fix: cap format string precision to prevent memory exhaustion#1292
Merged
TristonianJones merged 4 commits intogoogle:masterfrom Apr 6, 2026
Merged
fix: cap format string precision to prevent memory exhaustion#1292TristonianJones merged 4 commits intogoogle:masterfrom
TristonianJones merged 4 commits intogoogle:masterfrom
Conversation
parsePrecision() and parsePrecisionV2() accept unbounded precision values. An expression like "%.9999999f".format([3.14]) allocates 792MB at cost 501. Add maxPrecision=1000 cap.
Collaborator
|
/gcbrun |
TristonianJones
approved these changes
Mar 23, 2026
TristonianJones
requested changes
Mar 23, 2026
Collaborator
TristonianJones
left a comment
There was a problem hiding this comment.
Would you mind adding test cases which trigger the failure condition?
Contributor
Author
|
I Made maxPrecision configurable with a new StringsMaxPrecision() option. As requested, default is 100 when version >= 5, no limit for earlier versions to keep backward compatibility. As requested, I also added test cases. |
Collaborator
|
/gcbrun |
Contributor
Author
|
Hello @TristonianJones, I moved the actual set of maxPrecision closer to its usage instead of letting it at the beginning of CompileOptions. And I added a comment. |
Collaborator
|
/gcbrun |
TristonianJones
approved these changes
Apr 6, 2026
Maks1mS
pushed a commit
to stplr-dev/stplr
that referenced
this pull request
Apr 9, 2026
This PR contains the following updates: | Package | Type | Update | Change | OpenSSF | |---|---|---|---|---| | [github.com/google/cel-go](https://github.com/google/cel-go) | require | minor | `v0.27.0` → `v0.28.0` | [](https://securityscorecards.dev/viewer/?uri=github.com/google/cel-go) | --- >⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/23) for more information. --- ### Release Notes <details> <summary>google/cel-go (github.com/google/cel-go)</summary> ### [`v0.28.0`](https://github.com/google/cel-go/releases/tag/v0.28.0) [Compare Source](google/cel-go@v0.27.0...v0.28.0) #### High-Level Changes - **Enhanced JSON Interoperability:** New support for JSON names across the checker, AST, and runtime allows for more seamless data handling when working with JSON-native structures. - **Improved Developer Tooling:** Integration is now smoother thanks to new utilities for converting Go errors into `cel.Issues` and more descriptive, context-aware error messages. - **Greater Environment Flexibility:** You can now redeclare variables as constants and export parse limit options, providing finer control over how CEL environments are configured and constrained. - **Native Struct Improvements:** Support for mixing CEL and native values within native structs simplifies the handling of complex, hybrid data types. *** #### 🚀 Features - Add helper method to check whether a function has a singleton binding in [#​1266](google/cel-go#1266) - Helper utility for converting a Go error into `cel.Issues` in [#​1267](google/cel-go#1267) - Policy API improvements in [#​1268](google/cel-go#1268) - CEL Test usability requirements in [#​1269](google/cel-go#1269) - Better context-related error messages in [#​1271](google/cel-go#1271) - Sort `env.Config` values where reasonable in [#​1273](google/cel-go#1273) - Support redeclaring variables as constants in `NewEnv` in [#​1275](google/cel-go#1275) - Add support for exporting parse limit options in [#​1277](google/cel-go#1277) - Support mixing CEL values and native values in native structs in [#​1270](google/cel-go#1270) - Add checker, AST, and type-provider support for JSON names in [#​1283](google/cel-go#1283) - JSON field names runtime support in [#​1286](google/cel-go#1286) - Optionally include reachable fieldpaths in prompt in [#​1285](google/cel-go#1285) - REPL -- cel-spec pb2 and json name support [#​1294](google/cel-go#1294) #### 🐞 Bug Fixes - Fix support for config-based type references in [#​1265](google/cel-go#1265) - Check arg kinds in `optional.or` and `.orValue` impl in [#​1276](google/cel-go#1276) - Bazel fixes for import in [#​1278](google/cel-go#1278) - Support zero-value literals in presence test inlining [#​1280](google/cel-go#1280) - Cache concatList.Size() to prevent O(N^2) evaluation time [#​1291](google/cel-go#1291) - Preserve runtime error node IDs from Resolve [#​1290](google/cel-go#1290) - Default enable identifier escaping with backticks [#​1295](google/cel-go#1295) - Cap format string precision to prevent memory exhaustion [#​1292](google/cel-go#1292) #### 🛠️ Maintenance & Internal - **chore:** Migrate gsutil usage to gcloud storage in [#​1274](google/cel-go#1274) - Lint fixes for exported function/type comments in [#​1279](google/cel-go#1279) - Lint fixes for import in [#​1287](google/cel-go#1287) *** **Full Changelog**: [https://github.com/google/cel-go/compare/v0.27.0...v0.28.0-alpha](https://github.com/google/cel-go/compare/v0.27.0...v0.28.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At 12:00 AM through 04:59 AM and 10:00 PM through 11:59 PM, Monday through Friday (`* 0-4,22-23 * * 1-5`) - Only on Sunday and Saturday (`* * * * 0,6`) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDQuNSIsInVwZGF0ZWRJblZlciI6IjQzLjEwNC41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJLaW5kL0RlcGVuZGVuY2llcyJdfQ==--> Reviewed-on: https://altlinux.space/stapler/stplr/pulls/402 Co-authored-by: Renovate Bot <stapler-helper-bot@noreply.altlinux.space> Co-committed-by: Renovate Bot <stapler-helper-bot@noreply.altlinux.space>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
parsePrecision()inext/formatting.goandparsePrecisionV2()inext/formatting_v2.goaccept unbounded precision values from format strings. An expression like"%.9999999f".format([3.14])causesfmt.Sprintfto allocate a string proportional to the precision value. At cost 501, a single expression can allocate 792MB.The fix adds a
maxPrecisionconstant (1000) and rejects precision values exceeding it. This is consistent with the practical limits of floating-point display (IEEE 754 double has ~15-17 significant digits).Files changed:
ext/formatting.go,ext/formatting_v2.go