From ee4a33c6a0ba71b313e7ee754d1550137c7a3beb Mon Sep 17 00:00:00 2001 From: SweetSophia Date: Fri, 4 Sep 2026 21:12:57 +0200 Subject: [PATCH 1/2] fix: bound strtod() scan to the input length The scan loop had no upper bound. Once i exceeds s.length, substring clamps to the full string, so a complete number never becomes NaN and the loop never exits. Empty and whitespace-only inputs hang the same way because Number('') is 0. Keep the existing parse behavior; only terminate the prefix walk. --- src/live2dcubismframework.ts | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/live2dcubismframework.ts b/src/live2dcubismframework.ts index ada25a8..adde886 100644 --- a/src/live2dcubismframework.ts +++ b/src/live2dcubismframework.ts @@ -16,7 +16,9 @@ import { Value } from './utils/cubismjson'; export function strtod(s: string, endPtr: string[]): number { let index = 0; - for (let i = 1; ; i++) { + // Bound the scan: once i exceeds s.length, substring clamps and a complete + // number never becomes NaN, so an unbounded loop never terminates. + for (let i = 1; i <= s.length; i++) { const testC: string = s.slice(i - 1, i); // 指数・マイナスの可能性があるのでスキップする From 384c500c8ef796bf891abf79957fabe9a898d8c5 Mon Sep 17 00:00:00 2001 From: SweetSophia Date: Sat, 5 Sep 2026 03:15:23 +0200 Subject: [PATCH 2/2] fix: compute JSON number end position from consumed length strtod() remainder is empty when a number reaches end-of-input. buffer.indexOf('') always returns 0, so parseValue rewound to the start of the buffer and could loop. Derive outEndPos from the slice length minus remainder length instead. --- src/utils/cubismjson.ts | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/src/utils/cubismjson.ts b/src/utils/cubismjson.ts index e87c5e9..e4251ff 100644 --- a/src/utils/cubismjson.ts +++ b/src/utils/cubismjson.ts @@ -390,8 +390,11 @@ export class CubismJson { case '8': case '9': { const afterString: string[] = new Array(1); // 参照渡しにするため - f = strtod(buffer.slice(i), afterString); - outEndPos[0] = buffer.indexOf(afterString[0]); + const numericSlice = buffer.slice(i); + f = strtod(numericSlice, afterString); + // afterString[0] が空だと indexOf('') は 0 を返し、パース位置が巻き戻る + const remainder = afterString[0] ?? ''; + outEndPos[0] = i + numericSlice.length - remainder.length; return new JsonFloat(f); } case '"':