The baseline JIT is currently responsible for resizing the ctiOffsets Vector for SimpleJumpTables to be equal to the size of the branchOffsets Vector. If the DFG chooses to inline a function that has never been compiled by the baseline JIT then this resizing never happens and we crash at link time in the DFG.
We can fix this by doing the resize in the DFG as well to catch this case.
Created attachment 207873 [details]
Comment on attachment 207873 [details]
Committed r153540: <http://trac.webkit.org/changeset/153540>