]> CyberLeo.Net >> Repos - FreeBSD/stable/8.git/blob - contrib/file/softmagic.c
Fix multiple vulnerabilities in file(1) and libmagic(3).
[FreeBSD/stable/8.git] / contrib / file / softmagic.c
1 /*
2  * Copyright (c) Ian F. Darwin 1986-1995.
3  * Software written by Ian F. Darwin and others;
4  * maintained 1995-present by Christos Zoulas and others.
5  *
6  * Redistribution and use in source and binary forms, with or without
7  * modification, are permitted provided that the following conditions
8  * are met:
9  * 1. Redistributions of source code must retain the above copyright
10  *    notice immediately at the beginning of the file, without modification,
11  *    this list of conditions, and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  *
16  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19  * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR
20  * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  */
28 /*
29  * softmagic - interpret variable magic from MAGIC
30  */
31
32 #include "file.h"
33
34 #ifndef lint
35 FILE_RCSID("@(#)$File: softmagic.c,v 1.135 2009/03/27 22:42:49 christos Exp $")
36 #endif  /* lint */
37
38 #include "magic.h"
39 #include <string.h>
40 #include <ctype.h>
41 #include <stdlib.h>
42 #include <time.h>
43
44
45 private int match(struct magic_set *, struct magic *, uint32_t,
46     const unsigned char *, size_t, int, int);
47 private int mget(struct magic_set *, const unsigned char *,
48     struct magic *, size_t, unsigned int, int);
49 private int magiccheck(struct magic_set *, struct magic *);
50 private int32_t mprint(struct magic_set *, struct magic *);
51 private int32_t moffset(struct magic_set *, struct magic *);
52 private void mdebug(uint32_t, const char *, size_t);
53 private int mcopy(struct magic_set *, union VALUETYPE *, int, int,
54     const unsigned char *, uint32_t, size_t, size_t);
55 private int mconvert(struct magic_set *, struct magic *);
56 private int print_sep(struct magic_set *, int);
57 private int handle_annotation(struct magic_set *, struct magic *);
58 private void cvt_8(union VALUETYPE *, const struct magic *);
59 private void cvt_16(union VALUETYPE *, const struct magic *);
60 private void cvt_32(union VALUETYPE *, const struct magic *);
61 private void cvt_64(union VALUETYPE *, const struct magic *);
62
63 #define OFFSET_OOB(n, o, i)     ((n) < (o) || (i) > ((n) - (o)))
64 /*
65  * softmagic - lookup one file in parsed, in-memory copy of database
66  * Passed the name and FILE * of one file to be typed.
67  */
68 /*ARGSUSED1*/           /* nbytes passed for regularity, maybe need later */
69 protected int
70 file_softmagic(struct magic_set *ms, const unsigned char *buf, size_t nbytes,
71                size_t level, int mode)
72 {
73         struct mlist *ml;
74         int rv;
75         for (ml = ms->mlist->next; ml != ms->mlist; ml = ml->next)
76                 if ((rv = match(ms, ml->magic, ml->nmagic, buf, nbytes, mode, level)) != 0)
77                         return rv;
78
79         return 0;
80 }
81
82 /*
83  * Go through the whole list, stopping if you find a match.  Process all
84  * the continuations of that match before returning.
85  *
86  * We support multi-level continuations:
87  *
88  *      At any time when processing a successful top-level match, there is a
89  *      current continuation level; it represents the level of the last
90  *      successfully matched continuation.
91  *
92  *      Continuations above that level are skipped as, if we see one, it
93  *      means that the continuation that controls them - i.e, the
94  *      lower-level continuation preceding them - failed to match.
95  *
96  *      Continuations below that level are processed as, if we see one,
97  *      it means we've finished processing or skipping higher-level
98  *      continuations under the control of a successful or unsuccessful
99  *      lower-level continuation, and are now seeing the next lower-level
100  *      continuation and should process it.  The current continuation
101  *      level reverts to the level of the one we're seeing.
102  *
103  *      Continuations at the current level are processed as, if we see
104  *      one, there's no lower-level continuation that may have failed.
105  *
106  *      If a continuation matches, we bump the current continuation level
107  *      so that higher-level continuations are processed.
108  */
109 private int
110 match(struct magic_set *ms, struct magic *magic, uint32_t nmagic,
111     const unsigned char *s, size_t nbytes, int mode, int recursion_level)
112 {
113         uint32_t magindex = 0;
114         unsigned int cont_level = 0;
115         int need_separator = 0;
116         int returnval = 0, e; /* if a match is found it is set to 1*/
117         int firstline = 1; /* a flag to print X\n  X\n- X */
118         int printed_something = 0;
119         int print = (ms->flags & (MAGIC_MIME|MAGIC_APPLE)) == 0;
120
121         if (file_check_mem(ms, cont_level) == -1)
122                 return -1;
123
124         for (magindex = 0; magindex < nmagic; magindex++) {
125                 int flush = 0;
126                 struct magic *m = &magic[magindex];
127
128                 if ((m->flag & BINTEST) != mode) {
129                         /* Skip sub-tests */
130                         while (magic[magindex + 1].cont_level != 0 &&
131                                ++magindex < nmagic)
132                                 continue;
133                         continue; /* Skip to next top-level test*/
134                 }
135
136                 ms->offset = m->offset;
137                 ms->line = m->lineno;
138
139                 /* if main entry matches, print it... */
140                 switch (mget(ms, s, m, nbytes, cont_level, recursion_level + 1)) {
141                 case -1:
142                         return -1;
143                 case 0:
144                         flush = m->reln != '!';
145                         break;
146                 default:
147                         if (m->type == FILE_INDIRECT)
148                                 returnval = 1;
149                                 
150                         switch (magiccheck(ms, m)) {
151                         case -1:
152                                 return -1;
153                         case 0:
154                                 flush++;
155                                 break;
156                         default:
157                                 flush = 0;
158                                 break;
159                         }
160                         break;
161                 }
162                 if (flush) {
163                         /*
164                          * main entry didn't match,
165                          * flush its continuations
166                          */
167                         while (magindex < nmagic - 1 &&
168                             magic[magindex + 1].cont_level != 0)
169                                 magindex++;
170                         continue;
171                 }
172
173                 /*
174                  * If we are going to print something, we'll need to print
175                  * a blank before we print something else.
176                  */
177                 if (*m->desc) {
178                         need_separator = 1;
179                         printed_something = 1;
180                         if ((e = handle_annotation(ms, m)) != 0)
181                                 return e;
182                         if (print_sep(ms, firstline) == -1)
183                                 return -1;
184                 }
185
186
187                 if (print && mprint(ms, m) == -1)
188                         return -1;
189
190                 ms->c.li[cont_level].off = moffset(ms, m);
191
192                 /* and any continuations that match */
193                 if (file_check_mem(ms, ++cont_level) == -1)
194                         return -1;
195
196                 while (magic[magindex+1].cont_level != 0 &&
197                     ++magindex < nmagic) {
198                         m = &magic[magindex];
199                         ms->line = m->lineno; /* for messages */
200
201                         if (cont_level < m->cont_level)
202                                 continue;
203                         if (cont_level > m->cont_level) {
204                                 /*
205                                  * We're at the end of the level
206                                  * "cont_level" continuations.
207                                  */
208                                 cont_level = m->cont_level;
209                         }
210                         ms->offset = m->offset;
211                         if (m->flag & OFFADD) {
212                                 ms->offset +=
213                                     ms->c.li[cont_level - 1].off;
214                         }
215
216 #ifdef ENABLE_CONDITIONALS
217                         if (m->cond == COND_ELSE ||
218                             m->cond == COND_ELIF) {
219                                 if (ms->c.li[cont_level].last_match == 1)
220                                         continue;
221                         }
222 #endif
223                         switch (mget(ms, s, m, nbytes, cont_level, recursion_level + 1)) {
224                         case -1:
225                                 return -1;
226                         case 0:
227                                 if (m->reln != '!')
228                                         continue;
229                                 flush = 1;
230                                 break;
231                         default:
232                                 if (m->type == FILE_INDIRECT)
233                                         returnval = 1;
234                                 flush = 0;
235                                 break;
236                         }
237
238                         switch (flush ? 1 : magiccheck(ms, m)) {
239                         case -1:
240                                 return -1;
241                         case 0:
242 #ifdef ENABLE_CONDITIONALS
243                                 ms->c.li[cont_level].last_match = 0;
244 #endif
245                                 break;
246                         default:
247 #ifdef ENABLE_CONDITIONALS
248                                 ms->c.li[cont_level].last_match = 1;
249 #endif
250                                 if (m->type != FILE_DEFAULT)
251                                         ms->c.li[cont_level].got_match = 1;
252                                 else if (ms->c.li[cont_level].got_match) {
253                                         ms->c.li[cont_level].got_match = 0;
254                                         break;
255                                 }
256                                 /*
257                                  * If we are going to print something,
258                                  * make sure that we have a separator first.
259                                  */
260                                 if (*m->desc) {
261                                         if ((e = handle_annotation(ms, m)) != 0)
262                                                 return e;
263                                         if (!printed_something) {
264                                                 printed_something = 1;
265                                                 if (print_sep(ms, firstline)
266                                                     == -1)
267                                                         return -1;
268                                         }
269                                 }
270                                 /*
271                                  * This continuation matched.  Print
272                                  * its message, with a blank before it
273                                  * if the previous item printed and
274                                  * this item isn't empty.
275                                  */
276                                 /* space if previous printed */
277                                 if (need_separator
278                                     && ((m->flag & NOSPACE) == 0)
279                                     && *m->desc) {
280                                         if (print &&
281                                             file_printf(ms, " ") == -1)
282                                                 return -1;
283                                         need_separator = 0;
284                                 }
285                                 if (print && mprint(ms, m) == -1)
286                                         return -1;
287
288                                 ms->c.li[cont_level].off = moffset(ms, m);
289
290                                 if (*m->desc)
291                                         need_separator = 1;
292
293                                 /*
294                                  * If we see any continuations
295                                  * at a higher level,
296                                  * process them.
297                                  */
298                                 if (file_check_mem(ms, ++cont_level) == -1)
299                                         return -1;
300                                 break;
301                         }
302                 }
303                 if (printed_something) {
304                         firstline = 0;
305                         if (print)
306                                 returnval = 1;
307                 }
308                 if ((ms->flags & MAGIC_CONTINUE) == 0 && printed_something) {
309                         return returnval; /* don't keep searching */
310                 }
311         }
312         return returnval;  /* This is hit if -k is set or there is no match */
313 }
314
315 private int
316 check_fmt(struct magic_set *ms, struct magic *m)
317 {
318         regex_t rx;
319         int rc;
320
321         if (strchr(m->desc, '%') == NULL)
322                 return 0;
323
324         rc = regcomp(&rx, "%[-0-9\\.]*s", REG_EXTENDED|REG_NOSUB);
325         if (rc) {
326                 char errmsg[512];
327                 (void)regerror(rc, &rx, errmsg, sizeof(errmsg));
328                 file_magerror(ms, "regex error %d, (%s)", rc, errmsg);
329                 return -1;
330         } else {
331                 rc = regexec(&rx, m->desc, 0, 0, 0);
332                 regfree(&rx);
333                 return !rc;
334         }
335 }
336
337 #ifndef HAVE_STRNDUP
338 char * strndup(const char *, size_t);
339
340 char *
341 strndup(const char *str, size_t n)
342 {
343         size_t len;
344         char *copy;
345
346         for (len = 0; len < n && str[len]; len++)
347                 continue;
348         if ((copy = malloc(len + 1)) == NULL)
349                 return NULL;
350         (void)memcpy(copy, str, len);
351         copy[len] = '\0';
352         return copy;
353 }
354 #endif /* HAVE_STRNDUP */
355
356 private int32_t
357 mprint(struct magic_set *ms, struct magic *m)
358 {
359         uint64_t v;
360         float vf;
361         double vd;
362         int64_t t = 0;
363         char buf[128];
364         union VALUETYPE *p = &ms->ms_value;
365
366         switch (m->type) {
367         case FILE_BYTE:
368                 v = file_signextend(ms, m, (uint64_t)p->b);
369                 switch (check_fmt(ms, m)) {
370                 case -1:
371                         return -1;
372                 case 1:
373                         (void)snprintf(buf, sizeof(buf), "%c",
374                             (unsigned char)v);
375                         if (file_printf(ms, m->desc, buf) == -1)
376                                 return -1;
377                         break;
378                 default:
379                         if (file_printf(ms, m->desc, (unsigned char) v) == -1)
380                                 return -1;
381                         break;
382                 }
383                 t = ms->offset + sizeof(char);
384                 break;
385
386         case FILE_SHORT:
387         case FILE_BESHORT:
388         case FILE_LESHORT:
389                 v = file_signextend(ms, m, (uint64_t)p->h);
390                 switch (check_fmt(ms, m)) {
391                 case -1:
392                         return -1;
393                 case 1:
394                         (void)snprintf(buf, sizeof(buf), "%hu",
395                             (unsigned short)v);
396                         if (file_printf(ms, m->desc, buf) == -1)
397                                 return -1;
398                         break;
399                 default:
400                         if (
401                             file_printf(ms, m->desc, (unsigned short) v) == -1)
402                                 return -1;
403                         break;
404                 }
405                 t = ms->offset + sizeof(short);
406                 break;
407
408         case FILE_LONG:
409         case FILE_BELONG:
410         case FILE_LELONG:
411         case FILE_MELONG:
412                 v = file_signextend(ms, m, (uint64_t)p->l);
413                 switch (check_fmt(ms, m)) {
414                 case -1:
415                         return -1;
416                 case 1:
417                         (void)snprintf(buf, sizeof(buf), "%u", (uint32_t)v);
418                         if (file_printf(ms, m->desc, buf) == -1)
419                                 return -1;
420                         break;
421                 default:
422                         if (file_printf(ms, m->desc, (uint32_t) v) == -1)
423                                 return -1;
424                         break;
425                 }
426                 t = ms->offset + sizeof(int32_t);
427                 break;
428
429         case FILE_QUAD:
430         case FILE_BEQUAD:
431         case FILE_LEQUAD:
432                 v = file_signextend(ms, m, p->q);
433                 if (file_printf(ms, m->desc, (uint64_t) v) == -1)
434                         return -1;
435                 t = ms->offset + sizeof(int64_t);
436                 break;
437
438         case FILE_STRING:
439         case FILE_PSTRING:
440         case FILE_BESTRING16:
441         case FILE_LESTRING16:
442                 if (m->reln == '=' || m->reln == '!') {
443                         if (file_printf(ms, m->desc, m->value.s) == -1)
444                                 return -1;
445                         t = ms->offset + m->vallen;
446                 }
447                 else {
448                         if (*m->value.s == '\0')
449                                 p->s[strcspn(p->s, "\n")] = '\0';
450                         if (file_printf(ms, m->desc, p->s) == -1)
451                                 return -1;
452                         t = ms->offset + strlen(p->s);
453                         if (m->type == FILE_PSTRING)
454                                 t++;
455                 }
456                 break;
457
458         case FILE_DATE:
459         case FILE_BEDATE:
460         case FILE_LEDATE:
461         case FILE_MEDATE:
462                 if (file_printf(ms, m->desc, file_fmttime(p->l, 1)) == -1)
463                         return -1;
464                 t = ms->offset + sizeof(time_t);
465                 break;
466
467         case FILE_LDATE:
468         case FILE_BELDATE:
469         case FILE_LELDATE:
470         case FILE_MELDATE:
471                 if (file_printf(ms, m->desc, file_fmttime(p->l, 0)) == -1)
472                         return -1;
473                 t = ms->offset + sizeof(time_t);
474                 break;
475
476         case FILE_QDATE:
477         case FILE_BEQDATE:
478         case FILE_LEQDATE:
479                 if (file_printf(ms, m->desc, file_fmttime((uint32_t)p->q,
480                     1)) == -1)
481                         return -1;
482                 t = ms->offset + sizeof(uint64_t);
483                 break;
484
485         case FILE_QLDATE:
486         case FILE_BEQLDATE:
487         case FILE_LEQLDATE:
488                 if (file_printf(ms, m->desc, file_fmttime((uint32_t)p->q,
489                     0)) == -1)
490                         return -1;
491                 t = ms->offset + sizeof(uint64_t);
492                 break;
493
494         case FILE_FLOAT:
495         case FILE_BEFLOAT:
496         case FILE_LEFLOAT:
497                 vf = p->f;
498                 switch (check_fmt(ms, m)) {
499                 case -1:
500                         return -1;
501                 case 1:
502                         (void)snprintf(buf, sizeof(buf), "%g", vf);
503                         if (file_printf(ms, m->desc, buf) == -1)
504                                 return -1;
505                         break;
506                 default:
507                         if (file_printf(ms, m->desc, vf) == -1)
508                                 return -1;
509                         break;
510                 }
511                 t = ms->offset + sizeof(float);
512                 break;
513
514         case FILE_DOUBLE:
515         case FILE_BEDOUBLE:
516         case FILE_LEDOUBLE:
517                 vd = p->d;
518                 switch (check_fmt(ms, m)) {
519                 case -1:
520                         return -1;
521                 case 1:
522                         (void)snprintf(buf, sizeof(buf), "%g", vd);
523                         if (file_printf(ms, m->desc, buf) == -1)
524                                 return -1;
525                         break;
526                 default:
527                         if (file_printf(ms, m->desc, vd) == -1)
528                                 return -1;
529                         break;
530                 }
531                 t = ms->offset + sizeof(double);
532                 break;
533
534         case FILE_REGEX: {
535                 char *cp;
536                 int rval;
537
538                 cp = strndup((const char *)ms->search.s, ms->search.rm_len);
539                 if (cp == NULL) {
540                         file_oomem(ms, ms->search.rm_len);
541                         return -1;
542                 }
543                 rval = file_printf(ms, m->desc, cp);
544                 free(cp);
545
546                 if (rval == -1)
547                         return -1;
548
549                 if ((m->str_flags & REGEX_OFFSET_START))
550                         t = ms->search.offset;
551                 else
552                         t = ms->search.offset + ms->search.rm_len;
553                 break;
554         }
555
556         case FILE_SEARCH:
557                 if (file_printf(ms, m->desc, m->value.s) == -1)
558                         return -1;
559                 if ((m->str_flags & REGEX_OFFSET_START))
560                         t = ms->search.offset;
561                 else
562                         t = ms->search.offset + m->vallen;
563                 break;
564
565         case FILE_DEFAULT:
566                 if (file_printf(ms, m->desc, m->value.s) == -1)
567                         return -1;
568                 t = ms->offset;
569                 break;
570
571         case FILE_INDIRECT:
572                 t = ms->offset;
573                 break;
574
575         default:
576                 file_magerror(ms, "invalid m->type (%d) in mprint()", m->type);
577                 return -1;
578         }
579         return (int32_t)t;
580 }
581
582 private int32_t
583 moffset(struct magic_set *ms, struct magic *m)
584 {
585         switch (m->type) {
586         case FILE_BYTE:
587                 return ms->offset + sizeof(char);
588
589         case FILE_SHORT:
590         case FILE_BESHORT:
591         case FILE_LESHORT:
592                 return ms->offset + sizeof(short);
593
594         case FILE_LONG:
595         case FILE_BELONG:
596         case FILE_LELONG:
597         case FILE_MELONG:
598                 return ms->offset + sizeof(int32_t);
599
600         case FILE_QUAD:
601         case FILE_BEQUAD:
602         case FILE_LEQUAD:
603                 return ms->offset + sizeof(int64_t);
604
605         case FILE_STRING:
606         case FILE_PSTRING:
607         case FILE_BESTRING16:
608         case FILE_LESTRING16:
609                 if (m->reln == '=' || m->reln == '!')
610                         return ms->offset + m->vallen;
611                 else {
612                         union VALUETYPE *p = &ms->ms_value;
613                         uint32_t t;
614
615                         if (*m->value.s == '\0')
616                                 p->s[strcspn(p->s, "\n")] = '\0';
617                         t = ms->offset + strlen(p->s);
618                         if (m->type == FILE_PSTRING)
619                                 t++;
620                         return t;
621                 }
622
623         case FILE_DATE:
624         case FILE_BEDATE:
625         case FILE_LEDATE:
626         case FILE_MEDATE:
627                 return ms->offset + sizeof(time_t);
628
629         case FILE_LDATE:
630         case FILE_BELDATE:
631         case FILE_LELDATE:
632         case FILE_MELDATE:
633                 return ms->offset + sizeof(time_t);
634
635         case FILE_QDATE:
636         case FILE_BEQDATE:
637         case FILE_LEQDATE:
638                 return ms->offset + sizeof(uint64_t);
639
640         case FILE_QLDATE:
641         case FILE_BEQLDATE:
642         case FILE_LEQLDATE:
643                 return ms->offset + sizeof(uint64_t);
644
645         case FILE_FLOAT:
646         case FILE_BEFLOAT:
647         case FILE_LEFLOAT:
648                 return ms->offset + sizeof(float);
649
650         case FILE_DOUBLE:
651         case FILE_BEDOUBLE:
652         case FILE_LEDOUBLE:
653                 return ms->offset + sizeof(double);
654                 break;
655
656         case FILE_REGEX:
657                 if ((m->str_flags & REGEX_OFFSET_START) != 0)
658                         return ms->search.offset;
659                 else
660                         return ms->search.offset + ms->search.rm_len;
661
662         case FILE_SEARCH:
663                 if ((m->str_flags & REGEX_OFFSET_START) != 0)
664                         return ms->search.offset;
665                 else
666                         return ms->search.offset + m->vallen;
667
668         case FILE_DEFAULT:
669                 return ms->offset;
670
671         case FILE_INDIRECT:
672                 return ms->offset;
673
674         default:
675                 return 0;
676         }
677 }
678
679 #define DO_CVT(fld, cast) \
680         if (m->num_mask) \
681                 switch (m->mask_op & FILE_OPS_MASK) { \
682                 case FILE_OPAND: \
683                         p->fld &= cast m->num_mask; \
684                         break; \
685                 case FILE_OPOR: \
686                         p->fld |= cast m->num_mask; \
687                         break; \
688                 case FILE_OPXOR: \
689                         p->fld ^= cast m->num_mask; \
690                         break; \
691                 case FILE_OPADD: \
692                         p->fld += cast m->num_mask; \
693                         break; \
694                 case FILE_OPMINUS: \
695                         p->fld -= cast m->num_mask; \
696                         break; \
697                 case FILE_OPMULTIPLY: \
698                         p->fld *= cast m->num_mask; \
699                         break; \
700                 case FILE_OPDIVIDE: \
701                         p->fld /= cast m->num_mask; \
702                         break; \
703                 case FILE_OPMODULO: \
704                         p->fld %= cast m->num_mask; \
705                         break; \
706                 } \
707         if (m->mask_op & FILE_OPINVERSE) \
708                 p->fld = ~p->fld \
709
710 private void
711 cvt_8(union VALUETYPE *p, const struct magic *m)
712 {
713         DO_CVT(b, (uint8_t));
714 }
715
716 private void
717 cvt_16(union VALUETYPE *p, const struct magic *m)
718 {
719         DO_CVT(h, (uint16_t));
720 }
721
722 private void
723 cvt_32(union VALUETYPE *p, const struct magic *m)
724 {
725         DO_CVT(l, (uint32_t));
726 }
727
728 private void
729 cvt_64(union VALUETYPE *p, const struct magic *m)
730 {
731         DO_CVT(q, (uint64_t));
732 }
733
734 #define DO_CVT2(fld, cast) \
735         if (m->num_mask) \
736                 switch (m->mask_op & FILE_OPS_MASK) { \
737                 case FILE_OPADD: \
738                         p->fld += cast m->num_mask; \
739                         break; \
740                 case FILE_OPMINUS: \
741                         p->fld -= cast m->num_mask; \
742                         break; \
743                 case FILE_OPMULTIPLY: \
744                         p->fld *= cast m->num_mask; \
745                         break; \
746                 case FILE_OPDIVIDE: \
747                         p->fld /= cast m->num_mask; \
748                         break; \
749                 } \
750
751 private void
752 cvt_float(union VALUETYPE *p, const struct magic *m)
753 {
754         DO_CVT2(f, (float));
755 }
756
757 private void
758 cvt_double(union VALUETYPE *p, const struct magic *m)
759 {
760         DO_CVT2(d, (double));
761 }
762
763 /*
764  * Convert the byte order of the data we are looking at
765  * While we're here, let's apply the mask operation
766  * (unless you have a better idea)
767  */
768 private int
769 mconvert(struct magic_set *ms, struct magic *m)
770 {
771         union VALUETYPE *p = &ms->ms_value;
772
773         switch (m->type) {
774         case FILE_BYTE:
775                 cvt_8(p, m);
776                 return 1;
777         case FILE_SHORT:
778                 cvt_16(p, m);
779                 return 1;
780         case FILE_LONG:
781         case FILE_DATE:
782         case FILE_LDATE:
783                 cvt_32(p, m);
784                 return 1;
785         case FILE_QUAD:
786         case FILE_QDATE:
787         case FILE_QLDATE:
788                 cvt_64(p, m);
789                 return 1;
790         case FILE_STRING:
791         case FILE_BESTRING16:
792         case FILE_LESTRING16: {
793                 /* Null terminate and eat *trailing* return */
794                 p->s[sizeof(p->s) - 1] = '\0';
795 #if 0
796                 /* Why? breaks magic numbers that end with \xa */
797                 len = strlen(p->s);
798                 if (len-- && p->s[len] == '\n')
799                         p->s[len] = '\0';
800 #endif
801                 return 1;
802         }
803         case FILE_PSTRING: {
804                 char *ptr1 = p->s, *ptr2 = ptr1 + 1;
805                 size_t len = *p->s;
806                 if (len >= sizeof(p->s))
807                         len = sizeof(p->s) - 1;
808                 while (len--)
809                         *ptr1++ = *ptr2++;
810                 *ptr1 = '\0';
811 #if 0
812                 /* Why? breaks magic numbers that end with \xa */
813                 len = strlen(p->s);
814                 if (len-- && p->s[len] == '\n')
815                         p->s[len] = '\0';
816 #endif
817                 return 1;
818         }
819         case FILE_BESHORT:
820                 p->h = (short)((p->hs[0]<<8)|(p->hs[1]));
821                 cvt_16(p, m);
822                 return 1;
823         case FILE_BELONG:
824         case FILE_BEDATE:
825         case FILE_BELDATE:
826                 p->l = (int32_t)
827                     ((p->hl[0]<<24)|(p->hl[1]<<16)|(p->hl[2]<<8)|(p->hl[3]));
828                 cvt_32(p, m);
829                 return 1;
830         case FILE_BEQUAD:
831         case FILE_BEQDATE:
832         case FILE_BEQLDATE:
833                 p->q = (uint64_t)
834                     (((uint64_t)p->hq[0]<<56)|((uint64_t)p->hq[1]<<48)|
835                      ((uint64_t)p->hq[2]<<40)|((uint64_t)p->hq[3]<<32)|
836                      ((uint64_t)p->hq[4]<<24)|((uint64_t)p->hq[5]<<16)|
837                      ((uint64_t)p->hq[6]<<8)|((uint64_t)p->hq[7]));
838                 cvt_64(p, m);
839                 return 1;
840         case FILE_LESHORT:
841                 p->h = (short)((p->hs[1]<<8)|(p->hs[0]));
842                 cvt_16(p, m);
843                 return 1;
844         case FILE_LELONG:
845         case FILE_LEDATE:
846         case FILE_LELDATE:
847                 p->l = (int32_t)
848                     ((p->hl[3]<<24)|(p->hl[2]<<16)|(p->hl[1]<<8)|(p->hl[0]));
849                 cvt_32(p, m);
850                 return 1;
851         case FILE_LEQUAD:
852         case FILE_LEQDATE:
853         case FILE_LEQLDATE:
854                 p->q = (uint64_t)
855                     (((uint64_t)p->hq[7]<<56)|((uint64_t)p->hq[6]<<48)|
856                      ((uint64_t)p->hq[5]<<40)|((uint64_t)p->hq[4]<<32)|
857                      ((uint64_t)p->hq[3]<<24)|((uint64_t)p->hq[2]<<16)|
858                      ((uint64_t)p->hq[1]<<8)|((uint64_t)p->hq[0]));
859                 cvt_64(p, m);
860                 return 1;
861         case FILE_MELONG:
862         case FILE_MEDATE:
863         case FILE_MELDATE:
864                 p->l = (int32_t)
865                     ((p->hl[1]<<24)|(p->hl[0]<<16)|(p->hl[3]<<8)|(p->hl[2]));
866                 cvt_32(p, m);
867                 return 1;
868         case FILE_FLOAT:
869                 cvt_float(p, m);
870                 return 1;
871         case FILE_BEFLOAT:
872                 p->l =  ((uint32_t)p->hl[0]<<24)|((uint32_t)p->hl[1]<<16)|
873                         ((uint32_t)p->hl[2]<<8) |((uint32_t)p->hl[3]);
874                 cvt_float(p, m);
875                 return 1;
876         case FILE_LEFLOAT:
877                 p->l =  ((uint32_t)p->hl[3]<<24)|((uint32_t)p->hl[2]<<16)|
878                         ((uint32_t)p->hl[1]<<8) |((uint32_t)p->hl[0]);
879                 cvt_float(p, m);
880                 return 1;
881         case FILE_DOUBLE:
882                 cvt_double(p, m);
883                 return 1;
884         case FILE_BEDOUBLE:
885                 p->q =  ((uint64_t)p->hq[0]<<56)|((uint64_t)p->hq[1]<<48)|
886                         ((uint64_t)p->hq[2]<<40)|((uint64_t)p->hq[3]<<32)|
887                         ((uint64_t)p->hq[4]<<24)|((uint64_t)p->hq[5]<<16)|
888                         ((uint64_t)p->hq[6]<<8) |((uint64_t)p->hq[7]);
889                 cvt_double(p, m);
890                 return 1;
891         case FILE_LEDOUBLE:
892                 p->q =  ((uint64_t)p->hq[7]<<56)|((uint64_t)p->hq[6]<<48)|
893                         ((uint64_t)p->hq[5]<<40)|((uint64_t)p->hq[4]<<32)|
894                         ((uint64_t)p->hq[3]<<24)|((uint64_t)p->hq[2]<<16)|
895                         ((uint64_t)p->hq[1]<<8) |((uint64_t)p->hq[0]);
896                 cvt_double(p, m);
897                 return 1;
898         case FILE_REGEX:
899         case FILE_SEARCH:
900         case FILE_DEFAULT:
901                 return 1;
902         default:
903                 file_magerror(ms, "invalid type %d in mconvert()", m->type);
904                 return 0;
905         }
906 }
907
908
909 private void
910 mdebug(uint32_t offset, const char *str, size_t len)
911 {
912         (void) fprintf(stderr, "mget @%d: ", offset);
913         file_showstr(stderr, str, len);
914         (void) fputc('\n', stderr);
915         (void) fputc('\n', stderr);
916 }
917
918 private int
919 mcopy(struct magic_set *ms, union VALUETYPE *p, int type, int indir,
920     const unsigned char *s, uint32_t offset, size_t nbytes, size_t linecnt)
921 {
922         /*
923          * Note: FILE_SEARCH and FILE_REGEX do not actually copy
924          * anything, but setup pointers into the source
925          */
926         if (indir == 0) {
927                 switch (type) {
928                 case FILE_SEARCH:
929                         ms->search.s = (const char *)s + offset;
930                         ms->search.s_len = nbytes - offset;
931                         ms->search.offset = offset;
932                         return 0;
933
934                 case FILE_REGEX: {
935                         const char *b;
936                         const char *c;
937                         const char *last;       /* end of search region */
938                         const char *buf;        /* start of search region */
939                         const char *end;
940                         size_t lines;
941
942                         if (s == NULL) {
943                                 ms->search.s_len = 0;
944                                 ms->search.s = NULL;
945                                 return 0;
946                         }
947                         buf = (const char *)s + offset;
948                         end = last = (const char *)s + nbytes;
949                         /* mget() guarantees buf <= last */
950                         for (lines = linecnt, b = buf;
951                              lines && ((b = memchr(c = b, '\n', end - b)) || (b = memchr(c, '\r', end - c)));
952                              lines--, b++) {
953                                 last = b;
954                                 if (b[0] == '\r' && b[1] == '\n')
955                                         b++;
956                         }
957                         if (lines)
958                                 last = (const char *)s + nbytes;
959
960                         ms->search.s = buf;
961                         ms->search.s_len = last - buf;
962                         ms->search.offset = offset;
963                         ms->search.rm_len = 0;
964                         return 0;
965                 }
966                 case FILE_BESTRING16:
967                 case FILE_LESTRING16: {
968                         const unsigned char *src = s + offset;
969                         const unsigned char *esrc = s + nbytes;
970                         char *dst = p->s;
971                         char *edst = &p->s[sizeof(p->s) - 1];
972
973                         if (type == FILE_BESTRING16)
974                                 src++;
975
976                         /* check for pointer overflow */
977                         if (src < s) {
978                                 file_magerror(ms, "invalid offset %u in mcopy()",
979                                     offset);
980                                 return -1;
981                         }
982                         for (/*EMPTY*/; src < esrc; src += 2, dst++) {
983                                 if (dst < edst)
984                                         *dst = *src;
985                                 else
986                                         break;
987                                 if (*dst == '\0') {
988                                         if (type == FILE_BESTRING16 ?
989                                             *(src - 1) != '\0' :
990                                             *(src + 1) != '\0')
991                                                 *dst = ' ';
992                                 }
993                         }
994                         *edst = '\0';
995                         return 0;
996                 }
997                 case FILE_STRING:       /* XXX - these two should not need */
998                 case FILE_PSTRING:      /* to copy anything, but do anyway. */
999                 default:
1000                         break;
1001                 }
1002         }
1003
1004         if (offset >= nbytes) {
1005                 (void)memset(p, '\0', sizeof(*p));
1006                 return 0;
1007         }
1008         if (nbytes - offset < sizeof(*p))
1009                 nbytes = nbytes - offset;
1010         else
1011                 nbytes = sizeof(*p);
1012
1013         (void)memcpy(p, s + offset, nbytes);
1014
1015         /*
1016          * the usefulness of padding with zeroes eludes me, it
1017          * might even cause problems
1018          */
1019         if (nbytes < sizeof(*p))
1020                 (void)memset(((char *)(void *)p) + nbytes, '\0',
1021                     sizeof(*p) - nbytes);
1022         return 0;
1023 }
1024
1025 private int
1026 mget(struct magic_set *ms, const unsigned char *s,
1027     struct magic *m, size_t nbytes, unsigned int cont_level, int recursion_level)
1028 {
1029         uint32_t offset = ms->offset;
1030         uint32_t count = m->str_range;
1031         union VALUETYPE *p = &ms->ms_value;
1032
1033         if (recursion_level >= 20) {
1034                 file_error(ms, 0, "recursion nesting exceeded");
1035                 return -1;
1036         }
1037
1038         if (mcopy(ms, p, m->type, m->flag & INDIR, s, offset, nbytes, count) == -1)
1039                 return -1;
1040
1041         if ((ms->flags & MAGIC_DEBUG) != 0) {
1042                 mdebug(offset, (char *)(void *)p, sizeof(union VALUETYPE));
1043 #ifndef COMPILE_ONLY
1044                 file_mdump(m);
1045 #endif
1046         }
1047
1048         if (m->flag & INDIR) {
1049                 int off = m->in_offset;
1050                 if (m->in_op & FILE_OPINDIRECT) {
1051                         const union VALUETYPE *q = CAST(const union VALUETYPE *,
1052                             ((const void *)(s + offset + off)));
1053                         switch (m->in_type) {
1054                         case FILE_BYTE:
1055                                 off = q->b;
1056                                 break;
1057                         case FILE_SHORT:
1058                                 off = q->h;
1059                                 break;
1060                         case FILE_BESHORT:
1061                                 off = (short)((q->hs[0]<<8)|(q->hs[1]));
1062                                 break;
1063                         case FILE_LESHORT:
1064                                 off = (short)((q->hs[1]<<8)|(q->hs[0]));
1065                                 break;
1066                         case FILE_LONG:
1067                                 off = q->l;
1068                                 break;
1069                         case FILE_BELONG:
1070                         case FILE_BEID3:
1071                                 off = (int32_t)((q->hl[0]<<24)|(q->hl[1]<<16)|
1072                                                  (q->hl[2]<<8)|(q->hl[3]));
1073                                 break;
1074                         case FILE_LEID3:
1075                         case FILE_LELONG:
1076                                 off = (int32_t)((q->hl[3]<<24)|(q->hl[2]<<16)|
1077                                                  (q->hl[1]<<8)|(q->hl[0]));
1078                                 break;
1079                         case FILE_MELONG:
1080                                 off = (int32_t)((q->hl[1]<<24)|(q->hl[0]<<16)|
1081                                                  (q->hl[3]<<8)|(q->hl[2]));
1082                                 break;
1083                         }
1084                 }
1085                 switch (m->in_type) {
1086                 case FILE_BYTE:
1087                         if (OFFSET_OOB(nbytes, offset, 1))
1088                                 return 0;
1089                         if (off) {
1090                                 switch (m->in_op & FILE_OPS_MASK) {
1091                                 case FILE_OPAND:
1092                                         offset = p->b & off;
1093                                         break;
1094                                 case FILE_OPOR:
1095                                         offset = p->b | off;
1096                                         break;
1097                                 case FILE_OPXOR:
1098                                         offset = p->b ^ off;
1099                                         break;
1100                                 case FILE_OPADD:
1101                                         offset = p->b + off;
1102                                         break;
1103                                 case FILE_OPMINUS:
1104                                         offset = p->b - off;
1105                                         break;
1106                                 case FILE_OPMULTIPLY:
1107                                         offset = p->b * off;
1108                                         break;
1109                                 case FILE_OPDIVIDE:
1110                                         offset = p->b / off;
1111                                         break;
1112                                 case FILE_OPMODULO:
1113                                         offset = p->b % off;
1114                                         break;
1115                                 }
1116                         } else
1117                                 offset = p->b;
1118                         if (m->in_op & FILE_OPINVERSE)
1119                                 offset = ~offset;
1120                         break;
1121                 case FILE_BESHORT:
1122                         if (OFFSET_OOB(nbytes, offset, 2))
1123                                 return 0;
1124                         if (off) {
1125                                 switch (m->in_op & FILE_OPS_MASK) {
1126                                 case FILE_OPAND:
1127                                         offset = (short)((p->hs[0]<<8)|
1128                                                          (p->hs[1])) &
1129                                                  off;
1130                                         break;
1131                                 case FILE_OPOR:
1132                                         offset = (short)((p->hs[0]<<8)|
1133                                                          (p->hs[1])) |
1134                                                  off;
1135                                         break;
1136                                 case FILE_OPXOR:
1137                                         offset = (short)((p->hs[0]<<8)|
1138                                                          (p->hs[1])) ^
1139                                                  off;
1140                                         break;
1141                                 case FILE_OPADD:
1142                                         offset = (short)((p->hs[0]<<8)|
1143                                                          (p->hs[1])) +
1144                                                  off;
1145                                         break;
1146                                 case FILE_OPMINUS:
1147                                         offset = (short)((p->hs[0]<<8)|
1148                                                          (p->hs[1])) -
1149                                                  off;
1150                                         break;
1151                                 case FILE_OPMULTIPLY:
1152                                         offset = (short)((p->hs[0]<<8)|
1153                                                          (p->hs[1])) *
1154                                                  off;
1155                                         break;
1156                                 case FILE_OPDIVIDE:
1157                                         offset = (short)((p->hs[0]<<8)|
1158                                                          (p->hs[1])) /
1159                                                  off;
1160                                         break;
1161                                 case FILE_OPMODULO:
1162                                         offset = (short)((p->hs[0]<<8)|
1163                                                          (p->hs[1])) %
1164                                                  off;
1165                                         break;
1166                                 }
1167                         } else
1168                                 offset = (short)((p->hs[0]<<8)|
1169                                                  (p->hs[1]));
1170                         if (m->in_op & FILE_OPINVERSE)
1171                                 offset = ~offset;
1172                         break;
1173                 case FILE_LESHORT:
1174                         if (OFFSET_OOB(nbytes, offset, 2))
1175                                 return 0;
1176                         if (off) {
1177                                 switch (m->in_op & FILE_OPS_MASK) {
1178                                 case FILE_OPAND:
1179                                         offset = (short)((p->hs[1]<<8)|
1180                                                          (p->hs[0])) &
1181                                                  off;
1182                                         break;
1183                                 case FILE_OPOR:
1184                                         offset = (short)((p->hs[1]<<8)|
1185                                                          (p->hs[0])) |
1186                                                  off;
1187                                         break;
1188                                 case FILE_OPXOR:
1189                                         offset = (short)((p->hs[1]<<8)|
1190                                                          (p->hs[0])) ^
1191                                                  off;
1192                                         break;
1193                                 case FILE_OPADD:
1194                                         offset = (short)((p->hs[1]<<8)|
1195                                                          (p->hs[0])) +
1196                                                  off;
1197                                         break;
1198                                 case FILE_OPMINUS:
1199                                         offset = (short)((p->hs[1]<<8)|
1200                                                          (p->hs[0])) -
1201                                                  off;
1202                                         break;
1203                                 case FILE_OPMULTIPLY:
1204                                         offset = (short)((p->hs[1]<<8)|
1205                                                          (p->hs[0])) *
1206                                                  off;
1207                                         break;
1208                                 case FILE_OPDIVIDE:
1209                                         offset = (short)((p->hs[1]<<8)|
1210                                                          (p->hs[0])) /
1211                                                  off;
1212                                         break;
1213                                 case FILE_OPMODULO:
1214                                         offset = (short)((p->hs[1]<<8)|
1215                                                          (p->hs[0])) %
1216                                                  off;
1217                                         break;
1218                                 }
1219                         } else
1220                                 offset = (short)((p->hs[1]<<8)|
1221                                                  (p->hs[0]));
1222                         if (m->in_op & FILE_OPINVERSE)
1223                                 offset = ~offset;
1224                         break;
1225                 case FILE_SHORT:
1226                         if (OFFSET_OOB(nbytes, offset, 2))
1227                                 return 0;
1228                         if (off) {
1229                                 switch (m->in_op & FILE_OPS_MASK) {
1230                                 case FILE_OPAND:
1231                                         offset = p->h & off;
1232                                         break;
1233                                 case FILE_OPOR:
1234                                         offset = p->h | off;
1235                                         break;
1236                                 case FILE_OPXOR:
1237                                         offset = p->h ^ off;
1238                                         break;
1239                                 case FILE_OPADD:
1240                                         offset = p->h + off;
1241                                         break;
1242                                 case FILE_OPMINUS:
1243                                         offset = p->h - off;
1244                                         break;
1245                                 case FILE_OPMULTIPLY:
1246                                         offset = p->h * off;
1247                                         break;
1248                                 case FILE_OPDIVIDE:
1249                                         offset = p->h / off;
1250                                         break;
1251                                 case FILE_OPMODULO:
1252                                         offset = p->h % off;
1253                                         break;
1254                                 }
1255                         }
1256                         else
1257                                 offset = p->h;
1258                         if (m->in_op & FILE_OPINVERSE)
1259                                 offset = ~offset;
1260                         break;
1261                 case FILE_BELONG:
1262                 case FILE_BEID3:
1263                         if (OFFSET_OOB(nbytes, offset, 4))
1264                                 return 0;
1265                         if (off) {
1266                                 switch (m->in_op & FILE_OPS_MASK) {
1267                                 case FILE_OPAND:
1268                                         offset = (int32_t)((p->hl[0]<<24)|
1269                                                          (p->hl[1]<<16)|
1270                                                          (p->hl[2]<<8)|
1271                                                          (p->hl[3])) &
1272                                                  off;
1273                                         break;
1274                                 case FILE_OPOR:
1275                                         offset = (int32_t)((p->hl[0]<<24)|
1276                                                          (p->hl[1]<<16)|
1277                                                          (p->hl[2]<<8)|
1278                                                          (p->hl[3])) |
1279                                                  off;
1280                                         break;
1281                                 case FILE_OPXOR:
1282                                         offset = (int32_t)((p->hl[0]<<24)|
1283                                                          (p->hl[1]<<16)|
1284                                                          (p->hl[2]<<8)|
1285                                                          (p->hl[3])) ^
1286                                                  off;
1287                                         break;
1288                                 case FILE_OPADD:
1289                                         offset = (int32_t)((p->hl[0]<<24)|
1290                                                          (p->hl[1]<<16)|
1291                                                          (p->hl[2]<<8)|
1292                                                          (p->hl[3])) +
1293                                                  off;
1294                                         break;
1295                                 case FILE_OPMINUS:
1296                                         offset = (int32_t)((p->hl[0]<<24)|
1297                                                          (p->hl[1]<<16)|
1298                                                          (p->hl[2]<<8)|
1299                                                          (p->hl[3])) -
1300                                                  off;
1301                                         break;
1302                                 case FILE_OPMULTIPLY:
1303                                         offset = (int32_t)((p->hl[0]<<24)|
1304                                                          (p->hl[1]<<16)|
1305                                                          (p->hl[2]<<8)|
1306                                                          (p->hl[3])) *
1307                                                  off;
1308                                         break;
1309                                 case FILE_OPDIVIDE:
1310                                         offset = (int32_t)((p->hl[0]<<24)|
1311                                                          (p->hl[1]<<16)|
1312                                                          (p->hl[2]<<8)|
1313                                                          (p->hl[3])) /
1314                                                  off;
1315                                         break;
1316                                 case FILE_OPMODULO:
1317                                         offset = (int32_t)((p->hl[0]<<24)|
1318                                                          (p->hl[1]<<16)|
1319                                                          (p->hl[2]<<8)|
1320                                                          (p->hl[3])) %
1321                                                  off;
1322                                         break;
1323                                 }
1324                         } else
1325                                 offset = (int32_t)((p->hl[0]<<24)|
1326                                                  (p->hl[1]<<16)|
1327                                                  (p->hl[2]<<8)|
1328                                                  (p->hl[3]));
1329                         if (m->in_op & FILE_OPINVERSE)
1330                                 offset = ~offset;
1331                         break;
1332                 case FILE_LELONG:
1333                 case FILE_LEID3:
1334                         if (OFFSET_OOB(nbytes, offset, 4))
1335                                 return 0;
1336                         if (off) {
1337                                 switch (m->in_op & FILE_OPS_MASK) {
1338                                 case FILE_OPAND:
1339                                         offset = (int32_t)((p->hl[3]<<24)|
1340                                                          (p->hl[2]<<16)|
1341                                                          (p->hl[1]<<8)|
1342                                                          (p->hl[0])) &
1343                                                  off;
1344                                         break;
1345                                 case FILE_OPOR:
1346                                         offset = (int32_t)((p->hl[3]<<24)|
1347                                                          (p->hl[2]<<16)|
1348                                                          (p->hl[1]<<8)|
1349                                                          (p->hl[0])) |
1350                                                  off;
1351                                         break;
1352                                 case FILE_OPXOR:
1353                                         offset = (int32_t)((p->hl[3]<<24)|
1354                                                          (p->hl[2]<<16)|
1355                                                          (p->hl[1]<<8)|
1356                                                          (p->hl[0])) ^
1357                                                  off;
1358                                         break;
1359                                 case FILE_OPADD:
1360                                         offset = (int32_t)((p->hl[3]<<24)|
1361                                                          (p->hl[2]<<16)|
1362                                                          (p->hl[1]<<8)|
1363                                                          (p->hl[0])) +
1364                                                  off;
1365                                         break;
1366                                 case FILE_OPMINUS:
1367                                         offset = (int32_t)((p->hl[3]<<24)|
1368                                                          (p->hl[2]<<16)|
1369                                                          (p->hl[1]<<8)|
1370                                                          (p->hl[0])) -
1371                                                  off;
1372                                         break;
1373                                 case FILE_OPMULTIPLY:
1374                                         offset = (int32_t)((p->hl[3]<<24)|
1375                                                          (p->hl[2]<<16)|
1376                                                          (p->hl[1]<<8)|
1377                                                          (p->hl[0])) *
1378                                                  off;
1379                                         break;
1380                                 case FILE_OPDIVIDE:
1381                                         offset = (int32_t)((p->hl[3]<<24)|
1382                                                          (p->hl[2]<<16)|
1383                                                          (p->hl[1]<<8)|
1384                                                          (p->hl[0])) /
1385                                                  off;
1386                                         break;
1387                                 case FILE_OPMODULO:
1388                                         offset = (int32_t)((p->hl[3]<<24)|
1389                                                          (p->hl[2]<<16)|
1390                                                          (p->hl[1]<<8)|
1391                                                          (p->hl[0])) %
1392                                                  off;
1393                                         break;
1394                                 }
1395                         } else
1396                                 offset = (int32_t)((p->hl[3]<<24)|
1397                                                  (p->hl[2]<<16)|
1398                                                  (p->hl[1]<<8)|
1399                                                  (p->hl[0]));
1400                         if (m->in_op & FILE_OPINVERSE)
1401                                 offset = ~offset;
1402                         break;
1403                 case FILE_MELONG:
1404                         if (OFFSET_OOB(nbytes, offset, 4))
1405                                 return 0;
1406                         if (off) {
1407                                 switch (m->in_op & FILE_OPS_MASK) {
1408                                 case FILE_OPAND:
1409                                         offset = (int32_t)((p->hl[1]<<24)|
1410                                                          (p->hl[0]<<16)|
1411                                                          (p->hl[3]<<8)|
1412                                                          (p->hl[2])) &
1413                                                  off;
1414                                         break;
1415                                 case FILE_OPOR:
1416                                         offset = (int32_t)((p->hl[1]<<24)|
1417                                                          (p->hl[0]<<16)|
1418                                                          (p->hl[3]<<8)|
1419                                                          (p->hl[2])) |
1420                                                  off;
1421                                         break;
1422                                 case FILE_OPXOR:
1423                                         offset = (int32_t)((p->hl[1]<<24)|
1424                                                          (p->hl[0]<<16)|
1425                                                          (p->hl[3]<<8)|
1426                                                          (p->hl[2])) ^
1427                                                  off;
1428                                         break;
1429                                 case FILE_OPADD:
1430                                         offset = (int32_t)((p->hl[1]<<24)|
1431                                                          (p->hl[0]<<16)|
1432                                                          (p->hl[3]<<8)|
1433                                                          (p->hl[2])) +
1434                                                  off;
1435                                         break;
1436                                 case FILE_OPMINUS:
1437                                         offset = (int32_t)((p->hl[1]<<24)|
1438                                                          (p->hl[0]<<16)|
1439                                                          (p->hl[3]<<8)|
1440                                                          (p->hl[2])) -
1441                                                  off;
1442                                         break;
1443                                 case FILE_OPMULTIPLY:
1444                                         offset = (int32_t)((p->hl[1]<<24)|
1445                                                          (p->hl[0]<<16)|
1446                                                          (p->hl[3]<<8)|
1447                                                          (p->hl[2])) *
1448                                                  off;
1449                                         break;
1450                                 case FILE_OPDIVIDE:
1451                                         offset = (int32_t)((p->hl[1]<<24)|
1452                                                          (p->hl[0]<<16)|
1453                                                          (p->hl[3]<<8)|
1454                                                          (p->hl[2])) /
1455                                                  off;
1456                                         break;
1457                                 case FILE_OPMODULO:
1458                                         offset = (int32_t)((p->hl[1]<<24)|
1459                                                          (p->hl[0]<<16)|
1460                                                          (p->hl[3]<<8)|
1461                                                          (p->hl[2])) %
1462                                                  off;
1463                                         break;
1464                                 }
1465                         } else
1466                                 offset = (int32_t)((p->hl[1]<<24)|
1467                                                  (p->hl[0]<<16)|
1468                                                  (p->hl[3]<<8)|
1469                                                  (p->hl[2]));
1470                         if (m->in_op & FILE_OPINVERSE)
1471                                 offset = ~offset;
1472                         break;
1473                 case FILE_LONG:
1474                         if (OFFSET_OOB(nbytes, offset, 4))
1475                                 return 0;
1476                         if (off) {
1477                                 switch (m->in_op & FILE_OPS_MASK) {
1478                                 case FILE_OPAND:
1479                                         offset = p->l & off;
1480                                         break;
1481                                 case FILE_OPOR:
1482                                         offset = p->l | off;
1483                                         break;
1484                                 case FILE_OPXOR:
1485                                         offset = p->l ^ off;
1486                                         break;
1487                                 case FILE_OPADD:
1488                                         offset = p->l + off;
1489                                         break;
1490                                 case FILE_OPMINUS:
1491                                         offset = p->l - off;
1492                                         break;
1493                                 case FILE_OPMULTIPLY:
1494                                         offset = p->l * off;
1495                                         break;
1496                                 case FILE_OPDIVIDE:
1497                                         offset = p->l / off;
1498                                         break;
1499                                 case FILE_OPMODULO:
1500                                         offset = p->l % off;
1501                                         break;
1502                                 }
1503                         } else
1504                                 offset = p->l;
1505                         if (m->in_op & FILE_OPINVERSE)
1506                                 offset = ~offset;
1507                         break;
1508                 }
1509
1510                 switch (m->in_type) {
1511                 case FILE_LEID3:
1512                 case FILE_BEID3:
1513                         offset = ((((offset >>  0) & 0x7f) <<  0) |
1514                                  (((offset >>  8) & 0x7f) <<  7) |
1515                                  (((offset >> 16) & 0x7f) << 14) |
1516                                  (((offset >> 24) & 0x7f) << 21)) + 10;
1517                         break;
1518                 default:
1519                         break;
1520                 }
1521
1522                 if (m->flag & INDIROFFADD) {
1523                         offset += ms->c.li[cont_level-1].off;
1524                 }
1525                 if (mcopy(ms, p, m->type, 0, s, offset, nbytes, count) == -1)
1526                         return -1;
1527                 ms->offset = offset;
1528
1529                 if ((ms->flags & MAGIC_DEBUG) != 0) {
1530                         mdebug(offset, (char *)(void *)p,
1531                             sizeof(union VALUETYPE));
1532 #ifndef COMPILE_ONLY
1533                         file_mdump(m);
1534 #endif
1535                 }
1536         }
1537
1538         /* Verify we have enough data to match magic type */
1539         switch (m->type) {
1540         case FILE_BYTE:
1541                 if (OFFSET_OOB(nbytes, offset, 1))
1542                         return 0;
1543                 break;
1544
1545         case FILE_SHORT:
1546         case FILE_BESHORT:
1547         case FILE_LESHORT:
1548                 if (OFFSET_OOB(nbytes, offset, 2))
1549                         return 0;
1550                 break;
1551
1552         case FILE_LONG:
1553         case FILE_BELONG:
1554         case FILE_LELONG:
1555         case FILE_MELONG:
1556         case FILE_DATE:
1557         case FILE_BEDATE:
1558         case FILE_LEDATE:
1559         case FILE_MEDATE:
1560         case FILE_LDATE:
1561         case FILE_BELDATE:
1562         case FILE_LELDATE:
1563         case FILE_MELDATE:
1564         case FILE_FLOAT:
1565         case FILE_BEFLOAT:
1566         case FILE_LEFLOAT:
1567                 if (OFFSET_OOB(nbytes, offset, 4))
1568                         return 0;
1569                 break;
1570
1571         case FILE_DOUBLE:
1572         case FILE_BEDOUBLE:
1573         case FILE_LEDOUBLE:
1574                 if (OFFSET_OOB(nbytes, offset, 8))
1575                         return 0;
1576                 break;
1577
1578         case FILE_STRING:
1579         case FILE_PSTRING:
1580         case FILE_SEARCH:
1581                 if (OFFSET_OOB(nbytes, offset, m->vallen))
1582                         return 0;
1583                 break;
1584
1585         case FILE_REGEX:
1586                 if (OFFSET_OOB(nbytes, offset, 0))
1587                         return 0;
1588                 break;
1589
1590         case FILE_INDIRECT:
1591                 if (offset == 0)
1592                         return 0;
1593                 if ((ms->flags & (MAGIC_MIME|MAGIC_APPLE)) == 0 &&
1594                     file_printf(ms, m->desc) == -1)
1595                         return -1;
1596                 if (OFFSET_OOB(nbytes, offset, 0))
1597                         return 0;
1598                 return file_softmagic(ms, s + offset, nbytes - offset,
1599                     recursion_level, BINTEST);
1600
1601         case FILE_DEFAULT:      /* nothing to check */
1602         default:
1603                 break;
1604         }
1605         if (!mconvert(ms, m))
1606                 return 0;
1607         return 1;
1608 }
1609
1610 private uint64_t
1611 file_strncmp(const char *s1, const char *s2, size_t len, uint32_t flags)
1612 {
1613         /*
1614          * Convert the source args to unsigned here so that (1) the
1615          * compare will be unsigned as it is in strncmp() and (2) so
1616          * the ctype functions will work correctly without extra
1617          * casting.
1618          */
1619         const unsigned char *a = (const unsigned char *)s1;
1620         const unsigned char *b = (const unsigned char *)s2;
1621         uint64_t v;
1622
1623         /*
1624          * What we want here is v = strncmp(s1, s2, len),
1625          * but ignoring any nulls.
1626          */
1627         v = 0;
1628         if (0L == flags) { /* normal string: do it fast */
1629                 while (len-- > 0)
1630                         if ((v = *b++ - *a++) != '\0')
1631                                 break;
1632         }
1633         else { /* combine the others */
1634                 while (len-- > 0) {
1635                         if ((flags & STRING_IGNORE_LOWERCASE) &&
1636                             islower(*a)) {
1637                                 if ((v = tolower(*b++) - *a++) != '\0')
1638                                         break;
1639                         }
1640                         else if ((flags & STRING_IGNORE_UPPERCASE) &&
1641                             isupper(*a)) {
1642                                 if ((v = toupper(*b++) - *a++) != '\0')
1643                                         break;
1644                         }
1645                         else if ((flags & STRING_COMPACT_BLANK) &&
1646                             isspace(*a)) {
1647                                 a++;
1648                                 if (isspace(*b++)) {
1649                                         while (isspace(*b))
1650                                                 b++;
1651                                 }
1652                                 else {
1653                                         v = 1;
1654                                         break;
1655                                 }
1656                         }
1657                         else if ((flags & STRING_COMPACT_OPTIONAL_BLANK) &&
1658                             isspace(*a)) {
1659                                 a++;
1660                                 while (isspace(*b))
1661                                         b++;
1662                         }
1663                         else {
1664                                 if ((v = *b++ - *a++) != '\0')
1665                                         break;
1666                         }
1667                 }
1668         }
1669         return v;
1670 }
1671
1672 private uint64_t
1673 file_strncmp16(const char *a, const char *b, size_t len, uint32_t flags)
1674 {
1675         /*
1676          * XXX - The 16-bit string compare probably needs to be done
1677          * differently, especially if the flags are to be supported.
1678          * At the moment, I am unsure.
1679          */
1680         flags = 0;
1681         return file_strncmp(a, b, len, flags);
1682 }
1683
1684 private int
1685 magiccheck(struct magic_set *ms, struct magic *m)
1686 {
1687         uint64_t l = m->value.q;
1688         uint64_t v;
1689         float fl, fv;
1690         double dl, dv;
1691         int matched;
1692         union VALUETYPE *p = &ms->ms_value;
1693
1694         switch (m->type) {
1695         case FILE_BYTE:
1696                 v = p->b;
1697                 break;
1698
1699         case FILE_SHORT:
1700         case FILE_BESHORT:
1701         case FILE_LESHORT:
1702                 v = p->h;
1703                 break;
1704
1705         case FILE_LONG:
1706         case FILE_BELONG:
1707         case FILE_LELONG:
1708         case FILE_MELONG:
1709         case FILE_DATE:
1710         case FILE_BEDATE:
1711         case FILE_LEDATE:
1712         case FILE_MEDATE:
1713         case FILE_LDATE:
1714         case FILE_BELDATE:
1715         case FILE_LELDATE:
1716         case FILE_MELDATE:
1717                 v = p->l;
1718                 break;
1719
1720         case FILE_QUAD:
1721         case FILE_LEQUAD:
1722         case FILE_BEQUAD:
1723         case FILE_QDATE:
1724         case FILE_BEQDATE:
1725         case FILE_LEQDATE:
1726         case FILE_QLDATE:
1727         case FILE_BEQLDATE:
1728         case FILE_LEQLDATE:
1729                 v = p->q;
1730                 break;
1731
1732         case FILE_FLOAT:
1733         case FILE_BEFLOAT:
1734         case FILE_LEFLOAT:
1735                 fl = m->value.f;
1736                 fv = p->f;
1737                 switch (m->reln) {
1738                 case 'x':
1739                         matched = 1;
1740                         break;
1741
1742                 case '!':
1743                         matched = fv != fl;
1744                         break;
1745
1746                 case '=':
1747                         matched = fv == fl;
1748                         break;
1749
1750                 case '>':
1751                         matched = fv > fl;
1752                         break;
1753
1754                 case '<':
1755                         matched = fv < fl;
1756                         break;
1757
1758                 default:
1759                         matched = 0;
1760                         file_magerror(ms, "cannot happen with float: invalid relation `%c'",
1761                             m->reln);
1762                         return -1;
1763                 }
1764                 return matched;
1765
1766         case FILE_DOUBLE:
1767         case FILE_BEDOUBLE:
1768         case FILE_LEDOUBLE:
1769                 dl = m->value.d;
1770                 dv = p->d;
1771                 switch (m->reln) {
1772                 case 'x':
1773                         matched = 1;
1774                         break;
1775
1776                 case '!':
1777                         matched = dv != dl;
1778                         break;
1779
1780                 case '=':
1781                         matched = dv == dl;
1782                         break;
1783
1784                 case '>':
1785                         matched = dv > dl;
1786                         break;
1787
1788                 case '<':
1789                         matched = dv < dl;
1790                         break;
1791
1792                 default:
1793                         matched = 0;
1794                         file_magerror(ms, "cannot happen with double: invalid relation `%c'", m->reln);
1795                         return -1;
1796                 }
1797                 return matched;
1798
1799         case FILE_DEFAULT:
1800                 l = 0;
1801                 v = 0;
1802                 break;
1803
1804         case FILE_STRING:
1805         case FILE_PSTRING:
1806                 l = 0;
1807                 v = file_strncmp(m->value.s, p->s, (size_t)m->vallen, m->str_flags);
1808                 break;
1809
1810         case FILE_BESTRING16:
1811         case FILE_LESTRING16:
1812                 l = 0;
1813                 v = file_strncmp16(m->value.s, p->s, (size_t)m->vallen, m->str_flags);
1814                 break;
1815
1816         case FILE_SEARCH: { /* search ms->search.s for the string m->value.s */
1817                 size_t slen;
1818                 size_t idx;
1819
1820                 if (ms->search.s == NULL)
1821                         return 0;
1822
1823                 slen = MIN(m->vallen, sizeof(m->value.s));
1824                 l = 0;
1825                 v = 0;
1826
1827                 for (idx = 0; m->str_range == 0 || idx < m->str_range; idx++) {
1828                         if (slen + idx > ms->search.s_len)
1829                                 break;
1830
1831                         v = file_strncmp(m->value.s, ms->search.s + idx, slen, m->str_flags);
1832                         if (v == 0) {   /* found match */
1833                                 ms->search.offset += idx;
1834                                 break;
1835                         }
1836                 }
1837                 break;
1838         }
1839         case FILE_REGEX: {
1840                 int rc;
1841                 regex_t rx;
1842                 char errmsg[512];
1843
1844                 if (ms->search.s == NULL)
1845                         return 0;
1846
1847                 l = 0;
1848                 rc = regcomp(&rx, m->value.s,
1849                     REG_EXTENDED|REG_NEWLINE|
1850                     ((m->str_flags & STRING_IGNORE_CASE) ? REG_ICASE : 0));
1851                 if (rc) {
1852                         (void)regerror(rc, &rx, errmsg, sizeof(errmsg));
1853                         file_magerror(ms, "regex error %d, (%s)",
1854                             rc, errmsg);
1855                         v = (uint64_t)-1;
1856                 }
1857                 else {
1858                         regmatch_t pmatch[1];
1859 #ifndef REG_STARTEND
1860 #define REG_STARTEND    0
1861                         size_t l = ms->search.s_len - 1;
1862                         char c = ms->search.s[l];
1863                         ((char *)(intptr_t)ms->search.s)[l] = '\0';
1864 #else
1865                         pmatch[0].rm_so = 0;
1866                         pmatch[0].rm_eo = ms->search.s_len;
1867 #endif
1868                         rc = regexec(&rx, (const char *)ms->search.s,
1869                             1, pmatch, REG_STARTEND);
1870 #if REG_STARTEND == 0
1871                         ((char *)(intptr_t)ms->search.s)[l] = c;
1872 #endif
1873                         switch (rc) {
1874                         case 0:
1875                                 ms->search.s += (int)pmatch[0].rm_so;
1876                                 ms->search.offset += (size_t)pmatch[0].rm_so;
1877                                 ms->search.rm_len =
1878                                     (size_t)(pmatch[0].rm_eo - pmatch[0].rm_so);
1879                                 v = 0;
1880                                 break;
1881
1882                         case REG_NOMATCH:
1883                                 v = 1;
1884                                 break;
1885
1886                         default:
1887                                 (void)regerror(rc, &rx, errmsg, sizeof(errmsg));
1888                                 file_magerror(ms, "regexec error %d, (%s)",
1889                                     rc, errmsg);
1890                                 v = (uint64_t)-1;
1891                                 break;
1892                         }
1893                         regfree(&rx);
1894                 }
1895                 if (v == (uint64_t)-1)
1896                         return -1;
1897                 break;
1898         }
1899         case FILE_INDIRECT:
1900                 return 1;
1901         default:
1902                 file_magerror(ms, "invalid type %d in magiccheck()", m->type);
1903                 return -1;
1904         }
1905
1906         v = file_signextend(ms, m, v);
1907
1908         switch (m->reln) {
1909         case 'x':
1910                 if ((ms->flags & MAGIC_DEBUG) != 0)
1911                         (void) fprintf(stderr, "%llu == *any* = 1\n",
1912                             (unsigned long long)v);
1913                 matched = 1;
1914                 break;
1915
1916         case '!':
1917                 matched = v != l;
1918                 if ((ms->flags & MAGIC_DEBUG) != 0)
1919                         (void) fprintf(stderr, "%llu != %llu = %d\n",
1920                             (unsigned long long)v, (unsigned long long)l,
1921                             matched);
1922                 break;
1923
1924         case '=':
1925                 matched = v == l;
1926                 if ((ms->flags & MAGIC_DEBUG) != 0)
1927                         (void) fprintf(stderr, "%llu == %llu = %d\n",
1928                             (unsigned long long)v, (unsigned long long)l,
1929                             matched);
1930                 break;
1931
1932         case '>':
1933                 if (m->flag & UNSIGNED) {
1934                         matched = v > l;
1935                         if ((ms->flags & MAGIC_DEBUG) != 0)
1936                                 (void) fprintf(stderr, "%llu > %llu = %d\n",
1937                                     (unsigned long long)v,
1938                                     (unsigned long long)l, matched);
1939                 }
1940                 else {
1941                         matched = (int64_t) v > (int64_t) l;
1942                         if ((ms->flags & MAGIC_DEBUG) != 0)
1943                                 (void) fprintf(stderr, "%lld > %lld = %d\n",
1944                                     (long long)v, (long long)l, matched);
1945                 }
1946                 break;
1947
1948         case '<':
1949                 if (m->flag & UNSIGNED) {
1950                         matched = v < l;
1951                         if ((ms->flags & MAGIC_DEBUG) != 0)
1952                                 (void) fprintf(stderr, "%llu < %llu = %d\n",
1953                                     (unsigned long long)v,
1954                                     (unsigned long long)l, matched);
1955                 }
1956                 else {
1957                         matched = (int64_t) v < (int64_t) l;
1958                         if ((ms->flags & MAGIC_DEBUG) != 0)
1959                                 (void) fprintf(stderr, "%lld < %lld = %d\n",
1960                                        (long long)v, (long long)l, matched);
1961                 }
1962                 break;
1963
1964         case '&':
1965                 matched = (v & l) == l;
1966                 if ((ms->flags & MAGIC_DEBUG) != 0)
1967                         (void) fprintf(stderr, "((%llx & %llx) == %llx) = %d\n",
1968                             (unsigned long long)v, (unsigned long long)l,
1969                             (unsigned long long)l, matched);
1970                 break;
1971
1972         case '^':
1973                 matched = (v & l) != l;
1974                 if ((ms->flags & MAGIC_DEBUG) != 0)
1975                         (void) fprintf(stderr, "((%llx & %llx) != %llx) = %d\n",
1976                             (unsigned long long)v, (unsigned long long)l,
1977                             (unsigned long long)l, matched);
1978                 break;
1979
1980         default:
1981                 matched = 0;
1982                 file_magerror(ms, "cannot happen: invalid relation `%c'",
1983                     m->reln);
1984                 return -1;
1985         }
1986
1987         return matched;
1988 }
1989
1990 private int
1991 handle_annotation(struct magic_set *ms, struct magic *m)
1992 {
1993         if (ms->flags & MAGIC_APPLE) {
1994                 if (file_printf(ms, "%.8s", m->apple) == -1)
1995                         return -1;
1996                 return 1;
1997         }
1998         if ((ms->flags & MAGIC_MIME_TYPE) && m->mimetype[0]) {
1999                 if (file_printf(ms, "%s", m->mimetype) == -1)
2000                         return -1;
2001                 return 1;
2002         }
2003         return 0;
2004 }
2005
2006 private int
2007 print_sep(struct magic_set *ms, int firstline)
2008 {
2009         if (ms->flags & MAGIC_MIME)
2010                 return 0;
2011         if (firstline)
2012                 return 0;
2013         /*
2014          * we found another match
2015          * put a newline and '-' to do some simple formatting
2016          */
2017         return file_printf(ms, "\n- ");
2018 }