<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>146867</bug_id>
          
          <creation_ts>2015-07-10 19:24:22 -0700</creation_ts>
          <short_desc>AI folding of IsObjectOrNull is broken for non-object types that may be null</short_desc>
          <delta_ts>2015-07-10 20:03:09 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>JavaScriptCore</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Filip Pizlo">fpizlo</reporter>
          <assigned_to name="Filip Pizlo">fpizlo</assigned_to>
          <cc>barraclough</cc>
    
    <cc>benjamin</cc>
    
    <cc>commit-queue</cc>
    
    <cc>ggaren</cc>
    
    <cc>mark.lam</cc>
    
    <cc>mhahnenb</cc>
    
    <cc>mmirman</cc>
    
    <cc>msaboff</cc>
    
    <cc>nrotem</cc>
    
    <cc>oliver</cc>
    
    <cc>rniwa</cc>
    
    <cc>saam</cc>
    
    <cc>sam</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1108847</commentid>
    <comment_count>0</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2015-07-10 19:24:22 -0700</bug_when>
    <thetext>Patch forthcoming.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1108848</commentid>
    <comment_count>1</comment_count>
      <attachid>256638</attachid>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2015-07-10 19:26:27 -0700</bug_when>
    <thetext>Created attachment 256638
the patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1108849</commentid>
    <comment_count>2</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2015-07-10 19:29:32 -0700</bug_when>
    <thetext>Attachment 256638 did not pass style-queue:


ERROR: Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h:1044:  Should have only a single space after a punctuation in a comment.  [whitespace/comments] [5]
ERROR: Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h:1053:  Should have only a single space after a punctuation in a comment.  [whitespace/comments] [5]
Total errors found: 2 in 4 files


If any of these errors are false positives, please file a bug against check-webkit-style.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1108857</commentid>
    <comment_count>3</comment_count>
      <attachid>256638</attachid>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2015-07-10 19:51:13 -0700</bug_when>
    <thetext>Comment on attachment 256638
the patch

View in context: https://bugs.webkit.org/attachment.cgi?id=256638&amp;action=review

&gt; Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h:1056
&gt; +            if (!(child.m_type &amp; ((SpecObject - SpecFunction) | SpecOther))) {

Can we define a local variable immediately before this line to reduce the number of parentheses involved?
e.g.
SpeculatedType nonFunctionObject = ((SpecObject - SpecFunction) | SpecOther);</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1108858</commentid>
    <comment_count>4</comment_count>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2015-07-10 19:53:24 -0700</bug_when>
    <thetext>or maybe an inline helper function somewhere?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1108862</commentid>
    <comment_count>5</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2015-07-10 19:59:52 -0700</bug_when>
    <thetext>(In reply to comment #3)
&gt; Comment on attachment 256638 [details]
&gt; the patch
&gt; 
&gt; View in context:
&gt; https://bugs.webkit.org/attachment.cgi?id=256638&amp;action=review
&gt; 
&gt; &gt; Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h:1056
&gt; &gt; +            if (!(child.m_type &amp; ((SpecObject - SpecFunction) | SpecOther))) {
&gt; 
&gt; Can we define a local variable immediately before this line to reduce the
&gt; number of parentheses involved?
&gt; e.g.
&gt; SpeculatedType nonFunctionObject = ((SpecObject - SpecFunction) | SpecOther);

Well, we could, but nonFunctionObject would be the wrong name for this.  It&apos;s really nonFunctionObjectOrUndefinedOrNull.  At that point, the variable name is more complicated than the set expression!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1108863</commentid>
    <comment_count>6</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2015-07-10 20:00:07 -0700</bug_when>
    <thetext>(In reply to comment #4)
&gt; or maybe an inline helper function somewhere?

https://bugs.webkit.org/show_bug.cgi?id=146870</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1108865</commentid>
    <comment_count>7</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2015-07-10 20:03:09 -0700</bug_when>
    <thetext>Landed in http://trac.webkit.org/changeset/186702</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>256638</attachid>
            <date>2015-07-10 19:26:27 -0700</date>
            <delta_ts>2015-07-10 19:51:13 -0700</delta_ts>
            <desc>the patch</desc>
            <filename>blah.patch</filename>
            <type>text/plain</type>
            <size>4157</size>
            <attacher name="Filip Pizlo">fpizlo</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9DaGFuZ2VMb2cKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkocmV2aXNpb24gMTg2NzAwKQorKysgU291cmNl
L0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE3IEBA
CisyMDE1LTA3LTEwICBGaWxpcCBQaXpsbyAgPGZwaXpsb0BhcHBsZS5jb20+CisKKyAgICAgICAg
QUkgZm9sZGluZyBvZiBJc09iamVjdE9yTnVsbCBpcyBicm9rZW4gZm9yIG5vbi1vYmplY3QgdHlw
ZXMgdGhhdCBtYXkgYmUgbnVsbAorICAgICAgICBodHRwczovL2J1Z3Mud2Via2l0Lm9yZy9zaG93
X2J1Zy5jZ2k/aWQ9MTQ2ODY3CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISku
CisKKyAgICAgICAgKiBkZmcvREZHQWJzdHJhY3RJbnRlcnByZXRlcklubGluZXMuaDoKKyAgICAg
ICAgKEpTQzo6REZHOjpBYnN0cmFjdEludGVycHJldGVyPEFic3RyYWN0U3RhdGVUeXBlPjo6ZXhl
Y3V0ZUVmZmVjdHMpOiBGaXggdGhlIGJ1ZyBhbmQgYWRkIHNvbWUgdGV4dCBkZXNjcmliaW5nIHdo
YXQgaXMgZ29pbmcgb24uCisgICAgICAgICogdGVzdHMvc3RyZXNzL21pc2MtaXMtb2JqZWN0LW9y
LW51bGwuanM6IEFkZGVkLiBUZXN0IGZvciB0aGUgYnVnLgorICAgICAgICAoZm9vKToKKyAgICAg
ICAgKiB0ZXN0cy9zdHJlc3Mvb3RoZXItaXMtb2JqZWN0LW9yLW51bGwuanM6IEFkZGVkLiBUZXN0
IGZvciBhIGJ1ZyBJIGFsbW9zdCBpbnRyb2R1Y2VkLgorICAgICAgICAoZm9vKToKKwogMjAxNS0w
Ny0wNCAgRmlsaXAgUGl6bG8gIDxmcGl6bG9AYXBwbGUuY29tPgogCiAgICAgICAgIERGRyBmcmFn
aWxlIGZyb3plbiB2YWx1ZXMgYXJlIGZ1bmRhbWVudGFsbHkgYnJva2VuCkluZGV4OiBTb3VyY2Uv
SmF2YVNjcmlwdENvcmUvZGZnL0RGR0Fic3RyYWN0SW50ZXJwcmV0ZXJJbmxpbmVzLmgKPT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PQotLS0gU291cmNlL0phdmFTY3JpcHRDb3JlL2RmZy9ERkdBYnN0cmFjdEludGVycHJldGVy
SW5saW5lcy5oCShyZXZpc2lvbiAxODY3MDApCisrKyBTb3VyY2UvSmF2YVNjcmlwdENvcmUvZGZn
L0RGR0Fic3RyYWN0SW50ZXJwcmV0ZXJJbmxpbmVzLmgJKHdvcmtpbmcgY29weSkKQEAgLTEwMzQs
MTMgKzEwMzQsMjYgQEAgYm9vbCBBYnN0cmFjdEludGVycHJldGVyPEFic3RyYWN0U3RhdGVUeQog
ICAgICAgICAgICAgLy8gRklYTUU6IFVzZSB0aGUgbWFzcXVlcmFkZXMtYXMtdW5kZWZpbmVkIHdh
dGNocG9pbnQgdGhpbmd5LgogICAgICAgICAgICAgLy8gaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcv
c2hvd19idWcuY2dpP2lkPTE0NDQ1NgogICAgICAgICAgICAgCisgICAgICAgICAgICAvLyBUaGVz
ZSBleHByZXNzaW9ucyBhcmUgY29tcGxpY2F0ZWQgdG8gcGFyc2UuIEEgaGVscGZ1bCB3YXkgdG8g
cGFyc2UgdGhpcyBpcyB0aGF0CisgICAgICAgICAgICAvLyAiIShUICYgflMpIiBtZWFucyAiVCBp
cyBhIHN1YnNldCBvZiBTIi4gQ29udmVyc2VseSwgIiEoVCAmIFMpIiBtZWFucyAiVCBpcyBhCisg
ICAgICAgICAgICAvLyBkaXNqb2ludCBzZXQgZnJvbSBTIi4gVGhpbmdzIGxpa2UgIlQgLSBTIiBt
ZWFucyB0aGF0LCBwcm92aWRlZCB0aGF0IFMgaXMgYQorICAgICAgICAgICAgLy8gc3Vic2V0IG9m
IFQsIGl0J3MgdGhlICJzZXQgb2YgYWxsIHRoaW5ncyBpbiBUIGJ1dCBub3QgaW4gUyIuIFRoaW5n
cyBsaWtlICJUIHwgUyIKKyAgICAgICAgICAgIC8vIG1lYW4gdGhlICJ1bmlvbiBvZiBUIGFuZCBT
Ii4KKyAgICAgICAgICAgIAorICAgICAgICAgICAgLy8gSXMgdGhlIGNoaWxkJ3MgdHlwZSBhbiBv
YmplY3QgdGhhdCBpc24ndCBhbiBvdGhlci1vYmplY3QgKGkuZS4gb2JqZWN0IHRoYXQgY291bGQK
KyAgICAgICAgICAgIC8vIGhhdmUgbWFzcXVhcmVkZXMtYXMtdW5kZWZpbmVkIHRyYXBzKSBhbmQg
aXNuJ3QgYSBmdW5jdGlvbj8gIFRoZW46IHdlIHNob3VsZCBmb2xkCisgICAgICAgICAgICAvLyB0
aGlzIHRvIHRydWUuCiAgICAgICAgICAgICBpZiAoIShjaGlsZC5tX3R5cGUgJiB+KFNwZWNPYmpl
Y3QgLSBTcGVjT2JqZWN0T3RoZXIgLSBTcGVjRnVuY3Rpb24pKSkgewogICAgICAgICAgICAgICAg
IHNldENvbnN0YW50KG5vZGUsIGpzQm9vbGVhbih0cnVlKSk7CiAgICAgICAgICAgICAgICAgY29u
c3RhbnRXYXNTZXQgPSB0cnVlOwogICAgICAgICAgICAgICAgIGJyZWFrOwogICAgICAgICAgICAg
fQogICAgICAgICAgICAgCi0gICAgICAgICAgICBpZiAoIShjaGlsZC5tX3R5cGUgJiAoU3BlY09i
amVjdCAtIFNwZWNGdW5jdGlvbikpKSB7CisgICAgICAgICAgICAvLyBJcyB0aGUgY2hpbGQncyB0
eXBlIGRlZmluaXRlbHkgbm90IGVpdGhlciBvZjogYW4gb2JqZWN0IHRoYXQgaXNuJ3QgYSBmdW5j
dGlvbiwKKyAgICAgICAgICAgIC8vIG9yIGVpdGhlciB1bmRlZmluZWQgb3IgbnVsbD8gIFRoZW46
IHdlIHNob3VsZCBmb2xkIHRoaXMgdG8gZmFsc2UuICBUaGlzIG1lYW5zCisgICAgICAgICAgICAv
LyB0aGF0IGlmIGl0J3MgYW55IG9iamVjdCBub24tZnVuY3Rpb24gb2JqZWN0LCBpbmNsdWRpbmcg
dGhvc2UgdGhhdCBoYXZlCisgICAgICAgICAgICAvLyBtYXNxdWVyYWRlcy1hcy11bmRlZmluZWQg
dHJhcHMsIHRoZW4gd2UgZG9uJ3QgZm9sZC4KKyAgICAgICAgICAgIGlmICghKGNoaWxkLm1fdHlw
ZSAmICgoU3BlY09iamVjdCAtIFNwZWNGdW5jdGlvbikgfCBTcGVjT3RoZXIpKSkgewogICAgICAg
ICAgICAgICAgIHNldENvbnN0YW50KG5vZGUsIGpzQm9vbGVhbihmYWxzZSkpOwogICAgICAgICAg
ICAgICAgIGNvbnN0YW50V2FzU2V0ID0gdHJ1ZTsKICAgICAgICAgICAgICAgICBicmVhazsKSW5k
ZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS90ZXN0cy9zdHJlc3MvbWlzYy1pcy1vYmplY3Qtb3It
bnVsbC5qcwo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvSmF2YVNjcmlwdENvcmUvdGVzdHMvc3RyZXNz
L21pc2MtaXMtb2JqZWN0LW9yLW51bGwuanMJKHJldmlzaW9uIDApCisrKyBTb3VyY2UvSmF2YVNj
cmlwdENvcmUvdGVzdHMvc3RyZXNzL21pc2MtaXMtb2JqZWN0LW9yLW51bGwuanMJKHdvcmtpbmcg
Y29weSkKQEAgLTAsMCArMSwxMyBAQAorZnVuY3Rpb24gZm9vKHApIHsKKyAgICB2YXIgeCA9IHAg
PyBudWxsIDogZmFsc2U7CisgICAgcmV0dXJuICh0eXBlb2YgeCkgPT0gIm9iamVjdCI7Cit9CisK
K25vSW5saW5lKGZvbyk7CisKK2ZvciAodmFyIGkgPSAwOyBpIDwgMTAwMDA7ICsraSkgeworICAg
IHZhciBwID0gISEoaSAmIDEpOworICAgIHZhciByZXN1bHQgPSBmb28ocCk7CisgICAgaWYgKHJl
c3VsdCAhPT0gcCkKKyAgICAgICAgdGhyb3cgIkVycm9yOiBiYWQgcmVzdWx0IGZvciBwID0gIiAr
IHAgKyAiOiAiICsgcmVzdWx0OworfQpJbmRleDogU291cmNlL0phdmFTY3JpcHRDb3JlL3Rlc3Rz
L3N0cmVzcy9vdGhlci1pcy1vYmplY3Qtb3ItbnVsbC5qcwo9PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2Uv
SmF2YVNjcmlwdENvcmUvdGVzdHMvc3RyZXNzL290aGVyLWlzLW9iamVjdC1vci1udWxsLmpzCShy
ZXZpc2lvbiAwKQorKysgU291cmNlL0phdmFTY3JpcHRDb3JlL3Rlc3RzL3N0cmVzcy9vdGhlci1p
cy1vYmplY3Qtb3ItbnVsbC5qcwkod29ya2luZyBjb3B5KQpAQCAtMCwwICsxLDEzIEBACitmdW5j
dGlvbiBmb28ocCkgeworICAgIHZhciB4ID0gcCA/IG51bGwgOiB2b2lkIDA7CisgICAgcmV0dXJu
ICh0eXBlb2YgeCkgPT0gIm9iamVjdCI7Cit9CisKK25vSW5saW5lKGZvbyk7CisKK2ZvciAodmFy
IGkgPSAwOyBpIDwgMTAwMDA7ICsraSkgeworICAgIHZhciBwID0gISEoaSAmIDEpOworICAgIHZh
ciByZXN1bHQgPSBmb28ocCk7CisgICAgaWYgKHJlc3VsdCAhPT0gcCkKKyAgICAgICAgdGhyb3cg
IkVycm9yOiBiYWQgcmVzdWx0IGZvciBwID0gIiArIHAgKyAiOiAiICsgcmVzdWx0OworfQo=
</data>
<flag name="review"
          id="281743"
          type_id="1"
          status="+"
          setter="rniwa"
    />
          </attachment>
      

    </bug>

</bugzilla>