Repository navigation
create the new value before the walk in set_at_pointer - #1208
Ramya-9353 wants to merge 1 commit into
Conversation
|
An automated preview of the documentation is available at https://1208.json.prtest2.cppalliance.org/libs/json/doc/html/index.html If more commits are pushed to the pull request, the docs will rebuild at the same URL. 2026-10-07 07:57:50 UTC |
|
GCOVR code coverage report https://1208.json.prtest2.cppalliance.org/gcovr/index.html Build time: 2026-10-07 08:27:37 UTC |
|
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #1208 +/- ##
========================================
Coverage 93.98% 93.98%
========================================
Files 85 85
Lines 8971 8973 +2
========================================
+ Hits 8431 8433 +2
Misses 540 540
Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|

Repro:
{"c":null}withjv.set_at_pointer("/c/x", jv.at("c"))gives{"c":{"x":{"x":null}}}instead of{"c":{"x":null}}, on any build and with default options. The same value with"/c/0"gives{"c":[[null]]}, andjv.set_at_pointer("/x", jv)on a null root gives{"x":{"x":null}}. The reallocating cases report a heap-use-after-free under ASAN instead:jv.set_at_pointer("/a", jv.at("b"))on{"b":[1,2,3]}(heap-use-after-free invalue::value(value const&, storage_ptr)at value.ipp:112, read fromvalue_ref::make_valueat pointer.ipp:498), and the same for an index past the end of an array with a large enoughmax_created_elements.Cause: the value to store is built from
refonly afterwalk_pointerreturns, and the walk modifies the document on its way. A missing object key goes throughobject::emplaceand a missing array index througharray::resize, either of which can reallocate and free the tablerefpoints into. A scalar in the path of a further token is replaced in place by an empty array or object, sorefthen refers to the container the walk has just created rather than to the element the caller passed.Fix: create the value before the walk and move it into place, which is what
object::emplace_implandarray::emplacealready do for the same reason. One side effect is that the document is left untouched whenmake_valuethrows. Tests added totestSet: the four in-place replacement cases fail on develop with no sanitizer, and the object and array growth cases report a heap-use-after-free under ASAN before the change.