From bde1a82edd512a4e8a03a9948409f3260555b4ac Mon Sep 17 00:00:00 2001 From: Joyee Cheung Date: Wed, 7 Oct 2026 18:00:42 +0200 Subject: [PATCH 01/12] deps: update V8 to 15.6.75.8 Signed-off-by: Joyee Cheung --- deps/v8/AUTHORS | 5 + deps/v8/BUILD.bazel | 7 +- deps/v8/BUILD.gn | 185 ++- deps/v8/DEPS | 306 ++-- deps/v8/PRESUBMIT.py | 65 +- deps/v8/agents/.vpython3 | 137 -- deps/v8/agents/README.md | 15 +- deps/v8/agents/agents/builder/agent.json | 5 - deps/v8/agents/agents/builder/config.yaml | 11 - deps/v8/agents/agents/debugger/agent.json | 5 - deps/v8/agents/agents/debugger/config.yaml | 12 - deps/v8/agents/agents/researcher/agent.json | 5 - deps/v8/agents/agents/researcher/config.yaml | 11 - deps/v8/agents/agents/tester/agent.json | 5 - deps/v8/agents/agents/tester/config.yaml | 11 - deps/v8/agents/plugins/install.py | 49 +- deps/v8/agents/prompts/README.md | 27 +- deps/v8/agents/prompts/common.md | 268 ---- deps/v8/agents/prompts/templates/README.md | 17 - deps/v8/agents/prompts/templates/modular.md | 49 +- deps/v8/agents/rules/debugging.md | 100 +- deps/v8/agents/rules/execution-constraints.md | 23 +- deps/v8/agents/rules/framework.md | 27 - deps/v8/agents/rules/v8-best-practices.md | 28 +- .../agents/scripts/install_for_copilot_cli.py | 9 - .../agents/scripts/install_for_gemini_cli.py | 91 -- deps/v8/agents/scripts/install_for_jetski.py | 38 +- deps/v8/agents/skills/README.md | 20 +- .../v8/agents/skills/env-abstraction/SKILL.md | 57 - deps/v8/agents/skills/orchestrator/SKILL.md | 189 --- .../skills/subagent-env-passing/SKILL.md | 33 - .../skills/v8-regression-testing/SKILL.md | 16 +- .../skills/v8-security-triaging/SKILL.md | 14 +- deps/v8/agents/skills/v8-structure/SKILL.md | 19 +- deps/v8/agents/vpython.toml | 40 + deps/v8/agents/vpython.toml.uv.lock | 270 ++++ deps/v8/experimental/OWNERS | 1 + deps/v8/experimental/README.md | 7 + deps/v8/include/js_protocol.pdl | 2 +- deps/v8/include/v8-array-buffer.h | 5 + deps/v8/include/v8-callbacks.h | 8 + deps/v8/include/v8-context.h | 24 +- deps/v8/include/v8-debug.h | 6 + deps/v8/include/v8-fast-api-calls.h | 8 + deps/v8/include/v8-function-callback.h | 25 + deps/v8/include/v8-inspector.h | 2 + deps/v8/include/v8-internal.h | 47 +- deps/v8/include/v8-isolate.h | 12 +- deps/v8/include/v8-microtask-queue.h | 12 + deps/v8/include/v8-object.h | 12 +- deps/v8/include/v8-profiler.h | 21 + deps/v8/include/v8-sandbox.h | 64 +- deps/v8/include/v8-script.h | 11 +- deps/v8/include/v8-traced-handle.h | 47 +- deps/v8/include/v8-version.h | 6 +- deps/v8/include/v8-wasm.h | 2 +- deps/v8/include/v8config.h | 4 - deps/v8/infra/mb/mb_config.pyl | 12 +- deps/v8/infra/testing/builders.pyl | 23 +- deps/v8/src/api/api.cc | 72 +- deps/v8/src/ast/ast-value-factory.cc | 19 +- deps/v8/src/ast/ast-value-factory.h | 6 +- deps/v8/src/ast/ast.h | 11 +- deps/v8/src/ast/scopes.cc | 194 +-- deps/v8/src/ast/scopes.h | 18 +- deps/v8/src/ast/variables.h | 9 +- deps/v8/src/base/cpu/cpu-x86.cc | 2 +- deps/v8/src/base/platform/platform-posix.cc | 14 +- deps/v8/src/base/region-allocator.cc | 4 +- deps/v8/src/base/region-allocator.h | 11 +- deps/v8/src/baseline/baseline-compiler.cc | 16 +- deps/v8/src/builtins/arm/builtins-arm.cc | 12 +- deps/v8/src/builtins/arm64/builtins-arm64.cc | 24 +- deps/v8/src/builtins/array-join.tq | 37 +- deps/v8/src/builtins/base.tq | 2 + deps/v8/src/builtins/builtins-api.cc | 2 +- deps/v8/src/builtins/builtins-arraybuffer.cc | 22 +- deps/v8/src/builtins/builtins-date-gen.cc | 15 + deps/v8/src/builtins/builtins-function.cc | 92 +- deps/v8/src/builtins/builtins-internal-gen.cc | 6 +- deps/v8/src/builtins/builtins-intl-gen.cc | 4 + deps/v8/src/builtins/builtins-intl.cc | 3 +- .../builtins/builtins-microtask-queue-gen.cc | 5 +- deps/v8/src/builtins/builtins-regexp-gen.cc | 15 +- deps/v8/src/builtins/builtins-string-gen.cc | 12 + .../src/builtins/builtins-typed-array-gen.cc | 2 +- deps/v8/src/builtins/cast.tq | 10 + deps/v8/src/builtins/ia32/builtins-ia32.cc | 14 +- deps/v8/src/builtins/js-to-wasm.tq | 11 +- .../src/builtins/js-trampoline-assembler.cc | 27 +- .../v8/src/builtins/js-trampoline-assembler.h | 3 +- .../src/builtins/loong64/builtins-loong64.cc | 21 +- .../v8/src/builtins/mips64/builtins-mips64.cc | 12 +- deps/v8/src/builtins/ppc/builtins-ppc.cc | 12 +- deps/v8/src/builtins/riscv/builtins-riscv.cc | 25 +- deps/v8/src/builtins/s390/builtins-s390.cc | 12 +- deps/v8/src/builtins/wasm.tq | 50 +- deps/v8/src/builtins/x64/builtins-x64.cc | 21 +- deps/v8/src/codegen/arm/macro-assembler-arm.h | 6 + .../codegen/arm64/macro-assembler-arm64.cc | 61 +- .../src/codegen/arm64/macro-assembler-arm64.h | 5 + deps/v8/src/codegen/code-stub-assembler.cc | 95 +- deps/v8/src/codegen/code-stub-assembler.h | 29 +- deps/v8/src/codegen/compiler.cc | 11 +- deps/v8/src/codegen/heap-object-list.h | 1 + .../loong64/macro-assembler-loong64.cc | 86 +- .../codegen/loong64/macro-assembler-loong64.h | 5 + .../v8/src/codegen/ppc/macro-assembler-ppc.cc | 58 +- deps/v8/src/codegen/ppc/macro-assembler-ppc.h | 1 + .../codegen/riscv/macro-assembler-riscv.cc | 86 +- .../src/codegen/riscv/macro-assembler-riscv.h | 5 + .../src/codegen/s390/macro-assembler-s390.cc | 9 + .../src/codegen/s390/macro-assembler-s390.h | 1 + deps/v8/src/codegen/x64/assembler-x64.h | 158 +++ .../v8/src/codegen/x64/macro-assembler-x64.cc | 66 +- deps/v8/src/codegen/x64/macro-assembler-x64.h | 10 + deps/v8/src/compiler/access-builder.cc | 8 +- deps/v8/src/compiler/access-info.cc | 2 +- .../backend/arm/code-generator-arm.cc | 16 +- .../backend/arm/instruction-selector-arm.cc | 5 +- .../backend/arm64/code-generator-arm64.cc | 214 +-- .../backend/arm64/instruction-codes-arm64.h | 11 +- .../arm64/instruction-scheduler-arm64.cc | 32 +- .../arm64/instruction-selector-arm64.cc | 357 +++-- .../v8/src/compiler/backend/code-generator.cc | 4 + deps/v8/src/compiler/backend/code-generator.h | 4 + .../backend/ia32/code-generator-ia32.cc | 14 +- .../backend/ia32/instruction-selector-ia32.cc | 9 +- .../src/compiler/backend/instruction-codes.h | 56 +- .../compiler/backend/instruction-selector.cc | 6 +- .../compiler/backend/instruction-selector.h | 28 +- .../backend/loong64/code-generator-loong64.cc | 47 +- .../loong64/instruction-codes-loong64.h | 3 +- .../loong64/instruction-selector-loong64.cc | 126 +- .../backend/mips64/code-generator-mips64.cc | 27 +- .../backend/mips64/instruction-codes-mips64.h | 1 + .../mips64/instruction-scheduler-mips64.cc | 1 + .../mips64/instruction-selector-mips64.cc | 33 +- .../backend/ppc/code-generator-ppc.cc | 9 +- .../backend/ppc/instruction-selector-ppc.cc | 2 +- .../backend/riscv/code-generator-riscv.cc | 205 ++- .../backend/riscv/instruction-codes-riscv.h | 3 + .../riscv/instruction-scheduler-riscv.cc | 8 + .../riscv/instruction-selector-riscv.h | 26 +- .../riscv/instruction-selector-riscv32.cc | 13 +- .../riscv/instruction-selector-riscv64.cc | 215 ++- .../riscv/register-constraints-riscv.h | 4 +- .../backend/s390/code-generator-s390.cc | 9 +- .../backend/s390/instruction-selector-s390.cc | 2 +- .../backend/x64/code-generator-x64.cc | 61 +- .../backend/x64/instruction-selector-x64.cc | 66 +- .../v8/src/compiler/bytecode-graph-builder.cc | 17 +- deps/v8/src/compiler/common-operator.cc | 4 +- deps/v8/src/compiler/common-operator.h | 9 +- deps/v8/src/compiler/fast-api-calls.cc | 7 +- deps/v8/src/compiler/frame-states.cc | 3 +- deps/v8/src/compiler/frame-states.h | 20 +- deps/v8/src/compiler/heap-refs.cc | 43 +- deps/v8/src/compiler/heap-refs.h | 7 +- deps/v8/src/compiler/js-call-reducer.cc | 6 +- .../src/compiler/js-context-specialization.cc | 10 +- deps/v8/src/compiler/js-graph.cc | 10 + deps/v8/src/compiler/js-graph.h | 1 + deps/v8/src/compiler/js-heap-broker.cc | 7 +- deps/v8/src/compiler/js-heap-broker.h | 18 + deps/v8/src/compiler/js-inlining.cc | 2 +- deps/v8/src/compiler/js-operator.cc | 5 +- deps/v8/src/compiler/js-operator.h | 2 +- deps/v8/src/compiler/pipeline-data-inl.h | 15 +- deps/v8/src/compiler/pipeline.cc | 160 ++- deps/v8/src/compiler/pipeline.h | 22 +- deps/v8/src/compiler/refs-map.cc | 10 +- deps/v8/src/compiler/turboshaft/assembler.h | 12 + .../turboshaft/builtin-call-descriptors.h | 65 +- .../fast-api-call-lowering-reducer.h | 7 +- deps/v8/src/compiler/turboshaft/fast-hash.h | 24 + ...truction-selection-normalization-reducer.h | 42 + .../late-load-elimination-reducer.h | 12 +- .../turboshaft/machine-optimization-reducer.h | 45 +- deps/v8/src/compiler/turboshaft/operations.cc | 6 +- deps/v8/src/compiler/turboshaft/operations.h | 695 +++++++++- .../turboshaft/turbolev-graph-builder.cc | 59 +- deps/v8/src/compiler/turboshaft/typer.h | 6 +- .../wasm-gc-typed-optimization-reducer.cc | 36 +- .../wasm-gc-typed-optimization-reducer.h | 10 + .../wasm-in-js-inlining-reducer-inl.h | 2 + .../wasm-load-elimination-reducer.h | 75 +- .../compiler/turboshaft/wasm-revec-reducer.cc | 4 +- .../compiler/turboshaft/wasm-revec-reducer.h | 4 +- .../turboshaft/wasm-shuffle-reducer.cc | 258 +++- .../turboshaft/wasm-shuffle-reducer.h | 135 +- .../compiler/turboshaft/wasm-wrappers-inl.h | 35 +- .../src/compiler/turboshaft/wasm-wrappers.h | 23 +- .../src/compiler/wasm-compiler-definitions.h | 11 +- deps/v8/src/d8/d8-test.cc | 109 +- deps/v8/src/d8/d8.cc | 194 +-- deps/v8/src/d8/d8.h | 2 +- deps/v8/src/date/date.h | 11 +- deps/v8/src/debug/debug-block-list.cc | 130 ++ deps/v8/src/debug/debug-block-list.h | 40 + deps/v8/src/debug/debug-evaluate.cc | 59 +- deps/v8/src/debug/debug-interface.h | 3 + deps/v8/src/debug/debug-scope-info.cc | 254 +++- deps/v8/src/debug/debug-scope-info.h | 48 +- deps/v8/src/debug/debug-scope-iterator.cc | 11 +- deps/v8/src/debug/debug-scope-iterator.h | 3 +- deps/v8/src/debug/debug-scopes.cc | 756 +++------- deps/v8/src/debug/debug-scopes.h | 66 +- .../src/debug/debug-stack-trace-iterator.cc | 11 +- deps/v8/src/debug/debug-wasm-objects.cc | 2 + deps/v8/src/deoptimizer/deoptimizer.cc | 19 +- deps/v8/src/diagnostics/disassembler.cc | 16 +- deps/v8/src/diagnostics/objects-debug.cc | 49 +- deps/v8/src/diagnostics/objects-printer.cc | 11 +- deps/v8/src/execution/execution.cc | 2 +- deps/v8/src/execution/futex-emulation.cc | 32 +- deps/v8/src/execution/futex-emulation.h | 7 +- deps/v8/src/execution/isolate.cc | 28 +- deps/v8/src/execution/isolate.h | 7 + deps/v8/src/execution/microtask-queue.h | 8 + deps/v8/src/execution/tiering-manager.cc | 84 +- deps/v8/src/flags/feature-flags.h | 23 +- deps/v8/src/flags/flag-definitions.h | 81 +- deps/v8/src/handles/traced-handles-inl.h | 2 +- deps/v8/src/handles/traced-handles.cc | 46 +- deps/v8/src/heap/concurrent-marking.cc | 4 +- deps/v8/src/heap/cppgc-internal/marker.cc | 29 +- deps/v8/src/heap/cppgc-js/cpp-heap.cc | 18 +- deps/v8/src/heap/cppgc-js/cpp-snapshot.cc | 5 +- deps/v8/src/heap/cppgc-js/cpp-snapshot.h | 2 +- deps/v8/src/heap/factory-base-inl.h | 3 + deps/v8/src/heap/factory-base.cc | 4 + deps/v8/src/heap/factory-base.h | 3 + deps/v8/src/heap/factory.cc | 49 +- deps/v8/src/heap/factory.h | 13 +- deps/v8/src/heap/gc-tracer.cc | 129 +- deps/v8/src/heap/heap-write-barrier-inl.h | 47 +- deps/v8/src/heap/heap-write-barrier.cc | 14 +- deps/v8/src/heap/heap-write-barrier.h | 9 +- deps/v8/src/heap/heap.cc | 74 +- deps/v8/src/heap/heap.h | 10 + deps/v8/src/heap/incremental-marking.cc | 65 +- deps/v8/src/heap/mark-compact.cc | 53 +- deps/v8/src/heap/mark-sweep-utilities.cc | 2 - deps/v8/src/heap/marking-visitor-inl.h | 53 +- deps/v8/src/heap/marking-visitor.h | 4 +- deps/v8/src/heap/memory-measurement.cc | 16 +- deps/v8/src/heap/minor-mark-sweep.cc | 38 +- deps/v8/src/heap/setup-heap-internal.cc | 6 + .../young-generation-marking-visitor-inl.h | 4 +- deps/v8/src/ic/accessor-assembler.cc | 4 +- deps/v8/src/ic/ic.cc | 6 +- deps/v8/src/inspector/BUILD.gn | 32 +- deps/v8/src/inspector/DEPS | 1 + deps/v8/src/inspector/custom-preview.cc | 224 ++- deps/v8/src/inspector/injected-script.cc | 4 +- .../v8/src/inspector/v8-console-agent-impl.cc | 7 +- deps/v8/src/inspector/v8-console-message.cc | 22 +- deps/v8/src/inspector/v8-console-message.h | 6 +- deps/v8/src/inspector/v8-console.cc | 13 +- deps/v8/src/inspector/v8-console.h | 11 +- .../src/inspector/v8-debugger-agent-impl.cc | 20 +- .../v8/src/inspector/v8-debugger-agent-impl.h | 3 + deps/v8/src/inspector/v8-debugger.cc | 22 +- deps/v8/src/inspector/v8-inspector-impl.cc | 14 +- deps/v8/src/inspector/v8-inspector-impl.h | 4 + .../inspector/v8-inspector-session-impl.cc | 4 + .../src/inspector/v8-inspector-session-impl.h | 1 + .../v8/src/inspector/v8-runtime-agent-impl.cc | 25 +- deps/v8/src/inspector/value-mirror.cc | 4 +- .../src/interpreter/bytecode-array-builder.cc | 23 +- .../src/interpreter/bytecode-array-builder.h | 7 +- deps/v8/src/interpreter/bytecode-generator.cc | 87 +- deps/v8/src/interpreter/bytecode-generator.h | 2 +- deps/v8/src/interpreter/bytecodes.cc | 3 +- deps/v8/src/interpreter/bytecodes.h | 8 +- .../src/interpreter/interpreter-generator.cc | 41 +- deps/v8/src/json/json-parser.h | 6 + deps/v8/src/logging/code-events.h | 14 +- deps/v8/src/logging/counters-definitions.h | 2 + deps/v8/src/logging/log.cc | 31 +- deps/v8/src/logging/log.h | 14 +- .../maglev/arm64/maglev-assembler-arm64-inl.h | 22 + deps/v8/src/maglev/hamt.h | 72 +- deps/v8/src/maglev/maglev-assembler-inl.h | 86 +- deps/v8/src/maglev/maglev-assembler.cc | 8 +- deps/v8/src/maglev/maglev-assembler.h | 24 + deps/v8/src/maglev/maglev-code-gen-state.h | 13 + deps/v8/src/maglev/maglev-code-generator.cc | 34 +- deps/v8/src/maglev/maglev-code-generator.h | 1 + deps/v8/src/maglev/maglev-compilation-info.cc | 37 + deps/v8/src/maglev/maglev-compilation-info.h | 18 + deps/v8/src/maglev/maglev-graph-builder.cc | 344 +++-- deps/v8/src/maglev/maglev-graph-builder.h | 28 +- deps/v8/src/maglev/maglev-graph-optimizer.cc | 59 +- deps/v8/src/maglev/maglev-graph-optimizer.h | 5 + .../maglev/maglev-interpreter-frame-state.cc | 14 +- .../maglev/maglev-interpreter-frame-state.h | 103 +- deps/v8/src/maglev/maglev-ir.cc | 241 +++- deps/v8/src/maglev/maglev-ir.h | 66 +- deps/v8/src/maglev/maglev-kna-processor.h | 32 +- .../src/maglev/maglev-known-node-aspects.cc | 11 + .../maglev-phi-representation-selector.h | 4 +- deps/v8/src/maglev/maglev-range.h | 7 + deps/v8/src/maglev/maglev-reducer-inl.h | 41 +- deps/v8/src/maglev/maglev-reducer.h | 30 +- .../src/maglev/maglev-register-frame-array.h | 7 +- deps/v8/src/maglev/maglev-truncation.h | 7 +- .../src/maglev/ppc/maglev-assembler-ppc-inl.h | 10 +- .../maglev/riscv/maglev-assembler-riscv.cc | 21 +- deps/v8/src/maglev/riscv/maglev-ir-riscv.cc | 4 +- .../src/maglev/x64/maglev-assembler-x64-inl.h | 48 + deps/v8/src/numbers/conversions.cc | 5 +- deps/v8/src/objects/all-objects.h | 22 +- deps/v8/src/objects/backing-store.cc | 2 +- .../src/objects/compilation-cache-table-inl.h | 1 + deps/v8/src/objects/contexts-inl.h | 79 +- deps/v8/src/objects/contexts.cc | 67 +- deps/v8/src/objects/contexts.h | 11 +- deps/v8/src/objects/contexts.tq | 8 +- deps/v8/src/objects/embedder-data-slot-inl.h | 9 +- deps/v8/src/objects/feedback-vector-inl.h | 25 + deps/v8/src/objects/feedback-vector.cc | 46 +- deps/v8/src/objects/feedback-vector.h | 15 + deps/v8/src/objects/heap-object-field-inl.h | 16 +- deps/v8/src/objects/heap-object.h | 3 + deps/v8/src/objects/hole.h | 3 + deps/v8/src/objects/hole.tq | 2 + deps/v8/src/objects/intl-objects.cc | 5 +- deps/v8/src/objects/intl-objects.h | 26 +- deps/v8/src/objects/js-array-buffer-inl.h | 68 +- deps/v8/src/objects/js-array-buffer.cc | 12 + deps/v8/src/objects/js-array-buffer.h | 29 +- .../objects/js-atomics-synchronization-inl.h | 8 +- deps/v8/src/objects/js-collator-inl.h | 6 +- deps/v8/src/objects/js-collator.cc | 7 +- deps/v8/src/objects/js-collator.h | 6 +- deps/v8/src/objects/js-collator.tq | 2 +- .../src/objects/js-data-object-builder-inl.h | 7 +- deps/v8/src/objects/js-date-time-format-inl.h | 22 +- deps/v8/src/objects/js-date-time-format.cc | 71 +- deps/v8/src/objects/js-date-time-format.h | 21 +- deps/v8/src/objects/js-date-time-format.tq | 8 +- deps/v8/src/objects/js-duration-format-inl.h | 14 +- deps/v8/src/objects/js-duration-format.cc | 8 +- deps/v8/src/objects/js-duration-format.h | 13 +- deps/v8/src/objects/js-duration-format.tq | 4 +- deps/v8/src/objects/js-function.cc | 2 +- deps/v8/src/objects/js-list-format-inl.h | 8 +- deps/v8/src/objects/js-list-format.cc | 8 +- deps/v8/src/objects/js-list-format.h | 6 +- deps/v8/src/objects/js-list-format.tq | 2 +- deps/v8/src/objects/js-locale-inl.h | 6 +- deps/v8/src/objects/js-locale.cc | 20 +- deps/v8/src/objects/js-locale.h | 6 +- deps/v8/src/objects/js-locale.tq | 2 +- deps/v8/src/objects/js-number-format-inl.h | 6 +- deps/v8/src/objects/js-number-format.cc | 25 +- deps/v8/src/objects/js-number-format.h | 7 +- deps/v8/src/objects/js-number-format.tq | 2 +- deps/v8/src/objects/js-objects-inl.h | 5 +- deps/v8/src/objects/js-objects.cc | 7 +- deps/v8/src/objects/js-objects.h | 8 +- deps/v8/src/objects/js-plural-rules-inl.h | 12 +- deps/v8/src/objects/js-plural-rules.cc | 19 +- deps/v8/src/objects/js-plural-rules.h | 13 +- deps/v8/src/objects/js-plural-rules.tq | 4 +- .../src/objects/js-relative-time-format-inl.h | 7 +- .../v8/src/objects/js-relative-time-format.cc | 10 +- deps/v8/src/objects/js-relative-time-format.h | 7 +- .../v8/src/objects/js-relative-time-format.tq | 3 +- deps/v8/src/objects/js-segmenter-inl.h | 6 +- deps/v8/src/objects/js-segmenter.cc | 6 +- deps/v8/src/objects/js-segmenter.h | 6 +- deps/v8/src/objects/js-segmenter.tq | 2 +- deps/v8/src/objects/lookup-inl.h | 15 +- deps/v8/src/objects/lookup.cc | 3 + deps/v8/src/objects/managed-inl.h | 12 +- deps/v8/src/objects/managed-type-id.h | 18 - deps/v8/src/objects/map.cc | 18 +- deps/v8/src/objects/module.cc | 4 +- deps/v8/src/objects/object-list-macros.h | 14 + deps/v8/src/objects/object-macros.h | 23 +- .../objects/objects-body-descriptors-inl.h | 5 - deps/v8/src/objects/objects.h | 18 +- deps/v8/src/objects/oddball-predicates-inl.h | 6 + deps/v8/src/objects/oddball-predicates.h | 3 + deps/v8/src/objects/scope-info.cc | 39 +- deps/v8/src/objects/scope-info.h | 14 +- deps/v8/src/objects/script-inl.h | 55 +- deps/v8/src/objects/script.cc | 57 + deps/v8/src/objects/script.h | 19 +- .../v8/src/objects/shared-function-info-inl.h | 57 +- deps/v8/src/objects/shared-function-info.cc | 39 +- deps/v8/src/objects/shared-function-info.h | 8 +- deps/v8/src/objects/simd.cc | 59 +- deps/v8/src/objects/source-text-module.cc | 9 +- deps/v8/src/objects/string-inl.h | 59 +- deps/v8/src/objects/string-table.cc | 70 +- deps/v8/src/objects/string.cc | 5 +- deps/v8/src/objects/string.h | 25 +- deps/v8/src/objects/transitions.cc | 1 + deps/v8/src/objects/trusted-object-inl.h | 3 +- deps/v8/src/objects/value-serializer.cc | 14 +- deps/v8/src/parsing/parse-info.cc | 4 +- deps/v8/src/parsing/parse-info.h | 11 +- deps/v8/src/parsing/parser-base.h | 55 +- deps/v8/src/parsing/parser.cc | 68 +- deps/v8/src/parsing/parser.h | 3 +- deps/v8/src/parsing/preparse-data.cc | 1 + deps/v8/src/parsing/preparse-data.h | 6 +- deps/v8/src/parsing/preparser.cc | 9 +- deps/v8/src/parsing/preparser.h | 3 +- deps/v8/src/profiler/cpu-profiler.cc | 1 + deps/v8/src/profiler/heap-profiler.cc | 17 +- deps/v8/src/profiler/heap-profiler.h | 2 + .../src/profiler/heap-snapshot-generator.cc | 227 ++- .../v8/src/profiler/heap-snapshot-generator.h | 54 + deps/v8/src/profiler/profiler-listener.h | 4 +- .../v8/src/profiler/sampling-heap-profiler.cc | 76 +- deps/v8/src/profiler/sampling-heap-profiler.h | 36 +- deps/v8/src/profiler/strings-storage.cc | 44 + deps/v8/src/profiler/strings-storage.h | 5 + .../arm64/regexp-macro-assembler-arm64.cc | 30 + .../arm64/regexp-macro-assembler-arm64.h | 5 + deps/v8/src/regexp/gen-regexp-special-case.cc | 57 +- deps/v8/src/regexp/regexp-compiler-tonode.cc | 91 +- deps/v8/src/regexp/regexp-compiler.cc | 25 +- deps/v8/src/regexp/regexp-macro-assembler.cc | 34 +- deps/v8/src/regexp/special-case.h | 110 +- deps/v8/src/roots/roots-inl.h | 6 + deps/v8/src/roots/roots.cc | 14 + deps/v8/src/roots/roots.h | 130 +- deps/v8/src/roots/static-roots-intl-nowasm.h | 72 +- deps/v8/src/roots/static-roots-intl-wasm.h | 89 +- .../v8/src/roots/static-roots-nointl-nowasm.h | 72 +- deps/v8/src/roots/static-roots-nointl-wasm.h | 89 +- deps/v8/src/runtime/runtime-scopes.cc | 8 +- deps/v8/src/runtime/runtime-strings.cc | 18 +- deps/v8/src/runtime/runtime-test.cc | 35 +- deps/v8/src/runtime/runtime-wasm.cc | 256 ++-- deps/v8/src/runtime/runtime.cc | 1 + deps/v8/src/runtime/runtime.h | 7 +- deps/v8/src/sandbox/bytecode-verifier.cc | 2 + deps/v8/src/sandbox/cppheap-pointer-tag.h | 83 ++ deps/v8/src/sandbox/cppheap-pointer.h | 1 + deps/v8/src/sandbox/external-pointer-inl.h | 18 +- deps/v8/src/sandbox/external-pointer.h | 14 +- .../sandbox/generated-code-validator-arm64.cc | 13 +- deps/v8/src/sandbox/indirect-pointer-tag.h | 14 +- deps/v8/src/sandbox/js-dispatch-table-inl.h | 15 - deps/v8/src/sandbox/js-dispatch-table.h | 15 - deps/v8/src/sandbox/sandbox.cc | 108 +- deps/v8/src/sandbox/sandbox.h | 21 +- deps/v8/src/sandbox/testing.cc | 124 +- deps/v8/src/snapshot/deserializer.cc | 29 +- deps/v8/src/snapshot/serializer.cc | 128 +- deps/v8/src/snapshot/serializer.h | 3 + deps/v8/src/snapshot/snapshot.cc | 1 + deps/v8/src/snapshot/snapshot.h | 5 + deps/v8/src/snapshot/static-roots-gen.cc | 71 +- deps/v8/src/strings/string-hasher-inl.h | 1 + deps/v8/src/strings/string-stream.cc | 5 +- deps/v8/src/torque/implementation-visitor.cc | 8 +- deps/v8/src/torque/torque-parser.cc | 5 + deps/v8/src/torque/utils.cc | 3 +- deps/v8/src/tracing/perfetto-logger.cc | 3 +- deps/v8/src/tracing/perfetto-logger.h | 4 +- deps/v8/src/tracing/trace-categories.h | 2 + deps/v8/src/tracing/trace-event-no-perfetto.h | 9 +- deps/v8/src/utils/version.cc | 9 + deps/v8/src/utils/version.h | 8 +- .../arm64/liftoff-assembler-arm64-inl.h | 16 +- deps/v8/src/wasm/baseline/liftoff-assembler.h | 5 +- deps/v8/src/wasm/baseline/liftoff-compiler.cc | 187 ++- .../riscv/liftoff-assembler-riscv-inl.h | 4 +- .../baseline/x64/liftoff-assembler-x64-inl.h | 19 +- .../src/wasm/constant-expression-interface.cc | 89 +- deps/v8/src/wasm/function-body-decoder-impl.h | 55 +- deps/v8/src/wasm/module-compiler.cc | 43 +- .../v8/src/wasm/turboshaft-graph-interface.cc | 107 +- deps/v8/src/wasm/value-type.h | 2 + deps/v8/src/wasm/wasm-builtin-list.h | 4 +- deps/v8/src/wasm/wasm-code-manager.cc | 311 ++--- deps/v8/src/wasm/wasm-code-manager.h | 16 +- deps/v8/src/wasm/wasm-disassembler.cc | 38 +- deps/v8/src/wasm/wasm-engine.cc | 11 +- deps/v8/src/wasm/wasm-external-refs.cc | 14 +- deps/v8/src/wasm/wasm-js.cc | 24 +- deps/v8/src/wasm/wasm-linkage.h | 9 + deps/v8/src/wasm/wasm-memory-map-descriptor.h | 3 +- deps/v8/src/wasm/wasm-objects-inl.h | 29 - deps/v8/src/wasm/wasm-objects.cc | 127 +- deps/v8/src/wasm/wasm-objects.h | 30 +- deps/v8/src/wasm/wasm-objects.tq | 10 +- deps/v8/src/wasm/wasm-opcodes.h | 3 +- deps/v8/src/wasm/wasm-serialization.cc | 2 +- deps/v8/src/wasm/wasm-wrapper-cache-inl.h | 2 +- deps/v8/test/benchmarks/cpp/BUILD.gn | 3 + deps/v8/test/benchmarks/cpp/bindings.cc | 7 +- deps/v8/test/cctest/BUILD.gn | 1 + .../cctest/compiler/test-code-generator.cc | 60 +- .../cctest/compiler/test-js-typed-lowering.cc | 5 +- .../cctest/compiler/test-multiple-return.cc | 52 +- deps/v8/test/cctest/heap/heap-tester.h | 2 - deps/v8/test/cctest/heap/heap-utils.cc | 4 +- deps/v8/test/cctest/heap/test-heap.cc | 433 ------ deps/v8/test/cctest/test-accessors.cc | 17 +- deps/v8/test/cctest/test-api-array-buffer.cc | 56 + deps/v8/test/cctest/test-api-incumbent.cc | 2 +- deps/v8/test/cctest/test-api-interceptors.cc | 37 +- deps/v8/test/cctest/test-api.cc | 549 +++++++- deps/v8/test/cctest/test-api.h | 9 +- deps/v8/test/cctest/test-cpu-profiler.cc | 9 +- deps/v8/test/cctest/test-debug.cc | 8 +- deps/v8/test/cctest/test-heap-profiler.cc | 79 ++ deps/v8/test/cctest/test-js-weak-refs.cc | 24 +- deps/v8/test/cctest/test-serialize.cc | 125 +- deps/v8/test/cctest/test-strings.cc | 2 +- .../cctest/wasm/test-run-wasm-atomics64.cc | 30 +- .../cctest/wasm/test-run-wasm-wrappers.cc | 21 +- .../cctest/wasm/test-streaming-compilation.cc | 51 +- .../cctest/wasm/test-wasm-serialization.cc | 36 +- deps/v8/test/common/version-utils.h | 31 + deps/v8/test/common/wasm/fuzzer-common.cc | 2 +- deps/v8/test/common/wasm/wasm-run-utils.cc | 2 +- .../debug-evaluate-shadowed-context-reuse.js | 62 + .../debug/debug-evaluate-shadowed-context.js | 62 + deps/v8/test/fuzzer/multi-return.cc | 24 +- deps/v8/test/fuzzer/wasm/deopt.cc | 4 + deps/v8/test/inspector/BUILD.gn | 1 + .../console/stack-tagging-expected.txt | 8 +- .../debugger/class-fields-scopes-expected.txt | 11 + .../class-private-fields-scopes-expected.txt | 1 + ...-constructor-anonymous-scopes-expected.txt | 13 + .../function-constructor-anonymous-scopes.js | 50 + .../runtime/regress-553931056-expected.txt | 92 ++ .../inspector/runtime/regress-553931056.js | 143 ++ .../scopes-internal-property-expected.txt | 80 ++ .../runtime/scopes-internal-property.js | 114 ++ .../runtime/terminate-execution-expected.txt | 18 + .../inspector/runtime/terminate-execution.js | 8 + .../intl/date-format/temporal-cjk-format.js | 26 + deps/v8/test/intl/intl.status | 6 + deps/v8/test/intl/regexp-case-equivalence.js | 55 + .../intl/regexp-ignore-case-alternatives.js | 57 + deps/v8/test/intl/regress-10248.js | 2 +- deps/v8/test/intl/regress-10573.js | 6 +- .../compiler/concurrent-string-ext-seq.js | 28 +- .../mjsunit/compiler/regress-331909453.js | 2 +- .../mjsunit/compiler/regress-561186948.js | 26 + .../mjsunit/compiler/regress-crbug-1201011.js | 2 +- .../mjsunit/compiler/regress-crbug-1201057.js | 2 +- .../mjsunit/compiler/regress-crbug-1201082.js | 2 +- .../mjsunit/compiler/regress-crbug-1457532.js | 2 +- .../compiler/script-context-specialization.js | 58 + .../compiler/typed-array-length-as-number.js | 2 +- .../compiler/typed-array-length-iteration.js | 2 +- ...-test-access-checked-interceptor-object.js | 22 + .../test/mjsunit/d8/d8-test-special-object.js | 53 - .../test/mjsunit/empirical_max_arraybuffer.js | 32 +- ...aglev-no-elements-protector-invalidated.js | 4 +- ...or-optimization-maglev-custom-prototype.js | 2 +- ...tor-optimization-maglev-eager-next-call.js | 2 +- ...ator-optimization-maglev-elements-kinds.js | 4 +- ...-optimization-maglev-iterated-map-check.js | 4 +- ...-iterator-optimization-maglev-map-check.js | 4 +- ...terator-optimization-maglev-megamorphic.js | 4 +- ...nkey-patch-iterator-from-another-object.js | 4 +- ...r-optimization-maglev-monkey-patch-next.js | 4 +- ...v-no-elements-protector-already-invalid.js | 2 +- ...or-optimization-maglev-non-array-object.js | 6 +- ...terator-optimization-maglev-polymorphic.js | 4 +- ...-iterator-optimization-maglev-protector.js | 4 +- ...terator-optimization-maglev-typed-array.js | 2 +- deps/v8/test/mjsunit/es6/super.js | 18 + .../harmony/dynamic-code-brand-checks.js | 81 ++ deps/v8/test/mjsunit/homomorphic-array-smi.js | 34 +- deps/v8/test/mjsunit/homomorphic-ic.js | 6 +- .../regress/regress-561323344.js | 2 +- deps/v8/test/mjsunit/maglev/add-number.js | 14 +- deps/v8/test/mjsunit/maglev/add-smi.js | 8 +- .../maglev/alias-materialized-objects.js | 2 +- .../maglev/array-iterator-next-polymorphic.js | 6 +- ...array-prototype-map-elements-kinds-dict.js | 6 +- .../array-prototype-map-elements-kinds.js | 44 +- .../maglev/array-push-with-impossible-type.js | 2 +- .../maglev/array-push-with-smi-object.js | 4 +- .../v8/test/mjsunit/maglev/call-js-runtime.js | 2 +- .../mjsunit/maglev/call-runtime-for-pair.js | 2 +- .../test/mjsunit/maglev/check-int32-is-smi.js | 4 +- ...checkmaps-with-migration-and-deopt-mono.js | 6 +- ...heckmaps-with-migration-and-deopt-mono2.js | 2 +- ...checkmaps-with-migration-and-deopt-poly.js | 6 +- ...heckmaps-with-migration-and-deopt-poly2.js | 2 +- ...heckmaps-with-migration-and-deopt-poly3.js | 4 +- .../collection-iterator-next-inlined.js | 4 +- .../mjsunit/maglev/const-string-concat.js | 2 +- .../constant-typed-array-load-deopt-detach.js | 4 +- .../constant-typed-array-load-deopt-oob.js | 4 +- .../constant-typed-array-load-double.js | 2 +- .../constant-typed-array-load-no-rab-gsab.js | 8 +- .../constant-typed-array-load-signed.js | 2 +- .../constant-typed-array-load-unsigned.js | 2 +- ...constant-typed-array-store-deopt-detach.js | 4 +- .../constant-typed-array-store-deopt-oob.js | 4 +- .../constant-typed-array-store-double.js | 4 +- .../maglev/constant-typed-array-store-int.js | 2 +- .../constant-typed-array-store-no-rab-gsab.js | 8 +- .../maglev/context-extension-mutability.js | 78 ++ .../maglev/context-inverted-generator3.js | 30 + .../dataview-getbytelength-not-dataview.js | 2 +- .../dataview-getbytelength-undefined.js | 2 +- .../mjsunit/maglev/dataview-getbytelength.js | 2 +- ...ring-assignment-with-exclude-properties.js | 2 +- deps/v8/test/mjsunit/maglev/dict-load.js | 2 +- .../test/mjsunit/maglev/dont-forget-holes.js | 2 +- .../v8/test/mjsunit/maglev/dont-forget-oob.js | 2 +- .../mjsunit/maglev/equals-number-boolean.js | 4 +- deps/v8/test/mjsunit/maglev/extras-cped.js | 4 +- .../mjsunit/maglev/float64-conversions.js | 18 +- .../mjsunit/maglev/get-template-object.js | 2 +- .../maglev/holey-double-unsilenced-exit.js | 4 +- .../maglev/holey-float64-exception-phi.js | 2 +- .../mjsunit/maglev/inline-fulfill-promise.js | 6 +- deps/v8/test/mjsunit/maglev/inner-function.js | 2 +- deps/v8/test/mjsunit/maglev/int32-branch.js | 4 +- .../mjsunit/maglev/int32-mul-truncation.js | 10 +- .../maglev/keyed-access-thin-constant-key.js | 4 +- .../mjsunit/maglev/large-typedarray-oob.js | 2 +- .../lazy-deopt-with-onstack-activation.js | 4 +- .../lazy-deopt-without-onstack-activation.js | 4 +- .../maglev/lda-global-inside-typeof.js | 4 +- deps/v8/test/mjsunit/maglev/lda-global.js | 4 +- .../mjsunit/maglev/lda-module-variable.mjs | 4 +- deps/v8/test/mjsunit/maglev/literals.js | 6 +- deps/v8/test/mjsunit/maglev/load-named.js | 12 +- .../maglev/math-max-float64-holey-float.js | 2 +- .../maglev/math-max-float64-inlined-const.js | 2 +- ...ath-max-float64-non-eager-inlined-const.js | 2 +- .../maglev/math-max-float64-not-const.js | 2 +- .../maglev/math-max-float64-same-inlining.js | 4 +- ...x-float64-speculation-wrong-first-param.js | 4 +- ...ax-float64-speculation-wrong-only-param.js | 4 +- ...-float64-speculation-wrong-second-param.js | 4 +- .../maglev/math-min-float64-holey-float.js | 2 +- .../maglev/math-min-float64-inlined-const.js | 2 +- ...ath-min-float64-non-eager-inlined-const.js | 2 +- .../maglev/math-min-float64-not-const.js | 2 +- .../maglev/math-min-float64-same-inlining.js | 4 +- ...n-float64-speculation-wrong-first-param.js | 4 +- ...in-float64-speculation-wrong-only-param.js | 4 +- ...-float64-speculation-wrong-second-param.js | 4 +- deps/v8/test/mjsunit/maglev/negate.js | 6 +- .../mjsunit/maglev/new-closure-tenured.js | 2 +- .../mjsunit/maglev/no-deopt-deprecated-map.js | 4 +- .../omit-default-ctors-array-iterator.js | 2 +- .../test/mjsunit/maglev/omit-default-ctors.js | 94 +- deps/v8/test/mjsunit/maglev/poly-calls-1.js | 4 +- deps/v8/test/mjsunit/maglev/poly-calls-2.js | 4 +- .../mjsunit/maglev/poly-store-transition.js | 2 +- .../test/mjsunit/maglev/polymorphic-store.js | 4 +- .../mjsunit/maglev/promise-catch-reduction.js | 18 +- .../mjsunit/maglev/promise-resolve-inline.js | 12 +- .../test/mjsunit/maglev/regress-410867001.js | 4 +- .../test/mjsunit/maglev/regress-457475186.js | 2 +- .../mjsunit/maglev/regress-498816446-3.js | 2 +- .../test/mjsunit/maglev/regress-500507435.js | 2 +- .../test/mjsunit/maglev/regress-521604719.js | 1 + .../test/mjsunit/maglev/regress-525348892.js | 2 +- .../test/mjsunit/maglev/regress-525732296.js | 2 +- .../test/mjsunit/maglev/regress-559932543.js | 135 ++ .../test/mjsunit/maglev/regress-560408014.js | 30 + .../mjsunit/maglev/regress/regress-1405651.js | 4 - .../maglev/resolve-promise-elide-then.js | 10 +- .../maglev/script-context-specialization.js | 56 + .../mjsunit/maglev/set-pending-message.js | 2 +- .../mjsunit/maglev/shift-right-logical-smi.js | 4 +- .../mjsunit/maglev/shift-right-logical.js | 4 +- .../v8/test/mjsunit/maglev/shift-right-smi.js | 4 +- deps/v8/test/mjsunit/maglev/shift-right.js | 4 +- deps/v8/test/mjsunit/maglev/spill-double.js | 4 +- .../mjsunit/maglev/sta-module-variable.mjs | 2 +- ...static-private-brand-inverted-generator.js | 85 ++ .../maglev/store-constant-field-nan.js | 2 +- ...ct-equals-receiver-or-null-or-undefined.js | 4 +- deps/v8/test/mjsunit/maglev/string-compare.js | 12 +- .../maglev/string-or-oddball-compare.js | 14 +- deps/v8/test/mjsunit/maglev/string-slice.js | 8 +- .../test/mjsunit/maglev/string-substring.js | 6 +- .../mjsunit/maglev/string-wrapper-add-1.js | 8 +- .../mjsunit/maglev/string-wrapper-add-2.js | 2 +- .../mjsunit/maglev/string-wrapper-add-3.js | 8 +- deps/v8/test/mjsunit/maglev/string-wrapper.js | 4 +- deps/v8/test/mjsunit/maglev/super-ic.js | 4 +- .../maglev/truncate-int32-many-uses.js | 2 +- deps/v8/test/mjsunit/maglev/truncate-int32.js | 2 +- .../mjsunit/maglev/typed-array-length-abs.js | 4 +- .../maglev/typed-array-length-all-kinds.js | 2 +- .../typed-array-length-as-number-large.js | 2 +- .../maglev/typed-array-length-as-number.js | 4 +- .../maglev/typed-array-length-bitwise.js | 4 +- .../typed-array-length-branch-if-root.js | 4 +- ...-array-length-branch-if-to-boolean-true.js | 4 +- .../maglev/typed-array-length-custom-1a.js | 2 +- .../maglev/typed-array-length-custom-1b.js | 4 +- .../maglev/typed-array-length-custom-2a.js | 2 +- .../maglev/typed-array-length-custom-2b.js | 4 +- .../maglev/typed-array-length-deopt-large.js | 2 +- .../maglev/typed-array-length-detached-1.js | 4 +- .../maglev/typed-array-length-detached-2.js | 4 +- .../typed-array-length-exception-phi.js | 4 +- ...ped-array-length-index-into-array-large.js | 6 +- .../typed-array-length-index-into-array.js | 4 +- ...ray-length-index-into-typed-array-large.js | 8 +- ...ped-array-length-index-into-typed-array.js | 6 +- .../typed-array-length-iteration-large.js | 4 +- .../maglev/typed-array-length-iteration.js | 4 +- .../maglev/typed-array-length-parseint.js | 4 +- .../mjsunit/maglev/typed-array-length-phi.js | 4 +- .../maglev/typed-array-length-rab-gsab.js | 4 +- ...yped-array-length-store-as-uint8clamped.js | 4 +- ...ed-array-length-store-into-global-large.js | 6 +- .../typed-array-length-store-into-global.js | 4 +- ...array-length-store-script-context-large.js | 4 +- ...typed-array-length-store-script-context.js | 4 +- .../maglev/typed-array-length-to-boolean.js | 4 +- .../typed-array-length-to-number-large.js | 4 +- .../maglev/typed-array-length-to-number.js | 4 +- .../maglev/uint8-clamped-store-undefined.js | 2 +- .../maglev/undefined-or-null-branch.js | 2 +- .../mjsunit/maglev/unstable-map-transition.js | 2 +- deps/v8/test/mjsunit/mjsunit.js | 90 +- deps/v8/test/mjsunit/mjsunit.status | 109 +- .../proto-seq-opt-arrow-function.js | 2 +- ...proto-seq-opt-assign-key-multiple-times.js | 2 +- .../opt-proto-seq/proto-seq-opt-basic.js | 2 +- .../proto-seq-opt-before-after.js | 2 +- .../proto-seq-opt-class-fast-path.js | 2 +- .../opt-proto-seq/proto-seq-opt-computed.js | 2 +- .../proto-seq-opt-constructor.js | 2 +- .../proto-seq-opt-different-left-most-var.js | 2 +- .../proto-seq-opt-different-objects.js | 2 +- .../opt-proto-seq/proto-seq-opt-duplicate.js | 2 +- ...o-seq-opt-eval-return-last-set-property.js | 2 +- ...oto-seq-opt-feedback-vector-side-effect.js | 2 +- .../proto-seq-opt-frozen-objects-strict.js | 2 +- .../proto-seq-opt-frozen-objects.js | 2 +- .../proto-seq-opt-function-fast-path.js | 2 +- .../opt-proto-seq/proto-seq-opt-functions.js | 2 +- ...oto-seq-opt-get-own-property-descriptor.js | 2 +- ...to-seq-opt-get-own-property-descriptors.js | 2 +- .../proto-seq-opt-global-proxy.js | 2 +- .../proto-seq-opt-has-prototype-keys.js | 2 +- .../proto-seq-opt-has-setters.js | 2 +- .../proto-seq-opt-ignore-chain-descriptors.js | 2 +- .../opt-proto-seq/proto-seq-opt-iife.js | 2 +- .../proto-seq-opt-interleaved.js | 2 +- .../proto-seq-opt-lazy-override-builtin.js | 2 +- .../opt-proto-seq/proto-seq-opt-limit.js | 2 +- .../proto-seq-opt-locked-proto-strict.js | 2 +- .../proto-seq-opt-locked-proto.js | 2 +- ...o-seq-opt-non-extensible-objects-strict.js | 2 +- .../proto-seq-opt-non-extensible-objects.js | 2 +- .../proto-seq-opt-non-literal.js | 2 +- .../proto-seq-opt-not-function.js | 2 +- .../proto-seq-opt-not-proto-assign-seq.js | 2 +- .../proto-seq-opt-null-prototype.js | 2 +- .../proto-seq-opt-object-assign.js | 2 +- .../proto-seq-opt-object-entries.js | 2 +- .../proto-seq-opt-object-values.js | 2 +- .../proto-seq-opt-poison-default-proto.js | 2 +- .../proto-seq-opt-preserve-descriptor.js | 2 +- ...oto-seq-opt-proto-of-prototype-assigned.js | 2 +- .../opt-proto-seq/proto-seq-opt-proto-prop.js | 2 +- .../proto-seq-opt-prototype-proto-keys.js | 2 +- .../proto-seq-opt-prototype-read-only.js | 2 +- .../proto-seq-opt-readonly-chain.js | 2 +- .../proto-seq-opt-reassign-local.js | 2 +- ...opt-reflect-get-own-property-descriptor.js | 2 +- .../proto-seq-opt-reflect-get.js | 2 +- .../proto-seq-opt-setter-chain.js | 2 +- .../opt-proto-seq/proto-seq-opt-shadow.js | 2 +- .../proto-seq-opt-slow-modified.js | 2 +- .../proto-seq-opt-slow-non-extensible.js | 2 +- .../opt-proto-seq/proto-seq-opt-spreading.js | 2 +- .../opt-proto-seq/proto-seq-opt-strict.js | 2 +- .../proto-seq-opt-structured-clone.js | 2 +- .../proto-seq-opt-variable-proxy-eval.js | 2 +- .../proto-seq-opt-variable-proxy.js | 2 +- .../private_fields/test_private_fields.js | 12 +- .../test/mjsunit/regress/regress-1320641.js | 2 +- .../test/mjsunit/regress/regress-395028748.js | 2 +- .../test/mjsunit/regress/regress-424627229.js | 2 +- .../test/mjsunit/regress/regress-438321229.js | 2 +- .../mjsunit/regress/regress-499527555-2.js | 1 + .../test/mjsunit/regress/regress-499527555.js | 1 + .../test/mjsunit/regress/regress-506178478.js | 22 + .../test/mjsunit/regress/regress-509312809.js | 1 + .../test/mjsunit/regress/regress-511279942.js | 4 +- .../test/mjsunit/regress/regress-519652102.js | 17 + .../test/mjsunit/regress/regress-525472602.js | 16 + .../test/mjsunit/regress/regress-558568713.js | 21 + .../test/mjsunit/regress/regress-559266116.js | 20 + .../test/mjsunit/regress/regress-559408989.js | 24 + .../test/mjsunit/regress/regress-559536931.js | 38 + .../test/mjsunit/regress/regress-560730175.js | 31 + .../test/mjsunit/regress/regress-561116893.js | 10 + .../test/mjsunit/regress/regress-562529689.js | 10 + .../test/mjsunit/regress/regress-562557292.js | 41 + .../test/mjsunit/regress/regress-563764306.js | 22 + .../test/mjsunit/regress/regress-564625827.js | 28 + .../test/mjsunit/regress/regress-565836459.js | 32 + .../test/mjsunit/regress/regress-566243375.js | 12 + .../regress/regress-crbug-388320179.js | 30 + .../regress/regress-crbug-562108903.js | 47 + .../regress-derived-ctor-tdz-stack-trace.js | 42 + .../regress/regress-escaped-get-set-asi.js | 21 + .../regress/regress-homomorphic-maglev.js | 6 +- .../regress/regress-homomorphic-turbofan.js | 6 +- .../regress-homomorphic-unoptimized.js | 7 +- .../regress-json-escaped-key-transition.js | 76 + .../regress/regress-maglev-mul-minus-zero.js | 69 + ...ess-regexp-lookbehind-sort-alternatives.js | 22 + .../mjsunit/regress/regression-513327211.js | 52 + .../mjsunit/regress/regression-514440066.js | 32 + .../mjsunit/regress/wasm/regress-334687959.js | 2 +- .../mjsunit/regress/wasm/regress-368086282.js | 2 +- .../mjsunit/regress/wasm/regress-438770394.js | 2 +- .../mjsunit/regress/wasm/regress-523591366.js | 85 ++ .../mjsunit/regress/wasm/regress-557846268.js | 30 + .../mjsunit/regress/wasm/regress-561660149.js | 75 + .../mjsunit/regress/wasm/regress-561662099.js | 46 + .../mjsunit/regress/wasm/regress-562655126.js | 30 + .../regress/wasm/regress-563427048-2.js | 36 + .../regress/wasm/regress-563427048-3.js | 33 + .../mjsunit/regress/wasm/regress-563427048.js | 50 + .../mjsunit/regress/wasm/regress-565565747.js | 23 + .../mjsunit/regress/wasm/regress-565847635.js | 27 + .../mjsunit/regress/wasm/regress-566973959.js | 27 + .../regress/wasm/regress-simd-528884838.js | 2 +- .../wasm/regress-wasmfx-unreachable-resume.js | 51 + .../mjsunit/sandbox/memory-corruption-api.js | 1 + .../test/mjsunit/sandbox/regress-435630461.js | 2 +- .../test/mjsunit/sandbox/regress-561387542.js | 46 + .../test/mjsunit/sandbox/regress-562788806.js | 34 + .../test/mjsunit/sandbox/regress-565797753.js | 30 + .../sandbox/regress/regress-512160117.js | 2 +- .../sandbox/regress/regress-532513886.js | 36 + .../sandbox/regress/regress-560282287-2.js | 87 ++ .../sandbox/regress/regress-560282287.js | 62 + .../sandbox/regress/regress-562870022.js | 15 + .../tools/tickprocessor-test-large.log | 10 +- .../mjsunit/turbolev/dataview-deopt-oob.js | 2 +- .../mjsunit/turbolev/float64-mul-range.js | 20 + ...ound-function-graph-optimizer-map-check.js | 46 + .../instanceof-graph-optimizer-map-check.js | 37 + .../mjsunit/turbolev/regress-488090094.js | 4 +- ...ray-length-index-into-typed-array-large.js | 2 +- ...ped-array-length-index-into-typed-array.js | 2 +- .../turbolev/typed-array-length-phi.js | 2 +- .../mjsunit/turbolev/update-jsarray-length.js | 56 + .../v8/test/mjsunit/turboshaft/extras-cped.js | 2 +- .../turboshaft/typer-pow-matches-runtime.js | 57 + .../tzoffset-fractional-los-angeles.js | 62 + deps/v8/test/mjsunit/wasm/exact-types.js | 67 + ...i-calls-with-wellknown-imports-conflict.js | 2 +- ...api-calls-with-wellknown-imports-floats.js | 2 +- ...st-api-calls-with-wellknown-imports-i64.js | 2 +- ...api-calls-with-wellknown-imports-tagged.js | 2 +- .../wasm/gc-js-interop-private-symbols.js | 83 ++ deps/v8/test/mjsunit/wasm/indirect-tables.js | 16 +- .../v8/test/mjsunit/wasm/recognize-imports.js | 2 +- .../mjsunit/wasm/redundant-shuffle-lanes.js | 207 +++ .../v8/test/mjsunit/wasm/regress-561849345.js | 100 ++ .../v8/test/mjsunit/wasm/regress-564326756.js | 136 ++ .../wasm/shared-everything/post-message.js | 27 +- .../wasm/shared-everything/wait-queue.js | 183 ++- .../test/mjsunit/wasm/simd-int-narrowing.js | 91 ++ .../test/mjsunit/wasm/wasm-module-builder.js | 3 +- deps/v8/test/mjsunit/wasm/wide-add.js | 64 + deps/v8/test/mkgrokdump/BUILD.gn | 1 + deps/v8/test/test262/.lint-vpython3 | 4 - deps/v8/test/test262/PRESUBMIT.py | 2 +- deps/v8/test/test262/lint-vpython.toml | 9 + .../v8/test/test262/lint-vpython.toml.uv.lock | 19 + deps/v8/test/test262/test262.status | 15 +- deps/v8/test/unittests/BUILD.gn | 6 + .../unittests/api/access-check-unittest.cc | 2 +- .../test/unittests/api/api-wasm-unittest.cc | 14 +- .../unittests/api/remote-object-unittest.cc | 24 + .../unittests/api/v8-array-buffer-unittest.cc | 24 + .../test/unittests/api/v8-object-unittest.cc | 6 +- .../base/region-allocator-unittest.cc | 35 + ...aft-instruction-selector-arm64-unittest.cc | 266 +++- .../compiler/common-operator-unittest.cc | 49 +- .../unittests/compiler/compiler-unittest.cc | 53 + .../decompression-optimizer-unittest.cc | 6 +- ...haft-instruction-selector-ia32-unittest.cc | 2 +- .../compiler/js-call-reducer-unittest.cc | 10 +- ...t-instruction-selector-loong64-unittest.cc | 36 +- ...ft-instruction-selector-mips64-unittest.cc | 36 +- ...t-instruction-selector-riscv64-unittest.cc | 102 +- ...election-normalization-reducer-unittest.cc | 67 + .../wasm-shuffle-reducer-unittest.cc | 162 ++- .../compiler/turboshaft/wasm-simd-unittest.cc | 4 +- ...shaft-instruction-selector-x64-unittest.cc | 2 +- .../debug/debug-block-list-unittest.cc | 317 +++++ .../debug/debug-scope-info-unittest.cc | 601 ++++++++ .../diagnostics/etw-control-unittest.cc | 48 +- .../execution/microtask-queue-unittest.cc | 24 + .../flags/flag-definitions-unittest.cc | 8 + .../embedder-roots-handler-unittest.cc | 4 +- .../cppgc-js/traced-reference-unittest.cc | 140 ++ .../unified-heap-snapshot-unittest.cc | 7 +- .../heap/cppgc-js/unified-heap-unittest.cc | 1 - .../heap/cppgc-js/unified-heap-utils.cc | 4 +- .../test/unittests/heap/gc-tracer-unittest.cc | 26 +- deps/v8/test/unittests/heap/heap-unittest.cc | 447 +++++- deps/v8/test/unittests/heap/heap-utils.cc | 56 +- deps/v8/test/unittests/heap/heap-utils.h | 19 + .../unittests/inspector/inspector-unittest.cc | 9 - .../bytecode-array-builder-unittest.cc | 8 +- .../bytecode_expectations/BasicLoops.golden | 2 +- .../BreakableBlocks.golden | 6 +- .../ClassAndSuperClass.golden | 8 +- .../ConstVariable.golden | 4 +- .../ConstVariableContextSlot.golden | 10 +- .../ContextVariables.golden | 4 +- .../ElideRedundantHoleChecks.golden | 184 +-- .../bytecode_expectations/ForOfLoop.golden | 6 +- .../HoleCheckElision.golden | 10 +- .../bytecode_expectations/LetVariable.golden | 4 +- .../LetVariableContextSlot.golden | 10 +- .../bytecode_expectations/Modules.golden | 2 +- .../PrivateAccessorDeclaration.golden | 122 +- .../PrivateMethodAccess.golden | 6 +- .../PublicClassFields.golden | 10 +- .../SetPrototypePropertiesOptimization.golden | 2 +- .../StandardForLoop.golden | 6 +- .../StaticClassFields.golden | 20 +- .../StaticPrivateMethodAccess.golden | 18 +- .../StaticPrivateMethodDeclaration.golden | 48 +- .../SuperCallAndSpread.golden | 8 +- .../v8/test/unittests/maglev/hamt-unittest.cc | 134 ++ .../objects/feedback-vector-unittest.cc | 13 - .../unittests/parser/ast-value-unittest.cc | 88 ++ .../test/unittests/parser/decls-unittest.cc | 10 +- .../profiler/heap-snapshot-scopes-unittest.cc | 1233 +++++++++++++++++ .../unittests/profiler/heap-snapshot-utils.h | 6 + .../test/unittests/regexp/regexp-unittest.cc | 162 +++ .../generated-code-validator-unittest.cc | 34 +- .../sandbox/sandbox-crash-filter-unittest.cc | 147 +- deps/v8/test/unittests/test-helpers.cc | 3 - deps/v8/test/unittests/test-utils.h | 9 +- .../test/unittests/utils/version-unittest.cc | 17 + .../wasm/liftoff-register-unittests.cc | 76 +- ...imd-cross-compiler-determinism-fuzztest.cc | 97 +- .../unittests/wasm/wasm-compiler-unittest.cc | 34 + .../wasm-disassembler-unittest-fp16.wasm.inc | 53 + .../wasm-disassembler-unittest-fp16.wat.inc | 27 + .../wasm/wasm-disassembler-unittest.cc | 40 + .../v8/third_party/abseil-cpp/README.chromium | 2 +- .../abseil-cpp/absl/abseil.podspec.gen.py | 7 +- .../abseil-cpp/absl/algorithm/CMakeLists.txt | 4 +- .../abseil-cpp/absl/base/BUILD.bazel | 11 +- .../third_party/abseil-cpp/absl/base/BUILD.gn | 8 +- .../abseil-cpp/absl/base/CMakeLists.txt | 22 +- .../abseil-cpp/absl/base/attributes.h | 5 +- .../abseil-cpp/absl/base/bit_cast_test.cc | 1 + .../abseil-cpp/absl/base/call_once.h | 4 +- .../abseil-cpp/absl/base/call_once_test.cc | 1 + .../absl/base/dynamic_annotations.h | 6 + .../base/exception_safety_testing_test.cc | 3 + .../base/internal/atomic_hook_test_helper.cc | 1 + .../base/internal/atomic_hook_test_helper.h | 1 + .../absl/base/internal/direct_mmap.h | 2 + .../base/internal/exception_safety_testing.cc | 6 + .../base/internal/exception_safety_testing.h | 16 +- .../abseil-cpp/absl/base/internal/hardening.h | 1 + .../base/internal/low_level_alloc_test.cc | 3 +- .../absl/base/internal/low_level_scheduling.h | 1 + .../absl/base/internal/scoped_set_env.cc | 1 + .../absl/base/internal/spinlock_wait.cc | 4 +- .../absl/base/internal/spinlock_wait.h | 2 + .../abseil-cpp/absl/base/internal/strerror.cc | 1 + .../absl/base/internal/sysinfo_test.cc | 1 + .../absl/base/internal/thread_identity.cc | 5 +- .../base/internal/thread_identity_test.cc | 1 + .../absl/base/internal/unscaledcycleclock.cc | 10 +- .../abseil-cpp/absl/cleanup/BUILD.bazel | 2 + .../abseil-cpp/absl/cleanup/BUILD.gn | 2 + .../abseil-cpp/absl/cleanup/cleanup_test.cc | 1 + .../absl/cleanup/internal/cleanup.h | 1 + .../abseil-cpp/absl/container/BUILD.bazel | 67 +- .../abseil-cpp/absl/container/BUILD.gn | 65 +- .../abseil-cpp/absl/container/CMakeLists.txt | 71 +- .../absl/container/btree_benchmark.cc | 5 + .../abseil-cpp/absl/container/btree_map.h | 1 + .../abseil-cpp/absl/container/btree_set.h | 1 + .../abseil-cpp/absl/container/btree_test.cc | 4 + .../abseil-cpp/absl/container/btree_test.h | 1 + .../absl/container/fixed_array_test.cc | 2 + .../abseil-cpp/absl/container/flat_hash_map.h | 1 + .../abseil-cpp/absl/container/flat_hash_set.h | 5 +- .../absl/container/flat_hash_set_test.cc | 7 +- .../absl/container/inlined_vector.h | 2 + .../container/inlined_vector_benchmark.cc | 4 + .../absl/container/inlined_vector_test.cc | 31 +- .../absl/container/internal/btree_container.h | 1 + .../absl/container/internal/common.h | 1 + .../container/internal/common_policy_traits.h | 1 + .../container/internal/compressed_tuple.h | 2 + .../internal/compressed_tuple_test.cc | 1 + .../container/internal/container_memory.h | 20 +- .../internal/container_memory_test.cc | 17 +- .../internal/hash_function_defaults_test.cc | 6 + .../internal/hash_generator_testing.cc | 1 + .../internal/hash_generator_testing.h | 1 + .../container/internal/hash_policy_testing.h | 2 + .../internal/hash_policy_testing_test.cc | 3 + .../container/internal/hash_policy_traits.h | 13 +- .../internal/hash_policy_traits_test.cc | 19 +- .../absl/container/internal/hashtable_debug.h | 3 +- .../container/internal/hashtablez_sampler.h | 1 + ...ashtablez_sampler_force_weak_definition.cc | 4 +- .../internal/hashtablez_sampler_test.cc | 1 + .../absl/container/internal/inlined_vector.h | 1 + .../container/internal/layout_benchmark.cc | 1 + .../absl/container/internal/raw_hash_set.cc | 421 +++--- .../absl/container/internal/raw_hash_set.h | 651 +++++---- .../internal/raw_hash_set_benchmark.cc | 118 +- .../internal/raw_hash_set_probe_benchmark.cc | 2 +- .../container/internal/raw_hash_set_test.cc | 97 +- .../internal/test_instance_tracker.cc | 2 + .../internal/test_instance_tracker.h | 2 + .../internal/test_instance_tracker_test.cc | 2 + .../internal/unordered_map_constructor_test.h | 2 + .../internal/unordered_map_lookup_test.h | 3 + .../internal/unordered_map_members_test.h | 5 + .../internal/unordered_map_modifiers_test.h | 3 + .../container/internal/unordered_map_test.cc | 5 + .../internal/unordered_set_constructor_test.h | 2 + .../internal/unordered_set_lookup_test.h | 4 + .../internal/unordered_set_members_test.h | 4 + .../internal/unordered_set_modifiers_test.h | 3 + .../container/internal/unordered_set_test.cc | 4 + .../absl/container/linked_hash_map_test.cc | 1 + .../abseil-cpp/absl/container/node_hash_map.h | 5 +- .../abseil-cpp/absl/container/node_hash_set.h | 5 +- .../container/sample_element_size_test.cc | 2 + .../abseil-cpp/absl/crc/BUILD.bazel | 6 +- .../third_party/abseil-cpp/absl/crc/BUILD.gn | 2 +- .../abseil-cpp/absl/crc/CMakeLists.txt | 20 +- .../third_party/abseil-cpp/absl/crc/crc32c.cc | 1 + .../third_party/abseil-cpp/absl/crc/crc32c.h | 1 + .../abseil-cpp/absl/crc/internal/crc.cc | 1 + .../absl/crc/internal/crc_internal.h | 1 + .../abseil-cpp/absl/debugging/BUILD.bazel | 3 + .../abseil-cpp/absl/debugging/BUILD.gn | 1 + .../abseil-cpp/absl/debugging/CMakeLists.txt | 41 +- .../absl/debugging/failure_signal_handler.cc | 2 +- .../debugging/internal/address_is_readable.cc | 2 + .../debugging/internal/stack_consumption.cc | 2 + .../internal/stack_consumption_test.cc | 2 + .../internal/stacktrace_powerpc-inl.inc | 5 +- .../absl/debugging/internal/vdso_support.cc | 1 + .../absl/debugging/internal/vdso_support.h | 1 + .../absl/debugging/stacktrace_test.cc | 2 +- .../abseil-cpp/absl/debugging/symbolize.h | 1 + .../absl/debugging/symbolize_elf.inc | 4 +- .../abseil-cpp/absl/flags/BUILD.bazel | 29 +- .../abseil-cpp/absl/flags/BUILD.gn | 11 +- .../abseil-cpp/absl/flags/CMakeLists.txt | 92 +- .../abseil-cpp/absl/flags/config_test.cc | 1 + .../third_party/abseil-cpp/absl/flags/flag.h | 2 +- .../abseil-cpp/absl/flags/flag_benchmark.cc | 1 + .../abseil-cpp/absl/flags/flag_test.cc | 2 +- .../absl/flags/internal/commandlineflag.cc | 2 + .../abseil-cpp/absl/flags/internal/flag.h | 7 +- .../abseil-cpp/absl/flags/internal/registry.h | 1 + .../absl/flags/internal/sequence_lock.h | 1 + .../absl/flags/internal/sequence_lock_test.cc | 2 + .../abseil-cpp/absl/flags/marshalling_test.cc | 1 + .../third_party/abseil-cpp/absl/flags/parse.h | 1 + .../abseil-cpp/absl/flags/reflection.cc | 5 + .../abseil-cpp/absl/flags/reflection.h | 1 + .../abseil-cpp/absl/flags/reflection_test.cc | 5 + .../abseil-cpp/absl/flags/usage.cc | 1 + .../abseil-cpp/absl/functional/BUILD.bazel | 2 + .../abseil-cpp/absl/functional/BUILD.gn | 5 + .../abseil-cpp/absl/functional/CMakeLists.txt | 18 +- .../absl/functional/any_invocable_test.h | 4 +- .../functional/any_invocable_test_inst1.cc | 1 + .../functional/any_invocable_test_inst2.cc | 1 + .../functional/any_invocable_test_inst3.cc | 1 + .../functional/any_invocable_test_inst4.cc | 1 + .../abseil-cpp/absl/functional/bind_front.h | 1 + .../absl/functional/bind_front_test.cc | 5 +- .../absl/functional/function_ref_test.cc | 1 + .../functional/function_type_benchmark.cc | 1 + .../absl/functional/internal/front_binder.h | 1 + .../absl/functional/internal/function_ref.h | 1 + .../abseil-cpp/absl/hash/BUILD.bazel | 8 +- .../third_party/abseil-cpp/absl/hash/BUILD.gn | 9 +- .../abseil-cpp/absl/hash/CMakeLists.txt | 19 +- .../third_party/abseil-cpp/absl/hash/hash.h | 85 ++ .../abseil-cpp/absl/hash/hash_benchmark.cc | 2 +- .../abseil-cpp/absl/hash/hash_test.cc | 158 ++- .../abseil-cpp/absl/hash/hash_testing.h | 1 + .../absl/hash/internal/city_test.cc | 1 + .../abseil-cpp/absl/hash/internal/hash.h | 58 +- .../absl/hash/internal/spy_hash_state.h | 1 + .../abseil-cpp/absl/log/BUILD.bazel | 22 +- .../third_party/abseil-cpp/absl/log/BUILD.gn | 8 +- .../abseil-cpp/absl/log/CMakeLists.txt | 196 ++- .../abseil-cpp/absl/log/die_if_null_test.cc | 2 +- .../third_party/abseil-cpp/absl/log/flags.cc | 2 +- .../abseil-cpp/absl/log/flags_test.cc | 2 +- .../abseil-cpp/absl/log/globals_test.cc | 2 +- .../abseil-cpp/absl/log/internal/BUILD.bazel | 20 +- .../abseil-cpp/absl/log/internal/BUILD.gn | 7 - .../abseil-cpp/absl/log/internal/conditions.h | 2 +- .../abseil-cpp/absl/log/internal/fnmatch.cc | 74 +- .../absl/log/internal/fnmatch_test.cc | 15 + .../absl/log/internal/log_message.cc | 3 +- .../abseil-cpp/absl/log/internal/proto.h | 3 + .../absl/log/internal/stderr_log_sink_test.cc | 2 +- .../log/internal/structured_proto_test.cc | 11 + .../abseil-cpp/absl/log/log_benchmark.cc | 4 +- .../abseil-cpp/absl/log/log_entry_test.cc | 2 +- .../abseil-cpp/absl/log/log_format_test.cc | 3 +- .../absl/log/log_macro_hygiene_test.cc | 8 +- .../abseil-cpp/absl/log/log_sink_test.cc | 2 +- .../abseil-cpp/absl/log/log_streamer_test.cc | 2 +- .../absl/log/scoped_mock_log_test.cc | 2 +- .../abseil-cpp/absl/log/structured_test.cc | 2 +- .../abseil-cpp/absl/memory/BUILD.bazel | 1 + .../abseil-cpp/absl/memory/BUILD.gn | 1 + .../abseil-cpp/absl/memory/CMakeLists.txt | 2 +- .../abseil-cpp/absl/memory/memory.h | 1 + .../abseil-cpp/absl/meta/CMakeLists.txt | 2 +- .../meta/internal/constexpr_testing_test.cc | 1 + .../abseil-cpp/absl/meta/type_traits.h | 1 + .../abseil-cpp/absl/numeric/BUILD.bazel | 1 + .../abseil-cpp/absl/numeric/BUILD.gn | 1 + .../abseil-cpp/absl/numeric/CMakeLists.txt | 6 +- .../abseil-cpp/absl/numeric/bits_test.cc | 1 + .../abseil-cpp/absl/numeric/int128.cc | 1 + .../abseil-cpp/absl/profiling/BUILD.bazel | 6 + .../abseil-cpp/absl/profiling/BUILD.gn | 3 + .../abseil-cpp/absl/profiling/CMakeLists.txt | 23 +- .../abseil-cpp/absl/profiling/hashtable.h | 1 + .../profiling/internal/exponential_biased.cc | 1 + .../internal/exponential_biased_test.cc | 1 + .../profiling/internal/periodic_sampler.cc | 1 + .../profiling/internal/periodic_sampler.h | 1 + .../internal/periodic_sampler_benchmark.cc | 1 + .../internal/periodic_sampler_test.cc | 1 + .../absl/profiling/internal/profile_builder.h | 1 + .../internal/sample_recorder_test.cc | 1 + .../abseil-cpp/absl/random/BUILD.bazel | 1 + .../abseil-cpp/absl/random/BUILD.gn | 1 + .../abseil-cpp/absl/random/CMakeLists.txt | 100 +- .../absl/random/gaussian_distribution.cc | 1 + .../absl/random/internal/BUILD.bazel | 10 +- .../abseil-cpp/absl/random/internal/BUILD.gn | 8 +- .../absl/random/internal/fastmath.h | 1 + .../absl/random/internal/generate_real.h | 1 + .../abseil-cpp/absl/random/internal/randen.h | 1 + .../absl/random/internal/randen_engine.h | 1 + .../absl/random/internal/salted_seed_seq.h | 1 + .../abseil-cpp/absl/status/BUILD.bazel | 11 +- .../abseil-cpp/absl/status/BUILD.gn | 6 +- .../abseil-cpp/absl/status/CMakeLists.txt | 22 +- .../absl/status/internal/statusor_internal.h | 1 + .../abseil-cpp/absl/status/status.cc | 2 + .../absl/status/status_payload_printer.h | 1 + .../abseil-cpp/absl/status/statusor.h | 1 + .../abseil-cpp/absl/status/statusor_test.cc | 1 + .../abseil-cpp/absl/strings/BUILD.bazel | 50 +- .../abseil-cpp/absl/strings/BUILD.gn | 14 +- .../abseil-cpp/absl/strings/CMakeLists.txt | 131 +- .../abseil-cpp/absl/strings/cord.cc | 9 +- .../abseil-cpp/absl/strings/cord.h | 32 +- .../abseil-cpp/absl/strings/escaping.h | 3 +- .../absl/strings/internal/charconv_bigint.cc | 1 + .../strings/internal/charconv_bigint_test.cc | 1 + .../absl/strings/internal/charconv_parse.cc | 1 + .../strings/internal/cord_data_edge_test.cc | 1 + .../absl/strings/internal/cord_internal.cc | 1 + .../absl/strings/internal/cord_internal.h | 17 +- .../internal/cord_rep_btree_navigator.cc | 1 + .../internal/cord_rep_btree_navigator.h | 1 + .../absl/strings/internal/cord_rep_consume.cc | 1 + .../absl/strings/internal/cord_rep_consume.h | 1 + .../absl/strings/internal/cord_rep_flat.h | 4 +- .../absl/strings/internal/cordz_handle.cc | 1 + .../strings/internal/cordz_handle_test.cc | 1 + .../internal/cordz_info_statistics_test.cc | 2 +- .../internal/cordz_sample_token_test.cc | 1 + .../absl/strings/internal/escaping.cc | 1 + .../strings/internal/escaping_test_common.h | 2 + .../absl/strings/internal/generic_printer.h | 2 + .../absl/strings/internal/memutil.cc | 1 + .../absl/strings/internal/memutil.h | 1 + .../absl/strings/internal/ostringstream.cc | 2 + .../absl/strings/internal/pow10_helper.cc | 2 + .../strings/internal/pow10_helper_test.cc | 1 + .../strings/internal/resize_uninitialized.h | 1 + .../strings/internal/str_format/bind_test.cc | 1 + .../strings/internal/str_format/checker.h | 1 + .../internal/str_format/checker_test.cc | 1 + .../internal/str_format/convert_test.cc | 2 + .../strings/internal/str_format/extension.cc | 1 + .../internal/str_format/float_conversion.h | 1 + .../strings/internal/str_format/output.cc | 1 + .../absl/strings/internal/str_format/output.h | 1 + .../internal/str_format/output_test.cc | 1 + .../strings/internal/str_format/parser.cc | 1 + .../strings/internal/str_split_internal.h | 1 + .../absl/strings/internal/string_constant.h | 1 + .../absl/strings/internal/stringify_sink.cc | 2 + .../absl/strings/internal/stringify_sink.h | 1 + .../abseil-cpp/absl/strings/match.h | 1 + .../abseil-cpp/absl/strings/str_join.h | 1 + .../abseil-cpp/absl/strings/str_replace.h | 1 + .../abseil-cpp/absl/strings/str_split.h | 7 +- .../abseil-cpp/absl/strings/strip.h | 1 + .../abseil-cpp/absl/strings/substitute.h | 1 + .../absl/synchronization/BUILD.bazel | 3 +- .../abseil-cpp/absl/synchronization/BUILD.gn | 3 +- .../absl/synchronization/CMakeLists.txt | 18 +- .../abseil-cpp/absl/synchronization/barrier.h | 1 + .../absl/synchronization/blocking_counter.h | 1 + .../internal/create_thread_identity.h | 1 + .../synchronization/internal/per_thread_sem.h | 1 + .../synchronization/internal/thread_pool.h | 1 + .../abseil-cpp/absl/synchronization/mutex.cc | 4 +- .../abseil-cpp/absl/time/BUILD.bazel | 2 + .../third_party/abseil-cpp/absl/time/BUILD.gn | 2 + .../abseil-cpp/absl/time/CMakeLists.txt | 26 +- .../abseil-cpp/absl/time/civil_time.cc | 2 + .../abseil-cpp/absl/time/civil_time.h | 1 + .../abseil-cpp/absl/time/civil_time_test.cc | 1 + .../third_party/abseil-cpp/absl/time/clock.cc | 3 + .../abseil-cpp/absl/time/clock_benchmark.cc | 5 +- .../absl/time/duration_benchmark.cc | 1 + .../abseil-cpp/absl/time/flag_test.cc | 1 + .../abseil-cpp/absl/time/format.cc | 3 + .../abseil-cpp/absl/time/format_benchmark.cc | 1 + .../abseil-cpp/absl/time/format_test.cc | 1 + .../absl/time/internal/test_util.cc | 3 + .../abseil-cpp/absl/time/internal/test_util.h | 1 + .../absl/time/simulated_clock_test.cc | 1 + .../third_party/abseil-cpp/absl/time/time.cc | 5 + .../third_party/abseil-cpp/absl/time/time.h | 14 +- .../abseil-cpp/absl/time/time_benchmark.cc | 1 + .../abseil-cpp/absl/time/time_test.cc | 21 +- .../abseil-cpp/absl/types/BUILD.bazel | 2 + .../abseil-cpp/absl/types/BUILD.gn | 3 + .../abseil-cpp/absl/types/CMakeLists.txt | 9 +- .../abseil-cpp/absl/types/any_span_test.cc | 7 +- .../abseil-cpp/absl/types/compare_test.cc | 4 + .../abseil-cpp/absl/types/source_location.h | 18 +- .../abseil-cpp/absl/types/span_test.cc | 8 +- .../abseil-cpp/convert_bazel_to_gn.py | 2 +- .../patches/0001-Undeprecate-deprecated.patch | 14 + .../0004-string-view-transitive-includes | 7 +- .../abseil-cpp/symbols_arm64_dbg.def | 60 +- .../abseil-cpp/symbols_arm64_dbg_cxx23.def | 60 +- .../abseil-cpp/symbols_arm64_rel.def | 29 +- .../abseil-cpp/symbols_arm64_rel_cxx23.def | 29 +- .../abseil-cpp/symbols_x64_dbg.def | 60 +- .../abseil-cpp/symbols_x64_dbg_cxx23.def | 60 +- .../abseil-cpp/symbols_x64_rel.def | 32 +- .../abseil-cpp/symbols_x64_rel_asan.def | 75 +- .../abseil-cpp/symbols_x64_rel_asan_cxx23.def | 68 +- .../abseil-cpp/symbols_x64_rel_cxx23.def | 32 +- .../abseil-cpp/symbols_x86_dbg.def | 60 +- .../abseil-cpp/symbols_x86_dbg_cxx23.def | 60 +- .../abseil-cpp/symbols_x86_rel.def | 32 +- .../abseil-cpp/symbols_x86_rel_cxx23.def | 32 +- deps/v8/third_party/dragonbox/README.v8 | 2 +- deps/v8/third_party/fast_float/README.v8 | 2 +- .../src/include/fast_float/ascii_number.h | 59 +- .../src/include/fast_float/bigint.h | 4 +- .../src/include/fast_float/digit_comparison.h | 4 +- .../src/include/fast_float/float_common.h | 73 +- .../src/include/fast_float/parse_number.h | 31 +- .../v8/third_party/googletest/README.chromium | 2 +- .../highway/src/hwy/contrib/sort/BUILD | 310 ----- deps/v8/third_party/llvm-libc/README.v8 | 2 +- .../llvm-libc/src/hdr/CMakeLists.txt | 16 + .../llvm-libc/src/hdr/glob_macros.h | 27 + .../llvm-libc/src/hdr/sys_file_macros.h | 27 + .../llvm-libc/src/hdr/types/CMakeLists.txt | 42 + .../llvm-libc/src/hdr/types/char8_t.h | 17 + .../llvm-libc/src/hdr/types/glob_t.h | 27 + .../llvm-libc/src/hdr/types/id_t.h | 27 + .../llvm-libc/src/hdr/types/off64_t.h | 27 + .../llvm-libc/src/hdr/types/pthread_attr_t.h | 27 + .../llvm-libc/src/hdr/types/struct_group.h | 27 + .../llvm-libc/src/include/CMakeLists.txt | 41 + .../llvm-libc/src/include/fcntl.yaml | 40 + .../llvm-libc/src/include/glob.yaml | 45 + .../llvm-libc/src/include/grp.yaml | 37 +- .../llvm-libc/src/include/limits.yaml | 2 + .../include/llvm-libc-macros/CMakeLists.txt | 12 + .../llvm-libc-macros/darwin/CMakeLists.txt | 6 + .../llvm-libc-macros/darwin/signal-macros.h | 60 + .../include/llvm-libc-macros/glob-macros.h | 31 + .../include/llvm-libc-macros/limits-macros.h | 4 + .../llvm-libc-macros/linux/CMakeLists.txt | 6 + .../llvm-libc-macros/linux/fcntl-macros.h | 8 + .../llvm-libc-macros/linux/netdb-macros.h | 8 + .../llvm-libc-macros/linux/sys-file-macros.h | 22 + .../linux/sys-resource-macros.h | 4 + .../llvm-libc-macros/linux/unistd-macros.h | 31 +- .../include/llvm-libc-macros/pthread-macros.h | 6 + .../include/llvm-libc-macros/signal-macros.h | 2 + .../llvm-libc-macros/sys-file-macros.h | 21 + .../llvm-libc-macros/sys-mman-macros.h | 6 + .../include/llvm-libc-types/CMakeLists.txt | 95 +- .../src/include/llvm-libc-types/__jmp_buf.h | 2 +- .../src/include/llvm-libc-types/char8_t.h | 4 +- .../llvm-libc-types/cookie_io_functions_t.h | 4 +- .../src/include/llvm-libc-types/fenv_t.h | 7 + .../src/include/llvm-libc-types/glob_t.h | 25 + .../include/llvm-libc-types/pthread_attr_t.h | 4 + .../llvm-libc-types/struct_user_regs_struct.h | 23 + .../llvm-libc-types/x86_64/CMakeLists.txt | 21 + .../x86_64/struct_user_regs_struct.h | 47 + .../llvm-libc/src/include/netdb.yaml | 20 + .../llvm-libc/src/include/pthread.yaml | 46 + .../llvm-libc/src/include/pwd.yaml | 32 + .../llvm-libc/src/include/signal.yaml | 10 + .../llvm-libc/src/include/stdfix.yaml | 56 + .../llvm-libc/src/include/stdio.yaml | 8 + .../llvm-libc/src/include/stdlib.yaml | 20 + .../llvm-libc/src/include/sys/file.yaml | 23 + .../llvm-libc/src/include/sys/mman.yaml | 2 + .../llvm-libc/src/include/sys/resource.yaml | 21 + .../llvm-libc/src/include/sys/stat.yaml | 14 + .../llvm-libc/src/include/sys/user.yaml | 5 + .../llvm-libc/src/include/sys/xattr.yaml | 34 + .../llvm-libc/src/include/unistd.yaml | 136 ++ .../llvm-libc/src/include/wchar.yaml | 15 + .../llvm-libc/src/shared/math/copysignf128.h | 6 - .../llvm-libc/src/shared/math/fabsf128.h | 6 - .../llvm-libc/src/shared/math/fdimf128.h | 6 - .../src/shared/math/fmaximum_mag_numf128.h | 6 - .../src/shared/math/fmaximum_magf128.h | 6 - .../src/shared/math/fmaximum_numf128.h | 6 - .../llvm-libc/src/shared/math/fmaximumf128.h | 6 - .../src/shared/math/fminimum_mag_numf128.h | 6 - .../src/shared/math/fminimum_magf128.h | 6 - .../src/shared/math/fminimum_numf128.h | 6 - .../llvm-libc/src/shared/math/fminimumf128.h | 6 - .../v8/third_party/llvm-libc/src/shared/rpc.h | 71 +- .../src/src/__support/CMakeLists.txt | 12 + .../src/src/__support/CPP/CMakeLists.txt | 20 + .../src/src/__support/CPP/algorithm.h | 19 +- .../llvm-libc/src/src/__support/CPP/span.h | 12 +- .../llvm-libc/src/src/__support/CPP/utility.h | 8 +- .../src/src/__support/CPP/utility/swap.h | 39 + .../llvm-libc/src/src/__support/CPP/vector.h | 309 +++++ .../src/src/__support/FPUtil/CMakeLists.txt | 2 + .../src/src/__support/FPUtil/FEnvImpl.h | 59 + .../FPUtil/NearestIntegerOperations.h | 68 +- .../FPUtil/aarch64/fenv_darwin_impl.h | 136 +- .../src/src/__support/FPUtil/dyadic_float.h | 49 +- .../src/src/__support/FPUtil/float80.h | 5 +- .../llvm-libc/src/src/__support/File/file.cpp | 45 - .../llvm-libc/src/src/__support/File/file.h | 69 +- .../src/src/__support/File/file_mode.h | 152 ++ .../src/__support/File/linux/CMakeLists.txt | 1 + .../src/src/__support/File/linux/file.cpp | 144 +- .../src/src/__support/File/linux/file.h | 6 +- .../src/src/__support/File/linux/file_flags.h | 49 + .../src/src/__support/GPU/allocator.cpp | 17 +- .../src/src/__support/OSUtil/baremetal/io.h | 17 +- .../__support/OSUtil/darwin/CMakeLists.txt | 1 + .../darwin/syscall_wrappers/CMakeLists.txt | 13 + .../darwin/syscall_wrappers/sigprocmask.h | 48 + .../linux/syscall_wrappers/CMakeLists.txt | 266 +++- .../OSUtil/linux/syscall_wrappers/chroot.h | 33 + .../OSUtil/linux/syscall_wrappers/fallocate.h | 49 + .../OSUtil/linux/syscall_wrappers/fchmodat.h | 15 +- .../linux/syscall_wrappers/flistxattr.h | 33 + .../OSUtil/linux/syscall_wrappers/flock.h | 33 + .../OSUtil/linux/syscall_wrappers/getegid.h | 34 + .../OSUtil/linux/syscall_wrappers/getpgid.h | 34 + .../OSUtil/linux/syscall_wrappers/getpid.h | 31 + .../linux/syscall_wrappers/getpriority.h | 34 + .../OSUtil/linux/syscall_wrappers/listxattr.h | 34 + .../linux/syscall_wrappers/llistxattr.h | 34 + .../OSUtil/linux/syscall_wrappers/mknodat.h | 40 + .../linux/syscall_wrappers/posix_fadvise.h | 73 + .../OSUtil/linux/syscall_wrappers/raise.h | 9 +- .../OSUtil/linux/syscall_wrappers/setgid.h | 34 + .../OSUtil/linux/syscall_wrappers/setpgid.h | 34 + .../linux/syscall_wrappers/setpriority.h | 34 + .../OSUtil/linux/syscall_wrappers/setregid.h | 34 + .../OSUtil/linux/syscall_wrappers/setreuid.h | 34 + .../OSUtil/linux/syscall_wrappers/setuid.h | 34 + .../OSUtil/linux/syscall_wrappers/tgkill.h | 34 + .../OSUtil/linux/syscall_wrappers/umask.h | 34 + .../llvm-libc/src/src/__support/big_int.h | 17 +- .../src/src/__support/fixed_point/fx_bits.h | 208 +-- .../llvm-libc/src/src/__support/frac128.h | 21 +- .../llvm-libc/src/src/__support/frac256.h | 90 ++ .../llvm-libc/src/src/__support/frac64.h | 8 + .../src/src/__support/macros/attributes.h | 8 + .../macros/properties/cpu_features.h | 20 + .../src/src/__support/math/CMakeLists.txt | 160 ++- .../llvm-libc/src/src/__support/math/acosf.h | 2 +- .../src/src/__support/math/copysignf128.h | 11 +- .../llvm-libc/src/src/__support/math/cos.h | 12 +- .../llvm-libc/src/src/__support/math/exp10.h | 34 +- .../llvm-libc/src/src/__support/math/exp10f.h | 147 +- .../src/__support/math/exp10f_double_eval.h | 155 +++ .../src/__support/math/exp10f_float_eval.h | 153 ++ .../llvm-libc/src/src/__support/math/exp2.h | 38 +- .../llvm-libc/src/src/__support/math/exp2f.h | 171 +-- .../src/__support/math/exp2f_double_eval.h | 178 +++ .../src/src/__support/math/exp2f_float_eval.h | 96 ++ .../src/__support/math/exp2f_float_utils.h | 107 ++ .../llvm-libc/src/src/__support/math/expf.h | 122 +- .../src/src/__support/math/expf_double_eval.h | 125 ++ .../src/src/__support/math/expf_float_eval.h | 126 ++ .../src/__support/math/expf_integer_eval.h | 21 +- .../src/src/__support/math/fabsf128.h | 11 +- .../src/src/__support/math/fdimf128.h | 11 +- .../src/__support/math/fmaximum_mag_numf128.h | 11 +- .../src/src/__support/math/fmaximum_magf128.h | 11 +- .../src/src/__support/math/fmaximum_numf128.h | 11 +- .../src/src/__support/math/fmaximumf128.h | 11 +- .../src/__support/math/fminimum_mag_numf128.h | 11 +- .../src/src/__support/math/fminimum_magf128.h | 11 +- .../src/src/__support/math/fminimum_numf128.h | 11 +- .../src/src/__support/math/fminimumf128.h | 11 +- .../llvm-libc/src/src/__support/math/pow.h | 813 +++++------ .../src/src/__support/math/pow_accurate_128.h | 375 +++++ .../src/src/__support/math/pow_accurate_256.h | 818 +++++++++++ .../src/src/__support/math/pow_fast.h | 304 ++++ .../src/src/__support/math/pow_utils.h | 661 +++++++++ .../llvm-libc/src/src/__support/math/powf.h | 13 +- .../llvm-libc/src/src/__support/math/round.h | 12 +- .../llvm-libc/src/src/__support/math/roundf.h | 12 +- .../src/src/__support/math/setpayloadsig.h | 2 +- .../src/__support/math/setpayloadsigbf16.h | 2 +- .../src/src/__support/math/setpayloadsigf.h | 2 +- .../src/__support/math/setpayloadsigf128.h | 2 +- .../src/src/__support/math/setpayloadsigf16.h | 2 +- .../src/src/__support/math/setpayloadsigl.h | 2 +- .../llvm-libc/src/src/__support/math/sin.h | 11 +- .../llvm-libc/src/src/__support/math_extras.h | 24 +- .../src/src/__support/mathvec/CMakeLists.txt | 15 +- .../src/src/__support/mathvec/sinf.h | 80 +- .../src/__support/mathvec/trig_reductionf.h | 129 ++ .../__support/mathvec/trig_reductionf_nofma.h | 168 +++ .../src/src/__support/net/CMakeLists.txt | 1 + .../src/src/__support/net/address.cpp | 23 +- .../llvm-libc/src/src/__support/net/address.h | 3 +- .../src/__support/printf_core/CMakeLists.txt | 1 + .../__support/printf_core/char_converter.h | 4 +- .../src/src/__support/printf_core/converter.h | 18 +- .../src/__support/printf_core/core_structs.h | 33 +- .../__support/printf_core/fixed_converter.h | 4 +- .../printf_core/float_dec_converter.h | 55 +- .../printf_core/float_dec_converter_limited.h | 36 +- .../printf_core/float_hex_converter.h | 4 +- .../printf_core/float_inf_nan_converter.h | 4 +- .../src/__support/printf_core/int_converter.h | 4 +- .../{write_modes.def => overflow_modes.def} | 6 +- .../src/src/__support/printf_core/parser.h | 174 +-- .../src/__support/printf_core/printf_main.h | 11 +- .../src/__support/printf_core/ptr_converter.h | 4 +- .../printf_core/strerror_converter.h | 4 +- .../__support/printf_core/string_converter.h | 12 +- .../printf_core/vasprintf_internal.h | 42 +- .../__support/printf_core/vfprintf_internal.h | 9 +- .../printf_core/write_int_converter.h | 4 +- .../src/src/__support/printf_core/writer.h | 293 ++-- .../src/src/__support/pwd/CMakeLists.txt | 44 + .../src/src/__support/pwd/dynamic_buffer.h | 104 ++ .../src/src/__support/pwd/field_tokenizer.h | 69 + .../src/src/__support/pwd/flat_file_db.h | 341 +++++ .../src/src/__support/threads/CMakeLists.txt | 12 + .../__support/threads/linux/CMakeLists.txt | 20 + .../src/__support/threads/linux/aarch64/tcb.h | 45 + .../src/__support/threads/linux/riscv/tcb.h | 45 + .../src/src/__support/threads/linux/tcb.h | 29 + .../src/__support/threads/linux/thread.cpp | 72 +- .../src/__support/threads/linux/x86_64/tcb.h | 55 + .../llvm-libc/src/src/__support/threads/tcb.h | 25 + .../src/src/__support/threads/thread.cpp | 8 +- .../src/src/__support/threads/thread.h | 18 +- .../src/__support/threads/thread_attributes.h | 7 +- .../llvm-libc/src/src/__support/tlsf_table.h | 2 +- .../src/src/__support/wctype/CMakeLists.txt | 1 + .../src/__support/wctype/perfect_hash_map.h | 15 +- .../src/src/__support/wctype_utils.h | 12 + deps/v8/third_party/rapidhash-v8/secret.h | 7 + deps/v8/third_party/zlib/BUILD.gn | 2 - deps/v8/third_party/zlib/chromeconf.h | 3 - .../resources/differential_fuzz_v8.js | 2 + .../js_fuzzer/resources/sandbox.js | 1 + .../test_data/sandbox/load_expected.js | 5 +- deps/v8/tools/debug_helper/BUILD.gn | 1 + deps/v8/tools/metagen/cpp_hier.py | 5 +- deps/v8/tools/wasm/BUILD.gn | 1 + 1513 files changed, 33404 insertions(+), 12800 deletions(-) delete mode 100644 deps/v8/agents/.vpython3 delete mode 100644 deps/v8/agents/agents/builder/agent.json delete mode 100644 deps/v8/agents/agents/builder/config.yaml delete mode 100644 deps/v8/agents/agents/debugger/agent.json delete mode 100644 deps/v8/agents/agents/debugger/config.yaml delete mode 100644 deps/v8/agents/agents/researcher/agent.json delete mode 100644 deps/v8/agents/agents/researcher/config.yaml delete mode 100644 deps/v8/agents/agents/tester/agent.json delete mode 100644 deps/v8/agents/agents/tester/config.yaml delete mode 100644 deps/v8/agents/prompts/common.md delete mode 100644 deps/v8/agents/prompts/templates/README.md delete mode 100644 deps/v8/agents/rules/framework.md delete mode 100755 deps/v8/agents/scripts/install_for_gemini_cli.py delete mode 100644 deps/v8/agents/skills/env-abstraction/SKILL.md delete mode 100644 deps/v8/agents/skills/orchestrator/SKILL.md delete mode 100644 deps/v8/agents/skills/subagent-env-passing/SKILL.md create mode 100644 deps/v8/agents/vpython.toml create mode 100644 deps/v8/agents/vpython.toml.uv.lock create mode 100644 deps/v8/experimental/OWNERS create mode 100644 deps/v8/experimental/README.md create mode 100644 deps/v8/src/debug/debug-block-list.cc create mode 100644 deps/v8/src/debug/debug-block-list.h create mode 100644 deps/v8/src/sandbox/cppheap-pointer-tag.h create mode 100644 deps/v8/test/common/version-utils.h create mode 100644 deps/v8/test/inspector/debugger/function-constructor-anonymous-scopes-expected.txt create mode 100644 deps/v8/test/inspector/debugger/function-constructor-anonymous-scopes.js create mode 100644 deps/v8/test/inspector/runtime/regress-553931056-expected.txt create mode 100644 deps/v8/test/inspector/runtime/regress-553931056.js create mode 100644 deps/v8/test/inspector/runtime/scopes-internal-property-expected.txt create mode 100644 deps/v8/test/inspector/runtime/scopes-internal-property.js create mode 100644 deps/v8/test/intl/regexp-case-equivalence.js create mode 100644 deps/v8/test/intl/regexp-ignore-case-alternatives.js create mode 100644 deps/v8/test/mjsunit/compiler/regress-561186948.js create mode 100644 deps/v8/test/mjsunit/compiler/script-context-specialization.js create mode 100644 deps/v8/test/mjsunit/d8/d8-test-access-checked-interceptor-object.js delete mode 100644 deps/v8/test/mjsunit/d8/d8-test-special-object.js create mode 100644 deps/v8/test/mjsunit/harmony/dynamic-code-brand-checks.js create mode 100644 deps/v8/test/mjsunit/maglev/context-extension-mutability.js create mode 100644 deps/v8/test/mjsunit/maglev/context-inverted-generator3.js create mode 100644 deps/v8/test/mjsunit/maglev/regress-559932543.js create mode 100644 deps/v8/test/mjsunit/maglev/regress-560408014.js create mode 100644 deps/v8/test/mjsunit/maglev/script-context-specialization.js create mode 100644 deps/v8/test/mjsunit/maglev/static-private-brand-inverted-generator.js create mode 100644 deps/v8/test/mjsunit/regress/regress-506178478.js create mode 100644 deps/v8/test/mjsunit/regress/regress-519652102.js create mode 100644 deps/v8/test/mjsunit/regress/regress-525472602.js create mode 100644 deps/v8/test/mjsunit/regress/regress-558568713.js create mode 100644 deps/v8/test/mjsunit/regress/regress-559266116.js create mode 100644 deps/v8/test/mjsunit/regress/regress-559408989.js create mode 100644 deps/v8/test/mjsunit/regress/regress-559536931.js create mode 100644 deps/v8/test/mjsunit/regress/regress-560730175.js create mode 100644 deps/v8/test/mjsunit/regress/regress-561116893.js create mode 100644 deps/v8/test/mjsunit/regress/regress-562529689.js create mode 100644 deps/v8/test/mjsunit/regress/regress-562557292.js create mode 100644 deps/v8/test/mjsunit/regress/regress-563764306.js create mode 100644 deps/v8/test/mjsunit/regress/regress-564625827.js create mode 100644 deps/v8/test/mjsunit/regress/regress-565836459.js create mode 100644 deps/v8/test/mjsunit/regress/regress-566243375.js create mode 100644 deps/v8/test/mjsunit/regress/regress-crbug-388320179.js create mode 100644 deps/v8/test/mjsunit/regress/regress-crbug-562108903.js create mode 100644 deps/v8/test/mjsunit/regress/regress-derived-ctor-tdz-stack-trace.js create mode 100644 deps/v8/test/mjsunit/regress/regress-escaped-get-set-asi.js create mode 100644 deps/v8/test/mjsunit/regress/regress-json-escaped-key-transition.js create mode 100644 deps/v8/test/mjsunit/regress/regress-maglev-mul-minus-zero.js create mode 100644 deps/v8/test/mjsunit/regress/regress-regexp-lookbehind-sort-alternatives.js create mode 100644 deps/v8/test/mjsunit/regress/regression-513327211.js create mode 100644 deps/v8/test/mjsunit/regress/regression-514440066.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-523591366.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-557846268.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-561660149.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-561662099.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-562655126.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-563427048-2.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-563427048-3.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-563427048.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-565565747.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-565847635.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-566973959.js create mode 100644 deps/v8/test/mjsunit/regress/wasm/regress-wasmfx-unreachable-resume.js create mode 100644 deps/v8/test/mjsunit/sandbox/regress-561387542.js create mode 100644 deps/v8/test/mjsunit/sandbox/regress-562788806.js create mode 100644 deps/v8/test/mjsunit/sandbox/regress-565797753.js create mode 100644 deps/v8/test/mjsunit/sandbox/regress/regress-532513886.js create mode 100644 deps/v8/test/mjsunit/sandbox/regress/regress-560282287-2.js create mode 100644 deps/v8/test/mjsunit/sandbox/regress/regress-560282287.js create mode 100644 deps/v8/test/mjsunit/sandbox/regress/regress-562870022.js create mode 100644 deps/v8/test/mjsunit/turbolev/float64-mul-range.js create mode 100644 deps/v8/test/mjsunit/turbolev/instanceof-bound-function-graph-optimizer-map-check.js create mode 100644 deps/v8/test/mjsunit/turbolev/instanceof-graph-optimizer-map-check.js create mode 100644 deps/v8/test/mjsunit/turbolev/update-jsarray-length.js create mode 100644 deps/v8/test/mjsunit/turboshaft/typer-pow-matches-runtime.js create mode 100644 deps/v8/test/mjsunit/tzoffset-fractional-los-angeles.js create mode 100644 deps/v8/test/mjsunit/wasm/gc-js-interop-private-symbols.js create mode 100644 deps/v8/test/mjsunit/wasm/regress-561849345.js create mode 100644 deps/v8/test/mjsunit/wasm/regress-564326756.js create mode 100644 deps/v8/test/mjsunit/wasm/simd-int-narrowing.js delete mode 100644 deps/v8/test/test262/.lint-vpython3 create mode 100644 deps/v8/test/test262/lint-vpython.toml create mode 100644 deps/v8/test/test262/lint-vpython.toml.uv.lock create mode 100644 deps/v8/test/unittests/compiler/turboshaft/instruction-selection-normalization-reducer-unittest.cc create mode 100644 deps/v8/test/unittests/debug/debug-block-list-unittest.cc create mode 100644 deps/v8/test/unittests/profiler/heap-snapshot-scopes-unittest.cc create mode 100644 deps/v8/test/unittests/wasm/wasm-disassembler-unittest-fp16.wasm.inc create mode 100644 deps/v8/test/unittests/wasm/wasm-disassembler-unittest-fp16.wat.inc delete mode 100644 deps/v8/third_party/highway/src/hwy/contrib/sort/BUILD create mode 100644 deps/v8/third_party/llvm-libc/src/hdr/glob_macros.h create mode 100644 deps/v8/third_party/llvm-libc/src/hdr/sys_file_macros.h create mode 100644 deps/v8/third_party/llvm-libc/src/hdr/types/glob_t.h create mode 100644 deps/v8/third_party/llvm-libc/src/hdr/types/id_t.h create mode 100644 deps/v8/third_party/llvm-libc/src/hdr/types/off64_t.h create mode 100644 deps/v8/third_party/llvm-libc/src/hdr/types/pthread_attr_t.h create mode 100644 deps/v8/third_party/llvm-libc/src/hdr/types/struct_group.h create mode 100644 deps/v8/third_party/llvm-libc/src/include/glob.yaml create mode 100644 deps/v8/third_party/llvm-libc/src/include/llvm-libc-macros/darwin/signal-macros.h create mode 100644 deps/v8/third_party/llvm-libc/src/include/llvm-libc-macros/glob-macros.h create mode 100644 deps/v8/third_party/llvm-libc/src/include/llvm-libc-macros/linux/sys-file-macros.h create mode 100644 deps/v8/third_party/llvm-libc/src/include/llvm-libc-macros/sys-file-macros.h create mode 100644 deps/v8/third_party/llvm-libc/src/include/llvm-libc-types/glob_t.h create mode 100644 deps/v8/third_party/llvm-libc/src/include/llvm-libc-types/struct_user_regs_struct.h create mode 100644 deps/v8/third_party/llvm-libc/src/include/llvm-libc-types/x86_64/CMakeLists.txt create mode 100644 deps/v8/third_party/llvm-libc/src/include/llvm-libc-types/x86_64/struct_user_regs_struct.h create mode 100644 deps/v8/third_party/llvm-libc/src/include/sys/file.yaml create mode 100644 deps/v8/third_party/llvm-libc/src/include/sys/user.yaml create mode 100644 deps/v8/third_party/llvm-libc/src/include/sys/xattr.yaml create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/CPP/utility/swap.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/CPP/vector.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/File/file_mode.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/File/linux/file_flags.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/darwin/syscall_wrappers/CMakeLists.txt create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/darwin/syscall_wrappers/sigprocmask.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/chroot.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/fallocate.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/flistxattr.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/flock.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/getegid.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/getpgid.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/getpid.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/getpriority.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/listxattr.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/llistxattr.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/mknodat.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/posix_fadvise.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/setgid.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/setpgid.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/setpriority.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/setregid.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/setreuid.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/setuid.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/tgkill.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/OSUtil/linux/syscall_wrappers/umask.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/frac256.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/exp10f_double_eval.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/exp10f_float_eval.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/exp2f_double_eval.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/exp2f_float_eval.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/exp2f_float_utils.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/expf_double_eval.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/expf_float_eval.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/pow_accurate_128.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/pow_accurate_256.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/pow_fast.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/math/pow_utils.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/mathvec/trig_reductionf.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/mathvec/trig_reductionf_nofma.h rename deps/v8/third_party/llvm-libc/src/src/__support/printf_core/{write_modes.def => overflow_modes.def} (70%) create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/pwd/CMakeLists.txt create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/pwd/dynamic_buffer.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/pwd/field_tokenizer.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/pwd/flat_file_db.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/threads/linux/aarch64/tcb.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/threads/linux/riscv/tcb.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/threads/linux/tcb.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/threads/linux/x86_64/tcb.h create mode 100644 deps/v8/third_party/llvm-libc/src/src/__support/threads/tcb.h diff --git a/deps/v8/AUTHORS b/deps/v8/AUTHORS index ee6d6af3a38d..31ac08aa8ddb 100644 --- a/deps/v8/AUTHORS +++ b/deps/v8/AUTHORS @@ -45,6 +45,7 @@ CodeWeavers, Inc. <*@codeweavers.com> Alibaba, Inc. <*@alibaba-inc.com> SiFive, Inc. <*@sifive.com> Island Technology, Inc. <*@island.io> +Xperi Corporation <*@xperi.com> Aapo Alasuutari Aaron Bieber @@ -105,6 +106,7 @@ Chris Nardi Christopher A. Taylor Christopher Nady Colin Ihrig +Colin McDonnell Cong Zuo Craig Schlenter Cristiano Moraes @@ -300,6 +302,7 @@ Sam James Samuel Attard Sébastien Doeraene Seo Sanghyeon +Seongjin Kim Sergey Markelov Shawn Anastasio Shawn Presser @@ -310,6 +313,7 @@ Stefan Penner Stefan Stojanovic Stephan Hartmann Stephen Belanger +Stephen Jayna Steven R. Loomis Sylvestre Ledru Takeshi Yoneda @@ -355,6 +359,7 @@ Yong Wang Youfeng Hao Yu Yin Yujie Wang +Yun Jiyun Yuri Iozzelli Yuri Gaevsky Yusif Khudhur diff --git a/deps/v8/BUILD.bazel b/deps/v8/BUILD.bazel index 2350f14126e5..914fe144311e 100644 --- a/deps/v8/BUILD.bazel +++ b/deps/v8/BUILD.bazel @@ -183,7 +183,7 @@ v8_flag(name = "v8_enable_experimental_tq_to_tsa") # off, the metagen action is not part of the build graph. v8_flag( name = "v8_use_metagen_instance_types", - default = False, + default = True, ) v8_flag( @@ -797,6 +797,7 @@ filegroup( "include/v8-maybe.h", "include/v8-memory-span.h", "include/v8-message.h", + "include/v8-metrics.h", "include/v8-microtask.h", "include/v8-microtask-queue.h", "include/v8-object.h", @@ -815,6 +816,7 @@ filegroup( "include/v8-traced-handle.h", "include/v8-typed-array.h", "include/v8-unwinder.h", + "include/v8-unwinder-state.h", "include/v8-util.h", "include/v8-value.h", "include/v8-value-serializer.h", @@ -1652,6 +1654,8 @@ filegroup( "src/date/dateparser-inl.h", "src/debug/debug.cc", "src/debug/debug.h", + "src/debug/debug-block-list.cc", + "src/debug/debug-block-list.h", "src/debug/debug-coverage.cc", "src/debug/debug-coverage.h", "src/debug/debug-evaluate.cc", @@ -2608,6 +2612,7 @@ filegroup( "src/sandbox/external-pointer-table-inl.h", "src/sandbox/cppheap-pointer.h", "src/sandbox/cppheap-pointer-inl.h", + "src/sandbox/cppheap-pointer-tag.h", "src/sandbox/cppheap-pointer-table.cc", "src/sandbox/cppheap-pointer-table.h", "src/sandbox/cppheap-pointer-table-inl.h", diff --git a/deps/v8/BUILD.gn b/deps/v8/BUILD.gn index 78035a8caf95..1df3d4e31bcc 100644 --- a/deps/v8/BUILD.gn +++ b/deps/v8/BUILD.gn @@ -38,10 +38,6 @@ if (is_ios) { import("//build/config/apple/mobile_config.gni") # For `target_platform`. } -if (!build_with_v8_embedder && !(defined(build_with_node) && build_with_node)) { - import("//third_party/partition_alloc/partition_alloc.gni") -} - # For faster Windows builds. See https://crbug.com/v8/8475. emit_builtins_as_inline_asm = is_win && is_clang @@ -204,6 +200,10 @@ declare_args() { # to when v8_enable_static_roots is enabled. v8_enable_static_roots_generation = false + # Enables a separate TdzHole root for Temporal Dead Zone initialization and + # checks instead of aliasing TheHole. + v8_enable_tdz_hole = true + # Enable code-generation-time checking of types in the CodeStubAssembler. v8_enable_verify_csa = false @@ -885,6 +885,10 @@ assert( !v8_enable_memory_corruption_api || !is_lsan, "The Memory Corruption API cannot be enabled together with LSan as both attach to the d8 process via ptrace") +# ASan sandbox crash filters aren't wired up properly in component builds. +assert(!v8_enable_memory_corruption_api || !is_component_build, + "The Memory Corruption API cannot be enabled in a component build") + assert(!v8_enable_sandbox_hardware_support || v8_enable_sandbox, "The sandbox must be enabled to enable sandbox hardware support") @@ -1623,6 +1627,9 @@ config("features") { if (v8_enable_static_roots_generation) { defines += [ "V8_STATIC_ROOTS_GENERATION" ] } + if (v8_enable_tdz_hole) { + defines += [ "V8_ENABLE_TDZ_HOLE" ] + } if (v8_use_zlib) { defines += [ "V8_USE_ZLIB" ] } @@ -1677,12 +1684,6 @@ config("features") { if (v8_function_arguments_caller_are_own_props) { defines += [ "V8_FUNCTION_ARGUMENTS_CALLER_ARE_OWN_PROPS" ] } - if (!build_with_v8_embedder && - !(defined(build_with_node) && build_with_node)) { - if (enable_user_space_zero_segment) { - defines += [ "PA_ENABLE_USER_SPACE_ZERO_SEGMENT" ] - } - } } config("toolchain") { @@ -2529,6 +2530,12 @@ if (v8_use_metagen_instance_types) { "tools/metagen/instance_types.py", "tools/metagen/metagen.py", _metagen_driver_file, + + # The driver's aggregate header. It declares no classes, so + # metagen records no fact from it and it is absent from the + # depfile, but its include list determines which headers the + # harvest parses. PRESUBMIT.py checks that the list is complete. + "src/objects/all-objects.h", "$root_out_dir/v8_build_config.json", # Proxy for the whole builtin-header directory, which has no @@ -2884,6 +2891,7 @@ v8_cluster_source_set("torque_generated_initializers") { ":generate_bytecode_builtins_list", ":run_torque", ":v8_base_without_compiler", + ":v8_internal_headers", ":v8_maybe_temporal", ":v8_tracing", ] @@ -3565,6 +3573,7 @@ v8_cluster_source_set("v8_initializers") { deps = [ ":torque_generated_initializers", ":v8_base_without_compiler", + ":v8_internal_headers", ":v8_shared_internal_headers", ":v8_tracing", ] @@ -3743,6 +3752,7 @@ v8_source_set("v8_init") { deps = [ ":v8_base_without_compiler", ":v8_initializers", + ":v8_internal_headers", ":v8_maybe_temporal", ":v8_tracing", ] @@ -3825,6 +3835,7 @@ v8_header_set("v8_headers") { "include/v8-maybe.h", "include/v8-memory-span.h", "include/v8-message.h", + "include/v8-metrics.h", "include/v8-microtask-queue.h", "include/v8-microtask.h", "include/v8-object.h", @@ -3840,9 +3851,9 @@ v8_header_set("v8_headers") { "include/v8-snapshot.h", "include/v8-statistics.h", "include/v8-template.h", - "include/v8-trace-categories.h", "include/v8-traced-handle.h", "include/v8-typed-array.h", + "include/v8-unwinder-state.h", "include/v8-unwinder.h", "include/v8-util.h", "include/v8-value-serializer.h", @@ -3864,7 +3875,6 @@ v8_header_set("v8_headers") { deps = [ ":cppgc_headers", - ":v8_tracing", ":v8_version", ] } @@ -4306,6 +4316,7 @@ v8_header_set("v8_internal_headers") { "src/date/date.h", "src/date/dateparser-inl.h", "src/date/dateparser.h", + "src/debug/debug-block-list.h", "src/debug/debug-coverage.h", "src/debug/debug-evaluate.h", "src/debug/debug-frames.h", @@ -4908,6 +4919,7 @@ v8_header_set("v8_internal_headers") { "src/sandbox/cppheap-pointer-inl.h", "src/sandbox/cppheap-pointer-table-inl.h", "src/sandbox/cppheap-pointer-table.h", + "src/sandbox/cppheap-pointer-tag.h", "src/sandbox/cppheap-pointer.h", "src/sandbox/external-entity-table-inl.h", "src/sandbox/external-entity-table.h", @@ -5473,6 +5485,7 @@ v8_header_set("v8_internal_headers") { "src/codegen/mips64/assembler-mips64-inl.h", "src/codegen/mips64/assembler-mips64.h", "src/codegen/mips64/constants-mips64.h", + "src/codegen/mips64/interface-descriptors-mips64-inl.h", "src/codegen/mips64/macro-assembler-mips64.h", "src/codegen/mips64/register-mips64.h", "src/codegen/mips64/reglist-mips64.h", @@ -5494,6 +5507,7 @@ v8_header_set("v8_internal_headers") { "src/codegen/loong64/assembler-loong64-inl.h", "src/codegen/loong64/assembler-loong64.h", "src/codegen/loong64/constants-loong64.h", + "src/codegen/loong64/interface-descriptors-loong64-inl.h", "src/codegen/loong64/macro-assembler-loong64.h", "src/codegen/loong64/register-loong64.h", "src/codegen/loong64/reglist-loong64.h", @@ -5686,6 +5700,36 @@ v8_header_set("v8_internal_headers") { } } + if (is_win && v8_enable_etw_stack_walking) { + sources += [ + "src/diagnostics/etw-debug-win.h", + "src/diagnostics/etw-isolate-capture-state-monitor-win.h", + "src/diagnostics/etw-isolate-load-script-data-win.h", + "src/diagnostics/etw-isolate-operations-win.h", + "src/diagnostics/etw-jit-metadata-win.h", + "src/diagnostics/etw-jit-win.h", + ] + } + + if (v8_enable_generated_code_validator) { + sources += [ "src/sandbox/generated-code-validator.h" ] + } + + if (v8_fuzzilli) { + sources += [ "src/fuzzilli/fuzzilli.h" ] + } + + if (v8_dumpling) { + sources += [ + "src/dumpling/dumpling-manager.h", + "src/dumpling/object-dumping.h", + ] + } + + if (v8_enable_vtunetracemark && (is_linux || is_chromeos || is_win)) { + sources += [ "src/extensions/vtunedomain-support-extension.h" ] + } + frameworks = [] # BrowserEngineKit only exists on iOS itself, not on tvOS and other @@ -5908,7 +5952,6 @@ if (!v8_enable_maglev) { "src/maglev/maglev-range-verification.cc", "src/maglev/maglev-truncation.cc", "src/maglev/turbolev-escape-analysis.cc", - "src/maglev/turbolev-escape-analysis.h", ] } @@ -6086,6 +6129,9 @@ v8_cluster_source_set("v8_compiler_for_mksnapshot_source_set") { v8_cluster_source_set("v8_compiler") { visibility = [ ":*" ] # Only targets in this file can depend on this. + # Do not publicize any header to remove build dependency. + public = [] + if (v8_enable_turbofan) { sources = v8_compiler_sources } else { @@ -6150,6 +6196,9 @@ v8_cluster_source_set("v8_base_without_compiler") { "tools/gcmole/:*", ] + # Do not publicize any header to remove build dependency. + public = [] + # Split static libraries on windows into two. split_count = 2 @@ -6263,6 +6312,7 @@ v8_cluster_source_set("v8_base_without_compiler") { "src/compiler/linkage.cc", "src/date/date.cc", "src/date/dateparser.cc", + "src/debug/debug-block-list.cc", "src/debug/debug-coverage.cc", "src/debug/debug-evaluate.cc", "src/debug/debug-frames.cc", @@ -6970,7 +7020,6 @@ v8_cluster_source_set("v8_base_without_compiler") { "src/codegen/mips64/assembler-mips64.cc", "src/codegen/mips64/constants-mips64.cc", "src/codegen/mips64/cpu-mips64.cc", - "src/codegen/mips64/interface-descriptors-mips64-inl.h", "src/codegen/mips64/macro-assembler-mips64.cc", "src/deoptimizer/mips64/deoptimizer-mips64.cc", "src/diagnostics/mips64/disasm-mips64.cc", @@ -6985,7 +7034,6 @@ v8_cluster_source_set("v8_base_without_compiler") { "src/codegen/loong64/assembler-loong64.cc", "src/codegen/loong64/constants-loong64.cc", "src/codegen/loong64/cpu-loong64.cc", - "src/codegen/loong64/interface-descriptors-loong64-inl.h", "src/codegen/loong64/macro-assembler-loong64.cc", "src/deoptimizer/loong64/deoptimizer-loong64.cc", "src/diagnostics/loong64/disasm-loong64.cc", @@ -7119,23 +7167,15 @@ v8_cluster_source_set("v8_base_without_compiler") { } # Architecture independent but platform-specific sources - if (is_win) { - if (v8_enable_etw_stack_walking) { - sources += [ - "src/diagnostics/etw-debug-win.cc", - "src/diagnostics/etw-debug-win.h", - "src/diagnostics/etw-isolate-capture-state-monitor-win.cc", - "src/diagnostics/etw-isolate-capture-state-monitor-win.h", - "src/diagnostics/etw-isolate-load-script-data-win.cc", - "src/diagnostics/etw-isolate-load-script-data-win.h", - "src/diagnostics/etw-isolate-operations-win.cc", - "src/diagnostics/etw-isolate-operations-win.h", - "src/diagnostics/etw-jit-metadata-win.cc", - "src/diagnostics/etw-jit-metadata-win.h", - "src/diagnostics/etw-jit-win.cc", - "src/diagnostics/etw-jit-win.h", - ] - } + if (is_win && v8_enable_etw_stack_walking) { + sources += [ + "src/diagnostics/etw-debug-win.cc", + "src/diagnostics/etw-isolate-capture-state-monitor-win.cc", + "src/diagnostics/etw-isolate-load-script-data-win.cc", + "src/diagnostics/etw-isolate-operations-win.cc", + "src/diagnostics/etw-jit-metadata-win.cc", + "src/diagnostics/etw-jit-win.cc", + ] } configs = [ @@ -7160,10 +7200,7 @@ v8_cluster_source_set("v8_base_without_compiler") { ] if (v8_enable_generated_code_validator) { - sources += [ - "src/sandbox/generated-code-validator.cc", - "src/sandbox/generated-code-validator.h", - ] + sources += [ "src/sandbox/generated-code-validator.cc" ] if (v8_current_cpu == "x64") { deps += [ "//third_party/fadec" ] sources += [ "src/sandbox/generated-code-validator-x64.cc" ] @@ -7188,19 +7225,14 @@ v8_cluster_source_set("v8_base_without_compiler") { } if (v8_fuzzilli) { - sources += [ - "src/fuzzilli/fuzzilli.cc", - "src/fuzzilli/fuzzilli.h", - ] + sources += [ "src/fuzzilli/fuzzilli.cc" ] public_deps += [ ":fuzzilli_cov" ] } if (v8_dumpling) { sources += [ "src/dumpling/dumpling-manager.cc", - "src/dumpling/dumpling-manager.h", "src/dumpling/object-dumping.cc", - "src/dumpling/object-dumping.h", ] } @@ -7266,10 +7298,7 @@ v8_cluster_source_set("v8_base_without_compiler") { } if (v8_enable_vtunetracemark && (is_linux || is_chromeos || is_win)) { - sources += [ - "src/extensions/vtunedomain-support-extension.cc", - "src/extensions/vtunedomain-support-extension.h", - ] + sources += [ "src/extensions/vtunedomain-support-extension.cc" ] deps += [ "third_party/vtune:v8_vtune_trace_mark" ] } } @@ -7751,11 +7780,22 @@ v8_component("v8_libbase") { # TODO(infra): Add support for qnx, freebsd, openbsd, netbsd, and solaris. } -v8_component("v8_libplatform") { +v8_header_set("v8_libplatform_headers") { sources = [ "include/libplatform/libplatform-export.h", "include/libplatform/libplatform.h", "include/libplatform/v8-tracing.h", + ] + + configs = [ ":internal_config_base" ] + + public_configs = [ ":libplatform_config" ] + + deps = [ ":v8_config_headers" ] +} + +v8_component("v8_libplatform") { + sources = [ "src/libplatform/default-foreground-task-runner.cc", "src/libplatform/default-foreground-task-runner.h", "src/libplatform/default-job.cc", @@ -7792,7 +7832,7 @@ v8_component("v8_libplatform") { public_configs = [ ":libplatform_config" ] - public_deps = [] + public_deps = [ ":v8_libplatform_headers" ] deps = [ ":v8_config_headers", @@ -7844,6 +7884,7 @@ v8_source_set("fuzzer_support") { public_deps = [ ":v8", + ":v8_internal_headers", ":v8_libbase", ":v8_libplatform", ":v8_maybe_icu", @@ -8009,7 +8050,7 @@ v8_header_set("cppgc_headers") { deps = [ ":v8_libbase", - ":v8_libplatform", + ":v8_libplatform_headers", ] if (current_os == "zos" && is_component_build) { @@ -8151,6 +8192,7 @@ v8_cluster_source_set("cppgc_base") { if (v8_use_perfetto) { sources += [ + "include/v8-trace-categories.h", "src/tracing/perfetto-sdk.h", "src/tracing/trace-categories.cc", "src/tracing/trace-categories.h", @@ -8219,6 +8261,7 @@ if (v8_enable_webassembly) { v8_static_library("wee8") { deps = [ ":v8_base", + ":v8_internal_headers", ":v8_libbase", ":v8_libplatform", ":v8_shared_internal_headers", @@ -8306,6 +8349,7 @@ if (current_toolchain == v8_snapshot_toolchain) { ":v8_base_without_compiler", ":v8_compiler_for_mksnapshot", ":v8_init", + ":v8_internal_headers", ":v8_libbase", ":v8_libplatform", ":v8_maybe_icu", @@ -8655,11 +8699,19 @@ if (is_component_build) { v8_component("v8") { sources = [ "src/utils/v8dll-main.cc" ] - public_deps = [ + deps = [ ":v8_base", ":v8_snapshot", ] + public_deps = [ + ":cppgc_headers", + ":v8_abseil", + ":v8_headers", + ":v8_libplatform", + "src/inspector:inspector_headers", + ] + configs = [ ":internal_config" ] v8_add_configs += [ "//build/config/compiler:thinlto_optimize_max" ] v8_remove_configs += [ "//build/config/compiler:thinlto_optimize_default" ] @@ -8673,11 +8725,14 @@ if (is_component_build) { sources = [ "src/utils/v8dll-main.cc" ] public_deps = [ + ":cppgc_base", ":torque_base", ":torque_ls_base", ":v8_base", ":v8_headers", + ":v8_internal_headers", ":v8_snapshot", + "src/inspector:inspector_headers", ] if (v8_enable_turbofan) { @@ -8691,10 +8746,14 @@ if (is_component_build) { } v8_component("cppgc") { - public_deps = [ ":cppgc_base" ] + deps = [ ":cppgc_base" ] + public_deps = [ + ":cppgc_headers", + ":v8_libplatform", + ] if (!cppgc_is_standalone) { - deps = [ ":v8" ] + deps += [ ":v8" ] } configs = [] @@ -8722,10 +8781,17 @@ if (is_component_build) { } } else { group("v8") { - public_deps = [ + deps = [ ":v8_base", ":v8_snapshot", ] + public_deps = [ + ":cppgc_headers", + ":v8_abseil", + ":v8_headers", + ":v8_libplatform", + "src/inspector:inspector_headers", + ] public_configs = [ ":external_config" ] } @@ -8734,10 +8800,14 @@ if (is_component_build) { testonly = true public_deps = [ + ":cppgc_base", ":torque_base", ":torque_ls_base", ":v8_base", + ":v8_headers", + ":v8_internal_headers", ":v8_snapshot", + "src/inspector:inspector_headers", ] if (v8_enable_turbofan) { @@ -8749,10 +8819,14 @@ if (is_component_build) { } group("cppgc") { - public_deps = [ ":cppgc_base" ] + deps = [ ":cppgc_base" ] + public_deps = [ + ":cppgc_headers", + ":v8_libplatform", + ] if (!cppgc_is_standalone) { - deps = [ ":v8" ] + deps += [ ":v8" ] } public_configs = [ ":external_config" ] @@ -8807,6 +8881,7 @@ v8_executable("d8") { deps = [ ":v8", + ":v8_internal_headers", ":v8_libbase", ":v8_libplatform", ":v8_simdutf", diff --git a/deps/v8/DEPS b/deps/v8/DEPS index 67ee185a5afd..9547d0667a57 100644 --- a/deps/v8/DEPS +++ b/deps/v8/DEPS @@ -99,24 +99,24 @@ vars = { 'chromium_jetstream_git': 'https://chromium.googlesource.com/external/github.com/WebKit/JetStream.git', # GN CIPD package version. - 'gn_version': 'git_revision:a99d46a9d04c770d6bb87387058e1d7b151758ce', + 'gn_version': 'git_revision:127dd2a6d582528d6d61c4d838dc17385ef31abd', # ninja CIPD package version # https://chrome-infra-packages.appspot.com/p/infra/3pp/tools/ninja 'ninja_version': 'version:3@1.12.1.chromium.4', # siso CIPD package version - 'siso_version': 'git_revision:efbbe7f1892211b5e9512576843a3c247b6a6d7c', + 'siso_version': 'git_revision:22353054fea20f637c8fa302a90daf9e2cc10497', # Three lines of non-changing comments so that # the commit queue can handle CLs rolling Fuchsia sdk # and whatever else without interference from each other. - 'fuchsia_version': 'version:33.20260824.1.1', + 'fuchsia_version': 'version:33.20260915.5.1', # Three lines of non-changing comments so that # the commit queue can handle CLs rolling partition_alloc_version # and whatever else without interference from each other. - 'partition_alloc_version': 'c029851c21b7e1154fa3964e08c97710adc92cc7', + 'partition_alloc_version': 'a0f30e381c6e132215a0c8d809fd08ff4cdad244', # Three lines of non-changing comments so that # the commit queue can handle CLs rolling android_sdk_build-tools_version @@ -145,11 +145,11 @@ vars = { # Three lines of non-changing comments so that # the commit queue can handle CLs rolling agents-internal # and whatever else without interference from each other. - 'agents_internal_revision': 'd2d5adf5a243d90aba25902a46fc32e7a4f5ab99', + 'agents_internal_revision': '79ff29c61f3fcfd51da0a5be8579b01b4f6f61b3', # Three lines of non-changing comments so that # the commit queue can handle CLs rolling agents-public # and whatever else without interference from each other. - 'agents_public_revision': '4e0a8bacdfcc6b6303540aa466b05a508f349486', + 'agents_public_revision': '865684c4f7092e4ab05adcd3fcf068672ff28d27', } deps = { @@ -161,9 +161,9 @@ deps = { 'condition': 'checkout_agents_internal', }, 'build': - Var('chromium_url') + '/chromium/src/build.git' + '@' + '8ca8a372cab9ff143072204053d30fbc2c17bd7a', + Var('chromium_url') + '/chromium/src/build.git' + '@' + 'bc0661cf80717e97e1b6868396f61f7f94f2d04a', 'buildtools': - Var('chromium_url') + '/chromium/src/buildtools.git' + '@' + '6f6a5dbf04b734214f3b1f386567d101ec9d607e', + Var('chromium_url') + '/chromium/src/buildtools.git' + '@' + 'c202b4a9dac30e789ed6e3b2354efa94357a56f3', 'buildtools/linux64': { 'packages': [ { @@ -218,7 +218,7 @@ deps = { 'test/mozilla/data': Var('chromium_url') + '/v8/deps/third_party/mozilla-tests.git' + '@' + 'f6c578a10ea707b1a8ab0b88943fe5115ce2b9be', 'test/test262/data': - Var('chromium_url') + '/external/github.com/tc39/test262.git' + '@' + '72faf8ec1445c55149615e8b35187830783aba1a', + Var('chromium_url') + '/external/github.com/tc39/test262.git' + '@' + '7ab7fafa0003f73fc85c1b95d88094d33f7eb8bd', 'third_party/android_platform': { 'url': Var('chromium_url') + '/chromium/src/third_party/android_platform.git' + '@' + 'e3919359f2387399042d31401817db4a02d756ec', 'condition': 'checkout_android', @@ -260,7 +260,7 @@ deps = { 'dep_type': 'cipd', }, 'third_party/catapult': { - 'url': Var('chromium_url') + '/catapult.git' + '@' + '50c971fc0958d8c1fb0adcc97f41b90042fa7c87', + 'url': Var('chromium_url') + '/catapult.git' + '@' + 'e39ded11ffe971d360160c9d185a7e0ef98fb9a3', 'condition': 'checkout_android', }, 'third_party/clang-format/script': @@ -278,15 +278,15 @@ deps = { 'condition': 'checkout_android', }, 'third_party/depot_tools': - Var('chromium_url') + '/chromium/tools/depot_tools.git' + '@' + 'cb70c994a656601dc6a0d423f49ff57503bd70bc', + Var('chromium_url') + '/chromium/tools/depot_tools.git' + '@' + '0306e4682b4ac35287c726fa35a983157a625902', 'third_party/dragonbox/src': Var('chromium_url') + '/external/github.com/jk-jeon/dragonbox.git' + '@' + 'beeeef91cf6fef89a4d4ba5e95d47ca64ccb3a44', 'third_party/fp16/src': Var('chromium_url') + '/external/github.com/Maratyszcza/FP16.git' + '@' + '782eea126dc5c755827be751a099eb01826175cf', 'third_party/fast_float/src': - Var('chromium_url') + '/external/github.com/fastfloat/fast_float.git' + '@' + '34164f547b7df3f5d794ff67e9f885c36819ebfc', + Var('chromium_url') + '/external/github.com/fastfloat/fast_float.git' + '@' + 'b0ab987b3dfdde13fa1915f65ef2a5c068d9208c', 'third_party/fuchsia-gn-sdk': { - 'url': Var('chromium_url') + '/chromium/src/third_party/fuchsia-gn-sdk.git' + '@' + '740d23bfe5b137c2c387a4b421f120f6126845de', + 'url': Var('chromium_url') + '/chromium/src/third_party/fuchsia-gn-sdk.git' + '@' + '019c2f57c0f022f63d4d56b4e6427d4f4ea91daa', 'condition': 'checkout_fuchsia', }, 'third_party/simdutf': @@ -310,15 +310,15 @@ deps = { 'url': Var('chromium_url') + '/external/github.com/google/benchmark.git' + '@' + '8abf1e701fbd88c8170f48fe0558247e2e5f8e7d', }, 'third_party/fuzztest': - Var('chromium_url') + '/chromium/src/third_party/fuzztest.git' + '@' + 'f0f143db954fb311d4e7ba39972d2dab9ba47e2a', + Var('chromium_url') + '/chromium/src/third_party/fuzztest.git' + '@' + '55970ac2863f6b740d3e8247ac0ec48e7acb2113', 'third_party/fuzztest/src': - Var('chromium_url') + '/external/github.com/google/fuzztest.git' + '@' + '846bda6f291e26b7f8fb33c8de23796129bffd12', + Var('chromium_url') + '/external/github.com/google/fuzztest.git' + '@' + '7a8e9056de2a4f745082a4b3861a67ada47ced36', 'third_party/googletest/src': Var('chromium_url') + '/external/github.com/google/googletest.git' + '@' + '4fe3307fb2d9f86d19777c7eb0e4809e9694dde7', 'third_party/highway/src': Var('chromium_url') + '/external/github.com/google/highway.git' + '@' + '2607d3b5b0113992fe84d3848859eae13b3b52c1', 'third_party/icu': - Var('chromium_url') + '/chromium/deps/icu.git' + '@' + '6ebb40c594776cc2c21ea14df85a2a89a328b364', + Var('chromium_url') + '/chromium/deps/icu.git' + '@' + '5aa526207171ecadf31597f0980a7b7ad8872f33', 'third_party/instrumented_libs': { 'url': Var('chromium_url') + '/chromium/third_party/instrumented_libraries.git' + '@' + 'd15c278eed5d38d9acf2d8054cf37baba93cef8e', 'condition': 'checkout_instrumented_libraries', @@ -336,178 +336,178 @@ deps = { 'third_party/libc++/src': Var('chromium_url') + '/external/github.com/llvm/llvm-project/libcxx.git' + '@' + '97b436da4c33663581d394f4ee0a5977fc38c2f4', 'third_party/libc++abi/src': - Var('chromium_url') + '/external/github.com/llvm/llvm-project/libcxxabi.git' + '@' + 'fc1897a2c12aa27e703c3ed48b62eba8abf4ce19', + Var('chromium_url') + '/external/github.com/llvm/llvm-project/libcxxabi.git' + '@' + '92767730c5f8350fc53f5b3de5c3c02d00bbab8c', 'third_party/libpfm4': - Var('chromium_url') + '/chromium/src/third_party/libpfm4.git' + '@' + '4a112befd93f8d90a9b6894b2ec4d320310e1178', + Var('chromium_url') + '/chromium/src/third_party/libpfm4.git' + '@' + 'f2fec4fe8bc40a58b1f257e631fc5b8f49b39010', 'third_party/libpfm4/src': - Var('chromium_url') + '/external/git.code.sf.net/p/perfmon2/libpfm4.git' + '@' + '6870a9f00412830ceaa7e4384bb92ee323e2a28f', + Var('chromium_url') + '/external/git.code.sf.net/p/perfmon2/libpfm4.git' + '@' + '9c24ffc9d179244e05584ce4df2f4fbfecdfde9b', 'third_party/libunwind/src': - Var('chromium_url') + '/external/github.com/llvm/llvm-project/libunwind.git' + '@' + '45120ee2331193c3650acc9c427ed267fab31d62', + Var('chromium_url') + '/external/github.com/llvm/llvm-project/libunwind.git' + '@' + '24a407d5353ad38f948f107c7d6bc2bcbb4bca24', 'third_party/llvm-libc/src': - Var('chromium_url') + '/external/github.com/llvm/llvm-project/libc.git' + '@' + '43a9a99ce4b5a04954090f8a0e74bf2786f59379', + Var('chromium_url') + '/external/github.com/llvm/llvm-project/libc.git' + '@' + '5e61624667bf9e44ea452191dbda0172997018a2', 'third_party/llvm-build/Release+Asserts': { 'dep_type': 'gcs', 'bucket': 'chromium-browser-clang', 'objects': [ { - 'object_name': 'Linux_x64/clang-android-runtime-library-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '780597375163e78615a307a73ec66346b54c58ea3164aa6fbedf24eae85382fc', - 'size_bytes': 6210856, - 'generation': 1787607008868327, + 'object_name': 'Linux_x64/clang-android-runtime-library-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'b93725013ccd4f91d5ae40afc1a1b495e07c3be645ddbd7a3b48a7281fcecff8', + 'size_bytes': 6208368, + 'generation': 1789426565866244, 'condition': 'checkout_android', }, { - 'object_name': 'Linux_x64/clang-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '565f7d980b31411e76d9478731cf3f0ac907a46f274d289ea7f03d9137354053', - 'size_bytes': 56894668, - 'generation': 1787607001504676, + 'object_name': 'Linux_x64/clang-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '8039b5c9e7375df3a8082761cd1220223f90344b81d829c949f69224350d9d47', + 'size_bytes': 57238740, + 'generation': 1789426559193435, 'condition': 'host_os == "linux"', }, { - 'object_name': 'Linux_x64/clang-tidy-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '4290664a4fa8aa11fd1e6b2d3ff4965d26b41cca1a4950f9835ff19115c2384f', - 'size_bytes': 14877500, - 'generation': 1787607001575317, + 'object_name': 'Linux_x64/clang-tidy-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'f8206d1964bd8b59283589ca82159650611e217ad01ab885389f09e177fc80c0', + 'size_bytes': 14935260, + 'generation': 1789426559088623, 'condition': 'host_os == "linux" and checkout_clang_tidy', }, { - 'object_name': 'Linux_x64/clangd-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '9db50937915608c466da28ba4166cfa69a5f6bcad346233e47807f532cc3075b', - 'size_bytes': 15049952, - 'generation': 1787607001603946, + 'object_name': 'Linux_x64/clangd-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '79e4777278ef296219350c6a765eb215e4d23a76c85617ae6b4ec7a7fda524bc', + 'size_bytes': 15086928, + 'generation': 1789426559098441, 'condition': 'host_os == "linux" and checkout_clangd', }, { - 'object_name': 'Linux_x64/llvm-code-coverage-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '34747a8e113c399daa36f75a5a0a4c0963871ceafbce7c49a3b5133f81a63bae', - 'size_bytes': 2352288, - 'generation': 1787607001865886, + 'object_name': 'Linux_x64/llvm-code-coverage-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'b3b59473f37c63501c00d376c44ea46a59b840dab7298c67ba9101507c48ea65', + 'size_bytes': 2371412, + 'generation': 1789426559296849, 'condition': 'host_os == "linux" and checkout_clang_coverage_tools', }, { - 'object_name': 'Linux_x64/llvmobjdump-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': 'cc8a621ec8cc3c48471c90cf4ed88dcc56bfb403824eda10f8b55796abaec280', - 'size_bytes': 5912568, - 'generation': 1787607001713199, + 'object_name': 'Linux_x64/llvmobjdump-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '7da1f3e3754d2b841a909ddbdbdb91cf3cbea3fd7be4b51cbe2cfe171cbfa9d6', + 'size_bytes': 5917952, + 'generation': 1789426559151920, 'condition': '(checkout_linux or checkout_mac or checkout_android) and host_os == "linux"', }, { - 'object_name': 'Mac/clang-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': 'ba2b707d83f7a19d81b9403b4ebe8e999d41ae35fead00a142f02b67e197fe2f', - 'size_bytes': 56420628, - 'generation': 1787607010939621, + 'object_name': 'Mac/clang-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '5721c0e801c03b276a9680080ab3d5f0f572945e9d9d683ed8cbd50285598ea0', + 'size_bytes': 56731544, + 'generation': 1789426567536829, 'condition': 'host_os == "mac" and host_cpu == "x64"', }, { - 'object_name': 'Mac/clang-mac-runtime-library-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': 'da06337f54ba4b36c79e0d379557832bf82b9c7e85fe8ef78a5b953567d98de1', - 'size_bytes': 1012348, - 'generation': 1787607018227451, + 'object_name': 'Mac/clang-mac-runtime-library-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '5b7ee53434e68ca2d71a35da8c7bff79e246d5f3d499fddf10e0e3da564d9bdc', + 'size_bytes': 980916, + 'generation': 1789426574310634, 'condition': 'checkout_mac and not host_os == "mac"', }, { - 'object_name': 'Mac/clang-tidy-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': 'ae5cbec1362517b6928162fddb9b160bd1c75e8fd90789718393e1cadf1342ae', - 'size_bytes': 14882308, - 'generation': 1787607010909866, + 'object_name': 'Mac/clang-tidy-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '5aee98783a53c1acb489f78767c3562818759ee73ded863d08f9645233a3692e', + 'size_bytes': 14948968, + 'generation': 1789426567538151, 'condition': 'host_os == "mac" and host_cpu == "x64" and checkout_clang_tidy', }, { - 'object_name': 'Mac/clangd-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '73f5de0f007f8c588593d824147963ec770b66d487a707d1c377a06e34952d89', - 'size_bytes': 16779464, - 'generation': 1787607010899287, + 'object_name': 'Mac/clangd-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '74451b27944643780298bf5b667d41c2bc026f9fabbaaa543bd6a569d7cf3181', + 'size_bytes': 16825280, + 'generation': 1789426567538026, 'condition': 'host_os == "mac" and host_cpu == "x64" and checkout_clangd', }, { - 'object_name': 'Mac/llvm-code-coverage-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': 'c47eb37873d3290cc95ba5f9027337895eeeaa199c3f70e63c5d09b710faf250', - 'size_bytes': 2411184, - 'generation': 1787607011184644, + 'object_name': 'Mac/llvm-code-coverage-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '25fcd6877fd1124a879650c5d828ab9aac6a89bbb679188de89875656c062836', + 'size_bytes': 2423848, + 'generation': 1789426567755049, 'condition': 'host_os == "mac" and host_cpu == "x64" and checkout_clang_coverage_tools', }, { - 'object_name': 'Mac/llvmobjdump-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '4ddefa96f6aaa04ac502610fc736528f65dc3e1b997fc4a5380081937f6ffb1a', - 'size_bytes': 5874672, - 'generation': 1787607011035157, + 'object_name': 'Mac/llvmobjdump-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'fddb9d463c7c86698711435c1cab0e3dfd039ca6716ba5faed765e215ace9472', + 'size_bytes': 5908332, + 'generation': 1789426567556141, 'condition': 'host_os == "mac" and host_cpu == "x64"', }, { - 'object_name': 'Mac_arm64/clang-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '264d803970f9b58ddbdc90464ad82e54cef642c58ec371ba5356dfa7342ece4d', - 'size_bytes': 47226204, - 'generation': 1787607020088085, + 'object_name': 'Mac_arm64/clang-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'c6519a944e9ddd34fcc5273cdf1997f674c6d929b70eecd9020646774aa7b8aa', + 'size_bytes': 47559168, + 'generation': 1789426576079342, 'condition': 'host_os == "mac" and host_cpu == "arm64"', }, { - 'object_name': 'Mac_arm64/clang-tidy-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '3e02eae391e05018fb4e95d3c90b270688a5e3d5f5b31df6c59512e602478f36', - 'size_bytes': 12960456, - 'generation': 1787607020070956, + 'object_name': 'Mac_arm64/clang-tidy-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '6858c97a00a3e89de7b4bc1f4d2ed608811994067a5a8749ba830e39d10c456a', + 'size_bytes': 12998944, + 'generation': 1789426576095992, 'condition': 'host_os == "mac" and host_cpu == "arm64" and checkout_clang_tidy', }, { - 'object_name': 'Mac_arm64/clangd-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': 'a56514d09cfcb216efa297e5fecd51a2e248faf7db6edd2d444cfe78e0e219d3', - 'size_bytes': 13320572, - 'generation': 1787607020209265, + 'object_name': 'Mac_arm64/clangd-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'e8898cbd3448cea483971f8bd72fc3f45e59d5f02c639ce674c08b484cb42a1b', + 'size_bytes': 13313524, + 'generation': 1789426576068075, 'condition': 'host_os == "mac" and host_cpu == "arm64" and checkout_clangd', }, { - 'object_name': 'Mac_arm64/llvm-code-coverage-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': 'b593c509e8f4269cf4a16272f6eddcea0f9dd47f6f3fe39b9813041d0f96d4e3', - 'size_bytes': 2031112, - 'generation': 1787607020489366, + 'object_name': 'Mac_arm64/llvm-code-coverage-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'ce7a2040d2321222ae5751f0ecc3a8abf21da81f532095497524eb462ade02ff', + 'size_bytes': 2043608, + 'generation': 1789426576226450, 'condition': 'host_os == "mac" and host_cpu == "arm64" and checkout_clang_coverage_tools', }, { - 'object_name': 'Mac_arm64/llvmobjdump-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': 'c67f5dba316d6367be8c153ede456fdbef0dfffad4da10aaf597ff967c07378c', - 'size_bytes': 5610096, - 'generation': 1787607020228775, + 'object_name': 'Mac_arm64/llvmobjdump-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '53bd87b22289bd2df2e05a0f6a1bd297c8d8fc636584562668c72fee224354e6', + 'size_bytes': 5645448, + 'generation': 1789426576105416, 'condition': 'host_os == "mac" and host_cpu == "arm64"', }, { - 'object_name': 'Win/clang-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '166437ede456b3d7cf0d9317287511e47714f91da547dbde02992261aeef7174', - 'size_bytes': 51467544, - 'generation': 1787607030157700, + 'object_name': 'Win/clang-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'fcb789024398956d51b9b6018230b84981fe9160158c0de68e3ca4f254504cf3', + 'size_bytes': 51838392, + 'generation': 1789426584693424, 'condition': 'host_os == "win"', }, { - 'object_name': 'Win/clang-tidy-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '13cae70dfa207c9ec27e294f38b732b5c820ef637f48d24cc8b97f5f3a96e220', - 'size_bytes': 15134360, - 'generation': 1787607030186388, + 'object_name': 'Win/clang-tidy-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'e9c2f8b25cf6c2cc024c23823fbfb0d19149ab08faaec3bdb67e525eb224b20d', + 'size_bytes': 15129656, + 'generation': 1789426584789667, 'condition': 'host_os == "win" and checkout_clang_tidy', }, { - 'object_name': 'Win/clang-win-runtime-library-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '4ff9a06f5fc4a711103cd890e724ae4448d67873de438542f3ac6772e68d3c63', - 'size_bytes': 2638196, - 'generation': 1787607037249082, + 'object_name': 'Win/clang-win-runtime-library-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': '0556e0ba5ca0ecabdf16b544d3b671994f719a9b8530b77c9474ed5922d37f2b', + 'size_bytes': 2650852, + 'generation': 1789426591392711, 'condition': 'checkout_win and not host_os == "win"', }, { - 'object_name': 'Win/clangd-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '17f1d575127724051099a778d77e609f650702248cf4e7ff3ec33b377053edd9', - 'size_bytes': 15444040, - 'generation': 1787607030301504, + 'object_name': 'Win/clangd-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'c8cf60febcf4e7fcba61ab32153ea089d2b49ebe7d8d05230eb0c1ddc6d449f6', + 'size_bytes': 15433972, + 'generation': 1789426584780463, 'condition': 'host_os == "win" and checkout_clangd', }, { - 'object_name': 'Win/llvm-code-coverage-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '78aa6b2b9cf057077be6705b76e43ffed83e46e17ee86da1ab699340129b1aca', - 'size_bytes': 2512968, - 'generation': 1787607030493491, + 'object_name': 'Win/llvm-code-coverage-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'fe05d04734b47fd6e88602e597cab43a3f37eaa3f6f2e44f2ba808af8378a7b5', + 'size_bytes': 2527212, + 'generation': 1789426585050946, 'condition': 'host_os == "win" and checkout_clang_coverage_tools', }, { - 'object_name': 'Win/llvmobjdump-llvmorg-24-init-3796-g20e97c4b-4.tar.xz', - 'sha256sum': '4b899193da883a447c75f057e3a94f5e7ab93e5df5724ad94cbd6bf82ea792b4', - 'size_bytes': 5994644, - 'generation': 1787607030276791, + 'object_name': 'Win/llvmobjdump-llvmorg-24-init-7747-g62397f8b-29.tar.xz', + 'sha256sum': 'afb8027a34fd80557a3c500a3f77e1b0aa0c2f93c9c51becddd9dddbc555936e', + 'size_bytes': 6016140, + 'generation': 1789426584846994, 'condition': '(checkout_linux or checkout_mac or checkout_android) and host_os == "win"', }, ], @@ -531,9 +531,9 @@ deps = { 'condition': 'not build_with_chromium', }, 'third_party/perfetto': - Var('chromium_url') + '/external/github.com/google/perfetto.git' + '@' + '5dbeaad4ceb91470a835426b52e0cb43a3e5ef10', + Var('chromium_url') + '/external/github.com/google/perfetto.git' + '@' + 'aac4c25edfa1ad236f61622959166bc180a8ad2b', 'third_party/protobuf': - Var('chromium_url') + '/chromium/src/third_party/protobuf.git' + '@' + '5f8c379d1fc89fe8eee16ae560dd5e514a4608da', + Var('chromium_url') + '/chromium/src/third_party/protobuf.git' + '@' + '398c57e93a383373546bc6ae5ac2052b6155f2ba', 'third_party/re2/src': Var('chromium_url') + '/external/github.com/google/re2.git' + '@' + '972a15cedd008d846f1a39b2e88ce48d7f166cbd', 'third_party/requests': { @@ -541,41 +541,41 @@ deps = { 'condition': 'checkout_android', }, 'tools/rust': - Var('chromium_url') + '/chromium/src/tools/rust' + '@' + '54d1148695dbbbfc3e00dfd05aff502acaa602e3', + Var('chromium_url') + '/chromium/src/tools/rust' + '@' + '187bdac7c732777cf5e1b82b9caf6034d3a7e4e5', 'tools/win': Var('chromium_url') + '/chromium/src/tools/win' + '@' + '13cb6e5d223dc49eadd082d3aef4c2a5b0e4c0a0', 'third_party/rust': - Var('chromium_url') + '/chromium/src/third_party/rust' + '@' + '4dec6f65bcb34c4c289736b0e6fd571b35c6c665', + Var('chromium_url') + '/chromium/src/third_party/rust' + '@' + '4be2b73f368c8c2a3f5a42c16459b80d7d81b318', 'third_party/rust-toolchain': { 'dep_type': 'gcs', 'bucket': 'chromium-browser-clang', 'objects': [ { - 'object_name': 'Linux_x64/rust-toolchain-0913b18e489ac1011b580e31fa5559654be12bfc-2-llvmorg-24-init-3796-g20e97c4b.tar.xz', - 'sha256sum': '4b131e81d157a97bcf454ad0fbb71bc2063b2a3708c858410c04201ef06134e5', - 'size_bytes': 276314860, - 'generation': 1786821088882867, + 'object_name': 'Linux_x64/rust-toolchain-1edd55dcfcd573872c727fa3e086369a71661ee0-2-llvmorg-24-init-7747-g62397f8b.tar.xz', + 'sha256sum': '5a56edc35db24efbbe0373c724457c31a1febd75cbef6ac7fc9a1c5bca6fc697', + 'size_bytes': 276524576, + 'generation': 1789143384016025, 'condition': 'host_os == "linux"', }, { - 'object_name': 'Mac/rust-toolchain-0913b18e489ac1011b580e31fa5559654be12bfc-2-llvmorg-24-init-3796-g20e97c4b.tar.xz', - 'sha256sum': '12ca849195c27495073ba52ae7126d8a4a9a5807cd7a0dc6ba6b6fa612302a6d', - 'size_bytes': 264031896, - 'generation': 1786821092536805, + 'object_name': 'Mac/rust-toolchain-1edd55dcfcd573872c727fa3e086369a71661ee0-2-llvmorg-24-init-7747-g62397f8b.tar.xz', + 'sha256sum': '62530251d7e7d3741840289a45a3e4950ad0023857e03bf0e9d57f2d723a8624', + 'size_bytes': 264337576, + 'generation': 1789143387895737, 'condition': 'host_os == "mac" and host_cpu == "x64"', }, { - 'object_name': 'Mac_arm64/rust-toolchain-0913b18e489ac1011b580e31fa5559654be12bfc-2-llvmorg-24-init-3796-g20e97c4b.tar.xz', - 'sha256sum': 'fe128475561d7a51c797d1cb3ccea6f94fd770b167c8e0cc33bf75e7c25d8225', - 'size_bytes': 248465344, - 'generation': 1786821096222521, + 'object_name': 'Mac_arm64/rust-toolchain-1edd55dcfcd573872c727fa3e086369a71661ee0-2-llvmorg-24-init-7747-g62397f8b.tar.xz', + 'sha256sum': '5db21ffd4909ce82c0832df9d1eb06b01b15a54176b7341e39f7181f4b483dbc', + 'size_bytes': 248304876, + 'generation': 1789143391575553, 'condition': 'host_os == "mac" and host_cpu == "arm64"', }, { - 'object_name': 'Win/rust-toolchain-0913b18e489ac1011b580e31fa5559654be12bfc-2-llvmorg-24-init-3796-g20e97c4b.tar.xz', - 'sha256sum': '14bc9cea5e00cb191f58204ef44d68a6794f856a76f885c50298a12d052035bc', - 'size_bytes': 414479372, - 'generation': 1786821099612317, + 'object_name': 'Win/rust-toolchain-1edd55dcfcd573872c727fa3e086369a71661ee0-2-llvmorg-24-init-7747-g62397f8b.tar.xz', + 'sha256sum': '487387d6c7cfec69b06d613eb0f68331a3b56b1081f73bc673a1b26299865379', + 'size_bytes': 416611108, + 'generation': 1789143395284107, 'condition': 'host_os == "win"', }, ], @@ -594,31 +594,31 @@ deps = { 'bucket': 'chromium-browser-clang', 'objects': [ { - 'object_name': 'Linux_x64/rust-libclang-0913b18e489ac1011b580e31fa5559654be12bfc-2-llvmorg-24-init-3796-g20e97c4b.tar.xz', - 'sha256sum': 'a36afcfb09b2b096cd7d17b6008beb1993c3962d780a7ccc0aa4c5f544447429', - 'size_bytes': 22734560, - 'generation': 1786821090667672, + 'object_name': 'Linux_x64/rust-libclang-1edd55dcfcd573872c727fa3e086369a71661ee0-2-llvmorg-24-init-7747-g62397f8b.tar.xz', + 'sha256sum': '59c2086dabf6494fb7cc4690910d4dfddd9a598a1ecaf19d8408197445bbf7c3', + 'size_bytes': 22899948, + 'generation': 1789143385954506, 'condition': 'host_os == "linux"', }, { - 'object_name': 'Mac/rust-libclang-0913b18e489ac1011b580e31fa5559654be12bfc-2-llvmorg-24-init-3796-g20e97c4b.tar.xz', - 'sha256sum': '0ff3d2a46a0ed3851311cce6aa60f70f3d3e88e4177c2b10806c990a72461f67', - 'size_bytes': 23130796, - 'generation': 1786821094366500, + 'object_name': 'Mac/rust-libclang-1edd55dcfcd573872c727fa3e086369a71661ee0-2-llvmorg-24-init-7747-g62397f8b.tar.xz', + 'sha256sum': '6fa15d9cf2ff55b5ae1e4276369cfbde1f4f770e60ccb133e1fc7446c5ce607e', + 'size_bytes': 23309500, + 'generation': 1789143389794597, 'condition': 'host_os == "mac" and host_cpu == "x64"', }, { - 'object_name': 'Mac_arm64/rust-libclang-0913b18e489ac1011b580e31fa5559654be12bfc-2-llvmorg-24-init-3796-g20e97c4b.tar.xz', - 'sha256sum': '0a95d15ec7e992b60f47b9cf98f951b32f718488aa5d15d1c8cbae81f1db6b39', - 'size_bytes': 20545284, - 'generation': 1786821097847085, + 'object_name': 'Mac_arm64/rust-libclang-1edd55dcfcd573872c727fa3e086369a71661ee0-2-llvmorg-24-init-7747-g62397f8b.tar.xz', + 'sha256sum': 'd330fd41100be52b4e804c9252b3f3bb34cfed16d2973934de0930b297f7201e', + 'size_bytes': 20689276, + 'generation': 1789143393459608, 'condition': 'host_os == "mac" and host_cpu == "arm64"', }, { - 'object_name': 'Win/rust-libclang-0913b18e489ac1011b580e31fa5559654be12bfc-2-llvmorg-24-init-3796-g20e97c4b.tar.xz', - 'sha256sum': '75033b0243acf7c25227f6015c60797724b98d1de5514e9e1a374735ef76aa4e', - 'size_bytes': 21534908, - 'generation': 1786821101319840, + 'object_name': 'Win/rust-libclang-1edd55dcfcd573872c727fa3e086369a71661ee0-2-llvmorg-24-init-7747-g62397f8b.tar.xz', + 'sha256sum': 'fbe9978289a35ca45da1c1393ed6ef8adc86907d36a4ce81fcf590f56b07a096', + 'size_bytes': 21677148, + 'generation': 1789143397092006, 'condition': 'host_os == "win"', }, ], @@ -656,20 +656,20 @@ deps = { 'dep_type': 'cipd', }, 'third_party/zlib': - Var('chromium_url') + '/chromium/src/third_party/zlib.git'+ '@' + '285e94b8fa95ad3b7d16b80798ec8dce6febb8c8', + Var('chromium_url') + '/chromium/src/third_party/zlib.git'+ '@' + '13395eebe853e811d274f7bd9b71fb7d9b5a5851', 'tools/clang': - Var('chromium_url') + '/chromium/src/tools/clang.git' + '@' + '450d823868eaee61e2b2cb986e19aec287f16d58', + Var('chromium_url') + '/chromium/src/tools/clang.git' + '@' + '10f700407ca356594ea2a575572b7ce63183721d', 'tools/protoc_wrapper': Var('chromium_url') + '/chromium/src/tools/protoc_wrapper.git' + '@' + 'e9dbe1bf6a2a5d2d4973725874259eed587cf18d', 'third_party/abseil-cpp': { - 'url': Var('chromium_url') + '/chromium/src/third_party/abseil-cpp.git' + '@' + '435e7d977fb36fb47854a4c552c0706dad0bd7cf', + 'url': Var('chromium_url') + '/chromium/src/third_party/abseil-cpp.git' + '@' + 'edf0931ff4e2cddfeecade307ae948b5d09b8b38', 'condition': 'not build_with_chromium', }, 'third_party/fadec/src': { 'url': Var('chromium_url') + '/external/github.com/aengelke/fadec.git' + '@' + 'c9f78f532b9004de278489019ab2c6c28ae9746e', }, 'third_party/disarm/src': { - 'url': Var('chromium_url') + '/external/github.com/aengelke/disarm.git' + '@' + '2d13d3f410a52daff1c5d8ef07d623332f372560', + 'url': Var('chromium_url') + '/external/github.com/aengelke/disarm.git' + '@' + '2d960dae4b4fb29dba05cfc48210fbed423f3d2c', }, 'third_party/zoslib': { 'url': Var('chromium_url') + '/external/github.com/ibmruntimes/zoslib.git' + '@' + '804b13554e8dd6972a591c1d6e532514fadd42a8', diff --git a/deps/v8/PRESUBMIT.py b/deps/v8/PRESUBMIT.py index 335f2333e0b9..1bbf577c86dd 100644 --- a/deps/v8/PRESUBMIT.py +++ b/deps/v8/PRESUBMIT.py @@ -848,19 +848,23 @@ def FilterFile(affected_file): def _CheckMetagenHeaders(input_api, output_api): - """Check that tools/metagen's driver still reaches every heap object. + """Check that src/objects/all-objects.h includes every heap object header. tools/metagen/metagen.py harvests the InstanceType enum from the class - declarations its driver's include closure reaches. A header that grows a - V8_OBJECT / V8_IT_ class but that nothing in the closure includes is - silently skipped -- the class simply gets no instance type -- so catch the - drift at upload time. - - Reachability is resolved textually rather than by preprocessing, and - conditional includes are followed regardless of their guard: a header - reachable only under V8_INTL_SUPPORT still counts as reached, because the - harvest runs per build configuration and sees it in the configs that - enable it. + declarations included by all-objects.h. A header with a V8_OBJECT / + V8_IT_ class that all-objects.h does not include is skipped without + error and its class gets no instance type, so check at upload time. + + The check requires direct inclusion because BUILD.gn declares only + all-objects.h as an input of the harvest. A header included through an + intermediate header is still harvested, but the intermediate is in + neither the action's inputs nor the depfile, so an incremental build + keeps a stale instance-types.h. + + Includes are read textually, not by preprocessing, and conditional ones + count regardless of their guard: the harvest runs per build + configuration, so a header included only under V8_INTL_SUPPORT is + harvested in the configurations that enable it. """ import subprocess v8_root = input_api.PresubmitLocalPath() @@ -890,35 +894,28 @@ def _CheckMetagenHeaders(input_api, output_api): ] live = set(res.stdout.split()) - include_re = re.compile(r'^\s*#\s*include\s+"([^"]+)"', re.MULTILINE) - driver = join("tools", "metagen", "harvest-driver.cc") - reached = set() - queue = [driver] - while queue: - rel = queue.pop() - if rel in reached: - continue - reached.add(rel) - try: - with open(join(v8_root, rel)) as f: - body = f.read() - except OSError: - # Not a V8 file (a system or third_party header); its includes - # cannot reach a V8_OBJECT declaration we care about. - continue - queue.extend(include_re.findall(body)) + aggregate = join("src", "objects", "all-objects.h") + try: + with open(join(v8_root, aggregate)) as f: + body = f.read() + except OSError as e: + return [ + output_api.PresubmitNotifyResult( + f"_CheckMetagenHeaders: skipping ({aggregate}: {e})") + ] + included = set(re.findall(r'^\s*#\s*include\s+"([^"]+)"', body, re.MULTILINE)) - missing = sorted(live - reached) + missing = sorted(live - included) if not missing: return [] return [ output_api.PresubmitError("\n".join([ - f"{driver} no longer reaches every heap object.", - "These headers carry a V8_OBJECT/V8_IT_ marker but nothing in the " - "driver's include closure includes them, so metagen assigns their " - "classes no instance type:", + f"{aggregate} no longer includes every heap object header.", + "These headers carry a V8_OBJECT/V8_IT_ marker but are not " + "included there, so metagen either misses their classes or " + "harvests them through a header the build does not depend on:", ] + [f" {h}" for h in missing] + [ - "Add them to src/objects/all-objects.h.", + f"Add them to {aggregate}.", ])) ] diff --git a/deps/v8/agents/.vpython3 b/deps/v8/agents/.vpython3 deleted file mode 100644 index 9a55b6ba5af3..000000000000 --- a/deps/v8/agents/.vpython3 +++ /dev/null @@ -1,137 +0,0 @@ -python_version: "3.11" - -wheel: < - name: "infra/python/wheels/pyyaml/${vpython_platform}" - version: "version:5.4.1.chromium.1" -> - -wheel: < - name: "infra/python/wheels/tabulate-py3" - version: "version:0.9.0" -> - -wheel: < - name: "infra/python/wheels/platformdirs-py3" - version: "version:4.9.2" -> - -wheel: < - name: "infra/python/wheels/mcp-py3" - version: "version:1.9.4" -> -wheel: < - name: "infra/python/wheels/pydantic-py3" - version: "version:2.11.7" -> -wheel: < - name: "infra/python/wheels/starlette-py3" - version: "version:0.47.1" -> -wheel: < - name: "infra/python/wheels/anyio-py3" - version: "version:4.9.0" -> -wheel: < - name: "infra/python/wheels/sniffio-py3" - version: "version:1.3.0" -> -wheel: < - name: "infra/python/wheels/idna-py3" - version: "version:3.4" -> -wheel: < - name: "infra/python/wheels/typing-extensions-py3" - version: "version:4.13.2" -> -wheel: < - name: "infra/python/wheels/httpx_sse-py3" - version: "version:0.4.1" -> -wheel: < - name: "infra/python/wheels/httpx-py3" - version: "version:0.28.1" -> -wheel: < - name: "infra/python/wheels/certifi-py3" - version: "version:2025.4.26" -> -wheel: < - name: "infra/python/wheels/httpcore-py3" - version: "version:1.0.9" -> -wheel: < - name: "infra/python/wheels/h11-py3" - version: "version:0.16.0" -> -wheel: < - name: "infra/python/wheels/pydantic-settings-py3" - version: "version:2.10.1" -> -wheel: < - name: "infra/python/wheels/python-multipart-py3" - version: "version:0.0.20" -> -wheel: < - name: "infra/python/wheels/sse-starlette-py3" - version: "version:2.4.1" -> -wheel: < - name: "infra/python/wheels/uvicorn-py3" - version: "version:0.35.0" -> -wheel: < - name: "infra/python/wheels/annotated-types-py3" - version: "version:0.7.0" -> -wheel: < - name: "infra/python/wheels/pydantic_core/${vpython_platform}" - version: "version:2.33.2" -> -wheel: < - name: "infra/python/wheels/typing-inspection-py3" - version: "version:0.4.1" -> -wheel: < - name: "infra/python/wheels/python-dotenv-py3" - version: "version:1.1.1" -> -wheel: < - name: "infra/python/wheels/click-py3" - version: "version:8.0.3" -> -wheel: < - name: "infra/python/wheels/colorama-py2_py3" - version: "version:0.4.1" -> -wheel: < - name: "infra/python/wheels/perfetto-py3" - version: "version:0.16.0" -> -wheel: < - name: "infra/python/wheels/protobuf-py3" - version: "version:6.33.5" -> -wheel: < - name: "infra/python/wheels/pandas/${vpython_platform}" - version: "version:2.2.3.chromium.1" -> -wheel: < - name: "infra/python/wheels/numpy/${vpython_platform}" - version: "version:1.23.5.chromium.4" -> -wheel: < - name: "infra/python/wheels/python-dateutil-py2_py3" - version: "version:2.9.0" -> -wheel: < - name: "infra/python/wheels/pytz-py2_py3" - version: "version:2025.2" -> -wheel: < - name: "infra/python/wheels/six-py2_py3" - version: "version:1.17.0" -> -wheel: < - name: "infra/python/wheels/tzdata-py2_py3" - version: "version:2025.2" -> diff --git a/deps/v8/agents/README.md b/deps/v8/agents/README.md index 2d4e4f31732b..aeb73ceffc3f 100644 --- a/deps/v8/agents/README.md +++ b/deps/v8/agents/README.md @@ -1,7 +1,7 @@ # V8 Coding Agents This directory provides a centralized location for files related to AI coding -agents (e.g. `gemini-cli`) used for development within V8. +agents (e.g. `jetski-cli`) used for development within V8. The goal is to provide a scalable and organized way to share prompts and tools among developers, accommodating the various environments (Linux, Mac, Windows) @@ -14,18 +14,15 @@ in ## Directory Structure -### Subagents +### Skills & Rules -On-demand expertise for specific tasks. Source files are located in -[`agents/`](agents/). +Reusable workflows, commands, and conventions live in `skills/` and `rules/`. -To use them, you need to run the appropriate installation script from the -`agents/` directory: +To install them for your agent environment, run the appropriate installation +script from the `agents/` directory: -- **For Gemini CLI**: Run `vpython3 scripts/install_for_gemini_cli.py` to - generate the subagent files in `.gemini/agents/`. - **For Jetski**: Run `vpython3 scripts/install_for_jetski.py` to create - symlinks in `.agents/agents/`. + symlinks in `.agents/`. - **For GitHub Copilot CLI**: Run `vpython3 scripts/install_for_copilot_cli.py` to generate repository instructions in `.github/copilot-instructions.md`, install compatible V8 rules as instruction files in `.github/instructions/`, diff --git a/deps/v8/agents/agents/builder/agent.json b/deps/v8/agents/agents/builder/agent.json deleted file mode 100644 index 76a25ad8b64e..000000000000 --- a/deps/v8/agents/agents/builder/agent.json +++ /dev/null @@ -1,5 +0,0 @@ -{ - "name": "builder", - "description": "Specializes in building V8.", - "config_path": "config.yaml" -} \ No newline at end of file diff --git a/deps/v8/agents/agents/builder/config.yaml b/deps/v8/agents/agents/builder/config.yaml deleted file mode 100644 index 7d1a87f4700b..000000000000 --- a/deps/v8/agents/agents/builder/config.yaml +++ /dev/null @@ -1,11 +0,0 @@ -custom_agent: - system_prompt_sections: - - content: |- - You are a build assistant. Your goal is to compile V8 for specified configurations. You can read files and search code to understand build errors. - title: Instructions - tool_names: - - run_command - - view_file - - grep_search - - list_dir - - mcp_* diff --git a/deps/v8/agents/agents/debugger/agent.json b/deps/v8/agents/agents/debugger/agent.json deleted file mode 100644 index 2cd61be6d6b5..000000000000 --- a/deps/v8/agents/agents/debugger/agent.json +++ /dev/null @@ -1,5 +0,0 @@ -{ - "name": "debugger", - "description": "Specializes in interactive debugging and crash analysis.", - "config_path": "config.yaml" -} \ No newline at end of file diff --git a/deps/v8/agents/agents/debugger/config.yaml b/deps/v8/agents/agents/debugger/config.yaml deleted file mode 100644 index d5ab65ee34fc..000000000000 --- a/deps/v8/agents/agents/debugger/config.yaml +++ /dev/null @@ -1,12 +0,0 @@ -custom_agent: - system_prompt_sections: - - content: |- - You are a debugging assistant. Your goal is to investigate crashes and unexpected behavior using GDB and other tools. - title: Instructions - tool_names: - - run_command - - view_file - - grep_search - - list_dir - - call_mcp_tool - - mcp_* diff --git a/deps/v8/agents/agents/researcher/agent.json b/deps/v8/agents/agents/researcher/agent.json deleted file mode 100644 index 933c9a9ab382..000000000000 --- a/deps/v8/agents/agents/researcher/agent.json +++ /dev/null @@ -1,5 +0,0 @@ -{ - "name": "researcher", - "description": "Specializes in exploring the codebase and finding information.", - "config_path": "config.yaml" -} \ No newline at end of file diff --git a/deps/v8/agents/agents/researcher/config.yaml b/deps/v8/agents/agents/researcher/config.yaml deleted file mode 100644 index 8d5d84529bb7..000000000000 --- a/deps/v8/agents/agents/researcher/config.yaml +++ /dev/null @@ -1,11 +0,0 @@ -custom_agent: - system_prompt_sections: - - content: |- - You are a research assistant. Your goal is to find relevant code, documentation, and information in the V8 codebase and the web. You provide detailed reports with file paths and line numbers. - title: Instructions - tool_names: - - view_file - - grep_search - - list_dir - - search_web - - mcp_* diff --git a/deps/v8/agents/agents/tester/agent.json b/deps/v8/agents/agents/tester/agent.json deleted file mode 100644 index bc7feb78cba5..000000000000 --- a/deps/v8/agents/agents/tester/agent.json +++ /dev/null @@ -1,5 +0,0 @@ -{ - "name": "tester", - "description": "Specializes in running tests and benchmarks.", - "config_path": "config.yaml" -} \ No newline at end of file diff --git a/deps/v8/agents/agents/tester/config.yaml b/deps/v8/agents/agents/tester/config.yaml deleted file mode 100644 index de6f45cf0199..000000000000 --- a/deps/v8/agents/agents/tester/config.yaml +++ /dev/null @@ -1,11 +0,0 @@ -custom_agent: - system_prompt_sections: - - content: |- - You are a test assistant. Your goal is to run tests and benchmarks and report results. You can read files and search code to understand test failures. - title: Instructions - tool_names: - - run_command - - view_file - - grep_search - - list_dir - - mcp_* diff --git a/deps/v8/agents/plugins/install.py b/deps/v8/agents/plugins/install.py index 160c25f63348..4c18a73eb3f6 100755 --- a/deps/v8/agents/plugins/install.py +++ b/deps/v8/agents/plugins/install.py @@ -38,7 +38,7 @@ class AgentPlatform: mcp_config: dict def _load_config(self) -> dict: - if self.config_path.exists(): + if not self.config_path.exists(): return {"mcpServers": {}} cfg = load_json(self.config_path) if "mcpServers" not in cfg: @@ -109,43 +109,15 @@ def save(self) -> None: pass -class GeminiPlatform(CliAgentPlatform): - """Implementation for Gemini CLI MCP configuration.""" +class JetskiPlatform(AgentPlatform): + """Implementation for Jetski MCP configuration.""" - NAME = "gemini" - BINARY = "gemini" - COMMAND: ClassVar[str] = "mcp" - EXTRA_ARGS: ClassVar[list[str]] = ["--scope", "user"] + NAME = "jetski" def __init__(self) -> None: - super().__init__() self.config_path = Path.home() / ".gemini/config/mcp_config.json" self.mcp_config = self._load_config() - def _remove_server_cli(self, server_name: str) -> bool: - cmd = [self.BINARY, self.COMMAND, "remove", server_name] + self.EXTRA_ARGS - res = self._run(cmd, check=False) - return res.returncode == 0 - - def register_server(self, server_name: str, server_info: dict) -> dict: - config = super().register_server(server_name, server_info) - self._remove_server_cli(server_name) - cmd = [self.BINARY, self.COMMAND, "add"] + self.EXTRA_ARGS - for k, v in config.get("env", {}).items(): - cmd.extend(["-e", f"{k}={v}"]) - cmd.extend([server_name, config["command"]] + config["args"]) - self._run(cmd, check=True) - return config - - -class JetskiPlatform(GeminiPlatform): - """Implementation for Jetski MCP configuration.""" - - NAME = "jetski" - BINARY = "jetski-cli" - COMMAND = "plugin" - EXTRA_ARGS = [] - class ClaudeDesktopPlatform(AgentPlatform): """Implementation for Claude Desktop MCP configuration. @@ -200,7 +172,6 @@ def register_server(self, server_name: str, server_info: dict) -> dict: AGENT_PLATFORMS: Final[list[type[AgentPlatform]]] = [ - GeminiPlatform, JetskiPlatform, ClaudeDesktopPlatform, ClaudeCLIPlatform, @@ -216,13 +187,17 @@ def get_platform(agent_name: str) -> AgentPlatform: def get_available_plugins() -> dict[str, dict]: - """Scans agents/plugins for available Gemini plugins.""" - # TODO: support other agent directories too. + """Scans agents/plugins for available agent plugins.""" plugins = {} plugins_dir = _PROJECT_ROOT / "agents/plugins" - for manifest_path in plugins_dir.glob("*/gemini-extension.json"): + for manifest_path in plugins_dir.glob("*/plugin.json"): plugin_name = manifest_path.parent.name manifest = load_json(manifest_path) + mcp_config_path = manifest_path.parent / "mcp_config.json" + if mcp_config_path.exists(): + mcp_config = load_json(mcp_config_path) + manifest.setdefault("mcpServers", + {}).update(mcp_config.get("mcpServers", {})) plugins[plugin_name] = { "manifest_path": manifest_path, "manifest": manifest, @@ -335,7 +310,7 @@ def main() -> None: ) remove_parser = subparsers.add_parser( - "remove", help="Remove plugins from target agent.") + "remove", aliases=["rm"], help="Remove plugins from target agent.") remove_parser.add_argument( "plugins", nargs="+", help="Plugin names to remove.") diff --git a/deps/v8/agents/prompts/README.md b/deps/v8/agents/prompts/README.md index 0d78352ca598..1826e0796abe 100644 --- a/deps/v8/agents/prompts/README.md +++ b/deps/v8/agents/prompts/README.md @@ -1,28 +1,15 @@ # Prompts -This directory contains the common prompt for V8 and template prompts to teach -agents about specific tools. Everything is intended to work with gemini-cli. +This directory contains the system instruction prompt template +(`templates/modular.md`) for V8 coding agents (`jetski-cli`). ## Creating the System Instruction Prompt -Create a local, untracked `GEMINI.md` file in your root directory. Include -relevant prompts using the `@` syntax. For example: - -```GEMINI.md -@agents/prompts/common.md -``` - -You can confirm that prompts were successfully imported by running the -`/memory show` command in gemini-cli. - -## Known problems - -All imports must be scoped to the current prompt file. a/prompt.md can import -a/prompt2.md or a/b/prompt3.md, but cannot import c/prompt4.md. See -https://github.com/google-gemini/gemini-cli/issues/4098. +Run `vpython3 agents/scripts/install_for_jetski.py` to generate your root +`GEMINI.md` file from `agents/prompts/templates/modular.md` and link `.agents/` +rules and skills. ## Contributing -Changes to `common.md` should be done *carefully* as it's meant to be used -broadly. Use the `template/` directory to add new prompts that you want to -share. +Changes to `templates/modular.md` should be done *carefully* as it is meant to +be used broadly across V8 workspaces. diff --git a/deps/v8/agents/prompts/common.md b/deps/v8/agents/prompts/common.md deleted file mode 100644 index da65c3406c29..000000000000 --- a/deps/v8/agents/prompts/common.md +++ /dev/null @@ -1,268 +0,0 @@ -# Gemini Workspace for V8 - -This is the workspace configuration for V8 when using Gemini. - -Documentation can be found at https://v8.dev/docs. - -## Key Commands - -- **Build (Debug):** `tools/dev/gm.py quiet x64.debug tests` -- **Build (Optimized Debug):** `tools/dev/gm.py quiet x64.optdebug tests` -- **Build (Release):** `tools/dev/gm.py quiet x64.release tests` -- **Run All Tests:** - `tools/run-tests.py --progress dots --exit-after-n-failures=5 --outdir=out/x64.optdebug` -- **Run C++ Tests:** - `tools/run-tests.py --progress dots --exit-after-n-failures=5 --outdir=out/x64.optdebug cctest unittests` -- **Run JavaScript Tests:** - `tools/run-tests.py --progress dots --exit-after-n-failures=5 --outdir=out/x64.optdebug mjsunit` -- **Format Code:** `git cl format` - -Some hints: - -- You are an expert C++ developer. -- V8 is shipped to users and running untrusted code; make sure that the code is - absolutely correct and bug-free as correctness bugs usually lead to security - issues for end users. -- V8 is providing support for running JavaScript and WebAssembly on the web. As - such, it is critical to aim for best possible performance when optimizing V8. - -## Folder structure - -- `src/`: The main source folder providing the implementation of the virtual - machine. Key subdirectories include: - - `src/api/`: Implements the V8 public C++ API, as declared in `include/`. - - `src/ast/`: Defines the Abstract Syntax Tree (AST) used to represent parsed - JavaScript, including nodes, scopes, and variables. - - `src/base/`: Provides fundamental, low-level utilities, data structures, and - a platform abstraction layer for the entire V8 project. - - `src/baseline/`: Implements the Sparkplug baseline compiler, which generates - machine code directly from bytecode for a fast performance boost. - - `src/bigint/`: The implementation of BigInt operations. - - `src/builtins/`: Implementation of JavaScript built-in functions (e.g., - `Array.prototype.map`). - - `src/codegen/`: Code generation, including direct machine code generation - via macro assemblers, higher level codegen via CodeStubAssembler, - definitions of machine code metadata like safepoint tables and source - position tables, and `compiler.cc` which defines entry points into the - compilers. This contains subdirectories for architecture specific - implementations, which should be kept in sync with each other as much as - possible. - - `src/common/`: Common definitions and utilities. - - `src/compiler/`: The TurboFan optimizing compiler, including the Turboshaft - CFG compiler. - - `src/d8/`: The `d8` shell implementation, for running V8 in a CLI. - - `src/debug/`: The debugger and debug protocol implementation. - - `src/deoptimizer/`: The deoptimizer implementation, which translates - optimized frames into unoptimized ones. - - `src/execution/`: The definitions of the execution environment, including - the Isolate, frame definitions, microtasks, stack guards, tiering, and - on-stack argument handling. - - `src/handles/`: The handle implementation for GC-safe object references. - - `src/heap/`: The garbage collector and memory management code. - - `src/ic/`: The Inline Caching implementation. - - `src/init/`: The V8 initialization code. - - `src/inspector/`: The inspector protocol implementation. - - `src/interpreter/`: The Ignition bytecode compiler and interpreter. - - `src/json/`: The JSON parser and serializer. - - `src/libplatform/`: The platform abstraction layer, for task runners and - worker threads. - - `src/logging/`: The logging implementation. - - `src/maglev/`: The Maglev mid-tier optimizing compiler. - - `src/numbers/`: Implementations of various numeric operations. - - `src/objects/`: The representation and behaviour of V8 internal and - JavaScript objects. - - `src/parsing/`: The parser and scanner implementation. - - `src/profiler/`: The in-process profiler implementations, for heap - snapshots, allocation tracking, and a sampling CPU profiler. - - `src/regexp/`: The regular expression implementation. This contains - subdirectories for architecture specific implementations, which should be - kept in sync with each other as much as possible. - - `src/runtime/`: C++ functions that can be called from JavaScript at runtime. - - `src/sandbox/`: The implementation of the sandbox, which is a security - feature that attempts to limit V8 memory operations to be within a single - guarded virtual memory allocation, such that corruptions of objects within - the sandbox cannot lead to corruption of objects outside of it. - - `src/snapshot/`: The snapshot implementation, for both the startup snapshot - (read-only, startup heap, and startup context), as well as the - code-serializer, which generates code caches for caching of user script - code. - - `src/strings/`: Implementations of string helpers, such as predicates for - characters, unicode processing, hashing and string building. - - `src/torque/`: The Torque language implementation. - - `src/tracing/`: The tracing implementation. - - `src/trap-handler/`: Implementations of trap handlers. - - `src/wasm/`: The WebAssembly implementation. - - `src/zone/`: The implementation of a simple bump-pointer region-based zone - allocator. -- `test/`: Folder containing most of the tests and testing code. -- `include/`: Folder containing all of V8's publicAPI that is used when V8 is - embedded in other projects such as e.g. the Blink rendering engine. -- `out/`: Folder containing the results of a build. Usually organized in sub - folders for the respective configurations. - -## Building - -The full documentation for building using GN can be found at -https://v8.dev/docs/build-gn. - -Once the initial dependencies are installed, V8 can be built using `gm.py`, -which is a wrapper around GN and Ninja. - -```bash -# List all available build configurations and targets -tools/dev/gm.py - -# Build the d8 shell for x64 in release mode -tools/dev/gm.py quiet x64.release - -# Build d8 for x64 in debug mode -tools/dev/gm.py quiet x64.debug -``` - -- **release:** Optimized for performance, with debug information stripped. Use - for benchmarking. -- **debug:** Contains full debug information and enables assertions. Slower, but - essential for debugging. -- **optdebug:** A compromise with optimizations enabled and debug information - included. Good for general development. -- **sync:** - - Use `--sync` to run `gclient sync -D` before building. - - Use `--sync=force` to run `gclient sync -D --force --reset` before building. - -Make sure to pass the `quiet` keyword unless told to otherwise, so that you -don't waste tokens on compilation progress. Errors will still be reported. - -## Debugging - -For debugging, it is recommended to use a `debug` or `optdebug` build. You can -run `d8` with GDB or LLDB for native code debugging. - -```bash -# Example of running d8 with gdb -gdb --args out/x64.debug/d8 --my-flag my-script.js -``` - -V8 also provides a rich set of flags for diagnostics. Some of the most common -ones are: - -- `--trace-opt`: Log optimized functions. -- `--trace-deopt`: Log when and why functions are deoptimized. -- `--trace-gc`: Log garbage collection events. -- `--allow-natives-syntax`: Enables calling of internal V8 functions (e.g. - `%OptimizeFunctionOnNextCall(f)`) from JavaScript for testing purposes. - -A comprehensive list of all flags can be found by running -`out/x64.debug/d8 --help`. Most V8 flags are in `flag-definitions.h`; flags -specific to the `d8` shell are located in `src/d8/d8.cc` within the -`Shell::SetOptions` function. - -When debugging issues in Torque code, it is often useful to inspect the -generated C++ files in `out//gen/torque-generated/`. This allows -you to see the low-level CodeStubAssembler code that is actually being executed. - -## Testing - -The primary script for running tests is `tools/run-tests.py`. You specify the -build output directory and the tests you want to run. Key test suites include: - -- **unittests:** C++ unit tests for V8's internal components. -- **cctest:** Another, older format for C++ unit tests (deprecated, in the - process of being moved to unittests). -- **mjsunit:** JavaScript-based tests for JavaScript language features and - builtins. - -```bash -# Run all standard tests for the x64.optdebug build -tools/run-tests.py --progress dots --exit-after-n-failures=5 --outdir=out/x64.optdebug - -# Run a specific test suite (e.g., cctest) -tools/run-tests.py --progress dots --exit-after-n-failures=5 --outdir=out/x64.optdebug cctest - -# Run a specific test file -tools/run-tests.py --progress dots --exit-after-n-failures=5 --outdir=out/x64.optdebug cctest/test-heap -``` - -It's important to pass `--progress dots` so that there is minimal progress -reporting, to avoid cluttering the output. - -If there are any failing tests, they will be reported along their stderr and a -command to reproduce them e.g. - -``` -=== mjsunit/maglev/regress-429656023 === ---- stderr --- -# -# Fatal error in ../../src/heap/local-factory.h, line 41 -# unreachable code -# -# -# -...stack trace... -Received signal 6 -Command: out/x64.optdebug/d8 --test test/mjsunit/mjsunit.js test/mjsunit/maglev/regress-429656023.js --random-seed=-190258694 --nohard-abort --verify-heap --allow-natives-syntax -``` - -You can retry the test either by running the test name with -`tools/run-tests.py`, e.g. -`tools/run-tests.py --progress dots --outdir=out/x64.optdebug mjsunit/maglev/regress-429656023`, -or by running the command directly. When running the command directly, you can -add additional flags to help debug the issue, and you can try running a -different build (e.g. running a debug build if a release build fails). - -The full testing documentation is at https://v8.dev/docs/test. - -## Coding and Committing - -- Always follow the style conventions used in code surrounding your changes. -- Otherwise, follow - [Chromium's C++ style guide](https://chromium.googlesource.com/chromium/src/+/main/styleguide/styleguide.md). -- Use `git cl format` to automatically format your changes. - -### Commit Messages - -Commit messages should follow the convention described at -https:/v8.dev/docs/contribute#commit-messages. A typical format is: - -``` -[component]: Short description of the change - -Longer description explaining the "why" of the change, not just -the "what". Wrap lines at 72 characters. - -Bug: 123456 -``` - -- The `component` is the area of the codebase (e.g., `compiler`, `runtime`, - `api`). -- The `Bug:` line is important for linking to issues in the tracker at - https://crbug.com/ - -## Common Pitfalls & Best Practices - -- **Always format before committing:** Run `git cl format` before creating a - commit to ensure your code adheres to the style guide. -- **Do not edit generated files:** Files in `out/` are generated by the build - process. Edits should be made to the source files (e.g., `.tq` files for - Torque, `.pdl` for protocol definitions). -- **Match test configuration to build:** Ensure you are running tests against - the correct build type (e.g., run mjsunit from out/x64.debug if you built - x64.debug). -- **Check surrounding code for conventions:** Before adding new code, always - study the existing patterns, naming conventions, and architectural choices in - the file and directory you are working in. -- **Avoid changing unrelated code:** Keep diffs small by only changing the code - you intended to change. Nearby code should not be cleaned up while making a - change -- if you think there is a good cleanup, suggest it to me for a - separate patch. -- **Keep related functions together:** When adding a new function, try to insert - it near related functions, to keep similar behaviour close. -- **Don't guess header names:** If you don't know where the definition of a - class or function is, don't try to guess the header name, but search for it - instead. -- **Be careful with forward declarations:** Many types are forward declared; if - you want to use them, you'll need to find the definition. -- **Be careful with inline function definitions:** Many functions are declared - as `inline` in the `.h` file, and defined in a `-inl.h` file. If you get - compile errors about a missing definition, you are likely missing an - `#include` for a `-inl.h` file. You can only include `-inl.h` files from other - `-inl.h` files and `.cc` files. diff --git a/deps/v8/agents/prompts/templates/README.md b/deps/v8/agents/prompts/templates/README.md deleted file mode 100644 index 3cb7bef57a78..000000000000 --- a/deps/v8/agents/prompts/templates/README.md +++ /dev/null @@ -1,17 +0,0 @@ -# Prompt Templates - -These are prompt snippets that can be used independently or added to a base -prompt to provide specific context and functionality. - -They can be imported by a GEMINI.md file with the `@` syntax: - -```src/GEMINI.md -@agents/prompts/common.md -@agents/prompts/templates/ -``` - -or used standalone: - -```src/GEMINI.md -@agents/prompts/templates/ -``` diff --git a/deps/v8/agents/prompts/templates/modular.md b/deps/v8/agents/prompts/templates/modular.md index 98f3d4632463..144e1f539b00 100644 --- a/deps/v8/agents/prompts/templates/modular.md +++ b/deps/v8/agents/prompts/templates/modular.md @@ -1,9 +1,9 @@ -# Gemini Workspace for V8 +# V8 Agent Workspace -This is the workspace configuration for V8 when using Gemini. +This is the workspace configuration for V8 coding agents (`jetski-cli`). For understanding V8 concepts and structure, refer to the -[v8-understanding](agents/skills/v8-understanding/SKILL.md) skill. +[v8-understanding](/agents/skills/v8-understanding/SKILL.md) skill. Some hints: @@ -14,26 +14,15 @@ Some hints: - V8 is providing support for running JavaScript and WebAssembly on the web. As such, it is critical to aim for best possible performance when optimizing V8. -## Subagents Setup +## Skills & Rules Setup -To use the subagents in this repository, you need to run the appropriate -installation script depending on your environment: +To install workspace skills and rules: -- **For Gemini CLI**: Run `vpython3 agents/scripts/install_for_gemini_cli.py` to - generate the subagent files in `.gemini/agents/`. - **For Jetski**: Run `vpython3 agents/scripts/install_for_jetski.py` to create - symlinks in `.agents/agents/`. - -## Workspace Subagents - -Detailed information has been moved to specialized subagents in -`agents/agents/`. Use them on demand: - -- **Researcher**: Explores the codebase and finds information. See - `agents/agents/researcher/`. -- **Builder**: Compiles V8. See `agents/agents/builder/`. -- **Tester**: Runs tests and benchmarks. See `agents/agents/tester/`. -- **Debugger**: Investigates crashes using GDB. See `agents/agents/debugger/`. + symlinks in `.agents/`. +- **For GitHub Copilot CLI**: Run + `vpython3 agents/scripts/install_for_copilot_cli.py` to install repository + instructions and compatible rules/skills in `.github/`. ## Workspace Skills & Rules @@ -46,11 +35,12 @@ General guidance and reference information are available as skills or rules: - **Testing**: Detailed guide for running and interpreting tests. See [v8-testing](/agents/skills/v8-testing/SKILL.md). - **Best Practices**: Common pitfalls and fix proposal guidelines. See - [v8_best_practices](/agents/rules/v8-best-practices.md). + [v8-best-practices](/agents/rules/v8-best-practices.md). - **Setup**: Handles missing dependencies and configuration for V8 tools. See [v8-setup](/agents/skills/v8-setup/SKILL.md). -- **Git CL Conventions**: Commit message format and usage. See - [git_cl](/agents/rules/git-cl.md). +- **Git Commit & CL Conventions**: Commit message format and `git cl` usage. See + [git-commit](/agents/rules/git-commit.md) and + [git-cl](/agents/rules/git-cl.md). - **Torque**: Expert guidance for Torque. See [torque](/agents/skills/torque/SKILL.md). - **Debugging Workflow**: Guide for issue-based debugging. See @@ -72,14 +62,13 @@ General guidance and reference information are available as skills or rules: - Otherwise, follow [Chromium's C++ style guide](https://chromium.googlesource.com/chromium/src/+/main/styleguide/styleguide.md). - Use `git cl format` to automatically format your changes. -- Follow [git_cl](/agents/rules/git-cl.md) for commit conventions. +- Follow [git-commit](/agents/rules/git-commit.md) and + [git-cl](/agents/rules/git-cl.md) for commit conventions. - For best practices and common pitfalls, see - [v8_best_practices](/agents/rules/v8-best-practices.md). + [v8-best-practices](/agents/rules/v8-best-practices.md). ## Agent Framework -- **Mandatory Orchestration**: For any task in V8, the agent MUST act as an - Orchestrator and use the specialized subagents defined in `agents/agents/`. -- Follow the rules in `agents/rules/framework.md` and - `agents/rules/execution_constraints.md`. -- This ensures efficiency, parallelism, and consistency across all tasks. +- Follow the rules in + [execution-constraints](/agents/rules/execution-constraints.md) for background + execution, subagent delegation, and workspace isolation. diff --git a/deps/v8/agents/rules/debugging.md b/deps/v8/agents/rules/debugging.md index c3f06ef312b4..045482c7b0fe 100644 --- a/deps/v8/agents/rules/debugging.md +++ b/deps/v8/agents/rules/debugging.md @@ -1,91 +1,47 @@ --- name: debugging-rule -trigger: always_on +trigger: model_decision +description: Guidelines and guardrails for debugging V8 crashes, preserving reproducers, and running GDB --- -# Mandatory Debugging Workflow (ORCHESTRATION ONLY) +# Debugging Workflow Guidelines -When tasked with debugging a crash or investigating unexpected behavior, the -main agent **MUST** adhere to the following strict constraints: +When tasked with debugging a crash or investigating unexpected behavior, balance +direct technical investigation with background execution and targeted +delegation: -## 1. Role Restriction: Orchestrator Only +## 1. Execution & Parallelism -- Delegate execution of heavy technical investigation tools to specialized - subagents. -- Use subagents when running GDB (`gdb-mcp`). -- Delegate extensive searches or reading large C++ files to subagents. -- Your sole job is to **Orchestrate**, **Delegate**, and **Synthesize**. -- **Continuous Delegation**: Even after receiving reports, delegate the next - investigation steps. Do not take over. -- **Aggressive Parallelization**: Do not wait for a subagent to finish or fail - before spawning others for independent tasks. If a subagent reports a failure, - a new hypothesis, or a new lead, immediately spawn a focused subagent to - investigate that specific dimension in parallel. -- **User Interface**: Act strictly as the interface to the user. Keep them - informed of high-level certainties. You may provide brief status updates on - running agents. -- **Naming**: Do not refer to subagents by specific titles (e.g., "Spec Expert") - in user communications. Use generic descriptions of the inquiry instead. +- **Start Builds Asynchronously**: Kick off required builds (`gm.py`) in the + background immediately and begin reading the reproducing script, stack trace, + and relevant C++ code while the build runs. +- **Direct Investigation Default**: For tightly coupled compiler, GC, or runtime + invariants, read the relevant C++ files (via `code_search` and `view_file`) + and run GDB (`gdb-mcp` or `d8`) directly to keep full context in a single + loop. +- **Targeted Subagent Delegation**: Spawn subagents (`self` or + `research-google`) when investigating genuinely orthogonal hypotheses, + performing broad git blame/history archeology, or running independent test + suites in parallel. +- **GDB Resource Management**: Avoid running multiple concurrent GDB sessions on + the same binary/build directory unless they are testing independent execution + paths. -## 2. Mandatory First Actions (Three Parallel Tracks) +## 2. Reproducer & Triage Guardrails -Upon receiving a debugging task, you MUST immediately initialize the following -tracks in parallel: - -### Track A: Heavy Infrastructure - -- Start building (`gm.py`) and preparing for runtime analysis (`gdb-mcp` or - `rr`) immediately. - -### Track B: Conceptual Triage - -- **JS Source Reading**: Analyze the reproducing JS script to identify language - features (e.g., closures, `eval`, TDZ) and runtime flags/hints. - **Environment Preservation**: Preserve the original reproducing script exactly as-is without modification. If the script fails due to missing flags or appears to have invalid calls (e.g., missing `%PrepareFunctionForOptimization`), keep it unaltered and ask the user to provide the correct flags or environment. Create scratch copies for minimization or testing if needed. -- **Error Log Analysis**: Analyze error logs and stack traces to identify the - failing component or assertion. - -### Track C: Static Research & Eager Delegation - -- **V8/Spec Exploration**: Use your internal knowledge to start reading relevant - V8 C++ code (via `code_search`) and consulting ECMAScript spec requirements - simultaneously. -- **Work Branching**: PROACTIVELY spawn subagents (e.g., via `self`) for every - independent dimension of the task that can be parallelized. +- **Error Log & Source Triage**: Analyze the reproducing JS script, runtime + flags, and assertion stack traces early to narrow down the failing subsystem. -## 3. Iterative Concept Discovery & Overlap Analysis +## 3. Synthesis & Communication -During investigation (especially via GDB or subagent reports): - -- **Continuous Discovery**: If you encounter a new internal concept, spawn a - subagent to research it immediately. -- **Overlap & Re-evaluation**: Actively check for overlaps between concepts. - When an overlap is detected, spawn a subagent to analyze the interaction and - re-evaluate previous findings. - -## 4. Synthesis & Communication - -- **Proactive Updates**: Keep the user informed of key milestones (e.g., triage - results, parallel task status). -- **Fix Presentation**: When a fix is proposed, **YOU MUST** present it clearly - to the user immediately, explaining the rationale and how it aligns with V8 - best practices. +- **Fix Presentation**: When a fix is proposed, present it clearly to the user, + explaining the root cause, rationale, and how it aligns with V8 best + practices. - **Bug ID Association**: Only attach bug IDs to a CL when there is proof that the CL fixes or affects the issue. - -## 5. Subagent Coordination & Anti-Duplication - -- **Centralized Routing**: The main agent MUST monitor subagent tasks to prevent - duplicate investigations. -- **Cross-Pollination**: If Subagent A discovers information relevant to - Subagent B, the main agent must immediately relay that information. -- **Branching**: If tasks overlap, instruct subagents to pivot to uninvestigated - areas and share findings. -- **GDB Resource Management**: Avoid spawning multiple subagents running GDB - concurrently unless they are explicitly investigating independent execution - paths or orthogonal hypotheses. diff --git a/deps/v8/agents/rules/execution-constraints.md b/deps/v8/agents/rules/execution-constraints.md index 28978b1e4367..13a860d1ed81 100644 --- a/deps/v8/agents/rules/execution-constraints.md +++ b/deps/v8/agents/rules/execution-constraints.md @@ -19,10 +19,25 @@ To ensure efficient operation and prevent resource waste: content or guidance if a resource is inaccessible through available tools (like Buganizer MCP). -04. **Mandatory Orchestration**: For any complex task or project in V8, the - agent MUST act as an Orchestrator and use the multi-layered skill framework - defined in `agents/skills/`. Break down tasks and delegate to subagents to - maximize parallelism. Avoid sequential execution of independent tasks. +04. **Pragmatic Parallelism & Subagent Isolation**: + + - **Never wait idle on builds/tests**: Start slow operations (`gm.py` builds + or test suites) asynchronously in the background while reading code or + analyzing reproducers. Once parallel code analysis is complete, stop + calling tools to wait for the automatic completion wakeup rather than + polling `manage_task` or `manage_subagents`. + - **Keep tightly-coupled work in the main agent**: Read C++ files, trace + compiler/GC invariants, and author fixes directly when context needs to be + shared tightly. + - **Delegate independent or context-heavy work**: Prefer `research-google` + (`Workspace: "inherit"`) for read-only codebase, `docs/`, or git history + archeology, and `self` when exploring orthogonal hypotheses or executing + repeatable batch changes that require running commands or editing files. + - **Isolate parallel workspace modifications**: When a `self` subagent or + background assistant needs to build or edit files in parallel, create an + isolated V8 worktree via `agents/scripts/create_worktree.sh ` + (which runs `tools/dev/setup_worktree_build.py` to symlink `gclient` DEPS) + rather than raw `Workspace: "share"`. 05. **Avoid Interactive Pagers**: Always use `--no-pager` or ensure `PAGER=cat` is set when running commands that might produce long output (e.g., diff --git a/deps/v8/agents/rules/framework.md b/deps/v8/agents/rules/framework.md deleted file mode 100644 index a37bbb133860..000000000000 --- a/deps/v8/agents/rules/framework.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -name: framework-rule -trigger: always_on ---- - -# Framework Rule - -For any complex task or project, the agent MUST adhere to the multi-layered -skill framework defined in `.agents/skills/`. - -## Core Directives - -1. **Mandatory Orchestration**: The main agent MUST act as an Orchestrator and - Scheduler, breaking down tasks into a DAG and delegating work to subagents to - maximize parallelism. -2. **Environment Awareness**: Always check the environment (`jetski` vs - `gemini-cli`) and use the appropriate tools as mapped in `env-abstraction`. -3. **Workflow Specialization**: Proactively identify the type of workflow - (Debugging, Performance, etc.) and activate the corresponding specialized - skill. -4. **Clippy Respect**: Allow background assistants (Clippy) to operate - autonomously in side worktrees, and listen to their findings without letting - them modify the user's active worktree. - -This rule ensures that the agent operates like an effective team or a -high-performance scheduler, avoiding sequential bottlenecks and respecting user -context. diff --git a/deps/v8/agents/rules/v8-best-practices.md b/deps/v8/agents/rules/v8-best-practices.md index e9864aab0708..6609c5c88ef9 100644 --- a/deps/v8/agents/rules/v8-best-practices.md +++ b/deps/v8/agents/rules/v8-best-practices.md @@ -44,10 +44,30 @@ When proposing a fix, ensure the code adheres to V8 standards: - **Cleanup Constraint**: Keep diffs small by changing only the code intended for the task. Propose cleanups to nearby code as a separate patch to keep the current change focused. +- **Supported Architectures**: For most changes and bug fixes, it is fine to + omit not officially supported architectures and only implement or fix the main + four: `ia32`, `x64`, `arm`, and `arm64`. Architectures without official Google + support (e.g., `mips64`, `riscv32`, `riscv64`, `s390x`, `ppc64`, `loong64`) + are community-maintained and do not need to be updated unless specifically + requested or targeted. ## General Best Practices -For general best practices regarding formatting, generated files, test -configurations, header names, and forward declarations, refer to Common Pitfalls -& Best Practices section. This rule file focuses on V8-specific fix proposals -and technical guardrails. +- **Always format before committing:** Run `git cl format` before creating a + commit to ensure your code adheres to the style guide. +- **Do not edit generated files:** Files in `out/` are generated by the build + process. Edits should be made to the source files (e.g., `.tq` files for + Torque, `.pdl` for protocol definitions). +- **Match test configuration to build:** Ensure you are running tests against + the correct build type (e.g., run mjsunit from out/x64.debug if you built + x64.debug). +- **Check surrounding code for conventions:** Before adding new code, always + study the existing patterns, naming conventions, and architectural choices in + the file and directory you are working in. +- **Keep related functions together:** When adding a new function, try to insert + it near related functions, to keep similar behaviour close. +- **Don't guess header names:** If you don't know where the definition of a + class or function is, don't try to guess the header name, but search for it + instead. +- **Be careful with forward declarations:** Many types are forward declared; if + you want to use them, you'll need to find the definition. diff --git a/deps/v8/agents/scripts/install_for_copilot_cli.py b/deps/v8/agents/scripts/install_for_copilot_cli.py index 63d2182d27d2..7b7fd8dfe7c0 100644 --- a/deps/v8/agents/scripts/install_for_copilot_cli.py +++ b/deps/v8/agents/scripts/install_for_copilot_cli.py @@ -27,11 +27,6 @@ r"\A(?P---[ \t]*\r?\n(?P.*?)\r?\n---[ \t]*)" r"(?:\r?\n|\Z)", re.DOTALL) COPILOT_INCOMPATIBLE_RULES = { - # Mandates orchestration-only operation through subagent and `gdb-mcp` - # APIs not mapped by this adapter. - "debugging.md", - # Hard-codes Jetski/Gemini CLI behavior and adapter paths. - "framework.md", # Mandates `TAG=agy` and a conversation ID that this adapter cannot # supply, which would land in uploaded CL descriptions. "git-commit.md", @@ -42,10 +37,6 @@ "agent-evaluation-framework", # Mandates a subagent API and model tier not mapped by this adapter. "doc-invalidation-checker", - # Maps only Jetski and Gemini CLI tools. - "env-abstraction", - # Mandates scheduling and delegation APIs not mapped by this adapter. - "orchestrator", # Mandates internal Buganizer, session-context, and delegation APIs not # provisioned or mapped by this adapter. "v8-security-triaging", diff --git a/deps/v8/agents/scripts/install_for_gemini_cli.py b/deps/v8/agents/scripts/install_for_gemini_cli.py deleted file mode 100755 index f34e91904eb9..000000000000 --- a/deps/v8/agents/scripts/install_for_gemini_cli.py +++ /dev/null @@ -1,91 +0,0 @@ -#!/usr/bin/env vpython3 -# Copyright 2026 the V8 project authors. All rights reserved. -# Use of this source code is governed by a BSD-style license that can be -# found in the LICENSE file. -from __future__ import annotations - -import json -from pathlib import Path -import yaml - -FILE_PATH = Path(__file__).resolve() -repo_root = FILE_PATH.parents[2] -src_dir = FILE_PATH.parents[1] / "agents" -dest_dir = repo_root / ".gemini" / "agents" - -# 1. Check if .gemini/agents is a symlink -if dest_dir.is_symlink(): - print(f"Removing symlink at {dest_dir}") - dest_dir.unlink() - -dest_dir.mkdir(parents=True, exist_ok=True) - -for item in src_dir.iterdir(): - if not item.is_dir(): - continue - - agent_json_path = item / "agent.json" - config_yaml_path = item / "config.yaml" - - if not (agent_json_path.exists() and config_yaml_path.exists()): - print(f"Skipping {item.name}: missing agent.json or config.yaml") - continue - - with agent_json_path.open("r") as f: - agent_json = json.load(f) - with config_yaml_path.open("r") as f: - config_yaml = yaml.safe_load(f) - - name = agent_json.get("name") - description = agent_json.get("description") - - custom_agent = config_yaml.get("custom_agent", {}) - system_prompt_sections = custom_agent.get("system_prompt_sections", []) - tool_names = custom_agent.get("tool_names", []) - - # Concatenate system prompt sections - body = "" - for section in system_prompt_sections: - body += f"# {section.get('title')}\n\n{section.get('content')}\n\n" - - # Map tools to Gemini CLI names - gemini_tools = [] - for t in tool_names: - if t == "view_file": - gemini_tools.append("read_file") - elif t == "run_command": - gemini_tools.append("run_shell_command") - elif t == "list_dir": - gemini_tools.append("list_directory") - elif t == "search_web": - gemini_tools.append("google_web_search") - elif t == "call_mcp_tool": - pass - else: - gemini_tools.append(t) - - # Create frontmatter - frontmatter = { - "name": name, - "description": description, - "kind": "local", - "tools": gemini_tools, - "model": "inherit" - } - - dest_file = dest_dir / f"{name}.md" - with dest_file.open("w") as f: - f.write("---\n") - yaml.dump(frontmatter, f, default_flow_style=False) - f.write("---\n") - f.write(body) - - print(f"Installed {name}.md for Gemini CLI") - -gemini_md_path = repo_root / "GEMINI.md" -if not gemini_md_path.exists(): - with gemini_md_path.open("w") as f: - f.write("@[Modular Rules](agents/prompts/templates/modular.md)\n") - print(f"Created {gemini_md_path}") -else: - print(f"Skipping {gemini_md_path} creation since it already exists.") diff --git a/deps/v8/agents/scripts/install_for_jetski.py b/deps/v8/agents/scripts/install_for_jetski.py index ea9d9b1cd932..09c7d42df73d 100755 --- a/deps/v8/agents/scripts/install_for_jetski.py +++ b/deps/v8/agents/scripts/install_for_jetski.py @@ -32,11 +32,20 @@ def create_symlink(src: Path, dest: Path): # 2. Ensure .agents is a real directory agents_dest.mkdir(parents=True, exist_ok=True) -# Cleanup top-level dead symlinks in .agents/ (e.g. legacy extensions) +# Cleanup top-level dead symlinks and legacy subdirectories in .agents/ for item in agents_dest.iterdir(): if item.is_symlink() and not item.exists(): print(f"Removing dead top-level symlink {item}") item.unlink() + elif (item.is_dir() and not item.is_symlink() and + not (agents_src / item.name).exists()): + for sub_item in item.iterdir(): + if sub_item.is_symlink() and not sub_item.exists(): + print(f"Removing dead symlink {sub_item}") + sub_item.unlink() + if not any(item.iterdir()): + print(f"Removing empty legacy directory {item}") + item.rmdir() # 3. Process top-level items in agents/ for item in agents_src.iterdir(): @@ -46,7 +55,7 @@ def create_symlink(src: Path, dest: Path): dest_item = agents_dest / item.name - if item.name not in ["agents", "skills", "rules", "plugins"]: + if item.name not in ["skills", "rules", "plugins"]: # For other items, symlink directly if not dest_item.exists(): create_symlink(item, dest_item) @@ -77,10 +86,31 @@ def create_symlink(src: Path, dest: Path): if not dest_sub.exists(): create_symlink(shared_git_cl_helper, dest_sub) +modular_rule = "@[Modular Rules](agents/prompts/templates/modular.md)" gemini_md_path = repo_root / "GEMINI.md" if not gemini_md_path.exists(): with gemini_md_path.open("w") as f: - f.write("@[Modular Rules](agents/prompts/templates/modular.md)\n") + f.write(f"{modular_rule}\n") print(f"Created {gemini_md_path}") else: - print(f"Skipping {gemini_md_path} creation since it already exists.") + content = gemini_md_path.read_text() + updated = False + if "@agents/prompts/templates/modular.md" in content: + content = content.replace("@agents/prompts/templates/modular.md", + modular_rule) + updated = True + if "@agents/prompts/common.md" in content: + if modular_rule in content: + content = content.replace("@agents/prompts/common.md\n", "") + content = content.replace("@agents/prompts/common.md", "") + else: + content = content.replace("@agents/prompts/common.md", modular_rule) + if not content.endswith("\n"): + content += "\n" + updated = True + + if updated: + gemini_md_path.write_text(content) + print(f"Upgraded legacy rules in {gemini_md_path}") + else: + print(f"Skipping {gemini_md_path} creation since it already exists.") diff --git a/deps/v8/agents/skills/README.md b/deps/v8/agents/skills/README.md index 6c207a1d5f83..1a4af1e17eb2 100644 --- a/deps/v8/agents/skills/README.md +++ b/deps/v8/agents/skills/README.md @@ -2,29 +2,25 @@ This directory contains specialized Agent Skills for V8 development. -Unlike general context files, skills are shared, "on-demand" expertise that -multiple AI agents (such as Gemini CLI, Claude, GitHub Copilot, etc.) can -activate when relevant to your request. +Unlike general context files, skills are shared, "on-demand" expertise that AI +agents (such as Jetski, Claude, GitHub Copilot, etc.) can activate when relevant +to your request. ## How to Use -To use a skill, you must first install it into your workspace. Creating a -symlink is preferred so that the skill stays up-to-date when you sync your local +To use skills in Jetski, install them into your workspace `.agents/skills/` +directory via symlinks so they stay up-to-date when you sync your local checkout: ```bash -gemini skills link agents/skills/ --scope workspace +vpython3 agents/scripts/install_for_jetski.py ``` -Once installed, your agent (e.g. the Gemini CLI when using `.gemini/skills`) -will automatically detect when a skill is relevant to your request and ask for -permission to activate it. +Once installed, your agent will automatically detect when a skill is relevant to +your request and read its `SKILL.md` instructions. ## Contributing New skills should be self-contained within their own directory under `agents/skills/`. Each skill requires a `SKILL.md` file at its root with a name and description in the YAML frontmatter. - -Note that gemini-cli comes preloaded with a "skill creator" skill. Most skills -can be written or improved by asking gemini to do so. diff --git a/deps/v8/agents/skills/env-abstraction/SKILL.md b/deps/v8/agents/skills/env-abstraction/SKILL.md deleted file mode 100644 index cf9ace54b5b9..000000000000 --- a/deps/v8/agents/skills/env-abstraction/SKILL.md +++ /dev/null @@ -1,57 +0,0 @@ ---- -name: env-abstraction -description: Handles abstraction of environment-specific commands between Jetski and Gemini-CLI. Use when switching execution context between local terminal environments. Do not use for debugging logic issues. ---- - -# Environment Abstraction Skill - -This skill provides a layer of abstraction over environment-specific tools and -commands, allowing skills to be reused across different platforms like `jetski` -and `gemini-cli`. - -## Core Principles - -1. **Decoupling**: Keep tool calls independent from platform specific - implementations inside general workflow skills. -2. **Detection**: Determine the environment at startup (e.g., via environment - variables or tool availability). -3. **Mapping**: Map abstract actions to concrete commands or tool calls based on - the environment. - -## Environment Definitions - -### Jetski Environment - -- **Characteristics**: Rich set of specialized tools (e.g., `code_search`, - `moma_search`, `gdb-mcp`, `v8-utils`). -- **Usage**: Prefer specialized tools over generic shell commands to maximize - efficiency and respect workspace constraints (e.g., avoid heavy searches in - large workspaces). - -### Gemini-CLI Environment - -- **Characteristics**: May rely more on standard shell commands or a different - set of MCP servers. -- **Usage**: Fall back to standard tools like `grep`, `find`, or standard `gdb` - via `run_command` if specialized Jetski tools are unavailable. - -## Abstract Action Mapping - -When performing common actions, refer to this mapping to choose the correct -tool: - -| Abstract Action | Jetski Implementation | Gemini-CLI Implementation (Fallback) -| | :--- | :--- | :--- | | **Code Search** | `code_search` | `grep_search` (if -outside Google3) or standard `grep` | | **File Search** | `find_by_name` (if -safe) | Standard `find` or `fd` | | **Debugging** | `gdb-mcp` | Standard `gdb` -via `run_command` | | **Building** | `tools/dev/gm.py` (use -`use_remoteexec=true`) | `tools/dev/gm.py` | | **Testing** | -`tools/run-tests.py` | `tools/run-tests.py` | | **Starting Agents** | -`invoke_subagent` (tool) | `agentapi new-conversation` (CLI) | - -## Implementation Guidelines - -- When writing or updating skills, refer to actions by their abstract names. -- Check for the existence of specialized tools before falling back to generic - commands. -- Document any environment-specific assumptions in the skill file. diff --git a/deps/v8/agents/skills/orchestrator/SKILL.md b/deps/v8/agents/skills/orchestrator/SKILL.md deleted file mode 100644 index 8f4d03e20f76..000000000000 --- a/deps/v8/agents/skills/orchestrator/SKILL.md +++ /dev/null @@ -1,189 +0,0 @@ ---- -name: orchestrator -description: Core skill for task scheduling and multi-agent coordination in V8 development. Use for any multi-step workflow or complex task. Do not use for simple linear tasks. ---- - -# Orchestrator Skill - -This skill defines the behavior of the Main Agent acting as an Orchestrator and -Scheduler. It is mandatory for all complex tasks to ensure efficiency, -parallelism, and correct dependency handling. - -## Core Responsibilities - -1. **Task Breakdown & DAG Construction**: - - - Analyze the high-level goal and break it down into discrete tasks. - - Model tasks as a Directed Acyclic Graph (DAG) where edges represent - dependencies. - - Maintain the DAG in the `task.md` artifact or equivalent representation. - -2. **Scheduling & Execution**: - - - Identify tasks with satisfied dependencies (in-degree 0) that are ready for - execution. - - Delegate ALL ready tasks to specialized subagents. The Orchestrator agent - MUST NOT execute tasks (like running builds, tests, or benchmarks) - directly. - - Maximize parallelism by running independent tasks concurrently. - -3. **Priority & Resource Management**: - - - Assign priorities to tasks. Critical path tasks get highest priority. - - Monitor resource usage (context window, active subagents) and throttle - execution if necessary. - - Handle priority inversion: if a high-priority task is blocked on a - low-priority task, elevate the low-priority task. - -4. **Communication & Synthesis**: - - - Act as the central message broker between subagents. - - Cross-pollinate information: if Subagent A finds something relevant to - Subagent B's task, relay it immediately. - - Synthesize results from multiple streams to form a coherent picture for the - user. - -## Rules of Operation - -- **Autonomy with Oversight**: Subagents operate with high autonomy ("YOLO" - mode) but must report state changes and critical findings to the Orchestrator. -- **No Independent Branching**: Subagents cannot spawn new top-level workstreams - without Orchestrator approval. They can request the Orchestrator to add new - tasks to the DAG. -- **Continuous Re-evaluation**: As new facts emerge, the Orchestrator must - re-evaluate the DAG, potentially canceling, pausing, or reprioritizing tasks. -- **Update Timer**: The Orchestrator agent MUST set a 30-second recurring timer - using the `schedule` tool to provide synthesized updates to the user, - preventing long periods of silence. -- **Responsive Termination**: If the user issues a 'stop' command, immediately - initiate shutdown of all active subagents and background tasks. Hard-kill any - subagents that do not terminate gracefully within 30 seconds. -- **Concept Escalation**: Subagents MUST explicitly highlight unfamiliar - concepts in their reports. The Orchestrator MUST spawn a dedicated inquiry for - these concepts immediately. -- **Eager Subagent Escalation**: Subagents MUST proactively and eagerly ask the - Orchestrator for help or context when encountering unfamiliar concepts or - potential blockers, rather than getting bogged down in localized research. -- **Ambiguous Targets**: If a task target (e.g., a benchmark name, flag, or file - path) is ambiguous or not found in standard lists, the Orchestrator MUST - immediately ask the user for clarification instead of guessing or performing - extensive sequential searches. -- **Inaccessible Attachments/Resources**: If the intake phase detects that - critical attachments (e.g., POC script, flags, or reproduction steps) from a - bug report are inaccessible or redacted, the Orchestrator **MUST** stop - immediately and ask the user to provide them manually. -- **Resumption After Information Provision**: Once the user provides the missing - information, the Orchestrator **MUST** immediately restart the affected - intake/research phase with the new data to ensure all subsequent technical - steps (expert identification, reproduction, etc.) are based on complete - information. -- **Domain Context Awareness**: Do NOT assume terms in a task description refer - to the environment (e.g., assuming "WSL" means the OS) if they could be - domain-specific (e.g., a benchmark name). Verify with domain documentation or - tools first before taking action. -- **Forced Parallelization**: The Orchestrator MUST identify at least two - parallel tracks for any complex task before proceeding with execution. Do not - perform work sequentially if it can be delegated to subagents to maximize - concurrency. -- **Utilize Wait Time**: If a task involves a long wait (e.g., a V8 build), the - Orchestrator MUST schedule independent research or analysis tasks to run in - parallel. Do not let the main agent or subagents go idle or do trivial work if - there are unanswered questions. -- **Environment-Aware Delegation**: When delegating tasks to subagents, use the - appropriate method for the current environment. In `gemini-cli`, use - `agentapi new-conversation` (CLI) instead of the `invoke_subagent` tool, which - may not be available. Make sure to pass critical environment variables - explicitly to the subagent in its prompt, specifically passing `PATH` - containing `depot_tools` and any settings for `remoteexec` (siso). -- **Subagent Isolation Enforcement**: When delegating tasks that involve - modifying code, building, or running tests that could affect the workspace - state, the Orchestrator MUST ensure the task is scheduled in an isolated - worktree. Do not let subagents operate on the main workspace for destructive - or environment-polluting tasks. -- **Post-Task Self-Reflection & Divergence Analysis**: After the task is - complete: - - **Analyze Process**: Review the session logs. - - **Divergence Analysis**: If the final landed fix/result differs from the - agent's initial proposal: - - Identify *why* the initial proposal was rejected or modified. - - Determine if the agent was "too hasty" or missed critical invariants. - - Trace the logical gap in the investigation. - - **Process Refinement**: Formulate proposals to update skills based on - lessons learned, and implement them in separate, dedicated CLs. -- **Workspace and Branch Management**: Always base new branches on a clean - upstream (e.g., `origin/main`). Avoid creating spurious CLs or polluting - existing CLs with unrelated changes. Use isolated worktrees for tasks that - modify the workspace state. - -## Specialized Subagents - -The Orchestrator delegates tasks to the following specialized subagents: - -- **`researcher`**: Prompted to find relevant code, documentation, and - information in the V8 codebase and the web. Reports findings with file paths - and line numbers. -- **`builder`**: Prompted to compile V8 for specified configurations. Can read - files and search code to understand build errors. -- **`tester`**: Prompted to run tests and benchmarks and report results. Can - read files and search code to understand test failures. -- **`debugger`**: Prompted to investigate crashes and unexpected behavior using - GDB and other tools. - -## Advanced Scheduling & DAG Management - -- **Directed Acyclic Graph (DAG)**: The Orchestrator must maintain the task list - as a DAG to handle dependencies correctly. -- **Dynamic Re-planning**: When a subagent discovers new information or a task - fails, the Orchestrator must dynamically update the DAG (adding, removing, or - reordering tasks). -- **Eager Parallelism**: Identify independent branches of the DAG and execute - them in parallel by spawning multiple subagents or background tasks. - -## Handling Priority Inversion - -- **Priority Inheritance**: If a high-priority task (e.g., fixing a blocker) - depends on the completion of a low-priority task (e.g., running a clean build - or documentation), the low-priority task must temporarily inherit the higher - priority to resolve the dependency. -- **Resource Contention Awareness**: Ensure that low-priority tasks do not hold - onto exclusive resources (like GDB sessions or specific build targets) needed - by high-priority tasks. - -## Fair Scheduling & Starvation Prevention - -- **Task Aging**: To prevent low-priority tasks from being indefinitely starved - by a stream of high-priority tasks, increase their priority based on the time - they have spent in the queue. -- **Guaranteed Resource Allocation**: Allocate a small but fixed percentage of - resources or agent attention to lower-priority maintenance or exploratory - tasks. - -## Communication and Synthesis Rules - -- **Concise User Communication**: Do not over-explain assumptions or potential - confusions to the user. State what the plan is based on the interpreted - context and proceed. Avoid wordy justifications. - -- **Structured Reporting**: Subagents must report results in a structured - format, highlighting: - - - Key findings or answers to the assigned question. - - Blockers or new unfamiliar concepts. - - Proposed next steps. - -- **Synthesis Before Escalation**: The Orchestrator must not simply pass - subagent reports to the user. It must synthesize the reports from all active - tasks into a coherent state summary and present only the high-level - certainties and decisions to the user. - -- **Proactive Context Sharing**: The Orchestrator must relay relevant - discoveries between subagents working on overlapping or dependent tasks to - avoid duplicate work. - -## Analogies to Operating System Schedulers - -- **Task = Process/Thread**: A discrete unit of work. -- **Dependencies = Synchronization Primitives**: Tasks wait on other tasks to - complete (join). -- **Orchestrator = Kernel Scheduler**: Decides what runs when and on which "CPU" - (subagent). diff --git a/deps/v8/agents/skills/subagent-env-passing/SKILL.md b/deps/v8/agents/skills/subagent-env-passing/SKILL.md deleted file mode 100644 index 874ebdbec47f..000000000000 --- a/deps/v8/agents/skills/subagent-env-passing/SKILL.md +++ /dev/null @@ -1,33 +0,0 @@ ---- -name: subagent-env-passing -description: Workflow for passing environment variables (like PATH) from the Orchestrator to subagents. Use when spawning subagents that need specific environment variables. Do not use for standard subagent execution. ---- - -# Subagent Environment Passing Skill - -This skill documents how to ensure subagents have access to the correct -environment variables (such as `PATH`) when working in isolated environments -like worktrees. - -## Workflow - -1. **Retrieve Environment**: The Orchestrator should read the necessary - environment variables from its own context if they are not already known. For - example, run `echo $PATH` to get the current PATH. -2. **Pass to Subagent**: When invoking a subagent, include the environment - variable values in the `Prompt` provided to the subagent. -3. **Instruct Subagent**: Explicitly instruct the subagent to set these - variables in its environment before running tools that depend on them. - -## Example Prompt Snippet - -``` -Please use the following PATH and build settings in your environment: -export PATH=:$PATH -export SISO_PROJECT=rbe-chrome-untrusted - -``` - -Note: If building or running `gm.py`, also ensure that `use_remoteexec = true` -is set in your build config/`args.gn`. You can find the correct `SISO_PROJECT` -in `build/config/siso/.sisoenv`. diff --git a/deps/v8/agents/skills/v8-regression-testing/SKILL.md b/deps/v8/agents/skills/v8-regression-testing/SKILL.md index 18093db9cc55..9e4ab2c768b0 100644 --- a/deps/v8/agents/skills/v8-regression-testing/SKILL.md +++ b/deps/v8/agents/skills/v8-regression-testing/SKILL.md @@ -104,7 +104,7 @@ think you know about the bug, and deepen your understanding. ______________________________________________________________________ -## Synctatic Principles of a Good Regression Test +## Syntactic Principles of a Good Regression Test ### 1. Minimal & "Leaf" Compiler Flags @@ -137,6 +137,11 @@ Avoid default fuzzer variable and function names (`__f_0`, `__v_10`, `v17`, required to reproduce the issue. - Do not include catch-all blocks (`catch (e) {}`) or dummy wrapper functions (`__wrapTC`) unless they are semantically required to trigger the crash path. +- **Do not explicitly load `mjsunit.js`**: `mjsunit` tests run via + `tools/run-tests.py` automatically include `test/mjsunit/mjsunit.js`. Never + include `d8.file.execute('test/mjsunit/mjsunit.js')` in the test file itself. + (When executing the test manually via `d8`, pass `test/mjsunit/mjsunit.js` on + the command line instead). ### 4. Deterministic Optimization Control @@ -148,3 +153,12 @@ Avoid default fuzzer variable and function names (`__f_0`, `__v_10`, `v17`, - `%OptimizeFunctionOnNextCall(foo);` or `%OptimizeMaglevOnNextCall(foo);` - Make sure `--allow-natives-syntax` is included in the Flags header when using percent (`%`) intrinsics. + +### 5. Rely on Test Runner Variants for Execution Coverage + +- V8's test runner automatically executes test suites across different variants + (such as baseline execution, optimizing tiers, and stress modes). +- Avoid manually forcing execution across multiple tiers or duplicating + invocations solely to cover different compiler pipelines, unless the test + specifically exercises tier-up dynamics, on-stack replacement, or + deoptimization transitions between them. diff --git a/deps/v8/agents/skills/v8-security-triaging/SKILL.md b/deps/v8/agents/skills/v8-security-triaging/SKILL.md index 6e2e40f09b6c..0144f72d27cf 100644 --- a/deps/v8/agents/skills/v8-security-triaging/SKILL.md +++ b/deps/v8/agents/skills/v8-security-triaging/SKILL.md @@ -122,7 +122,9 @@ Buganizer. - **Version and Commit Identification**: Always retrieve the current V8 version number from `src/utils/version.h` and the specific git hash using `git rev-parse HEAD`. Prioritize referencing specific git hashes over generic - terms like "HEAD" in triage reports. + terms like "HEAD" in triage reports. For any commit referenced in the report, + retrieve its Gerrit changelist link (from `Reviewed-on:` in + `git log -n 1 --format=%b `). - **Attachment Check**: Ensure the subagent checks for mentioned files (e.g., "poc.html", "crash.log") that are NOT in the attachments list. If retrieval of an attachment via MCP tools fails, the subagent **MUST** use the @@ -218,7 +220,9 @@ Draft a concise synthesis based on verified subagent findings. [triaging.md](../../../docs/security/triaging.md) and Chromium guidelines. - **Introduced In / Regression Range**: Provide the commit or version where - the vulnerability was introduced, if identifiable. + the vulnerability was introduced, if identifiable. Always include a + clickable markdown link to the commit's Gerrit changelist (e.g. + `[commit ](https://chromium-review.googlesource.com/c/v8/v8/+/)`). - **Rationale**: Explain the technical conclusion. For sandbox bypasses, explicitly state if it violates the threat model. @@ -226,8 +230,8 @@ Draft a concise synthesis based on verified subagent findings. - **Local Reproduction Findings**: Follow the structure and mandatory fields defined in the **Classification Guidelines** of `v8-poc-classification`. Ensure all technical data (Status, Reproduction command, Result, Build - (including version from `src/utils/version.h` and git hash), Verified - Impact, and optional GDB Backtrace) is included here. + (including version from `src/utils/version.h` and git hash with a Gerrit + link), Verified Impact, and optional GDB Backtrace) is included here. - **Proposed Owner**: Based on expert discovery. Include a very short (half sentence) explanation for the choice (e.g., "author of affected code", @@ -299,6 +303,8 @@ Finalize the session by securing artifacts and cleaning up the environment. flag (`--run-as-[sandbox]-security-poc`)? - [ ] **Mandatory Data**: Are the V8 version and git hash included in the Build description? +- [ ] **Gerrit Links**: Are all referenced commits and CLs (introduction CL, + build commit, etc.) linked to their corresponding Gerrit changelists? - [ ] **Formatting**: Are there double line breaks between all top-level bulleted list items? Are sub-bullets indented by at least four spaces without internal double line breaks? diff --git a/deps/v8/agents/skills/v8-structure/SKILL.md b/deps/v8/agents/skills/v8-structure/SKILL.md index 17b3762b4ffc..ce65e7ffd436 100644 --- a/deps/v8/agents/skills/v8-structure/SKILL.md +++ b/deps/v8/agents/skills/v8-structure/SKILL.md @@ -26,9 +26,9 @@ components. via macro assemblers, higher level codegen via CodeStubAssembler, definitions of machine code metadata like safepoint tables and source position tables, and `compiler.cc` which defines entry points into the - compilers. This contains subdirectories for architecture specific - implementations, which should be kept in sync with each other as much as - possible. + compilers. This contains subdirectories for architecture-specific + implementations (only the main officially supported architectures `ia32`, + `x64`, `arm`, and `arm64` need to be maintained for most changes). - `src/common/`: Common definitions and utilities. - `src/compiler/`: The TurboFan optimizing compiler, including the Turboshaft CFG compiler. @@ -57,8 +57,9 @@ components. - `src/profiler/`: The in-process profiler implementations, for heap snapshots, allocation tracking, and a sampling CPU profiler. - `src/regexp/`: The regular expression implementation. This contains - subdirectories for architecture specific implementations, which should be - kept in sync with each other as much as possible. + subdirectories for architecture-specific implementations (as with codegen, + only the main officially supported architectures `ia32`, `x64`, `arm`, and + `arm64` need to be maintained for most changes). - `src/runtime/`: C++ functions that can be called from JavaScript at runtime. - `src/sandbox/`: The implementation of the sandbox, which is a security feature that attempts to limit V8 memory operations to be within a single @@ -102,3 +103,11 @@ components. - `docs/snapshot/`: Snapshot and serialization. - `docs/torque/`: Torque language and builtins. - `docs/wasm/`: WebAssembly implementation. + +## Supported Architectures + +For most changes and bug fixes, it is fine to omit not officially supported +architectures and only implement or fix the main four: `ia32`, `x64`, `arm`, and +`arm64`. Architectures without official Google support (e.g., `mips64`, +`riscv32`, `riscv64`, `s390x`, `ppc64`, `loong64`) are community-maintained and +do not need to be updated unless specifically requested or targeted by the task. diff --git a/deps/v8/agents/vpython.toml b/deps/v8/agents/vpython.toml new file mode 100644 index 000000000000..d9f6ab4bf582 --- /dev/null +++ b/deps/v8/agents/vpython.toml @@ -0,0 +1,40 @@ +# Copyright 2026 the V8 project authors. All rights reserved. +# Use of this source code is governed by a BSD-style license that can be +# found in the LICENSE file. + +requires-python = '>=3.11,<3.12' +dependencies = [ + 'pyyaml==5.4.1+chromium.1', + 'tabulate==0.9.0', + 'platformdirs==4.9.2', + 'mcp==1.9.4', + 'pydantic==2.11.7', + 'starlette==0.47.1', + 'anyio==4.9.0', + 'sniffio==1.3.0', + 'idna==3.4', + 'typing-extensions==4.13.2', + 'httpx-sse==0.4.1', + 'httpx==0.28.1', + 'certifi==2025.4.26', + 'httpcore==1.0.9', + 'h11==0.16.0', + 'pydantic-settings==2.10.1', + 'python-multipart==0.0.20', + 'sse-starlette==2.4.1', + 'uvicorn==0.35.0', + 'annotated-types==0.7.0', + 'pydantic-core==2.33.2', + 'typing-inspection==0.4.1', + 'python-dotenv==1.1.1', + 'click==8.0.3', + 'colorama==0.4.1', + 'perfetto==0.16.0', + 'protobuf==6.33.5', + 'pandas==2.2.3+chromium.1', + 'numpy==1.23.5+chromium.4', + 'python-dateutil==2.9.0', + 'pytz==2025.2', + 'six==1.17.0', + 'tzdata==2025.2' +] diff --git a/deps/v8/agents/vpython.toml.uv.lock b/deps/v8/agents/vpython.toml.uv.lock new file mode 100644 index 000000000000..7c421e82d945 --- /dev/null +++ b/deps/v8/agents/vpython.toml.uv.lock @@ -0,0 +1,270 @@ +annotated-types==0.7.0 \ + --hash=sha256:1f02e8b43a8fbbc3f3e0d4f0f4bfc8131bcb4eebe8849b8e5c773f3a1c582a53 \ + --hash=sha256:1f02e8b43a8fbbc3f3e0d4f0f4bfc8131bcb4eebe8849b8e5c773f3a1c582a53 \ + --hash=sha256:1f02e8b43a8fbbc3f3e0d4f0f4bfc8131bcb4eebe8849b8e5c773f3a1c582a53 \ + --hash=sha256:1f02e8b43a8fbbc3f3e0d4f0f4bfc8131bcb4eebe8849b8e5c773f3a1c582a53 \ + --hash=sha256:1f02e8b43a8fbbc3f3e0d4f0f4bfc8131bcb4eebe8849b8e5c773f3a1c582a53 \ + --hash=sha256:1f02e8b43a8fbbc3f3e0d4f0f4bfc8131bcb4eebe8849b8e5c773f3a1c582a53 \ + --hash=sha256:1f02e8b43a8fbbc3f3e0d4f0f4bfc8131bcb4eebe8849b8e5c773f3a1c582a53 \ + --hash=sha256:1f02e8b43a8fbbc3f3e0d4f0f4bfc8131bcb4eebe8849b8e5c773f3a1c582a53 \ + --hash=sha256:cb8e356aea87fe54a7fb5a59e71f508deff791fda0b1a5f1eedffdcc1fe16672 + # via pydantic +anyio==4.9.0 \ + --hash=sha256:428d7a13cbbc94e1c362cded4273280d4e486efe1e518bba067327fb0792514b \ + --hash=sha256:9f76d541cad6e36af7beb62e978876f3b41e3e04f2c1fbf0884604c0a9c4d93c + # via + # httpx + # mcp + # sse-starlette + # starlette +certifi==2025.4.26 \ + --hash=sha256:30350364dfe371162649852c63336a15c70c6510c2ad5015b21c2345311805f3 \ + --hash=sha256:f33ffedf5d31d74f9692dd30f5d8e553027a4e5b407cf931d5c9d5c583bd8fad + # via + # httpcore + # httpx +click==8.0.3 \ + --hash=sha256:353f466495adaeb40b6b5f592f9f91cb22372351c84caeb068132442a4518ef3 \ + --hash=sha256:353f466495adaeb40b6b5f592f9f91cb22372351c84caeb068132442a4518ef3 \ + --hash=sha256:b0a0492d07c8e7e4a88ee153ca6553d357a0746792d6868bfca79dc1a344bb1b + # via uvicorn +colorama==0.4.1 \ + --hash=sha256:758fb3cafa52391ea645703f283afd57f002011140d470793379790398876733 \ + --hash=sha256:758fb3cafa52391ea645703f283afd57f002011140d470793379790398876733 \ + --hash=sha256:758fb3cafa52391ea645703f283afd57f002011140d470793379790398876733 \ + --hash=sha256:f8ac84de7840f5b9c4e3347b3c1eaa50f7e49c2b07596221daec5edaabbd7c48 \ + --hash=sha256:f8ac84de7840f5b9c4e3347b3c1eaa50f7e49c2b07596221daec5edaabbd7c48 \ + --hash=sha256:f8ac84de7840f5b9c4e3347b3c1eaa50f7e49c2b07596221daec5edaabbd7c48 \ + --hash=sha256:f8ac84de7840f5b9c4e3347b3c1eaa50f7e49c2b07596221daec5edaabbd7c48 \ + --hash=sha256:f8ac84de7840f5b9c4e3347b3c1eaa50f7e49c2b07596221daec5edaabbd7c48 \ + --hash=sha256:f8ac84de7840f5b9c4e3347b3c1eaa50f7e49c2b07596221daec5edaabbd7c48 \ + --hash=sha256:f8ac84de7840f5b9c4e3347b3c1eaa50f7e49c2b07596221daec5edaabbd7c48 \ + --hash=sha256:f8ac84de7840f5b9c4e3347b3c1eaa50f7e49c2b07596221daec5edaabbd7c48 \ + --hash=sha256:f8ac84de7840f5b9c4e3347b3c1eaa50f7e49c2b07596221daec5edaabbd7c48 \ + --hash=sha256:f8ac84de7840f5b9c4e3347b3c1eaa50f7e49c2b07596221daec5edaabbd7c48 + # via click +h11==0.16.0 \ + --hash=sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86 \ + --hash=sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86 \ + --hash=sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86 \ + --hash=sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86 \ + --hash=sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86 \ + --hash=sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86 \ + --hash=sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86 \ + --hash=sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86 \ + --hash=sha256:67d7bfdfcac864327f0dc38606322e89b246ffe5f6b4e86c4c9fd5116500f3a5 + # via + # httpcore + # uvicorn +httpcore==1.0.9 \ + --hash=sha256:2d400746a40668fc9dec9810239072b40b4484b640a8c38fd654a024c7a1bf55 \ + --hash=sha256:9b6c124dac46a7e51898765b289fa68480d92c9f26e464d2d6bf1669fa4d03ec + # via httpx +httpx==0.28.1 \ + --hash=sha256:ae442346a10b89fbfeaa174019b1d012a7cc2f957f6b42994dd270154dd25618 \ + --hash=sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad \ + --hash=sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad \ + --hash=sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad \ + --hash=sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad \ + --hash=sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad \ + --hash=sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad \ + --hash=sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad \ + --hash=sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad + # via mcp +httpx-sse==0.4.1 \ + --hash=sha256:2a59b1e5c0558a031568b229d318dca516bc551ab7a311e1d1c5e8a5e8140d6b \ + --hash=sha256:cba42174344c3a5b06f255ce65b350880f962d99ead85e776f23c6618a377a37 \ + --hash=sha256:cba42174344c3a5b06f255ce65b350880f962d99ead85e776f23c6618a377a37 \ + --hash=sha256:cba42174344c3a5b06f255ce65b350880f962d99ead85e776f23c6618a377a37 \ + --hash=sha256:cba42174344c3a5b06f255ce65b350880f962d99ead85e776f23c6618a377a37 \ + --hash=sha256:cba42174344c3a5b06f255ce65b350880f962d99ead85e776f23c6618a377a37 \ + --hash=sha256:cba42174344c3a5b06f255ce65b350880f962d99ead85e776f23c6618a377a37 \ + --hash=sha256:cba42174344c3a5b06f255ce65b350880f962d99ead85e776f23c6618a377a37 \ + --hash=sha256:cba42174344c3a5b06f255ce65b350880f962d99ead85e776f23c6618a377a37 + # via mcp +idna==3.4 \ + --hash=sha256:52926a5baa595cfe5376963d8c5bbed33c4c83628dbd1958fc5734d664701b0c \ + --hash=sha256:90b77e79eaa3eba6de819a0c442c0b4ceefc341a7a2ab77d7562bf49f425c5c2 \ + --hash=sha256:90b77e79eaa3eba6de819a0c442c0b4ceefc341a7a2ab77d7562bf49f425c5c2 \ + --hash=sha256:90b77e79eaa3eba6de819a0c442c0b4ceefc341a7a2ab77d7562bf49f425c5c2 \ + --hash=sha256:90b77e79eaa3eba6de819a0c442c0b4ceefc341a7a2ab77d7562bf49f425c5c2 \ + --hash=sha256:90b77e79eaa3eba6de819a0c442c0b4ceefc341a7a2ab77d7562bf49f425c5c2 \ + --hash=sha256:90b77e79eaa3eba6de819a0c442c0b4ceefc341a7a2ab77d7562bf49f425c5c2 \ + --hash=sha256:90b77e79eaa3eba6de819a0c442c0b4ceefc341a7a2ab77d7562bf49f425c5c2 \ + --hash=sha256:90b77e79eaa3eba6de819a0c442c0b4ceefc341a7a2ab77d7562bf49f425c5c2 + # via + # anyio + # httpx +mcp==1.9.4 \ + --hash=sha256:78959d9958e78edfea30c9d1ea6da5d07ef17fdf0f64655dec2a8207700a5013 \ + --hash=sha256:7fcf36b62936adb8e63f89346bccca1268eeca9bf6dfb562ee10b1dfbda9dac0 +numpy==1.23.5+chromium.4 \ + --hash=sha256:1f09f09cd02263534f3f3376dc290bb33b2d16c10eb85fd1b0491b02028f559c \ + --hash=sha256:298e858d71fd8e2d963414be9d85288f4e04df92c1025128d7917b42a82768cd \ + --hash=sha256:3b6a0b96bcd6ce7393a92adbc00892d4af02f6c04936f671979dc285d9ed7c38 \ + --hash=sha256:3f58475348b7b887ebc9cf63ec63173b52acf988faa9d8e5b797c7befbf9a1c4 \ + --hash=sha256:44e321bb428153a6e396e7328d808def77c3cef8b3d93c5f9e4108d04c558997 \ + --hash=sha256:48f8428d17325de892ac883561d6ba485978f7b924e0b610d9f31ce968dbabe9 \ + --hash=sha256:5af4510cebaf0bb81ea9af5368fbf5a6ce21b4963dbd3e31fe0f796cffefc9ab \ + --hash=sha256:69098ac2618e6a95064a9096b8eb1e8a737b2105aeec1a21b4eac62ba8d48fa7 \ + --hash=sha256:785d2cec75a1dfb812be1a3a24da0c82ba60729c7b53e6bd132fda1479f6250f \ + --hash=sha256:9241565b3fb920fed1268068efbc0e46fbc4f2d6056495574507adaa32741f5d \ + --hash=sha256:929b83e970651c3971f1cb83ed2c3345266507487702155cb7007d2507d18771 \ + --hash=sha256:9b59a1ae3c94fd499099e304a23dacb486c030f13e826f79eb77470fa618d979 \ + --hash=sha256:a5706db7526e7edfafafe4fe620625c346a30f4b97acc8484f55ec5e83d25a74 \ + --hash=sha256:b80a749316f06b7d6a48cb1e7c5b0cf3de9a2b4ac6d001b3a6a0e5e800ea0f20 \ + --hash=sha256:eaf5507daa4d82341ad08bb2e5fd780c10e021ad48f8555ebf36027e2809787f + # via + # --override /tmp/overrides.txt + # pandas +pandas==2.2.3+chromium.1 \ + --hash=sha256:21c49f76db22c6f13370b357112ac28443d0b57c8c8476613385caa5bf8d7d23 \ + --hash=sha256:3322b4dba5f4d132abb393e202f22ec7777db4b9b5e7eddba5060ead0d975169 \ + --hash=sha256:c6f279f603a83f59fbc1b61306e644ca82c48b61ada7b335aa6dbb63c1e38f12 \ + --hash=sha256:d30cace0d7fc615a216e863bbda793f9eb8ed83b561af458bcbc6d7c421ddc63 +perfetto==0.16.0 \ + --hash=sha256:2394a32261988f0fb954dd5484c8c2488da7a75636db136399133acf08f515e8 \ + --hash=sha256:26c9e802763b06da9215d4437a56c2decb4e5e3156c8a7345454501d18a9664c +platformdirs==4.9.2 \ + --hash=sha256:9170634f126f8efdae22fb58ae8a0eaa86f38365bc57897a6c4f781d1f5875bd \ + --hash=sha256:ef245e78eb7a2ba57599bdb39c4ff323cfae3de356a47207b58bb29e7f479f46 +protobuf==6.33.5 \ + --hash=sha256:2d7cd4c2152df61dea8147caa60d428960d506c2fb85e1f4a979ec8b0d5ae4fc \ + --hash=sha256:69915a973dd0f60f31a08b8318b73eab2bd6a392c79184b3612226b0a3f8ec02 \ + --hash=sha256:69915a973dd0f60f31a08b8318b73eab2bd6a392c79184b3612226b0a3f8ec02 \ + --hash=sha256:69915a973dd0f60f31a08b8318b73eab2bd6a392c79184b3612226b0a3f8ec02 \ + --hash=sha256:69915a973dd0f60f31a08b8318b73eab2bd6a392c79184b3612226b0a3f8ec02 \ + --hash=sha256:69915a973dd0f60f31a08b8318b73eab2bd6a392c79184b3612226b0a3f8ec02 \ + --hash=sha256:69915a973dd0f60f31a08b8318b73eab2bd6a392c79184b3612226b0a3f8ec02 \ + --hash=sha256:69915a973dd0f60f31a08b8318b73eab2bd6a392c79184b3612226b0a3f8ec02 \ + --hash=sha256:69915a973dd0f60f31a08b8318b73eab2bd6a392c79184b3612226b0a3f8ec02 + # via perfetto +pydantic==2.11.7 \ + --hash=sha256:bf0c40ec69cef6193c091301b363bcb3e32f39c1ae39117accf81b8c6a21b898 \ + --hash=sha256:dde5df002701f6de26248661f6835bbe296a47bf73990135c7d07ce741b9623b + # via + # mcp + # pydantic-settings +pydantic-core==2.33.2 \ + --hash=sha256:03678d8617c2f4039931ab83bf88bf5ae7e411e7f21c9d829367851c8c9a117d \ + --hash=sha256:0a9f2c9dd19656823cb8250b0724ee9c60a82f3cdf68a080979d13092a3b0fef \ + --hash=sha256:1082dd3e2d7109ad8b7da48e1d4710c8d06c253cbc4a27c1cff4fbcaa97a9e3f \ + --hash=sha256:12a778136a420910394ff5566e5ac8ee0c1e6fcbcafd955d92c16e61bacde3d2 \ + --hash=sha256:3bf1e7157dc5769d118fd8b2c30314d19f31e686b22c50fc58bc6892f1fa1951 \ + --hash=sha256:3c9ce744525d5dada80dfa669fe94a1d590c4604702ebba60e9df61dfb0a09b4 \ + --hash=sha256:4c5b0a576fb381edd6d27f0a85915c6daf2f8138dc5c267a57c08a62900758c7 \ + --hash=sha256:899654b3dbcbdcc87293085ef59d826f762603d5b395d96df972669ac2512632 \ + --hash=sha256:9fdac5d6ffa1b5a83bca06ffe7583f5576555e6c8b3a91fbd25ea7780f825f7d \ + --hash=sha256:aff6903e22e7ee9e1d2eef334918b8ec93ed4153c252ae6878528a9b03ee5512 \ + --hash=sha256:c083a3bdd5a93dfe480f1125926afcdbf2917ae714bdb80b36d34318b2bec5d9 \ + --hash=sha256:dc46a01bf8d62f227d5ecee74178ffc448ff4e5197c756331f71efcc66dc980f \ + --hash=sha256:dc46a01bf8d62f227d5ecee74178ffc448ff4e5197c756331f71efcc66dc980f \ + --hash=sha256:f517ca031dfc037a9c07e748cefd8d96235088b83b4f4ba8939105d20fa1dcd6 + # via pydantic +pydantic-settings==2.10.1 \ + --hash=sha256:881fc1c77dc4f8396d2965cd82f15909d776750eb72ae05166135a27c1f584e5 \ + --hash=sha256:a60952460b99cf661dc25c29c0ef171721f98bfcb52ef8d9ea4c943d7c8cc796 + # via mcp +python-dateutil==2.9.0 \ + --hash=sha256:cbf2f1da5e6083ac2fbfd4da39a25f34312230110440f424a14c7558bb85d82e \ + --hash=sha256:d6e8ba261767bc6626b87eafbaff60e52b68417ae5d245ba5b703e59a384a169 + # via pandas +python-dotenv==1.1.1 \ + --hash=sha256:31f23644fe2602f88ff55e1f5c79ba497e01224ee7737937930c448e4d0e24dc \ + --hash=sha256:ac4a2ac45f7e1f94c09e819da5d582fbf5a2a3fcf22800fb61433f54f63d88d9 + # via pydantic-settings +python-multipart==0.0.20 \ + --hash=sha256:8a62d3a8335e06589fe01f2a3e178cdcc632f3fbe0d492ad9ee0ec35aab1f104 \ + --hash=sha256:99087ff3f8f0f3b8f37bec5111c1446c70a74c28fcf24c3e937c7819f4dd27dc + # via mcp +pytz==2025.2 \ + --hash=sha256:5ddf76296dd8c44c26eb8f4b6f35488f3ccbf6fbbd7adee0b7262d43f0ec2f00 \ + --hash=sha256:e14ffd5ea85d3acc73cb4fe5df3ef59e768f56e8b01c35197147a89988c7179e + # via pandas +pyyaml==5.4.1+chromium.1 \ + --hash=sha256:30943bf7ffc77849ab34b0c9a0bfdd2841d6cfef80a048443088c3981c3b7454 \ + --hash=sha256:30943bf7ffc77849ab34b0c9a0bfdd2841d6cfef80a048443088c3981c3b7454 \ + --hash=sha256:34de1c37474ed237b506bed193c3aa961136fb6c56d43c731b639a4658a561c7 \ + --hash=sha256:3bb84571b42414183e96cc560b602c0b907174dc2ca45bfe28e53371d34a3573 \ + --hash=sha256:3bf690dd33f9adb2493b54eed0eccedbb5dac7c38977dafbd6c5aaff4c2b9e72 \ + --hash=sha256:4db0e513d46d3feedff69b33fb4093a899396b6795b790d9b1a9ed84c9de9b83 \ + --hash=sha256:5cd00e9800df4255d79711cdfd039d957c5a06521ee6e4068efceca9ce09c333 \ + --hash=sha256:5ef917f3c0447944e3c6a2d6feb7e4c96cadc912436e0bec593d6676438723e9 \ + --hash=sha256:846e35c9c099b8d9a0b3c4c37444ef38dc9fbf9596f485565cdfa8b6bf33b8a4 \ + --hash=sha256:9626a7a5bbf3ba01f18eeb6dab7e1a8218bc554a5425103335ed726421f16dac \ + --hash=sha256:a757e3dbf41d474b343a1c9300051aad6857ba811a5b0844b229c9a81302b3e4 \ + --hash=sha256:d3624a91bf9acba3a3753052056d59012ee303bba33685d9332077d0029fadbf \ + --hash=sha256:d3624a91bf9acba3a3753052056d59012ee303bba33685d9332077d0029fadbf \ + --hash=sha256:d901525f60a95a76c9c7fb87968355e9c76d88b538a84b7319b37219bfa4f37c \ + --hash=sha256:e0f28dad378280bf0bfb1d3019c8b1dee1894f138f09643a10362235d3495be1 \ + --hash=sha256:ed50a1341d0580c1ee4f8e381beb56d141df93ab1690fbe9d6b49df55215f318 +six==1.17.0 \ + --hash=sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274 \ + --hash=sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274 \ + --hash=sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274 \ + --hash=sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274 \ + --hash=sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274 \ + --hash=sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274 \ + --hash=sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274 \ + --hash=sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274 \ + --hash=sha256:f5f26efe5825ae15ed1e5b419d3225e6b5a92eae4fcb1177f11927682c6a01b4 + # via python-dateutil +sniffio==1.3.0 \ + --hash=sha256:cd5f10406452e65ebd91db488adc3e51cab18f50b7edd4640b0bf88948b2adda \ + --hash=sha256:eecefdce1e5bbfb7ad2eeaabf7c1eeb404d7757c379bd1f7e5cce9d8bf425384 + # via anyio +sse-starlette==2.4.1 \ + --hash=sha256:08b77ea898ab1a13a428b2b6f73cfe6d0e607a7b4e15b9bb23e4a37b087fd39a \ + --hash=sha256:08b77ea898ab1a13a428b2b6f73cfe6d0e607a7b4e15b9bb23e4a37b087fd39a \ + --hash=sha256:08b77ea898ab1a13a428b2b6f73cfe6d0e607a7b4e15b9bb23e4a37b087fd39a \ + --hash=sha256:08b77ea898ab1a13a428b2b6f73cfe6d0e607a7b4e15b9bb23e4a37b087fd39a \ + --hash=sha256:08b77ea898ab1a13a428b2b6f73cfe6d0e607a7b4e15b9bb23e4a37b087fd39a \ + --hash=sha256:08b77ea898ab1a13a428b2b6f73cfe6d0e607a7b4e15b9bb23e4a37b087fd39a \ + --hash=sha256:08b77ea898ab1a13a428b2b6f73cfe6d0e607a7b4e15b9bb23e4a37b087fd39a \ + --hash=sha256:08b77ea898ab1a13a428b2b6f73cfe6d0e607a7b4e15b9bb23e4a37b087fd39a \ + --hash=sha256:d003715d225944e99f80a8f86429186b236943caf33a8d1021ad1ec75daa1ec5 + # via mcp +starlette==0.47.1 \ + --hash=sha256:5e11c9f5c7c3f24959edbf2dffdc01bba860228acf657129467d8a7468591527 \ + --hash=sha256:70b404a8ac9f2ef6d675e0962aa19e5237a094f3049aef195fc0d70c4138d3b6 + # via mcp +tabulate==0.9.0 \ + --hash=sha256:024ca478df22e9340661486f85298cff5f6dcdba14f3813e8830015b9ed1948f \ + --hash=sha256:2a24680b2b6348637deffb72547372f2726d34726cdbd7b8ffbd3218208a7b34 +typing-extensions==4.13.2 \ + --hash=sha256:9c32564c5ad29ea1284d73bf0026bd46a38554322643136080c36555b4601c59 \ + --hash=sha256:a439e7c04b49fec3e5d3e2beaa21755cadbbdc391694e28ccdd36ca4a1408f8c \ + --hash=sha256:a439e7c04b49fec3e5d3e2beaa21755cadbbdc391694e28ccdd36ca4a1408f8c \ + --hash=sha256:a439e7c04b49fec3e5d3e2beaa21755cadbbdc391694e28ccdd36ca4a1408f8c \ + --hash=sha256:a439e7c04b49fec3e5d3e2beaa21755cadbbdc391694e28ccdd36ca4a1408f8c \ + --hash=sha256:a439e7c04b49fec3e5d3e2beaa21755cadbbdc391694e28ccdd36ca4a1408f8c \ + --hash=sha256:a439e7c04b49fec3e5d3e2beaa21755cadbbdc391694e28ccdd36ca4a1408f8c \ + --hash=sha256:a439e7c04b49fec3e5d3e2beaa21755cadbbdc391694e28ccdd36ca4a1408f8c \ + --hash=sha256:a439e7c04b49fec3e5d3e2beaa21755cadbbdc391694e28ccdd36ca4a1408f8c + # via + # anyio + # pydantic + # pydantic-core + # starlette + # typing-inspection +typing-inspection==0.4.1 \ + --hash=sha256:389055682238f53b04f7badcb49b989835495a96700ced5dab2d8feae4b26f51 \ + --hash=sha256:389055682238f53b04f7badcb49b989835495a96700ced5dab2d8feae4b26f51 \ + --hash=sha256:389055682238f53b04f7badcb49b989835495a96700ced5dab2d8feae4b26f51 \ + --hash=sha256:389055682238f53b04f7badcb49b989835495a96700ced5dab2d8feae4b26f51 \ + --hash=sha256:389055682238f53b04f7badcb49b989835495a96700ced5dab2d8feae4b26f51 \ + --hash=sha256:389055682238f53b04f7badcb49b989835495a96700ced5dab2d8feae4b26f51 \ + --hash=sha256:389055682238f53b04f7badcb49b989835495a96700ced5dab2d8feae4b26f51 \ + --hash=sha256:389055682238f53b04f7badcb49b989835495a96700ced5dab2d8feae4b26f51 \ + --hash=sha256:420306879f55a5ea78991532847da46039ce9a899340211e7db84b6dbe6e91b2 + # via + # pydantic + # pydantic-settings +tzdata==2025.2 \ + --hash=sha256:1a403fada01ff9221ca8044d701868fa132215d84beb92242d9acd2147f667a8 \ + --hash=sha256:259d0754e270da739e95ad473d5adbcff926c9657914b325cc64f5048cfbe39d + # via pandas +uvicorn==0.35.0 \ + --hash=sha256:197535216b25ff9b785e29a0b79199f55222193d47f820816e7da751e9bc8d4a \ + --hash=sha256:57e22a1f2fa7f9bfbe555aafa2f4b39bdf7d4eb5494a31399a80ed00ad883a29 + # via mcp diff --git a/deps/v8/experimental/OWNERS b/deps/v8/experimental/OWNERS new file mode 100644 index 000000000000..72e8ffc0db8a --- /dev/null +++ b/deps/v8/experimental/OWNERS @@ -0,0 +1 @@ +* diff --git a/deps/v8/experimental/README.md b/deps/v8/experimental/README.md new file mode 100644 index 000000000000..f9c209d2f64c --- /dev/null +++ b/deps/v8/experimental/README.md @@ -0,0 +1,7 @@ +# Experimental + +This is a directory where anything goes - a place for experiments and tools +which are not code reviewed and/or do not meet the quality standards of the +rest of the codebase. + +Create a subdirectory for your project and commit there. diff --git a/deps/v8/include/js_protocol.pdl b/deps/v8/include/js_protocol.pdl index 99905a48ca7b..ad0d42bfa398 100644 --- a/deps/v8/include/js_protocol.pdl +++ b/deps/v8/include/js_protocol.pdl @@ -143,7 +143,7 @@ domain Debugger optional Location startLocation # Location in the source code where scope ends optional Location endLocation - # True if the scope does not declare any variables or have a runtime context. + # True if the scope does not declare any variables. # Only present if true. # Empty scopes are retained in the scope chain because # they can be targeted via `evaluateOnCallFrame` (using `scopeNumber`) or diff --git a/deps/v8/include/v8-array-buffer.h b/deps/v8/include/v8-array-buffer.h index 7d877608003c..839630680d72 100644 --- a/deps/v8/include/v8-array-buffer.h +++ b/deps/v8/include/v8-array-buffer.h @@ -62,6 +62,11 @@ class V8_EXPORT BackingStore : public v8::internal::BackingStoreBase { */ size_t ByteLength() const; + /** + * Returns the contents of this backing store as a span of bytes. + */ + std::span ByteSpan() const; + /** * The maximum length (in bytes) that this backing store may grow to. * diff --git a/deps/v8/include/v8-callbacks.h b/deps/v8/include/v8-callbacks.h index 456af07fe1d8..efa9de293072 100644 --- a/deps/v8/include/v8-callbacks.h +++ b/deps/v8/include/v8-callbacks.h @@ -22,6 +22,7 @@ struct _EXCEPTION_POINTERS; namespace v8 { +class ArrayBuffer; template class FunctionCallbackInfo; class Isolate; @@ -470,6 +471,13 @@ using HostCreateShadowRealmContextCallback = using IsJSApiWrapperNativeErrorCallback = bool (*)(Isolate* isolate, Local obj); +/** + * ArrayBufferDetachCallback is called when an ArrayBuffer wrapping an embedder + * object is detached. + */ +using ArrayBufferDetachCallback = void (*)(Isolate* isolate, + Local buffer); + /** * PrepareStackTraceCallback is called when the stack property of an error is * first accessed. The return value will be used as the stack value. If this diff --git a/deps/v8/include/v8-context.h b/deps/v8/include/v8-context.h index 6608be2d6213..8da2c8e48c1f 100644 --- a/deps/v8/include/v8-context.h +++ b/deps/v8/include/v8-context.h @@ -478,11 +478,15 @@ Local Context::GetEmbedderData(int index) { I::ReadTaggedPointerField(ctx, I::kNativeContextEmbedderDataOffset); int value_offset = I::kEmbedderDataArrayHeaderSize + (I::kEmbedderDataSlotSize * index); - A value = I::ReadRawField(embedder_data, value_offset); #ifdef V8_COMPRESS_POINTERS - // We read the full pointer value and then decompress it in order to avoid - // dealing with potential endianness issues. - value = I::DecompressTaggedField(embedder_data, static_cast(value)); + // The tagged payload lives in the low kTaggedSize half of the slot (at + // kTaggedPayloadOffset == 0). Read it as a 32-bit field so the correct half + // is picked on both little and big endian targets. A full width read plus + // truncation would return the CppHeap pointer half on big endian. + uint32_t compressed = I::ReadRawField(embedder_data, value_offset); + A value = I::DecompressTaggedField(embedder_data, compressed); +#else + A value = I::ReadRawField(embedder_data, value_offset); #endif auto* isolate = I::GetCurrentIsolate(); @@ -501,11 +505,15 @@ V8_INLINE Local Context::GetEmbedderDataV2(int index) { I::ReadTaggedPointerField(ctx, I::kNativeContextEmbedderDataOffset); int value_offset = I::kEmbedderDataArrayHeaderSize + (I::kEmbedderDataSlotSize * index); - A value = I::ReadRawField(embedder_data, value_offset); #ifdef V8_COMPRESS_POINTERS - // We read the full pointer value and then decompress it in order to avoid - // dealing with potential endianness issues. - value = I::DecompressTaggedField(embedder_data, static_cast(value)); + // The tagged payload lives in the low kTaggedSize half of the slot (at + // kTaggedPayloadOffset == 0). Read it as a 32-bit field so the correct half + // is picked on both little and big endian targets. A full-width read plus + // truncation would return the CppHeap pointer half on big endian. + uint32_t compressed = I::ReadRawField(embedder_data, value_offset); + A value = I::DecompressTaggedField(embedder_data, compressed); +#else + A value = I::ReadRawField(embedder_data, value_offset); #endif auto* isolate = I::GetCurrentIsolate(); diff --git a/deps/v8/include/v8-debug.h b/deps/v8/include/v8-debug.h index 1ffa08a02514..59dfe7b92c1d 100644 --- a/deps/v8/include/v8-debug.h +++ b/deps/v8/include/v8-debug.h @@ -109,6 +109,12 @@ class V8_EXPORT StackFrame { * Returns whether or not the associated function is defined by the user. */ bool IsUserJavaScript() const; + + /** + * Returns whether the script was compiled with resource_is_opaque set in its + * ScriptOrigin. + */ + bool IsScriptOpaque() const; }; /** diff --git a/deps/v8/include/v8-fast-api-calls.h b/deps/v8/include/v8-fast-api-calls.h index 42d9f61518d3..05486768e48e 100644 --- a/deps/v8/include/v8-fast-api-calls.h +++ b/deps/v8/include/v8-fast-api-calls.h @@ -466,7 +466,15 @@ struct FastApiCallbackOptions { /** * The `data` passed to the FunctionTemplate constructor, or `undefined`. */ + V8_DEPRECATE_SOON("Use DataV2 instead") v8::Local data; + + /** + * The `data` passed to the FunctionTemplate constructor as `v8::Data`. + */ + START_ALLOW_USE_DEPRECATED() + V8_INLINE v8::Local DataV2() const { return data; } + END_ALLOW_USE_DEPRECATED() }; namespace internal { diff --git a/deps/v8/include/v8-function-callback.h b/deps/v8/include/v8-function-callback.h index e0708430f615..de42be063916 100644 --- a/deps/v8/include/v8-function-callback.h +++ b/deps/v8/include/v8-function-callback.h @@ -35,6 +35,8 @@ class ConsoleCallArguments; namespace api_internal { V8_EXPORT v8::Local GetFunctionTemplateData( v8::Isolate* isolate, v8::Local raw_target); +V8_EXPORT v8::Local GetFunctionTemplateDataV2( + v8::Isolate* isolate, v8::Local raw_target); } // namespace api_internal template @@ -134,7 +136,10 @@ class FunctionCallbackInfo { /** Indicates whether this is a regular call or a construct call. */ V8_INLINE bool IsConstructCall() const; /** The data argument specified when creating the callback. */ + V8_DEPRECATE_SOON("Use DataV2 instead") V8_INLINE Local Data() const; + /** The data argument specified when creating the callback as `v8::Data`. */ + V8_INLINE Local DataV2() const; /** The current Isolate. */ V8_INLINE Isolate* GetIsolate() const; /** The ReturnValue for the call. */ @@ -233,8 +238,14 @@ class PropertyCallbackInfo { * `NamedPropertyHandlerConfiguration` or * `IndexedPropertyHandlerConfiguration.` */ + V8_DEPRECATE_SOON("Use DataV2 instead") V8_INLINE Local Data() const; + /** + * \return The data set in the callback configuration as `v8::Data`. + */ + V8_INLINE Local DataV2() const; + /** * \return The object in the prototype chain of the receiver that has the * interceptor. Suppose you have `x` and its prototype is `y`, and `y` @@ -642,6 +653,12 @@ Local FunctionCallbackInfo::Data() const { return api_internal::GetFunctionTemplateData(GetIsolate(), target); } +template +Local FunctionCallbackInfo::DataV2() const { + auto target = Local::FromSlot(&values_[kTargetIndex]); + return api_internal::GetFunctionTemplateDataV2(GetIsolate(), target); +} + template Isolate* FunctionCallbackInfo::GetIsolate() const { return reinterpret_cast(values_[kIsolateIndex]); @@ -681,6 +698,14 @@ Local PropertyCallbackInfo::Data() const { return Local::New(GetIsolate(), data); } +template +Local PropertyCallbackInfo::DataV2() const { + internal::Address callback_info = args_[kCallbackInfoIndex]; + internal::Address data = + I::ReadTaggedPointerField(callback_info, I::kCallbackInfoDataOffset); + return Local::New(GetIsolate(), data); +} + template Local PropertyCallbackInfo::Holder() const { return Local::FromSlot(&args_[kHolderIndex]); diff --git a/deps/v8/include/v8-inspector.h b/deps/v8/include/v8-inspector.h index d2909b688512..2f80c9ff3367 100644 --- a/deps/v8/include/v8-inspector.h +++ b/deps/v8/include/v8-inspector.h @@ -194,6 +194,8 @@ class V8_EXPORT V8InspectorSession { virtual void breakProgram(StringView breakReason, StringView breakDetails) = 0; virtual void setSkipAllPauses(bool) = 0; + // Temporarily overrides the protocol setting without changing session state. + virtual void setSkipAllPausesForInternalUse(bool) = 0; virtual void resume(bool setTerminateOnResume = false) = 0; virtual void stepOver() = 0; virtual std::vector> diff --git a/deps/v8/include/v8-internal.h b/deps/v8/include/v8-internal.h index 55d57d34255e..5c20dc45827f 100644 --- a/deps/v8/include/v8-internal.h +++ b/deps/v8/include/v8-internal.h @@ -223,6 +223,11 @@ using SandboxedPointer_t = Address; // virtual address space for userspace. As such, limit the sandbox to 128GB (a // quarter of the total available address space). constexpr size_t kSandboxSizeLog2 = 37; // 128 GB +#elif defined(V8_TARGET_ARCH_ARM64) && defined(V8_TARGET_OS_CHROMEOS) +// On ARM64 ChromeOS, kernel config is 39 bits of virtual address space for +// userspace, limit the sandbox to 128GB (a quarter of the total available +// address space). +constexpr size_t kSandboxSizeLog2 = 37; // 128 GB #elif defined(V8_TARGET_OS_IOS) // On iOS, we only get 64 GB of usable virtual address space even with the // "jumbo" extended virtual addressing entitlement. Limit the sandbox size to @@ -306,6 +311,9 @@ static_assert(kMaxSafeBufferSizeForSandbox <= kSandboxGuardRegionSize, #if defined(V8_TARGET_OS_ANDROID) // On Android, we often won't have sufficient virtual address space available. constexpr size_t kAdditionalTrailingGuardRegionSize = 0; +#elif defined(V8_TARGET_ARCH_ARM64) && defined(V8_TARGET_OS_CHROMEOS) +// On ARM64 ChromeOS, kernel configs 39 bits of virtual address space. +constexpr size_t kAdditionalTrailingGuardRegionSize = 0; #elif defined(V8_TARGET_ARCH_LOONG64) // Some hardwares like 2K3000 does not have sufficient virtual address space // available. @@ -467,14 +475,11 @@ constexpr size_t kMaxCppHeapPointers = 0; // // As an example, consider the following type hierarchy: // -// A -// +-- B -// | +-- C -// | +-- D -//. | -// +-- E -// -// F +// A F +// / \ +// B E +// / \ +// C D // // A potential type id assignment for range-based type checks is // {A: 0, B: 1, C: 2, D: 3, E: 4, F: 5}. With that, the type check for type A @@ -526,11 +531,7 @@ struct TagRange { constexpr TagRange(Tag first, Tag last) : first(first), last(last) { #ifdef V8_ENABLE_CHECKS // This would typically be a DCHECK, but that's not available here. -#if V8_HAS_BUILTIN_UNREACHABLE if (first > last) __builtin_unreachable(); // Invalid tag range. -#elif defined(_MSC_VER) - if (first > last) __assume(0); // Invalid tag range. -#endif #endif } @@ -590,16 +591,7 @@ enum class ManagedTypeId : uint32_t { kWasmFuncData, kWasmManagedData, kWasmNativeModule, - kIcuBreakIterator, kIcuBreakIteratorWithText, - kIcuLocale, - kIcuSimpleDateFormat, - kIcuDateIntervalFormat, - kIcuRelativeDateTimeFormatter, - kIcuListFormatter, - kIcuCollator, - kIcuPluralRules, - kIcuLocalizedNumberFormatter, kTemporalDuration, kTemporalInstant, kTemporalPlainDate, @@ -616,8 +608,17 @@ enum class ManagedTypeId : uint32_t { #define SHARED_MANAGED_TAG_LIST(V) V(WasmFutexManagedObjectWaitListTag) -#define MANAGED_TAG_LIST(V) \ - SHARED_MANAGED_TAG_LIST(V) +#define MANAGED_TAG_LIST(V) \ + SHARED_MANAGED_TAG_LIST(V) \ + V(IcuBreakIteratorTag) \ + V(IcuListFormatterTag) \ + V(IcuLocaleTag) \ + V(IcuSimpleDateFormatTag) \ + V(IcuDateIntervalFormatTag) \ + V(IcuRelativeDateTimeFormatterTag) \ + V(IcuLocalizedNumberFormatterTag) \ + V(IcuPluralRulesTag) \ + V(IcuCollatorTag) #define FOREIGN_TAG_LIST(V) \ V(GenericForeignTag) \ diff --git a/deps/v8/include/v8-isolate.h b/deps/v8/include/v8-isolate.h index 50c87b78de5e..a352b5f0164f 100644 --- a/deps/v8/include/v8-isolate.h +++ b/deps/v8/include/v8-isolate.h @@ -669,6 +669,7 @@ class V8_EXPORT Isolate { kModuleNamespaceMissingDefaultWithStarExport = 187, kRegExpMatcherFlagsMismatch = 188, kRegExpCustomSpecies = 189, + kWasmWideArithmetic = 190, // If you add new values here, you'll also need to update Chromium's: // web_feature.mojom, use_counter_callback.cc, and enums.xml. V8 changes to @@ -833,6 +834,12 @@ class V8_EXPORT Isolate { void SetIsJSApiWrapperNativeErrorCallback( IsJSApiWrapperNativeErrorCallback callback); + /** + * Set the callback invoked when an ArrayBuffer wrapping an embedder object + * is detached. + */ + void SetArrayBufferDetachCallback(ArrayBufferDetachCallback callback); + /** * This specifies the callback called when the stack property of Error * is accessed. @@ -995,6 +1002,7 @@ class V8_EXPORT Isolate { * if any. Returns undefiend if no continuation preserved embedder data was * set. */ + V8_DEPRECATE_SOON("Use GetContinuationPreservedEmbedderData instead") Local GetContinuationPreservedEmbedderDataV2(); /** @@ -1002,6 +1010,7 @@ class V8_EXPORT Isolate { * continuation runs. If `data` is empty, the continuation preserved embedder * data is set to undefined. */ + V8_DEPRECATE_SOON("Use SetContinuationPreservedEmbedderData instead") void SetContinuationPreservedEmbedderDataV2(Local data); /** @@ -1256,8 +1265,7 @@ class V8_EXPORT Isolate { void SetReleaseCppHeapCallbackForTesting(ReleaseCppHeapCallback callback); /** - * \returns the C++ heap managed by V8. Only available if such a heap has been - * attached using `AttachCppHeap()`. + * \returns the C++ heap managed by V8. */ CppHeap* GetCppHeap() const; diff --git a/deps/v8/include/v8-microtask-queue.h b/deps/v8/include/v8-microtask-queue.h index de58638c85d6..14ea13442a28 100644 --- a/deps/v8/include/v8-microtask-queue.h +++ b/deps/v8/include/v8-microtask-queue.h @@ -106,6 +106,18 @@ class V8_EXPORT MicrotaskQueue : public cppgc::GarbageCollected, */ virtual int GetMicrotasksScopeDepth() const = 0; + /** + * Controls how microtasks in this queue are invoked. This is the per-queue + * counterpart of Isolate::SetMicrotasksPolicy(), which only affects the + * isolate's default queue; the initial value is the policy passed to New(). + */ + virtual void SetMicrotasksPolicy(MicrotasksPolicy policy) = 0; + + /** + * Returns the policy controlling how microtasks in this queue are invoked. + */ + virtual MicrotasksPolicy GetMicrotasksPolicy() const = 0; + MicrotaskQueue(const MicrotaskQueue&) = delete; MicrotaskQueue& operator=(const MicrotaskQueue&) = delete; diff --git a/deps/v8/include/v8-object.h b/deps/v8/include/v8-object.h index 1dd2eb91124d..f7fbd4e13023 100644 --- a/deps/v8/include/v8-object.h +++ b/deps/v8/include/v8-object.h @@ -926,11 +926,15 @@ Local Object::GetInternalField(int index) { if (I::CanHaveInternalField(instance_type)) { int offset = I::kJSAPIObjectWithEmbedderSlotsHeaderSize + (I::kEmbedderDataSlotSize * index); - A value = I::ReadRawField(obj, offset); #ifdef V8_COMPRESS_POINTERS - // We read the full pointer value and then decompress it in order to avoid - // dealing with potential endianness issues. - value = I::DecompressTaggedField(obj, static_cast(value)); + // The tagged payload lives in the low kTaggedSize half of the slot (at + // kTaggedPayloadOffset == 0). Read it as a 32-bit field so the correct half + // is picked on both little and big endian targets. A full width read plus + // truncation would return the CppHeap pointer half on big endian. + uint32_t compressed = I::ReadRawField(obj, offset); + A value = I::DecompressTaggedField(obj, compressed); +#else + A value = I::ReadRawField(obj, offset); #endif auto* isolate = I::GetCurrentIsolate(); diff --git a/deps/v8/include/v8-profiler.h b/deps/v8/include/v8-profiler.h index 82769a8dfb4f..df60fd7f66d7 100644 --- a/deps/v8/include/v8-profiler.h +++ b/deps/v8/include/v8-profiler.h @@ -836,6 +836,11 @@ class V8_EXPORT AllocationProfile { * been collected by GC. */ bool is_live; + + /** + * Sample interval in bytes used when this sample was selected. + */ + uint64_t sample_interval; }; /** @@ -1257,6 +1262,22 @@ class V8_EXPORT HeapProfiler { */ void StopSamplingHeapProfiler(); + /** + * Updates the sampling interval for a currently running sampling heap + * profiler. The new interval is used for future sample scheduling. + * + * No-op if the sampling heap profiler is not running. + */ + void SetSamplingHeapProfilerInterval(uint64_t sample_interval); + + /** + * Returns the currently retained allocation samples without materializing + * the full allocation profile tree. + * + * Returns an empty vector if the sampling heap profiler is not running. + */ + std::vector GetSamplingHeapProfilerSamples(); + /** * Returns the sampled profile of allocations allocated (and still live) since * StartSamplingHeapProfiler was called. The ownership of the pointer is diff --git a/deps/v8/include/v8-sandbox.h b/deps/v8/include/v8-sandbox.h index 2cda25eb958e..31d18d625e4b 100644 --- a/deps/v8/include/v8-sandbox.h +++ b/deps/v8/include/v8-sandbox.h @@ -29,7 +29,9 @@ enum class CppHeapPointerTag : uint16_t { kFirstTag = 0, kNullTag = 0, + // Subtypes of v8::Object::Wrappable [0x0001 .. 0x6fff] kFirstObjectWrappableTag = 1, + kFirstEmbedderWrappableTag = kFirstObjectWrappableTag, /** * The lower type ids are reserved for the embedder to assign. For that, the @@ -54,24 +56,33 @@ enum class CppHeapPointerTag : uint16_t { * the type check to use even fewer instructions (essentially replace a AND + * SUB with a single AND). */ + kLastEmbedderWrappableTag = 0x6eff, - kFirstV8InternalTag = 0x6000, - // V8-internal Oilpan objects that use v8::Object::Wrap() should go here. - kTagForTesting, - kInspectorV8ConsoleTag, - kInspectorTaskInfoTag, - kMicrotaskQueueTag, - kWasmMemoryMapDescriptorTag, - kCppGCManagedTag, - kEmbedderDataSlotTag, - kLastV8InternalTag, + // V8-internal Oilpan objects that inherit from v8::Object::Wrappable. + kFirstV8InternalWrappableTag = 0x6f00, + // Kept temporarily for backwards compatibility with Chromium's + // wrapper_type_info.h across the V8 roll. + kFirstV8InternalTag = kFirstV8InternalWrappableTag, + kLastV8InternalWrappableTag = 0x6fff, + + kLastObjectWrappableTag = kLastV8InternalWrappableTag, + + // Non-v8::Object::Wrappable CppHeap objects [0x7000 .. 0x7ffc] + kFirstNonWrappableTag = 0x7000, + + kFirstV8InternalNonWrappableTag = kFirstNonWrappableTag, + kLastV8InternalNonWrappableTag = 0x70ff, + + kFirstEmbedderNonWrappableTag = 0x7100, + kLastEmbedderNonWrappableTag = 0x7ffc, + + kLastNonWrappableTag = kLastEmbedderNonWrappableTag, #if !V8_ENABLE_SANDBOX // Embedders that use the sandbox should use specific tags for each type. - kDefaultTag, + kDefaultTag = kFirstEmbedderWrappableTag, #endif // !V8_ENABLE_SANDBOX - kLastObjectWrappableTag = 0x7ffc, kZappedEntryTag = 0x7ffd, kEvacuationEntryTag = 0x7ffe, kFreeEntryTag = 0x7fff, @@ -79,9 +90,6 @@ enum class CppHeapPointerTag : uint16_t { kLastTag = 0x7fff, }; -static_assert(static_cast(CppHeapPointerTag::kLastV8InternalTag) < - static_cast(CppHeapPointerTag::kZappedEntryTag)); - using CppHeapPointerTagRange = internal::TagRange; constexpr CppHeapPointerTagRange kAnyCppHeapPointer( @@ -95,12 +103,26 @@ constexpr CppHeapPointerTagRange kObjectWrappableTagRange( CppHeapPointerTag::kFirstObjectWrappableTag, CppHeapPointerTag::kLastObjectWrappableTag); -constexpr CppHeapPointerTagRange kV8InternalTagRange( - CppHeapPointerTag::kFirstV8InternalTag, - CppHeapPointerTag::kLastV8InternalTag); - -static_assert(kObjectWrappableTagRange.Contains(kV8InternalTagRange), - "V8Internal tag range must be within kObjectWrappableTagRange"); +// The tag range that embedders can use for their own types that inherit from +// v8::Object::Wrappable. +constexpr CppHeapPointerTagRange kEmbedderWrappableTagRange( + CppHeapPointerTag::kFirstEmbedderWrappableTag, + CppHeapPointerTag::kLastEmbedderWrappableTag); + +// The tag range for all non-v8::Object::Wrappable CppHeap objects, both +// V8-internal and embedder-owned. +constexpr CppHeapPointerTagRange kNonWrappableTagRange( + CppHeapPointerTag::kFirstNonWrappableTag, + CppHeapPointerTag::kLastNonWrappableTag); + +// The tag range that embedders can use for their own types that do not inherit +// from v8::Object::Wrappable. +constexpr CppHeapPointerTagRange kEmbedderNonWrappableTagRange( + CppHeapPointerTag::kFirstEmbedderNonWrappableTag, + CppHeapPointerTag::kLastEmbedderNonWrappableTag); + +static_assert(kObjectWrappableTagRange.Contains(kEmbedderWrappableTagRange)); +static_assert(kNonWrappableTagRange.Contains(kEmbedderNonWrappableTagRange)); /** * Hardware support for the V8 Sandbox. diff --git a/deps/v8/include/v8-script.h b/deps/v8/include/v8-script.h index c6b0585cb119..3a67e56cb496 100644 --- a/deps/v8/include/v8-script.h +++ b/deps/v8/include/v8-script.h @@ -928,16 +928,17 @@ class V8_EXPORT ScriptCompiler { Local full_source_string, const ScriptOrigin& origin); /** - * Return a version tag for CachedData for the current V8 version & flags. + * Return a version tag for CachedData for the current V8 version, embedder + * version string, and flags. * * This value is meant only for determining whether a previously generated * CachedData instance is still valid; the tag has no other meaing. * * Background: The data carried by CachedData may depend on the exact - * V8 version number or current compiler flags. This means that when - * persisting CachedData, the embedder must take care to not pass in - * data from another V8 version, or the same version with different - * features enabled. + * V8 version number, embedder version string, or current compiler flags. + * This means that when persisting CachedData, the embedder must take care + * to not pass in data from another V8 build, or the same build with + * different features enabled. * * The easiest way to do so is to clear the embedder's cache on any * such change. diff --git a/deps/v8/include/v8-traced-handle.h b/deps/v8/include/v8-traced-handle.h index 3eb8e7835d74..72649e112e8d 100644 --- a/deps/v8/include/v8-traced-handle.h +++ b/deps/v8/include/v8-traced-handle.h @@ -82,9 +82,10 @@ class TracedReferenceBase : public api_internal::IndirectHandleBase { /** * Update this reference in a thread-safe way. */ - void SetSlotThreadSafe(internal::Address* new_val) { - reinterpret_cast*>(&slot())->store( - new_val, std::memory_order_relaxed); + void SetSlotThreadSafe(internal::Address* new_val, + std::memory_order order = std::memory_order_relaxed) { + reinterpret_cast*>(&slot())->store(new_val, + order); } /** @@ -185,10 +186,12 @@ class TracedReference : public BasicTracedReference { if (V8_UNLIKELY(that.IsEmpty())) { return; } - this->slot() = this->NewFromNonEmptyValue( - isolate, *that, &this->slot(), - internal::TracedReferenceStoreMode::kInitializingStore, - internal::TracedReferenceHandling::kDefault); + this->SetSlotThreadSafe( + this->NewFromNonEmptyValue( + isolate, *that, &this->slot(), + internal::TracedReferenceStoreMode::kInitializingStore, + internal::TracedReferenceHandling::kDefault), + std::memory_order_release); } /** @@ -206,10 +209,12 @@ class TracedReference : public BasicTracedReference { if (V8_UNLIKELY(that.IsEmpty())) { return; } - this->slot() = this->NewFromNonEmptyValue( - isolate, *that, &this->slot(), - internal::TracedReferenceStoreMode::kInitializingStore, - internal::TracedReferenceHandling::kDroppable); + this->SetSlotThreadSafe( + this->NewFromNonEmptyValue( + isolate, *that, &this->slot(), + internal::TracedReferenceStoreMode::kInitializingStore, + internal::TracedReferenceHandling::kDroppable), + std::memory_order_release); } /** @@ -356,10 +361,12 @@ void TracedReference::Reset(Isolate* isolate, const Local& other) { if (V8_UNLIKELY(other.IsEmpty())) { return; } - this->SetSlotThreadSafe(this->NewFromNonEmptyValue( - isolate, *other, &this->slot(), - internal::TracedReferenceStoreMode::kAssigningStore, - internal::TracedReferenceHandling::kDefault)); + this->SetSlotThreadSafe( + this->NewFromNonEmptyValue( + isolate, *other, &this->slot(), + internal::TracedReferenceStoreMode::kAssigningStore, + internal::TracedReferenceHandling::kDefault), + std::memory_order_release); } template @@ -371,10 +378,12 @@ void TracedReference::Reset(Isolate* isolate, const Local& other, if (V8_UNLIKELY(other.IsEmpty())) { return; } - this->SetSlotThreadSafe(this->NewFromNonEmptyValue( - isolate, *other, &this->slot(), - internal::TracedReferenceStoreMode::kAssigningStore, - internal::TracedReferenceHandling::kDroppable)); + this->SetSlotThreadSafe( + this->NewFromNonEmptyValue( + isolate, *other, &this->slot(), + internal::TracedReferenceStoreMode::kAssigningStore, + internal::TracedReferenceHandling::kDroppable), + std::memory_order_release); } template diff --git a/deps/v8/include/v8-version.h b/deps/v8/include/v8-version.h index d3a60cfe29e1..4d9a05127098 100644 --- a/deps/v8/include/v8-version.h +++ b/deps/v8/include/v8-version.h @@ -9,9 +9,9 @@ // NOTE these macros are used by some of the tool scripts and the build // system so their names cannot be changed without changing the scripts. #define V8_MAJOR_VERSION 15 -#define V8_MINOR_VERSION 5 -#define V8_BUILD_NUMBER 35 -#define V8_PATCH_LEVEL 20 +#define V8_MINOR_VERSION 6 +#define V8_BUILD_NUMBER 75 +#define V8_PATCH_LEVEL 8 // Use 1 for candidates and 0 otherwise. // (Boolean macro values are not supported by all preprocessors.) diff --git a/deps/v8/include/v8-wasm.h b/deps/v8/include/v8-wasm.h index 4d0158bd29d1..17227e6d485b 100644 --- a/deps/v8/include/v8-wasm.h +++ b/deps/v8/include/v8-wasm.h @@ -247,7 +247,7 @@ class V8_EXPORT WasmStreaming final { * unpack the {CppGCManaged} itself. */ static std::shared_ptr Unpack(Isolate* isolate, - Local value); + Local data); private: std::unique_ptr impl_; diff --git a/deps/v8/include/v8config.h b/deps/v8/include/v8config.h index 1e2d7c5658c9..b7aeeade6b81 100644 --- a/deps/v8/include/v8config.h +++ b/deps/v8/include/v8config.h @@ -609,15 +609,11 @@ path. Add it with -I to the command line // functions. // Use like: // V8_NOINLINE V8_PRESERVE_MOST void UnlikelyMethod(); -#if V8_OS_WIN -# define V8_PRESERVE_MOST -#else #if V8_HAS_ATTRIBUTE_PRESERVE_MOST # define V8_PRESERVE_MOST __attribute__((preserve_most)) #else # define V8_PRESERVE_MOST /* NOT SUPPORTED */ #endif -#endif // A macro (V8_DEPRECATED) to mark classes or functions as deprecated. diff --git a/deps/v8/infra/mb/mb_config.pyl b/deps/v8/infra/mb/mb_config.pyl index 0efde3556e70..3102eaf1ee57 100644 --- a/deps/v8/infra/mb/mb_config.pyl +++ b/deps/v8/infra/mb/mb_config.pyl @@ -653,7 +653,8 @@ 'release_bot', 'x64', 'v8_dumpling'], 'release_x64_fuzzilli': [ 'release_bot', 'x64', 'dcheck_always_on', 'v8_enable_slow_dchecks', - 'v8_verify_heap', 'v8_verify_csa', 'fuzzilli'], + 'backtrace', 'trace_pc_guard', 'v8_enable_fuzzilli', + 'v8_enable_verification_features'], 'release_x64_gcmole': [ 'release_bot', 'x64', 'gcmole'], 'release_x64_correctness_fuzzer_undefined_double' : [ @@ -954,11 +955,6 @@ 'gn_args': 'target_os="fuchsia"', }, - 'fuzzilli': { - 'gn_args': 'v8_static_library=true v8_enable_v8_checks=true ' - 'sanitizer_coverage_flags="trace-pc-guard" v8_fuzzilli=true', - }, - 'gcc': { 'gn_args': 'is_clang=false', }, @@ -1217,6 +1213,10 @@ 'gn_args': 'v8_enable_undefined_double=true', }, + 'v8_enable_verification_features': { + 'gn_args': 'v8_enable_verification_features=true', + }, + 'v8_enable_verify_predictable': { 'gn_args': 'v8_enable_verify_predictable=true', }, diff --git a/deps/v8/infra/testing/builders.pyl b/deps/v8/infra/testing/builders.pyl index c7ea3073b91a..cbc84e4984cb 100644 --- a/deps/v8/infra/testing/builders.pyl +++ b/deps/v8/infra/testing/builders.pyl @@ -332,7 +332,8 @@ {'name': 'v8testing', 'shards': 7}, {'name': 'benchmarks', 'shards': 5}, {'name': 'mozilla', 'shards': 5}, - {'name': 'test262', 'shards': 12}, + {'name': 'test262', 'variant': 'default', 'shards': 6}, + {'name': 'test262', 'variant': 'future', 'shards': 6}, ], }, 'v8_linux64_dbg': { @@ -445,8 +446,9 @@ 'swarming_dimensions' : { 'os': 'Ubuntu-22.04', }, - # TODO(almuthanna): Add a new test config for the fuzzilli suite. - 'tests': [], + 'tests': [ + {'name': 'mjsunit', 'variant': 'default'}, + ], }, 'v8_linux64_fyi_rel': { 'swarming_dimensions' : { @@ -1408,6 +1410,14 @@ }, ], }, + 'V8 Linux64 - Fuzzilli': { + 'swarming_dimensions' : { + 'os': 'Ubuntu-22.04', + }, + 'tests': [ + {'name': 'mjsunit', 'variant': 'default'}, + ], + }, 'V8 Linux64 - official': { 'swarming_dimensions' : { 'cpu': 'x86-64-avx2', @@ -1831,7 +1841,8 @@ {'name': 'v8testing', 'shards': 7}, {'name': 'benchmarks', 'shards': 5}, {'name': 'mozilla', 'shards': 5}, - {'name': 'test262', 'shards': 16}, + {'name': 'test262', 'variant': 'default', 'shards': 4}, + {'name': 'test262', 'variant': 'future', 'shards': 4}, ], }, 'V8 Linux64 GC Stress - custom snapshot': { @@ -2245,7 +2256,7 @@ }, 'tests': [ {'name': 'mozilla', 'shards': 3}, - {'name': 'test262', 'variant': 'default', 'shards': 3}, + {'name': 'test262', 'variant': 'default', 'shards': 6}, {'name': 'v8testing', 'shards': 10}, {'name': 'v8testing', 'variant': 'extra', 'shards': 9}, {'name': 'v8testing', 'variant': 'turbolev', 'shards': 2}, @@ -2337,7 +2348,7 @@ }, 'tests': [ {'name': 'mozilla', 'shards': 2}, - {'name': 'test262', 'variant': 'default', 'shards': 3}, + {'name': 'test262', 'variant': 'default', 'shards': 6}, {'name': 'v8testing', 'shards': 12}, {'name': 'v8testing', 'variant': 'extra', 'shards': 14}, { diff --git a/deps/v8/src/api/api.cc b/deps/v8/src/api/api.cc index adee19691fcf..568671193c5a 100644 --- a/deps/v8/src/api/api.cc +++ b/deps/v8/src/api/api.cc @@ -3542,6 +3542,10 @@ bool StackFrame::IsUserJavaScript() const { return Utils::OpenDirectHandle(this)->script()->IsUserJavaScript(); } +bool StackFrame::IsScriptOpaque() const { + return Utils::OpenDirectHandle(this)->script()->origin_options().IsOpaque(); +} + // --- J S O N --- MaybeLocal JSON::Parse(Local context, Local json_string, @@ -4361,6 +4365,10 @@ size_t v8::BackingStore::ByteLength() const { return reinterpret_cast(this)->byte_length(); } +std::span v8::BackingStore::ByteSpan() const { + return {static_cast(Data()), ByteLength()}; +} + size_t v8::BackingStore::MaxByteLength() const { return reinterpret_cast(this)->max_byte_length(); } @@ -10497,15 +10505,15 @@ i::ValueHelper::InternalRepresentationType Isolate::GetDataFromSnapshotOnce( return GetSerializedDataFromFixedArray(i_isolate, list, index); } -Local Isolate::GetContinuationPreservedEmbedderData() { - return GetContinuationPreservedEmbedderDataV2(); +Local Isolate::GetContinuationPreservedEmbedderDataV2() { + return GetContinuationPreservedEmbedderData(); } -void Isolate::SetContinuationPreservedEmbedderData(Local data) { - SetContinuationPreservedEmbedderDataV2(data); +void Isolate::SetContinuationPreservedEmbedderDataV2(Local data) { + SetContinuationPreservedEmbedderData(data); } -Local Isolate::GetContinuationPreservedEmbedderDataV2() { +Local Isolate::GetContinuationPreservedEmbedderData() { i::Isolate* i_isolate = reinterpret_cast(this); #ifdef V8_ENABLE_CONTINUATION_PRESERVED_EMBEDDER_DATA return ToApiHandle(i::direct_handle( @@ -10516,7 +10524,7 @@ Local Isolate::GetContinuationPreservedEmbedderDataV2() { #endif // V8_ENABLE_CONTINUATION_PRESERVED_EMBEDDER_DATA } -void Isolate::SetContinuationPreservedEmbedderDataV2(Local data) { +void Isolate::SetContinuationPreservedEmbedderData(Local data) { #ifdef V8_ENABLE_CONTINUATION_PRESERVED_EMBEDDER_DATA i::Isolate* i_isolate = reinterpret_cast(this); if (data.IsEmpty()) { @@ -11068,6 +11076,9 @@ CALLBACK_SETTER(IsJSApiWrapperNativeErrorCallback, IsJSApiWrapperNativeErrorCallback, is_js_api_wrapper_native_error_callback) +CALLBACK_SETTER(ArrayBufferDetachCallback, ArrayBufferDetachCallback, + array_buffer_detach_callback) + void Isolate::InstallConditionalFeatures(Local context) { v8::HandleScope handle_scope(this); v8::Context::Scope context_scope(context); @@ -12116,6 +12127,17 @@ void HeapProfiler::StopSamplingHeapProfiler() { reinterpret_cast(this)->StopSamplingHeapProfiler(); } +void HeapProfiler::SetSamplingHeapProfilerInterval(uint64_t sample_interval) { + reinterpret_cast(this)->SetSamplingHeapProfilerInterval( + sample_interval); +} + +std::vector +HeapProfiler::GetSamplingHeapProfilerSamples() { + return reinterpret_cast(this) + ->GetSamplingHeapProfilerSamples(); +} + AllocationProfile* HeapProfiler::GetAllocationProfile() { return reinterpret_cast(this)->GetAllocationProfile(); } @@ -12204,29 +12226,41 @@ const CTypeInfo& CFunctionInfo::ArgumentInfo(unsigned int index) const { } namespace api_internal { -V8_EXPORT v8::Local GetFunctionTemplateData( - v8::Isolate* isolate, v8::Local raw_target) { +namespace { +i::DirectHandle GetFunctionTemplateDataImpl( + v8::Isolate* isolate, v8::Local raw_target, + const char* location) { i::Isolate* i_isolate = reinterpret_cast(isolate); i::DirectHandle target = Utils::OpenDirectHandle(*raw_target); if (i::IsFunctionTemplateInfo(*target)) { - i::DirectHandle data( + return i::DirectHandle( i::Cast(*target)->callback_data(kAcquireLoad), i_isolate); - return Utils::ToLocal(data); - - } else if (i::IsJSFunction(*target)) { + } + if (i::IsJSFunction(*target)) { i::DirectHandle target_func = i::Cast(target); auto shared = target_func->shared(); if (shared->IsApiFunction()) { - i::DirectHandle data( + return i::DirectHandle( shared->api_func_data()->callback_data(kAcquireLoad), i_isolate); - return Utils::ToLocal(data); } } - Utils::ApiCheck(false, "api_internal::GetFunctionTemplateData", - "Target function is not an Api function"); + Utils::ApiCheck(false, location, "Target function is not an Api function"); UNREACHABLE(); } +} // namespace + +V8_EXPORT v8::Local GetFunctionTemplateData( + v8::Isolate* isolate, v8::Local raw_target) { + return Utils::ToLocal(GetFunctionTemplateDataImpl( + isolate, raw_target, "api_internal::GetFunctionTemplateData")); +} + +V8_EXPORT v8::Local GetFunctionTemplateDataV2( + v8::Isolate* isolate, v8::Local raw_target) { + return ToApiHandle(GetFunctionTemplateDataImpl( + isolate, raw_target, "api_internal::GetFunctionTemplateDataV2")); +} } // namespace api_internal RegisterState::RegisterState() @@ -12288,7 +12322,7 @@ void WasmStreaming::SetUrl(const char* url, size_t length) { UNREACHABLE(); } // static std::shared_ptr WasmStreaming::Unpack(Isolate* v8_isolate, - Local value) { + Local data) { FATAL("WebAssembly is disabled"); } #endif // !V8_ENABLE_WEBASSEMBLY @@ -12518,7 +12552,7 @@ bool ValidateFunctionCallbackInfo(const FunctionCallbackInfo& info) { CHECK_EQ(i_isolate, Isolate::Current()); CHECK(!i_isolate->GetIncumbentContext().is_null()); CHECK(info.This()->IsObject()); - CHECK(!info.Data().IsEmpty()); + CHECK(!info.DataV2().IsEmpty()); CHECK(info.GetReturnValue().Get()->IsValue()); return true; } @@ -12535,7 +12569,7 @@ bool ValidatePropertyCallbackInfo(const PropertyCallbackInfo& info) { *i::PropertyCallbackArguments::GetPropertyName(info); CHECK(i::IsName(name)); } - CHECK(info.Data()->IsValue()); + CHECK(info.DataV2()->IsValue()); USE(info.ShouldThrowOnError()); if (!std::is_same_v) { CHECK(info.GetReturnValue().Get()->IsValue()); diff --git a/deps/v8/src/ast/ast-value-factory.cc b/deps/v8/src/ast/ast-value-factory.cc index ed113acbd63c..0e2f6268b559 100644 --- a/deps/v8/src/ast/ast-value-factory.cc +++ b/deps/v8/src/ast/ast-value-factory.cc @@ -29,6 +29,7 @@ #include "src/base/hashmap-entry.h" #include "src/base/logging.h" +#include "src/base/small-vector.h" #include "src/common/globals.h" #include "src/heap/factory-inl.h" #include "src/heap/local-factory-inl.h" @@ -82,6 +83,7 @@ bool AstRawString::AsArrayIndex(uint32_t* index) const { // The StringHasher will set up the hash. Bail out early if we know it // can't be convertible to an array index. if (!IsIntegerIndex()) return false; + DCHECK(is_one_byte()); if (length() <= Name::kMaxCachedArrayIndexLength) { *index = StringHasher::DecodeArrayIndexFromHashField( raw_hash_field_, HashSeed(GetReadOnlyRoots())); @@ -340,6 +342,7 @@ const AstRawString* AstValueFactory::GetOneByteStringInternal( const AstRawString* AstValueFactory::GetTwoByteStringInternal( base::Vector literal) { + DCHECK(!String::IsOneByte(literal.begin(), literal.length())); uint32_t raw_hash_field = StringHasher::HashSequentialString( literal.begin(), literal.length(), hash_seed_); return GetString(raw_hash_field, false, @@ -349,16 +352,20 @@ const AstRawString* AstValueFactory::GetTwoByteStringInternal( const AstRawString* AstValueFactory::GetString( Tagged literal, const SharedStringAccessGuardIfNeeded& access_guard) { - const AstRawString* result = nullptr; DisallowGarbageCollection no_gc; String::FlatContent content = literal->GetFlatContent(no_gc, access_guard); if (content.IsOneByte()) { - result = GetOneByteStringInternal(content.ToOneByteVector()); - } else { - DCHECK(content.IsTwoByte()); - result = GetTwoByteStringInternal(content.ToUC16Vector()); + return GetOneByteStringInternal(content.ToOneByteVector()); } - return result; + DCHECK(content.IsTwoByte()); + base::Vector vector = content.ToUC16Vector(); + if (String::IsOneByte(vector.begin(), vector.length())) { + base::SmallVector one_byte(vector.length()); + CopyChars(one_byte.data(), vector.begin(), vector.length()); + return GetOneByteStringInternal( + base::Vector(one_byte.data(), vector.length())); + } + return GetTwoByteStringInternal(vector); } AstConsString* AstValueFactory::NewConsString() { diff --git a/deps/v8/src/ast/ast-value-factory.h b/deps/v8/src/ast/ast-value-factory.h index 5ca83bc76f22..23b37a9e2e8b 100644 --- a/deps/v8/src/ast/ast-value-factory.h +++ b/deps/v8/src/ast/ast-value-factory.h @@ -63,7 +63,7 @@ class AstRawString final : public ZoneObject { return is_one_byte() ? literal_bytes_.length() : literal_bytes_.length() / 2; } - bool AsArrayIndex(uint32_t* index) const; + V8_EXPORT_PRIVATE bool AsArrayIndex(uint32_t* index) const; bool IsIntegerIndex() const; V8_EXPORT_PRIVATE bool IsOneByteEqualTo(const char* data) const; V8_EXPORT_PRIVATE uint16_t FirstCharacter() const; @@ -383,8 +383,8 @@ class AstValueFactory { const AstRawString* GetTwoByteString(base::Vector literal) { return GetTwoByteStringInternal(literal); } - const AstRawString* GetString(Tagged literal, - const SharedStringAccessGuardIfNeeded&); + V8_EXPORT_PRIVATE const AstRawString* GetString( + Tagged literal, const SharedStringAccessGuardIfNeeded&); V8_EXPORT_PRIVATE AstConsString* NewConsString(); V8_EXPORT_PRIVATE AstConsString* NewConsString(const AstRawString* str); diff --git a/deps/v8/src/ast/ast.h b/deps/v8/src/ast/ast.h index 21ed80e6a4df..b036f590d044 100644 --- a/deps/v8/src/ast/ast.h +++ b/deps/v8/src/ast/ast.h @@ -1578,13 +1578,6 @@ class VariableProxy final : public Expression { bit_field_ = IsNewTargetField::update(bit_field_, true); } - bool is_inside_try_catch() const { - return IsInsideTryCatchField::decode(bit_field_); - } - void set_is_inside_try_catch() { - bit_field_ = IsInsideTryCatchField::update(bit_field_, true); - } - HoleCheckMode hole_check_mode() const { HoleCheckMode mode = HoleCheckModeField::decode(bit_field_); DCHECK_IMPLIES(mode == HoleCheckMode::kRequired, @@ -1658,7 +1651,6 @@ class VariableProxy final : public Expression { IsResolvedField::encode(false) | IsRemovedFromUnresolvedField::encode(false) | IsHomeObjectField::encode(false) | - IsInsideTryCatchField::encode(false) | HoleCheckModeField::encode(HoleCheckMode::kElided); } @@ -1669,8 +1661,7 @@ class VariableProxy final : public Expression { using IsRemovedFromUnresolvedField = IsResolvedField::Next; using IsNewTargetField = IsRemovedFromUnresolvedField::Next; using IsHomeObjectField = IsNewTargetField::Next; - using IsInsideTryCatchField = IsHomeObjectField::Next; - using HoleCheckModeField = IsInsideTryCatchField::Next; + using HoleCheckModeField = IsHomeObjectField::Next; union { const AstRawString* raw_name_; // if !is_resolved_ diff --git a/deps/v8/src/ast/scopes.cc b/deps/v8/src/ast/scopes.cc index 59d8ca6bbbf4..7713cd8103dd 100644 --- a/deps/v8/src/ast/scopes.cc +++ b/deps/v8/src/ast/scopes.cc @@ -232,17 +232,18 @@ ClassScope::ClassScope(IsolateT* isolate, Zone* zone, DCHECK_EQ(scope_info->ContextLocalInitFlag(index), InitializationFlag::kNeedsInitialization); DCHECK_EQ(scope_info->ContextLocalMaybeAssignedFlag(index), - MaybeAssignedFlag::kNotAssigned); + MaybeAssignedFlag::kMaybeAssigned); Variable* var = DeclareClassVariable( ast_value_factory, ast_value_factory->GetString(name, SharedStringAccessGuardIfNeeded(isolate)), scope_info->EndPosition()); + var->set_maybe_assigned(); var->AllocateTo(VariableLocation::CONTEXT, Context::MIN_CONTEXT_SLOTS + index); } - DCHECK(scope_info->HasPositionInfo()); + DCHECK(!scope_info->IsEmpty()); set_start_position(scope_info->StartPosition()); set_end_position(scope_info->EndPosition()); } @@ -265,7 +266,6 @@ Scope::Scope(Zone* zone, ScopeType scope_type, already_resolved_ = true; #endif set_language_mode(scope_info->language_mode()); - DCHECK_EQ(ContextHeaderLength(), num_heap_slots_); set_private_name_lookup_skips_outer_class( scope_info->PrivateNameLookupSkipsOuterClass()); // We don't really need to use the preparsed scope data; this is just to @@ -395,7 +395,7 @@ void Scope::SetDefaults() { IsHoistedInContextField::encode(false); num_stack_slots_ = 0; - num_heap_slots_ = ContextHeaderLength(); + num_heap_slots_ = 0; set_language_mode(LanguageMode::kSloppy); } @@ -449,7 +449,6 @@ Scope* Scope::DeserializeScopeChain( DeclarationScope* eval_scope = zone->New(zone, EVAL_SCOPE, ast_value_factory, isolate->factory()->empty_scope_info()); - eval_scope->num_heap_slots_ = 0; int position = script->eval_from_position(); eval_scope->set_start_position(position); eval_scope->set_end_position(position); @@ -473,10 +472,6 @@ Scope* Scope::DeserializeScopeChain( continue; } - if (parse_info && IsGeneratorFunction(scope_info->function_kind())) { - parse_info->set_has_generator_in_scope_chain(); - } - if (scope_info->scope_type() == FUNCTION_SCOPE) { outer_scope = zone->New( zone, FUNCTION_SCOPE, ast_value_factory, handle(scope_info, isolate)); @@ -501,6 +496,7 @@ Scope* Scope::DeserializeScopeChain( if (deserialization_mode == DeserializationMode::kIncludingVariables) { script_scope->SetScriptScopeInfo(handle(scope_info, isolate)); } + script_scope->num_heap_slots_ = scope_info->ContextLength(); script_scope->set_start_position(scope_info->StartPosition()); script_scope->set_end_position(scope_info->EndPosition()); DCHECK(!scope_info->HasOuterScopeInfo()); @@ -559,6 +555,7 @@ Scope* Scope::DeserializeScopeChain( if (current_scope != nullptr) { outer_scope->AddInnerScope(current_scope); } + outer_scope->num_heap_slots_ = scope_info->ContextLength(); outer_scope->set_start_position(scope_info->StartPosition()); outer_scope->set_end_position(scope_info->EndPosition()); @@ -622,11 +619,6 @@ const DeclarationScope* Scope::AsDeclarationScope() const { return static_cast(this); } -FunctionKind Scope::scope_closure_function_kind() const { - if (!scope_info_.is_null()) return scope_info_->function_kind(); - return GetClosureScope()->function_kind(); -} - ModuleScope* Scope::AsModuleScope() { SBXCHECK(is_module_scope()); return static_cast(this); @@ -894,15 +886,16 @@ Variable* DeclarationScope::DeclareFunctionVar(const AstRawString* name, if (cache == nullptr) { DCHECK_NULL(function_); cache = this; - } else if (function_ != nullptr) { - return function_; } DCHECK(this->IsOuterScopeOf(cache)); DCHECK_NULL(cache->variables_.Lookup(name)); - VariableKind kind = is_sloppy(language_mode()) ? SLOPPY_FUNCTION_NAME_VARIABLE - : NORMAL_VARIABLE; - function_ = zone()->New(this, name, VariableMode::kConst, kind, - kCreatedInitialized); + if (function_ == nullptr) { + VariableKind kind = is_sloppy(language_mode()) + ? SLOPPY_FUNCTION_NAME_VARIABLE + : NORMAL_VARIABLE; + function_ = zone()->New(this, name, VariableMode::kConst, kind, + kCreatedInitialized); + } if (sloppy_eval_can_extend_vars()) { cache->NonLocal(name, VariableMode::kDynamic); } else { @@ -975,7 +968,7 @@ Scope* Scope::FinalizeBlockScope() { !AsDeclarationScope()->sloppy_eval_can_extend_vars()); // This block does not need a context. - num_heap_slots_ = 0; + DCHECK_EQ(0, num_heap_slots_); // Mark scope as removed by making it its own sibling. #ifdef DEBUG @@ -1043,37 +1036,6 @@ void Scope::Snapshot::Reparent(DeclarationScope* new_parent) { } } -void Scope::MarkUnresolvedVariablesAsInsideTryCatch() { - // While proxy marking is generic, we only actually call this when nested in a - // generator because that's the only place we care about variables escaping - // try-catch blocks (for hole check elision and resume logic). - for (VariableProxy* proxy : unresolved_list_) { - proxy->set_is_inside_try_catch(); - } - for (Scope* inner = inner_scope_; inner; inner = inner->sibling_) { - if (inner->is_closure_scope()) continue; - inner->MarkUnresolvedVariablesAsInsideTryCatch(); - } -} - -void Scope::Snapshot::MarkUnresolvedVariablesAsInsideTryCatch() { - // While proxy marking is generic, we only actually call this when nested in a - // generator because that's the only place we care about variables escaping - // try-catch blocks (for hole check elision and resume logic). - auto it = top_unresolved_; - auto end = outer_scope_->unresolved_list_.end(); - - while (it != end) { - (*it)->set_is_inside_try_catch(); - ++it; - } - for (Scope* inner = outer_scope_->inner_scope_; inner != top_inner_scope_; - inner = inner->sibling_) { - if (inner->is_closure_scope()) continue; - inner->MarkUnresolvedVariablesAsInsideTryCatch(); - } -} - Variable* Scope::LookupInScopeInfo(const AstRawString* name, Scope* cache) { DCHECK(!scope_info_.is_null()); DCHECK(this->IsOuterScopeOf(cache)); @@ -1437,16 +1399,7 @@ Declaration* DeclarationScope::CheckConflictingVarDeclarations( // anything, so we can't conflict with anything either. The one // exception is the binding variable in catch scopes, which is handled // by the if above. - if (!IsLexicalVariableMode(other_var->mode())) { - if (current->sloppy_eval_can_extend_vars()) { - // See the comment for RemoveDynamic. In addition to removing - // dynamic variables we also need to remove function_ since - // otherwise we won't recreate a masking dynamic variable during - // scope resolution, causing divergent compilation. - current->AsDeclarationScope()->function_ = nullptr; - } - break; - } + if (!IsLexicalVariableMode(other_var->mode())) break; return decl; } current = current->outer_scope(); @@ -1612,18 +1565,6 @@ DeclarationScope* Scope::GetClosureScope() { return scope->AsDeclarationScope(); } -bool Scope::HasOuterGenerator() const { - const Scope* scope = GetClosureScope()->outer_scope(); - while (scope != nullptr) { - scope = scope->GetClosureScope(); - if (IsGeneratorFunction(scope->AsDeclarationScope()->function_kind())) { - return true; - } - scope = scope->outer_scope(); - } - return false; -} - bool Scope::NeedsScopeInfo() const { DCHECK(!already_resolved_); DCHECK(GetClosureScope()->ShouldEagerCompile()); @@ -1779,7 +1720,7 @@ void Scope::AnalyzePartially(DeclarationScope* max_outer_scope, } } else { var->set_is_used(); - UpdateVariableMaybeAssigned(var, proxy, scope); + if (proxy->is_assigned()) var->SetMaybeAssigned(); } } @@ -2535,36 +2476,11 @@ bool UpdateNeedsHoleCheck(Variable* var, VariableProxy* proxy, Scope* scope, } // anonymous namespace -void Scope::UpdateVariableMaybeAssigned(Variable* var, VariableProxy* proxy, - Scope* current_scope) { - if (proxy->is_assigned()) { - var->SetMaybeAssigned(); - return; - } - - if (proxy->is_inside_try_catch()) { - Variable* true_var = var; - while (true_var->has_local_if_not_shadowed()) { - true_var = true_var->local_if_not_shadowed(); - } - if (!true_var->scope()->IsOuterScopeUpToClosureScopeOf(current_scope) && - IsGeneratorFunction(true_var->scope()->scope_closure_function_kind())) { - // We treat variables captured by generator yields in a try-catch as - // maybe_assigned since the context allocation and assignment might be - // skipped when resuming from a yield. - // See test/mjsunit/maglev/context-inverted-generator2.js. - true_var->SetMaybeAssigned(); - } - } -} - void Scope::ResolveTo(VariableProxy* proxy, Variable* var, int access_position) { DCHECK_NOT_NULL(var); UpdateNeedsHoleCheck(var, proxy, this, access_position); proxy->BindTo(var); - - UpdateVariableMaybeAssigned(var, proxy, this); } void Scope::ResolvePreparsedVariable(VariableProxy* proxy, Scope* scope, @@ -2576,7 +2492,7 @@ void Scope::ResolvePreparsedVariable(VariableProxy* proxy, Scope* scope, var->set_is_used(); if (!var->is_dynamic()) { var->ForceContextAllocation(); - UpdateVariableMaybeAssigned(var, proxy, scope); + if (proxy->is_assigned()) var->SetMaybeAssigned(); return; } } @@ -2656,7 +2572,8 @@ void Scope::AllocateStackSlot(Variable* var) { void Scope::AllocateHeapSlot(Variable* var) { - var->AllocateTo(VariableLocation::CONTEXT, num_heap_slots_++); + var->AllocateTo(VariableLocation::CONTEXT, + ContextHeaderLength() + num_heap_slots_++); } void DeclarationScope::AllocateParameterLocals() { @@ -2840,10 +2757,7 @@ void Scope::AllocateVariablesRecursively() { this->ForEach([](Scope* scope) -> Iteration { DCHECK(!scope->already_resolved_); if (WasLazilyParsed(scope)) return Iteration::kContinue; - if (scope->sloppy_eval_can_extend_vars()) { - scope->num_heap_slots_ = Context::MIN_CONTEXT_EXTENDED_SLOTS; - } - DCHECK_EQ(scope->ContextHeaderLength(), scope->num_heap_slots_); + DCHECK_EQ(0, scope->num_heap_slots_); // Allocate variables for this scope. // Parameters must be allocated first, if any. @@ -2855,24 +2769,11 @@ void Scope::AllocateVariablesRecursively() { } scope->AllocateNonParameterLocalsAndDeclaredGlobals(); - // Force allocation of a context for this scope if necessary. For a 'with' - // scope and for a function scope that makes an 'eval' call we need a - // context, even if no local variables were statically allocated in the - // scope. Likewise for modules. Also force a context, if the scope is - // stricter than the outer scope. - bool must_have_context = - scope->is_with_scope() || scope->is_module_scope() || - scope->ForceContextForLanguageMode() || - (scope->is_function_scope() && - scope->AsDeclarationScope()->sloppy_eval_can_extend_vars()) || - (scope->is_block_scope() && scope->is_declaration_scope() && - scope->AsDeclarationScope()->sloppy_eval_can_extend_vars()); - - // If we didn't allocate any locals in the local context, then we only - // need the minimal number of slots if we must have a context. - if (scope->num_heap_slots_ == scope->ContextHeaderLength() && - !must_have_context) { - scope->num_heap_slots_ = 0; + // If we need a context, ensure num_heap_slots_ includes space for the + // context header. + if (scope->num_heap_slots_ > 0 || scope->HasContextExtensionSlot() || + scope->ForceContextForLanguageMode()) { + scope->num_heap_slots_ += scope->ContextHeaderLength(); } // If the number of context slots are over the function context threshold, @@ -2882,9 +2783,6 @@ void Scope::AllocateVariablesRecursively() { scope->set_has_context_cells(false); } - // Allocation done. - DCHECK(scope->num_heap_slots_ == 0 || - scope->num_heap_slots_ >= scope->ContextHeaderLength()); return Iteration::kDescend; }); } @@ -2892,8 +2790,7 @@ void Scope::AllocateVariablesRecursively() { template void Scope::AllocateScopeInfosRecursively( IsolateT* isolate, MaybeHandle outer_scope, - std::unordered_map>& scope_infos_to_reuse, - FunctionKind closure_function_kind) { + std::unordered_map>& scope_infos_to_reuse) { DCHECK(scope_info_.is_null()); MaybeHandle next_outer_scope = outer_scope; @@ -2915,8 +2812,7 @@ void Scope::AllocateScopeInfosRecursively( it->second = {}; #endif } else if (NeedsScopeInfo()) { - scope_info_ = ScopeInfo::Create(isolate, zone(), this, outer_scope, - closure_function_kind); + scope_info_ = ScopeInfo::Create(isolate, zone(), this, outer_scope); #ifdef DEBUG // Mark this ID as being used. scope_infos_to_reuse[UniqueIdInScript()] = {}; @@ -2940,12 +2836,8 @@ void Scope::AllocateScopeInfosRecursively( } if (!scope->is_function_scope() || scope->AsDeclarationScope()->ShouldEagerCompile()) { - FunctionKind inner_closure_kind = - scope->is_closure_scope() - ? scope->AsDeclarationScope()->function_kind() - : closure_function_kind; - scope->AllocateScopeInfosRecursively( - isolate, next_outer_scope, scope_infos_to_reuse, inner_closure_kind); + scope->AllocateScopeInfosRecursively(isolate, next_outer_scope, + scope_infos_to_reuse); } else { auto scope_it = scope_infos_to_reuse.find(scope->UniqueIdInScript()); if (scope_it != scope_infos_to_reuse.end()) { @@ -2963,14 +2855,12 @@ template EXPORT_TEMPLATE_DEFINE(V8_EXPORT_PRIVATE) void Scope:: AllocateScopeInfosRecursively( Isolate* isolate, MaybeHandle outer_scope, std::unordered_map>& - scope_infos_to_reuse, - FunctionKind closure_function_kind); + scope_infos_to_reuse); template EXPORT_TEMPLATE_DEFINE(V8_EXPORT_PRIVATE) void Scope:: AllocateScopeInfosRecursively( LocalIsolate* isolate, MaybeHandle outer_scope, std::unordered_map>& - scope_infos_to_reuse, - FunctionKind closure_function_kind); + scope_infos_to_reuse); void DeclarationScope::RecalcPrivateNameContextChain() { // The outermost scope in a class heritage expression is marked to skip the @@ -3028,6 +2918,7 @@ void DeclarationScope::AllocateScopeInfos(ParseInfo* parse_info, if (Scope* outer = scope->GetOuterScopeWithContext()) { DCHECK((std::is_same_v)); outer_scope = outer->scope_info_; + CHECK(!outer_scope.ToHandleChecked()->IsEmpty()); } } @@ -3054,7 +2945,7 @@ void DeclarationScope::AllocateScopeInfos(ParseInfo* parse_info, Tagged scope_info; if (Is(info)) { Tagged sfi = Cast(info); - if (!sfi->scope_info()->IsEmpty()) { + if (sfi->HasScopeInfo()) { scope_info = sfi->scope_info(); } else if (sfi->HasOuterScopeInfo()) { scope_info = sfi->GetOuterScopeInfo(); @@ -3063,7 +2954,7 @@ void DeclarationScope::AllocateScopeInfos(ParseInfo* parse_info, } } else { scope_info = Cast(info); - if (scope_info->IsEmpty()) continue; + DCHECK(!scope_info->IsEmpty()); } while (true) { if (scope_info == outer) break; @@ -3179,25 +3070,16 @@ void DeclarationScope::AllocateScopeInfos(ParseInfo* parse_info, } } - scope->AllocateScopeInfosRecursively( - isolate, outer_scope, scope_infos_to_reuse, - scope->GetClosureScope()->function_kind()); + scope->AllocateScopeInfosRecursively(isolate, outer_scope, + scope_infos_to_reuse); // The debugger expects all shared function infos to contain a scope info. // Since the top-most scope will end up in a shared function info, make sure // it has one, even if it doesn't need a scope info. // TODO(yangguo): Remove this requirement. if (scope->scope_info_.is_null()) { - scope->scope_info_ = ScopeInfo::Create(isolate, scope->zone(), scope, - outer_scope, scope->function_kind()); - } - - // Ensuring that the outer script scope has a scope info avoids having - // special case for native contexts vs other contexts. - if (parse_info->script_scope() && - parse_info->script_scope()->scope_info_.is_null()) { - parse_info->script_scope()->scope_info_ = - isolate->factory()->empty_scope_info(); + scope->scope_info_ = + ScopeInfo::Create(isolate, scope->zone(), scope, outer_scope); } } diff --git a/deps/v8/src/ast/scopes.h b/deps/v8/src/ast/scopes.h index 5a7effdcafa2..f85e7420968f 100644 --- a/deps/v8/src/ast/scopes.h +++ b/deps/v8/src/ast/scopes.h @@ -121,10 +121,6 @@ class V8_EXPORT_PRIVATE Scope : public NON_EXPORTED_BASE(ZoneObject) { // to REPL_GLOBAL. Should only be called on REPL scripts. void RewriteReplGlobalVariables(); - // Mark all unresolved variables added after taking the snapshot as inside a - // try/catch. - void MarkUnresolvedVariablesAsInsideTryCatch(); - class Snapshot final { public: inline explicit Snapshot(Scope* scope); @@ -145,9 +141,6 @@ class V8_EXPORT_PRIVATE Scope : public NON_EXPORTED_BASE(ZoneObject) { } void Reparent(DeclarationScope* new_parent); - // Mark all unresolved variables added after taking the snapshot as inside a - // try/catch. - void MarkUnresolvedVariablesAsInsideTryCatch(); private: Scope* outer_scope_; @@ -580,12 +573,6 @@ class V8_EXPORT_PRIVATE Scope : public NON_EXPORTED_BASE(ZoneObject) { DeclarationScope* GetClosureScope(); const DeclarationScope* GetClosureScope() const; - // Returns the function kind of the closure scope, even if the scope is fully - // deserialized and its closure scope isn't available. - FunctionKind scope_closure_function_kind() const; - - bool HasOuterGenerator() const; - // Returns true if this scope is an outer scope of the given scope, up to // and including the closure scope of the given scope. bool IsOuterScopeUpToClosureScopeOf(Scope* scope) const; @@ -814,8 +801,6 @@ class V8_EXPORT_PRIVATE Scope : public NON_EXPORTED_BASE(ZoneObject) { bool force_context_allocation = false); static void ResolvePreparsedVariable(VariableProxy* proxy, Scope* scope, Scope* end); - static void UpdateVariableMaybeAssigned(Variable* var, VariableProxy* proxy, - Scope* current_scope); void ResolveTo(VariableProxy* proxy, Variable* var, int access_position); void ResolveVariable(VariableProxy* proxy); V8_WARN_UNUSED_RESULT bool ResolveVariablesRecursively(Scope* end); @@ -846,8 +831,7 @@ class V8_EXPORT_PRIVATE Scope : public NON_EXPORTED_BASE(ZoneObject) { template void AllocateScopeInfosRecursively( IsolateT* isolate, MaybeHandle outer_scope, - std::unordered_map>& scope_infos_to_reuse, - FunctionKind closure_function_kind); + std::unordered_map>& scope_infos_to_reuse); // Construct a scope based on the scope info. Scope(Zone* zone, ScopeType type, AstValueFactory* ast_value_factory, diff --git a/deps/v8/src/ast/variables.h b/deps/v8/src/ast/variables.h index 7c83c3357184..342ac2740768 100644 --- a/deps/v8/src/ast/variables.h +++ b/deps/v8/src/ast/variables.h @@ -93,6 +93,9 @@ class Variable final : public ZoneObject { void clear_maybe_assigned() { bit_field_ = MaybeAssignedFlagField::update(bit_field_, kNotAssigned); } + void set_maybe_assigned() { + bit_field_ = MaybeAssignedFlagField::update(bit_field_, kMaybeAssigned); + } void SetMaybeAssigned() { if (IsImmutableLexicalVariableMode(mode())) { return; @@ -304,11 +307,13 @@ class Variable final : public ZoneObject { } // LINT.ThenChange(/src/debug/debug-scope-info.cc:VariableIsReceiver) + // LINT.IfChange(VariableIsExport) bool IsExport() const { DCHECK_EQ(location(), VariableLocation::MODULE); DCHECK_NE(index(), 0); return index() > 0; } + // LINT.ThenChange(/src/debug/debug-scope-info.h:VariableIsExport) void AllocateTo(VariableLocation location, int index) { DCHECK(IsUnallocated() || @@ -355,10 +360,6 @@ class Variable final : public ZoneObject { uint16_t bit_field_; uint16_t hole_check_analysis_bit_field_; - void set_maybe_assigned() { - bit_field_ = MaybeAssignedFlagField::update(bit_field_, kMaybeAssigned); - } - uint8_t HoleCheckBitmapIndex() const { return HoleCheckBitmapIndexField::decode(hole_check_analysis_bit_field_); } diff --git a/deps/v8/src/base/cpu/cpu-x86.cc b/deps/v8/src/base/cpu/cpu-x86.cc index 96ba25d15b2f..c50ed8dabcb3 100644 --- a/deps/v8/src/base/cpu/cpu-x86.cc +++ b/deps/v8/src/base/cpu/cpu-x86.cc @@ -133,7 +133,7 @@ void CPU::DetectFeatures() { has_avx_ = (cpu_info[2] & 0x10000000) != 0; has_avx2_ = (cpu_info70[1] & 0x00000020) != 0; has_avx_vnni_ = (cpu_info71[0] & 0x00000010) != 0; - has_avx_vnni_int8_ = (cpu_info71[3] & 0x00000020) != 0; + has_avx_vnni_int8_ = (cpu_info71[3] & 0x00000010) != 0; has_fma3_ = (cpu_info[2] & 0x00001000) != 0; has_f16c_ = (cpu_info[2] & 0x20000000) != 0; has_apx_f_ = (cpu_info71[3] & 0x00200000) != 0; diff --git a/deps/v8/src/base/platform/platform-posix.cc b/deps/v8/src/base/platform/platform-posix.cc index df122799fdca..7add12aa4798 100644 --- a/deps/v8/src/base/platform/platform-posix.cc +++ b/deps/v8/src/base/platform/platform-posix.cc @@ -82,19 +82,7 @@ #define MAP_ANONYMOUS MAP_ANON #endif -/* - * NOTE: illumos starting with illumos#14418 (pushed April 20th, 2022) - * prototypes madvise(3C) properly with a `void *` first argument. - * The only way to detect this outside of configure-time checking is to - * check for the existence of MEMCNTL_SHARED, which gets defined for the first - * time in illumos#14418 under the same circumstances save _STRICT_POSIX, which - * thankfully neither Solaris nor illumos builds of Node or V8 do. - * - * If some future illumos push changes the MEMCNTL_SHARED assumptions made - * above, the illumos check below will have to be revisited. This check - * will work on both pre-and-post illumos#14418 illumos environments. - */ -#if defined(V8_OS_SOLARIS) && !(defined(__illumos__) && defined(MEMCNTL_SHARED)) +#if defined(V8_OS_SOLARIS) #if (defined(_POSIX_C_SOURCE) && _POSIX_C_SOURCE > 2) || defined(__EXTENSIONS__) extern "C" int madvise(caddr_t, size_t, int); #else diff --git a/deps/v8/src/base/region-allocator.cc b/deps/v8/src/base/region-allocator.cc index 82642f6ab8c3..a7bc479bd08a 100644 --- a/deps/v8/src/base/region-allocator.cc +++ b/deps/v8/src/base/region-allocator.cc @@ -301,7 +301,8 @@ RegionAllocator::Address RegionAllocator::AllocateRegion(Address hint, return address; } -size_t RegionAllocator::TrimRegion(Address address, size_t new_size) { +size_t RegionAllocator::TrimRegion(Address address, size_t new_size, + AddressRegion* free_region) { DCHECK(IsAligned(new_size, page_size_)); AllRegionsSet::iterator region_iter = FindRegion(address); @@ -350,6 +351,7 @@ size_t RegionAllocator::TrimRegion(Address address, size_t new_size) { } } FreeListAddRegion(region); + if (free_region) *free_region = *region; return size; } diff --git a/deps/v8/src/base/region-allocator.h b/deps/v8/src/base/region-allocator.h index 09431254ed0b..ead800acc80e 100644 --- a/deps/v8/src/base/region-allocator.h +++ b/deps/v8/src/base/region-allocator.h @@ -106,13 +106,18 @@ class V8_BASE_EXPORT RegionAllocator final { // Frees region at given |address|, returns the size of the region. // There must be a used region starting at given address otherwise nothing // will be freed and 0 will be returned. - size_t FreeRegion(Address address) { return TrimRegion(address, 0); } + // If |free_region| is given, it receives the free region that the freed + // region became part of, after merging with any free neighbours. + size_t FreeRegion(Address address, AddressRegion* free_region = nullptr) { + return TrimRegion(address, 0, free_region); + } // Decreases size of the previously allocated region at |address|, returns // freed size. |new_size| must be |page_size|-aligned and // less than or equal to current region's size. Setting new size to zero - // frees the region. - size_t TrimRegion(Address address, size_t new_size); + // frees the region. |free_region| is as for FreeRegion(). + size_t TrimRegion(Address address, size_t new_size, + AddressRegion* free_region = nullptr); // Tries to grow the region at |address| to the size |new_size|. Returns true // on success. diff --git a/deps/v8/src/baseline/baseline-compiler.cc b/deps/v8/src/baseline/baseline-compiler.cc index 304dc849ac9c..91fa8f40e4ba 100644 --- a/deps/v8/src/baseline/baseline-compiler.cc +++ b/deps/v8/src/baseline/baseline-compiler.cc @@ -836,6 +836,10 @@ void BaselineCompiler::VisitLdaTheHole() { __ LoadRoot(kInterpreterAccumulatorRegister, RootIndex::kTheHoleValue); } +void BaselineCompiler::VisitLdaTdzHole() { + __ LoadRoot(kInterpreterAccumulatorRegister, RootIndex::kTdzHoleValue); +} + void BaselineCompiler::VisitLdaTrue() { __ LoadRoot(kInterpreterAccumulatorRegister, RootIndex::kTrueValue); } @@ -2820,9 +2824,9 @@ void BaselineCompiler::VisitReturn() { -profiling_weight); } -void BaselineCompiler::VisitThrowReferenceErrorIfHole() { +void BaselineCompiler::VisitThrowReferenceErrorIfTdzHole() { Label done; - __ JumpIfNotRoot(kInterpreterAccumulatorRegister, RootIndex::kTheHoleValue, + __ JumpIfNotRoot(kInterpreterAccumulatorRegister, RootIndex::kTdzHoleValue, &done); CallRuntime(Runtime::kThrowAccessedUninitializedVariable, Constant(0)); // Unreachable. @@ -2830,9 +2834,9 @@ void BaselineCompiler::VisitThrowReferenceErrorIfHole() { __ Bind(&done); } -void BaselineCompiler::VisitThrowSuperNotCalledIfHole() { +void BaselineCompiler::VisitThrowSuperNotCalledIfTdzHole() { Label done; - __ JumpIfNotRoot(kInterpreterAccumulatorRegister, RootIndex::kTheHoleValue, + __ JumpIfNotRoot(kInterpreterAccumulatorRegister, RootIndex::kTdzHoleValue, &done); CallRuntime(Runtime::kThrowSuperNotCalled); // Unreachable. @@ -2840,9 +2844,9 @@ void BaselineCompiler::VisitThrowSuperNotCalledIfHole() { __ Bind(&done); } -void BaselineCompiler::VisitThrowSuperAlreadyCalledIfNotHole() { +void BaselineCompiler::VisitThrowSuperAlreadyCalledIfNotTdzHole() { Label done; - __ JumpIfRoot(kInterpreterAccumulatorRegister, RootIndex::kTheHoleValue, + __ JumpIfRoot(kInterpreterAccumulatorRegister, RootIndex::kTdzHoleValue, &done); CallRuntime(Runtime::kThrowSuperAlreadyCalledError); // Unreachable. diff --git a/deps/v8/src/builtins/arm/builtins-arm.cc b/deps/v8/src/builtins/arm/builtins-arm.cc index 7fdedb6e0048..b3b37efa1f84 100644 --- a/deps/v8/src/builtins/arm/builtins-arm.cc +++ b/deps/v8/src/builtins/arm/builtins-arm.cc @@ -117,7 +117,7 @@ void Generate_JSBuiltinsConstructStubHelper(MacroAssembler* masm) { // r0: Number of arguments. Generate_PushArguments(masm, r4, r0, r5, ArgumentsElementType::kRaw); // The receiver for the builtin/api call. - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Call the function. // r0: number of arguments (untagged) @@ -186,9 +186,9 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { __ CallBuiltin(Builtin::kFastNewObject); __ b(&post_instantiation_deopt_entry); - // Else: use TheHoleValue as receiver for constructor call + // Else: use TdzHoleValue as receiver for constructor call __ bind(¬_create_implicit_receiver); - __ LoadRoot(r0, RootIndex::kTheHoleValue); + __ LoadRoot(r0, RootIndex::kTdzHoleValue); // ----------- S t a t e ------------- // -- r0: receiver @@ -256,7 +256,7 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { // on-stack receiver as the result. __ bind(&use_receiver); __ ldr(r0, MemOperand(sp, 0 * kPointerSize)); - __ JumpIfRoot(r0, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(r0, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Restore arguments count from the frame. @@ -1564,7 +1564,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( FrameScope scope(masm, StackFrame::MANUAL); __ EnterFrame(StackFrame::FAST_CONSTRUCT); // Implicit receiver stored in the construct frame. - __ LoadRoot(r2, RootIndex::kTheHoleValue); + __ LoadRoot(r2, RootIndex::kTdzHoleValue); __ Push(cp, r2); // Push arguments + implicit receiver. @@ -1625,7 +1625,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ bind(&use_receiver); __ ldr(r0, MemOperand(fp, FastConstructFrameConstants::kImplicitReceiverOffset)); - __ JumpIfRoot(r0, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(r0, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Leave construct frame. diff --git a/deps/v8/src/builtins/arm64/builtins-arm64.cc b/deps/v8/src/builtins/arm64/builtins-arm64.cc index 083e3f09db8b..17552f4d0dd3 100644 --- a/deps/v8/src/builtins/arm64/builtins-arm64.cc +++ b/deps/v8/src/builtins/arm64/builtins-arm64.cc @@ -101,7 +101,7 @@ void Generate_JSBuiltinsConstructStubHelper(MacroAssembler* masm) { __ Claim(slot_count); // Preserve the incoming parameters on the stack. - __ LoadRoot(x4, RootIndex::kTheHoleValue); + __ LoadRoot(x4, RootIndex::kTdzHoleValue); // Compute a pointer to the slot immediately above the location on the // stack to which arguments will be later copied. @@ -234,9 +234,9 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { __ B(&post_instantiation_deopt_entry); - // Else: use TheHoleValue as receiver for constructor call + // Else: use TdzHoleValue as receiver for constructor call __ Bind(¬_create_implicit_receiver); - __ LoadRoot(x0, RootIndex::kTheHoleValue); + __ LoadRoot(x0, RootIndex::kTdzHoleValue); // ----------- S t a t e ------------- // -- x0: receiver @@ -334,7 +334,7 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { // on-stack receiver as the result. __ Bind(&use_receiver); __ Peek(x0, 0 * kSystemPointerSize); - __ CompareRoot(x0, RootIndex::kTheHoleValue); + __ CompareRoot(x0, RootIndex::kTdzHoleValue); __ B(eq, &do_throw); __ Bind(&leave_and_return); @@ -1245,17 +1245,13 @@ void Builtins::Generate_BaselineOutOfLinePrologue(MacroAssembler* masm) { FrameScope frame_scope(masm, StackFrame::INTERNAL); // Save incoming new target or generator - Register maybe_dispatch_handle = V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE_BOOL - ? kJavaScriptCallDispatchHandleRegister - : padreg; - // No need to SmiTag as dispatch handles always look like Smis. - static_assert(kJSDispatchHandleShift > 0); - __ AssertSmi(maybe_dispatch_handle); - __ Push(maybe_dispatch_handle, new_target); + __ PushDispatchHandle(kJavaScriptCallDispatchHandleRegister, new_target, + feedback_cell, feedback_vector); __ SmiTag(frame_size); __ PushArgument(frame_size); __ CallRuntime(Runtime::kStackGuardWithGap); - __ Pop(new_target, maybe_dispatch_handle); + __ PopDispatchHandle(kJavaScriptCallDispatchHandleRegister, new_target, + feedback_cell, feedback_vector); } __ LoadRoot(kInterpreterAccumulatorRegister, RootIndex::kUndefinedValue); __ Ret(); @@ -1849,7 +1845,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( } // Implicit receiver stored in the construct frame. - __ LoadRoot(x2, RootIndex::kTheHoleValue); + __ LoadRoot(x2, RootIndex::kTdzHoleValue); __ Push(x2, padreg); // Push arguments + implicit receiver. @@ -1907,7 +1903,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ Bind(&use_receiver); __ Ldr(x0, MemOperand(fp, FastConstructFrameConstants::kImplicitReceiverOffset)); - __ CompareRoot(x0, RootIndex::kTheHoleValue); + __ CompareRoot(x0, RootIndex::kTdzHoleValue); __ B(eq, &do_throw); __ Bind(&leave_and_return); diff --git a/deps/v8/src/builtins/array-join.tq b/deps/v8/src/builtins/array-join.tq index 324013960e34..e721954d2c70 100644 --- a/deps/v8/src/builtins/array-join.tq +++ b/deps/v8/src/builtins/array-join.tq @@ -351,22 +351,14 @@ macro BufferJoin(implicit context: Context)(buffer: Buffer, sep: String): transitioning macro FastArrayJoin( implicit context: Context)(kind: constexpr ElementsKind, - array: FastJSArrayForRead, sep: String, lengthNumber: Number): String + array: FastJSArrayForRead, sep: String, length: Smi): String labels Bailout { // Check early if the separators might overflow. - let len: uintptr = Convert(lengthNumber); - // Fast array length is guaranteed to fit in Smi. - dcheck(len <= Convert(kFixedArrayMaxLength)); - static_assert(Convert(kFixedArrayMaxLength) < kSmiMaxValue); - // If separatorLength <= 1, fast arrays cannot overflow the separator counter - // or exceed kStringMaxLength from separators alone, because their maximum - // length is bounded by kMaxFastArrayLength (32MB) which is much smaller - // than kStringMaxLength (268MB/536MB). Thus we only need to perform checks - // if separatorLength > 1. - static_assert( - (Convert(kFixedArrayMaxLength) - 1) <= - Convert(kStringMaxLength)); - + let len: uintptr = Convert(length); + dcheck(len <= kStringMaxLengthUintptr); + // If separatorLength <= 1, separators alone cannot overflow kStringMaxLength + // because length <= kStringMaxLength. Thus we only need to perform checks if + // separatorLength > 1. const separatorLength: intptr = sep.length_intptr; if (separatorLength > 1 && len > 1) { const lenInt: int32 = Convert(Signed(len)); @@ -881,6 +873,11 @@ transitioning builtin ArrayPrototypeJoinImpl( dcheck(len <= kMaxArrayLength); try { + const smiLen: Smi = Cast(len) otherwise Fallback; + // FastArrayJoin relies on len <= kStringMaxLength to guarantee that + // separators with length <= 1 cannot overflow the maximum string length. + if (smiLen > kStringMaxLength) goto Fallback; + const castResult = CastFastJSArrayForRead(o) otherwise Fallback; const fastO = castResult.object; const elementsKind = castResult.elementsKind; @@ -888,32 +885,32 @@ transitioning builtin ArrayPrototypeJoinImpl( if (IsFastSmiElementsKind(elementsKind)) { if (IsHoleyFastElementsKind(elementsKind)) { return FastArrayJoin( - ElementsKind::HOLEY_SMI_ELEMENTS, fastO, separator, len) + ElementsKind::HOLEY_SMI_ELEMENTS, fastO, separator, smiLen) otherwise Fallback; } else { return FastArrayJoin( - ElementsKind::PACKED_SMI_ELEMENTS, fastO, separator, len) + ElementsKind::PACKED_SMI_ELEMENTS, fastO, separator, smiLen) otherwise Fallback; } } else if (IsDoubleElementsKind(elementsKind)) { if (IsHoleyFastElementsKind(elementsKind)) { return FastArrayJoin( - ElementsKind::HOLEY_DOUBLE_ELEMENTS, fastO, separator, len) + ElementsKind::HOLEY_DOUBLE_ELEMENTS, fastO, separator, smiLen) otherwise Fallback; } else { return FastArrayJoin( - ElementsKind::PACKED_DOUBLE_ELEMENTS, fastO, separator, len) + ElementsKind::PACKED_DOUBLE_ELEMENTS, fastO, separator, smiLen) otherwise Fallback; } } else if (IsFastElementsKind(elementsKind)) { if (IsHoleyFastElementsKind(elementsKind)) { return FastArrayJoin( - ElementsKind::HOLEY_ELEMENTS, fastO, separator, len) + ElementsKind::HOLEY_ELEMENTS, fastO, separator, smiLen) otherwise Fallback; } else { return FastArrayJoin( - ElementsKind::PACKED_ELEMENTS, fastO, separator, len) + ElementsKind::PACKED_ELEMENTS, fastO, separator, smiLen) otherwise Fallback; } } diff --git a/deps/v8/src/builtins/base.tq b/deps/v8/src/builtins/base.tq index e3a860d00229..3bbd3108699b 100644 --- a/deps/v8/src/builtins/base.tq +++ b/deps/v8/src/builtins/base.tq @@ -646,6 +646,7 @@ extern macro SizeStringConstant(): String; extern macro StringStringConstant(): String; extern macro SuppressedStringConstant(): String; extern macro TheHoleConstant(): TheHole; +extern macro TdzHoleConstant(): TdzHole; extern macro PromiseHoleConstant(): PromiseHole; extern macro ToPrimitiveSymbolConstant(): PublicSymbol; extern macro ToStringStringConstant(): String; @@ -657,6 +658,7 @@ extern macro ValueOfStringConstant(): String; extern macro InvalidDispatchHandleConstant(): DispatchHandle; const TheHole: TheHole = TheHoleConstant(); +const TdzHole: TdzHole = TdzHoleConstant(); const PromiseHole: PromiseHole = PromiseHoleConstant(); const Null: Null = NullConstant(); const Undefined: Undefined = UndefinedConstant(); diff --git a/deps/v8/src/builtins/builtins-api.cc b/deps/v8/src/builtins/builtins-api.cc index ff7ef690b6e8..24c7180fc3bf 100644 --- a/deps/v8/src/builtins/builtins-api.cc +++ b/deps/v8/src/builtins/builtins-api.cc @@ -65,7 +65,7 @@ V8_WARN_UNUSED_RESULT MaybeHandle HandleApiCallHelper( Handle js_receiver; if (is_construct) { - DCHECK(IsTheHole(*receiver)); + DCHECK(IsTdzHole(*receiver)); if (IsUndefined(fun_data->GetInstanceTemplate())) { v8::Local templ = ObjectTemplate::New(reinterpret_cast(isolate), diff --git a/deps/v8/src/builtins/builtins-arraybuffer.cc b/deps/v8/src/builtins/builtins-arraybuffer.cc index f3a6e701fa15..1768bee4c08b 100644 --- a/deps/v8/src/builtins/builtins-arraybuffer.cc +++ b/deps/v8/src/builtins/builtins-arraybuffer.cc @@ -486,7 +486,18 @@ static Tagged ResizeHelper(BuiltinArguments args, Isolate* isolate, kMethodName))); } - if (is_shared && new_byte_length < array_buffer->GetByteLength()) { + auto* extension = array_buffer->extension(); + // Only resizable ArrayBuffer should get here. + SBXCHECK(extension->is_resizable_by_js()); + SBXCHECK_EQ(extension->is_shared(), SharedFlag(is_shared)); + + auto backing_store = extension->backing_store(); + + if (is_shared && + new_byte_length < backing_store->byte_length(std::memory_order_seq_cst)) { + // `backing_store->byte_length(std::memory_order_seq_cst)` above is + // equivalent to the GSAB path of JSArrayBuffer::GetByteLength. + // GrowableSharedArrayBuffer is only allowed to grow. THROW_NEW_ERROR_RETURN_FAILURE( isolate, NewRangeError(MessageTemplate::kInvalidArrayBufferResizeLength, @@ -506,7 +517,6 @@ static Tagged ResizeHelper(BuiltinArguments args, Isolate* isolate, // If hostHandled is handled, return undefined. #ifdef V8_ENABLE_WEBASSEMBLY - auto backing_store = array_buffer->GetBackingStore(); if (backing_store->is_wasm_memory()) { size_t old_byte_length = backing_store->byte_length(std::memory_order_seq_cst); @@ -549,8 +559,7 @@ static Tagged ResizeHelper(BuiltinArguments args, Isolate* isolate, // [RAB] NOTE: Neither creation of the new Data Block nor copying from the // old Data Block are observable. Implementations reserve the right to // implement this method as in-place growth or shrinkage. - if (array_buffer->GetBackingStore()->ResizeInPlace(isolate, - new_byte_length) != + if (backing_store->ResizeInPlace(isolate, new_byte_length) != BackingStore::ResizeOrGrowResult::kSuccess) { THROW_NEW_ERROR_RETURN_FAILURE( isolate, NewRangeError(MessageTemplate::kOutOfMemory, @@ -569,15 +578,14 @@ static Tagged ResizeHelper(BuiltinArguments args, Isolate* isolate, } isolate->heap()->ResizeArrayBufferExtension( - array_buffer->extension(), + extension, static_cast(new_byte_length) - array_buffer->byte_length()); // [RAB] Set O.[[ArrayBufferByteLength]] to newLength. array_buffer->set_byte_length(new_byte_length); } else { // [GSAB] (Detailed description of the algorithm omitted.) - auto result = - array_buffer->GetBackingStore()->GrowInPlace(isolate, new_byte_length); + auto result = backing_store->GrowInPlace(isolate, new_byte_length); if (result == BackingStore::ResizeOrGrowResult::kFailure) { THROW_NEW_ERROR_RETURN_FAILURE( isolate, NewRangeError(MessageTemplate::kOutOfMemory, diff --git a/deps/v8/src/builtins/builtins-date-gen.cc b/deps/v8/src/builtins/builtins-date-gen.cc index 37125aac6073..2c15fa4792af 100644 --- a/deps/v8/src/builtins/builtins-date-gen.cc +++ b/deps/v8/src/builtins/builtins-date-gen.cc @@ -5,6 +5,7 @@ #include "src/builtins/builtins-inl.h" #include "src/builtins/builtins-utils-gen.h" #include "src/codegen/code-stub-assembler-inl.h" +#include "src/date/date.h" #include "src/objects/dictionary.h" namespace v8 { @@ -72,6 +73,20 @@ void DateBuiltinsAssembler::Generate_DatePrototype_GetField( std::make_pair(MachineType::Pointer(), isolate_ptr), std::make_pair(MachineType::AnyTagged(), date_receiver), std::make_pair(MachineType::AnyTagged(), field_index_smi))); + if (field_index == JSDate::kTimezoneOffset) { + // The offset comes back in milliseconds because the C function runs under + // DisallowGarbageCollection and cannot allocate the HeapNumber that a + // fractional-minute offset needs. Divide here instead. The cached path + // above would skip this, so the field must be uncached. + static_assert(JSDate::kTimezoneOffset >= JSDate::kFirstUncachedField); + Label if_nan(this, Label::kDeferred); + GotoIfNot(TaggedIsSmi(result), &if_nan); + TNode offset_ms = CAST(result); + Return(ChangeFloat64ToTagged(Float64Div( + SmiToFloat64(offset_ms), + Float64Constant(static_cast(DateCache::kMsPerMin))))); + BIND(&if_nan); + } Return(result); } diff --git a/deps/v8/src/builtins/builtins-function.cc b/deps/v8/src/builtins/builtins-function.cc index b511c42836f7..f7ca54126017 100644 --- a/deps/v8/src/builtins/builtins-function.cc +++ b/deps/v8/src/builtins/builtins-function.cc @@ -2,12 +2,14 @@ // Use of this source code is governed by a BSD-style license that can be // found in the LICENSE file. +#include "src/api/api-inl.h" #include "src/builtins/builtins-utils-inl.h" #include "src/builtins/builtins.h" #include "src/codegen/code-factory.h" #include "src/codegen/compiler.h" #include "src/handles/handle-scope-implementer-inl.h" #include "src/logging/counters.h" +#include "src/logging/runtime-call-stats-scope.h" #include "src/numbers/conversions.h" #include "src/objects/api-callbacks.h" #include "src/objects/lookup.h" @@ -19,6 +21,37 @@ namespace internal { namespace { +// Returns an embedder-provided source string, if any, or converts {arg} to a +// string. Throws if the embedder disallows code generation or ToString fails. +// TODO: Split this into a dedicated GetCodeForEvalCallback to align +// with HostGetCodeForEval, which only extracts code. CSP and permission +// validation belong in HostEnsureCanCompileStrings. +MaybeDirectHandle GetDynamicFunctionArgumentString( + Isolate* isolate, DirectHandle target, DirectHandle arg, + bool is_code_like, + v8::ModifyCodeGenerationFromStringsCallback2 modify_callback, + v8::Local v8_context) { + if (IsJSReceiver(*arg) && modify_callback) { + v8::Local v8_arg = Utils::ToLocal(arg); + RCS_SCOPE(isolate, + RuntimeCallCounterId::kCodeGenerationFromStringsCallbacks); + auto result = modify_callback(v8_context, v8_arg, is_code_like); + if (isolate->has_exception()) return {}; + if (!result.codegen_allowed) { + Handle error_message = + target->native_context()->ErrorMessageForCodeGenerationFromStrings(); + THROW_NEW_ERROR( + isolate, + NewEvalError(MessageTemplate::kCodeGenFromStrings, error_message)); + } + if (!result.modified_source.IsEmpty()) { + return Utils::OpenDirectHandle(*result.modified_source.ToLocalChecked()); + } + } + + return Object::ToString(isolate, arg); +} + // ES6 section 19.2.1.1.1 CreateDynamicFunction MaybeDirectHandle CreateDynamicFunction(Isolate* isolate, BuiltinArguments args, @@ -40,6 +73,38 @@ MaybeDirectHandle CreateDynamicFunction(Isolate* isolate, THROW_NEW_ERROR(isolate, NewTypeError(MessageTemplate::kNoAccess)); } + // Whether the overall constructed function should be treated as + // code-like, for use by Compiler::GetFunctionFromString below. + auto modify_callback = isolate->modify_code_gen_callback(); + v8::Local v8_context = + Utils::ToLocal(direct_handle(target->native_context(), isolate)); + + // Use an embedder-provided source string when available; otherwise, fall + // back to ToString(). + DirectHandleVector parameter_strings(isolate); + if (argc > 1) parameter_strings.reserve(argc - 1); + + // A call with no arguments has nothing trustworthy to base "code-like" + // on, so it starts false instead of true. + bool is_code_like = argc > 0; + DirectHandle body_string = isolate->factory()->empty_string(); + for (int i = 1; i <= argc; ++i) { + DirectHandle arg = args.at(i); + bool argument_is_code_like = Object::IsCodeLike(*arg, isolate); + is_code_like &= argument_is_code_like; + + DirectHandle argument_string; + ASSIGN_RETURN_ON_EXCEPTION(isolate, argument_string, + GetDynamicFunctionArgumentString( + isolate, target, arg, argument_is_code_like, + modify_callback, v8_context)); + if (i < argc) { + parameter_strings.push_back(argument_string); + } else { + body_string = argument_string; + } + } + // Build the source string. DirectHandle source; int parameters_end_pos = kNoSourcePosition; @@ -48,37 +113,18 @@ MaybeDirectHandle CreateDynamicFunction(Isolate* isolate, builder.AppendCharacter('('); builder.AppendCString(token); builder.AppendCStringLiteral(" anonymous("); - if (argc > 1) { - for (int i = 1; i < argc; ++i) { - if (i > 1) builder.AppendCharacter(','); - DirectHandle param; - ASSIGN_RETURN_ON_EXCEPTION(isolate, param, - Object::ToString(isolate, args.at(i))); - param = String::Flatten(isolate, param); - builder.AppendString(param); - } + for (size_t i = 0; i < parameter_strings.size(); ++i) { + if (i > 0) builder.AppendCharacter(','); + builder.AppendString(parameter_strings[i]); } builder.AppendCharacter('\n'); parameters_end_pos = builder.Length(); builder.AppendCStringLiteral(") {\n"); - if (argc > 0) { - DirectHandle body; - ASSIGN_RETURN_ON_EXCEPTION(isolate, body, - Object::ToString(isolate, args.at(argc))); - builder.AppendString(body); - } + builder.AppendString(body_string); builder.AppendCStringLiteral("\n})"); ASSIGN_RETURN_ON_EXCEPTION(isolate, source, builder.Finish()); } - bool is_code_like = true; - for (int i = 0; i < argc; ++i) { - if (!Object::IsCodeLike(*args.at(i + 1), isolate)) { - is_code_like = false; - break; - } - } - // Compile the string in the constructor and not a helper so that errors to // come from here. DirectHandle function; diff --git a/deps/v8/src/builtins/builtins-internal-gen.cc b/deps/v8/src/builtins/builtins-internal-gen.cc index 75deecf7d455..74703bcdb5c8 100644 --- a/deps/v8/src/builtins/builtins-internal-gen.cc +++ b/deps/v8/src/builtins/builtins-internal-gen.cc @@ -89,8 +89,11 @@ TF_BUILTIN(DebugBreakTrampoline, CodeStubAssembler) { #ifdef V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE auto dispatch_handle = UncheckedParameter(Descriptor::kJSDispatchHandle); + TNode expected_parameter_count = + LoadParameterCountFromJSDispatchTable(dispatch_handle); #else auto dispatch_handle = InvalidDispatchHandleConstant(); + TNode expected_parameter_count = Uint16Constant(0); #endif auto function = Parameter(Descriptor::kJSTarget); @@ -116,7 +119,8 @@ TF_BUILTIN(DebugBreakTrampoline, CodeStubAssembler) { TailCallJSCode( TrustedCast( code, "used in a call which will be checked via dispatch table"), - context, function, new_target, arg_count, dispatch_handle); + context, function, new_target, arg_count, dispatch_handle, + expected_parameter_count); } class WriteBarrierCodeStubAssembler : public CodeStubAssembler { diff --git a/deps/v8/src/builtins/builtins-intl-gen.cc b/deps/v8/src/builtins/builtins-intl-gen.cc index e095a5528af3..d4c7168db241 100644 --- a/deps/v8/src/builtins/builtins-intl-gen.cc +++ b/deps/v8/src/builtins/builtins-intl-gen.cc @@ -91,6 +91,10 @@ TF_BUILTIN(StringToLowerCaseIntl, IntlBuiltinsAssembler) { TF_BUILTIN(WasmStringToLowerCaseIntl, IntlBuiltinsAssembler) { auto context = Parameter(Descriptor::kContext); auto string = Parameter(Descriptor::kString); +#ifdef V8_IS_TSAN + CallRuntime(Runtime::kTsanAcquireForInitializationFence, context, + string); +#endif ToLowerCaseImpl(string, TNode() /*maybe_locales*/, context, ToLowerCaseKind::kToLowerCase, [this](TNode ret) { Return(ret); }); diff --git a/deps/v8/src/builtins/builtins-intl.cc b/deps/v8/src/builtins/builtins-intl.cc index 4b97358d910b..315b5f8c2c77 100644 --- a/deps/v8/src/builtins/builtins-intl.cc +++ b/deps/v8/src/builtins/builtins-intl.cc @@ -1241,8 +1241,7 @@ BUILTIN(CollatorInternalCompare) { Object::ToString(isolate, y)); // 7. Return CompareStrings(collator, X, Y). - CppGCManaged::Ptr icu_collator = - collator->icu_collator()->ptr(); + Managed::Ptr icu_collator = collator->icu_collator()->ptr(); CHECK_NOT_NULL(icu_collator); int result = Intl::CompareStrings(isolate, *icu_collator, string_x, string_y); // See StringPrototypeLocaleCompareIntl: the inline fast path relies on diff --git a/deps/v8/src/builtins/builtins-microtask-queue-gen.cc b/deps/v8/src/builtins/builtins-microtask-queue-gen.cc index 0193b0bd0cd7..725786e0b430 100644 --- a/deps/v8/src/builtins/builtins-microtask-queue-gen.cc +++ b/deps/v8/src/builtins/builtins-microtask-queue-gen.cc @@ -69,9 +69,8 @@ class MicrotaskQueueBuiltinsAssembler : public CodeStubAssembler { TNode MicrotaskQueueBuiltinsAssembler::GetMicrotaskQueue( TNode native_context) { CSA_DCHECK(this, IsNativeContext(native_context)); - return LoadCppHeapPointerFromObject(native_context, - NativeContext::kMicrotaskQueueOffset, - CppHeapPointerTag::kMicrotaskQueueTag); + return LoadCppHeapPointerFromObject( + native_context, NativeContext::kMicrotaskQueueOffset, kMicrotaskQueueTag); } TNode MicrotaskQueueBuiltinsAssembler::GetMicrotaskRingBuffer( diff --git a/deps/v8/src/builtins/builtins-regexp-gen.cc b/deps/v8/src/builtins/builtins-regexp-gen.cc index 951b56c662f0..fa705e82105f 100644 --- a/deps/v8/src/builtins/builtins-regexp-gen.cc +++ b/deps/v8/src/builtins/builtins-regexp-gen.cc @@ -267,10 +267,10 @@ void RegExpBuiltinsAssembler::ReplayLastMatchInfo( match_info = PrepareMatchInfo(context, match_info, SmiTag(register_count), subject); - // Both sides hold the capture offsets as Smis, so no write barrier is needed. - CopyRange(match_info, RegExpMatchInfo::OffsetOfElementAt(0), last_match_cache, - FixedArray::OffsetOfElementAt(0), register_count, - UNSAFE_SKIP_WRITE_BARRIER); + // Both sides hold the capture offsets as Smis. + CopyRange(match_info, RegExpMatchInfo::OffsetOfElementAt(0), + last_match_cache, FixedArray::OffsetOfElementAt(0), + register_count); Goto(&done); BIND(&done); @@ -292,10 +292,9 @@ TNode RegExpBuiltinsAssembler::SnapshotLastMatchInfo( TNode snapshot = CAST(AllocateFixedArray(PACKED_ELEMENTS, register_count)); - // Both sides hold the capture offsets as Smis, so no write barrier is needed. - CopyRange(snapshot, FixedArray::OffsetOfElementAt(0), match_info, - RegExpMatchInfo::OffsetOfElementAt(0), register_count, - UNSAFE_SKIP_WRITE_BARRIER); + // Both sides hold the capture offsets as Smis. + CopyRange(snapshot, FixedArray::OffsetOfElementAt(0), match_info, + RegExpMatchInfo::OffsetOfElementAt(0), register_count); var_result = snapshot; Goto(&done); diff --git a/deps/v8/src/builtins/builtins-string-gen.cc b/deps/v8/src/builtins/builtins-string-gen.cc index 06c2de1f2a76..d282fa8c5922 100644 --- a/deps/v8/src/builtins/builtins-string-gen.cc +++ b/deps/v8/src/builtins/builtins-string-gen.cc @@ -1014,6 +1014,12 @@ TF_BUILTIN(WasmJSStringEqual, StringBuiltinsAssembler) { // Callers must handle the case where {lhs} and {rhs} refer to the same // String object. CSA_DCHECK(this, TaggedNotEqual(left, right)); +#ifdef V8_IS_TSAN + CallRuntime(Runtime::kTsanAcquireForInitializationFence, NoContextConstant(), + right); + CallRuntime(Runtime::kTsanAcquireForInitializationFence, NoContextConstant(), + left); +#endif GenerateStringEqual(left, right, length); } @@ -1029,6 +1035,12 @@ TF_BUILTIN(WasmStringAdd_NoMapCheck, StringBuiltinsAssembler) { TF_BUILTIN(WasmStringCompare, StringBuiltinsAssembler) { auto left = Parameter(Descriptor::kLeft); auto right = Parameter(Descriptor::kRight); +#ifdef V8_IS_TSAN + CallRuntime(Runtime::kTsanAcquireForInitializationFence, NoContextConstant(), + right); + CallRuntime(Runtime::kTsanAcquireForInitializationFence, NoContextConstant(), + left); +#endif GenerateStringRelationalComparison(left, right, StringComparison::kCompare); } #endif diff --git a/deps/v8/src/builtins/builtins-typed-array-gen.cc b/deps/v8/src/builtins/builtins-typed-array-gen.cc index 6828322b6430..9a14e7162b00 100644 --- a/deps/v8/src/builtins/builtins-typed-array-gen.cc +++ b/deps/v8/src/builtins/builtins-typed-array-gen.cc @@ -498,7 +498,7 @@ void TypedArrayBuiltinsAssembler::SetJSTypedArrayOnHeapDataPtr( TNode ptr_compr_cage_base = IntPtrSub(full_base, Signed(ChangeUint32ToWord(compressed_base))); // Add JSTypedArray::ExternalPointerCompensationForOnHeapArray() to offset. - // See JSTypedArray::AddExternalPointerCompensationForDeserialization(). + // See JSTypedArray::InitOnHeapDataPtrAfterDeserialization(). DCHECK_EQ( isolate()->cage_base(), JSTypedArray::ExternalPointerCompensationForOnHeapArray(isolate())); diff --git a/deps/v8/src/builtins/cast.tq b/deps/v8/src/builtins/cast.tq index 0430427fa707..24cd719932b6 100644 --- a/deps/v8/src/builtins/cast.tq +++ b/deps/v8/src/builtins/cast.tq @@ -247,6 +247,16 @@ Cast(o: HeapObject): TheHole labels CastError { return Cast(o) otherwise CastError; } +Cast(o: Object): TdzHole labels CastError { + if (o == TdzHole) return %RawDownCast(o); + goto CastError; +} + +Cast(o: HeapObject): TdzHole labels CastError { + const o: Object = o; + return Cast(o) otherwise CastError; +} + Cast(o: Object): True labels CastError { if (o == True) return %RawDownCast(o); goto CastError; diff --git a/deps/v8/src/builtins/ia32/builtins-ia32.cc b/deps/v8/src/builtins/ia32/builtins-ia32.cc index 4af3c368c7c6..5ca8c70758cf 100644 --- a/deps/v8/src/builtins/ia32/builtins-ia32.cc +++ b/deps/v8/src/builtins/ia32/builtins-ia32.cc @@ -111,7 +111,7 @@ void Generate_JSBuiltinsConstructStubHelper(MacroAssembler* masm) { Generate_PushArguments(masm, esi, eax, ecx, no_reg, ArgumentsElementType::kRaw); // The receiver for the builtin/api call. - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Call the function. // eax: number of arguments (untagged) @@ -185,9 +185,9 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { __ CallBuiltin(Builtin::kFastNewObject); __ jmp(&post_instantiation_deopt_entry, Label::kNear); - // Else: use TheHoleValue as receiver for constructor call + // Else: use TdzHoleValue as receiver for constructor call __ bind(¬_create_implicit_receiver); - __ LoadRoot(eax, RootIndex::kTheHoleValue); + __ LoadRoot(eax, RootIndex::kTdzHoleValue); // ----------- S t a t e ------------- // -- eax: implicit receiver @@ -259,7 +259,7 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { // on-stack receiver as the result. __ bind(&use_receiver); __ mov(eax, Operand(esp, 0 * kSystemPointerSize)); - __ JumpIfRoot(eax, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(eax, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Restore arguments count from the frame. @@ -1579,7 +1579,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ EnterFrame(StackFrame::FAST_CONSTRUCT); __ Push(esi); // Implicit receiver stored in the construct frame. - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Push arguments + implicit receiver __ movd(eax, xmm0); // Recover number of arguments. @@ -1589,7 +1589,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ neg(esi); __ add(esi, ecx); GenerateInterpreterPushArgs(masm, esi, ecx); - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Restore context. __ mov(esi, Operand(ebp, FastConstructFrameConstants::kContextOffset)); @@ -1642,7 +1642,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( // on-stack receiver as the result. __ bind(&use_receiver); __ mov(eax, Operand(esp, 0 * kSystemPointerSize)); - __ JumpIfRoot(eax, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(eax, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); __ LeaveFrame(StackFrame::FAST_CONSTRUCT); diff --git a/deps/v8/src/builtins/js-to-wasm.tq b/deps/v8/src/builtins/js-to-wasm.tq index 8fc7fe1d54d4..8d72eccf7f4d 100644 --- a/deps/v8/src/builtins/js-to-wasm.tq +++ b/deps/v8/src/builtins/js-to-wasm.tq @@ -64,6 +64,7 @@ const kWasmF64Type: const kIsFpAlwaysDouble: constexpr bool generates 'wasm::kIsFpAlwaysDouble'; const kIsBigEndian: constexpr bool generates 'wasm::kIsBigEndian'; const kIsBigEndianOnSim: constexpr bool generates 'wasm::kIsBigEndianOnSim'; +const kFP32NeedNanBox: constexpr bool generates 'wasm::kFP32NeedNanBox'; extern enum Promise extends int32 constexpr 'wasm::Promise' { kPromise, @@ -692,7 +693,15 @@ macro JSToWasmWrapperHelper( if constexpr (kIsFpAlwaysDouble || kIsBigEndian || kIsBigEndianOnSim) { HandleF32Params(context, locationAllocator, toRef, param); } else { - *toRef = Convert(Bitcast(WasmTaggedToFloat32(param))); + const raw = + Convert(Bitcast(WasmTaggedToFloat32(param))); + if constexpr (kFP32NeedNanBox) { + // The assembly wrapper reloads f32 parameters with a 64-bit FP load + // (fld), so the slot must already contain a NaN-boxed f32. + *toRef = raw | (Convert(0xffffffff) << 32); + } else { + *toRef = raw; + } // TODO(nicohartmann,385155404): When passing a NaN to Wasm, every // single bit can be observable when the float64 is reinterpret casted // to an integral type. Hence, differences in NaN bit patterns are diff --git a/deps/v8/src/builtins/js-trampoline-assembler.cc b/deps/v8/src/builtins/js-trampoline-assembler.cc index 1f5c17a22c53..1b1fbc5e9ac6 100644 --- a/deps/v8/src/builtins/js-trampoline-assembler.cc +++ b/deps/v8/src/builtins/js-trampoline-assembler.cc @@ -16,7 +16,8 @@ namespace internal { #include "src/codegen/define-code-stub-assembler-macros.inc" -void JSTrampolineAssembler::TailCallJSFunction(TNode function) { +void JSTrampolineAssembler::TailCallJSFunction( + TNode function, TNode expected_parameter_count) { auto argc = UncheckedParameter(Descriptor::kActualArgumentsCount); auto context = Parameter(Descriptor::kContext); auto new_target = Parameter(Descriptor::kNewTarget); @@ -33,12 +34,22 @@ void JSTrampolineAssembler::TailCallJSFunction(TNode function) { function, offsetof(JSFunction, dispatch_handle_)))); // TailCallJSCode will load the code from the dispatch table. - TailCallJSCode(context, function, new_target, argc, dispatch_handle); + TailCallJSCode(context, function, new_target, argc, dispatch_handle, + expected_parameter_count); } - void JSTrampolineAssembler::CompileLazy(TNode function, TNode context) { +#ifdef V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE + auto dispatch_handle = + UncheckedParameter(Descriptor::kDispatchHandle); + TNode expected_parameter_count = + LoadParameterCountFromJSDispatchTable(dispatch_handle); +#else + CHECK(!V8_ENABLE_SANDBOX_BOOL); + TNode expected_parameter_count = Uint16Constant(0); +#endif + // First lookup code, maybe we don't need to compile! Label compile_function(this, Label::kDeferred); @@ -80,11 +91,11 @@ void JSTrampolineAssembler::CompileLazy(TNode function, // necessary as the dispatch table entry may still contain the CompileLazy // builtin at this point (we can only update dispatch table code from C++). CallRuntime(Runtime::kInstallSFICode, context, function); - TailCallJSFunction(function); + TailCallJSFunction(function, expected_parameter_count); BIND(&compile_function); CallRuntime(Runtime::kCompileLazy, context, function); - TailCallJSFunction(function); + TailCallJSFunction(function, expected_parameter_count); } TF_BUILTIN(CompileLazy, JSTrampolineAssembler) { @@ -105,10 +116,13 @@ void JSTrampolineAssembler::TieringBuiltinImpl(const Function& Impl) { #ifdef V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE auto dispatch_handle = UncheckedParameter(Descriptor::kDispatchHandle); + TNode expected_parameter_count = + LoadParameterCountFromJSDispatchTable(dispatch_handle); #else CHECK(!V8_ENABLE_SANDBOX_BOOL); auto dispatch_handle = LoadObjectField( function, offsetof(JSFunction, dispatch_handle_)); + TNode expected_parameter_count = Uint16Constant(0); #endif // Apply the actual tiering. This function must uninstall the tiering builtin. @@ -123,7 +137,8 @@ void JSTrampolineAssembler::TieringBuiltinImpl(const Function& Impl) { // TailCallJSCode will load the code from the dispatch table to guarantee // that the signature of the code matches with the number of arguments // passed when calling into this trampoline. - TailCallJSCode(context, function, new_target, argc, dispatch_handle); + TailCallJSCode(context, function, new_target, argc, dispatch_handle, + expected_parameter_count); } TF_BUILTIN(FunctionLogNextExecution, JSTrampolineAssembler) { diff --git a/deps/v8/src/builtins/js-trampoline-assembler.h b/deps/v8/src/builtins/js-trampoline-assembler.h index 21762a952951..f0b342bb9863 100644 --- a/deps/v8/src/builtins/js-trampoline-assembler.h +++ b/deps/v8/src/builtins/js-trampoline-assembler.h @@ -18,7 +18,8 @@ class JSTrampolineAssembler : public CodeStubAssembler { explicit JSTrampolineAssembler(compiler::CodeAssemblerState* state) : CodeStubAssembler(state) {} - void TailCallJSFunction(TNode function); + void TailCallJSFunction(TNode function, + TNode expected_parameter_count); template void TieringBuiltinImpl(const Function& Impl); diff --git a/deps/v8/src/builtins/loong64/builtins-loong64.cc b/deps/v8/src/builtins/loong64/builtins-loong64.cc index 1257a6ee3b0f..e3272c0fe56b 100644 --- a/deps/v8/src/builtins/loong64/builtins-loong64.cc +++ b/deps/v8/src/builtins/loong64/builtins-loong64.cc @@ -108,7 +108,7 @@ void Generate_JSBuiltinsConstructStubHelper(MacroAssembler* masm) { // a0: Number of arguments. Generate_PushArguments(masm, t2, a0, t3, t0, ArgumentsElementType::kRaw); // The receiver for the builtin/api call. - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Call the function. // a0: number of arguments (untagged) @@ -179,9 +179,9 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { __ CallBuiltin(Builtin::kFastNewObject); __ Branch(&post_instantiation_deopt_entry); - // Else: use TheHoleValue as receiver for constructor call + // Else: use TdzHoleValue as receiver for constructor call __ bind(¬_create_implicit_receiver); - __ LoadRoot(a0, RootIndex::kTheHoleValue); + __ LoadRoot(a0, RootIndex::kTdzHoleValue); // ----------- S t a t e ------------- // -- a0: receiver @@ -262,7 +262,7 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { // on-stack receiver as the result. __ bind(&use_receiver); __ Ld_d(a0, MemOperand(sp, 0 * kSystemPointerSize)); - __ JumpIfRoot(a0, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(a0, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Restore arguments count from the frame. @@ -1065,16 +1065,15 @@ void Builtins::Generate_BaselineOutOfLinePrologue(MacroAssembler* masm) { // Save incoming new target or generator __ Push(kJavaScriptCallNewTargetRegister); #ifdef V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE - // No need to SmiTag as dispatch handles always look like Smis. - static_assert(kJSDispatchHandleShift > 0); - __ AssertSmi(kJavaScriptCallDispatchHandleRegister); - __ Push(kJavaScriptCallDispatchHandleRegister); + __ PushDispatchHandle(kJavaScriptCallDispatchHandleRegister, feedback_cell, + feedback_vector); #endif __ SmiTag(frame_size); __ Push(frame_size); __ CallRuntime(Runtime::kStackGuardWithGap); #ifdef V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE - __ Pop(kJavaScriptCallDispatchHandleRegister); + __ PopDispatchHandle(kJavaScriptCallDispatchHandleRegister, feedback_cell, + feedback_vector); #endif __ Pop(kJavaScriptCallNewTargetRegister); } @@ -1614,7 +1613,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ EnterFrame(StackFrame::FAST_CONSTRUCT); // Implicit receiver stored in the construct frame. - __ LoadRoot(a2, RootIndex::kTheHoleValue); + __ LoadRoot(a2, RootIndex::kTdzHoleValue); __ Push(cp, a2); // Push arguments + implicit receiver. @@ -1671,7 +1670,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ bind(&use_receiver); __ Ld_d(a0, MemOperand(fp, FastConstructFrameConstants::kImplicitReceiverOffset)); - __ JumpIfRoot(a0, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(a0, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Leave construct frame. diff --git a/deps/v8/src/builtins/mips64/builtins-mips64.cc b/deps/v8/src/builtins/mips64/builtins-mips64.cc index e811c841236e..ba302ca33eec 100644 --- a/deps/v8/src/builtins/mips64/builtins-mips64.cc +++ b/deps/v8/src/builtins/mips64/builtins-mips64.cc @@ -106,7 +106,7 @@ void Generate_JSBuiltinsConstructStubHelper(MacroAssembler* masm) { // a0: Number of arguments. Generate_PushArguments(masm, t2, a0, t3, t0, ArgumentsElementType::kRaw); // The receiver for the builtin/api call. - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Call the function. // a0: number of arguments (untagged) @@ -176,9 +176,9 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { __ CallBuiltin(Builtin::kFastNewObject); __ Branch(&post_instantiation_deopt_entry); - // Else: use TheHoleValue as receiver for constructor call + // Else: use TdzHoleValue as receiver for constructor call __ bind(¬_create_implicit_receiver); - __ LoadRoot(v0, RootIndex::kTheHoleValue); + __ LoadRoot(v0, RootIndex::kTdzHoleValue); // ----------- S t a t e ------------- // -- v0: receiver @@ -258,7 +258,7 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { // on-stack receiver as the result. __ bind(&use_receiver); __ Ld(v0, MemOperand(sp, 0 * kSystemPointerSize)); - __ JumpIfRoot(v0, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(v0, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Restore arguments count from the frame. @@ -1552,7 +1552,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ EnterFrame(StackFrame::FAST_CONSTRUCT); // Implicit receiver stored in the construct frame. - __ LoadRoot(a2, RootIndex::kTheHoleValue); + __ LoadRoot(a2, RootIndex::kTdzHoleValue); __ Push(cp, a2); // Push arguments + implicit receiver. @@ -1608,7 +1608,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ bind(&use_receiver); __ Ld(v0, MemOperand(fp, FastConstructFrameConstants::kImplicitReceiverOffset)); - __ JumpIfRoot(v0, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(v0, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Leave construct frame. diff --git a/deps/v8/src/builtins/ppc/builtins-ppc.cc b/deps/v8/src/builtins/ppc/builtins-ppc.cc index 60be0d9367c6..801176b74a4e 100644 --- a/deps/v8/src/builtins/ppc/builtins-ppc.cc +++ b/deps/v8/src/builtins/ppc/builtins-ppc.cc @@ -359,7 +359,7 @@ void Generate_JSBuiltinsConstructStubHelper(MacroAssembler* masm) { Generate_PushArguments(masm, r7, r3, r8, ArgumentsElementType::kRaw); // The receiver for the builtin/api call. - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Call the function. // r3: number of arguments (untagged) @@ -527,9 +527,9 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { __ CallBuiltin(Builtin::kFastNewObject); __ b(&post_instantiation_deopt_entry); - // Else: use TheHoleValue as receiver for constructor call + // Else: use TdzHoleValue as receiver for constructor call __ bind(¬_create_implicit_receiver); - __ LoadRoot(r3, RootIndex::kTheHoleValue); + __ LoadRoot(r3, RootIndex::kTdzHoleValue); // ----------- S t a t e ------------- // -- r3: receiver @@ -607,7 +607,7 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { // on-stack receiver as the result. __ bind(&use_receiver); __ LoadU64(r3, MemOperand(sp)); - __ JumpIfRoot(r3, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(r3, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Restore arguments count from the frame. @@ -1841,7 +1841,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( FrameScope scope(masm, StackFrame::MANUAL); __ EnterFrame(StackFrame::FAST_CONSTRUCT); // Implicit receiver stored in the construct frame. - __ LoadRoot(r5, RootIndex::kTheHoleValue); + __ LoadRoot(r5, RootIndex::kTdzHoleValue); __ Push(cp, r5); // Push arguments + implicit receiver. @@ -1908,7 +1908,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ bind(&use_receiver); __ LoadU64( r3, MemOperand(fp, FastConstructFrameConstants::kImplicitReceiverOffset)); - __ JumpIfRoot(r3, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(r3, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Leave construct frame. diff --git a/deps/v8/src/builtins/riscv/builtins-riscv.cc b/deps/v8/src/builtins/riscv/builtins-riscv.cc index e35e8861d0d7..a663f76a2f2f 100644 --- a/deps/v8/src/builtins/riscv/builtins-riscv.cc +++ b/deps/v8/src/builtins/riscv/builtins-riscv.cc @@ -223,7 +223,7 @@ void Generate_JSBuiltinsConstructStubHelper(MacroAssembler* masm) { ArgumentsElementType::kRaw); } // The receiver for the builtin/api call. - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Call the function. // a0: number of arguments (untagged) @@ -292,9 +292,9 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { __ CallBuiltin(Builtin::kFastNewObject); __ BranchShort(&post_instantiation_deopt_entry); - // Else: use TheHoleValue as receiver for constructor call + // Else: use TdzHoleValue as receiver for constructor call __ bind(¬_create_implicit_receiver); - __ LoadRoot(a0, RootIndex::kTheHoleValue); + __ LoadRoot(a0, RootIndex::kTdzHoleValue); } // ----------- S t a t e ------------- // -- a0: receiver @@ -382,7 +382,7 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { // on-stack receiver as the result. __ bind(&use_receiver); __ LoadWord(a0, MemOperand(sp, 0 * kSystemPointerSize)); - __ JumpIfRoot(a0, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(a0, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Restore arguments count from the frame. @@ -517,8 +517,8 @@ void Builtins::Generate_ResumeGeneratorTrampoline(MacroAssembler* masm) { Register dispatch_handle = kJavaScriptCallDispatchHandleRegister; Register code = kJavaScriptCallCodeStartRegister; // a2 Register scratch = t2; - __ Lw(dispatch_handle, - FieldMemOperand(a5, offsetof(JSFunction, dispatch_handle_))); + __ Lwu(dispatch_handle, + FieldMemOperand(a5, offsetof(JSFunction, dispatch_handle_))); __ LoadEntrypointAndParameterCountFromJSDispatchTable( code, argc, dispatch_handle, scratch); // In case the formal parameter count is kDontAdaptArgumentsSentinel the @@ -1225,17 +1225,16 @@ void Builtins::Generate_BaselineOutOfLinePrologue(MacroAssembler* masm) { __ Push(kJavaScriptCallNewTargetRegister); #if defined(V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE) && \ defined(V8_TARGET_ARCH_RISCV64) - // No need to SmiTag as dispatch handles always look like Smis. - static_assert(kJSDispatchHandleShift > 0); - __ AssertSmi(kJavaScriptCallDispatchHandleRegister); - __ Push(kJavaScriptCallDispatchHandleRegister); + __ PushDispatchHandle(kJavaScriptCallDispatchHandleRegister, feedback_cell, + feedback_vector); #endif __ SmiTag(frame_size); __ Push(frame_size); __ CallRuntime(Runtime::kStackGuardWithGap); #if defined(V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE) && \ defined(V8_TARGET_ARCH_RISCV64) - __ Pop(kJavaScriptCallDispatchHandleRegister); + __ PopDispatchHandle(kJavaScriptCallDispatchHandleRegister, feedback_cell, + feedback_vector); #endif __ Pop(kJavaScriptCallNewTargetRegister); } @@ -1786,7 +1785,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ EnterFrame(StackFrame::FAST_CONSTRUCT); // Implicit receiver stored in the construct frame. - __ LoadRoot(a2, RootIndex::kTheHoleValue); + __ LoadRoot(a2, RootIndex::kTdzHoleValue); __ Push(cp, a2); // Push arguments + implicit receiver. @@ -1842,7 +1841,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ bind(&use_receiver); __ LoadWord( a0, MemOperand(fp, FastConstructFrameConstants::kImplicitReceiverOffset)); - __ JumpIfRoot(a0, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(a0, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Leave construct frame. diff --git a/deps/v8/src/builtins/s390/builtins-s390.cc b/deps/v8/src/builtins/s390/builtins-s390.cc index 78f88bc4726e..8d7e01cb739b 100644 --- a/deps/v8/src/builtins/s390/builtins-s390.cc +++ b/deps/v8/src/builtins/s390/builtins-s390.cc @@ -434,7 +434,7 @@ void Generate_JSBuiltinsConstructStubHelper(MacroAssembler* masm) { Generate_PushArguments(masm, r6, r2, r1, ArgumentsElementType::kRaw); // The receiver for the builtin/api call. - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Call the function. // r2: number of arguments @@ -506,9 +506,9 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { __ CallBuiltin(Builtin::kFastNewObject); __ b(&post_instantiation_deopt_entry); - // Else: use TheHoleValue as receiver for constructor call + // Else: use TdzHoleValue as receiver for constructor call __ bind(¬_create_implicit_receiver); - __ LoadRoot(r2, RootIndex::kTheHoleValue); + __ LoadRoot(r2, RootIndex::kTdzHoleValue); // ----------- S t a t e ------------- // -- r2: receiver @@ -582,7 +582,7 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { // on-stack receiver as the result. __ bind(&use_receiver); __ LoadU64(r2, MemOperand(sp)); - __ JumpIfRoot(r2, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(r2, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Restore arguments count from the frame. @@ -1887,7 +1887,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( FrameScope scope(masm, StackFrame::MANUAL); __ EnterFrame(StackFrame::FAST_CONSTRUCT); // Implicit receiver stored in the construct frame. - __ LoadRoot(r4, RootIndex::kTheHoleValue); + __ LoadRoot(r4, RootIndex::kTdzHoleValue); __ Push(cp, r4); // Push arguments + implicit receiver. @@ -1949,7 +1949,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ bind(&use_receiver); __ LoadU64( r2, MemOperand(fp, FastConstructFrameConstants::kImplicitReceiverOffset)); - __ JumpIfRoot(r2, RootIndex::kTheHoleValue, &do_throw); + __ JumpIfRoot(r2, RootIndex::kTdzHoleValue, &do_throw); __ bind(&leave_and_return); // Leave construct frame. diff --git a/deps/v8/src/builtins/wasm.tq b/deps/v8/src/builtins/wasm.tq index 9f06bebc51ad..2f85cf06de05 100644 --- a/deps/v8/src/builtins/wasm.tq +++ b/deps/v8/src/builtins/wasm.tq @@ -44,8 +44,12 @@ extern runtime WasmI32AtomicWait( Context, WasmTrustedInstanceData, Smi, Number, Number, BigInt): Smi; extern runtime WasmI64AtomicWait( Context, WasmTrustedInstanceData, Smi, Number, BigInt, BigInt): Smi; -extern runtime WasmManagedObjectWait( +extern runtime WasmManagedObjectWait32( Context, HeapObject, Smi, Number, HeapObject, BigInt): Smi; +extern runtime WasmManagedObjectWait64( + Context, HeapObject, Smi, BigInt, HeapObject, BigInt): Smi; +extern runtime WasmManagedObjectWaitRef( + Context, HeapObject, Smi, Object, HeapObject, BigInt): Smi; extern runtime WasmWaitqueueNew(Context): HeapObject; extern runtime WasmArrayCopy(Context, WasmArray, Smi, WasmArray, Smi, Smi): JSAny; @@ -96,6 +100,7 @@ extern runtime AllocateInSharedHeap(Context, Smi, Smi): HeapObject; extern runtime WasmConfigureAllPrototypesOpt( Context, Object, JSAny, WasmTrustedInstanceData): Object; extern runtime WasmTypeAssertionFailed(NoContext): never; +extern runtime TsanAcquireForInitializationFence(NoContext, Object): Undefined; } extern operator '.wasm_exported_function_data' macro @@ -704,15 +709,33 @@ builtin WasmI64AtomicWait( return Unsigned(SmiToInt32(result)); } -builtin WasmManagedObjectWait( +builtin WasmManagedObjectWait32( object: HeapObject, fieldOffset: int32, expectedValue: int32, waitqueue: HeapObject, timeout: BigInt): uint32 { - const result: Smi = runtime::WasmManagedObjectWait( + const result: Smi = runtime::WasmManagedObjectWait32( LoadContextFromFrame(), object, SmiFromInt32(fieldOffset), ChangeInt32ToTagged(expectedValue), waitqueue, timeout); return Unsigned(SmiToInt32(result)); } +builtin WasmManagedObjectWait64( + object: HeapObject, fieldOffset: int32, expectedValue: BigInt, + waitqueue: HeapObject, timeout: BigInt): uint32 { + const result: Smi = runtime::WasmManagedObjectWait64( + LoadContextFromFrame(), object, SmiFromInt32(fieldOffset), expectedValue, + waitqueue, timeout); + return Unsigned(SmiToInt32(result)); +} + +builtin WasmManagedObjectWaitRef( + object: HeapObject, fieldOffset: int32, expectedValue: Object, + waitqueue: HeapObject, timeout: BigInt): uint32 { + const result: Smi = runtime::WasmManagedObjectWaitRef( + LoadContextFromFrame(), object, SmiFromInt32(fieldOffset), expectedValue, + waitqueue, timeout); + return Unsigned(SmiToInt32(result)); +} + builtin WasmWaitqueueNew(): HeapObject { tail runtime::WasmWaitqueueNew(LoadContextFromFrame()); } @@ -1058,6 +1081,9 @@ macro StringFromTwoByteSlice(length: uint32, slice: ConstSlice): builtin WasmStringNewWtf16Array( array: WasmArray, start: uint32, end: uint32, config: Smi): String { + @if(V8_IS_TSAN) { + runtime::TsanAcquireForInitializationFence(kNoContext, array); + } try { if (array.length < end) goto OffsetOutOfRange; if (end < start) goto OffsetOutOfRange; @@ -1130,6 +1156,9 @@ builtin WasmStringFromDataSegment( // Contract: input is any string, output is a string that the TF operator // "StringPrepareForGetCodeunit" can handle. builtin WasmStringAsWtf16(str: String): String { + @if(V8_IS_TSAN) { + runtime::TsanAcquireForInitializationFence(kNoContext, str); + } const cons = Cast(str) otherwise return str; return Flatten(cons); } @@ -1181,6 +1210,7 @@ builtin WasmStringEncodeWtf16(string: String, offset: uintptr, memory: uint32): } builtin WasmStringEncodeWtf16Array( string: String, array: WasmArray, start: uint32): uint32 { + // TODO(manoskouk): Can we disable TSAN for this builtin? try { if (start > array.length) goto OffsetOutOfRange; if (array.length - start < Unsigned(string.length)) goto OffsetOutOfRange; @@ -1260,6 +1290,10 @@ builtin WasmStringAdd_NoMapCheck_Shared(a: String, b: String): String { extern builtin StringEqual(NoContext, String, String, intptr): Boolean; builtin WasmStringEqual(a: String, b: String): int32 { + @if(V8_IS_TSAN) { + runtime::TsanAcquireForInitializationFence(kNoContext, a); + runtime::TsanAcquireForInitializationFence(kNoContext, b); + } if (TaggedEqual(a, b)) return 1; if (a.length != b.length) return 0; if (StringEqual(kNoContext, a, b, a.length_intptr) == True) { @@ -1431,6 +1465,9 @@ transitioning builtin WasmStringViewWtf16Slice( } builtin WasmStringSliceShared(string: String, start: uint32, end: uint32): String { + @if(V8_IS_TSAN) { + runtime::TsanAcquireForInitializationFence(kNoContext, string); + } const length = Unsigned(string.length); if (start >= length) return kEmptyString; if (end <= start) return kEmptyString; @@ -1476,6 +1513,9 @@ macro CombineSurrogatePair(lead: char16, trail: char16): int32 { } builtin WasmStringCodePointAt(string: String, offset: uint32): uint32 { + @if(V8_IS_TSAN) { + runtime::TsanAcquireForInitializationFence(kNoContext, string); + } try { if (Unsigned(string.length) <= offset) goto OffsetOutOfRange; const lead: char16 = StringCharCodeAt(string, Convert(offset)); @@ -1654,6 +1694,10 @@ builtin WasmFastApiCallTypeCheckAndUpdateIC( } builtin WasmStringIndexOf(s: String, searchString: String, start: Smi): Smi { + @if(V8_IS_TSAN) { + runtime::TsanAcquireForInitializationFence(kNoContext, s); + runtime::TsanAcquireForInitializationFence(kNoContext, searchString); + } return AbstractStringIndexOf(s, searchString, SmiMax(start, 0)); } diff --git a/deps/v8/src/builtins/x64/builtins-x64.cc b/deps/v8/src/builtins/x64/builtins-x64.cc index c5cb7ddda099..a5a151bfac75 100644 --- a/deps/v8/src/builtins/x64/builtins-x64.cc +++ b/deps/v8/src/builtins/x64/builtins-x64.cc @@ -112,7 +112,7 @@ void Generate_JSBuiltinsConstructStubHelper(MacroAssembler* masm) { // rax: Number of arguments. Generate_PushArguments(masm, rbx, rax, rcx, ArgumentsElementType::kRaw); // The receiver for the builtin/api call. - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Call the function. // rax: number of arguments (untagged) @@ -211,9 +211,9 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { __ CallBuiltin(Builtin::kFastNewObject); __ jmp(&post_instantiation_deopt_entry, Label::kNear); - // Else: use TheHoleValue as receiver for constructor call + // Else: use TdzHoleValue as receiver for constructor call __ bind(¬_create_implicit_receiver); - __ LoadRoot(rax, RootIndex::kTheHoleValue); + __ LoadRoot(rax, RootIndex::kTdzHoleValue); // ----------- S t a t e ------------- // -- rax implicit receiver @@ -282,7 +282,7 @@ void Builtins::Generate_JSConstructStubGeneric(MacroAssembler* masm) { // on-stack receiver as the result. __ bind(&use_receiver); __ movq(rax, Operand(rsp, 0 * kSystemPointerSize)); - __ JumpIfRoot(rax, RootIndex::kTheHoleValue, &do_throw, Label::kNear); + __ JumpIfRoot(rax, RootIndex::kTdzHoleValue, &do_throw, Label::kNear); __ bind(&leave_and_return); // Restore the arguments count. @@ -1599,14 +1599,14 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ EnterFrame(StackFrame::FAST_CONSTRUCT); __ Push(rsi); // Implicit receiver stored in the construct frame. - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Push arguments + implicit receiver. Register argc_without_receiver = r11; __ leaq(argc_without_receiver, Operand(rax, -kJSArgcReceiverSlots)); GenerateInterpreterPushArgs(masm, argc_without_receiver, rcx, r12); // Implicit receiver as part of the arguments (patched later if needed). - __ PushRoot(RootIndex::kTheHoleValue); + __ PushRoot(RootIndex::kTdzHoleValue); // Check if it is a builtin call. Label builtin_call; @@ -1664,7 +1664,7 @@ void Builtins::Generate_InterpreterPushArgsThenFastConstructFunction( __ bind(&use_receiver); __ movq(rax, Operand(rbp, FastConstructFrameConstants::kImplicitReceiverOffset)); - __ JumpIfRoot(rax, RootIndex::kTheHoleValue, &do_throw, Label::kNear); + __ JumpIfRoot(rax, RootIndex::kTdzHoleValue, &do_throw, Label::kNear); __ bind(&leave_and_return); __ LeaveFrame(StackFrame::FAST_CONSTRUCT); @@ -1962,16 +1962,13 @@ void Builtins::Generate_BaselineOutOfLinePrologue(MacroAssembler* masm) { // Save incoming new target or generator __ Push(new_target); #ifdef V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE - // No need to SmiTag as dispatch handles always look like Smis. - static_assert(kJSDispatchHandleShift > 0); - __ AssertSmi(kJavaScriptCallDispatchHandleRegister); - __ Push(kJavaScriptCallDispatchHandleRegister); + __ PushDispatchHandle(kJavaScriptCallDispatchHandleRegister, rcx); #endif __ SmiTag(frame_size); __ Push(frame_size); __ CallRuntime(Runtime::kStackGuardWithGap, 1); #ifdef V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE - __ Pop(kJavaScriptCallDispatchHandleRegister); + __ PopDispatchHandle(kJavaScriptCallDispatchHandleRegister, rcx); #endif __ Pop(new_target); } diff --git a/deps/v8/src/codegen/arm/macro-assembler-arm.h b/deps/v8/src/codegen/arm/macro-assembler-arm.h index 45e46f917eed..ab3048481cf2 100644 --- a/deps/v8/src/codegen/arm/macro-assembler-arm.h +++ b/deps/v8/src/codegen/arm/macro-assembler-arm.h @@ -584,6 +584,12 @@ class V8_EXPORT_PRIVATE MacroAssembler : public MacroAssemblerBase { void LoadTaggedRoot(Register destination, RootIndex index) { LoadRoot(destination, index); } + void StoreTaggedRoot(const MemOperand& destination, RootIndex index) { + UseScratchRegisterScope temps(this); + Register scratch = temps.Acquire(); + LoadRoot(scratch, index); + StoreTaggedField(scratch, destination); + } void LoadRoot(Register destination, RootIndex index) final { LoadRoot(destination, index, al); } diff --git a/deps/v8/src/codegen/arm64/macro-assembler-arm64.cc b/deps/v8/src/codegen/arm64/macro-assembler-arm64.cc index a797c09ef530..a79bd6d3186d 100644 --- a/deps/v8/src/codegen/arm64/macro-assembler-arm64.cc +++ b/deps/v8/src/codegen/arm64/macro-assembler-arm64.cc @@ -1499,24 +1499,20 @@ void MacroAssembler::GenerateTailCallToReturnedCode( FrameScope scope(this, StackFrame::INTERNAL); // Push a copy of the target function, the new target, the actual // argument count, and the dispatch handle. - Register maybe_dispatch_handle = V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE_BOOL - ? kJavaScriptCallDispatchHandleRegister - : padreg; SmiTag(kJavaScriptCallArgCountRegister); - // No need to SmiTag the dispatch handle as it always looks like a Smi. - static_assert(kJSDispatchHandleShift > 0); - AssertSmi(maybe_dispatch_handle); - Push(kJavaScriptCallTargetRegister, kJavaScriptCallNewTargetRegister, - kJavaScriptCallArgCountRegister, maybe_dispatch_handle); + Push(kJavaScriptCallTargetRegister, kJavaScriptCallNewTargetRegister); + PushDispatchHandle(kJavaScriptCallDispatchHandleRegister, + kJavaScriptCallArgCountRegister, x5, x6); // Push another copy as a parameter to the runtime call. PushArgument(kJavaScriptCallTargetRegister); CallRuntime(function_id, 1); - // Restore target function, new target, actual argument count, and dispatch + // Restore target function, new target, actual argument count and dispatch // handle. - Pop(maybe_dispatch_handle, kJavaScriptCallArgCountRegister, - kJavaScriptCallNewTargetRegister, kJavaScriptCallTargetRegister); + PopDispatchHandle(kJavaScriptCallDispatchHandleRegister, + kJavaScriptCallArgCountRegister, x5, x6); + Pop(kJavaScriptCallNewTargetRegister, kJavaScriptCallTargetRegister); SmiUntag(kJavaScriptCallArgCountRegister); } @@ -1911,6 +1907,15 @@ void MacroAssembler::LoadTaggedRoot(Register destination, RootIndex index) { LoadRoot(destination, index); } +void MacroAssembler::StoreTaggedRoot(const MemOperand& destination, + RootIndex index) { + ASM_CODE_COMMENT(this); + UseScratchRegisterScope temps(this); + Register scratch = temps.AcquireX(); + LoadTaggedRoot(scratch, index); + StoreTaggedField(scratch, destination); +} + void MacroAssembler::LoadRoot(Register destination, RootIndex index) { ASM_CODE_COMMENT(this); if (V8_STATIC_ROOTS_BOOL && RootsTable::IsReadOnly(index) && @@ -4091,6 +4096,40 @@ void MacroAssembler::LoadEntrypointAndParameterCountFromJSDispatchTable( MemOperand(scratch, JSDispatchEntry::kCodeObjectOffset)); } +void MacroAssembler::PushDispatchHandle(Register dispatch_handle, + Register other, Register scratch1, + Register scratch2) { + Register maybe_dispatch_handle = + V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE_BOOL ? dispatch_handle : padreg; +#ifdef V8_ENABLE_SANDBOX + DCHECK(!AreAliased(dispatch_handle, other, scratch1, scratch2)); + AssertZeroExtended(dispatch_handle); + LoadParameterCountFromJSDispatchTable(scratch1, dispatch_handle, scratch2); + Bfi(dispatch_handle, scratch1, 32, 32); +#endif + Push(maybe_dispatch_handle, other); + // No need to SmiTag as dispatch handles always look like Smis. + static_assert(kJSDispatchHandleShift > 0); + AssertSmi(maybe_dispatch_handle); +} + +void MacroAssembler::PopDispatchHandle(Register dispatch_handle, Register other, + Register scratch1, Register scratch2) { + Register maybe_dispatch_handle = + V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE_BOOL ? dispatch_handle : padreg; + Pop(other, maybe_dispatch_handle); +#ifdef V8_ENABLE_SANDBOX + DCHECK(!AreAliased(dispatch_handle, other, scratch1, scratch2)); + UseScratchRegisterScope temps(this); + Lsr(scratch1, dispatch_handle, 32); + Uxtw(dispatch_handle, dispatch_handle); + LoadParameterCountFromJSDispatchTable(scratch2, dispatch_handle, + temps.AcquireX()); + Cmp(scratch1, scratch2); + SbxCheck(eq, AbortReason::kJSSignatureMismatch); +#endif +} + void MacroAssembler::LoadProtectedPointerField(Register destination, MemOperand field_operand) { DCHECK(root_array_available()); diff --git a/deps/v8/src/codegen/arm64/macro-assembler-arm64.h b/deps/v8/src/codegen/arm64/macro-assembler-arm64.h index 9467b9b2cf2f..ec3b6eb71c02 100644 --- a/deps/v8/src/codegen/arm64/macro-assembler-arm64.h +++ b/deps/v8/src/codegen/arm64/macro-assembler-arm64.h @@ -1514,6 +1514,7 @@ class V8_EXPORT_PRIVATE MacroAssembler : public MacroAssemblerBase { // Load an object from the root table. void LoadRoot(Register destination, RootIndex index) final; void LoadTaggedRoot(Register destination, RootIndex index); + void StoreTaggedRoot(const MemOperand& destination, RootIndex index); void PushRoot(RootIndex index); inline void Ret(const Register& xn = lr); @@ -1729,6 +1730,10 @@ class V8_EXPORT_PRIVATE MacroAssembler : public MacroAssemblerBase { void LoadEntrypointAndParameterCountFromJSDispatchTable( Register entrypoint, Register parameter_count, Register dispatch_handle, Register scratch); + void PushDispatchHandle(Register dispatch_handle, Register other, + Register scratch1, Register scratch2); + void PopDispatchHandle(Register dispatch_handle, Register other, + Register scratch1, Register scratch2); // Load a protected pointer field. void LoadProtectedPointerField(Register destination, diff --git a/deps/v8/src/codegen/code-stub-assembler.cc b/deps/v8/src/codegen/code-stub-assembler.cc index 19d51a7be0b0..200a57e75746 100644 --- a/deps/v8/src/codegen/code-stub-assembler.cc +++ b/deps/v8/src/codegen/code-stub-assembler.cc @@ -2217,16 +2217,7 @@ TNode CodeStubAssembler::LoadCodeObjectFromJSDispatchTable( TNode shifted_value; if (JSDispatchEntry::kObjectPointerOffset == 0) { shifted_value = -#if defined(__illumos__) && defined(V8_HOST_ARCH_64_BIT) - // Pointers in illumos span both the low 2^47 range and the high 2^47 range - // as well. Checking the high bit being set in illumos means all higher bits - // need to be set to 1 after shifting right. - // Use WordSar() so any high-bit check wouldn't be necessary. - UncheckedCast(WordSar(UncheckedCast(value), - IntPtrConstant(JSDispatchEntry::kObjectPointerShift))); -#else WordShr(value, UintPtrConstant(JSDispatchEntry::kObjectPointerShift)); -#endif /* __illumos__ and 64-bit */ } else { shifted_value = UintPtrAdd( WordShr(value, UintPtrConstant(JSDispatchEntry::kObjectPointerShift)), @@ -2249,19 +2240,24 @@ TNode CodeStubAssembler::LoadParameterCountFromJSDispatchTable( return Load(table, offset); } - void CodeStubAssembler::TailCallJSCode( TNode code, TNode context, TNode function, TNode new_target, TNode arg_count, - TNode dispatch_handle) { + TNode dispatch_handle, + TNode expected_parameter_count) { #ifdef V8_ENABLE_SANDBOX - // Check that the code has a matching parameter count. This ensures that - // the target code will correctly tear down parameters when leaving. + // Check that the code and dispatch table entry still have the expected + // parameter count. This ensures that the target code matches the native + // argument frame and will correctly tear down parameters when leaving. static_assert(V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE_BOOL); CSA_SBXCHECK( this, - Word32Equal(LoadCodeParameterCount(code), + Word32Equal(expected_parameter_count, LoadParameterCountFromJSDispatchTable(dispatch_handle))); + CSA_SBXCHECK(this, Word32Equal(LoadCodeParameterCount(code), + expected_parameter_count)); +#else + USE(expected_parameter_count); #endif // V8_ENABLE_SANDBOX CodeAssembler::TailCallJSCode(code, context, function, new_target, arg_count, @@ -2271,7 +2267,21 @@ void CodeStubAssembler::TailCallJSCode( void CodeStubAssembler::TailCallJSCode( TNode context, TNode function, TNode new_target, TNode arg_count, - TNode dispatch_handle) { + TNode dispatch_handle, + TNode expected_parameter_count) { +#ifdef V8_ENABLE_SANDBOX + // In regular execution, the dispatch entry is kept alive via the target + // JSFunction on the stack. However, with in-sandbox memory corruption, a + // dispatch handle may not be kept alive and its entry could be swept and + // reallocated with a different parameter count during a GC in the runtime. + static_assert(V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE_BOOL); + CSA_SBXCHECK( + this, + Word32Equal(expected_parameter_count, + LoadParameterCountFromJSDispatchTable(dispatch_handle))); +#else + USE(expected_parameter_count); +#endif // V8_ENABLE_SANDBOX TNode code = LoadCodeObjectFromJSDispatchTable(dispatch_handle); CodeAssembler::TailCallJSCode(code, context, function, new_target, arg_count, @@ -6692,10 +6702,14 @@ void CodeStubAssembler::CopyElements(ElementsKind kind, } } +template void CodeStubAssembler::CopyRange(TNode dst_object, int dst_offset, TNode src_object, int src_offset, TNode length_in_tagged, WriteBarrierMode mode) { + DCHECK(mode == UPDATE_WRITE_BARRIER || mode == SKIP_WRITE_BARRIER); + const WriteBarrierMode barrier_mode = + std::is_same_v ? SKIP_WRITE_BARRIER : mode; // TODO(jgruber): This could be a lot more involved (e.g. better code when // write barriers can be skipped). Extend as needed. BuildFastLoop( @@ -6703,15 +6717,11 @@ void CodeStubAssembler::CopyRange(TNode dst_object, int dst_offset, [=, this](TNode index) { TNode current_src_offset = IntPtrAdd(TimesTaggedSize(index), IntPtrConstant(src_offset)); - TNode value = LoadObjectField(src_object, current_src_offset); + TNode value = + LoadCopyRangeElement(src_object, current_src_offset); TNode current_dst_offset = IntPtrAdd(TimesTaggedSize(index), IntPtrConstant(dst_offset)); - if (mode == UNSAFE_SKIP_WRITE_BARRIER) { - UnsafeStoreNoWriteBarrier( - MachineRepresentation::kTagged, dst_object, - IntPtrSub(current_dst_offset, IntPtrConstant(kHeapObjectTag)), - value); - } else if (mode == SKIP_WRITE_BARRIER) { + if (barrier_mode == SKIP_WRITE_BARRIER) { StoreObjectFieldNoWriteBarrier(dst_object, current_dst_offset, value); } else { StoreObjectField(dst_object, current_dst_offset, value); @@ -6720,6 +6730,13 @@ void CodeStubAssembler::CopyRange(TNode dst_object, int dst_offset, 1, kLoopUnrolling, IndexAdvanceMode::kPost); } +template V8_EXPORT_PRIVATE void CodeStubAssembler::CopyRange( + TNode, int, TNode, int, TNode, + WriteBarrierMode); +template V8_EXPORT_PRIVATE void CodeStubAssembler::CopyRange( + TNode, int, TNode, int, TNode, + WriteBarrierMode); + template void CodeStubAssembler::CopyFixedArrayElements( ElementsKind from_kind, TNode from_array, @@ -20154,7 +20171,9 @@ TNode CodeStubAssembler::GetSharedFunctionInfoCode( Label check_is_baseline_data(this); Label check_is_interpreter_data(this); Label check_is_uncompiled_data(this); - Label check_is_wasm_function_data(this); +#if V8_ENABLE_WEBASSEMBLY + Label unexpected_wasm_data(this); +#endif // V8_ENABLE_WEBASSEMBLY LoadSharedFunctionInfoTrustedDataAndDispatch( shared_info, &sfi_data_out, data_type_out, &use_untrusted_data, @@ -20171,8 +20190,11 @@ TNode CodeStubAssembler::GetSharedFunctionInfoCode( {UNCOMPILED_DATA_WITH_PREPARSE_DATA_AND_JOB_TYPE, &check_is_uncompiled_data}, #if V8_ENABLE_WEBASSEMBLY - {WASM_CAPI_FUNCTION_DATA_TYPE, &check_is_wasm_function_data}, - {WASM_EXPORTED_FUNCTION_DATA_TYPE, &check_is_wasm_function_data}, + // GetSharedFunctionInfoCode is only called by CompileLazy, which Wasm + // functions never enter because their wrapper code is installed + // directly into the JSDispatchTable at creation time. + {WASM_EXPORTED_FUNCTION_DATA_TYPE, &unexpected_wasm_data}, + {WASM_CAPI_FUNCTION_DATA_TYPE, &unexpected_wasm_data}, #endif // V8_ENABLE_WEBASSEMBLY }); @@ -20210,14 +20232,6 @@ TNode CodeStubAssembler::GetSharedFunctionInfoCode( sfi_code = HeapConstantNoHole(BUILTIN_CODE(isolate(), CompileLazy)); Goto(if_compile_lazy ? if_compile_lazy : &done); -#if V8_ENABLE_WEBASSEMBLY - // IsWasmFunctionData: Use the wrapper code - BIND(&check_is_wasm_function_data); - sfi_code = LoadTrustedPointerFromObject( - CAST(sfi_data_out.value()), offsetof(WasmFunctionData, wrapper_code_)); - Goto(&done); -#endif // V8_ENABLE_WEBASSEMBLY - BIND(&use_untrusted_data); { TNode untrusted_sfi_data = @@ -20276,6 +20290,11 @@ TNode CodeStubAssembler::GetSharedFunctionInfoCode( #endif // V8_ENABLE_WEBASSEMBLY } +#if V8_ENABLE_WEBASSEMBLY + BIND(&unexpected_wasm_data); + Unreachable(); +#endif // V8_ENABLE_WEBASSEMBLY + BIND(&unknown_data); Unreachable(); @@ -21862,9 +21881,9 @@ TNode CodeStubAssembler::ArrayListEnsureSpace( GotoIf(Word32Equal(array_length, Uint32Constant(0)), &done); StoreObjectFieldNoWriteBarrier(new_array, offsetof(ArrayList, length_), array_length); - CopyRange(new_array, ArrayList::OffsetOfElementAt(0), array, - ArrayList::OffsetOfElementAt(0), - Signed(ChangeUint32ToWord(array_length))); + CopyRange(new_array, ArrayList::OffsetOfElementAt(0), array, + ArrayList::OffsetOfElementAt(0), + Signed(ChangeUint32ToWord(array_length))); Goto(&done); BIND(&overflow); @@ -21908,8 +21927,8 @@ TNode CodeStubAssembler::ArrayListElements(TNode array) { static constexpr ElementsKind kind = ElementsKind::PACKED_ELEMENTS; TNode length = Signed(ChangeUint32ToWord(ArrayListGetLength(array))); TNode elements = CAST(AllocateFixedArray(kind, length)); - CopyRange(elements, FixedArray::OffsetOfElementAt(0), array, - ArrayList::OffsetOfElementAt(0), length); + CopyRange(elements, FixedArray::OffsetOfElementAt(0), array, + ArrayList::OffsetOfElementAt(0), length); return elements; } diff --git a/deps/v8/src/codegen/code-stub-assembler.h b/deps/v8/src/codegen/code-stub-assembler.h index 968b1710583b..004d38e895c4 100644 --- a/deps/v8/src/codegen/code-stub-assembler.h +++ b/deps/v8/src/codegen/code-stub-assembler.h @@ -2504,6 +2504,13 @@ class V8_EXPORT_PRIVATE CodeStubAssembler TNode src_index, TNode length, WriteBarrierMode write_barrier = UPDATE_WRITE_BARRIER); + // Copies |length_in_tagged| tagged values from |src_object| + |src_offset| to + // |dst_object| + |dst_offset|. Offsets are measured from the start of the + // object (use offsetof). + // + // The elements type |T| may be Object or Smi (the latter ignores mode and + // always skips the barrier). + template void CopyRange(TNode dst_object, int dst_offset, TNode src_object, int src_offset, TNode length_in_tagged, @@ -4515,12 +4522,19 @@ class V8_EXPORT_PRIVATE CodeStubAssembler void TailCallJSCode(TNode code, TNode context, TNode function, TNode new_target, TNode arg_count, - TNode dispatch_handle); + TNode dispatch_handle, + TNode expected_parameter_count); // Same as above, but the code object is loaded from the dispatch table - // entry and thus the parameter count check is not necessary. + // entry. Still checks that the dispatch table entry's parameter count has + // not changed. In regular execution, the dispatch entry is kept alive via + // the target JSFunction on the stack, so it cannot be reclaimed during a + // runtime call. However, with in-sandbox memory corruption, a dispatch + // handle may not be kept alive and its entry could be swept and reallocated + // with a different parameter count during a GC. void TailCallJSCode(TNode context, TNode function, TNode new_target, TNode arg_count, - TNode dispatch_handle); + TNode dispatch_handle, + TNode expected_parameter_count); // Indicate that this code must support a dynamic parameter count. // @@ -5018,6 +5032,15 @@ class V8_EXPORT_PRIVATE CodeStubAssembler private: friend class CodeStubArguments; + // Loads one CopyRange element. + template + TNode LoadCopyRangeElement(TNode object, + TNode offset) { + TNode value = LoadReference(Reference{object, offset}); + if constexpr (std::is_same_v) CSA_DCHECK(this, TaggedIsSmi(value)); + return value; + } + void BigInt64Comparison(Operation op, TNode& left, TNode& right, Label* return_true, Label* return_false); diff --git a/deps/v8/src/codegen/compiler.cc b/deps/v8/src/codegen/compiler.cc index 7918e1548f8d..a93967addcb4 100644 --- a/deps/v8/src/codegen/compiler.cc +++ b/deps/v8/src/codegen/compiler.cc @@ -2154,7 +2154,7 @@ class ConstantPoolPointerForwarder { if (!sfi->HasOuterScopeInfo()) return; Tagged parent = - sfi->scope_info()->IsEmpty() ? Tagged() : sfi->scope_info(); + sfi->HasScopeInfo() ? sfi->scope_info() : Tagged(); Tagged outer_info = sfi->GetOuterScopeInfo(); auto it = scope_infos_to_update_.find(outer_info->UniqueIdInScript()); @@ -2379,7 +2379,7 @@ void VerifyCodeMerge(Isolate* isolate, DirectHandle