mirror of
https://github.com/nlohmann/json.git
synced 2026-10-02 14:25:48 +01:00
Throw std::length_error for operator[](SIZE_MAX) instead of corrupting the array (#5687)
For idx == SIZE_MAX, the non-const array operator[] computed the new size as idx + 1, which wraps to 0. resize(0) then emptied the array, and the subsequent operator[](idx) on the now-empty vector wrote one element before its buffer. Every other too-large index (e.g. SIZE_MAX - 1) already went through resize(), which throws std::length_error and leaves the array unchanged; SIZE_MAX was the one value for which the overflow bypassed that safety net. Add a guard that throws std::length_error before computing idx + 1 when idx is the largest representable size_type value, so the array is left unchanged, matching the exception vector::resize() already throws for smaller (but still too large) indices. Fixes #5647. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
@@ -147,6 +147,24 @@ TEST_CASE("element access 1")
|
||||
CHECK(j_const[7] == json({1, 2, 3}));
|
||||
}
|
||||
|
||||
SECTION("SIZE_MAX index (#5647)")
|
||||
{
|
||||
// idx + 1 must not be computed for idx == SIZE_MAX: it wraps to 0,
|
||||
// which would empty the array and then write out of bounds instead
|
||||
// of growing it; reject it like an oversized resize() would and
|
||||
// leave the array unchanged
|
||||
const auto max_idx = (std::numeric_limits<json::size_type>::max)();
|
||||
const std::string expected = "array index " + std::to_string(max_idx) + " exceeds size_type";
|
||||
const json j_before = j; // NOLINT(performance-unnecessary-copy-initialization)
|
||||
|
||||
CHECK_THROWS_WITH_AS(j[max_idx] = 1, expected.c_str(), std::length_error&);
|
||||
CHECK(j == j_before);
|
||||
|
||||
json j_empty = json::array();
|
||||
CHECK_THROWS_WITH_AS(j_empty[max_idx] = 1, expected.c_str(), std::length_error&);
|
||||
CHECK(j_empty == json::array());
|
||||
}
|
||||
|
||||
SECTION("access on non-array type")
|
||||
{
|
||||
SECTION("null")
|
||||
|
||||
Reference in New Issue
Block a user