4671cb5644
This reverts commit 91e3243d60
.
Reason for revert: This deopts to the wrong point.
Original change's description:
> Extend GetIterator bytecode to perform JSReceiver check on object[Symbol.iterator]()
>
> Current GetIterator bytecode loads and calls @@iterator property on a
> given object. This change extends the bytecode functionality to check
> whether the value returned after calling @@iterator property is a valid
> JSReceiver. The bytecode throws SymbolIteratorInvalid exception if the
> returned value is not a valid JSReceiver. This change absorbs the
> functionality of additional two bytecodes - JumpIfJSReceiver and
> CallRuntime, that are part of the iterator protocol in the GetIterator
> bytecode.
>
> Bug: v8:9489
> Change-Id: I9e84cfe85eeb9a1b8a97ca0595375ac26ba1bbfd
> Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/1792905
> Reviewed-by: Leszek Swirski <leszeks@chromium.org>
> Reviewed-by: Tobias Tebbi <tebbi@chromium.org>
> Commit-Queue: Swapnil Gaikwad <swapnilgaikwad@google.com>
> Cr-Commit-Position: refs/heads/master@{#63704}
TBR=rmcilroy@chromium.org,leszeks@chromium.org,tebbi@chromium.org,swapnilgaikwad@google.com
# Not skipping CQ checks because original CL landed > 1 day ago.
Bug: v8:9489
Change-Id: I9324b5b01ead29912ad793a1e7b4d009643d7901
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/1960288
Reviewed-by: Tobias Tebbi <tebbi@chromium.org>
Commit-Queue: Tobias Tebbi <tebbi@chromium.org>
Cr-Commit-Position: refs/heads/master@{#65541}
69 lines
2.1 KiB
JavaScript
69 lines
2.1 KiB
JavaScript
// Copyright 2019 the V8 project authors. All rights reserved.
|
|
// Use of this source code is governed by a BSD-style license that can be
|
|
// found in the LICENSE file.
|
|
|
|
// The GetIterator bytecode is used to implement a part of the iterator
|
|
// protocol (https://tc39.es/ecma262/#sec-getiterator). Here, the
|
|
// bytecode performs multiple operations including some that have side-effects
|
|
// and may deoptimize eagerly or lazily.
|
|
// This test ensures the eager deoptimization is handled correctly.
|
|
|
|
// Flags: --allow-natives-syntax --no-always-opt
|
|
|
|
var getIteratorCount = 0;
|
|
var iteratorCount = 0;
|
|
var iteratorAfterEagerDeoptCount = 0;
|
|
|
|
function foo(obj) {
|
|
// The following for-of loop uses the iterator protocol to iterate
|
|
// over the 'obj'.
|
|
// The GetIterator bytecode invovlves 2 steps:
|
|
// 1. method = GetMethod(obj, @@iterator)
|
|
// 2. iterator = Call(method, obj).
|
|
for(var x of obj){}
|
|
}
|
|
|
|
// This iterator gets inlined when the 'foo' function is JIT compiled for
|
|
// the first time.
|
|
var iterator = function() {
|
|
iteratorCount++;
|
|
return {
|
|
next: function() {
|
|
return { done: true };
|
|
}
|
|
}
|
|
}
|
|
|
|
var iteratorAfterEagerDeopt = function() {
|
|
iteratorAfterEagerDeoptCount++;
|
|
return {
|
|
next: function() {
|
|
return { done: true };
|
|
}
|
|
}
|
|
}
|
|
|
|
// Here, retrieval of function at @@iterator has side effect (increments the
|
|
// 'getIteratorCount'). Changing the value of 'iterator' in the JIT compiled
|
|
// 'foo' causes deoptimization after the count is incremented. Now the deopt
|
|
// cannot resume at the beginning of the bytecode because it would end up in
|
|
// incrementing the count again.
|
|
let y = { get [Symbol.iterator] () {
|
|
getIteratorCount++;
|
|
return iterator;
|
|
}
|
|
};
|
|
|
|
%PrepareFunctionForOptimization(foo);
|
|
foo(y);
|
|
foo(y);
|
|
%OptimizeFunctionOnNextCall(foo);
|
|
|
|
// Change the value of 'iterator' to trigger eager deoptimization of 'foo'.
|
|
iterator = iteratorAfterEagerDeopt
|
|
foo(y);
|
|
assertUnoptimized(foo);
|
|
assertEquals(getIteratorCount, 3);
|
|
assertEquals(iteratorCount, 2);
|
|
assertEquals(iteratorAfterEagerDeoptCount, 1);
|