:
os << "<FixedArray[" << FixedArray::cast(this)->length() << "]>";
@@ -2958,6 +2959,13 @@ Handle<Map> Map::ReconfigureProperty(Handle<Map>
old_map, int modify_index,
split_kind, old_descriptors->GetKey(split_nof), split_attributes,
*new_descriptors, *new_layout_descriptor);
+ if (from_kind != to_kind) {
+ // There was an elements kind change in the middle of transition tree
and
+ // we reconstructed the tree so that all elements kind transitions are
+ // done at the beginning, therefore the |old_map| is no longer stable.
+ old_map->NotifyLeafMapLayoutChange();
+ }
+
// If |transition_target_deprecated| is true then the transition array
// already contains entry for given descriptor. This means that the
transition
// could be inserted regardless of whether transitions array is full or
not.
Index: test/mjsunit/regress/regress-crbug-485548-1.js
diff --git a/test/mjsunit/regress/regress-crbug-485548-1.js
b/test/mjsunit/regress/regress-crbug-485548-1.js
new file mode 100644
index
0000000000000000000000000000000000000000..035ca5a4ce514441ef51980c40e56a860672f75f
--- /dev/null
+++ b/test/mjsunit/regress/regress-crbug-485548-1.js
@@ -0,0 +1,34 @@
+// Copyright 2015 the V8 project authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+// Flags: --allow-natives-syntax --expose-gc
+
+var inner = new Array();
+inner.a = {x:1};
+assertTrue(%HasFastSmiElements(inner));
+inner[0] = 1.5;
+inner.b = {x:2};
+assertTrue(%HasFastDoubleElements(inner));
+
+function foo(o) {
+ return o.field.a.x;
+}
+
+var outer = {};
+outer.field = inner;
+foo(outer);
+foo(outer);
+foo(outer);
+%OptimizeFunctionOnNextCall(foo);
+foo(outer);
+
+// Generalize representation of field "a" of inner object.
+var v = { get x() { return 0x7fffffff; } };
+inner.a = v;
+
+gc();
+
+var boom = foo(outer);
+print(boom);
+assertEquals(0x7fffffff, boom);
Index: test/mjsunit/regress/regress-crbug-485548-2.js
diff --git a/test/mjsunit/regress/regress-crbug-485548-2.js
b/test/mjsunit/regress/regress-crbug-485548-2.js
new file mode 100644
index
0000000000000000000000000000000000000000..89aaab76e47af19dc0fc2343de17fef7aee9b5be
--- /dev/null
+++ b/test/mjsunit/regress/regress-crbug-485548-2.js
@@ -0,0 +1,34 @@
+// Copyright 2015 the V8 project authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+// Flags: --allow-natives-syntax --expose-gc
+
+var inner = new Array();
+inner.a = {x:1};
+assertTrue(%HasFastSmiElements(inner));
+inner[0] = 1.5;
+inner.b = {x:2};
+assertTrue(%HasFastDoubleElements(inner));
+
+function foo(o) {
+ return o.field.b.x;
+}
+
+var outer = {};
+outer.field = inner;
+foo(outer);
+foo(outer);
+foo(outer);
+%OptimizeFunctionOnNextCall(foo);
+foo(outer);
+
+// Generalize representation of field "b" of inner object.
+var v = { get x() { return 0x7fffffff; } };
+inner.b = v;
+
+gc();
+
+var boom = foo(outer);
+print(boom);
+assertEquals(0x7fffffff, boom);
--
--
v8-dev mailing list
[email protected]
http://groups.google.com/group/v8-dev
---
You received this message because you are subscribed to the Google Groups "v8-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/d/optout.