json_decode() fails on nested input of around 10000 characters.
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 40.4k
- Forks
- 8.1k
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 96
Description
Description
The following code:
<?php
function test($i, $s) {
try {
json_decode($s, false, 999999999, JSON_THROW_ON_ERROR);
echo "Test $i passed\n";
} catch (Exception $e) {
echo "Test $i FAILED: $e\n";
}
}
// String like [[[[...1...]]]] fails at length 9999, nesting depth 4999.
test(1, str_repeat('[', 4998) . '1' . str_repeat(']', 4998)); // pass
test(2, str_repeat('[', 4999) . '1' . str_repeat(']', 4999)); // FAIL
// String like [1,[1,[1,...1...]]] fails at length 10001, nesting depth 2499.
test(3, str_repeat('[1,', 2499) . '1' . str_repeat(']', 2499)); // pass
test(4, str_repeat('[1,', 2500) . '1' . str_repeat(']', 2500)); // FAIL
// Flat string like [[1],[1],[1]...] passes even at much greater length.
test(5, '[' . str_repeat('[1],', 9999) . '1]'); // pass
?>
Resulted in this output:
Test 1 passed
Test 2 FAILED: JsonException: Syntax error in json_decode_bug.php:5
Stack trace:
#0 json_decode_bug.php(5): json_decode()
#1 json_decode_bug.php(14): test()
#2 {main}
Test 3 passed
Test 4 FAILED: JsonException: Syntax error in json_decode_bug.php:5
Stack trace:
#0 json_decode_bug.php(5): json_decode()
#1 json_decode_bug.php(18): test()
#2 {main}
Test 5 passed
(I've removed the directory names from the stack trace for brevity.)
But I expected this output instead:
Test 1 passed
Test 2 passed
Test 3 passed
Test 4 passed
Test 5 passed
Note that the exception message ("Syntax error') is different from what I get when I reduce the maximum depth argument from 999999999 to 999. Then I get JsonException: Maximum stack depth exceeded instead (which is expected).
So it looks like the parser hits an undocumented limit when the input string reaches 10,000 characters, but only for the heavily-nested input.
PHP Version
PHP 8.1.13
Operating System
Arch Linux (x86_64)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by running the provided json_decode() reproduction on PHP 8.1.13, varying the nesting depth and maximum-depth argument as shown. Investigate the parser behavior for deeply nested inputs around 10,000 characters; done means valid nested inputs decode successfully while genuinely excessive depth still reports the expected maximum stack depth error.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- backend
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100