Skip to content

Blob/File .text() crashes on odd-length input beginning with UTF-16 LE BOM in canary #31188

Description

@paul-antithesis

How can we reproduce the crash?

const b = new Blob([new Uint8Array([0xFF, 0xFE, 0x41, 0x41, 0x41, 0x41, 0x41])])
;(async () => await b.text())()

This also crashes:

const fs = require("node:fs");
const os = require("node:os");
const path = require("node:path");

const p = path.join(os.tmpdir(), "bun-repro-text-bom.bin");

(async () => {
  try {
    // 0xFF 0xFE = UTF-16 LE BOM; 0x41 = one trailing byte (odd remaining)
    fs.writeFileSync(p, Buffer.from([0xFF, 0xFE, 0x41]));
    const text = await Bun.file(p).text();
  } catch (e) {
    // Unreachable on Rust canary build
    console.log("CAUGHT:" + e.constructor.name + ":" + e.message);
  } finally {
    try { fs.unlinkSync(p); } catch {}
  }
})();

Replacing Bun.file(p).text() with Bun.file(p).json() also crashes.

I'm only able to trigger this crash when the file's length is an odd number and it begins with a little-endian byte order mark (i.e. 0xFF 0xFE, not 0xFE 0xFF)

Relevant log output

============================================================
Bun Canary v1.4.0-canary.1 (4c8a21b14) Linux x64
Linux Kernel v6.18.29 | glibc v2.42
CPU: sse42 popcnt avx avx2 avx512
Args: "bun-rust" "repro/blob-text-bom-crash.js" "bun-rust" "repro/bom-crash-simple.js"
Features: tsconfig 

Elapsed: 7ms | User: 3ms | Sys: 5ms
RSS: 26.48 MB | Peak: 24.90 MB | Commit: 26.48 MB | Faults: 0 | Machine: 64.93 GB

panic: cast_slice>OutputSliceWouldHaveSlop (<redacted>:0:0)
oh no: Bun has crashed. This indicates a bug in Bun, not your code.

To send a redacted crash report to Bun's team,
please file a GitHub issue using the link below:

 https://bun.report/1.4.0/l_24c8a21bgCA6vs5mFA0eNpLTiwuiS/OyUxOtfMvLSkoLQkGscPzS3NSPBLLUoNz8gsUNGyKUlMSk0tSU+ysDKwMNAEaRRMC

Illegal instruction        (core dumped) bun-rust repro/blob-text-bom-crash.js bun-rust repro/bom-crash-simple.js

Stack Trace (bun.report)

Bun v1.4.0-canary ([`4c8a21b`](<https://github.com/oven-sh/bun/tree/4c8a21b149ef1d927c9b6f0599ee2191af920157>)) on linux x86_64 [(pre-init)]

**panic**: Unexpected error while reloading: errno 2 (<redacted>:0:0)

- [`lib.rs:3225`](<https://github.com/oven-sh/bun/blob/4c8a21b149ef1d927c9b6f0599ee2191af920157/src/bun_core/lib.rs#L3225>): `Bun__captureStackTrace`
- [`lib.rs:3312`](<https://github.com/oven-sh/bun/blob/4c8a21b149ef1d927c9b6f0599ee2191af920157/src/bun_core/lib.rs#L3312>): `capture_stack_trace`
- [`lib.rs:92`](<https://github.com/oven-sh/bun/blob/4c8a21b149ef1d927c9b6f0599ee2191af920157/src/crash_handler/lib.rs#L92>): `capture_stack_trace`
- [`lib.rs:1884`](<https://github.com/oven-sh/bun/blob/4c8a21b149ef1d927c9b6f0599ee2191af920157/src/crash_handler/lib.rs#L1884>): `bun_crash_handler::draft::rust_panic_hook`

Features: transpiler\_cache, tsconfig, tsconfig\_paths, Bun.stderr, Bun.stdout, abort\_signal, http\_server

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions