Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 24e354459de9729d72651373055d02e08b5898f5
      
https://github.com/WebKit/WebKit/commit/24e354459de9729d72651373055d02e08b5898f5
  Author: Sosuke Suzuki <[email protected]>
  Date:   2026-09-30 (Wed, 30 Sep 2026)

  Changed paths:
    A JSTests/stress/tagged-template-super-property-this.js
    M Source/JavaScriptCore/bytecompiler/NodesCodegen.cpp

  Log Message:
  -----------
  [JSC] Tagged template with a super property tag should be called with the 
current `this`
https://bugs.webkit.org/show_bug.cgi?id=325756

Reviewed by Yusuke Suzuki.

When the tag of a tagged template is a super property, JSC called the tag
function with HomeObject.[[Prototype]] as `this`. Per spec, the this value of
a super reference is the current `this` binding [1].

    class A { tag() { return this; } }
    class B extends A { test() { return super.tag`x`; } }
    let b = new B;
    b.test() === b;           // should be true, was false
    b.test() === A.prototype; // should be false, was true

TaggedTemplateNode::emitBytecode passed the register used as the base of the
property lookup as `this` of the call. This patch passes the current `this`
instead, as FunctionCallDotNode and FunctionCallBracketNode already do.

[1]: https://tc39.es/ecma262/#sec-getthisvalue

Test: JSTests/stress/tagged-template-super-property-this.js

* JSTests/stress/tagged-template-super-property-this.js: Added.
(shouldBe):
(shouldThrow):
(A.prototype.tag):
(A.tag):
(A.prototype.get getter):
(A.prototype.mark):
(A):
(B.prototype.dot):
(B.prototype.bracket):
(B.prototype.computed):
(B.prototype.parenthesized):
(B.prototype.withExpressions):
(B.prototype.arrow):
(B.prototype.viaEval):
(B.prototype.getterDot):
(B.prototype.getterBracket):
(B.prototype.notTail):
(B.prototype.markSelf):
(B.dot):
(B.bracket):
(B):
(C):
(let.proto.tag):
(let.object.dot):
(let.object.bracket):
(test):
* Source/JavaScriptCore/bytecompiler/NodesCodegen.cpp:
(JSC::TaggedTemplateNode::emitBytecode):

Canonical link: https://commits.webkit.org/322253@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to