Implement KL4E/KL3E decompression, so firmware modules that use it can load

KL4E is Sony's second compression scheme for ~PSP modules, alongside gzip:
LZ77 tokens where every bit is arithmetic-coded, structurally close to LZMA.
PPSSPP could detect it but not decode it, so any module packed with it failed
to load at all - the loader reached the gzip path and bailed there.

Which scheme a compressed module uses is now decided by the payload's own
magic rather than assuming gzip. On a 6.61 flash0 dump this takes the kd/
modules that load from 126 to 129 of 129; libmp3.prx, libaac.prx and
libmp4.prx were the ones affected, and libmp3.prx decompresses to exactly the
elf_size its PRX header declares.

Two bounds problems in the format are fixed rather than reproduced: the match
copy is unchecked against the output buffer on real hardware, so a crafted
stream can write up to 255 bytes past it, and a long enough distance code
indexes copyDistProbs out of range. Input reads are bounded too - the format
carries no length and trusts the stream to terminate itself.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
This commit is contained in:
Henrik RydgårdandClaude Opus 5 committed 2026-09-07 11:06:17 -06:00
1 parent 0ab672f87f
commit 917cb1b0fc
10 files changed
+500 -13

No files matched your search

+1
View File
@@ -811,6 +811,7 @@ EXEC_AND_LIB_FILES := \
$(SRC)/Core/Util/GameManager.cpp \
$(SRC)/Core/Util/BlockAllocator.cpp \
$(SRC)/Core/Util/PPGeDraw.cpp \
$(SRC)/Core/Util/KL4E.cpp \
$(SRC)/Core/Util/PSARUnpack.cpp \
$(SRC)/Core/Util/RecentFiles.cpp \
$(SRC)/Core/Util/VideoPlayer.cpp \