@@ -262,19 +262,22 @@ t.test('deep chaining does not overflow the stack', async t => {
262262// remainder of the string once per brace group, so chaining groups inside a
263263// brace set exhausted the stack at ~7,000 groups (~29KB of input) even though
264264// the identical chain outside one was already safe.
265- t . test ( 'deeply chained comma groups do not overflow the stack' , async t => {
266- const str = '{' + '{a},' . repeat ( 50_000 ) + 'b}'
267- t . doesNotThrow ( ( ) => {
268- const expanded = expand ( str )
269- t . ok ( expanded . length > 0 , 'still returns a result' )
270- } )
271- // The overflow happened while parsing, before anything was expanded, so
272- // neither bound could prevent it - and neither is what keeps it safe now.
273- t . doesNotThrow (
274- ( ) => expand ( str , { max : 1 , maxLength : 1 } ) ,
275- 'still safe with both bounds set as low as they go' ,
276- )
277- } )
265+ t . test (
266+ 'deeply chained comma groups do not overflow the stack' ,
267+ async t => {
268+ const str = '{' + '{a},' . repeat ( 50_000 ) + 'b}'
269+ t . doesNotThrow ( ( ) => {
270+ const expanded = expand ( str )
271+ t . ok ( expanded . length > 0 , 'still returns a result' )
272+ } )
273+ // The overflow happened while parsing, before anything was expanded, so
274+ // neither bound could prevent it - and neither is what keeps it safe now.
275+ t . doesNotThrow (
276+ ( ) => expand ( str , { max : 1 , maxLength : 1 } ) ,
277+ 'still safe with both bounds set as low as they go' ,
278+ )
279+ } ,
280+ )
278281
279282// `push.apply(target, items)` passes one argument per element, so a single
280283// large array overflowed the stack with no recursion at all - this input
0 commit comments