CborValidateTagUse rejects valid tag 1 (epoch) with a floating-point value, and restricts tags 21-23 too much
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 86/100
Línea de trabajo
Inspecciona src/cborvalidation.c y la tabla knownTagData, y luego sigue cómo cbor_value_validate aplica CborValidateTagUse. Prueba el tag 1 con valores enteros y de coma flotante, y los tags 21–23 con distintos tipos de contenido; se considera terminado cuando estos casos válidos de RFC 8949 devuelvan CborNoError y las restricciones existentes sigan estando cubiertas.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
CborValidateTagUse refuses valid CBOR for two groups of tags, because of the knownTagData table in src/cborvalidation.c (checked at main, 213155c8, and in the v7.0 release).
Tag 1 (epoch-based date/time) with a float
{ 1, (uint32_t)(CborIntegerType+1) },
allows only an integer. RFC 8949 §3.4.2 says:
The tag content MUST be an unsigned or negative integer (major types 0 and 1) or a floating-point number (major type 7 with additional information 25, 26, or 27).
So RFC 8949's own Appendix A example 1(1363896240.5), c1fb41d452d9ec200000, fails validation with CborErrorInappropriateTagForType:
static const uint8_t item[] = {0xc1, 0xfb, 0x41, 0xd4, 0x52, 0xd9, 0xec, 0x20, 0x00, 0x00};
CborParser parser;
CborValue it;
cbor_parser_init(item, sizeof item, 0, &parser, &it);
CborError err = cbor_value_validate(&it, CborValidateTagUse);
/* err == CborErrorInappropriateTagForType; expected CborNoError */
The same happens for a half or single-precision float under tag 1.
Tags 21, 22 and 23
These entries allow only a byte string, array or map. RFC 8949 §3.4.5.2 says:
The data item tagged can be a byte string or any other data item.
So, for example, 21("text") (d5 64 74 65 78 74) or 23(1) (d7 01) is refused, although it is valid.
Suggested fix
- Tag 1: allow
CborHalfFloatType,CborFloatTypeandCborDoubleTypealongside the integer. - Tags 21–23: give them no type restriction, as tag 55799 has.
(Found while writing conformance tests for an R binding of TinyCBOR, zucbor, which now checks tag content itself as a workaround.)
- Lenguaje dominante
- C
- Estrellas
- 634
- Forks
- 222
- Merge medio
- 1 d 25 min
- PR fusionados (30 d)
- 2
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de intel/tinycbor
-
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
-
CBOR validation not worksAbierto
Dificultad 3/5 1-2 días Aptitud para principiantes 35/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 38/100
-
Fixing CI/CDAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 25/100
Todos los issues de intel/tinycbor
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
Los mantenedores suelen responder en 1 día
-
severity: low
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
luainkernel/lunatik#1853 ·
Los mantenedores suelen responder en 1 día
-
encoding.binary: bounds check guard is compiled away, so decode functions read past the sliceAbierto
Dificultad 2/5 Medio día Aptitud para principiantes 70/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
resetes12/pokeemerald#204 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Los mantenedores suelen responder en 6 días