Commit 33e50315039 for nodejs

commit 33e50315039b5941ccfbcf1da77c1efc3093d5f2
Author: Joyee Cheung <joyeec9h3@gmail.com>
Date:   Tue Sep 29 15:38:14 2026 +0200

    deps: V8: cherry-pick 99ebeac9c548

    Original commit message:

        [torque] Fix C++ object layout assertions for MSVC STL

        The assertions generated for @cppObjectLayoutDefinition classes assume
        that the first field of a derived class starts at sizeof(Parent) and
        that sizeof(Class) == the packed size computed by Torque. Both
        assumptions break when compiling with the MSVC STL, which stores
        std::atomic<T> with alignas(sizeof(T)). Under the Microsoft C++ ABI an
        alignas() is a required alignment that #pragma pack cannot lower, so the
        std::atomic bit fields of Map force Map, and in turn the pack(1)
        ExtendedMap, to align by 4 bytes. After rounding up,

        sizeof(ExtendedMap) == sizeof(Map) + 4 == kSize + 3

        so

        static_assert(kSize == sizeof(ExtendedMap))

        fails. The base subobject size is not rounded up
        however, so JSInterceptorMap places its first field at sizeof(Map) + 1
        rather than sizeof(ExtendedMap), and

        static_assert(kFlagsOffset == offsetof(JSInterceptorMap, flags_))

        fails as well.

        Fix this by:

        - Using the packed parent size that Torque already knows as the offset
          of the first derived field instead of sizeof(Parent).
        - Relaxing the assertion to only require that sizeof(Class) does not
          exceed kSize by alignof(Class) or more, so that any extra bytes fit
          into the alignment padding.

        Co-Authored-By: StefanStojanovic <stefan.stojanovic@janeasystems.com>
        Refs: https://github.com/nodejs/node/pull/65161
        Bug: 531344950
        Change-Id: I16811484a8ff3d1bff187bab950ac71b6ea7f297
        Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8486028
        Reviewed-by: Leszek Swirski <leszeks@chromium.org>
        Reviewed-by: Igor Sheludko <ishell@chromium.org>
        Commit-Queue: Joyee Cheung <joyee@igalia.com>
        Cr-Commit-Position: refs/heads/main@{#110223}

    Refs: https://github.com/v8/v8/commit/99ebeac9c548e36f9e18658097df0b6c42b1c71c
    Co-Authored-By: StefanStojanovic <stefan.stojanovic@janeasystems.com>
    Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
    PR-URL: https://github.com/nodejs/node/pull/65161
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    Reviewed-By: Richard Lau <richard.lau@ibm.com>

diff --git a/common.gypi b/common.gypi
index b4a3010d2ff..d0380616db6 100644
--- a/common.gypi
+++ b/common.gypi
@@ -44,7 +44,7 @@

     # Reset this number to 0 on major V8 upgrades.
     # Increment by one for each non-official patch applied to deps/v8.
-    'v8_embedder_string': '-node.11',
+    'v8_embedder_string': '-node.12',

     ##### V8 defaults for Node.js #####

diff --git a/deps/v8/src/torque/implementation-visitor.cc b/deps/v8/src/torque/implementation-visitor.cc
index 08caa5038e4..4ddcd25d3ee 100644
--- a/deps/v8/src/torque/implementation-visitor.cc
+++ b/deps/v8/src/torque/implementation-visitor.cc
@@ -4023,6 +4023,11 @@ class ClassFieldOffsetGenerator : public FieldOffsetsGenerator {
     std::string parent_name = use_templates ? "P" : parent->name();

     if (type->IsLayoutDefinedInCpp()) {
+      if (parent) {
+        if (std::optional<size_t> packed_size = parent->size().SingleValue()) {
+          return std::to_string(*packed_size);
+        }
+      }
       return "sizeof(" + parent_name + ")";
     }

@@ -4111,7 +4116,8 @@ void CppClassGenerator::GenerateCppObjectLayoutDefinitionAsserts() {
           << "::" << f.name_and_type.name << " in C++ do not match\");\n";
   }
   if (!type_->IsAbstract() && type_->HasStaticSize()) {
-    impl_ << "  static_assert(kSize == sizeof(" + name_ + "));\n";
+    impl_ << "  static_assert(kSize <= sizeof(" + name_ + ") && sizeof(" +
+                 name_ + ") < kSize + alignof(" + name_ + "));\n";
   }

   impl_ << "};\n\n";