[8.8.0] Fix Zip64 archive central directory extraction in ZipReader (https://github.com/bazelbuild/bazel/pull/30685) (#30764)

### Description

Fixes #30681.

In commit b12c06a2d54684cdf9a83d9ecc634850a7858db6 (#30530),
`ZipReader.readCentralDirectory()` was modified to compute the central
directory start as `actualCenStart = actualCenEnd -
zipData.getCentralDirectorySize()`, replacing the parsed
`zipData.getCentralDirectoryOffset()`.

This broke reading standard Zip64 archives where 32-bit EOCD fields do
not overflow (as the 76-byte Zip64 EOCD and locator sit between the
central directory and the 32-bit EOCD, shifting the computed offset 76
bytes into the central directory) or when `centralDirectorySize` is
`0xFFFFFFFF`.

This change:
1. Restores `ZipReader`'s standard central directory parsing to use
`zipData.getCentralDirectoryOffset()`.
2. Populates `centralDirectorySize` in
`Zip64EndOfCentralDirectory.read()`.
3. Restricts the unadjusted SFX central directory start computation
strictly to `AdjustSfx`.
4. Adds a unit test in `ZipReaderTest` covering Zip64 archives with
valid 32-bit EOCD offsets.

Closes #30685.

PiperOrigin-RevId: 966082613
Change-Id: I4c9583901610aeed4ad4bfce75915b32eb6b2c86

Commit
https://github.com/bazelbuild/bazel/commit/3dd0a0577005b741b83020ba669e8f9276969af3

Co-authored-by: Yun Peng <pcloudy@google.com>
Co-authored-by: Ian (Hee) Cha <heec@google.com>
4 files changed
tree: eb1cd4dd0bfc10767475102d0f78dda7937c4071
  1. .bazelci/
  2. .github/
  3. examples/
  4. scripts/
  5. site/
  6. src/
  7. third_party/
  8. tools/
  9. .bazelrc
  10. .bazelversion
  11. .gitattributes
  12. .gitignore
  13. AUTHORS
  14. bazel_downloader.cfg
  15. BUILD
  16. CHANGELOG.md
  17. CODE_OF_CONDUCT.md
  18. CODEOWNERS
  19. combine_distfiles.py
  20. combine_distfiles_to_tar.sh
  21. compile.sh
  22. CONTRIBUTING.md
  23. CONTRIBUTORS
  24. distdir.bzl
  25. extensions.bzl
  26. LICENSE
  27. maven_install.json
  28. MODULE.bazel
  29. MODULE.bazel.lock
  30. README.md
  31. repositories.bzl
  32. requirements.txt
  33. SECURITY.md
  34. workspace_deps.bzl
README.md

Bazel

{Fast, Correct} - Choose two

Build and test software of any size, quickly and reliably.

  • Speed up your builds and tests: Bazel rebuilds only what is necessary. With advanced local and distributed caching, optimized dependency analysis and parallel execution, you get fast and incremental builds.

  • One tool, multiple languages: Build and test Java, C++, Android, iOS, Go, and a wide variety of other language platforms. Bazel runs on Windows, macOS, and Linux.

  • Scalable: Bazel helps you scale your organization, codebase, and continuous integration solution. It handles codebases of any size, in multiple repositories or a huge monorepo.

  • Extensible to your needs: Easily add support for new languages and platforms with Bazel's familiar extension language. Share and re-use language rules written by the growing Bazel community.

Getting Started

Documentation

Reporting a Vulnerability

To report a security issue, please email security@bazel.build with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue. Our vulnerability management team will respond within 3 working days of your email. If the issue is confirmed as a vulnerability, we will open a Security Advisory. This project follows a 90 day disclosure timeline.

Contributing to Bazel

See CONTRIBUTING.md

Build status