-
Notifications
You must be signed in to change notification settings - Fork 5.1k
util.isError: propagate a throwing getPrototypeOf trap instead of crashing #37202
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔴 The rebase/squash dropped 7 of the 9 files this PR describes: the head commit (09f65a0) touches only
NodeUtilTypesModule.cpp+util.test.js, but the title, description, evidence block ("9 files touched", four passing console-log tests at lines 154–240), and every resolved review thread describe thebindings.cpp/ZigGlobalObject.cpp/napi.cpp/ProcessObjectInternals.ts/console-log.test.tschanges that are absent from the diff and not on main. Merging as-is closes fuzzer fingerprint79443a4a1351567bwithout fixing it (globalThis.Symbol = NaN; console.log(Bun)still aborts at bindings.cpp:5646–5649), and CI won't catch it because the console-log regression tests were dropped with the fix. Please either restore the 7 dropped files or retitle/redescribe to the util.isError-only scope.Extended reasoning...
What the finding is
The PR title is "Fix stale pending exceptions in console.log property iteration" and the description opens with "Fixes a fuzzer-found abort (fingerprint
79443a4a1351567b)", listing a 9-file diff-hotspot with 224 insertions. The evidence block shows fourconsole-log.test.tstests passing at lines 154–240 and cites a Rebase note claiming "Everything else applied cleanly and the suites above were rerun on the new base."But
git show --stat 09f65a0b(the squashed head, and the entirety of whatget_pr_diffreturns) is:The head commit's own message describes only the util.isError fix. Seven of the nine described files are absent, including the titular fix and its regression tests.
Step-by-step proof: each described change is absent from the diff and not on main
Verified against HEAD (the PR checkout) and
git log -- <file>on main:bindings.cpp— the PR's titular fix. Lines 5646–5649 still read:The not-found branch
continues past theCLEAR_IF_EXCEPTION— exactly the bug the title says is fixed. The reproducerglobalThis.Symbol = NaN; console.log(Bun);still aborts debug builds.test/js/web/console/console-log.test.ts.wc -lreports 152 lines; the file ends at the SharedArrayBuffer test. The four spawned regression tests the evidence block shows as(pass)at lines 154–240 ("console.log(Bun) survives lazy properties whose initializer throws", "stops the prototype walk when a getPrototypeOf trap throws", the two stylize tests) do not exist. The evidence block is showing pass output for tests that aren't in the tree.ZigGlobalObject.cpp. Lines 2310/2313/2337/2345/2350 stillRETURN_IF_EXCEPTION(scope, )withoutinit.set, and line 2315 stilluncheckedDowncast<JSFunction>(prop). The identity-fallback /dynamicDowncast/assertNoExceptionExceptTerminationhardening — the subject of three resolved review threads on this PR — is absent.napi.cpp. Lines 2079–2088 still readwhile (!owner->getOwnPropertyDescriptor(...)) { JSObject* proto = owner->getPrototype(globalObject).getObject(); ... } else { owner->getOwnPropertyDescriptor(...); }with noNAPI_RETURN_IF_EXCEPTIONafter eithergetOwnPropertyDescriptorcall or aftergetPrototype— the subject of two resolved review threads.ProcessObjectInternals.ts:453. Still readsBun.inspect.custominsidewindowsEnv. The Rebase note says the only conflict was here and was resolved by "appending the inspect symbol argument after"resetForDelete— but noinspectCustomparameter exists. The very conflict the note claims to have resolved lost the fix.BunObject.cpp/JSEnvironmentVariableMap.cpp.git logon both shows only unrelated commits; the described removals/additions are not present.Why this is not covered by anything else
git logon each of the 7 dropped files shows only unrelated commits (Drop the DOMWrapperWorld wrapper HashMap #39334, bake: name both flags at every insert_stale_extra call #39171).console-log.test.tsregression tests that would have caught it were dropped in the same squash.79443a4a1351567bwhile the crash remains.Impact
Merging as-is:
init.set), the napi prototype-climb null-cell dereference, and the Windows env mid-reification abort — each raised and marked resolved in review — unfixed with their threads closed.What is in the diff (the util.isError VMInquiry-scope fix +
RETURN_IF_EXCEPTIONaftergetPrototype, with a spawned regression test) is coherent and correct on its own.How to fix
Two valid paths:
Why normal, not nit
The default "PR-description mismatch is nit" rule covers stale/imprecise descriptions where the code is what was intended. Here 7 of 9 files — including the fix the PR is named after — went missing during a rebase the description explicitly claims preserved them, the evidence block shows pass output for tests that don't exist, and merging spuriously closes a tracked crash with no CI guard. That is a concrete failure the author must resolve before merge, not a wording tweak.