Would a patch that adds a support to disable the bomb detection be accepted? While maintaining the unzip package in Fedora/RHEL, there were quite a few false positives. While there are were some further patches dealing with those, an ability to disable the bomb detection would be quite useful in those cases. If a such patch would be acceptable, what would be a preferred way of doing this?
- By a command line option - since this repo deals just with the zipbombs, this could potentially lead to conflicts if the upstream decides to use the same option in some other way. There also doesn't seem to be many more unused single char options, and I am not sure what would be a good single char candidate.
- By an environment variable - something like UNZIP_DISABLE_ZIPBOMB_DETECTION={true,false}. Right now unzip doesn't use environment variables in this way, there also might be some portability issues outside of unix (although I don't think this is too important aspect these days).
Would a patch that adds a support to disable the bomb detection be accepted? While maintaining the unzip package in Fedora/RHEL, there were quite a few false positives. While there are were some further patches dealing with those, an ability to disable the bomb detection would be quite useful in those cases. If a such patch would be acceptable, what would be a preferred way of doing this?