Claude Bot 79653b6148 Add defensive exception handling for toString conversions during error formatting
Fixes a JSCell assertion failure that occurs when calling process.nextTick()
inside a recursive method that hits the JavaScript stack limit.

The bug manifests as:
  ASSERTION FAILED: isSymbol() || isHeapBigInt()
  vendor/WebKit/Source/JavaScriptCore/runtime/JSCell.cpp(252) :
  JSString *JSC::JSCell::toStringSlowCase(JSGlobalObject *) const

Minimal reproducer:
```javascript
const obj = {
  o() {
    try { this.o(); } catch (e) {}  // Recurse until stack overflow
    try { process.nextTick(() => {}); } catch (e) {}
  },
};
obj.o();
```

Root Cause Analysis:
When a stack overflow exception occurs and process.nextTick() is subsequently
called, the error formatting code attempts to generate a stack trace. During
this process, toString() methods are called on JSCell objects to extract
function names and source URLs. However, after a stack overflow, some of
these JSCell references may be in an invalid state, causing the assertion
to fail when toStringSlowCase() is called on a cell that is neither a
Symbol nor a HeapBigInt.

Changes Made:
1. **ZigException.cpp**: Added exception checking after all toWTFString()
   calls in exceptionFromString() to handle cases where string conversion
   fails.

2. **ErrorStackTrace.cpp**: Modified functionName() to use jsDynamicCast
   for safer type checking and added immediate exception handling after
   JSString::value() calls.

3. **CallSite.cpp**: Added comprehensive exception handling in
   formatAsString() after toStringOrNull() and getString() calls to
   prevent crashes when formatting corrupted call sites.

4. **Test**: Added regression test (marked as .todo) documenting the
   issue and expected behavior.

Status:
These changes improve error handling robustness and prevent some crashes,
but do not fully resolve the underlying memory corruption issue. The root
cause appears to be that stack overflow exceptions can leave JSCell objects
in an invalid state that persists into subsequent operations.

Further investigation is needed into:
- How JSC handles stack overflow exceptions
- Whether additional GC safepoints are needed before nextTick operations
- If stack trace generation should be skipped or simplified when the VM
  is in a corrupted state

Partial fix for the reported assertion failure. The defensive checks prevent
some crashes but the test remains marked as .todo pending a complete solution.
2025-10-22 08:12:53 +00:00
2025-10-13 14:25:37 -07:00
2025-10-07 20:08:57 -07:00
2025-10-15 13:25:28 -07:00
2024-12-26 11:48:30 -08:00
2024-12-12 03:21:56 -08:00
2025-10-05 04:28:25 -07:00
2025-01-07 20:19:12 -08:00
2025-10-19 18:45:54 -07:00
2025-10-10 14:13:34 -07:00
2025-10-10 14:13:34 -07:00
2025-07-10 00:10:43 -07:00
2025-07-10 00:10:43 -07:00

Logo

Bun

stars Bun speed

Documentation   •   Discord   •   Issues   •   Roadmap

Read the docs →

What is Bun?

Bun is an all-in-one toolkit for JavaScript and TypeScript apps. It ships as a single executable called bun.

At its core is the Bun runtime, a fast JavaScript runtime designed as a drop-in replacement for Node.js. It's written in Zig and powered by JavaScriptCore under the hood, dramatically reducing startup times and memory usage.

bun run index.tsx             # TS and JSX supported out-of-the-box

The bun command-line tool also implements a test runner, script runner, and Node.js-compatible package manager. Instead of 1,000 node_modules for development, you only need bun. Bun's built-in tools are significantly faster than existing options and usable in existing Node.js projects with little to no changes.

bun test                      # run tests
bun run start                 # run the `start` script in `package.json`
bun install <pkg>             # install a package
bunx cowsay 'Hello, world!'   # execute a package

Install

Bun supports Linux (x64 & arm64), macOS (x64 & Apple Silicon) and Windows (x64).

Linux users — Kernel version 5.6 or higher is strongly recommended, but the minimum is 5.1.

x64 users — if you see "illegal instruction" or similar errors, check our CPU requirements

# with install script (recommended)
curl -fsSL https://bun.com/install | bash

# on windows
powershell -c "irm bun.com/install.ps1 | iex"

# with npm
npm install -g bun

# with Homebrew
brew tap oven-sh/bun
brew install bun

# with Docker
docker pull oven/bun
docker run --rm --init --ulimit memlock=-1:-1 oven/bun

Upgrade

To upgrade to the latest version of Bun, run:

bun upgrade

Bun automatically releases a canary build on every commit to main. To upgrade to the latest canary build, run:

bun upgrade --canary

View canary build

Guides

Contributing

Refer to the Project > Contributing guide to start contributing to Bun.

License

Refer to the Project > License page for information about Bun's licensing.

Description
Bun is a fast, incrementally adoptable all-in-one JavaScript, TypeScript & JSX toolkit. Use individual tools like bun test or bun install in Node.js projects, or adopt the complete stack with a fast JavaScript runtime, bundler, test runner, and package manager built in. Bun aims for 100% Node.js compatibility.
Readme 843 MiB
Languages
Zig 60.6%
C++ 24.8%
TypeScript 8.3%
C 3.3%
JavaScript 1.4%
Other 1.1%