limit expression nesting depth to avoid bare RecursionError - #377
Open
choudhryfrompak wants to merge 1 commit into
Open
choudhryfrompak wants to merge 1 commit into
choudhryfrompak wants to merge 1 commit into
Conversation
_expression() recurses once per nesting level of the parsed expression with no bound. A deeply nested expression string (e.g. 50,000 levels of '[') drives the interpreter's call stack to its limit and raises a bare RecursionError, not jmespath.exceptions.ParseError or any other member of this library's own exception hierarchy - so a caller following the documented error-handling pattern (catching only JMESPathError around compile()/search()) does not catch it. Add _MAX_EXPRESSION_DEPTH (100, well above any realistic hand-written or generated expression) to Parser, track the current depth across the single shared recursive entry point (_expression), and raise a regular ParseError past that depth instead of recursing further. Adds 4 regression tests: a too-deep expression raises ParseError and never leaks a RecursionError, a reasonably nested expression still parses, and depth correctly resets between separate parse() calls on the same (possibly cache-reused) Parser instance. Full existing test suite (995 tests, including the upstream JMESPath compliance suite) passes unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
_expression() recurses once per nesting level of the parsed expression with no bound. A deeply nested expression (e.g. 50,000 levels of
[) drives the interpreter's call stack to its limit and raises a bareRecursionError, notjmespath.exceptions.ParseErroror any other member of this library's own exception hierarchy — so a caller following the documented error-handling pattern (catching onlyJMESPathErroraroundcompile()/search()) does not catch it.Fix: add
_MAX_EXPRESSION_DEPTH(100, well above any realistic expression), track depth through the single shared recursive entry point, raise a regularParseErrorpast that depth instead of recursing further.4 new regression tests, full existing suite (995 tests, including the upstream JMESPath compliance suite) passes unchanged.