From nobody Mon Feb 9 18:45:52 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=fail(p=none dis=none) header.from=oracle.com ARC-Seal: i=1; a=rsa-sha256; t=1589377225; cv=none; d=zohomail.com; s=zohoarc; b=iIyQbcSrZwCUaFdAIInMFaethaBXQXUICJjLA3q5MJ2QtLh+f6zbQXh9/jOp43619n1Pb7dGMJ1CJoaoC6twZMelPOz2N1SjAePi+Ee7ACPVdE2KOOadUhjEgdzs95y4GNH7upqNP4J6sBCgGfz14x3Woe73HFPEQiRHnhFKBWM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1589377225; h=Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject; bh=7uYVCNJ3IcRaqaueO/mQf4X8aaj6MOJoym/nvcg420A=; b=jcAP1uN7jvTY0+m+JPsO+8xVMn36Sqpj2EsF8+zztsB6o6odbszX5nMBR1KarHl2WgwoyvdfI2HBv/2B4DZYEwWc48MGoyxiPG1E4w7rjsrBBTnHAPETYqy03rMPRAMKB33ynY2ytUSOsFFHz4R05kNBnfv+9+8rWv0w+ygcKH4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=fail header.from= (p=none dis=none) header.from= Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1589377225184511.34535973027585; Wed, 13 May 2020 06:40:25 -0700 (PDT) Received: from localhost ([::1]:52880 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1jYrcV-0002kp-VC for importer@patchew.org; Wed, 13 May 2020 09:40:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:48258) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1jYrb1-0000l2-Q3; Wed, 13 May 2020 09:38:51 -0400 Received: from userp2130.oracle.com ([156.151.31.86]:38744) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1jYrb0-0005CL-TL; Wed, 13 May 2020 09:38:51 -0400 Received: from pps.filterd (userp2130.oracle.com [127.0.0.1]) by userp2130.oracle.com (8.16.0.42/8.16.0.42) with SMTP id 04DDWVp3163828; Wed, 13 May 2020 13:38:49 GMT Received: from aserp3030.oracle.com (aserp3030.oracle.com [141.146.126.71]) by userp2130.oracle.com with ESMTP id 3100yfv7fe-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=FAIL); Wed, 13 May 2020 13:38:49 +0000 Received: from pps.filterd (aserp3030.oracle.com [127.0.0.1]) by aserp3030.oracle.com (8.16.0.42/8.16.0.42) with SMTP id 04DDXuWb102343; Wed, 13 May 2020 13:36:48 GMT Received: from userv0122.oracle.com (userv0122.oracle.com [156.151.31.75]) by aserp3030.oracle.com with ESMTP id 3100yajc0w-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 13 May 2020 13:36:48 +0000 Received: from abhmp0002.oracle.com (abhmp0002.oracle.com [141.146.116.8]) by userv0122.oracle.com (8.14.4/8.14.4) with ESMTP id 04DDalVk015393; Wed, 13 May 2020 13:36:47 GMT Received: from localhost.localdomain (/10.74.123.68) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Wed, 13 May 2020 06:36:46 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=from : to : cc : subject : date : message-id : in-reply-to : references; s=corp-2020-01-29; bh=7uYVCNJ3IcRaqaueO/mQf4X8aaj6MOJoym/nvcg420A=; b=rnyQSZtNTdIuoWoFpyNQ9gLfAckEWix+QazyRz2u02uhbnZcZ9E10N+x/4D5Ieg4+/SD AI3eawt0C4kkH7s/LAPi3Fo7gEeuuzH1eQNwgt1K6FryCfmLd6EdCYEsZF0hTxFmJWjg 3CjDRvDtv+Idye1bjALEpFvuvJ5fFd5S54Xtr6Dp2ONya/PUvQwWkz3De8eK3pPh7/W/ qLmYBCPkWdh6P89oDjQI6yJ6likwznhP4E4Z+VEJfR7Hpk7DQacD0gK7TB0TwuHJ6eMS 3YIgarAFnoEZpLZtDQSP5lky2dT2gzbkbm5a8vHtXtN2HF4seelvNwyGKTA6cQEIScTO Iw== From: Eyal Moscovici To: Subject: [PATCH v3 2/4] qemu-img: validate image length in img_map Date: Wed, 13 May 2020 16:36:27 +0300 Message-Id: <20200513133629.18508-3-eyal.moscovici@oracle.com> X-Mailer: git-send-email 2.17.2 (Apple Git-113) In-Reply-To: <20200513133629.18508-1-eyal.moscovici@oracle.com> References: <20200513133629.18508-1-eyal.moscovici@oracle.com> X-Proofpoint-Virus-Version: vendor=nai engine=6000 definitions=9619 signatures=668687 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 bulkscore=0 malwarescore=0 phishscore=0 adultscore=0 suspectscore=0 mlxscore=0 mlxlogscore=999 spamscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2004280000 definitions=main-2005130121 X-Proofpoint-Virus-Version: vendor=nai engine=6000 definitions=9619 signatures=668687 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 lowpriorityscore=0 adultscore=0 cotscore=-2147483648 mlxscore=0 suspectscore=0 spamscore=0 impostorscore=0 mlxlogscore=999 malwarescore=0 clxscore=1015 phishscore=0 bulkscore=0 priorityscore=1501 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2004280000 definitions=main-2005130121 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=156.151.31.86; envelope-from=eyal.moscovici@oracle.com; helo=userp2130.oracle.com X-detected-operating-system: by eggs.gnu.org: First seen = 2020/05/13 09:36:43 X-ACL-Warn: Detected OS = Linux 3.1-3.10 [fuzzy] X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001 autolearn=_AUTOLEARN X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Kevin Wolf , Eyal Moscovici , qemu-block@nongnu.org, qemu-devel@nongnu.org, Max Reitz , liran.alon@oracle.com Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: fail (Header signature does not verify) Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" The code handles this case correctly we merely skip the loop. However it is probably best to return an explicit error. Reviewed-by: Eric Blake Acked-by: Mark Kanda Signed-off-by: Eyal Moscovici --- qemu-img.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/qemu-img.c b/qemu-img.c index cc2e4a3799..23e90a99e1 100644 --- a/qemu-img.c +++ b/qemu-img.c @@ -3091,6 +3091,11 @@ static int img_map(int argc, char **argv) } =20 length =3D blk_getlength(blk); + if (length < 0) { + error_report("Failed to get size for '%s'", filename); + return 1; + } + while (curr.start + curr.length < length) { int64_t offset =3D curr.start + curr.length; int64_t n; --=20 2.17.2 (Apple Git-113)