[v26.x backport] http2: avoid uaf while receiving and sending rst_stream - #65264

Merged
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging
Aug 13, 2026
Merged

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream#65264
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging

Conversation

@mcollina

@mcollinamcollina commented Aug 13, 2026

Copy link
Copy Markdown
Member

Backport of #64166 to v26.x-staging.

Original PR: http2: avoid uaf while receiving and sending rst_stream
Fixes:#64113

Backport note

The upstream fix relies on the http2 JS close/destroy refactor from PR #63249 (http2: error for incomplete reads on RST, auto-drain, deprecate aborted), which is semver-major and cannot be backported to a release branch. On v26.x (which lacks that refactor) the C++ backport alone stalls test-http2-many-writes-and-destroy.js (graceful close never completes — the server's GOAWAY is not flushed because the SendPendingData() guard returns busy during nghttp2_session_mem_recv()).

So this backport includes a second commit that drops the send guard. The primary UAF protection (the RST_STREAM / Destroy / Close deferrals) remains intact, and the full http2 suite passes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/http2
  • @nodejs/net

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. http2 Issues and PRs related to the http2 subsystem. needs-ci PRs that need a full CI run. v26.x Issues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch. labels Aug 13, 2026
@aduh95aduh95 changed the title http2: avoid uaf while receiving and sending rst_stream[v26.x backport] http2: avoid uaf while receiving and sending rst_streamAug 13, 2026
@aduh95

aduh95 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

116 tests failed on the FIPS jobs, that's expected and already fixed on the staging branch. Closing and reopening to fix that

@aduh95aduh95 closed this Aug 13, 2026
@aduh95aduh95 reopened this Aug 13, 2026
@codecov

codecovBot commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 75.92593% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.24%. Comparing base (9b55403) to head (ca26282).
⚠️ Report is 149 commits behind head on v26.x-staging.

Files with missing linesPatch %Lines
src/node_http2.cc73.46%6 Missing and 7 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v26.x-staging #65264 +/- ##
=================================================
- Coverage 90.29% 90.24% -0.05% 
=================================================
Files 729 729 Lines 242763 242760 -3 Branches 46920 46044 -876 =================================================
- Hits 219191 219073 -118 - Misses 15024 15133 +109 - Partials 8548 8554 +6 
Files with missing linesCoverage Δ
src/node_http2.h91.86% <100.00%> (ø)
src/node_http2.cc81.87% <73.46%> (+0.09%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: nodejs#64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: nodejs#64166
Backport-PR-URL: nodejs#65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95
aduh95force-pushed the backport-64166-v26.x-staging branch from 9b55403 to ca26282CompareAugust 13, 2026 21:34
@aduh95

Copy link
Copy Markdown
Contributor

Landed in ca26282

@aduh95
aduh95 merged commit ca26282 into nodejs:v26.x-stagingAug 13, 2026
18 checks passed
@juanarbol

Copy link
Copy Markdown
Member

This also fixes in v22.x. Will land this into v22.x-staging

juanarbol pushed a commit that referenced this pull request Aug 21, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@mcollina
mcollina deleted the backport-64166-v26.x-staging branch August 31, 2026 08:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++Issues and PRs that require attention from people who are familiar with C++.http2Issues and PRs related to the http2 subsystem.needs-ciPRs that need a full CI run.v26.xIssues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@mcollina@nodejs-github-bot@aduh95@juanarbol@Eusgor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream - #65264

Merged
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging
Aug 13, 2026
Merged

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream#65264
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging

Conversation

@mcollina

@mcollinamcollina commented Aug 13, 2026

Copy link
Copy Markdown
Member

Backport of #64166 to v26.x-staging.

Original PR: http2: avoid uaf while receiving and sending rst_stream
Fixes:#64113

Backport note

The upstream fix relies on the http2 JS close/destroy refactor from PR #63249 (http2: error for incomplete reads on RST, auto-drain, deprecate aborted), which is semver-major and cannot be backported to a release branch. On v26.x (which lacks that refactor) the C++ backport alone stalls test-http2-many-writes-and-destroy.js (graceful close never completes — the server's GOAWAY is not flushed because the SendPendingData() guard returns busy during nghttp2_session_mem_recv()).

So this backport includes a second commit that drops the send guard. The primary UAF protection (the RST_STREAM / Destroy / Close deferrals) remains intact, and the full http2 suite passes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/http2
  • @nodejs/net

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. http2 Issues and PRs related to the http2 subsystem. needs-ci PRs that need a full CI run. v26.x Issues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch. labels Aug 13, 2026
@aduh95aduh95 changed the title http2: avoid uaf while receiving and sending rst_stream[v26.x backport] http2: avoid uaf while receiving and sending rst_streamAug 13, 2026
@aduh95

aduh95 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

116 tests failed on the FIPS jobs, that's expected and already fixed on the staging branch. Closing and reopening to fix that

@aduh95aduh95 closed this Aug 13, 2026
@aduh95aduh95 reopened this Aug 13, 2026
@codecov

codecovBot commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 75.92593% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.24%. Comparing base (9b55403) to head (ca26282).
⚠️ Report is 149 commits behind head on v26.x-staging.

Files with missing linesPatch %Lines
src/node_http2.cc73.46%6 Missing and 7 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v26.x-staging #65264 +/- ##
=================================================
- Coverage 90.29% 90.24% -0.05% 
=================================================
Files 729 729 Lines 242763 242760 -3 Branches 46920 46044 -876 =================================================
- Hits 219191 219073 -118 - Misses 15024 15133 +109 - Partials 8548 8554 +6 
Files with missing linesCoverage Δ
src/node_http2.h91.86% <100.00%> (ø)
src/node_http2.cc81.87% <73.46%> (+0.09%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: nodejs#64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: nodejs#64166
Backport-PR-URL: nodejs#65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95
aduh95force-pushed the backport-64166-v26.x-staging branch from 9b55403 to ca26282CompareAugust 13, 2026 21:34
@aduh95

Copy link
Copy Markdown
Contributor

Landed in ca26282

@aduh95
aduh95 merged commit ca26282 into nodejs:v26.x-stagingAug 13, 2026
18 checks passed
@juanarbol

Copy link
Copy Markdown
Member

This also fixes in v22.x. Will land this into v22.x-staging

juanarbol pushed a commit that referenced this pull request Aug 21, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@mcollina
mcollina deleted the backport-64166-v26.x-staging branch August 31, 2026 08:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++Issues and PRs that require attention from people who are familiar with C++.http2Issues and PRs related to the http2 subsystem.needs-ciPRs that need a full CI run.v26.xIssues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@mcollina@nodejs-github-bot@aduh95@juanarbol@Eusgor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream - #65264

Merged
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging
Aug 13, 2026
Merged

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream#65264
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging

Conversation

@mcollina

@mcollinamcollina commented Aug 13, 2026

Copy link
Copy Markdown
Member

Backport of #64166 to v26.x-staging.

Original PR: http2: avoid uaf while receiving and sending rst_stream
Fixes:#64113

Backport note

The upstream fix relies on the http2 JS close/destroy refactor from PR #63249 (http2: error for incomplete reads on RST, auto-drain, deprecate aborted), which is semver-major and cannot be backported to a release branch. On v26.x (which lacks that refactor) the C++ backport alone stalls test-http2-many-writes-and-destroy.js (graceful close never completes — the server's GOAWAY is not flushed because the SendPendingData() guard returns busy during nghttp2_session_mem_recv()).

So this backport includes a second commit that drops the send guard. The primary UAF protection (the RST_STREAM / Destroy / Close deferrals) remains intact, and the full http2 suite passes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/http2
  • @nodejs/net

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. http2 Issues and PRs related to the http2 subsystem. needs-ci PRs that need a full CI run. v26.x Issues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch. labels Aug 13, 2026
@aduh95aduh95 changed the title http2: avoid uaf while receiving and sending rst_stream[v26.x backport] http2: avoid uaf while receiving and sending rst_streamAug 13, 2026
@aduh95

aduh95 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

116 tests failed on the FIPS jobs, that's expected and already fixed on the staging branch. Closing and reopening to fix that

@aduh95aduh95 closed this Aug 13, 2026
@aduh95aduh95 reopened this Aug 13, 2026
@codecov

codecovBot commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 75.92593% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.24%. Comparing base (9b55403) to head (ca26282).
⚠️ Report is 149 commits behind head on v26.x-staging.

Files with missing linesPatch %Lines
src/node_http2.cc73.46%6 Missing and 7 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v26.x-staging #65264 +/- ##
=================================================
- Coverage 90.29% 90.24% -0.05% 
=================================================
Files 729 729 Lines 242763 242760 -3 Branches 46920 46044 -876 =================================================
- Hits 219191 219073 -118 - Misses 15024 15133 +109 - Partials 8548 8554 +6 
Files with missing linesCoverage Δ
src/node_http2.h91.86% <100.00%> (ø)
src/node_http2.cc81.87% <73.46%> (+0.09%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: nodejs#64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: nodejs#64166
Backport-PR-URL: nodejs#65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95
aduh95force-pushed the backport-64166-v26.x-staging branch from 9b55403 to ca26282CompareAugust 13, 2026 21:34
@aduh95

Copy link
Copy Markdown
Contributor

Landed in ca26282

@aduh95
aduh95 merged commit ca26282 into nodejs:v26.x-stagingAug 13, 2026
18 checks passed
@juanarbol

Copy link
Copy Markdown
Member

This also fixes in v22.x. Will land this into v22.x-staging

juanarbol pushed a commit that referenced this pull request Aug 21, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@mcollina
mcollina deleted the backport-64166-v26.x-staging branch August 31, 2026 08:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++Issues and PRs that require attention from people who are familiar with C++.http2Issues and PRs related to the http2 subsystem.needs-ciPRs that need a full CI run.v26.xIssues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@mcollina@nodejs-github-bot@aduh95@juanarbol@Eusgor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream - #65264

Merged
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging
Aug 13, 2026
Merged

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream#65264
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging

Conversation

@mcollina

@mcollinamcollina commented Aug 13, 2026

Copy link
Copy Markdown
Member

Backport of #64166 to v26.x-staging.

Original PR: http2: avoid uaf while receiving and sending rst_stream
Fixes:#64113

Backport note

The upstream fix relies on the http2 JS close/destroy refactor from PR #63249 (http2: error for incomplete reads on RST, auto-drain, deprecate aborted), which is semver-major and cannot be backported to a release branch. On v26.x (which lacks that refactor) the C++ backport alone stalls test-http2-many-writes-and-destroy.js (graceful close never completes — the server's GOAWAY is not flushed because the SendPendingData() guard returns busy during nghttp2_session_mem_recv()).

So this backport includes a second commit that drops the send guard. The primary UAF protection (the RST_STREAM / Destroy / Close deferrals) remains intact, and the full http2 suite passes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/http2
  • @nodejs/net

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. http2 Issues and PRs related to the http2 subsystem. needs-ci PRs that need a full CI run. v26.x Issues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch. labels Aug 13, 2026
@aduh95aduh95 changed the title http2: avoid uaf while receiving and sending rst_stream[v26.x backport] http2: avoid uaf while receiving and sending rst_streamAug 13, 2026
@aduh95

aduh95 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

116 tests failed on the FIPS jobs, that's expected and already fixed on the staging branch. Closing and reopening to fix that

@aduh95aduh95 closed this Aug 13, 2026
@aduh95aduh95 reopened this Aug 13, 2026
@codecov

codecovBot commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 75.92593% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.24%. Comparing base (9b55403) to head (ca26282).
⚠️ Report is 149 commits behind head on v26.x-staging.

Files with missing linesPatch %Lines
src/node_http2.cc73.46%6 Missing and 7 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v26.x-staging #65264 +/- ##
=================================================
- Coverage 90.29% 90.24% -0.05% 
=================================================
Files 729 729 Lines 242763 242760 -3 Branches 46920 46044 -876 =================================================
- Hits 219191 219073 -118 - Misses 15024 15133 +109 - Partials 8548 8554 +6 
Files with missing linesCoverage Δ
src/node_http2.h91.86% <100.00%> (ø)
src/node_http2.cc81.87% <73.46%> (+0.09%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: nodejs#64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: nodejs#64166
Backport-PR-URL: nodejs#65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95
aduh95force-pushed the backport-64166-v26.x-staging branch from 9b55403 to ca26282CompareAugust 13, 2026 21:34
@aduh95

Copy link
Copy Markdown
Contributor

Landed in ca26282

@aduh95
aduh95 merged commit ca26282 into nodejs:v26.x-stagingAug 13, 2026
18 checks passed
@juanarbol

Copy link
Copy Markdown
Member

This also fixes in v22.x. Will land this into v22.x-staging

juanarbol pushed a commit that referenced this pull request Aug 21, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@mcollina
mcollina deleted the backport-64166-v26.x-staging branch August 31, 2026 08:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++Issues and PRs that require attention from people who are familiar with C++.http2Issues and PRs related to the http2 subsystem.needs-ciPRs that need a full CI run.v26.xIssues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@mcollina@nodejs-github-bot@aduh95@juanarbol@Eusgor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream - #65264

Merged
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging
Aug 13, 2026
Merged

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream#65264
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging

Conversation

@mcollina

@mcollinamcollina commented Aug 13, 2026

Copy link
Copy Markdown
Member

Backport of #64166 to v26.x-staging.

Original PR: http2: avoid uaf while receiving and sending rst_stream
Fixes:#64113

Backport note

The upstream fix relies on the http2 JS close/destroy refactor from PR #63249 (http2: error for incomplete reads on RST, auto-drain, deprecate aborted), which is semver-major and cannot be backported to a release branch. On v26.x (which lacks that refactor) the C++ backport alone stalls test-http2-many-writes-and-destroy.js (graceful close never completes — the server's GOAWAY is not flushed because the SendPendingData() guard returns busy during nghttp2_session_mem_recv()).

So this backport includes a second commit that drops the send guard. The primary UAF protection (the RST_STREAM / Destroy / Close deferrals) remains intact, and the full http2 suite passes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/http2
  • @nodejs/net

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. http2 Issues and PRs related to the http2 subsystem. needs-ci PRs that need a full CI run. v26.x Issues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch. labels Aug 13, 2026
@aduh95aduh95 changed the title http2: avoid uaf while receiving and sending rst_stream[v26.x backport] http2: avoid uaf while receiving and sending rst_streamAug 13, 2026
@aduh95

aduh95 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

116 tests failed on the FIPS jobs, that's expected and already fixed on the staging branch. Closing and reopening to fix that

@aduh95aduh95 closed this Aug 13, 2026
@aduh95aduh95 reopened this Aug 13, 2026
@codecov

codecovBot commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 75.92593% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.24%. Comparing base (9b55403) to head (ca26282).
⚠️ Report is 149 commits behind head on v26.x-staging.

Files with missing linesPatch %Lines
src/node_http2.cc73.46%6 Missing and 7 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v26.x-staging #65264 +/- ##
=================================================
- Coverage 90.29% 90.24% -0.05% 
=================================================
Files 729 729 Lines 242763 242760 -3 Branches 46920 46044 -876 =================================================
- Hits 219191 219073 -118 - Misses 15024 15133 +109 - Partials 8548 8554 +6 
Files with missing linesCoverage Δ
src/node_http2.h91.86% <100.00%> (ø)
src/node_http2.cc81.87% <73.46%> (+0.09%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: nodejs#64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: nodejs#64166
Backport-PR-URL: nodejs#65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95
aduh95force-pushed the backport-64166-v26.x-staging branch from 9b55403 to ca26282CompareAugust 13, 2026 21:34
@aduh95

Copy link
Copy Markdown
Contributor

Landed in ca26282

@aduh95
aduh95 merged commit ca26282 into nodejs:v26.x-stagingAug 13, 2026
18 checks passed
@juanarbol

Copy link
Copy Markdown
Member

This also fixes in v22.x. Will land this into v22.x-staging

juanarbol pushed a commit that referenced this pull request Aug 21, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@mcollina
mcollina deleted the backport-64166-v26.x-staging branch August 31, 2026 08:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++Issues and PRs that require attention from people who are familiar with C++.http2Issues and PRs related to the http2 subsystem.needs-ciPRs that need a full CI run.v26.xIssues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@mcollina@nodejs-github-bot@aduh95@juanarbol@Eusgor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream - #65264

Merged
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging
Aug 13, 2026
Merged

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream#65264
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging

Conversation

@mcollina

@mcollinamcollina commented Aug 13, 2026

Copy link
Copy Markdown
Member

Backport of #64166 to v26.x-staging.

Original PR: http2: avoid uaf while receiving and sending rst_stream
Fixes:#64113

Backport note

The upstream fix relies on the http2 JS close/destroy refactor from PR #63249 (http2: error for incomplete reads on RST, auto-drain, deprecate aborted), which is semver-major and cannot be backported to a release branch. On v26.x (which lacks that refactor) the C++ backport alone stalls test-http2-many-writes-and-destroy.js (graceful close never completes — the server's GOAWAY is not flushed because the SendPendingData() guard returns busy during nghttp2_session_mem_recv()).

So this backport includes a second commit that drops the send guard. The primary UAF protection (the RST_STREAM / Destroy / Close deferrals) remains intact, and the full http2 suite passes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/http2
  • @nodejs/net

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. http2 Issues and PRs related to the http2 subsystem. needs-ci PRs that need a full CI run. v26.x Issues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch. labels Aug 13, 2026
@aduh95aduh95 changed the title http2: avoid uaf while receiving and sending rst_stream[v26.x backport] http2: avoid uaf while receiving and sending rst_streamAug 13, 2026
@aduh95

aduh95 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

116 tests failed on the FIPS jobs, that's expected and already fixed on the staging branch. Closing and reopening to fix that

@aduh95aduh95 closed this Aug 13, 2026
@aduh95aduh95 reopened this Aug 13, 2026
@codecov

codecovBot commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 75.92593% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.24%. Comparing base (9b55403) to head (ca26282).
⚠️ Report is 149 commits behind head on v26.x-staging.

Files with missing linesPatch %Lines
src/node_http2.cc73.46%6 Missing and 7 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v26.x-staging #65264 +/- ##
=================================================
- Coverage 90.29% 90.24% -0.05% 
=================================================
Files 729 729 Lines 242763 242760 -3 Branches 46920 46044 -876 =================================================
- Hits 219191 219073 -118 - Misses 15024 15133 +109 - Partials 8548 8554 +6 
Files with missing linesCoverage Δ
src/node_http2.h91.86% <100.00%> (ø)
src/node_http2.cc81.87% <73.46%> (+0.09%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: nodejs#64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: nodejs#64166
Backport-PR-URL: nodejs#65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95
aduh95force-pushed the backport-64166-v26.x-staging branch from 9b55403 to ca26282CompareAugust 13, 2026 21:34
@aduh95

Copy link
Copy Markdown
Contributor

Landed in ca26282

@aduh95
aduh95 merged commit ca26282 into nodejs:v26.x-stagingAug 13, 2026
18 checks passed
@juanarbol

Copy link
Copy Markdown
Member

This also fixes in v22.x. Will land this into v22.x-staging

juanarbol pushed a commit that referenced this pull request Aug 21, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@mcollina
mcollina deleted the backport-64166-v26.x-staging branch August 31, 2026 08:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++Issues and PRs that require attention from people who are familiar with C++.http2Issues and PRs related to the http2 subsystem.needs-ciPRs that need a full CI run.v26.xIssues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@mcollina@nodejs-github-bot@aduh95@juanarbol@Eusgor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream - #65264

Merged
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging
Aug 13, 2026
Merged

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream#65264
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging

Conversation

@mcollina

@mcollinamcollina commented Aug 13, 2026

Copy link
Copy Markdown
Member

Backport of #64166 to v26.x-staging.

Original PR: http2: avoid uaf while receiving and sending rst_stream
Fixes:#64113

Backport note

The upstream fix relies on the http2 JS close/destroy refactor from PR #63249 (http2: error for incomplete reads on RST, auto-drain, deprecate aborted), which is semver-major and cannot be backported to a release branch. On v26.x (which lacks that refactor) the C++ backport alone stalls test-http2-many-writes-and-destroy.js (graceful close never completes — the server's GOAWAY is not flushed because the SendPendingData() guard returns busy during nghttp2_session_mem_recv()).

So this backport includes a second commit that drops the send guard. The primary UAF protection (the RST_STREAM / Destroy / Close deferrals) remains intact, and the full http2 suite passes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/http2
  • @nodejs/net

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. http2 Issues and PRs related to the http2 subsystem. needs-ci PRs that need a full CI run. v26.x Issues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch. labels Aug 13, 2026
@aduh95aduh95 changed the title http2: avoid uaf while receiving and sending rst_stream[v26.x backport] http2: avoid uaf while receiving and sending rst_streamAug 13, 2026
@aduh95

aduh95 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

116 tests failed on the FIPS jobs, that's expected and already fixed on the staging branch. Closing and reopening to fix that

@aduh95aduh95 closed this Aug 13, 2026
@aduh95aduh95 reopened this Aug 13, 2026
@codecov

codecovBot commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 75.92593% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.24%. Comparing base (9b55403) to head (ca26282).
⚠️ Report is 149 commits behind head on v26.x-staging.

Files with missing linesPatch %Lines
src/node_http2.cc73.46%6 Missing and 7 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v26.x-staging #65264 +/- ##
=================================================
- Coverage 90.29% 90.24% -0.05% 
=================================================
Files 729 729 Lines 242763 242760 -3 Branches 46920 46044 -876 =================================================
- Hits 219191 219073 -118 - Misses 15024 15133 +109 - Partials 8548 8554 +6 
Files with missing linesCoverage Δ
src/node_http2.h91.86% <100.00%> (ø)
src/node_http2.cc81.87% <73.46%> (+0.09%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: nodejs#64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: nodejs#64166
Backport-PR-URL: nodejs#65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95
aduh95force-pushed the backport-64166-v26.x-staging branch from 9b55403 to ca26282CompareAugust 13, 2026 21:34
@aduh95

Copy link
Copy Markdown
Contributor

Landed in ca26282

@aduh95
aduh95 merged commit ca26282 into nodejs:v26.x-stagingAug 13, 2026
18 checks passed
@juanarbol

Copy link
Copy Markdown
Member

This also fixes in v22.x. Will land this into v22.x-staging

juanarbol pushed a commit that referenced this pull request Aug 21, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@mcollina
mcollina deleted the backport-64166-v26.x-staging branch August 31, 2026 08:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++Issues and PRs that require attention from people who are familiar with C++.http2Issues and PRs related to the http2 subsystem.needs-ciPRs that need a full CI run.v26.xIssues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@mcollina@nodejs-github-bot@aduh95@juanarbol@Eusgor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream - #65264

Merged
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging
Aug 13, 2026
Merged

[v26.x backport] http2: avoid uaf while receiving and sending rst_stream#65264
aduh95 merged 1 commit into
nodejs:v26.x-stagingfrom
mcollina:backport-64166-v26.x-staging

Conversation

@mcollina

@mcollinamcollina commented Aug 13, 2026

Copy link
Copy Markdown
Member

Backport of #64166 to v26.x-staging.

Original PR: http2: avoid uaf while receiving and sending rst_stream
Fixes:#64113

Backport note

The upstream fix relies on the http2 JS close/destroy refactor from PR #63249 (http2: error for incomplete reads on RST, auto-drain, deprecate aborted), which is semver-major and cannot be backported to a release branch. On v26.x (which lacks that refactor) the C++ backport alone stalls test-http2-many-writes-and-destroy.js (graceful close never completes — the server's GOAWAY is not flushed because the SendPendingData() guard returns busy during nghttp2_session_mem_recv()).

So this backport includes a second commit that drops the send guard. The primary UAF protection (the RST_STREAM / Destroy / Close deferrals) remains intact, and the full http2 suite passes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/http2
  • @nodejs/net

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. http2 Issues and PRs related to the http2 subsystem. needs-ci PRs that need a full CI run. v26.x Issues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch. labels Aug 13, 2026
@aduh95aduh95 changed the title http2: avoid uaf while receiving and sending rst_stream[v26.x backport] http2: avoid uaf while receiving and sending rst_streamAug 13, 2026
@aduh95

aduh95 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

116 tests failed on the FIPS jobs, that's expected and already fixed on the staging branch. Closing and reopening to fix that

@aduh95aduh95 closed this Aug 13, 2026
@aduh95aduh95 reopened this Aug 13, 2026
@codecov

codecovBot commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 75.92593% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.24%. Comparing base (9b55403) to head (ca26282).
⚠️ Report is 149 commits behind head on v26.x-staging.

Files with missing linesPatch %Lines
src/node_http2.cc73.46%6 Missing and 7 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v26.x-staging #65264 +/- ##
=================================================
- Coverage 90.29% 90.24% -0.05% 
=================================================
Files 729 729 Lines 242763 242760 -3 Branches 46920 46044 -876 =================================================
- Hits 219191 219073 -118 - Misses 15024 15133 +109 - Partials 8548 8554 +6 
Files with missing linesCoverage Δ
src/node_http2.h91.86% <100.00%> (ø)
src/node_http2.cc81.87% <73.46%> (+0.09%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 13, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: nodejs#64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: nodejs#64166
Backport-PR-URL: nodejs#65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95
aduh95force-pushed the backport-64166-v26.x-staging branch from 9b55403 to ca26282CompareAugust 13, 2026 21:34
@aduh95

Copy link
Copy Markdown
Contributor

Landed in ca26282

@aduh95
aduh95 merged commit ca26282 into nodejs:v26.x-stagingAug 13, 2026
18 checks passed
@juanarbol

Copy link
Copy Markdown
Member

This also fixes in v22.x. Will land this into v22.x-staging

juanarbol pushed a commit that referenced this pull request Aug 21, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Mark the session as receiving around nghttp2_session_mem_recv() and
defer RST_STREAM handling while receive is in progress. This prevents
closing a stream while nghttp2 still processes it and avoids
heap-use-after-free in nghttp2_session_mem_recv2().
Fixes: #64113
Signed-off-by: Evgeniy Gorbanev <gorbanev.es@gmail.com>
PR-URL: #64166
Backport-PR-URL: #65264
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@mcollina
mcollina deleted the backport-64166-v26.x-staging branch August 31, 2026 08:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++Issues and PRs that require attention from people who are familiar with C++.http2Issues and PRs related to the http2 subsystem.needs-ciPRs that need a full CI run.v26.xIssues that can be reproduced on v26.x or PRs targeting the v26.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@mcollina@nodejs-github-bot@aduh95@juanarbol@Eusgor