Skip to content

object spread operator mutates first argument #25089

Description

@larsthorup
  • Version: v11.4.0
  • Platform: Windows 10.0.17134, 64-bit
  • Subsystem: don't know

Code to reproduce the issue:

const workspace = JSON.parse('{"orgContentScore":{"41":{"id":"41","contentId":"111","competenceId":"40","scoreTypeId":"6","value":0.25}}}');
const selectedObject = Object.values(workspace.orgContentScore).filter(ocs => ocs.contentId === '111').find(ocs => ocs.competenceId === '40');
console.log(selectedObject.value, 0.25); // Note: not mutated (yet)
console.log({...selectedObject, value: 0.9}.value, 0.9); // Note: This mutates selectedObject on node@11 but not on node@10
console.log(selectedObject.value, 0.25); // Note: selected objects is now mutated!!

On node@11 this outputs this unexpected result:

0.25 0.25
0.9 0.9
0.9 0.25

Where on node@10, it outputs the expected result:

0.25 0.25
0.9 0.9
0.25 0.25

according to my understanding of the description on MDN:

Activity

  1. larsthorup commented on Dec 17, 2018

    @larsthorup
    Author

    This appears to me to be related to JSON.parse(), as the code works correctly with this line instead of the first line:

    const workspace = {"orgContentScore":{"41":{"id":"41","contentId":"111","competenceId":"40","scoreTypeId":"6","value":0.25}}};
    
  2. added
    confirmed-bugIssues and PRs for confirmed bugs.
    v8 engineIssues and PRs related to the V8 dependency.
    on Dec 17, 2018
  3. BridgeAR commented on Dec 17, 2018

    @BridgeAR
    Member

    I reduced the test case and reported it to the @nodejs/v8 team:

    const weird = JSON.parse('{"a":0,"b":1,"c":2,"d":3,"e":0.1}');
    ({...weird, e: 666})
    console.assert(weird.e === 0.1);
  4. BridgeAR commented on Dec 17, 2018

    @BridgeAR
    Member

    See https://bugs.chromium.org/p/v8/issues/detail?id=8601. I provided some further details of what I found when looking into this in that issue.

  5. targos commented on Dec 17, 2018

    @targos
    Member

    It is fixed in V8 7.2.502.4 (from #24875)

  6. caitp commented on Dec 18, 2018

    @caitp
    Contributor

    Relevant commits which fixed this:
    v8/v8@bf84766,
    v8/v8@3e010af

  7. BridgeAR commented on Dec 18, 2018

    @BridgeAR
    Member

    @caitp it seems like the change depends on some other commits. Do you think it would be possible to backport your change?

  8. caitp commented on Dec 18, 2018

    @caitp
    Contributor

    I could, but I’m on holidays — but, if you feel like taking on fixing it yourself, I’m happy to answer questions.

    Otherwise, the folks assigned on the v8 bug will likely get to it before I do.

  9. hashseed commented on Dec 20, 2018

    @hashseed
    Member

    @GeorgNeis helpfully provided a patch to V8 7.1 and resolved merge conflicts here. Would anybody be willing to apply this patch to the right branch in Node.js?

  10. BridgeAR commented on Dec 20, 2018

    @BridgeAR
    Member

    @hashseed I updated V8 to the mentioned V8 version first and applied the patch afterwards but it still can't compile :/

    I missed something when comparing the patch.

  11. added a commit that references this issue on Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    confirmed-bugIssues and PRs for confirmed bugs.v8 engineIssues and PRs related to the V8 dependency.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions