It checks if the value is a cell is a really wrong way.
Created attachment 223755 [details] Patch
Comment on attachment 223755 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=223755&action=review r=me > Source/JavaScriptCore/llint/LowLevelInterpreter64.asm:413 > + loadConstantOrVariableCell(t1, t0, .writeBarrierDone) > btpz t0, .writeBarrierDone Why does this code check for a null t0? Is a null cell ever allowed?
(In reply to comment #2) > (From update of attachment 223755 [details]) > View in context: https://bugs.webkit.org/attachment.cgi?id=223755&action=review > > r=me > > > Source/JavaScriptCore/llint/LowLevelInterpreter64.asm:413 > > + loadConstantOrVariableCell(t1, t0, .writeBarrierDone) > > btpz t0, .writeBarrierDone > > Why does this code check for a null t0? Is a null cell ever allowed? I think init_global_const potentially does this...it's been a while since I added that however.
(In reply to comment #3) > (In reply to comment #2) > > (From update of attachment 223755 [details] [details]) > > View in context: https://bugs.webkit.org/attachment.cgi?id=223755&action=review > > > > r=me > > > > > Source/JavaScriptCore/llint/LowLevelInterpreter64.asm:413 > > > + loadConstantOrVariableCell(t1, t0, .writeBarrierDone) > > > btpz t0, .writeBarrierDone > > > > Why does this code check for a null t0? Is a null cell ever allowed? > > I think init_global_const potentially does this...it's been a while since I added that however. I filed bug 128608 to track getting rid of the null check.
Comment on attachment 223755 [details] Patch Clearing flags on attachment: 223755 Committed r163887: <http://trac.webkit.org/changeset/163887>
All reviewed patches have been landed. Closing bug.