2 * Copyright (c) 2009 Joerg Sonnenberger <joerg@NetBSD.org>
3 * Copyright (c) 2007-2008 Dag-Erling Coïdan Smørgrav
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
9 * 1. Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer
11 * in this position and unchanged.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
16 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
30 * This file would be much shorter if we didn't care about command-line
31 * compatibility with Info-ZIP's UnZip, which requires us to duplicate
32 * parts of libarchive in order to gain more detailed control of its
33 * behaviour for the purpose of implementing the -n, -o, -L and -a
37 #include <sys/queue.h>
51 #include <archive_entry.h>
53 /* command-line options */
54 static int a_opt; /* convert EOL */
55 static int C_opt; /* match case-insensitively */
56 static int c_opt; /* extract to stdout */
57 static const char *d_arg; /* directory */
58 static int f_opt; /* update existing files only */
59 static int j_opt; /* junk directories */
60 static int L_opt; /* lowercase names */
61 static int n_opt; /* never overwrite */
62 static int o_opt; /* always overwrite */
63 static int p_opt; /* extract to stdout, quiet */
64 static int q_opt; /* quiet */
65 static int t_opt; /* test */
66 static int u_opt; /* update */
67 static int v_opt; /* verbose/list */
69 /* time when unzip started */
73 static int unzip_debug;
78 /* convenience macro */
79 /* XXX should differentiate between ARCHIVE_{WARN,FAIL,RETRY} */
83 if (acret != ARCHIVE_OK) \
84 errorx("%s", archive_error_string(a)); \
88 * Indicates that last info() did not end with EOL. This helps error() et
89 * al. avoid printing an error message on the same line as an incomplete
90 * informational message.
94 /* fatal error message + errno */
96 error(const char *fmt, ...)
101 fprintf(stdout, "\n");
103 fprintf(stderr, "unzip: ");
105 vfprintf(stderr, fmt, ap);
107 fprintf(stderr, ": %s\n", strerror(errno));
111 /* fatal error message, no errno */
113 errorx(const char *fmt, ...)
118 fprintf(stdout, "\n");
120 fprintf(stderr, "unzip: ");
122 vfprintf(stderr, fmt, ap);
124 fprintf(stderr, "\n");
129 /* non-fatal error message + errno */
131 warning(const char *fmt, ...)
136 fprintf(stdout, "\n");
138 fprintf(stderr, "unzip: ");
140 vfprintf(stderr, fmt, ap);
142 fprintf(stderr, ": %s\n", strerror(errno));
146 /* non-fatal error message, no errno */
148 warningx(const char *fmt, ...)
153 fprintf(stdout, "\n");
155 fprintf(stderr, "unzip: ");
157 vfprintf(stderr, fmt, ap);
159 fprintf(stderr, "\n");
162 /* informational message (if not -q) */
164 info(const char *fmt, ...)
168 if (q_opt && !unzip_debug)
171 vfprintf(stdout, fmt, ap);
178 noeol = fmt[strlen(fmt) - 1] != '\n';
181 /* debug message (if unzip_debug) */
183 debug(const char *fmt, ...)
190 vfprintf(stderr, fmt, ap);
197 noeol = fmt[strlen(fmt) - 1] != '\n';
200 /* duplicate a path name, possibly converting to lower case */
202 pathdup(const char *path)
208 while (len && path[len - 1] == '/')
210 if ((str = malloc(len + 1)) == NULL) {
215 for (i = 0; i < len; ++i)
216 str[i] = tolower((unsigned char)path[i]);
218 memcpy(str, path, len);
225 /* concatenate two path names */
227 pathcat(const char *prefix, const char *path)
232 prelen = prefix ? strlen(prefix) + 1 : 0;
233 len = strlen(path) + 1;
234 if ((str = malloc(prelen + len)) == NULL) {
239 memcpy(str, prefix, prelen); /* includes zero */
240 str[prelen - 1] = '/'; /* splat zero */
242 memcpy(str + prelen, path, len); /* includes zero */
248 * Pattern lists for include / exclude processing
251 STAILQ_ENTRY(pattern) link;
255 STAILQ_HEAD(pattern_list, pattern);
256 static struct pattern_list include = STAILQ_HEAD_INITIALIZER(include);
257 static struct pattern_list exclude = STAILQ_HEAD_INITIALIZER(exclude);
260 * Add an entry to a pattern list
263 add_pattern(struct pattern_list *list, const char *pattern)
265 struct pattern *entry;
268 debug("adding pattern '%s'\n", pattern);
269 len = strlen(pattern);
270 if ((entry = malloc(sizeof *entry + len + 1)) == NULL) {
274 memcpy(entry->pattern, pattern, len + 1);
275 STAILQ_INSERT_TAIL(list, entry, link);
279 * Match a string against a list of patterns
282 match_pattern(struct pattern_list *list, const char *str)
284 struct pattern *entry;
286 STAILQ_FOREACH(entry, list, link) {
287 if (fnmatch(entry->pattern, str, C_opt ? FNM_CASEFOLD : 0) == 0)
294 * Verify that a given pathname is in the include list and not in the
298 accept_pathname(const char *pathname)
301 if (!STAILQ_EMPTY(&include) && !match_pattern(&include, pathname))
303 if (!STAILQ_EMPTY(&exclude) && match_pattern(&exclude, pathname))
309 * Create the specified directory with the specified mode, taking certain
310 * precautions on they way.
313 make_dir(const char *path, int mode)
317 if (lstat(path, &sb) == 0) {
318 if (S_ISDIR(sb.st_mode))
321 * Normally, we should either ask the user about removing
322 * the non-directory of the same name as a directory we
323 * wish to create, or respect the -n or -o command-line
324 * options. However, this may lead to a later failure or
325 * even compromise (if this non-directory happens to be a
326 * symlink to somewhere unsafe), so we don't.
330 * Don't check unlink() result; failure will cause mkdir()
331 * to fail later, which we will catch.
335 if (mkdir(path, mode) != 0 && errno != EEXIST)
336 error("mkdir('%s')", path);
340 * Ensure that all directories leading up to (but not including) the
341 * specified path exist.
343 * XXX inefficient + modifies the file in-place
346 make_parent(char *path)
351 sep = strrchr(path, '/');
352 if (sep == NULL || sep == path)
355 if (lstat(path, &sb) == 0) {
356 if (S_ISDIR(sb.st_mode)) {
367 for (sep = path; (sep = strchr(sep, '/')) != NULL; sep++) {
368 /* root in case of absolute d_arg */
372 make_dir(path, 0755);
379 * Extract a directory.
382 extract_dir(struct archive *a, struct archive_entry *e, const char *path)
386 mode = archive_entry_filetype(e) & 0777;
391 * Some zipfiles contain directories with weird permissions such
392 * as 0644 or 0444. This can cause strange issues such as being
393 * unable to extract files into the directory we just created, or
394 * the user being unable to remove the directory later without
395 * first manually changing its permissions. Therefore, we whack
396 * the permissions into shape, assuming that the user wants full
397 * access and that anyone who gets read access also gets execute
406 info("d %s\n", path);
407 make_dir(path, mode);
408 ac(archive_read_data_skip(a));
411 static unsigned char buffer[8192];
412 static char spinner[] = { '|', '/', '-', '\\' };
415 * Extract a regular file.
418 extract_file(struct archive *a, struct archive_entry *e, const char *path)
423 struct timeval tv[2];
424 int cr, fd, text, warn;
426 unsigned char *p, *q, *end;
428 mode = archive_entry_filetype(e) & 0777;
431 mtime = archive_entry_mtime(e);
433 /* look for existing file of same name */
434 if (lstat(path, &sb) == 0) {
435 if (u_opt || f_opt) {
436 /* check if up-to-date */
437 if (S_ISREG(sb.st_mode) && sb.st_mtime >= mtime)
444 /* do not overwrite */
448 errorx("not implemented");
455 if ((fd = open(path, O_RDWR|O_CREAT|O_TRUNC, mode)) < 0)
456 error("open('%s')", path);
458 /* loop over file contents and write to disk */
459 info(" extracting: %s", path);
463 for (int n = 0; ; n++) {
464 if (tty && (n % 4) == 0)
465 info(" %c\b\b", spinner[(n / 4) % sizeof spinner]);
467 len = archive_read_data(a, buffer, sizeof buffer);
472 /* left over CR from previous buffer */
474 if (len == 0 || buffer[0] != '\n')
475 if (write(fd, "\r", 1) != 1)
476 error("write('%s')", path);
486 * Detect whether this is a text file. The correct way to
487 * do this is to check the least significant bit of the
488 * "internal file attributes" field of the corresponding
489 * file header in the central directory, but libarchive
490 * does not read the central directory, so we have to
491 * guess by looking for non-ASCII characters in the
492 * buffer. Hopefully we won't guess wrong. If we do
493 * guess wrong, we print a warning message later.
495 if (a_opt && n == 0) {
496 for (p = buffer; p < end; ++p) {
497 if (!isascii((unsigned char)*p)) {
505 if (!a_opt || !text) {
506 if (write(fd, buffer, len) != len)
507 error("write('%s')", path);
511 /* hard case: convert \r\n to \n (sigh...) */
512 for (p = buffer; p < end; p = q + 1) {
513 for (q = p; q < end; q++) {
514 if (!warn && !isascii(*q)) {
515 warningx("%s may be corrupted due"
516 " to weak text file detection"
529 if (write(fd, p, q - p) != q - p)
530 error("write('%s')", path);
539 /* set access and modification time */
542 tv[1].tv_sec = mtime;
544 if (futimes(fd, tv) != 0)
545 error("utimes('%s')", path);
547 error("close('%s')", path);
551 * Extract a zipfile entry: first perform some sanity checks to ensure
552 * that it is either a directory or a regular file and that the path is
553 * not absolute and does not try to break out of the current directory;
554 * then call either extract_dir() or extract_file() as appropriate.
556 * This is complicated a bit by the various ways in which we need to
557 * manipulate the path name. Case conversion (if requested by the -L
558 * option) happens first, but the include / exclude patterns are applied
559 * to the full converted path name, before the directory part of the path
560 * is removed in accordance with the -j option. Sanity checks are
561 * intentionally done earlier than they need to be, so the user will get a
562 * warning about insecure paths even for files or directories which
563 * wouldn't be extracted anyway.
566 extract(struct archive *a, struct archive_entry *e)
568 char *pathname, *realpathname;
572 pathname = pathdup(archive_entry_pathname(e));
573 filetype = archive_entry_filetype(e);
576 if (pathname[0] == '/' ||
577 strncmp(pathname, "../", 3) == 0 ||
578 strstr(pathname, "/../") != NULL) {
579 warningx("skipping insecure entry '%s'", pathname);
580 ac(archive_read_data_skip(a));
585 /* I don't think this can happen in a zipfile.. */
586 if (!S_ISDIR(filetype) && !S_ISREG(filetype)) {
587 warningx("skipping non-regular entry '%s'", pathname);
588 ac(archive_read_data_skip(a));
593 /* skip directories in -j case */
594 if (S_ISDIR(filetype) && j_opt) {
595 ac(archive_read_data_skip(a));
600 /* apply include / exclude patterns */
601 if (!accept_pathname(pathname)) {
602 ac(archive_read_data_skip(a));
607 /* apply -j and -d */
609 for (p = q = pathname; *p; ++p)
612 realpathname = pathcat(d_arg, q);
614 realpathname = pathcat(d_arg, pathname);
617 /* ensure that parent directory exists */
618 make_parent(realpathname);
620 if (S_ISDIR(filetype))
621 extract_dir(a, e, realpathname);
623 extract_file(a, e, realpathname);
630 extract_stdout(struct archive *a, struct archive_entry *e)
636 unsigned char *p, *q, *end;
638 pathname = pathdup(archive_entry_pathname(e));
639 filetype = archive_entry_filetype(e);
641 /* I don't think this can happen in a zipfile.. */
642 if (!S_ISDIR(filetype) && !S_ISREG(filetype)) {
643 warningx("skipping non-regular entry '%s'", pathname);
644 ac(archive_read_data_skip(a));
649 /* skip directories in -j case */
650 if (S_ISDIR(filetype)) {
651 ac(archive_read_data_skip(a));
656 /* apply include / exclude patterns */
657 if (!accept_pathname(pathname)) {
658 ac(archive_read_data_skip(a));
664 info("x %s\n", pathname);
669 for (int n = 0; ; n++) {
670 len = archive_read_data(a, buffer, sizeof buffer);
675 /* left over CR from previous buffer */
677 if (len == 0 || buffer[0] != '\n') {
678 if (fwrite("\r", 1, 1, stderr) != 1)
679 error("write('%s')", pathname);
690 * Detect whether this is a text file. The correct way to
691 * do this is to check the least significant bit of the
692 * "internal file attributes" field of the corresponding
693 * file header in the central directory, but libarchive
694 * does not read the central directory, so we have to
695 * guess by looking for non-ASCII characters in the
696 * buffer. Hopefully we won't guess wrong. If we do
697 * guess wrong, we print a warning message later.
699 if (a_opt && n == 0) {
700 for (p = buffer; p < end; ++p) {
701 if (!isascii((unsigned char)*p)) {
709 if (!a_opt || !text) {
710 if (fwrite(buffer, 1, len, stdout) != (size_t)len)
711 error("write('%s')", pathname);
715 /* hard case: convert \r\n to \n (sigh...) */
716 for (p = buffer; p < end; p = q + 1) {
717 for (q = p; q < end; q++) {
718 if (!warn && !isascii(*q)) {
719 warningx("%s may be corrupted due"
720 " to weak text file detection"
721 " heuristic", pathname);
733 if (fwrite(p, 1, q - p, stdout) != (size_t)(q - p))
734 error("write('%s')", pathname);
742 * Print the name of an entry to stdout.
745 list(struct archive *a, struct archive_entry *e)
750 mtime = archive_entry_mtime(e);
751 strftime(buf, sizeof(buf), "%m-%d-%g %R", localtime(&mtime));
754 printf(" %8ju %s %s\n",
755 (uintmax_t)archive_entry_size(e),
756 buf, archive_entry_pathname(e));
757 } else if (v_opt == 2) {
758 printf("%8ju Stored %7ju 0%% %s %08x %s\n",
759 (uintmax_t)archive_entry_size(e),
760 (uintmax_t)archive_entry_size(e),
763 archive_entry_pathname(e));
765 ac(archive_read_data_skip(a));
769 * Extract to memory to check CRC
772 test(struct archive *a, struct archive_entry *e)
778 if (S_ISDIR(archive_entry_filetype(e)))
781 info(" testing: %s\t", archive_entry_pathname(e));
782 while ((len = archive_read_data(a, buffer, sizeof buffer)) > 0)
785 info(" %s\n", archive_error_string(a));
791 /* shouldn't be necessary, but it doesn't hurt */
792 ac(archive_read_data_skip(a));
799 * Main loop: open the zipfile, iterate over its contents and decide what
800 * to do with each entry.
803 unzip(const char *fn)
806 struct archive_entry *e;
808 uintmax_t total_size, file_count, error_count;
810 if ((fd = open(fn, O_RDONLY)) < 0)
813 a = archive_read_new();
814 ac(archive_read_support_format_zip(a));
815 ac(archive_read_open_fd(a, fd, 8192));
817 printf("Archive: %s\n", fn);
819 printf(" Length Date Time Name\n");
820 printf(" -------- ---- ---- ----\n");
821 } else if (v_opt == 2) {
822 printf(" Length Method Size Ratio Date Time CRC-32 Name\n");
823 printf("-------- ------ ------- ----- ---- ---- ------ ----\n");
830 ret = archive_read_next_header(a, &e);
831 if (ret == ARCHIVE_EOF)
835 error_count += test(a, e);
838 else if (p_opt || c_opt)
839 extract_stdout(a, e);
843 total_size += archive_entry_size(e);
848 printf(" -------- -------\n");
849 printf(" %8ju %ju file%s\n",
850 total_size, file_count, file_count != 1 ? "s" : "");
851 } else if (v_opt == 2) {
852 printf("-------- ------- --- -------\n");
853 printf("%8ju %7ju 0%% %ju file%s\n",
854 total_size, total_size, file_count,
855 file_count != 1 ? "s" : "");
858 ac(archive_read_close(a));
859 (void)archive_read_finish(a);
865 if (error_count > 0) {
866 errorx("%d checksum error(s) found.", error_count);
869 printf("No errors detected in compressed data of %s.\n",
879 fprintf(stderr, "usage: unzip [-aCcfjLlnopqtuv] [-d dir] [-x pattern] zipfile\n");
884 getopts(int argc, char *argv[])
888 optreset = optind = 1;
889 while ((opt = getopt(argc, argv, "aCcd:fjLlnopqtuvx:")) != -1)
939 add_pattern(&exclude, optarg);
949 main(int argc, char *argv[])
954 if (isatty(STDOUT_FILENO))
957 if (getenv("UNZIP_DEBUG") != NULL)
959 for (int i = 0; i < argc; ++i)
960 debug("%s%c", argv[i], (i < argc - 1) ? ' ' : '\n');
963 * Info-ZIP's unzip(1) expects certain options to come before the
964 * zipfile name, and others to come after - though it does not
965 * enforce this. For simplicity, we accept *all* options both
966 * before and after the zipfile name.
968 nopts = getopts(argc, argv);
972 zipfile = argv[nopts++];
974 while (nopts < argc && *argv[nopts] != '-')
975 add_pattern(&include, argv[nopts++]);
977 nopts--; /* fake argv[0] */
978 nopts += getopts(argc - nopts, argv + nopts);
980 if (n_opt + o_opt + u_opt > 1)
981 errorx("-n, -o and -u are contradictory");