Skip to content

cJSON_Utils, cJSON: harden pointer bounds, null checks, and merge patch case sensitivity - #1095

Open
filtede98 wants to merge 1 commit into
DaveGamble:masterfrom
filtede98:fix-null-and-bounds-guards
Open

filtede98 wants to merge 1 commit into
DaveGamble:masterfrom
filtede98:fix-null-and-bounds-guards

Conversation

@filtede98

Copy link
Copy Markdown

Summary of Changes

This PR provides comprehensive defensive hardening and bug fixes across cJSON_Utils and core cJSON:

  1. cJSONUtils_FindPointerFromObjectTo:

    • Check for allocation failure (full_pointer == NULL) in both array and object traversal paths before invoking sprintf or strcat, avoiding NULL pointer dereference (SIGSEGV) on out-of-memory.
    • Verify current_child->string != NULL before computing encoded pointer length and copying.
    • Free target_pointer cleanly upon allocation failures.
  2. cJSONUtils_GenerateMergePatchCaseSensitive:

    • Fixed a logic bug where recursive patch generation for nested sub-objects invoked cJSONUtils_GenerateMergePatch(from_child, to_child) (the case-insensitive variant), which caused case sensitivity to be dropped for all nested object members. Now propagates generate_merge_patch(from_child, to_child, case_sensitive).
    • Replaced raw strcmp in generate_merge_patch with compare_strings(..., case_sensitive) to respect case_sensitive and prevent NULL pointer dereferences on missing member names.
  3. decode_array_index_from_pointer (RFC 6901):

    • Validated non-NULL pointer and index.
    • Prevented empty array tokens (e.g. "/") from being parsed as index 0 (enforcing position > 0).
    • Added integer overflow detection on parsed_index during decimal accumulation.
  4. cJSONUtils_strdup, pointer_encoded_length, and encode_string_as_pointer:

    • Added defensive NULL pointer validation matching cJSON_strdup.
  5. insert_item_in_array & detach_item_from_array:

    • Guarded against NULL array and NULL newitem to avoid unconditional dereference of array->child.
  6. compare_json:

    • Added NULL checks on valuestring for cJSON_String and cJSON_Raw, avoiding strcmp(NULL, ...) crashes.
  7. create_patches:

    • Added allocation failure checks for new_path before formatting with sprintf.
    • Guarded NULL valuestrings in string diffing.
  8. cJSON_ReplaceItemViaPointer:

    • Added check (item != parent->child && item->prev == NULL) to prevent list corruption when attempting to replace an unlinked item, consistent with cJSON_DetachItemViaPointer.
  9. cJSON_PrintPreallocated:

    • Validated length <= 0, safely returning false for empty/zero-capacity buffers.
  10. cJSON_SetValuestring:

    • Replaced strcpy and relational pointer comparison between distinct allocations (valuestring + v1_len < object->valuestring, which constitutes undefined behavior in ISO C) with memmove.
  11. Unit Tests:

    • Added unit test coverage in tests/misc_utils_tests.c covering merge patch case sensitivity across nested objects, RFC 6901 pointer array index bounds/overflow, zero-length preallocated print buffer rejection, and unlinked replacement rejection.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant