2 * Copyright (c) Ian F. Darwin 1986-1995.
3 * Software written by Ian F. Darwin and others;
4 * maintained 1995-present by Christos Zoulas and others.
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
9 * 1. Redistributions of source code must retain the above copyright
10 * notice immediately at the beginning of the file, without modification,
11 * this list of conditions, and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
16 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR
20 * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29 * softmagic - interpret variable magic from MAGIC
42 FILE_RCSID("@(#)$Id: softmagic.c,v 1.87 2006/12/11 21:48:49 christos Exp $")
45 private int match(struct magic_set
*, struct magic
*, uint32_t,
46 const unsigned char *, size_t);
47 private int mget(struct magic_set
*, union VALUETYPE
*, const unsigned char *,
48 struct magic
*, size_t, unsigned int);
49 private int magiccheck(struct magic_set
*, union VALUETYPE
*, struct magic
*);
50 private int32_t mprint(struct magic_set
*, union VALUETYPE
*, struct magic
*);
51 private void mdebug(uint32_t, const char *, size_t);
52 private int mcopy(struct magic_set
*, union VALUETYPE
*, int, int,
53 const unsigned char *, uint32_t, size_t);
54 private int mconvert(struct magic_set
*, union VALUETYPE
*, struct magic
*);
55 private int check_mem(struct magic_set
*, unsigned int);
56 private int print_sep(struct magic_set
*, int);
57 private void cvt_8(union VALUETYPE
*, const struct magic
*);
58 private void cvt_16(union VALUETYPE
*, const struct magic
*);
59 private void cvt_32(union VALUETYPE
*, const struct magic
*);
60 private void cvt_64(union VALUETYPE
*, const struct magic
*);
63 * softmagic - lookup one file in parsed, in-memory copy of database
64 * Passed the name and FILE * of one file to be typed.
66 /*ARGSUSED1*/ /* nbytes passed for regularity, maybe need later */
68 file_softmagic(struct magic_set
*ms
, const unsigned char *buf
, size_t nbytes
)
72 for (ml
= ms
->mlist
->next
; ml
!= ms
->mlist
; ml
= ml
->next
)
73 if ((rv
= match(ms
, ml
->magic
, ml
->nmagic
, buf
, nbytes
)) != 0)
80 * Go through the whole list, stopping if you find a match. Process all
81 * the continuations of that match before returning.
83 * We support multi-level continuations:
85 * At any time when processing a successful top-level match, there is a
86 * current continuation level; it represents the level of the last
87 * successfully matched continuation.
89 * Continuations above that level are skipped as, if we see one, it
90 * means that the continuation that controls them - i.e, the
91 * lower-level continuation preceding them - failed to match.
93 * Continuations below that level are processed as, if we see one,
94 * it means we've finished processing or skipping higher-level
95 * continuations under the control of a successful or unsuccessful
96 * lower-level continuation, and are now seeing the next lower-level
97 * continuation and should process it. The current continuation
98 * level reverts to the level of the one we're seeing.
100 * Continuations at the current level are processed as, if we see
101 * one, there's no lower-level continuation that may have failed.
103 * If a continuation matches, we bump the current continuation level
104 * so that higher-level continuations are processed.
107 match(struct magic_set
*ms
, struct magic
*magic
, uint32_t nmagic
,
108 const unsigned char *s
, size_t nbytes
)
110 uint32_t magindex
= 0;
111 unsigned int cont_level
= 0;
112 int need_separator
= 0;
115 int returnval
= 0; /* if a match is found it is set to 1*/
116 int firstline
= 1; /* a flag to print X\n X\n- X */
117 int printed_something
= 0;
119 if (check_mem(ms
, cont_level
) == -1)
122 for (magindex
= 0; magindex
< nmagic
; magindex
++) {
123 /* if main entry matches, print it... */
124 ms
->offset
= magic
[magindex
].offset
;
125 int flush
= !mget(ms
, &p
, s
, &magic
[magindex
], nbytes
,
128 if (magic
[magindex
].reln
== '!')
131 switch (magiccheck(ms
, &p
, &magic
[magindex
])) {
143 * main entry didn't match,
144 * flush its continuations
146 while (magindex
< nmagic
- 1 &&
147 magic
[magindex
+ 1].cont_level
!= 0)
153 * If we are going to print something, we'll need to print
154 * a blank before we print something else.
156 if (magic
[magindex
].desc
[0]) {
158 printed_something
= 1;
159 if (print_sep(ms
, firstline
) == -1)
163 if ((ms
->c
.off
[cont_level
] = mprint(ms
, &p
, &magic
[magindex
]))
167 /* and any continuations that match */
168 if (check_mem(ms
, ++cont_level
) == -1)
171 while (magic
[magindex
+1].cont_level
!= 0 &&
172 ++magindex
< nmagic
) {
173 if (cont_level
< magic
[magindex
].cont_level
)
175 if (cont_level
> magic
[magindex
].cont_level
) {
177 * We're at the end of the level
178 * "cont_level" continuations.
180 cont_level
= magic
[magindex
].cont_level
;
182 ms
->offset
= magic
[magindex
].offset
;
183 if (magic
[magindex
].flag
& OFFADD
) {
185 ms
->c
.off
[cont_level
- 1];
188 flush
= !mget(ms
, &p
, s
, &magic
[magindex
], nbytes
,
190 if (flush
&& magic
[magindex
].reln
!= '!')
193 switch (flush
? 1 : magiccheck(ms
, &p
, &magic
[magindex
])) {
200 * If we are going to print something,
201 * make sure that we have a separator first.
203 if (magic
[magindex
].desc
[0]) {
204 printed_something
= 1;
205 if (print_sep(ms
, firstline
) == -1)
209 * This continuation matched.
210 * Print its message, with
211 * a blank before it if
212 * the previous item printed
213 * and this item isn't empty.
215 /* space if previous printed */
217 && (magic
[magindex
].nospflag
== 0)
218 && (magic
[magindex
].desc
[0] != '\0')) {
219 if (file_printf(ms
, " ") == -1)
223 if ((ms
->c
.off
[cont_level
] = mprint(ms
, &p
,
224 &magic
[magindex
])) == -1)
226 if (magic
[magindex
].desc
[0])
230 * If we see any continuations
234 if (check_mem(ms
, ++cont_level
) == -1)
239 if (printed_something
)
241 if ((ms
->flags
& MAGIC_CONTINUE
) == 0 && printed_something
) {
242 return 1; /* don't keep searching */
245 return returnval
; /* This is hit if -k is set or there is no match */
249 check_mem(struct magic_set
*ms
, unsigned int level
)
253 if (level
< ms
->c
.len
)
256 len
= (ms
->c
.len
+= 20) * sizeof(*ms
->c
.off
);
257 ms
->c
.off
= (ms
->c
.off
== NULL
) ? malloc(len
) : realloc(ms
->c
.off
, len
);
258 if (ms
->c
.off
!= NULL
)
265 check_fmt(struct magic_set
*ms
, struct magic
*m
)
270 if (strchr(m
->desc
, '%') == NULL
)
273 rc
= regcomp(&rx
, "%[-0-9\\.]*s", REG_EXTENDED
|REG_NOSUB
);
276 regerror(rc
, &rx
, errmsg
, sizeof(errmsg
));
277 file_error(ms
, 0, "regex error %d, (%s)", rc
, errmsg
);
280 rc
= regexec(&rx
, m
->desc
, 0, 0, 0);
287 mprint(struct magic_set
*ms
, union VALUETYPE
*p
, struct magic
*m
)
296 v
= file_signextend(ms
, m
, (uint64_t)p
->b
);
297 switch (check_fmt(ms
, m
)) {
301 if (snprintf(buf
, sizeof(buf
), "%c",
302 (unsigned char)v
) < 0)
304 if (file_printf(ms
, m
->desc
, buf
) == -1)
308 if (file_printf(ms
, m
->desc
, (unsigned char) v
) == -1)
312 t
= ms
->offset
+ sizeof(char);
318 v
= file_signextend(ms
, m
, (uint64_t)p
->h
);
319 switch (check_fmt(ms
, m
)) {
323 if (snprintf(buf
, sizeof(buf
), "%hu",
324 (unsigned short)v
) < 0)
326 if (file_printf(ms
, m
->desc
, buf
) == -1)
330 if (file_printf(ms
, m
->desc
, (unsigned short) v
) == -1)
334 t
= ms
->offset
+ sizeof(short);
341 v
= file_signextend(ms
, m
, (uint64_t)p
->l
);
342 switch (check_fmt(ms
, m
)) {
346 if (snprintf(buf
, sizeof(buf
), "%u", (uint32_t)v
) < 0)
348 if (file_printf(ms
, m
->desc
, buf
) == -1)
352 if (file_printf(ms
, m
->desc
, (uint32_t) v
) == -1)
356 t
= ms
->offset
+ sizeof(int32_t);
362 v
= file_signextend(ms
, m
, p
->q
);
363 if (file_printf(ms
, m
->desc
, (uint64_t) v
) == -1)
365 t
= ms
->offset
+ sizeof(int64_t);
369 case FILE_BESTRING16
:
370 case FILE_LESTRING16
:
371 if (m
->reln
== '=' || m
->reln
== '!') {
372 if (file_printf(ms
, m
->desc
, m
->value
.s
) == -1)
374 t
= ms
->offset
+ m
->vallen
;
377 if (*m
->value
.s
== '\0') {
378 char *cp
= strchr(p
->s
,'\n');
382 if (file_printf(ms
, m
->desc
, p
->s
) == -1)
384 t
= ms
->offset
+ strlen(p
->s
);
392 if (file_printf(ms
, m
->desc
, file_fmttime(p
->l
, 1)) == -1)
394 t
= ms
->offset
+ sizeof(time_t);
401 if (file_printf(ms
, m
->desc
, file_fmttime(p
->l
, 0)) == -1)
403 t
= ms
->offset
+ sizeof(time_t);
409 if (file_printf(ms
, m
->desc
, file_fmttime((uint32_t)p
->q
, 1))
412 t
= ms
->offset
+ sizeof(uint64_t);
418 if (file_printf(ms
, m
->desc
, file_fmttime((uint32_t)p
->q
, 0))
421 t
= ms
->offset
+ sizeof(uint64_t);
425 if (file_printf(ms
, m
->desc
, p
->s
) == -1)
427 t
= ms
->offset
+ strlen(p
->s
);
431 if (file_printf(ms
, m
->desc
, m
->value
.s
) == -1)
433 t
= ms
->offset
+ m
->vallen
;
437 file_error(ms
, 0, "invalid m->type (%d) in mprint()", m
->type
);
444 #define DO_CVT(fld, cast) \
446 switch (m->mask_op & 0x7F) { \
448 p->fld &= cast m->mask; \
451 p->fld |= cast m->mask; \
454 p->fld ^= cast m->mask; \
457 p->fld += cast m->mask; \
460 p->fld -= cast m->mask; \
462 case FILE_OPMULTIPLY: \
463 p->fld *= cast m->mask; \
465 case FILE_OPDIVIDE: \
466 p->fld /= cast m->mask; \
468 case FILE_OPMODULO: \
469 p->fld %= cast m->mask; \
472 if (m->mask_op & FILE_OPINVERSE) \
476 cvt_8(union VALUETYPE
*p
, const struct magic
*m
)
478 DO_CVT(b
, (uint8_t));
482 cvt_16(union VALUETYPE
*p
, const struct magic
*m
)
484 DO_CVT(h
, (uint16_t));
488 cvt_32(union VALUETYPE
*p
, const struct magic
*m
)
490 DO_CVT(l
, (uint32_t));
494 cvt_64(union VALUETYPE
*p
, const struct magic
*m
)
496 DO_CVT(q
, (uint64_t));
500 * Convert the byte order of the data we are looking at
501 * While we're here, let's apply the mask operation
502 * (unless you have a better idea)
505 mconvert(struct magic_set
*ms
, union VALUETYPE
*p
, struct magic
*m
)
525 case FILE_BESTRING16
:
526 case FILE_LESTRING16
:
530 /* Null terminate and eat *trailing* return */
531 p
->s
[sizeof(p
->s
) - 1] = '\0';
533 if (len
-- && p
->s
[len
] == '\n')
539 char *ptr1
= p
->s
, *ptr2
= ptr1
+ 1;
541 if (len
>= sizeof(p
->s
))
542 len
= sizeof(p
->s
) - 1;
547 if (len
-- && p
->s
[len
] == '\n')
552 p
->h
= (short)((p
->hs
[0]<<8)|(p
->hs
[1]));
559 ((p
->hl
[0]<<24)|(p
->hl
[1]<<16)|(p
->hl
[2]<<8)|(p
->hl
[3]));
566 (((int64_t)p
->hq
[0]<<56)|((int64_t)p
->hq
[1]<<48)|
567 ((int64_t)p
->hq
[2]<<40)|((int64_t)p
->hq
[3]<<32)|
568 (p
->hq
[4]<<24)|(p
->hq
[5]<<16)|(p
->hq
[6]<<8)|(p
->hq
[7]));
572 p
->h
= (short)((p
->hs
[1]<<8)|(p
->hs
[0]));
579 ((p
->hl
[3]<<24)|(p
->hl
[2]<<16)|(p
->hl
[1]<<8)|(p
->hl
[0]));
586 (((int64_t)p
->hq
[7]<<56)|((int64_t)p
->hq
[6]<<48)|
587 ((int64_t)p
->hq
[5]<<40)|((int64_t)p
->hq
[4]<<32)|
588 (p
->hq
[3]<<24)|(p
->hq
[2]<<16)|(p
->hq
[1]<<8)|(p
->hq
[0]));
595 ((p
->hl
[1]<<24)|(p
->hl
[0]<<16)|(p
->hl
[3]<<8)|(p
->hl
[2]));
602 file_error(ms
, 0, "invalid type %d in mconvert()", m
->type
);
609 mdebug(uint32_t offset
, const char *str
, size_t len
)
611 (void) fprintf(stderr
, "mget @%d: ", offset
);
612 file_showstr(stderr
, str
, len
);
613 (void) fputc('\n', stderr
);
614 (void) fputc('\n', stderr
);
618 mcopy(struct magic_set
*ms
, union VALUETYPE
*p
, int type
, int indir
,
619 const unsigned char *s
, uint32_t offset
, size_t nbytes
)
621 if (type
== FILE_REGEX
&& indir
== 0) {
623 * offset is interpreted as last line to search,
624 * (starting at 1), not as bytes-from start-of-file
626 char *b
, *c
, *last
= NULL
;
628 p
->search
.buflen
= 0;
629 p
->search
.buf
= NULL
;
632 if ((p
->search
.buf
= strdup((const char *)s
)) == NULL
) {
633 file_oomem(ms
, strlen((const char *)s
));
636 for (b
= p
->search
.buf
; offset
&&
637 ((b
= strchr(c
= b
, '\n')) || (b
= strchr(c
, '\r')));
640 if (b
[0] == '\r' && b
[1] == '\n') b
++;
644 p
->search
.buflen
= last
- p
->search
.buf
;
648 if (indir
== 0 && (type
== FILE_BESTRING16
|| type
== FILE_LESTRING16
))
650 const unsigned char *src
= s
+ offset
;
651 const unsigned char *esrc
= s
+ nbytes
;
652 char *dst
= p
->s
, *edst
= &p
->s
[sizeof(p
->s
) - 1];
654 if (type
== FILE_BESTRING16
)
657 /* check for pointer overflow */
659 file_error(ms
, 0, "invalid offset %zu in mcopy()",
664 for (;src
< esrc
; src
++, dst
++) {
676 if (offset
>= nbytes
) {
677 (void)memset(p
, '\0', sizeof(*p
));
680 if (nbytes
- offset
< sizeof(*p
))
681 nbytes
= nbytes
- offset
;
685 (void)memcpy(p
, s
+ offset
, nbytes
);
688 * the usefulness of padding with zeroes eludes me, it
689 * might even cause problems
691 if (nbytes
< sizeof(*p
))
692 (void)memset(((char *)(void *)p
) + nbytes
, '\0',
693 sizeof(*p
) - nbytes
);
698 mget(struct magic_set
*ms
, union VALUETYPE
*p
, const unsigned char *s
,
699 struct magic
*m
, size_t nbytes
, unsigned int cont_level
)
701 uint32_t offset
= ms
->offset
;
703 if (mcopy(ms
, p
, m
->type
, m
->flag
& INDIR
, s
, offset
, nbytes
) == -1)
706 if ((ms
->flags
& MAGIC_DEBUG
) != 0) {
707 mdebug(offset
, (char *)(void *)p
, sizeof(union VALUETYPE
));
711 if (m
->flag
& INDIR
) {
712 int off
= m
->in_offset
;
713 if (m
->in_op
& FILE_OPINDIRECT
) {
714 const union VALUETYPE
*q
=
715 ((const void *)(s
+ offset
+ off
));
716 switch (m
->in_type
) {
724 off
= (short)((q
->hs
[0]<<8)|(q
->hs
[1]));
727 off
= (short)((q
->hs
[1]<<8)|(q
->hs
[0]));
733 off
= (int32_t)((q
->hl
[0]<<24)|(q
->hl
[1]<<16)|
734 (q
->hl
[2]<<8)|(q
->hl
[3]));
737 off
= (int32_t)((q
->hl
[3]<<24)|(q
->hl
[2]<<16)|
738 (q
->hl
[1]<<8)|(q
->hl
[0]));
741 off
= (int32_t)((q
->hl
[1]<<24)|(q
->hl
[0]<<16)|
742 (q
->hl
[3]<<8)|(q
->hl
[2]));
746 switch (m
->in_type
) {
748 if (nbytes
< (offset
+ 1)) return 0;
750 switch (m
->in_op
& 0x3F) {
766 case FILE_OPMULTIPLY
:
778 if (m
->in_op
& FILE_OPINVERSE
)
782 if (nbytes
< (offset
+ 2))
785 switch (m
->in_op
& 0x7F) {
787 offset
= (short)((p
->hs
[0]<<8)|
792 offset
= (short)((p
->hs
[0]<<8)|
797 offset
= (short)((p
->hs
[0]<<8)|
802 offset
= (short)((p
->hs
[0]<<8)|
807 offset
= (short)((p
->hs
[0]<<8)|
811 case FILE_OPMULTIPLY
:
812 offset
= (short)((p
->hs
[0]<<8)|
817 offset
= (short)((p
->hs
[0]<<8)|
822 offset
= (short)((p
->hs
[0]<<8)|
828 offset
= (short)((p
->hs
[0]<<8)|
830 if (m
->in_op
& FILE_OPINVERSE
)
834 if (nbytes
< (offset
+ 2))
837 switch (m
->in_op
& 0x7F) {
839 offset
= (short)((p
->hs
[1]<<8)|
844 offset
= (short)((p
->hs
[1]<<8)|
849 offset
= (short)((p
->hs
[1]<<8)|
854 offset
= (short)((p
->hs
[1]<<8)|
859 offset
= (short)((p
->hs
[1]<<8)|
863 case FILE_OPMULTIPLY
:
864 offset
= (short)((p
->hs
[1]<<8)|
869 offset
= (short)((p
->hs
[1]<<8)|
874 offset
= (short)((p
->hs
[1]<<8)|
880 offset
= (short)((p
->hs
[1]<<8)|
882 if (m
->in_op
& FILE_OPINVERSE
)
886 if (nbytes
< (offset
+ 2))
889 switch (m
->in_op
& 0x7F) {
905 case FILE_OPMULTIPLY
:
918 if (m
->in_op
& FILE_OPINVERSE
)
922 if (nbytes
< (offset
+ 4))
925 switch (m
->in_op
& 0x7F) {
927 offset
= (int32_t)((p
->hl
[0]<<24)|
934 offset
= (int32_t)((p
->hl
[0]<<24)|
941 offset
= (int32_t)((p
->hl
[0]<<24)|
948 offset
= (int32_t)((p
->hl
[0]<<24)|
955 offset
= (int32_t)((p
->hl
[0]<<24)|
961 case FILE_OPMULTIPLY
:
962 offset
= (int32_t)((p
->hl
[0]<<24)|
969 offset
= (int32_t)((p
->hl
[0]<<24)|
976 offset
= (int32_t)((p
->hl
[0]<<24)|
984 offset
= (int32_t)((p
->hl
[0]<<24)|
988 if (m
->in_op
& FILE_OPINVERSE
)
992 if (nbytes
< (offset
+ 4))
995 switch (m
->in_op
& 0x7F) {
997 offset
= (int32_t)((p
->hl
[3]<<24)|
1004 offset
= (int32_t)((p
->hl
[3]<<24)|
1011 offset
= (int32_t)((p
->hl
[3]<<24)|
1018 offset
= (int32_t)((p
->hl
[3]<<24)|
1025 offset
= (int32_t)((p
->hl
[3]<<24)|
1031 case FILE_OPMULTIPLY
:
1032 offset
= (int32_t)((p
->hl
[3]<<24)|
1039 offset
= (int32_t)((p
->hl
[3]<<24)|
1046 offset
= (int32_t)((p
->hl
[3]<<24)|
1054 offset
= (int32_t)((p
->hl
[3]<<24)|
1058 if (m
->in_op
& FILE_OPINVERSE
)
1062 if (nbytes
< (offset
+ 4))
1065 switch (m
->in_op
& 0x7F) {
1067 offset
= (int32_t)((p
->hl
[1]<<24)|
1074 offset
= (int32_t)((p
->hl
[1]<<24)|
1081 offset
= (int32_t)((p
->hl
[1]<<24)|
1088 offset
= (int32_t)((p
->hl
[1]<<24)|
1095 offset
= (int32_t)((p
->hl
[1]<<24)|
1101 case FILE_OPMULTIPLY
:
1102 offset
= (int32_t)((p
->hl
[1]<<24)|
1109 offset
= (int32_t)((p
->hl
[1]<<24)|
1116 offset
= (int32_t)((p
->hl
[1]<<24)|
1124 offset
= (int32_t)((p
->hl
[1]<<24)|
1128 if (m
->in_op
& FILE_OPINVERSE
)
1132 if (nbytes
< (offset
+ 4))
1135 switch (m
->in_op
& 0x7F) {
1137 offset
= p
->l
& off
;
1140 offset
= p
->l
| off
;
1143 offset
= p
->l
^ off
;
1146 offset
= p
->l
+ off
;
1149 offset
= p
->l
- off
;
1151 case FILE_OPMULTIPLY
:
1152 offset
= p
->l
* off
;
1155 offset
= p
->l
/ off
;
1158 offset
= p
->l
% off
;
1160 /* case TOOMANYSWITCHBLOCKS:
1161 * ugh = p->eye % m->strain;
1164 * off = p->tab & m->in_gest;
1170 if (m
->in_op
& FILE_OPINVERSE
)
1175 if (m
->flag
& INDIROFFADD
) offset
+= ms
->c
.off
[cont_level
-1];
1176 if (mcopy(ms
, p
, m
->type
, 0, s
, offset
, nbytes
) == -1)
1178 ms
->offset
= offset
;
1180 if ((ms
->flags
& MAGIC_DEBUG
) != 0) {
1181 mdebug(offset
, (char *)(void *)p
,
1182 sizeof(union VALUETYPE
));
1187 /* Verify we have enough data to match magic type */
1190 if (nbytes
< (offset
+ 1)) /* should alway be true */
1197 if (nbytes
< (offset
+ 2))
1213 if (nbytes
< (offset
+ 4))
1220 if (nbytes
< (offset
+ m
->vallen
))
1226 if (m
->type
== FILE_SEARCH
) {
1227 size_t mlen
= (size_t)(m
->mask
+ m
->vallen
);
1228 size_t flen
= nbytes
- offset
;
1231 p
->search
.buflen
= mlen
;
1232 p
->search
.buf
= malloc(mlen
+ 1);
1233 if (p
->search
.buf
== NULL
) {
1234 file_error(ms
, errno
, "Cannot allocate search buffer");
1237 (void)memcpy(p
->search
.buf
, s
+ offset
, mlen
);
1238 p
->search
.buf
[mlen
] = '\0';
1240 if (!mconvert(ms
, p
, m
))
1246 magiccheck(struct magic_set
*ms
, union VALUETYPE
*p
, struct magic
*m
)
1248 uint64_t l
= m
->value
.q
;
1252 if ( (m
->value
.s
[0] == 'x') && (m
->value
.s
[1] == '\0') ) {
1296 case FILE_BESTRING16
:
1297 case FILE_LESTRING16
:
1301 * What we want here is:
1302 * v = strncmp(m->value.s, p->s, m->vallen);
1303 * but ignoring any nulls. bcmp doesn't give -/+/0
1304 * and isn't universally available anyway.
1306 unsigned char *a
= (unsigned char*)m
->value
.s
;
1307 unsigned char *b
= (unsigned char*)p
->s
;
1308 int len
= m
->vallen
;
1311 if (0L == m
->mask
) { /* normal string: do it fast */
1313 if ((v
= *b
++ - *a
++) != '\0')
1315 } else { /* combine the others */
1316 while (--len
>= 0) {
1317 if ((m
->mask
& STRING_IGNORE_LOWERCASE
) &&
1319 if ((v
= tolower(*b
++) - *a
++) != '\0')
1321 } else if ((m
->mask
& STRING_COMPACT_BLANK
) &&
1324 if (isspace(*b
++)) {
1331 } else if (isspace(*a
) &&
1332 (m
->mask
& STRING_COMPACT_OPTIONAL_BLANK
)) {
1337 if ((v
= *b
++ - *a
++) != '\0')
1350 if (p
->search
.buf
== NULL
)
1353 rc
= regcomp(&rx
, m
->value
.s
,
1354 REG_EXTENDED
|REG_NOSUB
|REG_NEWLINE
|
1355 ((m
->mask
& STRING_IGNORE_LOWERCASE
) ? REG_ICASE
: 0));
1357 free(p
->search
.buf
);
1358 p
->search
.buf
= NULL
;
1359 regerror(rc
, &rx
, errmsg
, sizeof(errmsg
));
1360 file_error(ms
, 0, "regex error %d, (%s)", rc
, errmsg
);
1363 rc
= regexec(&rx
, p
->search
.buf
, 0, 0, 0);
1365 free(p
->search
.buf
);
1366 p
->search
.buf
= NULL
;
1373 * search for a string in a certain range
1375 unsigned char *a
= (unsigned char*)m
->value
.s
;
1376 unsigned char *b
= (unsigned char*)p
->search
.buf
;
1377 size_t len
, slen
= m
->vallen
;
1379 if (slen
> sizeof(m
->value
.s
))
1380 slen
= sizeof(m
->value
.s
);
1386 while (++range
<= m
->mask
) {
1387 while (len
-- > 0 && (v
= *b
++ - *a
++) == 0)
1390 ms
->offset
+= range
- 1;
1393 if (range
+ slen
>= p
->search
.buflen
) {
1398 a
= (unsigned char*)m
->value
.s
;
1399 b
= (unsigned char*)p
->search
.buf
+ range
;
1401 free(p
->search
.buf
);
1402 p
->search
.buf
= NULL
;
1408 file_error(ms
, 0, "invalid type %d in magiccheck()", m
->type
);
1412 if (m
->type
!= FILE_STRING
&& m
->type
!= FILE_PSTRING
)
1413 v
= file_signextend(ms
, m
, v
);
1417 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1418 (void) fprintf(stderr
, "%llu == *any* = 1\n",
1419 (unsigned long long)v
);
1425 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1426 (void) fprintf(stderr
, "%llu != %llu = %d\n",
1427 (unsigned long long)v
, (unsigned long long)l
,
1433 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1434 (void) fprintf(stderr
, "%llu == %llu = %d\n",
1435 (unsigned long long)v
, (unsigned long long)l
,
1440 if (m
->flag
& UNSIGNED
) {
1442 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1443 (void) fprintf(stderr
, "%llu > %llu = %d\n",
1444 (unsigned long long)v
,
1445 (unsigned long long)l
, matched
);
1448 matched
= (int32_t) v
> (int32_t) l
;
1449 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1450 (void) fprintf(stderr
, "%lld > %lld = %d\n",
1451 (long long)v
, (long long)l
, matched
);
1456 if (m
->flag
& UNSIGNED
) {
1458 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1459 (void) fprintf(stderr
, "%llu < %llu = %d\n",
1460 (unsigned long long)v
,
1461 (unsigned long long)l
, matched
);
1464 matched
= (int32_t) v
< (int32_t) l
;
1465 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1466 (void) fprintf(stderr
, "%lld < %lld = %d\n",
1467 (long long)v
, (long long)l
, matched
);
1472 matched
= (v
& l
) == l
;
1473 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1474 (void) fprintf(stderr
, "((%llx & %llx) == %llx) = %d\n",
1475 (unsigned long long)v
, (unsigned long long)l
,
1476 (unsigned long long)l
, matched
);
1480 matched
= (v
& l
) != l
;
1481 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1482 (void) fprintf(stderr
, "((%llx & %llx) != %llx) = %d\n",
1483 (unsigned long long)v
, (unsigned long long)l
,
1484 (unsigned long long)l
, matched
);
1489 file_error(ms
, 0, "cannot happen: invalid relation `%c'",
1498 print_sep(struct magic_set
*ms
, int firstline
)
1503 * we found another match
1504 * put a newline and '-' to do some simple formatting
1506 return file_printf(ms
, "\n- ");