1. Jan 13, 2014
  2. Jan 11, 2014
  3. Jan 10, 2014
  4. Jan 09, 2014
  5. Jan 08, 2014
  6. Jan 07, 2014
  7. Jan 05, 2014
    • ayanamist's avatar
      stream: writes may return false but forget to emit drain · b922b5e9
      ayanamist authored
      If a write is above the highWaterMark, _write still manages to
      fully send it synchronously, _writableState.length will be adjusted down
      to 0 synchronously with the write returning false, but 'drain' will
      not be emitted until process.nextTick.
      
      If another small write which is below highWaterMark is issued before
      process.nextTick happens, _writableState.needDrain will be reset to false,
      and the drain event will never be fired.
      
      So we should check needDrain before setting it up, which prevents it
      from inproperly resetting to false.
      b922b5e9
  8. Jan 01, 2014
  9. Dec 31, 2013
  10. Dec 28, 2013
  11. Dec 26, 2013
  12. Dec 21, 2013
  13. Dec 20, 2013
  14. Dec 19, 2013
    • Timothy J Fontaine's avatar
      2013.12.18, Version 0.10.24 (Stable) · b7fd6bc8
      Timothy J Fontaine authored
      * uv: Upgrade to v0.10.21
      
      * npm: upgrade to 1.3.21
      
      * v8: backport fix for CVE-2013-{6639|6640}
      
      * build: unix install node and dep library headers (Timothy J Fontaine)
      
      * cluster, v8: fix --logfile=%p.log (Ben Noordhuis)
      
      * module: only cache package main (Wyatt Preul)
      b7fd6bc8
    • Timothy J Fontaine's avatar
      uv: Upgrade to v0.10.21 · 9371be0a
      Timothy J Fontaine authored
      9371be0a
    • Ben Noordhuis's avatar
      cluster, v8: fix --logfile=%p.log · 2eaef9f6
      Ben Noordhuis authored
      The %p is replaced with the current PID.  This used to work in node.js
      v0.9.7 but it seems to have been lost somewhere along the way.
      
      This commit makes the fix from 6b713b52 ("cluster: make --prof work for
      workers") work again.  Without it, all log data ends up in a single
      file and is unusable because the addresses are all wrong.
      2eaef9f6
    • Timothy J Fontaine's avatar
      build: unix install node and dep library headers · 32478acf
      Timothy J Fontaine authored
      Restores functionality from v0.8 where module authors may not be
      relying on gyp for building their modules.
      32478acf
  15. Dec 18, 2013
    • isaacs's avatar
      npm: upgrade to 1.3.21 · 2a741f2d
      isaacs authored
      2a741f2d
    • isaacs's avatar
      npm: upgrade to 1.3.20 · e10c223e
      isaacs authored
      The 1.3.19 release had a critical bug: any packages published with it
      could not be installed, because the shasum would be incorrect.
      
      Thankfully, 1.3.19 was published using 1.3.19, so could not be installed
      by any users!  However, if it goes out as part of a Node.js release,
      then obviously that would be a problem.
      e10c223e
  16. Dec 17, 2013
  17. Dec 14, 2013
    • jkummerow@chromium.org's avatar
      v8: backport fix for CVE-2013-{6639|6640} · 39e2426b
      jkummerow@chromium.org authored
      Quoting CVE-2013-6639:
      
          The DehoistArrayIndex function in hydrogen-dehoist.cc in Google V8
          before 3.22.24.7, as used in Google Chrome before 31.0.1650.63,
          allows remote attackers to cause a denial of service (out-of-bounds
          write) or possibly have unspecified other impact via JavaScript code
          that sets the value of an array element with a crafted index.
      
      Quoting CVE-2013-6640:
      
          The DehoistArrayIndex function in hydrogen-dehoist.cc in Google V8
          before 3.22.24.7, as used in Google Chrome before 31.0.1650.63,
          allows remote attackers to cause a denial of service (out-of-bounds
          read) via JavaScript code that sets a variable to the value of an
          array element with a crafted index.
      
      Like 6b92a7, this is unlikely to affect node.js because it only runs
      local, trusted code.  However, if there exists some module somewhere
      that populates an array index with remotely provided data this could
      very well be used to crash a remote server running node.  Defense in
      depth and all.
      
      This is a backport of upstream commit r17801. Original commit log:
      
          Limit size of dehoistable array indices
      
          LOG=Y
          BUG=chromium:319835,chromium:319860
          R=dslomov@chromium.org
      
          Review URL: https://codereview.chromium.org/74113002
      39e2426b
  18. Dec 13, 2013
  19. Dec 12, 2013