Remove and clean up more code.

This commit is contained in:
wolfbeast 2019-06-16 19:55:05 +00:00 • committed by Roy Tam
commit 90bb3e7f1d
8 changed files with 26 additions and 88 deletions

View file

@ -5365,13 +5365,6 @@ GetTemplateObjectForSimd(JSContext* cx, JSFunction* target, MutableHandleObject
return true; return true;
} }
static void
EnsureArrayGroupAnalyzed(JSContext* cx, JSObject* obj)
{
if (PreliminaryObjectArrayWithTemplate* objects = obj->group()->maybePreliminaryObjects())
objects->maybeAnalyze(cx, obj->group(), /* forceAnalyze = */ true);
}
static bool static bool
GetTemplateObjectForNative(JSContext* cx, HandleFunction target, const CallArgs& args, GetTemplateObjectForNative(JSContext* cx, HandleFunction target, const CallArgs& args,
MutableHandleObject res, bool* skipAttach) MutableHandleObject res, bool* skipAttach)
@ -5403,10 +5396,7 @@ GetTemplateObjectForNative(JSContext* cx, HandleFunction target, const CallArgs&
// With this and other array templates, analyze the group so that // With this and other array templates, analyze the group so that
// we don't end up with a template whose structure might change later. // we don't end up with a template whose structure might change later.
res.set(NewFullyAllocatedArrayForCallingAllocationSite(cx, count, TenuredObject)); res.set(NewFullyAllocatedArrayForCallingAllocationSite(cx, count, TenuredObject));
if (!res) return !!res;
return false;
EnsureArrayGroupAnalyzed(cx, res);
return true;
} }
} }
@ -5432,10 +5422,7 @@ GetTemplateObjectForNative(JSContext* cx, HandleFunction target, const CallArgs&
} }
res.set(NewFullyAllocatedArrayTryReuseGroup(cx, &args.thisv().toObject(), 0, res.set(NewFullyAllocatedArrayTryReuseGroup(cx, &args.thisv().toObject(), 0,
TenuredObject)); TenuredObject));
if (!res) return !!res;
return false;
EnsureArrayGroupAnalyzed(cx, res);
return true;
} }
} }
} }
@ -5452,10 +5439,7 @@ GetTemplateObjectForNative(JSContext* cx, HandleFunction target, const CallArgs&
} }
res.set(NewFullyAllocatedArrayForCallingAllocationSite(cx, 0, TenuredObject)); res.set(NewFullyAllocatedArrayForCallingAllocationSite(cx, 0, TenuredObject));
if (!res) return !!res;
return false;
EnsureArrayGroupAnalyzed(cx, res);
return true;
} }
if (native == StringConstructor) { if (native == StringConstructor) {
@ -5768,7 +5752,6 @@ CopyArray(JSContext* cx, HandleArrayObject arr, MutableHandleValue result)
ArrayObject* nobj = NewFullyAllocatedArrayTryReuseGroup(cx, arr, length, TenuredObject); ArrayObject* nobj = NewFullyAllocatedArrayTryReuseGroup(cx, arr, length, TenuredObject);
if (!nobj) if (!nobj)
return false; return false;
EnsureArrayGroupAnalyzed(cx, nobj); //XXX
MOZ_ASSERT(arr->isNative()); MOZ_ASSERT(arr->isNative());
MOZ_ASSERT(nobj->isNative()); MOZ_ASSERT(nobj->isNative());

View file

@ -9234,7 +9234,7 @@ class MLoadElement
ALLOW_CLONE(MLoadElement) ALLOW_CLONE(MLoadElement)
}; };
// Load a value from the elements vector for a dense native or unboxed array. // Load a value from the elements vector of a native object.
// If the index is out-of-bounds, or the indexed slot has a hole, undefined is // If the index is out-of-bounds, or the indexed slot has a hole, undefined is
// returned instead. // returned instead.
class MLoadElementHole class MLoadElementHole
@ -9465,10 +9465,10 @@ class MStoreElement
ALLOW_CLONE(MStoreElement) ALLOW_CLONE(MStoreElement)
}; };
// Like MStoreElement, but supports indexes >= initialized length, and can // Like MStoreElement, but supports indexes >= initialized length. The downside
// handle unboxed arrays. The downside is that we cannot hoist the elements // is that we cannot hoist the elements vector and bounds check, since this
// vector and bounds check, since this instruction may update the (initialized) // instruction may update the (initialized) length and reallocate the elements
// length and reallocate the elements vector. // vector.
class MStoreElementHole class MStoreElementHole
: public MAryInstruction<4>, : public MAryInstruction<4>,
public MStoreElementCommon, public MStoreElementCommon,

View file

@ -2261,9 +2261,6 @@ js::array_unshift(JSContext* cx, unsigned argc, Value* vp)
if (args.length() > 0) { if (args.length() > 0) {
/* Slide up the array to make room for all args at the bottom. */ /* Slide up the array to make room for all args at the bottom. */
if (length > 0) { if (length > 0) {
// Only include a fast path for boxed arrays. Unboxed arrays can'nt
// be optimized here because unshifting temporarily places holes at
// the start of the array.
bool optimized = false; bool optimized = false;
do { do {
if (!obj->is<ArrayObject>()) if (!obj->is<ArrayObject>())
@ -2323,10 +2320,10 @@ js::array_unshift(JSContext* cx, unsigned argc, Value* vp)
} }
/* /*
* Returns true if this is a dense or unboxed array whose |count| properties * Returns true if this is a dense array whose properties ending at |endIndex|
* starting from |startingIndex| may be accessed (get, set, delete) directly * (exclusive) may be accessed (get, set, delete) directly through its
* through its contiguous vector of elements without fear of getters, setters, * contiguous vector of elements without fear of getters, setters, etc. along
* etc. along the prototype chain, or of enumerators requiring notification of * the prototype chain, or of enumerators requiring notification of
* modifications. * modifications.
*/ */
static inline bool static inline bool
@ -3550,10 +3547,10 @@ js::NewDenseCopyOnWriteArray(JSContext* cx, HandleArrayObject templateObject, gc
return arr; return arr;
} }
// Return a new boxed or unboxed array with the specified length and allocated // Return a new array with the specified length and allocated capacity (up to
// capacity (up to maxLength), using the specified group if possible. If the // maxLength), using the specified group if possible. If the specified group
// specified group cannot be used, ensure that the created array at least has // cannot be used, ensure that the created array at least has the given
// the given [[Prototype]]. // [[Prototype]].
template <uint32_t maxLength> template <uint32_t maxLength>
static inline ArrayObject* static inline ArrayObject*
NewArrayTryUseGroup(ExclusiveContext* cx, HandleObjectGroup group, size_t length, NewArrayTryUseGroup(ExclusiveContext* cx, HandleObjectGroup group, size_t length,
@ -3561,10 +3558,7 @@ NewArrayTryUseGroup(ExclusiveContext* cx, HandleObjectGroup group, size_t length
{ {
MOZ_ASSERT(newKind != SingletonObject); MOZ_ASSERT(newKind != SingletonObject);
if (group->maybePreliminaryObjects()) if (group->shouldPreTenure())
group->maybePreliminaryObjects()->maybeAnalyze(cx, group);
if (group->shouldPreTenure() || group->maybePreliminaryObjects())
newKind = TenuredObject; newKind = TenuredObject;
RootedObject proto(cx, group->proto().toObject()); RootedObject proto(cx, group->proto().toObject());
@ -3579,9 +3573,6 @@ NewArrayTryUseGroup(ExclusiveContext* cx, HandleObjectGroup group, size_t length
if (res->length() > INT32_MAX) if (res->length() > INT32_MAX)
res->setLength(cx, res->length()); res->setLength(cx, res->length());
if (PreliminaryObjectArray* preliminaryObjects = group->maybePreliminaryObjects())
preliminaryObjects->registerNewObject(res);
return res; return res;
} }
@ -3601,10 +3592,7 @@ js::NewPartlyAllocatedArrayTryUseGroup(ExclusiveContext* cx, HandleObjectGroup g
// Return a new array with the default prototype and specified allocated // Return a new array with the default prototype and specified allocated
// capacity and length. If possible, try to reuse the group of the input // capacity and length. If possible, try to reuse the group of the input
// object. The resulting array will either reuse the input object's group or // object. The resulting array will either reuse the input object's group or
// will have unknown property types. Additionally, the result will have the // will have unknown property types.
// same boxed/unboxed elements representation as the input object, unless
// |length| is larger than the input object's initialized length (in which case
// UnboxedArrayObject::MaximumCapacity might be exceeded).
template <uint32_t maxLength> template <uint32_t maxLength>
static inline ArrayObject* static inline ArrayObject*
NewArrayTryReuseGroup(JSContext* cx, JSObject* obj, size_t length, NewArrayTryReuseGroup(JSContext* cx, JSObject* obj, size_t length,

View file

@ -75,8 +75,6 @@ NewDenseFullyAllocatedArrayWithTemplate(JSContext* cx, uint32_t length, JSObject
extern ArrayObject* extern ArrayObject*
NewDenseCopyOnWriteArray(JSContext* cx, HandleArrayObject templateObject, gc::InitialHeap heap); NewDenseCopyOnWriteArray(JSContext* cx, HandleArrayObject templateObject, gc::InitialHeap heap);
// The methods below can create either boxed or unboxed arrays.
extern ArrayObject* extern ArrayObject*
NewFullyAllocatedArrayTryUseGroup(ExclusiveContext* cx, HandleObjectGroup group, size_t length, NewFullyAllocatedArrayTryUseGroup(ExclusiveContext* cx, HandleObjectGroup group, size_t length,
NewObjectKind newKind = GenericObject); NewObjectKind newKind = GenericObject);

View file

@ -4933,7 +4933,7 @@ js::NewObjectOperation(JSContext* cx, HandleScript script, jsbytecode* pc,
newKind = TenuredObject; newKind = TenuredObject;
} }
RootedObject obj(cx); RootedPlainObject obj(cx);
if (*pc == JSOP_NEWOBJECT) { if (*pc == JSOP_NEWOBJECT) {
RootedPlainObject baseObject(cx, &script->getObject(pc)->as<PlainObject>()); RootedPlainObject baseObject(cx, &script->getObject(pc)->as<PlainObject>());
@ -5011,9 +5011,6 @@ js::NewArrayOperation(JSContext* cx, HandleScript script, jsbytecode* pc, uint32
MOZ_ASSERT(obj->isSingleton()); MOZ_ASSERT(obj->isSingleton());
} else { } else {
obj->setGroup(group); obj->setGroup(group);
if (PreliminaryObjectArray* preliminaryObjects = group->maybePreliminaryObjects())
preliminaryObjects->registerNewObject(obj);
} }
return obj; return obj;

View file

@ -838,17 +838,6 @@ ObjectGroup::newArrayObject(ExclusiveContext* cx,
AddTypePropertyId(cx, group, nullptr, JSID_VOID, elementType); AddTypePropertyId(cx, group, nullptr, JSID_VOID, elementType);
if (elementType != TypeSet::UnknownType()) {
// Keep track of the initial objects we create with this type.
// If the initial ones have a consistent shape and property types, we
// will try to use an unboxed layout for the group.
PreliminaryObjectArrayWithTemplate* preliminaryObjects =
cx->new_<PreliminaryObjectArrayWithTemplate>(nullptr);
if (!preliminaryObjects)
return nullptr;
group->setPreliminaryObjects(preliminaryObjects);
}
if (!p.add(cx, *table, ObjectGroupCompartment::ArrayObjectKey(elementType), group)) if (!p.add(cx, *table, ObjectGroupCompartment::ArrayObjectKey(elementType), group))
return nullptr; return nullptr;
} }
@ -856,9 +845,6 @@ ObjectGroup::newArrayObject(ExclusiveContext* cx,
// The type of the elements being added will already be reflected in type // The type of the elements being added will already be reflected in type
// information. // information.
ShouldUpdateTypes updateTypes = ShouldUpdateTypes::DontUpdate; ShouldUpdateTypes updateTypes = ShouldUpdateTypes::DontUpdate;
if (group->maybePreliminaryObjects())
group->maybePreliminaryObjects()->maybeAnalyze(cx, group);
return NewCopiedArrayTryUseGroup(cx, group, vp, length, newKind, updateTypes); return NewCopiedArrayTryUseGroup(cx, group, vp, length, newKind, updateTypes);
} }
@ -868,26 +854,12 @@ GiveObjectGroup(ExclusiveContext* cx, JSObject* source, JSObject* target)
{ {
MOZ_ASSERT(source->group() != target->group()); MOZ_ASSERT(source->group() != target->group());
if (!target->is<ArrayObject>()) if (!target->is<ArrayObject>() || !source->is<ArrayObject>()) {
return true; return true;
if (target->group()->maybePreliminaryObjects()) {
bool force = IsInsideNursery(source);
target->group()->maybePreliminaryObjects()->maybeAnalyze(cx, target->group(), force);
} }
ObjectGroup* sourceGroup = source->group();
if (source->is<ArrayObject>()) {
source->setGroup(target->group()); source->setGroup(target->group());
} else {
return true;
}
if (sourceGroup->maybePreliminaryObjects())
sourceGroup->maybePreliminaryObjects()->unregisterObject(source);
if (target->group()->maybePreliminaryObjects())
target->group()->maybePreliminaryObjects()->registerNewObject(source);
for (size_t i = 0; i < source->as<ArrayObject>().getDenseInitializedLength(); i++) { for (size_t i = 0; i < source->as<ArrayObject>().getDenseInitializedLength(); i++) {
Value v = source->as<ArrayObject>().getDenseElement(i); Value v = source->as<ArrayObject>().getDenseElement(i);
AddTypePropertyId(cx, source->group(), source, JSID_VOID, v); AddTypePropertyId(cx, source->group(), source, JSID_VOID, v);

View file

@ -3393,7 +3393,7 @@ JSFunction::setTypeForScriptedFunction(ExclusiveContext* cx, HandleFunction fun,
///////////////////////////////////////////////////////////////////// /////////////////////////////////////////////////////////////////////
void void
PreliminaryObjectArray::registerNewObject(JSObject* res) PreliminaryObjectArray::registerNewObject(PlainObject* res)
{ {
// The preliminary object pointers are weak, and won't be swept properly // The preliminary object pointers are weak, and won't be swept properly
// during nursery collections, so the preliminary objects need to be // during nursery collections, so the preliminary objects need to be
@ -3411,7 +3411,7 @@ PreliminaryObjectArray::registerNewObject(JSObject* res)
} }
void void
PreliminaryObjectArray::unregisterObject(JSObject* obj) PreliminaryObjectArray::unregisterObject(PlainObject* obj)
{ {
for (size_t i = 0; i < COUNT; i++) { for (size_t i = 0; i < COUNT; i++) {
if (objects[i] == obj) { if (objects[i] == obj) {

View file

@ -814,8 +814,8 @@ class PreliminaryObjectArray
public: public:
PreliminaryObjectArray() = default; PreliminaryObjectArray() = default;
void registerNewObject(JSObject* res); void registerNewObject(PlainObject* res);
void unregisterObject(JSObject* obj); void unregisterObject(PlainObject* obj);
JSObject* get(size_t i) const { JSObject* get(size_t i) const {
MOZ_ASSERT(i < COUNT); MOZ_ASSERT(i < COUNT);