blob: b07c4742db39f4ec25eeb5f9a00635cae801a880 [file] [log] [blame]
ager@chromium.org9258b6b2008-09-11 09:11:10 +00001// Copyright 2006-2008 the V8 project authors. All rights reserved.
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +00002// Redistribution and use in source and binary forms, with or without
3// modification, are permitted provided that the following conditions are
4// met:
5//
6// * Redistributions of source code must retain the above copyright
7// notice, this list of conditions and the following disclaimer.
8// * Redistributions in binary form must reproduce the above
9// copyright notice, this list of conditions and the following
10// disclaimer in the documentation and/or other materials provided
11// with the distribution.
12// * Neither the name of Google Inc. nor the names of its
13// contributors may be used to endorse or promote products derived
14// from this software without specific prior written permission.
15//
16// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
17// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
18// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
19// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
20// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
21// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
22// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
23// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
24// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
25// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
26// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
27
28#include "v8.h"
29
30#include "codegen-inl.h"
31#include "ic-inl.h"
32#include "runtime.h"
33#include "stub-cache.h"
34
35namespace v8 { namespace internal {
36
37
38// ----------------------------------------------------------------------------
39// Static IC stub generators.
40//
41
ager@chromium.org65dad4b2009-04-23 08:48:43 +000042#define __ ACCESS_MASM(masm)
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +000043
44
45// Helper function used from LoadIC/CallIC GenerateNormal.
46static void GenerateDictionaryLoad(MacroAssembler* masm,
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +000047 Label* miss,
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +000048 Register t0,
49 Register t1) {
50 // Register use:
51 //
52 // t0 - used to hold the property dictionary.
53 //
54 // t1 - initially the receiver
55 // - used for the index into the property dictionary
56 // - holds the result on exit.
57 //
58 // r3 - used as temporary and to hold the capacity of the property
59 // dictionary.
60 //
61 // r2 - holds the name of the property and is unchanges.
62
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +000063 Label done;
64
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +000065 // Check for the absence of an interceptor.
66 // Load the map into t0.
67 __ ldr(t0, FieldMemOperand(t1, JSObject::kMapOffset));
68 // Test the has_named_interceptor bit in the map.
69 __ ldr(t0, FieldMemOperand(t1, Map::kInstanceAttributesOffset));
70 __ tst(t0, Operand(1 << (Map::kHasNamedInterceptor + (3 * 8))));
71 // Jump to miss if the interceptor bit is set.
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +000072 __ b(ne, miss);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +000073
74
75 // Check that the properties array is a dictionary.
76 __ ldr(t0, FieldMemOperand(t1, JSObject::kPropertiesOffset));
77 __ ldr(r3, FieldMemOperand(t0, HeapObject::kMapOffset));
78 __ cmp(r3, Operand(Factory::hash_table_map()));
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +000079 __ b(ne, miss);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +000080
81 // Compute the capacity mask.
82 const int kCapacityOffset =
83 Array::kHeaderSize + Dictionary::kCapacityIndex * kPointerSize;
84 __ ldr(r3, FieldMemOperand(t0, kCapacityOffset));
85 __ mov(r3, Operand(r3, ASR, kSmiTagSize)); // convert smi to int
86 __ sub(r3, r3, Operand(1));
87
88 const int kElementsStartOffset =
89 Array::kHeaderSize + Dictionary::kElementsStartIndex * kPointerSize;
90
91 // Generate an unrolled loop that performs a few probes before
92 // giving up. Measurements done on Gmail indicate that 2 probes
93 // cover ~93% of loads from dictionaries.
94 static const int kProbes = 4;
95 for (int i = 0; i < kProbes; i++) {
96 // Compute the masked index: (hash + i + i * i) & mask.
97 __ ldr(t1, FieldMemOperand(r2, String::kLengthOffset));
ager@chromium.org7c537e22008-10-16 08:43:32 +000098 __ mov(t1, Operand(t1, LSR, String::kHashShift));
ager@chromium.org65dad4b2009-04-23 08:48:43 +000099 if (i > 0) {
100 __ add(t1, t1, Operand(Dictionary::GetProbeOffset(i)));
101 }
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000102 __ and_(t1, t1, Operand(r3));
103
104 // Scale the index by multiplying by the element size.
105 ASSERT(Dictionary::kElementSize == 3);
106 __ add(t1, t1, Operand(t1, LSL, 1)); // t1 = t1 * 3
107
108 // Check if the key is identical to the name.
109 __ add(t1, t0, Operand(t1, LSL, 2));
110 __ ldr(ip, FieldMemOperand(t1, kElementsStartOffset));
111 __ cmp(r2, Operand(ip));
112 if (i != kProbes - 1) {
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000113 __ b(eq, &done);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000114 } else {
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000115 __ b(ne, miss);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000116 }
117 }
118
119 // Check that the value is a normal property.
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000120 __ bind(&done); // t1 == t0 + 4*index
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000121 __ ldr(r3, FieldMemOperand(t1, kElementsStartOffset + 2 * kPointerSize));
122 __ tst(r3, Operand(PropertyDetails::TypeField::mask() << kSmiTagSize));
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000123 __ b(ne, miss);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000124
125 // Get the value at the masked, scaled index and return.
126 __ ldr(t1, FieldMemOperand(t1, kElementsStartOffset + 1 * kPointerSize));
127}
128
129
ager@chromium.org3a37e9b2009-04-27 09:26:21 +0000130// Helper function used to check that a value is either not an object
131// or is loaded if it is an object.
132static void GenerateCheckNonObjectOrLoaded(MacroAssembler* masm,
133 Label* miss,
134 Register value,
135 Register scratch) {
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000136 Label done;
137 // Check if the value is a Smi.
138 __ tst(value, Operand(kSmiTagMask));
139 __ b(eq, &done);
ager@chromium.org3a37e9b2009-04-27 09:26:21 +0000140 // Check if the object has been loaded.
141 __ ldr(scratch, FieldMemOperand(value, JSObject::kMapOffset));
142 __ ldrb(scratch, FieldMemOperand(scratch, Map::kBitField2Offset));
143 __ tst(scratch, Operand(1 << Map::kNeedsLoading));
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000144 __ b(ne, miss);
145 __ bind(&done);
146}
147
148
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000149void LoadIC::GenerateArrayLength(MacroAssembler* masm) {
150 // ----------- S t a t e -------------
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000151 // -- r2 : name
152 // -- lr : return address
153 // -- [sp] : receiver
154 // -----------------------------------
155
156 Label miss;
157
mads.s.ager31e71382008-08-13 09:32:07 +0000158 __ ldr(r0, MemOperand(sp, 0));
159
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000160 StubCompiler::GenerateLoadArrayLength(masm, r0, r3, &miss);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000161 __ bind(&miss);
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000162 StubCompiler::GenerateLoadMiss(masm, Code::LOAD_IC);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000163}
164
165
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000166void LoadIC::GenerateStringLength(MacroAssembler* masm) {
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000167 // ----------- S t a t e -------------
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000168 // -- r2 : name
169 // -- lr : return address
170 // -- [sp] : receiver
171 // -----------------------------------
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000172 Label miss;
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000173
mads.s.ager31e71382008-08-13 09:32:07 +0000174 __ ldr(r0, MemOperand(sp, 0));
175
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000176 StubCompiler::GenerateLoadStringLength2(masm, r0, r1, r3, &miss);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000177 // Cache miss: Jump to runtime.
178 __ bind(&miss);
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000179 StubCompiler::GenerateLoadMiss(masm, Code::LOAD_IC);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000180}
181
182
183void LoadIC::GenerateFunctionPrototype(MacroAssembler* masm) {
184 // ----------- S t a t e -------------
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000185 // -- r2 : name
186 // -- lr : return address
187 // -- [sp] : receiver
188 // -----------------------------------
189
190 // NOTE: Right now, this code always misses on ARM which is
191 // sub-optimal. We should port the fast case code from IA-32.
192
193 Handle<Code> ic(Builtins::builtin(Builtins::LoadIC_Miss));
ager@chromium.org236ad962008-09-25 09:45:57 +0000194 __ Jump(ic, RelocInfo::CODE_TARGET);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000195}
196
197
198// Defined in ic.cc.
199Object* CallIC_Miss(Arguments args);
200
201void CallIC::GenerateMegamorphic(MacroAssembler* masm, int argc) {
202 // ----------- S t a t e -------------
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000203 // -- lr: return address
204 // -----------------------------------
205 Label number, non_number, non_string, boolean, probe, miss;
206
mads.s.ager31e71382008-08-13 09:32:07 +0000207 // Get the receiver of the function from the stack into r1.
208 __ ldr(r1, MemOperand(sp, argc * kPointerSize));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000209 // Get the name of the function from the stack; 1 ~ receiver.
mads.s.ager31e71382008-08-13 09:32:07 +0000210 __ ldr(r2, MemOperand(sp, (argc + 1) * kPointerSize));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000211
212 // Probe the stub cache.
213 Code::Flags flags =
214 Code::ComputeFlags(Code::CALL_IC, MONOMORPHIC, NORMAL, argc);
215 StubCache::GenerateProbe(masm, flags, r1, r2, r3);
216
217 // If the stub cache probing failed, the receiver might be a value.
218 // For value objects, we use the map of the prototype objects for
219 // the corresponding JSValue for the cache and that is what we need
220 // to probe.
221 //
222 // Check for number.
223 __ tst(r1, Operand(kSmiTagMask));
224 __ b(eq, &number);
225 __ ldr(r3, FieldMemOperand(r1, HeapObject::kMapOffset));
226 __ ldrb(r3, FieldMemOperand(r3, Map::kInstanceTypeOffset));
227 __ cmp(r3, Operand(HEAP_NUMBER_TYPE));
228 __ b(ne, &non_number);
229 __ bind(&number);
230 StubCompiler::GenerateLoadGlobalFunctionPrototype(
231 masm, Context::NUMBER_FUNCTION_INDEX, r1);
232 __ b(&probe);
233
234 // Check for string.
235 __ bind(&non_number);
236 __ cmp(r3, Operand(FIRST_NONSTRING_TYPE));
237 __ b(hs, &non_string);
238 StubCompiler::GenerateLoadGlobalFunctionPrototype(
239 masm, Context::STRING_FUNCTION_INDEX, r1);
240 __ b(&probe);
241
242 // Check for boolean.
243 __ bind(&non_string);
244 __ cmp(r1, Operand(Factory::true_value()));
245 __ b(eq, &boolean);
246 __ cmp(r1, Operand(Factory::false_value()));
247 __ b(ne, &miss);
248 __ bind(&boolean);
249 StubCompiler::GenerateLoadGlobalFunctionPrototype(
250 masm, Context::BOOLEAN_FUNCTION_INDEX, r1);
251
252 // Probe the stub cache for the value object.
253 __ bind(&probe);
254 StubCache::GenerateProbe(masm, flags, r1, r2, r3);
255
256 // Cache miss: Jump to runtime.
257 __ bind(&miss);
258 Generate(masm, argc, ExternalReference(IC_Utility(kCallIC_Miss)));
259}
260
261
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000262static void GenerateNormalHelper(MacroAssembler* masm,
263 int argc,
264 bool is_global_object,
265 Label* miss) {
266 // Search dictionary - put result in register r1.
267 GenerateDictionaryLoad(masm, miss, r0, r1);
268
269 // Check that the value isn't a smi.
270 __ tst(r1, Operand(kSmiTagMask));
271 __ b(eq, miss);
272
273 // Check that the value is a JSFunction.
274 __ ldr(r0, FieldMemOperand(r1, HeapObject::kMapOffset));
275 __ ldrb(r0, FieldMemOperand(r0, Map::kInstanceTypeOffset));
276 __ cmp(r0, Operand(JS_FUNCTION_TYPE));
277 __ b(ne, miss);
278
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000279 // Check that the function has been loaded.
ager@chromium.org3a37e9b2009-04-27 09:26:21 +0000280 __ ldr(r0, FieldMemOperand(r1, JSObject::kMapOffset));
281 __ ldrb(r0, FieldMemOperand(r0, Map::kBitField2Offset));
282 __ tst(r0, Operand(1 << Map::kNeedsLoading));
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000283 __ b(ne, miss);
284
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000285 // Patch the receiver with the global proxy if necessary.
286 if (is_global_object) {
287 __ ldr(r2, MemOperand(sp, argc * kPointerSize));
288 __ ldr(r2, FieldMemOperand(r2, GlobalObject::kGlobalReceiverOffset));
289 __ str(r2, MemOperand(sp, argc * kPointerSize));
290 }
291
292 // Invoke the function.
293 ParameterCount actual(argc);
294 __ InvokeFunction(r1, actual, JUMP_FUNCTION);
295}
296
297
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000298void CallIC::GenerateNormal(MacroAssembler* masm, int argc) {
299 // ----------- S t a t e -------------
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000300 // -- lr: return address
301 // -----------------------------------
302
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000303 Label miss, global_object, non_global_object;
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000304
mads.s.ager31e71382008-08-13 09:32:07 +0000305 // Get the receiver of the function from the stack into r1.
306 __ ldr(r1, MemOperand(sp, argc * kPointerSize));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000307 // Get the name of the function from the stack; 1 ~ receiver.
mads.s.ager@gmail.com769cc962008-08-06 10:02:49 +0000308 __ ldr(r2, MemOperand(sp, (argc + 1) * kPointerSize));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000309
310 // Check that the receiver isn't a smi.
311 __ tst(r1, Operand(kSmiTagMask));
312 __ b(eq, &miss);
313
314 // Check that the receiver is a valid JS object.
ager@chromium.org8bb60582008-12-11 12:02:20 +0000315 __ ldr(r3, FieldMemOperand(r1, HeapObject::kMapOffset));
316 __ ldrb(r0, FieldMemOperand(r3, Map::kInstanceTypeOffset));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000317 __ cmp(r0, Operand(FIRST_JS_OBJECT_TYPE));
318 __ b(lt, &miss);
319
320 // If this assert fails, we have to check upper bound too.
321 ASSERT(LAST_TYPE == JS_FUNCTION_TYPE);
322
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000323 // Check for access to global object.
324 __ cmp(r0, Operand(JS_GLOBAL_OBJECT_TYPE));
325 __ b(eq, &global_object);
326 __ cmp(r0, Operand(JS_BUILTINS_OBJECT_TYPE));
327 __ b(ne, &non_global_object);
328
329 // Accessing global object: Load and invoke.
330 __ bind(&global_object);
ager@chromium.org8bb60582008-12-11 12:02:20 +0000331 // Check that the global object does not require access checks.
332 __ ldrb(r3, FieldMemOperand(r3, Map::kBitFieldOffset));
333 __ tst(r3, Operand(1 << Map::kIsAccessCheckNeeded));
334 __ b(ne, &miss);
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000335 GenerateNormalHelper(masm, argc, true, &miss);
336
337 // Accessing non-global object: Check for access to global proxy.
338 Label global_proxy, invoke;
339 __ bind(&non_global_object);
kasperl@chromium.org5a8ca6c2008-10-23 13:57:19 +0000340 __ cmp(r0, Operand(JS_GLOBAL_PROXY_TYPE));
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000341 __ b(eq, &global_proxy);
ager@chromium.org8bb60582008-12-11 12:02:20 +0000342 // Check that the non-global, non-global-proxy object does not
343 // require access checks.
344 __ ldrb(r3, FieldMemOperand(r3, Map::kBitFieldOffset));
345 __ tst(r3, Operand(1 << Map::kIsAccessCheckNeeded));
346 __ b(ne, &miss);
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000347 __ bind(&invoke);
348 GenerateNormalHelper(masm, argc, false, &miss);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000349
350 // Global object access: Check access rights.
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000351 __ bind(&global_proxy);
kasperl@chromium.org5a8ca6c2008-10-23 13:57:19 +0000352 __ CheckAccessGlobalProxy(r1, r0, &miss);
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000353 __ b(&invoke);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000354
mads.s.ager@gmail.com769cc962008-08-06 10:02:49 +0000355 // Cache miss: Jump to runtime.
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000356 __ bind(&miss);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000357 Generate(masm, argc, ExternalReference(IC_Utility(kCallIC_Miss)));
358}
359
360
361void CallIC::Generate(MacroAssembler* masm,
362 int argc,
363 const ExternalReference& f) {
364 // ----------- S t a t e -------------
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000365 // -- lr: return address
366 // -----------------------------------
367
kasperl@chromium.orgb9123622008-09-17 14:05:56 +0000368 // Get the receiver of the function from the stack.
369 __ ldr(r2, MemOperand(sp, argc * kPointerSize));
370 // Get the name of the function to call from the stack.
371 __ ldr(r1, MemOperand(sp, (argc + 1) * kPointerSize));
372
373 __ EnterInternalFrame();
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000374
375 // Push the receiver and the name of the function.
kasperl@chromium.orgb9123622008-09-17 14:05:56 +0000376 __ stm(db_w, sp, r1.bit() | r2.bit());
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000377
378 // Call the entry.
mads.s.ager31e71382008-08-13 09:32:07 +0000379 __ mov(r0, Operand(2));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000380 __ mov(r1, Operand(f));
381
382 CEntryStub stub;
383 __ CallStub(&stub);
384
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000385 // Move result to r1 and leave the internal frame.
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000386 __ mov(r1, Operand(r0));
ager@chromium.org236ad962008-09-25 09:45:57 +0000387 __ LeaveInternalFrame();
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000388
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000389 // Check if the receiver is a global object of some sort.
390 Label invoke, global;
391 __ ldr(r2, MemOperand(sp, argc * kPointerSize)); // receiver
392 __ tst(r2, Operand(kSmiTagMask));
393 __ b(eq, &invoke);
394 __ ldr(r3, FieldMemOperand(r2, HeapObject::kMapOffset));
395 __ ldrb(r3, FieldMemOperand(r3, Map::kInstanceTypeOffset));
396 __ cmp(r3, Operand(JS_GLOBAL_OBJECT_TYPE));
397 __ b(eq, &global);
398 __ cmp(r3, Operand(JS_BUILTINS_OBJECT_TYPE));
399 __ b(ne, &invoke);
400
401 // Patch the receiver on the stack.
402 __ bind(&global);
403 __ ldr(r2, FieldMemOperand(r2, GlobalObject::kGlobalReceiverOffset));
404 __ str(r2, MemOperand(sp, argc * kPointerSize));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000405
mads.s.ager@gmail.com769cc962008-08-06 10:02:49 +0000406 // Invoke the function.
407 ParameterCount actual(argc);
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000408 __ bind(&invoke);
mads.s.ager@gmail.com769cc962008-08-06 10:02:49 +0000409 __ InvokeFunction(r1, actual, JUMP_FUNCTION);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000410}
411
412
413// Defined in ic.cc.
414Object* LoadIC_Miss(Arguments args);
415
416void LoadIC::GenerateMegamorphic(MacroAssembler* masm) {
417 // ----------- S t a t e -------------
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000418 // -- r2 : name
419 // -- lr : return address
420 // -- [sp] : receiver
421 // -----------------------------------
422
mads.s.ager31e71382008-08-13 09:32:07 +0000423 __ ldr(r0, MemOperand(sp, 0));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000424 // Probe the stub cache.
425 Code::Flags flags = Code::ComputeFlags(Code::LOAD_IC, MONOMORPHIC);
426 StubCache::GenerateProbe(masm, flags, r0, r2, r3);
427
428 // Cache miss: Jump to runtime.
429 Generate(masm, ExternalReference(IC_Utility(kLoadIC_Miss)));
430}
431
432
433void LoadIC::GenerateNormal(MacroAssembler* masm) {
434 // ----------- S t a t e -------------
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000435 // -- r2 : name
436 // -- lr : return address
437 // -- [sp] : receiver
438 // -----------------------------------
439
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000440 Label miss, probe, global;
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000441
mads.s.ager31e71382008-08-13 09:32:07 +0000442 __ ldr(r0, MemOperand(sp, 0));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000443 // Check that the receiver isn't a smi.
444 __ tst(r0, Operand(kSmiTagMask));
445 __ b(eq, &miss);
446
447 // Check that the receiver is a valid JS object.
ager@chromium.org8bb60582008-12-11 12:02:20 +0000448 __ ldr(r3, FieldMemOperand(r0, HeapObject::kMapOffset));
449 __ ldrb(r1, FieldMemOperand(r3, Map::kInstanceTypeOffset));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000450 __ cmp(r1, Operand(FIRST_JS_OBJECT_TYPE));
451 __ b(lt, &miss);
452 // If this assert fails, we have to check upper bound too.
453 ASSERT(LAST_TYPE == JS_FUNCTION_TYPE);
454
455 // Check for access to global object (unlikely).
kasperl@chromium.org5a8ca6c2008-10-23 13:57:19 +0000456 __ cmp(r1, Operand(JS_GLOBAL_PROXY_TYPE));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000457 __ b(eq, &global);
458
ager@chromium.org8bb60582008-12-11 12:02:20 +0000459 // Check for non-global object that requires access check.
460 __ ldrb(r3, FieldMemOperand(r3, Map::kBitFieldOffset));
461 __ tst(r3, Operand(1 << Map::kIsAccessCheckNeeded));
462 __ b(ne, &miss);
463
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000464 __ bind(&probe);
kasperl@chromium.org9fe21c62008-10-28 08:53:51 +0000465 GenerateDictionaryLoad(masm, &miss, r1, r0);
ager@chromium.org3a37e9b2009-04-27 09:26:21 +0000466 GenerateCheckNonObjectOrLoaded(masm, &miss, r0, r1);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000467 __ Ret();
468
469 // Global object access: Check access rights.
470 __ bind(&global);
kasperl@chromium.org5a8ca6c2008-10-23 13:57:19 +0000471 __ CheckAccessGlobalProxy(r0, r1, &miss);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000472 __ b(&probe);
473
474 // Cache miss: Restore receiver from stack and jump to runtime.
475 __ bind(&miss);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000476 Generate(masm, ExternalReference(IC_Utility(kLoadIC_Miss)));
477}
478
479
480void LoadIC::GenerateMiss(MacroAssembler* masm) {
481 Generate(masm, ExternalReference(IC_Utility(kLoadIC_Miss)));
482}
483
484
485void LoadIC::Generate(MacroAssembler* masm, const ExternalReference& f) {
486 // ----------- S t a t e -------------
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000487 // -- r2 : name
488 // -- lr : return address
489 // -- [sp] : receiver
490 // -----------------------------------
491
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000492 __ ldr(r3, MemOperand(sp, 0));
493 __ stm(db_w, sp, r2.bit() | r3.bit());
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000494
mads.s.ager31e71382008-08-13 09:32:07 +0000495 // Perform tail call to the entry.
496 __ TailCallRuntime(f, 2);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000497}
498
499
ager@chromium.org5ec48922009-05-05 07:25:34 +0000500// TODO(181): Implement map patching once loop nesting is tracked on the
501// ARM platform so we can generate inlined fast-case code loads in
502// loops.
503void LoadIC::ClearInlinedVersion(Address address) {}
504bool LoadIC::PatchInlinedLoad(Address address, Object* map, int offset) {
505 return false;
506}
507
508void KeyedLoadIC::ClearInlinedVersion(Address address) {}
509bool KeyedLoadIC::PatchInlinedLoad(Address address, Object* map) {
510 return false;
511}
christian.plesner.hansen@gmail.com37abdec2009-01-06 14:43:28 +0000512
513
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000514Object* KeyedLoadIC_Miss(Arguments args);
515
516
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000517void KeyedLoadIC::GenerateMiss(MacroAssembler* masm) {
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000518 Generate(masm, ExternalReference(IC_Utility(kKeyedLoadIC_Miss)));
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000519}
520
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000521
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000522void KeyedLoadIC::Generate(MacroAssembler* masm, const ExternalReference& f) {
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000523 // ---------- S t a t e --------------
524 // -- lr : return address
525 // -- sp[0] : key
526 // -- sp[4] : receiver
527 __ ldm(ia, sp, r2.bit() | r3.bit());
528 __ stm(db_w, sp, r2.bit() | r3.bit());
529
530 __ TailCallRuntime(f, 2);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000531}
532
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000533
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000534void KeyedLoadIC::GenerateGeneric(MacroAssembler* masm) {
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000535 // ---------- S t a t e --------------
536 // -- lr : return address
537 // -- sp[0] : key
538 // -- sp[4] : receiver
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000539 Label slow, fast;
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000540
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000541 // Get the key and receiver object from the stack.
542 __ ldm(ia, sp, r0.bit() | r1.bit());
543 // Check that the key is a smi.
544 __ tst(r0, Operand(kSmiTagMask));
545 __ b(ne, &slow);
546 __ mov(r0, Operand(r0, ASR, kSmiTagSize));
547 // Check that the object isn't a smi.
548 __ tst(r1, Operand(kSmiTagMask));
549 __ b(eq, &slow);
550
ager@chromium.org8bb60582008-12-11 12:02:20 +0000551 // Get the map of the receiver.
552 __ ldr(r2, FieldMemOperand(r1, HeapObject::kMapOffset));
553 // Check that the receiver does not require access checks. We need
554 // to check this explicitly since this generic stub does not perform
555 // map checks.
556 __ ldrb(r3, FieldMemOperand(r2, Map::kBitFieldOffset));
557 __ tst(r3, Operand(1 << Map::kIsAccessCheckNeeded));
558 __ b(ne, &slow);
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000559 // Check that the object is some kind of JS object EXCEPT JS Value type.
560 // In the case that the object is a value-wrapper object,
561 // we enter the runtime system to make sure that indexing into string
562 // objects work as intended.
563 ASSERT(JS_OBJECT_TYPE > JS_VALUE_TYPE);
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000564 __ ldrb(r2, FieldMemOperand(r2, Map::kInstanceTypeOffset));
565 __ cmp(r2, Operand(JS_OBJECT_TYPE));
566 __ b(lt, &slow);
567
568 // Get the elements array of the object.
569 __ ldr(r1, FieldMemOperand(r1, JSObject::kElementsOffset));
570 // Check that the object is in fast mode (not dictionary).
571 __ ldr(r3, FieldMemOperand(r1, HeapObject::kMapOffset));
572 __ cmp(r3, Operand(Factory::hash_table_map()));
573 __ b(eq, &slow);
574 // Check that the key (index) is within bounds.
575 __ ldr(r3, FieldMemOperand(r1, Array::kLengthOffset));
576 __ cmp(r0, Operand(r3));
577 __ b(lo, &fast);
578
579 // Slow case: Push extra copies of the arguments (2).
580 __ bind(&slow);
581 __ IncrementCounter(&Counters::keyed_load_generic_slow, 1, r0, r1);
582 __ ldm(ia, sp, r0.bit() | r1.bit());
583 __ stm(db_w, sp, r0.bit() | r1.bit());
584 // Do tail-call to runtime routine.
585 __ TailCallRuntime(ExternalReference(Runtime::kGetProperty), 2);
586
587 // Fast case: Do the load.
588 __ bind(&fast);
589 __ add(r3, r1, Operand(Array::kHeaderSize - kHeapObjectTag));
590 __ ldr(r0, MemOperand(r3, r0, LSL, kPointerSizeLog2));
591 __ cmp(r0, Operand(Factory::the_hole_value()));
592 // In case the loaded value is the_hole we have to consult GetProperty
593 // to ensure the prototype chain is searched.
594 __ b(eq, &slow);
595
596 __ Ret();
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000597}
598
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000599
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000600void KeyedStoreIC::Generate(MacroAssembler* masm,
601 const ExternalReference& f) {
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000602 // ---------- S t a t e --------------
603 // -- r0 : value
604 // -- lr : return address
605 // -- sp[0] : key
606 // -- sp[1] : receiver
607
608 __ ldm(ia, sp, r2.bit() | r3.bit());
609 __ stm(db_w, sp, r0.bit() | r2.bit() | r3.bit());
610
611 __ TailCallRuntime(f, 3);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000612}
613
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000614
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000615void KeyedStoreIC::GenerateGeneric(MacroAssembler* masm) {
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000616 // ---------- S t a t e --------------
617 // -- r0 : value
618 // -- lr : return address
619 // -- sp[0] : key
620 // -- sp[1] : receiver
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000621 Label slow, fast, array, extra, exit;
622 // Get the key and the object from the stack.
623 __ ldm(ia, sp, r1.bit() | r3.bit()); // r1 = key, r3 = receiver
624 // Check that the key is a smi.
625 __ tst(r1, Operand(kSmiTagMask));
626 __ b(ne, &slow);
627 // Check that the object isn't a smi.
628 __ tst(r3, Operand(kSmiTagMask));
629 __ b(eq, &slow);
ager@chromium.org8bb60582008-12-11 12:02:20 +0000630 // Get the map of the object.
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000631 __ ldr(r2, FieldMemOperand(r3, HeapObject::kMapOffset));
ager@chromium.org8bb60582008-12-11 12:02:20 +0000632 // Check that the receiver does not require access checks. We need
633 // to do this because this generic stub does not perform map checks.
634 __ ldrb(ip, FieldMemOperand(r2, Map::kBitFieldOffset));
635 __ tst(ip, Operand(1 << Map::kIsAccessCheckNeeded));
636 __ b(ne, &slow);
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000637 // Check if the object is a JS array or not.
ager@chromium.org8bb60582008-12-11 12:02:20 +0000638 __ ldrb(r2, FieldMemOperand(r2, Map::kInstanceTypeOffset));
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000639 __ cmp(r2, Operand(JS_ARRAY_TYPE));
640 // r1 == key.
641 __ b(eq, &array);
642 // Check that the object is some kind of JS object.
643 __ cmp(r2, Operand(FIRST_JS_OBJECT_TYPE));
644 __ b(lt, &slow);
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000645
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000646
647 // Object case: Check key against length in the elements array.
648 __ ldr(r3, FieldMemOperand(r3, JSObject::kElementsOffset));
649 // Check that the object is in fast mode (not dictionary).
650 __ ldr(r2, FieldMemOperand(r3, HeapObject::kMapOffset));
651 __ cmp(r2, Operand(Factory::hash_table_map()));
652 __ b(eq, &slow);
653 // Untag the key (for checking against untagged length in the fixed array).
654 __ mov(r1, Operand(r1, ASR, kSmiTagSize));
655 // Compute address to store into and check array bounds.
656 __ add(r2, r3, Operand(Array::kHeaderSize - kHeapObjectTag));
657 __ add(r2, r2, Operand(r1, LSL, kPointerSizeLog2));
658 __ ldr(ip, FieldMemOperand(r3, Array::kLengthOffset));
659 __ cmp(r1, Operand(ip));
660 __ b(lo, &fast);
661
662
663 // Slow case: Push extra copies of the arguments (3).
664 __ bind(&slow);
665 __ ldm(ia, sp, r1.bit() | r3.bit()); // r0 == value, r1 == key, r3 == object
666 __ stm(db_w, sp, r0.bit() | r1.bit() | r3.bit());
667 // Do tail-call to runtime routine.
668 __ TailCallRuntime(ExternalReference(Runtime::kSetProperty), 3);
669
670 // Extra capacity case: Check if there is extra capacity to
671 // perform the store and update the length. Used for adding one
672 // element to the array by writing to array[array.length].
673 // r0 == value, r1 == key, r2 == elements, r3 == object
674 __ bind(&extra);
675 __ b(ne, &slow); // do not leave holes in the array
676 __ mov(r1, Operand(r1, ASR, kSmiTagSize)); // untag
677 __ ldr(ip, FieldMemOperand(r2, Array::kLengthOffset));
678 __ cmp(r1, Operand(ip));
679 __ b(hs, &slow);
680 __ mov(r1, Operand(r1, LSL, kSmiTagSize)); // restore tag
681 __ add(r1, r1, Operand(1 << kSmiTagSize)); // and increment
682 __ str(r1, FieldMemOperand(r3, JSArray::kLengthOffset));
683 __ mov(r3, Operand(r2));
684 // NOTE: Computing the address to store into must take the fact
685 // that the key has been incremented into account.
686 int displacement = Array::kHeaderSize - kHeapObjectTag -
687 ((1 << kSmiTagSize) * 2);
688 __ add(r2, r2, Operand(displacement));
689 __ add(r2, r2, Operand(r1, LSL, kPointerSizeLog2 - kSmiTagSize));
690 __ b(&fast);
691
692
693 // Array case: Get the length and the elements array from the JS
694 // array. Check that the array is in fast mode; if it is the
695 // length is always a smi.
696 // r0 == value, r3 == object
697 __ bind(&array);
698 __ ldr(r2, FieldMemOperand(r3, JSObject::kElementsOffset));
699 __ ldr(r1, FieldMemOperand(r2, HeapObject::kMapOffset));
700 __ cmp(r1, Operand(Factory::hash_table_map()));
701 __ b(eq, &slow);
702
703 // Check the key against the length in the array, compute the
704 // address to store into and fall through to fast case.
ager@chromium.org32912102009-01-16 10:38:43 +0000705 __ ldr(r1, MemOperand(sp)); // restore key
ager@chromium.orga74f0da2008-12-03 16:05:52 +0000706 // r0 == value, r1 == key, r2 == elements, r3 == object.
707 __ ldr(ip, FieldMemOperand(r3, JSArray::kLengthOffset));
708 __ cmp(r1, Operand(ip));
709 __ b(hs, &extra);
710 __ mov(r3, Operand(r2));
711 __ add(r2, r2, Operand(Array::kHeaderSize - kHeapObjectTag));
712 __ add(r2, r2, Operand(r1, LSL, kPointerSizeLog2 - kSmiTagSize));
713
714
715 // Fast case: Do the store.
716 // r0 == value, r2 == address to store into, r3 == elements
717 __ bind(&fast);
718 __ str(r0, MemOperand(r2));
719 // Skip write barrier if the written value is a smi.
720 __ tst(r0, Operand(kSmiTagMask));
721 __ b(eq, &exit);
722 // Update write barrier for the elements array address.
723 __ sub(r1, r2, Operand(r3));
724 __ RecordWrite(r3, r1, r2);
725
726 __ bind(&exit);
727 __ Ret();
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000728}
729
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000730
kasperl@chromium.org1accd572008-10-07 10:57:21 +0000731void KeyedStoreIC::GenerateExtendStorage(MacroAssembler* masm) {
ager@chromium.org3bf7b912008-11-17 09:09:45 +0000732 // ---------- S t a t e --------------
733 // -- r0 : value
734 // -- lr : return address
735 // -- sp[0] : key
736 // -- sp[1] : receiver
737 // ----------- S t a t e -------------
738
739 __ ldm(ia, sp, r2.bit() | r3.bit());
740 __ stm(db_w, sp, r0.bit() | r2.bit() | r3.bit());
741
742 // Perform tail call to the entry.
743 __ TailCallRuntime(
744 ExternalReference(IC_Utility(kSharedStoreIC_ExtendStorage)), 3);
kasperl@chromium.org1accd572008-10-07 10:57:21 +0000745}
746
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000747
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000748void StoreIC::GenerateMegamorphic(MacroAssembler* masm) {
749 // ----------- S t a t e -------------
750 // -- r0 : value
751 // -- r2 : name
752 // -- lr : return address
753 // -- [sp] : receiver
754 // -----------------------------------
755
756 // Get the receiver from the stack and probe the stub cache.
757 __ ldr(r1, MemOperand(sp));
758 Code::Flags flags = Code::ComputeFlags(Code::STORE_IC, MONOMORPHIC);
759 StubCache::GenerateProbe(masm, flags, r1, r2, r3);
760
761 // Cache miss: Jump to runtime.
762 Generate(masm, ExternalReference(IC_Utility(kStoreIC_Miss)));
763}
764
765
kasperl@chromium.org41044eb2008-10-06 08:24:46 +0000766void StoreIC::GenerateExtendStorage(MacroAssembler* masm) {
767 // ----------- S t a t e -------------
768 // -- r0 : value
769 // -- r2 : name
770 // -- lr : return address
771 // -- [sp] : receiver
772 // -----------------------------------
773
774 __ ldr(r3, MemOperand(sp)); // copy receiver
775 __ stm(db_w, sp, r0.bit() | r2.bit() | r3.bit());
776
777 // Perform tail call to the entry.
kasperl@chromium.org1accd572008-10-07 10:57:21 +0000778 __ TailCallRuntime(
779 ExternalReference(IC_Utility(kSharedStoreIC_ExtendStorage)), 3);
kasperl@chromium.org41044eb2008-10-06 08:24:46 +0000780}
781
782
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000783void StoreIC::Generate(MacroAssembler* masm, const ExternalReference& f) {
784 // ----------- S t a t e -------------
785 // -- r0 : value
786 // -- r2 : name
787 // -- lr : return address
788 // -- [sp] : receiver
789 // -----------------------------------
790
791 __ ldr(r3, MemOperand(sp)); // copy receiver
792 __ stm(db_w, sp, r0.bit() | r2.bit() | r3.bit());
793
mads.s.ager31e71382008-08-13 09:32:07 +0000794 // Perform tail call to the entry.
795 __ TailCallRuntime(f, 3);
christian.plesner.hansen43d26ec2008-07-03 15:10:15 +0000796}
797
798
799#undef __
800
801
802} } // namespace v8::internal