In Unchecked mode, when DFG::SpeculativeJIT::compileArithMod() detects that the divisor is 0, it just returns the divisor as the result. However, the result is expected to be of DataFormatIn32, but the divisor in this case is of DataFormatJSInt32. The fix is to return an immediate 0 instead. <rdar://problem/29912391>
Created attachment 306217 [details] proposed patch.
Comment on attachment 306217 [details] proposed patch. Thanks for the review. Landing now.
Comment on attachment 306217 [details] proposed patch. Clearing flags on attachment: 306217 Committed r214927: <http://trac.webkit.org/changeset/214927>
All reviewed patches have been landed. Closing bug.