blob: 65081b982e2b1588db0343dfede65147c5eec3dd [file] [log] [blame]
rossberg@chromium.orgfab14982012-01-05 15:02:15 +00001// Copyright 2012 the V8 project authors. All rights reserved.
ager@chromium.org5c838252010-02-19 08:53:10 +00002// Redistribution and use in source and binary forms, with or without
3// modification, are permitted provided that the following conditions are
4// met:
5//
6// * Redistributions of source code must retain the above copyright
7// notice, this list of conditions and the following disclaimer.
8// * Redistributions in binary form must reproduce the above
9// copyright notice, this list of conditions and the following
10// disclaimer in the documentation and/or other materials provided
11// with the distribution.
12// * Neither the name of Google Inc. nor the names of its
13// contributors may be used to endorse or promote products derived
14// from this software without specific prior written permission.
15//
16// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
17// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
18// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
19// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
20// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
21// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
22// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
23// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
24// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
25// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
26// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
27
28
29
30#include "v8.h"
31
erik.corry@gmail.com9dfbea42010-05-21 12:58:28 +000032#if defined(V8_TARGET_ARCH_MIPS)
33
karlklose@chromium.org83a47282011-05-11 11:54:09 +000034#include "codegen.h"
ager@chromium.org5c838252010-02-19 08:53:10 +000035#include "debug.h"
lrn@chromium.org7516f052011-03-30 08:52:27 +000036#include "deoptimizer.h"
37#include "full-codegen.h"
ager@chromium.org5c838252010-02-19 08:53:10 +000038#include "runtime.h"
39
40namespace v8 {
41namespace internal {
42
43
44#define __ ACCESS_MASM(masm)
45
46
47void Builtins::Generate_Adaptor(MacroAssembler* masm,
48 CFunctionId id,
49 BuiltinExtraArguments extra_args) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +000050 // ----------- S t a t e -------------
51 // -- a0 : number of arguments excluding receiver
52 // -- a1 : called function (only guaranteed when
53 // -- extra_args requires it)
54 // -- cp : context
55 // -- sp[0] : last argument
56 // -- ...
57 // -- sp[4 * (argc - 1)] : first argument
58 // -- sp[4 * agrc] : receiver
59 // -----------------------------------
60
61 // Insert extra arguments.
62 int num_extra_args = 0;
63 if (extra_args == NEEDS_CALLED_FUNCTION) {
64 num_extra_args = 1;
65 __ push(a1);
66 } else {
67 ASSERT(extra_args == NO_EXTRA_ARGUMENTS);
68 }
69
ulan@chromium.org6ff65142012-03-21 09:52:17 +000070 // JumpToExternalReference expects s0 to contain the number of arguments
vegorov@chromium.org7304bca2011-05-16 12:14:13 +000071 // including the receiver and the extra arguments.
ulan@chromium.org6ff65142012-03-21 09:52:17 +000072 __ Addu(s0, a0, num_extra_args + 1);
73 __ sll(s1, s0, kPointerSizeLog2);
74 __ Subu(s1, s1, kPointerSize);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +000075 __ JumpToExternalReference(ExternalReference(id, masm->isolate()));
76}
77
78
rossberg@chromium.orgfab14982012-01-05 15:02:15 +000079// Load the built-in InternalArray function from the current context.
80static void GenerateLoadInternalArrayFunction(MacroAssembler* masm,
81 Register result) {
yangguo@chromium.org46839fb2012-08-28 09:06:19 +000082 // Load the native context.
rossberg@chromium.orgfab14982012-01-05 15:02:15 +000083
rossberg@chromium.orgfab14982012-01-05 15:02:15 +000084 __ lw(result,
yangguo@chromium.org46839fb2012-08-28 09:06:19 +000085 MemOperand(cp, Context::SlotOffset(Context::GLOBAL_OBJECT_INDEX)));
86 __ lw(result,
87 FieldMemOperand(result, GlobalObject::kNativeContextOffset));
88 // Load the InternalArray function from the native context.
rossberg@chromium.orgfab14982012-01-05 15:02:15 +000089 __ lw(result,
90 MemOperand(result,
91 Context::SlotOffset(
92 Context::INTERNAL_ARRAY_FUNCTION_INDEX)));
93}
94
95
vegorov@chromium.org7304bca2011-05-16 12:14:13 +000096// Load the built-in Array function from the current context.
97static void GenerateLoadArrayFunction(MacroAssembler* masm, Register result) {
yangguo@chromium.org46839fb2012-08-28 09:06:19 +000098 // Load the native context.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +000099
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000100 __ lw(result,
yangguo@chromium.org46839fb2012-08-28 09:06:19 +0000101 MemOperand(cp, Context::SlotOffset(Context::GLOBAL_OBJECT_INDEX)));
102 __ lw(result,
103 FieldMemOperand(result, GlobalObject::kNativeContextOffset));
104 // Load the Array function from the native context.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000105 __ lw(result,
rossberg@chromium.orgfab14982012-01-05 15:02:15 +0000106 MemOperand(result,
107 Context::SlotOffset(Context::ARRAY_FUNCTION_INDEX)));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000108}
109
110
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000111// Allocate an empty JSArray. The allocated array is put into the result
112// register. An elements backing store is allocated with size initial_capacity
113// and filled with the hole values.
114static void AllocateEmptyJSArray(MacroAssembler* masm,
115 Register array_function,
116 Register result,
117 Register scratch1,
118 Register scratch2,
119 Register scratch3,
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000120 Label* gc_required) {
erik.corry@gmail.com394dbcf2011-10-27 07:38:48 +0000121 const int initial_capacity = JSArray::kPreallocatedArrayElements;
122 STATIC_ASSERT(initial_capacity >= 0);
svenpanne@chromium.org830d30c2012-05-29 13:20:14 +0000123 __ LoadInitialArrayMap(array_function, scratch2, scratch1, false);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000124
125 // Allocate the JSArray object together with space for a fixed array with the
126 // requested elements.
erik.corry@gmail.com6e28b562011-10-27 14:20:17 +0000127 int size = JSArray::kSize;
128 if (initial_capacity > 0) {
129 size += FixedArray::SizeFor(initial_capacity);
130 }
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000131 __ AllocateInNewSpace(size,
132 result,
133 scratch2,
134 scratch3,
135 gc_required,
136 TAG_OBJECT);
137 // Allocated the JSArray. Now initialize the fields except for the elements
138 // array.
139 // result: JSObject
140 // scratch1: initial map
141 // scratch2: start of next object
142 __ sw(scratch1, FieldMemOperand(result, JSObject::kMapOffset));
143 __ LoadRoot(scratch1, Heap::kEmptyFixedArrayRootIndex);
144 __ sw(scratch1, FieldMemOperand(result, JSArray::kPropertiesOffset));
145 // Field JSArray::kElementsOffset is initialized later.
146 __ mov(scratch3, zero_reg);
147 __ sw(scratch3, FieldMemOperand(result, JSArray::kLengthOffset));
148
erik.corry@gmail.com6e28b562011-10-27 14:20:17 +0000149 if (initial_capacity == 0) {
150 __ sw(scratch1, FieldMemOperand(result, JSArray::kElementsOffset));
151 return;
152 }
153
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000154 // Calculate the location of the elements array and set elements array member
155 // of the JSArray.
156 // result: JSObject
157 // scratch2: start of next object
158 __ Addu(scratch1, result, Operand(JSArray::kSize));
159 __ sw(scratch1, FieldMemOperand(result, JSArray::kElementsOffset));
160
161 // Clear the heap tag on the elements array.
162 __ And(scratch1, scratch1, Operand(~kHeapObjectTagMask));
163
164 // Initialize the FixedArray and fill it with holes. FixedArray length is
165 // stored as a smi.
166 // result: JSObject
167 // scratch1: elements array (untagged)
168 // scratch2: start of next object
169 __ LoadRoot(scratch3, Heap::kFixedArrayMapRootIndex);
erik.corry@gmail.com6e28b562011-10-27 14:20:17 +0000170 STATIC_ASSERT(0 * kPointerSize == FixedArray::kMapOffset);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000171 __ sw(scratch3, MemOperand(scratch1));
172 __ Addu(scratch1, scratch1, kPointerSize);
173 __ li(scratch3, Operand(Smi::FromInt(initial_capacity)));
erik.corry@gmail.com6e28b562011-10-27 14:20:17 +0000174 STATIC_ASSERT(1 * kPointerSize == FixedArray::kLengthOffset);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000175 __ sw(scratch3, MemOperand(scratch1));
176 __ Addu(scratch1, scratch1, kPointerSize);
177
erik.corry@gmail.com394dbcf2011-10-27 07:38:48 +0000178 // Fill the FixedArray with the hole value. Inline the code if short.
erik.corry@gmail.com6e28b562011-10-27 14:20:17 +0000179 STATIC_ASSERT(2 * kPointerSize == FixedArray::kHeaderSize);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000180 __ LoadRoot(scratch3, Heap::kTheHoleValueRootIndex);
erik.corry@gmail.com394dbcf2011-10-27 07:38:48 +0000181 static const int kLoopUnfoldLimit = 4;
182 if (initial_capacity <= kLoopUnfoldLimit) {
183 for (int i = 0; i < initial_capacity; i++) {
184 __ sw(scratch3, MemOperand(scratch1, i * kPointerSize));
185 }
186 } else {
187 Label loop, entry;
188 __ Addu(scratch2, scratch1, Operand(initial_capacity * kPointerSize));
189 __ Branch(&entry);
190 __ bind(&loop);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000191 __ sw(scratch3, MemOperand(scratch1));
192 __ Addu(scratch1, scratch1, kPointerSize);
erik.corry@gmail.com394dbcf2011-10-27 07:38:48 +0000193 __ bind(&entry);
194 __ Branch(&loop, lt, scratch1, Operand(scratch2));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000195 }
196}
197
198
199// Allocate a JSArray with the number of elements stored in a register. The
200// register array_function holds the built-in Array function and the register
201// array_size holds the size of the array as a smi. The allocated array is put
202// into the result register and beginning and end of the FixedArray elements
203// storage is put into registers elements_array_storage and elements_array_end
204// (see below for when that is not the case). If the parameter fill_with_holes
205// is true the allocated elements backing store is filled with the hole values
206// otherwise it is left uninitialized. When the backing store is filled the
207// register elements_array_storage is scratched.
208static void AllocateJSArray(MacroAssembler* masm,
209 Register array_function, // Array function.
erik.corry@gmail.com394dbcf2011-10-27 07:38:48 +0000210 Register array_size, // As a smi, cannot be 0.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000211 Register result,
212 Register elements_array_storage,
213 Register elements_array_end,
214 Register scratch1,
215 Register scratch2,
216 bool fill_with_hole,
217 Label* gc_required) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000218 // Load the initial map from the array function.
svenpanne@chromium.org830d30c2012-05-29 13:20:14 +0000219 __ LoadInitialArrayMap(array_function, scratch2,
220 elements_array_storage, fill_with_hole);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000221
erik.corry@gmail.com394dbcf2011-10-27 07:38:48 +0000222 if (FLAG_debug_code) { // Assert that array size is not zero.
223 __ Assert(
224 ne, "array size is unexpectedly 0", array_size, Operand(zero_reg));
225 }
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000226
227 // Allocate the JSArray object together with space for a FixedArray with the
228 // requested number of elements.
fschneider@chromium.org1805e212011-09-05 10:49:12 +0000229 STATIC_ASSERT(kSmiTagSize == 1 && kSmiTag == 0);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000230 __ li(elements_array_end,
231 (JSArray::kSize + FixedArray::kHeaderSize) / kPointerSize);
232 __ sra(scratch1, array_size, kSmiTagSize);
233 __ Addu(elements_array_end, elements_array_end, scratch1);
234 __ AllocateInNewSpace(
235 elements_array_end,
236 result,
237 scratch1,
238 scratch2,
239 gc_required,
240 static_cast<AllocationFlags>(TAG_OBJECT | SIZE_IN_WORDS));
241
242 // Allocated the JSArray. Now initialize the fields except for the elements
243 // array.
244 // result: JSObject
245 // elements_array_storage: initial map
246 // array_size: size of array (smi)
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000247 __ sw(elements_array_storage, FieldMemOperand(result, JSObject::kMapOffset));
248 __ LoadRoot(elements_array_storage, Heap::kEmptyFixedArrayRootIndex);
249 __ sw(elements_array_storage,
250 FieldMemOperand(result, JSArray::kPropertiesOffset));
251 // Field JSArray::kElementsOffset is initialized later.
252 __ sw(array_size, FieldMemOperand(result, JSArray::kLengthOffset));
253
254 // Calculate the location of the elements array and set elements array member
255 // of the JSArray.
256 // result: JSObject
257 // array_size: size of array (smi)
258 __ Addu(elements_array_storage, result, Operand(JSArray::kSize));
259 __ sw(elements_array_storage,
260 FieldMemOperand(result, JSArray::kElementsOffset));
261
262 // Clear the heap tag on the elements array.
263 __ And(elements_array_storage,
264 elements_array_storage,
265 Operand(~kHeapObjectTagMask));
266 // Initialize the fixed array and fill it with holes. FixedArray length is
267 // stored as a smi.
268 // result: JSObject
269 // elements_array_storage: elements array (untagged)
270 // array_size: size of array (smi)
271 __ LoadRoot(scratch1, Heap::kFixedArrayMapRootIndex);
272 ASSERT_EQ(0 * kPointerSize, FixedArray::kMapOffset);
273 __ sw(scratch1, MemOperand(elements_array_storage));
274 __ Addu(elements_array_storage, elements_array_storage, kPointerSize);
275
276 // Length of the FixedArray is the number of pre-allocated elements if
277 // the actual JSArray has length 0 and the size of the JSArray for non-empty
278 // JSArrays. The length of a FixedArray is stored as a smi.
fschneider@chromium.org1805e212011-09-05 10:49:12 +0000279 STATIC_ASSERT(kSmiTag == 0);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000280
281 ASSERT_EQ(1 * kPointerSize, FixedArray::kLengthOffset);
282 __ sw(array_size, MemOperand(elements_array_storage));
283 __ Addu(elements_array_storage, elements_array_storage, kPointerSize);
284
285 // Calculate elements array and elements array end.
286 // result: JSObject
287 // elements_array_storage: elements array element storage
288 // array_size: smi-tagged size of elements array
fschneider@chromium.org1805e212011-09-05 10:49:12 +0000289 STATIC_ASSERT(kSmiTag == 0 && kSmiTagSize < kPointerSizeLog2);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000290 __ sll(elements_array_end, array_size, kPointerSizeLog2 - kSmiTagSize);
291 __ Addu(elements_array_end, elements_array_storage, elements_array_end);
292
293 // Fill the allocated FixedArray with the hole value if requested.
294 // result: JSObject
295 // elements_array_storage: elements array element storage
296 // elements_array_end: start of next object
297 if (fill_with_hole) {
298 Label loop, entry;
299 __ LoadRoot(scratch1, Heap::kTheHoleValueRootIndex);
300 __ Branch(&entry);
301 __ bind(&loop);
302 __ sw(scratch1, MemOperand(elements_array_storage));
303 __ Addu(elements_array_storage, elements_array_storage, kPointerSize);
304
305 __ bind(&entry);
306 __ Branch(&loop, lt, elements_array_storage, Operand(elements_array_end));
307 }
308}
309
310
311// Create a new array for the built-in Array function. This function allocates
312// the JSArray object and the FixedArray elements array and initializes these.
313// If the Array cannot be constructed in native code the runtime is called. This
314// function assumes the following state:
315// a0: argc
316// a1: constructor (built-in Array function)
317// ra: return address
318// sp[0]: last argument
319// This function is used for both construct and normal calls of Array. The only
320// difference between handling a construct call and a normal call is that for a
321// construct call the constructor function in a1 needs to be preserved for
322// entering the generic code. In both cases argc in a0 needs to be preserved.
323// Both registers are preserved by this code so no need to differentiate between
324// construct call and normal call.
325static void ArrayNativeCode(MacroAssembler* masm,
326 Label* call_generic_code) {
327 Counters* counters = masm->isolate()->counters();
rossberg@chromium.orgfab14982012-01-05 15:02:15 +0000328 Label argc_one_or_more, argc_two_or_more, not_empty_array, empty_array,
ulan@chromium.org65a89c22012-02-14 11:46:07 +0000329 has_non_smi_element, finish, cant_transition_map, not_double;
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000330
331 // Check for array construction with zero arguments or one.
332 __ Branch(&argc_one_or_more, ne, a0, Operand(zero_reg));
333 // Handle construction of an empty array.
erik.corry@gmail.com394dbcf2011-10-27 07:38:48 +0000334 __ bind(&empty_array);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000335 AllocateEmptyJSArray(masm,
336 a1,
337 a2,
338 a3,
339 t0,
340 t1,
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000341 call_generic_code);
342 __ IncrementCounter(counters->array_function_native(), 1, a3, t0);
erik.corry@gmail.comf2038fb2012-01-16 11:42:08 +0000343 // Set up return value, remove receiver from stack and return.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000344 __ mov(v0, a2);
345 __ Addu(sp, sp, Operand(kPointerSize));
346 __ Ret();
347
348 // Check for one argument. Bail out if argument is not smi or if it is
349 // negative.
350 __ bind(&argc_one_or_more);
351 __ Branch(&argc_two_or_more, ne, a0, Operand(1));
352
fschneider@chromium.org1805e212011-09-05 10:49:12 +0000353 STATIC_ASSERT(kSmiTag == 0);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000354 __ lw(a2, MemOperand(sp)); // Get the argument from the stack.
erik.corry@gmail.com394dbcf2011-10-27 07:38:48 +0000355 __ Branch(&not_empty_array, ne, a2, Operand(zero_reg));
356 __ Drop(1); // Adjust stack.
357 __ mov(a0, zero_reg); // Treat this as a call with argc of zero.
358 __ Branch(&empty_array);
359
360 __ bind(&not_empty_array);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000361 __ And(a3, a2, Operand(kIntptrSignBit | kSmiTagMask));
362 __ Branch(call_generic_code, eq, a3, Operand(zero_reg));
363
364 // Handle construction of an empty array of a certain size. Bail out if size
365 // is too large to actually allocate an elements array.
fschneider@chromium.org1805e212011-09-05 10:49:12 +0000366 STATIC_ASSERT(kSmiTag == 0);
vegorov@chromium.org3cf47312011-06-29 13:20:01 +0000367 __ Branch(call_generic_code, Ugreater_equal, a2,
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000368 Operand(JSObject::kInitialMaxFastElementArray << kSmiTagSize));
369
370 // a0: argc
371 // a1: constructor
372 // a2: array_size (smi)
373 // sp[0]: argument
374 AllocateJSArray(masm,
375 a1,
376 a2,
377 a3,
378 t0,
379 t1,
380 t2,
381 t3,
382 true,
383 call_generic_code);
384 __ IncrementCounter(counters->array_function_native(), 1, a2, t0);
385
erik.corry@gmail.comf2038fb2012-01-16 11:42:08 +0000386 // Set up return value, remove receiver and argument from stack and return.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000387 __ mov(v0, a3);
388 __ Addu(sp, sp, Operand(2 * kPointerSize));
389 __ Ret();
390
391 // Handle construction of an array from a list of arguments.
392 __ bind(&argc_two_or_more);
393 __ sll(a2, a0, kSmiTagSize); // Convert argc to a smi.
394
395 // a0: argc
396 // a1: constructor
397 // a2: array_size (smi)
398 // sp[0]: last argument
399 AllocateJSArray(masm,
400 a1,
401 a2,
402 a3,
403 t0,
404 t1,
405 t2,
406 t3,
407 false,
408 call_generic_code);
409 __ IncrementCounter(counters->array_function_native(), 1, a2, t2);
410
411 // Fill arguments as array elements. Copy from the top of the stack (last
412 // element) to the array backing store filling it backwards. Note:
413 // elements_array_end points after the backing store.
414 // a0: argc
415 // a3: JSArray
416 // t0: elements_array storage start (untagged)
417 // t1: elements_array_end (untagged)
418 // sp[0]: last argument
419
420 Label loop, entry;
danno@chromium.orge78f9fc2011-12-21 08:29:34 +0000421 __ Branch(USE_DELAY_SLOT, &entry);
422 __ mov(t3, sp);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000423 __ bind(&loop);
danno@chromium.orge78f9fc2011-12-21 08:29:34 +0000424 __ lw(a2, MemOperand(t3));
danno@chromium.orge78f9fc2011-12-21 08:29:34 +0000425 if (FLAG_smi_only_arrays) {
rossberg@chromium.orgfab14982012-01-05 15:02:15 +0000426 __ JumpIfNotSmi(a2, &has_non_smi_element);
danno@chromium.orge78f9fc2011-12-21 08:29:34 +0000427 }
ulan@chromium.org65a89c22012-02-14 11:46:07 +0000428 __ Addu(t3, t3, kPointerSize);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000429 __ Addu(t1, t1, -kPointerSize);
430 __ sw(a2, MemOperand(t1));
431 __ bind(&entry);
432 __ Branch(&loop, lt, t0, Operand(t1));
ulan@chromium.org65a89c22012-02-14 11:46:07 +0000433
434 __ bind(&finish);
danno@chromium.orge78f9fc2011-12-21 08:29:34 +0000435 __ mov(sp, t3);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000436
437 // Remove caller arguments and receiver from the stack, setup return value and
438 // return.
439 // a0: argc
440 // a3: JSArray
441 // sp[0]: receiver
442 __ Addu(sp, sp, Operand(kPointerSize));
443 __ mov(v0, a3);
444 __ Ret();
rossberg@chromium.orgfab14982012-01-05 15:02:15 +0000445
446 __ bind(&has_non_smi_element);
ulan@chromium.org65a89c22012-02-14 11:46:07 +0000447 // Double values are handled by the runtime.
448 __ CheckMap(
449 a2, t5, Heap::kHeapNumberMapRootIndex, &not_double, DONT_DO_SMI_CHECK);
450 __ bind(&cant_transition_map);
rossberg@chromium.orgfab14982012-01-05 15:02:15 +0000451 __ UndoAllocationInNewSpace(a3, t0);
ulan@chromium.org65a89c22012-02-14 11:46:07 +0000452 __ Branch(call_generic_code);
453
454 __ bind(&not_double);
svenpanne@chromium.org830d30c2012-05-29 13:20:14 +0000455 // Transition FAST_SMI_ELEMENTS to FAST_ELEMENTS.
ulan@chromium.org65a89c22012-02-14 11:46:07 +0000456 // a3: JSArray
457 __ lw(a2, FieldMemOperand(a3, HeapObject::kMapOffset));
svenpanne@chromium.org830d30c2012-05-29 13:20:14 +0000458 __ LoadTransitionedArrayMapConditional(FAST_SMI_ELEMENTS,
ulan@chromium.org65a89c22012-02-14 11:46:07 +0000459 FAST_ELEMENTS,
460 a2,
461 t5,
462 &cant_transition_map);
463 __ sw(a2, FieldMemOperand(a3, HeapObject::kMapOffset));
464 __ RecordWriteField(a3,
465 HeapObject::kMapOffset,
466 a2,
467 t5,
468 kRAHasNotBeenSaved,
469 kDontSaveFPRegs,
470 EMIT_REMEMBERED_SET,
471 OMIT_SMI_CHECK);
472 Label loop2;
473 __ bind(&loop2);
474 __ lw(a2, MemOperand(t3));
475 __ Addu(t3, t3, kPointerSize);
476 __ Subu(t1, t1, kPointerSize);
477 __ sw(a2, MemOperand(t1));
478 __ Branch(&loop2, lt, t0, Operand(t1));
479 __ Branch(&finish);
rossberg@chromium.orgfab14982012-01-05 15:02:15 +0000480}
481
482
483void Builtins::Generate_InternalArrayCode(MacroAssembler* masm) {
484 // ----------- S t a t e -------------
485 // -- a0 : number of arguments
486 // -- ra : return address
487 // -- sp[...]: constructor arguments
488 // -----------------------------------
489 Label generic_array_code, one_or_more_arguments, two_or_more_arguments;
490
491 // Get the InternalArray function.
492 GenerateLoadInternalArrayFunction(masm, a1);
493
494 if (FLAG_debug_code) {
495 // Initial map for the builtin InternalArray functions should be maps.
496 __ lw(a2, FieldMemOperand(a1, JSFunction::kPrototypeOrInitialMapOffset));
497 __ And(t0, a2, Operand(kSmiTagMask));
498 __ Assert(ne, "Unexpected initial map for InternalArray function",
499 t0, Operand(zero_reg));
500 __ GetObjectType(a2, a3, t0);
501 __ Assert(eq, "Unexpected initial map for InternalArray function",
502 t0, Operand(MAP_TYPE));
503 }
504
505 // Run the native code for the InternalArray function called as a normal
506 // function.
507 ArrayNativeCode(masm, &generic_array_code);
508
509 // Jump to the generic array code if the specialized code cannot handle the
510 // construction.
511 __ bind(&generic_array_code);
512
513 Handle<Code> array_code =
514 masm->isolate()->builtins()->InternalArrayCodeGeneric();
515 __ Jump(array_code, RelocInfo::CODE_TARGET);
ager@chromium.org5c838252010-02-19 08:53:10 +0000516}
517
518
519void Builtins::Generate_ArrayCode(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000520 // ----------- S t a t e -------------
521 // -- a0 : number of arguments
522 // -- ra : return address
523 // -- sp[...]: constructor arguments
524 // -----------------------------------
525 Label generic_array_code;
526
527 // Get the Array function.
528 GenerateLoadArrayFunction(masm, a1);
529
530 if (FLAG_debug_code) {
531 // Initial map for the builtin Array functions should be maps.
532 __ lw(a2, FieldMemOperand(a1, JSFunction::kPrototypeOrInitialMapOffset));
533 __ And(t0, a2, Operand(kSmiTagMask));
534 __ Assert(ne, "Unexpected initial map for Array function (1)",
535 t0, Operand(zero_reg));
536 __ GetObjectType(a2, a3, t0);
537 __ Assert(eq, "Unexpected initial map for Array function (2)",
538 t0, Operand(MAP_TYPE));
539 }
540
541 // Run the native code for the Array function called as a normal function.
542 ArrayNativeCode(masm, &generic_array_code);
543
544 // Jump to the generic array code if the specialized code cannot handle
545 // the construction.
546 __ bind(&generic_array_code);
547
548 Handle<Code> array_code =
549 masm->isolate()->builtins()->ArrayCodeGeneric();
550 __ Jump(array_code, RelocInfo::CODE_TARGET);
ager@chromium.org5c838252010-02-19 08:53:10 +0000551}
552
553
554void Builtins::Generate_ArrayConstructCode(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000555 // ----------- S t a t e -------------
556 // -- a0 : number of arguments
557 // -- a1 : constructor function
558 // -- ra : return address
559 // -- sp[...]: constructor arguments
560 // -----------------------------------
561 Label generic_constructor;
562
563 if (FLAG_debug_code) {
564 // The array construct code is only set for the builtin and internal
565 // Array functions which always have a map.
566 // Initial map for the builtin Array function should be a map.
567 __ lw(a2, FieldMemOperand(a1, JSFunction::kPrototypeOrInitialMapOffset));
568 __ And(t0, a2, Operand(kSmiTagMask));
569 __ Assert(ne, "Unexpected initial map for Array function (3)",
570 t0, Operand(zero_reg));
571 __ GetObjectType(a2, a3, t0);
572 __ Assert(eq, "Unexpected initial map for Array function (4)",
573 t0, Operand(MAP_TYPE));
574 }
575
576 // Run the native code for the Array function called as a constructor.
577 ArrayNativeCode(masm, &generic_constructor);
578
579 // Jump to the generic construct code in case the specialized code cannot
580 // handle the construction.
581 __ bind(&generic_constructor);
582
583 Handle<Code> generic_construct_stub =
584 masm->isolate()->builtins()->JSConstructStubGeneric();
585 __ Jump(generic_construct_stub, RelocInfo::CODE_TARGET);
ager@chromium.org5c838252010-02-19 08:53:10 +0000586}
587
588
lrn@chromium.org7516f052011-03-30 08:52:27 +0000589void Builtins::Generate_StringConstructCode(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000590 // ----------- S t a t e -------------
591 // -- a0 : number of arguments
592 // -- a1 : constructor function
593 // -- ra : return address
594 // -- sp[(argc - n - 1) * 4] : arg[n] (zero based)
595 // -- sp[argc * 4] : receiver
596 // -----------------------------------
597 Counters* counters = masm->isolate()->counters();
598 __ IncrementCounter(counters->string_ctor_calls(), 1, a2, a3);
599
600 Register function = a1;
601 if (FLAG_debug_code) {
602 __ LoadGlobalFunction(Context::STRING_FUNCTION_INDEX, a2);
603 __ Assert(eq, "Unexpected String function", function, Operand(a2));
604 }
605
606 // Load the first arguments in a0 and get rid of the rest.
607 Label no_arguments;
608 __ Branch(&no_arguments, eq, a0, Operand(zero_reg));
609 // First args = sp[(argc - 1) * 4].
610 __ Subu(a0, a0, Operand(1));
611 __ sll(a0, a0, kPointerSizeLog2);
612 __ Addu(sp, a0, sp);
613 __ lw(a0, MemOperand(sp));
614 // sp now point to args[0], drop args[0] + receiver.
615 __ Drop(2);
616
617 Register argument = a2;
618 Label not_cached, argument_is_string;
619 NumberToStringStub::GenerateLookupNumberStringCache(
620 masm,
621 a0, // Input.
622 argument, // Result.
623 a3, // Scratch.
624 t0, // Scratch.
625 t1, // Scratch.
626 false, // Is it a Smi?
627 &not_cached);
628 __ IncrementCounter(counters->string_ctor_cached_number(), 1, a3, t0);
629 __ bind(&argument_is_string);
630
631 // ----------- S t a t e -------------
632 // -- a2 : argument converted to string
633 // -- a1 : constructor function
634 // -- ra : return address
635 // -----------------------------------
636
637 Label gc_required;
638 __ AllocateInNewSpace(JSValue::kSize,
639 v0, // Result.
640 a3, // Scratch.
641 t0, // Scratch.
642 &gc_required,
643 TAG_OBJECT);
644
645 // Initialising the String Object.
646 Register map = a3;
647 __ LoadGlobalFunctionInitialMap(function, map, t0);
648 if (FLAG_debug_code) {
649 __ lbu(t0, FieldMemOperand(map, Map::kInstanceSizeOffset));
650 __ Assert(eq, "Unexpected string wrapper instance size",
651 t0, Operand(JSValue::kSize >> kPointerSizeLog2));
652 __ lbu(t0, FieldMemOperand(map, Map::kUnusedPropertyFieldsOffset));
653 __ Assert(eq, "Unexpected unused properties of string wrapper",
654 t0, Operand(zero_reg));
655 }
656 __ sw(map, FieldMemOperand(v0, HeapObject::kMapOffset));
657
658 __ LoadRoot(a3, Heap::kEmptyFixedArrayRootIndex);
659 __ sw(a3, FieldMemOperand(v0, JSObject::kPropertiesOffset));
660 __ sw(a3, FieldMemOperand(v0, JSObject::kElementsOffset));
661
662 __ sw(argument, FieldMemOperand(v0, JSValue::kValueOffset));
663
664 // Ensure the object is fully initialized.
665 STATIC_ASSERT(JSValue::kSize == 4 * kPointerSize);
666
667 __ Ret();
668
669 // The argument was not found in the number to string cache. Check
670 // if it's a string already before calling the conversion builtin.
671 Label convert_argument;
672 __ bind(&not_cached);
673 __ JumpIfSmi(a0, &convert_argument);
674
675 // Is it a String?
676 __ lw(a2, FieldMemOperand(a0, HeapObject::kMapOffset));
677 __ lbu(a3, FieldMemOperand(a2, Map::kInstanceTypeOffset));
fschneider@chromium.org1805e212011-09-05 10:49:12 +0000678 STATIC_ASSERT(kNotStringTag != 0);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000679 __ And(t0, a3, Operand(kIsNotStringMask));
680 __ Branch(&convert_argument, ne, t0, Operand(zero_reg));
681 __ mov(argument, a0);
682 __ IncrementCounter(counters->string_ctor_conversions(), 1, a3, t0);
683 __ Branch(&argument_is_string);
684
685 // Invoke the conversion builtin and put the result into a2.
686 __ bind(&convert_argument);
687 __ push(function); // Preserve the function.
688 __ IncrementCounter(counters->string_ctor_conversions(), 1, a3, t0);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000689 {
690 FrameScope scope(masm, StackFrame::INTERNAL);
691 __ push(v0);
692 __ InvokeBuiltin(Builtins::TO_STRING, CALL_FUNCTION);
693 }
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000694 __ pop(function);
695 __ mov(argument, v0);
696 __ Branch(&argument_is_string);
697
698 // Load the empty string into a2, remove the receiver from the
699 // stack, and jump back to the case where the argument is a string.
700 __ bind(&no_arguments);
701 __ LoadRoot(argument, Heap::kEmptyStringRootIndex);
702 __ Drop(1);
703 __ Branch(&argument_is_string);
704
705 // At this point the argument is already a string. Call runtime to
706 // create a string wrapper.
707 __ bind(&gc_required);
708 __ IncrementCounter(counters->string_ctor_gc_required(), 1, a3, t0);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000709 {
710 FrameScope scope(masm, StackFrame::INTERNAL);
711 __ push(argument);
712 __ CallRuntime(Runtime::kNewStringWrapper, 1);
713 }
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000714 __ Ret();
lrn@chromium.org7516f052011-03-30 08:52:27 +0000715}
716
717
danno@chromium.org129d3982012-07-25 15:01:47 +0000718static void GenerateTailCallToSharedCode(MacroAssembler* masm) {
719 __ lw(a2, FieldMemOperand(a1, JSFunction::kSharedFunctionInfoOffset));
720 __ lw(a2, FieldMemOperand(a2, SharedFunctionInfo::kCodeOffset));
721 __ Addu(at, a2, Operand(Code::kHeaderSize - kHeapObjectTag));
722 __ Jump(at);
723}
724
725
726void Builtins::Generate_InRecompileQueue(MacroAssembler* masm) {
727 GenerateTailCallToSharedCode(masm);
728}
729
730
731void Builtins::Generate_ParallelRecompile(MacroAssembler* masm) {
732 {
733 FrameScope scope(masm, StackFrame::INTERNAL);
734
735 // Push a copy of the function onto the stack.
736 __ push(a1);
737 // Push call kind information.
738 __ push(t1);
739
740 __ push(a1); // Function is also the parameter to the runtime call.
741 __ CallRuntime(Runtime::kParallelRecompile, 1);
742
743 // Restore call kind information.
744 __ pop(t1);
745 // Restore receiver.
746 __ pop(a1);
747
748 // Tear down internal frame.
749 }
750
751 GenerateTailCallToSharedCode(masm);
752}
753
754
danno@chromium.orgfa458e42012-02-01 10:48:36 +0000755static void Generate_JSConstructStubHelper(MacroAssembler* masm,
756 bool is_api_function,
757 bool count_constructions) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000758 // ----------- S t a t e -------------
759 // -- a0 : number of arguments
760 // -- a1 : constructor function
761 // -- ra : return address
762 // -- sp[...]: constructor arguments
763 // -----------------------------------
764
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000765 // Should never count constructions for api objects.
766 ASSERT(!is_api_function || !count_constructions);
767
768 Isolate* isolate = masm->isolate();
769
770 // ----------- S t a t e -------------
771 // -- a0 : number of arguments
772 // -- a1 : constructor function
773 // -- ra : return address
774 // -- sp[...]: constructor arguments
775 // -----------------------------------
776
777 // Enter a construct frame.
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000778 {
779 FrameScope scope(masm, StackFrame::CONSTRUCT);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000780
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000781 // Preserve the two incoming parameters on the stack.
782 __ sll(a0, a0, kSmiTagSize); // Tag arguments count.
783 __ MultiPushReversed(a0.bit() | a1.bit());
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000784
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000785 // Use t7 to hold undefined, which is used in several places below.
786 __ LoadRoot(t7, Heap::kUndefinedValueRootIndex);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000787
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000788 Label rt_call, allocated;
789 // Try to allocate the object without transitioning into C code. If any of
790 // the preconditions is not met, the code bails out to the runtime call.
791 if (FLAG_inline_new) {
792 Label undo_allocation;
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000793#ifdef ENABLE_DEBUGGER_SUPPORT
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000794 ExternalReference debug_step_in_fp =
795 ExternalReference::debug_step_in_fp_address(isolate);
796 __ li(a2, Operand(debug_step_in_fp));
797 __ lw(a2, MemOperand(a2));
798 __ Branch(&rt_call, ne, a2, Operand(zero_reg));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000799#endif
800
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000801 // Load the initial map and verify that it is in fact a map.
802 // a1: constructor function
803 __ lw(a2, FieldMemOperand(a1, JSFunction::kPrototypeOrInitialMapOffset));
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +0000804 __ JumpIfSmi(a2, &rt_call);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000805 __ GetObjectType(a2, a3, t4);
806 __ Branch(&rt_call, ne, t4, Operand(MAP_TYPE));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000807
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000808 // Check that the constructor is not constructing a JSFunction (see
809 // comments in Runtime_NewObject in runtime.cc). In which case the
810 // initial map's instance type would be JS_FUNCTION_TYPE.
811 // a1: constructor function
812 // a2: initial map
813 __ lbu(a3, FieldMemOperand(a2, Map::kInstanceTypeOffset));
814 __ Branch(&rt_call, eq, a3, Operand(JS_FUNCTION_TYPE));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000815
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000816 if (count_constructions) {
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000817 Label allocate;
818 // Decrease generous allocation count.
819 __ lw(a3, FieldMemOperand(a1, JSFunction::kSharedFunctionInfoOffset));
820 MemOperand constructor_count =
821 FieldMemOperand(a3, SharedFunctionInfo::kConstructionCountOffset);
822 __ lbu(t0, constructor_count);
823 __ Subu(t0, t0, Operand(1));
824 __ sb(t0, constructor_count);
825 __ Branch(&allocate, ne, t0, Operand(zero_reg));
826
827 __ Push(a1, a2);
828
829 __ push(a1); // Constructor.
830 // The call will replace the stub, so the countdown is only done once.
831 __ CallRuntime(Runtime::kFinalizeInstanceSize, 1);
832
833 __ pop(a2);
834 __ pop(a1);
835
836 __ bind(&allocate);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000837 }
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000838
839 // Now allocate the JSObject on the heap.
840 // a1: constructor function
841 // a2: initial map
842 __ lbu(a3, FieldMemOperand(a2, Map::kInstanceSizeOffset));
843 __ AllocateInNewSpace(a3, t4, t5, t6, &rt_call, SIZE_IN_WORDS);
844
845 // Allocated the JSObject, now initialize the fields. Map is set to
846 // initial map and properties and elements are set to empty fixed array.
847 // a1: constructor function
848 // a2: initial map
849 // a3: object size
850 // t4: JSObject (not tagged)
851 __ LoadRoot(t6, Heap::kEmptyFixedArrayRootIndex);
852 __ mov(t5, t4);
853 __ sw(a2, MemOperand(t5, JSObject::kMapOffset));
854 __ sw(t6, MemOperand(t5, JSObject::kPropertiesOffset));
855 __ sw(t6, MemOperand(t5, JSObject::kElementsOffset));
856 __ Addu(t5, t5, Operand(3*kPointerSize));
857 ASSERT_EQ(0 * kPointerSize, JSObject::kMapOffset);
858 ASSERT_EQ(1 * kPointerSize, JSObject::kPropertiesOffset);
859 ASSERT_EQ(2 * kPointerSize, JSObject::kElementsOffset);
860
861 // Fill all the in-object properties with appropriate filler.
862 // a1: constructor function
863 // a2: initial map
864 // a3: object size (in words)
865 // t4: JSObject (not tagged)
866 // t5: First in-object property of JSObject (not tagged)
867 __ sll(t0, a3, kPointerSizeLog2);
868 __ addu(t6, t4, t0); // End of object.
869 ASSERT_EQ(3 * kPointerSize, JSObject::kHeaderSize);
rossberg@chromium.orgb4b2aa62011-10-13 09:49:59 +0000870 __ LoadRoot(t7, Heap::kUndefinedValueRootIndex);
871 if (count_constructions) {
872 __ lw(a0, FieldMemOperand(a2, Map::kInstanceSizesOffset));
873 __ Ext(a0, a0, Map::kPreAllocatedPropertyFieldsByte * kBitsPerByte,
874 kBitsPerByte);
875 __ sll(t0, a0, kPointerSizeLog2);
876 __ addu(a0, t5, t0);
877 // a0: offset of first field after pre-allocated fields
878 if (FLAG_debug_code) {
879 __ Assert(le, "Unexpected number of pre-allocated property fields.",
880 a0, Operand(t6));
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000881 }
rossberg@chromium.orgb4b2aa62011-10-13 09:49:59 +0000882 __ InitializeFieldsWithFiller(t5, a0, t7);
883 // To allow for truncation.
884 __ LoadRoot(t7, Heap::kOnePointerFillerMapRootIndex);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000885 }
rossberg@chromium.orgb4b2aa62011-10-13 09:49:59 +0000886 __ InitializeFieldsWithFiller(t5, t6, t7);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000887
888 // Add the object tag to make the JSObject real, so that we can continue
889 // and jump into the continuation code at any time from now on. Any
890 // failures need to undo the allocation, so that the heap is in a
891 // consistent state and verifiable.
892 __ Addu(t4, t4, Operand(kHeapObjectTag));
893
894 // Check if a non-empty properties array is needed. Continue with
895 // allocated object if not fall through to runtime call if it is.
896 // a1: constructor function
897 // t4: JSObject
898 // t5: start of next object (not tagged)
899 __ lbu(a3, FieldMemOperand(a2, Map::kUnusedPropertyFieldsOffset));
900 // The field instance sizes contains both pre-allocated property fields
901 // and in-object properties.
902 __ lw(a0, FieldMemOperand(a2, Map::kInstanceSizesOffset));
rossberg@chromium.orgb4b2aa62011-10-13 09:49:59 +0000903 __ Ext(t6, a0, Map::kPreAllocatedPropertyFieldsByte * kBitsPerByte,
904 kBitsPerByte);
905 __ Addu(a3, a3, Operand(t6));
906 __ Ext(t6, a0, Map::kInObjectPropertiesByte * kBitsPerByte,
907 kBitsPerByte);
908 __ subu(a3, a3, t6);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000909
910 // Done if no extra properties are to be allocated.
911 __ Branch(&allocated, eq, a3, Operand(zero_reg));
912 __ Assert(greater_equal, "Property allocation count failed.",
913 a3, Operand(zero_reg));
914
915 // Scale the number of elements by pointer size and add the header for
916 // FixedArrays to the start of the next object calculation from above.
917 // a1: constructor
918 // a3: number of elements in properties array
919 // t4: JSObject
920 // t5: start of next object
921 __ Addu(a0, a3, Operand(FixedArray::kHeaderSize / kPointerSize));
922 __ AllocateInNewSpace(
923 a0,
924 t5,
925 t6,
926 a2,
927 &undo_allocation,
928 static_cast<AllocationFlags>(RESULT_CONTAINS_TOP | SIZE_IN_WORDS));
929
930 // Initialize the FixedArray.
931 // a1: constructor
ulan@chromium.org2efb9002012-01-19 15:36:35 +0000932 // a3: number of elements in properties array (untagged)
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000933 // t4: JSObject
934 // t5: start of next object
935 __ LoadRoot(t6, Heap::kFixedArrayMapRootIndex);
936 __ mov(a2, t5);
937 __ sw(t6, MemOperand(a2, JSObject::kMapOffset));
938 __ sll(a0, a3, kSmiTagSize);
939 __ sw(a0, MemOperand(a2, FixedArray::kLengthOffset));
940 __ Addu(a2, a2, Operand(2 * kPointerSize));
941
942 ASSERT_EQ(0 * kPointerSize, JSObject::kMapOffset);
943 ASSERT_EQ(1 * kPointerSize, FixedArray::kLengthOffset);
944
945 // Initialize the fields to undefined.
946 // a1: constructor
947 // a2: First element of FixedArray (not tagged)
948 // a3: number of elements in properties array
949 // t4: JSObject
950 // t5: FixedArray (not tagged)
951 __ sll(t3, a3, kPointerSizeLog2);
952 __ addu(t6, a2, t3); // End of object.
953 ASSERT_EQ(2 * kPointerSize, FixedArray::kHeaderSize);
954 { Label loop, entry;
955 if (count_constructions) {
956 __ LoadRoot(t7, Heap::kUndefinedValueRootIndex);
957 } else if (FLAG_debug_code) {
958 __ LoadRoot(t8, Heap::kUndefinedValueRootIndex);
959 __ Assert(eq, "Undefined value not loaded.", t7, Operand(t8));
960 }
961 __ jmp(&entry);
962 __ bind(&loop);
963 __ sw(t7, MemOperand(a2));
964 __ addiu(a2, a2, kPointerSize);
965 __ bind(&entry);
966 __ Branch(&loop, less, a2, Operand(t6));
967 }
968
969 // Store the initialized FixedArray into the properties field of
970 // the JSObject.
971 // a1: constructor function
972 // t4: JSObject
973 // t5: FixedArray (not tagged)
974 __ Addu(t5, t5, Operand(kHeapObjectTag)); // Add the heap tag.
975 __ sw(t5, FieldMemOperand(t4, JSObject::kPropertiesOffset));
976
977 // Continue with JSObject being successfully allocated.
978 // a1: constructor function
979 // a4: JSObject
980 __ jmp(&allocated);
981
982 // Undo the setting of the new top so that the heap is verifiable. For
983 // example, the map's unused properties potentially do not match the
984 // allocated objects unused properties.
985 // t4: JSObject (previous new top)
986 __ bind(&undo_allocation);
987 __ UndoAllocationInNewSpace(t4, t5);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000988 }
989
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000990 __ bind(&rt_call);
991 // Allocate the new receiver object using the runtime call.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000992 // a1: constructor function
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000993 __ push(a1); // Argument for Runtime_NewObject.
994 __ CallRuntime(Runtime::kNewObject, 1);
995 __ mov(t4, v0);
996
997 // Receiver for constructor call allocated.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +0000998 // t4: JSObject
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +0000999 __ bind(&allocated);
1000 __ push(t4);
yangguo@chromium.org78d1ad42012-02-09 13:53:47 +00001001 __ push(t4);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001002
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001003 // Reload the number of arguments from the stack.
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001004 // sp[0]: receiver
yangguo@chromium.org78d1ad42012-02-09 13:53:47 +00001005 // sp[1]: receiver
1006 // sp[2]: constructor function
1007 // sp[3]: number of arguments (smi-tagged)
1008 __ lw(a1, MemOperand(sp, 2 * kPointerSize));
1009 __ lw(a3, MemOperand(sp, 3 * kPointerSize));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001010
erik.corry@gmail.comf2038fb2012-01-16 11:42:08 +00001011 // Set up pointer to last argument.
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001012 __ Addu(a2, fp, Operand(StandardFrameConstants::kCallerSPOffset));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001013
erik.corry@gmail.comf2038fb2012-01-16 11:42:08 +00001014 // Set up number of arguments for function call below.
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001015 __ srl(a0, a3, kSmiTagSize);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001016
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001017 // Copy arguments and receiver to the expression stack.
1018 // a0: number of arguments
1019 // a1: constructor function
1020 // a2: address of last argument (caller sp)
1021 // a3: number of arguments (smi-tagged)
1022 // sp[0]: receiver
yangguo@chromium.org78d1ad42012-02-09 13:53:47 +00001023 // sp[1]: receiver
1024 // sp[2]: constructor function
1025 // sp[3]: number of arguments (smi-tagged)
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001026 Label loop, entry;
1027 __ jmp(&entry);
1028 __ bind(&loop);
1029 __ sll(t0, a3, kPointerSizeLog2 - kSmiTagSize);
1030 __ Addu(t0, a2, Operand(t0));
1031 __ lw(t1, MemOperand(t0));
1032 __ push(t1);
1033 __ bind(&entry);
1034 __ Addu(a3, a3, Operand(-2));
1035 __ Branch(&loop, greater_equal, a3, Operand(zero_reg));
1036
1037 // Call the function.
1038 // a0: number of arguments
1039 // a1: constructor function
1040 if (is_api_function) {
1041 __ lw(cp, FieldMemOperand(a1, JSFunction::kContextOffset));
1042 Handle<Code> code =
1043 masm->isolate()->builtins()->HandleApiCallConstruct();
1044 ParameterCount expected(0);
1045 __ InvokeCode(code, expected, expected,
1046 RelocInfo::CODE_TARGET, CALL_FUNCTION, CALL_AS_METHOD);
1047 } else {
1048 ParameterCount actual(a0);
1049 __ InvokeFunction(a1, actual, CALL_FUNCTION,
1050 NullCallWrapper(), CALL_AS_METHOD);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001051 }
1052
ulan@chromium.org812308e2012-02-29 15:58:45 +00001053 // Store offset of return address for deoptimizer.
1054 if (!is_api_function && !count_constructions) {
1055 masm->isolate()->heap()->SetConstructStubDeoptPCOffset(masm->pc_offset());
1056 }
1057
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001058 // Restore context from the frame.
1059 __ lw(cp, MemOperand(fp, StandardFrameConstants::kContextOffset));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001060
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001061 // If the result is an object (in the ECMA sense), we should get rid
1062 // of the receiver and use the result; see ECMA-262 section 13.2.2-7
1063 // on page 74.
1064 Label use_receiver, exit;
1065
1066 // If the result is a smi, it is *not* an object in the ECMA sense.
1067 // v0: result
1068 // sp[0]: receiver (newly allocated object)
1069 // sp[1]: constructor function
1070 // sp[2]: number of arguments (smi-tagged)
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +00001071 __ JumpIfSmi(v0, &use_receiver);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001072
1073 // If the type of the result (stored in its map) is less than
1074 // FIRST_SPEC_OBJECT_TYPE, it is not an object in the ECMA sense.
1075 __ GetObjectType(v0, a3, a3);
1076 __ Branch(&exit, greater_equal, a3, Operand(FIRST_SPEC_OBJECT_TYPE));
1077
1078 // Throw away the result of the constructor invocation and use the
1079 // on-stack receiver as the result.
1080 __ bind(&use_receiver);
1081 __ lw(v0, MemOperand(sp));
1082
1083 // Remove receiver from the stack, remove caller arguments, and
1084 // return.
1085 __ bind(&exit);
1086 // v0: result
1087 // sp[0]: receiver (newly allocated object)
1088 // sp[1]: constructor function
1089 // sp[2]: number of arguments (smi-tagged)
1090 __ lw(a1, MemOperand(sp, 2 * kPointerSize));
1091
1092 // Leave construct frame.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001093 }
1094
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001095 __ sll(t0, a1, kPointerSizeLog2 - 1);
1096 __ Addu(sp, sp, t0);
1097 __ Addu(sp, sp, kPointerSize);
1098 __ IncrementCounter(isolate->counters()->constructed_objects(), 1, a1, a2);
1099 __ Ret();
ager@chromium.org5c838252010-02-19 08:53:10 +00001100}
1101
1102
lrn@chromium.org7516f052011-03-30 08:52:27 +00001103void Builtins::Generate_JSConstructStubCountdown(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001104 Generate_JSConstructStubHelper(masm, false, true);
lrn@chromium.org7516f052011-03-30 08:52:27 +00001105}
1106
1107
ager@chromium.org5c838252010-02-19 08:53:10 +00001108void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001109 Generate_JSConstructStubHelper(masm, false, false);
ager@chromium.org5c838252010-02-19 08:53:10 +00001110}
1111
1112
1113void Builtins::Generate_JSConstructStubApi(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001114 Generate_JSConstructStubHelper(masm, true, false);
1115}
1116
1117
1118static void Generate_JSEntryTrampolineHelper(MacroAssembler* masm,
1119 bool is_construct) {
1120 // Called from JSEntryStub::GenerateBody
1121
1122 // ----------- S t a t e -------------
1123 // -- a0: code entry
1124 // -- a1: function
ulan@chromium.org2efb9002012-01-19 15:36:35 +00001125 // -- a2: receiver_pointer
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001126 // -- a3: argc
1127 // -- s0: argv
1128 // -----------------------------------
1129
1130 // Clear the context before we push it when entering the JS frame.
1131 __ mov(cp, zero_reg);
1132
1133 // Enter an internal frame.
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001134 {
1135 FrameScope scope(masm, StackFrame::INTERNAL);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001136
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001137 // Set up the context from the function argument.
1138 __ lw(cp, FieldMemOperand(a1, JSFunction::kContextOffset));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001139
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001140 // Push the function and the receiver onto the stack.
1141 __ Push(a1, a2);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001142
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001143 // Copy arguments to the stack in a loop.
1144 // a3: argc
ulan@chromium.org2efb9002012-01-19 15:36:35 +00001145 // s0: argv, i.e. points to first arg
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001146 Label loop, entry;
1147 __ sll(t0, a3, kPointerSizeLog2);
1148 __ addu(t2, s0, t0);
1149 __ b(&entry);
1150 __ nop(); // Branch delay slot nop.
1151 // t2 points past last arg.
1152 __ bind(&loop);
1153 __ lw(t0, MemOperand(s0)); // Read next parameter.
1154 __ addiu(s0, s0, kPointerSize);
1155 __ lw(t0, MemOperand(t0)); // Dereference handle.
1156 __ push(t0); // Push parameter.
1157 __ bind(&entry);
1158 __ Branch(&loop, ne, s0, Operand(t2));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001159
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001160 // Initialize all JavaScript callee-saved registers, since they will be seen
1161 // by the garbage collector as part of handlers.
1162 __ LoadRoot(t0, Heap::kUndefinedValueRootIndex);
1163 __ mov(s1, t0);
1164 __ mov(s2, t0);
1165 __ mov(s3, t0);
1166 __ mov(s4, t0);
1167 __ mov(s5, t0);
1168 // s6 holds the root address. Do not clobber.
1169 // s7 is cp. Do not init.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001170
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001171 // Invoke the code and pass argc as a0.
1172 __ mov(a0, a3);
1173 if (is_construct) {
danno@chromium.orgfa458e42012-02-01 10:48:36 +00001174 CallConstructStub stub(NO_CALL_FUNCTION_FLAGS);
1175 __ CallStub(&stub);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001176 } else {
1177 ParameterCount actual(a0);
1178 __ InvokeFunction(a1, actual, CALL_FUNCTION,
1179 NullCallWrapper(), CALL_AS_METHOD);
1180 }
1181
1182 // Leave internal frame.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001183 }
1184
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001185 __ Jump(ra);
ager@chromium.org5c838252010-02-19 08:53:10 +00001186}
1187
1188
ager@chromium.org5c838252010-02-19 08:53:10 +00001189void Builtins::Generate_JSEntryTrampoline(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001190 Generate_JSEntryTrampolineHelper(masm, false);
ager@chromium.org5c838252010-02-19 08:53:10 +00001191}
1192
1193
1194void Builtins::Generate_JSConstructEntryTrampoline(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001195 Generate_JSEntryTrampolineHelper(masm, true);
lrn@chromium.org7516f052011-03-30 08:52:27 +00001196}
1197
1198
1199void Builtins::Generate_LazyCompile(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001200 // Enter an internal frame.
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001201 {
1202 FrameScope scope(masm, StackFrame::INTERNAL);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001203
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001204 // Preserve the function.
1205 __ push(a1);
1206 // Push call kind information.
1207 __ push(t1);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001208
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001209 // Push the function on the stack as the argument to the runtime function.
1210 __ push(a1);
1211 // Call the runtime function.
1212 __ CallRuntime(Runtime::kLazyCompile, 1);
1213 // Calculate the entry point.
1214 __ addiu(t9, v0, Code::kHeaderSize - kHeapObjectTag);
danno@chromium.org40cb8782011-05-25 07:58:50 +00001215
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001216 // Restore call kind information.
1217 __ pop(t1);
1218 // Restore saved function.
1219 __ pop(a1);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001220
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001221 // Tear down temporary frame.
1222 }
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001223
1224 // Do a tail-call of the compiled function.
1225 __ Jump(t9);
lrn@chromium.org7516f052011-03-30 08:52:27 +00001226}
1227
1228
1229void Builtins::Generate_LazyRecompile(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001230 // Enter an internal frame.
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001231 {
1232 FrameScope scope(masm, StackFrame::INTERNAL);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001233
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001234 // Preserve the function.
1235 __ push(a1);
1236 // Push call kind information.
1237 __ push(t1);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001238
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001239 // Push the function on the stack as the argument to the runtime function.
1240 __ push(a1);
1241 __ CallRuntime(Runtime::kLazyRecompile, 1);
1242 // Calculate the entry point.
1243 __ Addu(t9, v0, Operand(Code::kHeaderSize - kHeapObjectTag));
danno@chromium.org40cb8782011-05-25 07:58:50 +00001244
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001245 // Restore call kind information.
1246 __ pop(t1);
1247 // Restore saved function.
1248 __ pop(a1);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001249
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001250 // Tear down temporary frame.
1251 }
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001252
1253 // Do a tail-call of the compiled function.
1254 __ Jump(t9);
lrn@chromium.org7516f052011-03-30 08:52:27 +00001255}
1256
1257
yangguo@chromium.orgfb377212012-11-16 14:43:43 +00001258static void GenerateMakeCodeYoungAgainCommon(MacroAssembler* masm) {
1259 // For now, we are relying on the fact that make_code_young doesn't do any
1260 // garbage collection which allows us to save/restore the registers without
1261 // worrying about which of them contain pointers. We also don't build an
1262 // internal frame to make the code faster, since we shouldn't have to do stack
1263 // crawls in MakeCodeYoung. This seems a bit fragile.
1264
1265 __ mov(a0, ra);
1266 // Adjust a0 to point to the head of the PlatformCodeAge sequence
1267 __ Subu(a0, a0,
1268 Operand((kNoCodeAgeSequenceLength - 1) * Assembler::kInstrSize));
1269 // Restore the original return address of the function
1270 __ mov(ra, at);
1271
1272 // The following registers must be saved and restored when calling through to
1273 // the runtime:
1274 // a0 - contains return address (beginning of patch sequence)
1275 // a1 - function object
1276 RegList saved_regs =
1277 (a0.bit() | a1.bit() | ra.bit() | fp.bit()) & ~sp.bit();
1278 FrameScope scope(masm, StackFrame::MANUAL);
1279 __ MultiPush(saved_regs);
1280 __ PrepareCallCFunction(1, 0, a1);
1281 __ CallCFunction(
1282 ExternalReference::get_make_code_young_function(masm->isolate()), 1);
1283 __ MultiPop(saved_regs);
1284 __ Jump(a0);
1285}
1286
1287#define DEFINE_CODE_AGE_BUILTIN_GENERATOR(C) \
1288void Builtins::Generate_Make##C##CodeYoungAgainEvenMarking( \
1289 MacroAssembler* masm) { \
1290 GenerateMakeCodeYoungAgainCommon(masm); \
1291} \
1292void Builtins::Generate_Make##C##CodeYoungAgainOddMarking( \
1293 MacroAssembler* masm) { \
1294 GenerateMakeCodeYoungAgainCommon(masm); \
1295}
1296CODE_AGE_LIST(DEFINE_CODE_AGE_BUILTIN_GENERATOR)
1297#undef DEFINE_CODE_AGE_BUILTIN_GENERATOR
1298
1299
jkummerow@chromium.org59297c72013-01-09 16:32:23 +00001300void Builtins::Generate_NotifyStubFailure(MacroAssembler* masm) {
1301 {
1302 FrameScope scope(masm, StackFrame::INTERNAL);
1303
1304 // Preserve registers across notification, this is important for compiled
1305 // stubs that tail call the runtime on deopts passing their parameters in
1306 // registers.
1307 __ MultiPush(kJSCallerSaved | kCalleeSaved);
1308 // Pass the function and deoptimization type to the runtime system.
1309 __ CallRuntime(Runtime::kNotifyStubFailure, 0);
1310 __ MultiPop(kJSCallerSaved | kCalleeSaved);
1311 }
1312
jkummerow@chromium.org59297c72013-01-09 16:32:23 +00001313 __ Addu(sp, sp, Operand(kPointerSize)); // Ignore state
mstarzinger@chromium.orge3b8d0f2013-02-01 09:06:41 +00001314 __ Jump(ra); // Jump to miss handler
jkummerow@chromium.org59297c72013-01-09 16:32:23 +00001315}
1316
1317
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +00001318static void Generate_NotifyDeoptimizedHelper(MacroAssembler* masm,
1319 Deoptimizer::BailoutType type) {
1320 {
1321 FrameScope scope(masm, StackFrame::INTERNAL);
1322 // Pass the function and deoptimization type to the runtime system.
1323 __ li(a0, Operand(Smi::FromInt(static_cast<int>(type))));
1324 __ push(a0);
1325 __ CallRuntime(Runtime::kNotifyDeoptimized, 1);
1326 }
1327
1328 // Get the full codegen state from the stack and untag it -> t2.
1329 __ lw(t2, MemOperand(sp, 0 * kPointerSize));
1330 __ SmiUntag(t2);
1331 // Switch on the state.
1332 Label with_tos_register, unknown_state;
1333 __ Branch(&with_tos_register,
1334 ne, t2, Operand(FullCodeGenerator::NO_REGISTERS));
1335 __ Addu(sp, sp, Operand(1 * kPointerSize)); // Remove state.
1336 __ Ret();
1337
1338 __ bind(&with_tos_register);
1339 __ lw(v0, MemOperand(sp, 1 * kPointerSize));
1340 __ Branch(&unknown_state, ne, t2, Operand(FullCodeGenerator::TOS_REG));
1341
1342 __ Addu(sp, sp, Operand(2 * kPointerSize)); // Remove state.
1343 __ Ret();
1344
1345 __ bind(&unknown_state);
1346 __ stop("no cases left");
1347}
1348
1349
lrn@chromium.org7516f052011-03-30 08:52:27 +00001350void Builtins::Generate_NotifyDeoptimized(MacroAssembler* masm) {
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +00001351 Generate_NotifyDeoptimizedHelper(masm, Deoptimizer::EAGER);
lrn@chromium.org7516f052011-03-30 08:52:27 +00001352}
1353
1354
1355void Builtins::Generate_NotifyLazyDeoptimized(MacroAssembler* masm) {
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +00001356 Generate_NotifyDeoptimizedHelper(masm, Deoptimizer::LAZY);
lrn@chromium.org7516f052011-03-30 08:52:27 +00001357}
1358
1359
1360void Builtins::Generate_NotifyOSR(MacroAssembler* masm) {
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +00001361 // For now, we are relying on the fact that Runtime::NotifyOSR
1362 // doesn't do any garbage collection which allows us to save/restore
1363 // the registers without worrying about which of them contain
1364 // pointers. This seems a bit fragile.
1365 RegList saved_regs =
1366 (kJSCallerSaved | kCalleeSaved | ra.bit() | fp.bit()) & ~sp.bit();
1367 __ MultiPush(saved_regs);
1368 {
1369 FrameScope scope(masm, StackFrame::INTERNAL);
1370 __ CallRuntime(Runtime::kNotifyOSR, 0);
1371 }
1372 __ MultiPop(saved_regs);
1373 __ Ret();
lrn@chromium.org7516f052011-03-30 08:52:27 +00001374}
1375
1376
1377void Builtins::Generate_OnStackReplacement(MacroAssembler* masm) {
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +00001378 CpuFeatures::TryForceFeatureScope scope(VFP3);
1379 if (!CpuFeatures::IsSupported(FPU)) {
1380 __ Abort("Unreachable code: Cannot optimize without FPU support.");
1381 return;
1382 }
1383
1384 // Lookup the function in the JavaScript frame and push it as an
1385 // argument to the on-stack replacement function.
1386 __ lw(a0, MemOperand(fp, JavaScriptFrameConstants::kFunctionOffset));
1387 {
1388 FrameScope scope(masm, StackFrame::INTERNAL);
1389 __ push(a0);
1390 __ CallRuntime(Runtime::kCompileForOnStackReplacement, 1);
1391 }
1392
1393 // If the result was -1 it means that we couldn't optimize the
1394 // function. Just return and continue in the unoptimized version.
1395 __ Ret(eq, v0, Operand(Smi::FromInt(-1)));
1396
1397 // Untag the AST id and push it on the stack.
1398 __ SmiUntag(v0);
1399 __ push(v0);
1400
1401 // Generate the code for doing the frame-to-frame translation using
1402 // the deoptimizer infrastructure.
1403 Deoptimizer::EntryGenerator generator(masm, Deoptimizer::OSR);
1404 generator.Generate();
ager@chromium.org5c838252010-02-19 08:53:10 +00001405}
1406
1407
1408void Builtins::Generate_FunctionCall(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001409 // 1. Make sure we have at least one argument.
1410 // a0: actual number of arguments
1411 { Label done;
1412 __ Branch(&done, ne, a0, Operand(zero_reg));
1413 __ LoadRoot(t2, Heap::kUndefinedValueRootIndex);
1414 __ push(t2);
1415 __ Addu(a0, a0, Operand(1));
1416 __ bind(&done);
1417 }
1418
1419 // 2. Get the function to call (passed as receiver) from the stack, check
1420 // if it is a function.
1421 // a0: actual number of arguments
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001422 Label slow, non_function;
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001423 __ sll(at, a0, kPointerSizeLog2);
1424 __ addu(at, sp, at);
1425 __ lw(a1, MemOperand(at));
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +00001426 __ JumpIfSmi(a1, &non_function);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001427 __ GetObjectType(a1, a2, a2);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001428 __ Branch(&slow, ne, a2, Operand(JS_FUNCTION_TYPE));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001429
1430 // 3a. Patch the first argument if necessary when calling a function.
1431 // a0: actual number of arguments
1432 // a1: function
1433 Label shift_arguments;
jkummerow@chromium.org59297c72013-01-09 16:32:23 +00001434 __ li(t0, Operand(0, RelocInfo::NONE32)); // Indicate regular JS_FUNCTION.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001435 { Label convert_to_object, use_global_receiver, patch_receiver;
1436 // Change context eagerly in case we need the global receiver.
1437 __ lw(cp, FieldMemOperand(a1, JSFunction::kContextOffset));
1438
1439 // Do not transform the receiver for strict mode functions.
1440 __ lw(a2, FieldMemOperand(a1, JSFunction::kSharedFunctionInfoOffset));
1441 __ lw(a3, FieldMemOperand(a2, SharedFunctionInfo::kCompilerHintsOffset));
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001442 __ And(t3, a3, Operand(1 << (SharedFunctionInfo::kStrictModeFunction +
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001443 kSmiTagSize)));
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001444 __ Branch(&shift_arguments, ne, t3, Operand(zero_reg));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001445
danno@chromium.org40cb8782011-05-25 07:58:50 +00001446 // Do not transform the receiver for native (Compilerhints already in a3).
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001447 __ And(t3, a3, Operand(1 << (SharedFunctionInfo::kNative + kSmiTagSize)));
1448 __ Branch(&shift_arguments, ne, t3, Operand(zero_reg));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001449
1450 // Compute the receiver in non-strict mode.
1451 // Load first argument in a2. a2 = -kPointerSize(sp + n_args << 2).
1452 __ sll(at, a0, kPointerSizeLog2);
1453 __ addu(a2, sp, at);
1454 __ lw(a2, MemOperand(a2, -kPointerSize));
1455 // a0: actual number of arguments
1456 // a1: function
1457 // a2: first argument
1458 __ JumpIfSmi(a2, &convert_to_object, t2);
1459
danno@chromium.org40cb8782011-05-25 07:58:50 +00001460 __ LoadRoot(a3, Heap::kUndefinedValueRootIndex);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001461 __ Branch(&use_global_receiver, eq, a2, Operand(a3));
1462 __ LoadRoot(a3, Heap::kNullValueRootIndex);
1463 __ Branch(&use_global_receiver, eq, a2, Operand(a3));
1464
erik.corry@gmail.comd6076d92011-06-06 09:39:18 +00001465 STATIC_ASSERT(LAST_SPEC_OBJECT_TYPE == LAST_TYPE);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001466 __ GetObjectType(a2, a3, a3);
erik.corry@gmail.comd6076d92011-06-06 09:39:18 +00001467 __ Branch(&shift_arguments, ge, a3, Operand(FIRST_SPEC_OBJECT_TYPE));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001468
1469 __ bind(&convert_to_object);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001470 // Enter an internal frame in order to preserve argument count.
1471 {
1472 FrameScope scope(masm, StackFrame::INTERNAL);
1473 __ sll(a0, a0, kSmiTagSize); // Smi tagged.
1474 __ push(a0);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001475
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001476 __ push(a2);
1477 __ InvokeBuiltin(Builtins::TO_OBJECT, CALL_FUNCTION);
1478 __ mov(a2, v0);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001479
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001480 __ pop(a0);
1481 __ sra(a0, a0, kSmiTagSize); // Un-tag.
1482 // Leave internal frame.
1483 }
1484 // Restore the function to a1, and the flag to t0.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001485 __ sll(at, a0, kPointerSizeLog2);
1486 __ addu(at, sp, at);
1487 __ lw(a1, MemOperand(at));
jkummerow@chromium.org59297c72013-01-09 16:32:23 +00001488 __ li(t0, Operand(0, RelocInfo::NONE32));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001489 __ Branch(&patch_receiver);
1490
1491 // Use the global receiver object from the called function as the
1492 // receiver.
1493 __ bind(&use_global_receiver);
1494 const int kGlobalIndex =
yangguo@chromium.org46839fb2012-08-28 09:06:19 +00001495 Context::kHeaderSize + Context::GLOBAL_OBJECT_INDEX * kPointerSize;
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001496 __ lw(a2, FieldMemOperand(cp, kGlobalIndex));
yangguo@chromium.org46839fb2012-08-28 09:06:19 +00001497 __ lw(a2, FieldMemOperand(a2, GlobalObject::kNativeContextOffset));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001498 __ lw(a2, FieldMemOperand(a2, kGlobalIndex));
1499 __ lw(a2, FieldMemOperand(a2, GlobalObject::kGlobalReceiverOffset));
1500
1501 __ bind(&patch_receiver);
1502 __ sll(at, a0, kPointerSizeLog2);
1503 __ addu(a3, sp, at);
1504 __ sw(a2, MemOperand(a3, -kPointerSize));
1505
1506 __ Branch(&shift_arguments);
1507 }
1508
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001509 // 3b. Check for function proxy.
1510 __ bind(&slow);
jkummerow@chromium.org59297c72013-01-09 16:32:23 +00001511 __ li(t0, Operand(1, RelocInfo::NONE32)); // Indicate function proxy.
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001512 __ Branch(&shift_arguments, eq, a2, Operand(JS_FUNCTION_PROXY_TYPE));
1513
1514 __ bind(&non_function);
jkummerow@chromium.org59297c72013-01-09 16:32:23 +00001515 __ li(t0, Operand(2, RelocInfo::NONE32)); // Indicate non-function.
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001516
1517 // 3c. Patch the first argument when calling a non-function. The
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001518 // CALL_NON_FUNCTION builtin expects the non-function callee as
1519 // receiver, so overwrite the first argument which will ultimately
1520 // become the receiver.
1521 // a0: actual number of arguments
1522 // a1: function
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001523 // t0: call type (0: JS function, 1: function proxy, 2: non-function)
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001524 __ sll(at, a0, kPointerSizeLog2);
1525 __ addu(a2, sp, at);
1526 __ sw(a1, MemOperand(a2, -kPointerSize));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001527
1528 // 4. Shift arguments and return address one slot down on the stack
1529 // (overwriting the original receiver). Adjust argument count to make
1530 // the original first argument the new receiver.
1531 // a0: actual number of arguments
1532 // a1: function
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001533 // t0: call type (0: JS function, 1: function proxy, 2: non-function)
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001534 __ bind(&shift_arguments);
1535 { Label loop;
1536 // Calculate the copy start address (destination). Copy end address is sp.
1537 __ sll(at, a0, kPointerSizeLog2);
1538 __ addu(a2, sp, at);
1539
1540 __ bind(&loop);
1541 __ lw(at, MemOperand(a2, -kPointerSize));
1542 __ sw(at, MemOperand(a2));
1543 __ Subu(a2, a2, Operand(kPointerSize));
1544 __ Branch(&loop, ne, a2, Operand(sp));
1545 // Adjust the actual number of arguments and remove the top element
1546 // (which is a copy of the last argument).
1547 __ Subu(a0, a0, Operand(1));
1548 __ Pop();
1549 }
1550
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001551 // 5a. Call non-function via tail call to CALL_NON_FUNCTION builtin,
1552 // or a function proxy via CALL_FUNCTION_PROXY.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001553 // a0: actual number of arguments
1554 // a1: function
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001555 // t0: call type (0: JS function, 1: function proxy, 2: non-function)
1556 { Label function, non_proxy;
1557 __ Branch(&function, eq, t0, Operand(zero_reg));
1558 // Expected number of arguments is 0 for CALL_NON_FUNCTION.
1559 __ mov(a2, zero_reg);
danno@chromium.org40cb8782011-05-25 07:58:50 +00001560 __ SetCallKind(t1, CALL_AS_METHOD);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001561 __ Branch(&non_proxy, ne, t0, Operand(1));
1562
1563 __ push(a1); // Re-add proxy object as additional argument.
1564 __ Addu(a0, a0, Operand(1));
1565 __ GetBuiltinEntry(a3, Builtins::CALL_FUNCTION_PROXY);
1566 __ Jump(masm->isolate()->builtins()->ArgumentsAdaptorTrampoline(),
1567 RelocInfo::CODE_TARGET);
1568
1569 __ bind(&non_proxy);
1570 __ GetBuiltinEntry(a3, Builtins::CALL_NON_FUNCTION);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001571 __ Jump(masm->isolate()->builtins()->ArgumentsAdaptorTrampoline(),
1572 RelocInfo::CODE_TARGET);
1573 __ bind(&function);
1574 }
1575
1576 // 5b. Get the code to call from the function and check that the number of
1577 // expected arguments matches what we're providing. If so, jump
1578 // (tail-call) to the code in register edx without checking arguments.
1579 // a0: actual number of arguments
1580 // a1: function
1581 __ lw(a3, FieldMemOperand(a1, JSFunction::kSharedFunctionInfoOffset));
1582 __ lw(a2,
1583 FieldMemOperand(a3, SharedFunctionInfo::kFormalParameterCountOffset));
1584 __ sra(a2, a2, kSmiTagSize);
1585 __ lw(a3, FieldMemOperand(a1, JSFunction::kCodeEntryOffset));
danno@chromium.org40cb8782011-05-25 07:58:50 +00001586 __ SetCallKind(t1, CALL_AS_METHOD);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001587 // Check formal and actual parameter counts.
1588 __ Jump(masm->isolate()->builtins()->ArgumentsAdaptorTrampoline(),
1589 RelocInfo::CODE_TARGET, ne, a2, Operand(a0));
1590
1591 ParameterCount expected(0);
erik.corry@gmail.comd6076d92011-06-06 09:39:18 +00001592 __ InvokeCode(a3, expected, expected, JUMP_FUNCTION,
1593 NullCallWrapper(), CALL_AS_METHOD);
ager@chromium.org5c838252010-02-19 08:53:10 +00001594}
1595
1596
1597void Builtins::Generate_FunctionApply(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001598 const int kIndexOffset = -5 * kPointerSize;
1599 const int kLimitOffset = -4 * kPointerSize;
1600 const int kArgsOffset = 2 * kPointerSize;
1601 const int kRecvOffset = 3 * kPointerSize;
1602 const int kFunctionOffset = 4 * kPointerSize;
1603
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001604 {
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +00001605 FrameScope frame_scope(masm, StackFrame::INTERNAL);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001606 __ lw(a0, MemOperand(fp, kFunctionOffset)); // Get the function.
1607 __ push(a0);
1608 __ lw(a0, MemOperand(fp, kArgsOffset)); // Get the args array.
1609 __ push(a0);
1610 // Returns (in v0) number of arguments to copy to stack as Smi.
1611 __ InvokeBuiltin(Builtins::APPLY_PREPARE, CALL_FUNCTION);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001612
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001613 // Check the stack for overflow. We are not trying to catch
1614 // interruptions (e.g. debug break and preemption) here, so the "real stack
1615 // limit" is checked.
1616 Label okay;
1617 __ LoadRoot(a2, Heap::kRealStackLimitRootIndex);
1618 // Make a2 the space we have left. The stack might already be overflowed
1619 // here which will cause a2 to become negative.
1620 __ subu(a2, sp, a2);
1621 // Check if the arguments will overflow the stack.
1622 __ sll(t3, v0, kPointerSizeLog2 - kSmiTagSize);
1623 __ Branch(&okay, gt, a2, Operand(t3)); // Signed comparison.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001624
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001625 // Out of stack space.
1626 __ lw(a1, MemOperand(fp, kFunctionOffset));
1627 __ push(a1);
1628 __ push(v0);
1629 __ InvokeBuiltin(Builtins::APPLY_OVERFLOW, CALL_FUNCTION);
1630 // End of stack check.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001631
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001632 // Push current limit and index.
1633 __ bind(&okay);
1634 __ push(v0); // Limit.
1635 __ mov(a1, zero_reg); // Initial index.
1636 __ push(a1);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001637
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001638 // Get the receiver.
1639 __ lw(a0, MemOperand(fp, kRecvOffset));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001640
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001641 // Check that the function is a JS function (otherwise it must be a proxy).
1642 Label push_receiver;
1643 __ lw(a1, MemOperand(fp, kFunctionOffset));
1644 __ GetObjectType(a1, a2, a2);
1645 __ Branch(&push_receiver, ne, a2, Operand(JS_FUNCTION_TYPE));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001646
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001647 // Change context eagerly to get the right global object if necessary.
1648 __ lw(cp, FieldMemOperand(a1, JSFunction::kContextOffset));
1649 // Load the shared function info while the function is still in a1.
1650 __ lw(a2, FieldMemOperand(a1, JSFunction::kSharedFunctionInfoOffset));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001651
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001652 // Compute the receiver.
1653 // Do not transform the receiver for strict mode functions.
1654 Label call_to_object, use_global_receiver;
1655 __ lw(a2, FieldMemOperand(a2, SharedFunctionInfo::kCompilerHintsOffset));
1656 __ And(t3, a2, Operand(1 << (SharedFunctionInfo::kStrictModeFunction +
1657 kSmiTagSize)));
1658 __ Branch(&push_receiver, ne, t3, Operand(zero_reg));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001659
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001660 // Do not transform the receiver for native (Compilerhints already in a2).
1661 __ And(t3, a2, Operand(1 << (SharedFunctionInfo::kNative + kSmiTagSize)));
1662 __ Branch(&push_receiver, ne, t3, Operand(zero_reg));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001663
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001664 // Compute the receiver in non-strict mode.
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +00001665 __ JumpIfSmi(a0, &call_to_object);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001666 __ LoadRoot(a1, Heap::kNullValueRootIndex);
1667 __ Branch(&use_global_receiver, eq, a0, Operand(a1));
1668 __ LoadRoot(a2, Heap::kUndefinedValueRootIndex);
1669 __ Branch(&use_global_receiver, eq, a0, Operand(a2));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001670
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001671 // Check if the receiver is already a JavaScript object.
1672 // a0: receiver
1673 STATIC_ASSERT(LAST_SPEC_OBJECT_TYPE == LAST_TYPE);
1674 __ GetObjectType(a0, a1, a1);
1675 __ Branch(&push_receiver, ge, a1, Operand(FIRST_SPEC_OBJECT_TYPE));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001676
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001677 // Convert the receiver to a regular object.
1678 // a0: receiver
1679 __ bind(&call_to_object);
1680 __ push(a0);
1681 __ InvokeBuiltin(Builtins::TO_OBJECT, CALL_FUNCTION);
1682 __ mov(a0, v0); // Put object in a0 to match other paths to push_receiver.
1683 __ Branch(&push_receiver);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001684
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001685 // Use the current global receiver object as the receiver.
1686 __ bind(&use_global_receiver);
1687 const int kGlobalOffset =
yangguo@chromium.org46839fb2012-08-28 09:06:19 +00001688 Context::kHeaderSize + Context::GLOBAL_OBJECT_INDEX * kPointerSize;
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001689 __ lw(a0, FieldMemOperand(cp, kGlobalOffset));
yangguo@chromium.org46839fb2012-08-28 09:06:19 +00001690 __ lw(a0, FieldMemOperand(a0, GlobalObject::kNativeContextOffset));
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001691 __ lw(a0, FieldMemOperand(a0, kGlobalOffset));
1692 __ lw(a0, FieldMemOperand(a0, GlobalObject::kGlobalReceiverOffset));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001693
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001694 // Push the receiver.
1695 // a0: receiver
1696 __ bind(&push_receiver);
1697 __ push(a0);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001698
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001699 // Copy all arguments from the array to the stack.
1700 Label entry, loop;
1701 __ lw(a0, MemOperand(fp, kIndexOffset));
1702 __ Branch(&entry);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001703
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001704 // Load the current argument from the arguments array and push it to the
1705 // stack.
1706 // a0: current argument index
1707 __ bind(&loop);
1708 __ lw(a1, MemOperand(fp, kArgsOffset));
1709 __ push(a1);
1710 __ push(a0);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001711
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001712 // Call the runtime to access the property in the arguments array.
1713 __ CallRuntime(Runtime::kGetProperty, 2);
1714 __ push(v0);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001715
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001716 // Use inline caching to access the arguments.
1717 __ lw(a0, MemOperand(fp, kIndexOffset));
1718 __ Addu(a0, a0, Operand(1 << kSmiTagSize));
1719 __ sw(a0, MemOperand(fp, kIndexOffset));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001720
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001721 // Test if the copy loop has finished copying all the elements from the
1722 // arguments object.
1723 __ bind(&entry);
1724 __ lw(a1, MemOperand(fp, kLimitOffset));
1725 __ Branch(&loop, ne, a0, Operand(a1));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001726
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001727 // Invoke the function.
1728 Label call_proxy;
1729 ParameterCount actual(a0);
1730 __ sra(a0, a0, kSmiTagSize);
1731 __ lw(a1, MemOperand(fp, kFunctionOffset));
1732 __ GetObjectType(a1, a2, a2);
1733 __ Branch(&call_proxy, ne, a2, Operand(JS_FUNCTION_TYPE));
1734
1735 __ InvokeFunction(a1, actual, CALL_FUNCTION,
1736 NullCallWrapper(), CALL_AS_METHOD);
1737
jkummerow@chromium.orgc3b37122011-11-07 10:14:12 +00001738 frame_scope.GenerateLeaveFrame();
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001739 __ Ret(USE_DELAY_SLOT);
1740 __ Addu(sp, sp, Operand(3 * kPointerSize)); // In delay slot.
1741
1742 // Invoke the function proxy.
1743 __ bind(&call_proxy);
1744 __ push(a1); // Add function proxy as last argument.
1745 __ Addu(a0, a0, Operand(1));
jkummerow@chromium.org59297c72013-01-09 16:32:23 +00001746 __ li(a2, Operand(0, RelocInfo::NONE32));
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001747 __ SetCallKind(t1, CALL_AS_METHOD);
1748 __ GetBuiltinEntry(a3, Builtins::CALL_FUNCTION_PROXY);
1749 __ Call(masm->isolate()->builtins()->ArgumentsAdaptorTrampoline(),
1750 RelocInfo::CODE_TARGET);
erik.corry@gmail.comc3b670f2011-10-05 21:44:48 +00001751 // Tear down the internal frame and remove function, receiver and args.
1752 }
1753
1754 __ Ret(USE_DELAY_SLOT);
1755 __ Addu(sp, sp, Operand(3 * kPointerSize)); // In delay slot.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001756}
1757
1758
1759static void EnterArgumentsAdaptorFrame(MacroAssembler* masm) {
1760 __ sll(a0, a0, kSmiTagSize);
1761 __ li(t0, Operand(Smi::FromInt(StackFrame::ARGUMENTS_ADAPTOR)));
1762 __ MultiPush(a0.bit() | a1.bit() | t0.bit() | fp.bit() | ra.bit());
1763 __ Addu(fp, sp, Operand(3 * kPointerSize));
1764}
1765
1766
1767static void LeaveArgumentsAdaptorFrame(MacroAssembler* masm) {
1768 // ----------- S t a t e -------------
1769 // -- v0 : result being passed through
1770 // -----------------------------------
1771 // Get the number of arguments passed (as a smi), tear down the frame and
1772 // then tear down the parameters.
1773 __ lw(a1, MemOperand(fp, -3 * kPointerSize));
1774 __ mov(sp, fp);
1775 __ MultiPop(fp.bit() | ra.bit());
1776 __ sll(t0, a1, kPointerSizeLog2 - kSmiTagSize);
1777 __ Addu(sp, sp, t0);
1778 // Adjust for the receiver.
1779 __ Addu(sp, sp, Operand(kPointerSize));
ager@chromium.org5c838252010-02-19 08:53:10 +00001780}
1781
1782
1783void Builtins::Generate_ArgumentsAdaptorTrampoline(MacroAssembler* masm) {
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001784 // State setup as expected by MacroAssembler::InvokePrologue.
1785 // ----------- S t a t e -------------
1786 // -- a0: actual arguments count
1787 // -- a1: function (passed through to callee)
1788 // -- a2: expected arguments count
1789 // -- a3: callee code entry
danno@chromium.org40cb8782011-05-25 07:58:50 +00001790 // -- t1: call kind information
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001791 // -----------------------------------
1792
1793 Label invoke, dont_adapt_arguments;
1794
1795 Label enough, too_few;
1796 __ Branch(&dont_adapt_arguments, eq,
1797 a2, Operand(SharedFunctionInfo::kDontAdaptArgumentsSentinel));
1798 // We use Uless as the number of argument should always be greater than 0.
1799 __ Branch(&too_few, Uless, a0, Operand(a2));
1800
1801 { // Enough parameters: actual >= expected.
1802 // a0: actual number of arguments as a smi
1803 // a1: function
1804 // a2: expected number of arguments
1805 // a3: code entry to call
1806 __ bind(&enough);
1807 EnterArgumentsAdaptorFrame(masm);
1808
1809 // Calculate copy start address into a0 and copy end address into a2.
1810 __ sll(a0, a0, kPointerSizeLog2 - kSmiTagSize);
1811 __ Addu(a0, fp, a0);
1812 // Adjust for return address and receiver.
1813 __ Addu(a0, a0, Operand(2 * kPointerSize));
1814 // Compute copy end address.
1815 __ sll(a2, a2, kPointerSizeLog2);
1816 __ subu(a2, a0, a2);
1817
1818 // Copy the arguments (including the receiver) to the new stack frame.
1819 // a0: copy start address
1820 // a1: function
1821 // a2: copy end address
1822 // a3: code entry to call
1823
1824 Label copy;
1825 __ bind(&copy);
1826 __ lw(t0, MemOperand(a0));
1827 __ push(t0);
1828 __ Branch(USE_DELAY_SLOT, &copy, ne, a0, Operand(a2));
1829 __ addiu(a0, a0, -kPointerSize); // In delay slot.
1830
1831 __ jmp(&invoke);
1832 }
1833
1834 { // Too few parameters: Actual < expected.
1835 __ bind(&too_few);
1836 EnterArgumentsAdaptorFrame(masm);
1837
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001838 // Calculate copy start address into a0 and copy end address is fp.
1839 // a0: actual number of arguments as a smi
1840 // a1: function
1841 // a2: expected number of arguments
1842 // a3: code entry to call
1843 __ sll(a0, a0, kPointerSizeLog2 - kSmiTagSize);
1844 __ Addu(a0, fp, a0);
1845 // Adjust for return address and receiver.
1846 __ Addu(a0, a0, Operand(2 * kPointerSize));
1847 // Compute copy end address. Also adjust for return address.
erik.corry@gmail.comd6076d92011-06-06 09:39:18 +00001848 __ Addu(t3, fp, kPointerSize);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001849
1850 // Copy the arguments (including the receiver) to the new stack frame.
1851 // a0: copy start address
1852 // a1: function
1853 // a2: expected number of arguments
1854 // a3: code entry to call
erik.corry@gmail.comd6076d92011-06-06 09:39:18 +00001855 // t3: copy end address
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001856 Label copy;
1857 __ bind(&copy);
1858 __ lw(t0, MemOperand(a0)); // Adjusted above for return addr and receiver.
erik.corry@gmail.combbceb572012-03-09 10:52:05 +00001859 __ Subu(sp, sp, kPointerSize);
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001860 __ Subu(a0, a0, kPointerSize);
erik.corry@gmail.combbceb572012-03-09 10:52:05 +00001861 __ Branch(USE_DELAY_SLOT, &copy, ne, a0, Operand(t3));
1862 __ sw(t0, MemOperand(sp)); // In the delay slot.
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001863
1864 // Fill the remaining expected arguments with undefined.
1865 // a1: function
1866 // a2: expected number of arguments
1867 // a3: code entry to call
1868 __ LoadRoot(t0, Heap::kUndefinedValueRootIndex);
1869 __ sll(t2, a2, kPointerSizeLog2);
1870 __ Subu(a2, fp, Operand(t2));
1871 __ Addu(a2, a2, Operand(-4 * kPointerSize)); // Adjust for frame.
1872
1873 Label fill;
1874 __ bind(&fill);
erik.corry@gmail.combbceb572012-03-09 10:52:05 +00001875 __ Subu(sp, sp, kPointerSize);
1876 __ Branch(USE_DELAY_SLOT, &fill, ne, sp, Operand(a2));
1877 __ sw(t0, MemOperand(sp));
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001878 }
1879
1880 // Call the entry point.
1881 __ bind(&invoke);
1882
1883 __ Call(a3);
1884
ulan@chromium.org812308e2012-02-29 15:58:45 +00001885 // Store offset of return address for deoptimizer.
danno@chromium.orgfa458e42012-02-01 10:48:36 +00001886 masm->isolate()->heap()->SetArgumentsAdaptorDeoptPCOffset(masm->pc_offset());
ulan@chromium.org812308e2012-02-29 15:58:45 +00001887
vegorov@chromium.org7304bca2011-05-16 12:14:13 +00001888 // Exit frame and return.
1889 LeaveArgumentsAdaptorFrame(masm);
1890 __ Ret();
1891
1892
1893 // -------------------------------------------
1894 // Don't adapt arguments.
1895 // -------------------------------------------
1896 __ bind(&dont_adapt_arguments);
1897 __ Jump(a3);
ager@chromium.org5c838252010-02-19 08:53:10 +00001898}
1899
1900
1901#undef __
1902
1903} } // namespace v8::internal
1904
erik.corry@gmail.com9dfbea42010-05-21 12:58:28 +00001905#endif // V8_TARGET_ARCH_MIPS