Skip to content

diagnostics_channel: Channel::binding_data_ dangles after environment cleanup, crashing node:sqlite at exit #65858

Description

@TrevorBurnham

Version

v27.0.0-pre (2dfdb6a4206)

Platform

Darwin 25.6.0 arm64

Subsystem

diagnostics_channel, sqlite

What steps will reproduce the bug?

Channel holds its BindingData as a raw pointer that is never cleared, so any native holder that outlives environment cleanup reads a destroyed object. Here's a replication case using node:sqlite:

const dc = require('node:diagnostics_channel');
const { DatabaseSync } = require('node:sqlite');

dc.subscribe('sqlite.db.query', () => {});

const db = new DatabaseSync(':memory:');
db.exec('CREATE TABLE t(x)');
const ins = db.prepare('INSERT INTO t VALUES (?)');
for (let i = 0; i < 200; i++) ins.run(i);

// Start iterating and abandon it: the statement stays mid-step, so the
// finalize that happens at teardown fires SQLite's profile callback.
const it = db.prepare('SELECT * FROM t').iterate();
it.next();
globalThis.keepAlive = { db, it };
console.log('reached end of script');

How often does it reproduce? Is there a required condition?

Three conditions are required (all included in the example above):

  1. A subscriber on sqlite.db.query, so the SQLite profile hook is installed.
  2. A statement left mid-step at exit, so that the finalize during teardown has a started statement to profile.
  3. No explicit close(), so the statement is finalized by the destructor chain after Environment::RunCleanup() rather than before it.

What is the expected behavior? Why is that the expected behavior?

Exiting a process that used node:sqlite with a sqlite.db.query subscriber
shouldn't crash.

What do you see instead?

SIGSEGV, exit 139, after the script has finished.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions