Skip to content

fix: cache concatList.Size() to prevent O(N^2) evaluation time#1291

Merged
TristonianJones merged 3 commits intogoogle:masterfrom
Flo354:fix/concatlist-quadratic-size
Mar 26, 2026
Merged

fix: cache concatList.Size() to prevent O(N^2) evaluation time#1291
TristonianJones merged 3 commits intogoogle:masterfrom
Flo354:fix/concatlist-quadratic-size

Conversation

@Flo354
Copy link
Copy Markdown
Contributor

@Flo354 Flo354 commented Mar 23, 2026

concatList.Size() recomputes the total size by recursively calling Size() on prevList and nextList. After N concatenation operations, the resulting tree has depth N, and each Size() call traverses the full tree. List operations like exists(), all(), and filter() call Size() on each iteration, producing O(N^2) total time.

This means the CEL cost tracker (which uses Size() for cost estimation) reports O(N) cost while the actual evaluation time is O(N^2), bypassing CostLimit.

With N=1000 and CostLimit set: reported cost is 17011 (within budget), but actual evaluation takes 12s (706x the expected time).

The fix caches the computed size in a sync.Once field so repeated calls return in O(1).

Files changed: common/types/list.go

concatList.Size() recomputes the total size by recursively calling
Size() on prevList and nextList. After N concatenations, Size() on
each iteration produces O(N^2) total time, bypassing CostLimit.

Cache the result in a sync.Once field so repeated calls return in O(1).
@jnthntatum
Copy link
Copy Markdown
Collaborator

/gcbrun

@Flo354
Copy link
Copy Markdown
Contributor Author

Flo354 commented Mar 23, 2026

According to your last comment, I have added a newConcatList() constructor that precomputes the size, both Add() methods go through it now and removed the sync.

@TristonianJones
Copy link
Copy Markdown
Collaborator

Thanks, @Flo354!

@TristonianJones
Copy link
Copy Markdown
Collaborator

/gcbrun

@Flo354
Copy link
Copy Markdown
Contributor Author

Flo354 commented Mar 24, 2026

I did the changes, it's better indeed.
And from your comment on my other PR, I added a test case. It's on two angles. The first one verifies the size is correct, and the second one to check about the time required.

@jnthntatum
Copy link
Copy Markdown
Collaborator

/gcbrun

@TristonianJones TristonianJones merged commit d91350b into google:master Mar 26, 2026
3 checks passed
Maks1mS pushed a commit to stplr-dev/stplr that referenced this pull request Apr 9, 2026
This PR contains the following updates:

| Package | Type | Update | Change | OpenSSF |
|---|---|---|---|---|
| [github.com/google/cel-go](https://github.com/google/cel-go) | require | minor | `v0.27.0` → `v0.28.0` | [![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/google/cel-go/badge)](https://securityscorecards.dev/viewer/?uri=github.com/google/cel-go) |

---

> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/23) for more information.

---

### Release Notes

<details>
<summary>google/cel-go (github.com/google/cel-go)</summary>

### [`v0.28.0`](https://github.com/google/cel-go/releases/tag/v0.28.0)

[Compare Source](google/cel-go@v0.27.0...v0.28.0)

#### High-Level Changes

- **Enhanced JSON Interoperability:** New support for JSON names across the checker, AST, and runtime allows for more seamless data handling when working with JSON-native structures.
- **Improved Developer Tooling:** Integration is now smoother thanks to new utilities for converting Go errors into `cel.Issues` and more descriptive, context-aware error messages.
- **Greater Environment Flexibility:** You can now redeclare variables as constants and export parse limit options, providing finer control over how CEL environments are configured and constrained.
- **Native Struct Improvements:** Support for mixing CEL and native values within native structs simplifies the handling of complex, hybrid data types.

***

#### 🚀 Features

- Add helper method to check whether a function has a singleton binding in [#&#8203;1266](google/cel-go#1266)
- Helper utility for converting a Go error into `cel.Issues` in [#&#8203;1267](google/cel-go#1267)
- Policy API improvements in [#&#8203;1268](google/cel-go#1268)
- CEL Test usability requirements in [#&#8203;1269](google/cel-go#1269)
- Better context-related error messages in [#&#8203;1271](google/cel-go#1271)
- Sort `env.Config` values where reasonable in [#&#8203;1273](google/cel-go#1273)
- Support redeclaring variables as constants in `NewEnv` in [#&#8203;1275](google/cel-go#1275)
- Add support for exporting parse limit options in [#&#8203;1277](google/cel-go#1277)
- Support mixing CEL values and native values in native structs in [#&#8203;1270](google/cel-go#1270)
- Add checker, AST, and type-provider support for JSON names in [#&#8203;1283](google/cel-go#1283)
- JSON field names runtime support in [#&#8203;1286](google/cel-go#1286)
- Optionally include reachable fieldpaths in prompt in [#&#8203;1285](google/cel-go#1285)
- REPL -- cel-spec pb2 and json name support [#&#8203;1294](google/cel-go#1294)

#### 🐞 Bug Fixes

- Fix support for config-based type references in [#&#8203;1265](google/cel-go#1265)
- Check arg kinds in `optional.or` and `.orValue` impl in [#&#8203;1276](google/cel-go#1276)
- Bazel fixes for import in [#&#8203;1278](google/cel-go#1278)
- Support zero-value literals in presence test inlining [#&#8203;1280](google/cel-go#1280)
- Cache concatList.Size() to prevent O(N^2) evaluation time [#&#8203;1291](google/cel-go#1291)
- Preserve runtime error node IDs from Resolve  [#&#8203;1290](google/cel-go#1290)
- Default enable identifier escaping with backticks [#&#8203;1295](google/cel-go#1295)
- Cap format string precision to prevent memory exhaustion [#&#8203;1292](google/cel-go#1292)

#### 🛠️ Maintenance & Internal

- **chore:** Migrate gsutil usage to gcloud storage in [#&#8203;1274](google/cel-go#1274)
- Lint fixes for exported function/type comments in [#&#8203;1279](google/cel-go#1279)
- Lint fixes for import in [#&#8203;1287](google/cel-go#1287)

***

**Full Changelog**: [https://github.com/google/cel-go/compare/v0.27.0...v0.28.0-alpha](https://github.com/google/cel-go/compare/v0.27.0...v0.28.0)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At 12:00 AM through 04:59 AM and 10:00 PM through 11:59 PM, Monday through Friday (`* 0-4,22-23 * * 1-5`)
  - Only on Sunday and Saturday (`* * * * 0,6`)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDQuNSIsInVwZGF0ZWRJblZlciI6IjQzLjEwNC41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJLaW5kL0RlcGVuZGVuY2llcyJdfQ==-->

Reviewed-on: https://altlinux.space/stapler/stplr/pulls/402
Co-authored-by: Renovate Bot <stapler-helper-bot@noreply.altlinux.space>
Co-committed-by: Renovate Bot <stapler-helper-bot@noreply.altlinux.space>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants