0.3.0 - 2026-08-20
Release Notes
Added
-
slipcase repack, andslpc::Repackbehind it. Replaces a container's
metadata, its payload, or both, and copies every other member through as
stored bytes. This is the operation the specification requires when a
container is rewritten, and it is the one unpacking and packing again cannot
do: that route discards every member the tool does not recognize. Writes back
over the container it was given unless-onames somewhere else, resolving
symbolic links and keeping the container's permissions. -
-names standard output wherever a file is written, alongside its long
standing meaning of standard input wherever one is read.slipcase info c.slpc | your-editor | slipcase repack --meta - c.slpc -o out.slpcis the shape this
is for. Writing a container to a terminal is refused rather than done. -
A conformance corpus runner,
corpus/, which is not published and not
part ofcargo test. It checks both the verdict the library reaches and the
exit code the tool returns against every case in the corpus from
excelano/slipcase, and it is a step inRELEASING.mdrather than a test,
because it needs that repository checked out and a Python interpreter to
generate the cases.
Changed
-
rewrite_metadataandrewrite_metadata_bytesnow requireWrite + Seek
of their writer, where they requiredWritealone. This is the breaking
change in this release, and a caller passing a writer that cannot seek will
no longer compile.A member copied through a rewrite already knows its compressed size, and a
writer that cannot seek has nowhere to record it but a data descriptor after
the data — which is a promise to a reader walking forward that a length is
coming. Repacking never had a pipe for a source, since a ZIP's central
directory is at the end of the file, so requiring the same of the destination
costs a caller nothing they were not already paying.Packing is unaffected and keeps its
Write-only destination: a payload
arriving from a pipe genuinely has no size to write down, and a container can
still be packed from a pipe straight into a socket.
Fixed
-
Rewritten containers no longer claim a data descriptor they do not have.
zip8.6 sets general purpose bit 3 on a member copied raw into a stream
writer and then writes no descriptor, so the local header recorded a length of
zero and nothing supplied the real one. Readers that walk the central
directory were unaffected, which is why this survived undetected;
Info-ZIP walks forward and reportedinvalid zip file with overlapped components (possible zip bomb), exiting 12. Present inrewrite_metadata
since 0.1.0, where no shipped verb reached it. -
Files the tool writes now carry the permissions a new file gets. Writing
through a temporary file and renaming it into place carried the temporary
file's private mode onto the destination, so under an 0022 umaskslipcase packproduced a container at 0600 where an ordinary file would be 0644, and
slipcase unpackwrote a payload nobody but its author could read. Wrong
since 0.1.0.
Install slipcase 0.3.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/excelano/slpc-rust/releases/download/v0.3.0/slipcase-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/excelano/slpc-rust/releases/download/v0.3.0/slipcase-installer.ps1 | iex"Install prebuilt binaries via Homebrew
brew install excelano/tap/slipcaseDownload slipcase 0.3.0
| File | Platform | Checksum |
|---|---|---|
| slipcase-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| slipcase-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| slipcase-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| slipcase-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| slipcase-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |