<feed xmlns='http://www.w3.org/2005/Atom'>
<title>libplist, branch 2.8.0</title>
<subtitle>Library to handle Apple Property List format files in binary or XML</subtitle>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/'/>
<entry>
<title>Updated NEWS for release</title>
<updated>2026-09-29T23:37:53+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-09-29T23:37:53+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/commit/?id=fe3dc34dc3484006e12b403f7ceb06f0ad40b6f4'/>
<id>fe3dc34dc3484006e12b403f7ceb06f0ad40b6f4</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Bump soversion for release</title>
<updated>2026-09-29T23:34:04+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-09-29T23:34:04+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/commit/?id=93133cb7288062c3598083619983447a514af452'/>
<id>93133cb7288062c3598083619983447a514af452</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>plistutil: preserve binary data on Windows standard streams</title>
<updated>2026-09-29T15:00:18+00:00</updated>
<author>
<name>Alberto Maschietto</name>
</author>
<published>2026-09-07T21:12:20+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/commit/?id=fba74cf8bd9696b9b7f42a8cbb9e16dd065b0a83'/>
<id>fba74cf8bd9696b9b7f42a8cbb9e16dd065b0a83</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>plistutil: fix missing ssize_t definition when compiling with MSVC</title>
<updated>2026-09-29T14:58:36+00:00</updated>
<author>
<name>zero</name>
</author>
<published>2026-08-25T10:05:34+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/commit/?id=2b0754dee5c5b9c4b3d5114359436e7b737a57f4'/>
<id>2b0754dee5c5b9c4b3d5114359436e7b737a57f4</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>plist: fix inverted strcmp in string to boolean conversion</title>
<updated>2026-09-29T14:43:02+00:00</updated>
<author>
<name>Arpit Jain</name>
</author>
<published>2026-07-29T05:25:18+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/commit/?id=bd68e726e45c10fd223814eaf6129e1bb2f7b022'/>
<id>bd68e726e45c10fd223814eaf6129e1bb2f7b022</id>
<content type='text'>
plist_dict_get_bool() compared the string value with strcmp() but treated a
non-zero return as a match. strcmp() returns 0 on equality, so the conditions
were inverted: "true" produced 0, "false" produced 1, and any other string
also produced 1. The error branch could never be reached, since it required
both comparisons to return 0 at once.

The result is that the API returns the opposite of the stored value for both
valid boolean strings, and returns true for strings that are not booleans at
all, instead of reporting the conversion error.

Compare == 0 in both conditions:

  input          before   after
  true           0        1
  false          1        0
  not-a-bool     1        error
  TRUE           1        error
  (empty)        1        error

Signed-off-by: Arpit Jain &lt;arpitjain099@gmail.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
plist_dict_get_bool() compared the string value with strcmp() but treated a
non-zero return as a match. strcmp() returns 0 on equality, so the conditions
were inverted: "true" produced 0, "false" produced 1, and any other string
also produced 1. The error branch could never be reached, since it required
both comparisons to return 0 at once.

The result is that the API returns the opposite of the stored value for both
valid boolean strings, and returns true for strings that are not booleans at
all, instead of reporting the conversion error.

Compare == 0 in both conditions:

  input          before   after
  true           0        1
  false          1        0
  not-a-bool     1        error
  TRUE           1        error
  (empty)        1        error

Signed-off-by: Arpit Jain &lt;arpitjain099@gmail.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>fuzz: add plist writer API fuzzer</title>
<updated>2026-09-29T14:41:08+00:00</updated>
<author>
<name>Jeewoong Kim</name>
</author>
<published>2026-07-07T12:46:20+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/commit/?id=be3a7ff2862868b4612d4c56edbd42e1d7dd7fdb'/>
<id>be3a7ff2862868b4612d4c56edbd42e1d7dd7fdb</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>bytearray: Handle realloc() failure in byte_array_grow()</title>
<updated>2026-09-29T14:39:28+00:00</updated>
<author>
<name>Comtea04</name>
</author>
<published>2026-09-27T06:06:22+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/commit/?id=f168c10b52325b00da6355989a18a11743b33f89'/>
<id>f168c10b52325b00da6355989a18a11743b33f89</id>
<content type='text'>
byte_array_grow() assigned the result of realloc() directly to
ba-&gt;data and increased the capacity even if realloc() failed, so the
following memcpy() in byte_array_append() wrote to NULL + len.

On failure, free the old buffer and leave the byte array in a failed
state (data == NULL), which byte_array_append() already ignores. The
callers check for that state:

- the writers (bin, xml, json, openstep and the text output formats)
  return PLIST_ERR_NO_MEM instead of handing out a NULL/truncated buffer
- node_to_xml() base64-encodes &lt;data&gt; directly into the grown buffer,
  so it must bail out there (only guarded by assert() before)
- the OpenStep parser returns PLIST_ERR_NO_MEM for &lt;hex data&gt; instead of
  silently returning truncated data

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
byte_array_grow() assigned the result of realloc() directly to
ba-&gt;data and increased the capacity even if realloc() failed, so the
following memcpy() in byte_array_append() wrote to NULL + len.

On failure, free the old buffer and leave the byte array in a failed
state (data == NULL), which byte_array_append() already ignores. The
callers check for that state:

- the writers (bin, xml, json, openstep and the text output formats)
  return PLIST_ERR_NO_MEM instead of handing out a NULL/truncated buffer
- node_to_xml() base64-encodes &lt;data&gt; directly into the grown buffer,
  so it must bail out there (only guarded by assert() before)
- the OpenStep parser returns PLIST_ERR_NO_MEM for &lt;hex data&gt; instead of
  silently returning truncated data

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>ptrarray: Handle realloc() failure in ptr_array_insert()</title>
<updated>2026-09-27T06:06:22+00:00</updated>
<author>
<name>Comtea04</name>
</author>
<published>2026-09-27T06:06:22+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/commit/?id=8b48fa72d359de89215f50cbf6ac8c77ae5de9b4'/>
<id>8b48fa72d359de89215f50cbf6ac8c77ae5de9b4</id>
<content type='text'>
ptr_array_insert() assigned the result of realloc() directly to
pa-&gt;pdata and bumped the capacity without checking for failure, so on
out-of-memory the old buffer was leaked and the following store or
memmove() wrote through a NULL pointer.

Keep the old buffer on failure and return -1 from ptr_array_insert()
and ptr_array_add(). The callers now handle the error:

- the array lookup cache (plist.c) is dropped instead of silently going
  out of sync with the node list; lookups then fall back to walking
  the children, as they do before the cache exists
- bplist parsing (used_indexes) and serialization (objects) return
  PLIST_ERR_NO_MEM; ignoring the error in parse_bin_node_at_index()
  would otherwise loop forever since the array never grows

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
ptr_array_insert() assigned the result of realloc() directly to
pa-&gt;pdata and bumped the capacity without checking for failure, so on
out-of-memory the old buffer was leaked and the following store or
memmove() wrote through a NULL pointer.

Keep the old buffer on failure and return -1 from ptr_array_insert()
and ptr_array_add(). The callers now handle the error:

- the array lookup cache (plist.c) is dropped instead of silently going
  out of sync with the node list; lookups then fall back to walking
  the children, as they do before the cache exists
- bplist parsing (used_indexes) and serialization (objects) return
  PLIST_ERR_NO_MEM; ignoring the error in parse_bin_node_at_index()
  would otherwise loop forever since the array never grows

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>[github-actions] Updated build workflow</title>
<updated>2026-05-22T22:52:53+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-05-22T22:52:53+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/commit/?id=32428abacb909988e8e960a8845a6430b17b6a60'/>
<id>32428abacb909988e8e960a8845a6430b17b6a60</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Print debug error message when encoutering invalid PLIST_DATE values</title>
<updated>2026-05-22T18:41:23+00:00</updated>
<author>
<name>Nikias Bassen</name>
</author>
<published>2026-05-22T18:41:23+00:00</published>
<link rel='alternate' type='text/html' href='https://cgit.sukimashita.com/libplist.git/commit/?id=bd851a87ec93db2516455e982f121389a86fc0f7'/>
<id>bd851a87ec93db2516455e982f121389a86fc0f7</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
