From b8f710959ec528aea6c0dcac8776b2174f459d24 Mon Sep 17 00:00:00 2001 From: Danil Silantyev Date: Tue, 29 Sep 2026 14:49:05 +0500 Subject: [PATCH] feat: a release of this repository Published at 0.0.81. Propose changes through this repository's issues and pull requests. --- CHANGELOG.md | 8 ++++++++ Cargo.lock | 8 ++++---- Cargo.toml | 8 ++++---- README.md | 2 +- crates/setup-core/src/archive.rs | 26 +++++++++++++++++++++++--- install.ps1 | 2 +- install.sh | 2 +- 7 files changed, 42 insertions(+), 14 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9a408f3..2e493fa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -15,6 +15,14 @@ cut and that this clone does not carry. ## [Unreleased] +## [0.0.81] - 2026-09-29 + +The shared ZIP reader now flushes DEFLATE output buffered after the +last compressed byte. This lets the valid pi Windows x64 distribution pass +archive extraction and its evidence workflow. Truncated streams still fail +with an integrity error. Verification commands in the other six harnesses +and the provider protocol are unchanged. + ## [0.0.80] - 2026-09-29 The shared kernel extends linked-descent refusal to every staged diff --git a/Cargo.lock b/Cargo.lock index d9bfeca..3512c46 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -25,7 +25,7 @@ checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801" [[package]] name = "codex-setup-system" -version = "0.0.80" +version = "0.0.81" dependencies = [ "harness-runtime", "provider-v3", @@ -76,7 +76,7 @@ checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f" [[package]] name = "harness-runtime" -version = "0.0.80" +version = "0.0.81" dependencies = [ "provider-v3", "serde", @@ -147,7 +147,7 @@ dependencies = [ [[package]] name = "provider-v3" -version = "0.0.80" +version = "0.0.81" dependencies = [ "serde", "serde_json", @@ -209,7 +209,7 @@ dependencies = [ [[package]] name = "setup-core" -version = "0.0.80" +version = "0.0.81" dependencies = [ "miniz_oxide", "serde", diff --git a/Cargo.toml b/Cargo.toml index b22850b..a225a90 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -8,7 +8,7 @@ members = [ ] [workspace.package] -version = "0.0.80" +version = "0.0.81" edition = "2024" rust-version = "1.89" license = "AGPL-3.0-or-later" @@ -23,9 +23,9 @@ sha2 = "0.11" # `setup-core::archive`); an inflate loop is not, because its bugs are # memory-safety bugs and it is not improved by being hand-written here. miniz_oxide = "0.9" -setup-core = { path = "crates/setup-core", version = "0.0.80" } -provider-v3 = { path = "crates/provider-v3", version = "0.0.80" } -harness-runtime = { path = "crates/harness-runtime", version = "0.0.80" } +setup-core = { path = "crates/setup-core", version = "0.0.81" } +provider-v3 = { path = "crates/provider-v3", version = "0.0.81" } +harness-runtime = { path = "crates/harness-runtime", version = "0.0.81" } [workspace.lints.rust] unsafe_code = "forbid" diff --git a/README.md b/README.md index 641a8c6..fce1187 100644 --- a/README.md +++ b/README.md @@ -179,7 +179,7 @@ release is a convenience, not the authorised copy. ```bash docker run --rm -v "$HOME/.config:/config" \ - ghcr.io/nddev-opennetwork/codex-setup-system:0.0.80 \ + ghcr.io/nddev-opennetwork/codex-setup-system:0.0.81 \ status --target /config/ --json ``` diff --git a/crates/setup-core/src/archive.rs b/crates/setup-core/src/archive.rs index 727abc5..95e2352 100644 --- a/crates/setup-core/src/archive.rs +++ b/crates/setup-core/src/archive.rs @@ -992,9 +992,6 @@ mod zip { .read(&mut input) .map_err(|error| from_source_io("zip entry could not be read", error))?; consumed = 0; - if filled == 0 { - return Err(refuse("zip entry ended before its DEFLATE stream did")); - } } let result = miniz_oxide::inflate::stream::inflate( &mut state, @@ -1012,8 +1009,14 @@ mod zip { } match result.status { Ok(miniz_oxide::MZStatus::StreamEnd) => return Ok((crc, length)), + Ok(_) if filled == 0 && written == 0 => { + return Err(refuse("zip entry ended before its DEFLATE stream did")); + } Ok(_) => {} Err(error) => { + if filled == 0 && error == miniz_oxide::MZError::Buf { + return Err(refuse("zip entry ended before its DEFLATE stream did")); + } return Err(refuse(format!( "zip entry's DEFLATE stream is malformed: {error:?}" ))); @@ -2096,4 +2099,21 @@ mod tests { sizes, so the answer is knowable before the first byte lands" ); } + + #[test] + fn a_deflate_entry_flushes_buffered_output_at_eof() { + let mut body = vec![0_u8; 1_000_000]; + let mut state = 0x1234_5678_u32; + for byte in &mut body { + state ^= state << 13; + state ^= state >> 17; + state ^= state << 5; + *byte = state.to_le_bytes()[0]; + } + let archive = zip_bytes(&[("large.bin", &body, false)]); + let room = scratch("zip-buffered-eof"); + extract_zip(io::Cursor::new(archive), &room, ROOMY).unwrap(); + assert_eq!(read(&room, "large.bin"), body); + fs::remove_dir_all(&room).unwrap(); + } } diff --git a/install.ps1 b/install.ps1 index b0eb0cf..33d4665 100644 --- a/install.ps1 +++ b/install.ps1 @@ -7,7 +7,7 @@ # powershell -ExecutionPolicy Bypass -File install.ps1 -Version 0.1.0 [CmdletBinding()] param( - [string]$Version = "0.0.80", + [string]$Version = "0.0.81", [string]$InstallDir = "$env:LOCALAPPDATA\Programs\codex-setup-system" ) $ErrorActionPreference = "Stop" diff --git a/install.sh b/install.sh index 62d5d4c..f9e4a11 100644 --- a/install.sh +++ b/install.sh @@ -14,7 +14,7 @@ set -eu REPO="NDDev-OpenNetwork/codex-setup-system" BINARY="codex-setup-system" -VERSION="${1:-0.0.80}" +VERSION="${1:-0.0.81}" PREFIX="${CODEX_INSTALL_DIR:-$HOME/.local/bin}" case "$(uname -s)" in