mirror of
https://github.com/nlohmann/json.git
synced 2026-09-06 08:17:59 +00:00
Honor allow_exceptions=false for excessive array/object size (out_of_range.408)
The SAX DOM parsers' start_object()/start_array() threw out_of_range.408 directly via JSON_THROW when a binary format (CBOR/UBJSON/BJData) declared a container size exceeding max_size(), bypassing the allow_exceptions flag that every other malformed-input error path in these classes honors via parse_error(). This meant that json::from_cbor(data, true, false) etc. could still throw (or abort under JSON_NOEXCEPTION) instead of returning a discarded value, contrary to the allow_exceptions=false contract. Route all four call sites (two in json_sax_dom_parser, two in json_sax_dom_callback_parser) through parse_error() instead, matching the existing error-handling pattern used elsewhere in this file. Behavior is unchanged when allow_exceptions is true (the default); the exception message and type are identical. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
@@ -1637,4 +1637,30 @@ TEST_CASE("regression test - parser callback must not lose a duplicate key's pri
|
||||
}
|
||||
}
|
||||
|
||||
TEST_CASE("regression test - excessive binary container size honors allow_exceptions=false")
|
||||
{
|
||||
// CBOR array with declared length 2^63
|
||||
const std::vector<std::uint8_t> cbor = {0x9b, 0x80, 0, 0, 0, 0, 0, 0, 0};
|
||||
// CBOR map with declared length 2^63
|
||||
const std::vector<std::uint8_t> cbor_m = {0xbb, 0x80, 0, 0, 0, 0, 0, 0, 0};
|
||||
// UBJSON array with declared length 2^63-1
|
||||
const std::vector<std::uint8_t> ubj = {'[', '#', 'L', 0x7f, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff};
|
||||
// BJData array with declared length 2^63-1 (little endian)
|
||||
const std::vector<std::uint8_t> bjd = {'[', '#', 'L', 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f};
|
||||
|
||||
// allow_exceptions=false must report failure instead of throwing/aborting
|
||||
CHECK(json::from_cbor(cbor, true, false).is_discarded());
|
||||
CHECK(json::from_cbor(cbor_m, true, false).is_discarded());
|
||||
CHECK(json::from_ubjson(ubj, true, false).is_discarded());
|
||||
CHECK(json::from_bjdata(bjd, true, false).is_discarded());
|
||||
|
||||
// allow_exceptions=true (the default) must still throw exactly as before
|
||||
CHECK_THROWS_AS(json::from_cbor(cbor), json::out_of_range);
|
||||
CHECK_THROWS_WITH(json::from_cbor(cbor),
|
||||
"[json.exception.out_of_range.408] excessive array size: 9223372036854775808");
|
||||
|
||||
// regression guard: a genuinely truncated CBOR input must remain discarded
|
||||
CHECK(json::from_cbor(std::vector<std::uint8_t> {0x9b, 0, 0, 0, 0, 0, 0, 0, 0x02}, true, false).is_discarded());
|
||||
}
|
||||
|
||||
DOCTEST_CLANG_SUPPRESS_WARNING_POP
|
||||
|
||||
Reference in New Issue
Block a user