Compare commits

..
Author SHA1 Message Date
Niels Lohmann 46b04c6024 Move to_bson's binary subtype check into calc_bson_sizes
to_bson() rejected a binary value's subtype above 255 (out_of_range.415)
in write_bson_binary(), which only has the binary_t, not the basic_json
value that holds it, so the exception was created with no JSON_DIAGNOSTICS
context even though the equivalent to_msgpack() check names the value's
path. The check also ran after the document size, all preceding elements,
and this element's header and length had already reached the output
adapter, so a caller-provided std::vector or std::string ended up holding
a truncated document.

calc_bson_sizes() already walks every value before anything is written,
to size embedded documents and arrays and to reject invalid keys
(out_of_range.409) up front. The subtype check now runs there instead,
in calc_bson_binary_size(), which is given the basic_json value so the
exception can use it as context. The now-redundant check in
write_bson_binary() is removed, since calc_bson_sizes() always throws
first if any binary value in the document has an oversized subtype.

Fixes #5675.

Signed-off-by: Niels Lohmann <mail@nlohmann.me>
2026-09-29 23:43:56 +02:00
7 changed files with 68 additions and 85 deletions
@@ -43,6 +43,9 @@ Strong guarantee: if an exception is thrown, there are no changes in the JSON va
- Throws [`out_of_range.412`](../../home/exceptions.md#jsonexceptionout_of_range412) if the length of a document, array,
string, or binary value exceeds the range of the 32-bit BSON length field; example:
`"BSON length 2147483661 exceeds maximum of 2147483647"`
- Throws [`out_of_range.415`](../../home/exceptions.md#jsonexceptionout_of_range415) if the subtype of a binary value
exceeds 255, the maximum of the BSON binary subtype; example:
`"subtype 70000 is too large for the BSON binary subtype (max 255)"`
## Complexity
@@ -78,3 +81,4 @@ pass before anything is written.
- Added in version 3.4.0.
- Linear in the size of `j`, and no longer limited by the call stack for deeply nested values, since version 3.13.0.
- `out_of_range.415` is now detected before anything is written, like the other exceptions above, since version 3.13.0.
@@ -1055,15 +1055,26 @@ class binary_writer
}
/*!
@return The size of the BSON-encoded binary array @a value
@return The size of the BSON-encoded binary array in @a j
@throw out_of_range.415 if the subtype of @a j does not fit into a byte,
before anything is written
*/
static std::size_t calc_bson_binary_size(const typename BasicJsonType::binary_t& value)
static std::size_t calc_bson_binary_size(const BasicJsonType& j)
{
const auto& value = *j.m_data.m_value.binary;
if (value.has_subtype() && JSON_HEDLEY_UNLIKELY(value.subtype() > (std::numeric_limits<std::uint8_t>::max)()))
{
JSON_THROW(out_of_range::create(415, concat("subtype ", std::to_string(value.subtype()), " is too large for the BSON binary subtype (max 255)"), &j));
}
return sizeof(std::int32_t) + value.size() + 1ul;
}
/*!
@brief Writes a BSON element with key @a name and binary value @a value
@pre @a value's subtype, if any, fits into a byte; @ref calc_bson_sizes
checks this for every binary value in the document beforehand.
*/
void write_bson_binary(const string_t& name,
const binary_t& value)
@@ -1072,11 +1083,6 @@ class binary_writer
write_number<std::int32_t>(to_bson_length(value.size()), true);
if (value.has_subtype() && JSON_HEDLEY_UNLIKELY(value.subtype() > (std::numeric_limits<std::uint8_t>::max)()))
{
JSON_THROW(out_of_range::create(415, concat("subtype ", std::to_string(value.subtype()), " is too large for the BSON binary subtype (max 255)"), nullptr));
}
write_number(value.has_subtype() ? static_cast<std::uint8_t>(value.subtype()) : static_cast<std::uint8_t>(0x00));
oa.write_characters(reinterpret_cast<const CharType*>(value.data()), value.size());
@@ -1085,13 +1091,15 @@ class binary_writer
/*!
@return The size of the value of the BSON document entry for @a j, which
is neither an object nor an array
@throw out_of_range.415 if @a j is binary with a subtype that does not fit
into a byte, before anything is written
*/
static std::size_t calc_bson_value_size(const BasicJsonType& j)
{
switch (j.type())
{
case value_t::binary:
return calc_bson_binary_size(*j.m_data.m_value.binary);
return calc_bson_binary_size(j);
case value_t::boolean:
return 1ul;
@@ -1217,6 +1225,8 @@ class binary_writer
@return the size of @a document
@throw out_of_range.409 if a key contains U+0000, before anything is
written
@throw out_of_range.415 if a binary value's subtype does not fit into a
byte, before anything is written
*/
static std::size_t calc_bson_sizes(const BasicJsonType& document, std::vector<std::size_t>& nested_sizes)
{
+1 -8
View File
@@ -6187,14 +6187,7 @@ class basic_json // NOLINT(cppcoreguidelines-special-member-functions,hicpp-spec
}
}
// Only an object type that keeps its members in insertion
// order, such as nlohmann::ordered_map, can need reordering:
// patch() appends a new member at the end of such an object.
// Any other object type places its members itself - std::map
// in key order, a hash map in an order its operator== ignores -
// so a member-by-member diff always reproduces target there.
if (!detail::is_ordered_map<object_t>::value
|| (common_keys_source_order == common_keys_target_order && new_keys_form_suffix))
if (common_keys_source_order == common_keys_target_order && new_keys_form_suffix)
{
// fast path: order of common keys already matches (or the
// object_t's iteration order does not depend on
+19 -16
View File
@@ -21385,15 +21385,26 @@ class binary_writer
}
/*!
@return The size of the BSON-encoded binary array @a value
@return The size of the BSON-encoded binary array in @a j
@throw out_of_range.415 if the subtype of @a j does not fit into a byte,
before anything is written
*/
static std::size_t calc_bson_binary_size(const typename BasicJsonType::binary_t& value)
static std::size_t calc_bson_binary_size(const BasicJsonType& j)
{
const auto& value = *j.m_data.m_value.binary;
if (value.has_subtype() && JSON_HEDLEY_UNLIKELY(value.subtype() > (std::numeric_limits<std::uint8_t>::max)()))
{
JSON_THROW(out_of_range::create(415, concat("subtype ", std::to_string(value.subtype()), " is too large for the BSON binary subtype (max 255)"), &j));
}
return sizeof(std::int32_t) + value.size() + 1ul;
}
/*!
@brief Writes a BSON element with key @a name and binary value @a value
@pre @a value's subtype, if any, fits into a byte; @ref calc_bson_sizes
checks this for every binary value in the document beforehand.
*/
void write_bson_binary(const string_t& name,
const binary_t& value)
@@ -21402,11 +21413,6 @@ class binary_writer
write_number<std::int32_t>(to_bson_length(value.size()), true);
if (value.has_subtype() && JSON_HEDLEY_UNLIKELY(value.subtype() > (std::numeric_limits<std::uint8_t>::max)()))
{
JSON_THROW(out_of_range::create(415, concat("subtype ", std::to_string(value.subtype()), " is too large for the BSON binary subtype (max 255)"), nullptr));
}
write_number(value.has_subtype() ? static_cast<std::uint8_t>(value.subtype()) : static_cast<std::uint8_t>(0x00));
oa.write_characters(reinterpret_cast<const CharType*>(value.data()), value.size());
@@ -21415,13 +21421,15 @@ class binary_writer
/*!
@return The size of the value of the BSON document entry for @a j, which
is neither an object nor an array
@throw out_of_range.415 if @a j is binary with a subtype that does not fit
into a byte, before anything is written
*/
static std::size_t calc_bson_value_size(const BasicJsonType& j)
{
switch (j.type())
{
case value_t::binary:
return calc_bson_binary_size(*j.m_data.m_value.binary);
return calc_bson_binary_size(j);
case value_t::boolean:
return 1ul;
@@ -21547,6 +21555,8 @@ class binary_writer
@return the size of @a document
@throw out_of_range.409 if a key contains U+0000, before anything is
written
@throw out_of_range.415 if a binary value's subtype does not fit into a
byte, before anything is written
*/
static std::size_t calc_bson_sizes(const BasicJsonType& document, std::vector<std::size_t>& nested_sizes)
{
@@ -32268,14 +32278,7 @@ class basic_json // NOLINT(cppcoreguidelines-special-member-functions,hicpp-spec
}
}
// Only an object type that keeps its members in insertion
// order, such as nlohmann::ordered_map, can need reordering:
// patch() appends a new member at the end of such an object.
// Any other object type places its members itself - std::map
// in key order, a hash map in an order its operator== ignores -
// so a member-by-member diff always reproduces target there.
if (!detail::is_ordered_map<object_t>::value
|| (common_keys_source_order == common_keys_target_order && new_keys_form_suffix))
if (common_keys_source_order == common_keys_target_order && new_keys_form_suffix)
{
// fast path: order of common keys already matches (or the
// object_t's iteration order does not depend on
+20 -1
View File
@@ -797,7 +797,11 @@ TEST_CASE("regression test - BSON binary subtype rejects a value that doesn't fi
CHECK(json::from_bson(json::to_bson(doc255))["b"].get_binary().subtype() == 255);
CHECK_THROWS_AS(json::to_bson(json{{"b", json::binary({1, 2}, 256)}}), json::out_of_range);
CHECK_THROWS_WITH_AS(json::to_bson(json{{"b", json::binary({1, 2}, 300)}}), "[json.exception.out_of_range.415] subtype 300 is too large for the BSON binary subtype (max 255)", json::out_of_range);
#if JSON_DIAGNOSTICS
CHECK_THROWS_WITH_AS(json::to_bson(json {{"b", json::binary({1, 2}, 300)}}), "[json.exception.out_of_range.415] (/b) subtype 300 is too large for the BSON binary subtype (max 255)", json::out_of_range);
#else
CHECK_THROWS_WITH_AS(json::to_bson(json {{"b", json::binary({1, 2}, 300)}}), "[json.exception.out_of_range.415] subtype 300 is too large for the BSON binary subtype (max 255)", json::out_of_range);
#endif
}
TEST_CASE("BSON input/output_adapters")
@@ -1805,6 +1809,21 @@ value = depth % 2 == 0 ? json{{"a", std::move(value)}, {"b", {1, "x"}}} :
CHECK(output.empty());
}
SECTION("a binary subtype that doesn't fit a byte is rejected before anything is written (#5675)")
{
// the offending value is nested, so this also covers that the check
// is not limited to a directly written value's own document
json const j = {{"a", {{"b", json::binary({1, 2}, 300)}}}};
std::vector<std::uint8_t> vector_output;
CHECK_THROWS_AS(json::to_bson(j, vector_output), json::out_of_range&);
CHECK(vector_output.empty());
std::string string_output;
CHECK_THROWS_AS(json::to_bson(j, string_output), json::out_of_range&);
CHECK(string_output.empty());
}
SECTION("values nested too deeply for the call stack (#5392)")
{
// serializing recursed once per nesting level, and computed every
+6
View File
@@ -101,6 +101,12 @@ TEST_CASE("Regression tests for extended diagnostics")
CHECK_THROWS_WITH_AS(j.unflatten(), "[json.exception.type_error.315] (/~1foo) values in object must be primitive", json::type_error);
}
SECTION("Regression test for issue #5675 - to_bson: out_of_range.415 has no diagnostics context")
{
json const j = {{"a", {{"b", json::binary({1, 2}, 300)}}}};
CHECK_THROWS_WITH_AS(json::to_bson(j), "[json.exception.out_of_range.415] (/a/b) subtype 300 is too large for the BSON binary subtype (max 255)", json::out_of_range);
}
SECTION("Regression test for issue #2838 - Assertion failure when inserting into arrays with JSON_DIAGNOSTICS set")
{
// void push_back(basic_json&& val)
-52
View File
@@ -1752,58 +1752,6 @@ TEST_CASE("JSON patch - diff emits array removals in descending index order")
}
}
TEST_CASE("JSON patch - diff() takes the fast path for non-reorderable object types (regression #5639)")
{
// #5465 added an order check to diff()'s object handling so a
// member-by-member diff is only used when it would also reproduce
// target's member *order* -- needed for ordered_json, whose object_t
// keeps insertion order and whose patch() "add" op appends a new
// member at the end. For json's default object_t (std::map, which
// orders members by key regardless of insertion history), that check
// could still fail: a new key that sorts before an existing common key
// makes target's iteration interleave the new key between common keys,
// even though nothing else about the object changed. That sent the
// whole object through the slow (remove-every-member,
// re-add-every-member) path instead of the minimal one.
SECTION("json: added key sorts before an existing common key")
{
const json source = {{"a", 1}, {"c", {{"x", 1}, {"y", 2}}}};
const json target = {{"a", 1}, {"b", 0}, {"c", {{"x", 1}, {"y", 2}}}};
const json patch = json::diff(source, target);
// only the new key is added; "a" and "c" are left alone instead of
// being removed and re-added
const json expected = R"([{"op": "add", "path": "/b", "value": 0}])"_json;
CHECK(patch == expected);
CHECK(source.patch(patch) == target);
}
SECTION("ordered_json: reordering behavior from #5465 is unchanged")
{
using nlohmann::ordered_json;
// same key/value shape as the json case above, but for ordered_json
// the *target*'s member order must be reproduced, so the slow path
// is still required here.
ordered_json source;
source["a"] = 1;
source["c"] = ordered_json{{"x", 1}, {"y", 2}};
ordered_json target;
target["a"] = 1;
target["b"] = 0;
target["c"] = ordered_json{{"x", 1}, {"y", 2}};
const ordered_json patch = ordered_json::diff(source, target);
// unlike the json case: every member is still removed and re-added
// so the result ends up in target's order (2 removes + 3 adds)
CHECK(patch.size() == 5);
CHECK(source.patch(patch) == target);
}
}
TEST_CASE("JSON patch - every operation on ordered_json")
{
using nlohmann::ordered_json;