mirror of https://github.com/vee1e/flatbuffers - FlatBuffers: Memory Efficient Serialization Library
Find a file
carrerasdarren-cell 5761d6e67a
[Swift] Verify size-prefixed roots from reader position (#9196)
* [Swift] Verify size-prefixed roots from reader position

Validate the size prefix before advancing ByteBuffer.reader, then use the active reader position consistently for root, file identifier, and returned-object verification. Cover malformed decoy roots, oversized prefixes, short identifiers, and valid prefixed identifiers.

* Use wrapping arithmetic in Swift verifier

---------

Co-authored-by: Darren Carreras <283775510+carrerasdarren-cell@users.noreply.github.com>
2026-08-11 21:49:44 +02:00
.bazelci [Swift] Bump minimum supported version of swift to 5.10 (#8758) 2025-11-14 15:07:49 -08:00
.github Lock pnpm version to 10 in CI workflow (#9142) 2026-06-18 11:59:24 +02:00
android FlatBuffers Version 25.12.19 (#8871) 2025-12-19 15:06:07 -08:00
bazel [grpc] Support latest version of grpc PoC (#6338) 2021-03-25 12:12:35 -07:00
benchmarks swift 6.0+ performance tweaks 3x-6x (#9067) 2026-06-18 15:23:53 +02:00
CMake Remove invalid dependency on FLATBUFFERS_GENERATE_HEADERS_SCHEMAS (#8834) 2025-12-22 02:25:14 +00:00
dart [Dart] Actually use resized FlexBuffers buffer (#8935) 2026-03-05 02:15:45 +00:00
docs Fix typo in generated header name (#9034) 2026-04-18 00:09:10 +00:00
examples/go-echo bulk code format fix (#8707) 2025-09-23 21:50:27 -07:00
go fix(go): add bounds checking to ByteVector (#8776) 2025-12-21 20:25:30 +00:00
goldens Updates Rust codegen to use proper indentation (#8952) 2026-03-05 14:04:55 +00:00
grpc [Swift] Migrate to swift 6.0 and Implements support gRPC v2 (#8983) 2026-05-06 04:39:53 +02:00
include Fix logic inversion in FlexBuffers VerifyKey() (#9072) 2026-05-04 22:11:30 -04:00
java FlatBuffers Version 25.12.19 (#8871) 2025-12-19 15:06:07 -08:00
js docs: clean up whitespace and fix typo in tutorial.md (#8695) 2025-09-25 09:02:22 -07:00
kotlin Opt in to using experimental Kotlin Native APIs to suppress build warnings (#8885) 2026-02-04 14:54:08 +00:00
lobster [Lobster] file_identifier support 2022-03-08 15:39:12 -08:00
lua Feature: lua now file_ident aware (#8850) 2026-02-04 13:05:08 +00:00
mjs docs: clean up whitespace and fix typo in tutorial.md (#8695) 2025-09-25 09:02:22 -07:00
net/FlatBuffers Revert "fix using null string in vector (#7872)" (#8879) 2026-03-07 13:19:34 +00:00
nim [Nim] Bfbs Nim Generator (#7534) 2022-10-21 14:30:04 -04:00
php Fix PHP byte validation and reenable builds (#7670) 2022-11-29 08:12:28 -08:00
python Stage the Python license file during builds (#9015) 2026-04-17 20:30:06 -04:00
reflection Fix npm bzlmod (#8506) 2025-01-23 21:01:31 +00:00
rust fix: swapped argument order in new_inconsistent_union calls (#9001) (#9010) 2026-04-02 07:05:58 +00:00
samples [Swift] Migrate to swift 6.0 and Implements support gRPC v2 (#8983) 2026-05-06 04:39:53 +02:00
scripts [Swift] Migrate to swift 6.0 and Implements support gRPC v2 (#8983) 2026-05-06 04:39:53 +02:00
snap use improved versioning (#6691) 2021-06-11 15:27:59 -07:00
src [Dart] Fix namespace alias from union type (#9088) 2026-05-24 21:13:42 -04:00
swift [Swift] Verify size-prefixed roots from reader position (#9196) 2026-08-11 21:49:44 +02:00
tests [Swift] Verify size-prefixed roots from reader position (#9196) 2026-08-11 21:49:44 +02:00
ts Add --ts-undefined-for-optionals command line option (#8861) 2026-02-04 13:37:41 +01:00
.bazelignore Test external modules explicitly in CI (#8507) 2025-01-23 23:04:06 +00:00
.bazelrc Bump the versions of all aspect Bazel dependencies (#8508) 2025-01-24 10:09:22 -08:00
.clang-format Use the Google Style for clang-format without exceptions (#8706) 2025-09-23 21:19:33 -07:00
.clang-tidy Add clang-tidy, fix some bugpron problems. (#7708) 2022-12-14 21:58:55 -08:00
.editorconfig Editorconfig: als configure to trim whitespaces end EOL. (#7833) 2023-02-27 19:56:18 -08:00
.gitattributes
.gitignore Default Vector Support C++ (#8870) 2025-12-19 14:32:51 -08:00
.npmrc Migrate from rules_nodejs to rules_js/rules_ts (take 2) (#7928) 2023-05-03 11:48:15 -07:00
BUILD.bazel Remove Bazel WORKSPACE setup. (#8509) 2025-01-24 18:16:10 +00:00
build_defs.bzl Default Vector Support C++ (#8870) 2025-12-19 14:32:51 -08:00
CHANGELOG.md FlatBuffers Version 25.12.19 (#8871) 2025-12-19 15:06:07 -08:00
CMakeLists.txt Fix missing namespace qualifier in Pack() (#8967) 2026-03-11 22:11:06 -04:00
composer.json
CONTRIBUTING.md Fix docs: typo & dead link (#8826) 2025-12-05 20:31:04 -05:00
eslint.config.mjs [TS] Upgrade deps (#8620) 2025-06-22 08:59:42 -07:00
extensions.bzl Add support for Bzlmod (#8494) 2025-01-21 16:53:46 -08:00
FlatBuffers.podspec FlatBuffers Version 25.12.19 (#8871) 2025-12-19 15:06:07 -08:00
Formatters.md docs: clean up whitespace and fix typo in tutorial.md (#8695) 2025-09-25 09:02:22 -07:00
library.json FlatBuffers Version 25.12.19 (#8871) 2025-12-19 15:06:07 -08:00
LICENSE Rename LICENSE.txt to LICENSE (#7808) 2023-01-30 21:36:30 -08:00
MODULE.bazel build: Upgrade rules_swift to 3.1.2 and grpc to 1.76.0 (#8909) 2026-03-05 13:26:33 +00:00
package.json FlatBuffers Version 25.12.19 (#8871) 2025-12-19 15:06:07 -08:00
Package.swift [Swift] Migrate to swift 6.0 and Implements support gRPC v2 (#8983) 2026-05-06 04:39:53 +02:00
pnpm-lock.yaml [TS] Fixup TS test run at CI (#9004) 2026-03-30 13:32:24 +01:00
pnpm-workspace.yaml [TS] Fixup TS test run at CI (#9004) 2026-03-30 13:32:24 +01:00
README.md docs: clean up whitespace and fix typo in tutorial.md (#8695) 2025-09-25 09:02:22 -07:00
SECURITY.md Create Security.md 2021-05-19 11:55:50 -07:00
swift.swiftformat [Swift] Flexbuffers native swift port (#8577) 2025-06-22 08:36:38 +02:00
tsconfig.json Simplify and fix TypeScript compilation output (#7815) 2023-02-06 13:10:20 -08:00
tsconfig.mjs.json [TS/JS] Upgrade dependencies (#7996) 2023-12-13 16:57:46 -08:00
typescript.bzl Fix reflection.fbs import path (#8499) 2025-01-23 19:43:23 +00:00

logo FlatBuffers

Build status BuildKite status Fuzzing Status Discord Chat Twitter Follow Twitter Follow

FlatBuffers is a cross platform serialization library architected for maximum memory efficiency. It allows you to directly access serialized data without parsing/unpacking it first, while still having great forwards/backwards compatibility.

Quick Start

  1. Build the compiler for flatbuffers (flatc)

    Use cmake to create the build files for your platform and then perform the compilation (Linux example).

    cmake -G "Unix Makefiles"
    make -j
    
  2. Define your flatbuffer schema (.fbs)

    Write the schema to define the data you want to serialize. See monster.fbs for an example.

  3. Generate code for your language(s)

    Use the flatc compiler to take your schema and generate language-specific code:

    ./flatc --cpp --rust monster.fbs
    

    Which generates monster_generated.h and monster_generated.rs files.

  4. Serialize data

    Use the generated code, as well as the FlatBufferBuilder to construct your serialized buffer. (C++ example)

  5. Transmit/store/save Buffer

    Use your serialized buffer however you want. Send it to someone, save it for later, etc...

  6. Read the data

    Use the generated accessors to read the data from the serialized buffer.

    It doesn't need to be the same language/schema version, FlatBuffers ensures the data is readable across languages and schema versions. See the Rust example reading the data written by C++.

Documentation

Go to our landing page to browse our documentation.

Supported operating systems

  • Windows
  • macOS
  • Linux
  • Android
  • And any others with a recent C++ compiler (C++ 11 and newer)

Supported programming languages

Code generation and runtime libraries for many popular languages.

  1. C
  2. C++ - snapcraft.io
  3. C# - nuget.org
  4. Dart - pub.dev
  5. Go - go.dev
  6. Java - Maven
  7. JavaScript - NPM
  8. Kotlin
  9. Lobster
  10. Lua
  11. PHP
  12. Python - PyPI
  13. Rust - crates.io
  14. Swift - swiftpackageindex
  15. TypeScript - NPM
  16. Nim

Versioning

FlatBuffers does not follow traditional SemVer versioning (see rationale) but rather uses a format of the date of the release.

Contribution

To contribute to this project, see CONTRIBUTING.

Community

Security

Please see our Security Policy for reporting vulnerabilities.

Licensing

Flatbuffers is licensed under the Apache License, Version 2.0. See LICENSE for the full license text.