Use of the removed Buffer noAssert argument

Use of the removed Buffer noAssert argument

Description

Node.js 10 removed the noAssert argument from Buffer numeric read/write APIs. In modern Node.js, passing an extra true does not disable bounds checks, so this call form alone does not cause a buffer overflow. It is a code-quality issue involving an argument absent from the current API signature (CWE-685); the method itself remains valid.

Potential impact

  • Misunderstanding the removed argument as a bounds-check control can complicate review and maintenance.
  • The intended behavior can differ between runtimes before Node.js 10 and modern runtimes.

Remediation

  • Omit noAssert and use the current Buffer API signature.
  • Validate offsets and lengths before the call.
  • If you must support Node.js versions earlier than 10, document their behavior separately.

Examples

Before

javascript
const buf = Buffer.alloc(8);
// This removed third argument has no effect in modern Node.js
buf.writeInt32LE(1234, 0, true);

After

javascript
const buf = Buffer.alloc(8);
const offset = 0;
if (offset < 0 || offset + 4 > buf.length) {
  throw new RangeError('invalid buffer offset');
}
buf.writeInt32LE(1234, offset);

The first excerpt retains an argument that no longer controls bounds checking. The second uses the current signature and checks the offset range explicitly. Modern Buffer APIs also throw for out-of-range access.

References