node/test
Matteo Collina ad8f518a81
zlib: fix use-after-free when reset() is called during write
The Reset() method did not check the write_in_progress_ flag before
resetting the compression stream. This allowed reset() to free the
compression library's internal state while a worker thread was still
using it during an async write, causing a use-after-free.

Add a write_in_progress_ guard to Reset() that throws an error if a
write is in progress, matching the existing pattern used by Close()
and Write().

PR-URL: TODO
Refs: https://hackerone.com/reports/3609132
PR-URL: https://github.com/nodejs/node/pull/62325
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
2026-05-11 16:10:17 +02:00
..
abort
addons
async-hooks
benchmark node-api: use Node-API in comments 2026-02-24 08:38:56 +01:00
cctest node-api: use Node-API in comments 2026-02-24 08:38:56 +01:00
client-proxy
common
doctool
embedding
es-module module: handle null source from async loader hooks in sync hooks 2026-04-27 18:03:19 +02:00
fixtures deps: update timezone to 2026a 2026-05-11 15:49:24 +02:00
fuzzers
internet
js-native-api node-api: use Node-API in comments 2026-02-24 08:38:56 +01:00
known_issues
message module: do not wrap module._load when tracing is not enabled 2026-04-27 18:03:23 +02:00
module-hooks module: do not invoke resolve hooks twice for imported cjs 2026-04-27 18:03:26 +02:00
node-api node-api: use Node-API in comments 2026-02-24 08:38:56 +01:00
nop
overlapped-checker
parallel zlib: fix use-after-free when reset() is called during write 2026-05-11 16:10:17 +02:00
pseudo-tty module: do not wrap module._load when tracing is not enabled 2026-04-27 18:03:23 +02:00
pummel build,test: test array index hash collision 2026-03-23 20:06:35 +01:00
report
sea test: skip --build-sea tests on platforms where SEA is flaky 2026-02-24 08:39:02 +01:00
sequential cluster: fix port reuse between cluster 2026-02-24 08:38:54 +01:00
sqlite
system-ca
test426
testpy
tick-processor
tools
v8-updates
wasi
wasm-allocation
wpt test: skip test-url on --shared-ada builds 2026-05-11 15:01:12 +02:00
eslint.config_partial.mjs
README.md
root.status

Node.js Core Tests

This directory contains code and data used to test the Node.js implementation.

For a detailed guide on how to write tests in this directory, see the guide on writing tests.

On how to run tests in this directory, see the contributing guide.

For the tests to run on Windows, be sure to clone Node.js source code with the autocrlf git config flag set to true.

Test Directories

Directory Runs on CI Purpose
abort Yes Tests that use --abort-on-uncaught-exception and other cases where we want to avoid generating a core file.
addons Yes Tests for addon functionality along with some tests that require an addon.
async-hooks Yes Tests for async_hooks functionality.
benchmark Yes Test minimal functionality of benchmarks.
cctest Yes C++ tests that are run as part of the build process.
code-cache No Tests for a Node.js binary compiled with V8 code cache.
common N/A Common modules shared among many tests.1
doctool Yes Tests for the documentation generator.
es-module Yes Test ESM module loading.
fixtures N/A Test fixtures used in various tests throughout the test suite.
internet No Tests that make real outbound network connections.2
js-native-api Yes Tests for Node.js-agnostic Node-API functionality.
known_issues Yes Tests reproducing known issues within the system.3
message Yes Tests for messages that are output for various conditions
node-api Yes Tests for Node.js-specific Node-API functionality.
parallel Yes Various tests that are able to be run in parallel.
pseudo-tty Yes Tests that require stdin/stdout/stderr to be a TTY.
pummel No Various tests for various modules / system functionality operating under load.
sequential Yes Various tests that must not run in parallel.
testpy N/A Test configuration utility used by various test suites.
tick-processor No Tests for the V8 tick processor integration.4
v8-updates No Tests for V8 performance integration.

  1. Documentation ↩︎

  2. Tests for networking related modules may also be present in other directories, but those tests do not make outbound connections. ↩︎

  3. All tests inside of this directory are expected to fail. If a test doesn't fail on certain platforms, those should be skipped via known_issues.status. ↩︎

  4. The tests are for the logic in lib/internal/v8_prof_processor.js and lib/internal/v8_prof_polyfill.js. The tests confirm that the profile processor packages the correct set of scripts from V8 and introduces the correct platform specific logic. ↩︎