ZacohZhen成员
3月7日

相关的Issue

https://gitcode.com/openharmony/third_party_freetype/issues/183

原因(目的、解决的问题等)

CVE-2026-23865漏洞修复

描述(做了什么,变更了什么)

增加越界保护

测试用例(新增、改动、可能影响的功能)

tt_var_load_item_variation_store 函数存在整数溢出漏洞,可能导致在解析 OpenType 可变字体中的 HVAR/VVAR/MVAR 表时发生越界读取操作

likedislike
Pull Request已成功合入, 合并人@openharmony_ci
(感谢 ZacohZhen 的贡献)
ZZacohZhen成员
3月7日 关联了issue:CVE-2026-23865
openharmony_ci
openharmony_ci成员
3月7日 评论:

OpenHarmony-6.0-Release所有代码仓合入受控, 请联系分支负责人@shermanzhong: sherman.zhong@huawei.com, @RayShih: shirui721@huawei.com, @ggrong09: gaojinrong@huawei.com, @GGRong99: gaojinrong@huawei.com任一人评审并评论approve

likedislike
openharmony_ciopenharmony_ci成员
3月7日 添加了label:分支负责人未批准合入
openharmony_ciopenharmony_ci成员
3月7日 添加了label:waiting_on_author
openharmony_ci
openharmony_ci成员
3月7日 评论:

感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接


Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.

likedislike
openharmony_ciopenharmony_ci成员
3月7日 添加了label:dco检查成功
ZacohZhen成员
3月7日 评论:

start build

likedislike
openharmony_ci
openharmony_ci成员
3月7日 评论:

首次触发
门禁构建开始,包含静态检查、代码编译和测试【dayu200编译, hispark_taurus_LiteOS编译, hispark_taurus_LiteOS测试, hispark_taurus_Linux编译, dayu200_xts_acts编译, dayu200测试, dayu200_xts编译, ohos-sdk编译】,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/69ab76b064650f998b3be6cd/runlist

likedislike
openharmony_ciopenharmony_ci成员
3月7日 添加了label:编译成功
openharmony_ciopenharmony_ci成员
3月7日 添加了label:静态检查成功
openharmony_ciopenharmony_ci成员
3月7日 添加了label:冒烟测试成功
openharmony_ciopenharmony_ci成员
3月7日 通过测试
openharmony_ci
openharmony_ci成员
3月7日 评论:

代码门禁通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/69ab76b064650f998b3be6cd/runlist

静态检查:

# check type result report
1 codeCheck pass >>>

编译测试:
# Device build result test result package
1 hispark_taurus_LiteOS success success >>>
2 hispark_taurus_Linux success NA >>>
3 ohos-sdk success NA >>>
4 dayu200 success success >>>
5 dayu200_xts success NA >>>
6 dayu200_xts_acts success NA >>>

likedislike
openharmony_ciopenharmony_ci成员
3月7日 删除了label:waiting_on_author
openharmony_ciopenharmony_ci成员
3月7日 添加了label:waiting_for_review
openharmony_ci
openharmony_ci成员
3月7日 评论:

您好,Committer @pssea ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。


Hello, Committer @pssea . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.

likedislike
LizhiqiLizhiqi成员
3月7日 通过审查
zhongxiaoming
zhongxiaoming成员
3月7日 评论:

approve

likedislike
openharmony_ciopenharmony_ci成员
3月7日 删除了label:分支负责人未批准合入
openharmony_ciopenharmony_ci成员
3月7日 合入了pull request,合并节点 SHA:b848dfe114acab5cb610072daf9a940658dbd0dc
openharmony_ciopenharmony_ci成员
3月7日 删除了label:waiting_for_review
openharmony_ciopenharmony_ci成员
3月7日 添加了label:merged