v24: discarded vm contexts cause OOM; possible V8 backport
Nessuno ha ancora preso questa issue.
- Lingua principale
- JavaScript
- Stelle
- 122k
- Fork
- 37.3k
- Merge medio
- 4g 2h
- PR unite (30g)
- 283
Descrizione
Version
v24.21.0
Platform
Linux x86_64, kernel 6.8.0-139-generic
Subsystem
vm, V8
What steps will reproduce the bug?
Save as repro.mjs; run node --max-old-space-size=128 repro.mjs.
import { runInNewContext } from "node:vm";
import { setImmediate } from "node:timers/promises";
const source = `
globalThis.payload = new Array(1_000_000).fill(0);
${Array.from({ length: 30 }, (_, index) => `
function work${index}(values) {
let result = 0;
for (let i = 0; i < values.length; ++i) {
result += Math.sqrt(values[i] * values[i] + ${index});
}
return result;
}
`).join("\n")}
const values = [1, 2, 3, 4, 5];
for (let i = 0; i < 1000; ++i) {
${Array.from({ length: 30 }, (_, index) => `work${index}(values);`).join("\n")}
}
`;
for (let i = 0; i < 100; ++i) {
runInNewContext(source + `\n// ${i}`);
await setImmediate();
}
console.log("Completed");
How often does it reproduce? Is there a required condition?
Repeatedly on v24.15.0, v24.16.0, and v24.21.0. Completes on v22.23.2, v26.8.2, or with --no-concurrent-recompilation on v24.
What is the expected behavior? Why is that the expected behavior?
Print Completed; discarded contexts should be collectible.
What do you see instead?
FATAL ERROR: Reached heap limit Allocation failed - JavaScript heap out of memory
Additional information
This surfaced in jsdom’s WPT runner with the default ~4 GB heap; the smaller limit makes this reproduction quick. Sampled heap retainers point through V8’s IdentityMapBase to realm prototypes, keeping entire windows alive.
Could V8’s “Stop collecting array and object prototypes” change be backported to v24? Its later thread-safety follow-up might also be relevant.
I haven't verified that those commits are the key ones, but it's worth trying.
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Direzione di ricerca
Inizia con repro.mjs ed eseguilo su v24 con --max-old-space-size=128, quindi confronta v22, v26 e v24 con --no-concurrent-recompilation. Analizza i retainer di IdentityMapBase e i due commit collegati di V8 per determinare se risolvono il problema dei contesti vm scartati. Il lavoro è completato quando la riproduzione stampa "Completed" senza esaurire l’heap e i contesti scartati possono essere raccolti.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- javascript, node.js
- Ambito
- backend
- Tipo di issue
- Bug
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Attiva
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 35/100