nodejs / nodejs/node

diagnostics_channel: Channel::binding_data_ dangles after environment cleanup, crashing node:sqlite at exit

未关闭
#65,858 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

主要语言
JavaScript
星标
122k
派生
37.4k
平均合并
4 天 3 小时
30 天内合并 PR
272

描述

Version

v27.0.0-pre (2dfdb6a4206)

Platform
Darwin 25.6.0 arm64
Subsystem

diagnostics_channel, sqlite

What steps will reproduce the bug?

Channel holds its BindingData as a raw pointer that is never cleared, so any native holder that outlives environment cleanup reads a destroyed object. Here's a replication case using node:sqlite:

const dc = require('node:diagnostics_channel');
const { DatabaseSync } = require('node:sqlite');

dc.subscribe('sqlite.db.query', () => {});

const db = new DatabaseSync(':memory:');
db.exec('CREATE TABLE t(x)');
const ins = db.prepare('INSERT INTO t VALUES (?)');
for (let i = 0; i < 200; i++) ins.run(i);

// Start iterating and abandon it: the statement stays mid-step, so the
// finalize that happens at teardown fires SQLite's profile callback.
const it = db.prepare('SELECT * FROM t').iterate();
it.next();
globalThis.keepAlive = { db, it };
console.log('reached end of script');
How often does it reproduce? Is there a required condition?

Three conditions are required (all included in the example above):

  1. A subscriber on sqlite.db.query, so the SQLite profile hook is installed.
  2. A statement left mid-step at exit, so that the finalize during teardown has a started statement to profile.
  3. No explicit close(), so the statement is finalized by the destructor chain after Environment::RunCleanup() rather than before it.
What is the expected behavior? Why is that the expected behavior?

Exiting a process that used node:sqlite with a sqlite.db.query subscriber
shouldn't crash.

What do you see instead?

SIGSEGV, exit 139, after the script has finished.

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

先运行提供的 node:diagnostics_channel 和 node:sqlite 复现,然后通过 Environment::RunCleanup() 和 SQLite profile 回调跟踪 Channel::binding_data_。使用相同的退出场景确认修复,包括一个未显式调用 close() 而停留在步骤中途的语句,并确保进程在没有 SIGSEGV 的情况下退出。

由索引模型根据 Issue 内容生成。

评估

技术栈
javascript, node.js, sqlite
领域
backend, databases, observability
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
活跃
描述清晰度
基本清楚
新手友好度
48/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。