Add missing libarchive flags, some security tests #61
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hi,
I've been using your library to process untrusted archives provided by the users and have noticed that two flags were missing, one of which is important when dealing with untrusted input (EXTRACT_SECURE_NOABSOLUTEPATHS).
They have been supported by libarchive for around two years so it's a stable feature that I think should be merged to your library. Take a look at
man archive_write_disk.3
for details.This pull request adds them and provides a couple of tests for two security features that are important to me at the moment.
I'll add more tests to cover the remaining flags when I have some free time.
Thanks for a great library, it saved me a lot of work.
Cheers.
--
Add missing flags supported by libarchive:
Add some tests for security options: