Skip to content
Commit Detail

Commit 7c53dcb

Author
James M Snell <jsnell@cloudflare.com> 2026-03-16 19:48:19 -0700
Parents
876efe8
Tree
824acdc
Handle detached ArrayBuffers safely in Js buffer types*

`JsArrayBuffer::asArrayPtr()`, `JsArrayBufferView::asArrayPtr()`,
`JsUint8Array::asArrayPtr()`, and `JsBufferSource::asArrayPtr()` did
not check for detached `ArrayBuffer`s. For `ArrayBufferView`-based types,
a detached underlying buffer has `Data()` returning `nullptr` while
`ByteOffset()` may still be non-zero, producing a dangling pointer
(`nullptr + offset`).

All `asArrayPtr()` implementations now check `WasDetached()` and
return a 0-length `kj::ArrayPtr` for detached buffers.
`JsBufferSource::size()` similarly returns 0 for detached buffers.

Current call sites are safe in practice — user-provided buffers are
consumed synchronously within the same C++ call frame as the JS-to-C++
type unwrap, with no intervening JS execution that could detach the
buffer. The checks serve as defense-in-depth against future
refactoring.

Also moved `JsArrayBuffer::asArrayPtr()` out of the header into
`jsvalue.c++`.

Files changed

3 files changed~3 modified