Fixed parser denial of service through deep nesting and nested list types - #626
Open
xperiandri wants to merge 2 commits into
Open
xperiandri wants to merge 2 commits into
xperiandri wants to merge 2 commits into
Conversation
…ypes - `Parser.parse` and `Parser.tryParse` scan the document first and reject braces, brackets and parentheses nested deeper than `DocumentLimitsDefaults.MaxNestingDepth` (128) outside of strings and comments, instead of overflowing the stack - List types are parsed once before looking for `!`, instead of backtracking from a non-null attempt, which took exponential time in the nesting depth - An integer out of the 64-bit range is a syntax error instead of an `OverflowException` escaping `tryParse` - Moved the test helper running code on a 1 MiB stack into `Helpers.fs` Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ings The scan ended comments only at `\n` and `\r` and skipped `"""` block strings, while the grammar also ends comments and strings at U+2028 and U+2029 and has no block strings, reading `""""` as two empty strings. Brackets after such a separator or a run of quotes were parsed but not counted, so deep nesting still overflowed the stack. - The scan and the grammar share one set of line terminators - The scan reads strings exactly as the grammar does, without block strings - Regression tests go through `Parser.tryParse` Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The security-sensitive parser changes appear coherent, but the stacked dependency and unavailable CI warrant final human review.
Review effort: Balanced
Findings: None
What changed in this PR
Adds parser-level protections against denial-of-service inputs while preserving normal GraphQL parsing behavior.
Changes:
- Enforces a nesting-depth limit before parsing.
- Makes nested list-type parsing linear and integer overflow recoverable.
- Adds focused parser-limit tests and a shared small-stack test helper.
| File | Description |
|---|---|
src/FSharp.Data.GraphQL.Shared/Parser.fs |
Implements nesting scanning and parser fixes. |
src/FSharp.Data.GraphQL.Shared/DocumentLimits.fs |
Documents parser and validation limits. |
tests/FSharp.Data.GraphQL.Tests/ParserLimitsTests.fs |
Covers nesting, list types, strings, comments, and integers. |
tests/FSharp.Data.GraphQL.Tests/Helpers.fs |
Adds the shared small-stack runner. |
tests/FSharp.Data.GraphQL.Tests/ValidationDoSTests.fs |
Uses the shared test helper. |
tests/FSharp.Data.GraphQL.Tests/FSharp.Data.GraphQL.Tests.fsproj |
Includes the new test file. |
RELEASE_NOTES.md |
Records security fixes and the breaking limit. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on the validation DoS fix in
validation-dos-fixes, which should be reviewed first; this PR only shows the parser commits.Problem
Three requests could take a server down through
Parser.tryParse, which the ASP.NET Core handler calls before anything else:[[…Int…]], never finishes parsing. The type parser triedNonNullTypefirst and backtracked, which parsed every nested level twice.OverflowExceptionout oftryParse, so the server answered with an unhandled exception.Changes
parse/tryParsefirst run a linear scan,tryFindNestingViolation. It rejects braces, brackets and parentheses nested deeper thanDocumentLimitsDefaults.MaxNestingDepth(128) outside of strings and comments. The error is an ordinary syntax error with the line and column, in FParsec'sError in Ln: L Col: Cform.\n,\r, U+2028 and U+2029.!, which is linear.Int64.TryParsewith the invariant culture replaces the conversion that threw; an out-of-range integer is now a syntax error.runOnSmallStackmoved toHelpers.fs, so both the validation and the parser tests use it.Tests
ParserLimitsTests.fs(xUnit) runs every case on a 1 MiB thread stack with a timeout:Int!,[Int!]!and[Int].The parser and validation limit tests pass in both Debug and Release. The whole unit test project passes: 810 tests passed, 5 skipped as before.
Stacked PRs get no CI run, because the workflow only runs for PRs into
masteranddev.🤖 Generated with Claude Code