fix(aws-lambda): copy base64 bodies out of Node's shared Buffer pool - #92
Conversation
@standard-server/aws-lambda
@standard-server/core
@standard-server/fastify
@standard-server/fetch
@standard-server/node
@standard-server/peer
@standard-server/shared
commit: |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Merging this PR will not alter performance
Comparing Footnotes
|
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
- Base64 body copy in the aws-lambda adapter —
packages/aws-lambda/src/body.ts:37now wrapsBuffer.from(event.body, 'base64')innew Uint8Array(...), so the enqueued chunk owns a private, exactly-sizedArrayBufferinstead of a slice of Node's shared 64 KiB pool. The misleadingas Uint8Array<ArrayBuffer>cast is gone. - Regression test —
packages/aws-lambda/src/body.test.ts:139reads the first streamed chunk and assertsbyteOffset === 0,buffer.byteLength === byteLength, and content. I confirmed empirically that pre-fix code yields a 65536-byte backing buffer against a 6-byte chunk, so the assertion fails on the old code rather than being theatre.
The fix is correct (new Uint8Array(typedArray) copies element-wise, unlike the ArrayBuffer constructor overload), applies uniformly to every hint that consumes bytes, and there are no other Buffer.from(..., 'base64') sites in packages/. Mergeable as-is.
DeepSeek Flash (default — pick a model for stronger reviews) | 𝕏

Base64-decoded Lambda request bodies were streamed as a
Buffer.from(string)slice of Node's shared allocation pool. Because a warm Lambda process serves many invocations, that pool still holds other requests' bytes, so any consumer that touched the chunk's.buffer(for exampleBuffer.from(chunk.buffer),new DataView(chunk.buffer), or apostMessagetransfer) could read them or detach the pool process-wide. The adapter now copies the decoded bytes into a privateUint8Array, matching what the node adapter already does.Fixes
ArrayBuffersized exactly to the body;.bufferno longer exposes neighbouring invocations' data.as Uint8Array<ArrayBuffer>cast is gone; the type now reflects an actual plainArrayBuffer.Testing
aws-lambdasuite, eslint, andtsc -bare green.