In particular, if the JS function contains the op_call_varargs bytecode, it cannot be directly compiled but can be inlined (in certain cases) with DFG. In this case if we don't record the JITCodeMap for this function, we will have problems if OSR exit happens inside this function. This problem is exposed in a build with LLInt disabled but DFG JIT enabled, when browsing and clicking around www.android.com. Patch forthcoming.
Created attachment 190439 [details] patch
Ah... Just noticed Filip's commit of http://trac.webkit.org/changeset/144137. It should have been fixed! So this should be invalid.
*** This bug has been marked as a duplicate of bug 109036 ***