Skip to content

Commit 4230bc1

Browse files
committed
mini-racer: guard the sandbox status check on riscv64
The riscv64 build_dll job got through every prior GCC-compat and gn-arg fix and 2155/2176 of the way through the ninja build, then failed compiling mini_racer's own exports.cc: ../../custom_deps/mini_racer/exports.cc:180:18: error: 'IsSandboxConfiguredSecurely' is not a member of 'v8::V8' v8::V8::IsSandboxConfiguredSecurely() (include/v8-initialization.h) is declared only under V8_ENABLE_SANDBOX, which V8 (BUILD.gn/gni/v8.gni) defaults on only where pointer compression defaults on: v8_current_cpu == "arm64", "x64" or "loong64". riscv64 isn't in that list and this port sets no gn arg to force it, so the sandbox -- and the API exports.cc calls unconditionally -- doesn't exist there, unlike on every architecture upstream's own build.yml actually ships wheels for (x64/arm64), where it's on by default. Patch exports.cc to guard the call the same way v8-initialization.h guards the declaration, reporting "not securely configured" when there's no sandbox at all, same as a fallback insecure one would.
1 parent de51c8f commit 4230bc1

1 file changed

Lines changed: 56 additions & 0 deletions

File tree

Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
2+
From: Ludovic Henry <git@ludovic.dev>
3+
Date: Wed, 24 Sep 2026 00:00:00 +0200
4+
Subject: [PATCH] frontend: guard the sandbox status check on riscv64
5+
6+
The riscv64 build_dll job got past every prior GCC-compat and gn-arg
7+
fix and ~99% into the ninja build (2155/2176), then failed compiling
8+
mini_racer's own exports.cc:
9+
10+
../../custom_deps/mini_racer/exports.cc: In function
11+
'bool mr_v8_is_using_sandbox()':
12+
../../custom_deps/mini_racer/exports.cc:180:18: error:
13+
'IsSandboxConfiguredSecurely' is not a member of 'v8::V8'
14+
180 | return v8::V8::IsSandboxConfiguredSecurely();
15+
16+
v8::V8::IsSandboxConfiguredSecurely() (include/v8-initialization.h) is
17+
declared only `#if defined(V8_ENABLE_SANDBOX)`. V8_ENABLE_SANDBOX
18+
itself is off unless V8's sandbox is compiled in, and the sandbox
19+
(BUILD.gn) defaults on only when pointer-compression-backed-by-a-
20+
shared-cage is available, which in turn (gni/v8.gni) defaults true
21+
only for v8_current_cpu == "arm64", "x64" or "loong64" -- riscv64 is
22+
not in that list, and this port sets no gn arg to force it on. So on
23+
riscv64 the sandbox is off by default and the API this function calls
24+
unconditionally does not exist, whereas every architecture upstream
25+
actually ships wheels for (x64/arm64, per .github/workflows/build.yml)
26+
gets pointer compression, and hence the sandbox, on by default and
27+
never hits this.
28+
29+
Guard the call the same way v8-initialization.h guards the API: when
30+
V8_ENABLE_SANDBOX isn't defined there is no sandbox to speak of, so
31+
report it as not securely configured (mirrors what a fallback,
32+
insecure sandbox already reports via the same function).
33+
34+
Upstream-Status: To upstream [not yet submitted to bpcreech/PyMiniRacer]
35+
36+
Signed-off-by: Ludovic Henry <git@ludovic.dev>
37+
---
38+
src/v8_py_frontend/exports.cc | 4 ++++
39+
1 file changed, 4 insertions(+)
40+
41+
diff --git a/src/v8_py_frontend/exports.cc b/src/v8_py_frontend/exports.cc
42+
index 0000000..0000000 100644
43+
--- a/src/v8_py_frontend/exports.cc
44+
+++ b/src/v8_py_frontend/exports.cc
45+
@@ -177,7 +177,11 @@ LIB_EXPORT auto mr_v8_version() -> char const* {
46+
}
47+
48+
LIB_EXPORT auto mr_v8_is_using_sandbox() -> bool {
49+
+#if defined(V8_ENABLE_SANDBOX)
50+
return v8::V8::IsSandboxConfiguredSecurely();
51+
+#else
52+
+ return false;
53+
+#endif
54+
}
55+
56+
LIB_EXPORT auto mr_get_identity_hash(uint64_t context_id,

0 commit comments

Comments
 (0)