Skip to content

core: enforce recursion depth limits when parsing function parameters and arguments - #1340

Open
jdymitarai wants to merge 1 commit into
google:masterfrom
jdymitarai:fix/parser-depth-params-args
Open

jdymitarai wants to merge 1 commit into
google:masterfrom
jdymitarai:fix/parser-depth-params-args

Conversation

@jdymitarai

Copy link
Copy Markdown

Root Cause

While recursion depth tracking was introduced in Parser functions, parseParams did not check current_depth >= MAX_PARSER_DEPTH before processing arguments, and call sites in parseBind, parseObjectRemainder, maybeParseGreedy, and parseInfix passed current_depth without incrementing it. This permitted deeply nested function parameter lists and call arguments to consume unbounded stack frames, resulting in stack overflow crashes (SIGSEGV).

Fix Approach

Add a recursion depth guard in Parser::parseParams and increment current_depth when dispatching parseParams and parseArgs across binding and infix expression parsing.

Verification

  • Added TestMaxDepthLimit in core/parser_test.cpp verifying that deeply nested brackets, parentheses, and unary expressions trigger static parse depth errors cleanly.
  • Verified that flat iterative operations (binary arithmetic and chained indexing) continue parsing without false positive depth limit errors.
  • Verified with Semgrep (0 security issues).

Fixes #1116

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

stack-overflow exists in the function parse in parser.cpp

1 participant