Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Sanitization requires color, which parses every record

Abierto
#419 2 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

  • #420 de @kskalski — cerrado sin fusionar

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
52/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
rust

Línea de trabajo

Comienza en src/writer/mod.rs:134 y sigue la ruta de AutoStream con el color deshabilitado a través de la sanitización y el procesamiento de anstyle-parse. Reproduce el benchmark indicado y verifica después que los bytes C0 y DEL se neutralicen, que newline y tab permanezcan sin cambios, que la ruta de color no se vea afectada y que la entrada legítima no ASCII se gestione de acuerdo con el comportamiento elegido.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Problem

With styling disabled, AutoStream still walks every record through anstyle-parse's VT state machine, roughly doubling per-record cost even for builds emitting no styling.

Target::Stderr → /dev/null, 161-byte records, 500k iterations, release + LTO, 8 interleaved rounds:

ns/record
with color 596
without color 302

Turning off just auto-color doesn't avoid it — WriteStyle::Auto then collapses to Never (src/writer/mod.rs:134), making the parse unconditional. Only dropping color entirely removes the parser.

However dropping color also removes sanitization, as the two share a code path, so untrusted input then reaches the reader's terminal verbatim:

Note: deactivating the build-time feature color is not a mitigation as that
removes all ANSI escape code stripping from env_logger.

Neither configuration avoids both. The coupling isn't required though: without color there is no styling emitted, so nothing needs parsing, only payload bytes need neutralizing.

Proposal

Escape C0 and DEL as \xNN when color is off, sparing \n and \t.

  • 319 ns/record measured, so sanitizing costs ~17 ns over the unsafe build today
  • color path untouched, no behavior change for anyone using it
  • differs from the strip it replaces in both directions:
    • stricter on \r, VT and FF, which anstream passes through
    • more permissive on raw C1 and stray continuation bytes, which anstream drops (matching it there needs full UTF-8 validation — ~20 lines, free for ASCII records, ~+40 ns/record for records with legitimate non-ASCII)
Lenguaje dominante
Rust
Estrellas
1.1k
Forks
150
Merge medio
3 min
PR fusionados (30 d)
2

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de rust-cli/env_logger

Todos los issues de rust-cli/env_logger

Issues similares

Más issues de Rust

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.