Skip to content

Commit f532421

Browse files
IdanHoawesomekling
authored andcommitted
LibCompress: Make the Zlib decompressor fail gracefuly
This commit adds a verify-less try_create method to the Zlib decompressor to allow for graceful failures of parsing the Zlib headers.
1 parent a7b5a58 commit f532421

File tree

2 files changed

+33
-19
lines changed

2 files changed

+33
-19
lines changed

Userland/Libraries/LibCompress/Zlib.cpp

Lines changed: 29 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,6 @@
2424
* OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
2525
*/
2626

27-
#include <AK/Assertions.h>
2827
#include <AK/Span.h>
2928
#include <AK/Types.h>
3029
#include <AK/Vector.h>
@@ -33,26 +32,38 @@
3332

3433
namespace Compress {
3534

36-
Zlib::Zlib(ReadonlyBytes data)
35+
Optional<Zlib> Zlib::try_create(ReadonlyBytes data)
3736
{
38-
m_input_data = data;
37+
if (data.size() < 6)
38+
return {}; // header + footer size is 6
39+
40+
Zlib zlib { data };
3941

4042
u8 compression_info = data.at(0);
4143
u8 flags = data.at(1);
4244

43-
m_compression_method = compression_info & 0xF;
44-
m_compression_info = (compression_info >> 4) & 0xF;
45-
m_check_bits = flags & 0xF;
46-
m_has_dictionary = (flags >> 5) & 0x1;
47-
m_compression_level = (flags >> 6) & 0x3;
48-
m_checksum = 0;
45+
zlib.m_compression_method = compression_info & 0xF;
46+
zlib.m_compression_info = (compression_info >> 4) & 0xF;
47+
zlib.m_check_bits = flags & 0xF;
48+
zlib.m_has_dictionary = (flags >> 5) & 0x1;
49+
zlib.m_compression_level = (flags >> 6) & 0x3;
50+
51+
if (zlib.m_compression_method != 8 || zlib.m_compression_info > 7)
52+
return {}; // non-deflate compression
53+
54+
if (zlib.m_has_dictionary)
55+
return {}; // we dont support pre-defined dictionaries
4956

50-
VERIFY(m_compression_method == 8);
51-
VERIFY(m_compression_info == 7);
52-
VERIFY(!m_has_dictionary);
53-
VERIFY((compression_info * 256 + flags) % 31 == 0);
57+
if ((compression_info * 256 + flags) % 31 != 0)
58+
return {}; // error correction code doesnt match
5459

55-
m_data_bytes = data.slice(2, data.size() - 2 - 4);
60+
zlib.m_data_bytes = data.slice(2, data.size() - 2 - 4);
61+
return zlib;
62+
}
63+
64+
Zlib::Zlib(const ReadonlyBytes& data)
65+
: m_input_data(data)
66+
{
5667
}
5768

5869
Optional<ByteBuffer> Zlib::decompress()
@@ -62,8 +73,10 @@ Optional<ByteBuffer> Zlib::decompress()
6273

6374
Optional<ByteBuffer> Zlib::decompress_all(ReadonlyBytes bytes)
6475
{
65-
Zlib zlib { bytes };
66-
return zlib.decompress();
76+
auto zlib = try_create(bytes);
77+
if (!zlib.has_value())
78+
return {};
79+
return zlib->decompress();
6780
}
6881

6982
u32 Zlib::checksum()

Userland/Libraries/LibCompress/Zlib.h

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -34,21 +34,22 @@ namespace Compress {
3434

3535
class Zlib {
3636
public:
37-
Zlib(ReadonlyBytes data);
38-
3937
Optional<ByteBuffer> decompress();
4038
u32 checksum();
4139

40+
static Optional<Zlib> try_create(ReadonlyBytes data);
4241
static Optional<ByteBuffer> decompress_all(ReadonlyBytes);
4342

4443
private:
44+
Zlib(const ReadonlyBytes& data);
45+
4546
u8 m_compression_method;
4647
u8 m_compression_info;
4748
u8 m_check_bits;
4849
u8 m_has_dictionary;
4950
u8 m_compression_level;
5051

51-
u32 m_checksum;
52+
u32 m_checksum { 0 };
5253
ReadonlyBytes m_input_data;
5354
ReadonlyBytes m_data_bytes;
5455
};

0 commit comments

Comments
 (0)