Version
main
Platform
Subsystem
ffi
What steps will reproduce the bug?
import ffi from 'node:ffi';
const dest = new ArrayBuffer(8);
const ptr = ffi.getRawPointer(dest);
// Real ArrayBuffer with a custom tag: rejected.
const real = new ArrayBuffer(4);
Object.defineProperty(real, Symbol.toStringTag, { value: 'Custom' });
try {
ffi.exportArrayBuffer(real, ptr, 8);
} catch (err) {
console.log('real:', err.code, err.message);
}
// Fake object tagged as ArrayBuffer: passes the JS check.
const fake = { [Symbol.toStringTag]: 'ArrayBuffer', byteLength: 4 };
try {
ffi.exportArrayBuffer(fake, ptr, 8);
} catch (err) {
console.log('fake:', err.code, err.message);
}
How often does it reproduce? Is there a required condition?
Always
What is the expected behavior? Why is that the expected behavior?
The arrayBuffer argument is documented as {ArrayBuffer}
Docs https://github.com/nodejs/node/blob/main/doc/api/ffi.md#ffiexportarraybufferarraybuffer-pointer-length
So the check should depend on whether the value really is an ArrayBuffer, not on its tag. A real ArrayBuffer should be copied.
The fake object should be rejected in JS with The "arrayBuffer" argument must be an instance of ArrayBuffer.
What do you see instead?
real: ERR_INVALID_ARG_TYPE The "arrayBuffer" argument must be an instance of ArrayBuffer. Received an instance of ArrayBuffer
fake: ERR_INVALID_ARG_TYPE The first argument must be a Buffer, ArrayBuffer, SharedArrayBuffer, or ArrayBufferView
Additional information
No response
Version
main
Platform
Subsystem
ffi
What steps will reproduce the bug?
How often does it reproduce? Is there a required condition?
Always
What is the expected behavior? Why is that the expected behavior?
The
arrayBufferargument is documented as{ArrayBuffer}Docs https://github.com/nodejs/node/blob/main/doc/api/ffi.md#ffiexportarraybufferarraybuffer-pointer-length
So the check should depend on whether the value really is an
ArrayBuffer, not on its tag. A realArrayBuffershould be copied.The fake object should be rejected in JS with
The "arrayBuffer" argument must be an instance of ArrayBuffer.What do you see instead?
Additional information
No response