Fix JIT slot overflow during up-recursion.
Reported by Sergey Kaplun. #1358
This commit is contained in:
@@ -749,7 +749,8 @@ void lj_record_ret(jit_State *J, BCReg rbase, ptrdiff_t gotresults)
|
|||||||
lj_trace_err(J, LJ_TRERR_LLEAVE);
|
lj_trace_err(J, LJ_TRERR_LLEAVE);
|
||||||
} else if (J->needsnap) { /* Tailcalled to ff with side-effects. */
|
} else if (J->needsnap) { /* Tailcalled to ff with side-effects. */
|
||||||
lj_trace_err(J, LJ_TRERR_NYIRETL); /* No way to insert snapshot here. */
|
lj_trace_err(J, LJ_TRERR_NYIRETL); /* No way to insert snapshot here. */
|
||||||
} else if (1 + pt->framesize >= LJ_MAX_JSLOTS) {
|
} else if (1 + pt->framesize >= LJ_MAX_JSLOTS ||
|
||||||
|
J->baseslot + J->maxslot >= LJ_MAX_JSLOTS) {
|
||||||
lj_trace_err(J, LJ_TRERR_STACKOV);
|
lj_trace_err(J, LJ_TRERR_STACKOV);
|
||||||
} else { /* Return to lower frame. Guard for the target we return to. */
|
} else { /* Return to lower frame. Guard for the target we return to. */
|
||||||
TRef trpt = lj_ir_kgc(J, obj2gco(pt), IRT_PROTO);
|
TRef trpt = lj_ir_kgc(J, obj2gco(pt), IRT_PROTO);
|
||||||
|
|||||||
Reference in New Issue
Block a user