Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

process: stricter sourceMappingURL regex #34392

Closed
wants to merge 1 commit into from
Closed

Conversation

bcoe
Copy link
Contributor

@bcoe bcoe commented Jul 16, 2020

The library brrp, which itself processes source maps, had its
processing logic erroneously loaded as a source map URL.

Checklist
  • make -j4 test (UNIX), or vcbuild test (Windows) passes
  • tests and/or benchmarks are included
  • documentation is changed or added
  • commit message follows commit guidelines

@jasnell I screwed up a rebase in such a way that I couldn't get #34305 to reopen.

This is #34305 rebased against the main branch.

The library brrp, which itself processes source maps, had its
processing logic erroneously loaded as a source map URL.
@bcoe bcoe requested review from jasnell, Trott and addaleax July 16, 2020 06:48
@nodejs-github-bot
Copy link
Collaborator

} else {
const c = 102;
}
const sm = '//# sourceMappingURL=https://ci.nodejs.org/402'
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is technically an unsolvable problem, assuming an adversary opponent. V8 has APIs for this on UnboundScript, can we use those instead?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

V8 also just looks for comments of the form //[#@]\s<name>=\s*<value>\s*.*

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reference, here's a helper in the v8 inspector . I believe it might be susceptible to the same bug.

Should we just leave this as a known issue with source maps?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What I mean is, UnboundScript::GetSourceMappingURL uses information from the actual parser, it knows the difference between an actual comment and a tricky string.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking into this further, the helper in the V8 inspector is only used if parsing the script failed.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@devsnek I think this would be a pretty significant refactor, and we'd need a similar fallback for when parsing fails.

I like the idea that in some cases we could just use v8's source map extraction, mind you.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah not blocking or anything, but I think it would be much nicer.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm on the fence with this PR, just because I fear the complex regex slowing down module loading ... perhaps before we land a fix like this I could dig in to your suggestion.

@bcoe bcoe closed this Sep 9, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants