Commit Detail
Commit 7272ada
Check for isolate termination in iterating C++ callbacks (#6331) * Check for isolate termination in iterating C++ callbacks Root cause: When JS code uses Array.from() or spread on a C++ iterator (like the SQL cursor), V8's Torque builtin loops over .next() calls without JS back-edge interrupt checks. If TerminateExecution() is called (e.g. by the near-heap-limit callback when memory is exceeded), the termination request sits unprocessed in the stack guard, and the iterator keeps running, growing the heap until it hits the 4GB pointer compression cage limit and crashes. Three changes: 1. deps/workerd/src/workerd/jsg/setup.h -- Added requestTermination() / isTerminationRequested() flag on IsolateBase, checkable from C++ callbacks without relying on V8's internal interrupt processing. 2. deps/workerd/src/workerd/jsg/iterator.h + iterator.c++ -- nextImpl() checks isTerminationRequested() after each successful row and throws a JS exception if set. V8 sees the exception on the callback return path and stops the iteration. 3. src/edgeworker/scheduling/limit-enforcer-impl.c++ -- terminate() now calls requestTermination() alongside TerminateExecution(). Bug: EW-10621 * Format --------- Co-authored-by: Erik Corry <erikcorry@chromium.org>