Patch forthcoming.
Created attachment 224334 [details] the patch
Comment on attachment 224334 [details] the patch View in context: https://bugs.webkit.org/attachment.cgi?id=224334&action=review r=me > Source/JavaScriptCore/ChangeLog:3 > + FTL should support ToPrimitive and the DFG should fold it in a less dumb way Let's just say "better". > Source/JavaScriptCore/dfg/DFGConstantFoldingPhase.cpp:-331 > - case StoreBarrier: > - case StoreBarrierWithNullCheck: { What happened to store barrier?
Comment on attachment 224334 [details] the patch View in context: https://bugs.webkit.org/attachment.cgi?id=224334&action=review >> Source/JavaScriptCore/dfg/DFGConstantFoldingPhase.cpp:-331 >> - case StoreBarrierWithNullCheck: { > > What happened to store barrier? Looks like they weren't doing anything and could therefore fall through to the default case.
(In reply to comment #2) > (From update of attachment 224334 [details]) > View in context: https://bugs.webkit.org/attachment.cgi?id=224334&action=review > > r=me > > > Source/JavaScriptCore/ChangeLog:3 > > + FTL should support ToPrimitive and the DFG should fold it in a less dumb way > > Let's just say "better". > > > Source/JavaScriptCore/dfg/DFGConstantFoldingPhase.cpp:-331 > > - case StoreBarrier: > > - case StoreBarrierWithNullCheck: { > > What happened to store barrier? Nothing, since this was redundant with the default case.
Landed in http://trac.webkit.org/changeset/164243