Skip to content

fix: reject malformed streamed data encoding#16423

Merged
Rich-Harris merged 2 commits into
sveltejs:version-3from
scarab-systems:scarab-systems/sveltekit-15511-data-json-corruption
Jul 19, 2026
Merged

fix: reject malformed streamed data encoding#16423
Rich-Harris merged 2 commits into
sveltejs:version-3from
scarab-systems:scarab-systems/sveltekit-15511-data-json-corruption

Conversation

@scarab-systems

@scarab-systems scarab-systems commented Jul 19, 2026

Copy link
Copy Markdown
Contributor

Related to #15511.

Summary

Thanks for SvelteKit. I really appreciate the care that goes into this project.

This PR tightens streamed __data.json parsing so newline-delimited JSON data is decoded with fatal UTF-8 handling. Previously, malformed UTF-8 bytes could be decoded as replacement characters and then surface later as JSON.parse syntax errors. With this change, malformed stream encoding is rejected at the decoding boundary instead of being parsed as corrupted JSON text.

The diagnostic path that led to this patch traced the streamed response across the raw bytes -> UTF-8 text -> NDJSON record -> JSON parse boundary. That pointed at the byte-to-text transition as the useful place to fail fast, rather than changing the later JSON parsing path.

I also added regression coverage for the streamed-data parser:

  • split UTF-8 code points across chunks still parse correctly
  • malformed UTF-8 is rejected before JSON parsing

I did not have a reliable end-to-end reproduction of the original timing/network conditions described in #15511. The issue notes that the full problem has been difficult to reproduce, so this PR focuses on the malformed UTF-8 / NDJSON boundary shown by the replacement-character failures in the report. Happy to adjust the scope, wording, or test shape if you would prefer a different framing.

Validation

Passed:

  • pnpm -F @sveltejs/kit test:unit
  • pnpm lint after rerunning with a larger Node heap because the default local heap hit an OOM during repo-wide ESLint
  • pnpm check
  • git diff --check

Also run:

  • KIT_E2E_BROWSER=chromium pnpm run test:kit

That package-level browser/integration run reached the Chromium Playwright tests, but failed in packages/kit/test/apps/async on an existing direct http.get / Playwright webServer readiness case with ECONNREFUSED 127.0.0.1:5173. I did not change that area; the new unit regression passed in the focused and full @sveltejs/kit unit runs.


Please don't delete this checklist! Before submitting the PR, please make sure you do the following:

Tests

  • Run the tests with pnpm test and lint the project with pnpm lint and pnpm check

Changesets

  • If your PR makes a change that should be noted in one or more packages' changelogs, generate a changeset by running pnpm changeset and following the prompts. Changesets that add features should be minor and those that fix bugs should be patch. Please prefix changeset messages with feat:, fix:, or chore:.

Edits

  • Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed.

Disclosure: I used AI-assisted coding tools while preparing this PR. I reviewed the changes myself, tested them, and take responsibility for the implementation and any follow-up revisions needed.

@pkg-svelte-dev

pkg-svelte-dev Bot commented Jul 19, 2026

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from 3338528:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/3338528cdaec3a69658fc87f7b86ee026a90ce30

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/16423

Note

This PR is from a fork. A maintainer must approve approve each commit before it can be built and installed.

@changeset-bot

changeset-bot Bot commented Jul 19, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 3338528

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

This change addresses the issue of rejecting malformed streamed data encoding.

@Rich-Harris Rich-Harris left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you!

@Rich-Harris
Rich-Harris merged commit b88c7a7 into sveltejs:version-3 Jul 19, 2026
17 of 18 checks passed
@scarab-systems

scarab-systems commented Jul 19, 2026

Copy link
Copy Markdown
Contributor Author

thank you!

Woohoo! You're Welcome! so pleased we could help with this one!

Rich-Harris pushed a commit that referenced this pull request Jul 20, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/[email protected]

### Major Changes

- breaking: `config` exported from a universal route file takes
precedence over a server one
([#16400](#16400))

- breaking: consistent special filename patterns
([#16382](#16382))

### Minor Changes

- feat: support sourcemaps in production
([#16412](#16412))

- feat: support function validators for environment variables
([#16402](#16402))

- feat: better error logging
([#16374](#16374))

### Patch Changes

- fix: don't treat callable standard schemas as function param matchers
([#16403](#16403))

- fix: reject malformed streamed data encoding
([#16423](#16423))

- fix: hide stack traces for internal errors like 404s
([#16411](#16411))

- perf: match only unpaired surrogates when escaping HTML
([#16407](#16407))

- fix: don't report empty environment variables as missing
([#16401](#16401))

- chore: clarify which hooks run during server route resolution
([#16397](#16397))
## @sveltejs/[email protected]

### Minor Changes

- feat: better error logging
([#16374](#16374))

### Patch Changes

- Updated dependencies
[[`5220191`](5220191),
[`8cb2f7d`](8cb2f7d),
[`b88c7a7`](b88c7a7),
[`a6ea113`](a6ea113),
[`6446f64`](6446f64),
[`58f1789`](58f1789),
[`09774a2`](09774a2),
[`c542fdd`](c542fdd),
[`aedaa27`](aedaa27),
[`428ee1a`](428ee1a),
[`fefb3ae`](fefb3ae)]:
  - @sveltejs/[email protected]

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants