2 Commits
Author SHA1 Message Date
rootvector2andLasse Collin 1aab7e9cab xz: Fix --files/--files0 usage via XZ_OPT and XZ_DEFAULTS env vars
If --files=FILELIST or --files0=FILELIST was specified via an enrivonment
variable, it worked if there were no errors when reading from the file
FILELIST. However, if an error occurred when reading from FILELIST,
there was a use-after-free bug when printing the error message because
the memory containing the string "FILELIST" had been freed.

    printf foo.xz > filelist.txt
    XZ_OPT=--files=filelist.txt xz -l

Because filelist.txt doesn't end in a newline, the file list is seen as
invalid/truncated, resulting in an error message like this:

    xz: ????????.txt: Unexpected end of input when reading filenames

The question marks are because the garbage string is masked using
tuklib_mask_nonprint(). After this commit, it works:

    xz: filelist.txt: Unexpected end of input when reading filenames

Co-authored-by: Lasse Collin <lasse.collin@tukaani.org>
Fixes: https://github.com/tukaani-project/xz/pull/223
2026-05-28 13:22:55 +03:00
rootvector2 d0d380797e xz: Mask the multiplier suffix in str_to_uint64() error message
A similar error message in the same function was masked in the
previous commit 7e7bb6c21c.

Fixes: https://github.com/tukaani-project/xz/pull/222
2026-05-28 12:58:25 +03:00