Index: src/x64/full-codegen-x64.cc |
diff --git a/src/x64/full-codegen-x64.cc b/src/x64/full-codegen-x64.cc |
index 1a997dac85c975ed3edd0545da7708afcc95ed3a..073ecce60610078f73cdae01b22b1edd8d15a815 100644 |
--- a/src/x64/full-codegen-x64.cc |
+++ b/src/x64/full-codegen-x64.cc |
@@ -901,6 +901,8 @@ void FullCodeGenerator::VisitForInStatement(ForInStatement* stmt) { |
__ cmpq(rax, null_value); |
__ j(equal, &exit); |
+ PrepareForBailoutForId(stmt->PrepareId(), TOS_REG); |
+ |
// Convert the object to a JS object. |
Label convert, done_convert; |
__ JumpIfSmi(rax, &convert); |
@@ -922,47 +924,7 @@ void FullCodeGenerator::VisitForInStatement(ForInStatement* stmt) { |
// the JSObject::IsSimpleEnum cache validity checks. If we cannot |
// guarantee cache validity, call the runtime system to check cache |
// validity or get the property names in a fixed array. |
- Label next; |
- Register empty_fixed_array_value = r8; |
- __ LoadRoot(empty_fixed_array_value, Heap::kEmptyFixedArrayRootIndex); |
- Register empty_descriptor_array_value = r9; |
- __ LoadRoot(empty_descriptor_array_value, |
- Heap::kEmptyDescriptorArrayRootIndex); |
- __ movq(rcx, rax); |
- __ bind(&next); |
- |
- // Check that there are no elements. Register rcx contains the |
- // current JS object we've reached through the prototype chain. |
- __ cmpq(empty_fixed_array_value, |
- FieldOperand(rcx, JSObject::kElementsOffset)); |
- __ j(not_equal, &call_runtime); |
- |
- // Check that instance descriptors are not empty so that we can |
- // check for an enum cache. Leave the map in rbx for the subsequent |
- // prototype load. |
- __ movq(rbx, FieldOperand(rcx, HeapObject::kMapOffset)); |
- __ movq(rdx, FieldOperand(rbx, Map::kInstanceDescriptorsOrBitField3Offset)); |
- __ JumpIfSmi(rdx, &call_runtime); |
- |
- // Check that there is an enum cache in the non-empty instance |
- // descriptors (rdx). This is the case if the next enumeration |
- // index field does not contain a smi. |
- __ movq(rdx, FieldOperand(rdx, DescriptorArray::kEnumerationIndexOffset)); |
- __ JumpIfSmi(rdx, &call_runtime); |
- |
- // For all objects but the receiver, check that the cache is empty. |
- Label check_prototype; |
- __ cmpq(rcx, rax); |
- __ j(equal, &check_prototype, Label::kNear); |
- __ movq(rdx, FieldOperand(rdx, DescriptorArray::kEnumCacheBridgeCacheOffset)); |
- __ cmpq(rdx, empty_fixed_array_value); |
- __ j(not_equal, &call_runtime); |
- |
- // Load the prototype from the map and loop if non-null. |
- __ bind(&check_prototype); |
- __ movq(rcx, FieldOperand(rbx, Map::kPrototypeOffset)); |
- __ cmpq(rcx, null_value); |
- __ j(not_equal, &next); |
+ __ CheckEnumCache(null_value, &call_runtime); |
// The enum cache is valid. Load the map of the object being |
// iterated over and use the cache for the iteration. |
@@ -1014,6 +976,7 @@ void FullCodeGenerator::VisitForInStatement(ForInStatement* stmt) { |
__ Push(Smi::FromInt(0)); // Initial index. |
// Generate code for doing the condition check. |
+ PrepareForBailoutForId(stmt->BodyId(), NO_REGISTERS); |
__ bind(&loop); |
__ movq(rax, Operand(rsp, 0 * kPointerSize)); // Get the current index. |
__ cmpq(rax, Operand(rsp, 1 * kPointerSize)); // Compare to the array length. |
@@ -1059,7 +1022,7 @@ void FullCodeGenerator::VisitForInStatement(ForInStatement* stmt) { |
__ movq(result_register(), rbx); |
// Perform the assignment as if via '='. |
{ EffectContext context(this); |
- EmitAssignment(stmt->each(), stmt->AssignmentId()); |
+ EmitAssignment(stmt->each()); |
} |
// Generate code for the body of the loop. |
@@ -1078,6 +1041,7 @@ void FullCodeGenerator::VisitForInStatement(ForInStatement* stmt) { |
__ addq(rsp, Immediate(5 * kPointerSize)); |
// Exit and decrement the loop depth. |
+ PrepareForBailoutForId(stmt->ExitId(), NO_REGISTERS); |
__ bind(&exit); |
decrement_loop_depth(); |
} |
@@ -1800,7 +1764,7 @@ void FullCodeGenerator::EmitBinaryOp(BinaryOperation* expr, |
} |
-void FullCodeGenerator::EmitAssignment(Expression* expr, int bailout_ast_id) { |
+void FullCodeGenerator::EmitAssignment(Expression* expr) { |
// Invalid left-hand sides are rewritten to have a 'throw |
// ReferenceError' on the left-hand side. |
if (!expr->IsValidLeftHandSide()) { |
@@ -1852,7 +1816,6 @@ void FullCodeGenerator::EmitAssignment(Expression* expr, int bailout_ast_id) { |
break; |
} |
} |
- PrepareForBailoutForId(bailout_ast_id, TOS_REG); |
context()->Plug(rax); |
} |