Bug 127748

Summary: FTL should support ArrayPush
Product: WebKit Reporter: Filip Pizlo <fpizlo>
Component: JavaScriptCoreAssignee: Filip Pizlo <fpizlo>
Status: RESOLVED FIXED    
Severity: Normal CC: barraclough, ggaren, mark.lam, mhahnenberg, mmirman, msaboff, nrotem, oliver, sam
Priority: P2    
Version: 528+ (Nightly build)   
Hardware: All   
OS: All   
Bug Depends on: 127754    
Bug Blocks: 127746    
Attachments:
Description Flags
the patch
none
the patch oliver: review+

Description Filip Pizlo 2014-01-27 18:11:08 PST
...
Comment 1 Filip Pizlo 2014-01-27 19:47:18 PST
Created attachment 222398 [details]
the patch
Comment 2 Filip Pizlo 2014-01-27 20:05:10 PST
Comment on attachment 222398 [details]
the patch

There's still some bug here.
Comment 3 Filip Pizlo 2014-01-27 20:24:07 PST
This appears to be revealing a latent FTL bug.  Yuck.  I am investigating.
Comment 4 Filip Pizlo 2014-01-28 12:45:22 PST
It looks like a bug with arity fixup.  Those are the best!  I'm still investigating.
Comment 5 Filip Pizlo 2014-01-28 12:58:37 PST
Aha!  The bug is that the arityFixup code uses regT3, which is a callee-save.  Hence if we have an FTL->FTL call that requires fixup, we will clobber things.

This should be an easy fix.
Comment 6 Filip Pizlo 2014-01-28 14:12:38 PST
Latent bugs fixed in http://trac.webkit.org/changeset/162958, coming back to working on this.
Comment 7 Filip Pizlo 2014-01-28 15:11:08 PST
Created attachment 222503 [details]
the patch
Comment 8 Filip Pizlo 2014-01-28 15:18:44 PST
Landed in http://trac.webkit.org/changeset/162969