Worker with large inline source map aborts process in V8 HandleDebugMagicComments

Đang mở
#64,155 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
42/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
javascript
Lĩnh vực
backend

Hướng nghiên cứu

Bắt đầu với repro.js được cung cấp và stack đi qua V8's Parser::HandleDebugMagicComments, sau đó so sánh source map inline và source map bên ngoài trong giới hạn heap của worker. Truy vết điểm vào của worker thông qua node::worker::Worker::Run và xác định nơi xảy ra việc cấp phát nghiêm trọng. Được xem là hoàn tất khi repro không còn làm tiến trình Node.js bị abort và worker báo cáo lỗi một cách đúng cách.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

v8 engine
Version

v26.4.0

Platform
macOS 15.x arm64
Subsystem

worker_threads

What steps will reproduce the bug?

Create a worker entry file with a small amount of executable JavaScript and a very large inline sourceMappingURL=data:... comment, then load it in a worker with a constrained heap.

Minimal repro:

const fs = require("node:fs");
const os = require("node:os");
const path = require("node:path");
const { Worker } = require("node:worker_threads");

const dir = fs.mkdtempSync(path.join(os.tmpdir(), "node-inline-sourcemap-oom-"));

const workerPath = path.join(dir, "worker.cjs");

const source = [
  'const { parentPort } = require("node:worker_threads");',
  'parentPort.postMessage("loaded");',
  'parentPort.close();',
  "",
  "//# sourceMappingURL=data:application/json;base64,",
  "A".repeat(64 * 1024 * 1024),
  "",
].join("\n");

fs.writeFileSync(workerPath, source);

const worker = new Worker(workerPath, {
  resourceLimits: {
    maxOldGenerationSizeMb: 16,
  },
});

worker.on("message", console.log);

worker.on("error", console.error);

worker.on("exit", (code) => {
  console.log("exit", code);
  fs.rmSync(dir, { recursive: true, force: true });
});

Run: node repro.js

How often does it reproduce? Is there a required condition?

It reproduces consistently when the inline sourcemap comment is large enough relative to the worker heap limit.

For comparison, these do not reproduce the same fatal abort:

  1. Keeping the same large payload in an external worker.cjs.map file and using //# sourceMappingURL=worker.cjs.map.
  2. Putting a similarly large payload in a normal non-sourceMappingURL comment.
What is the expected behavior? Why is that the expected behavior?

The worker should fail gracefully, for example by emitting an error event or exiting with a worker failure, without aborting the entire Node.js process.

Ideally, parsing sourceMappingURL / debug magic comments should not internalize an arbitrarily large data URL into V8 old space during module compilation.

What do you see instead?

The whole Node process aborts with an out-of-memory fatal error before the worker can load the module.

Example stack from Node v26.4.0:

FATAL ERROR: CALL_AND_RETRY_LAST Allocation failed - JavaScript heap out of memory
...
v8::internal::FactoryBase<v8::internal::Factory>::AllocateRawOneByteInternalizedString
v8::internal::FactoryBase<v8::internal::Factory>::NewOneByteInternalizedString
v8::internal::StringTable::LookupKey
v8::internal::FactoryBase<v8::internal::Factory>::InternalizeString
void v8::internal::Parser::HandleDebugMagicComments
v8::internal::Parser::ParseProgram
v8::internal::parsing::ParseProgram
v8::internal::Compiler::GetWrappedFunction
v8::ScriptCompiler::CompileFunction
node::contextify::CompileFunctionForCJSLoader
node::worker::Worker::Run
Additional information

No response

Ngôn ngữ chính
JavaScript
Star
122k
Fork
37.4k
Merge trung bình
4 ngày 3 giờ
Pull request đã merge (30 ngày)
273

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của nodejs/node

Tất cả issue của nodejs/node

Issue tương tự

Thêm issue về JavaScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.