# CLEAN — WebKit (JavaScriptCore) Scanned 2026-03-30 for CWE-407 diamond recursion (O(2^D)). ## Scope Sparse clone: `Source/JavaScriptCore/` — bytecode/, dfg/, b3/ subdirectories (390 .cpp files). The `runtime/` directory (prototype chain traversal, JSObject hierarchy) is not present in this clone. ## Findings - `dfg/DFGValidate.cpp` — uses `seen.add(node).isNewEntry` (WebKit HashSet API; isNewEntry == true means newly inserted). Correctly guarded. CLEAN. - `dfg/DFGCombinedLiveness.cpp` — `seen.add(node).isNewEntry` guard. CLEAN. - `dfg/DFGLiveCatchVariablePreservationPhase.cpp` — `seen.add(predecessor)` with `bool isNewEntry` capture and conditional push. CLEAN. - `dfg/DFGIntegerRangeOptimizationPhase.cpp` — `m_seenBlocks.add(target)` with `if` guard. CLEAN. - No WebKit `.add()` without `.isNewEntry` check found in DFG, b3, or bytecode paths. - `runtime/` (JSObject prototype chain, JSClass hierarchy) not available in this sparse clone — cannot confirm absence of defects there. **Result: No actionable O(2^D) diamond defects in available code. Note: runtime/ not cloned; prototype chain traversal unverified.**