Skip to content

build(deps): update the napi crates now that the WASI target is gone - #602

Merged
derodero24 merged 1 commit into
developfrom
build/issue-518-update-napi-crates
Oct 3, 2026
Merged

derodero24 merged 1 commit into
developfrom
build/issue-518-update-napi-crates

Conversation

@derodero24

@derodero24 derodero24 commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Problem: napi, napi-derive and napi-build were pinned to =3.9.1 / =3.5.6 / =2.3.2, and a Renovate rule disabled them. Newer releases export emnapi_create_env / emnapi_delete_env for the wasm32-wasip1-threads target, and only the emnapi 2 alpha provides those symbols (build(wasi): napi-build 2.4 exports emnapi_create_env, which needs @emnapi/core 2 (alpha) #518). The WASI target is now gone (RFC: drop the napi wasm32-wasip1-threads target in favour of the wasm-bindgen build #571, merged in build: stop building the wasm32-wasip1-threads target #600), so nothing holds the crates back.
  • Change:
    • Cargo.toml goes back to the major-version requirements that the pins replaced ("3" / "2" / "3"), the same style as the other workspace dependencies.
    • Cargo.lock moves to napi 3.13.0, napi-derive 3.6.9 and napi-build 2.5.0, with napi-sys 3.3.2, napi-derive-backend 6.1.4 and convert_case 0.12.0. On Unix, napi now also uses the libc crate, which was already in the lockfile. No other crate changes version and no duplicate versions appear.
    • The lockfile deliberately stays one release behind the latest set (napi 3.14.0, napi-derive 3.6.10, napi-build 2.6.0, napi-sys 3.4.0). Those were published on 2026-10-01, less than the 3-day minimumReleaseAge that the Renovate configuration applies, and their changes after 3.13.0 / 3.6.9 / 2.5.0 only concern the WASI target. Renovate proposes them once they are old enough.
    • The enabled: false Renovate rule for the three crates is removed and nothing else in renovate.json changes; ci(renovate): toolchain-sensitive updates are automerged and the flate2 pin is overridden #575 regroups them.
  • User-visible fix (Bun and Deno):
    • Since napi 3.11 / napi-derive 3.6, every #[napi] class instance carries a Node-API type tag, which is checked before a method uses the instance's native state.
    • Node.js already rejects a method called with an instance of another class as this ("Illegal invocation"). Bun and Deno run the method anyway.
    • With the old crates, ZstdCompressContext.prototype.transform.call(new GzipCompressContext(), data) used the gzip state as zstd state. Bun 1.3.14 and Deno 2.9.6 crashed with a segmentation fault, with both debug and release builds.
    • The call now throws an InvalidArg error: "Value is not an instance of class ZstdCompressContext".
  • Other upstream changes reviewed (napi and napi-derive changelogs, plus source diffs of napi async_work.rs, buffer.rs, arraybuffer.rs and module_register.rs, napi-sys and napi-build):
    • None of them breaks this addon. Most concern WASI or APIs that comprs does not use.
    • Changes that reach the addon but cause no difference visible from JS here:
      • async work completion is guarded against Worker teardown (3.12.7);
      • Buffer references are released through a per-environment handle;
      • on Windows MSVC, if the executable does not export Node-API, symbol lookup falls back to the libnode/node modules.
    • The BufferSlice advisory fixed in 3.12.3 (GHSA-3hv5-cch8-c72w) does not affect comprs, which does not use BufferSlice.
    • On native targets, napi-build only adds cargo::rustc-check-cfg lines.
    • Errors from sync and async functions (constructor, name, code, message) are identical between the old and new binaries.
  • Performance:
    • Calls into the addon cost slightly more. Measured on release builds, Linux x64, Node 22, best of 5 (3.9.1 against the latest set; 3.13.0 differs from it only for WASI):
      • crc32 on 16 bytes: about 125 ns → 165 ns;
      • Lz4CompressContext#transform on 16 bytes: about 0.9 µs → 1.1 µs;
      • lz4Compress on 64 KiB: no change within noise.
    • CodSpeed only benchmarks the Rust core, so it is not affected.
  • Generated files: after a rebuild, index.js and index.d.ts are byte-identical, so there is no generator change to commit.
  • MSRV:
  • Tests:
    • New Bun and Deno end-to-end test "context methods reject an instance of another context class". It calls ZstdCompressContext#transform and GzipCompressContext#finish with an instance of the other class as this and expects an error.
    • With the 3.9.1 binary, both runtimes crash in that test (segmentation fault). With this branch it passes.
    • There is no Vitest spec, because Node.js throws "Illegal invocation" with either version.
  • Notes:
    • With the rule gone, the napi crates fall under the existing automerged rust-dependencies group until ci(renovate): toolchain-sensitive updates are automerged and the flate2 pin is overridden #575 moves them into a reviewed napi-rs toolchain group.
    • Not run locally:
      • cross-target and release (LTO) builds, which CI runs for all eight targets because Cargo.lock changed;
      • build:wasm-bindgen / test:wasm, because crates/wasm and its dependencies are unchanged;
      • the cargo-deny advisories check, because there is no access to the advisory DB here. OSV lists no advisories for napi 3.9.1 or 3.13.0.

Related issue

Closes #518
Part of #535

Breaking changes / Deprecations

N/A

Checklist

  • Lint passes (pnpm run check): the only diagnostic, the biome.json recommended deprecation info, already exists on develop
  • TypeScript type-check passes (pnpm run typecheck); the middleware typecheck passes too
  • JS tests pass (pnpm test): 21 files, 665 tests on Node 22 and on Node 24; Bun 1.3.14 10/10 and Deno 2.9.6 10/10 (--allow-ffi --allow-read --allow-env), re-run with the 3.13.0 lockfile
  • Rust tests pass (cargo test): 137 passed (cargo test --workspace); cargo fmt --all -- --check passes
  • Clippy passes (cargo clippy): no warnings with --all-targets -- -W clippy::all
  • Build succeeds (pnpm run build): verified with pnpm run build:debug (index.js / index.d.ts byte-identical, no generated-file changes); release (LTO) and cross-target builds are left to CI
  • Changeset included (if crates/ changed): .changeset/update-napi-crates.md (patch)
  • Benchmarks run for performance-sensitive changes: call-overhead micro-benchmarks on release builds (see Performance above); CodSpeed covers only the Rust core, which this PR does not change

🤖 Generated with Claude Code

https://claude.ai/code/session_01DRi2Qu5rPjQSDBcR8xmkSS

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 27 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d8dc54bb-359d-4b1e-b323-bd13b322b2c7
📥 Commits

Reviewing files that changed from the base of the PR and between 4f19597 and 527a918.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (5)
  • .changeset/update-napi-crates.md
  • Cargo.toml
  • e2e/bun.test.ts
  • e2e/deno.test.ts
  • renovate.json
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

WASM Binary Size

File Size
comprs-wasm_bg.wasm 2103 KB

napi, napi-derive and napi-build were pinned to 3.9.1, 3.5.6 and 2.3.2,
and Renovate was told to ignore them, because later releases export
emnapi_create_env and emnapi_delete_env for the wasm32-wasip1-threads
target, which only the emnapi 2 alpha provides. That target is no
longer built, so nothing holds the crates back.

Restore the major-version requirements that the pins replaced and
update Cargo.lock to napi 3.13.0, napi-derive 3.6.9 and napi-build
2.5.0, with napi-sys 3.3.2, napi-derive-backend 6.1.4 and convert_case
0.12.0. None of the releases in between is breaking for this addon,
and a rebuild generates the same index.js and index.d.ts. The lockfile
stays one release behind the latest (napi 3.14.0, napi-derive 3.6.10,
napi-build 2.6.0, napi-sys 3.4.0): those were published less than the
three days that the Renovate configuration waits before adopting a
release, and they only change the WASI target. Renovate proposes them
once they are old enough.

One change fixes a crash. Since napi 3.11 every #[napi] class instance
carries a Node-API type tag that is checked before a method uses the
instance's native state. Node.js already rejects a method called with
an instance of another class as `this` ("Illegal invocation"), but Bun
and Deno run it. With the old crates, a call such as
ZstdCompressContext.prototype.transform.call(gzipContext, chunk) then
used the gzip state as zstd state and crashed the process with a
segmentation fault; it now throws an InvalidArg error. The Bun and Deno
end-to-end tests cover this. The newer crates add a little to each
call into the addon, a fraction of a microsecond in a release build.

The new crates declare rust-version 1.88, as the pinned ones did, so
the minimum Rust version needed to build the addon does not change.
The workspace still declares 1.85, which #581 corrects.

Remove the Renovate rule that disabled the three crates, so they are
updated with the other Rust crates again; #575 regroups them.

Closes #518

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRi2Qu5rPjQSDBcR8xmkSS
@derodero24
derodero24 force-pushed the build/issue-518-update-napi-crates branch from b716e88 to 527a918 Compare October 3, 2026 15:31
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

WASM Binary Size

File Size
comprs-wasm_bg.wasm 2103 KB

@derodero24
derodero24 merged commit 54bf460 into develop Oct 3, 2026
36 checks passed
@derodero24
derodero24 deleted the build/issue-518-update-napi-crates branch October 3, 2026 15:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

build(wasi): napi-build 2.4 exports emnapi_create_env, which needs @emnapi/core 2 (alpha)

2 participants