Bug 211531

Summary: DFG ByVal nodes with ArrayModes should clobberTop until Fixup phase runs.
Product: WebKit Reporter: Keith Miller <keith_miller>
Component: New BugsAssignee: Keith Miller <keith_miller>
Status: RESOLVED FIXED    
Severity: Normal CC: ews-watchlist, mark.lam, msaboff, saam, tzagallo, webkit-bug-importer, ysuzuki
Priority: P2 Keywords: InRadar
Version: WebKit Nightly Build   
Hardware: Unspecified   
OS: Unspecified   
See Also: https://bugs.webkit.org/show_bug.cgi?id=211576
https://bugs.webkit.org/show_bug.cgi?id=211543
Attachments:
Description Flags
Patch
none
Patch ysuzuki: review+

Description Keith Miller 2020-05-06 14:30:32 PDT
GetByVal and HasIndexedProperty should clobberTop until Fixup Phase runs.
Comment 1 Keith Miller 2020-05-06 14:36:59 PDT
Created attachment 398660 [details]
Patch
Comment 2 Keith Miller 2020-05-06 14:59:00 PDT
Created attachment 398667 [details]
Patch
Comment 3 Keith Miller 2020-05-06 15:00:02 PDT
rdar://problem/62838095
Comment 4 Yusuke Suzuki 2020-05-06 15:10:12 PDT
Comment on attachment 398667 [details]
Patch

r=me
Comment 5 Mark Lam 2020-05-06 16:00:59 PDT
Comment on attachment 398667 [details]
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=398667&action=review

> Source/JavaScriptCore/dfg/DFGClobberize.h:159
> +    // Since Fixup can do widen our ArrayModes based on profiling from other nodes we pessimistically assume

/can do widen/can widen/
Comment 6 Keith Miller 2020-05-06 17:00:39 PDT
Committed r261260: <https://trac.webkit.org/changeset/261260>
Comment 7 Ryan Haddad 2020-05-06 20:44:03 PDT
(In reply to Keith Miller from comment #6)
> Committed r261260: <https://trac.webkit.org/changeset/261260>
This appears to have broken 26 JSC tests:
https://build.webkit.org/builders/Apple-Catalina-Release-JSC-Tests/builds/1894
Comment 8 Ryan Haddad 2020-05-07 09:19:24 PDT
Reverted r261260 for reason:

Caused 26 JSC test failures

Committed r261293: <https://trac.webkit.org/changeset/261293>
Comment 9 Keith Miller 2020-05-07 11:01:43 PDT
I relanded this with https://trac.webkit.org/changeset/261313