mirror of
https://github.com/nlohmann/json.git
synced 2026-10-11 11:25:16 +00:00
An image is a document stored so that loading it needs no
parsing: save() writes the node index, the text and the decoded
strings; the static load() reads an image written by save().
load() takes a pointer and size, a borrowed vector, or an owned
rvalue vector; the nodes are copied so they are aligned and can
be edited, while the text and decoded strings stay in the image.
image_check controls how much load() trusts the input: full
checks structure, bounds, strings and numbers, the parser's own
guarantees; bounds checks structure and bounds only; none skips
all checks, for images from a trusted source.
Layout is little-endian only ("NJVI" header, nodes, text, decoded
strings), following the idea of zero-copy formats such as
FlatBuffers and YaFF; the check follows FlatBuffers' Verifier.
New errors: parse_error.116 for a malformed image or a failed
check, type_error.320 for a discarded document or a big-endian
target.
A dedicated fuzzer and 6,000 seeded corruptions, checked under
ASan/UBSan, found and fixed two gaps: unchecked reserved header
fields, and unbounded null/boolean offsets that could make
dump() throw std::length_error.
Signed-off-by: Niels Lohmann <mail@nlohmann.me>
53 lines
2.1 KiB
C++
53 lines
2.1 KiB
C++
#include <cstdint>
|
|
#include <iostream>
|
|
#include <string>
|
|
#include <vector>
|
|
#include <nlohmann/json_view.hpp>
|
|
|
|
using json = nlohmann::json;
|
|
using json_document = nlohmann::json_document;
|
|
using image_check = json_document::image_check;
|
|
|
|
int main()
|
|
{
|
|
std::cout << std::boolalpha;
|
|
|
|
// the image of a parsed document -- as if read back from a cache file or
|
|
// received from another process running the same build of the library
|
|
const std::string text = R"({"name": "cache", "note": "caf\u00e9", "replicas": ["db2", "db3"]})";
|
|
const json_document parsed = json_document::parse(text);
|
|
const std::vector<std::uint8_t> image = parsed.save();
|
|
|
|
// (1)/(2) load() needs no parsing, yet dumps exactly what parsing did
|
|
const json_document borrowed = json_document::load(image);
|
|
std::cout << (borrowed.root().dump() == parsed.root().dump()) << '\n';
|
|
std::cout << borrowed.owns_source() << '\n'; // borrowed: still points into `image`
|
|
|
|
// (3) load(std::move(image)) keeps the vector instead of copying it
|
|
std::vector<std::uint8_t> to_move = image;
|
|
const json_document owned = json_document::load(std::move(to_move));
|
|
std::cout << owned.owns_source() << '\n';
|
|
|
|
// a damaged image -- the last byte of the decoded string "note" holds
|
|
// (an escape sequence, so it was unescaped into the document's own
|
|
// buffer), flipped, as storage or transport corruption might do
|
|
std::vector<std::uint8_t> damaged = image;
|
|
damaged[damaged.size() - 2] = 0xFF;
|
|
|
|
// image_check::full inspects strings and numbers, so it catches the damage
|
|
try
|
|
{
|
|
static_cast<void>(json_document::load(damaged, image_check::full));
|
|
}
|
|
catch (const json::parse_error& e)
|
|
{
|
|
std::cout << e.id << '\n';
|
|
}
|
|
|
|
// image_check::bounds only checks structure and bounds, so a cache the
|
|
// process already trusts loads without the extra scan -- reading a value
|
|
// the damage did not touch is still safe
|
|
const json_document trusted = json_document::load(damaged, image_check::bounds);
|
|
std::cout << trusted.root()["name"].get<std::string>() << '\n';
|
|
}
|