Repository navigation
fix(lab): rewrite raw POSIX path regex without ambiguous alternation - #629
devin-ai-integration[bot] wants to merge 1 commit into
Conversation
Code scanning flagged RAW_POSIX_PATH_RE as polynomial ReDoS (alert #1): the `(?:\/|[^/\0\r\n]+)+` alternation can repartition a run of path segments combinatorially on client-supplied event fields. Rewrite the segment run as an unambiguous `[^/]+(?:\/+[^/]+)*\/*` sequence so the match stays linear. The exec-side sibling regex was already rewritten on dev; this closes the remaining flagged pattern. Co-Authored-By: Epinephrine <luvs01@hanmail.net>
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: luvs01/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
✅ READY
Review readiness checklist
✅ 4/4 boxes ticked. This pull request is already Ready for Review. |
|
Closing: submitted upstream as lidge-jun#5773, rebased onto current |
Summary
src/lab/events/limits.ts:RAW_POSIX_PATH_REflagged by code scanning (alert [WRONG BRANCH] fix(command-code): disable repository fsmonitor during git metadata collection #1,js/redos). The(?:\/|[^/\0\r\n]+)+alternation lets a run of/-separated segments be repartitioned combinatorially — a client-controlled eventdetailfield can stall the event-limits check for seconds on a few-KB input.[^/\0\r\n]+(?:\/+[^/\0\r\n]+)*\/*segment sequence — the match is linear, and the acceptance set is unchanged (validated against the old pattern by randomized fuzzing in fix(security): rewrite two ReDoS-able regular expressions flagged by code scanning #604, where the same fix originally shipped alongside the exec-side rewrite that has since landed ondevseparately).EMPTY_EXEC_OUTPUT_REGEXno longer needs changing (dev now uses a forward scan).Verification
bun test tests/lab/lab-post-merge-hardening.test.ts— 9/9 pass, including a newevent privacy admission stays linear on pathological path stringsregression test (long segment chains and slash-dense runs reject asraw_pathpromptly; a URL-shaped field still passes).Checklist
Link to Devin session: https://app.devin.ai/sessions/18173a51bcf04824a2e66ca1d2e42ccf
Open in Devin Desktop: https://app.devin.ai/desktop/session/18173a51bcf04824a2e66ca1d2e42ccf?variant=devin
Requested by: @luvs01
Review readiness checklist
This PR stays in draft until every box below is ticked. Tick all four boxes once the requirements are met:
Required local validation passed; commands, results, and any full-suite exception are documented.
I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
I resolved all correct Codex and CodeRabbit findings.
My PR is ready for review.