zlib: createZstdCompress appends an empty frame when end() is called with writes still queued
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 68/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- cpp, javascript, node.js
- Domain
- backend, performance
Research direction
Start with the supplied JavaScript reproduction, then read lib/zlib.js, especially ZlibBase#_transform and _flush. Inspect ZstdCompressContext::DoThreadPoolWork in src/node_zlib.cc and compare the queued-write path with gzip and brotli behavior. Done means createZstdCompress emits one frame with identical bytes for one or multiple writes and no trailing empty frame.
Written by the indexing model from the issue text.
Description
Version
v26.9.0 (also v24.15.0)
Platform
Darwin 25.6.0 arm64 (also seen on Linux x64)
Subsystem
zlib
What steps will reproduce the bug?
'use strict';
const zlib = require('node:zlib');
function compress(create, writes) {
return new Promise((resolve, reject) => {
const stream = create();
const chunks = [];
stream.on('data', (chunk) => chunks.push(chunk));
stream.on('end', () => resolve(Buffer.concat(chunks)));
stream.on('error', reject);
for (const w of writes) stream.write(w);
stream.end();
});
}
(async () => {
const oneWrite = await compress(zlib.createZstdCompress, ['hello world']);
const twoWrites = await compress(zlib.createZstdCompress, ['hello ', 'world']);
console.log('one write: ', oneWrite.toString('hex'));
console.log('two writes:', twoWrites.toString('hex'));
console.log('extra bytes:', twoWrites.subarray(oneWrite.length).toString('hex'));
// Same input, queued writes: gzip and brotli are unaffected.
for (const [name, create, decompress] of [
['gzip', zlib.createGzip, zlib.gunzipSync],
['brotli', zlib.createBrotliCompress, zlib.brotliDecompressSync],
]) {
const a = await compress(create, ['hello world']);
const b = await compress(create, ['hello ', 'world']);
console.log(name, 'lengths', a.length, b.length, decompress(b).toString());
}
})();
How often does it reproduce? Is there a required condition?
Every time end() is called while at least one write is still queued in the compressor. In practice that is most pipelines whose source ends quickly, e.g. pipeline(tar.create(...), zlib.createZstdCompress(), fs.createWriteStream(...)): every archive we packed that way had the extra frame.
What is the expected behavior? Why is that the expected behavior?
One zstd frame, the same bytes whether the input arrived in one write or several:
one write: 28b52ffd005859000068656c6c6f20776f726c64
two writes: 28b52ffd005859000068656c6c6f20776f726c64
That's what gzip and brotli do. How the input was split into writes shouldn't change the compressed output.
What do you see instead?
one write: 28b52ffd005859000068656c6c6f20776f726c64
two writes: 28b52ffd005859000068656c6c6f20776f726c6428b52ffd2000010000
extra bytes: 28b52ffd2000010000
gzip lengths 31 31 hello world
brotli lengths 15 15 hello world
A second, empty zstd frame (28b52ffd 20 00 01 00 00: magic, single-segment descriptor with content size 0, one empty raw last block) is appended.
Additional information
I think the cause is in lib/zlib.js:
- In
ZlibBase#_transform, whenthis.writableEnded && this.writableLength === chunk.byteLength, the last queued chunk is processed with_finishFlushFlag, which ends the frame. ZlibBase#_flushthen calls_transformagain with an empty buffer.writableEndedis still true andwritableLengthis 0, so that call gets the finish flag too.
For deflate and brotli a second finish on a finished stream emits nothing. For zstd, ZSTD_compressStream2(..., ZSTD_e_end) on a context whose frame has just completed starts and completes a new frame. ZstdCompressContext::DoThreadPoolWork in src/node_zlib.cc doesn't guard against that. When end() is called with nothing queued, the frame is only finished once, so the output is a single frame.
The extra frame is valid zstd, but it has real consequences:
- The output depends on stream timing, not content. We hash the archive for deduplication, so identical inputs can hash differently.
- In released versions (including v26.9.0),
createZstdDecompressthrowsUnknown frame descriptorwhen a read chunk boundary falls inside those 9 bytes. Withfs.createReadStream's default 64 KiB chunks, that's about 1 archive in 8,200, and it fails the same way every time. We hit this in production on an archive thatzstd -tandzstdDecompressSyncboth accept. I believe #65865 fixes the decoding side onmain, but the compressor still writes the extra frame.
Our workaround is to strip a trailing 28b52ffd2000010000 after compressing.
- Dominant language
- JavaScript
- Stars
- 122k
- Forks
- 37.4k
- Avg merge
- 4d 4h
- Merged PRs (30d)
- 276
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from nodejs/node
-
doc
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
build
Difficulty 1/5 Under an hour Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
-
feature request
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Similar issues
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
githubnext/gh-aw-workshop#3692 ·
-
agent/guide documentation hive/hosted-available-lke648397-260827-5n31
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
-
Add: BuyPass TV Openchannels:add check:passed
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
S: triage
Difficulty 1/5 Under an hour Newbie friendliness 85/100
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 90/100
apache/cloudstack#14222 ·