Sitelet https://github.com/libxmljs/libxmljs/pull/676
Skip to content

fix: add several type checks to prevent crashes and seg faults - #676

Open
theosotr wants to merge 1 commit into
libxmljs:masterfrom
theosotr:fix/type-errors
Open

theosotr wants to merge 1 commit into
libxmljs:masterfrom
theosotr:fix/type-errors

Conversation

@theosotr

Copy link
Copy Markdown

Several native entry points assume their JavaScript arguments have the
expected type. When called with a wrong-typed value, they
abort the entire Node.js process through a failed C++ assertion or a segmentation fault.
A single bad argument from JavaScript takes down the whole process,
with no chance for a try/catch or a rejected promise to intervene.

This PR adds a type check to each affected entry point so the operation raises
a TypeError instead of crashing. Valid usage is unchanged.

As an indicative example, the following code results in a hard crash.

const libxml = require("libxmljs");

// A caller passes a number where a string or Buffer is expected.
libxml.parseXmlAsync(42).catch((err) => console.error(err));
# Assertion failed: val->IsArrayBufferView()
# ...
Aborted (core dumped)

After this change the same call rejects with a TypeError
(fromBufferAsync: buffer must be a string or a Buffer), which the .catch
handles normally.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant