MFC r348993,349135:Sync libarchive with vendor including security fixesr348993: - version bumped to 3.4.0 - check_symlinks_fsobj() without chdir() and fchdir() - bsdtar.1 manpage fixes - p
MFC r348993,349135:Sync libarchive with vendor including security fixesr348993: - version bumped to 3.4.0 - check_symlinks_fsobj() without chdir() and fchdir() - bsdtar.1 manpage fixes - patches from OpenBSD to libarchive_fe/passphrase.cr349135: PR #1212: RAR5 reader - window_mask was not updated correctly (OSS-Fuzz 15278) OSS-Fuzz 15120: RAR reader - extend use after free bugfix
show more ...
MFV r338519:Update libarchive to 3.3.3As all important changes have already been merged from libarchive gitthis is just version number bump, documentation update and somepolishing for cpio tests
MFV r338519:Update libarchive to 3.3.3As all important changes have already been merged from libarchive gitthis is just version number bump, documentation update and somepolishing for cpio tests. Other source code changes are not relevant toFreeBSD.Approved by: re (gjb)MFC after: 1 week
MFV r328323,328324:Sync libarchive with vendor.Relevant vendor changes: PR #893: delete dead ppmd7 alloc callbacks PR #904: Fix archive freeing bug in bsdcat PR #961: Fix ZIP format names
MFV r328323,328324:Sync libarchive with vendor.Relevant vendor changes: PR #893: delete dead ppmd7 alloc callbacks PR #904: Fix archive freeing bug in bsdcat PR #961: Fix ZIP format names PR #962: Don't modify attributes for existing directories when ARCHIVE_EXTRACT_NO_OVERWRITE is set PR #964: Fix -Werror=implicit-fallthrough= for GCC 7 PR #970: zip: Allow backslash as path separatorMFC after: 1 week
DIRDEPS_BUILD: Update dependencies.Sponsored by: Dell EMC Isilon
MFV r324145,324147:Sync libarchive with vendor.Relevant vendor changes: PR #905: Support for Zstandard read and write filters PR #922: Avoid overflow when reading corrupt cpio archive Issue
MFV r324145,324147:Sync libarchive with vendor.Relevant vendor changes: PR #905: Support for Zstandard read and write filters PR #922: Avoid overflow when reading corrupt cpio archive Issue #935: heap-based buffer overflow in xml_data (CVE-2017-14166) OSS-Fuzz 2936: Place a limit on the mtree line length OSS-Fuzz 2394: Ensure that the ZIP AES extension header is large enough OSS-Fuzz 573: Read off-by-one error in RAR archives (CVE-2017-14502)MFC after: 1 weekSecurity: CVE-2017-14166, CVE-2017-14502
Add HAS_TESTS to all Makefiles that are currently using the`SUBDIR.${MK_TESTS}+= tests` idiom.This is a follow up to r321912.
Convert traditional ${MK_TESTS} conditional idiom for including testdirectories to SUBDIR.${MK_TESTS} idiomThis is being done to pave the way for future work (and homogenity) in^/projects/make-ch
Convert traditional ${MK_TESTS} conditional idiom for including testdirectories to SUBDIR.${MK_TESTS} idiomThis is being done to pave the way for future work (and homogenity) in^/projects/make-check-sandbox .No functional change intended.MFC after: 1 weeks
MFV r320924:Bump libarchive to 3.3.2Vendor changes: PR #901: don't depend on stdin in a testcaseMFC after: 1 week
MFV r315633, 315635:Sync libarchive with vendorVendor changes/bugfixes (FreeBSD-related): PR 867 (bsdcpio): show numeric uid/gid when names are not found PR 870 (seekable zip): accept files w
MFV r315633, 315635:Sync libarchive with vendorVendor changes/bugfixes (FreeBSD-related): PR 867 (bsdcpio): show numeric uid/gid when names are not found PR 870 (seekable zip): accept files with valid ZIP64 EOCD headers PR 880 (pax): Fix handling of "size" pax header keyword PR 887 (crypto): Discard 3072 bytes instead of 1024 of first keystream OSS-Fuzz issue 806 (mtree): rework mtree_atol10 integer parser Break ACL read/write code into platform-specific source files Unbreak static dependency on libbz2MFC after: 1 week
MFV r314565,314567,314570:Update libarchive to version 3.3.1 (and sync with latest vendor dist)Notable vendor changes: PR #501: improvements in ACL path handling PR #724: fix hang when reading
MFV r314565,314567,314570:Update libarchive to version 3.3.1 (and sync with latest vendor dist)Notable vendor changes: PR #501: improvements in ACL path handling PR #724: fix hang when reading malformed cpio files PR #864: fix out of bounds read with malformed GNU tar archives Documentation, style, test suite improvements and typo fixes.New options to bsdtar that enable or disable reading and/or writing of: Access Control Lists (--acls, --no-acls) Extended file flags (--fflags, --no-fflags) Extended attributes (--xattrs, --no-xattrs) Mac OS X metadata (Mac OS X only) (--mac-metadata, --no-mac-metadata)MFC after: 2 weeks
Use SRCTOP instead of .CURDIR relative paths with ".."This simplifies pathing in make/displayed outputMFC after: 1 weekSponsored by: Dell EMC Isilon
MFV r307859:Update libarchive to 3.2.2
DIRDEPS_BUILD: Add some missing dirctories to the build.Sponsored by: EMC / Isilon Storage Division
MFV r302003,r302037,r302038,r302056:Update libarchive to 3.2.1 (bugfix and security fix release)List of vendor fixes:- fix exploitable heap overflow vulnerability in Rar decompression (vendor
MFV r302003,r302037,r302038,r302056:Update libarchive to 3.2.1 (bugfix and security fix release)List of vendor fixes:- fix exploitable heap overflow vulnerability in Rar decompression (vendor issue 719, CVE-2016-4302, TALOS-2016-0154)- fix exploitable stack based buffer overflow vulnebarility in mtree parse_device functionality (vendor PR 715, CVE-2016-4301, TALOS-2016-0153)- fix exploitable heap overflow vulnerability in 7-zip read_SubStreamsInfo (vendor issue 718, CVE-2016-4300, TALOS-2016-152)- fix integer overflow when computing location of volume descriptor (vendor issue 717)- fix buffer overflow when reading a crafred rar archive (vendor issue 521)- fix possible buffer overflow when reading ISO9660 archives on machines where sizeof(int) < sizeof(size_t) (vendor issue 711)- tar and cpio should fail if an input file named on the command line is missing (vendor issue 708)- fix incorrect writing of gnutar filenames that are exactly 512 bytes long (vendor issue 682)- allow tests to be run from paths that are equal or longer than 128 characters (vendor issue 657)- add memory allocation errors in archive_entry_xattr.c (vendor PR 603)- remove dead code in archive_entry_xattr_add_entry() (vendor PR 716)- fix broken decryption of ZIP files (vendor issue 553)- manpage style, typo and description fixesPost-3.2.1 vendor fixes:- fix typo in cpio version reporting (Vendor PR 725, 726)- fix argument range of ctype functions in libarchive_fe/passphrase.c- fix ctype use and avoid empty loop bodies in WARC readerMFC after: 1 weekSecurity: CVE-2016-4300, CVE-2016-4301, CVE-2016-4302Approved by: re (kib)
DIRDEPS_BUILD: Connect new directories and update dependencies.Sponsored by: EMC / Isilon Storage Division
MFV r299425:Update libarchive to 3.2.0New features:- new bsdcat command-line utility- LZ4 compression (in src only via external utility from ports)- Warc format support- 'Raw' format writer-
MFV r299425:Update libarchive to 3.2.0New features:- new bsdcat command-line utility- LZ4 compression (in src only via external utility from ports)- Warc format support- 'Raw' format writer- Zip: Support archives >4GB, entries >4GB- Zip: Support encrypting and decrypting entries- Zip: Support experimental streaming extension- Identify encrypted entries in several formats- New --clear-nochange-flags option to bsdtar tries to remove noschg and similar flags before deleting files- New --ignore-zeros option to bsdtar to handle concatenated tar archives- Use multi-threaded LZMA decompression if liblzma supports it- Expose version info for libraries used by libarchivePatched files (fixed compiler warnings):contrib/libarchive/cat/bsdcat.c (vendor PR #702)contrib/libarchive/cat/bsdcat.h (vendor PR #702)contrib/libarchive/libarchive/archive_read_support_format_mtree.c (PR #701)contrib/libarchive/libarchive_fe/err.c (vendor PR #703)MFC after: 1 monthRelnotes: yes