Skip to content

Fix panic in BoundedBacktracker when max_haystack_len returns 0 - #1388

Open
VrtxOmega wants to merge 1 commit into
rust-lang:masterfrom
VrtxOmega:fix/meta-backtracker-zero-haystack
Open

VrtxOmega wants to merge 1 commit into
rust-lang:masterfrom
VrtxOmega:fix/meta-backtracker-zero-haystack

Conversation

@VrtxOmega

Copy link
Copy Markdown

Fixes #1344

Problem

When a regex like ^.{0,404600}$ causes the bounded backtracker's max_haystack_len() to return 0, the meta layer's guard in wrappers.rs used '>' instead of '>=', allowing the engine to be selected for an empty string (length 0). The engine then panicked with MatchError(HaystackTooLong { len: 0 }) from an unwrap() at wrappers.rs:234.

Root Cause

In src/meta/wrappers.rs, BoundedBacktrackerEngine::get() guards against haystacks that are too long for the backtracker:

When max_haystack_len() returns 0, this guard evaluates to (false), so the engine IS selected. But the engine itself cannot handle any haystack (even length 0) and returns an error.

Fix

Changed the guard from '>' to '>=' so that when max_haystack_len() is 0, no haystack is selected for the backtracker engine:

Verification

  • Reproduced the panic: built regex-automata 0.4.18, ran MCVE from issue, confirmed panic at wrappers.rs:234 with MatchError(HaystackTooLong { len: 0 })
  • After fix: MCVE returns Ok(true) correctly (empty string matches ^.{0,404600}$)
  • Added regression test max_haystack_len_zero_excludes_engine
  • All existing tests pass: 2 passed, 0 failed

Issue rust-lang#1344: When a regex like /^.{0,404600}$/ causes the bounded
backtracker's max_haystack_len() to return 0, the meta layer's guard
in wrappers.rs used '>' instead of '>=', allowing the engine to be
selected for an empty string (length 0). The engine then panicked with
MatchError(HaystackTooLong { len: 0 }) from an unwrap().

The fix changes the guard from '>' to '>=' so that when
max_haystack_len() is 0, no haystack (including the empty string)
is excluded from the backtracker engine.

Added regression test max_haystack_len_zero_excludes_engine.
@VrtxOmega
VrtxOmega force-pushed the fix/meta-backtracker-zero-haystack branch from 5de4b19 to e926ddc Compare August 21, 2026 15:09

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

BoundedBacktracker::is_match panics on empty haystack when max_haystack_len() saturates to 0

1 participant