Repository navigation
fix(node:net): validate listen ports synchronously - #101
Merged
Merged
Conversation
Validate HTTP and HTTPS listen ports before DNS lookup and binding. Preserve asynchronous bind failures and use Node-compatible numeric string coercion. Adapts the net string-routing and Unicode whitespace fixes from oven-sh#34083.
This was referenced Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
http.Server.listen(65536)andhttps.Server.listen(65536)now throwRangeErrorwithERR_SOCKET_BAD_PORTbefore returning, matching Node 24. Real bind failures such asEADDRINUSEstill arrive through the asynchronouserrorevent.HTTP previously validated inside
Bun.serve()and caught argument errors as bind failures. This moves port validation ahead of DNS/binding, uses full numeric-string conversion instead ofparseInt, and preserves TCP-port precedence over a simultaneous path. The net change keeps empty strings intact until validation and uses Node's pipe-name routing. Numeric, string, options, host, backlog, non-integer, negative, non-finite, and whitespace cases are covered across net/HTTP/HTTPS.Adapts the net string-routing and U+3000 whitespace fixes from oven-sh/bun#34083, which remains open. The HTTP/HTTPS timing fix is additional. Thanks @robobun. No upstream HTTP timing fix was found in the scoped search.
Validation used a dedicated Linux host and Node v24.19.0:
EADDRINUSEcontrols pass after the fix; c999 and unpatched fork main each mismatch 195 cases.node-net-server.test.ts,node-http.test.ts, andnode-tls-server.test.tspass with--expose-internals, as required for release-build test internals.src/gateway/server/http-listen.test.ts, pinned toaffb994cf4193ff967b0f792b4634435d3942948: Node 5/5, c999 4/5, patched 5/5. Bun runs useOPENCLAW_VITEST_RUNTIME=bun, private HOME/state/TMPDIR, and umask 022.c75c48109ac294dbe78e2f2bbf8cd2ddaea65f31; format and JavaScript lint also passed. The optional Claude workflow fails at credential validation before analysis (existing fork setup issue).The fork changelog is append-only and the Node compatibility notes describe the new error timing.