#12302·swc

es/minifier: self-assignment removal ignores immutable binding writes

Author: kdy1Created Sep 9, 2026Updated Sep 9, 2026
LabelsC-bugLabor0

Describe the bug

simplify_assign_expr replaces matching identifier assignments with the identifier without checking binding writability. The ignored-value branch in pure/misc.rs has the same omission. Reading an initialized const is valid, but assigning it back to itself throws TypeError.

Input code

javascript
try{const x=1;x=x;console.log("ok")}catch(e){console.log(e.name)}

Config

Options used by the exact-source reproduction:

json
{
  "compress": {
    "defaults": false,
    "dead_code": true
  },
  "mangle": false,
  "module": false
}

Link to the code that reproduces this issue

Portable input and settings in SWC Playground

SWC Info output

Source build of swc_ecma_minifier 61.0.5, commit 246e6156ca14eaa07243ac8d9aa994c91c95cf3d, macOS arm64, Rust 1.96.0-nightly (f5eca4fcf 2026-04-09), Node v20.20.2.

The observed checkout and freshly fetched authoritative origin/main are the same commit. Fetch: git fetch --no-tags origin main, 2026-09-09T03:15:52Z, repository swc-project/swc. Reproduction was performed in a separate checkout of that fetched commit. Thus the cause remains on the default branch, not only in an older release.

For minify cases, the source harness follows the repository example: parse, resolve bindings, convert Terser compressor options, call optimize, apply fixer, emit, and execute original/output separately. Script-only behavior uses Script parsing. The playground carries portable source/settings; its published version is not evidence that the release matches the pinned source build. No implementation change was applied.

Expected behavior

Exit 0; stdout:

TypeError

Actual behavior

javascript
try{console.log("ok")}catch(e){console.log(e.name)}

Exit 0; stdout:

ok

Version

swc_ecma_minifier 61.0.5, 246e6156ca14eaa07243ac8d9aa994c91c95cf3d (also freshly fetched main).

Additional context

Responsible code: compress/pure/dead_code.rs:70.

A second responsible path is compress/pure/misc.rs:2125-2140. The primary isolated configuration disables const_to_let, excluding const lowering as the cause.

Proposed Scope

Require established writable-binding semantics before removing self-assignment in both pure simplification paths; otherwise preserve the assignment. Preserve safe var/let self-assignment elimination and unresolved-reference behavior.

Limit the change to this semantic boundary and its regression coverage. No API expansion, dependency update, migration, deployment, or feature-flag rollout is required. Preserve the documented minifier assumptions; the reproduction does not require overriding builtin implementations.

Acceptance Criteria and Test Scenarios

  • The primary input must print TypeError with const_to_let disabled by defaults:false.
  • Repeat with defaults:false,side_effects:true to cover the ignored-value path.
  • Replace const with let and var and verify successful execution remains unchanged.
  • Keep the throw observable when self-assignment is used as a value as well as an expression statement.
  • Add regression coverage in the existing SWC-owned fixture/execution suites under crates/swc_ecma_minifier/tests/fixture/issues, or the existing tests/eval.rs API harness for the Evaluator case. Check exact execution/return values and valid generated syntax, not only snapshots.
  • Initialize submodules, update fixture expectations only as needed, and rerun cargo test -p swc_ecma_minifier without UPDATE. Preserve passing controls above. Keep regression comments in English.

Duplicate search

No same-root open duplicate was found in bounded searches including "self assignment" and related minifier terms. Similar issues were evaluated by root cause and transformation boundary.

Out of Scope

Unrelated rewrites, new user options, implementing other audit findings, and changing semantic assumptions.


This is a message for readers, not the author of this issue.

Please read no +1 before leaving a comment.