Repository navigation
Object.is(-Number.MIN_VALUE, -0) broken on ≥ v10.0.0 #25268
Description
Activity
@TimothyGu I guess all we need to do is identify which patch fixed this and backport it to all affected release lines?
- addedv8 engineIssues and PRs related to the V8 dependency.Issues and PRs related to the V8 dependency.
on Dec 29, 2018 @ryzokuken Yeah I think so, though I don't have the resources to do that at this moment.
Even additional confirmation that V8 7.2 fixes is would be nice as I don't trust that I tested things correctly with Chrome.Tested with latest node-v8 canary; is indeed fixed there.The latest version of V8 seems to be just better at optimizing this sequence of calls
Disassembly
0x2e68d363f80f 4f c5fb104007 vmovsd xmm0,[rax+0x7] 0x2e68d363f814 54 c4e1f97ec3 vmovq rbx,xmm0 0x2e68d363f819 59 48ba0000000000000080 REX.W movq rdx,0x8000000000000000 0x2e68d363f823 63 483bd3 REX.W cmpq rdx,rbx 0x2e68d363f826 66 0f8534000000 jnz 0x2e68d363f860 <+0xa0> 0x2e68d363f82c 6c 48bb41996d980f250000 REX.W movq rbx,0x250f986d9941 ;; object: 0x250f986d9941 <String[3]: BAD> 0x2e68d363f836 76 53 push rbx 0x2e68d363f837 77 48bb20eb220100000000 REX.W movq rbx,0x122eb20 0x2e68d363f841 81 488bd0 REX.W movq rdx,rax 0x2e68d363f844 84 48bea1169864c50a0000 REX.W movq rsi,0xac5649816a1 ;; object: 0x0ac5649816a1 <NativeContext[248]> 0x2e68d363f84e 8e b801000000 movl rax,0x1 0x2e68d363f853 93 49baa073c90100000000 REX.W movq r10,0x1c973a0 (CEntry_Return1_DontSaveFPRegs_ArgvOnStack_NoBuiltinExit) 0x2e68d363f85d 9d 41ffd2 call r10 0x2e68d363f860 a0 498b45d8 REX.W movq rax,[r13-0x28] (root (undefined_value)) 0x2e68d363f864 a4 488be5 REX.W movq rsp,rbp 0x2e68d363f867 a7 5d pop rbp 0x2e68d363f868 a8 c21000 ret 0x10Notice how the sequence of eight instructions operating on xmm's that was in the original disassembly after
vmovsdwas replaced with merely "vmovq+movq+cmpq". This makes me think that this bug was fixed as a side effect of another bigger issue, which would make backporting difficult…@TimothyGu I think I got the right commit that has to be backported. I am compiling right now to check if it indeed fixes the issue.
I'll open a backport if it's correct.
Reacted by ZYSzysReacted by Timothy Gu and antsmartianReacted by Timothy GuDone.
Reacted by Timothy Gu- added a commit that references this issue
on Dec 29, 2018 - added a commit that references this issue
on Jul 27, 2026
This seems to be fixed as of upstream V8 7.2.502.13 (in Google Chrome 72.0.3626.28 beta) but is in all Node.js releases after 10.0.0 and the current master. It is distinct from #25221.
throws "BAD" after TurboFan runs.
--print-opt-codereveals that the expressionObject.is(-Number.MIN_VALUE, -0)was constant-folded totrue, which is not good.Like before, this throws "BAD", but avoids constant folding.
--print-opt-codereveals a complex set of floating point instructions emitted by TurboFan, that eventually lead to a bad result.Disassembly
/cc @devsnek @nodejs/v8