Skip to content

core: reduce MAX_PARSER_DEPTH to prevent stack overflow on deep nesting - #1339

Open
jdymitarai wants to merge 1 commit into
google:masterfrom
jdymitarai:fix/parser-stack-overflow
Open

jdymitarai wants to merge 1 commit into
google:masterfrom
jdymitarai:fix/parser-stack-overflow

Conversation

@jdymitarai

Copy link
Copy Markdown

Root Cause

When parsing deeply nested constructs (such as deep conditional expressions, assert chains, or deeply nested arrays), recursive descent parser calls consume stack space across Parser::parse, maybeParseGreedy, and parseTerminalBracketsOrUnary. Under AddressSanitizer or default thread stack allocations, stack exhaustion occurs before reaching MAX_PARSER_DEPTH = 1000, causing an unhandled stack-overflow crash (SIGSEGV).

Fix Approach

Reduce MAX_PARSER_DEPTH from 1000 to 500. This ensures that pathological or deeply nested expressions exceed the parse depth limit and abort cleanly via StaticError before the host execution stack is exhausted.

Verification

  • Added test_suite/error.parse.deep_if_nesting.jsonnet and corresponding golden output to verify deep conditional chains trigger static depth errors cleanly without stack overflow.
  • Updated test_suite/error.parse.deep_array_nesting.jsonnet.golden to match the 500 depth limit.
  • Verified with AddressSanitizer and Semgrep.

Fixes #1117

When parsing deeply nested structures (e.g. conditional branches, assert chains, or deep arrays), recursive descent parser calls consume stack frame space that can exhaust the thread stack under AddressSanitizer or default stack sizes before reaching MAX_PARSER_DEPTH = 1000.

Lower MAX_PARSER_DEPTH to 500 to reliably trigger a controlled static error before stack memory exhaustion, preventing ASAN stack-overflow / SIGSEGV.

Fixes google#1117

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

stack-overflow exists in the function maybeParseGreedy in parser.cpp

1 participant