Skip to content

perf(server-utils): Avoid quadratic SQL sanitizer output handling - #24834

Merged
nicohrubec merged 3 commits into
developfrom
feat/sql-sanitizer-array-output
Sep 30, 2026
Merged

nicohrubec merged 3 commits into
developfrom
feat/sql-sanitizer-array-output

Conversation

@nicohrubec

@nicohrubec nicohrubec commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Large SQL statements with many quoted literals can block the event loop, because the prefix checks in getLiteralPrefix cause repeated flattening of the result string buffer (resulting in a full copy of the result string up to that point). This is very costly and can be easily avoided by instead pushing the sanitized bits to an array and joining once at the end.

Local benchmark comparing the approaches:

Literals SQL size String Array
10,000 0.4 MB 5.01 ms 1.51 ms
50,000 2.0 MB 197.72 ms 6.73 ms
100,000 4.0 MB 1,354.99 ms 13.80 ms

Closes #24812

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 29.24 kB - -
@sentry/browser - with treeshaking flags 27.5 kB - -
@sentry/browser - with treeshaking flags tracing without tracing 27.4 kB - -
@sentry/browser (incl. Tracing) 51.15 kB - -
@sentry/browser (incl. Tracing + Span Streaming) 51.18 kB - -
@sentry/browser (incl. Tracing, Profiling) 54.18 kB - -
@sentry/browser (incl. Tracing, Replay) 90.76 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 79.86 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 95.46 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 108.41 kB - -
@sentry/browser (incl. Feedback) 46.76 kB - -
@sentry/browser (incl. sendFeedback) 34.3 kB - -
@sentry/browser (incl. FeedbackAsync) 39.41 kB - -
@sentry/browser (incl. Metrics) 30.25 kB - -
@sentry/browser (incl. Logs) 30.53 kB - -
@sentry/browser (incl. Metrics & Logs) 31.2 kB - -
@sentry/react 31.08 kB - -
@sentry/react (incl. Tracing) 53.54 kB - -
@sentry/vue 36.74 kB - -
@sentry/vue (incl. Tracing) 53.7 kB - -
@sentry/svelte 29.26 kB - -
CDN Bundle 31.05 kB - -
CDN Bundle (incl. Tracing) 51.8 kB - -
CDN Bundle (incl. Logs, Metrics) 33.31 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 53.77 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 74.02 kB - -
CDN Bundle (incl. Tracing, Replay) 89.39 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 91.36 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 95.55 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 97.53 kB - -
CDN Bundle - uncompressed 91.7 kB - -
CDN Bundle (incl. Tracing) - uncompressed 154.08 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 98.27 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 160.04 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 227.84 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 273.81 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 279.75 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 287.51 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 293.44 kB - -
@sentry/nextjs (client) 55.78 kB - -
@sentry/sveltekit (client) 51.6 kB - -
@sentry/core/server 39.99 kB - -
@sentry/core/browser 13.63 kB - -
@sentry/node 142.26 kB +0.02% +28 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection) 82.88 kB - -
@sentry/node - without tracing 91.25 kB +0.02% +13 B 🔺
@sentry/node - without channel injection 120.66 kB +0.03% +26 B 🔺
@sentry/aws-serverless 99.52 kB +0.01% +6 B 🔺
@sentry/cloudflare (withSentry) - minified 206.69 kB +0.03% +55 B 🔺
@sentry/cloudflare (withSentry) 514.13 kB +0.02% +87 B 🔺

View base workflow run

nicohrubec and others added 2 commits September 29, 2026 20:55
…ndaries

Co-Authored-By: GPT-6 <codex@openai.com>
Co-Authored-By: GPT-6 <codex@openai.com>
@nicohrubec
nicohrubec marked this pull request as ready for review September 29, 2026 19:11
@nicohrubec
nicohrubec requested a review from a team as a code owner September 29, 2026 19:11
@nicohrubec
nicohrubec requested review from JPeer264, Lms24 and isaacs and removed request for a team September 29, 2026 19:11

@Lms24 Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice, thanks for fixing this!

@nicohrubec
nicohrubec merged commit 9011a00 into develop Sep 30, 2026
677 of 679 checks passed
@nicohrubec
nicohrubec deleted the feat/sql-sanitizer-array-output branch September 30, 2026 06:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sanitizeSqlQuery is quadratic in query length and blocks the event loop on large mysql2 queries

2 participants