Skip to content

2026-10-14, Version 24.22.0 'Krypton' (LTS) - #66667

Draft
github-actions[bot] wants to merge 340 commits into
v24.xfrom
v24.22.0-proposal
Draft

github-actions[bot] wants to merge 340 commits into
v24.xfrom
v24.22.0-proposal

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

2026-10-14, Version 24.22.0 'Krypton' (LTS), @aduh95

Notable Changes

  • [ddbf974b47] - (SEMVER-MINOR) crypto: add crypto.parsePKCS12() (Brian Muenzenmeyer) #65627
  • [c162c68ff0] - (SEMVER-MINOR) crypto: add a generic MAC API (Filip Skokan) #65553
  • [a4ab3d84d7] - (SEMVER-MINOR) crypto: discover ciphers from OpenSSL providers (Filip Skokan) #65484
  • [c2f1e829ea] - (SEMVER-MINOR) crypto: discover hashes from OpenSSL providers (Filip Skokan) #65484
  • [51aad5a80d] - (SEMVER-MINOR) crypto: enable SIV and GCM-SIV modes in Cipher/Decipher APIs (Filip Skokan) #63411
  • [d11c65d2f2] - doc: add araujogui to collaborators (Guilherme Araújo) #66090
  • [acc1578179] - doc: deprecate Server.prototype._listen2 in node:net (Antoine du Hamel) #65593
  • [a7f8de6362] - (SEMVER-MINOR) net: support sending net.BoundSocket to threads and child processes (Guy Bedford) #64725
  • [60c3eb61bd] - (SEMVER-MINOR) perf_hooks: implement SlidingWindowHistogram (James M Snell) #65825
  • [6b3e6f9d5c] - (SEMVER-MINOR) perf_hooks: implement qrde analysis support in Histogram (James M Snell) #65806
  • [75456a3512] - (SEMVER-MINOR) perf_hooks: implement Histogram meanCI API (James M Snell) #65606
  • [72d1b40c56] - (SEMVER-MINOR) perf_hooks: add CBOR export/import for histogram exchange (James M Snell) #65434
  • [41161dda87] - (SEMVER-MINOR) sqlite: add StatementSync.prototype.close() (Guilherme Araújo) #64232
  • [adbc757d70] - (SEMVER-MINOR) sqlite: add StatementSync.prototype[Symbol.dispose]() (Guilherme Araújo) #64232
  • [241339f072] - (SEMVER-MINOR) src,lib: add util.markPromiseAsHandled (James M Snell) #65805
  • [b4a6719f37] - (SEMVER-MINOR) test: expand histogram test coverage (James M Snell) #65825
  • [63b0974d9e] - (SEMVER-MINOR) util: implement util.throttle (James M Snell) #65899
  • [a3bbb5a26f] - (SEMVER-MINOR) util: implement debounce (James M Snell) #65899

Commits

  • [e6832b2cb1] - assert: fix TypeError on deepStrictEqual with null Map key or Set member (Sergey Sannikov) #64449
  • [a079177d9f] - benchmark: add --csv option to compare.js with --analyze (James M Snell) #65922
  • [10b1a0f70f] - benchmark: fix max-regressions detection in compare.js (James M Snell) #65587
  • [e0c7ba8ad5] - benchmark: add --analyze option to benchmark/scatter.js (James M Snell) #65594
  • [21fed10bb0] - benchmark: add crypto class benchmarks (Filip Skokan) #65518
  • [fa912242b7] - buffer: fix unaligned UTF-16LE decoding (Matteo Collina) #65905
  • [a6bd0c1413] - build: suppress OpenSSL asm warnings with clang (Richard Lau) #66023
  • [94e12139ee] - build: derive V8_LOGGING_LEVEL from dcheck_always_on (Joyee Cheung) #65744
  • [7a2f322943] - build: fix quiet default for make builds (Shelley Vohr) #65826
  • [c280d650b0] - build: allow linking shared dependencies in the GN build (Shelley Vohr) #65797
  • [4b23a4472c] - build: enable the V8 sandbox in shared-cage builds (Shelley Vohr) #62237
  • [676e15c003] - build: define V8_CONTIGUOUS_COMPRESSED_RO_SPACE for shared cage (Shelley Vohr) #65464
  • [f784058482] - build: remove obsolete configure flags (Chengzhong Wu) #65456
  • [f63f37d243] - build: activate correct default flags for riscv64 (Stewart X Addison) #65708
  • [da46ac075d] - build: derive NODE_ARCH from target_cpu in the GN build (Shelley Vohr) #65491
  • [249e9a16dd] - build,src: gate jspi flag on V8_ENABLE_WEBASSEMBLY (Piotr Kubaj) #66082
  • [146f00f64b] - child_process: clear timeout timer on spawn-time error too (kishore280) #65506
  • [13987f4418] - crypto: remove redundent std::move call (Antoine du Hamel) #66111
  • [ef957ac85f] - crypto: skip private RSA parameters in key details (Filip Skokan) #66108
  • [8feccc5e22] - crypto: use provider EC group names (Filip Skokan) #66108
  • [764e0d1120] - crypto: fetch ciphers for private-key encoding (Filip Skokan) #66108
  • [50ffed1979] - crypto: decode PKCS#1 keys through providers (Filip Skokan) #66108
  • [56c16b2fd6] - crypto: derive keys through EVP_KDF (Filip Skokan) #66108
  • [a4effe6809] - crypto: use names for asymmetric key algorithms (Filip Skokan) #65966
  • [ddbf974b47] - (SEMVER-MINOR) crypto: add crypto.parsePKCS12() (Brian Muenzenmeyer) #65627
  • [8e631aa48f] - crypto: add Hybrid KEMs to Web Cryptography (Filip Skokan) #65759
  • [5c51129e16] - crypto: optimize private EC JWK import (Filip Skokan) #65908
  • [c2ec40c2d7] - crypto: disable non-FIPS WebCrypto paths in FIPS mode (Filip Skokan) #65172
  • [e198aa0f79] - crypto: read RSA-PSS restrictions from provider (Filip Skokan) #66108
  • [253784f0e9] - crypto: optimize and benchmark key preparation (Filip Skokan) #65892
  • [80a6ad509b] - crypto: avoid EC reconstruction for signature sizing (Filip Skokan) #65908
  • [5b592b772c] - crypto: avoid EC raw export reconstruction (Filip Skokan) #65908
  • [ee956ae3bf] - crypto: export EC JWK coordinates directly (Filip Skokan) #65908
  • [684008be58] - crypto: read EC curve metadata directly (Filip Skokan) #65908
  • [f4665f1c41] - crypto: validate the limit of PBKDF2 iterations (Filip Skokan) #65704
  • [624abbecd7] - crypto: use primordials in HKDF info validation (Filip Skokan) #65704
  • [e4d916f175] - crypto: add mgf1Hash for RSA-OAEP (Adam Mcgrath) #65073
  • [db8a9162a8] - crypto: fix multi-prime RSA JWKs (Filip Skokan) #65649
  • [022ac83504] - crypto: cache valid ECDH key pairs (Filip Skokan) #65615
  • [c61953ebcc] - crypto: add strict mode to --force-fips (Filip Skokan) #65645
  • [db6ea132a5] - crypto: add FIPS indicator diagnostics channel (Filip Skokan) #65645
  • [c162c68ff0] - (SEMVER-MINOR) crypto: add a generic MAC API (Filip Skokan) #65553
  • [2b62aafd20] - crypto: validate JWK usages before key_ops (Filip Skokan) #65550
  • [ec7819db69] - crypto: fix RSA-PSS oversized salt handling (Filip Skokan) #65550
  • [a4ab3d84d7] - (SEMVER-MINOR) crypto: discover ciphers from OpenSSL providers (Filip Skokan) #65484
  • [c2f1e829ea] - (SEMVER-MINOR) crypto: discover hashes from OpenSSL providers (Filip Skokan) #65484
  • [51aad5a80d] - (SEMVER-MINOR) crypto: enable SIV and GCM-SIV modes in Cipher/Decipher APIs (Filip Skokan) #63411
  • [5a46a9acbb] - crypto: improve SubtleCrypto.supports() accuracy (Filip Skokan) #65222
  • [191ebfb26c] - crypto: fix public PKCS8 export error (한국) #65609
  • [b6d7ed372b] - crypto: fix private SPKI export error (Filip Skokan) #65550
  • [79509c25a4] - crypto: correct CCM decryption FIPS error message (kyungrae) #65450
  • [9adc87bc16] - crypto: harden X509Certificate state (Filip Skokan) #65518
  • [c63aa331b4] - crypto: optimize key slot caching (Filip Skokan) #65518
  • [87daea43a7] - crypto: add null checks for OPENSSL_INIT_new() (Nora Dossche) #63457
  • [98ca5e9358] - crypto: prevent Hmac.digest() from returning uninitialized memory (Matteo Collina) #65112
  • [0c090a28cd] - crypto: avoid throwing CryptoKey brand checks (Filip Skokan) #65503
  • [a13cc3f723] - crypto: avoid throwing KeyObject brand checks (Filip Skokan) #65503
  • [b8db0045ef] - deps: V8: cherry-pick ea9c016f26ad (Gundepalli Sravani) #66570
  • [ba09b53487] - deps: V8: backport c3553509f460 (Jakob Linke) #66089
  • [9ce8ef405b] - deps: V8: backport 8901c793e439 (Toon Verwaest) #66089
  • [fb0d0ca289] - deps: V8: backport 0b94a9fd23ba (Ruan Gustavo) #65753
  • [2faca508c0] - deps: update googletest to 8eff9e336692fc95961e096564f1044c600b881d (Node.js GitHub Bot) #66009
  • [4396c9bffe] - deps: update googletest to 283c17563fe7a1111cd7f581aa5d541e8baeff2f (Node.js GitHub Bot) #65833
  • [8a5b12570c] - deps: update simdjson to 4.6.11 (Node.js GitHub Bot) #65834
  • [c47feb09e8] - deps: update zlib to 1.3.2.1-motley-285e94b (Node.js GitHub Bot) #65835
  • [9f0d905286] - deps: upgrade npm to 11.19.1 (npm team) #65573
  • [373cd332d8] - deps: update googletest to 36ba75f0ad5383a9759f17f3f72fd4661c72cb6d (Node.js GitHub Bot) #65654
  • [aeed6132a7] - deps: update simdjson to 4.6.9 (Node.js GitHub Bot) #65655
  • [2583571342] - deps: update zlib to 1.3.2.1-motley-5eb4d7e (Node.js GitHub Bot) #65494
  • [d11c65d2f2] - doc: add araujogui to collaborators (Guilherme Araújo) #66090
  • [0a4a8d602a] - doc: fix duplicate 'the' typo in node_platform.cc (Muhammad Al-Muzahid) #66058
  • [b6538138ef] - doc: clarify sub-1000ms behavior in socket.setKeepAlive (Haram Jeong) #65869
  • [d319fa7de4] - doc: remove obsolete mentioning of cl.exe on windows (Chengzhong Wu) #66038
  • [67cb305b59] - doc: note that default signal handling resets the signal mask (Shelley Vohr) #65877
  • [160d44e025] - doc: clarify QUIC async write backpressure (John Finnerty) #65947
  • [ffd47a7ee5] - doc: clarify permission model scope for output paths (Rafael Gonzaga) #66004
  • [2e1772a8ab] - doc: fill in missing zstd docs (James M Snell) #65867
  • [9f88c6f8dc] - doc: add inoway46 as triager (Yuya Inoue) #65565
  • [c2620d01f3] - doc: document windowsHide for child_process.fork (Christopher Buss) #65887
  • [6076111e1a] - doc: qualify directory read ordering for native fs (Trivikram Kamat) #65868
  • [7bf048a336] - doc: add DOMException section to errors API reference (Avocado) #65206
  • [414b6bfa62] - doc: expand revert commit collaborator instructions (Mike McCready) #65848
  • [c8ac91692c] - doc: note that FreeEnvironment() runs a shared event loop (Shelley Vohr) #65691
  • [cc47cc0983] - doc: clarify security triage dispositions and permission boundaries (Rafael Gonzaga) #65436
  • [8b79a71e78] - doc: fix default limit of maxHeadersCount (Aryn H) #65472
  • [56b1252a54] - doc: fix return types for sync methods (Chiang Fong Lee) #58575
  • [da0d32a333] - doc: document REPL DEP0185 throws and uncaught-exception behavior (Adrián Estrada) #64993
  • [f8ab3619b6] - doc: document close() error when in a sqlite callback (Trivikram Kamat) #65090
  • [131f1db302] - doc: clarify return type of fs.mkdtemp* (Antoine du Hamel) #65743
  • [7755e98183] - doc: update changelog-maker instructions for releasing (Juan José) #65707
  • [f982a53433] - doc: add stability status to crypto.setEngine (Antoine du Hamel) #65746
  • [17be003f7c] - doc: remove outdated TLS authorized warning (Tim Perry) #65597
  • [424002232d] - doc: fix stale TOC in maintaining-dependencies (greenhead) #65523
  • [dddb9b57a5] - doc: refactor the AI guidelines (Joyee Cheung) #65269
  • [397b58e113] - doc: fix triggerAsyncId() comment in async_hooks example (soreavis) #64583
  • [338ec94d83] - doc: fix fsPromises.watch overflow value (Matt Radbourne) #64605
  • [f18be21b14] - doc: clarify stream direction in options.stdio note (Avocado) #65236
  • [f07c6acd8b] - doc: clarify signal listener behavior (Som Samantray) #65243
  • [8bc17b0c7a] - doc: add test reporter event lifecycle diagram (sangwook) #63780
  • [452e7477d4] - doc: discourage AbortSignal cleanup for long-lived resources (Efe Karasakal) #64342
  • [acc1578179] - doc: deprecate Server.prototype._listen2 in node:net (Antoine du Hamel) #65593
  • [e7ed4361d6] - doc,test: account for OpenSSL 4.1 behaviours (Filip Skokan) #65956
  • [c65fafeab4] - errors: validate constructor name (Christian Aurich) #65607
  • [f6b47938b7] - events: fix weak listener retention overwrite (Aryan) #64024
  • [a27db42c3e] - fs: coerce FileHandle.read length like fs.read (Xia Chao) #65521
  • [f3019b522a] - fs: throw on existing dir in cpSync with errorOnExist (Daijiro Wachi) #64124
  • [cd1011458f] - fs: support removing read-only files in rmSync on Windows (Sparsh :)) #64453
  • [d659dd8cd8] - fs: give directories created by cpSync the source directory's mode (Shelley Vohr) #65488
  • [1dfb047293] - fs: handle recursive watch setup races (Filip Skokan) #65699
  • [bc431c8413] - fs: apply nocase to literal glob exclude patterns (Yusuke Hayashi) #64817
  • [dd5662e641] - fs: do not descend into symlinks for ** unless following symlinks (RafaelGSS) #65435
  • [ac4cf54292] - fs: watch directories, not files, in recursive fs.watch fallback (Shelley Vohr) #65486
  • [7804bfbd71] - fs: preserve directory timestamps in cp (Abhinandan Kumar) #65540
  • [ba5ca5a1a5] - fs: fix recursive watch error handling (Filip Skokan) #65635
  • [b71c4c0551] - fs: fix rmSync error messages for non-ASCII paths (Yeaseen) #61233
  • [53b4700892] - http: don't destroy socket after request completes (Barath Raj) #65952
  • [96d4c23f17] - http: fast-forward teardown of unread messages (Matteo Collina) #65732
  • [742b4bf5a6] - http: coalesce chunked writes during auto-corking (GetThatCookie) #64987
  • [8921108175] - http2: settle pending write callbacks on destroy (Matteo Collina) #66016
  • [9a2f77a3fc] - http2: fix onread assert when destroying session from stream handler (Sankalp Thakur) #65116
  • [99e41eb43a] - http2: error for incomplete reads on RST, auto-drain, deprecate aborted (Tim Perry) #63249
  • [d520b9601c] - http2: fix write deadlock exposed by larger window sizes (Tim Perry) #65440
  • [86b2497aae] - http2: fix async context loss when trailers carry END_STREAM (Orgad Shaneh) #63814
  • [536ccc7daf] - https: limit proxy CONNECT response headers (Matteo Collina) #64545
  • [fe6147832b] - inspector: fix abort when two Environments own the inspector (Shelley Vohr) #65877
  • [843a27782a] - inspector: fix crash when the IsolateData has no platform (Shelley Vohr) #65818
  • [3f0b6d3308] - lib: avoid repeat internal receiver checks (Filip Skokan) #65910
  • [0039479b4a] - lib: fix shared buffer growability validation (Filip Skokan) #65845
  • [e7907130ae] - lib: use Web IDL interface brand checks (Filip Skokan) #65846
  • [7ae085552b] - lib: fix AbortSignal.any() abort propagation (Yuya Inoue) #66014
  • [01032f4fdc] - lib: fix for FileHandle.readableWebStream (Patrick Dähne) #58842
  • [60a9a28206] - lib: avoid unsafe array iteration in cli table (Donghoon Kang) #65838
  • [230a7fcef0] - lib: optimize internal Web IDL dictionaries (Filip Skokan) #65857
  • [7cc02b14ec] - lib: validate sequence iterator objects (Filip Skokan) #65844
  • [c2bb3aeccc] - lib: defer source map payload decoding until first use (Shelley Vohr) #65490
  • [c4b390cf17] - lib: optimize async context frame activation (Tim Perry) #65519
  • [3e4fc50a4f] - lib: use validateArray for array arguments (JunHwan Choi) #65344
  • [b351ac9cd4] - meta: bump step-security/harden-runner from 2.21.0 to 2.21.1 (dependabot[bot]) #66044
  • [693e890fec] - meta: bump github/codeql-action/upload-sarif from 4.37.9 to 4.38.0 (dependabot[bot]) #66046
  • [9c2abc13c2] - meta: bump github/codeql-action/init from 4.37.9 to 4.38.0 (dependabot[bot]) #66048
  • [b3c5c2b91d] - meta: bump github/codeql-action/analyze from 4.37.9 to 4.38.0 (dependabot[bot]) #66049
  • [2428b13b02] - meta: bump github/codeql-action/autobuild from 4.37.9 to 4.38.0 (dependabot[bot]) #66050
  • [eff5d15041] - meta: add joyeecheung as v8 currency strategic initiative champion (Joyee Cheung) #65965
  • [aa549fed0d] - meta: expand on collaborator restoration process (Chengzhong Wu) #65962
  • [593b40eb2b] - meta: add web-standards as webidl owners (Filip Skokan) #65856
  • [e711d3fef3] - meta: bump actions/checkout from 7.0.0 to 7.0.1 (dependabot[bot]) #65718
  • [0fc8a38f5b] - meta: cleanup targos emeritus changes (Antoine du Hamel) #65738
  • [2ca2fd566d] - meta: bump github/codeql-action/init from 4.37.3 to 4.37.9 (dependabot[bot]) #65714
  • [325709818e] - meta: bump github/codeql-action/autobuild from 4.37.3 to 4.37.9 (dependabot[bot]) #65717
  • [8481d22f72] - meta: bump actions/setup-node from 6.4.0 to 7.0.0 (dependabot[bot]) #65720
  • [cd2bd5d9fd] - meta: bump step-security/harden-runner from 2.20.0 to 2.21.0 (dependabot[bot]) #65721
  • [fdec747105] - meta: bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.9 (dependabot[bot]) #65722
  • [34c2fca088] - meta: bump github/codeql-action/analyze from 4.37.3 to 4.37.9 (dependabot[bot]) #65723
  • [46d4549938] - meta: document collaborator automation (Filip Skokan) #65671
  • [a7f8de6362] - (SEMVER-MINOR) net: support sending net.BoundSocket to threads and child processes (Guy Bedford) #64725
  • [466f1f8e62] - net: fix BlockList.fromJSON for IPv4-mapped IPv6 rules (Daijiro Wachi) #64125
  • [cd04cb10d6] - net: recognize bare IPv6 loopback addresses in isLoopback (Daijiro Wachi) #63619
  • [d983942636] - node-api: make object property arrays const (Yilong Li) #65621
  • [cc124394cc] - path: remove StringPrototypeCharCodeAt from some methods of posix (Wiyeong Seo) #54668
  • [60c3eb61bd] - (SEMVER-MINOR) perf_hooks: implement SlidingWindowHistogram (James M Snell) #65825
  • [6b3e6f9d5c] - (SEMVER-MINOR) perf_hooks: implement qrde analysis support in Histogram (James M Snell) #65806
  • [8aa870940c] - perf_hooks: reuse buffer for uv metrics (Donghoon Kang) #65985
  • [9cfbfae660] - perf_hooks: validate import normalization offset (Matteo Collina) #65950
  • [75456a3512] - (SEMVER-MINOR) perf_hooks: implement Histogram meanCI API (James M Snell) #65606
  • [127cb31864] - perf_hooks: add missing resource timing attributes (greenhead) #65017
  • [72d1b40c56] - (SEMVER-MINOR) perf_hooks: add CBOR export/import for histogram exchange (James M Snell) #65434
  • [847fe4d049] - permission: block FileHandle fsync and fdatasync (Rafael Gonzaga) #65431
  • [fa9188bd63] - quic: fix two small bugs in HTTP/3 stream internals (Tim Perry) #65970
  • [ee80beaa9f] - quic: fix crash in onStreamClose (Marten Richter) #65861
  • [98486dd764] - quic: reject zero addressLRUSize (Christian Aurich) #65827
  • [97516fc256] - quic: stop guarding ngtcp2_recv_stop_sending callback field (René) #65688
  • [024bef25eb] - quic: remove unused fin flag from blob reader wakeup (trivenay) #65315
  • [5468337456] - quic: release stream arenas before cleanup (Trivikram Kamat) #65410
  • [a794e36970] - sqlite: throw on invalid URL path instead of abort (Guilherme Araújo) #66026
  • [f58a55b8d0] - sqlite: add diagnostic channel (Guilherme Araújo) #62241
  • [be849bc6af] - sqlite: reject connection access from authorizer callbacks (Trevor Burnham) #65156
  • [41161dda87] - (SEMVER-MINOR) sqlite: add StatementSync.prototype.close() (Guilherme Araújo) #64232
  • [adbc757d70] - (SEMVER-MINOR) sqlite: add StatementSync.prototype[Symbol.dispose]() (Guilherme Araújo) #64232
  • [b7b18fdbc9] - sqlite: run backup completion in callback scope (Filip Skokan) #65666
  • [59827acd7f] - sqlite: isolate applyChangeset filter errors (Trivikram Kamat) #64823
  • [5a01df2d15] - sqlite: reject deserialize() while in a callback (Trivikram Kamat) #64796
  • [c9b6e75a2e] - sqlite: refactor error helpers and user function pointers (Ali Hassan) #62794
  • [d4eb6c62a9] - sqlite: prevent database close during callbacks (Matteo Collina) #64743
  • [83b3431c25] - src: detach cppgc wrappers from their Realm before it is freed (Shelley Vohr) #65778
  • [13ed7e35e7] - src: list scripts when --run has no command (James Ross) #64606
  • [0f62f2b2df] - src: print exception thrown during primordial initialization (Joyee Cheung) #65991
  • [70117640f7] - src: don't kill own process group on failed spawn (Lazizbek Ergashev) #65054
  • [64649abfd4] - src: keep the first snapshot blob alive for later isolates (Shelley Vohr) #65779
  • [3c814e8c3c] - src: fix Stop() terminating the next Environment on the isolate (Shelley Vohr) #65819
  • [a3ababcebb] - src: fix null pointer call when running without a startup snapshot (Shelley Vohr) #65820
  • [7331f5cfcc] - src: stop leaking a CppHeap in CommonEnvironmentSetup (Shelley Vohr) #65792
  • [5570a84048] - src: fix use-after-free in CleanupHookThunkRun (Caleb Everett) #65630
  • [abe1b673e9] - src: keep global list of addon-provided cleanup hooks (Anna Henningsen) #63985
  • [2203ac9382] - src: fix startup snapshot reproducibility of InternalFieldInfo (Chengzhong Wu) #65684
  • [b282765d99] - src: fix live lock between environments with blocked requests (Ilyas Shabi) #65520
  • [61ca3ba93c] - src: apply IsolateSettings when using a snapshot (Shelley Vohr) #65407
  • [33b8d6e10f] - src: add re-entrancy guard to TriggerUncaughtException (Temuulen Undrakhbayar) #64327
  • [49232db71e] - src: reuse cached strings in CompileSerializeMain (agape1225) #65453
  • [e3f52b80a5] - src: report libuv error when openAsBlob cannot stat (Paul Bouchon) #65517
  • [42a5a19027] - src: shave about 20 bytes off each TLSWrap instance (James M Snell) #65144
  • [a06bb51e22] - src: use UTF-8 for task runner filesystem paths (Archkon) #64868
  • [241339f072] - (SEMVER-MINOR) src,lib: add util.markPromiseAsHandled (James M Snell) #65805
  • [1260642ace] - stream: destroy Duplex.from async function on early return (Aman Chadha(IVIXMMI)) #65963
  • [5f06defdbd] - stream: make share budget failures detach before throwing (James M Snell) #66028
  • [d1c60d898d] - stream: update broadcast to retain buffered data with zero consumers (James M Snell) #66028
  • [bbb00558c5] - stream: avoid promise allocation for parked transform writes (Matteo Collina) #65625
  • [3216bc3912] - stream: keep webstream stream states in fast-mode objects (Matteo Collina) #65625
  • [70c1415686] - stream: reject closed only after sink abort settles (Lazizbek Ergashev) #65727
  • [f8737b8ee5] - stream: fix ERR_INVALID_STATE when cancelling Readable.toWeb() (Richard Scarrott) #62773
  • [faa16f671c] - stream: amortize writable buffer compaction (Gürgün Dayıoğlu) #65847
  • [6262e0b8c6] - stream: create write request objects lazily (Matteo Collina) #64455
  • [0f0566de15] - stream: allocate stream read buffers from a slab (Matteo Collina) #64455
  • [02c776a7c6] - stream: ensure that stateful transforms preserve this (James M Snell) #65658
  • [4b29051971] - stream: fix nested async flushing with infinite sources (James M Snell) #65658
  • [2e54186d97] - stream: ensure from() observes returned rejecting promise correctly (James M Snell) #65658
  • [fd68d5ca6a] - stream: apply source normalization once at call time (James M Snell) #65658
  • [49ee85b462] - stream: make pipeTo source normalization independent of Writer (James M Snell) #65658
  • [d7d0440f08] - stream: pre-aborted pipeTo now applies dest failure handling (James M Snell) #65658
  • [6d8e643ef3] - stream: ensure async dispoal after endSync awaits for drain (James M Snell) #65658
  • [a082916c00] - stream: ensure factory signals remain active through closing (James M Snell) #65658
  • [38829295a7] - stream: skip unobserved 'readable' emission at EOF (Matteo Collina) #65749
  • [d535859c22] - stream: avoid per-chunk promises in webstream adapters (Matteo Collina) #65548
  • [80568f6818] - stream: address stream/iter review feedback (James M Snell) #65652
  • [6952928f68] - stream: replace object sentinel with symbol (James M Snell) #65652
  • [9c22c4124c] - stream: cancel active stream/iter pulls (James M Snell) #65652
  • [24d87990cf] - stream: fix merge settlement tagging and falsy error tracking (James M Snell) #65652
  • [1e215c4b51] - stream: ensure full-close semantics when closed (James M Snell) #65652
  • [f499d6fadf] - stream: fixup writer to terminate on consumer return/throw (James M Snell) #65652
  • [2130738033] - stream: ensure iterator cleanup on done, reject, etc (James M Snell) #65652
  • [748adc6275] - stream: fixup cancelation handling in pull() (James M Snell) #65652
  • [47b3f6a1fa] - stream: fix early drain after Utf8Stream reopen (Matteo Collina) #65633
  • [6dab5412cf] - test: skip RSA-PSS keygen deprecation tests with BoringSSL (Shelley Vohr) #65808
  • [95d9a25b61] - test: consolidate crypto provider cache coverage (Filip Skokan) #66108
  • [612db6d5b2] - test: deflake user timing WPT assertions (Filip Skokan) #66036
  • [61a73d31eb] - test: fix RSA/DSA wrong-passphrase flake (Filip Skokan) #65983
  • [d9f4a3ee3e] - test: reuse fixed primes in DH tests (Filip Skokan) #65980
  • [a0fd0a8bd6] - test: use named parameters in DH stress test (Filip Skokan) #65980
  • [810a6b00ee] - test: update tests to run with OpenSSL >= 3.0 FIPS mode (Filip Skokan) #64960
  • [dc6b9ba5b2] - test: deflake test-run-watch-cwd-isolation-none-* (Antoine du Hamel) #66035
  • [0f27bd2459] - test: unskip test-watch-create-isolation-none (Antoine du Hamel) #66041
  • [1019f624f3] - test: deflake util.throttle tests (Filip Skokan) #66034
  • [b4a6719f37] - (SEMVER-MINOR) test: expand histogram test coverage (James M Snell) #65825
  • [047d7c53d2] - test: implement low-risk test optimizations (James M Snell) #65926
  • [33775d2bbb] - test: prevent parser reuse across close scenarios (Filip Skokan) #66017
  • [b8c5283cbc] - test: fix stderr Buffer assertion in exec encoding test (greenhead) #66008
  • [13a2982002] - test: improve sequential test performance (James M Snell) #65928
  • [a578933da0] - test: overlap SLH-DSA signature checks (Filip Skokan) #65980
  • [bfdf20729d] - test: unref cancelled broadcast source timer (Filip Skokan) #65980
  • [b29154d471] - test: collect timeout signals explicitly (Filip Skokan) #65980
  • [384d4fe3ea] - test: skip retries in DNS timeout coverage (Filip Skokan) #65980
  • [c7323843f4] - test: synchronize ordered runner events (Filip Skokan) #65980
  • [625290573a] - test: avoid idle HTTP/HTTPS connections (Filip Skokan) #65980
  • [2bde68398f] - test: close WebAssembly test HTTP servers (Filip Skokan) #65980
  • [4c702e401b] - test: deflake node-api test-free-called (Christian Aurich) #65948
  • [0b6d945ebc] - test: skip C++ symbols in tick-processor-arguments (Philipp Dunkel) #65906
  • [e04210b383] - test: try fixing windows build replacing WMIC (James M Snell) #65949
  • [aed73444de] - test: fix flaky cleanup in http2 test (Tim Perry) #65701
  • [22f47ff728] - test: update WPT WebCrypto, WebIDL and interfaces (Filip Skokan) #65679
  • [f2af511a24] - test: zero-fill buffers before the string length limit check (Christian Aurich) #65755
  • [a28aad9960] - test: update WPT for url to c23755a144 (Node.js GitHub Bot) #65651
  • [ba65bb149a] - test: fix recursive fs.watch error fixture (Filip Skokan) #65683
  • [f3b9f132b1] - test: update streams WPT (Jeong SeokChan) #65638
  • [d2e0f2d3bd] - test: deflake fastutf8stream destroy and reopen tests (Christian Aurich) #65554
  • [7b5896c136] - test: cover Readable.from() sync iterator errors (jakecastelli) #65515
  • [66eafad642] - test: document WPT runner workflows (Filip Skokan) #65510
  • [2e2dc0f556] - test: simplify test-worker-heap-profile.js (Donghoon Kang) #65372
  • [2e57caac46] - test: prefer in-memory databases in sqlite tests (Paul Bouchon) #64701
  • [cef908596e] - test: fix typo from funciton to function (parkhojeong) #63403
  • [4c7bbd4182] - test: widen the gap in the resolver maxTimeout comparison (Shelley Vohr) #65780
  • [25c81c9eff] - test: fix the thread-spawn handshake in the WASI threads fixture (Shelley Vohr) #65780
  • [cab5dcedbe] - test: only count restarts after the write in watch emit-restarted test (Shelley Vohr) #65780
  • [db0ca93e94] - test: ignore tunnel resets in proxy invalid-char-in-url test (Shelley Vohr) #65780
  • [1f0087040a] - test: handle EPIPE in closed channel test (Christian Aurich) #65770
  • [ed4e5df638] - test: deflake test-runner-coverage (Christian Aurich) #65728
  • [48ecb16909] - test: set type=none on IBM i for empty source (Abdirahim Musse) #65545
  • [554a3fba98] - test: deflake WASI poll timing checks (Filip Skokan) #65672
  • [91b5389430] - test: skip fs-watch-recursive-delete-race on AIX (Antoine du Hamel) #65698
  • [4ed0c8cc6c] - test: deflake test-inspect-async-hook-setup-at-inspect (Christian Aurich) #65584
  • [500b98cc7d] - test: deflake test-watch-mode-restart-esm-loading-error (Christian Aurich) #65623
  • [099c20fcbd] - test: avoid orphaned child on Windows abort test (Kirill Saied) #65451
  • [fc9364fe55] - test: riscv64: skip node-api sea test (Stewart X Addison) #65569
  • [c9d6b5f731] - test: mark platform-specific tests as flaky (Filip Skokan) #65562
  • [cb93d40549] - test,benchmark: use OpenSSL feature helpers (Filip Skokan) #65762
  • [b4b859319d] - test_runner: avoid reusing v8 serializers (Yuya Inoue) #65951
  • [b3766225e1] - test_runner: fix quote escaping in JUnit (Jihwan) #65971
  • [ec37f934db] - tls: propagate singleUse to the secure context (Carlos Vinicius) #66025
  • [21aec3f286] - tls: defer re-entrant calls to SSL state machine from JS (Tim Perry) #65105
  • [ffd3de2831] - tls: read the peer certificate chain without consuming it (Tony Gies) #65602
  • [3481ea3c43] - tls: don't trigger SNICallback or OCSPRequest from the TLS lib stack (Tim Perry) #64827
  • [d75957f0c8] - tls: drop hand-rolled TLS client hello parser (Tim Perry) #64827
  • [c555ba0aeb] - tools: update tools/v8 for Python 3.13 (Richard Lau) #66109
  • [aafff27ebe] - tools: bump eslint-plugin-jsdoc in /tools/eslint in the eslint group (dependabot[bot]) #66102
  • [7a481ebd2c] - tools: group CodeQL GHA updates (Antoine du Hamel) #66057
  • [b2252b4074] - tools: summarize auto-start-ci failures (Filip Skokan) #65979
  • [499fe73da7] - tools: bump the eslint group in /tools/eslint with 6 updates (dependabot[bot]) #66045
  • [d004d957ae] - tools: update pgo build doc for linux (Chengzhong Wu) #66024
  • [bfa329dbba] - tools: correct Slack action version comments (Filip Skokan) #66013
  • [d55d30313b] - tools: make checkout credential use explicit (Filip Skokan) #66013
  • [0a9e844866] - tools: pass author to commit message validator (Filip Skokan) #66012
  • [f5edf1cd7c] - tools: reduce test runner timing overhead (Filip Skokan) #65980
  • [1cb899f727] - tools: bump js-yaml from 4.3.1 to 4.3.2 in /tools/eslint (dependabot[bot]) #65931
  • [9a1d47bc53] - tools: bump js-yaml from 4.3.1 to 4.3.2 in /tools/lint-md (dependabot[bot]) #65932
  • [a1649b36bc] - tools: fix commit queue error summary matching (Filip Skokan) #65913
  • [ff25d0a268] - tools: lint PR commit messages without approval (Filip Skokan) #65875
  • [ab3c2a81f4] - tools: unlabel author ready on base branch conflicts (Filip Skokan) #65872
  • [c97d09cb4a] - tools: apply feedback to and simplify contributor guidance workflow (Filip Skokan) #65785
  • [5410d94903] - tools: remove true from branch name for auto-update automation (Antoine du Hamel) #64961
  • [7a45a46798] - tools: bump @humanfs/node from 0.16.7 to 0.16.8 in /tools/eslint (dependabot[bot]) #65757
  • [5df6d29a24] - tools: bump browserslist from 4.28.4 to 4.28.8 in /tools/eslint (dependabot[bot]) #65758
  • [8a9f89bdaa] - tools: refine contributor guidance workflow (Filip Skokan) #65745
  • [ed3e9a2583] - tools: bump the eslint group in /tools/eslint with 4 updates (dependabot[bot]) #65716
  • [8d4f0cf264] - tools: do not flag force push as invalid message (Antoine du Hamel) #65700
  • [350b3e69bb] - tools: retry first-time contributor query (Filip Skokan) #65648
  • [fbbfcc499f] - tools: query first-time contributor status (Filip Skokan) #65592
  • [b5885fc823] - tools: offset GitHub crons by 3 minutes (Michaël Zasso) #65612
  • [0cdd3171c0] - tools: label PRs lacking second approval (Filip Skokan) #65538
  • [5240f00c2e] - tools: welcome first-time contributors (Filip Skokan) #65533
    …

panva and others added 30 commits September 19, 2026 12:07
Cache constructor-known KeyObject types in the existing private slot
until a native handle is needed. Prime normal CryptoKey slot arrays
from constructor arguments while retaining the native fallback for
transferred keys.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
PR-URL: #65518
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Construct X509Certificate instances directly on the existing native
X.509 wrapper and keep lazy cached values in private state. Use a
non-throwing native brand check while preserving the existing
structured-clone behavior.

Preserve derived-constructor prototype semantics without rereading
new.target.prototype.

Add coverage for receiver validation, hidden state, prototype edge
cases, subclassing, and structured cloning through workers and message
ports.

Replace the key-only instanceof lint rule with a module-aware crypto
class guard and extend it to X509Certificate. Resolve references by
lexical binding so shadowed constructor names remain valid.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
PR-URL: #65518
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
fs.rmSync previously embedded paths directly into
custom error messages while also passing the path
to ThrowErrnoException.

This caused duplicated paths for ASCII names and
corrupted paths for non-ASCII directory names on
Linux, and inconsistent path formatting on Windows.

Remove path concatenation from custom messages and
rely on ThrowErrnoException to attach the path safely.
Add a test to cover non-ASCII directory names.

Signed-off-by: Yeaseen <yeaseen.arafat96@gmail.com>
PR-URL: #61233
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com>
Release QUIC stream stats and state arena slots when the stream is
destroyed instead of from the Stream destructor.
Realm cleanup destroys QUIC binding data before draining remaining
BaseObjects, so a stream that survives until process teardown must
not need BindingData from its destructor.

HTTP/3 header callbacks can synchronously destroy their stream. Check
whether the stream was destroyed after those callbacks before accessing
its arena-backed state, and make repeated native destruction safe after
the slots have been released.

Signed-off-by: Kamat, Trivikram <16024985+trivikr@users.noreply.github.com>
Assisted-by: codex:gpt-5.6-sol
PR-URL: #65410
Fixes: #65408
Reviewed-By: James M Snell <jasnell@gmail.com>
Signed-off-by: kyungrae <kyungrae2002@gmail.com>
PR-URL: #65450
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Reviewed-By: Tobias Nießen <tniessen@tnie.de>
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: #65431
Reviewed-By: James M Snell <jasnell@gmail.com>
Reject SPKI export of a private asymmetric key with InvalidAccessError
as required by the algorithm export steps. Let wrapKey propagate the
same export failure.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
PR-URL: #65550
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: James M Snell <jasnell@gmail.com>
Signed-off-by: Renegade334 <contact.9a5d6388@renegade334.me.uk>
PR-URL: #63257
Reviewed-By: Chengzhong Wu <legendecas@gmail.com>
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
`FdEntry::Create()` returned nullptr for any failed `uv_fs_stat()`,
discarding the status, and `BlobFromFilePath()` turned that into
`ERR_INVALID_ARG_VALUE: Unable to open file as blob`. A missing file is
not a malformed argument, and the resulting `TypeError` carried no
`errno`, `syscall`, or `path`, so ENOENT could not be told apart from
any other reason the path was unusable.

Thread the libuv status out of `CreateFdEntry()` and throw a
`UVException` instead, so `fs.openAsBlob()` reports the same error
`fs.stat()` does for the same path.

Fixes: #65514
Signed-off-by: Paul Bouchon <mail@bitpshr.net>
PR-URL: #65517
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
The weakListeners() retention map in EventTarget stored a single
listener per retainer key. Multiple addEventListener() calls sharing
the same retainer (e.g. two listeners on one target using the same
AbortSignal) silently evicted each other's strong reference, allowing
the evicted listener to be garbage collected before its signal
aborted, so only the most recently registered listener was ever
actually removed on abort.

Changed the retention map to store a Set of listeners per retainer
key instead of a single listener, and added matching cleanup in
remove() so entries are released once their retainer's set is empty.

This also fixes the same class of bug in events.aborted() and the
streams kWeakHandler usage, since both go through the same
EventTarget.prototype.addEventListener() code path.

Fixes: #63954
Signed-off-by: aryan7905 <aryansrivastava354@gmail.com>
PR-URL: #64024
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com>
Signed-off-by: GetThatCookie <NimmenKeks@gmx.de>
PR-URL: #64987
Reviewed-By: Robert Nagy <ronagy@icloud.com>
Reviewed-By: Tim Perry <pimterry@gmail.com>
Signed-off-by: greenhead <shren0812@gmail.com>
PR-URL: #65350
Reviewed-By: James M Snell <jasnell@gmail.com>
Similar to compare.js, provide an R-free --analyze to
make scatter.js more self-contained.

Signed-off-by: James M Snell <jasnell@gmail.com>
Assisted-by: Opencode
PR-URL: #65594
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Since the V8 14.2 update, `globals.h` sizes the read-only space
reservation in the shared pointer compression cage from
`V8_CONTIGUOUS_COMPRESSED_RO_SPACE_SIZE_MB`, which BUILD.gn defines
together with `V8_CONTIGUOUS_COMPRESSED_RO_SPACE` whenever
`v8_enable_pointer_compression_shared_cage` is set. features.gypi
defines neither, so builds configured with
`--experimental-pointer-compression-shared-cage` fail to compile V8.
Define both the way BUILD.gn does, with the same 16 MB default.

Refs: #60254
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65464
Reviewed-By: Joyee Cheung <joyeec9h3@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Assisted-by: Opencode
PR-URL: #65587
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
exportKeySpki() already rejects exporting a private key as 'spki'
with an InvalidAccessError, per the Web Crypto export key algorithm
steps for each of RSA, EC, CFRG, ML-DSA, and ML-KEM. exportKeyPkcs8()
was missing the symmetric check: exporting a public key as 'pkcs8'
fell through to the generic "Unable to export ... key using pkcs8
format" NotSupportedError instead of the spec-mandated
InvalidAccessError.

Add the same key-type check to exportKeyPkcs8(), mirroring
exportKeySpki(), and drop the now-redundant type guard around its
call site in exportKeySync(). This also fixes wrapKey(), which
delegates to the same export path.

Add test coverage for both subtle.exportKey('pkcs8', publicKey) and
subtle.wrapKey('pkcs8', publicKey, ...).

Signed-off-by: koreahghg <koreahghg@gmail.com>
PR-URL: #65609
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
The fin argument threaded from Blob::Reader::NotifyPull to the JS
blob reader iterator was dead: the only consumer, `if (fin) continue;`,
was the last statement in the loop and behaved identically to falling
through. End-of-stream is always discovered by the subsequent pull
returning EOS, never via the wakeup label. Remove the flag from the
JS iterator, NotifyPull's signature/argv, and the EndReadable call
site. The `!fin` coalescing bypass collapses safely because a parked
reader always has pull_pending_ == false, so the first wakeup after
parking always fires.

Refs: #64767
Signed-off-by: Naman Trivedi <trivenay@amazon.com>
PR-URL: #65315
Reviewed-By: Tim Perry <pimterry@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com>
CompileSerializeMain() created new "require", "__filename", and
"__dirname" strings via FIXED_ONE_BYTE_STRING() on every call, even
though these strings are already cached on IsolateData/Environment
as require_string(), __filename_string(), and __dirname_string()
(defined via PER_ISOLATE_STRING_PROPERTIES in src/env_properties.h)
and are reused this way elsewhere (e.g. the sibling
RunEmbedderPreload() already obtains Environment* the same way).

Signed-off-by: agape1225 <49804691+agape1225@users.noreply.github.com>
PR-URL: #65453
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Reviewed-By: Chengzhong Wu <legendecas@gmail.com>
If a 'ready' listener starts a write after reopen(), the reopen path
still emits 'drain' from a nextTick before that write completes, so a
listener reading the file on 'drain' can observe it empty. This is the
race behind the test-fastutf8stream-reopen flake deflaked on the test
side in 2e8a4b1.

Skip the extra emit when a write is in flight: #release() emits the
real 'drain' once the write completes, so no event is lost.

The regression test defers the reopened file's fs.write by one
setImmediate, deterministically landing the write after the nextTick
on which the premature 'drain' used to fire.

Refs: 2e8a4b1a8ce
Signed-off-by: Matteo Collina <hello@matteocollina.com>
PR-URL: #65633
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: Robert Nagy <ronagy@icloud.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Add a thread_local re-entrancy guard to TriggerUncaughtException()
that detects when the JS-level exception handler
(process._fatalException) triggers another exception through the
inspector protocol.

This prevents the infinite loop:
  TriggerUncaughtException -> InspectorConsoleCall ->
  TriggerUncaughtException -> InspectorConsoleCall -> ...

When re-entrancy is detected, the function prints a diagnostic with the
formatted exception to stderr using FormatCaughtException (which avoids
the inspector path entirely), then aborts the process.

Fixes: #64326
Signed-off-by: Temuulen Undrakhbayar <zerone.offical@gmail.com>
PR-URL: #64327
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Recursive watch inverted the throwIfNoEntry check during setup, causing
the default behavior to suppress ENOENT while the opt-out threw it.
Other setup errors were also silently ignored.

Suppress only ENOENT when throwIfNoEntry is false. Propagate all
other setup failures and close watchers created before a partial
failure.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #65635
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Update the streams Web Platform Tests to upstream commit
4832db47614f5f48cc57374cbf5c1f70937fad48.

Adjust the streams WPT status entries for owning-type tests
that were renamed to tentative files upstream.

Signed-off-by: Jeong SeokChan <starp321@naver.com>
PR-URL: #65638
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
This fixes an issue where fs.cp and fs.cpSync (when a filter is
provided) correctly restore mtime and atime on copied files when
preserveTimestamps: true is passed, but skip restoring them for
directories.

The fix applies the existing setDestTimestamps helper to directories,
ensuring it is called after directory creation/copying but before any
modes are restored (since restoring a read-only mode would prevent
timestamp modification).

Note: This fix covers fs.cp() (async, all cases) and fs.cpSync()
when a filter is provided. The native fast path used by cpSync()
without a filter (CpSyncCopyDir in src/node_file.cc) has the
identical gap and is left for a separate follow-up contribution, since
it requires native code changes and a different review path.

Signed-off-by: Abhinandan Kumar <abhi128618@gmail.com>
PR-URL: #65540
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: LiviaMedeiros <livia@cirno.name>
The JavaScript recursive watcher used on platforms without a native one
(notably Linux) armed an fs.watch() handle and a stat() for every file
in the tree, and answered every event by stat()ing and re-reading the
whole directory it happened in. A 13k-entry tree cost 13.5k inotify
watches, ~150 ms and ~50 MB to set up, and appending to one file in a
3900-entry directory cost ~9 ms of CPU per event. A file replaced by
rename() (the usual editor save) also stopped being reported, since its
watch stayed on the old inode.

inotify reports changes to the entries of a watched directory, with
their names, so on Linux watch each directory once (symbolic links keep
their own watcher, as before), keep the set of known paths, and resolve
an event with a single stat() of the named entry: unknown names are
added and reported as 'rename', vanished ones are dropped and reported
as 'rename', file changes are reported as 'change'. kqueue and event
ports only report that a directory changed, so on the other platforms
served by this fallback every file keeps its own watcher and a
directory event rescans that directory, as before. unref() and ref()
now reach the underlying handles.

Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65486
Reviewed-By: Moshe Atlow <moshe@atlow.co.il>
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: #65435
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Moshe Atlow <moshe@atlow.co.il>
`NewIsolate()` deferred `SetIsolateErrorHandlers()` when snapshot data
was passed, and `CreateEnvironment()` later installed the handlers with
default `IsolateSettings` after deserializing the main context. An
embedder's `fatal_error_callback`, `oom_error_callback`,
`should_abort_on_uncaught_exception_callback` and
`prepare_stack_trace_callback` were therefore dropped whenever a
snapshot was used, and the per-isolate message listener was added even
if `MESSAGE_LISTENER_WITH_ERROR_LEVEL` had been cleared. The only way
to keep custom handlers was to call `SetIsolateUpForNode()` again after
`CreateEnvironment()`.

Install all handlers in `NewIsolate()` regardless of snapshot data, as
its documentation already describes, and stop touching isolate
handlers in `CreateEnvironment()`. The deferral dates from the initial
isolate snapshot work; every handler already copes with a missing
`Environment`, since without a snapshot they are installed before any
context exists, and workers have been calling `SetIsolateUpForNode()`
right after a snapshot `NewIsolate()` anyway.

Refs: #27321
Refs: #45888
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65407
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Use a child directory so recursive watcher setup always creates a
second watch. Linux no longer watches regular files after the directory
watcher optimization.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #65683
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
X509Certificate::GetPeerCert() built the certificate objects by deleting
entries from the stack returned by SSL_get_peer_cert_chain(), which is
owned by the SSL session. The first read emptied it, so any later read
by getPeerCertificate() or getPeerX509Certificate(), on either peer, saw
a truncated chain or nothing. Copy each issuer with X509_dup instead and
leave the session's stack untouched.

onServerSocketSecure() only called getPeerX509Certificate() to check
whether a peer certificate was present, building the whole chain on
every server handshake; that is what first exposed the destructive read.
Use a lightweight hasPeerCertificate() binding for the presence check.

Signed-off-by: Tony Gies <tgies@tgies.net>
PR-URL: #65602
Fixes: #65579
Refs: #64677
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Tim Perry <pimterry@gmail.com>
PR-URL: #65651
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Read URLPatternInit dictionary members in lexicographical order so
getters and proxy traps observe the access sequence required by WebIDL.
Use sparse dictionary template values so URLPatternResult inputs only
expose members present after WebIDL conversion.

Fixes: #64780
Signed-off-by: piyushrajyadav <piyushyadavrajyadav@gmail.com>
PR-URL: #65498
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
panva and others added 24 commits September 25, 2026 18:47
Use the modp14 prime instead of generating fresh parameters for tests
of constructors, key setters, and memory retention. Keep generic
DiffieHellman instances and the existing setter and leak assertions.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #65980
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Re-encrypting keys on each FIPS test run can produce ciphertext that
decrypts with valid padding under the wrong password, causing a decoder
error instead of the expected bad decrypt.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #65983
Backport-PR-URL: #66233
Refs: https://github.com/nodejs/node/actions/runs/34595689099/job/103251404626?pr=65980
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
PR-URL: #65759
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Add isBoringSSL to the test crypto helpers and use it in tests and
benchmarks. Replace hasOpenSSL3 call sites with hasOpenSSL(3).

Assisted-by: Codex
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
PR-URL: #65762
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
PR-URL: #65956
Backport-PR-URL: #66233
Refs: https://openssl-library.org/post/2026-09-09-openssl-4.1-alpha/
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Return the private key, end-entity certificate, and any other
non-matching certificates from a PKCS#12 (.p12/.pfx) bundle as a
KeyObject and X509Certificate instances.

Node.js already parses PKCS#12 in SecureContext::LoadPKCS12, which backs
tls's `pfx` option, but the results are consumed directly into an
SSL_CTX and never reach JavaScript. Callers who need the key or the
certificates for anything other than an immediate TLS connection have to
shell out to `openssl pkcs12` or take a userland dependency.
SecureContext::LoadPKCS12 now uses this same parsing logic.

The binding wraps d2i_PKCS12_bio() and PKCS12_parse() and follows their
semantics, matching the existing TLS path: the first private key is
returned, the end-entity certificate is the one associated with that
key, and any remaining certificates are returned through
`additionalCertificates`. A bundle containing no private key reports
`certificate` as null and returns its certificates through
`additionalCertificates`.

Absent and empty passphrases are kept distinct, since OpenSSL treats
them differently. Bundles that require OpenSSL's legacy provider throw
ERR_CRYPTO_UNSUPPORTED_OPERATION, reusing the error added for the TLS
path.

Signed-off-by: bmuenzenmeyer <brian.muenzenmeyer@gmail.com>
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
PR-URL: #65627
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Provider-backed keys can have no numeric OpenSSL ID. Identify and
construct asymmetric keys by algorithm name, replacing the custom PQC
name-to-NID substitution with provider-aware matching in ncrypto.

Centralize known algorithm names, public key-type names, capabilities,
and backend compatibility in ncrypto. Use named key generation jobs and
remove asymmetric EVP_PKEY constants from the internal JavaScript
binding.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #65966
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
The fixed 20 ms tolerance in mark.any.js can fail when execution pauses
between creating a mark and reading the clock. Adapt the test in memory
to check the mark timestamp against readings before and after mark().
Keep the vendored fixture and subtest names unchanged.

Apply script modifiers to worker entry scripts as well so the check
covers both WPT globals, and remove the suite-wide flaky expectation.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #66036
Backport-PR-URL: #66233
Fixes: #40449
Refs: #41203
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Use one owning KDF interface for HKDF expansion, PBKDF2 and scrypt,
sharing provider setup with Argon2.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #66108
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Import RSA public keys through OSSL_DECODER on OpenSSL 3 so the
resulting keys stay provider-backed. Preserve the PKCS#1 input structure
and the ASN.1 encodings accepted by the legacy decoder.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #66108
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Resolve provider ciphers before serializing private keys and retain the
fetched implementation across encoding configuration copies and async
key generation. Keep format-specific restrictions in the serializers.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #66108
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Pass group names through EC key generation and report provider names
in key details without requiring an OpenSSL NID. Preserve established
curve aliases and synchronous invalid-curve errors.

Filter built-in curves through EC parameter generation and refresh
getCurves() results when FIPS properties change.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #66108
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Retrieving asymmetricKeyDetails only needs the modulus, public exponent,
and RSA-PSS restrictions. Add a public-only Rsa view so provider-backed
keys do not also extract private components or probe additional primes.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #66108
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Exercise getCiphers(), getHashes(), getMacs() and getCurves() through
one shared cache/FIPS driver and one snapshot fixture. Keep defensive
copies, generation changes, rejected and idempotent toggles, and
cross-worker invalidation consistent across the lists.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #66108
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Signed-off-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
PR-URL: #66111
Backport-PR-URL: #66233
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Original commit message:

    [leaptiering] Fix BaselineOutOfLinePrologue builtin

    ... which tried to preserve kJavaScriptCallDispatchHandleRegister even
    on configurations where it's not used which resulted in a random value
    on the stack discoverable by GC.
    This issue triggered only on non-sandbox configuration with enabled
    leaptiering.

    Drive-by: fix MacroAssembler::GenerateTailCallToReturnedCode() on riscv
    port which wasn't preserving dispatch handle as all the other ports do.

    Bug: 42204201
    Fixed: 413769394

    Change-Id: If146b0b7a6cf972ed5a881142f40980774f19cba
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/6587010
    Commit-Queue: Igor Sheludko <ishell@chromium.org>
    Reviewed-by: Olivier Flückiger <olivf@chromium.org>
    Cr-Commit-Position: refs/heads/main@{#100512}

Node.js 24 builds V8 with leaptiering enabled and the sandbox disabled,
so V8_JS_LINKAGE_INCLUDES_DISPATCH_HANDLE is not defined and the JS
calling convention does not carry the dispatch handle register (x4 on
arm64). BaselineOutOfLinePrologue and GenerateTailCallToReturnedCode
still pushed that register as a tagged slot of an INTERNAL frame, so
whatever value the caller left there is dereferenced by
ClearStaleLeftTrimmedPointerVisitor during mark-compact root scanning
and crashes the process with SIGSEGV (seen as jest workers dying).

Refs: v8/v8@0b94a9f
Fixes: #62393
PR-URL: #65753
Reviewed-By: Richard Lau <richard.lau@ibm.com>
test-crypto-keygen-deprecation and
test-crypto-keygen-duplicate-deprecated-option generate rsa-pss key
pairs, which BoringSSL does not support. The other rsa-pss keygen tests
skip there since #62883, but these
two only exist on v24.x (#58706
removed them from main earlier), so its backport could not cover them.

Refs: #62883
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65808
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Since d937c8c ("wasm: enable JSPI") ProcessGlobalArgsInternal()
unconditionally appends --experimental-wasm-jspi to the V8 argument
list. V8 only defines the experimental_wasm_* flags when it is built
with V8_ENABLE_WEBASSEMBLY, and configure --v8-lite-mode sets
v8_enable_webassembly=0. V8::SetFlagsFromCommandLine() is called with
remove_flags=true, which silently leaves unrecognized flags in argv, so
node reports "bad option: --experimental-wasm-jspi" and exits with
kInvalidCommandLineArgument. The first binary to run that code is
node_mksnapshot, so every --v8-lite-mode build has failed since
v24.20.0:

  bad option: --experimental-wasm-jspi
  node_mksnapshot failed with exit code 9

Forward v8_enable_webassembly to all targets as V8_ENABLE_WEBASSEMBLY,
the same way common.gypi already forwards the other V8 build flags, and
only push the JSPI flag when WebAssembly is compiled in.

Refs: #59941
Assisted-by: claude:fable-5.1
Signed-off-by: Piotr Kubaj <pkubaj@FreeBSD.org>
PR-URL: #66082
Reviewed-By: Guy Bedford <guybedford@gmail.com>
Signed-off-by: James Ross <james@jross.me>
PR-URL: #64606
Backport-PR-URL: #66133
Fixes: #64870
Refs: #64606
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
`Realm::RunCleanup()` finalizes the cppgc-managed wrappers it tracks
so that none of them touches the Realm once it is gone, but it reaches
them through weak persistents, and the GC clears those as soon as it
finds a wrapper dead. With lazy and concurrent sweeping the destructor
can run much later, so a wrapper collected shortly before
`FreeEnvironment()` and swept after it was skipped by the cleanup and
kept its `realm_`: `~CppgcMixin()` then wrote
`should_purge_empty_cppgc_wrappers_` into the freed Realm, and a
subclass destructor calling `Finalize()` as documented would have
called `Clean()` with a dangling Realm. A Worker that compiles a few
`vm.Script`s, gets a full GC from external memory pressure and calls
`process.exit()` is enough to hit the first case.

Move the Realm pointer into the list node, which the wrapper now owns
and deletes in its destructor. `CppgcWrapperList::Cleanup()` unlinks
every node, finalizing the wrappers that are still alive and clearing
the Realm pointer for the collected ones, which only their own
destructor may still touch. `Realm::PendingCleanup()` accounts for the
list so it is always drained. The purge flag, its GC epilogue callback
and `PurgeEmpty()` are no longer needed, and removing them also stops
the list nodes of wrappers that are alive at `FreeEnvironment()` from
leaking.

Refs: #56534
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65778
Backport-PR-URL: #66168
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Original commit message:

    [compiler] Stop collecting array and object prototypes

    We can check in O(1) whether an object is either Object.prototype or
    Array.prototype by directly comparing it with the objects, so there's
    no need to collect them.

    Change-Id: Iadedf8b05cae3d67191fb4836c186620dc009118
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/6487694
    Commit-Queue: Toon Verwaest <verwaest@chromium.org>
    Reviewed-by: Igor Sheludko <ishell@chromium.org>
    Commit-Queue: Igor Sheludko <ishell@chromium.org>
    Auto-Submit: Toon Verwaest <verwaest@chromium.org>
    Cr-Commit-Position: refs/heads/main@{#99894}

Refs: v8/v8@8901c79
Co-authored-by: inoway46 <inoueyuya416@gmail.com>
PR-URL: #66089
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Original commit message:

    [compiler] Thread-safe IsArrayOrObjectPrototype

    Bug: 467311868
    Change-Id: I574aa62d859030545e6a52d693a61e570381e557
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7460949
    Reviewed-by: Leszek Swirski <leszeks@chromium.org>
    Commit-Queue: Jakob Linke <jgruber@chromium.org>
    Cr-Commit-Position: refs/heads/main@{#104707}

Refs: v8/v8@c355350
Co-authored-by: inoway46 <inoueyuya416@gmail.com>
PR-URL: #66089
Fixes: #66053
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Original commit message:

    AIX: Fix race condition in DecommitPages

    The current implementation of DecommitPages could lead to a race
    condition where another thread maps the same region of memory right after we unmap it.

    This is currently causing test failures on Node.js:
    #62647

    As a workaround we avoid unmapping the address space and instead
    mark the region as inaccessible using mprotect. We originally
    considered using madvise to release physical memory, but it is a
    no-op on AIX and was omitted from this implementation.
    IT:105

    Change-Id: I8271a562be2e7ebcb685a2dd3b7425a38bebe1c9
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8193436
    Reviewed-by: Anton Bikineev <bikineev@chromium.org>
    Commit-Queue: Milad Farazmand <mfarazma@ibm.com>
    Reviewed-by: Milad Farazmand <mfarazma@ibm.com>
    Cr-Commit-Position: refs/heads/main@{#109206}

Refs: v8/v8@ea9c016
Signed-off-by: Richard Lau <richard.lau@ibm.com>
PR-URL: #66570
Refs: #62647
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Notable changes:

crypto:
  * (SEMVER-MINOR) add crypto.parsePKCS12() (Brian Muenzenmeyer) #65627
  * (SEMVER-MINOR) add a generic MAC API (Filip Skokan) #65553
  * (SEMVER-MINOR) discover ciphers from OpenSSL providers (Filip Skokan) #65484
  * (SEMVER-MINOR) discover hashes from OpenSSL providers (Filip Skokan) #65484
  * (SEMVER-MINOR) enable SIV and GCM-SIV modes in Cipher/Decipher APIs (Filip Skokan) #63411
doc:
  * add araujogui to collaborators (Guilherme Araújo) #66090
  * deprecate `Server.prototype._listen2` in `node:net` (Antoine du Hamel) #65593
net:
  * (SEMVER-MINOR) support sending net.BoundSocket to threads and child processes (Guy Bedford) #64725
perf_hooks:
  * (SEMVER-MINOR) implement SlidingWindowHistogram (James M Snell) #65825
  * (SEMVER-MINOR) implement qrde analysis support in Histogram (James M Snell) #65806
  * (SEMVER-MINOR) implement Histogram meanCI API (James M Snell) #65606
  * (SEMVER-MINOR) add CBOR export/import for histogram exchange (James M Snell) #65434
sqlite:
  * (SEMVER-MINOR) add StatementSync.prototype.close() (Guilherme Araújo) #64232
  * (SEMVER-MINOR) add StatementSync.prototype[Symbol.dispose]() (Guilherme Araújo) #64232
src,lib:
  * (SEMVER-MINOR) add util.markPromiseAsHandled (James M Snell) #65805
test:
  * (SEMVER-MINOR) expand histogram test coverage (James M Snell) #65825
util:
  * (SEMVER-MINOR) implement util.throttle (James M Snell) #65899
  * (SEMVER-MINOR) implement debounce (James M Snell) #65899

PR-URL: #66667
@github-actions github-actions Bot added release Issues and PRs related to Node.js releases. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch. labels Oct 11, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/actions
  • @nodejs/releasers
  • @nodejs/tsc

@nodejs-github-bot

nodejs-github-bot commented Oct 11, 2026 •

Copy link
Copy Markdown
Collaborator

@fitzyracing1

This comment was marked as low quality.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release Issues and PRs related to Node.js releases. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.