diff --git a/src/file_evtx.c b/src/file_evtx.c index 6f19ad91..ee056c31 100644 --- a/src/file_evtx.c +++ b/src/file_evtx.c @@ -48,6 +48,7 @@ struct evtx_header uint32_t Checksum; } __attribute__ ((gcc_struct, __packed__)); +/*@ requires \valid(file_stat); */ static void register_header_check_evtx(file_stat_t *file_stat); const file_hint_t file_hint_evtx= { @@ -59,6 +60,16 @@ const file_hint_t file_hint_evtx= { .register_header_check=®ister_header_check_evtx }; +/*@ + @ requires buffer_size >= sizeof(struct evtx_header); + @ requires \valid_read(buffer+(0..buffer_size-1)); + @ requires valid_file_recovery(file_recovery); + @ requires \valid(file_recovery_new); + @ requires file_recovery_new->blocksize > 0; + @ requires separation: \separated(&file_hint_evtx, buffer+(..), file_recovery, file_recovery_new); + @ ensures \result!=0 ==> valid_file_recovery(file_recovery_new); + @ assigns *file_recovery_new; + @*/ static int header_check_evtx(const unsigned char *buffer, const unsigned int buffer_size, const unsigned int safe_header_only, const file_recovery_t *file_recovery, file_recovery_t *file_recovery_new) { const struct evtx_header *hdr=(const struct evtx_header *)buffer;