Commit Graph
458 Commits
Author SHA1 Message Date
Jeroen van Rijn c1ac93f9a6 `delete(dst, allocator) 2026-10-07 11:21:07 +02:00
bplu4t2f 758cdd19ae Fix #7779 - Make encoding/hex behave well on errors. 2026-10-07 10:47:57 +02:00
Arthur031221 eaa1cb34eb Fix CBOR bit set byte order conversion 2026-10-02 18:57:49 +08:00
Arthur031221 f01284d372 [core:encoding/csv] Read the final multiline record before EOF
The multiline line reader returned EOF with buffered data, so record
parsing discarded the last row when the file had no trailing newline.
Clear EOF while data remains, as the normal line reader does.

Add regressions for final records, empty input and unterminated quotes.
The normal core suite passes 627 tests with the new CSV tests included.
2026-10-02 14:10:58 +08:00
Ihor Antonov a5bef5224c core: add unpadded base64 encoding
core:encoding/base64 can only produce padded output, so callers that need
the canonical unpadded ("raw") form -- JOSE base64url, Go's
RawStdEncoding/RawURLEncoding -- have to encode and then trim, which
forces an extra allocation and cleanup dance around the returned string.

Add an Encode_Options bit set, mirroring Decode_Options, and honor
{.No_Padding} in `encode`, `encode_into_buf`, `encode_into`, and
`encoded_len`. Existing calls and padded output are unchanged.

Tests cover the RFC 4648 section 9 illustrations and section 10 test
vectors across the standard and URL alphabets, padded and raw, plus Go's
reference corpus. Newline characters are asserted to be rejected per
RFC 4648 section 3.3. Comments in `encode_impl` document the 24-bit group
packing and the padding decision for partial groups.
2026-09-30 19:53:10 -07:00
Ben Botwin 2796bf0fd0 removes private from unmarshal_value for use in user unmarshalers 2026-09-29 16:58:31 -04:00
Ihor Antonov 2109ba8fbd core: add strict base64 decoding
core:encoding/base64 currently decodes leniently: it infers padding from the
last one or two bytes, accepts missing/extra/interior padding, and does not
check the trailing padding bits required by RFC 4648 Section 3.5.
Go exposes canonical decoding as `Encoding.Strict()`; Odin has no equivalent,
so downstream ports (e.g. age) have to reimplement base64 from scratch.

This adds opt-in strict decoding through a `Decode_Options` bit set.
Existing calls and behavior are unchanged.
2026-09-28 19:59:23 -07:00
Jack Mordaunt 641844dae7 core/encoding/json: size the unquote buffer for replaced invalid UTF-8
unquote_string replaces each byte that is not valid UTF-8 with U+FFFD,
which is three bytes for one, but sized its buffer as len(s) + 2*UTF_MAX:
slack for a single replacement, not for one per invalid byte. A string
holding several ran the write cursor past the end, an out-of-range slice
under bounds checking and a memory-safety bug without it.

Count the invalid bytes in the remainder up front and size for them. The
escape sequences never grow their input, so they need no allowance.
2026-09-25 14:27:40 -03:00
user.name 6ccde7f80b bugfix: core/encoding/json leaks the key and value of a malformed object
parse_object_body allocates an object key, then may fail in parse_colon or
parse_value before that key is ever inserted into the object. Its cleanup defer
only walks `obj`, so a key that never got there is unreachable to it. The caller
cannot free it either -- a failed parse returns a nil Value -- so it leaks.

The same applies to the parsed element on the duplicate-key path, and to both on
the out-of-memory path.

JSON5 makes this reachable from ordinary malformed input, because an unquoted
ident is a legal key and anything other than a colon after it fails. Plain JSON
leaks it too, via a quoted key.

before, measured with a tracking allocator over 8 inputs x 2 specs:

	LEAK JSON5  colon fails after unquoted key   1 alloc / 7 bytes
	LEAK JSON   colon fails after quoted key     1 alloc / 2 bytes
	LEAK JSON5  colon fails after quoted key     1 alloc / 2 bytes
	LEAK JSON   value fails after key            1 alloc / 2 bytes
	LEAK JSON5  value fails after key            1 alloc / 2 bytes
	LEAK JSON   nested value fails               2 alloc / 4 bytes
	LEAK JSON5  nested value fails               2 alloc / 4 bytes
	LEAK JSON   deep nesting fails               3 alloc / 6 bytes
	LEAK JSON5  deep nesting fails               3 alloc / 6 bytes
	LEAK JSON   array element fails              1 alloc / 2 bytes
	LEAK JSON5  array element fails              1 alloc / 2 bytes
	total leaked allocations: 17

after, same probe:

	total leaked allocations: 0

The leak scales with nesting depth -- one orphaned key per enclosing object -- so
a service parsing untrusted JSON leaks a little on every malformed request.

The fix marks the key and the element as owned by the loop iteration until they
are stored, and frees them otherwise. The duplicate-key path loses its explicit
delete, which the same mechanism now covers.

Found via odinfmt, which reported a 7-byte leak in a downstream test that parses
`{ broken not json` to check that invalid input is rejected.

Regression test added to tests/core/encoding/json: it reports
`17 leaks and 0 bad frees` without this change and passes with it. The existing
11 tests pass unchanged under -define:ODIN_TEST_FAIL_ON_BAD_MEMORY=true.
2026-08-31 11:39:42 -07:00
kalsprite deeddc7b33 add missing endian 128 types 2026-08-25 23:03:11 -07:00
mo 4e0a71c24c Add non-allocating hex.decode_into_buffer
Also minor fixes to documentation of hex.decode().

Adds tests of the new procedure with buffers the correct size, larger,
and too small.
2026-08-16 19:48:19 +12:00
Stephen Hara 8757541ba4 docs: fix errors in encoding/csv examples
Fix 1 is passing an `io.Stream` to `reader_init` instead of a
`FileStream`.
Fix 2 is an `err` that should (probably?) have been `csv_err`.
2026-07-18 20:27:33 +09:00
kalsprite e4fc7a3a9e rsa, x509 write path 2026-07-12 12:14:32 -07:00
kalsprite 2fd11467c8 Merge branch 'master' into x.508 2026-07-12 10:51:44 -07:00
Mustafa Furkan Bulut 2c85085fc6 Fix data corruption in endcoding/cbor 2026-07-05 15:58:45 +03:00
Qiaoster 4b203f09c6 encoding/cbor: fix segfault decoding map/big.int nested in slice elements 2026-07-04 10:38:12 +08:00
Jeroen van Rijn 4b9f396cb3 Fix whitespace normalize 2026-06-30 13:23:44 +02:00
gingerBill 7d32c733d3 json.match utility procedure 2026-06-29 13:44:45 +01:00
gingerBill 9e713e2940 Update core:encoding/json to use proc groups and @(require_results) 2026-06-29 13:44:29 +01:00
Bärtschi Robin 3883d079c8 Fix #6874 2026-06-24 08:04:17 +02:00
gingerBill 8c63a70aad Fix identation 2026-06-23 13:14:56 +01:00
gingerBill 2b684ed1ec Add json.unparse allowing for json.Value to io.Writer without the need for RTTI 2026-06-23 12:47:38 +01:00
kalsprite 4876cf03bf asn1 DER reader/writer and X.509 reader 2026-06-13 23:40:08 -07:00
Yawning Angel e7698e4adf core/encoding/pem: Initial import 2026-06-02 17:48:46 +09:00
Yawning Angel 82a18797b4 core/encoding/base64: Misc fixes and improvements
- Add error checking to `decode`
- Add `encode_into_buf`/`decode_into_buf`
2026-05-26 00:38:50 +09:00
A1029384756 45a79f96f0 [encoding/json] add support for unmarshalling fixed capacity dynamic arrays 2026-05-21 11:48:25 -04:00
Brad Lewis 87d58b9fb7 Handle invalid utf8 when parsing json 2026-05-10 16:23:26 +10:00
Laytan d90cc4e3b6 json: fix user unmarshaller example (#6468)
* json: fix user unmarshaller example

- Returning `.None` in the custom unmarshaler is wrong, should be `nil`
- `advance_token` has to be called

Besides the fixes I made it an actual example that will show up on the package docs
2026-03-23 21:28:47 +01:00
Laytan 99dffb344a Merge pull request #6424 from andzdroid/patch-4
encoding/cbor: fix order-dependent partial unmarshals
2026-03-16 15:17:57 +01:00
andzdroid f123fb1e91 encoding/cbor: fix order-dependent partial unmarshals 2026-03-15 13:20:57 +00:00
gingerBillandLaytan 7b0121756c Update core/encoding/cbor/marshal.odin
Co-authored-by: Laytan <laytanlaats@hotmail.com>
2026-03-14 16:22:01 +00:00
gingerBill e485d82c9d cbor support for fixed capacity dynamic arrays 2026-03-12 13:01:29 +00:00
gingerBill 4df2de057b Add Type_Info_Fixed_Capacity_Dynamic_Array to json 2026-03-11 18:43:01 +00:00
Jeroen van Rijn 82b3917300 Update unicode.xml to 17 2026-02-21 14:02:41 +01:00
Jeroen van Rijn ac11491979 Update generated table 2026-02-21 01:55:07 +01:00
Krzesimir Nowak a90f2ad3a0 Print errors in tools and examples to stderr 2026-02-17 23:08:32 +01:00
Krzesimir Nowak 47775214d6 Fix some tools and examples after core:os update and using-stmt feature 2026-02-17 21:58:08 +01:00
Jeroen van Rijn 2622c1ab99 Fix #6229
Fixes #6229 by adding `encode_upper` and `encode_upper_into_writer`.

Also updated the documentation to be more like the rest of `core`.
2026-02-14 13:57:02 +01:00
Jeroen van Rijn c0300a3303 Remove core:mem imports from core:encoding. 2026-02-12 18:19:24 +01:00
Jeroen van Rijn e7dbabf668 core:os -> core:os/old && core:os/os2 -> core:os 2026-02-09 15:50:21 +01:00
Jeroen van Rijn 8ed264680b Remove all core:os imports from JS targets
Fix `local_tz_name` on FreeBSD.
2026-02-09 15:07:27 +01:00
Jeroen van Rijn 02477b2526 eprintf 2026-02-08 12:44:06 +01:00
Jeroen van Rijn e094de5874 Add loc := #caller_location to read_entire_file 2026-02-08 12:44:05 +01:00
Jeroen van Rijn f63c209478 Convert core:encoding/hxa 2026-02-08 12:42:26 +01:00
Jeroen van Rijn 304f22c8af core:os -> core:os/os for CSV, INI, and XML
Also had to vendor `core:encoding/ini` into `core:os/os2` for the user directories on *nix,
as it used that package to read `~/.config/user-dirs.dirs`, causing an import cycle.
2026-02-08 12:42:24 +01:00
Isabella Basso 56445dff97 encoding/xml: pass allocator on destroy 2026-01-25 21:33:23 -03:00
Jeroen van Rijn 3f8a32aeb9 Merge branch 'master' into xmlcomment 2026-01-22 11:47:23 +01:00
gingerBill 0de3d872d1 Keep -vet happy 2026-01-19 19:32:41 +00:00
gingerBill 85b3251105 Remove the nbsp change, as it is not necessary 2026-01-19 19:30:37 +00:00
gingerBill fddc732869 Escape non-breaking space (0xa0) to &nbsp; 2026-01-19 18:17:13 +00:00