grafana/k6 · error · TypeError

typedArray parameter's length is negative

Error message

typedArray parameter's length is negative

What it means

A generic argument validation guard in GetRandomValues: before filling the buffer with random bytes, the method verifies the passed TypedArray-derived object exposes a usable numeric length; when the extracted length is negative it is rejected. The input at fault is the typedArray argument whose length is negative, which would make the random-byte fill invalid, so the operation aborts before any random data is generated.

Solutions

  1. Don't override the length property of the TypedArray; pass a plain new Uint8Array(n) with a non-negative n.
  2. Replace custom/Proxy-wrapped array objects with genuine TypedArrays before calling.
  3. Validate the array yourself before the call and reject negative lengths.

Example fix

// before
const arr = new Uint8Array(16);
Object.defineProperty(arr, 'length', { value: -1 });
crypto.getRandomValues(arr);
// after
const arr = new Uint8Array(16);
crypto.getRandomValues(arr);
Defensive patterns

Strategy: validation

Validate before calling

if (!(buf instanceof Uint8Array) || buf.length < 0) {
  throw new TypeError('need a TypedArray with non-negative length');
}
crypto.getRandomValues(buf);

Type guard

function hasValidLength(v) {
  return ArrayBuffer.isView(v) && v.length >= 0;
}

Try / catch

try {
  crypto.getRandomValues(buf);
} catch (e) {
  if (String(e).includes('length is negative')) {
    buf = new Uint8Array(buf.byteLength); // recreate pristine array
    crypto.getRandomValues(buf);
  } else { throw e; }
}

Prevention

When it happens

Trigger: Calling crypto.getRandomValues(arr) where arr.length has been manually overridden to a negative number, e.g. Object.defineProperty(arr, 'length', {value: -1}) or a subclass returning a negative length.

Common situations: Deliberately adversarial scripts (fuzzing the runtime); buggy custom TypedArray subclasses; accidental property override via Proxy or defineProperty.

Related errors


AI-assisted analysis of grafana/k6@3fcf5388d7 (2026-09-20). Data as JSON: /api/errors/b35aaa3edc9946eb. Report an issue: GitHub.

Appendix: source

Thrown at internal/js/modules/k6/webcrypto/crypto.go:76

	// 1.
	if !IsInstanceOf(c.vu.Runtime(), typedArray, acceptedTypes...) {
		common.Throw(c.vu.Runtime(), NewError(TypeMismatchError, "typedArray parameter isn't a TypedArray instance"))
	}

	// 2.
	// Obtain the length of the typed array, and throw a QuotaExceededError if
	// it's too big, as specified in the [spec's] 10.2.1.2 paragraph.
	// [spec]: https://www.w3.org/TR/WebCryptoAPI/#Crypto-method-getRandomValues
	obj := typedArray.ToObject(c.vu.Runtime())
	objLength, ok := obj.Get("length").ToNumber().Export().(int64)
	if !ok {
		common.Throw(c.vu.Runtime(), NewError(TypeMismatchError, "typedArray parameter isn't a TypedArray instance"))
	}

	// The length property is script-controlled and can be overridden with a
	// negative value, which would make the make() call below panic.
	if objLength < 0 {
		panic(c.vu.Runtime().NewTypeError("typedArray parameter's length is negative"))
	}

	if objLength > maxRandomValuesLength {
		common.Throw(
			c.vu.Runtime(),
			NewError(
				QuotaExceededError,
				fmt.Sprintf("typedArray parameter is too big; maximum length is %d", maxRandomValuesLength),
			),
		)
	}

	// 3.
	// Create a buffer of a matching size and fill
	// it with random values.
	//
	// We use crypto/rand.Read() here as it will use /dev/urandom or
	// an equivalent on Unix-like systems, and CryptGenRandom()

View on GitHub (pinned to 3fcf5388d7)