17 KB

  1. .\" $File:,v 1.102 2013/01/04 15:39:22 christos Exp $
  2. .Dd October 25, 2012
  3. .Dt FILE __CSECTION__
  4. .Os
  5. .Sh NAME
  6. .Nm file
  7. .Nd determine file type
  9. .Nm
  10. .Bk -words
  11. .Op Fl bchiklLNnprsvz0
  12. .Op Fl Fl apple
  13. .Op Fl Fl mime-encoding
  14. .Op Fl Fl mime-type
  15. .Op Fl e Ar testname
  16. .Op Fl F Ar separator
  17. .Op Fl f Ar namefile
  18. .Op Fl m Ar magicfiles
  19. .Ar
  20. .Ek
  21. .Nm
  22. .Fl C
  23. .Op Fl m Ar magicfiles
  24. .Nm
  25. .Op Fl Fl help
  27. This manual page documents version __VERSION__ of the
  28. .Nm
  29. command.
  30. .Pp
  31. .Nm
  32. tests each argument in an attempt to classify it.
  33. There are three sets of tests, performed in this order:
  34. filesystem tests, magic tests, and language tests.
  35. The
  36. .Em first
  37. test that succeeds causes the file type to be printed.
  38. .Pp
  39. The type printed will usually contain one of the words
  40. .Em text
  41. (the file contains only
  42. printing characters and a few common control
  43. characters and is probably safe to read on an
  44. .Dv ASCII
  45. terminal),
  46. .Em executable
  47. (the file contains the result of compiling a program
  48. in a form understandable to some
  49. .Tn UNIX
  50. kernel or another),
  51. or
  52. .Em data
  53. meaning anything else (data is usually
  54. .Dq binary
  55. or non-printable).
  56. Exceptions are well-known file formats (core files, tar archives)
  57. that are known to contain binary data.
  58. When modifying magic files or the program itself, make sure to
  59. .Em "preserve these keywords" .
  60. Users depend on knowing that all the readable files in a directory
  61. have the word
  62. .Dq text
  63. printed.
  64. Don't do as Berkeley did and change
  65. .Dq shell commands text
  66. to
  67. .Dq shell script .
  68. .Pp
  69. The filesystem tests are based on examining the return from a
  70. .Xr stat 2
  71. system call.
  72. The program checks to see if the file is empty,
  73. or if it's some sort of special file.
  74. Any known file types appropriate to the system you are running on
  75. (sockets, symbolic links, or named pipes (FIFOs) on those systems that
  76. implement them)
  77. are intuited if they are defined in the system header file
  78. .In sys/stat.h .
  79. .Pp
  80. The magic tests are used to check for files with data in
  81. particular fixed formats.
  82. The canonical example of this is a binary executable (compiled program)
  83. .Dv a.out
  84. file, whose format is defined in
  85. .In elf.h ,
  86. .In a.out.h
  87. and possibly
  88. .In exec.h
  89. in the standard include directory.
  90. These files have a
  91. .Dq "magic number"
  92. stored in a particular place
  93. near the beginning of the file that tells the
  94. .Tn UNIX
  95. operating system
  96. that the file is a binary executable, and which of several types thereof.
  97. The concept of a
  98. .Dq "magic"
  99. has been applied by extension to data files.
  100. Any file with some invariant identifier at a small fixed
  101. offset into the file can usually be described in this way.
  102. The information identifying these files is read from the compiled
  103. magic file
  104. .Pa __MAGIC__.mgc ,
  105. or the files in the directory
  106. .Pa __MAGIC__
  107. if the compiled file does not exist.
  108. In addition, if
  109. .Pa $HOME/.magic.mgc
  110. or
  111. .Pa $HOME/.magic
  112. exists, it will be used in preference to the system magic files.
  113. .Pp
  114. If a file does not match any of the entries in the magic file,
  115. it is examined to see if it seems to be a text file.
  116. ASCII, ISO-8859-x, non-ISO 8-bit extended-ASCII character sets
  117. (such as those used on Macintosh and IBM PC systems),
  118. UTF-8-encoded Unicode, UTF-16-encoded Unicode, and EBCDIC
  119. character sets can be distinguished by the different
  120. ranges and sequences of bytes that constitute printable text
  121. in each set.
  122. If a file passes any of these tests, its character set is reported.
  123. ASCII, ISO-8859-x, UTF-8, and extended-ASCII files are identified
  124. as
  125. .Dq text
  126. because they will be mostly readable on nearly any terminal;
  127. UTF-16 and EBCDIC are only
  128. .Dq character data
  129. because, while
  130. they contain text, it is text that will require translation
  131. before it can be read.
  132. In addition,
  133. .Nm
  134. will attempt to determine other characteristics of text-type files.
  135. If the lines of a file are terminated by CR, CRLF, or NEL, instead
  136. of the Unix-standard LF, this will be reported.
  137. Files that contain embedded escape sequences or overstriking
  138. will also be identified.
  139. .Pp
  140. Once
  141. .Nm
  142. has determined the character set used in a text-type file,
  143. it will
  144. attempt to determine in what language the file is written.
  145. The language tests look for particular strings (cf.
  146. .In names.h )
  147. that can appear anywhere in the first few blocks of a file.
  148. For example, the keyword
  149. .Em .br
  150. indicates that the file is most likely a
  151. .Xr troff 1
  152. input file, just as the keyword
  153. .Em struct
  154. indicates a C program.
  155. These tests are less reliable than the previous
  156. two groups, so they are performed last.
  157. The language test routines also test for some miscellany
  158. (such as
  159. .Xr tar 1
  160. archives).
  161. .Pp
  162. Any file that cannot be identified as having been written
  163. in any of the character sets listed above is simply said to be
  164. .Dq data .
  165. .Sh OPTIONS
  166. .Bl -tag -width indent
  167. .It Fl b , Fl Fl brief
  168. Do not prepend filenames to output lines (brief mode).
  169. .It Fl C , Fl Fl compile
  170. Write a
  171. .Pa magic.mgc
  172. output file that contains a pre-parsed version of the magic file or directory.
  173. .It Fl c , Fl Fl checking-printout
  174. Cause a checking printout of the parsed form of the magic file.
  175. This is usually used in conjunction with the
  176. .Fl m
  177. flag to debug a new magic file before installing it.
  178. .It Fl e , Fl Fl exclude Ar testname
  179. Exclude the test named in
  180. .Ar testname
  181. from the list of tests made to determine the file type.
  182. Valid test names are:
  183. .Bl -tag -width compress
  184. .It apptype
  185. .Dv EMX
  186. application type (only on EMX).
  187. .It ascii
  188. Various types of text files (this test will try to guess the text
  189. encoding, irrespective of the setting of the
  190. .Sq encoding
  191. option).
  192. .It encoding
  193. Different text encodings for soft magic tests.
  194. .It tokens
  195. Ignored for backwards compatibility.
  196. .It cdf
  197. Prints details of Compound Document Files.
  198. .It compress
  199. Checks for, and looks inside, compressed files.
  200. .It elf
  201. Prints ELF file details.
  202. .It soft
  203. Consults magic files.
  204. .It tar
  205. Examines tar files.
  206. .El
  207. .It Fl F , Fl Fl separator Ar separator
  208. Use the specified string as the separator between the filename and the
  209. file result returned.
  210. Defaults to
  211. .Sq \&: .
  212. .It Fl f , Fl Fl files-from Ar namefile
  213. Read the names of the files to be examined from
  214. .Ar namefile
  215. (one per line)
  216. before the argument list.
  217. Either
  218. .Ar namefile
  219. or at least one filename argument must be present;
  220. to test the standard input, use
  221. .Sq -
  222. as a filename argument.
  223. Please note that
  224. .Ar namefile
  225. is unwrapped and the enclosed filenames are processed when this option is
  226. encountered and before any further options processing is done.
  227. This allows one to process multiple lists of files with different command line
  228. arguments on the same
  229. .Nm
  230. invocation.
  231. Thus if you want to set the delimiter, you need to do it before you specify
  232. the list of files, like:
  233. .Dq Fl F Ar @ Fl f Ar namefile ,
  234. instead of:
  235. .Dq Fl f Ar namefile Fl F Ar @ .
  236. .It Fl h , Fl Fl no-dereference
  237. option causes symlinks not to be followed
  238. (on systems that support symbolic links).
  239. This is the default if the environment variable
  241. is not defined.
  242. .It Fl i , Fl Fl mime
  243. Causes the file command to output mime type strings rather than the more
  244. traditional human readable ones.
  245. Thus it may say
  246. .Sq text/plain; charset=us-ascii
  247. rather than
  248. .Dq ASCII text .
  249. .It Fl Fl mime-type , Fl Fl mime-encoding
  250. Like
  251. .Fl i ,
  252. but print only the specified element(s).
  253. .It Fl k , Fl Fl keep-going
  254. Don't stop at the first match, keep going.
  255. Subsequent matches will be
  256. have the string
  257. .Sq "\[rs]012\- "
  258. prepended.
  259. (If you want a newline, see the
  260. .Fl r
  261. option.)
  262. The magic pattern with the highest strength (see the
  263. .Fl l
  264. option) comes first.
  265. .It Fl l , Fl Fl list
  266. Shows a list of patterns and their strength sorted descending by
  267. .Xr magic 4
  268. strength
  269. which is used for the matching (see also the
  270. .Fl k
  271. option).
  272. .It Fl L , Fl Fl dereference
  273. option causes symlinks to be followed, as the like-named option in
  274. .Xr ls 1
  275. (on systems that support symbolic links).
  276. This is the default if the environment variable
  278. is defined.
  279. .It Fl m , Fl Fl magic-file Ar magicfiles
  280. Specify an alternate list of files and directories containing magic.
  281. This can be a single item, or a colon-separated list.
  282. If a compiled magic file is found alongside a file or directory,
  283. it will be used instead.
  284. .It Fl N , Fl Fl no-pad
  285. Don't pad filenames so that they align in the output.
  286. .It Fl n , Fl Fl no-buffer
  287. Force stdout to be flushed after checking each file.
  288. This is only useful if checking a list of files.
  289. It is intended to be used by programs that want filetype output from a pipe.
  290. .It Fl p , Fl Fl preserve-date
  291. On systems that support
  292. .Xr utime 3
  293. or
  294. .Xr utimes 2 ,
  295. attempt to preserve the access time of files analyzed, to pretend that
  296. .Nm
  297. never read them.
  298. .It Fl r , Fl Fl raw
  299. Don't translate unprintable characters to \eooo.
  300. Normally
  301. .Nm
  302. translates unprintable characters to their octal representation.
  303. .It Fl s , Fl Fl special-files
  304. Normally,
  305. .Nm
  306. only attempts to read and determine the type of argument files which
  307. .Xr stat 2
  308. reports are ordinary files.
  309. This prevents problems, because reading special files may have peculiar
  310. consequences.
  311. Specifying the
  312. .Fl s
  313. option causes
  314. .Nm
  315. to also read argument files which are block or character special files.
  316. This is useful for determining the filesystem types of the data in raw
  317. disk partitions, which are block special files.
  318. This option also causes
  319. .Nm
  320. to disregard the file size as reported by
  321. .Xr stat 2
  322. since on some systems it reports a zero size for raw disk partitions.
  323. .It Fl v , Fl Fl version
  324. Print the version of the program and exit.
  325. .It Fl z , Fl Fl uncompress
  326. Try to look inside compressed files.
  327. .It Fl 0 , Fl Fl print0
  328. Output a null character
  329. .Sq \e0
  330. after the end of the filename.
  331. Nice to
  332. .Xr cut 1
  333. the output.
  334. This does not affect the separator which is still printed.
  335. .It Fl -help
  336. Print a help message and exit.
  337. .El
  338. .Sh FILES
  339. .Bl -tag -width __MAGIC__.mgc -compact
  340. .It Pa __MAGIC__.mgc
  341. Default compiled list of magic.
  342. .It Pa __MAGIC__
  343. Directory containing default magic files.
  344. .El
  346. The environment variable
  347. .Ev MAGIC
  348. can be used to set the default magic file name.
  349. If that variable is set, then
  350. .Nm
  351. will not attempt to open
  352. .Pa $HOME/.magic .
  353. .Nm
  354. adds
  355. .Dq Pa .mgc
  356. to the value of this variable as appropriate.
  357. However,
  358. .Pa file
  359. has to exist in order for
  360. .Pa file.mime
  361. to be considered.
  362. The environment variable
  364. controls (on systems that support symbolic links), whether
  365. .Nm
  366. will attempt to follow symlinks or not.
  367. If set, then
  368. .Nm
  369. follows symlink, otherwise it does not.
  370. This is also controlled by the
  371. .Fl L
  372. and
  373. .Fl h
  374. options.
  375. .Sh SEE ALSO
  376. .Xr magic __FSECTION__ ,
  377. .Xr hexdump 1 ,
  378. .Xr od 1 ,
  379. .Xr strings 1 ,
  381. This program is believed to exceed the System V Interface Definition
  382. of FILE(CMD), as near as one can determine from the vague language
  383. contained therein.
  384. Its behavior is mostly compatible with the System V program of the same name.
  385. This version knows more magic, however, so it will produce
  386. different (albeit more accurate) output in many cases.
  387. .\" URL:
  388. .Pp
  389. The one significant difference
  390. between this version and System V
  391. is that this version treats any white space
  392. as a delimiter, so that spaces in pattern strings must be escaped.
  393. For example,
  394. .Bd -literal -offset indent
  395. \*[Gt]10 string language impress\ (imPRESS data)
  396. .Ed
  397. .Pp
  398. in an existing magic file would have to be changed to
  399. .Bd -literal -offset indent
  400. \*[Gt]10 string language\e impress (imPRESS data)
  401. .Ed
  402. .Pp
  403. In addition, in this version, if a pattern string contains a backslash,
  404. it must be escaped.
  405. For example
  406. .Bd -literal -offset indent
  407. 0 string \ebegindata Andrew Toolkit document
  408. .Ed
  409. .Pp
  410. in an existing magic file would have to be changed to
  411. .Bd -literal -offset indent
  412. 0 string \e\ebegindata Andrew Toolkit document
  413. .Ed
  414. .Pp
  415. SunOS releases 3.2 and later from Sun Microsystems include a
  416. .Nm
  417. command derived from the System V one, but with some extensions.
  418. This version differs from Sun's only in minor ways.
  419. It includes the extension of the
  420. .Sq \*[Am]
  421. operator, used as,
  422. for example,
  423. .Bd -literal -offset indent
  424. \*[Gt]16 long\*[Am]0x7fffffff \*[Gt]0 not stripped
  425. .Ed
  427. The magic file entries have been collected from various sources,
  428. mainly USENET, and contributed by various authors.
  429. Christos Zoulas (address below) will collect additional
  430. or corrected magic file entries.
  431. A consolidation of magic file entries
  432. will be distributed periodically.
  433. .Pp
  434. The order of entries in the magic file is significant.
  435. Depending on what system you are using, the order that
  436. they are put together may be incorrect.
  437. If your old
  438. .Nm
  439. command uses a magic file,
  440. keep the old magic file around for comparison purposes
  441. (rename it to
  442. .Pa __MAGIC__.orig ) .
  443. .Sh EXAMPLES
  444. .Bd -literal -offset indent
  445. $ file file.c file /dev/{wd0a,hda}
  446. file.c: C program text
  447. file: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV),
  448. dynamically linked (uses shared libs), stripped
  449. /dev/wd0a: block special (0/0)
  450. /dev/hda: block special (3/0)
  451. $ file -s /dev/wd0{b,d}
  452. /dev/wd0b: data
  453. /dev/wd0d: x86 boot sector
  454. $ file -s /dev/hda{,1,2,3,4,5,6,7,8,9,10}
  455. /dev/hda: x86 boot sector
  456. /dev/hda1: Linux/i386 ext2 filesystem
  457. /dev/hda2: x86 boot sector
  458. /dev/hda3: x86 boot sector, extended partition table
  459. /dev/hda4: Linux/i386 ext2 filesystem
  460. /dev/hda5: Linux/i386 swap file
  461. /dev/hda6: Linux/i386 swap file
  462. /dev/hda7: Linux/i386 swap file
  463. /dev/hda8: Linux/i386 swap file
  464. /dev/hda9: empty
  465. /dev/hda10: empty
  466. $ file -i file.c file /dev/{wd0a,hda}
  467. file.c: text/x-c
  468. file: application/x-executable
  469. /dev/hda: application/x-not-regular-file
  470. /dev/wd0a: application/x-not-regular-file
  471. .Ed
  472. .Sh HISTORY
  473. There has been a
  474. .Nm
  475. command in every
  476. .Dv UNIX since at least Research Version 4
  477. (man page dated November, 1973).
  478. The System V version introduced one significant major change:
  479. the external list of magic types.
  480. This slowed the program down slightly but made it a lot more flexible.
  481. .Pp
  482. This program, based on the System V version,
  483. was written by Ian Darwin
  484. .Aq
  485. without looking at anybody else's source code.
  486. .Pp
  487. John Gilmore revised the code extensively, making it better than
  488. the first version.
  489. Geoff Collyer found several inadequacies
  490. and provided some magic file entries.
  491. Contributions by the
  492. .Sq \*[Am]
  493. operator by Rob McMahon,
  494. .Aq ,
  495. 1989.
  496. .Pp
  497. Guy Harris,
  498. .Aq ,
  499. made many changes from 1993 to the present.
  500. 1989.
  501. .Pp
  502. Primary development and maintenance from 1990 to the present by
  503. Christos Zoulas
  504. .Aq .
  505. .Pp
  506. Altered by Chris Lowth
  507. .Aq ,
  508. 2000: handle the
  509. .Fl i
  510. option to output mime type strings, using an alternative
  511. magic file and internal logic.
  512. .Pp
  513. Altered by Eric Fischer
  514. .Aq ,
  515. July, 2000,
  516. to identify character codes and attempt to identify the languages
  517. of non-ASCII files.
  518. .Pp
  519. Altered by Reuben Thomas
  520. .Aq ,
  521. 2007-2011, to improve MIME support, merge MIME and non-MIME magic,
  522. support directories as well as files of magic, apply many bug fixes,
  523. update and fix a lot of magic, improve the build system, improve the
  524. documentation, and rewrite the Python bindings in pure Python.
  525. .Pp
  526. The list of contributors to the
  527. .Sq magic
  528. directory (magic files)
  529. is too long to include here.
  530. You know who you are; thank you.
  531. Many contributors are listed in the source files.
  533. Copyright (c) Ian F. Darwin, Toronto, Canada, 1986-1999.
  534. Covered by the standard Berkeley Software Distribution copyright; see the file
  535. COPYING in the source distribution.
  536. .Pp
  537. The files
  538. .Pa tar.h
  539. and
  540. .Pa is_tar.c
  541. were written by John Gilmore from his public-domain
  542. .Xr tar 1
  543. program, and are not covered by the above license.
  544. .Sh RETURN CODE
  545. .Nm
  546. returns 0 on success, and non-zero on error.
  547. .Sh BUGS
  548. .Pp
  549. Please report bugs and send patches to the bug tracker at
  550. .Pa
  551. or the mailing list at
  552. .Aq .
  553. .Sh TODO
  554. .Pp
  555. Fix output so that tests for MIME and APPLE flags are not needed all
  556. over the place, and actual output is only done in one place.
  557. This needs a design.
  558. Suggestion: push possible outputs on to a list, then pick the
  559. last-pushed (most specific, one hopes) value at the end, or
  560. use a default if the list is empty.
  561. This should not slow down evaluation.
  562. .Pp
  563. Continue to squash all magic bugs.
  564. See Debian BTS for a good source.
  565. .Pp
  566. Store arbitrarily long strings, for example for %s patterns, so that
  567. they can be printed out.
  568. Fixes Debian bug #271672.
  569. Would require more complex store/load code in apprentice.
  570. .Pp
  571. Add syntax for relative offsets after current level (Debian bug #466037).
  572. .Pp
  573. Make file -ki work, i.e. give multiple MIME types.
  574. .Pp
  575. Add a zip library so we can peek inside Office2007 documents to
  576. figure out what they are.
  577. .Pp
  578. Add an option to print URLs for the sources of the file descriptions.
  579. .Pp
  580. Combine script searches and add a way to map executable names to MIME
  581. types (e.g. have a magic value for !:mime which causes the resulting
  582. string to be looked up in a table).
  583. This would avoid adding the same magic repeatedly for each new
  584. hash-bang interpreter.
  585. .Pp
  586. Fix
  587. .Dq name
  588. and
  589. .Dq use
  590. to check for consistency at compile time (duplicate
  591. .Dq name ,
  592. .Dq use
  593. pointing to undefined
  594. .Dq name
  595. ).
  596. Make
  597. .Dq name
  598. /
  599. .Dq use
  600. more efficient by keeping a sorted list of names.
  601. Special-case ^ to flip endianness in the parser so that it does not
  602. have to be escaped, and document it.
  604. You can obtain the original author's latest version by anonymous FTP
  605. on
  606. .Pa
  607. in the directory
  608. .Pa /pub/file/file-X.YZ.tar.gz .