Skip to content

2026-08-05, Version 26.7.0 (Current) - #65027

Merged
aduh95 merged 152 commits into
v26.xfrom
v26.7.0-proposal
Aug 5, 2026
Merged

2026-08-05, Version 26.7.0 (Current)#65027
aduh95 merged 152 commits into
v26.xfrom
v26.7.0-proposal

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor
  • [82712652cb] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #63949
  • [b3aec47d09] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746
  • [c1e4f7365e] - (SEMVER-MINOR) lib: add perfetto support (Chengzhong Wu) #64565
  • [11c2f9c642] - (SEMVER-MINOR) module: implement Symbol.dispose in ModuleHooks (Remco Haszing) #63928
  • [b6e7935aca] - (SEMVER-MINOR) net: add experimental node:net/promises API (Ethan Arrowood) #63965 removed as it should be treated as semver-major PRs that contain breaking changes and should be released in the next major version.
  • [dccee04558] - (SEMVER-MINOR) test_runner: add support for --test-coverage-include-all (avivkeller) #64830
Commits
  • [6168067ee0] - async_hooks: use validateBoolean for trackPromises (Soul Lee) #64731
  • [6eb33c2edd] - benchmark: fix calibrate-n option handling (Luan Muniz) #64146
  • [6c107c35ad] - buffer: use Clamp conversion in Blob slice (Donghoon Kang) #64739
  • [5fda0958bd] - buffer: validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) #63904
  • [5e433fdee6] - build: run perfetto build and test on GHA (Chengzhong Wu) #64721
  • [11680ab225] - build: fix v8_use_perfetto source scraping (Chengzhong Wu) #64721
  • [ab5f076d7f] - build: bump rustc requirement to >=1.86 (Renegade334) #64543
  • [df608e061f] - (SEMVER-MINOR) build: perfetto-sdk (Chengzhong Wu) #64565
  • [78538f1207] - build,tools: fix shared library cross-compile (Kirill Saied) #63963
  • [82712652cb] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #63949
  • [59f0682f7f] - crypto: preserve OpenSSL errors from KDF failures (Filip Skokan) #64776
  • [0a23c1a8bc] - crypto: fix Argon2 bypassing FIPS mode (Filip Skokan) #64776
  • [b3aec47d09] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746
  • [31f8c91e6e] - crypto: clarify missing cipher error (Filip Skokan) #64852
  • [efa22e71ff] - crypto: reuse X509 issuer result (Filip Skokan) #64852
  • [ac954d24ef] - crypto: validate key generation options (Filip Skokan) #64852
  • [a8a4e6669d] - crypto: fix Argon2 validation errors (Filip Skokan) #64852
  • [0264a04aff] - crypto: handle XOF output allocation failure (Filip Skokan) #64851
  • [6bb4121ed1] - crypto: initialize KeyObjectData mutex eagerly (Filip Skokan) #64851
  • [1516f7fc09] - crypto: handle DH operation failures (Filip Skokan) #64851
  • [12170c3753] - crypto: use user-facing error for output encoding changes (Archkon) #64692
  • [474f06d550] - debugger: preserve overlapping CDP request state (Trivikram Kamat) #64467
  • [95d27e2249] - deps: upgrade npm to 11.19.0 (npm team) #64883
  • [c03c9090d3] - deps: update ngtcp2 to 1.25.0 (Node.js GitHub Bot) #64944
  • [ebbb978b87] - deps: update nghttp3 to 1.18.0 (Node.js GitHub Bot) #64943
  • [2c4bf7234d] - deps: update minimatch to 10.2.6 (Node.js GitHub Bot) #64945
  • [29006f6da6] - deps: update simdjson to 4.6.6 (Node.js GitHub Bot) #64942
  • [d97ba2cb6c] - deps: update acorn to 8.18.0 (Node.js GitHub Bot) #64941
  • [261d78d724] - deps: update googletest to 1b6f64d659944658a4c685b7bd9f04c1c3b8a39b (Node.js GitHub Bot) #64940
  • [3133097be3] - deps: update nghttp2 to 1.70.0 (Node.js GitHub Bot) #64939
  • [ebcf3c95c9] - deps: update zlib to 1.3.2.1-motley-42c2f19 (Node.js GitHub Bot) #64744
  • [a22e4317c1] - deps: V8: backport 5177b10891e6 (avivkeller) #64631
  • [cd95d5c598] - deps: update ada to 4.0.0 (Node.js GitHub Bot) #64790
  • [70dedef942] - deps: update sqlite to 3.53.4 (Node.js GitHub Bot) #64745
  • [7bc4c171f5] - deps: update Rust crates for V8 14.6.202.34-node.26 (Renegade334) #64543
  • [308c6b2ac3] - deps: V8: backport 7d9b7e03141d (Manish Goregaokar) #64543
  • [8eeae28e88] - deps: V8: backport c4d06ba586f3 (liujiahui) #63731
  • [bbd6fc58c4] - diagnostics_channel: grow native channel storage (Stephen Belanger) #64497
  • [37a41c228b] - doc: fix grammar and punctuation in dgram documentation (Kamal Rawal) #64957
  • [a7625d5012] - doc: fix grammar and editorial issues in addons documentation (Kamal Rawal) #64952
  • [431fddf1c5] - doc: formalize fn/name as part of TestOptions API (Christopher Hiller) #64946
  • [a3951574dd] - doc: remove references to ca/crl as per-context QuicSession options (René) #64769
  • [abce850aef] - doc: fix typo in maintaining-dependencies.md (greenhead) #64896
  • [0a0549fcb9] - doc: add RafaelGSS as last security release stewards (Rafael Gonzaga) #64843
  • [3da9d77f27] - doc: fix typos in documentation (greenhead) #64900
  • [aa7c363f6d] - doc: fix missing references in doc type map (Tim Perry) #64872
  • [25c86942ae] - doc: improve TestContext hook descriptions (Kamal Rawal) #64899
  • [d926ddc307] - doc: add missing float32/float64 FFI type names (Soul Lee) #64874
  • [f2a05ee3d1] - doc: document stream.isDestroyed() (YspritanHyzygy) #64789
  • [5604e4e8e5] - doc: add contributing detail for git Signed-off-by trailer (Mike McCready) #64862
  • [fa6075f1ed] - doc: mark config-file as release candidate (Marco Ippolito) #64516
  • [24530c76bc] - doc: fix duplicated word in test snapshot docs (Kamal Rawal) #64837
  • [e27b4ad287] - doc: remove obsolete cctest node.gyp instructions (Soul Lee) #64814
  • [24c7eaf661] - doc: report proper return type on url.format (Brian Muenzenmeyer) #64806
  • [d35315b263] - doc: use ffi.suffix for library paths in examples (Junsoo Ha) #64805
  • [4be571df69] - doc: document --permission-audit audit mode behavior (Adrián Estrada) #64791
  • [e48b917bf7] - doc: clarify tlsSocket.authorized on resumption (soreavis) #64584
  • [db95655c4a] - doc: stabilize --disable-warning (Jean Michelet) #64742
  • [a8367200be] - doc: add MDN links for explicit resource management in fs (lluisemper) #59557
  • [1c09165c2e] - doc: mention constructor check in deepStrictEqual (Sumit Kumar Das) #62010
  • [29709324e0] - doc: update technical priorities (Jacob Smith) #64505
  • [522a28e648] - doc: deprecation add more codemod (Augustin Mauroy) #63175
  • [c40aaa6539] - doc: run license-builder (Node.js GitHub Bot) #63918
  • [e64152c641] - ffi: fix crash in refCallback and unrefCallback (Trivikram Kamat) #64881
  • [9b5642cbbf] - ffi: reject fast calls after library close (Trivikram Kamat) #64860
  • [7adc5a45ad] - ffi: validate fast 32-bit integer argument ranges (Trivikram Kamat) #64691
  • [2c3b1f1e9d] - ffi: fix optimized buffer conversions (Trivikram Kamat) #64639
  • [b2762a1ffa] - ffi: preserve link register in ppc64 trampoline (Trivikram Kamat) #64792
  • [aa3f168b31] - ffi: preserve strings during reentrant calls (Trivikram Kamat) #64551
  • [ca60942f38] - ffi: preserve uint8 semantics for bool fast calls (Trivikram Kamat) #64527
  • [0fb1d2bd65] - ffi: validate fast integer argument ranges (Trivikram Kamat) #64614
  • [9209bf1bd2] - fs: key glob matcher cache by platform (Archkon) #64571
  • [4de7938c5b] - http: fix writableFinished and 'finish' after write errors (Tim Perry) #64847
  • [daee5467c0] - http: avoid aborting IncomingMessage signal on normal close (Archkon) #64392
  • [d5cdc120c3] - http: guard invalid timeout values in checkConnections (Efe Karasakal) #64506
  • [6879aa4aa8] - http: propagate highWaterMark to ClientRequest OutgoingMessage (trivenay) #64653
  • [72448a82f4] - http2: avoid copying the options in respond() (Matteo Collina) #64265
  • [f6692da576] - http2: avoid per-write closures in kWriteGeneric (Matteo Collina) #64265
  • [3ed37153f8] - http2: reduce per-request allocations (Matteo Collina) #64265
  • [bce92debba] - Revert "http2: avoid per-write closures in kWriteGeneric" (Antoine du Hamel) #64663
  • [b5d5dd74a1] - Revert "http2: avoid copying the options in respond()" (Antoine du Hamel) #64663
  • [b95e5f9fd8] - lib: fix AbortSignal.any() observed-composite leak (Paul Bouchon) #64481
  • [22d8868e37] - lib: fix typo in comment in _http_client.js (agape1225) #64729
  • [c1e4f7365e] - (SEMVER-MINOR) lib: add perfetto support (Chengzhong Wu) #64565
  • [6c2157522d] - loader: enforce path normalization before lookup (Maël Nison) #63917
  • [f14be4c42a] - meta: bump actions/stale from 10.3.0 to 11.0.0 (dependabot[bot]) #64935
  • [f13b57da0d] - meta: bump github/codeql-action/analyze from 4.36.2 to 4.37.3 (dependabot[bot]) #64934
  • [3e5f5f3cca] - meta: bump github/codeql-action/autobuild from 4.36.2 to 4.37.3 (dependabot[bot]) #64933
  • [387211bcdb] - meta: bump actions/setup-python from 6.3.0 to 7.0.0 (dependabot[bot]) #64932
  • [e7738fa25d] - meta: bump github/codeql-action/init from 4.36.2 to 4.37.3 (dependabot[bot]) #64931
  • [cbceae1e4d] - meta: bump Mozilla-Actions/sccache-action from 0.0.10 to 0.0.11 (dependabot[bot]) #64930
  • [68ce6c71ab] - meta: bump cachix/install-nix-action from 31.10.6 to 31.11.0 (dependabot[bot]) #64929
  • [9d7e7c21a3] - meta: bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.3 (dependabot[bot]) #64927
  • [402c1eacb4] - meta: bump step-security/harden-runner from 2.19.4 to 2.20.0 (dependabot[bot]) #64926
  • [dba4d4b4c7] - meta: bump ossf/scorecard-action from 2.4.3 to 2.4.4 (dependabot[bot]) #64925
  • [9077d72ffe] - meta: remove node_crates .gitignore (René) #64779
  • [8e03c54347] - meta: add @nodejs/url as codeowner for node_url_pattern.* (Efe Karasakal) #64737
  • [11c2f9c642] - (SEMVER-MINOR) module: implement Symbol.dispose in ModuleHooks (Remco Haszing) #63928
  • [b6e7935aca] - (SEMVER-MINOR) net: add experimental net/promises API (Ethan Arrowood) #63965
  • [fffd8a76d0] - net: support TCP handle transfer on Windows (Matteo Collina) #64460
  • [fe9e0dbdc2] - net: support AF_UNIX paths in net.BoundSocket (Guy Bedford) #64399
  • [240a86dac0] - permission: add unique warning codes (David Evans) #64414
  • [e970e6735b] - permission: support v8.setHeapSnapshotNearHeapLimit (Ilyas Shabi) #64808
  • [0ba091165c] - quic: fix stop sending behaviour & callback (Tim Perry) #64710
  • [117ac84542] - quic: fix coverage comment typo (Jungwon Sohn) #64486
  • [960cc2c644] - quic: fix segfault after fragmented client hello (Tim Perry) #64720
  • [dcc348af97] - quic: serialize stream reset code as string (한만욱) #64577
  • [c25b8e3331] - readline: reduce createInterface overhead (Matteo Collina) #64585
  • [9d536c3eb8] - sqlite: invalidate sessions when closing database (Trivikram Kamat) #64783
  • [d31113ef25] - sqlite: check database state before calling SQLite (Trivikram Kamat) #64812
  • [bb86521a42] - sqlite: fix crash when a session outlives its database (Mohamed Sayed) #63797
  • [870f4997e7] - sqlite: fix use-after-free in Exec() and ApplyChangeset() (Matteo Collina) #64535
  • [863ce4a78b] - src: fix perfetto build on GetTraceFilePath (Chengzhong Wu) #64721
  • [c299d2eef3] - src: implement MemoryRetainer protocol for ByteSource (Filip Skokan) #64660
  • [8725e56928] - src: fix crash when writing odd-length hex string via Writev (RajeshKumar11) #63658
  • [e018f9a4a1] - (SEMVER-MINOR) src: add perfetto trace agent (Chengzhong Wu) #64565
  • [0611d443ab] - (SEMVER-MINOR) src: rename legacy trace event headers (Chengzhong Wu) #64565
  • [2897cc1d93] - (SEMVER-MINOR) src: fix trace macro compatibility (Chengzhong Wu) #64565
  • [d4d7172e10] - src: avoid using ToLocalChecked in crypto_hash (James M Snell) #64668
  • [53b7d48b47] - src: fix libuv assertion on windows (liuxingbaoyu) #61999
  • [bc041dd2bd] - src,test: disable trace events tests when perfetto is enabled (Chengzhong Wu) #64721
  • [76baf80f81] - stream: cut per-chunk allocations in pipeTo (Matteo Collina) #64890
  • [452c544489] - stream: preserve push signal abort reason (Trivikram Kamat) #64798
  • [f98a0f9c5b] - stream: skip zero-byte broadcast writes (Trivikram Kamat) #64772
  • [420c3efcab] - stream: honor AbortSignal in Writer.end() (Trivikram Kamat) #64727
  • [1e182d147f] - stream: use validateString for consumer encoding (Jungwon Sohn) #64754
  • [e024712134] - stream: use the ring buffer for pending BYOB pull-into descriptors (Matteo Collina) #64818
  • [fe06bf56dc] - stream: fix uncatchable error closing half-open Duplex.toWeb() writable (Mohamed Sayed) #64161
  • [6f57dbc1da] - test: unflake debugger and REPL tests (Matteo Collina) #64718
  • [582e88a68c] - test: ensure assertions are reached on all tests (Antoine du Hamel) #64716
  • [ba1ef78e48] - test: reuse ffi.suffix instead of reimplementing it (Seongeun Lee) #64840
  • [e700a2e72c] - test: remove test-repl-user-error-handler from flaky (avivkeller) #64631
  • [fafac6e29c] - test: update WPT for url to 4832db4761 (Node.js GitHub Bot) #64829
  • [37dee176c1] - test: update WPT for url to b63305b743 (Node.js GitHub Bot) #64790
  • [4cb72eecb3] - test: cover worker throwing primitive values (varshitha) #64365
  • [796acc8920] - test: mark test-repl-user-error-handler as flaky (Aviv Keller) #64612
  • [dccee04558] - (SEMVER-MINOR) test_runner: add support for --test-coverage-include-all (avivkeller) #64830
  • [04bba8d6c0] - test_runner: wait for filtered suite build (semimikoh) #64208
  • [70d11241a3] - test_runner: convert to uint during deserialization (Aviv Keller) #64706
  • [4bc2ed847e] - tls: fix SNICallback certificate selection (Matteo Collina) #64700
  • [3f53f86e86] - tools: bump the eslint group in /tools/eslint with 4 updates (dependabot[bot]) #64928
  • [339d5a1c9e] - tools: bump brace-expansion from 5.0.7 to 5.0.9 in /tools/eslint (dependabot[bot]) #64904
  • [65ef34b75c] - tools: use 'readonly' for EventSource global (Honey Tyagi) #64787
  • [92f5aed83b] - typings: add heap_utils internalBinding types (Donghoon Kang) #64816
  • [3bc0ee0492] - typings: remove isDataView from types binding (Archkon) #64738
  • [236d7ca965] - url: create URLPattern result properties in WebIDL order (Archkon) #64733
  • [3def577ab4] - v8: report minor mark-sweep in GCProfiler (Archkon) #64688
  • [de2ebff845] - vfs: speed up recursive readdir test setup (Trivikram Kamat) #64813
  • [4345185496] - vfs: make lchown update symlink metadata (Trivikram Kamat) #64573
  • [f6e39ed872] - wasm: register missing SetURL function (Archkon) #64679
  • [f322870bd1] - zlib: validate pledgedSrcSize as a safe integer (Archkon) #64604
  • [44042c20d4] - zlib: accept ArrayBuffer dictionary in Zstd (Ryuhei Shima) #64599

aduh95 and others added 30 commits August 4, 2026 18:40
This reverts commit 3329647.

PR-URL: #64663
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Ethan Arrowood <[email protected]>
This reverts commit a44fca5.

PR-URL: #64663
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Ethan Arrowood <[email protected]>
Cut several sources of per-stream/per-request overhead on the hot
path:

- Track 'priority'/'frameError' stream listeners by overriding the
  EventEmitter methods on Http2Stream instead of subscribing to
  'newListener'/'removeListener', which made every listener add and
  remove on every stream emit an extra tracking event.
- Replace the per-call SafeSet and sensitive-header mapping in
  buildNgHeaderString with a lazily allocated array and an
  empty-array fast path, and skip the HTTP token regex and
  connection-specific header checks for well-known single-value
  header names.
- Replace per-call closures with shared named handlers in
  onStreamClose, afterShutdown and Http2Stream._destroy.
- Skip the pendingStreams Set add/delete for streams that are
  created with their native handle already available (all server
  streams).
- Hoist the per-request onStreamTimeout closure factories in the
  compat layer to module-level handlers, and avoid a once() wrapper
  allocation per server stream.

h2load, 1 KiB response payload, -c 4 -m 100, mean of 6 alternating
runs: core API 60.2k -> 69.3k req/s (+15%), compat API 43.6k ->
46.2k req/s (+5.9%).

Signed-off-by: Matteo Collina <[email protected]>
PR-URL: #64265
Backport-PR-URL: #64663
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Ethan Arrowood <[email protected]>
Every _write()/_writev() on an Http2Stream allocated four closures
and an anonymous nextTick callback to coordinate the write callback
with the end-of-stream check. Since the stream machinery dispatches
at most one write at a time, that coordination state can live on the
stream's kState object instead, with shared named functions for the
end check and completion logic.

When trailers are pending the writable side cannot be shut down
early anyway, so the end-of-stream check tick is now skipped
entirely for those writes.

Also pre-initialize the kState fields that used to be added
dynamically (shutdownWritableCalled, fd) so hot-path stores no
longer transition the object shape.

h2load, 1 KiB response payload, -c 4 -m 100, mean of 6 alternating
runs vs main: core API 61.0k -> 70.7k req/s (+15.9% cumulative),
compat API 43.7k -> 50.4k req/s (+15.3% cumulative).

Signed-off-by: Matteo Collina <[email protected]>
PR-URL: #64265
Backport-PR-URL: #64663
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Ethan Arrowood <[email protected]>
respond() copied the user-provided options object on every call just
so it could normalize and locally flip options.endStream, and
prepareResponseHeadersObject() then looked the :status and date
fields up again on the dictionary-mode null-prototype headers copy
it had just built. Use a local variable for endStream and pick up
:status/date while copying the headers instead.

No measurable throughput change on its own; this removes an object
clone and several dictionary-mode property lookups per response.

Signed-off-by: Matteo Collina <[email protected]>
PR-URL: #64265
Backport-PR-URL: #64663
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Ethan Arrowood <[email protected]>
Fixes: #64598
Signed-off-by: islandryu <[email protected]>
PR-URL: #64599
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Every string-named JavaScript channel consumed an entry in the fixed
native subscriber array. Creating more than 1,024 channels triggered a
CHECK and terminated the process.

Allocate slots only for native publishers and grow the aliased buffer
when it fills. Refresh the JavaScript view after resizing and preserve
the capacity in snapshots.

Signed-off-by: Stephen Belanger <[email protected]>
PR-URL: #64497
Reviewed-By: Rafael Gonzaga <[email protected]>
Reviewed-By: Gerhard Stöbich <[email protected]>
Reviewed-By: James M Snell <[email protected]>
Validate narrow integer and 64-bit BigInt arguments before entering
the Fast API trampoline. This prevents out-of-range values from being
silently truncated or wrapped and matches the generic FFI path.

Signed-off-by: Kamat, Trivikram <[email protected]>
Assisted-by: openai:gpt-5.6-sol
PR-URL: #64614
Fixes: #64613
Reviewed-By: Paolo Insogna <[email protected]>
Reviewed-By: Matteo Collina <[email protected]>
Normalize bool to kUint8 when creating Fast API metadata. This keeps
optimized calls consistent with generic FFI behavior, including numeric
return values and rejection of JavaScript Boolean values.

Signed-off-by: Kamat, Trivikram <[email protected]>
Assisted-by: openai:gpt-5.6-sol
PR-URL: #64527
Fixes: #64526
Reviewed-By: Paolo Insogna <[email protected]>
When sqlite3_exec() or sqlite3changeset_apply() call JavaScript
callbacks (user-defined functions, conflict handlers, or filter
callbacks), the DatabaseSync object could be garbage-collected
if the JavaScript code drops all references to it. Both methods
only held a raw DatabaseSync* pointer on the C++ stack, which
V8 GC does not track.

Add a BaseObjectPtr<DatabaseSync> guard that keeps the database
alive for the duration of these SQLite API calls, preventing a
use-after-free when the JavaScript callback triggers GC.

Signed-off-by: Matteo Collina <[email protected]>
PR-URL: #64535
Reviewed-By: Edy Silva <[email protected]>
Reviewed-By: Stephen Belanger <[email protected]>
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: René <[email protected]>
Cache temporary string conversion buffers by wrapper and active call
depth. This prevents nested FFI calls from overwriting or replacing
buffers still in use by an outer native call.

Signed-off-by: Kamat, Trivikram <[email protected]>
Assisted-by: openai:gpt-5.6-sol
PR-URL: #64551
Fixes: #64550
Reviewed-By: Paolo Insogna <[email protected]>
Reviewed-By: Matteo Collina <[email protected]>
`http.request({ highWaterMark })` passes the value to the TCP socket
via createConnection() but does not set it on the OutgoingMessage
internal kHighWaterMark.  OutgoingMessage._writeRaw() has two mutually
exclusive write paths:

  Path A (socket connected): conn.write() — uses socket HWM ✓
  Path B (no socket yet):    outputSize < this[kHighWaterMark] — uses
                             OutgoingMessage own default (64 KB) ✗

Because the OutgoingMessage constructor already accepts
options.highWaterMark, the fix is to set kHighWaterMark from the
user options after they are parsed in the ClientRequest constructor.

This resolves two symptoms:

  1. write() returning the wrong boolean for pre-socket writes (the
     user highWaterMark was silently ignored on all Node versions).

  2. A deadlock on Node >= 24.16.0 where the incorrect false return
     sets kNeedDrain, but drain never fires because the socket was
     never backpressured (introduced by the stricter drain gate in
     #62936).

Signed-off-by: Naman Trivedi <[email protected]>
Fixes: #64645
Refs: #62936
PR-URL: #64653
Reviewed-By: Trivikram Kamat <[email protected]>
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Matteo Collina <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
pledgedSrcSize represents an exact byte count. Reject values that are
not non-negative safe integers instead of silently ignoring or coercing
them through IntegerValue().

Apply the same validation to zlib/iter and retain a native validation
check for internal callers.

Signed-off-by: Archkon <[email protected]>
PR-URL: #64604
Fixes: #64603
Reviewed-By: Ethan Arrowood <[email protected]>
Reviewed-By: Jan Martin <[email protected]>
PR-URL: #63918
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Michaël Zasso <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Ulises Gascón <[email protected]>
Ignore `PostDelayedTask` after `Stop`
to avoid assertions.

Fixes: #56645
Signed-off-by: liuxingbaoyu <[email protected]>
PR-URL: #61999
Reviewed-By: Santiago Gimeno <[email protected]>
Reviewed-By: Aviv Keller <[email protected]>
And other minor cleanups

Signed-off-by: James M Snell <[email protected]>
PR-URL: #64668
Reviewed-By: Filip Skokan <[email protected]>
Reviewed-By: Joyee Cheung <[email protected]>
Original commit message:

    [loong64][compiler] Extend Word64Select instruction functionality

    Change-Id: Iba762777642d2d2d3aa904f9afc1e9005139992e
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7801520
    Reviewed-by: Zhao Jiazhong <[email protected]>
    Commit-Queue: Liu Yu <[email protected]>
    Reviewed-by: Darius Mercadier <[email protected]>
    Auto-Submit: Liu Yu <[email protected]>
    Cr-Commit-Position: refs/heads/main@{#107619}

Refs: v8/v8@c4d06ba
Co-authored-by: liujiahui <[email protected]>
PR-URL: #63731
Fixes: #63721
Reviewed-By: René <[email protected]>
Reviewed-By: Michaël Zasso <[email protected]>
Signed-off-by: Chengzhong Wu <[email protected]>
PR-URL: #64565
Refs: nodejs/diagnostics#654
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Ryuhei Shima <[email protected]>
Signed-off-by: Chengzhong Wu <[email protected]>
PR-URL: #64565
Refs: nodejs/diagnostics#654
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Ryuhei Shima <[email protected]>
Signed-off-by: Chengzhong Wu <[email protected]>
PR-URL: #64565
Refs: nodejs/diagnostics#654
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Ryuhei Shima <[email protected]>
Signed-off-by: Chengzhong Wu <[email protected]>
PR-URL: #64565
Refs: nodejs/diagnostics#654
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Ryuhei Shima <[email protected]>
Signed-off-by: Chengzhong Wu <[email protected]>
PR-URL: #64565
Refs: nodejs/diagnostics#654
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Ryuhei Shima <[email protected]>
Speed up Interface construction:

- Hoist the history accessor property descriptors to module scope and
  define them with a single ObjectDefineProperties call, instead of
  allocating six closures and four descriptor objects per instance.
- Stop assigning the history options onto the input stream. This avoids
  hidden class transitions on the user provided stream and no longer
  mutates it observably.
- Only check process.env.TERM for a dumb terminal when the interface is
  in terminal mode. Reading process.env goes through the environment
  interceptor and is comparatively expensive, and _ttyWrite is never
  called when terminal is false.

Signed-off-by: Matteo Collina <[email protected]>
PR-URL: #64585
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Rafael Gonzaga <[email protected]>
Reviewed-By: Yagiz Nizipli <[email protected]>
Reviewed-By: Benjamin Gruenbaum <[email protected]>
Reviewed-By: Gürgün Dayıoğlu <[email protected]>
Signed-off-by: Guy Bedford <[email protected]>
PR-URL: #64399
Reviewed-By: Ethan Arrowood <[email protected]>
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Matteo Collina <[email protected]>
Signed-off-by: Matteo Collina <[email protected]>
PR-URL: #64460
Fixes: #64456
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Stefan Stojanovic <[email protected]>
Reviewed-By: Marco Ippolito <[email protected]>
A Debugger.paused event can arrive before the response to the resume
request that triggered it. The resulting probe evaluation replaces the
resume request in `inFlight`, but the resume cleanup then clears the
newer request's state.

Only clear `inFlight` when it still refers to the request being
completed. This preserves probe attribution when the target exits
during evaluation. Clarify the existing end-to-end test coverage
for this case.

Signed-off-by: Kamat, Trivikram <[email protected]>
Assisted-by: openai:gpt-5.6-sol
PR-URL: #64467
Refs: https://github.com/nodejs/reliability/issues?q=sort%3Aupdated-desc%20test-debugger-probe-failure-process-exit
Reviewed-By: Matteo Collina <[email protected]>
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Joyee Cheung <[email protected]>
Signed-off-by: Augustin Mauroy <[email protected]>
PR-URL: #63175
Reviewed-By: Trivikram Kamat <[email protected]>
Reviewed-By: Aviv Keller <[email protected]>
Signed-off-by: Jacob Smith <[email protected]>
PR-URL: #64505
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Ulises Gascón <[email protected]>
Reviewed-By: Aviv Keller <[email protected]>
Signed-off-by: Archkon <[email protected]>
PR-URL: #64688
Fixes: #64687
Reviewed-By: René <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
StringBytes::StorageSize had a CHECK that fatal-asserted when a
hex-encoded string with an odd number of characters was written
through Writev (e.g. via HTTP requests which are automatically
corked). Writing the same string via a single Write did not crash
because StringBytes::Write delegates to HexDecode, which silently
drops the trailing incomplete nibble.

Remove the CHECK and let integer division handle odd lengths, which
is consistent with StringBytes::Size and HexDecode.

Fixes: #45150
Signed-off-by: RajeshKumar11 <[email protected]>
PR-URL: #63658
Reviewed-By: Edy Silva <[email protected]>
Reviewed-By: Matteo Collina <[email protected]>
Reviewed-By: Gürgün Dayıoğlu <[email protected]>
nodejs-github-bot and others added 15 commits August 5, 2026 11:15
PR-URL: #64940
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
PR-URL: #64941
Reviewed-By: Antoine du Hamel <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
PR-URL: #64942
Reviewed-By: Moshe Atlow <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
PR-URL: #64945
Reviewed-By: Daeyeon Jeong <[email protected]>
Reviewed-By: Moshe Atlow <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
`TestOptions` as provided to `node:test`'s `test`/`it` supports both
`name` and `fn` as options per its implementation.

I'd like to formalize this as part of the public, documented API.

### Motivation

I have a use-case for consuming both fields.  I'd like to be able to
return the result of a function to `test`/`it` without needing to spread
 the parameters; e.g.:

```js
const testOptionsFactory = (opts = {}) => {
  return {
    fn: () => { /* .. */ },
    name: opts.name
  };
};

test(testOptionsFactory({name: 'foo'}));
```

If I cannot rely on this behavior, then I would need to instead return
an array of parameters and spread them:

```js
const testParamsFactory = (opts = {}) => {
  return opts.name !== undefined
    ? [opts.name, () => { /* .. */ }] : [() => { /* .. */ }];
};

test(...testParamsFactory({name: 'foo'}));
```

I don't think it's too terribly controversial that the former is more
ergonomic than the latter.

### Next Steps

Once this lands, I plan to propose the addition of these fields to
`@types/node`. Since the fields are not currently publicly documented, I
can't justify such a change.

Signed-off-by: Christopher Hiller <[email protected]>
PR-URL: #64946
Reviewed-By: Rich Trott <[email protected]>
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Ruy Adorno <[email protected]>
Reviewed-By: Colin Ihrig <[email protected]>
Reviewed-By: Chemi Atlow <[email protected]>
Pass the stream-wide signal reason directly to writer.fail() so valid
non-Error abort reasons are not replaced with an AbortError.

Signed-off-by: Kamat, Trivikram <[email protected]>
Assisted-by: codex:gpt-5.6-sol
PR-URL: #64798
Fixes: #64797
Reviewed-By: Aviv Keller <[email protected]>
Signed-off-by: Tim Perry <[email protected]>
PR-URL: #64710
Reviewed-By: James M Snell <[email protected]>
Only emit 'finish' and set writableFinished once all data has actually
been flushed successfully. end() callbacks now report the outcome like
stream.Writable: called with null on finish, or with the error that
prevented the flush.

Signed-off-by: Tim Perry <[email protected]>
PR-URL: #64847
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Matteo Collina <[email protected]>
Signed-off-by: Rawal27 <[email protected]>
PR-URL: #64952
Reviewed-By: Mike McCready <[email protected]>
Reviewed-By: Richard Lau <[email protected]>
Reviewed-By: Rich Trott <[email protected]>
PR-URL: #64943
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Antoine du Hamel <[email protected]>
PR-URL: #64944
Reviewed-By: Tim Perry <[email protected]>
Reviewed-By: Antoine du Hamel <[email protected]>
PR-URL: #64883
Reviewed-By: Jordan Harband <[email protected]>
Reviewed-By: Aviv Keller <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Mike McCready <[email protected]>
Reviewed-By: Trivikram Kamat <[email protected]>
readableStreamPipeTo allocated, for every chunk written to the
destination, a { promise, resolve, reject } write request record that
it immediately marked as handled, and drove its loop with an async
step()/run() pair whose implicit promises cost one allocation and one
reaction per iteration. The parked-read path additionally allocated a
read request object, a PromiseWithResolvers record, and a microtask
closure per chunk; this is the steady state for pipeThrough, since a
TransformStream's readable side has a high water mark of zero.

Replace the per-write records with a single per-pipe tracker that the
write request queue holds once per pending write and whose
resolve()/reject() methods maintain a pending-write count, drive the
pump loop with plain callbacks instead of async functions, and reuse
one read request and one forwarding function across all chunks, the
same pattern tee uses since c543cfb.

Benchmark results (benchmark/compare.js --runs 20):
webstreams/pipe-to.js +29.9% to +35.8% across all 16 configurations
(all 99.9% confidence); a pipeThrough(TransformStream) passthrough
loop improves ~17%; every other webstreams benchmark is unchanged.

Signed-off-by: Matteo Collina <[email protected]>
PR-URL: #64890
Reviewed-By: James M Snell <[email protected]>
Reviewed-By: Yagiz Nizipli <[email protected]>
Signed-off-by: Rawal27 <[email protected]>
PR-URL: #64957
Reviewed-By: Mike McCready <[email protected]>
Reviewed-By: Tierney Cyren <[email protected]>
Reviewed-By: Rich Trott <[email protected]>
Notable changes:

crypto:
  * (SEMVER-MINOR) support loading private keys through STORE loaders (Filip Skokan) #63949
  * update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746
lib:
  * (SEMVER-MINOR) add perfetto support (Chengzhong Wu) #64565
module:
  * (SEMVER-MINOR) implement `Symbol.dispose` in ModuleHooks (Remco Haszing) #63928
test_runner:
  * (SEMVER-MINOR) add support for `--test-coverage-include-all` (avivkeller) #64830

PR-URL: #65027
@aduh95
aduh95 force-pushed the v26.7.0-proposal branch from 6ed9d89 to b4f23d3 Compare August 5, 2026 09:18
@nodejs-github-bot

nodejs-github-bot commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author
Platform Number of requisites Proportion of new derivations
x86_64-linux 451 -> 455 => +4 4 / 455 = 0.8%
aarch64-linux 452 -> 456 => +4 4 / 456 = 0.8%
x86_64-darwin 388 -> 394 => +6 6 / 394 = 1.5%
aarch64-darwin 390 -> 396 => +6 6 / 396 = 1.5%
Total 1681 -> 1701 => +20 20 / 1701 = 1.1%
Changelog
@@ -680,0 +681 @@
+/nix/store/w83dnbrd7w2cvp8pvz5agf228dpkifxg-libtasn1-4.21.0 (aarch64-darwin)
@@ -681,0 +683 @@
+/nix/store/mwk2dssjyq3491nxpwizxnjf41cyjx4q-libtasn1-4.21.0 (x86_64-darwin)
@@ -1006,0 +1009,4 @@
+/nix/store/407rcl1ig0bk39cnk4hfflz2d7mr99dd-node-pkcs11-softhsm (aarch64-darwin)
+/nix/store/4d4lx7dllq1hss55la64lv4bfxlnc42x-node-pkcs11-softhsm (aarch64-linux)
+/nix/store/457f6kv5bgidlmsd0ggf41ggmqi89n6f-node-pkcs11-softhsm (x86_64-darwin)
+/nix/store/97jwl9hn3v9v7zpp033j3lcga7l31p38-node-pkcs11-softhsm (x86_64-linux)
@@ -1162,0 +1169,5 @@
+/nix/store/kcmiw9pa978fxafx91zwaz00cqlp1xsx-openssl-pkcs11.cnf (aarch64-darwin)
+/nix/store/dgjvcxm092jg9vsgfgf6m2i4mv9jln3c-openssl-pkcs11.cnf (aarch64-linux)
+/nix/store/8d925514nm15fw85li0zz0p7xrvj2gdp-openssl-pkcs11.cnf (x86_64-darwin)
+/nix/store/smzplbiai84y5fwgm55s00wh13p24f53-openssl-pkcs11.cnf (x86_64-linux)
+/nix/store/s2ljy8yv2qq563cybsmh5im8bjj0k8w6-p11-kit-0.26.2 (aarch64-darwin)
@@ -1163,0 +1175 @@
+/nix/store/sf6izqsd0wmgp81f1v8rqlfjd9dgz9lg-p11-kit-0.26.2 (x86_64-darwin)
@@ -1342,0 +1355,4 @@
+/nix/store/jhz3vfw8xz0rsmmzrq9i9w7fnvqhk1va-pkcs11-provider-1.2.0 (aarch64-darwin)
+/nix/store/9gwms4rd38922mz4rmn6ifc881381rdc-pkcs11-provider-1.2.0 (aarch64-linux)
+/nix/store/d28w0csy6w0x63bb0xd25rdy1qm0gf72-pkcs11-provider-1.2.0 (x86_64-darwin)
+/nix/store/aqvj16b1lbc8n35shw1yrcna97g2wk7n-pkcs11-provider-1.2.0 (x86_64-linux)
@@ -1516,0 +1533,4 @@
+/nix/store/v1yij4ymgqg86z3n5za11hwsgwamsqmh-softhsm-2.7.0 (aarch64-darwin)
+/nix/store/y9si5nxih0hiv339ab8aj2l04yqhxyzs-softhsm-2.7.0 (aarch64-linux)
+/nix/store/z0gbwg8b52nh3cb2bhfpckrw8d1pq5n6-softhsm-2.7.0 (x86_64-darwin)
+/nix/store/k0qxy12sj3vqissm8xqfgg82zi1rgi78-softhsm-2.7.0 (x86_64-linux)

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@avivkeller

Copy link
Copy Markdown
Member

Not that it really matters to me, just thought it was interesting that some commits in the PR description use full name (Aviv Keller, for instance), and others use username (avivkeller, for instance)

@aduh95

aduh95 commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Not that it really matters to me, just thought it was interesting that some commits in the PR description use full name (Aviv Keller, for instance), and others use username (avivkeller, for instance)

That would indicate that the MAILMAP is incomplete, as it's the thing suppose to tie together the different "identities" one person is using (without a MAILMAP entry, the tool uses the author commit info: in https://github.com/nodejs/node/commit/e700a2e72c.patch, you see From: avivkeller <[email protected]>, and in https://github.com/nodejs/node/commit/796acc8920.patch From: Aviv Keller <[email protected]>)

aduh95 added a commit that referenced this pull request Aug 5, 2026
Notable changes:

crypto:
  * (SEMVER-MINOR) support loading private keys through STORE loaders (Filip Skokan) #63949
  * update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746
lib:
  * (SEMVER-MINOR) add perfetto support (Chengzhong Wu) #64565
module:
  * (SEMVER-MINOR) implement `Symbol.dispose` in ModuleHooks (Remco Haszing) #63928
test_runner:
  * (SEMVER-MINOR) add support for `--test-coverage-include-all` (avivkeller) #64830

PR-URL: #65027
@aduh95
aduh95 merged commit b4f23d3 into v26.x Aug 5, 2026
69 of 72 checks passed
@aduh95
aduh95 deleted the v26.7.0-proposal branch August 5, 2026 16:22
R31K4G3 pushed a commit to R31K4G3/node that referenced this pull request Aug 10, 2026
@Crissmael

This comment was marked as spam.

2 similar comments
@Crissmael

This comment was marked as spam.

@Crissmael

This comment was marked as spam.

@Crissmael

This comment was marked as spam.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release Issues and PRs related to Node.js releases. v26.x Issues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.