|
1 | | -/*! js-yaml 3.15.1 https://github.com/nodeca/js-yaml */(function(f){if(typeof exports==="object"&&typeof module!=="undefined"){module.exports=f()}else if(typeof define==="function"&&define.amd){define([],f)}else{var g;if(typeof window!=="undefined"){g=window}else if(typeof global!=="undefined"){g=global}else if(typeof self!=="undefined"){g=self}else{g=this}g.jsyaml = f()}})(function(){var define,module,exports;return (function(){function r(e,n,t){function o(i,f){if(!n[i]){if(!e[i]){var c="function"==typeof require&&require;if(!f&&c)return c(i,!0);if(u)return u(i,!0);var a=new Error("Cannot find module '"+i+"'");throw a.code="MODULE_NOT_FOUND",a}var p=n[i]={exports:{}};e[i][0].call(p.exports,function(r){var n=e[i][1][r];return o(n||r)},p,p.exports,r,e,n,t)}return n[i].exports}for(var u="function"==typeof require&&require,i=0;i<t.length;i++)o(t[i]);return o}return r})()({1:[function(require,module,exports){ |
| 1 | +/*! js-yaml 3.15.2 https://github.com/nodeca/js-yaml */(function(f){if(typeof exports==="object"&&typeof module!=="undefined"){module.exports=f()}else if(typeof define==="function"&&define.amd){define([],f)}else{var g;if(typeof window!=="undefined"){g=window}else if(typeof global!=="undefined"){g=global}else if(typeof self!=="undefined"){g=self}else{g=this}g.jsyaml = f()}})(function(){var define,module,exports;return (function(){function r(e,n,t){function o(i,f){if(!n[i]){if(!e[i]){var c="function"==typeof require&&require;if(!f&&c)return c(i,!0);if(u)return u(i,!0);var a=new Error("Cannot find module '"+i+"'");throw a.code="MODULE_NOT_FOUND",a}var p=n[i]={exports:{}};e[i][0].call(p.exports,function(r){var n=e[i][1][r];return o(n||r)},p,p.exports,r,e,n,t)}return n[i].exports}for(var u="function"==typeof require&&require,i=0;i<t.length;i++)o(t[i]);return o}return r})()({1:[function(require,module,exports){ |
2 | 2 | 'use strict'; |
3 | 3 |
|
4 | 4 |
|
@@ -1283,21 +1283,30 @@ function captureSegment(state, start, end, checkJson) { |
1283 | 1283 | } |
1284 | 1284 | } |
1285 | 1285 |
|
| 1286 | +function chargeMergeWork(state) { |
| 1287 | + state.totalMergeKeys += 1; |
| 1288 | + |
| 1289 | + if (state.maxTotalMergeKeys !== -1 && state.totalMergeKeys > state.maxTotalMergeKeys) { |
| 1290 | + throwError(state, 'merge keys exceeded maxTotalMergeKeys (' + state.maxTotalMergeKeys + ')'); |
| 1291 | + } |
| 1292 | +} |
| 1293 | + |
1286 | 1294 | function mergeMappings(state, destination, source, overridableKeys) { |
1287 | 1295 | var sourceKeys, key, index, quantity; |
1288 | 1296 |
|
1289 | 1297 | if (!common.isObject(source)) { |
1290 | 1298 | throwError(state, 'cannot merge mappings; the provided source object is unacceptable'); |
1291 | 1299 | } |
1292 | 1300 |
|
| 1301 | + // Count the source mapping itself to bound sequences of empty mappings. |
| 1302 | + chargeMergeWork(state); |
| 1303 | + |
1293 | 1304 | sourceKeys = Object.keys(source); |
1294 | 1305 |
|
1295 | 1306 | for (index = 0, quantity = sourceKeys.length; index < quantity; index += 1) { |
1296 | 1307 | key = sourceKeys[index]; |
1297 | 1308 |
|
1298 | | - if (state.maxTotalMergeKeys !== -1 && ++state.totalMergeKeys > state.maxTotalMergeKeys) { |
1299 | | - throwError(state, 'merge keys exceeded maxTotalMergeKeys (' + state.maxTotalMergeKeys + ')'); |
1300 | | - } |
| 1309 | + chargeMergeWork(state); |
1301 | 1310 |
|
1302 | 1311 | if (!_hasOwnProperty.call(destination, key)) { |
1303 | 1312 | setProperty(destination, key, source[key]); |
@@ -1342,6 +1351,10 @@ function storeMappingPair(state, _result, overridableKeys, keyTag, keyNode, valu |
1342 | 1351 |
|
1343 | 1352 | if (keyTag === 'tag:yaml.org,2002:merge') { |
1344 | 1353 | if (Array.isArray(valueNode)) { |
| 1354 | + if (valueNode.length > 100) { |
| 1355 | + throwError(state, 'abnormal merge sequence size'); |
| 1356 | + } |
| 1357 | + |
1345 | 1358 | for (index = 0, quantity = valueNode.length; index < quantity; index += 1) { |
1346 | 1359 | mergeMappings(state, _result, valueNode[index], overridableKeys); |
1347 | 1360 | } |
|
0 commit comments