[8.8.0] Fix Zip64 archive central directory extraction in ZipReader (https://github.com/bazelbuild/bazel/pull/30685) (#30764) ### Description Fixes #30681. In commit b12c06a2d54684cdf9a83d9ecc634850a7858db6 (#30530), `ZipReader.readCentralDirectory()` was modified to compute the central directory start as `actualCenStart = actualCenEnd - zipData.getCentralDirectorySize()`, replacing the parsed `zipData.getCentralDirectoryOffset()`. This broke reading standard Zip64 archives where 32-bit EOCD fields do not overflow (as the 76-byte Zip64 EOCD and locator sit between the central directory and the 32-bit EOCD, shifting the computed offset 76 bytes into the central directory) or when `centralDirectorySize` is `0xFFFFFFFF`. This change: 1. Restores `ZipReader`'s standard central directory parsing to use `zipData.getCentralDirectoryOffset()`. 2. Populates `centralDirectorySize` in `Zip64EndOfCentralDirectory.read()`. 3. Restricts the unadjusted SFX central directory start computation strictly to `AdjustSfx`. 4. Adds a unit test in `ZipReaderTest` covering Zip64 archives with valid 32-bit EOCD offsets. Closes #30685. PiperOrigin-RevId: 966082613 Change-Id: I4c9583901610aeed4ad4bfce75915b32eb6b2c86 Commit https://github.com/bazelbuild/bazel/commit/3dd0a0577005b741b83020ba669e8f9276969af3 Co-authored-by: Yun Peng <pcloudy@google.com> Co-authored-by: Ian (Hee) Cha <heec@google.com>
{Fast, Correct} - Choose two
Build and test software of any size, quickly and reliably.
Speed up your builds and tests: Bazel rebuilds only what is necessary. With advanced local and distributed caching, optimized dependency analysis and parallel execution, you get fast and incremental builds.
One tool, multiple languages: Build and test Java, C++, Android, iOS, Go, and a wide variety of other language platforms. Bazel runs on Windows, macOS, and Linux.
Scalable: Bazel helps you scale your organization, codebase, and continuous integration solution. It handles codebases of any size, in multiple repositories or a huge monorepo.
Extensible to your needs: Easily add support for new languages and platforms with Bazel's familiar extension language. Share and re-use language rules written by the growing Bazel community.
Follow our tutorials:
To report a security issue, please email security@bazel.build with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue. Our vulnerability management team will respond within 3 working days of your email. If the issue is confirmed as a vulnerability, we will open a Security Advisory. This project follows a 90 day disclosure timeline.
See CONTRIBUTING.md