Description
jsonb::jsonpath::parse_json_path panics on an unterminated double-quoted field instead of returning a parse error. Reproduced with the published jsonb 0.5.6 release (also observed with 0.4.4).
Minimal reproduction
Cargo.toml:
[package]
name = "jsonb-jsonpath-repro"
version = "0.1.0"
edition = "2024"
[dependencies]
jsonb = { version = "=0.5.6", default-features = false, features = ["databend"] }
src/main.rs:
fn main() {
let path = r#"$."a"#; // Input is $."a, with no closing double quote.
println!("{:?}", jsonb::jsonpath::parse_json_path(path.as_bytes()));
}
Run cargo run.
Actual behavior
panicked at .../jsonb-0.5.6/src/jsonpath/parser.rs:159:34:
range start index 3 out of range for slice of length 2
The following inputs were tested independently and all panic:
The valid control input $."a" parses successfully.
Expected behavior
Return Err(Error::InvalidJsonPath) for an unterminated quoted field, without panicking. This matters when JSONPath expressions come from user-supplied SQL queries.
Apparent cause
In src/jsonpath/parser.rs, string() scans until a closing double quote or the end of the input. When the closing quote is missing, i reaches input.len(), but the subsequent code can still evaluate &input[i + 1..].
Checking that the closing quote was actually found before building the remaining-input slice should prevent this out-of-bounds access. A regression test should cover unterminated quoted fields, including escaped content, while retaining valid quoted-field behavior.
Description
jsonb::jsonpath::parse_json_pathpanics on an unterminated double-quoted field instead of returning a parse error. Reproduced with the publishedjsonb0.5.6 release (also observed with 0.4.4).Minimal reproduction
Cargo.toml:src/main.rs:Run
cargo run.Actual behavior
The following inputs were tested independently and all panic:
The valid control input
$."a"parses successfully.Expected behavior
Return
Err(Error::InvalidJsonPath)for an unterminated quoted field, without panicking. This matters when JSONPath expressions come from user-supplied SQL queries.Apparent cause
In
src/jsonpath/parser.rs,string()scans until a closing double quote or the end of the input. When the closing quote is missing,ireachesinput.len(), but the subsequent code can still evaluate&input[i + 1..].Checking that the closing quote was actually found before building the remaining-input slice should prevent this out-of-bounds access. A regression test should cover unterminated quoted fields, including escaped content, while retaining valid quoted-field behavior.