Skip to content

stream: fix flaky stream destroy, reachable from HTTP/2 teardown - #65079

Closed
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake
Closed

stream: fix flaky stream destroy, reachable from HTTP/2 teardown#65079
pimterry wants to merge 2 commits into
nodejs:mainfrom
pimterry:fix-h2-flake

Conversation

@pimterry

@pimterry pimterry commented Aug 6, 2026

Copy link
Copy Markdown
Member

Some of the HTTP/2 tests have become flaky, e.g. nodejs/reliability#1623 shows yesterday:

  • parallel/test-worker-terminate-http2-respond-with-file failed 11 times
  • parallel/test-stream-pipeline-http2 failed 10 times

Best guess is these are both due to the window update PR #64623 (cc @mcollina) since the timing lines up exactly. I think this is really just the window size highlighting existing issues though.

This PR fixes the first issue, which triggers flakes in parallel/test-worker-terminate-http2-respond-with-file. I'll kick off a stress test to confirm, but I can reproduce this locally, and reproduced as resolved with this fix. I'm still working on the 2nd, which only reproduces on Mac and seems a bit more complex.

Actual failure in the 1st test is a crash with pure virtual method called. That fires due to ReadStop within this trace:

Worker::Run → FreeEnvironment
  → Environment::RunCleanup
    → BaseObjectList::Cleanup
      → fs::FileHandle::~FileHandle
        → StreamResource::~StreamResource
          → StreamPipe::ReadableListener::OnStreamDestroy
            → StreamPipe::ReadableListener::OnStreamRead

I.e. during destroy within the destructor chain, we call OnStreamRead, which tries to call stream()->ReadStop inside the sources destructor.

This is only called because OnStreamDestroy manually calls OnStreamRead with an error code to reuse its error/eof teardown logic. We don't need most of that in the destruction scenario (which is only ever called from ~StreamResource, where the stream is already dead).

I've refactored out the relevant bit to split them up (just guarding just fails in the next line, where previous_listener_ is also null). That then exposed two other bugs for the same state, where two other methods that get reached later in this teardown flow also fail to check if the stream is already destroyed - those just need simple guards.

Seems like this is a flaky race because it depends on whether the sink (Http2Stream) or the file handle gets destroyed first by Cleanup().

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-bot nodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels Aug 6, 2026
@pimterry

pimterry commented Aug 6, 2026

Copy link
Copy Markdown
Member Author

cc @nodejs/http2

@codecov

codecov Bot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.32%. Comparing base (b33cc0e) to head (da4b684).
⚠️ Report is 81 commits behind head on main.

Files with missing lines Patch % Lines
src/stream_pipe.cc 0.00% 5 Missing and 2 partials ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main   #65079      +/-   ##
==========================================
+ Coverage   90.29%   90.32%   +0.03%     
==========================================
  Files         759      759              
  Lines      247598   248458     +860     
  Branches    46680    46869     +189     
==========================================
+ Hits       223566   224420     +854     
+ Misses      15503    15448      -55     
- Partials     8529     8590      +61     
Files with missing lines Coverage Δ
src/stream_pipe.cc 58.71% <0.00%> (-1.47%) ⬇️

... and 87 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pimterry

pimterry commented Aug 7, 2026

Copy link
Copy Markdown
Member Author

I'll kick off a stress test to confirm

Stress testing inconclusive - the tests passed on both main and this branch, even with multiple runs. They're definitely failing in PRs though. I can reliably reproduce the reported failure locally (that first failure above, it hits for 2-3% of runs) and validate that it's fixed with this change. The trace is where is crashes on my machine with the matching error, and it's clearly a broken flow, so I think this is the right fix regardless.

@mcollina mcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

I concur with the analysis

@mcollina mcollina added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@github-actions github-actions Bot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 7, 2026
@panva panva added the author ready PRs that have at least one approval, no pending requests for changes, and a CI started. label Aug 7, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva

panva commented Aug 7, 2026

Copy link
Copy Markdown
Member

Even with this PR's change I can still fail test-stream-pipeline-http2.js with a timeout 31/1000 times. Without it about 56/1000 times.

This diff that claude spit out to deflake test-stream-pipeline-http2.js makes that 0/1000 with or without this PR, but I don't know enough about this subsystem to say whether that retains the point of the test or not.

diff --git a/test/parallel/test-stream-pipeline-http2.js b/test/parallel/test-stream-pipeline-http2.js
--- a/test/parallel/test-stream-pipeline-http2.js
+++ b/test/parallel/test-stream-pipeline-http2.js
@@ -27,10 +27,11 @@
-    let cnt = 10;
+    let received = 0;
     req.on('data', (data) => {
-      cnt--;
-      if (cnt === 0) rs.destroy();
+      received += data.length;
+      // HTTP/2 data event boundaries are non-deterministic.
+      if (received >= 32 * 1024) rs.destroy();
     });

@pimterry

pimterry commented Aug 7, 2026

Copy link
Copy Markdown
Member Author

Even with this PR's change I can still fail test-stream-pipeline-http2.js

Yes, sorry if the description isn't clear - both failing tests are related to that PR, but this PR only fixes the first of the two. I.e. test-worker-terminate-http2-respond-with-file.

I haven't opened a fix for the second yet, because I think it's actually exposed a real bug that's a bit complicated, and mac-only. Looks like that fix would resolve the test, but from what I can tell so far there's a real underlying deadlock that's reproducible independently, so I want to get a proper fix for that instead. I'll update when I have more info there.

@panva

panva commented Aug 9, 2026

Copy link
Copy Markdown
Member

@pimterry can you land this with the fix/workaround i posted to the remaining flake knowing you'll revisit the underlying deadlock problem and possibly change it again?

This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.

Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
@pimterry

pimterry commented Aug 9, 2026

Copy link
Copy Markdown
Member Author

Good plan @panva, now done 👍.

I'll open the other fix separately. I've got it working now but the deadlock comes from code we added to resolve past CVEs, so needs some thought and it'd be nice not to rush it.

@pimterry pimterry added request-ci Add this label to start a Jenkins CI on a PR. commit-queue-rebase Add this label to allow the Commit Queue to land a PR in several commits. labels Aug 9, 2026
@panva panva removed the commit-queue-rebase Add this label to allow the Commit Queue to land a PR in several commits. label Aug 9, 2026
@github-actions github-actions Bot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@panva panva added the commit-queue-rebase Add this label to allow the Commit Queue to land a PR in several commits. label Aug 9, 2026

@mcollina mcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterry pimterry added the commit-queue Add this label to land a pull request using GitHub Actions. label Aug 10, 2026
panva pushed a commit that referenced this pull request Aug 10, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
panva added a commit that referenced this pull request Aug 10, 2026
This does not solve the remaining underlying deadlock issue, but does
bound the test behaviour in a way that seems to avoid failures in
practice. Deadlock fix to come separately later.

Co-authored-by: Filip Skokan <panva.ip@gmail.com>
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #65079
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
@panva

panva commented Aug 10, 2026

Copy link
Copy Markdown
Member

Landed in 780229b...404b0cf

@panva panva closed this Aug 10, 2026
@panva panva removed the commit-queue Add this label to land a pull request using GitHub Actions. label Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author ready PRs that have at least one approval, no pending requests for changes, and a CI started. c++ Issues and PRs that require attention from people who are familiar with C++. commit-queue-rebase Add this label to allow the Commit Queue to land a PR in several commits. needs-ci PRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants