DescriptionX87: Array() in optimized code can create with wrong ElementsKind in corner cases
port 13459c1ae3caa4cc546c522177bac5450a3252bf (r27857)
original commit message:
Array() in optimized code can create with wrong ElementsKind in corner cases.
Calling new Array(JSObject::kInitialMaxFastElementArray) in optimized code
makes a stub call that bails out due to the length. Currently, the bailout
code a) doesn't have the allocation site, and b) wouldn't use it if it did
because the length is perceived to be too high.
This CL passes the allocation site to the stub call (rather than undefined),
and alters the bailout code to utilize the feedback.
BUG=
Committed: https://crrev.com/5729299752c2ea3d2cae1844219273afc9ada3ca
Cr-Commit-Position: refs/heads/master@{#27875}
Patch Set 1 #
Messages
Total messages: 7 (2 generated)
|