Commit 08dbed22724 for nodejs
commit 08dbed22724162e5b61596ce00c79107bc336150
Author: Eliau Elkouby <145869377+eliau2005@users.noreply.github.com>
Date: Sat Sep 26 19:27:28 2026 +0300
deps: V8: backport 786c1c2d88d4
Original commit message:
[stack-traces] Fix overflow in Error.stackTraceLimit trimming
When stack traces are captured for uncaught exceptions (enabled via
Isolate::SetCaptureStackTraceForUncaughtExceptions, e.g. by the
inspector or by Node.js's --trace-uncaught), CaptureAndSetErrorStack
reuses the simple stack trace and trims it to Error.stackTraceLimit.
Error.stackTraceLimit counts frames, but the raw call site data stores
CallSiteInfo::Fields::kCount slots per frame, so the trim multiplied the
limit by kCount: once in the uint32_t comparison against the array
length and once, as int, to compute the new length. GetStackTraceLimit
clamps the limit to [0, INT_MAX], so for very large limits the uint32_t
product can wrap to a value below the array length. The trim branch is
then taken although the limit exceeds the number of captured frames,
and the int multiplication of the new length overflows.
On main (kCount == 5) the product first wraps at 858993460. That limit
trimmed the raw data to 4 slots (no complete frame) and 858993461 to 9
slots (one frame), so error.stack silently lost frames. Infinity, the
value from the Node.js report, is clamped to INT_MAX; its wrapped
product (2147483643) is not below the array length, so on main it does
not take the trim branch and does not reach the signed overflow.
Fix this by comparing the limit with the number of frames in the raw
data (length / kCount), and only multiplying once the limit is known to
be smaller than the frame count. The resulting length is then bounded
by the existing array length and cannot overflow. Behavior for limits
that did not overflow is unchanged, since the raw data length is always
a multiple of kCount.
This regressed with https://crrev.com/c/7673818 (ebd15783b7b,
"[objects]: Defer CallSiteInfo creation"), which switched from one
CallSiteInfo per frame to kCount raw slots per frame.
This is the underlying cause of Node.js issue 66074. The symptom there
differs from main: Node's V8 14.6 backport of that change has
kCount == 6 and uses int for the comparison and for RightTrim, so the
product overflows for limits above 357913941. For many of those,
including Infinity (INT_MAX * 6 wraps to -6), the result is negative
and fails "Check failed: new_capacity > 0." in RightTrim. Comparing in
frames avoids the overflow in both cases.
The new cctest CaptureStackTraceForUncaughtExceptionHugeStackTraceLimit
enables capture for uncaught exceptions and checks that limits of
858993460, 858993461 and Infinity yield the same error.stack as a limit
of 10, and that a limit of 1 still trims to a single frame. 858993460
and 858993461 are the first limits whose product with kCount wraps
around uint32_t; both fail without this change. The new test and the
existing stack trace tests also pass in a UBSan build, with no
diagnostics.
Bug: 565047704
Refs: https://github.com/nodejs/node/issues/66074
Change-Id: I3422ca1de6a7dd9448c7fd53fb9bc5e40e2a17c1
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8426465
Reviewed-by: Patrick Thier <pthier@chromium.org>
Reviewed-by: Leszek Swirski <leszeks@chromium.org>
Auto-Submit: eliau elkouby (אליהו אלקובי) <eliau.elkouby@gmail.com>
Commit-Queue: Patrick Thier <pthier@chromium.org>
Cr-Commit-Position: refs/heads/main@{#110043}
Refs: https://github.com/v8/v8/commit/786c1c2d88d445eecf54efe7ba9cef27a3eef3bb
Fixes: https://github.com/nodejs/node/issues/66074
Assisted-by: a closed-source coding agent
Signed-off-by: Eliau Elkouby <145869377+eliau2005@users.noreply.github.com>
PR-URL: https://github.com/nodejs/node/pull/66249
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Reviewed-By: Richard Lau <richard.lau@ibm.com>
diff --git a/common.gypi b/common.gypi
index 7eaad1e5ea1..3e37e440b86 100644
--- a/common.gypi
+++ b/common.gypi
@@ -43,7 +43,7 @@
# Reset this number to 0 on major V8 upgrades.
# Increment by one for each non-official patch applied to deps/v8.
- 'v8_embedder_string': '-node.35',
+ 'v8_embedder_string': '-node.36',
##### V8 defaults for Node.js #####
diff --git a/deps/v8/AUTHORS b/deps/v8/AUTHORS
index cf468f85950..404f8901990 100644
--- a/deps/v8/AUTHORS
+++ b/deps/v8/AUTHORS
@@ -124,6 +124,7 @@ Douglas Crosher <dtc-v8@scieneer.com>
Dusan Milosavljevic <dusan.m.milosavljevic@gmail.com>
Eden Wang <nedenwang@tencent.com>
Edoardo Marangoni <edoardo@wasmer.io>
+Eliau Elkouby <eliau.elkouby@gmail.com>
Elisha Hollander <just4now666666@gmail.com>
Eric Rannaud <eric.rannaud@gmail.com>
Erich Ocean <erich.ocean@me.com>
diff --git a/deps/v8/src/execution/isolate.cc b/deps/v8/src/execution/isolate.cc
index 74762de5a9a..e94255333ac 100644
--- a/deps/v8/src/execution/isolate.cc
+++ b/deps/v8/src/execution/isolate.cc
@@ -1645,12 +1645,15 @@ MaybeDirectHandle<JSObject> Isolate::CaptureAndSetErrorStack(
static_cast<uint32_t>(
stack_trace_for_uncaught_exceptions_frame_limit_));
DCHECK_GE(stack_trace_limit, 0);
- if (static_cast<int>(stack_trace_limit) *
- CallSiteInfo::Fields::kCount <
- raw_data_for_call_site_infos->length()) {
+ // Compare in frames rather than raw slots to avoid overflowing for
+ // large Error.stackTraceLimit values.
+ uint32_t frame_count = raw_data_for_call_site_infos->ulength() /
+ CallSiteInfo::Fields::kCount;
+ if (static_cast<uint32_t>(stack_trace_limit) < frame_count) {
call_site_infos_or_formatted_stack = FixedArray::RightTrimOrEmpty(
this, raw_data_for_call_site_infos,
- stack_trace_limit * CallSiteInfo::Fields::kCount);
+ static_cast<uint32_t>(stack_trace_limit) *
+ CallSiteInfo::Fields::kCount);
}
// Notify the debugger.
OnStackTraceCaptured(stack_trace);
diff --git a/deps/v8/test/cctest/test-api-stack-traces.cc b/deps/v8/test/cctest/test-api-stack-traces.cc
index 22626a5e11f..4e8de23db42 100644
--- a/deps/v8/test/cctest/test-api-stack-traces.cc
+++ b/deps/v8/test/cctest/test-api-stack-traces.cc
@@ -438,6 +438,34 @@ TEST(CaptureStackTraceForUncaughtException) {
CHECK_EQ(1, report_count);
}
+TEST(CaptureStackTraceForUncaughtExceptionHugeStackTraceLimit) {
+ LocalContext env;
+ v8::Isolate* isolate = env.isolate();
+ v8::HandleScope scope(isolate);
+ isolate->SetCaptureStackTraceForUncaughtExceptions(true);
+
+ CompileRun(
+ "function foo() { return new Error().stack; }\n"
+ "function bar() { return foo(); }\n"
+ "function stackWithLimit(limit) {\n"
+ " Error.stackTraceLimit = limit;\n"
+ " return bar();\n"
+ "}\n");
+ Local<Value> expected = CompileRun("stackWithLimit(10)");
+ CHECK(expected->IsString());
+
+ // For these limits, limit * CallSiteInfo::Fields::kCount overflows.
+ for (const char* limit : {"858993460", "858993461", "Infinity"}) {
+ std::string source = std::string("stackWithLimit(") + limit + ")";
+ CHECK(CompileRun(source.c_str())->StrictEquals(expected));
+ }
+
+ // Small limits must still trim the stack trace.
+ CHECK(CompileRun("stackWithLimit(1).split('\\n').length === 2")->IsTrue());
+
+ isolate->SetCaptureStackTraceForUncaughtExceptions(false);
+}
+
// Test uncaught exception in a setter
const char uncaught_setter_exception_source[] =
"var setters = ['column', 'lineNumber', 'scriptName',\n"