| 1 |
root |
1.1 |
Revision history for Perl extension CBOR::XS |
| 2 |
|
|
|
| 3 |
root |
1.30 |
TODO: pack_keys? |
| 4 |
root |
1.36 |
TODO: document encode_cbor_sharing? |
| 5 |
root |
1.38 |
TODO: weaken cyclic structures? |
| 6 |
root |
1.70 |
TODO: large negative integers |
| 7 |
root |
1.76 |
|
| 8 |
|
|
1.6 Wed Dec 7 15:13:23 CET 2016 |
| 9 |
root |
1.75 |
- greatly expand the SECURITY IMPLICATIONS and similar sections. |
| 10 |
root |
1.74 |
- new constructor new_safe, to create a secure CBOR::XS object. |
| 11 |
|
|
- new option forbid_objects, to disallow serialisation. |
| 12 |
|
|
- new CBOR::XS::safe_filter functionality. |
| 13 |
root |
1.69 |
- fix a crash when decoding a cyclic data structure using |
| 14 |
|
|
stringref/pack_strings when allow_cycles is disabled. |
| 15 |
root |
1.71 |
- fix a crash when decoding hash keys with length >= 2**31. |
| 16 |
|
|
- avoid unreasonably long decoding times for certain |
| 17 |
root |
1.75 |
types of (corrupt) cbor texts. |
| 18 |
root |
1.71 |
- support arrays and hashes with >= 2**31 members. |
| 19 |
|
|
- avoid overflow on pointer arithmetic when checking whether enough |
| 20 |
|
|
data is available. |
| 21 |
root |
1.72 |
- fix a memory leak that occured when decoding failed while decoding |
| 22 |
|
|
a tagged value. |
| 23 |
root |
1.73 |
- do not leak the partially constructed result when stringifying |
| 24 |
|
|
a hash key throws an exception. |
| 25 |
root |
1.74 |
- various code size and efficiency optimizations (reduced code |
| 26 |
root |
1.75 |
from 42 to 40kB on my system, despite the new features). |
| 27 |
root |
1.46 |
|
| 28 |
root |
1.67 |
1.5 Wed Apr 27 11:38:39 CEST 2016 |
| 29 |
root |
1.61 |
- Math::BigFloat madness workaround, see |
| 30 |
|
|
http://blog.schmorp.de/2016-04-23-mathbigfloat-maintainer-fail.html |
| 31 |
root |
1.57 |
(bugreport by zdm@softvisio.net). |
| 32 |
root |
1.61 |
- add text_keys and text_strings options to force CBOR text encoding |
| 33 |
|
|
for perl hash keys or all strings, as a result of discussions |
| 34 |
|
|
with Fredrik Ljunggren. |
| 35 |
root |
1.64 |
- implement support for arbitrary-exponent numbers (see |
| 36 |
|
|
http://peteroupc.github.io/CBOR/bigfrac.html, tags 264 and 265) |
| 37 |
|
|
for both en- and decoding. |
| 38 |
root |
1.65 |
- implement support for rational numbers (see |
| 39 |
|
|
http://peteroupc.github.io/CBOR/rational.html, tag 30) for both |
| 40 |
|
|
en- and decoding. |
| 41 |
root |
1.67 |
- the above effectively implements all registered CBOR extensions |
| 42 |
root |
1.66 |
in a sensible manner. |
| 43 |
root |
1.67 |
- remove some weird dead code that was duplicated (%FILTER). |
| 44 |
root |
1.60 |
- add t/58_hv.t, which tests hashes and the new text_* flags. |
| 45 |
root |
1.67 |
hashes apparently were not encoded at all in any of the existing |
| 46 |
root |
1.60 |
tests. |
| 47 |
root |
1.67 |
- document Math::BigFloat base-2 performance/crash issues. |
| 48 |
root |
1.62 |
- use stability canary. |
| 49 |
root |
1.57 |
|
| 50 |
root |
1.56 |
1.41 Thu 25 Feb 15:22:03 CET 2016 |
| 51 |
|
|
- avoid perl panics on nested FREEZE/THAW calls (testcase by |
| 52 |
|
|
Victor Efimov). |
| 53 |
|
|
|
| 54 |
root |
1.54 |
1.4 Mon Feb 8 05:10:15 CET 2016 |
| 55 |
|
|
- buffer overflow fix: a fast path during decoding did not check |
| 56 |
|
|
remaining length when decoding hash keys, found by fuzzing. |
| 57 |
root |
1.55 |
This can potentially leak information in the error message |
| 58 |
|
|
or crash the process. |
| 59 |
root |
1.53 |
- use C style { 0 } struct initializer. |
| 60 |
root |
1.54 |
- upgrade libecb. |
| 61 |
root |
1.53 |
|
| 62 |
root |
1.52 |
1.3 Mon Apr 27 22:21:04 CEST 2015 |
| 63 |
|
|
- the incremental parser didn't properly parse tagged values |
| 64 |
|
|
(testcase by Mons Anderson). |
| 65 |
root |
1.50 |
- slightly speed up encoding of plain (nonmagical) arrays. |
| 66 |
root |
1.51 |
- try to clarify further that effectively all 32 bit architectures |
| 67 |
|
|
have 64 bit integer support. |
| 68 |
root |
1.52 |
- upgrade libecb. |
| 69 |
root |
1.50 |
|
| 70 |
root |
1.49 |
1.26 Sat Oct 25 08:35:44 CEST 2014 |
| 71 |
root |
1.47 |
- update the t/57_incr.t subtest that would rely on 64 bit ints. |
| 72 |
root |
1.48 |
- disable t/50_rfc.t test that fails because of broken data::dumper. |
| 73 |
root |
1.47 |
|
| 74 |
root |
1.46 |
1.25 Sun Jan 5 15:19:14 CET 2014 |
| 75 |
|
|
- map key decoding was pretty much botched due to the recent cleanups. |
| 76 |
|
|
- work around Time::Piece->epoch returning a string value, avoid encoding |
| 77 |
|
|
this as a tag 1 string. |
| 78 |
|
|
- enable more testcases in t/50_rfc.t, now that they work :) |
| 79 |
|
|
|
| 80 |
|
|
1.2 Tue Dec 10 22:06:42 CET 2013 |
| 81 |
|
|
- implement an incremental decoder. |
| 82 |
root |
1.39 |
|
| 83 |
root |
1.44 |
1.12 Tue Dec 3 11:23:22 CET 2013 |
| 84 |
root |
1.45 |
- work around broken Time::Piece (in old versions of the module, %z doesn't |
| 85 |
|
|
work as documented, gives different results on different platforms(!)). |
| 86 |
root |
1.43 |
|
| 87 |
root |
1.42 |
1.11 Sun Dec 1 18:00:00 CET 2013 |
| 88 |
root |
1.39 |
- new setting: validate_utf8, for when you can't trust your cbor data. |
| 89 |
|
|
- do not leak memory on decoding errors, when allow_cycles is enabled. |
| 90 |
root |
1.41 |
- add default filters for tags 0 and 1, using Time::Piece. |
| 91 |
root |
1.42 |
- more tests added. |
| 92 |
root |
1.30 |
|
| 93 |
root |
1.37 |
1.1 Sat Nov 30 19:14:27 CET 2013 |
| 94 |
root |
1.36 |
- INCOMPATIBLE CHANGE: new decoder setting: allow_cyclic, needed to decode |
| 95 |
|
|
cyclic data structures (to avoid memleaks in unsuspecting code). |
| 96 |
root |
1.37 |
- no longer "share" references that aren't, i.e. true/false/null/error/tagged. |
| 97 |
root |
1.32 |
- fix stringref w.r.t. indefinite-length strings. |
| 98 |
|
|
- verify indefinite-length string chunk types. |
| 99 |
root |
1.35 |
- do not allow extremely large arrays - assume an array element |
| 100 |
root |
1.37 |
requires at least one CBOR byte, to avoid memory exhaustion attacks. |
| 101 |
root |
1.34 |
- major code overhaul. |
| 102 |
root |
1.32 |
|
| 103 |
root |
1.31 |
1.0 Thu Nov 28 16:43:31 CET 2013 |
| 104 |
root |
1.28 |
- use the now official tag values for extensions. remove the |
| 105 |
|
|
experimental notice. it's the real thing now, with real bugs. |
| 106 |
root |
1.29 |
- renamed allow_stringref to pack_strings. |
| 107 |
root |
1.27 |
- port to perl <= 5.16. |
| 108 |
root |
1.31 |
- slightly improve the documentation. |
| 109 |
root |
1.27 |
|
| 110 |
root |
1.25 |
0.09 Fri Nov 22 16:54:18 CET 2013 |
| 111 |
root |
1.24 |
- bignum/bigfloat/decimal support. |
| 112 |
|
|
- uri support. |
| 113 |
|
|
- tag filter functions support for decoding. |
| 114 |
root |
1.21 |
- do not support reference-to-1/0/undef anymore, you need to use |
| 115 |
|
|
the Types::Serialiser objects now. |
| 116 |
|
|
- experimental sharable extension support (http://cbor.schmorp.de/value-sharing). |
| 117 |
root |
1.22 |
- experimental stringref extension support (http://cbor.schmorp.de/stringref). |
| 118 |
root |
1.21 |
- implement indirection tag (http://cbor.schmorp.de/indirection). |
| 119 |
|
|
|
| 120 |
root |
1.20 |
0.08 Wed Oct 30 11:10:43 CET 2013 |
| 121 |
root |
1.19 |
- defused another too fragile test. |
| 122 |
|
|
|
| 123 |
root |
1.18 |
0.07 Tue Oct 29 23:04:07 CET 2013 |
| 124 |
root |
1.17 |
- don't crash in decode when silly values are passed in. |
| 125 |
|
|
- considerably speed up map decoding when map keys |
| 126 |
|
|
are utf-8 or byte strings. |
| 127 |
root |
1.18 |
- raising an exception in THAW should now work without |
| 128 |
|
|
leaking. |
| 129 |
root |
1.17 |
|
| 130 |
root |
1.16 |
0.06 Tue Oct 29 16:56:07 CET 2013 |
| 131 |
root |
1.14 |
- do not leak when deserialiasing via THAW. |
| 132 |
root |
1.15 |
- implement and document CBOR::XS creation/access/mutate |
| 133 |
|
|
methods. |
| 134 |
root |
1.14 |
|
| 135 |
root |
1.13 |
0.05 Mon Oct 28 22:27:47 CET 2013 |
| 136 |
root |
1.12 |
- do not leak hash keys on decoding. |
| 137 |
|
|
|
| 138 |
root |
1.11 |
0.04 Sun Oct 27 23:47:47 CET 2013 |
| 139 |
root |
1.10 |
- implement TO_CBOR/FREEZE/THAW serialisation protocols. |
| 140 |
root |
1.7 |
- requested perl-object and generic-object tags from iana. |
| 141 |
root |
1.9 |
- switched to Types::Serialiser for true, false and error. |
| 142 |
root |
1.8 |
- disabled some fragile tests (thanks, andk). |
| 143 |
root |
1.7 |
|
| 144 |
root |
1.6 |
0.03 Sun Oct 27 00:28:41 CEST 2013 |
| 145 |
root |
1.4 |
- improve 32 bit platform compatibility. |
| 146 |
root |
1.5 |
- take more advantage of ecb.h. |
| 147 |
root |
1.6 |
- preliminary and bare-bones tagged support. |
| 148 |
|
|
- improved docs. |
| 149 |
root |
1.4 |
|
| 150 |
root |
1.3 |
0.02 Sat Oct 26 13:08:05 CEST 2013 |
| 151 |
|
|
- no aborts left. |
| 152 |
|
|
- add $CBOR::XS::MAGIC. |
| 153 |
|
|
- preliminary tagged decoding to arrayref. |
| 154 |
root |
1.2 |
- indefinite encoding fixed. |
| 155 |
|
|
- half float decoding implemented. |
| 156 |
|
|
- t/50_rfc.t adds test vectors from the rfc, which |
| 157 |
|
|
are checked as applicable. |
| 158 |
|
|
|
| 159 |
root |
1.1 |
0.01 Fri Oct 25 21:39:56 CEST 2013 |
| 160 |
|
|
- original version; cloned from JSON-XS |
| 161 |
|
|
|