Skip to content

Fix slice offsets outside the signed 32-bit range - #378

Open
Huzaifa-Asif wants to merge 1 commit into
feross:masterfrom
Huzaifa-Asif:fix/large-slice-offsets
Open

Huzaifa-Asif wants to merge 1 commit into
feross:masterfrom
Huzaifa-Asif:fix/large-slice-offsets

Conversation

@Huzaifa-Asif

@Huzaifa-Asif Huzaifa-Asif commented Oct 6, 2026 •

Copy link
Copy Markdown

Fixes #315.

Buffer.prototype.slice currently converts start and end with ~~, which wraps large offsets to signed 32-bit values. For example, Buffer.from([1, 2, 3]).slice(1, 2 ** 32) returns an empty buffer instead of [2, 3].

Replace those two coercions with Math.trunc, preserving the existing bounds adjustment and shared-memory view. Regression coverage includes large positive and negative offsets, fractional and non-finite values, string/object coercion, and nested slice aliasing. The new tests produce 22 failing assertions before the fix; all 60 focused slice assertions pass afterward.

Verification

  • all 60 focused slice assertions pass locally on Node 24
  • full npm test: 1,048,618 assertions passed during preparation on Node 18, 20, 22, and 24
  • JavaScript Standard Style and git diff --check pass
  • 72,200 native-Buffer comparison cases had zero mismatches after the fix
  • browser bundles build, but real-browser execution was blocked by the preparation environment and remains unverified
  • the CI Node 16 job was not run locally

AI assistance disclosure

OpenAI Codex assisted with investigation, implementation, tests, review, and drafting this description. No human-review attestation is made.

@Huzaifa-Asif
Huzaifa-Asif marked this pull request as ready for review October 7, 2026 02:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Use Buffer slice will have wrong result when end is larger than int32.

1 participant