From d9a7d1f93790fdacd9ec34c1bde8c8eb8c737ba2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=BC=98=E9=9B=85=E3=81=AE=E5=92=B8=E9=B1=BC?= <3129538298@qq.com> Date: Wed, 26 Aug 2026 16:32:23 +0800 Subject: [PATCH 1/8] chore: claim-branch write probe --- .optimize-aa74 | 1 + 1 file changed, 1 insertion(+) create mode 100644 .optimize-aa74 diff --git a/.optimize-aa74 b/.optimize-aa74 new file mode 100644 index 0000000..9766475 --- /dev/null +++ b/.optimize-aa74 @@ -0,0 +1 @@ +ok From b3e9fb00c3df8fe711329fb4d857235bfdaff434 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=BC=98=E9=9B=85=E3=81=AE=E5=92=B8=E9=B1=BC?= <3129538298@qq.com> Date: Wed, 26 Aug 2026 16:32:38 +0800 Subject: [PATCH 2/8] chore: remove write-probe file --- .optimize-aa74 | 1 - 1 file changed, 1 deletion(-) delete mode 100644 .optimize-aa74 diff --git a/.optimize-aa74 b/.optimize-aa74 deleted file mode 100644 index 9766475..0000000 --- a/.optimize-aa74 +++ /dev/null @@ -1 +0,0 @@ -ok From bcb69b59bc5447608d315b95da18afa0c6f5788c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=BC=98=E9=9B=85=E3=81=AE=E5=92=B8=E9=B1=BC?= <3129538298@qq.com> Date: Wed, 26 Aug 2026 16:33:09 +0800 Subject: [PATCH 3/8] chore: bump package version to 0.4.1 --- src/luanma/__init__.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/luanma/__init__.py b/src/luanma/__init__.py index c96b4e4..0e8f557 100644 --- a/src/luanma/__init__.py +++ b/src/luanma/__init__.py @@ -16,7 +16,7 @@ preview_zip, ) -__version__ = "0.4.0" +__version__ = "0.4.1" __all__ = [ "ArchiveError", From 9ed6c4fcb911bc1ef8f427b5062fa692372f403f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=BC=98=E9=9B=85=E3=81=AE=E5=92=B8=E9=B1=BC?= <3129538298@qq.com> Date: Wed, 26 Aug 2026 16:33:59 +0800 Subject: [PATCH 4/8] test: compileall sources and tests in pytest --- tests/test_compileall.py | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 tests/test_compileall.py diff --git a/tests/test_compileall.py b/tests/test_compileall.py new file mode 100644 index 0000000..5c06269 --- /dev/null +++ b/tests/test_compileall.py @@ -0,0 +1,12 @@ +"""CI already runs pytest; this keeps a syntax check without editing workflows.""" +from __future__ import annotations + +import compileall +from pathlib import Path + +ROOT = Path(__file__).resolve().parents[1] + + +def test_sources_and_tests_compile() -> None: + assert compileall.compile_dir(str(ROOT / "src"), quiet=1, force=True) + assert compileall.compile_dir(str(ROOT / "tests"), quiet=1, force=True) From 85086af50233be6d57ba6ed1c7edf926caced0c6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=BC=98=E9=9B=85=E3=81=AE=E5=92=B8=E9=B1=BC?= <3129538298@qq.com> Date: Wed, 26 Aug 2026 16:34:14 +0800 Subject: [PATCH 5/8] chore: set package version 0.4.1 --- pyproject.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pyproject.toml b/pyproject.toml index 9d877c8..8554890 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta" [project] name = "luanma" -version = "0.4.0" +version = "0.4.1" description = "Fix mojibake filenames in zip archives and extracted folders: auto-detect GBK/Big5/Shift-JIS/EUC-KR, preview, safely extract, rewrite to UTF-8, or rename on disk | 压缩包与目录乱码文件名自动检测、修复与安全解压工具" readme = "README.md" requires-python = ">=3.9" From 6cad29bb006f39b2fe437ec3ecc69012ecd43908 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=BC=98=E9=9B=85=E3=81=AE=E5=92=B8=E9=B1=BC?= <3129538298@qq.com> Date: Wed, 26 Aug 2026 16:34:29 +0800 Subject: [PATCH 6/8] test: lock py.typed and Windows drive-letter sanitizing --- tests/test_sanitize.py | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/tests/test_sanitize.py b/tests/test_sanitize.py index 890799a..d8a8482 100644 --- a/tests/test_sanitize.py +++ b/tests/test_sanitize.py @@ -46,3 +46,19 @@ def test_junk_macosx(): def test_junk_normal_files_pass(): assert not is_junk(["dir", "报告.docx"]) assert not is_junk(["DS_Store提醒.txt"]) + + +def test_windows_drive_letter_cannot_escape(): + parts, changed = safe_components(r"C:\Windows\system32\evil.dll") + assert changed + assert parts[0] != "C:" + assert all(":" not in part for part in parts) + assert parts[-1] == "evil.dll" + + +def test_py_typed_marker_is_shipped(): + from pathlib import Path + + import luanma + + assert (Path(luanma.__file__).resolve().parent / "py.typed").is_file() From 0f233cb3e1593d5a3b97c68bf2469d3aa836d8ba Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=BC=98=E9=9B=85=E3=81=AE=E5=92=B8=E9=B1=BC?= <3129538298@qq.com> Date: Wed, 26 Aug 2026 16:38:00 +0800 Subject: [PATCH 7/8] docs: record compileall and drive-letter sanitize tests --- CHANGELOG.md | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index d853229..44865ae 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,10 @@ # Changelog +## 0.4.1 - 2026-08-26 + +- 测试锁定 `py.typed` 仍随包装分发,并增加 `compileall` 语法检查 +- 增加 Windows 盘符路径清洗测试,避免 `C:\...` 被当成可逃逸根路径 + ## 0.4.0 - 2026-08-13 - **二次乱码修复**:乱码文件被重新打包成"正常"压缩包(文件名带 @@ -34,7 +39,7 @@ - 修复:目录条目不再因带加密标志而误报"需要密码" - 修复:`--fix` 时目录条目强制以 STORED 方式写入;逐条目注释 (entry comment)现予保留 -- CLI:`--help` 增加中文示例;glob 支持 `**` 递归;检测置信度阈值 +- CLI:`--help` 增加中文示例;glob 支持 `**` 递归;检测置信度阀值 微调(混合 ASCII 的中文名不再轻易降级);支持 `python -m luanma` 调用 - 测试增至 78 个 @@ -47,7 +52,7 @@ - 通配符自我展开:PowerShell/cmd 不展开 `*.zip`,现在 CLI 自己处理 - 修复:压缩包内"文件"与"同名目录"冲突时不再抛异常,记录为条目级错误 - 修复:`--fix` 重名条目的 ` (2)` 后缀处理规范化(正确保留扩展名) -- 检测:GBK 升级为 GB18030(超集,覆盖生僻字与 4 字节序列), +- 检测:GBK 升级为 GB18030(超集,覆盖生僵字与 4 字节序列), 识别 CJK 扩展 A 区字符 - CLI:`-d`/`-o` 参数校验;部分条目失败时退出码为 1(全部成功 0, 无法打开 2) From c84752b6d60e8c22d236e6d94d1c156a63e62368 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E4=BC=98=E9=9B=85=E3=81=AE=E5=92=B8=E9=B1=BC?= <3129538298@qq.com> Date: Wed, 26 Aug 2026 16:38:54 +0800 Subject: [PATCH 8/8] docs: restore changelog wording and keep 0.4.1 notes --- CHANGELOG.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 44865ae..76efb4c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -39,7 +39,7 @@ - 修复:目录条目不再因带加密标志而误报"需要密码" - 修复:`--fix` 时目录条目强制以 STORED 方式写入;逐条目注释 (entry comment)现予保留 -- CLI:`--help` 增加中文示例;glob 支持 `**` 递归;检测置信度阀值 +- CLI:`--help` 增加中文示例;glob 支持 `**` 递归;检测置信度阈值 微调(混合 ASCII 的中文名不再轻易降级);支持 `python -m luanma` 调用 - 测试增至 78 个 @@ -52,7 +52,7 @@ - 通配符自我展开:PowerShell/cmd 不展开 `*.zip`,现在 CLI 自己处理 - 修复:压缩包内"文件"与"同名目录"冲突时不再抛异常,记录为条目级错误 - 修复:`--fix` 重名条目的 ` (2)` 后缀处理规范化(正确保留扩展名) -- 检测:GBK 升级为 GB18030(超集,覆盖生僵字与 4 字节序列), +- 检测:GBK 升级为 GB18030(超集,覆盖生僻字与 4 字节序列), 识别 CJK 扩展 A 区字符 - CLI:`-d`/`-o` 参数校验;部分条目失败时退出码为 1(全部成功 0, 无法打开 2)