Skip to content

Validate RE2 instance before unwrapping - #286

Merged
uhop merged 1 commit into
uhop:masterfrom
theosotr:fix/validate-re2-instance-before-unwrap
Sep 26, 2026
Merged

uhop merged 1 commit into
uhop:masterfrom
theosotr:fix/validate-re2-instance-before-unwrap

Conversation

@theosotr

Copy link
Copy Markdown
Contributor

fixes #285

@uhop uhop self-assigned this Sep 26, 2026
@uhop

uhop commented Sep 26, 2026

Copy link
Copy Markdown
Owner

Thank you for the report and the fix!

I reproduced it: on Node 26 new RE2(new RE2.Set(['abc'])) segfaults, and so does any other natively wrapped object, like a MessagePort or a v8.Serializer. Your change is the right one: WrappedRE2::HasInstance() is how the rest of the addon already checks its receivers, and this was the one place that relied on InternalFieldCount().

For the record, I treat this as a usage error, not a vulnerability. The TypeScript definitions reject new RE2(set) (TS2769), so a modern IDE flags it before it runs. Still, an answer to a wrong argument should be a TypeError not a crash.

I'm merging it as is. I'll add regression tests separately, and the fix will go out with the next release.

@uhop
uhop merged commit bc52fac into uhop:master Sep 26, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

new RE2(re2SetInstance) aborts the process: InternalFieldCount() > 0 lets an RE2.Set be unwrapped as a WrappedRE2

2 participants