Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(784)

Unified Diff: third_party/WebKit/Source/platform/json/JSONParserTest.cpp

Issue 2517183002: Add a configurable maximum parse depth for the blink JSON parser. (Closed)
Patch Set: Created 4 years, 1 month ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « third_party/WebKit/Source/platform/json/JSONParser.cpp ('k') | no next file » | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: third_party/WebKit/Source/platform/json/JSONParserTest.cpp
diff --git a/third_party/WebKit/Source/platform/json/JSONParserTest.cpp b/third_party/WebKit/Source/platform/json/JSONParserTest.cpp
index c4ca4d3f2a451e39a6d112d9fd1e413bb2350586..303b44cefd1f3d3ec0c8fd01257de4f202c30e6d 100644
--- a/third_party/WebKit/Source/platform/json/JSONParserTest.cpp
+++ b/third_party/WebKit/Source/platform/json/JSONParserTest.cpp
@@ -487,4 +487,64 @@ TEST(JSONParserTest, InvalidSanity) {
}
}
+// Test that the nesting depth can be limited to values less than 1000, but
+// cannot be extended past that maximum.
+TEST(JSONParserTest, LimitedDepth) {
+ std::unique_ptr<JSONValue> root;
+
+ // Test cases. Each pair is a JSON string, and the minimum depth required
+ // to successfully parse that string.
+ std::vector<std::pair<const char*, int>> test_cases = {
+ {"[[[[[]]]]]", 5},
+ {"[[[[[\"a\"]]]]]", 6},
+ {"[[],[],[],[],[]]", 2},
+ {"{\"a\":{\"a\":{\"a\":{\"a\":{\"a\": \"a\"}}}}}", 6},
+ {"\"root\"", 1}};
+
+ for (const auto& test_case : test_cases) {
+ // Each test case should parse successfully at the default depth
+ root = parseJSON(test_case.first);
+ EXPECT_TRUE(root.get());
+
+ // ... and should parse successfully at the minimum depth
+ root = parseJSON(test_case.first, test_case.second);
+ EXPECT_TRUE(root.get());
+
+ // ... but should fail to parse at a shallower depth.
+ root = parseJSON(test_case.first, test_case.second - 1);
+ EXPECT_FALSE(root.get());
+ }
+
+ // Test that everything fails to parse with depth 0
+ root = parseJSON("", 0);
+ EXPECT_FALSE(root.get());
+ root = parseJSON("", -1);
+ EXPECT_FALSE(root.get());
+ root = parseJSON("true", 0);
+ EXPECT_FALSE(root.get());
+
+ // Test that the limit can be set to the constant maximum.
+ StringBuilder evil;
+ evil.reserveCapacity(2002);
+ for (int i = 0; i < 1000; ++i)
+ evil.append('[');
+ for (int i = 0; i < 1000; ++i)
+ evil.append(']');
+ root = parseJSON(evil.toString());
+ EXPECT_TRUE(root.get());
+ root = parseJSON(evil.toString(), 1000);
+ EXPECT_TRUE(root.get());
+
+ // Test that the limit cannot be set higher than the constant maximum.
+ evil.clear();
+ for (int i = 0; i < 1001; ++i)
+ evil.append('[');
+ for (int i = 0; i < 1001; ++i)
+ evil.append(']');
+ root = parseJSON(evil.toString());
+ EXPECT_FALSE(root.get());
+ root = parseJSON(evil.toString(), 1001);
+ EXPECT_FALSE(root.get());
+}
+
} // namespace blink
« no previous file with comments | « third_party/WebKit/Source/platform/json/JSONParser.cpp ('k') | no next file » | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698