There are some corrupted registry files that have invalid hbin cells
but are still readable. This patch makes the following changes:
* hivex_open - do not abort with complete failure if we run across a
block with invalid size (unless it's the root block). Instead just
log the event, and move on. This will allow open hives that have
apparent invalid blocks but the ones of potential interest might be
perfectly accessible.
* _hivex_get_children - similiarly, if the's invalid subkey, just skip
it instead of failing so one can continue to browse other valid
subkeys.
The above is similar to the behavior to Windows regedit where one can
load such corrupted hives with e.g. "reg load HKU\Corrupted" and
browse/change it despite some keys might be missing.
---
lib/handle.c | 13 +++++++++----
lib/node.c | 11 +++++------
2 files changed, 14 insertions(+), 10 deletions(-)
diff --git a/lib/handle.c b/lib/handle.c
index 1e122ea..9be3b5f 100644
--- a/lib/handle.c
+++ b/lib/handle.c
@@ -300,10 +300,15 @@ hivex_open (const char *filename, int flags)
int used;
seg_len = block_len (h, blkoff, &used);
if (seg_len <= 4 || (seg_len & 3) != 0) {
- SET_ERRNO (ENOTSUP,
- "%s: block size %" PRIi32 " at 0x%zx, bad
registry",
- filename, le32toh (block->seg_len), blkoff);
- goto error;
+ if (is_root) {
+ bad_root_block = 1;
+ } else {
+ DEBUG(2,
+ "%s: block at 0x%zx (page 0x%zx) has invalid size %"
+ PRIi32", skipping\n",
+ filename, blkoff, off, le32toh (block->seg_len));
+ break;
+ }
}
if (h->msglvl >= 2) {
diff --git a/lib/node.c b/lib/node.c
index 822c250..35c0731 100644
--- a/lib/node.c
+++ b/lib/node.c
@@ -343,11 +343,10 @@ _hivex_get_children (hive_h *h, hive_node_h node,
*/
size_t nr_children = _hivex_get_offset_list_length (&children);
if (nr_subkeys_in_nk != nr_children) {
- SET_ERRNO (ENOTSUP,
- "nr_subkeys_in_nk = %zu "
- "is not equal to number of children read %zu",
- nr_subkeys_in_nk, nr_children);
- goto error;
+ DEBUG(2,
+ "nr_subkeys_in_nk = %zu "
+ "is not equal to number of children read %zu",
+ nr_subkeys_in_nk, nr_children);
}
out:
@@ -408,7 +407,7 @@ _get_children (hive_h *h, hive_node_h blkoff,
hive_node_h subkey = le32toh (lf->keys[i].offset);
subkey += 0x1000;
if (check_child_is_nk_block (h, subkey, flags) == -1)
- return -1;
+ continue;
if (_hivex_add_to_offset_list (children, subkey) == -1)
return -1;
}
--
2.9.3