]> git.proxmox.com Git - mirror_qemu.git/blame - qobject/json-streamer.c
json: Fix latent parser aborts at end of input
[mirror_qemu.git] / qobject / json-streamer.c
CommitLineData
d7ff3acb
AL
1/*
2 * JSON streaming support
3 *
4 * Copyright IBM, Corp. 2009
5 *
6 * Authors:
7 * Anthony Liguori <aliguori@us.ibm.com>
8 *
9 * This work is licensed under the terms of the GNU LGPL, version 2.1 or later.
10 * See the COPYING.LIB file in the top-level directory.
11 *
12 */
13
f2ad72b3 14#include "qemu/osdep.h"
d7ff3acb 15#include "qemu-common.h"
84a56f38 16#include "qapi/error.h"
7b1b5d19 17#include "qapi/qmp/json-lexer.h"
62815d85 18#include "qapi/qmp/json-parser.h"
7b1b5d19 19#include "qapi/qmp/json-streamer.h"
d7ff3acb 20
29c75ddd 21#define MAX_TOKEN_SIZE (64ULL << 20)
df649835 22#define MAX_TOKEN_COUNT (2ULL << 20)
29c75ddd
AL
23#define MAX_NESTING (1ULL << 10)
24
ba4dba54
EB
25static void json_message_free_token(void *token, void *opaque)
26{
27 g_free(token);
28}
29
95385fe9
PB
30static void json_message_free_tokens(JSONMessageParser *parser)
31{
32 if (parser->tokens) {
ba4dba54 33 g_queue_foreach(parser->tokens, json_message_free_token, NULL);
95385fe9
PB
34 g_queue_free(parser->tokens);
35 parser->tokens = NULL;
36 }
37}
38
037f2440
MA
39void json_message_process_token(JSONLexer *lexer, GString *input,
40 JSONTokenType type, int x, int y)
d7ff3acb
AL
41{
42 JSONMessageParser *parser = container_of(lexer, JSONMessageParser, lexer);
ff281a27 43 QObject *json = NULL;
62815d85 44 Error *err = NULL;
9bada897 45 JSONToken *token;
d7ff3acb 46
c5461660
MA
47 switch (type) {
48 case JSON_LCURLY:
49 parser->brace_count++;
50 break;
51 case JSON_RCURLY:
52 parser->brace_count--;
53 break;
54 case JSON_LSQUARE:
55 parser->bracket_count++;
56 break;
57 case JSON_RSQUARE:
58 parser->bracket_count--;
59 break;
269e57ae 60 case JSON_ERROR:
84a56f38 61 error_setg(&err, "JSON parse error, stray '%s'", input->str);
269e57ae 62 goto out_emit;
c5461660
MA
63 default:
64 break;
d7ff3acb
AL
65 }
66
9bada897
PB
67 token = g_malloc(sizeof(JSONToken) + input->len + 1);
68 token->type = type;
69 memcpy(token->str, input->str, input->len);
70 token->str[input->len] = 0;
71 token->x = x;
72 token->y = y;
d7ff3acb 73
d2ca7c0b 74 parser->token_size += input->len;
29c75ddd 75
9bada897 76 g_queue_push_tail(parser->tokens, token);
d7ff3acb 77
ff281a27 78 if (parser->brace_count < 0 ||
55f8301f
AL
79 parser->bracket_count < 0 ||
80 (parser->brace_count == 0 &&
81 parser->bracket_count == 0)) {
ff281a27
MA
82 json = json_parser_parse(parser->tokens, parser->ap, &err);
83 parser->tokens = NULL;
5e2dafeb 84 goto out_emit;
ff281a27
MA
85 }
86
84a56f38
MA
87 /*
88 * Security consideration, we limit total memory allocated per object
89 * and the maximum recursion depth that a message can force.
90 */
91 if (parser->token_size > MAX_TOKEN_SIZE) {
92 error_setg(&err, "JSON token size limit exceeded");
93 goto out_emit;
94 }
95 if (g_queue_get_length(parser->tokens) > MAX_TOKEN_COUNT) {
96 error_setg(&err, "JSON token count limit exceeded");
97 goto out_emit;
98 }
99 if (parser->bracket_count + parser->brace_count > MAX_NESTING) {
100 error_setg(&err, "JSON nesting depth limit exceeded");
ff281a27 101 goto out_emit;
5e2dafeb
MR
102 }
103
104 return;
105
5e2dafeb 106out_emit:
5e2dafeb
MR
107 parser->brace_count = 0;
108 parser->bracket_count = 0;
ff281a27 109 json_message_free_tokens(parser);
95385fe9 110 parser->tokens = g_queue_new();
5e2dafeb 111 parser->token_size = 0;
62815d85 112 parser->emit(parser->opaque, json, err);
d7ff3acb
AL
113}
114
115void json_message_parser_init(JSONMessageParser *parser,
62815d85
MA
116 void (*emit)(void *opaque, QObject *json,
117 Error *err),
118 void *opaque, va_list *ap)
d7ff3acb 119{
62815d85
MA
120 parser->emit = emit;
121 parser->opaque = opaque;
122 parser->ap = ap;
d7ff3acb
AL
123 parser->brace_count = 0;
124 parser->bracket_count = 0;
95385fe9 125 parser->tokens = g_queue_new();
29c75ddd 126 parser->token_size = 0;
d7ff3acb 127
2cbd15aa 128 json_lexer_init(&parser->lexer, !!ap);
d7ff3acb
AL
129}
130
7c1e1d54 131void json_message_parser_feed(JSONMessageParser *parser,
d7ff3acb
AL
132 const char *buffer, size_t size)
133{
7c1e1d54 134 json_lexer_feed(&parser->lexer, buffer, size);
d7ff3acb
AL
135}
136
7c1e1d54 137void json_message_parser_flush(JSONMessageParser *parser)
d7ff3acb 138{
7c1e1d54 139 json_lexer_flush(&parser->lexer);
d7ff3acb
AL
140}
141
142void json_message_parser_destroy(JSONMessageParser *parser)
143{
144 json_lexer_destroy(&parser->lexer);
95385fe9 145 json_message_free_tokens(parser);
d7ff3acb 146}