aboutsummaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2024-04-09Make sure to call isdigit and isspace with unsigned charupstream-masterMark Wielaard
Casting to Int32 or int could create negative values. Which isspace and isdigit don't handle. SEI CERT C Coding Standard STR37-C. Resolve by casting to UChar or unsigned char instead of Int32 or int. https://sourceware.org/bugzilla/show_bug.cgi?id=28283
2022-05-26Initialize the fave and cost arrays fullyMark Wielaard
We try to be smart in sendMTFValues by initializing just nGroups number of elements instead of all BZ_N_GROUPS elements. But this means the compiler doesn't know all elements are correctly initialized and might warn. The arrays are really small, BZ_N_GROUPS, 6 elements. And nGroups == BZ_N_GROUPS is the common case. So just initialize them all always. Using a constant loop might also help the compiler to optimize the initialization. https://sourceware.org/bugzilla/show_bug.cgi?id=28904
2022-04-21Mark SEE ALSO commands with .BR in bzdiff.1, bzgrep.1 and bzmore.1Mark Wielaard
This makes sure all commands show up as bold in the man pages. Suggested-by: Helge Kreutzmann <debian@helgefjell.de>
2022-04-20Define STDERR_FILENO for BZ_LCCWIN32Mark Wielaard
STDERR_FILENO is *nix specific and is not defined under MSVC. So define it using _fileno(stderr). Suggested-by: Dmitry Tsarevich <dimhotepus@gmail.com>
2020-05-17Don't call unsafe functions from SIGSEGV/SIGBUS signal handler.Mark Wielaard
GCC10 -fanalyzer notices that we try to call functions that are not signal safe from our fatal signal handler: bzip2.c: In function ‘mySIGSEGVorSIGBUScatcher’: bzip2.c:819:7: warning: call to ‘fprintf’ from within signal handler [CWE-479] [-Wanalyzer-unsafe-call-within-signal-handler] It also notices we then call showFileNames and cleanupAndFail which also call possibly not signal safe functions. Just write out the error message directly to STDERR and exit without trying to clean up any files.
2020-05-17manual.xml: Add BZ_SEQUENCE_ERROR to return values of BZ2_bzDecompressMark Wielaard
BZ_SEQUENCE_ERROR can be returned if BZ2_bzDecompress is called after an earlier call already returned BZ_STREAM_END. Reported-by: Vanessa McHale <vamchale@gmail.com>
2019-07-21Add generation of bzip2.txt and bzip2.1.preformatted to Makefile.Mark Wielaard
And remove both pages from the repository since the will now be generated by make dist. Also don't try to update them in prepare-release.sh script.
2019-07-21Mention the --help command line option in the documentation.Mark Wielaard
Bug-Debian: https://bugs.debian.org/517257
2019-07-21bzip2.1: remove blank spaces in man page and drop the .PU macro.Mark Wielaard
Author: Bjarni Ingi Gislason Bug-Debian: https://bugs.debian.org/675380
2019-07-13Prepare for 1.0.8 release.Mark Wielaard
2019-07-13prepare-release.sh: Fix bz-lifespan typo.Mark Wielaard
2019-07-12manual: Add id to legalnotice.Mark Wielaard
Otherwise the generated HTML will have a different randomly generated name id which generates spurious diffs.
2019-07-12Fix bzgrep so it doesn't always return a 0 exit code with multiple archivesMark Wielaard
The bzgrep wrapper always returns 0 as exit code when working on multiple archives, even when the pattern is not found. Fix from openSUSE by Kristýna Streitová <kstreitova@suse.com> https://bugzilla.suse.com/970260
2019-07-12Fix bashism in bzgrepMark Wielaard
bzgrep uses ${var//} which is a bashism. Replace by calling sed so other POSIX shells work. Patch from openSUSE by Led <ledest@gmail.com>
2019-07-11fix bzdiff when TMPDIR contains spacesMark Wielaard
The bzdiff script doesn't contain enough quotes, so that it doesn't work if the TMPDIR environment variable is defined and contains spaces. https://bugs.debian.org/493710 Author: Vincent Lefevre <vincent@vinc17.org>
2019-07-11Replace project contact email with bzip2-devel@sourceware.org.Mark Wielaard
Keep Julian's email as author information, but redirect general project feedback in the code and manual to the community mailinglist.
2019-07-11release-update.sh should update version number in website pages too.Mark Wielaard
2019-07-09Accept as many selectors as the file format allows.Mark Wielaard
But ignore any larger than the theoretical maximum, BZ_MAX_SELECTORS. The theoretical maximum number of selectors depends on the maximum blocksize (900000 bytes) and the number of symbols (50) that can be encoded with a different Huffman tree. BZ_MAX_SELECTORS is 18002. But the bzip2 file format allows the number of selectors to be encoded with 15 bits (because 18002 isn't a factor of 2 and doesn't fit in 14 bits). So the file format maximum is 32767 selectors. Some bzip2 encoders might actually have written out more selectors than the theoretical maximum because they rounded up the number of selectors to some convenient factor of 8. The extra 14766 selectors can never be validly used by the decompression algorithm. So we can read them, but then discard them. This is effectively what was done (by accident) before we added a check for nSelectors to be at most BZ_MAX_SELECTORS to mitigate CVE-2019-12900. The extra selectors were written out after the array inside the EState struct. But the struct has extra space allocated after the selector arrays of 18060 bytes (which is larger than 14766). All of which will be initialized later (so the overwrite of that space with extra selector values would have been harmless).
2019-07-09Fix a 'not a normal file' error when compressing large files.Phil Ross
The bzip2 command line would report 'not a normal file' for files of size larger than 2^32 - 1 bytes. Patch bzip2.c to use _stati64 instead of _stat so that a successful result is returned for large files. Resolves https://github.com/philr/bzip2-windows/issues/3.
2019-07-05Update prepare-release.sh for Makefile* and date ranges.Mark Wielaard
Also update the version number in the Makefile comments. And update any date ranges to include the current year.
2019-07-05Fix include path separatorJoshua Watt
Changes the include path separator for Windows builds to use "/" instead of "\". Windows has no problems with using a forward slash as a path separator, but using a backslash causes problems when attempting to cross compile for other platforms (for example, when trying to cross compile for MinGW from Linux).
2019-07-03Always treat .ref files as binaryJoshua Watt
.ref files should always be treated as binary files so that git does not attempt to convert the line endings if core.autocrlf is set.
2019-07-03Update .gitignoreJoshua Watt
Updates the .gitignore file to ignore many build artifacts
2019-06-27Prepare for 1.0.7 release.Mark Wielaard
2019-06-25Add prepare-release.sh script.Mark Wielaard
Script to run to prepare a new release. It will update the release number and tell you to update the CHANGES file and to double check everything looks before doing the release commit and tagging. Afterwards you probably want to run release-update.sh to upload the release and update the website at https://sourceware.org/bzip2/ There are embedded version strings and dates in a couple of places. To keep the script simple remove some that aren't absolutely necessary. README now just points to CHANGES. README.COMPILATION.PROBLEMS only mentions the version once at the top. bzip2.c only mentions the version once when doing --version. manual.xml now doesn't have any embedded versions, just uses &bz-version; everywhere.
2019-06-24Change a magic number (6) for a constant (BZ_N_GROUPS).Federico Mena Quintero
decompress.c (BZ2_decompress): Check nGroups against BZ_N_GROUPS.
2019-06-24Make sure nSelectors is not out of rangeAlbert Astals Cid
nSelectors is used in a loop from 0 to nSelectors to access selectorMtf which is UChar selectorMtf[BZ_MAX_SELECTORS]; so if nSelectors is bigger than BZ_MAX_SELECTORS it'll do an invalid memory access Fixes out of bounds access discovered while fuzzying karchive This was reported as CVE-2019-12900 BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
2019-06-24Fix undefined behavior in the macros SET_BH, CLEAR_BH, & ISSET_BHPaul Kehrer
These macros contain this pattern: 1 << ((Int32_value) & 31 This causes the undefined behavior sanitizers in clang and gcc to complain because the shift, while ultimately stored to an unsigned variable, is done as a signed value. Adding a cast to unsigned for the int32 value resolves this issue.
2019-06-24bzip2: Fix return value when combining --test,-t and -q.Mark Wielaard
When passing -q to get quiet output --test would not display an error message, but would also suppress the exit 2 code to indicate the file was corrupt. Only suppress the error message with -q, not the exit value. This patch comes from Debian. "bunzip2 -qt returns 0 for corrupt archives" https://bugs.debian.org/279025
2019-06-24bzip2recover: Fix use after free issue with outFile.Mark Wielaard
bzip2recover.c (main): Make sure to set outFile to NULL when done. This was reported as CVE-2016-3189 and found in multiple distributions. https://seclists.org/oss-sec/2016/q2/568 Some more analysis can be found in: https://bugzilla.redhat.com/show_bug.cgi?id=1319648
2019-06-24bzip2recover: Fix buffer overflow for large argv[0].Mark Wielaard
bzip2recover.c (main) copies argv[0] to a statically sized buffer without checking whether argv[0] might be too big (> 2000 chars). This patch comes from Fedora and was originally reported at https://bugzilla.redhat.com/show_bug.cgi?id=226979
2019-06-23bzip2.c (testStream): Remove set, but not used nread variable.Mark Wielaard
Modern GCC warns: bzip2.c: In function ‘testStream’: bzip2.c:557:37: warning: variable ‘nread’ set but not used [-Wunused-but-set-variable] Int32 bzerr, bzerr_dummy, ret, nread, streamNo, i; ^~~~~ GCC is correct. In testStream we don't care about the number of bytes read by BZ2_bzRead. So just remove the variable and the assignment.
2019-06-23Add release-update.sh script.Mark Wielaard
Script to run after a release has been tagged, signed and pushed to git. Will do a fresh checkout, verify the git tag, do fresh build/dist, sign the dist with gpg, create a backup copy in HOME, upload the tar.gz and sig to sourceware, checkout bzip2-htdocs, copy over the new changes, manual, etc. and git push that to update https://sourceware.org/bzip2/
2019-06-23Use UTF-8 encoding and include bzip.css as link for HTML manual.Mark Wielaard
2019-06-23Adjust bzip.css images to new https://sourceware.org/bzip2/ location.Mark Wielaard
2019-03-30Change all bzip.org URLs to sourceware.org/bzip2Mark Wielaard
2019-03-30Change Julian's email address to jseward@acm.orgMark Wielaard
2010-09-06bzip2-1.0.6Julian Seward
2007-12-10bzip2-1.0.5Julian Seward
2006-12-20bzip2-1.0.4Julian Seward
2005-02-15bzip2-1.0.3Julian Seward
2001-12-30bzip2-1.0.2Julian Seward
2000-06-24bzip2-1.0.1Julian Seward
1999-09-04bzip2-0.9.5dJulian Seward
1998-08-23bzip2-0.9.0cJulian Seward
1997-08-29bzip2-0.1pl2Julian Seward
1997-08-07bzip2-0.1Julian Seward