From fe0cfdf99c188361eef9cbc33ce2adfde7aa2266 Mon Sep 17 00:00:00 2001 From: kshitijk4poor <82637225+kshitijk4poor@users.noreply.github.com> Date: Mon, 31 Aug 2026 23:22:30 +0530 Subject: [PATCH] fix(redact): keep dotted config-key scans linear past the keyword pre-gate MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The _CFG_SECRET_WORD_RE pre-gate only skips secret-FREE text. A compaction payload containing one real secret assignment plus a long opaque dotted run still reaches _CFG_DOTTED_RE's backtrackable '*' prefix, which re.sub retries from every byte of the run — quadratic while holding the GIL (same class as the _ENV_ASSIGN_LOWER_RE fix in this branch, #99255). Anchor each attempt to the start of a key run with a negative lookbehind. Match set is unchanged: any match starting mid-run implies a leftmost match at the run start, verified 20/20 identical over a dotted-config corpus. 30k-char adversarial run: 102s -> 0.015s. --- agent/redact.py | 7 +++++++ tests/agent/test_redact.py | 17 +++++++++++++++++ 2 files changed, 24 insertions(+) diff --git a/agent/redact.py b/agent/redact.py index eb41ef0551..50e263cee3 100644 --- a/agent/redact.py +++ b/agent/redact.py @@ -204,7 +204,14 @@ _ENV_LOOKUP_VALUE_RE = re.compile( # ``(?:[A-Za-z0-9_\-]+\.)+`` (exponential backtracking on long dotted runs). # The ``*`` runs bordering {_SECRET_CFG_NAMES} must stay backtrackable # (secret words are matchable by the class, e.g. ``app.api.key=…``). +# The lookbehind anchors each attempt to the start of a key run: without it, +# ``re.sub`` retries the backtrackable ``*`` prefix at every byte of a long +# non-matching dotted run, making the sub quadratic whenever the text contains +# a secret keyword anywhere (the ``_CFG_SECRET_WORD_RE`` pre-gate only skips +# secret-free text). Match set is unchanged — any match starting mid-run +# implies a leftmost match starting at the run start (#99255). _CFG_DOTTED_RE = re.compile( + rf"(?