Skip to content

fix(minifier): preserve catch binding with direct eval#22221

Merged
graphite-app[bot] merged 1 commit into
mainfrom
codex/minifier-catch-direct-eval
May 7, 2026
Merged

fix(minifier): preserve catch binding with direct eval#22221
graphite-app[bot] merged 1 commit into
mainfrom
codex/minifier-catch-direct-eval

Conversation

@camc314

@camc314 camc314 commented May 7, 2026

Copy link
Copy Markdown
Contributor

Given:

try {
  throw "error"
} catch (e) {
  eval('console.log(e)')
}

The expected runtime behaviour is

"error"

instead, runtime behaviour is:

Uncaught ReferenceError: e is not defined
    at eval (eval at <anonymous> (REPL5:4:3), <anonymous>:1:13)

This is because we remove the catch parameter, as we see no references to it, despite it being referenced in the eval call.

This PR adds a check to see if we are in a direct eval scope, and bails removing the catch parameter if this is the case.

Copilot AI review requested due to automatic review settings May 7, 2026 11:13
@camc314 camc314 added the A-minifier Area - Minifier label May 7, 2026
@camc314 camc314 self-assigned this May 7, 2026
@camc314 camc314 requested a review from sapphi-red May 7, 2026 11:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an unsafe minification case where the peephole optimization that removes an unused catch (e) binding could change runtime semantics when the catch scope contains a direct eval, since eval can reference the catch parameter dynamically even if static analysis reports it as unused.

Changes:

  • Prevent catch parameter removal when the catch scope is flagged as containing direct eval.
  • Add regression tests covering direct eval (including inside a nested function) vs. indirect eval via optional chaining (eval?.(...)).

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
crates/oxc_minifier/src/peephole/substitute_alternate_syntax.rs Adds a safety guard to the optional catch binding optimization to preserve semantics in the presence of direct eval.
crates/oxc_minifier/tests/peephole/substitute_alternate_syntax.rs Adds regression tests ensuring catch bindings are preserved for direct eval, while still allowing removal for indirect eval (eval?.).

@codspeed-hq

codspeed-hq Bot commented May 7, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 44 untouched benchmarks
⏩ 7 skipped benchmarks1


Comparing codex/minifier-catch-direct-eval (9ee1100) with main (0e13d17)

Open in CodSpeed

Footnotes

  1. 7 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

@camc314 camc314 added the 0-merge Merge with Graphite Merge Queue label May 7, 2026

camc314 commented May 7, 2026

Copy link
Copy Markdown
Contributor Author

Merge activity

Given:
```
try {
  throw "error"
} catch (e) {
  eval('console.log(e)')
}
```

The expected runtime behaviour is
```
"error"
```

instead, runtime behaviour is:
```
Uncaught ReferenceError: e is not defined
    at eval (eval at <anonymous> (REPL5:4:3), <anonymous>:1:13)
```

This is because we remove the catch parameter, as we see no references to it, despite it being referenced in the `eval` call.

This PR adds a check to see if we are in a direct eval scope, and bails removing the catch parameter if this is the case.
@graphite-app graphite-app Bot force-pushed the codex/minifier-catch-direct-eval branch from 9ee1100 to 73b4f40 Compare May 7, 2026 11:20
@graphite-app graphite-app Bot merged commit 73b4f40 into main May 7, 2026
28 checks passed
@graphite-app graphite-app Bot removed the 0-merge Merge with Graphite Merge Queue label May 7, 2026
@graphite-app graphite-app Bot deleted the codex/minifier-catch-direct-eval branch May 7, 2026 11:24
camc314 added a commit that referenced this pull request May 11, 2026
### 🚀 Features

- 66c9b01 transformer/typescript: Debug_assert that `enum_eval` ran in
semantic (#22252) (Dunqing)
- ffe6475 minifier: Fold `Array` constructor with safe spreads (#22215)
(camc314)

### 🐛 Bug Fixes

- d3d0b18 traverse: Handle `ChainElement::TSNonNullExpression` in
`GatherNodeParts` (#22247) (leaysgur)
- 4e880de transformer/object-rest-spread: Declare temp vars for computed
keys (#22284) (camc314)
- a7c3e22 semantic: Clear member write target for computed keys (#22302)
(camc314)
- 6a8852d codegen: Emit newline after legal-comment orphan flush
(#22304) (Dunqing)
- 5da9fda transformer/explicit-resource-management: Preserve class names
(#22306) (Dunqing)
- b5d970f transformer/explicit-resource-management: Preserve class names
(#22290) (camc314)
- bc54fd4 minifier: Keep function / class names if direct eval is
present in the scope (#22241) (sapphi-red)
- 7a810c0 minifier: Refresh direct eval flags after DCE (#21787)
(Dunqing)
- dd88726 transformer/legacy-decorator: Preserve accessor type
annotation for emitDecoratorMetadata (#21966) (Dunqing)
- 29a3cd7 codegen: Swap mapping/indent order for top-level decls
(#22206) (Dunqing)
- 73b4f40 minifier: Preserve catch binding with direct eval (#22221)
(camc314)
- 0e13d17 minifier: Preserve optional chain base side effects (#22219)
(camc314)
- 0c7c01c transformer/typescript: Inline optional-chain enum member
access (#21834) (Dunqing)
- a6aff7e codegen: Emit block/array/object end mapping at close char
(#22200) (Dunqing)
- a099b03 codegen: Emit call end mapping at `)` position, not past it
(#22199) (Dunqing)
- 5753774 minifier: Cap if-return ternary collapse for firefox (#21841)
(Gurupungav Narayanan)
- 2493bdd codegen: Correct sourcemap end mappings for closing delimiters
(#22001) (Mark Dalgleish)
- 3b385e2 minifier: Bail optimizing `Array` with unknown arg count
(#22188) (camc314)
- 9fa2122 parser: Parse array computed class keys (#22159) (camc314)

### 📚 Documentation

- a4a6892 napi/parser: Correct code comment (#22278) (overlookmotel)
- 9305373 oxc: Update README (#22178) (camc314)

Co-authored-by: Cameron <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

A-minifier Area - Minifier

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants