archive_read_support_format_cab.c 83 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227
  1. /*-
  2. * Copyright (c) 2010-2012 Michihiro NAKAJIMA
  3. * All rights reserved.
  4. *
  5. * Redistribution and use in source and binary forms, with or without
  6. * modification, are permitted provided that the following conditions
  7. * are met:
  8. * 1. Redistributions of source code must retain the above copyright
  9. * notice, this list of conditions and the following disclaimer.
  10. * 2. Redistributions in binary form must reproduce the above copyright
  11. * notice, this list of conditions and the following disclaimer in the
  12. * documentation and/or other materials provided with the distribution.
  13. *
  14. * THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) ``AS IS'' AND ANY EXPRESS OR
  15. * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
  16. * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
  17. * IN NO EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY DIRECT, INDIRECT,
  18. * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  19. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
  20. * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
  21. * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
  22. * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
  23. * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  24. */
  25. #include "archive_platform.h"
  26. #ifdef HAVE_ERRNO_H
  27. #include <errno.h>
  28. #endif
  29. #ifdef HAVE_LIMITS_H
  30. #include <limits.h>
  31. #endif
  32. #ifdef HAVE_STDLIB_H
  33. #include <stdlib.h>
  34. #endif
  35. #ifdef HAVE_STRING_H
  36. #include <string.h>
  37. #endif
  38. #ifdef HAVE_ZLIB_H
  39. #include <cm_zlib.h>
  40. #endif
  41. #include "archive.h"
  42. #include "archive_entry.h"
  43. #include "archive_entry_locale.h"
  44. #include "archive_private.h"
  45. #include "archive_read_private.h"
  46. #include "archive_endian.h"
  47. struct lzx_dec {
  48. /* Decoding status. */
  49. int state;
  50. /*
  51. * Window to see last decoded data, from 32KBi to 2MBi.
  52. */
  53. int w_size;
  54. int w_mask;
  55. /* Window buffer, which is a loop buffer. */
  56. unsigned char *w_buff;
  57. /* The insert position to the window. */
  58. int w_pos;
  59. /* The position where we can copy decoded code from the window. */
  60. int copy_pos;
  61. /* The length how many bytes we can copy decoded code from
  62. * the window. */
  63. int copy_len;
  64. /* Translation reversal for x86 processor CALL byte sequence(E8).
  65. * This is used for LZX only. */
  66. uint32_t translation_size;
  67. char translation;
  68. char block_type;
  69. #define VERBATIM_BLOCK 1
  70. #define ALIGNED_OFFSET_BLOCK 2
  71. #define UNCOMPRESSED_BLOCK 3
  72. size_t block_size;
  73. size_t block_bytes_avail;
  74. /* Repeated offset. */
  75. int r0, r1, r2;
  76. unsigned char rbytes[4];
  77. int rbytes_avail;
  78. int length_header;
  79. int position_slot;
  80. int offset_bits;
  81. struct lzx_pos_tbl {
  82. int base;
  83. int footer_bits;
  84. } *pos_tbl;
  85. /*
  86. * Bit stream reader.
  87. */
  88. struct lzx_br {
  89. #define CACHE_TYPE uint64_t
  90. #define CACHE_BITS (8 * sizeof(CACHE_TYPE))
  91. /* Cache buffer. */
  92. CACHE_TYPE cache_buffer;
  93. /* Indicates how many bits avail in cache_buffer. */
  94. int cache_avail;
  95. unsigned char odd;
  96. char have_odd;
  97. } br;
  98. /*
  99. * Huffman coding.
  100. */
  101. struct huffman {
  102. int len_size;
  103. int freq[17];
  104. unsigned char *bitlen;
  105. /*
  106. * Use a index table. It's faster than searching a huffman
  107. * coding tree, which is a binary tree. But a use of a large
  108. * index table causes L1 cache read miss many times.
  109. */
  110. int max_bits;
  111. int tbl_bits;
  112. int tree_used;
  113. /* Direct access table. */
  114. uint16_t *tbl;
  115. } at, lt, mt, pt;
  116. int loop;
  117. int error;
  118. };
  119. static const int slots[] = {
  120. 30, 32, 34, 36, 38, 42, 50, 66, 98, 162, 290
  121. };
  122. #define SLOT_BASE 15
  123. #define SLOT_MAX 21/*->25*/
  124. struct lzx_stream {
  125. const unsigned char *next_in;
  126. int64_t avail_in;
  127. int64_t total_in;
  128. unsigned char *next_out;
  129. int64_t avail_out;
  130. int64_t total_out;
  131. struct lzx_dec *ds;
  132. };
  133. /*
  134. * Cabinet file definitions.
  135. */
  136. /* CFHEADER offset */
  137. #define CFHEADER_signature 0
  138. #define CFHEADER_cbCabinet 8
  139. #define CFHEADER_coffFiles 16
  140. #define CFHEADER_versionMinor 24
  141. #define CFHEADER_versionMajor 25
  142. #define CFHEADER_cFolders 26
  143. #define CFHEADER_cFiles 28
  144. #define CFHEADER_flags 30
  145. #define CFHEADER_setID 32
  146. #define CFHEADER_iCabinet 34
  147. #define CFHEADER_cbCFHeader 36
  148. #define CFHEADER_cbCFFolder 38
  149. #define CFHEADER_cbCFData 39
  150. /* CFFOLDER offset */
  151. #define CFFOLDER_coffCabStart 0
  152. #define CFFOLDER_cCFData 4
  153. #define CFFOLDER_typeCompress 6
  154. #define CFFOLDER_abReserve 8
  155. /* CFFILE offset */
  156. #define CFFILE_cbFile 0
  157. #define CFFILE_uoffFolderStart 4
  158. #define CFFILE_iFolder 8
  159. #define CFFILE_date_time 10
  160. #define CFFILE_attribs 14
  161. /* CFDATA offset */
  162. #define CFDATA_csum 0
  163. #define CFDATA_cbData 4
  164. #define CFDATA_cbUncomp 6
  165. static const char * const compression_name[] = {
  166. "NONE",
  167. "MSZIP",
  168. "Quantum",
  169. "LZX",
  170. };
  171. struct cfdata {
  172. /* Sum value of this CFDATA. */
  173. uint32_t sum;
  174. uint16_t compressed_size;
  175. uint16_t compressed_bytes_remaining;
  176. uint16_t uncompressed_size;
  177. uint16_t uncompressed_bytes_remaining;
  178. /* To know how many bytes we have decompressed. */
  179. uint16_t uncompressed_avail;
  180. /* Offset from the beginning of compressed data of this CFDATA */
  181. uint16_t read_offset;
  182. int64_t unconsumed;
  183. /* To keep memory image of this CFDATA to compute the sum. */
  184. size_t memimage_size;
  185. unsigned char *memimage;
  186. /* Result of calculation of sum. */
  187. uint32_t sum_calculated;
  188. unsigned char sum_extra[4];
  189. int sum_extra_avail;
  190. const void *sum_ptr;
  191. };
  192. struct cffolder {
  193. uint32_t cfdata_offset_in_cab;
  194. uint16_t cfdata_count;
  195. uint16_t comptype;
  196. #define COMPTYPE_NONE 0x0000
  197. #define COMPTYPE_MSZIP 0x0001
  198. #define COMPTYPE_QUANTUM 0x0002
  199. #define COMPTYPE_LZX 0x0003
  200. uint16_t compdata;
  201. const char *compname;
  202. /* At the time reading CFDATA */
  203. struct cfdata cfdata;
  204. int cfdata_index;
  205. /* Flags to mark progress of decompression. */
  206. char decompress_init;
  207. };
  208. struct cffile {
  209. uint32_t uncompressed_size;
  210. uint32_t offset;
  211. time_t mtime;
  212. uint16_t folder;
  213. #define iFoldCONTINUED_FROM_PREV 0xFFFD
  214. #define iFoldCONTINUED_TO_NEXT 0xFFFE
  215. #define iFoldCONTINUED_PREV_AND_NEXT 0xFFFF
  216. unsigned char attr;
  217. #define ATTR_RDONLY 0x01
  218. #define ATTR_NAME_IS_UTF 0x80
  219. struct archive_string pathname;
  220. };
  221. struct cfheader {
  222. /* Total bytes of all file size in a Cabinet. */
  223. uint32_t total_bytes;
  224. uint32_t files_offset;
  225. uint16_t folder_count;
  226. uint16_t file_count;
  227. uint16_t flags;
  228. #define PREV_CABINET 0x0001
  229. #define NEXT_CABINET 0x0002
  230. #define RESERVE_PRESENT 0x0004
  231. uint16_t setid;
  232. uint16_t cabinet;
  233. /* Version number. */
  234. unsigned char major;
  235. unsigned char minor;
  236. unsigned char cffolder;
  237. unsigned char cfdata;
  238. /* All folders in a cabinet. */
  239. struct cffolder *folder_array;
  240. /* All files in a cabinet. */
  241. struct cffile *file_array;
  242. int file_index;
  243. };
  244. struct cab {
  245. /* entry_bytes_remaining is the number of bytes we expect. */
  246. int64_t entry_offset;
  247. int64_t entry_bytes_remaining;
  248. int64_t entry_unconsumed;
  249. int64_t entry_compressed_bytes_read;
  250. int64_t entry_uncompressed_bytes_read;
  251. struct cffolder *entry_cffolder;
  252. struct cffile *entry_cffile;
  253. struct cfdata *entry_cfdata;
  254. /* Offset from beginning of a cabinet file. */
  255. int64_t cab_offset;
  256. struct cfheader cfheader;
  257. struct archive_wstring ws;
  258. /* Flag to mark progress that an archive was read their first header.*/
  259. char found_header;
  260. char end_of_archive;
  261. char end_of_entry;
  262. char end_of_entry_cleanup;
  263. char read_data_invoked;
  264. int64_t bytes_skipped;
  265. unsigned char *uncompressed_buffer;
  266. size_t uncompressed_buffer_size;
  267. int init_default_conversion;
  268. struct archive_string_conv *sconv;
  269. struct archive_string_conv *sconv_default;
  270. struct archive_string_conv *sconv_utf8;
  271. char format_name[64];
  272. #ifdef HAVE_ZLIB_H
  273. z_stream stream;
  274. char stream_valid;
  275. #endif
  276. struct lzx_stream xstrm;
  277. };
  278. static int archive_read_format_cab_bid(struct archive_read *, int);
  279. static int archive_read_format_cab_options(struct archive_read *,
  280. const char *, const char *);
  281. static int archive_read_format_cab_read_header(struct archive_read *,
  282. struct archive_entry *);
  283. static int archive_read_format_cab_read_data(struct archive_read *,
  284. const void **, size_t *, int64_t *);
  285. static int archive_read_format_cab_read_data_skip(struct archive_read *);
  286. static int archive_read_format_cab_cleanup(struct archive_read *);
  287. static int cab_skip_sfx(struct archive_read *);
  288. static time_t cab_dos_time(const unsigned char *);
  289. static int cab_read_data(struct archive_read *, const void **,
  290. size_t *, int64_t *);
  291. static int cab_read_header(struct archive_read *);
  292. static uint32_t cab_checksum_cfdata_4(const void *, size_t bytes, uint32_t);
  293. static uint32_t cab_checksum_cfdata(const void *, size_t bytes, uint32_t);
  294. static void cab_checksum_update(struct archive_read *, size_t);
  295. static int cab_checksum_finish(struct archive_read *);
  296. static int cab_next_cfdata(struct archive_read *);
  297. static const void *cab_read_ahead_cfdata(struct archive_read *, ssize_t *);
  298. static const void *cab_read_ahead_cfdata_none(struct archive_read *, ssize_t *);
  299. static const void *cab_read_ahead_cfdata_deflate(struct archive_read *,
  300. ssize_t *);
  301. static const void *cab_read_ahead_cfdata_lzx(struct archive_read *,
  302. ssize_t *);
  303. static int64_t cab_consume_cfdata(struct archive_read *, int64_t);
  304. static int64_t cab_minimum_consume_cfdata(struct archive_read *, int64_t);
  305. static int lzx_decode_init(struct lzx_stream *, int);
  306. static int lzx_read_blocks(struct lzx_stream *, int);
  307. static int lzx_decode_blocks(struct lzx_stream *, int);
  308. static void lzx_decode_free(struct lzx_stream *);
  309. static void lzx_translation(struct lzx_stream *, void *, size_t, uint32_t);
  310. static void lzx_cleanup_bitstream(struct lzx_stream *);
  311. static int lzx_decode(struct lzx_stream *, int);
  312. static int lzx_read_pre_tree(struct lzx_stream *);
  313. static int lzx_read_bitlen(struct lzx_stream *, struct huffman *, int);
  314. static int lzx_huffman_init(struct huffman *, size_t, int);
  315. static void lzx_huffman_free(struct huffman *);
  316. static int lzx_make_huffman_table(struct huffman *);
  317. static inline int lzx_decode_huffman(struct huffman *, unsigned);
  318. int
  319. archive_read_support_format_cab(struct archive *_a)
  320. {
  321. struct archive_read *a = (struct archive_read *)_a;
  322. struct cab *cab;
  323. int r;
  324. archive_check_magic(_a, ARCHIVE_READ_MAGIC,
  325. ARCHIVE_STATE_NEW, "archive_read_support_format_cab");
  326. cab = (struct cab *)calloc(1, sizeof(*cab));
  327. if (cab == NULL) {
  328. archive_set_error(&a->archive, ENOMEM,
  329. "Can't allocate CAB data");
  330. return (ARCHIVE_FATAL);
  331. }
  332. archive_string_init(&cab->ws);
  333. archive_wstring_ensure(&cab->ws, 256);
  334. r = __archive_read_register_format(a,
  335. cab,
  336. "cab",
  337. archive_read_format_cab_bid,
  338. archive_read_format_cab_options,
  339. archive_read_format_cab_read_header,
  340. archive_read_format_cab_read_data,
  341. archive_read_format_cab_read_data_skip,
  342. NULL,
  343. archive_read_format_cab_cleanup,
  344. NULL,
  345. NULL);
  346. if (r != ARCHIVE_OK)
  347. free(cab);
  348. return (ARCHIVE_OK);
  349. }
  350. static int
  351. find_cab_magic(const char *p)
  352. {
  353. switch (p[4]) {
  354. case 0:
  355. /*
  356. * Note: Self-Extraction program has 'MSCF' string in their
  357. * program. If we were finding 'MSCF' string only, we got
  358. * wrong place for Cabinet header, thus, we have to check
  359. * following four bytes which are reserved and must be set
  360. * to zero.
  361. */
  362. if (memcmp(p, "MSCF\0\0\0\0", 8) == 0)
  363. return 0;
  364. return 5;
  365. case 'F': return 1;
  366. case 'C': return 2;
  367. case 'S': return 3;
  368. case 'M': return 4;
  369. default: return 5;
  370. }
  371. }
  372. static int
  373. archive_read_format_cab_bid(struct archive_read *a, int best_bid)
  374. {
  375. const char *p;
  376. ssize_t bytes_avail, offset, window;
  377. /* If there's already a better bid than we can ever
  378. make, don't bother testing. */
  379. if (best_bid > 64)
  380. return (-1);
  381. if ((p = __archive_read_ahead(a, 8, NULL)) == NULL)
  382. return (-1);
  383. if (memcmp(p, "MSCF\0\0\0\0", 8) == 0)
  384. return (64);
  385. /*
  386. * Attempt to handle self-extracting archives
  387. * by noting a PE header and searching forward
  388. * up to 128k for a 'MSCF' marker.
  389. */
  390. if (p[0] == 'M' && p[1] == 'Z') {
  391. offset = 0;
  392. window = 4096;
  393. while (offset < (1024 * 128)) {
  394. const char *h = __archive_read_ahead(a, offset + window,
  395. &bytes_avail);
  396. if (h == NULL) {
  397. /* Remaining bytes are less than window. */
  398. window >>= 1;
  399. if (window < 128)
  400. return (0);
  401. continue;
  402. }
  403. p = h + offset;
  404. while (p + 8 < h + bytes_avail) {
  405. int next;
  406. if ((next = find_cab_magic(p)) == 0)
  407. return (64);
  408. p += next;
  409. }
  410. offset = p - h;
  411. }
  412. }
  413. return (0);
  414. }
  415. static int
  416. archive_read_format_cab_options(struct archive_read *a,
  417. const char *key, const char *val)
  418. {
  419. struct cab *cab;
  420. int ret = ARCHIVE_FAILED;
  421. cab = (struct cab *)(a->format->data);
  422. if (strcmp(key, "hdrcharset") == 0) {
  423. if (val == NULL || val[0] == 0)
  424. archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
  425. "cab: hdrcharset option needs a character-set name");
  426. else {
  427. cab->sconv = archive_string_conversion_from_charset(
  428. &a->archive, val, 0);
  429. if (cab->sconv != NULL)
  430. ret = ARCHIVE_OK;
  431. else
  432. ret = ARCHIVE_FATAL;
  433. }
  434. return (ret);
  435. }
  436. /* Note: The "warn" return is just to inform the options
  437. * supervisor that we didn't handle it. It will generate
  438. * a suitable error if no one used this option. */
  439. return (ARCHIVE_WARN);
  440. }
  441. static int
  442. cab_skip_sfx(struct archive_read *a)
  443. {
  444. const char *p, *q;
  445. size_t skip;
  446. ssize_t bytes, window;
  447. window = 4096;
  448. for (;;) {
  449. const char *h = __archive_read_ahead(a, window, &bytes);
  450. if (h == NULL) {
  451. /* Remaining size are less than window. */
  452. window >>= 1;
  453. if (window < 128) {
  454. archive_set_error(&a->archive,
  455. ARCHIVE_ERRNO_FILE_FORMAT,
  456. "Couldn't find out CAB header");
  457. return (ARCHIVE_FATAL);
  458. }
  459. continue;
  460. }
  461. p = h;
  462. q = p + bytes;
  463. /*
  464. * Scan ahead until we find something that looks
  465. * like the cab header.
  466. */
  467. while (p + 8 < q) {
  468. int next;
  469. if ((next = find_cab_magic(p)) == 0) {
  470. skip = p - h;
  471. __archive_read_consume(a, skip);
  472. return (ARCHIVE_OK);
  473. }
  474. p += next;
  475. }
  476. skip = p - h;
  477. __archive_read_consume(a, skip);
  478. }
  479. }
  480. static int
  481. truncated_error(struct archive_read *a)
  482. {
  483. archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT,
  484. "Truncated CAB header");
  485. return (ARCHIVE_FATAL);
  486. }
  487. static ssize_t
  488. cab_strnlen(const unsigned char *p, size_t maxlen)
  489. {
  490. size_t i;
  491. for (i = 0; i <= maxlen; i++) {
  492. if (p[i] == 0)
  493. break;
  494. }
  495. if (i > maxlen)
  496. return (-1);/* invalid */
  497. return ((ssize_t)i);
  498. }
  499. /* Read bytes as much as remaining. */
  500. static const void *
  501. cab_read_ahead_remaining(struct archive_read *a, size_t min, ssize_t *avail)
  502. {
  503. const void *p;
  504. while (min > 0) {
  505. p = __archive_read_ahead(a, min, avail);
  506. if (p != NULL)
  507. return (p);
  508. min--;
  509. }
  510. return (NULL);
  511. }
  512. /* Convert a path separator '\' -> '/' */
  513. static int
  514. cab_convert_path_separator_1(struct archive_string *fn, unsigned char attr)
  515. {
  516. size_t i;
  517. int mb;
  518. /* Easy check if we have '\' in multi-byte string. */
  519. mb = 0;
  520. for (i = 0; i < archive_strlen(fn); i++) {
  521. if (fn->s[i] == '\\') {
  522. if (mb) {
  523. /* This may be second byte of multi-byte
  524. * character. */
  525. break;
  526. }
  527. fn->s[i] = '/';
  528. mb = 0;
  529. } else if ((fn->s[i] & 0x80) && !(attr & ATTR_NAME_IS_UTF))
  530. mb = 1;
  531. else
  532. mb = 0;
  533. }
  534. if (i == archive_strlen(fn))
  535. return (0);
  536. return (-1);
  537. }
  538. /*
  539. * Replace a character '\' with '/' in wide character.
  540. */
  541. static void
  542. cab_convert_path_separator_2(struct cab *cab, struct archive_entry *entry)
  543. {
  544. const wchar_t *wp;
  545. size_t i;
  546. /* If a conversion to wide character failed, force the replacement. */
  547. if ((wp = archive_entry_pathname_w(entry)) != NULL) {
  548. archive_wstrcpy(&(cab->ws), wp);
  549. for (i = 0; i < archive_strlen(&(cab->ws)); i++) {
  550. if (cab->ws.s[i] == L'\\')
  551. cab->ws.s[i] = L'/';
  552. }
  553. archive_entry_copy_pathname_w(entry, cab->ws.s);
  554. }
  555. }
  556. /*
  557. * Read CFHEADER, CFFOLDER and CFFILE.
  558. */
  559. static int
  560. cab_read_header(struct archive_read *a)
  561. {
  562. const unsigned char *p;
  563. struct cab *cab;
  564. struct cfheader *hd;
  565. size_t bytes, used;
  566. ssize_t len;
  567. int64_t skip;
  568. int err, i;
  569. int cur_folder, prev_folder;
  570. uint32_t offset32;
  571. a->archive.archive_format = ARCHIVE_FORMAT_CAB;
  572. if (a->archive.archive_format_name == NULL)
  573. a->archive.archive_format_name = "CAB";
  574. if ((p = __archive_read_ahead(a, 42, NULL)) == NULL)
  575. return (truncated_error(a));
  576. cab = (struct cab *)(a->format->data);
  577. if (cab->found_header == 0 &&
  578. p[0] == 'M' && p[1] == 'Z') {
  579. /* This is an executable? Must be self-extracting... */
  580. err = cab_skip_sfx(a);
  581. if (err < ARCHIVE_WARN)
  582. return (err);
  583. /* Re-read header after processing the SFX. */
  584. if ((p = __archive_read_ahead(a, 42, NULL)) == NULL)
  585. return (truncated_error(a));
  586. }
  587. cab->cab_offset = 0;
  588. /*
  589. * Read CFHEADER.
  590. */
  591. hd = &cab->cfheader;
  592. if (p[CFHEADER_signature+0] != 'M' || p[CFHEADER_signature+1] != 'S' ||
  593. p[CFHEADER_signature+2] != 'C' || p[CFHEADER_signature+3] != 'F') {
  594. archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT,
  595. "Couldn't find out CAB header");
  596. return (ARCHIVE_FATAL);
  597. }
  598. hd->total_bytes = archive_le32dec(p + CFHEADER_cbCabinet);
  599. hd->files_offset = archive_le32dec(p + CFHEADER_coffFiles);
  600. hd->minor = p[CFHEADER_versionMinor];
  601. hd->major = p[CFHEADER_versionMajor];
  602. hd->folder_count = archive_le16dec(p + CFHEADER_cFolders);
  603. if (hd->folder_count == 0)
  604. goto invalid;
  605. hd->file_count = archive_le16dec(p + CFHEADER_cFiles);
  606. if (hd->file_count == 0)
  607. goto invalid;
  608. hd->flags = archive_le16dec(p + CFHEADER_flags);
  609. hd->setid = archive_le16dec(p + CFHEADER_setID);
  610. hd->cabinet = archive_le16dec(p + CFHEADER_iCabinet);
  611. used = CFHEADER_iCabinet + 2;
  612. if (hd->flags & RESERVE_PRESENT) {
  613. uint16_t cfheader;
  614. cfheader = archive_le16dec(p + CFHEADER_cbCFHeader);
  615. if (cfheader > 60000U)
  616. goto invalid;
  617. hd->cffolder = p[CFHEADER_cbCFFolder];
  618. hd->cfdata = p[CFHEADER_cbCFData];
  619. used += 4;/* cbCFHeader, cbCFFolder and cbCFData */
  620. used += cfheader;/* abReserve */
  621. } else
  622. hd->cffolder = 0;/* Avoid compiling warning. */
  623. if (hd->flags & PREV_CABINET) {
  624. /* How many bytes are used for szCabinetPrev. */
  625. if ((p = __archive_read_ahead(a, used+256, NULL)) == NULL)
  626. return (truncated_error(a));
  627. if ((len = cab_strnlen(p + used, 255)) <= 0)
  628. goto invalid;
  629. used += len + 1;
  630. /* How many bytes are used for szDiskPrev. */
  631. if ((p = __archive_read_ahead(a, used+256, NULL)) == NULL)
  632. return (truncated_error(a));
  633. if ((len = cab_strnlen(p + used, 255)) <= 0)
  634. goto invalid;
  635. used += len + 1;
  636. }
  637. if (hd->flags & NEXT_CABINET) {
  638. /* How many bytes are used for szCabinetNext. */
  639. if ((p = __archive_read_ahead(a, used+256, NULL)) == NULL)
  640. return (truncated_error(a));
  641. if ((len = cab_strnlen(p + used, 255)) <= 0)
  642. goto invalid;
  643. used += len + 1;
  644. /* How many bytes are used for szDiskNext. */
  645. if ((p = __archive_read_ahead(a, used+256, NULL)) == NULL)
  646. return (truncated_error(a));
  647. if ((len = cab_strnlen(p + used, 255)) <= 0)
  648. goto invalid;
  649. used += len + 1;
  650. }
  651. __archive_read_consume(a, used);
  652. cab->cab_offset += used;
  653. used = 0;
  654. /*
  655. * Read CFFOLDER.
  656. */
  657. hd->folder_array = (struct cffolder *)calloc(
  658. hd->folder_count, sizeof(struct cffolder));
  659. if (hd->folder_array == NULL)
  660. goto nomem;
  661. bytes = 8;
  662. if (hd->flags & RESERVE_PRESENT)
  663. bytes += hd->cffolder;
  664. bytes *= hd->folder_count;
  665. if ((p = __archive_read_ahead(a, bytes, NULL)) == NULL)
  666. return (truncated_error(a));
  667. offset32 = 0;
  668. for (i = 0; i < hd->folder_count; i++) {
  669. struct cffolder *folder = &(hd->folder_array[i]);
  670. folder->cfdata_offset_in_cab =
  671. archive_le32dec(p + CFFOLDER_coffCabStart);
  672. folder->cfdata_count = archive_le16dec(p+CFFOLDER_cCFData);
  673. folder->comptype =
  674. archive_le16dec(p+CFFOLDER_typeCompress) & 0x0F;
  675. folder->compdata =
  676. archive_le16dec(p+CFFOLDER_typeCompress) >> 8;
  677. /* Get a compression name. */
  678. if (folder->comptype <
  679. sizeof(compression_name) / sizeof(compression_name[0]))
  680. folder->compname = compression_name[folder->comptype];
  681. else
  682. folder->compname = "UNKNOWN";
  683. p += 8;
  684. used += 8;
  685. if (hd->flags & RESERVE_PRESENT) {
  686. p += hd->cffolder;/* abReserve */
  687. used += hd->cffolder;
  688. }
  689. /*
  690. * Sanity check if each data is acceptable.
  691. */
  692. if (offset32 >= folder->cfdata_offset_in_cab)
  693. goto invalid;
  694. offset32 = folder->cfdata_offset_in_cab;
  695. /* Set a request to initialize zlib for the CFDATA of
  696. * this folder. */
  697. folder->decompress_init = 0;
  698. }
  699. __archive_read_consume(a, used);
  700. cab->cab_offset += used;
  701. /*
  702. * Read CFFILE.
  703. */
  704. /* Seek read pointer to the offset of CFFILE if needed. */
  705. skip = (int64_t)hd->files_offset - cab->cab_offset;
  706. if (skip < 0) {
  707. archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
  708. "Invalid offset of CFFILE %jd < %jd",
  709. (intmax_t)hd->files_offset, (intmax_t)cab->cab_offset);
  710. return (ARCHIVE_FATAL);
  711. }
  712. if (skip) {
  713. __archive_read_consume(a, skip);
  714. cab->cab_offset += skip;
  715. }
  716. /* Allocate memory for CFDATA */
  717. hd->file_array = (struct cffile *)calloc(
  718. hd->file_count, sizeof(struct cffile));
  719. if (hd->file_array == NULL)
  720. goto nomem;
  721. prev_folder = -1;
  722. for (i = 0; i < hd->file_count; i++) {
  723. struct cffile *file = &(hd->file_array[i]);
  724. ssize_t avail;
  725. if ((p = __archive_read_ahead(a, 16, NULL)) == NULL)
  726. return (truncated_error(a));
  727. file->uncompressed_size = archive_le32dec(p + CFFILE_cbFile);
  728. file->offset = archive_le32dec(p + CFFILE_uoffFolderStart);
  729. file->folder = archive_le16dec(p + CFFILE_iFolder);
  730. file->mtime = cab_dos_time(p + CFFILE_date_time);
  731. file->attr = (uint8_t)archive_le16dec(p + CFFILE_attribs);
  732. __archive_read_consume(a, 16);
  733. cab->cab_offset += 16;
  734. if ((p = cab_read_ahead_remaining(a, 256, &avail)) == NULL)
  735. return (truncated_error(a));
  736. if ((len = cab_strnlen(p, avail-1)) <= 0)
  737. goto invalid;
  738. /* Copy a pathname. */
  739. archive_string_init(&(file->pathname));
  740. archive_strncpy(&(file->pathname), p, len);
  741. __archive_read_consume(a, len + 1);
  742. cab->cab_offset += len + 1;
  743. /*
  744. * Sanity check if each data is acceptable.
  745. */
  746. if (file->uncompressed_size > 0x7FFF8000)
  747. goto invalid;/* Too large */
  748. if ((int64_t)file->offset + (int64_t)file->uncompressed_size
  749. > ARCHIVE_LITERAL_LL(0x7FFF8000))
  750. goto invalid;/* Too large */
  751. switch (file->folder) {
  752. case iFoldCONTINUED_TO_NEXT:
  753. /* This must be last file in a folder. */
  754. if (i != hd->file_count -1)
  755. goto invalid;
  756. cur_folder = hd->folder_count -1;
  757. break;
  758. case iFoldCONTINUED_PREV_AND_NEXT:
  759. /* This must be only one file in a folder. */
  760. if (hd->file_count != 1)
  761. goto invalid;
  762. /* FALL THROUGH */
  763. case iFoldCONTINUED_FROM_PREV:
  764. /* This must be first file in a folder. */
  765. if (i != 0)
  766. goto invalid;
  767. prev_folder = cur_folder = 0;
  768. offset32 = file->offset;
  769. break;
  770. default:
  771. if (file->folder >= hd->folder_count)
  772. goto invalid;
  773. cur_folder = file->folder;
  774. break;
  775. }
  776. /* Dot not back track. */
  777. if (cur_folder < prev_folder)
  778. goto invalid;
  779. if (cur_folder != prev_folder)
  780. offset32 = 0;
  781. prev_folder = cur_folder;
  782. /* Make sure there are not any blanks from last file
  783. * contents. */
  784. if (offset32 != file->offset)
  785. goto invalid;
  786. offset32 += file->uncompressed_size;
  787. /* CFDATA is available for file contents. */
  788. if (file->uncompressed_size > 0 &&
  789. hd->folder_array[cur_folder].cfdata_count == 0)
  790. goto invalid;
  791. }
  792. if (hd->cabinet != 0 || hd->flags & (PREV_CABINET | NEXT_CABINET)) {
  793. archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT,
  794. "Multivolume cabinet file is unsupported");
  795. return (ARCHIVE_WARN);
  796. }
  797. return (ARCHIVE_OK);
  798. invalid:
  799. archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT,
  800. "Invalid CAB header");
  801. return (ARCHIVE_FATAL);
  802. nomem:
  803. archive_set_error(&a->archive, ENOMEM,
  804. "Can't allocate memory for CAB data");
  805. return (ARCHIVE_FATAL);
  806. }
  807. static int
  808. archive_read_format_cab_read_header(struct archive_read *a,
  809. struct archive_entry *entry)
  810. {
  811. struct cab *cab;
  812. struct cfheader *hd;
  813. struct cffolder *prev_folder;
  814. struct cffile *file;
  815. struct archive_string_conv *sconv;
  816. int err = ARCHIVE_OK, r;
  817. cab = (struct cab *)(a->format->data);
  818. if (cab->found_header == 0) {
  819. err = cab_read_header(a);
  820. if (err < ARCHIVE_WARN)
  821. return (err);
  822. /* We've found the header. */
  823. cab->found_header = 1;
  824. }
  825. hd = &cab->cfheader;
  826. if (hd->file_index >= hd->file_count) {
  827. cab->end_of_archive = 1;
  828. return (ARCHIVE_EOF);
  829. }
  830. file = &hd->file_array[hd->file_index++];
  831. cab->end_of_entry = 0;
  832. cab->end_of_entry_cleanup = 0;
  833. cab->entry_compressed_bytes_read = 0;
  834. cab->entry_uncompressed_bytes_read = 0;
  835. cab->entry_unconsumed = 0;
  836. cab->entry_cffile = file;
  837. /*
  838. * Choose a proper folder.
  839. */
  840. prev_folder = cab->entry_cffolder;
  841. switch (file->folder) {
  842. case iFoldCONTINUED_FROM_PREV:
  843. case iFoldCONTINUED_PREV_AND_NEXT:
  844. cab->entry_cffolder = &hd->folder_array[0];
  845. break;
  846. case iFoldCONTINUED_TO_NEXT:
  847. cab->entry_cffolder = &hd->folder_array[hd->folder_count-1];
  848. break;
  849. default:
  850. cab->entry_cffolder = &hd->folder_array[file->folder];
  851. break;
  852. }
  853. /* If a cffolder of this file is changed, reset a cfdata to read
  854. * file contents from next cfdata. */
  855. if (prev_folder != cab->entry_cffolder)
  856. cab->entry_cfdata = NULL;
  857. /* If a pathname is UTF-8, prepare a string conversion object
  858. * for UTF-8 and use it. */
  859. if (file->attr & ATTR_NAME_IS_UTF) {
  860. if (cab->sconv_utf8 == NULL) {
  861. cab->sconv_utf8 =
  862. archive_string_conversion_from_charset(
  863. &(a->archive), "UTF-8", 1);
  864. if (cab->sconv_utf8 == NULL)
  865. return (ARCHIVE_FATAL);
  866. }
  867. sconv = cab->sconv_utf8;
  868. } else if (cab->sconv != NULL) {
  869. /* Choose the conversion specified by the option. */
  870. sconv = cab->sconv;
  871. } else {
  872. /* Choose the default conversion. */
  873. if (!cab->init_default_conversion) {
  874. cab->sconv_default =
  875. archive_string_default_conversion_for_read(
  876. &(a->archive));
  877. cab->init_default_conversion = 1;
  878. }
  879. sconv = cab->sconv_default;
  880. }
  881. /*
  882. * Set a default value and common data
  883. */
  884. r = cab_convert_path_separator_1(&(file->pathname), file->attr);
  885. if (archive_entry_copy_pathname_l(entry, file->pathname.s,
  886. archive_strlen(&(file->pathname)), sconv) != 0) {
  887. if (errno == ENOMEM) {
  888. archive_set_error(&a->archive, ENOMEM,
  889. "Can't allocate memory for Pathname");
  890. return (ARCHIVE_FATAL);
  891. }
  892. archive_set_error(&a->archive,
  893. ARCHIVE_ERRNO_FILE_FORMAT,
  894. "Pathname cannot be converted "
  895. "from %s to current locale.",
  896. archive_string_conversion_charset_name(sconv));
  897. err = ARCHIVE_WARN;
  898. }
  899. if (r < 0) {
  900. /* Convert a path separator '\' -> '/' */
  901. cab_convert_path_separator_2(cab, entry);
  902. }
  903. archive_entry_set_size(entry, file->uncompressed_size);
  904. if (file->attr & ATTR_RDONLY)
  905. archive_entry_set_mode(entry, AE_IFREG | 0555);
  906. else
  907. archive_entry_set_mode(entry, AE_IFREG | 0666);
  908. archive_entry_set_mtime(entry, file->mtime, 0);
  909. cab->entry_bytes_remaining = file->uncompressed_size;
  910. cab->entry_offset = 0;
  911. /* We don't need compress data. */
  912. if (file->uncompressed_size == 0)
  913. cab->end_of_entry_cleanup = cab->end_of_entry = 1;
  914. /* Set up a more descriptive format name. */
  915. sprintf(cab->format_name, "CAB %d.%d (%s)",
  916. hd->major, hd->minor, cab->entry_cffolder->compname);
  917. a->archive.archive_format_name = cab->format_name;
  918. return (err);
  919. }
  920. static int
  921. archive_read_format_cab_read_data(struct archive_read *a,
  922. const void **buff, size_t *size, int64_t *offset)
  923. {
  924. struct cab *cab = (struct cab *)(a->format->data);
  925. int r;
  926. switch (cab->entry_cffile->folder) {
  927. case iFoldCONTINUED_FROM_PREV:
  928. case iFoldCONTINUED_TO_NEXT:
  929. case iFoldCONTINUED_PREV_AND_NEXT:
  930. *buff = NULL;
  931. *size = 0;
  932. *offset = 0;
  933. archive_clear_error(&a->archive);
  934. archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT,
  935. "Cannot restore this file split in multivolume.");
  936. return (ARCHIVE_FAILED);
  937. default:
  938. break;
  939. }
  940. if (cab->read_data_invoked == 0) {
  941. if (cab->bytes_skipped) {
  942. if (cab->entry_cfdata == NULL) {
  943. r = cab_next_cfdata(a);
  944. if (r < 0)
  945. return (r);
  946. }
  947. if (cab_consume_cfdata(a, cab->bytes_skipped) < 0)
  948. return (ARCHIVE_FATAL);
  949. cab->bytes_skipped = 0;
  950. }
  951. cab->read_data_invoked = 1;
  952. }
  953. if (cab->entry_unconsumed) {
  954. /* Consume as much as the compressor actually used. */
  955. r = (int)cab_consume_cfdata(a, cab->entry_unconsumed);
  956. cab->entry_unconsumed = 0;
  957. if (r < 0)
  958. return (r);
  959. }
  960. if (cab->end_of_archive || cab->end_of_entry) {
  961. if (!cab->end_of_entry_cleanup) {
  962. /* End-of-entry cleanup done. */
  963. cab->end_of_entry_cleanup = 1;
  964. }
  965. *offset = cab->entry_offset;
  966. *size = 0;
  967. *buff = NULL;
  968. return (ARCHIVE_EOF);
  969. }
  970. return (cab_read_data(a, buff, size, offset));
  971. }
  972. static uint32_t
  973. cab_checksum_cfdata_4(const void *p, size_t bytes, uint32_t seed)
  974. {
  975. const unsigned char *b;
  976. unsigned u32num;
  977. uint32_t sum;
  978. u32num = (unsigned)bytes / 4;
  979. sum = seed;
  980. b = p;
  981. for (;u32num > 0; --u32num) {
  982. sum ^= archive_le32dec(b);
  983. b += 4;
  984. }
  985. return (sum);
  986. }
  987. static uint32_t
  988. cab_checksum_cfdata(const void *p, size_t bytes, uint32_t seed)
  989. {
  990. const unsigned char *b;
  991. uint32_t sum;
  992. uint32_t t;
  993. sum = cab_checksum_cfdata_4(p, bytes, seed);
  994. b = p;
  995. b += bytes & ~3;
  996. t = 0;
  997. switch (bytes & 3) {
  998. case 3:
  999. t |= ((uint32_t)(*b++)) << 16;
  1000. /* FALL THROUGH */
  1001. case 2:
  1002. t |= ((uint32_t)(*b++)) << 8;
  1003. /* FALL THROUGH */
  1004. case 1:
  1005. t |= *b;
  1006. /* FALL THROUGH */
  1007. default:
  1008. break;
  1009. }
  1010. sum ^= t;
  1011. return (sum);
  1012. }
  1013. static void
  1014. cab_checksum_update(struct archive_read *a, size_t bytes)
  1015. {
  1016. struct cab *cab = (struct cab *)(a->format->data);
  1017. struct cfdata *cfdata = cab->entry_cfdata;
  1018. const unsigned char *p;
  1019. size_t sumbytes;
  1020. if (cfdata->sum == 0 || cfdata->sum_ptr == NULL)
  1021. return;
  1022. /*
  1023. * Calculate the sum of this CFDATA.
  1024. * Make sure CFDATA must be calculated in four bytes.
  1025. */
  1026. p = cfdata->sum_ptr;
  1027. sumbytes = bytes;
  1028. if (cfdata->sum_extra_avail) {
  1029. while (cfdata->sum_extra_avail < 4 && sumbytes > 0) {
  1030. cfdata->sum_extra[
  1031. cfdata->sum_extra_avail++] = *p++;
  1032. sumbytes--;
  1033. }
  1034. if (cfdata->sum_extra_avail == 4) {
  1035. cfdata->sum_calculated = cab_checksum_cfdata_4(
  1036. cfdata->sum_extra, 4, cfdata->sum_calculated);
  1037. cfdata->sum_extra_avail = 0;
  1038. }
  1039. }
  1040. if (sumbytes) {
  1041. int odd = sumbytes & 3;
  1042. if (sumbytes - odd > 0)
  1043. cfdata->sum_calculated = cab_checksum_cfdata_4(
  1044. p, sumbytes - odd, cfdata->sum_calculated);
  1045. if (odd)
  1046. memcpy(cfdata->sum_extra, p + sumbytes - odd, odd);
  1047. cfdata->sum_extra_avail = odd;
  1048. }
  1049. cfdata->sum_ptr = NULL;
  1050. }
  1051. static int
  1052. cab_checksum_finish(struct archive_read *a)
  1053. {
  1054. struct cab *cab = (struct cab *)(a->format->data);
  1055. struct cfdata *cfdata = cab->entry_cfdata;
  1056. int l;
  1057. /* Do not need to compute a sum. */
  1058. if (cfdata->sum == 0)
  1059. return (ARCHIVE_OK);
  1060. /*
  1061. * Calculate the sum of remaining CFDATA.
  1062. */
  1063. if (cfdata->sum_extra_avail) {
  1064. cfdata->sum_calculated =
  1065. cab_checksum_cfdata(cfdata->sum_extra,
  1066. cfdata->sum_extra_avail, cfdata->sum_calculated);
  1067. cfdata->sum_extra_avail = 0;
  1068. }
  1069. l = 4;
  1070. if (cab->cfheader.flags & RESERVE_PRESENT)
  1071. l += cab->cfheader.cfdata;
  1072. cfdata->sum_calculated = cab_checksum_cfdata(
  1073. cfdata->memimage + CFDATA_cbData, l, cfdata->sum_calculated);
  1074. if (cfdata->sum_calculated != cfdata->sum) {
  1075. archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT,
  1076. "Checksum error CFDATA[%d] %x:%x in %d bytes",
  1077. cab->entry_cffolder->cfdata_index -1,
  1078. cfdata->sum, cfdata->sum_calculated,
  1079. cfdata->compressed_size);
  1080. return (ARCHIVE_FAILED);
  1081. }
  1082. return (ARCHIVE_OK);
  1083. }
  1084. /*
  1085. * Read CFDATA if needed.
  1086. */
  1087. static int
  1088. cab_next_cfdata(struct archive_read *a)
  1089. {
  1090. struct cab *cab = (struct cab *)(a->format->data);
  1091. struct cfdata *cfdata = cab->entry_cfdata;
  1092. /* There are remaining bytes in current CFDATA, use it first. */
  1093. if (cfdata != NULL && cfdata->uncompressed_bytes_remaining > 0)
  1094. return (ARCHIVE_OK);
  1095. if (cfdata == NULL) {
  1096. int64_t skip;
  1097. cab->entry_cffolder->cfdata_index = 0;
  1098. /* Seek read pointer to the offset of CFDATA if needed. */
  1099. skip = cab->entry_cffolder->cfdata_offset_in_cab
  1100. - cab->cab_offset;
  1101. if (skip < 0) {
  1102. int folder_index;
  1103. switch (cab->entry_cffile->folder) {
  1104. case iFoldCONTINUED_FROM_PREV:
  1105. case iFoldCONTINUED_PREV_AND_NEXT:
  1106. folder_index = 0;
  1107. break;
  1108. case iFoldCONTINUED_TO_NEXT:
  1109. folder_index = cab->cfheader.folder_count-1;
  1110. break;
  1111. default:
  1112. folder_index = cab->entry_cffile->folder;
  1113. break;
  1114. }
  1115. archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
  1116. "Invalid offset of CFDATA in folder(%d) %jd < %jd",
  1117. folder_index,
  1118. (intmax_t)cab->entry_cffolder->cfdata_offset_in_cab,
  1119. (intmax_t)cab->cab_offset);
  1120. return (ARCHIVE_FATAL);
  1121. }
  1122. if (skip > 0) {
  1123. if (__archive_read_consume(a, skip) < 0)
  1124. return (ARCHIVE_FATAL);
  1125. cab->cab_offset =
  1126. cab->entry_cffolder->cfdata_offset_in_cab;
  1127. }
  1128. }
  1129. /*
  1130. * Read a CFDATA.
  1131. */
  1132. if (cab->entry_cffolder->cfdata_index <
  1133. cab->entry_cffolder->cfdata_count) {
  1134. const unsigned char *p;
  1135. int l;
  1136. cfdata = &(cab->entry_cffolder->cfdata);
  1137. cab->entry_cffolder->cfdata_index++;
  1138. cab->entry_cfdata = cfdata;
  1139. cfdata->sum_calculated = 0;
  1140. cfdata->sum_extra_avail = 0;
  1141. cfdata->sum_ptr = NULL;
  1142. l = 8;
  1143. if (cab->cfheader.flags & RESERVE_PRESENT)
  1144. l += cab->cfheader.cfdata;
  1145. if ((p = __archive_read_ahead(a, l, NULL)) == NULL)
  1146. return (truncated_error(a));
  1147. cfdata->sum = archive_le32dec(p + CFDATA_csum);
  1148. cfdata->compressed_size = archive_le16dec(p + CFDATA_cbData);
  1149. cfdata->compressed_bytes_remaining = cfdata->compressed_size;
  1150. cfdata->uncompressed_size =
  1151. archive_le16dec(p + CFDATA_cbUncomp);
  1152. cfdata->uncompressed_bytes_remaining =
  1153. cfdata->uncompressed_size;
  1154. cfdata->uncompressed_avail = 0;
  1155. cfdata->read_offset = 0;
  1156. cfdata->unconsumed = 0;
  1157. /*
  1158. * Sanity check if data size is acceptable.
  1159. */
  1160. if (cfdata->compressed_size == 0 ||
  1161. cfdata->compressed_size > (0x8000+6144))
  1162. goto invalid;
  1163. if (cfdata->uncompressed_size > 0x8000)
  1164. goto invalid;
  1165. if (cfdata->uncompressed_size == 0) {
  1166. switch (cab->entry_cffile->folder) {
  1167. case iFoldCONTINUED_PREV_AND_NEXT:
  1168. case iFoldCONTINUED_TO_NEXT:
  1169. break;
  1170. case iFoldCONTINUED_FROM_PREV:
  1171. default:
  1172. goto invalid;
  1173. }
  1174. }
  1175. /* If CFDATA is not last in a folder, an uncompressed
  1176. * size must be 0x8000(32KBi) */
  1177. if ((cab->entry_cffolder->cfdata_index <
  1178. cab->entry_cffolder->cfdata_count) &&
  1179. cfdata->uncompressed_size != 0x8000)
  1180. goto invalid;
  1181. /* A compressed data size and an uncompressed data size must
  1182. * be the same in no compression mode. */
  1183. if (cab->entry_cffolder->comptype == COMPTYPE_NONE &&
  1184. cfdata->compressed_size != cfdata->uncompressed_size)
  1185. goto invalid;
  1186. /*
  1187. * Save CFDATA image for sum check.
  1188. */
  1189. if (cfdata->memimage_size < (size_t)l) {
  1190. free(cfdata->memimage);
  1191. cfdata->memimage = malloc(l);
  1192. if (cfdata->memimage == NULL) {
  1193. archive_set_error(&a->archive, ENOMEM,
  1194. "Can't allocate memory for CAB data");
  1195. return (ARCHIVE_FATAL);
  1196. }
  1197. cfdata->memimage_size = l;
  1198. }
  1199. memcpy(cfdata->memimage, p, l);
  1200. /* Consume bytes as much as we used. */
  1201. __archive_read_consume(a, l);
  1202. cab->cab_offset += l;
  1203. } else if (cab->entry_cffolder->cfdata_count > 0) {
  1204. /* Run out of all CFDATA in a folder. */
  1205. cfdata->compressed_size = 0;
  1206. cfdata->uncompressed_size = 0;
  1207. cfdata->compressed_bytes_remaining = 0;
  1208. cfdata->uncompressed_bytes_remaining = 0;
  1209. } else {
  1210. /* Current folder does not have any CFDATA. */
  1211. cfdata = &(cab->entry_cffolder->cfdata);
  1212. cab->entry_cfdata = cfdata;
  1213. memset(cfdata, 0, sizeof(*cfdata));
  1214. }
  1215. return (ARCHIVE_OK);
  1216. invalid:
  1217. archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT,
  1218. "Invalid CFDATA");
  1219. return (ARCHIVE_FATAL);
  1220. }
  1221. /*
  1222. * Read ahead CFDATA.
  1223. */
  1224. static const void *
  1225. cab_read_ahead_cfdata(struct archive_read *a, ssize_t *avail)
  1226. {
  1227. struct cab *cab = (struct cab *)(a->format->data);
  1228. int err;
  1229. err = cab_next_cfdata(a);
  1230. if (err < ARCHIVE_OK) {
  1231. *avail = err;
  1232. return (NULL);
  1233. }
  1234. switch (cab->entry_cffolder->comptype) {
  1235. case COMPTYPE_NONE:
  1236. return (cab_read_ahead_cfdata_none(a, avail));
  1237. case COMPTYPE_MSZIP:
  1238. return (cab_read_ahead_cfdata_deflate(a, avail));
  1239. case COMPTYPE_LZX:
  1240. return (cab_read_ahead_cfdata_lzx(a, avail));
  1241. default: /* Unsupported compression. */
  1242. archive_set_error(&a->archive, ARCHIVE_ERRNO_FILE_FORMAT,
  1243. "Unsupported CAB compression : %s",
  1244. cab->entry_cffolder->compname);
  1245. *avail = ARCHIVE_FAILED;
  1246. return (NULL);
  1247. }
  1248. }
  1249. /*
  1250. * Read ahead CFDATA as uncompressed data.
  1251. */
  1252. static const void *
  1253. cab_read_ahead_cfdata_none(struct archive_read *a, ssize_t *avail)
  1254. {
  1255. struct cab *cab = (struct cab *)(a->format->data);
  1256. struct cfdata *cfdata;
  1257. const void *d;
  1258. cfdata = cab->entry_cfdata;
  1259. /*
  1260. * Note: '1' here is a performance optimization.
  1261. * Recall that the decompression layer returns a count of
  1262. * available bytes; asking for more than that forces the
  1263. * decompressor to combine reads by copying data.
  1264. */
  1265. d = __archive_read_ahead(a, 1, avail);
  1266. if (*avail <= 0) {
  1267. *avail = truncated_error(a);
  1268. return (NULL);
  1269. }
  1270. if (*avail > cfdata->uncompressed_bytes_remaining)
  1271. *avail = cfdata->uncompressed_bytes_remaining;
  1272. cfdata->uncompressed_avail = cfdata->uncompressed_size;
  1273. cfdata->unconsumed = *avail;
  1274. cfdata->sum_ptr = d;
  1275. return (d);
  1276. }
  1277. /*
  1278. * Read ahead CFDATA as deflate data.
  1279. */
  1280. #ifdef HAVE_ZLIB_H
  1281. static const void *
  1282. cab_read_ahead_cfdata_deflate(struct archive_read *a, ssize_t *avail)
  1283. {
  1284. struct cab *cab = (struct cab *)(a->format->data);
  1285. struct cfdata *cfdata;
  1286. const void *d;
  1287. int r, mszip;
  1288. uint16_t uavail;
  1289. char eod = 0;
  1290. cfdata = cab->entry_cfdata;
  1291. /* If the buffer hasn't been allocated, allocate it now. */
  1292. if (cab->uncompressed_buffer == NULL) {
  1293. cab->uncompressed_buffer_size = 0x8000;
  1294. cab->uncompressed_buffer
  1295. = (unsigned char *)malloc(cab->uncompressed_buffer_size);
  1296. if (cab->uncompressed_buffer == NULL) {
  1297. archive_set_error(&a->archive, ENOMEM,
  1298. "No memory for CAB reader");
  1299. *avail = ARCHIVE_FATAL;
  1300. return (NULL);
  1301. }
  1302. }
  1303. uavail = cfdata->uncompressed_avail;
  1304. if (uavail == cfdata->uncompressed_size) {
  1305. d = cab->uncompressed_buffer + cfdata->read_offset;
  1306. *avail = uavail - cfdata->read_offset;
  1307. return (d);
  1308. }
  1309. if (!cab->entry_cffolder->decompress_init) {
  1310. cab->stream.next_in = NULL;
  1311. cab->stream.avail_in = 0;
  1312. cab->stream.total_in = 0;
  1313. cab->stream.next_out = NULL;
  1314. cab->stream.avail_out = 0;
  1315. cab->stream.total_out = 0;
  1316. if (cab->stream_valid)
  1317. r = inflateReset(&cab->stream);
  1318. else
  1319. r = inflateInit2(&cab->stream,
  1320. -15 /* Don't check for zlib header */);
  1321. if (r != Z_OK) {
  1322. archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
  1323. "Can't initialize deflate decompression.");
  1324. *avail = ARCHIVE_FATAL;
  1325. return (NULL);
  1326. }
  1327. /* Stream structure has been set up. */
  1328. cab->stream_valid = 1;
  1329. /* We've initialized decompression for this stream. */
  1330. cab->entry_cffolder->decompress_init = 1;
  1331. }
  1332. if (cfdata->compressed_bytes_remaining == cfdata->compressed_size)
  1333. mszip = 2;
  1334. else
  1335. mszip = 0;
  1336. eod = 0;
  1337. cab->stream.total_out = uavail;
  1338. /*
  1339. * We always uncompress all data in current CFDATA.
  1340. */
  1341. while (!eod && cab->stream.total_out < cfdata->uncompressed_size) {
  1342. ssize_t bytes_avail;
  1343. cab->stream.next_out =
  1344. cab->uncompressed_buffer + cab->stream.total_out;
  1345. cab->stream.avail_out =
  1346. cfdata->uncompressed_size - cab->stream.total_out;
  1347. d = __archive_read_ahead(a, 1, &bytes_avail);
  1348. if (bytes_avail <= 0) {
  1349. *avail = truncated_error(a);
  1350. return (NULL);
  1351. }
  1352. if (bytes_avail > cfdata->compressed_bytes_remaining)
  1353. bytes_avail = cfdata->compressed_bytes_remaining;
  1354. /*
  1355. * A bug in zlib.h: stream.next_in should be marked 'const'
  1356. * but isn't (the library never alters data through the
  1357. * next_in pointer, only reads it). The result: this ugly
  1358. * cast to remove 'const'.
  1359. */
  1360. cab->stream.next_in = (Bytef *)(uintptr_t)d;
  1361. cab->stream.avail_in = (uInt)bytes_avail;
  1362. cab->stream.total_in = 0;
  1363. /* Cut out a tow-byte MSZIP signature(0x43, 0x4b). */
  1364. if (mszip > 0) {
  1365. if (bytes_avail <= 0)
  1366. goto nomszip;
  1367. if (bytes_avail <= mszip) {
  1368. if (mszip == 2) {
  1369. if (cab->stream.next_in[0] != 0x43)
  1370. goto nomszip;
  1371. if (bytes_avail > 1 &&
  1372. cab->stream.next_in[1] != 0x4b)
  1373. goto nomszip;
  1374. } else if (cab->stream.next_in[0] != 0x4b)
  1375. goto nomszip;
  1376. cfdata->unconsumed = bytes_avail;
  1377. cfdata->sum_ptr = d;
  1378. if (cab_minimum_consume_cfdata(
  1379. a, cfdata->unconsumed) < 0) {
  1380. *avail = ARCHIVE_FATAL;
  1381. return (NULL);
  1382. }
  1383. mszip -= (int)bytes_avail;
  1384. continue;
  1385. }
  1386. if (mszip == 1 && cab->stream.next_in[0] != 0x4b)
  1387. goto nomszip;
  1388. else if (cab->stream.next_in[0] != 0x43 ||
  1389. cab->stream.next_in[1] != 0x4b)
  1390. goto nomszip;
  1391. cab->stream.next_in += mszip;
  1392. cab->stream.avail_in -= mszip;
  1393. cab->stream.total_in += mszip;
  1394. mszip = 0;
  1395. }
  1396. r = inflate(&cab->stream, 0);
  1397. switch (r) {
  1398. case Z_OK:
  1399. break;
  1400. case Z_STREAM_END:
  1401. eod = 1;
  1402. break;
  1403. default:
  1404. goto zlibfailed;
  1405. }
  1406. cfdata->unconsumed = cab->stream.total_in;
  1407. cfdata->sum_ptr = d;
  1408. if (cab_minimum_consume_cfdata(a, cfdata->unconsumed) < 0) {
  1409. *avail = ARCHIVE_FATAL;
  1410. return (NULL);
  1411. }
  1412. }
  1413. uavail = (uint16_t)cab->stream.total_out;
  1414. if (uavail < cfdata->uncompressed_size) {
  1415. archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
  1416. "Invalid uncompressed size (%d < %d)",
  1417. uavail, cfdata->uncompressed_size);
  1418. *avail = ARCHIVE_FATAL;
  1419. return (NULL);
  1420. }
  1421. /*
  1422. * Note: I suspect there is a bug in makecab.exe because, in rare
  1423. * case, compressed bytes are still remaining regardless we have
  1424. * gotten all uncompressed bytes, which size is recorded in CFDATA,
  1425. * as much as we need, and we have to use the garbage so as to
  1426. * correctly compute the sum of CFDATA accordingly.
  1427. */
  1428. if (cfdata->compressed_bytes_remaining > 0) {
  1429. ssize_t bytes_avail;
  1430. d = __archive_read_ahead(a, cfdata->compressed_bytes_remaining,
  1431. &bytes_avail);
  1432. if (bytes_avail <= 0) {
  1433. *avail = truncated_error(a);
  1434. return (NULL);
  1435. }
  1436. cfdata->unconsumed = cfdata->compressed_bytes_remaining;
  1437. cfdata->sum_ptr = d;
  1438. if (cab_minimum_consume_cfdata(a, cfdata->unconsumed) < 0) {
  1439. *avail = ARCHIVE_FATAL;
  1440. return (NULL);
  1441. }
  1442. }
  1443. /*
  1444. * Set dictionary data for decompressing of next CFDATA, which
  1445. * in the same folder. This is why we always do decompress CFDATA
  1446. * even if beginning CFDATA or some of CFDATA are not used in
  1447. * skipping file data.
  1448. */
  1449. if (cab->entry_cffolder->cfdata_index <
  1450. cab->entry_cffolder->cfdata_count) {
  1451. r = inflateReset(&cab->stream);
  1452. if (r != Z_OK)
  1453. goto zlibfailed;
  1454. r = inflateSetDictionary(&cab->stream,
  1455. cab->uncompressed_buffer, cfdata->uncompressed_size);
  1456. if (r != Z_OK)
  1457. goto zlibfailed;
  1458. }
  1459. d = cab->uncompressed_buffer + cfdata->read_offset;
  1460. *avail = uavail - cfdata->read_offset;
  1461. cfdata->uncompressed_avail = uavail;
  1462. return (d);
  1463. zlibfailed:
  1464. switch (r) {
  1465. case Z_MEM_ERROR:
  1466. archive_set_error(&a->archive, ENOMEM,
  1467. "Out of memory for deflate decompression");
  1468. break;
  1469. default:
  1470. archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
  1471. "Deflate decompression failed (%d)", r);
  1472. break;
  1473. }
  1474. *avail = ARCHIVE_FATAL;
  1475. return (NULL);
  1476. nomszip:
  1477. archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
  1478. "CFDATA incorrect(no MSZIP signature)");
  1479. *avail = ARCHIVE_FATAL;
  1480. return (NULL);
  1481. }
  1482. #else /* HAVE_ZLIB_H */
  1483. static const void *
  1484. cab_read_ahead_cfdata_deflate(struct archive_read *a, ssize_t *avail)
  1485. {
  1486. *avail = ARCHIVE_FATAL;
  1487. archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
  1488. "libarchive compiled without deflate support (no libz)");
  1489. return (NULL);
  1490. }
  1491. #endif /* HAVE_ZLIB_H */
  1492. static const void *
  1493. cab_read_ahead_cfdata_lzx(struct archive_read *a, ssize_t *avail)
  1494. {
  1495. struct cab *cab = (struct cab *)(a->format->data);
  1496. struct cfdata *cfdata;
  1497. const void *d;
  1498. int r;
  1499. uint16_t uavail;
  1500. cfdata = cab->entry_cfdata;
  1501. /* If the buffer hasn't been allocated, allocate it now. */
  1502. if (cab->uncompressed_buffer == NULL) {
  1503. cab->uncompressed_buffer_size = 0x8000;
  1504. cab->uncompressed_buffer
  1505. = (unsigned char *)malloc(cab->uncompressed_buffer_size);
  1506. if (cab->uncompressed_buffer == NULL) {
  1507. archive_set_error(&a->archive, ENOMEM,
  1508. "No memory for CAB reader");
  1509. *avail = ARCHIVE_FATAL;
  1510. return (NULL);
  1511. }
  1512. }
  1513. uavail = cfdata->uncompressed_avail;
  1514. if (uavail == cfdata->uncompressed_size) {
  1515. d = cab->uncompressed_buffer + cfdata->read_offset;
  1516. *avail = uavail - cfdata->read_offset;
  1517. return (d);
  1518. }
  1519. if (!cab->entry_cffolder->decompress_init) {
  1520. r = lzx_decode_init(&cab->xstrm,
  1521. cab->entry_cffolder->compdata);
  1522. if (r != ARCHIVE_OK) {
  1523. archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
  1524. "Can't initialize LZX decompression.");
  1525. *avail = ARCHIVE_FATAL;
  1526. return (NULL);
  1527. }
  1528. /* We've initialized decompression for this stream. */
  1529. cab->entry_cffolder->decompress_init = 1;
  1530. }
  1531. /* Clean up remaining bits of previous CFDATA. */
  1532. lzx_cleanup_bitstream(&cab->xstrm);
  1533. cab->xstrm.total_out = uavail;
  1534. while (cab->xstrm.total_out < cfdata->uncompressed_size) {
  1535. ssize_t bytes_avail;
  1536. cab->xstrm.next_out =
  1537. cab->uncompressed_buffer + cab->xstrm.total_out;
  1538. cab->xstrm.avail_out =
  1539. cfdata->uncompressed_size - cab->xstrm.total_out;
  1540. d = __archive_read_ahead(a, 1, &bytes_avail);
  1541. if (bytes_avail <= 0) {
  1542. archive_set_error(&a->archive,
  1543. ARCHIVE_ERRNO_FILE_FORMAT,
  1544. "Truncated CAB file data");
  1545. *avail = ARCHIVE_FATAL;
  1546. return (NULL);
  1547. }
  1548. if (bytes_avail > cfdata->compressed_bytes_remaining)
  1549. bytes_avail = cfdata->compressed_bytes_remaining;
  1550. cab->xstrm.next_in = d;
  1551. cab->xstrm.avail_in = bytes_avail;
  1552. cab->xstrm.total_in = 0;
  1553. r = lzx_decode(&cab->xstrm,
  1554. cfdata->compressed_bytes_remaining == bytes_avail);
  1555. switch (r) {
  1556. case ARCHIVE_OK:
  1557. case ARCHIVE_EOF:
  1558. break;
  1559. default:
  1560. archive_set_error(&a->archive, ARCHIVE_ERRNO_MISC,
  1561. "LZX decompression failed (%d)", r);
  1562. *avail = ARCHIVE_FATAL;
  1563. return (NULL);
  1564. }
  1565. cfdata->unconsumed = cab->xstrm.total_in;
  1566. cfdata->sum_ptr = d;
  1567. if (cab_minimum_consume_cfdata(a, cfdata->unconsumed) < 0) {
  1568. *avail = ARCHIVE_FATAL;
  1569. return (NULL);
  1570. }
  1571. }
  1572. uavail = (uint16_t)cab->xstrm.total_out;
  1573. /*
  1574. * Make sure a read pointer advances to next CFDATA.
  1575. */
  1576. if (cfdata->compressed_bytes_remaining > 0) {
  1577. ssize_t bytes_avail;
  1578. d = __archive_read_ahead(a, cfdata->compressed_bytes_remaining,
  1579. &bytes_avail);
  1580. if (bytes_avail <= 0) {
  1581. *avail = truncated_error(a);
  1582. return (NULL);
  1583. }
  1584. cfdata->unconsumed = cfdata->compressed_bytes_remaining;
  1585. cfdata->sum_ptr = d;
  1586. if (cab_minimum_consume_cfdata(a, cfdata->unconsumed) < 0) {
  1587. *avail = ARCHIVE_FATAL;
  1588. return (NULL);
  1589. }
  1590. }
  1591. /*
  1592. * Translation reversal of x86 processor CALL byte sequence(E8).
  1593. */
  1594. lzx_translation(&cab->xstrm, cab->uncompressed_buffer,
  1595. cfdata->uncompressed_size,
  1596. (cab->entry_cffolder->cfdata_index-1) * 0x8000);
  1597. d = cab->uncompressed_buffer + cfdata->read_offset;
  1598. *avail = uavail - cfdata->read_offset;
  1599. cfdata->uncompressed_avail = uavail;
  1600. return (d);
  1601. }
  1602. /*
  1603. * Consume CFDATA.
  1604. * We always decompress CFDATA to consume CFDATA as much as we need
  1605. * in uncompressed bytes because all CFDATA in a folder are related
  1606. * so we do not skip any CFDATA without decompressing.
  1607. * Note: If the folder of a CFFILE is iFoldCONTINUED_PREV_AND_NEXT or
  1608. * iFoldCONTINUED_FROM_PREV, we won't decompress because a CFDATA for
  1609. * the CFFILE is remaining bytes of previous Multivolume CAB file.
  1610. */
  1611. static int64_t
  1612. cab_consume_cfdata(struct archive_read *a, int64_t consumed_bytes)
  1613. {
  1614. struct cab *cab = (struct cab *)(a->format->data);
  1615. struct cfdata *cfdata;
  1616. int64_t cbytes, rbytes;
  1617. int err;
  1618. rbytes = cab_minimum_consume_cfdata(a, consumed_bytes);
  1619. if (rbytes < 0)
  1620. return (ARCHIVE_FATAL);
  1621. cfdata = cab->entry_cfdata;
  1622. while (rbytes > 0) {
  1623. ssize_t avail;
  1624. if (cfdata->compressed_size == 0) {
  1625. archive_set_error(&a->archive,
  1626. ARCHIVE_ERRNO_FILE_FORMAT,
  1627. "Invalid CFDATA");
  1628. return (ARCHIVE_FATAL);
  1629. }
  1630. cbytes = cfdata->uncompressed_bytes_remaining;
  1631. if (cbytes > rbytes)
  1632. cbytes = rbytes;
  1633. rbytes -= cbytes;
  1634. if (cfdata->uncompressed_avail == 0 &&
  1635. (cab->entry_cffile->folder == iFoldCONTINUED_PREV_AND_NEXT ||
  1636. cab->entry_cffile->folder == iFoldCONTINUED_FROM_PREV)) {
  1637. /* We have not read any data yet. */
  1638. if (cbytes == cfdata->uncompressed_bytes_remaining) {
  1639. /* Skip whole current CFDATA. */
  1640. __archive_read_consume(a,
  1641. cfdata->compressed_size);
  1642. cab->cab_offset += cfdata->compressed_size;
  1643. cfdata->compressed_bytes_remaining = 0;
  1644. cfdata->uncompressed_bytes_remaining = 0;
  1645. err = cab_next_cfdata(a);
  1646. if (err < 0)
  1647. return (err);
  1648. cfdata = cab->entry_cfdata;
  1649. if (cfdata->uncompressed_size == 0) {
  1650. switch (cab->entry_cffile->folder) {
  1651. case iFoldCONTINUED_PREV_AND_NEXT:
  1652. case iFoldCONTINUED_TO_NEXT:
  1653. case iFoldCONTINUED_FROM_PREV:
  1654. rbytes = 0;
  1655. break;
  1656. default:
  1657. break;
  1658. }
  1659. }
  1660. continue;
  1661. }
  1662. cfdata->read_offset += (uint16_t)cbytes;
  1663. cfdata->uncompressed_bytes_remaining -= (uint16_t)cbytes;
  1664. break;
  1665. } else if (cbytes == 0) {
  1666. err = cab_next_cfdata(a);
  1667. if (err < 0)
  1668. return (err);
  1669. cfdata = cab->entry_cfdata;
  1670. if (cfdata->uncompressed_size == 0) {
  1671. switch (cab->entry_cffile->folder) {
  1672. case iFoldCONTINUED_PREV_AND_NEXT:
  1673. case iFoldCONTINUED_TO_NEXT:
  1674. case iFoldCONTINUED_FROM_PREV:
  1675. return (ARCHIVE_FATAL);
  1676. default:
  1677. break;
  1678. }
  1679. }
  1680. continue;
  1681. }
  1682. while (cbytes > 0) {
  1683. (void)cab_read_ahead_cfdata(a, &avail);
  1684. if (avail <= 0)
  1685. return (ARCHIVE_FATAL);
  1686. if (avail > cbytes)
  1687. avail = (ssize_t)cbytes;
  1688. if (cab_minimum_consume_cfdata(a, avail) < 0)
  1689. return (ARCHIVE_FATAL);
  1690. cbytes -= avail;
  1691. }
  1692. }
  1693. return (consumed_bytes);
  1694. }
  1695. /*
  1696. * Consume CFDATA as much as we have already gotten and
  1697. * compute the sum of CFDATA.
  1698. */
  1699. static int64_t
  1700. cab_minimum_consume_cfdata(struct archive_read *a, int64_t consumed_bytes)
  1701. {
  1702. struct cab *cab = (struct cab *)(a->format->data);
  1703. struct cfdata *cfdata;
  1704. int64_t cbytes, rbytes;
  1705. int err;
  1706. cfdata = cab->entry_cfdata;
  1707. rbytes = consumed_bytes;
  1708. if (cab->entry_cffolder->comptype == COMPTYPE_NONE) {
  1709. if (consumed_bytes < cfdata->unconsumed)
  1710. cbytes = consumed_bytes;
  1711. else
  1712. cbytes = cfdata->unconsumed;
  1713. rbytes -= cbytes;
  1714. cfdata->read_offset += (uint16_t)cbytes;
  1715. cfdata->uncompressed_bytes_remaining -= (uint16_t)cbytes;
  1716. cfdata->unconsumed -= cbytes;
  1717. } else {
  1718. cbytes = cfdata->uncompressed_avail - cfdata->read_offset;
  1719. if (cbytes > 0) {
  1720. if (consumed_bytes < cbytes)
  1721. cbytes = consumed_bytes;
  1722. rbytes -= cbytes;
  1723. cfdata->read_offset += (uint16_t)cbytes;
  1724. cfdata->uncompressed_bytes_remaining -= (uint16_t)cbytes;
  1725. }
  1726. if (cfdata->unconsumed) {
  1727. cbytes = cfdata->unconsumed;
  1728. cfdata->unconsumed = 0;
  1729. } else
  1730. cbytes = 0;
  1731. }
  1732. if (cbytes) {
  1733. /* Compute the sum. */
  1734. cab_checksum_update(a, (size_t)cbytes);
  1735. /* Consume as much as the compressor actually used. */
  1736. __archive_read_consume(a, cbytes);
  1737. cab->cab_offset += cbytes;
  1738. cfdata->compressed_bytes_remaining -= (uint16_t)cbytes;
  1739. if (cfdata->compressed_bytes_remaining == 0) {
  1740. err = cab_checksum_finish(a);
  1741. if (err < 0)
  1742. return (err);
  1743. }
  1744. }
  1745. return (rbytes);
  1746. }
  1747. /*
  1748. * Returns ARCHIVE_OK if successful, ARCHIVE_FATAL otherwise, sets
  1749. * cab->end_of_entry if it consumes all of the data.
  1750. */
  1751. static int
  1752. cab_read_data(struct archive_read *a, const void **buff,
  1753. size_t *size, int64_t *offset)
  1754. {
  1755. struct cab *cab = (struct cab *)(a->format->data);
  1756. ssize_t bytes_avail;
  1757. if (cab->entry_bytes_remaining == 0) {
  1758. *buff = NULL;
  1759. *size = 0;
  1760. *offset = cab->entry_offset;
  1761. cab->end_of_entry = 1;
  1762. return (ARCHIVE_OK);
  1763. }
  1764. *buff = cab_read_ahead_cfdata(a, &bytes_avail);
  1765. if (bytes_avail <= 0) {
  1766. *buff = NULL;
  1767. *size = 0;
  1768. *offset = 0;
  1769. if (bytes_avail == 0 &&
  1770. cab->entry_cfdata->uncompressed_size == 0) {
  1771. /* All of CFDATA in a folder has been handled. */
  1772. archive_set_error(&a->archive,
  1773. ARCHIVE_ERRNO_FILE_FORMAT, "Invalid CFDATA");
  1774. return (ARCHIVE_FATAL);
  1775. } else
  1776. return ((int)bytes_avail);
  1777. }
  1778. if (bytes_avail > cab->entry_bytes_remaining)
  1779. bytes_avail = (ssize_t)cab->entry_bytes_remaining;
  1780. *size = bytes_avail;
  1781. *offset = cab->entry_offset;
  1782. cab->entry_offset += bytes_avail;
  1783. cab->entry_bytes_remaining -= bytes_avail;
  1784. if (cab->entry_bytes_remaining == 0)
  1785. cab->end_of_entry = 1;
  1786. cab->entry_unconsumed = bytes_avail;
  1787. if (cab->entry_cffolder->comptype == COMPTYPE_NONE) {
  1788. /* Don't consume more than current entry used. */
  1789. if (cab->entry_cfdata->unconsumed > cab->entry_unconsumed)
  1790. cab->entry_cfdata->unconsumed = cab->entry_unconsumed;
  1791. }
  1792. return (ARCHIVE_OK);
  1793. }
  1794. static int
  1795. archive_read_format_cab_read_data_skip(struct archive_read *a)
  1796. {
  1797. struct cab *cab;
  1798. int64_t bytes_skipped;
  1799. int r;
  1800. cab = (struct cab *)(a->format->data);
  1801. if (cab->end_of_archive)
  1802. return (ARCHIVE_EOF);
  1803. if (!cab->read_data_invoked) {
  1804. cab->bytes_skipped += cab->entry_bytes_remaining;
  1805. cab->entry_bytes_remaining = 0;
  1806. /* This entry is finished and done. */
  1807. cab->end_of_entry_cleanup = cab->end_of_entry = 1;
  1808. return (ARCHIVE_OK);
  1809. }
  1810. if (cab->entry_unconsumed) {
  1811. /* Consume as much as the compressor actually used. */
  1812. r = (int)cab_consume_cfdata(a, cab->entry_unconsumed);
  1813. cab->entry_unconsumed = 0;
  1814. if (r < 0)
  1815. return (r);
  1816. } else if (cab->entry_cfdata == NULL) {
  1817. r = cab_next_cfdata(a);
  1818. if (r < 0)
  1819. return (r);
  1820. }
  1821. /* if we've already read to end of data, we're done. */
  1822. if (cab->end_of_entry_cleanup)
  1823. return (ARCHIVE_OK);
  1824. /*
  1825. * If the length is at the beginning, we can skip the
  1826. * compressed data much more quickly.
  1827. */
  1828. bytes_skipped = cab_consume_cfdata(a, cab->entry_bytes_remaining);
  1829. if (bytes_skipped < 0)
  1830. return (ARCHIVE_FATAL);
  1831. /* If the compression type is none(uncompressed), we've already
  1832. * consumed data as much as the current entry size. */
  1833. if (cab->entry_cffolder->comptype == COMPTYPE_NONE &&
  1834. cab->entry_cfdata != NULL)
  1835. cab->entry_cfdata->unconsumed = 0;
  1836. /* This entry is finished and done. */
  1837. cab->end_of_entry_cleanup = cab->end_of_entry = 1;
  1838. return (ARCHIVE_OK);
  1839. }
  1840. static int
  1841. archive_read_format_cab_cleanup(struct archive_read *a)
  1842. {
  1843. struct cab *cab = (struct cab *)(a->format->data);
  1844. struct cfheader *hd = &cab->cfheader;
  1845. int i;
  1846. if (hd->folder_array != NULL) {
  1847. for (i = 0; i < hd->folder_count; i++)
  1848. free(hd->folder_array[i].cfdata.memimage);
  1849. free(hd->folder_array);
  1850. }
  1851. if (hd->file_array != NULL) {
  1852. for (i = 0; i < cab->cfheader.file_count; i++)
  1853. archive_string_free(&(hd->file_array[i].pathname));
  1854. free(hd->file_array);
  1855. }
  1856. #ifdef HAVE_ZLIB_H
  1857. if (cab->stream_valid)
  1858. inflateEnd(&cab->stream);
  1859. #endif
  1860. lzx_decode_free(&cab->xstrm);
  1861. archive_wstring_free(&cab->ws);
  1862. free(cab->uncompressed_buffer);
  1863. free(cab);
  1864. (a->format->data) = NULL;
  1865. return (ARCHIVE_OK);
  1866. }
  1867. /* Convert an MSDOS-style date/time into Unix-style time. */
  1868. static time_t
  1869. cab_dos_time(const unsigned char *p)
  1870. {
  1871. int msTime, msDate;
  1872. struct tm ts;
  1873. msDate = archive_le16dec(p);
  1874. msTime = archive_le16dec(p+2);
  1875. memset(&ts, 0, sizeof(ts));
  1876. ts.tm_year = ((msDate >> 9) & 0x7f) + 80; /* Years since 1900. */
  1877. ts.tm_mon = ((msDate >> 5) & 0x0f) - 1; /* Month number. */
  1878. ts.tm_mday = msDate & 0x1f; /* Day of month. */
  1879. ts.tm_hour = (msTime >> 11) & 0x1f;
  1880. ts.tm_min = (msTime >> 5) & 0x3f;
  1881. ts.tm_sec = (msTime << 1) & 0x3e;
  1882. ts.tm_isdst = -1;
  1883. return (mktime(&ts));
  1884. }
  1885. /*****************************************************************
  1886. *
  1887. * LZX decompression code.
  1888. *
  1889. *****************************************************************/
  1890. /*
  1891. * Initialize LZX decoder.
  1892. *
  1893. * Returns ARCHIVE_OK if initialization was successful.
  1894. * Returns ARCHIVE_FAILED if w_bits has unsupported value.
  1895. * Returns ARCHIVE_FATAL if initialization failed; memory allocation
  1896. * error occurred.
  1897. */
  1898. static int
  1899. lzx_decode_init(struct lzx_stream *strm, int w_bits)
  1900. {
  1901. struct lzx_dec *ds;
  1902. int slot, w_size, w_slot;
  1903. int base, footer;
  1904. int base_inc[18];
  1905. if (strm->ds == NULL) {
  1906. strm->ds = calloc(1, sizeof(*strm->ds));
  1907. if (strm->ds == NULL)
  1908. return (ARCHIVE_FATAL);
  1909. }
  1910. ds = strm->ds;
  1911. ds->error = ARCHIVE_FAILED;
  1912. /* Allow bits from 15(32KBi) up to 21(2MBi) */
  1913. if (w_bits < SLOT_BASE || w_bits > SLOT_MAX)
  1914. return (ARCHIVE_FAILED);
  1915. ds->error = ARCHIVE_FATAL;
  1916. /*
  1917. * Alloc window
  1918. */
  1919. w_size = ds->w_size;
  1920. w_slot = slots[w_bits - SLOT_BASE];
  1921. ds->w_size = 1U << w_bits;
  1922. ds->w_mask = ds->w_size -1;
  1923. if (ds->w_buff == NULL || w_size != ds->w_size) {
  1924. free(ds->w_buff);
  1925. ds->w_buff = malloc(ds->w_size);
  1926. if (ds->w_buff == NULL)
  1927. return (ARCHIVE_FATAL);
  1928. free(ds->pos_tbl);
  1929. ds->pos_tbl = malloc(sizeof(ds->pos_tbl[0]) * w_slot);
  1930. if (ds->pos_tbl == NULL)
  1931. return (ARCHIVE_FATAL);
  1932. lzx_huffman_free(&(ds->mt));
  1933. }
  1934. for (footer = 0; footer < 18; footer++)
  1935. base_inc[footer] = 1 << footer;
  1936. base = footer = 0;
  1937. for (slot = 0; slot < w_slot; slot++) {
  1938. int n;
  1939. if (footer == 0)
  1940. base = slot;
  1941. else
  1942. base += base_inc[footer];
  1943. if (footer < 17) {
  1944. footer = -2;
  1945. for (n = base; n; n >>= 1)
  1946. footer++;
  1947. if (footer <= 0)
  1948. footer = 0;
  1949. }
  1950. ds->pos_tbl[slot].base = base;
  1951. ds->pos_tbl[slot].footer_bits = footer;
  1952. }
  1953. ds->w_pos = 0;
  1954. ds->state = 0;
  1955. ds->br.cache_buffer = 0;
  1956. ds->br.cache_avail = 0;
  1957. ds->r0 = ds->r1 = ds->r2 = 1;
  1958. /* Initialize aligned offset tree. */
  1959. if (lzx_huffman_init(&(ds->at), 8, 8) != ARCHIVE_OK)
  1960. return (ARCHIVE_FATAL);
  1961. /* Initialize pre-tree. */
  1962. if (lzx_huffman_init(&(ds->pt), 20, 10) != ARCHIVE_OK)
  1963. return (ARCHIVE_FATAL);
  1964. /* Initialize Main tree. */
  1965. if (lzx_huffman_init(&(ds->mt), 256+(w_slot<<3), 16)
  1966. != ARCHIVE_OK)
  1967. return (ARCHIVE_FATAL);
  1968. /* Initialize Length tree. */
  1969. if (lzx_huffman_init(&(ds->lt), 249, 16) != ARCHIVE_OK)
  1970. return (ARCHIVE_FATAL);
  1971. ds->error = 0;
  1972. return (ARCHIVE_OK);
  1973. }
  1974. /*
  1975. * Release LZX decoder.
  1976. */
  1977. static void
  1978. lzx_decode_free(struct lzx_stream *strm)
  1979. {
  1980. if (strm->ds == NULL)
  1981. return;
  1982. free(strm->ds->w_buff);
  1983. free(strm->ds->pos_tbl);
  1984. lzx_huffman_free(&(strm->ds->at));
  1985. lzx_huffman_free(&(strm->ds->pt));
  1986. lzx_huffman_free(&(strm->ds->mt));
  1987. lzx_huffman_free(&(strm->ds->lt));
  1988. free(strm->ds);
  1989. strm->ds = NULL;
  1990. }
  1991. /*
  1992. * E8 Call Translation reversal.
  1993. */
  1994. static void
  1995. lzx_translation(struct lzx_stream *strm, void *p, size_t size, uint32_t offset)
  1996. {
  1997. struct lzx_dec *ds = strm->ds;
  1998. unsigned char *b, *end;
  1999. if (!ds->translation || size <= 10)
  2000. return;
  2001. b = p;
  2002. end = b + size - 10;
  2003. while (b < end && (b = memchr(b, 0xE8, end - b)) != NULL) {
  2004. size_t i = b - (unsigned char *)p;
  2005. int32_t cp, displacement, value;
  2006. cp = (int32_t)(offset + (uint32_t)i);
  2007. value = archive_le32dec(&b[1]);
  2008. if (value >= -cp && value < (int32_t)ds->translation_size) {
  2009. if (value >= 0)
  2010. displacement = value - cp;
  2011. else
  2012. displacement = value + ds->translation_size;
  2013. archive_le32enc(&b[1], (uint32_t)displacement);
  2014. }
  2015. b += 5;
  2016. }
  2017. }
  2018. /*
  2019. * Bit stream reader.
  2020. */
  2021. /* Check that the cache buffer has enough bits. */
  2022. #define lzx_br_has(br, n) ((br)->cache_avail >= n)
  2023. /* Get compressed data by bit. */
  2024. #define lzx_br_bits(br, n) \
  2025. (((uint32_t)((br)->cache_buffer >> \
  2026. ((br)->cache_avail - (n)))) & cache_masks[n])
  2027. #define lzx_br_bits_forced(br, n) \
  2028. (((uint32_t)((br)->cache_buffer << \
  2029. ((n) - (br)->cache_avail))) & cache_masks[n])
  2030. /* Read ahead to make sure the cache buffer has enough compressed data we
  2031. * will use.
  2032. * True : completed, there is enough data in the cache buffer.
  2033. * False : we met that strm->next_in is empty, we have to get following
  2034. * bytes. */
  2035. #define lzx_br_read_ahead_0(strm, br, n) \
  2036. (lzx_br_has((br), (n)) || lzx_br_fillup(strm, br))
  2037. /* True : the cache buffer has some bits as much as we need.
  2038. * False : there are no enough bits in the cache buffer to be used,
  2039. * we have to get following bytes if we could. */
  2040. #define lzx_br_read_ahead(strm, br, n) \
  2041. (lzx_br_read_ahead_0((strm), (br), (n)) || lzx_br_has((br), (n)))
  2042. /* Notify how many bits we consumed. */
  2043. #define lzx_br_consume(br, n) ((br)->cache_avail -= (n))
  2044. #define lzx_br_consume_unaligned_bits(br) ((br)->cache_avail &= ~0x0f)
  2045. #define lzx_br_is_unaligned(br) ((br)->cache_avail & 0x0f)
  2046. static const uint32_t cache_masks[] = {
  2047. 0x00000000, 0x00000001, 0x00000003, 0x00000007,
  2048. 0x0000000F, 0x0000001F, 0x0000003F, 0x0000007F,
  2049. 0x000000FF, 0x000001FF, 0x000003FF, 0x000007FF,
  2050. 0x00000FFF, 0x00001FFF, 0x00003FFF, 0x00007FFF,
  2051. 0x0000FFFF, 0x0001FFFF, 0x0003FFFF, 0x0007FFFF,
  2052. 0x000FFFFF, 0x001FFFFF, 0x003FFFFF, 0x007FFFFF,
  2053. 0x00FFFFFF, 0x01FFFFFF, 0x03FFFFFF, 0x07FFFFFF,
  2054. 0x0FFFFFFF, 0x1FFFFFFF, 0x3FFFFFFF, 0x7FFFFFFF,
  2055. 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFF
  2056. };
  2057. /*
  2058. * Shift away used bits in the cache data and fill it up with following bits.
  2059. * Call this when cache buffer does not have enough bits you need.
  2060. *
  2061. * Returns 1 if the cache buffer is full.
  2062. * Returns 0 if the cache buffer is not full; input buffer is empty.
  2063. */
  2064. static int
  2065. lzx_br_fillup(struct lzx_stream *strm, struct lzx_br *br)
  2066. {
  2067. /*
  2068. * x86 processor family can read misaligned data without an access error.
  2069. */
  2070. int n = CACHE_BITS - br->cache_avail;
  2071. for (;;) {
  2072. switch (n >> 4) {
  2073. case 4:
  2074. if (strm->avail_in >= 8) {
  2075. br->cache_buffer =
  2076. ((uint64_t)strm->next_in[1]) << 56 |
  2077. ((uint64_t)strm->next_in[0]) << 48 |
  2078. ((uint64_t)strm->next_in[3]) << 40 |
  2079. ((uint64_t)strm->next_in[2]) << 32 |
  2080. ((uint32_t)strm->next_in[5]) << 24 |
  2081. ((uint32_t)strm->next_in[4]) << 16 |
  2082. ((uint32_t)strm->next_in[7]) << 8 |
  2083. (uint32_t)strm->next_in[6];
  2084. strm->next_in += 8;
  2085. strm->avail_in -= 8;
  2086. br->cache_avail += 8 * 8;
  2087. return (1);
  2088. }
  2089. break;
  2090. case 3:
  2091. if (strm->avail_in >= 6) {
  2092. br->cache_buffer =
  2093. (br->cache_buffer << 48) |
  2094. ((uint64_t)strm->next_in[1]) << 40 |
  2095. ((uint64_t)strm->next_in[0]) << 32 |
  2096. ((uint32_t)strm->next_in[3]) << 24 |
  2097. ((uint32_t)strm->next_in[2]) << 16 |
  2098. ((uint32_t)strm->next_in[5]) << 8 |
  2099. (uint32_t)strm->next_in[4];
  2100. strm->next_in += 6;
  2101. strm->avail_in -= 6;
  2102. br->cache_avail += 6 * 8;
  2103. return (1);
  2104. }
  2105. break;
  2106. case 0:
  2107. /* We have enough compressed data in
  2108. * the cache buffer.*/
  2109. return (1);
  2110. default:
  2111. break;
  2112. }
  2113. if (strm->avail_in < 2) {
  2114. /* There is not enough compressed data to
  2115. * fill up the cache buffer. */
  2116. if (strm->avail_in == 1) {
  2117. br->odd = *strm->next_in++;
  2118. strm->avail_in--;
  2119. br->have_odd = 1;
  2120. }
  2121. return (0);
  2122. }
  2123. br->cache_buffer =
  2124. (br->cache_buffer << 16) |
  2125. archive_le16dec(strm->next_in);
  2126. strm->next_in += 2;
  2127. strm->avail_in -= 2;
  2128. br->cache_avail += 16;
  2129. n -= 16;
  2130. }
  2131. }
  2132. static void
  2133. lzx_br_fixup(struct lzx_stream *strm, struct lzx_br *br)
  2134. {
  2135. int n = CACHE_BITS - br->cache_avail;
  2136. if (br->have_odd && n >= 16 && strm->avail_in > 0) {
  2137. br->cache_buffer =
  2138. (br->cache_buffer << 16) |
  2139. ((uint16_t)(*strm->next_in)) << 8 | br->odd;
  2140. strm->next_in++;
  2141. strm->avail_in--;
  2142. br->cache_avail += 16;
  2143. br->have_odd = 0;
  2144. }
  2145. }
  2146. static void
  2147. lzx_cleanup_bitstream(struct lzx_stream *strm)
  2148. {
  2149. strm->ds->br.cache_avail = 0;
  2150. strm->ds->br.have_odd = 0;
  2151. }
  2152. /*
  2153. * Decode LZX.
  2154. *
  2155. * 1. Returns ARCHIVE_OK if output buffer or input buffer are empty.
  2156. * Please set available buffer and call this function again.
  2157. * 2. Returns ARCHIVE_EOF if decompression has been completed.
  2158. * 3. Returns ARCHIVE_FAILED if an error occurred; compressed data
  2159. * is broken or you do not set 'last' flag properly.
  2160. */
  2161. #define ST_RD_TRANSLATION 0
  2162. #define ST_RD_TRANSLATION_SIZE 1
  2163. #define ST_RD_BLOCK_TYPE 2
  2164. #define ST_RD_BLOCK_SIZE 3
  2165. #define ST_RD_ALIGNMENT 4
  2166. #define ST_RD_R0 5
  2167. #define ST_RD_R1 6
  2168. #define ST_RD_R2 7
  2169. #define ST_COPY_UNCOMP1 8
  2170. #define ST_COPY_UNCOMP2 9
  2171. #define ST_RD_ALIGNED_OFFSET 10
  2172. #define ST_RD_VERBATIM 11
  2173. #define ST_RD_PRE_MAIN_TREE_256 12
  2174. #define ST_MAIN_TREE_256 13
  2175. #define ST_RD_PRE_MAIN_TREE_REM 14
  2176. #define ST_MAIN_TREE_REM 15
  2177. #define ST_RD_PRE_LENGTH_TREE 16
  2178. #define ST_LENGTH_TREE 17
  2179. #define ST_MAIN 18
  2180. #define ST_LENGTH 19
  2181. #define ST_OFFSET 20
  2182. #define ST_REAL_POS 21
  2183. #define ST_COPY 22
  2184. static int
  2185. lzx_decode(struct lzx_stream *strm, int last)
  2186. {
  2187. struct lzx_dec *ds = strm->ds;
  2188. int64_t avail_in;
  2189. int r;
  2190. if (ds->error)
  2191. return (ds->error);
  2192. avail_in = strm->avail_in;
  2193. lzx_br_fixup(strm, &(ds->br));
  2194. do {
  2195. if (ds->state < ST_MAIN)
  2196. r = lzx_read_blocks(strm, last);
  2197. else {
  2198. int64_t bytes_written = strm->avail_out;
  2199. r = lzx_decode_blocks(strm, last);
  2200. bytes_written -= strm->avail_out;
  2201. strm->next_out += bytes_written;
  2202. strm->total_out += bytes_written;
  2203. }
  2204. } while (r == 100);
  2205. strm->total_in += avail_in - strm->avail_in;
  2206. return (r);
  2207. }
  2208. static int
  2209. lzx_read_blocks(struct lzx_stream *strm, int last)
  2210. {
  2211. struct lzx_dec *ds = strm->ds;
  2212. struct lzx_br *br = &(ds->br);
  2213. int i, r;
  2214. for (;;) {
  2215. switch (ds->state) {
  2216. case ST_RD_TRANSLATION:
  2217. if (!lzx_br_read_ahead(strm, br, 1)) {
  2218. ds->state = ST_RD_TRANSLATION;
  2219. if (last)
  2220. goto failed;
  2221. return (ARCHIVE_OK);
  2222. }
  2223. ds->translation = lzx_br_bits(br, 1);
  2224. lzx_br_consume(br, 1);
  2225. /* FALL THROUGH */
  2226. case ST_RD_TRANSLATION_SIZE:
  2227. if (ds->translation) {
  2228. if (!lzx_br_read_ahead(strm, br, 32)) {
  2229. ds->state = ST_RD_TRANSLATION_SIZE;
  2230. if (last)
  2231. goto failed;
  2232. return (ARCHIVE_OK);
  2233. }
  2234. ds->translation_size = lzx_br_bits(br, 16);
  2235. lzx_br_consume(br, 16);
  2236. ds->translation_size <<= 16;
  2237. ds->translation_size |= lzx_br_bits(br, 16);
  2238. lzx_br_consume(br, 16);
  2239. }
  2240. /* FALL THROUGH */
  2241. case ST_RD_BLOCK_TYPE:
  2242. if (!lzx_br_read_ahead(strm, br, 3)) {
  2243. ds->state = ST_RD_BLOCK_TYPE;
  2244. if (last)
  2245. goto failed;
  2246. return (ARCHIVE_OK);
  2247. }
  2248. ds->block_type = lzx_br_bits(br, 3);
  2249. lzx_br_consume(br, 3);
  2250. /* Check a block type. */
  2251. switch (ds->block_type) {
  2252. case VERBATIM_BLOCK:
  2253. case ALIGNED_OFFSET_BLOCK:
  2254. case UNCOMPRESSED_BLOCK:
  2255. break;
  2256. default:
  2257. goto failed;/* Invalid */
  2258. }
  2259. /* FALL THROUGH */
  2260. case ST_RD_BLOCK_SIZE:
  2261. if (!lzx_br_read_ahead(strm, br, 24)) {
  2262. ds->state = ST_RD_BLOCK_SIZE;
  2263. if (last)
  2264. goto failed;
  2265. return (ARCHIVE_OK);
  2266. }
  2267. ds->block_size = lzx_br_bits(br, 8);
  2268. lzx_br_consume(br, 8);
  2269. ds->block_size <<= 16;
  2270. ds->block_size |= lzx_br_bits(br, 16);
  2271. lzx_br_consume(br, 16);
  2272. if (ds->block_size == 0)
  2273. goto failed;
  2274. ds->block_bytes_avail = ds->block_size;
  2275. if (ds->block_type != UNCOMPRESSED_BLOCK) {
  2276. if (ds->block_type == VERBATIM_BLOCK)
  2277. ds->state = ST_RD_VERBATIM;
  2278. else
  2279. ds->state = ST_RD_ALIGNED_OFFSET;
  2280. break;
  2281. }
  2282. /* FALL THROUGH */
  2283. case ST_RD_ALIGNMENT:
  2284. /*
  2285. * Handle an Uncompressed Block.
  2286. */
  2287. /* Skip padding to align following field on
  2288. * 16-bit boundary. */
  2289. if (lzx_br_is_unaligned(br))
  2290. lzx_br_consume_unaligned_bits(br);
  2291. else {
  2292. if (lzx_br_read_ahead(strm, br, 16))
  2293. lzx_br_consume(br, 16);
  2294. else {
  2295. ds->state = ST_RD_ALIGNMENT;
  2296. if (last)
  2297. goto failed;
  2298. return (ARCHIVE_OK);
  2299. }
  2300. }
  2301. /* Preparation to read repeated offsets R0,R1 and R2. */
  2302. ds->rbytes_avail = 0;
  2303. ds->state = ST_RD_R0;
  2304. /* FALL THROUGH */
  2305. case ST_RD_R0:
  2306. case ST_RD_R1:
  2307. case ST_RD_R2:
  2308. do {
  2309. uint16_t u16;
  2310. /* Drain bits in the cache buffer of
  2311. * bit-stream. */
  2312. if (lzx_br_has(br, 32)) {
  2313. u16 = lzx_br_bits(br, 16);
  2314. lzx_br_consume(br, 16);
  2315. archive_le16enc(ds->rbytes, u16);
  2316. u16 = lzx_br_bits(br, 16);
  2317. lzx_br_consume(br, 16);
  2318. archive_le16enc(ds->rbytes+2, u16);
  2319. ds->rbytes_avail = 4;
  2320. } else if (lzx_br_has(br, 16)) {
  2321. u16 = lzx_br_bits(br, 16);
  2322. lzx_br_consume(br, 16);
  2323. archive_le16enc(ds->rbytes, u16);
  2324. ds->rbytes_avail = 2;
  2325. }
  2326. if (ds->rbytes_avail < 4 && ds->br.have_odd) {
  2327. ds->rbytes[ds->rbytes_avail++] =
  2328. ds->br.odd;
  2329. ds->br.have_odd = 0;
  2330. }
  2331. while (ds->rbytes_avail < 4) {
  2332. if (strm->avail_in <= 0) {
  2333. if (last)
  2334. goto failed;
  2335. return (ARCHIVE_OK);
  2336. }
  2337. ds->rbytes[ds->rbytes_avail++] =
  2338. *strm->next_in++;
  2339. strm->avail_in--;
  2340. }
  2341. ds->rbytes_avail = 0;
  2342. if (ds->state == ST_RD_R0) {
  2343. ds->r0 = archive_le32dec(ds->rbytes);
  2344. if (ds->r0 < 0)
  2345. goto failed;
  2346. ds->state = ST_RD_R1;
  2347. } else if (ds->state == ST_RD_R1) {
  2348. ds->r1 = archive_le32dec(ds->rbytes);
  2349. if (ds->r1 < 0)
  2350. goto failed;
  2351. ds->state = ST_RD_R2;
  2352. } else if (ds->state == ST_RD_R2) {
  2353. ds->r2 = archive_le32dec(ds->rbytes);
  2354. if (ds->r2 < 0)
  2355. goto failed;
  2356. /* We've gotten all repeated offsets. */
  2357. ds->state = ST_COPY_UNCOMP1;
  2358. }
  2359. } while (ds->state != ST_COPY_UNCOMP1);
  2360. /* FALL THROUGH */
  2361. case ST_COPY_UNCOMP1:
  2362. /*
  2363. * Copy bytes form next_in to next_out directly.
  2364. */
  2365. while (ds->block_bytes_avail) {
  2366. int l;
  2367. if (strm->avail_out <= 0)
  2368. /* Output buffer is empty. */
  2369. return (ARCHIVE_OK);
  2370. if (strm->avail_in <= 0) {
  2371. /* Input buffer is empty. */
  2372. if (last)
  2373. goto failed;
  2374. return (ARCHIVE_OK);
  2375. }
  2376. l = (int)ds->block_bytes_avail;
  2377. if (l > ds->w_size - ds->w_pos)
  2378. l = ds->w_size - ds->w_pos;
  2379. if (l > strm->avail_out)
  2380. l = (int)strm->avail_out;
  2381. if (l > strm->avail_in)
  2382. l = (int)strm->avail_in;
  2383. memcpy(strm->next_out, strm->next_in, l);
  2384. memcpy(&(ds->w_buff[ds->w_pos]),
  2385. strm->next_in, l);
  2386. strm->next_in += l;
  2387. strm->avail_in -= l;
  2388. strm->next_out += l;
  2389. strm->avail_out -= l;
  2390. strm->total_out += l;
  2391. ds->w_pos = (ds->w_pos + l) & ds->w_mask;
  2392. ds->block_bytes_avail -= l;
  2393. }
  2394. /* FALL THROUGH */
  2395. case ST_COPY_UNCOMP2:
  2396. /* Re-align; skip padding byte. */
  2397. if (ds->block_size & 1) {
  2398. if (strm->avail_in <= 0) {
  2399. /* Input buffer is empty. */
  2400. ds->state = ST_COPY_UNCOMP2;
  2401. if (last)
  2402. goto failed;
  2403. return (ARCHIVE_OK);
  2404. }
  2405. strm->next_in++;
  2406. strm->avail_in --;
  2407. }
  2408. /* This block ended. */
  2409. ds->state = ST_RD_BLOCK_TYPE;
  2410. return (ARCHIVE_EOF);
  2411. /********************/
  2412. case ST_RD_ALIGNED_OFFSET:
  2413. /*
  2414. * Read Aligned offset tree.
  2415. */
  2416. if (!lzx_br_read_ahead(strm, br, 3 * ds->at.len_size)) {
  2417. ds->state = ST_RD_ALIGNED_OFFSET;
  2418. if (last)
  2419. goto failed;
  2420. return (ARCHIVE_OK);
  2421. }
  2422. memset(ds->at.freq, 0, sizeof(ds->at.freq));
  2423. for (i = 0; i < ds->at.len_size; i++) {
  2424. ds->at.bitlen[i] = lzx_br_bits(br, 3);
  2425. ds->at.freq[ds->at.bitlen[i]]++;
  2426. lzx_br_consume(br, 3);
  2427. }
  2428. if (!lzx_make_huffman_table(&ds->at))
  2429. goto failed;
  2430. /* FALL THROUGH */
  2431. case ST_RD_VERBATIM:
  2432. ds->loop = 0;
  2433. /* FALL THROUGH */
  2434. case ST_RD_PRE_MAIN_TREE_256:
  2435. /*
  2436. * Read Pre-tree for first 256 elements of main tree.
  2437. */
  2438. if (!lzx_read_pre_tree(strm)) {
  2439. ds->state = ST_RD_PRE_MAIN_TREE_256;
  2440. if (last)
  2441. goto failed;
  2442. return (ARCHIVE_OK);
  2443. }
  2444. if (!lzx_make_huffman_table(&ds->pt))
  2445. goto failed;
  2446. ds->loop = 0;
  2447. /* FALL THROUGH */
  2448. case ST_MAIN_TREE_256:
  2449. /*
  2450. * Get path lengths of first 256 elements of main tree.
  2451. */
  2452. r = lzx_read_bitlen(strm, &ds->mt, 256);
  2453. if (r < 0)
  2454. goto failed;
  2455. else if (!r) {
  2456. ds->state = ST_MAIN_TREE_256;
  2457. if (last)
  2458. goto failed;
  2459. return (ARCHIVE_OK);
  2460. }
  2461. ds->loop = 0;
  2462. /* FALL THROUGH */
  2463. case ST_RD_PRE_MAIN_TREE_REM:
  2464. /*
  2465. * Read Pre-tree for remaining elements of main tree.
  2466. */
  2467. if (!lzx_read_pre_tree(strm)) {
  2468. ds->state = ST_RD_PRE_MAIN_TREE_REM;
  2469. if (last)
  2470. goto failed;
  2471. return (ARCHIVE_OK);
  2472. }
  2473. if (!lzx_make_huffman_table(&ds->pt))
  2474. goto failed;
  2475. ds->loop = 256;
  2476. /* FALL THROUGH */
  2477. case ST_MAIN_TREE_REM:
  2478. /*
  2479. * Get path lengths of remaining elements of main tree.
  2480. */
  2481. r = lzx_read_bitlen(strm, &ds->mt, -1);
  2482. if (r < 0)
  2483. goto failed;
  2484. else if (!r) {
  2485. ds->state = ST_MAIN_TREE_REM;
  2486. if (last)
  2487. goto failed;
  2488. return (ARCHIVE_OK);
  2489. }
  2490. if (!lzx_make_huffman_table(&ds->mt))
  2491. goto failed;
  2492. ds->loop = 0;
  2493. /* FALL THROUGH */
  2494. case ST_RD_PRE_LENGTH_TREE:
  2495. /*
  2496. * Read Pre-tree for remaining elements of main tree.
  2497. */
  2498. if (!lzx_read_pre_tree(strm)) {
  2499. ds->state = ST_RD_PRE_LENGTH_TREE;
  2500. if (last)
  2501. goto failed;
  2502. return (ARCHIVE_OK);
  2503. }
  2504. if (!lzx_make_huffman_table(&ds->pt))
  2505. goto failed;
  2506. ds->loop = 0;
  2507. /* FALL THROUGH */
  2508. case ST_LENGTH_TREE:
  2509. /*
  2510. * Get path lengths of remaining elements of main tree.
  2511. */
  2512. r = lzx_read_bitlen(strm, &ds->lt, -1);
  2513. if (r < 0)
  2514. goto failed;
  2515. else if (!r) {
  2516. ds->state = ST_LENGTH_TREE;
  2517. if (last)
  2518. goto failed;
  2519. return (ARCHIVE_OK);
  2520. }
  2521. if (!lzx_make_huffman_table(&ds->lt))
  2522. goto failed;
  2523. ds->state = ST_MAIN;
  2524. return (100);
  2525. }
  2526. }
  2527. failed:
  2528. return (ds->error = ARCHIVE_FAILED);
  2529. }
  2530. static int
  2531. lzx_decode_blocks(struct lzx_stream *strm, int last)
  2532. {
  2533. struct lzx_dec *ds = strm->ds;
  2534. struct lzx_br bre = ds->br;
  2535. struct huffman *at = &(ds->at), *lt = &(ds->lt), *mt = &(ds->mt);
  2536. const struct lzx_pos_tbl *pos_tbl = ds->pos_tbl;
  2537. unsigned char *noutp = strm->next_out;
  2538. unsigned char *endp = noutp + strm->avail_out;
  2539. unsigned char *w_buff = ds->w_buff;
  2540. unsigned char *at_bitlen = at->bitlen;
  2541. unsigned char *lt_bitlen = lt->bitlen;
  2542. unsigned char *mt_bitlen = mt->bitlen;
  2543. size_t block_bytes_avail = ds->block_bytes_avail;
  2544. int at_max_bits = at->max_bits;
  2545. int lt_max_bits = lt->max_bits;
  2546. int mt_max_bits = mt->max_bits;
  2547. int c, copy_len = ds->copy_len, copy_pos = ds->copy_pos;
  2548. int w_pos = ds->w_pos, w_mask = ds->w_mask, w_size = ds->w_size;
  2549. int length_header = ds->length_header;
  2550. int offset_bits = ds->offset_bits;
  2551. int position_slot = ds->position_slot;
  2552. int r0 = ds->r0, r1 = ds->r1, r2 = ds->r2;
  2553. int state = ds->state;
  2554. char block_type = ds->block_type;
  2555. for (;;) {
  2556. switch (state) {
  2557. case ST_MAIN:
  2558. for (;;) {
  2559. if (block_bytes_avail == 0) {
  2560. /* This block ended. */
  2561. ds->state = ST_RD_BLOCK_TYPE;
  2562. ds->br = bre;
  2563. ds->block_bytes_avail =
  2564. block_bytes_avail;
  2565. ds->copy_len = copy_len;
  2566. ds->copy_pos = copy_pos;
  2567. ds->length_header = length_header;
  2568. ds->position_slot = position_slot;
  2569. ds->r0 = r0; ds->r1 = r1; ds->r2 = r2;
  2570. ds->w_pos = w_pos;
  2571. strm->avail_out = endp - noutp;
  2572. return (ARCHIVE_EOF);
  2573. }
  2574. if (noutp >= endp)
  2575. /* Output buffer is empty. */
  2576. goto next_data;
  2577. if (!lzx_br_read_ahead(strm, &bre,
  2578. mt_max_bits)) {
  2579. if (!last)
  2580. goto next_data;
  2581. /* Remaining bits are less than
  2582. * maximum bits(mt.max_bits) but maybe
  2583. * it still remains as much as we need,
  2584. * so we should try to use it with
  2585. * dummy bits. */
  2586. c = lzx_decode_huffman(mt,
  2587. lzx_br_bits_forced(
  2588. &bre, mt_max_bits));
  2589. lzx_br_consume(&bre, mt_bitlen[c]);
  2590. if (!lzx_br_has(&bre, 0))
  2591. goto failed;/* Over read. */
  2592. } else {
  2593. c = lzx_decode_huffman(mt,
  2594. lzx_br_bits(&bre, mt_max_bits));
  2595. lzx_br_consume(&bre, mt_bitlen[c]);
  2596. }
  2597. if (c > UCHAR_MAX)
  2598. break;
  2599. /*
  2600. * 'c' is exactly literal code.
  2601. */
  2602. /* Save a decoded code to reference it
  2603. * afterward. */
  2604. w_buff[w_pos] = c;
  2605. w_pos = (w_pos + 1) & w_mask;
  2606. /* Store the decoded code to output buffer. */
  2607. *noutp++ = c;
  2608. block_bytes_avail--;
  2609. }
  2610. /*
  2611. * Get a match code, its length and offset.
  2612. */
  2613. c -= UCHAR_MAX + 1;
  2614. length_header = c & 7;
  2615. position_slot = c >> 3;
  2616. /* FALL THROUGH */
  2617. case ST_LENGTH:
  2618. /*
  2619. * Get a length.
  2620. */
  2621. if (length_header == 7) {
  2622. if (!lzx_br_read_ahead(strm, &bre,
  2623. lt_max_bits)) {
  2624. if (!last) {
  2625. state = ST_LENGTH;
  2626. goto next_data;
  2627. }
  2628. c = lzx_decode_huffman(lt,
  2629. lzx_br_bits_forced(
  2630. &bre, lt_max_bits));
  2631. lzx_br_consume(&bre, lt_bitlen[c]);
  2632. if (!lzx_br_has(&bre, 0))
  2633. goto failed;/* Over read. */
  2634. } else {
  2635. c = lzx_decode_huffman(lt,
  2636. lzx_br_bits(&bre, lt_max_bits));
  2637. lzx_br_consume(&bre, lt_bitlen[c]);
  2638. }
  2639. copy_len = c + 7 + 2;
  2640. } else
  2641. copy_len = length_header + 2;
  2642. if ((size_t)copy_len > block_bytes_avail)
  2643. goto failed;
  2644. /*
  2645. * Get an offset.
  2646. */
  2647. switch (position_slot) {
  2648. case 0: /* Use repeated offset 0. */
  2649. copy_pos = r0;
  2650. state = ST_REAL_POS;
  2651. continue;
  2652. case 1: /* Use repeated offset 1. */
  2653. copy_pos = r1;
  2654. /* Swap repeated offset. */
  2655. r1 = r0;
  2656. r0 = copy_pos;
  2657. state = ST_REAL_POS;
  2658. continue;
  2659. case 2: /* Use repeated offset 2. */
  2660. copy_pos = r2;
  2661. /* Swap repeated offset. */
  2662. r2 = r0;
  2663. r0 = copy_pos;
  2664. state = ST_REAL_POS;
  2665. continue;
  2666. default:
  2667. offset_bits =
  2668. pos_tbl[position_slot].footer_bits;
  2669. break;
  2670. }
  2671. /* FALL THROUGH */
  2672. case ST_OFFSET:
  2673. /*
  2674. * Get the offset, which is a distance from
  2675. * current window position.
  2676. */
  2677. if (block_type == ALIGNED_OFFSET_BLOCK &&
  2678. offset_bits >= 3) {
  2679. int offbits = offset_bits - 3;
  2680. if (!lzx_br_read_ahead(strm, &bre, offbits)) {
  2681. state = ST_OFFSET;
  2682. if (last)
  2683. goto failed;
  2684. goto next_data;
  2685. }
  2686. copy_pos = lzx_br_bits(&bre, offbits) << 3;
  2687. /* Get an aligned number. */
  2688. if (!lzx_br_read_ahead(strm, &bre,
  2689. offbits + at_max_bits)) {
  2690. if (!last) {
  2691. state = ST_OFFSET;
  2692. goto next_data;
  2693. }
  2694. lzx_br_consume(&bre, offbits);
  2695. c = lzx_decode_huffman(at,
  2696. lzx_br_bits_forced(&bre,
  2697. at_max_bits));
  2698. lzx_br_consume(&bre, at_bitlen[c]);
  2699. if (!lzx_br_has(&bre, 0))
  2700. goto failed;/* Over read. */
  2701. } else {
  2702. lzx_br_consume(&bre, offbits);
  2703. c = lzx_decode_huffman(at,
  2704. lzx_br_bits(&bre, at_max_bits));
  2705. lzx_br_consume(&bre, at_bitlen[c]);
  2706. }
  2707. /* Add an aligned number. */
  2708. copy_pos += c;
  2709. } else {
  2710. if (!lzx_br_read_ahead(strm, &bre,
  2711. offset_bits)) {
  2712. state = ST_OFFSET;
  2713. if (last)
  2714. goto failed;
  2715. goto next_data;
  2716. }
  2717. copy_pos = lzx_br_bits(&bre, offset_bits);
  2718. lzx_br_consume(&bre, offset_bits);
  2719. }
  2720. copy_pos += pos_tbl[position_slot].base -2;
  2721. /* Update repeated offset LRU queue. */
  2722. r2 = r1;
  2723. r1 = r0;
  2724. r0 = copy_pos;
  2725. /* FALL THROUGH */
  2726. case ST_REAL_POS:
  2727. /*
  2728. * Compute a real position in window.
  2729. */
  2730. copy_pos = (w_pos - copy_pos) & w_mask;
  2731. /* FALL THROUGH */
  2732. case ST_COPY:
  2733. /*
  2734. * Copy several bytes as extracted data from the window
  2735. * into the output buffer.
  2736. */
  2737. for (;;) {
  2738. const unsigned char *s;
  2739. int l;
  2740. l = copy_len;
  2741. if (copy_pos > w_pos) {
  2742. if (l > w_size - copy_pos)
  2743. l = w_size - copy_pos;
  2744. } else {
  2745. if (l > w_size - w_pos)
  2746. l = w_size - w_pos;
  2747. }
  2748. if (noutp + l >= endp)
  2749. l = (int)(endp - noutp);
  2750. s = w_buff + copy_pos;
  2751. if (l >= 8 && ((copy_pos + l < w_pos)
  2752. || (w_pos + l < copy_pos))) {
  2753. memcpy(w_buff + w_pos, s, l);
  2754. memcpy(noutp, s, l);
  2755. } else {
  2756. unsigned char *d;
  2757. int li;
  2758. d = w_buff + w_pos;
  2759. for (li = 0; li < l; li++)
  2760. noutp[li] = d[li] = s[li];
  2761. }
  2762. noutp += l;
  2763. copy_pos = (copy_pos + l) & w_mask;
  2764. w_pos = (w_pos + l) & w_mask;
  2765. block_bytes_avail -= l;
  2766. if (copy_len <= l)
  2767. /* A copy of current pattern ended. */
  2768. break;
  2769. copy_len -= l;
  2770. if (noutp >= endp) {
  2771. /* Output buffer is empty. */
  2772. state = ST_COPY;
  2773. goto next_data;
  2774. }
  2775. }
  2776. state = ST_MAIN;
  2777. break;
  2778. }
  2779. }
  2780. failed:
  2781. return (ds->error = ARCHIVE_FAILED);
  2782. next_data:
  2783. ds->br = bre;
  2784. ds->block_bytes_avail = block_bytes_avail;
  2785. ds->copy_len = copy_len;
  2786. ds->copy_pos = copy_pos;
  2787. ds->length_header = length_header;
  2788. ds->offset_bits = offset_bits;
  2789. ds->position_slot = position_slot;
  2790. ds->r0 = r0; ds->r1 = r1; ds->r2 = r2;
  2791. ds->state = state;
  2792. ds->w_pos = w_pos;
  2793. strm->avail_out = endp - noutp;
  2794. return (ARCHIVE_OK);
  2795. }
  2796. static int
  2797. lzx_read_pre_tree(struct lzx_stream *strm)
  2798. {
  2799. struct lzx_dec *ds = strm->ds;
  2800. struct lzx_br *br = &(ds->br);
  2801. int i;
  2802. if (ds->loop == 0)
  2803. memset(ds->pt.freq, 0, sizeof(ds->pt.freq));
  2804. for (i = ds->loop; i < ds->pt.len_size; i++) {
  2805. if (!lzx_br_read_ahead(strm, br, 4)) {
  2806. ds->loop = i;
  2807. return (0);
  2808. }
  2809. ds->pt.bitlen[i] = lzx_br_bits(br, 4);
  2810. ds->pt.freq[ds->pt.bitlen[i]]++;
  2811. lzx_br_consume(br, 4);
  2812. }
  2813. ds->loop = i;
  2814. return (1);
  2815. }
  2816. /*
  2817. * Read a bunch of bit-lengths from pre-tree.
  2818. */
  2819. static int
  2820. lzx_read_bitlen(struct lzx_stream *strm, struct huffman *d, int end)
  2821. {
  2822. struct lzx_dec *ds = strm->ds;
  2823. struct lzx_br *br = &(ds->br);
  2824. int c, i, j, ret, same;
  2825. unsigned rbits;
  2826. i = ds->loop;
  2827. if (i == 0)
  2828. memset(d->freq, 0, sizeof(d->freq));
  2829. ret = 0;
  2830. if (end < 0)
  2831. end = d->len_size;
  2832. while (i < end) {
  2833. ds->loop = i;
  2834. if (!lzx_br_read_ahead(strm, br, ds->pt.max_bits))
  2835. goto getdata;
  2836. rbits = lzx_br_bits(br, ds->pt.max_bits);
  2837. c = lzx_decode_huffman(&(ds->pt), rbits);
  2838. switch (c) {
  2839. case 17:/* several zero lengths, from 4 to 19. */
  2840. if (!lzx_br_read_ahead(strm, br, ds->pt.bitlen[c]+4))
  2841. goto getdata;
  2842. lzx_br_consume(br, ds->pt.bitlen[c]);
  2843. same = lzx_br_bits(br, 4) + 4;
  2844. if (i + same > end)
  2845. return (-1);/* Invalid */
  2846. lzx_br_consume(br, 4);
  2847. for (j = 0; j < same; j++)
  2848. d->bitlen[i++] = 0;
  2849. break;
  2850. case 18:/* many zero lengths, from 20 to 51. */
  2851. if (!lzx_br_read_ahead(strm, br, ds->pt.bitlen[c]+5))
  2852. goto getdata;
  2853. lzx_br_consume(br, ds->pt.bitlen[c]);
  2854. same = lzx_br_bits(br, 5) + 20;
  2855. if (i + same > end)
  2856. return (-1);/* Invalid */
  2857. lzx_br_consume(br, 5);
  2858. memset(d->bitlen + i, 0, same);
  2859. i += same;
  2860. break;
  2861. case 19:/* a few same lengths. */
  2862. if (!lzx_br_read_ahead(strm, br,
  2863. ds->pt.bitlen[c]+1+ds->pt.max_bits))
  2864. goto getdata;
  2865. lzx_br_consume(br, ds->pt.bitlen[c]);
  2866. same = lzx_br_bits(br, 1) + 4;
  2867. if (i + same > end)
  2868. return (-1);
  2869. lzx_br_consume(br, 1);
  2870. rbits = lzx_br_bits(br, ds->pt.max_bits);
  2871. c = lzx_decode_huffman(&(ds->pt), rbits);
  2872. lzx_br_consume(br, ds->pt.bitlen[c]);
  2873. c = (d->bitlen[i] - c + 17) % 17;
  2874. if (c < 0)
  2875. return (-1);/* Invalid */
  2876. for (j = 0; j < same; j++)
  2877. d->bitlen[i++] = c;
  2878. d->freq[c] += same;
  2879. break;
  2880. default:
  2881. lzx_br_consume(br, ds->pt.bitlen[c]);
  2882. c = (d->bitlen[i] - c + 17) % 17;
  2883. if (c < 0)
  2884. return (-1);/* Invalid */
  2885. d->freq[c]++;
  2886. d->bitlen[i++] = c;
  2887. break;
  2888. }
  2889. }
  2890. ret = 1;
  2891. getdata:
  2892. ds->loop = i;
  2893. return (ret);
  2894. }
  2895. static int
  2896. lzx_huffman_init(struct huffman *hf, size_t len_size, int tbl_bits)
  2897. {
  2898. if (hf->bitlen == NULL || hf->len_size != (int)len_size) {
  2899. free(hf->bitlen);
  2900. hf->bitlen = calloc(len_size, sizeof(hf->bitlen[0]));
  2901. if (hf->bitlen == NULL)
  2902. return (ARCHIVE_FATAL);
  2903. hf->len_size = (int)len_size;
  2904. } else
  2905. memset(hf->bitlen, 0, len_size * sizeof(hf->bitlen[0]));
  2906. if (hf->tbl == NULL) {
  2907. hf->tbl = malloc(((size_t)1 << tbl_bits) * sizeof(hf->tbl[0]));
  2908. if (hf->tbl == NULL)
  2909. return (ARCHIVE_FATAL);
  2910. hf->tbl_bits = tbl_bits;
  2911. }
  2912. return (ARCHIVE_OK);
  2913. }
  2914. static void
  2915. lzx_huffman_free(struct huffman *hf)
  2916. {
  2917. free(hf->bitlen);
  2918. free(hf->tbl);
  2919. }
  2920. /*
  2921. * Make a huffman coding table.
  2922. */
  2923. static int
  2924. lzx_make_huffman_table(struct huffman *hf)
  2925. {
  2926. uint16_t *tbl;
  2927. const unsigned char *bitlen;
  2928. int bitptn[17], weight[17];
  2929. int i, maxbits = 0, ptn, tbl_size, w;
  2930. int len_avail;
  2931. /*
  2932. * Initialize bit patterns.
  2933. */
  2934. ptn = 0;
  2935. for (i = 1, w = 1 << 15; i <= 16; i++, w >>= 1) {
  2936. bitptn[i] = ptn;
  2937. weight[i] = w;
  2938. if (hf->freq[i]) {
  2939. ptn += hf->freq[i] * w;
  2940. maxbits = i;
  2941. }
  2942. }
  2943. if ((ptn & 0xffff) != 0 || maxbits > hf->tbl_bits)
  2944. return (0);/* Invalid */
  2945. hf->max_bits = maxbits;
  2946. /*
  2947. * Cut out extra bits which we won't house in the table.
  2948. * This preparation reduces the same calculation in the for-loop
  2949. * making the table.
  2950. */
  2951. if (maxbits < 16) {
  2952. int ebits = 16 - maxbits;
  2953. for (i = 1; i <= maxbits; i++) {
  2954. bitptn[i] >>= ebits;
  2955. weight[i] >>= ebits;
  2956. }
  2957. }
  2958. /*
  2959. * Make the table.
  2960. */
  2961. tbl_size = 1 << hf->tbl_bits;
  2962. tbl = hf->tbl;
  2963. bitlen = hf->bitlen;
  2964. len_avail = hf->len_size;
  2965. hf->tree_used = 0;
  2966. for (i = 0; i < len_avail; i++) {
  2967. uint16_t *p;
  2968. int len, cnt;
  2969. if (bitlen[i] == 0)
  2970. continue;
  2971. /* Get a bit pattern */
  2972. len = bitlen[i];
  2973. if (len > tbl_size)
  2974. return (0);
  2975. ptn = bitptn[len];
  2976. cnt = weight[len];
  2977. /* Calculate next bit pattern */
  2978. if ((bitptn[len] = ptn + cnt) > tbl_size)
  2979. return (0);/* Invalid */
  2980. /* Update the table */
  2981. p = &(tbl[ptn]);
  2982. while (--cnt >= 0)
  2983. p[cnt] = (uint16_t)i;
  2984. }
  2985. return (1);
  2986. }
  2987. static inline int
  2988. lzx_decode_huffman(struct huffman *hf, unsigned rbits)
  2989. {
  2990. int c;
  2991. c = hf->tbl[rbits];
  2992. if (c < hf->len_size)
  2993. return (c);
  2994. return (0);
  2995. }