MessageQueue resolves inherited Object properties as callable modules
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 127k
- Forks
- 25.3k
- Avg merge
- 1d 23h
- Merged PRs (30d)
- 4
Description
Description
The legacy bridge stores lazy callable-module initializers in an ordinary object and reads it by arbitrary module name. Unregistered names such as constructor and __proto__ therefore resolve through Object.prototype; getCallableModule('constructor') invokes the inherited constructor and returns an object although no module was registered. Assigning __proto__ also changes the registry prototype instead of creating a normal module entry.
Expected behavior
Only explicitly registered callable modules should resolve, and every valid string name—including __proto__—should be registrable.
React Native Version
0.87.1 and current main
Affected Platforms
Runtime - All
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at the legacy bridge's MessageQueue registry and the getCallableModule entry point. Check how arbitrary names are looked up and assigned, then verify that unregistered names do not resolve through Object.prototype and that every valid string name, including proto, can be registered and retrieved.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, react-native
- Domain
- mobile
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 70/100