stream: fix flaky stream destroy, reachable from HTTP/2 teardown - #65079

Closed
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake
Closed

stream: fix flaky stream destroy, reachable from HTTP/2 teardown#65079
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake

Conversation

@pimterry

Copy link
Copy Markdown
Member

Some of the HTTP/2 tests have become flaky, e.g. nodejs/reliability#1623 shows yesterday:

  • parallel/test-worker-terminate-http2-respond-with-file failed 11 times
  • parallel/test-stream-pipeline-http2 failed 10 times

Best guess is these are both due to the window update PR #64623 (cc @mcollina) since the timing lines up exactly. I think this is really just the window size highlighting existing issues though.

This PR fixes the first issue, which triggers flakes in parallel/test-worker-terminate-http2-respond-with-file. I'll kick off a stress test to confirm, but I can reproduce this locally, and reproduced as resolved with this fix. I'm still working on the 2nd, which only reproduces on Mac and seems a bit more complex.

Actual failure in the 1st test is a crash with pure virtual method called. That fires due to ReadStop within this trace:

Worker::Run → FreeEnvironment
→ Environment::RunCleanup
→ BaseObjectList::Cleanup
→ fs::FileHandle::~FileHandle
→ StreamResource::~StreamResource
→ StreamPipe::ReadableListener::OnStreamDestroy
→ StreamPipe::ReadableListener::OnStreamRead

I.e. during destroy within the destructor chain, we call OnStreamRead, which tries to call stream()->ReadStop inside the sources destructor.

This is only called because OnStreamDestroy manually calls OnStreamRead with an error code to reuse its error/eof teardown logic. We don't need most of that in the destruction scenario (which is only ever called from ~StreamResource, where the stream is already dead).

I've refactored out the relevant bit to split them up (just guarding just fails in the next line, where previous_listener_ is also null). That then exposed two other bugs for the same state, where two other methods that get reached later in this teardown flow also fail to check if the stream is already destroyed - those just need simple guards.

Seems like this is a flaky race because it depends on whether the sink (Http2Stream) or the file handle gets destroyed first by Cleanup().

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels Aug 6, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

cc @nodejs/http2

@codecov

codecovBot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.32%. Comparing base (b33cc0e) to head (da4b684).
⚠️ Report is 81 commits behind head on main.

Files with missing linesPatch %Lines
src/stream_pipe.cc0.00%5 Missing and 2 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65079 +/- ##
==========================================
+ Coverage 90.29% 90.32% +0.03% 
==========================================
Files 759 759 Lines 247598 248458 +860 Branches 46680 46869 +189 ==========================================
+ Hits 223566 224420 +854 + Misses 15503 15448 -55 - Partials 8529 8590 +61 
Files with missing linesCoverage Δ
src/stream_pipe.cc58.71% <0.00%> (-1.47%)⬇️

... and 87 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pimterry

Copy link
Copy Markdown
MemberAuthor

I'll kick off a stress test to confirm

Stress testing inconclusive - the tests passed on both main and this branch, even with multiple runs. They're definitely failing in PRs though. I can reliably reproduce the reported failure locally (that first failure above, it hits for 2-3% of runs) and validate that it's fixed with this change. The trace is where is crashes on my machine with the matching error, and it's clearly a broken flow, so I think this is the right fix regardless.

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

I concur with the analysis

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@panvapanva added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 7, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva

panva commented Aug 7, 2026

Copy link
Copy Markdown
Member

Even with this PR's change I can still fail test-stream-pipeline-http2.js with a timeout 31/1000 times. Without it about 56/1000 times.

This diff that claude spit out to deflake test-stream-pipeline-http2.js makes that 0/1000 with or without this PR, but I don't know enough about this subsystem to say whether that retains the point of the test or not.

diff --git a/test/parallel/test-stream-pipeline-http2.js b/test/parallel/test-stream-pipeline-http2.js
--- a/test/parallel/test-stream-pipeline-http2.js
+++ b/test/parallel/test-stream-pipeline-http2.js
@@ -27,10 +27,11 @@
- let cnt = 10;
+ let received = 0;
req.on('data', (data) => {
- cnt--;
- if (cnt === 0) rs.destroy();
+ received += data.length;
+ // HTTP/2 data event boundaries are non-deterministic.
+ if (received >= 32 * 1024) rs.destroy();
});

@pimterry

Copy link
Copy Markdown
MemberAuthor

Even with this PR's change I can still fail test-stream-pipeline-http2.js

Yes, sorry if the description isn't clear - both failing tests are related to that PR, but this PR only fixes the first of the two. I.e. test-worker-terminate-http2-respond-with-file.

I haven't opened a fix for the second yet, because I think it's actually exposed a real bug that's a bit complicated, and mac-only. Looks like that fix would resolve the test, but from what I can tell so far there's a real underlying deadlock that's reproducible independently, so I want to get a proper fix for that instead. I'll update when I have more info there.

@panva

panva commented Aug 9, 2026

Copy link
Copy Markdown
Member

@pimterry can you land this with the fix/workaround i posted to the remaining flake knowing you'll revisit the underlying deadlock problem and possibly change it again?

This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
@pimterry

Copy link
Copy Markdown
MemberAuthor

Good plan @panva, now done 👍.

I'll open the other fix separately. I've got it working now but the deadlock comes from code we added to resolve past CVEs, so needs some thought and it'd be nice not to rush it.

@pimterrypimterry added request-ci Add this label to start a Jenkins CI on a PR. commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. labels Aug 9, 2026
@panvapanva removed the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@panvapanva added the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterrypimterry added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
panva pushed a commit that referenced this pull request Aug 10, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
panva added a commit that referenced this pull request Aug 10, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@panva

Copy link
Copy Markdown
Member

Landed in 780229b...404b0cf

@panvapanva closed this Aug 10, 2026
@panvapanva removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@aduh95

Copy link
Copy Markdown
Contributor

IIUC 64a762b should not be backported as it is based on a semver-major change. If I'm wrong, please open a manual backport PR

@aduh95aduh95 added the backported-to-v26.x PRs backported to the v26.x-staging branch. label Aug 27, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

@aduh95 this can actually be safely backported I think. It fixes a bug (broken stream teardown) that exists independently of the semver-major change (increasing default HTTP/2 window sizes) and shouldn't conflict with anything else I'm aware of.

The bug was effectively invisible with small HTTP/2 windows, but it's still technically present, and users could always manually configure window sizes in the past which would likely trigger this as well, so it's probably reachable in all versions.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.backported-to-v26.xPRs backported to the v26.x-staging branch.c++Issues and PRs that require attention from people who are familiar with C++.commit-queue-rebasePRs the Commit Queue should land as multiple self-contained commits.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@pimterry@nodejs-github-bot@panva@aduh95@mcollina@anonrig
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

stream: fix flaky stream destroy, reachable from HTTP/2 teardown - #65079

Closed
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake
Closed

stream: fix flaky stream destroy, reachable from HTTP/2 teardown#65079
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake

Conversation

@pimterry

Copy link
Copy Markdown
Member

Some of the HTTP/2 tests have become flaky, e.g. nodejs/reliability#1623 shows yesterday:

  • parallel/test-worker-terminate-http2-respond-with-file failed 11 times
  • parallel/test-stream-pipeline-http2 failed 10 times

Best guess is these are both due to the window update PR #64623 (cc @mcollina) since the timing lines up exactly. I think this is really just the window size highlighting existing issues though.

This PR fixes the first issue, which triggers flakes in parallel/test-worker-terminate-http2-respond-with-file. I'll kick off a stress test to confirm, but I can reproduce this locally, and reproduced as resolved with this fix. I'm still working on the 2nd, which only reproduces on Mac and seems a bit more complex.

Actual failure in the 1st test is a crash with pure virtual method called. That fires due to ReadStop within this trace:

Worker::Run → FreeEnvironment
→ Environment::RunCleanup
→ BaseObjectList::Cleanup
→ fs::FileHandle::~FileHandle
→ StreamResource::~StreamResource
→ StreamPipe::ReadableListener::OnStreamDestroy
→ StreamPipe::ReadableListener::OnStreamRead

I.e. during destroy within the destructor chain, we call OnStreamRead, which tries to call stream()->ReadStop inside the sources destructor.

This is only called because OnStreamDestroy manually calls OnStreamRead with an error code to reuse its error/eof teardown logic. We don't need most of that in the destruction scenario (which is only ever called from ~StreamResource, where the stream is already dead).

I've refactored out the relevant bit to split them up (just guarding just fails in the next line, where previous_listener_ is also null). That then exposed two other bugs for the same state, where two other methods that get reached later in this teardown flow also fail to check if the stream is already destroyed - those just need simple guards.

Seems like this is a flaky race because it depends on whether the sink (Http2Stream) or the file handle gets destroyed first by Cleanup().

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels Aug 6, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

cc @nodejs/http2

@codecov

codecovBot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.32%. Comparing base (b33cc0e) to head (da4b684).
⚠️ Report is 81 commits behind head on main.

Files with missing linesPatch %Lines
src/stream_pipe.cc0.00%5 Missing and 2 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65079 +/- ##
==========================================
+ Coverage 90.29% 90.32% +0.03% 
==========================================
Files 759 759 Lines 247598 248458 +860 Branches 46680 46869 +189 ==========================================
+ Hits 223566 224420 +854 + Misses 15503 15448 -55 - Partials 8529 8590 +61 
Files with missing linesCoverage Δ
src/stream_pipe.cc58.71% <0.00%> (-1.47%)⬇️

... and 87 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pimterry

Copy link
Copy Markdown
MemberAuthor

I'll kick off a stress test to confirm

Stress testing inconclusive - the tests passed on both main and this branch, even with multiple runs. They're definitely failing in PRs though. I can reliably reproduce the reported failure locally (that first failure above, it hits for 2-3% of runs) and validate that it's fixed with this change. The trace is where is crashes on my machine with the matching error, and it's clearly a broken flow, so I think this is the right fix regardless.

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

I concur with the analysis

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@panvapanva added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 7, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva

panva commented Aug 7, 2026

Copy link
Copy Markdown
Member

Even with this PR's change I can still fail test-stream-pipeline-http2.js with a timeout 31/1000 times. Without it about 56/1000 times.

This diff that claude spit out to deflake test-stream-pipeline-http2.js makes that 0/1000 with or without this PR, but I don't know enough about this subsystem to say whether that retains the point of the test or not.

diff --git a/test/parallel/test-stream-pipeline-http2.js b/test/parallel/test-stream-pipeline-http2.js
--- a/test/parallel/test-stream-pipeline-http2.js
+++ b/test/parallel/test-stream-pipeline-http2.js
@@ -27,10 +27,11 @@
- let cnt = 10;
+ let received = 0;
req.on('data', (data) => {
- cnt--;
- if (cnt === 0) rs.destroy();
+ received += data.length;
+ // HTTP/2 data event boundaries are non-deterministic.
+ if (received >= 32 * 1024) rs.destroy();
});

@pimterry

Copy link
Copy Markdown
MemberAuthor

Even with this PR's change I can still fail test-stream-pipeline-http2.js

Yes, sorry if the description isn't clear - both failing tests are related to that PR, but this PR only fixes the first of the two. I.e. test-worker-terminate-http2-respond-with-file.

I haven't opened a fix for the second yet, because I think it's actually exposed a real bug that's a bit complicated, and mac-only. Looks like that fix would resolve the test, but from what I can tell so far there's a real underlying deadlock that's reproducible independently, so I want to get a proper fix for that instead. I'll update when I have more info there.

@panva

panva commented Aug 9, 2026

Copy link
Copy Markdown
Member

@pimterry can you land this with the fix/workaround i posted to the remaining flake knowing you'll revisit the underlying deadlock problem and possibly change it again?

This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
@pimterry

Copy link
Copy Markdown
MemberAuthor

Good plan @panva, now done 👍.

I'll open the other fix separately. I've got it working now but the deadlock comes from code we added to resolve past CVEs, so needs some thought and it'd be nice not to rush it.

@pimterrypimterry added request-ci Add this label to start a Jenkins CI on a PR. commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. labels Aug 9, 2026
@panvapanva removed the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@panvapanva added the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterrypimterry added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
panva pushed a commit that referenced this pull request Aug 10, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
panva added a commit that referenced this pull request Aug 10, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@panva

Copy link
Copy Markdown
Member

Landed in 780229b...404b0cf

@panvapanva closed this Aug 10, 2026
@panvapanva removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@aduh95

Copy link
Copy Markdown
Contributor

IIUC 64a762b should not be backported as it is based on a semver-major change. If I'm wrong, please open a manual backport PR

@aduh95aduh95 added the backported-to-v26.x PRs backported to the v26.x-staging branch. label Aug 27, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

@aduh95 this can actually be safely backported I think. It fixes a bug (broken stream teardown) that exists independently of the semver-major change (increasing default HTTP/2 window sizes) and shouldn't conflict with anything else I'm aware of.

The bug was effectively invisible with small HTTP/2 windows, but it's still technically present, and users could always manually configure window sizes in the past which would likely trigger this as well, so it's probably reachable in all versions.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.backported-to-v26.xPRs backported to the v26.x-staging branch.c++Issues and PRs that require attention from people who are familiar with C++.commit-queue-rebasePRs the Commit Queue should land as multiple self-contained commits.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@pimterry@nodejs-github-bot@panva@aduh95@mcollina@anonrig
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

stream: fix flaky stream destroy, reachable from HTTP/2 teardown - #65079

Closed
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake
Closed

stream: fix flaky stream destroy, reachable from HTTP/2 teardown#65079
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake

Conversation

@pimterry

Copy link
Copy Markdown
Member

Some of the HTTP/2 tests have become flaky, e.g. nodejs/reliability#1623 shows yesterday:

  • parallel/test-worker-terminate-http2-respond-with-file failed 11 times
  • parallel/test-stream-pipeline-http2 failed 10 times

Best guess is these are both due to the window update PR #64623 (cc @mcollina) since the timing lines up exactly. I think this is really just the window size highlighting existing issues though.

This PR fixes the first issue, which triggers flakes in parallel/test-worker-terminate-http2-respond-with-file. I'll kick off a stress test to confirm, but I can reproduce this locally, and reproduced as resolved with this fix. I'm still working on the 2nd, which only reproduces on Mac and seems a bit more complex.

Actual failure in the 1st test is a crash with pure virtual method called. That fires due to ReadStop within this trace:

Worker::Run → FreeEnvironment
→ Environment::RunCleanup
→ BaseObjectList::Cleanup
→ fs::FileHandle::~FileHandle
→ StreamResource::~StreamResource
→ StreamPipe::ReadableListener::OnStreamDestroy
→ StreamPipe::ReadableListener::OnStreamRead

I.e. during destroy within the destructor chain, we call OnStreamRead, which tries to call stream()->ReadStop inside the sources destructor.

This is only called because OnStreamDestroy manually calls OnStreamRead with an error code to reuse its error/eof teardown logic. We don't need most of that in the destruction scenario (which is only ever called from ~StreamResource, where the stream is already dead).

I've refactored out the relevant bit to split them up (just guarding just fails in the next line, where previous_listener_ is also null). That then exposed two other bugs for the same state, where two other methods that get reached later in this teardown flow also fail to check if the stream is already destroyed - those just need simple guards.

Seems like this is a flaky race because it depends on whether the sink (Http2Stream) or the file handle gets destroyed first by Cleanup().

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels Aug 6, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

cc @nodejs/http2

@codecov

codecovBot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.32%. Comparing base (b33cc0e) to head (da4b684).
⚠️ Report is 81 commits behind head on main.

Files with missing linesPatch %Lines
src/stream_pipe.cc0.00%5 Missing and 2 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65079 +/- ##
==========================================
+ Coverage 90.29% 90.32% +0.03% 
==========================================
Files 759 759 Lines 247598 248458 +860 Branches 46680 46869 +189 ==========================================
+ Hits 223566 224420 +854 + Misses 15503 15448 -55 - Partials 8529 8590 +61 
Files with missing linesCoverage Δ
src/stream_pipe.cc58.71% <0.00%> (-1.47%)⬇️

... and 87 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pimterry

Copy link
Copy Markdown
MemberAuthor

I'll kick off a stress test to confirm

Stress testing inconclusive - the tests passed on both main and this branch, even with multiple runs. They're definitely failing in PRs though. I can reliably reproduce the reported failure locally (that first failure above, it hits for 2-3% of runs) and validate that it's fixed with this change. The trace is where is crashes on my machine with the matching error, and it's clearly a broken flow, so I think this is the right fix regardless.

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

I concur with the analysis

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@panvapanva added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 7, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva

panva commented Aug 7, 2026

Copy link
Copy Markdown
Member

Even with this PR's change I can still fail test-stream-pipeline-http2.js with a timeout 31/1000 times. Without it about 56/1000 times.

This diff that claude spit out to deflake test-stream-pipeline-http2.js makes that 0/1000 with or without this PR, but I don't know enough about this subsystem to say whether that retains the point of the test or not.

diff --git a/test/parallel/test-stream-pipeline-http2.js b/test/parallel/test-stream-pipeline-http2.js
--- a/test/parallel/test-stream-pipeline-http2.js
+++ b/test/parallel/test-stream-pipeline-http2.js
@@ -27,10 +27,11 @@
- let cnt = 10;
+ let received = 0;
req.on('data', (data) => {
- cnt--;
- if (cnt === 0) rs.destroy();
+ received += data.length;
+ // HTTP/2 data event boundaries are non-deterministic.
+ if (received >= 32 * 1024) rs.destroy();
});

@pimterry

Copy link
Copy Markdown
MemberAuthor

Even with this PR's change I can still fail test-stream-pipeline-http2.js

Yes, sorry if the description isn't clear - both failing tests are related to that PR, but this PR only fixes the first of the two. I.e. test-worker-terminate-http2-respond-with-file.

I haven't opened a fix for the second yet, because I think it's actually exposed a real bug that's a bit complicated, and mac-only. Looks like that fix would resolve the test, but from what I can tell so far there's a real underlying deadlock that's reproducible independently, so I want to get a proper fix for that instead. I'll update when I have more info there.

@panva

panva commented Aug 9, 2026

Copy link
Copy Markdown
Member

@pimterry can you land this with the fix/workaround i posted to the remaining flake knowing you'll revisit the underlying deadlock problem and possibly change it again?

This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
@pimterry

Copy link
Copy Markdown
MemberAuthor

Good plan @panva, now done 👍.

I'll open the other fix separately. I've got it working now but the deadlock comes from code we added to resolve past CVEs, so needs some thought and it'd be nice not to rush it.

@pimterrypimterry added request-ci Add this label to start a Jenkins CI on a PR. commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. labels Aug 9, 2026
@panvapanva removed the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@panvapanva added the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterrypimterry added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
panva pushed a commit that referenced this pull request Aug 10, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
panva added a commit that referenced this pull request Aug 10, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@panva

Copy link
Copy Markdown
Member

Landed in 780229b...404b0cf

@panvapanva closed this Aug 10, 2026
@panvapanva removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@aduh95

Copy link
Copy Markdown
Contributor

IIUC 64a762b should not be backported as it is based on a semver-major change. If I'm wrong, please open a manual backport PR

@aduh95aduh95 added the backported-to-v26.x PRs backported to the v26.x-staging branch. label Aug 27, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

@aduh95 this can actually be safely backported I think. It fixes a bug (broken stream teardown) that exists independently of the semver-major change (increasing default HTTP/2 window sizes) and shouldn't conflict with anything else I'm aware of.

The bug was effectively invisible with small HTTP/2 windows, but it's still technically present, and users could always manually configure window sizes in the past which would likely trigger this as well, so it's probably reachable in all versions.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.backported-to-v26.xPRs backported to the v26.x-staging branch.c++Issues and PRs that require attention from people who are familiar with C++.commit-queue-rebasePRs the Commit Queue should land as multiple self-contained commits.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@pimterry@nodejs-github-bot@panva@aduh95@mcollina@anonrig
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

stream: fix flaky stream destroy, reachable from HTTP/2 teardown - #65079

Closed
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake
Closed

stream: fix flaky stream destroy, reachable from HTTP/2 teardown#65079
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake

Conversation

@pimterry

Copy link
Copy Markdown
Member

Some of the HTTP/2 tests have become flaky, e.g. nodejs/reliability#1623 shows yesterday:

  • parallel/test-worker-terminate-http2-respond-with-file failed 11 times
  • parallel/test-stream-pipeline-http2 failed 10 times

Best guess is these are both due to the window update PR #64623 (cc @mcollina) since the timing lines up exactly. I think this is really just the window size highlighting existing issues though.

This PR fixes the first issue, which triggers flakes in parallel/test-worker-terminate-http2-respond-with-file. I'll kick off a stress test to confirm, but I can reproduce this locally, and reproduced as resolved with this fix. I'm still working on the 2nd, which only reproduces on Mac and seems a bit more complex.

Actual failure in the 1st test is a crash with pure virtual method called. That fires due to ReadStop within this trace:

Worker::Run → FreeEnvironment
→ Environment::RunCleanup
→ BaseObjectList::Cleanup
→ fs::FileHandle::~FileHandle
→ StreamResource::~StreamResource
→ StreamPipe::ReadableListener::OnStreamDestroy
→ StreamPipe::ReadableListener::OnStreamRead

I.e. during destroy within the destructor chain, we call OnStreamRead, which tries to call stream()->ReadStop inside the sources destructor.

This is only called because OnStreamDestroy manually calls OnStreamRead with an error code to reuse its error/eof teardown logic. We don't need most of that in the destruction scenario (which is only ever called from ~StreamResource, where the stream is already dead).

I've refactored out the relevant bit to split them up (just guarding just fails in the next line, where previous_listener_ is also null). That then exposed two other bugs for the same state, where two other methods that get reached later in this teardown flow also fail to check if the stream is already destroyed - those just need simple guards.

Seems like this is a flaky race because it depends on whether the sink (Http2Stream) or the file handle gets destroyed first by Cleanup().

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels Aug 6, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

cc @nodejs/http2

@codecov

codecovBot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.32%. Comparing base (b33cc0e) to head (da4b684).
⚠️ Report is 81 commits behind head on main.

Files with missing linesPatch %Lines
src/stream_pipe.cc0.00%5 Missing and 2 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65079 +/- ##
==========================================
+ Coverage 90.29% 90.32% +0.03% 
==========================================
Files 759 759 Lines 247598 248458 +860 Branches 46680 46869 +189 ==========================================
+ Hits 223566 224420 +854 + Misses 15503 15448 -55 - Partials 8529 8590 +61 
Files with missing linesCoverage Δ
src/stream_pipe.cc58.71% <0.00%> (-1.47%)⬇️

... and 87 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pimterry

Copy link
Copy Markdown
MemberAuthor

I'll kick off a stress test to confirm

Stress testing inconclusive - the tests passed on both main and this branch, even with multiple runs. They're definitely failing in PRs though. I can reliably reproduce the reported failure locally (that first failure above, it hits for 2-3% of runs) and validate that it's fixed with this change. The trace is where is crashes on my machine with the matching error, and it's clearly a broken flow, so I think this is the right fix regardless.

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

I concur with the analysis

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@panvapanva added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 7, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva

panva commented Aug 7, 2026

Copy link
Copy Markdown
Member

Even with this PR's change I can still fail test-stream-pipeline-http2.js with a timeout 31/1000 times. Without it about 56/1000 times.

This diff that claude spit out to deflake test-stream-pipeline-http2.js makes that 0/1000 with or without this PR, but I don't know enough about this subsystem to say whether that retains the point of the test or not.

diff --git a/test/parallel/test-stream-pipeline-http2.js b/test/parallel/test-stream-pipeline-http2.js
--- a/test/parallel/test-stream-pipeline-http2.js
+++ b/test/parallel/test-stream-pipeline-http2.js
@@ -27,10 +27,11 @@
- let cnt = 10;
+ let received = 0;
req.on('data', (data) => {
- cnt--;
- if (cnt === 0) rs.destroy();
+ received += data.length;
+ // HTTP/2 data event boundaries are non-deterministic.
+ if (received >= 32 * 1024) rs.destroy();
});

@pimterry

Copy link
Copy Markdown
MemberAuthor

Even with this PR's change I can still fail test-stream-pipeline-http2.js

Yes, sorry if the description isn't clear - both failing tests are related to that PR, but this PR only fixes the first of the two. I.e. test-worker-terminate-http2-respond-with-file.

I haven't opened a fix for the second yet, because I think it's actually exposed a real bug that's a bit complicated, and mac-only. Looks like that fix would resolve the test, but from what I can tell so far there's a real underlying deadlock that's reproducible independently, so I want to get a proper fix for that instead. I'll update when I have more info there.

@panva

panva commented Aug 9, 2026

Copy link
Copy Markdown
Member

@pimterry can you land this with the fix/workaround i posted to the remaining flake knowing you'll revisit the underlying deadlock problem and possibly change it again?

This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
@pimterry

Copy link
Copy Markdown
MemberAuthor

Good plan @panva, now done 👍.

I'll open the other fix separately. I've got it working now but the deadlock comes from code we added to resolve past CVEs, so needs some thought and it'd be nice not to rush it.

@pimterrypimterry added request-ci Add this label to start a Jenkins CI on a PR. commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. labels Aug 9, 2026
@panvapanva removed the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@panvapanva added the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterrypimterry added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
panva pushed a commit that referenced this pull request Aug 10, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
panva added a commit that referenced this pull request Aug 10, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@panva

Copy link
Copy Markdown
Member

Landed in 780229b...404b0cf

@panvapanva closed this Aug 10, 2026
@panvapanva removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@aduh95

Copy link
Copy Markdown
Contributor

IIUC 64a762b should not be backported as it is based on a semver-major change. If I'm wrong, please open a manual backport PR

@aduh95aduh95 added the backported-to-v26.x PRs backported to the v26.x-staging branch. label Aug 27, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

@aduh95 this can actually be safely backported I think. It fixes a bug (broken stream teardown) that exists independently of the semver-major change (increasing default HTTP/2 window sizes) and shouldn't conflict with anything else I'm aware of.

The bug was effectively invisible with small HTTP/2 windows, but it's still technically present, and users could always manually configure window sizes in the past which would likely trigger this as well, so it's probably reachable in all versions.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.backported-to-v26.xPRs backported to the v26.x-staging branch.c++Issues and PRs that require attention from people who are familiar with C++.commit-queue-rebasePRs the Commit Queue should land as multiple self-contained commits.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@pimterry@nodejs-github-bot@panva@aduh95@mcollina@anonrig
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

stream: fix flaky stream destroy, reachable from HTTP/2 teardown - #65079

Closed
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake
Closed

stream: fix flaky stream destroy, reachable from HTTP/2 teardown#65079
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake

Conversation

@pimterry

Copy link
Copy Markdown
Member

Some of the HTTP/2 tests have become flaky, e.g. nodejs/reliability#1623 shows yesterday:

  • parallel/test-worker-terminate-http2-respond-with-file failed 11 times
  • parallel/test-stream-pipeline-http2 failed 10 times

Best guess is these are both due to the window update PR #64623 (cc @mcollina) since the timing lines up exactly. I think this is really just the window size highlighting existing issues though.

This PR fixes the first issue, which triggers flakes in parallel/test-worker-terminate-http2-respond-with-file. I'll kick off a stress test to confirm, but I can reproduce this locally, and reproduced as resolved with this fix. I'm still working on the 2nd, which only reproduces on Mac and seems a bit more complex.

Actual failure in the 1st test is a crash with pure virtual method called. That fires due to ReadStop within this trace:

Worker::Run → FreeEnvironment
→ Environment::RunCleanup
→ BaseObjectList::Cleanup
→ fs::FileHandle::~FileHandle
→ StreamResource::~StreamResource
→ StreamPipe::ReadableListener::OnStreamDestroy
→ StreamPipe::ReadableListener::OnStreamRead

I.e. during destroy within the destructor chain, we call OnStreamRead, which tries to call stream()->ReadStop inside the sources destructor.

This is only called because OnStreamDestroy manually calls OnStreamRead with an error code to reuse its error/eof teardown logic. We don't need most of that in the destruction scenario (which is only ever called from ~StreamResource, where the stream is already dead).

I've refactored out the relevant bit to split them up (just guarding just fails in the next line, where previous_listener_ is also null). That then exposed two other bugs for the same state, where two other methods that get reached later in this teardown flow also fail to check if the stream is already destroyed - those just need simple guards.

Seems like this is a flaky race because it depends on whether the sink (Http2Stream) or the file handle gets destroyed first by Cleanup().

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels Aug 6, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

cc @nodejs/http2

@codecov

codecovBot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.32%. Comparing base (b33cc0e) to head (da4b684).
⚠️ Report is 81 commits behind head on main.

Files with missing linesPatch %Lines
src/stream_pipe.cc0.00%5 Missing and 2 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65079 +/- ##
==========================================
+ Coverage 90.29% 90.32% +0.03% 
==========================================
Files 759 759 Lines 247598 248458 +860 Branches 46680 46869 +189 ==========================================
+ Hits 223566 224420 +854 + Misses 15503 15448 -55 - Partials 8529 8590 +61 
Files with missing linesCoverage Δ
src/stream_pipe.cc58.71% <0.00%> (-1.47%)⬇️

... and 87 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pimterry

Copy link
Copy Markdown
MemberAuthor

I'll kick off a stress test to confirm

Stress testing inconclusive - the tests passed on both main and this branch, even with multiple runs. They're definitely failing in PRs though. I can reliably reproduce the reported failure locally (that first failure above, it hits for 2-3% of runs) and validate that it's fixed with this change. The trace is where is crashes on my machine with the matching error, and it's clearly a broken flow, so I think this is the right fix regardless.

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

I concur with the analysis

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@panvapanva added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 7, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva

panva commented Aug 7, 2026

Copy link
Copy Markdown
Member

Even with this PR's change I can still fail test-stream-pipeline-http2.js with a timeout 31/1000 times. Without it about 56/1000 times.

This diff that claude spit out to deflake test-stream-pipeline-http2.js makes that 0/1000 with or without this PR, but I don't know enough about this subsystem to say whether that retains the point of the test or not.

diff --git a/test/parallel/test-stream-pipeline-http2.js b/test/parallel/test-stream-pipeline-http2.js
--- a/test/parallel/test-stream-pipeline-http2.js
+++ b/test/parallel/test-stream-pipeline-http2.js
@@ -27,10 +27,11 @@
- let cnt = 10;
+ let received = 0;
req.on('data', (data) => {
- cnt--;
- if (cnt === 0) rs.destroy();
+ received += data.length;
+ // HTTP/2 data event boundaries are non-deterministic.
+ if (received >= 32 * 1024) rs.destroy();
});

@pimterry

Copy link
Copy Markdown
MemberAuthor

Even with this PR's change I can still fail test-stream-pipeline-http2.js

Yes, sorry if the description isn't clear - both failing tests are related to that PR, but this PR only fixes the first of the two. I.e. test-worker-terminate-http2-respond-with-file.

I haven't opened a fix for the second yet, because I think it's actually exposed a real bug that's a bit complicated, and mac-only. Looks like that fix would resolve the test, but from what I can tell so far there's a real underlying deadlock that's reproducible independently, so I want to get a proper fix for that instead. I'll update when I have more info there.

@panva

panva commented Aug 9, 2026

Copy link
Copy Markdown
Member

@pimterry can you land this with the fix/workaround i posted to the remaining flake knowing you'll revisit the underlying deadlock problem and possibly change it again?

This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
@pimterry

Copy link
Copy Markdown
MemberAuthor

Good plan @panva, now done 👍.

I'll open the other fix separately. I've got it working now but the deadlock comes from code we added to resolve past CVEs, so needs some thought and it'd be nice not to rush it.

@pimterrypimterry added request-ci Add this label to start a Jenkins CI on a PR. commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. labels Aug 9, 2026
@panvapanva removed the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@panvapanva added the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterrypimterry added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
panva pushed a commit that referenced this pull request Aug 10, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
panva added a commit that referenced this pull request Aug 10, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@panva

Copy link
Copy Markdown
Member

Landed in 780229b...404b0cf

@panvapanva closed this Aug 10, 2026
@panvapanva removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@aduh95

Copy link
Copy Markdown
Contributor

IIUC 64a762b should not be backported as it is based on a semver-major change. If I'm wrong, please open a manual backport PR

@aduh95aduh95 added the backported-to-v26.x PRs backported to the v26.x-staging branch. label Aug 27, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

@aduh95 this can actually be safely backported I think. It fixes a bug (broken stream teardown) that exists independently of the semver-major change (increasing default HTTP/2 window sizes) and shouldn't conflict with anything else I'm aware of.

The bug was effectively invisible with small HTTP/2 windows, but it's still technically present, and users could always manually configure window sizes in the past which would likely trigger this as well, so it's probably reachable in all versions.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.backported-to-v26.xPRs backported to the v26.x-staging branch.c++Issues and PRs that require attention from people who are familiar with C++.commit-queue-rebasePRs the Commit Queue should land as multiple self-contained commits.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@pimterry@nodejs-github-bot@panva@aduh95@mcollina@anonrig
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

stream: fix flaky stream destroy, reachable from HTTP/2 teardown - #65079

Closed
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake
Closed

stream: fix flaky stream destroy, reachable from HTTP/2 teardown#65079
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake

Conversation

@pimterry

Copy link
Copy Markdown
Member

Some of the HTTP/2 tests have become flaky, e.g. nodejs/reliability#1623 shows yesterday:

  • parallel/test-worker-terminate-http2-respond-with-file failed 11 times
  • parallel/test-stream-pipeline-http2 failed 10 times

Best guess is these are both due to the window update PR #64623 (cc @mcollina) since the timing lines up exactly. I think this is really just the window size highlighting existing issues though.

This PR fixes the first issue, which triggers flakes in parallel/test-worker-terminate-http2-respond-with-file. I'll kick off a stress test to confirm, but I can reproduce this locally, and reproduced as resolved with this fix. I'm still working on the 2nd, which only reproduces on Mac and seems a bit more complex.

Actual failure in the 1st test is a crash with pure virtual method called. That fires due to ReadStop within this trace:

Worker::Run → FreeEnvironment
→ Environment::RunCleanup
→ BaseObjectList::Cleanup
→ fs::FileHandle::~FileHandle
→ StreamResource::~StreamResource
→ StreamPipe::ReadableListener::OnStreamDestroy
→ StreamPipe::ReadableListener::OnStreamRead

I.e. during destroy within the destructor chain, we call OnStreamRead, which tries to call stream()->ReadStop inside the sources destructor.

This is only called because OnStreamDestroy manually calls OnStreamRead with an error code to reuse its error/eof teardown logic. We don't need most of that in the destruction scenario (which is only ever called from ~StreamResource, where the stream is already dead).

I've refactored out the relevant bit to split them up (just guarding just fails in the next line, where previous_listener_ is also null). That then exposed two other bugs for the same state, where two other methods that get reached later in this teardown flow also fail to check if the stream is already destroyed - those just need simple guards.

Seems like this is a flaky race because it depends on whether the sink (Http2Stream) or the file handle gets destroyed first by Cleanup().

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels Aug 6, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

cc @nodejs/http2

@codecov

codecovBot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.32%. Comparing base (b33cc0e) to head (da4b684).
⚠️ Report is 81 commits behind head on main.

Files with missing linesPatch %Lines
src/stream_pipe.cc0.00%5 Missing and 2 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65079 +/- ##
==========================================
+ Coverage 90.29% 90.32% +0.03% 
==========================================
Files 759 759 Lines 247598 248458 +860 Branches 46680 46869 +189 ==========================================
+ Hits 223566 224420 +854 + Misses 15503 15448 -55 - Partials 8529 8590 +61 
Files with missing linesCoverage Δ
src/stream_pipe.cc58.71% <0.00%> (-1.47%)⬇️

... and 87 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pimterry

Copy link
Copy Markdown
MemberAuthor

I'll kick off a stress test to confirm

Stress testing inconclusive - the tests passed on both main and this branch, even with multiple runs. They're definitely failing in PRs though. I can reliably reproduce the reported failure locally (that first failure above, it hits for 2-3% of runs) and validate that it's fixed with this change. The trace is where is crashes on my machine with the matching error, and it's clearly a broken flow, so I think this is the right fix regardless.

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

I concur with the analysis

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@panvapanva added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 7, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva

panva commented Aug 7, 2026

Copy link
Copy Markdown
Member

Even with this PR's change I can still fail test-stream-pipeline-http2.js with a timeout 31/1000 times. Without it about 56/1000 times.

This diff that claude spit out to deflake test-stream-pipeline-http2.js makes that 0/1000 with or without this PR, but I don't know enough about this subsystem to say whether that retains the point of the test or not.

diff --git a/test/parallel/test-stream-pipeline-http2.js b/test/parallel/test-stream-pipeline-http2.js
--- a/test/parallel/test-stream-pipeline-http2.js
+++ b/test/parallel/test-stream-pipeline-http2.js
@@ -27,10 +27,11 @@
- let cnt = 10;
+ let received = 0;
req.on('data', (data) => {
- cnt--;
- if (cnt === 0) rs.destroy();
+ received += data.length;
+ // HTTP/2 data event boundaries are non-deterministic.
+ if (received >= 32 * 1024) rs.destroy();
});

@pimterry

Copy link
Copy Markdown
MemberAuthor

Even with this PR's change I can still fail test-stream-pipeline-http2.js

Yes, sorry if the description isn't clear - both failing tests are related to that PR, but this PR only fixes the first of the two. I.e. test-worker-terminate-http2-respond-with-file.

I haven't opened a fix for the second yet, because I think it's actually exposed a real bug that's a bit complicated, and mac-only. Looks like that fix would resolve the test, but from what I can tell so far there's a real underlying deadlock that's reproducible independently, so I want to get a proper fix for that instead. I'll update when I have more info there.

@panva

panva commented Aug 9, 2026

Copy link
Copy Markdown
Member

@pimterry can you land this with the fix/workaround i posted to the remaining flake knowing you'll revisit the underlying deadlock problem and possibly change it again?

This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
@pimterry

Copy link
Copy Markdown
MemberAuthor

Good plan @panva, now done 👍.

I'll open the other fix separately. I've got it working now but the deadlock comes from code we added to resolve past CVEs, so needs some thought and it'd be nice not to rush it.

@pimterrypimterry added request-ci Add this label to start a Jenkins CI on a PR. commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. labels Aug 9, 2026
@panvapanva removed the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@panvapanva added the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterrypimterry added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
panva pushed a commit that referenced this pull request Aug 10, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
panva added a commit that referenced this pull request Aug 10, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@panva

Copy link
Copy Markdown
Member

Landed in 780229b...404b0cf

@panvapanva closed this Aug 10, 2026
@panvapanva removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@aduh95

Copy link
Copy Markdown
Contributor

IIUC 64a762b should not be backported as it is based on a semver-major change. If I'm wrong, please open a manual backport PR

@aduh95aduh95 added the backported-to-v26.x PRs backported to the v26.x-staging branch. label Aug 27, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

@aduh95 this can actually be safely backported I think. It fixes a bug (broken stream teardown) that exists independently of the semver-major change (increasing default HTTP/2 window sizes) and shouldn't conflict with anything else I'm aware of.

The bug was effectively invisible with small HTTP/2 windows, but it's still technically present, and users could always manually configure window sizes in the past which would likely trigger this as well, so it's probably reachable in all versions.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.backported-to-v26.xPRs backported to the v26.x-staging branch.c++Issues and PRs that require attention from people who are familiar with C++.commit-queue-rebasePRs the Commit Queue should land as multiple self-contained commits.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@pimterry@nodejs-github-bot@panva@aduh95@mcollina@anonrig
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

stream: fix flaky stream destroy, reachable from HTTP/2 teardown - #65079

Closed
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake
Closed

stream: fix flaky stream destroy, reachable from HTTP/2 teardown#65079
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake

Conversation

@pimterry

Copy link
Copy Markdown
Member

Some of the HTTP/2 tests have become flaky, e.g. nodejs/reliability#1623 shows yesterday:

  • parallel/test-worker-terminate-http2-respond-with-file failed 11 times
  • parallel/test-stream-pipeline-http2 failed 10 times

Best guess is these are both due to the window update PR #64623 (cc @mcollina) since the timing lines up exactly. I think this is really just the window size highlighting existing issues though.

This PR fixes the first issue, which triggers flakes in parallel/test-worker-terminate-http2-respond-with-file. I'll kick off a stress test to confirm, but I can reproduce this locally, and reproduced as resolved with this fix. I'm still working on the 2nd, which only reproduces on Mac and seems a bit more complex.

Actual failure in the 1st test is a crash with pure virtual method called. That fires due to ReadStop within this trace:

Worker::Run → FreeEnvironment
→ Environment::RunCleanup
→ BaseObjectList::Cleanup
→ fs::FileHandle::~FileHandle
→ StreamResource::~StreamResource
→ StreamPipe::ReadableListener::OnStreamDestroy
→ StreamPipe::ReadableListener::OnStreamRead

I.e. during destroy within the destructor chain, we call OnStreamRead, which tries to call stream()->ReadStop inside the sources destructor.

This is only called because OnStreamDestroy manually calls OnStreamRead with an error code to reuse its error/eof teardown logic. We don't need most of that in the destruction scenario (which is only ever called from ~StreamResource, where the stream is already dead).

I've refactored out the relevant bit to split them up (just guarding just fails in the next line, where previous_listener_ is also null). That then exposed two other bugs for the same state, where two other methods that get reached later in this teardown flow also fail to check if the stream is already destroyed - those just need simple guards.

Seems like this is a flaky race because it depends on whether the sink (Http2Stream) or the file handle gets destroyed first by Cleanup().

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels Aug 6, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

cc @nodejs/http2

@codecov

codecovBot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.32%. Comparing base (b33cc0e) to head (da4b684).
⚠️ Report is 81 commits behind head on main.

Files with missing linesPatch %Lines
src/stream_pipe.cc0.00%5 Missing and 2 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65079 +/- ##
==========================================
+ Coverage 90.29% 90.32% +0.03% 
==========================================
Files 759 759 Lines 247598 248458 +860 Branches 46680 46869 +189 ==========================================
+ Hits 223566 224420 +854 + Misses 15503 15448 -55 - Partials 8529 8590 +61 
Files with missing linesCoverage Δ
src/stream_pipe.cc58.71% <0.00%> (-1.47%)⬇️

... and 87 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pimterry

Copy link
Copy Markdown
MemberAuthor

I'll kick off a stress test to confirm

Stress testing inconclusive - the tests passed on both main and this branch, even with multiple runs. They're definitely failing in PRs though. I can reliably reproduce the reported failure locally (that first failure above, it hits for 2-3% of runs) and validate that it's fixed with this change. The trace is where is crashes on my machine with the matching error, and it's clearly a broken flow, so I think this is the right fix regardless.

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

I concur with the analysis

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@panvapanva added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 7, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva

panva commented Aug 7, 2026

Copy link
Copy Markdown
Member

Even with this PR's change I can still fail test-stream-pipeline-http2.js with a timeout 31/1000 times. Without it about 56/1000 times.

This diff that claude spit out to deflake test-stream-pipeline-http2.js makes that 0/1000 with or without this PR, but I don't know enough about this subsystem to say whether that retains the point of the test or not.

diff --git a/test/parallel/test-stream-pipeline-http2.js b/test/parallel/test-stream-pipeline-http2.js
--- a/test/parallel/test-stream-pipeline-http2.js
+++ b/test/parallel/test-stream-pipeline-http2.js
@@ -27,10 +27,11 @@
- let cnt = 10;
+ let received = 0;
req.on('data', (data) => {
- cnt--;
- if (cnt === 0) rs.destroy();
+ received += data.length;
+ // HTTP/2 data event boundaries are non-deterministic.
+ if (received >= 32 * 1024) rs.destroy();
});

@pimterry

Copy link
Copy Markdown
MemberAuthor

Even with this PR's change I can still fail test-stream-pipeline-http2.js

Yes, sorry if the description isn't clear - both failing tests are related to that PR, but this PR only fixes the first of the two. I.e. test-worker-terminate-http2-respond-with-file.

I haven't opened a fix for the second yet, because I think it's actually exposed a real bug that's a bit complicated, and mac-only. Looks like that fix would resolve the test, but from what I can tell so far there's a real underlying deadlock that's reproducible independently, so I want to get a proper fix for that instead. I'll update when I have more info there.

@panva

panva commented Aug 9, 2026

Copy link
Copy Markdown
Member

@pimterry can you land this with the fix/workaround i posted to the remaining flake knowing you'll revisit the underlying deadlock problem and possibly change it again?

This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
@pimterry

Copy link
Copy Markdown
MemberAuthor

Good plan @panva, now done 👍.

I'll open the other fix separately. I've got it working now but the deadlock comes from code we added to resolve past CVEs, so needs some thought and it'd be nice not to rush it.

@pimterrypimterry added request-ci Add this label to start a Jenkins CI on a PR. commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. labels Aug 9, 2026
@panvapanva removed the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@panvapanva added the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterrypimterry added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
panva pushed a commit that referenced this pull request Aug 10, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
panva added a commit that referenced this pull request Aug 10, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@panva

Copy link
Copy Markdown
Member

Landed in 780229b...404b0cf

@panvapanva closed this Aug 10, 2026
@panvapanva removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@aduh95

Copy link
Copy Markdown
Contributor

IIUC 64a762b should not be backported as it is based on a semver-major change. If I'm wrong, please open a manual backport PR

@aduh95aduh95 added the backported-to-v26.x PRs backported to the v26.x-staging branch. label Aug 27, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

@aduh95 this can actually be safely backported I think. It fixes a bug (broken stream teardown) that exists independently of the semver-major change (increasing default HTTP/2 window sizes) and shouldn't conflict with anything else I'm aware of.

The bug was effectively invisible with small HTTP/2 windows, but it's still technically present, and users could always manually configure window sizes in the past which would likely trigger this as well, so it's probably reachable in all versions.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.backported-to-v26.xPRs backported to the v26.x-staging branch.c++Issues and PRs that require attention from people who are familiar with C++.commit-queue-rebasePRs the Commit Queue should land as multiple self-contained commits.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@pimterry@nodejs-github-bot@panva@aduh95@mcollina@anonrig
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

stream: fix flaky stream destroy, reachable from HTTP/2 teardown - #65079

Closed
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake
Closed

stream: fix flaky stream destroy, reachable from HTTP/2 teardown#65079
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake

Conversation

@pimterry

Copy link
Copy Markdown
Member

Some of the HTTP/2 tests have become flaky, e.g. nodejs/reliability#1623 shows yesterday:

  • parallel/test-worker-terminate-http2-respond-with-file failed 11 times
  • parallel/test-stream-pipeline-http2 failed 10 times

Best guess is these are both due to the window update PR #64623 (cc @mcollina) since the timing lines up exactly. I think this is really just the window size highlighting existing issues though.

This PR fixes the first issue, which triggers flakes in parallel/test-worker-terminate-http2-respond-with-file. I'll kick off a stress test to confirm, but I can reproduce this locally, and reproduced as resolved with this fix. I'm still working on the 2nd, which only reproduces on Mac and seems a bit more complex.

Actual failure in the 1st test is a crash with pure virtual method called. That fires due to ReadStop within this trace:

Worker::Run → FreeEnvironment
→ Environment::RunCleanup
→ BaseObjectList::Cleanup
→ fs::FileHandle::~FileHandle
→ StreamResource::~StreamResource
→ StreamPipe::ReadableListener::OnStreamDestroy
→ StreamPipe::ReadableListener::OnStreamRead

I.e. during destroy within the destructor chain, we call OnStreamRead, which tries to call stream()->ReadStop inside the sources destructor.

This is only called because OnStreamDestroy manually calls OnStreamRead with an error code to reuse its error/eof teardown logic. We don't need most of that in the destruction scenario (which is only ever called from ~StreamResource, where the stream is already dead).

I've refactored out the relevant bit to split them up (just guarding just fails in the next line, where previous_listener_ is also null). That then exposed two other bugs for the same state, where two other methods that get reached later in this teardown flow also fail to check if the stream is already destroyed - those just need simple guards.

Seems like this is a flaky race because it depends on whether the sink (Http2Stream) or the file handle gets destroyed first by Cleanup().

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels Aug 6, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

cc @nodejs/http2

@codecov

codecovBot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.32%. Comparing base (b33cc0e) to head (da4b684).
⚠️ Report is 81 commits behind head on main.

Files with missing linesPatch %Lines
src/stream_pipe.cc0.00%5 Missing and 2 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65079 +/- ##
==========================================
+ Coverage 90.29% 90.32% +0.03% 
==========================================
Files 759 759 Lines 247598 248458 +860 Branches 46680 46869 +189 ==========================================
+ Hits 223566 224420 +854 + Misses 15503 15448 -55 - Partials 8529 8590 +61 
Files with missing linesCoverage Δ
src/stream_pipe.cc58.71% <0.00%> (-1.47%)⬇️

... and 87 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pimterry

Copy link
Copy Markdown
MemberAuthor

I'll kick off a stress test to confirm

Stress testing inconclusive - the tests passed on both main and this branch, even with multiple runs. They're definitely failing in PRs though. I can reliably reproduce the reported failure locally (that first failure above, it hits for 2-3% of runs) and validate that it's fixed with this change. The trace is where is crashes on my machine with the matching error, and it's clearly a broken flow, so I think this is the right fix regardless.

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

I concur with the analysis

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@panvapanva added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 7, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva

panva commented Aug 7, 2026

Copy link
Copy Markdown
Member

Even with this PR's change I can still fail test-stream-pipeline-http2.js with a timeout 31/1000 times. Without it about 56/1000 times.

This diff that claude spit out to deflake test-stream-pipeline-http2.js makes that 0/1000 with or without this PR, but I don't know enough about this subsystem to say whether that retains the point of the test or not.

diff --git a/test/parallel/test-stream-pipeline-http2.js b/test/parallel/test-stream-pipeline-http2.js
--- a/test/parallel/test-stream-pipeline-http2.js
+++ b/test/parallel/test-stream-pipeline-http2.js
@@ -27,10 +27,11 @@
- let cnt = 10;
+ let received = 0;
req.on('data', (data) => {
- cnt--;
- if (cnt === 0) rs.destroy();
+ received += data.length;
+ // HTTP/2 data event boundaries are non-deterministic.
+ if (received >= 32 * 1024) rs.destroy();
});

@pimterry

Copy link
Copy Markdown
MemberAuthor

Even with this PR's change I can still fail test-stream-pipeline-http2.js

Yes, sorry if the description isn't clear - both failing tests are related to that PR, but this PR only fixes the first of the two. I.e. test-worker-terminate-http2-respond-with-file.

I haven't opened a fix for the second yet, because I think it's actually exposed a real bug that's a bit complicated, and mac-only. Looks like that fix would resolve the test, but from what I can tell so far there's a real underlying deadlock that's reproducible independently, so I want to get a proper fix for that instead. I'll update when I have more info there.

@panva

panva commented Aug 9, 2026

Copy link
Copy Markdown
Member

@pimterry can you land this with the fix/workaround i posted to the remaining flake knowing you'll revisit the underlying deadlock problem and possibly change it again?

This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
@pimterry

Copy link
Copy Markdown
MemberAuthor

Good plan @panva, now done 👍.

I'll open the other fix separately. I've got it working now but the deadlock comes from code we added to resolve past CVEs, so needs some thought and it'd be nice not to rush it.

@pimterrypimterry added request-ci Add this label to start a Jenkins CI on a PR. commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. labels Aug 9, 2026
@panvapanva removed the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@panvapanva added the commit-queue-rebase PRs the Commit Queue should land as multiple self-contained commits. label Aug 9, 2026

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterrypimterry added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
panva pushed a commit that referenced this pull request Aug 10, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
panva added a commit that referenced this pull request Aug 10, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@panva

Copy link
Copy Markdown
Member

Landed in 780229b...404b0cf

@panvapanva closed this Aug 10, 2026
@panvapanva removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 10, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.
Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@aduh95

Copy link
Copy Markdown
Contributor

IIUC 64a762b should not be backported as it is based on a semver-major change. If I'm wrong, please open a manual backport PR

@aduh95aduh95 added the backported-to-v26.x PRs backported to the v26.x-staging branch. label Aug 27, 2026
@pimterry

Copy link
Copy Markdown
MemberAuthor

@aduh95 this can actually be safely backported I think. It fixes a bug (broken stream teardown) that exists independently of the semver-major change (increasing default HTTP/2 window sizes) and shouldn't conflict with anything else I'm aware of.

The bug was effectively invisible with small HTTP/2 windows, but it's still technically present, and users could always manually configure window sizes in the past which would likely trigger this as well, so it's probably reachable in all versions.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.backported-to-v26.xPRs backported to the v26.x-staging branch.c++Issues and PRs that require attention from people who are familiar with C++.commit-queue-rebasePRs the Commit Queue should land as multiple self-contained commits.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@pimterry@nodejs-github-bot@panva@aduh95@mcollina@anonrig