Skip to content

Array.from incorrectly converts the value before rejecting an out-of-range TypedArray index #1123

Description

@d01c2

Version: GraalVM JavaScript (Oracle GraalVM Native 25.3.4.1), installed via jsvu
OS: macOS Golden Gate 27.0
Architecture: ARM64

What steps will reproduce the problem?

Running the following JavaScript program reproduces the problem:

// sample.js
var value = { valueOf() { throw new Error("value converted"); } };
Array.from.call(function () { return new Uint8Array(0); }, [value]);

What is the expected output?

A TypeError is expected, because index 0 is not valid for a TypedArray of length 0, and valueOf is never called.

What do you see instead?

valueOf is called, and Error: value converted is thrown.

$ graaljs sample.js
Error: value converted


$ v8 sample.js
TypeError: Cannot redefine property: 0

Additional information:

Array.from stores each element with CreateDataPropertyOrThrow, which calls the TypedArray's [[DefineOwnProperty]]. Its first step for a numeric key is "If IsValidIntegerIndex (O, numericIndex) is false, return false", so CreateDataPropertyOrThrow throws a TypeError. Only a valid index reaches TypedArraySetElement, where the value is converted with ToNumber or ToBigInt.

GraalJS converts the value first. The same happens in Array.of and Array.prototype.concat with a TypedArray species, and for every element type. With a BigInt64Array the wrong error is also visible without a valueOf:

Array.from.call(function () { return new BigInt64Array(0); }, ["aa"]);
// SyntaxError: Cannot convert aa to a BigInt.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions