{"record":{"id":"38ce23c7462c035e","repo":"JuliusBrussee/caveman","slug":"bounded","errorCode":null,"errorMessage":"bounded","messagePattern":"bounded","errorType":"exception","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"packages/middleware/python/caveman_middleware/_google_wire.py","lineNumber":19,"sourceCode":"\"\"\"Bounded Google JSON string offsets; untouched serialized text stays exact.\"\"\"\nimport json\n\n\ndef parse(text):\n    if len(text) > 2 << 20:\n        return None\n    decoder, strings, index, nodes = json.JSONDecoder(), {}, 0, 0\n\n    def white():\n        nonlocal index\n        while index < len(text) and text[index] in \" \\t\\r\\n\":\n            index += 1\n\n    def walk(path, depth=0):\n        nonlocal index, nodes\n        nodes += 1\n        if depth > 64 or nodes > 65536:\n            raise ValueError(\"bounded\")\n        white()\n        start = index\n        if text[index] == '\"':\n            value, index = decoder.raw_decode(text, index)\n            strings[path] = (start, index, value)\n            return value\n        if text[index] == \"{\":\n            index += 1\n            result = {}\n            white()\n            if text[index] == \"}\":\n                index += 1\n                return result\n            while True:\n                white()\n                key, index = decoder.raw_decode(text, index)\n                if type(key) is not str or key in result:\n                    raise ValueError(\"duplicate\")","sourceCodeStart":1,"sourceCodeEnd":37,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/packages/middleware/python/caveman_middleware/_google_wire.py#L1-L37","documentation":"walk is a custom position-tracking JSON parser used to record string spans. To keep the hand-rolled recursive descent safe it enforces hard bounds: nesting depth of 64 and 65536 total nodes. Exceeding either raises ValueError('bounded') instead of recursing without limit.","triggerScenarios":"Parsing a JSON text whose nesting exceeds 64 levels, or whose total node count exceeds 65536, via the parse() entry point of _google_wire.","commonSituations":"Feeding deeply machine-generated JSON (e.g. stacked API payloads or serialized traces) into the wire parser; adversarial/malformed inputs designed to blow the stack; re-parsing large accumulated transcript blobs.","solutions":["Reduce the nesting depth of the JSON payload before parsing (flatten or restructure)","Split oversized documents and parse them in chunks under the 65536-node budget","If legitimate payloads are deeper, raise the depth/nodes constants in _google_wire.py deliberately","Catch ValueError and treat the payload as unsupported wire format"],"exampleFix":"# before\nvalue = parse(deeply_nested_text)  # ValueError: bounded\n# after\ntext = json.dumps(flatten(json.loads(raw), max_depth=32))\nvalue = parse(text)","handlingStrategy":"try-catch","validationCode":"def within_bounds(text, max_depth=64, max_nodes=65536):\n    import json\n    def depth(pairs_or_obj):\n        if isinstance(pairs_or_obj, dict):\n            return 1 + max((depth(v) for v in pairs_or_obj.values()), default=0)\n        if isinstance(pairs_or_obj, list):\n            return 1 + max((depth(v) for v in pairs_or_obj), default=0)\n        return 0\n    obj = json.loads(text)\n    return depth(obj) <= max_depth","typeGuard":null,"tryCatchPattern":"try:\n    value = parse(text)\nexcept ValueError as e:\n    if str(e) == \"bounded\":\n        log.warning(\"payload exceeds parser bounds (depth>64 or nodes>65536); rejecting\")\n        value = None","preventionTips":["Flatten deeply nested payloads at the producer before sending","Keep generated JSON nesting under ~50 levels","Reject suspiciously large documents before parsing","Add a unit test with a 65-deep fixture to pin the boundary behavior"],"tags":["python","json","recursion","limits"],"backgroundTag":"value-out-of-range","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}