Ferroni
Oniguruma's regex engine, modernized in Rust.
Look-behind, backreferences, Unicode properties and the multi-pattern scanner that TextMate grammars run on, in one pure-Rust crate. No C compiler, memory-safe, and faster than the C original.
- Succeeds
- Oniguruma / vscode-oniguruma
- Checked against
- Oniguruma compatibility oracle
- Release
- v2.1.0
Same engine. Modern Rust.
Oniguruma’s C project closed on April 24, 2025, after more than twenty years as the engine TextMate grammars are written for. Ferroni carries it forward, and adds what C Oniguruma never shipped: Unicode 18.0, the vscode-oniguruma scanner, a backtracking check and an idiomatic Rust API.
- Same engine, verified- A line-by-line port of Oniguruma's parser, compiler and optimizer. All 2,974 upstream UTF-8 test cases pass, so a pattern behaves as it does in C.
- Easy to add- cargo add ferroniand build: no C compiler, no bindgen, four common dependencies. An idiomatic- RegexAPI on top,- Send + Syncfor sharing across threads.
- Safe with untrusted input- Memory-safe Rust, with unsafe confined to the links between parse-tree nodes. Timeouts and retry limits per search, a compile-time backtracking check, and continuous fuzzing.
- Faster than the original- Ahead of C Oniguruma in every measured workload: 1.4× to 12× faster, from everyday patterns to syntax highlighting, with inputs and raw data published.
Familiar Rust, full Oniguruma syntax
The look-behind that selects this date is syntax Rust’s regex crate does not run; the named groups and the API around them are the ones you already know. The output is what the example printed, committed with the site.
website_sample.rsRust source
Read the output as text
input: Date: 2026-09-26
year: 2026
month: 09
day: 26
Faster than the C original
How much faster Ferroni is than C Oniguruma on three kinds of work, as the geometric mean over every task and two test machines. The table adds six more engines. Each one first has to reproduce Oniguruma’s results, or the results Shiki produced for highlighting, before it is timed.
Where Ferroni is behind, the table says so. When patterns fit their syntax, Rust’s regex crate and PCRE2’s JIT win most text tasks; neither finds the earliest match among many patterns in one search, as a highlighter needs. C Oniguruma wins a few individual tasks, and grammar compilation is mixed.
- Everyday patterns
- 2.2×
- search and extraction in HTML, logs, chat with emoji, Markdown, JSON, CSV and source code, in syntax the regex crate also runs
- Advanced patterns
- 1.4×
- look-around, backreferences, possessive groups, subexpression calls, absent expressions and grapheme clusters
- Syntax highlighting
- 12×
- the scanner calls Shiki makes for whole C, Java and PHP documents, in grammars every engine runs
* Ran only some of the tasks: the engine rejects a pattern or finds different matches. The figure covers the tasks it ran.
– Not measured: the engine lacks the syntax, or the multi-pattern API the workload needs.
fancy-regex is quoted in its fastest configuration per column: seek mode for everyday patterns and advanced patterns; RegexSet for syntax highlighting.
- Measured
- 2026-10-09
- Machine
- Blacksmith runners. macOS arm64: Apple M4 Pro (Virtual), 6 vCPUs; Linux x86-64: AMD EPYC, 4 vCPUs
- Revision
- b93c6d20
Built for syntax highlighting
A highlighter asks, at every position in a line, which of a grammar’s many patterns matches next. Ferroni’s Scanner answers with the API of vscode-oniguruma, the engine under vscode-textmate and Shiki, UTF-16 offsets included.
Scanners built from one pattern cache compile each distinct pattern once, and a string id lets a scanner reuse what it learned about a line. The Scanner API in the guide
Safe with untrusted input
Memory-safe Rust replaces the C code behind Oniguruma’s CVEs, and unsafe stays confined to the links between parse-tree nodes. For text and patterns you did not write, a search can carry a timeout or a retry limit and report it as an error, and a compile-time check flags patterns that backtrack catastrophically.
Pattern compilation, matching and the scanner are fuzzed on every pull request. Untrusted input in the guide · The unsafe code policy
Compatibility, with the evidence attached
The port keeps Oniguruma’s module structure, function names and control flow, so it can be checked against C test by test. Every upstream test that targets UTF-8 passes.
Line coverage is gated in CI, and every benchmark case first has to reproduce C Oniguruma’s results. How compatibility is checked
- Upstream C test cases
- 2,974 / 2,974
- Every UTF-8 test file of Oniguruma, ported case by case.
- vscode-oniguruma tests
- 15 / 15
- The scanner's upstream suite, ported as 25 Rust tests.
- Unicode data
- 18.0
- Generated from the Unicode Character Database; C Oniguruma ships 16.0.
- Syntax modes
- 12
- Oniguruma, Ruby, Perl, Python, Java, POSIX and six more.
What it covers
Ferroni ports ASCII and UTF-8, two of Oniguruma’s 29 encodings, and leaves out the POSIX and GNU APIs (ADR-003, ADR-012). For the projects built on Oniguruma’s syntax, that means:
- TextMate grammars, VS Code, ShikiCoveredvscode-oniguruma compiles every pattern as UTF-8. Ferroni's scanner keeps its API shape and its UTF-16 offsets.
- jqCoveredjq matches on UTF-8 text, which Ferroni handles in full.
- PHP mbregexUTF-8 onlymb_ereg in Shift_JIS, EUC-JP or another non-UTF-8 encoding is not covered.
- RubyNot a targetRuby runs Onigmo, a fork of Oniguruma with its own history and encodings.
Where Ferroni sits
Ferroni supplies the regex engine for Ferriki, whose Shiki-compatible highlighter tokenizes code with TextMate grammars. Each tool also works on its own.
Start building with Ferroni
Oniguruma’s engine and the vscode-oniguruma scanner in one pure-Rust crate. The guide takes you from cargo add ferroni to your first match, a tokenizer loop, and searches that are safe to run on untrusted input. Ferroni is feature-complete for its scope and maintained, with no feature work planned; the project status says what is and is not covered.
Need one of these in your stack?
The people who build the engines also integrate them, support them, and maintain them for the long run.