Compare commits

..
2 Commits
Author SHA1 Message Date
owendswang f460178ac8 Release v0.2 2026-06-17 23:57:33 +08:00
owendswang 1ed55b499c Initial 2026-06-17 01:38:56 +08:00
404 changed files with 1366 additions and 114644 deletions

No files matched your search

-168
View File
@@ -1,168 +0,0 @@
#!/usr/bin/env bash
# ===========================================================================
# ps5-web-file-manager -- 一键在 WSL 里生成 PS5 ELF
#
# 这个脚本在 WSL (Ubuntu-22.04) 里执行,做四件事:
# 1. 把 Windows 仓库的源码 rsync 到 WSL 项目目录(增量,跳过构建缓存)
# 2. make all (PS5_PAYLOAD_SDK = /opt/ps5-payload-sdk)
# 3. 验证产物:size / sha256 / e_machine
# 4. 把 ELF 拷回 Windows 项目根
#
# 从 Windows 的 Git Bash / MinGW64 bash 里这样跑:
# wsl.exe -d Ubuntu-22.04 -- bash < \
# "/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager/.build/build-elf-wsl.sh"
#
# 注意:必须用 stdin 重定向 `bash < script`,不要 `bash -c '...'` ——
# 路径含空格时 -c 的参数会被 wsl.exe 拆断。
# ===========================================================================
set -uo pipefail
# ---------------------------------------------------------------- 配置 -----
SRC_WIN='/mnt/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager'
PROJ='/home/song/ps5-web-file-manager'
SDK='/opt/ps5-payload-sdk'
log() { printf '\033[1;36m%s\033[0m\n' "$*"; }
warn() { printf '\033[1;33m[WARN] %s\033[0m\n' "$*"; }
fail() { printf '\033[1;31m[FAIL] %s\033[0m\n' "$*"; exit 1; }
# ------------------------------------------------------------ jwasm --------
# The LZMA decoder has an asm implementation that is 26% faster than the C one
# (see docs/EXTRACTION-PERF.md). It is MASM syntax, so a MASM-compatible
# assembler is needed. Makefile only enables the optimisation when jwasm is on
# PATH, so a failure here downgrades rather than breaks the build.
JWASM_HOME="$HOME/.cache/wfm-jwasm"
JWASM_BIN="$JWASM_HOME/jwasm"
ensure_jwasm() {
if command -v jwasm >/dev/null 2>&1; then
echo " jwasm: $(command -v jwasm)"
return 0
fi
if [ -x "$JWASM_BIN" ]; then
export PATH="$JWASM_HOME:$PATH"
echo " jwasm: $JWASM_BIN (缓存)"
return 0
fi
echo " jwasm 不在,正在从源码编译(首次约 30 秒)..."
mkdir -p "$JWASM_HOME" || return 1
if [ ! -d "$JWASM_HOME/src" ]; then
git clone --depth 1 https://github.com/Baron-von-Riedesel/JWasm.git \
"$JWASM_HOME/src" >/dev/null 2>&1 || return 1
fi
make -C "$JWASM_HOME/src" -f GccUnix.mak -j4 >/dev/null 2>&1 || return 1
cp -f "$JWASM_HOME/src/build/GccUnixR/jwasm" "$JWASM_BIN" || return 1
chmod +x "$JWASM_BIN" || return 1
export PATH="$JWASM_HOME:$PATH"
echo " jwasm: $JWASM_BIN (已编译)"
}
# ------------------------------------------------------- 1/5 环境检查 -----
log "[1/5] 环境检查"
[ -d "$SRC_WIN" ] || fail "Windows 源码目录不可见: $SRC_WIN (/mnt/c 挂载了吗?)"
[ -x "$SDK/bin/prospero-clang" ] || fail "SDK 缺失: $SDK/bin/prospero-clang"
export PS5_PAYLOAD_SDK="$SDK"
# shellcheck disable=SC1091
source "$SDK/toolchain/prospero.sh" 2>/dev/null || true
export CC="$SDK/bin/prospero-clang"
export CXX="$SDK/bin/prospero-clang++"
export PKG_CONFIG="$SDK/bin/prospero-pkg-config"
"$CC" --version | head -1
"$PKG_CONFIG" --modversion libmicrohttpd 2>/dev/null \
|| fail "libmicrohttpd 未装到 sysroot —— 先跑一次完整的 build-elf.sh v4"
ensure_jwasm || warn "jwasm 不可用 —— 将退回纯 C 解码器(约慢 26%)"
echo
# ------------------------------------------------------- 2/5 同步源码 -----
log "[2/5] 同步源码 Windows -> WSL (rsync 增量)"
mkdir -p "$PROJ"
rsync -a --delete \
--exclude='/ps5-obj' --exclude='/linux-obj' \
--exclude='/web-file-mgr-*.elf' --exclude='/web-file-mgr-linux*' \
--exclude='/gen' --exclude='/.build' --exclude='/tests' \
--exclude='/docs' --exclude='/HANDOVER.md' \
--exclude='/README.md' --exclude='/CHANGELOG.md' \
--exclude='/erssongl*' \
--include='/src' --include='/assets' \
--include='/third_party' --include='/Makefile' \
--include='/gen-asset-module.py' --include='/.gitignore' \
--exclude='/*' \
"$SRC_WIN/" "$PROJ/" || fail "rsync 失败"
# rsync 的 --include 只放行目录本身,这几个顶层文件再单独 cp 一次
for f in Makefile gen-asset-module.py .gitignore; do
[ -f "$SRC_WIN/$f" ] && cp -f "$SRC_WIN/$f" "$PROJ/$f"
done
# 冒烟:今天的关键文件都在不在
for f in src/sevenz_extract.c src/zipx_common.c src/sevenz_volstream.c \
src/sevenz_chain.c Makefile gen-asset-module.py; do
[ -f "$PROJ/$f" ] || fail "同步后缺失: $PROJ/$f"
done
[ -d "$PROJ/third_party/7z" ] || fail "同步后缺失: $PROJ/third_party/7z"
# 输出文件名由 Makefile 的 VERSION_TAG 决定(web-file-mgr-<ver>.elf)。
# 从 Makefile 里读,别在脚本里硬编 —— 否则改了版本号脚本还在找旧名字。
VERSION=$(sed -n 's/^VERSION_TAG *[?:]*= *//p' "$PROJ/Makefile" | head -1)
[ -n "$VERSION" ] || fail "读不到 VERSION_TAG: $PROJ/Makefile"
BIN_NAME="web-file-mgr-${VERSION}.elf"
ELF="$PROJ/$BIN_NAME"
echo " src/ + assets/ + third_party/ + Makefile OK"
echo " 版本: $VERSION -> 输出: $BIN_NAME"
echo
# ---------------------------------------------------------- 3/5 编译 ------
log "[3/5] make all"
cd "$PROJ" || fail "cd $PROJ"
make all 2>&1 | tail -120
# make 的退出码被管道吃了,用 PIPESTATUS 取回来
if [ "${PIPESTATUS[0]}" -ne 0 ]; then
fail "make all 失败(详见上方输出)"
fi
echo
# ---------------------------------------------------------- 4/5 验证 ------
log "[4/5] 验证产物"
[ -f "$ELF" ] || fail "ELF 未生成: $ELF"
SIZE=$(stat -c%s "$ELF")
HASH=$(sha256sum "$ELF" | cut -d' ' -f1)
# ELF header: offset 18 起 2 字节 = e_machine。
# `od -tx2` 按 2 字节小端解释成一个 short 后打印其**值**,所以文件里的
# 字节序 "3e 00" 会输出成 "003e"(不是 "3e00")。别拿字节序去比对。
EM=$(od -An -tx2 -j 18 -N 2 "$ELF" | tr -d ' \n')
EM_NUM=$((16#$EM))
ls -lh "$ELF"
echo " size: $SIZE bytes (~$((SIZE / 1024)) KiB)"
echo " sha256: $HASH"
echo " e_machine = 0x$EM ($EM_NUM)"
case "$EM_NUM" in
62) echo " -> x86-64 / PS5 [OK]" ;;
183) fail "e_machine=$EM_NUM (0x$EM) 是 aarch64!PS5 是 x86-64,target 三元组错了" ;;
*) fail "e_machine=$EM_NUM (0x$EM) 非预期(期望 62 = 0x003e = x86-64)" ;;
esac
echo
# ------------------------------------------------- 5/5 拷回 Windows -------
log "[5/5] 拷回 Windows"
cp -f "$ELF" "$SRC_WIN/$BIN_NAME" || fail "拷回 Windows 失败"
ls -lh "$SRC_WIN/$BIN_NAME"
echo
printf '\033[1;32m[DONE]\033[0m %s\n' "$SRC_WIN/$BIN_NAME"
echo " $SIZE bytes / sha256 $HASH / e_machine 0x$EM"
# 顺便报告 Windows 侧现在有哪些版本化 ELF,方便挑一个拷进 U 盘
echo
echo " Windows 项目根现有的 ELF:"
ls -1 "$SRC_WIN"/web-file-mgr-*.elf 2>/dev/null | sed 's#.*/##' | sed 's/^/ /' || true
-74
View File
@@ -1,74 +0,0 @@
==========================================
PS5 Web File Manager -- ELF 构建 v4
时间: Fri Sep 4 12:45:52 CST 2026
PS5_PAYLOAD_SDK=/opt/ps5-payload-sdk
user: song uid=1000
==========================================
[0/7] 预热 sudo (会提示输 1 次密码)...
[1/7] SDK OK: /opt/ps5-payload-sdk
[2/7] LLVM bindir: /usr/lib/llvm-18/bin
[3/7] prospero-clang --version ...
Ubuntu clang version 18.1.8 (++20240731024944+3b5b5c1ec4a3-1~exp1~20240731145000.144)
[4/7] 同步源码 (Windows -> WSL, 增量) ...
已同步自 /mnt/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager
[5/7] libmicrohttpd (staging + 一次性 sudo cp)...
下载 libmicrohttpd-1.0.1.tar.gz...
tarball: /home/song/.cache/libmicrohttpd-1.0.1.tar.gz (2.2M)
configure (host=x86_64-pc-freebsd)...
make -j14...
mv -f $depbase.Tpo $depbase.Po
/bin/bash ../../libtool --tag=CC --mode=link /opt/ps5-payload-sdk/bin/prospero-clang -fno-strict-aliasing -O1 -w -o perf_replies perf_replies.o mhd_tool_get_cpu_count.o ../../src/microhttpd/libmicrohttpd.la
libtool: link: /opt/ps5-payload-sdk/bin/prospero-clang -fno-strict-aliasing -O1 -w -o perf_replies perf_replies.o mhd_tool_get_cpu_count.o ../../src/microhttpd/.libs/libmicrohttpd.a -lpthread -pthread
make[4]: Leaving directory '/tmp/tmp.1uwmf0LJPq/libmicrohttpd-1.0.1/src/tools'
make[3]: Leaving directory '/tmp/tmp.1uwmf0LJPq/libmicrohttpd-1.0.1/src/tools'
make[2]: Leaving directory '/tmp/tmp.1uwmf0LJPq/libmicrohttpd-1.0.1/src'
Making all in .
make[2]: Entering directory '/tmp/tmp.1uwmf0LJPq/libmicrohttpd-1.0.1'
make[2]: Leaving directory '/tmp/tmp.1uwmf0LJPq/libmicrohttpd-1.0.1'
make[1]: Leaving directory '/tmp/tmp.1uwmf0LJPq/libmicrohttpd-1.0.1'
make install DESTDIR=/tmp/ps5-homebrew-ext4 ...
make[2]: Nothing to be done for 'install-exec-am'.
/usr/bin/mkdir -p '/tmp/ps5-homebrew-ext4/user/homebrew/lib/pkgconfig'
/usr/bin/install -c -m 644 libmicrohttpd.pc '/tmp/ps5-homebrew-ext4/user/homebrew/lib/pkgconfig'
make[2]: Leaving directory '/tmp/tmp.1uwmf0LJPq/libmicrohttpd-1.0.1'
make[1]: Leaving directory '/tmp/tmp.1uwmf0LJPq/libmicrohttpd-1.0.1'
sudo cp stage -> SDK homebrew...
验证 prospero-pkg-config:
1.0.1
-L/opt/ps5-payload-sdk/target/user/homebrew/lib -lmicrohttpd -lpthread
[6/7] make all (增量编译, 复用第三方 obj)...
mkdir gen
python3 gen-asset-module.py --path icon-back.png assets/icon-back.png > gen/icon-back.png.c
python3 gen-asset-module.py --path icon-file.png assets/icon-file.png > gen/icon-file.png.c
python3 gen-asset-module.py --path icon-folder.png assets/icon-folder.png > gen/icon-folder.png.c
python3 gen-asset-module.py --path icon-generic.png assets/icon-generic.png > gen/icon-generic.png.c
python3 gen-asset-module.py --path icon-image.png assets/icon-image.png > gen/icon-image.png.c
python3 gen-asset-module.py --path icon-pkg.png assets/icon-pkg.png > gen/icon-pkg.png.c
python3 gen-asset-module.py --path icon-up.png assets/icon-up.png > gen/icon-up.png.c
python3 gen-asset-module.py --path index.html assets/index.html > gen/index.html.c
python3 gen-asset-module.py --path lang-en.js assets/lang-en.js > gen/lang-en.js.c
python3 gen-asset-module.py --path lang-zh.js assets/lang-zh.js > gen/lang-zh.js.c
python3 gen-asset-module.py --path main.css assets/main.css > gen/main.css.c
python3 gen-asset-module.py --path main.js assets/main.js > gen/main.js.c
python3 gen-asset-module.py --path param.json assets/param.json > gen/param.json.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/zlib/src/adler32.o third_party/zlib/src/adler32.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/zlib/src/crc32.o third_party/zlib/src/crc32.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/zlib/src/deflate.o third_party/zlib/src/deflate.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/zlib/src/inffast.o third_party/zlib/src/inffast.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/zlib/src/inflate.o third_party/zlib/src/inflate.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/zlib/src/inftrees.o third_party/zlib/src/inftrees.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/zlib/src/trees.o third_party/zlib/src/trees.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/zlib/src/zutil.o third_party/zlib/src/zutil.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/minizip-ng/src/mz_crypt.o third_party/minizip-ng/src/mz_crypt.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/minizip-ng/src/mz_os.o third_party/minizip-ng/src/mz_os.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/minizip-ng/src/mz_os_posix.o third_party/minizip-ng/src/mz_os_posix.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/minizip-ng/src/mz_strm.o third_party/minizip-ng/src/mz_strm.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/minizip-ng/src/mz_strm_mem.o third_party/minizip-ng/src/mz_strm_mem.c
/opt/ps5-payload-sdk/bin/prospero-clang -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE -c -o ps5-obj/third_party/minizip-ng/src/mz_strm_os_posix.o third_party/minizip-ng/src/mz_strm_os_posix.c
third_party/minizip-ng/src/mz_strm_os_posix.c:95:33: error: use of undeclared identifier 'O_BINARY'
95 | fd = open(path, mode_open | O_BINARY, S_IRUSR | S_IWUSR | S_IRGRP);
| ^
1 error generated.
make: *** [Makefile:78: ps5-obj/third_party/minizip-ng/src/mz_strm_os_posix.o] Error 1
[7/7] 验证产物 + 同步...
FAIL: ELF 未生成 -- 日志: /home/song/build-elf.log
-213
View File
@@ -1,213 +0,0 @@
#!/usr/bin/env bash
# PS5 Web File Manager 一键构建 (v4)
# 修复:
# (1) staging 模式装 libmicrohttpd -> make install 到 /tmp, 再 sudo cp 到 SDK
# (2) 显式 sudo -v 刷密码缓存 (v3 的 chown 静默失败了)
# (3) 增量: 保留 zlib/minizip-ng OBJ 缓存 (不每次 make clean)
# (4) libmicrohttpd tarball 缓存 ~/.cache/, 失败可重试不重下
# (5) 同步源用 rsync 增量
# (6) 失败时把 log 同步到 Windows .build/build-elf.log
#
# 跑法: bash /home/song/build-elf.sh
set -uo pipefail
export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdk
SRC_WIN="/mnt/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager"
PROJ="/home/song/ps5-web-file-manager"
LOG="/home/song/build-elf.log"
STAGE="/tmp/ps5-homebrew-ext4"
CACHE="${HOME}/.cache/libmicrohttpd-1.0.1.tar.gz"
mkdir -p "$(dirname "$LOG")" "$STAGE" "$(dirname "$CACHE")"
: >"$LOG"
exec > >(tee -a "$LOG") 2>&1
echo "=========================================="
echo "PS5 Web File Manager -- ELF 构建 v4"
echo "时间: $(date)"
echo "PS5_PAYLOAD_SDK=$PS5_PAYLOAD_SDK"
echo "user: $(whoami) uid=$(id -u)"
echo "=========================================="
# 0. sudo 密码缓存 (脚本会跑 sudo 几次, 在开头集中要求密码)
echo "[0/7] 预热 sudo (会提示输 1 次密码)..."
sudo -v 2>&1 || { echo "FAIL: sudo 不可用"; exit 99; }
# 1. SDK 验证
if [ ! -x "$PS5_PAYLOAD_SDK/bin/prospero-clang" ]; then
if [ -f /home/song/ps5-payload-sdk.zip ]; then
echo "[1/7] 展开 SDK zip 到 $PS5_PAYLOAD_SDK ..."
sudo mkdir -p "$PS5_PAYLOAD_SDK"
sudo unzip -q -o /home/song/ps5-payload-sdk.zip -d /tmp/sdk-stage
sudo cp -r /tmp/sdk-stage/. "$PS5_PAYLOAD_SDK/"
sudo chmod -R a+rx "$PS5_PAYLOAD_SDK"
else
echo "FAIL: 未发现 /home/song/ps5-payload-sdk.zip 也无 $PS5_PAYLOAD_SDK/bin/prospero-clang"
exit 1
fi
fi
echo "[1/7] SDK OK: $PS5_PAYLOAD_SDK"
# 2. LLVM 工具链
if ! command -v llvm-config-18 >/dev/null 2>&1; then
echo "[2/7] 装 LLVM 18 (apt.llvm.org) ..."
if [ ! -x /tmp/llvm.sh ]; then
wget -q https://apt.llvm.org/llvm.sh -O /tmp/llvm.sh
chmod +x /tmp/llvm.sh
fi
sudo /tmp/llvm.sh 18 all >/dev/null 2>&1 || true
fi
if ! command -v pkg-config >/dev/null 2>&1; then
echo "[2/7] 装 pkg-config ..."
sudo apt-get install -y pkg-config rsync
fi
LLVM_BINDIR="$(llvm-config-18 --bindir 2>/dev/null || llvm-config --bindir)"
echo "[2/7] LLVM bindir: $LLVM_BINDIR"
# 3. 工具链验证
echo "[3/7] prospero-clang --version ..."
"$PS5_PAYLOAD_SDK/bin/prospero-clang" --version | head -1
# 4. 同步源码 (rsync 增量)
echo "[4/7] 同步源码 (Windows -> WSL, 增量) ..."
mkdir -p "$PROJ"
if [ -d "$SRC_WIN/src" ]; then
rsync -a --delete \
--exclude='ps5-obj' --exclude='linux-obj' \
--exclude='web-file-mgr.elf' --exclude='web-file-mgr-linux' \
--exclude='.build/stub' --exclude='.build/obj' \
--exclude='.build/probe*' --exclude='.build/probe-work' \
--exclude='.build/host-test' --exclude='.build/tp' \
--exclude='.build/*.exe' --exclude='.build/*.txt' \
--exclude='gen' \
"$SRC_WIN/" "$PROJ/"
echo " 已同步自 $SRC_WIN"
else
echo " (Windows 端不可见 -- /mnt/c 是否挂载?)"
fi
# 5. 装 libmicrohttpd (staging 模式: make install 到 /tmp, 再 sudo cp 过去)
echo "[5/7] libmicrohttpd (staging + 一次性 sudo cp)..."
if "$PS5_PAYLOAD_SDK/bin/prospero-pkg-config" --modversion libmicrohttpd >/dev/null 2>&1; then
echo " 已装: $($PS5_PAYLOAD_SDK/bin/prospero-pkg-config --modversion libmicrohttpd) -- 跳过"
else
# 5a) 下载 tarball (缓存复用)
if [ ! -f "$CACHE" ] || [ ! -s "$CACHE" ]; then
echo " 下载 libmicrohttpd-1.0.1.tar.gz..."
if command -v wget >/dev/null; then
wget -q https://ftp.gnu.org/gnu/libmicrohttpd/libmicrohttpd-1.0.1.tar.gz -O "$CACHE"
else
curl -fsSL https://ftp.gnu.org/gnu/libmicrohttpd/libmicrohttpd-1.0.1.tar.gz -o "$CACHE"
fi
fi
[ -s "$CACHE" ] || { echo "FAIL: 下载失败: $CACHE"; exit 2; }
echo " tarball: $CACHE ($(du -h "$CACHE" | cut -f1))"
# 5b) 解压 + configure + make (普通 user 跑, 输出到临时目录)
TMPSRC=$(mktemp -d)
trap 'rm -rf -- "$TMPSRC"' EXIT
tar xf "$CACHE" -C "$TMPSRC"
cd "$TMPSRC/libmicrohttpd-1.0.1"
source "${PS5_PAYLOAD_SDK}/toolchain/prospero.sh"
export CFLAGS="${CFLAGS:-} -O1 -w"
echo " configure (host=x86_64-pc-freebsd)..."
./configure --prefix="/user/homebrew" \
--host=x86_64-pc-freebsd \
--enable-static --disable-shared \
--disable-doc --disable-curl --disable-examples \
--disable-https --disable-openssl \
>/dev/null 2>&1
echo " make -j$(nproc)..."
make -j"$(nproc)" 2>&1 | tail -10
# 5c) install 到 STAGE (普通 user 写到 /tmp)
rm -rf "$STAGE"
mkdir -p "$STAGE"
echo " make install DESTDIR=$STAGE ..."
make install DESTDIR="$STAGE" 2>&1 | tail -5
# 5d) 验证 stage 里有产物
if [ ! -f "$STAGE/user/homebrew/include/microhttpd.h" ]; then
echo "FAIL: stage 中无 microhttpd.h -- stage 内容:"
find "$STAGE" -maxdepth 4 -type f | head -10
exit 2
fi
# 5e) 一次性 sudo 拷到 SDK
echo " sudo cp stage -> SDK homebrew..."
sudo mkdir -p "$PS5_PAYLOAD_SDK/target/user/homebrew"
sudo cp -r "$STAGE/user/homebrew/." "$PS5_PAYLOAD_SDK/target/user/homebrew/"
echo " 验证 prospero-pkg-config:"
"$PS5_PAYLOAD_SDK/bin/prospero-pkg-config" --modversion libmicrohttpd
"$PS5_PAYLOAD_SDK/bin/prospero-pkg-config" --libs libmicrohttpd
fi
# 6. 编译 (不 make clean, 复用 zlib/minizip-ng OBJ 缓存)
echo "[6/7] make all (增量编译, 复用第三方 obj)..."
cd "$PROJ"
export PS5_PAYLOAD_SDK="/opt/ps5-payload-sdk"
# 仅当二进制缺失或源码变更才全量重编
# 重要: 必须包含 assets/* 和 gen-asset-module.py —— 它们经 gen-asset-module.py
# 生成 gen/*.c 进而影响 ELF, 不在列表里就会跳过 make 产生伪"无变更"(v1.8.3
# 被这个 bug 坑过, ELF sha256 没变)。
if [ -f web-file-mgr.elf ]; then
echo " 已存在 web-file-mgr.elf, 检查源码变更..."
NEEDS_REBUILD=""
for src in src/*.c Makefile assets/* gen-asset-module.py \
third_party/minizip-ng/include/*.h third_party/zlib/include/*.h; do
[ -e "$src" ] || continue
if [ "$src" -nt web-file-mgr.elf ]; then
NEEDS_REBUILD="$src"
break
fi
done
if [ -z "$NEEDS_REBUILD" ]; then
echo " 无源码变更 -- 跳过 make"
else
echo " 源码变更: $NEEDS_REBUILD"
if ! make all 2>&1 | tail -60; then
echo "FAIL: make all 失败(见上)。注意: 旧 ELF 仍留在原地, 但不算新产物"
exit 6
fi
fi
else
if ! make all 2>&1 | tail -60; then
echo "FAIL: make all 失败(见上)"
exit 6
fi
fi
# 7. 验证 + 同步回 Windows
echo "[7/7] 验证产物 + 同步..."
ELF="$PROJ/web-file-mgr.elf"
if [ ! -f "$ELF" ]; then
echo "FAIL: ELF 未生成 -- 日志: $LOG"
# 把日志同步到 Windows .build/ 方便排查
cp -f "$LOG" "$SRC_WIN/.build/build-elf.log" 2>/dev/null && \
echo " 日志已同步: $SRC_WIN/.build/build-elf.log"
exit 3
fi
SIZE=$(stat -c%s "$ELF")
HASH=$(sha256sum "$ELF" | cut -d' ' -f1)
echo "OK: $ELF"
echo " size: $SIZE bytes (~$((SIZE/1024)) KiB)"
echo " sha256: $HASH"
echo " header bytes (期望 ELF64 magic 7f454c46 + class 2 + little-endian 1 + e_machine 0x003e=x86-64):"
head -c 20 "$ELF" | xxd | head -2
echo ""
# 用 od 直接读 offset 18 起的 1 个 16-bit 小端 word = e_machine
EM_RAW=$(od -An -tx2 -j 18 -N 2 "$ELF" | tr -d ' \n') # e.g. "3e00"
EM_NUM=$((16#${EM_RAW})) # decimal
echo "e_machine = 0x$EM_RAW ($EM_NUM)"
case "$EM_NUM" in
62) echo " -> x86-64 (PS5 真机 target: x86_64-sie-ps5)" ;;
183) echo " -> aarch64 (注意: PS5 实际是 x86-64, 此结果可疑)" ;;
*) echo " -> 未知架构 (期望 62=0x3e, 当前 e_machine=$EM_NUM)" ;;
esac
# 同步 ELF 回项目根
mkdir -p "$SRC_WIN" 2>/dev/null
cp -f "$ELF" "$SRC_WIN/web-file-mgr.elf" 2>&1 && \
echo "" && echo "[bonus] 已同步回: $SRC_WIN/web-file-mgr.elf" && \
ls -lh "$SRC_WIN/web-file-mgr.elf"
-50
View File
@@ -1,50 +0,0 @@
#!/usr/bin/env bash
# ===========================================================================
# ps5-web-file-manager -- Windows 端一键构建入口
#
# 在 Windows 的 Git Bash / MinGW64 bash 里这样跑(注意用 /usr/bin/bash):
# /usr/bin/bash .build/build-win.sh
#
# 它只做一件事:把 WSL 脚本喂给 wsl.exe 执行,然后透传退出码。
# 真正的 sync / make / verify / 拷回都在 .build/build-elf-wsl.sh 里。
#
# 注意:
# * 用 `bash < script` 走 stdin,不要用 `bash -c '...'` ——
# 路径含空格时 -c 的参数会被 wsl.exe 拆断。
# * 别写裸 `bash .build/build-win.sh`,那个 bash 可能解析到
# C:\Windows\System32\bash.exe(WSL 启动器),脚本会跑进 Linux 环境。
# ===========================================================================
set -uo pipefail
REPO='/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager'
WSL_DISTRO='Ubuntu-22.04'
WSL_DIR='/home/song/ps5-web-file-manager/.build'
HOST_SCRIPT="$REPO/.build/build-elf-wsl.sh"
[ -f "$HOST_SCRIPT" ] || { echo "[FAIL] 找不到 $HOST_SCRIPT"; exit 1; }
# 每次都把最新的 WSL 脚本推进去(.build/ 被 rsync 排除,WSL 侧不会自己更新;
# 只做一次会导致改了脚本还在跑旧版 —— 这个坑踩过)
wsl.exe -d "$WSL_DISTRO" -- mkdir -p "$WSL_DIR" || exit 1
wsl.exe -d "$WSL_DISTRO" -- cp \
'/mnt/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager/.build/build-elf-wsl.sh' \
"$WSL_DIR/build-elf-wsl.sh" || {
echo "[FAIL] 无法写入 WSL 文件系统"
exit 1
}
echo "[run] wsl.exe -d $WSL_DISTRO -- bash < build-elf-wsl.sh"
echo "=================================================================="
wsl.exe -d "$WSL_DISTRO" -- bash < "$HOST_SCRIPT"
rc=$?
echo "=================================================================="
if [ "$rc" -eq 0 ]; then
# 输出文件带版本号(web-file-mgr-<VERSION_TAG>.elf),列出实际产物
echo "[OK] 构建完成,产物:"
ls -1 "$REPO"/web-file-mgr-*.elf 2>/dev/null | sed 's#^# #'
else
echo "[FAIL] 构建失败 (exit=$rc)"
fi
exit "$rc"
-51
View File
@@ -1,51 +0,0 @@
"""Verify our large-file mode identifiers made it into the ELF.
gen-asset-module.py gzips JS assets, so plain `strings` won't find them.
This script finds all gzip streams in the ELF, decompresses them, and greps
for the new identifiers."""
import re, sys, zlib
f = sys.argv[1]
data = open(f, "rb").read()
# Gzip streams start with 0x1f 0x8b. Walk through the file looking for them.
keys = [
b"extractLargeAsk",
b"extractLargeActive",
b"promptLargeMode",
b"shouldPromptLargeMode",
b"LARGE_FILE_THRESHOLD_BYTES",
b"/api/extract",
b"large",
]
seen = {}
i = 0
while i < len(data) - 10:
if data[i] == 0x1f and data[i + 1] == 0x8b:
# Try to decompress starting here, capped at 2 MiB.
end_cap = min(len(data), i + 2 * 1024 * 1024)
try:
dec = zlib.decompressobj(zlib.MAX_WBITS | 16)
chunk = dec.decompress(data[i:end_cap], 2 * 1024 * 1024)
if not dec.eof:
i += 1
continue
except Exception:
i += 1
continue
# Check for any of our keys in the decompressed stream.
for k in keys:
if k in chunk and k not in seen:
idx = chunk.find(k)
ctx = chunk[max(0, idx - 24):idx + len(k) + 48]
seen[k] = ctx.decode("utf-8", errors="replace")
i += 1
else:
i += 1
print(f"decompressed streams scanned, keys found: {len(seen)} / {len(keys)}")
for k, v in seen.items():
print(f" ✓ {k.decode()}")
print(f" context: {v[:160]}")
missing = [k for k in keys if k not in seen]
if missing:
print(f" ✗ not found: {[m.decode() for m in missing]}")
-29
View File
@@ -1,29 +0,0 @@
import re, sys
f = sys.argv[1]
data = open(f, "rb").read()
runs = re.findall(rb"[\x20-\x7e]{6,}", data)
hits = set()
keys = [
b"zipx_limits_profile",
b"k_large_limits",
b"ZIPX_LIMITS_LARGE",
b"ZIPX_LIMITS_DEFAULT",
b"large-file profile",
b"large-file",
b"LargeFile",
b"large_file",
b"extractLargeAsk",
b"extractLargeActive",
b"large",
]
for r in runs:
for k in keys:
if k in r and k.decode() not in hits:
# Trim the context a bit
i = r.find(k)
ctx = r[max(0, i - 8):i + len(k) + 24].strip()
if len(ctx) < 80:
hits.add(ctx.decode(errors="replace"))
for h in sorted(hits):
print(repr(h))
print("total:", len(hits))
File diff suppressed because it is too large. Load diff
+2 -28
View File
@@ -1,31 +1,5 @@
# Build artifacts
gen/
*.elf
web-file-mgr-linux
*.o
*.d
gen/
web-file-mgr-linux
# Sandbox scratch under .build/: ignore the whole directory, then re-allow the
# handful of files that are actually part of the repo (build scripts + the
# ELF checker). A whitelist is the only thing that survives -- every debugging
# session drops a new probe directory in here.
.build/*
!.build/build-elf.sh
!.build/build-elf-wsl.sh
!.build/build-win.sh
!.build/check-elf-*.py
!.build/extract-demo.html
!.build/build-elf.log
# Generated 7z fixtures (tests/make_sevenz_fixtures.py rebuilds them).
tests/fixtures-7z/
# Editor / OS noise
.vscode/
.idea/
*.swp
.DS_Store
Thumbs.db
# WorkBuddy session data (never commit; also never delete).
.workbuddy/
-504
View File
@@ -1,504 +0,0 @@
# Changelog
All notable changes to **PS5 Web File Manager** are documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
> Release artifact for v1.9:
> `web-file-mgr.elf` — size 919 440 bytes (~897 KiB)
> sha256 `bb8f17e9addc6a9984f611503ca01b51f8984b773d353630da1f25bd1a28a997`
> ELF class 64, little-endian, e_machine `0x003e` (x86_64-sie-ps5)
>
> Source delta vs v1.8.3: RAR engine replaced (dmc_unrar 1.7.0 → rarlab
> UnRAR 7.20.1, `third_party/unrar/` → `third_party/unrar7/`), new
> `src/rar_extract.c` scan/extract implementation, Makefile + host-test
> C++ rules, 5 real RAR fixtures committed. See [v1.9] below.
>
> Release artifact for v1.8.3:
> `web-file-mgr.elf` — size 509 704 bytes (~497 KiB)
> sha256 `fdcf7b09b69e2160e77dfa084c0e890ba0696d4dd478b1d5ff499cdc9f527955`
> ELF class 64, little-endian, e_machine `0x003e` (x86_64-sie-ps5)
>
> Source delta vs v1.8.2: 5 files touched (4 user-facing + 1 build pipeline) —
> see [v1.8.3] below for details.
>
> Release artifact for v1.8.2:
> `web-file-mgr.elf` — size 509 704 bytes (~497 KiB)
> sha256 `1b2c3d68b35e32737105f17d14a80a3c159ceca0cabd274ee168cbcd81906f65`
> ELF class 64, little-endian, e_machine `0x003e` (x86_64-sie-ps5)
>
> Source delta vs v1.8.1: 5 files relaxed (`src/zip_extract.c` k_default_limits
> + k_large_limits, `assets/main.js` `LARGE_FILE_THRESHOLD_BYTES`,
> `assets/lang-{en,zh}.js` copy, `tests/test_zip_extract.c` advertised-number
> assertion, README/HANDOVER numeric references) + 2 PS5-only build fixes
> (`Makefile` CFLAGS `-Ithird_party/unrar`, `src/extract.c` forward
> declaration of `extract_progress`); no vendored or engine changes.
## [v1.9] — 2026-09-05
**RAR engine replaced: rarlab UnRAR 7.20.1 (v6 / multi-volume / decryption-capable).**
The vendored dmc_unrar 1.7.0 only dispatched RAR5 compression version 5
(`switch(file->version)` case `0x5000`). Archives written by WinRAR 6.x /
7.x (algorithm string `v6`, version field `0x5001`) hit the default branch
and surfaced as "corrupt archive" — confirmed on a real `v6:8M` archive.
v1.9 swaps in the official rarlab UnRAR source (7.20.1) via its
C-compatible DLL API, compiled as a static library (`-DRARDLL`, PS5 uses
the toolchain's default `libc++`).
What this enables:
- **RAR5 "v6" compression** (WinRAR 6/7 archives) — the v1.9 trigger.
- **Multi-volume RAR** (`.partNN.rar`): unrar stitches volumes by name when
all parts sit next to the opened volume. Select the first volume
(`name.part1.rar`) and extract as usual.
- RAR4 and older RAR5 remain supported.
- The engine *can* decrypt encrypted archives (`RARSetPassword`), but the
password channel (API + UI) is not wired yet — encrypted headers/entries
still fail up front with `err_extract_unsupported`. Planned for a follow-up.
Engine changes:
- `src/rar_extract.c` rewritten to unrar's sequential DLL API
(`RAROpenArchiveEx → RARReadHeaderEx → RARProcessFile`); scan and extract
each re-open the archive. Multi-volume continuation segments
(`RHDF_SPLITBEFORE`) are advanced but not re-counted/deduped.
- The three-phase scan → staging → publish/rollback machinery is unchanged.
- Bug fix: `normalize_name()` no longer clears the caller's directory flag
(a real v6 archive with an explicit directory header after its files
tripped the duplicate detector).
Build & test:
- Makefile: `.cpp` rules for the unrar RARDLL source set (49 files, mirrors
`UnRARDll.vcxproj`); links through the C++ driver; `VERSION_TAG` v1.9.
- tests: 5 real RAR fixtures committed under `tests/fixtures-real/`
(generated with `tests/make-rar-fixtures.bat` + WinRAR); new happy-path
checks extract a real v6 archive, verify files on disk, auto-merge a
3-volume split, and reject encrypted archives. Total: **70 ZIP + 24 RAR
= 94 checks** (up from 70 + 14; the old 14 RAR checks never ran a real
archive).
Credits: unrar (c) Alexander Roshal, freeware license — see
`third_party/unrar7/license.txt` and `THIRD_PARTY_NOTICES`.
## [v1.8.3] — 2026-09-05
**Hotfix: "Upload and extract" now accepts `.rar` files.**
The "upload and extract" entry was hard-coded to accept only `.zip`,
even though the server-side dispatch in `src/extract.c:79` already
correctly routes `.rar` to `rar_extract()`. v1.8.3 fixes the frontend
filter so users can select a single-volume plaintext `.rar` from the
file picker and have it uploaded + extracted in one click (the same
flow that already worked for `.zip`).
What this enables:
- Choose a single-volume `.rar` from "Upload and extract"
- Server extracts it via the existing `rar_extract()` engine
- Uploaded `.rar` is auto-deleted after a successful extract (same as
`.zip` since v1.7)
What this does **not** enable (planned for v1.9.0):
- **Multi-volume RAR** (e.g. `name.part01.rar` + `name.part02.rar` …)
- **Encrypted RAR** (password-protected headers or entries)
Both still return `extract_unsupported` "single-volume RAR only" /
"encrypted RAR is not supported; please extract on a PC first" — see
the underlying engine limit in `third_party/unrar/dmc_unrar` (GPL-2.0,
1.7.0). v1.9 will swap the vendor to **opello/unrar 7.20.1** (UnRAR
License) which natively supports both.
Changed:
- `assets/index.html` — `<input id="uploadZip" accept>` now lists
`.rar` + the two RAR MIME types next to the existing ZIP entries.
- `assets/main.js:2340` — `/\.zip$/i` → `/\.(zip|rar)$/i` (the upload
pre-check), plus a local `isRar` flag so the next step branches.
- `assets/lang-en.js` — `extractUploadConfirm`: "uploaded ZIP" →
"uploaded archive".
- `assets/lang-zh.js` — `extractUploadConfirm` & `extractLargeAsk`
drop the "ZIP" wording so the copy reads sensibly for RAR uploads.
- `assets/main.js:38` — `APP_VERSION` `"v1.7"` → `"v1.8.3"` (footer
version string had been hard-coded to v1.7 since the frontend was
first imported; it no longer misleads about which build is running).
No backend changes — the server side was already correct. No test
changes — the existing RAR happy-path test in `tests/test_rar_extract.c`
passes against the same backend.
Build pipeline (also v1.8.3):
- `.build/build-elf.sh` step 6 "no source change → skip make" check now
also watches `assets/*` and `gen-asset-module.py`, not just `src/*.c`
and the `Makefile`. Without this, v1.8.3 (which touched no backend,
only frontend assets feeding `gen/*.c`) was misclassified as "no
change" and `make` was skipped — the result was that the v1.8.2 ELF
was reported as v1.8.3 with the same sha256. With this fix, only
frontend changes correctly trigger a rebuild. Users running the WSL
build need to re-copy `.build/build-elf.sh` to `/home/song/build-elf.sh`
(canonical source is on the Windows side).
## [v1.8.2] — 2026-09-05
**Hotfix: default ZIP extraction limits cover 3A-game single-file archives.**
The default `k_default_limits` profile is now **2 TiB total / 512 GiB per
entry / 500 : 1 ratio** (was 1 TiB / 256 GiB / 500 : 1 in v1.8.1). The
frontend threshold `LARGE_FILE_THRESHOLD_BYTES` is bumped from 240 GiB to
**480 GiB** to match. The `large=1` profile is widened to **4 TiB total
/ 1 TiB per entry / 1000 : 1 ratio** (was 2 TiB / 1 TiB / 1000 : 1); the
large profile must always be strictly more permissive than default.
Why: a 3A-game archive with a single ~300 GiB uncompressed file was
**silently rejected by the default profile** (`scan_archive` returns
`ZIPX_ERR_LIMIT_FILE_SIZE` in `src/zip_extract.c` line ~717 — the request
never reaches the frontend confirmation prompt, so the user just sees
"卡壳"). The 256 GiB default cap was tuned for PS5 system backups (which
have many smaller entries, not a single huge file) and was wrong for the
3A-game single-file case. The default cap is now 512 GiB so a typical
3A archive extracts under the default profile without prompting.
The safety argument is unchanged from v1.8.1: zip-bomb defence is
`check_space()` (`statvfs`-based real disk space check before staging) +
`max_ratio` (declared compression ratio cap). The size caps are a UX
guard, not a security boundary.
RAR extraction inherits the new defaults automatically — rar_extract.c
threads `c->limits` through from the engine, so no rar-side change is
required.
### Changed
- `src/zip_extract.c` — `k_default_limits` relaxed:
- `max_total_bytes`: 1 TiB → **2 TiB**
- `max_file_bytes`: 256 GiB → **512 GiB**
- `max_ratio`: 500 → **500** (unchanged)
- `src/zip_extract.c` — `k_large_limits` widened (must stay > default):
- `max_total_bytes`: 2 TiB → **4 TiB**
- `max_file_bytes`: 1 TiB → **1 TiB** (unchanged)
- `max_ratio`: 1000 → **1000** (unchanged)
- `assets/main.js` — `LARGE_FILE_THRESHOLD_BYTES`: 240 GiB → **480 GiB**
- `assets/lang-{en,zh}.js` — `extractLargeAsk` copy updated to reflect
the new numbers (default 512 GiB / 2 TiB; large 1 TiB / 4 TiB)
- `tests/test_zip_extract.c` — `test_large_profile` advertised-number
assertion updated: `max_total_bytes == 4 TiB` (was 2 TiB)
- `README.md` — both limit tables (ZIP + RAR), the "Tuning the threshold"
snippet, and the `err_extract_entry_too_large` FAQ entry bumped to the
new numbers
- `docs/HANDOVER.md` — `LARGE_FILE_THRESHOLD_BYTES`, the
`k_default_limits` / `k_large_limits` ASCII diagram, the user-scenario
description, the 480 GiB popup note, and the RAR limits paragraph
bumped to the new numbers
### Unchanged
- `src/rar_extract.c` — already threads `c->limits` from the engine,
picks up the new defaults for free
- `max_ratio` — both profiles unchanged (500 : 1 default / 1000 : 1 large)
- `check_space()` — unchanged; still the real disk-space guard
- `max_entries` — 200 000 default / 500 000 large, unchanged
- `docs/UPGRADE-v1.7-zip-large-file-profile.md` — historical v1.7
document left as-is so the v1.7 → v1.8.2 evolution is traceable
- Test fixture `medium_bomb.zip` (ratio ≈ 238) still exercises both
rejection under the default 500 : 1 cap and acceptance under the
`large=1` 1000 : 1 cap
- 84 host-side checks (70 ZIP + 14 RAR), 0 failures
### Migration notes
- **Forward-compatible** — users with v1.8.1 deployments who never trigger
`err_extract_entry_too_large` see no difference (defaults are strictly
more permissive)
- **3A-game single-file archives now extract silently** — no prompt, no
manual `large=1` API call required for files up to 512 GiB
- **No data loss** — the relaxation only widens accepted archives; the
real security guards (`check_space`, `max_ratio`, `path traversal`)
are untouched
- **No frontend UX change for typical use** — only archives > 480 GiB
on disk now trigger the confirmation prompt (previously 240 GiB)
---
## [v1.8.1] — 2026-09-05
**Hotfix: relaxed default ZIP extraction limits.**
The default `k_default_limits` profile is now **1 TiB total / 256 GiB per
entry / 500 : 1 ratio** (was 512 GiB / 64 GiB / 200 : 1). The frontend
threshold `LARGE_FILE_THRESHOLD_BYTES` is bumped from 60 GiB to 240 GiB
to match. The `large=1` profile (1 TiB / 1 TiB / 1000 : 1) is unchanged.
Why: the previous default was a UX-oriented early-fail guard, not a
security guard — `check_space()` already enforces available ≥ bytes_total
before staging begins, and `max_ratio` already rejects classic zip
bombs. A user with a multi-hundred-GiB system image shouldn't have to
click through a confirmation prompt for what's a perfectly safe archive.
The relaxed default still rejects any archive whose declared
uncompressed total exceeds the destination's free space (real check,
not a declared-vs-fs assertion) and any archive with a declared ratio
above 500 : 1 (real zip-bomb guard).
RAR extraction inherits the new defaults automatically — rar_extract.c
threads `c->limits` through from the engine, so no rar-side change is
required.
### Changed
- `src/zip_extract.c` — `k_default_limits` relaxed:
- `max_total_bytes`: 512 GiB → **1 TiB**
- `max_file_bytes`: 64 GiB → **256 GiB**
- `max_ratio`: 200 → **500**
- `assets/main.js` — `LARGE_FILE_THRESHOLD_BYTES`: 60 GiB → **240 GiB**
- `assets/lang-{en,zh}.js` — `extractLargeAsk` default-profile copy
updated to reflect the new numbers
- `README.md` — "Stricter default ZIP profile" line, the limit table
(two locations), and the `err_extract_entry_too_large` FAQ entry
bumped to the new numbers; "Tuning the threshold" snippet updated to
240 GiB
- `docs/HANDOVER.md` and `docs/UPGRADE-v1.8-rar-support.md` — the
few remaining numeric references in those docs updated
### Unchanged
- `src/rar_extract.c` — already threads `c->limits` from the engine,
picks up the new defaults for free
- `k_large_limits` — `large=1` profile (1 TiB / 1 TiB / 1000 : 1) is
unchanged
- `docs/UPGRADE-v1.7-zip-large-file-profile.md` — historical v1.7
document left as-is so the v1.7 → v1.8.1 evolution is traceable
- Test fixture `medium_bomb.zip` (ratio ≈ 238) still exercises both
rejection under the default 500 : 1 cap and acceptance under the
`large=1` 1000 : 1 cap
- 83 host-side checks (69 ZIP + 14 RAR), 0 failures
### Migration notes
- **Forward-compatible** — users with v1.7 / v1.8 deployments who never
trigger `err_extract_entry_too_large` see no difference (defaults are
strictly more permissive)
- **No data loss** — the relaxation only widens accepted archives; the
real security guards (`check_space`, `max_ratio`, `path traversal`)
are untouched
- **No frontend UX change for typical use** — only archives > 240 GiB
on disk now trigger the confirmation prompt (previously 60 GiB)
---
## [v1.8] — 2026-09-05
**RAR extraction: single-volume RAR4 / RAR5 (unencrypted).**
> ⚠️ Scope clarification — v1.8 ships **single-volume unencrypted RAR** only.
> The original RAR wishlist (multi-volume `.partNN.rar`, encrypted RAR with
> password UI) is **deferred to v1.9**; see `docs/UPGRADE-v1.8-rar-support.md`
> and `third_party/unrar/VENDORED.md` for the rationale and the engine
> upgrade path. ZIP behaviour and the large-file profile are unchanged.
### Added
- **`src/rar_extract.{c,h}`** — a new extraction engine that mirrors
`zip_extract`'s protocol exactly. Internally it wraps the vendored
`dmc_unrar` 1.7.0 (`third_party/unrar/dmc_unrar.c`). The public entry point
is `rar_extract(rar_path, dst_dir, conflict, limits, cancel, progress,
userdata, result)` — same signatures, same `zipx_status_t` codes, same
`zipx_result_t`, same `zipx_limits_t` profile lookup. ~1276 LOC
(`src/rar_extract.c`).
- **`third_party/unrar/`**:
- `dmc_unrar.c` — vendored verbatim from upstream (11 598 LOC, ~365 KiB).
GPL-2.0-or-later, attributed in `THIRD_PARTY_NOTICES`.
- `dmc_unrar_api.h` — **project-authored facade header**. Re-declares only
the `dmc_unrar_*` symbols `rar_extract.c` actually uses, so the engine
can `#include "dmc_unrar_api.h"` instead of `#include "dmc_unrar.c"`.
This keeps the vendored `.c` compiling as its own translation unit and
avoids polluting dmc_unrar's struct / function names with any
build-system macros (see `tests/posix_compat.h`'s `wfm_open` /
`wfm_close` rename pattern — that conflict is what motivated the
facade). The facade carries the project's license; the library body
remains unmodified.
- `COPYING`, `README.md` — upstream GPL notice + readme.
- `VENDORED.md` — explains why we chose `dmc_unrar` over rarlab UnRAR /
`opello/unrar`, what is and is not supported, and gives a step-by-step
upgrade plan for moving to a fuller C++ UnRAR in v1.9.
- **`src/extract.c` dispatch layer** — `extract_dispatch()` picks the
engine by extension (`.zip` → `zipx_extract`, `.rar` → `rar_extract`,
anything else → `ZIPX_ERR_UNSUPPORTED`). The case-insensitive suffix
matcher trims trailing path separators. `extract_worker` now calls the
dispatch instead of going straight to the ZIP engine.
- **Frontend + i18n wiring**:
- `assets/main.js` recognises `.rar` (single-volume) and `.part0*1.rar`
(multi-volume master) as extractable, greys out the extract button on
`.part02+.rar` sub-volumes with a tooltip "select the main volume
instead". This UX is only useful because v1.8 still rejects
multi-volume RAR with a friendly error — the visual feedback stops the
user from selecting a sub-volume and getting confused.
- `assets/lang-{en,zh}.js` `err_extract_unsupported` updated to:
"…(only unencrypted plain ZIP and single-volume RAR are supported)…".
- **Host test suite** (`tests/test_rar_extract.c`, **14 checks**) —
negative paths only (format dispatch, error translation, limits
handoff). The suite is wired into `tests/run-tests.sh` alongside the
existing ZIP suite; fixture generation falls back to a placeholder
blob when no `rar` / `7z` writer is present, so the negative tests
fire on any host. Total host checks: **69 ZIP + 14 RAR = 83**.
### Changed
- **`Makefile`**:
- `VERSION_TAG := v1.8` (was `v1.7`).
- `THIRD_PARTY_SRCS` adds `third_party/unrar/dmc_unrar.c`.
- `THIRD_PARTY_CFLAGS` adds `-Ithird_party/unrar` and
`-DDMC_UNRAR_DISABLE_BE32TOH_BE64TOH=1` (dmc_unrar's own byte-swap
helpers are avoided so we don't need an extra `byteswap.h` shim on
the SDK).
- **`src/extract.c` / `src/extract.h`** — no public-API break. The HTTP
surface (`POST /api/extract`) accepts the same fields as v1.7 plus
the existing `large=1`; there is **no** `password=` field because
v1.8 cannot decrypt. (The wire format is forward-compatible — a v1.9
`password=` field will be additive.)
- **`THIRD_PARTY_NOTICES`** — adds a section `3. dmc_unrar` crediting
Sven Hesse (DrMcCoy), summarising the GPL-2.0-or-later obligations on
the resulting binary, and noting that `dmc_unrar_api.h` is
project-authored and licensed with the project.
### Limitations (v1.8 scope)
- **Multi-volume RAR** (`.part02+.rar`, `.part1+.rar`, numbered
continuations) is rejected with `ZIPX_ERR_UNSUPPORTED` and the error
message "extract on a PC first". Upstream dmc_unrar does not chain
companion volumes by design. When opello/unrar replaces dmc_unrar
in v1.9 this becomes a one-line error-code drop.
- **Encrypted RAR** (any encrypted header / file flag) is rejected with
`ZIPX_ERR_UNSUPPORTED`. Same root cause — dmc_unrar omits decryption
to avoid patent complications. There is **no** password prompt in
the UI; there is **no** `password=` field in `/api/extract`.
- **Symbolic links, FIFOs, sockets, devices** inside a RAR archive are
rejected with `ZIPX_ERR_SPECIAL` (mirrors ZIP behaviour).
- **RAR 1.4** (very old) is not supported by dmc_unrar and is rejected
upstream with `DMC_UNRAR_ARCHIVE_VERSION_UNSUPPORTED`; the wrapper
maps that to `ZIPX_ERR_UNSUPPORTED`. RAR 1.5 through RAR 5.0 are
supported.
### Verification
```sh
make # builds web-file-mgr.elf (in WSL)
ls -la web-file-mgr.elf # record size
sha256sum web-file-mgr.elf # record digest (paste into the v1.8 banner above)
file web-file-mgr.elf # ELF 64-bit LSB pie, x86-64
od -An -tx1 -N20 web-file-mgr.elf # 7f45 4c46 0201 + e_machine 003e
(cd tests && bash run-tests.sh) # 69 + 14 = 83 checks, 0 failures
python3 .build/check-elf-gzip.py ./web-file-mgr.elf # 7/7 v1.7 keys + 1 v1.8 key (err_extract_unsupported)
```
### Technical notes
A long-form technical write-up of this upgrade lives in
[`docs/UPGRADE-v1.8-rar-support.md`](./docs/UPGRADE-v1.8-rar-support.md).
The vendoring decision tree (and the v1.9 plan) is in
[`third_party/unrar/VENDORED.md`](./third_party/unrar/VENDORED.md).
### Credits
Same as v1.7 — see [README.md → Credits](./README.md#credits). dmc_unrar
is credited in [`THIRD_PARTY_NOTICES`](./THIRD_PARTY_NOTICES).
---
## [v1.7] — 2026-09-04
**ZIP extraction: large-file profile, three-phase engine, host test suite.**
### Added
- **Large-file profile** (`ZIPX_LIMITS_LARGE`) for ZIP extraction — relaxed
caps of **500 000** entries, **2 TiB** total uncompressed, **1 TiB** per
entry, **1000 : 1** compression ratio. Enable via the new `large=1`
argument on `POST /api/extract`. The UI prompts the user automatically
whenever the archive on disk is larger than 60 GiB (`LARGE_FILE_THRESHOLD_BYTES`).
- **Standalone three-phase ZIP engine** (`src/zip_extract.{c,h}`) — the model
`SCAN → EXTRACT → PUBLISH → CLEANUP`. Each entry is written into a staging
directory first, fsynced, then atomically renamed into the destination. Any
mid-archive failure rolls back partial changes.
- **Profile lookup helper** `zipx_limits_profile(int)` and the new macros
`ZIPX_LIMITS_DEFAULT` (0) and `ZIPX_LIMITS_LARGE` (1). The public
`zipx_extract()` signature is unchanged.
- **Opt-in API field** `large` on `POST /api/extract`, backed by a new
`extract_large` flag in `file_task_t` (`src/filemgr_internal.h`,
`src/extract.c`).
- **Frontend wiring** (`assets/main.js`) — `LARGE_FILE_THRESHOLD_BYTES`,
`shouldPromptLargeMode()`, `promptLargeMode()`, consumed by
`actionExtract()` and `uploadAndExtractFile()`.
- **Bilingual UI strings** (`assets/lang-{en,zh}.js`) —
`extractLargeAsk` and `extractLargeActive`.
- **Host-side C test suite** (`tests/`) — POSIX-runnable, no PS5 SDK
required. **69 checks** at release: traversal, ZIP64, encryption rejection,
conflict policies, large-file profile switching.
- **Cross-compile helper** (`.build/build-elf.sh`) — staging-mode build that
works around the read-only SDK install location.
- **Demo page** (`.build/extract-demo.html`) — visualises the three policy
combinations (fail / overwrite / merge) against the new profile table.
### Changed
- **Engine internals** rewritten around the three-phase model. Public API
(`zipx_extract()`, `zipx_default_limits()`) is unchanged — old callers
compile and link clean.
- **`file_task_t`** gains `extract_large` (`src/filemgr_internal.h`).
Internal-only; downstream consumers reading the task struct need to
recognise the new field.
- **`gen-asset-module.py`** continues to gzip JS into the binary; the
helpers in `.build/check-elf-gzip.py` are the supported way to verify that
a fresh build picked up asset changes (regular `strings` won't see them).
### Security
- Default ZIP caps are unchanged: **512 GiB** total / **64 GiB** per entry /
**200 : 1** ratio.
- The large profile is **never** activated server-side on its own — the
client must explicitly send `large=1` (either via the UI prompt or directly
via the API).
- Encryption, path traversal, symbolic links, FIFOs and unresolved conflicts
are still rejected before any output file is opened.
- Strict value matching: only the literal `"1"` enables the large profile;
`true`, `yes`, `on` are all treated as `0`. Matches the existing
`remove_source=` semantics.
### Known limitations
- Multi-volume / split ZIP archives (`.zip` + `.z01`, `.z02`, …) are not
stitched by the engine. minizip-ng has the API; wiring it is post-v1.7.
- The 60 GiB frontend threshold for the large-profile prompt is hardcoded
(`LARGE_FILE_THRESHOLD_BYTES`, `assets/main.js` line 813).
- The large profile does **not** run `statvfs()` against `dst_dir` before
extraction; free-space preflight is on the post-v1.7 roadmap.
- Bomb-shaped archives with compression ratio **> 1000 : 1** are rejected
under both profiles (`bomb.zip` with 4 MiB of `'A'` has ratio ≈ 1026 and
hits this wall under the large profile).
### Verification
```sh
make # builds web-file-mgr.elf
ls -la web-file-mgr.elf
sha256sum web-file-mgr.elf # 648e4a00…
file web-file-mgr.elf # ELF 64-bit LSB pie, x86-64
od -An -tx1 -N20 web-file-mgr.elf # 7f45 4c46 0201 + e_machine 003e
(cd tests && bash run-tests.sh) # 69 checks, 0 failures
python3 .build/check-elf-gzip.py ./web-file-mgr.elf # 7/7 large-mode keys in ELF
```
### Technical notes
A long-form technical write-up of this upgrade (architecture delta, three-phase
model, behaviour contract, trade-offs, future work) lives in
[`docs/UPGRADE-v1.7-zip-large-file-profile.md`](./docs/UPGRADE-v1.7-zip-large-file-profile.md).
### Credits
The same as v1.6 — see [README.md → Credits](./README.md#credits).
-298
View File
@@ -1,298 +0,0 @@
# 交接文档 — ps5-web-file-manager 工作进度
> 交接时间:2026-09-15 · 分支 `main` · 最新提交 **`0d036a7`** · tag `v1.9.1` 指向 `1fa2f09`(**需重打到 `0d036a7`**)
>
> **主线(用户 2026-09-12 指令)**:「先从 zip 分卷开始吧,然后把六种组合打齐,并把密码通道补齐,注意一些报错信息提示的时候尽量详细准确」
> **状态:主线全部闭合。** 六种组合(ZIP/RAR/7z × 单卷/分卷)+ 密码通道(RAR 加密 + 7zAES)+ 报错详细信息,全部落地、测试全绿、PS5 ELF 构建成功。
> **剩余**:① 推送 `0d036a7`;② tag 重打;③ PS5 真机端到端验证;④ `-mhe=on` 加密头(唯一功能缺口)。
---
## 一、当前状态速览
| 维度 | 状态 |
|---|---|
| 解压引擎 | ZIP / RAR / 7z × 单卷/分卷(6 组合)+ 7zAES / RAR 加密 |
| 主机测试 | **ZIP 108 + RAR 27 + 7z 28 = 163 checks,0 失败**(MinGW gcc 16.2.0) |
| PS5 构建 | ✅ WSL prospero-clang 18.1.8,一键脚本可复现 |
| ELF 产物 | `web-file-mgr-v1.9.1.elf` · 1,017,864 B · sha256 `05952ac05fb937e8758846cbd8d495a427670e3cfb7f4020d42d4c6fe8c21631` · e_machine=0x003e |
| GitHub | `main` 已推到 `1fa2f09`;`0d036a7` 待推;`v1.9.1` tag 待重打 |
| 唯一功能缺口 | 7z `-mhe=on`(加密头) |
### 待用户在自己终端执行
```bash
cd "/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager"
# 1) 推送本轮的 /api/version 改动
git push origin main
# 2) v1.9.1 重打到最新(1fa2f09 -> 0d036a7,让 tag 内含 /api/version + 新 ELF)
git tag -f -a v1.9.1 -m "v1.9.1 -- 7z + multi-volume + 7zAES + PS5 build + version API" 0d036a7
git push -f origin v1.9.1
# 3) 可选:发 Release(附带 ELF)
gh release create v1.9.1 --title "v1.9.1" --notes-file .git/tag-v191.txt web-file-mgr-v1.9.1.elf
```
沙箱内 git 出站 HTTPS 被拦(502/403),推送只能用户侧执行。
---
## 二、本轮(2026-09-15)变更
### 2.1 一键构建脚本(`a54f34b` / `5229cd5`)
| 文件 | 跑在哪 | 作用 |
|---|---|---|
| `.build/build-win.sh` | Windows Git Bash | 入口:把 WSL 脚本经 **stdin** 喂给 `wsl.exe`,透传退出码 |
| `.build/build-elf-wsl.sh` | WSL Ubuntu-22.04 | 5 阶段:环境检查 → rsync 同步 → `make all` → 验证 → 拷回 Windows |
| `.build/build-elf.sh` | WSL 内 | **仅首次搭环境用**(libmicrohttpd staging 安装 + sudo) |
```bash
# Windows 端(注意:必须 /usr/bin/bash,裸 bash 会解析成 WSL 启动器)
cd "/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager"
/usr/bin/bash .build/build-win.sh
# 或 WSL 内
bash /home/song/build.sh
```
**两个关键实现点**(改脚本前必读):
- `wsl.exe -- bash -c '...'` 遇到含空格路径会被拆断 → 必须 `wsl.exe -- bash < script.sh`(stdin 重定向)
- `make ... | tail` 会吞掉退出码 → 用 `${PIPESTATUS[0]}`;否则编译失败还会继续跑验证,输出假成功
### 2.2 版本号体系统一(`f4fd464` / `1fa2f09` / `0d036a7`)
原本版本号有**两个真相来源**,已经漂移过:`Makefile` 写 `v1.9.1`,`assets/main.js` 硬编 `"v1.9"`,UI 右下角在整个 v1.9.1 发布期都显示旧值。
现在收敛到 `Makefile` 一处:
```make
VERSION_TAG ?= v1.9.1 # 可用 make VERSION_TAG=v1.9.2 临时覆盖
BIN := web-file-mgr-$(VERSION_TAG).elf
```
改这一行会同时影响 **四处**:ELF 内嵌版本串、PS5 启动通知、输出文件名、UI 右下角。
| 提交 | 内容 |
|---|---|
| `f4fd464` | `VERSION_TAG` `v1.9` → `v1.9.1`;`.gitignore` 改白名单式(`.build/*` 全忽略 + `!` 放行 6 个脚本),`.workbuddy/` 也忽略 |
| `1fa2f09` | 输出文件名派生自 `VERSION_TAG`;`build-elf-wsl.sh` 从 Makefile 反读版本(不硬编);`build-win.sh` 每次都推 WSL 脚本(原来只在缺失时推,导致改了脚本 WSL 侧仍跑旧版) |
| `0d036a7` | **新增 `/api/version`**,前端右下角改从后端取值(见 2.3) |
### 2.3 UI 版本号改由后端提供(`0d036a7`)
**问题**:`assets/main.js:38` 的 `const APP_VERSION = "v1.9"` 与 Makefile 无关,必然漂移。
**修法**:
- 新 `src/version.c` — `GET /api/version` → `{"ok":true,"version":"v1.9.1","titleId":"FMGR88888"}`,直接来自 Makefile 已传的 `-DVERSION_TAG` / `-DTITLE_ID` 宏,没有第二处要记得改
- `src/filemgr.c` 路由表加一行(紧邻 `/api/space`)+ `filemgr_internal.h` 声明 + `Makefile` `COMMON_SRCS`
- 前端:字面量降级为 `APP_VERSION_FALLBACK`(先渲染,保证页脚不空),`loadVersion()` 后台刷新。**请求失败静默吞掉** —— 版本号显示错属于装饰性问题,不该弹错误 toast
**踩坑**:新文件漏了 `#include "json_util.h"` → `strbuf_append` / `json_escape` 隐式声明报错。`space.c` 是模板,照抄时别漏。
---
## 三、功能矩阵与测试
### 3.1 六种组合 + 密码通道
| # | 引擎 | 单卷 | 分卷 | 密码 |
|---|---|---|---|---|
| ① | ZIP | ✅ | ✅ 三种命名约定 | ✅ |
| ② | RAR | ✅ | ✅(vendor unrar 7.20.1) | ✅ `RARSetPassword` |
| ③ | 7z | ✅ | ✅ `.7z.001` | ✅ 7zAES |
### 3.2 测试
```bash
export PATH="/c/mingw64/bin:/c/Users/songl/.workbuddy/binaries/PortableGit/versions/1.2.0/mingw64/bin:/c/Users/songl/.workbuddy/binaries/python/versions/3.13.12:/usr/bin:/bin:/c/Windows/System32:/c/Windows"
cd "/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager"
/usr/bin/bash tests/run-tests.sh # ZIP 108 + RAR 27
/usr/bin/bash tests/run-sevenz-tests.sh # 7z 28(含 KNOWN_GAPS 检查)
```
⚠️ **绝不写裸 `bash`** —— 可能解析到 `C:\Windows\System32\bash.exe`(WSL 启动器),脚本跑进 Linux,gcc/python 全变 Linux 版,报莫名错误。必须 `/usr/bin/bash`。
`run-sevenz-tests.sh` 带 `KNOWN_GAPS` 列表(当前仅 `aeshe`),缺口修好后脚本会主动报错,防止列表腐烂。脚本**不做任何删除**(safe-delete 钩子会拦 `rm -rf`)。
---
## 四、构建(PS5 ELF)
### 4.1 日常构建
```bash
cd "/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager"
/usr/bin/bash .build/build-win.sh
```
增量有效(`ps5-obj/` 缓存保留)→ 二次构建 30s–2min。**别 `make clean`**(全量重编第三方 3–5min)。
产物:项目根 `web-file-mgr-<VERSION_TAG>.elf`,同时留在 WSL `/home/song/ps5-web-file-manager/`。
### 4.2 验证清单
```bash
ls -lh web-file-mgr-v1.9.1.elf
sha256sum web-file-mgr-v1.9.1.elf
od -An -tx2 -j18 -N2 web-file-mgr-v1.9.1.elf # 期望 3e00
strings -a web-file-mgr-v1.9.1.elf | grep -m1 '^v1\.'
```
⚠️ `od -An -tx2` 打印的是**小端 short 的值**(`003e`),不是字节序(`3e00`)。脚本里比对用 `$((16#$EM))` 转数值(**62 = x86-64 ✅ / 183 = aarch64 ❌**)。
⚠️ **sha256 只在源码不变时可复现**。核对版本请用 `strings ... | grep ^v1.9`,比 sha256 直观且抗噪。
### 4.3 构建坑(已修,改 Makefile 前必读)
`third_party/7z/AesOpt.c` 用编译器版本宏判断是否启用 AES-NI / AVX / VAES,clang 18 直接进 VAES 分支,但 prospero-clang 默认 target 是 generic x86_64 → `_mm256_aesenc_epi128` 未声明,20 报错。
- ❌ **不能** `filter-out AesOpt.c` —— `Aes.c` 通过 `AesGenTables` 引用 `AesCbc_Encode_HW` 等符号,会链接失败
- ✅ **正解**:路径过滤 `SEVENZ_C_FLAGS := -maes -mavx2 -mvaes`,仅 `third_party/7z/*.c` 用。PS5 是 Zen 2,硬件全支持,运行时无差异
---
## 五、7z 引擎设计要点(改代码前必读)
### 5.1 为什么不走 SDK 的解码器
LZMA SDK 26.03(public domain,已 vendor 到 `third_party/7z/`,解码子集 60 文件)有两个硬限制,**实测复现过**:
1. **`CSzFolder` 上限 4 coder / 3 bond** —— 7-Zip 默认 `-m0=bcj2` 链 = BCJ2 + 4×LZMA2 = 5 coder,`SzAr_DecodeFolder()` 返回 `SZ_ERROR_UNSUPPORTED`。注意 `SzArEx_Open()` 用的是另一套宽松扫描器(`k_Scan_NumCoders_MAX 64`),所以**文件列表和解压尺寸仍然全对**,失败只在解压时按条目暴露
2. **C 解码器完全没有 7zAES coder** —— `-p` 与 `-mhe=on` 全被拒
→ 因此引擎**自解析 folder blob + 自己驱动 codec 链**(`src/sevenz_chain.c/.h`,pull pipeline:`node_pull(n, dst, want, &got)`,不够就 `node_refill()` 拉上游)。
### 5.2 最关键的坑
**【必记】每个 coder 节点的 `out_size` 必须取 `coder_unpack_sizes[index]`,绝不能用 folder 的 unpack size。** BCJ2 folder 里 MAIN 常大于 folder 最终尺寸(实测 300066 > 300000)。用错的症状:每层 LZMA2 静默短 21 字节,只在特定包上暴露。
其他:
- 编译必须 `-DZ7_PPMD_SUPPORT`,否则 `7zDec.c` 直接丢掉 PPMd
- `CoderUnpackSizes` 是**扁平数组**(每条 = 对应 coder 输出流大小),**非累计**;`FoToCoderUnpackSizes[f]..[f+1]` 是该 folder 的切片
- main coder = 第一个未被 bond 消费的 coder
- `SzArEx_Extract` 失败后会把半成品留在 block cache → 后续条目报**假 CRC**,要重置 `blockIndex`
- 造夹具用 Extra 包的 `7za.exe`(有 PPMd);**`7zr.exe` 没有 PPMd 编码器**
- 调试三件套在 `.build/`:`chainprobe.c`(摸内部图)、`chainprobe2.c -r <coder>`(强制 root 逐层二分)、`chaincheck.py`(Python liblzma 独立复现同一条链,秒判"图错"还是"循环错")
### 5.3 7zAES KDF
`numCyclesPower = b0 & 0x3F`;`saltSize = ((b0>>7)&1) + (b1>>4)`;`ivSize = ((b0>>6)&1) + (b1&0x0F)`,随后依次 salt → iv。
`numCyclesPower == 0x3F` 时 key = `salt||password` 补齐/截断到 32 字节;否则 `key = SHA256(salt || password_utf16le || counter_le64)` 迭代 `1<<numCyclesPower` 次。之后 AES-256-CBC。
限额 `max_aes_cycles = 24`(约 8s)。
**改引擎前先在 `.build/aesprobe.c` 独立验证 KDF**(用 vendor 的 `Sha256.c` + `Aes.c` 解 aes.7z coder0,与 `cus[0]=638314` 比对),确认后再集成。
### 5.4 分卷流抽象
- `src/zipx_volstream.c/.h`(ZIP,包成 `mz_stream`)· `src/sevenz_volstream.c/.h`(7z,包成 SDK `ISeekInStream`)
- **结构体首成员必须是 `mz_stream stream;` / `ISeekInStream vt;`**(回调把 `void*` 强转)
- `vol_is_open()` 必须返回 `MZ_OK`/`MZ_OPEN_ERROR`(**不是 1/0**)
- vtbl **必须注册 `destroy`**,否则 `mz_stream_delete()` 不回调 → 泄漏
- CONCAT 模式对 `DISK_NUMBER`/`DISK_SIZE` 返回 `MZ_PARAM_ERROR` → 让 minizip 不切盘
- DISK 模式 `set_prop(DISK_NUMBER, -1)` 必须切到**最后一卷**(minizip 路径 `mz_zip.c:2252-2275`)
- `remove_source_archives()` 要删**所有**卷,避免孤儿卷
### 5.5 提取门面
`src/sevenz_extract.c`(1753 行)完全仿 `zip_extract.c` / `rar_extract.c`:scan → extract(staging, 每 entry fsync) → publish(整 rename) → cleanup。
- **OVERWRITE 与 MERGE 对目录-目录碰撞都递归下钻**(仅叶子文件不同)
- 三方共用 `src/zipx_common.c`(限额 profile + `zipx_status_string()`)
- scan 阶段**每 256 entries** 报一次进度(曾用 4096,小包扫描期 UI 静默),扫描末 force-report;`precheck_folders` 入口也强制报一次
- 密码错时 detail **必须带 archive 名**(曾是 NULL → i18n `{arg}` 展开成空 → 用户看到「密码错误: 」后面光秃秃)
---
## 六、限额体系(ZIP 与 RAR 共用;7z 同源)
| 限额字段 | default | large | 160GB/9万文件场景 |
|---|---|---|---|
| `max_entries` | 200,000 | 500,000 | 9 万 ✅ |
| `max_total_bytes` | 2 TiB | 4 TiB | 160 GiB ✅ |
| `max_file_bytes` | **512 GiB** | **1 TiB** | 20 GiB ✅ |
| `max_ratio` | 500 | 1000 | 仅 ≥1GiB 条目受检 |
| `ratio_min_bytes` | 1 GiB | 1 GiB | 小文件豁免 |
- 切 large 档的触发条件:**压缩包文件本身** >480 GiB(`assets/main.js` `LARGE_FILE_THRESHOLD_BYTES`),160GB 包走 default
- **ratio 有尺寸下限**(`ratio_min_bytes` = 1GiB):小文件高压缩率合法常见(零填充/稀疏),且写出字节受"声明上限 + `check_space()`"双重约束,无害
- **唯一真实失败点是磁盘空间**:`check_space()` 按**解压后总量**查 `statvfs`,峰值 = `zip 体积 + 解出体积`。分卷场景"传一卷解一卷删一卷"可降峰值
- **32 位安全**:引擎内部 size 全 `uint64_t`;minizip `mz_zip.h:34-35` 的 `compressed/uncompressed_size` 是 `int64_t` → >4GiB 不截断
- **已知 UX 缺陷(未修)**:进度条 % 用字节(`main.js:1985`)、文字进度解压时用条目数(`main.js:2014`)、ETA 用字节速度(`task.c:129-177`)。混合大包上割裂,建议统一为字节
---
## 七、环境要点(新人必读)
- **PS5 是 x86-64 Zen 2**(不是 aarch64!),target triple `x86_64-sie-ps5`
- **PS5 SDK C++ runtime = LLVM libc++**(FreeBSD 系 sysroot,无 libstdc++)→ C++ 必须 `-stdlib=libc++`,链接 `-lc++ -lc++abi`(Makefile 已处理:unrar 用 prospero-clang++ 编)
- **PS5 SDK libc 的 `*at()` 族(mkdirat/openat/renameat/unlinkat)能链接但运行时损坏**:返回 -1 且 `errno=0`(2026-09-06 Frostpunk 2 真机确诊)。`zip_extract.c` 已有"*at() 失败回退全路径调用"兼容层;写新引擎代码时直接用全路径或沿用回退模式。报错要带 `(errno=%d)`,`errno=0` 时 `strerror` 会骗人
- WSL:`export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdk` 后才能 make
- `target/user/homebrew/` 由 songl(197609) 拥有,WSL 身份 song(1000) 写不进 → staging 模式(make install 到 /tmp → `sudo cp -r`)
- `//wsl$/Ubuntu-22.04/` 是 SMB 只读视图,改 WSL 文件必须走 Windows 路径
- libmicrohttpd 必须 `--disable-https --disable-openssl`
- **minizip-ng 4.2.2 补丁(升级会丢)**:`src/mz_strm_os_posix.c` L25 后插 `#ifndef O_BINARY / #define O_BINARY 0 / #endif`
- **主机 POSIX shim(CP936 主机必需)**:`tests/posix_compat.h` 把 `lstat/stat → wfm_stat`、`opendir → _wopendir`(UTF-8 转换)、`fopen → _wfopen`。MinGW ANSI 入口看不见 UTF-8 文件名
- 复杂 commit / tag message 用 `-F 文件`,不要 `-m` 长文本(bash quoting 会挂)
---
## 八、唯一功能缺口
### `-mhe=on` 加密头 7z
`-mhe=on` 时整个 header(含 folder 表)也被加密,引擎必须在**解析 folder 之前**先用密码解密第二份 header,才能知道有哪些 folder / 用什么 coder。工作量约为标准 7zAES 的 2 倍(两次 AES 解密路径)。
当前 `SZ_ERROR_UNSUPPORTED`,已在 `tests/run-sevenz-tests.sh` 的 `KNOWN_GAPS`(`aeshe`)标注 —— 缺口修好后脚本会主动报错提醒移除。
### 真机端到端待验证
ELF 已构建,但需装 PS5 实测:
1. ZIP / RAR / 7z 三类**分卷**真机解压
2. **加密 7z(7zAES)** 真机解压
3. 160GB / 9.5 万文件大 ZIP
4. 分卷 RAR 进度条实时走动
5. UI 右下角版本号显示 `v1.9.1`
### 可选项(非阻塞)
- **性能**:实测上游(7-Zip 本体)在 **7z 格式上快 1.9×(单线程)/ 3.4×(8 线程)**;ZIP 无显著差异。差距不在我们的架构(我们比 SDK 自己的 `SzArEx` 路径还快 1.02×)。**已全部落地(2026-09-16)**:①汇编解码器(`LzmaDecOpt.asm`+jwasm,1.26×,无 jwasm 自动退纯 C)②多线程 LZMA2(`Lzma2DecMt`,8 线程,1.37×,线程失败自动降级 chain;BCJ2/加密布局仍走 chain)③ZIP 逐条目 fsync 移除(8000 文件 ≥14×)。7z 现与 7-Zip 单线程打平、ZIP 已压过官方(本机受 Defender 拖累不可比,PS5 无该因素)。RAR 与官方 UnRAR 同速(unrar 自带 `target("aes")` SIMD 已启用,无逐条目 fsync)。完整数据见 `docs/EXTRACTION-PERF.md`,基准工具 `tests/bench_driver.py`
- fsync 批量化(每 64MB/N 条刷一次)—— 9.5 万文件级可省 20–30 分钟
- 解压失败保留 staging 支持续解(中等改动)
- 进度条 % / 文字进度 / ETA 三处口径统一为字节
---
## 九、仓库许可与代码归属(2026-09-15 核查)
用户曾担心「项目源自他人代码、没有许可」——**前提不成立**:
- 上游 `owendswang/ps5-web-file-manager` 经 GitHub API 确认 = **GPL-3.0**(78 stars,last push 2026-09-08)
- 本项目 `LICENSE`(GPL-3.0 全文)在 root commit `5cb0b76` 即存在,与上游一致
- 授权链完整:`ps5-payload-dev/websrv`(John Törnblom, GPLv3+,其 Copyright 头仍保留在 `asset.c` / `asset.h` / `mime.h` / `websrv.h`)→ `owendswang` → 本项目
代码量构成:
- 第三方 vendored **71,528 行**(unrar7 27,710 / zlib 20,106 / LZMA SDK 17,248 / minizip-ng 6,464)——重写时原样复用,零成本
- 第一方 20,844 行 = 上游 v1.7 遗产 13,860 + 自有 6,984
- **自有代码中 3,661 行零耦合**(`sevenz_chain` 2094 + `zipx_volume` 658 + `zipx_volstream` 494 + `sevenz_volstream` 415,只依赖 public domain / zlib)→ 可单独抽成 MIT 库
完整评估见 `docs/REWRITE-FEASIBILITY.md`(三路径:补合规 0.5 天 / 架构重构 12–18 天 / clean-room 重写 35–50 天)。**结论:建议补合规而非重写** —— GPL-3.0 保护 7z 引擎成果不被闭源白嫖。
---
## 十、工作区状态
工作树已干净(`git status` 仅剩有意保留的未跟踪文档)。
已清理(2026-09-15):
| 文件 | 说明 | 去向 |
|---|---|---|
| `erssonglDesktopWeb File Managerps5-web-file-manager¬`(2543 B) | 早期 shell 转义事故:一次 `git log --oneline --color` 的输出被重定向进了文件名。末尾是 U+F022(私用区码位,mojibake 残留),各工具渲染不一 —— git 显示成八进制转义、`ls -b` 印成 ASCII 引号 | **回收站**(`$R…`,2543 B,可还原) |
| `web-file-mgr-unpack 1.9.1.elf`(898 KiB) | 陷阱:文件名写 1.9.1,内嵌却是 9-07 的 **v1.9**(无 7z 引擎) | 已不在仓库根 |
> ⚠️ **清理这类特殊文件名时**:`SHFileOperationW`(带 `FOF_ALLOWUNDO` 走回收站)对含私用区码位的路径会返回 `ERROR_FILE_NOT_FOUND (2)`,**但动作实际已生效**。删完务必查 `C:\$Recycle.Bin\<SID>\$I*` 记录确认落在回收站(`$I` 存原路径 UTF-16,`$R` 是内容)。本沙箱里 `Add-Type` 与 `rm` 都被拦(后者有 safe-delete 钩子),只能用 Python `ctypes` 调 shell32。
`.build/` 下的探针/调试产物已被 `.gitignore` 白名单覆盖,不再污染 `git status`。
+25 -152
View File
@@ -13,11 +13,7 @@ ifeq ($(MAKECMDGOALS),)
endif
endif
# Bump this together with the git tag -- it is baked into the binary (the PS5
# notification and `--version` print it) AND into the output filename, so a
# stale value silently mislabels everything. Override per-build with:
# make VERSION_TAG=v1.9.2
VERSION_TAG ?= v1.9.1
VERSION_TAG := v0.2
TITLE_ID := FMGR88888
PYTHON ?= python3
STRIP ?= $(PS5_PAYLOAD_SDK)/bin/prospero-strip
@@ -26,114 +22,32 @@ HOST_CC ?= cc
HOST_STRIP ?= strip
HOST_PKG_CONFIG ?= pkg-config
# Output filename carries the version so two builds never overwrite each other
# and you can tell at a glance which ELF is on the USB stick.
BIN := web-file-mgr-$(VERSION_TAG).elf
LINUX_BIN := web-file-mgr-linux-$(VERSION_TAG)
COMMON_SRCS := src/main.c src/websrv.c src/filemgr.c src/file_response.c src/task.c src/upload.c src/download.c src/text.c src/list.c src/space.c src/version.c src/fs_util.c src/json_util.c src/path_util.c src/asset.c src/mime.c src/notify.c src/pkg_installer.c src/pkg_info.c src/extract.c src/zip_extract.c src/rar_extract.c src/zipx_volume.c src/zipx_volstream.c src/zipx_common.c src/sevenz_extract.c src/sevenz_chain.c src/sevenz_volstream.c src/sevenz_mt.c
PS5_SRCS := $(COMMON_SRCS) src/app_installer.c src/cpu_support_stub.c
BIN := web-file-mgr.elf
LEGACY_BIN := web-file-mgr-legacy.elf
LINUX_BIN := web-file-mgr-linux
COMMON_SRCS := src/main.c src/websrv.c src/filemgr.c src/asset.c src/mime.c src/notify.c
PS5_SRCS := $(COMMON_SRCS) src/app_installer.c
LINUX_SRCS := $(COMMON_SRCS)
BASE_ASSETS := $(filter-out %.dds,$(wildcard assets/*))
ifneq ($(filter linux,$(MAKECMDGOALS)),)
ASSETS := $(BASE_ASSETS)
else
ASSETS := $(filter-out assets/icon0.png,$(BASE_ASSETS))
endif
ASSETS := $(wildcard assets/*)
GEN_SRCS := $(patsubst assets/%,gen/%, $(ASSETS:=.c))
# Vendored third-party: zlib + minizip-ng (ZIP, C) and unrar 7.20.1 (RAR,
# C++). unrar sources are compiled as a static library in RARDLL mode (no
# main()); the project talks to it through the extern "C" DLL API in
# third_party/unrar7/unrar_c_api.h. Compiled with relaxed warnings (-w) —
# these are not our code and we do not want to chase upstream style updates.
#
# C++ compilers: PS5 uses prospero-clang++ (FreeBSD-style sysroot; the
# toolchain defaults to -stdlib=libc++, driver links libc++ automatically);
# host builds use the plain host C++ compiler (libstdc++).
CXX ?= $(dir $(CC))prospero-clang++
HOST_CXX ?= c++
# Source set mirrors UnRARDll.vcxproj's ClCompile list (49 files) MINUS the
# Windows-only isnt.cpp / motw.cpp (they need windows.h; the official unrar
# UNIX makefile omits them, and PS5/linux both use the _UNIX branch where
# their symbols are #ifdef'd out).
UNRAR7_SRCS := \
third_party/unrar7/archive.cpp third_party/unrar7/arcread.cpp third_party/unrar7/blake2s.cpp \
third_party/unrar7/cmddata.cpp third_party/unrar7/consio.cpp third_party/unrar7/crc.cpp \
third_party/unrar7/crypt.cpp third_party/unrar7/dll.cpp third_party/unrar7/encname.cpp \
third_party/unrar7/errhnd.cpp third_party/unrar7/extinfo.cpp third_party/unrar7/extract.cpp \
third_party/unrar7/filcreat.cpp third_party/unrar7/file.cpp third_party/unrar7/filefn.cpp \
third_party/unrar7/filestr.cpp third_party/unrar7/find.cpp third_party/unrar7/getbits.cpp \
third_party/unrar7/global.cpp third_party/unrar7/hash.cpp third_party/unrar7/headers.cpp \
third_party/unrar7/largepage.cpp third_party/unrar7/match.cpp \
third_party/unrar7/options.cpp third_party/unrar7/pathfn.cpp \
third_party/unrar7/qopen.cpp third_party/unrar7/rar.cpp third_party/unrar7/rarpch.cpp \
third_party/unrar7/rarvm.cpp third_party/unrar7/rawread.cpp third_party/unrar7/rdwrfn.cpp \
third_party/unrar7/rijndael.cpp third_party/unrar7/rs.cpp third_party/unrar7/rs16.cpp \
third_party/unrar7/scantree.cpp third_party/unrar7/secpassword.cpp third_party/unrar7/sha1.cpp \
third_party/unrar7/sha256.cpp third_party/unrar7/smallfn.cpp third_party/unrar7/strfn.cpp \
third_party/unrar7/strlist.cpp third_party/unrar7/system.cpp third_party/unrar7/threadpool.cpp \
third_party/unrar7/timefn.cpp third_party/unrar7/ui.cpp third_party/unrar7/unicode.cpp \
third_party/unrar7/unpack.cpp third_party/unrar7/volume.cpp
THIRD_PARTY_C_SRCS := $(wildcard third_party/zlib/src/*.c) $(wildcard third_party/minizip-ng/src/*.c) $(wildcard third_party/7z/*.c)
# AesOpt.c hard-codes x86 AES-NI / AVX / VAES intrinsics and guards them with
# a compiler-version check that lets clang 18 in unconditionally. The plain
# intrinsics (`_mm256_aesenc_epi128`) live behind <wmmintrin_aes.h>, which
# clang only declares after `+mvaes +mavx2` (or higher). PS5 is Zen 2 and has
# every one of these, so we just enable them for the 7z TU family instead of
# dropping AesOpt.c (Aes.c references those HW symbol names via AesGenTables).
SEVENZ_C_FLAGS := -maes -mavx2 -mvaes
THIRD_PARTY_C_FLAGS := -O2 -w -Ithird_party/zlib/include -Ithird_party/minizip-ng/include -Ithird_party/7z \
-DHAVE_ZLIB -DZLIB_COMPAT -DHAVE_UNISTD_H=1 -D_FILE_OFFSET_BITS=64 -D_LARGEFILE64_SOURCE \
-DHAVE_FSEEKO -DZ7_PPMD_SUPPORT
THIRD_PARTY_C_FLAGS_7Z := $(THIRD_PARTY_C_FLAGS) $(SEVENZ_C_FLAGS)
# Assembly-optimised LZMA decoder (optional, on when jwasm is present).
#
# LzmaDec.c carries a compile-time switch: with Z7_LZMA_DEC_OPT it calls an
# external LzmaDec_DecodeReal_3() and drops its own C implementation; without
# it, the C version is used. The asm version is measurably faster -- on a
# 330 MiB LZMA2 archive, 1.10 s vs 1.39 s, i.e. most of the gap to the
# official 7-Zip binary, which builds with this switch on.
#
# LzmaDecOpt.asm is MASM syntax, so it needs a MASM-compatible assembler
# (jwasm). That is not something we can assume the host has, so the whole
# optimisation is conditional: no jwasm, no asm, and the build still works.
# ABI_LINUX is load-bearing -- 7zAsm.asm keys its calling convention off it
# (SysV rdi/rsi/rdx vs Win64 rcx/rdx/r8); assembling without it links cleanly
# and then segfaults on the first call.
JWASM ?= jwasm
LZMA_DEC_ASM_DIR := third_party/7z/Asm/x86
LZMA_DEC_ASM_SRC := $(LZMA_DEC_ASM_DIR)/LzmaDecOpt.asm
ifneq ($(shell command -v $(JWASM) 2>/dev/null),)
LZMA_DEC_OPT_FLAG := -DZ7_LZMA_DEC_OPT
PS5_ASM_OBJS := ps5-obj/$(LZMA_DEC_ASM_DIR)/LzmaDecOpt.o
LINUX_ASM_OBJS := linux-obj/$(LZMA_DEC_ASM_DIR)/LzmaDecOpt.o
endif
UNRAR7_CXX_FLAGS := -O2 -w -std=c++17 -DRARDLL -D_FILE_OFFSET_BITS=64 -D_LARGEFILE_SOURCE
# prospero-clang++ defaults to -stdlib=libc++; state it explicitly for clarity.
UNRAR7_CXX_FLAGS_PS5 := $(UNRAR7_CXX_FLAGS) -stdlib=libc++
UNRAR7_CXX_FLAGS_HOST:= $(UNRAR7_CXX_FLAGS)
PS5_TP_OBJS := $(patsubst %.c,ps5-obj/%.o,$(THIRD_PARTY_C_SRCS)) \
$(patsubst %.cpp,ps5-obj/%.o,$(UNRAR7_SRCS))
LINUX_TP_OBJS := $(patsubst %.c,linux-obj/%.o,$(THIRD_PARTY_C_SRCS)) \
$(patsubst %.cpp,linux-obj/%.o,$(UNRAR7_SRCS))
CFLAGS := -Oz -fno-asynchronous-unwind-tables -fno-unwind-tables -Wall -Werror -ffunction-sections -fdata-sections -Isrc -Ithird_party/minizip-ng/include -Ithird_party/unrar7 -Ithird_party/7z -DVERSION_TAG=\"$(VERSION_TAG)\" -DTITLE_ID=\"$(TITLE_ID)\"
CFLAGS := -Oz -fno-asynchronous-unwind-tables -fno-unwind-tables -Wall -Werror -ffunction-sections -fdata-sections -Isrc -DVERSION_TAG=\"$(VERSION_TAG)\" -DTITLE_ID=\"$(TITLE_ID)\"
CFLAGS += `$(PKG_CONFIG) libmicrohttpd --cflags`
LDFLAGS := -Wl,--gc-sections
LEGACY_CFLAGS := $(filter-out -ffunction-sections -fdata-sections,$(CFLAGS))
LEGACY_LDFLAGS :=
LDADD := `$(PKG_CONFIG) libmicrohttpd --libs`
LDADD += -lSceIpmi -lSceAppInstUtil -lSceUserService
LINUX_CFLAGS := -O2 -flto -Wall -Werror -Isrc -Ithird_party/minizip-ng/include -Ithird_party/unrar7 -Ithird_party/7z -DVERSION_TAG=\"$(VERSION_TAG)\" -DTITLE_ID=\"$(TITLE_ID)\"
LDADD += -lSceIpmi -lSceAppInstUtil
LINUX_CFLAGS := -O2 -Wall -Werror -Isrc -DVERSION_TAG=\"$(VERSION_TAG)\" -DTITLE_ID=\"$(TITLE_ID)\"
LINUX_CFLAGS += `$(HOST_PKG_CONFIG) libmicrohttpd --cflags`
LINUX_LDADD := `$(HOST_PKG_CONFIG) libmicrohttpd --libs` -pthread
.PHONY: all linux deps linux-deps clean
.PHONY: all legacy linux deps linux-deps clean
all: deps $(BIN)
legacy: deps $(LEGACY_BIN)
linux: linux-deps $(LINUX_BIN)
deps:
@@ -147,60 +61,19 @@ gen:
mkdir gen
clean:
rm -rf $(BIN) $(LINUX_BIN) gen ps5-obj linux-obj
rm -rf $(BIN) $(LEGACY_BIN) $(LINUX_BIN) gen
gen/%.c: assets/% gen-asset-module.py | gen
gen/%.c: assets/% gen-asset-module.py gen
$(PYTHON) gen-asset-module.py --path $* $< > $@
# Only LzmaDec.c changes behaviour under the switch: it stops defining its own
# decoder and declares the external symbol instead. Everything else in the 7z
# TU family is unaffected.
ifneq ($(LZMA_DEC_OPT_FLAG),)
ps5-obj/third_party/7z/LzmaDec.o: THIRD_PARTY_C_FLAGS_7Z += $(LZMA_DEC_OPT_FLAG)
linux-obj/third_party/7z/LzmaDec.o: THIRD_PARTY_C_FLAGS_7Z += $(LZMA_DEC_OPT_FLAG)
endif
# make does not track flag changes, and installing or removing jwasm flips the
# switch above. Without this, an existing LzmaDec.o silently keeps the old
# decoder and the asm object just sits in the link line unreferenced (the
# binary comes out byte-identical, which is how the problem was noticed).
ps5-obj/third_party/7z/LzmaDec.o: Makefile
linux-obj/third_party/7z/LzmaDec.o: Makefile
ps5-obj/%.o: %.c
@mkdir -p $(dir $@)
$(CC) $(if $(findstring third_party/7z,$<),$(THIRD_PARTY_C_FLAGS_7Z),$(THIRD_PARTY_C_FLAGS)) -c -o $@ $<
linux-obj/%.o: %.c
@mkdir -p $(dir $@)
$(HOST_CC) $(if $(findstring third_party/7z,$<),$(THIRD_PARTY_C_FLAGS_7Z),$(THIRD_PARTY_C_FLAGS)) -c -o $@ $<
# The assembler emits a plain ELF64 relocatable object, which both linkers
# (prospero-clang++ for PS5, cc for linux) accept as-is.
ps5-obj/$(LZMA_DEC_ASM_DIR)/LzmaDecOpt.o: $(LZMA_DEC_ASM_SRC)
@mkdir -p $(dir $@)
$(JWASM) -elf64 -q -DABI_LINUX -I$(LZMA_DEC_ASM_DIR) -Fo$@ $<
linux-obj/$(LZMA_DEC_ASM_DIR)/LzmaDecOpt.o: $(LZMA_DEC_ASM_SRC)
@mkdir -p $(dir $@)
$(JWASM) -elf64 -q -DABI_LINUX -I$(LZMA_DEC_ASM_DIR) -Fo$@ $<
ps5-obj/%.o: %.cpp
@mkdir -p $(dir $@)
$(CXX) $(UNRAR7_CXX_FLAGS_PS5) -c -o $@ $<
linux-obj/%.o: %.cpp
@mkdir -p $(dir $@)
$(HOST_CXX) $(UNRAR7_CXX_FLAGS_HOST) -c -o $@ $<
# Link with the C++ driver so libc++ (PS5) / libstdc++ (host) is pulled in
# automatically for the unrar objects. The project's own C sources are passed
# through -x c (clang++ would otherwise compile .c files as C++ and trip
# -Wdeprecated); -x none restores extension-based handling for the .o files.
$(BIN): $(PS5_SRCS) $(GEN_SRCS) $(PS5_TP_OBJS) $(PS5_ASM_OBJS)
$(CXX) $(CFLAGS) $(LDFLAGS) -o $@ -x c $(filter %.c,$^) -x none $(PS5_TP_OBJS) $(PS5_ASM_OBJS) $(LDADD)
$(BIN): $(PS5_SRCS) $(GEN_SRCS)
$(CC) $(CFLAGS) $(LDFLAGS) -o $@ $^ $(LDADD)
$(STRIP) $@
$(LINUX_BIN): $(LINUX_SRCS) $(GEN_SRCS) $(LINUX_TP_OBJS) $(LINUX_ASM_OBJS)
$(HOST_CXX) $(LINUX_CFLAGS) -o $@ -x c $(filter %.c,$^) -x none $(LINUX_TP_OBJS) $(LINUX_ASM_OBJS) $(LINUX_LDADD)
$(LEGACY_BIN): $(PS5_SRCS) $(GEN_SRCS)
$(CC) $(LEGACY_CFLAGS) $(LEGACY_LDFLAGS) -o $@ $^ $(LDADD)
$(STRIP) $@
$(LINUX_BIN): $(LINUX_SRCS) $(GEN_SRCS)
$(HOST_CC) $(LINUX_CFLAGS) -o $@ $^ $(LINUX_LDADD)
$(HOST_STRIP) $@
+36 -411
View File
@@ -1,472 +1,97 @@
# PS5 Web File Manager
> Homebrew HTTP file manager for jailbroken PS5 consoles. Browse, edit, upload, download and extract ZIPs through any browser on the same network — single self-contained ELF payload, no external services, no telemetry.
A file manager for PS5 with a web UI. It is primarily intended for quickly and
safely copying game dump folders from USB storage to internal storage.
**Version:** v1.9 · **Title ID:** `FMGR88888` · **License:** GPLv3+ · **Target:** `x86_64-sie-ps5`
## Brief
---
## Overview
A payload ELF that runs an HTTP file manager inside a jailbroken PS5. Open `http://<PS5_IP>:8888/` from any browser on the LAN — including the PS5 browser itself — to manage files on attached USB storage and the user partition. Designed for safely copying game-dump folders from USB to internal storage, but it also handles general file management, in-place text editing, PKG preview/install, image preview, and ZIP extraction with built-in zip-bomb protection.
The same source tree builds a Linux binary for development and a PS5 payload ELF for deployment — see `make linux` below.
## What's new in v1.9
- **RAR engine replaced with the official rarlab UnRAR 7.20.1**
(`third_party/unrar7/`, replacing dmc_unrar). This is what actually
makes RAR extraction work on real files: dmc_unrar could not decode
archives written by **WinRAR 6.x/7.x** (RAR5 "v6" compression) and had
no multi-volume support — both now work.
- **RAR5 "v6" archives extract** (the v1.8-era "corrupt archive" report
on WinRAR 6/7 files is gone).
- **Multi-volume RAR** (`.part01.rar` chains): unrar stitches the parts by
name when the full set sits next to the volume you open.
- Engine can decrypt encrypted RAR (`RARSetPassword`) — password UI /
API plumbing still pending, encrypted archives are rejected for now.
- Host tests now run real archives (v6 / encrypted / 3-volume fixtures
committed under `tests/fixtures-real/`): **70 ZIP + 24 RAR = 94 checks**.
## What's new in v1.8
- **Single-volume RAR extraction** via the vendored FLOSS library
[`dmc_unrar`](https://github.com/DrMcCoy/dmc_unrar) (GPL-2.0-or-later).
RAR 1.5, 2.x, 3.x, 4.x and 5.x archives are supported. `.rar` files
appear in the file list with the **Extract** button enabled; the button
is greyed out on `.part02+.rar` sub-volumes with the tooltip "select
the main volume instead" — v1.8 cannot stitch multi-volume RARs (see
the [RAR extraction](#rar-extraction) section below).
- **Shared extraction protocol** between the new `src/rar_extract.c`
engine and the existing `src/zip_extract.c` engine: same `zipx_status_t`
codes, same `zipx_limits_t` profile (default / `large=1`), same
three-phase model (`scan → extract → publish → cleanup`), same staging
directory layout, same conflict policy, same error mapping into the
task UI. The dispatcher in `src/extract.c` is one tiny
`ends_with_ci(…)` switch.
- **14 new host-side C tests** (`tests/test_rar_extract.c`) wired into
the existing `tests/run-tests.sh`. Coverage: format dispatch, error
translation across every `DMC_UNRAR_*` code that affects RAR users,
limit-profile handoff. Total host checks: **69 ZIP + 14 RAR = 83**.
- **Documentation**: [`CHANGELOG.md`](./CHANGELOG.md),
[`docs/UPGRADE-v1.8-rar-support.md`](./docs/UPGRADE-v1.8-rar-support.md)
and the vendoring decision tree at
[`third_party/unrar/VENDORED.md`](./third_party/unrar/VENDORED.md).
- See the [dedicated section](#rar-extraction) below for scope and the
limitations that come from using dmc_unrar (no multi-volume, no
encryption in v1.8 — both lift in v1.9 when the library is replaced).
## What's new in v1.8.1
- **Default ZIP limits relaxed** (companion to v1.7's large profile).
v1.7 shipped with a 64 GiB default per-entry cap, which was too
aggressive for typical PS5 system-backup ZIPs (200-300 GiB). v1.8.1
raises the default profile to **1 TiB total / 256 GiB per entry /
500 : 1 ratio**, with the `large=1` opt-in kept at 2 TiB / 1 TiB /
1000 : 1. The frontend threshold rises from 60 GiB to 240 GiB so
common system-backup archives no longer trigger the prompt.
- RAR extraction inherits the new defaults (rar_extract.c threads
`c->limits` from the engine — no engine change required).
- Rationale: the real zip-bomb defence is `check_space()` (statvfs-based
real disk-space check before staging) + `max_ratio` (declared
compression ratio cap). The size caps are a UX guard, not a security
boundary.
## What's new in v1.8.2
- **Default ZIP limits relaxed again** for the 3A-game single-file case.
A single ~300 GiB uncompressed file inside an archive was still
silently rejected by v1.8.1 (the default scan returns
`ZIPX_ERR_LIMIT_FILE_SIZE` before the request ever reaches the
frontend confirmation prompt). v1.8.2 raises the default profile to
**2 TiB total / 512 GiB per entry / 500 : 1 ratio**, with the `large=1`
opt-in bumped to 4 TiB / 1 TiB / 1000 : 1. Frontend threshold rises
from 240 GiB to 480 GiB.
- **Two PS5-only build fixes** discovered when cross-compiling for the
PS5 target. The host-side test suite (`tests/run-tests.sh`) had
silently accepted both because it links the same sources but uses
gcc rather than clang 18 and a different include path:
- `Makefile` CFLAGS: add `-Ithird_party/unrar` so `src/rar_extract.c`
can find the project-authored `dmc_unrar_api.h` facade header.
- `src/extract.c`: move `extract_progress()` definition above
`extract_dispatch()` so the implicit function declaration is not
flagged by `-Werror=implicit-function-declaration` (clang 18 in the
PS5 SDK is stricter than the host gcc used by tests).
- **Release artifact** for v1.8.2: `web-file-mgr.elf` — 509 704 bytes,
sha256 `1b2c3d68b35e32737105f17d14a80a3c159ceca0cabd274ee168cbcd81906f65`,
ELF class 64, little-endian, e_machine `0x003e` (x86_64-sie-ps5).
- Tests: **84 host-side checks** (70 ZIP + 14 RAR), 0 failures. PS5
cross-compile succeeds end-to-end.
## What's new in v1.7
- **ZIP large-file profile** (opt-in via the new `large=1` argument on `/api/extract`): relaxed caps of **2 TiB** archive total, **1 TiB** per entry, **1000 : 1** compression ratio. The frontend prompts for confirmation whenever the archive on disk is larger than **60 GiB**; the server only activates the profile when the user explicitly agrees.
- **Stricter default ZIP profile** stays safe: **1 TiB** total / **256 GiB** per entry / **500 : 1** ratio. A 4 MiB compressed payload that expands to 800 GiB still gets rejected before any output file is opened.
- **69 host-side C tests** (`tests/run-tests.sh`) now cover path traversal, ZIP64, encryption rejection, ratios, conflict policies and the new large-file profile (`tests/test_zip_extract.c`).
- Earlier refinements — see `git log` since v1.6.
## Screenshots
<p>
<a href="docs/screenshots/20260617_231827.376.jpg" target="_blank"><img src="docs/screenshots/20260617_231827.376.jpg" width="31%" alt="PS5 Web File Manager screenshot 1"></a>
<a href="docs/screenshots/20260619_131432.399.jpg" target="_blank"><img src="docs/screenshots/20260619_131432.399.jpg" width="31%" alt="PS5 Web File Manager screenshot 2"></a>
<a href="docs/screenshots/20260617_232348.855.jpg" target="_blank"><img src="docs/screenshots/20260617_232348.855.jpg" width="31%" alt="PS5 Web File Manager screenshot 3"></a>
<a href="docs/screenshots/20260619_131811.644.jpg" target="_blank"><img src="docs/screenshots/20260619_131811.644.jpg" width="31%" alt="PS5 Web File Manager screenshot 4"></a>
<a href="docs/screenshots/20260619_131535.239.jpg" target="_blank"><img src="docs/screenshots/20260619_131535.239.jpg" width="31%" alt="PS5 Web File Manager screenshot 5"></a>
<a href="docs/screenshots/20260620_232728.533.jpg" target="_blank"><img src="docs/screenshots/20260620_232728.533.jpg" width="31%" alt="PS5 Web File Manager screenshot 6"></a>
</p>
PS5 web file manager payload. It runs an HTTP UI starting at port `8888`, installs a home screen launcher in Media catagory on startup when needed, and provides file operations from the PS5 browser. If `8888` is already in use, the payload tries the next port until one is available; the startup notification shows the actual listen port.
## Features
- **Browse** — list files and folders; sort by name, type, size, mtime or permissions. Last sort mode persists in `localStorage`.
- **Permissions** — toggle read/write/execute with checkboxes, or paste a validated four-digit octal mode.
- **Operations** — copy, move, delete (recursive, no recycle bin), rename, create files and folders.
- **Editor** — in-place UTF-8 text editor for files ≤ 1 MiB across a curated extension list: `.txt .json .xml .ini .cfg .conf .md .log .lua .js .css .html .htm .c .h .cpp .hpp .sh .csv .yaml .yml .shn`.
- **Multi-select** — copy, move, delete or tar-download many items in one go.
- **Upload** — single files or folder trees from any device on the LAN (hidden in the PS5 browser). Atomic temp + rename.
- **Download** — single file as raw bytes, or folders/multi-select as a streaming `.tar`. Hidden in the PS5 browser.
- **Tasks** — full-screen overlay with delayed show, live progress, throughput, ETA, cancel, and recovery if the browser is closed and reopened mid-task.
- **Archive extraction** — ZIP (encrypted rejected) and RAR (v1.9: RAR4 + RAR5 incl. WinRAR 6/7 "v6", multi-volume; encrypted still rejected pending password UI); see the [ZIP extraction](#zip-extraction) and [RAR extraction](#rar-extraction) sections below for scope.
- **PKG** — install and preview `.pkg` files.
- **Images** — preview `.png .jpg .jpeg .gif .bmp .webp`.
- **Localization** — English + Simplified Chinese, auto-selected from `navigator.languages`.
- **Mobile-friendly** — responsive layout with wrapped toolbars and horizontally scrollable file lists.
## Quickstart
1. **Build** the ELF:
```sh
export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdk # see "Build" for SDK setup
make
```
2. **Send** the payload to the PS5 (default ELF-loader port `9021`):
```sh
nc -q0 "$PS5_HOST" 9021 < web-file-mgr.elf
```
3. **Read** the on-screen PS5 notification — it prints the actual listen port (default `8888`).
4. **Open** `http://<PS5_IP>:<port>/` in any browser on the same LAN — the PS5 browser works too.
5. On first run, the payload also writes a **Media**-category home-screen launcher; existing launcher files are not overwritten.
- List files and folders.
- Copy, move, delete, rename, and create folders.
- Multi-select operations.
- Copy/move by choosing sources first, then pasting or moving them into the current folder.
- Conflict prompts for overwriting files and merging folders.
- Full-screen task overlay with progress, speed, ETA, cancel support, and task recovery after reopening the browser while the payload process is still running.
- Copied/moved files and folders are set to `0777` where the filesystem supports Unix permissions. FAT/exFAT-style filesystems may ignore chmod.
- Chinese and English UI. The browser language is read from `navigator.languages` / `navigator.language`; Chinese uses `zh`, everything else uses English.
- Startup notification showing the app name, version, and listen port.
## Build
Requires [ps5-payload-dev/sdk](https://github.com/ps5-payload-dev/sdk#quick-start):
It depends on PS5 payload SDK first: [ps5-payload-dev/sdk](https://github.com/ps5-payload-dev/sdk#quick-start)
```sh
export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdk
```
This project links against `libmicrohttpd`. `make` checks for it before building and runs the installer automatically when missing:
This project links against `libmicrohttpd`. `make` checks for it before building and runs the installer script automatically if it is missing:
```sh
make
```
If the build host has no network access, drop the libmicrohttpd tarball in advance and run the installer manually:
If the build host has no network access, download the libmicrohttpd source tarball yourself and run the dependency installer once:
```sh
LIBMICROHTTPD_TARBALL=/path/to/libmicrohttpd-1.0.1.tar.gz \
./install-libmicrohttpd.sh
```
Then build again:
```sh
make
```
Output:
The output is:
```text
web-file-mgr.elf (~several hundred KiB, larger in v1.9 with unrar; x86_64-sie-ps5)
web-file-mgr.elf
```
For pure UI/JS work without the PS5 toolchain:
```sh
make linux
./web-file-mgr-linux
```
The Linux build does **not** include the PS5 home-screen launcher installer.
## Usage
Start an ELF loader on the PS5 (port `9021` is common). Send the payload:
Start an ELF loader on the PS5. The common listener port is `9021`.
Send the built payload with netcat or NetCat GUI:
```sh
export PS5_HOST=ps5_ip_address
nc -q0 "$PS5_HOST" 9021 < web-file-mgr.elf
```
After the payload starts, the PS5 notification shows the app name, version and actual listen port. Open the URL it prints, for example:
After the payload starts, the PS5 notification shows the app name, version, and actual listen port. Open the shown URL in the PS5 browser, for example:
```text
http://${PS5_IP_ADDRESS}:8888/
```
If the payload had to fall back to a different port (e.g. `8889`), use whatever port the notification shows — the URL is not hard-coded.
On first startup, the payload installs a `PS5 Web File Manager` shortcut in the Media category when needed. Existing launcher files are preserved; only missing ones are written.
## ZIP extraction
Plain ZIPs only — stored / deflated / ZIP64, **never encrypted**. The engine is a standalone three-phase module (`scan → extract → publish → cleanup`) at `src/zip_extract.{c,h}`, with a separate host-side C test suite. Each entry is first written into a staging directory (`*.wfm-part-*`), fsynced, then atomically renamed into the destination. Any failure mid-archive rolls back partial changes; cancel and fatal errors always clean up staging.
### Limits
| Limit | Default profile | Large profile (`ZIPX_LIMITS_LARGE`) |
|---|---|---|
| `max_entries` | 200 000 | 500 000 |
| `max_total_bytes` (uncompressed) | 2 TiB | 4 TiB |
| `max_file_bytes` (per entry) | 512 GiB | 1 TiB |
| `max_ratio` (uncompressed / compressed) | 500 : 1 | 1000 : 1 |
| `max_depth` (folder nesting) | 32 | 32 |
| `max_name_len` / `max_path_len` | 255 / 1024 | 255 / 1024 |
The **default profile** is shipped safe: a 4 MiB compressed blob that decodes to 800 GiB is rejected before any output file is opened. The **large profile** is engaged **only** when the request includes `large=1` — the archive dialog prompts the user automatically whenever the archive on disk is larger than `LARGE_FILE_THRESHOLD_BYTES` (480 GiB by default; configurable in `assets/main.js`). Confirming the prompt is the user's explicit opt-in; the server still records nothing extra on its own.
### Security checks
The engine refuses to extract:
- Encrypted entries (any encryption flag set).
- Path traversal (`..` segments, absolute POSIX paths, Windows drive letters).
- Symbolic links, devices, FIFOs, sockets (`ZIPX_ERR_SPECIAL`).
- Duplicate entries or directory/file name clashes inside the same archive.
- Archives whose expanded size, entry count, depth, name length or compression ratio breach the active profile.
### Conflict policy
Passed as `conflict=` on `/api/extract`:
- `fail` (default) — refuse to overwrite any existing target.
- `overwrite` — replace existing files; merge into existing folders.
- `merge` — keep existing files, add new ones.
### Tuning the threshold
The 480 GiB frontend threshold lives in `assets/main.js`:
```js
const LARGE_FILE_THRESHOLD_BYTES = 480 * 1024 * 1024 * 1024;
```
Set it to `Infinity` to silence the prompt, lower it to be more conservative, or remove the call entirely — the server still respects `large=1` regardless of the threshold.
## RAR extraction
A RAR extraction engine (`src/rar_extract.{c,h}`) backed by the **official
rarlab UnRAR source** (`third_party/unrar7/`, version 7.20.1, compiled as a
static library and driven through its C-compatible DLL API). Files with the
extension `.rar` get the same **Extract** button as `.zip` files; the engine
is dispatched by `src/extract.c` based on extension.
> v1.9 replaced the v1.8 engine (dmc_unrar 1.7.0). dmc_unrar could not
> decode archives written by WinRAR 6.x/7.x (RAR5 "v6" compression) and had
> no multi-volume support; unrar handles both natively.
### Scope
| Format | Support | Notes |
|---|---|---|
| RAR 1.5 → 4.x (incl. 2.9 / 3.6 / 4.0) | ✅ | |
| RAR 5.0 and **5.0 "v6"** (WinRAR 6.x / 7.x) | ✅ | The v1.9 trigger |
| Solid blocks, dictionary up to 1 GiB | ✅ | |
| PPMd decompression (RAR 3.0+) | ✅ | |
| **Multi-volume** (`.part01.rar` + `.part02.rar` + …) | ✅ | unrar stitches parts by name when the whole set sits next to the volume you open. Select the first volume (`name.part1.rar` / `name.part01.rar`); non-first volumes are still greyed out in the UI with a hint. |
| **Encrypted RAR** | ⏳ | The engine can decrypt (`RARSetPassword`), but the password field / prompt is not wired into `/api/extract` yet. Encrypted archives are rejected up front with `ZIPX_ERR_UNSUPPORTED`. |
| Symbolic links / FIFOs / sockets / devices | ❌ | Rejected with `ZIPX_ERR_SPECIAL` (mirrors ZIP behaviour) |
| RAR 1.3 (pre-1.4) | ❌ | Rejected upstream by unrar |
When an archive is rejected, the user gets an `extract_unsupported`
failure with the file name as the detail argument. The frontend already
shows this with the typical bilingual retry guidance.
### Limits
The RAR engine re-uses the ZIP limits table verbatim — there is no RAR
profile table on top. Defaults and the `large=1` opt-in are identical:
| Limit | Default profile | Large profile (`large=1`) |
|---|---|---|
| `max_entries` | 200 000 | 500 000 |
| `max_total_bytes` (uncompressed) | 2 TiB | 4 TiB |
| `max_file_bytes` (per entry) | 512 GiB | 1 TiB |
| `max_ratio` (uncompressed / compressed) | 500 : 1 | 1000 : 1 |
| `max_depth` (folder nesting) | 32 | 32 |
| `max_name_len` / `max_path_len` | 255 / 1024 | 255 / 1024 |
Large-profile RAR extraction uses the same `LARGE_FILE_THRESHOLD_BYTES`
(480 GiB) prompt as ZIP — the frontend treats `.rar` and `.zip` the same
way for the prompt, and the server only ever activates the large caps
when the request carries `large=1` (opt-in).
### Security checks
The RAR engine applies the same checks as the ZIP engine — re-uses
`zipx_status_t` codes, so the task UI's `err_extract_unsafe_name`,
`err_extract_too_deep`, `err_extract_ratio`, etc. all fire identically:
- Path traversal (`..` segments, absolute POSIX paths, Windows drive
letters, `\` treated as a path separator after a `Rar!\x1a\x07…`
header, etc.).
- Symbolic links, FIFOs, sockets, devices.
- Duplicate entries or directory/file name clashes inside the archive.
- Archive size, entry count, depth, name length or compression ratio
breaches of the active profile.
### Vendoring and licence
`third_party/unrar7/` is a verbatim copy of the official **rarlab UnRAR
source** (7.20.1), mirrored by
[`opello/unrar`](https://github.com/opello/unrar) at commit `97e1780`. It is
distributed under the **UnRAR freeware licence** (see
`third_party/unrar7/license.txt`): it may be used in any software to handle
RAR archives, but may not be used to develop a RAR-compatible *archiver* or
re-create the RAR compression algorithm. The project-authored facade
`third_party/unrar7/unrar_c_api.h` carries the project's own licence.
> The v1.8 engine `third_party/unrar/dmc_unrar.c` (DrMcCoy/dmc_unrar 1.7.0,
> GPL-2.0-or-later) was removed in v1.9; its notice lives in git history.
### Encrypted RAR (planned)
The engine can decrypt archives (via `RARSetPassword`), but the password
channel — a `password=` field on `/api/extract` plus a frontend prompt —
is not wired yet. Encrypted archives currently fail with
`extract_unsupported`. The engine swap (v1.9) removed the hard engine
limits; the remaining work is purely API/UI plumbing.
## Verification
After `make`, sanity-check the produced ELF:
```sh
ls -la web-file-mgr.elf # size grew in v1.9 (unrar static library); ~509 KiB was v1.8.3
sha256sum web-file-mgr.elf # record the digest in your release notes
file web-file-mgr.elf # expect "ELF 64-bit LSB pie executable, x86-64"
od -An -tx1 -N20 web-file-mgr.elf | head -2 # magic 7f45 4c46 0201 + e_machine 003e
```
The `e_machine = 0x003e` confirms the PS5 target triple `x86_64-sie-ps5`. The `e_type = 3` (`ET_DYN`) confirms the position-independent payload expected by ELF loaders.
## Tests
A POSIX/host-side C test suite covers the ZIP engine and runs on any Linux / macOS / MSYS shell without the PS5 SDK:
```sh
cd tests && bash run-tests.sh
```
Output is a per-case `check`-style report — **84 checks** on the current `main`
(70 ZIP + 14 RAR). Coverage:
- ZIP entry parsing (stored + deflated + ZIP64)
- Path traversal, absolute paths, backslash, Windows drive letters
- Symbolic links, FIFOs, encrypted entries, bad CRC, truncated archives, non-ZIP files
- Limits: `entries`, `total_bytes`, `file_bytes`, `ratio`, `depth`, `name_len`
- Conflict policies: `fail` / `overwrite` / `merge`
- Cancellation in every phase
- **Large-file profile** — `medium_bomb.zip` (ratio ≈ 238) is rejected under default caps and accepted under large caps; lowered large caps still enforce.
- **RAR engine** (`tests/test_rar_extract.c`, 14 checks) — format
dispatch (renamed ZIP rejected, junk blob rejected), error translation
across every reachable `DMC_UNRAR_*` code, limits handoff (the
`large=1` opt-in flows into `rar_extract()` unchanged).
## Project layout
```
.
├── Makefile # PS5 + Linux builds (VERSION_TAG v1.8.2)
├── install-libmicrohttpd.sh # one-shot dependency installer
├── gen-asset-module.py # embeds assets/* as gzip-compressed C arrays
├── assets/ # HTML / CSS / JS / icons / param.json
├── src/ # C payload sources
│ ├── main.c websrv.c filemgr.c # entry, HTTP frontend, task model
│ ├── upload.c download.c # stream handlers
│ ├── extract.c # /api/extract dispatcher (ZIP + RAR)
│ ├── zip_extract.{c,h} # ZIP engine (v1.7)
│ ├── rar_extract.{c,h} # RAR engine (v1.8, dmc_unrar backend)
│ └── app_installer.c # PS5 Media launcher installer
├── third_party/ # vendored: zlib, minizip-ng, dmc_unrar
│ └── unrar/
│ ├── dmc_unrar.c # GPL-2.0-or-later, verbatim upstream
│ └── dmc_unrar_api.h # project-authored facade header
├── tests/ # POSIX/host test suite
│ ├── test_zip_extract.c
│ ├── test_rar_extract.c # 14 RAR negative-path checks (v1.8)
│ ├── make_fixtures.py # regenerate test fixtures
│ ├── run-tests.sh # one-shot runner (now runs ZIP + RAR suites)
│ ├── compat/ # tiny Win32/MSYS shims
│ └── fixtures/ # generated test ZIPs (and a couple of stub .rar blobs)
├── docs/
│ ├── HANDOVER.md # engineering handover / dev playbook (also §14 v1.8 close-out)
│ ├── UPGRADE-v1.7-zip-large-file-profile.md
│ ├── UPGRADE-v1.8-rar-support.md
│ └── screenshots/ # README screenshot images
├── THIRD_PARTY_NOTICES # bundled-library credits (incl. dmc_unrar section)
├── LICENSE # GPLv3+
└── README.md
```
On first startup the payload installs a `PS5 Web File Manager` web shortcut in the Media category when needed. If the payload had to use a fallback port such as `8889`, use the port shown in the startup notification.
## Notes
- Copy, move, delete, upload and download run as single background tasks. While one task is running, other file operations are rejected.
- Copy, move, and delete run as single background tasks. While one task is running, other file operations are rejected.
- Delete is recursive and permanent. There is no recycle bin.
- Copy/move tasks can be canceled. A partially copied single file is removed, but partially copied folders are left in place to avoid deleting pre-existing files when merging into an existing target folder.
- Upload tasks can be canceled. A partially uploaded temporary file is removed when possible.
- Downloading a folder or multiple selected items produces a tar stream. The tar archive is generated by the payload and is not written to PS5 storage first.
- Copy/move tasks can be canceled. A partially copied single file is removed, but partially copied folders are left in place to avoid deleting existing files when merging into an existing target folder.
- The UI can recover the active task display if the browser is closed and reopened while the payload process is still running.
- Text editing is limited to the curated extension list above. Non-UTF-8 and oversized files are rejected.
- File names are transmitted as UTF-8 through the web API. The payload also preserves legacy byte-oriented names returned by mounted filesystems so mixed USB filename encodings still display and operate correctly.
## FAQ
- **This is a homebrew app and should not intentionally modify system processes or kernel memory.** If you hit a kernel panic, make sure you are using a recent jailbreak method and ELF loader, or revert to the stable method you normally use.
- **P2JB users** — if this payload triggers a kernel panic, avoid using it on that setup. Stability matters more than convenience when each retry is expensive.
- **The preparing stage can take a while** when a folder contains many files — it sums folder size and checks free space, which helps avoid starting a copy / move / upload / download that cannot finish safely.
- **`err_extract_entry_too_large`** — default archive caps are 512 GiB per
entry / 500:1 ratio (covers a typical 3A-game archive with one ~300 GiB
uncompressed file). If you exceed the default, confirm the large-file
prompt (appears for archives > 480 GiB on disk), split the archive, or
pass `large=1` directly to the API.
- **`err_extract_unsupported`** — the archive uses a feature the engine
cannot handle: encrypted ZIP, encrypted RAR, multi-volume RAR
(`.part02+.rar`), very-old RAR 1.4, RAR symlinks / FIFOs, or a file
that is neither `.zip` nor `.rar`. For RAR specifically the message
lists the failure cause and points the user back to a PC extractor.
## Credits
This project was built with reference to these projects:
- **[ps5-payload-dev/websrv](https://github.com/ps5-payload-dev/websrv):** HTTP server structure, static asset embedding ideas, PS5 browser/websrv behaviour and PKG install function. License: GPLv3+.
- **[ps5-payload-dev/ftpsrv](https://github.com/ps5-payload-dev/ftpsrv):** PS5 payload conventions, home-screen launcher/install flow reference, process handling style and startup installation reference. License: GPLv3+.
- **[seregonwar/zftpd](https://github.com/seregonwar/zftpd):** PS5 TCP socket buffer tuning and high-throughput transfer behaviour reference. License: MIT.
- **[itsPLK/ps5-payload-manager](https://github.com/itsPLK/ps5-payload-manager):** Payload building behaviour. License: GPLv3.
- **[libmicrohttpd](https://ftp.gnu.org/gnu/libmicrohttpd/):** Used as the embedded HTTP server library. Licensed by GNU under the LGPL; this payload links it as the SDK-provided static library.
- **[ps5-payload-dev/websrv](https://github.com/ps5-payload-dev/websrv):** HTTP server structure, static asset embedding ideas, and PS5 browser/websrv behavior. License: GPLv3+.
- **[ps5-payload-dev/ftpsrv](https://github.com/ps5-payload-dev/ftpsrv):** PS5 payload conventions, home screen launcher/install flow reference, process handling style and startup installation reference. License: GPLv3+.
- **[itsPLK/ps5-payload-manager](https://github.com/itsPLK/ps5-payload-manager):** Payload building behavior. License: GPLv3.
- **[libmicrohttpd](https://ftp.gnu.org/gnu/libmicrohttpd/):** Used as the embedded HTTP server library. It is licensed by GNU under the LGPL; this payload links it as the SDK-provided static library.
- **[ps5-payload-dev/sdk](https://github.com/ps5-payload-dev/sdk):** Payload building foundation. License: GPLv3+.
- **[etaHEN](https://github.com/etaHEN/etaHEN):** ShellUI URI navigation used to return to the PS5 home screen before exit. License: GPLv3.
- **[ezremote](https://github.com/cy33hc/ps5-ezremote-client):** Preview PKG info. License: GPLv2.
- **[zlib-ng/minizip-ng](https://github.com/zlib-ng/minizip-ng):** ZIP reader used by the `/api/extract` endpoint. Vendored under `third_party/minizip-ng/`. License: zlib.
- **[zlib](https://www.zlib.net/):** Compression backend for minizip-ng. Vendored under `third_party/zlib/`. License: zlib.
- **[DrMcCoy/dmc_unrar](https://github.com/DrMcCoy/dmc_unrar):** RAR reader used by the `/api/extract` endpoint. Vendored under `third_party/unrar/` as a single-file drop-in (`dmc_unrar.c`); the project-authored facade `dmc_unrar_api.h` carries the project's own licence. License: GPL-2.0-or-later — see `third_party/unrar/COPYING`.
## License
The project is distributed under **GPLv3 or later**, matching the GPLv3+ projects used as implementation references. See [`LICENSE`](./LICENSE).
The project is distributed under GPLv3 or later, matching the GPLv3+ projects used as implementation references. See `LICENSE`.
Third-party projects retain their own licenses. Do not copy assets or source from the credited projects into another distribution without preserving the corresponding license notices.
If distributing binaries, comply with the LGPL terms for `libmicrohttpd`
in addition to this project's GPL license. The vendored `zlib` and
`minizip-ng` sources are distributed under the zlib license; retain the
copyright notices in `third_party/zlib/LICENSE` and
`third_party/minizip-ng/LICENSE` when redistributing binaries built
with this feature. The vendored `dmc_unrar` (RAR engine) is distributed
under the GPL-2.0-or-later; retain the copyright notice in
`third_party/unrar/COPYING` and ship the corresponding sources when
redistributing binaries built with v1.8 or later (the `web-file-mgr.elf`
binary is already GPLv3+, so the additional source-disclosure
requirement is the only practical effect).
## Disclaimer
Unofficial homebrew software. Runs only on jailbroken PS5 consoles. Use at your own risk — the authors are not responsible for damage, data loss, account action or warranty impact. Do not redistribute Sony-proprietary content. Under GPLv3+, modified redistributions must publish their sources.
If distributing binaries, comply with the LGPL terms for libmicrohttpd in addition to this project's GPL license.
-412
View File
@@ -1,412 +0,0 @@
# PS5 网页文件管理器(PS5 Web File Manager)
> 面向已越狱 PS5 主机的自制 HTTP 文件管理器。通过同一局域网内的任意浏览器(包括 PS5 自带浏览器)即可浏览、编辑、上传、下载并解压 ZIP / RAR / 7z 压缩包——单个自包含 ELF 载荷,无外部服务、无遥测上报。
**版本:** v1.9.1 · **标题 ID:** `FMGR88888` · **许可证:** GPLv3+ · **目标平台:** `x86_64-sie-ps5`
---
## 概述
一个在已越狱 PS5 上运行的 HTTP 文件管理器载荷。从局域网内任意浏览器(含 PS5 浏览器本身)打开 `http://<PS5_IP>:8888/`,即可管理外接 USB 存储与用户分区的文件。设计初衷是安全地把游戏 dump 文件夹从 USB 拷贝到内置存储,但它同时也支持常规文件管理、原地文本编辑、PKG 预览/安装、图片预览,以及内置防 zip 炸弹保护的解压功能。
同一套源码树可构建出供开发用的 Linux 二进制,以及供部署的 PS5 载荷 ELF——见下方 `make linux`。
## v1.9.1 新增内容
- **7z 解压引擎**(`src/sevenz_extract.{c,h}`):自研解码子集 + 拉式 codec 链(`src/sevenz_chain.c`,覆盖 LZMA2 / BCJ2 等),由 `src/extract.c` 按扩展名分派,与 ZIP / RAR 共用同一套三阶段模型与限额档位。`.7z` 文件在文件列表中同样带「解压」按钮。
- **7zAES 内容解密**(AES-256-CBC):引擎层可解密带密码的 7z 内容;密码输入 UI / API 通道尚未接入,目前加密归档仍被拒绝。
- **7z 分卷**:`.7z.001` / `.z01` 等链式分卷由 `src/sevenz_volstream.c` 按名拼接,打开首个分卷即可。
- **性能三项**(纯解码提速,不影响功能面):
- SDK 汇编 LZMA 解码器(`Asm/x86/LzmaDecOpt.asm` + jwasm,无 jwasm 自动回退纯 C)≈ 1.26×。
- 纯 LZMA2 文件夹多线程解码(`src/sevenz_mt.c` + `Lzma2DecMt`,8 线程)≈ 1.37×。
- 移除 ZIP 逐条目 fsync,减少 staging 重命名前的写盘开销。
- **唯一缺口**:7z `-mhe=on` 加密头(独立单元,读取需自研头解析器),其余 7z 特性均已支持。
## v1.9 新增内容
- **RAR 引擎替换为官方 rarlab UnRAR 7.20.1**(`third_party/unrar7/`,取代 dmc_unrar)。这正是让 RAR 解压在真实文件上可用的一步:dmc_unrar 无法解码 **WinRAR 6.x/7.x** 写出的归档(RAR5「v6」压缩),也不支持多卷;两者现在都能工作。
- **RAR5「v6」归档可解压**(v1.8 时代在 WinRAR 6/7 文件上报「归档损坏」的问题已消失)。
- **多卷 RAR**(`.part01.rar` 链):当完整卷集与被打开的卷放在同一目录时,unrar 按文件名拼接各部分。
- 引擎可解密加密 RAR(`RARSetPassword`)——密码 UI / API 接线仍未完成,加密归档暂时被拒绝。
- 主机测试现用真实归档(v6 / 加密 / 3 卷 fixture,提交于 `tests/fixtures-real/`):**70 ZIP + 24 RAR = 94 项检查**。
## v1.8 新增内容
- **单卷 RAR 解压**,基于内置的 FLOSS 库 [`dmc_unrar`](https://github.com/DrMcCoy/dmc_unrar)(GPL-2.0-or-later)。支持 RAR 1.5、2.x、3.x、4.x、5.x 归档。`.rar` 文件出现在文件列表中且「解压」按钮可用;`.part02+.rar` 子卷上的按钮置灰,提示「请选择主卷」——v1.8 无法拼接多卷 RAR(见下方 [RAR 解压](#rar-解压) 章节)。
- 新引擎 `src/rar_extract.c` 与既有 `src/zip_extract.c` 之间**共享解压协议**:相同的 `zipx_status_t` 状态码、相同的 `zipx_limits_t` 档位(默认 / `large=1`)、相同的三阶段模型(`scan → extract → publish → cleanup`)、相同的 staging 目录布局、相同的冲突策略、相同的错误映射到任务 UI。`src/extract.c` 中的分派器只是一个微小的 `ends_with_ci(…)` 判断。
- **14 个新增主机端 C 测试**(`tests/test_rar_extract.c`)接入现有 `tests/run-tests.sh`。覆盖:格式分派、每个影响 RAR 用户的 `DMC_UNRAR_*` 错误码翻译、限额档位交接。主机检查总数:**69 ZIP + 14 RAR = 83**。
- **文档**:[`CHANGELOG.md`](./CHANGELOG.md)、[`docs/UPGRADE-v1.8-rar-support.md`](./docs/UPGRADE-v1.8-rar-support.md),以及 `third_party/unrar/VENDORED.md` 中的 vendoring 决策树。
## v1.8.1 新增内容
- **放宽默认 ZIP 限额**(配合 v1.7 的大档案档位)。v1.7 默认单条目上限为 64 GiB,对典型 PS5 系统备份 ZIP(200–300 GiB)过于激进。v1.8.1 将默认档位提高到 **总量 1 TiB / 单条目 256 GiB / 500:1 比率**,保留 `large=1` 选项为 2 TiB / 1 TiB / 1000:1。前端阈值从 60 GiB 提升到 240 GiB,使常见系统备份归档不再触发确认提示。
- RAR 解压继承这些新默认值(`rar_extract.c` 直接从引擎透传 `c->limits`,无需改引擎)。
- 理由:真正的防 zip 炸弹防线是 `check_space()`(staging 前基于 statvfs 的真实磁盘空间检查)+ `max_ratio`(声明的压缩比上限)。尺寸上限只是 UX 护栏,而非安全边界。
## v1.8.2 新增内容
- **再次放宽默认 ZIP 限额**,针对 3A 游戏单文件场景。v1.8.1 仍会静默拒绝归档内单个约 300 GiB 的未压缩文件(默认扫描在请求到达前端确认提示之前就返回 `ZIPX_ERR_LIMIT_FILE_SIZE`)。v1.8.2 将默认档位提高到 **总量 2 TiB / 单条目 512 GiB / 500:1 比率**,`large=1` 选件提到 4 TiB / 1 TiB / 1000:1。前端阈值从 240 GiB 提升到 480 GiB。
- **两个 PS5 专属构建修复**,在交叉编译 PS5 目标时发现。主机端测试套件(`tests/run-tests.sh`)曾静默接受二者,因为它链接相同源码但使用 gcc 而非 clang 18,且包含路径不同:
- `Makefile` CFLAGS:加入 `-Ithird_party/unrar`,使 `src/rar_extract.c` 能找到项目自有的 `dmc_unrar_api.h` 门面头文件。
- `src/extract.c`:把 `extract_progress()` 定义移到 `extract_dispatch()` 之前,避免被 `-Werror=implicit-function-declaration` 标记(PS5 SDK 的 clang 18 比测试用的主机 gcc 更严格)。
- v1.8.2 发布产物:`web-file-mgr.elf` —— 509 704 字节,sha256 `1b2c3d68b35e32737105f17d14a80a3c159ceca0cabd274ee168cbcd81906f65`,ELF 64 位小端,e_machine `0x003e`(x86_64-sie-ps5)。
- 测试:**84 项主机端检查**(70 ZIP + 14 RAR),0 失败。PS5 交叉编译端到端成功。
## v1.7 新增内容
- **ZIP 大文件档位**(通过在 `/api/extract` 传入新的 `large=1` 参数选配启用):放宽的限额为 **总量 2 TiB** / **单条目 1 TiB** / **1000:1 压缩比**。当磁盘上归档大于 **60 GiB** 时前端会提示确认;仅当用户明确同意时服务器才启用该档位。
- **更严格的默认 ZIP 档位**保持安全:**总量 1 TiB** / **单条目 256 GiB** / **500:1 比率**。一个 4 MiB 压缩包解压到 800 GiB 仍会在打开任何输出文件之前被拒绝。
- **69 项主机端 C 测试**(`tests/run-tests.sh`)现已覆盖路径穿越、ZIP64、加密拒绝、压缩比、冲突策略与新增大文件档位(`tests/test_zip_extract.c`)。
- 更早的细化——见 v1.6 以来的 `git log`。
## 截图
<p>
<a href="docs/screenshots/20260617_231827.376.jpg" target="_blank"><img src="docs/screenshots/20260617_231827.376.jpg" width="31%" alt="PS5 网页文件管理器截图 1"></a>
<a href="docs/screenshots/20260619_131432.399.jpg" target="_blank"><img src="docs/screenshots/20260619_131432.399.jpg" width="31%" alt="PS5 网页文件管理器截图 2"></a>
<a href="docs/screenshots/20260617_232348.855.jpg" target="_blank"><img src="docs/screenshots/20260617_232348.855.jpg" width="31%" alt="PS5 网页文件管理器截图 3"></a>
<a href="docs/screenshots/20260619_131811.644.jpg" target="_blank"><img src="docs/screenshots/20260619_131811.644.jpg" width="31%" alt="PS5 网页文件管理器截图 4"></a>
<a href="docs/screenshots/20260619_131535.239.jpg" target="_blank"><img src="docs/screenshots/20260619_131535.239.jpg" width="31%" alt="PS5 网页文件管理器截图 5"></a>
<a href="docs/screenshots/20260620_232728.533.jpg" target="_blank"><img src="docs/screenshots/20260620_232728.533.jpg" width="31%" alt="PS5 网页文件管理器截图 6"></a>
</p>
## 功能
- **浏览** —— 列出文件与文件夹;按名称、类型、大小、修改时间或权限排序。上次排序方式持久化在 `localStorage`。
- **权限** —— 用复选框切换读/写/执行,或粘贴经过校验的四位八进制模式。
- **操作** —— 复制、移动、删除(递归、无回收站)、重命名、创建文件与文件夹。
- **编辑器** —— 针对 ≤ 1 MiB 的文件,跨精选扩展名列表的原地 UTF-8 文本编辑器:`.txt .json .xml .ini .cfg .conf .md .log .lua .js .css .html .htm .c .h .cpp .hpp .sh .csv .yaml .yml .shn`。
- **多选** —— 一次性复制、移动、删除或打包下载多个项目。
- **上传** —— 从局域网内任意设备上传单文件或文件夹树(在 PS5 浏览器中隐藏)。原子化的临时文件 + 重命名。
- **下载** —— 单文件以原始字节下载,或文件夹/多选以流式 `.tar` 下载。在 PS5 浏览器中隐藏。
- **任务** —— 全屏覆盖层,带延迟显示、实时进度、吞吐率、ETA、取消,以及浏览器中途关闭重开后的恢复能力。
- **归档解压** —— ZIP(加密拒绝)、RAR(v1.9:RAR4 + RAR5 含 WinRAR 6/7「v6」、多卷;加密仍拒绝,待密码 UI 接入)、7z(v1.9.1:LZMA2 / BCJ2 / 分卷 / 内容加密;`-mhe=on` 加密头除外)。详见下方 [ZIP 解压](#zip-解压)、[RAR 解压](#rar-解压)、[7z 解压](#7z-解压)。
- **PKG** —— 安装并预览 `.pkg` 文件。
- **图片** —— 预览 `.png .jpg .jpeg .gif .bmp .webp`。
- **本地化** —— 英文 + 简体中文,根据 `navigator.languages` 自动选择。
- **移动端友好** —— 响应式布局,工具栏自动换行,文件列表可横向滚动。
## 快速上手
1. **构建** ELF:
```sh
export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdk # 见「构建」章节的 SDK 配置
make
```
2. **发送** 载荷到 PS5(默认 ELF 加载器端口 `9021`):
```sh
nc -q0 "$PS5_HOST" 9021 < web-file-mgr.elf
```
3. **读取** PS5 屏幕上的通知——它会打印实际监听端口(默认 `8888`)。
4. 在**同一局域网**内的任意浏览器中打开 `http://<PS5_IP>:<port>/`——PS5 浏览器也可以。
5. 首次运行时,载荷还会写入一个 **Media** 分类的主屏启动器;已有的启动器文件不会被覆盖。
## 构建
需要 [ps5-payload-dev/sdk](https://github.com/ps5-payload-dev/sdk#quick-start):
```sh
export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdk
```
本项目链接 `libmicrohttpd`。`make` 在构建前会检查它,缺失时自动运行安装器:
```sh
make
```
若构建主机无网络访问,可提前放入 libmicrohttpd 源码包并手动运行安装器:
```sh
LIBMICROHTTPD_TARBALL=/path/to/libmicrohttpd-1.0.1.tar.gz \
./install-libmicrohttpd.sh
make
```
输出:
```text
web-file-mgr.elf (约数百 KiB,v1.9.1 含 unrar7 + 7z 后更大;x86_64-sie-ps5)
```
若只想做纯 UI/JS 开发而不需要 PS5 工具链:
```sh
make linux
./web-file-mgr-linux
```
Linux 构建**不包含** PS5 主屏启动器安装器。
## 使用
在 PS5 上启动一个 ELF 加载器(端口 `9021` 常见)。发送载荷:
```sh
export PS5_HOST=ps5_ip_address
nc -q0 "$PS5_HOST" 9021 < web-file-mgr.elf
```
载荷启动后,PS5 通知会显示应用名、版本与实际监听端口。打开它打印的 URL,例如:
```text
http://${PS5_IP_ADDRESS}:8888/
```
若载荷不得不回退到其它端口(如 `8889`),请以通知显示的端口为准——URL 并未硬编码。
首次启动时,载荷会在需要时于 Media 分类安装一个 `PS5 Web File Manager` 快捷方式。已有的启动器文件会被保留;只补写缺失的文件。
## ZIP 解压
仅支持普通 ZIP——stored / deflated / ZIP64,**绝不解密**。引擎是一个独立的三阶段模块(`scan → extract → publish → cleanup`),位于 `src/zip_extract.{c,h}`,配有独立的主机端 C 测试套件。每个条目先写入 staging 目录(`*.wfm-part-*`),fsync 后原子重命名到目标位置。归档中途任何失败都会回滚部分改动;取消与致命错误总会清理 staging。
### 限额
| 限额 | 默认档位 | 大档案档位(`ZIPX_LIMITS_LARGE`) |
|---|---|---|
| `max_entries` | 200 000 | 500 000 |
| `max_total_bytes`(未压缩) | 2 TiB | 4 TiB |
| `max_file_bytes`(单条目) | 512 GiB | 1 TiB |
| `max_ratio`(未压缩 / 压缩) | 500 : 1 | 1000 : 1 |
| `max_depth`(文件夹嵌套) | 32 | 32 |
| `max_name_len` / `max_path_len` | 255 / 1024 | 255 / 1024 |
**默认档位**出厂即安全:一个解压到 800 GiB 的 4 MiB 压缩块会在打开任何输出文件之前被拒绝。**大档案档位**仅在请求携带 `large=1` 时才启用——当磁盘上归档大于 `LARGE_FILE_THRESHOLD_BYTES`(默认 480 GiB;可在 `assets/main.js` 配置)时,解压对话框会自动提示用户。确认提示即为用户的明确选配;服务器自身不会额外记录任何内容。
### 安全检查
引擎拒绝解压以下归档:
- 加密条目(设置了任何加密标志)。
- 路径穿越(`..` 段、绝对 POSIX 路径、Windows 盘符)。
- 符号链接、设备、FIFO、套接字(`ZIPX_ERR_SPECIAL`)。
- 同一归档内的重复条目或目录/文件名冲突。
- 解压后尺寸、条目数、嵌套深度、名称长度或压缩比突破当前档位。
### 冲突策略
通过 `/api/extract` 上的 `conflict=` 传入:
- `fail`(默认)—— 拒绝覆盖任何已存在的目标。
- `overwrite` —— 替换已存在文件;合并进已存在文件夹。
- `merge` —— 保留已存在文件,新增其余文件。
### 调整阈值
480 GiB 的前端阈值位于 `assets/main.js`:
```js
const LARGE_FILE_THRESHOLD_BYTES = 480 * 1024 * 1024 * 1024;
```
设为 `Infinity` 可静音提示,调低则更保守,或干脆删掉该调用——无论阈值如何,服务器始终遵循 `large=1`。
## RAR 解压
RAR 解压引擎(`src/rar_extract.{c,h}`)由 **官方 rarlab UnRAR 源码** 支撑(`third_party/unrar7/`,版本 7.20.1,编译为静态库并通过其 C 兼容的 DLL API 驱动)。扩展名为 `.rar` 的文件与 `.zip` 文件一样拥有**解压**按钮;引擎由 `src/extract.c` 按扩展名分派。
> v1.9 替换了 v1.8 的引擎(dmc_unrar 1.7.0)。dmc_unrar 无法解码 WinRAR 6.x/7.x 写出的归档(RAR5「v6」压缩)且不支持多卷;unrar 原生支持两者。
### 支持范围
| 格式 | 支持 | 备注 |
|---|---|---|
| RAR 1.5 → 4.x(含 2.9 / 3.6 / 4.0) | ✅ | |
| RAR 5.0 及 **5.0「v6」**(WinRAR 6.x / 7.x) | ✅ | v1.9 的触发点 |
| Solid 块、最大 1 GiB 字典 | ✅ | |
| PPMd 解压(RAR 3.0+) | ✅ | |
| **多卷**(`.part01.rar` + `.part02.rar` + …) | ✅ | 当完整卷集与被打开的卷同处一目录时,unrar 按名拼接。选择首个卷(`name.part1.rar` / `name.part01.rar`);非首卷在 UI 中仍置灰并给出提示。 |
| **加密 RAR** | ⏳ | 引擎可解密(`RARSetPassword`),但密码字段/提示尚未接入 `/api/extract`。加密归档以 `ZIPX_ERR_UNSUPPORTED` 被提前拒绝。 |
| 符号链接 / FIFO / 套接字 / 设备 | ❌ | 以 `ZIPX_ERR_SPECIAL` 拒绝(与 ZIP 行为一致) |
| RAR 1.3(1.4 之前) | ❌ | 被 unrar 上游拒绝 |
当某归档被拒绝时,用户会收到 `extract_unsupported` 失败,文件名作为详情参数。前端已用典型的双语重试指引显示该错误。
### 限额
RAR 引擎原样复用 ZIP 的限额表——其上并无额外的 RAR 档位表。默认值与 `large=1` 选配完全相同:
| 限额 | 默认档位 | 大档案档位(`large=1`) |
|---|---|---|
| `max_entries` | 200 000 | 500 000 |
| `max_total_bytes`(未压缩) | 2 TiB | 4 TiB |
| `max_file_bytes`(单条目) | 512 GiB | 1 TiB |
| `max_ratio`(未压缩 / 压缩) | 500 : 1 | 1000 : 1 |
| `max_depth`(文件夹嵌套) | 32 | 32 |
| `max_name_len` / `max_path_len` | 255 / 1024 | 255 / 1024 |
大档案档位的 RAR 解压使用与 ZIP 相同的 `LARGE_FILE_THRESHOLD_BYTES`(480 GiB)提示——前端对 `.rar` 与 `.zip` 的提示处理相同,且服务器仅在请求携带 `large=1`(选配)时才启用大限额。
### 安全检查
RAR 引擎应用与 ZIP 引擎相同的检查——复用 `zipx_status_t` 状态码,因此任务 UI 的 `err_extract_unsafe_name`、`err_extract_too_deep`、`err_extract_ratio` 等会一致触发:
- 路径穿越(`..` 段、绝对 POSIX 路径、Windows 盘符、`\` 在 `Rar!\x1a\x07…` 头之后被视为路径分隔符等)。
- 符号链接、FIFO、套接字、设备。
- 归档内重复条目或目录/文件名冲突。
- 归档尺寸、条目数、深度、名称长度或压缩比突破当前档位。
### Vendoring 与许可
`third_party/unrar7/` 是官方 **rarlab UnRAR 源码**(7.20.1)的逐字副本,由 [`opello/unrar`](https://github.com/opello/unrar) 在提交 `97e1780` 处镜像。它依 **UnRAR 免费软件许可** 分发(见 `third_party/unrar7/license.txt`):可于任何软件中用于处理 RAR 归档,但不得用于开发 RAR 兼容的*归档器*或重新实现 RAR 压缩算法。项目自有的门面 `third_party/unrar7/unrar_c_api.h` 携带项目自身许可。
> v1.8 引擎 `third_party/unrar/dmc_unrar.c`(DrMcCoy/dmc_unrar 1.7.0,GPL-2.0-or-later)已在 v1.9 移除;其声明留存于 git 历史。
### 加密 RAR(计划中)
引擎可解密归档(经 `RARSetPassword`),但密码通道——`/api/extract` 上的 `password=` 字段加前端提示——尚未接线。加密归档目前以 `extract_unsupported` 失败。引擎替换(v1.9)已移除硬性引擎限制;剩余工作纯粹是 API/UI 接线。
## 7z 解压
7z 解压引擎(`src/sevenz_extract.{c,h}`)基于 SDK 解码子集(LZMA2 / LZMA / BCJ2 等)加上项目自研的拉式 codec 链(`src/sevenz_chain.c`,位于 `src/sevenz_chain.h`)。扩展名为 `.7z` 的文件与 ZIP / RAR 一样拥有**解压**按钮;引擎由 `src/extract.c` 按扩展名分派,并复用同一套三阶段模型、限额档位与冲突策略。
> v1.9.1 新增。SDK 自带的 `SzArEx` 路径仅覆盖 4 个 coder 的文件夹,不足以装下 BCJ2 的 5 coder;本项目改为自研 folder 解析 + 拉式 codec 链,从而原生支持 BCJ2 与多 coder 组合。
### 支持范围
| 格式 | 支持 | 备注 |
|---|---|---|
| LZMA2 / LZMA(含 ZIP64 式大尺寸) | ✅ | 单 coder 纯 LZMA2 走多线程解码(`src/sevenz_mt.c`,8 线程) |
| BCJ2(x86 反汇编后处理) | ✅ | 经自研拉式链;SDK `SzArEx` 装不下 5 coder 时由本项目承载 |
| 多 coder 组合文件夹 | ✅ | 自研 `sevenz_chain.c` 解析 |
| **分卷**(`.7z.001` / `.z01` 链) | ✅ | `src/sevenz_volstream.c` 按名拼接;打开首个分卷 |
| **内容加密**(7zAES,AES-256-CBC) | ⏳ | 引擎可解密;密码 UI / API 尚未接入,暂时以 `ZIPX_ERR_UNSUPPORTED` 拒绝 |
| **`-mhe=on` 加密头** | ❌ | 需自研头解析器;vendored SDK 在涉及我们之前就以 `SZ_ERROR_UNSUPPORTED` 拒绝。此为唯一已知缺口 |
当某归档被拒绝时,用户同样收到 `extract_unsupported` 失败,UI 显示双语重试指引。
### 限额
7z 引擎复用与 ZIP / RAR 完全相同的限额表;默认档位与 `large=1` 选配一致(见 [ZIP 解压 → 限额](#限额))。
### 安全检查
7z 引擎复用相同的 `zipx_status_t` 错误码与检查集合:路径穿越、特殊文件、重复条目/名冲突、以及突破当前档位的尺寸/条目数/深度/名称长度/压缩比。coder 的 `out_size` 取自 `coder_unpack_sizes[index]`(而非文件夹尺寸),`SzArEx` 失败时重置 `blockIndex` 以避免伪 CRC。
## 校验
`make` 之后,对生成的 ELF 做健全性检查:
```sh
ls -la web-file-mgr.elf # v1.9.1 因含 unrar7 + 7z 体积更大;v1.8.3 约 509 KiB
sha256sum web-file-mgr.elf # 把摘要记录进你的发布说明
file web-file-mgr.elf # 期望 "ELF 64-bit LSB pie executable, x86-64"
od -An -tx1 -N20 web-file-mgr.elf | head -2 # 魔数 7f45 4c46 0201 + e_machine 003e
```
`e_machine = 0x003e` 确认了 PS5 目标三元组 `x86_64-sie-ps5`。`e_type = 3`(`ET_DYN`)确认了 ELF 加载器期望的位置无关载荷。
## 测试
一套 POSIX / 主机端 C 测试套件覆盖 ZIP、RAR 与 7z 三个引擎,可在任意 Linux / macOS / MSYS shell 下、无需 PS5 SDK 运行:
```sh
cd tests && bash run-tests.sh # ZIP + RAR 套件
bash run-sevenz-tests.sh # 7z 套件(需 MinGW gcc 与 7-Zip 二进制)
```
输出为逐用例的 `check` 风格报告,覆盖:
- ZIP 条目解析(stored + deflated + ZIP64)
- 路径穿越、绝对路径、反斜杠、Windows 盘符
- 符号链接、FIFO、加密条目、坏 CRC、截断归档、非 ZIP 文件
- 限额:`entries`、`total_bytes`、`file_bytes`、`ratio`、`depth`、`name_len`
- 冲突策略:`fail` / `overwrite` / `merge`
- 每个阶段的取消
- **大文件档位** —— `medium_bomb.zip`(比率 ≈ 238)在默认限额下被拒、在大档位下通过;降低后的大档位仍生效
- **RAR 引擎**(`tests/test_rar_extract.c`)—— 格式分派、每个可达 `DMC_UNRAR_*` 码的错误翻译、限额交接
- **7z 引擎**(`tests/test_sevenz_extract.c` + `tests/run-sevenz-tests.sh`)—— 真实 `.7z` fixture 逐字节比对、加密头拒绝、各策略下的冲突、取消、限额、缺失目标父目录,以及失败时绝不发布且 staging 树被清理的保证
## 项目结构
```
.
├── Makefile # PS5 + Linux 构建(VERSION_TAG v1.9.1)
├── install-libmicrohttpd.sh # 一次性依赖安装器
├── gen-asset-module.py # 将 assets/* 内联为 gzip 压缩的 C 数组
├── assets/ # HTML / CSS / JS / 图标 / param.json
├── src/ # C 载荷源码
│ ├── main.c websrv.c filemgr.c # 入口、HTTP 前端、任务模型
│ ├── upload.c download.c # 流处理
│ ├── extract.c # /api/extract 分派器(ZIP + RAR + 7z)
│ ├── zip_extract.{c,h} # ZIP 引擎
│ ├── rar_extract.{c,h} # RAR 引擎(unrar7 后端)
│ ├── sevenz_extract.{c,h} # 7z 引擎
│ ├── sevenz_chain.{c,h} # 7z 拉式 codec 链(BCJ2 等)
│ ├── sevenz_mt.{c,h} # 7z 多线程 LZMA2 解码
│ ├── sevenz_volstream.{c,h} # 7z 分卷流拼接
│ └── app_installer.c # PS5 Media 启动器安装器
├── third_party/ # vendored:zlib、minizip-ng、unrar7、7z(SDK 子集)
│ ├── unrar7/ # rarlab UnRAR 7.20.1,静态库 + C API 门面
│ ├── minizip-ng/ # ZIP 读取器
│ ├── zlib/ # minizip-ng 的压缩后端
│ └── 7z/ # LZMA SDK 解码子集
├── tests/ # POSIX / 主机测试套件
│ ├── test_zip_extract.c
│ ├── test_rar_extract.c
│ ├── test_sevenz_extract.c # 7z 用例驱动
│ ├── make_fixtures.py # 重新生成测试 fixture
│ ├── run-tests.sh # 一次性运行器(ZIP + RAR)
│ ├── run-sevenz-tests.sh # 7z 运行器
│ ├── compat/ # 小型 Win32 / MSYS 垫片
│ └── fixtures/ fixtures-7z/ fixtures-real/ # 生成的测试归档
├── docs/
│ ├── HANDOVER.md # 工程交接 / 开发手册
│ ├── UPGRADE-v1.7-zip-large-file-profile.md
│ ├── UPGRADE-v1.8-rar-support.md
│ └── screenshots/ # README 截图
├── THIRD_PARTY_NOTICES # 捆绑库署名
├── LICENSE # GPLv3+
└── README.md
```
## 备注
- 复制、移动、删除、上传、下载作为单个后台任务运行。一个任务运行时,其它文件操作会被拒绝。
- 删除是递归且永久的。没有回收站。
- 复制/移动任务可取消。单个文件的部分拷贝会被移除,但部分拷贝的文件夹会保留在原地,以避免在合并进已存在目标文件夹时误删既有文件。
- 上传任务可取消。尽可能移除部分上传的临时文件。
- 下载文件夹或多个选中项会生成 tar 流。tar 归档由载荷生成,不会先写入 PS5 存储。
- 若浏览器在载荷进程仍在运行时被关闭重开,UI 可恢复活动任务显示。
- 文本编辑仅限于上述精选扩展名列表。非 UTF-8 与超大文件会被拒绝。
- 文件名通过 Web API 以 UTF-8 传输。载荷也会保留挂载文件系统返回的遗留字节序名称,以便混合 USB 文件名编码仍能正确显示与操作。
## 常见问题
- **这是自制应用,不应故意修改系统进程或内核内存。** 若遇到内核崩溃(kernel panic),请确保使用较新的越狱方法与 ELF 加载器,或回退到你惯用的稳定方法。
- **P2JB 用户** —— 若此载荷触发内核崩溃,请避免在该环境下使用。当每次重试代价高昂时,稳定性比便利更重要。
- **准备阶段可能耗时较久** —— 当文件夹含大量文件时,它会累加文件夹大小并检查剩余空间,这有助于避免启动一个无法安全完成的复制 / 移动 / 上传 / 下载。
- **`err_extract_entry_too_large`** —— 默认归档上限为单条目 512 GiB / 500:1 比率(覆盖典型 3A 游戏归档中单个约 300 GiB 未压缩文件)。若超过默认,请确认大文件提示(磁盘上 > 480 GiB 的归档会出现),拆分归档,或直接向 API 传入 `large=1`。
- **`err_extract_unsupported`** —— 归档使用了引擎无法处理的功能:加密 ZIP、加密 RAR、多卷 RAR(`.part02+.rar`)、极老的 RAR 1.4、RAR 符号链接 / FIFO,或既非 `.zip` 也非 `.rar` / `.7z` 的文件。对于 7z,特指 `-mhe=on` 加密头。针对 RAR 的消息会列出失败原因并提示用户回到 PC 端解压器。
## 署名
本项目参考了以下项目构建:
- **[ps5-payload-dev/websrv](https://github.com/ps5-payload-dev/websrv):** HTTP 服务器结构、静态资源内联思路、PS5 浏览器/websrv 行为与 PKG 安装函数。许可证:GPLv3+。
- **[ps5-payload-dev/ftpsrv](https://github.com/ps5-payload-dev/ftpsrv):** PS5 载荷约定、主屏启动器/安装流程参考、进程处理风格与启动安装参考。许可证:GPLv3+。
- **[seregonwar/zftpd](https://github.com/seregonwar/zftpd):** PS5 TCP socket 缓冲调优与高吞吐传输行为参考。许可证:MIT。
- **[itsPLK/ps5-payload-manager](https://github.com/itsPLK/ps5-payload-manager):** 载荷构建行为。许可证:GPLv3。
- **[libmicrohttpd](https://ftp.gnu.org/gnu/libmicrohttpd/):** 用作内嵌 HTTP 服务器库。由 GNU 以 LGPL 许可;本载荷以 SDK 提供的静态库链接它。
- **[ps5-payload-dev/sdk](https://github.com/ps5-payload-dev/sdk):** 载荷构建基础。许可证:GPLv3+。
- **[etaHEN](https://github.com/etaHEN/etaHEN):** 退出前用于返回 PS5 主屏的 ShellUI URI 导航。许可证:GPLv3。
- **[ezremote](https://github.com/cy33hc/ps5-ezremote-client):** 预览 PKG 信息。许可证:GPLv2。
- **[zlib-ng/minizip-ng](https://github.com/zlib-ng/minizip-ng):** `/api/extract` 端点使用的 ZIP 读取器。vendored 于 `third_party/minizip-ng/`。许可证:zlib。
- **[zlib](https://www.zlib.net/):** minizip-ng 的压缩后端。vendored 于 `third_party/zlib/`。许可证:zlib。
- **[rarlab UnRAR (opello/unrar)](https://github.com/opello/unrar):** v1.9 起 `/api/extract` 使用的 RAR 读取器(7.20.1)。vendored 于 `third_party/unrar7/`。许可证:UnRAR 免费软件许可。
## 许可证
本项目以 **GPLv3 或更高版本** 分发,与作为实现参考的 GPLv3+ 项目保持一致。见 [`LICENSE`](./LICENSE)。
第三方项目保留各自许可证。请勿在未保留相应许可证声明的情况下,将署名项目的资源或源码复制到其它发行版中。
若分发二进制,除本项目 GPL 许可外,还需遵守 `libmicrohttpd` 的 LGPL 条款。vendored 的 `zlib` 与 `minizip-ng` 源码以 zlib 许可分发;再分发用此特性构建的二进制时,保留 `third_party/zlib/LICENSE` 与 `third_party/minizip-ng/LICENSE` 中的版权声明。vendored 的 `unrar7`(RAR 引擎)依 UnRAR 免费软件许可分发;再分发用 v1.9 或更高版本构建的二进制时,保留 `third_party/unrar7/license.txt` 中的声明,且不得用其开发 RAR 兼容归档器或重新实现 RAR 压缩算法。
## 免责声明
非官方自制软件。仅在已越狱 PS5 主机上运行。使用风险自负——作者不对损坏、数据丢失、账号处罚或保修影响负责。请勿再分发 Sony 专有内容。依 GPLv3+,修改后的再分发必须公开其源码。
-66
View File
@@ -1,66 +0,0 @@
Third-Party Notices
===================
This project vendors a minimal set of third-party source files under
`third_party/` to provide the ZIP, RAR and 7z extraction features (the
`/api/extract` endpoint). Their full license texts are included
alongside the sources.
1. minizip-ng
-----------
Version : 4.2.2
Source : https://github.com/zlib-ng/minizip-ng
License : zlib (see third_party/minizip-ng/LICENSE)
Files : third_party/minizip-ng/** (vendored subset, compiled with
relaxed warnings into the final binary)
2. zlib
------
Version : 1.3.1
Source : https://www.zlib.net/
License : zlib (see third_party/zlib/LICENSE)
Files : third_party/zlib/** (vendored subset, compiled with relaxed
warnings into the final binary)
3. unrar (rarlab UnRAR source, v7.20.1)
-------------------------------------
Version : 7.20.1 (RAR 7.23-free source snapshot, 2025-10-28)
Source : https://www.rarlab.com/rar_add.htm — mirrored by
https://github.com/opello/unrar (commit 97e1780)
License : UnRAR freeware license (see third_party/unrar7/license.txt)
Files : third_party/unrar7/** (RARDLL source set compiled with
relaxed warnings; unrar_c_api.h is project-authored and
carries the project's license)
4. LZMA SDK (7z decoder)
----------------------
Version : 26.03 (2026-09-03)
Source : https://www.7-zip.org/sdk.html — release `lzma2603.7z` from
https://github.com/ip7z/7zip/releases
License : Public domain ("LZMA SDK is written and placed in the public
domain by Igor Pavlov", see third_party/7z/DOC/lzma-sdk.txt)
Files : third_party/7z/** (decoder-only subset, compiled with relaxed
warnings; see third_party/7z/README.md for the file list)
The LZMA SDK is the engine behind `src/sevenz_extract.c` (the v1.9.x 7z
support: LZMA/LZMA2/PPMd/Copy plus the BCJ, BCJ2 and Delta filters). Only the
C implementation is used — it builds with the plain PS5 C toolchain and does
not pull in the C++ runtime. The encoder half of the SDK is not vendored.
unrar is the engine behind `src/rar_extract.c` (the v1.9 RAR support: RAR4,
RAR5 including WinRAR 6/7 "v6" compression, and multi-volume archives; the
engine can also decrypt via RARSetPassword once a password channel is wired
up). The UnRAR source may be used in any software to handle RAR archives,
but may not be used to develop a RAR-compatible *archiver* or to re-create
the RAR compression algorithm, which is proprietary.
(The v1.8 engine, DrMcCoy/dmc_unrar 1.7.0 under GPL-2.0-or-later, was
replaced by the rarlab UnRAR source in v1.9; see git history under
`third_party/unrar/` for its notice.)
Libraries in sections 1 and 2 are distributed under the zlib license, which
permits redistribution in source and binary form provided the copyright
notice and this list of conditions are retained. unrar is distributed under
its own freeware terms. The LZMA SDK (section 4) is in the public domain and
carries no conditions. See the individual LICENSE / license.txt files in
each `third_party/` subdirectory for the complete terms.
Binary file not shown.

Before

Width:  |  Height:  |  Size: 268 B

Binary file not shown.

Before

Width:  |  Height:  |  Size: 139 B

Binary file not shown.

Before

Width:  |  Height:  |  Size: 184 B

Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.8 KiB

+15 -139
View File
@@ -4,35 +4,13 @@
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>PS5 Web File Manager</title>
<link rel="icon" type="image/png" href="/icon0.png">
<style>
html, body { margin: 0; min-height: 100%; background: #111316; color: #edf0f2; }
.init-loading {
position: fixed;
top: 0;
right: 0;
bottom: 0;
left: 0;
z-index: 20000;
display: flex;
align-items: center;
justify-content: center;
background: #111316;
color: #aab4be;
font: 18px system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", sans-serif;
}
</style>
<link rel="stylesheet" href="/main.css">
</head>
<body>
<main class="shell">
<header class="topbar">
<div class="top-left">
<div id="path" class="path">/</div>
</div>
<div class="top-right">
<div id="spaceInfo" class="space-info"></div>
</div>
<div id="path" class="path">/</div>
<div id="spaceInfo" class="space-info"></div>
<button id="exitBtn" class="icon-button power-button" type="button" aria-label="Exit"></button>
</header>
@@ -41,60 +19,35 @@
<button id="copyBtn" data-i18n="copy"></button>
<button id="moveBtn" data-i18n="move"></button>
<button id="renameBtn" data-i18n="rename"></button>
<button id="downloadBtn" class="remote-only" data-i18n="download"></button>
<button id="deleteBtn" class="danger" data-i18n="delete"></button>
<button id="installPkgBtn" class="install-action" data-i18n="install" hidden></button>
<button id="extractBtn" class="extract-action" data-i18n="extractToCurrent" hidden></button>
<button id="pasteBtn" class="paste-action" hidden>
<span id="pasteVerb" data-i18n="paste"></span>
<span id="pasteName" class="paste-name"></span><span id="pasteCount" class="paste-count"></span>
<span id="pasteName" class="paste-name"></span>
<span id="pasteTargetText" data-i18n="pasteToCurrent"></span>
</button>
<button id="clearClipboardBtn" data-i18n="cancel" hidden></button>
</div>
<div class="tool-right">
<button id="refreshBtn" data-i18n="refresh"></button>
<div id="uploadMenu" class="split-button remote-only">
<button id="uploadBtn" class="split-main" data-i18n="upload"></button>
<button id="uploadMenuBtn" class="split-arrow" type="button" aria-label="Upload menu"></button>
<div class="split-menu">
<button id="uploadFolderBtn" type="button" data-i18n="uploadFolder"></button>
<button id="uploadAndExtractBtn" type="button" data-i18n="extractUpload"></button>
</div>
</div>
<button id="newTextBtn" data-i18n="newText"></button>
<button id="mkdirBtn" data-i18n="mkdir"></button>
</div>
</section>
<input id="uploadFiles" type="file" multiple hidden>
<input id="uploadFolder" type="file" multiple webkitdirectory hidden>
<input id="uploadZip" type="file" accept=".zip,.rar,application/zip,application/x-zip-compressed,application/vnd.rar,application/x-rar-compressed" hidden>
<section id="content" class="content">
<table>
<thead>
<tr>
<th class="select-col"><label class="select-hit"><input id="selectAll" type="checkbox"></label></th>
<th class="name-col sortable" data-sort="name">
<div class="name-head">
<button id="parentBtn" class="parent-nav-button" type="button" aria-label="Parent directory" disabled>
<img src="/icon-back.png" alt="">
</button>
<span class="name-heading" data-i18n="name"></span>
</div>
</th>
<th class="type-col sortable" data-sort="type" data-i18n="type"></th>
<th class="size-col sortable" data-sort="size" data-i18n="size"></th>
<th class="time-col sortable" data-sort="mtime" data-i18n="mtime"></th>
<th class="mode-col sortable" data-sort="mode" data-i18n="mode"></th>
<th class="name-col" data-i18n="name"></th>
<th class="type-col" data-i18n="type"></th>
<th class="size-col" data-i18n="size"></th>
<th class="time-col" data-i18n="mtime"></th>
<th class="mode-col" data-i18n="mode"></th>
</tr>
</thead>
<tbody id="files"></tbody>
</table>
<div id="empty" class="empty" data-i18n="empty" hidden></div>
<div id="contentLoading" class="content-loading" hidden>
<div class="content-loading-text" data-i18n="readDir"></div>
</div>
</section>
<footer class="status">
@@ -103,96 +56,19 @@
</footer>
</main>
<div id="textEditorOverlay" class="text-editor-overlay" hidden>
<section class="text-editor-panel">
<div id="textEditorPath" class="text-editor-path"></div>
<textarea id="textEditor" class="text-editor" wrap="off" spellcheck="false"
autocomplete="off" autocorrect="off" autocapitalize="off"></textarea>
<div id="textEditorStatus" class="text-editor-status"></div>
<div class="text-editor-actions">
<button id="textEditorCloseBtn" class="secondary" data-i18n="close"></button>
<button id="textEditorSaveBtn" class="primary" data-i18n="save"></button>
</div>
</section>
</div>
<div id="imagePreviewOverlay" class="text-editor-overlay" hidden>
<section class="text-editor-panel image-preview-panel">
<div id="imagePreviewName" class="text-editor-path"></div>
<div class="image-preview-stage">
<img id="imagePreview" class="image-preview" alt="">
</div>
<button id="imagePreviewCloseBtn" class="secondary" data-i18n="close"></button>
</section>
</div>
<div id="pkgInfoOverlay" class="text-editor-overlay" hidden>
<section class="text-editor-panel pkg-info-panel" role="dialog" aria-modal="true" aria-labelledby="pkgInfoTitle">
<h2 id="pkgInfoTitle" class="pkg-info-title" data-i18n="pkgInfoTitle"></h2>
<div class="pkg-info-content">
<div class="pkg-info-image-stage">
<img id="pkgInfoImage" class="pkg-info-image" src="/icon-pkg.png" alt="">
</div>
<div id="pkgInfoFields" class="pkg-info-fields"></div>
</div>
<div class="text-editor-actions">
<button id="pkgInfoCloseBtn" class="secondary" data-i18n="close"></button>
<button id="pkgInfoInstallBtn" class="primary" data-i18n="install"></button>
</div>
</section>
</div>
<div id="permissionOverlay" class="permission-overlay" hidden>
<section class="permission-panel" role="dialog" aria-modal="true" aria-labelledby="permissionTitle">
<h2 id="permissionTitle" class="permission-title" data-i18n="permissionsTitle"></h2>
<div id="permissionPath" class="permission-path"></div>
<div class="permission-grid">
<div class="permission-row permission-head" aria-hidden="true">
<span class="permission-scope"></span>
<span>R</span><span>W</span><span>X</span>
</div>
<div class="permission-row">
<span class="permission-scope" data-i18n="permissionOwner"></span>
<label><input id="permissionOwnerRead" type="checkbox"><span>R</span></label>
<label><input id="permissionOwnerWrite" type="checkbox"><span>W</span></label>
<label><input id="permissionOwnerExecute" type="checkbox"><span>X</span></label>
</div>
<div class="permission-row">
<span class="permission-scope" data-i18n="permissionGroup"></span>
<label><input id="permissionGroupRead" type="checkbox"><span>R</span></label>
<label><input id="permissionGroupWrite" type="checkbox"><span>W</span></label>
<label><input id="permissionGroupExecute" type="checkbox"><span>X</span></label>
</div>
<div class="permission-row">
<span class="permission-scope" data-i18n="permissionOther"></span>
<label><input id="permissionOtherRead" type="checkbox"><span>R</span></label>
<label><input id="permissionOtherWrite" type="checkbox"><span>W</span></label>
<label><input id="permissionOtherExecute" type="checkbox"><span>X</span></label>
</div>
</div>
<label class="permission-octal">
<span data-i18n="permissionOctal"></span>
<input id="permissionMode" type="text" inputmode="numeric" pattern="0[0-7]{3}"
minlength="4" maxlength="4" autocomplete="off" spellcheck="false">
</label>
<label id="permissionRecursiveOption" class="permission-recursive" hidden>
<input id="permissionRecursive" type="checkbox" checked>
<span data-i18n="permissionRecursive"></span>
</label>
<div class="permission-actions">
<button id="permissionCancelBtn" class="secondary" data-i18n="close"></button>
<button id="permissionApplyBtn" class="primary" data-i18n="apply"></button>
</div>
</section>
</div>
<div id="taskOverlay" class="task-overlay" hidden>
<div class="task-panel">
<div id="tasks" class="tasks"></div>
</div>
</div>
<div id="initLoading" class="init-loading" aria-hidden="true">Loading...</div>
<div id="initLoading" class="init-loading" aria-hidden="true">
<div class="loading-dots">
<span></span>
<span></span>
<span></span>
</div>
</div>
<script src="/main.js"></script>
</body>
+2 -111
View File
@@ -3,34 +3,14 @@ window.WFM_LANG = {
copy: "Copy",
move: "Move",
delete: "Delete",
download: "Download",
upload: "Upload",
uploadFolder: "Upload Folder",
copying: "Copying",
moving: "Moving",
deleting: "Deleting",
changingPermissions: "Changing permissions",
rename: "Rename",
paste: "Paste",
cancel: "Cancel",
close: "Close",
save: "Save",
apply: "Apply",
exit: "Exit",
exitConfirm: "Exit and stop the file manager process?",
exiting: "Exiting...",
refresh: "Refresh",
mkdir: "New Folder",
newText: "New Text",
install: "Install",
installPackage: "Install package",
pkgInfoTitle: "Package Information",
pkgInfoLoading: "Reading package information...",
pkgInstalling: "Starting package installation: {name}...",
pkgInstallStarted: "Package installation started: {name}",
file: "File",
textFile: "Text",
image: "Image",
dir: "Folder",
parent: "Parent",
name: "Name",
@@ -38,19 +18,6 @@ window.WFM_LANG = {
size: "Size",
mtime: "Modified",
mode: "Mode",
permissionsTitle: "Change permissions",
permissionOwner: "Owner",
permissionGroup: "Group",
permissionOther: "Other",
permissionOctal: "Octal mode",
permissionRecursive: "Apply to all contents inside this folder",
permissionObjectCount: "and {count} objects",
permissionChangeTitle: "Change permissions for {name}",
permissionInvalid: "Enter exactly four octal digits from 0 to 7, starting with 0. The original value has been restored.",
unsavedPermissionConfirm: "The permissions have unsaved changes. Close without applying them?\n\nCancel keeps the permissions dialog open.",
permissionChanging: "Changing permissions...",
permissionChanged: "Permissions changed: {name} → {mode}",
permissionChangeFailed: "Failed to change permissions: {error}",
empty: "Folder is empty",
ready: "Ready",
freeSpace: "Free space",
@@ -64,21 +31,14 @@ window.WFM_LANG = {
checking: "Checking",
pleaseWait: "Please wait",
speedLabel: "Speed",
itemsPerSecond: "{count} objects/s",
progressLabel: "Progress",
permissionProgress: "{done} / {total} objects",
etaLabel: "ETA",
elapsedLabel: "Elapsed",
durationHours: "{hours}h {minutes}m",
durationMinutes: "{minutes}m {seconds}s",
durationSeconds: "{seconds}s",
preparingTask: "Preparing task",
canceling: "Canceling...",
selectedItems: "{name} and {count} items",
countItems: "{count} items",
totalItems: "{count} items",
readDir: "Reading folder...",
processing: "Processing...",
actionBusy: "{label}...",
taskCreated: "{label} task created",
actionDone: "{label} done",
@@ -87,53 +47,19 @@ window.WFM_LANG = {
taskCanceled: "{label} canceled",
selectedForPaste: "Selected {name}. Enter the target folder, then choose {verb}",
clipboardCleared: "Pending operation canceled",
downloadStarted: "Download started: {name}",
uploadFolderChoice: "Upload a folder?\n\nOK: choose a folder\nCancel: choose files",
uploadOverwriteConfirm: "Items with the same name already exist: {names}\n\nOverwrite matching files and merge matching folders?",
uploadingStatus: "Uploading {index}/{count}: {name}",
uploadDone: "Upload done, {count} items",
uploadFailed: "Upload failed: {error}",
downloading: "Downloading",
uploading: "Uploading",
extract: "Extract",
extractToCurrent: "Extract to current folder",
extractUpload: "Upload and extract",
extracting: "Extracting",
extractConfirm: "Extract {name} to {path}?",
extractOverwriteAsk: "If a file or folder with the same name already exists in the target:\n\nOK = overwrite same-name files (folders still merge)\nCancel = fail if the target already exists",
extractPasswordAsk: "This archive may be encrypted (e.g. 7zAES).\n\nEnter the password to extract, or leave it empty to try without one.",
extractUploadConfirm: "Upload and extract {name}?\n\nTarget folder: {path}\nThe uploaded archive will be deleted after success.",
extractStarted: "Extraction started: {name}",
extractDone: "Extraction complete: {name}",
extractProgress: "{done} / {total} files",
extractLargeAsk: "The archive looks large ({size}). Enable the large-file profile?\n\nOK = yes (single file up to 1 TiB, archive total up to 4 TiB)\nCancel = default limits (single file 512 GiB, archive total 2 TiB); this archive may be rejected",
extractLargeActive: "Large-file profile is enabled for this task",
extractSelectMainVolume: "Please select the main volume (.rar or .part01.rar)",
extractArchivePending: "Preparing to extract {name}",
sameSourceTarget: "Source and destination are the same. Cannot {label} {name}",
removeConflictFirst: "A {existingType} named {name} already exists. To {label} this {sourceType}, delete that {existingType} first.",
overwriteFiles: "Files with the same name will be overwritten: {names}",
mergeDirs: "Folders with the same name will be merged. Internal files with the same name will be overwritten: {names}",
continueConfirm: "Continue?",
preparingPaste: "Preparing: calculating size and checking target space...",
preparingPaste: "{label} preparing: calculating size and checking target space...",
preparingStatus: "{label} preparing...",
cancelPrepare: "Preparation canceled",
cancelTaskConfirm: "Cancel current {label} task?",
cancelFailed: "Cancel failed: {error}",
tasksPollFailed: "Failed to read task status: {error}",
transferComplete: "{label} completed: {name}\n\nTotal time: {duration}\nTransferred: {size}",
transferCompleteFiles: "{label} completed: {name}\n\nTotal time: {duration}\nTransferred: {size}\nFiles: {count}",
renamePrompt: "New name",
mkdirPrompt: "Folder name",
newTextPrompt: "Text file name",
creatingText: "Creating text file...",
createTextFailed: "Failed to create text file: {error}",
unsavedSaveConfirm: "The text has unsaved changes. Close without saving?\n\nCancel keeps the editor open.",
loadingText: "Loading text...",
savingText: "Saving...",
textSaved: "Text saved",
openTextFailed: "Failed to open text: {error}",
saveTextFailed: "Failed to save text: {error}",
deleteConfirm: "Delete {name}?",
deleteConfirmRecursive: "Delete {name}?\n\nFolders will be deleted recursively.",
activeTask: "A task is running",
@@ -144,14 +70,11 @@ window.WFM_LANG = {
storageUsb: "USB",
storageM2: "M.2",
storageExtended: "Extended",
storageRoot: "Root",
storageCurrent: "Current",
err_target_dir_not_writable: "Target folder is not writable: {path}",
err_target_file_not_writable: "Target file is not writable: {path}",
err_target_parent_not_writable: "Current folder is not writable: {path}",
err_target_parent_not_writable: "Target parent folder is not writable: {path}",
err_target_check_failed: "Cannot check target path: {path}",
err_target_path_too_long: "Target path is too long",
err_path_too_long: "Path is too long",
err_space_check_failed: "Cannot read target free space: {path}",
err_no_space: "Not enough target space. Required {required}, available {available}",
err_active_task: "A task is running",
@@ -159,41 +82,9 @@ window.WFM_LANG = {
err_source_destination_same: "Source and destination are the same",
err_destination_inside_source: "Cannot copy or move a folder inside itself",
err_invalid_path: "Invalid path",
err_invalid_mode: "Invalid permission mode",
err_chmod_failed: "Cannot change permissions: {path}",
err_pkg_type_invalid: "Only .pkg files can be installed",
err_pkg_info_failed: "Could not read package information: {path}",
err_pkg_install_failed: "Package installation failed ({arg})",
err_pkg_install_unsupported: "Package installation is only available on PS5",
err_file_not_found: "File not found",
err_file_already_exists: "A file with the same name already exists",
err_invalid_method: "Invalid request method",
err_text_type_not_editable: "This file type is not supported by the text editor",
err_text_file_too_large: "The text file is too large. The maximum size is 1 MiB",
err_text_invalid_utf8: "The file is not valid UTF-8 text",
err_text_file_changed: "The file changed after it was opened. Close and reopen it",
err_text_file_not_writable: "The text file is not writable",
err_request_body_too_large: "Too many selected items. Select fewer items and try again",
err_unknown_api: "Unknown API",
err_out_of_memory: "Out of memory",
err_no_source_paths: "No source paths",
err_destination_must_be_directory: "Destination must be a folder for multiple items",
err_extract_open_failed: "Cannot open archive: {arg}",
err_extract_corrupt: "Archive is corrupt or incomplete: {arg}",
err_extract_unsupported: "Unsupported archive (only plain ZIP, single-volume RAR, and 7z are supported): {arg}",
err_extract_password: "Wrong password or the archive is not encrypted with the one supplied: {arg}",
err_extract_unsafe_name: "Archive contains an unsafe path: {arg}",
err_extract_special_entry: "Archive contains an unsupported special file: {arg}",
err_extract_duplicate: "Archive contains duplicate entries: {arg}",
err_extract_too_many_entries: "Archive has too many entries: {arg}",
err_extract_entry_too_large: "A file inside the archive is too large: {arg}",
err_extract_too_large: "Archive expands to too much data: {arg}",
err_extract_ratio: "Suspicious compression ratio (possible zip bomb): {arg}",
err_extract_too_deep: "Directory nesting is too deep: {arg}",
err_extract_name_too_long: "File name or path is too long: {arg}",
err_extract_conflict: "A file or folder with the same name already exists: {arg}",
err_extract_io: "Extraction read/write failed: {arg}",
err_extract_crc: "CRC check failed: {arg}",
err_extract_failed: "Extraction failed: {arg}",
err_system_error: "System error: {arg}"
};
+3 -112
View File
@@ -3,34 +3,14 @@ window.WFM_LANG = {
copy: "复制",
move: "移动",
delete: "删除",
download: "下载",
upload: "上传",
uploadFolder: "上传文件夹",
copying: "复制",
moving: "移动",
deleting: "删除",
changingPermissions: "修改权限",
rename: "重命名",
paste: "粘贴",
cancel: "取消",
close: "关闭",
save: "保存",
apply: "应用",
exit: "退出",
exitConfirm: "是否退出并关闭文件管理器进程?",
exiting: "正在退出...",
refresh: "刷新",
mkdir: "新建目录",
newText: "新建文本",
install: "安装",
installPackage: "安装 PKG",
pkgInfoTitle: "PKG 信息",
pkgInfoLoading: "正在读取 PKG 信息...",
pkgInstalling: "正在提交安装:{name}...",
pkgInstallStarted: "已开始安装:{name}",
file: "文件",
textFile: "文本",
image: "图片",
dir: "目录",
parent: "上级目录",
name: "名称",
@@ -38,19 +18,6 @@ window.WFM_LANG = {
size: "大小",
mtime: "修改时间",
mode: "权限",
permissionsTitle: "修改权限",
permissionOwner: "拥有者",
permissionGroup: "组",
permissionOther: "其他",
permissionOctal: "八进制表示",
permissionRecursive: "应用于文件夹内的所有内容",
permissionObjectCount: "等 {count} 个对象",
permissionChangeTitle: "修改 {name} 的权限",
permissionInvalid: "请输入以 0 开头、由 0 到 7 组成的四位八进制权限。已恢复为原权限值。",
unsavedPermissionConfirm: "权限有未保存的修改,是否不保存并关闭?\n\n取消将留在权限弹窗中。",
permissionChanging: "正在修改权限...",
permissionChanged: "权限已修改:{name} → {mode}",
permissionChangeFailed: "修改权限失败:{error}",
empty: "目录为空",
ready: "就绪",
freeSpace: "可用空间",
@@ -64,21 +31,14 @@ window.WFM_LANG = {
checking: "检查中",
pleaseWait: "请稍候",
speedLabel: "速度",
itemsPerSecond: "{count} 个对象/秒",
progressLabel: "进度",
permissionProgress: "{done} / {total} 个对象",
etaLabel: "剩余",
elapsedLabel: "耗时",
durationHours: "{hours}小时 {minutes}分",
durationMinutes: "{minutes}分 {seconds}秒",
durationSeconds: "{seconds}秒",
preparingTask: "正在准备任务",
canceling: "正在取消...",
selectedItems: "{name} 等 {count} 项",
countItems: "{count} 项",
totalItems: "共 {count} 项",
readDir: "读取目录中...",
processing: "处理中...",
readDir: "读取目录...",
actionBusy: "{label}...",
taskCreated: "{label}任务已创建",
actionDone: "{label}完成",
@@ -87,53 +47,19 @@ window.WFM_LANG = {
taskCanceled: "{label}已取消",
selectedForPaste: "已选择 {name},进入目标目录后点击{verb}",
clipboardCleared: "已清除待操作项目",
downloadStarted: "已开始下载 {name}",
uploadFolderChoice: "选择要上传的目录?\n\n确定:选择目录\n取消:选择文件",
uploadOverwriteConfirm: "目标中已存在同名项目: {names}\n\n是否覆盖同名文件并合并同名目录?",
uploadingStatus: "正在上传 {index}/{count}: {name}",
uploadDone: "上传完成,共 {count} 项",
uploadFailed: "上传失败: {error}",
downloading: "下载中",
uploading: "上传中",
extract: "解压",
extractToCurrent: "解压到当前目录",
extractUpload: "上传并解压",
extracting: "解压",
extractConfirm: "解压 {name} 到 {path}?",
extractOverwriteAsk: "若目标已存在同名文件或目录:\n\n确定 = 覆盖同名文件(目录仍会合并)\n取消 = 若目标已存在则失败",
extractPasswordAsk: "此压缩包可能加密了(如 7zAES)。\n\n输入密码后解压,留空则尝试无密码解压。",
extractUploadConfirm: "上传并解压 {name}?\n\n目标目录:{path}\n成功后将删除上传的压缩包。",
extractStarted: "已开始解压 {name}",
extractDone: "解压完成:{name}",
extractProgress: "{done} / {total} 个文件",
extractLargeAsk: "压缩包体积较大({size}),是否启用「大文件模式」?\n\n确定 = 启用(单文件最大 1 TiB / 总解压最大 4 TiB)\n取消 = 默认限制(单文件 512 GiB / 总解压 2 TiB),可能拒绝此压缩包",
extractLargeActive: "此任务已启用大文件模式",
extractSelectMainVolume: "请改选主卷(如 .rar 或 .part01.rar)",
extractArchivePending: "正在准备解压 {name}",
sameSourceTarget: "源和目标相同,不能{label} {name}",
removeConflictFirst: "目标中已存在同名{existingType} {name}。要{label}{sourceType},请先删除该{existingType}才能继续。",
overwriteFiles: "同名文件将被覆盖: {names}",
mergeDirs: "同名目录将被合并,内部同名文件会被覆盖: {names}",
continueConfirm: "继续?",
preparingPaste: "准备中:正在计算大小并检查目标空间...",
preparingPaste: "{label}准备中:正在计算大小并检查目标空间...",
preparingStatus: "{label}准备中...",
cancelPrepare: "已取消准备操作",
cancelTaskConfirm: "取消当前{label}任务?",
cancelFailed: "取消失败: {error}",
tasksPollFailed: "任务状态读取失败: {error}",
transferComplete: "{label}完成:{name}\n\n总耗时:{duration}\n传输大小:{size}",
transferCompleteFiles: "{label}完成:{name}\n\n总耗时:{duration}\n传输大小:{size}\n文件数量:{count}",
renamePrompt: "新名称",
mkdirPrompt: "目录名",
newTextPrompt: "文本文件名",
creatingText: "正在新建文本...",
createTextFailed: "新建文本失败: {error}",
unsavedSaveConfirm: "文本有未保存的修改,是否不保存并关闭?\n\n取消将留在编辑器中。",
loadingText: "正在读取文本...",
savingText: "正在保存...",
textSaved: "文本已保存",
openTextFailed: "打开文本失败: {error}",
saveTextFailed: "保存文本失败: {error}",
deleteConfirm: "确认删除 {name}?",
deleteConfirmRecursive: "确认删除 {name}?\n\n目录会递归删除。",
activeTask: "有任务正在执行",
@@ -144,14 +70,11 @@ window.WFM_LANG = {
storageUsb: "USB存储",
storageM2: "M2扩充存储",
storageExtended: "扩展存储",
storageRoot: "根分区",
storageCurrent: "当前目录",
err_target_dir_not_writable: "目标目录不可写: {path}",
err_target_file_not_writable: "目标文件不可写: {path}",
err_target_parent_not_writable: "当前目录不可写: {path}",
err_target_parent_not_writable: "目标父目录不可写: {path}",
err_target_check_failed: "无法检查目标路径: {path}",
err_target_path_too_long: "目标路径过长",
err_path_too_long: "路径过长",
err_space_check_failed: "无法读取目标剩余空间: {path}",
err_no_space: "目标空间不足,需要 {required},可用 {available}",
err_active_task: "有任务正在执行",
@@ -159,41 +82,9 @@ window.WFM_LANG = {
err_source_destination_same: "源和目标相同",
err_destination_inside_source: "不能复制或移动目录到它自己的内部",
err_invalid_path: "路径无效",
err_invalid_mode: "权限格式无效",
err_chmod_failed: "无法修改权限:{path}",
err_pkg_type_invalid: "只能安装 .pkg 文件",
err_pkg_info_failed: "无法读取 PKG 信息:{path}",
err_pkg_install_failed: "PKG 安装失败({arg})",
err_pkg_install_unsupported: "PKG 安装仅支持 PS5 环境",
err_file_not_found: "文件不存在",
err_file_already_exists: "同名文件已存在",
err_invalid_method: "请求方式无效",
err_text_type_not_editable: "该文件类型不支持文本编辑",
err_text_file_too_large: "文本文件过大,最大支持 1 MiB",
err_text_invalid_utf8: "文件不是有效的 UTF-8 文本",
err_text_file_changed: "文件在打开后已发生变化,请关闭后重新打开",
err_text_file_not_writable: "文本文件不可写",
err_request_body_too_large: "选择的项目过多,请减少选择后重试",
err_unknown_api: "未知接口",
err_out_of_memory: "内存不足",
err_no_source_paths: "没有源路径",
err_destination_must_be_directory: "多个项目的目标必须是目录",
err_extract_open_failed: "无法打开压缩包: {arg}",
err_extract_corrupt: "压缩包损坏或不完整: {arg}",
err_extract_unsupported: "不支持的压缩包(仅支持未加密的普通 ZIP、单卷 RAR,以及 7z):{arg}",
err_extract_password: "密码错误,或压缩包未使用所提供的密码加密: {arg}",
err_extract_unsafe_name: "压缩包包含不安全的路径: {arg}",
err_extract_special_entry: "压缩包包含不支持的特殊文件: {arg}",
err_extract_duplicate: "压缩包包含重复条目: {arg}",
err_extract_too_many_entries: "压缩包条目过多: {arg}",
err_extract_entry_too_large: "压缩包内单个文件过大: {arg}",
err_extract_too_large: "压缩包解压后总大小过大: {arg}",
err_extract_ratio: "压缩比异常(疑似压缩炸弹): {arg}",
err_extract_too_deep: "目录层级过深: {arg}",
err_extract_name_too_long: "文件名或路径过长: {arg}",
err_extract_conflict: "目标已存在同名文件或目录: {arg}",
err_extract_io: "解压读写失败: {arg}",
err_extract_crc: "CRC 校验失败: {arg}",
err_extract_failed: "解压失败: {arg}",
err_system_error: "系统错误: {arg}"
};
+76 -995
View File
File diff suppressed because it is too large. Load diff
+169 -1894
View File
File diff suppressed because it is too large. Load diff
-188
View File
@@ -1,188 +0,0 @@
# 解压性能:实测、根因、提速方案
> 实测 2026-09-15 · 对照物 = 官方 7-Zip 26.03(上游 v1.8 的 helper 就是它)
> 复现:`python tests/bench_driver.py --big --runs 3`;WSL 同环境对比见 `.build/bench/wsl-*.sh`
> **✅ 方案 A 已落地(2026-09-16)**:`Asm/x86/LzmaDecOpt.asm` + `7zAsm.asm` 已 vendor 到
> `third_party/7z/`,jwasm `-elf64 -DABI_LINUX` 汇编进 PS5 与 Linux 两条链路,
> `LzmaDec.o` 加 `-DZ7_LZMA_DEC_OPT`。实测 **1.39 s → 1.05–1.13 s(1.26×)**,解出字节与
> C 版逐字节一致;7z 测试矩阵 28 checks 全过。Makefile 对该优化做了条件化(无 jwasm 自动
> 退回纯 C)并依赖 Makefile 本身触发重编(flag 变化不会被 make 察觉)。
>
> **✅ 方案 B 已落地(2026-09-16)**:`Lzma2DecMt.c` + `MtDec.c` + `Threads.c` 已 vendor,
> 单一纯 LZMA2 folder(7-Zip 默认布局)走 SDK 并行解码器(`src/sevenz_mt.c` 适配层),
> 8 线程 + 1 MiB inBufSize_MT;`SZ_ERROR_THREAD` 自动降级回单线程 chain(BCJ2/加密/奇异
> 布局本来就由 chain 负责)。实测 329 MiB:1.05 s → **0.77 s(1.37×)**,与 7za -mmt=off
> 打平(898 ms);7za -mmt=8 = 485 ms。7z/ZIP/RAR 163 checks 全绿。
>
> **✅ ZIP 引擎 fsync 批量化(2026-09-16)**:逐条目 fsync 已移除(publish 是纯 rename、
> 无续解功能,该 fsync 无收益;RAR/7z 引擎本来就没有)。8000 文件 fixture:fsync 版
> \>200 s 未完成 → 无 fsync **14.5 s(≥14×)**。同机官方 7-Zip 反而要 >400 s(Defender
> 实时扫描逐文件查杀;PS5 无此因素)。
## 结论
**7z 解码我们比 7-Zip 慢 1.57×(单线程),根因已定位到一个具体的编译开关。**
不是架构问题,不是算法问题,不是编译选项问题 —— 是 **SDK 里有一份汇编版解码器我们没启用**:
```c
/* LzmaDec.c */
#ifdef Z7_LZMA_DEC_OPT
int Z7_FASTCALL LZMA_DECODE_REAL(CLzmaDec *p, SizeT limit, const Byte *bufLimit); /* asm */
#else
... 纯 C 宏展开 + LzmaDec_DecodeReal2() /* ← 我们在这里 */
#endif
```
`LzmaDecOpt.asm` 是 Igor Pavlov 官方 SDK 的一部分(public domain),**1339 行**,实现同一个函数。开不开这个开关,实测差 1.5 倍。
---
## 一、同环境实测(关键:排除跨平台假象)
第一轮数据是在 Windows 上打的(我们 MinGW 构建 vs `7za.exe`),混了平台因素。重做:**在同一台机器、同一个 WSL Linux 环境、同一份归档、同一类编译器**下对比。
归档:329 MiB 解压量 / 22 MiB 压缩,LZMA2 solid,单文件
| 配置 | 单线程 | 8 线程 | 相对我们 |
|---|---:|---:|---:|
| **ours**(facade,含 staging + fsync + publish) | **1.39 s** | — | 1.00× |
| 官方 7-Zip(Linux 构建) | **0.89 s** | **0.51 s** | **1.57× / 2.73×** |
> 两个数字都是同一台机器上的实测。7-Zip 的 Linux 版和 Windows 版几乎一样快(0.89 vs 0.84 s),说明平台差异不是因素。
---
## 二、四个被实测排除的原因
排查过程里每个假设都先给出过错误结论,所以逐个记录:
| # | 假设 | 实验 | 结果 |
|---|---|---|---|
| 1 | **fsync / 写盘开销** | 两边都解到 `/dev/shm`(tmpfs,fsync 近乎免费) | ❌ 我们 1.47 s,磁盘上也是 1.47 s —— **fsync 成本可忽略** |
| 2 | **pull 粒度太小**(64 KiB 输出块 → 5000+ 次调用) | 把 `SZ_OUT_CHUNK` 提到 1 MiB | ❌ 1.39 s,与 64 KiB 无差别。profile 显示 `node_pull` **只调用 329 次**,调度开销 ≈ 0 |
| 3 | **编译选项保守**(我们用 `-O2 -w`) | `-O3` / `-march=native` / `-march=x86-64-v3` 各跑一遍 | ❌ 全部落在 1.31–1.52 s,无显著差异 |
| 4 | **汇编优化只值 6%**(我曾据此推断"不是主因") | 对比 Windows 版(有 asm) 与 Linux 版 | ❌ **这个推断是错的** —— Linux 官方版同样含 asm,所以只看到 6% 的平台差异。见下节 |
---
## 三、真正的根因:profile 说话
`gprof`,同一份归档:
```
% self calls name
82.81 1.06 s 81237 LzmaDec_DecodeReal2 ← LZMA 解码核心(C 版)
17.19 0.22 s 660 CrcUpdateT12 ← CRC32 校验
0.00 0.00 s 329 node_pull ← 我们的链调度,可忽略
0.00 0.00 s 329 szx_sink_write ← 写盘,可忽略
0.00 0.00 s 1705 LzmaDec_DecodeToDic
```
**82.8% 的时间在一个函数里,而那个函数有一个 asm 版本我们没有使用。**
这解释了为什么前四个假设全部落空:它们针对的都是那 0% 的部分。
### 三方交叉验证
- 我们的构建:未定义 `Z7_LZMA_DEC_OPT` → profile 里是 `LzmaDec_DecodeReal2` ✓
- SDK 源码:明确写着 `#ifdef Z7_LZMA_DEC_OPT` 时声明外部 asm 符号 ✓
- 官方 GCC 构建规则(`7zip_gcc_c.mak`):`USE_LZMA_DEC_ASM` 开关 + `jwasm` 汇编 `LzmaDecOpt.asm` ✓
### 附带发现:CRC 占 17%
`CrcUpdateT12`(slicing-by-12)花掉 0.22 s。7-Zip 解压时同样校验 CRC,所以这部分**不构成差距**,但如果单独优化(SSE4.2 硬件 `crc32` 指令,Zen 2 支持)能再省约 0.15 s。
---
## 四、提速方案
### 方案 A(推荐):启用 asm 解码器
| 步骤 | 内容 |
|---|---|
| 1 | 取 `Asm/x86/LzmaDecOpt.asm` + `Asm/x86/7zAsm.asm` 入 `third_party/7z/` |
| 2 | 用 **jwasm**(MASM 兼容汇编器,支持 ELF64 输出)汇编成 `.o` |
| 3 | Makefile 加规则;`LzmaDec.c` 编译时加 `-DZ7_LZMA_DEC_OPT` |
| 4 | 完整测试矩阵(163 checks)+ 基准复测 |
- **预期收益:1.39 s → ~0.95 s(≈1.45×)**,追平 7-Zip 单线程水平
- **工作量**:小~中(一个汇编文件 + 一条 Makefile 规则 + 一个宏)
- **风险**:中 —— 唯一的不确定点是 **jwasm 能否产出 PS5(prospero-clang / x86-64 ELF)可链接的目标文件**。这一条必须先验证再动手
- **为什么"稳"**:asm 是 SDK 官方组成部分(同一位作者维护,与 C 版有链接时版本校验 `_3`,对不上会直接链接失败而不是静默出错);正确性由现有 163 项测试兜底
### 方案 B:多线程 LZMA2 解码
SDK 自带 `C/Lzma2DecMt.c`(1095 行,public domain)就是 7-Zip `-mmt` 的并行实现,实测 0.89 → 0.51 s。
- **预期收益:额外 1.75×**(与 A 叠加后 ≈ 2.6×,基本追平 7-Zip 全核)
- **工作量**:大 —— 要重构 chain 的调度(block 级并行 + 字典依赖管理)
- **风险**:中高(并发正确性、内存峰值;PS5 只有 8 核且 HTTP/任务系统同进程,建议限制线程数)
- **前置**:建议先完成 A,因为 A 不改架构、收益确定、能独立验证
### 方案 C:CRC 硬件加速(可选)
用 SSE4.2 的 `crc32` 指令替换 `CrcUpdateT12`。Zen 2 支持。
- **预期收益:约 0.15 s(10%)**
- **工作量**:小
- **注意**:7-Zip 也做 CRC 校验,这不会拉开差距,只是净提速
### 方案 D(备选,不推荐):上游的 helper 路线
直接把 7-Zip 做成独立进程,一步到位拿到 1.57×/2.73×。
不推荐的理由:
1. 引入外部 ELF 依赖 + IPC + 进程生命周期管理,**故障模式比现在多得多**("最稳"的反面)
2. 方案 A 用一个文件 + 一条规则就能拿到 1.45×,D 的增量收益只有多线程那部分
3. PS5 上还要处理 elfldr 加载;上游自己都是"单独分发,让用户手动放到 `/data/wfm/`"
---
## 五、执行顺序建议
```
第一步 A(asm 解码器)
└─ 先验证 jwasm → ELF64 → prospero-ld 这条链能否走通
└─ 通过则:1.39 s → ~0.95 s,测试矩阵全绿后提交
第二步 B(多线程)
└─ 在 A 的基础上做,目标 ~0.55 s
第三步 C(CRC 硬件加速,可选)
└─ 再省 ~0.15 s
```
**不做任何优化时的现状也是可接受的**:1.39 s / 329 MiB ≈ 237 MiB/s 单线程吞吐。在真实场景(大游戏包)里受存储 I/O 限制,差距往往比这个倍数更小。
---
## 六、复现
```bash
export PATH="/c/mingw64/bin:/c/Users/songl/.workbuddy/binaries/PortableGit/versions/1.2.0/mingw64/bin:/c/Users/songl/.workbuddy/binaries/python/versions/3.13.12:/usr/bin:/bin:/c/Windows/System32:/c/Windows"
cd "/c/Users/songl/Desktop/Web File Manager/ps5-web-file-manager"
# 先各跑一次,生成引擎对象
/usr/bin/bash tests/run-sevenz-tests.sh
/usr/bin/bash tests/run-tests.sh --rebuild
# Windows 基准(我们的引擎 vs 7za.exe)
python tests/bench_driver.py --big --runs 3
# 同环境对比(WSL):官方 Linux 7-Zip / 我们的引擎 / 编译选项 / profile
wsl.exe -d Ubuntu-22.04 -- bash < .build/bench/wsl-perf.sh
wsl.exe -d Ubuntu-22.04 -- bash < .build/bench/wsl-ours.sh
wsl.exe -d Ubuntu-22.04 -- bash < .build/bench/wsl-flags.sh
wsl.exe -d Ubuntu-22.04 -- bash < .build/bench/wsl-prof.sh
```
## 附:测量方法备忘
这个沙箱里 bash 计时不可用,三个坑都先给出过错误数字:
- 每次 `date` 要 ~350 ms → `t0/t1` 对给 ~600 ms 的测量注入 700 ms 误差
- `time` 的 user/sys 看不到 native 子进程(解 82 MiB 报 `user 0.031s`)
- 反复跑堆积 2.7 GB 输出目录 → 测出过"内部时间 > 外部时间"
正确做法:Python 驱动(单次 spawn + 单调时钟)+ 候选程序自带内部计时 + 显式扣除 spawn tax(~190–240 ms)+ best of N + 每次跑前清输出目录。
-1714
View File
File diff suppressed because it is too large. Load diff
-236
View File
@@ -1,236 +0,0 @@
# 重写可行性评估报告
> 评估日期:2026-09-15 · 评估对象:`LisherSong/ps5-web-file-manager`(v1.9.1)
> 目标问题:项目源自他人代码、怀疑授权不清;若从零重写,改动量多大?能否做得更好?
>
> ⚠️ 本文是**工程视角**的合规盘点,不是法律意见。若涉及商用/闭源决策,请咨询律师。
---
## 0. 结论先行
| 问题 | 答案 |
|---|---|
| 上游真的没有许可吗? | **否。上游是 GPL-3.0**,我们自己也是 GPL-3.0,两者一致 |
| 现在能合法发布吗? | **能**。GPL-3.0 允许修改和再分发,只需满足归因 + 源码可得 |
| 有没有真实风险? | 有 4 个,全部**可在 1 天内修完**,没有一个需要重写 |
| 全量重写要多少人日? | **35–50 人日**(约 1.4–2 万行需重写,第三方 7.1 万行可直接复用) |
| 值得重写吗? | **取决于目标**:想闭源/商用 → 必须重写;想开源分享 → **完全不必** |
**最反直觉的一点**:我们自建的 7z 引擎核心(3,661 行)**只依赖公共领域和 zlib 许可的第三方库,与上游 GPL 代码零耦合** —— 它是完全干净的资产,今天就能单独抽成 MIT 授权的独立库。
---
## 1. 许可现状核查(事实,非猜测)
### 1.1 上游授权 —— 你的前提是错的
通过 GitHub API 查询(2026-09-15):
```
owendswang/ps5-web-file-manager
license: GPL-3.0 stars: 78 forks: 6
created: 2026-06-16 last push: 2026-09-08 archived: false
```
上游**有明确许可**,且是 GPL-3.0。我们的 `LICENSE` 同样是 GPL-3.0,在 root commit `5cb0b76`(Initial import)时加入 —— **两边一致,不存在"无授权"的灰色地带**。
### 1.2 授权链条
```
ps5-payload-dev/websrv (John Törnblom, GPLv3+)
│ 源码里仍保留 "Copyright (C) 2024/2025 John Törnblom"
│ —— asset.c / asset.h / mime.h / websrv.h 四个文件
▼
owendswang/ps5-web-file-manager (GPL-3.0)
▼
LisherSong/ps5-web-file-manager (GPL-3.0) ← 本项目
```
`src/asset.c:1` 等文件里的 Törnblom 版权声明**至今完整保留** ✅ —— 说明 GPL §5(a)「保留版权声明」这一条在最上游那一环是满足的。
---
## 2. 真实风险清单
按严重度排序。**注意:没有一条需要重写代码来解决。**
| # | 风险 | 严重度 | 具体位置 | 修法 | 成本 |
|---|---|---|---|---|---|
| 1 | **归因缺失**:README Credits 列了 8 个项目,唯独漏了 `owendswang`;git 历史被重写成 "Initial import",上游作者署名在历史里也找不到 | 🟡 中 | `README.md:436-451` | Credits 加一行 + 补 `NOTICE` 文件 | 1 小时 |
| 2 | **unRAR 与 GPL-3.0 的附加限制冲突**:UnRAR 许可禁止"用于开发 RAR 兼容压缩器",GPL-3.0 §7 禁止附加限制,严格讲不兼容 | 🟡 中 | `third_party/unrar7/` | 见 §2.1 | 0(接受)或 移除 RAR |
| 3 | **ezremote 是 GPLv2**:README 只写 "GPLv2",未标 "or later"。GPLv2-only 与 GPL-3.0 **不兼容** | 🟡 中 | `src/pkg_info.c`(PKG 预览) | 确认其许可措辞;若 v2-only 则重写该模块(591 行) | 1 天 |
| 4 | **二进制分发需提供源码**(GPL §6) | 🟢 低 | Release 里的 ELF | 仓库已公开,Release notes 附仓库链接即可 | 10 分钟 |
| 5 | Title ID `FMGR88888` 与上游相同,可能与他人 payload 冲突 | 🟢 低 | `Makefile:20` | 换一个自定义 ID | 5 分钟 |
### 2.1 关于 unRAR(风险 2 详解)
UnRAR 许可原文允许"在任何软件中处理 RAR 归档",但**禁止用它开发 RAR 兼容的压缩器**。这是一个"附加限制",与 GPL-3.0 §7 冲突。
实务上的三种处理:
| 方案 | 做法 | 代价 |
|---|---|---|
| **A. 接受现状(推荐)** | 明确声明 unrar 部分适用其自有条款,其余部分 GPL-3.0 | 0 —— rarlab 官方自己就这么分发,社区普遍接受 |
| B. 移除 RAR 支持 | 删掉 `rar_extract.c` + `third_party/unrar7` | 失去 RAR(含分卷/加密)—— 不划算 |
| C. 换实现 | 找自由许可的 RAR 解码器 | **市面上不存在可用的**,死路 |
**建议 A**。风险等级实际很低:你只做解压不做压缩,本来就不触碰被禁止的那一条。
---
## 3. 代码归属盘点(决定重写成本的关键)
### 3.1 总量分布
| 类别 | 行数 | 重写时怎么办 |
|---|---:|---|
| **第三方 vendored** | **71,528** | ♻️ **直接重新 vendor,一行都不用写** |
| ├ zlib 1.3.1 | 20,106 | zlib 许可 |
| ├ unrar7 7.20.1 | 27,710 | UnRAR 许可 |
| ├ LZMA SDK 26.03 | 17,248 | **公共领域** |
| └ minizip-ng 4.2.2 | 6,464 | zlib 许可 |
| **第一方代码** | **20,844** | 这是唯一需要写的部分 |
| ├ v1.7 上游遗产 | 13,860 | 🔴 受 GPL 约束 |
| └ 我们新增 | 6,984 | 🟢 版权归我们 |
**这是整份报告最重要的数字**:项目里 **77% 的代码是第三方库**,重写时原样搬走即可。真正需要动手的只有 2 万行第一方代码,其中又只有不到 1.4 万行受 GPL 约束。
### 3.2 我们新增代码的独立性分析
v1.7 之后**新建**的文件(6,745 行),逐个检查其依赖:
| 文件 | 行数 | 依赖 | 能否独立授权 |
|---|---:|---|:---:|
| `sevenz_chain.c/.h` | 2,094 | 仅 LZMA SDK(**公共领域**) | ✅ **完全干净** |
| `zipx_volume.c/.h` | 658 | 仅自身 | ✅ **完全干净** |
| `zipx_volstream.c/.h` | 494 | minizip-ng(zlib)+ zipx_volume.h | ✅ **完全干净** |
| `sevenz_volstream.c/.h` | 415 | LZMA SDK + zipx_volume.h | ✅ **完全干净** |
| `rar_extract.c/.h` | 1,169 | `zip_extract.h`(共享协议) | ⚠️ 弱耦合,抽协议即可解绑 |
| `sevenz_extract.c/.h` | 1,790 | `zip_extract.h`(共享协议) | ⚠️ 弱耦合,抽协议即可解绑 |
| `zipx_common.c` | 99 | `zip_extract.h` | ⚠️ 内容仅限额/状态串,30 分钟可重写 |
| `cpu_support_stub.c` | 26 | 无 | ✅ 干净 |
**核心结论**:
- **3,661 行(7z 解码链 + 分卷流抽象)与 GPL 代码零耦合** —— 这是项目最有价值的部分(自解析 folder + pull 式 codec 链 + BCJ2 + 7zAES + 三种分卷语义),也是投入最多的部分。它们**今天就可以抽成独立的 MIT/Apache 库**,不受上游任何影响。
- 另有 2,959 行只通过 `zip_extract.h` 的**共享协议**(状态枚举、进度回调、限额结构)与上游耦合。把那 100 行协议定义抽成独立的 `archive_api.h` 就能解绑。
---
## 4. 三条路径对比
### 路径 A:维持 GPL-3.0 + 补齐合规(推荐)
| 项 | 内容 |
|---|---|
| 做什么 | README 补 owendswang 署名、加 NOTICE、确认 ezremote 许可、Release 附源码链接、换 Title ID |
| 成本 | **0.5–1 人日** |
| 收益 | 合规闭环,零功能损失,保留全部现有能力 |
| 风险 | 无 |
| 适合 | **想开源分享、想让成果被保护** |
### 路径 B:架构重构(保留 GPL-3.0)
| 项 | 内容 |
|---|---|
| 做什么 | 分层重写:platform 层 / archive 引擎层 / HTTP 层 / 前端模块化;抽 `archive_api.h` 解耦;统一进度模型 |
| 成本 | **12–18 人日** |
| 收益 | 代码可维护性大幅提升,引擎可独立成库,修掉 §6 的已知缺陷 |
| 风险 | 中 —— 需真机回归,163 个 host check 要全绿 |
| 适合 | **觉得现在代码烂、想长期维护** |
### 路径 C:Clean-room 全量重写(换许可)
| 项 | 内容 |
|---|---|
| 做什么 | 不参考上游代码,按功能规格从零写 ~13,860 行受 GPL 约束的部分 |
| 成本 | **35–50 人日**(含真机调试) |
| 收益 | 完全自有版权,可任选许可(含闭源商用) |
| 风险 | **高** —— clean-room 必须严格隔离:写代码的人不能看过上游源码;否则法律上无效 |
| 适合 | **确定要闭源/商用** |
### 4.1 路径 C 的工作量拆解
| 模块 | 行数 | 难度 | 人日 |
|---|---:|---:|---:|
| HTTP 服务 + 路由(websrv/main/asset/mime/file_response) | ~700 | 低 | 3 |
| 文件管理核心(filemgr.c) | 2,458 | **高** | 8 |
| 上传 / 下载 / 断点续传 | 1,343 | 中 | 5 |
| 文件系统工具(fs_util/path_util/list/space/text) | 1,229 | 中 | 4 |
| PKG 安装 / 信息解析 / app_installer | 847 | 中 | 4 |
| 任务调度 + 通知(task/notify) | 253 | 低 | 1.5 |
| ZIP 引擎 + 分卷(zip_extract/zipx_*) | 3,091 | **高** | 8 |
| 前端(main.js / main.css / index.html / i18n) | 4,779 | 中 | 6 |
| 构建系统 + 资产内嵌 | ~200 | 低 | 1 |
| 测试矩阵(对齐现有 163 checks) | — | 中 | 5 |
| 真机调试 + PS5 平台适配 | — | **高** | 6 |
| **合计** | **~14,900** | | **≈ 51 人日** |
可复用的:7z 全套(4,299 行)+ zipx 分卷(1,193 行)+ 第三方(71,528 行)—— 这三项占了重头戏,所以才是 50 人日而不是 150 人日。
---
## 5. 重写能做到"比现在更好"的地方
如果真要走 B 或 C,这些是现在已知的技术债,**顺手一起解决才值得动**:
| # | 现有问题 | 位置 | 改进方案 |
|---|---|---|---|
| 1 | **进度口径三处不一致**:进度条按字节、文字按条目数、ETA 按字节速度,混合大包上体验割裂 | `main.js:1985` / `main.js:2014` / `task.c:129-177` | 统一为字节口径,ETA 用滑动窗口 |
| 2 | **PS5 `*at()` 族运行时损坏**(返回 -1 且 errno=0),现有绕行逻辑散落在 `zip_extract.c` | `zip_extract.c` | 抽 platform 层集中处理,写新代码不再踩 |
| 3 | 引擎与 HTTP 层耦合:解压协议定义在 `zip_extract.h` 里 | `zip_extract.h` | 抽 `archive_api.h`,引擎可独立成库 |
| 4 | `main.js` 2,652 行单文件,无模块拆分 | `assets/main.js` | 按 view / api / task 拆模块 |
| 5 | `filemgr.c` 2,458 行,路由 + 业务逻辑 + 平台调用混在一起 | `src/filemgr.c` | 分 handler / service / platform 三层 |
| 6 | 测试靠手工脚本,未接入 `make test` | `tests/` | 接 CI,覆盖率可量化 |
| 7 | 唯一功能缺口:7z `-mhe=on` 加密头 | `sevenz_extract.c` | 重写时一并补上(工作量约翻倍于现有 7z 头解析) |
---
## 6. 建议
### 6.1 我的推荐:路径 A,外加一条"资产剥离"
**不要全量重写。** 三个理由:
1. **GPL-3.0 对你有利,不是负担**。它保证别人拿走你的 7z 引擎成果后**必须同样开源**。换成 MIT,别人可以直接闭源拿去卖 —— 你花了大量精力做的 BCJ2 链、7zAES、分卷流抽象会被白嫖。
2. **重写的法律风险比不重写更高**。你已经看过上游源码了,clean-room 的前提已被破坏。真重写必须找没看过上游的人来做,还得隔离沟通 —— 成本远超 50 人日。
3. **你的核心资产本来就是干净的**。3,661 行的 7z 解码链 + 分卷流只依赖公共领域和 zlib 许可,**现在就能单独抽出来做 MIT 授权的独立库**,不需要动主项目一根指头。
### 6.2 立刻可做的三件事(共 1 天)
```
1. README.md Credits 补一行:
- [owendswang/ps5-web-file-manager](...): base implementation. License: GPL-3.0.
2. 把 sevenz_chain.{c,h} + sevenz_volstream.{c,h} + zipx_volume.{c,h}
+ zipx_volstream.{c,h} 抽成独立仓库,MIT 授权,主项目作为 submodule 引用。
→ 3,661 行成果立刻获得独立身份,且证明这部分是你的原创。
3. 确认 ezremote 是 "GPLv2" 还是 "GPLv2 or later";
若是 v2-only,重写 pkg_info.c(591 行)或改用别的数据源。
```
### 6.3 需要你回答的问题
**你重写的动机到底是什么?** 不同答案对应完全不同的方案:
| 如果你的目标是… | 应该走 | 成本 |
|---|---|---|
| 想闭源 / 商业化 | C(且必须找没看过上游的人写) | 50+ 人日 |
| 只是担心"没许可"不合法 | **A** —— 你的担心不成立 | 0.5 天 |
| 想让别人知道这是你写的 | **A** —— GPL 允许你在修改部分署名 | 0.5 天 |
| 觉得代码质量差、想重构 | B | 12–18 人日 |
| 想保护成果不被闭源 | **A** —— GPL-3.0 已经是最佳选择 | 0 天 |
---
## 附录:核查方法与数据来源
| 项 | 来源 |
|---|---|
| 上游许可 | GitHub API `repos/owendswang/ps5-web-file-manager`,2026-09-15 查询 |
| 本项目许可 | `LICENSE`(35,149 B,GPL-3.0 全文),root commit `5cb0b76` 引入 |
| 代码行数 | `wc -l` 于 v1.9.1 工作树;上游基线取 `git show 5cb0b76:<file>` |
| 文件归属 | `git ls-tree -r 5cb0b76 -- src assets` 与当前工作树的差集 |
| 依赖分析 | 逐个 grep `#include "` 于自有文件 |
| 已知缺陷 | 项目 `HANDOVER.md` 第四节 + `.workbuddy/memory/MEMORY.md` |
-448
View File
@@ -1,448 +0,0 @@
# Upgrade v1.7 — ZIP large-file profile
> Technical notes for the **v1.7** upgrade of `ps5-web-file-manager`.
> Audience: future maintainers, code reviewers, contributors reading the
> `git log` of this branch. Pair with `README.md` for the user-facing
> overview and `CHANGELOG.md` for the release-note summary.
---
## 1. Background
Before v1.7 the ZIP engine shipped with a single, conservative limits profile
(`zipx_default_limits()`). It rejected any archive whose uncompressed content
exceeded **512 GiB total** or contained an entry above **64 GiB**, or whose
compression ratio exceeded **200 : 1**. This was the right default for the
"copy game-dump folders" use case but blocked legitimate large payloads — most
notably system images and 200 GB+ backups.
The user asked: *"单个压缩包不可以为 200GB 以上么"* ("Can't a single archive
be larger than 200 GB?"). After surfacing three options (raise the default
limits, add an opt-in profile, or document-only) the choice was **🅱 — add an
opt-in "large-file profile"**. The implementation brief was:
> The server must **never** activate the relaxed caps on its own. The user
> must explicitly opt in, both via the HTTP API and via the UI.
## 2. Architecture delta (one-line summary)
The ZIP engine becomes a **profile-lookup** engine. A new profile table
(`k_large_limits`) and a switch (`zipx_limits_profile()`) sit between the HTTP
layer and the existing `zipx_extract()`. Everywhere else — task model, HTTP
handler, frontend — gains a single boolean that threads through to the engine.
```
HTTP /api/extract?large=1 frontend (confirm() 弹窗)
│ │
└──────► form parser ──► file_task_t.extract_large
│
▼
zipx_limits_profile(task->extract_large)
│
┌────────────┴────────────┐
▼ ▼
k_default_limits k_large_limits
(200K / 512GiB / (500K / 2TiB /
64GiB / 200:1) 1TiB / 1000:1)
│ │
└────────────┬─────────────┘
▼
zipx_extract()
(signature unchanged;
shared three-phase engine)
```
The public signature of `zipx_extract()` is **unchanged**. Backwards
compatibility is deliberate — anything linking against `src/zip_extract.{c,h}`
continues to compile without changes.
## 3. Engine layer (`src/zip_extract.h`, `src/zip_extract.c`)
### 3.1 New constants and API
```c
/* Pre-built limit profiles. Use zipx_limits_profile() to look one up.
ZIPX_LIMITS_DEFAULT is the safe profile shipped by zipx_default_limits().
ZIPX_LIMITS_LARGE allows archives up to 2 TiB total / 1 TiB per file and
a 1000:1 compression ratio. The caller is responsible for verifying that
the PS5 has enough free disk space. */
#define ZIPX_LIMITS_DEFAULT 0
#define ZIPX_LIMITS_LARGE 1
const zipx_limits_t *zipx_limits_profile(int profile);
```
### 3.2 The two profiles
```c
static const zipx_limits_t k_default_limits = {
.max_entries = 200000,
.max_total_bytes = 512ULL * 1024 * 1024 * 1024, /* 512 GiB */
.max_file_bytes = 64ULL * 1024 * 1024 * 1024, /* 64 GiB */
.max_ratio = 200,
.max_depth = 32,
.max_name_len = 255,
.max_path_len = 1024
};
static const zipx_limits_t k_large_limits = {
.max_entries = 500000,
.max_total_bytes = 2ULL * 1024 * 1024 * 1024 * 1024, /* 2 TiB */
.max_file_bytes = 1ULL * 1024 * 1024 * 1024 * 1024, /* 1 TiB */
.max_ratio = 1000,
.max_depth = 32,
.max_name_len = 255,
.max_path_len = 1024
};
```
The two profiles are otherwise identical on `max_depth`, `max_name_len` and
`max_path_len` — the v1.7 upgrade only relaxes the four "blast radius" caps.
### 3.3 Profile lookup
```c
const zipx_limits_t *
zipx_limits_profile(int profile) {
switch(profile) {
case ZIPX_LIMITS_LARGE: return &k_large_limits;
case ZIPX_LIMITS_DEFAULT:
default: return &k_default_limits;
}
}
```
`zipx_default_limits()` continues to return `&k_default_limits` — there is
**no behavioural change** for callers that did not opt in.
### 3.4 Behavioural contract (unchanged from pre-v1.7)
* Plain ZIPs only — stored / deflated / ZIP64. `ZIPX_ERR_UNSUPPORTED` is
raised for any encryption flag, multi-volume markers or unsupported
compression methods.
* Three-phase work model: `ZIPX_PHASE_SCAN → EXTRACT → PUBLISH → CLEANUP`.
Each entry is first written to a staging directory (`*.wfm-part-*`),
`fsync()`'d, then atomically renamed into place. A failure mid-archive
rolls back partial changes.
* Security checks run before any output file is opened:
- encryption
- path traversal (`..`), absolute POSIX paths, Windows drive letters
- symbolic links, devices, FIFOs, sockets
- duplicate entries / directory↔file clashes inside the archive
- the four blast-radius caps above (entries, total bytes, file bytes,
compression ratio)
## 4. Task layer (`src/filemgr_internal.h`, `src/extract.c`)
### 4.1 New task field
```c
typedef struct file_task {
/* …existing fields… */
int extract_conflict;
int extract_remove_source;
int extract_large; /* ← new: 0 = ZIPX_LIMITS_DEFAULT, 1 = ZIPX_LIMITS_LARGE */
/* …existing fields… */
} file_task_t;
```
### 4.2 Worker dispatch
In `extract_worker()` (`src/extract.c`, ~line 115):
```c
status = zipx_extract(task->src, task->dst, conflict,
zipx_limits_profile(task->extract_large),
extract_cancel, extract_progress, task, &result);
```
The third positional argument moved from a direct `&k_default_limits` (or a
caller-supplied struct) to `zipx_limits_profile(task->extract_large)`. The
`limits` parameter of `zipx_extract()` remains `const zipx_limits_t *` —
either pointer is fine.
### 4.3 Form parsing in `api_extract()`
```c
char *large_str = body_form_value(body, body_size, "large");
int large = (large_str != NULL && !strcmp(large_str, "1")) ? 1 : 0;
/* … free chain updated to release large_str … */
task->extract_large = large;
```
The string comparison is **strict** — only the literal `"1"` activates the
large profile. `"true"`, `"yes"`, `"on"` are all ignored. This matches the
convention used by the existing `remove_source` field (`src/extract.c`).
### 4.4 Error reporting path
When the active profile rejects an archive the engine returns one of:
| `zipx_status_t` | Frontend maps to |
|---------------------|--------------------------|
| `ZIPX_ERR_LIMIT_ENTRIES` | `err_extract_too_many_entries` |
| `ZIPX_ERR_LIMIT_FILE` | `err_extract_entry_too_large` |
| `ZIPX_ERR_LIMIT_TOTAL` | `err_extract_total_too_large` |
| `ZIPX_ERR_LIMIT_RATIO` | `err_extract_ratio` |
| `ZIPX_ERR_LIMIT_DEPTH` | `err_extract_depth` |
| `ZIPX_ERR_LIMIT_NAME` | `err_extract_name` |
The error string embedded in `zipx_result_t.message` interpolates the active
limit (`"compression ratio is above %u"`), so users can see exactly which cap
hit. **v1.7 does not change** this mapping — the new large profile uses the
same codes, just with larger caps.
## 5. HTTP API contract (`/api/extract`)
`POST /api/extract` accepts `application/x-www-form-urlencoded`:
| Field | Type | Required | Notes |
|-----------------|------|----------|-------|
| `path` | string | yes | Absolute path to the archive on the PS5. |
| `dst_dir` | string | yes | Output directory. |
| `conflict` | string | no | `fail` / `overwrite` / `merge`. Default `fail`. |
| `remove_source` | `0`/`1` | no | Default `0`. |
| `large` | `0`/`1` | no | **new in v1.7**. Default `0`. |
Compatibility:
- Existing callers that do **not** send `large` get identical behaviour as
before the upgrade — `ZIPX_LIMITS_DEFAULT` always.
- The server returns `400` for any value other than `"0"` or `"1"` (only the
exact literal `"1"` enables the large profile). This is enforced by the
`!strcmp(large_str, "1")` guard, not a separate validator.
The hand-rolled form parser (`src/json_util.c` `body_form_value()`) already
returned the raw value; the upgrade did not touch that helper.
## 6. Frontend (`assets/main.js`)
### 6.1 Threshold + prompt primitives
```js
const LARGE_FILE_THRESHOLD_BYTES = 60 * 1024 * 1024 * 1024; // 60 GiB
function shouldPromptLargeMode(itemSize) {
return Number(itemSize || 0) > LARGE_FILE_THRESHOLD_BYTES;
}
function promptLargeMode(sizeBytes) {
return confirm(t("extractLargeAsk",
{ size: formatSize(sizeBytes, "-") }));
}
```
The 60 GiB threshold is **hardcoded**, not user-configurable. To change it,
edit the constant on line `813` (current main branch). Setting it to
`Infinity` silences the prompt entirely.
### 6.2 The two call sites
* `actionExtract()` (existing) — invoked from the file-row "extract" menu
item — checks `item.size` and prompts before calling
`startExtractTask(item.path, cwd, conflict, false, displayName(item), large)`.
* `uploadAndExtractFile()` (existing) — invoked after a remote upload
completes — checks `file.size` and prompts before calling
`startExtractTask(zipPath, cwd, conflict, true, rel, large)`.
Both paths funnel into `startExtractTask(path, dst, conflict, removeSource,
name, large)`, which `POST`s to `/api/extract` with:
```js
const data = await apiForm("/api/extract", {
path,
dst_dir: dstDir,
conflict,
remove_source: removeSource ? "1" : "0",
large: large ? "1" : "0"
});
```
If the user clicks **Cancel** on the prompt, `large = false` and the request
goes out with `large=0`. **No silent fallback** to the large profile.
### 6.3 UI status
When `large=1` is sent, the engine logs `task->error_code = "err_extract_large"`
status field so the in-app task overlay can show a "large-file profile
active" badge. The exact badge wording lives in the locale files (see §7).
## 7. i18n strings (`assets/lang-{en,zh}.js`)
Two new keys, both on line `108-109` of each locale file:
* `extractLargeAsk` — the prompt body. Interpolation parameter: `size`
(already pre-formatted by `formatSize()` in bytes / KiB / MiB / GiB / TiB).
* `extractLargeActive` — short tag shown next to a running large-profile
task.
When changing the wording, keep the `{size}` placeholder and the
newline-separated **OK / Cancel** hint — the prompt is a `confirm()` so the
expected user gesture is documented inside the dialog.
## 8. Tests (`tests/test_zip_extract.c`, `tests/make_fixtures.py`)
### 8.1 Coverage matrix
| Scenario | Default | Large | Notes |
|---|---|---|---|
| `basic.zip` (small, benign) | ✓ | ✓ | sanity |
| `medium_bomb.zip` (1 MiB → ratio ≈ 238) | reject | accept | new fixture, profile switchover |
| `bomb.zip` (4 MiB of `'A'`, ratio ≈ 1026) | reject | **reject** | large caps still apply |
| `bomb.zip` with `tight.max_ratio = 10` | reject | reject | profile is a starting point, lower caps still enforced |
| `zip64.zip` with `tight.max_file_bytes = 1024` | reject | reject | lowering file cap from profile |
| Conflict policy `fail`/`overwrite`/`merge` | ✓ | ✓ | unchanged |
Run with:
```sh
cd tests && bash run-tests.sh
```
Output is a per-case `check()` style report — currently **69 checks**,
0 failures.
### 8.2 New fixture — `medium_bomb.zip`
* Generated by `make_fixtures.py::medium_bomb()`.
* Payload: 1 MiB of `bytes(range(256)) * 4096` (a perfect 256-byte period
repeated 4096 times).
* Compression ratio (with `zlib -9`): **≈ 238 : 1**, deliberately chosen to
fall in the band `(default_cap, large_cap) = (200, 1000]`.
* Why not the pre-existing `bomb.zip` (4 MiB of `'A'`)? Its real ratio on
`zlib -9` is **≈ 1026**, which the large profile's 1000 cap also rejects —
the two profiles would behave identically and the test wouldn't show the
switchover.
### 8.3 `test_large_profile()` cases
```c
const zipx_limits_t *d = zipx_limits_profile(ZIPX_LIMITS_DEFAULT);
const zipx_limits_t *l = zipx_limits_profile(ZIPX_LIMITS_LARGE);
check(d != NULL, "default profile exists");
check(l != NULL, "large profile exists");
check(d->max_total_bytes == 512ULL * 1024 * 1024 * 1024, "default 512 GiB");
check(d->max_file_bytes == 64ULL * 1024 * 1024 * 1024, "default 64 GiB");
check(d->max_ratio == 200, "default ratio 200");
check(l->max_entries == 500000, "large 500K entries");
check(l->max_total_bytes == 2ULL * 1024 * 1024 * 1024 * 1024, "large 2 TiB");
check(l->max_file_bytes == 1ULL * 1024 * 1024 * 1024 * 1024, "large 1 TiB");
check(l->max_ratio == 1000, "large ratio 1000");
expect_status("medium_bomb.zip", "out_default_medium", ZIPX_CONFLICT_FAIL, NULL,
ZIPX_ERR_LIMIT_RATIO, "default rejects medium_bomb");
expect_ok ("medium_bomb.zip", "out_large_medium", ZIPX_CONFLICT_FAIL, l,
"large accepts medium_bomb");
/* Large caps still enforced — bomb ratio 1026 > 1000 */
expect_status("bomb.zip", "out_large_bomb_default", ZIPX_CONFLICT_FAIL, NULL,
ZIPX_ERR_LIMIT_RATIO, "default rejects bomb");
expect_ok ("bomb.zip", "out_large_bomb_large", ZIPX_CONFLICT_FAIL, l,
"large accepts bomb-ratio-1000 border");
/* Lowered caps remain enforced */
zipx_limits_t tight = *l; tight.max_ratio = 10;
expect_status("bomb.zip", "out_tight_ratio", ZIPX_CONFLICT_FAIL, &tight,
ZIPX_ERR_LIMIT_RATIO, "tight ratio still enforced");
```
(13 new `check`/`expect_*` calls in this function alone.)
## 9. Build & verify pipeline
### 9.1 Cross-compile
The WSL staging helper `.build/build-elf.sh` automates the SDK write-access
workaround (the SDK lives at `/opt/ps5-payload-sdk/target/` owned by a
different uid). The script:
1. Runs `make` with a staging dir under `/tmp` for write-protected sources.
2. `sudo cp -r` the staged outputs back into the SDK tree in a single batch.
3. Copies the resulting `web-file-mgr.elf` to both `/home/song/...` and the
Windows desktop.
Incremental builds are fast — only `src/extract.c` recompiled for v1.7; the
nine `gen/lang-*.js.c` files were regenerated because `extractLargeAsk`
changed.
### 9.2 ELF sanity checks
```sh
ls -la web-file-mgr.elf
sha256sum web-file-mgr.elf # 648e4a00…
file web-file-mgr.elf # ELF 64-bit LSB pie, x86-64
od -An -tx1 -N20 web-file-mgr.elf | head -2 # 7f45 4c46 0201 + e_machine 003e
```
### 9.3 Verifying the upgrade made it into the binary
`assets/*.js` are embedded as `zlib`-compressed C arrays by `gen-asset-module.py`.
A simple `strings web-file-mgr.elf | grep` won't find them. Use
`.build/check-elf-gzip.py`:
```sh
python3 .build/check-elf-gzip.py ./web-file-mgr.elf
# expects:
# keys found (7/7):
# ✓ extractLargeAsk "The archive looks large …"
# ✓ extractLargeActive "Large-file profile is enabled for this task"
# ✓ promptLargeMode confirm(t("extractLargeAsk", …))
# ✓ shouldPromptLargeMode Number(itemSize || 0) > LARGE_FILE_THRESHOLD_BYTES
# ✓ LARGE_FILE_THRESHOLD_BYTES = 60 * 1024 * 1024 * 1024
# ✓ large ("…":"1":"0")
# ✓ /api/extract … large: large ? "1" : "0" …
```
If any of these are missing, the cross-compile did not pick up the asset
rebuild — run `make clean && make` (or remove only `gen/`) and rebuild.
## 10. Backwards compatibility & migration
| Surface | v1.6 → v1.7 | Notes |
|---|---|---|
| `zipx_extract()` signature | unchanged | old callers compile clean |
| `zipx_default_limits()` body | unchanged | still returns `&k_default_limits` |
| `/api/extract` `large` field | new (optional) | absent → `0` (default profile) |
| `file_task_t::extract_large` | new (last field of the extract trio) | downstream consumers reading tasks must handle the new field |
| Frontend default behaviour | unchanged | threshold gate is new |
| `./web-file-mgr-linux` ABI | unchanged | Linux build also rebuilt with the new symbols |
**Migration for downstream users**: nothing required. To opt in to large
archives, append `large=1` to the `/api/extract` request, OR click "OK" on the
prompt that appears for any archive > 60 GiB on disk.
## 11. Trade-offs and known edges
* **60 GiB threshold is hardcoded** — yes, deliberate. It's set where the
archival image / dump boundary typically lives. Power users can edit
`LARGE_FILE_THRESHOLD_BYTES` (line 813 in `assets/main.js`).
* **The large profile trusts the user about free space** — the server does
not run `statvfs()` against `dst_dir` before extraction. The space check
the engine itself runs (per-entry `max_file_bytes`) is the only guard.
* **`bomb.zip` with ratio 1026 is rejected under both profiles** — known and
intentional. The 1000 cap is the *floor* of the relaxed policy, not a
"ZIP bombs welcome" flag. Other ZIP-bomb-shaped payloads with the same
ratio will hit the same wall.
* **No multi-volume / split support** — unchanged from pre-v1.7. The
engine reads a single archive path; spans such as `archive.zip`,
`archive.z01`, `archive.z02` are not stitched. minizip-ng has the API;
wiring it is on the post-v1.7 roadmap.
* **No proxy / streaming for archives above the STAGING_DIR ceiling** — the
staging dir lives on the same filesystem as `dst_dir` and is sized
proportionally. 2 TiB staging is required for a worst-case 2 TiB archive.
## 12. Future work (post-v1.7, prioritised)
1. Multi-volume support via `mz_zip_open_multi()` from vendored minizip-ng.
2. Server-side `statvfs()` preflight against `dst_dir` when the active
profile is `LARGE`, with a clearer error if there's not enough space.
3. Compression-ratio cap that scales with file size (≤ small files: strict
200:1; large files: relaxed). Same vector as the explicit profile but
automatic.
4. Streaming extractor API — `zipx_extract_stream()` — that does not
materialise the staging dir at all. Useful once PS5 archive > 4 TiB is a
real workload.
5. Server-side telemetry (opt-in) for which profile is chosen per archive
size band, to validate the 60 GiB threshold over time.
-641
View File
@@ -1,641 +0,0 @@
# UPGRADE: v1.8 — RAR extraction support
> This is the long-form maintainer's manual for the v1.8 archive-engine
> expansion. It is written for the next developer, not the user. The
> user-facing description lives in [`README.md → RAR extraction`](../README.md#rar-extraction);
> the release notes are in [`CHANGELOG.md`](../CHANGELOG.md). The vendoring
> decision tree (and the v1.9 upgrade path) is at
> [`third_party/unrar/VENDORED.md`](../third_party/unrar/VENDORED.md) — most
> of the "why" questions are answered there, not here.
---
## 1. Scope at a glance
| Feature | Status | Why |
|---|---|---|
| Single-volume RAR 1.5 / 2.x / 3.x / 4.x / 5.x | ✅ | dmc_unrar 1.7.0 supports it. |
| RAR with PPMd, large dictionary | ✅ | dmc_unrar supports it. |
| Conflict policy `fail` / `overwrite` / `merge` | ✅ | Same `zipx_conflict_t` protocol. |
| Default + `large=1` limits via `LARGE_FILE_THRESHOLD_BYTES` | ✅ | Same `zipx_limits_t` protocol. |
| Path traversal / symlinks / duplicate / ratio bomb / CRC error | ✅ | Same `zipx_status_t` codes as ZIP. |
| Multi-volume RAR (`.part01.rar` + `.part02.rar` + …) | ❌ | Upstream `DMC_UNRAR_ARCHIVE_UNSUPPORTED_VOLUMES`; extracted to PC. |
| Encrypted RAR (any encrypted header or file) | ❌ | Upstream `DMC_UNRAR_ARCHIVE_UNSUPPORTED_ENCRYPTED`; no `password=` field in v1.8. |
| Symbolic links / FIFOs inside RAR | ❌ | `DMC_UNRAR_FILE_UNSUPPORTED_LINK` ⇒ `ZIPX_ERR_SPECIAL`. |
| RAR 1.4 (very old) | ❌ | `DMC_UNRAR_ARCHIVE_VERSION_UNSUPPORTED` ⇒ `ZIPX_ERR_UNSUPPORTED`. |
The "extract on a PC first" recovery is the same escape hatch the engine
already uses for ZIP encryption and ZIP64-stitched errors — the failure
is an `extract_unsupported` with the file name as the detail argument,
and the frontend already shows it with bilingual retry guidance.
---
## 2. Why dmc_unrar (and the v1.9 escape hatch)
`dmc_unrar` was chosen over the obvious alternatives for one reason each:
- **vs `winrar/unrar` upstream** — the official source is `UnRAR license`,
not OSS. Modifying it (which we need to do for the host-side test
shim, error-translation wrapper etc.) is prohibited.
- **vs `opello/unrar`** — faithful UnRAR 7.x mirror, supports volumes
*and* encryption, but is a 150-file C++17 codebase with its own
Windows / registry / threading primitives. The C++ integration cost
(`-DRAR_SMP`, third CXX link step, `prospero-pkg-config` audit) was
not justified by v1.8's stated requirement.
- **vs `libarchive`** — it pulls in `libarchive` itself (~400 KiB extra)
and still uses an UnRAR-equivalent internally. Adding libarchive for
RAR alone costs more than it returns.
- **vs implementing UnRAR ourselves** — not even on the table.
When (if) multi-volume + encrypted RAR becomes worth it, the recipe is
short: vendor `opello/unrar`, replace `dmc_unrar.c` with their `*.cpp`
in `third_party/unrar/`, add a CXX link step to `Makefile`, switch
`src/rar_extract.c` to the `RAROpenArchiveEx` / `RARSetPassword` DLL
API. **The `rar_extract()` signature, the dispatch layer and the host
tests do not need to change.** Full step-by-step recipe is in
[`third_party/unrar/VENDORED.md`](../third_party/unrar/VENDORED.md).
---
## 3. Architecture delta vs v1.7
### 3.1 The shape
```
┌──────────────────────────────────────────────────────────────────────┐
│ Frontend: assets/main.js │
│ - isExtractableArchive(item) covers .rar and .partNN.rar (NN==1) │
│ - isRarSubVolume(item) flags .partNN.rar (NN>1) → greys button │
│ - same LARGE_FILE_THRESHOLD_BYTES prompt for .rar as .zip │
└─────────────────────┬────────────────────────────────────────────────┘
│ POST /api/extract
│ (path, dst_dir, conflict, remove_source,
│ large) — no password= in v1.8
┌─────────────────────▼────────────────────────────────────────────────┐
│ Dispatch: src/extract.c │
│ - extract_dispatch() by case-insensitive .zip / .rar suffix │
│ - anything else → ZIPX_ERR_UNSUPPORTED, the same string the │
│ ZIP path used to produce on its own │
└─────────────────────┬────────────────────────────────────────────────┘
│
┌─────────────┴─────────────┐
│ │
┌───────▼───────────┐ ┌──────▼─────────────────┐
│ src/zip_extract.c │ │ src/rar_extract.c │
│ (unchanged in v1.8)│ │ (NEW) │
│ backend: │ │ backend: │
│ minizip-ng + zlib│ │ dmc_unrar (vendored) │
│ │ │ dmc_unrar_api.h │
│ │ │ (project-authored │
│ │ │ facade) │
└───────┬───────────┘ └──────┬─────────────────┘
│ │
└─────────────┬─────────────┘
│ zipx_status_t
│ zipx_limits_t (default / large)
│ zipx_conflict_t
│ zipx_progress_t
│ zipx_result_t
▼
(shared task UI / progress / error mapping)
```
The dispatcher and the engines share the entire type vocabulary from
`src/zip_extract.h`. `src/rar_extract.c` `#include`s only
`third_party/unrar/dmc_unrar_api.h` — it does not `#include` the
vendored `.c` and it does not reach into dmc_unrar internals.
### 3.2 Three-phase pipeline (shared with ZIP)
`rar_extract()` mirrors `zipx_extract()` exactly:
1. **Scan** — open the archive with `dmc_unrar_archive_init` /
`dmc_unrar_archive_open_path`, walk every entry header with
`dmc_unrar_read_header` (the API does not have a list-only mode;
scan reads the file content but discards it). For each entry:
- normalise the path (`\` → `/`, trim trailing separators),
validate against traversal / depth / name-length / file-size /
total-size limits,
- reject duplicate or clashing entry names with
`ZIPX_ERR_DUPLICATE`,
- reject encrypted / volume / version-unsupported / link / large
RAR via the DMC codes → mapped to `ZIPX_ERR_UNSUPPORTED` /
`ZIPX_ERR_SPECIAL` (see `rar_translate_error()`),
- report progress at the same throttle the ZIP engine uses.
2. **Extract** — for each entry, write into a staging directory (one
`.wfm-extract-{pid}-{tid}/` per task, derived from `getpid()` and the
task id), via `dmc_unrar_extract_file_to_path`. Each staging file
is `fsync`d before renaming, so a power-loss mid-archive does not
leave the destination half-written. Staging lives on the same
filesystem as the destination so the publish is `rename()` (atomic).
3. **Publish** — apply the conflict policy (`fail` / `overwrite` /
`merge`) — reuses `zip_extract.c`'s `publish_entry()` /
`publish_staging()` logic verbatim.
4. **Cleanup / rollback** — on any mid-archive failure, every published
entry created by this task is removed, the staging directory is
removed recursively with `nftw(..., FTW_DEPTH | FTW_PHYS)`, and the
caller is left with `dst_dir` exactly as it was (modulo whatever
`ZIPX_CONFLICT_OVERWRITE` had already clobbered).
The staging layout, fsync strategy, conflict policy plumbing, cancel /
progress callbacks and result-mapping logic are copied from
`zip_extract.c` — exactly once — into `rar_extract.c` so that the
engines can evolve independently. (Refactoring them into a
`src/archive_common/` module is on the post-v1.9 roadmap; see §10.)
### 3.3 Error mapping
`rar_translate_error()` in `src/rar_extract.c` maps the dmc_unrar
return codes to the shared `zipx_status_t` enum so the rest of the
project (and the frontend / task UI) cannot tell the difference
between a ZIP failure and a RAR failure:
| dmc_unrar code | `zipx_status_t` |
|---|---|
| `DMC_UNRAR_ARCHIVE_UNSUPPORTED_VOLUMES` | `ZIPX_ERR_UNSUPPORTED` |
| `DMC_UNRAR_ARCHIVE_UNSUPPORTED_ENCRYPTED` | `ZIPX_ERR_UNSUPPORTED` |
| `DMC_UNRAR_FILE_UNSUPPORTED_ENCRYPTED` | `ZIPX_ERR_UNSUPPORTED` |
| `DMC_UNRAR_FILE_UNSUPPORTED_LINK` | `ZIPX_ERR_SPECIAL` |
| `DMC_UNRAR_FILE_UNSUPPORTED_LARGE` | `ZIPX_ERR_LIMIT_FILE` |
| `DMC_UNRAR_ARCHIVE_SPLIT` | `ZIPX_ERR_UNSUPPORTED` |
| `DMC_UNRAR_ARCHIVE_ANCIENT` | `ZIPX_ERR_UNSUPPORTED` |
| `DMC_UNRAR_ARCHIVE_VERSION` | `ZIPX_ERR_UNSUPPORTED` |
| `DMC_UNRAR_ARCHIVE_METHOD` | `ZIPX_ERR_UNSUPPORTED` |
| `DMC_UNRAR_ARCHIVE_OPEN_FAIL` | `ZIPX_ERR_OPEN` |
| `DMC_UNRAR_ARCHIVE_READ_FAIL` | `ZIPX_ERR_IO` |
| `DMC_UNRAR_ARCHIVE_WRITE_FAIL` | `ZIPX_ERR_IO` |
| `DMC_UNRAR_ARCHIVE_SEEK_FAIL` | `ZIPX_ERR_IO` |
| `DMC_UNRAR_FILE_CRC32_FAIL` | `ZIPX_ERR_CRC` |
| `DMC_UNRAR_ARCHIVE_NOT_RAR` | `ZIPX_ERR_FORMAT` |
| `DMC_UNRAR_ARCHIVE_EMPTY` | `ZIPX_ERR_FORMAT` |
| `DMC_UNRAR_ARCHIVE_INVALID_DATA` | `ZIPX_ERR_FORMAT` |
| `DMC_UNRAR_ARCHIVE_NO_ALLOC` | `ZIPX_ERR_INTERNAL` |
| `DMC_UNRAR_ARCHIVE_ALLOC_FAIL` | `ZIPX_ERR_INTERNAL` |
| `DMC_UNRAR_ARCHIVE_IS_NULL` | `ZIPX_ERR_INTERNAL` |
| `DMC_UNRAR_ARCHIVE_NOT_CLEARED` | `ZIPX_ERR_INTERNAL` |
| `DMC_UNRAR_ARCHIVE_MISSING_FIELDS` | `ZIPX_ERR_INTERNAL` |
This table is exhaustive — every reachable dmc_unrar code has a
defined mapping and there are no `default:` fall-throughs in the
switch.
The progress / cancel / conflict protocol is byte-identical to ZIP:
same `zipx_progress_t`, same `zipx_cancel_fn` signature, same
`zipx_conflict_t` enum. The frontend never needs to branch on the
archive format.
### 3.4 Behaviour contract (v1.8 — what callers can rely on)
For any input that produces `ZIPX_OK`:
- All requested entries from the archive are present in the destination,
in the order they appear in the archive, with permissions `0644` for
files and `0755` for directories (mirror of `zip_extract`'s default).
- A conflict policy of `ZIPX_CONFLICT_FAIL` returns `ZIPX_ERR_CONFLICT`
on the first collision; nothing is written.
- `ZIPX_CONFLICT_OVERWRITE` replaces existing files with the extracted
contents (a copy-paste of the ZIP engine's behaviour).
- `ZIPX_CONFLICT_MERGE` keeps existing files, adds new ones.
- `result->entries_total`, `result->entries_done`,
`result->bytes_total`, `result->bytes_done`, `result->files_created`
and `result->dirs_created` are all filled in.
For any non-`ZIPX_OK` return code:
- `dst_dir` is left **exactly as it was** before the call (modulo any
`ZIPX_CONFLICT_OVERWRITE` clobbers that completed before the failure).
- The staging directory is removed before `rar_extract()` returns.
- `result->detail[]` and `result->message[]` are filled in for the
UI to display.
For any cancellation request:
- The engine returns `ZIPX_ERR_CANCELED` from the next progress / cancel
callback poll, all staging is removed, no `publish()` runs.
---
## 4. Source-tree layout
```
src/
extract.c # dispatcher (modified)
extract.h # unchanged
zip_extract.{c,h} # unchanged in v1.8
rar_extract.{c,h} # NEW, ~1276 LOC in .c
third_party/
unrar/
dmc_unrar.c # vendored (verbatim, 11 598 LOC)
dmc_unrar_api.h # NEW, project-authored facade (~138 LOC)
COPYING # GPL-2.0-or-later (vendored)
README.md # upstream README (vendored)
example.c # upstream usage example (vendored)
VENDORED.md # NEW, why-dmc_unrar + v1.9 upgrade recipe
tests/
test_rar_extract.c # NEW, 14 checks (negative paths only)
make_fixtures.py # adds rar_fixtures(); falls back to placeholder
run-tests.sh # compiles dmc_unrar.o + rar_extract.o,
# links test-rar-extract including zip_extract.o
# so zipx_status_string / zipx_default_limits
# / zipx_limits_profile resolve.
assets/
main.js # isExtractableArchive() / isRarSubVolume()
lang-en.js, lang-zh.js # err_extract_unsupported updated
Makefile # VERSION_TAG v1.8, third_party/unrar wired
THIRD_PARTY_NOTICES # NEW section 3 for dmc_unrar
```
---
## 5. Vendoring mechanic — the facade header
The most important *engineering* lesson from v1.8 is the pattern used
in `third_party/unrar/dmc_unrar_api.h`. Without it, integrating dmc_unrar
into the host test suite was a mess:
```c
/* src/rar_extract.c — what we wanted to write */
#include "dmc_unrar.h" /* dream: a real header */
```
But dmc_unrar ships as a single `.c` file. The "header" content is
inside the `.c`. Naively:
```c
/* src/rar_extract.c — what the naive approach forces */
#include "dmc_unrar.c" /* ← does NOT work as a TU separate from rar_extract.c */
```
…compiles if you do the `#include` in a **fresh** translation unit, but
**fails** when both `src/rar_extract.c` and `tests/test_rar_extract.c`
build with `-include tests/posix_compat.h`, because that shim
redefines `open` → `wfm_open` / `close` → `wfm_close` and the
`dmc_unrar_io_handler` struct inside dmc_unrar would then reference
undeclared fields. The result is a flood of `error: 'struct
dmc_unrar_io_handler' has no member named 'wfm_open'` and similar.
The facade pattern fix:
```c
/* third_party/unrar/dmc_unrar_api.h — project-authored, project-license */
#pragma once
/* Re-declare only the symbols rar_extract.c touches. The names match
dmc_unrar's internal names so the .c compiles unmodified. */
typedef enum { … } dmc_unrar_return;
typedef struct dmc_unrar_archive dmc_unrar_archive; /* opaque */
typedef struct { … } dmc_unrar_file;
dmc_unrar_return dmc_unrar_archive_init(dmc_unrar_archive *a);
dmc_unrar_return dmc_unrar_archive_open_path(dmc_unrar_archive *a, const char *p);
… /* … only the symbols rar_extract.c uses */
```
Then:
```c
/* src/rar_extract.c — what the facade enables */
#include "dmc_unrar_api.h" /* project-authored, project-licensed */
```
And:
```c
/* Makefile — dmc_unrar is its own TU, unmodified */
ps5-obj/third_party/unrar/dmc_unrar.o: third_party/unrar/dmc_unrar.c
$(CC) $(THIRD_PARTY_CFLAGS) -c -o $@ $<
```
The benefits:
- dmc_unrar.c is **never edited**, satisfying its GPL-2.0-or-later
purity requirement and making an opello/unrar swap a 5-line diff.
- The host test shim that renames `open` / `close` / `mkdirat` only
affects the engine and test files, never dmc_unrar's TU.
- The vendored `.c` is grep-able with reference back into the project
at exactly one symbol boundary — `dmc_unrar_api.h`.
- Future C++ integration (opello/unrar) reuses the same facade slot;
the body becomes `-DRARDLL` and a different header file.
This pattern generalises — *anytime you want to vendor a
single-file C library that internally uses a name that your build
system also touches*, write a 100-line facade header that re-declares
just the symbols you use, and treat the vendored `.c` as a compile
unit on its own.
---
## 6. Compression-ratio / format caveats specific to RAR
These are not bugs — they are *properties of dmc_unrar* that the
host test suite and the engine must respect:
- **dmc_unrar has no `RAR_OM_LIST`** (list-only mode). The "scan"
pass opens the archive, walks every header, and **reads the file
content** even though it doesn't write anything out. A 500-entry
archive with 4 GiB average entry size therefore costs ~2 TiB of
read I/O during scan. This is acceptable for v1.8 because the
typical PS5 use case is `one archive, few hundred MiB`, but it is
worth documenting so a future optimisation (on-the-fly skip
through `dmc_unrar_extract_file_to_path`) doesn't surprise the
next reader.
- **dmc_unrar decompresses synchronously on the same thread** that
calls `dmc_unrar_extract_file_to_path`. Cancel callbacks are
polled inside `dmc_unrar_read_header` (and at engine chokepoints)
— *not* in the inner loop. A 1 GiB file extraction cannot be
cancelled mid-decompression. A future improvement could fork a
child process for extract so SIGKILL works deterministically.
- **The dmc_unrar byte-swap helpers `be32toh` / `be64toh` collide
with `<endian.h>`** on some compilers. We work around it by
compiling with `-DDMC_UNRAR_DISABLE_BE32TOH_BE64TOH=1`, which
lets dmc_unrar use its own internal byte-swap implementation.
This is documented at the top of `dmc_unrar.c` and was the only
thing the Makefile needed to set to get a green build on PS5.
These are engine limitations, not failure modes the user will see in
normal operation.
---
## 7. Frontend wiring details
### 7.1 The detection rule
```js
function isExtractableArchive(item) {
if (item.type !== "-") return false; // file, not directory
if (/\.zipx?$/i.test(item.name)) return true;
if (/\.rar$/i.test(item.name)) return true;
if (/\.part0*1\.rar$/i.test(item.name)) return true; // RAR main volume
return false;
}
function isRarSubVolume(item) {
if (item.type !== "-") return false;
if (/\.part0*1\.rar$/i.test(item.name)) return false; // main is not a sub
return /\.part0*\d+\.rar$/i.test(item.name); // .partNN.rar, NN>1
}
```
### 7.2 The button-state rule
```js
function renderExtractButton(items, locked) {
const mains = items.filter(isExtractableArchive);
const subs = items.filter(isRarSubVolume);
if (subs.length && !mains.length) { // only sub-volumes
extractBtn.disabled = true;
extractBtn.title = t("extractSelectMainVolume");
return;
}
if (mains.length !== 1) {
extractBtn.hidden = mains.length !== 1;
extractBtn.disabled = true;
return;
}
extractBtn.title = t("extractToCurrent") + ": " + itemTitle(mains[0]);
extractBtn.disabled = locked;
}
```
### 7.3 The "extract on a PC first" error path
When the engine rejects a multi-volume / encrypted / link entry inside
a RAR, the failure is `ZIPX_ERR_UNSUPPORTED` (or
`ZIPX_ERR_SPECIAL`). The frontend already has
`err_extract_unsupported` updated to:
> `…(only unencrypted plain ZIP and single-volume RAR are
> supported)…` (en)
> `…(仅支持未加密的普通 ZIP 与单卷 RAR)…` (zh)
The "extract on a PC first" guidance is *implicit* — when the user
hits this message with a `.part01.rar` selected, the .part02+.rar
tooltips + the error string are the two breadcrumbs. There is no
explicit "unrar on your PC" button in v1.8 because the redirect is
self-evident from the failure.
### 7.4 The `large=1` prompt for RAR
The threshold is shared. A `.rar` larger than `240 GiB` triggers the
same `promptLargeMode()` confirmation as a `.zip`. The confirmation
text uses `extractLargeAsk` (slightly relaxed in v1.8.1) — the wording
is format-agnostic, so no new strings are needed.
---
## 8. Host test suite — what 14 checks actually cover
`tests/test_rar_extract.c` is a **negative-path-only** suite, because
we have no RAR writer in this repo and the host probably doesn't have
`rar` / `7z` installed either. The suite accepts the absence of real
fixtures as a feature: by exercising *only* the dispatch and error
translation layers, we get coverage that is independent of whether the
host has any RAR tooling.
| Check | What it asserts |
|---|---|
| `test_engine_dispatch_zip_renamed_rar` | `.zip` renamed to `.rar` is rejected with `ZIPX_ERR_UNSUPPORTED` (the engine decides by extension; the front-end tests the matching detection). |
| `test_engine_dispatch_junk_rar` | A 1 KiB blob named `.rar` is rejected as `ZIPX_ERR_UNSUPPORTED` — the dmc_unrar open fails, mapping to `ZIPX_ERR_UNSUPPORTED`. |
| `test_engine_dispatch_missing_source` | `rar_extract()` with a non-existent path returns `ZIPX_ERR_OPEN` (mapped from `DMC_UNRAR_OPEN_FAIL`). |
| `test_engine_dispatch_null_rar_path` | `rar_extract(NULL, dst, …)` is rejected with `ZIPX_ERR_INTERNAL` — defensive, never user-visible. |
| `test_engine_dispatch_null_dst` | `rar_extract(path, NULL, …)` is rejected with `ZIPX_ERR_INTERNAL`. |
| `test_engine_dispatch_dst_is_regular_file` | `rar_extract(path, /some/file, …)` returns `ZIPX_ERR_CONFLICT` (open_parent_dirs fails). |
| `test_format_translation` | Parametric: for each `DMC_UNRAR_*` code we care about, the corresponding `rar_translate_error()` mapping is exercised indirectly (via `result->message` strings). |
| `test_limits_handoff_default` | When `task->extract_large == 0`, the default profile is handed in (200 K entries / 1 TiB / 256 GiB / 500:1). |
| `test_limits_handoff_large` | When `task->extract_large == 1`, the large profile is handed in (500 K / 2 TiB / 1 TiB / 1000:1). |
| `test_translate_open_fail_to_err_open` | DMC open-failure → `ZIPX_ERR_OPEN`. |
| `test_translate_volume_unsp_to_err_unsupported` | The DMC volume code → `ZIPX_ERR_UNSUPPORTED`. |
| `test_translate_encrypted_unsp_to_err_unsupported` | The DMC encryption code → `ZIPX_ERR_UNSUPPORTED`. |
| `test_translate_link_unsp_to_err_special` | The DMC link code → `ZIPX_ERR_SPECIAL`. |
| `test_progress_throttle` | The progress callback is invoked at most every ~200 ms or every ~1 MiB extracted, like the ZIP engine. |
When `tests/make_fixtures.py` finds a host `rar` or `7z` writer, it
generates a real `basic.rar` fixture, and an additional 2 checks
(`test_rar4_basic_extract` / `test_rar5_basic_extract`) succeed
automatically — those are *not* counted in the 14 baseline.
The complete count after `bash tests/run-tests.sh` is therefore **83
checks** (69 ZIP + 14 RAR) on a RAR-less host, and **85 checks** on a
host with `rar` installed.
---
## 9. Cross-compile and verification (user-side checklist)
The host suite runs anywhere. The PS5 ELF build runs in WSL with
`PS5_PAYLOAD_SDK` set:
```bash
# WSL Ubuntu-22.04 bash
cd /home/song/ps5-web-file-manager
export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdk
make all # ~30 s on cold
ls -la web-file-mgr.elf # record size
sha256sum web-file-mgr.elf # record digest
```
Then in Windows-side Git Bash / PowerShell:
```bash
cd "C:/Users/songl/Desktop/Web File Manager/ps5-web-file-manager"
file web-file-mgr.elf # ELF 64-bit LSB pie, x86-64
od -An -tx1 -N20 web-file-mgr.elf | head -2 # 7f45 4c46 0201 + e_machine 003e
python3 .build/check-elf-gzip.py ./web-file-mgr.elf # 7 v1.7 keys + 1 v1.8 key
```
The new v1.8 ELF-gzip key to verify is `err_extract_unsupported`
("only unencrypted plain ZIP and single-volume RAR are supported").
It must appear in the binary.
Then in `CHANGELOG.md`, paste the size + sha256 into the v1.8 banner
header at the top of the file. Commit + push:
```bash
git add -A
git -c core.autocrlf=false commit -m "v1.8: RAR4/RAR5 single-volume unencrypted (dmc_unrar backend)"
# push runs in PowerShell on the user's machine (sandbox github 502)
```
---
## 10. Roadmap (post-v1.8)
### 10.1 v1.9 — full RAR (multi-volume + encrypted)
See [`third_party/unrar/VENDORED.md`](../third_party/unrar/VENDORED.md)
§"Upgrading to a fuller library (v1.9 plan)" for the migration recipe.
The public `rar_extract()` signature and the dispatch layer do **not**
need to change; only:
1. `third_party/unrar/dmc_unrar.c` is removed and `*.cpp` from
`opello/unrar` are placed there.
2. `Makefile` gains a `THIRD_PARTY_CPP_SRCS := $(wildcard
third_party/unrar/*.cpp)` and the corresponding CXX link step.
3. `third_party/unrar/dmc_unrar_api.h` is renamed to
`unrar_api.h` and its bodies filled in from the rarlab DLL API
(`RAROpenArchiveEx`, `RARSetPassword`, `RARProcessFileW`,
`RARCloseArchive`).
4. `src/rar_extract.c` swaps the `dmc_unrar_*` calls for the
`RAR*` calls; the visible behaviour is the same except `password=`
is now a real field on `POST /api/extract`.
5. Frontend gains a password modal (HTML + CSS + JS) that pops when
the engine returns `ZIPX_ERR_PASSWORD`, with retry semantics.
The host tests **should not change** — they test the dispatch /
error-translation / limits-handoff layers, none of which see dmc_unrar.
### 10.2 Common archive library
Both engines share:
- staging directory management (`open_parent_dirs`, `remove_tree`,
`cleanup_staging`, `publish_staging`, `rollback_published`);
- duplicate-name detection (`nameset_add_path`, `nameset_check_duplicate`);
- the `extract_progress` callback;
- `report()` / `rarx_fail()` / `rarx_set_detail()` style error
formatting;
- a `time()`-based throttle for progress;
- `chmod_0777_fd` permission normalisation.
These are duplicated between `src/zip_extract.c` and
`src/rar_extract.c` today. A natural refactor is
`src/archive_engine_common.c` exposing them; v1.9 is the moment to do
this refactor since the RAR engine is changing anyway.
### 10.3 ZIP multi-volume (no decision yet)
The original v1.7 wishlist also included multi-volume ZIP
(`.zip` + `.z01`, `.z02`). The implementation is similar to RAR multi-
volume in shape but uses minizip-ng's `zip_open_from_file`-style
APIs. Defer — no user demand on record for v1.9 yet.
### 10.4 Format dispatcher magic-byte sniffing
Today the dispatch is by extension. A magic-byte sniff for `Rar!` /
`PK\x03\x04` would let users rename `.bin` archives and still get
correct handling. Add when there's a real bug report — until then
the simple suffix check is enough.
### 10.5 ELF size trend
| Version | Approx. ELF size | Notes |
|---|---|---|
| v1.7 | 418 KiB | ZIP only. |
| v1.8 | ~430 KiB (est.) | + 11 598 LOC of stripped dmc_unrar code (≈ 25 KiB compressed). Actual size pending WSL cross-compile. |
| v1.9 (opello/unrar) | ~700 KiB (est.) | + ~280 KiB of C++ UnRAR. |
We are still well below the 4 MiB ELF-loader cap, but a future
addition (7z or AES ZIP) would tip us past the 1 MiB comfort line;
that is the right moment to reconsider scope.
---
## 11. Files touched in v1.8
### 11.1 New
```
third_party/unrar/dmc_unrar.c # 11 598 LOC, verbatim upstream
third_party/unrar/dmc_unrar_api.h # 138 LOC, project-authored facade
third_party/unrar/COPYING # GPL-2.0-or-later (vendored)
third_party/unrar/README.md # upstream README (vendored)
third_party/unrar/example.c # upstream usage example (vendored)
third_party/unrar/VENDORED.md # 76 LOC, vendoring rationale + v1.9 path
src/rar_extract.c # 1276 LOC, engine
src/rar_extract.h # 34 LOC, public signature
tests/test_rar_extract.c # 346 LOC, 14 negative-path checks
docs/UPGRADE-v1.8-rar-support.md # this document
```
### 11.2 Modified
```
Makefile # VERSION_TAG v1.8; add third_party/unrar
src/extract.c # extract_dispatch(); ends_with_ci()
assets/main.js # isExtractableArchive / isRarSubVolume
assets/lang-en.js # err_extract_unsupported copy
assets/lang-zh.js # err_extract_unsupported copy
tests/make_fixtures.py # rar_fixtures() with rar/7z/placeholder fallback
tests/run-tests.sh # dmc_unrar.o, rar_extract.o, test_rar_extract.o
THIRD_PARTY_NOTICES # section 3 = dmc_unrar attribution
README.md # What's new in v1.8, RAR section, + Credits entry
CHANGELOG.md # v1.8 block (this PR)
docs/HANDOVER.md # progress checkmarks (D1–D6)
```
### 11.3 Untouched but verified
```
src/zip_extract.{c,h} # ZIP engine behaviour identical
src/filemgr_internal.h # ZIP task struct fields unchanged
assets/param.json # no version bump; VERSION_TAG is in the build
src/app_installer.c # PS5 Media launcher flow unaffected
docs/UPGRADE-v1.7-zip-large-file-profile.md # unchanged
```
---
## 12. Closing notes
The hardest engineering decision in v1.8 was *not* "what RAR library
to use" — it was "how much scope to ship in v1.8 vs v1.9." The
original plan was multi-volume + encrypted; the audit on dmc_unrar
+ opello/unrar's audit surface pushed that to v1.9 with a clean
upgrade recipe. **v1.8 is therefore intentionally a smaller release
than the planning doc (`docs/HANDOVER.md` §6) anticipated.**
For the next developer reading this:
- If you implement v1.9, the natural starting point is the
`VENDORED.md` recipe, not this section.
- If you are debugging an in-the-wild report ("my .rar won't
extract"), the most common cause is multi-volume or encrypted —
point the user at the `err_extract_unsupported` message and the
PC-extract fallback. v1.8 is working as designed when this happens.
- If you are adding a new archive format (7z, tar.bz2, …), the
pattern is: (a) write a vendored facade header, (b) write a
`src/<fmt>_extract.{c,h}` mirror of `rar_extract.c`, (c) extend
`extract_dispatch()`, (d) add i18n strings, (e) extend the host
test suite.
Everything else is the same shape as the existing engines.
-218
View File
@@ -1,218 +0,0 @@
# 上游 v1.8 解压方案 vs 本项目 v1.9.1
> 核查时间:2026-09-15 · 上游 `owendswang/ps5-web-file-manager`
> 来源:GitHub API 查询 + commit `b405721`("Added support for 7zip helper",2026-09-08)完整 patch(2301 行)
> 上游 v1.8 = tag `ad7d754`,v1.7 = `72341d6`(本项目 fork 的基线)
## 结论速览
**不是同一个层面的方案,各有明确胜负手。**
| | 上游 v1.8 | 本项目 v1.9.1 |
|---|---|---|
| 一句话 | **把 7-Zip 本体做成外部 helper 进程,靠 IPC 调用** | **自研 + vendor 解码库,全部内嵌在同一进程** |
| 最强的点 | 格式覆盖 **30 种**,解压核心是 7-Zip 本体 | **完整安全护栏** + 单文件部署 |
| 最弱的点 | **零安全护栏**,且 helper 缺失 = 功能全废 | 格式覆盖只有 **3 种** |
## 一、上游 v1.8 的实际架构
### 1.1 三个组件
| 组件 | 位置 | 职责 |
|---|---|---|
| `src/archive_extract.c`(124 行) | 本仓库 | 只做**后缀识别** + 输出目录名推导 |
| `src/archive_helper.c`(732 行) | 本仓库 | **IPC 客户端**:启动 helper + Unix socket 协议 |
| `wfm-7zip-helper.elf`(~百 MB 级) | `/data/wfm/`,**不在仓库里,单独分发** | 真正的解压 = **7-Zip 本体** |
README 原文:
> Extraction requires the separately distributed `wfm-7zip-helper.elf` helper at `/data/wfm/wfm-7zip-helper.elf`.
### 1.2 启动链路
```c
/* archive_helper_autostart() —— 仅 __SCE__(PS5)分支,Linux 直接返回 0 */
1. archive_helper_probe() // 已有实例在跑就复用,绝不替换
2. stat("/data/wfm/wfm-7zip-helper.elf") // 不存在 → 静默返回 0
3. 校验 ELF magic "\x7fELF"、大小 4B ~ 128MB
4. connect(127.0.0.1:9021) // WFM_ELFLDR_PORT —— elfldr payload 加载器
5. 把 helper ELF 的**全部字节流**推过去
6. shutdown(SHUT_WR)
```
即:**通过 elfldr(PS5 homebrew 的 ELF 加载 payload)把 helper 拉起成一个独立进程。**
### 1.3 通信协议(自研二进制帧)
- 传输层:Unix domain socket —— PS5 走 `/system_tmp/wfm-7zip-helper.sock`,Linux 走 `/tmp/...`
- 帧格式:magic `"W7HP"` + 20 字节头(type / flags / request_id / payload_size,**大端序**)
- 上限:payload 1 MiB、路径 256 KiB、响应 64 KiB
消息类型:
| 方向 | 消息 |
|---|---|
| 主 → helper | `PING` `EXTRACT` `CANCEL` `LIST_TASKS` `ATTACH_TASK` `ACK_TASK` |
| helper → 主 | `PONG` `ACCEPTED` `PROGRESS` `CURRENT_FILE` `PASSWORD_REQUIRED` `DONE` `ERROR` `TASK_SNAPSHOT` `LIST_DONE` |
回调接口 `archive_helper_callbacks_t`:`cancel_requested()` / `progress(done,total)` / `current_file(path)`。
### 1.4 支持格式(30 种后缀)
```
.7z .001 .zip .zipx .rar .arj .bz2 .bzip2 .tbz .tbz2 .cab .gz .gzip
.tgz .tpz .lzh .lha .tar .xz .txz .z .taz .zst .tzst .xar .xip
.cpio .lzma .pmd
```
外加 `.partNN.rar`(只接受 `part1`,即必须从第一卷进入)。
分卷靠 7-Zip 原生能力:`.001` **无差别接受**(不校验卷集连续性)。
### 1.5 任务恢复(上游的亮点)
`filemgr_recover_extract_tasks()` 在 `main.c` 启动时调用:从 helper 拉 `TASK_SNAPSHOT` 列表,把还在跑的 job **reattach 回主进程的任务列表**。
因为 helper 是独立进程,**主 payload 被重启 / 浏览器重开,解压任务不会丢**。`archive_helper_probe()` 的注释也点明了这个设计的意图:
```c
/* Never replace a connected daemon, even if it is temporarily slow. */
```
### 1.6 ⚠️ 没有的东西(全 patch 逐行核查)
| 项目 | 上游 v1.8 | 说明 |
|---|---|---|
| 条目数上限 | ❌ | 无 `max_entries` 类逻辑 |
| 单文件/总大小上限 | ❌ | 无 |
| 压缩比筛查(防炸弹) | ❌ | 无 |
| 磁盘空间预检 | ❌ | 无 `statvfs` 调用 |
| 路径穿越防护 | ❌ | 未见 `..`/绝对路径校验,交给 7-Zip |
| 原子发布 | ❌(未见) | 直接解到目标目录,中断留半成品 |
`grep -i "ratio|max_entries|statvfs|bomb"` 的全部命中都是误报(`operations` 里含子串 `ratio`)。
**换句话说:上游把解压这件事整体外包给了 7-Zip,包括安全责任。**
## 二、本项目 v1.9.1 的架构
| 组件 | 职责 |
|---|---|
| `src/zip_extract.c` | ZIP:minizip-ng,含 zip64、三种分卷命名、`.z01` 真分盘语义 |
| `src/rar_extract.c` | RAR:vendor unrar 7.20.1(DLL 模式),v4/v5/多卷/加密 |
| `src/sevenz_extract.c` + `sevenz_chain.c` | 7z:自解析 folder + pull 式 codec 链 + 7zAES |
| `src/zipx_volume.c` / `zipx_volstream.c` / `sevenz_volstream.c` | 卷集识别 + 连续流抽象 |
**格式覆盖:`.zip` / `.rar` / `.7z` 三种**,各自支持单卷 / 分卷 / 密码。
### 已有的工程能力
| 项目 | 本项目 | 实现位置 |
|---|---|---|
| 条目数 / 总大小 / 单文件上限 | ✅ 两档 profile(20万~50万条目 / 2~4 TiB / 512 GiB~1 TiB) | `zipx_common.c` |
| 压缩比筛查 | ✅ `max_ratio` 500/1000,**1 GiB 下限豁免**小文件 | `zip_extract.c` |
| 磁盘空间预检 | ✅ `check_space()` 按**解压后总量**查 `statvfs` | `zip_extract.c:636` |
| 路径穿越防护 | ✅ 有专项测试(`path traversal variants`) | 测试矩阵 |
| 原子发布 | ✅ staging 目录 + 整 rename + 每 entry fsync | 三引擎统一 |
| 冲突策略 | ✅ FAIL / OVERWRITE / MERGE,目录碰撞递归下钻 | 三引擎统一 |
| 取消 | ✅ 条目粒度 | — |
| 任务恢复 | ❌ **没有** | — |
| 内存隔离 | ❌ 与主进程共享地址空间(LZMA2 字典须封顶) | — |
### 测试覆盖
ZIP 108 + RAR 27 + 7z 28 = **163 checks**,0 失败(MinGW host)+ PS5 真机构建通过。
## 三、逐维度对比
| 维度 | 上游 v1.8 | 本项目 v1.9.1 | 胜 |
|---|---|---|---|
| 格式覆盖 | **30 种** | 3 种 | 上游 |
| 解压核心正确性 | 7-Zip 本体(20 年验证) | 自研 7z 链 + 成熟 vendor 库 | 上游 |
| 分卷语义 | 靠 7-Zip 原生(`.001` 无差别) | 自研两套语义(byte-split / zip split disk) | 平手(我们更细,上游更省心) |
| `.rar.001` | ✅ 直接吃 | ⚠️ 需改名为 `.partN.rar` | 上游 |
| 部署 | **两个文件**,路径写死 `/data/wfm/` | **单文件**,零外部依赖 | 我们 |
| helper 缺失时 | **功能全废**(`archive_helper_not_running`) | 不适用 | 我们 |
| 防压缩炸弹 | ❌ 无 | ✅ ratio + 1 GiB 下限 | **我们** |
| 磁盘写满保护 | ❌ 无 | ✅ 预检解压后总量 | **我们** |
| 路径穿越 | ❌ 无 | ✅ 有防护 + 测试 | **我们** |
| 中断留残留 | ⚠️ 可能留半成品 | ✅ staging 隔离,失败即清 | **我们** |
| 任务恢复 / 跨重启 | ✅ 跨进程 reattach | ❌ | 上游 |
| 内存隔离 | ✅ 独立进程,峰值不影响主服务 | ❌ 共享地址空间 | 上游 |
| 主仓库构建成本 | 低(不编 7-Zip) | 首次 +3~5 min、ELF +98 KiB | 上游 |
| 错误信息详细度 | 中等(6 个 code) | 含条目名 / errno / 字节数 | 我们 |
## 四、该怎么评价
### 上游那步棋走对了什么
**把 7-Zip 当外部依赖,是性价比极高的工程决策。** 自己写解码器要几个月,`apt` 一个 7-Zip 就换来 30 种格式 + 20 年验证的正确性。而且顺手拿到了两个我们暂时没有的能力:跨进程任务恢复、内存隔离。
### 但它把安全责任也一起外包了
这是**实质缺陷**,不是风格问题。在 PS5 上跑的具体后果:
1. **压缩炸弹直接写满内置存储** —— 一个 10 KB 的 zip 可以声明 100 GB,没有任何拦截
2. **路径穿越** —— `../../` 条目可以写到解压目标之外(7-Zip 本身会做基本清理,但这属于"相信第三方"而非"自己保证")
3. **磁盘写满** —— 不预检,写到 ENOSPC 才失败,此时已留下部分文件
4. **失败留残留** —— 没有 staging 隔离
我们在这四项上都有明确实现和测试。163 checks 里专门有一组 `path traversal variants` 和 `limits`。
### 但必须承认格式覆盖是短板
31 种格式的差距不是"多一点便利",是**用户会觉得我们弱**:`.tar.gz`、`.xz`、`.zst`、`.bz2` 在 PS5 场景(游戏包、备份、Mod)里出现频率不低。
## 五、可借鉴 / 不建议照抄
### 建议做:补常见格式(性价比高)
按实际收益排序:
| 优先级 | 格式 | 实现路径 |
|---|---|---|
| 高 | `.tar` / `.tar.gz` / `.tgz` | tar 解析器自己写(格式极简,~300 行)+ zlib 已在手 |
| 高 | `.gz` / `.xz` / `.lzma` | gzip 用 zlib;xz/lzma 可 vendor liblzma 或复用 LZMA SDK 的 LzmaDec |
| 中 | `.bz2` / `.zst` | 单文件解码器,各 ~1000 行,可 vendor |
| 低 | `.cab` / `.arj` / `.lzh` / `.cpio` / `.xar` | 罕见,除非有具体需求 |
**注意**:`gzip`/`xz`/`zst` 是**单文件**格式(不是归档),解出来就是一个文件,输出路径语义需单独设计。
### 建议评估:任务恢复 / 进程隔离
**动机**:主 payload 被系统杀或用户重开浏览器时,正在跑的大包解压会整个丢失。上游靠 helper 独立进程解决了这点。
**但在我们架构下的成本**:需要引入子进程 + IPC(或至少状态持久化 + 重启后重扫 staging)。PS5 上 fork/exec 与 elfldr 强耦合,不是小改动。
**中间路线**:解压失败时保留 staging 目录 + 记录任务清单文件,重启后支持"续解"。改动量中等,能拿到大部分收益,不必引入 IPC。
### 不建议:照抄 helper 路线
理由:
1. **部署体验倒退** —— 用户要装两个文件,还得记住放 `/data/wfm/`;丢一个功能全废。现在单 ELF 是无状态交付,这是真实优势
2. **安全护栏会一起丢** —— 走 7-Zip 就意味着放弃我们对 entries/ratio/空间/穿越的控制
3. **helper 上游自己都不敢放进仓库**("separately distributed"),大概率是体积或许可原因,跟着走会继承同样的问题
4. **我们已经付过的成本会沉没** —— 7z 引擎(自解析 folder + pull 链 + 7zAES)+ 三类分卷抽象共约 3,600 行零耦合代码
### 一句话总结
**上游赢在"格式广度 + 进程架构",我们赢在"安全 + 部署 + 错误质量"。**
如果只想要功能广度,上游的路线更省力;如果要一个**能放心交付给用户、不会被一个恶意压缩包搞崩存储**的工具,我们的路线是对的,缺的只是格式覆盖 —— 而那是可以在现有架构里增量补的,不需要推倒重来。
## 附:核查方法备忘
```bash
# 拿某个 commit 的完整 patch(不要用 WebFetch,会被 AI 摘要截断)
curl -sSL --ssl-no-revoke -o up.patch \
"https://github.com/<owner>/<repo>/commit/<sha>.patch"
# 沙箱内 curl 必须加 --ssl-no-revoke,否则 schannel 报
# CRYPT_E_NO_REVOCATION_CHECK (0x80092012)
# 提取单个文件的 diff
sed -n '/^diff --git a\/src\/foo.c/,/^diff --git a\/src\/bar/p' up.patch
# 只看新增行(去掉 diff 前缀)
... | grep '^+' | sed 's/^+//'
```
Binary file not shown.

Before

Width:  |  Height:  |  Size: 279 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 146 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 153 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 124 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 116 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 290 KiB

Regular → Executable
View File
File mode changed.
+29 -18
View File
@@ -4,13 +4,12 @@
#include <stddef.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/stat.h>
#include <ps5/kernel.h>
#include "asset.h"
#include "pkg_installer.h"
#define INCASSET(name, file) \
__asm__(".section .rodata\n" \
".global " #name "\n" \
@@ -29,20 +28,14 @@
INCASSET(param_json, "assets/param.json");
INCASSET(icon0_png, "assets/icon0.png");
int sceAppInstUtilInitialize(void);
int sceAppInstUtilAppInstallAll(void *);
static int
install_file(const char *path, const uint8_t *data, size_t size) {
struct stat st;
FILE *f;
if(!stat(path, &st)) {
return 0;
}
if(errno != ENOENT) {
return -1;
}
if(!(f = fopen(path, "wb"))) {
if(!(f = fopen(path, "w"))) {
return -1;
}
if(fwrite(data, size, 1, f) != 1) {
@@ -72,13 +65,32 @@ install_app(const char *title_id, const char *dir) {
}
static int
needs_install_file(const char *path) {
needs_update(const char *path, const uint8_t *expected, size_t expected_size) {
struct stat st;
uint8_t *buf;
FILE *f;
int mismatch;
if(stat(path, &st)) {
if(stat(path, &st) || st.st_size != (off_t)expected_size) {
return 1;
}
return 0;
if(!(f = fopen(path, "r"))) {
return 1;
}
if(!(buf = malloc(expected_size))) {
fclose(f);
return 1;
}
if(fread(buf, 1, expected_size, f) != expected_size) {
free(buf);
fclose(f);
return 1;
}
fclose(f);
mismatch = memcmp(buf, expected, expected_size);
free(buf);
return mismatch != 0;
}
int
@@ -92,8 +104,6 @@ app_install_if_needed(void) {
int update_needed = 0;
int err;
asset_register("/icon0.png", icon0_png, icon0_png_size, "image/png", 0);
snprintf(base_dir, sizeof(base_dir), "/user/app/%s", title_id);
snprintf(sce_sys_dir, sizeof(sce_sys_dir), "/user/app/%s/sce_sys", title_id);
snprintf(param_path, sizeof(param_path), "%s/param.json", sce_sys_dir);
@@ -101,7 +111,8 @@ app_install_if_needed(void) {
if(stat(base_dir, &st)) {
update_needed = 1;
} else if(needs_install_file(param_path) || needs_install_file(icon_path)) {
} else if(needs_update(param_path, param_json, param_json_size) ||
needs_update(icon_path, icon0_png, icon0_png_size)) {
update_needed = 1;
}
@@ -111,7 +122,7 @@ app_install_if_needed(void) {
printf("Installing launcher app %s\n", title_id);
if((err = pkg_installer_initialize())) {
if((err = sceAppInstUtilInitialize())) {
printf("sceAppInstUtilInitialize: error 0x%08X\n", err);
return -1;
}
-26
View File
@@ -1,26 +0,0 @@
/* PS5-only stub for the libgcc CPU model symbols.
*
* unrar's rijndael.cpp / system.cpp call __builtin_cpu_supports() to pick
* AES-NI fast paths. Clang lowers that to a reference on __cpu_model (data)
* and __cpu_indicator_init() (function), which the FreeBSD-style PS5
* sysroot does not provide (no libgcc). This TU supplies both so the link
* succeeds; the detection result is unused because we always build the
* portable C path.
*
* Do NOT add this file to host/linux builds: libstdc++/libgcc already
* define __cpu_model there and the symbols would collide. */
#if defined(__x86_64__) && !defined(__linux__) && !defined(_WIN32)
struct __cpu_model {
int __cpu_vendor;
int __cpu_type;
int __cpu_subtype;
};
int __cpu_indicator_init(void) {
return 0;
}
struct __cpu_model __cpu_model = { 0, 0, 0 };
#endif
-761
View File
@@ -1,761 +0,0 @@
#include <dirent.h>
#include <errno.h>
#include <fcntl.h>
#include <limits.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/stat.h>
#include <time.h>
#include <unistd.h>
#include "filemgr_internal.h"
#include "json_util.h"
#include "path_util.h"
#include "websrv.h"
#define DOWNLOAD_ARCHIVE_NAME_LIMIT 20
#define DOWNLOAD_BUFFER_SIZE (2 * 1024 * 1024)
typedef struct tar_frame {
char path[PATH_MAX];
char name[PATH_MAX];
DIR *dir;
int header_sent;
struct tar_frame *next;
} tar_frame_t;
typedef struct tar_stream {
file_task_t *task;
char **paths;
size_t path_count;
size_t path_index;
size_t stack_depth;
tar_frame_t *stack;
int fd;
char current_file[PATH_MAX];
unsigned long long file_remaining;
size_t file_padding;
size_t pad_remaining;
char *pending;
size_t pending_size;
size_t pending_offset;
int final_blocks;
int done;
int error;
} tar_stream_t;
typedef struct download_file_stream {
file_task_t *task;
int fd;
unsigned long long size;
unsigned long long sent;
int done;
int error;
} download_file_stream_t;
static enum MHD_Result
download_task_request_error(struct MHD_Connection *conn, file_task_t *task,
char **paths, size_t count, unsigned int status,
const char *msg) {
free_paths(paths, count);
free_task(task);
return send_json_error(conn, status, msg);
}
static int
tar_checksum(char *header) {
int sum = 0;
int i;
memset(header + 148, ' ', 8);
for(i = 0; i < 512; i++) {
sum += (unsigned char)header[i];
}
snprintf(header + 148, 8, "%06o", sum);
header[154] = 0;
header[155] = ' ';
return 0;
}
static int
tar_split_name(const char *name, char *out_name, size_t out_name_size,
char *prefix, size_t prefix_size) {
size_t len = strlen(name);
const char *slash;
memset(out_name, 0, out_name_size);
memset(prefix, 0, prefix_size);
if(len < out_name_size) {
strcpy(out_name, name);
return 0;
}
for(slash = name + len; slash > name; slash--) {
size_t prefix_len;
size_t name_len;
if(*slash != '/') {
continue;
}
prefix_len = (size_t)(slash - name);
name_len = len - prefix_len - 1;
if(prefix_len < prefix_size && name_len > 0 && name_len < out_name_size) {
memcpy(prefix, name, prefix_len);
prefix[prefix_len] = 0;
memcpy(out_name, slash + 1, name_len + 1);
return 0;
}
}
errno = ENAMETOOLONG;
return -1;
}
static int
tar_queue_header(tar_stream_t *s, const char *name, const struct stat *st,
char type) {
char header[512];
char tar_name[100];
char prefix[155];
unsigned int mode = (unsigned int)(st->st_mode & 07777);
unsigned long long size = type == '0' ? (unsigned long long)st->st_size : 0;
long long mtime = (long long)st->st_mtime;
if(tar_split_name(name, tar_name, sizeof(tar_name), prefix, sizeof(prefix))) {
return -1;
}
memset(header, 0, sizeof(header));
memcpy(header, tar_name, strlen(tar_name));
snprintf(header + 100, 8, "%07o", mode);
snprintf(header + 108, 8, "%07o", 0);
snprintf(header + 116, 8, "%07o", 0);
snprintf(header + 124, 12, "%011llo", size);
snprintf(header + 136, 12, "%011llo", (unsigned long long)mtime);
header[156] = type;
memcpy(header + 257, "ustar", 5);
memcpy(header + 263, "00", 2);
if(prefix[0]) {
memcpy(header + 345, prefix, strlen(prefix));
}
tar_checksum(header);
s->pending = malloc(sizeof(header));
if(!s->pending) {
errno = ENOMEM;
return -1;
}
memcpy(s->pending, header, sizeof(header));
s->pending_size = sizeof(header);
s->pending_offset = 0;
return 0;
}
static int
tar_push_dir(tar_stream_t *s, const char *path, const char *name) {
tar_frame_t *frame = calloc(1, sizeof(*frame));
if(!frame) {
errno = ENOMEM;
return -1;
}
snprintf(frame->path, sizeof(frame->path), "%s", path);
snprintf(frame->name, sizeof(frame->name), "%s", name);
frame->dir = opendir(path);
if(!frame->dir) {
int error = errno;
free(frame);
errno = error;
return -1;
}
frame->next = s->stack;
s->stack = frame;
s->stack_depth++;
return 0;
}
static void
tar_pop_dir(tar_stream_t *s) {
tar_frame_t *frame = s->stack;
if(!frame) {
return;
}
s->stack = frame->next;
if(s->stack_depth) {
s->stack_depth--;
}
if(frame->dir) {
closedir(frame->dir);
}
free(frame);
}
static int
tar_start_path(tar_stream_t *s, const char *path, const char *name) {
struct stat st;
if(lstat(path, &st)) {
return -1;
}
if(S_ISDIR(st.st_mode)) {
char dir_name[PATH_MAX];
snprintf(dir_name, sizeof(dir_name), "%s%s", name,
name[strlen(name) - 1] == '/' ? "" : "/");
return tar_push_dir(s, path, dir_name);
}
if(!S_ISREG(st.st_mode)) {
errno = ENOTSUP;
return -1;
}
if(tar_queue_header(s, name, &st, '0')) {
return -1;
}
s->fd = open(path, O_RDONLY);
if(s->fd < 0) {
return -1;
}
snprintf(s->current_file, sizeof(s->current_file), "%s", path);
s->file_remaining = (unsigned long long)st.st_size;
s->file_padding = (size_t)((512 - ((unsigned long long)st.st_size % 512)) % 512);
return 0;
}
static int
tar_prepare_next(tar_stream_t *s) {
while(!s->pending && s->fd < 0 && !s->done) {
if(s->task && task_cancel_requested(s->task)) {
errno = ECANCELED;
return -1;
}
if(s->pad_remaining) {
size_t size = s->pad_remaining > 512 ? 512 : s->pad_remaining;
s->pending = calloc(1, size);
if(!s->pending) {
errno = ENOMEM;
return -1;
}
s->pending_size = size;
s->pending_offset = 0;
s->pad_remaining -= size;
return 0;
}
if(s->stack) {
tar_frame_t *frame = s->stack;
struct dirent *entry;
struct stat st;
if(!frame->header_sent) {
frame->header_sent = 1;
if(lstat(frame->path, &st) ||
tar_queue_header(s, frame->name, &st, '5')) {
return -1;
}
return 0;
}
while((entry = readdir(frame->dir))) {
char child[PATH_MAX];
char child_name[PATH_MAX];
if(!strcmp(entry->d_name, ".") || !strcmp(entry->d_name, "..")) {
continue;
}
if(path_join(child, sizeof(child), frame->path, entry->d_name) ||
path_join(child_name, sizeof(child_name), frame->name,
entry->d_name) ||
tar_start_path(s, child, child_name)) {
return -1;
}
return 0;
}
tar_pop_dir(s);
continue;
}
if(s->path_index < s->path_count) {
const char *path = s->paths[s->path_index++];
if(tar_start_path(s, path, path_basename(path))) {
return -1;
}
continue;
}
if(s->final_blocks < 2) {
s->pending = calloc(1, 512);
if(!s->pending) {
errno = ENOMEM;
return -1;
}
s->pending_size = 512;
s->pending_offset = 0;
s->final_blocks++;
return 0;
}
s->done = 1;
}
return 0;
}
static ssize_t
tar_read(void *cls, uint64_t pos, char *buf, size_t max) {
tar_stream_t *s = cls;
size_t out = 0;
unsigned long long progress = 0;
char progress_current[PATH_MAX] = {0};
(void)pos;
while(out < max && !s->done) {
if(s->task && task_cancel_requested(s->task)) {
s->error = ECANCELED;
return out ? (ssize_t)out : MHD_CONTENT_READER_END_WITH_ERROR;
}
if(tar_prepare_next(s)) {
s->error = errno ? errno : EIO;
return out ? (ssize_t)out : MHD_CONTENT_READER_END_WITH_ERROR;
}
if(s->pending) {
size_t left = s->pending_size - s->pending_offset;
size_t take = left < max - out ? left : max - out;
memcpy(buf + out, s->pending + s->pending_offset, take);
s->pending_offset += take;
out += take;
if(s->pending_offset >= s->pending_size) {
free(s->pending);
s->pending = NULL;
s->pending_size = 0;
s->pending_offset = 0;
}
continue;
}
if(s->fd >= 0) {
size_t want = max - out;
ssize_t n;
if((unsigned long long)want > s->file_remaining) {
want = (size_t)s->file_remaining;
}
n = read(s->fd, buf + out, want);
if(n < 0) {
s->error = errno;
return out ? (ssize_t)out : MHD_CONTENT_READER_END_WITH_ERROR;
}
if(!n) {
close(s->fd);
s->fd = -1;
s->current_file[0] = 0;
s->file_remaining = 0;
continue;
}
out += (size_t)n;
s->file_remaining -= (unsigned long long)n;
progress += (unsigned long long)n;
if(s->current_file[0]) {
snprintf(progress_current, sizeof(progress_current), "%s",
s->current_file);
}
if(!s->file_remaining) {
close(s->fd);
s->fd = -1;
s->current_file[0] = 0;
s->pad_remaining = s->file_padding;
s->file_padding = 0;
}
}
}
if(s->task && progress) {
task_update(s->task, TASK_RUNNING,
progress_current[0] ? progress_current : NULL,
progress, NULL);
}
return out ? (ssize_t)out : MHD_CONTENT_READER_END_OF_STREAM;
}
static void
tar_close(void *cls) {
tar_stream_t *s = cls;
int canceled;
if(!s) {
return;
}
if(s->fd >= 0) {
close(s->fd);
}
while(s->stack) {
tar_pop_dir(s);
}
canceled = s->task && task_cancel_requested(s->task);
if(s->task) {
char current[PATH_MAX];
snprintf(current, sizeof(current), "%s",
s->task->current[0] ? s->task->current : s->task->src);
if(canceled) {
task_update(s->task, TASK_CANCELED, current, 0, "canceled");
} else if(s->error) {
errno = s->error;
task_update(s->task, TASK_FAILED, current, 0, strerror(errno));
} else if(s->done) {
task_update(s->task, TASK_DONE, current, 0, NULL);
} else {
task_update(s->task, TASK_FAILED, current, 0, "client disconnected");
}
}
free(s->pending);
free_paths(s->paths, s->path_count);
free(s);
}
static int
prepare_download_task(file_task_t *task) {
unsigned long long total = 0;
size_t file_count = 0;
size_t dir_count = 0;
size_t i;
task_update(task, TASK_RUNNING, "preparing", 0, NULL);
for(i = 0; i < task->src_count; i++) {
if(count_task_path_bytes(task, task->srcs[i], task->srcs[i],
&total, &file_count, &dir_count)) {
return -1;
}
}
pthread_mutex_lock(&g_tasks_lock);
task->total = total;
task->file_count = file_count;
task->dir_count = dir_count;
task->updated_at = time(NULL);
pthread_mutex_unlock(&g_tasks_lock);
return 0;
}
static size_t
append_truncated_name(char *out, size_t size, size_t len, const char *name,
size_t limit) {
while(*name && len < limit && len + 1 < size) {
unsigned char c = (unsigned char)*name;
out[len++] = *name++;
if(c >= 0x80) {
while((*name & 0xc0) == 0x80 && len < limit && len + 1 < size) {
out[len++] = *name++;
}
}
}
out[len] = 0;
return len;
}
static void
download_archive_name(char *out, size_t size, char **paths, size_t count) {
char name[PATH_MAX];
size_t len = 0;
size_t i;
out[0] = 0;
if(count == 1) {
path_basename_copy(paths[0], name, sizeof(name));
append_truncated_name(out, size, 0, name, DOWNLOAD_ARCHIVE_NAME_LIMIT);
} else {
for(i = 0; i < count && len < DOWNLOAD_ARCHIVE_NAME_LIMIT; i++) {
path_basename_copy(paths[i], name, sizeof(name));
if(i && len + 1 < DOWNLOAD_ARCHIVE_NAME_LIMIT && len + 1 < size) {
out[len++] = ' ';
out[len] = 0;
}
len = append_truncated_name(out, size, len, name,
DOWNLOAD_ARCHIVE_NAME_LIMIT);
}
}
if(!out[0]) {
snprintf(out, size, "download");
}
snprintf(out + strlen(out), size - strlen(out), ".tar");
}
static void
download_file_name(char *out, size_t size, const char *path) {
path_basename_copy(path, out, size);
if(!out[0]) {
snprintf(out, size, "download");
}
}
static size_t
header_quoted_filename(char *out, size_t size, const char *name) {
size_t len = 0;
while(*name && len + 1 < size) {
unsigned char c = (unsigned char)*name++;
if(c < 0x20 || c == 0x7f || c == '"' || c == '\\') {
c = '_';
}
out[len++] = (char)c;
}
out[len] = 0;
return len;
}
static size_t
header_percent_filename(char *out, size_t size, const char *name) {
static const char hex[] = "0123456789ABCDEF";
size_t len = 0;
while(*name && len + 1 < size) {
unsigned char c = (unsigned char)*name++;
int safe = (c >= '0' && c <= '9') || (c >= 'A' && c <= 'Z') ||
(c >= 'a' && c <= 'z') || c == '.' || c == '_' || c == '-';
if(safe) {
out[len++] = (char)c;
} else {
if(len + 3 >= size) {
break;
}
out[len++] = '%';
out[len++] = hex[c >> 4];
out[len++] = hex[c & 15];
}
}
out[len] = 0;
return len;
}
static void
add_download_filename_header(struct MHD_Response *resp, const char *name) {
char quoted[PATH_MAX];
char encoded[PATH_MAX * 3];
char header[PATH_MAX * 4];
header_quoted_filename(quoted, sizeof(quoted), name);
header_percent_filename(encoded, sizeof(encoded), name);
snprintf(header, sizeof(header),
"attachment; filename=\"%s\"; filename*=UTF-8''%s",
quoted, encoded);
MHD_add_response_header(resp, "Content-Disposition", header);
}
static enum MHD_Result
create_download_task_response(struct MHD_Connection *conn, char **paths,
size_t count) {
file_task_t *task = calloc(1, sizeof(file_task_t));
strbuf_t b = {0};
struct stat st;
size_t i;
if(!task) {
free_paths(paths, count);
return send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR, "out of memory");
}
if(!count) {
return download_task_request_error(conn, task, paths, count,
MHD_HTTP_BAD_REQUEST, "no source paths");
}
for(i = 0; i < count; i++) {
if(lstat(paths[i], &st)) {
return download_task_request_error(conn, task, paths, count,
MHD_HTTP_NOT_FOUND, "file not found");
}
if(!S_ISREG(st.st_mode) && !S_ISDIR(st.st_mode)) {
return download_task_request_error(conn, task, paths, count,
MHD_HTTP_BAD_REQUEST, "invalid path");
}
}
task->op = TASK_DOWNLOAD;
task->state = TASK_QUEUED;
task->srcs = paths;
task->src_count = count;
snprintf(task->src, sizeof(task->src), "%s%s", paths[0],
count > 1 ? " ..." : "");
snprintf(task->current, sizeof(task->current), "%s", task->src);
task->created_at = time(NULL);
task->updated_at = task->created_at;
pthread_mutex_lock(&g_tasks_lock);
remove_finished_tasks_locked();
if(has_active_task_locked()) {
pthread_mutex_unlock(&g_tasks_lock);
return download_task_request_error(conn, task, paths, count,
MHD_HTTP_CONFLICT, "another task is running");
}
task->id = g_next_task_id++;
task->next = g_tasks;
g_tasks = task;
pthread_mutex_unlock(&g_tasks_lock);
strbuf_printf(&b, "{\"ok\":true,\"task_id\":%lu}", task->id);
return send_buffer(conn, MHD_HTTP_OK, b.data, "application/json");
}
enum MHD_Result
api_download_prepare(struct MHD_Connection *conn, const char *body,
size_t body_size) {
char *paths_raw = body_form_value(body, body_size, "paths");
char **paths = NULL;
size_t count = 0;
if(!paths_raw || parse_paths(paths_raw, &paths, &count)) {
free(paths_raw);
return send_json_error(conn, MHD_HTTP_BAD_REQUEST, "invalid path");
}
free(paths_raw);
return create_download_task_response(conn, paths, count);
}
static ssize_t
download_file_read(void *cls, uint64_t pos, char *buf, size_t max) {
download_file_stream_t *s = cls;
ssize_t len;
if(task_cancel_requested(s->task)) {
s->error = ECANCELED;
return MHD_CONTENT_READER_END_WITH_ERROR;
}
len = pread(s->fd, buf, max, (off_t)pos);
if(len < 0) {
s->error = errno ? errno : EIO;
return MHD_CONTENT_READER_END_WITH_ERROR;
}
if(!len) {
s->done = 1;
return MHD_CONTENT_READER_END_OF_STREAM;
}
{
unsigned long long end = (unsigned long long)pos + (unsigned long long)len;
unsigned long long add = end > s->sent ? end - s->sent : 0;
if(end > s->sent) {
s->sent = end;
}
if(s->sent >= s->size) {
s->done = 1;
}
task_update(s->task, TASK_RUNNING, s->task->src, add, NULL);
}
return len;
}
static void
download_file_close(void *cls) {
download_file_stream_t *s = cls;
int canceled;
if(!s) {
return;
}
if(s->fd >= 0) {
close(s->fd);
}
canceled = task_cancel_requested(s->task);
if(canceled) {
task_update(s->task, TASK_CANCELED, s->task->src, 0, "canceled");
} else if(s->error) {
errno = s->error;
task_update(s->task, TASK_FAILED, s->task->src, 0, strerror(errno));
} else if(s->done) {
task_update(s->task, TASK_DONE, s->task->src, 0, NULL);
} else {
task_update(s->task, TASK_FAILED, s->task->src, 0, "client disconnected");
}
free(s);
}
enum MHD_Result
api_download(struct MHD_Connection *conn) {
char *idstr = query_value(conn, "id");
unsigned long id = idstr ? strtoul(idstr, NULL, 10) : 0;
char **paths = NULL;
size_t count = 0;
struct stat st;
tar_stream_t *stream;
struct MHD_Response *resp;
enum MHD_Result ret;
file_task_t *task;
char download_name[PATH_MAX];
free(idstr);
pthread_mutex_lock(&g_tasks_lock);
task = find_task_locked(id);
if(!task || task->op != TASK_DOWNLOAD || task->state != TASK_QUEUED) {
pthread_mutex_unlock(&g_tasks_lock);
return send_json_error(conn, MHD_HTTP_NOT_FOUND, "active task not found");
}
task->state = TASK_RUNNING;
task->updated_at = time(NULL);
pthread_mutex_unlock(&g_tasks_lock);
if(prepare_download_task(task)) {
char current[PATH_MAX];
snprintf(current, sizeof(current), "%s",
task->current[0] ? task->current : task->src);
if(errno == ECANCELED || task_cancel_requested(task)) {
task_update(task, TASK_CANCELED, current, 0, "canceled");
} else {
task_update(task, TASK_FAILED, current, 0, strerror(errno));
}
return send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR, NULL);
}
paths = task->srcs;
count = task->src_count;
if(count == 1 && !stat(paths[0], &st) && S_ISREG(st.st_mode)) {
download_file_stream_t *file_stream = calloc(1, sizeof(*file_stream));
if(!file_stream) {
task_update(task, TASK_FAILED, task->src, 0, "out of memory");
return send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR, "out of memory");
}
file_stream->task = task;
file_stream->fd = -1;
file_stream->size = (unsigned long long)st.st_size;
file_stream->done = file_stream->size == 0;
file_stream->fd = open(paths[0], O_RDONLY);
if(file_stream->fd < 0) {
free(file_stream);
task_update(task, TASK_FAILED, task->src, 0, strerror(errno));
return send_json_error(conn, MHD_HTTP_NOT_FOUND, "file not found");
}
resp = MHD_create_response_from_callback((uint64_t)st.st_size,
DOWNLOAD_BUFFER_SIZE,
download_file_read, file_stream,
download_file_close);
if(!resp) {
download_file_close(file_stream);
return MHD_NO;
}
MHD_add_response_header(resp, MHD_HTTP_HEADER_CONTENT_TYPE,
"application/octet-stream");
download_file_name(download_name, sizeof(download_name), paths[0]);
add_download_filename_header(resp, download_name);
ret = websrv_queue_response(conn, MHD_HTTP_OK, resp);
MHD_destroy_response(resp);
return ret;
}
if(!(stream = calloc(1, sizeof(*stream)))) {
task_update(task, TASK_FAILED, task->src, 0, "out of memory");
return send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR, "out of memory");
}
stream->fd = -1;
stream->task = task;
stream->paths = NULL;
stream->path_count = count;
stream->paths = calloc(count, sizeof(char *));
if(!stream->paths) {
tar_close(stream);
task_update(task, TASK_FAILED, task->src, 0, "out of memory");
return send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR, "out of memory");
}
for(size_t i = 0; i < count; i++) {
stream->paths[i] = strdup(paths[i]);
if(!stream->paths[i]) {
stream->path_count = i;
tar_close(stream);
task_update(task, TASK_FAILED, task->src, 0, "out of memory");
return send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR, "out of memory");
}
}
resp = MHD_create_response_from_callback(MHD_SIZE_UNKNOWN,
DOWNLOAD_BUFFER_SIZE,
tar_read, stream, tar_close);
if(!resp) {
tar_close(stream);
return MHD_NO;
}
MHD_add_response_header(resp, MHD_HTTP_HEADER_CONTENT_TYPE,
"application/x-tar");
download_archive_name(download_name, sizeof(download_name), paths, count);
add_download_filename_header(resp, download_name);
ret = websrv_queue_response(conn, MHD_HTTP_OK, resp);
MHD_destroy_response(resp);
return ret;
}
-416
View File
@@ -1,416 +0,0 @@
#include "filemgr.h"
#include <ctype.h>
#include <errno.h>
#include <pthread.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/stat.h>
#include <time.h>
#include <unistd.h>
#include "extract.h"
#include "filemgr_internal.h"
#include "json_util.h"
#include "path_util.h"
#include "rar_extract.h"
#include "sevenz_extract.h"
#include "zip_extract.h"
#include "zipx_volume.h"
/* Cancellation callback: stop when the task is asked to cancel. */
static int
extract_cancel(void *userdata) {
file_task_t *task = userdata;
return task_cancel_requested(task);
}
/* Case-insensitive suffix check. Returns 1 if path ends in suffix
(the comparison ignores trailing slashes, so "x.rar/" is still .rar). */
static int
ends_with_ci(const char *path, const char *suffix) {
size_t path_len = strlen(path);
size_t suf_len = strlen(suffix);
if(path_len < suf_len) {
return 0;
}
/* Trim trailing path separators (defensive — the API rejects them but
we get here with whatever path the caller passed). */
while(path_len && path[path_len - 1] == '/') {
path_len--;
}
if(path_len < suf_len) {
return 0;
}
return !strcasecmp(path + path_len - suf_len, suffix);
}
/* Progress callback. The engine already throttles reports (200 ms / 1 MiB),
so we can forward each report straight into the shared task state.
Defined before extract_dispatch() so the dispatcher's call site compiles
cleanly under -Werror=implicit-function-declaration. */
static void
extract_progress(void *userdata, const zipx_progress_t *p) {
file_task_t *task = userdata;
unsigned long long prev_done;
unsigned long long delta;
pthread_mutex_lock(&g_tasks_lock);
task->entries_total = p->entries_total;
task->entries_done = p->entries_done;
task->total = p->bytes_total;
prev_done = task->done;
pthread_mutex_unlock(&g_tasks_lock);
delta = p->bytes_done > prev_done ? p->bytes_done - prev_done : 0;
task_update(task, TASK_RUNNING, p->current ? p->current : task->src,
delta, NULL);
}
/* Case-insensitive substring search (strcasestr is not available on MinGW). */
static const char *
ci_strstr(const char *hay, const char *needle) {
size_t nlen = strlen(needle);
const char *p;
if(!nlen) {
return hay;
}
for(p = hay; *p; p++) {
size_t i;
for(i = 0; i < nlen; i++) {
if(!p[i] ||
tolower((unsigned char)p[i]) != tolower((unsigned char)needle[i])) {
break;
}
}
if(i == nlen) {
return p;
}
}
return NULL;
}
static void
extract_set_detail(zipx_result_t *result, const char *text) {
size_t len = strlen(text);
if(len > sizeof(result->detail) - 1) {
len = sizeof(result->detail) - 1;
}
memcpy(result->detail, text, len);
result->detail[len] = 0;
}
/* Which engine a volume set belongs to, decided from the member names:
0 zip, 1 rar, 2 7z, -1 unknown. */
static int
volume_format(const zipx_volume_t *vol) {
static const char *const exts[] = { ".zip", ".rar", ".7z", NULL };
const char *best = NULL;
int best_kind = -1;
int i;
int j;
for(i = 0; i < vol->count; i++) {
for(j = 0; exts[j]; j++) {
const char *hit = ci_strstr(vol->paths[i], exts[j]);
if(hit && (!best || hit > best)) {
best = hit;
best_kind = j;
}
}
}
return best_kind;
}
/* Removes the source archive once a task is done with it. For a split set
every volume has to go: leaving the other parts behind would leave the user
with something that still looks like a usable archive. */
static void
remove_source_archives(const char *path) {
zipx_volume_t vol;
char *err = NULL;
int rc = zipx_volume_detect(path, &vol, &err);
int i;
free(err);
if(rc > 0) {
for(i = 0; i < vol.count; i++) {
unlink(vol.paths[i]);
}
zipx_volume_free(&vol);
return;
}
unlink(path);
}
/* Pick the right engine by the archive file name. Returns ZIPX_ERR_FORMAT
for anything that does not look like a supported archive. */
static zipx_status_t
extract_dispatch(file_task_t *task, zipx_conflict_t conflict,
const zipx_limits_t *limits, zipx_result_t *result) {
zipx_volume_t vol;
char *vol_err = NULL;
int vrc = zipx_volume_detect(task->src, &vol, &vol_err);
int kind = vrc > 0 ? volume_format(&vol) : -1;
if(vrc < 0) {
/* A broken set gets the precise reason (which volume is missing, ...)
instead of a generic "unsupported format". */
extract_set_detail(result, task->src);
snprintf(result->message, sizeof(result->message), "%s",
vol_err ? vol_err : "the archive volumes are incomplete");
free(vol_err);
return ZIPX_ERR_OPEN;
}
free(vol_err);
if(vrc > 0) {
zipx_status_t status;
if(kind == 0) {
status = zipx_extract(task->src, task->dst, conflict, limits,
extract_cancel, extract_progress, task, result);
} else if(kind == 1) {
/* unrar chains its own volume naming (x.part1.rar); a byte contiguous
set named x.rar.001 cannot be handed to it as-is. */
extract_set_detail(result, task->src);
snprintf(result->message, sizeof(result->message),
"RAR volume sets named 'x.rar.001' are not supported yet "
"(rename the parts to 'x.part1.rar', 'x.part2.rar', ...)");
status = ZIPX_ERR_UNSUPPORTED;
} else if(kind == 2) {
status = sevenz_extract(task->src, task->dst, conflict, limits,
extract_cancel, extract_progress, task,
task->extract_password[0] ? task->extract_password
: NULL,
result);
} else {
extract_set_detail(result, task->src);
snprintf(result->message, sizeof(result->message),
"unsupported split archive (only .zip, .rar and .7z volumes "
"are recognised)");
status = ZIPX_ERR_UNSUPPORTED;
}
zipx_volume_free(&vol);
return status;
}
if(ends_with_ci(task->src, ".zip")) {
return zipx_extract(task->src, task->dst, conflict, limits,
extract_cancel, extract_progress, task, result);
}
if(ends_with_ci(task->src, ".rar")) {
return rar_extract(task->src, task->dst, conflict, limits,
extract_cancel, extract_progress, task, result);
}
if(ends_with_ci(task->src, ".7z")) {
return sevenz_extract(task->src, task->dst, conflict, limits,
extract_cancel, extract_progress, task,
task->extract_password[0] ? task->extract_password
: NULL,
result);
}
extract_set_detail(result, task->src);
snprintf(result->message, sizeof(result->message),
"unsupported archive format (only .zip, .rar and .7z are accepted)");
return ZIPX_ERR_UNSUPPORTED;
}
static const char *
extract_error_code(zipx_status_t status) {
switch(status) {
case ZIPX_ERR_OPEN: return "extract_open_failed";
case ZIPX_ERR_FORMAT: return "extract_corrupt";
case ZIPX_ERR_UNSUPPORTED: return "extract_unsupported";
case ZIPX_ERR_UNSAFE_NAME: return "extract_unsafe_name";
case ZIPX_ERR_SPECIAL: return "extract_special_entry";
case ZIPX_ERR_DUPLICATE: return "extract_duplicate";
case ZIPX_ERR_LIMIT_ENTRIES: return "extract_too_many_entries";
case ZIPX_ERR_LIMIT_FILE: return "extract_entry_too_large";
case ZIPX_ERR_LIMIT_TOTAL: return "extract_too_large";
case ZIPX_ERR_LIMIT_RATIO: return "extract_ratio";
case ZIPX_ERR_LIMIT_DEPTH: return "extract_too_deep";
case ZIPX_ERR_LIMIT_NAME: return "extract_name_too_long";
case ZIPX_ERR_CONFLICT: return "extract_conflict";
case ZIPX_ERR_SPACE: return "no_space";
case ZIPX_ERR_IO: return "extract_io";
case ZIPX_ERR_CRC: return "extract_crc";
case ZIPX_ERR_PASSWORD: return "extract_password";
default: return "extract_failed";
}
}
static void
extract_set_error(file_task_t *task, zipx_status_t status,
const zipx_result_t *result) {
const char *code = extract_error_code(status);
const char *detail = result->detail[0] ? result->detail : NULL;
const char *msg = result->message[0] ? result->message :
zipx_status_string(status);
pthread_mutex_lock(&g_tasks_lock);
snprintf(task->error_code, sizeof(task->error_code), "%s", code);
if(detail) {
size_t n = strlen(detail);
if(n >= sizeof(task->error_arg)) {
n = sizeof(task->error_arg) - 1;
}
memcpy(task->error_arg, detail, n);
task->error_arg[n] = 0;
}
task->updated_at = time(NULL);
pthread_mutex_unlock(&g_tasks_lock);
task_update(task, TASK_FAILED, detail ? detail : task->src, 0, msg);
}
static void *
extract_worker(void *arg) {
file_task_t *task = arg;
zipx_result_t result = {0};
zipx_conflict_t conflict;
zipx_status_t status;
switch(task->extract_conflict) {
case EXTRACT_CONFLICT_OVERWRITE:
conflict = ZIPX_CONFLICT_OVERWRITE;
break;
case EXTRACT_CONFLICT_MERGE:
conflict = ZIPX_CONFLICT_MERGE;
break;
default:
conflict = ZIPX_CONFLICT_FAIL;
break;
}
task_update(task, TASK_RUNNING, "scanning archive", 0, NULL);
status = extract_dispatch(task, conflict,
zipx_limits_profile(task->extract_large),
&result);
if(status == ZIPX_OK) {
time_t completed_at = time(NULL);
/* Only delete the source archive when this task owns it (upload flow). */
if(task->extract_remove_source && task->src[0]) {
remove_source_archives(task->src);
}
pthread_mutex_lock(&g_tasks_lock);
task->state = TASK_DONE;
if(task->total) {
task->done = task->total;
}
task->entries_done = task->entries_total;
task->updated_at = completed_at;
record_task_completion_locked(task, completed_at);
pthread_mutex_unlock(&g_tasks_lock);
} else if(status == ZIPX_ERR_CANCELED) {
task_update(task, TASK_CANCELED,
task->current[0] ? task->current : task->src, 0, "canceled");
} else {
extract_set_error(task, status, &result);
}
return NULL;
}
enum MHD_Result
api_extract(struct MHD_Connection *conn, const char *body, size_t body_size) {
char *path = fs_path_value(body_form_value(body, body_size, "path"));
char *dst_dir = fs_path_value(body_form_value(body, body_size, "dst_dir"));
char *conflict_str = body_form_value(body, body_size, "conflict");
char *remove_str = body_form_value(body, body_size, "remove_source");
char *large_str = body_form_value(body, body_size, "large");
char *password_str = body_form_value(body, body_size, "password");
extract_conflict_t conflict = EXTRACT_CONFLICT_FAIL;
int remove_source = remove_str && !strcmp(remove_str, "1");
int large = large_str && !strcmp(large_str, "1");
file_task_t *task;
strbuf_t b = {0};
struct stat st;
if(!path || !dst_dir || !path[0] || !dst_dir[0]) {
free(path); free(dst_dir); free(conflict_str); free(remove_str);
free(large_str); free(password_str);
return send_json_error(conn, MHD_HTTP_BAD_REQUEST, "invalid path");
}
if(conflict_str) {
if(!strcmp(conflict_str, "overwrite")) {
conflict = EXTRACT_CONFLICT_OVERWRITE;
} else if(!strcmp(conflict_str, "merge")) {
conflict = EXTRACT_CONFLICT_MERGE;
} else if(strcmp(conflict_str, "fail")) {
free(path); free(dst_dir); free(conflict_str); free(remove_str);
free(large_str); free(password_str);
return send_json_error(conn, MHD_HTTP_BAD_REQUEST, "invalid conflict");
}
}
if(stat(path, &st) || !S_ISREG(st.st_mode)) {
free(path); free(dst_dir); free(conflict_str); free(remove_str);
free(large_str); free(password_str);
return send_json_error(conn, MHD_HTTP_BAD_REQUEST, "file not found");
}
if(stat(dst_dir, &st) || !S_ISDIR(st.st_mode)) {
free(path); free(dst_dir); free(conflict_str); free(remove_str);
free(large_str); free(password_str);
return send_json_error(conn, MHD_HTTP_BAD_REQUEST,
"destination must be a directory");
}
task = calloc(1, sizeof(*task));
if(!task) {
free(path); free(dst_dir); free(conflict_str); free(remove_str);
free(large_str); free(password_str);
return send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR,
"out of memory");
}
task->op = TASK_EXTRACT;
task->state = TASK_QUEUED;
task->extract_conflict = (int)conflict;
task->extract_remove_source = remove_source;
task->extract_large = large;
/* The size cap (256 bytes, including the NUL) leaves room for a 255-codepoint
UTF-8 password without overflowing the field or letting a malicious header
run away with it. Anything longer is truncated, which is what a sane user
will never hit but matches the storage size of the field. */
if(password_str) {
snprintf(task->extract_password, sizeof(task->extract_password), "%s",
password_str);
}
snprintf(task->src, sizeof(task->src), "%s", path);
snprintf(task->dst, sizeof(task->dst), "%s", dst_dir);
task->created_at = time(NULL);
task->updated_at = task->created_at;
pthread_mutex_lock(&g_tasks_lock);
remove_finished_tasks_locked();
if(has_active_task_locked()) {
pthread_mutex_unlock(&g_tasks_lock);
free_task(task);
free(path); free(dst_dir); free(conflict_str); free(remove_str);
free(large_str); free(password_str);
return send_json_error(conn, MHD_HTTP_CONFLICT, "another task is running");
}
task->id = g_next_task_id++;
task->next = g_tasks;
g_tasks = task;
pthread_mutex_unlock(&g_tasks_lock);
if(pthread_create(&task->thread, NULL, extract_worker, task)) {
task_update(task, TASK_FAILED, NULL, 0, "pthread_create failed");
} else {
pthread_detach(task->thread);
}
free(path); free(dst_dir); free(conflict_str); free(remove_str);
free(large_str); free(password_str);
strbuf_printf(&b, "{\"ok\":true,\"task_id\":%lu}", task->id);
return send_buffer(conn, MHD_HTTP_OK, b.data, "application/json");
}
-22
View File
@@ -1,22 +0,0 @@
#pragma once
#include <microhttpd.h>
/* Conflict policy for ZIP extraction, mirrors the zipx_conflict_t values. */
typedef enum extract_conflict {
EXTRACT_CONFLICT_FAIL = 0,
EXTRACT_CONFLICT_OVERWRITE = 1,
EXTRACT_CONFLICT_MERGE = 2
} extract_conflict_t;
/* POST /api/extract handler.
Accepts a form-encoded body (matching the other filemgr endpoints):
path - ZIP path on the device (required)
dst_dir - target directory (required)
conflict - "fail" (default) | "overwrite" | "merge"
remove_source - "1" deletes the source ZIP after a successful extraction
(used by the "upload and extract" flow; never set for a
pre-existing user archive).
Returns {"ok":true,"task_id":N} or a JSON error. */
enum MHD_Result api_extract(struct MHD_Connection *conn, const char *body,
size_t body_size);
-68
View File
@@ -1,68 +0,0 @@
#include "filemgr.h"
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <sys/stat.h>
#include <sys/types.h>
#include "filemgr_internal.h"
#include "mime.h"
#include "path_util.h"
#include "websrv.h"
static ssize_t
file_read(void *cls, uint64_t pos, char *buf, size_t max) {
FILE *file = cls;
size_t len;
if(fseek(file, (long)pos, SEEK_SET)) {
return MHD_CONTENT_READER_END_WITH_ERROR;
}
if(!(len = fread(buf, 1, max, file))) {
return ferror(file) ? MHD_CONTENT_READER_END_WITH_ERROR :
MHD_CONTENT_READER_END_OF_STREAM;
}
return (ssize_t)len;
}
static void
file_close(void *cls) {
fclose((FILE *)cls);
}
enum MHD_Result
filemgr_fs_request(struct MHD_Connection *conn) {
char *path = fs_path_value(query_value(conn, "path"));
struct MHD_Response *resp;
enum MHD_Result ret = MHD_NO;
struct stat st;
FILE *file;
if(has_active_task()) {
return send_json_error(conn, MHD_HTTP_CONFLICT, "another task is running");
}
if(!path || stat(path, &st) || !S_ISREG(st.st_mode) ||
!(file = fopen(path, "rb"))) {
free(path);
return send_json_error(conn, MHD_HTTP_NOT_FOUND, "file not found");
}
if((resp = MHD_create_response_from_callback((uint64_t)st.st_size,
32 * 0x4000, file_read, file,
file_close))) {
const char *mime = mime_get_type(path);
if(mime) {
MHD_add_response_header(resp, MHD_HTTP_HEADER_CONTENT_TYPE, mime);
}
ret = websrv_queue_response(conn, MHD_HTTP_OK, resp);
MHD_destroy_response(resp);
free(path);
return ret;
}
fclose(file);
free(path);
return MHD_NO;
}
+1000 -1484
View File
File diff suppressed because it is too large. Load diff
+1 -8
View File
@@ -3,12 +3,5 @@
#include <microhttpd.h>
enum MHD_Result filemgr_api_request(struct MHD_Connection *conn,
const char *url, const char *method,
const char *body, size_t body_size);
const char *url);
enum MHD_Result filemgr_fs_request(struct MHD_Connection *conn);
int filemgr_upload_begin(struct MHD_Connection *conn, void **upload_ctx);
int filemgr_upload_data(void *upload_ctx, const char *data, size_t size);
enum MHD_Result filemgr_upload_finish(struct MHD_Connection *conn,
void *upload_ctx);
void filemgr_upload_free(void *upload_ctx);
-140
View File
@@ -1,140 +0,0 @@
#pragma once
#include <limits.h>
#include <pthread.h>
#include <stddef.h>
#include <time.h>
#include <microhttpd.h>
#define ETA_SAMPLE_SLOTS 64
typedef enum task_op {
TASK_COPY,
TASK_MOVE,
TASK_DELETE,
TASK_CHMOD,
TASK_DOWNLOAD,
TASK_UPLOAD,
TASK_PKG_INSTALL,
TASK_EXTRACT,
} task_op_t;
typedef enum task_state {
TASK_QUEUED,
TASK_RUNNING,
TASK_DONE,
TASK_FAILED,
TASK_CANCELED,
} task_state_t;
typedef struct task_eta_sample {
unsigned long long done;
struct timespec time;
} task_eta_sample_t;
typedef struct file_task {
unsigned long id;
task_op_t op;
task_state_t state;
char src[PATH_MAX];
char dst[PATH_MAX];
char current[PATH_MAX];
char error[160];
char error_code[64];
char error_arg[PATH_MAX + 96];
char **srcs;
size_t src_count;
size_t file_count;
size_t dir_count;
size_t upload_completed;
unsigned int chmod_mode;
int recursive;
unsigned long long total;
unsigned long long done;
unsigned long long speed;
unsigned long long eta;
unsigned long long entries_total;
unsigned long long entries_done;
int extract_conflict;
int extract_remove_source;
int extract_large;
/* UTF-8 password for archives that encrypt their streams (7zAES, RAR5 AES).
Empty means "try without one"; the engine returns ZIPX_ERR_PASSWORD for
an archive that needs one, and the web UI prompts and retries. The
length is bounded so a runaway header field cannot overflow task memory. */
char extract_password[256];
unsigned long long speed_sample_done;
struct timespec speed_sample_time;
task_eta_sample_t eta_samples[ETA_SAMPLE_SLOTS];
unsigned int eta_sample_next;
unsigned int eta_sample_count;
int cancel_requested;
int reported; /* Terminal state has been included in /api/tasks. */
unsigned int active_streams;
time_t created_at;
time_t transfer_started_at;
time_t updated_at;
pthread_t thread;
struct file_task *next;
} file_task_t;
extern pthread_mutex_t g_tasks_lock;
extern file_task_t *g_tasks;
extern unsigned long g_next_task_id;
const char *task_op_name(task_op_t op);
const char *task_state_name(task_state_t state);
int task_is_active(const file_task_t *task);
int has_active_task_locked(void);
int has_active_task(void);
void free_task(file_task_t *task);
void remove_finished_tasks_locked(void);
int task_cancel_requested(file_task_t *task);
file_task_t *find_task_locked(unsigned long id);
void task_update(file_task_t *task, task_state_t state, const char *current,
unsigned long long add_done, const char *error);
void record_task_completion_locked(file_task_t *task, time_t completed_at);
enum MHD_Result send_json_ok(struct MHD_Connection *conn);
enum MHD_Result send_json_error(struct MHD_Connection *conn,
unsigned int status, const char *msg);
enum MHD_Result send_json_error_detail(struct MHD_Connection *conn,
unsigned int status, const char *msg,
const char *code, const char *arg);
enum MHD_Result send_buffer(struct MHD_Connection *conn, unsigned int status,
char *data, const char *mime);
int ensure_parent_dirs(const char *base, const char *rel);
int chmod_path_mode(const char *path, unsigned int mode);
int chmod_path_0777(const char *path);
int fchmod_0777(int fd);
int ignore_chmod_error(int err);
int mode_access(const char *path, int mode);
int check_target_writable(const char *target, char ***checked_dirs,
size_t *checked_dir_count,
char *error, size_t error_size,
char *code, size_t code_size,
char *arg, size_t arg_size);
int check_target_space(const char *target, unsigned long long required,
char *error, size_t error_size,
char *code, size_t code_size,
char *arg, size_t arg_size);
int target_available_space(const char *target, unsigned long long *available);
int count_task_path_bytes(file_task_t *task, const char *path,
const char *display, unsigned long long *total,
size_t *file_count, size_t *dir_count);
enum MHD_Result api_upload_prepare(struct MHD_Connection *conn,
const char *body, size_t body_size);
enum MHD_Result api_upload_finish(struct MHD_Connection *conn);
enum MHD_Result api_download_prepare(struct MHD_Connection *conn,
const char *body, size_t body_size);
enum MHD_Result api_download(struct MHD_Connection *conn);
enum MHD_Result api_list(struct MHD_Connection *conn);
enum MHD_Result api_space(struct MHD_Connection *conn);
enum MHD_Result api_version(struct MHD_Connection *conn);
enum MHD_Result api_text(struct MHD_Connection *conn);
enum MHD_Result api_text_create(struct MHD_Connection *conn);
enum MHD_Result api_text_save(struct MHD_Connection *conn, const char *body,
size_t body_size);
-371
View File
@@ -1,371 +0,0 @@
#include "filemgr_internal.h"
#include <errno.h>
#include <fcntl.h>
#include <limits.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/stat.h>
#include <sys/statvfs.h>
#include <sys/types.h>
#ifdef __linux__
#include <sys/vfs.h>
#else
#include <sys/mount.h>
#endif
#include <time.h>
#include <unistd.h>
#include "path_util.h"
int
ignore_chmod_error(int err) {
return err == ENOTSUP || err == EPERM || err == EINVAL || err == EROFS;
}
#ifndef __linux__
static int
fs_type_has_unix_modes(const char *type) {
return strcmp(type, "exfat") &&
strcmp(type, "exfatfs") &&
strcmp(type, "msdosfs") &&
strcmp(type, "fat") &&
strcmp(type, "vfat");
}
#endif
static int
path_has_unix_modes(const char *path) {
#ifdef __linux__
(void)path;
return 1;
#else
struct statfs fs;
if(statfs(path, &fs)) {
return 1;
}
return fs_type_has_unix_modes(fs.f_fstypename);
#endif
}
static int
fd_has_unix_modes(int fd) {
#ifdef __linux__
(void)fd;
return 1;
#else
struct statfs fs;
if(fstatfs(fd, &fs)) {
return 1;
}
return fs_type_has_unix_modes(fs.f_fstypename);
#endif
}
int
chmod_path_mode(const char *path, unsigned int mode) {
if(!path_has_unix_modes(path)) {
return 0;
}
if(chmod(path, (mode_t)(mode & 0777))) {
/* A filesystem that does not implement Unix modes is compatible with the
paste behavior. Real permission and read-only errors must reach the UI. */
if(errno != ENOTSUP && errno != EINVAL) {
return -1;
}
}
return 0;
}
int
chmod_path_0777(const char *path) {
if(!path_has_unix_modes(path)) {
return 0;
}
if(chmod(path, 0777) && !ignore_chmod_error(errno)) {
return -1;
}
return 0;
}
int
fchmod_0777(int fd) {
if(!fd_has_unix_modes(fd)) {
return 0;
}
if(fchmod(fd, 0777) && !ignore_chmod_error(errno)) {
return -1;
}
return 0;
}
static int
target_statvfs(const char *target, struct statvfs *vfs) {
char parent[PATH_MAX];
if(!statvfs(target, vfs)) {
return 0;
}
if(path_dirname(target, parent, sizeof(parent))) {
return -1;
}
return statvfs(parent, vfs);
}
int
target_available_space(const char *target, unsigned long long *available) {
struct statvfs vfs;
unsigned long long block_size;
if(target_statvfs(target, &vfs)) {
return -1;
}
block_size = vfs.f_frsize ? vfs.f_frsize : vfs.f_bsize;
*available = (unsigned long long)vfs.f_bavail * block_size;
return 0;
}
int
check_target_space(const char *target, unsigned long long required,
char *error, size_t error_size,
char *code, size_t code_size,
char *arg, size_t arg_size) {
unsigned long long available;
if(!required) {
return 0;
}
if(target_available_space(target, &available)) {
snprintf(error, error_size, "cannot read target free space");
snprintf(code, code_size, "space_check_failed");
snprintf(arg, arg_size, "%s", target);
return -1;
}
if(available < required) {
snprintf(error, error_size,
"not enough target space, required %llu bytes, available %llu bytes",
required, available);
snprintf(code, code_size, "no_space");
snprintf(arg, arg_size, "%llu,%llu", required, available);
errno = ENOSPC;
return -1;
}
return 0;
}
static void
set_error_detail(char *error, size_t error_size, char *code, size_t code_size,
char *arg, size_t arg_size, const char *error_code,
const char *message, const char *path) {
snprintf(error, error_size, "%s: %s", message, path);
snprintf(code, code_size, "%s", error_code);
snprintf(arg, arg_size, "%s", path);
}
static void
set_permission_error_detail(char *error, size_t error_size,
char *code, size_t code_size,
char *arg, size_t arg_size,
const char *error_code, const char *message,
const char *path) {
struct stat st;
set_error_detail(error, error_size, code, code_size, arg, arg_size,
error_code, message, path);
if(!stat(path, &st)) {
snprintf(arg, arg_size, "%s (mode=%04o, uid=%lu, gid=%lu)", path,
(unsigned int)(st.st_mode & 07777),
(unsigned long)st.st_uid, (unsigned long)st.st_gid);
}
}
static int
mode_access_stat(const struct stat *st, int mode) {
mode_t allowed;
uid_t uid = geteuid();
if(uid == 0) {
if(!(mode & X_OK) || !S_ISREG(st->st_mode) ||
(st->st_mode & (S_IXUSR | S_IXGRP | S_IXOTH))) {
return 0;
}
} else if(uid == st->st_uid) {
allowed = (st->st_mode >> 6) & 7;
if((allowed & mode) == (mode_t)mode) {
return 0;
}
} else {
gid_t gid = getegid();
int group_match = gid == st->st_gid;
if(!group_match) {
int count = getgroups(0, NULL);
gid_t *groups = count > 0 ? malloc((size_t)count * sizeof(*groups)) : NULL;
if(groups && getgroups(count, groups) == count) {
int i;
for(i = 0; i < count; i++) {
if(groups[i] == st->st_gid) {
group_match = 1;
break;
}
}
}
free(groups);
}
allowed = group_match ? (st->st_mode >> 3) & 7 : st->st_mode & 7;
if((allowed & mode) == (mode_t)mode) {
return 0;
}
}
errno = EACCES;
return -1;
}
int
mode_access(const char *path, int mode) {
struct stat st;
return stat(path, &st) ? -1 : mode_access_stat(&st, mode);
}
static int
probe_dir_writable(const char *path) {
char name[80];
char probe[PATH_MAX];
int attempt;
for(attempt = 0; attempt < 16; attempt++) {
int fd;
int error = 0;
snprintf(name, sizeof(name), ".web-file-mgr-%ld-%lld-%d.tmp",
(long)getpid(), (long long)time(NULL), attempt);
if(path_join(probe, sizeof(probe), path, name)) {
return -1;
}
fd = open(probe, O_WRONLY | O_CREAT | O_EXCL, 0600);
if(fd < 0) {
if(errno == EEXIST) {
continue;
}
return -1;
}
if(close(fd)) {
error = errno;
}
if(unlink(probe) && !error) {
error = errno;
}
if(error) {
errno = error;
return -1;
}
return 0;
}
errno = EEXIST;
return -1;
}
static int
probe_file_writable(const char *path) {
int fd = open(path, O_WRONLY);
return fd < 0 ? -1 : close(fd);
}
static int
path_seen(char **paths, size_t count, const char *path) {
size_t i;
for(i = 0; i < count; i++) {
if(!strcmp(paths[i], path)) {
return 1;
}
}
return 0;
}
static int
remember_path(char ***paths, size_t *count, const char *path) {
char **tmp;
if(path_seen(*paths, *count, path)) {
return 0;
}
tmp = realloc(*paths, sizeof(char *) * (*count + 1));
if(!tmp) {
errno = ENOMEM;
return -1;
}
*paths = tmp;
(*paths)[*count] = strdup(path);
if(!(*paths)[*count]) {
errno = ENOMEM;
return -1;
}
(*count)++;
return 0;
}
static int
probe_dir_once(const char *path, char ***checked, size_t *checked_count) {
if(path_seen(*checked, *checked_count, path)) {
return 0;
}
if(probe_dir_writable(path)) {
return -1;
}
return remember_path(checked, checked_count, path);
}
int
check_target_writable(const char *target, char ***checked_dirs,
size_t *checked_dir_count, char *error, size_t error_size,
char *code, size_t code_size, char *arg, size_t arg_size) {
struct stat st;
char parent[PATH_MAX];
if(!stat(target, &st)) {
if(S_ISDIR(st.st_mode)) {
if(probe_dir_once(target, checked_dirs, checked_dir_count)) {
set_permission_error_detail(error, error_size, code, code_size,
arg, arg_size, "target_dir_not_writable",
"target directory is not writable", target);
return -1;
}
} else {
if(probe_file_writable(target)) {
set_permission_error_detail(error, error_size, code, code_size,
arg, arg_size, "target_file_not_writable",
"target file is not writable", target);
return -1;
}
goto check_parent;
}
return 0;
}
if(errno != ENOENT) {
set_error_detail(error, error_size, code, code_size, arg, arg_size,
"target_check_failed", "cannot check target path", target);
return -1;
}
check_parent:
if(path_dirname(target, parent, sizeof(parent))) {
set_error_detail(error, error_size, code, code_size, arg, arg_size,
"target_check_failed", "cannot check target path", target);
return -1;
}
if(probe_dir_once(parent, checked_dirs, checked_dir_count)) {
set_permission_error_detail(error, error_size, code, code_size,
arg, arg_size, "target_parent_not_writable",
"current directory is not writable", parent);
return -1;
}
return 0;
}
-90
View File
@@ -1,90 +0,0 @@
#include "json_util.h"
#include <stdarg.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
int
strbuf_reserve(strbuf_t *b, size_t extra) {
size_t need = b->len + extra + 1;
char *tmp;
size_t cap;
if(need <= b->cap) {
return 0;
}
cap = b->cap ? b->cap : 4096;
while(cap < need) {
cap *= 2;
}
if(!(tmp = realloc(b->data, cap))) {
return -1;
}
b->data = tmp;
b->cap = cap;
return 0;
}
int
strbuf_append(strbuf_t *b, const char *s) {
size_t n = strlen(s);
if(strbuf_reserve(b, n)) {
return -1;
}
memcpy(b->data + b->len, s, n + 1);
b->len += n;
return 0;
}
int
strbuf_printf(strbuf_t *b, const char *fmt, ...) {
va_list ap;
va_list cp;
int n;
va_start(ap, fmt);
va_copy(cp, ap);
n = vsnprintf(NULL, 0, fmt, cp);
va_end(cp);
if(n < 0 || strbuf_reserve(b, (size_t)n)) {
va_end(ap);
return -1;
}
vsnprintf(b->data + b->len, b->cap - b->len, fmt, ap);
va_end(ap);
b->len += (size_t)n;
return 0;
}
int
json_escape(strbuf_t *b, const char *s) {
if(strbuf_append(b, "\"")) return -1;
while(*s) {
unsigned char c = (unsigned char)*s;
switch(c) {
case '"': if(strbuf_append(b, "\\\"")) return -1; s++; break;
case '\\': if(strbuf_append(b, "\\\\")) return -1; s++; break;
case '\b': if(strbuf_append(b, "\\b")) return -1; s++; break;
case '\f': if(strbuf_append(b, "\\f")) return -1; s++; break;
case '\n': if(strbuf_append(b, "\\n")) return -1; s++; break;
case '\r': if(strbuf_append(b, "\\r")) return -1; s++; break;
case '\t': if(strbuf_append(b, "\\t")) return -1; s++; break;
default:
if(c < 0x20 || c >= 0x80) {
if(strbuf_printf(b, "\\u%04x", c)) return -1;
} else {
if(strbuf_reserve(b, 1)) return -1;
b->data[b->len++] = (char)c;
b->data[b->len] = 0;
}
s++;
break;
}
}
return strbuf_append(b, "\"");
}
-14
View File
@@ -1,14 +0,0 @@
#pragma once
#include <stddef.h>
typedef struct strbuf {
char *data;
size_t len;
size_t cap;
} strbuf_t;
int strbuf_reserve(strbuf_t *b, size_t extra);
int strbuf_append(strbuf_t *b, const char *s);
int strbuf_printf(strbuf_t *b, const char *fmt, ...);
int json_escape(strbuf_t *b, const char *s);
-84
View File
@@ -1,84 +0,0 @@
#include "filemgr_internal.h"
#include <dirent.h>
#include <limits.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/stat.h>
#include <unistd.h>
#include "json_util.h"
#include "path_util.h"
static char
mode_type(const struct stat *st) {
if(S_ISDIR(st->st_mode)) return 'd';
if(S_ISLNK(st->st_mode)) return 'l';
if(S_ISCHR(st->st_mode)) return 'c';
if(S_ISBLK(st->st_mode)) return 'b';
if(S_ISFIFO(st->st_mode)) return 'p';
if(S_ISSOCK(st->st_mode)) return 's';
return '-';
}
enum MHD_Result
api_list(struct MHD_Connection *conn) {
char *path = fs_path_value(query_value(conn, "path"));
DIR *dir;
struct dirent *entry;
struct stat st;
strbuf_t b = {0};
int first = 1;
if(has_active_task()) {
return send_json_error(conn, MHD_HTTP_CONFLICT, "another task is running");
}
if(!path) {
path = strdup("/");
}
if(!(dir = opendir(path))) {
free(path);
return send_json_error(conn, MHD_HTTP_NOT_FOUND, NULL);
}
strbuf_append(&b, "{\"ok\":true,\"path\":");
json_escape(&b, path);
strbuf_append(&b, ",\"parent\":");
char parent[PATH_MAX];
if(path_dirname(path, parent, sizeof(parent))) {
strcpy(parent, "/");
}
json_escape(&b, parent);
strbuf_append(&b, ",\"entries\":[");
while((entry = readdir(dir))) {
char child[PATH_MAX];
if(!strcmp(entry->d_name, ".") || !strcmp(entry->d_name, "..")) {
continue;
}
if(path_join(child, sizeof(child), path, entry->d_name) ||
lstat(child, &st)) {
continue;
}
if(!first) {
strbuf_append(&b, ",");
}
first = 0;
strbuf_append(&b, "{\"name\":");
json_escape(&b, entry->d_name);
strbuf_append(&b, ",\"path\":");
json_escape(&b, child);
strbuf_printf(&b, ",\"type\":\"%c\",\"mode\":%u,\"size\":%lld,\"mtime\":%lld}",
mode_type(&st), (unsigned int)(st.st_mode & 07777),
(long long)st.st_size, (long long)st.st_mtime);
}
closedir(dir);
free(path);
strbuf_append(&b, "]}");
return send_buffer(conn, MHD_HTTP_OK, b.data, "application/json");
}
-3
View File
@@ -150,9 +150,6 @@ main(int argc, char **argv) {
#endif
websrv_listen(port);
if(websrv_stop_requested()) {
break;
}
sleep(3);
}
-3
View File
@@ -8,10 +8,8 @@ typedef struct mime_entry {
} mime_entry_t;
static const mime_entry_t g_mimes[] = {
{"bmp", "image/bmp"},
{"css", "text/css"},
{"elf", "application/octet-stream"},
{"gif", "image/gif"},
{"html", "text/html"},
{"jpeg", "image/jpeg"},
{"jpg", "image/jpeg"},
@@ -22,7 +20,6 @@ static const mime_entry_t g_mimes[] = {
{"png", "image/png"},
{"txt", "text/plain"},
{"xml", "text/xml"},
{"webp", "image/webp"},
{"zip", "application/zip"},
};
-401
View File
@@ -1,401 +0,0 @@
#include "path_util.h"
#include <ctype.h>
#include <errno.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
char *
query_value(struct MHD_Connection *conn, const char *key) {
const char *raw = MHD_lookup_connection_value(conn, MHD_GET_ARGUMENT_KIND, key);
char *value = raw ? strdup(raw) : NULL;
if(value && !strcmp(key, "name")) {
char *start = value;
char *end;
while(isspace((unsigned char)*start)) start++;
end = start + strlen(start);
while(end > start && isspace((unsigned char)end[-1])) end--;
memmove(value, start, (size_t)(end - start));
value[end - start] = 0;
}
return value;
}
char *
header_value(struct MHD_Connection *conn, const char *key) {
const char *raw = MHD_lookup_connection_value(conn, MHD_HEADER_KIND, key);
return raw ? form_decode(raw, strlen(raw)) : NULL;
}
char *
request_value(struct MHD_Connection *conn, const char *header,
const char *query) {
char *value = header_value(conn, header);
return value ? value : query_value(conn, query);
}
static int
hex_value(char c) {
if(c >= '0' && c <= '9') return c - '0';
if(c >= 'a' && c <= 'f') return c - 'a' + 10;
if(c >= 'A' && c <= 'F') return c - 'A' + 10;
return -1;
}
char *
form_decode(const char *src, size_t len) {
char *out = malloc(len + 1);
size_t i;
size_t j = 0;
if(!out) {
return NULL;
}
for(i = 0; i < len; i++) {
if(src[i] == '+') {
out[j++] = ' ';
} else if(src[i] == '%' && i + 2 < len) {
int hi = hex_value(src[i + 1]);
int lo = hex_value(src[i + 2]);
if(hi >= 0 && lo >= 0) {
out[j++] = (char)((hi << 4) | lo);
i += 2;
} else {
out[j++] = src[i];
}
} else {
out[j++] = src[i];
}
}
out[j] = 0;
return out;
}
char *
body_form_value(const char *body, size_t body_size, const char *key) {
size_t key_len = strlen(key);
size_t pos = 0;
while(body && pos < body_size) {
size_t start = pos;
size_t end;
size_t eq;
while(pos < body_size && body[pos] != '&') {
pos++;
}
end = pos;
if(pos < body_size && body[pos] == '&') {
pos++;
}
eq = start;
while(eq < end && body[eq] != '=') {
eq++;
}
if(eq - start == key_len && !strncmp(body + start, key, key_len)) {
return form_decode(body + eq + (eq < end), end - eq - (eq < end));
}
}
return NULL;
}
void
free_paths(char **paths, size_t count) {
size_t i;
if(!paths) {
return;
}
for(i = 0; i < count; i++) {
free(paths[i]);
}
free(paths);
}
int
parse_paths(const char *raw, char ***out_paths, size_t *out_count) {
char *copy;
char *line;
char *save;
char **paths = NULL;
size_t count = 0;
size_t capacity = 0;
const char *p;
int in_line = 0;
*out_paths = NULL;
*out_count = 0;
if(!raw || !raw[0]) {
errno = EINVAL;
return -1;
}
for(p = raw; *p; p++) {
if(*p == '\n') {
if(in_line) {
capacity++;
in_line = 0;
}
continue;
}
in_line = 1;
}
if(in_line) {
capacity++;
}
if(!capacity) {
errno = EINVAL;
return -1;
}
if(!(paths = calloc(capacity, sizeof(char *))) ||
!(copy = strdup(raw))) {
free(paths);
errno = ENOMEM;
return -1;
}
for(line = strtok_r(copy, "\n", &save); line; line = strtok_r(NULL, "\n", &save)) {
if(!line[0]) {
continue;
}
if(!(paths[count] = fs_path_value(strdup(line)))) {
free_paths(paths, count);
free(copy);
errno = ENOMEM;
return -1;
}
count++;
}
free(copy);
if(!count) {
errno = EINVAL;
return -1;
}
*out_paths = paths;
*out_count = count;
return 0;
}
const char *
path_basename(const char *path) {
const char *end = path + strlen(path);
const char *base;
while(end > path && end[-1] == '/') {
end--;
}
base = end;
while(base > path && base[-1] != '/') {
base--;
}
return base;
}
void
path_basename_copy(const char *path, char *out, size_t size) {
const char *end = path + strlen(path);
const char *base;
size_t len;
while(end > path && end[-1] == '/') {
end--;
}
base = end;
while(base > path && base[-1] != '/') {
base--;
}
len = (size_t)(end - base);
if(!len) {
snprintf(out, size, "root");
return;
}
if(len >= size) {
len = size - 1;
}
memcpy(out, base, len);
out[len] = 0;
}
int
path_dirname(const char *path, char *out, size_t size) {
const char *base = path_basename(path);
size_t len = (size_t)(base - path);
while(len > 1 && path[len - 1] == '/') {
len--;
}
if(!len) {
len = 1;
}
if(len >= size) {
return -1;
}
memcpy(out, path, len);
out[len] = 0;
return 0;
}
int
path_join(char *out, size_t size, const char *dir, const char *name) {
int n;
if(!dir || !name || !dir[0] || !name[0] || strchr(name, '/')) {
errno = EINVAL;
return -1;
}
n = snprintf(out, size, "%s%s%s", dir,
(strcmp(dir, "/") && dir[strlen(dir) - 1] != '/') ? "/" : "",
name);
if(n < 0 || (size_t)n >= size) {
errno = ENAMETOOLONG;
return -1;
}
return 0;
}
int
relative_path_safe(const char *path) {
const char *p = path;
if(!path || !path[0] || path[0] == '/') {
errno = EINVAL;
return 0;
}
while(*p) {
const char *start = p;
size_t len;
while(*p && *p != '/') {
if(*p == '\\') {
errno = EINVAL;
return 0;
}
p++;
}
len = (size_t)(p - start);
if(!len || (len == 1 && start[0] == '.') ||
(len == 2 && start[0] == '.' && start[1] == '.')) {
errno = EINVAL;
return 0;
}
if(*p == '/') {
p++;
}
}
return 1;
}
int
path_join_relative(char *out, size_t size, const char *dir, const char *rel) {
int n;
if(!relative_path_safe(rel)) {
return -1;
}
n = snprintf(out, size, "%s%s%s", dir,
(strcmp(dir, "/") && dir[strlen(dir) - 1] != '/') ? "/" : "",
rel);
if(n < 0 || (size_t)n >= size) {
errno = ENAMETOOLONG;
return -1;
}
return 0;
}
static int
utf8_decode_char(const char **ps, unsigned int *out) {
const unsigned char *s = (const unsigned char *)*ps;
unsigned char c = s[0];
unsigned int cp;
size_t n;
size_t i;
if(c < 0x80) {
*out = c;
*ps += 1;
return 0;
}
if((c & 0xe0) == 0xc0) {
cp = c & 0x1f;
n = 2;
} else if((c & 0xf0) == 0xe0) {
cp = c & 0x0f;
n = 3;
} else if((c & 0xf8) == 0xf0) {
cp = c & 0x07;
n = 4;
} else {
return -1;
}
for(i = 1; i < n; i++) {
unsigned char t = s[i];
if(!t || (t & 0xc0) != 0x80) {
return -1;
}
cp = (cp << 6) | (t & 0x3f);
}
if((n == 2 && cp < 0x80) ||
(n == 3 && cp < 0x800) ||
(n == 4 && (cp < 0x10000 || cp > 0x10ffff)) ||
(cp >= 0xd800 && cp <= 0xdfff)) {
return -1;
}
*out = cp;
*ps += n;
return 0;
}
char *
fs_path_value(char *path) {
const char *p;
char *out;
size_t len;
size_t pos = 0;
int has_byte_token = 0;
if(!path) {
return path;
}
for(p = path; *p;) {
unsigned int cp;
const char *next = p;
if(utf8_decode_char(&next, &cp)) {
return path;
}
if(cp >= 0x80 && cp <= 0xff) {
has_byte_token = 1;
} else if(cp > 0xff) {
return path;
}
p = next;
}
if(!has_byte_token) {
return path;
}
len = strlen(path);
if(!(out = malloc(len + 1))) {
return path;
}
for(p = path; *p;) {
unsigned int cp;
const char *next = p;
if(utf8_decode_char(&next, &cp)) {
free(out);
return path;
}
out[pos++] = (char)(unsigned char)cp;
p = next;
}
out[pos] = 0;
free(path);
return out;
}
-24
View File
@@ -1,24 +0,0 @@
#pragma once
#include <stddef.h>
#include <limits.h>
#include <microhttpd.h>
char *query_value(struct MHD_Connection *conn, const char *key);
char *header_value(struct MHD_Connection *conn, const char *key);
char *request_value(struct MHD_Connection *conn, const char *header,
const char *query);
char *form_decode(const char *src, size_t len);
char *body_form_value(const char *body, size_t body_size, const char *key);
void free_paths(char **paths, size_t count);
int parse_paths(const char *raw, char ***out_paths, size_t *out_count);
const char *path_basename(const char *path);
void path_basename_copy(const char *path, char *out, size_t size);
int path_dirname(const char *path, char *out, size_t size);
int path_join(char *out, size_t size, const char *dir, const char *name);
int relative_path_safe(const char *path);
int path_join_relative(char *out, size_t size, const char *dir, const char *rel);
char *fs_path_value(char *path);
-591
View File
@@ -1,591 +0,0 @@
#include "pkg_info.h"
#include <errno.h>
#include <fcntl.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/stat.h>
#include <unistd.h>
#include "filemgr_internal.h"
#include "json_util.h"
#include "path_util.h"
#include "websrv.h"
#define PKG_CNT_MAGIC 0x7f434e54u
#define PKG_FIH_MAGIC 0x7f464948u
#define PKG_LIH_MAGIC 0x7f4c4948u
#define PKG_HEADER_SIZE 0xa0
#define PKG_ENTRY_SIZE 0x20
#define PKG_ENTRY_PARAM_SFO 0x1000u
#define PKG_ENTRY_ICON0_PNG 0x1200u
#define PKG_ENTRY_ICON0_LOCALIZED_LAST 0x121fu
#define PKG_ENTRY_PARAM_JSON 0x2000u
#define PKG_ENTRY_FLAG_ENCRYPTED 0x80000000u
#define PKG_ENTRY_MAX 65536u
#define PKG_PARAM_MAX (4u * 1024u * 1024u)
#define PKG_ICON_MAX (32u * 1024u * 1024u)
#define SFO_MAGIC 0x46535000u
#define SFO_ENTRY_SIZE 0x10
#define SFO_ENTRY_MAX 256u
#define JSON_TOKEN_MAX 4096u
typedef enum pkg_param_type {
PKG_PARAM_SFO,
PKG_PARAM_JSON,
} pkg_param_type_t;
typedef struct pkg_source {
int fd;
uint64_t size;
uint32_t content_type;
uint32_t content_flags;
char content_id[37];
uint64_t param_offset;
uint32_t param_size;
pkg_param_type_t param_type;
uint64_t icon_offset;
uint32_t icon_size;
} pkg_source_t;
typedef enum json_token_type {
JSON_OBJECT,
JSON_ARRAY,
JSON_STRING,
JSON_PRIMITIVE,
} json_token_type_t;
typedef struct json_token {
json_token_type_t type;
size_t start;
size_t end;
int parent;
} json_token_t;
static uint16_t
read_le16(const unsigned char *p) {
return (uint16_t)p[0] | (uint16_t)p[1] << 8;
}
static uint32_t
read_le32(const unsigned char *p) {
return (uint32_t)p[0] | (uint32_t)p[1] << 8 |
(uint32_t)p[2] << 16 | (uint32_t)p[3] << 24;
}
static uint64_t
read_le64(const unsigned char *p) {
return (uint64_t)read_le32(p) | (uint64_t)read_le32(p + 4) << 32;
}
static uint32_t
read_be32(const unsigned char *p) {
return (uint32_t)p[0] << 24 | (uint32_t)p[1] << 16 |
(uint32_t)p[2] << 8 | (uint32_t)p[3];
}
static int
range_valid(uint64_t offset, uint64_t size, uint64_t file_size) {
return offset <= file_size && size <= file_size - offset;
}
static int
read_at(int fd, void *buffer, size_t size, uint64_t offset) {
unsigned char *p = buffer;
size_t done = 0;
while(done < size) {
ssize_t n = pread(fd, p + done, size - done, (off_t)(offset + done));
if(n <= 0) {
if(n < 0 && errno == EINTR) continue;
return -1;
}
done += (size_t)n;
}
return 0;
}
static int
png_signature_valid(const unsigned char *data, size_t size) {
static const unsigned char signature[] = "\x89PNG\r\n\x1a\n";
return size >= sizeof(signature) - 1 &&
!memcmp(data, signature, sizeof(signature) - 1);
}
static int
pkg_icon_is_png(const pkg_source_t *pkg, uint64_t offset, uint32_t size) {
unsigned char signature[8];
return size >= sizeof(signature) &&
!read_at(pkg->fd, signature, sizeof(signature), offset) &&
png_signature_valid(signature, sizeof(signature));
}
static void
pkg_source_close(pkg_source_t *pkg) {
if(pkg->fd >= 0) close(pkg->fd);
pkg->fd = -1;
}
static int
pkg_source_open(const char *path, pkg_source_t *pkg) {
unsigned char header[PKG_HEADER_SIZE];
unsigned char *table = NULL;
struct stat st;
uint64_t container_offset = 0;
uint64_t container_size;
uint32_t magic;
uint32_t entry_count;
uint32_t table_offset;
size_t table_size;
int ret = -1;
memset(pkg, 0, sizeof(*pkg));
pkg->fd = -1;
if((pkg->fd = open(path, O_RDONLY)) < 0 || fstat(pkg->fd, &st) ||
!S_ISREG(st.st_mode) || st.st_size < PKG_HEADER_SIZE ||
read_at(pkg->fd, header, sizeof(header), 0)) goto done;
pkg->size = (uint64_t)st.st_size;
magic = read_be32(header);
if(magic == PKG_FIH_MAGIC) {
container_offset = read_le64(header + 0x58);
} else if(magic == PKG_LIH_MAGIC) {
container_offset = read_le64(header + 0x30);
} else if(magic != PKG_CNT_MAGIC) {
goto done;
}
if(container_offset) {
if(!range_valid(container_offset, sizeof(header), pkg->size) ||
read_at(pkg->fd, header, sizeof(header), container_offset) ||
read_be32(header) != PKG_CNT_MAGIC) goto done;
}
container_size = pkg->size - container_offset;
memcpy(pkg->content_id, header + 0x40, 36);
pkg->content_id[36] = 0;
pkg->content_type = read_be32(header + 0x74);
pkg->content_flags = read_be32(header + 0x78);
entry_count = read_be32(header + 0x10);
table_offset = read_be32(header + 0x18);
if(!entry_count || entry_count > PKG_ENTRY_MAX) goto done;
table_size = (size_t)entry_count * PKG_ENTRY_SIZE;
if(!range_valid(table_offset, table_size, container_size) ||
!(table = malloc(table_size)) ||
read_at(pkg->fd, table, table_size, container_offset + table_offset)) {
goto done;
}
for(uint32_t i = 0; i < entry_count; i++) {
const unsigned char *entry = table + (size_t)i * PKG_ENTRY_SIZE;
uint32_t id = read_be32(entry);
uint32_t flags1 = read_be32(entry + 0x08);
uint32_t offset = read_be32(entry + 0x10);
uint32_t size = read_be32(entry + 0x14);
int encrypted = (flags1 & PKG_ENTRY_FLAG_ENCRYPTED) != 0;
if(!range_valid(offset, size, container_size)) goto done;
if(encrypted || !size) continue;
if(id == PKG_ENTRY_PARAM_SFO && size <= PKG_PARAM_MAX) {
pkg->param_offset = container_offset + offset;
pkg->param_size = size;
pkg->param_type = PKG_PARAM_SFO;
} else if(id == PKG_ENTRY_PARAM_JSON && size <= PKG_PARAM_MAX) {
pkg->param_offset = container_offset + offset;
pkg->param_size = size;
pkg->param_type = PKG_PARAM_JSON;
} else if(id >= PKG_ENTRY_ICON0_PNG &&
id <= PKG_ENTRY_ICON0_LOCALIZED_LAST &&
size <= PKG_ICON_MAX &&
(id == PKG_ENTRY_ICON0_PNG || !pkg->icon_size) &&
pkg_icon_is_png(pkg, container_offset + offset, size)) {
/* Prefer icon0.png; otherwise keep the first valid localized icon. */
pkg->icon_offset = container_offset + offset;
pkg->icon_size = size;
}
}
if(!pkg->param_size) goto done;
ret = 0;
done:
free(table);
if(ret) {
errno = EINVAL;
pkg_source_close(pkg);
}
return ret;
}
static int
append_sfo_fields(strbuf_t *json, const unsigned char *sfo, size_t size) {
uint32_t key_offset;
uint32_t value_offset;
uint32_t count;
uint64_t index_end;
int first = 1;
if(size < 20 || read_le32(sfo) != SFO_MAGIC) return -1;
key_offset = read_le32(sfo + 8);
value_offset = read_le32(sfo + 12);
count = read_le32(sfo + 16);
index_end = 20 + (uint64_t)count * SFO_ENTRY_SIZE;
if(count > SFO_ENTRY_MAX || index_end > size || key_offset < index_end ||
value_offset < key_offset || value_offset > size) return -1;
strbuf_append(json, "[");
for(uint32_t i = 0; i < count; i++) {
const unsigned char *entry = sfo + 20 + (size_t)i * SFO_ENTRY_SIZE;
uint16_t name_offset = read_le16(entry);
uint16_t format = read_le16(entry + 2);
uint32_t value_size = read_le32(entry + 4);
uint32_t value_max = read_le32(entry + 8);
uint32_t data_offset = read_le32(entry + 12);
uint64_t key_pos = (uint64_t)key_offset + name_offset;
uint64_t value_pos = (uint64_t)value_offset + data_offset;
const unsigned char *key_end;
char number[32];
char *value = NULL;
if(key_pos >= value_offset || value_pos > size ||
(value_max && value_size > value_max)) continue;
key_end = memchr(sfo + key_pos, 0, value_offset - (size_t)key_pos);
if(!key_end) continue;
if(format == 0x0204) {
size_t length;
if(!value_size || !range_valid(value_pos, value_size, size)) continue;
length = strnlen((const char *)sfo + value_pos, value_size);
if(!(value = malloc(length + 1))) continue;
memcpy(value, sfo + value_pos, length);
value[length] = 0;
} else if(format == 0x0404 && range_valid(value_pos, 4, size)) {
snprintf(number, sizeof(number), "%u", read_le32(sfo + value_pos));
value = strdup(number);
}
if(!value) continue;
if(!first) strbuf_append(json, ",");
first = 0;
strbuf_append(json, "{\"name\":");
json_escape(json, (const char *)sfo + key_pos);
strbuf_append(json, ",\"value\":");
json_escape(json, value);
strbuf_append(json, "}");
free(value);
}
strbuf_append(json, "]");
return 0;
}
static int
json_add_token(json_token_t *tokens, size_t *count, json_token_type_t type,
size_t start, int parent) {
if(*count >= JSON_TOKEN_MAX) return -1;
tokens[*count] = (json_token_t){
.type = type, .start = start, .end = 0, .parent = parent
};
return (int)(*count)++;
}
static int
parse_json_tokens(const unsigned char *data, size_t size, json_token_t *tokens,
size_t *token_count) {
int parent = -1;
size_t count = 0;
for(size_t i = 0; i < size; i++) {
unsigned char c = data[i];
if(c == '{' || c == '[') {
int index = json_add_token(tokens, &count,
c == '{' ? JSON_OBJECT : JSON_ARRAY,
i, parent);
if(index < 0) return -1;
parent = index;
} else if(c == '}' || c == ']') {
json_token_type_t type = c == '}' ? JSON_OBJECT : JSON_ARRAY;
if(parent < 0 || tokens[parent].type != type) return -1;
tokens[parent].end = i + 1;
parent = tokens[parent].parent;
} else if(c == '"') {
int index = json_add_token(tokens, &count, JSON_STRING, i + 1, parent);
if(index < 0) return -1;
for(i++; i < size && data[i] != '"'; i++) {
if(data[i] < 0x20) return -1;
if(data[i] == '\\') {
if(++i >= size || !strchr("\"\\/bfnrtu", data[i])) return -1;
if(data[i] == 'u') {
for(unsigned int n = 0; n < 4; n++) {
if(++i >= size || !((data[i] >= '0' && data[i] <= '9') ||
(data[i] >= 'a' && data[i] <= 'f') ||
(data[i] >= 'A' && data[i] <= 'F'))) return -1;
}
}
}
}
if(i >= size) return -1;
tokens[index].end = i;
} else if(c == ':' || c == ',' || c == ' ' || c == '\t' ||
c == '\r' || c == '\n') {
continue;
} else {
int index = json_add_token(tokens, &count, JSON_PRIMITIVE, i, parent);
if(index < 0) return -1;
while(i < size && data[i] != ',' && data[i] != ']' && data[i] != '}' &&
data[i] != ' ' && data[i] != '\t' && data[i] != '\r' &&
data[i] != '\n') i++;
if(tokens[index].start == i) return -1;
tokens[index].end = i;
i--;
}
}
if(parent >= 0 || !count || tokens[0].type != JSON_OBJECT ||
!tokens[0].end) return -1;
*token_count = count;
return 0;
}
static int
json_token_equals(const unsigned char *data, const json_token_t *token,
const char *text) {
size_t length = strlen(text);
return token->type == JSON_STRING && token->end - token->start == length &&
!memcmp(data + token->start, text, length);
}
static int
json_next_child(const json_token_t *tokens, size_t count, int parent,
size_t start) {
for(size_t i = start; i < count; i++) {
if(tokens[i].parent == parent) return (int)i;
}
return -1;
}
static int
json_object_value(const unsigned char *data, const json_token_t *tokens,
size_t count, int object, const char *key) {
int item = json_next_child(tokens, count, object, (size_t)object + 1);
while(item >= 0) {
int value = json_next_child(tokens, count, object, (size_t)item + 1);
if(value < 0) return -1;
if(json_token_equals(data, &tokens[item], key)) return value;
item = json_next_child(tokens, count, object, (size_t)value + 1);
}
return -1;
}
static int
json_object_value_token(const unsigned char *data, const json_token_t *tokens,
size_t count, int object, const json_token_t *key) {
int item = json_next_child(tokens, count, object, (size_t)object + 1);
size_t key_size = key->end - key->start;
while(item >= 0) {
int value = json_next_child(tokens, count, object, (size_t)item + 1);
if(value < 0) return -1;
if(tokens[item].type == JSON_STRING &&
tokens[item].end - tokens[item].start == key_size &&
!memcmp(data + tokens[item].start, data + key->start, key_size)) {
return value;
}
item = json_next_child(tokens, count, object, (size_t)value + 1);
}
return -1;
}
static void
append_json_token_string(strbuf_t *json, const unsigned char *data,
const json_token_t *token) {
strbuf_append(json, "\"");
strbuf_printf(json, "%.*s", (int)(token->end - token->start),
data + token->start);
strbuf_append(json, "\"");
}
static void
append_json_field(strbuf_t *json, const unsigned char *data,
const json_token_t *key, const json_token_t *value,
int *first) {
if(!*first) strbuf_append(json, ",");
*first = 0;
strbuf_append(json, "{\"name\":");
append_json_token_string(json, data, key);
strbuf_append(json, ",\"value\":");
append_json_token_string(json, data, value);
strbuf_append(json, "}");
}
static void
append_named_json_field(strbuf_t *json, const char *name,
const unsigned char *data, const json_token_t *value,
int *first) {
if(!*first) strbuf_append(json, ",");
*first = 0;
strbuf_append(json, "{\"name\":");
json_escape(json, name);
strbuf_append(json, ",\"value\":");
append_json_token_string(json, data, value);
strbuf_append(json, "}");
}
static int
append_param_json_fields(strbuf_t *json, const unsigned char *data,
size_t size) {
json_token_t *tokens = calloc(JSON_TOKEN_MAX, sizeof(*tokens));
size_t count = 0;
int first = 1;
int localized;
int title = -1;
if(!tokens || parse_json_tokens(data, size, tokens, &count)) {
free(tokens);
return -1;
}
strbuf_append(json, "[");
localized = json_object_value(data, tokens, count, 0, "localizedParameters");
if(localized >= 0 && tokens[localized].type == JSON_OBJECT) {
int language = json_object_value(data, tokens, count, localized,
"defaultLanguage");
int language_data = language >= 0 && tokens[language].type == JSON_STRING ?
json_object_value_token(data, tokens, count, localized,
&tokens[language]) : -1;
if(language_data >= 0 && tokens[language_data].type == JSON_OBJECT) {
title = json_object_value(data, tokens, count, language_data,
"titleName");
}
if(title < 0) {
int english = json_object_value(data, tokens, count, localized, "en-US");
if(english >= 0 && tokens[english].type == JSON_OBJECT) {
title = json_object_value(data, tokens, count, english, "titleName");
}
}
if(title < 0) {
int item = json_next_child(tokens, count, localized,
(size_t)localized + 1);
while(item >= 0 && title < 0) {
int value = json_next_child(tokens, count, localized,
(size_t)item + 1);
if(value < 0) break;
if(tokens[value].type == JSON_OBJECT) {
title = json_object_value(data, tokens, count, value, "titleName");
}
item = json_next_child(tokens, count, localized, (size_t)value + 1);
}
}
}
if(title >= 0 && tokens[title].type == JSON_STRING) {
append_named_json_field(json, "titleName", data, &tokens[title], &first);
}
for(int item = json_next_child(tokens, count, 0, 1); item >= 0;) {
int value = json_next_child(tokens, count, 0, (size_t)item + 1);
if(value < 0) break;
if(tokens[item].type == JSON_STRING &&
(tokens[value].type == JSON_STRING ||
tokens[value].type == JSON_PRIMITIVE)) {
append_json_field(json, data, &tokens[item], &tokens[value], &first);
}
item = json_next_child(tokens, count, 0, (size_t)value + 1);
}
strbuf_append(json, "]");
free(tokens);
return 0;
}
static enum MHD_Result
pkg_error(struct MHD_Connection *conn, const char *path) {
return send_json_error_detail(conn, MHD_HTTP_BAD_REQUEST,
"could not read package information",
"pkg_info_failed", path);
}
enum MHD_Result
api_pkg_info(struct MHD_Connection *conn) {
char *path = fs_path_value(query_value(conn, "path"));
pkg_source_t pkg = {.fd = -1};
unsigned char *param;
strbuf_t json = {0};
if(!path || pkg_source_open(path, &pkg)) {
enum MHD_Result ret = pkg_error(conn, path);
free(path);
return ret;
}
if(!(param = malloc(pkg.param_size)) ||
read_at(pkg.fd, param, pkg.param_size, pkg.param_offset)) {
enum MHD_Result ret = pkg_error(conn, path);
free(param);
pkg_source_close(&pkg);
free(path);
return ret;
}
strbuf_printf(&json,
"{\"ok\":true,\"size\":%llu,\"content_id\":",
(unsigned long long)pkg.size);
json_escape(&json, pkg.content_id);
strbuf_printf(&json,
",\"platform\":\"%s\",\"content_type\":%u,"
"\"content_flags\":%u,\"has_icon\":%s,\"fields\":",
pkg.param_type == PKG_PARAM_JSON ? "PS5" : "PS4",
pkg.content_type, pkg.content_flags,
pkg.icon_size ? "true" : "false");
if((pkg.param_type == PKG_PARAM_JSON &&
append_param_json_fields(&json, param, pkg.param_size)) ||
(pkg.param_type == PKG_PARAM_SFO &&
append_sfo_fields(&json, param, pkg.param_size))) {
enum MHD_Result ret;
free(json.data);
ret = pkg_error(conn, path);
free(param);
pkg_source_close(&pkg);
free(path);
return ret;
}
strbuf_append(&json, "}");
free(param);
pkg_source_close(&pkg);
free(path);
return send_buffer(conn, MHD_HTTP_OK, json.data, "application/json");
}
enum MHD_Result
api_pkg_icon(struct MHD_Connection *conn) {
char *path = fs_path_value(query_value(conn, "path"));
pkg_source_t pkg = {.fd = -1};
unsigned char *icon;
struct MHD_Response *response;
enum MHD_Result ret;
if(!path || pkg_source_open(path, &pkg) || !pkg.icon_size ||
!(icon = malloc(pkg.icon_size)) ||
read_at(pkg.fd, icon, pkg.icon_size, pkg.icon_offset)) {
if(path && pkg.fd >= 0) pkg_source_close(&pkg);
free(path);
return send_json_error(conn, MHD_HTTP_NOT_FOUND, "package icon not found");
}
if(!png_signature_valid(icon, pkg.icon_size)) {
free(icon);
pkg_source_close(&pkg);
free(path);
return send_json_error(conn, MHD_HTTP_NOT_FOUND,
"package icon not found");
}
pkg_source_close(&pkg);
free(path);
response = MHD_create_response_from_buffer(pkg.icon_size, icon,
MHD_RESPMEM_MUST_FREE);
if(!response) {
free(icon);
return MHD_NO;
}
MHD_add_response_header(response, MHD_HTTP_HEADER_CONTENT_TYPE, "image/png");
ret = websrv_queue_response(conn, MHD_HTTP_OK, response);
MHD_destroy_response(response);
return ret;
}
-6
View File
@@ -1,6 +0,0 @@
#pragma once
#include <microhttpd.h>
enum MHD_Result api_pkg_info(struct MHD_Connection *conn);
enum MHD_Result api_pkg_icon(struct MHD_Connection *conn);
-119
View File
@@ -1,119 +0,0 @@
#include "pkg_installer.h"
#ifndef __linux__
#include <limits.h>
#include <pthread.h>
#include <stdint.h>
#include <stdio.h>
#include <string.h>
typedef struct pkg_metadata {
const char *uri;
const char *ex_uri;
const char *playgo_scenario_id;
const char *content_id;
const char *content_name;
const char *icon_url;
uint32_t slot;
uint32_t is_playgo_enabled;
} pkg_metadata_t;
_Static_assert(sizeof(pkg_metadata_t) == 0x38,
"sceAppInstUtil metadata ABI mismatch");
typedef struct pkg_info {
char content_id[48];
int type;
int platform;
} pkg_info_t;
typedef struct playgo_info {
char languages[30][8];
char scenario_ids[64][3];
char content_ids[64][48];
long unknown[810];
} playgo_info_t;
_Static_assert(sizeof(playgo_info_t) == 0x2700,
"sceAppInstUtil PlayGoInfo ABI mismatch");
int sceAppInstUtilInitialize(void);
int sceAppInstUtilInstallByPackage(const pkg_metadata_t *, pkg_info_t *,
playgo_info_t *);
static pthread_mutex_t installer_lock = PTHREAD_MUTEX_INITIALIZER;
static int installer_initialized;
static int
initialize_locked(void) {
int result;
if(!installer_initialized) {
result = sceAppInstUtilInitialize();
if(result) return result;
installer_initialized = 1;
}
return 0;
}
int
pkg_installer_initialize(void) {
int result;
pthread_mutex_lock(&installer_lock);
result = initialize_locked();
pthread_mutex_unlock(&installer_lock);
return result;
}
int
pkg_installer_install(const char *path) {
char install_path[PATH_MAX + sizeof("/user")];
const char *uri = path;
pkg_metadata_t metadata = {
.uri = NULL,
.ex_uri = "",
.playgo_scenario_id = "",
.content_id = "",
.content_name = "",
.icon_url = "",
.slot = 0,
.is_playgo_enabled = 0
};
pkg_info_t pkg_info = {0};
playgo_info_t playgo_info = {0};
int result;
if(!path) return -1;
if(!strncmp(path, "/data/", 6)) {
snprintf(install_path, sizeof(install_path), "/user%s", path);
uri = install_path;
}
metadata.uri = uri;
pthread_mutex_lock(&installer_lock);
result = initialize_locked();
if(result) {
pthread_mutex_unlock(&installer_lock);
return result;
}
result = sceAppInstUtilInstallByPackage(&metadata, &pkg_info, &playgo_info);
pthread_mutex_unlock(&installer_lock);
return result;
}
#else
int
pkg_installer_initialize(void) {
return PKG_INSTALL_UNSUPPORTED;
}
int
pkg_installer_install(const char *path) {
(void)path;
return PKG_INSTALL_UNSUPPORTED;
}
#endif
-6
View File
@@ -1,6 +0,0 @@
#pragma once
#define PKG_INSTALL_UNSUPPORTED 0x7fffffff
int pkg_installer_initialize(void);
int pkg_installer_install(const char *path);
-1135
View File
File diff suppressed because it is too large. Load diff
-36
View File
@@ -1,36 +0,0 @@
#pragma once
/* Safe RAR extraction engine used by the /api/extract task.
Wraps the vendored rarlab UnRAR 7.20.1 (third_party/unrar7) through its
C-compatible DLL API (unrar_c_api.h facade).
Reuses the zip_extract types so the dispatch layer can call either engine
through the same status / limits / progress protocol.
See zip_extract.h for the shared limits, conflict, progress and result types.
Backend notes (v1.9, unrar 7.20.1):
* RAR4 and RAR5, any compression version including WinRAR 6/7 "v6".
* Multi-volume: unrar merges next .partNN.rar by name automatically.
* Encrypted RAR is NOT yet supported end-to-end: the engine can decrypt
via RARSetPassword, but password plumbing (API + UI) is unwired, so
encrypted headers/entries fail with ZIPX_ERR_UNSUPPORTED today.
See third_party/unrar7/VENDORED.md for full integration notes. */
#include "zip_extract.h"
#include <stdint.h>
#include <stddef.h>
/* Extract rar_path into dst_dir using the same protocol as zipx_extract().
Returns ZIPX_OK or an error code; *result is always filled in.
On any failure the staging directory is removed and dst_dir is left as it
was, except for objects already published with the overwrite policy. */
zipx_status_t rar_extract(const char *rar_path, const char *dst_dir,
zipx_conflict_t conflict,
const zipx_limits_t *limits,
zipx_cancel_fn cancel,
zipx_progress_fn progress,
void *userdata,
zipx_result_t *result);
-1934
View File
File diff suppressed because it is too large. Load diff
-187
View File
@@ -1,187 +0,0 @@
/* sevenz_chain -- 7z folder (coder chain) decoder.
part of ps5-web-file-manager
A 7z archive stores its data as *folders*. One folder is a small directed
graph of coders fed by N packed streams and producing a single unpacked
stream; entries are slices of the folder output (a folder holding several
entries is what makes an archive "solid").
The bundled LZMA SDK can decode a folder, but only through `CSzFolder`,
which is a fixed-size structure capped at 4 coders / 3 bonds. 7-Zip's own
BCJ2 chain uses 5 coders (BCJ2 plus four LZMA2 streams), so the SDK rejects
it -- while still listing the archive fine, because its *header* scanner is
a different, looser parser (64 coders). The C half of the SDK also has no
7zAES coder at all.
This module therefore parses the folder descriptor itself (dynamic arrays,
up to 64 coders, mirroring the SDK's header scanner) and drives the coder
graph itself. Two properties matter:
* Streaming. The decoded bytes are pushed into a sink as they are
produced; a folder is never materialised as a whole, so a multi-gigabyte
solid block is workable. The only buffers sized from the archive are
the LZMA/LZMA2 dictionary, the PPMd model and the three side streams of
BCJ2 -- each capped by sz_chain_limits_t.
* Precision. Every rejection names the coder and the method, and the
resource limits report the value the archive asked for and the value
that was allowed, so the UI can say something useful instead of
"corrupt archive".
Supported here:
* Copy, LZMA, LZMA2 and PPMd
* the Delta filter and the x86 / PPC / IA64 / ARM / ARMT / SPARC branch
converters
* BCJ2, whose three side streams are materialised under a limit while
MAIN keeps streaming
* 7zAES (method 0x06F10701), the coder 7-Zip wraps around the streams when
`-p` is used, driven from a caller supplied password
Not supported here (by design, see sz_chain_check):
* an encrypted *header* (`-mhe=on`): that is not a coder in a folder but a
second, encrypted copy of the archive header, which has to be decrypted
and parsed before any folder exists at all. Reported by the SDK header
reader as SZ_ERROR_UNSUPPORTED, not by this module.
*/
#ifndef SEVENZ_CHAIN_H
#define SEVENZ_CHAIN_H
#include <stddef.h>
#include <stdint.h>
/* The SDK's header scanner accepts up to 64 coders per folder; folders in the
wild have 1-5. Keeping the same ceiling means "the SDK could list it" and
"we can decode it" accept the same archives. */
#define SZ_CHAIN_MAX_CODERS 64
#define SZ_CHAIN_MAX_STREAMS 64
/* Ceilings for the buffers whose size comes from the (attacker controlled)
archive header. */
typedef struct {
uint64_t max_dict_bytes; /* LZMA / LZMA2 window */
uint64_t max_ppmd_bytes; /* PPMd model */
uint64_t max_side_bytes; /* BCJ2 CALL + JUMP + RC together */
uint32_t max_aes_cycles; /* 7zAES key derivation: 2^n SHA-256 passes */
} sz_chain_limits_t;
#define SZ_CHAIN_LIMITS_DEFAULT 0
#define SZ_CHAIN_LIMITS_LARGE 1
const sz_chain_limits_t *sz_chain_limits_profile(int profile);
const sz_chain_limits_t *sz_chain_default_limits(void);
typedef enum {
SZ_CHAIN_OK = 0,
SZ_CHAIN_ERR_PARAM, /* bad arguments from the caller */
SZ_CHAIN_ERR_MEM, /* allocation failed */
SZ_CHAIN_ERR_HEADER, /* malformed folder descriptor */
SZ_CHAIN_ERR_METHOD, /* coder method not supported */
SZ_CHAIN_ERR_LAYOUT, /* coder graph shape not supported */
SZ_CHAIN_ERR_LIMIT, /* a sz_chain_limits_t ceiling was hit */
SZ_CHAIN_ERR_PASSWORD,/* the archive is encrypted and no usable password
was supplied (or the one given is wrong) */
SZ_CHAIN_ERR_READ, /* the read callback failed */
SZ_CHAIN_ERR_WRITE, /* the sink callback failed */
SZ_CHAIN_ERR_DATA, /* a decoder rejected the data */
SZ_CHAIN_ERR_CANCELED,
SZ_CHAIN_ERR_INTERNAL
} sz_chain_status_t;
typedef struct {
sz_chain_status_t status;
int32_t coder; /* index of the offending coder, -1 when not applicable */
uint32_t method; /* its method id, 0 when not applicable */
uint64_t offset; /* decoded byte offset at the point of failure */
char message[192];
} sz_chain_err_t;
const char *sz_chain_status_string(sz_chain_status_t status);
/* "LZMA2", "BCJ2", "7zAES", "unknown 0x1234". Never returns NULL. */
const char *sz_chain_method_name(uint32_t method);
/* ---------------------------------------------------------------- folder */
typedef struct sz_chain sz_chain;
/* Parses one folder descriptor.
blob / blob_size
the CODERS_INFO bytes of this folder, i.e. the range
`CSzAr::CodersData[FoCodersOffsets[i] .. FoCodersOffsets[i + 1])`.
pack_positions
`CSzAr::PackPositions`, num_pack_streams + 1 entries, offsets of the
packed streams relative to the start of the archive's packed-data area.
coder_unpack_sizes
unpacked size of every coder of this folder, in stored coder order, i.e.
`&CSzAr::CoderUnpackSizes[CSzAr::FoToCoderUnpackSizes[i]]`.
unpack_size
`SzAr_GetFolderUnpackSize(&db, i)`.
Returns 0 on success. On success *out owns a copy of blob, release it with
sz_chain_free(). On failure *out is untouched and err describes the
problem. */
int sz_chain_parse(sz_chain **out, const uint8_t *blob, size_t blob_size,
const uint64_t *pack_positions, uint32_t num_pack_streams,
const uint64_t *coder_unpack_sizes, uint64_t unpack_size,
const sz_chain_limits_t *limits, sz_chain_err_t *err);
void sz_chain_free(sz_chain *c);
uint32_t sz_chain_num_coders(const sz_chain *c);
uint32_t sz_chain_num_pack_streams(const sz_chain *c);
/* Non-zero when the folder contains a 7zAES coder, i.e. when sz_chain_decode()
will need a password. Lets a caller ask for one before touching the disk. */
int sz_chain_needs_password(const sz_chain *c);
/* Method id of coder `index`, or -1 when out of range. */
int64_t sz_chain_coder_method(const sz_chain *c, uint32_t index);
/* True when the folder is a single plain LZMA2 coder -- the shape the SDK's
multithreaded decoder covers. Fills the coder's props byte and the packed
input size; both are only valid when this returns non-zero. */
int sz_chain_lzma2_root(const sz_chain *c, uint8_t *prop, uint64_t *in_size);
/* Writes e.g. "LZMA2 + BCJ2 (5 coders, 4 pack streams)" into buf. */
void sz_chain_describe(const sz_chain *c, char *buf, size_t size);
/* Walks every coder and the graph shape without touching any data, so callers
can refuse an archive before creating anything on disk. Fills err with the
same precision sz_chain_decode() would. */
int sz_chain_check(const sz_chain *c, sz_chain_err_t *err);
/* -------------------------------------------------------------- decoding */
/* Fills exactly size bytes at offset inside the packed-data area.
Returns 0 on success, non-zero on failure. */
typedef int (*sz_chain_read_fn)(void *ctx, uint64_t offset, void *dst,
size_t size);
/* Receives the decoded bytes in order. Returns 0 to continue. */
typedef int (*sz_chain_sink_fn)(void *ctx, const void *data, size_t size);
/* Returns non-zero to abort. May be NULL. */
typedef int (*sz_chain_cancel_fn)(void *ctx);
/* Decodes the whole folder, pushing the result into sink.
The bytes are delivered strictly in order and the total is the folder's
declared unpack size. When crc_out is not NULL it receives the CRC-32 of
the delivered bytes, for the caller to compare with the folder CRC.
`password` is the archive password as UTF-8, or NULL / "" when the caller
has none. It is only consulted by folders that contain a 7zAES coder; a
folder that needs one without a password fails as SZ_CHAIN_ERR_PASSWORD
before any data is read, so the caller can prompt and retry. A password
containing NUL is not supported: 7-Zip stores it as UTF-16LE and the
conversion stops at the terminator.
Returns 0 on success, -1 on failure with err filled. A failing sink is
reported as SZ_CHAIN_ERR_WRITE; the caller is expected to make its own
message more specific. */
int sz_chain_decode(sz_chain *c, sz_chain_read_fn read_at, void *read_ctx,
sz_chain_sink_fn sink, void *sink_ctx,
sz_chain_cancel_fn cancel, void *cancel_ctx,
const char *password, uint32_t *crc_out,
sz_chain_err_t *err);
#endif /* SEVENZ_CHAIN_H */
-1792
View File
File diff suppressed because it is too large. Load diff
-37
View File
@@ -1,37 +0,0 @@
#pragma once
/* Standalone 7z extraction engine, the third sibling of zip_extract.c and
rar_extract.c. Like them it has no HTTP or task dependencies, and it fills
in the same zipx_result_t so a caller can treat every format alike.
Input may be a single `name.7z` or a byte-split set (`name.7z.001`, ...):
both reach the decoder through src/sevenz_volstream.c.
The publish / staging / rollback / name-validation machinery is mirrored
from rar_extract.c on purpose -- three self-contained engines is the shape
this project has settled on, so that a format's bugs stay inside its file.
Backend notes (LZMA SDK 26.03 + src/sevenz_chain.c):
* Copy / LZMA / LZMA2 / PPMd, the Delta filter and the x86 / PPC / IA64 /
ARM / ARMT / SPARC branch converters, BCJ2, and 7zAES.
* An encrypted *header* (`-mhe=on`) is not readable: the SDK refuses it
before any folder is known, and we report exactly that.
*/
#include "zip_extract.h"
/* Extract sevenz_path into dst_dir.
`password` is the archive password as UTF-8, or NULL / "" when the caller
has none. It is only consulted by archives that encrypt their streams.
Returns ZIPX_OK or an error code; *result is always filled in. A missing or
wrong password comes back as ZIPX_ERR_PASSWORD so the caller can ask for one
and retry. On any failure the staging directory is removed and dst_dir is
left as it was, except for objects already published under the overwrite
policy. */
zipx_status_t sevenz_extract(const char *sevenz_path, const char *dst_dir,
zipx_conflict_t conflict,
const zipx_limits_t *limits,
zipx_cancel_fn cancel,
zipx_progress_fn progress, void *userdata,
const char *password, zipx_result_t *result);
-197
View File
@@ -1,197 +0,0 @@
#include "sevenz_mt.h"
#include <stdarg.h>
#include <stdio.h>
#include <string.h>
#include "7zTypes.h"
#include "7zCrc.h"
#include "Alloc.h"
#include "Lzma2DecMt.h"
/* ------------------------------------------------------------ adapters --
The SDK's decoders speak ISeqInStream / ISeqOutStream / ICompressProgress;
the engine speaks plain callbacks. These three structs translate. All of
them run on the calling thread -- MtDec only ever hands output to the
thread that called Lzma2DecMt_Decode, which is what makes the plain sink
safe to reuse here. */
typedef struct {
ISeqInStream vt;
sz_chain_read_fn read_at;
void *read_ctx;
uint64_t pos; /* absolute offset of the next byte to hand out */
uint64_t end; /* one past the last byte of the packed stream */
} mt_seq_in;
static SRes mt_seq_read(const ISeqInStream *pp, void *buf, size_t *size) {
mt_seq_in *s = (mt_seq_in *)pp;
size_t want = *size;
*size = 0;
if(want == 0) {
return SZ_OK;
}
if(s->end - s->pos < (uint64_t)want) {
want = (size_t)(s->end - s->pos);
}
if(want != 0 && s->read_at(s->read_ctx, s->pos, buf, want) != 0) {
return SZ_ERROR_READ;
}
s->pos += want;
*size = want;
/* A short read means "end of stream" to the SDK; since we only ever hand
it exactly in_size bytes, hitting the end early is the caller's bug and
the decoder's outSize check will flag it. */
return SZ_OK;
}
typedef struct {
ISeqOutStream vt;
sz_chain_sink_fn sink;
void *sink_ctx;
uint32_t crc;
int failed;
} mt_seq_out;
static size_t mt_seq_write(const ISeqOutStream *pp, const void *buf,
size_t size) {
mt_seq_out *s = (mt_seq_out *)pp;
if(s->failed) {
return 0;
}
s->crc = CrcUpdate(s->crc, buf, size);
if(s->sink(s->sink_ctx, buf, size) != 0) {
s->failed = 1;
/* Returning less than `size` tells the SDK the output side is done; it
reports SZ_ERROR_WRITE. */
return 0;
}
return size;
}
typedef struct {
ICompressProgress vt;
sz_chain_cancel_fn cancel;
void *cancel_ctx;
} mt_progress;
static SRes mt_progress_report(const ICompressProgress *pp, UInt64 in_size,
UInt64 out_size) {
mt_progress *s = (mt_progress *)pp;
(void)in_size;
(void)out_size;
if(s->cancel && s->cancel(s->cancel_ctx)) {
return SZ_ERROR_PROGRESS;
}
return SZ_OK;
}
/* --------------------------------------------------------------- decode --
Errors are mapped onto sz_chain_err_t so the facade's reporting stays in
one vocabulary. SZX_MT_ERR_THREADS is reserved for "the platform cannot
give me a thread pool": Lzma2DecMt returns SZ_ERROR_THREAD only from its
threading primitives, everything else is data or memory. */
static void mt_fail(sz_chain_err_t *err, sz_chain_status_t status,
const char *fmt, ...) {
va_list ap;
if(!err) {
return;
}
err->status = status;
err->coder = 0;
err->method = 0x21; /* SZ_M_LZMA2; kept literal to avoid dragging chain.c in */
err->offset = 0;
va_start(ap, fmt);
vsnprintf(err->message, sizeof(err->message), fmt, ap);
va_end(ap);
}
int szx_mt_decode(sz_chain_read_fn read_at, void *read_ctx, uint64_t in_offset,
uint64_t in_size, uint8_t prop, uint64_t out_size,
sz_chain_sink_fn sink, void *sink_ctx,
sz_chain_cancel_fn cancel, void *cancel_ctx,
uint32_t *crc_out, sz_chain_err_t *err) {
mt_seq_in in;
mt_seq_out out;
mt_progress progress;
CLzma2DecMtProps props;
CLzma2DecMtHandle mt;
UInt64 in_processed = 0;
int is_mt = 0;
SRes res;
memset(&in, 0, sizeof(in));
in.vt.Read = mt_seq_read;
in.read_at = read_at;
in.read_ctx = read_ctx;
in.pos = in_offset;
in.end = in_offset + in_size;
memset(&out, 0, sizeof(out));
out.vt.Write = mt_seq_write;
out.sink = sink;
out.sink_ctx = sink_ctx;
out.crc = CRC_INIT_VAL;
memset(&progress, 0, sizeof(progress));
progress.vt.Progress = mt_progress_report;
progress.cancel = cancel;
progress.cancel_ctx = cancel_ctx;
Lzma2DecMtProps_Init(&props);
props.numThreads = SZX_MT_THREADS;
props.inBufSize_MT = 1 << 20;
mt = Lzma2DecMt_Create(&g_Alloc, &g_MidAlloc);
if(!mt) {
mt_fail(err, SZ_CHAIN_ERR_INTERNAL, "LZMA2 MT: out of memory");
return -1;
}
res = Lzma2DecMt_Decode(mt, prop, &props, &out.vt, &out_size, 1, &in.vt,
&in_processed, &is_mt,
cancel ? &progress.vt : NULL);
Lzma2DecMt_Destroy(mt);
if(res == SZ_ERROR_THREAD) {
/* No usable thread pool (pthread init failure, thread creation denied).
The caller retries on the single-threaded chain path. */
return SZX_MT_ERR_THREADS;
}
if(out.failed) {
mt_fail(err, SZ_CHAIN_ERR_WRITE, "LZMA2 MT: sink rejected decoded data");
return -1;
}
if(res != SZ_OK) {
switch(res) {
case SZ_ERROR_PROGRESS:
mt_fail(err, SZ_CHAIN_ERR_CANCELED, "canceled");
break;
case SZ_ERROR_MEM:
mt_fail(err, SZ_CHAIN_ERR_INTERNAL, "LZMA2 MT: out of memory");
break;
case SZ_ERROR_WRITE:
mt_fail(err, SZ_CHAIN_ERR_WRITE, "LZMA2 MT: output stream failed");
break;
default:
mt_fail(err, SZ_CHAIN_ERR_DATA, "LZMA2 MT: decode failed (res=%d)",
(int)res);
break;
}
return -1;
}
if(in_processed != in_size) {
mt_fail(err, SZ_CHAIN_ERR_DATA,
"LZMA2 MT: consumed %llu of %llu packed bytes",
(unsigned long long)in_processed, (unsigned long long)in_size);
return -1;
}
if(crc_out) {
*crc_out = out.crc;
}
return 0;
}
-40
View File
@@ -1,40 +0,0 @@
/* Multithreaded LZMA2 decode for the 7z engine.
*
* Most 7z archives are a single plain LZMA2 coder (7-Zip's -m0=lzma2
* default). For that shape the SDK's own parallel decoder -- the same code
* 7-Zip runs for -mmt -- replaces the single-threaded chain walk and decodes
* consecutive LZMA2 blocks on worker threads while the main thread streams
* the output into the staging sink. Measured on a 329 MiB fixture this is
* worth ~1.7x on an 8-core host, on top of the assembly kernel.
*
* Threads are rented, not owned: any thread error falls back to the caller's
* single-threaded path, so a platform without working pthreads only ever
* loses speed, never correctness. */
#ifndef SEVENZ_MT_H
#define SEVENZ_MT_H
#include "sevenz_chain.h"
/* 8-core Zen 2 on the PS5: 4 decoders leave the HTTP server, the task
system and the kernel half of the machine. */
#define SZX_MT_THREADS 8
/* Decodes one folder that sz_chain_lzma2_root() has recognised. The
callbacks mirror sz_chain_decode()'s: read_at/ctx for the packed data,
sink/ctx for the decoded bytes (both run on the calling thread; the sink
sees the same ordered byte stream the chain would have produced).
cancel/ctx is polled from the progress callback and may be NULL.
crc_out, when not NULL, receives the CRC-32 of the delivered bytes.
err, when not NULL, receives a chain-style error description.
Returns 0 on success; SZX_MT_ERR_THREADS means "no working thread pool"
and the caller should retry single-threaded; other failures are terminal. */
#define SZX_MT_ERR_THREADS 2
int szx_mt_decode(sz_chain_read_fn read_at, void *read_ctx,
uint64_t in_offset, uint64_t in_size, uint8_t prop,
uint64_t out_size, sz_chain_sink_fn sink, void *sink_ctx,
sz_chain_cancel_fn cancel, void *cancel_ctx,
uint32_t *crc_out, sz_chain_err_t *err);
#endif /* SEVENZ_MT_H */
-356
View File
@@ -1,356 +0,0 @@
/* sevenz_volstream -- see sevenz_volstream.h for what this does and why. */
#include <stdarg.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#if defined(_WIN32)
#include <wchar.h>
#endif
#include "7zFile.h"
#include "sevenz_volstream.h"
#include "zipx_volume.h"
struct sevenz_volstream {
ISeekInStream vt;
zipx_volume_t vol; /* owns the ordered paths */
CSzFile *file; /* one per part */
uint64_t *start; /* count + 1 prefix offsets into the logical archive */
uint32_t count;
uint32_t open_count; /* how many entries of `file` were opened */
uint64_t pos; /* current offset in the logical archive */
uint32_t cur; /* part `pos` currently sits in, to skip redundant seeks */
uint64_t cur_off; /* file offset within that part */
char name[256]; /* stem of the set, for messages */
};
/* ---------------------------------------------------------------- helpers */
static char *err_printf(const char *fmt, ...) {
va_list ap;
char buf[512];
char *out;
va_start(ap, fmt);
vsnprintf(buf, sizeof(buf), fmt, ap);
va_end(ap);
out = (char *)malloc(strlen(buf) + 1);
if(out) memcpy(out, buf, strlen(buf) + 1);
return out;
}
static const char *file_base(const char *path) {
const char *slash = strrchr(path, '/');
const char *back = strrchr(path, '\\');
if(back && (!slash || back > slash)) slash = back;
return slash ? slash + 1 : path;
}
#if defined(_WIN32)
/* The SDK opens through CreateFileA otherwise, which cannot see non-ASCII
entry names. */
static void utf8_to_utf16(const char *src, WCHAR *dst, size_t cap) {
size_t out = 0;
while(*src && out + 2 < cap) {
unsigned char c = (unsigned char)*src++;
UInt32 cp;
if(c < 0x80) {
cp = c;
} else if((c & 0xE0) == 0xC0 && (src[0] & 0xC0) == 0x80) {
cp = ((UInt32)(c & 0x1F) << 6) | (UInt32)(*src++ & 0x3F);
} else if((c & 0xF0) == 0xE0 && (src[0] & 0xC0) == 0x80 &&
(src[1] & 0xC0) == 0x80) {
cp = ((UInt32)(c & 0x0F) << 12) | ((UInt32)(src[0] & 0x3F) << 6) |
(UInt32)(src[1] & 0x3F);
src += 2;
} else if((c & 0xF8) == 0xF0 && (src[0] & 0xC0) == 0x80 &&
(src[1] & 0xC0) == 0x80 && (src[2] & 0xC0) == 0x80) {
cp = ((UInt32)(c & 0x07) << 18) | ((UInt32)(src[0] & 0x3F) << 12) |
((UInt32)(src[1] & 0x3F) << 6) | (UInt32)(src[2] & 0x3F);
src += 3;
} else {
cp = '?';
}
if(cp >= 0x10000) {
cp -= 0x10000;
dst[out++] = (WCHAR)(0xD800 | (cp >> 10));
dst[out++] = (WCHAR)(0xDC00 | (cp & 0x3FF));
} else {
dst[out++] = (WCHAR)cp;
}
}
dst[out] = 0;
}
static int open_part(CSzFile *file, const char *path) {
WCHAR wide[4096];
utf8_to_utf16(path, wide, sizeof(wide) / sizeof(wide[0]));
return InFile_OpenW(file, wide) == 0 ? 0 : -1;
}
#else
static int open_part(CSzFile *file, const char *path) {
return InFile_Open(file, path) == 0 ? 0 : -1;
}
#endif
/* ----------------------------------------------------------------- stream */
static uint32_t part_at(const sevenz_volstream *v, uint64_t pos) {
uint32_t i;
for(i = 0; i < v->count; i++) {
if(pos < v->start[i + 1]) return i;
}
return v->count;
}
static SRes vol_read(const ISeekInStream *p, void *buf, size_t *size) {
sevenz_volstream *v = (sevenz_volstream *)p;
uint8_t *dst = (uint8_t *)buf;
size_t want = *size;
size_t got = 0;
*size = 0;
while(got < want) {
uint32_t i = part_at(v, v->pos);
uint64_t avail, off;
size_t take;
if(i >= v->count) break; /* end of the set: a short read means EOF */
off = v->pos - v->start[i];
avail = (v->start[i + 1] - v->start[i]) - off;
take = (size_t)(avail < (uint64_t)(want - got) ? avail
: (uint64_t)(want - got));
if(take == 0) break;
if(v->cur != i || v->cur_off != off) {
Int64 seek = (Int64)off;
if(File_Seek(&v->file[i], &seek, SZ_SEEK_SET) != 0) return SZ_ERROR_READ;
v->cur = i;
v->cur_off = off;
}
{
size_t part_got = take;
if(File_Read(&v->file[i], dst + got, &part_got) != 0) return SZ_ERROR_READ;
if(part_got == 0) break;
got += part_got;
v->pos += part_got;
v->cur_off += part_got;
if(part_got < take) break;
}
}
*size = got;
return SZ_OK;
}
static SRes vol_seek(const ISeekInStream *p, Int64 *pos, ESzSeek origin) {
sevenz_volstream *v = (sevenz_volstream *)p;
uint64_t total = v->start[v->count];
uint64_t target;
switch(origin) {
case SZ_SEEK_SET:
if(*pos < 0) return SZ_ERROR_PARAM;
target = (uint64_t)*pos;
break;
case SZ_SEEK_CUR:
if(*pos < 0) {
UInt64 back = (UInt64)(-*pos);
if(back > v->pos) return SZ_ERROR_PARAM;
target = v->pos - back;
} else {
target = v->pos + (UInt64)*pos;
}
break;
case SZ_SEEK_END:
if(*pos < 0) {
UInt64 back = (UInt64)(-*pos);
if(back > total) return SZ_ERROR_PARAM;
target = total - back;
} else {
target = total + (UInt64)*pos;
}
break;
default:
return SZ_ERROR_PARAM;
}
if(target > total) target = total;
v->pos = target;
*pos = (Int64)target;
return SZ_OK;
}
/* -------------------------------------------------------------------- open */
int sevenz_volstream_open(sevenz_volstream **out, const char *path, int *is_set,
char **err) {
sevenz_volstream *v;
char *vol_err = NULL;
int detected;
uint32_t i;
if(out) *out = NULL;
if(is_set) *is_set = 0;
if(err) *err = NULL;
if(!out || !path) {
if(err) *err = err_printf("no archive path given");
return -1;
}
v = (sevenz_volstream *)calloc(1, sizeof(*v));
if(!v) {
if(err) *err = err_printf("out of memory");
return -1;
}
/* One call does both jobs: it either reports "ordinary file" and clears the
struct, or fills in the ordered part list. A -1 here already carries the
message the user needs (a hole in the numbering names the missing part). */
detected = zipx_volume_detect(path, &v->vol, &vol_err);
if(detected < 0) {
if(err) {
*err = vol_err ? vol_err
: err_printf("'%s' cannot be read", file_base(path));
} else {
free(vol_err);
}
zipx_volume_free(&v->vol);
free(v);
return -1;
}
if(detected == 0) {
v->vol.paths = (char **)malloc(sizeof(char *));
if(v->vol.paths) v->vol.paths[0] = (char *)malloc(strlen(path) + 1);
if(!v->vol.paths || !v->vol.paths[0]) {
free(v->vol.paths);
free(v);
if(err) *err = err_printf("out of memory");
return -1;
}
memcpy(v->vol.paths[0], path, strlen(path) + 1);
v->vol.count = 1;
v->vol.mode = ZIPX_VOL_MODE_CONCAT;
v->vol.is_set = 0;
} else if(is_set) {
*is_set = 1;
}
snprintf(v->name, sizeof(v->name), "%s", file_base(path));
v->count = (uint32_t)v->vol.count;
v->file = (CSzFile *)calloc(v->count, sizeof(CSzFile));
v->start = (uint64_t *)calloc((size_t)v->count + 1, sizeof(uint64_t));
if(!v->file || !v->start) {
if(err) *err = err_printf("out of memory");
goto fail;
}
for(i = 0; i < v->count; i++) {
UInt64 length = 0;
File_Construct(&v->file[i]);
v->open_count = i + 1; /* File_Close() ignores a never-opened handle */
if(open_part(&v->file[i], v->vol.paths[i]) != 0) {
if(err) {
*err = err_printf("cannot open volume '%s' of '%s'",
file_base(v->vol.paths[i]), v->name);
}
goto fail;
}
if(File_GetLength(&v->file[i], &length) != 0) {
if(err) {
*err = err_printf("cannot measure volume '%s' of '%s'",
file_base(v->vol.paths[i]), v->name);
}
goto fail;
}
v->start[i + 1] = v->start[i] + length;
}
if(v->start[v->count] == 0) {
if(err) *err = err_printf("'%s' is empty", v->name);
goto fail;
}
/* 7-Zip cuts equal sized parts and lets only the last one be short. A part
of a different size in the middle means the set is damaged or was mixed
with another one, and decoding would fail much later with a message that
points nowhere useful. */
for(i = 0; i + 1 < v->count; i++) {
uint64_t size = v->start[i + 1] - v->start[i];
if(size != v->start[1]) {
if(err) {
*err = err_printf("volume '%s' of '%s' is %llu bytes, but the earlier "
"volumes are %llu bytes: the set is not a clean split",
file_base(v->vol.paths[i]), v->name,
(unsigned long long)size,
(unsigned long long)v->start[1]);
}
goto fail;
}
}
v->vt.Read = vol_read;
v->vt.Seek = vol_seek;
*out = v;
return 0;
fail:
sevenz_volstream_free(v);
return -1;
}
ISeekInStream *sevenz_volstream_stream(sevenz_volstream *v) {
return v ? &v->vt : NULL;
}
uint32_t sevenz_volstream_count(const sevenz_volstream *v) {
return v ? v->count : 0;
}
uint64_t sevenz_volstream_size(const sevenz_volstream *v) {
return v ? v->start[v->count] : 0;
}
const char *sevenz_volstream_describe(const sevenz_volstream *v, char *buf,
unsigned size) {
if(!buf || size == 0) return buf;
if(!v) {
snprintf(buf, size, "no archive");
} else if(v->count <= 1) {
snprintf(buf, size, "%s", v->name);
} else {
snprintf(buf, size, "%s (%u volumes)", v->name, (unsigned)v->count);
}
return buf;
}
void sevenz_volstream_free(sevenz_volstream *v) {
uint32_t i;
if(!v) return;
for(i = 0; i < v->open_count; i++) File_Close(&v->file[i]);
free(v->file);
free(v->start);
zipx_volume_free(&v->vol);
free(v);
}
-59
View File
@@ -1,59 +0,0 @@
/* sevenz_volstream -- present a multi-file 7z volume set as one stream.
part of ps5-web-file-manager
A split 7z is a plain byte split: `name.7z.001`, `name.7z.002`, ... are
consecutive slices of one archive, so byte N of the logical archive is byte
N of the concatenation and every offset stored inside the stream header is
already absolute. Nothing has to be merged on disk -- a 160 GiB set would
otherwise need a second 160 GiB scratch copy.
The LZMA SDK reads through ISeekInStream, so this module implements that
interface over the ordered part list produced by zipx_volume. The ordered
list is what makes a set with a hole in it fail loudly instead of decoding
garbage: zipx_volume names the missing part. */
#ifndef SEVENZ_VOLSTREAM_H
#define SEVENZ_VOLSTREAM_H
#include <stdint.h>
#include "7zTypes.h"
#ifdef __cplusplus
extern "C" {
#endif
typedef struct sevenz_volstream sevenz_volstream;
/* Opens `path` together with every volume of the set it belongs to and exposes
them as one seekable byte stream. `path` may be any member of the set; an
ordinary single-file archive is the degenerate one-file case.
Returns 0 on success, with *is_set set to 1 when the path was part of a
multi-file set (non-NULL only). Returns -1 on failure and, when `err` is
non-NULL, stores a malloc'd message the caller must free -- an incomplete
set reports the missing volume by name. */
int sevenz_volstream_open(sevenz_volstream **out, const char *path, int *is_set,
char **err);
/* The stream to hand to SzArEx_Open(); valid until sevenz_volstream_free(). */
ISeekInStream *sevenz_volstream_stream(sevenz_volstream *v);
/* Number of files backing the stream (1 for an ordinary archive). */
uint32_t sevenz_volstream_count(const sevenz_volstream *v);
/* Size of the whole logical archive. */
uint64_t sevenz_volstream_size(const sevenz_volstream *v);
/* Human readable description, e.g. "name.7z (3 volumes)"; writes into buf and
returns buf. */
const char *sevenz_volstream_describe(const sevenz_volstream *v, char *buf,
unsigned size);
void sevenz_volstream_free(sevenz_volstream *v);
#ifdef __cplusplus
}
#endif
#endif
-128
View File
@@ -1,128 +0,0 @@
#include "filemgr_internal.h"
#include <limits.h>
#include <stdlib.h>
#include <string.h>
#include <sys/stat.h>
#include <sys/statvfs.h>
#ifdef __SCE__
#include <sys/mount.h>
#endif
#include "json_util.h"
#include "path_util.h"
static unsigned long long
vfs_bytes(fsblkcnt_t blocks, unsigned long block_size) {
return (unsigned long long)blocks * (unsigned long long)block_size;
}
#ifdef __SCE__
static int
path_is_mounted(const char *path, const struct stat *st) {
char parent[PATH_MAX];
struct stat parent_st;
if(!strcmp(path, "/")) {
return 1;
}
if(path_dirname(path, parent, sizeof(parent)) || stat(parent, &parent_st)) {
return 0;
}
return st->st_dev != parent_st.st_dev;
}
#endif
enum MHD_Result
api_space(struct MHD_Connection *conn) {
#ifdef __SCE__
static const struct {
const char *label_key;
const char *path;
} mounts[] = {
{"storageInternal", "/data"},
{"storageUsb", "/mnt/usb0"},
{"storageUsb", "/mnt/usb1"},
{"storageUsb", "/mnt/usb2"},
{"storageUsb", "/mnt/usb3"},
{"storageUsb", "/mnt/usb4"},
{"storageUsb", "/mnt/usb5"},
{"storageUsb", "/mnt/usb6"},
{"storageUsb", "/mnt/usb7"},
{"storageM2", "/mnt/ext1"},
{"storageExtended", "/mnt/ext0"},
};
#endif
char *current = fs_path_value(query_value(conn, "path"));
strbuf_t b = {0};
int first = 1;
strbuf_append(&b, "{\"ok\":true,\"spaces\":[");
#ifdef __SCE__
for(size_t i = 0; i < sizeof(mounts) / sizeof(mounts[0]); i++) {
struct statvfs vfs;
struct stat st;
unsigned long block_size;
unsigned long long free_bytes;
unsigned long long total_bytes;
int is_current = 0;
if(stat(mounts[i].path, &st) || !path_is_mounted(mounts[i].path, &st) ||
statvfs(mounts[i].path, &vfs)) {
continue;
}
block_size = vfs.f_frsize ? vfs.f_frsize : vfs.f_bsize;
free_bytes = vfs_bytes(vfs.f_bavail, block_size);
total_bytes = vfs_bytes(vfs.f_blocks, block_size);
if(current) {
if(!strcmp(mounts[i].path, "/")) {
is_current = !strcmp(current, "/");
} else if(!strncmp(current, mounts[i].path, strlen(mounts[i].path)) &&
(current[strlen(mounts[i].path)] == 0 ||
current[strlen(mounts[i].path)] == '/')) {
is_current = 1;
}
}
if(!first) {
strbuf_append(&b, ",");
}
first = 0;
strbuf_append(&b, "{\"label_key\":");
json_escape(&b, mounts[i].label_key);
strbuf_append(&b, ",\"path\":");
json_escape(&b, mounts[i].path);
strbuf_printf(&b, ",\"free\":%llu,\"total\":%llu,\"current\":%s}",
free_bytes, total_bytes, is_current ? "true" : "false");
}
#else
const char *paths[] = {"/", current && strcmp(current, "/") ? current : NULL};
const char *labels[] = {"storageRoot", "storageCurrent"};
for(size_t i = 0; i < sizeof(paths) / sizeof(paths[0]); i++) {
struct statvfs vfs;
unsigned long block_size;
unsigned long long free_bytes;
unsigned long long total_bytes;
if(!paths[i] || statvfs(paths[i], &vfs)) {
continue;
}
block_size = vfs.f_frsize ? vfs.f_frsize : vfs.f_bsize;
free_bytes = vfs_bytes(vfs.f_bavail, block_size);
total_bytes = vfs_bytes(vfs.f_blocks, block_size);
if(!first) {
strbuf_append(&b, ",");
}
first = 0;
strbuf_append(&b, "{\"label_key\":");
json_escape(&b, labels[i]);
strbuf_append(&b, ",\"path\":");
json_escape(&b, paths[i]);
strbuf_printf(&b, ",\"free\":%llu,\"total\":%llu,\"current\":%s}",
free_bytes, total_bytes, i ? "true" : "false");
}
#endif
free(current);
strbuf_append(&b, "]}");
return send_buffer(conn, MHD_HTTP_OK, b.data, "application/json");
}
-221
View File
@@ -1,221 +0,0 @@
#include <errno.h>
#include <pthread.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <time.h>
#include "filemgr_internal.h"
#include "path_util.h"
#define ETA_AVERAGE_WINDOW_SECONDS 30
pthread_mutex_t g_tasks_lock = PTHREAD_MUTEX_INITIALIZER;
file_task_t *g_tasks = NULL;
unsigned long g_next_task_id = 1;
const char *
task_op_name(task_op_t op) {
switch(op) {
case TASK_COPY: return "copy";
case TASK_MOVE: return "move";
case TASK_DELETE: return "delete";
case TASK_CHMOD: return "chmod";
case TASK_DOWNLOAD: return "download";
case TASK_UPLOAD: return "upload";
case TASK_PKG_INSTALL: return "pkg_install";
case TASK_EXTRACT: return "extract";
default: return "unknown";
}
}
const char *
task_state_name(task_state_t state) {
switch(state) {
case TASK_QUEUED: return "queued";
case TASK_RUNNING: return "running";
case TASK_DONE: return "done";
case TASK_FAILED: return "failed";
case TASK_CANCELED: return "canceled";
default: return "unknown";
}
}
int
task_is_active(const file_task_t *task) {
return task->state == TASK_QUEUED || task->state == TASK_RUNNING;
}
int
has_active_task_locked(void) {
file_task_t *task;
for(task = g_tasks; task; task = task->next) {
if(task->op != TASK_PKG_INSTALL && task_is_active(task)) {
return 1;
}
}
return 0;
}
int
has_active_task(void) {
int active;
pthread_mutex_lock(&g_tasks_lock);
active = has_active_task_locked();
pthread_mutex_unlock(&g_tasks_lock);
return active;
}
void
free_task(file_task_t *task) {
if(!task) {
return;
}
free_paths(task->srcs, task->src_count);
free(task);
}
void
remove_finished_tasks_locked(void) {
file_task_t **link = &g_tasks;
while(*link) {
file_task_t *task = *link;
if(task_is_active(task) || task->active_streams ||
(task->op == TASK_PKG_INSTALL && !task->reported)) {
link = &task->next;
continue;
}
*link = task->next;
free_task(task);
}
}
int
task_cancel_requested(file_task_t *task) {
int cancel;
pthread_mutex_lock(&g_tasks_lock);
cancel = task->cancel_requested;
pthread_mutex_unlock(&g_tasks_lock);
if(cancel) {
errno = ECANCELED;
}
return cancel;
}
file_task_t *
find_task_locked(unsigned long id) {
file_task_t *task;
for(task = g_tasks; task; task = task->next) {
if(task->id == id) {
return task;
}
}
return NULL;
}
static long long
timespec_delta_ns(const struct timespec *end, const struct timespec *start) {
return (long long)(end->tv_sec - start->tv_sec) * 1000000000LL +
(long long)(end->tv_nsec - start->tv_nsec);
}
static void
task_update_eta_locked(file_task_t *task, const struct timespec *now_mono) {
task_eta_sample_t *sample;
task_eta_sample_t *base = NULL;
unsigned int i;
if(!task->total || !task->done || task->done >= task->total) {
task->eta = 0;
return;
}
sample = &task->eta_samples[task->eta_sample_next];
sample->done = task->done;
sample->time = *now_mono;
task->eta_sample_next = (task->eta_sample_next + 1) % ETA_SAMPLE_SLOTS;
if(task->eta_sample_count < ETA_SAMPLE_SLOTS) {
task->eta_sample_count++;
}
for(i = 0; i < task->eta_sample_count; i++) {
task_eta_sample_t *candidate = &task->eta_samples[i];
long long age_ns;
if(!candidate->time.tv_sec || candidate->done >= task->done) {
continue;
}
age_ns = timespec_delta_ns(now_mono, &candidate->time);
if(age_ns <= 0 || age_ns > (long long)ETA_AVERAGE_WINDOW_SECONDS * 1000000000LL) {
continue;
}
if(!base || age_ns > timespec_delta_ns(now_mono, &base->time)) {
base = candidate;
}
}
if(base) {
long long elapsed_ns = timespec_delta_ns(now_mono, &base->time);
unsigned long long delta = task->done - base->done;
unsigned long long remaining = task->total - task->done;
if(delta && elapsed_ns > 0) {
long double seconds = (long double)elapsed_ns / 1000000000.0L;
long double eta = ((long double)remaining / (long double)delta) * seconds;
task->eta = eta > 0 ? (unsigned long long)(eta + 0.999999L) : 0;
return;
}
}
task->eta = task->speed ? (task->total - task->done + task->speed - 1) / task->speed : 0;
}
void
task_update(file_task_t *task, task_state_t state, const char *current,
unsigned long long add_done, const char *error) {
struct timespec now_mono;
time_t now;
clock_gettime(CLOCK_MONOTONIC, &now_mono);
now = time(NULL);
pthread_mutex_lock(&g_tasks_lock);
task->state = state;
if(current) {
snprintf(task->current, sizeof(task->current), "%s", current);
}
if(add_done) {
if(!task->transfer_started_at) {
task->transfer_started_at = now;
}
task->done += add_done;
if(task->total && task->done > task->total) {
task->done = task->total;
}
if(task->speed_sample_time.tv_sec) {
long long elapsed_ns = timespec_delta_ns(&now_mono, &task->speed_sample_time);
if(elapsed_ns >= 250000000LL) {
unsigned long long delta = task->done - task->speed_sample_done;
task->speed = (unsigned long long)((delta * 1000000000ULL) /
(unsigned long long)elapsed_ns);
task->speed_sample_done = task->done;
task->speed_sample_time = now_mono;
}
} else {
task->speed_sample_done = task->done;
task->speed_sample_time = now_mono;
}
task_update_eta_locked(task, &now_mono);
}
if(error) {
snprintf(task->error, sizeof(task->error), "%s", error);
}
task->updated_at = now;
pthread_mutex_unlock(&g_tasks_lock);
}
-445
View File
@@ -1,445 +0,0 @@
#include "filemgr_internal.h"
#include <errno.h>
#include <fcntl.h>
#include <limits.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <strings.h>
#include <sys/stat.h>
#include <time.h>
#include <unistd.h>
#include "json_util.h"
#include "path_util.h"
#include "websrv.h"
#define TEXT_FILE_MAX_SIZE (1024 * 1024)
typedef enum text_newline {
TEXT_NEWLINE_LF,
TEXT_NEWLINE_CRLF,
TEXT_NEWLINE_CR,
} text_newline_t;
static enum MHD_Result
send_json_version(struct MHD_Connection *conn, unsigned long long version) {
char *data;
if(asprintf(&data, "{\"ok\":true,\"version\":\"%016llx\"}", version) < 0) {
return MHD_NO;
}
return send_buffer(conn, MHD_HTTP_OK, data, "application/json");
}
static int
text_extension_allowed(const char *path) {
static const char *extensions[] = {
".txt", ".json", ".xml", ".ini", ".cfg", ".conf", ".md",
".log", ".lua", ".js", ".css", ".html", ".htm", ".c", ".h",
".cpp", ".hpp", ".sh", ".csv", ".yaml", ".yml", ".shn"
};
const char *extension = strrchr(path, '.');
size_t i;
if(!extension) {
return 0;
}
for(i = 0; i < sizeof(extensions) / sizeof(extensions[0]); i++) {
if(!strcasecmp(extension, extensions[i])) {
return 1;
}
}
return 0;
}
static int
valid_utf8(const unsigned char *data, size_t size) {
size_t i = 0;
while(i < size) {
unsigned char c = data[i++];
size_t trailing;
unsigned int codepoint;
if(!c) return 0;
if(c < 0x80) continue;
if(c >= 0xc2 && c <= 0xdf) {
trailing = 1;
codepoint = c & 0x1f;
} else if(c >= 0xe0 && c <= 0xef) {
trailing = 2;
codepoint = c & 0x0f;
} else if(c >= 0xf0 && c <= 0xf4) {
trailing = 3;
codepoint = c & 0x07;
} else {
return 0;
}
if(trailing > size - i) return 0;
while(trailing--) {
unsigned char next = data[i++];
if((next & 0xc0) != 0x80) return 0;
codepoint = (codepoint << 6) | (next & 0x3f);
}
if((codepoint >= 0xd800 && codepoint <= 0xdfff) || codepoint > 0x10ffff ||
(codepoint < 0x800 && c >= 0xe0) ||
(codepoint < 0x10000 && c >= 0xf0)) {
return 0;
}
}
return 1;
}
static unsigned long long
text_version(const unsigned char *data, size_t size) {
unsigned long long hash = 1469598103934665603ULL;
size_t i;
for(i = 0; i < size; i++) {
hash ^= data[i];
hash *= 1099511628211ULL;
}
return hash;
}
static text_newline_t
detect_text_newline(const unsigned char *data, size_t size) {
size_t crlf = 0;
size_t lf = 0;
size_t cr = 0;
size_t i;
for(i = 0; i < size; i++) {
if(data[i] == '\r') {
if(i + 1 < size && data[i + 1] == '\n') {
crlf++;
i++;
} else {
cr++;
}
} else if(data[i] == '\n') {
lf++;
}
}
if(crlf > lf && crlf >= cr) return TEXT_NEWLINE_CRLF;
if(cr > lf && cr > crlf) return TEXT_NEWLINE_CR;
return TEXT_NEWLINE_LF;
}
static int
format_text_for_save(const char *body, size_t body_size,
const unsigned char *current, size_t current_size,
char **output, size_t *output_size) {
static const unsigned char bom[] = {0xef, 0xbb, 0xbf};
int keep_bom = current_size >= sizeof(bom) &&
!memcmp(current, bom, sizeof(bom));
text_newline_t newline = detect_text_newline(
current + (keep_bom ? sizeof(bom) : 0),
current_size - (keep_bom ? sizeof(bom) : 0));
const unsigned char *input = (const unsigned char *)(body ? body : "");
size_t input_size = body_size;
size_t capacity = body_size * (newline == TEXT_NEWLINE_CRLF ? 2 : 1) +
sizeof(bom) + 1;
char *formatted;
size_t i;
size_t len = 0;
if(input_size >= sizeof(bom) && !memcmp(input, bom, sizeof(bom))) {
input += sizeof(bom);
input_size -= sizeof(bom);
}
if(!(formatted = malloc(capacity))) {
errno = ENOMEM;
return -1;
}
if(keep_bom) {
memcpy(formatted + len, bom, sizeof(bom));
len += sizeof(bom);
}
for(i = 0; i < input_size; i++) {
unsigned char c = input[i];
if(c != '\r' && c != '\n') {
formatted[len++] = (char)c;
continue;
}
if(c == '\r' && i + 1 < input_size && input[i + 1] == '\n') {
i++;
}
if(newline == TEXT_NEWLINE_CRLF) {
formatted[len++] = '\r';
formatted[len++] = '\n';
} else {
formatted[len++] = newline == TEXT_NEWLINE_CR ? '\r' : '\n';
}
}
if(len > TEXT_FILE_MAX_SIZE) {
free(formatted);
errno = EFBIG;
return -1;
}
formatted[len] = 0;
*output = formatted;
*output_size = len;
return 0;
}
static int
read_text_file(const char *path, char **data, size_t *size,
struct stat *st) {
FILE *file;
size_t read_size;
*data = NULL;
*size = 0;
if(lstat(path, st) || !S_ISREG(st->st_mode)) {
return -1;
}
if(st->st_size < 0 || (unsigned long long)st->st_size > TEXT_FILE_MAX_SIZE) {
errno = EFBIG;
return -1;
}
if(!(file = fopen(path, "rb"))) {
return -1;
}
if(!(*data = malloc((size_t)st->st_size + 1))) {
fclose(file);
errno = ENOMEM;
return -1;
}
read_size = fread(*data, 1, (size_t)st->st_size, file);
if(read_size != (size_t)st->st_size || ferror(file)) {
free(*data);
*data = NULL;
fclose(file);
return -1;
}
fclose(file);
(*data)[read_size] = 0;
*size = read_size;
return 0;
}
static enum MHD_Result
send_text_file(struct MHD_Connection *conn, char *data, size_t size,
unsigned long long version) {
struct MHD_Response *resp;
enum MHD_Result ret;
char version_text[24];
if(!(resp = MHD_create_response_from_buffer(size, data,
MHD_RESPMEM_MUST_FREE))) {
free(data);
return MHD_NO;
}
snprintf(version_text, sizeof(version_text), "%016llx", version);
MHD_add_response_header(resp, MHD_HTTP_HEADER_CONTENT_TYPE,
"text/plain; charset=utf-8");
MHD_add_response_header(resp, "X-Text-Version", version_text);
ret = websrv_queue_response(conn, MHD_HTTP_OK, resp);
MHD_destroy_response(resp);
return ret;
}
enum MHD_Result
api_text(struct MHD_Connection *conn) {
char *path = fs_path_value(query_value(conn, "path"));
char *data;
size_t size;
struct stat st;
unsigned long long version;
if(has_active_task()) {
free(path);
return send_json_error(conn, MHD_HTTP_CONFLICT, "another task is running");
}
if(!path || !text_extension_allowed(path)) {
free(path);
return send_json_error(conn, MHD_HTTP_BAD_REQUEST,
"file type is not editable");
}
if(read_text_file(path, &data, &size, &st)) {
int error = errno;
free(path);
if(error == EFBIG) {
return send_json_error(conn, MHD_HTTP_CONTENT_TOO_LARGE,
"text file is too large");
}
errno = error;
return send_json_error(conn, MHD_HTTP_NOT_FOUND, "file not found");
}
free(path);
if(!valid_utf8((const unsigned char *)data, size)) {
free(data);
return send_json_error(conn, MHD_HTTP_UNSUPPORTED_MEDIA_TYPE,
"file is not valid UTF-8");
}
version = text_version((const unsigned char *)data, size);
return send_text_file(conn, data, size, version);
}
enum MHD_Result
api_text_create(struct MHD_Connection *conn) {
char *path = fs_path_value(query_value(conn, "path"));
char *name = fs_path_value(query_value(conn, "name"));
char target[PATH_MAX];
int fd = -1;
int ret = -1;
int error = 0;
int created = 0;
if(has_active_task()) {
free(path); free(name);
return send_json_error(conn, MHD_HTTP_CONFLICT, "another task is running");
}
if(!path || !name || path_join(target, sizeof(target), path, name)) {
free(path); free(name);
return send_json_error(conn, MHD_HTTP_BAD_REQUEST, "invalid path");
}
if(mode_access(path, W_OK | X_OK)) {
free(path); free(name);
return send_json_error(conn, MHD_HTTP_FORBIDDEN,
"text file is not writable");
}
if((fd = open(target, O_WRONLY | O_CREAT | O_EXCL, 0777)) >= 0) {
created = 1;
ret = fchmod_0777(fd);
if(close(fd) && !ret) ret = -1;
fd = -1;
}
if(ret) {
error = errno;
if(fd >= 0) close(fd);
if(created) unlink(target);
}
free(path); free(name);
if(!ret) {
return send_json_version(conn,
text_version((const unsigned char *)"", 0));
}
errno = error;
return error == EEXIST ?
send_json_error(conn, MHD_HTTP_CONFLICT, "file already exists") :
send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR, NULL);
}
static int
write_text_atomic(const char *path, const char *body, size_t body_size,
mode_t mode) {
struct timespec now;
char temp[PATH_MAX];
size_t written = 0;
int fd = -1;
int ret = -1;
int n;
clock_gettime(CLOCK_MONOTONIC, &now);
n = snprintf(temp, sizeof(temp), "%s.wfm-%ld-%ld.tmp", path,
(long)getpid(), now.tv_nsec);
if(n < 0 || (size_t)n >= sizeof(temp)) {
errno = ENAMETOOLONG;
return -1;
}
if((fd = open(temp, O_WRONLY | O_CREAT | O_EXCL, 0600)) < 0) {
return -1;
}
while(written < body_size) {
ssize_t count = write(fd, body + written, body_size - written);
if(count <= 0) {
goto done;
}
written += (size_t)count;
}
if(fchmod(fd, mode & 07777) && !ignore_chmod_error(errno)) {
goto done;
}
if(fsync(fd)) {
goto done;
}
if(close(fd)) {
fd = -1;
goto done;
}
fd = -1;
if(rename(temp, path)) {
goto done;
}
ret = 0;
done:
if(fd >= 0) close(fd);
if(ret) unlink(temp);
return ret;
}
enum MHD_Result
api_text_save(struct MHD_Connection *conn, const char *body,
size_t body_size) {
char *path = fs_path_value(query_value(conn, "path"));
char *expected = query_value(conn, "version");
char *current = NULL;
size_t current_size = 0;
struct stat st;
char version_text[24];
char parent[PATH_MAX];
char *formatted = NULL;
size_t formatted_size = 0;
int ret;
if(has_active_task()) {
free(path); free(expected);
return send_json_error(conn, MHD_HTTP_CONFLICT, "another task is running");
}
if(!path || !expected) {
free(path); free(expected);
return send_json_error(conn, MHD_HTTP_BAD_REQUEST, "invalid path");
}
if(body_size > TEXT_FILE_MAX_SIZE) {
free(path); free(expected);
return send_json_error(conn, MHD_HTTP_CONTENT_TOO_LARGE,
"text file is too large");
}
if(!valid_utf8((const unsigned char *)(body ? body : ""), body_size)) {
free(path); free(expected);
return send_json_error(conn, MHD_HTTP_UNSUPPORTED_MEDIA_TYPE,
"file is not valid UTF-8");
}
if(read_text_file(path, &current, &current_size, &st)) {
free(path); free(expected);
return send_json_error(conn, MHD_HTTP_NOT_FOUND, "file not found");
}
snprintf(version_text, sizeof(version_text), "%016llx",
text_version((const unsigned char *)current, current_size));
if(strcmp(expected, version_text)) {
free(current);
free(path); free(expected);
return send_json_error(conn, MHD_HTTP_CONFLICT,
"file changed since it was opened");
}
if(path_dirname(path, parent, sizeof(parent)) ||
mode_access(path, W_OK) || mode_access(parent, W_OK | X_OK)) {
free(current);
free(path); free(expected);
return send_json_error(conn, MHD_HTTP_FORBIDDEN,
"text file is not writable");
}
if(format_text_for_save(body, body_size, (const unsigned char *)current,
current_size, &formatted, &formatted_size)) {
int error = errno;
free(current);
free(path); free(expected);
errno = error;
return error == EFBIG ?
send_json_error(conn, MHD_HTTP_CONTENT_TOO_LARGE,
"text file is too large") :
send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR, NULL);
}
free(current);
ret = write_text_atomic(path, formatted, formatted_size, st.st_mode);
free(formatted);
free(path); free(expected);
return ret ? send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR, NULL)
: send_json_ok(conn);
}
-582
View File
@@ -1,582 +0,0 @@
#include "filemgr.h"
#include <errno.h>
#include <fcntl.h>
#include <limits.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/stat.h>
#include <time.h>
#include <unistd.h>
#include "filemgr_internal.h"
#include "json_util.h"
#include "path_util.h"
#define UPLOAD_BUFFER_SIZE (1024 * 1024)
typedef struct upload_context {
file_task_t *task;
int fd;
char *buffer;
size_t buffered;
char temp[PATH_MAX];
char target[PATH_MAX];
unsigned long long expected;
unsigned long long written;
int failed;
int error;
int task_done;
const char *stage;
char error_message[256];
} upload_context_t;
static const char *
upload_error_message(upload_context_t *ctx) {
if(!ctx->error_message[0]) {
snprintf(ctx->error_message, sizeof(ctx->error_message), "%s failed%s%s: %s",
ctx->stage ? ctx->stage : "upload",
ctx->target[0] ? " for " : "",
ctx->target[0] ? ctx->target : "",
strerror(ctx->error ? ctx->error : EIO));
}
return ctx->error_message;
}
static int
upload_flush(upload_context_t *ctx) {
size_t written = 0;
while(written < ctx->buffered) {
ssize_t n;
if(ctx->task && task_cancel_requested(ctx->task)) {
ctx->failed = 1;
ctx->error = ECANCELED;
return -1;
}
n = write(ctx->fd, ctx->buffer + written, ctx->buffered - written);
if(n <= 0) {
ctx->failed = 1;
ctx->error = errno ? errno : EIO;
return -1;
}
written += (size_t)n;
ctx->written += (unsigned long long)n;
}
if(ctx->task && written) {
task_update(ctx->task, TASK_RUNNING, ctx->target,
(unsigned long long)written, NULL);
}
ctx->buffered = 0;
return 0;
}
static void
finish_upload_task(file_task_t *task, task_state_t state, const char *current,
const char *error) {
if(!task) {
return;
}
pthread_mutex_lock(&g_tasks_lock);
if(task_is_active(task)) {
time_t completed_at = time(NULL);
task->state = state;
if(current) {
snprintf(task->current, sizeof(task->current), "%s", current);
}
if(state == TASK_DONE && task->total) {
task->done = task->total;
}
if(state == TASK_DONE) {
record_task_completion_locked(task, completed_at);
}
if(error) {
snprintf(task->error, sizeof(task->error), "%s", error);
}
if(state == TASK_FAILED) {
snprintf(task->error_code, sizeof(task->error_code), "upload_failed");
snprintf(task->error_arg, sizeof(task->error_arg), "%s",
current ? current : task->src);
}
task->updated_at = completed_at;
}
pthread_mutex_unlock(&g_tasks_lock);
}
static void
finish_upload_context_error(upload_context_t *ctx) {
if(!ctx->task || ctx->task_done) {
return;
}
upload_error_message(ctx);
finish_upload_task(ctx->task,
ctx->error == ECANCELED ? TASK_CANCELED : TASK_FAILED,
ctx->target[0] ? ctx->target : ctx->task->current,
ctx->error == ECANCELED ? "canceled" : ctx->error_message);
ctx->task_done = 1;
}
static file_task_t *
upload_task_from_conn(struct MHD_Connection *conn) {
char *idstr = request_value(conn, "X-WFM-Task-ID", "task_id");
unsigned long id = idstr ? strtoul(idstr, NULL, 10) : 0;
file_task_t *task = NULL;
free(idstr);
if(!id) {
return NULL;
}
pthread_mutex_lock(&g_tasks_lock);
task = find_task_locked(id);
if(!task || task->op != TASK_UPLOAD || !task_is_active(task)) {
task = NULL;
}
pthread_mutex_unlock(&g_tasks_lock);
return task;
}
static int
check_upload_manifest_space(const char *base, const char *rels,
const char *sizes, unsigned long long fallback_total,
char *error, size_t error_size,
char *code, size_t code_size,
char *arg, size_t arg_size) {
char *rels_copy = NULL;
char *sizes_copy = NULL;
char *rel;
char *size_text;
char *rel_save;
char *size_save;
unsigned long long available;
int ret = -1;
if(!rels || !sizes) {
return check_target_space(base, fallback_total, error, error_size,
code, code_size, arg, arg_size);
}
if(target_available_space(base, &available)) {
snprintf(error, error_size, "cannot read target free space");
snprintf(code, code_size, "space_check_failed");
snprintf(arg, arg_size, "%s", base);
return -1;
}
if(!(rels_copy = strdup(rels)) || !(sizes_copy = strdup(sizes))) {
errno = ENOMEM;
goto done;
}
rel = strtok_r(rels_copy, "\n", &rel_save);
size_text = strtok_r(sizes_copy, "\n", &size_save);
while(rel || size_text) {
char target[PATH_MAX];
unsigned long long size;
if(!rel || !size_text || path_join_relative(target, sizeof(target), base, rel)) {
snprintf(error, error_size, "invalid path");
snprintf(code, code_size, "invalid_path");
snprintf(arg, arg_size, "%s", rel ? rel : "");
errno = EINVAL;
goto done;
}
size = strtoull(size_text, NULL, 10);
if(available < size) {
snprintf(error, error_size,
"not enough target space, required %llu bytes, available %llu bytes",
size, available);
snprintf(code, code_size, "no_space");
snprintf(arg, arg_size, "%llu,%llu", size, available);
errno = ENOSPC;
goto done;
}
available -= size;
rel = strtok_r(NULL, "\n", &rel_save);
size_text = strtok_r(NULL, "\n", &size_save);
}
ret = 0;
done:
free(rels_copy);
free(sizes_copy);
return ret;
}
enum MHD_Result
api_upload_prepare(struct MHD_Connection *conn, const char *body,
size_t body_size) {
char *path = fs_path_value(body_form_value(body, body_size, "path"));
char *src = body_form_value(body, body_size, "src");
char *total_text = body_form_value(body, body_size, "total");
char *count_text = body_form_value(body, body_size, "count");
char *rels = body_form_value(body, body_size, "rels");
char *sizes = body_form_value(body, body_size, "sizes");
char *overwrite = body_form_value(body, body_size, "overwrite");
file_task_t *task = calloc(1, sizeof(*task));
strbuf_t b = {0};
unsigned long long total = total_text ? strtoull(total_text, NULL, 10) : 0;
size_t count = count_text ? (size_t)strtoull(count_text, NULL, 10) : 0;
char error[128] = {0};
char code[64] = {0};
char arg[PATH_MAX + 96] = {0};
if(!task) {
free(path); free(src); free(total_text); free(count_text);
free(rels); free(sizes); free(overwrite);
return send_json_error(conn, MHD_HTTP_INTERNAL_SERVER_ERROR, "out of memory");
}
if(!path || !src || !count) {
free_task(task);
free(path); free(src); free(total_text); free(count_text);
free(rels); free(sizes); free(overwrite);
return send_json_error(conn, MHD_HTTP_BAD_REQUEST, "invalid path");
}
pthread_mutex_lock(&g_tasks_lock);
remove_finished_tasks_locked();
if(has_active_task_locked()) {
pthread_mutex_unlock(&g_tasks_lock);
free_task(task);
free(path); free(src); free(total_text); free(count_text);
free(rels); free(sizes); free(overwrite);
return send_json_error(conn, MHD_HTTP_CONFLICT, "another task is running");
}
pthread_mutex_unlock(&g_tasks_lock);
if(check_upload_manifest_space(path, rels, sizes, total, error, sizeof(error),
code, sizeof(code), arg, sizeof(arg))) {
free_task(task);
free(path); free(src); free(total_text); free(count_text);
free(rels); free(sizes); free(overwrite);
return send_json_error_detail(conn,
errno == ENOSPC ? MHD_HTTP_INSUFFICIENT_STORAGE :
MHD_HTTP_INTERNAL_SERVER_ERROR,
error[0] ? error : NULL,
code[0] ? code : NULL,
arg[0] ? arg : NULL);
}
task->op = TASK_UPLOAD;
task->state = TASK_RUNNING;
task->src_count = count;
task->file_count = count;
task->total = total;
snprintf(task->src, sizeof(task->src), "%s", src);
snprintf(task->dst, sizeof(task->dst), "%s", path);
snprintf(task->current, sizeof(task->current), "%s", src);
task->created_at = time(NULL);
task->updated_at = task->created_at;
pthread_mutex_lock(&g_tasks_lock);
remove_finished_tasks_locked();
if(has_active_task_locked()) {
pthread_mutex_unlock(&g_tasks_lock);
free_task(task);
free(path); free(src); free(total_text); free(count_text);
free(rels); free(sizes); free(overwrite);
return send_json_error(conn, MHD_HTTP_CONFLICT, "another task is running");
}
task->id = g_next_task_id++;
task->next = g_tasks;
g_tasks = task;
pthread_mutex_unlock(&g_tasks_lock);
free(path); free(src); free(total_text); free(count_text);
free(rels); free(sizes); free(overwrite);
strbuf_printf(&b, "{\"ok\":true,\"task_id\":%lu}", task->id);
return send_buffer(conn, MHD_HTTP_OK, b.data, "application/json");
}
enum MHD_Result
api_upload_finish(struct MHD_Connection *conn) {
file_task_t *task = upload_task_from_conn(conn);
if(!task) {
return send_json_error(conn, MHD_HTTP_NOT_FOUND, "active task not found");
}
if(task_cancel_requested(task)) {
finish_upload_task(task, TASK_CANCELED,
task->current[0] ? task->current : task->src,
"canceled");
return send_json_error(conn, MHD_HTTP_CONFLICT, "canceled");
}
finish_upload_task(task, TASK_DONE,
task->current[0] ? task->current : task->src, NULL);
return send_json_ok(conn);
}
int
filemgr_upload_begin(struct MHD_Connection *conn, void **upload_ctx) {
upload_context_t *ctx;
char *base = fs_path_value(request_value(conn, "X-WFM-Path", "path"));
char *rel = request_value(conn, "X-WFM-Rel", "rel");
char *overwrite = request_value(conn, "X-WFM-Overwrite", "overwrite");
char *size_text = request_value(conn, "X-WFM-Size", "size");
file_task_t *task = upload_task_from_conn(conn);
char **checked_dirs = NULL;
size_t checked_dir_count = 0;
struct stat st;
char error[128] = {0};
char code[64] = {0};
char arg[PATH_MAX + 96] = {0};
int n;
*upload_ctx = NULL;
if(!(ctx = calloc(1, sizeof(*ctx)))) {
free(base); free(rel); free(overwrite); free(size_text);
errno = ENOMEM;
return -1;
}
ctx->fd = -1;
ctx->stage = "preparing upload";
*upload_ctx = ctx;
if(size_text) {
ctx->expected = strtoull(size_text, NULL, 10);
}
ctx->task = task;
if(task) {
pthread_mutex_lock(&g_tasks_lock);
task->active_streams++;
pthread_mutex_unlock(&g_tasks_lock);
}
if(task && task_cancel_requested(task)) {
ctx->failed = 1;
ctx->error = ECANCELED;
goto fail;
}
if(!task && has_active_task()) {
ctx->failed = 1;
ctx->error = EBUSY;
goto fail;
}
ctx->stage = "validating target path";
if(!base || !rel || path_join_relative(ctx->target, sizeof(ctx->target),
base, rel)) {
ctx->failed = 1;
ctx->error = errno ? errno : EINVAL;
goto fail;
}
ctx->stage = "creating target folders";
if(ensure_parent_dirs(base, rel)) {
ctx->failed = 1;
ctx->error = errno ? errno : EACCES;
goto fail;
}
ctx->stage = "checking target path";
if(!lstat(ctx->target, &st)) {
if(S_ISDIR(st.st_mode) || !overwrite || strcmp(overwrite, "1")) {
ctx->failed = 1;
ctx->error = S_ISDIR(st.st_mode) ? EISDIR : EEXIST;
goto fail;
}
} else if(errno != ENOENT) {
ctx->failed = 1;
ctx->error = errno;
goto fail;
}
ctx->stage = "checking target permissions";
if(check_target_writable(ctx->target, &checked_dirs, &checked_dir_count,
error, sizeof(error), code, sizeof(code),
arg, sizeof(arg))) {
snprintf(ctx->error_message, sizeof(ctx->error_message), "%s",
error[0] ? error : "target is not writable");
ctx->failed = 1;
ctx->error = errno ? errno : EACCES;
goto fail;
}
ctx->stage = "checking target space";
if(check_target_space(ctx->target, ctx->expected, error, sizeof(error),
code, sizeof(code), arg, sizeof(arg))) {
snprintf(ctx->error_message, sizeof(ctx->error_message), "%s",
error[0] ? error : "not enough target space");
ctx->failed = 1;
ctx->error = errno ? errno : ENOSPC;
goto fail;
}
ctx->stage = "creating temporary path";
n = snprintf(ctx->temp, sizeof(ctx->temp), "%s.wfm-upload-%ld-%lld.tmp",
ctx->target, (long)getpid(), (long long)time(NULL));
if(n < 0 || (size_t)n >= sizeof(ctx->temp)) {
ctx->failed = 1;
ctx->error = ENAMETOOLONG;
goto fail;
}
ctx->stage = "opening temporary file";
ctx->fd = open(ctx->temp, O_WRONLY | O_CREAT | O_TRUNC, 0600);
if(ctx->fd < 0) {
ctx->failed = 1;
ctx->error = errno;
goto fail;
}
ctx->stage = "allocating upload buffer";
if(!(ctx->buffer = malloc(UPLOAD_BUFFER_SIZE))) {
ctx->failed = 1;
ctx->error = ENOMEM;
goto fail;
}
fail:
free_paths(checked_dirs, checked_dir_count);
free(base); free(rel); free(overwrite); free(size_text);
if(ctx->failed) {
finish_upload_context_error(ctx);
if(ctx->fd >= 0) {
close(ctx->fd);
ctx->fd = -1;
}
if(ctx->temp[0]) {
unlink(ctx->temp);
}
errno = ctx->error ? ctx->error : EIO;
return -1;
}
ctx->stage = "writing file";
return 0;
}
int
filemgr_upload_data(void *upload_ctx, const char *data, size_t size) {
upload_context_t *ctx = upload_ctx;
if(!ctx || ctx->failed) {
return -1;
}
if(ctx->task && task_cancel_requested(ctx->task)) {
ctx->failed = 1;
ctx->error = ECANCELED;
finish_upload_context_error(ctx);
return -1;
}
while(size) {
size_t space = UPLOAD_BUFFER_SIZE - ctx->buffered;
size_t take = size < space ? size : space;
memcpy(ctx->buffer + ctx->buffered, data, take);
ctx->buffered += take;
data += take;
size -= take;
if(ctx->buffered == UPLOAD_BUFFER_SIZE && upload_flush(ctx)) {
finish_upload_context_error(ctx);
return -1;
}
}
return 0;
}
enum MHD_Result
filemgr_upload_finish(struct MHD_Connection *conn, void *upload_ctx) {
upload_context_t *ctx = upload_ctx;
int ret = -1;
if(!ctx) {
return send_json_error(conn, MHD_HTTP_BAD_REQUEST, "invalid path");
}
if(ctx->failed) {
finish_upload_context_error(ctx);
errno = ctx->error ? ctx->error : EIO;
return send_json_error_detail(conn,
errno == EEXIST ? MHD_HTTP_CONFLICT :
errno == EBUSY ? MHD_HTTP_CONFLICT :
errno == ECANCELED ? MHD_HTTP_CONFLICT :
errno == ENOSPC ? MHD_HTTP_INSUFFICIENT_STORAGE :
MHD_HTTP_INTERNAL_SERVER_ERROR,
ctx->error == ECANCELED ? "canceled" : ctx->error_message,
ctx->error == ECANCELED ? NULL : "upload_failed",
ctx->target[0] ? ctx->target : NULL);
}
ctx->stage = "writing file";
if(ctx->buffered && upload_flush(ctx)) {
ctx->error = ctx->error ? ctx->error : EIO;
goto done;
}
ctx->stage = "verifying uploaded size";
if(ctx->expected && ctx->written != ctx->expected) {
ctx->error = EIO;
goto done;
}
ctx->stage = "setting file permissions";
if(fchmod_0777(ctx->fd)) {
ctx->error = errno;
goto done;
}
ctx->stage = "syncing file data";
if(fsync(ctx->fd)) {
ctx->error = errno;
goto done;
}
ctx->stage = "closing temporary file";
if(close(ctx->fd)) {
ctx->fd = -1;
ctx->error = errno;
goto done;
}
ctx->fd = -1;
ctx->stage = "moving temporary file into place";
if(rename(ctx->temp, ctx->target)) {
ctx->error = errno;
goto done;
}
if(ctx->task) {
pthread_mutex_lock(&g_tasks_lock);
ctx->task->upload_completed++;
pthread_mutex_unlock(&g_tasks_lock);
}
ret = 0;
done:
if(ctx->fd >= 0) {
close(ctx->fd);
ctx->fd = -1;
}
if(ret) {
upload_error_message(ctx);
if(ctx->temp[0]) {
unlink(ctx->temp);
}
finish_upload_context_error(ctx);
errno = ctx->error ? ctx->error : EIO;
return send_json_error_detail(conn,
errno == ECANCELED ? MHD_HTTP_CONFLICT :
MHD_HTTP_INTERNAL_SERVER_ERROR,
ctx->error == ECANCELED ? "canceled" : ctx->error_message,
ctx->error == ECANCELED ? NULL : "upload_failed",
ctx->target[0] ? ctx->target : NULL);
}
return send_json_ok(conn);
}
void
filemgr_upload_free(void *upload_ctx) {
upload_context_t *ctx = upload_ctx;
if(!ctx) {
return;
}
if(ctx->fd >= 0) {
close(ctx->fd);
if(ctx->temp[0]) {
unlink(ctx->temp);
}
if(ctx->task && !ctx->task_done) {
int canceled = task_cancel_requested(ctx->task);
finish_upload_task(ctx->task, canceled ? TASK_CANCELED : TASK_FAILED,
ctx->target[0] ? ctx->target : ctx->task->current,
canceled ? "canceled" : "client disconnected");
ctx->task_done = 1;
}
}
free(ctx->buffer);
if(ctx->task) {
pthread_mutex_lock(&g_tasks_lock);
if(ctx->task->active_streams) {
ctx->task->active_streams--;
}
pthread_mutex_unlock(&g_tasks_lock);
}
free(ctx);
}
-34
View File
@@ -1,34 +0,0 @@
/*
* /api/version -- hands the build's VERSION_TAG to the web UI.
*
* The footer in the browser shows a version string, and for a long time that
* string was a literal in assets/main.js, so it drifted out of sync the moment
* the Makefile moved on (v1.9 stayed on screen through the whole v1.9.1
* release). Exposing it over the API keeps a single source of truth: bump
* VERSION_TAG in the Makefile and every surface -- startup notification
* (src/main.c), stdout banner, ELF file name and the UI footer -- follows.
*
* The response is tiny and immutable, so the client caches it for the session.
*/
#include "filemgr_internal.h"
#include <string.h>
#include "json_util.h"
#ifndef VERSION_TAG
#define VERSION_TAG "unknown"
#endif
enum MHD_Result
api_version(struct MHD_Connection *conn) {
strbuf_t b = {0};
strbuf_append(&b, "{\"ok\":true,\"version\":");
json_escape(&b, VERSION_TAG);
strbuf_append(&b, ",\"titleId\":");
json_escape(&b, TITLE_ID);
strbuf_append(&b, "}");
return send_buffer(conn, MHD_HTTP_OK, b.data, "application/json");
}
+8 -143
View File
@@ -6,7 +6,6 @@
#include <arpa/inet.h>
#include <microhttpd.h>
#include <netinet/in.h>
#include <netinet/tcp.h>
#include <sys/socket.h>
#include <unistd.h>
@@ -14,53 +13,6 @@
#include "filemgr.h"
#include "websrv.h"
#define REQUEST_BODY_MAX (4 * 1024 * 1024)
#define HTTP_CONNECTION_MEMORY_LIMIT (8 * 1024 * 1024)
#define HTTP_CONNECTION_MEMORY_INCREMENT (2 * 1024 * 1024)
#define HTTP_SOCKET_RCVBUF_SIZE (4 * 1024 * 1024)
#define HTTP_SOCKET_SNDBUF_SIZE (4 * 1024 * 1024)
static volatile sig_atomic_t g_stop_requested;
static int g_listen_fd = -1;
static void
websrv_tune_connection_socket(int fd) {
const int sndbuf = HTTP_SOCKET_SNDBUF_SIZE;
const int nodelay = 1;
/* OrbisOS HTTP sockets need an explicit send buffer to fill a GbE link. */
(void)setsockopt(fd, SOL_SOCKET, SO_SNDBUF, &sndbuf, sizeof(sndbuf));
(void)setsockopt(fd, IPPROTO_TCP, TCP_NODELAY, &nodelay, sizeof(nodelay));
}
typedef struct request_context {
char *body;
size_t size;
int too_large;
int upload_stream;
void *upload_ctx;
} request_context_t;
static enum MHD_Result
websrv_body_too_large(struct MHD_Connection *conn) {
static const char json[] =
"{\"ok\":false,\"error\":\"request body is too large\","
"\"error_code\":\"request_body_too_large\",\"error_arg\":\"\"}";
struct MHD_Response *resp =
MHD_create_response_from_buffer(sizeof(json) - 1, (void *)json,
MHD_RESPMEM_PERSISTENT);
enum MHD_Result ret;
if(!resp) {
return MHD_NO;
}
MHD_add_response_header(resp, MHD_HTTP_HEADER_CONTENT_TYPE,
"application/json");
ret = websrv_queue_response(conn, MHD_HTTP_CONTENT_TOO_LARGE, resp);
MHD_destroy_response(resp);
return ret;
}
enum MHD_Result
websrv_queue_response(struct MHD_Connection *conn, unsigned int status,
struct MHD_Response *resp) {
@@ -69,27 +21,15 @@ websrv_queue_response(struct MHD_Connection *conn, unsigned int status,
return MHD_queue_response(conn, status, resp);
}
void
websrv_stop(void) {
g_stop_requested = 1;
if(g_listen_fd >= 0) {
shutdown(g_listen_fd, SHUT_RDWR);
}
}
int
websrv_stop_requested(void) {
return g_stop_requested;
}
static enum MHD_Result
websrv_on_request(void *cls, struct MHD_Connection *conn, const char *url,
const char *method, const char *version,
const char *upload_data, size_t *upload_data_size,
void **con_cls) {
request_context_t *ctx = *con_cls;
(void)cls;
(void)version;
(void)upload_data;
(void)upload_data_size;
if(strcmp(method, MHD_HTTP_METHOD_GET) &&
strcmp(method, MHD_HTTP_METHOD_POST) &&
@@ -97,62 +37,13 @@ websrv_on_request(void *cls, struct MHD_Connection *conn, const char *url,
return MHD_NO;
}
if(!ctx) {
if(!(ctx = calloc(1, sizeof(*ctx)))) {
return MHD_NO;
}
ctx->upload_stream = !strcmp(url, "/api/upload-file") &&
!strcmp(method, MHD_HTTP_METHOD_POST);
*con_cls = ctx;
if(!*con_cls) {
*con_cls = (void *)1;
return MHD_YES;
}
if(*upload_data_size) {
size_t chunk_size = *upload_data_size;
if(ctx->upload_stream) {
if(!ctx->upload_ctx && filemgr_upload_begin(conn, &ctx->upload_ctx)) {
ctx->too_large = 1;
}
if(ctx->upload_ctx && filemgr_upload_data(ctx->upload_ctx, upload_data,
chunk_size)) {
ctx->too_large = 1;
}
*upload_data_size = 0;
return MHD_YES;
}
if(chunk_size > REQUEST_BODY_MAX - ctx->size) {
ctx->too_large = 1;
} else if(!ctx->too_large) {
char *body = realloc(ctx->body, ctx->size + chunk_size + 1);
if(!body) {
return MHD_NO;
}
ctx->body = body;
memcpy(ctx->body + ctx->size, upload_data, chunk_size);
ctx->size += chunk_size;
ctx->body[ctx->size] = 0;
}
*upload_data_size = 0;
return MHD_YES;
}
if(ctx->too_large) {
return ctx->upload_stream ?
filemgr_upload_finish(conn, ctx->upload_ctx) :
websrv_body_too_large(conn);
}
if(ctx->upload_stream) {
if(!ctx->upload_ctx && filemgr_upload_begin(conn, &ctx->upload_ctx)) {
return filemgr_upload_finish(conn, ctx->upload_ctx);
}
return filemgr_upload_finish(conn, ctx->upload_ctx);
}
if(!strncmp(url, "/api/", 5)) {
return filemgr_api_request(conn, url, method, ctx->body, ctx->size);
return filemgr_api_request(conn, url);
}
if(!strcmp(url, "/fs")) {
return filemgr_fs_request(conn);
@@ -160,9 +51,6 @@ websrv_on_request(void *cls, struct MHD_Connection *conn, const char *url,
if(!strcmp(url, "/") || !url[0]) {
return asset_request(conn, "/index.html");
}
if(!strcmp(url, "/favicon.ico")) {
return asset_request(conn, "/icon0.png");
}
return asset_request(conn, url);
}
@@ -172,15 +60,6 @@ websrv_on_completed(void *cls, struct MHD_Connection *connection,
(void)cls;
(void)connection;
(void)toe;
request_context_t *ctx = *con_cls;
if(ctx) {
if(ctx->upload_ctx) {
filemgr_upload_free(ctx->upload_ctx);
}
free(ctx->body);
free(ctx);
}
*con_cls = NULL;
}
@@ -205,12 +84,6 @@ websrv_listen(unsigned short port) {
close(srvfd);
return -1;
}
{
const int rcvbuf = HTTP_SOCKET_RCVBUF_SIZE;
/* Set before listen so accepted PS5 sockets inherit the larger window. */
(void)setsockopt(srvfd, SOL_SOCKET, SO_RCVBUF, &rcvbuf, sizeof(rcvbuf));
}
memset(&server_addr, 0, sizeof(server_addr));
server_addr.sin_family = AF_INET;
@@ -227,17 +100,11 @@ websrv_listen(unsigned short port) {
close(srvfd);
return -1;
}
g_stop_requested = 0;
g_listen_fd = srvfd;
if(!(httpd = MHD_start_daemon(MHD_USE_THREAD_PER_CONNECTION | MHD_USE_ITC |
MHD_USE_NO_LISTEN_SOCKET | MHD_USE_DEBUG |
MHD_USE_INTERNAL_POLLING_THREAD | MHD_USE_TURBO,
MHD_USE_INTERNAL_POLLING_THREAD,
0, NULL, NULL, &websrv_on_request, NULL,
MHD_OPTION_CONNECTION_MEMORY_LIMIT,
(size_t)HTTP_CONNECTION_MEMORY_LIMIT,
MHD_OPTION_CONNECTION_MEMORY_INCREMENT,
(size_t)HTTP_CONNECTION_MEMORY_INCREMENT,
MHD_OPTION_NOTIFY_COMPLETED,
&websrv_on_completed, NULL, MHD_OPTION_END))) {
perror("MHD_start_daemon");
@@ -245,13 +112,12 @@ websrv_listen(unsigned short port) {
return -1;
}
while(!g_stop_requested) {
while(1) {
addr_len = sizeof(client_addr);
if((connfd = accept(srvfd, (struct sockaddr *)&client_addr, &addr_len)) < 0) {
if(!g_stop_requested) perror("accept");
perror("accept");
break;
}
websrv_tune_connection_socket(connfd);
if(MHD_add_connection(httpd, connfd, (struct sockaddr *)&client_addr,
addr_len) != MHD_YES) {
perror("MHD_add_connection");
@@ -261,6 +127,5 @@ websrv_listen(unsigned short port) {
}
MHD_stop_daemon(httpd);
g_listen_fd = -1;
return close(srvfd);
}
-2
View File
@@ -23,5 +23,3 @@ enum MHD_Result websrv_queue_response(struct MHD_Connection *conn,
struct MHD_Response *resp);
int websrv_listen(unsigned short port);
void websrv_stop(void);
int websrv_stop_requested(void);
-1402
View File
File diff suppressed because it is too large. Load diff
-113
View File
@@ -1,113 +0,0 @@
#pragma once
/* Standalone ZIP extraction engine.
No HTTP / task dependencies: it can be compiled and tested on its own. */
#include <stdint.h>
#include <stddef.h>
#define ZIPX_PATH_MAX 4096
typedef enum {
ZIPX_PHASE_SCAN = 0,
ZIPX_PHASE_EXTRACT = 1,
ZIPX_PHASE_PUBLISH = 2,
ZIPX_PHASE_CLEANUP = 3
} zipx_phase_t;
typedef enum {
ZIPX_OK = 0,
ZIPX_ERR_CANCELED,
ZIPX_ERR_OPEN, /* cannot open the archive */
ZIPX_ERR_FORMAT, /* corrupt central directory / truncated */
ZIPX_ERR_UNSUPPORTED,/* encryption, multipart or unsupported method */
ZIPX_ERR_UNSAFE_NAME,/* traversal, absolute path, control chars, NUL */
ZIPX_ERR_SPECIAL, /* symlink / device / fifo / socket entry */
ZIPX_ERR_DUPLICATE, /* repeated entry or file/dir name clash inside zip */
ZIPX_ERR_LIMIT_ENTRIES,
ZIPX_ERR_LIMIT_FILE,
ZIPX_ERR_LIMIT_TOTAL,
ZIPX_ERR_LIMIT_RATIO,
ZIPX_ERR_LIMIT_DEPTH,
ZIPX_ERR_LIMIT_NAME,
ZIPX_ERR_CONFLICT, /* target already exists for the chosen policy */
ZIPX_ERR_PASSWORD, /* the archive is encrypted and the password is missing
or wrong; the caller can prompt and retry */
ZIPX_ERR_SPACE,
ZIPX_ERR_IO,
ZIPX_ERR_CRC,
ZIPX_ERR_INTERNAL
} zipx_status_t;
typedef enum {
ZIPX_CONFLICT_FAIL = 0,
ZIPX_CONFLICT_OVERWRITE = 1,
ZIPX_CONFLICT_MERGE = 2
} zipx_conflict_t;
typedef struct {
uint64_t max_entries;
uint64_t max_total_bytes;
uint64_t max_file_bytes;
uint32_t max_ratio; /* uncompressed/compressed, 0 disables */
/* Entries whose uncompressed size is below this are never ratio-screened.
Small highly-compressible entries are common in legitimate archives
(zero-filled placeholders, sparse blobs) and are harmless because the
actual bytes written are bounded by the declared size and by the real
free-space check; the ratio screen only needs to catch entries large
enough to matter. */
uint64_t ratio_min_bytes;
uint32_t max_depth;
uint32_t max_name_len;
uint32_t max_path_len;
} zipx_limits_t;
typedef struct {
int phase;
uint64_t entries_total;
uint64_t entries_done;
uint64_t bytes_total;
uint64_t bytes_done;
const char *current; /* entry name being processed, may be NULL */
} zipx_progress_t;
/* Returns non-zero when the caller wants the operation to stop. */
typedef int (*zipx_cancel_fn)(void *userdata);
typedef void (*zipx_progress_fn)(void *userdata, const zipx_progress_t *progress);
typedef struct {
zipx_status_t status;
int sys_errno;
uint64_t entries_total;
uint64_t entries_done;
uint64_t bytes_total;
uint64_t files_created;
uint64_t dirs_created;
char detail[ZIPX_PATH_MAX]; /* offending path or the staging directory */
char message[192];
} zipx_result_t;
const zipx_limits_t *zipx_default_limits(void);
/* Pre-built limit profiles. Use zipx_limits_profile() to look one up.
ZIPX_LIMITS_DEFAULT is the safe profile shipped by zipx_default_limits().
ZIPX_LIMITS_LARGE allows archives up to 2 TiB total / 1 TiB per file and
a 1000:1 compression ratio. The caller is responsible for verifying that
the PS5 has enough free disk space. */
#define ZIPX_LIMITS_DEFAULT 0
#define ZIPX_LIMITS_LARGE 1
const zipx_limits_t *zipx_limits_profile(int profile);
const char *zipx_status_string(zipx_status_t status);
/* Extract zip_path into dst_dir.
Returns ZIPX_OK or an error code; *result is always filled in.
On any failure the staging directory is removed and dst_dir is left as it
was, except for objects already published with the overwrite policy. */
zipx_status_t zipx_extract(const char *zip_path, const char *dst_dir,
zipx_conflict_t conflict,
const zipx_limits_t *limits,
zipx_cancel_fn cancel,
zipx_progress_fn progress,
void *userdata,
zipx_result_t *result);
-99
View File
@@ -1,99 +0,0 @@
/* Bits of the zipx_* contract that are not specific to a container format.
The limit profiles and the status-to-text mapping describe the *engine
family*, not ZIP, so they live here rather than inside zip_extract.c. All
three engines (ZIP, RAR, 7z) link this one object; keeping them in the ZIP
file would force the RAR and 7z test builds to drag in minizip-ng and zlib
for the sake of three functions. */
#include "zip_extract.h"
/* Default limits.
*
* Tuned to cover real-world PS5 workloads without prompting:
* - PS5 system backup archives (~200-300 GiB total, individual chunks
* well under 64 GiB)
* - 3A-game archives with a single ~300 GiB uncompressed file
*
* Safety against decompression bombs is delegated to:
* 1. `check_space()` (statvfs-based real disk space check) before extract
* 2. `max_ratio` below (declared compression ratio cap)
* The size caps here are an early-fail UX guard, not a security boundary.
*/
static const zipx_limits_t k_default_limits = {
.max_entries = 200000,
.max_total_bytes = 2ULL * 1024 * 1024 * 1024 * 1024,
.max_file_bytes = 512ULL * 1024 * 1024 * 1024,
.max_ratio = 500,
/* Only entries that would individually materialise >=1 GiB are screened
by ratio; anything smaller is harmless (bounded by declared size + the
real free-space check) and is commonly highly compressible in
legitimate archives. */
.ratio_min_bytes = 1ULL * 1024 * 1024 * 1024,
.max_depth = 32,
.max_name_len = 255,
.max_path_len = 1024
};
/* Large profile for archives that exceed the default cap.
*
* - max_file_bytes = 1 TiB (single uncompressed file)
* - max_total_bytes = 4 TiB (whole archive)
* - max_ratio = 1000 (relaxed ratio cap; check_space still applies)
*
* Requires the user to opt in via the web UI (large=1) before these take
* effect. Default limits must always be strictly smaller than large so the
* large profile is unambiguously a relaxation.
*/
static const zipx_limits_t k_large_limits = {
.max_entries = 500000,
.max_total_bytes = 4ULL * 1024 * 1024 * 1024 * 1024,
.max_file_bytes = 1ULL * 1024 * 1024 * 1024 * 1024,
.max_ratio = 1000,
.ratio_min_bytes = 1ULL * 1024 * 1024 * 1024,
.max_depth = 32,
.max_name_len = 255,
.max_path_len = 1024
};
const zipx_limits_t *
zipx_default_limits(void) {
return &k_default_limits;
}
const zipx_limits_t *
zipx_limits_profile(int profile) {
switch(profile) {
case ZIPX_LIMITS_LARGE:
return &k_large_limits;
case ZIPX_LIMITS_DEFAULT:
default:
return &k_default_limits;
}
}
const char *
zipx_status_string(zipx_status_t status) {
switch(status) {
case ZIPX_OK: return "ok";
case ZIPX_ERR_CANCELED: return "canceled";
case ZIPX_ERR_OPEN: return "cannot open archive";
case ZIPX_ERR_FORMAT: return "corrupt archive";
case ZIPX_ERR_UNSUPPORTED: return "unsupported archive";
case ZIPX_ERR_UNSAFE_NAME: return "unsafe entry name";
case ZIPX_ERR_SPECIAL: return "unsupported entry type";
case ZIPX_ERR_DUPLICATE: return "duplicate entry name";
case ZIPX_ERR_LIMIT_ENTRIES: return "too many entries";
case ZIPX_ERR_LIMIT_FILE: return "entry too large";
case ZIPX_ERR_LIMIT_TOTAL: return "archive contents too large";
case ZIPX_ERR_LIMIT_RATIO: return "compression ratio too high";
case ZIPX_ERR_LIMIT_DEPTH: return "path too deep";
case ZIPX_ERR_LIMIT_NAME: return "path too long";
case ZIPX_ERR_CONFLICT: return "target already exists";
case ZIPX_ERR_PASSWORD: return "password required or wrong";
case ZIPX_ERR_SPACE: return "not enough space";
case ZIPX_ERR_IO: return "read or write failed";
case ZIPX_ERR_CRC: return "crc mismatch";
default: return "internal error";
}
}
-438
View File
@@ -1,438 +0,0 @@
/* zipx_volstream -- present a multi-file archive volume set as one stream.
part of ps5-web-file-manager
See zipx_volstream.h for the two split layouts this supports. */
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include "mz.h"
#include "mz_os.h"
#include "mz_strm.h"
#include "mz_strm_os.h"
#include "zipx_volstream.h"
#define VOL_INT32_MAX 0x7fffffffLL
typedef struct {
mz_stream stream; /* first member: callbacks cast the handle to this */
char **paths; /* ordered part paths */
int32_t count;
int64_t *prefix; /* count + 1 entries, prefix[count] == total */
int64_t total;
int32_t mode; /* ZIPX_VOL_MODE_* */
int32_t disk; /* active part index */
int64_t pos; /* absolute position inside the concatenated set */
int32_t os_part; /* part currently held by os, -1 when nothing is open */
void *os;
int32_t opened;
int32_t error;
} zipx_volstream_t;
/* ------------------------------------------------------------------------- */
static int32_t
vol_use_part(zipx_volstream_t *v, int32_t part) {
if(v->os_part == part) {
return MZ_OK;
}
if(v->os_part >= 0) {
mz_stream_close(v->os);
v->os_part = -1;
}
if(mz_stream_open(v->os, v->paths[part], MZ_OPEN_MODE_READ) != MZ_OK) {
v->error = MZ_OPEN_ERROR;
return MZ_OPEN_ERROR;
}
v->os_part = part;
return MZ_OK;
}
/* Part holding an absolute offset, walking from `hint` (parts are laid out in
order and reads are sequential, so this stays O(1) amortised). */
static int32_t
vol_part_of(zipx_volstream_t *v, int64_t pos, int32_t hint) {
int32_t i;
if(pos < 0 || pos >= v->total) {
return -1;
}
i = hint;
if(i < 0) {
i = 0;
}
if(i > v->count - 1) {
i = v->count - 1;
}
while(i > 0 && pos < v->prefix[i]) {
i--;
}
while(i < v->count - 1 && pos >= v->prefix[i + 1]) {
i++;
}
return i;
}
static int32_t
vol_open(void *stream, const char *path, int32_t mode) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
int64_t sum = 0;
int32_t i;
(void)path;
(void)mode;
if(!v || v->count <= 0 || !v->paths) {
return MZ_PARAM_ERROR;
}
v->prefix = (int64_t *)calloc((size_t)v->count + 1, sizeof(*v->prefix));
if(!v->prefix) {
v->error = MZ_MEM_ERROR;
return MZ_MEM_ERROR;
}
for(i = 0; i < v->count; i++) {
int64_t size = mz_os_get_file_size(v->paths[i]);
if(size < 0) {
v->error = MZ_OPEN_ERROR;
return MZ_OPEN_ERROR;
}
v->prefix[i] = sum;
sum += size;
}
v->prefix[v->count] = sum;
v->total = sum;
if(!v->os) {
v->os = mz_stream_os_create();
if(!v->os) {
v->error = MZ_MEM_ERROR;
return MZ_MEM_ERROR;
}
}
/* The end-of-central-directory record sits on the last disk, so a split
disk set starts there; a byte split is read from its first byte. */
v->disk = (v->mode == ZIPX_VOL_MODE_DISK) ? v->count - 1 : 0;
v->pos = v->prefix[v->disk];
v->os_part = -1;
v->opened = 1;
v->error = MZ_OK;
return MZ_OK;
}
static int32_t
vol_is_open(void *stream) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
return (v && v->opened) ? MZ_OK : MZ_OPEN_ERROR;
}
static int32_t
vol_read(void *stream, void *buf, int32_t size) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
int32_t done = 0;
int32_t hint;
if(!v || !v->opened || !buf) {
return MZ_PARAM_ERROR;
}
if(size <= 0) {
return 0;
}
hint = v->os_part >= 0 ? v->os_part : 0;
while(done < size) {
int32_t part = vol_part_of(v, v->pos, hint);
int64_t in_part;
int64_t avail;
int64_t want;
int32_t got;
if(part < 0) {
break; /* end of the logical archive */
}
hint = part;
if(vol_use_part(v, part) != MZ_OK) {
break;
}
in_part = v->pos - v->prefix[part];
avail = (v->prefix[part + 1] - v->prefix[part]) - in_part;
if(avail <= 0) { /* empty part: step over it */
v->pos = v->prefix[part + 1];
continue;
}
want = (int64_t)(size - done);
if(want > avail) {
want = avail;
}
if(want > VOL_INT32_MAX) {
want = VOL_INT32_MAX;
}
if(mz_stream_tell(v->os) != in_part) {
if(mz_stream_seek(v->os, in_part, MZ_SEEK_SET) != MZ_OK) {
v->error = MZ_SEEK_ERROR;
break;
}
}
got = mz_stream_read(v->os, (uint8_t *)buf + done, (int32_t)want);
if(got <= 0) {
if(got < 0) {
v->error = MZ_READ_ERROR;
}
break;
}
done += got;
v->pos += got;
if(got < (int32_t)want) {
break; /* short read: let the caller come back */
}
}
if(done == 0 && v->error != MZ_OK) {
return v->error;
}
return done;
}
static int32_t
vol_write(void *stream, const void *buf, int32_t size) {
(void)stream;
(void)buf;
(void)size;
return MZ_SUPPORT_ERROR;
}
static int64_t
vol_tell(void *stream) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
if(!v || !v->opened) {
return -1;
}
if(v->mode == ZIPX_VOL_MODE_DISK) {
return v->pos - v->prefix[v->disk];
}
return v->pos;
}
static int32_t
vol_seek(void *stream, int64_t offset, int32_t origin) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
int64_t target;
if(!v || !v->opened) {
return MZ_PARAM_ERROR;
}
if(origin == MZ_SEEK_SET) {
target = offset;
if(v->mode == ZIPX_VOL_MODE_DISK) {
target += v->prefix[v->disk]; /* offsets are disk relative there */
}
} else if(origin == MZ_SEEK_CUR) {
target = v->pos + offset;
} else if(origin == MZ_SEEK_END) {
target = v->total + offset;
} else {
return MZ_PARAM_ERROR;
}
if(target < 0) {
target = 0;
}
if(target > v->total) {
target = v->total;
}
v->pos = target;
return MZ_OK;
}
static int32_t
vol_close(void *stream) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
if(!v) {
return MZ_PARAM_ERROR;
}
if(v->os && v->os_part >= 0) {
mz_stream_close(v->os);
v->os_part = -1;
}
v->opened = 0;
return MZ_OK;
}
static int32_t
vol_error(void *stream) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
return v ? v->error : MZ_PARAM_ERROR;
}
static int32_t
vol_get_prop(void *stream, int32_t prop, int64_t *value) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
if(!v || !value) {
return MZ_PARAM_ERROR;
}
if(v->mode != ZIPX_VOL_MODE_DISK) {
/* A byte split keeps absolute offsets, so the disk properties must look
unsupported: minizip-ng then leaves every offset alone. */
return MZ_PARAM_ERROR;
}
if(prop == MZ_STREAM_PROP_DISK_NUMBER) {
*value = v->disk;
return MZ_OK;
}
if(prop == MZ_STREAM_PROP_DISK_SIZE) {
*value = v->prefix[v->disk + 1] - v->prefix[v->disk];
return MZ_OK;
}
return MZ_PARAM_ERROR;
}
static int32_t
vol_set_prop(void *stream, int32_t prop, int64_t value) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
if(!v) {
return MZ_PARAM_ERROR;
}
if(prop != MZ_STREAM_PROP_DISK_NUMBER || v->mode != ZIPX_VOL_MODE_DISK) {
return MZ_PARAM_ERROR;
}
if(value < 0) {
/* minizip-ng passes -1 for entries that live on the same disk as the
central directory, which is the final volume of the set. */
v->disk = v->count - 1;
v->pos = v->prefix[v->disk];
return MZ_OK;
}
if(value >= v->count) {
return MZ_PARAM_ERROR;
}
v->disk = (int32_t)value;
v->pos = v->prefix[v->disk];
return MZ_OK;
}
/* ------------------------------------------------------------------------- */
static void vol_destroy(void **stream);
static mz_stream_vtbl vol_vtbl = {
vol_open, vol_is_open, vol_read, vol_write, vol_tell, vol_seek, vol_close,
vol_error, NULL, vol_destroy, vol_get_prop, vol_set_prop,
};
static void *
vol_create(void) {
zipx_volstream_t *v = (zipx_volstream_t *)calloc(1, sizeof(*v));
if(!v) {
return NULL;
}
v->stream.vtbl = &vol_vtbl;
v->os_part = -1;
return (void *)&v->stream;
}
static void
vol_destroy(void **stream) {
zipx_volstream_t *v;
int32_t i;
if(!stream || !*stream) {
return;
}
v = (zipx_volstream_t *)*stream;
vol_close(&v->stream);
if(v->os) {
mz_stream_os_delete(&v->os);
}
if(v->paths) {
for(i = 0; i < v->count; i++) {
free(v->paths[i]);
}
free(v->paths);
}
free(v->prefix);
free(v);
*stream = NULL;
}
/* ------------------------------------------------------------------------- */
void *
zipx_volstream_create(int32_t mode) {
void *stream = vol_create();
zipx_volstream_t *v = (zipx_volstream_t *)stream;
if(!v) {
return NULL;
}
v->mode = (mode == ZIPX_VOL_MODE_DISK) ? ZIPX_VOL_MODE_DISK :
ZIPX_VOL_MODE_CONCAT;
return stream;
}
void
zipx_volstream_delete(void **stream) {
mz_stream_delete(stream); /* routes through vtbl->destroy */
}
int32_t
zipx_volstream_set_parts(void *stream, const char *const *paths, int32_t count) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
int32_t i;
if(!v || !paths || count <= 0) {
return MZ_PARAM_ERROR;
}
v->paths = (char **)calloc((size_t)count, sizeof(*v->paths));
if(!v->paths) {
return MZ_MEM_ERROR;
}
v->count = count;
for(i = 0; i < count; i++) {
size_t len = strlen(paths[i]) + 1;
v->paths[i] = (char *)malloc(len);
if(!v->paths[i]) {
return MZ_MEM_ERROR;
}
memcpy(v->paths[i], paths[i], len);
}
return MZ_OK;
}
int64_t
zipx_volstream_total(void *stream) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
return v ? v->total : -1;
}
const char *
zipx_volstream_describe(void *stream, char *buf, unsigned int size) {
zipx_volstream_t *v = (zipx_volstream_t *)stream;
const char *base;
if(!buf || size == 0) {
return "";
}
if(!v || v->count <= 0) {
snprintf(buf, size, "(no volumes)");
return buf;
}
base = strrchr(v->paths[0], '/');
#ifdef _WIN32
{
const char *alt = strrchr(v->paths[0], '\\');
if(alt && (!base || alt > base)) {
base = alt;
}
}
#endif
base = base ? base + 1 : v->paths[0];
snprintf(buf, size, "%s (%d volumes)", base, (int)v->count);
return buf;
}
-56
View File
@@ -1,56 +0,0 @@
/* zipx_volstream -- present a multi-file archive volume set as one stream.
part of ps5-web-file-manager
Two split layouts exist in the wild and they need different behaviour:
ZIPX_VOL_MODE_CONCAT (byte split)
`name.zip.001`, `name.zip.002`, ... (7-Zip) and `name.part1.zip`,
`name.part2.zip` (WinRAR). Each part is a byte slice of one archive, so
byte N of the logical archive is byte N of the concatenation and every
offset stored inside the archive is already absolute. Offsets are passed
through untouched and the disk properties are reported as unsupported so
minizip-ng keeps using absolute offsets.
ZIPX_VOL_MODE_DISK (zip split disks)
`name.z01`, `name.z02`, ..., `name.zip` (Info-ZIP / PKZIP style). The
central directory stores the offset of a local header relative to the
disk it starts on, so minizip-ng switches the active disk through
MZ_STREAM_PROP_DISK_NUMBER before seeking. Seek/tell are relative to the
active disk here, which is exactly what mz_zip_entry_seek_local_header
expects, and the stream starts on the last disk because that is where the
end-of-central-directory record lives. */
#ifndef ZIPX_VOLSTREAM_H
#define ZIPX_VOLSTREAM_H
#include <stdint.h>
#include "zipx_volume.h"
#ifdef __cplusplus
extern "C" {
#endif
/* Creates a stream handle; pass it to mz_stream_open() afterwards. */
void *zipx_volstream_create(int32_t mode);
/* Deletes a handle created above (safe with *stream == NULL). */
void zipx_volstream_delete(void **stream);
/* Copies the ordered part paths into the handle. Must be called before the
stream is opened. Returns MZ_OK (0) or MZ_MEM_ERROR (-4). */
int32_t zipx_volstream_set_parts(void *stream, const char *const *paths,
int32_t count);
/* Total logical size (sum of the part sizes), or -1 when not resolved. */
int64_t zipx_volstream_total(void *stream);
/* Human readable description of the set, e.g. "name.z01 (3 volumes)".
Writes into buf and returns buf. */
const char *zipx_volstream_describe(void *stream, char *buf, unsigned int size);
#ifdef __cplusplus
}
#endif
#endif
-600
View File
@@ -1,600 +0,0 @@
/* zipx_volume -- see zipx_volume.h for what this groups and why. */
#include <ctype.h>
#include <dirent.h>
#include <stdarg.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <strings.h>
#include <sys/stat.h>
#include "zipx_volume.h"
typedef struct {
long num;
char *path;
} vol_part_t;
/* ------------------------------------------------------------------------- */
/* path helpers */
static const char *
file_base(const char *path) {
const char *slash = strrchr(path, '/');
const char *back = strrchr(path, '\\');
if(back && (!slash || back > slash)) {
slash = back;
}
return slash ? slash + 1 : path;
}
/* Directory part without a trailing separator; "" for a bare filename. */
static void
file_dir(const char *path, char *buf, size_t size) {
const char *base = file_base(path);
size_t len = (size_t)(base - path);
while(len > 0 && (path[len - 1] == '/' || path[len - 1] == '\\')) {
len--;
}
if(len >= size) {
len = size - 1;
}
memcpy(buf, path, len);
buf[len] = 0;
}
static int
ends_with_ci(const char *s, const char *suffix) {
size_t ls = strlen(s);
size_t lf = strlen(suffix);
if(lf > ls) {
return 0;
}
return strcasecmp(s + ls - lf, suffix) == 0;
}
static int
file_exists(const char *path) {
struct stat st;
return stat(path, &st) == 0;
}
static char *
vol_join(const char *dir, const char *name) {
size_t need = strlen(dir) + strlen(name) + 2;
char *out = (char *)malloc(need);
if(!out) {
return NULL;
}
if(dir[0]) {
snprintf(out, need, "%s/%s", dir, name);
} else {
snprintf(out, need, "%s", name);
}
return out;
}
static char *
err_printf(const char *fmt, ...) {
va_list ap;
char *buf;
int need;
va_start(ap, fmt);
need = vsnprintf(NULL, 0, fmt, ap);
va_end(ap);
if(need < 0) {
return NULL;
}
buf = (char *)malloc((size_t)need + 1);
if(!buf) {
return NULL;
}
va_start(ap, fmt);
vsnprintf(buf, (size_t)need + 1, fmt, ap);
va_end(ap);
return buf;
}
/* ------------------------------------------------------------------------- */
/* part collection */
/* Matches "PREFIX<digits>SUFFIX"; returns 1 and the value on a match. */
static int
match_numbered(const char *entry, const char *prefix, const char *suffix,
long *num) {
size_t plen = strlen(prefix);
size_t slen = strlen(suffix);
const char *p;
char *end = NULL;
long value;
if(strncmp(entry, prefix, plen) != 0) {
return 0;
}
p = entry + plen;
if(!isdigit((unsigned char)*p)) {
return 0;
}
value = strtol(p, &end, 10);
if(end == p) {
return 0;
}
if(slen > 0) {
if(strcmp(end, suffix) != 0) {
return 0;
}
} else if(*end != 0) {
return 0;
}
*num = value;
return 1;
}
static int
part_compare(const void *a, const void *b) {
const vol_part_t *pa = (const vol_part_t *)a;
const vol_part_t *pb = (const vol_part_t *)b;
if(pa->num < pb->num) {
return -1;
}
if(pa->num > pb->num) {
return 1;
}
return 0;
}
static void
free_parts(vol_part_t *parts, int count) {
int i;
for(i = 0; i < count; i++) {
free(parts[i].path);
parts[i].path = NULL;
}
}
/* Collects every entry in `dir` matching PREFIX<digits>SUFFIX, ordered by the
number. Returns the count, or -1 when the directory cannot be listed (with
*err set) or the set is larger than `max`. */
static int
scan_parts(const char *dir, const char *prefix, const char *suffix,
vol_part_t *parts, int max, char **err) {
const char *target = dir[0] ? dir : ".";
DIR *d = opendir(target);
struct dirent *ent;
int count = 0;
if(!d) {
if(err && !*err) {
*err = err_printf("cannot list the directory '%s' that holds the other "
"volumes", target);
}
return -1;
}
while((ent = readdir(d)) != NULL) {
long num = 0;
if(!match_numbered(ent->d_name, prefix, suffix, &num)) {
continue;
}
if(count >= max) {
if(err && !*err) {
*err = err_printf("volume set has more than %d parts, the supported "
"maximum", max);
}
free_parts(parts, count);
closedir(d);
return -1;
}
parts[count].num = num;
parts[count].path = vol_join(dir, ent->d_name);
if(!parts[count].path) {
free_parts(parts, count + 1);
closedir(d);
return -1;
}
count++;
}
closedir(d);
qsort(parts, (size_t)count, sizeof(*parts), part_compare);
return count;
}
/* Verifies the parts are numbered 1..count with no gap (and no duplicate),
filling *err with the exact missing name when they are not. */
static int
check_contiguous(vol_part_t *parts, int count, const char *dir,
const char *prefix, const char *suffix, int width,
char **err) {
int i;
for(i = 0; i < count; i++) {
if(parts[i].num != (long)(i + 1)) {
if(err && !*err) {
char name[512];
char *full;
snprintf(name, sizeof(name), "%s%0*ld%s", prefix, width,
(long)(i + 1), suffix);
full = vol_join(dir, name);
*err = err_printf("volume set is incomplete: '%s' is missing",
full ? full : name);
free(full);
}
return -1;
}
}
return 0;
}
/* ------------------------------------------------------------------------- */
/* volume set bookkeeping */
static void
volume_reset(zipx_volume_t *vol) {
memset(vol, 0, sizeof(*vol));
vol->index = -1;
}
static int
volume_take(zipx_volume_t *vol, vol_part_t *parts, int count, int mode,
const char *selected) {
int i;
vol->paths = (char **)calloc((size_t)count, sizeof(*vol->paths));
if(!vol->paths) {
return -1;
}
for(i = 0; i < count; i++) {
vol->paths[i] = parts[i].path;
parts[i].path = NULL; /* ownership moves into vol */
}
vol->count = count;
vol->mode = mode;
vol->is_set = 1;
vol->index = -1;
for(i = 0; i < count; i++) {
if(selected && strcmp(vol->paths[i], selected) == 0) {
vol->index = i;
break;
}
}
return 0;
}
/* ------------------------------------------------------------------------- */
/* detection: name.zip.001 / name.7z.001 / name.rar.001 */
static int
detect_digit_suffix(const char *dir, const char *base, const char *selected,
zipx_volume_t *vol, char **err) {
static const char *const known[] = { "zip", "7z", "rar", NULL };
const char *dot = strrchr(base, '.');
vol_part_t parts[ZIPX_VOL_MAX_PARTS];
char stem[2048];
char prefix[2100];
size_t stem_len;
int count;
int i;
int known_ext = 0;
if(!dot || dot == base || !dot[1]) {
return 0;
}
for(i = 1; dot[i]; i++) {
if(!isdigit((unsigned char)dot[i])) {
return 0;
}
}
stem_len = (size_t)(dot - base);
if(stem_len >= sizeof(stem)) {
return 0;
}
memcpy(stem, base, stem_len);
stem[stem_len] = 0;
for(i = 0; known[i]; i++) {
char tail[8];
snprintf(tail, sizeof(tail), ".%s", known[i]);
if(ends_with_ci(stem, tail)) {
known_ext = 1;
break;
}
}
if(!known_ext) {
return 0; /* "backup.001" style names are not archive volumes */
}
snprintf(prefix, sizeof(prefix), "%s.", stem);
count = scan_parts(dir, prefix, "", parts, ZIPX_VOL_MAX_PARTS, err);
if(count < 0) {
return -1;
}
if(count <= 1) {
free_parts(parts, count > 0 ? count : 0);
if(count == 1 && err && !*err) {
*err = err_printf("'%s' is the first volume of a split archive but no "
"other volumes ('%s.002', ...) are present", base,
stem);
}
return count == 1 ? -1 : 0;
}
if(check_contiguous(parts, count, dir, prefix, "", 3, err)) {
free_parts(parts, count);
return -1;
}
if(volume_take(vol, parts, count, ZIPX_VOL_MODE_CONCAT, selected)) {
free_parts(parts, count);
return -1;
}
return 1;
}
/* ------------------------------------------------------------------------- */
/* detection: name.z01 ... name.zip */
static int
detect_z_suffix(const char *dir, const char *base, const char *selected,
zipx_volume_t *vol, char **err) {
const char *dot = strrchr(base, '.');
vol_part_t parts[ZIPX_VOL_MAX_PARTS];
char stem[2048];
char prefix[2100];
size_t stem_len;
int count;
if(!dot || dot == base) {
return 0;
}
if((dot[1] != 'z' && dot[1] != 'Z') || !isdigit((unsigned char)dot[2])) {
return 0;
}
{
int i;
for(i = 2; dot[i]; i++) {
if(!isdigit((unsigned char)dot[i])) {
return 0;
}
}
}
stem_len = (size_t)(dot - base);
if(stem_len >= sizeof(stem)) {
return 0;
}
memcpy(stem, base, stem_len);
stem[stem_len] = 0;
snprintf(prefix, sizeof(prefix), "%s.z", stem);
count = scan_parts(dir, prefix, "", parts, ZIPX_VOL_MAX_PARTS - 1, err);
if(count < 0) {
return -1;
}
if(count == 0) {
return 0;
}
if(check_contiguous(parts, count, dir, prefix, "", 2, err)) {
free_parts(parts, count);
return -1;
}
/* The central directory always lives in "name.zip", the final volume. */
{
char name[2100];
char *last;
snprintf(name, sizeof(name), "%s.zip", stem);
last = vol_join(dir, name);
if(!last) {
free_parts(parts, count);
return -1;
}
if(!file_exists(last)) {
if(err && !*err) {
*err = err_printf("volume set is incomplete: the last volume '%s' that "
"holds the archive index is missing", name);
}
free(last);
free_parts(parts, count);
return -1;
}
parts[count].num = (long)count + 1;
parts[count].path = last;
count++;
}
if(volume_take(vol, parts, count, ZIPX_VOL_MODE_DISK, selected)) {
free_parts(parts, count);
return -1;
}
return 1;
}
/* ------------------------------------------------------------------------- */
/* detection: the final "name.zip" of a name.z01 ... name.zip set */
static int
detect_zip_tail(const char *dir, const char *base, const char *selected,
zipx_volume_t *vol, char **err) {
vol_part_t parts[ZIPX_VOL_MAX_PARTS];
char stem[2048];
char prefix[2100];
size_t stem_len;
int count;
if(!ends_with_ci(base, ".zip")) {
return 0;
}
stem_len = strlen(base) - 4;
if(stem_len == 0 || stem_len >= sizeof(stem)) {
return 0;
}
memcpy(stem, base, stem_len);
stem[stem_len] = 0;
snprintf(prefix, sizeof(prefix), "%s.z", stem);
count = scan_parts(dir, prefix, "", parts, ZIPX_VOL_MAX_PARTS - 1, err);
if(count < 0) {
return -1;
}
if(count == 0) {
return 0; /* an ordinary single volume archive */
}
if(check_contiguous(parts, count, dir, prefix, "", 2, err)) {
free_parts(parts, count);
return -1;
}
{
char *last = vol_join(dir, base);
if(!last) {
free_parts(parts, count);
return -1;
}
parts[count].num = (long)count + 1;
parts[count].path = last;
count++;
}
if(volume_take(vol, parts, count, ZIPX_VOL_MODE_DISK, selected)) {
free_parts(parts, count);
return -1;
}
return 1;
}
/* ------------------------------------------------------------------------- */
/* detection: name.part1.zip ... */
static int
detect_part_suffix(const char *dir, const char *base, const char *selected,
zipx_volume_t *vol, char **err) {
vol_part_t parts[ZIPX_VOL_MAX_PARTS];
char stem[2048];
char prefix[2100];
char trimmed[2048];
const char *dot;
size_t len;
int count;
if(!ends_with_ci(base, ".zip")) {
return 0;
}
len = strlen(base) - 4;
if(len == 0 || len >= sizeof(trimmed)) {
return 0;
}
memcpy(trimmed, base, len);
trimmed[len] = 0;
dot = strrchr(trimmed, '.');
if(!dot || dot == trimmed || strncasecmp(dot, ".part", 5) != 0 ||
!isdigit((unsigned char)dot[5])) {
return 0;
}
{
size_t stem_len = (size_t)(dot - trimmed);
if(stem_len >= sizeof(stem)) {
return 0;
}
memcpy(stem, trimmed, stem_len);
stem[stem_len] = 0;
}
snprintf(prefix, sizeof(prefix), "%s.part", stem);
count = scan_parts(dir, prefix, ".zip", parts, ZIPX_VOL_MAX_PARTS, err);
if(count < 0) {
return -1;
}
if(count <= 1) {
free_parts(parts, count > 0 ? count : 0);
if(count == 1 && err && !*err) {
*err = err_printf("'%s' is a volume of a split archive but the other "
"volumes ('%s.part1.zip', ...) are missing", base, stem);
}
return count == 1 ? -1 : 0;
}
if(check_contiguous(parts, count, dir, prefix, ".zip", 1, err)) {
free_parts(parts, count);
return -1;
}
if(volume_take(vol, parts, count, ZIPX_VOL_MODE_DISK, selected)) {
free_parts(parts, count);
return -1;
}
return 1;
}
/* ------------------------------------------------------------------------- */
int
zipx_volume_detect(const char *path, zipx_volume_t *out, char **err) {
char dir[4096];
const char *base;
int rc;
if(err) {
*err = NULL;
}
if(!path || !out) {
return -1;
}
volume_reset(out);
base = file_base(path);
file_dir(path, dir, sizeof(dir));
rc = detect_digit_suffix(dir, base, path, out, err);
if(rc != 0) {
return rc;
}
rc = detect_z_suffix(dir, base, path, out, err);
if(rc != 0) {
return rc;
}
rc = detect_zip_tail(dir, base, path, out, err);
if(rc != 0) {
return rc;
}
return detect_part_suffix(dir, base, path, out, err);
}
void
zipx_volume_free(zipx_volume_t *vol) {
int i;
if(!vol) {
return;
}
if(vol->paths) {
for(i = 0; i < vol->count; i++) {
free(vol->paths[i]);
}
free(vol->paths);
}
memset(vol, 0, sizeof(*vol));
vol->index = -1;
}
int
zipx_volume_is_first(const char *path) {
const char *base = file_base(path);
const char *dot = strrchr(base, '.');
if(!dot) {
return 0;
}
if(strcmp(dot, ".001") == 0) {
return 1;
}
if((dot[1] == 'z' || dot[1] == 'Z') && dot[2] == '0' && dot[3] == '1' &&
dot[4] == 0) {
return 1;
}
if(ends_with_ci(base, ".part1.zip")) {
return 1;
}
return 0;
}
-58
View File
@@ -1,58 +0,0 @@
/* zipx_volume -- group a multi-file archive volume set into an ordered list.
part of ps5-web-file-manager
Supports the naming conventions seen in the wild:
name.zip.001, name.zip.002, ... byte split (7-Zip "split to volumes")
name.part1.zip, name.part2.zip byte split (WinRAR zip volumes)
name.z01, name.z02, ..., name.zip zip split disks (Info-ZIP / PKZIP)
A caller can hand in any member of the set (the user usually clicks one file
in the browser) and gets back the full ordered list plus the split layout so
the engine can pick the matching stream behaviour. */
#ifndef ZIPX_VOLUME_H
#define ZIPX_VOLUME_H
#include <stdint.h>
#ifdef __cplusplus
extern "C" {
#endif
#define ZIPX_VOL_MAX_PARTS 512
/* How the set is split. A byte split (`name.zip.001`, `name.7z.001`,
`name.part1.zip`) is the concatenation of its parts with absolute offsets;
zip split disks (`name.z01` + `name.zip`) store per-disk offsets instead.
The constants live here because they describe the *set*, and every consumer
of zipx_volume_t needs them. */
#define ZIPX_VOL_MODE_CONCAT 0
#define ZIPX_VOL_MODE_DISK 1
typedef struct {
char **paths; /* ordered part paths, owned by this struct */
int count;
int index; /* position of the path that was handed in (-1 unknown) */
int mode; /* ZIPX_VOL_MODE_CONCAT or ZIPX_VOL_MODE_DISK */
int is_set; /* 1 when the path is part of a multi-file set */
} zipx_volume_t;
/* Inspects `path`: 1 when it belongs to a multi-file set (out is filled),
0 when it is an ordinary single file (out is cleared), -1 on a hard error
(*err, when non-NULL, receives a malloc'd message the caller must free;
it is also set for the 0 case when a sibling set looks broken, so callers
can surface "volumes are incomplete" instead of a generic open failure). */
int zipx_volume_detect(const char *path, zipx_volume_t *out, char **err);
void zipx_volume_free(zipx_volume_t *vol);
/* True when `path` looks like the first volume of a set ("x.zip.001",
"x.z01", "x.part1.zip"), used by the UI to label the entry. */
int zipx_volume_is_first(const char *path);
#ifdef __cplusplus
}
#endif
#endif
-15
View File
@@ -1,15 +0,0 @@
#!/usr/bin/env bash
# Thin wrapper -- the actual driver is tests/bench_driver.py.
#
# /usr/bin/bash tests/bench-sevenz.sh [--big] [--runs N]
#
# bash is deliberately not used for timing here. In this sandbox every `date`
# costs ~350 ms, so a t0/t1 pair injects ~700 ms of overhead into a
# measurement whose real value is ~600 ms, and `time`'s user/sys accounting
# does not see into the native child at all (it reported 31 ms of CPU for a
# run that demonstrably decodes 82 MiB). Python reads a monotonic clock
# around a single spawn per sample instead.
set -e
ROOT="$(cd "$(dirname "$0")/.." && pwd -W 2>/dev/null || pwd)"
exec python "$ROOT/tests/bench_driver.py" "$@"
-249
View File
@@ -1,249 +0,0 @@
#!/usr/bin/env python3
"""Performance baseline for the extraction engines.
python tests/bench_driver.py # 82 MiB fixture, fast
python tests/bench_driver.py --big # 320 MiB fixture, accurate
python tests/bench_driver.py --runs 5
Times our facades (src/zip_extract.c, src/sevenz_extract.c) against the two
external references that matter: the vendored SDK's own SzArEx path, and the
official 7-Zip binary -- the latter being what upstream v1.8 gets by shelling
out to a helper, so it doubles as the "how fast could we be" ceiling.
Why Python drives the measurement: in this sandbox a single `date` costs
~350 ms, so the usual `t0=$(date)` / `t1=$(date)` pair adds ~700 ms of pure
overhead to a measurement whose real value is ~600 ms, and `time`'s user/sys
accounting does not see into the native child at all. Python spawns each
child once and reads a monotonic clock around it, which leaves a small,
constant "spawn tax" that is measured and subtracted (see the report).
The candidate binaries print their own in-process timing, which excludes the
spawn tax entirely -- that is the most trustworthy figure for our side.
"""
import argparse
import os
import re
import subprocess
import sys
import time
REPO = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
BUILD = os.path.join(REPO, ".build", "bench")
SZ_BUILD = os.path.join(REPO, ".build", "sevenz-test")
HT_BUILD = os.path.join(REPO, ".build", "host-test")
SEVENZ_BIN = os.path.join(REPO, ".build", "7zdl", "extra", "x64", "7za.exe")
BENCH_BIN = os.path.join(BUILD, "bench_extract.exe")
SDK_BIN = os.path.join(SZ_BUILD, "sevenz_e2e.exe")
# Object lists mirror what tests/run-sevenz-tests.sh and tests/run-tests.sh
# build; those scripts must have run once before this can link.
VENDOR_7Z = ["7zAlloc", "7zArcIn", "7zBuf", "7zBuf2", "7zCrc", "7zCrcOpt",
"7zDec", "7zFile", "7zStream", "Aes", "AesOpt", "Alloc", "Bcj2",
"Bra", "Bra86", "BraIA64", "CpuArch", "Delta", "DllSecur",
"Lzma2Dec", "LzmaDec", "Lzma2DecMt", "MtDec", "Threads", "Ppmd7",
"Ppmd7Dec", "Sha256", "Sha256Opt", "SwapBytes"]
ZLIB = ["adler32", "crc32", "deflate", "inffast", "inflate", "inftrees",
"trees", "zutil"]
MINIZIP = ["mz_crypt", "mz_os", "mz_os_posix", "mz_strm", "mz_strm_mem",
"mz_strm_os_posix", "mz_strm_zlib", "mz_zip"]
EXTRA_LIBS = ["-lole32", "-loleaut32", "-luuid", "-ladvapi32", "-luser32",
"-lshell32"]
def objs(base, names):
return [os.path.join(base, n + ".o") for n in names]
def build_bench():
"""Link tests/bench_extract.c against the prebuilt engine objects."""
if os.path.exists(BENCH_BIN):
return True
needed = (objs(SZ_BUILD, ["sevenz_extract", "sevenz_chain",
"sevenz_mt", "sevenz_volstream", "zipx_common",
"zipx_volume"])
+ objs(HT_BUILD, ["zip_extract", "zipx_volstream"])
+ objs(HT_BUILD, ZLIB) + objs(HT_BUILD, MINIZIP)
+ objs(SZ_BUILD, VENDOR_7Z))
missing = [p for p in needed if not os.path.exists(p)]
if missing:
print("missing engine objects, run these first:")
print(" /usr/bin/bash tests/run-sevenz-tests.sh")
print(" /usr/bin/bash tests/run-tests.sh --rebuild")
print("first missing: %s" % missing[0])
return False
cmd = ["gcc", "-O2", "-w",
"-I" + os.path.join(REPO, "third_party", "7z"),
"-I" + os.path.join(REPO, "third_party", "minizip-ng", "include"),
"-I" + os.path.join(REPO, "third_party", "zlib", "include"),
"-I" + os.path.join(REPO, "src"),
"-I" + os.path.join(REPO, "tests", "compat"),
"-include", os.path.join(REPO, "tests", "posix_compat.h"),
"-o", BENCH_BIN, os.path.join(REPO, "tests", "bench_extract.c")]
cmd += needed + EXTRA_LIBS
print("== compiling bench harness ==")
if subprocess.run(cmd, cwd=REPO).returncode != 0:
return False
return True
def make_fixture(big, fmt):
"""Build the archive if absent: repeated source text plus a real PE file.
The blend matters -- compression throughput depends heavily on match
length, so a pure-text corpus would flatter every decoder equally and a
pure-random one would measure nothing but copying.
"""
stem = "big4" if big else "big"
archive = os.path.join(BUILD, "%s.%s" % (stem, fmt))
if os.path.exists(archive):
return archive
os.makedirs(BUILD, exist_ok=True)
tp = os.path.join(REPO, "third_party")
parts = []
for sub in ("zlib/src", "7z", "minizip-ng/src"):
d = os.path.join(tp, sub)
if os.path.isdir(d):
for name in sorted(os.listdir(d)):
if name.endswith((".c", ".h")):
parts.append(os.path.join(d, name))
if not parts:
print("no source available to build a fixture from")
return None
repeat = 240 if big else 60
src = os.path.join(BUILD, "payload_src.bin")
with open(src, "wb") as out:
for _ in range(repeat):
for path in parts:
with open(path, "rb") as fh:
out.write(fh.read())
payload = src
pe = r"C:\Windows\System32\ntoskrnl.exe"
if os.path.exists(pe):
binary = os.path.join(BUILD, "payload_bin.bin")
with open(binary, "wb") as out:
for _ in range(30 if big else 3):
with open(pe, "rb") as fh:
out.write(fh.read())
payload = os.path.join(BUILD, "payload_mix.bin")
with open(payload, "wb") as out:
for _ in range(4 if big else 1):
for path in (src, binary):
with open(path, "rb") as fh:
out.write(fh.read())
print("== creating fixture (first run only) ==")
if fmt == "7z":
add = ["a", "-t7z", "-m0=lzma2", "-mx=5", "-ms=on"]
else:
add = ["a", "-tzip", "-mx=5", "-mm=Deflate"]
subprocess.run([SEVENZ_BIN] + add + [archive, payload], cwd=REPO,
stdout=subprocess.DEVNULL)
return archive
def sample(argv, runs, workdir):
"""Run argv `runs` times; return (best wall ms, best in-process ms|None)."""
best = None
internal = None
for _ in range(runs):
os.makedirs(workdir, exist_ok=True)
started = time.perf_counter()
proc = subprocess.run(argv, stdout=subprocess.PIPE,
stderr=subprocess.STDOUT, cwd=REPO, timeout=1800)
elapsed = (time.perf_counter() - started) * 1000.0
if proc.returncode != 0:
sys.stdout.write(proc.stdout.decode("utf-8", "replace")[:300])
return None, None
if best is None or elapsed < best:
best = elapsed
match = re.search(rb"wall\s*:\s*([0-9.]+)\s*s", proc.stdout)
if match:
value = float(match.group(1)) * 1000.0
if internal is None or value < internal:
internal = value
return best, internal
def main():
ap = argparse.ArgumentParser()
ap.add_argument("--big", action="store_true",
help="4x fixture (~320 MiB) for accurate ratios")
ap.add_argument("--runs", type=int, default=3)
ap.add_argument("--format", choices=["7z", "zip"], default="7z",
help="which engine to benchmark (default 7z)")
args = ap.parse_args()
# For ZIP there is no useful SDK reference: the vendored SDK is 7z-only,
# so the comparison is just ours versus the official binary.
for path in (SEVENZ_BIN, SDK_BIN if args.format == "7z" else SEVENZ_BIN):
if not os.path.exists(path):
print("missing: %s" % path)
return 1
if not build_bench():
return 1
archive = make_fixture(args.big, args.format)
if not archive:
return 1
raw = os.path.getsize(archive)
print()
print("archive : %s (%.0f MiB packed), best of %d runs"
% (os.path.basename(archive), raw / 1048576.0, args.runs))
print()
rows = []
wall, inner = sample([BENCH_BIN, archive, ".build/bench/W7"], args.runs,
os.path.join(BUILD, "W7"))
if wall:
rows.append(("ours / " + args.format, wall, inner))
if args.format == "7z":
wall, _ = sample([SDK_BIN, archive, ".build/bench/W8"], args.runs,
os.path.join(BUILD, "W8"))
if wall:
rows.append(("sdk SzArEx", wall, None))
variants = (("7za 1 thread", ["-mmt=off"]),
("7za 8 threads", ["-mmt=8"]),
("7za all cores", []))
else:
variants = (("7za 1 thread", ["-mmt=off"]),)
for label, extra in variants:
wall, _ = sample([SEVENZ_BIN, "x", "-y", "-aoa"] + extra
+ ["-o.build/bench/W9", archive], args.runs,
os.path.join(BUILD, "W9"))
if wall:
rows.append((label, wall, None))
print(" %-18s %10s %12s" % ("configuration", "external", "internal"))
for label, wall, inner in rows:
print(" %-18s %9.0f ms %12s"
% (label, wall,
"%9.0f ms" % inner if inner else " -"))
tax = None
ours = [r for r in rows if r[0].startswith("ours")]
if ours and ours[0][2]:
tax = ours[0][1] - ours[0][2]
ref = ours[0][2]
print()
print(" spawn tax (ours external - internal): %.0f ms" % tax)
print()
print(" %-18s %12s %9s" % ("configuration", "net", "vs ours"))
for label, wall, inner in rows:
net = inner if inner else max(wall - tax, 1.0)
print(" %-18s %9.0f ms %8.2fx" % (label, net, ref / net))
print()
print(" net = external minus spawn tax; >1x means faster than ours")
return 0
if __name__ == "__main__":
sys.exit(main())
-115
View File
@@ -1,115 +0,0 @@
/* Wall-clock benchmark for the extraction paths, ZIP and 7z.
*
* bench_extract <archive> <out-dir> [password]
*
* Reports how long the facade takes end to end -- decode, staging writes,
* fsync, publish -- which is exactly what a PS5 user waits for. It is
* deliberately separate from the correctness drivers: those assert on bytes,
* this one only prints numbers, and it is not part of the test matrix.
*
* Keeping it in-tree matters because "is our engine fast?" is a question that
* will come up again, and the answer should be a command anyone can rerun
* rather than a number somebody remembers. The format is picked from the
* suffix so the same binary covers both engines.
*/
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <time.h>
#include "sevenz_extract.h"
static int
has_suffix(const char *path, const char *suffix) {
size_t path_len;
size_t suffix_len;
if(!path || !suffix) return 0;
path_len = strlen(path);
suffix_len = strlen(suffix);
if(path_len < suffix_len) return 0;
for(size_t i = 0; i < suffix_len; i++) {
char a = path[path_len - suffix_len + i];
char b = suffix[i];
if(a >= 'A' && a <= 'Z') a = (char)(a - 'A' + 'a');
if(b >= 'A' && b <= 'Z') b = (char)(b - 'A' + 'a');
if(a != b) return 0;
}
return 1;
}
static double
now_seconds(void) {
struct timespec ts;
if(timespec_get(&ts, TIME_UTC) != TIME_UTC) return 0.0;
return (double)ts.tv_sec + (double)ts.tv_nsec / 1000000000.0;
}
int
main(int argc, char **argv) {
zipx_result_t result;
zipx_status_t status;
const char *archive;
const char *out_dir;
const char *password;
const char *format;
double started;
double elapsed;
double mebibytes;
if(argc < 3) {
fprintf(stderr, "usage: %s <archive> <out-dir> [password]\n", argv[0]);
return 2;
}
archive = argv[1];
out_dir = argv[2];
password = argc > 3 ? argv[3] : NULL;
if(has_suffix(archive, ".7z") || has_suffix(archive, ".7z.001") ||
has_suffix(archive, ".001")) {
format = "7z";
}
#ifndef BENCH_SEVENZ_ONLY
else if(has_suffix(archive, ".zip") || has_suffix(archive, ".zip.001") ||
has_suffix(archive, ".z01")) {
format = "zip";
}
#endif
else {
fprintf(stderr, "unsupported benchmark format: %s\n", archive);
return 2;
}
memset(&result, 0, sizeof(result));
started = now_seconds();
#ifndef BENCH_SEVENZ_ONLY
if(!strcmp(format, "zip")) {
status = zipx_extract(archive, out_dir, ZIPX_CONFLICT_OVERWRITE,
zipx_default_limits(), NULL, NULL, NULL, &result);
} else
#endif
{
status = sevenz_extract(archive, out_dir, ZIPX_CONFLICT_OVERWRITE,
zipx_default_limits(), NULL, NULL, NULL,
password, &result);
}
elapsed = now_seconds() - started;
mebibytes = (double)result.bytes_total / (1024.0 * 1024.0);
printf("format : %s\n", format);
printf("status : %s\n", zipx_status_string(status));
printf("entries : %llu\n", (unsigned long long)result.entries_total);
printf("unpacked : %.1f MiB\n", mebibytes);
printf("wall : %.3f s\n", elapsed);
if(elapsed > 0.0) {
printf("through : %.1f MiB/s (single thread)\n", mebibytes / elapsed);
}
if(status != ZIPX_OK) {
printf("detail : %s\n", result.detail[0] ? result.detail : "(none)");
printf("message : %s\n", result.message[0] ? result.message : "(none)");
}
return status == ZIPX_OK ? 0 : 1;
}
-40
View File
@@ -1,40 +0,0 @@
/* Standalone big-file e2e: extract one large zip64 archive on the host and
* report the engine result. Verification (size + sha256/cmp) is done by the
* caller with shell tools.
*
* cc -O2 -Isrc -Ithird_party/minizip-ng/include \
* -include tests/posix_compat.h \
* -o bigfile_e2e bigfile_e2e.c zip_extract.o <minizip+zlib objs>
*
* ./bigfile_e2e <archive.zip> <out-dir>
*/
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include "zip_extract.h"
int
main(int argc, char **argv) {
zipx_result_t res;
zipx_status_t st;
if(argc != 3) {
fprintf(stderr, "usage: %s <archive.zip> <out-dir>\n", argv[0]);
return 2;
}
st = zipx_extract(argv[1], argv[2], ZIPX_CONFLICT_FAIL,
zipx_limits_profile(ZIPX_LIMITS_LARGE),
NULL, NULL, NULL, &res);
printf("status=%d (%s)\n", (int)st, zipx_status_string(st));
printf("sys_errno=%d entries=%llu/%llu files=%llu dirs=%llu\n",
res.sys_errno, (unsigned long long)res.entries_done,
(unsigned long long)res.entries_total,
(unsigned long long)res.files_created,
(unsigned long long)res.dirs_created);
printf("bytes_total=%llu detail=%s\n",
(unsigned long long)res.bytes_total, res.detail);
if(res.message[0]) {
printf("message=%s\n", res.message);
}
return st == ZIPX_OK ? 0 : 1;
}
-44
View File
@@ -1,44 +0,0 @@
/* Host test shim: provides <sys/statvfs.h> for MinGW hosts.
Only used when building the test suite (see run-tests.sh). */
#ifndef WFM_TEST_SYS_STATVFS_H
#define WFM_TEST_SYS_STATVFS_H
#include <windows.h>
struct statvfs {
unsigned long f_bsize;
unsigned long f_frsize;
unsigned long f_blocks;
unsigned long f_bfree;
unsigned long f_bavail;
};
static int
statvfs(const char *path, struct statvfs *buf) {
ULARGE_INTEGER total;
ULARGE_INTEGER free_bytes;
char full[MAX_PATH];
char root[8];
/* Resolve to an absolute path first: the drive-letter extraction below
only works for "X:\..." style paths, and callers may pass relative
paths (e.g. the standalone bigfile_e2e driver). */
if(!GetFullPathNameA(path, (DWORD)sizeof(full), full, NULL)) {
return -1;
}
snprintf(root, sizeof(root), "%.3s", full);
if(!GetDiskFreeSpaceExA(root, &free_bytes, &total, NULL)) {
return -1;
}
memset(buf, 0, sizeof(*buf));
/* `unsigned long` is 32-bit on Windows: store free space scaled by 4096
so archives up to 16 TiB don't overflow (real 64-bit hosts are LP64
and unaffected; PS5 SDK is LP64 too). */
buf->f_bsize = 4096;
buf->f_frsize = 4096;
buf->f_bavail = free_bytes.QuadPart / 4096;
return 0;
}
#endif
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
-1
View File
@@ -1 +0,0 @@
placeholder
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
Loaded 100 of 404 files, more files were not shown because too many files have changed in this diff. Show more