Repository navigation
Conversation
…ch case sensitivity
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary of Changes
This PR provides comprehensive defensive hardening and bug fixes across
cJSON_Utilsand corecJSON:cJSONUtils_FindPointerFromObjectTo:full_pointer == NULL) in both array and object traversal paths before invokingsprintforstrcat, avoiding NULL pointer dereference (SIGSEGV) on out-of-memory.current_child->string != NULLbefore computing encoded pointer length and copying.target_pointercleanly upon allocation failures.cJSONUtils_GenerateMergePatchCaseSensitive:cJSONUtils_GenerateMergePatch(from_child, to_child)(the case-insensitive variant), which caused case sensitivity to be dropped for all nested object members. Now propagatesgenerate_merge_patch(from_child, to_child, case_sensitive).strcmpingenerate_merge_patchwithcompare_strings(..., case_sensitive)to respectcase_sensitiveand prevent NULL pointer dereferences on missing member names.decode_array_index_from_pointer(RFC 6901):pointerandindex."/") from being parsed as index0(enforcingposition > 0).parsed_indexduring decimal accumulation.cJSONUtils_strdup,pointer_encoded_length, andencode_string_as_pointer:cJSON_strdup.insert_item_in_array&detach_item_from_array:arrayand NULLnewitemto avoid unconditional dereference ofarray->child.compare_json:valuestringforcJSON_StringandcJSON_Raw, avoidingstrcmp(NULL, ...)crashes.create_patches:new_pathbefore formatting withsprintf.cJSON_ReplaceItemViaPointer:(item != parent->child && item->prev == NULL)to prevent list corruption when attempting to replace an unlinked item, consistent withcJSON_DetachItemViaPointer.cJSON_PrintPreallocated:length <= 0, safely returningfalsefor empty/zero-capacity buffers.cJSON_SetValuestring:strcpyand relational pointer comparison between distinct allocations (valuestring + v1_len < object->valuestring, which constitutes undefined behavior in ISO C) withmemmove.Unit Tests:
tests/misc_utils_tests.ccovering merge patch case sensitivity across nested objects, RFC 6901 pointer array index bounds/overflow, zero-length preallocated print buffer rejection, and unlinked replacement rejection.