-
Notifications
You must be signed in to change notification settings - Fork 559
Expand file tree
/
Copy pathZipUtil.java
More file actions
93 lines (82 loc) · 3.53 KB
/
Copy pathZipUtil.java
File metadata and controls
93 lines (82 loc) · 3.53 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
// Licensed to the Apache Software Foundation (ASF) under one
// or more contributor license agreements. See the NOTICE file
// distributed with this work for additional information
// regarding copyright ownership. The ASF licenses this file
// to you under the Apache License, Version 2.0 (the
// "License"); you may not use this file except in compliance
// with the License. You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing,
// software distributed under the License is distributed on an
// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
// KIND, either express or implied. See the License for the
// specific language governing permissions and limitations
// under the License.
package org.apache.impala.util;
import java.io.File;
import java.io.FileOutputStream;
import java.io.InputStream;
import java.util.Enumeration;
import java.util.zip.ZipEntry;
import java.util.zip.ZipFile;
import org.apache.impala.common.InternalException;
import org.apache.impala.common.ImpalaException;
import org.apache.impala.common.JniUtil;
import org.apache.impala.thrift.TExtractFromZipParams;
import org.apache.thrift.protocol.TBinaryProtocol;
public class ZipUtil {
private final static TBinaryProtocol.Factory protocolFactory_ =
new TBinaryProtocol.Factory();
/**
* Extracts files from a Zip file to a destination directory in the local filesystem.
* Accepts serialized TExtractFromZipParams.
*/
public static void extractFiles(byte[] serializedParams) throws ImpalaException {
TExtractFromZipParams params = new TExtractFromZipParams();
JniUtil.deserializeThrift(protocolFactory_, params, serializedParams);
extractFiles(params.archive_file, params.destination_dir);
}
/**
* Extracts files from 'archiveFilePath' Zip file to 'destDirPath' destination directory
* in the local filesystem.
*/
public static void extractFiles(String archiveFilePath, String destDirPath)
throws ImpalaException {
try (ZipFile zip = new ZipFile(archiveFilePath)) {
File destDir = new File(destDirPath);
String canonicalDestDirPath = destDir.getCanonicalPath();
Enumeration enumEntries = zip.entries();
while (enumEntries.hasMoreElements()) {
ZipEntry entry = (ZipEntry) enumEntries.nextElement();
File destFile = new File(destDir, entry.getName());
// Fix for Zip-Slip vulnerability: Make sure that the destination file's path is
// under params.destination_dir.
String canonicalDestFilePath = destFile.getCanonicalPath();
if (!canonicalDestFilePath.startsWith(canonicalDestDirPath + File.separator)) {
throw new IllegalStateException("Invalid destination path in the archive:" +
canonicalDestFilePath);
}
if (entry.isDirectory()) {
if (!destFile.exists() && !destFile.mkdirs()) {
throw new IllegalStateException("Couldn't create dir: " + destFile);
}
continue;
}
File parent = destFile.getParentFile();
if (parent != null && !parent.exists() && !parent.mkdirs()) {
throw new IllegalStateException("Couldn't create dir: " + parent);
}
try (InputStream is = zip.getInputStream(entry);
FileOutputStream fos = new FileOutputStream(destFile)) {
while (is.available() > 0) {
fos.write(is.read());
}
}
}
} catch (Exception e) {
throw new InternalException(e.getMessage());
}
}
}