#ifdef WIN32
dllname = "zlib.dll";
+#elif defined(MACOSX)
+ dllname = "libz.dylib";
#else
dllname = "libz.so";
#endif
remaining -= count;
}
- Mem_Free (central_dir);
+ // If the package is empty, central_dir is NULL here
+ if (central_dir != NULL)
+ Mem_Free (central_dir);
return pack->numfiles;
}
packlist = pack;
real_nb_files = PK3_BuildFileList (pack, &eocd);
- if (real_nb_files <= 0)
+ if (real_nb_files < 0)
Sys_Error ("%s is not a valid PK3 file", packfile);
Con_Printf("Added packfile %s (%i files)\n", packfile, real_nb_files);
Cvar_SetQuick (&scr_screenshot_name, com_modname);
}
}
+
+ // If "-condebug" is in the command line, remove the previous log file
+ if (COM_CheckParm ("-condebug") != 0)
+ unlink (va("%s/qconsole.log", fs_gamedir));
}
return file;
}
+/*
+====================
+FS_CheckNastyPath
+
+Return true if the path should be rejected due to one of the following:
+1: path elements that are non-portable
+2: path elements that would allow access to files outside the game directory,
+ or are just not a good idea for a mod to be using.
+====================
+*/
+int FS_CheckNastyPath (const char *path)
+{
+ // Windows: don't allow \ in filenames (windows-only), period.
+ // (on Windows \ is a directory separator, but / is also supported)
+ if (strstr(path, "\\"))
+ return 1; // non-portable
+ // Mac: don't allow Mac-only filenames - : is a directory separator
+ // instead of /, but we rely on / working already, so there's no reason to
+ // support a Mac-only path
+ // Amiga and Windows: : tries to go to root of drive
+ if (strstr(path, ":"))
+ return 1; // non-portable attempt to go to root of drive
+ // Amiga: // is parent directory
+ if (strstr(path, "//"))
+ return 1; // non-portable attempt to go to parent directory
+ // all: don't allow going to current directory (./) or parent directory (../ or /../)
+ if (strstr(path, "./"))
+ return 2; // attempt to go to parent directory
+ // after all these checks we're pretty sure it's a / separated filename
+ // and won't do much if any harm
+ return false;
+}
+
/*
====================
if (!diff)
{
if (!quiet)
- Sys_Printf("FS_FindFile: %s in %s\n",
+ Con_DPrintf("FS_FindFile: %s in %s\n",
pak->files[middle].name, pak->filename);
if (index != NULL)
if (FS_SysFileExists (netpath))
{
if (!quiet)
- Sys_Printf("FS_FindFile: %s\n", netpath);
+ Con_DPrintf("FS_FindFile: %s\n", netpath);
if (index != NULL)
*index = -1;
}
if (!quiet)
- Sys_Printf("FS_FindFile: can't find %s\n", name);
+ Con_DPrintf("FS_FindFile: can't find %s\n", name);
if (index != NULL)
*index = -1;
*/
qfile_t* FS_Open (const char* filepath, const char* mode, qboolean quiet)
{
+ if (FS_CheckNastyPath(filepath))
+ {
+ Con_Printf("FS_Open(\"%s\", \"%s\", %s): nasty filename rejected\n", filepath, mode, quiet ? "true" : "false");
+ return NULL;
+ }
+
// If the file is opened in "write" or "append" mode
if (strchr (mode, 'w') || strchr (mode, 'a'))
{
if (liststart == NULL)
liststart = listcurrent;
if (!quiet)
- Sys_Printf("SearchPackFile: %s : %s\n", pak->filename, temp);
+ Con_DPrintf("SearchPackFile: %s : %s\n", pak->filename, temp);
}
}
// strip off one path element at a time until empty
if (liststart == NULL)
liststart = listcurrent;
if (!quiet)
- Sys_Printf("SearchDirFile: %s\n", temp);
+ Con_DPrintf("SearchDirFile: %s\n", temp);
}
}
}