Skip to content

Count empty containers toward parser nesting limits - #1089

Closed
ydah wants to merge 1 commit into
ruby:masterfrom
ydah:fix-empty-container-nesting
Closed

ydah wants to merge 1 commit into
ruby:masterfrom
ydah:fix-empty-container-nesting

Conversation

@ydah

@ydah ydah commented Oct 1, 2026

Copy link
Copy Markdown
Member

The parser skips the nesting check for empty arrays and objects, accepting structures that the generator rejects with the same max_nesting setting.

require "json"

JSON.parse("[[]]", max_nesting: 1)
# Before: [[]]
# After: raises JSON::NestingError, matching JSON.generate([[]], max_nesting: 1).

Check the nesting limit before handling empty containers in both the C and Java parsers. Add regression tests for empty arrays and objects, including ResumableParser with split input.

@byroot

byroot commented Oct 1, 2026

Copy link
Copy Markdown
Member

Thanks but this was deliberate. The goal of max_nesting isn't to be particularly precise, but to protect against DOS style of attacks. I chose to skip the depth increment/decrement for empty containers for performance reasons.

@byroot byroot closed this Oct 1, 2026
@ydah
ydah deleted the fix-empty-container-nesting branch October 1, 2026 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants