fix: drop a quadratic regex from the fake file watcher - #31
Merged
Conversation
`/\/+$/` stripping trailing separators is polynomial: the engine retries the greedy `\/+` from every position before `$` rejects it, so a base path of n separators costs time in n². CodeQL flags it as `js/polynomial-redos`, high. **It is not a vulnerability here** and the commit should not pretend otherwise. The input is `pattern.baseUri.path` from a `RelativePattern` the *test author* constructed — there is no untrusted path into a fake. What makes it worth fixing is that `src/testing/` is published code, the defect is real regardless of who can reach it, and counting backwards is both linear and easier to read than the regex was. Behaviour is identical: same trailing separators removed, and the existing watcher suites cover it. Verified: quality, verify:package, and both real-host lanes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
/\/+$/stripping trailing separators is polynomial: the engine retries thegreedy
\/+from every position before$rejects it, so a base path of nseparators costs time in n². CodeQL flags it as
js/polynomial-redos, high.It is not a vulnerability, and this PR should not pretend otherwise
The input is
pattern.baseUri.pathfrom aRelativePatternthe test authorconstructed. There is no untrusted path into a fake — reaching this needs you
to write the base URI yourself, in your own test.
What makes it worth fixing anyway:
src/testing/is published code, not internal scaffoldingScope
One
replacebecomes a named helper. Same trailing separators removed, sameresult for every input; the existing watcher suites cover it. The only other
+$insrc/is base64 padding inhtml.ts, bounded at two characters — notflagged, and correctly so.
Verification
quality,verify:package, and both real-host lanes (Extension Host and web).🤖 Generated with Claude Code