Skip to content

[core] Serialize only the viewed bytes of a Float16Array - #4594

Merged
TooTallNate merged 2 commits into
mainfrom
fix/serialize-unclaimed-view-bytes
Oct 2, 2026
Merged

TooTallNate merged 2 commits into
mainfrom
fix/serialize-unclaimed-view-bytes

Conversation

@TooTallNate

@TooTallNate TooTallNate commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

Node allocates small Buffers (Buffer.allocUnsafe, small Buffer.from) as windows onto a shared 8 KiB pool. A serializer that encodes a view's whole backing ArrayBuffer therefore writes unrelated, possibly sensitive pool memory into the run's event log. devalue is shipping a fix for this in its default stringify operations; this PR is our audit of the same class.

Audit

Every typed array except one was already safe: the workflow reducers claim Buffer/Uint8Array, the other typed arrays, and (since #4443) DataView, and encode only the viewed range. Probed through the real codec with a pooled Buffer neighbouring a secret:

Value Before After
Buffer, typed arrays, DataView viewed bytes only unchanged
Float16Array over a pooled Buffer whole 8 KiB pool viewed bytes only
buf.buffer passed explicitly whole buffer (what was asked for) unchanged

Float16Array has no reducer, so it reaches devalue's built-in typed-array branch, which calls our hardened viewInfo operation. That returned the whole backing buffer plus offset/length. Upgrading devalue would not fix this, because we override viewInfo.

Changes

  • node:vm engine (serialization/hardened.ts): the hardened viewInfo copies a subview's viewed bytes into a fresh buffer (through captured intrinsics, so guest patches can't influence it) and reports it as a whole-buffer view. devalue then emits the compact ["Float16Array", buffer] form, which every existing reader already parses. Whole-buffer views are unchanged.
  • VM reference codec (serialization/codec-devalue-vm.ts, the value-space model the QuickJS wire fixtures are checked against): same subview copy, so it agrees with both engines.
  • QuickJS engine (runtime/quickjs-serde.ts): Float16Array previously classified as a plain object and threw Cannot stringify arbitrary non-POJOs (no leak: the VM has no Buffer pool). It's now sampled and captured, so it takes the same devalue built-in branch, and the QuickJS viewInfo applies the same subview copy, so both engines emit byte-identical payloads. The constructor capture is optional so a capture root adopted from an older snapshot still works.

Why not add a Float16Array reducer (or drop the existing ones)?

devalue skips its built-in branch for any tag that has a custom reviver, and hands that reviver only the hydrated referent. A Float16Array reviver would therefore strip the bounds off ["Float16Array", buf, off, len] payloads already in event logs (the same reason #4443 used the DataViewBytes tag). Conversely, the existing typed-array reducers are the wire format for every stored ["Uint8Array","<base64>"], so they have to stay.

Tests

  • serialization.test.ts: pooled Float16Array step return carries only its 4 viewed bytes and round-trips; whole-buffer and empty subview round-trip.
  • quickjs-serde.test.ts: whole-buffer, subview and empty-subview Float16Array are byte-identical to both the reference codec and the node:vm engine and revive in the guest; a payload carrying subview bounds revives with them.
  • Both new suites fail without the corresponding source change. src/runtime + src/serialization* pass locally (1888 tests).

Docs Preview

Page v5
Serialization: supported types /docs/foundations/serialization

v4 docs are unchanged: this PR's changes are 5.x-only (see review thread).

Copilot AI balanced review requested due to automatic review settings October 2, 2026 18:41
@TooTallNate
TooTallNate requested a review from a team as a code owner October 2, 2026 18:41
@changeset-bot

changeset-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b61f19b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 17 packages
Name Type
@workflow/core Patch
@workflow/builders Patch
@workflow/cli Patch
@workflow/next Patch
@workflow/nitro Patch
@workflow/vitest Patch
@workflow/web-shared Patch
@workflow/web Patch
workflow Patch
@workflow/world-testing Patch
@workflow/astro Patch
@workflow/nest Patch
@workflow/rollup Patch
@workflow/sveltekit Patch
@workflow/vite Patch
@workflow/nuxt Patch
@workflow/world-vercel Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
example-nextjs-workflow-turbopack Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
example-nextjs-workflow-webpack Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
example-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-astro-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-express-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-fastify-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-hono-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-nestjs-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-nitro-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-nuxt-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-python-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-sveltekit-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-tanstack-start-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workbench-vite-workflow Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workflow-docs Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workflow-swc-playground Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workflow-tarballs Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC
workflow-web Ready Ready Preview, v0 Oct 2, 2026 6:51pm UTC

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

✅ All tests passed

🛠 Infra Events (absorbed by the harness)

Platform anomalies the e2e harness detected and worked around (e.g. a run the queue never picked up, replaced by a fresh run). Clustered timestamps indicate a backend blip; a steady drip indicates a platform issue worth escalating.

  • run-pickup-stall · runs app-generated source against a registered step (tanstack-start) · at 18:53:57Z · abandoned wrun_01M3YZE3WKAZ80K52PN47RAD1E
  • cold-start-warmup · suite warmup (tanstack-start) · at 18:54:04Z · abandoned wrun_01M3YZE3WZ9T5WP1CE10M76D6C
  • run-pickup-stall · hookCleanupTestWorkflow - hook token reuse after workflow completion (nextjs-webpack) · at 19:03:20Z · abandoned wrun_01M3YZZA25F4670ED13S9DWTH3
  • run-pickup-stall · hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload (nextjs-webpack) · at 19:03:28Z · abandoned wrun_01M3YZZHZFX61BXSZTHDK66SRY

E2E Test Summary

Summary
Passed Failed Skipped Total
✅ ▲ Vercel Production 3904 0 875 4779
✅ 💻 Local Development 4582 0 551 5133
✅ 📦 Local Production 4582 0 551 5133
✅ 🐘 Local Postgres 4582 0 551 5133
✅ 🪟 Windows 342 0 12 354
✅ 🌐 Cross-language Conformance 68 0 84 152
✅ dynamic-runs 0 0 0 0
✅ vercel-http-transport 879 0 183 1062
✅ vercel-multi-region 27 0 0 27
✅ vercel-ws-transport 595 0 113 708
Total 19561 0 2920 22481
Details by Category

✅ ▲ Vercel Production

App Passed Failed Skipped
✅ astro-node 142 0 35
✅ astro-quickjs 142 0 35
✅ example-node 142 0 35
✅ example-quickjs 142 0 35
✅ express-node 142 0 35
✅ express-quickjs 142 0 35
✅ fastify-node 142 0 35
✅ fastify-quickjs 142 0 35
✅ hono-node 142 0 35
✅ hono-quickjs 142 0 35
✅ nest-node 142 0 35
✅ nest-quickjs 142 0 35
✅ nextjs-turbopack-node 169 0 8
✅ nextjs-turbopack-quickjs 169 0 8
✅ nextjs-webpack-node 169 0 8
✅ nextjs-webpack-quickjs 169 0 8
✅ nitro-node 142 0 35
✅ nitro-quickjs 142 0 35
✅ nuxt-node 142 0 35
✅ nuxt-quickjs 142 0 35
✅ python-node 66 0 111
✅ sveltekit-node 161 0 16
✅ sveltekit-quickjs 161 0 16
✅ tanstack-start-node 142 0 35
✅ tanstack-start-quickjs 142 0 35
✅ vite-node 142 0 35
✅ vite-quickjs 142 0 35

✅ 💻 Local Development

App Passed Failed Skipped
✅ astro-stable-node 148 0 29
✅ astro-stable-quickjs 148 0 29
✅ express-stable-node 148 0 29
✅ express-stable-quickjs 148 0 29
✅ fastify-stable-node 148 0 29
✅ fastify-stable-quickjs 148 0 29
✅ hono-stable-node 148 0 29
✅ hono-stable-quickjs 148 0 29
✅ nest-stable-node 148 0 29
✅ nest-stable-quickjs 148 0 29
✅ nextjs-turbopack-canary-node 176 0 1
✅ nextjs-turbopack-canary-quickjs 176 0 1
✅ nextjs-turbopack-quickjs-snapshot 176 0 1
✅ nextjs-turbopack-stable-node 176 0 1
✅ nextjs-turbopack-stable-quickjs 176 0 1
✅ nextjs-webpack-canary-node 176 0 1
✅ nextjs-webpack-canary-quickjs 176 0 1
✅ nextjs-webpack-stable-node 176 0 1
✅ nextjs-webpack-stable-quickjs 176 0 1
✅ nitro-stable-node 148 0 29
✅ nitro-stable-quickjs 148 0 29
✅ nuxt-stable-node 148 0 29
✅ nuxt-stable-quickjs 148 0 29
✅ sveltekit-stable-node 167 0 10
✅ sveltekit-stable-quickjs 167 0 10
✅ tanstack-start-node 148 0 29
✅ tanstack-start-quickjs 148 0 29
✅ vite-stable-node 148 0 29
✅ vite-stable-quickjs 148 0 29

✅ 📦 Local Production

App Passed Failed Skipped
✅ astro-stable-node 148 0 29
✅ astro-stable-quickjs 148 0 29
✅ express-stable-node 148 0 29
✅ express-stable-quickjs 148 0 29
✅ fastify-stable-node 148 0 29
✅ fastify-stable-quickjs 148 0 29
✅ hono-stable-node 148 0 29
✅ hono-stable-quickjs 148 0 29
✅ nest-stable-node 148 0 29
✅ nest-stable-quickjs 148 0 29
✅ nextjs-turbopack-canary-node 176 0 1
✅ nextjs-turbopack-canary-quickjs 176 0 1
✅ nextjs-turbopack-quickjs-snapshot 176 0 1
✅ nextjs-turbopack-stable-node 176 0 1
✅ nextjs-turbopack-stable-quickjs 176 0 1
✅ nextjs-webpack-canary-node 176 0 1
✅ nextjs-webpack-canary-quickjs 176 0 1
✅ nextjs-webpack-stable-node 176 0 1
✅ nextjs-webpack-stable-quickjs 176 0 1
✅ nitro-stable-node 148 0 29
✅ nitro-stable-quickjs 148 0 29
✅ nuxt-stable-node 148 0 29
✅ nuxt-stable-quickjs 148 0 29
✅ sveltekit-stable-node 167 0 10
✅ sveltekit-stable-quickjs 167 0 10
✅ tanstack-start-node 148 0 29
✅ tanstack-start-quickjs 148 0 29
✅ vite-stable-node 148 0 29
✅ vite-stable-quickjs 148 0 29

✅ 🐘 Local Postgres

App Passed Failed Skipped
✅ astro-stable-node 148 0 29
✅ astro-stable-quickjs 148 0 29
✅ express-stable-node 148 0 29
✅ express-stable-quickjs 148 0 29
✅ fastify-stable-node 148 0 29
✅ fastify-stable-quickjs 148 0 29
✅ hono-stable-node 148 0 29
✅ hono-stable-quickjs 148 0 29
✅ nest-stable-node 148 0 29
✅ nest-stable-quickjs 148 0 29
✅ nextjs-turbopack-canary-node 176 0 1
✅ nextjs-turbopack-canary-quickjs 176 0 1
✅ nextjs-turbopack-quickjs-snapshot 176 0 1
✅ nextjs-turbopack-stable-node 176 0 1
✅ nextjs-turbopack-stable-quickjs 176 0 1
✅ nextjs-webpack-canary-node 176 0 1
✅ nextjs-webpack-canary-quickjs 176 0 1
✅ nextjs-webpack-stable-node 176 0 1
✅ nextjs-webpack-stable-quickjs 176 0 1
✅ nitro-stable-node 148 0 29
✅ nitro-stable-quickjs 148 0 29
✅ nuxt-stable-node 148 0 29
✅ nuxt-stable-quickjs 148 0 29
✅ sveltekit-stable-node 167 0 10
✅ sveltekit-stable-quickjs 167 0 10
✅ tanstack-start-node 148 0 29
✅ tanstack-start-quickjs 148 0 29
✅ vite-stable-node 148 0 29
✅ vite-stable-quickjs 148 0 29

✅ 🪟 Windows

App Passed Failed Skipped
✅ nextjs-turbopack-node 171 0 6
✅ nextjs-turbopack-quickjs 171 0 6

✅ 🌐 Cross-language Conformance

App Passed Failed Skipped
✅ python 68 0 84

✅ dynamic-runs

App Passed Failed Skipped
✅ astro-vercel 0 0 0
✅ example-vercel 0 0 0
✅ express-vercel 0 0 0
✅ fastify-vercel 0 0 0
✅ hono-vercel 0 0 0
✅ nest-vercel 0 0 0
✅ nextjs-turbopack-vercel 0 0 0
✅ nextjs-webpack-vercel 0 0 0
✅ nitro-vercel 0 0 0
✅ nuxt-vercel 0 0 0
✅ sveltekit-vercel 0 0 0
✅ tanstack-start-vercel 0 0 0
✅ vite-vercel 0 0 0

✅ vercel-http-transport

App Passed Failed Skipped
✅ example 142 0 35
✅ express 142 0 35
✅ hono 142 0 35
✅ nextjs-turbopack 169 0 8
✅ nitro 142 0 35
✅ vite 142 0 35

✅ vercel-multi-region

App Passed Failed Skipped
✅ nextjs-turbopack 27 0 0

✅ vercel-ws-transport

App Passed Failed Skipped
✅ example 142 0 35
✅ express 142 0 35
✅ nextjs-turbopack 169 0 8
✅ vite 142 0 35

📋 View full workflow run

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

📊 Workflow Benchmarks

commit b61f19b · Fri, 02 Oct 2026 19:16:53 GMT · run logs

Backend: vercel · app: nextjs-turbopack

Metric Scenario Best (ms) P75 (ms) P90 (ms) P99 (ms) Samples
TTFS step 416 (-75%) 💚 2345 🔴 (+26%) 🔻 2418 🔴 (+26%) 🔻 2702 🔴 (+32%) 🔻 30
TTFS stream 397 (-76%) 💚 2265 🔴 (+25%) 🔻 2327 🔴 (+26%) 🔻 2567 🔴 (+33%) 🔻 30
TTFS hook + stream 463 (-72%) 💚 2532 🔴 (+15%) 🔻 2583 🔴 (+12%) 2815 🔴 (+1.6%) 30
Fan-out TTFS Promise.all(100 steps) 543 (-4.2%) 960 (+4.9%) 2593 (+24%) 🔻 2642 (+19%) 🔻 10
Fan-out TTLS Promise.all(100 steps) 2786 (+93%) 🔻 5772 (-31%) 💚 6589 (-30%) 💚 6635 (-32%) 💚 10
STSO 1020 steps (inline) 157 (+57%) 🔻 216 (+51%) 🔻 251 (+40%) 🔻 380 (+4.4%) 1019
WO 1020 steps 210082 (+43%) 🔻 210082 (+43%) 🔻 210082 (+43%) 🔻 210082 (+43%) 🔻 1
CRTT first chunk (pooled) 67 (-6.9%) 98 (-24%) 💚 176 (-16%) 💚 381 (-0.8%) 28

Streams

Scenario CRTT 1st p75 p90 p99 CDV max iters
paced control (100/s, 60B) 85 (-20%) 150 (-30%) 197 (-47%) 427 (-30%) 117 (-57%) 10
size sweep (100/s, 160B-12KB) 88.5 (-18%) 158 (-45%) 233 (-68%) 379 (-61%) 148 (-62%) 10
replay gateway-gpt-5.4-nano-2000t (1x) 97 (-14%) 145 (-20%) 188 (-22%) 363 (-28%) 413 (+9%) 3
replay eve-gpt-5.6-sol-2000t (1x) 80.5 (-66%) 159 (-37%) 196 (-52%) 347 (-53%) 328 (-39%) 2
replay eve-gpt-5.6-sol-2000t (2x) 86 (-23%) 171 (-41%) 219 (-56%) 650 (-63%) 269 (-54%) 3
📈 STSO distribution vs main (inline / queue-hop histograms)

1020 steps (inline)

Cumulative STSO time: main 146558ms → this run 209613ms (Δ +63055ms, +43%)

 100-150 ms  ┃███████████████████████  main 798  this   0  -798
 150-200 ms  ████░░░░░░░░░░░░░┃        main 149  this 601  +452
 200-250 ms  █░░░░░░░┃                 main  34  this 313  +279
 250-300 ms  █┃                        main  17  this  69   +52
 300-350 ms  ┃                         main   9  this  22   +13
 350-400 ms  ┃                         main   5  this   7    +2
 400-450 ms  ┃                         main   3  this   5    +2
 450-500 ms  ┃                         main   0  this   1    +1
 500-550 ms  ┃                         main   0  this   1    +1
 600-650 ms  ┃                         main   1  this   0    -1
 700-750 ms  ┃                         main   1  this   0    -1
 750-800 ms  ┃                         main   1  this   0    -1
950-1000 ms  ┃                         main   1  this   0    -1
📈 CRTT drill-down vs main (RTT distributions & profiles)
variant  RTT 1ms→5s+             avg         p50         p90         p99     n
control  ······▃█▁····  128.7 (-28%)  124 (-18%)  197 (-47%)  427 (-30%)  3000
sweep    ······▃█▁····  130.6 (-42%)  122 (-25%)  233 (-68%)  379 (-61%)  3000
gw 1x    ·····▁▃█▁▁···  127.3 (-21%)  120 (-15%)  188 (-22%)  363 (-28%)  5295
eve 1x   ·····▁▃█▁▁···  135.6 (-34%)  123 (-25%)  196 (-52%)  347 (-53%)  5186
eve 2x   ·····▁▂█▂▁···  147.3 (-42%)  135 (-32%)  219 (-56%)  650 (-63%)  7779

RTT over stream progress (avg per tenth of stream, bars scaled min→max):

control  █▂▁▅▃▂▂▁▃▄  121–148ms
sweep    █▆█▄▄▁▃▄▂▆  118–142ms
gw 1x    ▆█▃▄▁▂█▂▄▂  117–141ms
eve 1x   ▂▂▃▂▁▃█▃▃▂  117–182ms
eve 2x   ▃▃█▂▁▂▃██▄  128–172ms

RTT by chunk size (avg per log size bin, ~160B → ~12KB serialized, bars scaled min→max):

sweep  ▇█▆▃▂▁▃  128–134ms

Delivery jitter over stream progress (avg positive CDV per tenth of stream, bars scaled min→max):

control  ▅▂▁▅▄▂▃██▂  38–47ms
sweep    ▂▁▃▄▇▆▇█▅█  52–62ms
gw 1x    ▆▇▄▁▁▅█▃▄▄  33–47ms
eve 1x   ▂▁▂▂▂▃█▃▂▂  25–40ms
eve 2x   ▅█▄▂▆▃▁▂█▆  25–31ms
ℹ️ Metric definitions & methodology

Streams: first-chunk RTT (the stream-open path, before any buffering/backpressure), CRTT percentiles, and worst delivery stall (CDV max). Cells are medians across iterations; per-run values in the artifacts. No 🔴/🟢 marks until targets attach.

The collapsed STSO distribution section above buckets every step gap, split inline (same warm process — pure framework overhead) vs queue-hop (fresh process — dispatch, reinit, replay). █ = main, ┃ = this run, ░ = fill.

The collapsed CRTT drill-down: per-variant RTT histograms (fixed log bins, · = empty) and mean RTT/positive-CDV profile lines over stream progress and chunk size. Histograms, avgs, and profiles merge exactly across runs; p50–p99 are percentile-of-percentiles. Per-index rows live in the artifacts.

Best/P75/P90/P99 deltas compare against the most recent benchmark run on main at the time of this run. 🔻 flags a delta worse than +15%, 💚 one better than −15%.

Metrics — TTFS: time to first step body (in-deployment start() → first step body) · Fan-out TTFS: fan-out time to first step (in-deployment start() → first of the parallel step bodies to complete) · Fan-out TTLS: fan-out time to last step (in-deployment start() → last of the parallel step bodies to complete, i.e. when the Promise.all resolves) · STSO: step-to-step overhead (gap between consecutive step bodies) · WO: workflow overhead (whole-run time outside step bodies, in-deployment anchored) · CRTT: chunk round-trip time (per-chunk write → read latency, one clock domain: deployment → stream backend → same deployment) · CDV: chunk delay variation / delivery jitter (inter-arrival gap minus inter-write gap per seq-adjacent pair; skew-free; the row is each run's MAX positive value, so one stall moves it)

Scenarios — step: one trivial no-op step, no stream; no hooks, so the run stays in turbo mode (in-process fast path) · stream: one streaming step; no hooks, so the run stays in turbo mode (in-process fast path) · hook + stream: registers a hook before one step, which exits turbo mode (dispatch path) · 1020 steps: 1020 trivial sequential steps; STSO is measured between consecutive steps in the given step ranges, and WO is the whole-run overhead outside step bodies · Promise.all(100 steps): 100 trivial no-op steps started together in a single Promise.all; Fan-out TTFS is the first of them to complete and Fan-out TTLS the last, both from the in-deployment clientStart, so their gap is the spread the runtime adds across the fan-out · paced control (100/s, 60B): the control: 300 tiny (~60B) deltas metronome-paced at 100/s — zero workload structure, so it reads the transport floor and flush cadence, and disambiguates transport-wide vs workload-specific when a replay row moves · size sweep (100/s, 160B-12KB): same pacing as the control with deltas padded in rotation across seven log-spaced sizes (~160B–12KB) — rotation decouples size from stream position, so it isolates whether chunk size causes latency · replay gateway-gpt-5.4-nano-2000t (1x): raw provider SSE cadence captured at the AI gateway boundary (gpt-5.4-nano, the most popular gateway model; per-token deltas p50 208B = the modal production chunk size), replayed exactly as measured — the typical customer's workload; its CDV is the typical customer's real delivery jitter · replay eve-gpt-5.6-sol-2000t (1x): a captured eve turn (gpt-5.6-sol, the most-used demanding eve model; ~2000 output tokens = production p50 turn length) replayed exactly as measured — eve's envelope protocol re-ships the cumulative message so sizes ramp 142B→13KB; the demanding outlier tenant's reality · replay eve-gpt-5.6-sol-2000t (2x): the same eve capture at 2x — the headroom/stress row; real fast-tier models emit the same chunk sizes at proportionally higher rate, so time compression is a faithful speed model · first chunk (pooled): every run's seq-0 RTT pooled across all stream scenarios — the first chunk precedes any workload differentiation, so pooling samples one shared stream-open path with exact percentiles

Replay cadences (semantic sha256) — eve-gpt-5.6-sol-2000t eaf22f5946e7c61f3c65c7006d550df180cfabd4e706254a09f22aec0cfb420d · gateway-gpt-5.4-nano-2000t 6f24ac518b6b83ff1d0e85a5fe78230db192716d66a7fc6b2fe022752001d041

🔴 marks a percentile over its target (within target is left unmarked). Targets (p75/p90/p99, ms) — TTFS 200/300/600

All timestamps are deployment-side; runs are triggered in-deployment, so the CI runner and api.vercel.com sit outside every measured window. TTFS = start() → first step body (includes dispatch + any cold start); Fan-out TTFS/TTLS = first/last step completion of one Promise.all from the same anchor (the gap is the runtime’s fan-out spread); STSO/WO between step bodies; CRTT inside the workflow (excludes the api.vercel.com read path).

Cold starts stay in the numbers (real bursty-workload latency, inflates P75+); Best is the warm floor.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The canonical QuickJS reference codec still emits the unsafe legacy representation, and supported-type documentation remains outdated.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Prevents Float16Array subviews from serializing unrelated backing-buffer bytes and adds equivalent QuickJS support.

Changes:

  • Copies only viewed bytes before devalue serialization.
  • Adds QuickJS Float16Array detection and revival.
  • Adds cross-engine and pooled-buffer tests.
File Description
serialization/​hardened.ts Restricts serialized views to their byte range.
serialization.test.ts Tests pooled, whole, and empty views.
runtime/​quickjs-serde.ts Adds QuickJS Float16Array support.
runtime/​quickjs-serde.test.ts Tests parity and legacy revival.
.changeset/​unclaimed-view-pool-leak.md Records the patch release.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

// The node:vm engine's encoding is the contract: `Float16Array` has no
// workflow reducer on either engine, so both must emit devalue's built-in
// `[tag, buffer]` form, and a subview must carry only its viewed bytes.
const nodeEngine = (value: unknown) => text(nodeEngineSerialize(value));

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed, fixed in b61f19b. codec-devalue-vm.ts now passes a viewInfo operation that copies a subview's viewed bytes into a fresh buffer, the same as hardened.ts and quickjs-serde.ts. The Float16Array parity tests now assert that QuickJS output is byte-identical to both referenceSerialize and the node:vm engine. Without the reference-codec change, the subview and empty-subview cases fail.

"@workflow/core": patch
---

Serialize only the viewed bytes of a `Float16Array` (no longer the whole Node `Buffer` pool behind it), and support `Float16Array` in the QuickJS engine with the same wire format as the node:vm engine.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed for v5, fixed in b61f19b: Float16Array is now listed next to Float32Array/Float64Array in docs/content/docs/v5/foundations/serialization.mdx, and the PR description has a Docs Preview section.

I left v4 alone on purpose. Nothing in this PR applies to 4.x: stable has no QuickJS engine and no hardened viewInfo (it calls devalue's stringify with the default operations). Whether to list Float16Array in the v4 docs belongs with a fix on stable, not here.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Sim World

Simulated world deterministic testing for races. Traces

🟠 world-sim scenario book — 1 fail of 42 total

fence=per-spec

scenario outcome events virt replay violations
✅ smoke-no-steps completed 3 0ms ok 0
✅ smoke-one-step completed 6 0ms ok 0
✅ hook-at-step-started completed 12 0ms ok 0
✅ hook-at-step-completed completed 12 0ms ok 0
✅ hook-at-hook-created completed 12 0ms ok 0
✅ deadline-hook-wins completed 7 1.0h ok 0
✅ deadline-expires completed 7 1.0h ok 0
✅ step-vs-timer-early-settlement completed 8 1.0h ok 0
✅ long-sleep completed 11 30.0d ok 0
✅ hook-never-arrives stalled 3 0ms skipped 0
✅ step-retries-twice completed 10 2.0s ok 0
✅ parallel-steps completed 9 0ms ok 0
✅ hook-on-execution-state completed 12 0ms ok 0
✅ peek-hook-before-branch completed 12 0ms ok 0
✅ peek-hook-after-branch completed 12 0ms ok 0
✅ peek-hook-at-registration completed 12 0ms ok 0
✅ race-hook-before-probe completed 12 0ms ok 0
✅ race-hook-after-probe completed 12 0ms ok 0
✅ race-duplicate-delivery completed 13 0ms ok 0
✅ attr-hook-before-step completed 11 0ms ok 0
✅ attr-hook-after-step completed 11 0ms ok 0
✅ attr-from-step-body completed 13 0ms ok 0
✅ fork-hook-after-timeout completed 14 1.0m ok 0
✅ fork-hook-before-timeout completed 14 1.0m ok 0
✅ count-hook-after-timeout completed 17 1.0m ok 0
✅ count-hook-before-timeout completed 20 1.0m ok 0
✅ stale-read-step-count-fork completed 20 1.0m ok 0
✅ stale-read-equal-step-counts completed 14 1.0m ok 0
✅ step-vs-step-fork completed 12 0ms ok 0
✅ step-vs-step-fork-fenced completed 12 0ms ok 0
✅ fence-catches-benign-direction completed 12 5ms ok 0
✅ in-flight-before-decision completed 17 1.0m ok 0
❌ in-flight-before-decision-counted completed 17 1.0m ok 0
✅ in-flight-after-decision completed 19 2.0m ok 0
✅ stale-read-step-count-fork-fenced completed 20 1.0m ok 0
✅ fork-hook-wins completed 13 1.0m ok 0
✅ fork-timeout-wins completed 13 1.0m ok 0
✅ unclaimed-payload-under-fork completed 17 1.0m ok 0
✅ claimed-payload-under-fork completed 17 1.0m ok 0
✅ writers-independent-step-bodies completed 12 0ms ok 0
✅ writers-scripted-tempo completed 12 0ms ok 0
✅ cancel-mid-step cancelled 7 0ms skipped 0

Full trace: world-sim.txt

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor
Framework Flow route Step reg. Framework output
hono 267.2 KiB (±0) 97.3 KiB (±0) 2.01 MiB (-84 B)
nextjs-turbopack 274.6 KiB (±0) 426 B (±0) 986.2 KiB (+83 B)
About these numbers

Sizes are gzip; parentheses show the change against main.
Flow route and Step reg. gate this job, on raw bytes rather than the gzip shown, at max(2%, 50.0 KiB). Framework output is informational.

b61f19b · run

@TooTallNate
TooTallNate enabled auto-merge (squash) October 2, 2026 18:52
@TooTallNate
TooTallNate merged commit c1e70ef into main Oct 2, 2026
326 of 329 checks passed
@TooTallNate
TooTallNate deleted the fix/serialize-unclaimed-view-bytes branch October 2, 2026 19:13
@github-actions github-actions Bot mentioned this pull request Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

No backport to stable for c1e70ef (AI decision).

The fix lands almost entirely in code that does not exist on stable: packages/core/src/serialization/hardened.ts, packages/core/src/serialization/codec-devalue-vm.ts, and packages/core/src/runtime/quickjs-serde.ts are all absent there (verified with git ls-tree origin/stable), and stable's serialization.ts calls devalue's stringify without any custom viewInfo operations, so the hardened override this patch corrects has no counterpart to correct. The commit also mixes in feature work — Float16Array support in the QuickJS engine (previously it threw, with no leak since that VM has no Buffer pool) plus the v5-only docs addition — and the PR itself states the changes are 5.x-only. If the equivalent pool-residue leak affects 4.x, it would need a separately written fix (likely a devalue upgrade) rather than this cherry-pick.

To override, re-run the Backport to stable workflow manually via workflow_dispatch and paste this commit SHA into the ref input:

c1e70efbe0c0ed6d73230773af3f9d15c17a45d6

TooTallNate added a commit that referenced this pull request Oct 2, 2026
## Summary

`packages/core/src/runtime/vm-serde-bundle.generated.ts` is dead code
that was committed by accident.

- #3048 generated it at build time with
`scripts/build-vm-serde-bundle.js` and gitignored it. It was the
serializer bundle evaluated *inside* the QuickJS VM.
- #3263 moved QuickJS serialization to the host
(`runtime/quickjs-serde.ts`). That PR deleted the build script and the
gitignore entry, but the leftover generated file got committed in the
same change.

Since then:
- nothing imports it, and no build step regenerates it (core's
`turbo.json` outputs list only `quickjs-assets.generated.ts`);
- `quickjs-serde.test.ts` refers to it as "the retired in-VM serde
bundle";
- it is stale: it predates #4443, so its reducers have no
`DataViewBytes`.

It never runs, but `tsc` compiles it into `@workflow/core`'s `dist`. It
is also easy to mistake for live serializer code during an audit (it
came up while auditing #4594).

## Changes

- Delete the file.
- Drop its path from the e2e build-artifact list in `tests.yml`, which
is meant to stay aligned with the `turbo.json` build outputs.

## Testing

- `tsc --noEmit` reports nothing referencing it; `src/runtime` tests
pass (1256).

This branch was successfully deployed

1 active deployment
Preview – workflow-docs — b61f19b0 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants