Compare commits

...

2 Commits

Author SHA1 Message Date
Julien Neuhart
ff817f6cf8 chore(deps)!: migrate from regexp2 v1 to regexp2 v2 2026-09-17 15:33:55 +02:00
Julien Neuhart
ab18384a51 build(dockerfile): update AWS Lambda Web Adapter to 1.0.1 2026-09-17 15:33:55 +02:00
23 changed files with 45 additions and 45 deletions

View File

@@ -498,7 +498,7 @@ FROM gotenberg AS gotenberg-aws-lambda
USER root
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:0.9.1 /lambda-adapter /opt/extensions/lambda-adapter
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:1.0.1 /lambda-adapter /opt/extensions/lambda-adapter
ENV AWS_LWA_PORT=3000
ENV AWS_LWA_READINESS_CHECK_PATH=/health
@@ -516,7 +516,7 @@ FROM gotenberg-chromium AS gotenberg-aws-lambda-chromium
USER root
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:0.9.1 /lambda-adapter /opt/extensions/lambda-adapter
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:1.0.1 /lambda-adapter /opt/extensions/lambda-adapter
ENV AWS_LWA_PORT=3000
ENV AWS_LWA_READINESS_CHECK_PATH=/health
@@ -534,7 +534,7 @@ FROM gotenberg-libreoffice AS gotenberg-aws-lambda-libreoffice
USER root
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:0.9.1 /lambda-adapter /opt/extensions/lambda-adapter
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:1.0.1 /lambda-adapter /opt/extensions/lambda-adapter
ENV AWS_LWA_PORT=3000
ENV AWS_LWA_READINESS_CHECK_PATH=/health

2
go.mod
View File

@@ -8,7 +8,7 @@ require (
github.com/chromedp/chromedp v0.14.2 // pinned: v0.15.x breaks the headless print-mode paint pipeline (rAF / ResizeObserver / IntersectionObserver stop firing, blank charts). See https://github.com/gotenberg/gotenberg/issues/1535.
github.com/coreos/go-oidc/v3 v3.21.0
github.com/cucumber/godog v0.16.0
github.com/dlclark/regexp2 v1.12.0
github.com/dlclark/regexp2/v2 v2.8.0
github.com/gomarkdown/markdown v0.0.0-20260824154242-13c5cf49db8d
github.com/google/uuid v1.6.0
github.com/hashicorp/go-retryablehttp v0.7.8

4
go.sum
View File

@@ -58,8 +58,8 @@ github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSs
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/distribution/reference v0.6.0 h1:0IXCQ5g4/QMHHkarYzh5l+u8T3t73zM5QvfrDyIgxBk=
github.com/distribution/reference v0.6.0/go.mod h1:BbU0aIcezP1/5jX/8MP0YiH4SdvB5Y4f/wlDRiLyi3E=
github.com/dlclark/regexp2 v1.12.0 h1:0j4c5qQmnC6XOWNjP3PIXURXN2gWx76rd3KvgdPkCz8=
github.com/dlclark/regexp2 v1.12.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
github.com/dlclark/regexp2/v2 v2.8.0 h1:CekDhPLGfm+GAJmPVFIG+5dqMIQPkyHJll7BbdneDfw=
github.com/dlclark/regexp2/v2 v2.8.0/go.mod h1:avUrQvPaLz2DrFNHJF0taWAFFX2C1GMSSoeiqFjcBmU=
github.com/docker/go-connections v0.8.1 h1:JibmG5hULs5qXSr/cp/w3Pw5fZuStt4MOHMUExb29/M=
github.com/docker/go-connections v0.8.1/go.mod h1:no1qkHdjq7kLMGUXYAduOhYPSJxxvgWBh7ogVvptn3Q=
github.com/docker/go-units v0.5.0 h1:69rxXcBk27SvSaaxTtLh/8llcHD8vYHT7WSdRZ/jvr4=

View File

@@ -3,7 +3,7 @@ package gotenberg
import (
"testing"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
)
func TestAuditAllowList(t *testing.T) {
@@ -93,7 +93,7 @@ func TestAuditAllowList_FlaggedPatternsAreActuallyExploitable(t *testing.T) {
t.Fatalf("pattern %q was not flagged", tc.pattern)
}
ok, err := regexp2.MustCompile(tc.pattern, 0).MatchString(tc.attack)
ok, err := regexp2.MustCompile(tc.pattern, regexp2.None).MatchString(tc.attack)
if err != nil {
t.Fatalf("match %q: %v", tc.attack, err)
}
@@ -129,7 +129,7 @@ func TestAuditAllowList_SafePatternsRejectTheAttacks(t *testing.T) {
t.Fatalf("safe pattern %q was flagged as %q", pattern, findings[0].Risk)
}
re := regexp2.MustCompile(pattern, 0)
re := regexp2.MustCompile(pattern, regexp2.None)
for _, attack := range attacks {
ok, err := re.MatchString(attack)
if err != nil {

View File

@@ -7,7 +7,7 @@ import (
"strings"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"github.com/labstack/gommon/bytes"
flag "github.com/spf13/pflag"
@@ -239,7 +239,7 @@ func (f *ParsedFlags) MustRegexp(name string) *regexp2.Regexp {
panic(err)
}
re := regexp2.MustCompile(val, 0)
re := regexp2.MustCompile(val, regexp2.None)
re.MatchTimeout = PatternMatchTimeout
return re
@@ -276,7 +276,7 @@ func (f *ParsedFlags) MustRegexpSlice(name string) []*regexp2.Regexp {
continue
}
re := regexp2.MustCompile(val, 0)
re := regexp2.MustCompile(val, regexp2.None)
re.MatchTimeout = PatternMatchTimeout
regexps = append(regexps, re)

View File

@@ -7,7 +7,7 @@ import (
"testing"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
flag "github.com/spf13/pflag"
)

View File

@@ -15,7 +15,7 @@ import (
"strings"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"github.com/hashicorp/go-retryablehttp"
"golang.org/x/net/http/httpproxy"
)

View File

@@ -9,7 +9,7 @@ import (
"testing"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
)
func TestIsPublicIP(t *testing.T) {
@@ -164,10 +164,10 @@ func mustAddrs(t *testing.T, ss ...string) []netip.Addr {
func TestFilterOutboundURL(t *testing.T) {
defaultDeny := []*regexp2.Regexp{
regexp2.MustCompile(`^https?://(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|169\.254\.|0\.0\.0\.0|127\.|localhost|\[::1\]|\[fd)`, 0),
regexp2.MustCompile(`^https?://(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|169\.254\.|0\.0\.0\.0|127\.|localhost|\[::1\]|\[fd)`, regexp2.None),
}
chromiumDeny := []*regexp2.Regexp{
regexp2.MustCompile(`^file:(?!//\/tmp/).*`, 0),
regexp2.MustCompile(`^file:(?!//\/tmp/).*`, regexp2.None),
}
for _, tc := range []struct {
@@ -246,7 +246,7 @@ func TestFilterOutboundURL(t *testing.T) {
{
scenario: "allow-list match bypasses IP check",
rawURL: "http://internal.service/api",
allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal\.service`, 0)},
allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal\.service`, regexp2.None)},
deny: defaultDeny,
opts: []DecideOption{WithDenyPrivateIPs(true)},
expectErr: false,
@@ -254,15 +254,15 @@ func TestFilterOutboundURL(t *testing.T) {
{
scenario: "deny-list still wins over allow-list match",
rawURL: "http://internal.service/api",
allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal`, 0)},
deny: []*regexp2.Regexp{regexp2.MustCompile(`/api$`, 0)},
allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal`, regexp2.None)},
deny: []*regexp2.Regexp{regexp2.MustCompile(`/api$`, regexp2.None)},
expectErr: true,
expectIs: ErrFiltered,
},
{
scenario: "allow-list non-empty and no match rejects",
rawURL: "https://other.example/",
allow: []*regexp2.Regexp{regexp2.MustCompile(`^https://allowed\.example`, 0)},
allow: []*regexp2.Regexp{regexp2.MustCompile(`^https://allowed\.example`, regexp2.None)},
expectErr: true,
expectIs: ErrFiltered,
},
@@ -539,7 +539,7 @@ func TestDecideOutbound_DenyLists_WinOverDenyPrivateIPs(t *testing.T) {
// The regex deny-list fires before any resolution; verifies that
// operator-supplied deny patterns remain effective regardless of
// IP-class options.
deny := []*regexp2.Regexp{regexp2.MustCompile(`^http://evil\.`, 0)}
deny := []*regexp2.Regexp{regexp2.MustCompile(`^http://evil\.`, regexp2.None)}
_, err := DecideOutbound(
context.Background(),
@@ -605,7 +605,7 @@ func TestDecideOutbound_UserinfoDoesNotEvadeDenyList(t *testing.T) {
context.Background(),
rawURL,
nil,
[]*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, 0)},
[]*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, regexp2.None)},
time.Now().Add(5*time.Second),
)
if !errors.Is(err, ErrFiltered) {
@@ -617,7 +617,7 @@ func TestDecideOutbound_UserinfoDoesNotEvadeDenyList(t *testing.T) {
func TestDecideOutbound_UserinfoDoesNotSatisfyAllowList(t *testing.T) {
// A host-terminated allow-list, the shape the documentation recommends.
allowList := []*regexp2.Regexp{regexp2.MustCompile(`^https://trusted\.example\.com(:[0-9]+)?(/|$)`, 0)}
allowList := []*regexp2.Regexp{regexp2.MustCompile(`^https://trusted\.example\.com(:[0-9]+)?(/|$)`, regexp2.None)}
for _, rawURL := range []string{
"https://trusted.example.com@169.254.169.254/latest/meta-data/",
@@ -656,7 +656,7 @@ func TestDecideOutbound_UserinfoKeptOutOfErrorMessages(t *testing.T) {
context.Background(),
"http://alice:hunter2@127.0.0.1:9999/",
nil,
[]*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, 0)},
[]*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, regexp2.None)},
time.Now().Add(5*time.Second),
)
if err == nil {
@@ -680,7 +680,7 @@ func TestDecideOutbound_LegitimateCredentialsStillReachTheHost(t *testing.T) {
decision, err := DecideOutbound(
context.Background(),
"https://alice:hunter2@example.com/report.pdf",
[]*regexp2.Regexp{regexp2.MustCompile(`^https://example\.com(:[0-9]+)?(/|$)`, 0)},
[]*regexp2.Regexp{regexp2.MustCompile(`^https://example\.com(:[0-9]+)?(/|$)`, regexp2.None)},
nil,
time.Now().Add(5*time.Second),
WithDenyPrivateIPs(true),
@@ -774,7 +774,7 @@ func TestDecideOutboundBoundsCatastrophicPatterns(t *testing.T) {
// caller's whole budget, so a 30s API_TIMEOUT bought a 30s CPU burn.
// The trailing "!" makes the match fail only after the nested quantifier
// has explored every way to split the run of "a"s.
pattern := regexp2.MustCompile(`^https://example\.com/(a+)+$`, 0)
pattern := regexp2.MustCompile(`^https://example\.com/(a+)+$`, regexp2.None)
pattern.MatchTimeout = PatternMatchTimeout
rawURL := "https://example.com/" + strings.Repeat("a", 40) + "!"

View File

@@ -1,7 +1,7 @@
package gotenberg
import (
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
)
// patternMatchAttempts caps how many times [MatchPattern] runs one pattern

View File

@@ -5,14 +5,14 @@ import (
"testing"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
)
// mustPattern compiles a pattern the way the production lists are built.
func mustPattern(t *testing.T, expr string) *regexp2.Regexp {
t.Helper()
re := regexp2.MustCompile(expr, 0)
re := regexp2.MustCompile(expr, regexp2.None)
re.MatchTimeout = PatternMatchTimeout
return re

View File

@@ -12,7 +12,7 @@ import (
"time"
"github.com/alexliesenfeld/health"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"github.com/labstack/echo/v5"
flag "github.com/spf13/pflag"
"golang.org/x/sync/errgroup"

View File

@@ -19,7 +19,7 @@ import (
"testing"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"github.com/labstack/echo/v5"
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
@@ -875,7 +875,7 @@ func TestNewContext_DownloadFromRedirectVerdictStaysGeneric(t *testing.T) {
fs := gotenberg.NewFileSystem(new(gotenberg.OsMkdirAll))
// The first hop is allowed, the redirect target is denied by the deny-list.
denyList := []*regexp2.Regexp{regexp2.MustCompile("^"+regexp.QuoteMeta(private.URL), 0)}
denyList := []*regexp2.Regexp{regexp2.MustCompile("^"+regexp.QuoteMeta(private.URL), regexp2.None)}
_, cancel, err := newContext(echoCtx, logger, fs, 10*time.Second, 0, downloadFromConfig{
denyList: denyList,

View File

@@ -17,7 +17,7 @@ import (
"github.com/chromedp/cdproto/page"
"github.com/chromedp/cdproto/runtime"
"github.com/chromedp/chromedp"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"github.com/shirou/gopsutil/v4/process"
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"

View File

@@ -14,7 +14,7 @@ import (
"github.com/alexliesenfeld/health"
"github.com/chromedp/cdproto/network"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
flag "github.com/spf13/pflag"
"go.opentelemetry.io/otel/attribute"
"go.opentelemetry.io/otel/codes"

View File

@@ -19,7 +19,7 @@ import (
"github.com/chromedp/cdproto/page"
"github.com/chromedp/cdproto/runtime"
"github.com/chromedp/chromedp"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"golang.org/x/sync/errgroup"
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"

View File

@@ -14,7 +14,7 @@ import (
"sync/atomic"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"golang.org/x/net/http/httpproxy"
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"

View File

@@ -18,7 +18,7 @@ import (
"testing"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
)

View File

@@ -14,7 +14,7 @@ import (
"testing"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
)

View File

@@ -14,7 +14,7 @@ import (
"strings"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"github.com/gomarkdown/markdown"
"github.com/labstack/echo/v5"
"github.com/microcosm-cc/bluemonday"

View File

@@ -6,7 +6,7 @@ import (
"testing"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
)

View File

@@ -14,7 +14,7 @@ import (
"sync"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
"golang.org/x/net/http/httpproxy"
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"

View File

@@ -17,14 +17,14 @@ import (
"testing"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
)
func compileRegexes(t *testing.T, patterns ...string) []*regexp2.Regexp {
t.Helper()
out := make([]*regexp2.Regexp, 0, len(patterns))
for _, p := range patterns {
r, err := regexp2.Compile(p, 0)
r, err := regexp2.Compile(p, regexp2.None)
if err != nil {
t.Fatalf("compile %q: %v", p, err)
}

View File

@@ -5,7 +5,7 @@ import (
"sync/atomic"
"time"
"github.com/dlclark/regexp2"
"github.com/dlclark/regexp2/v2"
flag "github.com/spf13/pflag"
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"