1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: 30: 31: 32: 33: 34: 35: 36: 37: 38: 39: 40: 41: 42: 43: 44: 45: 46: 47: 48: 49: 50: 51: 52: 53: 54: 55: 56: 57: 58: 59: 60: 61: 62: 63: 64: 65: 66: 67: 68: 69: 70: 71: 72: 73: 74: 75: 76: 77: 78: 79: 80: 81: 82: 83: 84: 85: 86: 87: 88: 89: 90: 91: 92: 93: 94: 95: 96: 97: 98: 99: 100: 101: 102: 103: 104: 105: 106: 107: 108: 109: 110: 111: 112: 113: 114: 115: 116: 117: 118: 119: 120: 121: 122: 123: 124: 125: 126: 127: 128: 129: 130: 131: 132: 133: 134: 135: 136: 137: 138: 139: 140: 141: 142: 143: 144: 145: 146: 147: 148: 149: 150: 151: 152: 153: 154: 155: 156: 157: 158: 159: 160: 161: 162: 163: 164: 165: 166: 167: 168: 169: 170: 171: 172: 173: 174: 175: 176: 177: 178: 179: 180: 181: 182: 183: 184: 185: 186: 187: 188: 189: 190: 191: 192: 193: 194: 195: 196: 197: 198: 199: 200: 201: 202: 203: 204: 205: 206: 207: 208: 209: 210: 211: 212: 213: 214: 215: 216: 217: 218: 219: 220: 221: 222: 223: 224: 225: 226: 227: 228: 229: 230: 231: 232: 233: 234: 235: 236: 237: 238: 239: 240: 241: 242: 243: 244: 245: 246: 247: 248: 249: 250: 251: 252: 253: 254: 255: 256: 257: 258: 259: 260: 261: 262: 263: 264: 265:
<?php
namespace MvcCore\Ext\Forms\Validators\Files\Validations\BombScanners;
class GzArchive implements \MvcCore\Ext\Forms\Validators\Files\Validations\IBombScanner {
protected $validator = NULL;
protected $spl = NULL;
protected $fullPath = NULL;
protected $gz = NULL;
protected $phar = FALSE;
protected $pharFullPath = NULL;
protected $files = [];
protected $index = 0;
static function MatchMagicBytes ($firstFourBytes) {
return substr($firstFourBytes, 0, 3) === "\x1f\x8b\x08";
}
static function IsArchive () {
return TRUE;
}
static function IsSupported () {
return TRUE;
}
static function GetNotSupportedError () {
return '';
}
public function __construct (\MvcCore\Ext\Forms\Validators\IFiles $validator, \SplFileObject $spl) {
$this->validator = $validator;
$this->spl = $spl;
$this->fullPath = str_replace('\\', '/', $this->spl->getRealPath());
}
public function Open () {
$this->gz = gzopen($this->fullPath, 'r');
if ($this->gz === FALSE) return FALSE;
$tmpDir = $this->validator->GetUploadsTmpDir();
$entryNameBase = preg_replace('#[^A-Za-z0-9_\.]#', '', basename($this->fullPath));
$itemDir = $tmpDir . '/' . $entryNameBase . '.' . uniqid();
$itemDirCreated = mkdir($itemDir, 0600);
if (!$itemDirCreated) return FALSE;
$this->pharFullPath = $itemDir . '/' . $entryNameBase;
$writePointer = fopen($this->pharFullPath, 'w');
while (!gzeof($this->gz)) {
$uncompressed = gzread($this->gz, 131072);
fwrite($writePointer, $uncompressed, strlen($uncompressed));
}
fclose($writePointer);
$equalFiles = $this->filesAreEqual($this->fullPath, $this->pharFullPath);
if ($equalFiles) {
unlink($this->pharFullPath);
$this->pharFullPath = NULL;
return FALSE;
}
try {
$this->phar = new \PharData($this->pharFullPath,
\Phar::CURRENT_AS_FILEINFO |
\Phar::KEY_AS_FILENAME |
\Phar::SKIP_DOTS
);
$pharFiles = new \RecursiveIteratorIterator($this->phar, \RecursiveIteratorIterator::LEAVES_ONLY);
foreach ($pharFiles as $item)
$this->files[] = $item;
$this->index = -1;
} catch (\Exception $e) {
} catch (\Throwable $e) {
}
return TRUE;
}
public function GetError () {
return "Uploaded file is inconsistent GZ archive (`{1}`).";
}
public function GetCompressedSize () {
return $this->spl->getSize();
}
public function Close () {
gzclose($this->gz);
if ($this->phar !== NULL) {
unset($this->phar);
unlink($this->pharFullPath);
@rmdir(dirname($this->pharFullPath));
}
}
public function Move () {
if ($this->phar === NULL) {
if ($this->index === 0) {
$this->index = 1;
return TRUE;
}
return FALSE;
} else {
$this->index++;
if ($this->index < count($this->files))
return TRUE;
return FALSE;
}
}
public function GetEntrySize () {
if ($this->phar === NULL) {
$isize = 0;
$this->spl->rewind();
$this->spl->fseek(-4, SEEK_END);
$isizeBinnary = (string) $this->spl->fread(4);
$isizeUnpacked = unpack("V",$isizeBinnary);
if (isset($isizeUnpacked[1]))
$isize = $isizeUnpacked[1];
return $isize;
} else {
return $this->files[$this->index]->getSize();
}
}
public function GetEntryName () {
if ($this->phar === NULL) {
return basename($this->fullPath);
} else {
$pharItem = $this->files[$this->index];
return $pharItem->getFilename();
}
}
public function ExtractEntry ($destinationFullPath) {
if ($this->phar === NULL) {
return NULL;
} else {
$pharItem = $this->files[$this->index];
$pharEntryFullPath = str_replace('\\', '/', $pharItem->getPathname());
$readPointer = fopen($pharEntryFullPath, 'r');
if (!$readPointer)
return NULL;
$writePointer = fopen($destinationFullPath, 'w');
while (!feof($readPointer))
fwrite($writePointer, fread($readPointer, 131072));
fclose($readPointer);
fclose($writePointer);
return $destinationFullPath;
}
}
protected function filesAreEqual ($a, $b) {
if (filesize($a) !== filesize($b))
return FALSE;
$ah = fopen($a, 'rb');
$bh = fopen($b, 'rb');
$result = true;
while (!feof($ah)) {
if (fread($ah, 131072) != fread($bh, 131072)) {
$result = false;
break;
}
}
fclose($ah);
fclose($bh);
return $result;
}
}