Skip to content

feat: Add DecOptions.FixedArrayLength to enforce Go array length - #848

Open
AdamMagued wants to merge 1 commit into
fxamacker:masterfrom
AdamMagued:fix-fixed-array-decode-length
Open

AdamMagued wants to merge 1 commit into
fxamacker:masterfrom
AdamMagued:fix-fixed-array-decode-length

Conversation

@AdamMagued

Copy link
Copy Markdown

Description

When decoding CBOR byte strings or arrays into Go fixed-size arrays ([N]byte or [N]T), the default decoder behavior follows Go standard library encoding/json semantics: shorter inputs are padded with zero values and longer inputs are truncated.

This PR introduces a FixedArrayLength decoding option (FixedArrayLengthMode / alias ArrayLengthMode) with two settings:

  • FixedArrayLengthNone (default): maintains standard library compatibility by zero-padding shorter inputs and discarding extra elements.
  • FixedArrayLengthEnforced: strictly validates that the number of bytes or elements in the CBOR data item matches the dimension of the target Go array, returning *UnmarshalTypeError when there is a mismatch.

Fixes #735

PR Was Proposed and Welcomed in Currently Open Issue

Checklist (for code PR only, ignore for docs PR)

  • Include unit tests that cover the new code
  • Pass all unit tests
  • Pass all lint checks in CI (goimports, gosec, staticcheck, etc.)
  • Sign each commit with your real name and email.
    Last line of each commit message should be in this format:
    Signed-off-by: Firstname Lastname firstname.lastname@example.com
  • Certify the Developer's Certificate of Origin 1.1
    (see next section).

Certify the Developer's Certificate of Origin 1.1

  • By marking this item as completed, I certify
    the Developer Certificate of Origin 1.1.
Developer Certificate of Origin
Version 1.1

Copyright (C) 2004, 2006 The Linux Foundation and its contributors.
660 York Street, Suite 102,
San Francisco, CA 94110 USA

Everyone is permitted to copy and distribute verbatim copies of this
license document, but changing it is not allowed.

Developer's Certificate of Origin 1.1

By making a contribution to this project, I certify that:

(a) The contribution was created in whole or in part by me and I
    have the right to submit it under the open source license
    indicated in the file; or

(b) The contribution is based upon previous work that, to the best
    of my knowledge, is covered under an appropriate open source
    license and I have the right under that license to submit that
    work with modifications, whether created in whole or in part
    by me, under the same open source license (unless I am
    permitted to submit under a different license), as indicated
    in the file; or

(c) The contribution was provided directly to me by some other
    person who certified (a), (b) or (c) and I have not modified
    it.

(d) I understand and agree that this project and the contribution
    are public and that a record of the contribution (including all
    personal information I submit with it, including my sign-off) is
    maintained indefinitely and may be redistributed consistent with
    this project or the open source license(s) involved.

Add FixedArrayLength decoding option to validate that CBOR byte string and array lengths strictly match destination Go fixed-size array dimensions.

When FixedArrayLength is set to FixedArrayLengthEnforced, length mismatches return an *UnmarshalTypeError instead of zero-padding shorter inputs or silently truncating longer inputs. Default decoding behavior continues to match Go standard library encoding/json codec.

Fixes fxamacker#735

Signed-off-by: AdamMagued <adamismailmageud@gmail.com>
@fxamacker fxamacker changed the title fix: validate byte length when decoding into fixed-size byte arrays feat: Add DecOptions.FixedArrayLength to enforce Go array length Oct 2, 2026
@fxamacker

fxamacker commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

When decoding CBOR byte strings or arrays into Go fixed-size arrays ([N]byte or [N]T), the default decoder behavior follows Go standard library encoding/json semantics: shorter inputs are padded with zero values and longer inputs are truncated.

This PR introduces a FixedArrayLength decoding option

Thanks, I'll take a look after wrapping up in-progress work needed to release v2.9.5 and v2.10.0.

In the meantime, user-defined types implementing cbor.Marshaler can do this before the feature is added (not as convenient but available now).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: decoding fixed bytes into fixed array

2 participants