fix(worker-bundler): bound stacked import scans (#1718)#1961
Merged
Conversation
The clause sub-pattern [\w*{}\s,]+ followed by \s+ let both quantifiers
consume the same whitespace, backtracking polynomially on near-match
inputs (import + 10k spaces took ~175s). Match clauses as non-whitespace
tokens separated by whitespace instead — linear and behaviorally
equivalent. Applies to rewriteImports (transformer.ts) and the
parseImports regex fallback (resolver.ts), which had the same shape.
Fixes #1537
🦋 Changeset detectedLatest commit: 229b8b3 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
agents
@cloudflare/ai-chat
@cloudflare/codemode
create-think
hono-agents
@cloudflare/shell
@cloudflare/think
@cloudflare/voice
@cloudflare/worker-bundler
commit: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by @mattzcarey
Closes #1718
What was wrong
The original change correctly removes the overlapping whitespace quantifiers in
packages/worker-bundler/src/transformer.tsand the regex fallback inresolver.ts. During the requested final review, I found one remaining polynomial shape: because each regex is an unanchored global search, stacked near-matches such as("import value ").repeat(n) + "X"retried the whole remaining suffix at everyimport. At 15,000 repetitions, the PR-head rewrite and fallback each took about 8 seconds locally.What changed
This keeps the PR's small regex-based approach, but bounds each candidate at the next whole-word
import/exportkeyword. That prevents repeated suffix scans while preserving the valid import/export forms already covered by the PR. A regression test exercises 15,000 stacked near-matches, and the changeset now describes both protections.Testing
pnpm --filter @cloudflare/worker-bundler test: 186 passed (6 files)tsc --noEmit -p packages/worker-bundler/tsconfig.json: passedoxfmt --checkon changed files: passedoxlinton changed TypeScript files: 0 warnings/errorspnpm --filter @cloudflare/worker-bundler build: passedDemo
Demo URL (expires after 60 mins): https://issue-1718-redos-fix-demo.alpine-larch.workers.dev
Open it and click Run 500k-space case and Run 100k stacked imports; both execute
createWorker({ bundle: false })in a live Worker and report successful completion. The demo installs and runs the packed@cloudflare/worker-bundlerbuild from this branch (its unused, bundle-only esbuild WASM import is stubbed solely to fit the temporary free-preview upload limit).This final review builds on the original PR #1718 and the original report in #1537.
🤖 generated by the pr-agent — please review carefully