From fff87e22a219e74f79091b04c30c5af6eeb2d7ec Mon Sep 17 00:00:00 2001 From: elhoim Date: Mon, 31 Aug 2026 01:02:59 +0000 Subject: [PATCH] fix: [reversinglabs_spectra_analyze] parse dns child-key limit for obj:path branch The obj:path directive branch of _process_object_recursive derives its foreach limit by calling _parse_obj_key on the obj:path value (e.g. "last_dns_records[type=A,AAAA]"), but MAPPING_RULES encodes the per-field cap on the child object key instead (e.g. "dns-ips[10]"). Since the obj:path value never carries a numeric suffix, foreach_limit always stays at the parser's default (MAX_FOREACH_ITERATIONS), so the effective_limit fallback silently becomes MAX_DNS_CHILDREN (25) instead of the declared cap of 10, letting the dns-ips and dns-hostnames child objects grow far beyond what the mapping author intended. The fix parses child_key with _parse_obj_key as well and, when it yields an explicit limit, uses that as foreach_limit -- mirroring what the sibling foreach-key branch a few lines below already does. Verified with flake8 (clean) and the full pytest suite against a live misp-modules server on port 6770: 161 passed, 4 skipped, 5 subtests passed, matching the baseline. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_018dfYpyaSZd1nxSRLr8suj8 --- .../modules/expansion/reversinglabs_spectra_analyze.py | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/misp_modules/modules/expansion/reversinglabs_spectra_analyze.py b/misp_modules/modules/expansion/reversinglabs_spectra_analyze.py index 209be8e9..38b7c654 100644 --- a/misp_modules/modules/expansion/reversinglabs_spectra_analyze.py +++ b/misp_modules/modules/expansion/reversinglabs_spectra_analyze.py @@ -2539,6 +2539,11 @@ def _process_object_recursive( if not foreach_path: foreach_path = obj_path_value.strip() + # The limit is encoded on the child key (e.g. "dns-ips[10]"), not on obj:path + _, _, _, _, key_limit = _parse_obj_key(child_key) + if key_limit != MAX_FOREACH_ITERATIONS: + foreach_limit = key_limit + # Get the data at the path path_data = get_first(data, [foreach_path])