Files
ppsspp/android
Henrik Rydgård f3d7d8bc0c Fix Zip Slip in zip extraction and add unit test
A crafted zip with a parent-directory ("..") entry name could escape the
destination directory during extraction, writing arbitrary files on the
host (e.g. into startup/autostart folders). ExtractZipContents built the
output path by concatenating the raw zip entry name onto the destination
with no traversal check.

Changes:
- Add HasParentDirComponent() utility in Core/Util/PathUtil and use it in
  GameManager::ExtractZipContents to reject entries with a ".." component.
  Guard both the directory-creation and file-writing passes.
- Expose ExtractZipContents as public for testing.
- Add unittest/TestZipSlip which crafts a zip with a "../evil.txt" entry
  and verifies it is not written outside the destination directory.
2026-07-31 20:35:12 +02:00
..
2026-07-30 18:50:32 +02:00
2025-11-14 10:10:44 +01:00
2025-11-14 10:10:44 +01:00
2026-06-15 09:17:13 +02:00

================================================================

NOTE: These are legacy instructions for building using ndk-build.

We mostly only use this on CI because it's faster than gradle.
There might also be some holdouts around still using eclipse.

================================================================

First, build the C++ static library:

> cd android
> ./ab.sh
Or
> ./ab.cmd

as appropriate.

Start Eclipse, import the android directory as an existing project
You need to also load the "native" project into your eclipse workspace
Build and run. 

If you modify the C++ code, you need to rebuild the static library, of
course. To get Eclipse to understand that you have in fact changed something
if you haven't also changed any Java code, just add a space character to 
PPSSPPActivity.java, or right click the project and choose Refresh, and then
relaunch the app on the device.

A real Android device is strongly recommended for testing. Don't trust
the emulator.