mirror of
https://github.com/nlohmann/json.git
synced 2026-10-10 08:27:13 +00:00
Reject integer lengths in json_document::parse
parse(ptr, len) compiled: len converted to allow_exceptions, and ptr was read as a C string, past the end of a buffer without a terminating NUL. Delete the overloads of parse, parse_copy, accept, and read that take an integer other than bool where the flags are expected. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
7 files changed
+88
No files matched your search
@@ -43,6 +43,11 @@ input's own copy (for inputs that are always read into a buffer) throws.
|
||||
|
||||
Linear in the length of the input.
|
||||
|
||||
## Notes
|
||||
|
||||
An integer argument that is not a `#!cpp bool` where the flags are expected, such as `#!cpp accept(ptr, len)`, does not
|
||||
compile; see [`parse`](parse.md#notes).
|
||||
|
||||
## Examples
|
||||
|
||||
??? example
|
||||
|
||||
@@ -100,6 +100,12 @@ See [`owns_source`](owns_source.md) to check which happened after a call, and th
|
||||
**Numbers.** As for [`BasicJsonType::parse()`](../basic_json/parse.md), an integer literal too large for the 64-bit
|
||||
integer type becomes a floating-point value.
|
||||
|
||||
**No lengths.** An integer argument that is not a `#!cpp bool` where the flags are expected -- for example
|
||||
`#!cpp parse(ptr, len)` -- does not compile (the overload is deleted). Such a call would convert `len` to
|
||||
`allow_exceptions` and read `ptr` as a null-terminated string, past the end of a buffer that has none. To parse a
|
||||
buffer of a given length, pass a pair of pointers: `#!cpp parse(ptr, ptr + len)`. The same holds for
|
||||
[`parse_copy`](parse_copy.md), [`accept`](accept.md), and [`read`](read.md).
|
||||
|
||||
## Examples
|
||||
|
||||
??? example "Example: (1) borrowed vs. owned input, and errors identical to `BasicJsonType::parse()`"
|
||||
|
||||
@@ -51,6 +51,9 @@ Linear in the length of the input.
|
||||
only differs in that the input is always copied rather than sometimes borrowed. Prefer [`parse()`](parse.md) when the
|
||||
input's lifetime already covers the document's, since it avoids the copy for borrowed inputs.
|
||||
|
||||
An integer argument that is not a `#!cpp bool` where the flags are expected, such as `#!cpp parse_copy(ptr, len)`, does not
|
||||
compile; see [`parse`](parse.md#notes).
|
||||
|
||||
## Examples
|
||||
|
||||
??? example
|
||||
|
||||
@@ -49,6 +49,9 @@ whether or not the new parse succeeds; take fresh views from [`root()`](root.md)
|
||||
`input` is borrowed or owned by the same rules as [`parse()`](parse.md#notes); a document can borrow on one call and
|
||||
own on the next, since ownership is decided freshly each time.
|
||||
|
||||
An integer argument that is not a `#!cpp bool` where the flags are expected, such as `#!cpp read(ptr, len)`, does not
|
||||
compile; see [`parse`](parse.md#notes).
|
||||
|
||||
## Examples
|
||||
|
||||
??? example
|
||||
|
||||
@@ -59,6 +59,13 @@ struct classify_input
|
||||
// NOLINTEND(readability-avoid-nested-conditional-operator)
|
||||
};
|
||||
|
||||
/// an integer type other than bool: a length passed where a flag is expected
|
||||
template<typename T>
|
||||
struct is_integer_not_bool : std::is_integral<T> {};
|
||||
|
||||
template<>
|
||||
struct is_integer_not_bool<bool> : std::false_type {};
|
||||
|
||||
/// std::basic_string guarantees a NUL at data()[size()] (the parser's sentinel)
|
||||
template<typename T>
|
||||
struct is_std_string : std::false_type {};
|
||||
|
||||
@@ -291,6 +291,13 @@ class basic_json_document
|
||||
return d;
|
||||
}
|
||||
|
||||
/// parse(ptr, len) does not compile: len would convert to allow_exceptions
|
||||
/// and ptr be read as a C string (as for the overloads of parse_copy,
|
||||
/// accept, and read below)
|
||||
template<typename InputType, typename IntegerType, typename... Flags>
|
||||
static typename std::enable_if<detail::view::is_integer_not_bool<IntegerType>::value, basic_json_document>::type
|
||||
parse(InputType&& input, IntegerType value, Flags&&... flags) = delete;
|
||||
|
||||
/// parse [first, last)
|
||||
template<typename IteratorType, typename std::enable_if<
|
||||
std::is_base_of<std::input_iterator_tag, typename std::iterator_traits<IteratorType>::iterator_category>::value, int>::type = 0>
|
||||
@@ -318,6 +325,10 @@ class basic_json_document
|
||||
return d;
|
||||
}
|
||||
|
||||
template<typename InputType, typename IntegerType, typename... Flags>
|
||||
static typename std::enable_if<detail::view::is_integer_not_bool<IntegerType>::value, basic_json_document>::type
|
||||
parse_copy(InputType&& input, IntegerType value, Flags&&... flags) = delete;
|
||||
|
||||
/// check whether the input is valid JSON (the result of basic_json::accept)
|
||||
template<typename InputType>
|
||||
static bool accept(InputType&& input, const bool ignore_comments = false, const bool ignore_trailing_commas = false)
|
||||
@@ -327,6 +338,10 @@ class basic_json_document
|
||||
return !d.is_discarded();
|
||||
}
|
||||
|
||||
template<typename InputType, typename IntegerType, typename... Flags>
|
||||
static typename std::enable_if<detail::view::is_integer_not_bool<IntegerType>::value, bool>::type
|
||||
accept(InputType&& input, IntegerType value, Flags&&... flags) = delete;
|
||||
|
||||
/// parse into this document, reusing its memory
|
||||
template<typename InputType>
|
||||
// flawfinder: ignore (a member function, not POSIX read())
|
||||
@@ -339,6 +354,11 @@ class basic_json_document
|
||||
std::integral_constant<detail::view::input_kind, detail::view::classify_input<InputType>::value> {});
|
||||
}
|
||||
|
||||
template<typename InputType, typename IntegerType, typename... Flags>
|
||||
// flawfinder: ignore (a member function, not POSIX read())
|
||||
typename std::enable_if<detail::view::is_integer_not_bool<IntegerType>::value, void>::type
|
||||
read(InputType&& input, IntegerType value, Flags&&... flags) = delete;
|
||||
|
||||
////////////
|
||||
// access //
|
||||
////////////
|
||||
|
||||
@@ -15,12 +15,14 @@ using nlohmann::json_document;
|
||||
using nlohmann::json_view;
|
||||
using nlohmann::ordered_json_document;
|
||||
|
||||
#include <cstddef>
|
||||
#include <cstdint>
|
||||
#include <list>
|
||||
#include <map>
|
||||
#include <random>
|
||||
#include <sstream>
|
||||
#include <string>
|
||||
#include <type_traits>
|
||||
#include <utility>
|
||||
#include <vector>
|
||||
|
||||
@@ -30,6 +32,16 @@ using nlohmann::ordered_json_document;
|
||||
|
||||
namespace
|
||||
{
|
||||
// detection of calls that must not compile
|
||||
template<typename... Args>
|
||||
using parse_call_t = decltype(json_document::parse(std::declval<Args>()...));
|
||||
template<typename... Args>
|
||||
using parse_copy_call_t = decltype(json_document::parse_copy(std::declval<Args>()...));
|
||||
template<typename... Args>
|
||||
using accept_call_t = decltype(json_document::accept(std::declval<Args>()...));
|
||||
template<typename... Args>
|
||||
using read_call_t = decltype(std::declval<json_document&>().read(std::declval<Args>()...));
|
||||
|
||||
#if !defined(JSON_NOEXCEPTION)
|
||||
// the exception parse() throws for a text, or "" if it accepts it
|
||||
std::string parse_exception(const std::string& text, bool comments = false, bool trailing_commas = false)
|
||||
@@ -329,6 +341,38 @@ TEST_CASE("json_view")
|
||||
CHECK(json_document::parse("", false).is_discarded());
|
||||
}
|
||||
|
||||
SECTION("integer arguments do not compile")
|
||||
{
|
||||
using nlohmann::detail::is_detected;
|
||||
|
||||
// a length is not a flag: parse(ptr, len) would convert len to
|
||||
// allow_exceptions and read ptr as a C string, which need not end
|
||||
static_assert(is_detected<parse_call_t, const char*, bool>::value, "parse(ptr, bool) is valid");
|
||||
static_assert(is_detected<parse_call_t, const char*, bool, bool, bool>::value, "parse(ptr, bool, bool, bool) is valid");
|
||||
static_assert(is_detected<parse_call_t, const char*, const char*>::value, "parse(first, last) is valid");
|
||||
static_assert(is_detected<parse_call_t, const char*, const char*, bool>::value, "parse(first, last, bool) is valid");
|
||||
static_assert(!is_detected<parse_call_t, const char*, std::size_t>::value, "parse(ptr, len) must not compile");
|
||||
static_assert(!is_detected<parse_call_t, const char*, int>::value, "parse(ptr, int) must not compile");
|
||||
static_assert(!is_detected<parse_call_t, const char*, char>::value, "parse(ptr, char) must not compile");
|
||||
static_assert(!is_detected<parse_call_t, const char*, std::size_t, bool>::value, "parse(ptr, len, bool) must not compile");
|
||||
static_assert(!is_detected<parse_call_t, const std::string&, std::size_t>::value, "parse(string, len) must not compile");
|
||||
static_assert(!is_detected<parse_call_t, const std::vector<char>&, std::size_t>::value, "parse(vector, len) must not compile");
|
||||
|
||||
static_assert(is_detected<parse_copy_call_t, const char*, bool>::value, "parse_copy(ptr, bool) is valid");
|
||||
static_assert(!is_detected<parse_copy_call_t, const char*, std::size_t>::value, "parse_copy(ptr, len) must not compile");
|
||||
|
||||
static_assert(is_detected<accept_call_t, const char*, bool>::value, "accept(ptr, bool) is valid");
|
||||
static_assert(!is_detected<accept_call_t, const char*, std::size_t>::value, "accept(ptr, len) must not compile");
|
||||
|
||||
static_assert(is_detected<read_call_t, const char*, bool>::value, "read(ptr, bool) is valid");
|
||||
static_assert(!is_detected<read_call_t, const char*, std::size_t>::value, "read(ptr, len) must not compile");
|
||||
|
||||
// the valid calls still work
|
||||
const char* const text = "[1]";
|
||||
CHECK(json_document::parse(text, true).root().is_array());
|
||||
CHECK(json_document::accept(text, true, true));
|
||||
}
|
||||
|
||||
SECTION("document lifetime and reuse")
|
||||
{
|
||||
json_document d;
|
||||
|
||||
Reference in new issue
Block a user