fix(#3477): run untrusted key_links patterns on a linear-time engine (#3496)

`cmdVerifyKeyLinks` compiled `must_haves.key_links[].pattern` from plan frontmatter with `new RegExp()` and tested it against whole file contents, so a nested-quantifier pattern such as `(a+)+$` hung `verify-phase` indefinitely (CWE-1333). JavaScript has no regex-execution timeout.

Untrusted patterns now run on RE2 (re2js), whose match time is linear in input length — the class is closed by the engine, not by a heuristic screen. The screen lost in the ADR-0174 consolidation was deliberately NOT restored: it never worked, since `(a|a)*$`, `((a+))+$`, `(a+){2,}$` and `(a{1,3})+$` all evade it. A refused pattern's matcher returns false for every input, so it cannot report a match no matter what the caller does.

The engine is vendored at gsd-core/bin/lib/vendor/re2js.cjs because gsd-core/bin/** is copied into installed trees with no node_modules; runtime dependencies are unchanged. New ESLint rule local/no-external-require-in-bin enforces that invariant, which had been documented in a comment since the #3024/#2071 bug class and enforced nowhere.

Backreferences and look-around are unsupported by RE2 by construction — disclosed in a Changed changeset.

Closes #3477

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-08-14 14:34:36 -04:00
committed by GitHub
parent b946051a46
commit 895d9df96d
19 changed files with 9067 additions and 17 deletions

View File

@@ -29,6 +29,7 @@ import requireFsOpFallback from './eslint-rules/require-fs-op-fallback.cjs';
import noUnboundedSpawn from './eslint-rules/no-unbounded-spawn.cjs';
import noDuplicateFoldMarker from './eslint-rules/no-duplicate-fold-marker.cjs';
import requireSubprocessTimeout from './eslint-rules/require-subprocess-timeout.cjs';
import noExternalRequireInBin from './eslint-rules/no-external-require-in-bin.cjs';
const localPlugin = {
rules: {
@@ -52,6 +53,7 @@ const localPlugin = {
'no-unbounded-spawn': noUnboundedSpawn,
'no-duplicate-fold-marker': noDuplicateFoldMarker,
'require-subprocess-timeout': requireSubprocessTimeout,
'no-external-require-in-bin': noExternalRequireInBin,
},
};
@@ -293,6 +295,15 @@ export default tseslint.config(
'gsd-core/bin/lib/workflow-fragments.cjs',
// ADR-1671 Phase 5 (#2932): tsc-generated runtime artifact — lint the src/section-manifest.cts source.
'gsd-core/bin/lib/section-manifest.cjs',
// #3477 follow-up: verbatim third-party artifact vendored so gsd-core/bin/**
// carries zero external requires (installed trees have no node_modules).
// See gsd-core/bin/lib/vendor/README.md; never lint/edit these by hand.
'gsd-core/bin/lib/vendor/**',
// Source-side twin of the same vendored .d.cts (needed so tsc resolves
// types for the relative './vendor/re2js.cjs' import from
// src/pattern.cts — module resolution for a .cts source is relative to
// src/, not the output dir). Same verbatim-third-party exemption.
'src/vendor/**',
],
},
@@ -342,6 +353,14 @@ export default tseslint.config(
// repo/missing network (DEFECT.UNBOUNDED-SUBPROCESS in CONTEXT.md).
// The 8 pre-existing call sites this surfaced were migrated in #2896.
'local/require-subprocess-timeout': 'error',
// #3477 follow-up: every src/**/*.cts module compiles 1:1 into
// gsd-core/bin/lib/*.cjs, which ships into installed trees with no
// node_modules — and the emitted mirror is almost always
// eslint-ignored as a generated artifact (see the src/pattern.cts note
// in eslint-rules/no-external-require-in-bin.cjs), so this is the ONLY
// place a bad external import in an already-migrated module is still
// visible to lint.
'local/no-external-require-in-bin': 'error',
},
},
@@ -428,6 +447,34 @@ export default tseslint.config(
},
},
// ── gsd-core/bin/**/*.cjs only — no-external-require-in-bin ────────────────
// A NARROWER block than the combined glob above on purpose: gsd-core/bin/**
// is the ONLY surface in that shared glob that is copied verbatim into
// installed trees with no node_modules (scripts/**, eslint-rules/**,
// bin/lib/**, pi/**, examples/**, vscode/*.js, .kilo/plugins/*.js, and
// .opencode/plugins/*.js all run inside THIS repo checkout, where
// node_modules exists, and legitimately require npm packages). Registering
// this rule on the shared block above would falsely flag every one of
// those. #3477 follow-up: re2js was the live instance of this defect —
// src/pattern.cts (compiled to gsd-core/bin/lib/pattern.cjs) shipped
// `import { RE2JS } from 're2js'` and broke `verify` for every installed
// user until the dependency was vendored under gsd-core/bin/lib/vendor/.
{
files: ['gsd-core/bin/**/*.cjs'],
plugins: {
local: localPlugin,
},
languageOptions: {
sourceType: 'commonjs',
globals: {
...globals.node,
},
},
rules: {
'local/no-external-require-in-bin': 'error',
},
},
// ── hooks/**/*.js — enforcement hooks (#3059) ──────────────────────────────
{
files: ['hooks/**/*.js', 'hooks/**/*.cjs'],