mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-09-03 11:15:20 +02:00
The "is this an ELF rather than a PBP" test compared against "\nFLE", which is neither ELF's magic (\x7fELF) nor anything else - most likely a \x7f escape that swallowed the E when it was written in 2013. Since no real file matches it, every file that wasn't a PBP was reported as an ELF and the error branch was unreachable. Compares against the real magic now, so something that's neither is reported as neither. That error also printed the 4-byte magic with %s, which isn't NUL-terminated - it's four hex bytes instead. GetSubFileSize subtracted offsets that come straight out of the file without checking they're ordered or even inside it, so a corrupt PBP produced a size from an unsigned underflow - nearly 4GB, which the callers then had to catch by size limit. It returns 0 for anything that doesn't make sense. Also &(*out)[0] on a zero-length subfile, which is UB on an empty vector. Plus one in ParamSFO: GetDataOffset mixed int and u32 for the data offset, so its bounds check ran in whichever type the promotion landed on. It's size_t throughout now, matching how ReadSFO does the same arithmetic. Booted an EBOOT.PBP to check the PBP path end to end - loads, and generates the same fake disc ID as before. pspautotests 314/314, UnitTest 55/55. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GZq8ZtJmFY7bkX5FVkr3P9