mirror of
https://github.com/nlohmann/json.git
synced 2026-09-07 00:37:58 +00:00
Reject array insert(pos, first, last) iterators not pointing into an array
The array-range insert() overload checked that pos fits the current value and that first/last share the same owning value, but never verified that value is itself an array. Passing iterators from an object, a primitive, or null handed value-initialized (singular) std::vector iterators straight to array_t::insert(), which is undefined behavior. Add the missing is_array() check, mirroring the equivalent check already present in the object-range insert() overload. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
@@ -88,6 +88,8 @@ Strong exception safety: if an exception occurs, the original value stays intact
|
|||||||
do not belong to the same JSON value; example: `"iterators do not fit"`
|
do not belong to the same JSON value; example: `"iterators do not fit"`
|
||||||
- Throws [`invalid_iterator.211`](../../home/exceptions.md#jsonexceptioninvalid_iterator211) if `first` or `last`
|
- Throws [`invalid_iterator.211`](../../home/exceptions.md#jsonexceptioninvalid_iterator211) if `first` or `last`
|
||||||
are iterators into container for which insert is called; example: `"passed iterators may not belong to container"`
|
are iterators into container for which insert is called; example: `"passed iterators may not belong to container"`
|
||||||
|
- Throws [`invalid_iterator.202`](../../home/exceptions.md#jsonexceptioninvalid_iterator202) if `first` or `last`
|
||||||
|
do not point to an array; example: `"iterators first and last must point to arrays"`
|
||||||
4. The function can throw the following exceptions:
|
4. The function can throw the following exceptions:
|
||||||
- Throws [`type_error.309`](../../home/exceptions.md#jsonexceptiontype_error309) if called on JSON values other than
|
- Throws [`type_error.309`](../../home/exceptions.md#jsonexceptiontype_error309) if called on JSON values other than
|
||||||
arrays; example: `"cannot use insert() with string"`
|
arrays; example: `"cannot use insert() with string"`
|
||||||
|
|||||||
@@ -3425,6 +3425,12 @@ class basic_json // NOLINT(cppcoreguidelines-special-member-functions,hicpp-spec
|
|||||||
JSON_THROW(invalid_iterator::create(211, "passed iterators may not belong to container", this));
|
JSON_THROW(invalid_iterator::create(211, "passed iterators may not belong to container", this));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// passed iterators must belong to arrays
|
||||||
|
if (JSON_HEDLEY_UNLIKELY(!first.m_object->is_array()))
|
||||||
|
{
|
||||||
|
JSON_THROW(invalid_iterator::create(202, "iterators first and last must point to arrays", this));
|
||||||
|
}
|
||||||
|
|
||||||
// insert to array and return iterator
|
// insert to array and return iterator
|
||||||
return insert_iterator(pos, first.m_it.array_iterator, last.m_it.array_iterator);
|
return insert_iterator(pos, first.m_it.array_iterator, last.m_it.array_iterator);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -24932,6 +24932,12 @@ class basic_json // NOLINT(cppcoreguidelines-special-member-functions,hicpp-spec
|
|||||||
JSON_THROW(invalid_iterator::create(211, "passed iterators may not belong to container", this));
|
JSON_THROW(invalid_iterator::create(211, "passed iterators may not belong to container", this));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// passed iterators must belong to arrays
|
||||||
|
if (JSON_HEDLEY_UNLIKELY(!first.m_object->is_array()))
|
||||||
|
{
|
||||||
|
JSON_THROW(invalid_iterator::create(202, "iterators first and last must point to arrays", this));
|
||||||
|
}
|
||||||
|
|
||||||
// insert to array and return iterator
|
// insert to array and return iterator
|
||||||
return insert_iterator(pos, first.m_it.array_iterator, last.m_it.array_iterator);
|
return insert_iterator(pos, first.m_it.array_iterator, last.m_it.array_iterator);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -641,6 +641,20 @@ TEST_CASE("modifiers")
|
|||||||
CHECK_THROWS_WITH_AS(j_array.insert(j_array.end(), j_other_array.begin(), j_other_array2.end()), "[json.exception.invalid_iterator.210] iterators do not fit",
|
CHECK_THROWS_WITH_AS(j_array.insert(j_array.end(), j_other_array.begin(), j_other_array2.end()), "[json.exception.invalid_iterator.210] iterators do not fit",
|
||||||
json::invalid_iterator&);
|
json::invalid_iterator&);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
SECTION("iterators not pointing into an array")
|
||||||
|
{
|
||||||
|
json j_object2 = {{"k", 1}, {"l", 2}};
|
||||||
|
json j_primitive = 5;
|
||||||
|
json j_null;
|
||||||
|
|
||||||
|
CHECK_THROWS_WITH_AS(j_array.insert(j_array.begin(), j_object2.begin(), j_object2.end()), "[json.exception.invalid_iterator.202] iterators first and last must point to arrays",
|
||||||
|
json::invalid_iterator&);
|
||||||
|
CHECK_THROWS_WITH_AS(j_array.insert(j_array.begin(), j_primitive.begin(), j_primitive.end()), "[json.exception.invalid_iterator.202] iterators first and last must point to arrays",
|
||||||
|
json::invalid_iterator&);
|
||||||
|
CHECK_THROWS_WITH_AS(j_array.insert(j_array.begin(), j_null.begin(), j_null.end()), "[json.exception.invalid_iterator.202] iterators first and last must point to arrays",
|
||||||
|
json::invalid_iterator&);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
SECTION("range for object")
|
SECTION("range for object")
|
||||||
|
|||||||
Reference in New Issue
Block a user