-
Notifications
You must be signed in to change notification settings - Fork 2
Comparing changes
Open a pull request
base repository: diunko/msgpack-node
base: master
head repository: msgpack/msgpack-node
compare: master
- 12 commits
- 121 files changed
- 4 contributors
Commits on Sep 24, 2019
-
Configuration menu - View commit details
-
Copy full SHA for bb073f2 - Browse repository at this point
Copy the full SHA bb073f2View commit details -
Merge pull request msgpack#51 from touhonoob/issue-50
Upgrade NAN to ^2.14.0
Configuration menu - View commit details
-
Copy full SHA for 84a9351 - Browse repository at this point
Copy the full SHA 84a9351View commit details -
Configuration menu - View commit details
-
Copy full SHA for a63f288 - Browse repository at this point
Copy the full SHA a63f288View commit details
Commits on Sep 18, 2026
-
feat: 2.0.0 security modernization (msgpack#25687)
* feat: 2.0.0 security modernization Vendor msgpack-c c-7.0.2, fail-closed unpack limits, and fix the sbuffer leak on pack throw (nodejs/node#25686). Replace nodeunit with node:test, require Node 18+, and run GitHub Actions on 18/20/22. * fix: address review round 2 on pack/unpack and CLI Dates and toJSON apply at every nesting level. Numeric object keys are packed instead of dropped. Cycle marks use V8 private symbols so a user key named _msgpack_stack is no longer stripped. Integral doubles outside uint64/int64 range (e.g. 1e30) pack as float64. Pack recursion is capped at 512 so 8000-deep input throws instead of SIGSEGV. The vendored C unpacker is built with MSGPACK_EMBED_STACK_SIZE=512 so advertised unpack depth matches the walker. Stream emits error on unpack throw and treats packed nil as a message. The CLI bins run on Node 18+. * fix: unpack __proto__, pack TryCatch, Stream emit order DefineOwnProperty on map keys so a wire __proto__ cannot replace the decoded object's prototype. Property reads during pack go through Nan::TryCatch so a throwing getter or Proxy ownKeys raises a catchable error instead of aborting on ToLocalChecked. Stream snapshots bytes_remaining and advances the buffer before emit('msg'), so a listener that unpacks or throws cannot desync or replay a frame. * fix: pack top-level Buffer as bin, not toJSON map pack() ran a JS pre-pass that called toJSON() on any top-level object. Buffer.prototype.toJSON exists, so msgpack.pack(Buffer.from([1,2,3])) emitted a {type:'Buffer',data:[...]} map instead of msgpack bin, and unpack() no longer returned a Buffer. Nested Buffers were unaffected because they went straight to the binding. The pre-pass is redundant: the native JsToMsgpack checks node::Buffer::HasInstance before the generic object path, PackObject applies toJSON at every level, and Dates pack as ISO strings natively. Drop it and forward arguments to the binding unchanged. Co-Authored-By: Claude Opus 5 <[email protected]> * fix: load native addon in worker_threads NODE_MODULE is not context-aware, so requiring msgpack in the main thread then in a Worker throws "Module did not self-register". Register with NODE_MODULE_CONTEXT_AWARE and keep the sbuffer pool, unpack remainder, and cycle-detection key thread_local so workers do not race the main isolate. Fixes msgpack#60 * test: lock Stream 0 and Python bin-map unpack Packed integer 0 must emit on Stream (msgpack-node#44). A map written by python-msgpack with a bin8 payload must unpack Payload as Buffer (msgpack-node#10). Both already work on 2.0.0; these tests keep them so. Refs msgpack#10 Refs msgpack#44 * feat: ship TypeScript types for pack, unpack, and Stream Adds index.d.ts matching the 2.0.0 runtime: pack(...values) returns Buffer, unpack.bytes_remaining is per-thread, Stream wraps a duplex. Fixes msgpack#39 * fix: thread_local sbuf pool and NAN_MODULE_WORKER_ENABLED Address review on PR msgpack#2 for worker_threads (msgpack#60): - Mark sbuf_pool thread_local so a worker pack cannot share the pool - Register with NAN_MODULE_WORKER_ENABLED instead of NODE_MODULE_CONTEXT_AWARE - Return non-pooled sbuffers to the pool so it actually fills - Add concurrent pack (workers + main) and sequential pool-reuse tests * test: raise JS and native coverage to 95% lib/ and bin/ reach 100% statements/branches/functions/lines under c8; src/msgpack.cc reaches 95.9% lines and 99.5% branches under gcovr. New tests: - test/coverage-native.test.js walks every MessagePack format family from hand-built wire bytes, including the ones pack() never emits (float32, str8/16/32, bin16/32, array32, map16/32, all eight ext forms, negative fixint); a truncation point for every header and payload; the kMaxBytes, kMaxContainer and kMaxDepth rejections; 0xc1; the pack-side type dispatch (Symbol, BigInt, non-finite numbers, integer edges, undefined, zero- and multi-argument pack); Date and toJSON failure modes with mark cleanup; and a worker nesting 600 packs deep to saturate the thread-local sbuffer pool and reach the "pool is full, free it" arm of ~PackBuffer. - test/cli.test.js covers the exit-1 paths of both CLIs. The pack-failure arm of json2msgpack is reachable from real JSON only through nesting deeper than the 512-level pack cap; every other pack error needs a value JSON.parse cannot produce. Infrastructure: - binding.gyp grows an msgpack_coverage variable, default 0. Only when it is set to 1 does the addon compile and link with --coverage -O0 -g, so npm install and node-gyp rebuild stay uninstrumented. - npm run coverage runs coverage:js (c8, gated at 95% on all four metrics) then coverage:native (scripts/coverage-native.js). The native script rebuilds instrumented, runs the suite, gates on gcovr --fail-under-line 95 --fail-under-branch 95 over src/ excluding deps/, and always rebuilds uninstrumented afterwards -- including when the gate fails. src/msgpack.cc gains comments only. GCOVR_EXCL_BR markers, each with its reason inline, mark branches unreachable without stubbing malloc or V8: allocation-failure arms of msgpack_pack_*, empty-MaybeLocal guards, Skip() calls a preceding CheckBytes has already proved safe, and the post-ScanOne error tail of Unpack. No production code was removed. COVERAGE.md lists all 45 marked lines, the 20 still-uncovered lines, the 2 still-uncovered branches and the un-gated numbers (70.6% raw, 86.3% throw-excluded, 99.5% as shipped). * ci: fail coverage job under 95% Adds an ubuntu-latest / Node 20 job that installs gcovr via pip when it is not already present and runs npm run coverage. Both halves are threshold- gated, so the job fails when JS or native coverage drops below 95%. The existing node 18/20/22 x ubuntu/macos test matrix is unchanged. * docs: document npm run coverage in README Acceptance requires the coverage script in the Building section and a pointer to COVERAGE.md for gates and remainder. * docs: address review — license history, CLI, current benchmarks Strip personal-fork branding so this reads as the upstream 2.0.0 tree. Document that vendored msgpack-c c-7.0.2 is Boost Software License 1.0 (relicensed from Apache-2.0 in msgpack-c 1.3.0). Restore Command Line Utilities and Benchmarks, refresh the bench runner for Node 18+, and record current numbers. * fix: restore contributors and cite msgpack-node#25686 Restore the master contributors list in package.json. Point SECURITY.md, src/msgpack.cc, and the leak regression at msgpack#25686 instead of nodejs/node#25686. Correct the Stream comment: bytesRemaining is thread_local. Add windows-latest to the CI matrix. Closes msgpack#25686 * fix: Windows CI native rebuild and Stream test comment Pin the Windows matrix to windows-2022 so node-gyp 10/11 (Node 18/20/22) can find Visual Studio. windows-latest currently ships VS 2026, which those node-gyp versions report as unknown version "undefined". Run install and test as one bash command so a failed rebuild cannot continue into npm test. List test files explicitly so npm test works on Windows Node 18/20 (cmd.exe does not expand *, and node --test globs need Node 21+). The Stream test comment now matches thread_local bytesRemaining. --------- Co-authored-by: Claude Opus 5 <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for e04c9b5 - Browse repository at this point
Copy the full SHA e04c9b5View commit details
Commits on Sep 19, 2026
-
docs: add Keep a Changelog for 2.0.0 (msgpack#25688)
Record the 2.0.0 security modernization against master e04c9b5. No v2.0.0 tag exists yet, so compare links use that commit. Closes msgpack#38
Configuration menu - View commit details
-
Copy full SHA for 5c557fb - Browse repository at this point
Copy the full SHA 5c557fbView commit details -
feat: pack and unpack 64-bit integers as BigInt (msgpack#25689)
Integers outside Number.MAX_SAFE_INTEGER unpack as bigint instead of a rounded number. Values that fit stay number regardless of wire width. pack() accepts bigint in the int64/uint64 range and throws for anything larger. Closes msgpack#37.
Configuration menu - View commit details
-
Copy full SHA for 1efff3d - Browse repository at this point
Copy the full SHA 1efff3dView commit details -
Configuration menu - View commit details
-
Copy full SHA for f578245 - Browse repository at this point
Copy the full SHA f578245View commit details -
Configuration menu - View commit details
-
Copy full SHA for adad486 - Browse repository at this point
Copy the full SHA adad486View commit details -
Configuration menu - View commit details
-
Copy full SHA for 4944d65 - Browse repository at this point
Copy the full SHA 4944d65View commit details -
feat: pack oversized BigInt as MessagePack ext 0x42 (msgpack#25693)
Values outside int64/uint64 pack as msgpackr useBigIntExtension (two's-complement, type 0x42) with a 256-byte payload cap. In-range values still use integer wire. Unpack of ext 0x42 returns bigint.
Configuration menu - View commit details
-
Copy full SHA for c0f78a1 - Browse repository at this point
Copy the full SHA c0f78a1View commit details
Commits on Sep 22, 2026
-
fix: close review issues msgpack#25696-msgpack#25703 on 3.4.0 (msgpac…
…k#25695) * fix: close review issues msgpack#25696-msgpack#25703 on 3.4.0 Rebase the OPEN review follow-ups onto live upstream master (c0f78a1, 3.4.0) so Stream drain/backpressure from msgpack#43 is kept. Pin nan 2.28.0 and c8 12.0.0; CI uses npm ci on Node 22/24 with full-SHA GitHub Actions. engines.node is >=22. Cap Stream receive before allocate and drop buf on close/end/error. Re-emit underlying socket errors when the Stream is not already dead so a socket 'error' is not swallowed by the listener. Apply kMaxContainer to pack array/map walks. Cap CLI stdin concat at MAX_STDIN_BYTES. Document a risk-based bump window in SECURITY.md. * fix: drop Node 24 from engines and CI InitLazy still calls ObjectTemplate::SetIndexedPropertyHandler, which Node 24 V8 headers no longer provide. Parent never tested 24. engines.node is ^22 so 24 is not advertised. CI matrix is [22] only. * fix: cap PackArrayInterpreted at kMaxContainer Snapshot Length() once, throw when n > 1e6, and iterate the frozen n so interpret cannot walk a sparse array past the PackArray policy.
Configuration menu - View commit details
-
Copy full SHA for 4f93644 - Browse repository at this point
Copy the full SHA 4f93644View commit details
Commits on Sep 29, 2026
-
ci: pin coverage Python/gcovr and align lockfile docs (msgpack#25704)
- Pin coverage job to Python 3.12 and gcovr==8.6 - Record package 3.4.0 in package-lock.json - Name package-lock.json instead of a missing shrinkwrap in SECURITY.md
Configuration menu - View commit details
-
Copy full SHA for e65d556 - Browse repository at this point
Copy the full SHA e65d556View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff master...master