Read the node array base after emit() in the view builder's open()

emit() moves the node array when it grows, and the subtraction read base
in the same expression, so the order was unspecified. MSVC Release builds
without forced inlining read the old base; the container index then
pointed outside the array and close() wrote out of bounds.

Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
Niels Lohmann committed 2026-10-11 10:27:56 +02:00
1 parent eeae3e9121
commit 10d36d3af2
1 file changed
+4 -1
+4 -1
View File
@@ -821,7 +821,10 @@ indent_done:
NLOHMANN_VIEW_ALWAYS_INLINE void open(value_t k)
{
const auto idx = static_cast<std::uint32_t>(emit(k, 0, 0, static_cast<std::size_t>(p - b), 0) - base);
// (base is read after emit(), which moves the node array when it
// grows; in one expression the order of the two is unspecified)
const node* const n = emit(k, 0, 0, static_cast<std::size_t>(p - b), 0);
const auto idx = static_cast<std::uint32_t>(n - base);
if (depth != 0)
{
const frame f = {cur_idx, cur_count, cur_is_object};