Do not leak the old prototype in JS_AddIntrinsicDOMException() - #1642
Open
andreasrosdal wants to merge 2 commits into
Open
Do not leak the old prototype in JS_AddIntrinsicDOMException()#1642andreasrosdal wants to merge 2 commits into
andreasrosdal wants to merge 2 commits into
Conversation
JS_AddIntrinsicDOMException() overwrites ctx->class_proto[] with a plain assignment. The slot is initialised to JS_NULL by JS_NewContext(), so a single call is harmless, but a second call on the same context drops the reference to the prototype installed by the first one and leaks it. Use set_value(), like every other class_proto[] store in the file. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014mv33YvfHz7t9mmkituBnn
JS_NewContext() already installs DOMException through JS_AddIntrinsicAToB(), so a host that also calls JS_AddIntrinsicDOMException() installs it twice. The test installs it several more times and lets new_runtime()'s JS_ABORT_ON_LEAKS catch the prototype the old code dropped on the floor, then checks that the class prototype still matches the global constructor and that internally thrown DOMExceptions use it too. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01K6eRbuuuCujKgQkrHgvMrc
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
JS_AddIntrinsicDOMException()overwritesctx->class_proto[JS_CLASS_DOM_EXCEPTION]with a plain assignment. The slot is initialised toJS_NULLbyJS_NewContext(), so a single call is harmless, but a second call on the same context drops the reference to the prototype installed by the first one and leaks it.Use
set_value(), like every otherclass_proto[]store in the file.🤖 Generated with Claude Code
https://claude.ai/code/session_014mv33YvfHz7t9mmkituBnn
Generated by Claude Code