qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] [PATCH v2 0/4] json-streamer: Fix up code to limit nesting and size
@ 2015-11-19 15:29 Markus Armbruster
  2015-11-19 15:29 ` [Qemu-devel] [PATCH v2 1/4] json-streamer: Apply nesting limit more sanely Markus Armbruster
                   ` (4 more replies)
  0 siblings, 5 replies; 14+ messages in thread
From: Markus Armbruster @ 2015-11-19 15:29 UTC (permalink / raw)
  To: qemu-devel; +Cc: lcapitulino

Ugh, I almost dropped this on the floor.  I think it should go into
2.5, and I plan to take it through my tree.  If you disagree, please
speak up.

We limit nesting depth and input size to defend against input
triggering excessive heap or stack memory use (commit 29c75dd
json-streamer: limit the maximum recursion depth and maximum token
count).  This limiting is flawed in multiple ways.  Fix it up some.

Not yet fixed: this JSON parser is an absurd memory hog; see last
patch.

v2:
* Trivially rebased, R-bys retained
* PATCH 3: Fix a nearby comment typo [Eric]
* PATCH 4: Simplify make_nest() slightly
* PATCH 5: Commit message tweaked

Markus Armbruster (4):
  json-streamer: Apply nesting limit more sanely
  json-streamer: Don't crash when input exceeds nesting limit
  check-qjson: Add test for JSON nesting depth limit
  json-streamer: Limit number of tokens in addition to total size

 qobject/json-streamer.c | 10 ++++++----
 tests/check-qjson.c     | 25 +++++++++++++++++++++++++
 2 files changed, 31 insertions(+), 4 deletions(-)

-- 
2.4.3

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2015-11-23 17:09 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-11-19 15:29 [Qemu-devel] [PATCH v2 0/4] json-streamer: Fix up code to limit nesting and size Markus Armbruster
2015-11-19 15:29 ` [Qemu-devel] [PATCH v2 1/4] json-streamer: Apply nesting limit more sanely Markus Armbruster
2015-11-19 15:29 ` [Qemu-devel] [PATCH v2 2/4] json-streamer: Don't crash when input exceeds nesting limit Markus Armbruster
2015-11-19 15:29 ` [Qemu-devel] [PATCH v2 3/4] check-qjson: Add test for JSON nesting depth limit Markus Armbruster
2015-11-19 15:29 ` [Qemu-devel] [PATCH v2 4/4] json-streamer: Limit number of tokens in addition to total size Markus Armbruster
2015-11-19 22:01   ` Paolo Bonzini
2015-11-20  6:13     ` Markus Armbruster
2015-11-20  8:50       ` Paolo Bonzini
2015-11-20 17:32         ` Eric Blake
2015-11-23 14:27           ` Paolo Bonzini
2015-11-23 16:03             ` Eric Blake
2015-11-23 17:09               ` Markus Armbruster
2015-11-19 16:15 ` [Qemu-devel] [PATCH v2 0/4] json-streamer: Fix up code to limit nesting and size Eric Blake
2015-11-19 16:59   ` Markus Armbruster

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).