envoyproxy / envoyproxy/java-control-plane

Heads up: max_program_size deprecation will require re2j changes to allow validation

Đang mở
#138 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
enhancement
Ngôn ngữ chính
Java
Star
312
Fork
149
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

This is just documenting the information that may be necessary if java-control-plane wants to start validating regular expression [max_program_size](https://github.com/envoyproxy/envoy/blob/1d03d302ba9670d04cc8c731393be90ff7b47f2f/api/envoy/type/matcher/regex.proto#L23)s. __This is unnecessary if the regular expressions are considered "trusted"__ (known to be non-malicious).

I had this information and wanted to dump it somewhere that it may be useful if the need arises. It _seems_ there is no explicit management of GoogleRE2 in this repo. Feel free to close.

-----

In https://github.com/envoyproxy/envoy/pull/10971, Envoy deprecated the max_program_size configuration field in favor of the control plane being responsible. This is great, and works for C++ and Go languages, but leaves some TODOs for Java.

The C++ re2 exposes [RE2::ProgramSize()](https://github.com/google/re2/blob/e48b461c1e3e09574300587672c2498b77bc24dc/re2/re2.h#L300-L302) which reports [the number of instructions](https://github.com/google/re2/blob/e48b461c1e3e09574300587672c2498b77bc24dc/re2/prog.cc#L631) of the compiled regular expression. This is the "program size" that Envoy was referring to.

Go's `regexp/syntax` package allows getting something similar:
```
regex, err := syntax.Parse("INPUT HERE", 0)
prog, err := syntax.Compile(regex)
len(prog.Inst) // this is the program size
```

But it does not appear re2j supports such a feature. Basically, you will need a new Pattern method that [returns the length of `Prog.inst`](https://github.com/google/re2j/blob/9708be1d64e75cd096352e08724dc596666040dc/java/com/google/re2j/Prog.java#L17) (via re2.prog).

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.