Repository navigation
·
10 commits
to main
since this release
REDox v1.0.1
This release focuses on security hardening, correctness fixes, and System.Text.Json compatibility.
All packages are updated to version 1.0.1. Preview packages are published as 1.0.1-preview.
Breaking changes
A numeric string that cannot be converted now throws FormatException. (#5)
NaNandInfinitystring literals forHalf,float, anddoubleare accepted only whenAllowNamedFloatingPointLiteralsis enabled.
orSettings.Culturefor timestamps. (#3)- Reading a JSON
nullinto a collection now returnsnullinstead of keeping the existing value. - REDox.Csv: Records whose column count differs from the header record are rejected with
ColumnCountMismatch. (#4)
REDox
New features
- Added the
DElement[int]indexer for array access, matchingJsonElement. Arrays edited after parsing, and parsed arrays that contain only primitive values, are accessed in O(1). Other arrays are accessed in O(n). - Added
Utf8TextWriter.WriteDateTimeandUtf8TextWriter.WriteDateTimeOffset, and allocation-freeUtf8Helper.TryFormatTimestampoverloads. - Numeric string reference IDs are accepted by
DefaultReferenceResolver.
Performance
DProperty.NameEqualsandGetProperty(string)compare names in the format stored in the document, which removes a string allocation per call.
Security fixes
JsonTextEncoderno longer writes unescaped characters, such as"or<, when the input contains invalid UTF-8. Invalid sequences are written as\ufffd.JsonTextEncoderno longer drops the character that follows an unpaired UTF-16 surrogate. Unpaired surrogates are written as\ufffd.- Object converters, including the
ISerializablepath, clone the element they read. This keeps deserialized objects from referring to parser buffers that are returned toArrayPooland reused. Duplicate()no longer returns the original document's rented source buffer toArrayPool. The copy also gets its own source.- A document and its snapshot no longer share the parent table, so
ParentandGetPath()return correct results on both. EncodeToalways disposes pooled writers, even when encoding throws.
Bug fixes
- Fixed an extend slot leak that made the document grow without limit when a value was repeatedly replaced with an inline literal.
- Leading trivia can now be added to inline integer and float tokens.
- Fixed escaped quotes and truncated raw values in large JSON strings that use the compressed length encoding.
are converted toDateTimecorrectly. (#1) - Time-only
DateTimeOffsetstrings, such as10:30:10+09:00, keep their offset and date. - Timestamp formatting is consistent across text writers. Formatted timestamps are escaped in JSON5.
JsonWriterwrites ISO 8601 instead ofnullwhen a custom format does not fit the buffer.- Fixed out-of-bounds reads in
Utf8Helper.Equalsfor truncated UTF-8 sequences and unpaired surrogates. - Removed the unused
Utf8Helper.Utf8CharsToUtf32Char.
Internal changes
- The generic collection converters now share a common base,
CollectionReadConverter<T, U>.
REDox.Cbor
- Hardened input validation for malformed and truncated CBOR. Added
CborDocumentOptions.MaxLength. MaxLengthis now enforced on the total size of indefinite-length byte and text strings.- Tags larger than
int.MaxValueare no longer truncated to 32 bits. Large tags are not misread as known tags such as BigNum, and they are kept as trivia and round-trip correctly. CborWriterwrites big numbers usingInvariantCulture.- Added regression tests for length overflow in definite-length and indefinite-length strings.
REDox.MessagePack
- Fixed Ext32 payloads of exactly 16 MiB, which previously returned the wrong length.
REDox.Csv
Previously, the header was extended with empty keys. (#4)
- Formatted timestamps are escaped so that custom formats containing delimiters, quotes, or line breaks produce valid CSV.
REDox.Toml
- Keys and strings are escaped according to the output quoting style. This prevents untrusted keys or values from injecting TOML.
could loop or overflow the stack. (#4) - Number and timestamp conversion uses
InvariantCulture. (#3)
REDox.Xml
MaxDepthis enforced, and unmatched closing tags are rejected.
Truncated input raisesParseException. (#4)- Processing instructions are kept in document order.
REDox.Html
- Added
HtmlDocumentOptions.MaxDepth. The parser stack now grows up to this limit instead of using a fixed-size buffer.
REDox.Ini
- Timestamp formatting follows the unified text writer behavior.
REDox.Serialization.DataContractJson
is now applied to DateTime and DateTimeOffset values. (#2)
- Numeric and
DateOnlydictionary keys use the current culture, matchingDataContractJsonSerializer. ObjectConverterclones the element it reads, so values do not refer to pooled parser buffers.
REDox.Serialization.NewtonsoftJson
BigIntegerconversion usesInvariantCulture.
Documentation
The section also explains which types are safe to use from multiple threads.
Acknowledgements
Thanks to the following people for reporting issues in this release: