Skip to content

Releases: RealBurst/arcana

Arcana v1.0.6

Choose a tag to compare

@RealBurst RealBurst released this 05 Oct 14:18

Arcana v1.0.6

This release fixes the problems found while writing the format documentation (doc/formats), with a regression test for each fix.

Security and integrity

  • ZIP: the WinZip AES authentication code is now checked, so modified encrypted data is reported instead of extracted
  • 7z: AES key derivation limited to 2^24 rounds (as 7-Zip): a crafted archive can no longer make Arcana hash for hours
  • ISO 9660: crafted images (directory loops, huge lengths, bad Rock Ridge entries) give a clean error instead of a crash
  • .Z and SZDD: extraction can no longer overwrite the archive itself

Fixes

  • ZIP: passwords with accented characters now work with 7-Zip and other tools (note: AES archives created by earlier Arcana versions with such a password must be opened with the old version)
  • ZIP: creation with a password no longer loads files in memory and supports ZIP64 (files over 4 GB, more than 65535 entries)
  • RAR: a wrong password on an archive with encrypted headers is reported; listing works with encrypted headers; RAR 4 empty files are extracted
  • Zstandard: .tar.zst files made with "tar --zstd" or through a pipe are read; several frames and skippable frames; detection by content
  • Unix compress (.Z): files with CLEAR codes (compress -b 10 to -b 16) decode correctly
  • CAB: cabinets created by Arcana are accepted by 7-Zip
  • WIM: rare LZX uncompressed blocks decoded correctly
  • Self-extracting executables: a ZIP stored inside the image is found
  • ISO 9660: deep Rock Ridge directories (rr_moved) are put back in place

Tests and documentation

  • 36 new regression samples (137 in total with the corpus), generators in test/tools/samples
  • Technical documentation of every format in doc/formats, with the list of remaining known issues

Arcana v1.0.5

Choose a tag to compare

@RealBurst RealBurst released this 05 Oct 10:29

Arcana v1.0.5

New

  • JexePack plugin: support JexePack 7 and 8 executables (in addition to JexePack 5)
  • Extract Windows Installer packages stored in executable resources: the files get their real names and folders, and the other resources (DLLs...) go to [resources]/ (e.g. the Java online installer)
  • An .msi now also extracts the files of an external cabinet placed next to it
  • Windows Explorer context menu: "Arcana Unpack ...", "Arcana List ..." and "Arcana Info ..." (windows/ folder, no administrator rights needed)
  • Regression test suite: about 100 samples of every supported format, damaged files included, plus your own corpus of real files (build.bat test)

Fixes

  • UPX plugin: support PE files whose import names were moved by UPX
  • RPM: compressed payloads (gzip, bzip2, xz, zstd) are now extracted (wrong header tag was read)
  • "arcana l" shows a message when there is nothing to list

Arcana v1.0.4

Choose a tag to compare

@RealBurst RealBurst released this 04 Oct 14:59

Arcana 1.0.4

New formats (core)

  • Windows Installer (.msi): extracted as the tree of installed files, with their real names and folders (File, Component and Directory tables, embedded cabinets); the other streams go to [streams]/.
  • OLE compound files: .msp, Office 97-2003 documents (.doc, .xls, .ppt), Outlook .msg (storages and streams).
  • Compiled HTML Help (.chm): pages, images and scripts (LZX).
  • ARJ: methods 0 to 4.
  • MS COMPRESS.EXE files (SZDD): the .ex_, .dl_... files of old setup disks, with their original name restored.
  • WIM / ESD with LZMS: the install.esd of Windows ISO images and other solid .esd files.

Fixes and improvements

  • LZX decoder rewritten, shared by CAB and CHM: cabinets compressed with LZX:21 (and IExpress self-extracting archives using them) failed before.
  • WIM: the SHA-1 of every extracted file is now checked (damaged data used to go unnoticed); files are extracted in data order, much faster on solid archives.
  • When an installer is not supported by the core, the error message names the plugin that extracts it.
  • Plugins can read up to 4 MiB of a file to recognize it (was 1 MiB).

New plugins

  • arcana-plugin-innosetup: Inno Setup installers, setup data 5.4.2 to 7.x; LZMA, LZMA2, zlib, bzip2; solid or not; setup-1.bin data files; encrypted installers with the password (-p).
  • arcana-plugin-installshield: InstallShield cabinet sets (data1.hdr, data1.cab...) and the files embedded in InstallShield setup.exe.
  • arcana-plugin-jexepack: Java programs packed into an .exe by JexePack (Duckware). Extracts the jar files and DLLs to check what the program really contains.

Plugins: copy the JAR into ~/.arcana/plugins/ (or plugins/ next to Arcana). The new plugins require Arcana 1.0.4.

Arcana v1.0.3

Choose a tag to compare

@RealBurst RealBurst released this 03 Oct 13:28

New formats (extraction)

  • UDF disc images: DVD, Blu-ray, Windows install media, UDF 1.02 to 2.60 (physical, sparable, virtual and metadata partitions). On UDF + ISO 9660 discs, the UDF side is read.
  • WIM (Windows Imaging Format): XPRESS, LZX, uncompressed and solid resources, multi-image files. LZMS (most .esd files) and split .swm files are not supported.
  • SquashFS 4.0: gzip, LZMA, LZO, XZ, LZ4 and Zstandard.

New in existing formats

  • ZIP: PPMd compression (method 98).
  • 7z: ARM64, RISC-V, Swap2 and Swap4 filters; split archives (.7z.001, .7z.002...) are read as one file.
  • RAR 4: RGB, AUDIO and ITANIUM filters (WinRAR uses AUDIO and RGB for WAV and BMP files).

Fixes

  • XAR: compressed files were written without being decompressed. Encodings are now read correctly (gzip, bzip2, LZMA, XZ), and checksums and hard links are handled.
  • RAR 4: executables larger than about 190 KB compressed with the x86 filter could be extracted corrupted.

Plugins

  • New NSIS installer plugin (NSIS 2 and 3, zlib, bzip2, LZMA, solid or not).
  • UPX plugin 0.3.2: PE files packed by UPX 3.x, Linux x86-64 PIE executables.

Arcana v1.0.2

Choose a tag to compare

@RealBurst RealBurst released this 02 Oct 14:38

Add NSIS installer plugin (NSIS 2/3, zlib/bzip2/LZMA, solid)

Arcana v1.0.1

Choose a tag to compare

@RealBurst RealBurst released this 02 Oct 09:27

UPX plugin: fix ELF unpacking (filtered code blocks)

UPX applies the x86-64 call/jump filter 0x49 to the code segment of
ELF executables. Filtered blocks were rejected, so the extractor
skipped to a wrong offset and failed. They are now unfiltered (after
reading, before the decoded Adler-32 check, which UPX computes on the
original data for ELF). A reassembled ELF is now named ".unpacked".

Arcana v1.0.0

Choose a tag to compare

@RealBurst RealBurst released this 02 Oct 08:14

First public release of Arcana, a pure-Java archive library and command-line tool.
No native libraries, no JNI, no external dependencies. Runs on Java 8 or later.

Highlights

  • Extract ZIP, 7z, RAR 4 and 5, TAR (gz, bz2, xz, lz4, zst, br), GZIP, BZIP2, XZ, LZMA, LZ4, Zstandard, Snappy, Brotli, Unix compress, LHA, CAB, CPIO, ISO 9660, AR / DEB, RPM, XAR and self-extracting archives
  • Encrypted archives: ZIP (ZipCrypto, WinZip AES), 7z (AES-256), RAR 4 (AES-128) and RAR 5 (AES-256), including encrypted headers and multi-volume RAR
  • Compress to ZIP, 7z, TAR, TAR.GZ, TAR.BZ2, TAR.XZ, TAR.LZ4, GZIP, BZIP2, XZ, LHA and CAB, with AES-256 encryption for ZIP and 7z
  • Archive-based files such as Office documents, OpenDocument, EPUB, JAR / APK or Dia diagrams are recognized by their content and extracted directly
  • Identify any file, recover damaged archives, split files made of several files glued together
  • Plugins: add new formats without changing Arcana

Downloads

File Description
Arcana-v1.0.0.jar Command-line tool and library
arcana-plugin-pak.jar Optional plugin: Quake PAK archives (Apache-2.0)
arcana-plugin-upx.jar Optional plugin: unpacks UPX-compressed executables (GPL-3.0-or-later)
SHA256SUMS.txt SHA-256 checksums of the JAR files

Quick start

java -jar Arcana-v1.0.0.jar x archive.rar -o ./out
java -jar Arcana-v1.0.0.jar c ./mydir backup.7z -p secret
java -jar Arcana-v1.0.0.jar help

To install a plugin, copy its JAR into a plugins folder next to Arcana-v1.0.0.jar, then check with java -jar Arcana-v1.0.0.jar plugins.

See the README for the full documentation and the Java API.

Feedback

This is a first release and it may still contain bugs. Please open an issue with the command, the error message and, if possible, the file.

Like Arcana? Spread the word and give the project a star!