Re: [Cbor] Do we care about array-tags issue 6, clamped-uint8 arrays?

Jim Schaad <> Fri, 26 July 2019 14:08 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id D664D120044 for <>; Fri, 26 Jul 2019 07:08:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id 9ijNjnwkNnI5 for <>; Fri, 26 Jul 2019 07:08:45 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 923D0120072 for <>; Fri, 26 Jul 2019 07:08:21 -0700 (PDT)
Received: from Jude ( by ( with Microsoft SMTP Server (TLS) id 15.0.1395.4; Fri, 26 Jul 2019 07:08:14 -0700
From: Jim Schaad <>
To: 'Carsten Bormann' <>, 'Jeffrey Yasskin' <>
CC: <>, 'Sean Leonard' <>
References: <> <> <> <> <> <> <> <>
In-Reply-To: <>
Date: Fri, 26 Jul 2019 10:08:11 -0400
Message-ID: <046501d543bb$90f52d30$b2df8790$>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQK/Tufj5AbRSJa8nmBSWNHNjScWbwIJz96mAaxsNKwB0TlobgLRCBxtAvmG4zUCPt//8wGfgnXfpI9UHVA=
Content-Language: en-us
X-Originating-IP: []
Archived-At: <>
Subject: Re: [Cbor] Do we care about array-tags issue 6, clamped-uint8 arrays?
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Concise Binary Object Representation \(CBOR\)" <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 26 Jul 2019 14:08:48 -0000


We are expecting that Carsten will provide a pull request with the suggested Security Considerations changes to deal with this issue:

As Individual: 
See below.

-----Original Message-----
From: CBOR <> On Behalf Of Carsten Bormann
Sent: Thursday, July 25, 2019 10:07 PM
To: Jeffrey Yasskin <>
Cc:; Sean Leonard <>
Subject: Re: [Cbor] Do we care about array-tags issue 6, clamped-uint8 arrays?

On Jul 25, 2019, at 16:36, Jeffrey Yasskin <> wrote:
> I remain
> uncomfortable with having a serialization format describe behaviors 
> that the data had or should have when it was or is loaded into a 
> program.

I don’t know how to avoid that.  If the input is an array, in most generic decoders I get an array to work from.  If the input is instead a map, I get a map (or a JavaScript object); that has quite different behavior.  So the supplier of the input already has a lot of control over the data structures that are input to my system.  Uint8ClampedArray just adds a slight twist to that as it might look too much like a Uint8Array.
None of this relieves an application of validating its input — with a standard serialization format and a robust generic decoder, this can now simply be done on a higher level.

[JLS]  In many respects I kind of agree with Carsten on this.   When I look at this I have a hard time distinguishing between this case and some of the other cases where similar rules are also being required.  For example, if you tag something as UTF-8 or as MIME, the sender is controlling how both the generic decoder and the application are supposed to handle this information.   If I created a tag which defined a subset of UTF-8 then this would be even more true.   For my application both Uint8ClampedArray and Uint8Array would be placed in the same data structure type as I don't have a native type for clamped arrays.  There are then rules on how I manipulate the data.  The same is true for the subset of UTF-8.  This is going to be put into a native format for my machine - maybe UTF16 since that is the native C# data type - but there are still rules on what can be done with the data and how it can be changed.  The application is not permitted to place items in the string which do not match the legal subset of strings allowed.


Grüße, Carsten

CBOR mailing list