Skip to content

Harden AUR HTTP error matching against regex backtracking - #763

Merged
timmo001 merged 2 commits into
distro/arch-omarchy-quattrofrom
copilot/fix-code-scanning-alerts
Sep 21, 2026
Merged

timmo001 merged 2 commits into
distro/arch-omarchy-quattrofrom
copilot/fix-code-scanning-alerts

Conversation

Copilot AI commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

This change addresses the code scanning finding in the AUR update backoff path. The HTTP/status error detection used a single regex with ambiguous repetition; it now uses simple bounded patterns that preserve the existing 4xx/5xx detection intent without the ReDoS risk.

  • AUR error classification

    • Replace the backtracking-prone stderr matcher in dot/src/commands/Updates.ts
    • Split detection into two explicit cases:
      • status ... 4xx/5xx
      • HTTP[/version] ... 4xx/5xx
  • Behaviour preserved

    • Keep the existing backoff flow unchanged
    • Continue treating AUR failures as retryable only when the error output indicates HTTP 4xx/5xx conditions
const AUR_HTTP_FAILURE_PATTERNS = [
  /\bstatus\b[^0-9]*\b[45][0-9]{2}\b/i,
  /\bhttp(?:\/\d+(?:\.\d+)?)?\b[^0-9]*\b[45][0-9]{2}\b/i,
] as const;

AUR_HTTP_FAILURE_PATTERNS.some((pattern) => pattern.test(aurResult.stderr));

Co-authored-by: timmo001 <28114703+timmo001@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix code scanning alert #4 in repository Harden AUR HTTP error matching against regex backtracking Sep 21, 2026
Copilot AI requested a review from timmo001 September 21, 2026 18:34
@timmo001
timmo001 marked this pull request as ready for review September 21, 2026 18:35
@timmo001
timmo001 enabled auto-merge (squash) September 21, 2026 18:35
@timmo001
timmo001 merged commit 8736169 into distro/arch-omarchy-quattro Sep 21, 2026
20 checks passed
@timmo001
timmo001 deleted the copilot/fix-code-scanning-alerts branch September 21, 2026 18:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants