Add Windows CE and CAB extraction support - #48
Conversation
|
@nmatt0 updated to handle compressed lzx with a default configuration to only extract if it's the root file passed in or if you add the optional flag |
|
Thanks for the update, this is a big improvement and the LZX fix is spot on. What I verified locally:
One blocker before merge: CFBF extraction can be crashed by crafted input. It's a DoS rather than memory corruption, and the default nesting policy means a nested CFBF inside firmware isn't auto-extracted, but it triggers when moria is pointed at a malicious Minor: Everything else looks ready to merge once |
walk_tree recursed over the directory's sibling tree and storage children with only a cycle guard. A compound file's directory is not required to be balanced, so a crafted file can lay its entries out as one long linear left/right chain (entry count bounded only by the 262144 cap). The recursion then overflowed the call stack: moria -e segfaulted on a ~15 MB MSI built this way. Rewrite the walk with an explicit heap work stack so any depth up to the entry cap is safe. Behavior is otherwise unchanged (same paths recorded, same cycle guard). tests/cfbfbuild.build_deep_chain builds such a file (120k-entry chain whose deepest entry carries a payload) and test_cfbf.deep_directory_chain asserts extraction completes and the deepest stream round-trips byte-for-byte. The chain length is sized to exhaust a default 8 MiB stack on the old code, so the test fails if the recursion returns. Also drop an unused variable in extract_cab (-Wall).
No description provided.