Compare commits

..
Author SHA1 Message Date
Niels LohmannandClaude Sonnet 5 80475865c0 Fix std::terminate and null pointer access in input_stream_adapter
Parsing from a std::istream crashed in two unusual but valid stream
states, both in input_stream_adapter:

- With eofbit in the stream's exceptions() mask, get_character() sets
  eofbit via is->clear(), which throws std::ios_base::failure. While
  that exception unwinds, ~input_stream_adapter() called clear() again
  to reset eofbit, which is still set and still in the exception mask,
  so it throws a second time out of the (implicitly noexcept)
  destructor and std::terminate() is called. The destructor now only
  calls clear() if a bit other than eofbit remains set, so the first
  exception can propagate normally.
- For an std::istream without a stream buffer (rdbuf() == nullptr,
  e.g. std::istream(nullptr)), the constructor stored the null
  pointer without checking it, and get_character() dereferenced it.
  input_adapter(std::istream&) now throws parse_error.101 for such a
  stream, the same as it already does for a null FILE* or char*.

Added regression tests to unit-deserialization.cpp and, for the
JSON_PRECISE_STREAM_POSITION variant of get_character(), to
unit-precise-stream-position.cpp; both crashed before this fix.
Documented the two exceptions in parse.md and operator_gtgt.md.

Fixes #5646.

Signed-off-by: Niels Lohmann <mail@nlohmann.me>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-29 23:40:41 +02:00
9 changed files with 118 additions and 84 deletions
+8 -1
View File
@@ -88,7 +88,12 @@ Strong guarantee: if an exception is thrown, there are no changes in the JSON va
## Exceptions
- Throws [`parse_error.101`](../../home/exceptions.md#jsonexceptionparse_error101) in case of an unexpected token, or
empty input like a null `FILE*` or `char*` pointer.
empty input like a null `FILE*` or `char*` pointer, or an `std::istream` without a stream buffer
(`#!cpp i.rdbuf() == nullptr`, for instance `#!cpp std::istream(nullptr)`).
- If reading from an `std::istream` reaches the end of the input and `eofbit` is part of the stream's
[`exceptions()`](https://en.cppreference.com/w/cpp/io/basic_ios/exceptions) mask, the `std::ios_base::failure`
thrown by the stream itself propagates instead of a `parse_error`, the same as it would for the standard library's
own extraction operators.
## Complexity
@@ -254,6 +259,8 @@ outside of a string, invalid) byte; see the [FAQ entry](../../home/faq.md#nul-by
- Extended overload (2) to accept heterogeneous iterator+sentinel pairs (C++20 ranges support) in version 3.13.0.
- `JSON_STRICT_NUL_HANDLING` added in version 3.13.0 to optionally reject a NUL byte in the input instead of treating
it as end of input; planned to become the default in version 4.0.0.
- Extended empty-input detection to also cover an `std::istream` without a stream buffer, and fixed a crash
(`std::terminate`) when parsing from an `std::istream` with `eofbit` in its exception mask, in version 3.13.0.
!!! warning "Deprecation"
@@ -76,6 +76,3 @@ Linear in the size of the JSON value `j`.
- Added in version 2.0.9.
- Throws `out_of_range.412` and `out_of_range.415` since version 3.13.0.
- Fixed in version 3.13.0 to serialize `number_integer_t`/`number_unsigned_t` pairs of different width correctly;
before, integers could be serialized with the wrong value if `number_integer_t` was narrower than
`number_unsigned_t`.
+8 -1
View File
@@ -20,7 +20,12 @@ the stream `i`
## Exceptions
- Throws [`parse_error.101`](../home/exceptions.md#jsonexceptionparse_error101) in case of an unexpected token.
- Throws [`parse_error.101`](../home/exceptions.md#jsonexceptionparse_error101) in case of an unexpected token, or if
`i` has no stream buffer (`#!cpp i.rdbuf() == nullptr`, for instance `#!cpp std::istream(nullptr)`).
- If reading from `i` reaches the end of the input and `eofbit` is part of `i`'s
[`exceptions()`](https://en.cppreference.com/w/cpp/io/basic_ios/exceptions) mask, the `std::ios_base::failure`
thrown by `i` itself propagates instead of a `parse_error`, the same as it would for the standard library's own
extraction operators.
## Complexity
@@ -118,3 +123,5 @@ being read.
it as end of input; planned to become the default in version 4.0.0.
- `JSON_PRECISE_STREAM_POSITION` added in version 3.13.0 to optionally leave the character that terminates a number in
the stream; planned to become the default in version 4.0.0.
- Fixed a null pointer dereference for an `std::istream` without a stream buffer (now throws `parse_error.101`), and a
crash (`std::terminate`) when `i` has `eofbit` in its exception mask, in version 3.13.0.
@@ -106,7 +106,13 @@ class input_stream_adapter
// was given back with release_lookahead()
commit_lookahead();
#endif
is->clear(is->rdstate() & std::ios::eofbit);
// only call clear() if there is something to clear: it throws
// std::ios_base::failure if the stream has exceptions() enabled
// for a state bit that remains set, and a destructor must not throw
if ((is->rdstate() & ~std::ios::eofbit) != 0)
{
is->clear(is->rdstate() & std::ios::eofbit);
}
}
}
@@ -811,12 +817,16 @@ inline file_input_adapter input_adapter(std::FILE* file)
inline input_stream_adapter input_adapter(std::istream& stream)
{
if (stream.rdbuf() == nullptr)
{
JSON_THROW(parse_error::create(101, 0, "attempting to parse an empty input; check that your input string or stream contains the expected JSON", nullptr));
}
return input_stream_adapter(stream);
}
inline input_stream_adapter input_adapter(std::istream&& stream)
{
return input_stream_adapter(stream);
return input_adapter(stream);
}
#endif // JSON_NO_IO
@@ -337,24 +337,24 @@ class binary_writer
// MessagePack does not differentiate between positive
// signed integers and unsigned integers. Therefore, we used
// the code from the value_t::number_unsigned case here.
if (static_cast<typename BasicJsonType::number_unsigned_t>(j.m_data.m_value.number_integer) < 128)
if (j.m_data.m_value.number_unsigned < 128)
{
// positive fixnum
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_integer));
}
else if (static_cast<typename BasicJsonType::number_unsigned_t>(j.m_data.m_value.number_integer) <= (std::numeric_limits<std::uint8_t>::max)())
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint8_t>::max)())
{
// uint 8
oa.write_character(to_char_type(0xCC));
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_integer));
}
else if (static_cast<typename BasicJsonType::number_unsigned_t>(j.m_data.m_value.number_integer) <= (std::numeric_limits<std::uint16_t>::max)())
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint16_t>::max)())
{
// uint 16
oa.write_character(to_char_type(0xCD));
write_number(static_cast<std::uint16_t>(j.m_data.m_value.number_integer));
}
else if (static_cast<typename BasicJsonType::number_unsigned_t>(j.m_data.m_value.number_integer) <= (std::numeric_limits<std::uint32_t>::max)())
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint32_t>::max)())
{
// uint 32
oa.write_character(to_char_type(0xCE));
@@ -410,31 +410,31 @@ class binary_writer
if (j.m_data.m_value.number_unsigned < 128)
{
// positive fixnum
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_unsigned));
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_integer));
}
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint8_t>::max)())
{
// uint 8
oa.write_character(to_char_type(0xCC));
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_unsigned));
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_integer));
}
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint16_t>::max)())
{
// uint 16
oa.write_character(to_char_type(0xCD));
write_number(static_cast<std::uint16_t>(j.m_data.m_value.number_unsigned));
write_number(static_cast<std::uint16_t>(j.m_data.m_value.number_integer));
}
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint32_t>::max)())
{
// uint 32
oa.write_character(to_char_type(0xCE));
write_number(static_cast<std::uint32_t>(j.m_data.m_value.number_unsigned));
write_number(static_cast<std::uint32_t>(j.m_data.m_value.number_integer));
}
else
{
// uint 64
oa.write_character(to_char_type(0xCF));
write_number(static_cast<std::uint64_t>(j.m_data.m_value.number_unsigned));
write_number(static_cast<std::uint64_t>(j.m_data.m_value.number_integer));
}
break;
}
+21 -11
View File
@@ -7650,7 +7650,13 @@ class input_stream_adapter
// was given back with release_lookahead()
commit_lookahead();
#endif
is->clear(is->rdstate() & std::ios::eofbit);
// only call clear() if there is something to clear: it throws
// std::ios_base::failure if the stream has exceptions() enabled
// for a state bit that remains set, and a destructor must not throw
if ((is->rdstate() & ~std::ios::eofbit) != 0)
{
is->clear(is->rdstate() & std::ios::eofbit);
}
}
}
@@ -8355,12 +8361,16 @@ inline file_input_adapter input_adapter(std::FILE* file)
inline input_stream_adapter input_adapter(std::istream& stream)
{
if (stream.rdbuf() == nullptr)
{
JSON_THROW(parse_error::create(101, 0, "attempting to parse an empty input; check that your input string or stream contains the expected JSON", nullptr));
}
return input_stream_adapter(stream);
}
inline input_stream_adapter input_adapter(std::istream&& stream)
{
return input_stream_adapter(stream);
return input_adapter(stream);
}
#endif // JSON_NO_IO
@@ -20667,24 +20677,24 @@ class binary_writer
// MessagePack does not differentiate between positive
// signed integers and unsigned integers. Therefore, we used
// the code from the value_t::number_unsigned case here.
if (static_cast<typename BasicJsonType::number_unsigned_t>(j.m_data.m_value.number_integer) < 128)
if (j.m_data.m_value.number_unsigned < 128)
{
// positive fixnum
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_integer));
}
else if (static_cast<typename BasicJsonType::number_unsigned_t>(j.m_data.m_value.number_integer) <= (std::numeric_limits<std::uint8_t>::max)())
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint8_t>::max)())
{
// uint 8
oa.write_character(to_char_type(0xCC));
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_integer));
}
else if (static_cast<typename BasicJsonType::number_unsigned_t>(j.m_data.m_value.number_integer) <= (std::numeric_limits<std::uint16_t>::max)())
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint16_t>::max)())
{
// uint 16
oa.write_character(to_char_type(0xCD));
write_number(static_cast<std::uint16_t>(j.m_data.m_value.number_integer));
}
else if (static_cast<typename BasicJsonType::number_unsigned_t>(j.m_data.m_value.number_integer) <= (std::numeric_limits<std::uint32_t>::max)())
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint32_t>::max)())
{
// uint 32
oa.write_character(to_char_type(0xCE));
@@ -20740,31 +20750,31 @@ class binary_writer
if (j.m_data.m_value.number_unsigned < 128)
{
// positive fixnum
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_unsigned));
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_integer));
}
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint8_t>::max)())
{
// uint 8
oa.write_character(to_char_type(0xCC));
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_unsigned));
write_number(static_cast<std::uint8_t>(j.m_data.m_value.number_integer));
}
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint16_t>::max)())
{
// uint 16
oa.write_character(to_char_type(0xCD));
write_number(static_cast<std::uint16_t>(j.m_data.m_value.number_unsigned));
write_number(static_cast<std::uint16_t>(j.m_data.m_value.number_integer));
}
else if (j.m_data.m_value.number_unsigned <= (std::numeric_limits<std::uint32_t>::max)())
{
// uint 32
oa.write_character(to_char_type(0xCE));
write_number(static_cast<std::uint32_t>(j.m_data.m_value.number_unsigned));
write_number(static_cast<std::uint32_t>(j.m_data.m_value.number_integer));
}
else
{
// uint 64
oa.write_character(to_char_type(0xCF));
write_number(static_cast<std::uint64_t>(j.m_data.m_value.number_unsigned));
write_number(static_cast<std::uint64_t>(j.m_data.m_value.number_integer));
}
break;
}
+31
View File
@@ -388,6 +388,37 @@ TEST_CASE("deserialization")
}));
}
SECTION("stream with eofbit in its exception mask (issue #5646)")
{
// reaching EOF while parsing a value that fills the whole input
// (e.g., a number, or any value under strict parsing) makes
// get_character() call std::istream::clear() to record eofbit;
// with eofbit in the exception mask, that clear() itself throws
// std::ios_base::failure - it must propagate to the caller instead
// of ~input_stream_adapter() throwing a second exception while the
// first is still unwinding, which would call std::terminate
json _;
std::istringstream is1("1");
is1.exceptions(std::ios::eofbit);
CHECK_THROWS_AS(_ = json::parse(is1), std::ios_base::failure&);
// the same holds for the common std::ifstream::exceptions(failbit |
// badbit | eofbit) pattern, because only eofbit ends up set
std::istringstream is2("1");
is2.exceptions(std::ios::failbit | std::ios::badbit | std::ios::eofbit);
CHECK_THROWS_AS(_ = json::parse(is2), std::ios_base::failure&);
}
SECTION("stream without a streambuf (issue #5646)")
{
// std::istream(nullptr) has badbit set and rdbuf() == nullptr;
// get_character() must not dereference that null streambuf
std::istream is(nullptr);
json _;
CHECK_THROWS_WITH_AS(_ = json::parse(is), "[json.exception.parse_error.101] parse error: attempting to parse an empty input; check that your input string or stream contains the expected JSON", json::parse_error&);
}
SECTION("string")
{
json::string_t const s = R"(["foo",1,2,3,false,{"one":1})";
-57
View File
@@ -2475,60 +2475,3 @@ TEST_CASE("MessagePack lengths beyond UINT32_MAX cannot be serialized")
}
#endif
}
TEST_CASE("MessagePack numbers use the active union member (see #5644)")
{
// when number_integer_t is narrower than number_unsigned_t, to_msgpack()
// used to read the union member that was not the active one, writing
// wrong bytes for some values; std::int64_t/std::uint64_t (the default
// types, where both members have the same width) were not affected
using int32_json = nlohmann::basic_json<std::map, std::vector, std::string, bool, std::int32_t, std::uint64_t, double>;
using int16_json = nlohmann::basic_json<std::map, std::vector, std::string, bool, std::int16_t, std::uint64_t, double>;
SECTION("number_integer_t = std::int32_t")
{
SECTION("6442450944 (uint 64; the low 32 bits used to be sign-extended)")
{
const int32_json j = 6442450944ULL;
CHECK(j.is_number_unsigned());
std::vector<uint8_t> const expected{0xcf, 0x00, 0x00, 0x00, 0x01, 0x80, 0x00, 0x00, 0x00};
const auto result = int32_json::to_msgpack(j);
CHECK(result == expected);
CHECK(int32_json::from_msgpack(result) == j);
}
SECTION("4294967496 (uint 64; the low 32 bits used to be the whole value)")
{
const int32_json j = 4294967496ULL;
CHECK(j.is_number_unsigned());
std::vector<uint8_t> const expected{0xcf, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0xc8};
const auto result = int32_json::to_msgpack(j);
CHECK(result == expected);
CHECK(int32_json::from_msgpack(result) == j);
}
}
SECTION("number_integer_t = std::int16_t, 98304 (uint 32)")
{
const int16_json j = 98304ULL;
CHECK(j.is_number_unsigned());
std::vector<uint8_t> const expected{0xce, 0x00, 0x01, 0x80, 0x00};
const auto result = int16_json::to_msgpack(j);
CHECK(result == expected);
CHECK(int16_json::from_msgpack(result) == j);
}
SECTION("default types (std::int64_t/std::uint64_t) are unaffected")
{
const json j = 4294967496ULL;
CHECK(j.is_number_unsigned());
std::vector<uint8_t> const expected{0xcf, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0xc8};
const auto result = json::to_msgpack(j);
CHECK(result == expected);
CHECK(json::from_msgpack(result) == j);
}
}
@@ -234,4 +234,33 @@ TEST_CASE("JSON_PRECISE_STREAM_POSITION")
CHECK(j == json(1));
CHECK(remaining(is) == "true");
}
SECTION("stream with eofbit in its exception mask (issue #5646)")
{
// with JSON_PRECISE_STREAM_POSITION, get_character() peeks via
// sb->sgetc() rather than consuming via sb->sbumpc(), but it still
// calls std::istream::clear() to record eofbit once the streambuf is
// exhausted; with eofbit in the exception mask, that clear() itself
// throws std::ios_base::failure, which must propagate to the caller
// instead of ~input_stream_adapter() throwing a second exception
// while the first is still unwinding (which would call std::terminate)
json _;
std::istringstream is1("1");
is1.exceptions(std::ios::eofbit);
CHECK_THROWS_AS(_ = json::parse(is1), std::ios_base::failure&);
std::istringstream is2("1");
is2.exceptions(std::ios::failbit | std::ios::badbit | std::ios::eofbit);
CHECK_THROWS_AS(_ = json::parse(is2), std::ios_base::failure&);
}
SECTION("stream without a streambuf (issue #5646)")
{
// std::istream(nullptr) has badbit set and rdbuf() == nullptr;
// get_character() must not dereference that null streambuf
std::istream is(nullptr);
json _;
CHECK_THROWS_WITH_AS(_ = json::parse(is), "[json.exception.parse_error.101] parse error: attempting to parse an empty input; check that your input string or stream contains the expected JSON", json::parse_error&);
}
}