Repository navigation
Spread host arrays and lists that script sees as arrays in Array.prototype.concat - #4216
Merged
Merged
Conversation
…otype.concat IsConcatSpreadable falls back to IsArray, which a host wrapper is not, so a live view over a CLR array (ArrayConversionMode.LiveView, the default in 4.14 through 4.x) or a List<T> was appended as a single element. A wrapper that exposes its target's elements by index is now spreadable. The check is reached only for a non-array, so concat of ordinary arrays is unchanged. Fixes sebastienros#4201. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
lahma
added a commit
that referenced
this pull request
Oct 5, 2026
…as arrays in Array.prototype.concat (#4219) IsConcatSpreadable falls back to IsArray, which a host wrapper is not, so a live view over a CLR array (ArrayConversionMode.LiveView, the default on 4.x) or a List<T> was appended as a single element. A wrapper that exposes its target's elements by index is now spreadable. Adapted for 4.x: the fallback there is IsArray() rather than main's IsSpecArray(), and the test lives in Jint.Tests/Runtime with xUnit [Fact]s. Fixes #4201. Adapted from 0a6288a Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #4201.
Array.prototype.concat asks IsConcatSpreadable, which falls back to IsArray when there is no Symbol.isConcatSpreadable. A host wrapper is not an array exotic object, so a wrapper over a CLR array or list was appended as one element instead of being spread.
The regression came in 4.14.0 with ed087db (#2728), which made ArrayConversionMode.LiveView the default and so turned CLR arrays passed through SetValue into wrappers (introduced by 749fc22, #2721). Before that they were copied into JsArray, which concat spreads. On main the default is Copy again (5da1196, #3056), so the issue's exact code works there; it still fails for an explicit LiveView and for List, which was never spread.
The fix lets a wrapper that is array-like and exposes its elements by index count as spreadable. Collections with a Count but no element at index 0 (Queue, HashSet) stay single elements. The extra check sits behind IsSpecArray(), so concat of ordinary JS arrays does no new work.
Tests are in Jint.Tests/Runtime/Interop/ClrCollectionConcatTests.cs; the LiveView and List cases fail without the change. SpecAnchors.txt gains the sec-isconcatspreadable anchor.
🤖 Generated with Claude Code