Description[Interpreter] Fix incorrect frame walking in arguments create stubs
The previous approach taken by FastNew[Sloppy,Strict,Rest]ArgumentsStub
looked at the function slot in order to skip stub frames
and find the JS frame. However, stub frames do not have a
function slot (in fact their fixed frame ends one slot
before the JS frame's function slot). Therefore, if this
location in the stub frame happens to have the function
object the create arguments stubs won't skip this frame
correctly.
Replace this approach with one where the stub is
specialized to either skip a frame if required (since
there will only ever be one extra frame on Ignition
the loop approach isn't necessary).
BUG=v8:4928
LOG=N
CQ_INCLUDE_TRYBOTS=tryserver.v8:v8_linux_nosnap_dbg
Committed: https://crrev.com/40f345416f00761c79b9d2094c2e12e798329935
Cr-Commit-Position: refs/heads/master@{#36181}
Patch Set 1 : #Patch Set 2 : Rebased #Patch Set 3 : Rebased #Patch Set 4 : Add ports #
Depends on Patchset: Messages
Total messages: 26 (16 generated)
|