Skip to content

fix(Network): pass nullish XHR event callbacks through instead of wrapping them - #741

Open
cyhano wants to merge 1 commit into
Tencent:devfrom
cyhano:fix/network-nullish-xhr-callbacks
Open

cyhano wants to merge 1 commit into
Tencent:devfrom
cyhano:fix/network-nullish-xhr-callbacks

Conversation

@cyhano

@cyhano cyhano commented Sep 15, 2026

Copy link
Copy Markdown

Fixes #740

Problem

Libraries like hls.js clear XHR event callbacks before aborting in-flight requests (XhrLoader.abortInternal):

xhr.onreadystatechange = null;
xhr.onprogress = null;
xhr.abort();

With vConsole enabled this throws an uncaught TypeError, because the XHR proxy wraps whatever value is assigned to onreadystatechange / onabort / ontimeout without a nullish check — the wrapper then calls value.apply(...) on null when the event fires:

Uncaught TypeError: Cannot read properties of null (reading 'apply')
    at XMLHttpRequest.<anonymous> (vconsole.min.js)
    at abortInternal (hls.min.js)
    ...

Any page playing HLS video via hls.js hits this on every stream switch / stop / destroy. Assigning null to these callbacks is a spec-compliant way to remove them, so the proxy should pass nullish values through instead of wrapping them.

Fix

In setOnReadyStateChange / setOnAbort / setOnTimeout: if the assigned value is nullish, Reflect.set it directly on the real XHR instead of installing a wrapper (a comment documents why).

Verification

Minimal repro (new VConsole() + the cleanup sequence above), run headless in Chromium:

Build pageerror User callbacks Network panel
master Cannot read properties of null (reading 'apply') — —
this patch none fired normally (status=200) both XHRs tracked, status=200 (including one whose lifecycle went fn → null → fn)

Also verified that a callback re-assigned after being cleared with null is wrapped and tracked again as before.

…pping them

Libraries like hls.js clear XHR event callbacks before aborting
in-flight requests (XhrLoader.abortInternal):

    xhr.onreadystatechange = null;
    xhr.onprogress = null;
    xhr.abort();

Assigning null to these callbacks is a spec-compliant way to remove
them, but the XHR proxy wrapped whatever value was assigned, so the
wrapper later crashed with an uncaught TypeError when the event fired:

    Uncaught TypeError: Cannot read properties of null (reading 'apply')
        at XMLHttpRequest.<anonymous> (vconsole.min.js)
        at abortInternal (hls.js)
        ...

Pass null/undefined through to the real XHR instead of wrapping them,
in setOnReadyStateChange / setOnAbort / setOnTimeout.

Verified with a minimal repro (vConsole + xhr.onreadystatechange = null
+ xhr.abort()): master throws the TypeError, this patch does not; normal
callbacks are still wrapped and tracked in the Network panel.

Fixes Tencent#740

Co-Authored-By: ZCode <noreply@z.ai>
@tencent-adm

tencent-adm commented Sep 15, 2026 •

Copy link
Copy Markdown
Member

CLA assistant check
All committers have signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Uncaught TypeError when assigning null to xhr.onreadystatechange/onprogress (breaks hls.js abort)

2 participants