ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/CBOR-XS/Changes
(Generate patch)

Comparing CBOR-XS/Changes (file contents):
Revision 1.63 by root, Mon Apr 25 21:30:23 2016 UTC vs.
Revision 1.77 by root, Tue Jun 27 02:03:23 2017 UTC

1Revision history for Perl extension CBOR::XS 1Revision history for Perl extension CBOR::XS
2 2
3TODO: pack_keys? 3TODO: pack_keys?
4TODO: document encode_cbor_sharing? 4TODO: document encode_cbor_sharing?
5TODO: weaken cyclic structures? 5TODO: weaken cyclic structures?
6TODO: allowed_classes or so? 6TODO: large negative integers
7 7
81.5 81.7 Tue Jun 27 04:02:23 CEST 2017
9 - SECURITY FIX: fix two bugs found by american fuzzy lop,
10 upgrade is advised if you accept data from untrusted
11 sources.
12 - an out-of bound sharedref or stringref index could cause an
13 out of bounds access - might be exploitable.
14 - a decoding error during indefinite array or hash decoding
15 could cause an endless loop.
16
171.6 Wed Dec 7 15:13:23 CET 2016
18 - greatly expand the SECURITY IMPLICATIONS and similar sections.
19 - new constructor new_safe, to create a secure CBOR::XS object.
20 - new option forbid_objects, to disallow serialisation.
21 - new CBOR::XS::safe_filter functionality.
22 - fix a crash when decoding a cyclic data structure using
23 stringref/pack_strings when allow_cycles is disabled.
24 - fix a crash when decoding hash keys with length >= 2**31.
25 - avoid unreasonably long decoding times for certain
26 types of (corrupt) cbor texts.
27 - support arrays and hashes with >= 2**31 members.
28 - avoid overflow on pointer arithmetic when checking whether enough
29 data is available.
30 - fix a memory leak that occured when decoding failed while decoding
31 a tagged value.
32 - do not leak the partially constructed result when stringifying
33 a hash key throws an exception.
34 - various code size and efficiency optimizations (reduced code
35 from 42 to 40kB on my system, despite the new features).
36
371.5 Wed Apr 27 11:38:39 CEST 2016
9 - Math::BigFloat madness workaround, see 38 - Math::BigFloat madness workaround, see
10 http://blog.schmorp.de/2016-04-23-mathbigfloat-maintainer-fail.html 39 http://blog.schmorp.de/2016-04-23-mathbigfloat-maintainer-fail.html
11 (bugreport by zdm@softvisio.net). 40 (bugreport by zdm@softvisio.net).
12 - add text_keys and text_strings options to force CBOR text encoding 41 - add text_keys and text_strings options to force CBOR text encoding
13 for perl hash keys or all strings, as a result of discussions 42 for perl hash keys or all strings, as a result of discussions
14 with Fredrik Ljunggren. 43 with Fredrik Ljunggren.
15 - remove some weird dead code that was duplication (%FILTER).
16 - add t/58_hv.t, which tests hashes and the new text_* flags.
17 hashes apparently were not encoded at all in any of the previous
18 tests.
19 - implement support for arbitrary-exponent numbers (see 44 - implement support for arbitrary-exponent numbers (see
20 http://peteroupc.github.io/CBOR/bigfrac.html, tags 264 and 265) 45 http://peteroupc.github.io/CBOR/bigfrac.html, tags 264 and 265)
21 for both en- and decoding. 46 for both en- and decoding.
47 - implement support for rational numbers (see
48 http://peteroupc.github.io/CBOR/rational.html, tag 30) for both
49 en- and decoding.
50 - the above effectively implements all registered CBOR extensions
51 in a sensible manner.
52 - remove some weird dead code that was duplicated (%FILTER).
53 - add t/58_hv.t, which tests hashes and the new text_* flags.
54 hashes apparently were not encoded at all in any of the existing
55 tests.
22 - document base-2 Math::BigFloat performance/crash issues. 56 - document Math::BigFloat base-2 performance/crash issues.
23 - use stability canary. 57 - use stability canary.
24 58
251.41 Thu 25 Feb 15:22:03 CET 2016 591.41 Thu 25 Feb 15:22:03 CET 2016
26 - avoid perl panics on nested FREEZE/THAW calls (testcase by 60 - avoid perl panics on nested FREEZE/THAW calls (testcase by
27 Victor Efimov). 61 Victor Efimov).

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines