gh-156353: Fix configparser space delimiter parsing - #156382
Conversation
This commit fixes a bug introduced in pythongh-146333 where using a space as a delimiter would cause the option name parsing to incorrectly absorb the space. The regular expressions _OPT_TMPL and _OPT_NV_TMPL have been adjusted to ensure that whitespace matches do not consume valid delimiters. Signed-off-by: sundeep8967 <sundeep8967@gmail.com>
|
Most changes to Python require a NEWS entry. Add one using the blurb_it web app or the blurb command-line tool. If this change has little impact on Python users, wait for a maintainer to apply the |
Signed-off-by: sundeep8967 <sundeep8967@gmail.com>
…om options Signed-off-by: sundeep8967 <sundeep8967@gmail.com>
encukou
left a comment
There was a problem hiding this comment.
Thank you for the fix!
I pushed some tests I used to convince myself that this is good, and a few wording/formatting changes.
|
Thanks @sundeep8967 for the PR, and @hugovk for merging it 🌮🎉.. I'm working now to backport this PR to: 3.10, 3.11, 3.12, 3.13, 3.14, 3.15. |
|
GH-156557 is a backport of this pull request to the 3.15 branch. |
|
GH-156558 is a backport of this pull request to the 3.14 branch. |
|
GH-156559 is a backport of this pull request to the 3.13 branch. |
|
GH-156560 is a backport of this pull request to the 3.12 branch. |
|
GH-156561 is a backport of this pull request to the 3.11 branch. |
|
GH-156562 is a backport of this pull request to the 3.10 branch. |
Problem
Between Python 3.14.4 and 3.14.5 (and similarly in 3.13),
configparserstopped recognizing a space as a delimiter whendelimiters=(' ', '=')was used. This regression was caused by gh-146333 which addressed a ReDoS vulnerability in the option parsing regex but inadvertently allowed the greedy\s+inside the option name group to consume whitespace characters even if they were valid delimiters.Solution
This PR adjusts
_OPT_TMPLand_OPT_NV_TMPLto explicitly ensure that any whitespace character consumed as part of the option name is NOT a valid delimiter ((?:(?!{delim})\s)+).This retains the catastrophic backtracking protection introduced in gh-146333 (the mutually exclusive possessive-like parsing structure remains intact) while restoring the ability to use spaces as delimiters.