Skip to content

fix(chat): parse long lines of unclosed brackets in linear time - #574

Merged
devswha merged 4 commits into
mainfrom
fix/markdown-inline-quadratic
Oct 7, 2026
Merged

devswha merged 4 commits into
mainfrom
fix/markdown-inline-quadratic

Conversation

@devswha

@devswha devswha commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Change

parseInline in src/lib/markdown.ts took quadratic time on one long line of openers that never close: [a, \(, _a or __a repeated. The chat parses every agent message with it while it draws, so a single such line (a log, a minified blob) froze the tab: about a minute or more per megabyte. It stayed under the 1 s bound the tests use at 48 KB, so nothing failed. #547 hardened this file against other shapes and left this one.

The cause was the single pattern searched over the whole line: from every opener it scans to the end of the line for a closer, fails, and starts again at the next opener.

Now the pattern is tried (sticky) only at places a mark can start. For the three openers whose closer may be far away, it is tried only when a closer is there, and each closer is searched for once and reused for every opener before it:

  • \( needs a \) before the next line break.
  • [ needs ]( at the first ], and a ) ending the address.
  • __ and _ need their closing __ or _ on the line. A __ that only a _ can close is tried as the single-underscore form alone.

The pattern itself is unchanged, so the marks found are the same. While measuring I found two more quadratic shapes with the same cause, [a](b and __a b_ repeated; the same change covers them.

The change is in src/lib/markdown.ts only (a new exported generator inlineMarks that parseInline loops over; the loop body is untouched).

Validation

Time to parse one line, parseMarkdown, main (f8f09d1) against this branch:

Line Bun, main, 192 KB Bun, branch, 1 MB Chrome 151, main, 192 KB Chrome 151, branch, 1 MB
[a repeated 4003 ms 41 ms 9374 ms 54 ms
\( repeated 8069 ms 25 ms 4027 ms 20 ms
_a repeated 4936 ms 19 ms 3592 ms 20 ms
__a repeated 8952 ms 35 ms 9159 ms 29 ms
[a](b repeated 1603 ms 31 ms 5063 ms 27 ms
__a b_ repeated 2140 ms 91 ms 1696 ms 90 ms

Main was not timed at 1 MB for every shape: [a at 1 MB took 111 s there, in the new test. On the branch 8 MB takes 138 to 744 ms in Bun, so the growth is linear.

  • New test in src/lib/markdown.test.ts: each of the four shapes at 1 MB parses within the file's 1 s bound and stays plain text, the two extra shapes parse within it, and for 66,430 short lines inlineMarks finds exactly what one search with the pattern finds. Run against main's parser it fails (Expected: < 1000, Received: 111111); with a closer looked for one place too far, the comparison fails.
  • Output compared with main's parser outside the suite: 8,012,554 inline inputs (exhaustive short lines over six alphabets, plus random lines with links, URLs, code, CJK, emoji and line separators, each with and without links) and 60,000 random documents through parseMarkdown. No difference.
  • HERDR_TEST_MODE=unit bun test ./src/lib/markdown.test.ts: 41 pass, 0 fail.
  • bun run check fast: generated types fresh, typecheck, build, unit tests 1700 pass, 0 fail.

No UI or contract change, so no screenshot or contract test.

e2e added 2 commits October 8, 2026 02:32
parseInline searched the line with one pattern, and that search looks from
every `[`, `\(` and `_` to the end of the line for what closes it. A long
line of them that never close (a log, a minified blob) took a minute per
megabyte and froze the tab, since the chat parses every message as it draws.

The pattern is now tried only where a mark can start, and where its closer
may be far away, only if one is there: each closer is looked for once and
serves every opener before it. The marks found are the same ones.
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: devswha/herdr-web-ui/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 62620297-c1dc-43d8-aff5-059c2086f4ec
📥 Commits

Reviewing files that changed from the base of the PR and between 4e654ac and 882669f.

📒 Files selected for processing (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 5 remain after this review.


📝 Summary

Summary by CodeRabbit

  • Bug Fixes
    • Chat reading no longer freezes when messages contain long runs of unclosed brackets, inline-math markers, or underscores. This improves responsiveness when viewing malformed Markdown, including very large amounts of affected text, while keeping the displayed message appearance unchanged.

Walkthrough

Inline Markdown parsing now uses inlineMarks to find marker matches instead of a global matchAll scan. Regression tests check match equivalence and completion time for long or malformed inputs.

Changes

Markdown Inline Scanning

Layer / File(s) Summary
Scanner and parser integration
src/lib/markdown.ts
inlineMarks scans candidate markers and checks closers with cached forward searches. parseInline consumes its matches.
Scanner regression tests and changelog
src/lib/markdown.test.ts, CHANGELOG.md
Tests compare scanner matches with the previous regex and check long or malformed inputs. The changelog records the reported rendering-time change.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 88266

No unresolved merge-blocking issue is identified. Merge after normal checks.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the primary fix: parsing long lines with unclosed brackets in linear time.
Description check ✅ Passed The description includes complete Change and Validation sections. It explains the failure, implementation, regression coverage, performance results, and why screenshots and contract tests are not appl…
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (1 skipped: 1 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@devswha devswha left a comment •

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review (merge-own lane).

Classification: serious bug fix. One long line of unclosed [, \(, _ or __ froze the chat tab for a minute or more per megabyte, and agents print such lines in logs and minified output.

What I checked:

  • inlineMarks tries the unchanged marker pattern (now sticky) only at positions where an alternative can start (opener covers every alternative's first characters). For \(, [ and _/__ it tries the pattern only when the closer exists before the line ends. Each closer search goes through next(), which caches the last hit, and every call passes a non-decreasing from, so each closer is found once per line. The conditions match the regex: the formula needs \) at or after start + 3 before a .-breaking character. The link needs a non-empty label, ]( at the first ]/newline, and a non-empty target ended by ). A __ with no closing __ is tried as the single-_ form only.
  • Mutations, each run against the new equivalence test: mathClose(start + 4) fails it, and so does emphasisClose(start + 3). labelEnd(start + 2) and strongClose(start + 4) stay green, but they change only which positions skip the full pattern, not the result: the sticky marker re-checks the label, and the emphasis path yields the same span. So these are not coverage gaps.
  • Codex (gpt-6.1-sol, xhigh, adversarial, read-only) found no material issue. It compared 400,000 malformed and Unicode inputs with the old scanner and found no difference.
  • The CHANGELOG entry sits under ## [Unreleased] / ### Fixed, after #572, with its PR link.

What I ran:

  • HERDR_TEST_MODE=unit bun test ./src/lib/markdown.test.ts: 41 pass.
  • Updated the branch with main (merge, CHANGELOG conflict with #572 resolved by keeping both entries; now 4e654ac). bun run check fast on 4e654ac: 1700 pass, 0 fail.
  • On 4e654ac, Integration and browser first failed at scripts/ui-regression.ts:604 ("the message sent before the snapshot is a live pending row"). That assertion is a known timing flake and is unrelated to markdown. One rerun of the failed job passed.
  • main moved again (#563, CHANGELOG conflict) before the merge, so I updated once more to 882669f (CHANGELOG order #566, #572, #563, #574). bun run check fast: 1715 pass, 0 fail. Fast checks and Integration and browser are green on 882669f. There are no review threads, and CodeRabbit had no actionable comments.

@devswha
devswha merged commit a576111 into main Oct 7, 2026
4 checks passed
@devswha
devswha deleted the fix/markdown-inline-quadratic branch October 7, 2026 19:57
devswha added a commit that referenced this pull request Oct 8, 2026
…e notes (#598)

Two changes the owner asked for, one commit each.

## 1. Clipboard from a pane (OSC 52) is on by default

#570 turned **Settings → Terminal → Clipboard from a pane** off by
default, so copying from vim, tmux and Claude Code silently did nothing.
It is on again; the switch stays for anyone running output they do not
trust.

**Migration: a new storage key.** Settings are saved as one whole
record, so any 0.4.1 install whose user changed *any* setting has
`terminalOsc52: false` stored without choosing it. The choice now lives
under `paneClipboard` (default `true`) and `terminalOsc52` is ignored
and dropped by `sanitizeSettings`, which already discards unknown keys.
That is the simplest correct option:
- a 0.4.1 record loads as on (its `false` cannot be told apart from a
real choice, so it is not trusted);
- an off chosen from now on is written under `paneClipboard` and stays
off across saves and reloads;
- no version field or one-off migration state is needed. A settings
version would do the same with more code.

Known edge: a tab still running the 0.4.1 bundle that saves settings
writes its own record, which has no `paneClipboard`, so a new "off"
would read as on again until it is re-chosen. Tabs pick up the new
bundle on reload, and settings already have no cross-tab sync (each tab
saves its in-memory record), so this is no worse than any other setting.

Tests (`src/lib/settings.test.ts`, "clipboard from a pane"): fresh
default on; a 0.4.1 record with `terminalOsc52: false` loads as on; an
off chosen after the change survives a save, a reload and an unrelated
change. A mutation that falls back to the old key fails the second case.

Also: the setting's description and code comments say what is true now,
ko/ja/zh entries are updated, and there is a CHANGELOG line under
Unreleased → Changed. No doc in `docs/`, `DESIGN.md`, `INSTALL.md` or
`README.md` mentions the default.

## 2. Patch-note style GitHub release notes

`scripts/release-notes.ts` printed the whole CHANGELOG section (181
lines for v0.4.1). It now prints the English lists from
`release-summaries.json` (`### New features`, `### Improvements`, `###
Bug fixes`, a list with no lines left out), then the full section inside
`<details><summary>Full changelog</summary>` with blank lines around it
so GitHub renders the markdown. Lines come through `readSummary`, so
they are trimmed and capped exactly as an install shows them. Every
validation is unchanged (version format, the three version sources,
exactly one heading, nonempty notes, all four languages).
`scripts/release-notes.test.ts` pins the shape, the order and an empty
list left out. `docs/development.md` → Releasing and `scripts/AGENTS.md`
describe the new body.

The published v0.4.1 release is not touched here; the lead regenerates
it after the merge.

### v0.4.1 rendered with this script (`bun scripts/release-notes.ts
0.4.1`)

### New features

- Typing /effort in a Claude Code chat opens a card to pick the effort
for this session
- Settings → Appearance can keep waiting and the latest agents on top of
the Agents list
- A finished agent you opened in the web UI can lose its dot, as it
would in herdr (opt-in)
- The guide shows how to give the app a public HTTPS address with Portal

### Improvements

- A wrong access token waits longer after five tries, up to a minute
- A program in a pane copies to your clipboard only once you allow it in
Settings → Terminal
- Dialogs keep Tab inside them, and screen readers announce tabs, panes
and status lines
- Add PC, Reconnect PC and Update remote bridge open as a bottom sheet
on a phone
- Updating a remote PC that is already current reuses its bridge without
a new download
- Alerts go only to https push services and never follow a redirect
- Long drafts wrap, and the scrollbar no longer covers text when the
page is zoomed

### Bug fixes

- A long line of unclosed brackets or broken escape codes no longer
freezes the chat
- On Windows, more Claude Code and Codex panes show their chat instead
of an error
- Your own devices are recognised by their Tailscale login again,
without pairing
- A Claude Code chat shows what a slash command answered, and /goal is
suggested
- Settings, the palette, Add PC and file previews stack in order; Escape
closes the top one
- The plugin's start keeps the app on its port while herdr is away
- A secret or typed text no longer reaches a pane you have already left
- Gajae Code's selection and startup menus show their choices, not only
arrow keys

<details><summary>Full changelog</summary>

### Added
- `/effort` sent from a Claude Code chat opens a card with the effort
levels, low to max, so the
level no longer has to be set in the terminal. A pick applies to this
session only, as a pick
from the `/model` card does, and leaves the default for new sessions
alone. `/effort` is also in
  the chat's command list now.
  ([#594](#594),
  [#523](#523) by @suho-han)
- Settings → Terminal has a **Clipboard from a pane** switch, off by
default: a program running in a
pane can no longer put text on your clipboard unless you turn it on.
Programs that copy this way
  (vim, tmux, Claude Code) copy again once it is on.
  ([#570](#570) by @radicor)
- The guide's **Behind a reverse proxy** shows how to give the app a
public HTTPS address with
[Portal](https://github.com/gosuda/portal-tunnel) v2.6.1 or later,
behind a long random token
  and with a visitor's `Tailscale-User-Login` header dropped.
([#229](#229) by
@rabbitson87)
- **Settings → Appearance → Agents order → Activity** keeps a waiting
agent on top of the Agents
list and orders the rest by their latest state change, as herdr's agents
panel keeps the latest
work in view: the agent you just sent a message to stays on top while it
runs and after it
finishes, and a new one starts there. herdr's own order and the
workspace rows are unchanged.
  **Workspaces** (herdr's order) remains the default.
([#529](#529) by
@phirschybar)
- **Settings → Appearance → Quiet opened finishes** (off by default): a
finished agent you have
opened in the web UI loses its dot and reads as ready, as viewing it in
herdr would make it.
herdr's DONE otherwise stands until herdr itself shows the pane. It is
remembered per PC in
this browser. ([#529](#529)
by @phirschybar)

### Changed
- A wrong access token is refused with a growing wait after five tries,
up to a minute, whether it
is typed into the sign-in form or sent with a request. Each visitor
behind `tailscale serve` has
their own count, and a browser holding an old token never stops you
signing in with the new one.
  ([#570](#570) by @radicor)
- The app now sends itself a Content-Security-Policy, so third-party
content rendered in a chat —
  math, agent marks — cannot run script in the app.
  ([#570](#570) by @radicor)
- A web-push subscription must be an https endpoint.
  ([#570](#570) by @radicor)

### Fixed
- Gajae Code's selection menus show their choices instead of only
arrow-key buttons, including
startup selectors shown before the pane reports that it is waiting.
Answers move to the selected
  row and recheck the menu before confirming.
  ([#593](#593))
- Secret input and the Codex follow-up fallback validate the live
screen, so a password
prompt or collapsed question queue in scrollback cannot send input into
the current program.
  ([#566](#566))
- The PC's Tailscale login is read from a real Tailscale user id. These
ids are too large for a
JavaScript number, so the owner was not recognised and the owner's own
devices had to pair. Two
  logins with neighbouring ids are also no longer taken for one.
  ([#572](#572))
- On Windows, a Claude Code pane started with a second account's
`~/.claude-*` directory as its
`CLAUDE_CONFIG_DIR` shows its chat. Before, the pane fell back to
`~/.claude`, so the chat said
**Conversation unavailable** and only the terminal worked. Windows does
not let the server read
another process's environment, so the store is the one among the
server's own
`CLAUDE_CONFIG_DIR`, `~/.claude` and the `~/.claude-*` directories
beside it that holds the
Claude process's own record, checked against the time the process
started. A directory
elsewhere is not looked in. Claude Code processes reported as
`claude.exe` are
  recognized too.
([#563](#563) by
@David-Sousa-Web)
- A long line of brackets, `\(` or underscores that never close, as an
agent prints in a log or a
minified file, no longer freezes the chat: a megabyte of them took a
minute or more to read, and
  now takes milliseconds. What every message shows is unchanged.
  ([#574](#574))
- On a mirrored pane (Windows, where herdr cannot attach a terminal),
text typed while a message
was still being sent no longer reaches the pane once you have left it,
or left it and opened it
  again, before the text's turn came.
  ([#576](#576))
- The plugin's `start` keeps the app on its port when the app's own
server holds it but cannot
reach herdr. It used to move the app to another port beside the running
one and blame another
program; now it says that the app runs there without herdr and exits,
and the app answers
  again on its port once herdr is back.
  ([#577](#577))
- On Windows, a Codex pane shows its chat when Codex stored its paths
with the `\\?\` prefix, as
it does for a canonical Windows path (`\\?\D:\work` for `D:\work`).
Before, the chat said
**Conversation unavailable**: the session's file seemed to lie outside
Codex's store, and none of
  the threads matched the pane's directory as herdr reports it.
([#582](#582) by
@David-Sousa-Web)
- In a Claude Code pane, the chat shows what a slash command answered,
so a `/goal` that Claude
Code refuses says why in the chat instead of only in the terminal.
`/goal` is also among the
  commands the message box suggests.
  ([#583](#583))
- Settings opened over a file preview is visible above it; Escape and
Back close Settings
first, preserving the preview and its history entry until the file
itself is closed.
  ([#568](#568))
- Command palette buttons keep their native Enter action; IME commit and
cancel keys
stay with text input, and arrow navigation keeps the selected result
visible.
  ([#567](#567))
- Long drafts in the message box wrap and keep a narrow scroll cue in
reserved space, so the
  scrollbar no longer covers text at fractional zoom.
([#522](#522) by @suho-han)
- A secret sent from a pane you then left and opened again, while
another browser kept the pane
open, is no longer typed into the pane: you send it again from the pane
you opened.
  ([#588](#588))
- A Claude Code slash command whose answer holds a long run of broken
terminal escape codes no
longer stalls the server while the chat reads it. Its answer also drops
a link cut off before
its end and a stray `B` after a charset switch, and an answer with both
output and errors
  shows both.
  ([#588](#588))
- The command palette opened over Settings and a file preview shows
above both, instead of
  taking the keyboard unseen beneath them.
  ([#588](#588))
- The plugin's `start` no longer takes another program on the app's port
for the app because
its answer says `ok`: it treats it as any other program there, moving
the app to a free port,
  or saying the port is taken when `PORT` is set.
  ([#588](#588))
- A 500 from the server no longer repeats the system's own error text,
which carried absolute paths
and the herdr socket location; it names a short id you can quote in a
bug report instead.
  ([#570](#570) by @radicor)
- Settings, the command palette, the file viewer, the file browser and
the new-workspace dialog keep
  Tab inside them and give the focus back to whatever opened them.
  ([#570](#570) by @radicor)
- The tabs of a workspace name the pane region they govern, so a screen
reader announces the tab and
  the pane together.
  ([#570](#570) by @radicor)
- Agent headings in a chat no longer pose as the app's own page
structure; they sit below the app's
  own headings and look the same as before.
  ([#570](#570) by @radicor)
- The "reconnecting" line and the composer's terminal-only hint are
announced when they appear.
  ([#570](#570) by @radicor)
- A chat locked out by the token gate, the "Last checked" line under
Settings → About (with its
date in your language) and a remote PC's state word in the sidebar are
translated like the rest of
  the UI.
  ([#570](#570) by @radicor)
- The alerts menu item now says the same thing the same way in every
state.
  ([#570](#570) by @radicor)
- Held terminal input typed while disconnected is forgotten after a day.
  ([#570](#570) by @radicor)
- A link printed in the terminal opens only if it is an http(s) address,
on both link paths.
  ([#570](#570) by @radicor)
- A second tab open on one pane no longer sends a message the first tab
is already sending: it
sees that send on its way and holds back. Two tabs that press Send at
nearly the same moment can still
  both send it.
  ([#570](#570) by @radicor)
- A row's ⋯ menu is capped to the room its button leaves and scrolls
instead of being cut off by the
viewport, so the pane picker of a tab with many panes keeps every entry
reachable with the pointer
as well as the keyboard. Before, items below the fold were rendered but
unreachable.
  ([#570](#570) by @radicor)
- A row menu open while the window crosses the 640 px breakpoint now
switches between bottom sheet and
  popover instead of keeping the form it opened with.
  ([#570](#570) by @radicor)
- The workspace drawer a narrow window opened is closed again when the
window is widened past 768 px,
  so narrowing it no longer brings back a drawer and its scrim unasked.
  ([#570](#570) by @radicor)
- **Add PC**, **Reconnect PC** and **Update remote bridge** open as a
bottom sheet on a phone, like
every other dialog, and keep clear of the on-screen keyboard. Before,
the one native dialog stayed
  a centred card on a phone.
  ([#570](#570) by @radicor)
- **Remove PC**'s first click is a quiet ghost button that only arms the
removal; the second is the
  red one, as revoking a device already was.
  ([#570](#570) by @radicor)
- A PC's rename, connect and disconnect buttons disable while their
request is in flight, so a double
  click no longer sends two overlapping requests.
  ([#570](#570) by @radicor)
- A failed pane or workspace rename keeps the field open with what you
typed, so a network blip no
  longer makes you write the name again.
  ([#570](#570) by @radicor)
- A workspace reorder that fails no longer undoes a later, successful
reorder.
  ([#570](#570) by @radicor)
- A tab watching several busy panes gives up its oldest cached
conversation answers when they grow
  past a byte budget, not only past sixteen of them.
  ([#570](#570) by @radicor)
- The usage meters' note is the same size as every other advisory and
empty state.
  ([#570](#570) by @radicor)
- The PDF viewer's page colour, the pill radii, the tab dot and the
pairing-code size come from
design tokens now, and the pairing code follows the compact density
setting.
  ([#570](#570) by @radicor)
- Updating an already current remote bridge verifies and reuses it
without downloading or
restarting it again, while a bridge from a newer app is left running
instead of downgraded.
A PC that waits on such a conflict says so in the sidebar and under the
header, with a
  **Reconnect** button, instead of asking for setup approval.
([#519](#519) by @suho-han)
- A wrong access token sent through a proxy on this PC with a made-up
`X-Forwarded-For` address
that itself says " via " now counts against the limit every visitor
through that proxy shares,
like any other wrong token. Before, each such try started a fresh count.
  ([#592](#592))
- A web-push subscription must be an https address, with no exception
for this PC, and an alert is
never sent on where a push service redirects it, so an alert can never
be posted to a service
running on this PC.
([#592](#592))
- In the **Add PC** dialog opened over a file preview, Tab moves through
the dialog's own controls
and Escape closes the dialog alone, leaving the preview beneath it open.
  ([#592](#592))

</details>


## Checks
- `bun run check fast`: ok (1817 pass, 6 platform skips, 0 fail).
- No browser regression covers OSC 52 (`terminal-copy-regression.ts`
covers drag and Ctrl+C copy), so none was run for it.

## Codex review (gpt-6-astra, read-only)
- **Fixed** (P2): summary text was put into the markdown as-is, so
`"…\n\n<!--"` could hide the whole changelog fold. The gate now refuses
a summary line with a line break in any language, and the English lines
escape `<`. A test covers both and fails without the fix.
- **Declined, documented** (P2): a tab still on the 0.4.1 bundle that
saves settings drops `paneClipboard`, so a new "off" reads as on until
it is chosen again. A versioned storage key would stop that, but then
every setting changed in such a tab would be lost instead. It lasts only
until that tab reloads, and every setting added before this one had the
same gap.
- **Pre-existing, not in this diff** (P2): settings have no cross-tab
sync, so a stale tab's next save writes its own copy of every setting,
this one included. Reported to the lead as a follow-up.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant