Skip to content

v5.2.0: trie router, performance pass, executor hardening - #57

Merged
jkyberneees merged 1 commit into
masterfrom
feat/v5.2.0-trie-router
Oct 9, 2026
Merged

jkyberneees merged 1 commit into
masterfrom
feat/v5.2.0-trie-router

Conversation

@jkyberneees

Copy link
Copy Markdown
Collaborator

Summary

  • New trie router (lib/router/trie.js, zero external dependencies): same API, middleware chain, nested routers and error containment as the sequential router, with a segment-trie matcher and a compile-on-demand static table. Case-sensitive by default, literal static segments, null-prototype params, no request-keyed cache. Opt in with require('0http/lib/router/trie')().
  • Sequential router performance pass: drop-in find with exact length prefilters, lazy params, top-level lookup fast path, structural query-string fast path, no per-request closure in the setImmediate dispatch.
  • Executor hardening (both routers), from an adversarial security/correctness/perf review:
    • mount prefixes are stripped from the path only, so a query string can never become a nested router's path
    • a user errorHandler is skipped once the response has ended (writing would raise an uncatchable stream error)
    • defaultRoute runs under error containment
    • one router mounted at several prefixes keeps every mount; use() normalizes g/y RegExp flags
    • linear query parsing for segment-heavy strings
  • Docs and landing page updated; version bumped to 5.2.0.

Benchmarks (ns per lookup, min of 5, Node 22, M2 Pro)

Routes Router static param 2 params nested query
5 sequential 153 192 259 325 320
5 trie 81 175 233 339 318
505 sequential 149 1438 7878 334 1615
505 trie 83 180 238 347 323

Verification

  • 142 tests passing, lint clean, 97.7% statement coverage; every fix has a regression test
  • Differential fuzzing: trie vs sequential (360k lookups), new find vs Trouter#find (millions), query parser vs URLSearchParams (600k strings), all zero diffs
  • Repo security tooling (pentest, pollution, type confusion, regex audit) passes with both routers

🤖 Generated with Claude Code

…ning

New dependency-free trie router (lib/router/trie.js): same API, middleware
chain, nested routers and error containment as the sequential router with a
segment-trie matcher and a compile-on-demand static table. ~80ns static
lookups (2x faster than sequential), flat dynamic-route cost at any route
count, case-sensitive by default, literal static segments, null-prototype
params, no request-keyed cache.

Sequential router performance pass: custom find with exact length prefilters
(drop-in for Trouter#find), lazy params allocation, top-level lookup fast
path, structural query-string fast path, no per-request closure in the
setImmediate dispatch. 11-21% faster per lookup at small route tables.

Hardening (shared executor, both routers), found by adversarial review:
- mount prefixes are stripped from the path only; a query string can no
  longer become a nested router's path (`/api/acme?x=/admin`)
- a user errorHandler is skipped once the response has ended (writing would
  raise an uncatchable stream error and kill the process)
- defaultRoute runs under error containment
- one router mounted at several prefixes keeps every mount
- use() normalizes g/y RegExp flags like add()
- linear query parsing for segment-heavy strings

Docs: README, docs/README.md and the landing page promote the trie router.
Version bumped to 5.2.0.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@jkyberneees
jkyberneees merged commit 3f2772a into master Oct 9, 2026
5 checks passed
@jkyberneees
jkyberneees deleted the feat/v5.2.0-trie-router branch October 9, 2026 08:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant