• rmcilroy's avatar
    [Interpreter] Fix incorrect frame walking in arguments create stubs · 40f34541
    rmcilroy authored
    The previous approach taken by FastNew[Sloppy,Strict,Rest]ArgumentsStub
    looked at the function slot in order to skip stub frames
    and find the JS frame. However, stub frames do not have a
    function slot (in fact their fixed frame ends one slot
    before the JS frame's function slot). Therefore, if this
    location in the stub frame happens to have the function
    object the create arguments stubs won't skip this frame
    correctly.
    
    Replace this approach with one where the stub is
    specialized to either skip a frame if required (since
    there will only ever be one extra frame on Ignition
    the loop approach isn't necessary).
    
    BUG=v8:4928
    LOG=N
    CQ_INCLUDE_TRYBOTS=tryserver.v8:v8_linux_nosnap_dbg
    
    Review-Url: https://codereview.chromium.org/1949023003
    Cr-Commit-Position: refs/heads/master@{#36181}
    40f34541
webkit.status 4.89 KB