Merged: [turbofan] Fix bug in receiver maps inference Revision: fb0a60e15695466621cf65932f9152935d859447 BUG=chromium:1053604 NOTRY=true NOPRESUBMIT=true NOTREECHECKS=true R=mvstanton@chromium.org Change-Id: I40329f730fbfc5d578f607ecadc7853d4d5bd351 Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2062406 Reviewed-by: Michael Stanton <mvstanton@chromium.org> Reviewed-by: Michael Hablich <hablich@chromium.org> Commit-Queue: Michael Hablich <hablich@chromium.org> Cr-Commit-Position: refs/branch-heads/8.1@{#25} Cr-Branched-From: a4dcd39d521d14c4b1cac020812e44ee04a7f244-refs/heads/8.1.307@{#1} Cr-Branched-From: f22c213304ec3542df87019aed0909b7dafeaa93-refs/heads/master@{#66031}
diff --git a/src/compiler/node-properties.cc b/src/compiler/node-properties.cc index f43a348..ab4ced6 100644 --- a/src/compiler/node-properties.cc +++ b/src/compiler/node-properties.cc
@@ -386,6 +386,7 @@ // We reached the allocation of the {receiver}. return kNoReceiverMaps; } + result = kUnreliableReceiverMaps; // JSCreate can have side-effect. break; } case IrOpcode::kJSCreatePromise: {
diff --git a/test/mjsunit/compiler/regress-1053604.js b/test/mjsunit/compiler/regress-1053604.js new file mode 100644 index 0000000..ef87fbe --- /dev/null +++ b/test/mjsunit/compiler/regress-1053604.js
@@ -0,0 +1,30 @@ +// Copyright 2020 the V8 project authors. All rights reserved. +// Use of this source code is governed by a BSD-style license that can be +// found in the LICENSE file. + +// Flags: --allow-natives-syntax + +let a = [0, 1, 2, 3, 4]; + +function empty() {} + +function f(p) { + a.pop(Reflect.construct(empty, arguments, p)); +} + +let p = new Proxy(Object, { + get: () => (a[0] = 1.1, Object.prototype) +}); + +function main(p) { + f(p); +} + +%PrepareFunctionForOptimization(empty); +%PrepareFunctionForOptimization(f); +%PrepareFunctionForOptimization(main); + +main(empty); +main(empty); +%OptimizeFunctionOnNextCall(main); +main(p);