We are currently trying to build the most updated version of the server using the approach below, where we are downloading Formio at a specific commit and building the server, replacing the "#main" references with their versions.
During any "dry run" submission, we are facing the following issue.
formio:validator Starting validation +0ms
formio:vm Error setting global t: TypeError: (text) => {
return text;
} could not be cloned.
at IsolateVM.evaluateSync (/formio/node_modules/@formio/vm/build/IsolateVM.js:89:36)
at IsolateVMEvaluator.evaluate (/formio/src/vm/index.js:89:26)
at evaluate (/formio/node_modules/@formio/core/lib/utils/utils.js:135:34)
at calculateProcessSync (/formio/node_modules/@formio/core/lib/process/calculation/index.js:36:43)
at /formio/node_modules/@formio/core/lib/process/calculation/index.js:56:45
at Generator.next (<anonymous>)
at /formio/node_modules/@formio/core/lib/process/calculation/index.js:8:71
at new Promise (<anonymous>)
at __awaiter (/formio/node_modules/@formio/core/lib/process/calculation/index.js:4:12)
at Object.calculateProcess [as process] (/formio/node_modules/@formio/core/lib/process/calculation/index.js:55:39)
Possible Root Cause
I am not sure which layer a possible fix (if one really exists) should be executed, since the formio, calls the @formio/core, which then would call the @formio/vm. In a quick (and shallow) analysis, the root cause of this error lies in how the evaluation context is passed to the isolated VM sandbox:
Function Injection: @formio/core provides a normalizeContext method which injects a translation helper function, t, into the global evaluation context: (text) => { return text; }.
Serialization Failure: @formio/vm uses a library called isolated-vm to securely execute form logic. isolated-vm relies on the structured clone algorithm to securely copy global variables from the Node environment into the isolated VM environment.
The Crash: The structured clone algorithm, by design, cannot serialize JavaScript functions. When isolated-vm encounters the injected t function in the arguments, it fails to clone it and throws the TypeError: ... could not be cloned.
Maybe this commit in formio repo would resolve it, but it did not handle this specific t function?
We are currently trying to build the most updated version of the server using the approach below, where we are downloading Formio at a specific commit and building the server, replacing the "#main" references with their versions.
During any "dry run" submission, we are facing the following issue.
Possible Root Cause
I am not sure which layer a possible fix (if one really exists) should be executed, since the
formio, calls the@formio/core, which then would call the@formio/vm. In a quick (and shallow) analysis, the root cause of this error lies in how the evaluation context is passed to the isolated VM sandbox:Function Injection:
@formio/coreprovides anormalizeContextmethod which injects a translation helper function,t, into the global evaluationcontext: (text) => { return text; }.Serialization Failure:
@formio/vmuses a library calledisolated-vmto securely execute form logic.isolated-vmrelies on the structured clone algorithm to securely copy global variables from the Node environment into the isolated VM environment.The Crash: The structured clone algorithm, by design, cannot serialize JavaScript functions. When isolated-vm encounters the injected t function in the arguments, it fails to clone it and throws the TypeError: ... could not be cloned.
Maybe this commit in formio repo would resolve it, but it did not handle this specific
tfunction?