softmagic.c 58 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526
  1. /*
  2. * Copyright (c) Ian F. Darwin 1986-1995.
  3. * Software written by Ian F. Darwin and others;
  4. * maintained 1995-present by Christos Zoulas and others.
  5. *
  6. * Redistribution and use in source and binary forms, with or without
  7. * modification, are permitted provided that the following conditions
  8. * are met:
  9. * 1. Redistributions of source code must retain the above copyright
  10. * notice immediately at the beginning of the file, without modification,
  11. * this list of conditions, and the following disclaimer.
  12. * 2. Redistributions in binary form must reproduce the above copyright
  13. * notice, this list of conditions and the following disclaimer in the
  14. * documentation and/or other materials provided with the distribution.
  15. *
  16. * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
  17. * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
  18. * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
  19. * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR
  20. * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
  21. * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
  22. * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
  23. * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
  24. * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
  25. * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
  26. * SUCH DAMAGE.
  27. */
  28. /*
  29. * softmagic - interpret variable magic from MAGIC
  30. */
  31. #include "file.h"
  32. #ifndef lint
  33. FILE_RCSID("@(#)$File: softmagic.c,v 1.350 2024/11/27 15:37:00 christos Exp $")
  34. #endif /* lint */
  35. #include "magic.h"
  36. #include <assert.h>
  37. #include <math.h>
  38. #include <string.h>
  39. #include <ctype.h>
  40. #include <stdlib.h>
  41. #include <limits.h>
  42. #include <time.h>
  43. #include "der.h"
  44. file_private int match(struct magic_set *, struct magic *, file_regex_t **, size_t,
  45. const struct buffer *, size_t, int, int, int, uint16_t *,
  46. uint16_t *, int *, int *, int *, int *, int *);
  47. file_private int mget(struct magic_set *, struct magic *, const struct buffer *,
  48. const unsigned char *, size_t,
  49. size_t, unsigned int, int, int, int, uint16_t *,
  50. uint16_t *, int *, int *, int *, int *, int *);
  51. file_private int msetoffset(struct magic_set *, struct magic *, struct buffer *,
  52. const struct buffer *, size_t, unsigned int);
  53. file_private int magiccheck(struct magic_set *, struct magic *, file_regex_t **);
  54. file_private int mprint(struct magic_set *, struct magic *);
  55. file_private int moffset(struct magic_set *, struct magic *,
  56. const struct buffer *, size_t, int32_t *);
  57. file_private void mdebug(uint32_t, const char *, size_t);
  58. file_private int mcopy(struct magic_set *, union VALUETYPE *, int, int,
  59. const unsigned char *, uint32_t, size_t, struct magic *);
  60. file_private int mconvert(struct magic_set *, struct magic *, int);
  61. file_private int print_sep(struct magic_set *, int);
  62. file_private int handle_annotation(struct magic_set *, struct magic *, int);
  63. file_private int cvt_8(union VALUETYPE *, const struct magic *);
  64. file_private int cvt_16(union VALUETYPE *, const struct magic *);
  65. file_private int cvt_32(union VALUETYPE *, const struct magic *);
  66. file_private int cvt_64(union VALUETYPE *, const struct magic *);
  67. #define OFFSET_OOB(n, o, i) ((n) < CAST(uint32_t, (o)) || (i) > ((n) - (o)))
  68. #define BE64(p) ( \
  69. (CAST(uint64_t, (p)[0])<<56)| \
  70. (CAST(uint64_t, (p)[1])<<48)| \
  71. (CAST(uint64_t, (p)[2])<<40)| \
  72. (CAST(uint64_t, (p)[3])<<32)| \
  73. (CAST(uint64_t, (p)[4])<<24)| \
  74. (CAST(uint64_t, (p)[5])<<16)| \
  75. (CAST(uint64_t, (p)[6])<<8)| \
  76. (CAST(uint64_t, (p)[7])))
  77. #define LE64(p) ( \
  78. (CAST(uint64_t, (p)[7])<<56)| \
  79. (CAST(uint64_t, (p)[6])<<48)| \
  80. (CAST(uint64_t, (p)[5])<<40)| \
  81. (CAST(uint64_t, (p)[4])<<32)| \
  82. (CAST(uint64_t, (p)[3])<<24)| \
  83. (CAST(uint64_t, (p)[2])<<16)| \
  84. (CAST(uint64_t, (p)[1])<<8)| \
  85. (CAST(uint64_t, (p)[0])))
  86. #define LE32(p) ( \
  87. (CAST(uint32_t, (p)[3])<<24)| \
  88. (CAST(uint32_t, (p)[2])<<16)| \
  89. (CAST(uint32_t, (p)[1])<<8)| \
  90. (CAST(uint32_t, (p)[0])))
  91. #define BE32(p) ( \
  92. (CAST(uint32_t, (p)[0])<<24)| \
  93. (CAST(uint32_t, (p)[1])<<16)| \
  94. (CAST(uint32_t, (p)[2])<<8)| \
  95. (CAST(uint32_t, (p)[3])))
  96. #define ME32(p) ( \
  97. (CAST(uint32_t, (p)[1])<<24)| \
  98. (CAST(uint32_t, (p)[0])<<16)| \
  99. (CAST(uint32_t, (p)[3])<<8)| \
  100. (CAST(uint32_t, (p)[2])))
  101. #define BE16(p) ((CAST(uint16_t, (p)[0])<<8)|(CAST(uint16_t, (p)[1])))
  102. #define LE16(p) ((CAST(uint16_t, (p)[1])<<8)|(CAST(uint16_t, (p)[0])))
  103. #define SEXT(s,v,p) ((s) ? \
  104. CAST(intmax_t, CAST(int##v##_t, p)) : \
  105. CAST(intmax_t, CAST(uint##v##_t, p)))
  106. /*
  107. * softmagic - lookup one file in parsed, in-memory copy of database
  108. * Passed the name and FILE * of one file to be typed.
  109. */
  110. /*ARGSUSED1*/ /* nbytes passed for regularity, maybe need later */
  111. file_protected int
  112. file_softmagic(struct magic_set *ms, const struct buffer *b,
  113. uint16_t *indir_count, uint16_t *name_count, int mode, int text)
  114. {
  115. struct mlist *ml;
  116. int rv = 0, printed_something = 0, need_separator = 0, firstline = 1;
  117. uint16_t nc, ic;
  118. if (name_count == NULL) {
  119. nc = 0;
  120. name_count = &nc;
  121. }
  122. if (indir_count == NULL) {
  123. ic = 0;
  124. indir_count = &ic;
  125. }
  126. for (ml = ms->mlist[0]->next; ml != ms->mlist[0]; ml = ml->next) {
  127. int ret = match(ms, ml->magic, ml->magic_rxcomp, ml->nmagic, b,
  128. 0, mode, text, 0, indir_count, name_count,
  129. &printed_something, &need_separator, &firstline,
  130. NULL, NULL);
  131. switch (ret) {
  132. case -1:
  133. return ret;
  134. case 0:
  135. continue;
  136. default:
  137. if ((ms->flags & MAGIC_CONTINUE) == 0)
  138. return ret;
  139. rv = ret;
  140. break;
  141. }
  142. }
  143. return rv;
  144. }
  145. #define FILE_FMTDEBUG
  146. #ifdef FILE_FMTDEBUG
  147. #define F(a, b, c) file_fmtcheck((a), (b), (c), __FILE__, __LINE__)
  148. file_private const char * __attribute__((__format_arg__(3)))
  149. file_fmtcheck(struct magic_set *ms, const char *desc, const char *def,
  150. const char *file, size_t line)
  151. {
  152. const char *ptr;
  153. if (strchr(desc, '%') == NULL)
  154. return desc;
  155. ptr = fmtcheck(desc, def);
  156. if (ptr == def)
  157. file_magerror(ms,
  158. "%s, %" SIZE_T_FORMAT "u: format `%s' does not match"
  159. " with `%s'", file, line, desc, def);
  160. return ptr;
  161. }
  162. #else
  163. #define F(a, b, c) fmtcheck((b), (c))
  164. #endif
  165. /*
  166. * Go through the whole list, stopping if you find a match. Process all
  167. * the continuations of that match before returning.
  168. *
  169. * We support multi-level continuations:
  170. *
  171. * At any time when processing a successful top-level match, there is a
  172. * current continuation level; it represents the level of the last
  173. * successfully matched continuation.
  174. *
  175. * Continuations above that level are skipped as, if we see one, it
  176. * means that the continuation that controls them - i.e, the
  177. * lower-level continuation preceding them - failed to match.
  178. *
  179. * Continuations below that level are processed as, if we see one,
  180. * it means we've finished processing or skipping higher-level
  181. * continuations under the control of a successful or unsuccessful
  182. * lower-level continuation, and are now seeing the next lower-level
  183. * continuation and should process it. The current continuation
  184. * level reverts to the level of the one we're seeing.
  185. *
  186. * Continuations at the current level are processed as, if we see
  187. * one, there's no lower-level continuation that may have failed.
  188. *
  189. * If a continuation matches, we bump the current continuation level
  190. * so that higher-level continuations are processed.
  191. */
  192. file_private int
  193. match(struct magic_set *ms, struct magic *magic, file_regex_t **magic_rxcomp,
  194. size_t nmagic, const struct buffer *b, size_t offset, int mode, int text,
  195. int flip, uint16_t *indir_count, uint16_t *name_count,
  196. int *printed_something, int *need_separator, int *firstline,
  197. int *returnval, int *found_match)
  198. {
  199. uint32_t magindex = 0;
  200. unsigned int cont_level = 0;
  201. int found_matchv = 0; /* if a match is found it is set to 1*/
  202. int returnvalv = 0, e;
  203. struct buffer bb;
  204. int print = (ms->flags & MAGIC_NODESC) == 0;
  205. /*
  206. * returnval can be 0 if a match is found, but there was no
  207. * annotation to be printed.
  208. */
  209. if (returnval == NULL)
  210. returnval = &returnvalv;
  211. if (found_match == NULL)
  212. found_match = &found_matchv;
  213. if (file_check_mem(ms, cont_level) == -1)
  214. return -1;
  215. for (magindex = 0; magindex < nmagic; magindex++) {
  216. int flush = 0;
  217. struct magic *m = &magic[magindex];
  218. file_regex_t **m_rxcomp = &magic_rxcomp[magindex];
  219. if (m->type != FILE_NAME)
  220. if ((IS_STRING(m->type) &&
  221. #define FLT (STRING_BINTEST | STRING_TEXTTEST)
  222. ((text && (m->str_flags & FLT) == STRING_BINTEST) ||
  223. (!text && (m->str_flags & FLT) == STRING_TEXTTEST))) ||
  224. (m->flag & mode) != mode) {
  225. flush:
  226. /* Skip sub-tests */
  227. while (magindex < nmagic - 1 &&
  228. magic[magindex + 1].cont_level != 0)
  229. magindex++;
  230. cont_level = 0;
  231. continue; /* Skip to next top-level test*/
  232. }
  233. if (msetoffset(ms, m, &bb, b, offset, cont_level) == -1)
  234. goto flush;
  235. ms->line = m->lineno;
  236. /* if main entry matches, print it... */
  237. switch (mget(ms, m, b, CAST(const unsigned char *, bb.fbuf),
  238. bb.flen, offset, cont_level,
  239. mode, text, flip, indir_count, name_count,
  240. printed_something, need_separator, firstline, returnval,
  241. found_match))
  242. {
  243. case -1:
  244. return -1;
  245. case 0:
  246. flush = m->reln != '!';
  247. break;
  248. default:
  249. if (m->type == FILE_INDIRECT) {
  250. *found_match = 1;
  251. *returnval = 1;
  252. }
  253. switch (magiccheck(ms, m, m_rxcomp)) {
  254. case -1:
  255. return -1;
  256. case 0:
  257. flush++;
  258. break;
  259. default:
  260. flush = 0;
  261. break;
  262. }
  263. break;
  264. }
  265. if (flush) {
  266. /*
  267. * main entry didn't match,
  268. * flush its continuations
  269. */
  270. goto flush;
  271. }
  272. if ((e = handle_annotation(ms, m, *firstline)) != 0)
  273. {
  274. *found_match = 1;
  275. *need_separator = 1;
  276. *printed_something = 1;
  277. *returnval = 1;
  278. *firstline = 0;
  279. return e;
  280. }
  281. /*
  282. * If we are going to print something, we'll need to print
  283. * a blank before we print something else.
  284. */
  285. if (*m->desc) {
  286. *found_match = 1;
  287. if (print) {
  288. *returnval = 1;
  289. *need_separator = 1;
  290. *printed_something = 1;
  291. if (print_sep(ms, *firstline) == -1)
  292. return -1;
  293. if (mprint(ms, m) == -1)
  294. return -1;
  295. }
  296. }
  297. switch (moffset(ms, m, &bb, offset, &ms->c.li[cont_level].off)) {
  298. case -1:
  299. case 0:
  300. goto flush;
  301. default:
  302. break;
  303. }
  304. /* and any continuations that match */
  305. if (file_check_mem(ms, ++cont_level) == -1)
  306. return -1;
  307. while (magindex + 1 < nmagic &&
  308. magic[magindex + 1].cont_level != 0) {
  309. m = &magic[++magindex];
  310. m_rxcomp = &magic_rxcomp[magindex];
  311. ms->line = m->lineno; /* for messages */
  312. if (cont_level < m->cont_level)
  313. continue;
  314. if (cont_level > m->cont_level) {
  315. /*
  316. * We're at the end of the level
  317. * "cont_level" continuations.
  318. */
  319. cont_level = m->cont_level;
  320. }
  321. if (msetoffset(ms, m, &bb, b, offset, cont_level) == -1)
  322. goto flush;
  323. if (m->flag & OFFADD) {
  324. if (cont_level == 0) {
  325. if ((ms->flags & MAGIC_DEBUG) != 0)
  326. fprintf(stderr,
  327. "direct *zero*"
  328. " cont_level\n");
  329. return 0;
  330. }
  331. ms->offset +=
  332. ms->c.li[cont_level - 1].off;
  333. }
  334. #ifdef ENABLE_CONDITIONALS
  335. if (m->cond == COND_ELSE ||
  336. m->cond == COND_ELIF) {
  337. if (ms->c.li[cont_level].last_match == 1)
  338. continue;
  339. }
  340. #endif
  341. switch (mget(ms, m, b, CAST(const unsigned char *,
  342. bb.fbuf), bb.flen, offset,
  343. cont_level, mode, text, flip, indir_count,
  344. name_count, printed_something, need_separator,
  345. firstline, returnval, found_match)) {
  346. case -1:
  347. return -1;
  348. case 0:
  349. if (m->reln != '!')
  350. continue;
  351. flush = 1;
  352. break;
  353. default:
  354. if (m->type == FILE_INDIRECT) {
  355. *found_match = 1;
  356. *returnval = 1;
  357. }
  358. flush = 0;
  359. break;
  360. }
  361. switch (flush ? 1 : magiccheck(ms, m, m_rxcomp)) {
  362. case -1:
  363. return -1;
  364. case 0:
  365. #ifdef ENABLE_CONDITIONALS
  366. ms->c.li[cont_level].last_match = 0;
  367. #endif
  368. break;
  369. default:
  370. #ifdef ENABLE_CONDITIONALS
  371. ms->c.li[cont_level].last_match = 1;
  372. #endif
  373. if (m->type == FILE_CLEAR)
  374. ms->c.li[cont_level].got_match = 0;
  375. else if (ms->c.li[cont_level].got_match) {
  376. if (m->type == FILE_DEFAULT)
  377. break;
  378. } else
  379. ms->c.li[cont_level].got_match = 1;
  380. if ((e = handle_annotation(ms, m, *firstline))
  381. != 0) {
  382. *found_match = 1;
  383. *need_separator = 1;
  384. *printed_something = 1;
  385. *returnval = 1;
  386. return e;
  387. }
  388. if (*m->desc) {
  389. *found_match = 1;
  390. }
  391. if (print && *m->desc) {
  392. *returnval = 1;
  393. /*
  394. * This continuation matched. Print
  395. * its message, with a blank before it
  396. * if the previous item printed and
  397. * this item isn't empty.
  398. */
  399. /*
  400. * If we are going to print something,
  401. * make sure that we have a separator
  402. * first.
  403. */
  404. if (!*printed_something) {
  405. *printed_something = 1;
  406. if (print_sep(ms, *firstline)
  407. == -1)
  408. return -1;
  409. }
  410. /* space if previous printed */
  411. if (*need_separator
  412. && (m->flag & NOSPACE) == 0) {
  413. if (file_printf(ms, " ") == -1)
  414. return -1;
  415. }
  416. if (mprint(ms, m) == -1)
  417. return -1;
  418. *need_separator = 1;
  419. }
  420. switch (moffset(ms, m, &bb, offset,
  421. &ms->c.li[cont_level].off)) {
  422. case -1:
  423. case 0:
  424. cont_level--;
  425. break;
  426. default:
  427. break;
  428. }
  429. /*
  430. * If we see any continuations
  431. * at a higher level,
  432. * process them.
  433. */
  434. if (file_check_mem(ms, ++cont_level) == -1)
  435. return -1;
  436. break;
  437. }
  438. }
  439. if (*printed_something) {
  440. *firstline = 0;
  441. }
  442. if (*found_match) {
  443. if ((ms->flags & MAGIC_CONTINUE) == 0)
  444. return *returnval;
  445. // So that we print a separator
  446. *printed_something = 0;
  447. *firstline = 0;
  448. }
  449. cont_level = 0;
  450. }
  451. return *returnval;
  452. }
  453. file_private int
  454. check_fmt(struct magic_set *ms, const char *fmt)
  455. {
  456. file_regex_t rx;
  457. int rc, rv = -1;
  458. const char* pat = "%[-0-9\\.]*s";
  459. if (strchr(fmt, '%') == NULL)
  460. return 0;
  461. rc = file_regcomp(ms, &rx, pat, REG_EXTENDED|REG_NOSUB);
  462. if (rc == 0) {
  463. rc = file_regexec(ms, &rx, fmt, 0, 0, 0);
  464. rv = !rc;
  465. }
  466. file_regfree(&rx);
  467. return rv;
  468. }
  469. #if !defined(HAVE_STRNDUP) || defined(__aiws__) || defined(_AIX)
  470. # if defined(__aiws__) || defined(_AIX)
  471. # define strndup aix_strndup /* aix is broken */
  472. # endif
  473. char *strndup(const char *, size_t);
  474. char *
  475. strndup(const char *str, size_t n)
  476. {
  477. size_t len;
  478. char *copy;
  479. for (len = 0; len < n && str[len]; len++)
  480. continue;
  481. if ((copy = CAST(char *, malloc(len + 1))) == NULL)
  482. return NULL;
  483. (void)memcpy(copy, str, len);
  484. copy[len] = '\0';
  485. return copy;
  486. }
  487. #endif /* HAVE_STRNDUP */
  488. static int
  489. varexpand(struct magic_set *ms, char *buf, size_t len, const char *str)
  490. {
  491. const char *ptr, *sptr, *e, *t, *ee, *et;
  492. size_t l;
  493. for (sptr = str; (ptr = strstr(sptr, "${")) != NULL;) {
  494. l = CAST(size_t, ptr - sptr);
  495. if (l >= len)
  496. return -1;
  497. memcpy(buf, sptr, l);
  498. buf += l;
  499. len -= l;
  500. ptr += 2;
  501. if (!*ptr || ptr[1] != '?')
  502. return -1;
  503. for (et = t = ptr + 2; *et && *et != ':'; et++)
  504. continue;
  505. if (*et != ':')
  506. return -1;
  507. for (ee = e = et + 1; *ee && *ee != '}'; ee++)
  508. continue;
  509. if (*ee != '}')
  510. return -1;
  511. switch (*ptr) {
  512. case 'x':
  513. if (ms->mode & 0111) {
  514. ptr = t;
  515. l = et - t;
  516. } else {
  517. ptr = e;
  518. l = ee - e;
  519. }
  520. break;
  521. default:
  522. return -1;
  523. }
  524. if (l >= len)
  525. return -1;
  526. memcpy(buf, ptr, l);
  527. buf += l;
  528. len -= l;
  529. sptr = ee + 1;
  530. }
  531. l = strlen(sptr);
  532. if (l >= len)
  533. return -1;
  534. memcpy(buf, sptr, l);
  535. buf[l] = '\0';
  536. return 0;
  537. }
  538. file_private int
  539. mprint(struct magic_set *ms, struct magic *m)
  540. {
  541. uint64_t v;
  542. float vf;
  543. double vd;
  544. char buf[128], tbuf[26], sbuf[512], ebuf[512];
  545. const char *desc;
  546. union VALUETYPE *p = &ms->ms_value;
  547. if (varexpand(ms, ebuf, sizeof(ebuf), m->desc) == -1)
  548. desc = m->desc;
  549. else
  550. desc = ebuf;
  551. #define PRINTER(value, format, stype, utype) \
  552. v = file_signextend(ms, m, CAST(uint64_t, value)); \
  553. switch (check_fmt(ms, desc)) { \
  554. case -1: \
  555. return -1; \
  556. case 1: \
  557. if (m->flag & UNSIGNED) { \
  558. (void)snprintf(buf, sizeof(buf), "%" format "u", \
  559. CAST(utype, v)); \
  560. } else { \
  561. (void)snprintf(buf, sizeof(buf), "%" format "d", \
  562. CAST(stype, v)); \
  563. } \
  564. if (file_printf(ms, F(ms, desc, "%s"), buf) == -1) \
  565. return -1; \
  566. break; \
  567. default: \
  568. if (m->flag & UNSIGNED) { \
  569. if (file_printf(ms, F(ms, desc, "%" format "u"), \
  570. CAST(utype, v)) == -1) \
  571. return -1; \
  572. } else { \
  573. if (file_printf(ms, F(ms, desc, "%" format "d"), \
  574. CAST(stype, v)) == -1) \
  575. return -1; \
  576. } \
  577. break; \
  578. } \
  579. break
  580. switch (m->type) {
  581. case FILE_BYTE:
  582. PRINTER(p->b, "", int8_t, uint8_t);
  583. case FILE_SHORT:
  584. case FILE_BESHORT:
  585. case FILE_LESHORT:
  586. PRINTER(p->h, "", int16_t, uint16_t);
  587. case FILE_LONG:
  588. case FILE_BELONG:
  589. case FILE_LELONG:
  590. case FILE_MELONG:
  591. PRINTER(p->l, "", int32_t, uint32_t);
  592. case FILE_QUAD:
  593. case FILE_BEQUAD:
  594. case FILE_LEQUAD:
  595. case FILE_OFFSET:
  596. PRINTER(p->q, INT64_T_FORMAT, long long, unsigned long long);
  597. case FILE_STRING:
  598. case FILE_PSTRING:
  599. case FILE_BESTRING16:
  600. case FILE_LESTRING16:
  601. if (m->reln == '=' || m->reln == '!') {
  602. if (file_printf(ms, F(ms, desc, "%s"),
  603. file_printable(ms, sbuf, sizeof(sbuf), m->value.s,
  604. sizeof(m->value.s))) == -1)
  605. return -1;
  606. }
  607. else {
  608. char *str = p->s;
  609. /* compute t before we mangle the string? */
  610. if (*m->value.s == '\0')
  611. str[strcspn(str, "\r\n")] = '\0';
  612. if (m->str_flags & STRING_TRIM)
  613. str = file_strtrim(str);
  614. if (file_printf(ms, F(ms, desc, "%s"),
  615. file_printable(ms, sbuf, sizeof(sbuf), str,
  616. sizeof(p->s) - (str - p->s))) == -1)
  617. return -1;
  618. if (m->type == FILE_PSTRING) {
  619. size_t l = file_pstring_length_size(ms, m);
  620. if (l == FILE_BADSIZE)
  621. return -1;
  622. }
  623. }
  624. break;
  625. case FILE_DATE:
  626. case FILE_BEDATE:
  627. case FILE_LEDATE:
  628. case FILE_MEDATE:
  629. if (file_printf(ms, F(ms, desc, "%s"),
  630. file_fmtdatetime(tbuf, sizeof(tbuf), p->l, 0)) == -1)
  631. return -1;
  632. break;
  633. case FILE_LDATE:
  634. case FILE_BELDATE:
  635. case FILE_LELDATE:
  636. case FILE_MELDATE:
  637. if (file_printf(ms, F(ms, desc, "%s"),
  638. file_fmtdatetime(tbuf, sizeof(tbuf), p->l, FILE_T_LOCAL))
  639. == -1)
  640. return -1;
  641. break;
  642. case FILE_QDATE:
  643. case FILE_BEQDATE:
  644. case FILE_LEQDATE:
  645. if (file_printf(ms, F(ms, desc, "%s"),
  646. file_fmtdatetime(tbuf, sizeof(tbuf), p->q, 0)) == -1)
  647. return -1;
  648. break;
  649. case FILE_QLDATE:
  650. case FILE_BEQLDATE:
  651. case FILE_LEQLDATE:
  652. if (file_printf(ms, F(ms, desc, "%s"),
  653. file_fmtdatetime(tbuf, sizeof(tbuf), p->q, FILE_T_LOCAL)) == -1)
  654. return -1;
  655. break;
  656. case FILE_QWDATE:
  657. case FILE_BEQWDATE:
  658. case FILE_LEQWDATE:
  659. if (file_printf(ms, F(ms, desc, "%s"),
  660. file_fmtdatetime(tbuf, sizeof(tbuf), p->q, FILE_T_WINDOWS))
  661. == -1)
  662. return -1;
  663. break;
  664. case FILE_FLOAT:
  665. case FILE_BEFLOAT:
  666. case FILE_LEFLOAT:
  667. vf = p->f;
  668. switch (check_fmt(ms, desc)) {
  669. case -1:
  670. return -1;
  671. case 1:
  672. (void)snprintf(buf, sizeof(buf), "%g", vf);
  673. if (file_printf(ms, F(ms, desc, "%s"), buf) == -1)
  674. return -1;
  675. break;
  676. default:
  677. if (file_printf(ms, F(ms, desc, "%g"), vf) == -1)
  678. return -1;
  679. break;
  680. }
  681. break;
  682. case FILE_DOUBLE:
  683. case FILE_BEDOUBLE:
  684. case FILE_LEDOUBLE:
  685. vd = p->d;
  686. switch (check_fmt(ms, desc)) {
  687. case -1:
  688. return -1;
  689. case 1:
  690. (void)snprintf(buf, sizeof(buf), "%g", vd);
  691. if (file_printf(ms, F(ms, desc, "%s"), buf) == -1)
  692. return -1;
  693. break;
  694. default:
  695. if (file_printf(ms, F(ms, desc, "%g"), vd) == -1)
  696. return -1;
  697. break;
  698. }
  699. break;
  700. case FILE_SEARCH:
  701. case FILE_REGEX: {
  702. char *cp, *scp;
  703. int rval;
  704. cp = strndup(RCAST(const char *, ms->search.s),
  705. ms->search.rm_len);
  706. if (cp == NULL) {
  707. file_oomem(ms, ms->search.rm_len);
  708. return -1;
  709. }
  710. scp = (m->str_flags & STRING_TRIM) ? file_strtrim(cp) : cp;
  711. rval = file_printf(ms, F(ms, desc, "%s"), file_printable(ms,
  712. sbuf, sizeof(sbuf), scp, ms->search.rm_len));
  713. free(cp);
  714. if (rval == -1)
  715. return -1;
  716. break;
  717. }
  718. case FILE_DEFAULT:
  719. case FILE_CLEAR:
  720. if (file_printf(ms, "%s", m->desc) == -1)
  721. return -1;
  722. break;
  723. case FILE_INDIRECT:
  724. case FILE_USE:
  725. case FILE_NAME:
  726. break;
  727. case FILE_DER:
  728. if (file_printf(ms, F(ms, desc, "%s"),
  729. file_printable(ms, sbuf, sizeof(sbuf), ms->ms_value.s,
  730. sizeof(ms->ms_value.s))) == -1)
  731. return -1;
  732. break;
  733. case FILE_GUID:
  734. (void) file_print_guid(buf, sizeof(buf), ms->ms_value.guid);
  735. if (file_printf(ms, F(ms, desc, "%s"), buf) == -1)
  736. return -1;
  737. break;
  738. case FILE_MSDOSDATE:
  739. case FILE_BEMSDOSDATE:
  740. case FILE_LEMSDOSDATE:
  741. if (file_printf(ms, F(ms, desc, "%s"),
  742. file_fmtdate(tbuf, sizeof(tbuf), p->h)) == -1)
  743. return -1;
  744. break;
  745. case FILE_MSDOSTIME:
  746. case FILE_BEMSDOSTIME:
  747. case FILE_LEMSDOSTIME:
  748. if (file_printf(ms, F(ms, desc, "%s"),
  749. file_fmttime(tbuf, sizeof(tbuf), p->h)) == -1)
  750. return -1;
  751. break;
  752. case FILE_OCTAL:
  753. file_fmtnum(buf, sizeof(buf), m->value.s, 8);
  754. if (file_printf(ms, F(ms, desc, "%s"), buf) == -1)
  755. return -1;
  756. break;
  757. default:
  758. file_magerror(ms, "invalid m->type (%d) in mprint()", m->type);
  759. return -1;
  760. }
  761. return 0;
  762. }
  763. file_private int
  764. moffset(struct magic_set *ms, struct magic *m, const struct buffer *b,
  765. size_t offset, int32_t *op)
  766. {
  767. size_t nbytes = b->flen;
  768. int32_t o;
  769. switch (m->type) {
  770. case FILE_BYTE:
  771. o = CAST(int32_t, (ms->offset + sizeof(char)));
  772. break;
  773. case FILE_SHORT:
  774. case FILE_BESHORT:
  775. case FILE_LESHORT:
  776. case FILE_MSDOSDATE:
  777. case FILE_LEMSDOSDATE:
  778. case FILE_BEMSDOSDATE:
  779. case FILE_MSDOSTIME:
  780. case FILE_LEMSDOSTIME:
  781. case FILE_BEMSDOSTIME:
  782. o = CAST(int32_t, (ms->offset + sizeof(short)));
  783. break;
  784. case FILE_LONG:
  785. case FILE_BELONG:
  786. case FILE_LELONG:
  787. case FILE_MELONG:
  788. o = CAST(int32_t, (ms->offset + sizeof(int32_t)));
  789. break;
  790. case FILE_QUAD:
  791. case FILE_BEQUAD:
  792. case FILE_LEQUAD:
  793. o = CAST(int32_t, (ms->offset + sizeof(int64_t)));
  794. break;
  795. case FILE_STRING:
  796. case FILE_PSTRING:
  797. case FILE_BESTRING16:
  798. case FILE_LESTRING16:
  799. case FILE_OCTAL:
  800. if (m->reln == '=' || m->reln == '!') {
  801. o = ms->offset + m->vallen;
  802. } else {
  803. union VALUETYPE *p = &ms->ms_value;
  804. if (*m->value.s == '\0')
  805. p->s[strcspn(p->s, "\r\n")] = '\0';
  806. o = CAST(uint32_t, (ms->offset + strlen(p->s)));
  807. if (m->type == FILE_PSTRING) {
  808. size_t l = file_pstring_length_size(ms, m);
  809. if (l == FILE_BADSIZE)
  810. return -1;
  811. o += CAST(uint32_t, l);
  812. }
  813. }
  814. break;
  815. case FILE_DATE:
  816. case FILE_BEDATE:
  817. case FILE_LEDATE:
  818. case FILE_MEDATE:
  819. o = CAST(int32_t, (ms->offset + sizeof(uint32_t)));
  820. break;
  821. case FILE_LDATE:
  822. case FILE_BELDATE:
  823. case FILE_LELDATE:
  824. case FILE_MELDATE:
  825. o = CAST(int32_t, (ms->offset + sizeof(uint32_t)));
  826. break;
  827. case FILE_QDATE:
  828. case FILE_BEQDATE:
  829. case FILE_LEQDATE:
  830. o = CAST(int32_t, (ms->offset + sizeof(uint64_t)));
  831. break;
  832. case FILE_QLDATE:
  833. case FILE_BEQLDATE:
  834. case FILE_LEQLDATE:
  835. o = CAST(int32_t, (ms->offset + sizeof(uint64_t)));
  836. break;
  837. case FILE_FLOAT:
  838. case FILE_BEFLOAT:
  839. case FILE_LEFLOAT:
  840. o = CAST(int32_t, (ms->offset + sizeof(float)));
  841. break;
  842. case FILE_DOUBLE:
  843. case FILE_BEDOUBLE:
  844. case FILE_LEDOUBLE:
  845. o = CAST(int32_t, (ms->offset + sizeof(double)));
  846. break;
  847. case FILE_REGEX:
  848. if ((m->str_flags & REGEX_OFFSET_START) != 0)
  849. o = CAST(int32_t, ms->search.offset - offset);
  850. else
  851. o = CAST(int32_t,
  852. (ms->search.offset + ms->search.rm_len - offset));
  853. break;
  854. case FILE_SEARCH:
  855. if ((m->str_flags & REGEX_OFFSET_START) != 0)
  856. o = CAST(int32_t, ms->search.offset - offset);
  857. else
  858. o = CAST(int32_t, (ms->search.offset + m->vallen - offset));
  859. break;
  860. case FILE_CLEAR:
  861. case FILE_DEFAULT:
  862. case FILE_INDIRECT:
  863. case FILE_OFFSET:
  864. case FILE_USE:
  865. o = ms->offset;
  866. break;
  867. case FILE_DER:
  868. o = der_offs(ms, m, nbytes);
  869. if (o == -1 || CAST(size_t, o) > nbytes) {
  870. if ((ms->flags & MAGIC_DEBUG) != 0) {
  871. (void)fprintf(stderr,
  872. "Bad DER offset %d nbytes=%"
  873. SIZE_T_FORMAT "u", o, nbytes);
  874. }
  875. *op = 0;
  876. return 0;
  877. }
  878. break;
  879. case FILE_GUID:
  880. o = CAST(int32_t, (ms->offset + 2 * sizeof(uint64_t)));
  881. break;
  882. default:
  883. o = 0;
  884. break;
  885. }
  886. if (CAST(size_t, o) > nbytes) {
  887. #if 0
  888. file_error(ms, 0, "Offset out of range %" SIZE_T_FORMAT
  889. "u > %" SIZE_T_FORMAT "u", (size_t)o, nbytes);
  890. #endif
  891. return -1;
  892. }
  893. *op = o;
  894. return 1;
  895. }
  896. file_private uint32_t
  897. cvt_id3(struct magic_set *ms, uint32_t v)
  898. {
  899. v = ((((v >> 0) & 0x7f) << 0) |
  900. (((v >> 8) & 0x7f) << 7) |
  901. (((v >> 16) & 0x7f) << 14) |
  902. (((v >> 24) & 0x7f) << 21));
  903. if ((ms->flags & MAGIC_DEBUG) != 0)
  904. fprintf(stderr, "id3 offs=%u\n", v);
  905. return v;
  906. }
  907. file_private int
  908. cvt_flip(int type, int flip)
  909. {
  910. if (flip == 0)
  911. return type;
  912. switch (type) {
  913. case FILE_BESHORT:
  914. return FILE_LESHORT;
  915. case FILE_BELONG:
  916. return FILE_LELONG;
  917. case FILE_BEDATE:
  918. return FILE_LEDATE;
  919. case FILE_BELDATE:
  920. return FILE_LELDATE;
  921. case FILE_BEQUAD:
  922. return FILE_LEQUAD;
  923. case FILE_BEQDATE:
  924. return FILE_LEQDATE;
  925. case FILE_BEQLDATE:
  926. return FILE_LEQLDATE;
  927. case FILE_BEQWDATE:
  928. return FILE_LEQWDATE;
  929. case FILE_LESHORT:
  930. return FILE_BESHORT;
  931. case FILE_LELONG:
  932. return FILE_BELONG;
  933. case FILE_LEDATE:
  934. return FILE_BEDATE;
  935. case FILE_LELDATE:
  936. return FILE_BELDATE;
  937. case FILE_LEQUAD:
  938. return FILE_BEQUAD;
  939. case FILE_LEQDATE:
  940. return FILE_BEQDATE;
  941. case FILE_LEQLDATE:
  942. return FILE_BEQLDATE;
  943. case FILE_LEQWDATE:
  944. return FILE_BEQWDATE;
  945. case FILE_BEFLOAT:
  946. return FILE_LEFLOAT;
  947. case FILE_LEFLOAT:
  948. return FILE_BEFLOAT;
  949. case FILE_BEDOUBLE:
  950. return FILE_LEDOUBLE;
  951. case FILE_LEDOUBLE:
  952. return FILE_BEDOUBLE;
  953. default:
  954. return type;
  955. }
  956. }
  957. #define DO_CVT(fld, type) \
  958. if (m->num_mask) \
  959. switch (m->mask_op & FILE_OPS_MASK) { \
  960. case FILE_OPAND: \
  961. p->fld &= CAST(type, m->num_mask); \
  962. break; \
  963. case FILE_OPOR: \
  964. p->fld |= CAST(type, m->num_mask); \
  965. break; \
  966. case FILE_OPXOR: \
  967. p->fld ^= CAST(type, m->num_mask); \
  968. break; \
  969. case FILE_OPADD: \
  970. p->fld += CAST(type, m->num_mask); \
  971. break; \
  972. case FILE_OPMINUS: \
  973. p->fld -= CAST(type, m->num_mask); \
  974. break; \
  975. case FILE_OPMULTIPLY: \
  976. p->fld *= CAST(type, m->num_mask); \
  977. break; \
  978. case FILE_OPDIVIDE: \
  979. if (CAST(type, m->num_mask) == 0) \
  980. return -1; \
  981. p->fld /= CAST(type, m->num_mask); \
  982. break; \
  983. case FILE_OPMODULO: \
  984. if (CAST(type, m->num_mask) == 0) \
  985. return -1; \
  986. p->fld %= CAST(type, m->num_mask); \
  987. break; \
  988. } \
  989. if (m->mask_op & FILE_OPINVERSE) \
  990. p->fld = ~p->fld \
  991. file_private int
  992. cvt_8(union VALUETYPE *p, const struct magic *m)
  993. {
  994. DO_CVT(b, uint8_t);
  995. return 0;
  996. }
  997. file_private int
  998. cvt_16(union VALUETYPE *p, const struct magic *m)
  999. {
  1000. DO_CVT(h, uint16_t);
  1001. return 0;
  1002. }
  1003. file_private int
  1004. cvt_32(union VALUETYPE *p, const struct magic *m)
  1005. {
  1006. DO_CVT(l, uint32_t);
  1007. return 0;
  1008. }
  1009. file_private int
  1010. cvt_64(union VALUETYPE *p, const struct magic *m)
  1011. {
  1012. DO_CVT(q, uint64_t);
  1013. return 0;
  1014. }
  1015. #define DO_CVT2(fld, type) \
  1016. if (m->num_mask) \
  1017. switch (m->mask_op & FILE_OPS_MASK) { \
  1018. case FILE_OPADD: \
  1019. p->fld += CAST(type, m->num_mask); \
  1020. break; \
  1021. case FILE_OPMINUS: \
  1022. p->fld -= CAST(type, m->num_mask); \
  1023. break; \
  1024. case FILE_OPMULTIPLY: \
  1025. p->fld *= CAST(type, m->num_mask); \
  1026. break; \
  1027. case FILE_OPDIVIDE: \
  1028. if (CAST(type, m->num_mask) == 0) \
  1029. return -1; \
  1030. p->fld /= CAST(type, m->num_mask); \
  1031. break; \
  1032. } \
  1033. file_private int
  1034. cvt_float(union VALUETYPE *p, const struct magic *m)
  1035. {
  1036. DO_CVT2(f, float);
  1037. return 0;
  1038. }
  1039. file_private int
  1040. cvt_double(union VALUETYPE *p, const struct magic *m)
  1041. {
  1042. DO_CVT2(d, double);
  1043. return 0;
  1044. }
  1045. /*
  1046. * Convert the byte order of the data we are looking at
  1047. * While we're here, let's apply the mask operation
  1048. * (unless you have a better idea)
  1049. */
  1050. file_private int
  1051. mconvert(struct magic_set *ms, struct magic *m, int flip)
  1052. {
  1053. union VALUETYPE *p = &ms->ms_value;
  1054. switch (cvt_flip(m->type, flip)) {
  1055. case FILE_BYTE:
  1056. if (cvt_8(p, m) == -1)
  1057. goto out;
  1058. return 1;
  1059. case FILE_SHORT:
  1060. case FILE_MSDOSDATE:
  1061. case FILE_LEMSDOSDATE:
  1062. case FILE_BEMSDOSDATE:
  1063. case FILE_MSDOSTIME:
  1064. case FILE_LEMSDOSTIME:
  1065. case FILE_BEMSDOSTIME:
  1066. if (cvt_16(p, m) == -1)
  1067. goto out;
  1068. return 1;
  1069. case FILE_LONG:
  1070. case FILE_DATE:
  1071. case FILE_LDATE:
  1072. if (cvt_32(p, m) == -1)
  1073. goto out;
  1074. return 1;
  1075. case FILE_QUAD:
  1076. case FILE_QDATE:
  1077. case FILE_QLDATE:
  1078. case FILE_QWDATE:
  1079. case FILE_OFFSET:
  1080. if (cvt_64(p, m) == -1)
  1081. goto out;
  1082. return 1;
  1083. case FILE_STRING:
  1084. case FILE_BESTRING16:
  1085. case FILE_LESTRING16:
  1086. case FILE_OCTAL: {
  1087. /* Null terminate and eat *trailing* return */
  1088. p->s[sizeof(p->s) - 1] = '\0';
  1089. return 1;
  1090. }
  1091. case FILE_PSTRING: {
  1092. char *ptr1, *ptr2;
  1093. size_t len, sz = file_pstring_length_size(ms, m);
  1094. if (sz == FILE_BADSIZE)
  1095. return 0;
  1096. ptr1 = p->s;
  1097. ptr2 = ptr1 + sz;
  1098. len = file_pstring_get_length(ms, m, ptr1);
  1099. if (len == FILE_BADSIZE)
  1100. return 0;
  1101. sz = sizeof(p->s) - sz; /* maximum length of string */
  1102. if (len >= sz) {
  1103. /*
  1104. * The size of the pascal string length (sz)
  1105. * is 1, 2, or 4. We need at least 1 byte for NUL
  1106. * termination, but we've already truncated the
  1107. * string by p->s, so we need to deduct sz.
  1108. * Because we can use one of the bytes of the length
  1109. * after we shifted as NUL termination.
  1110. */
  1111. len = sz;
  1112. }
  1113. while (len--)
  1114. *ptr1++ = *ptr2++;
  1115. *ptr1 = '\0';
  1116. return 1;
  1117. }
  1118. case FILE_BESHORT:
  1119. p->h = CAST(short, BE16(p->hs));
  1120. if (cvt_16(p, m) == -1)
  1121. goto out;
  1122. return 1;
  1123. case FILE_BELONG:
  1124. case FILE_BEDATE:
  1125. case FILE_BELDATE:
  1126. p->l = CAST(int32_t, BE32(p->hl));
  1127. if (cvt_32(p, m) == -1)
  1128. goto out;
  1129. return 1;
  1130. case FILE_BEQUAD:
  1131. case FILE_BEQDATE:
  1132. case FILE_BEQLDATE:
  1133. case FILE_BEQWDATE:
  1134. p->q = CAST(uint64_t, BE64(p->hq));
  1135. if (cvt_64(p, m) == -1)
  1136. goto out;
  1137. return 1;
  1138. case FILE_LESHORT:
  1139. p->h = CAST(short, LE16(p->hs));
  1140. if (cvt_16(p, m) == -1)
  1141. goto out;
  1142. return 1;
  1143. case FILE_LELONG:
  1144. case FILE_LEDATE:
  1145. case FILE_LELDATE:
  1146. p->l = CAST(int32_t, LE32(p->hl));
  1147. if (cvt_32(p, m) == -1)
  1148. goto out;
  1149. return 1;
  1150. case FILE_LEQUAD:
  1151. case FILE_LEQDATE:
  1152. case FILE_LEQLDATE:
  1153. case FILE_LEQWDATE:
  1154. p->q = CAST(uint64_t, LE64(p->hq));
  1155. if (cvt_64(p, m) == -1)
  1156. goto out;
  1157. return 1;
  1158. case FILE_MELONG:
  1159. case FILE_MEDATE:
  1160. case FILE_MELDATE:
  1161. p->l = CAST(int32_t, ME32(p->hl));
  1162. if (cvt_32(p, m) == -1)
  1163. goto out;
  1164. return 1;
  1165. case FILE_FLOAT:
  1166. if (cvt_float(p, m) == -1)
  1167. goto out;
  1168. return 1;
  1169. case FILE_BEFLOAT:
  1170. p->l = BE32(p->hl);
  1171. if (cvt_float(p, m) == -1)
  1172. goto out;
  1173. return 1;
  1174. case FILE_LEFLOAT:
  1175. p->l = LE32(p->hl);
  1176. if (cvt_float(p, m) == -1)
  1177. goto out;
  1178. return 1;
  1179. case FILE_DOUBLE:
  1180. if (cvt_double(p, m) == -1)
  1181. goto out;
  1182. return 1;
  1183. case FILE_BEDOUBLE:
  1184. p->q = BE64(p->hq);
  1185. if (cvt_double(p, m) == -1)
  1186. goto out;
  1187. return 1;
  1188. case FILE_LEDOUBLE:
  1189. p->q = LE64(p->hq);
  1190. if (cvt_double(p, m) == -1)
  1191. goto out;
  1192. return 1;
  1193. case FILE_REGEX:
  1194. case FILE_SEARCH:
  1195. case FILE_DEFAULT:
  1196. case FILE_CLEAR:
  1197. case FILE_NAME:
  1198. case FILE_USE:
  1199. case FILE_DER:
  1200. case FILE_GUID:
  1201. return 1;
  1202. default:
  1203. file_magerror(ms, "invalid type %d in mconvert()", m->type);
  1204. return 0;
  1205. }
  1206. out:
  1207. file_magerror(ms, "zerodivide in mconvert()");
  1208. return 0;
  1209. }
  1210. file_private void
  1211. mdebug(uint32_t offset, const char *str, size_t len)
  1212. {
  1213. (void) fprintf(stderr, "mget/%" SIZE_T_FORMAT "u @%d: ", len, offset);
  1214. file_showstr(stderr, str, len);
  1215. (void) fputc('\n', stderr);
  1216. (void) fputc('\n', stderr);
  1217. }
  1218. file_private int
  1219. mcopy(struct magic_set *ms, union VALUETYPE *p, int type, int indir,
  1220. const unsigned char *s, uint32_t offset, size_t nbytes, struct magic *m)
  1221. {
  1222. size_t size = sizeof(*p);
  1223. /*
  1224. * Note: FILE_SEARCH and FILE_REGEX do not actually copy
  1225. * anything, but setup pointers into the source
  1226. */
  1227. if (indir == 0) {
  1228. switch (type) {
  1229. case FILE_DER:
  1230. case FILE_SEARCH:
  1231. if (offset > nbytes)
  1232. offset = CAST(uint32_t, nbytes);
  1233. ms->search.s = RCAST(const char *, s) + offset;
  1234. ms->search.s_len = nbytes - offset;
  1235. ms->search.offset = offset;
  1236. return 0;
  1237. case FILE_REGEX: {
  1238. const char *b;
  1239. const char *c;
  1240. const char *last; /* end of search region */
  1241. const char *buf; /* start of search region */
  1242. const char *end;
  1243. size_t lines, linecnt, bytecnt;
  1244. if (s == NULL || nbytes < offset) {
  1245. ms->search.s_len = 0;
  1246. ms->search.s = NULL;
  1247. return 0;
  1248. }
  1249. if (m->str_flags & REGEX_LINE_COUNT) {
  1250. linecnt = m->str_range;
  1251. bytecnt = linecnt * 80;
  1252. } else {
  1253. linecnt = 0;
  1254. bytecnt = m->str_range;
  1255. }
  1256. if (bytecnt == 0 || bytecnt > nbytes - offset)
  1257. bytecnt = nbytes - offset;
  1258. if (bytecnt > ms->regex_max)
  1259. bytecnt = ms->regex_max;
  1260. buf = RCAST(const char *, s) + offset;
  1261. end = last = RCAST(const char *, s) + bytecnt + offset;
  1262. /* mget() guarantees buf <= last */
  1263. for (lines = linecnt, b = buf; lines && b < end &&
  1264. ((b = CAST(const char *,
  1265. memchr(c = b, '\n', CAST(size_t, (end - b)))))
  1266. || (b = CAST(const char *,
  1267. memchr(c, '\r', CAST(size_t, (end - c))))));
  1268. lines--, b++) {
  1269. if (b < end - 1 && b[0] == '\r' && b[1] == '\n')
  1270. b++;
  1271. if (b < end - 1 && b[0] == '\n')
  1272. b++;
  1273. last = b;
  1274. }
  1275. if (lines)
  1276. last = end;
  1277. ms->search.s = buf;
  1278. ms->search.s_len = last - buf;
  1279. ms->search.offset = offset;
  1280. ms->search.rm_len = 0;
  1281. return 0;
  1282. }
  1283. case FILE_BESTRING16:
  1284. case FILE_LESTRING16: {
  1285. const unsigned char *src = s + offset;
  1286. const unsigned char *esrc = s + nbytes;
  1287. char *dst = p->s;
  1288. char *edst = &p->s[sizeof(p->s) - 1];
  1289. if (type == FILE_BESTRING16)
  1290. src++;
  1291. /* check that offset is within range */
  1292. if (offset >= nbytes)
  1293. break;
  1294. for (/*EMPTY*/; src < esrc; src += 2, dst++) {
  1295. if (dst < edst)
  1296. *dst = *src;
  1297. else
  1298. break;
  1299. if (*dst == '\0') {
  1300. if (type == FILE_BESTRING16 ?
  1301. *(src - 1) != '\0' :
  1302. ((src + 1 < esrc) &&
  1303. *(src + 1) != '\0'))
  1304. *dst = ' ';
  1305. }
  1306. }
  1307. *edst = '\0';
  1308. *dst = '\0';
  1309. return 0;
  1310. }
  1311. case FILE_STRING: /* XXX - these two should not need */
  1312. case FILE_PSTRING: /* to copy anything, but do anyway. */
  1313. if (m->str_range != 0 && m->str_range < sizeof(*p))
  1314. size = m->str_range;
  1315. break;
  1316. default:
  1317. break;
  1318. }
  1319. }
  1320. if (type == FILE_OFFSET) {
  1321. (void)memset(p, '\0', sizeof(*p));
  1322. p->q = offset;
  1323. return 0;
  1324. }
  1325. if (offset >= nbytes) {
  1326. (void)memset(p, '\0', sizeof(*p));
  1327. return 0;
  1328. }
  1329. if (nbytes - offset < size)
  1330. nbytes = nbytes - offset;
  1331. else
  1332. nbytes = size;
  1333. (void)memcpy(p, s + offset, nbytes);
  1334. /*
  1335. * the usefulness of padding with zeroes eludes me, it
  1336. * might even cause problems
  1337. */
  1338. if (nbytes < sizeof(*p))
  1339. (void)memset(RCAST(char *, RCAST(void *, p)) + nbytes, '\0',
  1340. sizeof(*p) - nbytes);
  1341. return 0;
  1342. }
  1343. file_private int
  1344. do_ops(struct magic_set *ms, struct magic *m, uint32_t *rv, intmax_t lhs,
  1345. intmax_t off)
  1346. {
  1347. intmax_t offset;
  1348. // On purpose not INTMAX_MAX
  1349. if (lhs >= UINT_MAX || lhs <= INT_MIN ||
  1350. off >= UINT_MAX || off <= INT_MIN) {
  1351. if ((ms->flags & MAGIC_DEBUG) != 0)
  1352. fprintf(stderr, "lhs/off overflow %jd %jd\n", lhs, off);
  1353. return 1;
  1354. }
  1355. if (off) {
  1356. switch (m->in_op & FILE_OPS_MASK) {
  1357. case FILE_OPAND:
  1358. offset = lhs & off;
  1359. break;
  1360. case FILE_OPOR:
  1361. offset = lhs | off;
  1362. break;
  1363. case FILE_OPXOR:
  1364. offset = lhs ^ off;
  1365. break;
  1366. case FILE_OPADD:
  1367. offset = lhs + off;
  1368. break;
  1369. case FILE_OPMINUS:
  1370. offset = lhs - off;
  1371. break;
  1372. case FILE_OPMULTIPLY:
  1373. offset = lhs * off;
  1374. break;
  1375. case FILE_OPDIVIDE:
  1376. offset = lhs / off;
  1377. break;
  1378. case FILE_OPMODULO:
  1379. offset = lhs % off;
  1380. break;
  1381. }
  1382. } else
  1383. offset = lhs;
  1384. if (m->in_op & FILE_OPINVERSE)
  1385. offset = ~offset;
  1386. if (offset >= UINT_MAX) {
  1387. if ((ms->flags & MAGIC_DEBUG) != 0)
  1388. fprintf(stderr, "offset overflow %jd\n", offset);
  1389. return 1;
  1390. }
  1391. *rv = CAST(uint32_t, offset);
  1392. return 0;
  1393. }
  1394. file_private int
  1395. msetoffset(struct magic_set *ms, struct magic *m, struct buffer *bb,
  1396. const struct buffer *b, size_t o, unsigned int cont_level)
  1397. {
  1398. int32_t offset;
  1399. if (m->flag & OFFNEGATIVE) {
  1400. offset = -m->offset;
  1401. if (cont_level > 0) {
  1402. if (m->flag & (OFFADD|INDIROFFADD))
  1403. goto normal;
  1404. #if 0
  1405. file_error(ms, 0, "negative offset %d at continuation"
  1406. "level %u", m->offset, cont_level);
  1407. return -1;
  1408. #endif
  1409. }
  1410. if (buffer_fill(b) == -1)
  1411. return -1;
  1412. if (o != 0) {
  1413. // Not yet!
  1414. file_magerror(ms, "non zero offset %" SIZE_T_FORMAT
  1415. "u at level %u", o, cont_level);
  1416. return -1;
  1417. }
  1418. if (CAST(size_t, m->offset) > b->elen)
  1419. return -1;
  1420. buffer_init(bb, -1, NULL, b->ebuf, b->elen);
  1421. ms->eoffset = ms->offset = CAST(int32_t, b->elen - m->offset);
  1422. } else {
  1423. offset = m->offset;
  1424. if ((m->flag & OFFPOSITIVE) || cont_level == 0) {
  1425. normal:
  1426. // XXX: Pass real fd, then who frees bb?
  1427. buffer_init(bb, -1, NULL, b->fbuf, b->flen);
  1428. ms->offset = offset;
  1429. ms->eoffset = 0;
  1430. } else {
  1431. ms->offset = ms->eoffset + offset;
  1432. }
  1433. }
  1434. if ((ms->flags & MAGIC_DEBUG) != 0) {
  1435. fprintf(stderr, "bb=[%p,%" SIZE_T_FORMAT "u,%"
  1436. SIZE_T_FORMAT "u], %d [b=%p,%"
  1437. SIZE_T_FORMAT "u,%" SIZE_T_FORMAT "u], [o=%#x, c=%d]\n",
  1438. bb->fbuf, bb->flen, bb->elen, ms->offset, b->fbuf,
  1439. b->flen, b->elen, offset, cont_level);
  1440. }
  1441. return 0;
  1442. }
  1443. file_private int
  1444. save_cont(struct magic_set *ms, struct cont *c)
  1445. {
  1446. size_t len;
  1447. *c = ms->c;
  1448. len = c->len * sizeof(*c->li);
  1449. ms->c.li = CAST(struct level_info *, malloc(len));
  1450. if (ms->c.li == NULL) {
  1451. ms->c = *c;
  1452. return -1;
  1453. }
  1454. memcpy(ms->c.li, c->li, len);
  1455. return 0;
  1456. }
  1457. file_private void
  1458. restore_cont(struct magic_set *ms, struct cont *c)
  1459. {
  1460. free(ms->c.li);
  1461. ms->c = *c;
  1462. }
  1463. file_private int
  1464. mget(struct magic_set *ms, struct magic *m, const struct buffer *b,
  1465. const unsigned char *s, size_t nbytes, size_t o, unsigned int cont_level,
  1466. int mode, int text, int flip, uint16_t *indir_count, uint16_t *name_count,
  1467. int *printed_something, int *need_separator, int *firstline, int *returnval,
  1468. int *found_match)
  1469. {
  1470. uint32_t eoffset, offset = ms->offset;
  1471. struct buffer bb;
  1472. intmax_t lhs;
  1473. file_pushbuf_t *pb;
  1474. int rv, oneed_separator, in_type, nfound_match;
  1475. char *rbuf;
  1476. union VALUETYPE *p = &ms->ms_value;
  1477. struct mlist ml, *mlp;
  1478. struct cont c;
  1479. if (*indir_count >= ms->indir_max) {
  1480. file_error(ms, 0, "indirect count (%hu) exceeded",
  1481. *indir_count);
  1482. return -1;
  1483. }
  1484. if (*name_count >= ms->name_max) {
  1485. file_error(ms, 0, "name use count (%hu) exceeded",
  1486. *name_count);
  1487. return -1;
  1488. }
  1489. if (mcopy(ms, p, m->type, m->flag & INDIR, s,
  1490. CAST(uint32_t, offset + o), CAST(uint32_t, nbytes), m) == -1)
  1491. return -1;
  1492. if ((ms->flags & MAGIC_DEBUG) != 0) {
  1493. fprintf(stderr, "mget(type=%d, flag=%#x, offset=%u, o=%"
  1494. SIZE_T_FORMAT "u, " "nbytes=%" SIZE_T_FORMAT
  1495. "u, il=%hu, nc=%hu)\n",
  1496. m->type, m->flag, offset, o, nbytes,
  1497. *indir_count, *name_count);
  1498. mdebug(offset, RCAST(char *, RCAST(void *, p)),
  1499. sizeof(union VALUETYPE));
  1500. #ifndef COMPILE_ONLY
  1501. file_mdump(m);
  1502. #endif
  1503. }
  1504. if (m->flag & INDIR) {
  1505. intmax_t off = m->in_offset;
  1506. const int sgn = m->in_op & FILE_OPSIGNED;
  1507. if (m->in_op & FILE_OPINDIRECT) {
  1508. uint8_t *hb = CCAST(uint8_t *, s + offset + off);
  1509. uint16_t hs;
  1510. uint32_t hl;
  1511. int op;
  1512. switch (op = cvt_flip(m->in_type, flip)) {
  1513. case FILE_BYTE:
  1514. if (OFFSET_OOB(nbytes, offset + off, 1))
  1515. return 0;
  1516. off = SEXT(sgn,8,hb[0]);
  1517. break;
  1518. case FILE_SHORT:
  1519. if (OFFSET_OOB(nbytes, offset + off, 2))
  1520. return 0;
  1521. memcpy(&hs, hb, sizeof(hs));
  1522. off = SEXT(sgn,16,hs);
  1523. break;
  1524. case FILE_BESHORT:
  1525. if (OFFSET_OOB(nbytes, offset + off, 2))
  1526. return 0;
  1527. off = SEXT(sgn,16,BE16(hb));
  1528. break;
  1529. case FILE_LESHORT:
  1530. if (OFFSET_OOB(nbytes, offset + off, 2))
  1531. return 0;
  1532. off = SEXT(sgn,16,LE16(hb));
  1533. break;
  1534. case FILE_LONG:
  1535. if (OFFSET_OOB(nbytes, offset + off, 4))
  1536. return 0;
  1537. memcpy(&hl, hb, sizeof(hl));
  1538. off = SEXT(sgn,32,hl);
  1539. break;
  1540. case FILE_BELONG:
  1541. case FILE_BEID3:
  1542. if (OFFSET_OOB(nbytes, offset + off, 4))
  1543. return 0;
  1544. off = SEXT(sgn,32,BE32(hb));
  1545. break;
  1546. case FILE_LEID3:
  1547. case FILE_LELONG:
  1548. if (OFFSET_OOB(nbytes, offset + off, 4))
  1549. return 0;
  1550. off = SEXT(sgn,32,LE32(hb));
  1551. break;
  1552. case FILE_MELONG:
  1553. if (OFFSET_OOB(nbytes, offset + off, 4))
  1554. return 0;
  1555. off = SEXT(sgn,32,ME32(hb));
  1556. break;
  1557. case FILE_BEQUAD:
  1558. if (OFFSET_OOB(nbytes, offset + off, 8))
  1559. return 0;
  1560. off = SEXT(sgn,64,BE64(hb));
  1561. break;
  1562. case FILE_LEQUAD:
  1563. if (OFFSET_OOB(nbytes, offset + off, 8))
  1564. return 0;
  1565. off = SEXT(sgn,64,LE64(hb));
  1566. break;
  1567. case FILE_OCTAL:
  1568. if (OFFSET_OOB(nbytes, offset, m->vallen))
  1569. return 0;
  1570. off = SEXT(sgn,64,strtoull(p->s, NULL, 8));
  1571. break;
  1572. default:
  1573. if ((ms->flags & MAGIC_DEBUG) != 0)
  1574. fprintf(stderr, "bad op=%d\n", op);
  1575. return 0;
  1576. }
  1577. if ((ms->flags & MAGIC_DEBUG) != 0)
  1578. fprintf(stderr, "indirect offs=%jd\n", off);
  1579. }
  1580. switch (in_type = cvt_flip(m->in_type, flip)) {
  1581. case FILE_BYTE:
  1582. if (OFFSET_OOB(nbytes, offset, 1))
  1583. return 0;
  1584. if (do_ops(ms, m, &offset, SEXT(sgn,8,p->b), off))
  1585. return 0;
  1586. break;
  1587. case FILE_BESHORT:
  1588. if (OFFSET_OOB(nbytes, offset, 2))
  1589. return 0;
  1590. if (do_ops(ms, m, &offset, SEXT(sgn,16,BE16(p->hs)), off))
  1591. return 0;
  1592. break;
  1593. case FILE_LESHORT:
  1594. if (OFFSET_OOB(nbytes, offset, 2))
  1595. return 0;
  1596. if (do_ops(ms, m, &offset, SEXT(sgn,16,LE16(p->hs)), off))
  1597. return 0;
  1598. break;
  1599. case FILE_SHORT:
  1600. if (OFFSET_OOB(nbytes, offset, 2))
  1601. return 0;
  1602. if (do_ops(ms, m, &offset, SEXT(sgn,16,p->h), off))
  1603. return 0;
  1604. break;
  1605. case FILE_BELONG:
  1606. case FILE_BEID3:
  1607. if (OFFSET_OOB(nbytes, offset, 4))
  1608. return 0;
  1609. lhs = BE32(p->hl);
  1610. if (in_type == FILE_BEID3)
  1611. lhs = cvt_id3(ms, CAST(uint32_t, lhs));
  1612. if (do_ops(ms, m, &offset, SEXT(sgn,32,lhs), off))
  1613. return 0;
  1614. break;
  1615. case FILE_LELONG:
  1616. case FILE_LEID3:
  1617. if (OFFSET_OOB(nbytes, offset, 4))
  1618. return 0;
  1619. lhs = LE32(p->hl);
  1620. if (in_type == FILE_LEID3)
  1621. lhs = cvt_id3(ms, CAST(uint32_t, lhs));
  1622. if (do_ops(ms, m, &offset, SEXT(sgn,32,lhs), off))
  1623. return 0;
  1624. break;
  1625. case FILE_MELONG:
  1626. if (OFFSET_OOB(nbytes, offset, 4))
  1627. return 0;
  1628. if (do_ops(ms, m, &offset, SEXT(sgn,32,ME32(p->hl)), off))
  1629. return 0;
  1630. break;
  1631. case FILE_LONG:
  1632. if (OFFSET_OOB(nbytes, offset, 4))
  1633. return 0;
  1634. if (do_ops(ms, m, &offset, SEXT(sgn,32,p->l), off))
  1635. return 0;
  1636. break;
  1637. case FILE_LEQUAD:
  1638. if (OFFSET_OOB(nbytes, offset, 8))
  1639. return 0;
  1640. if (do_ops(ms, m, &offset, SEXT(sgn,64,LE64(p->hq)), off))
  1641. return 0;
  1642. break;
  1643. case FILE_BEQUAD:
  1644. if (OFFSET_OOB(nbytes, offset, 8))
  1645. return 0;
  1646. if (do_ops(ms, m, &offset, SEXT(sgn,64,BE64(p->hq)), off))
  1647. return 0;
  1648. break;
  1649. case FILE_OCTAL:
  1650. if (OFFSET_OOB(nbytes, offset, m->vallen))
  1651. return 0;
  1652. if(do_ops(ms, m, &offset,
  1653. SEXT(sgn,64,strtoull(p->s, NULL, 8)), off))
  1654. return 0;
  1655. break;
  1656. default:
  1657. if ((ms->flags & MAGIC_DEBUG) != 0)
  1658. fprintf(stderr, "bad in_type=%d\n", in_type);
  1659. return 0;
  1660. }
  1661. if (m->flag & INDIROFFADD) {
  1662. if (cont_level == 0) {
  1663. if ((ms->flags & MAGIC_DEBUG) != 0)
  1664. fprintf(stderr,
  1665. "indirect *zero* cont_level\n");
  1666. return 0;
  1667. }
  1668. offset += ms->c.li[cont_level - 1].off;
  1669. if (offset == 0) {
  1670. if ((ms->flags & MAGIC_DEBUG) != 0)
  1671. fprintf(stderr,
  1672. "indirect *zero* offset\n");
  1673. return 0;
  1674. }
  1675. if ((ms->flags & MAGIC_DEBUG) != 0)
  1676. fprintf(stderr, "indirect +offs=%u\n", offset);
  1677. }
  1678. if (mcopy(ms, p, m->type, 0, s, offset, nbytes, m) == -1)
  1679. return -1;
  1680. ms->offset = offset;
  1681. if ((ms->flags & MAGIC_DEBUG) != 0) {
  1682. mdebug(offset, RCAST(char *, RCAST(void *, p)),
  1683. sizeof(union VALUETYPE));
  1684. #ifndef COMPILE_ONLY
  1685. file_mdump(m);
  1686. #endif
  1687. }
  1688. }
  1689. /* Verify we have enough data to match magic type */
  1690. switch (m->type) {
  1691. case FILE_BYTE:
  1692. if (OFFSET_OOB(nbytes, offset, 1))
  1693. return 0;
  1694. break;
  1695. case FILE_SHORT:
  1696. case FILE_BESHORT:
  1697. case FILE_LESHORT:
  1698. if (OFFSET_OOB(nbytes, offset, 2))
  1699. return 0;
  1700. break;
  1701. case FILE_LONG:
  1702. case FILE_BELONG:
  1703. case FILE_LELONG:
  1704. case FILE_MELONG:
  1705. case FILE_DATE:
  1706. case FILE_BEDATE:
  1707. case FILE_LEDATE:
  1708. case FILE_MEDATE:
  1709. case FILE_LDATE:
  1710. case FILE_BELDATE:
  1711. case FILE_LELDATE:
  1712. case FILE_MELDATE:
  1713. case FILE_FLOAT:
  1714. case FILE_BEFLOAT:
  1715. case FILE_LEFLOAT:
  1716. if (OFFSET_OOB(nbytes, offset, 4))
  1717. return 0;
  1718. break;
  1719. case FILE_DOUBLE:
  1720. case FILE_BEDOUBLE:
  1721. case FILE_LEDOUBLE:
  1722. if (OFFSET_OOB(nbytes, offset, 8))
  1723. return 0;
  1724. break;
  1725. case FILE_GUID:
  1726. if (OFFSET_OOB(nbytes, offset, 16))
  1727. return 0;
  1728. break;
  1729. case FILE_STRING:
  1730. case FILE_PSTRING:
  1731. case FILE_SEARCH:
  1732. case FILE_OCTAL:
  1733. if (OFFSET_OOB(nbytes, offset, m->vallen))
  1734. return 0;
  1735. break;
  1736. case FILE_REGEX:
  1737. if (nbytes < offset)
  1738. return 0;
  1739. break;
  1740. case FILE_INDIRECT:
  1741. if (m->str_flags & INDIRECT_RELATIVE)
  1742. offset += CAST(uint32_t, o);
  1743. if (offset == 0)
  1744. return 0;
  1745. if (nbytes < offset)
  1746. return 0;
  1747. if ((pb = file_push_buffer(ms)) == NULL)
  1748. return -1;
  1749. (*indir_count)++;
  1750. bb = *b;
  1751. bb.fbuf = s + offset;
  1752. bb.flen = nbytes - offset;
  1753. bb.ebuf = NULL;
  1754. bb.elen = 0;
  1755. rv = -1;
  1756. for (mlp = ms->mlist[0]->next; mlp != ms->mlist[0];
  1757. mlp = mlp->next)
  1758. {
  1759. if ((rv = match(ms, mlp->magic, mlp->magic_rxcomp,
  1760. mlp->nmagic, &bb, 0, BINTEST, text, 0, indir_count,
  1761. name_count, printed_something, need_separator,
  1762. firstline, NULL, NULL)) != 0)
  1763. break;
  1764. }
  1765. buffer_fini(&bb);
  1766. if ((ms->flags & MAGIC_DEBUG) != 0)
  1767. fprintf(stderr, "indirect @offs=%u[%d]\n", offset, rv);
  1768. rbuf = file_pop_buffer(ms, pb);
  1769. if (rbuf == NULL && ms->event_flags & EVENT_HAD_ERR)
  1770. return -1;
  1771. if (rv == 1) {
  1772. if ((ms->flags & MAGIC_NODESC) == 0 &&
  1773. file_printf(ms, F(ms, m->desc, "%u"), offset) == -1)
  1774. {
  1775. free(rbuf);
  1776. return -1;
  1777. }
  1778. if (file_printf(ms, "%s", rbuf) == -1) {
  1779. free(rbuf);
  1780. return -1;
  1781. }
  1782. }
  1783. free(rbuf);
  1784. return rv;
  1785. case FILE_USE:
  1786. if (nbytes < offset)
  1787. return 0;
  1788. rbuf = m->value.s;
  1789. if (*rbuf == '^') {
  1790. rbuf++;
  1791. flip = !flip;
  1792. }
  1793. if (file_magicfind(ms, rbuf, &ml) == -1) {
  1794. file_error(ms, 0, "cannot find entry `%s'", rbuf);
  1795. return -1;
  1796. }
  1797. if (save_cont(ms, &c) == -1) {
  1798. file_error(ms, errno, "can't allocate continuation");
  1799. return -1;
  1800. }
  1801. oneed_separator = *need_separator;
  1802. if (m->flag & NOSPACE)
  1803. *need_separator = 0;
  1804. nfound_match = 0;
  1805. (*name_count)++;
  1806. eoffset = ms->eoffset;
  1807. rv = match(ms, ml.magic, ml.magic_rxcomp, ml.nmagic, b,
  1808. offset + o, mode, text, flip, indir_count, name_count,
  1809. printed_something, need_separator, firstline, returnval,
  1810. &nfound_match);
  1811. ms->ms_value.q = nfound_match;
  1812. (*name_count)--;
  1813. *found_match |= nfound_match;
  1814. restore_cont(ms, &c);
  1815. if (rv != 1)
  1816. *need_separator = oneed_separator;
  1817. ms->offset = offset;
  1818. ms->eoffset = eoffset;
  1819. return rv || *found_match;
  1820. case FILE_NAME:
  1821. if (ms->flags & MAGIC_NODESC)
  1822. return 1;
  1823. if (file_printf(ms, "%s", m->desc) == -1)
  1824. return -1;
  1825. return 1;
  1826. case FILE_DER:
  1827. case FILE_DEFAULT: /* nothing to check */
  1828. case FILE_CLEAR:
  1829. default:
  1830. break;
  1831. }
  1832. if (!mconvert(ms, m, flip))
  1833. return 0;
  1834. return 1;
  1835. }
  1836. file_private uint64_t
  1837. file_strncmp(const char *s1, const char *s2, size_t len, size_t maxlen,
  1838. uint32_t flags)
  1839. {
  1840. /*
  1841. * Convert the source args to unsigned here so that (1) the
  1842. * compare will be unsigned as it is in strncmp() and (2) so
  1843. * the ctype functions will work correctly without extra
  1844. * casting.
  1845. */
  1846. const unsigned char *a = RCAST(const unsigned char *, s1);
  1847. const unsigned char *b = RCAST(const unsigned char *, s2);
  1848. uint32_t ws = flags & (STRING_COMPACT_WHITESPACE |
  1849. STRING_COMPACT_OPTIONAL_WHITESPACE);
  1850. const unsigned char *eb = b + (ws ? maxlen : len);
  1851. uint64_t v;
  1852. /*
  1853. * What we want here is v = strncmp(s1, s2, len),
  1854. * but ignoring any nulls.
  1855. */
  1856. v = 0;
  1857. len++;
  1858. if (0L == flags) { /* normal string: do it fast */
  1859. while (--len > 0)
  1860. if ((v = *b++ - *a++) != '\0')
  1861. break;
  1862. }
  1863. else { /* combine the others */
  1864. while (--len > 0) {
  1865. if (b >= eb) {
  1866. v = 1;
  1867. break;
  1868. }
  1869. if ((flags & STRING_IGNORE_LOWERCASE) &&
  1870. islower(*a)) {
  1871. if ((v = tolower(*b++) - *a++) != '\0')
  1872. break;
  1873. }
  1874. else if ((flags & STRING_IGNORE_UPPERCASE) &&
  1875. isupper(*a)) {
  1876. if ((v = toupper(*b++) - *a++) != '\0')
  1877. break;
  1878. }
  1879. else if ((flags & STRING_COMPACT_WHITESPACE) &&
  1880. isspace(*a)) {
  1881. a++;
  1882. if (isspace(*b)) {
  1883. b++;
  1884. if (!isspace(*a))
  1885. while (b < eb && isspace(*b))
  1886. b++;
  1887. }
  1888. else {
  1889. v = 1;
  1890. break;
  1891. }
  1892. }
  1893. else if ((flags & STRING_COMPACT_OPTIONAL_WHITESPACE) &&
  1894. isspace(*a)) {
  1895. a++;
  1896. while (b < eb && isspace(*b))
  1897. b++;
  1898. }
  1899. else {
  1900. if ((v = *b++ - *a++) != '\0')
  1901. break;
  1902. }
  1903. }
  1904. if (len == 0 && v == 0 && (flags & STRING_FULL_WORD)) {
  1905. if (*b && !isspace(*b))
  1906. v = 1;
  1907. }
  1908. }
  1909. return v;
  1910. }
  1911. file_private uint64_t
  1912. file_strncmp16(const char *a, const char *b, size_t len, size_t maxlen,
  1913. uint32_t flags)
  1914. {
  1915. /*
  1916. * XXX - The 16-bit string compare probably needs to be done
  1917. * differently, especially if the flags are to be supported.
  1918. * At the moment, I am unsure.
  1919. */
  1920. flags = 0;
  1921. return file_strncmp(a, b, len, maxlen, flags);
  1922. }
  1923. file_private file_regex_t *
  1924. alloc_regex(struct magic_set *ms, struct magic *m)
  1925. {
  1926. int rc;
  1927. file_regex_t *rx = CAST(file_regex_t *, malloc(sizeof(*rx)));
  1928. if (rx == NULL) {
  1929. file_error(ms, errno, "can't allocate %" SIZE_T_FORMAT
  1930. "u bytes", sizeof(*rx));
  1931. return NULL;
  1932. }
  1933. rc = file_regcomp(ms, rx, m->value.s, REG_EXTENDED | REG_NEWLINE |
  1934. ((m->str_flags & STRING_IGNORE_CASE) ? REG_ICASE : 0));
  1935. if (rc == 0)
  1936. return rx;
  1937. free(rx);
  1938. return NULL;
  1939. }
  1940. file_private int
  1941. magiccheck(struct magic_set *ms, struct magic *m, file_regex_t **m_cache)
  1942. {
  1943. uint64_t l = m->value.q;
  1944. uint64_t v;
  1945. float fl, fv;
  1946. double dl, dv;
  1947. int matched;
  1948. union VALUETYPE *p = &ms->ms_value;
  1949. switch (m->type) {
  1950. case FILE_BYTE:
  1951. v = p->b;
  1952. break;
  1953. case FILE_SHORT:
  1954. case FILE_BESHORT:
  1955. case FILE_LESHORT:
  1956. case FILE_MSDOSDATE:
  1957. case FILE_LEMSDOSDATE:
  1958. case FILE_BEMSDOSDATE:
  1959. case FILE_MSDOSTIME:
  1960. case FILE_LEMSDOSTIME:
  1961. case FILE_BEMSDOSTIME:
  1962. v = p->h;
  1963. break;
  1964. case FILE_LONG:
  1965. case FILE_BELONG:
  1966. case FILE_LELONG:
  1967. case FILE_MELONG:
  1968. case FILE_DATE:
  1969. case FILE_BEDATE:
  1970. case FILE_LEDATE:
  1971. case FILE_MEDATE:
  1972. case FILE_LDATE:
  1973. case FILE_BELDATE:
  1974. case FILE_LELDATE:
  1975. case FILE_MELDATE:
  1976. v = p->l;
  1977. break;
  1978. case FILE_QUAD:
  1979. case FILE_LEQUAD:
  1980. case FILE_BEQUAD:
  1981. case FILE_QDATE:
  1982. case FILE_BEQDATE:
  1983. case FILE_LEQDATE:
  1984. case FILE_QLDATE:
  1985. case FILE_BEQLDATE:
  1986. case FILE_LEQLDATE:
  1987. case FILE_QWDATE:
  1988. case FILE_BEQWDATE:
  1989. case FILE_LEQWDATE:
  1990. case FILE_OFFSET:
  1991. v = p->q;
  1992. break;
  1993. case FILE_FLOAT:
  1994. case FILE_BEFLOAT:
  1995. case FILE_LEFLOAT:
  1996. fl = m->value.f;
  1997. fv = p->f;
  1998. switch (m->reln) {
  1999. case 'x':
  2000. matched = 1;
  2001. break;
  2002. case '!':
  2003. matched = isunordered(fl, fv) ? 1 : fv != fl;
  2004. break;
  2005. case '=':
  2006. matched = isunordered(fl, fv) ? 0 : fv == fl;
  2007. break;
  2008. case '>':
  2009. matched = isgreater(fv, fl);
  2010. break;
  2011. case '<':
  2012. matched = isless(fv, fl);
  2013. break;
  2014. default:
  2015. file_magerror(ms, "cannot happen with float: "
  2016. "invalid relation `%c'", m->reln);
  2017. return -1;
  2018. }
  2019. return matched;
  2020. case FILE_DOUBLE:
  2021. case FILE_BEDOUBLE:
  2022. case FILE_LEDOUBLE:
  2023. dl = m->value.d;
  2024. dv = p->d;
  2025. switch (m->reln) {
  2026. case 'x':
  2027. matched = 1;
  2028. break;
  2029. case '!':
  2030. matched = isunordered(dv, dl) ? 1 : dv != dl;
  2031. break;
  2032. case '=':
  2033. matched = isunordered(dv, dl) ? 0 : dv == dl;
  2034. break;
  2035. case '>':
  2036. matched = isgreater(dv, dl);
  2037. break;
  2038. case '<':
  2039. matched = isless(dv, dl);
  2040. break;
  2041. default:
  2042. file_magerror(ms, "cannot happen with double: "
  2043. "invalid relation `%c'", m->reln);
  2044. return -1;
  2045. }
  2046. return matched;
  2047. case FILE_DEFAULT:
  2048. case FILE_CLEAR:
  2049. l = 0;
  2050. v = 0;
  2051. break;
  2052. case FILE_STRING:
  2053. case FILE_PSTRING:
  2054. case FILE_OCTAL:
  2055. l = 0;
  2056. v = file_strncmp(m->value.s, p->s, CAST(size_t, m->vallen),
  2057. sizeof(p->s), m->str_flags);
  2058. break;
  2059. case FILE_BESTRING16:
  2060. case FILE_LESTRING16:
  2061. l = 0;
  2062. v = file_strncmp16(m->value.s, p->s, CAST(size_t, m->vallen),
  2063. sizeof(p->s), m->str_flags);
  2064. break;
  2065. case FILE_SEARCH: { /* search ms->search.s for the string m->value.s */
  2066. size_t slen;
  2067. size_t idx;
  2068. if (ms->search.s == NULL)
  2069. return 0;
  2070. slen = MIN(m->vallen, sizeof(m->value.s));
  2071. l = 0;
  2072. v = 0;
  2073. if ((ms->flags & MAGIC_DEBUG) != 0) {
  2074. size_t xlen = ms->search.s_len > 100 ? 100
  2075. : ms->search.s_len;
  2076. fprintf(stderr, "search: [");
  2077. file_showstr(stderr, ms->search.s, xlen);
  2078. fprintf(stderr, "%s] for [", ms->search.s_len == xlen
  2079. ? "" : "...");
  2080. file_showstr(stderr, m->value.s, slen);
  2081. }
  2082. #ifdef HAVE_MEMMEM
  2083. if (slen > 0 && m->str_flags == 0) {
  2084. const char *found;
  2085. idx = m->str_range + slen;
  2086. if (m->str_range == 0 || ms->search.s_len < idx)
  2087. idx = ms->search.s_len;
  2088. found = CAST(const char *, memmem(ms->search.s, idx,
  2089. m->value.s, slen));
  2090. if ((ms->flags & MAGIC_DEBUG) != 0) {
  2091. fprintf(stderr, "] %sfound\n",
  2092. found ? "" : "not ");
  2093. }
  2094. if (!found) {
  2095. v = 1;
  2096. break;
  2097. }
  2098. idx = found - ms->search.s;
  2099. ms->search.offset += idx;
  2100. ms->search.rm_len = ms->search.s_len - idx;
  2101. break;
  2102. }
  2103. #endif
  2104. for (idx = 0; m->str_range == 0 || idx < m->str_range; idx++) {
  2105. if (slen + idx > ms->search.s_len) {
  2106. v = 1;
  2107. break;
  2108. }
  2109. v = file_strncmp(m->value.s, ms->search.s + idx, slen,
  2110. ms->search.s_len - idx, m->str_flags);
  2111. if (v == 0) { /* found match */
  2112. ms->search.offset += idx;
  2113. ms->search.rm_len = ms->search.s_len - idx;
  2114. break;
  2115. }
  2116. }
  2117. if ((ms->flags & MAGIC_DEBUG) != 0) {
  2118. fprintf(stderr, "] %sfound\n", v == 0 ? "" : "not ");
  2119. }
  2120. break;
  2121. }
  2122. case FILE_REGEX: {
  2123. int rc;
  2124. file_regex_t *rx = *m_cache;
  2125. const char *search;
  2126. regmatch_t pmatch;
  2127. size_t slen = ms->search.s_len;
  2128. char *copy;
  2129. if (ms->search.s == NULL)
  2130. return 0;
  2131. if (rx == NULL) {
  2132. rx = *m_cache = alloc_regex(ms, m);
  2133. if (rx == NULL)
  2134. return -1;
  2135. }
  2136. l = 0;
  2137. if (slen != 0) {
  2138. copy = CAST(char *, malloc(slen));
  2139. if (copy == NULL) {
  2140. file_error(ms, errno,
  2141. "can't allocate %" SIZE_T_FORMAT "u bytes",
  2142. slen);
  2143. return -1;
  2144. }
  2145. memcpy(copy, ms->search.s, slen);
  2146. copy[--slen] = '\0';
  2147. search = copy;
  2148. } else {
  2149. search = CCAST(char *, "");
  2150. copy = NULL;
  2151. }
  2152. rc = file_regexec(ms, rx, RCAST(const char *, search),
  2153. 1, &pmatch, 0);
  2154. free(copy);
  2155. switch (rc) {
  2156. case 0:
  2157. ms->search.s += CAST(int, pmatch.rm_so);
  2158. ms->search.offset += CAST(size_t, pmatch.rm_so);
  2159. ms->search.rm_len = CAST(size_t,
  2160. pmatch.rm_eo - pmatch.rm_so);
  2161. v = 0;
  2162. break;
  2163. case REG_NOMATCH:
  2164. v = 1;
  2165. break;
  2166. default:
  2167. return -1;
  2168. }
  2169. break;
  2170. }
  2171. case FILE_USE:
  2172. return ms->ms_value.q != 0;
  2173. case FILE_NAME:
  2174. case FILE_INDIRECT:
  2175. return 1;
  2176. case FILE_DER:
  2177. matched = der_cmp(ms, m);
  2178. if (matched == -1) {
  2179. if ((ms->flags & MAGIC_DEBUG) != 0) {
  2180. (void) fprintf(stderr,
  2181. "EOF comparing DER entries\n");
  2182. }
  2183. return 0;
  2184. }
  2185. return matched;
  2186. case FILE_GUID:
  2187. l = 0;
  2188. v = memcmp(m->value.guid, p->guid, sizeof(p->guid));
  2189. break;
  2190. default:
  2191. file_magerror(ms, "invalid type %d in magiccheck()", m->type);
  2192. return -1;
  2193. }
  2194. v = file_signextend(ms, m, v);
  2195. switch (m->reln) {
  2196. case 'x':
  2197. if ((ms->flags & MAGIC_DEBUG) != 0)
  2198. (void) fprintf(stderr, "%" INT64_T_FORMAT
  2199. "u == *any* = 1", CAST(unsigned long long, v));
  2200. matched = 1;
  2201. break;
  2202. case '!':
  2203. matched = v != l;
  2204. if ((ms->flags & MAGIC_DEBUG) != 0)
  2205. (void) fprintf(stderr, "%" INT64_T_FORMAT "u != %"
  2206. INT64_T_FORMAT "u = %d",
  2207. CAST(unsigned long long, v),
  2208. CAST(unsigned long long, l), matched);
  2209. break;
  2210. case '=':
  2211. matched = v == l;
  2212. if ((ms->flags & MAGIC_DEBUG) != 0)
  2213. (void) fprintf(stderr, "%" INT64_T_FORMAT "u == %"
  2214. INT64_T_FORMAT "u = %d",
  2215. CAST(unsigned long long, v),
  2216. CAST(unsigned long long, l), matched);
  2217. break;
  2218. case '>':
  2219. if (m->flag & UNSIGNED) {
  2220. matched = v > l;
  2221. if ((ms->flags & MAGIC_DEBUG) != 0)
  2222. (void) fprintf(stderr, "%" INT64_T_FORMAT
  2223. "u > %" INT64_T_FORMAT "u = %d",
  2224. CAST(unsigned long long, v),
  2225. CAST(unsigned long long, l), matched);
  2226. }
  2227. else {
  2228. matched = CAST(int64_t, v) > CAST(int64_t, l);
  2229. if ((ms->flags & MAGIC_DEBUG) != 0)
  2230. (void) fprintf(stderr, "%" INT64_T_FORMAT
  2231. "d > %" INT64_T_FORMAT "d = %d",
  2232. CAST(long long, v),
  2233. CAST(long long, l), matched);
  2234. }
  2235. break;
  2236. case '<':
  2237. if (m->flag & UNSIGNED) {
  2238. matched = v < l;
  2239. if ((ms->flags & MAGIC_DEBUG) != 0)
  2240. (void) fprintf(stderr, "%" INT64_T_FORMAT
  2241. "u < %" INT64_T_FORMAT "u = %d",
  2242. CAST(unsigned long long, v),
  2243. CAST(unsigned long long, l), matched);
  2244. }
  2245. else {
  2246. matched = CAST(int64_t, v) < CAST(int64_t, l);
  2247. if ((ms->flags & MAGIC_DEBUG) != 0)
  2248. (void) fprintf(stderr, "%" INT64_T_FORMAT
  2249. "d < %" INT64_T_FORMAT "d = %d",
  2250. CAST(long long, v),
  2251. CAST(long long, l), matched);
  2252. }
  2253. break;
  2254. case '&':
  2255. matched = (v & l) == l;
  2256. if ((ms->flags & MAGIC_DEBUG) != 0)
  2257. (void) fprintf(stderr, "((%" INT64_T_FORMAT "x & %"
  2258. INT64_T_FORMAT "x) == %" INT64_T_FORMAT
  2259. "x) = %d", CAST(unsigned long long, v),
  2260. CAST(unsigned long long, l),
  2261. CAST(unsigned long long, l),
  2262. matched);
  2263. break;
  2264. case '^':
  2265. matched = (v & l) != l;
  2266. if ((ms->flags & MAGIC_DEBUG) != 0)
  2267. (void) fprintf(stderr, "((%" INT64_T_FORMAT "x & %"
  2268. INT64_T_FORMAT "x) != %" INT64_T_FORMAT
  2269. "x) = %d", CAST(unsigned long long, v),
  2270. CAST(unsigned long long, l),
  2271. CAST(unsigned long long, l), matched);
  2272. break;
  2273. default:
  2274. file_magerror(ms, "cannot happen: invalid relation `%c'",
  2275. m->reln);
  2276. return -1;
  2277. }
  2278. if ((ms->flags & MAGIC_DEBUG) != 0) {
  2279. (void) fprintf(stderr, " strength=%zu\n",
  2280. file_magic_strength(m, 1));
  2281. }
  2282. return matched;
  2283. }
  2284. file_private int
  2285. handle_annotation(struct magic_set *ms, struct magic *m, int firstline)
  2286. {
  2287. if ((ms->flags & MAGIC_APPLE) && m->apple[0]) {
  2288. if (print_sep(ms, firstline) == -1)
  2289. return -1;
  2290. if (file_printf(ms, "%.8s", m->apple) == -1)
  2291. return -1;
  2292. return 1;
  2293. }
  2294. if ((ms->flags & MAGIC_EXTENSION) && m->ext[0]) {
  2295. if (print_sep(ms, firstline) == -1)
  2296. return -1;
  2297. if (file_printf(ms, "%s", m->ext) == -1)
  2298. return -1;
  2299. return 1;
  2300. }
  2301. if ((ms->flags & MAGIC_MIME_TYPE) && m->mimetype[0]) {
  2302. char buf[1024];
  2303. const char *p;
  2304. if (print_sep(ms, firstline) == -1)
  2305. return -1;
  2306. if (varexpand(ms, buf, sizeof(buf), m->mimetype) == -1)
  2307. p = m->mimetype;
  2308. else
  2309. p = buf;
  2310. if (file_printf(ms, "%s", p) == -1)
  2311. return -1;
  2312. return 1;
  2313. }
  2314. return 0;
  2315. }
  2316. file_private int
  2317. print_sep(struct magic_set *ms, int firstline)
  2318. {
  2319. if (firstline)
  2320. return 0;
  2321. /*
  2322. * we found another match
  2323. * put a newline and '-' to do some simple formatting
  2324. */
  2325. return file_separator(ms);
  2326. }