Bump mimalloc - #41253
Bump mimalloc#41253
Conversation
|
Updated 11:34 PM PT - Sep 2nd, 2026
@Jarred-Sumner, your commit 3a2cafb is building: |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Essentials Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 10 included reviews per hour; 7 remain after this review. WalkthroughThe pull request updates the mimalloc dependency source commit in the build configuration. Changesmimalloc update
Suggested reviewers: Merge Risk: ⚪ Minimal · up to This updates the pinned mimalloc revision without changing local build integration. No current merge-readiness risk remains. 🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Comment |
There was a problem hiding this comment.
LGTM — straightforward vendored-dep pin bump.
What was reviewed:
- Single-line
MIMALLOC_COMMITchange; constant name preserved (load-bearing for workflow sed). sources: ["src/static.c"]is the unity TU, so upstream file adds/removes don't need a source-list edit here.- Repo is
oven-sh/mimalloc(own fork); no patches to rebase; identity hash invalidates.refand triggers re-fetch automatically. - No CODEOWNERS entry covers this path.
Extended reasoning...
Overview
This PR changes exactly one line in scripts/build/deps/mimalloc.ts: the MIMALLOC_COMMIT constant is bumped from 942b834… to b20b60d…. mimalloc is Bun's allocator, vendored as a direct build dep from the oven-sh/mimalloc fork. The build spec compiles only src/static.c (mimalloc's unity translation unit that #includes every other source), so unlike other direct deps with hardcoded source lists, an upstream commit that adds or removes .c files does not require a matching edit here. No patches, defines, cflags, or source-list changes accompany the bump.
Security risks
None introduced by this diff itself — it's a commit-hash edit in a build-config script. The pinned commit is in Bun's own fork (oven-sh/mimalloc), not an arbitrary upstream, so the referenced code is under the project's control. The build system fetches by exact commit hash into vendor/, and the identity hash (sha256 of commit + patch contents) invalidates the .ref stamp so there's no risk of stale sources being reused. Any behavioral risk lives in the mimalloc changes themselves (allocator correctness under threading), which CI compile/link and the test suite exercise; that's outside what a diff review of this file can assess.
Level of scrutiny
Low. scripts/build/CLAUDE.md documents this exact operation as the canonical way to bump a dep ("edit the commit in scripts/build/deps/<name>.ts"), and deps/README.md notes the only follow-up concern for direct deps is source-list drift — which the unity-TU build here sidesteps. The MIMALLOC_COMMIT constant name is unchanged, so any .github/workflows/update-*.yml sed convention is preserved (no update-mimalloc workflow exists anyway). No CODEOWNERS rule covers scripts/build/deps/.
Other factors
The PR author is the project lead and the fork owner. Exit reason was dry_streak with no findings and no ruled-out candidates. The timeline shows no third-party reviews or outstanding objections. This is precisely the "config tweaks / version bumps" category the approval guidelines call out as safe to approve.
Bumps oven-sh/mimalloc from 942b834 to 6a64e1b (12 commits).