mirror of https://github.com/icsharpcode/ILSpy.git
Branch:
fix/lambda-parameter-syntax
christophwille/closedhierarchies
christophwille/membench
compound-assignment-operators
fix/1982-params-attribute-args
fix/2040-invalid-xml-characters
fix/2093-navigateto-reference-assembly
fix/2362-xalz-references
fix/2372-address-taken-by
fix/3282-indexer-optional-arguments
fix/3568-record-member-order
fix/4059-deconstruct-out-slots
fix/lambda-parameter-syntax
fix/scroll-children-on-expand
gh-pages
ldmembertoken
master
natural-type-lambdas-methods
null-coalescing-assignment
release/10.1
release/6.2
release/7.1
release/7.2
release/8.1
substring-optimizations
tests/829-async-method-builder-override
tests/829-collection-expressions
tests/829-compound-assignment-operators
tests/829-coverage-audit
tests/829-expression-tree-named-optional-args
tests/829-expression-variables-in-initializers
tests/829-extended-property-patterns
tests/829-extension-members
tests/829-extension-operators
tests/829-file-local-types
tests/829-improved-definite-assignment
tests/829-improved-overload-candidates
tests/829-inline-arrays
tests/829-interpolated-string-improvements
tests/829-lambda-param-modifiers
tests/829-list-patterns
tests/829-lock-object
tests/829-mixed-deconstruction
tests/829-null-coalescing-assignment
tests/829-null-conditional-assignment
tests/829-object-initializer-indexer
tests/829-overload-resolution-priority
tests/829-params-collections
tests/829-pattern-matching-improvements
tests/829-primary-constructors
tests/829-ref-unsafe-in-iterators-async
tests/829-sealed-record-tostring
tests/829-target-typed-conditional
tests/829-tuple-comparison
win-a11y-textsize
1.0-Beta
1.0-M1
1.0-M2
1.0-M3
1.0.0
2.0.0
2.1
2.2
2.3
2.3.1
3.0-Preview1
3.0-Preview2
3.0.2
v10.0
v10.0-preview1
v10.0-preview2
v10.0-preview3
v10.0.1
v10.1
v10.1.1
v11.0
v11.0-preview1
v11.0-rc
v2.3.2
v2.4
v3.0
v3.0-beta1
v3.0-beta2
v3.0-beta2a
v3.0-beta3
v3.0-beta4
v3.0.1
v3.1-beta1
v3.1-final
v3.1-rc
v3.2-beta
v3.2-rc
v3.2.0
v4.0
v4.0-alpha1
v4.0-beta1
v4.0-beta2
v4.0-beta3
v4.0-rc1
v4.0-rc2
v4.0.1
v5.0
v5.0-preview1
v5.0-preview2
v5.0-preview3
v5.0-preview4
v5.0-rc1
v5.0.1
v5.0.2
v6.0
v6.0-preview1
v6.0-preview2
v6.0-preview3
v6.0-preview4
v6.0-rc1
v6.1
v6.2
v6.2-preview1
v6.2-preview2
v6.2.1
v7.0
v7.0-preview1
v7.0-preview2
v7.0-preview3
v7.0-rc1
v7.0-rc2
v7.1
v7.2
v7.2-preview1
v7.2-preview2
v7.2-preview3
v7.2-preview4
v7.2-rc
v7.2.1
v8.0
v8.0-preview1
v8.0-preview2
v8.0-preview3
v8.0-preview4
v8.0-rc1
v8.1
v8.1.1
v8.2
v9.0
v9.0-preview1
v9.0-preview2
v9.0-preview3
v9.0-rc
v9.1
${ item.name }
${ noResults }
2 Commits (fix/lambda-parameter-syntax)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
c74990d987 |
Share the bundle signature with the tests instead of copying it
Two test fixtures carried their own copy of the 32-byte signature, which would silently drift from the real one. The signature is now an internal member of SingleFileBundle and ILSpy.Tests gets internals access to the decompiler assembly, matching what ILSpyX already grants it. Assisted-by: Claude:claude-fable-5:Claude Code |
3 weeks ago |
|
|
4980c011b8 |
Never size bundle entry decompression from the manifest's declared size
A single-file bundle manifest is attacker-controlled. Opening a compressed entry pre-allocated a MemoryStream of the declared decompressed size through an unchecked long-to-int cast, then inflated the whole deflate stream before comparing lengths. A few-byte payload declaring ~2 GB thus forced a ~2 GB allocation up front, sizes at or above 2 GB wrapped to a negative capacity, and a decompression bomb was expanded in full before the mismatch was noticed (CWE-789, CWE-197). Grow the buffer only with bytes the deflate stream actually produces and stop reading one byte past the declared size, which already proves the entry corrupt. Reject declared sizes that cannot fit a single in-memory buffer as invalid bundle data. Entry offsets need no extra check: the UnmanagedMemoryStream over the mapping already validates them against the view length. Assisted-by: Claude:claude-fable-5:Claude Code |
3 weeks ago |