Repository navigation
Conversation
JavaScriptCore's parser now ends the parse at the first stack overflow. A literal nested past the parser's stack limit throws "RangeError: Maximum call stack size exceeded." Before, the parser parsed the same text again as a destructuring pattern at every nesting level on the way out and never returned. The preview build is the previous pin, ebd5a6145bf7, plus that one commit.
|
Status: draft. It waits for oven-sh/WebKit#700, which holds the fix. When that PR merges, the pin here must move from the preview tag to the merge commit's How I reproduced it: CI (build 118270): the new test passes on every lane. One job is red, debian 13 x64-asan, on |
|
Updated 4:56 AM PT - Sep 19th, 2026
❌ @robobun, your commit 8162eb8 has 1 failures in
🧪 To try this PR locally: bunx bun-pr 43436That installs a local version of the PR into your bun-43436 --bun |
Problem
(0, eval)("var x = " + "{v:".repeat(2900) + "1" + "}".repeat(2900))spins one core and grows by about 250 MB per second. Node throws aRangeErrorin 44 ms.Source/JavaScriptCore/parser/Parser.cpp:4417).Fix
RangeError: Maximum call stack size exceeded.within milliseconds at any depth.ebd5a6145bf7plus that one commit.autobuild-<sha>.test/js/bun/jsc/parser-stack-overflow.test.ts. Both tests fail on the released Bun (the timeout kills the children) and pass with the pin. Also ranbun-jsc.test.tsandvm.test.ts.Background
scripts/build/deps/webkit.tsnames. A WebKit pull request publishes a preview build asautobuild-preview-pr-<n>-<sha8>.{a: b}can be a literal or a destructuring pattern.// @bunskips Bun's transpiler. The module test uses that to reach JavaScriptCore's parser directly.Notes
The limit is about 2900 levels of
{v:on a release build of Bun.History: oven-sh/WebKit#297 and #34339 had the same one-line parser change in July. #297 went stale with unrelated CI changes that conflict, and #34339 was closed in a stale-PR cleanup. The bug still reproduces on
1.4.3-canary.1+367d939d9. oven-sh/WebKit#700 replaces #297 and adds a stress test.The test:
exitCode: 143, signalCode: "SIGTERM".eval(the AST builder) and throughnew Function(the syntax checker). The WebKit PR has a stress test with more shapes.var, becauseevalgives a program that is only a literal toLiteralParser, which never reaches this parser.vm.test.tson the debug build: one timing test (a SIGINT interrupts only the innermost of nested breakOnSigint runs) hit its 5 s default timeout on a machine with a load average near 300. Its sibling passed at 5.19 s. The other 301 tests pass.What the WebKit change does to depth limits is in the tables of oven-sh/WebKit#700: a literal overflows at the same depth as before, and two rare kinds of program that recovered from an overflow no longer do.
[policy-decision:webkit] gate passed · iteration 0 · 2 files touched
passes on PR (with fix)
diff hotspot
gate history · 1 passed · 0 rejected · iteration 0
evidence per changed file