Coverage Report

Created: 2026-09-13 07:02

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/xz/src/liblzma/common/alone_decoder.c
Line
Count
Source
1
// SPDX-License-Identifier: 0BSD
2
3
///////////////////////////////////////////////////////////////////////////////
4
//
5
/// \file       alone_decoder.c
6
/// \brief      Decoder for LZMA_Alone files
7
//
8
//  Author:     Lasse Collin
9
//
10
///////////////////////////////////////////////////////////////////////////////
11
12
#include "alone_decoder.h"
13
#include "lzma_decoder.h"
14
#include "lz_decoder.h"
15
16
17
typedef struct {
18
  lzma_next_coder next;
19
20
  enum {
21
    SEQ_PROPERTIES,
22
    SEQ_DICTIONARY_SIZE,
23
    SEQ_UNCOMPRESSED_SIZE,
24
    SEQ_CODER_INIT,
25
    SEQ_CODE,
26
  } sequence;
27
28
  /// If true, reject files that are unlikely to be .lzma files.
29
  /// If false, more non-.lzma files get accepted and will give
30
  /// LZMA_DATA_ERROR either immediately or after a few output bytes.
31
  bool picky;
32
33
  /// Position in the header fields
34
  size_t pos;
35
36
  /// Uncompressed size decoded from the header
37
  lzma_vli uncompressed_size;
38
39
  /// Memory usage limit
40
  uint64_t memlimit;
41
42
  /// Amount of memory actually needed (only an estimate)
43
  uint64_t memusage;
44
45
  /// Options decoded from the header needed to initialize
46
  /// the LZMA decoder
47
  lzma_options_lzma options;
48
} lzma_alone_coder;
49
50
51
static lzma_ret
52
alone_decode(void *coder_ptr, const lzma_allocator *allocator,
53
    const uint8_t *restrict in, size_t *restrict in_pos,
54
    size_t in_size, uint8_t *restrict out,
55
    size_t *restrict out_pos, size_t out_size,
56
    lzma_action action)
57
83.6k
{
58
83.6k
  lzma_alone_coder *coder = coder_ptr;
59
60
116k
  while (*out_pos < out_size
61
116k
      && (coder->sequence == SEQ_CODE || *in_pos < in_size))
62
116k
  switch (coder->sequence) {
63
2.69k
  case SEQ_PROPERTIES:
64
2.69k
    if (lzma_lzma_lclppb_decode(&coder->options, in[*in_pos]))
65
33
      return LZMA_FORMAT_ERROR;
66
67
2.66k
    coder->sequence = SEQ_DICTIONARY_SIZE;
68
2.66k
    ++*in_pos;
69
2.66k
    break;
70
71
10.5k
  case SEQ_DICTIONARY_SIZE:
72
10.5k
    coder->options.dict_size
73
10.5k
        |= (size_t)(in[*in_pos]) << (coder->pos * 8);
74
75
10.5k
    if (++coder->pos == 4) {
76
2.64k
      if (coder->picky && coder->options.dict_size
77
2.64k
          != UINT32_MAX) {
78
        // A hack to ditch tons of false positives:
79
        // We allow only dictionary sizes that are
80
        // 2^n or 2^n + 2^(n-1). LZMA_Alone created
81
        // only files with 2^n, but accepts any
82
        // dictionary size.
83
2.62k
        uint32_t d = coder->options.dict_size - 1;
84
2.62k
        d |= d >> 2;
85
2.62k
        d |= d >> 3;
86
2.62k
        d |= d >> 4;
87
2.62k
        d |= d >> 8;
88
2.62k
        d |= d >> 16;
89
2.62k
        ++d;
90
91
2.62k
        if (d != coder->options.dict_size)
92
114
          return LZMA_FORMAT_ERROR;
93
2.62k
      }
94
95
2.53k
      coder->pos = 0;
96
2.53k
      coder->sequence = SEQ_UNCOMPRESSED_SIZE;
97
2.53k
    }
98
99
10.4k
    ++*in_pos;
100
10.4k
    break;
101
102
20.2k
  case SEQ_UNCOMPRESSED_SIZE:
103
20.2k
    coder->uncompressed_size
104
20.2k
        |= (lzma_vli)(in[*in_pos]) << (coder->pos * 8);
105
20.2k
    ++*in_pos;
106
20.2k
    if (++coder->pos < 8)
107
17.6k
      break;
108
109
    // Another hack to ditch false positives: Assume that
110
    // if the uncompressed size is known, it must be less
111
    // than 256 GiB.
112
    //
113
    // FIXME? Without picky we allow > LZMA_VLI_MAX which doesn't
114
    // really matter in this specific situation (> LZMA_VLI_MAX is
115
    // safe in the LZMA decoder) but it's somewhat weird still.
116
2.52k
    if (coder->picky
117
2.52k
        && coder->uncompressed_size != LZMA_VLI_UNKNOWN
118
2.39k
        && coder->uncompressed_size
119
2.39k
          >= (LZMA_VLI_C(1) << 38))
120
175
      return LZMA_FORMAT_ERROR;
121
122
    // Use LZMA_FILTER_LZMA1EXT features to specify the
123
    // uncompressed size and that the end marker is allowed
124
    // even when the uncompressed size is known. Both .lzma
125
    // header and LZMA1EXT use UINT64_MAX indicate that size
126
    // is unknown.
127
2.34k
    coder->options.ext_flags = LZMA_LZMA1EXT_ALLOW_EOPM;
128
2.34k
    lzma_set_ext_size(coder->options, coder->uncompressed_size);
129
130
    // Calculate the memory usage so that it is ready
131
    // for SEQ_CODER_INIT. We know that lc/lp/pb are valid
132
    // so we can use the _nocheck variant.
133
2.34k
    coder->memusage
134
2.34k
      = lzma_lzma_decoder_memusage_nocheck(&coder->options)
135
2.34k
        + LZMA_MEMUSAGE_BASE;
136
137
2.34k
    coder->pos = 0;
138
2.34k
    coder->sequence = SEQ_CODER_INIT;
139
2.34k
    FALLTHROUGH;
140
141
2.34k
  case SEQ_CODER_INIT: {
142
2.34k
    if (coder->memusage > coder->memlimit)
143
0
      return LZMA_MEMLIMIT_ERROR;
144
145
2.34k
    lzma_filter_info filters[2] = {
146
2.34k
      {
147
2.34k
        .id = LZMA_FILTER_LZMA1EXT,
148
2.34k
        .init = &lzma_lzma_decoder_init,
149
2.34k
        .options = &coder->options,
150
2.34k
      }, {
151
2.34k
        .init = NULL,
152
2.34k
      }
153
2.34k
    };
154
155
2.34k
    const lzma_ret ret = lzma_next_filter_init(&coder->next,
156
2.34k
        allocator, filters);
157
2.34k
    if (ret != LZMA_OK) {
158
11
      lzma_next_end(&coder->next, allocator);
159
11
      return ret;
160
11
    }
161
162
2.33k
    coder->sequence = SEQ_CODE;
163
2.33k
    break;
164
2.34k
  }
165
166
82.9k
  case SEQ_CODE: {
167
82.9k
    return coder->next.code(coder->next.coder,
168
82.9k
        allocator, in, in_pos, in_size,
169
82.9k
        out, out_pos, out_size, action);
170
2.34k
  }
171
172
0
  default:
173
0
    return LZMA_PROG_ERROR;
174
116k
  }
175
176
339
  return LZMA_OK;
177
83.6k
}
178
179
180
static void
181
alone_decoder_end(void *coder_ptr, const lzma_allocator *allocator)
182
2.69k
{
183
2.69k
  lzma_alone_coder *coder = coder_ptr;
184
2.69k
  lzma_next_end(&coder->next, allocator);
185
2.69k
  lzma_free(coder, allocator);
186
2.69k
  return;
187
2.69k
}
188
189
190
static lzma_ret
191
alone_decoder_memconfig(void *coder_ptr, uint64_t *memusage,
192
    uint64_t *old_memlimit, uint64_t new_memlimit)
193
0
{
194
0
  lzma_alone_coder *coder = coder_ptr;
195
196
0
  *memusage = coder->memusage;
197
0
  *old_memlimit = coder->memlimit;
198
199
0
  if (new_memlimit != 0) {
200
0
    if (new_memlimit < coder->memusage)
201
0
      return LZMA_MEMLIMIT_ERROR;
202
203
0
    coder->memlimit = new_memlimit;
204
0
  }
205
206
0
  return LZMA_OK;
207
0
}
208
209
210
extern lzma_ret
211
lzma_alone_decoder_init(lzma_next_coder *next, const lzma_allocator *allocator,
212
    uint64_t memlimit, bool picky)
213
2.69k
{
214
2.69k
  lzma_next_coder_init(&lzma_alone_decoder_init, next, allocator);
215
216
2.69k
  lzma_alone_coder *coder = next->coder;
217
218
2.69k
  if (coder == NULL) {
219
2.69k
    coder = lzma_alloc(sizeof(lzma_alone_coder), allocator);
220
2.69k
    if (coder == NULL)
221
0
      return LZMA_MEM_ERROR;
222
223
2.69k
    next->coder = coder;
224
2.69k
    next->code = &alone_decode;
225
2.69k
    next->end = &alone_decoder_end;
226
2.69k
    next->memconfig = &alone_decoder_memconfig;
227
2.69k
    coder->next = LZMA_NEXT_CODER_INIT;
228
2.69k
  }
229
230
2.69k
  coder->sequence = SEQ_PROPERTIES;
231
2.69k
  coder->picky = picky;
232
2.69k
  coder->pos = 0;
233
2.69k
  coder->options.dict_size = 0;
234
2.69k
  coder->options.preset_dict = NULL;
235
2.69k
  coder->options.preset_dict_size = 0;
236
2.69k
  coder->uncompressed_size = 0;
237
2.69k
  coder->memlimit = my_max(1, memlimit);
238
2.69k
  coder->memusage = LZMA_MEMUSAGE_BASE;
239
240
2.69k
  return LZMA_OK;
241
2.69k
}
242
243
244
extern LZMA_API(lzma_ret)
245
lzma_alone_decoder(lzma_stream *strm, uint64_t memlimit)
246
0
{
247
0
  lzma_next_strm_init(lzma_alone_decoder_init, strm, memlimit, false);
248
249
0
  strm->internal->supported_actions[LZMA_RUN] = true;
250
0
  strm->internal->supported_actions[LZMA_FINISH] = true;
251
252
0
  return LZMA_OK;
253
0
}