Reviewers: Jakob,

Message:
Please take a look.

Description:
Do not emit Simulates in HandlePolymorphicElementAccess.

BUG=2653
[email protected]
TEST=mjsunit/regress/regress-2653.js

Please review this at https://chromiumcodereview.appspot.com/14081025/

SVN Base: https://v8.googlecode.com/svn/branches/bleeding_edge

Affected files:
  M src/hydrogen.cc
  A + test/mjsunit/regress/regress-2653.js


Index: src/hydrogen.cc
diff --git a/src/hydrogen.cc b/src/hydrogen.cc
index 97e95e906f03d5126cc5cab9cc17068c1f9f0343..29426236e53bd43453b9c44ebc367faaef8fa889 100644
--- a/src/hydrogen.cc
+++ b/src/hydrogen.cc
@@ -7689,10 +7689,12 @@ HValue* HOptimizedGraphBuilder::HandlePolymorphicElementAccess(
         }

         *has_side_effects |= access->HasObservableSideEffects();
+        // The caller will use has_side_effects and add correct Simulate.
+        access->SetFlag(HValue::kHasNoObservableSideEffects);
         if (position != -1) {
           access->set_position(position);
         }
-        if_jsarray->Goto(join);
+        if_jsarray->GotoNoSimulate(join);

         set_current_block(if_fastobject);
length = AddInstruction(new(zone()) HFixedArrayBaseLength(elements)); @@ -7712,18 +7714,19 @@ HValue* HOptimizedGraphBuilder::HandlePolymorphicElementAccess(
             elements_kind_branch, elements_kind, is_store));
       }
       *has_side_effects |= access->HasObservableSideEffects();
+      // The caller will use has_side_effects and add correct Simulate.
+      access->SetFlag(HValue::kHasNoObservableSideEffects);
if (position != RelocInfo::kNoPosition) access->set_position(position);
       if (!is_store) {
         Push(access);
       }
-      current_block()->Goto(join);
+      current_block()->GotoNoSimulate(join);
       set_current_block(if_false);
     }
   }

   // Deopt if none of the cases matched.
   current_block()->FinishExitWithDeoptimization(HDeoptimize::kNoUses);
-  join->SetJoinId(ast_id);
   set_current_block(join);
   return is_store ? NULL : Pop();
 }
Index: test/mjsunit/regress/regress-2653.js
diff --git a/test/mjsunit/regress/regress-crbug-217858.js b/test/mjsunit/regress/regress-2653.js
similarity index 78%
copy from test/mjsunit/regress/regress-crbug-217858.js
copy to test/mjsunit/regress/regress-2653.js
index 8563e07eee9e1acbcdc8c5c28c461f2d27fad6f1..eb0c6315e6ae5c3d6526398efc03c0d6f5ce5388 100644
--- a/test/mjsunit/regress/regress-crbug-217858.js
+++ b/test/mjsunit/regress/regress-2653.js
@@ -25,16 +25,23 @@
 // (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
 // OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

-// Flags: --allow-natives-syntax
+// Flags: --allow-natives-syntax --deopt_every_n_garbage_collections=1

-var r = /r/;
-var a = "";
-function f() {
-  %OptimizeFunctionOnNextCall(f, "osr");
-  for (var i = 0; i < 1000000; i++) {
-    a += i.toString();
-    r[r] = function() {};
+function foo(a, b) {
+  var l = a.length;
+  var array = new Array(l);
+  for (var k = 0; k < l; k++) {
+    array[k] = 120;
   }
+  var result = new Array(l);
+  for (var i = 0; i < l; i++) {
+    result[i] = array[i];
+  }
+  return result;
 }

-f();
+a = "xxxxxxxxxxxxxxxxxxxxxxxxx";
+while (a.length < 100000) a = a + a;
+foo(a, []);
+%OptimizeFunctionOnNextCall(foo)
+foo(a, []);


--
--
v8-dev mailing list
[email protected]
http://groups.google.com/group/v8-dev
--- You received this message because you are subscribed to the Google Groups "v8-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.


Reply via email to