Reviewers: Jakob,
Message:
Please take a look.
Description:
Do not emit Simulates in HandlePolymorphicElementAccess.
BUG=2653
[email protected]
TEST=mjsunit/regress/regress-2653.js
Please review this at https://chromiumcodereview.appspot.com/14081025/
SVN Base: https://v8.googlecode.com/svn/branches/bleeding_edge
Affected files:
M src/hydrogen.cc
A + test/mjsunit/regress/regress-2653.js
Index: src/hydrogen.cc
diff --git a/src/hydrogen.cc b/src/hydrogen.cc
index
97e95e906f03d5126cc5cab9cc17068c1f9f0343..29426236e53bd43453b9c44ebc367faaef8fa889
100644
--- a/src/hydrogen.cc
+++ b/src/hydrogen.cc
@@ -7689,10 +7689,12 @@ HValue*
HOptimizedGraphBuilder::HandlePolymorphicElementAccess(
}
*has_side_effects |= access->HasObservableSideEffects();
+ // The caller will use has_side_effects and add correct Simulate.
+ access->SetFlag(HValue::kHasNoObservableSideEffects);
if (position != -1) {
access->set_position(position);
}
- if_jsarray->Goto(join);
+ if_jsarray->GotoNoSimulate(join);
set_current_block(if_fastobject);
length = AddInstruction(new(zone())
HFixedArrayBaseLength(elements));
@@ -7712,18 +7714,19 @@ HValue*
HOptimizedGraphBuilder::HandlePolymorphicElementAccess(
elements_kind_branch, elements_kind, is_store));
}
*has_side_effects |= access->HasObservableSideEffects();
+ // The caller will use has_side_effects and add correct Simulate.
+ access->SetFlag(HValue::kHasNoObservableSideEffects);
if (position != RelocInfo::kNoPosition)
access->set_position(position);
if (!is_store) {
Push(access);
}
- current_block()->Goto(join);
+ current_block()->GotoNoSimulate(join);
set_current_block(if_false);
}
}
// Deopt if none of the cases matched.
current_block()->FinishExitWithDeoptimization(HDeoptimize::kNoUses);
- join->SetJoinId(ast_id);
set_current_block(join);
return is_store ? NULL : Pop();
}
Index: test/mjsunit/regress/regress-2653.js
diff --git a/test/mjsunit/regress/regress-crbug-217858.js
b/test/mjsunit/regress/regress-2653.js
similarity index 78%
copy from test/mjsunit/regress/regress-crbug-217858.js
copy to test/mjsunit/regress/regress-2653.js
index
8563e07eee9e1acbcdc8c5c28c461f2d27fad6f1..eb0c6315e6ae5c3d6526398efc03c0d6f5ce5388
100644
--- a/test/mjsunit/regress/regress-crbug-217858.js
+++ b/test/mjsunit/regress/regress-2653.js
@@ -25,16 +25,23 @@
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
-// Flags: --allow-natives-syntax
+// Flags: --allow-natives-syntax --deopt_every_n_garbage_collections=1
-var r = /r/;
-var a = "";
-function f() {
- %OptimizeFunctionOnNextCall(f, "osr");
- for (var i = 0; i < 1000000; i++) {
- a += i.toString();
- r[r] = function() {};
+function foo(a, b) {
+ var l = a.length;
+ var array = new Array(l);
+ for (var k = 0; k < l; k++) {
+ array[k] = 120;
}
+ var result = new Array(l);
+ for (var i = 0; i < l; i++) {
+ result[i] = array[i];
+ }
+ return result;
}
-f();
+a = "xxxxxxxxxxxxxxxxxxxxxxxxx";
+while (a.length < 100000) a = a + a;
+foo(a, []);
+%OptimizeFunctionOnNextCall(foo)
+foo(a, []);
--
--
v8-dev mailing list
[email protected]
http://groups.google.com/group/v8-dev
---
You received this message because you are subscribed to the Google Groups "v8-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.