Backport upgrade diagnostics lifecycle fixes to v7.x - #5783
Merged
Merged
Conversation
Successful CONNECT and protocol upgrades stop before Undici marks the request complete. Diagnostics subscribers retain per-request state, and streamed request-body listeners remain attached for the lifetime of the upgraded socket. Publish the existing headers and trailers lifecycle around accepted upgrades. Abort instead when the application upgrade handler throws so subscribers always receive a terminal event. Signed-off-by: Ruben Bridgewater <ruben.bridgewater@datadoghq.com>
Accepted upgrades run the user handler after H1 hands off its socket and H2 assigns stream cleanup. Request-level error handling replaced H1 exceptions and rethrew H2 exceptions outside their transport owners.
v7 converts HTTP/2 upgrade headers to raw buffer pairs and uses separate response callbacks for WebSocket and CONNECT. Count each stream at creation so a thrown handler cannot leave the session referenced.
BridgeAR
marked this pull request as ready for review
September 7, 2026 14:24
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## v7.x #5783 +/- ##
=======================================
Coverage 93.11% 93.12%
=======================================
Files 112 112
Lines 37108 37139 +31
=======================================
+ Hits 34554 34584 +30
- Misses 2554 2555 +1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
metcoder95
approved these changes
Sep 10, 2026
3 of 7 tasks
mcollina
pushed a commit
that referenced
this pull request
Sep 17, 2026
* fix: complete upgrade diagnostics lifecycle Successful CONNECT and protocol upgrades stop before Undici marks the request complete. Diagnostics subscribers retain request state, and streamed request-body listeners remain attached to the upgraded socket. Publish the existing response lifecycle around accepted upgrades. Preserve the early HTTP/2 CONNECT handoff in v6, and terminate diagnostics if the stream fails before its response. Refs: #5783 Signed-off-by: Ruben Bridgewater <ruben.bridgewater@datadoghq.com> * fix: preserve abort after upgrade handoff Completing upgrade requests suppresses late request errors, but v6 retains the abort callback as the transport cleanup owner after handoff. Returning early leaves upgraded sockets and HTTP/2 CONNECT streams open. Signed-off-by: Ruben Bridgewater <ruben.bridgewater@datadoghq.com> --------- Signed-off-by: Ruben Bridgewater <ruben.bridgewater@datadoghq.com>
Merged
meta-codesync Bot
pushed a commit
to facebook/memlab
that referenced
this pull request
Sep 29, 2026
Summary: Bumps [[ https://github.com/nodejs/undici | undici ]] from 7.29.0 to 7.30.0 in the memlab `website/` workspace. `yarn.lock` change only; it also picks up the 7.29.1 security release. **v7.30.0** - fix: selectively re-enable SIMD for ppc64 ([[ nodejs/undici#5794 | #5794 ]]) - Backport upgrade diagnostics lifecycle fixes ([[ nodejs/undici#5783 | #5783 ]]) - fix: honor backpressure in the decompression interceptor ([[ nodejs/undici#5837 | #5837 ]]) - fix: close rejected HTTP/2 WebSocket streams ([[ nodejs/undici#5876 | #5876 ]]) - test(fetch): make pull-dont-push exceed any socket buffer ([[ nodejs/undici#5889 | #5889 ]]) **v7.29.1 — security fixes** High severity: - [[ GHSA-w293-vg96-wgc3 | GHSA-w293-vg96-wgc3 ]]: `BalancedPool` could drop function-valued connection options, including custom TLS certificate validation callbacks, when cloning its configuration - [[ GHSA-rfgv-xxqx-mfg5 | GHSA-rfgv-xxqx-mfg5 ]]: a WebSocket server selecting a subprotocol when none was requested caused an uncaught `TypeError` that could terminate the process Medium severity: - [[ GHSA-3wwx-pv8p-q78v | GHSA-3wwx-pv8p-q78v ]]: a permessage-deflate payload over the decompression limit could emit an unhandled zlib error and terminate the process - [[ GHSA-rx4f-c7p8-82vq | GHSA-rx4f-c7p8-82vq ]]: an unclean `WebSocketStream` close with a locked writable stream could create an unobserved rejected promise - [[ GHSA-2jfj-6hjv-fm6j | GHSA-2jfj-6hjv-fm6j ]]: shared caches could store and replay responses containing `Set-Cookie`, disclosing one user's cookies to another caller - [[ GHSA-3xpg-4rpp-hhhm | GHSA-3xpg-4rpp-hhhm ]]: the decompression interceptor did not bound decoded output; every stage is now limited to 64 MiB by default, configurable via `maxSize` - [[ GHSA-pmjh-fq2x-6v4x | GHSA-pmjh-fq2x-6v4x ]]: a terminal retry failure after response headers were exposed could orphan the response body and hang consumers Low severity: - [[ GHSA-8436-99hf-9mmv | GHSA-8436-99hf-9mmv ]]: cache interceptors could store and replay responses to unsafe methods such as `POST` or `DELETE` - [[ GHSA-2gqq-gqf2-x968 | GHSA-2gqq-gqf2-x968 ]]: the dump interceptor could treat an oversized chunked response without `Content-Length` as successfully truncated - [[ GHSA-r53p-7pc4-xj5r | GHSA-r53p-7pc4-xj5r ]]: the retry interceptor could concatenate a resumed response with inconsistent framing, enabling response splitting or corruption **v7.29.1 — other changes** - fix(h2): honour `headersTimeout` ([[ nodejs/undici#5604 | #5604 ]]) - fix(h2): keep the connection ref'd while requests are outstanding ([[ nodejs/undici#5605 | #5605 ]]) - fix(h2): retire the request that completed, not the head of the queue ([[ nodejs/undici#5618 | #5618 ]]) - fix(h2): settle a request whose stream is cancelled ([[ nodejs/undici#5607 | #5607 ]]) - fix(h2): handle GOAWAY for CONNECT streams ([[ nodejs/undici#5640 | #5640 ]]) - perf: reduce `EventSourceStream` parser allocations ([[ nodejs/undici#5646 | #5646 ]]) - perf(h1): drop the idle-socket timer floor with a ref'd `setImmediate` ([[ nodejs/undici#5769 | #5769 ]]) - CI only: drop Node.js 26 from the shared-builtin build ([[ nodejs/undici#5592 | #5592 ]]); raise the Windows workflow timeout ([[ nodejs/undici#5621 | #5621 ]]) Full changelog: [[ nodejs/undici@v7.29.0...v7.30.0 | v7.29.0...v7.30.0 ]] Opened by Dependabot. Comment `dependabot rebase` on the GitHub PR to resolve conflicts; do not hand-edit the PR branch. Pull Request resolved: #155 Differential Revision: D122269178 Pulled By: JacksonGL fbshipit-source-id: 56fb568c08248253c483c6b44b1175af4a6b6d0c
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This relates to...
Backport of #5761 to
v7.x.Rationale
Successful CONNECT and protocol upgrades do not publish terminal request diagnostics. This retains subscriber state and request-body listeners for the upgraded socket lifetime.
Changes
Bug Fixes
Breaking Changes and Deprecations
N/A
Status