1
0
mirror of https://github.com/golang/go synced 2024-11-11 19:21:37 -07:00
go/src
Russ Cox ac071634c4 [release-branch.go1.17] regexp/syntax: reject very deeply nested regexps in Parse
The regexp code assumes it can recurse over the structure of
a regexp safely. Go's growable stacks make that reasonable
for all plausible regexps, but implausible ones can reach the
“infinite recursion?” stack limit.

This CL limits the depth of any parsed regexp to 1000.
That is, the depth of the parse tree is required to be ≤ 1000.
Regexps that require deeper parse trees will return ErrInternalError.
A future CL will change the error to ErrInvalidDepth,
but using ErrInternalError for now avoids introducing new API
in point releases when this is backported.

Fixes #51112.
Fixes #51118.

Change-Id: I97d2cd82195946eb43a4ea8561f5b95f91fb14c5
Reviewed-on: https://go-review.googlesource.com/c/go/+/384616
Trust: Russ Cox <rsc@golang.org>
Run-TryBot: Russ Cox <rsc@golang.org>
Reviewed-by: Ian Lance Taylor <iant@golang.org>
Reviewed-on: https://go-review.googlesource.com/c/go/+/384854
TryBot-Result: Gopher Robot <gobot@golang.org>
2022-02-17 19:20:55 +00:00
..
archive [release-branch.go1.17] archive/zip: don't panic on (*Reader).Open 2021-11-03 16:57:44 +00:00
bufio
builtin
bytes
cmd [release-branch.go1.17] cmd/link: force eager binding when using plugins on darwin 2022-02-07 20:38:20 +00:00
compress
container
context
crypto [release-branch.go1.17] crypto/x509: support NumericString in DN components 2022-02-09 21:57:04 +00:00
database/sql database/sql: fix deadlock test in prepare statement 2021-06-21 17:37:23 +00:00
debug [release-branch.go1.17] debug/pe,debug/macho: add support for DWARF5 sections 2022-02-03 20:56:27 +00:00
embed [release-branch.go1.17] cmd/compile: allow embed into any byte slice type 2021-09-01 16:49:05 +00:00
encoding
errors
expvar
flag
fmt fmt: split package documentation into more sections 2021-06-07 15:17:48 +00:00
go [release-branch.go1.17] go/types: break cycles in invalid types 2021-12-01 23:34:46 +00:00
hash
html
image image/gif: fix typo in the comment (io.ReadByte -> io.ByteReader) 2021-06-30 17:58:50 +00:00
index/suffixarray
internal [release-branch.go1.17] reflect: keep pointer in aggregate-typed args live in Call 2021-12-21 22:57:03 +00:00
io io/fs: don't use absolute path in DirEntry.Name doc 2021-08-02 17:18:57 +00:00
log
math [release-branch.go1.17] math/big: prevent overflow in (*Rat).SetString 2022-01-28 15:39:12 +00:00
mime mime: document use of the Shared MIME-Info Database 2021-05-26 22:41:35 +00:00
net [release-branch.go1.17] net/http/internal/testcert: use FIPS-compliant certificate 2022-01-27 15:54:22 +00:00
os [release-branch.go1.17] syscall: do not use handle lists on windows when NoInheritHandles is true 2021-10-25 21:16:46 +00:00
path path/filepath: deflake TestEvalSymlinksAboveRoot on darwin 2021-06-30 20:03:34 +00:00
plugin
reflect [release-branch.go1.17] reflect: keep pointer in aggregate-typed args live in Call 2021-12-21 22:57:03 +00:00
regexp [release-branch.go1.17] regexp/syntax: reject very deeply nested regexps in Parse 2022-02-17 19:20:55 +00:00
runtime [release-branch.go1.17] runtime: set vdsoSP to caller's SP consistently 2022-02-07 22:08:06 +00:00
sort
strconv strconv: document parsing of leading +/- 2021-06-09 18:16:27 +00:00
strings
sync [release-branch.go1.17] sync/atomic: fix documentation for CompareAndSwap 2021-08-15 22:50:19 +00:00
syscall [release-branch.go1.17] syscall: avoid writing to p when Pipe(p) fails 2021-12-09 12:28:48 +00:00
testdata
testing testing: clarify T.Name returns a distinct name of the running test 2021-07-27 05:07:46 +00:00
text [release-branch.go1.17] text/template: initialize template before locking it 2021-09-23 21:18:37 +00:00
time [release-branch.go1.17] time: fix looking for zone offset when date is close to a zone transition 2021-11-29 19:46:17 +00:00
unicode
unsafe spec, unsafe: clarify unsafe.Slice docs 2021-07-02 19:26:52 +00:00
vendor [release-branch.go1.17] net/http: update bundled golang.org/x/net/http2 2022-01-06 15:30:17 +00:00
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod [release-branch.go1.17] net/http: update bundled golang.org/x/net/http2 2022-01-06 15:30:17 +00:00
go.sum [release-branch.go1.17] net/http: update bundled golang.org/x/net/http2 2022-01-06 15:30:17 +00:00
make.bash src/make.*: make --no-clean flag a no-op that prints a warning 2021-08-11 22:07:50 +00:00
make.bat src/make.*: make --no-clean flag a no-op that prints a warning 2021-08-11 22:07:50 +00:00
Make.dist
make.rc src/make.*: make --no-clean flag a no-op that prints a warning 2021-08-11 22:07:50 +00:00
race.bash
race.bat
README.vendor
run.bash
run.bat
run.rc

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

In GOPATH mode, imports of vendored packages are resolved to these
directories following normal vendor directory logic
(see golang.org/s/go15vendor).

In module mode, std and cmd are modules (defined in src/go.mod and
src/cmd/go.mod). When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure GO111MODULE=off is not set ('on' or 'auto' should work).

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src
    go get -d golang.org/x/net@latest
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not only
the module providing the target package.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.