Skip to content

chore(deps): update node toolchain (asdf + oracle container + xfuse image) to v24.21.0 - #45

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/node-toolchain-(asdf-+-oracle-container-+-xfuse-image)
Sep 21, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/node-toolchain-(asdf-+-oracle-container-+-xfuse-image)

Conversation

@renovate

@renovate renovate Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
node (source) container minor 24.20.0-alpine → 24.21.0-alpine
node (source) final minor 24.20.0-bookworm-slim → 24.21.0-bookworm-slim
node (source) minor 24.20.0 → 24.21.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

nodejs/node (node)

v24.21.0: 2026-09-08, Version 24.21.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [71106e1f17] - crypto: update root certificates to NSS 3.126 (Node.js GitHub Bot) #​65495
  • [afca0a912d] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #​63949
  • [6274fccbd9] - deps: update OpenSSL to 3.5.8 (Node.js GitHub Bot) #​65542
  • [53cba013c7] - deps: update Undici to 7.29.1 (Node.js GitHub Bot) #​65789
  • [0529772798] - (SEMVER-MINOR) lib,src: improve histogram implementation (James M Snell) #​65024
  • [41c7062b81] - (SEMVER-MINOR) net: improve performance of net.BlockList (James M Snell) #​64974
  • [5197b5a3c5] - (SEMVER-MINOR) perf_hooks: add statistical hypothesis testing to histogram (James M Snell) #​65416
  • [35c635b032] - (SEMVER-MINOR) util: add non-throwing MIMEType.parse (James M Snell) #​64965
Commits

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/node-toolchain-(asdf-+-oracle-container-+-xfuse-image) branch from afedf37 to 935c153 Compare September 9, 2026 22:05
@renovate renovate Bot changed the title chore(deps): update node.js to v24.21.0 chore(deps): update node toolchain (asdf + oracle container + xfuse image) Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/node-toolchain-(asdf-+-oracle-container-+-xfuse-image) branch 19 times, most recently from 124e1c7 to 6f20eaf Compare September 19, 2026 13:55
@renovate
renovate Bot force-pushed the renovate/node-toolchain-(asdf-+-oracle-container-+-xfuse-image) branch 9 times, most recently from 4a4cd8d to e4353f4 Compare September 20, 2026 21:32
@renovate
renovate Bot force-pushed the renovate/node-toolchain-(asdf-+-oracle-container-+-xfuse-image) branch 3 times, most recently from 2b9b9e7 to 7fe7097 Compare September 21, 2026 02:58
schmonz pushed a commit that referenced this pull request Sep 21, 2026
…its own patch

scripts/gen-node-constants.mjs has carried a staleness ratchet since it was
written: the host's fs/os constants cannot supply the cross-platform UNION the
patch needs, but any name the HOST has that NODE_CONSTANTS lacks is precisely the
"node grew a constant" signal, and the generator exits 1 on it. It only ever ran
when somebody ran the generator, which is when you already know.

So node 24.21.0's four new fs names (Renovate #45, toolchain bump) reached CI as
two red tjs ORACLE legs reporting `fs.missing: [UV_FS_O_RANDOM, ...]` — true, and
silent about the fix being "re-transcribe node's NODE_DEFINE_CONSTANT list".

A second staleness has been sitting in the tree meanwhile: 97a3fe6 renamed a word
inside the comment this generator emits and did not regenerate, so the committed
txiki-node-constants.patch has not been what its generator produces since. Nothing
compares the two — the same shape as the src/js/** patches that were silently
dropped because regeneration was opt-in (0c72693).

`--check` answers both and writes nothing. Regenerating needs the txiki vendor
tree, but the text spliced into signals.c is computed from this file alone, so the
freshness question needs no vendor tree, no engine, and no network: hoist the
include block to module scope beside the body, recompute the added lines, and
compare them to the committed patch's. RED right now on the 97a3fe6 drift:

    added lines: patch 619, generator 619
    first difference at added line 46:
      patch:     "... rather than fusing a quaude that is subtly"
      generator: "... rather than blobulating a quaude that is subtly"

The hoist is behavior-neutral: regenerating before and after produces byte-identical
output.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BVks4skLBgHSDcjnQ4kHz6
schmonz pushed a commit that referenced this pull request Sep 21, 2026
…d not

Renovate #45 bumps the toolchain node 24.20.0 -> 24.21.0 and goes red on exactly
two rows, the node-shim-oracle legs on linux and darwin:

    node-shim constants: the gap inventory matches the reviewed golden
      fs.missing: [UV_FS_O_RANDOM, UV_FS_O_SEQUENTIAL, UV_FS_O_SHORT_LIVED,
                   UV_FS_O_TEMPORARY]

Diffing node's src/node_constants.cc v24.20.0..v24.21.0: those four names are the
only constant change in the entire file. They join UV_FS_O_FILEMAP under a new
comment, "Windows-only open flags honored by libuv. They are 0 on other platforms."

So the shim really is behind node, and the fix is the transcription, not a wider
golden. Widening would retire the row: off Windows these are 0, but ON Windows an
absent UV_FS_O_TEMPORARY OR'd into an open-flag mask yields NaN, and a NaN mask is
the silent misclassification this inventory exists to catch.

Emitted like UV_FS_O_FILEMAP, #ifdef with a 0 fallback rather than node's unguarded
form: libuv defines all five everywhere (uv/win.h -> _O_*, uv/unix.h -> 0), but a
leg whose libuv or cosmo compat header predates the unix zero-defines would hard-
fail the compile unguarded, and a plain #ifdef would let the key vanish where node
has it. 0 is node's own answer off Windows, so the fallback is not a guess.

No ABI bump: the shim requires nothing new from the engine (engine-constants.cjs
passes the tables through), and engine reuse is keyed on the recipe hash, which
this moves — c68c7da2 -> 8098dab7, measured staged. All 42 legs rebuild; that is
the correct cost of an engine-source change.

RED, node 24.21.0 against the engine built from the old patch: the gap inventory
reported those four under `fs.missing`, and `gen-node-constants.mjs --check` exited
1 naming them. GREEN after: the rebuilt engine reports 59 fs keys, exactly host
24.21.0's 59, with all four present; the patch applies ("patch
txiki-node-constants.patch: applied"); both rows pass under 24.20.0 and 24.21.0.

The list stays hand-transcribed ON PURPOSE and cannot be derived from a host: it is
node's cross-platform UNION, and every host's keys are already #ifdef-filtered down
to that host. Deriving here would delete O_DIRECT, O_NOATIME, SIGPOLL, SIGPWR,
SIGSTKFLT, SIGBREAK, SIGUNUSED and RTLD_DEEPBIND, all real on legs this mac cannot
see. The derivable part is the staleness signal, and that is now gated (3b1bc37).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BVks4skLBgHSDcjnQ4kHz6
schmonz pushed a commit that referenced this pull request Sep 21, 2026
The toolchain packageRule's description claimed two mechanisms neither rule
implemented: "package.json engines.node is EXCLUDED deliberately" (no rule
gave it its own group, so PR #45 swept it into the toolchain's branch
anyway) and an allowedVersions clamp holding the group to available Docker
Hub images (the actual gap behind the 2026-08-27 `manifest unknown`
incident).

Added a packageRule for matchDepTypes:["engines"] + matchDepNames:["node"],
placed after the toolchain group so it wins, giving package.json's embedded
node its own branch the way #30/#31 rode separately before the group
existed -- a re-group, not a policy change to what gets bumped or how.

allowedVersions is NOT added: a correct value would have to track which
node:*-alpine/bookworm-slim tags Docker Hub has published, which is not
derivable from anything in this repo and isn't a static range or regex --
inventing one risks silently holding back an eligible bump, which is
exactly the policy change this task was scoped to avoid. The description is
corrected to say the gap is open instead of claiming it's closed.

test/node-pins-agree.test.cjs gains renovate-rules-agree-with-description,
a guard asserting a mechanism the toolchain rule's own description NAMES is
backed by an actual rule -- the same "config prose that no rule implements"
class this repo has now found in ~17 places. RED against the real pre-fix
file: 2 findings (both gaps, exactly). GREEN after.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BVks4skLBgHSDcjnQ4kHz6
@renovate
renovate Bot force-pushed the renovate/node-toolchain-(asdf-+-oracle-container-+-xfuse-image) branch from 7fe7097 to 7f8620c Compare September 21, 2026 04:53
@renovate renovate Bot changed the title chore(deps): update node toolchain (asdf + oracle container + xfuse image) chore(deps): update node toolchain (asdf + oracle container + xfuse image) to v24.21.0 Sep 21, 2026
@renovate
renovate Bot merged commit 71fbad3 into main Sep 21, 2026
49 checks passed
@renovate
renovate Bot deleted the renovate/node-toolchain-(asdf-+-oracle-container-+-xfuse-image) branch September 21, 2026 12:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants