Skip to content

fs: fix crash on negative zero file descriptor - #65888

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
christianaurichzm:fs-negative-zero-fd
Sep 26, 2026
Merged

nodejs-github-bot merged 1 commit into
nodejs:mainfrom
christianaurichzm:fs-negative-zero-fd

Conversation

@christianaurichzm

Copy link
Copy Markdown
Contributor

fs.writeFileSync(-0, '') and fs.appendFileSync(-0, '') currently abort in the utf8 fast path. I also found the same issue with fs.readFileSync(-0, 'utf8').

The JS side treats -0 as an int32 file descriptor, but V8 does not report -0 as an Int32 in the binding. The binding then takes it for a path and hits the null check.

This normalizes -0 to 0 before entering the binding, matching the existing fs behavior for negative-zero file descriptors.

Tests were added to test/parallel/test-fs-negative-zero.js.

Fixes: #65886

`isInt32()` accepts -0 because `-0 === (-0 | 0)`, but V8 does not
represent -0 as an Int32 value, so `Value::IsInt32()` rejects it. The
utf8 fast paths of `readFileSync()` and `writeFileSync()` hand the value
straight to the binding, which then took it for a path and aborted on
the null check.

Coerce -0 to 0 before the call, matching `getValidatedFd()` and the rest
of fs, where -0 is a valid way to name file descriptor 0.

Signed-off-by: Christian Aurich <christian.aurichzm@gmail.com>
@nodejs-github-bot nodejs-github-bot added fs Issues and PRs related to file-system APIs and the fs module. needs-ci PRs that need a full CI run. labels Sep 7, 2026
@codecov

codecov Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.18%. Comparing base (b113d09) to head (c4cc7a9).
⚠️ Report is 399 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #65888      +/-   ##
==========================================
+ Coverage   90.16%   90.18%   +0.02%     
==========================================
  Files         771      771              
  Lines      265094   265102       +8     
  Branches    50355    50364       +9     
==========================================
+ Hits       239027   239091      +64     
+ Misses      17011    16963      -48     
+ Partials     9056     9048       -8     
Files with missing lines Coverage Δ
lib/fs.js 97.31% <100.00%> (+<0.01%) ⬆️

... and 32 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@meixg meixg added the request-ci Add this label to start a Jenkins CI on a PR. Only starts once the PR has an approving review. label Sep 8, 2026
@github-actions github-actions Bot removed the request-ci Add this label to start a Jenkins CI on a PR. Only starts once the PR has an approving review. label Sep 8, 2026
@nodejs-github-bot

This comment has been minimized.

@hamidrezaghavami hamidrezaghavami left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

By using process.platform !== 'win32', we guarantee it won't throw a "not defined" error, and the tests will continue running perfectly on all the Linux and Mac machines where they already passed!

Comment thread test/parallel/test-fs-negative-zero.js
Comment thread test/parallel/test-fs-negative-zero.js
@christianaurichzm

Copy link
Copy Markdown
Contributor Author

@meixg, could you please rerun CI here when you have a chance? The previous failures appear to be unrelated flakes. Thanks!

@nodejs-github-bot

This comment has been minimized.

@christianaurichzm

Copy link
Copy Markdown
Contributor Author

Looks like the rerun also ran into an unrelated CI issue. This run is listed in the reliability report as Build data is unavailable:

nodejs/reliability@c91c0db

Would someone mind giving CI another try? Thanks!

@panva panva added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Sep 25, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva panva added the resume-ci Add this label to resume the latest eligible Jenkins CI run on a PR with an approving review. label Sep 25, 2026
@github-actions github-actions Bot removed the resume-ci Add this label to resume the latest eligible Jenkins CI run on a PR with an approving review. label Sep 25, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@aduh95 aduh95 added the resume-ci Add this label to resume the latest eligible Jenkins CI run on a PR with an approving review. label Sep 25, 2026
@panva panva removed the resume-ci Add this label to resume the latest eligible Jenkins CI run on a PR with an approving review. label Sep 26, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva panva added the commit-queue PRs queued for automated landing through the Commit Queue. label Sep 26, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 1e17275 into nodejs:main Sep 26, 2026
95 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 1e17275

@nodejs-github-bot nodejs-github-bot removed the commit-queue PRs queued for automated landing through the Commit Queue. label Sep 26, 2026
aduh95 pushed a commit that referenced this pull request Sep 27, 2026
`isInt32()` accepts -0 because `-0 === (-0 | 0)`, but V8 does not
represent -0 as an Int32 value, so `Value::IsInt32()` rejects it. The
utf8 fast paths of `readFileSync()` and `writeFileSync()` hand the value
straight to the binding, which then took it for a path and aborted on
the null check.

Coerce -0 to 0 before the call, matching `getValidatedFd()` and the rest
of fs, where -0 is a valid way to name file descriptor 0.

Signed-off-by: Christian Aurich <christian.aurichzm@gmail.com>
PR-URL: #65888
Fixes: #65886
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
HoonDongKang pushed a commit to HoonDongKang/node that referenced this pull request Sep 28, 2026
`isInt32()` accepts -0 because `-0 === (-0 | 0)`, but V8 does not
represent -0 as an Int32 value, so `Value::IsInt32()` rejects it. The
utf8 fast paths of `readFileSync()` and `writeFileSync()` hand the value
straight to the binding, which then took it for a path and aborted on
the null check.

Coerce -0 to 0 before the call, matching `getValidatedFd()` and the rest
of fs, where -0 is a valid way to name file descriptor 0.

Signed-off-by: Christian Aurich <christian.aurichzm@gmail.com>
PR-URL: nodejs#65888
Fixes: nodejs#65886
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
aduh95 pushed a commit that referenced this pull request Sep 28, 2026
`isInt32()` accepts -0 because `-0 === (-0 | 0)`, but V8 does not
represent -0 as an Int32 value, so `Value::IsInt32()` rejects it. The
utf8 fast paths of `readFileSync()` and `writeFileSync()` hand the value
straight to the binding, which then took it for a path and aborted on
the null check.

Coerce -0 to 0 before the call, matching `getValidatedFd()` and the rest
of fs, where -0 is a valid way to name file descriptor 0.

Signed-off-by: Christian Aurich <christian.aurichzm@gmail.com>
PR-URL: #65888
Fixes: #65886
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author ready PRs with CI started, the required approvals, and no outstanding review comments. fs Issues and PRs related to file-system APIs and the fs module. needs-ci PRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

node:fs: calling writeFileSync/appendFileSync with negative 0 causes an assertion failure

6 participants