Skip to content

fix(s390x): use json-escape-simd 3.1.1 for big-endian JSON escaping fix#10211

Merged
IWANABETHATGUY merged 4 commits into
rolldown:mainfrom
satyamg1620:s390x
Jul 10, 2026
Merged

fix(s390x): use json-escape-simd 3.1.1 for big-endian JSON escaping fix#10211
IWANABETHATGUY merged 4 commits into
rolldown:mainfrom
satyamg1620:s390x

Conversation

@satyamg1620

Copy link
Copy Markdown
Contributor

What this solves

Bumps json-escape-simd to 3.1.1, which fixes JSON string escaping on big-endian targets (s390x).

The crate's portable SIMD fallback (used on s390x — no SSE2/AVX/NEON) built its lane bitmask with a bit order inconsistent with how the first-escape offset was read back. On big-endian this corrupted escaped output — e.g. "node:module""node:modle\0\4…" — breaking sourcemaps, ESM import paths, and asset/data-URL escaping. In debug builds it panics (attempt to subtract with overflow in json-escape-simd); in release it silently corrupts output.

It reaches rolldown two ways, both fixed by this single bump:

  • directlycrates/rolldown/src/ecmascript/format/esm.rs, parse_to_ecma_ast.rs
  • transitivelyoxc_sourcemapjson-escape-simd

Root cause fixed upstream in napi-rs/json-escape-simd#88 and released as 3.1.1 (the earlier 3.1.0 is buggy, so the requirement is pinned to 3.1.1).

Alternatives explored

Interim we vendored the crate and used [patch.crates-io] (first a local copy, then a fixed fork). This PR drops all of that in favour of the published 3.1.1.

For reviewers

  • The bug only manifests on big-endian, so existing tests don't fail on x86 CI.
  • rolldown CI currently cross-builds s390x but never runs the suite on big-endian — which is why this shipped undetected.

Tests

The existing utils::render_ecma_module::tests::* (sourcemap) tests already cover this — they panic without this bump and pass with it when run on s390x. No new test is added because the failure is not reproducible on x86 CI (byte-order specific). Verified natively on s390x: cargo test --workspace --exclude rolldown_binding → previously-panicking tests pass, 1805 passed.

@socket-security

socket-security Bot commented Jul 9, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcargo/​json-escape-simd@​3.1.0 ⏵ 3.1.110010093100100

View full report

@codspeed-hq

codspeed-hq Bot commented Jul 9, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 7 untouched benchmarks
⏩ 10 skipped benchmarks1


Comparing satyamg1620:s390x (de2c063) with main (1e7c9a8)

Open in CodSpeed

Footnotes

  1. 10 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

@netlify

netlify Bot commented Jul 10, 2026

Copy link
Copy Markdown

Deploy Preview for rolldown-rs canceled.

Name Link
🔨 Latest commit de2c063
🔍 Latest deploy log https://app.netlify.com/projects/rolldown-rs/deploys/6a507b8670d67c000872e8b0

@IWANABETHATGUY
IWANABETHATGUY merged commit 279c03b into rolldown:main Jul 10, 2026
33 checks passed
@rolldown-guard rolldown-guard Bot mentioned this pull request Jul 15, 2026
shulaoda added a commit that referenced this pull request Jul 15, 2026
## [1.2.0] - 2026-07-15

### 🚀 Features

- dev: skip shipping factories for newly imported top-level modules (#10223) by @h-a-n-a
- dev: per-client ship map for HMR patch sizing (#10208) by @h-a-n-a
- dev: client-side HMR (#10164) by @h-a-n-a
- dev: send a full-reload update to clients when a tsconfig changes (#10262) by @shulaoda
- treat `import.meta['url']` and `import.meta['ROLLUP_FILE_URL_*']` as side-effect free (#10267) by @sapphi-red
- rewrite `import.meta['url']` (#10251) by @sapphi-red
- add `FILE_NOT_FOUND` error (#10220) by @sapphi-red
- treat `import.meta.ROLLUP_FILE_URL_*` as side-effect free (#10217) by @sapphi-red

### 🐛 Bug Fixes

- sourcemap: preserve unmapped boundaries during composition (#10254) by @hyfdev
- `[format]` in `*FileNames` option for ESM format should be `es` instead of `esm` (#10214) by @sapphi-red
- sourcemap: preserve coarse mappings during composition (#10249) by @hyfdev
- rolldown_plugin_vite_import_glob: support tsconfig paths with `import.meta.glob` (#10167) by @sapphi-red
- dev: clear tsconfig caches for bare full builds (#10276) by @shulaoda
- dev: force a full rebuild when a tsconfig changes (#10261) by @shulaoda
- treat rooted drive-less module ids as absolute in preserveModules naming (#10235) by @IWANABETHATGUY
- watch: rebuild when tsconfig files change (#10258) by @shulaoda
- watch: drop tsconfig-merged transform options on each rebuild (#10257) by @shulaoda
- incorrect `EMPTY_IMPORT_META` warning for `import.meta.ROLLUP_FILE_URL_*` for CJS output (#10221) by @sapphi-red
- deconflict: rename CJS locals shadowing wrapped-ESM namespace objects (#9970) by @IWANABETHATGUY
- rolldown: drop the unused runtime module after entry-level external flattening (#10237) by @IWANABETHATGUY
- rolldown: re-propagate has_dynamic_exports to transitive star importers (#10239) by @IWANABETHATGUY
- tree-shaking: tree-shake destructured dynamic import namespace bindings (#10213) by @logaretm
- s390x: use json-escape-simd 3.1.1 for big-endian JSON escaping fix (#10211) by @satyamg1620

### 🚜 Refactor

- dev: move full-reload to client side (#10207) by @h-a-n-a
- readability follow-ups to the ReplaceWith migration (#10286) by @IWANABETHATGUY
- replace take_in-then-write-back with ReplaceWith and by-value moves (#10285) by @Boshen
- share the main resolver's cache with the transformer's tsconfig lookups (#10205) by @shulaoda
- rolldown: extract the ns star-external __reExport emission rule into LinkingMetadata (#10238) by @IWANABETHATGUY
- rolldown: unify link/generate diagnostics into a Diagnostics accumulator (#10234) by @IWANABETHATGUY
- sourcemap_filenames: drop dead sourcemap-filename plumbing (#10189) by @IWANABETHATGUY
- extract external import symbol merging into a method (#10224) by @IWANABETHATGUY
- rolldown: skip CJS namespace merging under strict execution order (#10203) by @hyfdev
- resolve the manual tsconfig per file instead of once at startup (#10200) by @shulaoda
- rolldown: route interop ESM init emission through a shared init-target view (#10202) by @hyfdev
- rolldown: collapse vestigial wrap-kind state and share chunk sort helper (#10201) by @hyfdev

### 📚 Documentation

- show plugin kinds in JSDoc and each hook's description (#10218) by @sapphi-red
- add an explanation about removing imports from external modules without any messages (#10215) by @sapphi-red

### ⚡ Performance

- sourcemap: owned merge in SourceJoiner::join (4005->5 allocs/chunk) (#10250) by @Boshen
- avoid redundant sourcemap string copies in collapse and minify paths (#10093) by @Boshen

### 🧪 Testing

- code-splitting: establish strict-order review baselines (#10287) by @hyfdev
- dev: add hot API test cases (#10181) by @h-a-n-a
- code-splitting: normalize strict execution order variants (#10277) by @hyfdev
- code-splitting: harden strict execution order coverage (#10252) by @hyfdev
- code-splitting: add strict execution order regressions (#10253) by @hyfdev

### ⚙️ Miscellaneous Tasks

- deps: update github actions (#10241) by @renovate[bot]
- deps: update oxc to 0.140.0 (#10274) by @shulaoda
- update Yunfei's GitHub username (#10275) by @hyfdev
- deps: update napi (#10260) by @renovate[bot]
- deps: update test262 submodule for tests (#10266) by @rolldown-guard[bot]
- deps: update dependency vite-plus to v0.2.4 (#10256) by @renovate[bot]
- deps: update napi (#10240) by @renovate[bot]
- deps: update oxc resolver to v11.24.2 (#10245) by @renovate[bot]
- deps: update rust crates (#10244) by @renovate[bot]
- disable Renovate updates for idna_adapter (#10248) by @shulaoda
- deps: update oxc resolver to v11.24.1 (#10232) by @renovate[bot]
- deps: update rust crate oxc_sourcemap to v8.1.1 (#10233) by @renovate[bot]
- deps: update dependency rolldown-plugin-dts to ^0.27.0 (#10206) by @renovate[bot]
- deps: upgrade sugar_path to v3 (#10230) by @hyfdev
- add `dist-*` to `.gitignore` in sourcemap-filenames/hash-final-content fixture (#10216) by @sapphi-red
- deps: update dependency rust to v1.97.0 (#10209) by @renovate[bot]

### ❤️ New Contributors

* @satyamg1620 made their first contribution in [#10211](#10211)

Co-authored-by: shulaoda <[email protected]>
satyamg1620 added a commit to satyamg1620/agentgateway that referenced this pull request Jul 20, 2026
… binding from fork

- pprof 0.15 frame-pointer feature doesn't compile on s390x (call site not
  arch-gated); enable it only on x86_64/aarch64/riscv64/loongarch64, falling
  back to pprof's default unwinder elsewhere.
- Regenerate Cargo.lock consistent with the tokio git patch so --locked builds
  (Dockerfile builder stage) don't fail.
- Dockerfile.s390x: add rolldown-s390x stage building the s390x binding from the
  fork carrying the big-endian fix (rolldown/rolldown#10211), add cmake for
  mimalloc, and reference upstream s390x-prebuilt PRs for lightningcss/oxide.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
satyamg1620 added a commit to satyamg1620/agentgateway that referenced this pull request Jul 21, 2026
… binding from fork

- pprof 0.15 frame-pointer feature doesn't compile on s390x (call site not
  arch-gated); enable it only on x86_64/aarch64/riscv64/loongarch64, falling
  back to pprof's default unwinder elsewhere.
- Regenerate Cargo.lock consistent with the tokio git patch so --locked builds
  (Dockerfile builder stage) don't fail.
- Dockerfile.s390x: add rolldown-s390x stage building the s390x binding from the
  fork carrying the big-endian fix (rolldown/rolldown#10211), add cmake for
  mimalloc, and reference upstream s390x-prebuilt PRs for lightningcss/oxide.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
satyamg1620 added a commit to satyamg1620/agentgateway that referenced this pull request Jul 21, 2026
… binding from fork

- pprof 0.15 frame-pointer feature doesn't compile on s390x (call site not
  arch-gated); enable it only on x86_64/aarch64/riscv64/loongarch64, falling
  back to pprof's default unwinder elsewhere.
- Regenerate Cargo.lock consistent with the tokio git patch so --locked builds
  (Dockerfile builder stage) don't fail.
- Dockerfile.s390x: add rolldown-s390x stage building the s390x binding from the
  fork carrying the big-endian fix (rolldown/rolldown#10211), add cmake for
  mimalloc, and reference upstream s390x-prebuilt PRs for lightningcss/oxide.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Signed-off-by: satyamg1620 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants