Skip to content

[core] Fix webhook 404s on Nitro apps running Node 24 - #4575

Merged
VaguelySerious merged 1 commit into
mainfrom
peter/headers-node24-brand-check
Oct 1, 2026
Merged

VaguelySerious merged 1 commit into
mainfrom
peter/headers-node24-brand-check

Conversation

@VaguelySerious

Copy link
Copy Markdown
Member

Webhooks on Nitro-based apps (Express, Fastify, and other nitro presets) return 404 on Node 24. Every resumeWebhook call fails while serializing the incoming request:

Error during resumeWebhook Error: Failed to serialize step return value
Caused by: TypeError: Cannot read private member #headersList from an object whose class did not declare it
    at headersToEntries (serialization/hardened.ts)

This is what turned the express/fastify Vercel e2e lanes red on main (webhookWorkflow, parallelStepsThenWebhookWorkflow). Those lanes went red when the workbench projects' runtime moved from nodejs22.x to nodejs24.x. No SDK commit caused it.

Cause

srvx (Nitro's server layer) gives handlers a Headers look-alike. It inherits from Headers.prototype and forwards every member, symbol-keyed ones included, to a native Headers it creates lazily. headersToEntries iterates with the native iterator captured at boot:

  • Node 22: undici reads header state through a symbol-keyed prototype accessor, which srvx forwards, so this works.
  • Node 24: undici keeps that state in #headersList private fields. A forwarding wrapper can't provide those, so the iterator throws.

Fix

If the native iterator throws a TypeError, iterate through the object's own iterator instead, and record that as guest code ({ kind: 'method', detail: 'Headers[Symbol.iterator]' }), the same way other non-intrinsic execution in this module is recorded. Genuine Headers instances, from the host or the VM, still take the side-effect-free path and record nothing.

Testing

  • New test in hardened.test.ts: a forwarding look-alike shaped like srvx's NodeRequestHeaders round-trips and records the fallback. It fails on main with the #headersList TypeError on Node 20, 22 and 24, and passes on Node 22 and 24 with the fix.
  • Checked by hand on Node 24: real srvx 0.12.8 NodeRequest headers go through the built devalueCodec and round-trip.
  • The express/fastify Vercel Prod lanes in this PR's CI exercise the end-to-end path on Node 24.

🤖 Generated with Claude Code

srvx (Nitro) hands out request headers that inherit from Headers.prototype
but forward to a wrapped native instance. Node 24's undici keeps header
state in private fields, so the boot-captured Headers iterator rejects
them, and resumeWebhook failed with a SerializationError (404) for every
webhook on Nitro apps. Fall back to the object's own iterator and record
it as guest code.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@VaguelySerious
VaguelySerious requested a review from a team as a code owner October 1, 2026 20:03
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
example-nextjs-workflow-turbopack Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
example-nextjs-workflow-webpack Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
example-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-astro-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-express-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-fastify-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-hono-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-nestjs-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-nitro-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-nuxt-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-python-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-sveltekit-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-tanstack-start-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workbench-vite-workflow Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workflow-docs Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workflow-swc-playground Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workflow-tarballs Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC
workflow-web Ready Ready Preview, v0 Oct 1, 2026 8:09pm UTC

@changeset-bot

changeset-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 33476aa

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 17 packages
Name Type
@workflow/core Patch
@workflow/builders Patch
@workflow/cli Patch
@workflow/next Patch
@workflow/nitro Patch
@workflow/vitest Patch
@workflow/web-shared Patch
@workflow/web Patch
workflow Patch
@workflow/world-testing Patch
@workflow/astro Patch
@workflow/nest Patch
@workflow/rollup Patch
@workflow/sveltekit Patch
@workflow/vite Patch
@workflow/nuxt Patch
@workflow/world-vercel Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

📊 Workflow Benchmarks

commit 33476aa · Thu, 01 Oct 2026 20:30:58 GMT · run logs

Backend: vercel · app: nextjs-turbopack

Metric Scenario Best (ms) P75 (ms) P90 (ms) P99 (ms) Samples
TTFS step 2232 (+30%) 🔻 2378 🔴 (+25%) 🔻 2420 🔴 (+24%) 🔻 2489 🔴 (+18%) 🔻 30
TTFS stream 2225 (+68%) 🔻 2301 🔴 (+30%) 🔻 2326 🔴 (+29%) 🔻 2371 🔴 (+27%) 🔻 30
TTFS hook + stream 2458 (+24%) 🔻 2608 🔴 (+20%) 🔻 2647 🔴 (+14%) 2728 🔴 (+7.7%) 30
Fan-out TTFS Promise.all(100 steps) 553 (+13%) 757 (+14%) 2591 (+52%) 🔻 2600 (+27%) 🔻 10
Fan-out TTLS Promise.all(100 steps) 1511 (-10%) 3024 (+5.2%) 4941 (+5.3%) 10154 (+39%) 🔻 10
STSO 1020 steps (inline) 148 (-1.3%) 184 (-22%) 💚 205 (-30%) 💚 337 (-50%) 💚 1019
WO 1020 steps 183864 (-21%) 💚 183864 (-21%) 💚 183864 (-21%) 💚 183864 (-21%) 💚 1
CRTT first chunk (pooled) 70 (-5.4%) 114 (±0%) 195 (+42%) 🔻 4203 (+2527%) 🔻 28

Streams

Scenario CRTT 1st p75 p90 p99 CDV max iters
paced control (100/s, 60B) 92.5 (-14%) 172 (+4%) 705 (+209%) 4174 (+761%) 149 (-14%) 10
size sweep (100/s, 160B-12KB) 106 (+11%) 215 (+24%) 624 (+134%) 968 (-44%) 209 (+33%) 10
replay gateway-gpt-5.4-nano-2000t (1x) 90 (-18%) 155 (+1%) 193 (-1%) 450 (+36%) 331 (+56%) 3
replay eve-gpt-5.6-sol-2000t (1x) 90 (-24%) 160 (-14%) 194 (-21%) 410 (-7%) 319 (+16%) 2
replay eve-gpt-5.6-sol-2000t (2x) 110 (±0%) 204 (-2%) 286 (+3%) 461 (-3%) 336 (+18%) 3
📈 STSO distribution vs main (inline / queue-hop histograms)

1020 steps (inline)

Cumulative STSO time: main 232433ms → this run 183494ms (Δ -48939ms, -21%)

  100-150 ms  ┃                         main   0  this   5    +5
  150-200 ms  ████████████░░░░░░░░░░░┃  main 447  this 894  +447
  200-250 ms  █┃████████                main 381  this  84  -297
  250-300 ms  ┃██                       main  98  this  19   -79
  300-350 ms  ┃                         main  36  this   8   -28
  350-400 ms  ┃                         main  15  this   4   -11
  400-450 ms  ┃                         main  10  this   2    -8
  450-500 ms  ┃                         main  12  this   2   -10
  500-550 ms  ┃                         main   5  this   1    -4
  550-600 ms  ┃                         main   3  this   0    -3
  600-650 ms  ┃                         main   1  this   0    -1
  650-700 ms  ┃                         main   4  this   0    -4
  700-750 ms  ┃                         main   1  this   0    -1
  750-800 ms  ┃                         main   1  this   0    -1
  800-850 ms  ┃                         main   2  this   0    -2
  850-900 ms  ┃                         main   1  this   0    -1
  900-950 ms  ┃                         main   1  this   0    -1
1200-1250 ms  ┃                         main   1  this   0    -1
📈 CRTT drill-down vs main (RTT distributions & profiles)
variant  RTT 1ms→5s+              avg         p50          p90           p99     n
control  ······▃█▂▁▁▁·  416.5 (+207%)   123 (-1%)  705 (+209%)  4174 (+761%)  3000
sweep    ······▂█▂▁···    188.6 (+2%)   136 (+1%)  624 (+134%)    968 (-44%)  3000
gw 1x    ·····▁▃█▁▁···    134.3 (-1%)   129 (+1%)    193 (-1%)    450 (+36%)  5295
eve 1x   ·····▁▃█▂▁···   134.2 (-12%)  115 (-14%)   194 (-21%)     410 (-7%)  5186
eve 2x   ······▂█▃▁···    161.4 (-6%)   151 (-5%)    286 (+3%)     461 (-3%)  7779

RTT over stream progress (avg per tenth of stream, bars scaled min→max):

control  █▇▆▅▄▄▃▂▁▁  286–567ms
sweep    ▂▂█▇▄▂▁▂▄▄  155–250ms
gw 1x    █▄▃▅▄▃▄▁▃▅  116–158ms
eve 1x   ▃▁▃▃▃█▄▆▃▁  118–163ms
eve 2x   ▇▁▅▂▆▃▆█▃▄  138–187ms

RTT by chunk size (avg per log size bin, ~160B → ~12KB serialized, bars scaled min→max):

sweep  ▁▅█▇▇▅▄  186–190ms

Delivery jitter over stream progress (avg positive CDV per tenth of stream, bars scaled min→max):

control  ▂▂▁▁▄▄▆▃▂█  36–68ms
sweep    ▃▂█▆▄▁▂▃▄▃  54–85ms
gw 1x    █▅▄▄▅▁▆▁▃▅  34–47ms
eve 1x   ▂▁▂▃▂█▃▃▃▃  23–37ms
eve 2x   ▇▆▅▃▇▄█▁▃▇  20–35ms
ℹ️ Metric definitions & methodology

Streams: first-chunk RTT (the stream-open path, before any buffering/backpressure), CRTT percentiles, and worst delivery stall (CDV max). Cells are medians across iterations; per-run values in the artifacts. No 🔴/🟢 marks until targets attach.

The collapsed STSO distribution section above buckets every step gap, split inline (same warm process — pure framework overhead) vs queue-hop (fresh process — dispatch, reinit, replay). █ = main, ┃ = this run, ░ = fill.

The collapsed CRTT drill-down: per-variant RTT histograms (fixed log bins, · = empty) and mean RTT/positive-CDV profile lines over stream progress and chunk size. Histograms, avgs, and profiles merge exactly across runs; p50–p99 are percentile-of-percentiles. Per-index rows live in the artifacts.

Best/P75/P90/P99 deltas compare against the most recent benchmark run on main at the time of this run. 🔻 flags a delta worse than +15%, 💚 one better than −15%.

Metrics — TTFS: time to first step body (in-deployment start() → first step body) · Fan-out TTFS: fan-out time to first step (in-deployment start() → first of the parallel step bodies to complete) · Fan-out TTLS: fan-out time to last step (in-deployment start() → last of the parallel step bodies to complete, i.e. when the Promise.all resolves) · STSO: step-to-step overhead (gap between consecutive step bodies) · WO: workflow overhead (whole-run time outside step bodies, in-deployment anchored) · CRTT: chunk round-trip time (per-chunk write → read latency, one clock domain: deployment → stream backend → same deployment) · CDV: chunk delay variation / delivery jitter (inter-arrival gap minus inter-write gap per seq-adjacent pair; skew-free; the row is each run's MAX positive value, so one stall moves it)

Scenarios — step: one trivial no-op step, no stream; no hooks, so the run stays in turbo mode (in-process fast path) · stream: one streaming step; no hooks, so the run stays in turbo mode (in-process fast path) · hook + stream: registers a hook before one step, which exits turbo mode (dispatch path) · 1020 steps: 1020 trivial sequential steps; STSO is measured between consecutive steps in the given step ranges, and WO is the whole-run overhead outside step bodies · Promise.all(100 steps): 100 trivial no-op steps started together in a single Promise.all; Fan-out TTFS is the first of them to complete and Fan-out TTLS the last, both from the in-deployment clientStart, so their gap is the spread the runtime adds across the fan-out · paced control (100/s, 60B): the control: 300 tiny (~60B) deltas metronome-paced at 100/s — zero workload structure, so it reads the transport floor and flush cadence, and disambiguates transport-wide vs workload-specific when a replay row moves · size sweep (100/s, 160B-12KB): same pacing as the control with deltas padded in rotation across seven log-spaced sizes (~160B–12KB) — rotation decouples size from stream position, so it isolates whether chunk size causes latency · replay gateway-gpt-5.4-nano-2000t (1x): raw provider SSE cadence captured at the AI gateway boundary (gpt-5.4-nano, the most popular gateway model; per-token deltas p50 208B = the modal production chunk size), replayed exactly as measured — the typical customer's workload; its CDV is the typical customer's real delivery jitter · replay eve-gpt-5.6-sol-2000t (1x): a captured eve turn (gpt-5.6-sol, the most-used demanding eve model; ~2000 output tokens = production p50 turn length) replayed exactly as measured — eve's envelope protocol re-ships the cumulative message so sizes ramp 142B→13KB; the demanding outlier tenant's reality · replay eve-gpt-5.6-sol-2000t (2x): the same eve capture at 2x — the headroom/stress row; real fast-tier models emit the same chunk sizes at proportionally higher rate, so time compression is a faithful speed model · first chunk (pooled): every run's seq-0 RTT pooled across all stream scenarios — the first chunk precedes any workload differentiation, so pooling samples one shared stream-open path with exact percentiles

Replay cadences (semantic sha256) — eve-gpt-5.6-sol-2000t eaf22f5946e7c61f3c65c7006d550df180cfabd4e706254a09f22aec0cfb420d · gateway-gpt-5.4-nano-2000t 6f24ac518b6b83ff1d0e85a5fe78230db192716d66a7fc6b2fe022752001d041

🔴 marks a percentile over its target (within target is left unmarked). Targets (p75/p90/p99, ms) — TTFS 200/300/600

All timestamps are deployment-side; runs are triggered in-deployment, so the CI runner and api.vercel.com sit outside every measured window. TTFS = start() → first step body (includes dispatch + any cold start); Fan-out TTFS/TTLS = first/last step completion of one Promise.all from the same anchor (the gap is the runtime’s fan-out spread); STSO/WO between step bodies; CRTT inside the workflow (excludes the api.vercel.com read path).

Cold starts stay in the numbers (real bursty-workload latency, inflates P75+); Best is the warm floor.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

✅ All tests passed

⚠️ Flaky E2E Tests (passed on retry)

These tests failed at least once and passed on a retry. A recurring entry here is a real race worth investigating.

  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution (nextjs-webpack · local-dev / local / node / stable) — flaked in 2 jobs
  • a run can take over its own earlier hook (nextjs-webpack · local-dev / local / quickjs / stable)
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload (nextjs-webpack · local-dev / local / node / stable)

🛠 Infra Events (absorbed by the harness)

Platform anomalies the e2e harness detected and worked around (e.g. a run the queue never picked up, replaced by a fresh run). Clustered timestamps indicate a backend blip; a steady drip indicates a platform issue worth escalating.

  • run-pickup-stall · runs app-generated source against a registered step (tanstack-start) · at 20:09:57Z · abandoned wrun_01M3WHCJPB4NW5K476KW7D10HE
  • cold-start-warmup · suite warmup (tanstack-start) · at 20:10:05Z · abandoned wrun_01M3WHCJQ5B50J0YXVKGENRKYW
  • run-pickup-stall · hookCleanupTestWorkflow - hook token reuse after workflow completion (nextjs-webpack) · at 20:16:44Z · abandoned wrun_01M3WHRZCJ0CXHN6XCE2JCPV0S
  • run-pickup-stall · hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload (nextjs-webpack) · at 20:16:52Z · abandoned wrun_01M3WHS74N1C1NKEX8WGF8J9J3
  • run-pickup-stall · 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution (nextjs-webpack) · at 20:16:52Z · abandoned wrun_01M3WHS7B5S81NEE90ZY8P7R9D

E2E Test Summary

Summary
Passed Failed Skipped Total
✅ ▲ Vercel Production 3904 0 875 4779
✅ 💻 Local Development 4582 0 551 5133
✅ 📦 Local Production 4582 0 551 5133
✅ 🐘 Local Postgres 4582 0 551 5133
✅ 🪟 Windows 342 0 12 354
✅ 🌐 Cross-language Conformance 68 0 84 152
✅ dynamic-runs 0 0 0 0
✅ vercel-http-transport 879 0 183 1062
✅ vercel-multi-region 27 0 0 27
✅ vercel-ws-transport 595 0 113 708
Total 19561 0 2920 22481
Details by Category

✅ ▲ Vercel Production

App Passed Failed Skipped
✅ astro-node 142 0 35
✅ astro-quickjs 142 0 35
✅ example-node 142 0 35
✅ example-quickjs 142 0 35
✅ express-node 142 0 35
✅ express-quickjs 142 0 35
✅ fastify-node 142 0 35
✅ fastify-quickjs 142 0 35
✅ hono-node 142 0 35
✅ hono-quickjs 142 0 35
✅ nest-node 142 0 35
✅ nest-quickjs 142 0 35
✅ nextjs-turbopack-node 169 0 8
✅ nextjs-turbopack-quickjs 169 0 8
✅ nextjs-webpack-node 169 0 8
✅ nextjs-webpack-quickjs 169 0 8
✅ nitro-node 142 0 35
✅ nitro-quickjs 142 0 35
✅ nuxt-node 142 0 35
✅ nuxt-quickjs 142 0 35
✅ python-node 66 0 111
✅ sveltekit-node 161 0 16
✅ sveltekit-quickjs 161 0 16
✅ tanstack-start-node 142 0 35
✅ tanstack-start-quickjs 142 0 35
✅ vite-node 142 0 35
✅ vite-quickjs 142 0 35

✅ 💻 Local Development

App Passed Failed Skipped
✅ astro-stable-node 148 0 29
✅ astro-stable-quickjs 148 0 29
✅ express-stable-node 148 0 29
✅ express-stable-quickjs 148 0 29
✅ fastify-stable-node 148 0 29
✅ fastify-stable-quickjs 148 0 29
✅ hono-stable-node 148 0 29
✅ hono-stable-quickjs 148 0 29
✅ nest-stable-node 148 0 29
✅ nest-stable-quickjs 148 0 29
✅ nextjs-turbopack-canary-node 176 0 1
✅ nextjs-turbopack-canary-quickjs 176 0 1
✅ nextjs-turbopack-quickjs-snapshot 176 0 1
✅ nextjs-turbopack-stable-node 176 0 1
✅ nextjs-turbopack-stable-quickjs 176 0 1
✅ nextjs-webpack-canary-node 176 0 1
✅ nextjs-webpack-canary-quickjs 176 0 1
✅ nextjs-webpack-stable-node 176 0 1
✅ nextjs-webpack-stable-quickjs 176 0 1
✅ nitro-stable-node 148 0 29
✅ nitro-stable-quickjs 148 0 29
✅ nuxt-stable-node 148 0 29
✅ nuxt-stable-quickjs 148 0 29
✅ sveltekit-stable-node 167 0 10
✅ sveltekit-stable-quickjs 167 0 10
✅ tanstack-start-node 148 0 29
✅ tanstack-start-quickjs 148 0 29
✅ vite-stable-node 148 0 29
✅ vite-stable-quickjs 148 0 29

✅ 📦 Local Production

App Passed Failed Skipped
✅ astro-stable-node 148 0 29
✅ astro-stable-quickjs 148 0 29
✅ express-stable-node 148 0 29
✅ express-stable-quickjs 148 0 29
✅ fastify-stable-node 148 0 29
✅ fastify-stable-quickjs 148 0 29
✅ hono-stable-node 148 0 29
✅ hono-stable-quickjs 148 0 29
✅ nest-stable-node 148 0 29
✅ nest-stable-quickjs 148 0 29
✅ nextjs-turbopack-canary-node 176 0 1
✅ nextjs-turbopack-canary-quickjs 176 0 1
✅ nextjs-turbopack-quickjs-snapshot 176 0 1
✅ nextjs-turbopack-stable-node 176 0 1
✅ nextjs-turbopack-stable-quickjs 176 0 1
✅ nextjs-webpack-canary-node 176 0 1
✅ nextjs-webpack-canary-quickjs 176 0 1
✅ nextjs-webpack-stable-node 176 0 1
✅ nextjs-webpack-stable-quickjs 176 0 1
✅ nitro-stable-node 148 0 29
✅ nitro-stable-quickjs 148 0 29
✅ nuxt-stable-node 148 0 29
✅ nuxt-stable-quickjs 148 0 29
✅ sveltekit-stable-node 167 0 10
✅ sveltekit-stable-quickjs 167 0 10
✅ tanstack-start-node 148 0 29
✅ tanstack-start-quickjs 148 0 29
✅ vite-stable-node 148 0 29
✅ vite-stable-quickjs 148 0 29

✅ 🐘 Local Postgres

App Passed Failed Skipped
✅ astro-stable-node 148 0 29
✅ astro-stable-quickjs 148 0 29
✅ express-stable-node 148 0 29
✅ express-stable-quickjs 148 0 29
✅ fastify-stable-node 148 0 29
✅ fastify-stable-quickjs 148 0 29
✅ hono-stable-node 148 0 29
✅ hono-stable-quickjs 148 0 29
✅ nest-stable-node 148 0 29
✅ nest-stable-quickjs 148 0 29
✅ nextjs-turbopack-canary-node 176 0 1
✅ nextjs-turbopack-canary-quickjs 176 0 1
✅ nextjs-turbopack-quickjs-snapshot 176 0 1
✅ nextjs-turbopack-stable-node 176 0 1
✅ nextjs-turbopack-stable-quickjs 176 0 1
✅ nextjs-webpack-canary-node 176 0 1
✅ nextjs-webpack-canary-quickjs 176 0 1
✅ nextjs-webpack-stable-node 176 0 1
✅ nextjs-webpack-stable-quickjs 176 0 1
✅ nitro-stable-node 148 0 29
✅ nitro-stable-quickjs 148 0 29
✅ nuxt-stable-node 148 0 29
✅ nuxt-stable-quickjs 148 0 29
✅ sveltekit-stable-node 167 0 10
✅ sveltekit-stable-quickjs 167 0 10
✅ tanstack-start-node 148 0 29
✅ tanstack-start-quickjs 148 0 29
✅ vite-stable-node 148 0 29
✅ vite-stable-quickjs 148 0 29

✅ 🪟 Windows

App Passed Failed Skipped
✅ nextjs-turbopack-node 171 0 6
✅ nextjs-turbopack-quickjs 171 0 6

✅ 🌐 Cross-language Conformance

App Passed Failed Skipped
✅ python 68 0 84

✅ dynamic-runs

App Passed Failed Skipped
✅ astro-vercel 0 0 0
✅ example-vercel 0 0 0
✅ express-vercel 0 0 0
✅ fastify-vercel 0 0 0
✅ hono-vercel 0 0 0
✅ nest-vercel 0 0 0
✅ nextjs-turbopack-vercel 0 0 0
✅ nextjs-webpack-vercel 0 0 0
✅ nitro-vercel 0 0 0
✅ nuxt-vercel 0 0 0
✅ sveltekit-vercel 0 0 0
✅ tanstack-start-vercel 0 0 0
✅ vite-vercel 0 0 0

✅ vercel-http-transport

App Passed Failed Skipped
✅ example 142 0 35
✅ express 142 0 35
✅ hono 142 0 35
✅ nextjs-turbopack 169 0 8
✅ nitro 142 0 35
✅ vite 142 0 35

✅ vercel-multi-region

App Passed Failed Skipped
✅ nextjs-turbopack 27 0 0

✅ vercel-ws-transport

App Passed Failed Skipped
✅ example 142 0 35
✅ express 142 0 35
✅ nextjs-turbopack 169 0 8
✅ vite 142 0 35

📋 View full workflow run

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Sim World

Simulated world deterministic testing for races. Traces

🟠 world-sim scenario book — 1 fail of 42 total

fence=per-spec

scenario outcome events virt replay violations
✅ smoke-no-steps completed 3 0ms ok 0
✅ smoke-one-step completed 6 0ms ok 0
✅ hook-at-step-started completed 12 0ms ok 0
✅ hook-at-step-completed completed 12 0ms ok 0
✅ hook-at-hook-created completed 12 0ms ok 0
✅ deadline-hook-wins completed 7 1.0h ok 0
✅ deadline-expires completed 7 1.0h ok 0
✅ step-vs-timer-early-settlement completed 8 1.0h ok 0
✅ long-sleep completed 11 30.0d ok 0
✅ hook-never-arrives stalled 3 0ms skipped 0
✅ step-retries-twice completed 10 2.0s ok 0
✅ parallel-steps completed 9 0ms ok 0
✅ hook-on-execution-state completed 12 0ms ok 0
✅ peek-hook-before-branch completed 12 0ms ok 0
✅ peek-hook-after-branch completed 12 0ms ok 0
✅ peek-hook-at-registration completed 12 0ms ok 0
✅ race-hook-before-probe completed 12 0ms ok 0
✅ race-hook-after-probe completed 12 0ms ok 0
✅ race-duplicate-delivery completed 13 0ms ok 0
✅ attr-hook-before-step completed 11 0ms ok 0
✅ attr-hook-after-step completed 11 0ms ok 0
✅ attr-from-step-body completed 13 0ms ok 0
✅ fork-hook-after-timeout completed 14 1.0m ok 0
✅ fork-hook-before-timeout completed 14 1.0m ok 0
✅ count-hook-after-timeout completed 17 1.0m ok 0
✅ count-hook-before-timeout completed 20 1.0m ok 0
✅ stale-read-step-count-fork completed 20 1.0m ok 0
✅ stale-read-equal-step-counts completed 14 1.0m ok 0
✅ step-vs-step-fork completed 12 0ms ok 0
✅ step-vs-step-fork-fenced completed 12 0ms ok 0
✅ fence-catches-benign-direction completed 12 5ms ok 0
✅ in-flight-before-decision completed 17 1.0m ok 0
❌ in-flight-before-decision-counted completed 17 1.0m ok 0
✅ in-flight-after-decision completed 19 2.0m ok 0
✅ stale-read-step-count-fork-fenced completed 20 1.0m ok 0
✅ fork-hook-wins completed 13 1.0m ok 0
✅ fork-timeout-wins completed 13 1.0m ok 0
✅ unclaimed-payload-under-fork completed 17 1.0m ok 0
✅ claimed-payload-under-fork completed 17 1.0m ok 0
✅ writers-independent-step-bodies completed 12 0ms ok 0
✅ writers-scripted-tempo completed 12 0ms ok 0
✅ cancel-mid-step cancelled 7 0ms skipped 0

Full trace: world-sim.txt

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor
Framework Flow route Step reg. Framework output
hono 267.2 KiB (±0) 97.3 KiB (±0) 2.00 MiB (+229 B)
nextjs-turbopack 274.6 KiB (±0) 426 B (±0) 985.6 KiB (+33 B)
About these numbers

Sizes are gzip; parentheses show the change against main.
Flow route and Step reg. gate this job, on raw bytes rather than the gzip shown, at max(2%, 50.0 KiB). Framework output is informational.

33476aa · run

@karthikscale3 karthikscale3 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No blockers found. The focused hardened-serialization suite passes locally on Node 22 and Node 24. The current Vitest Plugin Tests (node) failure is in the unrelated hook-token-reuse test.

@VaguelySerious
VaguelySerious merged commit 3b09dd7 into main Oct 1, 2026
182 of 184 checks passed
@VaguelySerious
VaguelySerious deleted the peter/headers-node24-brand-check branch October 1, 2026 20:17
@github-actions github-actions Bot mentioned this pull request Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

No backport to stable for 3b09dd7 (AI decision).

This is a genuine bug fix, but it targets packages/core/src/serialization/hardened.ts, which does not exist on stable (verified: packages/core/src/serialization/ is absent there and no headersToEntries/headersIterator exists anywhere in the branch). stable serializes Headers via plain Array.from(value) in packages/core/src/serialization.ts:1285, which uses the object's own iterator and therefore never hits the Node 24 #headersList TypeError, so the maintenance line is not affected by this defect. There is nothing to apply and no bug to fix on stable.

To override, re-run the Backport to stable workflow manually via workflow_dispatch and paste this commit SHA into the ref input:

3b09dd7da5ea4e5de852d59c33db8db10a3d314b

This branch was successfully deployed

1 active deployment
Preview – workflow-docs — 33476aab Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants