Repository navigation
Backport #4157 to 4.x: Fix TypedArray.prototype.with after a shrinking coercion - #4218
Merged
Merged
Conversation
…r a shrinking coercion Adapted from 431590d (engine fix and regression tests only; the test262 pin is not bumped). %TypedArray%.prototype.with bulk-copied the length read before coercing the index and the value, so a coercion that shrank a resizable buffer made Array.Copy read past the reallocated block and a CLR ArgumentException escaped into the host. It now copies only the elements the source still has and writes undefined through TypedArraySetElement for the rest (NaN, +0, or a TypeError for BigInt). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backports the engine fix from #4157 to 4.x:
%TypedArray%.prototype.withno longer lets a CLRArgumentExceptionescape when coercing the index or the value shrinks a resizable buffer.withbulk-copied the length it read before the coercions, reading past the reallocated, shorter buffer.Adapted for 4.x
Only the engine fix and its regression tests are taken. The test262 pin is not bumped. The pin on 4.x predates tc39/test262#5136, so no
*-coercion-shrinks.jsexclusion exists to remove. The tests are written for 4.x's xUnit ([Theory]/[Fact]) rather than NUnit, and the Float16 rows return early whereSystem.Halfis missing (net472). The SpecAnchors.txt entry from main is not carried over (4.x has no such guardian).The fix copies only
min(len, current length)elements, then writesundefinedthrough the typed-array element setter for the rest. That gives NaN for floats, 0 for integers, and a TypeError for BigInt arrays.Evidence (new tests, 28 cases)
Unfixed 4.x: net10.0 24 failed, 4 passed. net472 22 failed, 6 passed. With the fix: 0 failed on both.
Skipped
Nothing from the source PR. The test262 bump and the INTL402 exclusion are deliberately left out.
Totals
UnwrapIfPromiseAsync_WithIOBoundTask_DoesNotBlockCallerThread), which passes on rerun.ADeadlineSpansAHostLoopOfShortCallsAndFailsItOnceTheBudgetIsGone), which passes on rerun.🤖 Generated with Claude Code