Skip to content

No Depth Limit on Nested Anonymous Types #795

Description

@InsertCreativityHere

Slice allows for Sequences, Dictionarys, and Results to be nested inside themselves and each other to arbitrary depth. The parser handles this gracefully since Slice is an LR-grammar. But proceeding validation logic will recursively walk these structures causing a stack overflow at around 600 levels of nesting (a 6 KB file on the 8 MB main-thread stack; far fewer levels on a 2 MB worker-thread stack).

Confirmed locations include:

  • slicec/src/visitor.rs:237
  • slicec/src/validators/cycle_detection.rs:76
  • slicec/src/grammar/elements/sequences.rs:12

This class of bug is also present within the preprocessor: #if ((((…))))), confirmed separately.

Reproducation:

python -c "n=600; open('deep.slice','w').write('module T\nstruct S { x: '+'Sequence<'*n+'int32'+'>'*n+' }\n')" && ./slicec deep.slice --dry-run

Fix:

Enforce a maximum nesting depth limit during parsing and emit a syntax diagnostic if it is passed.
Emitting a syntax diagnostic is key, since that will cause the compilation to early-exit before the validation logic runs.

Or

Change the logic in these locations to use iteration instead of native recursion, allowing the same work to be done, but with a bounded number of stack frames necessary.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

slicecRelated to the 'slicec' crate

Type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions