$ the-wire · showcase
undici 8.11.0 lands HTTP/2 length checks and WebSocket fixes
By RepoJournal · Filed · About Node.js · Composed from the cited sources · methodology
undici validated the tail of its HTTP/2 and WebSocket paths while Node core closed a recursive child-spawning bug in watch mode.
fix(h2): validate response content-length nodejs/undici
The HTTP/2 client now checks a response's Content-Length against the DATA bytes it actually receives, so truncated and oversized bodies fail with the existing response length mismatch error instead of arriving wrong. HEAD and 304 semantics are preserved, and fetch regression tests cover mismatches plus session reuse.
fix(websocket): reset the compressed flag when a message completes nodejs/undici
ByteParser never cleared #info.compressed after delivering a permessage-deflate message, so the continuation-frame guard in lib/web/websocket/receiver.js was skipped after any compressed message and a stray continuation frame was decompressed and delivered. Resetting the flag on message completion closes that path.
watch: strip watch flags from NODE_OPTIONS in child process nodejs/node
NODE_OPTIONS containing --watch made the watch parent spawn a child that inherited the same NODE_OPTIONS, entering watch mode itself and spawning another child in an infinite chain. The parent now strips --watch, --watch-path, --watch-preserve-output, and --watch-kill-signal from the child environment.
fix(h2): keep queued requests alive when the last stream closes nodejs/undici
closeStreamSession unrefs the session when the last stream closes even while requests are still queued, leaving no handle to keep the event loop alive; this follows the earlier fix to resumeH2 for peers advertising SETTINGS_MAX_CONCURRENT_STREAMS = 0. If you queue HTTP/2 requests through undici, stalled sessions are the thing to watch.
v8.11.0 nodejs/undici
by github-actions[bot]
The 8.11.0 release collects the HTTP/2, decompress, cookie, and upgrade-diagnostics work above into a tagged version, with a repeated content-encoding header now joined and a cookie named __proto__ kept by getCookies. The long tail was routine: a jest dev bump to 30.5.2, a WebCryptoAPI WPT sync, and two test deflakes from panva that fix a 1/256 buffer collision in test-benchmark-crypto and lost...