Closed Bug 1994205 Opened 11 months ago Closed 11 months ago

Pasting small text on https://opentype.js.org/ is 3x slower in Firefox and spends time in things like IonInstanceOfIC::update, map, and js::BaseShape::clasp

Categories

(Core :: JavaScript Engine, task, P3)

task

Tracking

()

VERIFIED FIXED
146 Branch
Tracking Status
firefox146 --- fixed

People

(Reporter: mayankleoboy1, Assigned: jandem)

References

(Blocks 1 open bug, )

Details

Attachments

(3 files)

Attached file test.txt —

Go to https://opentype.js.org/
Copy-paste the attached sample text
Once the text is pasted, you can try to check/uncheck the options, or play with the sliders of the second demo.

firefox pasting: https://share.firefox.dev/4n5Qg4K (3s)
Firefox all operations: https://share.firefox.dev/43dc4UZ
Chrome: https://share.firefox.dev/43avYQu (1s to paste, all the operations)

Severity: -- → N/A
Priority: -- → P3

Interesting find. The code does action instanceof SubstitutionAction where action is a primitive. Our CacheIR implementation of instanceof requires the RHS (SubstitutionAction) to have a .prototype property, but because the LHS is a primitive, we never resolve this lazy property in the fallback code because the spec only does the lookup for LHS objects.

I checked some other benchmarks and apparently the new-ish prismjs test in JetStream 3 also hit this a number of times (for LHS string values).

Assignee: nobody → jdemooij
Status: NEW → ASSIGNED

Here's a micro-benchmark that improves from 6863 ms to 284 ms (--spectre-mitigations=off) with a fix for this.

function Foo() {}
function f() {
  var res = 0;
  var t = Date.now();
  for (var i = 0; i < 100_000_000; i++) {
    res += (i instanceof Foo);
  }
  print(Date.now() - t);
  return res;
}
f();

This fixes a performance cliff when the LHS is a primitive. In that case
the fallback code will not resolve the lazy RHS.prototype property but our
CacheIR code currently requires a prototype object for LoadInstanceOfObjectResult.

We could emit different CacheIR ops for this case involving a primitive LHS with a
not-yet-resolved RHS.prototype, but that seemed more complicated.

Status: ASSIGNED → RESOLVED
Closed: 11 months ago
Resolution: --- → FIXED
Target Milestone: --- → 146 Branch

Latest Nightly: https://share.firefox.dev/4qkUDf1 (850ms)
So we are 3.5x faster than before and 15% faster than Chrome now.

Status: RESOLVED → VERIFIED
QA Whiteboard: [qa-triage-done-c147/b146]
Regressions: 2012663
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: