Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,14 @@ cut and that this clone does not carry.

## [Unreleased]

## [0.0.81] - 2026-09-29

The shared ZIP reader now flushes DEFLATE output buffered after the
last compressed byte. This lets the valid pi Windows x64 distribution pass
archive extraction and its evidence workflow. Truncated streams still fail
with an integrity error. Verification commands in the other six harnesses
and the provider protocol are unchanged.

## [0.0.80] - 2026-09-29

The shared kernel extends linked-descent refusal to every staged
Expand Down
8 changes: 4 additions & 4 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

8 changes: 4 additions & 4 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ members = [
]

[workspace.package]
version = "0.0.80"
version = "0.0.81"
edition = "2024"
rust-version = "1.89"
license = "AGPL-3.0-or-later"
Expand All @@ -23,9 +23,9 @@ sha2 = "0.11"
# `setup-core::archive`); an inflate loop is not, because its bugs are
# memory-safety bugs and it is not improved by being hand-written here.
miniz_oxide = "0.9"
setup-core = { path = "crates/setup-core", version = "0.0.80" }
provider-v3 = { path = "crates/provider-v3", version = "0.0.80" }
harness-runtime = { path = "crates/harness-runtime", version = "0.0.80" }
setup-core = { path = "crates/setup-core", version = "0.0.81" }
provider-v3 = { path = "crates/provider-v3", version = "0.0.81" }
harness-runtime = { path = "crates/harness-runtime", version = "0.0.81" }

[workspace.lints.rust]
unsafe_code = "forbid"
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -179,7 +179,7 @@ release is a convenience, not the authorised copy.

```bash
docker run --rm -v "$HOME/.config:/config" \
ghcr.io/nddev-opennetwork/codex-setup-system:0.0.80 \
ghcr.io/nddev-opennetwork/codex-setup-system:0.0.81 \
status --target /config/<dir> --json
```

Expand Down
26 changes: 23 additions & 3 deletions crates/setup-core/src/archive.rs
Original file line number Diff line number Diff line change
Expand Up @@ -992,9 +992,6 @@ mod zip {
.read(&mut input)
.map_err(|error| from_source_io("zip entry could not be read", error))?;
consumed = 0;
if filled == 0 {
return Err(refuse("zip entry ended before its DEFLATE stream did"));
}
}
let result = miniz_oxide::inflate::stream::inflate(
&mut state,
Expand All @@ -1012,8 +1009,14 @@ mod zip {
}
match result.status {
Ok(miniz_oxide::MZStatus::StreamEnd) => return Ok((crc, length)),
Ok(_) if filled == 0 && written == 0 => {
return Err(refuse("zip entry ended before its DEFLATE stream did"));
}
Ok(_) => {}
Err(error) => {
if filled == 0 && error == miniz_oxide::MZError::Buf {
return Err(refuse("zip entry ended before its DEFLATE stream did"));
}
return Err(refuse(format!(
"zip entry's DEFLATE stream is malformed: {error:?}"
)));
Expand Down Expand Up @@ -2096,4 +2099,21 @@ mod tests {
sizes, so the answer is knowable before the first byte lands"
);
}

#[test]
fn a_deflate_entry_flushes_buffered_output_at_eof() {
let mut body = vec![0_u8; 1_000_000];
let mut state = 0x1234_5678_u32;
for byte in &mut body {
state ^= state << 13;
state ^= state >> 17;
state ^= state << 5;
*byte = state.to_le_bytes()[0];
}
let archive = zip_bytes(&[("large.bin", &body, false)]);
let room = scratch("zip-buffered-eof");
extract_zip(io::Cursor::new(archive), &room, ROOMY).unwrap();
assert_eq!(read(&room, "large.bin"), body);
fs::remove_dir_all(&room).unwrap();
}
}
2 changes: 1 addition & 1 deletion install.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
# powershell -ExecutionPolicy Bypass -File install.ps1 -Version 0.1.0
[CmdletBinding()]
param(
[string]$Version = "0.0.80",
[string]$Version = "0.0.81",
[string]$InstallDir = "$env:LOCALAPPDATA\Programs\codex-setup-system"
)
$ErrorActionPreference = "Stop"
Expand Down
2 changes: 1 addition & 1 deletion install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ set -eu

REPO="NDDev-OpenNetwork/codex-setup-system"
BINARY="codex-setup-system"
VERSION="${1:-0.0.80}"
VERSION="${1:-0.0.81}"
PREFIX="${CODEX_INSTALL_DIR:-$HOME/.local/bin}"

case "$(uname -s)" in
Expand Down
Loading