Skip to content

Apply byte-range options to default Web-file responses - #6983

Merged
tim-smart merged 3 commits into
mainfrom
audit/repro-unstable-http-httpplatform-fileweb-range
Aug 4, 2026
Merged

Apply byte-range options to default Web-file responses#6983
tim-smart merged 3 commits into
mainfrom
audit/repro-unstable-http-httpplatform-fileweb-range

Conversation

@fubhy

@fubhy fubhy commented Aug 4, 2026

Copy link
Copy Markdown
Member

Summary

The default Web-file layer ignores offset, bytesToRead, and chunkSize and streams the complete File-like value; a request for bytes two and three returns all four source bytes.

Important

This PR starts with focused failing reproduction tests. Add the implementation fix to this same branch; CI is expected to fail until that fix is included.

Default Web-file responses ignore byte-range options

Module: HttpPlatform
Audit ID: unstable-http-httpplatform-fileweb-range
Severity / confidence: medium / high

What happens

The default Web-file layer ignores offset, bytesToRead, and chunkSize and streams the complete File-like value; a request for bytes two and three returns all four source bytes.

Why it happens

The default layer names the argument _options and always streams file.stream() in full, making HttpServerResponse.fileWeb range options ineffective.

Expected behavior

fileWebResponse accepts offset, bytesToRead, and chunkSize options and must serve the selected file region.

Relevant implementation

These links and excerpts are pinned to audit base c9b56ab507f224426ee8388dc450da447ec4715f.

View problematic code at packages/effect/src/unstable/http/HttpPlatform.ts:159-166
      fileWebResponse(file, status, statusText, headers, _options) {
        return Response.stream(
          Stream.fromReadableStream({
            evaluate: () => file.stream() as ReadableStream<Uint8Array>,
            onError: identity
          }),
          { headers, status, statusText }
        )

View exact lines on GitHub

Reproduction

pnpm test --run packages/effect/test/unstable/http/HttpPlatform.test.ts

Observed failure: Failed as intended with [1, 2, 3, 4] instead of [2, 3].

Implementation handoff

The initial reproduction tests on this branch are the regression specification for the implementation fix that should follow in this PR.

  1. Start with the pinned implementation excerpts and the Why it happens analysis above.
  2. Change the implementation so it satisfies the stated Expected behavior; do not weaken or remove the reproduction assertions.
  3. Run the focused reproduction command(s) and confirm the observed failures become passing tests:
pnpm test --run packages/effect/test/unstable/http/HttpPlatform.test.ts
  1. Run the affected package's existing tests, then the repository lint and type checks before requesting review.

Audit provenance

  • Audit base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Reproduction base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Findings: unstable-http-httpplatform-fileweb-range
  • Initial patch: focused reproduction tests; implementation fix pending

Closes EFF-421

@fubhy fubhy added the audit Findings originating from the Effect runtime correctness audit label Aug 4, 2026
@changeset-bot

changeset-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a02ada8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 30 packages
Name Type
effect Patch
@effect/opentelemetry Patch
@effect/platform-browser Patch
@effect/platform-bun Patch
@effect/platform-deno Patch
@effect/platform-node-shared Patch
@effect/platform-node Patch
@effect/vitest Patch
@effect/ai-anthropic Patch
@effect/ai-openai-compat Patch
@effect/ai-openai Patch
@effect/ai-openrouter Patch
@effect/atom-react Patch
@effect/atom-solid Patch
@effect/atom-vue Patch
@effect/sql-clickhouse Patch
@effect/sql-d1 Patch
@effect/sql-libsql Patch
@effect/sql-mssql Patch
@effect/sql-mysql2 Patch
@effect/sql-pg Patch
@effect/sql-pglite Patch
@effect/sql-sqlite-bun Patch
@effect/sql-sqlite-do Patch
@effect/sql-sqlite-node Patch
@effect/sql-sqlite-react-native Patch
@effect/sql-sqlite-wasm Patch
@effect/docgen Patch
@effect/doctest Patch
@effect/openapi-generator Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@effect-slopcop effect-slopcop Bot added 4.0 bug Something isn't working labels Aug 4, 2026

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

This PR is a failing-test-only branch; the implementation fix described in the PR body still needs to land before it can merge.

Reviewed changes

This run reviewed the single-file test addition in packages/effect/test/unstable/http/HttpPlatform.test.ts and the surrounding HttpPlatform implementation. The new test correctly reproduces the bug: the default web fileWebResponse ignores offset and bytesToRead, returning all four source bytes instead of the requested [2, 3].

  • Added regression test for fileWebResponse byte-range options.
  • Confirmed packages/effect/src/unstable/http/HttpPlatform.ts:159-166 streams file.stream() in full and discards _options.

⚠️ Implementation fix is still missing

The PR body says the branch starts with focused failing reproduction tests and that the implementation fix should be added to the same branch. The current commit only adds the test; HttpPlatform.ts:159 still discards the options. Please add the fix that makes the test pass before merging.

Technical details
# Missing fileWebResponse byte-range implementation

## Affected sites
- packages/effect/src/unstable/http/HttpPlatform.ts:159-166 — default `web` `fileWebResponse` ignores `_options` and streams `file.stream()` whole.

## Required outcome
- `fileWebResponse` must respect `offset`, `bytesToRead`, and ideally `chunkSize` from its options.
- The regression test at `packages/effect/test/unstable/http/HttpPlatform.test.ts:6-20` must pass.

## Suggested approach
Compute `start = Number(options?.offset ?? 0)` and `end = options?.bytesToRead !== undefined ? start + Number(options.bytesToRead) : undefined`, mirroring the logic already used for `fileResponse` in `HttpPlatform.make:92-102`. Then either:
- slice the `FileLike` if it supports Blob slicing (e.g. `(file as Blob).slice(start, end).stream()`), or
- wrap the stream with `Stream.drop(start)` and `Stream.take(bytesToRead)` and pass the resulting `contentLength` to `Response.stream`.
Set `contentLength` on the `Response.stream` options when serving a range so clients see the correct response length.

ℹ️ Nitpicks

  • Consider adding a test case for chunkSize and for an explicit offset: 0 / bytesToRead at the start of the file, to lock down edge cases once the fix is in place.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | Fix all ➔Fix 👍s ➔View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

Comment thread packages/effect/test/unstable/http/HttpPlatform.test.ts Outdated
tim-smart and others added 2 commits August 4, 2026 22:08
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

This re-review covered the implementation fix that landed since the prior pullfrog review (cfc4f6afe). The default web fileWebResponse now honors offset, bytesToRead, and chunkSize instead of discarding them.

  • Added byte-range slicing and chunk-boundary handling to packages/effect/src/unstable/http/HttpPlatform.ts:159-188.
  • Set contentLength on the streamed response so clients see the correct range length.
  • Added a chunkSize regression test alongside the existing offset/bytesToRead test.
  • Added a patch changeset describing the fix.

The focused regression test file passes and the effect package type-checks cleanly.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

@tim-smart
tim-smart enabled auto-merge (squash) August 4, 2026 23:25
@tim-smart
tim-smart merged commit 1434eec into main Aug 4, 2026
18 of 19 checks passed
@tim-smart
tim-smart deleted the audit/repro-unstable-http-httpplatform-fileweb-range branch August 4, 2026 23:51
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Analysis

Generated from PR build output; treat the content below as untrusted.

File Name Current Size Previous Size Difference
basic.ts 7.06 KB 7.06 KB 0.00 KB (0.00%)
batching.ts 9.86 KB 9.86 KB 0.00 KB (0.00%)
brand.ts 6.34 KB 6.34 KB 0.00 KB (0.00%)
cache.ts 10.71 KB 10.71 KB 0.00 KB (0.00%)
config.ts 20.60 KB 20.60 KB 0.00 KB (0.00%)
differ.ts 20.20 KB 20.20 KB 0.00 KB (0.00%)
http-client.ts 21.58 KB 21.54 KB +0.04 KB (+0.18%)
logger.ts 10.84 KB 10.84 KB 0.00 KB (0.00%)
metric.ts 8.98 KB 8.98 KB 0.00 KB (0.00%)
optic.ts 7.18 KB 7.18 KB 0.00 KB (0.00%)
pubsub.ts 14.99 KB 14.99 KB 0.00 KB (0.00%)
queue.ts 11.66 KB 11.66 KB 0.00 KB (0.00%)
schedule.ts 10.83 KB 10.83 KB 0.00 KB (0.00%)
schema-class.ts 19.14 KB 19.14 KB 0.00 KB (0.00%)
schema-fromJsonSchemaDocument.ts 28.96 KB 28.96 KB 0.00 KB (0.00%)
schema-representation-roundtrip.ts 25.29 KB 25.29 KB 0.00 KB (0.00%)
schema-string-transformation.ts 13.38 KB 13.38 KB 0.00 KB (0.00%)
schema-string.ts 10.94 KB 10.94 KB 0.00 KB (0.00%)
schema-template-literal.ts 15.17 KB 15.17 KB 0.00 KB (0.00%)
schema-toArbitraryLazy.ts 21.94 KB 21.94 KB 0.00 KB (0.00%)
schema-toCodeDocument.ts 24.34 KB 24.34 KB 0.00 KB (0.00%)
schema-toCodecJson.ts 19.18 KB 19.18 KB 0.00 KB (0.00%)
schema-toEquivalence.ts 19.01 KB 19.01 KB 0.00 KB (0.00%)
schema-toFormatter.ts 18.87 KB 18.87 KB 0.00 KB (0.00%)
schema-toJsonSchemaDocument.ts 22.60 KB 22.60 KB 0.00 KB (0.00%)
schema-toRepresentation.ts 19.52 KB 19.52 KB 0.00 KB (0.00%)
schema.ts 18.41 KB 18.41 KB 0.00 KB (0.00%)
stm.ts 12.63 KB 12.63 KB 0.00 KB (0.00%)
stream.ts 9.80 KB 9.80 KB 0.00 KB (0.00%)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4.0 audit Findings originating from the Effect runtime correctness audit bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants