Skip to content

deps: update v8 to 15.6 - #66601

Draft
joyeecheung wants to merge 12 commits into
nodejs:mainfrom
joyeecheung:v8-156
Draft

joyeecheung wants to merge 12 commits into
nodejs:mainfrom
joyeecheung:v8-156

Conversation

@joyeecheung

@joyeecheung joyeecheung commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

joyeecheung and others added 12 commits October 7, 2026 23:52
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Major V8 updates are usually API/ABI incompatible with previous
versions. This commit adapts NODE_MODULE_VERSION for V8 15.6.

Refs: https://github.com/nodejs/CTC/blob/master/meetings/2016-09-28.md
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
PR-URL: nodejs#65161
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Original commit message:

    [platform] support madvise(3C) across ALL illumos revisions

    In illumos, madvise(3C) now takes `void *` for its first argument
    post-illumos#14418, but uses `caddr_t` pre-illumos#14418. This fix will
    detect if the illumos mman.h file in use is pre-or-post-illumos#14418 so
    builds can work either way.

    Co-Authored-By: Dan McDonald <danmcd@mnx.io>
    Refs: nodejs#65161

Refs: v8/v8@415b7d3
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Original commit message:

    [sandbox] fix dispatch table access on illumos

    illumos pointers are VA48, can allocate from the top of the 64-bit range
    as well.

    Co-Authored-By: Dan McDonald <danmcd@mnx.io>
    Refs: nodejs#65161

Refs: v8/v8@5dfeb2e
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Original commit message:

    Do not use preserve_most when targeting the MSVC ABI

    In the Microsoft C++ ABI, because preserve_most changes the calling
    convention, clang mangles it with U while cdecl gets an A, which
    means components compiled with different toolchains can fail to link.
    Make it a no-op when targetting MSVC and its ABI.

    Co-Authored-By: Stefan Stojanovic <stefan.stojanovic@janeasystems.com>
    Refs: nodejs#55784

Refs: v8/v8@e10d795
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Original commit message:

    Avoid backslash at the end of the comments

    This triggers -Wcomment in GCC. Switch to a different diagram style
    to avoid it.

    Change-Id: Iaadabdecb76de21937def43cbac817470a90c735
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8480492
    Commit-Queue: Andreas Haas <ahaas@chromium.org>
    Reviewed-by: Andreas Haas <ahaas@chromium.org>
    Cr-Commit-Position: refs/heads/main@{#110151}

Refs: v8/v8@b2fc93f
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
PR-URL: nodejs#65161
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Original commit message:

    [torque] Fix C++ object layout assertions for MSVC STL

    The assertions generated for @cppObjectLayoutDefinition classes assume
    that the first field of a derived class starts at sizeof(Parent) and
    that sizeof(Class) == the packed size computed by Torque. Both
    assumptions break when compiling with the MSVC STL, which stores
    std::atomic<T> with alignas(sizeof(T)). Under the Microsoft C++ ABI an
    alignas() is a required alignment that #pragma pack cannot lower, so the
    std::atomic bit fields of Map force Map, and in turn the pack(1)
    ExtendedMap, to align by 4 bytes. After rounding up,

    sizeof(ExtendedMap) == sizeof(Map) + 4 == kSize + 3

    so

    static_assert(kSize == sizeof(ExtendedMap))

    fails. The base subobject size is not rounded up
    however, so JSInterceptorMap places its first field at sizeof(Map) + 1
    rather than sizeof(ExtendedMap), and

    static_assert(kFlagsOffset == offsetof(JSInterceptorMap, flags_))

    fails as well.

    Fix this by:

    - Using the packed parent size that Torque already knows as the offset
      of the first derived field instead of sizeof(Parent).
    - Relaxing the assertion to only require that sizeof(Class) does not
      exceed kSize by alignof(Class) or more, so that any extra bytes fit
      into the alignment padding.

    Co-Authored-By: StefanStojanovic <stefan.stojanovic@janeasystems.com>
    Refs: nodejs#65161
    Bug: 531344950
    Change-Id: I16811484a8ff3d1bff187bab950ac71b6ea7f297
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8486028
    Reviewed-by: Leszek Swirski <leszeks@chromium.org>
    Reviewed-by: Igor Sheludko <ishell@chromium.org>
    Commit-Queue: Joyee Cheung <joyee@igalia.com>
    Cr-Commit-Position: refs/heads/main@{#110223}

Refs: v8/v8@99ebeac
Co-Authored-By: StefanStojanovic <stefan.stojanovic@janeasystems.com>
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
PR-URL: nodejs#65161
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Original commit message:

    [objects] Use a generic lambda for gc_retry in BackingStore

    gc_retry passes a std::function<bool()> as base::FunctionRef, which
    derives the signature from decltype(&Functor::operator()), whose type
    is unspecified by the standard, and it fails to compile with
    MSVC STL.

    Use a generic lambda so FunctionRef binds to the caller's lambda
    directly.

    Co-Authored-By: StefanStojanovic <stefan.stojanovic@janeasystems.com>
    Refs: nodejs#61898
    Change-Id: I9ce000ed3136942577b1a6da0b890bc48d0f00e5
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8517726
    Commit-Queue: Joyee Cheung <joyee@igalia.com>
    Reviewed-by: Clemens Backes <clemensb@chromium.org>
    Cr-Commit-Position: refs/heads/main@{#110418}

Refs: v8/v8@95626c6
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
Original commit message:

    Make TagRange build without __builtin_unreachable

    Guard the call with V8_HAS_BUILTIN_UNREACHABLE, if it's not
    available in the toolchain, skip the compiler hint so it still
    compiles.

    Co-Authored-By: StefanStojanovic <stefan.stojanovic@janeasystems.com>
    Refs: nodejs#61898
    Change-Id: Ided07825644ffdd5b6aa7c6fa7f39ae3e62d2535
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8517724
    Commit-Queue: Joyee Cheung <joyee@igalia.com>
    Reviewed-by: Michael Lippautz <mlippautz@chromium.org>
    Cr-Commit-Position: refs/heads/main@{#110422}

Refs: v8/v8@19173cd
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/gyp
  • @nodejs/security-wg
  • @nodejs/v8-update

@joyeecheung
joyeecheung marked this pull request as draft October 8, 2026 12:49
@nodejs-github-bot nodejs-github-bot added build Issues and PRs related to Node.js builds or CI infrastructure. dependencies PRs that add, update, or configure Node.js dependencies. needs-ci PRs that need a full CI run. v8 engine Issues and PRs related to the V8 dependency. labels Oct 8, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

build Issues and PRs related to Node.js builds or CI infrastructure. dependencies PRs that add, update, or configure Node.js dependencies. needs-ci PRs that need a full CI run. v8 engine Issues and PRs related to the V8 dependency.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants