CodeQL library for JavaScript
Search

Predicate isPumpable

Holds if matching repetitions of pump can:

  1. Transition from pivot back to pivot.
  2. Transition from pivot to succ.
  3. Transition from succ to succ.

From theorem 3 in the paper linked in the top of this file we can therefore conclude that the regular expression has polynomial backtracking - if a rejecting suffix exists.

This predicate is used by SuperLinearReDoSConfiguration, and the final results are available in the hasReDoSResult predicate.

Import path

import semmle.javascript.security.performance.SuperlinearBackTracking
predicate isPumpable(State pivot, State succ, string pump)