Skip to content

Synchronize response metadata when replacing bodies - #6986

Merged
tim-smart merged 4 commits into
mainfrom
audit/repro-unstable-http-httpserverresponse-stale-metadata
Aug 4, 2026
Merged

Synchronize response metadata when replacing bodies#6986
tim-smart merged 4 commits into
mainfrom
audit/repro-unstable-http-httpserverresponse-stale-metadata

Conversation

@fubhy

@fubhy fubhy commented Aug 4, 2026

Copy link
Copy Markdown
Member

Summary

A known zero-length response omits content-length: 0, while replacing a body with empty or unknown-length content can retain obsolete content type and length headers.

Important

This PR starts with focused failing reproduction tests. Add the implementation fix to this same branch; CI is expected to fail until that fix is included.

Response body metadata becomes missing or stale

Module: HttpServerResponse
Audit ID: unstable-http-httpserverresponse-stale-metadata
Severity / confidence: medium / high

What happens

A known zero-length response omits content-length: 0, while replacing a body with empty or unknown-length content can retain obsolete content type and length headers.

Why it happens

makeResponse tests contentLength by truthiness, so zero is omitted. It starts from existing headers and only overwrites metadata present on the new body, preserving obsolete entity headers when the replacement is empty or has unknown length.

Expected behavior

Response headers generated from a body must remain synchronized with that body's content type and length.

Relevant implementation

These links and excerpts are pinned to audit base c9b56ab507f224426ee8388dc450da447ec4715f.

View problematic code at packages/effect/src/unstable/http/HttpServerResponse.ts:911-917
export const setBody: {
  (body: Body.HttpBody): (self: HttpServerResponse) => HttpServerResponse
  (self: HttpServerResponse, body: Body.HttpBody): HttpServerResponse
} = dual(
  2,
  (self: HttpServerResponse, body: Body.HttpBody): HttpServerResponse => makeResponse({ ...self, body })
)

View exact lines on GitHub

View problematic code at packages/effect/src/unstable/http/HttpServerResponse.ts:1328-1342
  if (
    self.body._tag !== "Empty" &&
    (self.body.contentType || self.body.contentLength)
  ) {
    const newHeaders = Headers.fromRecordUnsafe({ ...options.headers }) as any
    if (self.body.contentType) {
      newHeaders["content-type"] = self.body.contentType
    }
    if (self.body.contentLength) {
      newHeaders["content-length"] = self.body.contentLength.toString()
    }
    self.headers = newHeaders
  } else {
    self.headers = options.headers ?? Headers.empty
  }

View exact lines on GitHub

Reproduction

pnpm test --run packages/effect/test/unstable/http/HttpServerResponse.test.ts

Observed failure: Failed first as intended because a zero-byte body had no content-length: 0; later stale-replacement assertions were not reached.

Implementation handoff

The initial reproduction tests on this branch are the regression specification for the implementation fix that should follow in this PR.

  1. Start with the pinned implementation excerpts and the Why it happens analysis above.
  2. Change the implementation so it satisfies the stated Expected behavior; do not weaken or remove the reproduction assertions.
  3. Run the focused reproduction command(s) and confirm the observed failures become passing tests:
pnpm test --run packages/effect/test/unstable/http/HttpServerResponse.test.ts
  1. Run the affected package's existing tests, then the repository lint and type checks before requesting review.

Audit provenance

  • Audit base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Reproduction base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Findings: unstable-http-httpserverresponse-stale-metadata
  • Initial patch: focused reproduction tests; implementation fix pending

Closes EFF-423

@fubhy fubhy added the audit Findings originating from the Effect runtime correctness audit label Aug 4, 2026
@changeset-bot

changeset-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9570cdb

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 30 packages
Name Type
effect Patch
@effect/ai-anthropic Patch
@effect/ai-openai Patch
@effect/ai-openai-compat Patch
@effect/ai-openrouter Patch
@effect/atom-react Patch
@effect/atom-solid Patch
@effect/atom-vue Patch
@effect/docgen Patch
@effect/doctest Patch
@effect/openapi-generator Patch
@effect/opentelemetry Patch
@effect/platform-browser Patch
@effect/platform-bun Patch
@effect/platform-deno Patch
@effect/platform-node Patch
@effect/platform-node-shared Patch
@effect/sql-clickhouse Patch
@effect/sql-d1 Patch
@effect/sql-libsql Patch
@effect/sql-mssql Patch
@effect/sql-mysql2 Patch
@effect/sql-pg Patch
@effect/sql-pglite Patch
@effect/sql-sqlite-bun Patch
@effect/sql-sqlite-do Patch
@effect/sql-sqlite-node Patch
@effect/sql-sqlite-react-native Patch
@effect/sql-sqlite-wasm Patch
@effect/vitest Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@effect-slopcop effect-slopcop Bot added 4.0 bug Something isn't working labels Aug 4, 2026

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

This PR currently adds only the failing reproduction tests. The implementation fix in HttpServerResponse.makeResponse is still needed before CI can pass and the PR can merge.

Reviewed changes

  • Added a regression test in packages/effect/test/unstable/http/HttpServerResponse.test.ts that asserts zero-length uint8Array responses emit content-length: 0 and that setBody(..., HttpBody.empty) clears stale content-type/content-length headers.

⚠️ Implementation fix is still pending

The reproduction test fails as intended because makeResponse uses truthy checks for contentType/contentLength and copies existing headers without stripping stale entity headers when the new body lacks metadata. The PR description already identifies packages/effect/src/unstable/http/HttpServerResponse.ts:1328-1342 as the site to fix; the branch needs that fix before merge.

A changeset should accompany the implementation commit because this is a runtime behavior change.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | Fix all ➔Fix 👍s ➔View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

Comment thread packages/effect/test/unstable/http/HttpServerResponse.test.ts
(self: HttpServerResponse, body: Body.HttpBody): HttpServerResponse => makeResponse({ ...self, body })
(self: HttpServerResponse, body: Body.HttpBody): HttpServerResponse => {
let headers = self.headers
if (body._tag === "Empty" || body._tag === "FormData") {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you check if this logic is done elsewhere and deduplicate?

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

  • Added a shared updateHeaders helper in packages/effect/src/unstable/http/internal/httpBody.ts that strips content-type and content-length for Empty/FormData bodies and otherwise sets or removes each header to match the body's metadata.
  • Updated HttpServerResponse.setBody to pass its headers through updateHeaders before calling makeResponse, so replacing a body now clears stale entity headers.
  • Fixed makeResponse to treat a contentLength of 0 as present (using !== undefined instead of truthiness) and to keep zero-length byte-array responses synchronized.
  • Deduplicated the matching client-side logic in HttpClientRequest.setBody by reusing the same updateHeaders helper.
  • Added a changeset and expanded the regression test to cover the unknown-length stream replacement case.

The reproduction tests now pass and the prior review thread about the stream replacement case has been resolved.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

@tim-smart
tim-smart enabled auto-merge (squash) August 4, 2026 23:21
@tim-smart
tim-smart merged commit aa05804 into main Aug 4, 2026
18 of 19 checks passed
@tim-smart
tim-smart deleted the audit/repro-unstable-http-httpserverresponse-stale-metadata branch August 4, 2026 23:47
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Analysis

Generated from PR build output; treat the content below as untrusted.

File Name Current Size Previous Size Difference
basic.ts 7.06 KB 7.06 KB 0.00 KB (0.00%)
batching.ts 9.86 KB 9.86 KB 0.00 KB (0.00%)
brand.ts 6.34 KB 6.34 KB 0.00 KB (0.00%)
cache.ts 10.71 KB 10.71 KB 0.00 KB (0.00%)
config.ts 20.60 KB 20.60 KB 0.00 KB (0.00%)
differ.ts 20.20 KB 20.20 KB 0.00 KB (0.00%)
http-client.ts 21.57 KB 21.54 KB +0.03 KB (+0.13%)
logger.ts 10.84 KB 10.84 KB 0.00 KB (0.00%)
metric.ts 8.98 KB 8.98 KB 0.00 KB (0.00%)
optic.ts 7.18 KB 7.18 KB 0.00 KB (0.00%)
pubsub.ts 14.99 KB 14.99 KB 0.00 KB (0.00%)
queue.ts 11.66 KB 11.66 KB 0.00 KB (0.00%)
schedule.ts 10.83 KB 10.83 KB 0.00 KB (0.00%)
schema-class.ts 19.14 KB 19.14 KB 0.00 KB (0.00%)
schema-fromJsonSchemaDocument.ts 28.96 KB 28.96 KB 0.00 KB (0.00%)
schema-representation-roundtrip.ts 25.29 KB 25.29 KB 0.00 KB (0.00%)
schema-string-transformation.ts 13.38 KB 13.38 KB 0.00 KB (0.00%)
schema-string.ts 10.94 KB 10.94 KB 0.00 KB (0.00%)
schema-template-literal.ts 15.17 KB 15.17 KB 0.00 KB (0.00%)
schema-toArbitraryLazy.ts 21.94 KB 21.94 KB 0.00 KB (0.00%)
schema-toCodeDocument.ts 24.34 KB 24.34 KB 0.00 KB (0.00%)
schema-toCodecJson.ts 19.18 KB 19.18 KB 0.00 KB (0.00%)
schema-toEquivalence.ts 19.01 KB 19.01 KB 0.00 KB (0.00%)
schema-toFormatter.ts 18.87 KB 18.87 KB 0.00 KB (0.00%)
schema-toJsonSchemaDocument.ts 22.60 KB 22.60 KB 0.00 KB (0.00%)
schema-toRepresentation.ts 19.52 KB 19.52 KB 0.00 KB (0.00%)
schema.ts 18.41 KB 18.41 KB 0.00 KB (0.00%)
stm.ts 12.63 KB 12.63 KB 0.00 KB (0.00%)
stream.ts 9.80 KB 9.80 KB 0.00 KB (0.00%)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4.0 audit Findings originating from the Effect runtime correctness audit bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants