Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 8ae122a8481bde0fe19e7c9fdd50d86587685af1
      
https://github.com/WebKit/WebKit/commit/8ae122a8481bde0fe19e7c9fdd50d86587685af1
  Author: Sosuke Suzuki <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    A JSTests/stress/reflect-construct-array-literal-argument-counts.js
    A JSTests/stress/reflect-construct-array-literal-element-expressions.js
    A JSTests/stress/reflect-construct-array-literal-indexed-accessors.js
    A JSTests/stress/reflect-construct-array-literal-invalid-targets.js
    A JSTests/stress/reflect-construct-array-literal-replaced-callee.js
    A JSTests/stress/reflect-construct-array-literal-shapes.js
    M Source/JavaScriptCore/bytecompiler/BytecodeGenerator.cpp
    M Source/JavaScriptCore/bytecompiler/BytecodeGenerator.h
    M Source/JavaScriptCore/bytecompiler/NodesCodegen.cpp

  Log Message:
  -----------
  [JSC] Emit `op_construct` for `Reflect.construct` call sites with an array 
literal
https://bugs.webkit.org/show_bug.cgi?id=325232

Reviewed by Yusuke Suzuki.

Since 321764@main, a `Reflect.construct(...)` call site emits
op_construct_varargs. When the arguments list is an array literal, as in
`Reflect.construct(F, [a, b])`, the call site still allocates the array
only for op_construct_varargs to copy its elements into the callee frame.

This patch evaluates the elements of such an array literal into the
argument registers of an op_construct, as `f.apply(thisArg, [a, b])`
already does for op_call. The array is created only when the checks of
the call site fail and the ordinary call is made. An array literal with
holes or spread elements keeps using op_construct_varargs.

                                                 Baseline                  
Patched

reflect-construct-array-literal              40.5969+-0.1958     ^     
16.4136+-0.0946        ^ definitely 2.4734x faster

Tests: JSTests/stress/reflect-construct-array-literal-argument-counts.js
       JSTests/stress/reflect-construct-array-literal-element-expressions.js
       JSTests/stress/reflect-construct-array-literal-indexed-accessors.js
       JSTests/stress/reflect-construct-array-literal-invalid-targets.js
       JSTests/stress/reflect-construct-array-literal-replaced-callee.js
       JSTests/stress/reflect-construct-array-literal-shapes.js

* JSTests/stress/reflect-construct-array-literal-argument-counts.js: Added.
(shouldBe):
(Other):
(none):
(one):
(two):
(many):
(mixedTypes):
(fewerThanParameters):
* JSTests/stress/reflect-construct-array-literal-element-expressions.js: Added.
(shouldBe):
(callsInElements):
(conditionalElements):
(tryInElements):
(closesOverElements):
(async awaitsInElements):
(i.awaitsInElements.i.then):
* JSTests/stress/reflect-construct-array-literal-indexed-accessors.js: Added.
(shouldBe):
(let.fake.construct):
(test):
* JSTests/stress/reflect-construct-array-literal-invalid-targets.js: Added.
(shouldBe):
(Collect):
(Other):
(test):
(withoutNewTarget):
(throwingElement):
(async method):
* JSTests/stress/reflect-construct-array-literal-replaced-callee.js: Added.
(shouldBe):
(Other):
(let.fake.construct):
(none):
(three):
(withNewTarget):
(many):
(checkList):
* JSTests/stress/reflect-construct-array-literal-shapes.js: Added.
(shouldBe):
(hole):
(trailingHole):
(spread):
(parenthesized):
(commaExpression):
* Source/JavaScriptCore/bytecompiler/BytecodeGenerator.cpp:
(JSC::BytecodeGenerator::emitNewArrayByReversingArguments):
* Source/JavaScriptCore/bytecompiler/BytecodeGenerator.h:
* Source/JavaScriptCore/bytecompiler/NodesCodegen.cpp:
(JSC::ReflectConstructFunctionCallDotNode::emitBytecode):

Canonical link: https://commits.webkit.org/322378@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to