Title: [254597] branches/safari-609-branch
Revision
254597
Author
[email protected]
Date
2020-01-15 11:15:05 -0800 (Wed, 15 Jan 2020)

Log Message

Cherry-pick r254188. rdar://problem/58553146

    AI rule for ValueMod/ValueDiv produce constants with the wrong format when the result can be an int32
    https://bugs.webkit.org/show_bug.cgi?id=205906
    <rdar://problem/56108519>

    Reviewed by Yusuke Suzuki.

    JSTests:

    * stress/ai-value-div-should-result-in-constant-int-where-possible.js: Added.
    (foo.bar.f):
    (foo.):
    (foo):
    * stress/ai-value-mod-should-result-in-constant-int-where-possible.js: Added.
    (foo.bar.f):
    (foo.):
    (foo):

    Source/_javascript_Core:

    The runtime code for ValueMod and ValueDiv produces an int32 when the result
    is of int32 value. However, the AI was saying the result is in double format.
    This patch fixes AI to produce a JSValue in the right format.

    * dfg/DFGAbstractInterpreterInlines.h:
    (JSC::DFG::AbstractInterpreter<AbstractStateType>::handleConstantDivOp):

    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@254188 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Modified Paths

Added Paths

Diff

Modified: branches/safari-609-branch/JSTests/ChangeLog (254596 => 254597)


--- branches/safari-609-branch/JSTests/ChangeLog	2020-01-15 19:15:02 UTC (rev 254596)
+++ branches/safari-609-branch/JSTests/ChangeLog	2020-01-15 19:15:05 UTC (rev 254597)
@@ -1,3 +1,53 @@
+2020-01-14  Alan Coon  <[email protected]>
+
+        Cherry-pick r254188. rdar://problem/58553146
+
+    AI rule for ValueMod/ValueDiv produce constants with the wrong format when the result can be an int32
+    https://bugs.webkit.org/show_bug.cgi?id=205906
+    <rdar://problem/56108519>
+    
+    Reviewed by Yusuke Suzuki.
+    
+    JSTests:
+    
+    * stress/ai-value-div-should-result-in-constant-int-where-possible.js: Added.
+    (foo.bar.f):
+    (foo.):
+    (foo):
+    * stress/ai-value-mod-should-result-in-constant-int-where-possible.js: Added.
+    (foo.bar.f):
+    (foo.):
+    (foo):
+    
+    Source/_javascript_Core:
+    
+    The runtime code for ValueMod and ValueDiv produces an int32 when the result
+    is of int32 value. However, the AI was saying the result is in double format.
+    This patch fixes AI to produce a JSValue in the right format.
+    
+    * dfg/DFGAbstractInterpreterInlines.h:
+    (JSC::DFG::AbstractInterpreter<AbstractStateType>::handleConstantDivOp):
+    
+    
+    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@254188 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+    2020-01-07  Saam Barati  <[email protected]>
+
+            AI rule for ValueMod/ValueDiv produce constants with the wrong format when the result can be an int32
+            https://bugs.webkit.org/show_bug.cgi?id=205906
+            <rdar://problem/56108519>
+
+            Reviewed by Yusuke Suzuki.
+
+            * stress/ai-value-div-should-result-in-constant-int-where-possible.js: Added.
+            (foo.bar.f):
+            (foo.):
+            (foo):
+            * stress/ai-value-mod-should-result-in-constant-int-where-possible.js: Added.
+            (foo.bar.f):
+            (foo.):
+            (foo):
+
 2020-01-13  Alan Coon  <[email protected]>
 
         Cherry-pick r254349. rdar://problem/58529720

Added: branches/safari-609-branch/JSTests/stress/ai-value-div-should-result-in-constant-int-where-possible.js (0 => 254597)


--- branches/safari-609-branch/JSTests/stress/ai-value-div-should-result-in-constant-int-where-possible.js	                        (rev 0)
+++ branches/safari-609-branch/JSTests/stress/ai-value-div-should-result-in-constant-int-where-possible.js	2020-01-15 19:15:05 UTC (rev 254597)
@@ -0,0 +1,21 @@
+//@ runDefault("--useRandomizingFuzzerAgent=1", "--validateAbstractInterpreterState=1", "--jitPolicyScale=0", "--useConcurrentJIT=0")
+
+function foo() {
+    for (let i = 0; i < 3; i++) {
+        const o = {};
+        function bar(a0) {
+            let x;
+            do {
+                function f() { z; }
+                x = o;
+                const y = typeof x === a0;
+                [a0, 0.1];
+                const z = 0 + y;
+                const c = z / 1.0 + 0;
+            } while (!x);
+        }
+        bar(0);
+    }
+}
+
+foo();

Added: branches/safari-609-branch/JSTests/stress/ai-value-mod-should-result-in-constant-int-where-possible.js (0 => 254597)


--- branches/safari-609-branch/JSTests/stress/ai-value-mod-should-result-in-constant-int-where-possible.js	                        (rev 0)
+++ branches/safari-609-branch/JSTests/stress/ai-value-mod-should-result-in-constant-int-where-possible.js	2020-01-15 19:15:05 UTC (rev 254597)
@@ -0,0 +1,21 @@
+//@ runDefault("--useRandomizingFuzzerAgent=1", "--validateAbstractInterpreterState=1", "--jitPolicyScale=0", "--useConcurrentJIT=0")
+
+function foo() {
+    for (let i = 0; i < 3; i++) {
+        const o = {};
+        function bar(a0) {
+            let x;
+            do {
+                function f() { z; }
+                x = o;
+                const y = typeof x === a0;
+                [a0, 0.1];
+                const z = 0 + y;
+                const c = z / 1.0 + 0;
+            } while (!x);
+        }
+        bar(0);
+    }
+}
+
+foo();

Modified: branches/safari-609-branch/Source/_javascript_Core/ChangeLog (254596 => 254597)


--- branches/safari-609-branch/Source/_javascript_Core/ChangeLog	2020-01-15 19:15:02 UTC (rev 254596)
+++ branches/safari-609-branch/Source/_javascript_Core/ChangeLog	2020-01-15 19:15:05 UTC (rev 254597)
@@ -1,5 +1,53 @@
 2020-01-14  Alan Coon  <[email protected]>
 
+        Cherry-pick r254188. rdar://problem/58553146
+
+    AI rule for ValueMod/ValueDiv produce constants with the wrong format when the result can be an int32
+    https://bugs.webkit.org/show_bug.cgi?id=205906
+    <rdar://problem/56108519>
+    
+    Reviewed by Yusuke Suzuki.
+    
+    JSTests:
+    
+    * stress/ai-value-div-should-result-in-constant-int-where-possible.js: Added.
+    (foo.bar.f):
+    (foo.):
+    (foo):
+    * stress/ai-value-mod-should-result-in-constant-int-where-possible.js: Added.
+    (foo.bar.f):
+    (foo.):
+    (foo):
+    
+    Source/_javascript_Core:
+    
+    The runtime code for ValueMod and ValueDiv produces an int32 when the result
+    is of int32 value. However, the AI was saying the result is in double format.
+    This patch fixes AI to produce a JSValue in the right format.
+    
+    * dfg/DFGAbstractInterpreterInlines.h:
+    (JSC::DFG::AbstractInterpreter<AbstractStateType>::handleConstantDivOp):
+    
+    
+    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@254188 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+    2020-01-07  Saam Barati  <[email protected]>
+
+            AI rule for ValueMod/ValueDiv produce constants with the wrong format when the result can be an int32
+            https://bugs.webkit.org/show_bug.cgi?id=205906
+            <rdar://problem/56108519>
+
+            Reviewed by Yusuke Suzuki.
+
+            The runtime code for ValueMod and ValueDiv produces an int32 when the result
+            is of int32 value. However, the AI was saying the result is in double format.
+            This patch fixes AI to produce a JSValue in the right format.
+
+            * dfg/DFGAbstractInterpreterInlines.h:
+            (JSC::DFG::AbstractInterpreter<AbstractStateType>::handleConstantDivOp):
+
+2020-01-14  Alan Coon  <[email protected]>
+
         Cherry-pick r254152. rdar://problem/58552854
 
     [JSC] Remove vm accessor in JSVirtualMachine to reduce binary size

Modified: branches/safari-609-branch/Source/_javascript_Core/dfg/DFGAbstractInterpreterInlines.h (254596 => 254597)


--- branches/safari-609-branch/Source/_javascript_Core/dfg/DFGAbstractInterpreterInlines.h	2020-01-15 19:15:02 UTC (rev 254596)
+++ branches/safari-609-branch/Source/_javascript_Core/dfg/DFGAbstractInterpreterInlines.h	2020-01-15 19:15:05 UTC (rev 254597)
@@ -323,10 +323,17 @@
             if (isClobbering)
                 didFoldClobberWorld();
 
-            if (isDivOperation)
-                setConstant(node, jsDoubleNumber(left.asNumber() / right.asNumber()));
-            else
-                setConstant(node, jsDoubleNumber(fmod(left.asNumber(), right.asNumber())));
+            if (isDivOperation) {
+                if (op == ValueDiv)
+                    setConstant(node, jsNumber(left.asNumber() / right.asNumber()));
+                else
+                    setConstant(node, jsDoubleNumber(left.asNumber() / right.asNumber()));
+            } else {
+                if (op == ValueMod)
+                    setConstant(node, jsNumber(fmod(left.asNumber(), right.asNumber())));
+                else
+                    setConstant(node, jsDoubleNumber(fmod(left.asNumber(), right.asNumber())));
+            }
 
             return true;
         }
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to