This requires introducing a NodeType for watchpointing typed array neutering.
Created attachment 218647 [details] it starts
Created attachment 218661 [details] the patch
Attachment 218661 [details] did not pass style-queue: Failed to run "['Tools/Scripts/check-webkit-style', '--diff-files', u'Source/JavaScriptCore/CMakeLists.txt', u'Source/JavaScriptCore/ChangeLog', u'Source/JavaScriptCore/GNUmakefile.list.am', u'Source/JavaScriptCore/JavaScriptCore.vcxproj/JavaScriptCore.vcxproj', u'Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj', u'Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h', u'Source/JavaScriptCore/dfg/DFGClobberize.h', u'Source/JavaScriptCore/dfg/DFGFixupPhase.cpp', u'Source/JavaScriptCore/dfg/DFGGraph.cpp', u'Source/JavaScriptCore/dfg/DFGGraph.h', u'Source/JavaScriptCore/dfg/DFGNode.h', u'Source/JavaScriptCore/dfg/DFGNodeType.h', u'Source/JavaScriptCore/dfg/DFGPlan.cpp', u'Source/JavaScriptCore/dfg/DFGPredictionPropagationPhase.cpp', u'Source/JavaScriptCore/dfg/DFGSafeToExecute.h', u'Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp', u'Source/JavaScriptCore/dfg/DFGSpeculativeJIT32_64.cpp', u'Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp', u'Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.cpp', u'Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.h', u'Source/JavaScriptCore/dfg/DFGWatchpointCollectionPhase.cpp', u'Source/JavaScriptCore/ftl/FTLCapabilities.cpp', u'Source/JavaScriptCore/ftl/FTLLowerDFGToLLVM.cpp', u'Source/JavaScriptCore/jsc.cpp', u'Source/JavaScriptCore/runtime/ArrayBufferView.h', u'Source/JavaScriptCore/tests/stress/fold-typed-array-properties.js', u'Tools/ChangeLog', u'Tools/Scripts/run-javascriptcore-tests', '--commit-queue']" exit_code: 1 ERROR: Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.cpp:43: Comma should be at the beginning of the line in a member initialization list. [whitespace/init] [4] Total errors found: 1 in 28 files If any of these errors are false positives, please file a bug against check-webkit-style.
Created attachment 218662 [details] the patch
(In reply to comment #3) > Attachment 218661 [details] did not pass style-queue: > > Failed to run "['Tools/Scripts/check-webkit-style', '--diff-files', u'Source/JavaScriptCore/CMakeLists.txt', u'Source/JavaScriptCore/ChangeLog', u'Source/JavaScriptCore/GNUmakefile.list.am', u'Source/JavaScriptCore/JavaScriptCore.vcxproj/JavaScriptCore.vcxproj', u'Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj', u'Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h', u'Source/JavaScriptCore/dfg/DFGClobberize.h', u'Source/JavaScriptCore/dfg/DFGFixupPhase.cpp', u'Source/JavaScriptCore/dfg/DFGGraph.cpp', u'Source/JavaScriptCore/dfg/DFGGraph.h', u'Source/JavaScriptCore/dfg/DFGNode.h', u'Source/JavaScriptCore/dfg/DFGNodeType.h', u'Source/JavaScriptCore/dfg/DFGPlan.cpp', u'Source/JavaScriptCore/dfg/DFGPredictionPropagationPhase.cpp', u'Source/JavaScriptCore/dfg/DFGSafeToExecute.h', u'Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp', u'Source/JavaScriptCore/dfg/DFGSpeculativeJIT32_64.cpp', u'Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp', u'Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.cpp', u'Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.h', u'Source/JavaScriptCore/dfg/DFGWatchpointCollectionPhase.cpp', u'Source/JavaScriptCore/ftl/FTLCapabilities.cpp', u'Source/JavaScriptCore/ftl/FTLLowerDFGToLLVM.cpp', u'Source/JavaScriptCore/jsc.cpp', u'Source/JavaScriptCore/runtime/ArrayBufferView.h', u'Source/JavaScriptCore/tests/stress/fold-typed-array-properties.js', u'Tools/ChangeLog', u'Tools/Scripts/run-javascriptcore-tests', '--commit-queue']" exit_code: 1 > ERROR: Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.cpp:43: Comma should be at the beginning of the line in a member initialization list. [whitespace/init] [4] Umm no. > Total errors found: 1 in 28 files > > > If any of these errors are false positives, please file a bug against check-webkit-style.
Created attachment 218663 [details] the patch
Attachment 218663 [details] did not pass style-queue: Failed to run "['Tools/Scripts/check-webkit-style', '--diff-files', u'Source/JavaScriptCore/CMakeLists.txt', u'Source/JavaScriptCore/ChangeLog', u'Source/JavaScriptCore/GNUmakefile.list.am', u'Source/JavaScriptCore/JavaScriptCore.vcxproj/JavaScriptCore.vcxproj', u'Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj', u'Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h', u'Source/JavaScriptCore/dfg/DFGClobberize.h', u'Source/JavaScriptCore/dfg/DFGFixupPhase.cpp', u'Source/JavaScriptCore/dfg/DFGGraph.cpp', u'Source/JavaScriptCore/dfg/DFGGraph.h', u'Source/JavaScriptCore/dfg/DFGNode.h', u'Source/JavaScriptCore/dfg/DFGNodeType.h', u'Source/JavaScriptCore/dfg/DFGPlan.cpp', u'Source/JavaScriptCore/dfg/DFGPredictionPropagationPhase.cpp', u'Source/JavaScriptCore/dfg/DFGSafeToExecute.h', u'Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp', u'Source/JavaScriptCore/dfg/DFGSpeculativeJIT32_64.cpp', u'Source/JavaScriptCore/dfg/DFGSpeculativeJIT64.cpp', u'Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.cpp', u'Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.h', u'Source/JavaScriptCore/dfg/DFGWatchpointCollectionPhase.cpp', u'Source/JavaScriptCore/ftl/FTLCapabilities.cpp', u'Source/JavaScriptCore/ftl/FTLLowerDFGToLLVM.cpp', u'Source/JavaScriptCore/jsc.cpp', u'Source/JavaScriptCore/runtime/ArrayBufferView.h', u'Source/JavaScriptCore/tests/stress/fold-typed-array-properties.js', u'Tools/ChangeLog', u'Tools/Scripts/run-javascriptcore-tests', '--commit-queue']" exit_code: 1 ERROR: Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.cpp:43: Comma should be at the beginning of the line in a member initialization list. [whitespace/init] [4] Total errors found: 1 in 28 files If any of these errors are false positives, please file a bug against check-webkit-style.
Comment on attachment 218663 [details] the patch View in context: https://bugs.webkit.org/attachment.cgi?id=218663&action=review > Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.cpp:126 > + SamplingRegion samplingRegion("DFG Strength Reduction Phase"); > + return runPhase<StrengthReductionPhase>(graph); Given how often these two lines of code go together, perhaps we should make runPhase<> make the SamplingRegion at some point.
(In reply to comment #8) > (From update of attachment 218663 [details]) > View in context: https://bugs.webkit.org/attachment.cgi?id=218663&action=review > > > Source/JavaScriptCore/dfg/DFGStrengthReductionPhase.cpp:126 > > + SamplingRegion samplingRegion("DFG Strength Reduction Phase"); > > + return runPhase<StrengthReductionPhase>(graph); > > Given how often these two lines of code go together, perhaps we should make runPhase<> make the SamplingRegion at some point. Yeah, I know! :-) https://bugs.webkit.org/show_bug.cgi?id=125419
Landed in http://trac.webkit.org/changeset/160292