deps: backport V8 LLE alias fix to 26.x and 24.x

Offen
#66,112 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
52/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
javascript
Bereich
compilers, release

Rechercherichtung

Beginne mit deps/v8/src/compiler/turboshaft/late-load-elimination-reducer.cc und vergleiche die aktiven 26.x- und 24.x-V8-Snapshots mit dem Upstream-Commit b44239fe. Führe v8-lle-poc.js mit node --allow-natives-syntax auf beiden Release-Linien aus und überprüfe anschließend, dass der Upstream-Fix und die regress-554421904-Abdeckung vorhanden sind und der Reproducer 1.1 zurückgibt.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Summary

Please backport V8 commit b44239fe / V8 bug 554421904, "Turboshaft LLE: non-writing calls can create aliases", to the active Node.js 26.x and 24.x release lines.

This is the same upstream V8 miscompilation tracked in #66083 for 26.x, but 24.x is also affected by default: Node 24 ships V8 13.6 with Turboshaft load elimination enabled by default, and the minimized reproducer returns the wrong value there too.

Version

Reproduced locally with:

  • v26.9.0 / V8 14.6.202.34-node.32
  • v24.18.0 / V8 13.6.233.17-node.50

Source check after fetching current tags/branches:

  • upstream/v26.x and upstream/v26.x-staging: V8 14.6.202.34, no regress-554421904 test
  • upstream/v24.x and upstream/v24.x-staging: V8 13.6.233.17, no regress-554421904 test

Platform

macOS arm64

This appears to be a compiler optimization bug rather than platform-specific behavior.

Subsystem

V8 / deps

What steps will reproduce the bug?

Run the minimized reproducer from #66083 with native syntax enabled:

node --allow-natives-syntax v8-lle-poc.js

I also checked the relevant runtime flag defaults:

  • 26.x: --turboshaft-load-elimination is enabled by default
  • 24.x: --turboshaft-load-elimination is enabled by default
  • 22.x: --turboshaft-load-elimination is disabled by default, so this request is intentionally limited to 26.x and 24.x

How often does it reproduce? Is there a required condition?

It reproduced consistently for me on both default-affected lines listed above.

The reproducer requires optimized code and the Turboshaft load-elimination pass. That pass is enabled by default on the Node 26 and Node 24 builds tested.

What is the expected behavior? Why is that the expected behavior?

The store to staleArray[7] should be preserved, so the returned array slot should contain 1.1:

staleArray[7]: 1.1 | expected: 1.1 | OK
RESULT: NOT TRIGGERED on this build

What do you see instead?

Node 26:

v26.9.0 V8 14.6.202.34-node.32
staleArray[7]: undefined | expected: 1.1 | WRONG!
RESULT: BUG TRIGGERED — Turboshaft LLE eliminated a valid store

Node 24:

v24.18.0 V8 13.6.233.17-node.50
staleArray[7]: undefined | expected: 1.1 | WRONG!
RESULT: BUG TRIGGERED — Turboshaft LLE eliminated a valid store

Additional information

The upstream fix is small and directly addresses the alias invalidation ordering in Turboshaft late load elimination:

The current 26.x and 24.x V8 snapshots still have the vulnerable early !op.Effects().can_write() bailout before invalidating non-aliasing inputs in deps/v8/src/compiler/turboshaft/late-load-elimination-reducer.cc.

Vorherrschende Sprache
JavaScript
Sterne
122k
Forks
37.4k
Ø Merge
4 T. 3 Std.
Gemergte PRs (30 T.)
273

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus nodejs/node

Alle Issues in nodejs/node

Ähnliche Issues

Weitere Issues zu JavaScript

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.