Skip to content

Do not leak the old prototype in JS_AddIntrinsicDOMException() - #1642

Open
andreasrosdal wants to merge 2 commits into
quickjs-ng:masterfrom
nordstjernen-web:fix-domexception-proto-leak
Open

Do not leak the old prototype in JS_AddIntrinsicDOMException()#1642
andreasrosdal wants to merge 2 commits into
quickjs-ng:masterfrom
nordstjernen-web:fix-domexception-proto-leak

Conversation

@andreasrosdal

Copy link
Copy Markdown
Contributor

JS_AddIntrinsicDOMException() overwrites ctx->class_proto[JS_CLASS_DOM_EXCEPTION] with a plain assignment. The slot is initialised to JS_NULL by JS_NewContext(), so a single call is harmless, but a second call on the same context drops the reference to the prototype installed by the first one and leaks it.

Use set_value(), like every other class_proto[] store in the file.

🤖 Generated with Claude Code

https://claude.ai/code/session_014mv33YvfHz7t9mmkituBnn


Generated by Claude Code

claude added 2 commits August 6, 2026 17:06
JS_AddIntrinsicDOMException() overwrites ctx->class_proto[] with a plain
assignment. The slot is initialised to JS_NULL by JS_NewContext(), so a
single call is harmless, but a second call on the same context drops the
reference to the prototype installed by the first one and leaks it.

Use set_value(), like every other class_proto[] store in the file.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014mv33YvfHz7t9mmkituBnn
JS_NewContext() already installs DOMException through JS_AddIntrinsicAToB(),
so a host that also calls JS_AddIntrinsicDOMException() installs it twice.
The test installs it several more times and lets new_runtime()'s
JS_ABORT_ON_LEAKS catch the prototype the old code dropped on the floor,
then checks that the class prototype still matches the global constructor
and that internally thrown DOMExceptions use it too.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01K6eRbuuuCujKgQkrHgvMrc
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants