Skip to content

fix: Reject NaN when serializing a decimal - #18

Open
youdie006 wants to merge 1 commit into
dunglas:mainfrom
youdie006:reject-nan-decimal
Open

youdie006 wants to merge 1 commit into
dunglas:mainfrom
youdie006:reject-nan-decimal

Conversation

@youdie006

Copy link
Copy Markdown
Contributor

marshalDecimal rejects values outside the 12-digit range, but every comparison with NaN is false, so NaN passes the check (decimal.go:27) and FormatFloat writes NaN:

s, err := httpsfv.Marshal(httpsfv.NewItem(math.NaN())) // "NaN", <nil>
it, err := httpsfv.UnmarshalItem([]string{"NaN"})      // parses as a Token, <nil>

So a NaN float is sent as a Token without an error. RFC 9651 section 4.1.5 step 1 says to fail if the input is not a decimal number; +Inf and -Inf already return ErrInvalidDecimal. This adds math.IsNaN(d) to the same check, and a NaN row to TestMarshalDecimal that fails on main. NaN gets the same error text as the infinities.

go test -race, go vet, gofmt and GOARCH=386 go test pass on Go 1.26; I did not run oldstable.

Written with AI assistance (Claude); I have reviewed the change.

Every comparison with NaN is false, so the range check let it through
and FormatFloat wrote "NaN", which parses back as a Token. RFC 9651
4.1.5 requires failing when the input is not a decimal number.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant