v2.7.0
This release introduces over a dozen bug fixes, including some
denial-of-service vulnerabilities, and approximately triples or quadruples the
performance of parsing! There's also now a CLI too for parsing ASN.1.
Added
asn1parserCLI:lex,cst,ast, andchecksubcommands that
concatenate ASN.1 files and print JSON (orok) to stdout or-o/
--output. Pretty-print with-p/--pretty.
Fixed
- Grok
SEQUENCEandSETtypes whose component list starts with an extension
marker (...). Groking previously crashed with
TypeError: Cannot read properties of undefined. - Parse a parameterized
DefinedType(for example
CAMEL-AChBillingChargingCharacteristics {bound}) as a
UserDefinedConstraintParameterinsideCONSTRAINED BY { ... }. The parser
previously accepted the type reference as a bare object-set or object-class
name and left the parameter list unconsumed. - Report empty value-set assignments (
Foo Type ::= { }and
Foo Type ::= { ... }) with a descriptive syntax error. These previously
failed the assignment and surfaced as a generic missingEND. - Report correct line and column numbers after tokens that contain newlines
(block comments, character strings, and bit/hex strings). Substring re-lexing
viastartlocnow keeps columns in substring-relative coordinates. - Throw
ASN1SyntaxErrorfor an unterminatedcstringinstead of hanging. - Emit a
SYNTAX_ERRORtoken for unrecognized characters instead of swallowing
them into the next token or spinning until the infinite-loop guard.parse()
records these insyntaxErrorsand continues with the rest of the module. - Lex
realnumberforms with an exponent and no decimal point (1e10,1E-5).
These previously split into anumberand an identifier. - Nest
/* */block comments per X.680, and do not treat the*in the opener
as the start of a closer (/*/is not a closed comment). - Do not close a
--comment by overlapping the opener, so---is not treated
as a finished comment. - Emit a
SYNTAX_ERRORfor numbers with leading zeros (0123), matching X.680
12.8. Bare0and realnumbers such as0.5and0e10are unchanged. - Lex lowercase
trueandfalseas XML boolean keywords
(ProductionType._true/_false) soEmptyElementBoolean(<true/>,
<false/>) parses correctly. - Allow NBSP (
U+00A0) insidebstringandhstring, matching X.680
white-space. - Fail
anythingUntilwhen its terminator never appears, instead of treating
end of input as a successful match. Encoding instructions that never see]
(orEND/ENCODING-CONTROL) are now parse failures.assertrecovery
still skips to end of input and records a syntax error when the recovery token
is missing. - Parse
{ ... }BuiltinValuealternatives according tocurrentTypewhen it
is known, and includeSetValue/SetOfValuein the untyped{fallback.
Without a type,{}was aBitStringValueand{ a 1 }was an
ObjectIdentifierValue, so SEQUENCE/SET value assignments were misidentified. - Handle maliciously recursive inputs.
DefinitiveOID, when groked, had whitespace remaining innamefor OID arcs
that used a name and number (e.g.asdf(4)).
Changed
- Dispatch
BuiltinType,ReferencedType,BuiltinValue,
CharacterStringType, and related choices on the current token type
(FIRST-set gating) so doomed alternatives are not executed.
TypeWithConstraintandOpenTypeFieldValare skipped unless the following
token can start those productions. - Packrat-memoize expensive singleton parsers (
recursiveParser,whitespace,
Setting) by parser identity, token index, and semantic context so
backtracking does not re-run the same production.recursiveParsernow
resolves its getter once so inner combinators keep a stable identity. - Use
String.prototype.startsWithfor lexer delimiter prefix checks so
comments, colons, and slashes are not O(n²) on large inputs.