This document lists the known incompatibilities between the lrzsz 0.12 and 0.13 series. I) Wire Format * lsz no longer sends the "rz\r" auto-download trigger. "Modern" practice is, and has been for 30 years, to look for a ZRQINIT frame instead: `* * ^X B 0 0`. lsz has been the only implementation to still send the old trigger, which was documented as optional even in the original ZMODEM specification (40 years old). * lrz does not support remote command execution anymore. No incompatibilites exist in the documented and mandatory X/Y/ZMODEM file transfer features. II) Environment 0.12 compiled cleanly with ANSI C (C 89) and C libraries of the 90s. 0.12 needed patches for compilation in newer environments. 0.13 targets C99 and newer, and POSIX.1-2008 and newer. 0.13 will not compile in most older environments. I feel a bit sorry for giving up the compatibility with compilers and systems of the 80s, but it is how it is. It was either that, or worsening the #ifdef mess instead of cleaning it up. Also i had no way to test compilation of old machines, anyway. III) Usage * the support for the PUBDIR, a public upload directory, is gone from both programs. This feature has to be --enabled with he configure script. If you really need that you can achieve something very similar with a symlink. * the lrz pipe execution feature was removed. When lrz was installed as `lrzCMD`, it would have tried to execute CMD with the (attacker controlled) filename as argument, without escaping it, allowing arbitrary command exexution (think of '--version ; rm -rf /'). I seem to remember that `lrztar` might have been used by some people. * the lrz remote command execution feature (receiving and executing remote commands) was removed. This was a feature of the original public domain zmodem, and by default disabled in lrzsz since sometime in the 90s, by hiding it behind the -C or --allow-commands options. * the -C or --allow-remote-commands option was disabled, and its usage causes an error. The sending side is kept for compatibility with old ZMODEM implementations (OMEN zmodem and older lrz) that still execute received commands. This will be removed in a future release. * lrz in very restricted mode now disallows invisible leading directories, too (`dir/.subdir/filename` was allowed before). * the TCP mode was removed, because it neither used authentication nor encryption. To the best of my knowledge this feature was only used in two BBS systems which have been dead for 20 years. If you need something like that, try: (cd /tmp ; netcat -l -p 5120 -c lrz -v ) netcat localhost 5120 -c 'lsz /etc/passwd' (when using the netcat `-u` option (UDP), do yourself a favor and use the lsz `--sync-transfer` option - overwise corruption can happen if a ZMODEM data subframe is lost) * the -U/--unrestrict option has been removed from both lrz and lsz. Rationale: It should be impossible to turn off security-relevant options. Whoever can add -U to a command line can also forgo activating the restricted mode. Removing this option removed a trap. The only legitimate use, keeping partially received files in case of a transfer error, lives on as lrz's new --keep-incomplete option. * the -S / --timesync options and the timesync protocol support was removed. No other zmodem suite still in use implemented it, and the function to set the receivers time needed root rights - which, given the security record of this package, lrz should not have. Besides: 1 second granularity, now support for timezones. * the `-d / --dot-to-slash` option (DOS 8.3 filename transformation) was removed (it collided with the now extended pathname checking). Besides: even windows can deal with multiple dots. * lrz now reports the reason why a transfer was aborted at verbosity level 1, instead of 3. This matches what lsz did for a long time. * syslog support is now always compiled in. Earlier releases had configure options to deselect it. As before you can syslogging off by `--syslog=no` (or `=off`). * In the '-s +N' case the programs stopped after less than N seconds (due to integer calculation). It now stops a second later. Rationale: it broke some new tests in the test suite. * the -s / --stop-at option only worked if verbose mode was active. It now works as intended in any case. * the german translation was removed, because it was seriously out of date. Translations are welcome, just my own ill-maintained one wasn't.