Skip to content

PYTHON-6111 C extension accepts BSON documents where element data overlaps the document terminator - #3113

Draft
blink1073 wants to merge 1 commit into
mongodb:mainfrom
blink1073:PYTHON-6111
Draft

blink1073 wants to merge 1 commit into
mongodb:mainfrom
blink1073:PYTHON-6111

Conversation

@blink1073

Copy link
Copy Markdown
Member

PYTHON-6111

Changes in this PR

  • The C BSON decoder accepted documents where an element's value consumed the document terminator byte; the pure-Python decoder rejects them with InvalidBSON.
  • Adds bounds checks to the boolean and regex element handlers so the C decoder matches the pure-Python decoder.
  • No public APIs changed. All reads stay within the caller's buffer.

Test Plan

  • Added a regression test with terminator-overlapping boolean and regex payloads, exercised through all decode entry points and buffer types.
  • Confirmed the test fails without the fix and passes with it; the full test/test_bson.py suite and just lint-manual pass.
  • just typing (mypy) crashes on an environment issue unrelated to this diff; re-run on a clean checkout before merge.

Checklist

Checklist for Author

  • Did you update the changelog (if necessary)?
  • Is there test coverage?
  • Is any followup work tracked in a JIRA ticket? If so, add link(s). (No followup work identified.)

Checklist for Reviewer

  • Does the title of the PR reference a JIRA Ticket?
  • Do you fully understand the implementation? (Would you be comfortable explaining how this code works to someone else?)
  • Is all relevant documentation (README or docstring) updated?

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The bounds checks correctly enforce BSON document boundaries and are covered by focused regression tests.

0 open findings

What changed in this PR

Aligns the C BSON decoder with the pure-Python decoder by rejecting element data that consumes a document terminator.

Changes:

  • Adds boolean and regex bounds checks.
  • Adds regression coverage across buffer types and decode paths.
  • Documents the fix in the changelog.
File Description
bson/​_cbsonmodule.c Prevents boolean and regex values from overlapping the terminator.
test/​test_bson.py Tests malformed boolean and regex documents.
doc/​changelog.rst Records the PYTHON-6111 fix.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@codecov

codecov Bot commented Oct 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants