2 * Copyright (C) 2013, 2014 Apple Inc. All rights reserved.
4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that the following conditions
7 * 1. Redistributions of source code must retain the above copyright
8 * notice, this list of conditions and the following disclaimer.
9 * 2. Redistributions in binary form must reproduce the above copyright
10 * notice, this list of conditions and the following disclaimer in the
11 * documentation and/or other materials provided with the distribution.
13 * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY
14 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
15 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
16 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE INC. OR
17 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
18 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
19 * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
20 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
21 * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
22 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
23 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
26 #ifndef DFGSafeToExecute_h
27 #define DFGSafeToExecute_h
33 namespace JSC
{ namespace DFG
{
35 template<typename AbstractStateType
>
36 class SafeToExecuteEdge
{
38 SafeToExecuteEdge(AbstractStateType
& state
)
44 void operator()(Node
*, Edge edge
)
46 switch (edge
.useKind()) {
50 case DoubleRepRealUse
:
57 case ObjectOrOtherUse
:
61 case StringOrStringObjectUse
:
67 case DoubleRepMachineIntUse
:
71 if (m_state
.forNode(edge
).m_type
& ~SpecInt32
)
76 if (m_state
.forNode(edge
).m_type
& ~SpecCell
)
81 if (m_state
.forNode(edge
).m_type
& ~SpecString
)
86 RELEASE_ASSERT_NOT_REACHED();
89 RELEASE_ASSERT_NOT_REACHED();
92 bool result() const { return m_result
; }
94 AbstractStateType
& m_state
;
98 // Determines if it's safe to execute a node within the given abstract state. This may
99 // return false conservatively. If it returns true, then you can hoist the given node
100 // up to the given point and expect that it will not crash. This doesn't guarantee that
101 // the node will produce the result you wanted other than not crashing.
102 template<typename AbstractStateType
>
103 bool safeToExecute(AbstractStateType
& state
, Graph
& graph
, Node
* node
)
105 SafeToExecuteEdge
<AbstractStateType
> safeToExecuteEdge(state
);
106 DFG_NODE_DO_TO_CHILDREN(graph
, node
, safeToExecuteEdge
);
107 if (!safeToExecuteEdge
.result())
110 switch (node
->op()) {
130 case GetLocalUnlinked
:
162 case CheckExecutable
:
166 case ArrayifyToStructure
:
171 case GetClosureRegisters
:
176 case VariableWatchpoint
:
177 case VarInjectionWatchpoint
:
179 case AllocationProfileWatchpoint
:
185 case CompareGreaterEq
:
187 case CompareEqConstant
:
188 case CompareStrictEq
:
193 case NewArrayWithSize
:
197 case ProfileWillCall
:
199 case CheckHasInstance
:
211 case NewStringObject
:
214 case CreateActivation
:
215 case TearOffActivation
:
216 case CreateArguments
:
217 case PhantomArguments
:
218 case TearOffArguments
:
219 case GetMyArgumentsLength
:
220 case GetMyArgumentByVal
:
221 case GetMyArgumentsLengthSafe
:
222 case GetMyArgumentByValSafe
:
223 case CheckArgumentsNotCreated
:
224 case NewFunctionNoCheck
:
226 case NewFunctionExpression
:
232 case ThrowReferenceError
:
235 case CheckWatchdogTimer
:
236 case StringFromCharCode
:
239 case ExtractOSREntryLocal
:
240 case CheckTierUpInLoop
:
241 case CheckTierUpAtReturn
:
242 case CheckTierUpAndOSREnter
:
245 case StoreBarrierWithNullCheck
:
246 case InvalidationPoint
:
248 case FunctionReentryWatchpoint
:
249 case TypedArrayWatchpoint
:
251 case ConstantStoragePointer
:
253 case MultiGetByOffset
:
254 case MultiPutByOffset
:
258 case BooleanToNumber
:
263 case GetIndexedPropertyStorage
:
268 case StringCharCodeAt
:
269 return node
->arrayMode().alreadyChecked(graph
, node
, state
.forNode(node
->child1()));
271 case GetTypedArrayByteOffset
:
272 return !(state
.forNode(node
->child1()).m_type
& ~(SpecTypedArrayView
));
277 return node
->arrayMode().modeForPut().alreadyChecked(
278 graph
, node
, state
.forNode(graph
.varArgChild(node
, 0)));
280 case StructureTransitionWatchpoint
:
281 return state
.forNode(node
->child1()).m_futurePossibleStructure
.isSubsetOf(
282 StructureSet(node
->structure()));
285 case PhantomPutStructure
:
286 case AllocatePropertyStorage
:
287 case ReallocatePropertyStorage
:
288 return state
.forNode(node
->child1()).m_currentKnownStructure
.isSubsetOf(
289 StructureSet(node
->structureTransitionData().previousStructure
));
293 return state
.forNode(node
->child1()).m_currentKnownStructure
.isValidOffset(
294 graph
.m_storageAccessData
[node
->storageAccessDataIndex()].offset
);
297 RELEASE_ASSERT_NOT_REACHED();
301 RELEASE_ASSERT_NOT_REACHED();
305 } } // namespace JSC::DFG
307 #endif // ENABLE(DFG_JIT)
309 #endif // DFGSafeToExecute_h