Skip to content

create the new value before the walk in set_at_pointer - #1208

Open
Ramya-9353 wants to merge 1 commit into
boostorg:developfrom
Ramya-9353:pointer-set-value-order
Open

Ramya-9353 wants to merge 1 commit into
boostorg:developfrom
Ramya-9353:pointer-set-value-order

Conversation

@Ramya-9353

Copy link
Copy Markdown
Contributor

Repro: {"c":null} with jv.set_at_pointer("/c/x", jv.at("c")) gives {"c":{"x":{"x":null}}} instead of {"c":{"x":null}}, on any build and with default options. The same value with "/c/0" gives {"c":[[null]]}, and jv.set_at_pointer("/x", jv) on a null root gives {"x":{"x":null}}. The reallocating cases report a heap-use-after-free under ASAN instead: jv.set_at_pointer("/a", jv.at("b")) on {"b":[1,2,3]} (heap-use-after-free in value::value(value const&, storage_ptr) at value.ipp:112, read from value_ref::make_value at pointer.ipp:498), and the same for an index past the end of an array with a large enough max_created_elements.

Cause: the value to store is built from ref only after walk_pointer returns, and the walk modifies the document on its way. A missing object key goes through object::emplace and a missing array index through array::resize, either of which can reallocate and free the table ref points into. A scalar in the path of a further token is replaced in place by an empty array or object, so ref then refers to the container the walk has just created rather than to the element the caller passed.

Fix: create the value before the walk and move it into place, which is what object::emplace_impl and array::emplace already do for the same reason. One side effect is that the document is left untouched when make_value throws. Tests added to testSet: the four in-place replacement cases fail on develop with no sanitizer, and the object and array growth cases report a heap-use-after-free under ASAN before the change.

@cppalliance-bot

Copy link
Copy Markdown

An automated preview of the documentation is available at https://1208.json.prtest2.cppalliance.org/libs/json/doc/html/index.html

If more commits are pushed to the pull request, the docs will rebuild at the same URL.

2026-10-07 07:57:50 UTC

@cppalliance-bot

Copy link
Copy Markdown

GCOVR code coverage report https://1208.json.prtest2.cppalliance.org/gcovr/index.html
LCOV code coverage report https://1208.json.prtest2.cppalliance.org/genhtml/index.html
Coverage Diff Report https://1208.json.prtest2.cppalliance.org/diff-report/index.html

Build time: 2026-10-07 08:27:37 UTC

@cppalliance-bot

Copy link
Copy Markdown

@codecov

codecov Bot commented Oct 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.98%. Comparing base (87c2e5e) to head (cf464aa).

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff            @@
##           develop    #1208   +/-   ##
========================================
  Coverage    93.98%   93.98%           
========================================
  Files           85       85           
  Lines         8971     8973    +2     
========================================
+ Hits          8431     8433    +2     
  Misses         540      540           
Files with missing lines Coverage Δ
include/boost/json/impl/pointer.ipp 100.00% <100.00%> (ø)

Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 87c2e5e...cf464aa. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants