v24: discarded vm contexts cause OOM; possible V8 backport

Aperta
#66,053 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
javascript, node.js
Ambito
backend

Direzione di ricerca

Inizia con repro.mjs ed eseguilo su v24 con --max-old-space-size=128, quindi confronta v22, v26 e v24 con --no-concurrent-recompilation. Analizza i retainer di IdentityMapBase e i due commit collegati di V8 per determinare se risolvono il problema dei contesti vm scartati. Il lavoro è completato quando la riproduzione stampa "Completed" senza esaurire l’heap e i contesti scartati possono essere raccolti.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

confirmed-bug v24.x v8 engine vm
Version

v24.21.0

Platform
Linux x86_64, kernel 6.8.0-139-generic
Subsystem

vm, V8

What steps will reproduce the bug?

Save as repro.mjs; run node --max-old-space-size=128 repro.mjs.

import { runInNewContext } from "node:vm";
import { setImmediate } from "node:timers/promises";

const source = `
  globalThis.payload = new Array(1_000_000).fill(0);
  ${Array.from({ length: 30 }, (_, index) => `
    function work${index}(values) {
      let result = 0;
      for (let i = 0; i < values.length; ++i) {
        result += Math.sqrt(values[i] * values[i] + ${index});
      }
      return result;
    }
  `).join("\n")}
  const values = [1, 2, 3, 4, 5];
  for (let i = 0; i < 1000; ++i) {
    ${Array.from({ length: 30 }, (_, index) => `work${index}(values);`).join("\n")}
  }
`;

for (let i = 0; i < 100; ++i) {
  runInNewContext(source + `\n// ${i}`);
  await setImmediate();
}
console.log("Completed");
How often does it reproduce? Is there a required condition?

Repeatedly on v24.15.0, v24.16.0, and v24.21.0. Completes on v22.23.2, v26.8.2, or with --no-concurrent-recompilation on v24.

What is the expected behavior? Why is that the expected behavior?

Print Completed; discarded contexts should be collectible.

What do you see instead?
FATAL ERROR: Reached heap limit Allocation failed - JavaScript heap out of memory
Additional information

This surfaced in jsdom’s WPT runner with the default ~4 GB heap; the smaller limit makes this reproduction quick. Sampled heap retainers point through V8’s IdentityMapBase to realm prototypes, keeping entire windows alive.

Could V8’s “Stop collecting array and object prototypes” change be backported to v24? Its later thread-safety follow-up might also be relevant.

I haven't verified that those commits are the key ones, but it's worth trying.

Lingua principale
JavaScript
Stelle
122k
Fork
37.4k
Merge medio
4g 3h
PR unite (30g)
272

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di nodejs/node

Tutte le issue di nodejs/node

Issue simili

Altre issue su JavaScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.