Skip to content

Bound captured extension route backtracking - #188

Merged
agrafix merged 1 commit into
masterfrom
codex/fix-cpu-denial-of-service-vulnerability
Oct 1, 2026
Merged

agrafix merged 1 commit into
masterfrom
codex/fix-cpu-denial-of-service-vulnerability

Conversation

@agrafix

@agrafix agrafix commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Motivation

  • The PI_Extension parser enumerated every dot split for captured extensions and reparsed the left-hand pattern for each candidate, causing combinatorial backtracking and a CPU DoS risk for routes with chained captured extensions.
  • The intent is to bound attacker-controlled work during route selection while preserving behavior for fixed literal extensions.

Description

  • Added an early rejection in parsePrefix for PI_Extension that returns Nothing when the right-hand side requires split enumeration and the incoming segment contains more than maximumExtensionSeparators dots, implemented in reroute/src/Web/Routing/SafeRouting.hs.
  • Introduced maximumExtensionSeparators :: Int (set to 16) and helper extensionNeedsSearch so fixed literal suffix paths (PI_StaticCons and PI_Empty) keep the existing fast single-split behavior.
  • Kept the existing extensionSplits/dotSplits behavior for normal cases so functionality is preserved for benign inputs and literal extensions.
  • Added regression tests in reroute/test/Web/Routing/SafeRoutingSpec.hs that assert adversarial chained-capture inputs are rejected and that many-dot filenames still match fixed literal extensions.

Testing

  • Ran git diff --check to validate patch formatting and it passed.
  • Executed a small Python combinatorics check validating the chosen bound (sum of combinations up to 16 equals 2^16) and it passed.
  • The Haskell test-suite (cabal/stack/ghc) was not executed because the toolchain is not available in the environment, so reroute tests were not run locally.

Codex Task

@agrafix
agrafix marked this pull request as ready for review October 1, 2026 01:04
@agrafix
agrafix merged commit 872f97d into master Oct 1, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant