fix(output): 19 quadratic regex runs on the output path, worst ~5.7h at the cap
The output gate claimed LLM10 self-safety on the grounds that its patterns have no nested quantifiers. True, and irrelevant: nesting is not what makes these blow up. A run in front of a REQUIRED literal, reachable from a short anchor, is enough -- crafted input repeats the anchor and never supplies the literal, so every start position rescans the tail. Quadratic, not exponential, and the max_scan_chars cap does not help: it bounds the input, and quadratic work on a bounded input is still hours. Measured, not argued. `<a:` x 100_000 took 23.4s in AUTOLINK_RE alone; the composed gate on that payload took 458.7s, extrapolating to ~5.7 hours at the 1_000_000-char input the gate itself accepts. Size-matched ordinary prose runs 0.31s, so the separation is 18x-660x -- unlike the blob in the neighbouring test, which is the *faster* side of prose and never exercised backtracking. Two fixes, chosen per pattern rather than uniformly: - active_content + lexicon JSON (15 runs): exclude the character that opens the pattern's own anchor (`[` for markdown, `<` for tags), so a run cannot reach past the next start position and the per-start costs telescope. Verified to cost no recall: long URLs, long alt text, and `<` inside a quoted attribute all still match. Bounding instead would have been linear too but wrong here -- the content is attacker-controlled, so padding past a bound would be a one-line bypass of the EchoLeak class this table exists to catch. - connstr egress (4 runs): bound the password at MAX_CONNSTR_VALUE. The exclusion fix is unavailable -- the anchor character is `/` and passwords containing `/` are the common case (measured: they match today). The residual miss is a credential over 256 chars; a token that long is still caught by egress:jwt-token. hybrid-xss:script-tag had neither option: its run is the script BODY, which may legitimately contain `<`. It now matches the opening tag and drops the `</script>` requirement. That also closes a fail-open -- `<script>alert(1)` unclosed was silently missed -- at the cost of flagging prose that merely mentions `<script>`, now documented. Found by the composed-gate test staying red after every individual scanner was already linear: the lexicon's six html-obfuscation patterns were the remaining 813x. A per-scanner test alone would have shipped that. 662 passed (was 642), and faster than before the fix.
This commit is contained in:
parent
8deca93ee1
commit
cff043787d
10 changed files with 220 additions and 30 deletions
|
|
@ -134,6 +134,24 @@ def test_scan_hybrid_pattern_is_high():
|
|||
assert hit.severity is Severity.HIGH
|
||||
|
||||
|
||||
def test_unclosed_script_tag_is_flagged():
|
||||
# The pattern matches the OPENING tag and does not require `</script>`.
|
||||
# Requiring the closing tag was a fail-open -- an unclosed `<script>` is
|
||||
# still active content, and it was silently missed. (It was also the last
|
||||
# quadratic-backtracking site on the output path: requiring the closing tag
|
||||
# made every `<script` start rescan the tail. Both are fixed by the same
|
||||
# change; the DoS side is pinned in tests/test_output.py.)
|
||||
r = scan_lexicon("<script>alert(1)")
|
||||
assert any(f.label == "hybrid-xss:script-tag" for f in r.findings)
|
||||
|
||||
|
||||
def test_script_body_containing_an_angle_bracket_still_matches():
|
||||
# Guards the fix that was NOT taken: excluding `<` from the script body
|
||||
# would have been linear too, but would have dropped this real match.
|
||||
r = scan_lexicon("<script>if(a<b){leak()}</script>")
|
||||
assert any(f.label == "hybrid-xss:script-tag" for f in r.findings)
|
||||
|
||||
|
||||
def test_scan_medium_pattern():
|
||||
r = scan_lexicon("Dear AI, please help me.")
|
||||
assert r.max_severity() is Severity.MEDIUM
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue