diagnostics_channel: Channel::binding_data_ dangles after environment cleanup, crashing node:sqlite at exit
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 新手友好度
- 48/100
- Issue 類型
- 缺陷
- 描述清晰度
- 基本清楚
- 活躍度
- 活躍
- 技術堆疊
- javascript, node.js, sqlite
研究方向
先執行提供的 node:diagnostics_channel 與 node:sqlite 重現案例,然後透過 Environment::RunCleanup() 和 SQLite profile callback 追蹤 Channel::binding_data_。使用相同的結束情境確認修正,包括一個未明確呼叫 close() 而停留在步驟中途的 statement,並確保程序在沒有 SIGSEGV 的情況下結束。
由索引模型根據 Issue 內容生成。
描述
Version
v27.0.0-pre (2dfdb6a4206)
Platform
Darwin 25.6.0 arm64
Subsystem
diagnostics_channel, sqlite
What steps will reproduce the bug?
Channel holds its BindingData as a raw pointer that is never cleared, so any native holder that outlives environment cleanup reads a destroyed object. Here's a replication case using node:sqlite:
const dc = require('node:diagnostics_channel');
const { DatabaseSync } = require('node:sqlite');
dc.subscribe('sqlite.db.query', () => {});
const db = new DatabaseSync(':memory:');
db.exec('CREATE TABLE t(x)');
const ins = db.prepare('INSERT INTO t VALUES (?)');
for (let i = 0; i < 200; i++) ins.run(i);
// Start iterating and abandon it: the statement stays mid-step, so the
// finalize that happens at teardown fires SQLite's profile callback.
const it = db.prepare('SELECT * FROM t').iterate();
it.next();
globalThis.keepAlive = { db, it };
console.log('reached end of script');
How often does it reproduce? Is there a required condition?
Three conditions are required (all included in the example above):
- A subscriber on
sqlite.db.query, so the SQLite profile hook is installed. - A statement left mid-step at exit, so that the finalize during teardown has a started statement to profile.
- No explicit
close(), so the statement is finalized by the destructor chain afterEnvironment::RunCleanup()rather than before it.
What is the expected behavior? Why is that the expected behavior?
Exiting a process that used node:sqlite with a sqlite.db.query subscriber
shouldn't crash.
What do you see instead?
SIGSEGV, exit 139, after the script has finished.
- 主要語言
- JavaScript
- 星號
- 122k
- 分支
- 38.4k
- 平均合併
- 4 天 10 小時
- 30 天內合併 PR
- 276
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
nodejs/node 的其他 Issue
-
doc
難度 1/5 1 小時以內 新手友好度 90/100
維護者通常 1 天內回覆
-
doc
難度 2/5 1-3 小時 新手友好度 65/100
維護者通常 1 天內回覆
-
build
難度 1/5 1 小時以內 新手友好度 88/100
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 84/100
nodejs/node#65994 · 2 則留言 · 2 個 reaction ·
維護者通常 1 天內回覆
-
feature request
難度 2/5 1-3 小時 新手友好度 68/100
維護者通常 1 天內回覆
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 65/100
daisy/a11y-meta-viewer#18 ·
-
good first issue status: needs triaging type: bug version: 2.0
難度 2/5 1-3 小時 新手友好度 85/100
medusajs/medusa#17094 · 2 則留言 ·
維護者通常 1 天內回覆
-
browser: chrome package: @carbon/react package: styles
難度 1/5 1 小時以內 新手友好度 92/100
carbon-design-system/carbon#23567 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 88/100
clerk/javascript#10033 ·
維護者通常 1 天內回覆
-
bug client p1
難度 2/5 1-3 小時 新手友好度 78/100
維護者通常 1 天內回覆