react / react/react-native

MessageQueue resolves inherited Object properties as callable modules

Open Beginner friendly
#58,198 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Needs: Author Feedback Needs: Repro
Dominant language
C++
Stars
127k
Forks
25.3k
Avg merge
1d 23h
Merged PRs (30d)
4

Description

Description

The legacy bridge stores lazy callable-module initializers in an ordinary object and reads it by arbitrary module name. Unregistered names such as constructor and __proto__ therefore resolve through Object.prototype; getCallableModule('constructor') invokes the inherited constructor and returns an object although no module was registered. Assigning __proto__ also changes the registry prototype instead of creating a normal module entry.

Expected behavior

Only explicitly registered callable modules should resolve, and every valid string name—including __proto__—should be registrable.

React Native Version

0.87.1 and current main

Affected Platforms

Runtime - All

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the legacy bridge's MessageQueue registry and the getCallableModule entry point. Check how arbitrary names are looked up and assigned, then verify that unregistered names do not resolve through Object.prototype and that every valid string name, including proto, can be registered and retrieved.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, react-native
Domain
mobile
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
70/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.