Inline.cpp 245 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152515351545155515651575158515951605161516251635164516551665167516851695170517151725173517451755176517751785179518051815182518351845185518651875188518951905191519251935194519551965197519851995200520152025203520452055206520752085209521052115212521352145215521652175218521952205221522252235224522552265227522852295230523152325233523452355236523752385239524052415242
  1. //-------------------------------------------------------------------------------------------------------
  2. // Copyright (C) Microsoft. All rights reserved.
  3. // Licensed under the MIT license. See LICENSE.txt file in the project root for full license information.
  4. //-------------------------------------------------------------------------------------------------------
  5. #include "BackEnd.h"
  6. void
  7. Inline::Optimize()
  8. {
  9. this->Optimize(this->topFunc);
  10. }
  11. void
  12. Inline::Optimize(Func *func, __in_ecount_opt(callerArgOutCount) IR::Instr *callerArgOuts[], Js::ArgSlot callerArgOutCount, uint recursiveInlineDepth)
  13. {
  14. if (!func->DoInline() || !topFunc->DoInline() || func->GetJnFunction()->GetIsAsmjsMode()) // disable inlining for asm
  15. {
  16. return;
  17. }
  18. bool doFixedMethods = !PHASE_OFF(Js::FixedMethodsPhase, func->GetJnFunction());
  19. const auto inlinerData = func->m_workItem->RecyclableData()->JitTimeData();
  20. bool doInline = (inlinerData->InlineeCount() > 0 || inlinerData->IsLdFldInlineePresent());
  21. if (PHASE_OFF(Js::InlinePhase, this->topFunc) ||
  22. PHASE_OFF(Js::InlinePhase, func->GetJnFunction()) ||
  23. func->IsJitInDebugMode())
  24. {
  25. doInline = false;
  26. }
  27. func->actualCount = callerArgOutCount;
  28. // Keep the caller's "this" symbol (if any).
  29. StackSym *symThis = nullptr;
  30. lastStatementBoundary = nullptr;
  31. IR::LabelInstr* loopTop = nullptr;
  32. int32 backEdgeCount = 0;
  33. // Profile data already filter call site outside of loops if the function has loops, so we don't need to detect that here.
  34. FOREACH_INSTR_EDITING(instr, instrNext, func->m_headInstr)
  35. {
  36. bool isInlined = false;
  37. bool isPolymorphic = false;
  38. bool isBuiltIn = false;
  39. bool isCtor = false;
  40. if (doInline)
  41. {
  42. switch (instr->m_opcode)
  43. {
  44. case Js::OpCode::StatementBoundary:
  45. lastStatementBoundary = instr->AsPragmaInstr();
  46. break;
  47. case Js::OpCode::Label:
  48. {
  49. if (!loopTop && instr->AsLabelInstr()->m_isLoopTop)
  50. {
  51. // We only need to know if we are inside loop or not, it doesn't matter how many nested levels we are in.
  52. // This is the cheap way of doing so.
  53. loopTop = instr->AsLabelInstr();
  54. AnalysisAssert(loopTop);
  55. this->isInLoop++;
  56. backEdgeCount = loopTop->labelRefs.Count();
  57. }
  58. }
  59. break;
  60. case Js::OpCode::StFld:
  61. case Js::OpCode::LdFld:
  62. {
  63. // Try inlining of getter setter
  64. if (!inlinerData->IsLdFldInlineePresent())
  65. {
  66. break;
  67. }
  68. if (!instr->IsProfiledInstr())
  69. {
  70. break;
  71. }
  72. if (!(instr->AsProfiledInstr()->u.FldInfo().flags & Js::FldInfoFlags::FldInfo_FromAccessor))
  73. {
  74. break;
  75. }
  76. bool getter = instr->m_opcode == Js::OpCode::LdFld;
  77. IR::Opnd *opnd = getter ? instr->GetSrc1() : instr->GetDst();
  78. if (!(opnd && opnd->IsSymOpnd()))
  79. {
  80. break;
  81. }
  82. IR::SymOpnd* symOpnd = opnd->AsSymOpnd();
  83. if (!symOpnd->m_sym->IsPropertySym())
  84. {
  85. break;
  86. }
  87. Assert(symOpnd->AsSymOpnd()->IsPropertySymOpnd());
  88. const auto inlineCacheIndex = symOpnd->AsPropertySymOpnd()->m_inlineCacheIndex;
  89. const auto inlineeData = inlinerData->GetLdFldInlinee(inlineCacheIndex);
  90. if (!inlineeData)
  91. {
  92. break;
  93. }
  94. Js::FunctionInfo* functionInfo = inlineeData->GetFunctionInfo();
  95. if (!functionInfo->GetFunctionBody())
  96. {
  97. #ifdef ENABLE_DOM_FAST_PATH
  98. Assert(functionInfo->GetLocalFunctionId() == Js::JavascriptBuiltInFunction::DOMFastPathGetter ||
  99. functionInfo->GetLocalFunctionId() == Js::JavascriptBuiltInFunction::DOMFastPathSetter);
  100. if (PHASE_OFF1(Js::InlineHostCandidatePhase))
  101. {
  102. break;
  103. }
  104. this->InlineDOMGetterSetterFunction(instr, inlineeData, inlinerData);
  105. #endif
  106. break;
  107. }
  108. bool isInlinePhaseOff = PHASE_OFF(Js::InlineCandidatePhase, functionInfo->GetFunctionBody()) ||
  109. PHASE_OFF(Js::InlineAccessorsPhase, functionInfo->GetFunctionBody()) ||
  110. (getter && PHASE_OFF(Js::InlineGettersPhase, functionInfo->GetFunctionBody())) ||
  111. (!getter && PHASE_OFF(Js::InlineSettersPhase, functionInfo->GetFunctionBody()));
  112. if (isInlinePhaseOff)
  113. {
  114. break;
  115. }
  116. this->InlineGetterSetterFunction(instr, inlineeData, symThis, inlineCacheIndex, getter /*isGetter*/, recursiveInlineDepth);
  117. break;
  118. }
  119. case Js::OpCode::NewScObjArray:
  120. // We know we're not going to inline these. Just break out and try to do a fixed function check.
  121. isCtor = true;
  122. isBuiltIn = true;
  123. break;
  124. case Js::OpCode::NewScObject:
  125. isCtor = true;
  126. if (PHASE_OFF(Js::InlineConstructorsPhase, this->topFunc))
  127. {
  128. break;
  129. }
  130. // fall-through
  131. case Js::OpCode::CallI:
  132. {
  133. IR::PropertySymOpnd* methodValueOpnd = GetMethodLdOpndForCallInstr(instr);
  134. if (this->inlineesProcessed == inlinerData->InlineeCount())
  135. {
  136. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  137. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  138. break;
  139. }
  140. if(!instr->IsProfiledInstr())
  141. {
  142. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  143. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  144. break;
  145. }
  146. const auto profileId = static_cast<Js::ProfileId>(instr->AsProfiledInstr()->u.profileId);
  147. if(profileId >= func->GetJnFunction()->GetProfiledCallSiteCount())
  148. {
  149. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  150. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  151. break;
  152. }
  153. const auto inlineeData = inlinerData->GetInlinee(profileId);
  154. if(!inlineeData)
  155. {
  156. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  157. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  158. break;
  159. }
  160. if(inlinerData->IsPolymorphicCallSite(profileId))
  161. {
  162. isPolymorphic = true;
  163. if (isCtor ||
  164. (PHASE_OFF(Js::PolymorphicInlinePhase, this->topFunc) || PHASE_OFF(Js::PolymorphicInlinePhase, func->GetJnFunction())) ||
  165. (this->IsInliningOutSideLoops() && !PHASE_FORCE(Js::InlinePhase, this->topFunc) && !PHASE_FORCE(Js::InlinePhase, func->GetJnFunction())))
  166. {
  167. #if defined(DBG_DUMP) || defined(ENABLE_DEBUG_CONFIG_OPTIONS)
  168. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  169. #endif
  170. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic): Skip Inline: Inlining polymorphic call site outside loop\tIsConstructorCall: %s \tisTopFunc: %s\tCaller: %s (%s)\n",
  171. (isCtor? L"true": L"false"), (this->topFunc != func? L"true":L"false"),
  172. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  173. // TODO: Constructor polymorphic inlining
  174. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  175. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  176. break;
  177. }
  178. if (!PHASE_OFF(Js::FixedMethodsPhase, this->topFunc) && !PHASE_OFF(Js::PolymorphicInlineFixedMethodsPhase, this->topFunc))
  179. {
  180. instrNext = InlinePolymorphicFunctionUsingFixedMethods(instr, inlinerData, symThis, profileId, methodValueOpnd, &isInlined, recursiveInlineDepth);
  181. }
  182. else
  183. {
  184. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  185. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  186. instrNext = InlinePolymorphicFunction(instr, inlinerData, symThis, profileId, &isInlined, recursiveInlineDepth);
  187. }
  188. }
  189. else
  190. {
  191. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  192. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  193. Js::FunctionInfo* functionInfo = inlineeData->GetFunctionInfo();
  194. Js::OpCode builtInInlineCandidateOpCode;
  195. ValueType builtInReturnType;
  196. // If the inlinee info is the array constructor, just change the opcode to NewScObjArray
  197. // so that we will inline the array allocation in lower
  198. if (isCtor && functionInfo == &Js::JavascriptArray::EntryInfo::NewInstance)
  199. {
  200. isBuiltIn = true;
  201. instr->m_opcode = Js::OpCode::NewScObjArray;
  202. instr->AsProfiledInstr()->u.profileId = Js::Constants::NoProfileId;
  203. break;
  204. }
  205. isBuiltIn = InliningDecider::GetBuiltInInfo(functionInfo, &builtInInlineCandidateOpCode, &builtInReturnType, func->GetScriptContext());
  206. if(!builtInReturnType.IsUninitialized() && instr->GetDst())
  207. {
  208. Assert(!functionInfo->HasBody());
  209. AssertMsg(instr->m_opcode != Js::OpCode::NewScObjArray, "We should have broken out of the switch statement earlier on this opcode.");
  210. // Value types for the array built-in calls are pulled from the profile; don't change them here.
  211. if ((instr->m_opcode != Js::OpCode::NewScObjArray) ||
  212. !instr->GetDst()->GetValueType().IsLikelyNativeArray())
  213. {
  214. // Assume that this built-in function is not going to be inlined, so the return type cannot be definite
  215. instr->GetDst()->SetValueType(builtInReturnType.ToLikely());
  216. }
  217. }
  218. bool isInlinePhaseOff = functionInfo->HasBody() ?
  219. PHASE_OFF(Js::InlineCandidatePhase, functionInfo->GetFunctionBody()) :
  220. PHASE_OFF1(Js::InlineBuiltInPhase);
  221. if (isInlinePhaseOff)
  222. {
  223. break;
  224. }
  225. if(!functionInfo->HasBody() && builtInInlineCandidateOpCode == 0)
  226. {
  227. // This built-in function is not going to be inlined
  228. break;
  229. }
  230. if(!functionInfo->HasBody())
  231. {
  232. Assert(builtInInlineCandidateOpCode != 0);
  233. if(isCtor)
  234. {
  235. // Inlining a built-in function called as a constructor is currently not supported. Although InliningDecider
  236. // already checks for this, profile data matching with a function does not take into account the difference
  237. // between a constructor call and a regular function call, so need to check it again.
  238. break;
  239. }
  240. // This built-in function is going to be inlined, so reset the destination's value type
  241. if(!builtInReturnType.IsUninitialized())
  242. {
  243. if(instr->GetDst())
  244. {
  245. instr->GetDst()->SetValueType(builtInReturnType);
  246. if(builtInReturnType.IsDefinite())
  247. {
  248. instr->GetDst()->SetValueTypeFixed();
  249. }
  250. }
  251. }
  252. }
  253. else
  254. {
  255. if (!inlineeData->GetFunctionBody()->HasDynamicProfileInfo()) // Don't try to inline a function if it doesn't have profile data
  256. {
  257. break;
  258. }
  259. uint16 constantArguments = 0;
  260. if (!PHASE_OFF(Js::InlineRecursivePhase, func->GetJnFunction()))
  261. {
  262. instr->IterateArgInstrs([&](IR::Instr* argInstr) {
  263. IR::Opnd *src1 = argInstr->GetSrc1();
  264. if (!src1->IsRegOpnd())
  265. {
  266. return false;
  267. }
  268. StackSym *sym = src1->AsRegOpnd()->m_sym;
  269. if (sym->IsIntConst())
  270. {
  271. if (argInstr->GetSrc2() && argInstr->GetSrc2()->IsSymOpnd())
  272. {
  273. StackSym *dstSym = argInstr->GetDst()->AsSymOpnd()->m_sym->AsStackSym();
  274. Assert(dstSym->IsSingleDef());
  275. Assert(dstSym->IsArgSlotSym());
  276. Js::ArgSlot argCount = dstSym->GetArgSlotNum() - 1;
  277. if (argCount == Js::Constants::MaximumArgumentCountForConstantArgumentInlining)
  278. {
  279. return true;
  280. }
  281. constantArguments |= (1 << argCount);
  282. }
  283. }
  284. return false;
  285. });
  286. }
  287. if (!inliningHeuristics.BackendInlineIntoInliner(inlineeData->GetFunctionBody(),
  288. func->GetJnFunction(), this->topFunc, profileId, isCtor, true /*isFixedMethodCall*/,
  289. this->IsInliningOutSideLoops(), this->isInLoop != 0, recursiveInlineDepth, constantArguments))
  290. {
  291. break;
  292. }
  293. }
  294. instrNext = builtInInlineCandidateOpCode != 0 ?
  295. this->InlineBuiltInFunction(instr, functionInfo, builtInInlineCandidateOpCode, inlinerData, symThis, &isInlined, profileId, recursiveInlineDepth) :
  296. this->InlineScriptFunction(instr, inlineeData, symThis, profileId, &isInlined, recursiveInlineDepth);
  297. }
  298. if(++this->inlineesProcessed == inlinerData->InlineeCount())
  299. {
  300. // getterSetter inline caches are shared and we have no way of knowing how many more are present
  301. if (!inlinerData->IsLdFldInlineePresent() && !doFixedMethods)
  302. {
  303. return ;
  304. }
  305. }
  306. break;
  307. }
  308. case Js::OpCode::CallIExtended:
  309. {
  310. if (this->inlineesProcessed == inlinerData->InlineeCount())
  311. {
  312. break;
  313. }
  314. if (!instr->IsProfiledInstr())
  315. {
  316. break;
  317. }
  318. const auto profileId = static_cast<Js::ProfileId>(instr->AsProfiledInstr()->u.profileId);
  319. if (profileId >= func->GetJnFunction()->GetProfiledCallSiteCount())
  320. {
  321. break;
  322. }
  323. const auto inlineeData = inlinerData->GetInlinee(profileId);
  324. if (!inlineeData)
  325. {
  326. break;
  327. }
  328. if (Lowerer::IsSpreadCall(instr))
  329. {
  330. InlineSpread(instr);
  331. }
  332. break;
  333. }
  334. case Js::OpCode::ArgOut_A:
  335. InlConstFoldArg(instr, callerArgOuts, callerArgOutCount);
  336. break;
  337. case Js::OpCode::LdThis:
  338. Assert(instr->GetDst() && instr->GetDst()->IsRegOpnd());
  339. Assert(symThis == nullptr);
  340. symThis = instr->GetDst()->AsRegOpnd()->m_sym;
  341. break;
  342. case Js::OpCode::CheckThis:
  343. // Is this possible? Can we be walking an inlinee here? Doesn't hurt to support this case...
  344. Assert(instr->GetSrc1() && instr->GetSrc1()->IsRegOpnd());
  345. Assert(symThis == nullptr);
  346. symThis = instr->GetSrc1()->AsRegOpnd()->m_sym;
  347. break;
  348. default:
  349. {
  350. if (loopTop && instr->IsBranchInstr())
  351. {
  352. // Look for the back edge to loopTop.
  353. IR::BranchInstr *branch = instr->AsBranchInstr();
  354. IR::LabelInstr *labelDestination = branch->GetTarget();
  355. if (labelDestination == loopTop) // We found the back edge
  356. {
  357. backEdgeCount--;
  358. if (backEdgeCount == 0) // We have seen all the back edges, hence we are outside loop now.
  359. {
  360. Assert(this->isInLoop > 0);
  361. --this->isInLoop;
  362. loopTop = nullptr;
  363. }
  364. }
  365. }
  366. }
  367. }
  368. }
  369. // If we chose not to inline, let's try to optimize this call if it uses a fixed method
  370. if (!isInlined)
  371. {
  372. switch (instr->m_opcode)
  373. {
  374. case Js::OpCode::NewScObject:
  375. case Js::OpCode::NewScObjArray:
  376. isCtor = true;
  377. // intentionally fall through.
  378. case Js::OpCode::CallI:
  379. {
  380. IR::PropertySymOpnd* methodValueOpnd = GetMethodLdOpndForCallInstr(instr);
  381. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  382. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  383. StackSym* originalCallTargetStackSym = instr->GetSrc1()->GetStackSym();
  384. bool safeThis = false;
  385. if (TryOptimizeCallInstrWithFixedMethod(instr, nullptr, isPolymorphic /*isPolymorphic*/, isBuiltIn /*isBuiltIn*/, isCtor /*isCtor*/, false /*isInlined*/, safeThis /*unused here*/))
  386. {
  387. Assert(originalCallTargetStackSym != nullptr);
  388. // Insert a ByteCodeUsesInstr to make sure the methodValueDstOpnd's constant value is captured by any
  389. // bailout that occurs between CheckFixedMethodField and CallI.
  390. IR::ByteCodeUsesInstr * useCallTargetInstr = IR::ByteCodeUsesInstr::New(instr, originalCallTargetStackSym->m_id);
  391. instr->InsertBefore(useCallTargetInstr);
  392. // Split NewScObject into NewScObjectNoCtor and CallI, but don't touch NewScObjectArray.
  393. if (instr->m_opcode == Js::OpCode::NewScObject && !PHASE_OFF(Js::SplitNewScObjectPhase, this->topFunc))
  394. {
  395. SplitConstructorCall(instr, false, true);
  396. }
  397. }
  398. else if (instr->m_opcode == Js::OpCode::NewScObjArray)
  399. {
  400. if (instr->GetDst() && instr->GetDst()->GetValueType().IsLikelyNativeArray())
  401. {
  402. // We expect to create a native array here, so we'll insert a check against the
  403. // expected call target, which requires a bailout.
  404. instr = instr->ConvertToBailOutInstr(instr, IR::BailOutOnNotNativeArray);
  405. }
  406. }
  407. }
  408. break;
  409. }
  410. }
  411. } NEXT_INSTR_EDITING;
  412. INLINE_FLUSH();
  413. }
  414. uint Inline::FillInlineesDataArray(
  415. const Js::FunctionCodeGenJitTimeData* inlineeJitTimeData,
  416. const Js::FunctionCodeGenRuntimeData* inlineeRuntimeData,
  417. _Out_writes_to_(inlineesDataArrayLength, (return >= inlineesDataArrayLength ? inlineesDataArrayLength : return)) InlineeData *inlineesDataArray,
  418. uint inlineesDataArrayLength
  419. )
  420. {
  421. uint inlineeCount = 0;
  422. while(inlineeJitTimeData)
  423. {
  424. if (inlineeCount >= inlineesDataArrayLength)
  425. {
  426. // Count the actual number of inlinees for logging.
  427. while (inlineeJitTimeData)
  428. {
  429. inlineeCount++;
  430. inlineeJitTimeData = inlineeJitTimeData->GetNext();
  431. }
  432. return inlineeCount;
  433. }
  434. Js::FunctionBody *inlineeFunctionBody = inlineeJitTimeData->GetFunctionBody();
  435. if (!PHASE_OFF(Js::PolymorphicInlinePhase, inlineeFunctionBody))
  436. {
  437. const Js::FunctionCodeGenJitTimeData* rightInlineeJitTimeData = inlineeJitTimeData->GetJitTimeDataFromFunctionInfo(inlineeFunctionBody);
  438. const Js::FunctionCodeGenRuntimeData* rightInlineeRuntimeData = inlineeRuntimeData->GetRuntimeDataFromFunctionInfo(inlineeFunctionBody);
  439. if (rightInlineeJitTimeData)
  440. {
  441. inlineesDataArray[inlineeCount].inlineeJitTimeData = rightInlineeJitTimeData;
  442. inlineesDataArray[inlineeCount].inlineeRuntimeData = rightInlineeRuntimeData;
  443. inlineesDataArray[inlineeCount].functionBody = inlineeFunctionBody;
  444. Assert(rightInlineeJitTimeData->GetFunctionBody() == inlineeFunctionBody);
  445. #ifdef DBG
  446. for (uint k = 0; k < inlineeCount; k++)
  447. {
  448. if (inlineesDataArray[k].functionBody == inlineeFunctionBody)
  449. {
  450. AssertMsg(false, "We should never see duplicate function body here");
  451. }
  452. }
  453. #endif
  454. inlineeCount++;
  455. }
  456. else
  457. {
  458. #if defined(DBG_DUMP) || defined(ENABLE_DEBUG_CONFIG_OPTIONS)
  459. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  460. #endif
  461. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic): Missing jit time data skipped inlinee\tInlinee: %s (%s)\n",
  462. inlineeFunctionBody->GetDisplayName(), inlineeFunctionBody->GetDebugNumberSet(debugStringBuffer));
  463. }
  464. }
  465. inlineeJitTimeData = inlineeJitTimeData->GetNext();
  466. }
  467. return inlineeCount;
  468. }
  469. void Inline::FillInlineesDataArrayUsingFixedMethods(
  470. const Js::FunctionCodeGenJitTimeData* inlineeJitTimeData,
  471. const Js::FunctionCodeGenRuntimeData* inlineeRuntimeData,
  472. __inout_ecount(inlineesDataArrayLength) InlineeData *inlineesDataArray,
  473. uint inlineesDataArrayLength,
  474. __inout_ecount(cachedFixedInlineeCount) Js::FixedFieldInfo* fixedFieldInfoArray,
  475. uint16 cachedFixedInlineeCount
  476. )
  477. {
  478. AnalysisAssert(cachedFixedInlineeCount <= inlineesDataArrayLength);
  479. Js::FunctionBody* inlineeFuncBody = nullptr;
  480. while (inlineeJitTimeData)
  481. {
  482. inlineeFuncBody = inlineeJitTimeData->GetFunctionBody();
  483. if (!PHASE_OFF(Js::PolymorphicInlinePhase, inlineeFuncBody) && !PHASE_OFF(Js::PolymorphicInlineFixedMethodsPhase, inlineeFuncBody))
  484. {
  485. const Js::FunctionCodeGenJitTimeData* jitTimeData = inlineeJitTimeData->GetJitTimeDataFromFunctionInfo(inlineeFuncBody);
  486. if (jitTimeData)
  487. {
  488. for (uint16 i = 0; i < cachedFixedInlineeCount; i++)
  489. {
  490. if (inlineeFuncBody == ((Js::JavascriptFunction*)(fixedFieldInfoArray[i].fieldValue))->GetFunctionBody())
  491. {
  492. inlineesDataArray[i].inlineeJitTimeData = inlineeJitTimeData->GetJitTimeDataFromFunctionInfo(inlineeFuncBody);
  493. inlineesDataArray[i].inlineeRuntimeData = inlineeRuntimeData->GetRuntimeDataFromFunctionInfo(inlineeFuncBody);
  494. inlineesDataArray[i].functionBody = inlineeFuncBody;
  495. break;
  496. }
  497. }
  498. }
  499. else
  500. {
  501. #if defined(DBG_DUMP) || defined(ENABLE_DEBUG_CONFIG_OPTIONS)
  502. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  503. #endif
  504. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic): Missing jit time data skipped inlinee\tInlinee: %s (%s)\n",
  505. inlineeFuncBody->GetDisplayName(), inlineeFuncBody->GetDebugNumberSet(debugStringBuffer));
  506. }
  507. }
  508. inlineeJitTimeData = inlineeJitTimeData->GetNext();
  509. }
  510. }
  511. IR::Instr *
  512. Inline::InlinePolymorphicFunctionUsingFixedMethods(IR::Instr *callInstr, const Js::FunctionCodeGenJitTimeData* inlinerData, const StackSym *symCallerThis, const Js::ProfileId profileId, IR::PropertySymOpnd* methodValueOpnd, bool* pIsInlined, uint recursiveInlineDepth)
  513. {
  514. IR::Instr* instrNext = callInstr->m_next;
  515. *pIsInlined = false;
  516. const Js::FunctionCodeGenJitTimeData* inlineeJitTimeData = inlinerData->GetInlinee(profileId);
  517. AnalysisAssert(inlineeJitTimeData);
  518. #if defined(DBG_DUMP) || defined(ENABLE_DEBUG_CONFIG_OPTIONS)
  519. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  520. wchar_t debugStringBuffer2[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  521. #endif
  522. // Abort conditions:
  523. if(!inlineeJitTimeData->GetNext())
  524. {
  525. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic): Skip Inline: Missing JitTime data \tInlinee: %s (%s):\tCaller: %s (%s)\n",
  526. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  527. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  528. // There are no multiple codegen jit-time data allocated for this call site, not sure how is this possible, abort
  529. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  530. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  531. return instrNext;
  532. }
  533. // arguments exceed MaxInlineeArgoutCount
  534. if (callInstr->GetSrc2() &&
  535. callInstr->GetSrc2()->IsSymOpnd() &&
  536. callInstr->GetSrc2()->AsSymOpnd()->m_sym->AsStackSym()->GetArgSlotNum() > Js::InlineeCallInfo::MaxInlineeArgoutCount)
  537. {
  538. // This is a hard limit as we only use 4 bits to encode the actual count in the InlineeCallInfo. Although
  539. // InliningDecider already checks for this, the check is against profile data that may not be accurate since profile
  540. // data matching does not take into account some types of changes to source code. Need to check this again with current
  541. // information.
  542. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic): Skip Inline: ArgSlot > MaxInlineeArgoutCount\tInlinee: %s (%s)\tArgSlotNum: %d\tMaxInlineeArgoutCount: %d\tCaller: %s (%s)\n",
  543. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer) , callInstr->GetSrc2()->AsSymOpnd()->m_sym->AsStackSym()->GetArgSlotNum(),
  544. Js::InlineeCallInfo::MaxInlineeArgoutCount, inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  545. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  546. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  547. return instrNext;
  548. }
  549. uint inlineeCount = 0;
  550. const Js::FunctionCodeGenJitTimeData* tmpInlineeJitTimeData = inlineeJitTimeData;
  551. while(tmpInlineeJitTimeData)
  552. {
  553. inlineeCount++;
  554. tmpInlineeJitTimeData = tmpInlineeJitTimeData->GetNext();
  555. }
  556. // Inlinee count too small (<2) or too large (>4)
  557. if (inlineeCount < 2 || inlineeCount > Js::DynamicProfileInfo::maxPolymorphicInliningSize)
  558. {
  559. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic): Skip Inline: Inlinee count either too small or too large: InlineeCount %d (Max: %d)\tInlinee: %s (%s):\tCaller: %s (%s)\n",
  560. inlineeCount, Js::DynamicProfileInfo::maxPolymorphicInliningSize,
  561. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  562. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  563. TryResetObjTypeSpecFldInfoOn(methodValueOpnd);
  564. TryDisableRuntimePolymorphicCacheOn(methodValueOpnd);
  565. return instrNext;
  566. }
  567. *pIsInlined = true;
  568. IR::Instr* tmpInstr = callInstr->m_prev;
  569. while (tmpInstr->m_opcode != Js::OpCode::StartCall)
  570. {
  571. if ((tmpInstr->m_opcode != Js::OpCode::ArgOut_A) && (tmpInstr->m_opcode != Js::OpCode::Ld_A))
  572. {
  573. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Skip Inline: ArgOuts may have side effects Inlinee: %s (%s):\tCaller: %s (%s)\n",
  574. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  575. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  576. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  577. }
  578. tmpInstr = tmpInstr->m_prev;
  579. }
  580. StackSym* methodValueSym = callInstr->GetSrc1()->AsRegOpnd()->m_sym->AsStackSym();
  581. if (!methodValueSym->IsSingleDef())
  582. {
  583. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  584. }
  585. IR::Instr* ldMethodFldInstr = methodValueSym->GetInstrDef();
  586. if (!(ldMethodFldInstr->GetSrc1()->IsSymOpnd() && ldMethodFldInstr->GetSrc1()->AsSymOpnd()->IsPropertySymOpnd()))
  587. {
  588. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Skip Inline: Did not find property sym operand for the method load Inlinee: %s (%s):\tCaller: %s (%s)\n",
  589. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  590. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  591. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  592. }
  593. IR::PropertySymOpnd* methodPropertyOpnd = ldMethodFldInstr->GetSrc1()->AsPropertySymOpnd();
  594. if (!methodPropertyOpnd->HasObjTypeSpecFldInfo())
  595. {
  596. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Skip Inline: no ObjTypeSpecFldInfo to get Fixed Methods from Inlinee: %s (%s):\tCaller: %s (%s)\n",
  597. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  598. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  599. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  600. }
  601. if (!methodPropertyOpnd->HasFixedValue())
  602. {
  603. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Skip Inline: ObjTypeSpecFldInfo doesn't have Fixed Methods for one or some of the inlinees Inlinee: %s (%s):\tCaller: %s (%s)\n",
  604. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  605. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  606. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  607. }
  608. uint16 cachedFixedInlineeCount = methodPropertyOpnd->GetFixedFieldCount();
  609. if (cachedFixedInlineeCount < 2)
  610. {
  611. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Skip Inline: fixed function count too less %d (Max: %d)\tInlinee: %s (%s):\tCaller: %s (%s)\n",
  612. cachedFixedInlineeCount, Js::DynamicProfileInfo::maxPolymorphicInliningSize,
  613. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  614. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  615. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  616. }
  617. Js::FixedFieldInfo* fixedFunctionInfoArray = methodPropertyOpnd->GetFixedFieldInfoArray();
  618. // It might so be the case that two objects of different types call the same function (body), for e.g., if they share the prototype on which the function is defined.
  619. uint uniqueFixedFunctionCount = HandleDifferentTypesSameFunction(fixedFunctionInfoArray, cachedFixedInlineeCount);
  620. if (uniqueFixedFunctionCount != inlineeCount)
  621. {
  622. // inlineeCount obtained from the inlineeJitTimeData is more accurate than cached number of fixed methods for inlinees.
  623. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Skip Inline: cached fixed function count (%d) doesn't match inlinee count (%d); (Max: %d)\tInlinee: %s (%s):\tCaller: %s (%s)\n",
  624. uniqueFixedFunctionCount, inlineeCount, Js::DynamicProfileInfo::maxPolymorphicInliningSize,
  625. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  626. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  627. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  628. }
  629. Assert(cachedFixedInlineeCount <= Js::DynamicProfileInfo::maxPolymorphicInliningSize);
  630. InlineeData inlineesDataArray[Js::DynamicProfileInfo::maxPolymorphicInliningSize] = {};
  631. const Js::FunctionCodeGenRuntimeData* inlineeRuntimeData = callInstr->m_func->m_runtimeData ?
  632. callInstr->m_func->m_runtimeData->GetInlinee(profileId) :
  633. this->topFunc->GetJnFunction()->GetInlineeCodeGenRuntimeData(profileId);
  634. FillInlineesDataArrayUsingFixedMethods(inlineeJitTimeData, inlineeRuntimeData, inlineesDataArray, Js::DynamicProfileInfo::maxPolymorphicInliningSize, fixedFunctionInfoArray, cachedFixedInlineeCount);
  635. for (uint i = 0; i < cachedFixedInlineeCount; i++)
  636. {
  637. if(!inlineesDataArray[i].functionBody)
  638. {
  639. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Skip Inline: One of the inlinees doesn't have the corresponding object/prototype's type cached\tCaller: %s (%s)\n",
  640. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  641. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  642. }
  643. #if DBG
  644. if(inlineesDataArray[i].functionBody && inlineesDataArray[i].functionBody != methodPropertyOpnd->GetFieldValueAsFixedFunction(i)->GetFunctionBody())
  645. {
  646. AssertMsg(false, "inlineesDataArray and fixedfunctionInfoArray should be aligned with each other at this point");
  647. }
  648. #endif
  649. while (fixedFunctionInfoArray[i].nextHasSameFixedField)
  650. {
  651. i++;
  652. }
  653. }
  654. bool safeThis = true; // Eliminate CheckThis for inlining.
  655. for (uint i = 0; i < cachedFixedInlineeCount; i++)
  656. {
  657. if (!methodPropertyOpnd->GetFieldValue(i))
  658. {
  659. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Skip Inline: no fixed method for one of the inlinees; Inlinee: %s (%s):\tCaller: %s (%s)\n",
  660. inlineesDataArray[i].functionBody->GetDisplayName(), inlineesDataArray[i].functionBody->GetDebugNumberSet(debugStringBuffer),
  661. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  662. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  663. }
  664. if (i == 0)
  665. {
  666. // Do all the general, non-function-object-specific checks just once.
  667. if (!TryOptimizeCallInstrWithFixedMethod(callInstr, (Js::FunctionInfo*)(inlineesDataArray[i].functionBody), true, false, false, true /*isInlined*/, safeThis, true /*dontOptimizeJustCheck*/, i))
  668. {
  669. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Skip Inline: can't optimize using Fixed Methods %d (Max: %d)\tInlinee: %s (%s):\tCaller: %s (%s)\n",
  670. inlineeCount, Js::DynamicProfileInfo::maxPolymorphicInliningSize,
  671. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  672. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  673. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  674. }
  675. }
  676. else
  677. {
  678. if (methodPropertyOpnd->GetFieldValueAsFixedFunction(i) &&
  679. methodPropertyOpnd->GetFieldValueAsFixedFunction(i)->GetFunctionInfo() != (Js::FunctionInfo*)(inlineesDataArray[i].functionBody))
  680. {
  681. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Skip Inline: can't optimize using Fixed Methods %d (Max: %d)\tInlinee: %s (%s):\tCaller: %s (%s)\n",
  682. inlineeCount, Js::DynamicProfileInfo::maxPolymorphicInliningSize,
  683. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  684. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  685. return InlinePolymorphicFunction(callInstr, inlinerData, symCallerThis, profileId, pIsInlined, recursiveInlineDepth, true);
  686. }
  687. }
  688. Js::TypeId typeId = methodPropertyOpnd->GetTypeId(i);
  689. if(!(typeId > Js::TypeIds_LastJavascriptPrimitiveType && typeId <= Js::TypeIds_LastTrueJavascriptObjectType))
  690. {
  691. // Don't eliminate CheckThis if it cannot be done for any one of the inlinees
  692. safeThis = false;
  693. }
  694. while (fixedFunctionInfoArray[i].nextHasSameFixedField)
  695. {
  696. i++;
  697. }
  698. }
  699. Assert(methodPropertyOpnd->IsPoly());
  700. // emit property guard check for the method load, and load type
  701. IR::RegOpnd *typeOpnd = IR::RegOpnd::New(TyVar, callInstr->m_func);
  702. IR::Instr* propertyGuardCheckInstr = IR::Instr::New(Js::OpCode::CheckPropertyGuardAndLoadType, typeOpnd, ldMethodFldInstr->GetSrc1(), callInstr->m_func);
  703. ldMethodFldInstr->InsertBefore(propertyGuardCheckInstr);
  704. propertyGuardCheckInstr->SetByteCodeOffset(ldMethodFldInstr);
  705. propertyGuardCheckInstr = propertyGuardCheckInstr->ConvertToBailOutInstr(ldMethodFldInstr, IR::BailOutFailedFixedFieldCheck);
  706. POLYMORPHIC_INLINE_TESTTRACE(L"------------------------------------------------\n");
  707. for (uint i = 0; i < cachedFixedInlineeCount; i++)
  708. {
  709. Js::FunctionBody *inlineeFunctionBody = inlineesDataArray[i].functionBody;
  710. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic; Using Fixed Methods): Start inlining: \tInlinee: %s (%s):\tCaller: %s (%s)\n",
  711. inlineeFunctionBody->GetDisplayName(), inlineeFunctionBody->GetDebugNumberSet(debugStringBuffer),
  712. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  713. while (fixedFunctionInfoArray[i].nextHasSameFixedField)
  714. {
  715. i++;
  716. }
  717. }
  718. POLYMORPHIC_INLINE_TESTTRACE(L"------------------------------------------------\n");
  719. IR::RegOpnd * returnValueOpnd;
  720. if (callInstr->GetDst())
  721. {
  722. returnValueOpnd = callInstr->UnlinkDst()->AsRegOpnd();
  723. }
  724. else
  725. {
  726. returnValueOpnd = nullptr;
  727. }
  728. callInstr->MoveArgs(/*generateByteCodeCapture*/ true);
  729. callInstr->m_opcode = Js::OpCode::CallIFixed;
  730. // iterate over inlineesDataArray to emit each inlinee
  731. IR::LabelInstr * doneLabel = IR::LabelInstr::New(Js::OpCode::Label, callInstr->m_func, false);
  732. IR::Instr* dispatchStartLabel = IR::LabelInstr::New(Js::OpCode::Label, callInstr->m_func, false);
  733. callInstr->InsertBefore(dispatchStartLabel);
  734. for(uint i=0; i < cachedFixedInlineeCount; i++)
  735. {
  736. IR::LabelInstr* inlineeStartLabel = IR::LabelInstr::New(Js::OpCode::Label, callInstr->m_func);
  737. callInstr->InsertBefore(inlineeStartLabel);
  738. IR::AddrOpnd * constMethodValueOpnd = IR::AddrOpnd::New(methodPropertyOpnd->GetFieldValue(i), IR::AddrOpndKind::AddrOpndKindDynamicVar, callInstr->m_func);
  739. constMethodValueOpnd->m_isFunction = true;
  740. InsertOneInlinee(callInstr, returnValueOpnd, constMethodValueOpnd, inlineesDataArray[i], doneLabel, symCallerThis, safeThis, recursiveInlineDepth);
  741. while (fixedFunctionInfoArray[i].nextHasSameFixedField)
  742. {
  743. dispatchStartLabel->InsertBefore(IR::BranchInstr::New(Js::OpCode::BrAddr_A, inlineeStartLabel, typeOpnd, IR::AddrOpnd::New(methodPropertyOpnd->GetType(i),
  744. IR::AddrOpndKindDynamicType, dispatchStartLabel->m_func), dispatchStartLabel->m_func));
  745. this->topFunc->PinTypeRef(methodPropertyOpnd->GetType(i)); // Keep the types alive as the types may not be equivalent and, hence, won't be kept alive by EquivalentTypeCache
  746. i++;
  747. }
  748. dispatchStartLabel->InsertBefore(IR::BranchInstr::New(Js::OpCode::BrAddr_A, inlineeStartLabel,
  749. typeOpnd, IR::AddrOpnd::New(methodPropertyOpnd->GetType(i), IR::AddrOpndKindDynamicType, dispatchStartLabel->m_func), dispatchStartLabel->m_func));
  750. this->topFunc->PinTypeRef(methodPropertyOpnd->GetType(i)); // Keep the types alive as the types may not be equivalent and, hence, won't be kept alive by EquivalentTypeCache
  751. }
  752. ldMethodFldInstr->Unlink();
  753. ldMethodFldInstr->m_opcode = Js::OpCode::LdMethodFldPolyInlineMiss;
  754. Assert(cachedFixedInlineeCount > 0);
  755. CompletePolymorphicInlining(callInstr, returnValueOpnd, doneLabel, dispatchStartLabel, ldMethodFldInstr, IR::BailOutOnFailedPolymorphicInlineTypeCheck);
  756. this->topFunc->SetHasInlinee();
  757. InsertStatementBoundary(instrNext);
  758. return instrNext;
  759. }
  760. void Inline::CloneCallSequence(IR::Instr* callInstr, IR::Instr* clonedCallInstr)
  761. {
  762. IR::Instr* previousArg = nullptr;
  763. IR::Instr* previousClonedArg = clonedCallInstr;
  764. callInstr->IterateArgInstrs([&](IR::Instr* argInstr){
  765. IR::Instr* cloneArg = IR::Instr::New(argInstr->m_opcode,
  766. IR::SymOpnd::New(callInstr->m_func->m_symTable->GetArgSlotSym(argInstr->GetDst()->GetStackSym()->GetArgSlotNum()), 0, TyMachPtr, callInstr->m_func),
  767. argInstr->GetSrc1(), callInstr->m_func);
  768. cloneArg->SetByteCodeOffset(callInstr);
  769. cloneArg->GetDst()->GetStackSym()->m_isArgCaptured = true;
  770. previousClonedArg->SetSrc2(cloneArg->GetDst());
  771. previousClonedArg->InsertBefore(cloneArg);
  772. previousArg = argInstr;
  773. previousClonedArg = cloneArg;
  774. return false;
  775. });
  776. IR::Instr* startCall = previousArg->GetSrc2()->GetStackSym()->GetInstrDef();
  777. previousClonedArg->SetSrc2(startCall->GetDst());
  778. }
  779. IR::Instr *
  780. Inline::InlinePolymorphicFunction(IR::Instr *callInstr, const Js::FunctionCodeGenJitTimeData* inlinerData, const StackSym *symCallerThis, const Js::ProfileId profileId, bool* pIsInlined, uint recursiveInlineDepth, bool triedUsingFixedMethods)
  781. {
  782. IR::Instr* instrNext = callInstr->m_next;
  783. *pIsInlined = false;
  784. if (triedUsingFixedMethods)
  785. {
  786. if (callInstr->GetSrc1()->AsRegOpnd()->m_sym->AsStackSym()->IsSingleDef())
  787. {
  788. IR::Instr* ldMethodFldInstr = callInstr->GetSrc1()->AsRegOpnd()->m_sym->AsStackSym()->GetInstrDef();
  789. if (ldMethodFldInstr->GetSrc1()->IsSymOpnd() && ldMethodFldInstr->GetSrc1()->AsSymOpnd()->IsPropertySymOpnd())
  790. {
  791. TryResetObjTypeSpecFldInfoOn(ldMethodFldInstr->GetSrc1()->AsPropertySymOpnd());
  792. TryDisableRuntimePolymorphicCacheOn(ldMethodFldInstr->GetSrc1()->AsPropertySymOpnd());
  793. }
  794. }
  795. }
  796. const Js::FunctionCodeGenJitTimeData* inlineeJitTimeData = inlinerData->GetInlinee(profileId);
  797. #if defined(DBG_DUMP) || defined(ENABLE_DEBUG_CONFIG_OPTIONS)
  798. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  799. wchar_t debugStringBuffer2[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  800. #endif
  801. if (!triedUsingFixedMethods) // We would have done the following two checks when we tried to inline using fixed methods
  802. {
  803. if(!inlineeJitTimeData->GetNext())
  804. {
  805. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic): Skip Inline: Missing JitTime data \tInlinee: %s (%s):\tCaller: %s (%s)\n",
  806. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  807. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  808. //There are no multiple codegen jit-time data allocated for this call site, not sure how is this possible, abort
  809. return instrNext;
  810. }
  811. if (callInstr->GetSrc2() &&
  812. callInstr->GetSrc2()->IsSymOpnd() &&
  813. callInstr->GetSrc2()->AsSymOpnd()->m_sym->AsStackSym()->GetArgSlotNum() > Js::InlineeCallInfo::MaxInlineeArgoutCount)
  814. {
  815. // This is a hard limit as we only use 4 bits to encode the actual count in the InlineeCallInfo. Although
  816. // InliningDecider already checks for this, the check is against profile data that may not be accurate since profile
  817. // data matching does not take into account some types of changes to source code. Need to check this again with current
  818. // information.
  819. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic): Skip Inline: ArgSlot > MaxInlineeArgoutCount\tInlinee: %s (%s)\tArgSlotNum: %d\tMaxInlineeArgoutCount: %d\tCaller: %s (%s)\n",
  820. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer) , callInstr->GetSrc2()->AsSymOpnd()->m_sym->AsStackSym()->GetArgSlotNum(),
  821. Js::InlineeCallInfo::MaxInlineeArgoutCount, inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  822. return instrNext;
  823. }
  824. }
  825. InlineeData inlineesDataArray[Js::DynamicProfileInfo::maxPolymorphicInliningSize];
  826. const Js::FunctionCodeGenRuntimeData* inlineeRuntimeData = callInstr->m_func->m_runtimeData ?
  827. callInstr->m_func->m_runtimeData->GetInlinee(profileId) :
  828. this->topFunc->GetJnFunction()->GetInlineeCodeGenRuntimeData(profileId);
  829. uint inlineeCount = FillInlineesDataArray(inlineeJitTimeData, inlineeRuntimeData, inlineesDataArray, Js::DynamicProfileInfo::maxPolymorphicInliningSize);
  830. if (inlineeCount < 2 || inlineeCount > Js::DynamicProfileInfo::maxPolymorphicInliningSize)
  831. {
  832. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic): Skip Inline: Inlinee count either too small or too large %d (Max: %d)\tInlinee: %s (%s):\tCaller: %s (%s)\n",
  833. inlineeCount, Js::DynamicProfileInfo::maxPolymorphicInliningSize,
  834. inlineeJitTimeData->GetFunctionBody()->GetDisplayName(), inlineeJitTimeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  835. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  836. return instrNext;
  837. }
  838. // Begin inlining.
  839. POLYMORPHIC_INLINE_TESTTRACE(L"------------------------------------------------\n");
  840. for (uint i = 0; i < inlineeCount; i++)
  841. {
  842. Js::FunctionBody *inlineeFunctionBody = inlineesDataArray[i].functionBody;
  843. POLYMORPHIC_INLINE_TESTTRACE(L"INLINING (Polymorphic): Start inlining: \tInlinee: %s (%s):\tCaller: %s (%s)\n",
  844. inlineeFunctionBody->GetDisplayName(), inlineeFunctionBody->GetDebugNumberSet(debugStringBuffer),
  845. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2));
  846. }
  847. POLYMORPHIC_INLINE_TESTTRACE(L"------------------------------------------------\n");
  848. *pIsInlined = true;
  849. // This function is recursive, so when jitting in the foreground, probe the stack
  850. if (!this->topFunc->IsBackgroundJIT())
  851. {
  852. PROBE_STACK(this->topFunc->GetScriptContext(), Js::Constants::MinStackDefault);
  853. }
  854. IR::RegOpnd * returnValueOpnd;
  855. Js::RegSlot returnRegSlot;
  856. if (callInstr->GetDst())
  857. {
  858. returnValueOpnd = callInstr->UnlinkDst()->AsRegOpnd();
  859. returnRegSlot = returnValueOpnd->m_sym->GetByteCodeRegSlot();
  860. }
  861. else
  862. {
  863. returnValueOpnd = nullptr;
  864. returnRegSlot = Js::Constants::NoRegister;
  865. }
  866. Assert(inlineeCount >= 2);
  867. // Shared bailout point for all the guard check bailouts.
  868. InsertJsFunctionCheck(callInstr, callInstr, IR::BailOutOnPolymorphicInlineFunction);
  869. callInstr->MoveArgs(/*generateByteCodeCapture*/ true);
  870. IR::LabelInstr * doneLabel = IR::LabelInstr::New(Js::OpCode::Label, callInstr->m_func, false);
  871. IR::Instr* dispatchStartLabel = IR::LabelInstr::New(Js::OpCode::Label, callInstr->m_func, false);
  872. callInstr->InsertBefore(dispatchStartLabel);
  873. for (uint i = 0; i < inlineeCount; i++)
  874. {
  875. IR::LabelInstr* inlineeStartLabel = IR::LabelInstr::New(Js::OpCode::Label, callInstr->m_func);
  876. callInstr->InsertBefore(inlineeStartLabel);
  877. InsertOneInlinee(callInstr, returnValueOpnd, callInstr->GetSrc1(), inlineesDataArray[i], doneLabel, symCallerThis, /*fixedFunctionSafeThis*/ false, recursiveInlineDepth);
  878. IR::RegOpnd* functionObject = callInstr->GetSrc1()->AsRegOpnd();
  879. dispatchStartLabel->InsertBefore(IR::BranchInstr::New(Js::OpCode::BrAddr_A, inlineeStartLabel,
  880. IR::IndirOpnd::New(functionObject, Js::JavascriptFunction::GetOffsetOfFunctionInfo(), TyMachPtr, dispatchStartLabel->m_func),
  881. IR::AddrOpnd::New(inlineesDataArray[i].functionBody, IR::AddrOpndKindDynamicFunctionBody, dispatchStartLabel->m_func), dispatchStartLabel->m_func));
  882. }
  883. CompletePolymorphicInlining(callInstr, returnValueOpnd, doneLabel, dispatchStartLabel, /*ldMethodFldInstr*/nullptr, IR::BailOutOnPolymorphicInlineFunction);
  884. this->topFunc->SetHasInlinee();
  885. InsertStatementBoundary(instrNext);
  886. return instrNext;
  887. }
  888. void Inline::CompletePolymorphicInlining(IR::Instr* callInstr, IR::RegOpnd* returnValueOpnd, IR::LabelInstr* doneLabel, IR::Instr* dispatchStartLabel, IR::Instr* ldMethodFldInstr, IR::BailOutKind bailoutKind)
  889. {
  890. // Label $bailout:
  891. // LdMethodFldPolyInlineMiss
  892. // BailOnNotPolymorphicInlinee $callOutBytecodeOffset - BailOutOnFailedPolymorphicInlineTypeCheck
  893. // ByteCoudeUses
  894. // BytecodeArgoutUses
  895. // returnValueOpnd = EndCallForPolymorphicInlinee actualsCount
  896. IR::LabelInstr* bailOutLabel = IR::LabelInstr::New(Js::OpCode::Label, callInstr->m_func, /*helperLabel*/ true);
  897. callInstr->InsertBefore(bailOutLabel);
  898. dispatchStartLabel->InsertBefore(IR::BranchInstr::New(Js::OpCode::Br, bailOutLabel, callInstr->m_func));
  899. // Only fixed function inlining requires a ldMethodFldInstr
  900. if (ldMethodFldInstr)
  901. {
  902. callInstr->InsertBefore(ldMethodFldInstr);
  903. }
  904. callInstr->InsertBefore(IR::BailOutInstr::New(Js::OpCode::BailOnNotPolymorphicInlinee, bailoutKind, callInstr, callInstr->m_func));
  905. uint actualsCount = 0;
  906. callInstr->IterateArgInstrs([&](IR::Instr* argInstr) {
  907. IR::Instr* bytecodeArgOutUse = IR::Instr::New(Js::OpCode::BytecodeArgOutUse, callInstr->m_func);
  908. bytecodeArgOutUse->SetByteCodeOffset(callInstr);
  909. bytecodeArgOutUse->SetSrc1(argInstr->GetSrc1());
  910. callInstr->InsertBefore(bytecodeArgOutUse);
  911. actualsCount++;
  912. // Remove the original args
  913. argInstr->Remove();
  914. return false;
  915. });
  916. callInstr->InsertBefore(IR::ByteCodeUsesInstr::New(callInstr, callInstr->GetSrc1()->GetStackSym()->m_id));
  917. IR::Instr* endCallInstr = IR::Instr::New(Js::OpCode::EndCallForPolymorphicInlinee, callInstr->m_func);
  918. endCallInstr->SetSrc1(IR::IntConstOpnd::New(actualsCount + Js::Constants::InlineeMetaArgCount, TyInt32, callInstr->m_func, /*dontEncode*/ true));
  919. if (returnValueOpnd)
  920. {
  921. StackSym* returnValueSym = returnValueOpnd->m_sym->AsStackSym();
  922. IR::Opnd* dstOpnd = IR::RegOpnd::New(returnValueSym, returnValueSym->GetType(), callInstr->m_func);
  923. dstOpnd->SetValueType(returnValueOpnd->GetValueType());
  924. endCallInstr->SetDst(dstOpnd);
  925. }
  926. callInstr->InsertBefore(endCallInstr);
  927. callInstr->InsertBefore(doneLabel);
  928. callInstr->Remove(); // We don't need callInstr anymore.
  929. }
  930. //
  931. // Inlines a function if it is a polymorphic inlining candidate.
  932. // otherwise introduces a call to it.
  933. // The IR for the args & calls is cloned to do this
  934. //
  935. void Inline::InsertOneInlinee(IR::Instr* callInstr, IR::RegOpnd* returnValueOpnd, IR::Opnd* methodOpnd,
  936. const InlineeData& inlineeData, IR::LabelInstr* doneLabel, const StackSym* symCallerThis, bool fixedFunctionSafeThis, uint recursiveInlineDepth)
  937. {
  938. bool isInlined = inlineeData.inlineeJitTimeData->GetIsInlined();
  939. IR::Instr* currentCallInstr;
  940. if (isInlined)
  941. {
  942. currentCallInstr = IR::Instr::New(Js::OpCode::InlineeStart, IR::RegOpnd::New(TyVar, callInstr->m_func), methodOpnd, callInstr->m_func);
  943. }
  944. else
  945. {
  946. currentCallInstr = IR::Instr::New(callInstr->m_opcode, callInstr->m_func);
  947. currentCallInstr->SetSrc1(methodOpnd);
  948. if (returnValueOpnd)
  949. {
  950. currentCallInstr->SetDst(returnValueOpnd);
  951. }
  952. }
  953. currentCallInstr->SetIsCloned(true);
  954. callInstr->InsertBefore(currentCallInstr);
  955. this->CloneCallSequence(callInstr, currentCallInstr);
  956. if (isInlined)
  957. {
  958. Js::FunctionBody *funcBody = inlineeData.functionBody;
  959. Func *inlinee = BuildInlinee(funcBody, inlineeData, returnValueOpnd ? returnValueOpnd->m_sym->GetByteCodeRegSlot() : Js::Constants::NoRegister, callInstr, recursiveInlineDepth);
  960. IR::Instr *argOuts[Js::InlineeCallInfo::MaxInlineeArgoutCount];
  961. #if DBG
  962. memset(argOuts, 0xFE, sizeof(argOuts));
  963. #endif
  964. bool stackArgsArgOutExpanded = false;
  965. Js::ArgSlot actualCount = MapActuals(currentCallInstr, argOuts, Js::InlineeCallInfo::MaxInlineeArgoutCount, inlinee, (Js::ProfileId)callInstr->AsProfiledInstr()->u.profileId, &stackArgsArgOutExpanded);
  966. Assert(actualCount > 0);
  967. MapFormals(inlinee, argOuts, funcBody->GetInParamsCount(), actualCount, returnValueOpnd, currentCallInstr->GetSrc1(), symCallerThis, stackArgsArgOutExpanded, fixedFunctionSafeThis, argOuts);
  968. currentCallInstr->m_func = inlinee;
  969. // Put the meta arguments that the stack walker expects to find on the stack.
  970. // As all the argouts are shared among the inlinees, do this only once.
  971. SetupInlineeFrame(inlinee, currentCallInstr, actualCount, currentCallInstr->GetSrc1());
  972. IR::Instr* inlineeEndInstr = IR::Instr::New(Js::OpCode::InlineeEnd, inlinee);
  973. inlineeEndInstr->SetByteCodeOffset(inlinee->m_tailInstr->GetPrevRealInstr());
  974. inlineeEndInstr->SetSrc1(IR::IntConstOpnd::New(actualCount + Js::Constants::InlineeMetaArgCount, TyInt32, inlinee));
  975. inlineeEndInstr->SetSrc2(currentCallInstr->GetDst());
  976. inlinee->m_tailInstr->InsertBefore(inlineeEndInstr);
  977. // JMP to done at the end
  978. IR::Instr* doneInstr = IR::BranchInstr::New(Js::OpCode::Br, doneLabel, currentCallInstr->m_func);
  979. inlinee->m_tailInstr->InsertBefore(doneInstr);
  980. currentCallInstr->InsertRangeAfter(inlinee->m_headInstr->m_next, inlinee->m_tailInstr->m_prev);
  981. inlinee->m_headInstr->Free();
  982. inlinee->m_tailInstr->Free();
  983. }
  984. else
  985. {
  986. callInstr->InsertBefore(IR::BranchInstr::New(Js::OpCode::Br, doneLabel, callInstr->m_func));
  987. }
  988. }
  989. uint
  990. Inline::HandleDifferentTypesSameFunction(__inout_ecount(cachedFixedInlineeCount) Js::FixedFieldInfo* fixedFunctionInfoArray, uint16 cachedFixedInlineeCount)
  991. {
  992. uint16 uniqueCount = cachedFixedInlineeCount;
  993. uint16 swapIndex;
  994. for (uint16 i = 0; i < cachedFixedInlineeCount; i++)
  995. {
  996. swapIndex = i+1;
  997. for (uint16 j = i+1; j < cachedFixedInlineeCount; j++)
  998. {
  999. if (fixedFunctionInfoArray[i].fieldValue == fixedFunctionInfoArray[j].fieldValue)
  1000. {
  1001. Js::FixedFieldInfo tmpInfo = fixedFunctionInfoArray[j];
  1002. fixedFunctionInfoArray[j] = fixedFunctionInfoArray[swapIndex];
  1003. fixedFunctionInfoArray[swapIndex] = tmpInfo;
  1004. fixedFunctionInfoArray[swapIndex - 1].nextHasSameFixedField = true;
  1005. swapIndex++;
  1006. uniqueCount--;
  1007. }
  1008. }
  1009. i = swapIndex-1;
  1010. }
  1011. return uniqueCount;
  1012. }
  1013. void
  1014. Inline::SetInlineeFrameStartSym(Func *inlinee, uint actualCount)
  1015. {
  1016. StackSym *stackSym = inlinee->m_symTable->GetArgSlotSym((Js::ArgSlot)actualCount + 1);
  1017. stackSym->m_isInlinedArgSlot = true;
  1018. this->topFunc->SetArgOffset(stackSym, (currentInlineeFrameSlot) * MachPtr);
  1019. inlinee->SetInlineeFrameStartSym(stackSym);
  1020. }
  1021. Func *
  1022. Inline::BuildInlinee(Js::FunctionBody* funcBody, const InlineeData& inlineeData, Js::RegSlot returnRegSlot, IR::Instr *callInstr, uint recursiveInlineDepth)
  1023. {
  1024. Assert(callInstr->IsProfiledInstr());
  1025. Js::ProfileId callSiteId = static_cast<Js::ProfileId>(callInstr->AsProfiledInstr()->u.profileId);
  1026. Assert(callSiteId >= 0);
  1027. Js::ProxyEntryPointInfo *defaultEntryPointInfo = funcBody->GetDefaultEntryPointInfo();
  1028. Assert(defaultEntryPointInfo->IsFunctionEntryPointInfo());
  1029. Js::FunctionEntryPointInfo *functionEntryPointInfo = static_cast<Js::FunctionEntryPointInfo*>(defaultEntryPointInfo);
  1030. JsFunctionCodeGen *workItem = JitAnew(this->topFunc->m_alloc, JsFunctionCodeGen,
  1031. funcBody->GetScriptContext()->GetNativeCodeGenerator(), funcBody, functionEntryPointInfo, this->topFunc->IsJitInDebugMode());
  1032. workItem->SetRecyclableData(JitAnew(this->topFunc->m_alloc, Js::CodeGenRecyclableData, inlineeData.inlineeJitTimeData));
  1033. workItem->SetJitMode(this->topFunc->m_workItem->GetJitMode());
  1034. const auto profileInfo =
  1035. JitAnew(
  1036. this->topFunc->m_alloc,
  1037. Js::ReadOnlyDynamicProfileInfo,
  1038. funcBody->HasDynamicProfileInfo() ? funcBody->GetAnyDynamicProfileInfo() : nullptr,
  1039. this->topFunc->IsBackgroundJIT() ? this->topFunc->m_alloc : nullptr);
  1040. Js::EntryPointPolymorphicInlineCacheInfo * entryPointPolymorphicInlineCacheInfo = this->topFunc->m_workItem->GetEntryPoint()->GetPolymorphicInlineCacheInfo();
  1041. Func *inlinee = JitAnew(this->topFunc->m_alloc,
  1042. Func,
  1043. this->topFunc->m_alloc,
  1044. workItem,
  1045. inlineeData.inlineeRuntimeData,
  1046. entryPointPolymorphicInlineCacheInfo ? entryPointPolymorphicInlineCacheInfo->GetInlineeInfo(funcBody) : nullptr,
  1047. this->topFunc->GetCodeGenAllocators(),
  1048. this->topFunc->GetNumberAllocator(),
  1049. profileInfo,
  1050. this->topFunc->GetCodeGenProfiler(),
  1051. this->topFunc->IsBackgroundJIT(),
  1052. callInstr->m_func,
  1053. callInstr->m_next->GetByteCodeOffset(),
  1054. returnRegSlot,
  1055. false,
  1056. callSiteId,
  1057. false);
  1058. BuildIRForInlinee(inlinee, funcBody, callInstr, false, recursiveInlineDepth);
  1059. return inlinee;
  1060. }
  1061. void
  1062. Inline::BuildIRForInlinee(Func *inlinee, Js::FunctionBody *funcBody, IR::Instr *callInstr, bool isApplyTarget, uint recursiveInlineDepth)
  1063. {
  1064. Js::ArgSlot actualsCount = 0;
  1065. IR::Instr *argOuts[Js::InlineeCallInfo::MaxInlineeArgoutCount];
  1066. #if DBG
  1067. memset(argOuts, 0xFE, sizeof(argOuts));
  1068. #endif
  1069. callInstr->IterateArgInstrs([&](IR::Instr* argInstr){
  1070. StackSym *argSym = argInstr->GetDst()->AsSymOpnd()->m_sym->AsStackSym();
  1071. argOuts[argSym->GetArgSlotNum() - 1] = argInstr;
  1072. actualsCount++;
  1073. return false;
  1074. });
  1075. inlinee->actualCount = actualsCount;
  1076. inlinee->m_symTable = this->topFunc->m_symTable;
  1077. inlinee->m_symTable->SetIDAdjustment();
  1078. inlinee->m_symTable->IncreaseStartingID(funcBody->GetLocalsCount());
  1079. BEGIN_CODEGEN_PHASE(this->topFunc, Js::IRBuilderPhase);
  1080. IRBuilder irBuilder(inlinee);
  1081. irBuilder.Build();
  1082. END_CODEGEN_PHASE_NO_DUMP(this->topFunc, Js::IRBuilderPhase);
  1083. inlinee->m_symTable->ClearIDAdjustment();
  1084. Inline recursiveInliner(this->topFunc, this->inliningHeuristics, this->isInLoop, currentInlineeFrameSlot + Js::Constants::InlineeMetaArgCount + actualsCount, isApplyTarget);
  1085. recursiveInliner.Optimize(inlinee, argOuts, actualsCount, inlinee->GetJnFunction() == callInstr->m_func->GetJnFunction() ? recursiveInlineDepth + 1 : 0);
  1086. #ifdef DBG
  1087. Js::ArgSlot formalCount = funcBody->GetInParamsCount();
  1088. if (formalCount > Js::InlineeCallInfo::MaxInlineeArgoutCount)
  1089. {
  1090. Fatal();
  1091. }
  1092. #endif
  1093. }
  1094. bool
  1095. Inline::TryOptimizeCallInstrWithFixedMethod(IR::Instr *callInstr, Js::FunctionInfo* functionInfo, bool isPolymorphic, bool isBuiltIn, bool isCtor, bool isInlined, bool &safeThis,
  1096. bool dontOptimizeJustCheck, uint i /*i-th inlinee at a polymorphic call site*/)
  1097. {
  1098. Assert(!callInstr->m_func->GetJnFunction()->GetHasTry());
  1099. if (PHASE_OFF(Js::FixedMethodsPhase, callInstr->m_func->GetJnFunction()))
  1100. {
  1101. return false;
  1102. }
  1103. #ifdef ENABLE_DEBUG_CONFIG_OPTIONS
  1104. #define TRACE_FIXED_FIELDS 1
  1105. #endif
  1106. #if TRACE_FIXED_FIELDS
  1107. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  1108. wchar_t debugStringBuffer2[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  1109. bool printFixedFieldsTrace =
  1110. ((PHASE_TRACE(Js::FixedMethodsPhase, callInstr->m_func->GetJnFunction()) || PHASE_TESTTRACE(Js::FixedMethodsPhase, callInstr->m_func->GetJnFunction()) ||
  1111. (isCtor && PHASE_TRACE(Js::FixedNewObjPhase, callInstr->m_func->GetJnFunction()) || PHASE_TESTTRACE(Js::FixedNewObjPhase, callInstr->m_func->GetJnFunction()))) && !dontOptimizeJustCheck);
  1112. if (printFixedFieldsTrace)
  1113. {
  1114. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1115. Js::FunctionBody* calleeFunctionBody = functionInfo != nullptr && functionInfo->HasBody() ? functionInfo->GetFunctionBody() : nullptr;
  1116. const wchar_t* calleeName = calleeFunctionBody != nullptr ? calleeFunctionBody->GetDisplayName() : L"<unknown>";
  1117. Output::Print(L"FixedFields: function %s (%s): considering method <unknown> (%s %s): polymorphic = %d, built-in = %d, ctor = %d, inlined = %d, functionInfo = %p.\n",
  1118. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer), calleeName,
  1119. calleeFunctionBody ? calleeFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)",
  1120. isPolymorphic, isBuiltIn, isCtor, isInlined, functionInfo);
  1121. Output::Flush();
  1122. }
  1123. #endif
  1124. if (isPolymorphic && isInlined)
  1125. {
  1126. Assert(dontOptimizeJustCheck);
  1127. }
  1128. StackSym* methodValueSym = callInstr->GetSrc1()->AsRegOpnd()->m_sym->AsStackSym();
  1129. if (!methodValueSym->IsSingleDef())
  1130. {
  1131. #if TRACE_FIXED_FIELDS
  1132. if (printFixedFieldsTrace)
  1133. {
  1134. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1135. Js::FunctionBody* calleeFunctionBody = functionInfo != nullptr && functionInfo->HasBody() ? functionInfo->GetFunctionBody() : nullptr;
  1136. const wchar_t* calleeName = calleeFunctionBody != nullptr ? calleeFunctionBody->GetDisplayName() : L"<unknown>";
  1137. Output::Print(L"FixedFields: function %s (%s): %s non-fixed method <unknown> (%s %s), because callee is not single def.\n",
  1138. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer),
  1139. functionInfo != nullptr ? L"inlining" : L"calling", calleeName,
  1140. calleeFunctionBody ? calleeFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)");
  1141. Output::Flush();
  1142. }
  1143. #endif
  1144. return false;
  1145. }
  1146. IR::Instr* ldMethodFldInstr = methodValueSym->GetInstrDef();
  1147. if (ldMethodFldInstr->m_opcode != Js::OpCode::ScopedLdMethodFld
  1148. && ldMethodFldInstr->m_opcode != Js::OpCode::LdRootMethodFld
  1149. && ldMethodFldInstr->m_opcode != Js::OpCode::LdMethodFld
  1150. && ldMethodFldInstr->m_opcode != Js::OpCode::LdRootFld
  1151. && ldMethodFldInstr->m_opcode != Js::OpCode::LdFld
  1152. && ldMethodFldInstr->m_opcode != Js::OpCode::LdFldForCallApplyTarget
  1153. && ldMethodFldInstr->m_opcode != Js::OpCode::LdMethodFromFlags)
  1154. {
  1155. #if TRACE_FIXED_FIELDS
  1156. if (printFixedFieldsTrace)
  1157. {
  1158. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1159. Js::FunctionBody* calleeFunctionBody = functionInfo != nullptr && functionInfo->HasBody() ? functionInfo->GetFunctionBody() : nullptr;
  1160. const wchar_t* calleeName = calleeFunctionBody != nullptr ? calleeFunctionBody->GetDisplayName() : L"<unknown>";
  1161. Output::Print(L"FixedFields: function %s (%s): %s non-fixed method <unknown> (%s %s), because callee does not come from LdMethodFld.\n",
  1162. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer),
  1163. functionInfo != nullptr ? L"inlining" : L"calling", calleeName,
  1164. calleeFunctionBody ? calleeFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)");
  1165. Output::Flush();
  1166. }
  1167. #endif
  1168. return false;
  1169. }
  1170. IR::PropertySymOpnd* methodPropertyOpnd = ldMethodFldInstr->GetSrc1()->AsPropertySymOpnd();
  1171. if ((isCtor &&
  1172. ((isInlined && PHASE_OFF(Js::FixedCtorInliningPhase, callInstr->m_func->GetJnFunction())) ||
  1173. (!isInlined && PHASE_OFF(Js::FixedCtorCallsPhase, callInstr->m_func->GetJnFunction())) ||
  1174. (methodPropertyOpnd->UsesAccessor()))) ||
  1175. (!isCtor &&
  1176. ((isBuiltIn &&
  1177. ((isInlined && PHASE_OFF(Js::FixedBuiltInMethodInliningPhase, callInstr->m_func->GetJnFunction())) ||
  1178. (!isInlined && PHASE_OFF(Js::FixedBuiltInMethodCallsPhase, callInstr->m_func->GetJnFunction())))) ||
  1179. (!isBuiltIn &&
  1180. ((isInlined && PHASE_OFF(Js::FixedScriptMethodInliningPhase, callInstr->m_func->GetJnFunction())) ||
  1181. (!isInlined && !PHASE_ON(Js::FixedScriptMethodCallsPhase, callInstr->m_func->GetJnFunction()))))))
  1182. )
  1183. {
  1184. #if TRACE_FIXED_FIELDS
  1185. if (printFixedFieldsTrace)
  1186. {
  1187. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1188. Js::FunctionBody* calleeFunctionBody = functionInfo != nullptr && functionInfo->HasBody() ? functionInfo->GetFunctionBody() : nullptr;
  1189. const wchar_t* calleeName = calleeFunctionBody != nullptr ? calleeFunctionBody->GetDisplayName() : L"<unknown>";
  1190. Js::PropertyId methodPropertyId = callerFunctionBody->GetPropertyIdFromCacheId(methodPropertyOpnd->m_inlineCacheIndex);
  1191. Js::PropertyRecord const * const methodPropertyRecord = callerFunctionBody->GetScriptContext()->GetPropertyNameLocked(methodPropertyId);
  1192. Output::Print(L"FixedFields: function %s (#%u): %s non-fixed method %s (%s #%u) (cache id: %d), because %s fixed %s %s is disabled.\n",
  1193. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer),
  1194. functionInfo != nullptr ? L"inlining" : L"calling", methodPropertyRecord->GetBuffer(), calleeName,
  1195. calleeFunctionBody ? calleeFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)",
  1196. methodPropertyOpnd->m_inlineCacheIndex, isInlined ? L"inlining" : L"calling", isBuiltIn ? L"built-in" : L"script",
  1197. isCtor ? L"ctors" : L"methods");
  1198. Output::Flush();
  1199. }
  1200. #endif
  1201. return false;
  1202. }
  1203. if (!methodPropertyOpnd->IsObjTypeSpecCandidate() && !methodPropertyOpnd->IsRootObjectNonConfigurableFieldLoad())
  1204. {
  1205. #if TRACE_FIXED_FIELDS
  1206. if (printFixedFieldsTrace)
  1207. {
  1208. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1209. Js::FunctionBody* calleeFunctionBody = functionInfo != nullptr && functionInfo->HasBody() ? functionInfo->GetFunctionBody() : nullptr;
  1210. const wchar_t* calleeName = calleeFunctionBody != nullptr ? calleeFunctionBody->GetDisplayName() : L"<unknown>";
  1211. Js::PropertyId methodPropertyId = callerFunctionBody->GetPropertyIdFromCacheId(methodPropertyOpnd->m_inlineCacheIndex);
  1212. Js::PropertyRecord const * const methodPropertyRecord = callerFunctionBody->GetScriptContext()->GetPropertyNameLocked(methodPropertyId);
  1213. Output::Print(L"FixedFields: function %s (%s): %s non-fixed method %s (%s %s) (cache id: %d), because inline cache has no cached type.\n",
  1214. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer),
  1215. functionInfo != nullptr ? L"inlining" : L"calling", methodPropertyRecord->GetBuffer(), calleeName,
  1216. calleeFunctionBody ? calleeFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)",
  1217. methodPropertyOpnd->m_inlineCacheIndex);
  1218. Output::Flush();
  1219. }
  1220. #endif
  1221. return false;
  1222. }
  1223. Js::JavascriptFunction const * functionObject = nullptr;
  1224. if (!isPolymorphic)
  1225. {
  1226. functionObject = methodPropertyOpnd->HasFixedValue() ? methodPropertyOpnd->GetFieldValueAsFixedFunction() : nullptr;
  1227. }
  1228. else if (isPolymorphic && isInlined)
  1229. {
  1230. functionObject = methodPropertyOpnd->HasFixedValue() ? methodPropertyOpnd->GetFieldValueAsFixedFunction(i) : nullptr;
  1231. }
  1232. if (!functionObject)
  1233. {
  1234. #if TRACE_FIXED_FIELDS
  1235. if (printFixedFieldsTrace)
  1236. {
  1237. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1238. Js::FunctionBody* calleeFunctionBody = functionInfo != nullptr && functionInfo->HasBody() ? functionInfo->GetFunctionBody() : nullptr;
  1239. const wchar_t* calleeName = calleeFunctionBody != nullptr ? calleeFunctionBody->GetDisplayName() : L"<unknown>";
  1240. Js::PropertyId methodPropertyId = callerFunctionBody->GetPropertyIdFromCacheId(methodPropertyOpnd->m_inlineCacheIndex);
  1241. Js::PropertyRecord const * const methodPropertyRecord = callerFunctionBody->GetScriptContext()->GetPropertyNameLocked(methodPropertyId);
  1242. Output::Print(L"FixedFields: function %s (%s): %s non-fixed method %s (%s %s) (cache id: %d, layout: %s), because inline cache has no fixed function object.\n",
  1243. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer),
  1244. functionInfo != nullptr ? L"inlining" : L"calling", methodPropertyRecord->GetBuffer(), calleeName,
  1245. calleeFunctionBody ? calleeFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)",
  1246. methodPropertyOpnd->m_inlineCacheIndex,
  1247. methodPropertyOpnd->IsLoadedFromProto() ? L"proto" : methodPropertyOpnd->UsesAccessor() ? L"accessor" : L"local");
  1248. Output::Flush();
  1249. }
  1250. #endif
  1251. return false;
  1252. }
  1253. // Certain built-ins that we decide not to inline will get a fast path emitted by the lowerer.
  1254. // The lowering code cannot handle a call with a fixed function target, because it needs access to
  1255. // the original property sym. Turn off fixed method calls for these cases.
  1256. if (functionInfo == nullptr && Func::IsBuiltInInlinedInLowerer(callInstr->GetSrc1()))
  1257. {
  1258. #if TRACE_FIXED_FIELDS
  1259. if (printFixedFieldsTrace)
  1260. {
  1261. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1262. Js::FunctionBody* calleeFunctionBody = functionInfo != nullptr && functionInfo->HasBody() ? functionInfo->GetFunctionBody() : nullptr;
  1263. const wchar_t* calleeName = calleeFunctionBody != nullptr ? calleeFunctionBody->GetDisplayName() : L"<unknown>";
  1264. Js::PropertyId methodPropertyId = callerFunctionBody->GetPropertyIdFromCacheId(methodPropertyOpnd->m_inlineCacheIndex);
  1265. Js::PropertyRecord const * const methodPropertyRecord = callerFunctionBody->GetScriptContext()->GetPropertyNameLocked(methodPropertyId);
  1266. Output::Print(L"FixedFields: function %s (%s): %s non-fixed method %s (%s %s) (cache id: %d, layout: %s), because callee is a built-in with fast path in lowerer.\n",
  1267. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer),
  1268. functionInfo != nullptr ? L"inlining" : L"calling", methodPropertyRecord->GetBuffer(), calleeName,
  1269. calleeFunctionBody ? calleeFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)",
  1270. methodPropertyOpnd->m_inlineCacheIndex,
  1271. methodPropertyOpnd->IsLoadedFromProto() ? L"proto" : methodPropertyOpnd->UsesAccessor() ? L"accessor" : L"local");
  1272. Output::Flush();
  1273. }
  1274. #endif
  1275. return false;
  1276. }
  1277. if (functionInfo != nullptr && functionObject->GetFunctionInfo() != functionInfo)
  1278. {
  1279. #if TRACE_FIXED_FIELDS
  1280. if (printFixedFieldsTrace)
  1281. {
  1282. wchar_t debugStringBuffer3[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  1283. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1284. Js::PropertyId methodPropertyId = callerFunctionBody->GetPropertyIdFromCacheId(methodPropertyOpnd->m_inlineCacheIndex);
  1285. Js::PropertyRecord const * const methodPropertyRecord = callerFunctionBody->GetScriptContext()->GetPropertyNameLocked(methodPropertyId);
  1286. bool isProto = methodPropertyOpnd->IsLoadedFromProto();
  1287. bool isAccessor = methodPropertyOpnd->UsesAccessor();
  1288. Js::DynamicObject* protoObject = isProto ? methodPropertyOpnd->GetProtoObject() : nullptr;
  1289. Js::FunctionBody* fixedFunctionBody = functionObject->GetFunctionInfo()->GetFunctionBody();
  1290. const wchar_t* fixedFunctionNumbers = fixedFunctionBody ? fixedFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)";
  1291. Js::FunctionBody* profileFunctionBody = functionInfo->GetFunctionBody();
  1292. const wchar_t* profileFunctionName = profileFunctionBody != nullptr ? profileFunctionBody->GetDisplayName() : L"<unknown>";
  1293. const wchar_t* profileFunctionNumbers = profileFunctionBody ? profileFunctionBody->GetDebugNumberSet(debugStringBuffer3) : L"(null)";
  1294. if (PHASE_TRACE(Js::FixedMethodsPhase, callInstr->m_func->GetJnFunction()))
  1295. {
  1296. Output::Print(L"FixedFields: function %s (#%s): function body mismatch for inlinee: %s (%s) 0x%p->0x%p != %s (%s) 0x%p (cache id: %d, layout: %s, type: 0x%p, proto: 0x%p, proto type: 0x%p).\n",
  1297. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer),
  1298. methodPropertyRecord->GetBuffer(), fixedFunctionNumbers, functionObject, functionObject->GetFunctionInfo(),
  1299. profileFunctionName, profileFunctionNumbers, functionInfo,
  1300. methodPropertyOpnd->m_inlineCacheIndex, isProto ? L"proto" : isAccessor ? L"accessor" : L"local",
  1301. methodPropertyOpnd->GetType(), protoObject, protoObject != nullptr ? protoObject->GetType() : nullptr);
  1302. }
  1303. if (PHASE_TESTTRACE(Js::FixedMethodsPhase, callInstr->m_func->GetJnFunction()))
  1304. {
  1305. Output::Print(L"FixedFields: function %s (%s): function body mismatch for inlinee: %s (%s) != %s (%s) (cache id: %d, layout: %s).\n",
  1306. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer),
  1307. methodPropertyRecord->GetBuffer(), fixedFunctionNumbers, profileFunctionName, profileFunctionNumbers,
  1308. methodPropertyOpnd->m_inlineCacheIndex, isProto ? L"proto" : isAccessor ? L"accessor" : L"local");
  1309. }
  1310. Output::Flush();
  1311. }
  1312. #endif
  1313. // It appears that under certain bailout and re-JIT conditions we may end up with an updated
  1314. // inline cache pointing to a new function object, while the call site profile info still
  1315. // holds the old function body. If the two don't match, let's fall back on the regular LdMethodFld.
  1316. return false;
  1317. }
  1318. else
  1319. {
  1320. #if TRACE_FIXED_FIELDS
  1321. if (printFixedFieldsTrace)
  1322. {
  1323. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1324. Js::FunctionBody* calleeFunctionBody = functionInfo != nullptr && functionInfo->HasBody() ? functionInfo->GetFunctionBody() : nullptr;
  1325. Js::PropertyId methodPropertyId = callerFunctionBody->GetPropertyIdFromCacheId(methodPropertyOpnd->m_inlineCacheIndex);
  1326. Js::PropertyRecord const * const methodPropertyRecord = callerFunctionBody->GetScriptContext()->GetPropertyNameLocked(methodPropertyId);
  1327. const wchar_t* fixedFunctionName = calleeFunctionBody != nullptr ? calleeFunctionBody->GetDisplayName() : L"<unknown>";
  1328. Js::FunctionBody* fixedFunctionBody = functionObject->GetFunctionInfo()->GetFunctionBody();
  1329. const wchar_t* fixedFunctionNumbers = fixedFunctionBody ? fixedFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)";
  1330. Output::Print(L"FixedFields: function %s (%s): %s fixed method %s (%s %s) (cache id: %d, layout: %s).\n",
  1331. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer),
  1332. functionInfo != nullptr ? L"inlining" : L"calling",
  1333. methodPropertyRecord->GetBuffer(), fixedFunctionName, fixedFunctionNumbers,
  1334. methodPropertyOpnd->m_inlineCacheIndex,
  1335. methodPropertyOpnd->IsLoadedFromProto() ? L"proto" : methodPropertyOpnd->UsesAccessor() ? L"accessor" : L"local");
  1336. Output::Flush();
  1337. }
  1338. #endif
  1339. }
  1340. #undef TRACE_FIXED_FIELDS
  1341. if (dontOptimizeJustCheck)
  1342. {
  1343. return true;
  1344. }
  1345. // Change Ld[Root]MethodFld, LdMethodFromFlags to CheckFixedFld, which doesn't need a dst.
  1346. if(ldMethodFldInstr->m_opcode == Js::OpCode::LdMethodFromFlags)
  1347. {
  1348. Assert(ldMethodFldInstr->HasBailOutInfo());
  1349. ldMethodFldInstr->ClearBailOutInfo();
  1350. }
  1351. ldMethodFldInstr->m_opcode = Js::OpCode::CheckFixedFld;
  1352. IR::Opnd * methodValueDstOpnd = ldMethodFldInstr->UnlinkDst();
  1353. IR::Instr * chkMethodFldInstr = ldMethodFldInstr->ConvertToBailOutInstr(ldMethodFldInstr,
  1354. !methodPropertyOpnd->HasEquivalentTypeSet() ? IR::BailOutFailedFixedFieldTypeCheck : IR::BailOutFailedEquivalentFixedFieldTypeCheck);
  1355. chkMethodFldInstr->GetBailOutInfo()->polymorphicCacheIndex = methodPropertyOpnd->m_inlineCacheIndex;
  1356. Assert(chkMethodFldInstr->GetSrc1()->IsSymOpnd());
  1357. if (chkMethodFldInstr->GetSrc1()->AsSymOpnd()->IsPropertySymOpnd())
  1358. {
  1359. Assert(chkMethodFldInstr->m_opcode == Js::OpCode::CheckFixedFld);
  1360. IR::PropertySymOpnd* chkMethodFldOpnd = chkMethodFldInstr->GetSrc1()->AsPropertySymOpnd();
  1361. // For polymorphic field loads we only support fixed functions on prototypes. This helps keep the equivalence check helper simple.
  1362. Assert(chkMethodFldOpnd->IsMono() || chkMethodFldOpnd->IsLoadedFromProto() || chkMethodFldOpnd->UsesAccessor());
  1363. chkMethodFldOpnd->SetUsesFixedValue(true);
  1364. }
  1365. if (isCtor)
  1366. {
  1367. Js::JitTimeConstructorCache* constructorCache = methodPropertyOpnd->GetCtorCache();
  1368. if (constructorCache != nullptr && callInstr->IsProfiledInstr())
  1369. {
  1370. #if ENABLE_DEBUG_CONFIG_OPTIONS
  1371. if (PHASE_TRACE(Js::FixedNewObjPhase, callInstr->m_func->GetJnFunction()) || PHASE_TESTTRACE(Js::FixedNewObjPhase, callInstr->m_func->GetJnFunction()))
  1372. {
  1373. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1374. Js::FunctionBody* calleeFunctionBody = functionInfo != nullptr && functionInfo->HasBody() ? functionInfo->GetFunctionBody() : nullptr;
  1375. Js::PropertyId methodPropertyId = callerFunctionBody->GetPropertyIdFromCacheId(methodPropertyOpnd->m_inlineCacheIndex);
  1376. Js::PropertyRecord const * const methodPropertyRecord = callerFunctionBody->GetScriptContext()->GetPropertyNameLocked(methodPropertyId);
  1377. const wchar_t* fixedFunctionName = calleeFunctionBody != nullptr ? calleeFunctionBody->GetDisplayName() : L"<unknown>";
  1378. Js::FunctionBody* fixedFunctionBody = functionObject->GetFunctionInfo()->GetFunctionBody();
  1379. const wchar_t* fixedFunctionNumbers = fixedFunctionBody ? fixedFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)";
  1380. Output::Print(L"FixedNewObj: function %s (%s): fixed new object for %s with %s ctor %s (%s %s)%s\n",
  1381. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer), Js::OpCodeUtil::GetOpCodeName(callInstr->m_opcode),
  1382. functionInfo != nullptr ? L"inlined" : L"called",
  1383. methodPropertyRecord->GetBuffer(), fixedFunctionName, fixedFunctionNumbers,
  1384. constructorCache->skipNewScObject ? L" skip default object" : L"");
  1385. Output::Flush();
  1386. }
  1387. #endif
  1388. // The profile ID's hung from array ctor opcodes don't match up with normal profiled call sites.
  1389. if (callInstr->m_opcode != Js::OpCode::NewScObjArray)
  1390. {
  1391. // Because we are storing flow sensitive info in the cache (guarded property operations),
  1392. // we must make sure the same cache cannot be used multiple times in the flow.
  1393. if (constructorCache->isUsed)
  1394. {
  1395. // It's okay to allocate a JitTimeConstructorCache from the func's allocator (rather than recycler),
  1396. // because we only use these during JIT. We use the underlying runtime cache as a guard that must
  1397. // live after JIT, and these are added to the EntryPointInfo during work item creation and thus kept alive.
  1398. constructorCache = constructorCache->Clone(this->topFunc->m_alloc);
  1399. }
  1400. Assert(!constructorCache->isUsed);
  1401. constructorCache->isUsed = true;
  1402. callInstr->m_func->SetConstructorCache(static_cast<Js::ProfileId>(callInstr->AsProfiledInstr()->u.profileId), constructorCache);
  1403. }
  1404. }
  1405. else
  1406. {
  1407. #if ENABLE_DEBUG_CONFIG_OPTIONS
  1408. if (PHASE_TRACE(Js::FixedNewObjPhase, callInstr->m_func->GetJnFunction()) || PHASE_TESTTRACE(Js::FixedNewObjPhase, callInstr->m_func->GetJnFunction()))
  1409. {
  1410. Js::FunctionBody* callerFunctionBody = callInstr->m_func->GetJnFunction();
  1411. Js::FunctionBody* calleeFunctionBody = functionInfo != nullptr && functionInfo->HasBody() ? functionInfo->GetFunctionBody() : nullptr;
  1412. Js::PropertyId methodPropertyId = callerFunctionBody->GetPropertyIdFromCacheId(methodPropertyOpnd->m_inlineCacheIndex);
  1413. Js::PropertyRecord const * const methodPropertyRecord = callerFunctionBody->GetScriptContext()->GetPropertyNameLocked(methodPropertyId);
  1414. const wchar_t* fixedFunctionName = calleeFunctionBody != nullptr ? calleeFunctionBody->GetDisplayName() : L"<unknown>";
  1415. Js::FunctionBody* fixedFunctionBody = functionObject->GetFunctionInfo()->GetFunctionBody();
  1416. const wchar_t* fixedFunctionNumbers = fixedFunctionBody ? fixedFunctionBody->GetDebugNumberSet(debugStringBuffer2) : L"(null)";
  1417. Output::Print(L"FixedNewObj: function %s (%s): non-fixed new object for %s with %s ctor %s (%s %s), because %s.\n",
  1418. callerFunctionBody->GetDisplayName(), callerFunctionBody->GetDebugNumberSet(debugStringBuffer), Js::OpCodeUtil::GetOpCodeName(callInstr->m_opcode),
  1419. functionInfo != nullptr ? L"inlined" : L"called",
  1420. methodPropertyRecord->GetBuffer(), fixedFunctionName, fixedFunctionNumbers,
  1421. constructorCache == nullptr ? L"constructor cache hasn't been cloned" : L"instruction isn't profiled");
  1422. Output::Flush();
  1423. }
  1424. #endif
  1425. }
  1426. }
  1427. // Insert a load instruction to place the constant address in methodOpnd (the Ld[Root]MethodFld's original dst).
  1428. IR::AddrOpnd * constMethodValueOpnd = IR::AddrOpnd::New((Js::Var)functionObject, IR::AddrOpndKind::AddrOpndKindDynamicVar, callInstr->m_func);
  1429. constMethodValueOpnd->m_isFunction = true;
  1430. IR::Instr * ldMethodValueInstr = IR::Instr::New(Js::OpCode::Ld_A, methodValueDstOpnd, constMethodValueOpnd, callInstr->m_func);
  1431. StackSym* methodSym = methodValueDstOpnd->AsRegOpnd()->m_sym;
  1432. if (methodSym->IsSingleDef())
  1433. {
  1434. methodSym->SetIsConst();
  1435. }
  1436. methodValueDstOpnd->SetValueType(ValueType::FromObject((Js::RecyclableObject* const)functionObject));
  1437. chkMethodFldInstr->InsertAfter(ldMethodValueInstr);
  1438. callInstr->ReplaceSrc1(constMethodValueOpnd);
  1439. if (callInstr->m_opcode == Js::OpCode::CallI || callInstr->CallsAccessor(methodPropertyOpnd))
  1440. {
  1441. callInstr->m_opcode = Js::OpCode::CallIFixed;
  1442. }
  1443. else
  1444. {
  1445. // We patch later for constructor inlining.
  1446. Assert(
  1447. callInstr->m_opcode == Js::OpCode::NewScObject ||
  1448. callInstr->m_opcode == Js::OpCode::NewScObjArray);
  1449. }
  1450. if (!isBuiltIn && isInlined)
  1451. {
  1452. // We eliminate CheckThis for fixed method inlining. Assert here that our assumption is true.
  1453. Js::TypeId typeId = methodPropertyOpnd->IsRootObjectNonConfigurableField() ?
  1454. Js::TypeIds_GlobalObject : methodPropertyOpnd->GetTypeId();
  1455. if(typeId > Js::TypeIds_LastJavascriptPrimitiveType && typeId <= Js::TypeIds_LastTrueJavascriptObjectType)
  1456. {
  1457. // Eliminate CheckThis for inlining.
  1458. safeThis = true;
  1459. }
  1460. }
  1461. return true;
  1462. }
  1463. Js::Var
  1464. Inline::TryOptimizeInstrWithFixedDataProperty(IR::Instr *&instr)
  1465. {
  1466. if (PHASE_OFF(Js::UseFixedDataPropsPhase, instr->m_func->GetJnFunction()) ||
  1467. PHASE_OFF(Js::UseFixedDataPropsInInlinerPhase, instr->m_func->GetJnFunction()))
  1468. {
  1469. return nullptr;
  1470. }
  1471. if (!instr->IsProfiledInstr() ||
  1472. !instr->GetSrc1()->IsSymOpnd() || !instr->GetSrc1()->AsSymOpnd()->IsPropertySymOpnd())
  1473. {
  1474. return nullptr;
  1475. }
  1476. if (!OpCodeAttr::CanLoadFixedFields(instr->m_opcode))
  1477. {
  1478. return nullptr;
  1479. }
  1480. return instr->TryOptimizeInstrWithFixedDataProperty(&instr, nullptr);
  1481. }
  1482. // Inline a built-in/math function call, such as Math.sin(x).
  1483. // Main idea on what happens with IR during different stages.
  1484. // 1) Copy args from ArgOuts into inline instr.
  1485. // 2) Change opcode: ArgOut_A -> ArgOut_A_InlineBuiltIn (aka BIA).
  1486. // 3) Notes:
  1487. // - General logic is similar to inlining regular functions, except that:
  1488. // - There are no inner instructions to inline.
  1489. // - We don't need to support arguments object inside the inlinee - don't need inlinee meta frame, etc.
  1490. // - ArgOuts are linked through src2->m_sym->m_instrDef.
  1491. // - ArgOuts are not needed for the inlined call itself, but we can't remove them because they are needed for bailout.
  1492. // We convert them to ArgOut_A_InlineBuiltIn.
  1493. // Example for Math.pow(x, y), x86 case.
  1494. // Original:
  1495. // instrS: dstS = StartCall <N=count>, NULL -- N is actual number of parameters, including "this".
  1496. // instr0: arg0 = ArgOut t, link(->instrS) -- "this" arg
  1497. // instr1: arg1 = ArgOut x, link(->instr0) -- src1
  1498. // instr2: arg2 = ArgOut y, link(->instr1) -- src2
  1499. // instr3: dstC = CallI fn, link(->instr2) -- links to instr2, etc.
  1500. // After Inline:
  1501. // instrS: dstS = StartCall <N=count>, NULL -- N is actual number of parameters, including "this".
  1502. // tmpt = BytecodeArgOutCapture t -- create assigns to temps to snapshot argout values in case they are modified later before the call
  1503. // tmpx = BytecodeArgOutCapture x
  1504. // tmpy = BytecodeArgOutCapture y
  1505. // instr1: arg1 = ArgOut_InlineBuiltIn tmpx, link(->instr0) -- src1
  1506. // instr0: arg0 = ArgOut_InlineBuiltIn tmpt, link(->instrS) -- "this" arg -- Change ArgOut_a to ArgOut_A_InlineBuiltIn
  1507. // instr2: arg2 = ArgOut_InlineBuiltIn tmpy, link(->instr1) -- src2
  1508. // NULL = InlineBuiltInStart fn, link(->instr2)
  1509. // dstC = InlineMathPow, tmpx, tmpy -- actual native math call.
  1510. // NULL = InlineBuiltInEnd <N=count>, link(->instr2)
  1511. // After Globopt:
  1512. // instrS: dstS = StartCall <N=count>, NULL -- N is actual number of parameters, including "this".
  1513. // tmpt = BytecodeArgOutCapture t -- create assigns to temps to snapshot argout values in case they are modified later before the call
  1514. // tmpx = BytecodeArgOutCapture x
  1515. // Bailout 1
  1516. // tmpy = BytecodeArgOutCapture y
  1517. // Bailout 2
  1518. // instr1: arg1 = ArgOut_InlineBuiltIn tmpx, link(->instr0) -- src1
  1519. // instr0: arg0 = ArgOut_InlineBuiltIn tmpt, link(->instrS) -- "this" arg -- Change ArgOut_a to ArgOut_A_InlineBuiltIn
  1520. // instr2: arg2 = ArgOut_InlineBuiltIn tmpy, link(->instr1) -- src2
  1521. // ...
  1522. // NULL = InlineBuiltInStart fn, link(->instr2) -- Note that InlineBuiltInStart is after last bailout.
  1523. // This is important so that fn used for bailout is after last bailout.
  1524. // dstC = InlineMathPow, tmpx, tmpy -- actual native math call.
  1525. // NULL = InlineBuiltInEnd <N=count>, link(->instr2)
  1526. // After Lowerer:
  1527. // ...
  1528. // s1(XMM0) = MOVSD tmpx
  1529. // s2(XMM1) = MOVSD tmpy
  1530. // s1(XMM0) = CALL pow -- actual native math call.
  1531. // dstC = MOVSD s1(XMM0)
  1532. IR::Instr *
  1533. Inline::InlineBuiltInFunction(IR::Instr *callInstr, Js::FunctionInfo *funcInfo, Js::OpCode inlineCallOpCode, const Js::FunctionCodeGenJitTimeData* inlinerData, const StackSym *symCallerThis, bool* pIsInlined, uint profileId, uint recursiveInlineDepth)
  1534. {
  1535. Assert(callInstr);
  1536. Assert(funcInfo);
  1537. Assert(inlinerData);
  1538. Assert(inlineCallOpCode != 0);
  1539. // We may still decide not to inline.
  1540. *pIsInlined = false;
  1541. // Inlining is profile-based, so get the built-in function from profile rather than from the callInstr's opnd.
  1542. Js::BuiltinFunction builtInId = Js::JavascriptLibrary::GetBuiltInForFuncInfo(funcInfo, callInstr->m_func->GetScriptContext());
  1543. #if defined(DBG_DUMP) || defined(ENABLE_DEBUG_CONFIG_OPTIONS)
  1544. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  1545. #endif
  1546. if(inlineCallOpCode == Js::OpCode::InlineMathFloor || inlineCallOpCode == Js::OpCode::InlineMathCeil || inlineCallOpCode == Js::OpCode::InlineMathRound)
  1547. {
  1548. #if defined(_M_IX86) || defined(_M_X64)
  1549. if (!AutoSystemInfo::Data.SSE4_1Available())
  1550. {
  1551. INLINE_TESTTRACE(L"INLINING: Skip Inline: SSE4.1 not available\tInlinee: %s (#%d)\tCaller: %s\n", Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId, inlinerData->GetFunctionBody()->GetDisplayName());
  1552. return callInstr->m_next;
  1553. }
  1554. #endif
  1555. if(callInstr->m_func->GetTopFunc()->GetProfileInfo()->IsFloorInliningDisabled())
  1556. {
  1557. INLINE_TESTTRACE(L"INLINING: Skip Inline: Floor Inlining Disabled\tInlinee: %s (#%d)\tCaller: %s\n", Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId, inlinerData->GetFunctionBody()->GetDisplayName());
  1558. return callInstr->m_next;
  1559. }
  1560. }
  1561. if (callInstr->GetSrc2() &&
  1562. callInstr->GetSrc2()->IsSymOpnd() &&
  1563. callInstr->GetSrc2()->AsSymOpnd()->m_sym->AsStackSym()->GetArgSlotNum() > Js::InlineeCallInfo::MaxInlineeArgoutCount)
  1564. {
  1565. // This is a hard limit as we only use 4 bits to encode the actual count in the InlineeCallInfo. Although
  1566. // InliningDecider already checks for this, the check is against profile data that may not be accurate since profile
  1567. // data matching does not take into account some types of changes to source code. Need to check this again with current
  1568. // information.
  1569. INLINE_TESTTRACE(L"INLINING: Skip Inline: ArgSlot > MaxInlineeArgoutCount\tInlinee: %s (#%d)\tArgSlotNum: %d\tMaxInlineeArgoutCount: %d\tCaller: %s (#%d)\n",
  1570. Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId, callInstr->GetSrc2()->AsSymOpnd()->m_sym->AsStackSym()->GetArgSlotNum(),
  1571. Js::InlineeCallInfo::MaxInlineeArgoutCount, inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1572. return callInstr->m_next;
  1573. }
  1574. Js::BuiltInFlags builtInFlags = Js::JavascriptLibrary::GetFlagsForBuiltIn(builtInId);
  1575. bool isAnyArgFloat = (builtInFlags & Js::BuiltInFlags::BIF_TypeSpecAllToFloat) != 0;
  1576. if (isAnyArgFloat && !GlobOpt::DoFloatTypeSpec(this->topFunc))
  1577. {
  1578. INLINE_TESTTRACE(L"INLINING: Skip Inline: float type spec is off\tInlinee: %s (#%d)\tCaller: %s (%s)\n",
  1579. Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId,
  1580. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1581. return callInstr->m_next;
  1582. }
  1583. bool canDstBeFloat = (builtInFlags & Js::BuiltInFlags::BIF_TypeSpecDstToFloat) != 0;
  1584. if (canDstBeFloat && !Js::JavascriptLibrary::CanFloatPreferenceFunc(builtInId) && inlineCallOpCode != Js::OpCode::InlineArrayPop)
  1585. {
  1586. // Note that for Math.abs that means that even though it can potentially be type-spec'd to int, we won't inline it.
  1587. // Some built-in functions, such as atan2, are disabled for float-pref.
  1588. INLINE_TESTTRACE(L"INLINING: Skip Inline: Cannot float-type-spec the inlinee\tInlinee: %s (#%d)\tCaller: %s (%s)\n",
  1589. Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId, // Get the _value (cause operator _E) to avoid using struct directly.
  1590. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1591. return callInstr->m_next;
  1592. }
  1593. bool isAnyArgInt = (builtInFlags & (Js::BuiltInFlags::BIF_TypeSpecDstToInt | Js::BuiltInFlags::BIF_TypeSpecSrc1ToInt | Js::BuiltInFlags::BIF_TypeSpecSrc2ToInt)) != 0;
  1594. if (isAnyArgInt && !GlobOpt::DoAggressiveIntTypeSpec(this->topFunc))
  1595. {
  1596. // Note that for Math.abs that means that even though it can potentially be type-spec'd to float, we won't inline it.
  1597. INLINE_TESTTRACE(L"INLINING: Skip Inline: int type spec is off\tInlinee: %s (#%d)\tCaller: %s (%s)\n",
  1598. Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId,
  1599. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1600. return callInstr->m_next;
  1601. }
  1602. if(inlineCallOpCode == Js::OpCode::InlineMathImul && !GlobOpt::DoLossyIntTypeSpec(topFunc))
  1603. {
  1604. INLINE_TESTTRACE(L"INLINING: Skip Inline: lossy int type spec is off, it's required for Math.imul to do | 0 on src opnds\tInlinee: %s (#%d)\tCaller: %s (%s)\n",
  1605. Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId,
  1606. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1607. return callInstr->m_next;
  1608. }
  1609. if(inlineCallOpCode == Js::OpCode::InlineMathClz32 && !GlobOpt::DoLossyIntTypeSpec(topFunc))
  1610. {
  1611. INLINE_TESTTRACE(L"INLINING: Skip Inline: lossy int type spec is off, it's required for Math.clz32 to do | 0 on src opnds\tInlinee: %s (#%d)\tCaller: %s (%s)\n",
  1612. Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId,
  1613. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1614. return callInstr->m_next;
  1615. }
  1616. if (inlineCallOpCode == Js::OpCode::InlineFunctionApply && (!callInstr->m_func->GetHasStackArgs() || this->topFunc->GetJnFunction()->IsInlineApplyDisabled()))
  1617. {
  1618. INLINE_TESTTRACE(L"INLINING: Skip Inline: stack args of inlining is off\tInlinee: %s (#%d)\tCaller: %s (%s)\n",
  1619. Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId,
  1620. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1621. return callInstr->m_next;
  1622. }
  1623. // TODO: when adding support for other type spec args (array, string) do appropriate check as well.
  1624. Assert(callInstr->GetSrc1());
  1625. Assert(callInstr->GetSrc1()->IsRegOpnd());
  1626. Assert(callInstr->GetSrc1()->AsRegOpnd()->m_sym);
  1627. if (!(builtInFlags & Js::BuiltInFlags::BIF_IgnoreDst) && callInstr->GetDst() == nullptr && inlineCallOpCode != Js::OpCode::InlineArrayPop)
  1628. {
  1629. // Is seems that it's not worth optimizing odd cases where the result is unused.
  1630. INLINE_TESTTRACE(L"INLINING: Skip Inline: inlinee's return value is not assigned to anything\tInlinee: %s (#%d)\tCaller: %s (%s)\n",
  1631. Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId,
  1632. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1633. return callInstr->m_next;
  1634. }
  1635. // Number of arguments, not including "this".
  1636. IntConstType requiredInlineCallArgCount = (IntConstType)Js::JavascriptLibrary::GetArgCForBuiltIn(builtInId);
  1637. IR::Opnd* linkOpnd = callInstr->GetSrc2();
  1638. Js::ArgSlot actualCount = linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->GetArgSlotNum();
  1639. // Check for missing actuals:
  1640. // if number of passed params to built-in function is not what it needs, don't inline.
  1641. int inlineCallArgCount = (int)((builtInFlags & Js::BuiltInFlags::BIF_UseSrc0) != 0 ? actualCount : actualCount - 1);
  1642. Assert(inlineCallArgCount >= 0);
  1643. if (linkOpnd->IsSymOpnd())
  1644. {
  1645. #if ENABLE_DEBUG_CONFIG_OPTIONS
  1646. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  1647. #endif
  1648. if((builtInFlags & Js::BuiltInFlags::BIF_VariableArgsNumber) != 0)
  1649. {
  1650. if(inlineCallArgCount > requiredInlineCallArgCount)
  1651. {
  1652. INLINE_TESTTRACE(L"INLINING: Skip Inline: parameter count exceeds the maximum number of parameters allowed\tInlinee: %s (#%d)\tCaller: %s (%s)\n",
  1653. Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId,
  1654. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1655. return callInstr->m_next;
  1656. }
  1657. }
  1658. else if(inlineCallArgCount != requiredInlineCallArgCount)
  1659. {
  1660. INLINE_TESTTRACE(L"INLINING: Skip Inline: parameter count doesn't match dynamic profile\tInlinee: %s (#%d)\tCaller: %s (%s)\n",
  1661. Js::JavascriptLibrary::GetNameForBuiltIn(builtInId), (int)builtInId,
  1662. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1663. return callInstr->m_next;
  1664. }
  1665. }
  1666. IR::Instr *inlineBuiltInEndInstr = nullptr;
  1667. if (inlineCallOpCode == Js::OpCode::InlineFunctionApply)
  1668. {
  1669. inlineBuiltInEndInstr = InlineApply(callInstr, funcInfo, inlinerData, symCallerThis, pIsInlined, profileId, recursiveInlineDepth);
  1670. return inlineBuiltInEndInstr->m_next;
  1671. }
  1672. if (inlineCallOpCode == Js::OpCode::InlineFunctionCall)
  1673. {
  1674. inlineBuiltInEndInstr = InlineCall(callInstr, funcInfo, inlinerData, symCallerThis, pIsInlined, profileId, recursiveInlineDepth);
  1675. return inlineBuiltInEndInstr->m_next;
  1676. }
  1677. #if defined(ENABLE_DEBUG_CONFIG_OPTIONS)
  1678. InliningDecider::TraceInlining(inlinerData->GetFunctionBody(), Js::JavascriptLibrary::GetNameForBuiltIn(builtInId),
  1679. nullptr, 0, this->topFunc->m_workItem->GetFunctionBody(), 0, nullptr, profileId, builtInId);
  1680. #endif
  1681. // From now on we are committed to inlining.
  1682. *pIsInlined = true;
  1683. // Save off the call target operand (function object) so we can extend its lifetime as needed, even if
  1684. // the call instruction gets transformed to CallIFixed.
  1685. StackSym* originalCallTargetStackSym = callInstr->GetSrc1()->GetStackSym();
  1686. // We are committed to inlining, optimize the call instruction for fixed fields now and don't attempt it later.
  1687. bool safeThis = false;
  1688. if (TryOptimizeCallInstrWithFixedMethod(callInstr, funcInfo, false /*isPolymorphic*/, true /*isBuiltIn*/, false /*isCtor*/, true /*isInlined*/, safeThis /*unused here*/))
  1689. {
  1690. Assert(callInstr->m_opcode == Js::OpCode::CallIFixed);
  1691. Assert(callInstr->GetFixedFunction()->GetFunctionInfo() == funcInfo);
  1692. }
  1693. else
  1694. {
  1695. // FunctionObject check for built-ins
  1696. IR::BailOutInstr * bailOutInstr = IR::BailOutInstr::New(Js::OpCode::BailOnNotBuiltIn, IR::BailOutOnInlineFunction, callInstr, callInstr->m_func);
  1697. InsertFunctionObjectCheck(callInstr, callInstr, bailOutInstr, funcInfo);
  1698. }
  1699. // To push function object for cases when we have to make calls to helper method to assist in inlining
  1700. if(inlineCallOpCode == Js::OpCode::CallDirect)
  1701. {
  1702. IR::Instr* argoutInstr;
  1703. StackSym *dstSym = callInstr->m_func->m_symTable->GetArgSlotSym((uint16)(1));
  1704. argoutInstr = IR::Instr::New(Js::OpCode::ArgOut_A_InlineSpecialized, IR::SymOpnd::New(dstSym, 0, TyMachPtr, callInstr->m_func), callInstr->UnlinkSrc1(), callInstr->UnlinkSrc2(), callInstr->m_func);
  1705. argoutInstr->SetByteCodeOffset(callInstr);
  1706. callInstr->GetInsertBeforeByteCodeUsesInstr()->InsertBefore(argoutInstr);
  1707. Js::BuiltinFunction builtInId = Js::JavascriptLibrary::GetBuiltInForFuncInfo(funcInfo, callInstr->m_func->GetScriptContext());
  1708. callInstr->m_opcode = inlineCallOpCode;
  1709. SetupInlineInstrForCallDirect(builtInId, callInstr, argoutInstr);
  1710. // Generate ByteCodeArgOutCaptures and move the ArgOut_A/ArgOut_A_Inline close to the call instruction
  1711. callInstr->MoveArgs(/*generateByteCodeCapture*/ true);
  1712. WrapArgsOutWithCoerse(builtInId, callInstr);
  1713. inlineBuiltInEndInstr = callInstr;
  1714. }
  1715. else
  1716. {
  1717. inlineBuiltInEndInstr = InsertInlineeBuiltInStartEndTags(callInstr, actualCount);
  1718. // InlineArrayPop - TrackCalls Need to be done at InlineArrayPop and not at the InlineBuiltInEnd
  1719. // Hence we use a new opcode, to detect that it is a InlineArrayPop and we don't track the call during End of inlineBuiltInCall sequence
  1720. if(inlineCallOpCode == Js::OpCode::InlineArrayPop)
  1721. {
  1722. inlineBuiltInEndInstr->m_opcode = Js::OpCode::InlineNonTrackingBuiltInEnd;
  1723. }
  1724. }
  1725. // Insert a byteCodeUsesInstr to make sure the function object's lifetime is extended beyond the last bailout point
  1726. // at which we may need to call the inlinee again in the interpreter.
  1727. IR::ByteCodeUsesInstr * useCallTargetInstr = IR::ByteCodeUsesInstr::New(callInstr, originalCallTargetStackSym->m_id);
  1728. callInstr->InsertBefore(useCallTargetInstr);
  1729. if(Js::JavascriptLibrary::IsTypeSpecRequired(builtInFlags)
  1730. // SIMD_JS
  1731. || IsSimd128Opcode(inlineCallOpCode)
  1732. //
  1733. )
  1734. {
  1735. // Emit byteCodeUses for function object
  1736. IR::Instr * inlineBuilitInStartInstr = inlineBuiltInEndInstr;
  1737. while(inlineBuilitInStartInstr->m_opcode != Js::OpCode::InlineBuiltInStart)
  1738. {
  1739. inlineBuilitInStartInstr = inlineBuilitInStartInstr->m_prev;
  1740. }
  1741. IR::Opnd * tmpDst = nullptr;
  1742. IR::Opnd * callInstrDst = callInstr->GetDst();
  1743. if(callInstrDst && inlineCallOpCode != Js::OpCode::InlineArrayPop)
  1744. {
  1745. StackSym * tmpSym = StackSym::New(callInstr->GetDst()->GetType(), callInstr->m_func);
  1746. tmpDst = IR::RegOpnd::New(tmpSym, tmpSym->GetType(), callInstr->m_func);
  1747. callInstrDst = callInstr->UnlinkDst();
  1748. callInstr->SetDst(tmpDst);
  1749. }
  1750. else
  1751. {
  1752. AssertMsg(inlineCallOpCode == Js::OpCode::InlineArrayPush || inlineCallOpCode == Js::OpCode::InlineArrayPop || Js::IsSimd128Opcode(inlineCallOpCode),
  1753. "Currently Dst can be null only for InlineArrayPush/InlineArrayPop");
  1754. }
  1755. // Insert a byteCodeUsesInstr to make sure the function object's lifetime is extended beyond the last bailout point
  1756. // at which we may need to call the inlinee again in the interpreter.
  1757. IR::ByteCodeUsesInstr * useCallTargetInstr = IR::ByteCodeUsesInstr::New(callInstr->GetPrevRealInstrOrLabel(), originalCallTargetStackSym->m_id);
  1758. if(inlineCallOpCode == Js::OpCode::InlineArrayPop)
  1759. {
  1760. callInstr->InsertBefore(useCallTargetInstr);
  1761. }
  1762. else
  1763. {
  1764. inlineBuiltInEndInstr->InsertBefore(useCallTargetInstr);
  1765. }
  1766. if(tmpDst)
  1767. {
  1768. IR::Instr * ldInstr = IR::Instr::New(Js::OpCode::Ld_A, callInstrDst, tmpDst, callInstr->m_func);
  1769. inlineBuiltInEndInstr->InsertBefore(ldInstr);
  1770. }
  1771. // Set srcs of the callInstr, and process ArgOuts.
  1772. callInstr->UnlinkSrc1();
  1773. callInstr->UnlinkSrc2();
  1774. callInstr->m_opcode = inlineCallOpCode;
  1775. int argIndex = inlineCallArgCount; // We'll use it to fill call instr srcs from upper to lower.
  1776. IR::ByteCodeUsesInstr * byteCodeUsesInstr = IR::ByteCodeUsesInstr::New(callInstr->m_func);
  1777. byteCodeUsesInstr->SetByteCodeOffset(callInstr);
  1778. byteCodeUsesInstr->byteCodeUpwardExposedUsed = JitAnew(callInstr->m_func->m_alloc, BVSparse<JitArenaAllocator>, callInstr->m_func->m_alloc);
  1779. IR::Instr *argInsertInstr = inlineBuilitInStartInstr;
  1780. // SIMD_JS
  1781. IR::Instr *eaInsertInstr = callInstr;
  1782. IR::Opnd *eaLinkOpnd = nullptr;
  1783. ThreadContext::SimdFuncSignature simdFuncSignature;
  1784. if (IsSimd128Opcode(callInstr->m_opcode))
  1785. {
  1786. callInstr->m_func->GetScriptContext()->GetThreadContext()->GetSimdFuncSignatureFromOpcode(callInstr->m_opcode, simdFuncSignature);
  1787. Assert(simdFuncSignature.valid);
  1788. }
  1789. //
  1790. inlineBuiltInEndInstr->IterateArgInstrs([&](IR::Instr* argInstr) {
  1791. StackSym *linkSym = linkOpnd->GetStackSym();
  1792. linkSym->m_isInlinedArgSlot = true;
  1793. linkSym->m_allocated = true;
  1794. // We are going to replace the use on the call (below), insert byte code use if necessary
  1795. if (OpCodeAttr::BailOutRec(inlineCallOpCode) || Js::IsSimd128Opcode(inlineCallOpCode))
  1796. {
  1797. StackSym * sym = argInstr->GetSrc1()->GetStackSym();
  1798. if (!sym->m_isSingleDef || !sym->m_instrDef->GetSrc1() || !sym->m_instrDef->GetSrc1()->IsConstOpnd())
  1799. {
  1800. if (!sym->IsFromByteCodeConstantTable())
  1801. {
  1802. byteCodeUsesInstr->byteCodeUpwardExposedUsed->Set(sym->m_id);
  1803. }
  1804. }
  1805. }
  1806. // Convert the arg out to built in arg out, and get the src of the arg out
  1807. IR::Opnd * argOpnd = ConvertToInlineBuiltInArgOut(argInstr);
  1808. // SIMD_JS
  1809. if (inlineCallArgCount > 2 && argIndex != 0 /* don't include 'this' */)
  1810. {
  1811. Assert(IsSimd128Opcode(callInstr->m_opcode));
  1812. // Insert ExtendedArgs
  1813. IR::Instr *eaInstr;
  1814. // inliner sets the dst type of the ExtendedArg to the expected arg type for the operation. The globOpt uses this info to know the type-spec target for each ExtendedArg.
  1815. eaInstr = IR::Instr::New(Js::OpCode::ExtendArg_A, callInstr->m_func);
  1816. eaInstr->SetByteCodeOffset(callInstr);
  1817. if (argIndex == inlineCallArgCount)
  1818. {
  1819. // fix callInstr
  1820. eaLinkOpnd = IR::RegOpnd::New(TyVar, callInstr->m_func);
  1821. eaLinkOpnd->GetStackSym()->m_isInlinedArgSlot = true;
  1822. eaLinkOpnd->GetStackSym()->m_allocated = true;
  1823. Assert(callInstr->GetSrc1() == nullptr && callInstr->GetSrc2() == nullptr);
  1824. callInstr->SetSrc1(eaLinkOpnd);
  1825. }
  1826. Assert(eaLinkOpnd);
  1827. eaInstr->SetDst(eaLinkOpnd);
  1828. eaInstr->SetSrc1(argInstr->GetSrc1());
  1829. // insert link opnd, except for first ExtendedArg
  1830. if (argIndex > 1)
  1831. {
  1832. eaInstr->SetSrc2(IR::RegOpnd::New(TyVar, callInstr->m_func));
  1833. eaLinkOpnd = eaInstr->GetSrc2();
  1834. eaLinkOpnd->GetStackSym()->m_isInlinedArgSlot = true;
  1835. eaLinkOpnd->GetStackSym()->m_allocated = true;
  1836. }
  1837. eaInstr->GetDst()->SetValueType(simdFuncSignature.args[argIndex - 1]);
  1838. eaInsertInstr->InsertBefore(eaInstr);
  1839. eaInsertInstr = eaInstr;
  1840. }
  1841. else
  1842. {
  1843. // Use parameter to the inline call to tempDst.
  1844. if (argIndex == 2)
  1845. {
  1846. callInstr->SetSrc2(argOpnd);
  1847. // Prevent inserting ByteCodeUses instr during globopt, as we already track the src in ArgOut.
  1848. callInstr->GetSrc2()->SetIsJITOptimizedReg(true);
  1849. }
  1850. else if (argIndex == 1)
  1851. {
  1852. callInstr->SetSrc1(argOpnd);
  1853. // Prevent inserting ByteCodeUses instr during globopt, as we already track the src in ArgOut.
  1854. callInstr->GetSrc1()->SetIsJITOptimizedReg(true);
  1855. }
  1856. }
  1857. argIndex--;
  1858. linkOpnd = argInstr->GetSrc2();
  1859. // Move the arguments next to the call.
  1860. argInstr->Move(argInsertInstr);
  1861. argInsertInstr = argInstr;
  1862. return false;
  1863. });
  1864. if(inlineCallOpCode == Js::OpCode::InlineMathImul || inlineCallOpCode == Js::OpCode::InlineMathClz32)
  1865. {
  1866. // Convert:
  1867. // s1 = InlineMathImul s2, s3
  1868. // Into:
  1869. // s4 = Or_A s2, 0
  1870. // s5 = Or_A s3, 0
  1871. // s1 = InlineMathImul s4, s5
  1872. Func *const func = callInstr->m_func;
  1873. IR::AddrOpnd *const zeroOpnd = IR::AddrOpnd::NewFromNumber(0, func, true);
  1874. IR::RegOpnd *const s4 = IR::RegOpnd::New(TyVar, func);
  1875. s4->SetIsJITOptimizedReg(true);
  1876. IR::Instr *orInstr = IR::Instr::New(Js::OpCode::Or_A, s4, callInstr->UnlinkSrc1(), zeroOpnd, func);
  1877. orInstr->SetByteCodeOffset(callInstr);
  1878. callInstr->InsertBefore(orInstr);
  1879. callInstr->SetSrc1(s4);
  1880. if (inlineCallOpCode == Js::OpCode::InlineMathImul)
  1881. {
  1882. if (callInstr->GetSrc2()->IsEqual(callInstr->GetSrc1()))
  1883. {
  1884. callInstr->ReplaceSrc2(s4);
  1885. }
  1886. else
  1887. {
  1888. IR::RegOpnd *const s5 = IR::RegOpnd::New(TyVar, func);
  1889. s5->SetIsJITOptimizedReg(true);
  1890. orInstr = IR::Instr::New(Js::OpCode::Or_A, s5, callInstr->UnlinkSrc2(), zeroOpnd, func);
  1891. orInstr->SetByteCodeOffset(callInstr);
  1892. callInstr->InsertBefore(orInstr);
  1893. callInstr->SetSrc2(s5);
  1894. }
  1895. }
  1896. }
  1897. if(OpCodeAttr::BailOutRec(inlineCallOpCode))
  1898. {
  1899. inlineBuiltInEndInstr->InsertBefore(byteCodeUsesInstr);
  1900. }
  1901. Assert(linkOpnd->AsRegOpnd()->m_sym->GetInstrDef()->m_opcode == Js::OpCode::StartCall);
  1902. Assert(linkOpnd->AsRegOpnd()->m_sym->GetInstrDef()->GetArgOutCount(/*getInterpreterArgOutCount*/ false) == actualCount);
  1903. // Mark the StartCall's dst as an inlined arg slot as well so we know this is an inlined start call
  1904. // and not adjust the stack height on x86
  1905. linkOpnd->AsRegOpnd()->m_sym->m_isInlinedArgSlot = true;
  1906. if(OpCodeAttr::BailOutRec(inlineCallOpCode))
  1907. {
  1908. callInstr = callInstr->ConvertToBailOutInstr(callInstr, IR::BailOutOnFloor);
  1909. }
  1910. }
  1911. return inlineBuiltInEndInstr->m_next;
  1912. }
  1913. IR::Instr* Inline::InsertInlineeBuiltInStartEndTags(IR::Instr* callInstr, uint actualCount, IR::Instr** builtinStartInstr)
  1914. {
  1915. IR::Instr* inlineBuiltInStartInstr = IR::Instr::New(Js::OpCode::InlineBuiltInStart, callInstr->m_func);
  1916. inlineBuiltInStartInstr->SetSrc1(callInstr->GetSrc1());
  1917. inlineBuiltInStartInstr->SetSrc2(callInstr->GetSrc2());
  1918. inlineBuiltInStartInstr->SetByteCodeOffset(callInstr);
  1919. callInstr->InsertBefore(inlineBuiltInStartInstr);
  1920. if (builtinStartInstr)
  1921. {
  1922. *builtinStartInstr = inlineBuiltInStartInstr;
  1923. }
  1924. IR::Instr* inlineBuiltInEndInstr = IR::Instr::New(Js::OpCode::InlineBuiltInEnd, callInstr->m_func);
  1925. inlineBuiltInEndInstr->SetSrc1(IR::IntConstOpnd::New(actualCount, TyInt32, callInstr->m_func));
  1926. inlineBuiltInEndInstr->SetSrc2(callInstr->GetSrc2());
  1927. inlineBuiltInEndInstr->SetByteCodeOffset(callInstr->GetNextRealInstrOrLabel());
  1928. callInstr->InsertAfter(inlineBuiltInEndInstr);
  1929. return inlineBuiltInEndInstr;
  1930. }
  1931. IR::Instr* Inline::GetDefInstr(IR::Opnd* linkOpnd)
  1932. {
  1933. StackSym *linkSym = linkOpnd->AsSymOpnd()->m_sym->AsStackSym();
  1934. Assert(linkSym->m_isSingleDef);
  1935. Assert(linkSym->IsArgSlotSym());
  1936. return linkSym->m_instrDef;
  1937. }
  1938. IR::Instr* Inline::InlineApply(IR::Instr *callInstr, Js::FunctionInfo *funcInfo, const Js::FunctionCodeGenJitTimeData* inlinerData, const StackSym *symCallerThis, bool* pIsInlined, uint callSiteId, uint recursiveInlineDepth)
  1939. {
  1940. // We may still decide not to inline.
  1941. *pIsInlined = false;
  1942. Js::BuiltinFunction builtInId = Js::JavascriptLibrary::GetBuiltInForFuncInfo(funcInfo, callInstr->m_func->GetScriptContext());
  1943. const Js::FunctionCodeGenJitTimeData * inlineeData = nullptr;
  1944. IR::SymOpnd* linkOpnd = callInstr->GetSrc2()->AsSymOpnd();
  1945. StackSym *arrayArgsym = linkOpnd->AsSymOpnd()->m_sym->AsStackSym();
  1946. Assert(arrayArgsym->m_isSingleDef);
  1947. Assert(arrayArgsym->IsArgSlotSym());
  1948. IR::Instr* arrayArgInstr = arrayArgsym->m_instrDef;
  1949. IR::Opnd *arrayArgOpnd = arrayArgInstr->GetSrc1();
  1950. // if isArrayOpndArgumentsObject == false, the array opnd can still be the arguments object; we just can't say that for sure
  1951. bool isArrayOpndArgumentsObject = arrayArgOpnd->IsArgumentsObject();
  1952. IR::Instr * returnInstr = nullptr;
  1953. if (!PHASE_OFF(Js::InlineApplyTargetPhase, this->topFunc))
  1954. {
  1955. if (isArrayOpndArgumentsObject && InlineApplyTarget(callInstr, inlinerData, &inlineeData, funcInfo, symCallerThis, &returnInstr, recursiveInlineDepth))
  1956. {
  1957. *pIsInlined = true;
  1958. Assert(returnInstr);
  1959. return returnInstr;
  1960. }
  1961. }
  1962. #if defined(ENABLE_DEBUG_CONFIG_OPTIONS)
  1963. InliningDecider::TraceInlining(inlinerData->GetFunctionBody(), Js::JavascriptLibrary::GetNameForBuiltIn(builtInId),
  1964. nullptr, 0, this->topFunc->m_workItem->GetFunctionBody(), 0, nullptr, callSiteId, builtInId);
  1965. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  1966. #endif
  1967. if (!isArrayOpndArgumentsObject)
  1968. {
  1969. if (inlineeData && inlineeData->GetFunctionBody() == nullptr)
  1970. {
  1971. *pIsInlined = true;
  1972. Assert((inlineeData->GetFunctionInfo()->GetAttributes() & Js::FunctionInfo::Attributes::BuiltInInlinableAsLdFldInlinee) != 0);
  1973. return InlineApplyWithArray(callInstr, funcInfo, Js::JavascriptLibrary::GetBuiltInForFuncInfo(inlineeData->GetFunctionInfo(), callInstr->m_func->GetScriptContext()));
  1974. }
  1975. else
  1976. {
  1977. INLINE_TESTTRACE(L"INLINING: Skip Inline: Supporting inlining func.apply(this, array) or func.apply(this, arguments) with formals in the parent function only when func is a built-in inlineable as apply target \tCaller: %s (%s)\n",
  1978. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer));
  1979. return callInstr;
  1980. }
  1981. }
  1982. *pIsInlined = true;
  1983. return InlineApplyWithArgumentsObject(callInstr, arrayArgInstr, funcInfo);
  1984. }
  1985. IR::Instr * Inline::InlineApplyWithArgumentsObject(IR::Instr * callInstr, IR::Instr * argsObjectArgInstr, Js::FunctionInfo * funcInfo)
  1986. {
  1987. IR::Instr* ldHeapArguments = argsObjectArgInstr->GetSrc1()->GetStackSym()->GetInstrDef();
  1988. IR::RegOpnd* argumentsObj = IR::RegOpnd::New(TyVar, callInstr->m_func);
  1989. IR::Instr *assignInstr = IR::Instr::New(Js::OpCode::LdArgumentsFromStack, argumentsObj, ldHeapArguments->GetDst(), callInstr->m_func);
  1990. assignInstr->SetByteCodeOffset(argsObjectArgInstr);
  1991. argsObjectArgInstr->InsertBefore(assignInstr);
  1992. argsObjectArgInstr->ReplaceSrc1(ldHeapArguments->GetDst());
  1993. IR::Opnd * linkOpnd = callInstr->GetSrc2()->AsSymOpnd();
  1994. IR::Instr * explicitThisArgOut = nullptr;
  1995. IR::Instr * implicitThisArgOut = nullptr;
  1996. callInstr->IterateArgInstrs([&](IR::Instr* argInstr) {
  1997. explicitThisArgOut = implicitThisArgOut;
  1998. implicitThisArgOut = argInstr;
  1999. linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->m_isInlinedArgSlot = true;
  2000. linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->m_allocated = true;
  2001. ConvertToInlineBuiltInArgOut(argInstr);
  2002. linkOpnd = argInstr->GetSrc2();
  2003. return false;
  2004. });
  2005. // BailOnNotEqual s4.var ---------------New additional BAILOUT if not stack args or actuals exceed 16 at runtime.
  2006. // Bailout: #004e (BailOutOnInlineFunction)
  2007. // linkOpnd Argout_FromStackArgs s4.var
  2008. // linkOpnd1 ArgOut_A_Dynamic s3.var, linkOpnd
  2009. // CallI_Dynamic s6.var, linkOpnd1
  2010. IR::Instr* bailOutOnNotStackArgs;
  2011. IR::Instr* bailOutOnNotStackArgsInsertionPoint = callInstr;
  2012. // Save off the call target operand (function object) so we can extend its lifetime as needed, even if
  2013. // the call instruction gets transformed to CallIFixed.
  2014. StackSym* originalCallTargetStackSym = callInstr->GetSrc1()->GetStackSym();
  2015. // If we optimized the call instruction for a fixed function we will have bailed out earlier if the function
  2016. // wasn't what we expected or was not a function at all. However, we must still check and bail out on heap arguments.
  2017. bool safeThis = false;
  2018. if (TryOptimizeCallInstrWithFixedMethod(callInstr, funcInfo, false /*isPolymorphic*/, true /*isBuiltIn*/, false /*isCtor*/, true /*isInlined*/, safeThis /*unused here*/))
  2019. {
  2020. Assert(callInstr->m_opcode == Js::OpCode::CallIFixed);
  2021. bailOutOnNotStackArgs = IR::BailOutInstr::New(Js::OpCode::BailOnNotStackArgs, IR::BailOutOnInlineFunction, callInstr, callInstr->m_func);
  2022. }
  2023. else
  2024. {
  2025. IR::Instr *primaryBailoutInstr = PrepareInsertionPoint(callInstr, funcInfo, callInstr);
  2026. bailOutOnNotStackArgs = IR::BailOutInstr::New(Js::OpCode::BailOnNotStackArgs, IR::BailOutOnInlineFunction, primaryBailoutInstr->GetBailOutInfo(), callInstr->m_func);
  2027. bailOutOnNotStackArgsInsertionPoint = primaryBailoutInstr;
  2028. }
  2029. bailOutOnNotStackArgs->SetSrc1(argumentsObj);
  2030. bailOutOnNotStackArgs->SetSrc2(IR::AddrOpnd::NewNull(callInstr->m_func));
  2031. bailOutOnNotStackArgsInsertionPoint->InsertBefore(bailOutOnNotStackArgs);
  2032. // If we optimized the call instruction for a fixed function, we must extend the function object's lifetime until after
  2033. // the bailout on non-stack arguments.
  2034. if (callInstr->m_opcode == Js::OpCode::CallIFixed)
  2035. {
  2036. IR::ByteCodeUsesInstr * useCallTargetInstr = IR::ByteCodeUsesInstr::New(callInstr, originalCallTargetStackSym->m_id);
  2037. callInstr->InsertBefore(useCallTargetInstr);
  2038. }
  2039. // Optimize .init.apply(this, arguments);
  2040. IR::Instr* builtInStartInstr;
  2041. InsertInlineeBuiltInStartEndTags(callInstr, 3, &builtInStartInstr); //3 args (implicit this + explicit this + arguments = 3)
  2042. // Move argouts close to call
  2043. IR::Instr* argInsertInstr = builtInStartInstr;
  2044. builtInStartInstr->IterateArgInstrs([&](IR::Instr* argInstr) {
  2045. argInstr->Move(argInsertInstr);
  2046. argInsertInstr = argInstr;
  2047. return false;
  2048. });
  2049. IR::Instr *startCall = IR::Instr::New(Js::OpCode::StartCall, callInstr->m_func);
  2050. startCall->SetDst(IR::RegOpnd::New(TyVar, callInstr->m_func));
  2051. startCall->SetSrc1(IR::IntConstOpnd::New(2, TyInt32, callInstr->m_func)); //2 args (this pointer & ArgOut_A_From_StackArgs for this direct call to init
  2052. callInstr->InsertBefore(startCall);
  2053. StackSym *symDst = callInstr->m_func->m_symTable->GetArgSlotSym((uint16)(2));
  2054. IR::SymOpnd* linkOpnd1 = IR::SymOpnd::New(symDst, 0, TyMachPtr, callInstr->m_func);
  2055. symDst = callInstr->m_func->m_symTable->GetArgSlotSym((uint16)(1));
  2056. IR::Opnd *linkOpnd2 = IR::SymOpnd::New(symDst, 0, TyMachPtr, callInstr->m_func);
  2057. // This keeps the stack args alive for bailout to recover
  2058. IR::Instr* argout = IR::Instr::New(Js::OpCode::ArgOut_A_FromStackArgs, linkOpnd1, ldHeapArguments->GetDst(), startCall->GetDst(), callInstr->m_func);
  2059. callInstr->InsertBefore(argout);
  2060. callInstr->ReplaceSrc1(implicitThisArgOut->GetSrc1());
  2061. callInstr->ReplaceSrc2(linkOpnd2);
  2062. callInstr->m_opcode = Js::OpCode::CallIDynamic;
  2063. argout = IR::Instr::New(Js::OpCode::ArgOut_A_Dynamic, linkOpnd2, explicitThisArgOut->GetSrc1(), linkOpnd1, callInstr->m_func); // push explicit this as this pointer
  2064. callInstr->InsertBefore(argout);
  2065. return callInstr;
  2066. }
  2067. IR::Instr * Inline::InlineApplyWithArray(IR::Instr * callInstr, Js::FunctionInfo * funcInfo, Js::BuiltinFunction builtInId)
  2068. {
  2069. IR::Opnd * linkOpnd = callInstr->GetSrc2()->AsSymOpnd();
  2070. IR::Instr * argInsertInstr = callInstr;
  2071. IR::Instr * arrayArgOut = nullptr;
  2072. IR::Instr * explicitThisArgOut = nullptr;
  2073. IR::Instr * implicitThisArgOut = nullptr;
  2074. callInstr->IterateArgInstrs([&](IR::Instr* argInstr) {
  2075. arrayArgOut = explicitThisArgOut;
  2076. explicitThisArgOut = implicitThisArgOut;
  2077. implicitThisArgOut = argInstr;
  2078. linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->m_isInlinedArgSlot = true;
  2079. linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->m_allocated = true;
  2080. ConvertToInlineBuiltInArgOut(argInstr);
  2081. argInstr->Move(argInsertInstr);
  2082. argInsertInstr = argInstr;
  2083. linkOpnd = argInstr->GetSrc2();
  2084. return false;
  2085. });
  2086. StackSym* originalCallTargetStackSym = callInstr->GetSrc1()->GetStackSym();
  2087. // If we optimized the call instruction for a fixed function we will have bailed out earlier if the function
  2088. // wasn't what we expected or was not a function at all. However, we must still check and bail out on heap arguments.
  2089. bool safeThis = false;
  2090. if (TryOptimizeCallInstrWithFixedMethod(callInstr, funcInfo, false /*isPolymorphic*/, true /*isBuiltIn*/, false /*isCtor*/, true /*isInlined*/, safeThis /*unused here*/))
  2091. {
  2092. Assert(callInstr->m_opcode == Js::OpCode::CallIFixed);
  2093. }
  2094. else
  2095. {
  2096. PrepareInsertionPoint(callInstr, funcInfo, callInstr);
  2097. }
  2098. // If we optimized the call instruction for a fixed function, we must extend the function object's lifetime until after the last bailout before the call.
  2099. if (callInstr->m_opcode == Js::OpCode::CallIFixed)
  2100. {
  2101. IR::ByteCodeUsesInstr * useCallTargetInstr = IR::ByteCodeUsesInstr::New(callInstr, originalCallTargetStackSym->m_id);
  2102. callInstr->InsertBefore(useCallTargetInstr);
  2103. }
  2104. IR::Instr* builtInEndInstr = InsertInlineeBuiltInStartEndTags(callInstr, 3); // 3 args (implicit this + explicit this + array = 3)
  2105. builtInEndInstr->m_opcode = Js::OpCode::InlineNonTrackingBuiltInEnd; // We will call EndTrackCall when we see CallDirect for reasons explained in GlobOpt::TrackCalls
  2106. IR::Instr * startCall = IR::Instr::New(Js::OpCode::StartCall,
  2107. IR::RegOpnd::New(TyVar, callInstr->m_func),
  2108. IR::IntConstOpnd::New(2, TyInt32, callInstr->m_func),
  2109. callInstr->m_func);
  2110. callInstr->InsertBefore(startCall);
  2111. StackSym * sym = callInstr->m_func->m_symTable->GetArgSlotSym((uint16)(1));
  2112. linkOpnd = IR::SymOpnd::New(sym, 0, TyMachPtr, callInstr->m_func);
  2113. IR::Instr * argOut = IR::Instr::New(Js::OpCode::ArgOut_A, linkOpnd, explicitThisArgOut->GetSrc1(), startCall->GetDst(), callInstr->m_func);
  2114. callInstr->InsertBefore(argOut);
  2115. sym = callInstr->m_func->m_symTable->GetArgSlotSym((uint16)(2));
  2116. linkOpnd = IR::SymOpnd::New(sym, 0, TyMachPtr, callInstr->m_func);
  2117. argOut = IR::Instr::New(Js::OpCode::ArgOut_A, linkOpnd, arrayArgOut->GetSrc1(), argOut->GetDst(), callInstr->m_func);
  2118. callInstr->InsertBefore(argOut);
  2119. linkOpnd = IR::SymOpnd::New(callInstr->m_func->m_symTable->GetArgSlotSym((uint16)(1)), 0, TyMachPtr, callInstr->m_func);
  2120. argOut = IR::Instr::New(Js::OpCode::ArgOut_A_InlineSpecialized, linkOpnd, implicitThisArgOut->GetSrc1(), argOut->GetDst(), callInstr->m_func);
  2121. callInstr->InsertBefore(argOut);
  2122. IR::HelperCallOpnd * helperCallOpnd = nullptr;
  2123. switch (builtInId)
  2124. {
  2125. case Js::BuiltinFunction::Math_Max:
  2126. helperCallOpnd = IR::HelperCallOpnd::New(IR::HelperOp_MaxInAnArray, callInstr->m_func);
  2127. break;
  2128. case Js::BuiltinFunction::Math_Min:
  2129. helperCallOpnd = IR::HelperCallOpnd::New(IR::HelperOp_MinInAnArray, callInstr->m_func);
  2130. break;
  2131. default:
  2132. Assert(false);
  2133. __assume(UNREACHED);
  2134. }
  2135. callInstr->m_opcode = Js::OpCode::CallDirect;
  2136. callInstr->ReplaceSrc1(helperCallOpnd);
  2137. callInstr->ReplaceSrc2(argOut->GetDst());
  2138. return callInstr;
  2139. }
  2140. bool Inline::InlineApplyTarget(IR::Instr *callInstr, const Js::FunctionCodeGenJitTimeData* inlinerData, const Js::FunctionCodeGenJitTimeData** pInlineeData, Js::FunctionInfo *applyFuncInfo,
  2141. const StackSym *symCallerThis, IR::Instr ** returnInstr, uint recursiveInlineDepth)
  2142. {
  2143. #if ENABLE_DEBUG_CONFIG_OPTIONS
  2144. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  2145. wchar_t debugStringBuffer2[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  2146. #endif
  2147. if (this->isApplyTargetInliningInProgress)
  2148. {
  2149. INLINE_TESTTRACE(L"INLINING: Skip Inline: Skipping apply target inlining, Recursive apply inlining is not supported \tCaller: %s\t(%s) \tTop Func:%s\t(%s)\n", inlinerData->GetFunctionBody()->GetDisplayName(),
  2150. inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer), this->topFunc->GetJnFunction()->GetDisplayName(), this->topFunc->GetJnFunction()->GetDebugNumberSet(debugStringBuffer2));
  2151. return false;
  2152. }
  2153. // Begin inlining apply target
  2154. IR::Opnd* applyOpnd = callInstr->GetSrc1();
  2155. Assert(applyOpnd->IsRegOpnd());
  2156. StackSym* applySym = applyOpnd->AsRegOpnd()->m_sym->AsStackSym();
  2157. if (!applySym->IsSingleDef())
  2158. {
  2159. return false;
  2160. }
  2161. IR::Instr* applyLdInstr = applySym->GetInstrDef();
  2162. IR::Instr* applyTargetLdInstr = applyLdInstr->m_prev;
  2163. if(applyTargetLdInstr->m_opcode != Js::OpCode::LdFldForCallApplyTarget)
  2164. {
  2165. return false;
  2166. }
  2167. IR::Opnd *applyTargetLdOpnd = applyTargetLdInstr->GetSrc1();
  2168. if (!applyTargetLdOpnd->IsSymOpnd() || !applyTargetLdOpnd->AsSymOpnd()->IsPropertySymOpnd())
  2169. {
  2170. return false;
  2171. }
  2172. const auto inlineCacheIndex = applyTargetLdOpnd->AsPropertySymOpnd()->m_inlineCacheIndex;
  2173. const auto inlineeData = inlinerData->GetLdFldInlinee(inlineCacheIndex);
  2174. if (SkipCallApplyTargetInlining_Shared(callInstr, inlinerData, inlineeData, /*isApplyTarget*/ true, /*isCallTarget*/ false))
  2175. {
  2176. *pInlineeData = inlineeData;
  2177. return false;
  2178. }
  2179. if (callInstr->m_func->IsTopFunc())
  2180. {
  2181. INLINE_TESTTRACE(L"INLINING: Skip Inline: Skipping apply target inlining in top func\tCaller: %s\t(%s) \tTop Func:%s\t(%s)\n", inlinerData->GetFunctionBody()->GetDisplayName(),
  2182. inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer), this->topFunc->GetJnFunction()->GetDisplayName(), this->topFunc->GetJnFunction()->GetDebugNumberSet(debugStringBuffer2));
  2183. return false;
  2184. }
  2185. StackSym* originalCallTargetStackSym = callInstr->GetSrc1()->GetStackSym();
  2186. bool safeThis = false;
  2187. if (!TryGetFixedMethodsForBuiltInAndTarget(callInstr, inlinerData, inlineeData, applyFuncInfo, applyLdInstr, applyTargetLdInstr, safeThis, /*isApplyTarget*/ true))
  2188. {
  2189. return false;
  2190. }
  2191. // o.foo.apply(obj, arguments)
  2192. //
  2193. // StartCall
  2194. // ArgOut_A <-- implicit "this" (foo) argout
  2195. // ArgOut_A <-- explicit "this" (obj) argout
  2196. // ArgOut_A <-- arguments object argout
  2197. // CallIFixed
  2198. IR::Instr* implicitThisArgOut = nullptr;
  2199. IR::Instr* explicitThisArgOut = nullptr;
  2200. IR::Instr* argumentsObjArgOut = nullptr;
  2201. callInstr->IterateArgInstrs([&](IR::Instr* argInstr)
  2202. {
  2203. argumentsObjArgOut = explicitThisArgOut;
  2204. explicitThisArgOut = implicitThisArgOut;
  2205. implicitThisArgOut = argInstr;
  2206. argInstr->GenerateBytecodeArgOutCapture(); // Generate BytecodeArgOutCapture here to capture the implicit "this" (to be removed) and arguments object (to be expanded) argouts,
  2207. // so that any bailout in the call sequence restores the argouts stack as the interpreter would expect it to be.
  2208. argInstr->GetDst()->AsSymOpnd()->GetStackSym()->DecrementArgSlotNum(); // We will be removing implicit "this" argout
  2209. return false;
  2210. });
  2211. if (safeThis)
  2212. {
  2213. IR::Instr * byteCodeArgOutCapture = explicitThisArgOut->GetBytecodeArgOutCapture();
  2214. Assert(byteCodeArgOutCapture->GetSrc1()->IsRegOpnd());
  2215. if (byteCodeArgOutCapture->GetSrc1()->AsRegOpnd()->GetStackSym() != symCallerThis)
  2216. {
  2217. safeThis = false;
  2218. }
  2219. }
  2220. IR::Opnd *src1 = argumentsObjArgOut->GetSrc1();
  2221. IR::Instr* ldHeapArguments = src1->AsRegOpnd()->m_sym->m_instrDef;
  2222. IR::RegOpnd* argumentsObj = IR::RegOpnd::New(TyVar, callInstr->m_func);
  2223. IR::Instr *assignInstr = IR::Instr::New(Js::OpCode::LdArgumentsFromStack, argumentsObj, ldHeapArguments->GetDst(), callInstr->m_func);
  2224. assignInstr->SetByteCodeOffset(argumentsObjArgOut);
  2225. argumentsObjArgOut->InsertBefore(assignInstr);
  2226. IR::Instr* argObjByteCodeArgoutCapture = argumentsObjArgOut->GetBytecodeArgOutCapture();
  2227. argObjByteCodeArgoutCapture->GetDst()->GetStackSym()->m_nonEscapingArgObjAlias = true;
  2228. argumentsObjArgOut->m_opcode = Js::OpCode::ArgOut_A_FromStackArgs;
  2229. Assert(implicitThisArgOut->GetSrc2()->IsRegOpnd());
  2230. IR::Instr * startCall = implicitThisArgOut->GetSrc2()->AsRegOpnd()->m_sym->AsStackSym()->GetInstrDef();
  2231. Assert(startCall->m_opcode == Js::OpCode::StartCall);
  2232. IR::Instr * bailOutOnNotStackArgs = IR::BailOutInstr::New(Js::OpCode::BailOnNotStackArgs, IR::BailOutOnInlineFunction,
  2233. callInstr, callInstr->m_func);
  2234. bailOutOnNotStackArgs->SetSrc1(argumentsObj);
  2235. bailOutOnNotStackArgs->SetSrc2(IR::AddrOpnd::NewNull(callInstr->m_func));
  2236. argumentsObjArgOut->InsertBefore(bailOutOnNotStackArgs);
  2237. IR::Instr* byteCodeArgOutUse = IR::Instr::New(Js::OpCode::BytecodeArgOutUse, callInstr->m_func);
  2238. byteCodeArgOutUse->SetSrc1(implicitThisArgOut->GetSrc1());
  2239. byteCodeArgOutUse->SetSrc2(argumentsObjArgOut->GetSrc1());
  2240. callInstr->InsertBefore(byteCodeArgOutUse);
  2241. // don't need the implicit "this" anymore
  2242. explicitThisArgOut->ReplaceSrc2(startCall->GetDst());
  2243. implicitThisArgOut->Remove();
  2244. startCall->SetSrc2(IR::IntConstOpnd::New(startCall->GetArgOutCount(/*getInterpreterArgOutCount*/ false), TyUint32, startCall->m_func));
  2245. startCall->GetSrc1()->AsIntConstOpnd()->IncrValue(-1); // update the count of argouts as seen by JIT, in the start call instruction
  2246. *returnInstr = InlineCallApplyTarget_Shared(callInstr, originalCallTargetStackSym, inlineeData->GetFunctionInfo(), inlineeData, inlineCacheIndex,
  2247. safeThis, /*isApplyTarget*/ true, /*isCallTarget*/ false, recursiveInlineDepth);
  2248. return true;
  2249. }
  2250. IR::Instr *
  2251. Inline::InlineCallApplyTarget_Shared(IR::Instr *callInstr, StackSym* originalCallTargetStackSym, Js::FunctionInfo *funcInfo, const Js::FunctionCodeGenJitTimeData *const inlineeData,
  2252. uint inlineCacheIndex, bool safeThis, bool isApplyTarget, bool isCallTarget, uint recursiveInlineDepth)
  2253. {
  2254. Assert(isApplyTarget ^ isCallTarget);
  2255. // function body
  2256. Js::FunctionBody* funcBody = funcInfo->GetFunctionBody();
  2257. // returnValueOpnd
  2258. IR::RegOpnd * returnValueOpnd;
  2259. Js::RegSlot returnRegSlot;
  2260. if (callInstr->GetDst())
  2261. {
  2262. returnValueOpnd = callInstr->UnlinkDst()->AsRegOpnd();
  2263. returnRegSlot = returnValueOpnd->m_sym->GetByteCodeRegSlot();
  2264. }
  2265. else
  2266. {
  2267. returnValueOpnd = nullptr;
  2268. returnRegSlot = Js::Constants::NoRegister;
  2269. }
  2270. Assert(callInstr->IsProfiledInstr());
  2271. Js::ProfileId callSiteId = static_cast<Js::ProfileId>(callInstr->AsProfiledInstr()->u.profileId);
  2272. Assert(callSiteId >= 0);
  2273. // inlinee
  2274. Js::ProxyEntryPointInfo *defaultEntryPointInfo = funcBody->GetDefaultEntryPointInfo();
  2275. Assert(defaultEntryPointInfo->IsFunctionEntryPointInfo());
  2276. Js::FunctionEntryPointInfo *functionEntryPointInfo = static_cast<Js::FunctionEntryPointInfo*>(defaultEntryPointInfo);
  2277. JsFunctionCodeGen *workItem = JitAnew(this->topFunc->m_alloc, JsFunctionCodeGen,
  2278. funcBody->GetScriptContext()->GetNativeCodeGenerator(), funcBody, functionEntryPointInfo, this->topFunc->IsJitInDebugMode());
  2279. workItem->SetRecyclableData(JitAnew(this->topFunc->m_alloc, Js::CodeGenRecyclableData, inlineeData));
  2280. workItem->SetJitMode(this->topFunc->m_workItem->GetJitMode());
  2281. const auto profileInfo =
  2282. JitAnew(
  2283. this->topFunc->m_alloc,
  2284. Js::ReadOnlyDynamicProfileInfo,
  2285. funcBody->HasDynamicProfileInfo() ? funcBody->GetAnyDynamicProfileInfo() : nullptr,
  2286. this->topFunc->IsBackgroundJIT() ? this->topFunc->m_alloc : nullptr);
  2287. Js::EntryPointPolymorphicInlineCacheInfo * entryPointPolymorphicInlineCacheInfo = this->topFunc->m_workItem->GetEntryPoint()->GetPolymorphicInlineCacheInfo();
  2288. Func *inlinee = JitAnew(this->topFunc->m_alloc,
  2289. Func,
  2290. this->topFunc->m_alloc,
  2291. workItem,
  2292. callInstr->m_func->m_runtimeData ?
  2293. callInstr->m_func->m_runtimeData->GetLdFldInlinee(inlineCacheIndex) :
  2294. this->topFunc->GetJnFunction()->GetLdFldInlineeCodeGenRuntimeData(inlineCacheIndex),
  2295. entryPointPolymorphicInlineCacheInfo ? entryPointPolymorphicInlineCacheInfo->GetInlineeInfo(funcBody) : nullptr,
  2296. this->topFunc->GetCodeGenAllocators(),
  2297. this->topFunc->GetNumberAllocator(),
  2298. profileInfo,
  2299. this->topFunc->GetCodeGenProfiler(),
  2300. this->topFunc->IsBackgroundJIT(),
  2301. callInstr->m_func,
  2302. callInstr->m_next->GetByteCodeOffset(),
  2303. returnRegSlot,
  2304. false,
  2305. callSiteId,
  2306. false);
  2307. // instrNext
  2308. IR::Instr* instrNext = callInstr->m_next;
  2309. return InlineFunctionCommon(callInstr, originalCallTargetStackSym, funcBody, inlinee, instrNext, returnValueOpnd, callInstr, nullptr, recursiveInlineDepth, safeThis, isApplyTarget);
  2310. }
  2311. IR::Opnd *
  2312. Inline::ConvertToInlineBuiltInArgOut(IR::Instr * argInstr)
  2313. {
  2314. argInstr->m_opcode = Js::OpCode::ArgOut_A_InlineBuiltIn;
  2315. argInstr->GenerateBytecodeArgOutCapture();
  2316. return argInstr->GetSrc1();
  2317. }
  2318. IR::Instr*
  2319. Inline::InlineCall(IR::Instr *callInstr, Js::FunctionInfo *funcInfo, const Js::FunctionCodeGenJitTimeData* inlinerData, const StackSym *symCallerThis, bool* pIsInlined, uint callSiteId, uint recursiveInlineDepth)
  2320. {
  2321. Js::BuiltinFunction builtInId = Js::JavascriptLibrary::GetBuiltInForFuncInfo(funcInfo, callInstr->m_func->GetScriptContext());
  2322. Func *func = callInstr->m_func;
  2323. *pIsInlined = false;
  2324. if (PHASE_OFF(Js::InlineCallPhase, this->topFunc) || PHASE_OFF(Js::InlineCallPhase, func->GetJnFunction())
  2325. || !this->topFunc->GetJnFunction()->GetInParamsCount())
  2326. {
  2327. return callInstr;
  2328. }
  2329. // Convert all the current ARG_OUT to ArgOut_A_InlineBuiltIn
  2330. IR::Opnd *linkOpnd = callInstr->GetSrc2();
  2331. if (!GetDefInstr(linkOpnd)->GetSrc2()->IsSymOpnd())
  2332. {
  2333. // There is no benefit of inlining.call() with no arguments.
  2334. return callInstr;
  2335. }
  2336. *pIsInlined = true;
  2337. const Js::FunctionCodeGenJitTimeData * inlineeData = nullptr;
  2338. IR::Instr * returnInstr = nullptr;
  2339. if (!PHASE_OFF(Js::InlineCallTargetPhase, this->topFunc))
  2340. {
  2341. if (InlineCallTarget(callInstr, inlinerData, &inlineeData, funcInfo, symCallerThis, &returnInstr, recursiveInlineDepth))
  2342. {
  2343. Assert(returnInstr);
  2344. return returnInstr;
  2345. }
  2346. }
  2347. #if defined(ENABLE_DEBUG_CONFIG_OPTIONS)
  2348. InliningDecider::TraceInlining(inlinerData->GetFunctionBody(), Js::JavascriptLibrary::GetNameForBuiltIn(builtInId),
  2349. nullptr, 0, this->topFunc->m_workItem->GetFunctionBody(), 0, nullptr, callSiteId, builtInId);
  2350. #endif
  2351. uint actualCount = 0;
  2352. Assert(linkOpnd->IsSymOpnd());
  2353. // We are trying to optimize this.superConstructor.call(this, a, b,c);
  2354. // argImplicitInstr represents this.superConstructor which we need to call directly.
  2355. IR::Instr *argImplicitInstr;
  2356. IR::Instr* argInsertInstr = callInstr;
  2357. callInstr->IterateArgInstrs([&](IR::Instr* argInstr) {
  2358. argImplicitInstr = argInstr;
  2359. ++actualCount;
  2360. linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->m_isInlinedArgSlot = true;
  2361. linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->m_allocated = true;
  2362. ConvertToInlineBuiltInArgOut(argInstr);
  2363. // Move the arguments next to the call.
  2364. argInstr->Move(argInsertInstr);
  2365. argInsertInstr = argInstr;
  2366. linkOpnd = argInstr->GetSrc2();
  2367. return false;
  2368. });
  2369. linkOpnd->AsRegOpnd()->m_sym->m_isInlinedArgSlot = true;
  2370. IR::SymOpnd* orgLinkOpnd = callInstr->GetSrc2()->AsSymOpnd();
  2371. // Save off the call target operand (function object) so we can extend its lifetime as needed, even if
  2372. // the call instruction gets transformed to CallIFixed.
  2373. StackSym* originalCallTargetStackSym = callInstr->GetSrc1()->GetStackSym();
  2374. bool safeThis = false;
  2375. if (!TryOptimizeCallInstrWithFixedMethod(callInstr, funcInfo, false /*isPolymorphic*/, true /*isBuiltIn*/, false /*isCtor*/, true /*isInlined*/, safeThis))
  2376. {
  2377. PrepareInsertionPoint(callInstr, funcInfo, callInstr);
  2378. }
  2379. else
  2380. {
  2381. Assert(callInstr->m_opcode == Js::OpCode::CallIFixed);
  2382. // If we optimized the call instruction for a fixed function, we must extend the function object's lifetime until after
  2383. // the bailout on non-stack arguments.
  2384. IR::ByteCodeUsesInstr * useCallTargetInstr = IR::ByteCodeUsesInstr::New(callInstr, originalCallTargetStackSym->m_id);
  2385. callInstr->InsertBefore(useCallTargetInstr);
  2386. }
  2387. InsertInlineeBuiltInStartEndTags(callInstr, actualCount);
  2388. uint actualCountToInlinedCall = actualCount - 1;
  2389. IR::Instr *startCall = IR::Instr::New(Js::OpCode::StartCall, func);
  2390. startCall->SetDst(IR::RegOpnd::New(TyVar, func));
  2391. startCall->SetSrc1(IR::IntConstOpnd::New(actualCountToInlinedCall, TyInt32, func)); // New call will have one less parameter.
  2392. callInstr->InsertBefore(startCall);
  2393. callInstr->ReplaceSrc1(argImplicitInstr->GetSrc1());
  2394. callInstr->UnlinkSrc2();
  2395. callInstr->m_opcode = Js::OpCode::CallI;
  2396. IR::Instr* insertBeforeInstr = callInstr;
  2397. IR::Instr* clonedArgout = nullptr;
  2398. IR::Instr* orgArgout = nullptr;
  2399. for (uint i = actualCountToInlinedCall ; i > 0; i--)
  2400. {
  2401. orgArgout = GetDefInstr(orgLinkOpnd);
  2402. orgLinkOpnd = orgArgout->GetSrc2()->AsSymOpnd();
  2403. IR::Opnd *orgSrc1 = orgArgout->GetSrc1();
  2404. // Change ArgOut to use temp as src1.
  2405. StackSym * stackSym = StackSym::New(orgSrc1->GetStackSym()->GetType(), argImplicitInstr->m_func);
  2406. IR::Opnd* tempDst = IR::RegOpnd::New(stackSym, orgSrc1->GetType(), argImplicitInstr->m_func);
  2407. IR::Instr *assignInstr = IR::Instr::New(Js::OpCode::Ld_A, tempDst, orgSrc1, argImplicitInstr->m_func);
  2408. assignInstr->SetByteCodeOffset(orgArgout);
  2409. tempDst->SetIsJITOptimizedReg(true);
  2410. orgArgout->InsertBefore(assignInstr);
  2411. StackSym *symDst = callInstr->m_func->m_symTable->GetArgSlotSym((uint16)(i));
  2412. IR::SymOpnd* newLinkOpnd = IR::SymOpnd::New(symDst, 0, TyMachPtr, func);
  2413. clonedArgout = IR::Instr::New(Js::OpCode::ArgOut_A, newLinkOpnd, tempDst, func);
  2414. insertBeforeInstr->SetSrc2(newLinkOpnd);
  2415. insertBeforeInstr->InsertBefore(clonedArgout);
  2416. insertBeforeInstr = clonedArgout;
  2417. }
  2418. clonedArgout->SetSrc2(startCall->GetDst());
  2419. Assert(GetDefInstr(orgLinkOpnd) == argImplicitInstr);
  2420. return callInstr;
  2421. }
  2422. bool
  2423. Inline::InlineCallTarget(IR::Instr *callInstr, const Js::FunctionCodeGenJitTimeData* inlinerData, const Js::FunctionCodeGenJitTimeData** pInlineeData, Js::FunctionInfo *callFuncInfo,
  2424. const StackSym *symCallerThis, IR::Instr ** returnInstr, uint recursiveInlineDepth)
  2425. {
  2426. IR::Opnd* src1 = callInstr->GetSrc1();
  2427. Assert(src1->IsRegOpnd());
  2428. StackSym* sym = src1->AsRegOpnd()->GetStackSym();
  2429. if (!sym->IsSingleDef())
  2430. {
  2431. return false;
  2432. }
  2433. IR::Instr* callLdInstr = sym->GetInstrDef();
  2434. Assert(callLdInstr);
  2435. IR::Instr* callTargetLdInstr = callLdInstr->m_prev;
  2436. if (callTargetLdInstr->m_opcode != Js::OpCode::LdFldForCallApplyTarget)
  2437. {
  2438. return false;
  2439. }
  2440. IR::Opnd* callTargetLdOpnd = callTargetLdInstr->GetSrc1();
  2441. if (!callTargetLdOpnd->IsSymOpnd() || !callTargetLdOpnd->AsSymOpnd()->IsPropertySymOpnd())
  2442. {
  2443. return false;
  2444. }
  2445. const auto inlineCacheIndex = callTargetLdOpnd->AsPropertySymOpnd()->m_inlineCacheIndex;
  2446. const auto inlineeData = inlinerData->GetLdFldInlinee(inlineCacheIndex);
  2447. if (SkipCallApplyTargetInlining_Shared(callInstr, inlinerData, inlineeData, /*isApplyTarget*/ false, /*isCallTarget*/ true))
  2448. {
  2449. *pInlineeData = inlineeData;
  2450. return false;
  2451. }
  2452. StackSym* originalCallTargetStackSym = callInstr->GetSrc1()->GetStackSym();
  2453. bool safeThis = false;
  2454. if (!TryGetFixedMethodsForBuiltInAndTarget(callInstr, inlinerData, inlineeData, callFuncInfo, callLdInstr, callTargetLdInstr, safeThis, /*isApplyTarget*/ false))
  2455. {
  2456. return false;
  2457. }
  2458. IR::Instr* implicitThisArgOut = nullptr;
  2459. IR::Instr* explicitThisArgOut = nullptr;
  2460. callInstr->IterateArgInstrs([&] (IR::Instr* argInstr)
  2461. {
  2462. explicitThisArgOut = implicitThisArgOut;
  2463. implicitThisArgOut = argInstr;
  2464. argInstr->GenerateBytecodeArgOutCapture(); // Generate BytecodeArgOutCapture here to capture the implicit "this" argout (which will be removed) as well,
  2465. // so that any bailout in the call sequence restores the argouts stack as the interpreter would expect it to be.
  2466. argInstr->GetDst()->AsSymOpnd()->GetStackSym()->DecrementArgSlotNum(); // We will be removing implicit "this" argout
  2467. return false;
  2468. });
  2469. Assert(explicitThisArgOut);
  2470. Assert(explicitThisArgOut->HasByteCodeArgOutCapture());
  2471. if (safeThis)
  2472. {
  2473. IR::Instr * byteCodeArgOutCapture = explicitThisArgOut->GetBytecodeArgOutCapture();
  2474. Assert(byteCodeArgOutCapture->GetSrc1()->IsRegOpnd());
  2475. if (byteCodeArgOutCapture->GetSrc1()->AsRegOpnd()->GetStackSym() != symCallerThis)
  2476. {
  2477. safeThis = false;
  2478. }
  2479. }
  2480. IR::Opnd* linkOpnd = implicitThisArgOut->GetSrc2();
  2481. Assert(linkOpnd->IsRegOpnd() && linkOpnd->AsRegOpnd()->GetStackSym()->IsSingleDef());
  2482. Assert(linkOpnd->AsRegOpnd()->GetStackSym()->GetInstrDef()->m_opcode == Js::OpCode::StartCall);
  2483. IR::Instr* startCall = linkOpnd->AsRegOpnd()->GetStackSym()->GetInstrDef();
  2484. explicitThisArgOut->ReplaceSrc2(startCall->GetDst());
  2485. IR::Instr * bytecodeArgOutUse = IR::Instr::New(Js::OpCode::BytecodeArgOutUse, callInstr->m_func);
  2486. bytecodeArgOutUse->SetSrc1(implicitThisArgOut->GetSrc1());
  2487. callInstr->InsertBefore(bytecodeArgOutUse); // Need to keep the implicit "this" argout live till the call instruction for it to be captured by any bailout in the call sequence.
  2488. implicitThisArgOut->Remove();
  2489. startCall->SetSrc2(IR::IntConstOpnd::New(startCall->GetArgOutCount(/*getInterpreterArgOutCount*/ false), TyUint32, startCall->m_func));
  2490. startCall->GetSrc1()->AsIntConstOpnd()->SetValue(startCall->GetSrc1()->AsIntConstOpnd()->GetValue() - 1);
  2491. *returnInstr = InlineCallApplyTarget_Shared(callInstr, originalCallTargetStackSym, inlineeData->GetFunctionInfo(), inlineeData, inlineCacheIndex,
  2492. safeThis, /*isApplyTarget*/ false, /*isCallTarget*/ true, recursiveInlineDepth);
  2493. return true;
  2494. }
  2495. bool
  2496. Inline::SkipCallApplyTargetInlining_Shared(IR::Instr *callInstr, const Js::FunctionCodeGenJitTimeData* inlinerData, const Js::FunctionCodeGenJitTimeData* inlineeData, bool isApplyTarget, bool isCallTarget)
  2497. {
  2498. #if ENABLE_DEBUG_CONFIG_OPTIONS
  2499. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  2500. wchar_t debugStringBuffer2[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  2501. wchar_t debugStringBuffer3[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  2502. #endif
  2503. Assert(isApplyTarget ^ isCallTarget);
  2504. if (PHASE_OFF(Js::FixedMethodsPhase, callInstr->m_func->GetJnFunction()))
  2505. {
  2506. INLINE_TESTTRACE(L"INLINING: Skip Inline: Skipping %s target inlining, Fixed Methods turned off\tCaller: %s\t(#%d) \tTop Func:%s\t(#%d)\n", isApplyTarget ? L"apply" : L"call" ,
  2507. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  2508. this->topFunc->GetJnFunction()->GetDisplayName(), this->topFunc->GetJnFunction()->GetDebugNumberSet(debugStringBuffer2));
  2509. return true;
  2510. }
  2511. if (!inlineeData)
  2512. {
  2513. INLINE_TESTTRACE(L"INLINING: Skip Inline: Skipping %s target inlining, inlineeData not present\tCaller: %s\t(#%d) \tTop Func:%s\t(#%d)\n", isApplyTarget ? L"apply" : L"call",
  2514. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  2515. this->topFunc->GetJnFunction()->GetDisplayName(), this->topFunc->GetJnFunction()->GetDebugNumberSet(debugStringBuffer2));
  2516. return true;
  2517. }
  2518. if (!inlineeData->GetFunctionBody())
  2519. {
  2520. if (isCallTarget)
  2521. {
  2522. INLINE_TESTTRACE(L"INLINING: Skip Inline: Skipping .call inlining, target is a built-in\tCaller: %s\t(#%d) \tTop Func:%s\t(#%d)\n",
  2523. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  2524. this->topFunc->GetJnFunction()->GetDisplayName(), this->topFunc->GetJnFunction()->GetDebugNumberSet(debugStringBuffer2));
  2525. }
  2526. return true;
  2527. }
  2528. if (!inlinerData->IsLdFldInlineePresent())
  2529. {
  2530. INLINE_TESTTRACE(L"INLINING: Skip Inline: Skipping %s target inlining, not registered as a LdFld inlinee \tInlinee: %s (#%d)\tCaller: %s\t(#%d) \tTop Func:%s\t(#%d)\n", isApplyTarget ? L"apply" : L"call",
  2531. inlineeData->GetFunctionBody()->GetDisplayName(), inlineeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  2532. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2),
  2533. this->topFunc->GetJnFunction()->GetDisplayName(), this->topFunc->GetJnFunction()->GetDebugNumberSet(debugStringBuffer3));
  2534. return true;
  2535. }
  2536. return false;
  2537. }
  2538. bool
  2539. Inline::TryGetFixedMethodsForBuiltInAndTarget(IR::Instr *callInstr, const Js::FunctionCodeGenJitTimeData* inlinerData, const Js::FunctionCodeGenJitTimeData* inlineeData, Js::FunctionInfo *builtInFuncInfo,
  2540. IR::Instr* builtInLdInstr, IR::Instr* targetLdInstr, bool& safeThis, bool isApplyTarget)
  2541. {
  2542. #if ENABLE_DEBUG_CONFIG_OPTIONS
  2543. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  2544. wchar_t debugStringBuffer2[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  2545. wchar_t debugStringBuffer3[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  2546. #endif
  2547. Assert(isApplyTarget || (Js::JavascriptLibrary::GetBuiltInForFuncInfo(builtInFuncInfo, callInstr->m_func->GetScriptContext()) == Js::BuiltinFunction::Function_Call));
  2548. Js::OpCode originalCallOpCode = callInstr->m_opcode;
  2549. StackSym* originalCallTargetStackSym = callInstr->GetSrc1()->GetStackSym();
  2550. IR::ByteCodeUsesInstr * useCallTargetInstr = IR::ByteCodeUsesInstr::New(callInstr->m_func);
  2551. useCallTargetInstr->SetByteCodeOffset(callInstr);
  2552. useCallTargetInstr->byteCodeUpwardExposedUsed = JitAnew(callInstr->m_func->m_alloc, BVSparse<JitArenaAllocator>, callInstr->m_func->m_alloc);
  2553. Js::FunctionInfo* targetFunctionInfo = inlineeData->GetFunctionInfo();
  2554. safeThis = false;
  2555. // Check if we can get fixed method for call
  2556. if (TryOptimizeCallInstrWithFixedMethod(callInstr, builtInFuncInfo/*funcinfo for call*/, false /*isPolymorphic*/, false /*isBuiltIn*/, false /*isCtor*/, true /*isInlined*/,
  2557. safeThis /*unused here*/, true /*dontOptimizeJustCheck*/))
  2558. {
  2559. Assert(callInstr->m_opcode == originalCallOpCode); // check that we didn't change the opcode to CallIFixed.
  2560. callInstr->ReplaceSrc1(targetLdInstr->GetDst());
  2561. safeThis = false;
  2562. // Check if we can get fixed method for call target
  2563. if (!TryOptimizeCallInstrWithFixedMethod(callInstr, targetFunctionInfo, false /*isPolymorphic*/, false /*isBuiltIn*/, false /*isCtor*/, true /*isInlined*/,
  2564. safeThis /*unused here*/, true /*dontOptimizeJustCheck*/))
  2565. {
  2566. callInstr->ReplaceSrc1(builtInLdInstr->GetDst());
  2567. INLINE_TESTTRACE(L"INLINING: Skip Inline: Skipping %s target inlining, did not get fixed method for %s target \tInlinee: %s (#%d)\tCaller: %s\t(#%d) \tTop Func:%s\t(#%d)\n", isApplyTarget ? L"apply" : L"call", isApplyTarget ? L"apply" : L"call",
  2568. inlineeData->GetFunctionBody()->GetDisplayName(), inlineeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  2569. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2),
  2570. this->topFunc->GetJnFunction()->GetDisplayName(), this->topFunc->GetJnFunction()->GetDebugNumberSet(debugStringBuffer3));
  2571. return false;
  2572. }
  2573. }
  2574. else
  2575. {
  2576. INLINE_TESTTRACE(L"INLINING: Skip Inline: Skipping %s target inlining, did not get fixed method for %s \tInlinee: %s (#%d)\tCaller: %s\t(#%d) \tTop Func:%s\t(#%d)\n", isApplyTarget ? L"apply" : L"call", isApplyTarget ? L"apply" : L"call",
  2577. inlineeData->GetFunctionBody()->GetDisplayName(), inlineeData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer),
  2578. inlinerData->GetFunctionBody()->GetDisplayName(), inlinerData->GetFunctionBody()->GetDebugNumberSet(debugStringBuffer2),
  2579. this->topFunc->GetJnFunction()->GetDisplayName(), this->topFunc->GetJnFunction()->GetDebugNumberSet(debugStringBuffer3));
  2580. return false;
  2581. }
  2582. if (isApplyTarget)
  2583. {
  2584. callInstr->m_func->SetHasApplyTargetInlining();
  2585. }
  2586. Assert(callInstr->m_opcode == originalCallOpCode);
  2587. callInstr->ReplaceSrc1(builtInLdInstr->GetDst());
  2588. // Emit Fixed Method check for apply/call
  2589. safeThis = false;
  2590. TryOptimizeCallInstrWithFixedMethod(callInstr, builtInFuncInfo/*funcinfo for apply/call */, false /*isPolymorphic*/, false /*isBuiltIn*/, false /*isCtor*/, true /*isInlined*/, safeThis /*unused here*/);
  2591. // If we optimized the call instruction for a fixed function, we must extend the function object's lifetime until after
  2592. // the bailout on non-stack arguments.
  2593. Assert(callInstr->m_opcode == Js::OpCode::CallIFixed);
  2594. useCallTargetInstr->byteCodeUpwardExposedUsed->Set(originalCallTargetStackSym->m_id);
  2595. // Make the target of apply/call as the target of the call instruction
  2596. callInstr->ReplaceSrc1(targetLdInstr->GetDst());
  2597. callInstr->m_opcode = originalCallOpCode;
  2598. //Emit Fixed Method check for apply/call target
  2599. originalCallTargetStackSym = callInstr->GetSrc1()->GetStackSym();
  2600. safeThis = false;
  2601. TryOptimizeCallInstrWithFixedMethod(callInstr, targetFunctionInfo, false /*isPolymorphic*/, false /*isBuiltIn*/, false /*isCtor*/, true /*isInlined*/, safeThis /*unused here*/);
  2602. // If we optimized the call instruction for a fixed function, we must extend the function object's lifetime until after
  2603. // the bailout on non-stack arguments.
  2604. Assert(callInstr->m_opcode == Js::OpCode::CallIFixed);
  2605. useCallTargetInstr->byteCodeUpwardExposedUsed->Set(originalCallTargetStackSym->m_id);
  2606. callInstr->InsertBefore(useCallTargetInstr);
  2607. return true;
  2608. }
  2609. void
  2610. Inline::SetupInlineInstrForCallDirect(Js::BuiltinFunction builtInId, IR::Instr* callInstr, IR::Instr* argoutInstr)
  2611. {
  2612. switch(builtInId)
  2613. {
  2614. case Js::BuiltinFunction::Array_Concat:
  2615. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperArray_Concat, callInstr->m_func));
  2616. break;
  2617. case Js::BuiltinFunction::Array_IndexOf:
  2618. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperArray_IndexOf, callInstr->m_func));
  2619. break;
  2620. case Js::BuiltinFunction::Array_Includes:
  2621. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperArray_Includes, callInstr->m_func));
  2622. break;
  2623. case Js::BuiltinFunction::Array_Join:
  2624. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperArray_Join, callInstr->m_func));
  2625. break;
  2626. case Js::BuiltinFunction::Array_LastIndexOf:
  2627. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperArray_LastIndexOf, callInstr->m_func));
  2628. break;
  2629. case Js::BuiltinFunction::Array_Reverse:
  2630. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperArray_Reverse, callInstr->m_func));
  2631. break;
  2632. case Js::BuiltinFunction::Array_Shift:
  2633. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperArray_Shift, callInstr->m_func));
  2634. break;
  2635. case Js::BuiltinFunction::Array_Slice:
  2636. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperArray_Slice, callInstr->m_func));
  2637. break;
  2638. case Js::BuiltinFunction::Array_Splice:
  2639. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperArray_Splice, callInstr->m_func));
  2640. break;
  2641. case Js::BuiltinFunction::Array_Unshift:
  2642. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperArray_Unshift, callInstr->m_func));
  2643. break;
  2644. case Js::BuiltinFunction::String_Concat:
  2645. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_Concat, callInstr->m_func));
  2646. break;
  2647. case Js::BuiltinFunction::String_CharCodeAt:
  2648. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_CharCodeAt, callInstr->m_func));
  2649. break;
  2650. case Js::BuiltinFunction::String_CharAt:
  2651. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_CharAt, callInstr->m_func));
  2652. break;
  2653. case Js::BuiltinFunction::String_FromCharCode:
  2654. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_FromCharCode, callInstr->m_func));
  2655. break;
  2656. case Js::BuiltinFunction::String_FromCodePoint:
  2657. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_FromCodePoint, callInstr->m_func));
  2658. break;
  2659. case Js::BuiltinFunction::String_IndexOf:
  2660. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_IndexOf, callInstr->m_func));
  2661. break;
  2662. case Js::BuiltinFunction::String_LastIndexOf:
  2663. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_LastIndexOf, callInstr->m_func));
  2664. break;
  2665. case Js::BuiltinFunction::String_Link:
  2666. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_Link, callInstr->m_func));
  2667. break;
  2668. case Js::BuiltinFunction::String_LocaleCompare:
  2669. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_LocaleCompare, callInstr->m_func));
  2670. break;
  2671. case Js::BuiltinFunction::String_Match:
  2672. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_Match, callInstr->m_func));
  2673. break;
  2674. case Js::BuiltinFunction::String_Replace:
  2675. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_Replace, callInstr->m_func));
  2676. break;
  2677. case Js::BuiltinFunction::String_Search:
  2678. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_Search, callInstr->m_func));
  2679. break;
  2680. case Js::BuiltinFunction::String_Slice:
  2681. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_Slice, callInstr->m_func));
  2682. break;
  2683. case Js::BuiltinFunction::String_Split:
  2684. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_Split, callInstr->m_func));
  2685. break;
  2686. case Js::BuiltinFunction::String_Substr:
  2687. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_Substr, callInstr->m_func));
  2688. break;
  2689. case Js::BuiltinFunction::String_Substring:
  2690. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_Substring, callInstr->m_func));
  2691. break;
  2692. case Js::BuiltinFunction::String_ToLocaleLowerCase:
  2693. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_ToLocaleLowerCase, callInstr->m_func));
  2694. break;
  2695. case Js::BuiltinFunction::String_ToLocaleUpperCase:
  2696. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_ToLocaleUpperCase, callInstr->m_func));
  2697. break;
  2698. case Js::BuiltinFunction::String_ToLowerCase:
  2699. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_ToLowerCase, callInstr->m_func));
  2700. break;
  2701. case Js::BuiltinFunction::String_ToUpperCase:
  2702. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_ToUpperCase, callInstr->m_func));
  2703. break;
  2704. case Js::BuiltinFunction::String_Trim:
  2705. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_Trim, callInstr->m_func));
  2706. break;
  2707. case Js::BuiltinFunction::String_TrimLeft:
  2708. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_TrimLeft, callInstr->m_func));
  2709. break;
  2710. case Js::BuiltinFunction::String_TrimRight:
  2711. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperString_TrimRight, callInstr->m_func));
  2712. break;
  2713. case Js::BuiltinFunction::GlobalObject_ParseInt:
  2714. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperGlobalObject_ParseInt, callInstr->m_func));
  2715. break;
  2716. case Js::BuiltinFunction::RegExp_Exec:
  2717. callInstr->SetSrc1(IR::HelperCallOpnd::New(IR::JnHelperMethod::HelperRegExp_Exec, callInstr->m_func));
  2718. break;
  2719. };
  2720. callInstr->SetSrc2(argoutInstr->GetDst());
  2721. return;
  2722. }
  2723. void
  2724. Inline::WrapArgsOutWithCoerse(Js::BuiltinFunction builtInId, IR::Instr* callInstr)
  2725. {
  2726. switch (builtInId)
  2727. {
  2728. case Js::BuiltinFunction::String_Match:
  2729. callInstr->ForEachCallDirectArgOutInstrBackward([&](IR::Instr *argOutInstr, uint argNum)
  2730. {
  2731. IR::Instr * newInstr = nullptr;
  2732. bool isPreOpBailOutNeeded = false;
  2733. if (argNum == 0)
  2734. {
  2735. newInstr = argOutInstr->HoistSrc1(Js::OpCode::Coerse_Str);
  2736. isPreOpBailOutNeeded = true;
  2737. newInstr->GetDst()->SetValueType(ValueType::String);
  2738. newInstr->SetSrc2(IR::AddrOpnd::New(L"String.prototype.match", IR::AddrOpndKindSz, newInstr->m_func));
  2739. argOutInstr->GetSrc1()->SetValueType(ValueType::String);
  2740. }
  2741. else if (argNum == 1)
  2742. {
  2743. newInstr = argOutInstr->HoistSrc1(Js::OpCode::Coerse_Regex);
  2744. isPreOpBailOutNeeded = true;
  2745. }
  2746. if (isPreOpBailOutNeeded)
  2747. {
  2748. newInstr->SetByteCodeOffset(argOutInstr);
  2749. newInstr->forcePreOpBailOutIfNeeded = true;
  2750. }
  2751. return false;
  2752. }, 2);
  2753. break;
  2754. case Js::BuiltinFunction::String_Replace:
  2755. callInstr->ForEachCallDirectArgOutInstrBackward([&](IR::Instr *argOutInstr, uint argNum)
  2756. {
  2757. IR::Instr * newInstr = nullptr;
  2758. bool isPreOpBailOutNeeded = false;
  2759. if (argNum == 0)
  2760. {
  2761. newInstr = argOutInstr->HoistSrc1(Js::OpCode::Coerse_Str);
  2762. isPreOpBailOutNeeded = true;
  2763. newInstr->GetDst()->SetValueType(ValueType::String);
  2764. newInstr->SetSrc2(IR::AddrOpnd::New(L"String.prototype.replace", IR::AddrOpndKindSz, newInstr->m_func));
  2765. argOutInstr->GetSrc1()->SetValueType(ValueType::String);
  2766. }
  2767. if (argNum == 1)
  2768. {
  2769. newInstr = argOutInstr->HoistSrc1(Js::OpCode::Coerse_StrOrRegex);
  2770. isPreOpBailOutNeeded = true;
  2771. }
  2772. if (isPreOpBailOutNeeded)
  2773. {
  2774. newInstr->SetByteCodeOffset(argOutInstr);
  2775. newInstr->forcePreOpBailOutIfNeeded = true;
  2776. }
  2777. return false;
  2778. }, 3);
  2779. break;
  2780. case Js::BuiltinFunction::RegExp_Exec:
  2781. callInstr->ForEachCallDirectArgOutInstrBackward([&](IR::Instr *argOutInstr, uint argNum)
  2782. {
  2783. IR::Instr * newInstr = nullptr;
  2784. bool isPreOpBailOutNeeded = false;
  2785. if (argNum == 0)
  2786. {
  2787. newInstr = argOutInstr->HoistSrc1(Js::OpCode::Coerse_Regex);
  2788. isPreOpBailOutNeeded = true;
  2789. }
  2790. else if (argNum == 1)
  2791. {
  2792. newInstr = argOutInstr->HoistSrc1(Js::OpCode::Conv_Str);
  2793. newInstr->GetDst()->SetValueType(ValueType::String);
  2794. argOutInstr->GetSrc1()->SetValueType(ValueType::String);
  2795. isPreOpBailOutNeeded = true;
  2796. }
  2797. if (isPreOpBailOutNeeded)
  2798. {
  2799. newInstr->SetByteCodeOffset(argOutInstr);
  2800. newInstr->forcePreOpBailOutIfNeeded = true;
  2801. }
  2802. return false;
  2803. }, 2);
  2804. break;
  2805. }
  2806. }
  2807. IR::Instr *
  2808. Inline::SimulateCallForGetterSetter(IR::Instr *accessorInstr, IR::Instr* insertInstr, IR::PropertySymOpnd* methodOpnd, bool isGetter)
  2809. {
  2810. Assert(methodOpnd->UsesAccessor());
  2811. IntConstType argOutCount = isGetter ? 1 : 2; // A setter would have an additional ArgOut in the form of the value being set.
  2812. IR::Instr *ldMethodFld = IR::Instr::New(Js::OpCode::LdMethodFromFlags, IR::RegOpnd::New(TyVar, accessorInstr->m_func), methodOpnd, accessorInstr->m_func);
  2813. insertInstr->InsertBefore(ldMethodFld);
  2814. ldMethodFld = ldMethodFld->ConvertToBailOutInstr(accessorInstr, IR::BailOutFailedInlineTypeCheck);
  2815. ldMethodFld->SetByteCodeOffset(accessorInstr);
  2816. IR::Instr *startCall = IR::Instr::New(Js::OpCode::StartCall, accessorInstr->m_func);
  2817. startCall->SetDst(IR::RegOpnd::New(TyVar, accessorInstr->m_func));
  2818. startCall->SetSrc1(IR::IntConstOpnd::New(argOutCount, TyInt32, accessorInstr->m_func));
  2819. insertInstr->InsertBefore(startCall);
  2820. startCall->SetByteCodeOffset(accessorInstr);
  2821. PropertySym * fieldSym = methodOpnd->AsSymOpnd()->m_sym->AsPropertySym();
  2822. IR::RegOpnd * instanceOpnd = IR::RegOpnd::New(fieldSym->m_stackSym, TyVar, accessorInstr->m_func);
  2823. IR::Instr *argOutThis = IR::Instr::New(Js::OpCode::ArgOut_A, accessorInstr->m_func);
  2824. StackSym *symDst = accessorInstr->m_func->m_symTable->GetArgSlotSym((uint16)(1));
  2825. argOutThis->SetDst(IR::SymOpnd::New(symDst, 0, TyVar, accessorInstr->m_func));
  2826. argOutThis->SetSrc1(instanceOpnd);
  2827. argOutThis->SetSrc2(startCall->GetDst());
  2828. insertInstr->InsertBefore(argOutThis);
  2829. IR::Instr * argOut = nullptr;
  2830. if(!isGetter)
  2831. {
  2832. // Set the src1 of the StFld to be the second ArgOut.
  2833. argOut = IR::Instr::New(Js::OpCode::ArgOut_A, accessorInstr->m_func);
  2834. symDst = accessorInstr->m_func->m_symTable->GetArgSlotSym((uint16)(2));
  2835. argOut->SetDst(IR::SymOpnd::New(symDst, 0, TyVar, accessorInstr->m_func));
  2836. argOut->SetSrc1(accessorInstr->GetSrc1());
  2837. argOut->SetSrc2(argOutThis->GetDst());
  2838. insertInstr->InsertBefore(argOut);
  2839. }
  2840. accessorInstr->ReplaceSrc1(ldMethodFld->GetDst());
  2841. isGetter ? accessorInstr->SetSrc2(argOutThis->GetDst()) : accessorInstr->SetSrc2(argOut->GetDst());
  2842. if(!isGetter)
  2843. {
  2844. accessorInstr->UnlinkDst();
  2845. }
  2846. return startCall;
  2847. }
  2848. IR::Instr *
  2849. Inline::InlineGetterSetterFunction(IR::Instr *accessorInstr, const Js::FunctionCodeGenJitTimeData *const inlineeData, const StackSym *symCallerThis, const uint inlineCacheIndex, bool isGetter, uint recursiveInlineDepth)
  2850. {
  2851. // This function is recursive, so when jitting in the foreground, probe the stack
  2852. if (!this->topFunc->IsBackgroundJIT())
  2853. {
  2854. PROBE_STACK(this->topFunc->GetScriptContext(), Js::Constants::MinStackDefault);
  2855. }
  2856. IR::Instr *instrNext = accessorInstr->m_next;
  2857. Js::FunctionBody *funcCaller = accessorInstr->m_func->GetJnFunction();
  2858. Js::FunctionBody *funcBody = inlineeData->GetFunctionBody();
  2859. Assert(!accessorInstr->GetSrc2());
  2860. JS_ETW(EventWriteJSCRIPT_BACKEND_INLINE(
  2861. funcCaller->GetFunctionNumber(), funcBody->GetFunctionNumber(),
  2862. funcCaller->GetExternalDisplayName(), funcBody->GetExternalDisplayName()));
  2863. IR::Instr *inlineBailoutChecksBeforeInstr = accessorInstr;
  2864. Js::ProxyEntryPointInfo *defaultEntryPointInfo = funcBody->GetDefaultEntryPointInfo();
  2865. Assert(defaultEntryPointInfo->IsFunctionEntryPointInfo());
  2866. Js::FunctionEntryPointInfo *functionEntryPointInfo = static_cast<Js::FunctionEntryPointInfo*>(defaultEntryPointInfo);
  2867. JsFunctionCodeGen *workItem = JitAnew(this->topFunc->m_alloc, JsFunctionCodeGen,
  2868. funcBody->GetScriptContext()->GetNativeCodeGenerator(), funcBody, functionEntryPointInfo, this->topFunc->IsJitInDebugMode());
  2869. workItem->SetRecyclableData(JitAnew(this->topFunc->m_alloc, Js::CodeGenRecyclableData, inlineeData));
  2870. workItem->SetJitMode(this->topFunc->m_workItem->GetJitMode());
  2871. IR::RegOpnd * returnValueOpnd;
  2872. Js::RegSlot returnRegSlot;
  2873. if (isGetter && accessorInstr->GetDst())
  2874. {
  2875. returnValueOpnd = accessorInstr->UnlinkDst()->AsRegOpnd();
  2876. returnRegSlot = returnValueOpnd->m_sym->GetByteCodeRegSlot();
  2877. }
  2878. else
  2879. {
  2880. returnValueOpnd = nullptr;
  2881. returnRegSlot = Js::Constants::NoRegister;
  2882. }
  2883. const auto profileInfo =
  2884. JitAnew(
  2885. this->topFunc->m_alloc,
  2886. Js::ReadOnlyDynamicProfileInfo,
  2887. funcBody->HasDynamicProfileInfo() ? funcBody->GetAnyDynamicProfileInfo() : nullptr,
  2888. this->topFunc->IsBackgroundJIT() ? this->topFunc->m_alloc : nullptr);
  2889. Js::EntryPointPolymorphicInlineCacheInfo * entryPointPolymorphicInlineCacheInfo = this->topFunc->m_workItem->GetEntryPoint()->GetPolymorphicInlineCacheInfo();
  2890. Func *inlinee = JitAnew(this->topFunc->m_alloc,
  2891. Func,
  2892. this->topFunc->m_alloc,
  2893. workItem,
  2894. accessorInstr->m_func->m_runtimeData ?
  2895. accessorInstr->m_func->m_runtimeData->GetLdFldInlinee(inlineCacheIndex) :
  2896. this->topFunc->GetJnFunction()->GetLdFldInlineeCodeGenRuntimeData(inlineCacheIndex),
  2897. entryPointPolymorphicInlineCacheInfo ? entryPointPolymorphicInlineCacheInfo->GetInlineeInfo(funcBody) : nullptr,
  2898. this->topFunc->GetCodeGenAllocators(),
  2899. this->topFunc->GetNumberAllocator(),
  2900. profileInfo,
  2901. this->topFunc->GetCodeGenProfiler(),
  2902. this->topFunc->IsBackgroundJIT(),
  2903. accessorInstr->m_func,
  2904. accessorInstr->m_next->GetByteCodeOffset(),
  2905. returnRegSlot,
  2906. false,
  2907. UINT16_MAX,
  2908. true);
  2909. // funcBody->GetInParamsCount() can be greater than one even if it is all undefined. Example defineProperty(a,"foo", {get:function(a,b,c){}});
  2910. #ifdef ENABLE_DEBUG_CONFIG_OPTIONS
  2911. if (Js::Configuration::Global.flags.TestTrace.IsEnabled(Js::InlinePhase) ||
  2912. Js::Configuration::Global.flags.TestTrace.IsEnabled(Js::InlineAccessorsPhase) || Js::Configuration::Global.flags.Trace.IsEnabled(Js::InlineAccessorsPhase))
  2913. {
  2914. wchar_t debugStringBuffer [MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  2915. wchar_t debugStringBuffer2[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  2916. PropertySym *propertySym = isGetter ? accessorInstr->GetSrc1()->AsSymOpnd()->m_sym->AsPropertySym() : accessorInstr->GetDst()->AsSymOpnd()->m_sym->AsPropertySym();
  2917. Js::ScriptContext* scriptContext = propertySym->GetFunc()->GetScriptContext();
  2918. Output::Print(L"INLINING: %s: \tInlinee: %s (%s)\tCaller: %s (%s)\t fieldName: %s\n", isGetter ? L"Getter" : L"Setter",
  2919. funcBody->GetDisplayName(), funcBody->GetDebugNumberSet(debugStringBuffer), funcCaller->GetDisplayName(), funcCaller->GetDebugNumberSet(debugStringBuffer2),
  2920. scriptContext->GetPropertyNameLocked(propertySym->m_propertyId)->GetBuffer());
  2921. Output::Flush();
  2922. }
  2923. #endif
  2924. IR::Opnd * methodOpnd = isGetter ? accessorInstr->GetSrc1() : accessorInstr->GetDst();
  2925. Assert(methodOpnd->IsSymOpnd() && methodOpnd->AsSymOpnd()->IsPropertySymOpnd());
  2926. inlineBailoutChecksBeforeInstr = SimulateCallForGetterSetter(accessorInstr, accessorInstr, methodOpnd->AsPropertySymOpnd(), isGetter);
  2927. bool safeThis = false;
  2928. TryOptimizeCallInstrWithFixedMethod(accessorInstr, inlineeData->GetFunctionInfo(), false, false, false, true, safeThis);
  2929. return InlineFunctionCommon(accessorInstr, nullptr, funcBody, inlinee, instrNext, returnValueOpnd, inlineBailoutChecksBeforeInstr, symCallerThis, recursiveInlineDepth, safeThis);
  2930. }
  2931. IR::Instr *
  2932. Inline::InlineFunctionCommon(IR::Instr *callInstr, StackSym* originalCallTargetStackSym, Js::FunctionBody *funcBody, Func *inlinee, IR::Instr *instrNext,
  2933. IR::RegOpnd * returnValueOpnd, IR::Instr *inlineBailoutChecksBeforeInstr, const StackSym *symCallerThis, uint recursiveInlineDepth, bool safeThis, bool isApplyTarget)
  2934. {
  2935. BuildIRForInlinee(inlinee, funcBody, callInstr, isApplyTarget, recursiveInlineDepth);
  2936. Js::ArgSlot formalCount = funcBody->GetInParamsCount();
  2937. IR::Instr *argOuts[Js::InlineeCallInfo::MaxInlineeArgoutCount];
  2938. #if DBG
  2939. memset(argOuts, 0xFE, sizeof(argOuts));
  2940. #endif
  2941. if (callInstr->m_opcode == Js::OpCode::CallIFixed)
  2942. {
  2943. Assert(callInstr->GetFixedFunction()->GetFunctionInfo() == funcBody);
  2944. }
  2945. else
  2946. {
  2947. PrepareInsertionPoint(callInstr, funcBody, inlineBailoutChecksBeforeInstr);
  2948. }
  2949. Assert(formalCount <= Js::InlineeCallInfo::MaxInlineeArgoutCount);
  2950. __analysis_assume(formalCount <= Js::InlineeCallInfo::MaxInlineeArgoutCount);
  2951. IR::Instr *argOutsExtra[Js::InlineeCallInfo::MaxInlineeArgoutCount];
  2952. #if DBG
  2953. memset(argOutsExtra, 0xFE, sizeof(argOutsExtra));
  2954. #endif
  2955. bool stackArgsArgOutExpanded = false;
  2956. Js::ArgSlot actualCount = MapActuals(callInstr, argOuts, formalCount, inlinee, (Js::ProfileId)callInstr->AsProfiledInstr()->u.profileId, &stackArgsArgOutExpanded, argOutsExtra);
  2957. inlinee->actualCount = actualCount;
  2958. Assert(actualCount > 0);
  2959. #if DBG
  2960. if(safeThis)
  2961. {
  2962. Assert(callInstr->m_opcode == Js::OpCode::CallIFixed);
  2963. }
  2964. #endif
  2965. MapFormals(inlinee, argOuts, formalCount, actualCount, returnValueOpnd, callInstr->GetSrc1(), symCallerThis, stackArgsArgOutExpanded, safeThis, argOutsExtra);
  2966. if (callInstr->m_opcode == Js::OpCode::CallIFixed && !inlinee->isGetterSetter)
  2967. {
  2968. Assert(originalCallTargetStackSym != nullptr);
  2969. // Insert a ByteCodeUsesInstr to make sure the function object's lifetimes is extended beyond the last bailout point
  2970. // at which we may have to call the function again in the interpreter.
  2971. // Don't need to do this for a getter/setter inlinee as, upon bailout, the execution will start in the interpreter at the LdFld/StFld itself.
  2972. callInstr->InsertBefore(IR::ByteCodeUsesInstr::New(callInstr, originalCallTargetStackSym->m_id));
  2973. }
  2974. // InlineeStart indicate the beginning of the inlinee, and we need the stack arg for the inlinee until InlineeEnd
  2975. callInstr->m_opcode = Js::OpCode::InlineeStart;
  2976. // Set it to belong to the inlinee, so that we can use the actual count when lowering InlineeStart
  2977. callInstr->m_func = inlinee;
  2978. callInstr->SetDst(IR::RegOpnd::New(TyVar, inlinee));
  2979. // Put the meta arguments that the stack walker expects to find on the stack.
  2980. SetupInlineeFrame(inlinee, callInstr, actualCount, callInstr->GetSrc1());
  2981. // actualCount + MetaArgCount to include the meta arguments to pop from the inlinee argout stack.
  2982. IR::Instr *inlineeEndInstr = IR::Instr::New(Js::OpCode::InlineeEnd, inlinee);
  2983. inlineeEndInstr->SetByteCodeOffset(inlinee->m_tailInstr->GetPrevRealInstr());
  2984. inlineeEndInstr->SetSrc1(IR::IntConstOpnd::New(actualCount + Js::Constants::InlineeMetaArgCount, TyInt32, callInstr->m_func));
  2985. inlineeEndInstr->SetSrc2(callInstr->GetDst()); // Link the inlinee end to the inlinee Start
  2986. callInstr->InsertAfter(inlineeEndInstr);
  2987. // Move the ArgOut_A_Inlines close to the InlineeStart
  2988. callInstr->MoveArgs();
  2989. inlineeEndInstr->InsertRangeBefore(inlinee->m_headInstr->m_next, inlinee->m_tailInstr->m_prev);
  2990. inlinee->m_headInstr->Free();
  2991. inlinee->m_tailInstr->Free();
  2992. this->topFunc->SetHasInlinee();
  2993. InsertStatementBoundary(instrNext);
  2994. return instrNext;
  2995. }
  2996. #ifdef ENABLE_DOM_FAST_PATH
  2997. // we have LdFld, src1 obj, src2: null; dest: return value
  2998. // We need to convert it to inlined method call.
  2999. // We cannot do CallDirect as it requires ArgOut and that cannot be hoisted/copyprop'd
  3000. // Create a new OpCode, DOMFastPathGetter. The OpCode takes three arguments:
  3001. // The function object, the "this" instance object, and the helper routine as we have one for each index
  3002. // A functionInfo->Index# table is created in scriptContext (and potentially movable to threadContext if WS is not a concern).
  3003. // we use the table to identify the helper that needs to be lowered.
  3004. // At lower time we create the call to helper, which is function entrypoint at this time.
  3005. IR::Instr * Inline::InlineDOMGetterSetterFunction(IR::Instr *ldFldInstr, const Js::FunctionCodeGenJitTimeData *const inlineeData, const Js::FunctionCodeGenJitTimeData *const inlinerData)
  3006. {
  3007. Js::FunctionInfo* functionInfo = inlineeData->GetFunctionInfo();
  3008. Assert(ldFldInstr->GetSrc1()->IsSymOpnd() && ldFldInstr->GetSrc1()->AsSymOpnd()->IsPropertySymOpnd());
  3009. Assert(ldFldInstr->GetSrc1()->AsPropertySymOpnd()->HasObjTypeSpecFldInfo());
  3010. Assert(ldFldInstr->GetSrc1()->AsPropertySymOpnd()->GetObjTypeSpecInfo()->UsesAccessor());
  3011. // Find the helper routine for this functionInfo.
  3012. Js::ScriptContext* scriptContext = this->topFunc->GetScriptContext();
  3013. IR::JnHelperMethod helperMethod;
  3014. bool found = scriptContext->EnsureDOMFastPathIRHelperMap()->TryGetValue(functionInfo, &helperMethod);
  3015. Assert(found);
  3016. // Find the instance object (External object).
  3017. PropertySym * fieldSym = ldFldInstr->GetSrc1()->AsSymOpnd()->m_sym->AsPropertySym();
  3018. IR::RegOpnd * instanceOpnd = IR::RegOpnd::New(fieldSym->m_stackSym, TyMachPtr, ldFldInstr->m_func);
  3019. // Find the function object from getter inline cache. Need bailout to verify.
  3020. IR::Instr *ldMethodFld = IR::Instr::New(Js::OpCode::LdMethodFromFlags, IR::RegOpnd::New(TyVar, ldFldInstr->m_func), ldFldInstr->GetSrc1(), ldFldInstr->m_func);
  3021. ldFldInstr->InsertBefore(ldMethodFld);
  3022. ldMethodFld = ldMethodFld->ConvertToBailOutInstr(ldFldInstr, IR::BailOutFailedInlineTypeCheck);
  3023. ldFldInstr->ReplaceSrc1(ldMethodFld->GetDst());
  3024. ldMethodFld->SetByteCodeOffset(ldFldInstr);
  3025. // generate further object/type bailout
  3026. PrepareInsertionPoint(ldFldInstr, functionInfo, ldFldInstr);
  3027. // We have three arguments to pass to the OpCode. Create a new ExtendArg_A opcode to chain up the argument. It is similar to ArgOut chain
  3028. // except that it is not argout.
  3029. // The Opcode sequence is like:
  3030. // (dst)helpArg1: ExtendArg_A (src1)thisObject (src2)null
  3031. // (dst)helpArg2: ExtendArg_A (src1)funcObject (src2)helpArg1
  3032. // method: DOMFastPathGetter (src1)HelperCall (src2)helpArg2
  3033. IR::Instr* extendArg0 = IR::Instr::New(Js::OpCode::ExtendArg_A, IR::RegOpnd::New(TyVar, ldFldInstr->m_func), instanceOpnd, ldFldInstr->m_func);
  3034. ldFldInstr->InsertBefore(extendArg0);
  3035. IR::Instr* extendArg1 = IR::Instr::New(Js::OpCode::ExtendArg_A, IR::RegOpnd::New(TyVar, ldFldInstr->m_func), ldMethodFld->GetDst(), extendArg0->GetDst(), ldFldInstr->m_func);
  3036. ldFldInstr->InsertBefore(extendArg1);
  3037. ldFldInstr->ReplaceSrc1(IR::HelperCallOpnd::New(helperMethod, ldFldInstr->m_func));
  3038. ldFldInstr->SetSrc2(extendArg1->GetDst());
  3039. ldFldInstr->m_opcode = Js::OpCode::DOMFastPathGetter;
  3040. StackSym * tmpSym = StackSym::New(ldFldInstr->GetDst()->GetType(), ldFldInstr->m_func);
  3041. IR::Opnd * tmpDst = IR::RegOpnd::New(tmpSym, tmpSym->GetType(), ldFldInstr->m_func);
  3042. IR::Opnd * callInstrDst = ldFldInstr->UnlinkDst();
  3043. ldFldInstr->SetDst(tmpDst);
  3044. IR::Instr * ldInstr = IR::Instr::New(Js::OpCode::Ld_A, callInstrDst, tmpDst, ldFldInstr->m_func);
  3045. ldFldInstr->InsertAfter(ldInstr);
  3046. this->topFunc->SetHasInlinee();
  3047. InsertStatementBoundary(ldInstr->m_next);
  3048. return ldInstr->m_next;
  3049. }
  3050. #endif
  3051. void
  3052. Inline::InsertStatementBoundary(IR::Instr * instrNext)
  3053. {
  3054. if (lastStatementBoundary)
  3055. {
  3056. Assert(lastStatementBoundary->m_func == instrNext->m_func);
  3057. IR::PragmaInstr * pragmaInstr = IR::PragmaInstr::New(Js::OpCode::StatementBoundary,
  3058. lastStatementBoundary->m_statementIndex,
  3059. lastStatementBoundary->m_func);
  3060. pragmaInstr->SetByteCodeOffset(instrNext);
  3061. instrNext->InsertBefore(pragmaInstr);
  3062. }
  3063. }
  3064. IR::Instr *
  3065. Inline::InlineScriptFunction(IR::Instr *callInstr, const Js::FunctionCodeGenJitTimeData *const inlineeData, const StackSym *symCallerThis, const Js::ProfileId profileId, bool* pIsInlined, uint recursiveInlineDepth)
  3066. {
  3067. *pIsInlined = false;
  3068. // This function is recursive, so when jitting in the foreground, probe the stack
  3069. if (!this->topFunc->IsBackgroundJIT())
  3070. {
  3071. PROBE_STACK(this->topFunc->GetScriptContext(), Js::Constants::MinStackDefault);
  3072. }
  3073. IR::Instr *instrNext = callInstr->m_next;
  3074. Js::FunctionBody *funcCaller = callInstr->m_func->GetJnFunction();
  3075. Js::FunctionBody *funcBody = inlineeData->GetFunctionBody();
  3076. if (callInstr->GetSrc2() &&
  3077. callInstr->GetSrc2()->IsSymOpnd() &&
  3078. callInstr->GetSrc2()->AsSymOpnd()->m_sym->AsStackSym()->GetArgSlotNum() > Js::InlineeCallInfo::MaxInlineeArgoutCount)
  3079. {
  3080. #if ENABLE_DEBUG_CONFIG_OPTIONS
  3081. wchar_t debugStringBuffer[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  3082. wchar_t debugStringBuffer2[MAX_FUNCTION_BODY_DEBUG_STRING_SIZE];
  3083. #endif
  3084. // This is a hard limit as we only use 4 bits to encode the actual count in the InlineeCallInfo. Although
  3085. // InliningDecider already checks for this, the check is against profile data that may not be accurate since profile
  3086. // data matching does not take into account some types of changes to source code. Need to check this again with current
  3087. // information.
  3088. INLINE_TESTTRACE(L"INLINING: Skip Inline: ArgSlot > MaxInlineeArgoutCount\tInlinee: %s (%s)\tArgSlotNum: %d\tMaxInlineeArgoutCount: %d\tCaller: %s (%s)\n",
  3089. funcBody->GetDisplayName(), funcBody->GetDebugNumberSet(debugStringBuffer), callInstr->GetSrc2()->AsSymOpnd()->m_sym->AsStackSym()->GetArgSlotNum(),
  3090. Js::InlineeCallInfo::MaxInlineeArgoutCount, funcCaller->GetDisplayName(), funcCaller->GetDebugNumberSet(debugStringBuffer2));
  3091. return instrNext;
  3092. }
  3093. *pIsInlined = true;
  3094. // Save off the call target operand (function object) so we can extend its lifetime as needed, even if
  3095. // the call instruction gets transformed to CallIFixed.
  3096. StackSym* originalCallTargetStackSym = callInstr->GetSrc1()->GetStackSym();
  3097. // We are committed to inlining, optimize the call instruction for fixed fields now and don't attempt it later.
  3098. bool isFixed = false;
  3099. JS_ETW(EventWriteJSCRIPT_BACKEND_INLINE(
  3100. funcCaller->GetFunctionNumber(), funcBody->GetFunctionNumber(),
  3101. funcCaller->GetExternalDisplayName(), funcBody->GetExternalDisplayName()));
  3102. bool isCtor = false;
  3103. bool safeThis = false;
  3104. IR::Instr *inlineBailoutChecksBeforeInstr;
  3105. if (callInstr->m_opcode == Js::OpCode::NewScObject || callInstr->m_opcode == Js::OpCode::NewScObjArray)
  3106. {
  3107. isCtor = true;
  3108. isFixed = TryOptimizeCallInstrWithFixedMethod(callInstr, inlineeData->GetFunctionInfo(),
  3109. false /*isPolymorphic*/, false /*isBuiltIn*/, isCtor /*isCtor*/, true /*isInlined*/, safeThis /*&safeThis*/);
  3110. bool split = SplitConstructorCall(callInstr, true, isFixed, &inlineBailoutChecksBeforeInstr);
  3111. Assert(split && inlineBailoutChecksBeforeInstr != nullptr);
  3112. }
  3113. else
  3114. {
  3115. isFixed = TryOptimizeCallInstrWithFixedMethod(callInstr, inlineeData->GetFunctionInfo(),
  3116. false /*isPolymorphic*/, false /*isBuiltIn*/, isCtor /*isCtor*/, true /*isInlined*/, safeThis /*&safeThis*/);
  3117. inlineBailoutChecksBeforeInstr = callInstr;
  3118. }
  3119. Assert(callInstr->IsProfiledInstr());
  3120. Js::ProfileId callSiteId = static_cast<Js::ProfileId>(callInstr->AsProfiledInstr()->u.profileId);
  3121. Assert(callSiteId >= 0);
  3122. Js::ProxyEntryPointInfo *defaultEntryPointInfo = funcBody->GetDefaultEntryPointInfo();
  3123. Assert(defaultEntryPointInfo->IsFunctionEntryPointInfo());
  3124. Js::FunctionEntryPointInfo *functionEntryPointInfo = static_cast<Js::FunctionEntryPointInfo*>(defaultEntryPointInfo);
  3125. JsFunctionCodeGen *workItem = JitAnew(this->topFunc->m_alloc, JsFunctionCodeGen,
  3126. funcBody->GetScriptContext()->GetNativeCodeGenerator(), funcBody, functionEntryPointInfo, this->topFunc->IsJitInDebugMode());
  3127. workItem->SetRecyclableData(JitAnew(this->topFunc->m_alloc, Js::CodeGenRecyclableData, inlineeData));
  3128. workItem->SetJitMode(this->topFunc->m_workItem->GetJitMode());
  3129. IR::RegOpnd * returnValueOpnd;
  3130. Js::RegSlot returnRegSlot;
  3131. if (callInstr->GetDst())
  3132. {
  3133. returnValueOpnd = callInstr->UnlinkDst()->AsRegOpnd();
  3134. returnRegSlot = returnValueOpnd->m_sym->GetByteCodeRegSlot();
  3135. }
  3136. else
  3137. {
  3138. returnValueOpnd = nullptr;
  3139. returnRegSlot = Js::Constants::NoRegister;
  3140. }
  3141. const auto profileInfo =
  3142. JitAnew(
  3143. this->topFunc->m_alloc,
  3144. Js::ReadOnlyDynamicProfileInfo,
  3145. funcBody->HasDynamicProfileInfo() ? funcBody->GetAnyDynamicProfileInfo() : nullptr,
  3146. this->topFunc->IsBackgroundJIT() ? this->topFunc->m_alloc : nullptr);
  3147. Js::EntryPointPolymorphicInlineCacheInfo * entryPointPolymorphicInlineCacheInfo = this->topFunc->m_workItem->GetEntryPoint()->GetPolymorphicInlineCacheInfo();
  3148. Func *inlinee = JitAnew(this->topFunc->m_alloc,
  3149. Func,
  3150. this->topFunc->m_alloc,
  3151. workItem,
  3152. callInstr->m_func->m_runtimeData ?
  3153. callInstr->m_func->m_runtimeData->GetInlineeForTargetInlinee(profileId, funcBody) :
  3154. this->topFunc->GetJnFunction()->GetInlineeCodeGenRuntimeDataForTargetInlinee(profileId, funcBody),
  3155. entryPointPolymorphicInlineCacheInfo ? entryPointPolymorphicInlineCacheInfo->GetInlineeInfo(funcBody) : nullptr,
  3156. this->topFunc->GetCodeGenAllocators(),
  3157. this->topFunc->GetNumberAllocator(),
  3158. profileInfo,
  3159. this->topFunc->GetCodeGenProfiler(),
  3160. this->topFunc->IsBackgroundJIT(),
  3161. callInstr->m_func,
  3162. callInstr->m_next->GetByteCodeOffset(),
  3163. returnRegSlot,
  3164. isCtor,
  3165. callSiteId,
  3166. false);
  3167. return InlineFunctionCommon(callInstr, originalCallTargetStackSym, funcBody, inlinee, instrNext, returnValueOpnd, inlineBailoutChecksBeforeInstr, symCallerThis, recursiveInlineDepth, safeThis);
  3168. }
  3169. bool
  3170. Inline::SplitConstructorCall(IR::Instr *const newObjInstr, const bool isInlined, const bool isFixed, IR::Instr** createObjInstrOut, IR::Instr** callCtorInstrOut) const
  3171. {
  3172. Assert(newObjInstr);
  3173. Assert(newObjInstr->m_opcode == Js::OpCode::NewScObject);
  3174. Assert(newObjInstr->GetSrc1());
  3175. Assert(newObjInstr->GetSrc2());
  3176. this->topFunc->SetHasTempObjectProducingInstr(true);
  3177. return
  3178. SplitConstructorCallCommon(
  3179. newObjInstr,
  3180. newObjInstr->GetSrc2(),
  3181. Js::OpCode::NewScObjectNoCtor,
  3182. isInlined,
  3183. isFixed,
  3184. createObjInstrOut,
  3185. callCtorInstrOut);
  3186. }
  3187. bool
  3188. Inline::SplitConstructorCallCommon(
  3189. IR::Instr *const newObjInstr,
  3190. IR::Opnd *const lastArgOpnd,
  3191. const Js::OpCode newObjOpCode,
  3192. const bool isInlined,
  3193. const bool isFixed,
  3194. IR::Instr** createObjInstrOut,
  3195. IR::Instr** callCtorInstrOut) const
  3196. {
  3197. Assert(newObjInstr);
  3198. Assert(newObjInstr->GetSrc1());
  3199. Assert(lastArgOpnd);
  3200. Assert(isInlined || isFixed);
  3201. const auto callerFunc = newObjInstr->m_func;
  3202. // Call the NoCtor version of NewScObject
  3203. // Use a temporary register for the newly allocated object (before the call to ctor) - even if we know we'll return this
  3204. // object from the whole operation. That's so that we don't trash the bytecode register if we need to bail out at
  3205. // object allocation (bytecode instruction has the form [Profiled]NewScObject R6 = R6).
  3206. IR::RegOpnd* createObjDst = nullptr;
  3207. IR::Instr* createObjInstr = nullptr;
  3208. const Js::JitTimeConstructorCache* constructorCache;
  3209. bool returnCreatedObject = false;
  3210. bool skipNewScObj = false;
  3211. if (newObjInstr->IsProfiledInstr())
  3212. {
  3213. Js::ProfileId profiledCallSiteId = static_cast<Js::ProfileId>(newObjInstr->AsProfiledInstr()->u.profileId);
  3214. constructorCache = newObjInstr->m_func->GetConstructorCache(profiledCallSiteId);
  3215. returnCreatedObject = constructorCache != nullptr && constructorCache->ctorHasNoExplicitReturnValue;
  3216. skipNewScObj = constructorCache != nullptr && constructorCache->skipNewScObject;
  3217. if (!skipNewScObj)
  3218. {
  3219. createObjDst = IR::RegOpnd::New(TyVar, callerFunc);
  3220. createObjInstr = IR::ProfiledInstr::New(newObjOpCode, createObjDst, newObjInstr->GetSrc1(), callerFunc);
  3221. createObjInstr->AsProfiledInstr()->u.profileId = profiledCallSiteId;
  3222. }
  3223. }
  3224. else
  3225. {
  3226. constructorCache = nullptr;
  3227. createObjDst = IR::RegOpnd::New(TyVar, callerFunc);
  3228. createObjInstr = IR::Instr::New(newObjOpCode, createObjDst, newObjInstr->GetSrc1(), callerFunc);
  3229. }
  3230. Assert(!isInlined || !skipNewScObj);
  3231. Assert(isFixed || !skipNewScObj);
  3232. // For new Object() and new Array() we have special fast helpers. We'll let the lowerer convert this instruction directly
  3233. // into a call to one of these helpers.
  3234. if (skipNewScObj)
  3235. {
  3236. Js::JavascriptFunction* ctor = newObjInstr->GetFixedFunction();
  3237. Js::FunctionInfo* ctorInfo = ctor->GetFunctionInfo();
  3238. if ((ctorInfo == &Js::JavascriptObject::EntryInfo::NewInstance || ctorInfo == &Js::JavascriptArray::EntryInfo::NewInstance) &&
  3239. newObjInstr->HasEmptyArgOutChain())
  3240. {
  3241. return false;
  3242. }
  3243. }
  3244. IR::Opnd* thisPtrOpnd;
  3245. if (createObjInstr != nullptr)
  3246. {
  3247. createObjInstr->SetByteCodeOffset(newObjInstr);
  3248. createObjInstr->GetSrc1()->SetIsJITOptimizedReg(true);
  3249. newObjInstr->InsertBefore(createObjInstr);
  3250. createObjDst->SetValueType(ValueType::GetObject(ObjectType::UninitializedObject));
  3251. thisPtrOpnd = createObjDst;
  3252. }
  3253. else
  3254. {
  3255. thisPtrOpnd = IR::AddrOpnd::NewNull(newObjInstr->m_func);
  3256. }
  3257. // Pass the new object to the constructor function with an ArgOut
  3258. const auto thisArgOpnd = IR::SymOpnd::New(callerFunc->m_symTable->GetArgSlotSym(1), TyVar, callerFunc);
  3259. auto instr = IR::Instr::New(Js::OpCode::ArgOut_A, thisArgOpnd, thisPtrOpnd, lastArgOpnd, callerFunc);
  3260. instr->SetByteCodeOffset(newObjInstr);
  3261. instr->GetDst()->SetIsJITOptimizedReg(true);
  3262. instr->GetSrc2()->SetIsJITOptimizedReg(true);
  3263. newObjInstr->InsertBefore(instr);
  3264. // Call the constructor using CallI with isCtorCall set. If we inline the constructor, and the inlined constructor
  3265. // bails out, the interpreter would be entered with CallFlags_Value as well. If the interpreter starts using the
  3266. // call flags, the proper call flags will need to be specified here by using a different op code specific to constructors.
  3267. if (isFixed)
  3268. {
  3269. newObjInstr->m_opcode = Js::OpCode::CallIFixed;
  3270. }
  3271. else
  3272. {
  3273. newObjInstr->m_opcode = Js::OpCode::CallI;
  3274. }
  3275. newObjInstr->isCtorCall = true;
  3276. if(newObjInstr->GetSrc2())
  3277. {
  3278. newObjInstr->FreeSrc2();
  3279. }
  3280. newObjInstr->SetSrc2(thisArgOpnd);
  3281. const auto insertBeforeInstr = newObjInstr->m_next;
  3282. Assert(insertBeforeInstr);
  3283. const auto nextByteCodeOffsetInstr = newObjInstr->GetNextRealInstrOrLabel();
  3284. // Determine which object to use as the final result of NewScObject, the object passed into the constructor as 'this', or
  3285. // the object returned by the constructor. We only need this if we don't have a hard-coded constructor cache, or if the
  3286. // constructor returns something explicitly. Otherwise, we simply return the object we allocated and passed to the constructor.
  3287. if (returnCreatedObject)
  3288. {
  3289. instr = IR::Instr::New(Js::OpCode::Ld_A, newObjInstr->GetDst(), createObjDst, callerFunc);
  3290. instr->SetByteCodeOffset(nextByteCodeOffsetInstr);
  3291. instr->GetDst()->SetIsJITOptimizedReg(true);
  3292. instr->GetSrc1()->SetIsJITOptimizedReg(true);
  3293. insertBeforeInstr->InsertBefore(instr);
  3294. }
  3295. else if (!skipNewScObj)
  3296. {
  3297. Assert(createObjDst != newObjInstr->GetDst());
  3298. // Since we're not returning the default new object, the constructor must be returning something explicitly. We don't
  3299. // know at this point whether it's an object or not. If the constructor is later inlined, the value type will be determined
  3300. // from the flow in glob opt. Otherwise, we'll need to emit an object check.
  3301. newObjInstr->GetDst()->SetValueType(ValueType::Uninitialized);
  3302. instr = IR::Instr::New(Js::OpCode::GetNewScObject, newObjInstr->GetDst(), newObjInstr->GetDst(), createObjDst, callerFunc);
  3303. instr->SetByteCodeOffset(nextByteCodeOffsetInstr);
  3304. instr->GetDst()->SetIsJITOptimizedReg(true);
  3305. instr->GetSrc1()->SetIsJITOptimizedReg(true);
  3306. insertBeforeInstr->InsertBefore(instr);
  3307. }
  3308. // Update the NewScObject cache, but only if we don't have a hard-coded constructor cache. We only clone caches that
  3309. // don't require update, and once updated a cache never requires an update again.
  3310. if (constructorCache == nullptr)
  3311. {
  3312. instr = IR::Instr::New(Js::OpCode::UpdateNewScObjectCache, callerFunc);
  3313. instr->SetSrc1(newObjInstr->GetSrc1()); // constructor function
  3314. instr->SetSrc2(newObjInstr->GetDst()); // the new object
  3315. instr->SetByteCodeOffset(nextByteCodeOffsetInstr);
  3316. instr->GetSrc1()->SetIsJITOptimizedReg(true);
  3317. instr->GetSrc2()->SetIsJITOptimizedReg(true);
  3318. insertBeforeInstr->InsertBefore(instr);
  3319. }
  3320. if (createObjInstrOut != nullptr)
  3321. {
  3322. *createObjInstrOut = createObjInstr;
  3323. }
  3324. if (callCtorInstrOut != nullptr)
  3325. {
  3326. *callCtorInstrOut = newObjInstr;
  3327. }
  3328. return true;
  3329. }
  3330. void
  3331. Inline::InsertObjectCheck(IR::Instr *callInstr, IR::Instr* insertBeforeInstr, IR::Instr*bailOutIfNotObject)
  3332. {
  3333. // Bailout if 'functionRegOpnd' is not an object.
  3334. bailOutIfNotObject->SetSrc1(callInstr->GetSrc1()->AsRegOpnd());
  3335. bailOutIfNotObject->SetByteCodeOffset(insertBeforeInstr);
  3336. insertBeforeInstr->InsertBefore(bailOutIfNotObject);
  3337. }
  3338. void
  3339. Inline::InsertFunctionTypeIdCheck(IR::Instr *callInstr, IR::Instr* insertBeforeInstr, IR::Instr* bailOutIfNotJsFunction)
  3340. {
  3341. // functionTypeRegOpnd = Ld functionRegOpnd->type
  3342. IR::IndirOpnd *functionTypeIndirOpnd = IR::IndirOpnd::New(callInstr->GetSrc1()->AsRegOpnd(), Js::RecyclableObject::GetOffsetOfType(), TyMachPtr, callInstr->m_func);
  3343. IR::RegOpnd *functionTypeRegOpnd = IR::RegOpnd::New(TyVar, this->topFunc);
  3344. IR::Instr *instr = IR::Instr::New(Js::OpCode::Ld_A, functionTypeRegOpnd, functionTypeIndirOpnd, callInstr->m_func);
  3345. if(instr->m_func->HasByteCodeOffset())
  3346. {
  3347. instr->SetByteCodeOffset(insertBeforeInstr);
  3348. }
  3349. insertBeforeInstr->InsertBefore(instr);
  3350. CompileAssert(sizeof(Js::TypeId) == sizeof(int32));
  3351. // if (functionTypeRegOpnd->typeId != TypeIds_Function) goto $noInlineLabel
  3352. // BrNeq_I4 $noInlineLabel, functionTypeRegOpnd->typeId, TypeIds_Function
  3353. IR::IndirOpnd *functionTypeIdIndirOpnd = IR::IndirOpnd::New(functionTypeRegOpnd, Js::Type::GetOffsetOfTypeId(), TyInt32, callInstr->m_func);
  3354. IR::IntConstOpnd *typeIdFunctionConstOpnd = IR::IntConstOpnd::New(Js::TypeIds_Function, TyInt32, callInstr->m_func);
  3355. bailOutIfNotJsFunction->SetSrc1(functionTypeIdIndirOpnd);
  3356. bailOutIfNotJsFunction->SetSrc2(typeIdFunctionConstOpnd);
  3357. insertBeforeInstr->InsertBefore(bailOutIfNotJsFunction);
  3358. }
  3359. void
  3360. Inline::InsertJsFunctionCheck(IR::Instr *callInstr, IR::Instr *insertBeforeInstr, IR::BailOutKind bailOutKind)
  3361. {
  3362. // This function only inserts bailout for tagged int & TypeIds_Function.
  3363. // As of now this is only used for polymorphic inlining.
  3364. Assert(bailOutKind == IR::BailOutOnPolymorphicInlineFunction);
  3365. Assert(insertBeforeInstr);
  3366. Assert(insertBeforeInstr->m_func == callInstr->m_func);
  3367. // bailOutIfNotFunction is primary bailout instruction
  3368. IR::Instr* bailOutIfNotFunction = IR::BailOutInstr::New(Js::OpCode::BailOnNotEqual, bailOutKind, insertBeforeInstr, callInstr->m_func);
  3369. IR::Instr *bailOutIfNotObject = IR::BailOutInstr::New(Js::OpCode::BailOnNotObject, bailOutKind, bailOutIfNotFunction->GetBailOutInfo(),callInstr->m_func);
  3370. InsertObjectCheck(callInstr, insertBeforeInstr, bailOutIfNotObject);
  3371. InsertFunctionTypeIdCheck(callInstr, insertBeforeInstr, bailOutIfNotFunction);
  3372. }
  3373. void
  3374. Inline::InsertFunctionBodyCheck(IR::Instr *callInstr, IR::Instr *insertBeforeInstr, IR::Instr* bailoutInstr, Js::FunctionInfo *funcInfo)
  3375. {
  3376. // if (JavascriptFunction::FromVar(r1)->functionInfo != funcInfo) goto noInlineLabel
  3377. // BrNeq_I4 noInlineLabel, r1->functionInfo, funcInfo
  3378. IR::IndirOpnd* funcBody = IR::IndirOpnd::New(callInstr->GetSrc1()->AsRegOpnd(), Js::JavascriptFunction::GetOffsetOfFunctionInfo(), TyMachPtr, callInstr->m_func);
  3379. IR::AddrOpnd* inlinedFuncBody = IR::AddrOpnd::New(funcInfo, IR::AddrOpndKindDynamicFunctionBody, callInstr->m_func);
  3380. bailoutInstr->SetSrc1(funcBody);
  3381. bailoutInstr->SetSrc2(inlinedFuncBody);
  3382. insertBeforeInstr->InsertBefore(bailoutInstr);
  3383. }
  3384. void
  3385. Inline::InsertFunctionObjectCheck(IR::Instr *callInstr, IR::Instr *insertBeforeInstr, IR::Instr *bailOutInstr, Js::FunctionInfo *funcInfo)
  3386. {
  3387. Js::BuiltinFunction index = Js::JavascriptLibrary::GetBuiltInForFuncInfo(funcInfo, callInstr->m_func->GetScriptContext());
  3388. AssertMsg(index < Js::BuiltinFunction::Count, "Invalid built-in index on a call target marked as built-in");
  3389. bailOutInstr->SetSrc1(callInstr->GetSrc1()->AsRegOpnd());
  3390. bailOutInstr->SetSrc2(IR::IntConstOpnd::New(index, TyInt32, callInstr->m_func));
  3391. insertBeforeInstr->InsertBefore(bailOutInstr);
  3392. }
  3393. IR::Instr *
  3394. Inline::PrepareInsertionPoint(IR::Instr *callInstr, Js::FunctionInfo *funcInfo, IR::Instr *insertBeforeInstr, IR::BailOutKind bailOutKind)
  3395. {
  3396. Assert(insertBeforeInstr);
  3397. Assert(insertBeforeInstr->m_func == callInstr->m_func);
  3398. Assert(bailOutKind == IR::BailOutOnInlineFunction);
  3399. // FunctionBody check is the primary bailout instruction, create it first
  3400. IR::BailOutInstr* primaryBailOutInstr = IR::BailOutInstr::New(Js::OpCode::BailOnNotEqual, bailOutKind, insertBeforeInstr, callInstr->m_func);
  3401. // 1. Bailout if function object is not an object.
  3402. IR::Instr *bailOutIfNotObject = IR::BailOutInstr::New(Js::OpCode::BailOnNotObject,
  3403. bailOutKind,
  3404. primaryBailOutInstr->GetBailOutInfo(),
  3405. callInstr->m_func);
  3406. InsertObjectCheck(callInstr, insertBeforeInstr, bailOutIfNotObject);
  3407. // 2. Bailout if function object is not a TypeId_Function
  3408. IR::Instr* bailOutIfNotJsFunction = IR::BailOutInstr::New(Js::OpCode::BailOnNotEqual, bailOutKind, primaryBailOutInstr->GetBailOutInfo(), callInstr->m_func);
  3409. InsertFunctionTypeIdCheck(callInstr, insertBeforeInstr, bailOutIfNotJsFunction);
  3410. // 3. Bailout if function body doesn't match funcInfo
  3411. InsertFunctionBodyCheck(callInstr, insertBeforeInstr, primaryBailOutInstr, funcInfo);
  3412. return primaryBailOutInstr;
  3413. }
  3414. uint Inline::CountActuals(IR::Instr *callInstr)
  3415. {
  3416. IR::Opnd *linkOpnd = callInstr->GetSrc2();
  3417. uint actualCount = 0;
  3418. if (linkOpnd->IsSymOpnd())
  3419. {
  3420. IR::Instr *argInstr;
  3421. do
  3422. {
  3423. Assert(linkOpnd->IsSymOpnd());
  3424. StackSym *sym = linkOpnd->AsSymOpnd()->m_sym->AsStackSym();
  3425. Assert(sym->m_isSingleDef);
  3426. Assert(sym->IsArgSlotSym());
  3427. argInstr = sym->m_instrDef;
  3428. ++actualCount;
  3429. linkOpnd = argInstr->GetSrc2();
  3430. }
  3431. while (linkOpnd->IsSymOpnd());
  3432. }
  3433. return actualCount;
  3434. }
  3435. bool Inline::InlConstFoldArg(IR::Instr *instr, __in_ecount_opt(callerArgOutCount) IR::Instr *callerArgOuts[], Js::ArgSlot callerArgOutCount)
  3436. {
  3437. Assert(instr->m_opcode == Js::OpCode::ArgOut_A);
  3438. if (PHASE_OFF(Js::InlinerConstFoldPhase, instr->m_func->GetTopFunc()))
  3439. {
  3440. return false;
  3441. }
  3442. IR::Opnd *src1 = instr->GetSrc1();
  3443. IntConstType value;
  3444. if (!src1->IsRegOpnd())
  3445. {
  3446. return false;
  3447. }
  3448. StackSym *sym = instr->GetSrc1()->AsRegOpnd()->m_sym;
  3449. if (!sym->IsSingleDef())
  3450. {
  3451. return false;
  3452. }
  3453. IR::Instr *instrDef = sym->GetInstrDef();
  3454. if (!this->InlConstFold(instrDef, &value, callerArgOuts, callerArgOutCount))
  3455. {
  3456. return false;
  3457. }
  3458. return true;
  3459. }
  3460. bool Inline::InlConstFold(IR::Instr *instr, IntConstType *pValue, __in_ecount_opt(callerArgOutCount) IR::Instr *callerArgOuts[], Js::ArgSlot callerArgOutCount)
  3461. {
  3462. IR::Opnd *src1 = instr->GetSrc1();
  3463. if (!src1)
  3464. {
  3465. return false;
  3466. }
  3467. switch (src1->GetKind())
  3468. {
  3469. case IR::OpndKindReg:
  3470. // Walk the tree below
  3471. break;
  3472. case IR::OpndKindIntConst:
  3473. if (instr->m_opcode == Js::OpCode::LdC_A_I4)
  3474. {
  3475. // Found a constant
  3476. *pValue = src1->AsIntConstOpnd()->GetValue();
  3477. return true;
  3478. }
  3479. return false;
  3480. case IR::OpndKindSym:
  3481. if (callerArgOuts && instr->m_opcode == Js::OpCode::ArgIn_A)
  3482. {
  3483. // We have an ArgIn. Walk the caller's ArgOut tree to see if a constant
  3484. // is passed in to the inlinee.
  3485. Assert(callerArgOuts && callerArgOutCount != (Js::ArgSlot) - 1);
  3486. Assert(src1->AsSymOpnd()->m_sym->AsStackSym()->IsParamSlotSym());
  3487. Js::ArgSlot paramSlot = src1->AsSymOpnd()->m_sym->AsStackSym()->GetParamSlotNum();
  3488. if (paramSlot <= callerArgOutCount)
  3489. {
  3490. IR::Instr *argOut = callerArgOuts[paramSlot - 1];
  3491. IR::Opnd *argOutSrc1 = argOut->GetSrc1();
  3492. if (!argOutSrc1->IsRegOpnd())
  3493. {
  3494. return false;
  3495. }
  3496. StackSym *sym = argOutSrc1->AsRegOpnd()->m_sym;
  3497. if (!sym->IsSingleDef())
  3498. {
  3499. return false;
  3500. }
  3501. IR::Instr *instrDef = sym->GetInstrDef();
  3502. // Walk the caller
  3503. return InlConstFold(instrDef, pValue, nullptr, (Js::ArgSlot) - 1);
  3504. }
  3505. }
  3506. else if (src1->AsSymOpnd()->IsPropertySymOpnd())
  3507. {
  3508. // See if we have a LdFld of a fixed field.
  3509. Js::Var var = TryOptimizeInstrWithFixedDataProperty(instr);
  3510. if (!Js::TaggedInt::Is(var))
  3511. {
  3512. return false;
  3513. }
  3514. else
  3515. {
  3516. *pValue = Js::TaggedInt::ToInt32(var);
  3517. return true;
  3518. }
  3519. }
  3520. return false;
  3521. default:
  3522. return false;
  3523. }
  3524. // All that is left is RegOpnds
  3525. Assert(src1->IsRegOpnd());
  3526. StackSym *sym = instr->GetSrc1()->AsRegOpnd()->m_sym;
  3527. if (!sym->IsSingleDef())
  3528. {
  3529. return false;
  3530. }
  3531. if (!src1 || !src1->IsRegOpnd() || !src1->AsRegOpnd()->m_sym->IsSingleDef())
  3532. {
  3533. return false;
  3534. }
  3535. IR::Opnd *src2 = instr->GetSrc2();
  3536. if (src2)
  3537. {
  3538. if (!src2->IsRegOpnd() || !src2->AsRegOpnd()->m_sym->IsSingleDef())
  3539. {
  3540. return false;
  3541. }
  3542. }
  3543. // See if src1 can be folded to a constant
  3544. if (!InlConstFold(src1->AsRegOpnd()->m_sym->GetInstrDef(), pValue, callerArgOuts, callerArgOutCount))
  3545. {
  3546. return false;
  3547. }
  3548. IntConstType src1Constant = *pValue;
  3549. // See if src2 (unless it is unary) can be folded to a constant
  3550. if (src2 && !InlConstFold(src2->AsRegOpnd()->m_sym->GetInstrDef(), pValue, callerArgOuts, callerArgOutCount))
  3551. {
  3552. return false;
  3553. }
  3554. // Now let's try to constant fold the current instruction
  3555. if (src2)
  3556. {
  3557. IntConstType src2Constant = *pValue;
  3558. if (!instr->BinaryCalculator(src1Constant, src2Constant, pValue)
  3559. || !Math::FitsInDWord(*pValue))
  3560. {
  3561. return false;
  3562. }
  3563. // Success
  3564. IR::ByteCodeUsesInstr * byteCodeInstr = IR::ByteCodeUsesInstr::New(instr->m_func);
  3565. byteCodeInstr->SetByteCodeOffset(instr);
  3566. StackSym *src1Sym = src1->AsRegOpnd()->m_sym;
  3567. StackSym *src2Sym = src2->AsRegOpnd()->m_sym;
  3568. if (src1Sym->HasByteCodeRegSlot() || src2Sym->HasByteCodeRegSlot())
  3569. {
  3570. if (src1Sym->HasByteCodeRegSlot())
  3571. {
  3572. byteCodeInstr->Set(src1Sym->m_id);
  3573. }
  3574. if (src2Sym->HasByteCodeRegSlot())
  3575. {
  3576. byteCodeInstr->Set(src2Sym->m_id);
  3577. }
  3578. instr->InsertBefore(byteCodeInstr);
  3579. }
  3580. #if DBG_DUMP
  3581. if (Js::Configuration::Global.flags.Trace.IsEnabled(Js::InlinerConstFoldPhase, this->topFunc->GetSourceContextId(), this->topFunc->GetLocalFunctionId()))
  3582. {
  3583. Output::Print(L"Constant folding to %d\n", *pValue);
  3584. instr->Dump();
  3585. }
  3586. #endif
  3587. instr->m_opcode = Js::OpCode::LdC_A_I4;
  3588. instr->ReplaceSrc1(IR::IntConstOpnd::New(*pValue, TyInt32, instr->m_func));
  3589. instr->GetDst()->AsRegOpnd()->m_sym->SetIsConst();
  3590. instr->FreeSrc2();
  3591. }
  3592. else
  3593. {
  3594. if (!instr->UnaryCalculator(src1Constant, pValue)
  3595. || !Math::FitsInDWord(*pValue))
  3596. {
  3597. // Skip over BytecodeArgOutCapture
  3598. if (instr->m_opcode == Js::OpCode::BytecodeArgOutCapture)
  3599. {
  3600. return true;
  3601. }
  3602. return false;
  3603. }
  3604. // Success
  3605. StackSym *src1Sym = src1->AsRegOpnd()->m_sym;
  3606. if (src1Sym->HasByteCodeRegSlot())
  3607. {
  3608. IR::ByteCodeUsesInstr * byteCodeInstr = IR::ByteCodeUsesInstr::New(instr->m_func);
  3609. byteCodeInstr->SetByteCodeOffset(instr);
  3610. byteCodeInstr->Set(src1Sym->m_id);
  3611. instr->InsertBefore(byteCodeInstr);
  3612. }
  3613. #if DBG_DUMP
  3614. if (Js::Configuration::Global.flags.Trace.IsEnabled(Js::InlinerConstFoldPhase, this->topFunc->GetSourceContextId(), this->topFunc->GetLocalFunctionId()))
  3615. {
  3616. Output::Print(L"Constant folding to %d\n", *pValue);
  3617. instr->Dump();
  3618. }
  3619. #endif
  3620. instr->m_opcode = Js::OpCode::LdC_A_I4;
  3621. instr->ReplaceSrc1(IR::IntConstOpnd::New(*pValue, TyInt32, instr->m_func));
  3622. instr->GetDst()->AsRegOpnd()->m_sym->SetIsConst();
  3623. }
  3624. return true;
  3625. }
  3626. Js::ArgSlot
  3627. Inline::MapActuals(IR::Instr *callInstr, __out_ecount(maxParamCount) IR::Instr *argOuts[],
  3628. Js::ArgSlot formalCount,
  3629. Func* inlinee,
  3630. Js::ProfileId callSiteId,
  3631. bool *stackArgsArgOutExpanded,
  3632. IR::Instr *argOutsExtra[],
  3633. Js::ArgSlot maxParamCount /* = Js::InlineeCallInfo::MaxInlineeArgoutCount*/)
  3634. {
  3635. AnalysisAssert(formalCount <= maxParamCount);
  3636. IR::Opnd *linkOpnd = callInstr->GetSrc2();
  3637. Js::ArgSlot actualCount = 0;
  3638. *stackArgsArgOutExpanded = false;
  3639. uint inlineeFrameSlot = currentInlineeFrameSlot + (Js::Constants::InlineeMetaArgCount - 1);
  3640. uint fixupArgoutCount = 0;
  3641. if (inlinee)
  3642. {
  3643. bool hasArgumentsAccess = this->GetInlineeHasArgumentObject(inlinee);
  3644. inlinee->SetHasUnoptimizedArgumentsAccess(hasArgumentsAccess);
  3645. }
  3646. if (linkOpnd->IsSymOpnd())
  3647. {
  3648. IR::Instr *argInstr;
  3649. do
  3650. {
  3651. Assert(linkOpnd->IsSymOpnd());
  3652. StackSym *sym = linkOpnd->AsSymOpnd()->m_sym->AsStackSym();
  3653. Assert(sym->m_isSingleDef);
  3654. Assert(sym->IsArgSlotSym());
  3655. sym->m_isInlinedArgSlot = true;
  3656. this->topFunc->SetArgOffset(sym, (inlineeFrameSlot + sym->GetArgSlotNum()) * MachPtr);
  3657. argInstr = sym->m_instrDef;
  3658. if (argInstr->m_opcode == Js::OpCode::ArgOut_A)
  3659. {
  3660. if(inlinee)
  3661. {
  3662. if (!inlinee->GetHasUnoptimizedArgumentsAcccess())
  3663. {
  3664. // This allows us to markTemp the argOut source.
  3665. argInstr->m_opcode = Js::OpCode::ArgOut_A_Inline;
  3666. }
  3667. }
  3668. argInstr->GenerateBytecodeArgOutCapture();
  3669. }
  3670. // Expand
  3671. //
  3672. // s31 ArgOut_A s32
  3673. // s30 ArgOut_A_FromStackArgs s31
  3674. //
  3675. // to
  3676. //
  3677. // s31 ArgOut_A(_Inline) s32
  3678. // sXX ArgOut_A_FixupForStackArgs s31
  3679. // .
  3680. // .
  3681. // s34 ArgOut_A_FixupForStackArgs sXX
  3682. // s30 ArgOut_A_FromStackArgs s34
  3683. if (inlinee && argInstr->m_opcode == Js::OpCode::ArgOut_A_FromStackArgs)
  3684. {
  3685. IR::Instr * argFixupInstr;
  3686. for(uint currentFormal = 1; currentFormal < formalCount; currentFormal++)
  3687. {
  3688. StackSym* newStackSym = StackSym::NewArgSlotSym(sym->GetArgSlotNum(), argInstr->m_func);
  3689. newStackSym->m_isInlinedArgSlot = true;
  3690. IR::SymOpnd * linkOpnd = IR::SymOpnd::New(newStackSym, sym->GetType(), argInstr->m_func);
  3691. IR::Opnd * undefined = IR::AddrOpnd::New(this->topFunc->GetScriptContext()->GetLibrary()->GetUndefined(),
  3692. IR::AddrOpndKindDynamicVar, this->topFunc, true);
  3693. undefined->SetValueType(ValueType::Undefined);
  3694. argFixupInstr = IR::Instr::New(Js::OpCode::ArgOut_A_FixupForStackArgs, linkOpnd, undefined, argInstr->GetSrc2(), argInstr->m_func);
  3695. argInstr->InsertBefore(argFixupInstr);
  3696. argInstr->ReplaceSrc2(argFixupInstr->GetDst());
  3697. sym->IncrementArgSlotNum();
  3698. argInstr->m_func->SetArgOffset(sym, (inlineeFrameSlot + sym->GetArgSlotNum()) * MachPtr);
  3699. argFixupInstr->GenerateArgOutSnapshot();
  3700. fixupArgoutCount++;
  3701. }
  3702. // Now that the arguments object has been expanded, we don't require the sym corresponding to it.
  3703. IR::IntConstOpnd* callSiteIdOpnd = IR::IntConstOpnd::New(callSiteId, TyUint16, argInstr->m_func);
  3704. argInstr->ReplaceSrc1(callSiteIdOpnd);
  3705. // Don't count ArgOut_A_FromStackArgs as an actual, when it has been expanded
  3706. --actualCount;
  3707. *stackArgsArgOutExpanded = true;
  3708. }
  3709. ++actualCount;
  3710. const Js::ArgSlot currentActual = sym->GetArgSlotNum() - 1;
  3711. if (currentActual < formalCount)
  3712. {
  3713. Assert(currentActual < Js::InlineeCallInfo::MaxInlineeArgoutCount);
  3714. argOuts[currentActual] = argInstr;
  3715. }
  3716. // We don't want to treat ArgOut_A_FromStackArgs as an actual arg.
  3717. else if (argInstr->m_opcode != Js::OpCode::ArgOut_A_FromStackArgs)
  3718. {
  3719. Assert(currentActual <= Js::InlineeCallInfo::MaxInlineeArgoutCount);
  3720. if(argOutsExtra)
  3721. {
  3722. argOutsExtra[currentActual] = argInstr;
  3723. if (currentActual < maxParamCount)
  3724. {
  3725. __analysis_assume(currentActual < Js::InlineeCallInfo::MaxInlineeArgoutCount);
  3726. argOuts[currentActual] = nullptr;
  3727. }
  3728. }
  3729. }
  3730. linkOpnd = argInstr->GetSrc2();
  3731. }
  3732. while (linkOpnd->IsSymOpnd());
  3733. #if DBG
  3734. Assert(actualCount <= Js::InlineeCallInfo::MaxInlineeArgoutCount);
  3735. for(Js::ArgSlot i = 0; i < min(actualCount, formalCount); ++i)
  3736. {
  3737. #pragma prefast(suppress:6001)
  3738. Assert(argOuts[i]);
  3739. }
  3740. #endif
  3741. }
  3742. Assert(linkOpnd->IsRegOpnd());
  3743. Assert(linkOpnd->AsRegOpnd()->m_sym->m_isSingleDef);
  3744. Js::OpCode startCallOpCode = linkOpnd->AsRegOpnd()->m_sym->m_instrDef->m_opcode;
  3745. Assert(startCallOpCode == Js::OpCode::StartCall);
  3746. // Update the count in StartCall to reflect
  3747. // 1. ArgOut_A_FromStackArgs is not an actual once it has been expanded.
  3748. // 2. The expanded argouts (from ArgOut_A_FromStackArgs).
  3749. //
  3750. // Note that the StartCall will reflect the formal count only as of now; the actual count would be set during MapFormals
  3751. if(*stackArgsArgOutExpanded)
  3752. {
  3753. // TODO: Is an underflow here intended, it triggers on test\inlining\OS_2733280.js
  3754. IR::IntConstOpnd * countOpnd = linkOpnd->AsRegOpnd()->m_sym->m_instrDef->GetSrc1()->AsIntConstOpnd();
  3755. int32 count = countOpnd->AsInt32();
  3756. count += fixupArgoutCount - 1;
  3757. countOpnd->SetValue(count);
  3758. callInstr->m_func->EnsureCallSiteToArgumentsOffsetFixupMap();
  3759. Assert(!(callInstr->m_func->callSiteToArgumentsOffsetFixupMap->ContainsKey(callSiteId)));
  3760. callInstr->m_func->callSiteToArgumentsOffsetFixupMap->Add(callSiteId, fixupArgoutCount - 1);
  3761. }
  3762. Assert(linkOpnd->AsRegOpnd()->m_sym->m_instrDef->GetArgOutCount(/*getInterpreterArgOutCount*/ false) == actualCount);
  3763. // Mark the StartCall's dst as an inlined arg slot as well so we know this is an inlined start call
  3764. // and not adjust the stack height on x86
  3765. linkOpnd->AsRegOpnd()->m_sym->m_isInlinedArgSlot = true;
  3766. // Missing arguments...
  3767. for (Js::ArgSlot i = actualCount; i < formalCount; i++)
  3768. {
  3769. argOuts[i] = nullptr;
  3770. }
  3771. // We may not know the exact number of actuals that "b" gets in a.b.apply just yet, since we have expanded the ArgOut_A_FromStackArgs based on the number of formals "b" accepts.
  3772. // So, return the actualCount stored on the func if the ArgOut_A_FromStackArgs was expanded (and thus, the expanded argouts were accounted for in calculating the local actualCount)
  3773. return *stackArgsArgOutExpanded ? callInstr->m_func->actualCount : actualCount;
  3774. }
  3775. void
  3776. Inline::MapFormals(Func *inlinee,
  3777. __in_ecount(formalCount) IR::Instr *argOuts[],
  3778. uint formalCount,
  3779. uint actualCount,
  3780. IR::RegOpnd *retOpnd,
  3781. IR::Opnd * funcObjOpnd,
  3782. const StackSym *symCallerThis,
  3783. bool stackArgsArgOutExpanded,
  3784. bool fixedFunctionSafeThis,
  3785. IR::Instr *argOutsExtra[])
  3786. {
  3787. IR::SymOpnd *formalOpnd;
  3788. uint argIndex;
  3789. uint formalCountForInlinee;
  3790. IR::Instr * argInstr;
  3791. IR::Opnd * linkOpnd;
  3792. bool fUsesSafeThis = false;
  3793. bool fUsesConstThis = false;
  3794. StackSym *symThis = nullptr;
  3795. Js::Var thisConstVar = nullptr;
  3796. FOREACH_INSTR_EDITING(instr, instrNext, inlinee->m_headInstr)
  3797. {
  3798. switch (instr->m_opcode)
  3799. {
  3800. case Js::OpCode::ArgIn_Rest:
  3801. {
  3802. // We only currently support a statically known number of actuals.
  3803. if (stackArgsArgOutExpanded)
  3804. {
  3805. break;
  3806. }
  3807. IR::Opnd *restDst = instr->GetDst();
  3808. Assert(actualCount < 1 << 24 && formalCount < 1 << 24); // 24 bits for arg count (see CallInfo.h)
  3809. int excess = actualCount - formalCount;
  3810. if (excess < 0)
  3811. {
  3812. excess = 0;
  3813. }
  3814. // Set the type info about the destination so the array offsets get calculated properly.
  3815. restDst->SetValueType(
  3816. ValueType::GetObject(ObjectType::Array)
  3817. .SetHasNoMissingValues(true)
  3818. .SetArrayTypeId(Js::TypeIds_Array));
  3819. restDst->SetValueTypeFixed();
  3820. // Create the array and assign the elements.
  3821. IR::Instr *newArrInstr = IR::Instr::New(Js::OpCode::NewScArray, restDst, IR::IntConstOpnd::New(excess, TyUint32, inlinee), inlinee);
  3822. instr->InsertBefore(newArrInstr);
  3823. for (uint i = formalCount; i < actualCount; ++i)
  3824. {
  3825. IR::IndirOpnd *arrayLocOpnd = IR::IndirOpnd::New(restDst->AsRegOpnd(), i - formalCount, TyVar, inlinee);
  3826. IR::Instr *stElemInstr = IR::Instr::New(Js::OpCode::StElemC, arrayLocOpnd, argOutsExtra[i]->GetBytecodeArgOutCapture()->GetDst(), inlinee);
  3827. instr->InsertBefore(stElemInstr);
  3828. }
  3829. instr->Remove();
  3830. break;
  3831. }
  3832. case Js::OpCode::ArgIn_A:
  3833. formalOpnd = instr->UnlinkSrc1()->AsSymOpnd();
  3834. argIndex = formalOpnd->m_sym->AsStackSym()->GetParamSlotNum() - 1;
  3835. if (argIndex >= formalCount)
  3836. {
  3837. Fatal();
  3838. }
  3839. formalOpnd->Free(this->topFunc);
  3840. if (argOuts[argIndex])
  3841. {
  3842. IR::Instr *argOut = argOuts[argIndex];
  3843. IR::Instr* instrDef;
  3844. if (argOut->HasByteCodeArgOutCapture())
  3845. {
  3846. instrDef = argOut->GetBytecodeArgOutCapture();
  3847. }
  3848. else
  3849. {
  3850. Assert(argOut->m_opcode == Js::OpCode::ArgOut_A_FixupForStackArgs);
  3851. instrDef = argOut->GetArgOutSnapshot();
  3852. }
  3853. instr->SetSrc1(instrDef->GetDst());
  3854. instr->m_opcode = Js::OpCode::Ld_A;
  3855. IR::Opnd* dst = instr->GetDst();
  3856. IR::Opnd* src = instrDef->GetSrc1();
  3857. if (argIndex == 0)
  3858. {
  3859. // Look at the "this" argument source.
  3860. // If it's known to be a normal object (the caller has already guaranteed that, or
  3861. // it was defined by an instruction that produces normal objects), we'll omit CheckThis.
  3862. // If it's a constant value, we'll do the mapping at jit time and copy the final value.
  3863. if (src->IsRegOpnd())
  3864. {
  3865. symThis = dst->AsRegOpnd()->m_sym;
  3866. StackSym *symSrc = src->AsRegOpnd()->m_sym;
  3867. if (symSrc == symCallerThis ||
  3868. symSrc->m_isSafeThis ||
  3869. inlinee->IsInlinedConstructor())
  3870. {
  3871. fUsesSafeThis = true;
  3872. }
  3873. else if (symSrc->m_isSingleDef && symSrc->IsConst() && !symSrc->IsIntConst() && !symSrc->IsFloatConst())
  3874. {
  3875. thisConstVar = symSrc->GetConstAddress();
  3876. fUsesConstThis = true;
  3877. }
  3878. else if(fixedFunctionSafeThis)
  3879. {
  3880. // Note this need to come after we determined that this pointer is not const (undefined/null)
  3881. fUsesSafeThis = true;
  3882. }
  3883. }
  3884. }
  3885. }
  3886. else
  3887. {
  3888. instr->SetSrc1(IR::AddrOpnd::New(this->topFunc->GetScriptContext()->GetLibrary()->GetUndefined(),
  3889. IR::AddrOpndKindDynamicVar, this->topFunc, true));
  3890. instr->GetSrc1()->SetValueType(ValueType::Undefined);
  3891. instr->m_opcode = Js::OpCode::Ld_A;
  3892. }
  3893. break;
  3894. case Js::OpCode::ArgOut_A_FromStackArgs:
  3895. {
  3896. linkOpnd = instr->GetSrc2();
  3897. if(!linkOpnd->IsSymOpnd())
  3898. {
  3899. break;
  3900. }
  3901. Assert(instr->GetSrc1()->IsIntConstOpnd());
  3902. Js::ProfileId callSiteId = static_cast<Js::ProfileId>(instr->GetSrc1()->AsIntConstOpnd()->GetValue());
  3903. argInstr = linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->GetInstrDef();
  3904. while(linkOpnd->IsSymOpnd())
  3905. {
  3906. argInstr = linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->GetInstrDef();
  3907. linkOpnd = argInstr->GetSrc2();
  3908. }
  3909. Assert(linkOpnd->IsRegOpnd());
  3910. Js::OpCode startCallOpCode = linkOpnd->AsRegOpnd()->m_sym->AsStackSym()->GetInstrDef()->m_opcode;
  3911. Assert(startCallOpCode == Js::OpCode::StartCall);
  3912. IR::Instr* startCallForInlinee = linkOpnd->AsRegOpnd()->m_sym->AsStackSym()->GetInstrDef();
  3913. formalCountForInlinee = startCallForInlinee->GetArgOutCount(false); // As of now, StartCall has the formal count
  3914. if(actualCount < formalCountForInlinee)
  3915. {
  3916. RemoveExtraFixupArgouts(instr, formalCountForInlinee - actualCount, callSiteId);
  3917. startCallForInlinee->GetSrc1()->AsIntConstOpnd()->DecrValue(formalCountForInlinee - actualCount); //account for the extra formals
  3918. }
  3919. linkOpnd = instr->GetSrc2();
  3920. argInstr = linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->GetInstrDef();
  3921. argIndex = ((actualCount < formalCountForInlinee) ? actualCount : formalCountForInlinee) - 1;
  3922. for ( ; argIndex > 0; argIndex--)
  3923. {
  3924. if(argInstr->m_opcode != Js::OpCode::ArgOut_A_FixupForStackArgs)
  3925. {
  3926. break;
  3927. }
  3928. Assert(!argInstr->HasByteCodeArgOutCapture()); // ArgOut_A_FixupForStackArgs should not be restored on bailout, so we don't generate ByteCodeArgOutCapture for these argouts.
  3929. IR::Instr* currentArgOutInstr = nullptr;
  3930. if(argOuts[argIndex])
  3931. {
  3932. currentArgOutInstr = argOuts[argIndex];
  3933. }
  3934. else if(argOutsExtra && argOutsExtra[argIndex])
  3935. {
  3936. currentArgOutInstr = argOutsExtra[argIndex];
  3937. }
  3938. if(currentArgOutInstr)
  3939. {
  3940. Assert(currentArgOutInstr->m_opcode == Js::OpCode::ArgOut_A || currentArgOutInstr->m_opcode == Js::OpCode::ArgOut_A_Inline);
  3941. IR::Instr* bytecodeArgoutCapture = currentArgOutInstr->GetBytecodeArgOutCapture();
  3942. IR::Instr* formalArgOutUse = argInstr->GetArgOutSnapshot();
  3943. Assert(formalArgOutUse->m_opcode == Js::OpCode::Ld_A);
  3944. Assert(formalArgOutUse->GetSrc1()->AsAddrOpnd()->m_address == this->topFunc->GetScriptContext()->GetLibrary()->GetUndefined());
  3945. formalArgOutUse->ReplaceSrc1(bytecodeArgoutCapture->GetDst());
  3946. linkOpnd = argInstr->GetSrc2();
  3947. argInstr = linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->GetInstrDef();
  3948. }
  3949. }
  3950. if (formalCountForInlinee < actualCount)
  3951. {
  3952. FixupExtraActualParams(instr, argOuts, argOutsExtra, formalCountForInlinee, actualCount, callSiteId);
  3953. startCallForInlinee->GetSrc1()->AsIntConstOpnd()->IncrValue(actualCount - formalCountForInlinee); //account for the extra actuals
  3954. }
  3955. break;
  3956. }
  3957. case Js::OpCode::InlineeStart:
  3958. {
  3959. linkOpnd = instr->GetSrc2();
  3960. if(!linkOpnd->IsSymOpnd())
  3961. {
  3962. break;
  3963. }
  3964. IR::Instr* stackArgsInstr = linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->GetInstrDef();
  3965. if (stackArgsInstr->m_opcode == Js::OpCode::ArgOut_A_FromStackArgs)
  3966. {
  3967. linkOpnd = stackArgsInstr->GetSrc2();
  3968. argInstr = linkOpnd->AsSymOpnd()->m_sym->AsStackSym()->GetInstrDef();
  3969. Assert(argInstr->m_opcode == Js::OpCode::ArgOut_A_Inline || argInstr->m_opcode == Js::OpCode::ArgOut_A_FixupForStackArgs || argInstr->m_opcode == Js::OpCode::ArgOut_A);
  3970. stackArgsInstr->Remove();
  3971. Assert(argInstr->GetDst()->IsSymOpnd());
  3972. instr->ReplaceSrc2(argInstr->GetDst());
  3973. }
  3974. break;
  3975. }
  3976. case Js::OpCode::LdEnv:
  3977. if (instr->m_func == inlinee)
  3978. {
  3979. // Need to give the inlinee's function to load the environment
  3980. if (funcObjOpnd->IsAddrOpnd())
  3981. {
  3982. instr->m_opcode = Js::OpCode::Ld_A;
  3983. instr->SetSrc1(IR::AddrOpnd::New(Js::ScriptFunction::FromVar(funcObjOpnd->AsAddrOpnd()->m_address)->GetEnvironment(),
  3984. IR::AddrOpndKindDynamicFrameDisplay, instr->m_func));
  3985. }
  3986. else
  3987. {
  3988. instr->SetSrc1(funcObjOpnd);
  3989. }
  3990. }
  3991. else
  3992. {
  3993. Assert(instr->GetSrc1() != nullptr);
  3994. }
  3995. break;
  3996. case Js::OpCode::LdNewTarget:
  3997. if (instr->m_func == inlinee)
  3998. {
  3999. if (instr->m_func->IsInlinedConstructor())
  4000. {
  4001. instr->SetSrc1(funcObjOpnd);
  4002. }
  4003. else
  4004. {
  4005. instr->SetSrc1(IR::AddrOpnd::New(this->topFunc->GetScriptContext()->GetLibrary()->GetUndefined(),
  4006. IR::AddrOpndKindDynamicVar, this->topFunc, true));
  4007. instr->GetSrc1()->SetValueType(ValueType::Undefined);
  4008. }
  4009. instr->m_opcode = Js::OpCode::Ld_A;
  4010. }
  4011. break;
  4012. case Js::OpCode::ChkNewCallFlag:
  4013. if (instr->m_func == inlinee)
  4014. {
  4015. if (instr->m_func->IsInlinedConstructor())
  4016. {
  4017. instr->Remove();
  4018. }
  4019. else
  4020. {
  4021. // InliningDecider::Inline should have decided not to inline this since we are going to end up throwing anyway
  4022. Assert(false);
  4023. }
  4024. }
  4025. break;
  4026. case Js::OpCode::LdSuper:
  4027. case Js::OpCode::LdSuperCtor:
  4028. if (instr->m_func == inlinee)
  4029. {
  4030. instr->SetSrc1(funcObjOpnd);
  4031. }
  4032. else
  4033. {
  4034. Assert(instr->GetSrc1() != nullptr);
  4035. }
  4036. break;
  4037. case Js::OpCode::LdThis:
  4038. case Js::OpCode::StrictLdThis:
  4039. // Optimization of LdThis may be possible.
  4040. // Verify that this is a use of the "this" passed by the caller (not a nested function).
  4041. if (instr->GetSrc1()->AsRegOpnd()->m_sym == symThis)
  4042. {
  4043. if (fUsesSafeThis)
  4044. {
  4045. // No need for any "this" mapping.
  4046. instrNext = this->RemoveLdThis(instr);
  4047. break;
  4048. }
  4049. else if (fUsesConstThis)
  4050. {
  4051. // "this" is a constant, so map it now.
  4052. // Don't bother mapping if it's not an object, though, since we'd have to create a
  4053. // boxed value at JIT time, and that case doesn't seem worth it.
  4054. Js::TypeId typeId = Js::JavascriptOperators::GetTypeId(thisConstVar);
  4055. if (Js::JavascriptOperators::IsObjectType(typeId) ||
  4056. Js::JavascriptOperators::IsUndefinedOrNullType(typeId))
  4057. {
  4058. Js::ScriptContext *scriptContext = inlinee->GetScriptContext();
  4059. if (instr->m_opcode == Js::OpCode::LdThis)
  4060. {
  4061. thisConstVar = Js::JavascriptOperators::OP_GetThis(
  4062. thisConstVar, instr->GetSrc2()->AsIntConstOpnd()->AsInt32(), scriptContext);
  4063. instr->FreeSrc2();
  4064. }
  4065. else
  4066. {
  4067. thisConstVar = Js::JavascriptOperators::OP_StrictGetThis(thisConstVar, scriptContext);
  4068. }
  4069. IR::Opnd *thisOpnd = IR::AddrOpnd::New(thisConstVar, IR::AddrOpndKindDynamicVar, inlinee, true);
  4070. instr->m_opcode = Js::OpCode::Ld_A;
  4071. instr->ReplaceSrc1(thisOpnd);
  4072. break;
  4073. }
  4074. }
  4075. }
  4076. // Couldn't eliminate the execution-time "this" mapping. Try to change it to a check.
  4077. instrNext = this->DoCheckThisOpt(instr);
  4078. break;
  4079. case Js::OpCode::Throw:
  4080. instr->m_opcode = Js::OpCode::InlineThrow;
  4081. instr->m_func->SetHasImplicitCallsOnSelfAndParents();
  4082. break;
  4083. case Js::OpCode::RuntimeTypeError:
  4084. instr->m_opcode = Js::OpCode::InlineRuntimeTypeError;
  4085. instr->m_func->SetHasImplicitCallsOnSelfAndParents();
  4086. break;
  4087. case Js::OpCode::RuntimeReferenceError:
  4088. instr->m_opcode = Js::OpCode::InlineRuntimeReferenceError;
  4089. instr->m_func->SetHasImplicitCallsOnSelfAndParents();
  4090. break;
  4091. case Js::OpCode::Ret:
  4092. if (!retOpnd)
  4093. {
  4094. instr->Remove();
  4095. }
  4096. else
  4097. {
  4098. instr->m_opcode = Js::OpCode::Ld_A;
  4099. instr->SetDst(retOpnd);
  4100. }
  4101. break;
  4102. }
  4103. } NEXT_INSTR_EDITING;
  4104. }
  4105. void
  4106. Inline::SetupInlineeFrame(Func *inlinee, IR::Instr *inlineeStart, Js::ArgSlot actualCount, IR::Opnd *functionObject)
  4107. {
  4108. Js::ArgSlot argSlots[Js::Constants::InlineeMetaArgCount] = {
  4109. actualCount + 1, /* argc */
  4110. actualCount + 2, /* function object */
  4111. actualCount + 3 /* arguments object slot */
  4112. };
  4113. IR::Opnd *srcs[Js::Constants::InlineeMetaArgCount] = {
  4114. IR::AddrOpnd::New((Js::Var)actualCount, IR::AddrOpndKindConstant, inlinee, true /*dontEncode*/),
  4115. /*
  4116. * Don't initialize this slot with the function object yet. In compat mode we evaluate
  4117. * the target only after evaluating all arguments. Having this SymOpnd here ensures it gets
  4118. * the correct slot in the frame. Lowerer fills this slot with the function object just
  4119. * before entering the inlinee when we're sure we've evaluated the target in all modes.
  4120. */
  4121. nullptr,
  4122. IR::AddrOpnd::NewNull(inlinee)
  4123. };
  4124. const IRType types[Js::Constants::InlineeMetaArgCount] = {
  4125. TyMachReg,
  4126. TyVar,
  4127. TyMachReg
  4128. };
  4129. for (unsigned instrIndex = 0; instrIndex < Js::Constants::InlineeMetaArgCount; instrIndex++)
  4130. {
  4131. StackSym *stackSym = inlinee->m_symTable->GetArgSlotSym(argSlots[instrIndex]);
  4132. stackSym->m_isInlinedArgSlot = true;
  4133. this->topFunc->SetArgOffset(stackSym, (currentInlineeFrameSlot + instrIndex) * MachPtr);
  4134. IR::SymOpnd *symOpnd = IR::SymOpnd::New(stackSym, 0, types[instrIndex], inlinee);
  4135. IR::Instr *instr = IR::Instr::New(Js::OpCode::InlineeMetaArg, inlinee);
  4136. instr->SetDst(symOpnd);
  4137. if (srcs[instrIndex])
  4138. {
  4139. instr->SetSrc1(srcs[instrIndex]);
  4140. }
  4141. inlineeStart->InsertBefore(instr);
  4142. if (instrIndex == 0)
  4143. {
  4144. inlinee->SetInlineeFrameStartSym(stackSym);
  4145. }
  4146. }
  4147. }
  4148. void
  4149. Inline::FixupExtraActualParams(IR::Instr * instr, IR::Instr *argOuts[], IR::Instr *argOutsExtra[], uint index, uint actualCount, Js::ProfileId callSiteId)
  4150. {
  4151. Assert(instr->m_opcode == Js::OpCode::ArgOut_A_FromStackArgs);
  4152. int offsetFixup;
  4153. Assert(instr->m_func->callSiteToArgumentsOffsetFixupMap->ContainsKey(callSiteId));
  4154. instr->m_func->callSiteToArgumentsOffsetFixupMap->TryGetValue(callSiteId, &offsetFixup);
  4155. StackSym *sym = instr->GetDst()->AsSymOpnd()->m_sym->AsStackSym();
  4156. while (index < actualCount)
  4157. {
  4158. IR::Instr* argOutToMapTo = argOuts[index] ? argOuts[index] : argOutsExtra[index];
  4159. StackSym* newStackSym = StackSym::NewArgSlotSym(sym->GetArgSlotNum(), instr->m_func);
  4160. newStackSym->m_isInlinedArgSlot = true;
  4161. this->topFunc->SetArgOffset(newStackSym, sym->m_offset);
  4162. sym->IncrementArgSlotNum();
  4163. this->topFunc->SetArgOffset(sym, sym->m_offset + MachPtr);
  4164. IR::SymOpnd * linkOpnd = IR::SymOpnd::New(newStackSym, sym->GetType(), instr->m_func);
  4165. IR::Instr * extraActualParamInstr = IR::Instr::New(Js::OpCode::ArgOut_A_FixupForStackArgs, linkOpnd, argOutToMapTo->GetSrc1(), instr->GetSrc2(), instr->m_func);
  4166. instr->InsertBefore(extraActualParamInstr);
  4167. extraActualParamInstr->GenerateArgOutSnapshot();
  4168. instr->m_func->callSiteToArgumentsOffsetFixupMap->Item(callSiteId, ++offsetFixup);
  4169. instr->ReplaceSrc2(extraActualParamInstr->GetDst());
  4170. index++;
  4171. }
  4172. }
  4173. void
  4174. Inline::RemoveExtraFixupArgouts(IR::Instr* instr, uint argoutRemoveCount, Js::ProfileId callSiteId)
  4175. {
  4176. Assert(instr->m_opcode == Js::OpCode::ArgOut_A_FromStackArgs);
  4177. int offsetFixup;
  4178. Assert(instr->m_func->callSiteToArgumentsOffsetFixupMap->ContainsKey(callSiteId));
  4179. instr->m_func->callSiteToArgumentsOffsetFixupMap->TryGetValue(callSiteId, &offsetFixup);
  4180. StackSym* argSym = instr->GetDst()->AsSymOpnd()->m_sym->AsStackSym();
  4181. IR::Instr* argInstr = instr->GetSrc2()->AsSymOpnd()->m_sym->AsStackSym()->GetInstrDef();
  4182. for(uint argIndex = 0; argIndex < argoutRemoveCount; argIndex++)
  4183. {
  4184. Assert(argInstr->m_opcode == Js::OpCode::ArgOut_A_FixupForStackArgs);
  4185. Assert(!argInstr->HasByteCodeArgOutCapture()); // ArgOut_A_FixupForStackArgs should not be restored on bailout, so we don't generate ByteCodeArgOutCapture for these argouts.
  4186. instr->ReplaceSrc2(argInstr->GetSrc2());
  4187. argSym->DecrementArgSlotNum();
  4188. argSym->m_offset -= MachPtr;
  4189. argSym->m_allocated = true;
  4190. argInstr->Remove();
  4191. instr->m_func->callSiteToArgumentsOffsetFixupMap->Item(callSiteId, --offsetFixup);
  4192. argInstr = instr->GetSrc2()->AsSymOpnd()->m_sym->AsStackSym()->GetInstrDef();
  4193. }
  4194. }
  4195. IR::Instr *
  4196. Inline::DoCheckThisOpt(IR::Instr * instr)
  4197. {
  4198. IR::Instr * instrNext = instr->m_next;
  4199. if (PHASE_OFF(Js::CheckThisPhase, instr->m_func->GetTopFunc()))
  4200. {
  4201. return instrNext;
  4202. }
  4203. if (!PHASE_FORCE(Js::CheckThisPhase, instr->m_func->GetTopFunc()))
  4204. {
  4205. if (!instr->m_func->HasProfileInfo())
  4206. {
  4207. return instrNext;
  4208. }
  4209. if (instr->m_func->GetProfileInfo()->GetThisInfo().thisType != Js::ThisType_Simple)
  4210. {
  4211. return instrNext;
  4212. }
  4213. if (instr->m_func->GetProfileInfo()->IsCheckThisDisabled())
  4214. {
  4215. return instrNext;
  4216. }
  4217. }
  4218. // If the instr is an inlined LdThis, try to replace it with a CheckThis
  4219. // that will bail out if a helper call is required to get the real "this" pointer.
  4220. Assert(instr->m_opcode == Js::OpCode::LdThis || instr->m_opcode == Js::OpCode::StrictLdThis);
  4221. Assert(instr->IsInlined());
  4222. // Create the CheckThis. The target is the original offset, i.e., the LdThis still has to be executed.
  4223. if(instr->m_opcode == Js::OpCode::LdThis)
  4224. {
  4225. instr->FreeSrc2();
  4226. }
  4227. IR::Instr *newInstr =
  4228. IR::BailOutInstr::New( instr->m_opcode == Js::OpCode::LdThis ? Js::OpCode::CheckThis : Js::OpCode::StrictCheckThis, IR::BailOutCheckThis, instr, instr->m_func);
  4229. // Just re-use the original src1 since the LdThis will usually be deleted.
  4230. newInstr->SetSrc1(instr->GetSrc1());
  4231. newInstr->SetByteCodeOffset(instr);
  4232. instr->InsertBefore(newInstr);
  4233. return this->RemoveLdThis(instr);
  4234. }
  4235. IR::Instr *
  4236. Inline::RemoveLdThis(IR::Instr *instr)
  4237. {
  4238. // Replace the original instr with a copy, if needed.
  4239. if (instr->GetDst()->IsEqual(instr->GetSrc1()))
  4240. {
  4241. // The copy would be a nop, so just delete.
  4242. IR::Instr *instrNext = instr->m_next;
  4243. instr->Remove();
  4244. return instrNext;
  4245. }
  4246. else
  4247. {
  4248. instr->m_opcode = Js::OpCode::Ld_A;
  4249. return instr;
  4250. }
  4251. }
  4252. bool
  4253. Inline::IsArgumentsOpnd(IR::Opnd* opnd, SymID argumentsSymId)
  4254. {
  4255. if (opnd->IsRegOpnd())
  4256. {
  4257. return argumentsSymId == opnd->AsRegOpnd()->m_sym->m_id;
  4258. }
  4259. else if (opnd->IsSymOpnd())
  4260. {
  4261. Sym *sym = opnd->AsSymOpnd()->m_sym;
  4262. if (sym && sym->IsPropertySym())
  4263. {
  4264. PropertySym *propertySym = sym->AsPropertySym();
  4265. return argumentsSymId == propertySym->m_stackSym->m_id;
  4266. }
  4267. return false;
  4268. }
  4269. else if (opnd->IsIndirOpnd())
  4270. {
  4271. IR::RegOpnd *indexOpnd = opnd->AsIndirOpnd()->GetIndexOpnd();
  4272. IR::RegOpnd *baseOpnd = opnd->AsIndirOpnd()->GetBaseOpnd();
  4273. return (argumentsSymId == baseOpnd->m_sym->m_id) || (indexOpnd && indexOpnd->m_sym->m_id == argumentsSymId);
  4274. }
  4275. AssertMsg(false, "Unknown type");
  4276. return false;
  4277. }
  4278. bool
  4279. Inline::HasArgumentsAccess(IR::Opnd *opnd, SymID argumentsSymId)
  4280. {
  4281. // We should look at dst last to correctly handle cases where it's the same as one of the src operands.
  4282. if (opnd)
  4283. {
  4284. if (opnd->IsRegOpnd() || opnd->IsSymOpnd() || opnd->IsIndirOpnd())
  4285. {
  4286. if (IsArgumentsOpnd(opnd, argumentsSymId))
  4287. {
  4288. return true;
  4289. }
  4290. }
  4291. }
  4292. return false;
  4293. }
  4294. bool
  4295. Inline::HasArgumentsAccess(IR::Instr * instr, SymID argumentsSymId)
  4296. {
  4297. IR::Opnd* dst = instr->GetDst();
  4298. IR::Opnd* src1 = instr->GetSrc1();
  4299. IR::Opnd* src2 = instr->GetSrc2();
  4300. // Super conservative here, if we see the arguments or any of its alias being used in any
  4301. // other opcode just don't do this optimization.
  4302. if (HasArgumentsAccess(src1, argumentsSymId) || HasArgumentsAccess(src2, argumentsSymId))
  4303. {
  4304. return true;
  4305. }
  4306. if (dst)
  4307. {
  4308. // For dst no need to check for RegOpnd
  4309. if (dst->IsSymOpnd() || dst->IsIndirOpnd())
  4310. {
  4311. if (IsArgumentsOpnd(dst, argumentsSymId))
  4312. {
  4313. return true;
  4314. }
  4315. }
  4316. }
  4317. return false;
  4318. }
  4319. bool
  4320. Inline::GetInlineeHasArgumentObject(Func * inlinee)
  4321. {
  4322. if (!inlinee->GetHasArgumentObject())
  4323. {
  4324. // If inlinee has no arguments access return false
  4325. return false;
  4326. }
  4327. // Inlinee has arguments access
  4328. if (!inlinee->GetHasApplyTargetInlining())
  4329. {
  4330. // There is no apply target inlining (this.init.apply(this, arguments))
  4331. // So arguments access continues to exist
  4332. return true;
  4333. }
  4334. // Its possible there is no more arguments access after we inline apply target validate the same.
  4335. // This sounds expensive, but we are only walking inlinee which has apply target inlining optimization enabled.
  4336. // Also we walk only instruction in that inlinee and not nested inlinees. So it is not expensive.
  4337. SymID argumentsSymId = 0;
  4338. FOREACH_INSTR_IN_FUNC(instr, inlinee)
  4339. {
  4340. if (instr->m_func != inlinee)
  4341. {
  4342. // Skip nested inlinees
  4343. continue;
  4344. }
  4345. if (instr->m_opcode == Js::OpCode::LdHeapArguments || instr->m_opcode == Js::OpCode::LdLetHeapArguments)
  4346. {
  4347. argumentsSymId = instr->GetDst()->AsRegOpnd()->m_sym->m_id;
  4348. }
  4349. else if (argumentsSymId != 0)
  4350. {
  4351. // Once we find the arguments object i.e. argumentsSymId is set
  4352. // Make sure no one refers to it.
  4353. switch (instr->m_opcode)
  4354. {
  4355. case Js::OpCode::InlineBuiltInStart:
  4356. {
  4357. IR::Opnd* builtInOpnd = instr->GetSrc1();
  4358. if (builtInOpnd->IsAddrOpnd())
  4359. {
  4360. Assert(builtInOpnd->AsAddrOpnd()->m_isFunction);
  4361. Js::BuiltinFunction builtinFunction = Js::JavascriptLibrary::GetBuiltInForFuncInfo(((Js::JavascriptFunction*)builtInOpnd->AsAddrOpnd()->m_address)->GetFunctionInfo(), inlinee->GetScriptContext());
  4362. if (builtinFunction == Js::BuiltinFunction::Function_Apply)
  4363. {
  4364. this->SetIsInInlinedApplyCall(true);
  4365. }
  4366. }
  4367. else if (builtInOpnd->IsRegOpnd())
  4368. {
  4369. if (builtInOpnd->AsRegOpnd()->m_sym->m_builtInIndex == Js::BuiltinFunction::Function_Apply)
  4370. {
  4371. this->SetIsInInlinedApplyCall(true);
  4372. }
  4373. }
  4374. break;
  4375. }
  4376. case Js::OpCode::InlineBuiltInEnd:
  4377. {
  4378. if(this->GetIsInInlinedApplyCall())
  4379. {
  4380. this->SetIsInInlinedApplyCall(false);
  4381. }
  4382. break;
  4383. }
  4384. case Js::OpCode::BailOnNotStackArgs:
  4385. case Js::OpCode::LdArgumentsFromStack:
  4386. case Js::OpCode::ArgOut_A_InlineBuiltIn:
  4387. case Js::OpCode::BytecodeArgOutCapture:
  4388. case Js::OpCode::BytecodeArgOutUse:
  4389. // These are part of arguments optimization and we are fine if they access stack args.
  4390. break;
  4391. case Js::OpCode::ArgOut_A_FromStackArgs:
  4392. {
  4393. // If ArgOut_A_FromStackArgs is part of the call sequence for apply built-in inlining (as opposed to apply target inlining),
  4394. // then arguments access continues to exist.
  4395. if (this->GetIsInInlinedApplyCall() && HasArgumentsAccess(instr, argumentsSymId))
  4396. {
  4397. return true;
  4398. }
  4399. break;
  4400. }
  4401. default:
  4402. {
  4403. if (HasArgumentsAccess(instr, argumentsSymId))
  4404. {
  4405. return true;
  4406. }
  4407. }
  4408. }
  4409. }
  4410. }
  4411. NEXT_INSTR_IN_FUNC;
  4412. return false;
  4413. }
  4414. IR::Instr *
  4415. Inline::InlineSpread(IR::Instr *spreadCall)
  4416. {
  4417. Assert(Lowerer::IsSpreadCall(spreadCall));
  4418. if (spreadCall->m_func->GetJnFunction()->IsInlineSpreadDisabled()
  4419. || this->topFunc->GetJnFunction()->IsInlineSpreadDisabled())
  4420. {
  4421. return spreadCall;
  4422. }
  4423. IR::Instr *spreadIndicesInstr = Lowerer::GetLdSpreadIndicesInstr(spreadCall);
  4424. IR::Opnd *spreadIndicesOpnd = spreadIndicesInstr->GetSrc1();
  4425. Js::AuxArray<uint32>* spreadIndices = static_cast<Js::AuxArray<uint32>*>(spreadIndicesOpnd->AsAddrOpnd()->m_address);
  4426. Assert(spreadIndices->count > 0);
  4427. IR::Instr *argInstr = spreadIndicesInstr;
  4428. IR::SymOpnd *argLinkOpnd = argInstr->GetSrc2()->AsSymOpnd();
  4429. StackSym *argLinkSym = argLinkOpnd->m_sym->AsStackSym();
  4430. argInstr = argLinkSym->m_instrDef;
  4431. // We only support one spread argument for inlining.
  4432. if (argLinkSym->GetArgSlotNum() > 2)
  4433. {
  4434. return spreadCall;
  4435. }
  4436. // We are now committed to inlining spread. Remove the LdSpreadIndices instr
  4437. // and convert the spread and 'this' ArgOuts.
  4438. spreadCall->ReplaceSrc2(argLinkOpnd);
  4439. spreadIndicesInstr->Remove();
  4440. // Insert the bailout before the array ArgOut
  4441. IR::Opnd *arrayOpnd = argInstr->GetSrc1();
  4442. argInstr->m_opcode = Js::OpCode::ArgOut_A_SpreadArg;
  4443. IR::Instr *bailoutInstr = IR::BailOutInstr::New(Js::OpCode::BailOnNotSpreadable, IR::BailOutOnInlineFunction, argInstr, argInstr->m_func);
  4444. bailoutInstr->SetSrc1(arrayOpnd);
  4445. argInstr->InsertBefore(bailoutInstr);
  4446. argLinkOpnd = argInstr->GetSrc2()->AsSymOpnd();
  4447. argLinkSym = argLinkOpnd->m_sym->AsStackSym();
  4448. argInstr = argLinkSym->m_instrDef;
  4449. argInstr->m_opcode = Js::OpCode::ArgOut_A_Dynamic;
  4450. IR::RegOpnd *startCallDstOpnd = argInstr->GetSrc2()->AsRegOpnd();
  4451. argLinkSym = startCallDstOpnd->m_sym->AsStackSym();
  4452. argInstr = argLinkSym->m_instrDef;
  4453. Assert(argInstr->m_opcode == Js::OpCode::StartCall);
  4454. spreadCall->m_opcode = Js::OpCode::CallIDynamicSpread;
  4455. return spreadCall;
  4456. }
  4457. void
  4458. Inline::TryResetObjTypeSpecFldInfoOn(IR::PropertySymOpnd* propertySymOpnd)
  4459. {
  4460. // if an objTypeSpecFldInfo was created just for the purpose of polymorphic inlining but didn't get used for the same (for some reason or the other), and the polymorphic cache it was created from, wasn't equivalent,
  4461. // we should null out this info on the propertySymOpnd so that assumptions downstream around equivalent object type spec still hold.
  4462. if (propertySymOpnd)
  4463. {
  4464. propertySymOpnd->TryResetObjTypeSpecFldInfo();
  4465. }
  4466. }
  4467. void
  4468. Inline::TryDisableRuntimePolymorphicCacheOn(IR::PropertySymOpnd* propertySymOpnd)
  4469. {
  4470. if (propertySymOpnd)
  4471. {
  4472. propertySymOpnd->TryDisableRuntimePolymorphicCache();
  4473. }
  4474. }
  4475. IR::PropertySymOpnd*
  4476. Inline::GetMethodLdOpndForCallInstr(IR::Instr* callInstr)
  4477. {
  4478. IR::Opnd* methodOpnd = callInstr->GetSrc1();
  4479. if (methodOpnd->IsRegOpnd())
  4480. {
  4481. if (methodOpnd->AsRegOpnd()->m_sym->IsStackSym())
  4482. {
  4483. if (methodOpnd->AsRegOpnd()->m_sym->AsStackSym()->IsSingleDef())
  4484. {
  4485. IR::Instr* defInstr = methodOpnd->AsRegOpnd()->m_sym->AsStackSym()->GetInstrDef();
  4486. if (defInstr->GetSrc1() && defInstr->GetSrc1()->IsSymOpnd() && defInstr->GetSrc1()->AsSymOpnd()->IsPropertySymOpnd())
  4487. {
  4488. return defInstr->GetSrc1()->AsSymOpnd()->AsPropertySymOpnd();
  4489. }
  4490. return nullptr;
  4491. }
  4492. return nullptr;
  4493. }
  4494. return nullptr;
  4495. }
  4496. return nullptr;
  4497. }