Cpanel-JSON-XS
view release on metacpan or search on metacpan
Revision history for Perl extension Cpanel::JSON::XS
TODO: http://stevehanov.ca/blog/index.php?id=104 compression
4.43 2026-07-18 (rurban)
- Fix canonical sort: compare by UTF-16 code units per RFC 8785 (GH #248, leont)
- Fix canonical sort on Perl 5.8-5.18: utf16_cmp now always attempts
UTF-8 decoding instead of checking SvUTF8 flag, since older Perls
may store valid UTF-8 hash keys without the flag set.
- Fix quadmath encode dropping ".0" for large floats (GH #246, reported by Tux).
The .0 guard condition that suppressed appending for NV values > UV_MAX was
incorrect on high-precision FP (quadmath, 128-bit long double on arm64) where
%g uses fixed-point notation for values like 1.01e30. Guarded with #if NV_DIG < 31
to skip only on double/80-bit-ld where %g naturally uses %e for large values.
4.42 2026-06-27 (rurban)
- Ensure encode with a type spec hashref does not change the hashref argument (GH #240)
- Fix -e docs: "written" â "read" (GH #239, reported by Ron Savage).
- Fix Boolean eq overload matching undef (GH #207, reported by fd-t).
Cpanel::JSON::XS::Boolean overloaded eq would match undef as equal
to false because undef stringifies to "". Added defined() guard.
- Fix error messages showing overloaded stringification for blessed
objects (GH #191, reported by karenetheridge). Error messages now
use ClassName=TYPE(addr) format, bypassing any "" overload.
- Fix type_all_string overriding allow_blessed/convert_blessed (GH #175,
reported by alpha6). With type_all_string + allow_blessed, blessed
objects are now encoded as null (not stringified as HASH address).
- Fix infinite recursion when encode is called from a "" overload
(GH #128, reported by pbrthemaster). The recursion guard temporarily
clears convert_blessed and allow_stringify flags on the JSON object
before calling the overload, preventing re-entrant encode loops.
- Fix $obj->new creating a broken object (GH #93, reported by cpansprout).
When new() is called on an existing object (e.g. $json->new->new),
the class name is now extracted from the object's stash rather than
using the stringified reference.
- Change allow_nonref default to true (GH #241, matching JSON::PP and
JSON::XS 4.0+ and the insecure RFC 7159).
encode and decode now accept non-reference values by default.
decode_json() with an explicit 0/1 second argument still works.
allow_nonref(0) to disable scalars-only for secure JSON.
- Fix minor t/12_blessed.t typo.
- Fix GH #112: encode large whole-number NV values without .0 on
32-bit Perl (values exceeding UV_MAX that Perl stores as float).
- Fix GH #197: prefer IOK over pNOK when encoding values where
IV is accurate but NV is imprecise (SvNOK not set).
4.41 2026-05-27 (rurban)
- Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) (patch by Paul Johnson)
- Fix dupkeys_as_arrayref type confusion (CVE-2026-9334) (patch by Paul Johnson)
- Fix incr_parse single-quote string delimiter (GH #245, reported by
Paul Johnson)
- Fix a one-byte out-of-bounds heap read reachable via allow_barekey on
truncated input (GH #244, reported by Paul Johnson)
4.40 2025-09-07 (rurban)
- Fix CVE-2025-40929 overflow with overlong numbers, fuzzing only.
- Detect more malformed numbers, with two decimal points.
- Pin github actions to latest @v via pinact run -u
4.39 2024-12-12 (rurban)
- Fix Windows -Dusequadmath (sisyphus GH #235, GH #229)
- Fix inconsistent behavior between decoding escaped and unescaped
surrogates, and escaped non-characters vs non-escaped non-characters.
Now aligned to JSON::PP (Gavin Hayes GH #233, GH #227)
- Add type_all_string tests (Bernhard Schmalhofer GH #236)
- Silence UV to char cast warnings (bulk88 GH #232)
- Fix MSVC preprocessor errors (bulk88 GH #232)
- Fix -Wformat warnings on Windows (sisyphus GH #228)
- Clarify BigInt decoding (GH #226)
4.38 2024-05-27 (rurban)
- Encode real core booleans as boolean notation (PR #224 leonerd)
- Minor test fixes by leonerd
- Fix docs typo (PR #225 karenetheridge)
4.37 2023-07-04 (rurban)
- Fix NAN/INF for AIX (Tux: AIX-5.3, tested by XSven on AIX-7.3) GH #165
- Fix empty string result in object stringification (PR #221 jixam)
- Allow \' in strings when allow_singlequote is enabled (PR #217 warpspin)
4.36 2023-03-02 (rurban)
- remove the SAVESTACK_POS noop. Merged from JSON-XS-3.02,
removed there with 4.0. requested to remove with
L<https://github.com/Perl/perl5/pull/20858>
4.35 2023-02-22 (rurban)
- fix utf8 object stringification (jixam PR #212)
4.34 2023-02-21 (rurban)
- fix c89 compilation regression, for loop init on centos. GH #211
4.33 2023-02-21 (rurban)
- fix a security issue, decoding hash keys without ending :
(GH #208)
- check all bare hash keys for utf8 (GH #209)
- improve overload warnings (Graham Knop PR #205)
- fix a croak leak (GH #206)
4.32 2022-08-13 (rurban)
- fix new JSON::PP::Boolean overload redefinition warnings. GH #200
4.31 2022-08-10 (rurban)
- adjust t/20_unknown.t pp bool tests for native bool when supported.
GH #198 PR by Graham Knop.
4.30 2022-06-14 (rurban)
- Fix perl 5.37 utf8n_to_uvuni deprecation. GH #196
- Work on better inf/nan detection on AIX (#165 Peter Heuchert)
- Fix documentation for booleans and their types (#162 by Karen Etheridge)
4.19 2020-02-06 (rurban)
- Fix typed decode memory leak (#160 by Pali).
4.18 2019-12-13 (rurban)
- Add new method ->type_all_string (#156 by Pali).
When type_all_string is set then encode method produce stable deterministic
string types in result JSON.
This can be an alternative to Cpanel::JSON::XS::Type when having
deterministic output is required but string JSON types are enough for any
output.
- Move SvGETMAGIC() from encode_av() and encode_hv() to encode_sv()
(#156 by Pali)
- Add Math::BigInt and Math::BigFloat as recommended dependences
(#157 by Pali and Grinnz)
4.17 2019-11-04 (rurban)
- Add Changes tests and fixups (see #155)
4.16 2019-11-04 (rurban)
- Use Perl_strtod instead of self-made atof (via pow), to
minimize differences from core string-to-float conversions.
(#154). Fixes float representation regressions (in the 1e-6
to 1e-16 range) since 5.22.
4.15 2019-10-21 (rurban)
- Fix more tests for nvtype long double
4.14 2019-10-15 (rurban)
- Fix tests for nvtype long double (#153)
- Fix PREREQ's. E.g. CentOS 7 has not Test::More anymore. (#152 by Pali)
4.13 2019-10-14 (rurban)
- For JSON_TYPE_INT and JSON_TYPE_FLOAT allow to encode numeric values
above 2^64 in PV slot via Math::BigInt/Float (#145, #148, #149 by Pali)
- For JSON_TYPE_INT and JSON_TYPE_FLOAT encoder allow to pass Math::BigInt
and Math::BigFloat objects with allow_bignum. (#147 by Pali)
- Fix encoding floating point values above 2^64 in PV slot to JSON_TYPE_INT
(#148, #150 by Pali)
- Do not allow serializing objects when convert_blessed is not enabled.
(#146 by Pali)
4.12 2019-06-11 (rurban)
- Make encoder independent on Math::BigInt version (#140 by Pali)
- Rethrow error from eval_sv and eval_pv() (#138, #139 by Pali),
e.g. when Math::BigInt/BigFloat fails.
- Fix encoding Inf and NaN from PV and NV slots to JSON_TYPE_INT
(#137 by Pali)
- Fix memory corruption in sv_to_ivuv() function (#136 by Pali)
- Add new method ->require_types (#135 by Pali)
- Fix typed json encoder conversion from scalar's PV and NV slot to
JSON_TYPE_INT (#133, #134 by Pali)
- Fix inconsistency with warnings in typed json encoder (#131 by Pali)
- Fix Perl 5.8.0 support (#130 by Pali)
- Fixed minor pod typo (#129 by sheeit)
- Document invalid recursive callbacks or overloads (#128)
4.11 2019-03-26 (rurban)
- Fix unicode strings with BOM corrupt ->utf8 state (#125)
The BOM encoding effects only its very own decode call,
not its object.
4.10 2019-03-18 (rurban)
- Fix incr_text refcounts (#123)
- Add incr_rest testcase (#123)
- Fix encode_stringify string-overload refcnt problem (#124)
"Attempt to free unreferenced scalar" with convert_blessed and overload.
4.09 2019-02-15 (rurban)
- Add seperate allow_dupkeys property, in relaxed (#122)
- Fixed allow_dupkeys for the XS slow path
- Silence 2 -Wunused-value warnings
- Fix ->unblessed_bool to produce modifiable perl structures (PR #121 by Pali)
4.08 2018-11-28 (rurban)
- Add unblessed_bool property (PR #118 by Pali)
4.07 2018-11-02 (rurban)
- Silence Gconvert -Wunused-result.
gcvt returns a string, sprintf int, so suppress the retval
4.06 2018-08-22 (rurban)
- Fix overloaded eq/ne comparisons (GH #116 by demerphq, GH #117 by Graham Knopp):
detect strings, protect from endless recursion. false is now ne "True".
clarify eq/ne rules in the docs.
4.05 2018-08-19 (rurban)
- Set decoded type (PR #115 by Pali)
- Add json_type_weaken (PR #114 by Pali)
- Fix tests for 5.6 (rurban, pali)
4.04 2018-06-22 (rurban)
- Fix bignum NaN/inf handling (#78 reported by Slaven Rezic)
- Move author tests to xt/ as suggested in #106, added a make xtest target.
Fixes a test fail with ASAN.
4.03 2018-06-21 (rurban)
- Add sereal cpanel_json_xs type (#110 James Rouzier)
- Fix bencode/bdecode methods in cpanel_json_xs (#111 Fulvio Scapin)
- Overload ne operator for JSON::PP::Boolean (#107 tevfik1903)
- Add a missing semicolon to a documentation example (#104 E. Choroba)
4.02 2018-02-27 (rurban)
- Add encoder indent_length method (#103 rouzier), previously
hard-coded to 3.
4.01 2018-02-03 (rurban)
- Fix centos7 locale crash (#101 McA), fix required for all
threaded perl's < 5.22 with glibc.
4.00 2018-02-02 (rurban,pali)
- No changes
3.99_03 2018-01-30 (rurban,pali)
- Fix uselocale() code.
- Probe for uselocale and xlocale.h with <5.22 threaded.
3.99_02 2018-01-30 (rurban,pali)
- Avoid setlocale race in threads with non-C locales, where the threads differ
in the LC_NUMERIC locale. (#99 pali)
3.99_01 2018-01-30 (rurban,pali)
- Added Cpanel::JSON::XS::Type as 2nd optional encode argument. (#94 pali)
- Removed calling get magic hooks twice in encode.
3.0240 2017-12-17 (rurban)
- Simplify >allow_singlequote check, coverity cid #165321
- Deprecate UTF-16 or UTF-32 BOM's: RFC 8259.
3.0239 2017-08-28 (rurban)
- Fix compilation under windows. (#98 mauke)
3.0238 2017-08-25 (rurban)
- Make printing of numbers on perl's earlier than 5.22 locale
insensitive, to produce a dot as decimal sep. (#96)
3.0237 2017-07-28 (rurban)
- relax inf/nan tests as in t/op/infnan.t for windows.
we cannot know if msvcrt.dll or the new ucrt.dll is used.
try a list of valid values.
3.0236 2017-07-27 (rurban)
- Stringify true again as "1", not as "true" due to popular demand.
(haarg #87)
3.0235 2017-07-27 (rurban)
- Disallow duplicate keys by default, only allow them in relaxed
mode. (#75)
Analog to invalid unicode, which does error by default.
RFC 7159 section 4 says that "The names within an object should be unique."
So it's either i_ (undefined) or n_ (errors).
See http://seriot.ch/parsing_json.php#24
This is different to the other JSON modules, which do have a different
interpretation of the spec. Use relaxed for backcompat if you want to
allow duplicate keys.
- De-fragilize t/96_mojo.t false test to "". It mostly is.
3.0234 2017-07-27 (rurban)
- Fix and unify utf8 handling with 5.6.2
and improve many utf8 tests. (pali #88)
- Add tests for boolean sv_yes and sv_no (pali #88)
- Check for correct module in %INC (Patrick Cronin #89)
- Fix appveyor smoke with latest strawberry, use $Config{make} (pali #91)
- Fix inf/nan for strawberry 5.26
3.0233 2017-05-01 (rurban)
- 5.6 test fixes, silence some cc warnings,
add coverage and release targets, fix appveyor
3.0232 2017-04-30 (rurban)
- Fix for MSVC 2015/14.0 and newer with changed nan/inf. #85
- Added appveyor CI
- Silence 32bit debugging format warning
- stabilize decode_hv hook (Coverity)
- ignore sv_utf8_downgrade errors (Coverity)
3.0231 2017-03-29 (rurban)
- Fix need() overallocation (#84 Matthew Horsfall) and missing
need() calls.
3.0230 2017-03-12 (rurban)
- Relax -Werror=declaration-after-statement for older gcc < 4.2
3.0229 2017-03-10 (rurban)
- fix minor gcc compilation warnings.
- Add some core compat. warnings for gcc/clang compat. compilers.
3.0228 2017-03-08 (rurban)
- fix decode_prefix offset when the string was re-allocated.
rather return the offset not the pointer to the old start. (#82 PaulGWebster)
3.0227 2017-02-13 (rurban)
- fix CLONE and END, broken with 3.0226 (#80 y).
These methods are usually called with arguments, which we ignore.
3.0226 2017-02-11 (rurban)
- relax longdouble Gconvert test on ppc64le and aarch64-linux-ld,
with apparent HW quadmath without USE_QUADMATH (older perls).
(detected by dgolden)
- Fixed 2 uninit warnings in the XS
3.0225 2016-11-23 (rurban)
- decode utf8 security fixes for perl 5.6.
added extra detection code for overflows and non-continuations.
This broke one 5.6 test with an overlong multi-byte character,
which previously worked accidently.
i.e. decode "\ud801\udc02\x{10204}"
- Added tests for ill-formed utf8 sequences from Encode.
3.0224 2016-11-20 (rurban)
- fixes for g++-6, stricter -fpermissive and -Wc++11-compat
3.0223 2016-11-16 (rurban)
- fixed decode bignum with a string prefix. #76, patch by GilmarSantosJr.
3.0222 2016-10-30 (rurban)
- enable decode_bom for multibyte encodings UTF16 and UTF32.
encode internally to UTF-8.
3.0221 2016-10-30 (rurban)
- fixed documentation of decode for unicode noncharacters.
added correct code to warn as in core.
no replacement, ignore warnings when in relaxed mode.
We used a wrong range also, but the wrong code from 3.02220
was never executed because of an coding error. #73, #74
- Fixed a perl 5.6 compilation regression from 3.0220.
- Improve decode_bom for multibyte encoding, but not yet enabled.
refcount error.
- Add 5.24 to travis tests
3.0220 2016-10-28 (rurban)
- add comprehensive JSON decode spectests from
http://seriot.ch/parsing_json.html. #72
- decode with BOM (UTF-8, UTF-16, or UTF-32). For now only UTF-8,
the others error.
- fixed detection of final \0 as illegal non-whitespace garbage. Fixes
spectest 'n_number_then_00'. #72
- changed decode of unicode noncharacters between U+FFFD and U+10FFFF
to the recommended U+FFFD REPLACEMENT CHARACTER, when not in the binary
or relaxed mode.
- fail decode of non-unicode raw characters above U+10FFFF
when not in relaxed mode.
3.0219 2016-10-26 (rurban)
- workaround mingw 4.0 modfl() bug [perl #125924]
3.0218 2016-10-13 (rurban)
- no changes
3.0217_06 2016-10-08 (rurban)
- fix DPPP_dummy_PL_parser warnings
3.0217_05 2016-10-07 (rurban)
- fix t/gh70-asan.t for older perls < 5.14
3.0217_04 2016-10-07 (rurban)
- fix and document wrong strEQc usage in new(). #70 (ilmari)
3.0217_03 2016-10-06 (rurban)
- expect_false() macro fix for MSVC
- fix av and hv length types: protect from security sensitive overflows,
add HVMAX_T and RITER_T
- add new "Hash key too large" error. perl5 silently truncates it, we
prefer errors, cperl 5.25.1 does error also.
- fix broken 5.8.1 SvPOK_only, i.e. assert_not_ROK
3.0217_02 2016-10-04 (rurban)
- Use faster strEQc macros from cperl with constant strings.
- prefer memEQ for systems without memcmp, to use bcmp there.
- add more expect_false() to inf/nan branches.
3.0217_01 2016-10-04 (rurban)
- Detect INF/NAN: ?/++/-?/--- on HP-UX (#56)
- New stringify_infnan(3) infnan_mode. Easy to detect platform
independent "inf", "-inf" or "nan" strings with double quotes,
with qnan, snan or negative nan unified to "nan".
3.0217 2016-06-18 (rurban)
- Improve test t/20_unknown.t for older JSON::PP (Christopher J. Madsen)
3.0216 2016-06-12 (rurban)
- Fix wrong test 117 for 5.10.0 (pghmcfc)
3.0215 2016-06-03 (rurban)
- Fix wrong test 117 (pghmcfc)
- TODO the fragile mojo boolean interop test.
- Improve error message with class based method calls,
when forgetting ->new. #66
3.0214 2016-06-02 (rurban)
- Fix a off-by-one IV_MIN -> NV overflow in decode_json. #67 (xdg)
- Avoid encode_sv SEGV with -Dusequadmath #62
Fix quadmath NV stringification.
( run in 1.109 second using v1.01-cache-2.11-cpan-bbc515a03b3 )