RESOLVED FIXED145062
DFGLICMPhase shouldn't create NodeOrigins with forExit but without semantic
https://bugs.webkit.org/show_bug.cgi?id=145062
Summary DFGLICMPhase shouldn't create NodeOrigins with forExit but without semantic
Basile Clement
Reported 2015-05-15 11:28:27 PDT
This can be hit by running e.g. sunspider/access-nsieve with DYLD_FRAMEWORK_PATH=WebKitBuild/Debug WebKitBuild/Debug/jsc --forceEagerCompilation=true --useFTLJIT=true --dumpGraphAtEachPhase=true In this case, a Phi node is converted into a JSConstant by the DFGConstantFoldingPhase, and doesn't have a NodeOrigin. Then it gets LICM'd, which unconditionally sets the NodeOrigin's forExit, and now we have a NodeOrigin with a set forExit and unset semantic, which we assert against in various places.
Attachments
Patch (3.74 KB, patch)
2015-05-15 12:14 PDT, Basile Clement
fpizlo: review+
Basile Clement
Comment 1 2015-05-15 12:14:05 PDT
Basile Clement
Comment 2 2015-05-15 12:31:42 PDT
Note You need to log in before you can comment on or make changes to this bug.