| Index: src/runtime.cc
|
| diff --git a/src/runtime.cc b/src/runtime.cc
|
| index 80b68279468fba09989f34c62ebf5a2e07175b07..9df3ff882e61479fe3953a122d74a3705a103de6 100644
|
| --- a/src/runtime.cc
|
| +++ b/src/runtime.cc
|
| @@ -14688,7 +14688,7 @@ RUNTIME_FUNCTION(MaybeObject*, Runtime_IsAccessAllowedForObserver) {
|
|
|
| static MaybeObject* ArrayConstructorCommon(Isolate* isolate,
|
| Handle<JSFunction> constructor,
|
| - Handle<Object> type_info,
|
| + Handle<AllocationSite> site,
|
| Arguments* caller_args) {
|
| bool holey = false;
|
| bool can_use_type_feedback = true;
|
| @@ -14710,14 +14710,7 @@ static MaybeObject* ArrayConstructorCommon(Isolate* isolate,
|
|
|
| JSArray* array;
|
| MaybeObject* maybe_array;
|
| - if (!type_info.is_null() &&
|
| - *type_info != isolate->heap()->undefined_value() &&
|
| - Cell::cast(*type_info)->value()->IsAllocationSite() &&
|
| - can_use_type_feedback) {
|
| - Handle<Cell> cell = Handle<Cell>::cast(type_info);
|
| - Handle<AllocationSite> site = Handle<AllocationSite>(
|
| - AllocationSite::cast(cell->value()), isolate);
|
| - ASSERT(!site->SitePointsToLiteral());
|
| + if (!site.is_null() && can_use_type_feedback) {
|
| ElementsKind to_kind = site->GetElementsKind();
|
| if (holey && !IsFastHoleyElementsKind(to_kind)) {
|
| to_kind = GetHoleyElementsKind(to_kind);
|
| @@ -14743,8 +14736,17 @@ static MaybeObject* ArrayConstructorCommon(Isolate* isolate,
|
| maybe_array = isolate->heap()->AllocateJSArrayStorage(array, 0, 0,
|
| DONT_INITIALIZE_ARRAY_ELEMENTS);
|
| if (maybe_array->IsFailure()) return maybe_array;
|
| + ElementsKind old_kind = array->GetElementsKind();
|
| maybe_array = ArrayConstructInitializeElements(array, caller_args);
|
| if (maybe_array->IsFailure()) return maybe_array;
|
| + if (!site.is_null() &&
|
| + (old_kind != array->GetElementsKind() ||
|
| + !can_use_type_feedback)) {
|
| + // The arguments passed in caused a transition. This kind of complexity
|
| + // can't be dealt with in the inlined hydrogen array constructor case.
|
| + // We must mark the allocationsite as un-inlinable.
|
| + site->SetDoNotInlineCall();
|
| + }
|
| return array;
|
| }
|
|
|
| @@ -14771,9 +14773,19 @@ RUNTIME_FUNCTION(MaybeObject*, Runtime_ArrayConstructor) {
|
| ASSERT(arg_count == caller_args->length());
|
| }
|
| #endif
|
| +
|
| + Handle<AllocationSite> site;
|
| + if (!type_info.is_null() &&
|
| + *type_info != isolate->heap()->undefined_value() &&
|
| + Cell::cast(*type_info)->value()->IsAllocationSite()) {
|
| + site = Handle<AllocationSite>(
|
| + AllocationSite::cast(Cell::cast(*type_info)->value()), isolate);
|
| + ASSERT(!site->SitePointsToLiteral());
|
| + }
|
| +
|
| return ArrayConstructorCommon(isolate,
|
| constructor,
|
| - type_info,
|
| + site,
|
| caller_args);
|
| }
|
|
|
| @@ -14796,7 +14808,7 @@ RUNTIME_FUNCTION(MaybeObject*, Runtime_InternalArrayConstructor) {
|
| #endif
|
| return ArrayConstructorCommon(isolate,
|
| constructor,
|
| - Handle<Object>::null(),
|
| + Handle<AllocationSite>::null(),
|
| caller_args);
|
| }
|
|
|
|
|