Files
Odin/tests/core/encoding/json
Jack Mordaunt 641844dae7 core/encoding/json: size the unquote buffer for replaced invalid UTF-8
unquote_string replaces each byte that is not valid UTF-8 with U+FFFD,
which is three bytes for one, but sized its buffer as len(s) + 2*UTF_MAX:
slack for a single replacement, not for one per invalid byte. A string
holding several ran the write cursor past the end, an out-of-range slice
under bounds checking and a memory-safety bug without it.

Count the invalid bytes in the remainder up front and size for them. The
escape sequences never grow their input, so they need no allowance.
2026-09-25 14:27:40 -03:00
..