Skip to content

v0.2.7

Choose a tag to compare

@dkulyk dkulyk released this 08 Sep 23:31
· 7 commits to main since this release
b1b0a94

Fixed

  • Close the owned file handle immediately when parsing fails. Directory entries form a reference cycle back to the parser, so the handle previously stayed open until cyclic garbage collection ran. Resources passed to fromResource() are still left open.
  • Reject a DirectoryEntry that belongs to a different parser. Passing a foreign entry to openStream() or getStreamContents() previously applied its sector metadata to the receiving file and silently returned bytes from the wrong container.
  • Reject directory entry names containing the reserved characters /, \, : and !. Such names fabricated a hierarchy that no directory entry described.

Compatibility

The reserved-character check rejects malformed files that the reader previously accepted. Real containers are unaffected: the control-character prefixes used by OLE special streams such as \x01CompObj and \x05SummaryInformation remain valid.

Internal

The sector chain cache and the CFBF directory tree builder were extracted into internal classes. No public API or serialized format change.

Verification

  • 103 tests and 8,309 assertions
  • PHP 8.1-8.5, lowest dependencies, and Windows

Full changelog: v0.2.6...v0.2.7