<feed xmlns='http://www.w3.org/2005/Atom'>
<title>engrampa/tests, branch master</title>
<subtitle>Engrampa archive manager for MATE</subtitle>
<link rel='alternate' type='text/html' href='http://git.mate-desktop.org/engrampa/'/>
<entry>
<title>tests: add regression test for CVE-2023-52138</title>
<updated>2026-08-08T11:56:43+00:00</updated>
<author>
<name>gaoyukun</name>
<email>gaoyukun@kylinos.cn</email>
</author>
<published>2026-08-06T04:46:32+00:00</published>
<link rel='alternate' type='text/html' href='http://git.mate-desktop.org/engrampa/commit/?id=f8b49310898c7c011d4be14335e0c59558b478d5'/>
<id>f8b49310898c7c011d4be14335e0c59558b478d5</id>
<content type='text'>
Add a test script that verifies the cpio extraction path traversal
fix (--no-absolute-filenames) in both fr-command-cpio.c and
fr-command-rpm.c:

- static check: both extraction commands must carry the flag
- dynamic check: crafted cpio payloads with absolute-path and ../
  entries must stay inside the extraction directory
- rpm2cpio | cpio pipeline extracts a normal RPM without regression

Run the test as part of the CI build (autotools check stage).

Co-Authored-By: AtomCode (deepseek-v4-flash) &lt;noreply@atomgit.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Add a test script that verifies the cpio extraction path traversal
fix (--no-absolute-filenames) in both fr-command-cpio.c and
fr-command-rpm.c:

- static check: both extraction commands must carry the flag
- dynamic check: crafted cpio payloads with absolute-path and ../
  entries must stay inside the extraction directory
- rpm2cpio | cpio pipeline extracts a normal RPM without regression

Run the test as part of the CI build (autotools check stage).

Co-Authored-By: AtomCode (deepseek-v4-flash) &lt;noreply@atomgit.com&gt;
</pre>
</div>
</content>
</entry>
</feed>
