From nobody Sat Jul 25 08:04:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1784740047; cv=none; d=zohomail.com; s=zohoarc; b=ZrhHB3BrC2BJVmUqm7RMd1fbA2+E1sAprxorMISnURSvb+2nDlCNvgQHgoYCcjEIdzjDedSuHPZo1gaBuAM/B9RAwyHqYKu7x4RXHQxKRIT+QrI4kzAuv8kikOvgCMkwpXX785nYvaglqp4n8hH2+xkZ4uIYaRjKt1F4RSVYBZk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784740047; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6peXfCAI9PBCc+mW0GS1f5pARDqtu1ectajEcLcGxc4=; b=DpB10vtqw/xKiCeJnVZjL9bNm1ZP55O0q0yxwXiXhBLSep1FUr8LHXw8XpE6ubNgDJpVACDEumICn0IXNrc6WrKK3ceCU50c/Hj6Jfc2oTAVOcq6xWYmxb0VK90j1V3yyj6qxt07TprMwy7ehIOjtZYuxYGyIIJQrkjDrGvSEyU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784740047074781.4146180194228; Wed, 22 Jul 2026 10:07:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmaO2-00059q-6O; Wed, 22 Jul 2026 13:05:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmaNz-000598-QD for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:35 -0400 Received: from mail-wm1-x334.google.com ([2a00:1450:4864:20::334]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wmaNy-0001YG-3x for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:35 -0400 Received: by mail-wm1-x334.google.com with SMTP id 5b1f17b1804b1-4955de8797cso22910955e9.3 for ; Wed, 22 Jul 2026 10:05:33 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:9c54:c407:8170:580d]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956b7483f0sm63993215e9.3.2026.07.22.10.05.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:05:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1784739933; x=1785344733; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6peXfCAI9PBCc+mW0GS1f5pARDqtu1ectajEcLcGxc4=; b=bKNxdLfBZqq60BOvjAPWergIOC6S+PpuQkQ9GwnQF1u8hMWYMwCrplcpasO7vgN62u onXBs16iw4kTdoxAwDV3JIHsdz1iOJr3rVNRe8sdcMaAGkoAzHbmZ46F99uxNEyjahUT +IYnCAM4SZmuHFYJ4aQPF7wNo6+txs6ikPjK3vIpxyLE+MNdEko3mi4Z10Uii2c1ATyU lTGk81IsE14SNDHskpwW7dYV49nxYSkIAHkIG8l9DTmhDXZnZ/4QmtIxiP8Lg3AZoRZf 1oVbaB+Ov35xCrnwmW9TxzRn0H94sRrXNGDhLg4JzgahAf49SOmPbvbK8pEfz/oDtOl6 vrBA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784739933; x=1785344733; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=6peXfCAI9PBCc+mW0GS1f5pARDqtu1ectajEcLcGxc4=; b=XBB3hSvQeXfIPOpFE9IHr28Nr0+2gLhRS5cAYTqNvO59C2bLoWzxBxo2ZR8+M5RyY6 Gz+y8SAZ1UMbf1c2NNra1pXbrVcIHt7UKbSukHrybbgbdapYc6Up07HuRPu8JqWFQJv6 QmUSvj/naq+EJ3A2zBNwvnczn0XeQetEHmyOUmZsubr7PqwO6OQOWL5y/C8YtGyrvm4A XRBSg5eLslDq6KDzUet+I0a27chXeoj+CtSVkYuNMPgjKScz/Jr0qjjBhTmaqiGaVYzT 5hEHzo4/8QVXMdMUm+PO1V5X72UsQCekNnD9oMnxAr/vVoOLdfIrSPSRNAp6f/CZedqm eXPQ== X-Gm-Message-State: AOJu0YxJJsH7MSoge1FDiXJOsQ/7s0/LTUTo8/pajW8Y74TDb5Rha0q3 aNoxHhRpcFJM5TtMen3PYsDBG4lmpF6HR1313xMXgcI8H/SxNjHFBkFq3a6qKHwXgBiSpM/obup OvVsd X-Gm-Gg: AR+sD103uW0tLwCSdgGUYWVT4TqvZJ99ANQIMl5883o1Q5vw+MYzDLGua/djFJGdGCr mzcie7wx/WGZqz7vF7DRXIGJLQChR0hMZUk80Uxi/eDdGhpvhHE1TxGGuhBPI2TjX8wBECY8dKQ Mjx7DPfJ8HAUCkC/pIAWjsNp/9P4sUvcJlbA2yBjr6O8e7PVNbSZBY4B6bmULF8wvAAcLkbuROT Or/P8L2IV8I/MnLtXjzn20l85ibbK5vTNb2NZwbITLsnrePpDw3M1DXg2mlovbHQeUXsPH89xf1 NxBS6QwugVleUS7RExnMmna9VahaiSJ0i2eGTi4dkVFpT7Y6HUdfWTiyXjq3ulPg2WjpxRySAam MboOu/7/fSLcYf6gmX5MUpyf0zdgzRdrWu4GuXAqqV6pPHkvHA9K1Z7FE3UQmxAdIMe6ba/KelB k= X-Received: by 2002:a05:600c:1554:b0:495:3de8:33a6 with SMTP id 5b1f17b1804b1-4954a3dc7bcmr304740015e9.16.1784739932647; Wed, 22 Jul 2026 10:05:32 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org, qemu-block@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PATCH 1/9] parallels: fix integer overflow in header size calculation Date: Wed, 22 Jul 2026 19:05:19 +0200 Message-ID: <20260722170527.2593225-2-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260722170527.2593225-1-den@openvz.org> References: <20260722170527.2593225-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::334; envelope-from=den@openvz.org; helo=mail-wm1-x334.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1784740047554158500 Content-Type: text/plain; charset="utf-8" parallels_open() caches bat_entry_off(s->bat_size) - a uint32_t - in a plain int before it feeds into s->header_size. Near the "Catalog too large" bound the value exceeds INT_MAX and overflows on assignment. Match the cached value's type to bat_entry_off()'s return type. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/block/parallels.c b/block/parallels.c index 7a90fb5220..59f00c64a6 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -1240,7 +1240,8 @@ static int parallels_open(BlockDriverState *bs, QDict= *options, int flags, { BDRVParallelsState *s =3D bs->opaque; ParallelsHeader ph; - int ret, size, i; + int ret, i; + uint32_t size; int64_t file_nb_sectors, sector; uint32_t data_start; bool need_check =3D false; --=20 2.53.0 From nobody Sat Jul 25 08:04:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1784740047; cv=none; d=zohomail.com; s=zohoarc; b=GArQ8/dsXR5PCAQu4GG/EcbmQCrln82DgahthHUvZ0eJjUYdRuD09g45u1gzVtagH5nl+hRTIXUaavx2XwIVi8WU9cJaRrz5QNxjeZ/841s7oL9u9ylzBanQGnMkxjEqUBERag2Ppg446os1q92H8gsWxetLh+myIsLLGcIaoFk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784740047; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bm+t6tVWssOS3Bc74G2+tUbVOT2wab5L0F6cKOp1Il0=; b=CCsEo1pGe4eGXS4gJ+BwkihNpPSgA8r4pP91VsmnzfU4e5y9iHIxRJMznWOrnJP5iV5l14jTe7Yoy/mKLa/JuN6oDlph3n4JHstUdNwd9k81nHUIOqWoM1CM9570bCAG0ED43ghDDKTs6wgQtDDLCPVbXt/4mmtD2LZgIvy6P3o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784740047909938.6235474897119; Wed, 22 Jul 2026 10:07:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmaO4-0005CO-Nu; Wed, 22 Jul 2026 13:05:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmaO1-00059T-8z for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:37 -0400 Received: from mail-wm1-x335.google.com ([2a00:1450:4864:20::335]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wmaNz-0001YW-A1 for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:37 -0400 Received: by mail-wm1-x335.google.com with SMTP id 5b1f17b1804b1-49557167508so43953285e9.1 for ; Wed, 22 Jul 2026 10:05:34 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:9c54:c407:8170:580d]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956b7483f0sm63993215e9.3.2026.07.22.10.05.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:05:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1784739934; x=1785344734; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=bm+t6tVWssOS3Bc74G2+tUbVOT2wab5L0F6cKOp1Il0=; b=ob+iSTUMjmw4TR47itrNyaHz93k4tn/y9tYXHJkuUTOZ7mYawAL68dWYjBEx0YyMEc ePhpI1TNM3Kk88YMuPMlicx5t6XX6PvuZujdAdzn/dmRqLzh4wGBV48gE7RtRlp++4e5 AarSzCvbdAmN2AEFbAPNh2WJkKEmX/tJrA+bhhNm+dfQUlsjBl9IAqjRmpsJa1XyMwBl BBf7C6R3juWjiTEc34zrEpFBWgoIu4zlI8/0wMyy15Znl9tLqtOIT04QxrCZXitPIUbQ gmTPs2u+M4riNX1HTCKjg3kmV36SrF+K/J1hxX80XRkL5QVirUFeAtnXqSc9DgDiWuPH ZURA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784739934; x=1785344734; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=bm+t6tVWssOS3Bc74G2+tUbVOT2wab5L0F6cKOp1Il0=; b=KEIHrb4z/vM+tp0WKmrU4HGaGdHKqRXCys6TxBKrZ/hYFEB28Tx/6U4Q7xks+96EwQ XLVwD8Si0tK/L+8/+bFZ5RtbQmZnhkbM/Eir0nGTV7FNZbMlIsLKk7fp+hYieHiDdZrk cDSa3LwabtgFFwd8Xn6fRPELYIo6q1Ear4qNejlxylbr226OihhK9RUohtgY9/gh8Wm9 OGGfttFwqa3SMs2U0LUx3lYu5eLYpn5qrqYi1Apu1mtbKk+hdg5U63Igp9Pq2TF7JajY 39dSbO3AhzTV8I/YvBR8VZfMw7rvkENkkE4dfIyjCqPFnrsfweXTmMd1upFOcHvaAjDK +B2A== X-Gm-Message-State: AOJu0YzA4cp02ix3md6IjbYzKdyhBVs0GD9eYp6/is3mGJGxqMQ6y+nz TnnmAhtV5mFYtUseOdURhDkh+Uqq2IVh/Mw6Zxjl79XCf3heTvMKTlbDLyOYlO8vBf7pM0YpFRx 35ACz X-Gm-Gg: AR+sD11bxpVYOpVnkrl851uSxgigKLgY5FxW9usm+5WdAH5II+5+1aR7t5fU389qg4u CZwMGOKcIlEW4DcVsKjCkueMMGagTY6oVPdXRVKEBAjJ9PUQUxoETgthQsXfMWFZOn6w29S/LyR y+YT95BQ5hNlUEVBP1KrxN82WucdE56jOxHI24t58XasVpwVp5axnuAIYELSQJt29ABggaKyl4Z SSkpig6wCW5WIDlt5MKRmfflK8P+WR/w5A8PjvSJBKD730VonTqLeWJULt0G/nJn3bCPQt3wxbs 2JqrCnNWnjdU/MYbh/Uq/hGlk3LGugcU0nkv3/PyiJ7AICZSB12SUlzyREILeYtzinfvui5eYS8 UybWZOyLqHK6Txcg6VGts2tWH3ltHtbAYAt9EJ2uNXMZeUHappJPJ2sqi4fpq9UicuM+7gRtyX4 A= X-Received: by 2002:a05:600c:42c6:b0:495:4182:4456 with SMTP id 5b1f17b1804b1-4954a4104e1mr171163275e9.29.1784739933607; Wed, 22 Jul 2026 10:05:33 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org, qemu-block@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PATCH 2/9] parallels: read header/BAT table in bounded chunks Date: Wed, 22 Jul 2026 19:05:20 +0200 Message-ID: <20260722170527.2593225-3-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260722170527.2593225-1-den@openvz.org> References: <20260722170527.2593225-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::335; envelope-from=den@openvz.org; helo=mail-wm1-x335.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1784740049587158500 Content-Type: text/plain; charset="utf-8" parallels_open() read the whole header+BAT table with a single bdrv_pread() call sized s->header_size. For an image whose catalog approaches the "Catalog too large" bound (INT_MAX / sizeof(uint32_t) entries), that size approaches BDRV_REQUEST_MAX_BYTES, and the block layer legitimately refuses a single request that large, so the image failed to open with a generic I/O error even though the catalog size itself is within the format's documented limit. Read the header and BAT table in fixed-size chunks instead, so the maximum catalog size parallels_open() can actually address matches the bound it already enforces, independent of the file's block-layer alignment requirements. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 17 ++++++++++---- tests/qemu-iotests/tests/parallels-checks | 23 +++++++++++++++++++ tests/qemu-iotests/tests/parallels-checks.out | 17 ++++++++++++++ 3 files changed, 53 insertions(+), 4 deletions(-) diff --git a/block/parallels.c b/block/parallels.c index 59f00c64a6..0f655b58d5 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -52,6 +52,7 @@ #define HEADER_VERSION 2 #define HEADER_INUSE_MAGIC (0x746F6E59) #define MAX_PARALLELS_IMAGE_FACTOR (1ull << 32) +#define PARALLELS_HEADER_READ_CHUNK (64 * 1024 * 1024) =20 static QEnumLookup prealloc_mode_lookup =3D { .array =3D (const char *const[]) { @@ -1241,7 +1242,7 @@ static int parallels_open(BlockDriverState *bs, QDict= *options, int flags, BDRVParallelsState *s =3D bs->opaque; ParallelsHeader ph; int ret, i; - uint32_t size; + uint32_t size, header_off; int64_t file_nb_sectors, sector; uint32_t data_start; bool need_check =3D false; @@ -1311,9 +1312,17 @@ static int parallels_open(BlockDriverState *bs, QDic= t *options, int flags, return -ENOMEM; } =20 - ret =3D bdrv_pread(bs->file, 0, s->header_size, s->header, 0); - if (ret < 0) { - goto fail; + /* A single request s->header_size large exceeds BDRV_REQUEST_MAX_BYTE= S. */ + for (header_off =3D 0; header_off < s->header_size; + header_off +=3D PARALLELS_HEADER_READ_CHUNK) { + uint32_t chunk =3D MIN(s->header_size - header_off, + PARALLELS_HEADER_READ_CHUNK); + + ret =3D bdrv_pread(bs->file, header_off, chunk, + (uint8_t *)s->header + header_off, 0); + if (ret < 0) { + goto fail; + } } s->bat_bitmap =3D (uint32_t *)(s->header + 1); =20 diff --git a/tests/qemu-iotests/tests/parallels-checks b/tests/qemu-iotests= /tests/parallels-checks index b281246a42..8087b03fb9 100755 --- a/tests/qemu-iotests/tests/parallels-checks +++ b/tests/qemu-iotests/tests/parallels-checks @@ -44,6 +44,7 @@ _supported_os Linux SIZE=3D$((4 * 1024 * 1024)) IMGFMT=3Dparallels CLUSTER_SIZE_OFFSET=3D28 +BAT_ENTRIES_OFFSET=3D32 DATA_OFF_OFFSET=3D48 BAT_OFFSET=3D64 =20 @@ -199,6 +200,28 @@ _check_test_img -r all echo "=3D=3D check first cluster =3D=3D" { $QEMU_IO -r -c "read -P 0x55 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir =20 +# Clear image +_make_test_img $SIZE + +echo "=3D=3D TEST HUGE BAT TABLE OPEN =3D=3D" + +# Overflows a single read request, but stays under parallels_open()'s +# own catalog-size cap. +BAT_ENTRIES=3D536870896 +HEADER_SIZE=3D$((64 + 4 * BAT_ENTRIES)) + +echo "=3D=3D advertise a BAT table larger than BDRV_REQUEST_MAX_BYTES =3D= =3D" +poke_file "$TEST_IMG" "$BAT_ENTRIES_OFFSET" "\xf0\xff\xff\x1f" + +echo "=3D=3D grow the file to match, without writing real data =3D=3D" +truncate -s $HEADER_SIZE "$TEST_IMG" + +echo "=3D=3D open must succeed: the header/BAT read is chunked =3D=3D" +{ $QEMU_IMG info "$TEST_IMG"; } 2>&1 | _filter_qemu_io | _filter_testdir + +echo "=3D=3D an unallocated cluster still reads as zeroes =3D=3D" +{ $QEMU_IO -r -c "read -P 0x00 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir + # success, all done echo "*** done" rm -f $seq.full diff --git a/tests/qemu-iotests/tests/parallels-checks.out b/tests/qemu-iot= ests/tests/parallels-checks.out index 9793423111..b47c42cf4d 100644 --- a/tests/qemu-iotests/tests/parallels-checks.out +++ b/tests/qemu-iotests/tests/parallels-checks.out @@ -129,4 +129,21 @@ No errors were found on the image. =3D=3D check first cluster =3D=3D read 1048576/1048576 bytes at offset 0 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 +=3D=3D TEST HUGE BAT TABLE OPEN =3D=3D +=3D=3D advertise a BAT table larger than BDRV_REQUEST_MAX_BYTES =3D=3D +=3D=3D grow the file to match, without writing real data =3D=3D +=3D=3D open must succeed: the header/BAT read is chunked =3D=3D +image: TEST_DIR/t.parallels +file format: parallels +virtual size: 4 MiB (4194304 bytes) +disk size: 1 MiB +Child node '/file': + filename: TEST_DIR/t.parallels + protocol type: file + file length: 2 GiB (2147483648 bytes) + disk size: 1 MiB +=3D=3D an unallocated cluster still reads as zeroes =3D=3D +read 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) *** done --=20 2.53.0 From nobody Sat Jul 25 08:04:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1784740001; cv=none; d=zohomail.com; s=zohoarc; b=IeEVrPATjjz9gJFPnvpM645KhRyLOIgBkqxaPFFfUTne7AvQlvMvDKIf6mBdmqQSwCyY3hSMM1OGrKaR3P/8f99JAHY679rOAP24EWnQltMTj4qzzHtza7Ls23xIWA4ZrIkTyeojuGRac++hGsRDqZU6ZUz+11c5kBgfRpZoK18= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784740001; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/g2p3N4kfpkZuJaxI9UjRhwniulc+lWWhKKajqjETAQ=; b=jrJlKtjYGADCYPn31j5XZ/jzjNL3Ir2LVGUizX80raA8nE2vkDi6kVSrF599RD6JmrzNWoAlZjNOJAwCcKWBMWolgfCLMZVdXZkNbTOEdsYjublzYCQnmpPghXwVvRBqp8UrqV9TUelkpbPJNEMtlGATH4HKzAlLiJs2+55c4FM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784740001531444.2368674195509; Wed, 22 Jul 2026 10:06:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmaO5-0005Cm-Gq; Wed, 22 Jul 2026 13:05:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmaO2-0005Ai-Ra for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:38 -0400 Received: from mail-wm1-x331.google.com ([2a00:1450:4864:20::331]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wmaO0-0001Yz-Ec for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:38 -0400 Received: by mail-wm1-x331.google.com with SMTP id 5b1f17b1804b1-495635a85d2so27664985e9.0 for ; Wed, 22 Jul 2026 10:05:36 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:9c54:c407:8170:580d]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956b7483f0sm63993215e9.3.2026.07.22.10.05.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:05:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1784739935; x=1785344735; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/g2p3N4kfpkZuJaxI9UjRhwniulc+lWWhKKajqjETAQ=; b=XuG8DZmk8EXwSOlwCeBqNL3vDfVI+Ww+w7b/VZjisJAHiGKRdj9xZYNGB5ccKWUN0G Jyg3UgiSo/64bkfvvmhRRgoqdK3A5OnEYNUfZuD3b+vhaUtdwx2OffCOVE8d/YY8WMFr IN807a9VooWkbGoAERyt0JEmZ1jU+PFA8nrnSWHr/gvYq+MNaHiUnfPcVg5Y8LmXGVtP IbGxvLJO5Bt1egg0W1ej3+94iyjdEXGOuQ/0cRo1a7P+RsgnXerAGtUU5QR1rTfLAtiI LmW2Ki3KXBizPVXJMFY5l5cRiiq3mKctsXSpRJnFHad86mCrxLAfakuin+Xx/gfps3Bl h85A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784739935; x=1785344735; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/g2p3N4kfpkZuJaxI9UjRhwniulc+lWWhKKajqjETAQ=; b=RbVjZ4xKWKkaTmVQIYxtpRvNCIOUy4Bxix0WnG/zj6Aa0hOFTKTiX3xrHt6eYYO/wR YVphRpWYzWwWkJinJzzOw9jqULQk5CF0rgt6B0bw9AxGqaygVlYg8tbCZIzciktwPctM ltlmxJfyRdX+2rzDsAkw6X32nY3amSUxhfxmHxMarhOxB5ytSO0dzE+kTN+cdTOtgGzj 1+PZ44LDh5LMRF1NCgaYGgPRXa7HkKY78B02m9fh1m5gjZ2+0nCYgxqsCTnq3n4w5GPm upCsjyqYRNenPT6WGDLcC96ynsS/icDT6FDGG4F73nLunW0qm6BDoP3CFmwixIzdVlv0 UofQ== X-Gm-Message-State: AOJu0YxkP8MW1zk3BwYx+iBidxe9S+d3Btnk1XQSS437wTtPdFuMRRxb B2Uo38zix07EhuDMoiVSuTuj+DgcCUxMii9i03eYyDnB1eDGzH68fFPxszSKdO55wsz/QrRsdZU pejk5 X-Gm-Gg: AR+sD11lRzUkjwfUSmL5UB89Ezt4MAKoAw0HFGIMoqSfTfZBxiNgfaHURTFou4qGpZY s0ZSs4Txj4SQF+6WXid+gWmW/8M1DdwdLbAwqBWHsYsFQJSJ1hue/hw2+IcGGCLx9YuYGKe1fL2 TDvpVqB9Fq2ZG5PAMGNnq8oCN+qDgPcRMI2oopIY3S5LPK+g5FPs09IdJ5mSjeBM5m3GbI6XYZ6 G1pYA5+kQXygISOL2PhcZVLnEz5zdJhctZEfy7q8/CMFgCEyNLMY4qzp/Zz6xRtKFIQQvQctMcO jJDmskawvru0vKmZlmjtJ8yRIC3nfm56edwd3qMW7lA6CLAegLXTA2TZ6kmqcV/czy/2IWz3e/6 Xh2CifSQRDAYU7JeIcvwdUUIFMTP739RnjI+nIdpmJlBPv2YcnEmYviXveGYnbnJJsDF0H8ttD6 krmnzDbI0iqQ== X-Received: by 2002:a05:600c:8b4c:b0:495:6a2f:2c76 with SMTP id 5b1f17b1804b1-4956a2f2cd7mr54583215e9.32.1784739934646; Wed, 22 Jul 2026 10:05:34 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org, qemu-block@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PATCH 3/9] parallels: fix bat_entries overflow in image creation Date: Wed, 22 Jul 2026 19:05:21 +0200 Message-ID: <20260722170527.2593225-4-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260722170527.2593225-1-den@openvz.org> References: <20260722170527.2593225-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::331; envelope-from=den@openvz.org; helo=mail-wm1-x331.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1784740003311158501 Content-Type: text/plain; charset="utf-8" parallels_co_create() computed the BAT entry count directly into a uint32_t, wrapping silently to zero at exactly 2^32 entries and writing out a header whose BAT no longer matches its advertised size. Compute it in an int64_t first and reject it once it no longer fits, matching the cap parallels_open() already enforces. Also reject cluster-size 0, and clamp header.cylinders instead of letting it truncate the same way. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 23 +++++++++++++++++------ tests/qemu-iotests/212 | 8 ++++++-- tests/qemu-iotests/212.out | 10 ++++++++-- 3 files changed, 31 insertions(+), 10 deletions(-) diff --git a/block/parallels.c b/block/parallels.c index 0f655b58d5..e3d26a6650 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -999,7 +999,8 @@ parallels_co_create(BlockdevCreateOptions* opts, Error = **errp) BlockdevCreateOptionsParallels *parallels_opts; BlockDriverState *bs; BlockBackend *blk; - int64_t total_size, cl_size; + int64_t total_size, cl_size, bat_count; + uint64_t cylinders; uint32_t bat_entries, bat_sectors; ParallelsHeader header; uint8_t tmp[BDRV_SECTOR_SIZE]; @@ -1017,16 +1018,22 @@ parallels_co_create(BlockdevCreateOptions* opts, Er= ror **errp) cl_size =3D DEFAULT_CLUSTER_SIZE; } =20 - /* XXX What is the real limit here? This is an insanely large maximum.= */ + /* Bounds cl_size so the multiplication below can't overflow int64_t. = */ if (cl_size >=3D INT64_MAX / MAX_PARALLELS_IMAGE_FACTOR) { error_setg(errp, "Cluster size is too large"); return -EINVAL; } - if (total_size >=3D MAX_PARALLELS_IMAGE_FACTOR * cl_size) { + if (cl_size <=3D 0 || total_size >=3D MAX_PARALLELS_IMAGE_FACTOR * cl_= size) { error_setg(errp, "Image size is too large for this cluster size"); return -E2BIG; } =20 + bat_count =3D DIV_ROUND_UP(total_size, cl_size); + if (bat_count > INT_MAX / (int64_t)sizeof(uint32_t)) { + error_setg(errp, "Catalog too large"); + return -EFBIG; + } + if (!QEMU_IS_ALIGNED(total_size, BDRV_SECTOR_SIZE)) { error_setg(errp, "Image size must be a multiple of 512 bytes"); return -EINVAL; @@ -1052,7 +1059,7 @@ parallels_co_create(BlockdevCreateOptions* opts, Erro= r **errp) blk_set_allow_write_beyond_eof(blk, true); =20 /* Create image format */ - bat_entries =3D DIV_ROUND_UP(total_size, cl_size); + bat_entries =3D bat_count; bat_sectors =3D DIV_ROUND_UP(bat_entry_off(bat_entries), cl_size); bat_sectors =3D (bat_sectors * cl_size) >> BDRV_SECTOR_BITS; =20 @@ -1061,8 +1068,12 @@ parallels_co_create(BlockdevCreateOptions* opts, Err= or **errp) header.version =3D cpu_to_le32(HEADER_VERSION); /* don't care much about geometry, it is not used on image level */ header.heads =3D cpu_to_le32(HEADS_NUMBER); - header.cylinders =3D cpu_to_le32(total_size / BDRV_SECTOR_SIZE - / HEADS_NUMBER / SEC_IN_CYL); + cylinders =3D total_size / BDRV_SECTOR_SIZE / HEADS_NUMBER / SEC_IN_CY= L; + /* Write only by spec, do not care */ + if (cylinders >=3D UINT32_MAX) { + cylinders =3D UINT32_MAX; + } + header.cylinders =3D cpu_to_le32(cylinders); header.tracks =3D cpu_to_le32(cl_size >> BDRV_SECTOR_BITS); header.bat_entries =3D cpu_to_le32(bat_entries); header.nb_sectors =3D cpu_to_le64(DIV_ROUND_UP(total_size, BDRV_SECTOR= _SIZE)); diff --git a/tests/qemu-iotests/212 b/tests/qemu-iotests/212 index d4af0c4ac8..4ca6149b6b 100755 --- a/tests/qemu-iotests/212 +++ b/tests/qemu-iotests/212 @@ -133,13 +133,15 @@ with iotests.FilePath('t.parallels') as disk_path, \ # # Maximum size # + # Largest catalog parallels_open() can address. + # iotests.log("=3D=3D=3D Maximum size =3D=3D=3D") iotests.log("") =20 vm.launch() vm.blockdev_create({ 'driver': imgfmt, 'file': 'node0', - 'size': 4503599627369984}) + 'size': 562949952372736}) vm.shutdown() =20 iotests.img_info_log(disk_path) @@ -158,13 +160,15 @@ with iotests.FilePath('t.parallels') as disk_path, \ # 4. 2^63 - 512 (generally valid, but with the image header the file w= ill # exceed 63 bits) # 5. 2^52 (512 bytes more than maximum image size) + # 6. 2^52 - 512 (wraps bat_entries to 0 at the default 1 MiB cluster s= ize) =20 iotests.log("=3D=3D=3D Invalid sizes =3D=3D=3D") iotests.log("") =20 vm.launch() for size in [ 1234, 18446744073709551104, 9223372036854775808, - 9223372036854775296, 4503599627370497 ]: + 9223372036854775296, 4503599627370497, + 4503599627369984 ]: vm.blockdev_create({ 'driver': imgfmt, 'file': 'node0', 'size': size }) diff --git a/tests/qemu-iotests/212.out b/tests/qemu-iotests/212.out index 8102033488..d59f8ed44b 100644 --- a/tests/qemu-iotests/212.out +++ b/tests/qemu-iotests/212.out @@ -69,14 +69,14 @@ virtual size: 0 B (0 bytes) =20 =3D=3D=3D Maximum size =3D=3D=3D =20 -{"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"driver": "parallels", "file": "node0", "size": 4503599627369984}}} +{"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"driver": "parallels", "file": "node0", "size": 562949952372736}}} {"return": {}} {"execute": "job-dismiss", "arguments": {"id": "job0"}} {"return": {}} =20 image: TEST_IMG file format: IMGFMT -virtual size: 4 PiB (4503599627369984 bytes) +virtual size: 512 TiB (562949952372736 bytes) =20 =3D=3D=3D Invalid sizes =3D=3D=3D =20 @@ -110,6 +110,12 @@ Job failed: Image size is too large for this cluster s= ize {"execute": "job-dismiss", "arguments": {"id": "job0"}} {"return": {}} =20 +{"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"driver": "parallels", "file": "node0", "size": 4503599627369984}}} +{"return": {}} +Job failed: Catalog too large +{"execute": "job-dismiss", "arguments": {"id": "job0"}} +{"return": {}} + =3D=3D=3D Invalid cluster size =3D=3D=3D =20 {"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"cluster-size": 1234, "driver": "parallels", "file": "node0", "size": 6710= 8864}}} --=20 2.53.0 From nobody Sat Jul 25 08:04:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1784739986; cv=none; d=zohomail.com; s=zohoarc; b=T5wUPi2PrBmChHMN72+eqngsgPGIrkcIIVlkAKK0cf/ZdufCjHUIXlP1BocgDBqX98iKR52ZVVjcdmnLvnXY3DVSOJMJg8uYN1k86NvoSjIme4kzZsyaMacJcLQtF68lmJ2MhsWRnEam5kDQ1KPOjvsKS2kwO7Ac8fJKnWQdyrM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784739986; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=BhGcypSN9c7MXiKGLST/q5b00sWwo654rqpJZ/LWYcg=; b=Xp6res/xZRIzyTlkGYeh2ERkHhVB328ICPzOwOKqpwyHW1Sas+Cjefq5jl8GztVwrHOvW9q4RQxQfLi9s0LiPpdsfhp6RL4hwF8QYjinLS/3++CHpqQ5kfC+WtJyVmwU4TUTyfiPwFKBct4RzWRPHoS6OVl2ZmtWx+d2LAeZZNw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784739986859683.5286372167168; Wed, 22 Jul 2026 10:06:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmaO8-0005DR-9k; Wed, 22 Jul 2026 13:05:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmaO3-0005B0-Kr for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:39 -0400 Received: from mail-wm1-x331.google.com ([2a00:1450:4864:20::331]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wmaO1-0001ZI-8j for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:39 -0400 Received: by mail-wm1-x331.google.com with SMTP id 5b1f17b1804b1-49550ec592cso23063065e9.0 for ; Wed, 22 Jul 2026 10:05:36 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:9c54:c407:8170:580d]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956b7483f0sm63993215e9.3.2026.07.22.10.05.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:05:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1784739936; x=1785344736; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=BhGcypSN9c7MXiKGLST/q5b00sWwo654rqpJZ/LWYcg=; b=kBwy9BK/7VAsmJH2z7ZMCzCLt69muBdgK2+SgOmEL8FFgjt8PFENGNKoSCOgl97LSs +bPCUUBYoTiw5k+hZk3y96uq6vpVFJANqNdDrwjvl8pOyq3e0aOCiSZWwalf+CRAoDDK cisQjDJxhiqclEDLUeaUcxGYYUQM6QjESe7kGtjyo68WQHdbut5PwOG5yhy39Il3iT6s J6iWprhpSmqcapGju4TVegLEpKW1qf6aM1XS9WP4T/wsN5VuXCXPUXAdYqJix/OInQUj CGbsBqkWOm/ysChUCycuSGIC8wo/Ge3sKkI8jI00Qb6PxreGsAc07rpfgrW9xOS7HQgc 8z8w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784739936; x=1785344736; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=BhGcypSN9c7MXiKGLST/q5b00sWwo654rqpJZ/LWYcg=; b=MfOpZIjol7Nbjlhefnd9NO+Cjmiq4lFNdHoKSvEWacv6lsTAwB7MwX8TcNFofqYM2S gsPalQ3vosMgSok0q8WLXG+jy/DEWQoOTP6EY72kT2EjqKA3dF2ZIOV+y4Kk+HFul1hX vSLmrOB5osZ1Ck60FEnXSx5/ML8dzXFaClf2yGoRHcnrth8CynfppmZ2dAwCywAIFInT PSr0jaIfRCQZ7bZ7g5z3NBXoNRfxdafnVe+NhNftNIxt2qcL/STilGs6w+H2dSE6HVV9 Rxpdglwj7VvtvUI+FVaIGHi28Z7u0Ee6noA1IiQBqiceh3+UJmpKdvzUxchiryCTEN+q QFzg== X-Gm-Message-State: AOJu0YxBmbQayq45ccaPeaPQuMM1HAUTOwucPQZu1DcjNUYALepvrErY aqnjhPp/SbGZ/UD50cSOhSHv8pqDSwx9ytGmauyclVUiDHm5NtDQ7f8SeRShbirXUFgnlrT+hmD ZQBLT X-Gm-Gg: AR+sD118TJZToVp/4tJzS6I2lLUbcUxiUcYkSZNu37iN51dw+SYvfarWMNX/8mqIgGJ rs0en+d41vJioYFBIDqKvr0woBvIU4vBZvf5D8uMmzlU+bYL2sjEyL7YkFuXqICf/2mwD6QAQKu +sHpKoMGZWi7467ddbhHB6k9u2QiOU87gWoBOVMb6bV9UUb3mDWLzbN8Tw9fsK7mDPNEuvCZuY6 x8H+Lx1P3jFD863OnAZ+4y/ANVkuX4qXx74PU8rKt6wHGaEZDYL745iK5UnP0cwCKSKyBS9cIrK mqbW5/snjPTfIkNFvf5utEZn9Qm797mjuul2fAV+3VYhfF6gIM9x3HZ5YY8YhHGG7EvEkH6VVsg ioPrYX8wep636T6xBHnCjMhqbZQS7mZrLlh/UCPBQ3jXDbnhK2SePpje7W+hpimiI7RijGU6RRr D2FgAKHhovsA== X-Received: by 2002:a05:600c:4687:b0:495:3a52:71b1 with SMTP id 5b1f17b1804b1-4956a4ef4e2mr56959605e9.5.1784739935705; Wed, 22 Jul 2026 10:05:35 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org, qemu-block@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PATCH 4/9] parallels: reject BAT entries pointing outside backed storage Date: Wed, 22 Jul 2026 19:05:22 +0200 Message-ID: <20260722170527.2593225-5-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260722170527.2593225-1-den@openvz.org> References: <20260722170527.2593225-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::331; envelope-from=den@openvz.org; helo=mail-wm1-x331.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1784739989366158500 Content-Type: text/plain; charset="utf-8" parallels_open()'s BAT scan and parallels_check_outside_image() only checked entries against the file's upper end, matching just half of what docs/interop/parallels.rst requires: an entry's offset must be both >=3D data_start and < the file size. An entry below data_start resolves into the header/BAT region itself, corrupting metadata on write or losing the write silently on a partial overlap, and neither qemu-img check nor the open-time scan ever caught it. Check both bounds everywhere a BAT entry is resolved to a host offset: seek_to_sector(), the open-time scan (without letting a bad entry inflate data_end), and parallels_check_outside_image(). Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 27 +++++++-- tests/qemu-iotests/tests/parallels-checks | 58 +++++++++++++++++++ tests/qemu-iotests/tests/parallels-checks.out | 35 +++++++++++ 3 files changed, 116 insertions(+), 4 deletions(-) diff --git a/block/parallels.c b/block/parallels.c index e3d26a6650..8a7e8b4aba 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -119,6 +119,7 @@ static uint32_t bat_entry_off(uint32_t idx) static int64_t seek_to_sector(BDRVParallelsState *s, int64_t sector_num) { uint32_t index, offset; + int64_t cluster_off; =20 index =3D sector_num / s->tracks; offset =3D sector_num % s->tracks; @@ -127,7 +128,14 @@ static int64_t seek_to_sector(BDRVParallelsState *s, i= nt64_t sector_num) if ((index >=3D s->bat_size) || (s->bat_bitmap[index] =3D=3D 0)) { return -1; } - return bat2sect(s, index) + offset; + + cluster_off =3D bat2sect(s, index); + if (cluster_off < s->data_start || cluster_off + s->tracks > s->data_e= nd) { + /* Cluster is outside of the image file or overlaps the header. */ + return -1; + } + + return cluster_off + offset; } =20 static int cluster_remainder(BDRVParallelsState *s, int64_t sector_num, @@ -703,18 +711,22 @@ parallels_check_outside_image(BlockDriverState *bs, B= drvCheckResult *res, { BDRVParallelsState *s =3D bs->opaque; uint32_t i; - int64_t off, high_off, size; + int64_t off, high_off, size, data_start_off; =20 size =3D bdrv_co_getlength(bs->file->bs); if (size < 0) { res->check_errors++; return size; } + data_start_off =3D s->data_start << BDRV_SECTOR_BITS; =20 high_off =3D 0; for (i =3D 0; i < s->bat_size; i++) { off =3D bat2sect(s, i) << BDRV_SECTOR_BITS; - if (off + s->cluster_size > size) { + if (off =3D=3D 0) { + continue; + } + if (off < data_start_off || off + s->cluster_size > size) { fprintf(stderr, "%s cluster %u is outside image\n", fix & BDRV_FIX_ERRORS ? "Repairing" : "ERROR", i); res->corruptions++; @@ -1398,11 +1410,18 @@ static int parallels_open(BlockDriverState *bs, QDi= ct *options, int flags, =20 for (i =3D 0; i < s->bat_size; i++) { sector =3D bat2sect(s, i); + if (sector =3D=3D 0) { + continue; /* not allocated */ + } + if (sector < data_start || sector + s->tracks > file_nb_sectors) { + /* Cluster is outside of the image file or overlaps the header= . */ + need_check =3D true; + continue; + } if (sector + s->tracks > s->data_end) { s->data_end =3D sector + s->tracks; } } - need_check =3D need_check || s->data_end > file_nb_sectors; =20 if (!need_check) { ret =3D parallels_fill_used_bitmap(bs); diff --git a/tests/qemu-iotests/tests/parallels-checks b/tests/qemu-iotests= /tests/parallels-checks index 8087b03fb9..eef1c86809 100755 --- a/tests/qemu-iotests/tests/parallels-checks +++ b/tests/qemu-iotests/tests/parallels-checks @@ -222,6 +222,64 @@ echo "=3D=3D open must succeed: the header/BAT read is= chunked =3D=3D" echo "=3D=3D an unallocated cluster still reads as zeroes =3D=3D" { $QEMU_IO -r -c "read -P 0x00 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir =20 +# Clear image +_make_test_img $SIZE + +echo "=3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D" + +echo "=3D=3D corrupt image: point first cluster far outside the file =3D= =3D" +poke_file_le "$TEST_IMG" $BAT_OFFSET 4 1000000 + +echo "=3D=3D read-only read must return zeroes, not an I/O error =3D=3D" +{ $QEMU_IO -r -c "read -P 0x00 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir + +echo "=3D=3D write must allocate a fresh cluster instead of trusting the e= ntry =3D=3D" +{ $QEMU_IO -c "write -P 0x77 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _filte= r_qemu_io | _filter_testdir + +echo "=3D=3D file did not grow anywhere near the bogus offset =3D=3D" +file_size=3D`stat --printf=3D"%s" "$TEST_IMG"` +if [ "$file_size" -lt $((16 * 1024 * 1024)) ]; then + echo "file size sane: yes" +else + echo "file size sane: no ($file_size bytes)" +fi + +echo "=3D=3D data reads back correctly =3D=3D" +{ $QEMU_IO -r -c "read -P 0x77 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir + +# Clear image, with a small cluster size so the BAT table itself spans +# more than one cluster and there is room to point before data_off. +_make_test_img -o cluster_size=3D512 65536 + +SMALL_CLUSTER_SIZE=3D$(peek_file_le $TEST_IMG $CLUSTER_SIZE_OFFSET 4) +SMALL_CLUSTER_SIZE=3D$((SMALL_CLUSTER_SIZE * 512)) +DATA_OFF=3D$(peek_file_le $TEST_IMG $DATA_OFF_OFFSET 4) +echo "cluster size: $SMALL_CLUSTER_SIZE, data offset (sectors): $DATA_OFF" + +# Cluster index 1 starts at this byte offset, which must be < data_off +# in sectors * 512 for this test to actually exercise the bug. +VICTIM_OFFSET=3D$SMALL_CLUSTER_SIZE + +echo "=3D=3D TEST BAT ENTRY POINTING BEFORE DATA AREA =3D=3D" + +echo "=3D=3D corrupt image: point first cluster into the BAT table itself = =3D=3D" +poke_file_le "$TEST_IMG" $BAT_OFFSET 4 1 + +echo "=3D=3D qemu-img check detects it without repairing =3D=3D" +_check_test_img + +echo "=3D=3D bytes at the victim offset before write =3D=3D" +echo "$(peek_file_le "$TEST_IMG" $VICTIM_OFFSET 4)" + +echo "=3D=3D write must allocate a fresh cluster instead of clobbering the= BAT =3D=3D" +{ $QEMU_IO -c "write -P 0x88 0 $SMALL_CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | = _filter_qemu_io | _filter_testdir + +echo "=3D=3D bytes at the victim offset are unchanged =3D=3D" +echo "$(peek_file_le "$TEST_IMG" $VICTIM_OFFSET 4)" + +echo "=3D=3D data reads back correctly =3D=3D" +{ $QEMU_IO -r -c "read -P 0x88 0 $SMALL_CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 = | _filter_qemu_io | _filter_testdir + # success, all done echo "*** done" rm -f $seq.full diff --git a/tests/qemu-iotests/tests/parallels-checks.out b/tests/qemu-iot= ests/tests/parallels-checks.out index b47c42cf4d..86d5b6ac2d 100644 --- a/tests/qemu-iotests/tests/parallels-checks.out +++ b/tests/qemu-iotests/tests/parallels-checks.out @@ -146,4 +146,39 @@ Child node '/file': =3D=3D an unallocated cluster still reads as zeroes =3D=3D read 1048576/1048576 bytes at offset 0 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 +=3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D +=3D=3D corrupt image: point first cluster far outside the file =3D=3D +=3D=3D read-only read must return zeroes, not an I/O error =3D=3D +read 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +=3D=3D write must allocate a fresh cluster instead of trusting the entry = =3D=3D +Repairing cluster 0 is outside image +wrote 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +=3D=3D file did not grow anywhere near the bogus offset =3D=3D +file size sane: yes +=3D=3D data reads back correctly =3D=3D +read 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D65536 +cluster size: 512, data offset (sectors): 2 +=3D=3D TEST BAT ENTRY POINTING BEFORE DATA AREA =3D=3D +=3D=3D corrupt image: point first cluster into the BAT table itself =3D=3D +=3D=3D qemu-img check detects it without repairing =3D=3D +ERROR cluster 0 is outside image + +1 errors were found on the image. +Data may be corrupted, or further writes to the image may corrupt it. +=3D=3D bytes at the victim offset before write =3D=3D +0 +=3D=3D write must allocate a fresh cluster instead of clobbering the BAT = =3D=3D +Repairing cluster 0 is outside image +wrote 512/512 bytes at offset 0 +512 bytes, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +=3D=3D bytes at the victim offset are unchanged =3D=3D +0 +=3D=3D data reads back correctly =3D=3D +read 512/512 bytes at offset 0 +512 bytes, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) *** done --=20 2.53.0 From nobody Sat Jul 25 08:04:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1784739985; cv=none; d=zohomail.com; s=zohoarc; b=Hlq9INw22GZCbGg+5p3iGHYMQRw1gyzufFbovMT7QU2PYmS2t0oGX3xGLHO3YMEd0M5C4GOpAqqG33ZNaxH9BsZ8QOn1aNJx7fhqhSy++nAazjTvTbqV0+21ShxjmvqSIvqWyPtZx43gWaTX9gR1jucf6y3psmGzq9ID1i90MJo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784739985; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=aVkbd/prjb9WYwlM7SXvDF45HVgnD6g6uz+iwnib8ps=; b=msgucym+9XKTnWhVd6vDMuVr3Mq8o3UQCGHr+WddoBgDuQ9PdDA4qZ8G08vGKLPqLc95gVYPMSYT8qfE/rgUsaEdQJZhPBL3ifsNnSq6O8f4zFy8JxAA3U0ArQKxc6ZdHSSUPjHwCYMtky2MovuIiJ0Ckw13HduuF1AEZGJ8HTg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784739985717701.0260583997922; Wed, 22 Jul 2026 10:06:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmaOB-0005Db-W9; Wed, 22 Jul 2026 13:05:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmaO4-0005Bq-Ai for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:40 -0400 Received: from mail-wm1-x334.google.com ([2a00:1450:4864:20::334]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wmaO2-0001Zg-HP for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:40 -0400 Received: by mail-wm1-x334.google.com with SMTP id 5b1f17b1804b1-4956869750eso14250125e9.2 for ; Wed, 22 Jul 2026 10:05:38 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:9c54:c407:8170:580d]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956b7483f0sm63993215e9.3.2026.07.22.10.05.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:05:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1784739937; x=1785344737; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aVkbd/prjb9WYwlM7SXvDF45HVgnD6g6uz+iwnib8ps=; b=q+9p02/Hq4w6iGEWAPJlr24s1GZpw3aSO9kWULSP7uIWs6rXqTl9wCGMc45I5IlJ3i 4eAMd0g5O2U4vYEPqf07ZU3WVzlngAlbIqEwk8XACEAHEuqegKf5YsvlN56PpBu/PtMU 2D/LWO0it4FgEiGWt3JRFZD5syeg45HxKteyObsvBMA/I1g9a0ZfmuMtsA1HYGiSsMuh REZp/G64bn1P2n/Hz825yyJH2xV9W1SwiuY2plfnzX7OuMusV8KuoZsITx5YZ08EoG5U tw1G1P4Ih7WlgH7Ye6PhN1OZUVW/O2//KF4PEEBHvcSplUIuA23FAPtX+9hDaL40kPRh LS/A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784739937; x=1785344737; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aVkbd/prjb9WYwlM7SXvDF45HVgnD6g6uz+iwnib8ps=; b=VDOsoZBQv+yI+7W/URK9fy9oQRXZGyzSgDjS1jF4ZD9mVjgXOMXh8QyZtG96wlWHXM uc4tlsw17TCiSH0rb1DMvb21+Suvx1fEEgWYo5R+yabh1ib40vaaEmrRrMsYZwFQN17W ZrRrFhAM8Kgh/TFp80yGI5TTP6UYQF9Q7pYAbtIVx3faMY5u5nz87xB8G0sCvvGmKA/t sW51V2lm4dyQli51xRjxAbwAYT8+q0xV59p7IMhBq42DBxN+ZJXBdhJZ/hWZo1EmKzV4 +3BTnP5nXFYPKj31UsHKh+bacNvtxQdD5cxssISvj+YXb8ZeJCggfEz3lZj5pEALRiWQ +X9w== X-Gm-Message-State: AOJu0Yw9JzWDF+P9fPARZ5K+QFPO67+mAIRl1k+VfO4nlTY4PoK5n3yx Yckl0KCokeWxtF2HabUcezMXgjwpwyqczDjrKdZuzKLPeYREfmBl43uRJAwG3ktpkQVJx6+HAb6 u3eJR X-Gm-Gg: AR+sD11H9/CLVz97ef2N1m1pDRTJ04Dz4B293iV9Q4veLKLqcxQrlg5NZum5fhvyRbt Wpim/acZ7stBSE+0UzP+LLUy8plP1H9xGZRm3/hkiYtO22Pv8ZmJPy8KDe1IoxMbw13+K/WqUVp VU6gBqVjGO7L5KqeVNZp+sJ1wecHJWccbI+h9voe1Di3QfG725YFr1Bp+jWrPHJvOb4OO/bhWx3 eMzPDlqQSACbUYwQe9UR9r52AuD4FxflICwHovcLtcgSKLrDNWEqXlyV+sYYWlGbIXT2LsfRgfc LAexYbw9e9y5zMTK5PmFSmQ0CoV19y6IkKdgbpK2ChDSyWEYZX6lzslkcOdEhIv5HMiksSi9hsm 1ZlRhjBahCsQTSInbcUg/+Q2myD7V3RyAcyGI7o6TEf7kIbgrSJzDRG9TkjAxyMDP+7oYt17DAC w= X-Received: by 2002:a05:600c:4fc2:b0:495:5b02:23b0 with SMTP id 5b1f17b1804b1-4955b0224c7mr214038955e9.26.1784739936740; Wed, 22 Jul 2026 10:05:36 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org, qemu-block@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PATCH 5/9] parallels: validate bitmap L1 table size before allocating it Date: Wed, 22 Jul 2026 19:05:23 +0200 Message-ID: <20260722170527.2593225-6-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260722170527.2593225-1-den@openvz.org> References: <20260722170527.2593225-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::334; envelope-from=den@openvz.org; helo=mail-wm1-x334.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1784739987744158500 Content-Type: text/plain; charset="utf-8" parallels_load_bitmap() allocated the L1 table sized directly from the untrusted l1_size field, only cross-checking it against the bitmap's actual size after the allocation and the L1 table copy had already happened. Compute the expected size and reject a mismatch before touching the allocator, instead of after. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels-ext.c | 33 ++++++++++++++++++++------------- 1 file changed, 20 insertions(+), 13 deletions(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 3410daa620..97744c9696 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -70,20 +70,11 @@ parallels_load_bitmap_data(BlockDriverState *bs, const = uint64_t *l1_table, uint64_t offset, limit; uint64_t bm_size =3D bdrv_dirty_bitmap_size(bitmap); uint8_t *buf =3D NULL; - uint64_t i, tab_size =3D - DIV_ROUND_UP(bdrv_dirty_bitmap_serialization_size(bitmap, 0, bm_si= ze), - s->cluster_size); - - if (tab_size !=3D l1_size) { - error_setg(errp, "Bitmap table size %" PRIu32 " does not correspon= d " - "to bitmap size and cluster size. Expected %" PRIu64, - l1_size, tab_size); - return -EINVAL; - } + uint64_t i; =20 buf =3D qemu_blockalign(bs, s->cluster_size); limit =3D bdrv_dirty_bitmap_serialization_coverage(s->cluster_size, bi= tmap); - for (i =3D 0, offset =3D 0; i < tab_size; ++i, offset +=3D limit) { + for (i =3D 0, offset =3D 0; i < l1_size; ++i, offset +=3D limit) { uint64_t count =3D MIN(bm_size - offset, limit); uint64_t entry =3D l1_table[i]; =20 @@ -124,12 +115,14 @@ static BdrvDirtyBitmap * GRAPH_RDLOCK parallels_load_bitmap(BlockDriverState *bs, uint8_t *data, size_t data_siz= e, Error **errp) { + BDRVParallelsState *s =3D bs->opaque; int ret; ParallelsDirtyBitmapFeature bf; g_autofree uint64_t *l1_table =3D NULL; BdrvDirtyBitmap *bitmap; QemuUUID uuid; char uuidstr[UUID_STR_LEN]; + uint64_t bm_size, tab_size; int i; =20 if (data_size < sizeof(bf)) { @@ -164,6 +157,17 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *d= ata, size_t data_size, return NULL; } =20 + bm_size =3D bdrv_dirty_bitmap_size(bitmap); + tab_size =3D DIV_ROUND_UP( + bdrv_dirty_bitmap_serialization_size(bitmap, 0, bm_size), + s->cluster_size); + if (tab_size !=3D bf.l1_size) { + error_setg(errp, "Bitmap table size %" PRIu32 " does not correspon= d " + "to bitmap size and cluster size. Expected %" PRIu64, + bf.l1_size, tab_size); + goto fail; + } + l1_table =3D g_new(uint64_t, bf.l1_size); for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { l1_table[i] =3D ldq_le_p(data); @@ -171,8 +175,7 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *da= ta, size_t data_size, =20 ret =3D parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitmap, e= rrp); if (ret < 0) { - bdrv_release_dirty_bitmap(bitmap); - return NULL; + goto fail; } =20 /* We support format extension only for RO parallels images. */ @@ -180,6 +183,10 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *d= ata, size_t data_size, bdrv_dirty_bitmap_set_readonly(bitmap, true); =20 return bitmap; + +fail: + bdrv_release_dirty_bitmap(bitmap); + return NULL; } =20 static int GRAPH_RDLOCK --=20 2.53.0 From nobody Sat Jul 25 08:04:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1784740014; cv=none; d=zohomail.com; s=zohoarc; b=Yj54vdKCd24XgyN2d7T4MZc1f+QMDy//219gzvLxXNsFdwMqmt3qqdNKMF2fg52zBn12OHyCvRQNGTYcLNCZRo1OiVuKFxANKHpPI5ay1mlCQgo572gAEK9Uujc2hM1xW9x+u10/S4eDd+M01pNZY398cCgafHJbmivfGuHObKQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784740014; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7pAFxtzfR1kXmS5OJ99MnGy/nFG6E2fuCMA2MDYotSI=; b=moIdjmoQuNxrE8V/FKlKw11VL9LEOJwQNhEaVs8SSc+8zd/98rSuagHccFeLp2y5TK7W78i4PtAr1f6dvFeRuKpuJ1DMx3HX5Ido2YoxFVT+ZJnHNt8zK6jAVvbX6zco9xoPgM7nCsylTvx2c2CNywgBiMcmaAAKWg8Z+gT6ygg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784740014939853.279319394216; Wed, 22 Jul 2026 10:06:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmaOE-0005EG-0s; Wed, 22 Jul 2026 13:05:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmaO5-0005Co-Hh for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:41 -0400 Received: from mail-wm1-x335.google.com ([2a00:1450:4864:20::335]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wmaO3-0001Zw-78 for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:41 -0400 Received: by mail-wm1-x335.google.com with SMTP id 5b1f17b1804b1-4954a2e73a9so36469695e9.3 for ; Wed, 22 Jul 2026 10:05:38 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:9c54:c407:8170:580d]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956b7483f0sm63993215e9.3.2026.07.22.10.05.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:05:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1784739938; x=1785344738; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=7pAFxtzfR1kXmS5OJ99MnGy/nFG6E2fuCMA2MDYotSI=; b=rNuPAx453FfBIvjARgpu4wf93+8uoVdf2jexSPMm51qvam1e5cPupH1tasBuL4qQL0 CaoRr/CxZ1s9HofRO8NjxRaLz0Qk118mbYPvK9Z2JkvbLDJQV5eSfXQe4tfZBK2wBNEz BTMf9KNRjFiJ0AEEAz/95Xk+HutoSGb+C/ojL5kCLFPxBttatJGjVGoOjVqKkkJHwHQG Zwj8/MV6Me0dussx+oSU7gXYy3W7NfWlE3THuPYn4JjyKQGGLJWDZsDt09d8V5F0sAO0 qrl/4duaHU0st9dI6FfGHeXwjbPy4oRntWl08P3/7eDSyCKgU7nVy6yFvf3IEazrmd4O JKAg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784739938; x=1785344738; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=7pAFxtzfR1kXmS5OJ99MnGy/nFG6E2fuCMA2MDYotSI=; b=Km6ct+QIIjTHf6L9eBP7d1FPoLt1Ji1d865XVPxYPDamYSEnHGbHDIYjzmzPcghTk0 w5NarzmwPVJtPzmILJf8DcFtBDFnAcaFVWg1I+0Te2hb6qjQ99Yr9hYQGvOPAhNl4yvC 15aYEX9vZ2TCwKBYYbXO7Z60cO1cHg/B8TK4fnjhhq7OKmDLopUE9t+Xf3CUiyv/WQSa q04bQS0q15V18SlOeqL/hilBG6fOknb8RFO7XwY9pg0NGWJwuI5IDu0BCgOVwvZ9mbi+ 9Qof2EOBydGBexc7DfECU5S6S03m8td162tXTRGpCzKh+AGm7mpLW6nyQHD38GVNEOWH XpyQ== X-Gm-Message-State: AOJu0YzYbri2S4WBKdsqgfaAWeUMBFY3memDuxSBhGI3L9lfww3OBpoK NzXiNskemrFsft+suzz2XD6Oo83I+FmTHaxMeMd4JmAn/uqrkouj42keo4M4xJjSTZ0Pe9522OO 6vSUx X-Gm-Gg: AR+sD12Jxy1i6xgSDcKsDNsGPDeeOj8aL4Ptjb3JUDeiYIM32I7KcF9Q3ada0F+qMDc 6HfDPs23MSmOhroPNGz+uMFc2dbyuEfxCjQy+G9AL51zwcinF/ROE0vr9hooGazlCkdKtBlQ7qV 5R6ODFFeA+dGYO8ch2PcvS26Rtj92kd0D2fCbZIimW0tascm84E99ESQs423t/QBNXALHSoRvE1 0cmFJOCXcpO5kLh7WCiAjFKgHMPcdHLGrPoPtnjXMXqo5elZaMdLHpgcsv/3mu8X7rWW4UBodup wFq1c0lOipmU/q/QnYk0IzQzEw4DcJ6TpYhbhBaA/SGNl4Nh95jE4JMvHYVWHUraZoCIVjKSwmB HZrmSWi+JeYwrr1/Hf9FrjTNUE2A8iGnTFQYwdVg2uHAujprlCIIJYX3IUJ+Yg3Ys2ekOe9zVjU p4SXNSYH29mg== X-Received: by 2002:a05:600c:574d:b0:492:4a50:41fe with SMTP id 5b1f17b1804b1-4954a405e58mr190434835e9.22.1784739937725; Wed, 22 Jul 2026 10:05:37 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org, qemu-block@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PATCH 6/9] parallels: skip loading a genuinely empty bitmap L1 table Date: Wed, 22 Jul 2026 19:05:24 +0200 Message-ID: <20260722170527.2593225-7-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260722170527.2593225-1-den@openvz.org> References: <20260722170527.2593225-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::335; envelope-from=den@openvz.org; helo=mail-wm1-x335.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1784740015511158500 Content-Type: text/plain; charset="utf-8" parallels_load_bitmap_data() unconditionally calls bdrv_dirty_bitmap_deserialize_finish() even when there is nothing to deserialize, which hits an assertion in hbitmap (hbitmap_iter_init: 'pos < hb->size') when the bitmap itself has zero size, i.e. the disk is a zero-sector image. Skip allocating, populating and loading the L1 table entirely when l1_size =3D=3D 0. This is safe only because the previous commit already guarantees l1_size =3D=3D 0 exclusively means the disk has 0 size. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels-ext.c | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 97744c9696..704e16e1de 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -168,14 +168,17 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *= data, size_t data_size, goto fail; } =20 - l1_table =3D g_new(uint64_t, bf.l1_size); - for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { - l1_table[i] =3D ldq_le_p(data); - } + if (bf.l1_size !=3D 0) { + l1_table =3D g_new(uint64_t, bf.l1_size); + for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { + l1_table[i] =3D ldq_le_p(data); + } =20 - ret =3D parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitmap, e= rrp); - if (ret < 0) { - goto fail; + ret =3D parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitma= p, + errp); + if (ret < 0) { + goto fail; + } } =20 /* We support format extension only for RO parallels images. */ --=20 2.53.0 From nobody Sat Jul 25 08:04:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1784739985; cv=none; d=zohomail.com; s=zohoarc; b=RvV+cKzvA6WwczvWsxnpUEHCFxGlyKb0tQLGR7OfacwpHlxozx0ypLnJZhk7nbb5lWNr0v4bcxa4H258uDqrh2MmB/NwhFEGDV8Am+5ziIZQrwlvQa5vaTQN3zFj5K30akkj9ccKImR3chPD+wFQ/uG/6lNVKvARdLI8+MCOsZI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784739985; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yfUxWo9DRfnzypPrGvcp6jHwrWI7DnwyNSb11uKFohg=; b=JGAu+GPpmWp76lqgjgKWMhMnBzUYjafXMSHEm2xVpS5QqNK3wzyjRzXe1UU+CTMtdR/7CkRPtupWS1Qw28s7bcSM1v8dSE2UFPwYeTUAVBQ+6Hhppq6cVoBtEL9I+lyYMAuLfI/cUR5/E1+pgJ9zgW49y9sT1XJmG8XX2DoO2tU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784739985903750.4726957930558; Wed, 22 Jul 2026 10:06:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmaOK-0005FB-OH; Wed, 22 Jul 2026 13:05:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmaO6-0005DE-6u for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:42 -0400 Received: from mail-wm1-x331.google.com ([2a00:1450:4864:20::331]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wmaO4-0001aJ-3n for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:41 -0400 Received: by mail-wm1-x331.google.com with SMTP id 5b1f17b1804b1-495437bb891so53564515e9.1 for ; Wed, 22 Jul 2026 10:05:39 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:9c54:c407:8170:580d]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956b7483f0sm63993215e9.3.2026.07.22.10.05.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:05:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1784739939; x=1785344739; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yfUxWo9DRfnzypPrGvcp6jHwrWI7DnwyNSb11uKFohg=; b=UfiLf6IQmGYZoAsI545lPW1kNHGgT9JDqG+RIjZJBNWv/xs2yI8FhQ5/F1SIAh9NpR +tyLcdbwC9upBn0D+o8zhvLB0wD/CjPk9kuu2RYEvEO081oVrbOZCkaSYbkEOOQgfo78 RuAV4Z9XG7ANC6sCQ/V/tcrcjWHvFYlcGExBsrZX9icZZ7I/B/atXDHE1TRiDNQ6WlTy VHKrU0Q11ETevvylHgG44n6g025NVEY/pzv8lpIfYnXmJmubI7LrGvgSEYJq6vmVIA17 5wEtFuo9Xpw6m0hs7JF9zQ8YsKguhRepiJxnzesLgh6BqeLR6hQD9MhpmVi7LqvuExdS k1aA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784739939; x=1785344739; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=yfUxWo9DRfnzypPrGvcp6jHwrWI7DnwyNSb11uKFohg=; b=g7472v55rkbxd2z9yWyMCyx4QVz5GkfN7sEnTbTVFVOugX1hueilzlFUAEOy4rKQd/ 83P1qcvQanOZWYvdSwNhxJS6T/nBHU2R9oQuBiAQpuoHCNXM28uYhsVsIbA2LKa7AaKi yV9OrpxFg1f3gPbzQJ4c6eXhcrJN40by8tEkTZtH3L4IwD1EnSYkEV0nURNx11mN+Qtg Xn/FghIH3/ibimsgr/uH2Z2SOf9tupSp0cezriy+PUV0yJijtbsj+Iq9GF2rcOUnaeJt iUStwkDHHMFTR3mp8RynR9E5gy+TFX4nobdNQYkRuxrUP9wGs9NkCf26M64dUtxvF++x Bs/w== X-Gm-Message-State: AOJu0YySzywTeqvwQpMUxIbS3j3Q5eLy2GKLXpai/jFj2/dgp7Fd2TVn T+fh+PvL/g8rxdZXcwWs5dbrik6P819szCyZOUe5L6naYCP8L2WBVd33jRqNF8e0tcGep1p2tMS BEgeW X-Gm-Gg: AR+sD10RBlRZip0sEAqXoxCpezcUhnTmupALsZ+ZdSJsgLHOPdgBsDNYGJ0rl6KVv7n YT087h7KZXV6mHPSFj3B7i5U8IJ/eYRWbu4bb0msWiMjMsT+GHwgDREGwEPo8VPOoGq4ZDJX43M YvMOe7lrlt/JkTgQObSON5XmOTzISG1btY4qzvstKYNb9ftEkGkCEeFGTJWaqOseKMu5sWjXMgi YFeesEmsBfWonBcIX2obawO0ZHogJ3cy574OJOwKRR1vM0x05iS3QvVv8SAmnu8Ko3gimmO9253 imILTMmNTdKgPByHaaCIwRAJ0+oKzA2ub1XBlQMT+QwpSo0d4RI+JlfZQE3yymqvBTSfoKjf6q/ cgcsMjVk0IE/FOHgW3s6zfPAXL9KSlYUi1Q9YGX6aqOOLsXGdlLJIg3awz3EoPzQMsJJhTseO2o c= X-Received: by 2002:a05:600c:4f88:b0:493:b698:9247 with SMTP id 5b1f17b1804b1-4956a50fe9dmr58627915e9.14.1784739938686; Wed, 22 Jul 2026 10:05:38 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org, qemu-block@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PATCH 7/9] parallels: avoid fatal abort on large bitmap L1 table Date: Wed, 22 Jul 2026 19:05:25 +0200 Message-ID: <20260722170527.2593225-8-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260722170527.2593225-1-den@openvz.org> References: <20260722170527.2593225-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::331; envelope-from=den@openvz.org; helo=mail-wm1-x331.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1784739987582158500 Content-Type: text/plain; charset="utf-8" parallels_load_bitmap() allocated the L1 table with g_new(), which aborts the whole process on allocation failure instead of returning an error. Use g_try_new() and fail the open normally. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels-ext.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 704e16e1de..7f6ab6b0d2 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -169,7 +169,13 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *d= ata, size_t data_size, } =20 if (bf.l1_size !=3D 0) { - l1_table =3D g_new(uint64_t, bf.l1_size); + l1_table =3D g_try_new(uint64_t, bf.l1_size); + if (!l1_table) { + error_setg(errp, "Failed to allocate the bitmap L1 table " + "(%" PRIu32 " entries)", bf.l1_size); + goto fail; + } + for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { l1_table[i] =3D ldq_le_p(data); } --=20 2.53.0 From nobody Sat Jul 25 08:04:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1784740027; cv=none; d=zohomail.com; s=zohoarc; b=K97ABhUTkHXW6V/aBGWO+4WfJhlZoQp9beZWoWxfEYmF71l0FMzmsZSM7PRdcrNTXB2nm3kk4KVrb/8o1lYqFDGmoUGAbyv5U4GGX+jnU3fXOsRdhH1+hXU74EaVEXh0u2DWZLjNoyJIFZ/b3/EOmAJeuIzPW8A2T4OTLJq1TUg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784740027; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=c49tA2kmkgqkYuO/8OxNBkqfpXW7FHoFYG45qhc9Iks=; b=CncMCD9nb5JhGQwYQltHaKtNroMOPeYb8tQL/A3udhE6paaHC2niQs0CDxoK650I+H4b91Cu9EW6Uvx5yUKpruJAEMM2Irdftm9DBtFHgjmKcJIiHjhuOVFbDpLZdUTjQwjbB/nh/nUfYWAtQp65SjDvPRyuSZ/zdbMPLgIh2Qk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784740027577972.2349732428304; Wed, 22 Jul 2026 10:07:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmaOT-0005J6-0w; Wed, 22 Jul 2026 13:06:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmaO7-0005DH-EW for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:44 -0400 Received: from mail-wm1-x334.google.com ([2a00:1450:4864:20::334]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wmaO5-0001ax-I2 for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:43 -0400 Received: by mail-wm1-x334.google.com with SMTP id 5b1f17b1804b1-493f75f7172so99490865e9.1 for ; Wed, 22 Jul 2026 10:05:41 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:9c54:c407:8170:580d]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956b7483f0sm63993215e9.3.2026.07.22.10.05.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:05:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1784739940; x=1785344740; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=c49tA2kmkgqkYuO/8OxNBkqfpXW7FHoFYG45qhc9Iks=; b=HYFKExrTam6DtA/g4VzX6Iu9DPC/Rkq1Gpu9gdLADaS6R4O168IX198r9eFM/EH+dJ 68r/ih82GCBbHNzODfcix+f2nDVYEhhcvgzpERarHujD4o+OFQrSy4chc2h7PpSGWoqW TY0CWl49kzRJVpIv2vfDgJuqqt1v+jSQRok26nTBvtNZ2cUZGiarvJpn69SrcOH70dCC U729lcPbTNlzLTe7pwBJglMEqzTqw6rwEenug8qoUpPSs7B3f3c0A8Y/p+z1WJaORIRL d4RHl7epbI8VfUjtG0CYXUENdn8bMg8Htz817YEUp5pvkvwV20Bo6fGxxvubvmQrNUry oUtA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784739940; x=1785344740; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=c49tA2kmkgqkYuO/8OxNBkqfpXW7FHoFYG45qhc9Iks=; b=mUaMdN83lTP47GfO0ZJJQS+ikvW34YD3M1IdKWn17+6zuDM/WL0DoXqdUo+1WDMbMC xPjvEJcO1XijN5W05AuxIovEnB7pgr8SLP4TGIvK6AZspIttKK3Yi2LxFyxpiWO/5W6J rOWqday9QxqMf7WQ28Jy7GYUaDnCDj+sVV2Dj1Nloa2PA0SNAHKd43Xb9zPpcFl7mHP/ Jq9z+dSZFsVZRTVe0rGOTKmO5W3NCRBsgEOgf6PW8ET/h/4hI3jp6VP/i9j2V/nzRJL9 2Q/XXi9qUPk3XimasAQChcw9yt+LJOxdThXLkjqiGtee3tvFTM1eRwpJOqYcEe4T9TJY +E6A== X-Gm-Message-State: AOJu0Yxyz6/AzRkY6Ey4clRcNRf7CigNAlID5diFVcISmAOM/QLJuAJv Qcf7tjcpqgonqQvuOxmvGKD29uX6f7exmhNRvO79YP2KiJCzDLEf4Tt9LPJi09GWM4pg3ujzd11 jUW0a X-Gm-Gg: AR+sD12uBo++ZdItCRvI8VTvxOkjPBBImmimoeqo3M2HqqR15IEy5hwujklszFHUNy1 AoS6fH1FBQOJm3IZ203ASB+zKPvke028oG7pj7YyfFzg25GXhPFwO0S2RGkFgd6/HaipmHesa9k xITOtNfwl5kYHXT8rnTePNFFnpNYhhNo1AD0UNtZV4aoskfbWLVCoJdM5YChl+Q29aCnV8BlDgU +7fxv3RWr+H4V80CITNL6LQ6QNWloZB1g/u/aa8+Y26orovYD62aBwuLzUXqYanz0vgF+tGcTu/ lAFfnEdgL6M1YkaWcDzPYv5hNYwFa41oNFHPkvOq9znq7IdPdk6v+GvqES5F+TNg/7oPvv7mTS5 tMW3KpAYt04QmPMQlnyh0a9ya5JHvuj6tvtHPKQF3TbvgE7Fj15z9djpaathTiUTIhGeNzSuapN U= X-Received: by 2002:a05:600c:1d25:b0:495:6c44:633f with SMTP id 5b1f17b1804b1-4956c4463c8mr37143635e9.31.1784739939918; Wed, 22 Jul 2026 10:05:39 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org, qemu-block@nongnu.org Cc: den@openvz.org, Feifan Qian , Thomas Huth , Stefan Hajnoczi Subject: [PATCH 8/9] parallels: validate BAT capacity against advertised disk size Date: Wed, 22 Jul 2026 19:05:26 +0200 Message-ID: <20260722170527.2593225-9-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260722170527.2593225-1-den@openvz.org> References: <20260722170527.2593225-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::334; envelope-from=den@openvz.org; helo=mail-wm1-x334.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1784740029534158500 Content-Type: text/plain; charset="utf-8" parallels_open() copied nb_sectors, tracks, and bat_entries from the image header without checking that the BAT actually covers the advertised virtual disk size. An image whose header claims more sectors than its BAT covers passes the generic block-layer bounds check on open. A write into the gap between BAT coverage and the advertised size then reaches allocate_clusters(), whose internal assert(idx < s->bat_size && idx + to_allocate <=3D s->bat_size) aborts the process instead of returning a normal I/O error. Reject such images at open time by requiring bat_size * tracks >=3D total_sectors, matching the invariant that allocate_clusters() already assumes. Reported-by: Feifan Qian Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3804 Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 6 ++++++ tests/qemu-iotests/tests/parallels-checks | 21 +++++++++++++++++++ tests/qemu-iotests/tests/parallels-checks.out | 7 +++++++ 3 files changed, 34 insertions(+) diff --git a/block/parallels.c b/block/parallels.c index 8a7e8b4aba..93b5fa9dcd 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -1328,6 +1328,12 @@ static int parallels_open(BlockDriverState *bs, QDic= t *options, int flags, return -EFBIG; } =20 + if ((uint64_t)s->bat_size * s->tracks < bs->total_sectors) { + error_setg(errp, "Invalid image: Catalog size too small for " + "advertised disk size"); + return -EINVAL; + } + size =3D bat_entry_off(s->bat_size); s->header_size =3D ROUND_UP(size, bdrv_opt_mem_align(bs->file->bs)); s->header =3D qemu_try_blockalign(bs->file->bs, s->header_size); diff --git a/tests/qemu-iotests/tests/parallels-checks b/tests/qemu-iotests= /tests/parallels-checks index eef1c86809..66199fff1a 100755 --- a/tests/qemu-iotests/tests/parallels-checks +++ b/tests/qemu-iotests/tests/parallels-checks @@ -225,6 +225,27 @@ echo "=3D=3D an unallocated cluster still reads as zer= oes =3D=3D" # Clear image _make_test_img $SIZE =20 +echo "=3D=3D TEST OVERSIZED VIRTUAL DISK CHECK =3D=3D" + +BAT_ENTRIES_OFFSET=3D32 +NB_SECTORS_OFFSET=3D36 + +TRACKS=3D$(peek_file_le $TEST_IMG $CLUSTER_SIZE_OFFSET 4) +BAT_ENTRIES=3D$(peek_file_le $TEST_IMG $BAT_ENTRIES_OFFSET 4) +COVERED_SECTORS=3D$((BAT_ENTRIES * TRACKS)) + +echo "=3D=3D advertise one more cluster than the BAT covers =3D=3D" +poke_file_le "$TEST_IMG" $NB_SECTORS_OFFSET 8 $((COVERED_SECTORS + TRACKS)) + +echo "=3D=3D open must fail cleanly instead of aborting =3D=3D" +{ $QEMU_IMG info "$TEST_IMG"; } 2>&1 | _filter_qemu_io | _filter_testdir + +echo "=3D=3D write into the uncovered range must fail cleanly too =3D=3D" +{ $QEMU_IO -c "write -P 0x41 $((COVERED_SECTORS * 512)) $CLUSTER_SIZE" "$T= EST_IMG"; } 2>&1 | _filter_qemu_io | _filter_testdir + +# Clear image +_make_test_img $SIZE + echo "=3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D" =20 echo "=3D=3D corrupt image: point first cluster far outside the file =3D= =3D" diff --git a/tests/qemu-iotests/tests/parallels-checks.out b/tests/qemu-iot= ests/tests/parallels-checks.out index 86d5b6ac2d..7b73498271 100644 --- a/tests/qemu-iotests/tests/parallels-checks.out +++ b/tests/qemu-iotests/tests/parallels-checks.out @@ -147,6 +147,13 @@ Child node '/file': read 1048576/1048576 bytes at offset 0 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 +=3D=3D TEST OVERSIZED VIRTUAL DISK CHECK =3D=3D +=3D=3D advertise one more cluster than the BAT covers =3D=3D +=3D=3D open must fail cleanly instead of aborting =3D=3D +qemu-img: Could not open 'TEST_DIR/t.parallels': Invalid image: Catalog si= ze too small for advertised disk size +=3D=3D write into the uncovered range must fail cleanly too =3D=3D +qemu-io: can't open device TEST_DIR/t.parallels: Invalid image: Catalog si= ze too small for advertised disk size +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 =3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D =3D=3D corrupt image: point first cluster far outside the file =3D=3D =3D=3D read-only read must return zeroes, not an I/O error =3D=3D --=20 2.53.0 From nobody Sat Jul 25 08:04:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1784739999; cv=none; d=zohomail.com; s=zohoarc; b=lkzW3iIM8As/nNWnLd17Kpm19e20eXD0/8o2+IVNqBbhfTnBu3pEm8XqJ+MAFgaoohDVunjXVSoVr0k6zEaT3j0Rg1UWzHwXx2L4/obYVJxvMbMXpLIlor0QHufg4D5qEYXXaCSRdhkLeLIN6PvvU8W9pS25wO/105GKSjQC0v0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784739999; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=uhfeGe/4CB094Qsb3YMVun3IRBzdJrjy7hL+hy4mT8o=; b=bc/Uur5WxG9a1/iRC50fD/COIxkJyD4N4nF8rQaGcWqrffmvcDRrEwdTyVkE8PgSMfDA0HjWhshjGERROp3c1We8MWSzyjhY68aGL/S9ZKU8v7sepMPqcLfNl1bCcNAvAmGMa1N59pvCSIRXg4Sz+e9Mf06SCz5uncgsznJgScc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784739999500337.87566381147826; Wed, 22 Jul 2026 10:06:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmaOS-0005Iq-P0; Wed, 22 Jul 2026 13:06:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmaO8-0005De-ST for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:47 -0400 Received: from mail-wm1-x32f.google.com ([2a00:1450:4864:20::32f]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wmaO7-0001bW-8h for qemu-devel@nongnu.org; Wed, 22 Jul 2026 13:05:44 -0400 Received: by mail-wm1-x32f.google.com with SMTP id 5b1f17b1804b1-4954c0833b4so37170115e9.1 for ; Wed, 22 Jul 2026 10:05:42 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:9c54:c407:8170:580d]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956b7483f0sm63993215e9.3.2026.07.22.10.05.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 10:05:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1784739942; x=1785344742; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uhfeGe/4CB094Qsb3YMVun3IRBzdJrjy7hL+hy4mT8o=; b=obpby+CLkN/xw8MotLp2Tsz1rqx1ESd4U64wqCyGD0Ik0YYFcMSC6He9tsX/8pRp19 wb/jhu2aQYknvWAuqjTghgvNqH5WWJ9yZS8reHqvju0ENffS3ojiThzDbxliISmw7/Cz FHAww/BvLbUOLqs3eJ9XGzj1dX9jVZCRLC89fhi2O02VS/6KZfqV+09WcyzZyUN3Jhbi V1EQSDUBl1rMq/gzJ1bkXTJKA2h9DG/RVvpaJsD2q3730tuzsx57TGZM45D+ehUke7au d/dh79FIg0GCghryJBfHwKaBLrCGMvBtQk1VOokF1fLsjYYY1OuNe5zvAzWCDtaavSGh /sag== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784739942; x=1785344742; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=uhfeGe/4CB094Qsb3YMVun3IRBzdJrjy7hL+hy4mT8o=; b=mr9bOrVgf4iLr2ofdi5iOrFh7A3DqBl1p0/xE3fZ9zVVujj8EGZBGxNucAWfBN4/Li a0EImLO3i+1bNhY5wB0PeAtBBb8yPvLc8iHNGzIBoV1C6Mq2u9+U3S5eBYsHTZkcaf4+ T2BSOIWD/O+zmVFasDHS6UvlIJ9Wzyx7rBIPDfL1S0CM3Lm90xDnpbX8QfeRygu3risZ sT0dMfhDiSKyFyvLC++n+Dhz7i/8gGOS2P4ZLs3ttKM6VWJEtwwQPJcbMwrGN1DnWue4 gxP1cnazIm09FrN/B4E7tSZ8VxRngM2Xfd5aQH1V7c8HonoN5frGwpBICDhyy6j9lZ/B ksug== X-Gm-Message-State: AOJu0YyL5GD8Q9b4v6l7NXHCFF85lP4n4aVZIEiZhTZGTJ8K0Arx+lva 2bc1XRu26/oRhJCapzK/Vmj4tnAKlq9IbDq0HoJh1Er+vrolP/SRuUDiytx439Mis3vsFRON/Cn +CmPu X-Gm-Gg: AR+sD13S/HTP2usOd7Bgq9k2f+WV1KWNwV29WPkLwI0QJ5Yed62eFooq2wHYCbYOXQl uj0SjKDAAiTYJ+PK29/a1GF11HLnPgaW7nXC76O5iNHvHS5EdU/NwFzD+Qw3LU7bGXO7U9TP2L/ YF9btfsmH4m+8WLwiyMII8YwJCtsV4cSocT/vs9+IVYluU5mVbyD8ySAg6YHDGxd8AL1giyuj22 Zk+ftLakJ4CmWOYNlNBf2PK1P44ZNPv5qEL3jlIq8e/yuU/Szxae06mExBCCXyvHbxzfhaIi2aR ONtIKM6dZg7BpZ/hIOrnieg5bkDira6ks0CyJ32qqvHkrt37K39Pi5eJ427SAfa5kdybLkDPwoR 7Utn4Ei9EesOAHQSGzCEM9rmYJSqRFJLN3eszBfUYBmEANQYYi99wvbh6aqotf8k7FuNDLUPJGI k= X-Received: by 2002:a05:600c:3b28:b0:493:a623:d090 with SMTP id 5b1f17b1804b1-4954a3f36b6mr272514675e9.10.1784739941881; Wed, 22 Jul 2026 10:05:41 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org, qemu-block@nongnu.org Cc: den@openvz.org, Stefan Hajnoczi Subject: [PATCH 9/9] MAINTAINERS: update parallels tree location Date: Wed, 22 Jul 2026 19:05:27 +0200 Message-ID: <20260722170527.2593225-10-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260722170527.2593225-1-den@openvz.org> References: <20260722170527.2593225-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::32f; envelope-from=den@openvz.org; helo=mail-wm1-x32f.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1784740001398158500 Content-Type: text/plain; charset="utf-8" src.openvz.org is become unmaintained, point to the GitLab tree instead. Signed-off-by: Denis V. Lunev CC: Stefan Hajnoczi --- MAINTAINERS | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/MAINTAINERS b/MAINTAINERS index a28935c898..902db77218 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -4393,7 +4393,7 @@ F: block/parallels.c F: block/parallels-ext.c F: docs/interop/parallels.rst F: docs/interop/prl-xml.rst -T: git https://src.openvz.org/scm/~den/qemu.git parallels +T: git https://gitlab.com/dlunev/qemu.git parallels =20 qed M: Stefan Hajnoczi --=20 2.53.0