Re: [PATCH RFC 7/9] lib/lz4: switch the decompressor to the vendored sources

From: Michal Wilczynski

Date: Sat Oct 03 2026 - 19:38:57 EST




On 9/28/26 06:16, Sergey Senozhatsky wrote:
> On (26/09/25 13:27), Michal Wilczynski wrote:
> [..]
>> -static FORCE_INLINE int LZ4_decompress_generic(
> [..]
>> - /* Necessarily EOF when !partialDecoding.
>> - * When partialDecoding, it is EOF if we've either
>> - * filled the output buffer or
>> - * can't proceed with reading an offset for following match.
>> - */
>> - if (!partialDecoding || (cpy == oend) || (ip >= (iend - 2)))
>> - break;
>
> Worth noting, these lines are downstream commit eafc0a02391b
> (lz4: fix LZ4_decompress_safe_partial read out of bound).
>
> Is this intended or are we "loosing" some of the downstream fixes?
>

Yeah it's intended, eafc0a02391b was itself a backport of upstream
c5d6f8a8be39 which is in v1.9.3 and later; its own commit message links
it. The same check is at lib/lz4/upstream/lz4.c in this series.

And upstream's version also clamps a literal run that would read past
the end of the input, which the backport didn't take.

Best regards,
--
Michal Wilczynski <m.wilczynski@xxxxxxxxxxx>