1 from __future__ import unicode_literals
14 def _extract_tags(file_contents):
15 if file_contents[1:3] != b'WS':
17 'Not an SWF file; header is %r' % file_contents[:3])
18 if file_contents[:1] == b'C':
19 content = zlib.decompress(file_contents[8:])
21 raise NotImplementedError(
22 'Unsupported compression format %r' %
25 # Determine number of bits in framesize rectangle
26 framesize_nbits = struct_unpack('!B', content[:1])[0] >> 3
27 framesize_len = (5 + 4 * framesize_nbits + 7) // 8
29 pos = framesize_len + 2 + 2
30 while pos < len(content):
31 header16 = struct_unpack('<H', content[pos:pos + 2])[0]
33 tag_code = header16 >> 6
34 tag_len = header16 & 0x3f
36 tag_len = struct_unpack('<I', content[pos:pos + 4])[0]
38 assert pos + tag_len <= len(content), \
39 ('Tag %d ends at %d+%d - that\'s longer than the file (%d)'
40 % (tag_code, pos, tag_len, len(content)))
41 yield (tag_code, content[pos:pos + tag_len])
45 class _AVMClass_Object(object):
46 def __init__(self, avm_class):
47 self.avm_class = avm_class
50 return '%s#%x' % (self.avm_class.name, id(self))
53 class _ScopeDict(dict):
54 def __init__(self, avm_class):
55 super(_ScopeDict, self).__init__()
56 self.avm_class = avm_class
59 return '%s__Scope(%s)' % (
61 super(_ScopeDict, self).__repr__())
64 class _AVMClass(object):
65 def __init__(self, name_idx, name):
66 self.name_idx = name_idx
68 self.method_names = {}
71 self.method_pyfunctions = {}
73 self.variables = _ScopeDict(self)
75 def make_object(self):
76 return _AVMClass_Object(self)
79 return '_AVMClass(%s)' % (self.name)
81 def register_methods(self, methods):
82 self.method_names.update(methods.items())
83 self.method_idxs.update(dict(
85 for name, idx in methods.items()))
88 class _Multiname(object):
89 def __init__(self, kind):
93 return '[MULTINAME kind: 0x%x]' % self.kind
96 def _read_int(reader):
102 b = struct_unpack('<B', buf)[0]
103 res = res | ((b & 0x7f) << shift)
111 res = _read_int(reader)
112 assert res & 0xf0000000 == 0
118 v = _read_int(reader)
119 if v & 0x80000000 != 0:
120 v = - ((v ^ 0xffffffff) + 1)
127 last_byte = b'\xff' if (ord(bs[2:3]) >= 0x80) else b'\x00'
128 return struct_unpack('<i', bs + last_byte)[0]
131 def _read_string(reader):
133 resb = reader.read(slen)
134 assert len(resb) == slen
135 return resb.decode('utf-8')
138 def _read_bytes(count, reader):
140 resb = reader.read(count)
141 assert len(resb) == count
145 def _read_byte(reader):
146 resb = _read_bytes(1, reader=reader)
147 res = struct_unpack('<B', resb)[0]
151 StringClass = _AVMClass('(no name idx)', 'String')
154 class _Undefined(object):
155 def __boolean__(self):
161 undefined = _Undefined()
164 class SWFInterpreter(object):
165 def __init__(self, file_contents):
166 self._patched_functions = {}
168 for tag_code, tag in _extract_tags(file_contents)
170 p = code_tag.index(b'\0', 4) + 1
171 code_reader = io.BytesIO(code_tag[p:])
173 # Parse ABC (AVM2 ByteCode)
175 # Define a couple convenience methods
176 u30 = lambda *args: _u30(*args, reader=code_reader)
177 s32 = lambda *args: _s32(*args, reader=code_reader)
178 u32 = lambda *args: _u32(*args, reader=code_reader)
179 read_bytes = lambda *args: _read_bytes(*args, reader=code_reader)
180 read_byte = lambda *args: _read_byte(*args, reader=code_reader)
182 # minor_version + major_version
187 for _c in range(1, int_count):
190 for _c in range(1, uint_count):
193 read_bytes(max(0, (double_count - 1)) * 8)
195 self.constant_strings = ['']
196 for _c in range(1, string_count):
197 s = _read_string(code_reader)
198 self.constant_strings.append(s)
199 namespace_count = u30()
200 for _c in range(1, namespace_count):
204 for _c in range(1, ns_set_count):
206 for _c2 in range(count):
208 multiname_count = u30()
217 0x0e: 2, # MultinameA
218 0x1b: 1, # MultinameL
219 0x1c: 1, # MultinameLA
221 self.multinames = ['']
222 for _c in range(1, multiname_count):
224 assert kind in MULTINAME_SIZES, 'Invalid multiname kind %r' % kind
226 u30() # namespace_idx
228 self.multinames.append(self.constant_strings[name_idx])
232 self.multinames.append(self.constant_strings[name_idx])
234 self.multinames.append(_Multiname(kind))
235 for _c2 in range(MULTINAME_SIZES[kind]):
240 MethodInfo = collections.namedtuple(
242 ['NEED_ARGUMENTS', 'NEED_REST'])
244 for method_id in range(method_count):
247 for _ in range(param_count):
249 u30() # name index (always 0 for youtube)
251 if flags & 0x08 != 0:
254 for c in range(option_count):
257 if flags & 0x80 != 0:
258 # Param names present
259 for _ in range(param_count):
261 mi = MethodInfo(flags & 0x01 != 0, flags & 0x04 != 0)
262 method_infos.append(mi)
265 metadata_count = u30()
266 for _c in range(metadata_count):
269 for _c2 in range(item_count):
273 def parse_traits_info():
274 trait_name_idx = u30()
275 kind_full = read_byte()
276 kind = kind_full & 0x0f
277 attrs = kind_full >> 4
279 if kind in [0x00, 0x06]: # Slot or Const
281 u30() # type_name_idx
285 elif kind in [0x01, 0x02, 0x03]: # Method / Getter / Setter
288 methods[self.multinames[trait_name_idx]] = method_idx
289 elif kind == 0x04: # Class
292 elif kind == 0x05: # Function
295 methods[function_idx] = self.multinames[trait_name_idx]
297 raise ExtractorError('Unsupported trait kind %d' % kind)
299 if attrs & 0x4 != 0: # Metadata present
300 metadata_count = u30()
301 for _c3 in range(metadata_count):
302 u30() # metadata index
309 for class_id in range(class_count):
312 cname = self.multinames[name_idx]
313 avm_class = _AVMClass(name_idx, cname)
314 classes.append(avm_class)
316 u30() # super_name idx
318 if flags & 0x08 != 0: # Protected namespace is present
319 u30() # protected_ns_idx
321 for _c2 in range(intrf_count):
325 for _c2 in range(trait_count):
326 trait_methods = parse_traits_info()
327 avm_class.register_methods(trait_methods)
329 assert len(classes) == class_count
330 self._classes_by_name = dict((c.name, c) for c in classes)
332 for avm_class in classes:
335 for _c2 in range(trait_count):
336 trait_methods = parse_traits_info()
337 avm_class.register_methods(trait_methods)
341 for _c in range(script_count):
344 for _c2 in range(trait_count):
348 method_body_count = u30()
349 Method = collections.namedtuple('Method', ['code', 'local_count'])
350 for _c in range(method_body_count):
354 u30() # init_scope_depth
355 u30() # max_scope_depth
357 code = read_bytes(code_length)
358 for avm_class in classes:
359 if method_idx in avm_class.method_idxs:
360 m = Method(code, local_count)
361 avm_class.methods[avm_class.method_idxs[method_idx]] = m
362 exception_count = u30()
363 for _c2 in range(exception_count):
370 for _c2 in range(trait_count):
373 assert p + code_reader.tell() == len(code_tag)
375 def patch_function(self, avm_class, func_name, f):
376 self._patched_functions[(avm_class, func_name)] = f
378 def extract_class(self, class_name):
380 return self._classes_by_name[class_name]
382 raise ExtractorError('Class %r not found' % class_name)
384 def extract_function(self, avm_class, func_name):
385 p = self._patched_functions.get((avm_class, func_name))
388 if func_name in avm_class.method_pyfunctions:
389 return avm_class.method_pyfunctions[func_name]
390 if func_name in self._classes_by_name:
391 return self._classes_by_name[func_name].make_object()
392 if func_name not in avm_class.methods:
393 raise ExtractorError('Cannot find function %s.%s' % (
394 avm_class.name, func_name))
395 m = avm_class.methods[func_name]
399 coder = io.BytesIO(m.code)
400 s24 = lambda: _s24(coder)
401 u30 = lambda: _u30(coder)
403 registers = [avm_class.variables] + list(args) + [None] * m.local_count
405 scopes = collections.deque([
406 self._classes_by_name, avm_class.variables])
408 opcode = _read_byte(coder)
409 if opcode == 16: # jump
411 coder.seek(coder.tell() + offset)
412 elif opcode == 17: # iftrue
416 coder.seek(coder.tell() + offset)
417 elif opcode == 18: # iffalse
421 coder.seek(coder.tell() + offset)
422 elif opcode == 19: # ifeq
427 coder.seek(coder.tell() + offset)
428 elif opcode == 20: # ifne
433 coder.seek(coder.tell() + offset)
434 elif opcode == 32: # pushnull
436 elif opcode == 33: # pushundefined
437 stack.append(undefined)
438 elif opcode == 36: # pushbyte
439 v = _read_byte(coder)
441 elif opcode == 38: # pushtrue
443 elif opcode == 39: # pushfalse
445 elif opcode == 40: # pushnan
446 stack.append(float('NaN'))
447 elif opcode == 42: # dup
450 elif opcode == 44: # pushstring
452 stack.append(self.constant_strings[idx])
453 elif opcode == 48: # pushscope
454 new_scope = stack.pop()
455 scopes.append(new_scope)
456 elif opcode == 66: # construct
458 args = list(reversed(
459 [stack.pop() for _ in range(arg_count)]))
461 res = obj.avm_class.make_object()
463 elif opcode == 70: # callproperty
465 mname = self.multinames[index]
467 args = list(reversed(
468 [stack.pop() for _ in range(arg_count)]))
471 if isinstance(obj, _AVMClass_Object):
472 func = self.extract_function(obj.avm_class, mname)
476 elif isinstance(obj, _ScopeDict):
477 if mname in obj.avm_class.method_names:
478 func = self.extract_function(obj.avm_class, mname)
484 elif isinstance(obj, compat_str):
486 assert len(args) == 1
487 assert isinstance(args[0], compat_str)
491 res = obj.split(args[0])
494 elif isinstance(obj, list):
496 assert len(args) == 1
497 assert isinstance(args[0], int)
501 elif mname == 'join':
502 assert len(args) == 1
503 assert isinstance(args[0], compat_str)
504 res = args[0].join(obj)
507 elif obj == StringClass:
508 if mname == 'String':
509 assert len(args) == 1
510 assert isinstance(args[0], (
511 int, compat_str, _Undefined))
512 if args[0] == undefined:
515 res = compat_str(args[0])
519 raise NotImplementedError(
520 'Function String.%s is not yet implemented'
522 raise NotImplementedError(
523 'Unsupported property %r on %r'
525 elif opcode == 71: # returnvoid
528 elif opcode == 72: # returnvalue
531 elif opcode == 74: # constructproperty
534 args = list(reversed(
535 [stack.pop() for _ in range(arg_count)]))
538 mname = self.multinames[index]
539 assert isinstance(obj, _AVMClass)
541 # We do not actually call the constructor for now;
542 # we just pretend it does nothing
543 stack.append(obj.make_object())
544 elif opcode == 79: # callpropvoid
546 mname = self.multinames[index]
548 args = list(reversed(
549 [stack.pop() for _ in range(arg_count)]))
551 if isinstance(obj, _AVMClass_Object):
552 func = self.extract_function(obj.avm_class, mname)
554 assert res is undefined
556 if isinstance(obj, _ScopeDict):
557 assert mname in obj.avm_class.method_names
558 func = self.extract_function(obj.avm_class, mname)
560 assert res is undefined
562 if mname == 'reverse':
563 assert isinstance(obj, list)
566 raise NotImplementedError(
567 'Unsupported (void) property %r on %r'
569 elif opcode == 86: # newarray
572 for i in range(arg_count):
573 arr.append(stack.pop())
576 elif opcode == 93: # findpropstrict
578 mname = self.multinames[index]
579 for s in reversed(scopes):
585 if mname not in res and mname == 'String':
586 stack.append(StringClass)
588 stack.append(res[mname])
589 elif opcode == 94: # findproperty
591 mname = self.multinames[index]
592 for s in reversed(scopes):
597 res = avm_class.variables
599 elif opcode == 96: # getlex
601 mname = self.multinames[index]
602 for s in reversed(scopes):
607 scope = avm_class.variables
608 # I cannot find where static variables are initialized
609 # so let's just return None
610 res = scope.get(mname)
612 elif opcode == 97: # setproperty
615 idx = self.multinames[index]
616 if isinstance(idx, _Multiname):
620 elif opcode == 98: # getlocal
622 stack.append(registers[index])
623 elif opcode == 99: # setlocal
626 registers[index] = value
627 elif opcode == 102: # getproperty
629 pname = self.multinames[index]
630 if pname == 'length':
632 assert isinstance(obj, (compat_str, list))
633 stack.append(len(obj))
634 elif isinstance(pname, compat_str): # Member access
636 assert isinstance(obj, (dict, _ScopeDict)), \
637 'Accessing member %r on %r' % (pname, obj)
638 res = obj.get(pname, undefined)
640 else: # Assume attribute access
642 assert isinstance(idx, int)
644 assert isinstance(obj, list)
645 stack.append(obj[idx])
646 elif opcode == 115: # convert_
648 intvalue = int(value)
649 stack.append(intvalue)
650 elif opcode == 128: # coerce
652 elif opcode == 130: # coerce_a
654 # um, yes, it's any value
656 elif opcode == 133: # coerce_s
657 assert isinstance(stack[-1], (type(None), compat_str))
658 elif opcode == 147: # decrement
660 assert isinstance(value, int)
661 stack.append(value - 1)
662 elif opcode == 149: # typeof
665 _Undefined: 'undefined',
666 compat_str: 'String',
670 elif opcode == 160: # add
673 res = value1 + value2
675 elif opcode == 161: # subtract
678 res = value1 - value2
680 elif opcode == 164: # modulo
683 res = value1 % value2
685 elif opcode == 171: # equals
688 result = value1 == value2
690 elif opcode == 175: # greaterequals
693 result = value1 >= value2
695 elif opcode == 208: # getlocal_0
696 stack.append(registers[0])
697 elif opcode == 209: # getlocal_1
698 stack.append(registers[1])
699 elif opcode == 210: # getlocal_2
700 stack.append(registers[2])
701 elif opcode == 211: # getlocal_3
702 stack.append(registers[3])
703 elif opcode == 212: # setlocal_0
704 registers[0] = stack.pop()
705 elif opcode == 213: # setlocal_1
706 registers[1] = stack.pop()
707 elif opcode == 214: # setlocal_2
708 registers[2] = stack.pop()
709 elif opcode == 215: # setlocal_3
710 registers[3] = stack.pop()
712 raise NotImplementedError(
713 'Unsupported opcode %d' % opcode)
715 avm_class.method_pyfunctions[func_name] = resfunc