summaryrefslogtreecommitdiffstats
AgeCommit message (Collapse)AuthorFilesLines
4 daysplistutil: fix missing ssize_t definition when compiling with MSVCGravatar zero1-0/+3
4 daysplist: fix inverted strcmp in string to boolean conversionGravatar Arpit Jain1-2/+2
plist_dict_get_bool() compared the string value with strcmp() but treated a non-zero return as a match. strcmp() returns 0 on equality, so the conditions were inverted: "true" produced 0, "false" produced 1, and any other string also produced 1. The error branch could never be reached, since it required both comparisons to return 0 at once. The result is that the API returns the opposite of the stored value for both valid boolean strings, and returns true for strings that are not booleans at all, instead of reporting the conversion error. Compare == 0 in both conditions: input before after true 0 1 false 1 0 not-a-bool 1 error TRUE 1 error (empty) 1 error Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
4 daysfuzz: add plist writer API fuzzerGravatar Jeewoong Kim3-0/+183
4 daysbytearray: Handle realloc() failure in byte_array_grow()Gravatar Comtea048-2/+72
byte_array_grow() assigned the result of realloc() directly to ba->data and increased the capacity even if realloc() failed, so the following memcpy() in byte_array_append() wrote to NULL + len. On failure, free the old buffer and leave the byte array in a failed state (data == NULL), which byte_array_append() already ignores. The callers check for that state: - the writers (bin, xml, json, openstep and the text output formats) return PLIST_ERR_NO_MEM instead of handing out a NULL/truncated buffer - node_to_xml() base64-encodes <data> directly into the grown buffer, so it must bail out there (only guarded by assert() before) - the OpenStep parser returns PLIST_ERR_NO_MEM for <hex data> instead of silently returning truncated data Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7 daysptrarray: Handle realloc() failure in ptr_array_insert()Gravatar Comtea044-12/+32
ptr_array_insert() assigned the result of realloc() directly to pa->pdata and bumped the capacity without checking for failure, so on out-of-memory the old buffer was leaked and the following store or memmove() wrote through a NULL pointer. Keep the old buffer on failure and return -1 from ptr_array_insert() and ptr_array_add(). The callers now handle the error: - the array lookup cache (plist.c) is dropped instead of silently going out of sync with the node list; lookups then fall back to walking the children, as they do before the cache exists - bplist parsing (used_indexes) and serialization (objects) return PLIST_ERR_NO_MEM; ignoring the error in parse_bin_node_at_index() would otherwise loop forever since the array never grows Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-05-23[github-actions] Updated build workflowGravatar Nikias Bassen1-6/+6
2026-05-22Print debug error message when encoutering invalid PLIST_DATE valuesGravatar Nikias Bassen6-0/+12
2026-05-22bplist: Use format macro to use correct format in error messageGravatar Nikias Bassen1-1/+1
2026-05-22common: validate PLIST_DATE values before Time64_T conversionGravatar Nikias Bassen9-6/+48
Avoid undefined behavior when serializing malformed PLIST_DATE values containing NaN, infinity, or values outside the Time64_T range. Add a shared helper for checked date conversion and use it across writer paths.
2026-05-22refactor: centralize formatting helpers and harden out-plutilGravatar Nikias Bassen10-435/+204
2026-05-22out-default: harden node serialization pathsGravatar Nikias Bassen1-23/+63
Improve robustness and memory safety in node_to_string() and dtostr(): - add missing NULL and allocation checks - fix snprintf() error handling and signed/unsigned conversions - replace sprintf() with snprintf() - fix base64 buffer sizing - switch string offset tracking to size_t - improve malformed data handling for strings and data blobs
2026-05-22out-limd: Properly handle snprintf and some smaller improvementsGravatar Nikias Bassen1-27/+84
2026-05-22out-limd: Fix memory buffer allocation size (#313)Gravatar Nikias Bassen1-3/+9
Credit to @Bri1987
2026-04-27Add error handling to all modification functionsGravatar Nikias Bassen2-92/+163
Convert all array/dict modification functions from void to plist_err_t return type: - plist_array_set_item: replace at index n - plist_array_append_item: append to end - plist_array_insert_item: insert at position n - plist_array_remove_item: remove item at index n - plist_array_item_remove: remove item from its array parent - plist_dict_set_item: replace or insert key/value - plist_dict_remove_item: remove key/value pair - plist_dict_merge: merge source dict into target Returns: - PLIST_ERR_SUCCESS on success - PLIST_ERR_INVALID_ARG for invalid arguments (NULL, wrong type, out of range, etc.) - PLIST_ERR_NO_MEM on memory allocation failure - PLIST_ERR_UNKNOWN on unexpected internal errors Header documentation updated with full error code semantics for each function.
2026-04-10Add OpenStep to man pageGravatar Dave Nicolson1-2/+2
2026-04-10Fix fread() unused return values by actually handling errorsGravatar Nikias Bassen5-4/+34
2026-03-30Fix Cython crashesGravatar Dave Nicolson1-1/+4
2026-03-22Add OpenStep coercion support for non-OpenStep plist typesGravatar Nikias Bassen5-35/+164
- Use PLIST_OPT_COERCE option to coerce PLIST_BOOLEAN, PLIST_DATE, PLIST_UID, and PLIST_NULL to OpenStep-compatible types (1 or 0, ISO 8601 strings, integers, and 'NULL' string) - Add plist_to_openstep_with_options() function to allow passing coercion option (and others) - Update plist_write_to_string() and plist_write_to_stream() accordingly
2026-03-20Add JSON coercion support for non-JSON plist typesGravatar Calil Khalil5-31/+165
- Add PLIST_OPT_COERCE option to coerce PLIST_DATE, PLIST_DATA, and PLIST_UID to JSON-compatible types (ISO 8601 strings, Base64 strings, and integers) - Add plist_to_json_with_options() function to allow passing coercion options (and others) - Update plist_write_to_string() and plist_write_to_stream() to support coercion option - Add --coerce flag to plistutil for JSON output - Create plist2json symlink that automatically enables coercion when invoked
2026-02-25xplist: Enforce single root value inside <plist>Gravatar Sami Kortelainen5-17/+203
Ensure that XML property lists contain exactly one root value inside the <plist> element and reject any additional value nodes before </plist>. Add tests covering root value handling and nested CF$UID conversion behavior. Co-authored-by: Sami Kortelainen <sami.kortelainen@piceasoft.com> Co-authored-by: Nikias Bassen <nikias@gmx.li>
2026-02-22xplist: Convert nested {CF$UID:<int>} dicts to PLIST_UID safelyGravatar Sami Kortelainen2-32/+100
Convert single-entry { "CF$UID" : <integer> } dictionaries to PLIST_UID nodes when closing a dict in the XML parser. Refactor node cleanup logic: - Split plist_free_data() into internal _plist_free_data() - Introduce plist_free_children() to release child nodes separately - Update plist_set_element_val() to free children before changing container node types - Ensure PLIST_DICT hashtables do not free values (assert + force free_func = NULL) This avoids in-place container mutation issues and ensures child nodes and container metadata are released correctly before changing node type. Co-authored-by: Sami Kortelainen <sami.kortelainen@piceasoft.com> Co-authored-by: Nikias Bassen <nikias@gmx.li>
2026-02-20plistutil: Read STDIN in chunks instead of 1 byte at a timeGravatar Nikias Bassen1-31/+35
2026-02-20plistutil: Add a --nodepath option to allow selecting a specific nodeGravatar Nikias Bassen2-2/+114
2026-02-20plistutil: Use getopt for solid option parsingGravatar Nikias Bassen1-89/+99
2026-02-13json: Fix a few memory leaksGravatar Nikias Bassen1-0/+25
2026-02-13libcnary: Fix leak on error in node_copy_deep()Gravatar Nikias Bassen1-0/+1
2026-02-12bplist: Add overflow check to node offset pointer arithmeticGravatar Nikias Bassen1-1/+7
Credit to OSSFuzz
2026-02-12jplist: Add another NULL check to prevent NULL pointer dereferenceGravatar Nikias Bassen1-0/+1
2026-02-12plist: make array and dict iterators opaqueGravatar Nikias Bassen2-41/+81
Introduce private iterator structs for plist_array_iter and plist_dict_iter, and fix *_next_item() to properly advance iterator state and handle malformed containers safely.
2026-02-12Add NULL checks across codebaseGravatar Nikias Bassen5-18/+197
2026-02-10plist: Make plist copy and free implementations iterativeGravatar Nikias Bassen2-48/+211
Convert plist_free_node() and plist_copy_node() to iterative implementations. This avoids unbounded recursion and stack overflow when handling deeply nested plist data, while preserving existing semantics and caches.
2026-02-08plist: Handle node_attach/node_insert failuresGravatar Nikias Bassen1-43/+154
Update plist array and dict mutation helpers to check return values from node_attach() and node_insert(). This prevents cache corruption and allows new depth and cycle checks to be enforced correctly.
2026-02-08libcnary: Fix node_detach to fully clear parent relationshipGravatar Nikias Bassen1-1/+7
Ensure node_detach() clears child->parent after removal and handles missing children lists safely. This makes detached nodes reusable and allows correct rollback when reinserting nodes after failed inserts (e.g. depth-limit failures). Without this, detached nodes could remain logically parented, causing inconsistent state and preventing reinsertion.
2026-02-06libcnary: Define error codes and add cycle, depth, and parent guardsGravatar Nikias Bassen3-67/+164
2026-01-29xplist: Improve robustness of XML text parsing and value conversionGravatar Nikias Bassen2-72/+155
This change adds stricter validation for numeric and date nodes, including full-input consumption, overflow/range checks, and rejection of invalid floating-point values. Whitespace handling is clarified by explicitly trimming trailing XML whitespace for value nodes.
2026-01-26xplist: Use small stack buffer instead of dynamic allocationsGravatar Nikias Bassen1-31/+16
This removes the necessity for malloc failures and reduces overhead
2026-01-23plistutil: Make sure to check for memory allocation failureGravatar Nikias Bassen1-1/+7
Addresses #302. Credit to @ylwango613.
2026-01-23plist: Improve plist_dict_get_item() to safely iterate key/value pairsGravatar Nikias Bassen1-24/+32
Use explicit key/value stepping, zero-initialize hash lookup key, and perform length-checked comparisons on NUL-terminated key strings.
2026-01-22bplist: Fix compiler warning with explicit castGravatar Nikias Bassen1-1/+1
Credit to @ylwango613
2026-01-22time64: Add time_s support for WIN32Gravatar Rosen Penev2-2/+6
Signed-off-by: Rosen Penev <rosenp@gmail.com>
2026-01-22plist: Fix plist_is_binary() not checking for NULL inputGravatar Nikias Bassen1-1/+1
Fixes issue #300 Credit to @jasonmli8
2026-01-22xplist: Use memcpy instead of strncpy since we know the exact sizeGravatar Nikias Bassen1-3/+3
2026-01-22xplist: Harden entity unescaping against malformed inputGravatar Nikias Bassen1-18/+32
- Fix numeric character reference parsing - Enforce exact entity name matching - Guard against size_t underflow and oversized entities - Reject invalid Unicode code points
2026-01-21bplist: Fix is_ascii_string by using sufficiently large data typeGravatar Nikias Bassen1-11/+10
Fixes #285 Credit to @ylwango613 for reporting.
2026-01-21bplist: Fix UTF-8 to UTF-16 decoding and enforce strict validationGravatar Nikias Bassen1-54/+69
- Treat input as unsigned bytes - Correct UTF-8 bit decoding for 2/3/4-byte sequences - Add overlong, surrogate, and range checks - Enforce lead/continuation byte constraints This addresses issue #283. Credit to @hgarrereyn for reporting.
2026-01-21plist: Fix incorrect size storage in plist_copy() for PLIST_STRING nodesGravatar Nikias Bassen1-3/+3
2026-01-21jsmn: use size_t for token offsets and harden against overflowGravatar Nikias Bassen3-25/+59
Use size_t for token start/end offsets instead of int, replace the -1 sentinel with SIZE_MAX, and add a defensive guard against offset wraparound. This prevents overflow when parsing very large JSON inputs. This addresses issue #282. Credit to @ylwango613 for repporting.
2026-01-20plist: Fix heap overflow caused by incorrect PLIST_STRING length during copyGravatar Nikias Bassen1-3/+18
Credit to @LkkkLxy. Addresses #277.
2026-01-20plist: Reject insertion of plist nodes that already have a parentGravatar Nikias Bassen1-57/+74
Credit to @LkkkLxy for reporting (#276). libplist nodes are owned by exactly one container. Inserting the same plist_t into multiple dicts or arrays corrupts the tree structure and leads to use-after-free crashes during traversal or plist_free(). Add explicit parent checks to dict and array insertion APIs to reject nodes that already belong to another container. In debug builds, this fails loudly via assert() and optional diagnostics; in release builds, the operation safely no-ops. Callers that need to reuse values must create a copy using plist_copy() or explicitly detach the node before reinserting it.
2026-01-17plistutil: Use proper error description for new error codesGravatar Nikias Bassen2-1/+18