Skip to content

fix: bound actor and date parsing - #2253

Merged
Byron merged 1 commit into
mainfrom
fix-regex
Sep 27, 2026
Merged

Byron merged 1 commit into
mainfrom
fix-regex

Conversation

@Byron

@Byron Byron commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Tasks

This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.

  • refackiew

Everything below this line was generated by Codex GPT-6.

Created by Codex on behalf of Byron. Byron will review before this is ready to merge.

Bound parsing work for malformed actor metadata in the shared helper used by commit authors, committers, and annotated taggers. Preserve existing parsed values, accepted suffixes, and malformed-date fallbacks. Add compatibility and performance regression coverage.

Advisory summary

GHSA-m64x-33q8-m5h7: medium severity, affecting the GitPython package on PyPI (<= 3.1.62). The advisory currently lists no patched version or CVE identifier.

Validation

  • Both performance regressions failed before the fix; all 17 focused parser tests pass afterward.
  • Related utility, actor, commit, and reference tests: 118 passed, 70 platform skips. Three tests required a rerun with access to their temporary files in the shared Git directory.
  • Ruff 0.16.5 lint and formatting checks passed for both changed files; git diff --check passed.
  • A separate 3,240-case comparison preserved both expressions' capture groups.
  • Codex review of b386c177 found no actionable issues and independently checked capture groups across 97,656 inputs.

Git behavior reference: git/git@d38352cd43ab9745686d697872408bc3249a153f, ident.c:split_ident_line() and t/t4212-log-corrupt.sh, for delimiter scanning and tolerant handling of invalid dates.

<!-- agent -->
Address `GHSA-m64x-33q8-m5h7` in the shared `parse_actor_and_date()`
helper used for commit authors, committers, and annotated taggers.
Malformed metadata could make its regular expressions retry overlapping
field boundaries and consume excessive CPU time before returning.

Bound the leading field name at its first separator and check the line
ending once, before extracting the actor and date. The date expression
then needs no trailing wildcard or end assertion. Apply the same field
boundary to the actor-only fallback. This prevents repeated scans while
preserving accepted suffixes, Unicode digits, final newlines, and the
existing zero-date fallback for malformed input.

Add compatibility cases and CPU-time regressions for long malformed
metadata and multiline input, covering all three field names and long
valid names. Both timing regressions failed before the fix and pass
afterward. A separate comparison preserved capture groups in 3,240 cases.

Git reference: `git/git@d38352cd43ab9745686d697872408bc3249a153f`,
`ident.c:split_ident_line()` and `t/t4212-log-corrupt.sh`, which scan
identity delimiters directly and cover tolerant handling of invalid
dates. Retain GitPython's existing return values for malformed input.

Assisted-by: GPT 6.0
Co-authored-by: GPT 6.0 <codex@openai.com>
@Byron
Byron marked this pull request as ready for review September 27, 2026 19:17
Copilot AI lite review requested due to automatic review settings September 27, 2026 19:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Correct the failing parser expectation and add the required 3.2.1 release URL.

Review effort: Lite
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

This pull request hardens actor and date parsing against malformed or oversized metadata while preserving existing behavior.

Changes:

  • Replaces vulnerable regexes with bounded parsing patterns.
  • Adds compatibility and performance regression tests.
  • Documents the security advisory.
File Summary
test/​test_util.py Adds parser behavior and performance tests; one expected fallback requires correction.
git/​objects/​util.py Updates actor/date parsing regexes.
doc/​source/​changes.rst Records the security advisory; requires the forthcoming 3.2.1 release URL.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread test/test_util.py
Comment thread doc/source/changes.rst
@Byron
Byron merged commit 71b9545 into main Sep 27, 2026
51 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants