Skip to content

Commit 1de19de

Browse files
joyeecheungtargos
authored andcommitted
deps: V8: cherry-pick e061cf9970d9
Original commit message: [arraybuffers] initialize max byte length of empty array buffers Without initializing the max byte length field, any empty array buffer captured in the snapshot can make the snapshot unreproducible. Refs: nodejs#53579 Change-Id: I2489ab2e57ecbb405ec431a87d0acc92822b777c Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/5662576 Reviewed-by: Marja Hölttä <marja@chromium.org> Commit-Queue: Marja Hölttä <marja@chromium.org> Cr-Commit-Position: refs/heads/main@{#94754} Refs: v8/v8@e061cf9 PR-URL: nodejs#53755 Fixes: nodejs#53579 Reviewed-By: Benjamin Gruenbaum <benjamingr@gmail.com> Reviewed-By: Chengzhong Wu <legendecas@gmail.com>
1 parent 3adceb4 commit 1de19de

File tree

2 files changed

+3
-1
lines changed

2 files changed

+3
-1
lines changed

common.gypi

+1-1
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@
3636

3737
# Reset this number to 0 on major V8 upgrades.
3838
# Increment by one for each non-official patch applied to deps/v8.
39-
'v8_embedder_string': '-node.9',
39+
'v8_embedder_string': '-node.10',
4040

4141
##### V8 defaults for Node.js #####
4242

deps/v8/src/builtins/builtins-typed-array-gen.cc

+2
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,8 @@ TNode<JSArrayBuffer> TypedArrayBuiltinsAssembler::AllocateEmptyOnHeapBuffer(
6969
UndefinedConstant());
7070
StoreBoundedSizeToObject(buffer, JSArrayBuffer::kRawByteLengthOffset,
7171
UintPtrConstant(0));
72+
StoreBoundedSizeToObject(buffer, JSArrayBuffer::kRawMaxByteLengthOffset,
73+
UintPtrConstant(0));
7274
StoreSandboxedPointerToObject(buffer, JSArrayBuffer::kBackingStoreOffset,
7375
EmptyBackingStoreBufferConstant());
7476
#ifdef V8_COMPRESS_POINTERS

0 commit comments

Comments
 (0)