Adds sfTime (UINT32/96), sfJsonTxDelta (VL/96), and sfAppLoader/sfAppLoaderID
which were added to sfields.macro but not propagated to the generated hook
header, causing verify-generated-headers CI failure.
Cover unsanitize_jsontx error paths: truncated delta, unmerged literal/run,
empty delta, undersize copy, unmerged copy run, bad literal length, overlong
varint, and delta value out of range. Also add timestamp edge cases: malformed
ISO format, out-of-range month/day, non-leap Feb 29, and before-epoch dates.
jsontx_exact: change the double boundary check from exclusive to inclusive
(d > max -> d >= max, d < -max -> d <= -max). Doubles cannot uniquely
represent odd integers at or above 2^53, so values like 2^53+1 silently
round to 2^53, corrupting the canonical form. The safe ceiling for
round-trip-exact integers is 2^53 - 1.
tests: add coverage for the 2^53 boundary (positive and negative sides,
and the silent rounding case).
jsontx_strict: the comment claimed \u sequences were rejected but the
code only tracked backslashes without checking if they introduced a
unicode escape. Now properly throws on \u inside strings, which also
covers NUL-byte injection (\u0000) and prevents canonical form
mismatches caused by jsoncpp silently decoding \uXXXX.
tests: add coverage for \u rejection, jsontx_u64 negative/non-integer/
infinity rejection, delta size scaling with transaction complexity,
and sanitize rejection of unicode escapes.
Fixes a subtle security concern: without this check, a signer could
send a preimage with \uXXXX that jsoncpp would decode into a
different character, causing the canonical form to diverge from what
the signer actually signed while still passing the delta round-trip.
Submit.cpp: validate jss::sig presence before use so missing-signature
errors are reported clearly rather than as a misleading 'bad signature'.
JSONTxSignatures_test: 40 test sections covering:
- strict JSON parsing (comments, unicode, trailing commas, single quotes)
- ISO-8601 timestamp round-trips and overflow
- sanitize/unsanitize delta encoding round-trips
- unknown field and duplicate field rejection
- NUL byte rejection in string values
- document size limit enforcement
- nested objects and canonical field reordering
- delta decoding edge cases (varint bounds, too many ops, copy past end,
unknown ops, non-minimal varints)
- multiple round-trip stability
- u64 formatting edge cases