Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

CborValidateTagUse rejects valid tag 1 (epoch) with a floating-point value, and restricts tags 21-23 too much

Aperta Adatta ai principianti
#339 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
86/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
c
Ambito
backend

Direzione di ricerca

Esamina src/cborvalidation.c e la tabella knownTagData, quindi segui il modo in cui cbor_value_validate applica CborValidateTagUse. Esegui dei test sul tag 1 con valori interi e a virgola mobile e sui tag 21–23 con diversi tipi di contenuto; il lavoro è completato quando questi casi validi di RFC 8949 restituiscono CborNoError e le restrizioni esistenti rimangono coperte.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

CborValidateTagUse refuses valid CBOR for two groups of tags, because of the knownTagData table in src/cborvalidation.c (checked at main, 213155c8, and in the v7.0 release).

Tag 1 (epoch-based date/time) with a float
{ 1, (uint32_t)(CborIntegerType+1) },

allows only an integer. RFC 8949 §3.4.2 says:

The tag content MUST be an unsigned or negative integer (major types 0 and 1) or a floating-point number (major type 7 with additional information 25, 26, or 27).

So RFC 8949's own Appendix A example 1(1363896240.5), c1fb41d452d9ec200000, fails validation with CborErrorInappropriateTagForType:

static const uint8_t item[] = {0xc1, 0xfb, 0x41, 0xd4, 0x52, 0xd9, 0xec, 0x20, 0x00, 0x00};
CborParser parser;
CborValue it;
cbor_parser_init(item, sizeof item, 0, &parser, &it);
CborError err = cbor_value_validate(&it, CborValidateTagUse);
/* err == CborErrorInappropriateTagForType; expected CborNoError */

The same happens for a half or single-precision float under tag 1.

Tags 21, 22 and 23

These entries allow only a byte string, array or map. RFC 8949 §3.4.5.2 says:

The data item tagged can be a byte string or any other data item.

So, for example, 21("text") (d5 64 74 65 78 74) or 23(1) (d7 01) is refused, although it is valid.

Suggested fix
  • Tag 1: allow CborHalfFloatType, CborFloatType and CborDoubleType alongside the integer.
  • Tags 21–23: give them no type restriction, as tag 55799 has.

(Found while writing conformance tests for an R binding of TinyCBOR, zucbor, which now checks tag content itself as a workaround.)

Lingua principale
C
Stelle
632
Fork
222
Merge medio
1g 25m
PR unite (30g)
2

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di intel/tinycbor

Tutte le issue di intel/tinycbor

Issue simili

Altre issue su C

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.