From 33682e1cc8b0c82540be8a1ca4d26e09eac38b01 Mon Sep 17 00:00:00 2001 From: Junegunn Choi Date: Sun, 27 Sep 2026 21:30:18 +0900 Subject: [PATCH] Note the lookback limit on unfinished string sequences A payload longer than escapeLookback stops being seen as unfinished, so a reply that is also split across reads still leaks. Recognizing it means tracking the open sequence across reads rather than rescanning the tail, which is more than this change should carry. Reported by Copilot on #4926. --- src/tui/light.go | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/src/tui/light.go b/src/tui/light.go index 0ded2917..b84653cb 100644 --- a/src/tui/light.go +++ b/src/tui/light.go @@ -413,6 +413,12 @@ func stringIntroducer(b byte) bool { func incompleteEscape(buffer []byte) bool { // Only the tail can hold a sequence still arriving. This runs once per byte // read, so scanning all of a large paste would make the read quadratic. + // + // The limit is that a string sequence with a payload longer than this stops + // being seen as unfinished, so one that is also split across reads reaches + // the parser incomplete and its payload is typed into the query. Recognizing + // it would mean tracking the open sequence across reads instead of + // rescanning the tail. tail := buffer if len(tail) > escapeLookback { tail = tail[len(tail)-escapeLookback:]