Commit Detail
Commit 7c53dcb
Handle detached ArrayBuffers safely in Js buffer types* `JsArrayBuffer::asArrayPtr()`, `JsArrayBufferView::asArrayPtr()`, `JsUint8Array::asArrayPtr()`, and `JsBufferSource::asArrayPtr()` did not check for detached `ArrayBuffer`s. For `ArrayBufferView`-based types, a detached underlying buffer has `Data()` returning `nullptr` while `ByteOffset()` may still be non-zero, producing a dangling pointer (`nullptr + offset`). All `asArrayPtr()` implementations now check `WasDetached()` and return a 0-length `kj::ArrayPtr` for detached buffers. `JsBufferSource::size()` similarly returns 0 for detached buffers. Current call sites are safe in practice — user-provided buffers are consumed synchronously within the same C++ call frame as the JS-to-C++ type unwrap, with no intervening JS execution that could detach the buffer. The checks serve as defense-in-depth against future refactoring. Also moved `JsArrayBuffer::asArrayPtr()` out of the header into `jsvalue.c++`.
Files changed
3 files changed~3 modified