WasmGC cumulative array allocations crash Node.js process with FATAL ERROR instead of trapping
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 新手友好度
- 45/100
- Issue 類型
- 缺陷
- 描述清晰度
- 基本清楚
- 活躍度
- 冷清
- 技術堆疊
- javascript, nodejs, wasm
研究方向
使用 exhaust.wat、wasm-tools parse 和 test.js 重現該故障,然後檢查報告中所示的 V8 堆積與 OOM 堆疊附近的 WasmGC 配置路徑。追蹤配置失敗如何回報給 Node.js,並驗證重現過程以可捕捉的錯誤或 trap 結束,而不是中止程序。
由索引模型根據 Issue 內容生成。
描述
Version
24.2.0
Platform
Linux unknown387c76016c42.lan 6.19.14-108.fc42.x86_64 #1 SMP PREEMPT_DYNAMIC Thu May 21 18:06:59 UTC 2026 x86_64 GNU/Linux
Subsystem
No response
What steps will reproduce the bug?
- Save the attached
exhaust.watfile - Compile:
wasm-tools parse exhaust.wat -o exhaust.wasm - Run:
node test.js - Process crashes with FATAL ERROR + core dump
exhaust.wat:
(module
(type $arr (array (mut i64)))
(type $holder (array (mut (ref null $arr))))
(func (export "exhaust") (param $count i32)
(local $h (ref $holder))
(local $i i32)
;; parent array to hold all refs (prevents GC collection)
(array.new_default $holder (local.get $count))
(local.set $h)
(loop $loop
;; allocate ~1MB array (131072 x 8 bytes)
(local.get $h)
(local.get $i)
(array.new_default $arr (i32.const 131072))
(array.set $holder)
;; i++
(local.get $i)
(i32.const 1)
(i32.add)
(local.set $i)
;; loop while i < count
(local.get $i)
(local.get $count)
(i32.lt_u)
(br_if $loop)
)
)
)
test.js:
const fs = require('fs');
(async () => {
const mod = await WebAssembly.compile(fs.readFileSync('exhaust.wasm'));
const inst = await WebAssembly.instantiate(mod);
console.log('Allocating 10,000 x 1MB...');
inst.exports.exhaust(10000);
console.log('Survived (should not reach here)');
})();
How often does it reproduce? Is there a required condition?
Fully reproducible.
What is the expected behavior? Why is that the expected behavior?
The Wasm module should trap or throw a catchable JavaScript error on GC allocation failure, not crash the process with abort(). Linear memory already handles exhaustion gracefully (memory.grow returns -1), and the WasmGC spec allows implementations to "terminate that computation and report an embedder-specific error" on resource exhaustion.
What do you see instead?
Exit code: 134
Allocating 10,000 x 1MB...
<--- Last few GCs --->
[132127:0x365f6000] 1871 ms: Mark-Compact 4062.8 (4207.1) -> 4062.1 (4207.1) MB, pooled: 1 MB, 5.87 / 0.00 ms (average mu = 0.944, current mu = 0.848) allocation failure; scavenge might not succeed
[132127:0x365f6000] 1891 ms: Mark-Compact 4095.1 (4240.3) -> 4095.0 (4240.3) MB, pooled: 1 MB, 7.87 / 0.00 ms (average mu = 0.894, current mu = 0.604) allocation failure; scavenge might not succeed
FATAL ERROR: Reached heap limit Allocation failed - JavaScript heap out of memory
----- Native stack trace -----
1: 0xf1eeef node::OOMErrorHandler(char const*, v8::OOMDetails const&) [node]
2: 0x1351da0 v8::Utils::ReportOOMFailure(v8::internal::Isolate*, char const*, v8::OOMDetails const&) [node]
3: 0x1351e8f v8::internal::V8::FatalProcessOutOfMemory(v8::internal::Isolate*, char const*, v8::OOMDetails const&) [node]
4: 0x15e8505 [node]
5: 0x15f968c v8::internal::Heap::CollectGarbage(v8::internal::AllocationSpace, v8::internal::GarbageCollectionReason, v8::GCCallbackFlags) [node]
6: 0x15cf2f3 v8::internal::HeapAllocator::AllocateRawWithRetryOrFailSlowPath(int, v8::internal::AllocationType, v8::internal::AllocationOrigin, v8::internal::AllocationAlignment) [node]
7: 0x15a5770 v8::internal::Factory::NewFillerObject(int, v8::internal::AllocationAlignment, v8::internal::AllocationType, v8::internal::AllocationOrigin) [node]
8: 0x1a98558 v8::internal::Runtime_AllocateInYoungGeneration(int, unsigned long*, v8::internal::Isolate*) [node]
9: 0x21a1989 [node]
[1] 132127 IOT instruction (core dumped) node test.js
Additional information
Bug found during the investigation on https://github.com/bytecodealliance/endive/issues/102
- 主要語言
- JavaScript
- 星號
- 122k
- 分支
- 38.4k
- 平均合併
- 3 天 22 小時
- 30 天內合併 PR
- 273
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
nodejs/node 的其他 Issue
-
build / doc: missing platform and toolchain info for `linux-x64-musl`可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉alpine build doc
難度 2/5 1-3 小時 新手友好度 75/100
維護者通常 1 天內回覆
-
[Docs] `process.loadEnvFile()` does not document behaviour when variables already exist可能已有人在做 @Sepandard 於 10 天前認領。 未關閉doc
難度 1/5 1 小時以內 新手友好度 90/100
維護者通常 1 天內回覆
-
Stream.prototype.forEach will block in first promise in queue before read more chunk可能已有人在做 @mmustafasenoglu 於 11 天前認領。 未關閉doc
難度 2/5 1-3 小時 新手友好度 65/100
維護者通常 1 天內回覆
-
build
難度 1/5 1 小時以內 新手友好度 88/100
維護者通常 1 天內回覆
-
`TextEncoder.encodeInto()` underfills the destination for some non-ASCII text可能已有人在做 @XadillaX 於 24 天前認領。 未關閉
難度 2/5 1-3 小時 新手友好度 84/100
nodejs/node#65994 · 2 則留言 · 2 個 reaction ·
維護者通常 1 天內回覆
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 68/100
smansfield635-create/smansfield635-create.github.io#5818 · 4 則留言 ·
維護者通常 1 天內回覆
-
documentation
難度 2/5 1-3 小時 新手友好度 85/100
danjdewhurst/story-skills#538 ·
維護者通常 1 天內回覆
-
good first issue
難度 1/5 1-3 小時 新手友好度 88/100
anoopcodehack/DevBoard#589 ·
維護者通常 2 天內回覆
-
難度 2/5 1 小時以內 新手友好度 85/100
capricorn86/happy-dom#2474 ·
維護者通常 2 天內回覆
-
難度 1/5 1 小時以內 新手友好度 95/100
vigetlabs/mega-menu-block#30 ·
維護者通常 2 天內回覆