libarchive: backport PR #2386 (fixes output of one test)(cherry picked from commit 6c40282284d6eab20256914648cdec39acb2c52a)
libarchive: merge from vendor branchLibarchive 3.7.7Security fixes: #2158 rpm: calculate huge header sizes correctly #2160 util: fix out of boundary access in mktemp functions #2168 uu: stop p
libarchive: merge from vendor branchLibarchive 3.7.7Security fixes: #2158 rpm: calculate huge header sizes correctly #2160 util: fix out of boundary access in mktemp functions #2168 uu: stop processing if lines are too long #2174 lzop: prevent integer overflow #2172 rar4: protect copy_from_lzss_window_to_unp() (CVE-2024-20696) #2175 unzip: unify EOF handling #2179 rar4: fix out of boundary access with large files #2203 rar4: fix OOB access with unicode filenames #2210 rar4: add boundary checks to rgb filter #2248 rar4: fix OOB in delta filter #2249 rar4: fix OOB in audio filter #2256 fix multiple vulnerabilities identified by SAST #2258 cpio: ignore out-of-range gid/uid/size/ino and harden AFIO parsing #2265 rar5: clear 'data ready' cache on window buffer reallocs #2269 rar4: fix CVE-2024-26256 (CVE-2024-26256) #2330 iso: be more cautious about parsing ISO-9660 timestamps #2343 tar: clean up linkpath between entries #2364 tar: don't crash on truncated tar archives #2366 gzip: prevent a hang when processing a malformed gzip inside a gzip #2377 tar: fix two leaks in tar header parsingImportant bugfixes: #2096 rar5: report encrypted entries #2150 xar: fix another infinite loop and expat error handling #2173 shar: check strdup return value #2161 lha: fix integer truncation on 32-bit systems #2338 tar: fix memory leaks when processing symlinks or parsing pax headers #2245 7zip: fix issue when skipping first file in 7zip archive that is a multiple of 65536 bytes #2252 7-zip: read/write symlink paths as UTF-8 #2259 rar5: don't try to read rediculously long names #2290 ar: fix archive entries having no type #2360 tar: fix truncation of entry pathnames in specific archivesCVE: CVE-2024-20696, CVE-2024-26256(cherry picked from commit bd66c1b43e33540205dbc1187c2f2a15c58b57ba)
show more ...
libarchive: merge bugfixes from vendor branch #2147 archive_string: clean up strncat_from_utf8_to_utf8 (36047967a) #2153 archive_match: check archive_read_support_format_raw() return value
libarchive: merge bugfixes from vendor branch #2147 archive_string: clean up strncat_from_utf8_to_utf8 (36047967a) #2153 archive_match: check archive_read_support_format_raw() return value (0ce1b4c38) #2154 archive_match: turn counter into flag (287e05d53) #2155 lha: Do not allow negative file sizes (93b11caed) #2156 tests: setenv LANG to en_US.UTF-8 in bsdunzip test_I.c (83e8b0ea8)(cherry picked from commit c0b58e65deca1e5e2c434ede7e64f03af6044be8)
libarchive: merge from vendor branchLibarchive 3.7.4 + three fixes from masterSecurity fixes: #2135 rar: Fix OOB in rar e8 filter (CVE-2024-26256) #2145 zip: Fix out of boundary access #2148 r
libarchive: merge from vendor branchLibarchive 3.7.4 + three fixes from masterSecurity fixes: #2135 rar: Fix OOB in rar e8 filter (CVE-2024-26256) #2145 zip: Fix out of boundary access #2148 rar: Fix OOB in rar delta filter #2149 rar: Fix OOB in rar audio filterImportant bugfixes: #2131 7zip: Limit amount of properties #2110 bsdtar: Fix error handling around strtol() usages #2116 passphrase: Never allow empty passwords #2124 rar: Fix "File CRC Error" when extracting specific rar4 archives #2123 xar: Avoid infinite link loop #2150 xar: Fix another infinite loop and expat error handling #2108 zip: Update AppleDouble support for directories #2071 zstd: Implement core detectiongit(cherry picked from commit 13d826ff947d9026f98e317e7385b22abfc0eace)
libarchive: fix null format string error in tests (unbreaks gcc13 build)Obtained from: libarchive (d43c39247)(cherry picked from commit 701d0666c03dacba9b73d91dff2a6140e157bdc4)
libarchive: merge from vendor branchLibarchive 3.7.3New features: #1941 uudecode filter: support file name and file mode in raw mode #1943 7-zip reader: translate Windows permissions into UNI
libarchive: merge from vendor branchLibarchive 3.7.3New features: #1941 uudecode filter: support file name and file mode in raw mode #1943 7-zip reader: translate Windows permissions into UNIX permissions #1962 zstd filter now supports the "long" write option #2012 add trailing letter b to bsdtar(1) substitute pattern #2031 PCRE2 support #2054 add support for long options "--group" and "--owner" to tar(1)Security fixes: #2101 Fix possible vulnerability in tar error reporting introduced in f27c173Important bugfixes: #1974 ISO9660: preserve the natural order of links #2105 rar5: fix infinite loop if during rar5 decompression the last block produced no data #2027 xz filter: fix incorrect eof at the end of an lzip member #2043 zip: fix end-of-data marker processing when decompressing zip archives(cherry picked from commit b9128a37faafede823eb456aa65a11ac69997284)
tar: make error reporting more robust and use correct errnoApply upstream pull request 2101.(cherry picked from commit d68c68693e110353f70b5c04f8de416cf5766eca)
libarchive: merge security fix from vendor branchThis commit fixes a couple of security vulnerabilities in the PAX writer:1. Heap overflow in url_encode() in archive_write_set_format_pax.c2. NULL
libarchive: merge security fix from vendor branchThis commit fixes a couple of security vulnerabilities in the PAX writer:1. Heap overflow in url_encode() in archive_write_set_format_pax.c2. NULL dereference in archive_write_pax_header_xattrs()3. Another NULL dereference in archive_write_pax_header_xattrs()4. NULL dereference in archive_write_pax_header_xattr()Security: No known reference yetObtained from: https://github.com/libarchive/libarchive/commit/1b4e0d0f9(cherry picked from commit f10f65999fe56e92f00b5bc5d27ac342cfea5364)
libarchive: merge from vendor branchChanges to not yet connected unzip only.MFC after: 1 week
libarchive: merge from vendor branchLibarchive 3.7.1Important changes (relevant to FreeBSD): ISSUE #1934: stack buffer overflow in cpio verbose mode ISSUE #1935: SEGV in cpio verbose mode P
libarchive: merge from vendor branchLibarchive 3.7.1Important changes (relevant to FreeBSD): ISSUE #1934: stack buffer overflow in cpio verbose mode ISSUE #1935: SEGV in cpio verbose mode PR #1731 tar: respect --strip-components and -s patterns in cru modesMFC after: 1 week
libarchive: merge from vendor branchLibarchive 3.7.0Important changes (relevant to FreeBSD): #1814 Do not account for NULL terminator when comparing with "TRAILER!!!" #1818 Add ability to pro
libarchive: merge from vendor branchLibarchive 3.7.0Important changes (relevant to FreeBSD): #1814 Do not account for NULL terminator when comparing with "TRAILER!!!" #1818 Add ability to produce multi-frame zstd archives #1840 year 2038 fix for pax archives on platforms with 64-bit time_t #1860 Make single bit bitfields unsigned to avoid clang 16 warning #1869 Fix FreeBSD builds with WARNS=6 #1873 bsdunzip ported to libarchive from FreeBSD #1894 read support for zstd compression in 7zip archives #1918 ARM64 filter support in 7zip archivesMFC after: 2 weeksPR: 272567 (exp-run)
libarchive: Avoid a build failure with OpenSSL 3.0This is a minimal workaround; a proper fix will come via a future updatefrom upstream.Sponsored by: The FreeBSD Foundation
libarchive: make single bit bitfields unsigned to avoid clang 16 warningClang 16 introduced a warning about single bit bitfields in structs,which is triggered by various declarations in libarchive
libarchive: make single bit bitfields unsigned to avoid clang 16 warningClang 16 introduced a warning about single bit bitfields in structs,which is triggered by various declarations in libarchive: contrib/libarchive/libarchive/archive_write_set_format_7zip.c:1541:13: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] file->dir = 1; ^ ~ contrib/libarchive/libarchive/archive_write_set_format_iso9660.c:5127:15: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] isoent->dir = 1; ^ ~ contrib/libarchive/libarchive/archive_write_set_format_iso9660.c:5213:14: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] isoent->dir = 1; ^ ~ contrib/libarchive/libarchive/archive_write_set_format_iso9660.c:5214:18: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] isoent->virtual = 1; ^ ~ contrib/libarchive/libarchive/archive_write_set_format_iso9660.c:7149:18: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] isoent->virtual = 1; ^ ~ contrib/libarchive/libarchive/archive_write_set_format_iso9660.c:7435:32: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] iso9660->zisofs.detect_magic = 1; ^ ~ contrib/libarchive/libarchive/archive_write_set_format_iso9660.c:7495:25: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] iso9660->zisofs.making = 1; ^ ~ contrib/libarchive/libarchive/archive_write_set_format_iso9660.c:7496:26: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] iso9660->zisofs.allzero = 1; ^ ~ contrib/libarchive/libarchive/archive_write_set_format_iso9660.c:7702:28: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] iso9660->zisofs.allzero = 1; ^ ~ contrib/libarchive/libarchive/archive_write_set_format_iso9660.c:7871:25: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] zisofs->header_passed = 1; ^ ~ contrib/libarchive/libarchive/archive_write_set_format_iso9660.c:7894:24: error: implicit truncation from 'int' to a one-bit wide bit-field changes value from 1 to -1 [-Werror,-Wsingle-bit-bitfield-constant-conversion] zisofs->initialized = 1; ^ ~Signed one-bit bitfields can only have values -1 and 0, but the intenthere is to use the fields as booleans, so make them unsigned.This has also been sent upstream.MFC after: 3 days
libarchive: merge from vendor branchLibarchive 3.6.2Important bug fixes: rar5 reader: fix possible garbled output with bsdtar -O (#1745) mtree reader: support reading mtree files with tabs (#
libarchive: merge from vendor branchLibarchive 3.6.2Important bug fixes: rar5 reader: fix possible garbled output with bsdtar -O (#1745) mtree reader: support reading mtree files with tabs (#1783) various small fixes for issues found by CodeQLMFC after: 2 weeksPR: 286306 (exp-run)
libarchive: import changes from upstreamLibarchive 3.6.1Bug fixes: PR #1549: archive_digest: check return value of EVP_DigestInit()PR: 263146 (exp-run)MFC after: 1 week
libarchive: merge vendor bugfixesBugfixes: IS #1685 and OSS-Fuzz #38764 (security): (ISO reader) fix possible heap buffer overflow in read_children() IS #1715 and OSS-Fuzz #46279 (security)
libarchive: merge vendor bugfixesBugfixes: IS #1685 and OSS-Fuzz #38764 (security): (ISO reader) fix possible heap buffer overflow in read_children() IS #1715 and OSS-Fuzz #46279 (security): (RARv4 reader) fix heap-use-after-free in run_filters()MFC after: 3 days
libarchive: merge vendor bugfixesBugfixes: IS #1672 and OSS-Fuzz #38766: (zip reader) fix possible out-of-bounds read in zipx_lzma_alone_init() PR #1676: (mtree reader) remove the unused va
libarchive: merge vendor bugfixesBugfixes: IS #1672 and OSS-Fuzz #38766: (zip reader) fix possible out-of-bounds read in zipx_lzma_alone_init() PR #1676: (mtree reader) remove the unused variable "detected_bytes" PR #1674: (doc) fix use of At mdoc(7) macro in cpio.5MFC after: 3 days
libarchive: merge vendor bugfixOSS-Fuzz #44843 (security):RAR reader: fix null-dereference in RAR (v4) filter codeX-MFC-with: 833a452e9d
libarchive: merge vendor bugfixesBugfixes:OSS-Fuzz #44547: fix heap-use-after-free in RAR (v4) filter codePR #1671: Fix 7z PPMD reading beyond boundaryX-MFC-with: 833a452e9d
libarchive: import changes from upstreamLibarchive 3.6.0New features:PR #1614: tar: new option "--no-read-sparse"PR #1503: RAR reader: filter supportPR #1585: RAR5 reader: self-extracting arch
libarchive: import changes from upstreamLibarchive 3.6.0New features:PR #1614: tar: new option "--no-read-sparse"PR #1503: RAR reader: filter supportPR #1585: RAR5 reader: self-extracting archive supportNew features (not used in FreeBSD base):PR #1567: tar: threads support for zstd (#1567)PR #1518: ZIP reader: zstd decompression supportSecurity Fixes:PR #1491, #1492, #1493, CVE-2021-36976: fix invalid memory access and out of bounds read in RAR5 readerPR #1566, #1618, CVE-2021-31566: extended fix for following symlinks when processing the fixup listOther notable bugfixes and improvements:PR #1620: tar: respect "--ignore-zeros" in c, r and u modesPR #1625: reduced size of application binariesMFC after: 2 weeksRelnotes: yes
libarchive: cherry-pick bugfix from vendorVendor commit message (ede459d2e): archive_write_disk_posix: fix writing fflags broken in 8a1bd5c The fixup list was erroneously assumed to be directo
libarchive: cherry-pick bugfix from vendorVendor commit message (ede459d2e): archive_write_disk_posix: fix writing fflags broken in 8a1bd5c The fixup list was erroneously assumed to be directories only. Only in the case of critical file flags modification (e.g. SF_IMMUTABLE on BSD systems), other file types (e.g. regular files or symbolic links) may be added to the fixup list. We still need to verify that we are writing to the correct file type, so compare the archive entry file type with the file type of the file to be modified.Fixes vendor issue #1617: Immutable flag no longer preserved during tar extraction on FreeBSDMFC after: 3 daysReported by: markjdbLibarchive commit: ede459d2ebb879f5eedb6f7abea203be0b334230
libarchive: import bugfix from upstreamReworked bugfix for upstream issue #1566: Do not follow symlinks when processing the fixup listMFC after: 2 weeks
libarchive: import changes from upstreamLibarchive 3.5.2New features: PR #1502: Support for PWB and v7 binary cpio formats PR #1509: Support of deflate algorithm in symbolic link decompressio
libarchive: import changes from upstreamLibarchive 3.5.2New features: PR #1502: Support for PWB and v7 binary cpio formats PR #1509: Support of deflate algorithm in symbolic link decompression for ZIP archivesImportant bugfixes: IS #1044: fix extraction of hardlinks to symlinks PR #1480: Fix truncation of size values during 7zip archive extraction on 32bit architectures PR #1504: fix rar header skiming PR #1514: ZIP excessive disk read - fix location of central directory PR #1520: fix double-free in CAB reader PR #1521: Fixed leak of rar before ending with error PR #1530: Handle short writes from archive_write_callback PR #1532: 7zip: Use compression settings from file also for file header IS #1566: do not follow symlinks when processing the fixup listMFC after: 2 weeksRelnotes: yes
libarchive: Make test_read_append_filter_wrong_program pass againlibarchive: Apply upstream commit a1b7bf8013fb7a11a486794247daae592db6f5aeThis fixes the failing test_read_append_filter_wrong_pro
libarchive: Make test_read_append_filter_wrong_program pass againlibarchive: Apply upstream commit a1b7bf8013fb7a11a486794247daae592db6f5aeThis fixes the failing test_read_append_filter_wrong_program test in CIwhich has been failing since 01-Dec-2020.Commit message from https://github.com/libarchive/libarchive/commit/a1b7bf8013fb7a11a486794247daae592db6f5ae Silence stderr in test_read_append_filter_program When the FreeBSD testsuite runs the libarchive tests it checks that stderr is empty. Since #1382 this is no longer the case. This change restores the behaviour of silencing bunzip2 stderr but doesn't bring back the output text check. Partially reverts 2e7aa5d9MFC after: 3 daysDifferential Revision: https://reviews.freebsd.org/D29036
123456