Bug 154011 - Baseline JIT should not require its input to be constant-propagated
Summary: Baseline JIT should not require its input to be constant-propagated
Alias: None
Product: WebKit
Classification: Unclassified
Component: JavaScriptCore (show other bugs)
Version: WebKit Nightly Build
Hardware: All All
: P2 Normal
Assignee: Filip Pizlo
Depends on:
Reported: 2016-02-08 14:49 PST by Filip Pizlo
Modified: 2016-02-08 15:00 PST (History)
5 users (show)

See Also:

the patch (3.19 KB, patch)
2016-02-08 14:52 PST, Filip Pizlo
mark.lam: review+
Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Filip Pizlo 2016-02-08 14:49:28 PST
The snippet generator code in the baseline JIT was assuming that bytecode *must* have been constant-propagated.  But you can’t guarantee that.  For example, this constraint means that almost any optimization performed after constant propagation is an invalid optimization, since it may reveal new constant propagation opportunities.

The bytecode generator runs after we have done some constant propagation in the parser, but it doesn’t guarantee that it won’t also do other things that reveal constants.

The correct thing to do - and indeed the thing that all of our other compiler code does - is to gracefully deal with unfolded operations in the backend.  There is no cost to doing so, and it ensures that the compiler doesn't crash if by some weird chance we revealed a constant in some late optimization.
Comment 1 Filip Pizlo 2016-02-08 14:52:26 PST
Created attachment 270884 [details]
the patch
Comment 2 Mark Lam 2016-02-08 14:57:56 PST
Comment on attachment 270884 [details]
the patch

Comment 3 Filip Pizlo 2016-02-08 15:00:42 PST
Landed in http://trac.webkit.org/changeset/196273