Skip to content

fix(lab): rewrite raw POSIX path regex without ambiguous alternation - #629

Closed
devin-ai-integration[bot] wants to merge 1 commit into
devfrom
devin/1790260418-redos-limits-regex
Closed

devin-ai-integration[bot] wants to merge 1 commit into
devfrom
devin/1790260418-redos-limits-regex

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Summary

Verification

  • bun test tests/lab/lab-post-merge-hardening.test.ts — 9/9 pass, including a new event privacy admission stays linear on pathological path strings regression test (long segment chains and slash-dense runs reject as raw_path promptly; a URL-shaped field still passes).
  • Prior equivalence check in fix(security): rewrite two ReDoS-able regular expressions flagged by code scanning #604: 200k randomized + hand-written edge strings produced zero acceptance differences between old and new patterns.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed (regex internals only; no contract change).
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

Link to Devin session: https://app.devin.ai/sessions/18173a51bcf04824a2e66ca1d2e42ccf
Open in Devin Desktop: https://app.devin.ai/desktop/session/18173a51bcf04824a2e66ca1d2e42ccf?variant=devin
Requested by: @luvs01


Devin Review

Review readiness checklist

This PR stays in draft until every box below is ticked. Tick all four boxes once the requirements are met:

  • Required local validation passed; commands, results, and any full-suite exception are documented.

  • I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).

  • I resolved all correct Codex and CodeRabbit findings.

  • My PR is ready for review.

Code scanning flagged RAW_POSIX_PATH_RE as polynomial ReDoS (alert #1):
the `(?:\/|[^/\0\r\n]+)+` alternation can repartition a run of path
segments combinatorially on client-supplied event fields. Rewrite the
segment run as an unambiguous `[^/]+(?:\/+[^/]+)*\/*` sequence so the
match stays linear. The exec-side sibling regex was already rewritten
on dev; this closes the remaining flagged pattern.

Co-Authored-By: Epinephrine <luvs01@hanmail.net>
@devin-ai-integration

Copy link
Copy Markdown
Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: luvs01/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: b1760edb-fc12-4776-b4f4-7bf794eeb353

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the bug Something isn't working label Sep 24, 2026
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

✅ READY

  • all PR quality gates passed; the review readiness checklist is complete.

Review readiness checklist

  • ✅ Required local validation passed; commands, results, and any full-suite exception are documented.
  • ✅ I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
  • ✅ I resolved all correct Codex and CodeRabbit findings.
  • ✅ My PR is ready for review.

✅ 4/4 boxes ticked.

This pull request is already Ready for Review.
The review-ready label marks this PR as ready; review automation runs independently.
Maintainers: @lidge-jun @Ingwannu

@github-actions
github-actions Bot marked this pull request as draft September 24, 2026 14:35
@github-actions
github-actions Bot marked this pull request as ready for review September 24, 2026 14:36

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment thread tests/lab/lab-post-merge-hardening.test.ts
@luvs01

luvs01 commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Closing: submitted upstream as lidge-jun#5773, rebased onto current dev and verified — bun test tests/lab/lab-post-merge-hardening.test.ts 9 pass. Nothing left to merge here.

@luvs01 luvs01 closed this Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working review-ready

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant