Index: src/x64/macro-assembler-x64.cc |
diff --git a/src/x64/macro-assembler-x64.cc b/src/x64/macro-assembler-x64.cc |
index 0c31809588befb995187f4fc66431a936e36dfa2..3217ae91beef2ab0c334838fa03941d2cbac9205 100644 |
--- a/src/x64/macro-assembler-x64.cc |
+++ b/src/x64/macro-assembler-x64.cc |
@@ -5615,19 +5615,39 @@ void MacroAssembler::TestJSArrayForAllocationMemento( |
Register receiver_reg, |
Register scratch_reg, |
Label* no_memento_found) { |
- ExternalReference new_space_start = |
- ExternalReference::new_space_start(isolate()); |
+ Label map_check; |
+ Label top_check; |
ExternalReference new_space_allocation_top = |
ExternalReference::new_space_allocation_top_address(isolate()); |
- |
- leap(scratch_reg, Operand(receiver_reg, |
- JSArray::kSize + AllocationMemento::kSize - kHeapObjectTag)); |
- Move(kScratchRegister, new_space_start); |
- cmpp(scratch_reg, kScratchRegister); |
- j(less, no_memento_found); |
+ const int kMementoMapOffset = JSArray::kSize - kHeapObjectTag; |
+ const int kMementoEndOffset = kMementoMapOffset + AllocationMemento::kSize; |
+ |
+ // Bail out if the object is not in new space. |
+ JumpIfNotInNewSpace(receiver_reg, scratch_reg, no_memento_found); |
+ // If the object is in new space, we need to check whether it is on the same |
+ // page as the current top. |
+ leap(scratch_reg, Operand(receiver_reg, kMementoEndOffset)); |
+ xorp(scratch_reg, ExternalOperand(new_space_allocation_top)); |
+ testp(scratch_reg, Immediate(~Page::kPageAlignmentMask)); |
+ j(zero, &top_check); |
+ // The object is on a different page than allocation top. Bail out if the |
+ // object sits on the page boundary as no memento can follow and we cannot |
+ // touch the memory following it. |
+ leap(scratch_reg, Operand(receiver_reg, kMementoEndOffset)); |
+ xorp(scratch_reg, receiver_reg); |
+ testp(scratch_reg, Immediate(~Page::kPageAlignmentMask)); |
+ j(not_zero, no_memento_found); |
+ // Continue with the actual map check. |
+ jmp(&map_check); |
+ // If top is on the same page as the current object, we need to check whether |
+ // we are below top. |
+ bind(&top_check); |
+ leap(scratch_reg, Operand(receiver_reg, kMementoEndOffset)); |
cmpp(scratch_reg, ExternalOperand(new_space_allocation_top)); |
j(greater, no_memento_found); |
- CompareRoot(MemOperand(scratch_reg, -AllocationMemento::kSize), |
+ // Memento map check. |
+ bind(&map_check); |
+ CompareRoot(MemOperand(receiver_reg, kMementoMapOffset), |
Heap::kAllocationMementoMapRootIndex); |
} |