VerifyScript runs a P2SH scriptPubKey on the stack the scriptSig leaves before handling the redeemScript. The 20-byte push in HASH160 <20> EQUAL adds one item, so a scriptSig that leaves 1,000 items fails with STACK_SIZE, while 999 items is valid.
An implementation that checks the redeemScript hash without running the scriptPubKey accepts the 1,000-item spend. No existing vector leaves the scriptSig at this boundary, so such an implementation can pass every row.
Add 999 and 1,000 item cases with P2SH and WITNESS, and the 1,000 item case with no flags, which fails the same way because the scriptPubKey always runs.
Also add the case as a feature_taproot spender, so its dump can be added to the script assets (bitcoin-core/qa-assets#297).
These were discovered by finding gaps in an alternate implementation (rbitcoin)