lib: fix validatePort to reject string '0' when allowZero is false#62836
Open
deepview-autofix wants to merge 1 commit intonodejs:mainfrom
Open
lib: fix validatePort to reject string '0' when allowZero is false#62836deepview-autofix wants to merge 1 commit intonodejs:mainfrom
deepview-autofix wants to merge 1 commit intonodejs:mainfrom
Conversation
The `port === 0 && !allowZero` check used strict equality, so the
string `'0'` (and other numeric-zero string forms like `'0x0'`) slipped
through because `'0' === 0` is `false`. As a result,
`validatePort('0', name, false)` returned `0`, contradicting the
`allowZero=false` contract and letting callers such as
`dgram.Socket#connect('0', ...)` proceed past the validator and fail
deep in the stack with `EADDRNOTAVAIL` while leaking the handle.
Compare the numeric coercion (`+port === 0`) so all numeric-zero forms
are rejected consistently.
Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: DeepView Autofix <276251120+deepview-autofix@users.noreply.github.com>
Co-Authored-By: Nikita Skovoroda <chalkerx@gmail.com>
Signed-off-by: Nikita Skovoroda <chalkerx@gmail.com>
ChALkeR
reviewed
Apr 20, 2026
ChALkeR
reviewed
Apr 20, 2026
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #62836 +/- ##
==========================================
- Coverage 89.62% 89.62% -0.01%
==========================================
Files 706 706
Lines 219136 219136
Branches 41987 41984 -3
==========================================
- Hits 196404 196395 -9
- Misses 14611 14619 +8
- Partials 8121 8122 +1
🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The
port === 0 && !allowZerocheck used strict equality, so the string'0'(and other numeric-zero string forms like'0x0') slipped through because'0' === 0isfalse. As a result,validatePort('0', name, false)returned0, contradicting theallowZero=falsecontract and letting callers such asdgram.Socket#connect('0', ...)proceed past the validator and fail deep in the stack withEADDRNOTAVAILwhile leaking the handle.Compare the numeric coercion (
+port === 0) so all numeric-zero forms are rejected consistently.