Skip to content

gh-156353: Fix configparser space delimiter parsing - #156382

Open
sundeep8967 wants to merge 3 commits into
python:mainfrom
sundeep8967:fix-configparser-space-delim
Open

gh-156353: Fix configparser space delimiter parsing#156382
sundeep8967 wants to merge 3 commits into
python:mainfrom
sundeep8967:fix-configparser-space-delim

Conversation

@sundeep8967

Copy link
Copy Markdown

Problem

Between Python 3.14.4 and 3.14.5 (and similarly in 3.13), configparser stopped recognizing a space as a delimiter when delimiters=(' ', '=') was used. This regression was caused by gh-146333 which addressed a ReDoS vulnerability in the option parsing regex but inadvertently allowed the greedy \s+ inside the option name group to consume whitespace characters even if they were valid delimiters.

Solution

This PR adjusts _OPT_TMPL and _OPT_NV_TMPL to explicitly ensure that any whitespace character consumed as part of the option name is NOT a valid delimiter ((?:(?!{delim})\s)+).

This retains the catastrophic backtracking protection introduced in gh-146333 (the mutually exclusive possessive-like parsing structure remains intact) while restoring the ability to use spaces as delimiters.

This commit fixes a bug introduced in pythongh-146333 where using a space as a delimiter would cause the option name parsing to incorrectly absorb the space.

The regular expressions _OPT_TMPL and _OPT_NV_TMPL have been adjusted to ensure that whitespace matches do not consume valid delimiters.

Signed-off-by: sundeep8967 <sundeep8967@gmail.com>
@sundeep8967
sundeep8967 requested a review from jaraco as a code owner August 25, 2026 20:55
@python-cla-bot

python-cla-bot Bot commented Aug 25, 2026

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

CLA signed

@bedevere-app

bedevere-app Bot commented Aug 25, 2026

Copy link
Copy Markdown

Most changes to Python require a NEWS entry. Add one using the blurb_it web app or the blurb command-line tool.

If this change has little impact on Python users, wait for a maintainer to apply the skip news label instead.

Signed-off-by: sundeep8967 <sundeep8967@gmail.com>
…om options

Signed-off-by: sundeep8967 <sundeep8967@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant