Skip to content
Closed
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
build: enable the V8 sandbox in shared-cage builds
V8 defaults `v8_enable_sandbox` to on whenever the shared pointer
compression cage and the external code space are enabled, and that is
the configuration embedders that use the sandbox build with. Now that
the sandbox builds and passes the tests, follow that default for
`--experimental-pointer-compression-shared-cage` so the configuration
is reachable from `configure`. Multi-cage pointer compression builds
stay without it: there every IsolateGroup gets its own sandbox, and
`NodeArrayBufferAllocator` always allocates from the default one.

Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
  • Loading branch information
codebytere committed Sep 5, 2026
commit 5e897639a5102dec6688f361d15a6dd06fa7a6bf
16 changes: 5 additions & 11 deletions configure.py
Original file line number Diff line number Diff line change
Expand Up @@ -872,7 +872,7 @@
action='store_true',
dest='pointer_compression_shared_cage',
default=None,
help='[Experimental] Use V8 pointer compression with shared cage (requires --experimental-enable-pointer-compression)')
help='[Experimental] Use V8 pointer compression with a shared cage and enable the V8 sandbox (requires --experimental-enable-pointer-compression)')

parser.add_argument('--v8-options',
action='store',
Expand Down Expand Up @@ -2214,16 +2214,10 @@ def configure_v8(o, configs):
flavor not in ('aix', 'os400', 'zos') and
o['variables']['target_arch'] in maglev_enabled_architectures)
o['variables']['v8_enable_pointer_compression'] = 1 if options.enable_pointer_compression else 0
# Using the sandbox requires always allocating array buffer backing stores in the sandbox.
# We currently have many backing stores tied to pointers from C++ land that are not
# even necessarily dynamic (e.g. in static storage) for fast communication between JS and C++.
# Until we manage to get rid of all those, v8_enable_sandbox cannot be used.
# Note that enabling pointer compression without enabling sandbox is unsupported by V8,
# so this can be broken at any time.
o['variables']['v8_enable_sandbox'] = 0
# We set v8_enable_pointer_compression_shared_cage to 0 always, even when
# pointer compression is enabled so that we don't accidentally enable shared
# cage mode when pointer compression is on.
# Like V8's own default, the sandbox goes with the shared pointer compression
# cage. Multi-cage builds give every IsolateGroup its own sandbox, which the
# array buffer allocator does not know about yet.
o['variables']['v8_enable_sandbox'] = 1 if options.pointer_compression_shared_cage else 0
o['variables']['v8_enable_pointer_compression_shared_cage'] = 1 if options.pointer_compression_shared_cage else 0
o['variables']['v8_enable_external_code_space'] = 1 if options.enable_pointer_compression else 0
o['variables']['v8_enable_31bit_smis_on_64bit_arch'] = 1 if options.enable_pointer_compression else 0
Expand Down
Loading