nodejs / nodejs/node

Crash in V8 GC on v24.x and earlier

未关闭
#62,393 6 条评论 2 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

v24.x v8 engine
主要语言
JavaScript
星标
122k
派生
37.3k
平均合并
4 天 2 小时
30 天内合并 PR
283

描述

Version

24.10.0

Platform
Darwin HQX-LGM9L426J5 25.2.0 Darwin Kernel Version 25.2.0: Tue Nov 18 21:09:40 PST 2025; root:xnu-12377.61.12~1/RELEASE_ARM64_T6000 arm64
Subsystem

GC, from the looks of it, maybe vm

What steps will reproduce the bug?

It's unfortunately not trivially reproducible. We see this ~1/10 times running our un-cached build runner, primarily while executing tests (which use a combination of worker threads and the vm module)

How often does it reproduce? Is there a required condition?

As stated above, something like 1/10 times.

What is the expected behavior? Why is that the expected behavior?

No segfault.

What do you see instead?
PID 22412 received SIGSEGV for address: 0xe
0   segfault-handler.node               0x0000000109630ee4 _ZL16segfault_handleriP9__siginfoPv + 288
1   libsystem_platform.dylib            0x0000000181a67744 _sigtramp + 56
2   node                                0x00000001029e0280 _ZN2v88internal35ClearStaleLeftTrimmedPointerVisitor17VisitRootPointersENS0_4RootEPKcNS0_14FullObjectSlotES5_ + 80
3   node                                0x00000001029278e4 _ZNK2v88internal13InternalFrame7IterateEPNS0_11RootVisitorE + 240
4   node                                0x000000010292cbf8 _ZN2v88internal7Isolate7IterateEPNS0_11RootVisitorEPNS0_14ThreadLocalTopE + 364
5   node                                0x00000001029e04ac _ZN2v88internal4Heap12IterateRootsEPNS0_11RootVisitorENS_4base7EnumSetINS0_8SkipRootEiEENS1_16IterateRootsModeE + 460
6   node                                0x00000001029fefe4 _ZN2v88internal20MarkCompactCollector9MarkRootsEPNS0_11RootVisitorE + 56
7   node                                0x00000001029fa96c _ZN2v88internal20MarkCompactCollector15MarkLiveObjectsEv + 968
8   node                                0x00000001029fa514 _ZN2v88internal20MarkCompactCollector14CollectGarbageEv + 128
9   node                                0x00000001029d94e8 _ZN2v88internal4Heap11MarkCompactEv + 420
10  node                                0x00000001029d8e50 _ZN2v88internal4Heap24PerformGarbageCollectionENS0_16GarbageCollectorENS0_23GarbageCollectionReasonEPKc + 824
11  node                                0x00000001029eb8c4 _ZZN2v88internal4Heap14CollectGarbageENS0_15AllocationSpaceENS0_23GarbageCollectionReasonENS_15GCCallbackFlagsEENK3$_1clEv + 1188
12  node                                0x00000001029eb408 _ZN4heap4base5Stack24SetMarkerAndCallbackImplIZN2v88internal4Heap14CollectGarbageENS4_15AllocationSpaceENS4_23GarbageCollectionReasonENS3_15GCCallbackFlagsEE3$_1EEvPS1_PvPKv + 40
13  node                                0x00000001033a09e4 PushAllRegistersAndIterateStack + 40
14  node                                0x00000001029d5248 _ZN2v88internal4Heap14CollectGarbageENS0_15AllocationSpaceENS0_23GarbageCollectionReasonENS_15GCCallbackFlagsE + 748
15  node                                0x000000010294d124 _ZN2v88internal10StackGuard16HandleInterruptsENS1_14InterruptLevelE + 504
16  node                                0x0000000102e3a19c _ZN2v88internal25Runtime_StackGuardWithGapEiPmPNS0_7IsolateE + 312
17  node                                0x0000000103491f74 Builtins_CEntry_Return1_ArgvOnStack_NoBuiltinExit + 84
18  node                                0x00000001033f5934 Builtins_BaselineOutOfLinePrologue + 116
19  ???                                 0x00000003205419b8 0x0 + 13427284408
20  ???                                 0x0000000320541bc0 0x0 + 13427284928
21  ???                                 0x00000003206e4504 0x0 + 13428999428
22  node                                0x00000001033f4bec Builtins_InterpreterEntryTrampoline + 268
23  ???                                 0x000000032048b6f0 0x0 + 13426538224
24  ???                                 0x000000032048c9e4 0x0 + 13426543076
25  ???                                 0x000000032048d328 0x0 + 13426545448
26  ???                                 0x0000000320433be8 0x0 + 13426179048
27  ???                                 0x00000003201fddf8 0x0 + 13423861240
28  ???                                 0x00000003201fe22c 0x0 + 13423862316
29  ???                                 0x00000003201fe474 0x0 + 13423862900
30  ???                                 0x00000003204e32c0 0x0 + 13426897600
31  ???                                 0x00000003204e7dec 0x0 + 13426916844
Additional information

I'm not using native extensions other than the segfault handler installed specifically to capture this trace—the segfault was occuring prior to that.

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从 ClearStaleLeftTrimmedPointerVisitor 周围的 V8 GC 栈以及报告中描述的 Node vm 和 worker-thread 使用方式开始。使用未缓存的构建运行器及其测试工作负载重现崩溃,然后追踪 macOS 上间歇性出现的 SIGSEGV。完成的标准是识别并阻止 GC 崩溃;如果 payload 支持,则提供回归测试或可靠的复现方式。

由索引模型根据 Issue 内容生成。

评估

技术栈
javascript, node.js
领域
backend
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
活跃
描述清晰度
需要澄清
新手友好度
38/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。