<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[152944] branches/dfgFourthTier</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://trac.webkit.org/projects/webkit/changeset/152944">152944</a></dd>
<dt>Author</dt> <dd>fpizlo@apple.com</dd>
<dt>Date</dt> <dd>2013-07-20 10:58:57 -0700 (Sat, 20 Jul 2013)</dd>
</dl>

<h3>Log Message</h3>
<pre>fourthTier: String GetByVal out-of-bounds handling is so wrong
https://bugs.webkit.org/show_bug.cgi?id=118935

Source/JavaScriptCore: 

Reviewed by Geoffrey Garen.
        
Bunch of String GetByVal out-of-bounds fixes:
        
- Even if the string proto chain is sane, we need to watch out for negative
  indices. They may get values or call getters in the prototypes, since proto
  sanity doesn't check for negative indexed properties, as they are not
  technically indexed properties.
        
- GetByVal String out-of-bounds does in fact clobberWorld(). CSE should be
  given this information.
        
- GetByVal String out-of-bounds does in fact clobberWorld(). CFA should be
  given this information.
        
Also fixed some other things:
        
- If the DFG is disabled, the testRunner should pretend that we've done a
  bunch of DFG compiles. That's necessary to prevent the tests from timing
  out.
        
- Disassembler shouldn't try to dump source code since it's not safe in the
  concurrent JIT.

* API/JSCTestRunnerUtils.cpp:
(JSC::numberOfDFGCompiles):
* JavaScriptCore.xcodeproj/project.pbxproj:
* dfg/DFGAbstractInterpreterInlines.h:
(JSC::DFG::::executeEffects):
* dfg/DFGDisassembler.cpp:
(JSC::DFG::Disassembler::dumpHeader):
* dfg/DFGGraph.h:
(JSC::DFG::Graph::byValIsPure):
* dfg/DFGSaneStringGetByValSlowPathGenerator.h: Added.
(DFG):
(SaneStringGetByValSlowPathGenerator):
(JSC::DFG::SaneStringGetByValSlowPathGenerator::SaneStringGetByValSlowPathGenerator):
(JSC::DFG::SaneStringGetByValSlowPathGenerator::generateInternal):
* dfg/DFGSpeculativeJIT.cpp:
(JSC::DFG::SpeculativeJIT::compileGetByValOnString):

LayoutTests: 

Reviewed by Geoffrey Garen.

* fast/js/dfg-string-out-of-bounds-check-structure-expected.txt: Added.
* fast/js/dfg-string-out-of-bounds-check-structure.html: Added.
* fast/js/dfg-string-out-of-bounds-cse-expected.txt: Added.
* fast/js/dfg-string-out-of-bounds-cse.html: Added.
* fast/js/dfg-string-out-of-bounds-negative-check-structure-expected.txt: Added.
* fast/js/dfg-string-out-of-bounds-negative-check-structure.html: Added.
* fast/js/dfg-string-out-of-bounds-negative-proto-value-expected.txt: Added.
* fast/js/dfg-string-out-of-bounds-negative-proto-value.html: Added.
* fast/js/jsc-test-list:
* fast/js/script-tests/dfg-string-out-of-bounds-check-structure.js: Added.
(foo):
* fast/js/script-tests/dfg-string-out-of-bounds-cse.js: Added.
(foo):
* fast/js/script-tests/dfg-string-out-of-bounds-negative-check-structure.js: Added.
(foo):
(while):
* fast/js/script-tests/dfg-string-out-of-bounds-negative-proto-value.js: Added.
(foo):</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#branchesdfgFourthTierLayoutTestsChangeLog">branches/dfgFourthTier/LayoutTests/ChangeLog</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsjsctestlist">branches/dfgFourthTier/LayoutTests/fast/js/jsc-test-list</a></li>
<li><a href="#branchesdfgFourthTierSourceJavaScriptCoreAPIJSCTestRunnerUtilscpp">branches/dfgFourthTier/Source/JavaScriptCore/API/JSCTestRunnerUtils.cpp</a></li>
<li><a href="#branchesdfgFourthTierSourceJavaScriptCoreChangeLog">branches/dfgFourthTier/Source/JavaScriptCore/ChangeLog</a></li>
<li><a href="#branchesdfgFourthTierSourceJavaScriptCoreJavaScriptCorexcodeprojprojectpbxproj">branches/dfgFourthTier/Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj</a></li>
<li><a href="#branchesdfgFourthTierSourceJavaScriptCoredfgDFGAbstractInterpreterInlinesh">branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h</a></li>
<li><a href="#branchesdfgFourthTierSourceJavaScriptCoredfgDFGDisassemblercpp">branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGDisassembler.cpp</a></li>
<li><a href="#branchesdfgFourthTierSourceJavaScriptCoredfgDFGGraphh">branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGGraph.h</a></li>
<li><a href="#branchesdfgFourthTierSourceJavaScriptCoredfgDFGSpeculativeJITcpp">branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp</a></li>
</ul>

<h3>Added Paths</h3>
<ul>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundscheckstructureexpectedtxt">branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-check-structure-expected.txt</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundscheckstructurehtml">branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-check-structure.html</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundscseexpectedtxt">branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-cse-expected.txt</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundscsehtml">branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-cse.html</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundsnegativecheckstructureexpectedtxt">branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-check-structure-expected.txt</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundsnegativecheckstructurehtml">branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-check-structure.html</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundsnegativeprotovalueexpectedtxt">branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-proto-value-expected.txt</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundsnegativeprotovaluehtml">branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-proto-value.html</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsscripttestsdfgstringoutofboundscheckstructurejs">branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-check-structure.js</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsscripttestsdfgstringoutofboundscsejs">branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-cse.js</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsscripttestsdfgstringoutofboundsnegativecheckstructurejs">branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-negative-check-structure.js</a></li>
<li><a href="#branchesdfgFourthTierLayoutTestsfastjsscripttestsdfgstringoutofboundsnegativeprotovaluejs">branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-negative-proto-value.js</a></li>
<li><a href="#branchesdfgFourthTierSourceJavaScriptCoredfgDFGSaneStringGetByValSlowPathGeneratorh">branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGSaneStringGetByValSlowPathGenerator.h</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="branchesdfgFourthTierLayoutTestsChangeLog"></a>
<div class="modfile"><h4>Modified: branches/dfgFourthTier/LayoutTests/ChangeLog (152943 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/ChangeLog        2013-07-20 07:26:29 UTC (rev 152943)
+++ branches/dfgFourthTier/LayoutTests/ChangeLog        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -1,3 +1,29 @@
</span><ins>+2013-07-19  Filip Pizlo  &lt;fpizlo@apple.com&gt;
+
+        fourthTier: String GetByVal out-of-bounds handling is so wrong
+        https://bugs.webkit.org/show_bug.cgi?id=118935
+
+        Reviewed by Geoffrey Garen.
+
+        * fast/js/dfg-string-out-of-bounds-check-structure-expected.txt: Added.
+        * fast/js/dfg-string-out-of-bounds-check-structure.html: Added.
+        * fast/js/dfg-string-out-of-bounds-cse-expected.txt: Added.
+        * fast/js/dfg-string-out-of-bounds-cse.html: Added.
+        * fast/js/dfg-string-out-of-bounds-negative-check-structure-expected.txt: Added.
+        * fast/js/dfg-string-out-of-bounds-negative-check-structure.html: Added.
+        * fast/js/dfg-string-out-of-bounds-negative-proto-value-expected.txt: Added.
+        * fast/js/dfg-string-out-of-bounds-negative-proto-value.html: Added.
+        * fast/js/jsc-test-list:
+        * fast/js/script-tests/dfg-string-out-of-bounds-check-structure.js: Added.
+        (foo):
+        * fast/js/script-tests/dfg-string-out-of-bounds-cse.js: Added.
+        (foo):
+        * fast/js/script-tests/dfg-string-out-of-bounds-negative-check-structure.js: Added.
+        (foo):
+        (while):
+        * fast/js/script-tests/dfg-string-out-of-bounds-negative-proto-value.js: Added.
+        (foo):
+
</ins><span class="cx"> 2013-06-25  Filip Pizlo  &lt;fpizlo@apple.com&gt;
</span><span class="cx"> 
</span><span class="cx">         fourthTier: DFG should support switch_string
</span></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundscheckstructureexpectedtxt"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-check-structure-expected.txt (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-check-structure-expected.txt                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-check-structure-expected.txt        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,9 @@
</span><ins>+Tests what happens when you do a out-of-bounds access on a string and use that to install a getter that clobbers a structure.
+
+On success, you will see a series of &quot;PASS&quot; messages, followed by &quot;TEST COMPLETE&quot;.
+
+
+Passed some tests silently.
+
+TEST COMPLETE
+
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundscheckstructurehtml"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-check-structure.html (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-check-structure.html                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-check-structure.html        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,10 @@
</span><ins>+&lt;!DOCTYPE HTML PUBLIC &quot;-//IETF//DTD HTML//EN&quot;&gt;
+&lt;html&gt;
+&lt;head&gt;
+&lt;script src=&quot;resources/js-test-pre.js&quot;&gt;&lt;/script&gt;
+&lt;/head&gt;
+&lt;body&gt;
+&lt;script src=&quot;script-tests/dfg-string-out-of-bounds-check-structure.js&quot;&gt;&lt;/script&gt;
+&lt;script src=&quot;resources/js-test-post.js&quot;&gt;&lt;/script&gt;
+&lt;/body&gt;
+&lt;/html&gt;
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundscseexpectedtxt"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-cse-expected.txt (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-cse-expected.txt                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-cse-expected.txt        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,9 @@
</span><ins>+Tests what happens when you present a CSE opportunity across an out-of-bounds string access.
+
+On success, you will see a series of &quot;PASS&quot; messages, followed by &quot;TEST COMPLETE&quot;.
+
+
+Passed some tests silently.
+
+TEST COMPLETE
+
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundscsehtml"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-cse.html (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-cse.html                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-cse.html        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,10 @@
</span><ins>+&lt;!DOCTYPE HTML PUBLIC &quot;-//IETF//DTD HTML//EN&quot;&gt;
+&lt;html&gt;
+&lt;head&gt;
+&lt;script src=&quot;resources/js-test-pre.js&quot;&gt;&lt;/script&gt;
+&lt;/head&gt;
+&lt;body&gt;
+&lt;script src=&quot;script-tests/dfg-string-out-of-bounds-cse.js&quot;&gt;&lt;/script&gt;
+&lt;script src=&quot;resources/js-test-post.js&quot;&gt;&lt;/script&gt;
+&lt;/body&gt;
+&lt;/html&gt;
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundsnegativecheckstructureexpectedtxt"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-check-structure-expected.txt (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-check-structure-expected.txt                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-check-structure-expected.txt        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,9 @@
</span><ins>+Tests what happens when you do a negative out-of-bounds access on a string and use that to install a getter that clobbers a structure.
+
+On success, you will see a series of &quot;PASS&quot; messages, followed by &quot;TEST COMPLETE&quot;.
+
+
+Passed some tests silently.
+
+TEST COMPLETE
+
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundsnegativecheckstructurehtml"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-check-structure.html (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-check-structure.html                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-check-structure.html        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,10 @@
</span><ins>+&lt;!DOCTYPE HTML PUBLIC &quot;-//IETF//DTD HTML//EN&quot;&gt;
+&lt;html&gt;
+&lt;head&gt;
+&lt;script src=&quot;resources/js-test-pre.js&quot;&gt;&lt;/script&gt;
+&lt;/head&gt;
+&lt;body&gt;
+&lt;script src=&quot;script-tests/dfg-string-out-of-bounds-negative-check-structure.js&quot;&gt;&lt;/script&gt;
+&lt;script src=&quot;resources/js-test-post.js&quot;&gt;&lt;/script&gt;
+&lt;/body&gt;
+&lt;/html&gt;
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundsnegativeprotovalueexpectedtxt"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-proto-value-expected.txt (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-proto-value-expected.txt                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-proto-value-expected.txt        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,9 @@
</span><ins>+Tests what happens when you do a negative out-of-bounds access on a string while the prototype has a negative indexed property.
+
+On success, you will see a series of &quot;PASS&quot; messages, followed by &quot;TEST COMPLETE&quot;.
+
+
+Passed some tests silently.
+
+TEST COMPLETE
+
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsdfgstringoutofboundsnegativeprotovaluehtml"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-proto-value.html (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-proto-value.html                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/dfg-string-out-of-bounds-negative-proto-value.html        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,10 @@
</span><ins>+&lt;!DOCTYPE HTML PUBLIC &quot;-//IETF//DTD HTML//EN&quot;&gt;
+&lt;html&gt;
+&lt;head&gt;
+&lt;script src=&quot;resources/js-test-pre.js&quot;&gt;&lt;/script&gt;
+&lt;/head&gt;
+&lt;body&gt;
+&lt;script src=&quot;script-tests/dfg-string-out-of-bounds-negative-proto-value.js&quot;&gt;&lt;/script&gt;
+&lt;script src=&quot;resources/js-test-post.js&quot;&gt;&lt;/script&gt;
+&lt;/body&gt;
+&lt;/html&gt;
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsjsctestlist"></a>
<div class="modfile"><h4>Modified: branches/dfgFourthTier/LayoutTests/fast/js/jsc-test-list (152943 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/jsc-test-list        2013-07-20 07:26:29 UTC (rev 152943)
+++ branches/dfgFourthTier/LayoutTests/fast/js/jsc-test-list        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -199,6 +199,10 @@
</span><span class="cx"> fast/js/dfg-redundant-load-of-captured-variable-proven-constant
</span><span class="cx"> fast/js/dfg-side-effect-assignment-osr-exit
</span><span class="cx"> fast/js/dfg-sqrt-backwards-propagation
</span><ins>+fast/js/dfg-string-out-of-bounds-check-structure
+fast/js/dfg-string-out-of-bounds-cse
+fast/js/dfg-string-out-of-bounds-negative-check-structure
+fast/js/dfg-string-out-of-bounds-negative-proto-value
</ins><span class="cx"> fast/js/dfg-string-stricteq
</span><span class="cx"> fast/js/dfg-tear-off-arguments-not-activation
</span><span class="cx"> fast/js/dfg-to-string-bad-toString
</span></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsscripttestsdfgstringoutofboundscheckstructurejs"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-check-structure.js (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-check-structure.js                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-check-structure.js        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,29 @@
</span><ins>+description(
+&quot;Tests what happens when you do a out-of-bounds access on a string and use that to install a getter that clobbers a structure.&quot;
+);
+
+function foo(s, o) {
+    var x = o.f;
+    s[42];
+    var y = o.g;
+    return x + y;
+}
+
+noInline(foo);
+silentTestPass = true;
+
+var theObject = {};
+
+var didGetCalled = false;
+String.prototype.__defineGetter__(&quot;42&quot;, function() { didGetCalled = true; delete theObject.g; theObject.h = 42 });
+
+while (testRunner.numberOfDFGCompiles(foo) &lt; 1) {
+    didGetCalled = false;
+    shouldBe(&quot;foo(\&quot;hello\&quot;, {f:1, g:2})&quot;, &quot;3&quot;);
+    shouldBe(&quot;didGetCalled&quot;, &quot;true&quot;);
+}
+
+theObject = {f:1, g:2};
+didGetCalled = false;
+shouldBe(&quot;foo(\&quot;hello\&quot;, theObject)&quot;, &quot;0/0&quot;);
+shouldBe(&quot;didGetCalled&quot;, &quot;true&quot;);
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsscripttestsdfgstringoutofboundscsejs"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-cse.js (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-cse.js                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-cse.js        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,23 @@
</span><ins>+description(
+&quot;Tests what happens when you present a CSE opportunity across an out-of-bounds string access.&quot;
+);
+
+function foo(s, o) {
+    var x = o.f;
+    s[0];
+    var y = o.f;
+    return x + y;
+}
+
+noInline(foo);
+silentTestPass = true;
+
+var theObject = {};
+
+String.prototype.__defineGetter__(&quot;0&quot;, function() { theObject.f = 42; });
+
+while (!dfgCompiled({f:foo}))
+    shouldBe(&quot;foo(\&quot;\&quot;, {f:1})&quot;, &quot;2&quot;);
+
+theObject = {f:1};
+shouldBe(&quot;foo(\&quot;\&quot;, theObject)&quot;, &quot;43&quot;);
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsscripttestsdfgstringoutofboundsnegativecheckstructurejs"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-negative-check-structure.js (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-negative-check-structure.js                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-negative-check-structure.js        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,23 @@
</span><ins>+description(
+&quot;Tests what happens when you do a negative out-of-bounds access on a string and use that to install a getter that clobbers a structure.&quot;
+);
+
+function foo(s, o) {
+    var x = o.f;
+    s[-1];
+    var y = o.g;
+    return x + y;
+}
+
+noInline(foo);
+silentTestPass = true;
+
+var theObject = {};
+
+String.prototype.__defineGetter__(&quot;-1&quot;, function() { delete theObject.g; });
+
+while (testRunner.numberOfDFGCompiles(foo) &lt; 1)
+    shouldBe(&quot;foo(\&quot;hello\&quot;, {f:1, g:2})&quot;, &quot;3&quot;);
+
+theObject = {f:1, g:2};
+shouldBe(&quot;foo(\&quot;hello\&quot;, theObject)&quot;, &quot;0/0&quot;);
</ins></span></pre></div>
<a id="branchesdfgFourthTierLayoutTestsfastjsscripttestsdfgstringoutofboundsnegativeprotovaluejs"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-negative-proto-value.js (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-negative-proto-value.js                                (rev 0)
+++ branches/dfgFourthTier/LayoutTests/fast/js/script-tests/dfg-string-out-of-bounds-negative-proto-value.js        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,16 @@
</span><ins>+description(
+&quot;Tests what happens when you do a negative out-of-bounds access on a string while the prototype has a negative indexed property.&quot;
+);
+
+function foo(s) {
+    return s[-1];
+}
+
+noInline(foo);
+silentTestPass = true;
+
+String.prototype[-1] = &quot;hello&quot;;
+
+for (var i = 0; i &lt; 2; i = dfgIncrement({f:foo, i:i + 1, n:1, compiles:2}))
+    shouldBe(&quot;foo(\&quot;hello\&quot;)&quot;, &quot;\&quot;hello\&quot;&quot;);
+
</ins></span></pre></div>
<a id="branchesdfgFourthTierSourceJavaScriptCoreAPIJSCTestRunnerUtilscpp"></a>
<div class="modfile"><h4>Modified: branches/dfgFourthTier/Source/JavaScriptCore/API/JSCTestRunnerUtils.cpp (152943 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/Source/JavaScriptCore/API/JSCTestRunnerUtils.cpp        2013-07-20 07:26:29 UTC (rev 152943)
+++ branches/dfgFourthTier/Source/JavaScriptCore/API/JSCTestRunnerUtils.cpp        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -48,17 +48,23 @@
</span><span class="cx"> 
</span><span class="cx"> JSValueRef numberOfDFGCompiles(JSContextRef context, JSValueRef theFunctionValueRef)
</span><span class="cx"> {
</span><ins>+    bool pretendToHaveManyCompiles = false;
+#if ENABLE(DFG_JIT)
+    if (!Options::useJIT() || !Options::useDFGJIT())
+        pretendToHaveManyCompiles = true;
+#else
+    pretendToHaveManyCompiles = true;
+#endif
+    
</ins><span class="cx">     if (FunctionExecutable* executable = getExecutable(context, theFunctionValueRef)) {
</span><span class="cx">         CodeBlock* baselineCodeBlock = executable-&gt;baselineCodeBlockFor(CodeForCall);
</span><span class="cx">         
</span><span class="cx">         if (!baselineCodeBlock)
</span><span class="cx">             return JSValueMakeNumber(context, 0);
</span><span class="cx"> 
</span><del>-#if ENABLE(DFG_JIT)        
</del><ins>+        if (pretendToHaveManyCompiles)
+            return JSValueMakeNumber(context, 1000000.0);
</ins><span class="cx">         return JSValueMakeNumber(context, baselineCodeBlock-&gt;numberOfDFGCompiles());
</span><del>-#else
-        return JSValueMakeNumber(context, 1000000.0);
-#endif
</del><span class="cx">     }
</span><span class="cx">     
</span><span class="cx">     return JSValueMakeUndefined(context);
</span></span></pre></div>
<a id="branchesdfgFourthTierSourceJavaScriptCoreChangeLog"></a>
<div class="modfile"><h4>Modified: branches/dfgFourthTier/Source/JavaScriptCore/ChangeLog (152943 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/Source/JavaScriptCore/ChangeLog        2013-07-20 07:26:29 UTC (rev 152943)
+++ branches/dfgFourthTier/Source/JavaScriptCore/ChangeLog        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -1,5 +1,51 @@
</span><span class="cx"> 2013-07-19  Filip Pizlo  &lt;fpizlo@apple.com&gt;
</span><span class="cx"> 
</span><ins>+        fourthTier: String GetByVal out-of-bounds handling is so wrong
+        https://bugs.webkit.org/show_bug.cgi?id=118935
+
+        Reviewed by Geoffrey Garen.
+        
+        Bunch of String GetByVal out-of-bounds fixes:
+        
+        - Even if the string proto chain is sane, we need to watch out for negative
+          indices. They may get values or call getters in the prototypes, since proto
+          sanity doesn't check for negative indexed properties, as they are not
+          technically indexed properties.
+        
+        - GetByVal String out-of-bounds does in fact clobberWorld(). CSE should be
+          given this information.
+        
+        - GetByVal String out-of-bounds does in fact clobberWorld(). CFA should be
+          given this information.
+        
+        Also fixed some other things:
+        
+        - If the DFG is disabled, the testRunner should pretend that we've done a
+          bunch of DFG compiles. That's necessary to prevent the tests from timing
+          out.
+        
+        - Disassembler shouldn't try to dump source code since it's not safe in the
+          concurrent JIT.
+
+        * API/JSCTestRunnerUtils.cpp:
+        (JSC::numberOfDFGCompiles):
+        * JavaScriptCore.xcodeproj/project.pbxproj:
+        * dfg/DFGAbstractInterpreterInlines.h:
+        (JSC::DFG::::executeEffects):
+        * dfg/DFGDisassembler.cpp:
+        (JSC::DFG::Disassembler::dumpHeader):
+        * dfg/DFGGraph.h:
+        (JSC::DFG::Graph::byValIsPure):
+        * dfg/DFGSaneStringGetByValSlowPathGenerator.h: Added.
+        (DFG):
+        (SaneStringGetByValSlowPathGenerator):
+        (JSC::DFG::SaneStringGetByValSlowPathGenerator::SaneStringGetByValSlowPathGenerator):
+        (JSC::DFG::SaneStringGetByValSlowPathGenerator::generateInternal):
+        * dfg/DFGSpeculativeJIT.cpp:
+        (JSC::DFG::SpeculativeJIT::compileGetByValOnString):
+
+2013-07-19  Filip Pizlo  &lt;fpizlo@apple.com&gt;
+
</ins><span class="cx">         fourthTier: Structure::isValidOffset() should be able to tell you if you're loading a valid JSValue, and not just not crashing
</span><span class="cx">         https://bugs.webkit.org/show_bug.cgi?id=118911
</span><span class="cx"> 
</span></span></pre></div>
<a id="branchesdfgFourthTierSourceJavaScriptCoreJavaScriptCorexcodeprojprojectpbxproj"></a>
<div class="modfile"><h4>Modified: branches/dfgFourthTier/Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj (152943 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj        2013-07-20 07:26:29 UTC (rev 152943)
+++ branches/dfgFourthTier/Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -366,13 +366,14 @@
</span><span class="cx">                 0FE5057B178F5B5300B35F8C /* DFGOSRAvailabilityAnalysisPhase.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FE5056E178F5B5300B35F8C /* DFGOSRAvailabilityAnalysisPhase.h */; settings = {ATTRIBUTES = (Private, ); }; };
</span><span class="cx">                 0FE5057C178F5B5300B35F8C /* DFGSSAConversionPhase.cpp in Sources */ = {isa = PBXBuildFile; fileRef = 0FE5056F178F5B5300B35F8C /* DFGSSAConversionPhase.cpp */; };
</span><span class="cx">                 0FE5057D178F5B5300B35F8C /* DFGSSAConversionPhase.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FE50570178F5B5300B35F8C /* DFGSSAConversionPhase.h */; settings = {ATTRIBUTES = (Private, ); }; };
</span><ins>+                0FE5058217965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.cpp in Sources */ = {isa = PBXBuildFile; fileRef = 0FE5058017965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.cpp */; };
+                0FE5058317965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FE5058117965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.h */; settings = {ATTRIBUTES = (Private, ); }; };
</ins><span class="cx">                 0FE5058A1798ABF500B35F8C /* DFGAbstractInterpreter.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FE505861798ABF500B35F8C /* DFGAbstractInterpreter.h */; settings = {ATTRIBUTES = (Private, ); }; };
</span><span class="cx">                 0FE5058B1798ABF500B35F8C /* DFGAbstractInterpreterInlines.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FE505871798ABF500B35F8C /* DFGAbstractInterpreterInlines.h */; settings = {ATTRIBUTES = (Private, ); }; };
</span><span class="cx">                 0FE5058C1798ABF500B35F8C /* DFGInPlaceAbstractState.cpp in Sources */ = {isa = PBXBuildFile; fileRef = 0FE505881798ABF500B35F8C /* DFGInPlaceAbstractState.cpp */; };
</span><span class="cx">                 0FE5058D1798ABF500B35F8C /* DFGInPlaceAbstractState.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FE505891798ABF500B35F8C /* DFGInPlaceAbstractState.h */; settings = {ATTRIBUTES = (Private, ); }; };
</span><span class="cx">                 0FE5058F1798AE7100B35F8C /* DFGMergeMode.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FE5058E1798AE6F00B35F8C /* DFGMergeMode.h */; settings = {ATTRIBUTES = (Private, ); }; };
</span><del>-                0FE5058217965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.cpp in Sources */ = {isa = PBXBuildFile; fileRef = 0FE5058017965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.cpp */; };
-                0FE5058317965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FE5058117965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.h */; settings = {ATTRIBUTES = (Private, ); }; };
</del><ins>+                0FE50591179A492400B35F8C /* DFGSaneStringGetByValSlowPathGenerator.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FE50590179A492400B35F8C /* DFGSaneStringGetByValSlowPathGenerator.h */; settings = {ATTRIBUTES = (Private, ); }; };
</ins><span class="cx">                 0FE8534B1723CDA500B618F5 /* DFGDesiredWatchpoints.cpp in Sources */ = {isa = PBXBuildFile; fileRef = 0FE853491723CDA500B618F5 /* DFGDesiredWatchpoints.cpp */; };
</span><span class="cx">                 0FE8534C1723CDA500B618F5 /* DFGDesiredWatchpoints.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FE8534A1723CDA500B618F5 /* DFGDesiredWatchpoints.h */; settings = {ATTRIBUTES = (Private, ); }; };
</span><span class="cx">                 0FEA0A08170513DB00BB722C /* FTLAbbreviations.h in Headers */ = {isa = PBXBuildFile; fileRef = 0FEA09FD170513DB00BB722C /* FTLAbbreviations.h */; settings = {ATTRIBUTES = (Private, ); }; };
</span><span class="lines">@@ -1417,13 +1418,14 @@
</span><span class="cx">                 0FE5056E178F5B5300B35F8C /* DFGOSRAvailabilityAnalysisPhase.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = DFGOSRAvailabilityAnalysisPhase.h; path = dfg/DFGOSRAvailabilityAnalysisPhase.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><span class="cx">                 0FE5056F178F5B5300B35F8C /* DFGSSAConversionPhase.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; name = DFGSSAConversionPhase.cpp; path = dfg/DFGSSAConversionPhase.cpp; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><span class="cx">                 0FE50570178F5B5300B35F8C /* DFGSSAConversionPhase.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = DFGSSAConversionPhase.h; path = dfg/DFGSSAConversionPhase.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><ins>+                0FE5058017965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; name = DFGLoopPreHeaderCreationPhase.cpp; path = dfg/DFGLoopPreHeaderCreationPhase.cpp; sourceTree = &quot;&lt;group&gt;&quot;; };
+                0FE5058117965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = DFGLoopPreHeaderCreationPhase.h; path = dfg/DFGLoopPreHeaderCreationPhase.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</ins><span class="cx">                 0FE505861798ABF500B35F8C /* DFGAbstractInterpreter.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = DFGAbstractInterpreter.h; path = dfg/DFGAbstractInterpreter.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><span class="cx">                 0FE505871798ABF500B35F8C /* DFGAbstractInterpreterInlines.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = DFGAbstractInterpreterInlines.h; path = dfg/DFGAbstractInterpreterInlines.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><span class="cx">                 0FE505881798ABF500B35F8C /* DFGInPlaceAbstractState.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; name = DFGInPlaceAbstractState.cpp; path = dfg/DFGInPlaceAbstractState.cpp; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><span class="cx">                 0FE505891798ABF500B35F8C /* DFGInPlaceAbstractState.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = DFGInPlaceAbstractState.h; path = dfg/DFGInPlaceAbstractState.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><span class="cx">                 0FE5058E1798AE6F00B35F8C /* DFGMergeMode.h */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.c.h; name = DFGMergeMode.h; path = dfg/DFGMergeMode.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><del>-                0FE5058017965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; name = DFGLoopPreHeaderCreationPhase.cpp; path = dfg/DFGLoopPreHeaderCreationPhase.cpp; sourceTree = &quot;&lt;group&gt;&quot;; };
-                0FE5058117965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = DFGLoopPreHeaderCreationPhase.h; path = dfg/DFGLoopPreHeaderCreationPhase.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</del><ins>+                0FE50590179A492400B35F8C /* DFGSaneStringGetByValSlowPathGenerator.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = DFGSaneStringGetByValSlowPathGenerator.h; path = dfg/DFGSaneStringGetByValSlowPathGenerator.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</ins><span class="cx">                 0FE853491723CDA500B618F5 /* DFGDesiredWatchpoints.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; name = DFGDesiredWatchpoints.cpp; path = dfg/DFGDesiredWatchpoints.cpp; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><span class="cx">                 0FE8534A1723CDA500B618F5 /* DFGDesiredWatchpoints.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = DFGDesiredWatchpoints.h; path = dfg/DFGDesiredWatchpoints.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><span class="cx">                 0FEA09FD170513DB00BB722C /* FTLAbbreviations.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = FTLAbbreviations.h; path = ftl/FTLAbbreviations.h; sourceTree = &quot;&lt;group&gt;&quot;; };
</span><span class="lines">@@ -2985,7 +2987,6 @@
</span><span class="cx">                 86EC9DB31328DF44002B2AD7 /* dfg */ = {
</span><span class="cx">                         isa = PBXGroup;
</span><span class="cx">                         children = (
</span><del>-                                0FE5058E1798AE6F00B35F8C /* DFGMergeMode.h */,
</del><span class="cx">                                 0FE505861798ABF500B35F8C /* DFGAbstractInterpreter.h */,
</span><span class="cx">                                 0FE505871798ABF500B35F8C /* DFGAbstractInterpreterInlines.h */,
</span><span class="cx">                                 0F55C19317276E4600CEABFD /* DFGAbstractValue.cpp */,
</span><span class="lines">@@ -3083,6 +3084,7 @@
</span><span class="cx">                                 0FB4B51D16B62772003F696B /* DFGLongLivedState.h */,
</span><span class="cx">                                 0FE5058017965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.cpp */,
</span><span class="cx">                                 0FE5058117965C3D00B35F8C /* DFGLoopPreHeaderCreationPhase.h */,
</span><ins>+                                0FE5058E1798AE6F00B35F8C /* DFGMergeMode.h */,
</ins><span class="cx">                                 0F2BDC3D1522801700CD8910 /* DFGMinifiedGraph.h */,
</span><span class="cx">                                 0FB4B51016B3A964003F696B /* DFGMinifiedID.h */,
</span><span class="cx">                                 0F2BDC4C1522818300CD8910 /* DFGMinifiedNode.cpp */,
</span><span class="lines">@@ -3128,6 +3130,7 @@
</span><span class="cx">                                 0F766D4215B2A3BD008F363E /* DFGRegisterSet.h */,
</span><span class="cx">                                 86BB09BE138E381B0056702F /* DFGRepatch.cpp */,
</span><span class="cx">                                 86BB09BF138E381B0056702F /* DFGRepatch.h */,
</span><ins>+                                0FE50590179A492400B35F8C /* DFGSaneStringGetByValSlowPathGenerator.h */,
</ins><span class="cx">                                 86ECA3F9132DF25A002B2AD7 /* DFGScoreBoard.h */,
</span><span class="cx">                                 0F766D4515B3701D008F363E /* DFGScratchRegisterAllocator.h */,
</span><span class="cx">                                 0F1E3A65153A21DF000F9456 /* DFGSilentRegisterSavePlan.h */,
</span><span class="lines">@@ -3507,6 +3510,7 @@
</span><span class="cx">                                 0FC097A2146B28CC00CF2442 /* DFGThunks.h in Headers */,
</span><span class="cx">                                 0F3B3A2C15475002003ED0FF /* DFGValidate.h in Headers */,
</span><span class="cx">                                 0F2BDC471522802500CD8910 /* DFGValueRecoveryOverride.h in Headers */,
</span><ins>+                                0FE50591179A492400B35F8C /* DFGSaneStringGetByValSlowPathGenerator.h in Headers */,
</ins><span class="cx">                                 FED94F2F171E3E2300BE77A4 /* Watchdog.h in Headers */,
</span><span class="cx">                                 0FE5055D1787B0CF00B35F8C /* DFGCriticalEdgeBreakingPhase.h in Headers */,
</span><span class="cx">                                 0F2BDC481522802900CD8910 /* DFGValueSource.h in Headers */,
</span></span></pre></div>
<a id="branchesdfgFourthTierSourceJavaScriptCoredfgDFGAbstractInterpreterInlinesh"></a>
<div class="modfile"><h4>Modified: branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h (152943 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h        2013-07-20 07:26:29 UTC (rev 152943)
+++ branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -776,7 +776,9 @@
</span><span class="cx">                 // GetByVal operation the fact that we're using a watchpoint, using
</span><span class="cx">                 // something like Array::SaneChain (except not quite, because that
</span><span class="cx">                 // implies an in-bounds access). None of this feels like it's worth it,
</span><del>-                // so we're going with TOP for now.
</del><ins>+                // so we're going with TOP for now. The same thing applies to
+                // clobbering the world.
+                clobberWorld(node-&gt;codeOrigin, indexInBlock);
</ins><span class="cx">                 forNode(node).makeTop();
</span><span class="cx">             } else
</span><span class="cx">                 forNode(node).set(m_graph, m_graph.m_vm.stringStructure.get());
</span></span></pre></div>
<a id="branchesdfgFourthTierSourceJavaScriptCoredfgDFGDisassemblercpp"></a>
<div class="modfile"><h4>Modified: branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGDisassembler.cpp (152943 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGDisassembler.cpp        2013-07-20 07:26:29 UTC (rev 152943)
+++ branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGDisassembler.cpp        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -69,7 +69,6 @@
</span><span class="cx"> {
</span><span class="cx">     out.print(&quot;Generated DFG JIT code for &quot;, CodeBlockWithJITType(m_graph.m_codeBlock, JITCode::DFGJIT), &quot;, instruction count = &quot;, m_graph.m_codeBlock-&gt;instructionCount(), &quot;:\n&quot;);
</span><span class="cx">     out.print(&quot;    Optimized with execution counter = &quot;, m_graph.m_profiledBlock-&gt;jitExecuteCounter(), &quot;\n&quot;);
</span><del>-    out.print(&quot;    Source: &quot;, m_graph.m_codeBlock-&gt;sourceCodeOnOneLine(), &quot;\n&quot;);
</del><span class="cx">     out.print(&quot;    Code at [&quot;, RawPointer(linkBuffer.debugAddress()), &quot;, &quot;, RawPointer(static_cast&lt;char*&gt;(linkBuffer.debugAddress()) + linkBuffer.debugSize()), &quot;):\n&quot;);
</span><span class="cx"> }
</span><span class="cx"> 
</span></span></pre></div>
<a id="branchesdfgFourthTierSourceJavaScriptCoredfgDFGGraphh"></a>
<div class="modfile"><h4>Modified: branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGGraph.h (152943 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGGraph.h        2013-07-20 07:26:29 UTC (rev 152943)
+++ branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGGraph.h        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -492,7 +492,7 @@
</span><span class="cx">         case Array::SlowPutArrayStorage:
</span><span class="cx">             return !node-&gt;arrayMode().mayStoreToHole();
</span><span class="cx">         case Array::String:
</span><del>-            return node-&gt;op() == GetByVal;
</del><ins>+            return node-&gt;op() == GetByVal &amp;&amp; node-&gt;arrayMode().isInBounds();
</ins><span class="cx"> #if USE(JSVALUE32_64)
</span><span class="cx">         case Array::Arguments:
</span><span class="cx">             if (node-&gt;op() == GetByVal)
</span></span></pre></div>
<a id="branchesdfgFourthTierSourceJavaScriptCoredfgDFGSaneStringGetByValSlowPathGeneratorh"></a>
<div class="addfile"><h4>Added: branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGSaneStringGetByValSlowPathGenerator.h (0 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGSaneStringGetByValSlowPathGenerator.h                                (rev 0)
+++ branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGSaneStringGetByValSlowPathGenerator.h        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -0,0 +1,97 @@
</span><ins>+/*
+ * Copyright (C) 2013 Apple Inc. All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ *    notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ *    notice, this list of conditions and the following disclaimer in the
+ *    documentation and/or other materials provided with the distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY
+ * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
+ * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL APPLE INC. OR
+ * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
+ * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
+ * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
+ * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
+ * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 
+ */
+
+#ifndef DFGSaneStringGetByValSlowPathGenerator_h
+#define DFGSaneStringGetByValSlowPathGenerator_h
+
+#include &lt;wtf/Platform.h&gt;
+
+#if ENABLE(DFG_JIT)
+
+#include &quot;DFGCommon.h&quot;
+#include &quot;DFGOperations.h&quot;
+#include &quot;DFGSlowPathGenerator.h&quot;
+#include &quot;DFGSpeculativeJIT.h&quot;
+#include &lt;wtf/Vector.h&gt;
+
+namespace JSC { namespace DFG {
+
+class SaneStringGetByValSlowPathGenerator : public JumpingSlowPathGenerator&lt;MacroAssembler::Jump&gt; {
+public:
+    SaneStringGetByValSlowPathGenerator(
+        const MacroAssembler::Jump&amp; from, SpeculativeJIT* jit, JSValueRegs resultRegs,
+        GPRReg baseReg, GPRReg propertyReg)
+        : JumpingSlowPathGenerator&lt;MacroAssembler::Jump&gt;(from, jit)
+        , m_resultRegs(resultRegs)
+        , m_baseReg(baseReg)
+        , m_propertyReg(propertyReg)
+    {
+        jit-&gt;silentSpillAllRegistersImpl(false, m_plans, extractResult(resultRegs));
+    }
+    
+protected:
+    void generateInternal(SpeculativeJIT* jit)
+    {
+        linkFrom(jit);
+        
+        MacroAssembler::Jump isNeg = jit-&gt;m_jit.branch32(
+            MacroAssembler::LessThan, m_propertyReg, MacroAssembler::TrustedImm32(0));
+        
+#if USE(JSVALUE64)
+        jit-&gt;m_jit.move(
+            MacroAssembler::TrustedImm64(JSValue::encode(jsUndefined())), m_resultRegs.gpr());
+#else
+        jit-&gt;m_jit.move(
+            MacroAssembler::TrustedImm32(JSValue::UndefinedTag), m_resultRegs.tagGPR());
+        jit-&gt;m_jit.move(
+            MacroAssembler::TrustedImm32(0), m_resultRegs.payloadGPR());
+#endif
+        jumpTo(jit);
+        
+        isNeg.link(&amp;jit-&gt;m_jit);
+
+        for (unsigned i = 0; i &lt; m_plans.size(); ++i)
+            jit-&gt;silentSpill(m_plans[i]);
+        jit-&gt;callOperation(operationGetByValStringInt, extractResult(m_resultRegs), m_baseReg, m_propertyReg);
+        GPRReg canTrample = SpeculativeJIT::pickCanTrample(extractResult(m_resultRegs));
+        for (unsigned i = m_plans.size(); i--;)
+            jit-&gt;silentFill(m_plans[i], canTrample);
+        
+        jumpTo(jit);
+    }
+    
+private:
+    JSValueRegs m_resultRegs;
+    GPRReg m_baseReg;
+    GPRReg m_propertyReg;
+    Vector&lt;SilentRegisterSavePlan, 2&gt; m_plans;
+};
+
+} } // namespace JSC::DFG
+
+#endif // ENABLE(DFG_JIT)
+
+#endif // DFGSaneStringGetByValSlowPathGenerator_h
+
</ins></span></pre></div>
<a id="branchesdfgFourthTierSourceJavaScriptCoredfgDFGSpeculativeJITcpp"></a>
<div class="modfile"><h4>Modified: branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp (152943 => 152944)</h4>
<pre class="diff"><span>
<span class="info">--- branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp        2013-07-20 07:26:29 UTC (rev 152943)
+++ branches/dfgFourthTier/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp        2013-07-20 17:58:57 UTC (rev 152944)
</span><span class="lines">@@ -33,6 +33,7 @@
</span><span class="cx"> #include &quot;DFGArrayifySlowPathGenerator.h&quot;
</span><span class="cx"> #include &quot;DFGBinarySwitch.h&quot;
</span><span class="cx"> #include &quot;DFGCallArrayAllocatorSlowPathGenerator.h&quot;
</span><ins>+#include &quot;DFGSaneStringGetByValSlowPathGenerator.h&quot;
</ins><span class="cx"> #include &quot;DFGSlowPathGenerator.h&quot;
</span><span class="cx"> #include &quot;JSCJSValueInlines.h&quot;
</span><span class="cx"> #include &quot;LinkBuffer.h&quot;
</span><span class="lines">@@ -2114,16 +2115,12 @@
</span><span class="cx">         JSGlobalObject* globalObject = m_jit.globalObjectFor(node-&gt;codeOrigin);
</span><span class="cx">         if (globalObject-&gt;stringPrototypeChainIsSane()) {
</span><span class="cx"> #if USE(JSVALUE64)
</span><del>-            addSlowPathGenerator(
-                slowPathMove(
-                    outOfBounds, this, TrustedImm64(JSValue::encode(jsUndefined())),
-                    scratchReg));
</del><ins>+            addSlowPathGenerator(adoptPtr(new SaneStringGetByValSlowPathGenerator(
+                outOfBounds, this, JSValueRegs(scratchReg), baseReg, propertyReg)));
</ins><span class="cx"> #else
</span><del>-            addSlowPathGenerator(
-                slowPathMove(
-                    outOfBounds, this,
-                    TrustedImm32(JSValue::UndefinedTag), resultTagReg,
-                    TrustedImm32(0), scratchReg));
</del><ins>+            addSlowPathGenerator(adoptPtr(new SaneStringGetByValSlowPathGenerator(
+                outOfBounds, this, JSValueRegs(resultTagReg, scratchReg),
+                baseReg, propertyReg)));
</ins><span class="cx"> #endif
</span><span class="cx">         } else {
</span><span class="cx"> #if USE(JSVALUE64)
</span></span></pre>
</div>
</div>

</body>
</html>