Skip to content

Fix nil pointer dereference on whole-document operations without a value - #223

Open
AmazinMax wants to merge 2 commits into
evanphx:masterfrom
AmazinMax:fix-missing-value-on-root
Open

AmazinMax wants to merge 2 commits into
evanphx:masterfrom
AmazinMax:fix-missing-value-on-root

Conversation

@AmazinMax

Copy link
Copy Markdown

Applying an add, replace or test operation with an empty path and no value member dereferences a nil *lazyNode and panics. This affects both v4 and v5:

Patch v4.13.0 v5.9.11
[{"op":"replace","path":""}] panic rejected by DecodePatch, panic if the Patch is built directly
[{"op":"add","path":""}] error rejected by DecodePatch, panic if the Patch is built directly
[{"op":"test","path":""}] panic panic

Reproducer:

p, _ := jsonpatch.DecodePatch([]byte(`[{"op":"test","path":""}]`))
p.Apply([]byte(`{"foo":"bar"}`)) // panic: runtime error: invalid memory address or nil pointer dereference

The replace case was reported in #168, which was closed, but it still reproduces on v4.13.0. #114 / #158 fixed the same panic for test with a non-empty path, but not for the whole document.

This matters for servers that apply patches received from clients. For example, kube-apiserver applies user-supplied JSON Patch documents with v4, so any user allowed to patch a resource can trigger the panic with a single request.

Changes

  • add (v5) and replace (v4, v5) with an empty path and no value return an error wrapping ErrMissing.
  • test with an empty path and no value fails with ErrTestFailed. This keeps the existing semantics of test, where a missing value is treated as null (see the test cases without a value in TestCases), and the whole document is never null.
  • Operations with a non-empty path are not changed.

The v4 and v5 changes are in separate commits, so either can be taken on its own.

Tests

  • New entries in BadCases and TestCases for v4 and v5.
  • TestMissingValueOnWholeDocument in v5 builds the Patch without DecodePatch, because DecodePatch already rejects add and replace without a value.
  • Without the fix, the new cases panic in both go test runs. v4 has no go.mod and is not run in CI, so I ran its tests with a temporary go.mod (module gopkg.in/evanphx/json-patch.v4).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant