Skip to content

feat: production sourcemaps#16412

Merged
Rich-Harris merged 10 commits into
version-3from
sourcemaps
Jul 19, 2026
Merged

feat: production sourcemaps#16412
Rich-Harris merged 10 commits into
version-3from
sourcemaps

Conversation

@Rich-Harris

@Rich-Harris Rich-Harris commented Jul 18, 2026

Copy link
Copy Markdown
Member

Follow-up to #16374. Wanted to do this for a long time. Slightly experimental — anything sourcemap-related always needs battle-testing — but I'm reasonably sure it won't do any harm in cases where it doesn't work perfectly.

Whereas #16374 made sourcemaps work during prerendering, this makes them work in production generally, which includes prerendering and vite preview. It applies three changes:

  • it traces locations back to the source on a best-effort basis
  • it makes paths relative to the cwd — much shorter and more readable, but still cmd-clickable
  • it truncates the framework's internal stack frames from the bottom

Additionally, it configures Vite to generate sourcemaps for the server build (but allows that config to be overwritten, if someone really doesn't want sourcemaps for whatever reason).

This is vite preview on version-3...

image

...and this is on this branch:

image

It's not bulletproof. Taking adapter-node as an example, if the emitted build directory was deployed without the .svelte-kit directory alongside it, it wouldn't be able to trace all the way back to the source. For that to happen, we would need to do something like add a method on builder that bundled the sourcemaps, or moved (and adjusted) them to a new location that could be shipped with the build.

Similarly if an adapter moves files around, or does an additional bundling step without generating sourcemaps, there's not much we can do.

But these are fixable things that we can address once this layer is in place, and we shouldn't let perfect be the enemy of the good.


Please don't delete this checklist! Before submitting the PR, please make sure you do the following:

Tests

  • Run the tests with pnpm test and lint the project with pnpm lint and pnpm check

Changesets

  • If your PR makes a change that should be noted in one or more packages' changelogs, generate a changeset by running pnpm changeset and following the prompts. Changesets that add features should be minor and those that fix bugs should be patch. Please prefix changeset messages with feat:, fix:, or chore:.

Edits

  • Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed.

@pkg-svelte-dev

pkg-svelte-dev Bot commented Jul 18, 2026

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from 955ae8c:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/955ae8c2bd6c49f18949c9187d4e2f4ba937f42e

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/16412

@changeset-bot

changeset-bot Bot commented Jul 18, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 955ae8c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@svelte-docs-bot

Copy link
Copy Markdown

@Nic-Polumeyv

Copy link
Copy Markdown
Contributor

I think I found a bug. A crafted URL flips a 404 into a 500.

curl --path-as-is '/nope'               # 404, fine
curl --path-as-is '/file:///a%2Fb:9:9'  # 500
TypeError [ERR_INVALID_FILE_URL_PATH]: File URL path must not include encoded / characters
    at Object.fileURLToPath (node:internal/url:...)
    at .../runtime/server/sourcemaps.js:34

The cause is that fix_stack_trace runs its file:// regex over every line of error.stack, including line 0, the message. The 404's message is Not found: /file:///a%2Fb:9:9, which is URL-controlled, so it matches and fileURLToPath throws on the encoded slash. Nothing catches it, so it escapes handle_error_and_jsonify and the outer handler downgrades to a 500. Any error message ending in a file://...:n:n shape trips it, the encoded slash is just the easiest way in.

I think either guard fixes it: only tracing real at frames so the message line is never fed to fileURLToPath, or wrapping the trace in try/catch since it's best-effort anyway (get_source_map already swallows its own failures).

Comment thread packages/kit/src/runtime/server/internal.js Outdated
Comment thread packages/kit/src/runtime/server/sourcemaps.js Outdated
Comment thread packages/kit/src/runtime/server/sourcemaps.js
Comment thread packages/kit/src/runtime/server/sourcemaps.js Outdated
Comment thread packages/kit/src/runtime/server/sourcemaps.js Outdated

@teemingc teemingc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Some minor comments but LGTM

EDIT: might want to add the guard like Nic's comment suggests but that should be simple enough

Comment on lines +3 to +7
// using `getBuiltinModule` rather than `import` makes this safe to run in non-Node-compatible environments
const fs = globalThis.process?.getBuiltinModule?.('node:fs');
const url = globalThis.process?.getBuiltinModule?.('node:url');
const path = globalThis.process?.getBuiltinModule?.('node:path');
const module = globalThis.process?.getBuiltinModule?.('node:module');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unrelated to this PR: we might end up running most of this in the Vite dev server process and communicating the result back to the app runtime process since we can't use these Node.js APIs in for example, workerd, anyway

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah admittedly I hadn't thought about how this interacts with the environment API. On version-3 we just override the fix_stack_trace implementation during dev

@Rich-Harris
Rich-Harris merged commit 5220191 into version-3 Jul 19, 2026
17 of 18 checks passed
@Rich-Harris
Rich-Harris deleted the sourcemaps branch July 19, 2026 18:31
Rich-Harris pushed a commit that referenced this pull request Jul 20, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/[email protected]

### Major Changes

- breaking: `config` exported from a universal route file takes
precedence over a server one
([#16400](#16400))

- breaking: consistent special filename patterns
([#16382](#16382))

### Minor Changes

- feat: support sourcemaps in production
([#16412](#16412))

- feat: support function validators for environment variables
([#16402](#16402))

- feat: better error logging
([#16374](#16374))

### Patch Changes

- fix: don't treat callable standard schemas as function param matchers
([#16403](#16403))

- fix: reject malformed streamed data encoding
([#16423](#16423))

- fix: hide stack traces for internal errors like 404s
([#16411](#16411))

- perf: match only unpaired surrogates when escaping HTML
([#16407](#16407))

- fix: don't report empty environment variables as missing
([#16401](#16401))

- chore: clarify which hooks run during server route resolution
([#16397](#16397))
## @sveltejs/[email protected]

### Minor Changes

- feat: better error logging
([#16374](#16374))

### Patch Changes

- Updated dependencies
[[`5220191`](5220191),
[`8cb2f7d`](8cb2f7d),
[`b88c7a7`](b88c7a7),
[`a6ea113`](a6ea113),
[`6446f64`](6446f64),
[`58f1789`](58f1789),
[`09774a2`](09774a2),
[`c542fdd`](c542fdd),
[`aedaa27`](aedaa27),
[`428ee1a`](428ee1a),
[`fefb3ae`](fefb3ae)]:
  - @sveltejs/[email protected]

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants