Skip to content
Commit Detail

Commit 8b01b21

Author
Erik Corry <ecorry@cloudflare.com> 2026-04-22 16:47:10 +0200
Parents
56f0376
Tree
987c0ee
Websockets: Wrap the ongoingAutoResponse so it gets destructed on the IO thread.

The WebSocket::AutoResponse struct holds a bare kj::Promise<void>
(ongoingAutoResponse) directly on the JS heap. When V8's GC collects a
WebSocketPair, the destructor chain reaches this promise under
DISALLOW_KJ_IO_DESTRUCTORS_SCOPE, and if the promise holds a real async node (a
ForkBranch from ws.send().fork()), destroying it triggers a fatal "KJ async
object being destroyed when not allowed" error (Sentry 37914510). The fix wraps
the promise in kj::Maybe<IoOwn<kj::Promise<void>>> so that destruction is
deferred to the IoContext's delete queue, following the same pattern already
used by outgoingMessages.

Files changed

2 files changed~2 modified