|email@example.com <firstname.lastname@example.org@268f45cc-cd09-0410-ab3c-d52691b4dbfc>||Sat Nov 09 01:37:55 2019 +0000|
|email@example.com <firstname.lastname@example.org@268f45cc-cd09-0410-ab3c-d52691b4dbfc>||Sat Nov 09 01:37:55 2019 +0000|
[JSC] Make IsoSubspace scalable https://bugs.webkit.org/show_bug.cgi?id=201908 Reviewed by Keith Miller. This patch introduces lower-tier into IsoSubspace so that we can avoid allocating MarkedBlock if a certain type of object is not allocated so many. This optimization allows us apply IsoSubspace more aggressively to various types of objects without introducing memory regression even if such a type of object is allocated so frequently. We use LargeAllocation for these lower-tier objects. Each IsoSubspace holds up to 8 lower-tier objects allocated via LargeAllocation. We use this special LargeAllocation when we tend to allocate small # of cells for this type. Specifically, what we are doing right now is, (1) first, try to allocate in an existing MarkedBlock (there won't be one to start), and (2) then, try to allocate in LargeAllocation, and if we cannot allocate lower-tier objects, (3) finally we allocate a new MarkedBlock. Once this LargeAllocation is allocated to a certain type, we do not deallocate it until VM is destroyed, so that we can keep IsoSubspace's characteristics: once an address is assigned to a certain type, we continue using this address only for this type. To introduce this optimization, we need to remove an restriction that no callee cells can be a LargeAllocation. This also turns out that SamplingProfiler's isValueGCObject is heavily relies on that all the callee is small-sized. isValueGCObject relies on the thing that MarkedSpace::m_largeAllocations is sorted. But this is not true since this vector is sorted only when conservative scan happens. And further, this vector is only partially sorted: we sort only an eden part part of this vector. So we cannot use this vector to implement isValueGCObject in the sampling profiler. Instead we register HeapCell address into a hash-set in MarkedSpace. Since we do not need to find a pointer that is pointing at the middle of the JSCell in sampling profiler, just registering cell address is enough. And we maintain this hash-set only when sampling profiler is enabled to save memory in major cases. We also fix the code that is relying on that JSString is always allocated in MarkedBlock. And we also fix PackedCellPtr's assumption that CodeBlock is always allocated in MarkedBlock. We also make sizeof(LargeAllocation) small since it is now used for non-large allocations. JetStream2 and Speedometer2 are neutral. RAMification shows 0.6% progression on iOS devices. * heap/BlockDirectory.cpp: (JSC::BlockDirectory::BlockDirectory): * heap/BlockDirectory.h: * heap/BlockDirectoryInlines.h: (JSC::BlockDirectory::tryAllocateFromLowerTier): * heap/CompleteSubspace.cpp: (JSC::CompleteSubspace::allocatorForSlow): (JSC::CompleteSubspace::tryAllocateSlow): (JSC::CompleteSubspace::reallocateLargeAllocationNonVirtual): * heap/Heap.cpp: (JSC::Heap::dumpHeapStatisticsAtVMDestruction): (JSC::Heap::addCoreConstraints): * heap/HeapUtil.h: (JSC::HeapUtil::isPointerGCObjectJSCell): (JSC::HeapUtil::isValueGCObject): * heap/IsoAlignedMemoryAllocator.cpp: (JSC::IsoAlignedMemoryAllocator::tryAllocateMemory): (JSC::IsoAlignedMemoryAllocator::freeMemory): (JSC::IsoAlignedMemoryAllocator::tryReallocateMemory): * heap/IsoCellSet.cpp: (JSC::IsoCellSet::~IsoCellSet): * heap/IsoCellSet.h: * heap/IsoCellSetInlines.h: (JSC::IsoCellSet::add): (JSC::IsoCellSet::remove): (JSC::IsoCellSet::contains const): (JSC::IsoCellSet::forEachMarkedCell): (JSC::IsoCellSet::forEachMarkedCellInParallel): (JSC::IsoCellSet::forEachLiveCell): (JSC::IsoCellSet::sweepLowerTierCell): * heap/IsoSubspace.cpp: (JSC::IsoSubspace::IsoSubspace): (JSC::IsoSubspace::tryAllocateFromLowerTier): (JSC::IsoSubspace::sweepLowerTierCell): * heap/IsoSubspace.h: * heap/LargeAllocation.cpp: (JSC::LargeAllocation::tryReallocate): (JSC::LargeAllocation::createForLowerTier): (JSC::LargeAllocation::reuseForLowerTier): (JSC::LargeAllocation::LargeAllocation): * heap/LargeAllocation.h: (JSC::LargeAllocation::lowerTierIndex const): (JSC::LargeAllocation::isLowerTier const): * heap/LocalAllocator.cpp: (JSC::LocalAllocator::allocateSlowCase): * heap/MarkedBlock.cpp: (JSC::MarkedBlock::Handle::Handle): (JSC::MarkedBlock::Handle::stopAllocating): * heap/MarkedBlock.h: (JSC::MarkedBlock::Handle::forEachCell): * heap/MarkedSpace.cpp: (JSC::MarkedSpace::freeMemory): (JSC::MarkedSpace::lastChanceToFinalize): (JSC::MarkedSpace::sweepLargeAllocations): (JSC::MarkedSpace::enableLargeAllocationTracking): * heap/MarkedSpace.h: (JSC::MarkedSpace:: const): * heap/PackedCellPtr.h: (JSC::PackedCellPtr::PackedCellPtr): * heap/Subspace.h: * heap/WeakSet.cpp: (JSC::WeakSet::~WeakSet): (JSC::WeakSet::findAllocator): (JSC::WeakSet::addAllocator): * heap/WeakSet.h: (JSC::WeakSet::WeakSet): (JSC::WeakSet::resetAllocator): (JSC::WeakSet::container const): Deleted. (JSC::WeakSet::setContainer): Deleted. * heap/WeakSetInlines.h: (JSC::WeakSet::allocate): * runtime/InternalFunction.cpp: (JSC::InternalFunction::InternalFunction): * runtime/JSCallee.cpp: (JSC::JSCallee::JSCallee): * runtime/JSString.h: * runtime/SamplingProfiler.cpp: (JSC::SamplingProfiler::SamplingProfiler): (JSC::SamplingProfiler::processUnverifiedStackTraces): (JSC::SamplingProfiler::releaseStackTraces): (JSC::SamplingProfiler::stackTracesAsJSON): (JSC::SamplingProfiler::reportTopFunctions): (JSC::SamplingProfiler::reportTopBytecodes): * runtime/SamplingProfiler.h: git-svn-id: http://svn.webkit.org/repository/webkit/trunk@252298 268f45cc-cd09-0410-ab3c-d52691b4dbfc
WebKit is a cross-platform web browser engine. On iOS and macOS, it powers Safari, Mail, iBooks, and many other applications.
Visit WebKit Feature Status page to see which Web API has been implemented, in development, or under consideration.
Once your bug is filed, you will receive email when it is updated at each stage in the bug life cycle. After the bug is considered fixed, you may be asked to download the latest nightly and confirm that the fix works for you.
On Windows, follow the instructions on our website.
Run the following command to clone WebKit's Git SVN repository:
git clone git://git.webkit.org/WebKit.git WebKit
git clone https://git.webkit.org/git/WebKit.git WebKit
If you want to be able to commit changes to the repository, or just want to check out branches that aren’t contained in WebKit.git, you will need track WebKit's Subversion repository. You can run the following command to configure this and other options of the new Git clone for WebKit development.
For information about this, and other aspects of using Git with WebKit, read the wiki page.
If you don‘t want to use Git, run the following command to check out WebKit’s Subversion repository:
svn checkout https://svn.webkit.org/repository/webkit/trunk WebKit
Install Xcode and its command line tools if you haven't done so already:
Run the following command to build a debug build with debugging symbols and assertions:
For performance testing, and other purposes, use
You can open
WebKit.xcworkspace to build and debug WebKit within Xcode.
If you don't use a custom build location in Xcode preferences, you have to update the workspace settings to use
WebKitBuild directory. In menu bar, choose File > Workspace Settings, then click the Advanced button, select “Custom”, “Relative to Workspace”, and enter
WebKitBuild for both Products and Intermediates.
The first time after you install a new Xcode, you will need to run the following command to enable Xcode to build command line tools for iOS Simulator:
Without this step, you will see the error message: “
target specifies product type ‘com.apple.product-type.tool’, but there’s no such product type for the ‘iphonesimulator’ platform.” when building target
JSCLLIntOffsetsExtractor of project
Run the following command to build a debug build with debugging symbols and assertions for iOS:
Tools/Scripts/build-webkit --debug --ios-simulator
For production builds:
cmake -DPORT=GTK -DCMAKE_BUILD_TYPE=RelWithDebInfo -GNinja ninja sudo ninja install
For development builds:
Tools/gtk/install-dependencies Tools/Scripts/update-webkitgtk-libs Tools/Scripts/build-webkit --gtk --debug
For more information on building WebKitGTK+, see the wiki page.
For production builds:
cmake -DPORT=WPE -DCMAKE_BUILD_TYPE=RelWithDebInfo -GNinja ninja sudo ninja install
For development builds:
Tools/wpe/install-dependencies Tools/Scripts/update-webkitwpe-libs Tools/Scripts/build-webkit --wpe --debug
For building WebKit on Windows, see the wiki page.
Run the following command to launch Safari with your local build of WebKit:
run-safari script sets the
DYLD_FRAMEWORK_PATH environment variable to point to your build products, and then launches
DYLD_FRAMEWORK_PATH tells the system loader to prefer your build products over the frameworks installed in
To run other applications with your local build of WebKit, run the following command:
Run the following command to launch iOS simulator with your local build of WebKit:
run-safari --debug --ios-simulator
In both cases, if you have built release builds instead, use
--release instead of
If you have a development build, you can use the run-minibrowser script, e.g.:
run-minibrowser --debug --wpe
Pass one of
--wpe to indicate the port to use.
Congratulations! You’re up and running. Now you can begin coding in WebKit and contribute your fixes and new features to the project. For details on submitting your code to the project, read Contributing Code.