Skip to content

Escape strings in Crashlytics JSON records - #16772

Open
dajiaohuang wants to merge 1 commit into
firebase:mainfrom
dajiaohuang:fix/crashlytics-json-string-escaping
Open

dajiaohuang wants to merge 1 commit into
firebase:mainfrom
dajiaohuang:fix/crashlytics-json-string-escaping

Conversation

@dajiaohuang

Copy link
Copy Markdown

Summary

  • Escape quotes, backslashes, and JSON control characters in Crashlytics record keys and values.
  • Keep the existing fast path for strings that need no escaping.
  • Add buffered and unbuffered writer tests that parse the generated record and verify round-trip values.

Testing

  • Added FIRCLSFileTests.testEscapesJSONStrings for quotes, backslashes, newlines, tabs, and a control character.
  • Not run locally: Xcode and the Apple toolchain are unavailable in this environment.
  • git diff --check passed.

@gemini-code-assist

Copy link
Copy Markdown
Contributor
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

@paulb777

paulb777 commented Oct 1, 2026

Copy link
Copy Markdown
Member

Thanks for the contribution! A few housekeeping items:

  • CHANGELOG: The entry in Crashlytics/CHANGELOG.md is under # 13.0.0, which has already shipped. Please move it under a # Unreleased heading at the top of the file (add the heading if it isn't there yet).
  • PR number: end the entry with this PR's number, e.g. - [fixed] Description. (#16772).
  • Formatting: after updating, please run scripts/style.sh so the infra.check job passes. It needs clang-format 23 and swiftformat (see scripts/setup_check.sh). If you can't run it locally, the infra.check log lists the files that need formatting.

@paulb777 paulb777 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, this looks correct and async-signal-safe (stack buffers, a static table, no allocation or locks). Note that user-supplied data (custom keys, logs, errors) is already hex-encoded, so the practical effect is on raw strings like thread names, dispatch queue labels and binary image paths. The CHANGELOG entry could say that.

The catalyst failure in CI isn't caused by this PR: it's the FIRCLSContextManagerTests crash fixed in #16776, so merging main should clear it. testEscapesJSONStrings passes.

const char* string,
size_t length,
char suffix) {
bool needsEscaping = false;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you add a short comment noting that this path runs from the signal and Mach exception handlers (thread names, queue labels) and must stay async-signal-safe?


#pragma mark -

- (void)testEscapesJSONStrings {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It would be good to also cover FIRCLSFileWriteArrayEntryString (the thread-name path), and a buffered escaped string longer than FIRCLSWriteBufferLength (1000 bytes) so the escaped segments cross a buffer flush.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants