Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 07a51e2433958d4995841ab2fc0cfbf4115be7b6
      
https://github.com/WebKit/WebKit/commit/07a51e2433958d4995841ab2fc0cfbf4115be7b6
  Author: Yusuke Suzuki <[email protected]>
  Date:   2026-10-03 (Sat, 03 Oct 2026)

  Changed paths:
    A JSTests/stress/json-parse-cached-string-value.js
    A JSTests/stress/json-parse-colliding-short-strings.js
    M Source/JavaScriptCore/runtime/JSONCache.cpp
    M Source/JavaScriptCore/runtime/JSONCache.h
    M Source/JavaScriptCore/runtime/JSONCacheInlines.h
    M Source/JavaScriptCore/runtime/LiteralParser.cpp
    M Source/JavaScriptCore/runtime/LiteralParser.h

  Log Message:
  -----------
  [JSC] Match repeated short JSON string values against the source text
https://bugs.webkit.org/show_bug.cgi?id=326165
rdar://189052025

Reviewed by Vassili Bykov.

Short string values repeat heavily in JSON. This patch adds a 64-entry
table to JSONCache that maps a string value's source text, quotes
included, to its JSString. It is indexed by the first eight bytes of
the source, and a hit is verified with the same masked vector comparison
used for property names, so the value is consumed without scanning it.

The table is 2-way set associative, and a new entry goes into way 0
and demotes the previous one, so it tracks the values seen most
recently; that keeps the hit rate at 76% with an eighth of the space
a 512-entry table with no demotion needed (77.6%). Only values without
escapes are recorded, so the raw text determines the value. Entries are
cleared with the other JSString caches at the end of every GC.

We also make normal JSON AtomString cache two-way by using primary /
secondary cache mechanism and reduce the size of cache to keep cache
structure smaller.

Tests: JSTests/stress/json-parse-cached-string-value.js
       JSTests/stress/json-parse-colliding-short-strings.js

* JSTests/stress/json-parse-cached-string-value.js: Added.
(shouldBe):
(iteration.i.values):
* JSTests/stress/json-parse-colliding-short-strings.js: Added.
(shouldBe):
* Source/JavaScriptCore/runtime/JSONCache.cpp:
(JSC::JSONCache::NameTable<size>::insert):
(JSC::JSONCache::addPrefixedName):
(JSC::JSONCache::addName):
* Source/JavaScriptCore/runtime/JSONCache.h:
(JSC::JSONCache::clearJSStrings):
(JSC::JSONCache::reconcileTransitionsAtGCEnd):
(JSC::JSONCache::atomStringIndex): Deleted.
(JSC::JSONCache::atomStringSlot): Deleted.
* Source/JavaScriptCore/runtime/JSONCacheInlines.h:
(JSC::JSONCache::atomStringKey):
(JSC::JSONCache::primaryAtomStringIndex):
(JSC::JSONCache::secondaryAtomStringIndex):
(JSC::JSONCache::atomStringMatches const):
(JSC::JSONCache::findAtomString const):
(JSC::JSONCache::addAtomString):
(JSC::JSONCache::makeIdentifierSlow):
(JSC::JSONCache::makeIdentifier):
(JSC::JSONCache::existingIdentifierSlow):
(JSC::JSONCache::existingIdentifier):
(JSC::JSONCache::makeJSStringSlow):
(JSC::JSONCache::makeJSString):
(JSC::JSONCache::NameTable<size>::match const):
(JSC::JSONCache::stringIndex):
(JSC::JSONCache::StringTable::match const):
(JSC::JSONCache::StringTable::insert):
(JSC::JSONCache::findString const):
(JSC::JSONCache::addString):
(JSC::JSONCache::visitAggregate):
* Source/JavaScriptCore/runtime/LiteralParser.cpp:
(JSC::reviverMode>::Lexer::cacheString):
(JSC::requires):
* Source/JavaScriptCore/runtime/LiteralParser.h:

Canonical link: https://commits.webkit.org/322596@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to