--- NEWS | 5 ++--- zic.8 | 14 ++++++++++---- 2 files changed, 12 insertions(+), 7 deletions(-)
diff --git a/NEWS b/NEWS index 63af4098..d4f2d4cc 100644 --- a/NEWS +++ b/NEWS @@ -8,9 +8,8 @@ Unreleased, experimental changes Changes to code - zic now rejects Link targets that are absolute or contain ‘.’ or - ‘..’ components. Previously, crafted input could cause zic to - link to a file outside its output directory. + zic now rejects Link targets that would have invalid names. + (Thanks to Darren Carreras.) Release 2026c - 2026-07-08 10:23:58 -0700 diff --git a/zic.8 b/zic.8 index 3e32e85c..233c2eaf 100644 --- a/zic.8 +++ b/zic.8 @@ -586,6 +586,7 @@ The name of the timezone. This is the name used in creating the time conversion information file for the timezone. It should not contain a file name component +that is empty or is .q ".\&" or .q ".." ; @@ -737,8 +738,16 @@ A link line has the form .ta \w'Link\0\0'u +\w'Europe/Istanbul\0\0'u Link TARGET LINK-NAME .sp +.fi +where +.B TARGET +and +.B LINK-NAME +both have the same syntax as a zone line's +.BR NAME . For example: .sp +.nf .ti +2 Link Europe/Istanbul Asia/Istanbul .sp @@ -752,10 +761,7 @@ field in some zone line or as the field in some link line. The .B LINK-NAME -field is used as an alternative name for that zone; -it has the same syntax as a zone line's -.B NAME -field. +field is an alternative name for that zone. Links can chain together, although the behavior is unspecified if a chain of one or more links does not terminate in a Zone name. A link line can appear before the line that defines the link target. -- 2.53.0
