INNER CODE UNIT · Python

safe_member

KSwordDEV/KSword · GhidraRuntimePlugin/package.py:33

def safe_member(name: str, expected_root: str) -> PurePosixPath:
    if '\\' in name or '\x00' in name:
        raise ValueError('unsafe ZIP separator or NUL')
    parts = name.rstrip('/').split('/')
    if not parts or parts[0] != expected_root:
        raise ValueError('ZIP root does not match pinned upstream root')
    for part in parts:
        if not part or part in ('.', '..') or part.endswith((' ', '.')):
            raise ValueError('unsafe ZIP path component')
        if any(character in part for character in ':<>"|?*'):
            raise ValueError('invalid Windows ZIP path')
        if part.split('.')[0].casefold() in DEVICES:
            raise ValueError('reserved Windows device in ZIP')
    return PurePosixPath(*parts)


def inspect_archive(path: Path, profile: dict) -> dict:
    if not path.is_file() or path.stat().st_size > profile['max_archive_bytes']:

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…