From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from [87.239.111.99] (localhost [127.0.0.1]) by dev.tarantool.org (Postfix) with ESMTP id 2D0DD1721A14; Wed, 25 Feb 2026 15:12:55 +0300 (MSK) DKIM-Filter: OpenDKIM Filter v2.11.0 dev.tarantool.org 2D0DD1721A14 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tarantool.org; s=dev; t=1772021575; bh=XnLW3JCzCujtUe8s8Y3rd9YkOUZW8HTY3GX6gpAbZoo=; h=To:Date:Subject:List-Id:List-Unsubscribe:List-Archive:List-Post: List-Help:List-Subscribe:From:Reply-To:Cc:From; b=QWGxKiaUSjo37aO8dzzyzEL7qWUthbvJMpoQir0KvroDXjC9CWa+OEquVckX/vSgv zSbBJyknOQ6FMTxA3FzCtUH5E9aGRkQ+CYucdFW4l5lh0hqIHg5HfqjgGrVXATfaYY wuNrPsO183U//ax21i6+XsSLlEBK+FofJ9+N9RHY= Received: from send129.i.mail.ru (send129.i.mail.ru [89.221.237.224]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by dev.tarantool.org (Postfix) with ESMTPS id 8190E1A3E243 for ; Wed, 25 Feb 2026 15:12:53 +0300 (MSK) DKIM-Filter: OpenDKIM Filter v2.11.0 dev.tarantool.org 8190E1A3E243 Received: by exim-smtp-64fd7cf497-vvfzb with esmtpa (envelope-from ) id 1vvDl6-000000001WZ-1hbI; Wed, 25 Feb 2026 15:12:52 +0300 To: Sergey Bronnikov Date: Wed, 25 Feb 2026 15:11:40 +0300 Message-ID: <20260225121140.18847-1-skaplun@tarantool.org> X-Mailer: git-send-email 2.53.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Mailru-Src: smtp X-7564579A: B8F34718100C35BD X-77F55803: 4F1203BC0FB41BD9A6EFB945BF0DEAB249BE586A260CD219BF609F5A632C54BC182A05F5380850402528EC7A5B7E61C73DE06ABAFEAF6705C42F78A2F9C2FD46E21C93DBF3BE6342BE00556ACD475582 X-7FA49CB5: FF5795518A3D127A4AD6D5ED66289B5278DA827A17800CE7A4C4638C9DDF45FCEA1F7E6F0F101C67BD4B6F7A4D31EC0BCC500DACC3FED6E28638F802B75D45FF8AA50765F7900637AC83A81C8FD4AD23D82A6BABE6F325AC2E85FA5F3EDFCBAA7353EFBB55337566145F6DE9D17D49A8CAD490CBE0003B9F14BAED11FB32BED34F44D1703F814243389733CBF5DBD5E913377AFFFEAFD269176DF2183F8FC7C07734D68A6916D8318941B15DA834481FCF19DD082D7633A0EF3E4896CB9E6436389733CBF5DBD5E9D5E8D9A59859A8B6E232F00D8D26902CA471835C12D1D977C4224003CC836476EB9C4185024447017B076A6E789B0E975F5C1EE8F4F765FCB4A02512E8976AF43AA81AA40904B5D9CF19DD082D7633A0C84D3B47A649675F3AA81AA40904B5D98AA50765F79006372E259A0B6EAE59E7D81D268191BDAD3D3666184CF4C3C14F3FC91FA280E0CE3D1A620F70A64A45A98AA50765F79006372E808ACE2090B5E1725E5C173C3A84C3C5EA940A35A165FF2DBA43225CD8A89FB26E97DCB74E62526D8C47C27EEC5E9FB5C8C57E37DE458BEDA766A37F9254B7 X-C1DE0DAB: 0D63561A33F958A5CCA2BAA418D4E49D5002B1117B3ED696CE802F484A54A8ABA13BD6A4B0E00B96823CB91A9FED034534781492E4B8EEAD13926AAAFEFA6645C79554A2A72441328621D336A7BC284946AD531847A6065A535571D14F44ED41 X-C8649E89: 1C3962B70DF3F0AD73CAD6646DEDE191716CD42B3DD1D34C77DD89D51EBB774225B6776AC983F447FC0B9F89525902EE6F57B2FD27647F25E66C117BDB76D6591D9D72EAEE41D917FD2453123F5C5676BF7BC1DD4D4CDB2E28CC437C65FD674B0A2A48C880F9BDCAB8341EE9D5BE9A0ABA294CE333222FD1ABE0FB4FD3BC5740893A84AB74155FE16536EB022892E5344C41F94D744909CECFA6C6B0C050A61A8CAF69B82BA93681CD72808BE417F3B9E0E7457915DAA85F X-D57D3AED: 3ZO7eAau8CL7WIMRKs4sN3D3tLDjz0dLbV79QFUyzQ2Ujvy7cMT6pYYqY16iZVKkSc3dCLJ7zSJH7+u4VD18S7Vl4ZUrpaVfd2+vE6kuoey4m4VkSEu53w8ahmwBjZKM/YPHZyZHvz5uv+WouB9+ObcCpyrx6l7KImUglyhkEat/+ysWwi0gdhEs0JGjl6ggRWTy1haxBpVdbIX1nthFXMZebaIdHP2ghjoIc/363UZI6Kf1ptIMVbwN8XFWZxQUnZfORMwkE5Q= X-Mailru-Sender: 520A125C2F17F0B1A9638AD358559B597143FB2CDDACF04A3DE06ABAFEAF6705C42F78A2F9C2FD46B7CBEF92542CD7C88B0A2698F12F5C9EC77752E0C033A69E86920BD37369036789A8C6A0E60D2BB63A5DB60FBEB33A8A0DA7A0AF5A3A8387 X-Mras: Ok Subject: [Tarantool-patches] [PATCH luajit] Prevent snapshot purge while recording a function header. X-BeenThere: tarantool-patches@dev.tarantool.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: Tarantool development patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Sergey Kaplun via Tarantool-patches Reply-To: Sergey Kaplun Cc: tarantool-patches@dev.tarantool.org Errors-To: tarantool-patches-bounces@dev.tarantool.org Sender: "Tarantool-patches" From: Mike Pall Thanks to Sergey Kaplun. (cherry picked from commit d459c6ce503e880dc30aefb6b61aa7f2124c7a6e) This patch is a follow-up to the commit 7505e78bd6c24cac6e93f5163675021734801b65 "Handle on-trace OOM errors from helper functions.". Since this commit, the `pcall()` (and `xpcall()`) emits an additional snapshot, but the arguments to the pcall-ed function are momentarily purged from the snapshot since they are not used. Hence, in several cases `debug.getlocal()` can't find the corresponding slot for the previous frame. This patch prevents purging right after `pcall()`, `xpcall()` recording. Sergey Kaplun: * added the description and the test for the problem Part of tarantool/tarantool#12134 --- Branch: https://github.com/tarantool/luajit/tree/skaplun/lj-1425-pcall-snap-purge Related issues: * https://github.com/LuaJIT/LuaJIT/issues/1425 * https://github.com/tarantool/tarantool/issues/12134 src/lj_record.c | 2 +- .../lj-1425-pcall-snap-purge.test.lua | 93 +++++++++++++++++++ 2 files changed, 94 insertions(+), 1 deletion(-) create mode 100644 test/tarantool-tests/lj-1425-pcall-snap-purge.test.lua diff --git a/src/lj_record.c b/src/lj_record.c index ba409a61..e2e86f79 100644 --- a/src/lj_record.c +++ b/src/lj_record.c @@ -2120,7 +2120,7 @@ void lj_record_ins(jit_State *J) /* Need snapshot before recording next bytecode (e.g. after a store). */ if (J->needsnap) { J->needsnap = 0; - if (J->pt) lj_snap_purge(J); + if (J->pt && bc_op(*J->pc) < BC_FUNCF) lj_snap_purge(J); lj_snap_add(J); J->mergesnap = 1; } diff --git a/test/tarantool-tests/lj-1425-pcall-snap-purge.test.lua b/test/tarantool-tests/lj-1425-pcall-snap-purge.test.lua new file mode 100644 index 00000000..353842f1 --- /dev/null +++ b/test/tarantool-tests/lj-1425-pcall-snap-purge.test.lua @@ -0,0 +1,93 @@ +local tap = require('tap') + +-- Test file to demonstrate incorrect snapshot purge for the +-- `pcall()` and `xpcall()`. +-- See also: https://github.com/LuaJIT/LuaJIT/issues/1425. + +local test = tap.test('lj-1425-pcall-snap-purge'):skipcond({ + ['Test requires JIT enabled'] = not jit.status(), +}) + +-- `pcall()` and `xpcall()`. +test:plan(2) + +-- XXX: simplify `jit.dump()` output. +local type = type +local pcall = pcall +local xpcall = xpcall +local math_modf = math.modf +local debug_getlocal = debug.getlocal + +local checkers = {} + +-- Called twice for the pseudo-type that aliases base Lua type via +-- checkers map. +local function checks(expected_type) + -- Value expected to be `checks_tab()` or `checks_obj()` + -- argument. It is always a table. + local _, value = debug_getlocal(2, 1) + -- Simple stitching function. Additional arguments are needed to + -- occupy the corresponding slot. + math_modf(0, nil, nil) + -- Start trace now, one iteration only. + -- luacheck: ignore 512 + while true do + -- Base type? + if type(value) == expected_type then + return true + end + -- Pseudo types fallbacks to the map. + local checker = checkers[expected_type] + -- For the xpcall. + if checker(value) == true then + return true + end + break + end + error('Unreachable path taken') +end + +-- Need to be pcalled. +local function checks_tab(_) + checks('table') +end + +local function checks_tab_p(map) + return pcall(checks_tab, map) +end + +local function nop() +end + +local function checks_tab_xp(map) + return xpcall(checks_tab, nop, map) +end + +local function checks_obj(_) + checks('obj') +end + +local function check_ff(name, checks_func) + test:test(name, function(subtest) + subtest:plan(1) + + checkers['obj'] = checks_func + + jit.flush() + jit.opt.start('hotloop=1') + + checks_obj({}) + -- Forcify stack reallocation on trace in `checks()`. The + -- source stack lacks the needed slot. + coroutine.wrap(function() + checks_obj({}) + end)() + + subtest:ok(true, 'No error for ' .. name) + end) +end + +check_ff('pcall', checks_tab_p) +check_ff('xpcall', checks_tab_xp) + +test:done(true) -- 2.53.0