Problem: Converting an object with a pathologically-deep prototype chain to a primitive was segfaulting. Cause: Object::internal_get implements [[Get]] by recursing into the prototype’s [[Get]] (parent->internal_get) when the property isn’t an own property. For a sufficiently deep prototype chain, that C++ recursion exhausts the native stack, and segfaults. The bytecode interpreter’s call-stack limit doesn’t cover this native recursion. Fix: Before recursing into the prototype in Object::internal_get, check VM::did_reach_stack_space_limit(), and throw a CallStackSizeExceeded InternalError — the same way the interpreter and other recursive runtime operations guard the native stack. The deep-chain get now throws a catchable call-stack-size-exceeded error, rather than crashing. Fixes https://github.com/LadybirdBrowser/ladybird/issues/3584 |
||
|---|---|---|
| .. | ||
| AST | ||
| Bytecode | ||
| Runtime | ||
| CMakeLists.txt | ||
| test-bytecode-cache.cpp | ||
| test-js-ast.py | ||
| test-js-bytecode.py | ||
| test-js.cpp | ||
| test-primitive-string.cpp | ||
| test-value-js.cpp | ||