microsoft / microsoft/TypeScript

`checkImportMetaProperty`: debug failure crash

Open
#56,054 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Bug Domain: Crashes Help Wanted
Dominant language
Go
Stars
111k
Forks
14.4k
Avg merge
1d 19h
Merged PRs (30d)
117

Description

🔎 Search Terms

Hi

This is another follow-up ticket from the fuzzing crashes discussion and
the first debug failure report

Search terms:

  • transpileModule
  • debug failure
  • crash
  • checkImportMetaProperty
🕗 Version & Regression Information
⏯ Playground Link

No response

💻 Code
const ts = require("typescript");

const hex_string = "2c726270726f746f74797065326f746f747970656201000000000000053c7b746f3b6f74796f6a7375747270726f3b6f747970652d7c7b7c3c7b643c7c3c7f004005041274747375747270726f3b70652d72742a40283c7f7f61776169747f7f7670652d7c7b7c3c7b643c7c3c7f000005045b1274747375743170726f3b70652d7c28696d706f72742a40283c7f7f5f7f7f7f7f00000061776169747f7f7661727b067b636f6e7374727563746f722e70726f746f7439707b6f6a737574722c726f3b6f747970652d7c7b7c3c7b643c7c3c7f000005041274747375747270726f63617f3d045f523c6e7b5b233c7c213c7576616e0a726c3c696d706f726c742e7d0c3c696d706f72742e7d0c7b746f7b746f5c5c745c745c745c745c745c745c745c745c745c745c745c745c745c745c745c745c745c745c745c745c745c745c74733d3d2b3333333328732e2e73706f726c742e7d0c3c696d706f72742e7d0c7b743d083e28732c08006172756e6b6e6f776e747275270b100d2e70726f746f7479707b7c3c7b743c7c3c5100007b7b75740b00000000652e0030002a00002c000000120c0b50000000007273000005041274747375740470726f3b7f7f7f7f7f7f7f2e283c7f7f61776169747f7f7670650d2d7c7b7c3c7b643c7c3c7f0000050412747473757432707211440f742c637b6f127d3d7b0500000000000000742c637b6f127d3d7b05000000000000007a21593a";
const input = hex_string.match(/.{1,2}/g).map(byte => String.fromCharCode(parseInt(byte, 16))).join('');
ts.transpileModule(input, {});
🙁 Actual behavior
TypeScript/node_modules/typescript/lib/typescript.js:119406
        throw e;
        ^

Error: Debug Failure. False expression: Containing file is missing import meta node flag.
    at checkImportMetaProperty (TypeScript/node_modules/typescript/lib/typescript.js:74543:13)
    at checkMetaProperty (TypeScript/node_modules/typescript/lib/typescript.js:74506:16)
    at checkExpressionWorker (TypeScript/node_modules/typescript/lib/typescript.js:77249:18)
    at checkExpression (TypeScript/node_modules/typescript/lib/typescript.js:77138:34)
    at maybeCheckExpression (TypeScript/node_modules/typescript/lib/typescript.js:76222:30)
    at BinaryExpressionStateMachine.onRight (TypeScript/node_modules/typescript/lib/typescript.js:76186:18)
    at Array.right (TypeScript/node_modules/typescript/lib/typescript.js:27825:36)
    at trampoline (TypeScript/node_modules/typescript/lib/typescript.js:27591:44)
    at TypeScript/node_modules/typescript/lib/typescript.js:76116:24
    at checkExpressionWorker (TypeScript/node_modules/typescript/lib/typescript.js:77261:18)

Node.js v18.16.0

🙂 Expected behavior

Not crash the Node.js runtime

Additional information about the issue

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the crash with the provided Node.js script using ts.transpileModule, then inspect checkImportMetaProperty and the surrounding checkMetaProperty path in typescript.js. Done means the minimized input no longer triggers a Debug Failure or crashes the Node.js runtime.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js, typescript
Domain
compilers
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.