Correction — please use these attachments instead of the earlier 0004–0006.

The previously attached patches contained leftover merge-conflict markers in the gifalloc hunks — a commit-tooling error on my side, caught during follow-up work. The corrected series (6 patches, all final-state, no fixup-on-fixup) supersedes them:

0004 (attached): gifalloc memory-safety hardening as one commit with all four fixes and full evidence: (1) stale ImageCount after GifFreeSavedImages() → OOB write in GifMakeSavedImage(); (2) self-aliased copy → heap-use-after-free (realloc invalidates the source); (3) NULL-raster copy, dangling RasterBits, speculative extension count; (4) ExtensionBlockCount never restored by the deep copy — copies lose GCEs (frame timing/disposal/transparency) and leak the copied Bytes (this also retires my earlier OOM-aliasing worry: the maintainer's null-out already protects the source). The count tracks completed blocks per iteration, so every exit frees exactly what was built; the failure path was additionally exercised with -Wl,--wrap=malloc under valgrind (0 errors, source intact — glibc-specific, run locally).
0005 (attached): DGifOpen/EGifOpen reject NULL I/O callbacks, fail closed.
0006 (attached): tests/api_test.c + makefile wiring — 23 checks covering the series (GCE fixture included so the extension preservation check genuinely bites), build rule tracks library sources and honors $(CFLAGS), tests clean target, binary gitignored.
Plus two fixes filed as their own tickets with their own checks: quantize *ColorMapSize bounds (new ticket), encoder color-map representability → CodeMask overread (new ticket).
Verified: full suite 74 tests, 0 failures; api_test 23/23 under ASan+UBSan; all patches marker-free; each fix's before/after sanitizer evidence in the original ticket text above. Apologies for the churn — the fixes themselves are unchanged in substance; the packaging is what's corrected.

 

Last edit: Mohmamed Mohamed Elnady 2026-09-30