> On 30 Sep 2026, at 12:51, Vadim Shakirov <vadimsakirov5@gmail.com> wrote:
>
> parser_state stores parser state in p_stack, il, and cstk, which
> share the tos index. The existing overflow check used p_stack, the
> largest array, allowing out-of-bounds accesses to cstk and il. Size
> all three arrays equally.
>
> Also widen the overflow check by one element: the lbrace case pushes
> two entries (lbrace and then stmt), so there must be room for two
> more elements when parse() is entered.
I haven't read the patch, but reproducers of bugs are good to have. Is there a
pattern which hits this out-of-bounds access?
--
Daniel Gustafsson