From nobody Tue Sep 22 15:57:54 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) client-ip=38.145.34.151; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=reject dis=none) header.from=lists.libvirt.org ARC-Seal: i=1; a=rsa-sha256; t=1785879443; cv=none; d=zohomail.com; s=zohoarc; b=g/9zEvKpJmGdj6fyEC1zCgJnmCw4XtkFylZVCAKZ4vv7AMoF9UWZgTgjuXiL1zZS6zf+/wXV2stqBgMiwC09mRpwNaOFTKS/48Q9E0+pnCOJW6sxNakD5dg6b5Uqy4mM0q6vdF2DBLN4P00tA8jEF/h2qhhD+wnxQkRy4NsryT4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785879443; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:References:Subject:Subject:To:To:Message-Id:Cc; bh=T1pqnjEBxrKA2z7shKwyhFJhmoHlmjfUCVuj41m4w1c=; b=ezmtHiybIWhVBbXhlcuRnrc9yd3q6/eTqLYwK7A3p40BZyeDql2asJR3cMQg2eXht1OuisIvqexdn9zl81a62yRvupkWAK2FUPz9u/G+n62MvcpnXM+AGdXGbJYwF9F+XK1MCjbCriJWgVLR7VUsknA6VVc3O9n8MMGIG3n/SiY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [38.145.34.151]) by mx.zohomail.com with SMTPS id 1785879443734539.8024911654771; Tue, 4 Aug 2026 14:37:23 -0700 (PDT) Received: by lists.libvirt.org (Postfix, from userid 993) id 7202241862; Tue, 4 Aug 2026 17:37:22 -0400 (EDT) Received: from [172.19.199.10] (unknown [10.16.107.18]) by lists.libvirt.org (Postfix) with ESMTP id E725A41BB9; Tue, 4 Aug 2026 17:35:05 -0400 (EDT) Received: by lists.libvirt.org (Postfix, from userid 993) id 3527840473; Tue, 4 Aug 2026 17:34:54 -0400 (EDT) Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits) server-digest SHA256) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id 64AF63FB05 for ; Tue, 4 Aug 2026 17:34:53 -0400 (EDT) Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-552-gkKGVTQsM0m1dQBxlSEP0Q-1; Tue, 04 Aug 2026 17:34:51 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B0C9A1956069 for ; Tue, 4 Aug 2026 21:34:50 +0000 (UTC) Received: from speedmetal.openshiftapps.com (unknown [10.44.22.5]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0BA1F1956087 for ; Tue, 4 Aug 2026 21:34:49 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=0.6 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL,RCVD_IN_SBL_CSS,SPF_HELO_PASS autolearn=no autolearn_force=no version=4.0.1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785879293; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=T1pqnjEBxrKA2z7shKwyhFJhmoHlmjfUCVuj41m4w1c=; b=Pl6C6Wmalt8EGstwHU0jaHhjDCJaZ6xqDxuWA088SXRicAwFY81wd+FKL4iQWrr7tf7x9Z cbzavBinLvjW34iST9/m6s893UxsMN/sXONJXWyo12dBqjtbhk32D7c6YIAvST6ubftOT7 aA7NTzqJHEqGHXq0FozNFIBeIrqmjZQ= X-MC-Unique: gkKGVTQsM0m1dQBxlSEP0Q-1 X-Mimecast-MFC-AGG-ID: gkKGVTQsM0m1dQBxlSEP0Q_1785879290 To: devel@lists.libvirt.org Subject: [PATCH 2/2] virStorageSourceGetMetadataRecurse: Fix format probing exception for images with 'data_file' Date: Tue, 4 Aug 2026 23:34:45 +0200 Message-ID: <28ca1148ffbd0f9aa08f065b051fe40a2f6b21c8.1785879137.git.pkrempa@redhat.com> In-Reply-To: References: MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: PKApdsWXITKaK5vCrBfVbOQk0nvHveFaRHKeU2B8Wnk_1785879290 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: quoted-printable Message-ID-Hash: AASCWWPGOXFZM473KSKMUQ27P6U5O6QL X-Message-ID-Hash: AASCWWPGOXFZM473KSKMUQ27P6U5O6QL X-MailFrom: pkrempa@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: Peter Krempa via Devel Reply-To: Peter Krempa X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZM-MESSAGEID: 1785879444995158500 Content-Type: text/plain; charset="utf-8" From: Peter Krempa The image metadata crawler code generally forbids qcow2 images which have a 'backing_file' but don't specify a 'backing_file_fmt' header as we don't want to probe the format due to security implications. There's one notable exception for the last image in the chain which can be format probed if it doesn't have another 'backing_file'. As the comment in 'virStorageSourceGetMetadataRecurse' suggests we don't want to allow the probe if anything probed would influence access to more resources. Unfortunately that didn't involve 'data_file' header which gives more access. Fortunately there is no way for a guest OS having a 'raw' disk and access to libvirt's snapshot API to abuse this as libvirt's snapshot API does specify the header. Other cases where an arbitrary image is passed to libvirt can 'backing_file'+'backing_file_fmt' directly to access arbitrary file on disk so this bug is no worse in this regard. Nevertheless it's a bug which should be fixed. Closes: https://gitlab.com/libvirt/libvirt/-/work_items/904 Fixes: 0a3d177d9bd6cc608cc8e5769188e5f45f70ee62 Signed-off-by: Peter Krempa --- src/storage_file/storage_source.c | 3 +- tests/virstoragetest.c | 2 +- .../qcow2datafile-qcow2_qcow2-datafile-auto | 31 ------------------- 3 files changed, 3 insertions(+), 33 deletions(-) delete mode 100644 tests/virstoragetestdata/out/qcow2datafile-qcow2_qcow2-= datafile-auto diff --git a/src/storage_file/storage_source.c b/src/storage_file/storage_s= ource.c index e886433bb4..aa7e834819 100644 --- a/src/storage_file/storage_source.c +++ b/src/storage_file/storage_source.c @@ -1426,9 +1426,10 @@ virStorageSourceGetMetadataRecurse(virStorageSource = *src, /* If we probed the format we MUST ensure that nothing else than the c= urrent * image is considered for security labelling and/or recursion. */ if (orig_format =3D=3D VIR_STORAGE_FILE_AUTO) { - if (src->backingStoreRaw) { + if (src->backingStoreRaw || src->dataFileRaw) { src->format =3D VIR_STORAGE_FILE_RAW; VIR_FREE(src->backingStoreRaw); + VIR_FREE(src->dataFileRaw); return -2; } } diff --git a/tests/virstoragetest.c b/tests/virstoragetest.c index 1514991c20..4c9272150c 100644 --- a/tests/virstoragetest.c +++ b/tests/virstoragetest.c @@ -499,7 +499,7 @@ mymain(void) VIR_STORAGE_FILE_QCOW2, EXP_PASS); TEST_CHAIN("qcow2datafile-qcow2_qcow2-datafile-auto", abs_srcdir "/virstoragetestdata/images/qcow2_datafile-auto.= qcow2", - VIR_STORAGE_FILE_QCOW2, EXP_PASS); + VIR_STORAGE_FILE_QCOW2, EXP_FAIL); /* broken qcow2 with a 'data_file' which is an empty string */ TEST_CHAIN("qcow2-datafile-broken", diff --git a/tests/virstoragetestdata/out/qcow2datafile-qcow2_qcow2-datafil= e-auto b/tests/virstoragetestdata/out/qcow2datafile-qcow2_qcow2-datafile-au= to deleted file mode 100644 index 421e0c8d5a..0000000000 --- a/tests/virstoragetestdata/out/qcow2datafile-qcow2_qcow2-datafile-auto +++ /dev/null @@ -1,31 +0,0 @@ -path:ABS_SRCDIR/virstoragetestdata/images/qcow2_datafile-auto.qcow2 -backingStoreRaw: datafile.qcow2 -backingStoreRawFormat: (-1) -dataFileRaw: -capacity: 1024 -encryption: 0 -relPath: -type:file -format:qcow2 -protocol:none -hostname: - -path:ABS_SRCDIR/virstoragetestdata/images/datafile.qcow2 -backingStoreRaw: -backingStoreRawFormat: none(0) -dataFileRaw: raw -capacity: 1024 -encryption: 0 -relPath:datafile.qcow2 -type:file -format:qcow2 -protocol:none -hostname: - - dataFileStoreSource for 'ABS_SRCDIR/virstoragetestdata/images/datafile.qc= ow2': - path: ABS_SRCDIR/virstoragetestdata/images/raw - capacity: 0 - encryption: 0 - type:file - format:raw - --=20 2.55.0