Skip to content

fix: honor backpressure in decompression interceptor - #5829

Merged
mcollina merged 2 commits into
mainfrom
fix/decompress-backpressure
Sep 16, 2026
Merged

mcollina merged 2 commits into
mainfrom
fix/decompress-backpressure

Conversation

@mcollina

@mcollina mcollina commented Sep 15, 2026 •

Copy link
Copy Markdown
Member

I made a mess of the original GHSA fix by treating a stream backpressure bug as a response-size policy decision.

A 64 MiB limit answers a different question: how large a decoded response an application is willing to accept. It also rejects legitimate responses that can be consumed safely as streams. The correct fix is to honor the stream contract: stop pulling decoded output when the consumer pauses, propagate writable pressure from the decoder back to the transport, keep those pause reasons independent across retries, and wait to signal completion until the consumer resumes.

maxSize still exists as an opt-in per-stage circuit breaker. It now defaults to 0, leaving size policy to applications while backpressure keeps buffering tied to consumer demand.

Signed-off-by: Matteo Collina <hello@matteocollina.com>
Signed-off-by: Matteo Collina <hello@matteocollina.com>
@codecov-commenter

codecov-commenter commented Sep 15, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.63566% with 19 lines in your changes missing coverage. Please review.
✅ Project coverage is 93.48%. Comparing base (fb3d786) to head (409b1f4).
⚠️ Report is 7 commits behind head on main.

Files with missing lines Patch % Lines
lib/interceptor/decompress.js 91.66% 19 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #5829      +/-   ##
==========================================
- Coverage   93.50%   93.48%   -0.03%     
==========================================
  Files         110      110              
  Lines       39557    39755     +198     
==========================================
+ Hits        36987    37163     +176     
- Misses       2570     2592      +22     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollina
mcollina merged commit 19901d8 into main Sep 16, 2026
68 of 69 checks passed
@mcollina
mcollina deleted the fix/decompress-backpressure branch September 16, 2026 13:41
@github-actions

Copy link
Copy Markdown
Contributor

The backport to v7.x failed:

The process '/usr/bin/git' failed with exit code 1

To backport manually, run these commands in your terminal:

# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add .worktrees/backport-v7.x v7.x
# Navigate to the new working tree
cd .worktrees/backport-v7.x
# Create a new branch
git switch --create backport-5829-to-v7.x
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 19901d8b73cb46a48e817dab4afce790f37fd2c1
# Push it to GitHub
git push --set-upstream origin backport-5829-to-v7.x
# Go back to the original working tree
cd ../..
# Delete the working tree
git worktree remove .worktrees/backport-v7.x

Then, create a pull request where the base branch is v7.x and the compare/head branch is backport-5829-to-v7.x.

mcollina added a commit that referenced this pull request Sep 21, 2026
* fix: honor decompression backpressure



* fix(decompress): disable size limit by default



---------


(cherry picked from commit 19901d8)

Signed-off-by: Matteo Collina <hello@matteocollina.com>
This was referenced Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants