JSON input cap + oversize test

This commit is contained in:
SirHumza committed 2026-09-24 10:28:01 +02:00
1 parent 29609377d8
commit efa635d989
3 files changed
+6

No files matched your search

+4
View File
@@ -152,6 +152,10 @@ static jl_val_t *parse_value(jl_parse_t *p){ return parse_value_depth(p, 0); }
jl_val_t *jl_parse(const char *s, size_t len){
if(!s) return NULL;
/* Input cap: no legitimate input here exceeds it (gateway frames,
* manifests, configs are KBs); unbounded input means unbounded
* allocation inside parse_string's doubling buffer. */
if(len > 4u*1024u*1024u) return NULL;
size_t l = len;
jl_parse_t p={s,s+l,0};
jl_val_t *v=parse_value(&p);
+2
View File
@@ -68,6 +68,8 @@ static void test_json_oom_safe(void) { assert(jl_parse("true", 4) != NULL);
/* incomplete pair must fail cleanly, no leak/crash */
assert(jl_parse("{\"a\":", 5) == NULL);
assert(jl_parse("{\"a\":1", 6) == NULL);
/* oversize input refused before any allocation */
assert(jl_parse("[]", 5u*1024u*1024u) == NULL);
}
static void test_json_hostile(void) {
/* 200-deep nesting must be rejected, not stack-smash */
BIN
View File
Binary file not shown.