Bug 193483 - StringObjectUse should not be a structure check for the original string object structure
Summary: StringObjectUse should not be a structure check for the original string objec...
Status: RESOLVED FIXED
Alias: None
Product: WebKit
Classification: Unclassified
Component: JavaScriptCore (show other bugs)
Version: WebKit Nightly Build
Hardware: Unspecified Unspecified
: P2 Normal
Assignee: Saam Barati
URL:
Keywords: InRadar
Depends on:
Blocks:
 
Reported: 2019-01-15 19:45 PST by Saam Barati
Modified: 2019-01-20 21:04 PST (History)
14 users (show)

See Also:


Attachments
patch (35.69 KB, patch)
2019-01-16 23:16 PST, Saam Barati
ysuzuki: review+
Details | Formatted Diff | Diff
patch for landing (35.71 KB, patch)
2019-01-17 00:11 PST, Saam Barati
no flags Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Saam Barati 2019-01-15 19:45:33 PST
This is probably buggy, and goes against how we use UseKinds elsewhere. We should figure out the handful of places that actually rely on this behavior and have them emit a CheckStructure. And then change StringObjectUse to just mean that the thing has StringObject classInfo.
Comment 1 Saam Barati 2019-01-16 22:52:45 PST
<rdar://problem/47280522>
Comment 2 Saam Barati 2019-01-16 23:16:08 PST
Created attachment 359354 [details]
patch
Comment 3 Yusuke Suzuki 2019-01-16 23:33:24 PST
Comment on attachment 359354 [details]
patch

View in context: https://bugs.webkit.org/attachment.cgi?id=359354&action=review

r=me with FTL fixes

> Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp:6335
> +            LValue type = m_out.load32(cell, m_heaps.JSCell_typeInfoType);

load8ZeroExt32?

> Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp:16068
> +        LValue type = m_out.load32(cellBase, m_heaps.JSCell_typeInfoType);

Ditto.

> Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp:16088
> +        LValue type = m_out.load32(cell, m_heaps.JSCell_typeInfoType);

Ditto.
Comment 4 Saam Barati 2019-01-17 00:07:31 PST
Comment on attachment 359354 [details]
patch

View in context: https://bugs.webkit.org/attachment.cgi?id=359354&action=review

>> Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp:6335
>> +            LValue type = m_out.load32(cell, m_heaps.JSCell_typeInfoType);
> 
> load8ZeroExt32?

Oops. Will fix
Comment 5 Saam Barati 2019-01-17 00:11:52 PST
Created attachment 359359 [details]
patch for landing
Comment 6 WebKit Commit Bot 2019-01-17 09:50:33 PST
Comment on attachment 359359 [details]
patch for landing

Clearing flags on attachment: 359359

Committed r240114: <https://trac.webkit.org/changeset/240114>
Comment 7 WebKit Commit Bot 2019-01-17 09:50:35 PST
All reviewed patches have been landed.  Closing bug.
Comment 8 Michael Catanzaro 2019-01-20 21:04:25 PST
Committed r240225: <https://trac.webkit.org/changeset/240225>