Commit Graph
48822 Commits
Author SHA1 Message Date
Node.js GitHub Bot 691cf6245c deps: update lief to 1.0.0
PR-URL: https://github.com/nodejs/node/pull/66345
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
2026-09-29 08:57:54 +00:00
Antoine du Hamel 5a271b3495 tools: add deps/LIEF to the ignore list of test-shared.yml
Signed-off-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66342
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Chemi Atlow <chemi@atlow.co.il>
2026-09-29 08:39:46 +00:00
Antoine du Hamel d9274ce623 tools: fix nixpkgs updater script
We only want the first match, which by convention is the global pin the
script is meant to update.

Signed-off-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66337
Refs: https://github.com/nodejs/node/actions/runs/36284249504/job/108521854021
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Chemi Atlow <chemi@atlow.co.il>
2026-09-29 07:10:00 +00:00
Nigro Simone 686612918b test: check frame restore in CallbackScope
A CallbackScope must restore the async context frame that was active
before it, when there was none and when there was one.

Signed-off-by: Nigro Simone <nigro.simone@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66316
Refs: https://github.com/nodejs/performance/issues/24
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
2026-09-29 06:45:37 +00:00
Nigro Simone e77e173004 benchmark: add a node::MakeCallback benchmark
The addon calls into JS with node::MakeCallback from a libuv timer, so
every call opens a top-level callback scope, like an I/O callback does.

Signed-off-by: Nigro Simone <nigro.simone@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66316
Refs: https://github.com/nodejs/performance/issues/24
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
2026-09-29 06:45:36 +00:00
Nigro Simone d97041fff9 src: reduce InternalCallbackScope overhead
InternalCallbackScope looks up the Environment from the isolate two
times per call, inside async_context_frame::exchange, and it keeps the
prior async context frame in a v8::Global also when there is no frame,
that is the common case. Every call from native code into JS pays this:
MakeCallback, CallbackScope, AsyncWrap, Node-API.

Now the scope passes the Environment it already has, the option is read
with an inline accessor instead of copying the shared_ptr, and the
global handle is created only when the prior frame is not undefined.

benchmark/napi/make_callback, Node 26.3.0 built with and without this
change, Linux x64, 30 runs: from 202-208 ns to 155-159 ns per call.

Refs: https://github.com/nodejs/performance/issues/24
Signed-off-by: Nigro Simone <nigro.simone@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66316
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
2026-09-29 06:45:35 +00:00
James M Snell 296584b7af benchmark: add http header validator benchmark
Compare http.isValidHeaderName() and http.isValidHeaderValue() with
http.validateHeaderName() and http.validateHeaderValue() wrapped in
try/catch, for valid and invalid input, and for both 'strict' and
'relaxed' header value validation.

Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66334
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Tim Perry <pimterry@gmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
2026-09-29 04:38:28 +00:00
James M Snell 44ba289f55 http: add isValidHeaderName() and isValidHeaderValue()
Add non-throwing counterparts of http.validateHeaderName() and
http.validateHeaderValue() that return a boolean instead of throwing.

Rejecting an invalid header with the existing validators costs a few
microseconds, because an error object and its stack trace are created,
compared to ~20ns for the boolean check. Userland HTTP implementations
such as undici (fetch Headers, request options) therefore keep private
copies of the token and field-value tables from _http_common. These new
functions let them reuse the core implementation.

isValidHeaderValue() accepts an optional `httpValidation` option
('strict' or 'relaxed') that has the same meaning as the option of the
same name on http.createServer() and http.request().

Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66334
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Tim Perry <pimterry@gmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
2026-09-29 04:38:26 +00:00
Node.js GitHub Bot 3a30bcad56 deps: update zlib to 1.3.2.1-motley-456ae73
PR-URL: https://github.com/nodejs/node/pull/66330
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
2026-09-29 01:40:20 +00:00
Node.js GitHub Bot 914c1c8a6f deps: update undici to 8.11.2
PR-URL: https://github.com/nodejs/node/pull/66332
Reviewed-By: Chemi Atlow <chemi@atlow.co.il>
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com>
2026-09-29 01:40:06 +00:00
Node.js GitHub Bot e168cbf046 deps: update timezone to 2026d
PR-URL: https://github.com/nodejs/node/pull/66333
Reviewed-By: Chemi Atlow <chemi@atlow.co.il>
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
2026-09-29 01:39:54 +00:00
Samuel Attard 471fe813bb module: avoid allocating a cache key string for every require()
The relative resolve cache was keyed by a concatenated
${parent.path}\x00${request} string, allocating a new key for every
require() call including fully cached ones. Key the cache by the
parent directory first (a Map keyed by the already-retained
module.path string) and then by the request (a dictionary object,
whose property access internalizes dynamically-constructed
specifiers). Faster on every measured workload shape and slightly
smaller in memory, since the concatenated keys are no longer
retained.

Signed-off-by: Sam Attard <sattard@anthropic.com>
PR-URL: https://github.com/nodejs/node/pull/63884
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com>
2026-09-28 23:30:13 +00:00
Maksim Romanov ae9c25acc5 test: use common.PIPE in fs.cp socket tests
The socket was created under a nested tmpdir using an absolute path,
which can exceed the 104-byte sun_path limit on macOS when the
checkout lives in a long directory. common.PIPE uses a path relative
to the cwd, as the other pipe tests do.

Fixes: https://github.com/nodejs/node/issues/66324
Assisted-by: a closed-source coding agent
Signed-off-by: Maksim Romanov <romanov.maxim.98@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66329
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Reviewed-By: Chemi Atlow <chemi@atlow.co.il>
2026-09-28 20:12:21 +00:00
Filip Skokan 58821eed26 test: deflake fast FFI buffer tests
The optimized buffer tests can leave compiler jobs running during
library teardown. Wait for those jobs before closing the libraries,
matching the existing integer validation tests.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: https://github.com/nodejs/node/pull/66327
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
2026-09-28 19:47:03 +00:00
Hilary Asogwa e6d47201e1 buffer: fix negative index for large buffers
Fix incorrect negative index results for large buffers.
Add tests for number, Buffer and string searches beyond 2 GiB.

Fixes: https://github.com/nodejs/node/issues/66294

Signed-off-by: dansatch <dansatch98@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66325
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
2026-09-28 17:58:14 +00:00
Filip Skokan c570b67593 test: unmark loader inspector wait test as flaky
Disconnecting the inspector can race with its final notification write.
If EOF resets the socket first, the write used to dereference a null
TCP handle. 8a84e6be90 added guards for writes after disconnect.

Removing those guards reproduces the loader test's SIGSEGV under a
scheduling-delay probe; the normal binary passes the same probe.
Remove the flaky expectations left over from before that fix.

Refs: https://github.com/nodejs/node/issues/54346
Refs: https://github.com/nodejs/node/issues/34833
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Claude, Codex
PR-URL: https://github.com/nodejs/node/pull/66319
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
2026-09-28 14:52:19 +00:00
Filip Skokan c12d483b1f test: unmark exit timeout tests as flaky
Background compilation could deadlock at process exit: DrainTasks
waited for the compiler task while that task waited for main-thread
garbage collection. Since 5fb879c458, only user-blocking tasks count
toward that wait, excluding ordinary background compilation.

Remove the old flaky expectations for test-http2-large-file and
test-fs-read-stream-concurrent-reads.

Refs: https://github.com/nodejs/node/issues/47409
Refs: https://github.com/nodejs/node/issues/51862
Refs: https://github.com/nodejs/node/issues/54918
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Claude, Codex
PR-URL: https://github.com/nodejs/node/pull/66319
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
2026-09-28 14:52:18 +00:00
Filip Skokan 1a15692fb6 test: unmark test-cpu-prof-dir-worker as flaky
The test could finish its workload without recording a workload frame.
0ab4a1ce90 increased the non-Windows workload from fib(30) to fib(40),
and 92e63426c0 moved Profiler.setSamplingInterval before Profiler.start
so the requested interval takes effect.

Remove the flaky expectation left over from before those fixes.

Refs: https://github.com/nodejs/node/issues/27611
Refs: https://github.com/nodejs/node/issues/32168
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Claude, Codex
PR-URL: https://github.com/nodejs/node/pull/66319
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
2026-09-28 14:52:16 +00:00
Filip Skokan cbf3566b12 test: remove stale SEA Linux debug flaky entries
The entries added for Linux arm64 debug failures use arch==arm, so they
do not match that configuration. Since 9ea61828c7, the shared SEA guard
also correctly skips executable tests on Linux debug builds.

Remove the stale entries. The tests without that guard only validate
SEA configuration errors.

Refs: https://github.com/nodejs/node/issues/63749
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Claude, Codex
PR-URL: https://github.com/nodejs/node/pull/66319
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
2026-09-28 14:52:14 +00:00
Filip Skokan e0a3c37c30 test: remove stale flaky status entries
Remove entries for test-performance-function and
test-report-fatal-error. Both tests were renamed, so their original
names no longer match tests.

Refs: https://github.com/nodejs/node/issues/54803
Refs: https://github.com/nodejs/node/issues/43457
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Claude, Codex
PR-URL: https://github.com/nodejs/node/pull/66319
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
2026-09-28 14:52:11 +00:00
Robert Nagy 191a3b2db4 http2: emit close for aborted HEAD compat responses
The compat response defers 'finish' and 'close' for a HEAD request
until response.end(), because the stream of a headers-only response
closes as soon as the headers are sent. The same deferral also applied
to a HEAD stream that closed before any response was sent, for example
when the client cancelled it or the session was destroyed. Nothing was
left to call end(), so the response never emitted 'close' and the abort
could not be observed on it.

Defer only once the headers were sent, and otherwise close the response
as for any other method. The writable side of a HEAD stream is finished
from the start, so 'finish' is emitted only after the headers were
sent, and an aborted HEAD response does not report success.

Assisted-by: Opus 5.5
Signed-off-by: Robert Nagy <ronagy@icloud.com>
PR-URL: https://github.com/nodejs/node/pull/66310
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
2026-09-28 10:40:58 +00:00
Matteo Collina cff7b12df1 stream: keep webstreams nil requests in fast mode
The shared "no pending request" records in the writable stream were
`__proto__: null` literals, which V8 creates in dictionary mode. They
sit in inFlightWriteRequest, closeRequest and pendingAbortRequest
whenever nothing is pending, and their promise field is checked several
times per write, so those loads did a hash lookup on every write and
every pipe. They are now built as plain literals and get their null
prototype afterwards, which keeps them in fast mode.

The readable controllers also initialized their state slot with an
empty object that setup replaced immediately. That throwaway allocation
is gone, matching the writable and transform controllers.

Add a writable-write benchmark: nothing in benchmark/webstreams drove
WritableStreamDefaultWriter.write() directly.

Signed-off-by: Matteo Collina <hello@matteocollina.com>
PR-URL: https://github.com/nodejs/node/pull/66230
Reviewed-By: Mattias Buelens <mattias@buelens.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
2026-09-28 07:51:16 +00:00
James M Snell b59840b593 buffer: add isLatin1
Implements a fast check to determine if a string is
a valid byte string (only chars <= 0xff).

Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66298
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Reviewed-By: Robert Nagy <ronagy@icloud.com>
2026-09-28 04:22:57 +00:00
James M Snell 8f43e8884b buffer: add isLatin1
Implements a fast check to determine if a string is
a valid byte string (only chars <= 0xff).

Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66298
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Reviewed-By: Robert Nagy <ronagy@icloud.com>
2026-09-28 04:22:37 +00:00
Trivikram Kamat 75e4bbe0a8 report: skip unresponsive workers on process timeout
When --process-timeout expires, --report-on-process-timeout asked
every Worker for a subreport and waited without a time limit. A Worker
blocked in a synchronous native call never answers, so the watchdog
force-exited the process before the report was written. That left a
truncated, invalid JSON file, and the forced-exit message was glued
onto the "Writing Node.js report to file" line.

For reports triggered by --process-timeout, wait at most two seconds
for Worker subreports and leave out Worker threads that have not
responded by then. The subreport state is now shared with the interrupt
callbacks, so a Worker that answers late does not touch freed memory.
Other report triggers are unchanged.

Signed-off-by: Trivikram Kamat <16024985+trivikr@users.noreply.github.com>
Assisted-by: claude:opus-5.5
PR-URL: https://github.com/nodejs/node/pull/66304
Fixes: https://github.com/nodejs/node/issues/66303
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
2026-09-27 22:04:18 +00:00
dependabot[bot] df775ec2ea tools: bump the doc group in /tools/doc with 4 updates
Bumps the doc group in /tools/doc with 4 updates: [@doc-kit/cli](https://github.com/nodejs/doc-kit/tree/HEAD/packages/cli), [@doc-kit/generator-react](https://github.com/nodejs/doc-kit/tree/HEAD/packages/react), [@node-core/doc-kit](https://github.com/nodejs/doc-kit/tree/HEAD/packages/node) and [@node-core/doc-kit-legacy](https://github.com/nodejs/doc-kit/tree/HEAD/packages/node-legacy).

Updates `@doc-kit/cli` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/nodejs/doc-kit/releases)
- [Changelog](https://github.com/nodejs/doc-kit/blob/main/packages/cli/CHANGELOG.md)
- [Commits](https://github.com/nodejs/doc-kit/commits/@doc-kit/cli@1.0.3/packages/cli)

Updates `@doc-kit/generator-react` from 0.3.0 to 0.3.1
- [Release notes](https://github.com/nodejs/doc-kit/releases)
- [Changelog](https://github.com/nodejs/doc-kit/blob/main/packages/react/CHANGELOG.md)
- [Commits](https://github.com/nodejs/doc-kit/commits/@doc-kit/generator-react@0.3.1/packages/react)

Updates `@node-core/doc-kit` from 2.0.2 to 2.0.3
- [Release notes](https://github.com/nodejs/doc-kit/releases)
- [Changelog](https://github.com/nodejs/doc-kit/blob/main/packages/node/CHANGELOG.md)
- [Commits](https://github.com/nodejs/doc-kit/commits/@node-core/doc-kit@2.0.3/packages/node)

Updates `@node-core/doc-kit-legacy` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/nodejs/doc-kit/releases)
- [Changelog](https://github.com/nodejs/doc-kit/blob/main/packages/node-legacy/CHANGELOG.md)
- [Commits](https://github.com/nodejs/doc-kit/commits/@node-core/doc-kit-legacy@1.0.3/packages/node-legacy)

---
updated-dependencies:
- dependency-name: "@doc-kit/cli"
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: doc
- dependency-name: "@doc-kit/generator-react"
  dependency-version: 0.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: doc
- dependency-name: "@node-core/doc-kit"
  dependency-version: 2.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: doc
- dependency-name: "@node-core/doc-kit-legacy"
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: doc
...

Signed-off-by: dependabot[bot] <support@github.com>
PR-URL: https://github.com/nodejs/node/pull/66295
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
2026-09-27 18:47:26 +00:00
Brian Muenzenmeyer 37d5c80f97 build: toggle doc-kit verbosity based on V
Signed-off-by: bmuenzenmeyer <brian.muenzenmeyer@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66293
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
2026-09-27 18:29:58 +00:00
Filip Skokan a2a064c76a test: split FFI call and callback coverage
Isolate each callback abort scenario so timeouts identify the failing
case. Consolidate callback GC coverage in the weakref test and disable
core dumps for intentional aborts on POSIX.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: https://github.com/nodejs/node/pull/66287
Reviewed-By: Daeyeon Jeong <daeyeon.dev@gmail.com>
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
2026-09-27 14:54:18 +00:00
Filip Skokan 5137638062 tools: check CI availability and workload
Select mergeable PRs and check Jenkins availability and workload before
removing request labels. Leave requests for a later run when Jenkins is
unavailable or the workload has reached the configured limit.

Make the batch size and workload limit repository variables, defaulting
to 5 and 10 respectively.

Refs: https://github.com/nodejs/node-core-utils/pull/1204
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: https://github.com/nodejs/node/pull/66280
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
2026-09-27 12:34:10 +00:00
Donghoon Kang c97bbfb2e7 benchmark: remove duplicate ffi string length direct
Signed-off-by: HoonDongKang <d159123@naver.com>
PR-URL: https://github.com/nodejs/node/pull/66278
Reviewed-By: Daeyeon Jeong <daeyeon.dev@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
2026-09-27 12:05:50 +00:00
Marco 3641c36af1 watch: detect files replaced via unlink and create
Signed-off-by: marcopiraccini <marco.piraccini@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/63888
Fixes: https://github.com/nodejs/node/issues/51621
Refs: https://github.com/nodejs/node/issues/54774
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
2026-09-27 09:36:07 +00:00
James M Snell 2ce7a73fec perf_hooks: fix truncation of monitorEventLoopDelay() resolution
`IntervalHistogram` stored the interval as `int32_t`, so a resolution
above 2^31 - 1 ms wrapped: `resolution: 2 ** 32 + 1` sampled every
millisecond.

Signed-off-by: James M Snell <jasnell@gmail.com>
Assisted-by: OpenCode
PR-URL: https://github.com/nodejs/node/pull/66115
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
2026-09-27 08:10:15 +00:00
Matteo Collina 0519f500b4 http: cache parser callbacks
Cache the per-message callback lookups on the parser's JS object instead
of retaining callback functions in strong v8::Global handles. A callback
that captures its parser can otherwise keep the parser alive.

Clear the cache when a parser is initialized or freed so reused parsers
can load replacement callbacks and idle parsers do not retain them.
Header field names remain non-internalized because they are supplied by
clients.

Assisted-by: pi
Signed-off-by: Matteo Collina <hello@matteocollina.com>
PR-URL: https://github.com/nodejs/node/pull/66152
Reviewed-By: Robert Nagy <ronagy@icloud.com>
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Tim Perry <pimterry@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
2026-09-27 08:10:01 +00:00
Yuya Inoue 55e966fbe2 build: support LIEF 0.17.x and 1.x
Keep bundled LIEF at 0.17.0 while selecting the Mach-O section API
from the headers in use and the bundled build settings by version.
Prepare the updater for Mbed TLS 4 and TF-PSA-Crypto so the vendor
update can land separately.

Assisted-by: Codex
Signed-off-by: inoway46 <inoueyuya416@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66240
Fixes: https://github.com/nodejs/node/issues/66238
Refs: https://github.com/nodejs/node/pull/66242
Refs: https://github.com/nodejs/node/issues/63530
Refs: https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/360
Refs: https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/342
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
2026-09-27 08:09:47 +00:00
Ali Hassan 7d79ed37de sea: add test and update docs for import() with code cache
Signed-off-by: Ali Hassan <ali-hassan27@outlook.com>
PR-URL: https://github.com/nodejs/node/pull/62678
Reviewed-By: Joyee Cheung <joyeec9h3@gmail.com>
2026-09-27 06:56:43 +00:00
agape1225 cf0434f59c typings: wire up spawn_sync internal binding types
Signed-off-by: agape1225 <49804691+agape1225@users.noreply.github.com>
PR-URL: https://github.com/nodejs/node/pull/65996
Reviewed-By: Daeyeon Jeong <daeyeon.dev@gmail.com>
2026-09-27 03:54:54 +00:00
Antoine du Hamel 14e8f5bca4 tools: enable temporal by default in Nix integration
So we can test it with `test-shared.yml`.

Signed-off-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66267
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
2026-09-26 22:45:17 +00:00
Lazizbek Ergashev cd908df27f worker: add Symbol.toStringTag to BroadcastChannel
Signed-off-by: Lazizbek Ergashev <lazerg2@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65532
Fixes: https://github.com/nodejs/node/issues/65527
Reviewed-By: James M Snell <jasnell@gmail.com>
2026-09-27 00:37:26 +02:00
Lazizbek Ergashev b456adbcd6 worker: add Symbol.toStringTag to MessageChannel and MessagePort
Signed-off-by: Lazizbek Ergashev <lazerg2@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65532
Fixes: https://github.com/nodejs/node/issues/65527
Reviewed-By: James M Snell <jasnell@gmail.com>
2026-09-27 00:37:25 +02:00
Matteo Collina 7ff62671a5 stream: keep consumer state in fast mode
Create null-prototype share and broadcast consumer state with fast
   properties instead of V8 dictionary properties.

Assisted-by: Pi
Signed-off-by: Matteo Collina <hello@matteocollina.com>
PR-URL: https://github.com/nodejs/node/pull/66266
Reviewed-By: Mattias Buelens <mattias@buelens.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
2026-09-26 21:43:46 +00:00
James M Snell 147ade5ff9 test: deflake sliding window histogram test
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66132
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
2026-09-26 21:18:48 +00:00
James M Snell d1960949bb benchmark: protect against accidental fork bomb
Signed-off-by: James M Snell <jasnell@gmail.com>
Assisted-by: Opencode
PR-URL: https://github.com/nodejs/node/pull/66132
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
2026-09-26 21:18:45 +00:00
James M Snell f378cfcfbf src,lib: add --allow-env permission
Necessarily semver-major.

When `--permission` is on, every env var not matched by
`--allow-env` is removed at startup. It takes names,
prefix patterns (`PREFIX_*`), or `*`, repeatable or
comma-sep'd.

There are a range of env vars that Node.js itself uses,
and a default range that are generally known to be safe
in common usage. These are never scrubbed. These include
things like `NODE_OPTIONS`, `NODE_EXTRA_CA_CERTS`, `PATH`,
`HOME`, etc. `NODE_ENV` is not in the defaults and must
be allowed explicitly.

Proxy vars (`HTTP_PROXY`, `HTTPS_PROXY`, `NO_PROXY`) are
also not in the defaults since they can carry credentials.
When `--use-env-proxy` or `NODE_USE_ENV_PROXY` is set and
any of them were removed, a single warning naming them is
emitted.

Env vars can be dropped at runtime after reading using
`permission.drop()`. This is a stronger protection than
using `process.env.FOO = undefined` because it will
scrub the env var also from the environment block.

On Linux, the removed entries are overwritten in the
initial environment block. fs reads of any other
process's /proc/<pid>/environ, ancestors included, are
denied regardless of `--allow-fs-read`. A process's own
is readable only with `--allow-env=*`. Symlinks are
resolved before the check so paths like
/dev/fd/../../<ppid>/environ are caught. The check only
canonicalizes paths that statfs() reports are on procfs.

On Windows, removal also clears the C runtime's copy
of the environ using _wputenv_s.

Reading a removed name returns undefined, warns once per
name, and publishes to a diagnostics channel.

Env file keys are allowed. If the user had reason to pass
in an env file the assumption is they meant to allow them.

File-source config (node.config.json and NODE_OPTIONS
from a .env file) can only narrow the allow list.

Embedders must call ScrubProcessEnvironment() themselves
on startup. This is left up to the embedder to determine
the exact timing but needs to be called before startup
actually happens.

Child processes are started with `--allow-env=*`. Those
either receive the explicit env they were started with
or only the env they inherit from the parent. Since the
parent process is scrubbed, and the child cannot read
any other process's /proc/<pid>/environ, it should never
see more than the parent can.

Main part of the impl was done by hand. Docs, tests,
verification pass, and cleanup nits were automated.

Signed-off-by: James M Snell <jasnell@gmail.com>
Assisted-by: Opencode
PR-URL: https://github.com/nodejs/node/pull/66132
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
2026-09-26 21:18:43 +00:00
Lazizbek Ergashev 261c8a196c events: fix addAbortListener for aborted signals
Signed-off-by: Lazizbek Ergashev <lazerg2@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65640
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Robert Nagy <ronagy@icloud.com>
2026-09-26 20:55:09 +00:00
Ilyas Shabi cf072ab0cd src: expose size and count in heap profile output
Signed-off-by: ishabi <ilyasshabi94@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65737
Reviewed-By: Anna Henningsen <anna@addaleax.net>
2026-09-26 20:46:13 +00:00
Yagiz NizipliandYagiz Nizipli 6a6e09e834 querystring: speed up default parse and unescape
Skip the %XX walk in unescapeBuffer when the input has no '%'.
Add a dedicated '&'/'=' scanner for the default parse path so
it does not build separator code arrays or run the multi-char
state machine.

Official benchmark/querystring/querystring-parse.js:
encodemany is about 38% faster, manyblankpairs about 17%,
encodelast about 10%, noencode about 8%.
Official querystring-unescapebuffer.js with no escapes is
about 36% faster.

Assisted-by: a closed-source coding agent
Signed-off-by: Yagiz Nizipli <yagiz@nizipli.com>
Co-authored-by: Yagiz Nizipli <anonrig@users.noreply.github.com>
PR-URL: https://github.com/nodejs/node/pull/66175
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
2026-09-26 20:34:53 +00:00
Maya Lekova d35c89e03d test: add smoke tests for defer importing synthetic modules
The tests added ensure that Node.js doesn't crash or produce
incorrect results when importing synthetic modules (i.e. JSON,
text or builtin modules) with the `defer` modifier.

Signed-off-by: Maya Lekova <maya@igalia.com>
PR-URL: https://github.com/nodejs/node/pull/65537
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Joyee Cheung <joyeec9h3@gmail.com>
2026-09-26 19:53:05 +00:00
Christian Aurich Zanettini Martins 1e17275dea fs: fix crash on negative zero file descriptor
`isInt32()` accepts -0 because `-0 === (-0 | 0)`, but V8 does not
represent -0 as an Int32 value, so `Value::IsInt32()` rejects it. The
utf8 fast paths of `readFileSync()` and `writeFileSync()` hand the value
straight to the binding, which then took it for a path and aborted on
the null check.

Coerce -0 to 0 before the call, matching `getValidatedFd()` and the rest
of fs, where -0 is a valid way to name file descriptor 0.

Signed-off-by: Christian Aurich <christian.aurichzm@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65888
Fixes: https://github.com/nodejs/node/issues/65886
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
2026-09-26 19:52:53 +00:00
Dayun d9208ccdcc worker: remove messageerror listeners on exit
Signed-off-by: Dayun <dlekdbs6530@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66075
Fixes: https://github.com/nodejs/node/issues/65782
Reviewed-By: James M Snell <jasnell@gmail.com>
2026-09-26 19:42:29 +00:00
Dayun 31e841f056 stream: fix pipeline function tail deadlock
Signed-off-by: Dayun <dlekdbs6530@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65559
Fixes: https://github.com/nodejs/node/issues/40685
Reviewed-By: Robert Nagy <ronagy@icloud.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
2026-09-26 19:32:45 +00:00