mirror of
https://github.com/nlohmann/json.git
synced 2026-10-11 17:07:15 +00:00
* Stop the BON8 writer overflowing the stack on deep values to_bon8() recursed once per nesting level, so a value the iterative BON8 reader accepts (e.g. ~24k nested one-element arrays) crashed on the way back out. #5781 bounded the CBOR, MessagePack, and UBJSON/BJData writers, but BON8 was merged before it and was not covered. Apply the same scheme: recurse for the first recursion_depth_limit() levels, then finish the value with write_bon8_iterative, which keeps the open containers on a heap stack (reusing binary_container_frame) and writes the 0xFE closer when it leaves a container with more than four elements. The output is byte-for-byte unchanged. Fixes https://issues.oss-fuzz.com/issues/572238015 Signed-off-by: Niels Lohmann <mail@nlohmann.me> * Merge the array and object branches of the BON8 iterative writer write_bon8_iterative and write_bon8_value_or_push handled arrays and objects in separate branches that repeated the end-of-container check, the 0xFE closer and the marker computation. Share those parts and branch only where arrays and objects really differ. The output is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Hz7VJi1FTKr6gpseLErbbS Signed-off-by: Niels Lohmann <mail@nlohmann.me> --------- Signed-off-by: Niels Lohmann <mail@nlohmann.me> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>