Bug 245657

Summary: crash in javascriptcore
Product: WebKit Reporter: zhunkibatu
Component: JavaScriptCoreAssignee: Nobody <webkit-unassigned>
Status: RESOLVED DUPLICATE    
Severity: Normal CC: mark.lam, serakeri, webkit-bug-importer, ysuzuki
Priority: P2 Keywords: InRadar
Version: WebKit Local Build   
Hardware: Unspecified   
OS: Unspecified   
See Also: https://bugs.webkit.org/show_bug.cgi?id=225094
Attachments:
Description Flags
the minimal poc none

Description zhunkibatu 2022-09-25 23:29:35 PDT
Created attachment 462613 [details]
the minimal poc

The following poc cause latest JavaScriptCore to crash.

function main() {
    class a {
        g =  [] 
        'a'(){}
    }
}
Comment 1 Alexey Proskuryakov 2022-09-26 14:16:35 PDT
Similar stack trace to bug 225094.
Comment 2 Radar WebKit Bug Importer 2022-09-26 14:17:00 PDT
<rdar://problem/100427854>
Comment 3 serakeri 2023-01-26 14:01:06 PST
I believe this may have been fixed. I'm unable to reproduce this on Safari 16.3 or on a jsc build with the latest commits.
Comment 4 Yusuke Suzuki 2023-01-26 14:22:52 PST
Yeah, this is fixed in bug 245066. Thanks!

*** This bug has been marked as a duplicate of bug 245066 ***