Move to_bson's binary subtype check into calc_bson_sizes (#5703)

to_bson() rejected a binary value's subtype above 255 (out_of_range.415)
in write_bson_binary(), which only has the binary_t, not the basic_json
value that holds it, so the exception was created with no JSON_DIAGNOSTICS
context even though the equivalent to_msgpack() check names the value's
path. The check also ran after the document size, all preceding elements,
and this element's header and length had already reached the output
adapter, so a caller-provided std::vector or std::string ended up holding
a truncated document.

calc_bson_sizes() already walks every value before anything is written,
to size embedded documents and arrays and to reject invalid keys
(out_of_range.409) up front. The subtype check now runs there instead,
in calc_bson_binary_size(), which is given the basic_json value so the
exception can use it as context. The now-redundant check in
write_bson_binary() is removed, since calc_bson_sizes() always throws
first if any binary value in the document has an oversized subtype.

Fixes #5675.

Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
Niels Lohmann
2026-09-30 20:07:41 +02:00
committed by GitHub
parent 4bb1b14b06
commit 5bd766aa50
5 changed files with 66 additions and 17 deletions
@@ -1056,15 +1056,26 @@ class binary_writer
}
/*!
@return The size of the BSON-encoded binary array @a value
@return The size of the BSON-encoded binary array in @a j
@throw out_of_range.415 if the subtype of @a j does not fit into a byte,
before anything is written
*/
static std::size_t calc_bson_binary_size(const typename BasicJsonType::binary_t& value)
static std::size_t calc_bson_binary_size(const BasicJsonType& j)
{
const auto& value = *j.m_data.m_value.binary;
if (value.has_subtype() && JSON_HEDLEY_UNLIKELY(value.subtype() > (std::numeric_limits<std::uint8_t>::max)()))
{
JSON_THROW(out_of_range::create(415, concat("subtype ", std::to_string(value.subtype()), " is too large for the BSON binary subtype (max 255)"), &j));
}
return sizeof(std::int32_t) + value.size() + 1ul;
}
/*!
@brief Writes a BSON element with key @a name and binary value @a value
@pre @a value's subtype, if any, fits into a byte; @ref calc_bson_sizes
checks this for every binary value in the document beforehand.
*/
void write_bson_binary(const string_t& name,
const binary_t& value)
@@ -1073,11 +1084,6 @@ class binary_writer
write_number<std::int32_t>(to_bson_length(value.size()), true);
if (value.has_subtype() && JSON_HEDLEY_UNLIKELY(value.subtype() > (std::numeric_limits<std::uint8_t>::max)()))
{
JSON_THROW(out_of_range::create(415, concat("subtype ", std::to_string(value.subtype()), " is too large for the BSON binary subtype (max 255)"), nullptr));
}
write_number(value.has_subtype() ? static_cast<std::uint8_t>(value.subtype()) : static_cast<std::uint8_t>(0x00));
oa.write_characters(reinterpret_cast<const CharType*>(value.data()), value.size());
@@ -1086,13 +1092,15 @@ class binary_writer
/*!
@return The size of the value of the BSON document entry for @a j, which
is neither an object nor an array
@throw out_of_range.415 if @a j is binary with a subtype that does not fit
into a byte, before anything is written
*/
static std::size_t calc_bson_value_size(const BasicJsonType& j)
{
switch (j.type())
{
case value_t::binary:
return calc_bson_binary_size(*j.m_data.m_value.binary);
return calc_bson_binary_size(j);
case value_t::boolean:
return 1ul;
@@ -1218,6 +1226,8 @@ class binary_writer
@return the size of @a document
@throw out_of_range.409 if a key contains U+0000, before anything is
written
@throw out_of_range.415 if a binary value's subtype does not fit into a
byte, before anything is written
*/
static std::size_t calc_bson_sizes(const BasicJsonType& document, std::vector<std::size_t>& nested_sizes)
{