Skip to content

Commit 589098d

Browse files
deps: update undici to 8.11.2
1 parent 14e8f5b commit 589098d

54 files changed

Lines changed: 2111 additions & 1294 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎deps/undici/src/README.md‎

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -378,7 +378,16 @@ The `body` mixins are the most common way to format the request/response body. M
378378
> The body returned from `undici.request` does not implement `.formData()`.
379379
380380
> [!WARNING]
381-
> Calling `body.formData()` on a fetch response causes undici to buffer and parse the entire body. Since this is dictated by the spec, `body.formData()` must only be called on responses from trusted servers.
381+
> The body mixins `.arrayBuffer()`, `.blob()`, `.bytes()`, `.json()`, `.text()`,
382+
> and `.formData()` buffer the entire body in memory before returning. Where
383+
> applicable, they also decode or parse the payload and retain that
384+
> representation in memory. Calling these methods therefore means trusting that
385+
> the response body is small enough to fit in the available memory. Do not use
386+
> them for responses from untrusted or user-controlled sources. Instead, consume
387+
> the response body as a stream and enforce an application-specific size limit:
388+
> use `response.body` for fetch responses or the `body` returned by
389+
> `undici.request()`. For streaming decoded text, use `body.textStream()` on a
390+
> fetch `Request` or `Response`.
382391
383392
Example usage:
384393

‎deps/undici/src/SECURITY.md‎

Lines changed: 20 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -153,16 +153,26 @@ lead to a loss of confidentiality, integrity, or availability.
153153
resources, that is not considered a vulnerability. Applications are
154154
responsible for setting appropriate limits on response sizes.
155155

156-
#### Calling `body.formData()` on untrusted responses
157-
158-
* `body.formData()` buffers and parses the entire response body. Multipart
159-
parsing has inherent security risks, especially when the body is supplied by
160-
an untrusted or user-controlled server. Applications must only call
161-
`body.formData()` on responses from trusted servers. For untrusted responses,
162-
applications should use a dedicated streaming multipart parser and enforce
163-
application-specific limits. Resource exhaustion or parser exposure caused by
164-
calling `body.formData()` on untrusted responses is considered an application
165-
responsibility, not a vulnerability in undici.
156+
#### Calling body-consuming methods on untrusted responses
157+
158+
* The `body.arrayBuffer()`, `body.blob()`, `body.bytes()`, `body.formData()`,
159+
`body.json()`, and `body.text()` methods buffer the entire response body in
160+
memory before returning. Where applicable, they also decode or parse the
161+
payload and retain that representation in memory. Calling one of these
162+
methods means the application trusts that the response is small enough to
163+
fit in the available memory. Applications must not use these methods on
164+
responses from untrusted or user-controlled servers. They should instead
165+
process the response with a streaming API, such as `Response.body`,
166+
`body.textStream()`, or the `Readable` body returned by `undici.request()`,
167+
and enforce application-specific size limits while streaming. Resource
168+
exhaustion caused by buffering an untrusted response is considered an
169+
application responsibility, not a vulnerability in undici.
170+
171+
* Multipart parsing has additional inherent security risks. Applications
172+
processing untrusted multipart responses should use a dedicated streaming
173+
multipart parser and enforce application-specific limits. Parser exposure
174+
caused by calling `body.formData()` on an untrusted response is considered an
175+
application responsibility, not a vulnerability in undici.
166176

167177
#### HTTP/1.1 keep-alive with untrusted servers
168178

‎deps/undici/src/docs/docs/api/Agent.md‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -56,16 +56,16 @@ changes:
5656
`Infinity`, no limit is enforced. Must be a number greater than `0`.
5757
**Default:** `Infinity`.
5858

59-
`Agent` inherits all {PoolOptions} (and therefore all {ClientOptions}). The
60-
per-origin {Pool} it creates uses the default unlimited `connections`, so
61-
concurrent requests to the same origin are spread across separate {Client}
62-
instances on separate sockets.
59+
`Agent` inherits all {PoolOptions} (and therefore all {ClientOptions}). Each
60+
origin gets a separate {Pool}, with `connections` acting as the maximum number
61+
of clients that pool may create.
6362

6463
> [!NOTE]
65-
> Because each concurrent request to an origin may use a different {Client},
66-
> HTTP/2 multiplexing on a shared session does not apply unless `connections` is
67-
> set to a small value (for example `connections: 1`). See {PoolOptions} and
68-
> {ClientOptions} for the full set of inherited options such as `allowH2`
64+
> For an h2-capable HTTPS origin, the per-origin pool waits for the first TLS
65+
> connection to finish ALPN negotiation. If the server selects h2, concurrent
66+
> requests share that session up to `maxConcurrentStreams`. If it selects
67+
> HTTP/1.1, normal connection fan-out resumes up to `connections`. See
68+
> {PoolOptions} and {ClientOptions} for inherited options such as `allowH2`
6969
> (default `true`) and `maxConcurrentStreams` (default `100`).
7070
7171
### `agent.closed`

‎deps/undici/src/docs/docs/api/DiagnosticsChannel.md‎

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -120,24 +120,26 @@ diagnosticsChannel.channel('undici:request:bodySent').subscribe(({ request }) =>
120120
added: v6.3.0
121121
-->
122122

123-
Published after the response headers have been received.
123+
Published after the response headers have been received. This includes a
124+
successful CONNECT or protocol upgrade response.
124125

125126
* `message` {Object}
126127
* `request` {Object} The same object published by
127128
[`'undici:request:create'`][].
128129
* `response` {Object} The response being received.
129130
* `statusCode` {number} The HTTP status code.
130131
* `statusText` {string} The HTTP status message.
131-
* `headers` {Buffer[]} The raw response headers as an array of buffers,
132-
alternating between header name and value.
132+
* `headers` {Buffer[]|Object} HTTP/1.1 response headers are an array of
133+
buffers alternating between header name and value. HTTP/2 response
134+
headers are an object.
133135

134136
```mjs
135137
import diagnosticsChannel from 'node:diagnostics_channel'
136138

137139
diagnosticsChannel.channel('undici:request:headers').subscribe(({ request, response }) => {
138140
console.log('statusCode', response.statusCode)
139141
console.log(response.statusText)
140-
console.log(response.headers.map((x) => x.toString()))
142+
console.log(response.headers)
141143
})
142144
```
143145

@@ -168,8 +170,9 @@ diagnosticsChannel.channel('undici:request:bodyChunkReceived').subscribe(({ requ
168170
added: v6.3.0
169171
-->
170172

171-
Published after the response body and trailers have been received, that is, once
172-
the response has fully completed.
173+
Published once the response has fully completed. After an upgraded socket has
174+
been passed to the request handler, this event is published with an empty
175+
`trailers` array.
173176

174177
* `message` {Object}
175178
* `request` {Object} The same object published by

‎deps/undici/src/docs/docs/api/Dispatcher.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -466,6 +466,15 @@ example, calling `text()` after `json()` throws a `TypeError`. The body also
466466
provides `dump({ limit })`, which discards up to `limit` bytes (default
467467
`131072`) without destroying the socket.
468468

469+
> [!WARNING]
470+
> The `arrayBuffer()`, `blob()`, `bytes()`, `json()`, and `text()` methods buffer
471+
> the entire body in memory before returning. Where applicable, they also decode
472+
> or parse the payload and retain that representation in memory. Calling these
473+
> methods therefore means trusting that the body is small enough to fit in the
474+
> available memory. Do not use them for bodies received from untrusted or
475+
> user-controlled sources. Instead, process `body` as a `Readable` stream and
476+
> enforce an application-specific size limit.
477+
469478
The body is always a `Readable`, even when empty. Deserializing an empty body
470479
with `json()` throws. To guard against this, verify the status code is not `204`
471480
and the `content-type` header starts with `application/json` before calling

‎deps/undici/src/docs/docs/api/Errors.md‎

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -446,6 +446,31 @@ The response returned an error status code. This is raised, for example, when th
446446
* `headers` {Object|string[]|null} The response headers. (optional)
447447
* `body` {Object|string|null} The response body. (optional)
448448

449+
## Class: `ProxyConnectionError`
450+
451+
<!-- YAML
452+
added: v8.10.1
453+
changes:
454+
- version: v8.10.1
455+
pr-url: https://github.com/nodejs/undici/pull/5707
456+
description: Added to fail the request instead of retrying forever when the proxy connection is torn down.
457+
-->
458+
459+
* Extends: {UndiciError}
460+
461+
A connection to the proxy failed in a way that cannot be recovered on the
462+
same connection, so the request fails instead of being retried.
463+
464+
* `name` {string} Always `'ProxyConnectionError'`.
465+
* `code` {string} Always `'UND_ERR_PRX_CONN'`.
466+
* `cause` {Error} The underlying error that caused the proxy connection to fail.
467+
468+
### `new ProxyConnectionError(cause[, message[, options]])`
469+
470+
* `cause` {Error} The underlying error. (optional)
471+
* `message` {string} The error message. (optional)
472+
* `options` {Object} Additional `Error` options merged with `cause`. (optional)
473+
449474
## Class: `SecureProxyConnectionError`
450475

451476
<!-- YAML

‎deps/undici/src/docs/docs/api/Fetch.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -596,6 +596,16 @@ properties for reading a body. Each consuming method reads the body once; after
596596
the body has been consumed, [`bodyUsed`](#bodybodyused) becomes `true` and
597597
calling another consuming method throws a `TypeError`.
598598

599+
> [!WARNING]
600+
> The `arrayBuffer()`, `blob()`, `bytes()`, `formData()`, `json()`, and `text()`
601+
> methods buffer the entire body in memory before returning. Where applicable,
602+
> they also decode or parse the payload and retain that representation in
603+
> memory. Calling these methods therefore means trusting that the body is small
604+
> enough to fit in the available memory. Do not use them for bodies received
605+
> from untrusted or user-controlled sources. Instead, process `body.body` or
606+
> `body.textStream()` incrementally and enforce an application-specific size
607+
> limit.
608+
599609
### `body.arrayBuffer()`
600610

601611
<!-- YAML

‎deps/undici/src/docs/docs/api/Interceptors.md‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -210,9 +210,10 @@ Automatically decompresses response bodies encoded with `gzip`, `x-gzip`,
210210
skipped. **Default:** `[204, 304]`.
211211
* `skipErrorResponses` {boolean} When `true`, responses with a status code
212212
>= 400 are not decompressed. **Default:** `true`.
213-
* `maxSize` {number} Maximum decompressed response size in bytes. The request
214-
fails with a `ResponseExceededMaxSizeError` if the decoded body exceeds
215-
this limit. **Default:** `67108864` (64 MiB).
213+
* `maxSize` {number} Maximum decompressed response size in bytes for each
214+
decompression stage. The request fails with a
215+
`ResponseExceededMaxSizeError` if a stage exceeds this limit. Set to `0` to
216+
disable the limit. **Default:** `0`.
216217
217218
**Returns:** {Dispatcher.DispatcherComposeInterceptor}
218219

‎deps/undici/src/docs/docs/api/Pool.md‎

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -73,12 +73,11 @@ connector shared by every pooled client.
7373

7474
> [!NOTE]
7575
> `Pool` inherits all {ClientOptions}, including `allowH2` and
76-
> `maxConcurrentStreams`. With the default unlimited `connections`, the pool
77-
> opens a new client - and therefore a new TCP/TLS socket - per concurrent
78-
> dispatch, which defeats HTTP/2 multiplexing over a shared session. To benefit
79-
> from h2 multiplexing on a single session, cap `connections` (for example
80-
> `connections: 1`) so that concurrent requests share a session up to
81-
> `maxConcurrentStreams`.
76+
> `maxConcurrentStreams`. For an h2-capable HTTPS origin, the pool waits for
77+
> the first TLS connection to finish ALPN negotiation before opening more
78+
> clients. If the server selects h2, concurrent requests share that session up
79+
> to `maxConcurrentStreams`. If it selects HTTP/1.1, the pool resumes normal
80+
> connection fan-out up to `connections`.
8281
8382
```mjs
8483
import { Pool } from 'undici'

‎deps/undici/src/docs/docs/index.md‎

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -380,7 +380,16 @@ The `body` mixins are the most common way to format the request/response body. M
380380
> The body returned from `undici.request` does not implement `.formData()`.
381381
382382
> [!WARNING]
383-
> Calling `body.formData()` on a fetch response causes undici to buffer and parse the entire body. Since this is dictated by the spec, `body.formData()` must only be called on responses from trusted servers.
383+
> The body mixins `.arrayBuffer()`, `.blob()`, `.bytes()`, `.json()`, `.text()`,
384+
> and `.formData()` buffer the entire body in memory before returning. Where
385+
> applicable, they also decode or parse the payload and retain that
386+
> representation in memory. Calling these methods therefore means trusting that
387+
> the response body is small enough to fit in the available memory. Do not use
388+
> them for responses from untrusted or user-controlled sources. Instead, consume
389+
> the response body as a stream and enforce an application-specific size limit:
390+
> use `response.body` for fetch responses or the `body` returned by
391+
> `undici.request()`. For streaming decoded text, use `body.textStream()` on a
392+
> fetch `Request` or `Response`.
384393
385394
Example usage:
386395

0 commit comments

Comments
 (0)