Skip to content

Backport #4157 to 4.x: Fix TypedArray.prototype.with after a shrinking coercion - #4218

Merged
lahma merged 1 commit into
sebastienros:4.xfrom
lahma:backport/4x-typedarray
Oct 5, 2026
Merged

lahma merged 1 commit into
sebastienros:4.xfrom
lahma:backport/4x-typedarray

Conversation

@lahma

@lahma lahma commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Backports the engine fix from #4157 to 4.x: %TypedArray%.prototype.with no longer lets a CLR ArgumentException escape when coercing the index or the value shrinks a resizable buffer.

Commit Main PR What it fixes
22b1587 #4157 (431590d) with bulk-copied the length it read before the coercions, reading past the reallocated, shorter buffer.

Adapted for 4.x

Only the engine fix and its regression tests are taken. The test262 pin is not bumped. The pin on 4.x predates tc39/test262#5136, so no *-coercion-shrinks.js exclusion exists to remove. The tests are written for 4.x's xUnit ([Theory]/[Fact]) rather than NUnit, and the Float16 rows return early where System.Half is missing (net472). The SpecAnchors.txt entry from main is not carried over (4.x has no such guardian).

The fix copies only min(len, current length) elements, then writes undefined through the typed-array element setter for the rest. That gives NaN for floats, 0 for integers, and a TypeError for BigInt arrays.

Evidence (new tests, 28 cases)

Unfixed 4.x: net10.0 24 failed, 4 passed. net472 22 failed, 6 passed. With the fix: 0 failed on both.

Skipped

Nothing from the source PR. The test262 bump and the INTL402 exclusion are deliberately left out.

Totals

  • Jint.Tests net10.0: 7683 passed, 4 skipped.
  • Jint.Tests net472: 7597 passed, 4 skipped, 1 timing flake (UnwrapIfPromiseAsync_WithIOBoundTask_DoesNotBlockCallerThread), which passes on rerun.
  • PublicInterface net10.0: 1903 passed, 9 skipped.
  • PublicInterface net472: 1894 passed, 9 skipped, 1 timing flake (ADeadlineSpansAHostLoopOfShortCallsAndFailsItOnceTheBudgetIsGone), which passes on rerun.
  • Test262 filtered to TypedArray on net10.0: 4519 passed.
  • Public API snapshots are untouched.

🤖 Generated with Claude Code

…r a shrinking coercion

Adapted from 431590d (engine fix and regression
tests only; the test262 pin is not bumped).

%TypedArray%.prototype.with bulk-copied the length read before coercing the index
and the value, so a coercion that shrank a resizable buffer made Array.Copy read
past the reallocated block and a CLR ArgumentException escaped into the host. It
now copies only the elements the source still has and writes undefined through
TypedArraySetElement for the rest (NaN, +0, or a TypeError for BigInt).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant