<feed xmlns='http://www.w3.org/2005/Atom'>
<title>libplist/src/jplist.c, branch 2.8.0</title>
<subtitle>Library to handle Apple Property List format files in binary or XML</subtitle>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/'/>
<entry>
<title>bytearray: Handle realloc() failure in byte_array_grow()</title>
<updated>2026-09-29T14:39:28+00:00</updated>
<author>
<name>Comtea04</name>
</author>
<published>2026-09-27T06:06:22+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=f168c10b52325b00da6355989a18a11743b33f89'/>
<id>f168c10b52325b00da6355989a18a11743b33f89</id>
<content type='text'>
byte_array_grow() assigned the result of realloc() directly to
ba-&gt;data and increased the capacity even if realloc() failed, so the
following memcpy() in byte_array_append() wrote to NULL + len.

On failure, free the old buffer and leave the byte array in a failed
state (data == NULL), which byte_array_append() already ignores. The
callers check for that state:

- the writers (bin, xml, json, openstep and the text output formats)
  return PLIST_ERR_NO_MEM instead of handing out a NULL/truncated buffer
- node_to_xml() base64-encodes &lt;data&gt; directly into the grown buffer,
  so it must bail out there (only guarded by assert() before)
- the OpenStep parser returns PLIST_ERR_NO_MEM for &lt;hex data&gt; instead of
  silently returning truncated data

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
byte_array_grow() assigned the result of realloc() directly to
ba-&gt;data and increased the capacity even if realloc() failed, so the
following memcpy() in byte_array_append() wrote to NULL + len.

On failure, free the old buffer and leave the byte array in a failed
state (data == NULL), which byte_array_append() already ignores. The
callers check for that state:

- the writers (bin, xml, json, openstep and the text output formats)
  return PLIST_ERR_NO_MEM instead of handing out a NULL/truncated buffer
- node_to_xml() base64-encodes &lt;data&gt; directly into the grown buffer,
  so it must bail out there (only guarded by assert() before)
- the OpenStep parser returns PLIST_ERR_NO_MEM for &lt;hex data&gt; instead of
  silently returning truncated data

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Print debug error message when encoutering invalid PLIST_DATE values</title>
<updated>2026-05-22T18:41:23+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-05-22T18:41:23+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=bd851a87ec93db2516455e982f121389a86fc0f7'/>
<id>bd851a87ec93db2516455e982f121389a86fc0f7</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>common: validate PLIST_DATE values before Time64_T conversion</title>
<updated>2026-05-22T17:20:51+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-05-22T17:20:51+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=ba82092e43d4769dbc6f0557d58a243f93542486'/>
<id>ba82092e43d4769dbc6f0557d58a243f93542486</id>
<content type='text'>
Avoid undefined behavior when serializing malformed PLIST_DATE values
containing NaN, infinity, or values outside the Time64_T range. Add a
shared helper for checked date conversion and use it across writer paths.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Avoid undefined behavior when serializing malformed PLIST_DATE values
containing NaN, infinity, or values outside the Time64_T range. Add a
shared helper for checked date conversion and use it across writer paths.
</pre>
</div>
</content>
</entry>
<entry>
<title>refactor: centralize formatting helpers and harden out-plutil</title>
<updated>2026-05-22T16:46:02+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-05-22T16:46:02+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=9711459dbed7d60bb00c7d2c052623e8489c88e1'/>
<id>9711459dbed7d60bb00c7d2c052623e8489c88e1</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Add JSON coercion support for non-JSON plist types</title>
<updated>2026-03-20T16:12:47+00:00</updated>
<author>
<name>Calil Khalil</name>
</author>
<published>2026-02-21T13:39:24+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=3edac28498d883f1f768699ee15ce85a82bb2a7b'/>
<id>3edac28498d883f1f768699ee15ce85a82bb2a7b</id>
<content type='text'>
- Add PLIST_OPT_COERCE option to coerce PLIST_DATE, PLIST_DATA, and PLIST_UID to JSON-compatible types (ISO 8601 strings, Base64 strings, and integers)
- Add plist_to_json_with_options() function to allow passing coercion options (and others)
- Update plist_write_to_string() and plist_write_to_stream() to support coercion option
- Add --coerce flag to plistutil for JSON output
- Create plist2json symlink that automatically enables coercion when invoked
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
- Add PLIST_OPT_COERCE option to coerce PLIST_DATE, PLIST_DATA, and PLIST_UID to JSON-compatible types (ISO 8601 strings, Base64 strings, and integers)
- Add plist_to_json_with_options() function to allow passing coercion options (and others)
- Update plist_write_to_string() and plist_write_to_stream() to support coercion option
- Add --coerce flag to plistutil for JSON output
- Create plist2json symlink that automatically enables coercion when invoked
</pre>
</div>
</content>
</entry>
<entry>
<title>json: Fix a few memory leaks</title>
<updated>2026-02-13T00:05:53+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-02-13T00:05:53+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=d5a582e95a0535ba2ec916cf0532dfe29bcd7e6e'/>
<id>d5a582e95a0535ba2ec916cf0532dfe29bcd7e6e</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>jplist: Add another NULL check to prevent NULL pointer dereference</title>
<updated>2026-02-12T01:14:45+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-02-12T01:13:59+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=c4763002d20e845b566edbe499ada85b03d38dc2'/>
<id>c4763002d20e845b566edbe499ada85b03d38dc2</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Add NULL checks across codebase</title>
<updated>2026-02-12T00:20:05+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-02-12T00:20:05+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=4e82bc85671cfe50763de2637b54cb8576d7976f'/>
<id>4e82bc85671cfe50763de2637b54cb8576d7976f</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>jsmn: use size_t for token offsets and harden against overflow</title>
<updated>2026-01-21T11:26:13+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-01-21T11:24:52+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=c0f9df912d2a4001e56321fb53615e6474b32232'/>
<id>c0f9df912d2a4001e56321fb53615e6474b32232</id>
<content type='text'>
Use size_t for token start/end offsets instead of int, replace the -1
sentinel with SIZE_MAX, and add a defensive guard against offset
wraparound. This prevents overflow when parsing very large JSON inputs.

This addresses issue #282.

Credit to @ylwango613 for repporting.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Use size_t for token start/end offsets instead of int, replace the -1
sentinel with SIZE_MAX, and add a defensive guard against offset
wraparound. This prevents overflow when parsing very large JSON inputs.

This addresses issue #282.

Credit to @ylwango613 for repporting.
</pre>
</div>
</content>
</entry>
<entry>
<title>Prevent deep nesting of plist structures in all input/output formats</title>
<updated>2026-01-17T15:04:00+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-01-17T14:18:06+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.libimobiledevice.org/libplist.git/commit/?id=e45099fb21b679aa0cdb0db394587bb5ba675b0c'/>
<id>e45099fb21b679aa0cdb0db394587bb5ba675b0c</id>
<content type='text'>
Thanks to @unbengable12 for reporting. Addresses #288, #289, #290, #291, and #292.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Thanks to @unbengable12 for reporting. Addresses #288, #289, #290, #291, and #292.
</pre>
</div>
</content>
</entry>
</feed>
