Skip to content

[ENG-4059] Screen the scaffolded rule sets in the regex cost gate - #307

Merged
patchstackdave merged 1 commit into
mainfrom
fix/demo-rule-cost
Sep 29, 2026
Merged

patchstackdave merged 1 commit into
mainfrom
fix/demo-rule-cost

Conversation

@patchstackdave

Copy link
Copy Markdown
Contributor

The regex cost gate measures how long each pattern takes to reject its worst input at the size it may really be run against. Until now it covered only the compiled-in default rules. It now covers every regex the package ships, including the rule sets the installer scaffolds into an app:

  • rules.json, the offline starter set;
  • demo-rules.json, the set protect --demo writes.

Every clause has a declared worst case.

Two demo patterns did not stay within the budget, so they are rewritten to stay linear:

  • Response email redaction. The local part and labels are bounded to their RFC lengths, and a match must start at the beginning of a local part. It now takes about 1 ms at 512 KB.
  • XXE detection. The text between <!DOCTYPE and SYSTEM is bounded to 256 characters, and the pattern now scales linearly with input size.

Every demo still blocks or redacts its exploit and lets its benign twin through: the demo rule tests and scripts/run-demos.mjs both pass. The example bundle and the scaffolded template stay identical.

Tool change. screenPatternCost accepts derive: false. The heuristic that derives a candidate reads a pattern as one sequence, so for a top-level alternation or a repeated group it can build an input the pattern matches. That would invalidate the screening. The gate lists those clauses explicitly, and a test checks that each listed clause's derived candidate really does match, so the list can't switch off a useful measurement.

Validation:

  • full suite: 3,445 passed, 7 skipped;
  • typecheck and build;
  • scripts/run-demos.mjs.

🤖 Generated with Claude Code

The regex cost gate now screens every regex the package ships: the
compiled defaults plus the rule sets the installer scaffolds
(`rules.json`, and `demo-rules.json` for `protect --demo`). Each
clause has a declared worst case.

Two demo patterns did not stay within the budget and are rewritten
to stay linear with the same demo behaviour:
- the response email pattern now has bounded parts and must start at
  the beginning of a local part;
- the XXE pattern bounds the text between `<!DOCTYPE` and `SYSTEM`.

`screenPatternCost` takes `derive: false` for a pattern whose derived
candidate matches it; the test checks that each such clause's derived
candidate really does match.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderbuds

coderbuds Bot commented Sep 28, 2026

Copy link
Copy Markdown

Adds derive flag support and screens scaffolded rule sets with thorough tests.

🎯 Quality: 100% Elite · 📦 Size: Medium

📈 This month: Your 158th PR — above team average · Averaging Elite

See how your team is trending →

@patchstackdave
patchstackdave merged commit 79401a1 into main Sep 29, 2026
18 checks passed
@patchstackdave
patchstackdave deleted the fix/demo-rule-cost branch September 29, 2026 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants