Skip to content

Throw CborContentException for dangling tag at end of root-level sequence - #135359

Open
MuhammadBilal64 wants to merge 3 commits into
dotnet:mainfrom
MuhammadBilal64:fix/cbor-dangling-root-level-tag
Open

MuhammadBilal64 wants to merge 3 commits into
dotnet:mainfrom
MuhammadBilal64:fix/cbor-dangling-root-level-tag

Conversation

@MuhammadBilal64

Copy link
Copy Markdown

Fixes #135191

CborReader now throws CborContentException when a root-level value sequence (AllowMultipleRootLevelValues) ends with a tag that is not followed by a data item, instead of reporting Finished. This applies to both single-buffer and incremental (SlideData) readers, so equivalent states now throw the same exception type.

Changes:

  • PeekStateCore: throw at the end of a root-level sequence if a tag is pending
  • PeekInitialByte: same check before the end-of-sequence guard, which covers the case where the tag is the only token consumed (SlideData rebases the offset to zero)
  • Updated PeekState_DanglingTagAtEndOfRootSequence, which asserted the old Finished behavior, and added a test for the tag-only case

Note: this changes shipped behavior. PeekState() previously returned Finished for a dangling root-level tag.

Testing: I verified the scenarios from the issue (before and after the change) with a scratch console project that compiles the library sources. I couldn't run the full System.Formats.Cbor test suite locally, so I'm relying on CI for that.

@dotnet-policy-service dotnet-policy-service Bot added the community-contribution Indicates that the PR has been added by a community member label Oct 7, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/area-system-formats-cbor, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-System.Formats.Cbor community-contribution Indicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CborReader with AllowMultipleRootLevelValues reports Finished for a root sequence ending in a dangling tag

2 participants