Skip to content

src: fix crash when writing odd-length hex string via Writev - #63658

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
RajeshKumar11:fix/stream-hex-odd-length-45150
Jul 25, 2026
Merged

src: fix crash when writing odd-length hex string via Writev#63658
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
RajeshKumar11:fix/stream-hex-odd-length-45150

Conversation

@RajeshKumar11

Copy link
Copy Markdown
Contributor

Summary

Writing an odd-length hex string to a stream that batches writes via
Writev (e.g. http.request which auto-corks its socket) would
fatal-assert:

node: ../src/string_bytes.cc: Assertion `str->Length() % 2 == 0 &&
"invalid hex string length"' failed.

Reproduction:

const http = require('http');
const req = http.request('http://example.org', { method: 'POST' });
req.write('1', 'hex'); // crashes

Root cause

StringBytes::StorageSize had a CHECK that asserted the hex string
length was even. When writes are batched through Writev, this check
runs before any data is written. A single Write (non-corked path)
did not crash because StringBytes::Write calls HexDecode, which
silently drops the trailing incomplete nibble.

Fix

Remove the CHECK and use integer division for the HEX case, which
naturally rounds down for odd lengths. This is already the behaviour
of StringBytes::Size and HexDecode.

Test

Added test/parallel/test-http-odd-hex-write.js with three cases:

  1. HTTP POST with a single odd-length hex write (was crashing)
  2. HTTP POST with cork/uncork and mixed hex writes (was crashing)
  3. net socket with cork/uncork and an odd-length hex write

Fixes: #45150

@nodejs-github-bot nodejs-github-bot added buffer Issues and PRs related to the buffer subsystem. c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels May 30, 2026
@RajeshKumar11
RajeshKumar11 force-pushed the fix/stream-hex-odd-length-45150 branch from fd3d0ec to 6a0c023 Compare May 30, 2026 07:51
@codecov

codecov Bot commented May 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.34%. Comparing base (30a7e28) to head (0e3192c).
⚠️ Report is 550 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #63658      +/-   ##
==========================================
- Coverage   91.95%   90.34%   -1.61%     
==========================================
  Files         379      732     +353     
  Lines      166454   236434   +69980     
  Branches    25427    44532   +19105     
==========================================
+ Hits       153058   213614   +60556     
- Misses      13104    14522    +1418     
- Partials      292     8298    +8006     
Files with missing lines Coverage Δ
src/string_bytes.cc 71.54% <ø> (ø)

... and 482 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@RajeshKumar11
RajeshKumar11 force-pushed the fix/stream-hex-odd-length-45150 branch from 6a0c023 to 84ef8a0 Compare May 30, 2026 11:13
StringBytes::StorageSize had a CHECK that fatal-asserted when a
hex-encoded string with an odd number of characters was written
through Writev (e.g. via HTTP requests which are automatically
corked). Writing the same string via a single Write did not crash
because StringBytes::Write delegates to HexDecode, which silently
drops the trailing incomplete nibble.

Remove the CHECK and let integer division handle odd lengths, which
is consistent with StringBytes::Size and HexDecode.

Fixes: nodejs#45150
Signed-off-by: RajeshKumar11 <kakumanurajeshkumar@gmail.com>
@RajeshKumar11
RajeshKumar11 force-pushed the fix/stream-hex-odd-length-45150 branch from 84ef8a0 to 0e3192c Compare May 30, 2026 11:21

@geeksilva97 geeksilva97 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@geeksilva97

Copy link
Copy Markdown
Contributor

cc @nodejs/buffer

@geeksilva97 geeksilva97 added the request-ci Add this label to start a Jenkins CI on a PR. label Jun 24, 2026
@github-actions github-actions Bot removed the request-ci Add this label to start a Jenkins CI on a PR. label Jun 24, 2026
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@mcollina mcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@gurgunday gurgunday left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@gurgunday gurgunday added the author ready PRs that have at least one approval, no pending requests for changes, and a CI started. label Jul 25, 2026
@geeksilva97 geeksilva97 added commit-queue Add this label to land a pull request using GitHub Actions. and removed needs-ci PRs that need a full CI run. labels Jul 25, 2026
@nodejs-github-bot nodejs-github-bot removed the commit-queue Add this label to land a pull request using GitHub Actions. label Jul 25, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 3e06d53 into nodejs:main Jul 25, 2026
75 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 3e06d53

aduh95 pushed a commit that referenced this pull request Aug 3, 2026
StringBytes::StorageSize had a CHECK that fatal-asserted when a
hex-encoded string with an odd number of characters was written
through Writev (e.g. via HTTP requests which are automatically
corked). Writing the same string via a single Write did not crash
because StringBytes::Write delegates to HexDecode, which silently
drops the trailing incomplete nibble.

Remove the CHECK and let integer division handle odd lengths, which
is consistent with StringBytes::Size and HexDecode.

Fixes: #45150
Signed-off-by: RajeshKumar11 <kakumanurajeshkumar@gmail.com>
PR-URL: #63658
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
aduh95 pushed a commit that referenced this pull request Aug 4, 2026
StringBytes::StorageSize had a CHECK that fatal-asserted when a
hex-encoded string with an odd number of characters was written
through Writev (e.g. via HTTP requests which are automatically
corked). Writing the same string via a single Write did not crash
because StringBytes::Write delegates to HexDecode, which silently
drops the trailing incomplete nibble.

Remove the CHECK and let integer division handle odd lengths, which
is consistent with StringBytes::Size and HexDecode.

Fixes: #45150
Signed-off-by: RajeshKumar11 <kakumanurajeshkumar@gmail.com>
PR-URL: #63658
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
aduh95 pushed a commit that referenced this pull request Aug 6, 2026
StringBytes::StorageSize had a CHECK that fatal-asserted when a
hex-encoded string with an odd number of characters was written
through Writev (e.g. via HTTP requests which are automatically
corked). Writing the same string via a single Write did not crash
because StringBytes::Write delegates to HexDecode, which silently
drops the trailing incomplete nibble.

Remove the CHECK and let integer division handle odd lengths, which
is consistent with StringBytes::Size and HexDecode.

Fixes: #45150
Signed-off-by: RajeshKumar11 <kakumanurajeshkumar@gmail.com>
PR-URL: #63658
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
tmeijn pushed a commit to tmeijn/dotfiles that referenced this pull request Aug 11, 2026
This MR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [node](https://nodejs.org) ([source](https://github.com/nodejs/node)) | tools | minor | `26.5.0` → `26.7.0` |

MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot).

**Proposed changes to behavior should be submitted there as MRs.**

---

### Release Notes

<details>
<summary>nodejs/node (node)</summary>

### [`v26.7.0`](https://github.com/nodejs/node/releases/tag/v26.7.0): 2026-08-05, Version 26.7.0 (Current), @&#8203;aduh95

[Compare Source](nodejs/node@v26.5.0...v26.7.0)

##### Notable Changes

- \[[`58717685a1`](nodejs/node@58717685a1)] - **(SEMVER-MINOR)** **crypto**: support loading private keys through STORE loaders (Filip Skokan) [#&#8203;63949](nodejs/node#63949)
- \[[`44b940ee8c`](nodejs/node@44b940ee8c)] - **crypto**: update root certificates to NSS 3.125 (Node.js GitHub Bot) [#&#8203;64746](nodejs/node#64746)
- \[[`c1e4f7365e`](nodejs/node@c1e4f7365e)] - **(SEMVER-MINOR)** **lib**: add perfetto support (Chengzhong Wu) [#&#8203;64565](nodejs/node#64565)
- \[[`11c2f9c642`](nodejs/node@11c2f9c642)] - **(SEMVER-MINOR)** **module**: implement `Symbol.dispose` in `ModuleHooks` (Remco Haszing) [#&#8203;63928](nodejs/node#63928)
- \[[`a646319f61`](nodejs/node@a646319f61)] - **(SEMVER-MINOR)** **test\_runner**: add support for `--test-coverage-include-all` (avivkeller) [#&#8203;64830](nodejs/node#64830)

##### Commits

- \[[`a2d3f891d3`](nodejs/node@a2d3f891d3)] - **async\_hooks**: use validateBoolean for trackPromises (Soul Lee) [#&#8203;64731](nodejs/node#64731)
- \[[`d7266cdd99`](nodejs/node@d7266cdd99)] - **benchmark**: fix calibrate-n option handling (Luan Muniz) [#&#8203;64146](nodejs/node#64146)
- \[[`2e64293e3f`](nodejs/node@2e64293e3f)] - **buffer**: use Clamp conversion in Blob slice (Donghoon Kang) [#&#8203;64739](nodejs/node#64739)
- \[[`5fda0958bd`](nodejs/node@5fda0958bd)] - **buffer**: validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) [#&#8203;63904](nodejs/node#63904)
- \[[`5298db40f9`](nodejs/node@5298db40f9)] - **build**: run perfetto build and test on GHA (Chengzhong Wu) [#&#8203;64721](nodejs/node#64721)
- \[[`e3eac7cef9`](nodejs/node@e3eac7cef9)] - **build**: fix v8\_use\_perfetto source scraping (Chengzhong Wu) [#&#8203;64721](nodejs/node#64721)
- \[[`ab5f076d7f`](nodejs/node@ab5f076d7f)] - **build**: bump rustc requirement to >=1.86 (Renegade334) [#&#8203;64543](nodejs/node#64543)
- \[[`df608e061f`](nodejs/node@df608e061f)] - **(SEMVER-MINOR)** **build**: perfetto-sdk (Chengzhong Wu) [#&#8203;64565](nodejs/node#64565)
- \[[`74928adc46`](nodejs/node@74928adc46)] - **build,tools**: fix shared library cross-compile (Kirill Saied) [#&#8203;63963](nodejs/node#63963)
- \[[`58717685a1`](nodejs/node@58717685a1)] - **(SEMVER-MINOR)** **crypto**: support loading private keys through STORE loaders (Filip Skokan) [#&#8203;63949](nodejs/node#63949)
- \[[`58d13b6f3d`](nodejs/node@58d13b6f3d)] - **crypto**: preserve OpenSSL errors from KDF failures (Filip Skokan) [#&#8203;64776](nodejs/node#64776)
- \[[`478a719cb5`](nodejs/node@478a719cb5)] - **crypto**: fix Argon2 bypassing FIPS mode (Filip Skokan) [#&#8203;64776](nodejs/node#64776)
- \[[`44b940ee8c`](nodejs/node@44b940ee8c)] - **crypto**: update root certificates to NSS 3.125 (Node.js GitHub Bot) [#&#8203;64746](nodejs/node#64746)
- \[[`fde85237c7`](nodejs/node@fde85237c7)] - **crypto**: clarify missing cipher error (Filip Skokan) [#&#8203;64852](nodejs/node#64852)
- \[[`c604d8846d`](nodejs/node@c604d8846d)] - **crypto**: reuse X509 issuer result (Filip Skokan) [#&#8203;64852](nodejs/node#64852)
- \[[`c68c7d0112`](nodejs/node@c68c7d0112)] - **crypto**: validate key generation options (Filip Skokan) [#&#8203;64852](nodejs/node#64852)
- \[[`c36bb1d017`](nodejs/node@c36bb1d017)] - **crypto**: fix Argon2 validation errors (Filip Skokan) [#&#8203;64852](nodejs/node#64852)
- \[[`f61408bb27`](nodejs/node@f61408bb27)] - **crypto**: handle XOF output allocation failure (Filip Skokan) [#&#8203;64851](nodejs/node#64851)
- \[[`2b4053d046`](nodejs/node@2b4053d046)] - **crypto**: initialize KeyObjectData mutex eagerly (Filip Skokan) [#&#8203;64851](nodejs/node#64851)
- \[[`4b7b2adf44`](nodejs/node@4b7b2adf44)] - **crypto**: handle DH operation failures (Filip Skokan) [#&#8203;64851](nodejs/node#64851)
- \[[`12170c3753`](nodejs/node@12170c3753)] - **crypto**: use user-facing error for output encoding changes (Archkon) [#&#8203;64692](nodejs/node#64692)
- \[[`474f06d550`](nodejs/node@474f06d550)] - **debugger**: preserve overlapping CDP request state (Trivikram Kamat) [#&#8203;64467](nodejs/node#64467)
- \[[`718cbe9497`](nodejs/node@718cbe9497)] - **deps**: upgrade npm to 11.19.0 (npm team) [#&#8203;64883](nodejs/node#64883)
- \[[`657c6154b3`](nodejs/node@657c6154b3)] - **deps**: update ngtcp2 to 1.25.0 (Node.js GitHub Bot) [#&#8203;64944](nodejs/node#64944)
- \[[`75a1fbeff9`](nodejs/node@75a1fbeff9)] - **deps**: update nghttp3 to 1.18.0 (Node.js GitHub Bot) [#&#8203;64943](nodejs/node#64943)
- \[[`07d7cb7cd8`](nodejs/node@07d7cb7cd8)] - **deps**: update minimatch to 10.2.6 (Node.js GitHub Bot) [#&#8203;64945](nodejs/node#64945)
- \[[`f7d56359f1`](nodejs/node@f7d56359f1)] - **deps**: update simdjson to 4.6.6 (Node.js GitHub Bot) [#&#8203;64942](nodejs/node#64942)
- \[[`8b06457cfb`](nodejs/node@8b06457cfb)] - **deps**: update acorn to 8.18.0 (Node.js GitHub Bot) [#&#8203;64941](nodejs/node#64941)
- \[[`5919d01525`](nodejs/node@5919d01525)] - **deps**: update googletest to [`1b6f64d`](nodejs/node@1b6f64d) (Node.js GitHub Bot) [#&#8203;64940](nodejs/node#64940)
- \[[`4a87ad6cff`](nodejs/node@4a87ad6cff)] - **deps**: update nghttp2 to 1.70.0 (Node.js GitHub Bot) [#&#8203;64939](nodejs/node#64939)
- \[[`c96d76a7c8`](nodejs/node@c96d76a7c8)] - **deps**: update zlib to 1.3.2.1-motley-42c2f19 (Node.js GitHub Bot) [#&#8203;64744](nodejs/node#64744)
- \[[`2b59984c0f`](nodejs/node@2b59984c0f)] - **deps**: V8: backport [`5177b10`](nodejs/node@5177b10891e6) (avivkeller) [#&#8203;64631](nodejs/node#64631)
- \[[`b839af91da`](nodejs/node@b839af91da)] - **deps**: update ada to 4.0.0 (Node.js GitHub Bot) [#&#8203;64790](nodejs/node#64790)
- \[[`70dedef942`](nodejs/node@70dedef942)] - **deps**: update sqlite to 3.53.4 (Node.js GitHub Bot) [#&#8203;64745](nodejs/node#64745)
- \[[`7bc4c171f5`](nodejs/node@7bc4c171f5)] - **deps**: update Rust crates for V8 14.6.202.34-node.26 (Renegade334) [#&#8203;64543](nodejs/node#64543)
- \[[`308c6b2ac3`](nodejs/node@308c6b2ac3)] - **deps**: V8: backport [`7d9b7e0`](nodejs/node@7d9b7e03141d) (Manish Goregaokar) [#&#8203;64543](nodejs/node#64543)
- \[[`8eeae28e88`](nodejs/node@8eeae28e88)] - **deps**: V8: backport [`c4d06ba`](nodejs/node@c4d06ba586f3) (liujiahui) [#&#8203;63731](nodejs/node#63731)
- \[[`bbd6fc58c4`](nodejs/node@bbd6fc58c4)] - **diagnostics\_channel**: grow native channel storage (Stephen Belanger) [#&#8203;64497](nodejs/node#64497)
- \[[`ce8b292955`](nodejs/node@ce8b292955)] - **doc**: fix grammar and punctuation in dgram documentation (Kamal Rawal) [#&#8203;64957](nodejs/node#64957)
- \[[`1a413a60cf`](nodejs/node@1a413a60cf)] - **doc**: fix grammar and editorial issues in addons documentation (Kamal Rawal) [#&#8203;64952](nodejs/node#64952)
- \[[`63fbd59e64`](nodejs/node@63fbd59e64)] - **doc**: formalize fn/name as part of TestOptions API (Christopher Hiller) [#&#8203;64946](nodejs/node#64946)
- \[[`b263b0bca1`](nodejs/node@b263b0bca1)] - **doc**: remove references to `ca`/`crl` as per-context QuicSession options (René) [#&#8203;64769](nodejs/node#64769)
- \[[`f37de14b27`](nodejs/node@f37de14b27)] - **doc**: fix typo in maintaining-dependencies.md (greenhead) [#&#8203;64896](nodejs/node#64896)
- \[[`16cb77cdc8`](nodejs/node@16cb77cdc8)] - **doc**: add RafaelGSS as last security release stewards (Rafael Gonzaga) [#&#8203;64843](nodejs/node#64843)
- \[[`335c28cd17`](nodejs/node@335c28cd17)] - **doc**: fix typos in documentation (greenhead) [#&#8203;64900](nodejs/node#64900)
- \[[`d4bed8ca39`](nodejs/node@d4bed8ca39)] - **doc**: fix missing references in doc type map (Tim Perry) [#&#8203;64872](nodejs/node#64872)
- \[[`e71d09d5f1`](nodejs/node@e71d09d5f1)] - **doc**: improve TestContext hook descriptions (Kamal Rawal) [#&#8203;64899](nodejs/node#64899)
- \[[`7089bd9ae4`](nodejs/node@7089bd9ae4)] - **doc**: add missing float32/float64 FFI type names (Soul Lee) [#&#8203;64874](nodejs/node#64874)
- \[[`8d3ae0830e`](nodejs/node@8d3ae0830e)] - **doc**: document stream.isDestroyed() (YspritanHyzygy) [#&#8203;64789](nodejs/node#64789)
- \[[`a757e62af7`](nodejs/node@a757e62af7)] - **doc**: add contributing detail for git Signed-off-by trailer (Mike McCready) [#&#8203;64862](nodejs/node#64862)
- \[[`3e840f43ed`](nodejs/node@3e840f43ed)] - **doc**: mark config-file as release candidate (Marco Ippolito) [#&#8203;64516](nodejs/node#64516)
- \[[`70cd5df810`](nodejs/node@70cd5df810)] - **doc**: fix duplicated word in test snapshot docs (Kamal Rawal) [#&#8203;64837](nodejs/node#64837)
- \[[`d5f36c7adc`](nodejs/node@d5f36c7adc)] - **doc**: remove obsolete cctest node.gyp instructions (Soul Lee) [#&#8203;64814](nodejs/node#64814)
- \[[`a0bf29ea09`](nodejs/node@a0bf29ea09)] - **doc**: report proper return type on url.format (Brian Muenzenmeyer) [#&#8203;64806](nodejs/node#64806)
- \[[`e655e42085`](nodejs/node@e655e42085)] - **doc**: use ffi.suffix for library paths in examples (Junsoo Ha) [#&#8203;64805](nodejs/node#64805)
- \[[`e0f0830dbc`](nodejs/node@e0f0830dbc)] - **doc**: document --permission-audit audit mode behavior (Adrián Estrada) [#&#8203;64791](nodejs/node#64791)
- \[[`efbede6de0`](nodejs/node@efbede6de0)] - **doc**: clarify tlsSocket.authorized on resumption (soreavis) [#&#8203;64584](nodejs/node#64584)
- \[[`db95655c4a`](nodejs/node@db95655c4a)] - **doc**: stabilize --disable-warning (Jean Michelet) [#&#8203;64742](nodejs/node#64742)
- \[[`a8367200be`](nodejs/node@a8367200be)] - **doc**: add MDN links for explicit resource management in fs (lluisemper) [#&#8203;59557](nodejs/node#59557)
- \[[`1c09165c2e`](nodejs/node@1c09165c2e)] - **doc**: mention constructor check in deepStrictEqual (Sumit Kumar Das) [#&#8203;62010](nodejs/node#62010)
- \[[`29709324e0`](nodejs/node@29709324e0)] - **doc**: update technical priorities (Jacob Smith) [#&#8203;64505](nodejs/node#64505)
- \[[`522a28e648`](nodejs/node@522a28e648)] - **doc**: deprecation add more codemod (Augustin Mauroy) [#&#8203;63175](nodejs/node#63175)
- \[[`c40aaa6539`](nodejs/node@c40aaa6539)] - **doc**: run license-builder (Node.js GitHub Bot) [#&#8203;63918](nodejs/node#63918)
- \[[`428e9bc50f`](nodejs/node@428e9bc50f)] - **ffi**: fix crash in refCallback and unrefCallback (Trivikram Kamat) [#&#8203;64881](nodejs/node#64881)
- \[[`33912103e7`](nodejs/node@33912103e7)] - **ffi**: reject fast calls after library close (Trivikram Kamat) [#&#8203;64860](nodejs/node#64860)
- \[[`b348ed7f92`](nodejs/node@b348ed7f92)] - **ffi**: validate fast 32-bit integer argument ranges (Trivikram Kamat) [#&#8203;64691](nodejs/node#64691)
- \[[`48f4cfb480`](nodejs/node@48f4cfb480)] - **ffi**: fix optimized buffer conversions (Trivikram Kamat) [#&#8203;64639](nodejs/node#64639)
- \[[`109ffcd4f3`](nodejs/node@109ffcd4f3)] - **ffi**: preserve link register in ppc64 trampoline (Trivikram Kamat) [#&#8203;64792](nodejs/node#64792)
- \[[`aa3f168b31`](nodejs/node@aa3f168b31)] - **ffi**: preserve strings during reentrant calls (Trivikram Kamat) [#&#8203;64551](nodejs/node#64551)
- \[[`ca60942f38`](nodejs/node@ca60942f38)] - **ffi**: preserve uint8 semantics for bool fast calls (Trivikram Kamat) [#&#8203;64527](nodejs/node#64527)
- \[[`0fb1d2bd65`](nodejs/node@0fb1d2bd65)] - **ffi**: validate fast integer argument ranges (Trivikram Kamat) [#&#8203;64614](nodejs/node#64614)
- \[[`b250b40b30`](nodejs/node@b250b40b30)] - **fs**: key glob matcher cache by platform (Archkon) [#&#8203;64571](nodejs/node#64571)
- \[[`e26891ec6a`](nodejs/node@e26891ec6a)] - **http**: fix writableFinished and 'finish' after write errors (Tim Perry) [#&#8203;64847](nodejs/node#64847)
- \[[`dfc192fdfb`](nodejs/node@dfc192fdfb)] - **http**: avoid aborting IncomingMessage signal on normal close (Archkon) [#&#8203;64392](nodejs/node#64392)
- \[[`6794441c85`](nodejs/node@6794441c85)] - **http**: guard invalid timeout values in checkConnections (Efe Karasakal) [#&#8203;64506](nodejs/node#64506)
- \[[`6879aa4aa8`](nodejs/node@6879aa4aa8)] - **http**: propagate highWaterMark to ClientRequest OutgoingMessage (trivenay) [#&#8203;64653](nodejs/node#64653)
- \[[`72448a82f4`](nodejs/node@72448a82f4)] - **http2**: avoid copying the options in respond() (Matteo Collina) [#&#8203;64265](nodejs/node#64265)
- \[[`f6692da576`](nodejs/node@f6692da576)] - **http2**: avoid per-write closures in kWriteGeneric (Matteo Collina) [#&#8203;64265](nodejs/node#64265)
- \[[`3ed37153f8`](nodejs/node@3ed37153f8)] - **http2**: reduce per-request allocations (Matteo Collina) [#&#8203;64265](nodejs/node#64265)
- \[[`bce92debba`](nodejs/node@bce92debba)] - ***Revert*** "**http2**: avoid per-write closures in kWriteGeneric" (Antoine du Hamel) [#&#8203;64663](nodejs/node#64663)
- \[[`b5d5dd74a1`](nodejs/node@b5d5dd74a1)] - ***Revert*** "**http2**: avoid copying the options in respond()" (Antoine du Hamel) [#&#8203;64663](nodejs/node#64663)
- \[[`19b9c14d60`](nodejs/node@19b9c14d60)] - **lib**: fix AbortSignal.any() observed-composite leak (Paul Bouchon) [#&#8203;64481](nodejs/node#64481)
- \[[`d3cada57c2`](nodejs/node@d3cada57c2)] - **lib**: fix typo in comment in \_http\_client.js (agape1225) [#&#8203;64729](nodejs/node#64729)
- \[[`c1e4f7365e`](nodejs/node@c1e4f7365e)] - **(SEMVER-MINOR)** **lib**: add perfetto support (Chengzhong Wu) [#&#8203;64565](nodejs/node#64565)
- \[[`6c2157522d`](nodejs/node@6c2157522d)] - **loader**: enforce path normalization before lookup (Maël Nison) [#&#8203;63917](nodejs/node#63917)
- \[[`31522c41a7`](nodejs/node@31522c41a7)] - **meta**: bump actions/stale from 10.3.0 to 11.0.0 (dependabot\[bot]) [#&#8203;64935](nodejs/node#64935)
- \[[`88c8b8ef54`](nodejs/node@88c8b8ef54)] - **meta**: bump github/codeql-action/analyze from 4.36.2 to 4.37.3 (dependabot\[bot]) [#&#8203;64934](nodejs/node#64934)
- \[[`9dcd759a84`](nodejs/node@9dcd759a84)] - **meta**: bump github/codeql-action/autobuild from 4.36.2 to 4.37.3 (dependabot\[bot]) [#&#8203;64933](nodejs/node#64933)
- \[[`82ca02db3c`](nodejs/node@82ca02db3c)] - **meta**: bump actions/setup-python from 6.3.0 to 7.0.0 (dependabot\[bot]) [#&#8203;64932](nodejs/node#64932)
- \[[`848e2287f2`](nodejs/node@848e2287f2)] - **meta**: bump github/codeql-action/init from 4.36.2 to 4.37.3 (dependabot\[bot]) [#&#8203;64931](nodejs/node#64931)
- \[[`ae8ad3b17b`](nodejs/node@ae8ad3b17b)] - **meta**: bump Mozilla-Actions/sccache-action from 0.0.10 to 0.0.11 (dependabot\[bot]) [#&#8203;64930](nodejs/node#64930)
- \[[`0b359cfa4c`](nodejs/node@0b359cfa4c)] - **meta**: bump cachix/install-nix-action from 31.10.6 to 31.11.0 (dependabot\[bot]) [#&#8203;64929](nodejs/node#64929)
- \[[`3b4f980f4c`](nodejs/node@3b4f980f4c)] - **meta**: bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.3 (dependabot\[bot]) [#&#8203;64927](nodejs/node#64927)
- \[[`d7ee9e9ea7`](nodejs/node@d7ee9e9ea7)] - **meta**: bump step-security/harden-runner from 2.19.4 to 2.20.0 (dependabot\[bot]) [#&#8203;64926](nodejs/node#64926)
- \[[`7e80bbaaa9`](nodejs/node@7e80bbaaa9)] - **meta**: bump ossf/scorecard-action from 2.4.3 to 2.4.4 (dependabot\[bot]) [#&#8203;64925](nodejs/node#64925)
- \[[`915cabbfcf`](nodejs/node@915cabbfcf)] - **meta**: remove node\_crates .gitignore (René) [#&#8203;64779](nodejs/node#64779)
- \[[`8e03c54347`](nodejs/node@8e03c54347)] - **meta**: add [@&#8203;nodejs/url](https://github.com/nodejs/url) as codeowner for node\_url\_pattern.\* (Efe Karasakal) [#&#8203;64737](nodejs/node#64737)
- \[[`11c2f9c642`](nodejs/node@11c2f9c642)] - **(SEMVER-MINOR)** **module**: implement Symbol.dispose in ModuleHooks (Remco Haszing) [#&#8203;63928](nodejs/node#63928)
- \[[`fffd8a76d0`](nodejs/node@fffd8a76d0)] - **net**: support TCP handle transfer on Windows (Matteo Collina) [#&#8203;64460](nodejs/node#64460)
- \[[`fe9e0dbdc2`](nodejs/node@fe9e0dbdc2)] - **net**: support AF\_UNIX paths in net.BoundSocket (Guy Bedford) [#&#8203;64399](nodejs/node#64399)
- \[[`eb61b7ee1e`](nodejs/node@eb61b7ee1e)] - **permission**: add unique warning codes (David Evans) [#&#8203;64414](nodejs/node#64414)
- \[[`999a928822`](nodejs/node@999a928822)] - **permission**: support v8.setHeapSnapshotNearHeapLimit (Ilyas Shabi) [#&#8203;64808](nodejs/node#64808)
- \[[`7de3d095b6`](nodejs/node@7de3d095b6)] - **quic**: fix stop sending behaviour & callback (Tim Perry) [#&#8203;64710](nodejs/node#64710)
- \[[`6289398bb2`](nodejs/node@6289398bb2)] - **quic**: fix coverage comment typo (Jungwon Sohn) [#&#8203;64486](nodejs/node#64486)
- \[[`01510dc759`](nodejs/node@01510dc759)] - **quic**: fix segfault after fragmented client hello (Tim Perry) [#&#8203;64720](nodejs/node#64720)
- \[[`dcc348af97`](nodejs/node@dcc348af97)] - **quic**: serialize stream reset code as string (한만욱) [#&#8203;64577](nodejs/node#64577)
- \[[`c25b8e3331`](nodejs/node@c25b8e3331)] - **readline**: reduce createInterface overhead (Matteo Collina) [#&#8203;64585](nodejs/node#64585)
- \[[`14e802d1cd`](nodejs/node@14e802d1cd)] - **sqlite**: invalidate sessions when closing database (Trivikram Kamat) [#&#8203;64783](nodejs/node#64783)
- \[[`279547b7da`](nodejs/node@279547b7da)] - **sqlite**: check database state before calling SQLite (Trivikram Kamat) [#&#8203;64812](nodejs/node#64812)
- \[[`bb86521a42`](nodejs/node@bb86521a42)] - **sqlite**: fix crash when a session outlives its database (Mohamed Sayed) [#&#8203;63797](nodejs/node#63797)
- \[[`870f4997e7`](nodejs/node@870f4997e7)] - **sqlite**: fix use-after-free in Exec() and ApplyChangeset() (Matteo Collina) [#&#8203;64535](nodejs/node#64535)
- \[[`a8ec5a9df7`](nodejs/node@a8ec5a9df7)] - **src**: fix perfetto build on GetTraceFilePath (Chengzhong Wu) [#&#8203;64721](nodejs/node#64721)
- \[[`6cd643acaa`](nodejs/node@6cd643acaa)] - **src**: implement MemoryRetainer protocol for ByteSource (Filip Skokan) [#&#8203;64660](nodejs/node#64660)
- \[[`8725e56928`](nodejs/node@8725e56928)] - **src**: fix crash when writing odd-length hex string via Writev (RajeshKumar11) [#&#8203;63658](nodejs/node#63658)
- \[[`e018f9a4a1`](nodejs/node@e018f9a4a1)] - **(SEMVER-MINOR)** **src**: add perfetto trace agent (Chengzhong Wu) [#&#8203;64565](nodejs/node#64565)
- \[[`0611d443ab`](nodejs/node@0611d443ab)] - **(SEMVER-MINOR)** **src**: rename legacy trace event headers (Chengzhong Wu) [#&#8203;64565](nodejs/node#64565)
- \[[`2897cc1d93`](nodejs/node@2897cc1d93)] - **(SEMVER-MINOR)** **src**: fix trace macro compatibility (Chengzhong Wu) [#&#8203;64565](nodejs/node#64565)
- \[[`d4d7172e10`](nodejs/node@d4d7172e10)] - **src**: avoid using ToLocalChecked in crypto\_hash (James M Snell) [#&#8203;64668](nodejs/node#64668)
- \[[`53b7d48b47`](nodejs/node@53b7d48b47)] - **src**: fix libuv assertion on windows (liuxingbaoyu) [#&#8203;61999](nodejs/node#61999)
- \[[`69d10ed021`](nodejs/node@69d10ed021)] - **src,test**: disable trace events tests when perfetto is enabled (Chengzhong Wu) [#&#8203;64721](nodejs/node#64721)
- \[[`1b0597b4ef`](nodejs/node@1b0597b4ef)] - **stream**: cut per-chunk allocations in pipeTo (Matteo Collina) [#&#8203;64890](nodejs/node#64890)
- \[[`2632d606bb`](nodejs/node@2632d606bb)] - **stream**: preserve push signal abort reason (Trivikram Kamat) [#&#8203;64798](nodejs/node#64798)
- \[[`d5358a75bc`](nodejs/node@d5358a75bc)] - **stream**: skip zero-byte broadcast writes (Trivikram Kamat) [#&#8203;64772](nodejs/node#64772)
- \[[`796c896fb4`](nodejs/node@796c896fb4)] - **stream**: honor AbortSignal in Writer.end() (Trivikram Kamat) [#&#8203;64727](nodejs/node#64727)
- \[[`ff12b8e22e`](nodejs/node@ff12b8e22e)] - **stream**: use validateString for consumer encoding (Jungwon Sohn) [#&#8203;64754](nodejs/node#64754)
- \[[`cfad2efb06`](nodejs/node@cfad2efb06)] - **stream**: use the ring buffer for pending BYOB pull-into descriptors (Matteo Collina) [#&#8203;64818](nodejs/node#64818)
- \[[`fe06bf56dc`](nodejs/node@fe06bf56dc)] - **stream**: fix uncatchable error closing half-open Duplex.toWeb() writable (Mohamed Sayed) [#&#8203;64161](nodejs/node#64161)
- \[[`f2919dbb83`](nodejs/node@f2919dbb83)] - **test**: unflake debugger and REPL tests (Matteo Collina) [#&#8203;64718](nodejs/node#64718)
- \[[`a1c29174e8`](nodejs/node@a1c29174e8)] - **test**: ensure assertions are reached on all tests (Antoine du Hamel) [#&#8203;64716](nodejs/node#64716)
- \[[`b9e596f8e5`](nodejs/node@b9e596f8e5)] - **test**: reuse ffi.suffix instead of reimplementing it (Seongeun Lee) [#&#8203;64840](nodejs/node#64840)
- \[[`c816918e14`](nodejs/node@c816918e14)] - **test**: remove test-repl-user-error-handler from flaky (avivkeller) [#&#8203;64631](nodejs/node#64631)
- \[[`9d2f10ec54`](nodejs/node@9d2f10ec54)] - **test**: update WPT for url to [`4832db4`](nodejs/node@4832db4761) (Node.js GitHub Bot) [#&#8203;64829](nodejs/node#64829)
- \[[`75b80d0b7b`](nodejs/node@75b80d0b7b)] - **test**: update WPT for url to [`b63305b`](nodejs/node@b63305b743) (Node.js GitHub Bot) [#&#8203;64790](nodejs/node#64790)
- \[[`9a139b3c86`](nodejs/node@9a139b3c86)] - **test**: cover worker throwing primitive values (varshitha) [#&#8203;64365](nodejs/node#64365)
- \[[`796acc8920`](nodejs/node@796acc8920)] - **test**: mark test-repl-user-error-handler as flaky (Aviv Keller) [#&#8203;64612](nodejs/node#64612)
- \[[`a646319f61`](nodejs/node@a646319f61)] - **(SEMVER-MINOR)** **test\_runner**: add support for --test-coverage-include-all (avivkeller) [#&#8203;64830](nodejs/node#64830)
- \[[`4368303e01`](nodejs/node@4368303e01)] - **test\_runner**: wait for filtered suite build (semimikoh) [#&#8203;64208](nodejs/node#64208)
- \[[`70d11241a3`](nodejs/node@70d11241a3)] - **test\_runner**: convert to uint during deserialization (Aviv Keller) [#&#8203;64706](nodejs/node#64706)
- \[[`cafe7bffcc`](nodejs/node@cafe7bffcc)] - **tls**: fix SNICallback certificate selection (Matteo Collina) [#&#8203;64700](nodejs/node#64700)
- \[[`9ee05ec40f`](nodejs/node@9ee05ec40f)] - **tools**: bump the eslint group in /tools/eslint with 4 updates (dependabot\[bot]) [#&#8203;64928](nodejs/node#64928)
- \[[`5f4b859932`](nodejs/node@5f4b859932)] - **tools**: bump brace-expansion from 5.0.7 to 5.0.9 in /tools/eslint (dependabot\[bot]) [#&#8203;64904](nodejs/node#64904)
- \[[`b5ced907b3`](nodejs/node@b5ced907b3)] - **tools**: use 'readonly' for EventSource global (Honey Tyagi) [#&#8203;64787](nodejs/node#64787)
- \[[`fd4460e34e`](nodejs/node@fd4460e34e)] - **typings**: add heap\_utils internalBinding types (Donghoon Kang) [#&#8203;64816](nodejs/node#64816)
- \[[`3bc0ee0492`](nodejs/node@3bc0ee0492)] - **typings**: remove isDataView from types binding (Archkon) [#&#8203;64738](nodejs/node#64738)
- \[[`236d7ca965`](nodejs/node@236d7ca965)] - **url**: create URLPattern result properties in WebIDL order (Archkon) [#&#8203;64733](nodejs/node#64733)
- \[[`3def577ab4`](nodejs/node@3def577ab4)] - **v8**: report minor mark-sweep in GCProfiler (Archkon) [#&#8203;64688](nodejs/node#64688)
- \[[`5293abff73`](nodejs/node@5293abff73)] - **vfs**: speed up recursive readdir test setup (Trivikram Kamat) [#&#8203;64813](nodejs/node#64813)
- \[[`4345185496`](nodejs/node@4345185496)] - **vfs**: make lchown update symlink metadata (Trivikram Kamat) [#&#8203;64573](nodejs/node#64573)
- \[[`b6ab546de5`](nodejs/node@b6ab546de5)] - **wasm**: register missing SetURL function (Archkon) [#&#8203;64679](nodejs/node#64679)
- \[[`f322870bd1`](nodejs/node@f322870bd1)] - **zlib**: validate pledgedSrcSize as a safe integer (Archkon) [#&#8203;64604](nodejs/node#64604)
- \[[`44042c20d4`](nodejs/node@44042c20d4)] - **zlib**: accept ArrayBuffer dictionary in Zstd (Ryuhei Shima) [#&#8203;64599](nodejs/node#64599)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this MR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box

---

This MR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODguMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4OC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJSZW5vdmF0ZSBCb3QiLCJhdXRvbWF0aW9uOmJvdC1hdXRob3JlZCIsImRlcGVuZGVuY3ktdHlwZTo6bWlub3IiXX0=-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author ready PRs that have at least one approval, no pending requests for changes, and a CI started. buffer Issues and PRs related to the buffer subsystem. c++ Issues and PRs that require attention from people who are familiar with C++.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Crash if wrong hex string is written to http.ClientRequest

5 participants