fix: make the JSONCPP_USE_SECURE_MEMORY build compile and pass (#1709)

Building with JSONCPP_USE_SECURE_MEMORY=1 fails in three separate ways,
each hidden behind the previous one. No CI job builds this configuration,
which is why they have accumulated.

1. allocator.h calls RtlSecureZeroMemory on the _WIN32 branch without
   including <windows.h>, so MSVC fails with error C3861. Removing that
   branch lets the portable volatile std::fill_n path handle Windows.
   The same fill was zeroing n bytes rather than n * sizeof(T), so for
   any T wider than a char, most of the allocation was never wiped.

2. jsontestrunner declares a std::string where the surrounding code uses
   Json::String. The two are the same type only in default builds, so the
   test runner does not compile under secure memory.

3. CZString's move-assignment released a key with
   releasePrefixedStringValue, but CZString keys come from
   duplicateStringValue and carry no length prefix. The destructor
   already uses the matching releaseStringValue. Under the default
   allocator this mismatch is survivable; under SecureAllocator the
   suite segfaults.

Verified on MSVC 19.44, x64, C++17. Before: error C3861. With only the
first two fixed: builds, then jsoncpp_test SEGFAULT. With all three:
secure build compiles and 3/3 ctest suites pass. The default build is
unaffected and also 3/3.

Fixes #1399

Co-authored-by: Jordan Bayles <bayles.jordan@gmail.com>
4 files changed
tree: 8d353e7bd23d7651727527317c1a485a9e85e64a
  1. .github/
  2. cmake/
  3. devtools/
  4. doc/
  5. example/
  6. include/
  7. pkg-config/
  8. src/
  9. test/
  10. .clang-format
  11. .clang-tidy
  12. .gitattributes
  13. .gitignore
  14. amalgamate.py
  15. appveyor.yml
  16. AUTHORS
  17. BUILD.bazel
  18. CMakeLists.txt
  19. CONTRIBUTING.md
  20. CTestConfig.cmake
  21. dev.makefile
  22. doxybuild.py
  23. gcovr.cfg
  24. get_version.pl
  25. jsoncpp-namespaced-targets.cmake
  26. jsoncppConfig.cmake.in
  27. jsoncppConfig.cmake.meson.in
  28. LICENSE
  29. meson.build
  30. meson_options.txt
  31. MODULE.bazel
  32. README.md
  33. reformat.sh
  34. SECURITY.md
  35. version.in
README.md

JsonCpp

Conan Center badge badge Coverage Status

JSON is a lightweight data-interchange format. It can represent numbers, strings, ordered sequences of values, and collections of name/value pairs.

JsonCpp is a C++ library that allows manipulating JSON values, including serialization and deserialization to and from strings. It can also preserve existing comment in deserialization/serialization steps, making it a convenient format to store user input files.

Project Status

JsonCpp is a mature project in maintenance mode. Our priority is providing a stable, reliable JSON library for the long tail of C++ development.

Current Focus

  • Security: Addressing vulnerabilities and fuzzing results.
  • Compatibility: Ensuring the library builds without warnings on the latest versions of GCC, Clang, and MSVC.
  • Reliability: Fixing regressions and critical logical bugs.

Out of Scope

  • Performance: We are not competing with SIMD-accelerated or reflection-based parsers.
  • Features: We are generally not accepting requests for new data formats or major API changes.

JsonCpp remains a primary choice for developers who require comment preservation and support for legacy toolchains where modern C++ standards are unavailable. The library is intended to be a reliable dependency that does not require frequent updates or major migration efforts.

A note on backward-compatibility

  • 1.y.z (master): Actively maintained. Requires C++11.

  • 0.y.z: Legacy support for pre-C++11 compilers. Maintenance is limited to critical security fixes.

  • 00.11.z: Discontinued.

Major versions maintain binary compatibility. Critical security fixes are accepted for both the master and 0.y.z branches.

Integration

[!NOTE] Package manager ports (vcpkg, Conan, etc.) are community-maintained. Please report outdated versions or missing generators to their respective repositories.

Meson

meson wrap install jsoncpp

Amalgamated source

For projects requiring a single-header approach, JsonCpp provides a script to generate an amalgamated source and header file.

You can generate the amalgamated files by running the following Python script from the top-level directory:

python3 amalgamate.py

This will generate a dist directory containing jsoncpp.cpp, json/json.h, and json/json-forwards.h. You can then drop these files directly into your project's source tree and compile jsoncpp.cpp alongside your other source files.

Documentation

Documentation is generated via Doxygen. Additional information is available on the Project Wiki.

License

JsonCpp is licensed under the MIT license, or public domain where recognized. See LICENSE for details.