镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

ffi reuses mutated temporary string buffer without restoring its contents #65050

Description

@trivikr

Version

main

Platform

macOS 26.6.0

Subsystem

ffi

What steps will reproduce the bug?

repro.c

#include <stddef.h>
#include <string.h>

char* overwrite(char* string, int byte, size_t count) {
  return memset(string, byte, count);
}

repro.js

import { DynamicLibrary, suffix, toString } from 'node:ffi';

const lib = new DynamicLibrary(`./repro.${suffix}`);
const overwrite = lib.getFunction('overwrite', {
  arguments: ['string', 'i32', 'u64'],
  return: 'pointer',
});

console.log(toString(overwrite('hello', 0x79, 1n))); // "yello"
console.log(toString(overwrite('hello', 0, 0n))); // "yello"; expected "hello"

lib.close();

Run commands

$ cc -dynamiclib -o repro.dylib repro.c
$ node --experimental-ffi repro.js

How often does it reproduce? Is there a required condition?

Always

What is the expected behavior? Why is that the expected behavior?

yello
hello

each call should populate temporary storage from the supplied JavaScript string, so reusing "hello" should produce "hello".

What do you see instead?

yello
yello

the second call receives "yello" because the cached temporary buffer retains the native mutation from the first call.

Additional information

No response

Activity

  1. self-assigned this
    on Aug 5, 2026
  2. added
    ffiIssues and PRs related to experimental Foreign Function Interface support.
    on Aug 5, 2026
  3. trivikr commented on Aug 11, 2026

    @trivikr
    MemberAuthor

    The minimal repro is partially correct above. It should not return a pointer, but the observed byte by value.

    repro.c

    #include <stddef.h>
    #include <string.h>
    
    char overwrite(char* str, int byte, size_t count) {
      memset(str, byte, count);
      return str[0];
    }

    repro.js

    import { DynamicLibrary, suffix, toString } from 'node:ffi';
    
    const lib = new DynamicLibrary(`./repro.${suffix}`);
    const overwrite = lib.getFunction('overwrite', {
      arguments: ['string', 'i32', 'u64'],
      return: 'char',
    });
    
    console.log(String.fromCharCode(overwrite('hello', 0x79, 1n))); // "y"
    console.log(String.fromCharCode(overwrite('hello', 0, 0n))); // "y"; expected "h"
    
    lib.close();

    This was observed during implementation in #65051 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

ffiIssues and PRs related to experimental Foreign Function Interface support.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions