Skip to content

fix(node:net): validate listen ports synchronously - #101

Merged
steipete merged 1 commit into
mainfrom
claude/w131-listen-port-validation
Oct 4, 2026
Merged

steipete merged 1 commit into
mainfrom
claude/w131-listen-port-validation

Conversation

@steipete

@steipete steipete commented Oct 4, 2026 •

Copy link
Copy Markdown

http.Server.listen(65536) and https.Server.listen(65536) now throw RangeError with ERR_SOCKET_BAD_PORT before returning, matching Node 24. Real bind failures such as EADDRINUSE still arrive through the asynchronous error event.

HTTP previously validated inside Bun.serve() and caught argument errors as bind failures. This moves port validation ahead of DNS/binding, uses full numeric-string conversion instead of parseInt, and preserves TCP-port precedence over a simultaneous path. The net change keeps empty strings intact until validation and uses Node's pipe-name routing. Numeric, string, options, host, backlog, non-integer, negative, non-finite, and whitespace cases are covered across net/HTTP/HTTPS.

Adapts the net string-routing and U+3000 whitespace fixes from oven-sh/bun#34083, which remains open. The HTTP/HTTPS timing fix is additional. Thanks @robobun. No upstream HTTP timing fix was found in the scoped search.

Validation used a dedicated Linux host and Node v24.19.0:

  • Dependency-free oracle: all 264 invalid-port cases plus three asynchronous EADDRINUSE controls pass after the fix; c999 and unpatched fork main each mismatch 195 cases.
  • New regression suite: c999 has 36 failures and 39 passes; patched head passes all 75 tests.
  • Surrounding node-net-server.test.ts, node-http.test.ts, and node-tls-server.test.ts pass with --expose-internals, as required for release-build test internals.
  • OpenClaw src/gateway/server/http-listen.test.ts, pinned to affb994cf4193ff967b0f792b4634435d3942948: Node 5/5, c999 4/5, patched 5/5. Bun runs use OPENCLAW_VITEST_RUNTIME=bun, private HOME/state/TMPDIR, and umask 022.
  • Scoped P2 branch review is clean. Linux x64 and macOS arm64 CI both passed on exact head c75c48109ac294dbe78e2f2bbf8cd2ddaea65f31; format and JavaScript lint also passed. The optional Claude workflow fails at credential validation before analysis (existing fork setup issue).

The fork changelog is append-only and the Node compatibility notes describe the new error timing.

Validate HTTP and HTTPS listen ports before DNS lookup and binding. Preserve asynchronous bind failures and use Node-compatible numeric string coercion.

Adapts the net string-routing and Unicode whitespace fixes from oven-sh#34083.
@steipete
steipete merged commit 02a67c2 into main Oct 4, 2026
8 of 9 checks passed
@steipete
steipete deleted the claude/w131-listen-port-validation branch October 4, 2026 04:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant