Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 10 additions & 3 deletions src/attribute/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -51,9 +51,16 @@ impl MftAttributeContent {
resident: &ResidentHeader,
) -> Result<Self> {
match header.type_code {
MftAttributeType::StandardInformation => Ok(MftAttributeContent::AttrX10(
StandardInfoAttr::from_reader(stream)?,
)),
MftAttributeType::StandardInformation => {
// `$STANDARD_INFORMATION` has multiple on-disk layouts. Its value size (48 vs 72)
// is the discriminator, so read exactly `data_size` and parse based on length.
let content_size = resident.data_size as usize;
let mut buf = vec![0_u8; content_size];
stream.read_exact(&mut buf)?;
Ok(MftAttributeContent::AttrX10(StandardInfoAttr::from_slice(
&buf,
)?))
}
MftAttributeType::AttributeList => {
// An attribute list is a buffer of attribute entries which are varying sizes if
// the attributes contain names. Thus, we must know when to stop reading. To
Expand Down
140 changes: 140 additions & 0 deletions src/attribute/x10.rs
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ use byteorder::{LittleEndian, ReadBytesExt};
use jiff::Timestamp;
use log::trace;
use serde::Serialize;
use std::io::{Cursor, ErrorKind};

#[derive(Serialize, Debug, Clone)]
pub struct StandardInfoAttr {
Expand All @@ -30,6 +31,70 @@ pub struct StandardInfoAttr {
}

impl StandardInfoAttr {
/// Parse a Standard Information attribute buffer whose length is the attribute value size.
///
/// NTFS uses (at least) two layouts:
/// - **48 bytes** (NTFS < 3.0): ends at `class_id`
/// - **72 bytes** (NTFS >= 3.0): includes `owner_id`, `security_id`, `quota`, and `usn`
pub fn from_slice(value: &[u8]) -> Result<StandardInfoAttr> {
if value.len() < 48 {
return Err(std::io::Error::from(ErrorKind::UnexpectedEof).into());
}
if value.len() != 48 && value.len() < 72 {
return Err(std::io::Error::new(
ErrorKind::InvalidData,
format!(
"$STANDARD_INFORMATION has unsupported size {} (expected 48 or >=72)",
value.len()
),
)
.into());
}

let mut reader = Cursor::new(value);

// Timestamps are stored as Windows FILETIME (100ns since 1601-01-01 UTC).
let created =
crate::utils::windows_filetime_to_timestamp(reader.read_u64::<LittleEndian>()?)?;
let modified =
crate::utils::windows_filetime_to_timestamp(reader.read_u64::<LittleEndian>()?)?;
let mft_modified =
crate::utils::windows_filetime_to_timestamp(reader.read_u64::<LittleEndian>()?)?;
let accessed =
crate::utils::windows_filetime_to_timestamp(reader.read_u64::<LittleEndian>()?)?;

let file_flags = FileAttributeFlags::from_bits_truncate(reader.read_u32::<LittleEndian>()?);
let max_version = reader.read_u32::<LittleEndian>()?;
let version = reader.read_u32::<LittleEndian>()?;
let class_id = reader.read_u32::<LittleEndian>()?;

let (owner_id, security_id, quota, usn) = if value.len() >= 72 {
(
reader.read_u32::<LittleEndian>()?,
reader.read_u32::<LittleEndian>()?,
reader.read_u64::<LittleEndian>()?,
reader.read_u64::<LittleEndian>()?,
)
} else {
(0, 0, 0, 0)
};

Ok(StandardInfoAttr {
created,
modified,
mft_modified,
accessed,
file_flags,
max_version,
version,
class_id,
owner_id,
security_id,
quota,
usn,
})
}

/// Parse a Standard Information attrbiute buffer.
///
/// # Example
Expand Down Expand Up @@ -90,3 +155,78 @@ impl StandardInfoAttr {
})
}
}

#[cfg(test)]
mod tests {
use super::StandardInfoAttr;
use crate::attribute::FileAttributeFlags;
use crate::err::Error;

// Test vectors are based on the doc-test buffer above.
const STDINFO_72: &[u8] = &[
0x2F, 0x6D, 0xB6, 0x6F, 0x0C, 0x97, 0xCE, 0x01, 0x56, 0xCD, 0x1A, 0x75, 0x73, 0xB5, 0xCE,
0x01, 0x56, 0xCD, 0x1A, 0x75, 0x73, 0xB5, 0xCE, 0x01, 0x56, 0xCD, 0x1A, 0x75, 0x73, 0xB5,
0xCE, 0x01, 0x20, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xB0, 0x05, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x68, 0x58, 0xA0, 0x0A, 0x02, 0x00, 0x00, 0x00,
];

#[test]
fn from_slice_len_48_treats_extended_fields_as_absent() {
// Spec note: the "base" STANDARD_INFORMATION value layout is 48 bytes; the extended
// layout is 72 bytes. When a value is 48 bytes, the additional fields are not present
// and must not be read from subsequent bytes in the file record.
//
// See: https://flatcap.github.io/linux-ntfs/ntfs/attributes/standard_information.html
let buf48 = &STDINFO_72[..48];
let attr = StandardInfoAttr::from_slice(buf48).unwrap();

assert_eq!(attr.created.as_second(), 1376278290);
assert_eq!(attr.modified.as_second(), 1379621073);
assert_eq!(attr.mft_modified.as_second(), 1379621073);
assert_eq!(attr.accessed.as_second(), 1379621073);
assert_eq!(attr.file_flags, FileAttributeFlags::FILE_ATTRIBUTE_ARCHIVE);
assert_eq!(attr.max_version, 0);
assert_eq!(attr.version, 0);
assert_eq!(attr.class_id, 0);

// Extended fields absent => zero.
assert_eq!(attr.owner_id, 0);
assert_eq!(attr.security_id, 0);
assert_eq!(attr.quota, 0);
assert_eq!(attr.usn, 0);
}

#[test]
fn from_slice_len_72_parses_extended_fields() {
let attr = StandardInfoAttr::from_slice(STDINFO_72).unwrap();

assert_eq!(attr.created.as_second(), 1376278290);
assert_eq!(attr.modified.as_second(), 1379621073);
assert_eq!(attr.mft_modified.as_second(), 1379621073);
assert_eq!(attr.accessed.as_second(), 1379621073);
assert_eq!(attr.file_flags.bits(), 32);
assert_eq!(attr.max_version, 0);
assert_eq!(attr.version, 0);
assert_eq!(attr.class_id, 0);
assert_eq!(attr.security_id, 1456);
assert_eq!(attr.quota, 0);
assert_eq!(attr.usn, 8768215144);
}

#[test]
fn from_slice_rejects_intermediate_sizes() {
let buf60 = [0u8; 60];
let err = StandardInfoAttr::from_slice(&buf60).unwrap_err();
match err {
Error::IoError { source } => {
assert_eq!(source.kind(), std::io::ErrorKind::InvalidData);
assert!(
source.to_string().contains("unsupported size"),
"unexpected io error message for len=60: {source}"
);
}
other => panic!("unexpected error kind for len=60: {other:?}"),
}
}
}
45 changes: 45 additions & 0 deletions tests/test_standard_information.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
mod fixtures;

use fixtures::*;

use mft::attribute::MftAttributeType;
use mft::attribute::header::ResidentialHeader;
use mft::mft::MftParser;

/// Regression test for a subtle parsing bug:
///
/// `$STANDARD_INFORMATION` can be **48 bytes** (base layout) or **72 bytes** (extended layout).
/// Older code parsed it by reading a fixed 72-byte layout from the entry cursor, which meant that
/// for 48-byte values it would read 24 bytes from the *next attribute record header* and interpret
/// them as `owner_id/security_id/quota/usn` garbage.
#[test]
fn standard_information_len_48_does_not_leak_next_attribute_header_bytes() {
// The sample MFT contains at least one entry where `$STANDARD_INFORMATION` is 48 bytes.
// (In practice, the root directory entry 5 is one such case.)
let sample = mft_sample();
let mut parser = MftParser::from_path(sample).unwrap();

let entry = parser.get_entry(5).unwrap();
let attr = entry
.iter_attributes_matching(Some(vec![MftAttributeType::StandardInformation]))
.filter_map(Result::ok)
.next()
.expect("expected $STANDARD_INFORMATION");

let data_size = match &attr.header.residential_header {
ResidentialHeader::Resident(r) => r.data_size,
ResidentialHeader::NonResident(_) => panic!("$STANDARD_INFORMATION must be resident"),
};
assert_eq!(data_size, 48, "fixture should exercise the 48-byte layout");

let si = attr
.data
.into_standard_info()
.expect("expected parsed standard info");

// Extended fields are absent in the 48-byte layout => should be zero.
assert_eq!(si.owner_id, 0);
assert_eq!(si.security_id, 0);
assert_eq!(si.quota, 0);
assert_eq!(si.usn, 0);
}