Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(15)

Side by Side Diff: src/ic-arm.cc

Issue 11272: When probing a dictionary backing storage in generated code, make sure... (Closed) Base URL: http://v8.googlecode.com/svn/branches/bleeding_edge/
Patch Set: '' Created 12 years, 1 month ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch | Annotate | Revision Log
« no previous file with comments | « no previous file | src/ic-ia32.cc » ('j') | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 // Copyright 2006-2008 the V8 project authors. All rights reserved. 1 // Copyright 2006-2008 the V8 project authors. All rights reserved.
2 // Redistribution and use in source and binary forms, with or without 2 // Redistribution and use in source and binary forms, with or without
3 // modification, are permitted provided that the following conditions are 3 // modification, are permitted provided that the following conditions are
4 // met: 4 // met:
5 // 5 //
6 // * Redistributions of source code must retain the above copyright 6 // * Redistributions of source code must retain the above copyright
7 // notice, this list of conditions and the following disclaimer. 7 // notice, this list of conditions and the following disclaimer.
8 // * Redistributions in binary form must reproduce the above 8 // * Redistributions in binary form must reproduce the above
9 // copyright notice, this list of conditions and the following 9 // copyright notice, this list of conditions and the following
10 // disclaimer in the documentation and/or other materials provided 10 // disclaimer in the documentation and/or other materials provided
(...skipping 107 matching lines...) Expand 10 before | Expand all | Expand 10 after
118 __ bind(&done); // t1 == t0 + 4*index 118 __ bind(&done); // t1 == t0 + 4*index
119 __ ldr(r3, FieldMemOperand(t1, kElementsStartOffset + 2 * kPointerSize)); 119 __ ldr(r3, FieldMemOperand(t1, kElementsStartOffset + 2 * kPointerSize));
120 __ tst(r3, Operand(PropertyDetails::TypeField::mask() << kSmiTagSize)); 120 __ tst(r3, Operand(PropertyDetails::TypeField::mask() << kSmiTagSize));
121 __ b(ne, miss); 121 __ b(ne, miss);
122 122
123 // Get the value at the masked, scaled index and return. 123 // Get the value at the masked, scaled index and return.
124 __ ldr(t1, FieldMemOperand(t1, kElementsStartOffset + 1 * kPointerSize)); 124 __ ldr(t1, FieldMemOperand(t1, kElementsStartOffset + 1 * kPointerSize));
125 } 125 }
126 126
127 127
128 // Helper function used to check that a value is either not a function
129 // or is loaded if it is a function.
130 static void GenerateCheckNonFunctionOrLoaded(MacroAssembler* masm,
131 Label* miss,
132 Register value,
133 Register scratch) {
134 Label done;
135 // Check if the value is a Smi.
136 __ tst(value, Operand(kSmiTagMask));
137 __ b(eq, &done);
138 // Check if the value is a function.
139 __ ldr(scratch, FieldMemOperand(value, HeapObject::kMapOffset));
140 __ ldrb(scratch, FieldMemOperand(scratch, Map::kInstanceTypeOffset));
141 __ cmp(scratch, Operand(JS_FUNCTION_TYPE));
142 __ b(ne, &done);
143 // Check if the function has been loaded.
144 __ ldr(scratch,
145 FieldMemOperand(value, JSFunction::kSharedFunctionInfoOffset));
146 __ ldr(scratch,
147 FieldMemOperand(scratch, SharedFunctionInfo::kLazyLoadDataOffset));
148 __ cmp(scratch, Operand(Factory::undefined_value()));
149 __ b(ne, miss);
150 __ bind(&done);
151 }
152
153
128 void LoadIC::GenerateArrayLength(MacroAssembler* masm) { 154 void LoadIC::GenerateArrayLength(MacroAssembler* masm) {
129 // ----------- S t a t e ------------- 155 // ----------- S t a t e -------------
130 // -- r2 : name 156 // -- r2 : name
131 // -- lr : return address 157 // -- lr : return address
132 // -- [sp] : receiver 158 // -- [sp] : receiver
133 // ----------------------------------- 159 // -----------------------------------
134 160
135 Label miss; 161 Label miss;
136 162
137 __ ldr(r0, MemOperand(sp, 0)); 163 __ ldr(r0, MemOperand(sp, 0));
(...skipping 155 matching lines...) Expand 10 before | Expand all | Expand 10 after
293 // Check that the value isn't a smi. 319 // Check that the value isn't a smi.
294 __ tst(r1, Operand(kSmiTagMask)); 320 __ tst(r1, Operand(kSmiTagMask));
295 __ b(eq, miss); 321 __ b(eq, miss);
296 322
297 // Check that the value is a JSFunction. 323 // Check that the value is a JSFunction.
298 __ ldr(r0, FieldMemOperand(r1, HeapObject::kMapOffset)); 324 __ ldr(r0, FieldMemOperand(r1, HeapObject::kMapOffset));
299 __ ldrb(r0, FieldMemOperand(r0, Map::kInstanceTypeOffset)); 325 __ ldrb(r0, FieldMemOperand(r0, Map::kInstanceTypeOffset));
300 __ cmp(r0, Operand(JS_FUNCTION_TYPE)); 326 __ cmp(r0, Operand(JS_FUNCTION_TYPE));
301 __ b(ne, miss); 327 __ b(ne, miss);
302 328
329 // Check that the function has been loaded.
330 __ ldr(r0, FieldMemOperand(r1, JSFunction::kSharedFunctionInfoOffset));
331 __ ldr(r0, FieldMemOperand(r0, SharedFunctionInfo::kLazyLoadDataOffset));
332 __ cmp(r0, Operand(Factory::undefined_value()));
333 __ b(ne, miss);
334
303 // Patch the receiver with the global proxy if necessary. 335 // Patch the receiver with the global proxy if necessary.
304 if (is_global_object) { 336 if (is_global_object) {
305 __ ldr(r2, MemOperand(sp, argc * kPointerSize)); 337 __ ldr(r2, MemOperand(sp, argc * kPointerSize));
306 __ ldr(r2, FieldMemOperand(r2, GlobalObject::kGlobalReceiverOffset)); 338 __ ldr(r2, FieldMemOperand(r2, GlobalObject::kGlobalReceiverOffset));
307 __ str(r2, MemOperand(sp, argc * kPointerSize)); 339 __ str(r2, MemOperand(sp, argc * kPointerSize));
308 } 340 }
309 341
310 // Invoke the function. 342 // Invoke the function.
311 ParameterCount actual(argc); 343 ParameterCount actual(argc);
312 __ InvokeFunction(r1, actual, JUMP_FUNCTION); 344 __ InvokeFunction(r1, actual, JUMP_FUNCTION);
(...skipping 147 matching lines...) Expand 10 before | Expand all | Expand 10 after
460 __ b(lt, &miss); 492 __ b(lt, &miss);
461 // If this assert fails, we have to check upper bound too. 493 // If this assert fails, we have to check upper bound too.
462 ASSERT(LAST_TYPE == JS_FUNCTION_TYPE); 494 ASSERT(LAST_TYPE == JS_FUNCTION_TYPE);
463 495
464 // Check for access to global object (unlikely). 496 // Check for access to global object (unlikely).
465 __ cmp(r1, Operand(JS_GLOBAL_PROXY_TYPE)); 497 __ cmp(r1, Operand(JS_GLOBAL_PROXY_TYPE));
466 __ b(eq, &global); 498 __ b(eq, &global);
467 499
468 __ bind(&probe); 500 __ bind(&probe);
469 GenerateDictionaryLoad(masm, &miss, r1, r0); 501 GenerateDictionaryLoad(masm, &miss, r1, r0);
502 GenerateCheckNonFunctionOrLoaded(masm, &miss, r0, r1);
470 __ Ret(); 503 __ Ret();
471 504
472 // Global object access: Check access rights. 505 // Global object access: Check access rights.
473 __ bind(&global); 506 __ bind(&global);
474 __ CheckAccessGlobalProxy(r0, r1, &miss); 507 __ CheckAccessGlobalProxy(r0, r1, &miss);
475 __ b(&probe); 508 __ b(&probe);
476 509
477 // Cache miss: Restore receiver from stack and jump to runtime. 510 // Cache miss: Restore receiver from stack and jump to runtime.
478 __ bind(&miss); 511 __ bind(&miss);
479 Generate(masm, ExternalReference(IC_Utility(kLoadIC_Miss))); 512 Generate(masm, ExternalReference(IC_Utility(kLoadIC_Miss)));
(...skipping 144 matching lines...) Expand 10 before | Expand all | Expand 10 after
624 657
625 // Perform tail call to the entry. 658 // Perform tail call to the entry.
626 __ TailCallRuntime(f, 3); 659 __ TailCallRuntime(f, 3);
627 } 660 }
628 661
629 662
630 #undef __ 663 #undef __
631 664
632 665
633 } } // namespace v8::internal 666 } } // namespace v8::internal
OLDNEW
« no previous file with comments | « no previous file | src/ic-ia32.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698