Skip to content
This repository was archived by the owner on Sep 2, 2023. It is now read-only.
This repository was archived by the owner on Sep 2, 2023. It is now read-only.

Are custom loaders run on their own realm always? #384

Description

@dead-claudia

In the "How do loaders declare what hooks they implement?" part of the loaders design document, it makes several claims regarding loaders imported by third parties:

Loaders can expose and exported constructor that creates an object with functions matching the names the hooks they implement.

  • This allows Loaders to function even within Realms that have frozen globals.
    • Globals would not work if Loader has a frozen realm.
  • This avoids potential overriding by dependencies by 3rd party modules.
  • This guarantees that 3rd party modules could import the hook if they know the specifier of the loader.
    • Use policies or similar to restrict this capability.
    • This does not allow them to use the same instance of loader object as the runtime since an independent call only made by the runtime can be used to obtain a unique object.

Two claims stick out to me in this mix:

  • This avoids potential overriding by dependencies by 3rd party modules.
  • This does not allow them to use the same instance of loader object as the runtime since an independent call only made by the runtime can be used to obtain a unique object.

Suppose we have three loaders root_app/loaders/alice.mjs, root_app/loaders/bob.mjs, and node_modules/dep/eve.mjs, each loaded in that order.

// root_app/loaders/alice.mjs
export default class Alice {
	// ...
}

// root_app/loaders/bob.mjs
import Alice from "./alice.mjs"
export default class Bob {
	// ...
}

// node_modules/dep/eve.mjs
import Alice from "../../loaders/alice.mjs"
let loaders = new Set()
let prev = Alice.prototype.resolve
Alice.prototype.resolve = function (...args) {
	loaders.add(this)
	return Reflect.apply(prev, this, args)
}
export default class Eve {
	// ...
}

What would eve.mjs see here? If eve.mjs is in the same realm as the alice.mjs and bob.mjs loaders, or at least share the same module cache, both of the claims in question are false. And based on my reading, it's unclear whether this is the case or not, and I can't find any language explicitly stating one way or the other.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions