Skip to content

perf: match only unpaired surrogates when escaping HTML - #16407

Merged
Rich-Harris merged 2 commits into
sveltejs:version-3from
Nic-Polumeyv:perf-escape-surrogates
Jul 18, 2026
Merged

Rich-Harris merged 2 commits into
sveltejs:version-3from
Nic-Polumeyv:perf-escape-surrogates

Conversation

@Nic-Polumeyv

Copy link
Copy Markdown
Contributor

Resolves the TODO in escape.js from #4024, which planned to simplify the surrogate pattern with lookbehind assertions once widely supported. Lookbehind has been safe everywhere relevant since Safari 16.4, but \p{Surrogate} with the u flag is simpler still and supported even longer (ES2018). Under the u flag a valid surrogate pair forms a single astral code point, so \p{Surrogate} matches only unpaired surrogates and the pattern's other two branches disappear, including the branch that existed only to match valid pairs so the replace callback could return them unchanged.

That branch is also why this is a perf change rather than a cleanup. Every valid pair in rendered content currently invokes the replace callback just to pass through. With the new pattern pairs never match, so escape_html measures about 2x faster on emoji-heavy content in a quick microbench, with plain ASCII at parity.

Output is unchanged. I diffed the old and new implementations over 200k fuzzed strings built from surrogate halves, dict characters and astral pairs, plus curated edge cases, in both modes, all byte-identical. escape.spec.js passes as-is.


Please don't delete this checklist! Before submitting the PR, please make sure you do the following:

  • It's really useful if your PR references an issue where it is discussed ahead of time. In many cases, features are absent for a reason. For large changes, please create an RFC: https://github.com/sveltejs/rfcs
  • This message body should clearly illustrate what problems it solves.
  • Ideally, include a test that fails without this PR but passes with it.

Tests

  • Run the tests with pnpm test and lint the project with pnpm lint and pnpm check

Changesets

  • If your PR makes a change that should be noted in one or more packages' changelogs, generate a changeset by running pnpm changeset and following the prompts. Changesets that add features should be minor and those that fix bugs should be patch. Please prefix changeset messages with feat:, fix:, or chore:.

Edits

  • Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed.

@pkg-svelte-dev

pkg-svelte-dev Bot commented Jul 18, 2026

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from 29ac8ca:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/29ac8cae9564fac5960dad2b62d72e03fd3cf843

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/16407

Note

This PR is from a fork. A maintainer must approve approve each commit before it can be built and installed.

@changeset-bot

changeset-bot Bot commented Jul 18, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 29ac8ca

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@Nic-Polumeyv
Nic-Polumeyv force-pushed the perf-escape-surrogates branch from 1ce40e3 to 675006c Compare July 18, 2026 15:25
@Nic-Polumeyv
Nic-Polumeyv marked this pull request as ready for review July 18, 2026 15:36

@Rich-Harris Rich-Harris left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

love it!

@Rich-Harris
Rich-Harris merged commit 6446f64 into sveltejs:version-3 Jul 18, 2026
17 of 18 checks passed
Rich-Harris pushed a commit that referenced this pull request Jul 20, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/kit@3.0.0-next.11

### Major Changes

- breaking: `config` exported from a universal route file takes
precedence over a server one
([#16400](#16400))

- breaking: consistent special filename patterns
([#16382](#16382))

### Minor Changes

- feat: support sourcemaps in production
([#16412](#16412))

- feat: support function validators for environment variables
([#16402](#16402))

- feat: better error logging
([#16374](#16374))

### Patch Changes

- fix: don't treat callable standard schemas as function param matchers
([#16403](#16403))

- fix: reject malformed streamed data encoding
([#16423](#16423))

- fix: hide stack traces for internal errors like 404s
([#16411](#16411))

- perf: match only unpaired surrogates when escaping HTML
([#16407](#16407))

- fix: don't report empty environment variables as missing
([#16401](#16401))

- chore: clarify which hooks run during server route resolution
([#16397](#16397))
## @sveltejs/adapter-node@6.0.0-next.5

### Minor Changes

- feat: better error logging
([#16374](#16374))

### Patch Changes

- Updated dependencies
[[`5220191`](5220191),
[`8cb2f7d`](8cb2f7d),
[`b88c7a7`](b88c7a7),
[`a6ea113`](a6ea113),
[`6446f64`](6446f64),
[`58f1789`](58f1789),
[`09774a2`](09774a2),
[`c542fdd`](c542fdd),
[`aedaa27`](aedaa27),
[`428ee1a`](428ee1a),
[`fefb3ae`](fefb3ae)]:
  - @sveltejs/kit@3.0.0-next.11

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@Nic-Polumeyv
Nic-Polumeyv deleted the perf-escape-surrogates branch July 30, 2026 22:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants