Note the lookback limit on unfinished string sequences

A payload longer than escapeLookback stops being seen as unfinished, so a
reply that is also split across reads still leaks. Recognizing it means
tracking the open sequence across reads rather than rescanning the tail,
which is more than this change should carry.

Reported by Copilot on #4926.
This commit is contained in:
Junegunn Choi
2026-09-27 21:30:18 +09:00
parent 78d45f26fb
commit 33682e1cc8
+6
View File
@@ -413,6 +413,12 @@ func stringIntroducer(b byte) bool {
func incompleteEscape(buffer []byte) bool {
// Only the tail can hold a sequence still arriving. This runs once per byte
// read, so scanning all of a large paste would make the read quadratic.
//
// The limit is that a string sequence with a payload longer than this stops
// being seen as unfinished, so one that is also split across reads reaches
// the parser incomplete and its payload is typed into the query. Recognizing
// it would mean tracking the open sequence across reads instead of
// rescanning the tail.
tail := buffer
if len(tail) > escapeLookback {
tail = tail[len(tail)-escapeLookback:]