Compare commits

...

8 Commits

Author SHA1 Message Date
Max Bruckner
d48d988d7e Use character literal to declare range of nonprintable characters. 2018-01-11 00:19:41 +01:00
Max Bruckner
15d9ec8b07 New macro static_strlen and replace magic numbers with it. 2018-01-10 17:43:25 +01:00
Max Bruckner
f07a3b7cb3 print_value: Use sizeof(literal) instead of magic numbers 2018-01-10 15:45:14 +01:00
Max Bruckner
7cc52f6035 Merge pull request #231 from DaveGamble/fixes
Release Version 1.7.1
2018-01-09 22:34:48 +01:00
Max Bruckner
b60b5d3744 Update version to 1.7.1 2018-01-09 21:59:42 +01:00
Max Bruckner
4d84acf926 print_number: fix Off-By-One error
Thanks @liuyunbin for reporting this in #230
2018-01-09 21:40:55 +01:00
Max Bruckner
28d4410f42 print: fix: realloc was allocating too much memory
Thanks @liuyunbin for reporting this in #230
2018-01-09 20:53:33 +01:00
Max Bruckner
f33fa95f3d print: Fix default buffer size in printbuffer
Thanks @liuyunbin for reporting this in #230
2018-01-09 20:49:03 +01:00
5 changed files with 62 additions and 50 deletions

View File

@@ -1,3 +1,10 @@
1.7.1
=====
Fixes:
------
* Fixed an Off-By-One error that could lead to an out of bounds write. Thanks @liuyunbin for reporting (see #230)
* Fixed two errors with buffered printing. Thanks @liuyunbin for reporting (see #230)
1.7.0 1.7.0
===== =====
Features: Features:

View File

@@ -7,7 +7,7 @@ include(GNUInstallDirs)
set(PROJECT_VERSION_MAJOR 1) set(PROJECT_VERSION_MAJOR 1)
set(PROJECT_VERSION_MINOR 7) set(PROJECT_VERSION_MINOR 7)
set(PROJECT_VERSION_PATCH 0) set(PROJECT_VERSION_PATCH 1)
set(CJSON_VERSION_SO 1) set(CJSON_VERSION_SO 1)
set(CJSON_UTILS_VERSION_SO 1) set(CJSON_UTILS_VERSION_SO 1)
set(PROJECT_VERSION "${PROJECT_VERSION_MAJOR}.${PROJECT_VERSION_MINOR}.${PROJECT_VERSION_PATCH}") set(PROJECT_VERSION "${PROJECT_VERSION_MAJOR}.${PROJECT_VERSION_MINOR}.${PROJECT_VERSION_PATCH}")

View File

@@ -8,7 +8,7 @@ CJSON_TEST_SRC = cJSON.c test.c
LDLIBS = -lm LDLIBS = -lm
LIBVERSION = 1.7.0 LIBVERSION = 1.7.1
CJSON_SOVERSION = 1 CJSON_SOVERSION = 1
UTILS_SOVERSION = 1 UTILS_SOVERSION = 1

99
cJSON.c
View File

@@ -82,7 +82,7 @@ CJSON_PUBLIC(char *) cJSON_GetStringValue(cJSON *item) {
} }
/* This is a safeguard to prevent copy-pasters from using incompatible C and header files */ /* This is a safeguard to prevent copy-pasters from using incompatible C and header files */
#if (CJSON_VERSION_MAJOR != 1) || (CJSON_VERSION_MINOR != 7) || (CJSON_VERSION_PATCH != 0) #if (CJSON_VERSION_MAJOR != 1) || (CJSON_VERSION_MINOR != 7) || (CJSON_VERSION_PATCH != 1)
#error cJSON.h and cJSON.c have different versions. Make sure that both have the same. #error cJSON.h and cJSON.c have different versions. Make sure that both have the same.
#endif #endif
@@ -145,6 +145,9 @@ static void *internal_realloc(void *pointer, size_t size)
#define internal_realloc realloc #define internal_realloc realloc
#endif #endif
/* Compile time strlen for string literals */
#define static_strlen(literal) ((size_t)(sizeof(literal) - sizeof("")))
static internal_hooks global_hooks = { internal_malloc, internal_free, internal_realloc }; static internal_hooks global_hooks = { internal_malloc, internal_free, internal_realloc };
static unsigned char* cJSON_strdup(const unsigned char* string, const internal_hooks * const hooks) static unsigned char* cJSON_strdup(const unsigned char* string, const internal_hooks * const hooks)
@@ -280,7 +283,7 @@ static cJSON_bool parse_number(cJSON * const item, parse_buffer * const input_bu
/* copy the number into a temporary buffer and replace '.' with the decimal point /* copy the number into a temporary buffer and replace '.' with the decimal point
* of the current locale (for strtod) * of the current locale (for strtod)
* This also takes care of '\0' not necessarily being available for marking the end of the input */ * This also takes care of '\0' not necessarily being available for marking the end of the input */
for (i = 0; (i < (sizeof(number_c_string) - 1)) && can_access_at_index(input_buffer, i); i++) for (i = 0; (i < (sizeof(number_c_string) - sizeof(""))) && can_access_at_index(input_buffer, i); i++)
{ {
switch (buffer_at_offset(input_buffer)[i]) switch (buffer_at_offset(input_buffer)[i])
{ {
@@ -506,13 +509,13 @@ static cJSON_bool print_number(const cJSON * const item, printbuffer * const out
} }
/* sprintf failed or buffer overrun occured */ /* sprintf failed or buffer overrun occured */
if ((length < 0) || (length > (int)(sizeof(number_buffer) - 1))) if ((length < 0) || (length > (int)(sizeof(number_buffer) - sizeof(""))))
{ {
return false; return false;
} }
/* reserve appropriate space in the output */ /* reserve appropriate space in the output */
output_pointer = ensure(output_buffer, (size_t)length); output_pointer = ensure(output_buffer, (size_t)length + sizeof(""));
if (output_pointer == NULL) if (output_pointer == NULL)
{ {
return false; return false;
@@ -585,14 +588,14 @@ static unsigned char utf16_literal_to_utf8(const unsigned char * const input_poi
unsigned char sequence_length = 0; unsigned char sequence_length = 0;
unsigned char first_byte_mark = 0; unsigned char first_byte_mark = 0;
if ((input_end - first_sequence) < 6) if ((input_end - first_sequence) < ((int)static_strlen("\\uXXXX")))
{ {
/* input ends unexpectedly */ /* input ends unexpectedly */
goto fail; goto fail;
} }
/* get the first utf16 sequence */ /* get the first utf16 sequence */
first_code = parse_hex4(first_sequence + 2); first_code = parse_hex4(first_sequence + static_strlen("\\u"));
/* check that the code is valid */ /* check that the code is valid */
if (((first_code >= 0xDC00) && (first_code <= 0xDFFF))) if (((first_code >= 0xDC00) && (first_code <= 0xDFFF)))
@@ -603,11 +606,11 @@ static unsigned char utf16_literal_to_utf8(const unsigned char * const input_poi
/* UTF16 surrogate pair */ /* UTF16 surrogate pair */
if ((first_code >= 0xD800) && (first_code <= 0xDBFF)) if ((first_code >= 0xD800) && (first_code <= 0xDBFF))
{ {
const unsigned char *second_sequence = first_sequence + 6; const unsigned char *second_sequence = first_sequence + static_strlen("\\uXXXX");
unsigned int second_code = 0; unsigned int second_code = 0;
sequence_length = 12; /* \uXXXX\uXXXX */ sequence_length = static_strlen("\\uXXXX\\uXXXX");
if ((input_end - second_sequence) < 6) if ((input_end - second_sequence) < ((int)static_strlen("\\uXXXX")))
{ {
/* input ends unexpectedly */ /* input ends unexpectedly */
goto fail; goto fail;
@@ -620,7 +623,7 @@ static unsigned char utf16_literal_to_utf8(const unsigned char * const input_poi
} }
/* get the second utf16 sequence */ /* get the second utf16 sequence */
second_code = parse_hex4(second_sequence + 2); second_code = parse_hex4(second_sequence + static_strlen("\\u"));
/* check that the code is valid */ /* check that the code is valid */
if ((second_code < 0xDC00) || (second_code > 0xDFFF)) if ((second_code < 0xDC00) || (second_code > 0xDFFF))
{ {
@@ -634,7 +637,7 @@ static unsigned char utf16_literal_to_utf8(const unsigned char * const input_poi
} }
else else
{ {
sequence_length = 6; /* \uXXXX */ sequence_length = static_strlen("\\uXXXX");
codepoint = first_code; codepoint = first_code;
} }
@@ -698,8 +701,8 @@ fail:
/* Parse the input text into an unescaped cinput, and populate item. */ /* Parse the input text into an unescaped cinput, and populate item. */
static cJSON_bool parse_string(cJSON * const item, parse_buffer * const input_buffer) static cJSON_bool parse_string(cJSON * const item, parse_buffer * const input_buffer)
{ {
const unsigned char *input_pointer = buffer_at_offset(input_buffer) + 1; const unsigned char *input_pointer = buffer_at_offset(input_buffer) + static_strlen("\"");
const unsigned char *input_end = buffer_at_offset(input_buffer) + 1; const unsigned char *input_end = buffer_at_offset(input_buffer) + static_strlen("\"");
unsigned char *output_pointer = NULL; unsigned char *output_pointer = NULL;
unsigned char *output = NULL; unsigned char *output = NULL;
@@ -718,7 +721,7 @@ static cJSON_bool parse_string(cJSON * const item, parse_buffer * const input_bu
/* is escape sequence */ /* is escape sequence */
if (input_end[0] == '\\') if (input_end[0] == '\\')
{ {
if ((size_t)(input_end + 1 - input_buffer->content) >= input_buffer->length) if ((size_t)(input_end + sizeof("") - input_buffer->content) >= input_buffer->length)
{ {
/* prevent buffer overflow when last input character is a backslash */ /* prevent buffer overflow when last input character is a backslash */
goto fail; goto fail;
@@ -753,7 +756,7 @@ static cJSON_bool parse_string(cJSON * const item, parse_buffer * const input_bu
/* escape sequence */ /* escape sequence */
else else
{ {
unsigned char sequence_length = 2; unsigned char sequence_length = static_strlen("\\X");
if ((input_end - input_pointer) < 1) if ((input_end - input_pointer) < 1)
{ {
goto fail; goto fail;
@@ -868,10 +871,10 @@ static cJSON_bool print_string_ptr(const unsigned char * const input, printbuffe
escape_characters++; escape_characters++;
break; break;
default: default:
if (*input_pointer < 32) if (*input_pointer < '\x20')
{ {
/* UTF-16 escape sequence uXXXX */ /* UTF-16 escape sequence */
escape_characters += 5; escape_characters += static_strlen("uXXXX");
} }
break; break;
} }
@@ -888,7 +891,7 @@ static cJSON_bool print_string_ptr(const unsigned char * const input, printbuffe
if (escape_characters == 0) if (escape_characters == 0)
{ {
output[0] = '\"'; output[0] = '\"';
memcpy(output + 1, input, output_length); memcpy(output + static_strlen("\""), input, output_length);
output[output_length + 1] = '\"'; output[output_length + 1] = '\"';
output[output_length + 2] = '\0'; output[output_length + 2] = '\0';
@@ -896,11 +899,11 @@ static cJSON_bool print_string_ptr(const unsigned char * const input, printbuffe
} }
output[0] = '\"'; output[0] = '\"';
output_pointer = output + 1; output_pointer = output + static_strlen("\"");
/* copy the string */ /* copy the string */
for (input_pointer = input; *input_pointer != '\0'; (void)input_pointer++, output_pointer++) for (input_pointer = input; *input_pointer != '\0'; (void)input_pointer++, output_pointer++)
{ {
if ((*input_pointer > 31) && (*input_pointer != '\"') && (*input_pointer != '\\')) if ((*input_pointer >= '\x20') && (*input_pointer != '\"') && (*input_pointer != '\\'))
{ {
/* normal character, copy */ /* normal character, copy */
*output_pointer = *input_pointer; *output_pointer = *input_pointer;
@@ -935,7 +938,7 @@ static cJSON_bool print_string_ptr(const unsigned char * const input, printbuffe
default: default:
/* escape and print as unicode codepoint */ /* escape and print as unicode codepoint */
sprintf((char*)output_pointer, "u%04x", *input_pointer); sprintf((char*)output_pointer, "u%04x", *input_pointer);
output_pointer += 4; output_pointer += static_strlen("XXXX");
break; break;
} }
} }
@@ -968,7 +971,7 @@ static parse_buffer *buffer_skip_whitespace(parse_buffer * const buffer)
return NULL; return NULL;
} }
while (can_access_at_index(buffer, 0) && (buffer_at_offset(buffer)[0] <= 32)) while (can_access_at_index(buffer, 0) && (buffer_at_offset(buffer)[0] <= '\x20'))
{ {
buffer->offset++; buffer->offset++;
} }
@@ -989,9 +992,9 @@ static parse_buffer *skip_utf8_bom(parse_buffer * const buffer)
return NULL; return NULL;
} }
if (can_access_at_index(buffer, 4) && (strncmp((const char*)buffer_at_offset(buffer), "\xEF\xBB\xBF", 3) == 0)) if (can_access_at_index(buffer, sizeof("\xEF\xBB\xBF")) && (strncmp((const char*)buffer_at_offset(buffer), "\xEF\xBB\xBF", static_strlen("\xEF\xBB\xBF")) == 0))
{ {
buffer->offset += 3; buffer->offset += static_strlen("\xEF\xBB\xBF");
} }
return buffer; return buffer;
@@ -1087,13 +1090,15 @@ CJSON_PUBLIC(cJSON *) cJSON_Parse(const char *value)
static unsigned char *print(const cJSON * const item, cJSON_bool format, const internal_hooks * const hooks) static unsigned char *print(const cJSON * const item, cJSON_bool format, const internal_hooks * const hooks)
{ {
static const size_t default_buffer_size = 256;
printbuffer buffer[1]; printbuffer buffer[1];
unsigned char *printed = NULL; unsigned char *printed = NULL;
memset(buffer, 0, sizeof(buffer)); memset(buffer, 0, sizeof(buffer));
/* create buffer */ /* create buffer */
buffer->buffer = (unsigned char*) hooks->allocate(256); buffer->buffer = (unsigned char*) hooks->allocate(default_buffer_size);
buffer->length = default_buffer_size;
buffer->format = format; buffer->format = format;
buffer->hooks = *hooks; buffer->hooks = *hooks;
if (buffer->buffer == NULL) if (buffer->buffer == NULL)
@@ -1111,7 +1116,7 @@ static unsigned char *print(const cJSON * const item, cJSON_bool format, const i
/* check if reallocate is available */ /* check if reallocate is available */
if (hooks->reallocate != NULL) if (hooks->reallocate != NULL)
{ {
printed = (unsigned char*) hooks->reallocate(buffer->buffer, buffer->length); printed = (unsigned char*) hooks->reallocate(buffer->buffer, buffer->offset + 1);
buffer->buffer = NULL; buffer->buffer = NULL;
if (printed == NULL) { if (printed == NULL) {
goto fail; goto fail;
@@ -1217,25 +1222,25 @@ static cJSON_bool parse_value(cJSON * const item, parse_buffer * const input_buf
/* parse the different types of values */ /* parse the different types of values */
/* null */ /* null */
if (can_read(input_buffer, 4) && (strncmp((const char*)buffer_at_offset(input_buffer), "null", 4) == 0)) if (can_read(input_buffer, static_strlen("null")) && (strncmp((const char*)buffer_at_offset(input_buffer), "null", static_strlen("null")) == 0))
{ {
item->type = cJSON_NULL; item->type = cJSON_NULL;
input_buffer->offset += 4; input_buffer->offset += static_strlen("null");
return true; return true;
} }
/* false */ /* false */
if (can_read(input_buffer, 5) && (strncmp((const char*)buffer_at_offset(input_buffer), "false", 5) == 0)) if (can_read(input_buffer, static_strlen("false")) && (strncmp((const char*)buffer_at_offset(input_buffer), "false", static_strlen("false")) == 0))
{ {
item->type = cJSON_False; item->type = cJSON_False;
input_buffer->offset += 5; input_buffer->offset += static_strlen("false");
return true; return true;
} }
/* true */ /* true */
if (can_read(input_buffer, 4) && (strncmp((const char*)buffer_at_offset(input_buffer), "true", 4) == 0)) if (can_read(input_buffer, static_strlen("true")) && (strncmp((const char*)buffer_at_offset(input_buffer), "true", static_strlen("true")) == 0))
{ {
item->type = cJSON_True; item->type = cJSON_True;
item->valueint = 1; item->valueint = 1;
input_buffer->offset += 4; input_buffer->offset += static_strlen("true");
return true; return true;
} }
/* string */ /* string */
@@ -1275,7 +1280,7 @@ static cJSON_bool print_value(const cJSON * const item, printbuffer * const outp
switch ((item->type) & 0xFF) switch ((item->type) & 0xFF)
{ {
case cJSON_NULL: case cJSON_NULL:
output = ensure(output_buffer, 5); output = ensure(output_buffer, sizeof("null"));
if (output == NULL) if (output == NULL)
{ {
return false; return false;
@@ -1284,7 +1289,7 @@ static cJSON_bool print_value(const cJSON * const item, printbuffer * const outp
return true; return true;
case cJSON_False: case cJSON_False:
output = ensure(output_buffer, 6); output = ensure(output_buffer, sizeof("false"));
if (output == NULL) if (output == NULL)
{ {
return false; return false;
@@ -1293,7 +1298,7 @@ static cJSON_bool print_value(const cJSON * const item, printbuffer * const outp
return true; return true;
case cJSON_True: case cJSON_True:
output = ensure(output_buffer, 5); output = ensure(output_buffer, sizeof("true"));
if (output == NULL) if (output == NULL)
{ {
return false; return false;
@@ -1448,7 +1453,7 @@ static cJSON_bool print_array(const cJSON * const item, printbuffer * const outp
/* Compose the output array. */ /* Compose the output array. */
/* opening square bracket */ /* opening square bracket */
output_pointer = ensure(output_buffer, 1); output_pointer = ensure(output_buffer, static_strlen("["));
if (output_pointer == NULL) if (output_pointer == NULL)
{ {
return false; return false;
@@ -1467,8 +1472,8 @@ static cJSON_bool print_array(const cJSON * const item, printbuffer * const outp
update_offset(output_buffer); update_offset(output_buffer);
if (current_element->next) if (current_element->next)
{ {
length = (size_t) (output_buffer->format ? 2 : 1); length = (size_t) (output_buffer->format ? static_strlen(", ") : static_strlen(","));
output_pointer = ensure(output_buffer, length + 1); output_pointer = ensure(output_buffer, length + sizeof(""));
if (output_pointer == NULL) if (output_pointer == NULL)
{ {
return false; return false;
@@ -1484,7 +1489,7 @@ static cJSON_bool print_array(const cJSON * const item, printbuffer * const outp
current_element = current_element->next; current_element = current_element->next;
} }
output_pointer = ensure(output_buffer, 2); output_pointer = ensure(output_buffer, sizeof("]"));
if (output_pointer == NULL) if (output_pointer == NULL)
{ {
return false; return false;
@@ -1618,8 +1623,8 @@ static cJSON_bool print_object(const cJSON * const item, printbuffer * const out
} }
/* Compose the output: */ /* Compose the output: */
length = (size_t) (output_buffer->format ? 2 : 1); /* fmt: {\n */ length = (size_t) (output_buffer->format ? static_strlen("{\n") : static_strlen("{"));
output_pointer = ensure(output_buffer, length + 1); output_pointer = ensure(output_buffer, length + sizeof(""));
if (output_pointer == NULL) if (output_pointer == NULL)
{ {
return false; return false;
@@ -1657,7 +1662,7 @@ static cJSON_bool print_object(const cJSON * const item, printbuffer * const out
} }
update_offset(output_buffer); update_offset(output_buffer);
length = (size_t) (output_buffer->format ? 2 : 1); length = (size_t) (output_buffer->format ? static_strlen(":\t") : static_strlen(":"));
output_pointer = ensure(output_buffer, length); output_pointer = ensure(output_buffer, length);
if (output_pointer == NULL) if (output_pointer == NULL)
{ {
@@ -1678,8 +1683,8 @@ static cJSON_bool print_object(const cJSON * const item, printbuffer * const out
update_offset(output_buffer); update_offset(output_buffer);
/* print comma if not last */ /* print comma if not last */
length = (size_t) ((output_buffer->format ? 1 : 0) + (current_item->next ? 1 : 0)); length = (size_t) ((output_buffer->format ? static_strlen(",") : static_strlen("")) + (current_item->next ? static_strlen(",") : static_strlen("")));
output_pointer = ensure(output_buffer, length + 1); output_pointer = ensure(output_buffer, length + sizeof(""));
if (output_pointer == NULL) if (output_pointer == NULL)
{ {
return false; return false;
@@ -1699,7 +1704,7 @@ static cJSON_bool print_object(const cJSON * const item, printbuffer * const out
current_item = current_item->next; current_item = current_item->next;
} }
output_pointer = ensure(output_buffer, output_buffer->format ? (output_buffer->depth + 1) : 2); output_pointer = ensure(output_buffer, output_buffer->format ? (output_buffer->depth - 1 + sizeof("}")) : sizeof("}"));
if (output_pointer == NULL) if (output_pointer == NULL)
{ {
return false; return false;
@@ -2667,7 +2672,7 @@ CJSON_PUBLIC(void) cJSON_Minify(char *json)
{ {
json++; json++;
} }
json += 2; json += static_strlen("*/");
} }
else if (*json == '\"') else if (*json == '\"')
{ {

View File

@@ -31,7 +31,7 @@ extern "C"
/* project version */ /* project version */
#define CJSON_VERSION_MAJOR 1 #define CJSON_VERSION_MAJOR 1
#define CJSON_VERSION_MINOR 7 #define CJSON_VERSION_MINOR 7
#define CJSON_VERSION_PATCH 0 #define CJSON_VERSION_PATCH 1
#include <stddef.h> #include <stddef.h>