No description
Find a file
Matt Van Horn b9286a7346
fix: Drop invalid UTF-8 scanner candidates (#20389)
## Summary

Replace the three unchecked scanner conversions in
`crates/oxide/src/scanner/mod.rs` with checked conversions that omit
only extracted slices that are not valid UTF-8. Apply the check in the
shared `extract` pipeline so initial scans, incremental `scan_content`
calls, and CSS-variable extraction cannot insert invalid strings into
scanner state, and apply the same policy to both branches of
`get_candidates_with_positions` while preserving byte offsets and the
legacy `-[]` restoration. Keep the extractor's byte-oriented CSS
identifier classification unchanged: accepting non-ASCII bytes during
extraction is useful for valid multibyte code points, while the
conversion boundary is the authoritative place to enforce the `String`
contract.

The scanner currently converts extracted byte slices with unchecked
UTF-8 constructors at the shared extraction boundary and both
candidate-with-position branches. A source file containing a stray
continuation byte can therefore produce an invalid `String`, violating
Rust's string invariant and allowing corrupted candidates to persist in
a long-lived scanner. The thread provides a deterministic reproduction
using invalid bytes inside an arbitrary value, so the problem no longer
depends on reproducing the originally reported Turbopack race. Valid
candidates found alongside malformed byte sequences must continue to be
returned normally.

Fixes #20368

## Test plan

Not applicable to this change.

AI was used for assistance.

---------

Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
Co-authored-by: Robin Malfait <malfait.robin@gmail.com>
2026-08-13 13:01:13 +02:00
.github Bump dependencies (#20381) 2026-08-04 13:55:03 +02:00
crates fix: Drop invalid UTF-8 scanner candidates (#20389) 2026-08-13 13:01:13 +02:00
integrations Don't scan ignored folders using .gitignore safelist setup (#20397) 2026-08-07 17:44:33 +02:00
packages test: fix 'with with' typo in css parser tests (#20410) 2026-08-13 11:05:30 +02:00
patches Use wasm as a fallback for @tailwindcss/oxide (#20383) 2026-08-04 18:41:43 +02:00
playgrounds migrate to pnpm v11 (#20273) 2026-06-25 19:14:10 +02:00
scripts migrate to pnpm v11 (#20273) 2026-06-25 19:14:10 +02:00
.gitignore Fix slow unit test (#17465) 2025-03-31 15:26:01 +02:00
.prettierignore Bump dependencies (#19608) 2026-02-04 12:38:50 +01:00
Cargo.lock Visualize scanner related tests (#20412) 2026-08-13 12:45:40 +02:00
Cargo.toml Hoist oxide/crates to just crates (#13333) 2024-03-23 09:00:48 -04:00
CHANGELOG.md fix: Drop invalid UTF-8 scanner candidates (#20389) 2026-08-13 13:01:13 +02:00
LICENSE Add README, LICENSE, and CONTRIBUTING (#13088) 2024-03-05 14:45:39 -05:00
package.json Bump dependencies (#20381) 2026-08-04 13:55:03 +02:00
pnpm-lock.yaml Use wasm as a fallback for @tailwindcss/oxide (#20383) 2026-08-04 18:41:43 +02:00
pnpm-workspace.yaml Use wasm as a fallback for @tailwindcss/oxide (#20383) 2026-08-04 18:41:43 +02:00
README.md docs: fix GitHub links to tailwindlabs org (#19686) 2026-02-17 13:06:49 +01:00
rust-toolchain.toml Bump NAPI related dependencies (#19982) 2026-04-26 17:49:06 +02:00
turbo.json Bump dependencies (#20381) 2026-08-04 13:55:03 +02:00
vitest.config.mts Bump dependencies (#20381) 2026-08-04 13:55:03 +02:00

Tailwind CSS

A utility-first CSS framework for rapidly building custom user interfaces.

Build Status Total Downloads Latest Release License


Documentation

For full documentation, visit tailwindcss.com.

Community

For help, discussion about best practices, or feature ideas:

Discuss Tailwind CSS on GitHub

Contributing

If you're interested in contributing to Tailwind CSS, please read our contributing docs before submitting a pull request.