Bug 127748 - FTL should support ArrayPush
Summary: FTL should support ArrayPush
Status: RESOLVED FIXED
Alias: None
Product: WebKit
Classification: Unclassified
Component: JavaScriptCore (show other bugs)
Version: 528+ (Nightly build)
Hardware: All All
: P2 Normal
Assignee: Filip Pizlo
URL:
Keywords:
Depends on: 127754
Blocks: 127746
  Show dependency treegraph
 
Reported: 2014-01-27 18:11 PST by Filip Pizlo
Modified: 2014-01-28 15:18 PST (History)
9 users (show)

See Also:


Attachments
the patch (9.36 KB, patch)
2014-01-27 19:47 PST, Filip Pizlo
no flags Details | Formatted Diff | Diff
the patch (12.13 KB, patch)
2014-01-28 15:11 PST, Filip Pizlo
oliver: review+
Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Filip Pizlo 2014-01-27 18:11:08 PST
...
Comment 1 Filip Pizlo 2014-01-27 19:47:18 PST
Created attachment 222398 [details]
the patch
Comment 2 Filip Pizlo 2014-01-27 20:05:10 PST
Comment on attachment 222398 [details]
the patch

There's still some bug here.
Comment 3 Filip Pizlo 2014-01-27 20:24:07 PST
This appears to be revealing a latent FTL bug.  Yuck.  I am investigating.
Comment 4 Filip Pizlo 2014-01-28 12:45:22 PST
It looks like a bug with arity fixup.  Those are the best!  I'm still investigating.
Comment 5 Filip Pizlo 2014-01-28 12:58:37 PST
Aha!  The bug is that the arityFixup code uses regT3, which is a callee-save.  Hence if we have an FTL->FTL call that requires fixup, we will clobber things.

This should be an easy fix.
Comment 6 Filip Pizlo 2014-01-28 14:12:38 PST
Latent bugs fixed in http://trac.webkit.org/changeset/162958, coming back to working on this.
Comment 7 Filip Pizlo 2014-01-28 15:11:08 PST
Created attachment 222503 [details]
the patch
Comment 8 Filip Pizlo 2014-01-28 15:18:44 PST
Landed in http://trac.webkit.org/changeset/162969