Version
v27.0.0-nightly20261007aa1bf2cc37 (main at 9899b39b95)
Platform
Linux x64
Subsystem
buffer
What steps will reproduce the bug?
const buf = Buffer.from('abcabc');
// Each of these aborts the process, try/catch does not help:
buf.indexOf('a', 0, null);
buf.includes(97, 0, null);
buf.lastIndexOf(Buffer.from('a'), 5, {});
// These return -1, expected 0:
buf.indexOf('a', 0, Infinity);
buf.indexOf(97, 0, 1e20);
How often does it reproduce? Is there a required condition?
Always. Any end other than a number, a string or undefined aborts (null, booleans, objects, arrays, BigInts, symbols). Numbers outside the int64 range give a wrong result on x64.
What is the expected behavior? Why is that the expected behavior?
end is documented as {integer}, so a wrong type should throw ERR_INVALID_ARG_TYPE instead of aborting. Infinity should be clamped to buf.length, the same way end = 100 already is.
What do you see instead?
# node[788155]: void node::Buffer::(anonymous namespace)::IndexOfString(const FunctionCallbackInfo<Value> &) at ../src/node_buffer.cc:1036
# Assertion failed: args[5]->IsNumber()
and -1 for the Infinity / cases.