Use pinReg/unpinReg more in write barriers

RESOLVED FIXED in mozilla12

Status

()

Core
JavaScript Engine
RESOLVED FIXED
6 years ago
6 years ago

People

(Reporter: billm, Assigned: billm)

Tracking

unspecified
mozilla12
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

Attachments

(1 attachment, 2 obsolete attachments)

(Assignee)

Description

6 years ago
Created attachment 579736 [details] [diff] [review]
patch

Now that pinReg works with syncFancy, we can use it throughout the write barrier code.

This patch fixes one case that was previously broken, and it removes some unnecessary save/restore code in another place.

I'm a little worried about pinning two registers at once.
Attachment #579736 - Flags: review?(dmandelin)
Comment on attachment 579736 [details] [diff] [review]
patch

Review of attachment 579736 [details] [diff] [review]:
-----------------------------------------------------------------

I think pinning 2 is OK. The pin code is simple enough and shouldn't have any problems. I rechecked the reg allocator in ImmutableSync, and if all else fails, it can pick a last resort register, which just has to be in the standard set and not pinned.
Attachment #579736 - Flags: review?(dmandelin) → review+
(Assignee)

Updated

6 years ago
Assignee: general → wmccloskey
(Assignee)

Comment 2

6 years ago
https://hg.mozilla.org/integration/mozilla-inbound/rev/1deb23332fb5
Target Milestone: --- → mozilla11
(Assignee)

Comment 3

6 years ago
Backed out. This fails with --jitflags=amdn.

https://hg.mozilla.org/integration/mozilla-inbound/rev/3fb1a1208df6
Target Milestone: mozilla11 → ---
(Assignee)

Comment 4

6 years ago
Created attachment 584848 [details] [diff] [review]
patch v2

The original patch was wrong because it was calling pinReg on registers that were not owned by the FrameState. This happened in two places:
1. In jsop_setelem_dense, where pinReg was called on a register that is sometimes obtained from tempRegForData (this one is safe) and sometimes from allocReg (no safe)
2. In jsop_setprop, where pinReg was called on a register obtained by allocReg

For the first problem, since we already save the register in question in VMFrame::scratch, I just restored the saved value when pinReg can't be used. pinReg is still used when the register comes from tempRegForData.

In the second problem, the register was already being allocated from SavedRegs. So I changed syncFancy so that it shouldn't clobber registers from SavedRegs. This further limits the set of registers available to syncFancy, but I suspect this should still be safe.
Attachment #579736 - Attachment is obsolete: true
Attachment #584848 - Flags: review?(dmandelin)
Attachment #584848 - Flags: review?(dmandelin) → review+
(Assignee)

Comment 5

6 years ago
https://hg.mozilla.org/integration/mozilla-inbound/rev/60eb0da71cdb
Target Milestone: --- → mozilla12
https://hg.mozilla.org/mozilla-central/rev/60eb0da71cdb
Status: NEW → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → FIXED
I backed this patch out as a suspected cause of a major new crash on mobile:
https://hg.mozilla.org/mozilla-central/rev/79e5d0b77d10

See bug 718765
Status: RESOLVED → REOPENED
Resolution: FIXED → ---

Updated

6 years ago
Depends on: 718765
(Assignee)

Comment 8

6 years ago
Created attachment 591661 [details] [diff] [review]
patch v3

Marty ran into this problem in bug 718852, which is probably the same thing as was happening with the Spiegel site: ARM only has three temp registers, and we had them all pinned. So there was nothing left for syncFancy to use.

This patch is more conservative. There was only one place where I wanted syncFancy to avoid using a SavedReg. So instead I changed that place to reload the register after the sync. It's a little hackier, but at this point I think that's what's called for.
Attachment #584848 - Attachment is obsolete: true
Attachment #591661 - Flags: review?(dmandelin)
Attachment #591661 - Flags: review?(dmandelin) → review+
(Assignee)

Comment 9

6 years ago
https://hg.mozilla.org/integration/mozilla-inbound/rev/9b81bf7d458c
https://hg.mozilla.org/mozilla-central/rev/9b81bf7d458c
Status: REOPENED → RESOLVED
Last Resolved: 6 years ago6 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.