ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/JSON-XS/Changes
Revision: 1.196
Committed: Fri Sep 5 21:32:34 2025 UTC (12 months, 1 week ago) by root
Branch: MAIN
Changes since 1.195: +1 -0 lines
Log Message:
*** empty log message ***

File Contents

# Content
1 Revision history for Perl extension JSON::XS
2
3 TODO: maybe detect and croak on more invalid inputs (e.g. +-inf/nan)
4 TODO: maybe avoid the reblessing and better support readonly objects.
5 TODO: how to cope with tagged values and standard json decoders
6 TODO: investigate magic (Eric Brine)
7 TODO: [PATCH] Types::Serialiser: Inline true(), false() and error() functions
8 TODO: replace bool_stash by BOOL_STASH seems to work with mod_perl, make a compile time option?
9 TODO: https://github.com/ulfjack/ryu https://lemire.me/blog/2020/03/10/fast-float-parsing-in-practice/ / https://github.com/lemire/fast_double_parser
10
11 TODO: validate_utf8, apparewntly some people confuse themselves.
12 TODO: security considerations
13
14 TODO: perl 5.36 has builtin::true/false/is_bool. Not sure how to integrate those.
15 TODO: Peter Juhasz <peter.juhasz@comnica.com>: '11111111111111111111111e1111111111111111111' is parsed as 0
16 # copy freed scalart()??)
17 <config.json runIP-radar eval '
18 use JSON::XS;
19 local $/;
20 my $cfg = decode_json scalar <>;
21 $cfg->{login_background} = Types::Serialiser::as_bool $ARGV[0] eq "";
22 print JSON::XS->new->pretty->utf8->encode ($cfg);
23 ' "$LBUI_ENABLE"
24
25
26 4.03 Tue Oct 27 19:05:01 CET 2020
27 - when parsing comments in relaxed mode, JSON::XS would detect garbage
28 after the JSON text if the comment is after the end and does not end in
29 a newline (reported by Felipe Gasper).
30
31 4.02 Wed Mar 6 08:31:24 CET 2019
32 - undo the fix from 4.01, it breaks more things than it fixes
33 (another testcase by Wesley Schwengle).
34 - try a proper fix this time.
35
36 4.01 Sun Feb 24 05:03:30 CET 2019
37 - fix some stack corruption caused mostly when calling methods
38 in list context (testcase by Wesley Schwengle).
39
40 4.0 Fri Nov 16 00:06:54 CET 2018
41 - SECURITY IMPLICATION: this release enables allow_nonref by default
42 for compatibility with RFC 7159 and newer. See "old" vs. "new"
43 JSON under SECURITY CONSIDERATIONS.
44 - reworked the "old" vs. "new" JSON section.
45 - add ->boolean_values to provide the values to which booleans
46 decode (requested by Aristotle Pagaltzis).
47 - decode would wrongly accept ASCII NUL characters instead of
48 reporting them as trailing garbage.
49 - work around what smells like a perl bug w.r.t. exceptions
50 thrown in callbacks.
51 - incremental parser now more or less respects allow_nonref.
52 - json_xs json-pretty now enables canonical mode.
53 - add documentation section about I-JSON.
54 - minor documentation fixes/updates.
55
56 3.04 Thu Aug 17 04:30:47 CEST 2017
57 - change exponential realloc algorithm on encoding and string decoding to be
58 really exponential (this helps slow/debugging allocators such as libumem)
59 (reported by Matthew Horsfall).
60 - string encoding would needlessly overallocate output space
61 (testcase by Matthew Horsfall).
62 - be very paranoid about extending buffer lengths and croak if buffers get too large,
63 which might (or might not) improve security.
64 - add cbor-packed type to json_xs.
65 - switch from YAML to YAML::XS in json_xs, as YAML is way too buggy and outdated.
66
67 3.03 Wed Nov 16 20:20:59 CET 2016
68 - fix a bug introduced by a perl bug workaround that would cause
69 incremental parsing to fail with a sv_chop panic.
70 - json_xs: toformat failure error message fixed.
71 - json_xs: allow cyclic data structures in CBOR.
72
73 3.02 Fri Feb 26 22:45:20 CET 2016
74 - allow_nonref now affects booleans (\1, $Types::Serialiser::Boolean)
75 as well (reported by Alex Efros).
76 - allow literal tabs in strings in relaxed mode (patch by
77 lubo.rintel@gooddata.com).
78 - support "cbor" format in json_xs tool.
79 - support (and fix) calling encode and decode in list context
80 (reported by Вадим Власов).
81 - work around a bug in older perls crashing when presented
82 with shared hash keys (Reini Urban).
83 - use stability canary.
84
85 3.01 Tue Oct 29 16:55:15 CET 2013
86 - backport to perls < 5.18 (reported by Paul Howarth).
87
88 3.0 Tue Oct 29 01:35:37 CET 2013
89 - implemented an object tagging extension (using the
90 Types::Serialiser serialisation protocol).
91 - reworked the documentation regarding object serialisation,
92 add a new OBJECT SERIALISATION section that explains th
93 whole process.
94 - new setting: allow_tags.
95 - switch to Types::Serialiser booleans.
96 - remove to_json/from_json.
97 - other minor improvements to the documentation.
98
99 2.34 Thu May 23 11:30:34 CEST 2013
100 - work around bugs in perl 5.18 breaking more than 100
101 widely used modules, without a fix in sight because
102 p5pers don't care about CPAN anymore.
103 - when canonicalising, only allocate up to 64 hash key
104 pointers on the stack. for larger hashes, use the heap,
105 to avoid using too much stackspace.
106 - discuss the problem with setlocale (reported by a few victims).
107
108 2.33 Wed Aug 1 21:03:52 CEST 2012
109 - internal encode/decode XS wrappers did not expect stack
110 moves caused by callbacks (analyzed and testcase by Jesse Luehrs).
111 - add bencode as to/from option in bin/json_xs.
112 - add -e option to json_xs, and none and string in/out formats.
113
114 2.32 Thu Aug 11 19:06:38 CEST 2011
115 - fix a bug in the initial whitespace accumulation.
116
117 2.31 Wed Jul 27 17:53:05 CEST 2011
118 - don't accumulate initial whitespace in the incremental buffer
119 (this can be useful to allow whitespace-keepalive on a tcp
120 connection without triggering the max_size limit).
121 - properly croak on some invalid inputs that are not strings
122 (e.g. undef) when trying to decode a json text (reported
123 and analyzed by Goro Fuji).
124
125 2.3 Wed Aug 18 01:26:47 CEST 2010
126 - make sure decoder doesn't change the decoding in the incremental
127 parser (testcase provided by Hendrik Schumacher).
128 - applied patch by DaTa for Data::Dumper support in json_xs.
129 - added -t dump support to json_xs, using Data::Dump.
130 - added -f eval support to json_xs.
131
132 2.29 Wed Mar 17 02:39:12 CET 2010
133 - fix a memory leak when callbacks set using filter_json_object
134 or filter_json_single_key_object were called (great testcase
135 by Eric Wilhelm).
136
137 2.28 Thu Mar 11 20:30:46 CET 2010
138 - implement our own atof function - perl's can be orders of
139 magnitudes slower than even the system one. on the positive
140 side, ours seems to be more exact in general than perl's.
141 (testcase provided by Tim Meadowcroft).
142 - clarify floating point conversion issues a bit.
143 - update jpsykes csrf article url.
144 - updated benchmark section - JSON::PP became much faster!
145
146 2.27 Thu Jan 7 07:35:08 CET 2010
147 - support relaxed option inside the incremental parser
148 (testcase provided by IKEGAMI via Makamaka).
149
150 2.26 Sat Oct 10 03:26:19 CEST 2009
151 - big integers could become truncated (based on patch
152 by Strobl Anton).
153 - output format change: indent now adds a final newline, which is
154 more expected and more true to the documentation.
155
156 2.25 Sat Aug 8 12:04:41 CEST 2009
157 - the perl debugger completely breaks lvalue subs - try to work
158 around the issue.
159 - ignore RMAGICAL hashes w.r.t. CANONICAL.
160 - try to work around a possible char signedness issue on aix.
161 - require common sense.
162
163 2.24 Sat May 30 08:25:45 CEST 2009
164 - the incremental parser did not update its parse offset
165 pointer correctly when parsing utf8-strings (nicely
166 debugged by Martin Evans).
167 - appending a non-utf8-string to the incremental parser
168 in utf8 mode failed to upgrade the string.
169 - wording of parse error messages has been improved.
170
171 2.232 Sun Feb 22 11:12:25 CET 2009
172 - use an exponential algorithm to extend strings, to
173 help platforms with bad or abysmal==windows memory
174 allocater performance, at the expense of some memory
175 wastage (use shrink to recover this extra memory).
176 (nicely analysed by Dmitry Karasik).
177
178 2.2311 Thu Feb 19 02:12:54 CET 2009
179 - add a section "JSON and ECMAscript" to explain some
180 incompatibilities between the two (problem was noted by
181 various people).
182 - add t/20_faihu.t.
183
184 2.231 Thu Nov 20 04:59:08 CET 2008
185 - work around 5.10.0 magic bugs where manipulating magic values
186 (such as $1) would permanently damage them as perl would
187 ignore the magicalness, by making a full copy of the string,
188 reported by Dmitry Karasik.
189 - work around spurious warnings under older perl 5.8's.
190
191 2.23 Mon Sep 29 05:08:29 CEST 2008
192 - fix a compilation problem when perl is not using char * as, well,
193 char *.
194 - use PL_hexdigit in favour of rolling our own.
195
196 2.2222 Sun Jul 20 18:49:00 CEST 2008
197 - same game again, broken 5.10 finds yet another assertion
198 failure, and the workaround causes additional runtime warnings.
199 Work around the next assertion AND the warning. 5.10 seriously
200 needs to adjust it's attitude against working code.
201
202 2.222 Sat Jul 19 06:15:34 CEST 2008
203 - you work around one -DDEBUGGING assertion bug in perl 5.10
204 just to hit the next one. work around this one, too.
205
206 2.22 Tue Jul 15 13:26:51 CEST 2008
207 - allow higher nesting levels in incremental parser.
208 - error out earlier in some cases in the incremental parser
209 (as suggested by Yuval Kogman).
210 - improve incr-parser test (Yuval Kogman).
211
212 2.21 Tue Jun 3 08:43:23 CEST 2008
213 - (hopefully) work around a perl 5.10 bug with -DDEBUGGING.
214 - remove the experimental status of the incremental parser interface.
215 - move =encoding around again, to avoid bugs with search.cpan.org.
216 when can we finally have utf-8 in pod???
217 - add ->incr_reset method.
218
219 2.2 Wed Apr 16 20:37:25 CEST 2008
220 - lifted the log2 rounding restriction of max_depth and max_size.
221 - make booleans mutable by creating a copy instead of handing out
222 the same scalar (reported by pasha sadri).
223 - added support for incremental json parsing (still EXPERIMENTAL).
224 - implemented and added a json_xs command line utility that can convert
225 from/to a number of serialisation formats - tell me if you need more.
226 - implement allow_unknown/get_allow_unknown methods.
227 - fixed documentation of max_depth w.r.t. higher and equal.
228 - moved down =encoding directive a bit, too much breaks if it's the first
229 pod directive :/.
230 - removed documentation section on other modules, it became somewhat
231 outdated and is nowadays mostly of historical interest.
232
233 2.1 Wed Mar 19 23:23:18 CET 2008
234 - update documentation here and there: add a large section
235 about utf8/latin1/ascii flags, add a security consideration
236 and extend and clarify the JSON and YAML section.
237 - medium speed enhancements when encoding/decoding non-ascii chars.
238 - minor speedup in number encoding case.
239 - extend and clarify the section on incompatibilities
240 between YAML and JSON.
241 - switch to static inline from just inline when using gcc.
242 - add =encoding utf-8 to the manpage, now that perl 5.10 supports it.
243 - fix some issues with UV to JSON conversion of unknown impact.
244 - published the yahoo locals search result used in benchmarks as the
245 original url changes so comparison is impossible.
246
247 2.01 Wed Dec 5 11:40:28 CET 2007
248 - INCOMPATIBLE API CHANGE: to_json and from_json have been
249 renamed to encode_json/decode_json for JSON.pm compatibility.
250 The old functions croak and might be replaced by JSON.pm
251 comaptible versions in some later release.
252
253 2.0 Tue Dec 4 11:30:46 CET 2007
254 - this is supposed to be the first version of JSON::XS
255 compatible with version 2.0+ of the JSON module.
256 Using the JSON module as frontend to JSON::XS should be
257 as fast as using JSON::XS directly, so consider using it
258 instead.
259 - added get_* methods for all "simple" options.
260 - make JSON::XS subclassable.
261
262 1.53 Tue Nov 13 23:58:33 CET 2007
263 - minor doc clarifications.
264 - fixed many doc typos (patch by Thomas L. Shinnick).
265
266 1.52 Mon Oct 15 03:22:06 CEST 2007
267 - remove =encoding pod directive again, it confuses too many pod
268 parsers :/.
269
270 1.51 Sat Oct 13 03:55:56 CEST 2007
271 - encode empty arrays/hashes in a compact way when pretty is enabled.
272 - apparently JSON::XS was used to find some bugs in the
273 JSON_checker testsuite, so add (the corrected) JSON_checker tests to
274 the testsuite.
275 - quite a bit of doc updates/extension.
276 - require 5.8.2, as this seems to be the first unicode-stable version.
277
278 1.5 Tue Aug 28 04:05:38 CEST 2007
279 - add support for tied hashes, based on ideas and testcase by
280 Marcus Holland-Moritz.
281 - implemented relaxed parsing mode where some extensions are being
282 accepted. generation is still JSON-only.
283
284 1.44 Wed Aug 22 01:02:44 CEST 2007
285 - very experimental process-emulation support, slowing everything down.
286 the horribly broken perl threads are still not supported - YMMV.
287
288 1.43 Thu Jul 26 13:26:37 CEST 2007
289 - convert big json numbers exclusively consisting of digits to NV
290 only when there is no loss of precision, otherwise to string.
291
292 1.42 Tue Jul 24 00:51:18 CEST 2007
293 - fix a crash caused by not handling missing array elements
294 (report and testcase by Jay Kuri).
295
296 1.41 Tue Jul 10 18:21:44 CEST 2007
297 - fix compilation with NDEBUG (assert side-effect),
298 affects convert_blessed only.
299 - fix a bug in decode filters calling ENTER; SAVETMPS;
300 one time too often.
301 - catch a typical error in TO_JSON methods.
302 - antique-ised XS.xs again to work with outdated
303 C compilers (windows...).
304
305 1.4 Mon Jul 2 10:06:30 CEST 2007
306 - add convert_blessed setting.
307 - encode did not catch all blessed objects, encoding their
308 contents in most cases. This has been fixed by introducing
309 the allow_blessed setting.
310 - added filter_json_object and filter_json_single_key_object
311 settings that specify a callback to be called when
312 all/specific json objects are encountered.
313 - assume that most object keys are simple ascii words and
314 optimise this case, penalising the general case. This can
315 speed up decoding by 30% in typical cases and gives
316 a smaller and faster perl hash.
317 - implemented simpleminded, optional resource size checking
318 in decode_json.
319 - remove objToJson/jsonToObj aliases, as the next version
320 of JSON will not have them either.
321 - bit the bullet and converted the very simple json object
322 into a more complex one.
323 - work around a bug where perl wrongly claims an integer
324 is not an integer.
325 - unbundle JSON::XS::Boolean into own pm file so Storable
326 and similar modules can resolve the overloading when thawing.
327
328 1.3 Sun Jun 24 01:55:02 CEST 2007
329 - make JSON::XS::true and false special overloaded objects
330 and return those instead of 1 and 0 for those json atoms
331 (JSON::PP compatibility is NOT achieved yet).
332 - add JSON::XS::is_bool predicate to test for those special
333 values.
334 - add a reference to
335 http://jpsykes.com/47/practical-csrf-and-json-security.
336 - removed require 5.8.8 again, it is just not very expert-friendly.
337 Also try to be more compatible with slightly older versions,
338 which are not recommended (because they are buggy).
339
340 1.24 Mon Jun 11 05:40:49 CEST 2007
341 - added informative section on JSON-as-YAML.
342 - get rid of some c99-isms again.
343 - localise dec->cur in decode_str, speeding up
344 string decoding considerably (>15% on my amd64 + gcc).
345 - increased SHORT_STRING_LEN to 16kb: stack space is
346 usually plenty, and this actually saves memory
347 when !shrinking as short strings will fit perfectly.
348
349 1.23 Wed Jun 6 20:13:06 CEST 2007
350 - greatly improved small integer encoding and decoding speed.
351 - implement a number of µ-optimisations.
352 - updated benchmarks.
353
354 1.22 Thu May 24 00:07:25 CEST 2007
355 - require 5.8.8 explicitly as older perls do not seem to offer
356 the required macros.
357 - possibly made it compile on so-called C compilers by microsoft.
358
359 1.21 Wed May 9 18:40:32 CEST 2007
360 - character offset reported for trailing garbage was random.
361
362 1.2 Wed May 9 18:35:01 CEST 2007
363 - decode did not work with magical scalars (doh!).
364 - added latin1 flag to produce JSON texts in the latin1 subset
365 of unicode.
366 - flag trailing garbage as error.
367 - new decode_prefix method that returns the number
368 of characters consumed by a decode.
369 - max octets/char in perls UTF-X is actually 13, not 11,
370 as pointed out by Glenn Linderman.
371 - fixed typoe reported by YAMASHINA Hio.
372
373 1.11 Mon Apr 9 07:05:49 CEST 2007
374 - properly 0-terminate sv's returned by encode to help
375 C libraries that expect that 0 to be there.
376 - partially "port" JSON from C to microsofts fucking broken
377 pseudo-C. They should be burned to the ground for pissing
378 on standards. And I should be stoned for even trying to
379 support this filthy excuse for a c compiler.
380
381 1.1 Wed Apr 4 01:45:00 CEST 2007
382 - clarify documentation (pointed out by Quinn Weaver).
383 - decode_utf8 sometimes did not correctly flag errors,
384 leading to segfaults.
385 - further reduced default nesting depth to 512 due to the test
386 failure by that anonymous "chris" whose e-mail address seems
387 to be impossible to get. Tests on other freebsd systems indicate
388 that this is likely a problem in his/her configuration and not this
389 module.
390 - renamed json => JSON in error messages.
391 - corrected the character offset in some error messages.
392
393 1.01 Sat Mar 31 16:15:40 CEST 2007
394 - do not segfault when from_json/decode gets passed
395 a non-string object (reported by Florian Ragwitz).
396 This has no effect on normal operation.
397
398 1.0 Thu Mar 29 04:43:34 CEST 2007
399 - the long awaited (by me) 1.0 version.
400 - add \0 (JSON::XS::false) and \1 (JSON::XS::true) mappings to JSON
401 true and false.
402 - add some more notes to shrink, as suggested by Alex Efros.
403 - improve testsuite.
404 - halve the default nesting depth limit, to hopefully make it
405 work on Freebsd (unfortunately, the cpan tester did not
406 send me his report, so I cannot ask about the stack limit on fbsd).
407
408 0.8 Mon Mar 26 00:10:48 CEST 2007
409 - fix a memleak when decoding hashes.
410 - export jsonToBj and objToJson as aliases
411 to to_json and from_json, to reduce incompatibilities
412 between JSON/JSON::PC and JSON::XS. (experimental).
413 - implement a maximum nesting depth for both en- and de-coding.
414 - added a security considerations sections.
415
416 0.7 Sun Mar 25 01:46:30 CET 2007
417 - code cleanup.
418 - fix a memory overflow bug when indenting.
419 - pretty-printing now up to 15% faster.
420 - improve decoding speed of strings by
421 up to 50% by specialcasing short strings.
422 - further decoding speedups for strings using
423 lots of \u escapes.
424 - improve utf8 decoding speed for U+80 .. U+7FF.
425
426 0.5 Sat Mar 24 20:41:51 CET 2007
427 - added the UTF-16 encoding example hinted at in previous
428 versions.
429 - minor documentation fixes.
430 - fix a bug in and optimise canonicalising fastpath
431 (reported by Craig Manley).
432 - remove a subtest that breaks with bleadperl (reported
433 by Andreas König).
434
435 0.31 Sat Mar 24 02:14:34 CET 2007
436 - documentation updates.
437 - do some casting to hopefully fix Andreas' problem.
438 - nuke bogus json rpc stuff.
439
440 0.3 Fri Mar 23 19:33:21 CET 2007
441 - remove spurious PApp::Util reference (John McNamara).
442 - adapted lots of tests from other json modules
443 (idea by Chris Carline).
444 - documented mapping from json to perl and vice versa.
445 - improved the documentation by adding more examples.
446 - added short escaping forms, reducing the created
447 json texts a bit.
448 - added shrink flag.
449 - when flag methods are called without enable argument
450 they will by default enable their flag.
451 - considerably improved string encoding speed (at least
452 with gcc 4).
453 - added a test that covers lots of different characters.
454 - clarified some error messages.
455 - error messages now use correct character offset
456 with F_UTF8.
457 - improve the "no bytes" and "no warnings" hacks in
458 case the called functions do... stuff.
459 - croak when encoding to ascii and an out-of-range
460 (non-unicode) codepoint is encountered.
461
462 0.2 Fri Mar 23 00:23:34 CET 2007
463 - the "could not sleep without debugging release".
464 it should basically work now, with many bugs as
465 no production tests have been run yet.
466 - added more testcases.
467 - the expected shitload of bugfixes.
468 - handle utf8 flag correctly in decode.
469 - fix segfault in decoder.
470 - utf8n_to_uvuni sets retlen to -1, but retlen is an
471 unsigned types (argh).
472 - fix decoding of utf-8 strings.
473 - improved error diagnostics.
474 - fix decoding of 'null'.
475 - fix parsing of empty array/hashes
476 - silence warnings when we prepare the croak message.
477
478 0.1 Thu Mar 22 22:13:43 CET 2007
479 - first release, very untested, basically just to claim
480 the namespace.
481
482 0.01 Thu Mar 22 06:08:12 CET 2007
483 - original version; cloned from Convert-Scalar
484