Repository navigation
Deserialize struct variants from a sequence in Value - #488
Merged
Merged
Conversation
Licenser
reviewed
Oct 3, 2026
Licenser
left a comment
Member
There was a problem hiding this comment.
just some minor test addition
The Value deserializers (`from_owned_value`, `from_borrowed_value` and
the `&Value` variants) handed arrays to the visitor without checking
afterwards that every element was consumed, so a fixed-length type
silently dropped the rest:
let v = to_owned_value(b"[1,2,3]")?;
from_owned_value::<(u8, u8)>(v) Ok((1, 2))
from_refowned_value::<[u8; 2]>(&v) Ok([1, 2])
The text deserializer rejects these (`fix/seq-extra-elements`), as do
serde_json's `from_value` and sonic-rs. Arrays now go through
`visit_array`, which returns `invalid_length` when elements are left,
like serde's `SeqDeserializer::end`.
Test: `value_fixed_length_sequences_reject_extra_elements` (fails before
this change).
Found by a differential fuzzer (serde_json, simd-json, sonic-rs, jiter).
A struct variant written as a JSON array deserializes from text, but
from an owned or borrowed Value (`from_owned_value` etc.) it failed with
`Unexpected(Some(Object), Some(Array))`:
from_slice::<E>(br#"{"S":[5,"k"]}"#) Ok(S { a: 5, .. })
from_owned_value::<E>(to_owned_value(..)?) Err(Unexpected(..))
`struct_variant` now hands an array to the visitor through
`visit_array`, which also rejects wrong lengths. serde_json (#1049) and
sonic-rs had the same gap.
Builds on `fix/value-seq-extra-elements` (uses its `visit_array`).
Test: `value_struct_variant_from_sequence` (fails before this change).
Found by a differential fuzzer (serde_json, simd-json, sonic-rs, jiter).
Licenser
force-pushed
the
pr/struct-variant-seq
branch
from
October 4, 2026 10:39
6a0c348 to
cf629f7
Compare
Licenser
approved these changes
Oct 4, 2026
Licenser
enabled auto-merge (squash)
October 4, 2026 10:39
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #488 +/- ##
==========================================
+ Coverage 72.00% 75.23% +3.23%
==========================================
Files 49 49
Lines 11347 11613 +266
==========================================
+ Hits 8170 8737 +567
+ Misses 3177 2876 -301
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on #484: the first commit here is the Value commit of #484 (its
Remaininghelper is used by this fix). Review the last commit; once #484 is merged this PR reduces to it.fix: reject extra array elements when deserializing from a Value
The Value deserializers (
from_owned_value,from_borrowed_valueandthe
&Valuevariants) handed arrays to the visitor without checkingafterwards that every element was consumed, so a fixed-length type
silently dropped the rest:
The text deserializer rejects these (
fix/seq-extra-elements), as doserde_json's
from_valueand sonic-rs. Arrays now go throughvisit_array, which returnsinvalid_lengthwhen elements are left,like serde's
SeqDeserializer::end.Test:
value_fixed_length_sequences_reject_extra_elements(fails beforethis change).
fix: deserialize struct variants from a sequence in Value
A struct variant written as a JSON array deserializes from text, but
from an owned or borrowed Value (
from_owned_valueetc.) it failed withUnexpected(Some(Object), Some(Array)):struct_variantnow hands an array to the visitor throughvisit_array, which also rejects wrong lengths. serde_json (serde-rs/json#1049) andsonic-rs had the same gap.
Builds on
fix/value-seq-extra-elements(uses itsvisit_array).Test:
value_struct_variant_from_sequence(fails before this change).Testing
Each commit adds a regression test that fails before the change. The full test suite passes and
cargo fmt --checkis clean on the changed files.Found with a differential fuzzer comparing serde_json, simd-json, sonic-rs and jiter.