Skip to content

Catch open parenthesis with no following tokens - #168

Merged
elrayle merged 1 commit into
mainfrom
elr/nil-panic
Oct 8, 2026
Merged

elrayle merged 1 commit into
mainfrom
elr/nil-panic

Conversation

@elrayle

@elrayle elrayle commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

closes #158

Description

prevents panic in cases where an open parenthesis is the last token in the stream

What was done

BEFORE

func parseParenthesizedExpression checks for an open parenthesis operator. If found, it immediately parsed an expression. If the token stream does not have any tokens remaining, this resulted in a panic.

AFTER

func parseParenthesizedExpression now follows the parenthesis operator check with a check that more tokens are in the stream. If not, it raises an error instead of throwing a panic.

prevents panic in cases where an open parenthesis is the last token in the stream
Copilot AI balanced review requested due to automatic review settings October 8, 2026 21:11

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The defensive checks address the reported nil dereferences and are covered by focused regression tests.

0 open findings

What changed in this PR

Prevents parser panics on truncated SPDX expressions by returning validation errors instead.

Changes:

  • Adds end-of-stream guards to parser functions.
  • Reports dangling parentheses and incomplete document references.
  • Adds parser and validation regression tests.
File Description
spdxexp/​parse.go Safely handles exhausted token streams.
spdxexp/​parse_test.go Tests malformed trailing tokens and operators.
spdxexp/​satisfies_test.go Verifies malformed licenses are rejected without panic.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@claire153 claire153 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice fix

@elrayle
elrayle merged commit 065aa3f into main Oct 8, 2026
8 checks passed
@elrayle
elrayle deleted the elr/nil-panic branch October 8, 2026 22:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

panic: nil-pointer dereference when parsing a dangling open parenthesis

3 participants