push/unshift/splice take spread arguments; push takes more than one item - #388
Merged
Merged
Conversation
`a.push(1, 2)` failed to verify: ArrayPush checked its items with a RangedTypesMatchWith against a one-type range, which only a single item matches. It now has a verifier that checks every item against the element type. A spread argument (`a.push(...xs)`, `a.unshift(...xs)`, `a.splice(start, count, ...xs)`) has a length known only at run time, and the builtins take one operand per item. Every item argument, spread or not, now goes into one array literal (which spreads at run time), and its elements go in one at a time through the same builtin without a spread, so the casts and retains stay the builtin's. splice deletes first, then inserts at the start JavaScript normalizes to (negative from the end, clamped to the array). A spread in splice's start or delete count position is an error. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ASDAlexander77
force-pushed
the
array-builtin-spread-args
branch
from
September 28, 2026 15:06
7a1591c to
7cc9038
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two array-builtin bugs, one of which hid the other.
1.
pushwith more than one item failed to verify.ArrayPushchecked its items withRangedTypesMatchWithagainstTypeRange(elementType), a one-type range. Only a single item can match it. The trait is replaced with a verifier (TypeScriptOps.cpp) that checks every item against the element type.unshiftandsplicenever had the trait, which is whysplice(1, 1, 10, 20, 30)worked.2. Spread arguments to
push,unshiftandsplice. A builtin takes one operand per item, and a spread's length is known only at run time.a.push(...xs)handedxsitself over as one item, so it hit the verifier above.The new
mlirGenArrayInsertWithSpread(MLIRGenAccessCall.cpp) runs before operands are generated, and only when a spread argument is present:-mm=rcretains stay the builtin's.pushreusesmlirGenAppendArrayByEachElement.unshiftandspliceinsert at a position. Forsplice, the delete runs first, and the position is the start as JavaScript normalizes it: a negative start counts from the end, and the result is clamped to the array.Test:
00array_spread_args.ts, registered for compile, jit and the corpus. It covers:s32[]spread intonumber[], and strings.It fails on main, and it runs clean under
-mm=rc --verify-ownership.Results: the suite passes locally, 3017/3017.
Found along the way, not changed here (both also fail on main):
assert(cond, what + ": x"): an assert message built at run time fails with "operation's operand is unlinked", or "'ts.Retain' op using value defined outside the region". The test uses constant messages.s += v + ","loses its first append when it is called after certain array-literal spreads. AOT and-mm=rcare correct, and the Sep 11 build is too.🤖 Generated with Claude Code