Skip to content

v1.0.1

Latest

Choose a tag to compare

@tomofumi-ishida-oss tomofumi-ishida-oss released this 06 Oct 09:04
· 10 commits to main since this release

REDox v1.0.1

This release focuses on security hardening, correctness fixes, and System.Text.Json compatibility.
All packages are updated to version 1.0.1. Preview packages are published as 1.0.1-preview.

Breaking changes

A numeric string that cannot be converted now throws FormatException. (#5)

  • NaN and Infinity string literals for Half, float, and double are accepted only when AllowNamedFloatingPointLiterals is enabled.
    or Settings.Culture for timestamps. (#3)
  • Reading a JSON null into a collection now returns null instead of keeping the existing value.
  • REDox.Csv: Records whose column count differs from the header record are rejected with ColumnCountMismatch. (#4)

REDox

New features

  • Added the DElement[int] indexer for array access, matching JsonElement. Arrays edited after parsing, and parsed arrays that contain only primitive values, are accessed in O(1). Other arrays are accessed in O(n).
  • Added Utf8TextWriter.WriteDateTime and Utf8TextWriter.WriteDateTimeOffset, and allocation-free Utf8Helper.TryFormatTimestamp overloads.
  • Numeric string reference IDs are accepted by DefaultReferenceResolver.

Performance

  • DProperty.NameEquals and GetProperty(string) compare names in the format stored in the document, which removes a string allocation per call.

Security fixes

  • JsonTextEncoder no longer writes unescaped characters, such as " or <, when the input contains invalid UTF-8. Invalid sequences are written as \ufffd.
  • JsonTextEncoder no longer drops the character that follows an unpaired UTF-16 surrogate. Unpaired surrogates are written as \ufffd.
  • Object converters, including the ISerializable path, clone the element they read. This keeps deserialized objects from referring to parser buffers that are returned to ArrayPool and reused.
  • Duplicate() no longer returns the original document's rented source buffer to ArrayPool. The copy also gets its own source.
  • A document and its snapshot no longer share the parent table, so Parent and GetPath() return correct results on both.
  • EncodeTo always disposes pooled writers, even when encoding throws.

Bug fixes

  • Fixed an extend slot leak that made the document grow without limit when a value was repeatedly replaced with an inline literal.
  • Leading trivia can now be added to inline integer and float tokens.
  • Fixed escaped quotes and truncated raw values in large JSON strings that use the compressed length encoding.
    are converted to DateTime correctly. (#1)
  • Time-only DateTimeOffset strings, such as 10:30:10+09:00, keep their offset and date.
  • Timestamp formatting is consistent across text writers. Formatted timestamps are escaped in JSON5.
  • JsonWriter writes ISO 8601 instead of null when a custom format does not fit the buffer.
  • Fixed out-of-bounds reads in Utf8Helper.Equals for truncated UTF-8 sequences and unpaired surrogates.
  • Removed the unused Utf8Helper.Utf8CharsToUtf32Char.

Internal changes

  • The generic collection converters now share a common base, CollectionReadConverter<T, U>.

REDox.Cbor

  • Hardened input validation for malformed and truncated CBOR. Added CborDocumentOptions.MaxLength.
  • MaxLength is now enforced on the total size of indefinite-length byte and text strings.
  • Tags larger than int.MaxValue are no longer truncated to 32 bits. Large tags are not misread as known tags such as BigNum, and they are kept as trivia and round-trip correctly.
  • CborWriter writes big numbers using InvariantCulture.
  • Added regression tests for length overflow in definite-length and indefinite-length strings.

REDox.MessagePack

  • Fixed Ext32 payloads of exactly 16 MiB, which previously returned the wrong length.

REDox.Csv

Previously, the header was extended with empty keys. (#4)

  • Formatted timestamps are escaped so that custom formats containing delimiters, quotes, or line breaks produce valid CSV.

REDox.Toml

  • Keys and strings are escaped according to the output quoting style. This prevents untrusted keys or values from injecting TOML.
    could loop or overflow the stack. (#4)
  • Number and timestamp conversion uses InvariantCulture. (#3)

REDox.Xml

  • MaxDepth is enforced, and unmatched closing tags are rejected.
    Truncated input raises ParseException. (#4)
  • Processing instructions are kept in document order.

REDox.Html

  • Added HtmlDocumentOptions.MaxDepth. The parser stack now grows up to this limit instead of using a fixed-size buffer.

REDox.Ini

  • Timestamp formatting follows the unified text writer behavior.

REDox.Serialization.DataContractJson

is now applied to DateTime and DateTimeOffset values. (#2)

  • Numeric and DateOnly dictionary keys use the current culture, matching DataContractJsonSerializer.
  • ObjectConverter clones the element it reads, so values do not refer to pooled parser buffers.

REDox.Serialization.NewtonsoftJson

  • BigInteger conversion uses InvariantCulture.

Documentation

The section also explains which types are safe to use from multiple threads.

Acknowledgements

Thanks to the following people for reporting issues in this release: