<feed xmlns='http://www.w3.org/2005/Atom'>
<title>libplist/src/bplist.c, branch 2.8.0</title>
<subtitle>Library to handle Apple Property List format files in binary or XML</subtitle>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/'/>
<entry>
<title>bytearray: Handle realloc() failure in byte_array_grow()</title>
<updated>2026-09-29T14:39:28+00:00</updated>
<author>
<name>Comtea04</name>
</author>
<published>2026-09-27T06:06:22+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=f168c10b52325b00da6355989a18a11743b33f89'/>
<id>f168c10b52325b00da6355989a18a11743b33f89</id>
<content type='text'>
byte_array_grow() assigned the result of realloc() directly to
ba-&gt;data and increased the capacity even if realloc() failed, so the
following memcpy() in byte_array_append() wrote to NULL + len.

On failure, free the old buffer and leave the byte array in a failed
state (data == NULL), which byte_array_append() already ignores. The
callers check for that state:

- the writers (bin, xml, json, openstep and the text output formats)
  return PLIST_ERR_NO_MEM instead of handing out a NULL/truncated buffer
- node_to_xml() base64-encodes &lt;data&gt; directly into the grown buffer,
  so it must bail out there (only guarded by assert() before)
- the OpenStep parser returns PLIST_ERR_NO_MEM for &lt;hex data&gt; instead of
  silently returning truncated data

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
byte_array_grow() assigned the result of realloc() directly to
ba-&gt;data and increased the capacity even if realloc() failed, so the
following memcpy() in byte_array_append() wrote to NULL + len.

On failure, free the old buffer and leave the byte array in a failed
state (data == NULL), which byte_array_append() already ignores. The
callers check for that state:

- the writers (bin, xml, json, openstep and the text output formats)
  return PLIST_ERR_NO_MEM instead of handing out a NULL/truncated buffer
- node_to_xml() base64-encodes &lt;data&gt; directly into the grown buffer,
  so it must bail out there (only guarded by assert() before)
- the OpenStep parser returns PLIST_ERR_NO_MEM for &lt;hex data&gt; instead of
  silently returning truncated data

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>ptrarray: Handle realloc() failure in ptr_array_insert()</title>
<updated>2026-09-27T06:06:22+00:00</updated>
<author>
<name>Comtea04</name>
</author>
<published>2026-09-27T06:06:22+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=8b48fa72d359de89215f50cbf6ac8c77ae5de9b4'/>
<id>8b48fa72d359de89215f50cbf6ac8c77ae5de9b4</id>
<content type='text'>
ptr_array_insert() assigned the result of realloc() directly to
pa-&gt;pdata and bumped the capacity without checking for failure, so on
out-of-memory the old buffer was leaked and the following store or
memmove() wrote through a NULL pointer.

Keep the old buffer on failure and return -1 from ptr_array_insert()
and ptr_array_add(). The callers now handle the error:

- the array lookup cache (plist.c) is dropped instead of silently going
  out of sync with the node list; lookups then fall back to walking
  the children, as they do before the cache exists
- bplist parsing (used_indexes) and serialization (objects) return
  PLIST_ERR_NO_MEM; ignoring the error in parse_bin_node_at_index()
  would otherwise loop forever since the array never grows

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
ptr_array_insert() assigned the result of realloc() directly to
pa-&gt;pdata and bumped the capacity without checking for failure, so on
out-of-memory the old buffer was leaked and the following store or
memmove() wrote through a NULL pointer.

Keep the old buffer on failure and return -1 from ptr_array_insert()
and ptr_array_add(). The callers now handle the error:

- the array lookup cache (plist.c) is dropped instead of silently going
  out of sync with the node list; lookups then fall back to walking
  the children, as they do before the cache exists
- bplist parsing (used_indexes) and serialization (objects) return
  PLIST_ERR_NO_MEM; ignoring the error in parse_bin_node_at_index()
  would otherwise loop forever since the array never grows

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>bplist: Use format macro to use correct format in error message</title>
<updated>2026-05-22T17:23:23+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-05-22T17:23:23+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=024864926b1de278d6877a0864c1ca36f35c20e6'/>
<id>024864926b1de278d6877a0864c1ca36f35c20e6</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>bplist: Add overflow check to node offset pointer arithmetic</title>
<updated>2026-02-12T01:43:50+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-02-12T01:43:50+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=9969b8ebeb2dd2ac66e4d18fc15d0340de6e8d0e'/>
<id>9969b8ebeb2dd2ac66e4d18fc15d0340de6e8d0e</id>
<content type='text'>
Credit to OSSFuzz
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Credit to OSSFuzz
</pre>
</div>
</content>
</entry>
<entry>
<title>Add NULL checks across codebase</title>
<updated>2026-02-12T00:20:05+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-02-12T00:20:05+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=4e82bc85671cfe50763de2637b54cb8576d7976f'/>
<id>4e82bc85671cfe50763de2637b54cb8576d7976f</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>bplist: Fix compiler warning with explicit cast</title>
<updated>2026-01-22T12:29:11+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-01-22T12:29:11+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=1d628bc5b051ba941389a13aa94983d5d273618b'/>
<id>1d628bc5b051ba941389a13aa94983d5d273618b</id>
<content type='text'>
Credit to @ylwango613
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Credit to @ylwango613
</pre>
</div>
</content>
</entry>
<entry>
<title>bplist: Fix is_ascii_string by using sufficiently large data type</title>
<updated>2026-01-21T17:28:45+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-01-21T17:28:45+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=502eb2a10201e98f247186672add810e54afc15b'/>
<id>502eb2a10201e98f247186672add810e54afc15b</id>
<content type='text'>
Fixes #285

Credit to @ylwango613 for reporting.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Fixes #285

Credit to @ylwango613 for reporting.
</pre>
</div>
</content>
</entry>
<entry>
<title>bplist: Fix UTF-8 to UTF-16 decoding and enforce strict validation</title>
<updated>2026-01-21T17:22:13+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-01-21T17:22:13+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=80c2fe807308475d183ae62cc05766f3caee0463'/>
<id>80c2fe807308475d183ae62cc05766f3caee0463</id>
<content type='text'>
- Treat input as unsigned bytes
- Correct UTF-8 bit decoding for 2/3/4-byte sequences
- Add overlong, surrogate, and range checks
- Enforce lead/continuation byte constraints

This addresses issue #283.

Credit to @hgarrereyn for reporting.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
- Treat input as unsigned bytes
- Correct UTF-8 bit decoding for 2/3/4-byte sequences
- Add overlong, surrogate, and range checks
- Enforce lead/continuation byte constraints

This addresses issue #283.

Credit to @hgarrereyn for reporting.
</pre>
</div>
</content>
</entry>
<entry>
<title>plistutil: Use proper error description for new error codes</title>
<updated>2026-01-17T15:35:19+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-01-17T15:35:19+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=001a59eef3b2a981f28af74ea82e1fc06b0c4275'/>
<id>001a59eef3b2a981f28af74ea82e1fc06b0c4275</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Prevent deep nesting of plist structures in all input/output formats</title>
<updated>2026-01-17T15:04:00+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-01-17T14:18:06+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=e45099fb21b679aa0cdb0db394587bb5ba675b0c'/>
<id>e45099fb21b679aa0cdb0db394587bb5ba675b0c</id>
<content type='text'>
Thanks to @unbengable12 for reporting. Addresses #288, #289, #290, #291, and #292.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Thanks to @unbengable12 for reporting. Addresses #288, #289, #290, #291, and #292.
</pre>
</div>
</content>
</entry>
</feed>
