Skip to content

Commit

Permalink
src: prevent changing FunctionTemplateInfo after publish
Browse files Browse the repository at this point in the history
Refs https://chromium-review.googlesource.com/c/v8/v8/+/2718147

Fixes an issue where Node.js tries to call SetClassName on a
FunctionTemplate twice in some cases. The above CL made it so that
V8 CHECKs when this occurs. It is fixed by ensuring SetClassName
is only called once.
  • Loading branch information
codebytere committed Mar 16, 2023
1 parent 8713c83 commit 91290c4
Show file tree
Hide file tree
Showing 2 changed files with 9 additions and 5 deletions.
7 changes: 4 additions & 3 deletions src/histogram.cc
Original file line number Diff line number Diff line change
Expand Up @@ -344,9 +344,9 @@ void HistogramBase::RegisterExternalReferences(
void HistogramBase::Initialize(IsolateData* isolate_data,
Local<ObjectTemplate> target) {
SetConstructorFunction(isolate_data->isolate(),
target,
"Histogram",
GetConstructorTemplate(isolate_data));
target, "Histogram",
GetConstructorTemplate(isolate_data),
SetConstructorFunctionFlag::NONE);
}

BaseObjectPtr<BaseObject> HistogramBase::HistogramTransferData::Deserialize(
Expand All @@ -372,6 +372,7 @@ Local<FunctionTemplate> IntervalHistogram::GetConstructorTemplate(
Isolate* isolate = env->isolate();
tmpl = NewFunctionTemplate(isolate, nullptr);
tmpl->Inherit(HandleWrap::GetConstructorTemplate(env));
tmpl->SetClassName(OneByteString(isolate, "Histogram"));
tmpl->InstanceTemplate()->SetInternalFieldCount(
HistogramBase::kInternalFieldCount);
SetProtoMethodNoSideEffect(isolate, tmpl, "count", GetCount);
Expand Down
7 changes: 5 additions & 2 deletions src/node_messaging.cc
Original file line number Diff line number Diff line change
Expand Up @@ -1495,13 +1495,16 @@ static void InitMessaging(Local<Object> target,
t->Inherit(BaseObject::GetConstructorTemplate(env));
t->InstanceTemplate()->SetInternalFieldCount(
JSTransferable::kInternalFieldCount);
SetConstructorFunction(context, target, "JSTransferable", t);
t->SetClassName(OneByteString(isolate, "JSTransferable"));
SetConstructorFunction(context, target, "JSTransferable", t,
SetConstructorFunctionFlag::NONE);
}

SetConstructorFunction(context,
target,
env->message_port_constructor_string(),
GetMessagePortConstructorTemplate(env));
GetMessagePortConstructorTemplate(env),
SetConstructorFunctionFlag::NONE);

// These are not methods on the MessagePort prototype, because
// the browser equivalents do not provide them.
Expand Down

0 comments on commit 91290c4

Please sign in to comment.