lambdaclass / lambdaclass/lambda_compiler_kit
security: add input pattern length bounds in Parser.lean to prevent stack overflow
Nobody has claimed this yet.
- Dominant language
- Lean
- Stars
- 2
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
Problem
Lck/Regex/Parser.lean (lines 441-450) has no explicit bound on input pattern length. A sufficiently large pattern could cause a stack overflow.
Suggested Fix
Add a length check at the parser entry point and return an error for patterns exceeding a reasonable maximum (e.g., 10,000 characters).
References
Raised in AI code review.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with Lck/Regex/Parser.lean around lines 441-450 and trace the parser entry point and its existing error-return path. Add a maximum pattern-length check, then verify that oversized patterns return an error rather than causing a stack overflow.
Written by the indexing model from the issue text.
Assessment
- Domain
- compilers, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100