Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 12, 2025

Bumps github.com/valyala/fasthttp from 1.65.0 to 1.66.0.

Release notes

Sourced from github.com/valyala/fasthttp's releases.

v1.66.0

What's Changed

New Contributors

Full Changelog: valyala/fasthttp@v1.65.0...v1.66.0

Commits
  • e04490f Add flushing support to fasthttpadaptor (#2054)
  • e9640b4 Update benchmarks in readme
  • 4d25421 Drop Go 1.23 support (#2065)
  • 72dccd0 Fix extra whitespace parsing in HTTP request lines to prevent cache poisoning...
  • 8c7d2bc chore(deps): bump actions/setup-go from 5 to 6 (#2060)
  • 28b7880 server: refactor to use atomic type (#2058)
  • 68d21ed docs: add fasthttp-auth to related projects section (#2057)
  • 7ad0219 chore(deps): bump securego/gosec from 2.22.7 to 2.22.8 (#2056)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/valyala/fasthttp](https://github.com/valyala/fasthttp) from 1.65.0 to 1.66.0.
- [Release notes](https://github.com/valyala/fasthttp/releases)
- [Commits](valyala/fasthttp@v1.65.0...v1.66.0)

---
updated-dependencies:
- dependency-name: github.com/valyala/fasthttp
  dependency-version: 1.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Copy link
Contributor

coderabbitai bot commented Sep 12, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@ReneWerner87
Copy link
Member

we have failed unittests
image

they are related to pprof and the fasthttp adpator
@grivera64 there is only your change https://github.com/valyala/fasthttp/pull/2054/files
related to the adaptor in 1.66
maybe you can help us to understand and fix this

@ReneWerner87
Copy link
Member

ReneWerner87 commented Sep 17, 2025

image image ---

@erikdubbelboer Just so you know, it might also be a bug in the new release.
Perhaps you can help here too.

@grivera64
Copy link
Member

@ReneWerner87 I was taking a look at the workflow failing earlier this week. The error seems to be due to trying to re-close a recycled netHTTPResponseWriter. Since w.Close() is called on the release of the writer, it isn't necessary to close it at that point, so I think it can safely be removed.

I think the stem of the issue is releasing the writer while still having a reference to it (since Close() and reset() are both being called at the same time).

An idea I have is to use wait group to ensure wait until both the ServeHTTP AND/OR SetBodyStreamWriter() and other concurrent tasks are done, then we can recycle the writer.

Do you have any ideas on how we can mimic the pprof setup as a unit test for fasthttpadaptor/adaptor_test.go to verify that this will fix the issue? I've tried making several mock test connections to an endpoint within a single test, but I get connection timeout errors rather than the current error here when I do this.

@grivera64
Copy link
Member

grivera64 commented Sep 18, 2025

I've made a draft PR with a fix: valyala/fasthttp#2069

I still need to finish writing a new unit test to detect this kind of bug from within fasthttp, so it is still marked as a draft for now.

@ReneWerner87 From the failed workflows, app.Test() is just called in a sequential loop to test all endpoints in the pprof middleware, right? If so, I could just do the same by adding a test where a loop calls the same (or different) endpoints several times.

I was initially trying to make a test that takes concurrent calls, but I don't think that is needed if the pprof tests caught the error within a sequential loop.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants