Skip to content

[pull] v1.x from libuv:v1.x - #190

Open
pull[bot] wants to merge 995 commits into
bazelregistry:v1.xfrom
libuv:v1.x
Open

pull[bot] wants to merge 995 commits into
bazelregistry:v1.xfrom
libuv:v1.x

Conversation

@pull

@pull pull Bot commented Apr 28, 2021 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

bnoordhuis and others added 27 commits July 6, 2025 16:19
uv_set_process_title loads and unloads a bunch of dynamic libraries,
and that's quite slow and prone to time out when running concurrently
under AddressSanitizer.
Commit 7fb43d3 from August 2012 moved uv__atomic_exchange_set from
async.c into a header file but in all those years, nothing except
async.c has ever used it. Move the function back again and remove
the header file.

I removed the superfluous uses of inline/INLINE but this is otherwise
a non-functional change.

Refs: #4819
Large-ish functions with many call sites in different translation units
should not be `static inline`, that just results in lots of code
duplication which the linker may or may not deduplicate. When it does,
the linker has to do extra work; when it doesn't, binaries get bigger.

Refs: #4819
Switch to __sync_fetch_and_or on x86. Libuv already uses it on other
architectures.
Starting a new read after uv_read_cb returns causes memory corruption on
the OVERLAPPED read_req if uv_read_stop+uv_read_start was called during
the callback after the latest refactoring. This apparently also forces
the kernel to deadlock us, since it apparently cannot cancel the second
read while the first one is pending (reads apparently are not permitted
to finish out of order). Avoid that simply by not issuing another read
(set more=0) if there is already a read pending (from uv_read_start).

There are probably better things we could do here (such as bring back
`uv_active_tcp_streams_threshold`), but the current `alloc_cb` design
may not currently permit that without making breaking changes. We could
also detect in `uv_read_start` that we are inside of of the `read_cb`
for that stream, and defer the actual zero-read until the read_cb
returns, but that would likely be a larger change.

Fix #4738
I was testing a static analyzer on libuv's code, and it could not
understand the use of a constant variable in the condition as an assert
branch. This simplifies the code for easier static analysis. I also
removed the explicit casts, relying instead on C's casting rules to
catch some misuse.
Fixes: #4838
Co-authored-by: maxim <maxim@wiselydone.com>
Wine has a bug (https://bugs.winehq.org/show_bug.cgi?id=50771) where
FILE_WRITE_ATTRIBUTES will cause CreateFile to fail if the file is
read-only. The recommended work around is to instead use
FILE_DISPOSITION_IGNORE_READONLY_ATTRIBUTE, which we do as of #4318.
However, we were still using FILE_WRITE_ATTRIBUTES to create the
initial handle, despite this no longer being required, except for
the fallback path. As a result, libuv is still broken under wine,
even on master. Fix this by removing the `FILE_WRITE_ATTRIBUTES`
from the initial CreateFile call and re-opening the handle in the
fallback path if necessary. Note that we still have the same issue
in fs_chmod and I've requested some guidance from wine on what
to do about this, but this should at least fix unlink.

Refs: JuliaLang/julia#58980
It was incorrectly documented as returning void since its addition, but it
returns int.
Fix a logic bug in the fallback code for platforms that don't have a
sendmmsg-like system call. It only sent at most one packet, even when
there were more available, and that was observable through a failing
test on such systems.

Fixes: #4848
This apparently manifests when one passes `--cpu=.5` to docker because
then /sys/fs/cgroup/cpu.max looks like `50000 100000`, and 50000 divided
by 100000 is zero when using integer math.

Return 1 in that case, indicating there is at least one CPU available.
Returning 0 makes no sense because there is always at least one CPU
available, otherwise the program wouldn't be running.

Fixes: nodejs/node#59200
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 5.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v5)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
The original repository was deleted and the URL is now owned by someone
else.

Refs: https://hackerone.com/bugs?report_id=3295855
This fixes the test suite in environments where `/tmp` is not writable
or does not allow the use of Unix sockets, and matches the use of
relative paths elsewhere in the tests.
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 5.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v5)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
The AArch64 YIELD instruction affects processors that support
symmetric multithreading, while on other implementations (which
are the majority on the market) it is equivalent to NOP, thus
failing to achieve the desired delay effect inside uv__async_spin().
Instead, use the ISB instruction, following one of Arm's
recommendations [1].

[1] https://community.arm.com/arm-community-blogs/b/architectures-and-processors-blog/posts/multi-threaded-applications-arm

Signed-off-by: Anton Kirilov <anton.kirilov@arm.com>
Rationale for changing it to an enum:

- frees up some bits that can be used for other things
- is potentially faster (direct vs. indirect call)
- is potentially more secure (makes UAF or overruns harder to exploit,
  no arbitrary function pointer to clobber)

Fixes: #4842
bnoordhuis and others added 30 commits September 15, 2026 17:23
Commit 8749360 ("unix: drain tty reads on POLLHUP without POLLIN")
from a few days ago fixed the failure but now it sometimes times out.
Lower the number of iterations from 1,000 to 50.

Fixes: #5247
FreeBSD defines SOCK_MAXADDRLEN but clamps Unix socket paths to the
size of sockaddr_un.sun_path.

Fixes: #5134
Co-authored-by: Ben Noordhuis <info@bnoordhuis.nl>
OpenBSD has added a getexecpath() API to be able
to retrieve the executable and path.
Bumps [vmactions/freebsd-vm](https://github.com/vmactions/freebsd-vm) from 1.5.6 to 1.5.7.
- [Release notes](https://github.com/vmactions/freebsd-vm/releases)
- [Commits](vmactions/freebsd-vm@8b0f1a8...4469451)

---
updated-dependencies:
- dependency-name: vmactions/freebsd-vm
  dependency-version: 1.5.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Treat an explicit stack size as the reservation size on Windows.

This matches Unix semantics and lets Windows commit stack pages on demand.
Changes since version 1.52.1:

* unix: fix pedantic compiler warnings (Ben Noordhuis)

* win: fix const correctness compiler error (apocelipes)

* doc: clarify handle close behavior of uv_spawn (Ben Noordhuis)

* doc: name function crosslinks consistently (Ben Noordhuis)

* win: fix const correctness warning (Ben Noordhuis)

* win: fix off-by-one in utf-16 to wtf-8 conversion (locus-x64)

* udp: validate nbufs in send functions (Oren)

* unix: improve handling of uv_async_send mistakes (Jameson Nash)

* unix,stream: verify uv_try_write2 handle (cui)

* test,win: fix race in test runner (Jameson Nash)

* unix,tty: don't drain when setting the TTY mode (Gabriel Baraldi)

* inet: prefer sizeof with parenthesis (Juan José Arboleda)

* test: remove unused headers and use newer ASSERT macros (Juan José
  Arboleda)

* doc: Add textual images into libuv man page (Stacey Marshall)

* darwin: replace EV_OOBAND handling with EVFILT_EXCEPT + NOTE_OOB (Juan
  José Arboleda)

* docs: add copybutton sphinx extension (HArsil)

* doc: fix threading bugs in progress example (PRANAV KUMAR)

* unix: support long path names in pipe.c (Edigleysson Silva (Edy))

* win: fix some compiler warnings (Benjamin Gilbert)

* docs: fix broken and redirected links (Jameson Nash)

* doc: remove random reference to libev (Ben Noordhuis)

* process: better validation for process->pid usage (Jameson Nash)

* unix: check return value of fcntl call (Ben Noordhuis)

* test: fix -Wunused-function warning (Ben Noordhuis)

* linux: close streams without an extra read (Jameson Nash)

* unix: enforce recvmmsg buffer size requirements (Ben Noordhuis)

* android: fix termux build (BarryLhm)

* io: make libuv 64-bit safe (Jameson Nash)

* win,pipe: skip IOCP for pipe handles (Jameson Nash)

* win: use WSA_FLAG_NO_HANDLE_INHERIT in all WSASocketW (Jameson Nash)

* unix: use posix_spawn instead of fork (Jameson Nash)

* test: use correct type for uv_fileno arguments (Saúl Ibarra Corretgé)

* misc: revise security vulnerability reporting instructions (Jameson
  Nash)

* win: fix watch loop logic (Stefan Stojanovic)

* win: properly initialize OSVERSIONINFOW (Santiago Gimeno)

* misc: fix error code returned from uv_wtf8_length_as_utf16 (Ryan
  Liptak)

* stream: fix server stop accepting after uv_accept() error (ivinx)

* unix,ibmi: abort on process_title_mutex init failure (Juan José
  Arboleda)

* unix,stream: fix getsockopt error handling in connect (Juan José
  Arboleda)

* unix: treat futimens() as best-effort in copyfile (skooch)

* unix: free statxbuf on iouring statx fallback (Santiago Gimeno)

* aix,ibmi: fix undeclared identifiers (SRAVANI GUNDEPALLI)

* unix: fix uv__udp_recvmsg crash (theanarkh)

* win: use PROC_THREAD_ATTRIBUTE_HANDLE_LIST in uv_spawn (Jameson Nash)

* unix: avoid duplicate recvmmsg terminal callback (Isaac Elbaz)

* win: fix spawn process with no argument (sturcotte06)

* unix: handle cloexec failure in kqueue init (Juan José Arboleda)

* unix: remove UV_HANDLE_READING flag (Edigleysson Silva (Edy))

* src: use INET6_ADDRSTRLEN for IPv6 address buffer (orbisai0security)

* test: include pty.h for GNU Hurd (Jérémy Lal)

* test: skip recvmsg unreachable test when no ipv6 (Santiago Gimeno)

* win: fix race condition in uv_async_send (Jameson Nash)

* unix,fs: fix busyloop in big copyfile (Jameson Nash)

* process,unix: avoid off-by-one in uv__spawn_resolve_and_spawn (Jameson
  Nash)

* test: check that sizeof is constant (Jameson Nash)

* async: make seq_cst the default (Jameson Nash)

* Reland "linux: eliminate a read on eventfd per wakeup" (Jameson Nash)

* win,process: skip dump silently if no valid folder can be determined
  (Jameson Nash)

* win: handle short path mismatch with a fallback in fs events (Joyee
  Cheung)

* unix,udp: handle msg_hdr.msg_namelen=0 on recvmmsg (Santiago Gimeno)

* ci: lock down permissions and pin action SHAs (Alb3e3)

* docs: ignore unstable ncurses linkcheck URL (Alb3e3)

* unix: handle EINTR in uv_resident_set_memory (Nandan Acharya)

* build(deps): bump reactivecircus/android-emulator-runner
  (dependabot[bot])

* build(deps): bump actions/setup-python from 6.2.0 to 6.3.0
  (dependabot[bot])

* unix: return EINVAL for invalid tty modes (Samuel Williams)

* ci: use VS 18 / 2026 in Windows Server 2025 (Saúl Ibarra Corretgé)

* win: fix use of wrong constant in tcp code (Ben Noordhuis)

* unix: fix UV_FS_O_DIRECT on more linux architectures (Archkon)

* doc: add UB warning to threading documentation (Ben Noordhuis)

* build(deps): bump reactivecircus/android-emulator-runner
  (dependabot[bot])

* sunos: use getrandom(2) for uv_random (Petr Sumbera)

* unix,poll: fix callback event bits on error/hangup (Yuki Ibe)

* haiku: build tests with libbsd (Jérôme Duval)

* unix: fix static declaration in nested block for AIX and IBM i PASE
  (sravani1510)

* win: fix unique named pipes to work inside Windows AppContainer (Russ
  Cox)

* build(deps): bump actions/setup-python from 6.3.0 to 7.0.0
  (dependabot[bot])

* build(deps): bump actions/checkout from 6.0.3 to 7.0.0
  (dependabot[bot])

* stream: Implement cancellation support for uv_write_t (Keno Fischer)

* unix: handle trailing empty write buffers (Alb3e3)

* stream: handle cancel write after close (Tyler Gibbs)

* build(deps): bump actions/checkout from 7.0.0 to 7.0.1
  (dependabot[bot])

* test: don't generate io_uring variants of loopless fs tests (Jameson
  Nash)

* test: close the loop in udp_recvmsg_unreachable_error{,6} (Jameson
  Nash)

* linux: use scaling_max_freq in uv_cpu_info() (James Ross)

* win: fix leak if uv_loop_init fails (Jameson Nash)

* solaris: fix build and test failures, add CI (Petr Sumbera)

* test: improve fs event filename assertion (Petr Sumbera)

* build(deps): bump vmactions/solaris-vm from 1.3.7 to 1.3.8
  (dependabot[bot])

* build(deps): bump actions/checkout from 6.0.3 to 7.0.1
  (dependabot[bot])

* win: fix crash when closing a pipe after a failed bind (Yury
  Semikhatsky)

* darwin: report physical footprint as rss (Jarred Sumner)

* test: close file descriptors leaked by tests (Jameson Nash)

* unix: short-circuit no-op event mask changes in uv__io_stop (Shelley
  Vohr)

* unix,process: never shrink the stdio socket pair buffers (Shelley
  Vohr)

* build(deps): bump vmactions/solaris-vm from 1.3.8 to 1.3.9
  (dependabot[bot])

* linux: fix tcc build (Ben Noordhuis)

* aix: canonicalize fs event path with realpath() (Milad Fa)

* openbsd: use fork instead of posix_spawn (Ben Noordhuis)

* freebsd,netbsd,openbsd: add build CI (neil)

* win,fs: suppress CRT assertion on close (Yiğit Tanrıverdi)

* unix: drain tty reads on POLLHUP without POLLIN (Santiago Gimeno)

* doc: fix on guide filesystem.rst (Viacheslav Muravyev)

* linux: support cancelling io_uring file requests (hunterinvariants)

* build: distribute Windows long path manifest (Yiğit Tanrıverdi)

* netbsd: free cpu times on sysctl failure (cui fliter)

* build(deps): bump vmactions/netbsd-vm from 1.4.8 to 1.4.9
  (dependabot[bot])

* freebsd: don't fail uv_cpu_info() when hw.clockrate is missing (Piotr
  Kubaj)

* build(deps): bump vmactions/netbsd-vm from 1.4.9 to 1.5.0
  (dependabot[bot])

* build(deps): bump vmactions/solaris-vm from 1.3.9 to 1.4.0
  (dependabot[bot])

* build(deps): bump vmactions/freebsd-vm from 1.5.5 to 1.5.6
  (dependabot[bot])

* unix: fix warning in OpenBSD code (Brad Smith)

* test: lower number of iterations (Ben Noordhuis)

* openbsd: update EVFILT_USER comment (Brad Smith)

* freebsd: don't use long AF_UNIX socket paths (Juan José Arboleda)

* openbsd: use getexecpath in uv_exepath if present (Brad Smith)

* build(deps): bump vmactions/freebsd-vm from 1.5.6 to 1.5.7
  (dependabot[bot])

* win: reserve explicit thread stack size (Zuohui Yang)
Signed-off-by: Santiago Gimeno <santiago.gimeno@gmail.com>
alloc_cb runs while the handle is still in the middle of
dispatching a read/recv. Calling uv_read_stop, uv_udp_recv_stop,
or uv_close from within it is not supported: libuv may still
invoke the handle's read/recv callback right after alloc_cb
returns (e.g. with UV_ENOBUFS on a zero-length buffer), and that
callback may have already been cleared by the stop/close call.

This came up while investigating a crash triggered by calling
uv_udp_recv_stop() from inside alloc_cb after rejecting a buffer.
Maintainers confirmed this usage pattern is unsupported rather
than a bug, so documenting it explicitly here.
Fixes: #4183

Signed-off-by: Kirill Saied <sayed.kirill@gmail.com>
`uv__poll_close(`) cancelled the outstanding AFD poll requests by
submitting one more, exclusive, poll request, whose only purpose was the
side effect of making the others return. That request was issued with a
process-wide `OVERLAPPED` and `AFD_POLL_INFO` and with its event tagged
so that no completion would be reported, which means nothing ever
observed it finish. Two sockets closing at once had the kernel writing
the same `IO_STATUS_BLOCK` and the same output buffer, and because no
one could know when the last such request had completed, neither buffer
could ever be released.

`CancelIoEx()` has been available since Vista and does this directly.
Cancel each request by its own overlapped rather than everything on the
socket, since peer sockets are shared between poll handles, and name the
peer socket rather than the watched one, because that is where the
request was issued; the watched socket only ever appears in the poll
info. The requests come back with `handle->events` already zero, so
`uv__fast_poll_process_poll_req()` reports nothing and the handle
proceeds to its endgame, exactly as before.

This leaves `uv__msafd_poll()` with no caller that tags hEvent and none
that asks for a blocking poll, so both of those paths are dead.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
`ASSERT_OK(0)` asserts that zero is zero, so it never fires: a `NAN`
reaching the `atime`/`mtime` fallthrough in `check_utime_ex()` was
silently accepted.

Dates from 85b526f, which split the
single combined atime/mtime branch in two and added these fallthroughs.

Assisted-by: Claude Opus 5
Since the busy counter was folded into the pending field, the counter
decrement in uv_async_send() and the poll in uv__async_spin() are
relaxed. uv__async_spin() still waits for the sender but no longer
synchronizes with it according to C11 — the ordering for the sender's
write to the wakeup fd before uv__async_stop() closes it is hidden
inside the kernel, and typically not modeled by user-tooling. The old
seq_cst busy flag provided that edge. For example, ThreadSanitizer
reports this as a race between close() in uv__async_stop() and write()
in uv__async_send() when a foreign thread uses an async handle to
trigger loop teardown.

Make the decrement a release and the poll an acquire.

Fixes: #5297
Refs: #5079
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
handle->recv_cb can become NULL if alloc_cb stops or closes the
handle before returning (unsupported usage, but cheap to guard
against — see docs/src/handle.rst). Mirrors the existing
handle->recv_cb != NULL guard added to the POLLERR path in
uv__udp_io() by commit cafbb1a (#5131).
Co-authored-by: gengjiawen <technicalcute@gmail.com>
Cache the result of RtlGetVersion because the Windows version cannot
change during the process lifetime. Abort on an unexpected status
instead of reading potentially invalid output.
Refs: nodejs/node#61397

Signed-off-by: PickBas <sayed.kirill@gmail.com>
The Darwin select fallback keeps the original stream descriptor in
`s->fd` while the I/O watcher uses a socketpair. Stream cleanup joins
the selector thread and closes the socketpair, but did not close that
original descriptor.
uv_fs_event_start() opens the path with FILE_LIST_DIRECTORY to tell
files and directories apart. On a file that is FILE_READ_DATA, so the
open takes part in the sharing check and fails with
ERROR_SHARING_VIOLATION when some other process has the file open
without FILE_SHARE_READ: a compiler emitting an object file, an
installer, a virus scanner. Up to 1.51.0 the type was determined with
GetFileAttributesW(), which never opened the path, so watching such a
file used to work.

Probe the type with FILE_READ_ATTRIBUTES instead. It is all that
GetFileInformationByHandle() needs and it stays out of the sharing
check. Then open what is actually watched, the path itself when it is a
directory and its parent otherwise, and check the type of that handle
too.

Metadata still never comes from a path lookup, so the race fixed in
#4948 stays fixed, and the directory case gains the same post-open check
the file case already had.

The file branch still opens the parent by name and keeps its post-open
directory check; Win32 has no relative open short of NtCreateFile.

Fixes: #5270
Co-authored-by: Jameson Nash <vtjnash@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This reverts commit cc6d059
due to failing CI (mea culpa).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.