diff options
-rw-r--r-- | chromium/v8/src/codegen/bailout-reason.h | 1 | ||||
-rw-r--r-- | chromium/v8/src/compiler/pipeline.cc | 22 |
2 files changed, 22 insertions, 1 deletions
diff --git a/chromium/v8/src/codegen/bailout-reason.h b/chromium/v8/src/codegen/bailout-reason.h index c99730d1c78..5babb1ed2a7 100644 --- a/chromium/v8/src/codegen/bailout-reason.h +++ b/chromium/v8/src/codegen/bailout-reason.h @@ -95,6 +95,7 @@ namespace internal { V(kNoReason, "no reason") \ \ V(kBailedOutDueToDependencyChange, "Bailed out due to dependency change") \ + V(kConcurrentMapDeprecation, "Maps became deprecated during optimization")\ V(kCodeGenerationFailed, "Code generation failed") \ V(kCyclicObjectStateDetectedInEscapeAnalysis, \ "Cyclic object state detected by escape analysis") \ diff --git a/chromium/v8/src/compiler/pipeline.cc b/chromium/v8/src/compiler/pipeline.cc index a71427f5682..2aa9fc3d5d8 100644 --- a/chromium/v8/src/compiler/pipeline.cc +++ b/chromium/v8/src/compiler/pipeline.cc @@ -701,7 +701,10 @@ class PipelineImpl final { // Step D. Run the code finalization pass. MaybeHandle<Code> FinalizeCode(bool retire_broker = true); - // Step E. Install any code dependencies. + // Step E. Ensure all embedded maps are non-deprecated. + bool CheckNoDeprecatedMaps(Handle<Code> code); + + // Step F. Install any code dependencies. bool CommitDependencies(Handle<Code> code); void VerifyGeneratedCodeIsIdempotent(); @@ -1237,6 +1240,9 @@ PipelineCompilationJob::Status PipelineCompilationJob::FinalizeJobImpl( } return FAILED; } + if (!pipeline_.CheckNoDeprecatedMaps(code)) { + return RetryOptimization(BailoutReason::kConcurrentMapDeprecation); + } if (!pipeline_.CommitDependencies(code)) { return RetryOptimization(BailoutReason::kBailedOutDueToDependencyChange); } @@ -3686,6 +3692,20 @@ MaybeHandle<Code> PipelineImpl::GenerateCode(CallDescriptor* call_descriptor) { return FinalizeCode(); } +// We must not embed deprecated maps, as we rely in the compiler on all explicit +// maps not being deprecated. +bool PipelineImpl::CheckNoDeprecatedMaps(Handle<Code> code) { + int mode_mask = RelocInfo::EmbeddedObjectModeMask(); + for (RelocIterator it(*code, mode_mask); !it.done(); it.next()) { + DCHECK(RelocInfo::IsEmbeddedObjectMode(it.rinfo()->rmode())); + HeapObject obj = it.rinfo()->target_object(data_->isolate()); + if (obj.IsMap() && Map::cast(obj).is_deprecated()) { + return false; + } + } + return true; +} + bool PipelineImpl::CommitDependencies(Handle<Code> code) { return data_->dependencies() == nullptr || data_->dependencies()->Commit(code); |