Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: d29218b6deb2d15b064dd44d647bea4415cf2370
      
https://github.com/WebKit/WebKit/commit/d29218b6deb2d15b064dd44d647bea4415cf2370
  Author: Yusuke Suzuki <[email protected]>
  Date:   2026-09-30 (Wed, 30 Sep 2026)

  Changed paths:
    A JSTests/stress/array-splice-fast-path-dfg.js
    A JSTests/stress/array-splice-shift-hole-forwarding-to-prototype.js
    M Source/JavaScriptCore/dfg/DFGOperations.cpp
    M Source/JavaScriptCore/runtime/ArrayPrototype.cpp
    M Source/JavaScriptCore/runtime/ArrayPrototypeInlines.h
    M Source/JavaScriptCore/runtime/JSArray.cpp
    M Source/JavaScriptCore/runtime/JSArray.h

  Log Message:
  -----------
  [JSC] Add JSArray::fastSplice
rdar://188758890

Reviewed by Sosuke Suzuki.

This patch implements JSArray::fastSplice, this is extremely fast path
for splice operation.

1. Array is Int32, Contiguous, Double.
2. holesMustForwardToPrototype is false.

We will attempt to take a fast path without copying scratch buffer's
values as they can run splice without user-observable behavior (function
calls etc.), so nested JS call does not happen. To make implementation
better, we tweak shiftCountWithAnyIndexingType /
unshiftCountWithAnyIndexingType not to change the Array when it fails
due to array holes.

Tests: JSTests/stress/array-splice-fast-path-dfg.js
       JSTests/stress/array-splice-shift-hole-forwarding-to-prototype.js

* JSTests/stress/array-splice-fast-path-dfg.js: Added.
(shouldBe):
(shouldBeArray):
(makeArray):
(referenceSplice):
(splice0):
(splice1):
(splice2):
(splice3):
(splice0Result):
(splice2Result):
(runCase):
* JSTests/stress/array-splice-shift-hole-forwarding-to-prototype.js: Added.
(shouldBe):
(shouldBeArray):
(splice0):
(splice1):
(splice2):
* Source/JavaScriptCore/dfg/DFGOperations.cpp:
(JSC::DFG::arraySpliceImpl):
* Source/JavaScriptCore/runtime/ArrayPrototype.cpp:
(JSC::JSC_DEFINE_HOST_FUNCTION):
* Source/JavaScriptCore/runtime/ArrayPrototypeInlines.h:
(JSC::setLength):
(JSC::shift):
(JSC::unshift):
* Source/JavaScriptCore/runtime/JSArray.cpp:
(JSC::JSArray::fastSplice):
(JSC::JSArray::shiftCountWithAnyIndexingType):
(JSC::JSArray::unshiftCountWithAnyIndexingType):
* Source/JavaScriptCore/runtime/JSArray.h:
(JSC::JSArray::shiftCount):

Canonical link: https://commits.webkit.org/322256@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to