crates/perry/tests/issue_4926_boxed_slot_skipped_init.rs::boxed_var_skipped_init_is_defined_behavior fails on main: the compiled fixture binary SIGSEGVs (exit 139). It reproduces on cab6d62 and on PR #11680's head. Main's CI skips the cargo-test-perry shards, which is why main shows it as green.
Crash site. gdb stops at vmovsd (%rax) in readSkipped$spec_i32, with rax = 0x7ffc000000000001 (TAG_UNDEFINED).
What happens. A captured let x now lives in a GC scope context (js_scope_alloc). When the read runs on a path where the let never executed (case 2: typeof x), it loads straight through the slot. The slot still holds its TAG_UNDEFINED initial value, so the read dereferences that value as a pointer.
Likely origin. #11710 (e6b897e, "GC scope contexts for captured bindings"). This is matched from the code, not bisected.
crates/perry/tests/issue_4926_boxed_slot_skipped_init.rs::boxed_var_skipped_init_is_defined_behaviorfails on main: the compiled fixture binary SIGSEGVs (exit 139). It reproduces on cab6d62 and on PR #11680's head. Main's CI skips thecargo-test-perryshards, which is why main shows it as green.Crash site. gdb stops at
vmovsd (%rax)inreadSkipped$spec_i32, withrax = 0x7ffc000000000001(TAG_UNDEFINED).What happens. A captured
let xnow lives in a GC scope context (js_scope_alloc). When the read runs on a path where theletnever executed (case 2: typeof x), it loads straight through the slot. The slot still holds its TAG_UNDEFINED initial value, so the read dereferences that value as a pointer.Likely origin. #11710 (e6b897e, "GC scope contexts for captured bindings"). This is matched from the code, not bisected.