diff --git a/.licenses/npm/brace-expansion-1.1.18.dep.yml b/.licenses/npm/brace-expansion-1.1.16.dep.yml similarity index 99% rename from .licenses/npm/brace-expansion-1.1.18.dep.yml rename to .licenses/npm/brace-expansion-1.1.16.dep.yml index 32de44b..0dd0376 100644 --- a/.licenses/npm/brace-expansion-1.1.18.dep.yml +++ b/.licenses/npm/brace-expansion-1.1.16.dep.yml @@ -1,6 +1,6 @@ --- name: brace-expansion -version: 1.1.18 +version: 1.1.16 type: npm summary: Brace expansion as known from sh/bash homepage: https://github.com/juliangruber/brace-expansion diff --git a/.licenses/npm/brace-expansion-5.0.9.dep.yml b/.licenses/npm/brace-expansion-5.0.8.dep.yml similarity index 98% rename from .licenses/npm/brace-expansion-5.0.9.dep.yml rename to .licenses/npm/brace-expansion-5.0.8.dep.yml index fd7e18f..f40e870 100644 --- a/.licenses/npm/brace-expansion-5.0.9.dep.yml +++ b/.licenses/npm/brace-expansion-5.0.8.dep.yml @@ -1,6 +1,6 @@ --- name: brace-expansion -version: 5.0.9 +version: 5.0.8 type: npm summary: Brace expansion as known from sh/bash homepage: diff --git a/.licenses/npm/undici.dep.yml b/.licenses/npm/undici.dep.yml index b339a44..c46a5c7 100644 --- a/.licenses/npm/undici.dep.yml +++ b/.licenses/npm/undici.dep.yml @@ -1,6 +1,6 @@ --- name: undici -version: 6.28.0 +version: 6.27.0 type: npm summary: An HTTP/1.1 client, written from scratch for Node.js homepage: https://undici.nodejs.org diff --git a/dist/cache-save/index.js b/dist/cache-save/index.js index a5b4218..59f8a5a 100644 --- a/dist/cache-save/index.js +++ b/dist/cache-save/index.js @@ -84,20 +84,6 @@ var escClose = '\0CLOSE'+Math.random()+'\0'; var escComma = '\0COMMA'+Math.random()+'\0'; var escPeriod = '\0PERIOD'+Math.random()+'\0'; -var EXPANSION_MAX = 100000 - -// `EXPANSION_MAX` caps the *number* of expansions, but not their length. An -// input like `'{a,b}'.repeat(1500)` stays under that count - its output is -// truncated to 100k results - while making every result ~1500 characters -// long. The result set, and the intermediate arrays built while combining -// brace sets, then grow large enough to exhaust memory and crash the process -// (CVE-2026-14257). `EXPANSION_MAX_LENGTH` bounds the total number of -// characters the accumulator may hold at any point, so memory stays flat no -// matter how many brace groups are chained. The limit sits well above any -// realistic expansion (100k results hitting `EXPANSION_MAX` measure ~1M -// characters) so legitimate input is unaffected. -var EXPANSION_MAX_LENGTH = 4000000 - function numeric(str) { return parseInt(str, 10) == str ? parseInt(str, 10) @@ -156,8 +142,7 @@ function expandTop(str, options) { return []; options = options || {}; - var max = options.max == null ? EXPANSION_MAX : options.max; - var maxLength = options.maxLength == null ? EXPANSION_MAX_LENGTH : options.maxLength; + var max = options.max == null ? Infinity : options.max; // I don't know why Bash 4.3 does this, but it does. // Anything starting with {} will have the first two bytes preserved @@ -169,7 +154,7 @@ function expandTop(str, options) { str = '\\{\\}' + str.substr(2); } - return expand(escapeBraces(str), max, maxLength, true).map(unescapeBraces); + return expand(escapeBraces(str), max, true).map(unescapeBraces); } function identity(e) { @@ -190,155 +175,15 @@ function gte(i, y) { return i >= y; } -// Build `{ acc[a] + pre + values[v] }` for every combination, capping the -// number of results at `max` and the total number of characters at `maxLength`. -// This is the one place output grows, so bounding it here keeps the single -// accumulator - and therefore memory - flat regardless of how many brace groups -// are combined (CVE-2026-14257). -// -// `base[a]` is the length of the part of `acc[a]` that predates the current -// empty-drop baseline (see `expand`). The matching baselines for the results -// are appended to `outBase`, which the caller carries forward alongside them. -function combine( - acc, - base, - pre, - values, - max, - maxLength, - dropEmpties, - outBase -) { - var out = [] - var length = 0 - for (var a = 0; a < acc.length; a++) { - for (var v = 0; v < values.length; v++) { - if (out.length >= max) return out - var expansion = acc[a] + pre + values[v] - // Bash drops empty results at the top level. Skip them before they count - // against `max`, so `max` bounds the number of *kept* results. "Empty" - // means "adds nothing past the baseline", not "empty overall". - if (dropEmpties && expansion.length === base[a]) continue - if (length + expansion.length > maxLength) return out - out.push(expansion) - outBase.push(base[a]) - length += expansion.length - } - } - return out -} - -// The expansion values of a single numeric (`1..5`) or alphabetic (`a..e..2`) -// sequence body. -function expandSequence( - body, - isAlphaSequence, - max, - maxLength -) { - var n = body.split(/\.\./) - var N = [] - // A sequence body always splits into two or three parts, but the compiler - // can't know that. - /* c8 ignore start */ - if (n[0] === undefined || n[1] === undefined) { - return N - } - /* c8 ignore stop */ - var x = numeric(n[0]) - var y = numeric(n[1]) - var width = Math.max(n[0].length, n[1].length) - var incr = - n.length === 3 && n[2] !== undefined ? - Math.max(Math.abs(numeric(n[2])), 1) - : 1 - var test = lte - var reverse = y < x - if (reverse) { - incr *= -1 - test = gte - } - var pad = n.some(isPadded) - - var length = 0 - for (var i = x; test(i, y) && N.length < max; i += incr) { - var c - if (isAlphaSequence) { - c = String.fromCharCode(i) - if (c === '\\') { - c = '' - } - } else { - c = String(i) - if (pad) { - var need = width - c.length - if (need > 0) { - var z = new Array(need + 1).join('0') - if (i < 0) { - c = '-' + z + c.slice(1) - } else { - c = z + c - } - } - } - } - if (length + c.length > maxLength) break - N.push(c) - length += c.length - } - return N -} - -function expand( - str, - max, - maxLength, - isTop -) { - // Consume the string's top-level brace groups left to right, threading a - // running set of combined prefixes (`acc`). Expanding the tail iteratively - - // rather than recursing on `m.post` once per group - keeps the native stack - // depth constant, so deeply chained input (`'{a,b}'.repeat(3000)`) can no - // longer overflow the stack, and leaves a single accumulator whose size - // `maxLength` bounds directly (CVE-2026-14257). - var acc = [''] - - // Bash drops empty results, but only when the *first* group of the run is a - // comma set - a sequence like `{a..\}` may legitimately yield ''. The drop - // is on the final strings, so it is applied to whichever `combine` produces - // them (the one with no brace set left in the tail). - // - // The old implementation recursed on `m.post`, so the drop tested only the - // expansion of the current call's substring. The `{a},b}` rewrite below turns - // `isTop` back on part-way through a string, starting a fresh such run, so - // the drop must ignore whatever `acc` already holds from earlier groups. - // `accBase[a]` records how much of `acc[a]` predates the current run; - // `combine` treats an expansion as empty when it adds nothing past that. - var accBase = [0] - var dropEmpties = false - var firstGroup = true - var nextBase +function expand(str, max, isTop) { + var expansions = []; + // The `{a},b}` rewrite below restarts expansion on a rewritten string with + // the same `max` and `isTop = true`. Loop instead of recursing so a long run + // of non-expanding `{}` groups can't exhaust the call stack. for (;;) { var m = balanced('{', '}', str); - - // No brace set left: the rest of the string is literal. - if (!m) { - return combine(acc, accBase, str, [''], max, maxLength, dropEmpties, []) - } - - // no need to expand pre, since it is guaranteed to be free of brace-sets - var pre = m.pre; - - // For compatibility reasons, `${` is not eligible for brace expansion, and - // on the 1.x line it suppresses expansion of the rest of the string too: - // the whole remainder is literal. The 2.x and 5.x lines instead keep - // expanding the tail, which is what bash does, but changing that here would - // be a breaking change for 1.x consumers. Routed through `combine` so the - // result is still bounded by `max` and `maxLength`. - if (/\$$/.test(pre)) { - return combine(acc, accBase, str, [''], max, maxLength, dropEmpties, []) - } + if (!m || /\$$/.test(m.pre)) return [str]; var isNumericSequence = /^-?\d+\.\.-?\d+(?:\.\.-?\d+)?$/.test(m.body); var isAlphaSequence = /^[a-zA-Z]\.\.[a-zA-Z](?:\.\.-?\d+)?$/.test(m.body); @@ -348,112 +193,94 @@ function expand( // {a},b} if (m.post.match(/,(?!,).*\}/)) { str = m.pre + '{' + m.body + escClose + m.post; - // The rewritten string is expanded as if it were a fresh top-level one, - // so start a new empty-drop run: anchor the baseline at what `acc` - // holds now, and let the next expanding group decide whether to drop. isTop = true - firstGroup = true - dropEmpties = false - accBase = [] - for (var b = 0; b < acc.length; b++) { - accBase.push(acc[b].length) - } continue } - // Nothing here expands, so the whole remaining string is literal. - return combine( - acc, - accBase, - pre + '{' + m.body + '}' + m.post, - [''], - max, - maxLength, - dropEmpties, - [] - ) + return [str]; } - if (firstGroup) { - dropEmpties = isTop && !isSequence - firstGroup = false - } - - var values; + var n; if (isSequence) { - values = expandSequence(m.body, isAlphaSequence, max, maxLength); + n = m.body.split(/\.\./); } else { - var n = parseCommaParts(m.body); - if (n.length === 1 && n[0] !== undefined) { + n = parseCommaParts(m.body); + if (n.length === 1) { // x{{a,b}}y ==> x{a}y x{b}y - n = expand(n[0], max, maxLength, false).map(embrace); - //XXX is this necessary? Can't seem to hit it in tests. - /* c8 ignore start */ + n = expand(n[0], max, false).map(embrace); if (n.length === 1) { - nextBase = [] - acc = combine( - acc, - accBase, - pre + n[0], - [''], - max, - maxLength, - dropEmpties && !m.post.length, - nextBase - ) - accBase = nextBase - if (!m.post.length) break - str = m.post - continue - } - /* c8 ignore stop */ - } - - // Values that `combine` is going to drop as empty produce no result, so - // they must not count against `max` - otherwise `{a,,b}` with `max: 2` - // would stop at `['a', '']` and yield one result instead of two. Skipping - // them outright keeps `values` bounded while leaving `max` a bound on - // *kept* results. A value is dropped when it adds nothing past the - // baseline, which is what `combine` tests. - var dropsEmpties = dropEmpties && !m.post.length && !pre - for (var d = 0; dropsEmpties && d < acc.length; d++) { - if (acc[d].length !== accBase[d]) { - dropsEmpties = false - } - } - - values = [] - var valuesLength = 0 - outer: for (var j = 0; j < n.length; j++) { - var expanded = expand(n[j], max, maxLength, false) - for (var k = 0; k < expanded.length; k++) { - var v = expanded[k] - if (dropsEmpties && !v) continue - if (values.length >= max || valuesLength + v.length > maxLength) { - break outer - } - values.push(v) - valuesLength += v.length + var post = m.post.length + ? expand(m.post, max, false) + : ['']; + return post.map(function(p) { + return m.pre + n[0] + p; + }); } } } - nextBase = [] - acc = combine( - acc, - accBase, - pre, - values, - max, - maxLength, - dropEmpties && !m.post.length, - nextBase - ) - accBase = nextBase - if (!m.post.length) break - str = m.post - } + // at this point, n is the parts, and we know it's not a comma set + // with a single entry. - return acc + // no need to expand pre, since it is guaranteed to be free of brace-sets + var pre = m.pre; + var post = m.post.length + ? expand(m.post, max, false) + : ['']; + + var N; + + if (isSequence) { + var x = numeric(n[0]); + var y = numeric(n[1]); + var width = Math.max(n[0].length, n[1].length) + var incr = n.length == 3 + ? Math.max(Math.abs(numeric(n[2])), 1) + : 1; + var test = lte; + var reverse = y < x; + if (reverse) { + incr *= -1; + test = gte; + } + var pad = n.some(isPadded); + + N = []; + + for (var i = x; test(i, y) && N.length < max; i += incr) { + var c; + if (isAlphaSequence) { + c = String.fromCharCode(i); + if (c === '\\') + c = ''; + } else { + c = String(i); + if (pad) { + var need = width - c.length; + if (need > 0) { + var z = new Array(need + 1).join('0'); + if (i < 0) + c = '-' + z + c.slice(1); + else + c = z + c; + } + } + } + N.push(c); + } + } else { + N = concatMap(n, function(el) { return expand(el, max, false) }); + } + + for (var j = 0; j < N.length; j++) { + for (var k = 0; k < post.length && expansions.length < max; k++) { + var expansion = pre + N[j] + post[k]; + if (!isTop || isSequence || expansion) + expansions.push(expansion); + } + } + + return expansions; + } } @@ -14377,13 +14204,7 @@ function processHeader (request, key, val) { } else if (typeof val[i] === 'object') { throw new InvalidArgumentError(`invalid ${key} header`) } else { - // Coerce primitives (and reject unsafe coercions such as functions - // with a crafted toString/Symbol.toPrimitive). - const str = `${val[i]}` - if (!isValidHeaderValue(str)) { - throw new InvalidArgumentError(`invalid ${key} header`) - } - arr.push(str) + arr.push(`${val[i]}`) } } val = arr @@ -14394,12 +14215,7 @@ function processHeader (request, key, val) { } else if (val === null) { val = '' } else { - // Coerce primitives (and reject unsafe coercions such as functions - // with a crafted toString/Symbol.toPrimitive). val = `${val}` - if (!isValidHeaderValue(val)) { - throw new InvalidArgumentError(`invalid ${key} header`) - } } if (headerName === 'host') { @@ -15771,7 +15587,6 @@ const { RequestContentLengthMismatchError, ResponseContentLengthMismatchError, RequestAbortedError, - InvalidArgumentError, HeadersTimeoutError, HeadersOverflowError, SocketError, @@ -16755,16 +16570,8 @@ function writeH1 (client, request) { } body = bodyStream.stream contentLength = bodyStream.length - } else if (util.isBlobLike(body) && request.contentType == null) { - const contentType = body.type - if (contentType) { - const contentTypeValue = `${contentType}` - if (!util.isValidHeaderValue(contentTypeValue)) { - util.errorRequest(client, request, new InvalidArgumentError('invalid content-type header')) - return false - } - headers.push('content-type', contentTypeValue) - } + } else if (util.isBlobLike(body) && request.contentType == null && body.type) { + headers.push('content-type', body.type) } if (body && typeof body.read === 'function') { @@ -20237,28 +20044,6 @@ function calculateRetryAfterHeader (retryAfter) { return new Date(retryAfter).getTime() - current } -function validatePartialResponseContentLength (headers, range, statusCode, retryCount) { - const contentLength = headers['content-length'] - if (contentLength == null) { - return null - } - - if (!Number.isFinite(range.start) || !Number.isFinite(range.end)) { - return null - } - - const length = Number(contentLength) - const expectedLength = range.end - range.start + 1 - if (!Number.isFinite(length) || length !== expectedLength) { - return new RequestRetryError('Content-Length mismatch', statusCode, { - headers, - data: { count: retryCount } - }) - } - - return null -} - class RetryHandler { constructor (opts, handlers) { const { retryOptions, ...dispatchOpts } = opts @@ -20473,12 +20258,6 @@ class RetryHandler { return false } - const contentLengthError = validatePartialResponseContentLength(headers, contentRange, statusCode, this.retryCount) - if (contentLengthError != null) { - this.abort(contentLengthError) - return false - } - const { start, size, end = size - 1 } = contentRange assert(this.start === start, 'content-range mismatch') @@ -20502,12 +20281,6 @@ class RetryHandler { ) } - const contentLengthError = validatePartialResponseContentLength(headers, range, statusCode, this.retryCount) - if (contentLengthError != null) { - this.abort(contentLengthError) - return false - } - const { start, size, end = size - 1 } = range assert( start != null && Number.isFinite(start), @@ -24752,7 +24525,7 @@ function validateCookiePath (path) { if ( code < 0x20 || // exclude CTLs (0-31) - code > 0x7E || // exclude DEL and non-ascii + code === 0x7F || // DEL code === 0x3B // ; ) { throw new Error('Invalid cookie path') @@ -24761,80 +24534,16 @@ function validateCookiePath (path) { } /** - * ::= | - * - * ::= any one of the 52 alphabetic characters A through Z in - * upper case and a through z in lower case - * - * ::= any one of the ten digits 0 through 9r - * - * @see https://www.rfc-editor.org/rfc/rfc1034#section-3.5 - * @param {number} code - */ -function isLetterOrDigit (code) { - return ( - (code >= 0x30 && code <= 0x39) || // 0-9 - (code >= 0x41 && code <= 0x5A) || // A-Z - (code >= 0x61 && code <= 0x7A) // a-z - ) -} - -/** - * Validates a cookie domain against the "preferred name syntax". - * - * ::= | " " - * ::=