[Test262] fix delete super[...] with uninitialized this

56 views
Skip to first unread message

Temiloluwa

unread,
Sep 14, 2026, 2:55:11 PMSep 14
to v8-dev

Hi Marja, I investigated another skipped Test262 test:


language/expressions/delete/super-property-uninitialized-this


Test262 source: https://github.com/tc39/test262/blob/419d3e0a2273ba01a3bfcbec423f2801425b8e93/test/language/expressions/delete/super-property-uninitialized-this.js


The test evaluates the following expression inside a derived constructor before this has been initialized: 


delete super[(super(), 0)];


It expects a ReferenceError before the computed property expression is evaluated. When I force the skipped test to run in V8, both Test262 variants fail because the inner super() is evaluated first and calls the base constructor, which throws Test262Error.


This appears inconsistent with the current ECMA-262 evaluation order:


In src/interpreter/bytecode-generator.cc, the super-property branch of BytecodeGenerator::VisitDelete() currently evaluates the key before throwing:


if (property->IsSuperAccess()) {

  VisitForEffect(property->key());

  builder()->CallRuntime(Runtime::kThrowUnsupportedSuperError);

}


From my current investigation calling BuildThisVariableLoad() before evaluating the key would generate the missing check for uninitialized this, causing a ReferenceError before the computed property expression runs.


My proposed changes are:

  • adding the missing this check in BytecodeGenerator::VisitDelete();
  • adding an mjsunit regression test covering both initialized and uninitialized this;
  • removing the corresponding Test262 SKIP entry


Would a fix along these lines be welcome? 

Marja Hölttä

unread,
Sep 16, 2026, 5:32:16 AMSep 16
to v8-...@googlegroups.com
I didn't look into it deeper yet, but feel free to send the fix for code review. Thanks!

--
--
v8-dev mailing list
v8-...@googlegroups.com
http://groups.google.com/group/v8-dev
---
You received this message because you are subscribed to the Google Groups "v8-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to v8-dev+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/v8-dev/fc48241b-af98-485d-8be8-d0e51af83758n%40googlegroups.com.


--


Google Germany GmbH

Erika-Mann-Straße 33

80636 München


Geschäftsführer: Paul Manicle, Liana Sebastian.

Registergericht und -nummer: Hamburg, HRB 86891

Sitz der Gesellschaft: Hamburg


Diese E-Mail ist vertraulich. Falls sie diese fälschlicherweise erhalten haben sollten, leiten Sie diese bitte nicht an jemand anderes weiter, löschen Sie alle Kopien und Anhänge davon und lassen Sie mich bitte wissen, dass die E-Mail an die falsche Person gesendet wurde.

    

This e-mail is confidential. If you received this communication by mistake, please don't forward it to anyone else, please erase all copies and attachments, and please let me know that it has gone to the wrong person.

Temiloluwa

unread,
Sep 20, 2026, 12:42:36 AMSep 20
to v8-dev
I have submitted the fix. you can take a look at it here. https://chromium-review.googlesource.com/c/v8/v8/+/8419154
Reply all
Reply to author
Forward
0 new messages