Repository navigation
Commit 5171e68
authored
Merge commit from fork
* fix: make parseCommaParts iterative and avoid push.apply
`parseCommaParts` recursed on the remainder of the string once per brace
group, so a chain of groups nested inside a brace set exhausted the native
stack at ~7,000 groups (~29KB of input):
expand('{' + '{a},'.repeat(7000) + 'b}')
// RangeError: Maximum call stack size exceeded
This is the parsing-side counterpart to the `expand` overflow fixed for
CVE-2026-14257. That fix documented a constant-stack-depth guarantee, but
only `expand` was made iterative, so putting the same chain inside a brace
group routed parsing through the recursion that was left in place.
Neither `max` nor `maxLength` could bound it: the crash happens while
parsing, before anything is expanded, and the payload produces one result
per group, so output size grows linearly and is never the limiter.
Rewrite the function as a loop that carries the partial part across chunks.
Separately, `push.apply(target, items)` passes one argument per element, so
a single large array overflows the stack with no recursion at all - this
input reaches a recursion depth of exactly one:
expand('{{x},' + 'a,'.repeat(125000) + 'b}')
// RangeError: Maximum call stack size exceeded
Append element by element via `pushAll` instead.
The leading `if (!str) return ['']` guard is dropped: it is unreachable from
the sole call site (`m.body` always contains a comma there), and the loop
returns `['']` for the empty string on its own.
Equivalence with the previous implementation was checked by differential
testing against the published release of this line - exhaustive over every
string of `{`, `}`, `,` and `a` up to length 8, plus 300k random inputs with
and without `max` / `maxLength` - 387,381 cases, zero mismatches.
* review: trim comments1 parent b25213d commit 5171e68
2 files changed
Lines changed: 91 additions & 18 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
48 | 55 | | |
49 | 56 | | |
50 | 57 | | |
51 | 58 | | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | 59 | | |
56 | | - | |
57 | 60 | | |
58 | | - | |
59 | | - | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
60 | 68 | | |
61 | | - | |
62 | | - | |
63 | | - | |
64 | | - | |
| 69 | + | |
| 70 | + | |
65 | 71 | | |
66 | | - | |
67 | | - | |
68 | | - | |
69 | | - | |
70 | | - | |
71 | | - | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
72 | 83 | | |
73 | | - | |
| 84 | + | |
| 85 | + | |
74 | 86 | | |
75 | | - | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
76 | 96 | | |
77 | 97 | | |
78 | 98 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
0 commit comments