Skip to content

test: enforce regex error propagation in validation - #120

Merged
Artifizer merged 1 commit into
GlobalTypeSystem:mainfrom
aviator5:more-regexp-redos-tests
Oct 1, 2026
Merged

Artifizer merged 1 commit into
GlobalTypeSystem:mainfrom
aviator5:more-regexp-redos-tests

Conversation

@aviator5

@aviator5 aviator5 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Clarify that unsupported regular expressions and exhausted resource limits must fail validation as a whole wherever pattern or patternProperties is evaluated, preventing execution errors from silently accepting invalid data.

  • Cover matching property names whose values violate patternProperties, including a successful fallback alternative after expensive backtracking.
  • Check that not cannot invert regex execution failures into successful validation for either pattern or patternProperties.
  • Exercise property classification through additionalProperties in draft-07 and unevaluatedProperties in draft 2020-12, placing the keyword before patternProperties to expose unbounded classification matches.
  • Include short valid controls and adversarial inputs, require explicit rejection, and enforce a two-second response bound for stress cases.

Summary by CodeRabbit

  • Bug Fixes

    • Regular-expression errors and resource-limit exhaustion now cause validation to fail, rather than being treated as a non-match or overridden by schema rules.
    • Property classification based on regular expressions now follows the same behavior across supported schema versions.
  • Documentation

    • Clarified how regular-expression validation errors affect schema validation.

Clarify that unsupported regular expressions and exhausted resource limits
must fail validation as a whole wherever pattern or patternProperties is
evaluated, preventing execution errors from silently accepting invalid data.

- Cover matching property names whose values violate patternProperties,
  including a successful fallback alternative after expensive backtracking.
- Check that not cannot invert regex execution failures into successful
  validation for either pattern or patternProperties.
- Exercise property classification through additionalProperties in draft-07
  and unevaluatedProperties in draft 2020-12, placing the keyword before
  patternProperties to expose unbounded classification matches.
- Include short valid controls and adversarial inputs, require explicit
  rejection, and enforce a two-second response bound for stress cases.

Signed-off-by: Aviator 5 <ai.agent.tor@gmail.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: d454d697-ca94-47c1-ba49-fc07f3307963

📥 Commits

Reviewing files that changed from the base of the PR and between 6f91ebd and db29169.

📒 Files selected for processing (2)
  • README.md
  • tests/test_op6_schema_validation.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The README clarifies how regex execution errors affect schema validation. Regression tests exercise resource exhaustion in pattern matching, negation, and property classification across Draft-07 and Draft 2020-12.

Changes

Regex validation

Layer / File(s) Summary
Regex error semantics and regression coverage
README.md, tests/test_op6_schema_validation.py
The README states that regex errors fail validation as a whole and cannot be overridden by enclosing applicators. Parameterized tests cover patternProperties, not, additionalProperties, and unevaluatedProperties, with a two-second limit for stress validations.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: artifizer

Merge Risk: ⚪ Minimal · up to db291

The specification clarification and regression tests introduce no established merge-blocking risk. Merge after normal checks confirm the new tests pass.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to db291

The change strengthens fail-closed validation requirements and adds regression tests. No material security risk introduced or worsened by this PR was identified, and the added functions are test entrypoints rather than new production interfaces.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The added executable reachability is confined to conformance-test requests against the configured validation service. The supplied public-entrypoint classifications do not establish new attacker-accessible production interfaces or greater production privileges.

Trust Boundaries and Controls

  • observed — The clarified control prevents regex execution errors from silently skipping value validation or being inverted by not into successful validation. Regression cases exercise matching property names with invalid values and matching instances inside not; these are expected-control tests, not verified production vulnerabilities.

Resilience and Maintainability Implications

  • observed — Stress requests use a two-second client timeout and elapsed-time assertion. Property-classification tests cover additionalProperties in draft-07 and unevaluatedProperties in draft 2020-12, placing classification before patternProperties. These assertions do not independently prove server-side cancellation or release of regex execution resources.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 42.86% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 1 files. (1 skipped: 1… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: tests that enforce regex error propagation during validation.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 42.86% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 1 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Artifizer
Artifizer merged commit 510c3e2 into GlobalTypeSystem:main Oct 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants