v24.x: "Fatal process out of memory: Zone" crash in V8 turboshaft WASM compilation (WasmLoweringReducer)
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 45/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- javascript, node.js, wasm
- 领域
- compilers
调研方向
首先使用 Node.js v24.x 和 codegraph 工作负载复现崩溃,然后在据报告可以正常工作的 v22.x 下比较相同的语法。使用原生堆栈跟踪调查 V8 turboshaft's WasmLoweringReducer、SnapshotTable::MergePredecessors 以及 Zone 分配路径。完成的标准是:中型到大型项目在所有受影响的工作负载下都能完成解析,而不会出现 fatal Zone OOM。
由索引模型根据 Issue 内容生成。
描述
Version
v24.13.1, v24.14.1, v24.15.0 confirmed affected. v22.x LTS works fine.
Platform
macOS arm64 (Darwin 25.3.0, Apple Silicon M1) and Linux x64. Not architecture-specific.
Subsystem
V8 turboshaft WASM compiler — specifically WasmLoweringReducer during tree-sitter grammar compilation.
Severity
100% reproducible. Crashes the entire Node.js process with no JS-level error handling possible.
What steps will reproduce the bug?
- Install Node.js v24.x
- Install a package that uses tree-sitter WASM grammars (e.g.
npm install -g @colbymchenry/codegraph) - Run against a medium-sized project (500+ source files):
cd /path/to/any-project
codegraph init # or codegraph index if already initialized
The crash occurs consistently at 12-14% parsing progress, when V8's turboshaft pipeline compiles the tree-sitter WASM grammars for Swift/TypeScript/Python/etc.
How often does it reproduce? Is there a required condition?
100% of runs. No special conditions — any project with enough diverse file types to trigger multiple tree-sitter WASM grammar compilations will hit it.
The number of files seems to matter: small projects (< ~50 files) may succeed because fewer grammars are loaded. Medium-to-large projects (500+ files, 5+ languages) crash every time at parse phase.
What is the expected behavior? Why is that wrong?
The Node.js process should complete normally. Instead it crashes with a native-level OOM in V8's Zone allocator, which is unrecoverable from JS land.
What do you see instead?
#
# Fatal process out of memory: Zone
#
----- Native stack trace -----
1: node::NodePlatform::GetStackTracePrinter()::$_0::__invoke()
2: v8::base::FatalOOM(v8::base::OOMType, char const*)
3: v8::internal::V8::FatalProcessOutOfMemory(...)
4: v8::internal::Zone::Expand(unsigned long)
5: v8::internal::compiler::turboshaft::SnapshotTable::MergePredecessors<...WasmLoweringReducer...>::Bind(...)
6: v8::internal::compiler::turboshaft::VariableReducer<...WasmLoweringReducer...>::Bind(Block*)
7: v8::internal::compiler::turboshaft::GraphVisitor<...WasmLoweringReducer...>::VisitBlock<false>(Block const*)
8: v8::internal::compiler::turboshaft::GraphVisitor<...>::VisitAllBlocks<false>()
9: v8::internal::compiler::turboshaft::CopyingPhaseImpl<WasmLoweringReducer, MachineOptimizationReducer>::Run(...)
10: v8::internal::compiler::turboshaft::Pipeline::Run<WasmLoweringPhase>()
11: v8::internal::compiler::Pipeline::GenerateWasmCode(...)
12: v8::internal::compiler::turboshaft::ExecuteTurboshaftWasmCompilation(...)
13: v8::internal::wasm::WasmCompilationUnit::ExecuteCompilation(...)
14: v8::internal::wasm::ExecuteCompilationUnits(...)
15: v8::internal::wasm::BackgroundCompileJob::Run(JobDelegate*)
16: v8::platform::DefaultJobWorker::Run()
17: node::PlatformWorkerThread(void*)
18: _pthread_start
Abort trap: 6
Additional information
- Not a JS heap OOM:
--max-old-space-sizehas no effect — this is V8's internal Zone memory, not the managed heap. - Already tracked downstream: colbymchenry/codegraph#140 (multiple users confirmed, codegraph added a hard-exit guard for Node 25.x but v24.x is also affected and not yet guarded).
- Node 22 LTS unaffected: v22.22.0 works correctly with the same workload and same WASM grammars.
- Likely regression: The Zone allocator in turboshaft's WASM pipeline appears to have a size calculation or growth bug triggered by the size/number of tree-sitter WASM modules.
Stack traces from three separate runs (v24.13.1, v24.15.0, different memory limits) are identical — the crash point is deterministic.
- 主要语言
- JavaScript
- 星标
- 122k
- 派生
- 37.4k
- 平均合并
- 4 天 3 小时
- 30 天内合并 PR
- 279
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
nodejs/node 的其他 Issue
-
doc
难度 2/5 1-3 小时 新手友好度 65/100
-
build
难度 1/5 1 小时以内 新手友好度 88/100
-
难度 2/5 1-3 小时 新手友好度 84/100
-
难度 1/5 1 小时以内 新手友好度 90/100
-
feature request
难度 2/5 1-3 小时 新手友好度 68/100
相似的 Issue
-
bug confirmed issue
难度 2/5 1-3 小时 新手友好度 75/100
open-webui/open-webui#30750 · 1 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 70/100
-
难度 2/5 1-3 小时 新手友好度 75/100
-
Mend: dependency security vulnerability untriaged
难度 2/5 1-3 小时 新手友好度 70/100