mirror of
https://github.com/nlohmann/json.git
synced 2026-09-11 10:48:01 +00:00
Make contains(json_pointer) return false instead of throwing on unrepresentable array-index tokens (#5495)
contains(const json_pointer&) is documented to never throw, but a purely numeric reference token that is syntactically a valid array index yet numerically too large to be represented (exceeding size_type's max, or exceeding ULLONG_MAX and causing strtoull() to set errno to ERANGE) made it fall through to array_index(), which throws out_of_range.410/404. Pre-check the token's magnitude the same way array_index() does, but return false instead of throwing, mirroring how the surrounding code already rejects other malformed tokens (leading zero, non-digit characters, "-") without throwing. operator[]/at() are untouched and keep throwing for these inputs. Fixes #5395 Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
@@ -748,6 +748,20 @@ class json_pointer
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// the reference token consists only of digits at this point (cf. checks
|
||||||
|
// above); however, its numeric value might not be representable, in which
|
||||||
|
// case array_index() would throw out_of_range.404/410 -- contains() must
|
||||||
|
// not throw (see #5395), so such a reference token is treated as "not found"
|
||||||
|
errno = 0; // strtoull() does not reset errno on success
|
||||||
|
char* p_end = nullptr; // NOLINT(misc-const-correctness)
|
||||||
|
const unsigned long long magnitude = std::strtoull(reference_token.c_str(), &p_end, 10); // NOLINT(runtime/int)
|
||||||
|
if (JSON_HEDLEY_UNLIKELY(errno == ERANGE // the value exceeds ULLONG_MAX
|
||||||
|
|| magnitude >= static_cast<unsigned long long>((std::numeric_limits<typename BasicJsonType::size_type>::max)()))) // NOLINT(runtime/int)
|
||||||
|
{
|
||||||
|
// the array index cannot be represented as size_type
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
const auto idx = array_index<BasicJsonType>(reference_token);
|
const auto idx = array_index<BasicJsonType>(reference_token);
|
||||||
if (idx >= ptr->size())
|
if (idx >= ptr->size())
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -16520,6 +16520,20 @@ class json_pointer
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// the reference token consists only of digits at this point (cf. checks
|
||||||
|
// above); however, its numeric value might not be representable, in which
|
||||||
|
// case array_index() would throw out_of_range.404/410 -- contains() must
|
||||||
|
// not throw (see #5395), so such a reference token is treated as "not found"
|
||||||
|
errno = 0; // strtoull() does not reset errno on success
|
||||||
|
char* p_end = nullptr; // NOLINT(misc-const-correctness)
|
||||||
|
const unsigned long long magnitude = std::strtoull(reference_token.c_str(), &p_end, 10); // NOLINT(runtime/int)
|
||||||
|
if (JSON_HEDLEY_UNLIKELY(errno == ERANGE // the value exceeds ULLONG_MAX
|
||||||
|
|| magnitude >= static_cast<unsigned long long>((std::numeric_limits<typename BasicJsonType::size_type>::max)()))) // NOLINT(runtime/int)
|
||||||
|
{
|
||||||
|
// the array index cannot be represented as size_type
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
const auto idx = array_index<BasicJsonType>(reference_token);
|
const auto idx = array_index<BasicJsonType>(reference_token);
|
||||||
if (idx >= ptr->size())
|
if (idx >= ptr->size())
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -319,6 +319,44 @@ TEST_CASE("JSON pointers")
|
|||||||
|
|
||||||
CHECK_THROWS_WITH_AS(j[jp] = 1, throw_msg.c_str(), json::out_of_range&);
|
CHECK_THROWS_WITH_AS(j[jp] = 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
CHECK_THROWS_WITH_AS(j_const[jp] == 1, throw_msg.c_str(), json::out_of_range&);
|
CHECK_THROWS_WITH_AS(j_const[jp] == 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
|
|
||||||
|
// #5395: contains() must not throw for a reference token that is a
|
||||||
|
// syntactically valid array index but numerically exceeds ULLONG_MAX
|
||||||
|
// (causing strtoull() to set errno to ERANGE) -- it should just report
|
||||||
|
// that the pointer does not resolve to an element
|
||||||
|
CHECK(!j.contains(jp));
|
||||||
|
CHECK(!j_const.contains(jp));
|
||||||
|
}
|
||||||
|
|
||||||
|
{
|
||||||
|
// #5395: same as above, but using the exact reproduction from the issue
|
||||||
|
json::json_pointer const jp("/99999999999999999999");
|
||||||
|
std::string const throw_msg = "[json.exception.out_of_range.404] unresolved reference token '99999999999999999999'";
|
||||||
|
|
||||||
|
CHECK_THROWS_WITH_AS(j[jp] = 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
|
CHECK_THROWS_WITH_AS(j_const[jp] == 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
|
CHECK_THROWS_WITH_AS(j.at(jp) = 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
|
CHECK_THROWS_WITH_AS(j_const.at(jp) == 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
|
|
||||||
|
CHECK(!j.contains(jp));
|
||||||
|
CHECK(!j_const.contains(jp));
|
||||||
|
}
|
||||||
|
|
||||||
|
{
|
||||||
|
// #5395: a reference token that is numerically representable in
|
||||||
|
// unsigned long long but exceeds size_type's max (e.g. ULLONG_MAX
|
||||||
|
// itself on typical 64-bit platforms, where size_type's max equals
|
||||||
|
// ULLONG_MAX) must not make contains() throw either
|
||||||
|
json::json_pointer const jp("/18446744073709551615");
|
||||||
|
std::string const throw_msg = "[json.exception.out_of_range.410] array index 18446744073709551615 exceeds size_type";
|
||||||
|
|
||||||
|
CHECK_THROWS_WITH_AS(j[jp] = 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
|
CHECK_THROWS_WITH_AS(j_const[jp] == 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
|
CHECK_THROWS_WITH_AS(j.at(jp) = 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
|
CHECK_THROWS_WITH_AS(j_const.at(jp) == 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
|
|
||||||
|
CHECK(!j.contains(jp));
|
||||||
|
CHECK(!j_const.contains(jp));
|
||||||
}
|
}
|
||||||
|
|
||||||
// on some machines, the check below is not constant
|
// on some machines, the check below is not constant
|
||||||
@@ -334,6 +372,10 @@ TEST_CASE("JSON pointers")
|
|||||||
|
|
||||||
CHECK_THROWS_WITH_AS(j[jp] = 1, throw_msg.c_str(), json::out_of_range&);
|
CHECK_THROWS_WITH_AS(j[jp] = 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
CHECK_THROWS_WITH_AS(j_const[jp] == 1, throw_msg.c_str(), json::out_of_range&);
|
CHECK_THROWS_WITH_AS(j_const[jp] == 1, throw_msg.c_str(), json::out_of_range&);
|
||||||
|
|
||||||
|
// #5395: contains() must not throw for a reference token exceeding size_type's max
|
||||||
|
CHECK(!j.contains(jp));
|
||||||
|
CHECK(!j_const.contains(jp));
|
||||||
}
|
}
|
||||||
|
|
||||||
DOCTEST_MSVC_SUPPRESS_WARNING_POP
|
DOCTEST_MSVC_SUPPRESS_WARNING_POP
|
||||||
|
|||||||
Reference in New Issue
Block a user