Merged: [turbofan] Fix bug in receiver maps inference

Revision: fb0a60e15695466621cf65932f9152935d859447

BUG=chromium:1053604
NOTRY=true
NOPRESUBMIT=true
NOTREECHECKS=true
R=mvstanton@chromium.org

Change-Id: I40329f730fbfc5d578f607ecadc7853d4d5bd351
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2062406
Reviewed-by: Michael Stanton <mvstanton@chromium.org>
Reviewed-by: Michael Hablich <hablich@chromium.org>
Commit-Queue: Michael Hablich <hablich@chromium.org>
Cr-Commit-Position: refs/branch-heads/8.1@{#25}
Cr-Branched-From: a4dcd39d521d14c4b1cac020812e44ee04a7f244-refs/heads/8.1.307@{#1}
Cr-Branched-From: f22c213304ec3542df87019aed0909b7dafeaa93-refs/heads/master@{#66031}
diff --git a/src/compiler/node-properties.cc b/src/compiler/node-properties.cc
index f43a348..ab4ced6 100644
--- a/src/compiler/node-properties.cc
+++ b/src/compiler/node-properties.cc
@@ -386,6 +386,7 @@
           // We reached the allocation of the {receiver}.
           return kNoReceiverMaps;
         }
+        result = kUnreliableReceiverMaps;  // JSCreate can have side-effect.
         break;
       }
       case IrOpcode::kJSCreatePromise: {
diff --git a/test/mjsunit/compiler/regress-1053604.js b/test/mjsunit/compiler/regress-1053604.js
new file mode 100644
index 0000000..ef87fbe
--- /dev/null
+++ b/test/mjsunit/compiler/regress-1053604.js
@@ -0,0 +1,30 @@
+// Copyright 2020 the V8 project authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+// Flags: --allow-natives-syntax
+
+let a = [0, 1, 2, 3, 4];
+
+function empty() {}
+
+function f(p) {
+  a.pop(Reflect.construct(empty, arguments, p));
+}
+
+let p = new Proxy(Object, {
+    get: () => (a[0] = 1.1, Object.prototype)
+});
+
+function main(p) {
+  f(p);
+}
+
+%PrepareFunctionForOptimization(empty);
+%PrepareFunctionForOptimization(f);
+%PrepareFunctionForOptimization(main);
+
+main(empty);
+main(empty);
+%OptimizeFunctionOnNextCall(main);
+main(p);