2 * Copyright (c) Ian F. Darwin 1986-1995.
3 * Software written by Ian F. Darwin and others;
4 * maintained 1995-present by Christos Zoulas and others.
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
9 * 1. Redistributions of source code must retain the above copyright
10 * notice immediately at the beginning of the file, without modification,
11 * this list of conditions, and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
16 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR
20 * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29 * softmagic - interpret variable magic from MAGIC
35 FILE_RCSID("@(#)$File: softmagic.c,v 1.206 2015/01/01 17:07:34 christos Exp $")
45 private int match(struct magic_set
*, struct magic
*, uint32_t,
46 const unsigned char *, size_t, size_t, int, int, int, uint16_t,
47 uint16_t *, int *, int *, int *);
48 private int mget(struct magic_set
*, const unsigned char *,
49 struct magic
*, size_t, size_t, unsigned int, int, int, int, uint16_t,
50 uint16_t *, int *, int *, int *);
51 private int magiccheck(struct magic_set
*, struct magic
*);
52 private int32_t mprint(struct magic_set
*, struct magic
*);
53 private int32_t moffset(struct magic_set
*, struct magic
*);
54 private void mdebug(uint32_t, const char *, size_t);
55 private int mcopy(struct magic_set
*, union VALUETYPE
*, int, int,
56 const unsigned char *, uint32_t, size_t, struct magic
*);
57 private int mconvert(struct magic_set
*, struct magic
*, int);
58 private int print_sep(struct magic_set
*, int);
59 private int handle_annotation(struct magic_set
*, struct magic
*);
60 private void cvt_8(union VALUETYPE
*, const struct magic
*);
61 private void cvt_16(union VALUETYPE
*, const struct magic
*);
62 private void cvt_32(union VALUETYPE
*, const struct magic
*);
63 private void cvt_64(union VALUETYPE
*, const struct magic
*);
65 #define OFFSET_OOB(n, o, i) ((n) < (o) || (i) > ((n) - (o)))
68 * softmagic - lookup one file in parsed, in-memory copy of database
69 * Passed the name and FILE * of one file to be typed.
71 /*ARGSUSED1*/ /* nbytes passed for regularity, maybe need later */
73 file_softmagic(struct magic_set
*ms
, const unsigned char *buf
, size_t nbytes
,
74 uint16_t indir_level
, uint16_t *name_count
, int mode
, int text
)
77 int rv
, printed_something
= 0, need_separator
= 0;
80 if (name_count
== NULL
) {
85 for (ml
= ms
->mlist
[0]->next
; ml
!= ms
->mlist
[0]; ml
= ml
->next
)
86 if ((rv
= match(ms
, ml
->magic
, ml
->nmagic
, buf
, nbytes
, 0, mode
,
87 text
, 0, indir_level
, name_count
,
88 &printed_something
, &need_separator
, NULL
)) != 0)
96 #define F(a, b, c) file_fmtcheck((a), (b), (c), __FILE__, __LINE__)
98 private const char * __attribute__((__format_arg__(3)))
99 file_fmtcheck(struct magic_set
*ms
, const struct magic
*m
, const char *def
,
100 const char *file
, size_t line
)
102 const char *ptr
= fmtcheck(m
->desc
, def
);
105 "%s, %" SIZE_T_FORMAT
"u: format `%s' does not match"
106 " with `%s'", file
, line
, m
->desc
, def
);
110 #define F(a, b, c) fmtcheck((b)->desc, (c))
114 * Go through the whole list, stopping if you find a match. Process all
115 * the continuations of that match before returning.
117 * We support multi-level continuations:
119 * At any time when processing a successful top-level match, there is a
120 * current continuation level; it represents the level of the last
121 * successfully matched continuation.
123 * Continuations above that level are skipped as, if we see one, it
124 * means that the continuation that controls them - i.e, the
125 * lower-level continuation preceding them - failed to match.
127 * Continuations below that level are processed as, if we see one,
128 * it means we've finished processing or skipping higher-level
129 * continuations under the control of a successful or unsuccessful
130 * lower-level continuation, and are now seeing the next lower-level
131 * continuation and should process it. The current continuation
132 * level reverts to the level of the one we're seeing.
134 * Continuations at the current level are processed as, if we see
135 * one, there's no lower-level continuation that may have failed.
137 * If a continuation matches, we bump the current continuation level
138 * so that higher-level continuations are processed.
141 match(struct magic_set
*ms
, struct magic
*magic
, uint32_t nmagic
,
142 const unsigned char *s
, size_t nbytes
, size_t offset
, int mode
, int text
,
143 int flip
, uint16_t indir_level
, uint16_t *name_count
,
144 int *printed_something
, int *need_separator
, int *returnval
)
146 uint32_t magindex
= 0;
147 unsigned int cont_level
= 0;
148 int returnvalv
= 0, e
; /* if a match is found it is set to 1*/
149 int firstline
= 1; /* a flag to print X\n X\n- X */
150 int print
= (ms
->flags
& (MAGIC_MIME
|MAGIC_APPLE
)) == 0;
152 if (returnval
== NULL
)
153 returnval
= &returnvalv
;
155 if (file_check_mem(ms
, cont_level
) == -1)
158 for (magindex
= 0; magindex
< nmagic
; magindex
++) {
160 struct magic
*m
= &magic
[magindex
];
162 if (m
->type
!= FILE_NAME
)
163 if ((IS_STRING(m
->type
) &&
164 #define FLT (STRING_BINTEST | STRING_TEXTTEST)
165 ((text
&& (m
->str_flags
& FLT
) == STRING_BINTEST
) ||
166 (!text
&& (m
->str_flags
& FLT
) == STRING_TEXTTEST
))) ||
167 (m
->flag
& mode
) != mode
) {
169 while (magindex
+ 1 < nmagic
&&
170 magic
[magindex
+ 1].cont_level
!= 0 &&
173 continue; /* Skip to next top-level test*/
176 ms
->offset
= m
->offset
;
177 ms
->line
= m
->lineno
;
179 /* if main entry matches, print it... */
180 switch (mget(ms
, s
, m
, nbytes
, offset
, cont_level
, mode
, text
,
181 flip
, indir_level
, name_count
,
182 printed_something
, need_separator
, returnval
)) {
186 flush
= m
->reln
!= '!';
189 if (m
->type
== FILE_INDIRECT
)
192 switch (magiccheck(ms
, m
)) {
206 * main entry didn't match,
207 * flush its continuations
209 while (magindex
< nmagic
- 1 &&
210 magic
[magindex
+ 1].cont_level
!= 0)
215 if ((e
= handle_annotation(ms
, m
)) != 0) {
217 *printed_something
= 1;
222 * If we are going to print something, we'll need to print
223 * a blank before we print something else.
227 *printed_something
= 1;
228 if (print_sep(ms
, firstline
) == -1)
233 if (print
&& mprint(ms
, m
) == -1)
236 ms
->c
.li
[cont_level
].off
= moffset(ms
, m
);
238 /* and any continuations that match */
239 if (file_check_mem(ms
, ++cont_level
) == -1)
242 while (magindex
+ 1 < nmagic
&&
243 magic
[magindex
+ 1].cont_level
!= 0) {
244 m
= &magic
[++magindex
];
245 ms
->line
= m
->lineno
; /* for messages */
247 if (cont_level
< m
->cont_level
)
249 if (cont_level
> m
->cont_level
) {
251 * We're at the end of the level
252 * "cont_level" continuations.
254 cont_level
= m
->cont_level
;
256 ms
->offset
= m
->offset
;
257 if (m
->flag
& OFFADD
) {
259 ms
->c
.li
[cont_level
- 1].off
;
262 #ifdef ENABLE_CONDITIONALS
263 if (m
->cond
== COND_ELSE
||
264 m
->cond
== COND_ELIF
) {
265 if (ms
->c
.li
[cont_level
].last_match
== 1)
269 switch (mget(ms
, s
, m
, nbytes
, offset
, cont_level
, mode
,
270 text
, flip
, indir_level
, name_count
,
271 printed_something
, need_separator
, returnval
)) {
280 if (m
->type
== FILE_INDIRECT
)
286 switch (flush
? 1 : magiccheck(ms
, m
)) {
290 #ifdef ENABLE_CONDITIONALS
291 ms
->c
.li
[cont_level
].last_match
= 0;
295 #ifdef ENABLE_CONDITIONALS
296 ms
->c
.li
[cont_level
].last_match
= 1;
298 if (m
->type
== FILE_CLEAR
)
299 ms
->c
.li
[cont_level
].got_match
= 0;
300 else if (ms
->c
.li
[cont_level
].got_match
) {
301 if (m
->type
== FILE_DEFAULT
)
304 ms
->c
.li
[cont_level
].got_match
= 1;
305 if ((e
= handle_annotation(ms
, m
)) != 0) {
307 *printed_something
= 1;
312 * If we are going to print something,
313 * make sure that we have a separator first.
316 if (!*printed_something
) {
317 *printed_something
= 1;
318 if (print_sep(ms
, firstline
)
324 * This continuation matched. Print
325 * its message, with a blank before it
326 * if the previous item printed and
327 * this item isn't empty.
329 /* space if previous printed */
331 && ((m
->flag
& NOSPACE
) == 0)
334 file_printf(ms
, " ") == -1)
338 if (print
&& mprint(ms
, m
) == -1)
341 ms
->c
.li
[cont_level
].off
= moffset(ms
, m
);
347 * If we see any continuations
351 if (file_check_mem(ms
, ++cont_level
) == -1)
356 if (*printed_something
) {
361 if ((ms
->flags
& MAGIC_CONTINUE
) == 0 && *printed_something
) {
362 return *returnval
; /* don't keep searching */
365 return *returnval
; /* This is hit if -k is set or there is no match */
369 check_fmt(struct magic_set
*ms
, struct magic
*m
)
374 if (strchr(m
->desc
, '%') == NULL
)
377 rc
= file_regcomp(&rx
, "%[-0-9\\.]*s", REG_EXTENDED
|REG_NOSUB
);
379 file_regerror(&rx
, rc
, ms
);
381 rc
= file_regexec(&rx
, m
->desc
, 0, 0, 0);
389 char * strndup(const char *, size_t);
392 strndup(const char *str
, size_t n
)
397 for (len
= 0; len
< n
&& str
[len
]; len
++)
399 if ((copy
= malloc(len
+ 1)) == NULL
)
401 (void)memcpy(copy
, str
, len
);
405 #endif /* HAVE_STRNDUP */
408 mprint(struct magic_set
*ms
, struct magic
*m
)
414 char buf
[128], tbuf
[26], sbuf
[512];
415 union VALUETYPE
*p
= &ms
->ms_value
;
419 v
= file_signextend(ms
, m
, (uint64_t)p
->b
);
420 switch (check_fmt(ms
, m
)) {
424 (void)snprintf(buf
, sizeof(buf
), "%d",
426 if (file_printf(ms
, F(ms
, m
, "%s"), buf
) == -1)
430 if (file_printf(ms
, F(ms
, m
, "%d"),
431 (unsigned char) v
) == -1)
435 t
= ms
->offset
+ sizeof(char);
441 v
= file_signextend(ms
, m
, (uint64_t)p
->h
);
442 switch (check_fmt(ms
, m
)) {
446 (void)snprintf(buf
, sizeof(buf
), "%u",
448 if (file_printf(ms
, F(ms
, m
, "%s"), buf
) == -1)
452 if (file_printf(ms
, F(ms
, m
, "%u"),
453 (unsigned short) v
) == -1)
457 t
= ms
->offset
+ sizeof(short);
464 v
= file_signextend(ms
, m
, (uint64_t)p
->l
);
465 switch (check_fmt(ms
, m
)) {
469 (void)snprintf(buf
, sizeof(buf
), "%u", (uint32_t) v
);
470 if (file_printf(ms
, F(ms
, m
, "%s"), buf
) == -1)
474 if (file_printf(ms
, F(ms
, m
, "%u"), (uint32_t) v
) == -1)
478 t
= ms
->offset
+ sizeof(int32_t);
484 v
= file_signextend(ms
, m
, p
->q
);
485 switch (check_fmt(ms
, m
)) {
489 (void)snprintf(buf
, sizeof(buf
), "%" INT64_T_FORMAT
"u",
490 (unsigned long long)v
);
491 if (file_printf(ms
, F(ms
, m
, "%s"), buf
) == -1)
495 if (file_printf(ms
, F(ms
, m
, "%" INT64_T_FORMAT
"u"),
496 (unsigned long long) v
) == -1)
500 t
= ms
->offset
+ sizeof(int64_t);
505 case FILE_BESTRING16
:
506 case FILE_LESTRING16
:
507 if (m
->reln
== '=' || m
->reln
== '!') {
508 if (file_printf(ms
, F(ms
, m
, "%s"),
509 file_printable(sbuf
, sizeof(sbuf
), m
->value
.s
))
512 t
= ms
->offset
+ m
->vallen
;
517 /* compute t before we mangle the string? */
518 t
= ms
->offset
+ strlen(str
);
520 if (*m
->value
.s
== '\0')
521 str
[strcspn(str
, "\n")] = '\0';
523 if (m
->str_flags
& STRING_TRIM
) {
525 while (isspace((unsigned char)*str
))
531 while (isspace((unsigned char)*last
))
536 if (file_printf(ms
, F(ms
, m
, "%s"),
537 file_printable(sbuf
, sizeof(sbuf
), str
)) == -1)
540 if (m
->type
== FILE_PSTRING
)
541 t
+= file_pstring_length_size(m
);
549 if (file_printf(ms
, F(ms
, m
, "%s"),
550 file_fmttime(p
->l
+ m
->num_mask
, FILE_T_LOCAL
, tbuf
)) == -1)
552 t
= ms
->offset
+ sizeof(uint32_t);
559 if (file_printf(ms
, F(ms
, m
, "%s"),
560 file_fmttime(p
->l
+ m
->num_mask
, 0, tbuf
)) == -1)
562 t
= ms
->offset
+ sizeof(uint32_t);
568 if (file_printf(ms
, F(ms
, m
, "%s"),
569 file_fmttime(p
->q
+ m
->num_mask
, FILE_T_LOCAL
, tbuf
)) == -1)
571 t
= ms
->offset
+ sizeof(uint64_t);
577 if (file_printf(ms
, F(ms
, m
, "%s"),
578 file_fmttime(p
->q
+ m
->num_mask
, 0, tbuf
)) == -1)
580 t
= ms
->offset
+ sizeof(uint64_t);
586 if (file_printf(ms
, F(ms
, m
, "%s"),
587 file_fmttime(p
->q
+ m
->num_mask
, FILE_T_WINDOWS
, tbuf
)) == -1)
589 t
= ms
->offset
+ sizeof(uint64_t);
596 switch (check_fmt(ms
, m
)) {
600 (void)snprintf(buf
, sizeof(buf
), "%g", vf
);
601 if (file_printf(ms
, F(ms
, m
, "%s"), buf
) == -1)
605 if (file_printf(ms
, F(ms
, m
, "%g"), vf
) == -1)
609 t
= ms
->offset
+ sizeof(float);
616 switch (check_fmt(ms
, m
)) {
620 (void)snprintf(buf
, sizeof(buf
), "%g", vd
);
621 if (file_printf(ms
, F(ms
, m
, "%s"), buf
) == -1)
625 if (file_printf(ms
, F(ms
, m
, "%g"), vd
) == -1)
629 t
= ms
->offset
+ sizeof(double);
636 cp
= strndup((const char *)ms
->search
.s
, ms
->search
.rm_len
);
638 file_oomem(ms
, ms
->search
.rm_len
);
641 rval
= file_printf(ms
, F(ms
, m
, "%s"),
642 file_printable(sbuf
, sizeof(sbuf
), cp
));
648 if ((m
->str_flags
& REGEX_OFFSET_START
))
649 t
= ms
->search
.offset
;
651 t
= ms
->search
.offset
+ ms
->search
.rm_len
;
656 if (file_printf(ms
, F(ms
, m
, "%s"),
657 file_printable(sbuf
, sizeof(sbuf
), m
->value
.s
)) == -1)
659 if ((m
->str_flags
& REGEX_OFFSET_START
))
660 t
= ms
->search
.offset
;
662 t
= ms
->search
.offset
+ m
->vallen
;
667 if (file_printf(ms
, "%s", m
->desc
) == -1)
679 file_magerror(ms
, "invalid m->type (%d) in mprint()", m
->type
);
686 moffset(struct magic_set
*ms
, struct magic
*m
)
690 return CAST(int32_t, (ms
->offset
+ sizeof(char)));
695 return CAST(int32_t, (ms
->offset
+ sizeof(short)));
701 return CAST(int32_t, (ms
->offset
+ sizeof(int32_t)));
706 return CAST(int32_t, (ms
->offset
+ sizeof(int64_t)));
710 case FILE_BESTRING16
:
711 case FILE_LESTRING16
:
712 if (m
->reln
== '=' || m
->reln
== '!')
713 return ms
->offset
+ m
->vallen
;
715 union VALUETYPE
*p
= &ms
->ms_value
;
718 if (*m
->value
.s
== '\0')
719 p
->s
[strcspn(p
->s
, "\n")] = '\0';
720 t
= CAST(uint32_t, (ms
->offset
+ strlen(p
->s
)));
721 if (m
->type
== FILE_PSTRING
)
722 t
+= (uint32_t)file_pstring_length_size(m
);
730 return CAST(int32_t, (ms
->offset
+ sizeof(uint32_t)));
736 return CAST(int32_t, (ms
->offset
+ sizeof(uint32_t)));
741 return CAST(int32_t, (ms
->offset
+ sizeof(uint64_t)));
746 return CAST(int32_t, (ms
->offset
+ sizeof(uint64_t)));
751 return CAST(int32_t, (ms
->offset
+ sizeof(float)));
756 return CAST(int32_t, (ms
->offset
+ sizeof(double)));
759 if ((m
->str_flags
& REGEX_OFFSET_START
) != 0)
760 return CAST(int32_t, ms
->search
.offset
);
762 return CAST(int32_t, (ms
->search
.offset
+
766 if ((m
->str_flags
& REGEX_OFFSET_START
) != 0)
767 return CAST(int32_t, ms
->search
.offset
);
769 return CAST(int32_t, (ms
->search
.offset
+ m
->vallen
));
782 cvt_flip(int type
, int flip
)
800 return FILE_LEQLDATE
;
802 return FILE_LEQWDATE
;
816 return FILE_BEQLDATE
;
818 return FILE_BEQWDATE
;
824 return FILE_LEDOUBLE
;
826 return FILE_BEDOUBLE
;
831 #define DO_CVT(fld, cast) \
833 switch (m->mask_op & FILE_OPS_MASK) { \
835 p->fld &= cast m->num_mask; \
838 p->fld |= cast m->num_mask; \
841 p->fld ^= cast m->num_mask; \
844 p->fld += cast m->num_mask; \
847 p->fld -= cast m->num_mask; \
849 case FILE_OPMULTIPLY: \
850 p->fld *= cast m->num_mask; \
852 case FILE_OPDIVIDE: \
853 p->fld /= cast m->num_mask; \
855 case FILE_OPMODULO: \
856 p->fld %= cast m->num_mask; \
859 if (m->mask_op & FILE_OPINVERSE) \
863 cvt_8(union VALUETYPE
*p
, const struct magic
*m
)
865 DO_CVT(b
, (uint8_t));
869 cvt_16(union VALUETYPE
*p
, const struct magic
*m
)
871 DO_CVT(h
, (uint16_t));
875 cvt_32(union VALUETYPE
*p
, const struct magic
*m
)
877 DO_CVT(l
, (uint32_t));
881 cvt_64(union VALUETYPE
*p
, const struct magic
*m
)
883 DO_CVT(q
, (uint64_t));
886 #define DO_CVT2(fld, cast) \
888 switch (m->mask_op & FILE_OPS_MASK) { \
890 p->fld += cast m->num_mask; \
893 p->fld -= cast m->num_mask; \
895 case FILE_OPMULTIPLY: \
896 p->fld *= cast m->num_mask; \
898 case FILE_OPDIVIDE: \
899 p->fld /= cast m->num_mask; \
904 cvt_float(union VALUETYPE
*p
, const struct magic
*m
)
910 cvt_double(union VALUETYPE
*p
, const struct magic
*m
)
912 DO_CVT2(d
, (double));
916 * Convert the byte order of the data we are looking at
917 * While we're here, let's apply the mask operation
918 * (unless you have a better idea)
921 mconvert(struct magic_set
*ms
, struct magic
*m
, int flip
)
923 union VALUETYPE
*p
= &ms
->ms_value
;
926 switch (type
= cvt_flip(m
->type
, flip
)) {
945 case FILE_BESTRING16
:
946 case FILE_LESTRING16
: {
947 /* Null terminate and eat *trailing* return */
948 p
->s
[sizeof(p
->s
) - 1] = '\0';
952 size_t sz
= file_pstring_length_size(m
);
953 char *ptr1
= p
->s
, *ptr2
= ptr1
+ sz
;
954 size_t len
= file_pstring_get_length(m
, ptr1
);
955 sz
= sizeof(p
->s
) - sz
; /* maximum length of string */
958 * The size of the pascal string length (sz)
959 * is 1, 2, or 4. We need at least 1 byte for NUL
960 * termination, but we've already truncated the
961 * string by p->s, so we need to deduct sz.
962 * Because we can use one of the bytes of the length
963 * after we shifted as NUL termination.
973 p
->h
= (short)((p
->hs
[0]<<8)|(p
->hs
[1]));
980 ((p
->hl
[0]<<24)|(p
->hl
[1]<<16)|(p
->hl
[2]<<8)|(p
->hl
[3]));
981 if (type
== FILE_BELONG
)
989 (((uint64_t)p
->hq
[0]<<56)|((uint64_t)p
->hq
[1]<<48)|
990 ((uint64_t)p
->hq
[2]<<40)|((uint64_t)p
->hq
[3]<<32)|
991 ((uint64_t)p
->hq
[4]<<24)|((uint64_t)p
->hq
[5]<<16)|
992 ((uint64_t)p
->hq
[6]<<8)|((uint64_t)p
->hq
[7]));
993 if (type
== FILE_BEQUAD
)
997 p
->h
= (short)((p
->hs
[1]<<8)|(p
->hs
[0]));
1004 ((p
->hl
[3]<<24)|(p
->hl
[2]<<16)|(p
->hl
[1]<<8)|(p
->hl
[0]));
1005 if (type
== FILE_LELONG
)
1013 (((uint64_t)p
->hq
[7]<<56)|((uint64_t)p
->hq
[6]<<48)|
1014 ((uint64_t)p
->hq
[5]<<40)|((uint64_t)p
->hq
[4]<<32)|
1015 ((uint64_t)p
->hq
[3]<<24)|((uint64_t)p
->hq
[2]<<16)|
1016 ((uint64_t)p
->hq
[1]<<8)|((uint64_t)p
->hq
[0]));
1017 if (type
== FILE_LEQUAD
)
1024 ((p
->hl
[1]<<24)|(p
->hl
[0]<<16)|(p
->hl
[3]<<8)|(p
->hl
[2]));
1025 if (type
== FILE_MELONG
)
1032 p
->l
= ((uint32_t)p
->hl
[0]<<24)|((uint32_t)p
->hl
[1]<<16)|
1033 ((uint32_t)p
->hl
[2]<<8) |((uint32_t)p
->hl
[3]);
1037 p
->l
= ((uint32_t)p
->hl
[3]<<24)|((uint32_t)p
->hl
[2]<<16)|
1038 ((uint32_t)p
->hl
[1]<<8) |((uint32_t)p
->hl
[0]);
1045 p
->q
= ((uint64_t)p
->hq
[0]<<56)|((uint64_t)p
->hq
[1]<<48)|
1046 ((uint64_t)p
->hq
[2]<<40)|((uint64_t)p
->hq
[3]<<32)|
1047 ((uint64_t)p
->hq
[4]<<24)|((uint64_t)p
->hq
[5]<<16)|
1048 ((uint64_t)p
->hq
[6]<<8) |((uint64_t)p
->hq
[7]);
1052 p
->q
= ((uint64_t)p
->hq
[7]<<56)|((uint64_t)p
->hq
[6]<<48)|
1053 ((uint64_t)p
->hq
[5]<<40)|((uint64_t)p
->hq
[4]<<32)|
1054 ((uint64_t)p
->hq
[3]<<24)|((uint64_t)p
->hq
[2]<<16)|
1055 ((uint64_t)p
->hq
[1]<<8) |((uint64_t)p
->hq
[0]);
1066 file_magerror(ms
, "invalid type %d in mconvert()", m
->type
);
1073 mdebug(uint32_t offset
, const char *str
, size_t len
)
1075 (void) fprintf(stderr
, "mget/%" SIZE_T_FORMAT
"u @%d: ", len
, offset
);
1076 file_showstr(stderr
, str
, len
);
1077 (void) fputc('\n', stderr
);
1078 (void) fputc('\n', stderr
);
1082 mcopy(struct magic_set
*ms
, union VALUETYPE
*p
, int type
, int indir
,
1083 const unsigned char *s
, uint32_t offset
, size_t nbytes
, struct magic
*m
)
1086 * Note: FILE_SEARCH and FILE_REGEX do not actually copy
1087 * anything, but setup pointers into the source
1092 ms
->search
.s
= RCAST(const char *, s
) + offset
;
1093 ms
->search
.s_len
= nbytes
- offset
;
1094 ms
->search
.offset
= offset
;
1100 const char *last
; /* end of search region */
1101 const char *buf
; /* start of search region */
1103 size_t lines
, linecnt
, bytecnt
;
1106 ms
->search
.s_len
= 0;
1107 ms
->search
.s
= NULL
;
1111 if (m
->str_flags
& REGEX_LINE_COUNT
) {
1112 linecnt
= m
->str_range
;
1113 bytecnt
= linecnt
* 80;
1116 bytecnt
= m
->str_range
;
1121 if (bytecnt
> nbytes
)
1124 buf
= RCAST(const char *, s
) + offset
;
1125 end
= last
= RCAST(const char *, s
) + bytecnt
;
1126 /* mget() guarantees buf <= last */
1127 for (lines
= linecnt
, b
= buf
; lines
&& b
< end
&&
1128 ((b
= CAST(const char *,
1129 memchr(c
= b
, '\n', CAST(size_t, (end
- b
)))))
1130 || (b
= CAST(const char *,
1131 memchr(c
, '\r', CAST(size_t, (end
- c
))))));
1134 if (b
[0] == '\r' && b
[1] == '\n')
1138 last
= RCAST(const char *, s
) + bytecnt
;
1141 ms
->search
.s_len
= last
- buf
;
1142 ms
->search
.offset
= offset
;
1143 ms
->search
.rm_len
= 0;
1146 case FILE_BESTRING16
:
1147 case FILE_LESTRING16
: {
1148 const unsigned char *src
= s
+ offset
;
1149 const unsigned char *esrc
= s
+ nbytes
;
1151 char *edst
= &p
->s
[sizeof(p
->s
) - 1];
1153 if (type
== FILE_BESTRING16
)
1156 /* check that offset is within range */
1157 if (offset
>= nbytes
)
1159 for (/*EMPTY*/; src
< esrc
; src
+= 2, dst
++) {
1165 if (type
== FILE_BESTRING16
?
1166 *(src
- 1) != '\0' :
1174 case FILE_STRING
: /* XXX - these two should not need */
1175 case FILE_PSTRING
: /* to copy anything, but do anyway. */
1181 if (offset
>= nbytes
) {
1182 (void)memset(p
, '\0', sizeof(*p
));
1185 if (nbytes
- offset
< sizeof(*p
))
1186 nbytes
= nbytes
- offset
;
1188 nbytes
= sizeof(*p
);
1190 (void)memcpy(p
, s
+ offset
, nbytes
);
1193 * the usefulness of padding with zeroes eludes me, it
1194 * might even cause problems
1196 if (nbytes
< sizeof(*p
))
1197 (void)memset(((char *)(void *)p
) + nbytes
, '\0',
1198 sizeof(*p
) - nbytes
);
1203 mget(struct magic_set
*ms
, const unsigned char *s
, struct magic
*m
,
1204 size_t nbytes
, size_t o
, unsigned int cont_level
, int mode
, int text
,
1205 int flip
, uint16_t indir_level
, uint16_t *name_count
,
1206 int *printed_something
, int *need_separator
, int *returnval
)
1208 uint32_t offset
= ms
->offset
;
1211 int rv
, oneed_separator
, in_type
;
1213 union VALUETYPE
*p
= &ms
->ms_value
;
1216 if (indir_level
>= ms
->indir_max
) {
1217 file_error(ms
, 0, "indirect recursion nesting (%hu) exceeded",
1222 if (*name_count
>= ms
->name_max
) {
1223 file_error(ms
, 0, "name use count (%hu) exceeded",
1228 if (mcopy(ms
, p
, m
->type
, m
->flag
& INDIR
, s
, (uint32_t)(offset
+ o
),
1229 (uint32_t)nbytes
, m
) == -1)
1232 if ((ms
->flags
& MAGIC_DEBUG
) != 0) {
1233 fprintf(stderr
, "mget(type=%d, flag=%x, offset=%u, o=%"
1234 SIZE_T_FORMAT
"u, " "nbytes=%" SIZE_T_FORMAT
1235 "u, il=%hu, nc=%hu)\n",
1236 m
->type
, m
->flag
, offset
, o
, nbytes
,
1237 indir_level
, *name_count
);
1238 mdebug(offset
, (char *)(void *)p
, sizeof(union VALUETYPE
));
1239 #ifndef COMPILE_ONLY
1244 if (m
->flag
& INDIR
) {
1245 int off
= m
->in_offset
;
1246 if (m
->in_op
& FILE_OPINDIRECT
) {
1247 const union VALUETYPE
*q
= CAST(const union VALUETYPE
*,
1248 ((const void *)(s
+ offset
+ off
)));
1249 switch (cvt_flip(m
->in_type
, flip
)) {
1257 off
= (short)((q
->hs
[0]<<8)|(q
->hs
[1]));
1260 off
= (short)((q
->hs
[1]<<8)|(q
->hs
[0]));
1267 off
= (int32_t)((q
->hl
[0]<<24)|(q
->hl
[1]<<16)|
1268 (q
->hl
[2]<<8)|(q
->hl
[3]));
1272 off
= (int32_t)((q
->hl
[3]<<24)|(q
->hl
[2]<<16)|
1273 (q
->hl
[1]<<8)|(q
->hl
[0]));
1276 off
= (int32_t)((q
->hl
[1]<<24)|(q
->hl
[0]<<16)|
1277 (q
->hl
[3]<<8)|(q
->hl
[2]));
1280 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1281 fprintf(stderr
, "indirect offs=%u\n", off
);
1283 switch (in_type
= cvt_flip(m
->in_type
, flip
)) {
1285 if (OFFSET_OOB(nbytes
, offset
, 1))
1288 switch (m
->in_op
& FILE_OPS_MASK
) {
1290 offset
= p
->b
& off
;
1293 offset
= p
->b
| off
;
1296 offset
= p
->b
^ off
;
1299 offset
= p
->b
+ off
;
1302 offset
= p
->b
- off
;
1304 case FILE_OPMULTIPLY
:
1305 offset
= p
->b
* off
;
1308 offset
= p
->b
/ off
;
1311 offset
= p
->b
% off
;
1316 if (m
->in_op
& FILE_OPINVERSE
)
1320 if (OFFSET_OOB(nbytes
, offset
, 2))
1322 lhs
= (p
->hs
[0] << 8) | p
->hs
[1];
1324 switch (m
->in_op
& FILE_OPS_MASK
) {
1340 case FILE_OPMULTIPLY
:
1352 if (m
->in_op
& FILE_OPINVERSE
)
1356 if (OFFSET_OOB(nbytes
, offset
, 2))
1358 lhs
= (p
->hs
[1] << 8) | p
->hs
[0];
1360 switch (m
->in_op
& FILE_OPS_MASK
) {
1376 case FILE_OPMULTIPLY
:
1388 if (m
->in_op
& FILE_OPINVERSE
)
1392 if (OFFSET_OOB(nbytes
, offset
, 2))
1395 switch (m
->in_op
& FILE_OPS_MASK
) {
1397 offset
= p
->h
& off
;
1400 offset
= p
->h
| off
;
1403 offset
= p
->h
^ off
;
1406 offset
= p
->h
+ off
;
1409 offset
= p
->h
- off
;
1411 case FILE_OPMULTIPLY
:
1412 offset
= p
->h
* off
;
1415 offset
= p
->h
/ off
;
1418 offset
= p
->h
% off
;
1424 if (m
->in_op
& FILE_OPINVERSE
)
1429 if (OFFSET_OOB(nbytes
, offset
, 4))
1431 lhs
= (p
->hl
[0] << 24) | (p
->hl
[1] << 16) |
1432 (p
->hl
[2] << 8) | p
->hl
[3];
1434 switch (m
->in_op
& FILE_OPS_MASK
) {
1450 case FILE_OPMULTIPLY
:
1462 if (m
->in_op
& FILE_OPINVERSE
)
1467 if (OFFSET_OOB(nbytes
, offset
, 4))
1469 lhs
= (p
->hl
[3] << 24) | (p
->hl
[2] << 16) |
1470 (p
->hl
[1] << 8) | p
->hl
[0];
1472 switch (m
->in_op
& FILE_OPS_MASK
) {
1488 case FILE_OPMULTIPLY
:
1500 if (m
->in_op
& FILE_OPINVERSE
)
1504 if (OFFSET_OOB(nbytes
, offset
, 4))
1506 lhs
= (p
->hl
[1] << 24) | (p
->hl
[0] << 16) |
1507 (p
->hl
[3] << 8) | p
->hl
[2];
1509 switch (m
->in_op
& FILE_OPS_MASK
) {
1525 case FILE_OPMULTIPLY
:
1537 if (m
->in_op
& FILE_OPINVERSE
)
1541 if (OFFSET_OOB(nbytes
, offset
, 4))
1544 switch (m
->in_op
& FILE_OPS_MASK
) {
1546 offset
= p
->l
& off
;
1549 offset
= p
->l
| off
;
1552 offset
= p
->l
^ off
;
1555 offset
= p
->l
+ off
;
1558 offset
= p
->l
- off
;
1560 case FILE_OPMULTIPLY
:
1561 offset
= p
->l
* off
;
1564 offset
= p
->l
/ off
;
1567 offset
= p
->l
% off
;
1572 if (m
->in_op
& FILE_OPINVERSE
)
1582 offset
= ((((offset
>> 0) & 0x7f) << 0) |
1583 (((offset
>> 8) & 0x7f) << 7) |
1584 (((offset
>> 16) & 0x7f) << 14) |
1585 (((offset
>> 24) & 0x7f) << 21)) + 10;
1591 if (m
->flag
& INDIROFFADD
) {
1592 offset
+= ms
->c
.li
[cont_level
-1].off
;
1594 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1596 "indirect *zero* offset\n");
1599 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1600 fprintf(stderr
, "indirect +offs=%u\n", offset
);
1602 if (mcopy(ms
, p
, m
->type
, 0, s
, offset
, nbytes
, m
) == -1)
1604 ms
->offset
= offset
;
1606 if ((ms
->flags
& MAGIC_DEBUG
) != 0) {
1607 mdebug(offset
, (char *)(void *)p
,
1608 sizeof(union VALUETYPE
));
1609 #ifndef COMPILE_ONLY
1615 /* Verify we have enough data to match magic type */
1618 if (OFFSET_OOB(nbytes
, offset
, 1))
1625 if (OFFSET_OOB(nbytes
, offset
, 2))
1644 if (OFFSET_OOB(nbytes
, offset
, 4))
1651 if (OFFSET_OOB(nbytes
, offset
, 8))
1658 if (OFFSET_OOB(nbytes
, offset
, m
->vallen
))
1663 if (nbytes
< offset
)
1668 if (m
->str_flags
& INDIRECT_RELATIVE
)
1673 if (nbytes
< offset
)
1676 if ((pb
= file_push_buffer(ms
)) == NULL
)
1679 rv
= file_softmagic(ms
, s
+ offset
, nbytes
- offset
,
1680 indir_level
+ 1, name_count
, BINTEST
, text
);
1682 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
1683 fprintf(stderr
, "indirect @offs=%u[%d]\n", offset
, rv
);
1685 rbuf
= file_pop_buffer(ms
, pb
);
1686 if (rbuf
== NULL
&& ms
->event_flags
& EVENT_HAD_ERR
)
1690 if ((ms
->flags
& (MAGIC_MIME
|MAGIC_APPLE
)) == 0 &&
1691 file_printf(ms
, F(ms
, m
, "%u"), offset
) == -1) {
1695 if (file_printf(ms
, "%s", rbuf
) == -1) {
1704 if (nbytes
< offset
)
1711 if (file_magicfind(ms
, rbuf
, &ml
) == -1) {
1712 file_error(ms
, 0, "cannot find entry `%s'", rbuf
);
1716 oneed_separator
= *need_separator
;
1717 if (m
->flag
& NOSPACE
)
1718 *need_separator
= 0;
1719 rv
= match(ms
, ml
.magic
, ml
.nmagic
, s
, nbytes
, offset
+ o
,
1720 mode
, text
, flip
, indir_level
, name_count
,
1721 printed_something
, need_separator
, returnval
);
1723 *need_separator
= oneed_separator
;
1727 if (file_printf(ms
, "%s", m
->desc
) == -1)
1730 case FILE_DEFAULT
: /* nothing to check */
1735 if (!mconvert(ms
, m
, flip
))
1741 file_strncmp(const char *s1
, const char *s2
, size_t len
, uint32_t flags
)
1744 * Convert the source args to unsigned here so that (1) the
1745 * compare will be unsigned as it is in strncmp() and (2) so
1746 * the ctype functions will work correctly without extra
1749 const unsigned char *a
= (const unsigned char *)s1
;
1750 const unsigned char *b
= (const unsigned char *)s2
;
1754 * What we want here is v = strncmp(s1, s2, len),
1755 * but ignoring any nulls.
1758 if (0L == flags
) { /* normal string: do it fast */
1760 if ((v
= *b
++ - *a
++) != '\0')
1763 else { /* combine the others */
1765 if ((flags
& STRING_IGNORE_LOWERCASE
) &&
1767 if ((v
= tolower(*b
++) - *a
++) != '\0')
1770 else if ((flags
& STRING_IGNORE_UPPERCASE
) &&
1772 if ((v
= toupper(*b
++) - *a
++) != '\0')
1775 else if ((flags
& STRING_COMPACT_WHITESPACE
) &&
1778 if (isspace(*b
++)) {
1788 else if ((flags
& STRING_COMPACT_OPTIONAL_WHITESPACE
) &&
1795 if ((v
= *b
++ - *a
++) != '\0')
1804 file_strncmp16(const char *a
, const char *b
, size_t len
, uint32_t flags
)
1807 * XXX - The 16-bit string compare probably needs to be done
1808 * differently, especially if the flags are to be supported.
1809 * At the moment, I am unsure.
1812 return file_strncmp(a
, b
, len
, flags
);
1816 magiccheck(struct magic_set
*ms
, struct magic
*m
)
1818 uint64_t l
= m
->value
.q
;
1823 union VALUETYPE
*p
= &ms
->ms_value
;
1893 file_magerror(ms
, "cannot happen with float: invalid relation `%c'",
1926 file_magerror(ms
, "cannot happen with double: invalid relation `%c'", m
->reln
);
1940 v
= file_strncmp(m
->value
.s
, p
->s
, (size_t)m
->vallen
, m
->str_flags
);
1943 case FILE_BESTRING16
:
1944 case FILE_LESTRING16
:
1946 v
= file_strncmp16(m
->value
.s
, p
->s
, (size_t)m
->vallen
, m
->str_flags
);
1949 case FILE_SEARCH
: { /* search ms->search.s for the string m->value.s */
1953 if (ms
->search
.s
== NULL
)
1956 slen
= MIN(m
->vallen
, sizeof(m
->value
.s
));
1960 for (idx
= 0; m
->str_range
== 0 || idx
< m
->str_range
; idx
++) {
1961 if (slen
+ idx
> ms
->search
.s_len
)
1964 v
= file_strncmp(m
->value
.s
, ms
->search
.s
+ idx
, slen
,
1966 if (v
== 0) { /* found match */
1967 ms
->search
.offset
+= idx
;
1978 if (ms
->search
.s
== NULL
)
1982 rc
= file_regcomp(&rx
, m
->value
.s
,
1983 REG_EXTENDED
|REG_NEWLINE
|
1984 ((m
->str_flags
& STRING_IGNORE_CASE
) ? REG_ICASE
: 0));
1986 file_regerror(&rx
, rc
, ms
);
1989 regmatch_t pmatch
[1];
1990 size_t slen
= ms
->search
.s_len
;
1991 #ifndef REG_STARTEND
1992 #define REG_STARTEND 0
1995 copy
= malloc(slen
);
1997 file_error(ms
, errno
,
1998 "can't allocate %" SIZE_T_FORMAT
"u bytes",
2002 memcpy(copy
, ms
->search
.s
, slen
);
2003 copy
[--slen
] = '\0';
2006 search
= ms
->search
.s
;
2010 search
= ms
->search
.s
;
2011 pmatch
[0].rm_so
= 0;
2012 pmatch
[0].rm_eo
= slen
;
2014 rc
= file_regexec(&rx
, (const char *)search
,
2015 1, pmatch
, REG_STARTEND
);
2016 #if REG_STARTEND == 0
2021 ms
->search
.s
+= (int)pmatch
[0].rm_so
;
2022 ms
->search
.offset
+= (size_t)pmatch
[0].rm_so
;
2024 (size_t)(pmatch
[0].rm_eo
- pmatch
[0].rm_so
);
2033 file_regerror(&rx
, rc
, ms
);
2039 if (v
== (uint64_t)-1)
2048 file_magerror(ms
, "invalid type %d in magiccheck()", m
->type
);
2052 v
= file_signextend(ms
, m
, v
);
2056 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
2057 (void) fprintf(stderr
, "%" INT64_T_FORMAT
2058 "u == *any* = 1\n", (unsigned long long)v
);
2064 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
2065 (void) fprintf(stderr
, "%" INT64_T_FORMAT
"u != %"
2066 INT64_T_FORMAT
"u = %d\n", (unsigned long long)v
,
2067 (unsigned long long)l
, matched
);
2072 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
2073 (void) fprintf(stderr
, "%" INT64_T_FORMAT
"u == %"
2074 INT64_T_FORMAT
"u = %d\n", (unsigned long long)v
,
2075 (unsigned long long)l
, matched
);
2079 if (m
->flag
& UNSIGNED
) {
2081 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
2082 (void) fprintf(stderr
, "%" INT64_T_FORMAT
2083 "u > %" INT64_T_FORMAT
"u = %d\n",
2084 (unsigned long long)v
,
2085 (unsigned long long)l
, matched
);
2088 matched
= (int64_t) v
> (int64_t) l
;
2089 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
2090 (void) fprintf(stderr
, "%" INT64_T_FORMAT
2091 "d > %" INT64_T_FORMAT
"d = %d\n",
2092 (long long)v
, (long long)l
, matched
);
2097 if (m
->flag
& UNSIGNED
) {
2099 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
2100 (void) fprintf(stderr
, "%" INT64_T_FORMAT
2101 "u < %" INT64_T_FORMAT
"u = %d\n",
2102 (unsigned long long)v
,
2103 (unsigned long long)l
, matched
);
2106 matched
= (int64_t) v
< (int64_t) l
;
2107 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
2108 (void) fprintf(stderr
, "%" INT64_T_FORMAT
2109 "d < %" INT64_T_FORMAT
"d = %d\n",
2110 (long long)v
, (long long)l
, matched
);
2115 matched
= (v
& l
) == l
;
2116 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
2117 (void) fprintf(stderr
, "((%" INT64_T_FORMAT
"x & %"
2118 INT64_T_FORMAT
"x) == %" INT64_T_FORMAT
2119 "x) = %d\n", (unsigned long long)v
,
2120 (unsigned long long)l
, (unsigned long long)l
,
2125 matched
= (v
& l
) != l
;
2126 if ((ms
->flags
& MAGIC_DEBUG
) != 0)
2127 (void) fprintf(stderr
, "((%" INT64_T_FORMAT
"x & %"
2128 INT64_T_FORMAT
"x) != %" INT64_T_FORMAT
2129 "x) = %d\n", (unsigned long long)v
,
2130 (unsigned long long)l
, (unsigned long long)l
,
2135 file_magerror(ms
, "cannot happen: invalid relation `%c'",
2144 handle_annotation(struct magic_set
*ms
, struct magic
*m
)
2146 if (ms
->flags
& MAGIC_APPLE
) {
2147 if (file_printf(ms
, "%.8s", m
->apple
) == -1)
2151 if ((ms
->flags
& MAGIC_MIME_TYPE
) && m
->mimetype
[0]) {
2152 if (file_printf(ms
, "%s", m
->mimetype
) == -1)
2160 print_sep(struct magic_set
*ms
, int firstline
)
2162 if (ms
->flags
& MAGIC_MIME
)
2167 * we found another match
2168 * put a newline and '-' to do some simple formatting
2170 return file_printf(ms
, "\n- ");