Repository navigation
FATAL ERROR v8::FromJust Maybe value is Nothing #54186
Description
Activity
- changed the title
[-]FATAL ERROR v8::FromJust Maybe value is Nothing [/-][+]FATAL ERROR `v8::FromJust Maybe value is Nothing` [/+]on Aug 3, 2024 I also tested it on Mac OS, using the same node version, and I got the same FATAL ERROR.
- addedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.v8 engineIssues and PRs related to the V8 dependency.Issues and PRs related to the V8 dependency.
on Aug 3, 2024 I'm able to reproduce on latest
mainas well as on 20.14.0./cc @nodejs/v8
Any reason to believe this is a V8 bug?
It looks like
FromJustis used somewhere in core with an emptyMaybe(which is the equivalent of ignoring errors and crashes the process).This is due to node creating holey arrays in some places. Then the setter is called when the first element is set.
In this case, it happens here:
Lines 114 to 115 in 67f7137
const winSize = new Array(2); const err = this._handle.getWindowSize(winSize); That's easy to fix with an initialization like
const winSize = [0, 0];, but then it crashes at another place, for the same reason:Lines 1306 to 1325 in 67f7137
Local<Array> methods = Array::New(env->isolate()); Local<Array> all_methods = Array::New(env->isolate()); size_t method_index = -1; size_t all_method_index = -1; #define V(num, name, string) \ methods \ ->Set(env->context(), \ ++method_index, \ FIXED_ONE_BYTE_STRING(env->isolate(), #string)) \ .Check(); HTTP_METHOD_MAP(V) #undef V #define V(num, name, string) \ all_methods \ ->Set(env->context(), \ ++all_method_index, \ FIXED_ONE_BYTE_STRING(env->isolate(), #string)) \ .Check(); HTTP_ALL_METHOD_MAP(V) #undef V I think using
CreateDataPropertyinstead ofSetwould avoid the issue but there are countless places where we can do it, as it's not specific to array indices:Object.defineProperty(Object.prototype, 'methods', { set() { throw new Error('boom') } }); const http = require('http');
We could use the alternative Array::New and Object::New variants that take arrays of keys and/or values and copies them directly to avoid it, but then this looks like another case of invalid modifications to prototypes that we don't explicitly support
We don't support them, but we usually try to avoid hard crashes in these cases.
Reacted by Ruben Bridgewater and Vinicius LourençoI have a PR to get rid of the crashes #54276 but I am hesitant to write a regression tests for these, because monkey patching prototypes are generally considered unsupported, there are also many other bindings where we don't care about this...well, it's worth the code cleanup anyway.
I don't think we should add tests.
- added a commit that references this issue
on Aug 9, 2024 - added a commit that references this issue
on Aug 11, 2024 - added 3 commits that reference this issue
on Sep 21, 2024 This no longer crashes since awhile ago (22.9.0/20.18.0 I think?), closing.
Version
v22.5.1
Platform
Subsystem
No response
What steps will reproduce the bug?
Hi,
I want to report a node bug, by running the following code snippet, node.js gives a FATAL error.
AH
How often does it reproduce? Is there a required condition?
By just running the given code, node runtime gives node crash.
What is the expected behavior? Why is that the expected behavior?
Not a crash, by looking at the stack trace, it seems it is connected to
v8::FromJust Maybe value is Nothing.What do you see instead?
Additional information
No response