mirror of
https://github.com/SirHumza/orbisRPC.git
synced 2026-10-06 08:00:34 +02:00
JSON input cap + oversize test
This commit is contained in:
1 parent
29609377d8
commit
efa635d989
3 files changed
+6
No files matched your search
@@ -152,6 +152,10 @@ static jl_val_t *parse_value(jl_parse_t *p){ return parse_value_depth(p, 0); }
|
||||
|
||||
jl_val_t *jl_parse(const char *s, size_t len){
|
||||
if(!s) return NULL;
|
||||
/* Input cap: no legitimate input here exceeds it (gateway frames,
|
||||
* manifests, configs are KBs); unbounded input means unbounded
|
||||
* allocation inside parse_string's doubling buffer. */
|
||||
if(len > 4u*1024u*1024u) return NULL;
|
||||
size_t l = len;
|
||||
jl_parse_t p={s,s+l,0};
|
||||
jl_val_t *v=parse_value(&p);
|
||||
|
||||
@@ -68,6 +68,8 @@ static void test_json_oom_safe(void) { assert(jl_parse("true", 4) != NULL);
|
||||
/* incomplete pair must fail cleanly, no leak/crash */
|
||||
assert(jl_parse("{\"a\":", 5) == NULL);
|
||||
assert(jl_parse("{\"a\":1", 6) == NULL);
|
||||
/* oversize input refused before any allocation */
|
||||
assert(jl_parse("[]", 5u*1024u*1024u) == NULL);
|
||||
}
|
||||
static void test_json_hostile(void) {
|
||||
/* 200-deep nesting must be rejected, not stack-smash */
|
||||
|
||||
Executable
BIN
Binary file not shown.
Reference in new issue
Block a user