Skip to content
Commit Detail

Commit 7272ada

Author
Erik Corry <ecorry@cloudflare.com> 2026-03-16 21:20:37 +0100
Parents
bc0bc2a
Tree
767b1ea
Check for isolate termination in iterating C++ callbacks (#6331)

* Check for isolate termination in iterating C++ callbacks

Root cause: When JS code uses Array.from() or spread on a C++ iterator (like
the SQL cursor), V8's Torque builtin loops over .next() calls without JS
back-edge interrupt checks. If TerminateExecution() is called (e.g. by the
near-heap-limit callback when memory is exceeded), the termination request sits
unprocessed in the stack guard, and the iterator keeps running, growing the
heap until it hits the 4GB pointer compression cage limit and crashes.

Three changes:

1. deps/workerd/src/workerd/jsg/setup.h -- Added requestTermination() /
isTerminationRequested() flag on IsolateBase, checkable from C++ callbacks
without relying on V8's internal interrupt processing.

2. deps/workerd/src/workerd/jsg/iterator.h + iterator.c++ -- nextImpl() checks
isTerminationRequested() after each successful row and throws a JS exception if
set. V8 sees the exception on the callback return path and stops the iteration.

3. src/edgeworker/scheduling/limit-enforcer-impl.c++ -- terminate() now calls
requestTermination() alongside TerminateExecution().

Bug: EW-10621

* Format

---------

Co-authored-by: Erik Corry <erikcorry@chromium.org>

Files changed

5 files changed~5 modified