Skip to content

Backport #4443: fix(core): serialize a DataView as its viewed bytes - #4477

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-4443-to-stable
Sep 29, 2026
Merged

TooTallNate merged 1 commit into
stablefrom
backport/pr-4443-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #4443 to stable (backport job run).

AI recommendation: This fixes a real data-leak defect: without a DataView reducer, devalue's built-in encoding persists the entire backing ArrayBuffer, which for Node's pooled Buffer allocator means unrelated process memory (including uninitialized allocUnsafe residue) is written into the run's event log. I verified the bug exists on stable: packages/core/src/serialization.ts there has typed-array reducers but no DataView entry, so a DataView falls through the same way. The change is a fix rather than feature work — DataView was already serializable, just leaking — and it is deliberately backward compatible via a distinct DataViewBytes tag, though the cherry-pick will need rework since stable has a single serialization.ts instead of the serialization/reducers/ split and has no quickjs-serde.ts.

Merge conflicts were resolved by AI (opencode with anthropic/claude-opus-5). Please review the conflict resolution carefully before merging.

* fix(core): serialize a DataView as its viewed bytes

`DataView` had no reducer, so it fell through to devalue's built-in
encoding: the whole backing `ArrayBuffer` plus the view's offset and
length. Node hands out small `Buffer`s as windows onto a shared 8 KiB
pool, so a four-byte `DataView` over a `Buffer.allocUnsafe(4)`
serialized 8 KiB of unrelated allocations — and step returns are
written to the run's event log, where that residue outlives the
process that leaked it.

Add a `DataView` reducer alongside the typed-array ones, base64 of the
viewed range only, in all three reducer sets that share the wire
format (host, VM twin, QuickJS handle-space) so a value round-trips
identically whichever side serializes it.

Revivers accept a non-string payload as well: devalue hands a custom
reviver the hydrated referent, so a pre-reducer payload arrives as the
backing `ArrayBuffer` rather than base64. Without that branch, old
event logs would decode an `ArrayBuffer` as if it were base64 (or
throw, in the `atob` implementations).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

Co-Authored-By: Nathan Rajlich <71256+TooTallNate@users.noreply.github.com>

* fix(core): emit the new DataView encoding under its own tag

Registering a custom reviver for `DataView` took devalue's built-in
parse branch out of reach, and with it the bounds that branch restores
from `["DataView", buf, offset, length]`. Those tuples are already in
event logs, and the o11y UI and CLI read them with current code — so
the previous commit made them render the whole pooled slab where `main`
renders the few viewed bytes, surfacing exactly the residue it exists
to keep out of new logs.

Emit the base64 form under `DataViewBytes` instead and register no
`DataView` reviver anywhere. Old payloads keep taking the built-in
branch with their bounds in every reader (QuickJS's `fromViewInfo`
already handles the tag), new payloads still carry only the viewed
range, and the four "accept an ArrayBuffer too" reviver branches and
their helpers go away. A payload written under the new tag remains
unreadable by an older SDK, as it was before, but now fails with
`Unknown type DataViewBytes` rather than a TypeError.

Tests pin both directions: a legacy tuple revives as its recorded
[2, 3] with byteOffset 1 / byteLength 2, and no reducer or reviver set
claims the `DataView` tag.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

Co-Authored-By: Nathan Rajlich <71256+TooTallNate@users.noreply.github.com>

---------

Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Nathan Rajlich <71256+TooTallNate@users.noreply.github.com>
@changeset-bot

changeset-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4f05621

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
Name Type
@workflow/core Patch
@workflow/web-shared Patch
@workflow/cli Patch
@workflow/builders Patch
@workflow/next Patch
@workflow/nitro Patch
@workflow/vitest Patch
@workflow/web Patch
workflow Patch
@workflow/world-testing Patch
@workflow/astro Patch
@workflow/nest Patch
@workflow/rollup Patch
@workflow/sveltekit Patch
@workflow/vite Patch
@workflow/nuxt Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
example-nextjs-workflow-turbopack Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
example-nextjs-workflow-webpack Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
example-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workbench-astro-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workbench-express-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workbench-fastify-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workbench-hono-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workbench-nestjs-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workbench-nitro-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workbench-nuxt-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workbench-python-workflow Error Error v0 Sep 29, 2026 4:47pm UTC
workbench-sveltekit-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workbench-tanstack-start-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workbench-vite-workflow Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workflow-docs Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workflow-swc-playground Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workflow-tarballs Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC
workflow-web Ready Ready Preview, v0 Sep 29, 2026 4:47pm UTC

@TooTallNate
TooTallNate enabled auto-merge (squash) September 29, 2026 17:24
@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor Author

🧪 E2E Test Results

❌ Some tests failed

Summary

Passed Failed Skipped Total
✅ ▲ Vercel Production 1099 0 78 1177
✅ 💻 Local Development 1198 0 86 1284
✅ 📦 Local Production 1198 0 86 1284
✅ 🐘 Local Postgres 1198 0 86 1284
✅ 🪟 Windows 107 0 0 107
❌ 🌍 Community Worlds 82 106 9 197
✅ 📋 Other 606 0 36 642
Total 5488 106 381 5975

❌ Failed Tests

🌍 Community Worlds (106 failed)

redis (21 failed):

  • hookWorkflow | wrun_01M3Q37TBZYYKXXDTCVDMR0Z8F
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01M3Q381Z97EFKTFDPG70RVKWH
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01M3Q38BZPYVTQ8H6HVBCF05V6
  • sleepingWorkflow | wrun_01M3Q39AT3CN45F6GAQ3T0MQZZ
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • error handling serialization failures step-argument serialization failure is catchable in workflow code
  • error handling serialization failures uncaught step-argument serialization failure fails the run as USER_ERROR without redelivery retries
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01M3Q3H31RBNG4F0MY8TCPQAFE
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01M3Q3HE2MA3SXD3SBVN0E2KWM
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01M3Q3HMR78STN8S8AJQ14W8M1
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01M3Q3J1KJG4BJM19CB5G400J3
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01M3Q3JTBD3HTWN3W5MA4S8964
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01M3Q3JX9VV3ZSXQ54Y0N5E363
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01M3Q3K2GK0QD1S066AC3WVKW8
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01M3Q3K7GBRMKR2C17FBD7G16Q
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01M3Q3KFN176P777B6PNT373AA
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01M3Q3RHKG3P6CK9T7BG0TPS05

turso (85 failed):

  • addTenWorkflow | wrun_01M3Q36VQFP2NHRMEABZZM7K3H
  • addTenWorkflow | wrun_01M3Q36VQFP2NHRMEABZZM7K3H
  • deploymentId: 'latest' is a no-op in non-Vercel worlds
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01M3Q377NK0YBCGV1NKHJG08X0
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01M3Q3724RCSN26MR2G465G98N
  • promiseRaceWorkflow | wrun_01M3Q376J4S7FG100YX6CVQKY4
  • promiseAnyWorkflow | wrun_01M3Q378HPYWGYGN103845B9GN
  • importedStepOnlyWorkflow | wrun_01M3Q37KJPEYVPJ8N57K8X1FEJ
  • readableStreamWorkflow | wrun_01M3Q37AJ4B9C6Z5FVJK6VBEB5
  • hookWorkflow | wrun_01M3Q37TBZYYKXXDTCVDMR0Z8F
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01M3Q381Z97EFKTFDPG70RVKWH
  • webhookWorkflow | wrun_01M3Q385V22G1TR4Y2HKW17HDA
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01M3Q38BZPYVTQ8H6HVBCF05V6
  • sleepingWorkflow | wrun_01M3Q39AT3CN45F6GAQ3T0MQZZ
  • parallelSleepWorkflow | wrun_01M3Q39TERNJSA0GSB1HRQ8P0N
  • sleepWinsRaceWorkflow | wrun_01M3Q39XSQE1H32Z4K1JBP0H1Z
  • stepWinsRaceWorkflow | wrun_01M3Q3A11165STSR2HS2WXHK73
  • nullByteWorkflow | wrun_01M3Q3A4JFVF2F0JJVNSV0X5FR
  • workflowAndStepMetadataWorkflow | wrun_01M3Q3A6KE3J2AF454MYCAXGRZ
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01M3Q3CEPW3D7VW32P0W8BXW90
  • writableForwardedFromWorkflowWorkflow | wrun_01M3Q3CV7FQY97G4M5Z48QJCGG
  • writableForwardedFromStepWorkflow | wrun_01M3Q3CYH7RXJWFB448Z0EKVM0
  • fetchWorkflow | wrun_01M3Q3D13HBTH77DK8GZE622BT
  • promiseRaceStressTestWorkflow | wrun_01M3Q3D49MC6Q0TSSFHPH74703
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling serialization failures step-argument serialization failure is catchable in workflow code
  • error handling serialization failures uncaught step-argument serialization failure fails the run as USER_ERROR without redelivery retries
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01M3Q3GR0JD4HZ4W0P8WH9BNQM
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01M3Q3H31RBNG4F0MY8TCPQAFE
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01M3Q3HE2MA3SXD3SBVN0E2KWM
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01M3Q3HGB3TE3CJPPK2R4RGJ6B
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01M3Q3HJHBB4Z7S9R7AFYY56JY
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01M3Q3HMR78STN8S8AJQ14W8M1
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01M3Q3J1KJG4BJM19CB5G400J3
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01M3Q3JTBD3HTWN3W5MA4S8964
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01M3Q3JX9VV3ZSXQ54Y0N5E363
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01M3Q3K2GK0QD1S066AC3WVKW8
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01M3Q3K7GBRMKR2C17FBD7G16Q
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01M3Q3KFN176P777B6PNT373AA
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01M3Q3KPGQ4R1ZN6NSEMXYN1KN
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01M3Q3M4NKYPB9TF9SVN0TCNR8
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01M3Q3MCXG0Q546QN8DRNF19D1
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01M3Q3MJ4V8021H3X3QQ2YH1GK
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01M3Q3MM93MX5QQWFZSJ6M7VT5
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01M3Q3N1GHVE8EXXRHMAXVWY1F
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01M3Q3N6JB6ZYJHEPV66ZSFK0T
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01M3Q3NCQPTM41ZEA985F920H7
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01M3Q3NJWJ7QFCMG3HPK6TD6FN
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01M3Q3NRZJY3CSES4DSSSKPYZN
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01M3Q3NZ4F4HK7VVBGMCMEZ5YB
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01M3Q3P5H177RVZ0DC3CBY700Z
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01M3Q3PFXJ5JVTA2RTMYWTJ4ET
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01M3Q3PQCJKDBT3E9HZ7EYFGG9
  • cancelRun - cancelling a running workflow | wrun_01M3Q3PXX7WA4DGTSQ10Y70VJX
  • cancelRun via CLI - cancelling a running workflow | wrun_01M3Q3Q241FNG9Z36CQ3YDBYNN
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01M3Q3Q901AWJ648E2PXFPB556
  • hookWithSleepFinalStepWorkflow - step only on final payload | wrun_01M3Q3QMD02V88DTWYGYREQJ7M
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01M3Q3QW6307T6NC66QK34F7M7
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01M3Q3R6EY6CJM6KQT0C30GS3P
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01M3Q3RCZ9D0HTMSQBBPJY193A
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01M3Q3RF5CZJMT40RFW0JYS05B
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01M3Q3RHKG3P6CK9T7BG0TPS05

Details by Category

✅ ▲ Vercel Production
App Passed Failed Skipped
✅ astro 99 0 8
✅ example 99 0 8
✅ express 99 0 8
✅ fastify 99 0 8
✅ hono 99 0 8
✅ nextjs-turbopack 104 0 3
✅ nextjs-webpack 104 0 3
✅ nitro 99 0 8
✅ nuxt 99 0 8
✅ sveltekit 99 0 8
✅ vite 99 0 8
✅ 💻 Local Development
App Passed Failed Skipped
✅ astro-stable 101 0 6
✅ express-stable 101 0 6
✅ fastify-stable 101 0 6
✅ hono-stable 101 0 6
✅ nextjs-turbopack-canary 88 0 19
✅ nextjs-turbopack-stable 107 0 0
✅ nextjs-webpack-canary 88 0 19
✅ nextjs-webpack-stable 107 0 0
✅ nitro-stable 101 0 6
✅ nuxt-stable 101 0 6
✅ sveltekit-stable 101 0 6
✅ vite-stable 101 0 6
✅ 📦 Local Production
App Passed Failed Skipped
✅ astro-stable 101 0 6
✅ express-stable 101 0 6
✅ fastify-stable 101 0 6
✅ hono-stable 101 0 6
✅ nextjs-turbopack-canary 88 0 19
✅ nextjs-turbopack-stable 107 0 0
✅ nextjs-webpack-canary 88 0 19
✅ nextjs-webpack-stable 107 0 0
✅ nitro-stable 101 0 6
✅ nuxt-stable 101 0 6
✅ sveltekit-stable 101 0 6
✅ vite-stable 101 0 6
✅ 🐘 Local Postgres
App Passed Failed Skipped
✅ astro-stable 101 0 6
✅ express-stable 101 0 6
✅ fastify-stable 101 0 6
✅ hono-stable 101 0 6
✅ nextjs-turbopack-canary 88 0 19
✅ nextjs-turbopack-stable 107 0 0
✅ nextjs-webpack-canary 88 0 19
✅ nextjs-webpack-stable 107 0 0
✅ nitro-stable 101 0 6
✅ nuxt-stable 101 0 6
✅ sveltekit-stable 101 0 6
✅ vite-stable 101 0 6
✅ 🪟 Windows
App Passed Failed Skipped
✅ nextjs-turbopack 107 0 0
❌ 🌍 Community Worlds
App Passed Failed Skipped
✅ mongodb-dev 4 0 3
✅ redis-dev 4 0 3
❌ redis 67 21 0
✅ turso-dev 4 0 3
❌ turso 3 85 0
✅ 📋 Other
App Passed Failed Skipped
✅ e2e-local-dev-nest-stable 101 0 6
✅ e2e-local-dev-tanstack-start-stable 101 0 6
✅ e2e-local-postgres-nest-stable 101 0 6
✅ e2e-local-postgres-tanstack-start-stable 101 0 6
✅ e2e-local-prod-nest-stable 101 0 6
✅ e2e-local-prod-tanstack-start-stable 101 0 6

📋 View full workflow run

@TooTallNate
TooTallNate merged commit 3699c30 into stable Sep 29, 2026
156 of 165 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-4443-to-stable branch September 29, 2026 17:59

This branch was successfully deployed

1 active deployment
Preview – workflow-docs — 4f05621f Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant