Title: [254597] branches/safari-609-branch
- Revision
- 254597
- Author
- [email protected]
- Date
- 2020-01-15 11:15:05 -0800 (Wed, 15 Jan 2020)
Log Message
Cherry-pick r254188. rdar://problem/58553146
AI rule for ValueMod/ValueDiv produce constants with the wrong format when the result can be an int32
https://bugs.webkit.org/show_bug.cgi?id=205906
<rdar://problem/56108519>
Reviewed by Yusuke Suzuki.
JSTests:
* stress/ai-value-div-should-result-in-constant-int-where-possible.js: Added.
(foo.bar.f):
(foo.):
(foo):
* stress/ai-value-mod-should-result-in-constant-int-where-possible.js: Added.
(foo.bar.f):
(foo.):
(foo):
Source/_javascript_Core:
The runtime code for ValueMod and ValueDiv produces an int32 when the result
is of int32 value. However, the AI was saying the result is in double format.
This patch fixes AI to produce a JSValue in the right format.
* dfg/DFGAbstractInterpreterInlines.h:
(JSC::DFG::AbstractInterpreter<AbstractStateType>::handleConstantDivOp):
git-svn-id: https://svn.webkit.org/repository/webkit/trunk@254188 268f45cc-cd09-0410-ab3c-d52691b4dbfc
Modified Paths
Added Paths
Diff
Modified: branches/safari-609-branch/JSTests/ChangeLog (254596 => 254597)
--- branches/safari-609-branch/JSTests/ChangeLog 2020-01-15 19:15:02 UTC (rev 254596)
+++ branches/safari-609-branch/JSTests/ChangeLog 2020-01-15 19:15:05 UTC (rev 254597)
@@ -1,3 +1,53 @@
+2020-01-14 Alan Coon <[email protected]>
+
+ Cherry-pick r254188. rdar://problem/58553146
+
+ AI rule for ValueMod/ValueDiv produce constants with the wrong format when the result can be an int32
+ https://bugs.webkit.org/show_bug.cgi?id=205906
+ <rdar://problem/56108519>
+
+ Reviewed by Yusuke Suzuki.
+
+ JSTests:
+
+ * stress/ai-value-div-should-result-in-constant-int-where-possible.js: Added.
+ (foo.bar.f):
+ (foo.):
+ (foo):
+ * stress/ai-value-mod-should-result-in-constant-int-where-possible.js: Added.
+ (foo.bar.f):
+ (foo.):
+ (foo):
+
+ Source/_javascript_Core:
+
+ The runtime code for ValueMod and ValueDiv produces an int32 when the result
+ is of int32 value. However, the AI was saying the result is in double format.
+ This patch fixes AI to produce a JSValue in the right format.
+
+ * dfg/DFGAbstractInterpreterInlines.h:
+ (JSC::DFG::AbstractInterpreter<AbstractStateType>::handleConstantDivOp):
+
+
+ git-svn-id: https://svn.webkit.org/repository/webkit/trunk@254188 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+ 2020-01-07 Saam Barati <[email protected]>
+
+ AI rule for ValueMod/ValueDiv produce constants with the wrong format when the result can be an int32
+ https://bugs.webkit.org/show_bug.cgi?id=205906
+ <rdar://problem/56108519>
+
+ Reviewed by Yusuke Suzuki.
+
+ * stress/ai-value-div-should-result-in-constant-int-where-possible.js: Added.
+ (foo.bar.f):
+ (foo.):
+ (foo):
+ * stress/ai-value-mod-should-result-in-constant-int-where-possible.js: Added.
+ (foo.bar.f):
+ (foo.):
+ (foo):
+
2020-01-13 Alan Coon <[email protected]>
Cherry-pick r254349. rdar://problem/58529720
Added: branches/safari-609-branch/JSTests/stress/ai-value-div-should-result-in-constant-int-where-possible.js (0 => 254597)
--- branches/safari-609-branch/JSTests/stress/ai-value-div-should-result-in-constant-int-where-possible.js (rev 0)
+++ branches/safari-609-branch/JSTests/stress/ai-value-div-should-result-in-constant-int-where-possible.js 2020-01-15 19:15:05 UTC (rev 254597)
@@ -0,0 +1,21 @@
+//@ runDefault("--useRandomizingFuzzerAgent=1", "--validateAbstractInterpreterState=1", "--jitPolicyScale=0", "--useConcurrentJIT=0")
+
+function foo() {
+ for (let i = 0; i < 3; i++) {
+ const o = {};
+ function bar(a0) {
+ let x;
+ do {
+ function f() { z; }
+ x = o;
+ const y = typeof x === a0;
+ [a0, 0.1];
+ const z = 0 + y;
+ const c = z / 1.0 + 0;
+ } while (!x);
+ }
+ bar(0);
+ }
+}
+
+foo();
Added: branches/safari-609-branch/JSTests/stress/ai-value-mod-should-result-in-constant-int-where-possible.js (0 => 254597)
--- branches/safari-609-branch/JSTests/stress/ai-value-mod-should-result-in-constant-int-where-possible.js (rev 0)
+++ branches/safari-609-branch/JSTests/stress/ai-value-mod-should-result-in-constant-int-where-possible.js 2020-01-15 19:15:05 UTC (rev 254597)
@@ -0,0 +1,21 @@
+//@ runDefault("--useRandomizingFuzzerAgent=1", "--validateAbstractInterpreterState=1", "--jitPolicyScale=0", "--useConcurrentJIT=0")
+
+function foo() {
+ for (let i = 0; i < 3; i++) {
+ const o = {};
+ function bar(a0) {
+ let x;
+ do {
+ function f() { z; }
+ x = o;
+ const y = typeof x === a0;
+ [a0, 0.1];
+ const z = 0 + y;
+ const c = z / 1.0 + 0;
+ } while (!x);
+ }
+ bar(0);
+ }
+}
+
+foo();
Modified: branches/safari-609-branch/Source/_javascript_Core/ChangeLog (254596 => 254597)
--- branches/safari-609-branch/Source/_javascript_Core/ChangeLog 2020-01-15 19:15:02 UTC (rev 254596)
+++ branches/safari-609-branch/Source/_javascript_Core/ChangeLog 2020-01-15 19:15:05 UTC (rev 254597)
@@ -1,5 +1,53 @@
2020-01-14 Alan Coon <[email protected]>
+ Cherry-pick r254188. rdar://problem/58553146
+
+ AI rule for ValueMod/ValueDiv produce constants with the wrong format when the result can be an int32
+ https://bugs.webkit.org/show_bug.cgi?id=205906
+ <rdar://problem/56108519>
+
+ Reviewed by Yusuke Suzuki.
+
+ JSTests:
+
+ * stress/ai-value-div-should-result-in-constant-int-where-possible.js: Added.
+ (foo.bar.f):
+ (foo.):
+ (foo):
+ * stress/ai-value-mod-should-result-in-constant-int-where-possible.js: Added.
+ (foo.bar.f):
+ (foo.):
+ (foo):
+
+ Source/_javascript_Core:
+
+ The runtime code for ValueMod and ValueDiv produces an int32 when the result
+ is of int32 value. However, the AI was saying the result is in double format.
+ This patch fixes AI to produce a JSValue in the right format.
+
+ * dfg/DFGAbstractInterpreterInlines.h:
+ (JSC::DFG::AbstractInterpreter<AbstractStateType>::handleConstantDivOp):
+
+
+ git-svn-id: https://svn.webkit.org/repository/webkit/trunk@254188 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+ 2020-01-07 Saam Barati <[email protected]>
+
+ AI rule for ValueMod/ValueDiv produce constants with the wrong format when the result can be an int32
+ https://bugs.webkit.org/show_bug.cgi?id=205906
+ <rdar://problem/56108519>
+
+ Reviewed by Yusuke Suzuki.
+
+ The runtime code for ValueMod and ValueDiv produces an int32 when the result
+ is of int32 value. However, the AI was saying the result is in double format.
+ This patch fixes AI to produce a JSValue in the right format.
+
+ * dfg/DFGAbstractInterpreterInlines.h:
+ (JSC::DFG::AbstractInterpreter<AbstractStateType>::handleConstantDivOp):
+
+2020-01-14 Alan Coon <[email protected]>
+
Cherry-pick r254152. rdar://problem/58552854
[JSC] Remove vm accessor in JSVirtualMachine to reduce binary size
Modified: branches/safari-609-branch/Source/_javascript_Core/dfg/DFGAbstractInterpreterInlines.h (254596 => 254597)
--- branches/safari-609-branch/Source/_javascript_Core/dfg/DFGAbstractInterpreterInlines.h 2020-01-15 19:15:02 UTC (rev 254596)
+++ branches/safari-609-branch/Source/_javascript_Core/dfg/DFGAbstractInterpreterInlines.h 2020-01-15 19:15:05 UTC (rev 254597)
@@ -323,10 +323,17 @@
if (isClobbering)
didFoldClobberWorld();
- if (isDivOperation)
- setConstant(node, jsDoubleNumber(left.asNumber() / right.asNumber()));
- else
- setConstant(node, jsDoubleNumber(fmod(left.asNumber(), right.asNumber())));
+ if (isDivOperation) {
+ if (op == ValueDiv)
+ setConstant(node, jsNumber(left.asNumber() / right.asNumber()));
+ else
+ setConstant(node, jsDoubleNumber(left.asNumber() / right.asNumber()));
+ } else {
+ if (op == ValueMod)
+ setConstant(node, jsNumber(fmod(left.asNumber(), right.asNumber())));
+ else
+ setConstant(node, jsDoubleNumber(fmod(left.asNumber(), right.asNumber())));
+ }
return true;
}
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes