Skip to content

recreate insert iterator after clear in parse_into sequence handler - #1207

Open
Ramya-9353 wants to merge 1 commit into
boostorg:developfrom
Ramya-9353:parse-into-stale-inserter
Open

Ramya-9353 wants to merge 1 commit into
boostorg:developfrom
Ramya-9353:parse-into-stale-inserter

Conversation

@Ramya-9353

Copy link
Copy Markdown
Contributor

Repro: parse_into a boost::container::flat_set<int> that already holds elements ([1,2,3], then [4] into the same object), or a std::vector<flat_set<int>> from [[1,2],[3,4]]. Debug builds stop on Boost.Container's priv_in_range_or_end(hint) assertion; with NDEBUG, ASan reports a heap-buffer-overflow read in flat_tree::priv_insert_unique_prepare, reached from signal_value. C++23 std::flat_set fails the same way.

Cause: the sequence handler builds its inserter in the constructor and in signal_end, but the target is cleared later, in on_array_begin, and a nested target (next_value_) is also moved from and reassigned by the parent between elements. Without push_back the inserter is std::inserter(c, c.end()), so the stored hint is already invalid when the first element arrives. std::set still works (checked with libc++) because its end() survives both, which is why this went unnoticed.

Fix: build the inserter in on_array_begin, right after the clear, instead of in signal_end. The added test aborts on develop and passes with the change.

@cppalliance-bot

Copy link
Copy Markdown

An automated preview of the documentation is available at https://1207.json.prtest2.cppalliance.org/libs/json/doc/html/index.html

If more commits are pushed to the pull request, the docs will rebuild at the same URL.

2026-10-05 08:37:46 UTC

@cppalliance-bot

Copy link
Copy Markdown

GCOVR code coverage report https://1207.json.prtest2.cppalliance.org/gcovr/index.html
LCOV code coverage report https://1207.json.prtest2.cppalliance.org/genhtml/index.html
Coverage Diff Report https://1207.json.prtest2.cppalliance.org/diff-report/index.html

Build time: 2026-10-05 09:13:10 UTC

@cppalliance-bot

Copy link
Copy Markdown

@codecov

codecov Bot commented Oct 5, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.98%. Comparing base (fc70d23) to head (1fd61ae).

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff            @@
##           develop    #1207   +/-   ##
========================================
  Coverage    93.98%   93.98%           
========================================
  Files           85       85           
  Lines         8973     8973           
========================================
  Hits          8433     8433           
  Misses         540      540           
Files with missing lines Coverage Δ
include/boost/json/detail/parse_into.hpp 99.33% <100.00%> (ø)

Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update fc70d23...1fd61ae. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants