Commit b386c17
fix: bound actor and date parsing
Address `GHSA-m64x-33q8-m5h7` in the shared `parse_actor_and_date()`
helper used for commit authors, committers, and annotated taggers.
Malformed metadata could make its regular expressions retry overlapping
field boundaries and consume excessive CPU time before returning.
Bound the leading field name at its first separator and check the line
ending once, before extracting the actor and date. The date expression
then needs no trailing wildcard or end assertion. Apply the same field
boundary to the actor-only fallback. This prevents repeated scans while
preserving accepted suffixes, Unicode digits, final newlines, and the
existing zero-date fallback for malformed input.
Add compatibility cases and CPU-time regressions for long malformed
metadata and multiline input, covering all three field names and long
valid names. Both timing regressions failed before the fix and pass
afterward. A separate comparison preserved capture groups in 3,240 cases.
Git reference: `git/git@d38352cd43ab9745686d697872408bc3249a153f`,
`ident.c:split_ident_line()` and `t/t4212-log-corrupt.sh`, which scan
identity delimiters directly and cover tolerant handling of invalid
dates. Retain GitPython's existing return values for malformed input.
Validation on Python 3.14.7:
- Focused parser tests: 17 passed.
- `test/test_util.py`, `test/test_actor.py`, `test/test_commit.py`, and
`test/test_refs.py`: 118 passed, 70 platform skips. Three tests passed
on rerun with the shared Git-directory access their fixtures require.
- Ruff 0.16.5 lint and formatting checks passed for both changed files.
- `git diff --check` passed.1 parent 153cc76 commit b386c17
2 files changed
Lines changed: 53 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
318 | 318 | | |
319 | 319 | | |
320 | 320 | | |
321 | | - | |
322 | | - | |
323 | | - | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
| 324 | + | |
324 | 325 | | |
325 | 326 | | |
326 | 327 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| 25 | + | |
25 | 26 | | |
26 | 27 | | |
27 | 28 | | |
| |||
571 | 572 | | |
572 | 573 | | |
573 | 574 | | |
| 575 | + | |
| 576 | + | |
| 577 | + | |
| 578 | + | |
| 579 | + | |
| 580 | + | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
574 | 623 | | |
575 | 624 | | |
576 | 625 | | |
| |||
0 commit comments