Index: src/crankshaft/arm64/lithium-codegen-arm64.cc |
diff --git a/src/crankshaft/arm64/lithium-codegen-arm64.cc b/src/crankshaft/arm64/lithium-codegen-arm64.cc |
index 5c90beb68ef79d5b81d0625e5073b6941ba1baf9..ab0dd936b6a931aae8df6603f4ac9a84e67171ea 100644 |
--- a/src/crankshaft/arm64/lithium-codegen-arm64.cc |
+++ b/src/crankshaft/arm64/lithium-codegen-arm64.cc |
@@ -1979,7 +1979,8 @@ void LCodeGen::CallKnownFunction(Handle<JSFunction> function, |
// Change context. |
__ Ldr(cp, FieldMemOperand(function_reg, JSFunction::kContextOffset)); |
- // Always initialize x0 to the number of actual arguments. |
+ // Always initialize new target and number of actual arguments. |
+ __ LoadRoot(x3, Heap::kUndefinedValueRootIndex); |
__ Mov(arity_reg, arity); |
// Invoke function. |
@@ -2047,11 +2048,13 @@ void LCodeGen::DoCallJSFunction(LCallJSFunction* instr) { |
DCHECK(instr->IsMarkedAsCall()); |
DCHECK(ToRegister(instr->function()).is(x1)); |
- __ Mov(x0, Operand(instr->arity())); |
- |
// Change context. |
__ Ldr(cp, FieldMemOperand(x1, JSFunction::kContextOffset)); |
+ // Always initialize new target and number of actual arguments. |
+ __ LoadRoot(x3, Heap::kUndefinedValueRootIndex); |
+ __ Mov(x0, instr->arity()); |
+ |
// Load the code entry address |
__ Ldr(x10, FieldMemOperand(x1, JSFunction::kCodeEntryOffset)); |
__ Call(x10); |