Skip to content

ffi: exportArrayBuffer type check is fooled by Symbol.toStringTag #66454

Description

@trivikr

Version

main

Platform

macOS 26.7.1

Subsystem

ffi

What steps will reproduce the bug?

import ffi from 'node:ffi';

const dest = new ArrayBuffer(8);
const ptr = ffi.getRawPointer(dest);

// Real ArrayBuffer with a custom tag: rejected.
const real = new ArrayBuffer(4);
Object.defineProperty(real, Symbol.toStringTag, { value: 'Custom' });
try {
  ffi.exportArrayBuffer(real, ptr, 8);
} catch (err) {
  console.log('real:', err.code, err.message);
}

// Fake object tagged as ArrayBuffer: passes the JS check.
const fake = { [Symbol.toStringTag]: 'ArrayBuffer', byteLength: 4 };
try {
  ffi.exportArrayBuffer(fake, ptr, 8);
} catch (err) {
  console.log('fake:', err.code, err.message);
}

How often does it reproduce? Is there a required condition?

Always

What is the expected behavior? Why is that the expected behavior?

The arrayBuffer argument is documented as {ArrayBuffer}
Docs https://github.com/nodejs/node/blob/main/doc/api/ffi.md#ffiexportarraybufferarraybuffer-pointer-length

So the check should depend on whether the value really is an ArrayBuffer, not on its tag. A real ArrayBuffer should be copied.
The fake object should be rejected in JS with The "arrayBuffer" argument must be an instance of ArrayBuffer.

What do you see instead?

real: ERR_INVALID_ARG_TYPE The "arrayBuffer" argument must be an instance of ArrayBuffer. Received an instance of ArrayBuffer
fake: ERR_INVALID_ARG_TYPE The first argument must be a Buffer, ArrayBuffer, SharedArrayBuffer, or ArrayBufferView

Additional information

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ffiIssues and PRs related to experimental Foreign Function Interface support.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions