Skip to content

chore: upgrade standardserver to 0.8.1 - #1956

Merged
dinwwwh merged 1 commit into
middleapi:mainfrom
dinwwwh:claude/standardserver-0-8-1-upgrade-c786c3
Aug 26, 2026
Merged

dinwwwh merged 1 commit into
middleapi:mainfrom
dinwwwh:claude/standardserver-0-8-1-upgrade-c786c3

Conversation

@dinwwwh

@dinwwwh dinwwwh commented Aug 26, 2026

Copy link
Copy Markdown
Member

Upgrades all seven @standardserver/* packages from ^0.8.0 to ^0.8.1. Only @standardserver/node actually changed between the two releases (the other six tarballs are byte-identical), and the change it brings is a cancel-safe toWebReadableStream that the static file handler now uses.

Changes

StaticFileHandlerPlugin serves file bodies through toWebReadableStream instead of Readable.toWeb. The helper enqueues only from inside pull rather than from 'data' events, so a chunk arriving after the consumer cancels can no longer hit a closed controller and take down the process with an uncaught ERR_INVALID_STATE (nodejs/node#54205). It returns ReadableStream<Uint8Array<ArrayBuffer>> directly, so the cast at the call site is gone along with the now-unused node:stream import. @orpc/node picks up @standardserver/node as a dependency to import it, matching how @orpc/server and @orpc/nest already declare it.

minimumReleaseAgeExclude is pruned to only the entries still inside the release-age window. The 0.7.1 and 0.8.0 pins aged out weeks ago, and the blume / @tanstack entries pinned versions the workspace no longer resolves (it is on [email protected], @tanstack/[email protected], @tanstack/[email protected]).

Scope of the fix

On Node 24 the two stream helpers behave identically: a control-vs-fixed harness that cancels mid-read across three topologies (bare, through a TransformStream, through a CompressionStream) produced no uncaught exception either way, since Node has fixed the underlying bug on its side. This is hardening for the older Node versions in the supported range (22+) where it still bites, plus the cast removal. It is not a fix for a crash reachable on current Node.

Testing

Full suite passes: 3270 root, 26 cloudflare, 97 bun, including the 77 static file handler tests. type:check and eslint are clean. Fifty read-then-cancel cycles leak no file descriptors, matching the previous behavior.

Bumps all seven @standardserver packages from ^0.8.0 to ^0.8.1 across the
workspace. Only @standardserver/node changed between the two releases; the
other six tarballs are byte-identical.

That release adds a cancel-safe `toWebReadableStream`, which the static file
handler now uses in place of `Readable.toWeb`. It returns the exact stream
type, so the accompanying cast is gone, and `node:stream` is no longer needed
there. `@orpc/node` gains `@standardserver/node` as a dependency to import it.

Also prunes `minimumReleaseAgeExclude` down to the entries still inside the
release-age window. The 0.7.1 and 0.8.0 pins had long since aged out, and the
blume and @TanStack entries pinned versions the workspace no longer resolves.
@dinwwwh dinwwwh changed the title chore: upgrade @standardserver/* to 0.8.1 chore: upgrade standardserver/* to 0.8.1 Aug 26, 2026
@dinwwwh dinwwwh changed the title chore: upgrade standardserver/* to 0.8.1 chore: upgrade standardserver to 0.8.1 Aug 26, 2026
@pkg-pr-new

pkg-pr-new Bot commented Aug 26, 2026

Copy link
Copy Markdown
More templates

@orpc/ai-sdk

npm i https://pkg.pr.new/@orpc/ai-sdk@1956

@orpc/arktype

npm i https://pkg.pr.new/@orpc/arktype@1956

@orpc/bun

npm i https://pkg.pr.new/@orpc/bun@1956

@orpc/client

npm i https://pkg.pr.new/@orpc/client@1956

@orpc/cloudflare

npm i https://pkg.pr.new/@orpc/cloudflare@1956

@orpc/contract

npm i https://pkg.pr.new/@orpc/contract@1956

@orpc/experimental-effect

npm i https://pkg.pr.new/@orpc/experimental-effect@1956

@orpc/evlog

npm i https://pkg.pr.new/@orpc/evlog@1956

@orpc/hibernation

npm i https://pkg.pr.new/@orpc/hibernation@1956

@orpc/json-schema

npm i https://pkg.pr.new/@orpc/json-schema@1956

@orpc/experimental-msw

npm i https://pkg.pr.new/@orpc/experimental-msw@1956

@orpc/nest

npm i https://pkg.pr.new/@orpc/nest@1956

@orpc/next

npm i https://pkg.pr.new/@orpc/next@1956

@orpc/node

npm i https://pkg.pr.new/@orpc/node@1956

@orpc/openapi

npm i https://pkg.pr.new/@orpc/openapi@1956

@orpc/opentelemetry

npm i https://pkg.pr.new/@orpc/opentelemetry@1956

@orpc/pinia-colada

npm i https://pkg.pr.new/@orpc/pinia-colada@1956

@orpc/pino

npm i https://pkg.pr.new/@orpc/pino@1956

@orpc/publisher

npm i https://pkg.pr.new/@orpc/publisher@1956

@orpc/ratelimit

npm i https://pkg.pr.new/@orpc/ratelimit@1956

@orpc/server

npm i https://pkg.pr.new/@orpc/server@1956

@orpc/shared

npm i https://pkg.pr.new/@orpc/shared@1956

@orpc/swr

npm i https://pkg.pr.new/@orpc/swr@1956

@orpc/tanstack-query

npm i https://pkg.pr.new/@orpc/tanstack-query@1956

@orpc/trpc

npm i https://pkg.pr.new/@orpc/trpc@1956

@orpc/valibot

npm i https://pkg.pr.new/@orpc/valibot@1956

@orpc/zod

npm i https://pkg.pr.new/@orpc/zod@1956

commit: f58618a

@codecov

codecov Bot commented Aug 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@codspeed

codspeed Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 30 untouched benchmarks


Comparing dinwwwh:claude/standardserver-0-8-1-upgrade-c786c3 (f58618a) with main (8b925be)

Open in CodSpeed

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

  • Dependency bump — Upgrades all seven @standardserver/* packages from ^0.8.0 to ^0.8.1 across the root and workspace package.jsons, with matching pnpm-lock.yaml updates (specifier, integrity, and snapshot graphs all consistent; @standardserver/node@^0.8.1 added to @orpc/node).
  • Static file handler — packages/node/src/static-file-handler-plugin.ts now serves file bodies via toWebReadableStream(...) from @standardserver/node instead of Readable.toWeb(...) as ReadableStream<Uint8Array<ArrayBuffer>>. This drops the cast, the now-unused node:stream import, and picks up upstream's cancel-safe enqueue (guards a post-cancel enqueue on a closed controller — nodejs/node#54205).
  • Release-age exclusions — pnpm-workspace.yaml::minimumReleaseAgeExclude is pruned of entries whose pinned versions aged out (0.7.1/0.8.0, stale blume/@tanstack pins), replaced with the new 0.8.1 entries and a policy comment.

I verified at head that @standardserver/[email protected] exports toWebReadableStream(stream: Readable): ReadableStream<Uint8Array<ArrayBuffer>> — the return type matches exactly what body is declared as, so the cast removal is type-sound and type:check's passing claim is consistent. The implementation iterates Symbol.asyncIterator only from inside pull(), checks a canceled flag before enqueue, and destroys the stream on cancel (skipping IncomingMessage), which is precisely the cancel-safety hardening described. The compressed (sse) path's Duplex.toWeb in batch-response-compression-handler-plugin.ts is a separate write-side concern and is correctly left untouched; blast radius is static-file body serving only. Scope, lockfile, and cleanup are all consistent and well-scoped.

Minor, non-blocking observation: there's no dedicated regression test for the cancel race itself (it reproduces only on Node 22, which makes it genuinely hard to pin reliably), so future coverage bears watching if the helper behavior ever changes upstream.

Pullfrog  | View workflow run | Using DeepSeek Flash (free via Pullfrog for OSS) | 𝕏

@dinwwwh
dinwwwh merged commit 3100950 into middleapi:main Aug 26, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant