added. Also, TDUP IR is affected, too.
See also the issue mentioned in the test.
Sergey Kaplun:
* added the description and the test for the problem
Part of tarantool/tarantool#8516
---
Branch:
https://github.com/tarantool/luajit/tree/skaplun/lj-994-instable-types-during-loop-unrollPR:
https://github.com/tarantool/tarantool/pull/8642Related issues:
*
https://github.com/tarantool/tarantool/issues/8516*
https://github.com/LuaJIT/LuaJIT/issues/994I don't mention the 994 intentionally to avoid Mike bothering. Also, it
isn't the origin of this commit. Quite the opposite: as a result of this
backporting the following issue was created.
I prefer to backport the patches (this one and the prospective for 994)
separately. So, after this patch is backported, it doesn't add any
critical bugs (always failing guard just creates a new side trace), but
helps to avoid conflicts for future backporting (sadly remembered
"Improve assertions.").
src/lj_opt_mem.c | 3 +-
...instable-types-during-loop-unroll.test.lua | 53 +++++++++++++++++++
2 files changed, 55 insertions(+), 1 deletion(-)
create mode 100644 test/tarantool-tests/lj-994-instable-types-during-loop-unroll.test.lua
diff --git a/src/lj_opt_mem.c b/src/lj_opt_mem.c
index cc177d39..c8265b4f 100644
--- a/src/lj_opt_mem.c
+++ b/src/lj_opt_mem.c
@@ -180,7 +180,8 @@ static TRef fwd_ahload(jit_State *J, IRRef xref)
}
ref = store->prev;
}
- lua_assert(ir->o != IR_TNEW || irt_isnil(fins->t));
+ if (ir->o == IR_TNEW && !irt_isnil(fins->t))
+ return 0; /* Type instability in loop-carried dependency. */
if (irt_ispri(fins->t)) {
return TREF_PRI(irt_type(fins->t));
} else if (irt_isnum(fins->t) || (LJ_DUALNUM && irt_isint(fins->t)) ||
diff --git a/test/tarantool-tests/lj-994-instable-types-during-loop-unroll.test.lua b/test/tarantool-tests/lj-994-instable-types-during-loop-unroll.test.lua
new file mode 100644
index 00000000..435f6e0e
--- /dev/null
+++ b/test/tarantool-tests/lj-994-instable-types-during-loop-unroll.test.lua
@@ -0,0 +1,53 @@
+local tap = require('tap')
+
+local test = tap.test('lj-994-instable-types-during-loop-unroll'):skipcond({
+ ['Test requires JIT enabled'] = not jit.status(),
+})
+
+-- Test file to demonstrate LuaJIT misbehaviour during loop
+-- unrolling and load forwarding for newly created tables.
+-- See also
https://github.com/LuaJIT/LuaJIT/issues/994.
+
+-- TODO: test that compiled traces don't always exit by the type
+-- guard. See also the comment for the TDUP test chunk.
+test:plan(1)
+
+-- TNEW.
+local result
+local stored_tab = {1}
+local slot = {}
+local key = 1
+
+jit.opt.start('hotloop=1')
+-- The trouble happens during loop unrolling when we copy
+-- `>+ num ALOAD` IR in the context of the table on the previous
+-- iteration instead of a new one created via TNEW containing no
+-- values (so type nil should be used instead of num).
+for _ = 1, 5 do
+ local t = slot
+ -- Use non-constant key to avoid LJ_TRERR_GFAIL and undoing the
+ -- loop.