I managed to upload the wrong patch, the correct one is the -3 one *.
My patch includes some tests, if you can think about other ways to break
the function I can add more tests (and possibly make the function more
robust if they fail).  FWIW the "Clear this message" link still works,
probably because it's added after the escaping.

* If I try to remove the old patches with the "Remove" button I get an
"Invalid request" error.  I think that's because method="post" is
missing from the form, and it should be already fixed in recent versions
of Roundup (is this instance updated?)
