...
Seems like a DFG bug. Looking into it.
Found the bug. DFGSpeculativeJIT has some code like, `m_jit.codeBlock()->isStrictMode()`. This is obviously wrong since it does not consider inlined CodeBlocks.
Created attachment 367014 [details] Patch
Attachment 367014 [details] did not pass style-queue: ERROR: Source/JavaScriptCore/ChangeLog:13: Please consider whether the use of security-sensitive phrasing could help someone exploit WebKit: fuzzer [changelog/unwantedsecurityterms] [3] Total errors found: 1 in 14 files If any of these errors are false positives, please file a bug against check-webkit-style.
Comment on attachment 367014 [details] Patch r=me
Committed r244067: <https://trac.webkit.org/changeset/244067>
<rdar://problem/49722731>