Temporal and Intl parsing cannot fail because the machine was busy (#3486) - #3543
Merged
Merged
Conversation
…ebastienros#3486) The internal patterns that parse ISO 8601 strings for Temporal, and the one that validates BCP 47 tags for Intl, each carried a 100 ms Regex.MatchTimeout. That is a wall-clock deadline sampled while matching, so it cannot tell a pattern that is backtracking apart from a thread that lost the CPU: a descheduled thread trips it having burned almost no CPU at all. What that produced was not a JavaScript error. RegexMatchTimeoutException is listed in Throw.MustPropagateHostException, so it escaped Engine.Evaluate as a raw CLR exception, straight through the script's own try/catch -- a script could not defend itself, and the message blamed "very large inputs or excessive backtracking" for a short valid string. The patterns are linear, so the budget could only ever fire spuriously, and the cost is bounded by construction instead: the fixed-width patterns reject anything longer than the longest string they could match without matching at all, and those bounds are exact and pinned. One pattern was not linear. AnnotationPattern -- \[(!?)([^\]]+)\] -- is quadratic on input holding no ']'. Measured on this branch against the net462 asset: 4 KB of '[' costs 305 ms of genuine CPU, 8 KB 951 ms, 16 KB 2.21 s and 32 KB 7.08 s, and with the shipped 100 ms budget every one of those throws RegexMatchTimeoutException. It was unreachable with such input only by an argument about its caller, so it is replaced by a linear walk -- 0.13 ms over 200,000 '[' -- pinned by a test that drives both over a corpus including the two cases the pattern's backtracking decided on its own ("[]" and "[!]"). The starvation cannot be reproduced without loading the machine, which would make the test the very flake it is about, so the tests pin the property: no pattern carries a deadline, every cap is the longest its pattern can match, an over-long input is rejected as a JavaScript error, and a valid string parses. Backport of sebastienros#3486 (main: ba18893). The engine change applies unmodified; the test file is transcribed from NUnit to xUnit v3, which is what Jint.Tests uses on this branch, and the v5 migration-guide entry is dropped because 4.x has no such document. Fixes sebastienros#3485 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014W5mbjGhyvgAS4pivXoc4S
This was referenced Sep 9, 2026
PatrickSt1991
pushed a commit
to Apps2Samsung/Apps2Samsung
that referenced
this pull request
Sep 14, 2026
Updated [Avalonia](https://github.com/AvaloniaUI/Avalonia/) from 11.3.20 to 11.3.22. <details> <summary>Release notes</summary> _Sourced from [Avalonia's releases](https://github.com/AvaloniaUI/Avalonia//releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/AvaloniaUI/Avalonia//commits). </details> Updated [Avalonia.Desktop](https://github.com/AvaloniaUI/Avalonia/) from 11.3.20 to 11.3.22. <details> <summary>Release notes</summary> _Sourced from [Avalonia.Desktop's releases](https://github.com/AvaloniaUI/Avalonia//releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/AvaloniaUI/Avalonia//commits). </details> Updated [Avalonia.Diagnostics](https://github.com/AvaloniaUI/Avalonia/) from 11.3.20 to 11.3.22. <details> <summary>Release notes</summary> _Sourced from [Avalonia.Diagnostics's releases](https://github.com/AvaloniaUI/Avalonia//releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/AvaloniaUI/Avalonia//commits). </details> Updated [Avalonia.Fonts.Inter](https://github.com/AvaloniaUI/Avalonia/) from 11.3.20 to 11.3.22. <details> <summary>Release notes</summary> _Sourced from [Avalonia.Fonts.Inter's releases](https://github.com/AvaloniaUI/Avalonia//releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/AvaloniaUI/Avalonia//commits). </details> Updated [Avalonia.Themes.Fluent](https://github.com/AvaloniaUI/Avalonia/) from 11.3.20 to 11.3.22. <details> <summary>Release notes</summary> _Sourced from [Avalonia.Themes.Fluent's releases](https://github.com/AvaloniaUI/Avalonia//releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/AvaloniaUI/Avalonia//commits). </details> Updated [Jint](https://github.com/sebastienros/jint) from 4.16.1 to 4.16.2. <details> <summary>Release notes</summary> _Sourced from [Jint's releases](https://github.com/sebastienros/jint/releases)._ ## 4.16.2 Jint 4.16.2 is a maintenance release from the `4.x` branch: **correctness and conformance fixes backported from `main`, and nothing that changes an existing API or an existing default.** If you are on 4.16.1 it is a drop-in update — every public signature is the one 4.16.0 shipped, on all five target frameworks, and the per-framework snapshots in `Jint.Tests.PublicInterface/Verify/` are unchanged. `main` remains 5.0.0 development; what is coming there is recorded as it lands in [`docs/v5-migration.md`](https://github.com/sebastienros/jint/blob/main/docs/v5-migration.md). ### Highlights **Failures that used to end the process, or never end.** A native error raised while a call's arguments are being evaluated is propagated instead of leaving an empty value behind, which on 4.16.1 could recurse until the process died — `decodeURIComponent` on a malformed sequence was enough (#4009). Native recursion and the forwarding paths through bound functions and proxies are guarded so a deep native chain raises a catchable error (#4007). A module graph too deep to link raises an error the host can catch instead of overflowing the stack (#3548). Temporal and Intl parsing cannot throw an uncatchable `RegexMatchTimeoutException` because the machine was busy (#3543), a Temporal difference past a calendar's range raises `RangeError` instead of spinning forever (#3555), and the process-wide Intl culture cache and Temporal zone cache are read-only and bounded, with a rejected zone no longer remembered — closing a script-driven unbounded growth (#3546). **Generators and built-ins, step by step.** A `yield*` delegation reached again by a loop both re-delegates and keeps its place: `countdown(3)` in a loop no longer hangs, and a delegating generator no longer returns the memoized first result (#3545). `Array.prototype.map` and `slice` hand a `@@species` constructor the length `ToLength` produced, and a non-callable `map` argument is a `TypeError` (#3547). A trailing NUL pads neither a numeric string nor an array index (#3552). A removed property slot is a tombstone rather than a free slot to reuse, so enumeration order survives a delete-and-readd (#3318), and `LengthOfArrayLike` no longer clamps through a `uint` overload (#3328). **Interop that answers for the right engine.** Two engines in one process no longer decide each other's conversions and operators (#3559), a host type converter's answer stays with the engine whose converter gave it (#3563), and a value the host registers on a `ShadowRealm` — and the members its wrapper builds eagerly — belong to that realm (#3557). Realm construction state is restored after nesting or a failure (#4008). Overload selection is by the arguments in hand: an operator overload is chosen that way (#3611), a `params` overload is chosen by the array's element type with a failing element declining rather than throwing (#3782), an overload the argument cannot bind to is not a match, and a host operator that throws reports what it threw (#3554). An index on a wrapped host collection is one property however it is spelled, and a member filter that hides the indexer hides it (#3562); a read-only host collection refuses a write with a JavaScript `TypeError` rather than the CLR's `NotSupportedException` (#3556). **Internationalization and Temporal.** The Persian calendar extends into proleptic years on its 33-year cycle, so the ends of Temporal's range land in the right Persian year (#4006); a calendar that counts Gregorian months writes their names (#3612); and a `-u-` extension carrying more than one key is read whole (#3613). **Errors.** Only a string-valued `stack` counts as a pre-existing stack when a `JavaScriptException` is built, so an accessor or non-string `stack` on a thrown object no longer breaks error reporting (#3677, reported by @jeske). Every change was verified failing-first against the unfixed branch on both .NET Framework and .NET 10, and the release was gated on a paired SunSpider and Dromaeo comparison against 4.16.1 on an idle machine: no row regressed outside run-to-run noise, most run 1–4 % faster. ## What's Changed * Backport: a removed property slot is a tombstone, not a free slot to reuse (#3273) by @lahma in sebastienros/jint#3318 * Backport: LengthOfArrayLike, delete the uint overload rather than clamp it (#3248) by @lahma in sebastienros/jint#3328 * Temporal and Intl parsing cannot fail because the machine was busy (#3486) by @lahma in sebastienros/jint#3543 * Backport: the process-wide Intl culture cache and Temporal zone cache are read-only and bounded, and a rejected zone is not remembered by @lahma in sebastienros/jint#3546 * Array: map and slice hand a @@species constructor the length ToLength produced (#3510) by @lahma in sebastienros/jint#3547 * Generators: a yield* delegation both re-delegates and keeps its place (backport of #3506 and #3518) by @lahma in sebastienros/jint#3545 * A module graph too deep to link raises an error the host can catch, instead of ending the process (#3415) by @lahma in sebastienros/jint#3548 * String to number: a trailing NUL pads neither a number string nor an array index (backport of #3544) by @lahma in sebastienros/jint#3552 * Interop: a host operator reports what it threw, and an overload the argument cannot bind to is not a match by @lahma in sebastienros/jint#3554 * Temporal: a difference past a calendar's range raises RangeError instead of spinning (#3452) by @lahma in sebastienros/jint#3555 * Interop: a read-only host collection refuses script with a JavaScript error, not the CLR's own (backport of #3385) by @lahma in sebastienros/jint#3556 * ShadowRealm: a value the host registers, and the members its wrapper builds eagerly, belong to that realm by @lahma in sebastienros/jint#3557 * Interop: two engines in one process do not decide each other's conversions and operators (backport of #3521 and #3526) by @lahma in sebastienros/jint#3559 * Interop: an index on a wrapped host collection is one property, and a filter that hides the indexer hides it by @lahma in sebastienros/jint#3562 * Interop: a host type converter's answer stays with the engine whose converter gave it by @lahma in sebastienros/jint#3563 * Interop: an operator overload is chosen by the arguments in hand (backport of #3578) by @lahma in sebastienros/jint#3611 * Intl: a calendar counting Gregorian months writes their names (backport of #3589) by @lahma in sebastienros/jint#3612 * Intl: a `-u-` extension carrying more than one key is read whole (backport of #3594) by @lahma in sebastienros/jint#3613 * JavaScriptException: only a string "stack" counts as a pre-existing stack (#3607 backport) by @lahma in sebastienros/jint#3677 * Interop: a params overload is chosen by the array's element type, and a failing element declines instead of throwing (#3764) by @lahma in sebastienros/jint#3782 * Backport #3751 to 4.x: Temporal: the persian calendar extends into proleptic years on the 33-year cycle by @lahma in sebastienros/jint#4006 * Backport #3922 to 4.x: Restore realm construction state after nesting or failure by @lahma in sebastienros/jint#4008 * Backport #3845 to 4.x: Propagate native errors during call argument evaluation by @lahma in sebastienros/jint#4009 * Backport #3877 to 4.x: Guard native recursion and forwarding paths by @lahma in sebastienros/jint#4007 **Full Changelog**: sebastienros/jint@v4.16.1...v4.16.2 Commits viewable in [compare view](sebastienros/jint@v4.16.1...v4.16.2). </details> Updated [Microsoft.AspNetCore](https://github.com/dotnet/aspnetcore) from 2.3.12 to 2.3.13. <details> <summary>Release notes</summary> _Sourced from [Microsoft.AspNetCore's releases](https://github.com/dotnet/aspnetcore/releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/dotnet/aspnetcore/commits). </details> Updated [Microsoft.AspNetCore.Server.Kestrel.Core](https://github.com/dotnet/aspnetcore) from 2.3.12 to 2.3.13. <details> <summary>Release notes</summary> _Sourced from [Microsoft.AspNetCore.Server.Kestrel.Core's releases](https://github.com/dotnet/aspnetcore/releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/dotnet/aspnetcore/commits). </details> Updated [System.Security.Cryptography.Xml](https://github.com/dotnet/dotnet) from 10.0.11 to 10.0.12. <details> <summary>Release notes</summary> _Sourced from [System.Security.Cryptography.Xml's releases](https://github.com/dotnet/dotnet/releases)._ No release notes found for this version range. Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits). </details> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Sep 14, 2026
legrab
added a commit
to legrab/pocok
that referenced
this pull request
Sep 15, 2026
Updated [Jint](https://github.com/sebastienros/jint) from 4.16.1 to 4.16.2. <details> <summary>Release notes</summary> _Sourced from [Jint's releases](https://github.com/sebastienros/jint/releases)._ ## 4.16.2 Jint 4.16.2 is a maintenance release from the `4.x` branch: **correctness and conformance fixes backported from `main`, and nothing that changes an existing API or an existing default.** If you are on 4.16.1 it is a drop-in update — every public signature is the one 4.16.0 shipped, on all five target frameworks, and the per-framework snapshots in `Jint.Tests.PublicInterface/Verify/` are unchanged. `main` remains 5.0.0 development; what is coming there is recorded as it lands in [`docs/v5-migration.md`](https://github.com/sebastienros/jint/blob/main/docs/v5-migration.md). ### Highlights **Failures that used to end the process, or never end.** A native error raised while a call's arguments are being evaluated is propagated instead of leaving an empty value behind, which on 4.16.1 could recurse until the process died — `decodeURIComponent` on a malformed sequence was enough (#4009). Native recursion and the forwarding paths through bound functions and proxies are guarded so a deep native chain raises a catchable error (#4007). A module graph too deep to link raises an error the host can catch instead of overflowing the stack (#3548). Temporal and Intl parsing cannot throw an uncatchable `RegexMatchTimeoutException` because the machine was busy (#3543), a Temporal difference past a calendar's range raises `RangeError` instead of spinning forever (#3555), and the process-wide Intl culture cache and Temporal zone cache are read-only and bounded, with a rejected zone no longer remembered — closing a script-driven unbounded growth (#3546). **Generators and built-ins, step by step.** A `yield*` delegation reached again by a loop both re-delegates and keeps its place: `countdown(3)` in a loop no longer hangs, and a delegating generator no longer returns the memoized first result (#3545). `Array.prototype.map` and `slice` hand a `@@species` constructor the length `ToLength` produced, and a non-callable `map` argument is a `TypeError` (#3547). A trailing NUL pads neither a numeric string nor an array index (#3552). A removed property slot is a tombstone rather than a free slot to reuse, so enumeration order survives a delete-and-readd (#3318), and `LengthOfArrayLike` no longer clamps through a `uint` overload (#3328). **Interop that answers for the right engine.** Two engines in one process no longer decide each other's conversions and operators (#3559), a host type converter's answer stays with the engine whose converter gave it (#3563), and a value the host registers on a `ShadowRealm` — and the members its wrapper builds eagerly — belong to that realm (#3557). Realm construction state is restored after nesting or a failure (#4008). Overload selection is by the arguments in hand: an operator overload is chosen that way (#3611), a `params` overload is chosen by the array's element type with a failing element declining rather than throwing (#3782), an overload the argument cannot bind to is not a match, and a host operator that throws reports what it threw (#3554). An index on a wrapped host collection is one property however it is spelled, and a member filter that hides the indexer hides it (#3562); a read-only host collection refuses a write with a JavaScript `TypeError` rather than the CLR's `NotSupportedException` (#3556). **Internationalization and Temporal.** The Persian calendar extends into proleptic years on its 33-year cycle, so the ends of Temporal's range land in the right Persian year (#4006); a calendar that counts Gregorian months writes their names (#3612); and a `-u-` extension carrying more than one key is read whole (#3613). **Errors.** Only a string-valued `stack` counts as a pre-existing stack when a `JavaScriptException` is built, so an accessor or non-string `stack` on a thrown object no longer breaks error reporting (#3677, reported by @jeske). Every change was verified failing-first against the unfixed branch on both .NET Framework and .NET 10, and the release was gated on a paired SunSpider and Dromaeo comparison against 4.16.1 on an idle machine: no row regressed outside run-to-run noise, most run 1–4 % faster. ## What's Changed * Backport: a removed property slot is a tombstone, not a free slot to reuse (#3273) by @lahma in sebastienros/jint#3318 * Backport: LengthOfArrayLike, delete the uint overload rather than clamp it (#3248) by @lahma in sebastienros/jint#3328 * Temporal and Intl parsing cannot fail because the machine was busy (#3486) by @lahma in sebastienros/jint#3543 * Backport: the process-wide Intl culture cache and Temporal zone cache are read-only and bounded, and a rejected zone is not remembered by @lahma in sebastienros/jint#3546 * Array: map and slice hand a @@species constructor the length ToLength produced (#3510) by @lahma in sebastienros/jint#3547 * Generators: a yield* delegation both re-delegates and keeps its place (backport of #3506 and #3518) by @lahma in sebastienros/jint#3545 * A module graph too deep to link raises an error the host can catch, instead of ending the process (#3415) by @lahma in sebastienros/jint#3548 * String to number: a trailing NUL pads neither a number string nor an array index (backport of #3544) by @lahma in sebastienros/jint#3552 * Interop: a host operator reports what it threw, and an overload the argument cannot bind to is not a match by @lahma in sebastienros/jint#3554 * Temporal: a difference past a calendar's range raises RangeError instead of spinning (#3452) by @lahma in sebastienros/jint#3555 * Interop: a read-only host collection refuses script with a JavaScript error, not the CLR's own (backport of #3385) by @lahma in sebastienros/jint#3556 * ShadowRealm: a value the host registers, and the members its wrapper builds eagerly, belong to that realm by @lahma in sebastienros/jint#3557 * Interop: two engines in one process do not decide each other's conversions and operators (backport of #3521 and #3526) by @lahma in sebastienros/jint#3559 * Interop: an index on a wrapped host collection is one property, and a filter that hides the indexer hides it by @lahma in sebastienros/jint#3562 * Interop: a host type converter's answer stays with the engine whose converter gave it by @lahma in sebastienros/jint#3563 * Interop: an operator overload is chosen by the arguments in hand (backport of #3578) by @lahma in sebastienros/jint#3611 * Intl: a calendar counting Gregorian months writes their names (backport of #3589) by @lahma in sebastienros/jint#3612 * Intl: a `-u-` extension carrying more than one key is read whole (backport of #3594) by @lahma in sebastienros/jint#3613 * JavaScriptException: only a string "stack" counts as a pre-existing stack (#3607 backport) by @lahma in sebastienros/jint#3677 * Interop: a params overload is chosen by the array's element type, and a failing element declines instead of throwing (#3764) by @lahma in sebastienros/jint#3782 * Backport #3751 to 4.x: Temporal: the persian calendar extends into proleptic years on the 33-year cycle by @lahma in sebastienros/jint#4006 * Backport #3922 to 4.x: Restore realm construction state after nesting or failure by @lahma in sebastienros/jint#4008 * Backport #3845 to 4.x: Propagate native errors during call argument evaluation by @lahma in sebastienros/jint#4009 * Backport #3877 to 4.x: Guard native recursion and forwarding paths by @lahma in sebastienros/jint#4007 **Full Changelog**: sebastienros/jint@v4.16.1...v4.16.2 Commits viewable in [compare view](sebastienros/jint@v4.16.1...v4.16.2). </details> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details>
This was referenced Sep 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #3486 (
main:ba18893a1) to4.x. Fixes #3485 on this branch too.What an embedder on 4.x sees today
Temporal.PlainDate.from('2024-01-15T10:30:00')— a correct call with a valid string — can throwSystem.Text.RegularExpressions.RegexMatchTimeoutException. It is not aJintExceptionand not aJavaScriptException: becauseRegexMatchTimeoutExceptionis listed inThrow.MustPropagateHostException,it goes straight through the script's own
try/catchand reaches the host as a raw CLR exceptionwhose message blames "very large inputs or excessive backtracking" for a 19-character valid string.
Regex.MatchTimeoutis a wall-clock deadline sampled while matching. It cannot tell "this pattern isbacktracking" apart from "this thread lost the CPU". Eight patterns in
TemporalHelpers.csand one inIntlUtilities.cscarried 100 ms of it on this branch, byte-identical to whatmaincarried.Evidence on this branch, before the fix
The new test file was compiled against unfixed
4.xfirst, on both legs.Jint.Teststargetsnet472(which resolves Jint'snet462asset) andnet10.0.net472→ Jintnet462net10.0Both legs failed identically:
The quadratic pattern, measured on this branch
AnnotationPattern—\[(!?)([^\]]+)\]— is quadratic on input holding no]: each of the n startpositions consumes the rest of the string and backtracks over it. A throwaway probe drove the shipped
pattern (
RegexOptions.Compiled) with'['×n, once with the 100 ms budget it ships with and once withRegex.InfiniteMatchTimeoutto read the genuine CPU cost:net472(Jintnet462) with 100 ms budgetnet472genuine CPUnet10.0genuine CPURegexMatchTimeoutExceptionRegexMatchTimeoutExceptionRegexMatchTimeoutExceptionRegexMatchTimeoutExceptionThat is real backtracking, not scheduling: 2x the input costs ~3x the time on both runtimes (
net10.0'srewritten engine has a far smaller constant but the same shape — 4.1 → 15.6 ms across the last doubling).
The linear walk that replaces it costs 0.126 ms on
net472and 0.107 ms onnet10.0over 200,000[.It was unreachable with such input only because its sole caller hands it
InstantPattern's group 14,which that grammar already guarantees is well-formed — an argument about the caller, not a property of the
code. The probe was deleted; it is not part of this PR.
The fix
Identical to #3486, applied unmodified:
TemporalHelpers.csand one inIntlUtilities.csnow takeRegex.InfiniteMatchTimeout. The failure mode is removed rather than relabelled.matching — bounds 13, 18 and 37, pinned so a widened pattern cannot outgrow its cap silently.
AnnotationPatternis replaced by a linear walk, pinned by a test that drives the walk and theretired pattern over ~5,000 inputs including the two cases the pattern's backtracking decided on its
own:
[], which has no content and is not an annotation, and[!], where the optional!is givenback to the content.
Options.Constraints.RegexTimeoutnever reached these patterns and still does not — it boundsscript-supplied regular expressions, unchanged.
Divergence from #3486
Jint.Testson4.xis xUnit v3, not NUnit.TemporalParsePatternBudgetTestsis transcribedattribute-for-attribute:
[Test]→[Fact],[TestCase(...)]→[Theory]+[InlineData(...)].Nothing else in the file changed — same assertions, same corpora, same seeds.
docs/v5-migration.mddoes not exist on4.x, so that hunk is dropped. There is nothing tomigrate: a host that caught
RegexMatchTimeoutExceptionaroundEngine.Evaluateto absorb this cansimply drop that handler.
4.x's pattern block is byte-identical to the pre-fixmainone,so the two source files are the same after this as they are on
main.Verification
dotnet build -c Release— clean,TreatWarningsAsErrorson.dotnet test -c Release, both TFMs where the project has one:Jint.Tests6,854 (net10.0) / 6,769 (net472),Jint.Tests.PublicInterface1,500 / 1,493,Jint.Tests.CommonScripts28 / 28,Jint.Tests.SourceGenerators52 — all green, 0 failed.staging/sm/Array/toSpliced-dense.jsandstaging/sm/TypedArray/sort_large_countingsort.js, each×2 for the strict/sloppy pair, each at 30–33 s, i.e. the engine's 30-second default timeout. All
four pass in isolation in 4 s total, and none of them touches Temporal or Intl. Load flakes on a
busy shared box, unrelated to this change.