Skip to content

fix(file-parsers): cap untrusted number formats and make time-format check linear - #8893

Merged
waleedlatif1 merged 3 commits into
stagingfrom
fix/xlsx-time-format-quadratic
Oct 10, 2026
Merged

waleedlatif1 merged 3 commits into
stagingfrom
fix/xlsx-time-format-quadratic

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • isTimeOnlyFormat sliced the format and ran an unanchored /[:\s]+$/ once per m run, so classifying a date cell's number format was quadratic in the format's length. The format comes verbatim from the workbook's styles.xml (cell.z), so one spreadsheet could make each date cell cost hundreds of ms of synchronous CPU across the parse/preview window (server ingestion and the Files viewer tab)
  • Replaced the per-match slicing with isMinutesRun, a linear walk outward from each m run that skips :/whitespace — same classification as before
  • normalizeSheetDisplayText now treats a cell.z longer than 255 characters (Excel's own custom-format limit) as unformatted, which bounds every scan of the format, including dateTokensOf's bracket strip and the elapsed-token check

Type of Change

  • Bug fix

Testing

  • isTimeOnlyFormat on a 50k-char format: 645 ms → <1 ms; normalizeSheetDisplayText over 20 such cells: 12.7 s → <1 ms
  • New regression test (307-char format ignored, 247-char format still honored) fails with the cap reverted
  • vitest run lib/file-parsers — 29 files, 298 tests passing; biome clean

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

🤖 Generated with Claude Code

@vercel

vercel Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 10, 2026 7:55pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files

Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/file-parsers/sheet-display-text.ts Outdated
@greptile-apps

greptile-apps Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium impact] The PR appears safe to merge; no actionable new issue was found.

Summary

The PR bounds date-format checks and replaces repeated slicing with nearby character checks.

  • Date cells keep workbook text when formats exceed 255 characters.
  • Time-only format checks now scan the format in linear time.

Reviews (3) · Last reviewed commit: "fix(file-parsers): leave dates with over..." · Reviewed by Greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/file-parsers/sheet-display-text.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit dc9654d into staging Oct 10, 2026
48 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/xlsx-time-format-quadratic branch October 10, 2026 20:22

This branch was previously deployed

1 inactive deployment
Preview — 9c399032 Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant