OLD | NEW |
1 // Copyright 2012 the V8 project authors. All rights reserved. | 1 // Copyright 2012 the V8 project authors. All rights reserved. |
2 // Redistribution and use in source and binary forms, with or without | 2 // Redistribution and use in source and binary forms, with or without |
3 // modification, are permitted provided that the following conditions are | 3 // modification, are permitted provided that the following conditions are |
4 // met: | 4 // met: |
5 // | 5 // |
6 // * Redistributions of source code must retain the above copyright | 6 // * Redistributions of source code must retain the above copyright |
7 // notice, this list of conditions and the following disclaimer. | 7 // notice, this list of conditions and the following disclaimer. |
8 // * Redistributions in binary form must reproduce the above | 8 // * Redistributions in binary form must reproduce the above |
9 // copyright notice, this list of conditions and the following | 9 // copyright notice, this list of conditions and the following |
10 // disclaimer in the documentation and/or other materials provided | 10 // disclaimer in the documentation and/or other materials provided |
(...skipping 714 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
725 ASSERT(cell->value()->IsTheHole()); | 725 ASSERT(cell->value()->IsTheHole()); |
726 __ Move(scratch, cell); | 726 __ Move(scratch, cell); |
727 __ Cmp(FieldOperand(scratch, JSGlobalPropertyCell::kValueOffset), | 727 __ Cmp(FieldOperand(scratch, JSGlobalPropertyCell::kValueOffset), |
728 masm->isolate()->factory()->the_hole_value()); | 728 masm->isolate()->factory()->the_hole_value()); |
729 __ j(not_equal, miss); | 729 __ j(not_equal, miss); |
730 } | 730 } |
731 | 731 |
732 | 732 |
733 // Both name_reg and receiver_reg are preserved on jumps to miss_label, | 733 // Both name_reg and receiver_reg are preserved on jumps to miss_label, |
734 // but may be destroyed if store is successful. | 734 // but may be destroyed if store is successful. |
735 void StubCompiler::GenerateStoreField(MacroAssembler* masm, | 735 void StubCompiler::GenerateStoreTransition(MacroAssembler* masm, |
736 Handle<JSObject> object, | 736 Handle<JSObject> object, |
737 LookupResult* lookup, | 737 LookupResult* lookup, |
738 Handle<Map> transition, | 738 Handle<Map> transition, |
739 Handle<Name> name, | 739 Handle<Name> name, |
740 Register receiver_reg, | 740 Register receiver_reg, |
741 Register name_reg, | 741 Register name_reg, |
742 Register value_reg, | 742 Register value_reg, |
743 Register scratch1, | 743 Register scratch1, |
744 Register scratch2, | 744 Register scratch2, |
745 Label* miss_label, | 745 Label* miss_label, |
746 Label* miss_restore_name) { | 746 Label* miss_restore_name) { |
747 // Check that the map of the object hasn't changed. | 747 // Check that the map of the object hasn't changed. |
748 CompareMapMode mode = transition.is_null() ? ALLOW_ELEMENT_TRANSITION_MAPS | |
749 : REQUIRE_EXACT_MAP; | |
750 __ CheckMap(receiver_reg, Handle<Map>(object->map()), | 748 __ CheckMap(receiver_reg, Handle<Map>(object->map()), |
751 miss_label, DO_SMI_CHECK, mode); | 749 miss_label, DO_SMI_CHECK, REQUIRE_EXACT_MAP); |
752 | 750 |
753 // Perform global security token check if needed. | 751 // Perform global security token check if needed. |
754 if (object->IsJSGlobalProxy()) { | 752 if (object->IsJSGlobalProxy()) { |
755 __ CheckAccessGlobalProxy(receiver_reg, scratch1, miss_label); | 753 __ CheckAccessGlobalProxy(receiver_reg, scratch1, miss_label); |
756 } | 754 } |
757 | 755 |
758 // Check that we are allowed to write this. | 756 // Check that we are allowed to write this. |
759 if (!transition.is_null() && object->GetPrototype()->IsJSObject()) { | 757 if (object->GetPrototype()->IsJSObject()) { |
760 JSObject* holder; | 758 JSObject* holder; |
761 // holder == object indicates that no property was found. | 759 // holder == object indicates that no property was found. |
762 if (lookup->holder() != *object) { | 760 if (lookup->holder() != *object) { |
763 holder = lookup->holder(); | 761 holder = lookup->holder(); |
764 } else { | 762 } else { |
765 // Find the top object. | 763 // Find the top object. |
766 holder = *object; | 764 holder = *object; |
767 do { | 765 do { |
768 holder = JSObject::cast(holder->GetPrototype()); | 766 holder = JSObject::cast(holder->GetPrototype()); |
769 } while (holder->GetPrototype()->IsJSObject()); | 767 } while (holder->GetPrototype()->IsJSObject()); |
(...skipping 17 matching lines...) Expand all Loading... |
787 masm, miss_restore_name, holder_reg, name, scratch1, scratch2); | 785 masm, miss_restore_name, holder_reg, name, scratch1, scratch2); |
788 } | 786 } |
789 } | 787 } |
790 } | 788 } |
791 | 789 |
792 // Stub never generated for non-global objects that require access | 790 // Stub never generated for non-global objects that require access |
793 // checks. | 791 // checks. |
794 ASSERT(object->IsJSGlobalProxy() || !object->IsAccessCheckNeeded()); | 792 ASSERT(object->IsJSGlobalProxy() || !object->IsAccessCheckNeeded()); |
795 | 793 |
796 // Perform map transition for the receiver if necessary. | 794 // Perform map transition for the receiver if necessary. |
797 if (!transition.is_null() && (object->map()->unused_property_fields() == 0)) { | 795 if (object->map()->unused_property_fields() == 0) { |
798 // The properties must be extended before we can store the value. | 796 // The properties must be extended before we can store the value. |
799 // We jump to a runtime call that extends the properties array. | 797 // We jump to a runtime call that extends the properties array. |
800 __ pop(scratch1); // Return address. | 798 __ pop(scratch1); // Return address. |
801 __ push(receiver_reg); | 799 __ push(receiver_reg); |
802 __ Push(transition); | 800 __ Push(transition); |
803 __ push(value_reg); | 801 __ push(value_reg); |
804 __ push(scratch1); | 802 __ push(scratch1); |
805 __ TailCallExternalReference( | 803 __ TailCallExternalReference( |
806 ExternalReference(IC_Utility(IC::kSharedStoreIC_ExtendStorage), | 804 ExternalReference(IC_Utility(IC::kSharedStoreIC_ExtendStorage), |
807 masm->isolate()), | 805 masm->isolate()), |
808 3, | 806 3, |
809 1); | 807 1); |
810 return; | 808 return; |
811 } | 809 } |
812 | 810 |
813 int index; | 811 // Update the map of the object. |
814 if (!transition.is_null()) { | 812 __ Move(scratch1, transition); |
815 // Update the map of the object. | 813 __ movq(FieldOperand(receiver_reg, HeapObject::kMapOffset), scratch1); |
816 __ Move(scratch1, transition); | |
817 __ movq(FieldOperand(receiver_reg, HeapObject::kMapOffset), scratch1); | |
818 | 814 |
819 // Update the write barrier for the map field and pass the now unused | 815 // Update the write barrier for the map field and pass the now unused |
820 // name_reg as scratch register. | 816 // name_reg as scratch register. |
821 __ RecordWriteField(receiver_reg, | 817 __ RecordWriteField(receiver_reg, |
822 HeapObject::kMapOffset, | 818 HeapObject::kMapOffset, |
823 scratch1, | 819 scratch1, |
824 name_reg, | 820 name_reg, |
825 kDontSaveFPRegs, | 821 kDontSaveFPRegs, |
826 OMIT_REMEMBERED_SET, | 822 OMIT_REMEMBERED_SET, |
827 OMIT_SMI_CHECK); | 823 OMIT_SMI_CHECK); |
828 index = transition->instance_descriptors()->GetFieldIndex( | 824 |
829 transition->LastAdded()); | 825 int index = transition->instance_descriptors()->GetFieldIndex( |
830 } else { | 826 transition->LastAdded()); |
831 index = lookup->GetFieldIndex().field_index(); | |
832 } | |
833 | 827 |
834 // Adjust for the number of properties stored in the object. Even in the | 828 // Adjust for the number of properties stored in the object. Even in the |
835 // face of a transition we can use the old map here because the size of the | 829 // face of a transition we can use the old map here because the size of the |
836 // object and the number of in-object properties is not going to change. | 830 // object and the number of in-object properties is not going to change. |
837 index -= object->map()->inobject_properties(); | 831 index -= object->map()->inobject_properties(); |
838 | 832 |
| 833 // TODO(verwaest): Share this code as a code stub. |
839 if (index < 0) { | 834 if (index < 0) { |
840 // Set the property straight into the object. | 835 // Set the property straight into the object. |
841 int offset = object->map()->instance_size() + (index * kPointerSize); | 836 int offset = object->map()->instance_size() + (index * kPointerSize); |
| 837 __ movq(FieldOperand(receiver_reg, offset), value_reg); |
| 838 |
| 839 // Update the write barrier for the array address. |
| 840 // Pass the value being stored in the now unused name_reg. |
| 841 __ movq(name_reg, value_reg); |
| 842 __ RecordWriteField( |
| 843 receiver_reg, offset, name_reg, scratch1, kDontSaveFPRegs); |
| 844 } else { |
| 845 // Write to the properties array. |
| 846 int offset = index * kPointerSize + FixedArray::kHeaderSize; |
| 847 // Get the properties array (optimistically). |
| 848 __ movq(scratch1, FieldOperand(receiver_reg, JSObject::kPropertiesOffset)); |
| 849 __ movq(FieldOperand(scratch1, offset), value_reg); |
| 850 |
| 851 // Update the write barrier for the array address. |
| 852 // Pass the value being stored in the now unused name_reg. |
| 853 __ movq(name_reg, value_reg); |
| 854 __ RecordWriteField( |
| 855 scratch1, offset, name_reg, receiver_reg, kDontSaveFPRegs); |
| 856 } |
| 857 |
| 858 // Return the value (register rax). |
| 859 ASSERT(value_reg.is(rax)); |
| 860 __ ret(0); |
| 861 } |
| 862 |
| 863 |
| 864 // Both name_reg and receiver_reg are preserved on jumps to miss_label, |
| 865 // but may be destroyed if store is successful. |
| 866 void StubCompiler::GenerateStoreField(MacroAssembler* masm, |
| 867 Handle<JSObject> object, |
| 868 LookupResult* lookup, |
| 869 Register receiver_reg, |
| 870 Register name_reg, |
| 871 Register value_reg, |
| 872 Register scratch1, |
| 873 Register scratch2, |
| 874 Label* miss_label) { |
| 875 // Check that the map of the object hasn't changed. |
| 876 __ CheckMap(receiver_reg, Handle<Map>(object->map()), |
| 877 miss_label, DO_SMI_CHECK, ALLOW_ELEMENT_TRANSITION_MAPS); |
| 878 |
| 879 // Perform global security token check if needed. |
| 880 if (object->IsJSGlobalProxy()) { |
| 881 __ CheckAccessGlobalProxy(receiver_reg, scratch1, miss_label); |
| 882 } |
| 883 |
| 884 // Stub never generated for non-global objects that require access |
| 885 // checks. |
| 886 ASSERT(object->IsJSGlobalProxy() || !object->IsAccessCheckNeeded()); |
| 887 |
| 888 int index = lookup->GetFieldIndex().field_index(); |
| 889 |
| 890 // Adjust for the number of properties stored in the object. Even in the |
| 891 // face of a transition we can use the old map here because the size of the |
| 892 // object and the number of in-object properties is not going to change. |
| 893 index -= object->map()->inobject_properties(); |
| 894 |
| 895 // TODO(verwaest): Share this code as a code stub. |
| 896 if (index < 0) { |
| 897 // Set the property straight into the object. |
| 898 int offset = object->map()->instance_size() + (index * kPointerSize); |
842 __ movq(FieldOperand(receiver_reg, offset), value_reg); | 899 __ movq(FieldOperand(receiver_reg, offset), value_reg); |
843 | 900 |
844 // Update the write barrier for the array address. | 901 // Update the write barrier for the array address. |
845 // Pass the value being stored in the now unused name_reg. | 902 // Pass the value being stored in the now unused name_reg. |
846 __ movq(name_reg, value_reg); | 903 __ movq(name_reg, value_reg); |
847 __ RecordWriteField( | 904 __ RecordWriteField( |
848 receiver_reg, offset, name_reg, scratch1, kDontSaveFPRegs); | 905 receiver_reg, offset, name_reg, scratch1, kDontSaveFPRegs); |
849 } else { | 906 } else { |
850 // Write to the properties array. | 907 // Write to the properties array. |
851 int offset = index * kPointerSize + FixedArray::kHeaderSize; | 908 int offset = index * kPointerSize + FixedArray::kHeaderSize; |
(...skipping 2561 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
3413 TailCallBuiltin(masm, Builtins::kKeyedStoreIC_Slow); | 3470 TailCallBuiltin(masm, Builtins::kKeyedStoreIC_Slow); |
3414 } | 3471 } |
3415 } | 3472 } |
3416 | 3473 |
3417 | 3474 |
3418 #undef __ | 3475 #undef __ |
3419 | 3476 |
3420 } } // namespace v8::internal | 3477 } } // namespace v8::internal |
3421 | 3478 |
3422 #endif // V8_TARGET_ARCH_X64 | 3479 #endif // V8_TARGET_ARCH_X64 |
OLD | NEW |