From 7580065043761b0c04cf06ac4322c5c790760766 Mon Sep 17 00:00:00 2001 From: dansatch Date: Sat, 26 Sep 2026 18:57:43 +0100 Subject: [PATCH 1/2] buffer: fix negative index for large buffers Fix incorrect negative index results for large buffers. Add tests for number, Buffer and string searches beyond 2 GiB. Fixes: https://github.com/nodejs/node/issues/66294 Signed-off-by: dansatch --- src/node_buffer.cc | 10 ++++----- test/pummel/test-buffer-indexof-large.js | 27 ++++++++++++++++++++++++ 2 files changed, 32 insertions(+), 5 deletions(-) create mode 100644 test/pummel/test-buffer-indexof-large.js diff --git a/src/node_buffer.cc b/src/node_buffer.cc index 7e966e5f3936..aa42ba032c96 100644 --- a/src/node_buffer.cc +++ b/src/node_buffer.cc @@ -1158,7 +1158,7 @@ void IndexOfString(const FunctionCallbackInfo& args) { } args.GetReturnValue().Set(result >= search_end ? -1 - : static_cast(result)); + : static_cast(result)); } void IndexOfBuffer(const FunctionCallbackInfo& args) { @@ -1246,10 +1246,10 @@ void IndexOfBuffer(const FunctionCallbackInfo& args) { } args.GetReturnValue().Set(result >= search_end ? -1 - : static_cast(result)); + : static_cast(result)); } -int32_t IndexOfNumberImpl(Local buffer_obj, +int64_t IndexOfNumberImpl(Local buffer_obj, const uint32_t needle, const int64_t offset_i64, const int64_t end_i64, @@ -1276,7 +1276,7 @@ int32_t IndexOfNumberImpl(Local buffer_obj, ptr = nbytes::stringsearch::MemrchrFill(buffer_data, needle, backward_end); } const uint8_t* ptr_uint8 = static_cast(ptr); - return ptr != nullptr ? static_cast(ptr_uint8 - buffer_data) : -1; + return ptr != nullptr ? static_cast(ptr_uint8 - buffer_data) : -1; } void SlowIndexOfNumber(const FunctionCallbackInfo& args) { @@ -1297,7 +1297,7 @@ void SlowIndexOfNumber(const FunctionCallbackInfo& args) { IndexOfNumberImpl(buffer_obj, needle, offset_i64, end_i64, is_forward)); } -int32_t FastIndexOfNumber(Local, +int64_t FastIndexOfNumber(Local, Local buffer_obj, uint32_t needle, int64_t offset_i64, diff --git a/test/pummel/test-buffer-indexof-large.js b/test/pummel/test-buffer-indexof-large.js new file mode 100644 index 000000000000..0f0999705417 --- /dev/null +++ b/test/pummel/test-buffer-indexof-large.js @@ -0,0 +1,27 @@ +'use strict'; + +const common = require('../common'); +const assert = require('assert'); + +common.skipIf32Bits(); + +const match = 2 ** 31 + 100; +let buffer; +try { + buffer = Buffer.allocUnsafe(match + 1); +} catch (error) { + if (error.code === 'ERR_MEMORY_ALLOCATION_FAILED' || + /Array buffer allocation failed/.test(error.message)) { + common.skip('insufficient space for Buffer.allocUnsafe'); + } + throw error; +} + +buffer[match] = 0x0a; + +assert.strictEqual(buffer.indexOf(0x0a, -1), match); +assert.strictEqual(buffer.indexOf(Buffer.from([0x0a]), -1), match); +assert.strictEqual(buffer.indexOf('\n', -1), match); +assert.strictEqual(buffer.lastIndexOf(0x0a, -1), match); +assert.strictEqual(buffer.lastIndexOf(Buffer.from([0x0a]), -1), match); +assert.strictEqual(buffer.lastIndexOf('\n', -1), match); From 8861a47a475faaa7c1274685173b33a3c16c0f1b Mon Sep 17 00:00:00 2001 From: dansatch Date: Sun, 27 Sep 2026 05:09:19 +0100 Subject: [PATCH 2/2] buffer: fix C++ formatting Signed-off-by: dansatch --- src/node_buffer.cc | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/src/node_buffer.cc b/src/node_buffer.cc index aa42ba032c96..8738abeb9f17 100644 --- a/src/node_buffer.cc +++ b/src/node_buffer.cc @@ -1157,8 +1157,8 @@ void IndexOfString(const FunctionCallbackInfo& args) { is_forward); } - args.GetReturnValue().Set(result >= search_end ? -1 - : static_cast(result)); + args.GetReturnValue().Set( + result >= search_end ? -1 : static_cast(result)); } void IndexOfBuffer(const FunctionCallbackInfo& args) { @@ -1245,8 +1245,8 @@ void IndexOfBuffer(const FunctionCallbackInfo& args) { is_forward); } - args.GetReturnValue().Set(result >= search_end ? -1 - : static_cast(result)); + args.GetReturnValue().Set( + result >= search_end ? -1 : static_cast(result)); } int64_t IndexOfNumberImpl(Local buffer_obj,