nodejs / nodejs/node

Worker with large inline source map aborts process in V8 HandleDebugMagicComments

未关闭
#64,155 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

v8 engine
主要语言
JavaScript
星标
122k
派生
37.3k
平均合并
4 天 2 小时
30 天内合并 PR
283

描述

Version

v26.4.0

Platform
macOS 15.x arm64
Subsystem

worker_threads

What steps will reproduce the bug?

Create a worker entry file with a small amount of executable JavaScript and a very large inline sourceMappingURL=data:... comment, then load it in a worker with a constrained heap.

Minimal repro:

const fs = require("node:fs");
const os = require("node:os");
const path = require("node:path");
const { Worker } = require("node:worker_threads");

const dir = fs.mkdtempSync(path.join(os.tmpdir(), "node-inline-sourcemap-oom-"));

const workerPath = path.join(dir, "worker.cjs");

const source = [
  'const { parentPort } = require("node:worker_threads");',
  'parentPort.postMessage("loaded");',
  'parentPort.close();',
  "",
  "//# sourceMappingURL=data:application/json;base64,",
  "A".repeat(64 * 1024 * 1024),
  "",
].join("\n");

fs.writeFileSync(workerPath, source);

const worker = new Worker(workerPath, {
  resourceLimits: {
    maxOldGenerationSizeMb: 16,
  },
});

worker.on("message", console.log);

worker.on("error", console.error);

worker.on("exit", (code) => {
  console.log("exit", code);
  fs.rmSync(dir, { recursive: true, force: true });
});

Run: node repro.js

How often does it reproduce? Is there a required condition?

It reproduces consistently when the inline sourcemap comment is large enough relative to the worker heap limit.

For comparison, these do not reproduce the same fatal abort:

  1. Keeping the same large payload in an external worker.cjs.map file and using //# sourceMappingURL=worker.cjs.map.
  2. Putting a similarly large payload in a normal non-sourceMappingURL comment.
What is the expected behavior? Why is that the expected behavior?

The worker should fail gracefully, for example by emitting an error event or exiting with a worker failure, without aborting the entire Node.js process.

Ideally, parsing sourceMappingURL / debug magic comments should not internalize an arbitrarily large data URL into V8 old space during module compilation.

What do you see instead?

The whole Node process aborts with an out-of-memory fatal error before the worker can load the module.

Example stack from Node v26.4.0:

FATAL ERROR: CALL_AND_RETRY_LAST Allocation failed - JavaScript heap out of memory
...
v8::internal::FactoryBase<v8::internal::Factory>::AllocateRawOneByteInternalizedString
v8::internal::FactoryBase<v8::internal::Factory>::NewOneByteInternalizedString
v8::internal::StringTable::LookupKey
v8::internal::FactoryBase<v8::internal::Factory>::InternalizeString
void v8::internal::Parser::HandleDebugMagicComments
v8::internal::Parser::ParseProgram
v8::internal::parsing::ParseProgram
v8::internal::Compiler::GetWrappedFunction
v8::ScriptCompiler::CompileFunction
node::contextify::CompileFunctionForCJSLoader
node::worker::Worker::Run
Additional information

No response

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从提供的 repro.js 和经过 V8's Parser::HandleDebugMagicComments 的堆栈开始,然后在 worker 堆限制下比较内联和外部 source map。通过 node::worker::Worker::Run 跟踪 worker 入口,并确定致命分配发生的位置。完成的标准是 repro 不再中止 Node.js 进程,并且 worker 能够正常报告失败。

由索引模型根据 Issue 内容生成。

评估

技术栈
javascript
领域
backend
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
冷清
描述清晰度
基本清楚
新手友好度
42/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。