CborValidateTagUse rejects valid tag 1 (epoch) with a floating-point value, and restricts tags 21-23 too much
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 86/100
Direzione di ricerca
Esamina src/cborvalidation.c e la tabella knownTagData, quindi segui il modo in cui cbor_value_validate applica CborValidateTagUse. Esegui dei test sul tag 1 con valori interi e a virgola mobile e sui tag 21–23 con diversi tipi di contenuto; il lavoro è completato quando questi casi validi di RFC 8949 restituiscono CborNoError e le restrizioni esistenti rimangono coperte.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
CborValidateTagUse refuses valid CBOR for two groups of tags, because of the knownTagData table in src/cborvalidation.c (checked at main, 213155c8, and in the v7.0 release).
Tag 1 (epoch-based date/time) with a float
{ 1, (uint32_t)(CborIntegerType+1) },
allows only an integer. RFC 8949 §3.4.2 says:
The tag content MUST be an unsigned or negative integer (major types 0 and 1) or a floating-point number (major type 7 with additional information 25, 26, or 27).
So RFC 8949's own Appendix A example 1(1363896240.5), c1fb41d452d9ec200000, fails validation with CborErrorInappropriateTagForType:
static const uint8_t item[] = {0xc1, 0xfb, 0x41, 0xd4, 0x52, 0xd9, 0xec, 0x20, 0x00, 0x00};
CborParser parser;
CborValue it;
cbor_parser_init(item, sizeof item, 0, &parser, &it);
CborError err = cbor_value_validate(&it, CborValidateTagUse);
/* err == CborErrorInappropriateTagForType; expected CborNoError */
The same happens for a half or single-precision float under tag 1.
Tags 21, 22 and 23
These entries allow only a byte string, array or map. RFC 8949 §3.4.5.2 says:
The data item tagged can be a byte string or any other data item.
So, for example, 21("text") (d5 64 74 65 78 74) or 23(1) (d7 01) is refused, although it is valid.
Suggested fix
- Tag 1: allow
CborHalfFloatType,CborFloatTypeandCborDoubleTypealongside the integer. - Tags 21–23: give them no type restriction, as tag 55799 has.
(Found while writing conformance tests for an R binding of TinyCBOR, zucbor, which now checks tag content itself as a workaround.)
- Lingua principale
- C
- Stelle
- 632
- Fork
- 222
- Merge medio
- 1g 25m
- PR unite (30g)
- 2
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di intel/tinycbor
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
-
CBOR validation not worksAperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
-
Fixing CI/CDAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 25/100
Tutte le issue di intel/tinycbor
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
fastfetch-cli/fastfetch#2628 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
FujiNetWIFI/fujinet-firmware#1736 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 3 giorni
-
Unix 1 can't be startedAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
obsolescence/pidp11#20 ·