tauri-apps/tauri · error

unable to render codegen isolation script template

Error message

unable to render codegen isolation script template

What it means

Same failure as the html.rs variant but in the alternate `html2` implementation: `inject_codegen_isolation_script` renders the `IsolationJavascriptCodegen` template with `serialize_to_javascript` before injecting a nonce-tagged `<script>`; render failure panics with this message.

Solutions

  1. Run `cargo update -p serialize-to-javascript` to align versions.
  2. Do a clean rebuild (`cargo clean && cargo build`).
  3. Confirm no workspace dependency pins override `serialize-to-javascript`.

Example fix

// shell fix
cargo clean && cargo update -p serialize-to-javascript && cargo build
Defensive patterns

Strategy: try-catch

Try / catch

// guard the html2 injection path
std::panic::catch_unwind(|| {
  tauri::utils::html2::inject_codegen_isolation_script(&document);
}).unwrap_or_else(|_| eprintln!("isolation script injection failed (html2)"));

Prevention

When it happens

Trigger: `IsolationJavascriptCodegen::render_default` returning `Err` during isolation-pattern HTML injection — effectively only from `serialize-to-javascript` version mismatch or corrupted build artifacts.

Common situations: After upgrading Tauri crates with a stale Cargo.lock; cargo cache corruption; mixed crate versions in a workspace.

Understand the failure class

Background: "This is a bug, please report it": internal invariant violations, unreachable panics, and SNH errors explained — this error's family across 47 libraries.

Related errors


AI-assisted analysis of tauri-apps/tauri@460ec35447 (2026-09-18). Data as JSON: /api/errors/936b3f155b5b1848. Report an issue: GitHub.

Appendix: source

Thrown at crates/tauri-utils/src/html2.rs:120

}

/// Injects the Isolation JavaScript to a codegen time document.
///
/// Note: This function is not considered part of the stable API.
///
/// # Stability
///
/// This dependency [`dom_query`] for [`Document`] might receive updates in minor releases.
#[cfg(feature = "isolation")]
pub fn inject_codegen_isolation_script(document: &Document) {
  use crate::pattern::isolation::IsolationJavascriptCodegen;
  use serialize_to_javascript::DefaultTemplate;

  let head = ensure_head(document);

  let script_content = IsolationJavascriptCodegen {}
    .render_default(&Default::default())
    .expect("unable to render codegen isolation script template")
    .into_string();

  let script_tag = document.tree.new_element("script");
  script_tag.set_attr("nonce", SCRIPT_NONCE_TOKEN);
  script_tag.set_text(script_content);

  head.prepend_child(&script_tag);
}

/// Temporary workaround for Windows not allowing requests
///
/// Note: this does not prevent path traversal due to the isolation application expectation that it
/// is secure.
///
/// # Stability
///
/// This dependency [`dom_query`] for [`Document`] might receive updates in minor releases.
#[cfg(feature = "isolation")]

View on GitHub (pinned to 460ec35447)