SEA: BlobDeserializer SIGSEGVs when fuse byte is set but no NODE_SEA_BLOB is present
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 76/100
- Tipo de issue
- Bug
- Clareza
- Claramente especificada
- Status de atividade
- Ativa
- Domínio
- operating-systems
Direção de pesquisa
Comece em src/node_sea_bin.cc, em node::sea::FindSingleExecutableBlob(), e rastreie o resultado de postject_find_resource("NODE_SEA_BLOB", ...) antes que BlobDeserializer seja executado. Reproduza o problema com o comando fornecido para alternar o fuse e, em seguida, verifique se a ausência do blob produz um erro de inicialização claro e uma saída diferente de zero em vez de um SIGSEGV.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Version
v26.1.0 (also reproduces on v25.6.0)
Platform
Linux arm64 (reproduced on Apple Silicon via Docker Desktop, but the SEGV is platform-independent)
Subsystem
sea
What steps will reproduce the bug?
Binaries where the postject fuse byte is set to 1 but NODE_SEA_BLOB cannot be located at runtime currently die with a NULL-deref SIGSEGV inside BlobDeserializer::ReadArithmetic, with no error message indicating the cause.
Take any Node binary, flip the fuse byte from 0 to 1 without injecting an actual SEA blob:
python3 -c "
sent = b'NODE_SEA_FUSE_fce680ab2cc467b6e072b8b5df1996b2'
with open('hello','rb') as f: buf = bytearray(f.read())
i = buf.find(sent)
buf[i + len(sent) + 1] = ord('1')
with open('hello','wb') as f: f.write(bytes(buf))
"
chmod +x hello
./hello --version # → Segmentation fault, exit 139
This state arises naturally when postject is run against a host binary with no PT_NOTE program header — postject silently fails to inject the note but still flips the fuse byte. See https://github.com/nodejs/postject/issues/107 and https://github.com/nodejs/unofficial-builds/issues/200.
How often does it reproduce? Is there a required condition?
100% reproducible. Required condition: fuse byte set to 1 AND no NODE_SEA_BLOB discoverable via postject_find_resource().
What is the expected behavior? Why is that the expected behavior?
A clear error indicating that the SEA fuse is set but no blob is present, rather than a bare SIGSEGV at startup. The current behavior makes it look like a crash in OpenSSL or libc (because the SIGILLs from OpenSSL's ARM crypto-extension probes show up first under gdb), when the actual cause is much earlier and recoverable.
What do you see instead?
Program received signal SIGSEGV, Segmentation fault.
#0 memcpy ()
#1 node::BlobDeserializer<...>::ReadArithmetic<unsigned int>()
#2 node::sea::FindSingleExecutableResource()
#3 node::sea::FixupArgsForSEA(int, char**)
#4 node::Start(int, char**)
postject_find_resource("NODE_SEA_BLOB", &size, ...) returns NULL, then BlobDeserializer::ReadArithmetic calls memcpy(dst, NULL, sizeof(uint32_t)) → SIGSEGV.
Additional information
Suggested fix in node::sea::FindSingleExecutableBlob() (src/node_sea_bin.cc) — guard the deserialization on the resource lookup:
const char* blob = static_cast<const char*>(
postject_find_resource("NODE_SEA_BLOB", &size, ...));
if (blob == nullptr) {
fprintf(stderr,
"node: SEA fuse is set but no NODE_SEA_BLOB resource was found "
"in this binary. The host binary may be missing a PT_NOTE program "
"header (run `readelf -lW <binary> | grep NOTE` to check).\n");
exit(static_cast<int>(node::ExitCode::kGenericUserError));
}
Either that or CHECK_NOT_NULL(blob) — anything that surfaces a cause rather than a bare SEGV.
Related:
- https://github.com/nodejs/unofficial-builds/issues/200 — upstream cause (arm64-musl tarball with no PT_NOTE)
- https://github.com/nodejs/unofficial-builds/pull/233 — fix for that root cause
- https://github.com/nodejs/postject/issues/107 — companion postject issue (silent injection failure)
- Linguagem predominante
- JavaScript
- Estrelas
- 122k
- Forks
- 38.4k
- Merge médio
- 3d 23h
- PRs com merge (30d)
- 274
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de nodejs/node
-
build / doc: missing platform and toolchain info for `linux-x64-musl`Talvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Abertaalpine build doc
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
Mantenedores costumam responder em até 1 dia
-
[Docs] `process.loadEnvFile()` does not document behaviour when variables already existTalvez já em andamento @Sepandard assumiu há 9 dias. Abertadoc
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 90/100
Mantenedores costumam responder em até 1 dia
-
Stream.prototype.forEach will block in first promise in queue before read more chunkTalvez já em andamento @mmustafasenoglu assumiu há 9 dias. Abertadoc
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 65/100
Mantenedores costumam responder em até 1 dia
-
build
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
nodejs/node#66076 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
`TextEncoder.encodeInto()` underfills the destination for some non-ASCII textTalvez já em andamento @XadillaX assumiu há 23 dias. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
nodejs/node#65994 · 2 comentários · 2 reações ·
Mantenedores costumam responder em até 1 dia
Todas as issues de nodejs/node
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
[quality] useFocusTrap's Shift+Tab wrap and non-Tab/non-Escape key arms are never driven end to endTalvez já em andamento @hivecommons-hive assumiu hoje. Abertaagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5n31 quality testing
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
Mantenedores costumam responder em até 1 dia
-
[aw] Upgrade availableAbertaagentic-workflows
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 85/100
githubnext/gh-aw-workshop#4220 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 92/100
JuliusBrussee/caveman#1189 ·
Mantenedores costumam responder em até 1 dia
-
priority:low ready-for-dev
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
OpenHands/extensions#738 ·
Mantenedores costumam responder em até 1 dia