Skip to content

Commit 32c05a7

Browse files
committed
docs(changelog): add 2.4.1 entry
The synced sources are a superset of Node.js v26.8.1, so the README compatibility line moves from v26.7.0.
1 parent ab07020 commit 32c05a7

2 files changed

Lines changed: 16 additions & 2 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,20 @@
22

33
All notable changes to this project will be documented in this file.
44

5+
## [2.4.1](https://github.com/PhotoStructure/node-sqlite/releases/tag/v2.4.1) (2026-09-08)
6+
7+
API compatible with `node:sqlite` from Node.js v26.8.1, plus four fixes landed on `v26.x-staging` but not yet in a Node.js release. SQLite is unchanged at 3.53.4.
8+
9+
### Fixed
10+
11+
- **Options getters that close the database**: a property getter on an options bag runs arbitrary JavaScript in the middle of the call, so `prepare()`, `function()`, `aggregate()`, `deserialize()`, `createSession()`, `applyChangeset()`, and `backup()` now re-check that the database is still open after reading their options (and, for `function()` and `aggregate()`, the callback's `length`) and throw `ERR_INVALID_STATE` if a getter closed it. Previously `applyChangeset()` segfaulted, `createSession()` returned a session on a closed connection, and the others surfaced SQLite misuse errors. Ports [Node.js PR #65595](https://github.com/nodejs/node/pull/65595).
12+
- **`deserialize()` buffer resized from an options getter**: if the getter shrinks or detaches the `buffer` argument's backing store, `deserialize()` throws `ERR_INVALID_STATE` instead of copying past the end of it (previously a segfault). Same upstream PR.
13+
- **Non-integer callback `length`**: `function()` and `aggregate()` throw `ERR_INVALID_ARG_TYPE` when `fn.length`, `options.step.length`, or `options.inverse.length` has been redefined to a non-integer. Previously a non-number was silently treated as varargs. Same upstream PR.
14+
- **Changeset detached mid-apply**: when a `filter` or `onConflict` callback is supplied, `applyChangeset()` copies the changeset before applying it, so a callback that detaches or overwrites the input buffer can no longer hand SQLite freed or zeroed memory. Changesets over 2 GiB are rejected with `ERR_OUT_OF_RANGE`. Ports [Node.js PR #65286](https://github.com/nodejs/node/pull/65286).
15+
- **Closing a session from a callback**: `session.close()` and `session[Symbol.dispose]()` throw `ERR_INVALID_STATE` (`session cannot be closed while in a callback`) when called from any SQLite callback on the same connection: an authorizer, a user-defined function, or a `sqlite.db.query` diagnostics subscriber. SQLite's session module runs `PRAGMA table_xinfo` from inside its pre-update hook while it is still walking the connection's session list, so deleting a session there is a use-after-free. Disposing an already-closed session from a callback remains a no-op. Ports [Node.js PR #65454](https://github.com/nodejs/node/pull/65454).
16+
- **Double free when `function()` or `aggregate()` registration fails**: when `sqlite3_create_function_v2()` or `sqlite3_create_window_function()` rejects a registration (for example a callback whose `length` exceeds `SQLITE_MAX_FUNCTION_ARG`, 1000 in this build), SQLite invokes the user data's `xDestroy` itself. The port freed it a second time and crashed the process instead of throwing `ERR_SQLITE_ERROR`. Found while porting the fixes above; not present in Node.js.
17+
- **Portable Linux prebuild**: `scripts/prebuild-linux-glibc.sh` no longer runs `apt-get` inside the `node:22-bullseye` image, which already ships GCC 10.2, make, and Python 3.9. Debian 11's `bullseye-security` Release file expired on 2026-09-07 (Bullseye LTS ended 2026-08-31), so `apt-get update` failed and blocked the glibc 2.31 prebuild locally and in both release workflows. The script now also removes its build container when a step fails. The glibc 2.31 target is unchanged.
18+
519
## [2.4.0](https://github.com/PhotoStructure/node-sqlite/releases/tag/v2.4.0) (2026-09-02)
620

721
### Added

‎README.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
[![npm version](https://img.shields.io/npm/v/@photostructure/sqlite.svg)](https://www.npmjs.com/package/@photostructure/sqlite)
66
[![CI](https://github.com/photostructure/node-sqlite/actions/workflows/build.yml/badge.svg)](https://github.com/photostructure/node-sqlite/actions/workflows/build.yml)
77

8-
Native SQLite for Node.js 22+. Drop-in replacement for `node:sqlite`. Synced with Node.js v26.7.0 for the latest features including native `Symbol.dispose` resource management.
8+
Native SQLite for Node.js 22+. Drop-in replacement for `node:sqlite`. Synced with Node.js v26.8.1 for the latest features including native `Symbol.dispose` resource management.
99

1010
## Installation
1111

@@ -54,7 +54,7 @@ production.
5454

5555
## Features
5656

57-
- API-compatible with Node.js v26.7.0 built-in `node:sqlite` module\*
57+
- API-compatible with Node.js v26.8.1 built-in `node:sqlite` module\*
5858
- Zero dependencies - native SQLite implementation
5959
- Stable synchronous API with no async overhead on the root entry point
6060
- Native SQLite performance ([benchmarks and tradeoffs](./benchmark/README.md))

0 commit comments

Comments
 (0)