1 /*-
2  * Copyright (c) 2003-2023 Tim Kientzle
3  * Copyright (c) 2008 Anselm Strauss
4  * All rights reserved.
5  *
6  * Redistribution and use in source and binary forms, with or without
7  * modification, are permitted provided that the following conditions
8  * are met:
9  * 1. Redistributions of source code must retain the above copyright
10  *    notice, this list of conditions and the following disclaimer.
11  * 2. Redistributions in binary form must reproduce the above copyright
12  *    notice, this list of conditions and the following disclaimer in the
13  *    documentation and/or other materials provided with the distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) ``AS IS'' AND ANY EXPRESS OR
16  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
17  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
18  * IN NO EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY DIRECT, INDIRECT,
19  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
20  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
21  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
22  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
23  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
24  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
25  */
26 
27 #include "test.h"
28 
29 /*
30  * Detailed byte-for-byte verification of the format of a zip archive
31  * written in streaming mode WITHOUT Zip64 extensions enabled.
32  */
33 
34 static unsigned long
bitcrc32(unsigned long c,void * _p,size_t s)35 bitcrc32(unsigned long c, void *_p, size_t s)
36 {
37 	/* This is a drop-in replacement for crc32() from zlib.
38 	 * Libarchive should be able to correctly generate
39 	 * uncompressed zip archives (including correct CRCs) even
40 	 * when zlib is unavailable, and this function helps us verify
41 	 * that.  Yes, this is very, very slow and unsuitable for
42 	 * production use, but it's correct, compact, and works well
43 	 * enough for this particular usage.  Libarchive internally
44 	 * uses a much more efficient implementation.  */
45 	const unsigned char *p = _p;
46 	int bitctr;
47 
48 	if (p == NULL)
49 		return (0);
50 
51 	for (; s > 0; --s) {
52 		c ^= *p++;
53 		for (bitctr = 8; bitctr > 0; --bitctr) {
54 			if (c & 1) c = (c >> 1);
55 			else	   c = (c >> 1) ^ 0xedb88320;
56 			c ^= 0x80000000;
57 		}
58 	}
59 	return (c);
60 }
61 
62 /* Quick and dirty: Read 2-byte and 4-byte integers from Zip file. */
i2(const unsigned char * p)63 static unsigned i2(const unsigned char *p) { return ((p[0] & 0xff) | ((p[1] & 0xff) << 8)); }
i4(const unsigned char * p)64 static unsigned i4(const unsigned char *p) { return (i2(p) | (i2(p + 2) << 16)); }
65 
DEFINE_TEST(test_write_format_zip_stream)66 DEFINE_TEST(test_write_format_zip_stream)
67 {
68 	struct archive *a;
69 	struct archive_entry *ae;
70 	size_t used, buffsize = 1000000;
71 	unsigned long crc;
72 	unsigned long compressed_size = 0;
73 	int file_perm = 00644;
74 	int zip_version = 20;
75 	int zip_compression = 8;
76 	short file_uid = 10, file_gid = 20;
77 	unsigned char *buff, *buffend, *p;
78 	unsigned char *central_header, *local_header, *eocd, *eocd_record;
79 	unsigned char *extension_start, *extension_end;
80 	unsigned char *data_start, *data_end;
81 	char file_data[] = {'1', '2', '3', '4', '5', '6', '7', '8'};
82 	const char *file_name = "file";
83 
84 #ifndef HAVE_ZLIB_H
85 	zip_compression = 0;
86 #endif
87 
88 	buff = malloc(buffsize);
89 
90 	/* Create a new archive in memory. */
91 	assert((a = archive_write_new()) != NULL);
92 	assertEqualIntA(a, ARCHIVE_OK, archive_write_set_format_zip(a));
93 	assertEqualIntA(a, ARCHIVE_OK,
94 	    archive_write_set_options(a, "zip:!zip64"));
95 	assertEqualIntA(a, ARCHIVE_OK,
96 	    archive_write_open_memory(a, buff, buffsize, &used));
97 
98 	assert((ae = archive_entry_new()) != NULL);
99 	archive_entry_copy_pathname(ae, file_name);
100 	archive_entry_set_mode(ae, AE_IFREG | file_perm);
101 	archive_entry_set_uid(ae, file_uid);
102 	archive_entry_set_gid(ae, file_gid);
103 	archive_entry_set_mtime(ae, 0, 0);
104 	assertEqualInt(0, archive_write_header(a, ae));
105 	archive_entry_free(ae);
106 	assertEqualInt(8, archive_write_data(a, file_data, sizeof(file_data)));
107 	assertEqualIntA(a, ARCHIVE_OK, archive_write_close(a));
108 	assertEqualInt(ARCHIVE_OK, archive_write_free(a));
109 	buffend = buff + used;
110 	dumpfile("constructed.zip", buff, used);
111 
112 	/* Verify "End of Central Directory" record. */
113 	/* Get address of end-of-central-directory record. */
114 	eocd_record = p = buffend - 22; /* Assumes there is no zip comment field. */
115 	failure("End-of-central-directory begins with PK\\005\\006 signature");
116 	assertEqualMem(p, "PK\005\006", 4);
117 	failure("This must be disk 0");
118 	assertEqualInt(i2(p + 4), 0);
119 	failure("Central dir must start on disk 0");
120 	assertEqualInt(i2(p + 6), 0);
121 	failure("All central dir entries are on this disk");
122 	assertEqualInt(i2(p + 8), i2(p + 10));
123 	eocd = buff + i4(p + 12) + i4(p + 16);
124 	failure("no zip comment");
125 	assertEqualInt(i2(p + 20), 0);
126 
127 	/* Get address of first entry in central directory. */
128 	central_header = p = buff + i4(buffend - 6);
129 	failure("Central file record at offset %d should begin with"
130 	    " PK\\001\\002 signature",
131 	    i4(buffend - 10));
132 
133 	/* Verify file entry in central directory. */
134 	assertEqualMem(p, "PK\001\002", 4); /* Signature */
135 	assertEqualInt(i2(p + 4), 3 * 256 + zip_version); /* Version made by */
136 	assertEqualInt(i2(p + 6), zip_version); /* Version needed to extract */
137 	assertEqualInt(i2(p + 8), 8); /* Flags */
138 	assertEqualInt(i2(p + 10), zip_compression); /* Compression method */
139 	assertEqualInt(i2(p + 12), 0); /* File time */
140 	assertEqualInt(i2(p + 14), 33); /* File date */
141 	crc = bitcrc32(0, file_data, sizeof(file_data));
142 	assertEqualInt(i4(p + 16), crc); /* CRC-32 */
143 	compressed_size = i4(p + 20);  /* Compressed size */
144 	assertEqualInt(i4(p + 24), sizeof(file_data)); /* Uncompressed size */
145 	assertEqualInt(i2(p + 28), strlen(file_name)); /* Pathname length */
146 	/* assertEqualInt(i2(p + 30), 28); */ /* Extra field length: See below */
147 	assertEqualInt(i2(p + 32), 0); /* File comment length */
148 	assertEqualInt(i2(p + 34), 0); /* Disk number start */
149 	assertEqualInt(i2(p + 36), 0); /* Internal file attrs */
150 	assertEqualInt(i4(p + 38) >> 16 & 01777, file_perm); /* External file attrs */
151 	assertEqualInt(i4(p + 42), 0); /* Offset of local header */
152 	assertEqualMem(p + 46, file_name, strlen(file_name)); /* Pathname */
153 	p = extension_start = central_header + 46 + strlen(file_name);
154 	extension_end = extension_start + i2(central_header + 30);
155 
156 	assertEqualInt(i2(p), 0x7875);  /* 'ux' extension header */
157 	assertEqualInt(i2(p + 2), 11); /* 'ux' size */
158 	assertEqualInt(p[4], 1); /* 'ux' version */
159 	assertEqualInt(p[5], 4); /* 'ux' uid size */
160 	assertEqualInt(i4(p + 6), file_uid); /* 'Ux' UID */
161 	assertEqualInt(p[10], 4); /* 'ux' gid size */
162 	assertEqualInt(i4(p + 11), file_gid); /* 'Ux' GID */
163 	p += 4 + i2(p + 2);
164 
165 	assertEqualInt(i2(p), 0x5455);  /* 'UT' extension header */
166 	assertEqualInt(i2(p + 2), 5); /* 'UT' size */
167 	assertEqualInt(p[4], 1); /* 'UT' flags */
168 	assertEqualInt(i4(p + 5), 0); /* 'UT' mtime */
169 	p += 4 + i2(p + 2);
170 
171 	/* Note: We don't expect to see zip64 extension in the central
172 	 * directory, since the writer knows the actual full size by
173 	 * the time it is ready to write the central directory and has
174 	 * no reason to insert it then.  Info-Zip seems to do the same
175 	 * thing. */
176 
177 	/* Just in case: Report any extra extensions. */
178 	while (p < extension_end) {
179 		failure("Unexpected extension 0x%04X", i2(p));
180 		assert(0);
181 		p += 4 + i2(p + 2);
182 	}
183 
184 	/* Should have run exactly to end of extra data. */
185 	assert(p == extension_end);
186 
187 	assert(p == eocd);
188 	assert(p == eocd_record);
189 
190 	/* Verify local header of file entry. */
191 	p = local_header = buff;
192 	assertEqualMem(p, "PK\003\004", 4); /* Signature */
193 	assertEqualInt(i2(p + 4), zip_version); /* Version needed to extract */
194 	assertEqualInt(i2(p + 6), 8); /* Flags */
195 	assertEqualInt(i2(p + 8), zip_compression); /* Compression method */
196 	assertEqualInt(i2(p + 10), 0); /* File time */
197 	assertEqualInt(i2(p + 12), 33); /* File date */
198 	assertEqualInt(i4(p + 14), 0); /* CRC-32 */
199 	assertEqualInt(i4(p + 18), 0); /* Compressed size */
200 	assertEqualInt(i4(p + 22), 0); /* Uncompressed size */
201 	assertEqualInt(i2(p + 26), strlen(file_name)); /* Pathname length */
202 	assertEqualInt(i2(p + 28), 24); /* Extra field length */
203 	assertEqualMem(p + 30, file_name, strlen(file_name)); /* Pathname */
204 	p = extension_start = local_header + 30 + strlen(file_name);
205 	extension_end = extension_start + i2(local_header + 28);
206 
207 	assertEqualInt(i2(p), 0x7875);  /* 'ux' extension header */
208 	assertEqualInt(i2(p + 2), 11); /* 'ux' size */
209 	assertEqualInt(p[4], 1); /* 'ux' version */
210 	assertEqualInt(p[5], 4); /* 'ux' uid size */
211 	assertEqualInt(i4(p + 6), file_uid); /* 'Ux' UID */
212 	assertEqualInt(p[10], 4); /* 'ux' gid size */
213 	assertEqualInt(i4(p + 11), file_gid); /* 'Ux' GID */
214 	p += 4 + i2(p + 2);
215 
216 	assertEqualInt(i2(p), 0x5455);  /* 'UT' extension header */
217 	assertEqualInt(i2(p + 2), 5); /* 'UT' size */
218 	assertEqualInt(p[4], 1); /* 'UT' flags */
219 	assertEqualInt(i4(p + 5), 0); /* 'UT' mtime */
220 	p += 4 + i2(p + 2);
221 
222 	/* Just in case: Report any extra extensions. */
223 	while (p < extension_end) {
224 		failure("Unexpected extension 0x%04X", i2(p));
225 		assert(0);
226 		p += 4 + i2(p + 2);
227 	}
228 
229 	/* Should have run exactly to end of extra data. */
230 	assert(p == extension_end);
231 	data_start = p;
232 
233 	/* Data descriptor should follow compressed data. */
234 	while (p < central_header && memcmp(p, "PK\007\010", 4) != 0)
235 		++p;
236 	data_end = p;
237 	assertEqualInt(data_end - data_start, compressed_size);
238 	assertEqualMem(p, "PK\007\010", 4);
239 	assertEqualInt(i4(p + 4), crc); /* CRC-32 */
240 	assertEqualInt(i4(p + 8), compressed_size); /* compressed size */
241 	assertEqualInt(i4(p + 12), sizeof(file_data)); /* uncompressed size */
242 
243 	/* Central directory should immediately follow the data descriptor. */
244 	assert(p + 16 == central_header);
245 
246 	free(buff);
247 }
248