Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Bounds active formatting element reconstruction work during HTML parsing to prevent pathological mis-nested formatting markup from causing super-linear DOM growth and exhausting the Node.js heap.
This affects DOMino's HTML parsing path used by Angular server-side rendering.
Problem
When formatting elements are repeatedly left in the active formatting elements list,
afereconstruct()can reconstruct an increasingly large number of stale entries.A comparatively small input can therefore cause quadratic DOM allocation.
On current
main, using Node.js 22.22.3 with a 128 MiB heap limit, an 8,290-byte non-numeric test case causes the unpatched parser to terminate with a fatal V8 out-of-memory error (SIGABRT).This remains reproducible after the existing numeric attribute storage hardening (
c5aa1eb). The reproducer uses non-numeric attribute names, so the active-formatting reconstruction issue does not depend on sparse numeric attribute storage.Fix
Track:
Reconstruction work is bounded to:
If this limit is exceeded, parsing stops with a controlled error instead of continuing until the process exhausts its heap.
The accounting also handles incremental parsing: buffered input is counted when originally supplied, while
process()andresume()re-enter the parser with an empty string and do not count the same input again.Compatibility
The existing DOMino test corpus was also tested with substantially stricter experimental budgets.
All existing tests still passed with:
The submitted
max(4096, inputLength * 2)limit therefore provides additional compatibility headroom.Incremental parsing was additionally checked using chunk sizes of:
The pathological input was bounded in every case, while normally nested formatting continued to parse successfully.
Tests
Added regression coverage for:
The pathological regression fails before the fix with a missing expected exception and passes after applying the fix.
Full test suite on current
mainwith the patch:fixes : angular/angular#70926