Skip to content

fix: build Bun apps that use server instrumentation - #16898

Merged
elliott-with-the-longest-name-on-github merged 4 commits into
version-3from
bun-adapter-instrumented-build
Aug 25, 2026
Merged

fix: build Bun apps that use server instrumentation#16898
elliott-with-the-longest-name-on-github merged 4 commits into
version-3from
bun-adapter-instrumented-build

Conversation

@Nic-Polumeyv

Copy link
Copy Markdown
Contributor

The side-effect chunk workaround in packages/adapter-bun/index.js registers build.onResolve({ filter: /\.js$/ }) and returns undefined for anything outside server/chunks/. A Bun.build hook that matches without resolving sends Bun to the filesystem, past the files virtual entries. An app with src/instrumentation.server.js gets a virtual src/start.js entrypoint that exists nowhere on disk, so its build fails with ModuleNotFound resolving ".../adapter-bun/src/start.js" (entry point).

The plugin now reads server/chunks/ once up front, keeps the stubs it matches in side_effect_sources, and builds side_effect_filter from their basenames, so no other specifier reaches the hook. A path that still matches without being a stub resolves to its virtual entry when there is one.

The non-GET e2e test posted an http origin, which fails the CSRF check against the https origin the adapter computes. platform-tests-bun.yml runs on workflow_dispatch only, so neither of these showed up in CI.

#16880 is stacked on this.

The workaround's onResolve matched every .js specifier, and a hook that
matches without resolving sends Bun back to the filesystem, where the
virtual start.js entrypoint does not exist. Instrumented builds failed with
ModuleNotFound. Scan the chunk directory once and filter on the stubs it
found, so nothing else reaches the hook.
Without PROTOCOL_HEADER the adapter assumes TLS terminates upstream, so an
http origin fails the CSRF check and the request never reaches SvelteKit.
@pkg-svelte-dev

pkg-svelte-dev Bot commented Aug 22, 2026

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from 852cdef:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/852cdefef307c5d79059fe6392252aa706a738c6

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/16898

@changeset-bot

changeset-bot Bot commented Aug 22, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 852cdef

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/adapter-bun Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@svelte-docs-bot

Copy link
Copy Markdown

Comment thread packages/adapter-bun/index.js
@ottomated ottomated added the needs-platform-tests This PR needs to run platform tests in order to merge. label Aug 22, 2026
@Nic-Polumeyv Nic-Polumeyv removed the needs-platform-tests This PR needs to run platform tests in order to merge. label Aug 23, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks, I hate it

@elliott-with-the-longest-name-on-github
elliott-with-the-longest-name-on-github merged commit a41ac33 into version-3 Aug 25, 2026
40 checks passed
@elliott-with-the-longest-name-on-github
elliott-with-the-longest-name-on-github deleted the bun-adapter-instrumented-build branch August 25, 2026 21:23
elliott-with-the-longest-name-on-github added a commit that referenced this pull request Aug 25, 2026
Stacked on #16898

Follow-ups to the Bun 1.4 release. `HEAD` now reaches `GET` handlers and
`stop()` settles after a force close, so routes stop registering both
methods and shutdown stops racing a timer. That makes 1.4 the floor.

---------

Co-authored-by: Tee Ming <chewteeming01@gmail.com>
Rich-Harris pushed a commit that referenced this pull request Aug 26, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/adapter-bun@1.0.0-next.2

### Major Changes

- breaking: require Bun 1.4, which routes `HEAD` to `GET` handlers and
settles `stop()` after a force close
([#16880](#16880))

### Patch Changes

- fix: build apps that use server instrumentation
([#16898](#16898))
- Updated dependencies
[[`ff8cdd4`](ff8cdd4),
[`723572c`](723572c),
[`3b8e034`](3b8e034),
[`f2c5102`](f2c5102),
[`c66a6ed`](c66a6ed),
[`428e5ef`](428e5ef)]:
  - @sveltejs/kit@3.0.0-next.26
## @sveltejs/adapter-node@6.0.0-next.11

### Patch Changes

- chore: remove polka, attach the handler to the http server directly
([#16907](#16907))
- Updated dependencies
[[`ff8cdd4`](ff8cdd4),
[`723572c`](723572c),
[`3b8e034`](3b8e034),
[`f2c5102`](f2c5102),
[`c66a6ed`](c66a6ed),
[`428e5ef`](428e5ef)]:
  - @sveltejs/kit@3.0.0-next.26
## @sveltejs/kit@3.0.0-next.26

### Patch Changes

- fix: only require the `svelte-trusted-html` trusted-types policy when
client-side code is shipped, allowing builds where all pages have `csr:
false` ([#16928](#16928))

- chore: stop externalizing `cookie` dependency during build
([#16936](#16936))

- fix: preserve metadata on streamed page responses
([#16935](#16935))

- fix: error on server-only imports reachable from hooks or service
worker files outside the project root
([#16912](#16912))

- fix: copy worker files emitted by the server build to the client
output directory ([#16929](#16929))

- fix: Reject all pending query promises when a query fails before
resolving with a value for the first time
([#16890](#16890))

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants