Opened 3 weeks ago

Closed 8 days ago

#6021 closed enhancement (fixed)

flit_core-4.1.0 (Python module)

Reported by: Bruce Dubbs Owned by: lfs-book
Priority: normal Milestone: 13.2
Component: Book Version: git
Severity: normal Keywords:
Cc:

Description

New minor version.

Change History (4)

comment:1 by Bruce Dubbs, 8 days ago

Summary: flit_core-4.1.0(Python module) → flit_core-4.1.0 (Python module)

Version 4.1

  • License expressions with named exceptions, the WITH syntax, are accepted
  • flit init allows dotted module names, for a component of a namespace package
  • Fix line endings in .cmd script wrappers on Windows

comment:2 by Bruce Dubbs, 8 days ago

Version 1.24.2 released 2026-09-28

  • src/preproc/html/pre-html.cpp (imageList::createImage): Fix command injection vulnerability by rejecting shell-significant syntax characters in raster image file names.
    • Problem appears to date back to commit a0fae9edb7, 2001-01-07, the initial check-in of the pre-grohtml preprocessor, which first shipped in groff 1.17.

  • src/roff/troff/input.cpp (do_suppress): Reject \O5 output suppression escape sequence if it contains shell-unsafe characters in the file name portion of its argument, to advise user of limitation of pre-grohtml(1) preprocessor.
    • While blindly passing shell-unsafe characters via the \O5 escape sequence is not _itself_ an avenue for command injection, the only _consumer_ of such escape sequences is the pre-grohtml preprocessor (which is vulnerable), so performing strict input validation here makes sense.

  • src/utils/pdfmom/pdfmom.pl: Pass arguments from command line through Clean subroutine. (Clean): New subroutinze sanitizes command-line arguments to defeat command injection vulnerability.
    • Problem appears to date back to commit f2a501fff5, 2012-08-31, the initial check-in of the pdfmom command script, which first shipped in groff 1.22.1.
  • src/devices/xditview/xditview.c (main): Avoid invalid memory access by checking that argc is greater than 1 before trying to access argv[1].

comment:3 by Bruce Dubbs, 8 days ago

  • Noteworthy changes in release 1.15 (2026-09-20) [stable]

Bug fixes

gzip no longer can mistakenly remove the wrong file if some other process simultaneously renames a gzip destination's ancestor. [bug present since the beginning]

gzip -d no longer rejects PKZIP signatures, local header, and data descriptors. These can appear in well-formed streamed zip files. [bug present since the beginning]

gzip diagnostics now quote file names containing unusual characters. [bug present since the beginning]

A use of uninitialized memory on some malformed inputs has been fixed. [bug present since the beginning]

A buffer overflow has been fixed when decompressing an .lzh file after decompressing a .Z file. [bug present since the beginning]

When decompressing an .lzh file, the output is no longer corrupted when an internal bit buffer is not properly cleared. [bug present since the beginning]

When decompressing an .lzh file after another .lzh file, the output is no longer corrupted by the previous file's decoding table. [bug present since the beginning]

gzip --synchronous no longer fails to synchronize unreadable parent directories on platforms like GNU/Linux that have O_PATH, or to synchronize any parent directories on platforms like FreeBSD that have O_SEARCH but not O_PATH. [bug introduced in gzip-1.7]

On old-fashioned or limited platforms lacking mktemp, gzexe, zdiff and znew no longer have a race when creating a temporary file. [bug present since the beginning]

Changes in behavior

gzip no longer insists on the "C" locale; instead, it follows the typical practice of using the locale specified by the environment. This change, which is needed for file name quoting, can affect the format of floating-point numbers output by gzip's -l and -v options. Diagnostics are still in English, though.

gzip -l now reports "-Inf%" instead of "0.0%" for the infinite compression ratio of an empty file.

znew's -P option is now ignored, with a warning. It was present only to improve performance, and its implementation had too many bugs to be worth supporting.

Platforms no longer supported

The following platforms (or earlier) are no longer supported because their old multibyte libraries do not work well enough: FreeBSD 4.11 (2005), HP-UX 11.00 (1997), Minix 3.1.8 (2010), MS-Windows 8.1 (2013) via mingw without UCRT.

comment:4 by Bruce Dubbs, 8 days ago

Resolution: → fixed
Status: new → closed

Fixed at commit 9bb7b28d5.

Note: See TracTickets for help on using tickets.