Skip to content

TypedArray slice, subarray, filter and map incorrectly accept a species constructor with a different content type #1125

Description

@d01c2

Version: GraalVM JavaScript (Oracle GraalVM Native 25.3.4.1), installed via jsvu
OS: macOS Golden Gate 27.0
Architecture: ARM64

What steps will reproduce the problem?

Running the following JavaScript program reproduces the problem:

// sample1.js
var ta = new Float64Array(0);
ta.constructor = BigInt64Array;
print(ta.slice(0).constructor.name);

What is the expected output?

A TypeError is expected, because a BigInt64Array holds BigInts and a Float64Array holds Numbers.

What do you see instead?

A BigInt64Array is returned.

$ graaljs sample1.js
BigInt64Array

$ jsc sample1.js
Exception: TypeError: Content types of source and created typed arrays are different

Additional information:

%TypedArray%.prototype.slice creates its result with TypedArraySpeciesCreate, whose step 4 is "If result.[[ContentType]] is not exemplar.[[ContentType]], throw a TypeError exception". subarray, filter and map use the same operation, and all four return a BigInt64Array here.

With a non-empty source, subarray returns a view that reads the Float64 bytes as a BigInt:

// sample2.js
var ta = new Float64Array([1.5]);
ta.constructor = BigInt64Array;
print(ta.subarray(0)[0]);
print(ta.map(x => 1n)[0]);
$ graaljs sample2.js
4609434218613702656
1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions