Skip to content

Backport upgrade diagnostics lifecycle fixes to v7.x - #5783

Merged
mcollina merged 3 commits into
v7.xfrom
BridgeAR/2026-09-04-backport-5761-v7
Sep 13, 2026
Merged

mcollina merged 3 commits into
v7.xfrom
BridgeAR/2026-09-04-backport-5761-v7

Conversation

@BridgeAR

@BridgeAR BridgeAR commented Sep 7, 2026

Copy link
Copy Markdown
Member

This relates to...

Backport of #5761 to v7.x.

Rationale

Successful CONNECT and protocol upgrades do not publish terminal request diagnostics. This retains subscriber state and request-body listeners for the upgraded socket lifetime.

Changes

Bug Fixes

  • Publish response headers and empty trailers for accepted upgrades.
  • Preserve upgrade handler errors through the H1 and H2 transport owners.
  • Preserve v7's raw-buffer header type and balance H2 stream accounting before handler callbacks.

Breaking Changes and Deprecations

N/A

Status

Successful CONNECT and protocol upgrades stop before Undici marks the request complete. Diagnostics subscribers retain per-request state, and streamed request-body listeners remain attached for the lifetime of the upgraded socket.

Publish the existing headers and trailers lifecycle around accepted upgrades. Abort instead when the application upgrade handler throws so subscribers always receive a terminal event.

Signed-off-by: Ruben Bridgewater <ruben.bridgewater@datadoghq.com>
Accepted upgrades run the user handler after H1 hands off its socket and H2 assigns stream cleanup. Request-level error handling replaced H1 exceptions and rethrew H2 exceptions outside their transport owners.
v7 converts HTTP/2 upgrade headers to raw buffer pairs and uses separate response callbacks for WebSocket and CONNECT. Count each stream at creation so a thrown handler cannot leave the session referenced.
@BridgeAR
BridgeAR marked this pull request as ready for review September 7, 2026 14:24
@BridgeAR
BridgeAR requested review from mcollina and ronag September 7, 2026 14:24
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.12%. Comparing base (d39a83e) to head (3af2365).

Additional details and impacted files
@@           Coverage Diff           @@
##             v7.x    #5783   +/-   ##
=======================================
  Coverage   93.11%   93.12%           
=======================================
  Files         112      112           
  Lines       37108    37139   +31     
=======================================
+ Hits        34554    34584   +30     
- Misses       2554     2555    +1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollina mcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@mcollina
mcollina merged commit a7914e5 into v7.x Sep 13, 2026
37 checks passed
@mcollina
mcollina deleted the BridgeAR/2026-09-04-backport-5761-v7 branch September 13, 2026 19:15
mcollina pushed a commit that referenced this pull request Sep 17, 2026
* fix: complete upgrade diagnostics lifecycle

Successful CONNECT and protocol upgrades stop before Undici marks the request complete. Diagnostics subscribers retain request state, and streamed request-body listeners remain attached to the upgraded socket.

Publish the existing response lifecycle around accepted upgrades. Preserve the early HTTP/2 CONNECT handoff in v6, and terminate diagnostics if the stream fails before its response.

Refs: #5783
Signed-off-by: Ruben Bridgewater <ruben.bridgewater@datadoghq.com>

* fix: preserve abort after upgrade handoff

Completing upgrade requests suppresses late request errors, but v6 retains the abort callback as the transport cleanup owner after handoff. Returning early leaves upgraded sockets and HTTP/2 CONNECT streams open.

Signed-off-by: Ruben Bridgewater <ruben.bridgewater@datadoghq.com>

---------

Signed-off-by: Ruben Bridgewater <ruben.bridgewater@datadoghq.com>
@github-actions github-actions Bot mentioned this pull request Sep 24, 2026
meta-codesync Bot pushed a commit to facebook/memlab that referenced this pull request Sep 29, 2026
Summary:
Bumps [[ https://github.com/nodejs/undici | undici ]] from 7.29.0 to 7.30.0 in the memlab `website/` workspace. `yarn.lock` change only; it also picks up the 7.29.1 security release.

**v7.30.0**
- fix: selectively re-enable SIMD for ppc64 ([[ nodejs/undici#5794 | #5794 ]])
- Backport upgrade diagnostics lifecycle fixes ([[ nodejs/undici#5783 | #5783 ]])
- fix: honor backpressure in the decompression interceptor ([[ nodejs/undici#5837 | #5837 ]])
- fix: close rejected HTTP/2 WebSocket streams ([[ nodejs/undici#5876 | #5876 ]])
- test(fetch): make pull-dont-push exceed any socket buffer ([[ nodejs/undici#5889 | #5889 ]])

**v7.29.1 — security fixes**

High severity:
- [[ GHSA-w293-vg96-wgc3 | GHSA-w293-vg96-wgc3 ]]: `BalancedPool` could drop function-valued connection options, including custom TLS certificate validation callbacks, when cloning its configuration
- [[ GHSA-rfgv-xxqx-mfg5 | GHSA-rfgv-xxqx-mfg5 ]]: a WebSocket server selecting a subprotocol when none was requested caused an uncaught `TypeError` that could terminate the process

Medium severity:
- [[ GHSA-3wwx-pv8p-q78v | GHSA-3wwx-pv8p-q78v ]]: a permessage-deflate payload over the decompression limit could emit an unhandled zlib error and terminate the process
- [[ GHSA-rx4f-c7p8-82vq | GHSA-rx4f-c7p8-82vq ]]: an unclean `WebSocketStream` close with a locked writable stream could create an unobserved rejected promise
- [[ GHSA-2jfj-6hjv-fm6j | GHSA-2jfj-6hjv-fm6j ]]: shared caches could store and replay responses containing `Set-Cookie`, disclosing one user's cookies to another caller
- [[ GHSA-3xpg-4rpp-hhhm | GHSA-3xpg-4rpp-hhhm ]]: the decompression interceptor did not bound decoded output; every stage is now limited to 64 MiB by default, configurable via `maxSize`
- [[ GHSA-pmjh-fq2x-6v4x | GHSA-pmjh-fq2x-6v4x ]]: a terminal retry failure after response headers were exposed could orphan the response body and hang consumers

Low severity:
- [[ GHSA-8436-99hf-9mmv | GHSA-8436-99hf-9mmv ]]: cache interceptors could store and replay responses to unsafe methods such as `POST` or `DELETE`
- [[ GHSA-2gqq-gqf2-x968 | GHSA-2gqq-gqf2-x968 ]]: the dump interceptor could treat an oversized chunked response without `Content-Length` as successfully truncated
- [[ GHSA-r53p-7pc4-xj5r | GHSA-r53p-7pc4-xj5r ]]: the retry interceptor could concatenate a resumed response with inconsistent framing, enabling response splitting or corruption

**v7.29.1 — other changes**
- fix(h2): honour `headersTimeout` ([[ nodejs/undici#5604 | #5604 ]])
- fix(h2): keep the connection ref'd while requests are outstanding ([[ nodejs/undici#5605 | #5605 ]])
- fix(h2): retire the request that completed, not the head of the queue ([[ nodejs/undici#5618 | #5618 ]])
- fix(h2): settle a request whose stream is cancelled ([[ nodejs/undici#5607 | #5607 ]])
- fix(h2): handle GOAWAY for CONNECT streams ([[ nodejs/undici#5640 | #5640 ]])
- perf: reduce `EventSourceStream` parser allocations ([[ nodejs/undici#5646 | #5646 ]])
- perf(h1): drop the idle-socket timer floor with a ref'd `setImmediate` ([[ nodejs/undici#5769 | #5769 ]])
- CI only: drop Node.js 26 from the shared-builtin build ([[ nodejs/undici#5592 | #5592 ]]); raise the Windows workflow timeout ([[ nodejs/undici#5621 | #5621 ]])

Full changelog: [[ nodejs/undici@v7.29.0...v7.30.0 | v7.29.0...v7.30.0 ]]

Opened by Dependabot. Comment `dependabot rebase` on the GitHub PR to resolve conflicts; do not hand-edit the PR branch.

Pull Request resolved: #155

Differential Revision: D122269178

Pulled By: JacksonGL

fbshipit-source-id: 56fb568c08248253c483c6b44b1175af4a6b6d0c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants