msooxml revision 360521
1
2#------------------------------------------------------------------------------
3# $File: msooxml,v 1.13 2019/11/27 13:12:55 christos Exp $
4# msooxml:  file(1) magic for Microsoft Office XML
5# From: Ralf Brown <ralf.brown@gmail.com>
6
7# .docx, .pptx, and .xlsx are XML plus other files inside a ZIP
8#   archive.  The first member file is normally "[Content_Types].xml".
9#   but some libreoffice generated files put this later. Perhaps skip
10#   the "[Content_Types].xml" test?
11# Since MSOOXML doesn't have anything like the uncompressed "mimetype"
12#   file of ePub or OpenDocument, we'll have to scan for a filename
13#   which can distinguish between the three types
14
150		name		msooxml
16>0		string		word/		Microsoft Word 2007+
17!:mime application/vnd.openxmlformats-officedocument.wordprocessingml.document
18>0		string		ppt/		Microsoft PowerPoint 2007+
19!:mime application/vnd.openxmlformats-officedocument.presentationml.presentation
20>0		string		xl/		Microsoft Excel 2007+
21!:mime application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
220		string		visio/		Microsoft Visio 2013+
23!:mime application/vnd.ms-visio.drawing.main+xml
24
25# start by checking for ZIP local file header signature
260		string		PK\003\004
27!:strength +10
28# make sure the first file is correct
29>0x1E		use		msooxml
30>0x1E		regex		\\[Content_Types\\]\\.xml|_rels/\\.rels|docProps
31# skip to the second local file header
32# since some documents include a 520-byte extra field following the file
33# header, we need to scan for the next header
34>>(18.l+49)	search/6000	PK\003\004
35# now skip to the *third* local file header; again, we need to scan due to a
36# 520-byte extra field following the file header
37>>>&26		search/6000	PK\003\004
38# and check the subdirectory name to determine which type of OOXML
39# file we have.  Correct the mimetype with the registered ones:
40# https://technet.microsoft.com/en-us/library/cc179224.aspx
41>>>>&26		use		msooxml	
42>>>>&26		default		x
43# OpenOffice/Libreoffice orders ZIP entry differently, so check the 4th file
44>>>>>&26	search/6000	PK\003\004
45>>>>>>&26	use		msooxml	
46>>>>>>&26	default		x		Microsoft OOXML
47>>>>>&26	default		x		Microsoft OOXML
48