regex: java.util.regex companion code (groups, lookarounds, replaceAll lambdas, ReDoS and timeouts)

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01KqJyCidz3ZgRyHABv2GVJh
This commit is contained in:
2026-09-30 19:00:39 +00:00
co-authored by Claude Sonnet 5.5
parent bfa7f97432
commit b31c6716a3
22 changed files with 647 additions and 0 deletions
+1
View File
@@ -15,6 +15,7 @@ article; each module's own README has that article's version table, quickstart,
| [`arithmetic`](arithmetic/) | Add Two Numbers in Java Without Overflow: addExact, Widening, and BigInteger |
| [`hashmap-concurrenthashmap`](hashmap-concurrenthashmap/) | Java HashMap vs ConcurrentHashMap: Complete Interview Guide |
| [`exceptions`](exceptions/) | Java Exception Handling Deep Dive: Checked vs Unchecked, Suppression, and What Exceptions Actually Cost |
| [`regex`](regex/) | Java Regex Tutorial: Pattern, Matcher, Groups, Lookarounds and ReDoS |
## License
+1
View File
@@ -23,6 +23,7 @@
<module>arithmetic</module>
<module>hashmap-concurrenthashmap</module>
<module>exceptions</module>
<module>regex</module>
</modules>
<properties>
+38
View File
@@ -0,0 +1,38 @@
# regex
Companion code for the ankurm.com post *"Java Regex Tutorial: Pattern, Matcher, Groups, Lookarounds
and ReDoS."* Module `regex` in `java-core-examples`.
All explanation lives in the post; this module holds the runnable evidence and the captured output.
## Versions
| Component | Version |
|---|---|
| JDK | 25.0.4.1+1 (Temurin, LTS) |
| JUnit Jupiter | 5.11.0 |
| Hardware | 2 vCPU x86-64 VM (timings are indicative, not a leaderboard) |
## Quickstart
```bash
export JDK25_HOME=/path/to/jdk-25
./scripts/run-all.sh # rebuilds, runs the tests, regenerates everything in output/
```
## What is in here
| File | Shows | Output |
|---|---|---|
| `BasicsDemo` | `matches` / `lookingAt` / `find`, numbered and named groups, `results()`, flags | `01` |
| `LookaroundDemo` | lookahead, lookbehind, password policy, thousands separators, lookbehind limits | `02` |
| `ReplaceDemo` | `$1` / `${name}`, the `$` trap, `replaceAll(Function)`, `quoteReplacement`, `appendReplacement` | `03` |
| `BlowupDemo` | timings at growing input: what the JDK tames, what it does not | `04` |
| `FixesDemo` | rewrite, possessive, atomic group; `find()` is still quadratic | `05` |
| `LimitsDemo` | `StackOverflowError` from `(?:a\|b)*` on long input | `06` |
| `RegexTimeout`, `Safe` | a `CharSequence` that aborts a match at a deadline; length limit + deadline wrapper | used by `04`, `05` |
| JDK `Pattern.java` excerpt | the loop-memoisation gate, and the absence of any timeout API | `07` |
| `RegexClaimsTest` | 11 assertions behind the claims above | `08` |
Every timing run is capped (2 s in `BlowupDemo`) by `RegexTimeout`, so the demos always finish.
Timings move by tens of percent between runs; the growth shape and which patterns abort do not.
+23
View File
@@ -0,0 +1,23 @@
matches() = true
group(0) = 2026-03-14 ERROR disk /dev/sda1 is 97% full
group(2) = ERROR
level = ERROR
start(msg) = 17, end(msg) = 43
namedGroups = {date=1, level=2, msg=3}
matches() on "order-42 shipped" = false
lookingAt() on "order-42 shipped" = false
find() on "order-42 shipped" = true
results() over "a1 b22 c333":
a1 -> group(1)=1
b22 -> group(1)=22
c333 -> group(1)=333
no flags : 0
CASE_INSENSITIVE : 0
MULTILINE : 1
MULTILINE|CASE_INS. : 3
embedded (?im) : 3
'.' vs newline : 0 / DOTALL 1
COMMENTS : 1
+12
View File
@@ -0,0 +1,12 @@
\d+(?=px) -> "120", "48"
foo(?!bar) -> "foo", "foo"
(?<=\$)\d+(?:\.\d\d)? -> "19.99", "23"
(?<![\d$.])\d+ -> "3"
policy abcdefgh -> false
policy Abcdefg1 -> true
policy Ab1 -> false
policy ABCDEFG1x -> true
1,234,567
compiled (?<=a+)b
compiled (?<=a{1,9})b
rejected (?<=(?:ab)+)c : Look-behind group does not have an obvious maximum length
+9
View File
@@ -0,0 +1,9 @@
price: 5 dollars, fee: 12 dollars
price: USD 5, fee: USD 12
replaceAll("$") -> IllegalArgumentException: Illegal group reference: group index is missing
price: 5 $, fee: 12 $
price: 10 USD, fee: 24 USD
unquoted lambda -> IndexOutOfBoundsException: No group 5
hello ankur, you owe $5
hi ${nobody}
rEgUlAr ExprEssIOns
+28
View File
@@ -0,0 +1,28 @@
cap per run: 2000 ms; input = n letters 'a' followed by '!' (no match possible)
pattern (a+)+b
n=20 0 ms matches=false
n=36 0 ms matches=false
n=500 1 ms matches=false
n=1000 23 ms matches=false
n=2000 63 ms matches=false
n=4000 161 ms matches=false
pattern (a+)+\1?b
n=20 27 ms matches=false
n=24 690 ms matches=false
n=26 ABORTED after 2036 ms (cap)
pattern (?:(?:a+)+)+b
n=16 3 ms matches=false
n=18 13 ms matches=false
n=20 101 ms matches=false
n=22 896 ms matches=false
n=24 ABORTED after 2000 ms (cap)
pattern a*a*a*a*b
n=50 2 ms matches=false
n=100 69 ms matches=false
n=150 285 ms matches=false
n=200 824 ms matches=false
+12
View File
@@ -0,0 +1,12 @@
input: 40 x 'a' + '!' budget 1000 ms
vulnerable (?:(?:a+)+)+b ABORTED after 1019 ms
rewritten a+b 0 ms matches=false
possessive (?:a++)++b 7 ms matches=false
atomic (?>(?:a+)+)b 0 ms matches=false
find() a+b n=5000 139 ms found=false
find() a+b n=10000 489 ms found=false
find() a+b n=20000 1906 ms found=false
find() (?<!a)a+b n=5000 6 ms found=false
find() (?<!a)a+b n=10000 6 ms found=false
find() (?<!a)a+b n=20000 15 ms found=false
+6
View File
@@ -0,0 +1,6 @@
(?:a|b)*c length 1000 -> true
(?:a|b)*c length 5000 -> StackOverflowError
(?:a|b)*c length 20000 -> StackOverflowError
(?:a|b)*c length 100000 -> StackOverflowError
[ab]*c length 100000 -> true
(?:a|b)*+c length 100000 -> true
+22
View File
@@ -0,0 +1,22 @@
$ java -version
openjdk version "25.0.4.1" 2026-08-18 LTS
OpenJDK Runtime Environment Temurin-25.0.4.1+1 (build 25.0.4.1+1-LTS)
OpenJDK 64-Bit Server VM Temurin-25.0.4.1+1 (build 25.0.4.1+1-LTS, mixed mode, sharing)
$ unzip -p lib/src.zip java.base/java/util/regex/Pattern.java | sed -n "/Optimize the greedy Loop/,/^ }$/p"
// Optimize the greedy Loop to prevent exponential backtracking, IF there
// is no group ref in this pattern. With a non-negative localTCNCount value,
// the greedy type Loop, Curly will skip the backtracking for any starting
// position "i" that failed in the past.
if (!hasGroupRef) {
for (Node node : topClosureNodes) {
if (node instanceof Loop) {
// non-deterministic-greedy-group
((Loop)node).posIndex = localTCNCount++;
}
}
}
$ grep -ci timeout Pattern.java Matcher.java
Pattern.java: 0
Matcher.java: 0
+4
View File
@@ -0,0 +1,4 @@
-------------------------------------------------------------------------------
Test set: com.ankurm.regex.RegexClaimsTest
-------------------------------------------------------------------------------
Tests run: 11, Failures: 0, Errors: 0, Skipped: 0, Time elapsed: 1.131 s -- in com.ankurm.regex.RegexClaimsTest
+43
View File
@@ -0,0 +1,43 @@
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<parent>
<groupId>com.ankurm</groupId>
<artifactId>java-core-examples</artifactId>
<version>1.0</version>
</parent>
<artifactId>regex</artifactId>
<name>regex</name>
<description>java.util.regex: groups, flags, lookarounds, replaceAll with lambdas, catastrophic backtracking, and ways to bound it.</description>
<dependencies>
<dependency>
<groupId>org.junit.jupiter</groupId>
<artifactId>junit-jupiter</artifactId>
<version>5.11.0</version>
<scope>test</scope>
</dependency>
</dependencies>
<build>
<plugins>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-compiler-plugin</artifactId>
<version>3.13.0</version>
<configuration>
<release>25</release>
</configuration>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-surefire-plugin</artifactId>
<version>3.2.5</version>
</plugin>
</plugins>
</build>
</project>
+28
View File
@@ -0,0 +1,28 @@
#!/usr/bin/env bash
# Regenerates every file in ../output/. Requires JDK25_HOME.
set -euo pipefail
[[ -z "${JDK25_HOME:-}" ]] && { echo "JDK25_HOME must be set" >&2; exit 1; }
cd "$(dirname "$0")/.."
OUT=output; mkdir -p "$OUT"
export JAVA_HOME="$JDK25_HOME"
mvn -q -f ../pom.xml -pl regex -am package
J="$JDK25_HOME/bin/java"
run() { echo "==> $1"; "$J" -cp target/classes "com.ankurm.regex.$1" 2>&1 | grep -v "Picked up" > "$OUT/$2"; }
run BasicsDemo 01-basics.txt
run LookaroundDemo 02-lookarounds.txt
run ReplaceDemo 03-replace.txt
run BlowupDemo 04-blowup.txt
run FixesDemo 05-fixes.txt
run LimitsDemo 06-limits.txt
echo "==> JDK source: the backtracking mitigation and the absence of a timeout"
{
echo '$ java -version'; "$J" -version 2>&1 | grep -v "Picked up"
echo
echo '$ unzip -p lib/src.zip java.base/java/util/regex/Pattern.java | sed -n "/Optimize the greedy Loop/,/^ }$/p"'
unzip -p "$JDK25_HOME/lib/src.zip" java.base/java/util/regex/Pattern.java | sed -n '/Optimize the greedy Loop/,/^ }$/p'
echo
echo '$ grep -ci timeout Pattern.java Matcher.java'
for f in Pattern Matcher; do echo "$f.java: $(unzip -p "$JDK25_HOME/lib/src.zip" java.base/java/util/regex/$f.java | grep -ci timeout)"; done
} > "$OUT/07-jdk-source.txt"
cp target/surefire-reports/com.ankurm.regex.RegexClaimsTest.txt "$OUT/08-tests.txt"
echo Done
@@ -0,0 +1,53 @@
package com.ankurm.regex;
import java.util.regex.MatchResult;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
/** Pattern, Matcher, the three match methods, numbered and named groups, flags. */
public class BasicsDemo {
static final Pattern LOG = Pattern.compile(
"(?<date>\\d{4}-\\d{2}-\\d{2}) (?<level>INFO|WARN|ERROR) (?<msg>.+)");
public static void main(String[] args) {
String line = "2026-03-14 ERROR disk /dev/sda1 is 97% full";
Matcher m = LOG.matcher(line);
System.out.println("matches() = " + m.matches());
System.out.println("group(0) = " + m.group(0));
System.out.println("group(2) = " + m.group(2));
System.out.println("level = " + m.group("level"));
System.out.println("start(msg) = " + m.start("msg") + ", end(msg) = " + m.end("msg"));
System.out.println("namedGroups = " + new java.util.TreeMap<>(m.namedGroups()));
System.out.println();
String s = "order-42 shipped";
Pattern digits = Pattern.compile("\\d+");
System.out.println("matches() on \"" + s + "\" = " + digits.matcher(s).matches());
System.out.println("lookingAt() on \"" + s + "\" = " + digits.matcher(s).lookingAt());
System.out.println("find() on \"" + s + "\" = " + digits.matcher(s).find());
System.out.println();
System.out.println("results() over \"a1 b22 c333\":");
Pattern.compile("[a-z](\\d+)").matcher("a1 b22 c333").results()
.map((MatchResult r) -> r.group() + " -> group(1)=" + r.group(1))
.forEach(x -> System.out.println(" " + x));
System.out.println();
String text = "Error\nerror\nERROR";
System.out.println("no flags : " + count("^error$", 0, text));
System.out.println("CASE_INSENSITIVE : " + count("^error$", Pattern.CASE_INSENSITIVE, text));
System.out.println("MULTILINE : " + count("^error$", Pattern.MULTILINE, text));
System.out.println("MULTILINE|CASE_INS. : " + count("^error$", Pattern.MULTILINE | Pattern.CASE_INSENSITIVE, text));
System.out.println("embedded (?im) : " + count("(?im)^error$", 0, text));
System.out.println("'.' vs newline : " + count("a.b", 0, "a\nb") + " / DOTALL " + count("a.b", Pattern.DOTALL, "a\nb"));
System.out.println("COMMENTS : " + count("\\d{3} # area code\n - \\d{4} # number", Pattern.COMMENTS, "555-1234"));
}
static int count(String regex, int flags, String text) {
Matcher m = Pattern.compile(regex, flags).matcher(text);
int n = 0;
while (m.find()) n++;
return n;
}
}
@@ -0,0 +1,43 @@
package com.ankurm.regex;
import java.util.regex.Pattern;
/** Times patterns at growing input sizes. Every run is capped by RegexTimeout so the demo always finishes. */
public class BlowupDemo {
static final long CAP_MS = 2000;
public static void main(String[] args) {
warmUp();
System.out.println("cap per run: " + CAP_MS + " ms; input = n letters 'a' followed by '!' (no match possible)");
System.out.println();
// A: the textbook nested quantifier. Looks deadly; JDK 25 handles it.
series("(a+)+b", new int[] {20, 36, 500, 1_000, 2_000, 4_000});
// B: the same pattern with a backreference somewhere in it: the JDK's optimisation is switched off
series("(a+)+\\1?b", new int[] {20, 24, 26, 28, 30});
// C: nested quantifiers without a capturing group: not covered by the optimisation
series("(?:(?:a+)+)+b", new int[] {16, 18, 20, 22, 24, 26});
// D: polynomial, not exponential: adjacent quantifiers over the same characters
series("a*a*a*a*b", new int[] {50, 100, 150, 200});
}
/** Let the JIT see each pattern before anything is timed, so the first row is not a cold start. */
static void warmUp() {
for (String re : new String[] {"(a+)+b", "(a+)+\\1?b", "(?:(?:a+)+)+b", "a*a*a*a*b"})
for (int i = 0; i < 300; i++)
RegexTimeout.matchesWithin(Pattern.compile(re), "a".repeat(12) + "!", CAP_MS);
}
static void series(String regex, int[] sizes) {
Pattern p = Pattern.compile(regex);
System.out.println("pattern " + regex);
for (int n : sizes) {
String input = "a".repeat(n) + "!";
long t0 = System.nanoTime();
Boolean r = RegexTimeout.matchesWithin(p, input, CAP_MS);
long ms = (System.nanoTime() - t0) / 1_000_000;
System.out.printf(" n=%-6d %s%n", n, r == null ? "ABORTED after " + ms + " ms (cap)" : ms + " ms matches=" + r);
if (r == null) break;
}
System.out.println();
}
}
@@ -0,0 +1,36 @@
package com.ankurm.regex;
import java.util.regex.Pattern;
/** The same hostile input against the vulnerable pattern and each fix. */
public class FixesDemo {
static final int N = 40;
static final String HOSTILE = "a".repeat(N) + "!";
public static void main(String[] args) {
System.out.println("input: " + N + " x 'a' + '!' budget 1000 ms");
run("vulnerable (?:(?:a+)+)+b ", "(?:(?:a+)+)+b", HOSTILE);
run("rewritten a+b ", "a+b", HOSTILE);
run("possessive (?:a++)++b ", "(?:a++)++b", HOSTILE);
run("atomic (?>(?:a+)+)b ", "(?>(?:a+)+)b", HOSTILE);
System.out.println();
// find() tries every start position, so even a safe pattern is quadratic on this input
// find() tries every start position, so even a safe pattern is quadratic on this input.
// Plain String input here (no deadline wrapper) and a warm-up, so the numbers are the regex's own.
for (int i = 0; i < 20; i++) Pattern.compile("a+b").matcher("a".repeat(2_000) + "!").find();
for (String re : new String[] {"a+b", "(?<!a)a+b"})
for (int n : new int[] {5_000, 10_000, 20_000}) {
String s = "a".repeat(n) + "!";
long t0 = System.nanoTime();
boolean found = Pattern.compile(re).matcher(s).find();
System.out.printf("find() %-10s n=%-6d %4d ms found=%s%n", re, n, (System.nanoTime() - t0) / 1_000_000, found);
}
}
static void run(String label, String regex, String input) {
long t0 = System.nanoTime();
Boolean r = RegexTimeout.matchesWithin(Pattern.compile(regex), input, 1000);
long ms = (System.nanoTime() - t0) / 1_000_000;
System.out.printf("%s %s%n", label, r == null ? "ABORTED after " + ms + " ms" : ms + " ms matches=" + r);
}
}
@@ -0,0 +1,26 @@
package com.ankurm.regex;
import java.util.regex.Pattern;
/** Two non-exponential ways a regex call can still hurt: deep recursion and oversized input. */
public class LimitsDemo {
public static void main(String[] args) {
Pattern alt = Pattern.compile("(?:a|b)*c");
for (int n : new int[] {1_000, 5_000, 20_000, 100_000}) {
String s = "ab".repeat(n / 2) + "c";
try {
System.out.println("(?:a|b)*c length " + n + " -> " + alt.matcher(s).matches());
} catch (StackOverflowError e) {
System.out.println("(?:a|b)*c length " + n + " -> StackOverflowError");
}
}
Pattern safe = Pattern.compile("[ab]*c");
System.out.println("[ab]*c length 100000 -> " + safe.matcher("ab".repeat(50_000) + "c").matches());
Pattern poss = Pattern.compile("(?:a|b)*+c");
try {
System.out.println("(?:a|b)*+c length 100000 -> " + poss.matcher("ab".repeat(50_000) + "c").matches());
} catch (StackOverflowError e) {
System.out.println("(?:a|b)*+c length 100000 -> StackOverflowError");
}
}
}
@@ -0,0 +1,44 @@
package com.ankurm.regex;
import java.util.List;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
/** Zero-width assertions: they test the text around a position but consume nothing. */
public class LookaroundDemo {
public static void main(String[] args) {
// positive lookahead: a digit run that is followed by "px", without including "px"
show("\\d+(?=px)", "width:120px; z-index:7; height:48px");
// negative lookahead: "foo" not followed by "bar"
show("foo(?!bar)", "foobar foobaz foo");
// positive lookbehind: digits preceded by a dollar sign
show("(?<=\\$)\\d+(?:\\.\\d\\d)?", "cost $19.99, tax 3, total $23");
// negative lookbehind: digits NOT preceded by a dollar sign
show("(?<![\\d$.])\\d+", "cost $19.99, tax 3, total $23");
// several lookaheads at one position = AND of conditions: a password policy
Pattern policy = Pattern.compile("^(?=.*\\d)(?=.*[a-z])(?=.*[A-Z]).{8,}$");
for (String pw : List.of("abcdefgh", "Abcdefg1", "Ab1", "ABCDEFG1x"))
System.out.printf("policy %-10s -> %s%n", pw, policy.matcher(pw).matches());
// thousands separators: insert a comma before every group of 3 digits that ends the number
System.out.println(Pattern.compile("(?<=\\d)(?=(?:\\d{3})+$)").matcher("1234567").replaceAll(","));
// lookbehind needs a computable maximum length; probe which shapes this JDK accepts
for (String re : new String[] {"(?<=a+)b", "(?<=a{1,9})b", "(?<=(?:ab)+)c"}) {
try {
Pattern.compile(re);
System.out.println("compiled " + re);
} catch (java.util.regex.PatternSyntaxException e) {
System.out.println("rejected " + re + " : " + e.getDescription());
}
}
}
static void show(String regex, String text) {
Matcher m = Pattern.compile(regex).matcher(text);
StringBuilder sb = new StringBuilder();
while (m.find()) sb.append(sb.isEmpty() ? "" : ", ").append('"').append(m.group()).append('"');
System.out.printf("%-28s -> %s%n", regex, sb);
}
}
@@ -0,0 +1,63 @@
package com.ankurm.regex;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
/**
* java.util.regex has no timeout API. The matcher reads its input only through CharSequence.charAt,
* so a CharSequence that checks a deadline can abort a runaway match by throwing.
*/
public final class RegexTimeout implements CharSequence {
/** Unchecked, so it can cross charAt(). Carries how long the match had run. */
public static final class RegexTimeoutException extends RuntimeException {
public RegexTimeoutException(long budgetMillis) {
super("regex exceeded " + budgetMillis + " ms");
}
}
private final CharSequence inner;
private final long deadlineNanos;
private final long budgetMillis;
private int calls;
public RegexTimeout(CharSequence inner, long budgetMillis) {
this.inner = inner;
this.budgetMillis = budgetMillis;
this.deadlineNanos = System.nanoTime() + budgetMillis * 1_000_000L;
}
@Override public char charAt(int index) {
// nanoTime() is cheap but not free; look at the clock once per 1024 reads
if ((++calls & 1023) == 0 && System.nanoTime() > deadlineNanos)
throw new RegexTimeoutException(budgetMillis);
return inner.charAt(index);
}
@Override public int length() { return inner.length(); }
@Override public CharSequence subSequence(int start, int end) {
return new RegexTimeout(inner.subSequence(start, end), budgetMillis);
}
@Override public String toString() { return inner.toString(); }
/** matches() with a budget; returns null when the budget ran out. */
public static Boolean matchesWithin(Pattern p, CharSequence input, long budgetMillis) {
try {
return p.matcher(new RegexTimeout(input, budgetMillis)).matches();
} catch (RegexTimeoutException e) {
return null;
}
}
/** find() with a budget; returns null when the budget ran out. */
public static Boolean findWithin(Pattern p, CharSequence input, long budgetMillis) {
try {
Matcher m = p.matcher(new RegexTimeout(input, budgetMillis));
return m.find();
} catch (RegexTimeoutException e) {
return null;
}
}
}
@@ -0,0 +1,51 @@
package com.ankurm.regex;
import java.util.Map;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
/** replaceAll with a replacement string, with a lambda, and the $ and \ traps. */
public class ReplaceDemo {
public static void main(String[] args) {
String text = "price: 5 USD, fee: 12 USD";
// 1. replacement string: $1 is group 1, ${name} is a named group
System.out.println(Pattern.compile("(\\d+) USD").matcher(text).replaceAll("$1 dollars"));
System.out.println(Pattern.compile("(?<n>\\d+) USD").matcher(text).replaceAll("USD ${n}"));
// 2. the trap: a literal dollar sign in the replacement is an error
try {
Pattern.compile("USD").matcher(text).replaceAll("$");
} catch (IllegalArgumentException e) {
System.out.println("replaceAll(\"$\") -> " + e.getClass().getSimpleName() + ": " + e.getMessage());
}
System.out.println(Pattern.compile("USD").matcher(text).replaceAll(Matcher.quoteReplacement("$")));
// 3. lambda: Matcher.replaceAll(Function<MatchResult,String>) computes each replacement
System.out.println(Pattern.compile("\\d+").matcher(text)
.replaceAll(r -> String.valueOf(Integer.parseInt(r.group()) * 2)));
// 4. the lambda's return value is still parsed for $ and \ -- quote it if it is data
Map<String, String> vars = Map.of("user", "ankur", "cost", "$5");
Pattern tpl = Pattern.compile("\\$\\{(\\w+)}");
String tplText = "hello ${user}, you owe ${cost}";
try {
System.out.println(tpl.matcher(tplText).replaceAll(r -> vars.get(r.group(1))));
} catch (RuntimeException e) {
System.out.println("unquoted lambda -> " + e.getClass().getSimpleName() + ": " + e.getMessage());
}
System.out.println(tpl.matcher(tplText)
.replaceAll(r -> Matcher.quoteReplacement(vars.get(r.group(1)))));
// 5. a missing key: decide explicitly instead of letting null through
System.out.println(tpl.matcher("hi ${nobody}")
.replaceAll(r -> Matcher.quoteReplacement(vars.getOrDefault(r.group(1), r.group()))));
// 6. before Java 9: appendReplacement / appendTail (still the way to write to a StringBuilder)
Matcher m = Pattern.compile("[aeiou]").matcher("regular expressions");
StringBuilder sb = new StringBuilder();
while (m.find()) m.appendReplacement(sb, m.group().toUpperCase());
m.appendTail(sb);
System.out.println(sb);
}
}
@@ -0,0 +1,16 @@
package com.ankurm.regex;
import java.util.regex.Pattern;
/** The defensive wrapper: a length limit first, then a deadline. */
public final class Safe {
private Safe() {}
public static boolean matches(Pattern p, String input, int maxLength, long budgetMillis) {
if (input.length() > maxLength)
throw new IllegalArgumentException("input longer than " + maxLength + " characters");
Boolean r = RegexTimeout.matchesWithin(p, input, budgetMillis);
if (r == null) throw new RegexTimeout.RegexTimeoutException(budgetMillis);
return r;
}
}
@@ -0,0 +1,88 @@
package com.ankurm.regex;
import static org.junit.jupiter.api.Assertions.*;
import java.lang.reflect.Method;
import java.util.List;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
import org.junit.jupiter.api.Test;
class RegexClaimsTest {
@Test void namedGroupsAreNumberedInOrder() {
Matcher m = BasicsDemo.LOG.matcher("2026-03-14 ERROR disk full");
assertTrue(m.matches());
assertEquals("ERROR", m.group("level"));
assertEquals("ERROR", m.group(2));
assertEquals(2, m.namedGroups().get("level"));
}
@Test void matchesLookingAtFindDiffer() {
Pattern d = Pattern.compile("\\d+");
assertFalse(d.matcher("order-42").matches());
assertFalse(d.matcher("order-42").lookingAt());
assertTrue(d.matcher("order-42").find());
}
@Test void lookaroundsConsumeNothing() {
assertEquals("1,234,567", Pattern.compile("(?<=\\d)(?=(?:\\d{3})+$)").matcher("1234567").replaceAll(","));
Matcher m = Pattern.compile("\\d+(?=px)").matcher("120px");
assertTrue(m.find());
assertEquals("120", m.group());
}
@Test void lambdaReplacementIsStillParsedForDollar() {
Pattern tpl = Pattern.compile("\\$\\{(\\w+)}");
assertThrows(IndexOutOfBoundsException.class, () -> tpl.matcher("${c}").replaceAll(r -> "$5"));
assertEquals("$5", tpl.matcher("${c}").replaceAll(r -> Matcher.quoteReplacement("$5")));
assertEquals("10 USD", Pattern.compile("\\d+").matcher("5 USD")
.replaceAll(r -> String.valueOf(Integer.parseInt(r.group()) * 2)));
}
@Test void noTimeoutApiExistsOnPatternOrMatcher() {
for (Class<?> c : List.of(Pattern.class, Matcher.class))
for (Method m : c.getMethods())
assertFalse(m.getName().toLowerCase().contains("timeout"), c.getSimpleName() + "." + m.getName());
}
@Test void deadlineAbortsExponentialPattern() {
Pattern p = Pattern.compile("(?:(?:a+)+)+b");
long t0 = System.nanoTime();
assertNull(RegexTimeout.matchesWithin(p, "a".repeat(40) + "!", 300));
assertTrue((System.nanoTime() - t0) / 1_000_000 < 3000, "abort should come soon after the 300 ms budget");
}
@Test void backreferenceDisablesTheJdkOptimisation() {
// same nested quantifier; 40 chars is hopeless with a backreference, instant without
assertEquals(Boolean.FALSE, RegexTimeout.matchesWithin(Pattern.compile("(a+)+b"), "a".repeat(40) + "!", 1000));
assertNull(RegexTimeout.matchesWithin(Pattern.compile("(a+)+\\1?b"), "a".repeat(40) + "!", 300));
}
@Test void fixesAcceptTheSameLanguageOnShortInputs() {
String[] res = {"(?:(?:a+)+)+b", "a+b", "(?:a++)++b", "(?>(?:a+)+)b"};
for (String in : List.of("b", "ab", "aaab", "aaa", "aabb", "ba", ""))
for (String re : res)
assertEquals(Pattern.matches(res[0], in), Pattern.matches(re, in), re + " on '" + in + "'");
}
@Test void fixesFinishInstantlyOnHostileInput() {
String hostile = "a".repeat(40) + "!";
for (String re : new String[] {"a+b", "(?:a++)++b", "(?>(?:a+)+)b"})
assertEquals(Boolean.FALSE, RegexTimeout.matchesWithin(Pattern.compile(re), hostile, 1000), re);
}
@Test void lengthLimitRejectsBeforeMatching() {
assertThrows(IllegalArgumentException.class, () -> Safe.matches(Pattern.compile("a+b"), "a".repeat(101), 100, 500));
assertTrue(Safe.matches(Pattern.compile("a+b"), "aab", 100, 500));
assertThrows(RegexTimeout.RegexTimeoutException.class,
() -> Safe.matches(Pattern.compile("(?:(?:a+)+)+b"), "a".repeat(40) + "!", 100, 200));
}
@Test void alternationInLoopOverflowsTheStackButClassAndPossessiveDoNot() {
String s = "ab".repeat(10_000) + "c";
assertThrows(StackOverflowError.class, () -> Pattern.compile("(?:a|b)*c").matcher(s).matches());
assertTrue(Pattern.compile("[ab]*c").matcher(s).matches());
assertTrue(Pattern.compile("(?:a|b)*+c").matcher(s).matches());
}
}