nodejs / nodejs/node

`parallel/test-snapshot-reproducible` fails when ASLR is enabled

Open
#63,914 1 comment 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

snapshot test
Dominant language
JavaScript
Stars
122k
Forks
37.3k
Avg merge
4d 2h
Merged PRs (30d)
283

Description

Testing main on linux:

# sysctl -w kernel.randomize_va_space=2
$ ./configure && make && ./node test/parallel/test-snapshot-reproducible.js
node:internal/assert/utils:146
  throw error;
  ^

AssertionError [ERR_ASSERTION]: Expected values to be strictly deep-equal:
+ actual - expected
... Skipped lines

  [
    '#include <cstddef>',
    '#include "env.h"',
    '#include "node_snapshot_builder.h"',
    '#include "v8.h"',
...
    'namespace node {',
+   'static const char v8_snapshot_blob_data[] = {4,0,0,0,1,0,0,0,43,108,-20,-8,-43,-25,-94,-55,49,52,46,54,46,50,48,50,46,51,52,45,110,111,100,101,46,50,49,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,  // 0',
-   'static const char v8_snapshot_blob_data[] = {4,0,0,0,1,0,0,0,-99,103,75,7,-43,-25,-94,-55,49,52,46,54,46,50,48,50,46,51,52,45,110,111,100,101,46,50,49,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,  // 0',
    '0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,16,10,23,0,64,8,25,0,72,114,29,0,8,107,30,0,-120,98,31,0,-40,88,32,0,-85,6,-34,-64,-96,9,23,0,-83,24,96,0,0,0,0,86,0,0,0,96,0,0,0,0,  // 1',
    '0,0,0,0,96,0,0,0,0,0,0,0,0,96,0,0,0,0,-53,1,0,0,96,0,0,0,0,-84,1,0,0,96,0,0,0,0,-64,2,0,0,96,0,0,0,0,0,0,0,0,96,0,0,0,0,-30,0,0,0,11,5,24,98,0,2,  // 2',
    '5,24,34,1,2,5,24,-30,1,2,5,24,-94,2,2,5,24,98,3,2,5,24,34,4,2,5,24,-30,4,2,5,24,-94,5,2,5,24,98,6,2,5,24,34,7,2,5,24,-30,7,2,5,24,-94,8,2,5,24,98,9,2,1,76,7,101,  // 3',
    '15,69,64,97,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,64,98,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,64,96,0,0,0,0,0,0,0,0,7,-123,2,64,96,0,0,0,  // 4',
    '0,8,0,0,0,-127,0,91,64,1,20,83,69,97,0,0,0,0,96,0,0,0,0,0,0,0,1,0,0,0,93,1,20,83,69,97,0,0,0,0,96,0,0,0,0,0,0,0,1,0,0,0,93,1,20,83,69,97,0,0,0,0,96,0,  // 5',
...
    '26,-87,22,26,-11,27,26,93,28,26,101,28,26,105,34,26,69,37,26,73,37,26,77,37,26,81,37,26,85,37,26,89,37,26,93,37,26,97,37,26,101,37,26,-87,43,26,-83,43,26,-71,43,1,20,86,98,0,0,0,0,3,0,0,0,0,  // 42996',
+   '0,0,0,1,0,0,0,0,0,0,0,14,0,0,0,64,91,31,0,6,-71,2,5,24,66,66,4,4,8,95,4,73,33,11,15,0,-3,15,0,8,6,0,0,-3,15,4,96,6,-86,-127,-107,44,127,0,0,24,0,0,0,0,0,0,0,47,  // 42997',
+   '0,0,0,0,0,0,0,0,-107,26,0,8,8,0,0,-107,26,4,64,8,-102,-74,95,5,0,0,0,16,0,0,0,0,0,0,0,0,-99,39,0,8,2,0,0,-99,39,4,-64,2,-102,-74,95,5,0,0,0,48,0,0,0,0,0,0,0,51,  // 42998',
+   '0,0,0,0,0,0,0,52,0,0,0,0,0,0,0,53,0,0,0,0,0,0,0,54,0,0,0,0,0,0,0,0,-67,49,0,8,7,0,0,-67,49,4,64,7,-102,-74,95,5,0,0,0,16,0,0,0,0,0,0,0,0,-123,56,0,8,  // 42999',
+   '9,0,0,-123,56,4,64,9,-101,-74,95,5,0,0,0,16,0,0,0,0,0,0,0,0,-59,79,-128,32,32,0,0,0,0,0,0,0,0,-59,79,-108,32,37,0,0,0,0,0,0,0,0,-59,79,-104,32,38,0,0,0,0,0,0,0,0,-59,  // 43000',
+   '79,-100,32,39,0,0,0,0,0,0,0,0,-91,108,0,8,3,0,0,-91,108,4,96,3,-86,-127,-107,44,127,0,0,24,0,0,0,0,0,0,0,43,0,0,0,0,0,0,0,0,-75,108,0,8,0,0,0,-75,108,4,96,0,-102,-74,95,5,  // 43001',
+   '0,0,0,24,0,0,0,0,0,0,0,45,0,0,0,0,0,0,0,0,-67,108,0,8,5,0,0,-67,108,4,64,5,114,5,54,-2,85,0,0,16,0,0,0,0,0,0,0,0,-51,108,0,8,1,0,0,-51,108,4,96,1,-102,-74,95,5,  // 43002',
-   '0,0,0,1,0,0,0,0,0,0,0,14,0,0,0,64,91,31,0,6,-71,2,5,24,66,66,4,4,8,95,4,73,33,11,15,0,-3,15,0,8,6,0,0,-3,15,4,96,6,-86,33,30,70,127,0,0,24,0,0,0,0,0,0,0,47,  // 42997',
-   '0,0,0,0,0,0,0,0,-107,26,0,8,8,0,0,-107,26,4,64,8,36,-106,100,5,0,0,0,16,0,0,0,0,0,0,0,0,-99,39,0,8,2,0,0,-99,39,4,-64,2,36,-106,100,5,0,0,0,48,0,0,0,0,0,0,0,51,  // 42998',
-   '0,0,0,0,0,0,0,52,0,0,0,0,0,0,0,53,0,0,0,0,0,0,0,54,0,0,0,0,0,0,0,0,-67,49,0,8,7,0,0,-67,49,4,64,7,36,-106,100,5,0,0,0,16,0,0,0,0,0,0,0,0,-123,56,0,8,  // 42999',
-   '9,0,0,-123,56,4,64,9,36,-106,100,5,0,0,0,16,0,0,0,0,0,0,0,0,-59,79,-128,32,32,0,0,0,0,0,0,0,0,-59,79,-108,32,37,0,0,0,0,0,0,0,0,-59,79,-104,32,38,0,0,0,0,0,0,0,0,-59,  // 43000',
-   '79,-100,32,39,0,0,0,0,0,0,0,0,-91,108,0,8,3,0,0,-91,108,4,96,3,-86,33,30,70,127,0,0,24,0,0,0,0,0,0,0,43,0,0,0,0,0,0,0,0,-75,108,0,8,0,0,0,-75,108,4,96,0,36,-106,100,5,  // 43001',
-   '0,0,0,24,0,0,0,0,0,0,0,45,0,0,0,0,0,0,0,0,-67,108,0,8,5,0,0,-67,108,4,64,5,-52,-33,6,76,86,0,0,16,0,0,0,0,0,0,0,0,-51,108,0,8,1,0,0,-51,108,4,96,1,36,-106,100,5,  // 43002',
    '0,0,0,24,0,0,0,0,0,0,0,57,0,0,0,0,0,0,0,11,10,10,10,10',
    '};',
    'static const int v8_snapshot_blob_size = 2752216;',
    'static const uint8_t vm_cache_data[] = {171,6,222,192,82,189,255,151,217,50,0,32,97,100,152,163,213,231,162,201,96,21,0,0,0,0,0,0,0,0,0,0,1,36,81,3,109,1,7,196,96,0,0,0,0,151,2,0,0,1,8,7,33,15,4,4,33,3,112,7,181,1,122,0,  // 0',
    '0,0,0,205,0,0,0,2,4,6,0,179,5,156,36,26,100,22,64,26,76,26,68,26,64,23,220,3,14,0,22,203,2,22,80,26,60,22,112,27,216,3,14,0,22,104,22,203,2,26,124,27,168,9,14,0,22,143,7,26,68,26,76,26,  // 1',

    at Object.<anonymous> (/node/test/parallel/test-snapshot-reproducible.js:47:8)
    at Module._compile (node:internal/modules/cjs/loader:1947:14)
    at Object..js (node:internal/modules/cjs/loader:2087:10)
    at Module.load (node:internal/modules/cjs/loader:1669:32)
    at Module._load (node:internal/modules/cjs/loader:1450:12)
    at wrapModuleLoad (node:internal/modules/cjs/loader:260:19)
    at Module.executeUserEntryPoint [as runMain] (node:internal/modules/run_main:154:5)
    at node:internal/main/run_main_module:33:47 {
  generatedMessage: true,
  code: 'ERR_ASSERTION',
  actual: [ <skipped> ],
  expected: [ <skipped> ],
  operator: 'deepStrictEqual',
  diff: 'simple'
}

Node.js v27.0.0-pre

Reproducible locally with gcc 15.3.0 and 16.1.1.
The byteranges that differ are randomized so the exact bytes are different each time. Everything else seems to be consistent.
Completely disabling ASLR (setting kernel/randomize_va_space to 0) makes the test pass. Conservative ASLR (1) still breaks it.

Not exactly sure when this started (maybe some of v8 upgrades?) nor whether it can be fixed (maybe on v8 side?) nor what else causes this (test passes on CI so i assume there's additional factor to it).

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with test/parallel/test-snapshot-reproducible.js, especially the assertion at line 47. Reproduce with ./configure && make and Linux ASLR set to 1 or 2, then compare the generated snapshot with ASLR disabled. Done means the failure is fixed or narrowed to a documented V8 or environment-specific cause with a clear next step.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, linux, node.js
Domain
operating-systems, testing-qa
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.