[Flight Reply] Align Rspack decoders with upstream changes - #1
Merged
SyMind merged 7 commits intoAug 11, 2026
Merged
Conversation
…n is not a Blob (react#36055) Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de> (cherry picked from commit 12ba7d8)
Co-authored-by: "Sebastian \"Sebbie\" Silbermann" <sebastian.silbermann@vercel.com> (cherry picked from commit 672b242)
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de> (cherry picked from commit 795203e)
…eact#36468) Fixes a regression from react#36425 where referenced `FormData` entries can be dropped by `decodeReplyFromBusboy` when files are interleaved with text fields in the payload. `decodeReplyFromBusboy` queues text fields that arrive while a file is being streamed and flushes them after the last file's `'end'`, working around busboy emitting `'end'` deferred relative to subsequent `'field'` events. With multiple files interleaved with text, this loses the relative order of the affected text entries. The reorder was a long-standing but invisible issue — entries came back in the wrong order but were all present — until react#36425 tightened how referenced FormData entries are collected from the backing store to rely on them being contiguous. With that assumption violated, referenced FormDatas can now come back with some entries dropped. The pattern is most easily surfaced through `useActionState` actions that return the submitted `FormData` as part of their state. This replaces the tail-flush with a linked list of pending files. Text fields that arrive while a file is in flight are queued on the tail file's `queuedFields`; fields that arrive when the list is empty resolve immediately. `flush()` walks from the head, resolving each completed file followed by its queued fields, and stops at the first file that hasn't ended yet. The backing FormData now matches the payload's order, restoring the contiguity assumption (and fixing the long-standing reorder as a side effect). The same change is applied to all five copies in `react-server-dom-{webpack,turbopack,parcel,esm,unbundled}`. Two new tests cover the multi-file interleave. fixesvercel/next.js#93822 (cherry picked from commit b91823e)
This fixes security vulnerabilities in Server Functions. (cherry picked from commit 1dd4ecb)
Mirror the selected Reply changes into the Rspack-owned browser, edge, and Node adapters after the dependency-closed upstream backports. Forward caller-provided array size limits, preserve multipart field/file order, and settle failed async iterators without recursive error re-entry. Add public behavior coverage across every Rspack decoder, action-selection path, cyclic collection type, iterator settlement, and Busboy ordering direction. This is a tactical source-parity change for the existing proposal branch; it does not make that branch current with React main.
SyMind
approved these changes
Aug 11, 2026
SyMind
marked this pull request as ready for review
August 11, 2026 03:04
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This is a focused, tactical update to
SyMind/react:react-server-dom-rspack, the source branch for react/react#35473.It forward-ports the dependency-closed Reply changes represented by:
12ba7d812— Blob backing-entry validation;404b38c764— cyclic model protection;dd453071d— Reply type and backing-store hardening;b91823e214— ordered interleaved FormData decoding; and81e442eaf— action selection and iterator error handling.The corresponding Rspack work:
arraySizeLimitvalues through browser, edge, Node, async-iterable, and Busboy decoders;decodeFormState;19.3.0source-version placeholder in place of the generated January canary string.The upstream-derived commits retain their authorship and cherry-pick provenance. Generated package bundles are not edited.
This PR aligns the existing proposal branch with these selected Reply changes only. It is not a rebase onto current React
main, does not make react#35473 merge-ready, and does not assign React advisories, CVEs, or vulnerable-version ranges toreact-server-dom-rspack.How did you test this change?
dom-node-rspack,dom-browser-rspack, anddom-edge-rspack: 0 errors.check-changedpassed.version-checkpassed.git diff --checkpassed.