[maglev] Don't constant-fold an Int32 multiply whose product is -0 TryFoldInt32BinaryOperation(int32_t, int32_t) folded cst_left * cst_right whenever the product did not overflow, including cases such as -1 * 0, whose result must be -0 rather than +0. Bail out of the fold when the product is a negative zero, letting Int32MultiplyWithOverflow handle the deopt instead, matching what the kNegate sibling fold in a6b7238b3b6 does. TAG=agy Fixed: 563238900 Change-Id: If111ecd213af8935f91dba27bf982b5d6a6a6964 Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8423789 Reviewed-by: Jakob Linke <jgruber@chromium.org> Commit-Queue: Marco Vitale <mrcvtl@chromium.org> Cr-Commit-Position: refs/heads/main@{#109978}
V8 is Google's open source JavaScript engine.
V8 implements ECMAScript as specified in ECMA-262.
V8 is written in C++ and is used in Chromium, the open source browser from Google.
V8 can run standalone, or can be embedded into any C++ application.
V8 Project page: https://v8.dev/docs
Checkout depot tools, and run
fetch v8
This will checkout V8 into the directory v8 and fetch all of its dependencies. To stay up to date, run
git pull origin
gclient sync
For fetching all branches, add the following into your remote configuration in .git/config:
fetch = +refs/branch-heads/*:refs/remotes/branch-heads/*
fetch = +refs/tags/*:refs/tags/*
Please follow the instructions mentioned at v8.dev/docs/contribute.