From nobody Mon Sep 28 02:01:23 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785235467; cv=none; d=zohomail.com; s=zohoarc; b=b11C4HcuxvM3vmEMTTNto+q0qZUi3m2FyTlOWCL3O7i/M5Kt/nbJTVHHaDQn1BVlCZ3KZz2MsaSNrsbeXcLDEFn/YxG6xTFKCBo9u4mTvXtNwlLzsjjM1FR4DV7m6O/IQPh7TufDsmr4DlZzwZHl6xGm8gwcL0MZ+W8zoTpjP6o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785235467; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6peXfCAI9PBCc+mW0GS1f5pARDqtu1ectajEcLcGxc4=; b=kvoTXVGz22/1+FN8t1o8it0E8S29RnwYzlkM3+NFziMJ/GJqqgSoxABdFjnkmWlr8WtBYBYyT0tah7RjLsQP6uo2OMQNN1oB3VhQT+naubknnW/1lVDjM9ym1hm2kVrpcovSjPshMEgACNPcLZ4WoACMZ3Unmt+ie2y6oU6Gq7s= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785235467401261.2962900656661; Tue, 28 Jul 2026 03:44:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wofGZ-00085Y-5Z; Tue, 28 Jul 2026 06:42:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wofGX-00084Q-UX for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:29 -0400 Received: from mail-ed1-x52a.google.com ([2a00:1450:4864:20::52a]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wofGV-0008GV-5A for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:29 -0400 Received: by mail-ed1-x52a.google.com with SMTP id 4fb4d7f45d1cf-69fe400c14aso3782792a12.2 for ; Tue, 28 Jul 2026 03:42:26 -0700 (PDT) Received: from athena ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32c90b4dsm745682266b.35.2026.07.28.03.42.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 03:42:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785235346; x=1785840146; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6peXfCAI9PBCc+mW0GS1f5pARDqtu1ectajEcLcGxc4=; b=f4wKxxHdnTsneEaYLagWRIZFAxSij4aqiitL5/2Olx3WWwSXXu3otwznP4f8xx20AY 9XFsMYdaNqCa5QIldQCiBLRqh4T6HrWdvTadHqgm84Xh4F5gCnrjdaBliFS0OmcKZBiW Nl8j4/dTpMpwmObkDNf96/Z/kfgBJI2P7sfnAUuByrNTHcLpqQBkhiXISIpDs4lv4EK4 epUkmHf7wij7GmI8FmlBy+ze8oBPYifh78gzOkuJ/ZiJ8XNO0h1yThZpiCDmg7JoDPXG h/EXrhffRUlGV5sLdgXD6S60rc5gO6LoaUGWTGxyjmQvROqeqg1OyvaO0KmwFhf0wsc0 mLsw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785235346; x=1785840146; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=6peXfCAI9PBCc+mW0GS1f5pARDqtu1ectajEcLcGxc4=; b=RWNjeRSjo9LOxZJ6lrlX+GzvTVA9cJk78utPGPuqunlkI3h+DtbCYQMKrOkycmKj9G aO6jbUwQQrXqdiP9tk8GNZws29oRXsHi2LsEWyI8LPtfGGF1rADKftsC8GYY9SjDe8J4 F5Imd3Ca7ZkORwgz8gpGODQQU1yQNCXQcicNITHeAHGjxux9AbJyUJDrbtmxeoRQCZti h1Z7wOIR1HGMg2U2keC96dH+a2kAGxFaQhidEhcxbRrc7PhoAqTd2xnRsFqeAp+OU9Mj 1yImYrQ2PUFmJKD+cl/6raYBiMjwQGFnp3v/LqnI1oFNjjoecrJo8Zm33+G8a9YSVzpO 7oJA== X-Forwarded-Encrypted: i=1; AHgh+RoH22UBYVUUo0jGlXnbKyqzjDYBtB3OrXU7l+Mk1D9RjBWU48gDHz6sy3ZRKJlDRZOYkKstXwXrwAdV@nongnu.org X-Gm-Message-State: AOJu0YzcY1qJnyKoy3V1eK0XVVLZopOHHpWsWZs5LVhmE2FYmY5fDOt2 UAXzXvd+2XS9G85AFnJ/70IC8Tj2CnMbmjIsaspJHmnklTAYS4cBoSwK3y7dN2ZH9Kg= X-Gm-Gg: AR+sD12WreBvpWFzfMeGUpa8WHNgwSE+KqxjUhqKaimxBtGDm7vVRU5XRaZ7j7dIy3Q Bg6xmLBLbHeGDOuqUPkOr6u9F+/fS11OOISzi0b10EHAeGta34Hq1UrUI2HXCpjsbnDQHmvkfeT freVcLIiex2IsCeivMKXb3ydriG+jZsE0qefPR5WAFVkEcVwD6LKK0Xw+Y5GgRqwUtrPzW9kXPv tJ+SnkADZhoZ1ZuY2zpH9Crk3DEnOmZEdkq6hl5zLSycqf817r/CT2Kkzp0DSF/bT/GSi1yV+An jLzu/vhbxHEvICr2jt79uqoenpk3RSBvRN4ROHM38FGyV6GIlSF3Tju6rS3wzjU9knMZzkYJxip iLSzAG+0vfqtGnA/k1O5BAbUWBHLtHzXN5ydc4AnJdh/XZRuSv0oHSj1i/zCveqdG4Q== X-Received: by 2002:a17:907:3ea5:b0:c15:ee0d:9a32 with SMTP id a640c23a62f3a-c1f71d86427mr93044566b.21.1785235345700; Tue, 28 Jul 2026 03:42:25 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL 1/9] parallels: fix integer overflow in header size calculation Date: Tue, 28 Jul 2026 12:42:13 +0200 Message-ID: <20260728104221.3981592-2-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728104221.3981592-1-den@openvz.org> References: <20260728104221.3981592-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::52a; envelope-from=den@openvz.org; helo=mail-ed1-x52a.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785235468314158500 Content-Type: text/plain; charset="utf-8" parallels_open() caches bat_entry_off(s->bat_size) - a uint32_t - in a plain int before it feeds into s->header_size. Near the "Catalog too large" bound the value exceeds INT_MAX and overflows on assignment. Match the cached value's type to bat_entry_off()'s return type. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/block/parallels.c b/block/parallels.c index 7a90fb5220..59f00c64a6 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -1240,7 +1240,8 @@ static int parallels_open(BlockDriverState *bs, QDict= *options, int flags, { BDRVParallelsState *s =3D bs->opaque; ParallelsHeader ph; - int ret, size, i; + int ret, i; + uint32_t size; int64_t file_nb_sectors, sector; uint32_t data_start; bool need_check =3D false; --=20 2.53.0 From nobody Mon Sep 28 02:01:23 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785235453; cv=none; d=zohomail.com; s=zohoarc; b=KZHw+nRYL946ITr5BZJtuyQvju6gWX8fPSYLr1wgNv+YRXZxqaR9T9kOEFh1mZ5jYXf5Z5069pLmCA82BtBAogQl1mTYP5eBV9BYwBviolI/RuZ9yYc4jdab9AWU7VOlzX4JMwWu8Iw4gBhm/73zjOpfk5afEfBiytEwP9Dr85Y= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785235453; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bm+t6tVWssOS3Bc74G2+tUbVOT2wab5L0F6cKOp1Il0=; b=O9Oukl4rMGYyHHSnmkQJFK9s1zaw43YN4yL3VvuG71imIYTLIgjlMEzsOSq0zo3a8af8ay/gW6bMm/iSBQms+a1NL85vicGiKw/JJ3i+0GbJQGWTgpEWh5ZUyPQB/v7QjFczQwyL3RxCCq0S/dpptbYMK/W5bk23lGCmfS1reBk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785235453015194.9176459139935; Tue, 28 Jul 2026 03:44:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wofGa-00086p-L4; Tue, 28 Jul 2026 06:42:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wofGY-00085B-FM for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:30 -0400 Received: from mail-ej1-x634.google.com ([2a00:1450:4864:20::634]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wofGW-0008Gf-Hq for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:30 -0400 Received: by mail-ej1-x634.google.com with SMTP id a640c23a62f3a-c1712a04ddaso593249666b.2 for ; Tue, 28 Jul 2026 03:42:28 -0700 (PDT) Received: from athena ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32c90b4dsm745682266b.35.2026.07.28.03.42.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 03:42:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785235347; x=1785840147; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=bm+t6tVWssOS3Bc74G2+tUbVOT2wab5L0F6cKOp1Il0=; b=YHQn9TV9Lj3uVLkdiE/jMSRw5DJ4oOWjO3sjepj44PtcUhG9dvIO5uqUeZ40dVYNwy LUj35iRUT9Gv/VWC97oVAqC8JlVTOoMsmlHC2vbROakoozvyLj59vpVyTGY6zlYFCN2J IBMLn955LhF0DpjRC9t3HQPJNcffIuC9PWtuGKDJvXMEwGKt+U2Cpea8fJzi0wNiFwa1 0saPJ2rUKHLcQAL+7PHxaWxivZ3hfYZJwo5DuLyU1brFKF9vX1xboFhPWgq10/TmsRAn 67kRalYgi3JWnjTZMaXOUxga1ysoZRXsBGdLPHk3/XPRqnxFfZYbt2RltgJUecf47Mi7 MbpQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785235347; x=1785840147; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=bm+t6tVWssOS3Bc74G2+tUbVOT2wab5L0F6cKOp1Il0=; b=Wv9mFAl9rhqdjwKOJOaOL9xGVXToKHHdrapp2qbQDBm27ET6NA+gcbB3gTvAybB4OG IU8fP/uM6bl2zNktD0okXWghr0rol+Q24lQ9XJqtucYaeE3OVPc1yMatWYiAW7FhE2PE niLq+kjBZaqZYnA32kEi7Hf2/mty0/389fcZJATWU1ctthYoth9IFUGViu1tniS4RWnQ U/eWLeipBldoLnrpzturF3e/cZdNzSK8YJpeowoG9gcdcaMQANXOQZJw+YB63Q/aylaO jvSoU0x7KxyO7NG4d/ipgwTSEHnFlOllsArQyLePuKyRgC1nTwolOTyJyBhJ1ksi8HxI aKbg== X-Forwarded-Encrypted: i=1; AHgh+Rr9rp13q82MSOrowEpmnnymYTsuj1GNpRc3bkl6YaFshT87wcjr52FkbexGjXUBPd6xAt6y1fNW+RYY@nongnu.org X-Gm-Message-State: AOJu0YzUE2muJUcyFBKZx4O04R9XDfuhgO2/sTaWPpM8CznPwa2Y8GEv +tM+tkBXZr4YuNsm1dZrf1uJXL09AHwnLzKJqrmUjYSsXEOKTZqoRhZMKtAbHh93qVY= X-Gm-Gg: AR+sD11DPTu886DPhUwHD8UzZuYif9l4GQ9crASzqhQa4jQ43BKMM0d8yqZBGaL3eKE 9MmsWe7isKELreZdsuJyL22TQW4sAP20PHuVY90wmAtyvLQH4auL1mo6zINik4gURQyULFFi53O g7c1uCU0sVSifaPvPi+6WkUGCNggBe7lYt/A+xip3+M81U8fU5AUOZRBpioGDbeXm/jnpTWdJF2 8fWRyUiWdroRDpFOzr7DwODwVXDNIxJGz5ar+o7vWKf1B4Pq2I6HGtBtkEyCGjoSGmEJm5NJ6Yk CVgmic5fVjJdj2lXT+A9K2tL38vpvVInkFsgDakVtPI8rL85FfqNQcgSkwkV5PylETlXbm+ihzn Lr4SI7+5BxVOQBrlQ7fT0v53CnOr3fWMpN8WtM7FfhJN4NHYoi8E0nLEtyPiQHy3BZg== X-Received: by 2002:a17:907:1c93:b0:c16:5855:65a3 with SMTP id a640c23a62f3a-c1f71d2c871mr84993666b.7.1785235346794; Tue, 28 Jul 2026 03:42:26 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL 2/9] parallels: read header/BAT table in bounded chunks Date: Tue, 28 Jul 2026 12:42:14 +0200 Message-ID: <20260728104221.3981592-3-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728104221.3981592-1-den@openvz.org> References: <20260728104221.3981592-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::634; envelope-from=den@openvz.org; helo=mail-ej1-x634.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785235453968158500 Content-Type: text/plain; charset="utf-8" parallels_open() read the whole header+BAT table with a single bdrv_pread() call sized s->header_size. For an image whose catalog approaches the "Catalog too large" bound (INT_MAX / sizeof(uint32_t) entries), that size approaches BDRV_REQUEST_MAX_BYTES, and the block layer legitimately refuses a single request that large, so the image failed to open with a generic I/O error even though the catalog size itself is within the format's documented limit. Read the header and BAT table in fixed-size chunks instead, so the maximum catalog size parallels_open() can actually address matches the bound it already enforces, independent of the file's block-layer alignment requirements. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 17 ++++++++++---- tests/qemu-iotests/tests/parallels-checks | 23 +++++++++++++++++++ tests/qemu-iotests/tests/parallels-checks.out | 17 ++++++++++++++ 3 files changed, 53 insertions(+), 4 deletions(-) diff --git a/block/parallels.c b/block/parallels.c index 59f00c64a6..0f655b58d5 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -52,6 +52,7 @@ #define HEADER_VERSION 2 #define HEADER_INUSE_MAGIC (0x746F6E59) #define MAX_PARALLELS_IMAGE_FACTOR (1ull << 32) +#define PARALLELS_HEADER_READ_CHUNK (64 * 1024 * 1024) =20 static QEnumLookup prealloc_mode_lookup =3D { .array =3D (const char *const[]) { @@ -1241,7 +1242,7 @@ static int parallels_open(BlockDriverState *bs, QDict= *options, int flags, BDRVParallelsState *s =3D bs->opaque; ParallelsHeader ph; int ret, i; - uint32_t size; + uint32_t size, header_off; int64_t file_nb_sectors, sector; uint32_t data_start; bool need_check =3D false; @@ -1311,9 +1312,17 @@ static int parallels_open(BlockDriverState *bs, QDic= t *options, int flags, return -ENOMEM; } =20 - ret =3D bdrv_pread(bs->file, 0, s->header_size, s->header, 0); - if (ret < 0) { - goto fail; + /* A single request s->header_size large exceeds BDRV_REQUEST_MAX_BYTE= S. */ + for (header_off =3D 0; header_off < s->header_size; + header_off +=3D PARALLELS_HEADER_READ_CHUNK) { + uint32_t chunk =3D MIN(s->header_size - header_off, + PARALLELS_HEADER_READ_CHUNK); + + ret =3D bdrv_pread(bs->file, header_off, chunk, + (uint8_t *)s->header + header_off, 0); + if (ret < 0) { + goto fail; + } } s->bat_bitmap =3D (uint32_t *)(s->header + 1); =20 diff --git a/tests/qemu-iotests/tests/parallels-checks b/tests/qemu-iotests= /tests/parallels-checks index b281246a42..8087b03fb9 100755 --- a/tests/qemu-iotests/tests/parallels-checks +++ b/tests/qemu-iotests/tests/parallels-checks @@ -44,6 +44,7 @@ _supported_os Linux SIZE=3D$((4 * 1024 * 1024)) IMGFMT=3Dparallels CLUSTER_SIZE_OFFSET=3D28 +BAT_ENTRIES_OFFSET=3D32 DATA_OFF_OFFSET=3D48 BAT_OFFSET=3D64 =20 @@ -199,6 +200,28 @@ _check_test_img -r all echo "=3D=3D check first cluster =3D=3D" { $QEMU_IO -r -c "read -P 0x55 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir =20 +# Clear image +_make_test_img $SIZE + +echo "=3D=3D TEST HUGE BAT TABLE OPEN =3D=3D" + +# Overflows a single read request, but stays under parallels_open()'s +# own catalog-size cap. +BAT_ENTRIES=3D536870896 +HEADER_SIZE=3D$((64 + 4 * BAT_ENTRIES)) + +echo "=3D=3D advertise a BAT table larger than BDRV_REQUEST_MAX_BYTES =3D= =3D" +poke_file "$TEST_IMG" "$BAT_ENTRIES_OFFSET" "\xf0\xff\xff\x1f" + +echo "=3D=3D grow the file to match, without writing real data =3D=3D" +truncate -s $HEADER_SIZE "$TEST_IMG" + +echo "=3D=3D open must succeed: the header/BAT read is chunked =3D=3D" +{ $QEMU_IMG info "$TEST_IMG"; } 2>&1 | _filter_qemu_io | _filter_testdir + +echo "=3D=3D an unallocated cluster still reads as zeroes =3D=3D" +{ $QEMU_IO -r -c "read -P 0x00 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir + # success, all done echo "*** done" rm -f $seq.full diff --git a/tests/qemu-iotests/tests/parallels-checks.out b/tests/qemu-iot= ests/tests/parallels-checks.out index 9793423111..b47c42cf4d 100644 --- a/tests/qemu-iotests/tests/parallels-checks.out +++ b/tests/qemu-iotests/tests/parallels-checks.out @@ -129,4 +129,21 @@ No errors were found on the image. =3D=3D check first cluster =3D=3D read 1048576/1048576 bytes at offset 0 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 +=3D=3D TEST HUGE BAT TABLE OPEN =3D=3D +=3D=3D advertise a BAT table larger than BDRV_REQUEST_MAX_BYTES =3D=3D +=3D=3D grow the file to match, without writing real data =3D=3D +=3D=3D open must succeed: the header/BAT read is chunked =3D=3D +image: TEST_DIR/t.parallels +file format: parallels +virtual size: 4 MiB (4194304 bytes) +disk size: 1 MiB +Child node '/file': + filename: TEST_DIR/t.parallels + protocol type: file + file length: 2 GiB (2147483648 bytes) + disk size: 1 MiB +=3D=3D an unallocated cluster still reads as zeroes =3D=3D +read 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) *** done --=20 2.53.0 From nobody Mon Sep 28 02:01:23 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785235422; cv=none; d=zohomail.com; s=zohoarc; b=P8xiWBl9tg07gZ4pQoeSxIUn+hBubjmteWe/LQGN6fm7GEpHZySsLCWb2ge9iNvpQJhQMyo3mHlgKji9a14LOTIvPO0TWc1cCIEBVkHWMXmAMEc90IEqBypangLh8uEP0S9UwNfI4FDVgqX+7KekTEDbiaVLEdv4+13r44L64q0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785235422; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/g2p3N4kfpkZuJaxI9UjRhwniulc+lWWhKKajqjETAQ=; b=LH9+07LxhhKOCV4FCrl7f+WjiojVW0euWqfsNclLpxy3scTf5qDvgmzGv4UkBZnH9sQg3YKfOdayTZ5mAqi+cB9qabifwpYTvcyeOlgxRkAQbSls2Szb+q8m/sMLnHh1cieYLvMK/FHQ6ZRS2Y3RkMnbMKhhCyllz2OfhWVtnVw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785235422484103.88675448659728; Tue, 28 Jul 2026 03:43:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wofGb-00086z-0r; Tue, 28 Jul 2026 06:42:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wofGZ-00085u-Kn for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:31 -0400 Received: from mail-ej1-x62e.google.com ([2a00:1450:4864:20::62e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wofGX-0008H5-Lt for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:31 -0400 Received: by mail-ej1-x62e.google.com with SMTP id a640c23a62f3a-c1740c36c5cso517481866b.2 for ; Tue, 28 Jul 2026 03:42:29 -0700 (PDT) Received: from athena ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32c90b4dsm745682266b.35.2026.07.28.03.42.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 03:42:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785235348; x=1785840148; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/g2p3N4kfpkZuJaxI9UjRhwniulc+lWWhKKajqjETAQ=; b=IKh93pawvEqa8NYZoolfKngH2Wi9n79FKNTFWNxXL/Hm5kRK5P63gT1fe+frY+fMSW N7lIbCKLXsfmGDOEs4JNc+0GaScWbznOqKpzeNjjvEDgTl9y4SndeIQ+PFGXBUWlo+lb rxj+tAxOhcRY3tfnk/wznUEFubPMm+9Ns/5GWkFB1XUDQDq1wZ4SDbikcqDHBUir+4fI J8P61PVKv68M4XtOp53Abjx6WBssbV3ASfgbnHQT8b0yRV84Ee6+mE0RWudVk3bb/ZGP 7rtecd6Vt7YlQjjgry2puMuGSE9KkCqMI9CosBVeLCUlO8FXMwd/MH78XOKqzvLoFYLG /WoQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785235348; x=1785840148; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/g2p3N4kfpkZuJaxI9UjRhwniulc+lWWhKKajqjETAQ=; b=COSHvcHNRMxLaivR8m519RwOVHcgsxCy4TRYDtkRQclpI9TXO+Pe/s1z59l/LfTeAM qyxEOJql3TM8CY3MS0frQtyc1yRXEE+cNekWoF7fnTrrCdkLVAAGE4/hyKURRgHbLq/s XnxSmxE5TC9gqs6iSdeRZQtx6HCus2lHzAkR8uJntQEsB+WcfB88jLfVQ9MctNO57mr4 JFySjpI5z520vcuegLQMoOUhFrOomE43xvudFawfTsIs5MEd6nAZS938YfiDsJb4iuMv fvf8gSWVn9FXsXDdiVPqCGiqRWxWbjmLOO/iVVmOEzgR2ebT8n6xfPcsZoAwjrIqyJNB c2/w== X-Forwarded-Encrypted: i=1; AHgh+RqnNB25U5+3biLI2cER+DFGScQOpsNCtudOgWqlx2g7P9uL+HBWWDYfmdNacnBa719LlHTDMTReiGp8@nongnu.org X-Gm-Message-State: AOJu0Yybf1EUDmE7EOYEZIWSulRySlotFhXtQcYXkawYlqukZj9HhQHZ KtYAFtnuWCysE8xB7pK1TwZFJHd5hpJb8I+SDhVEA3gXPea/CrkFPlynKQQzRZV9r5Q= X-Gm-Gg: AR+sD13o0BHWwlBLmljVhmaL8vWSyYlpQ7ku19Ed8h5pih3SskHFWk1GvEJYXd5/nvk h0+0DE6/c4RVKG2p4+6JlzPPkceHQNr23XMYog6zubTofUVVicx8frinA8A3myPbhmufTkUY/27 DrykO0GDNJrwEDL97mTv0PvDAwEDFpUwtqkiTHwNpeJeBYlzcc+PaMIbsPRgRC4K7Nfq4WOQ9Y+ DxBW8aJKWANtAIoPT6NO+H8fhEB10UTYDIoSUKibun96yFsu9JcVuLua8A80rbBK0JqonXpvTwG AJXRlMXF4Mrrwiq5wOCBEznjvSVZfaXXQi4oUe/XX+RDlqLDKgULLn3Q3LhL/gffYt3zh9Kxa2b hJip0HIyZ+AMQvJRMXKWTdykFk7O83sk+92+q2oVTcDjt7/zQyHufSOfGVE0ORsgUUw== X-Received: by 2002:a17:906:7951:b0:c16:945:97f0 with SMTP id a640c23a62f3a-c1f72223e01mr83211566b.39.1785235348032; Tue, 28 Jul 2026 03:42:28 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL 3/9] parallels: fix bat_entries overflow in image creation Date: Tue, 28 Jul 2026 12:42:15 +0200 Message-ID: <20260728104221.3981592-4-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728104221.3981592-1-den@openvz.org> References: <20260728104221.3981592-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::62e; envelope-from=den@openvz.org; helo=mail-ej1-x62e.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785235423914158500 Content-Type: text/plain; charset="utf-8" parallels_co_create() computed the BAT entry count directly into a uint32_t, wrapping silently to zero at exactly 2^32 entries and writing out a header whose BAT no longer matches its advertised size. Compute it in an int64_t first and reject it once it no longer fits, matching the cap parallels_open() already enforces. Also reject cluster-size 0, and clamp header.cylinders instead of letting it truncate the same way. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 23 +++++++++++++++++------ tests/qemu-iotests/212 | 8 ++++++-- tests/qemu-iotests/212.out | 10 ++++++++-- 3 files changed, 31 insertions(+), 10 deletions(-) diff --git a/block/parallels.c b/block/parallels.c index 0f655b58d5..e3d26a6650 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -999,7 +999,8 @@ parallels_co_create(BlockdevCreateOptions* opts, Error = **errp) BlockdevCreateOptionsParallels *parallels_opts; BlockDriverState *bs; BlockBackend *blk; - int64_t total_size, cl_size; + int64_t total_size, cl_size, bat_count; + uint64_t cylinders; uint32_t bat_entries, bat_sectors; ParallelsHeader header; uint8_t tmp[BDRV_SECTOR_SIZE]; @@ -1017,16 +1018,22 @@ parallels_co_create(BlockdevCreateOptions* opts, Er= ror **errp) cl_size =3D DEFAULT_CLUSTER_SIZE; } =20 - /* XXX What is the real limit here? This is an insanely large maximum.= */ + /* Bounds cl_size so the multiplication below can't overflow int64_t. = */ if (cl_size >=3D INT64_MAX / MAX_PARALLELS_IMAGE_FACTOR) { error_setg(errp, "Cluster size is too large"); return -EINVAL; } - if (total_size >=3D MAX_PARALLELS_IMAGE_FACTOR * cl_size) { + if (cl_size <=3D 0 || total_size >=3D MAX_PARALLELS_IMAGE_FACTOR * cl_= size) { error_setg(errp, "Image size is too large for this cluster size"); return -E2BIG; } =20 + bat_count =3D DIV_ROUND_UP(total_size, cl_size); + if (bat_count > INT_MAX / (int64_t)sizeof(uint32_t)) { + error_setg(errp, "Catalog too large"); + return -EFBIG; + } + if (!QEMU_IS_ALIGNED(total_size, BDRV_SECTOR_SIZE)) { error_setg(errp, "Image size must be a multiple of 512 bytes"); return -EINVAL; @@ -1052,7 +1059,7 @@ parallels_co_create(BlockdevCreateOptions* opts, Erro= r **errp) blk_set_allow_write_beyond_eof(blk, true); =20 /* Create image format */ - bat_entries =3D DIV_ROUND_UP(total_size, cl_size); + bat_entries =3D bat_count; bat_sectors =3D DIV_ROUND_UP(bat_entry_off(bat_entries), cl_size); bat_sectors =3D (bat_sectors * cl_size) >> BDRV_SECTOR_BITS; =20 @@ -1061,8 +1068,12 @@ parallels_co_create(BlockdevCreateOptions* opts, Err= or **errp) header.version =3D cpu_to_le32(HEADER_VERSION); /* don't care much about geometry, it is not used on image level */ header.heads =3D cpu_to_le32(HEADS_NUMBER); - header.cylinders =3D cpu_to_le32(total_size / BDRV_SECTOR_SIZE - / HEADS_NUMBER / SEC_IN_CYL); + cylinders =3D total_size / BDRV_SECTOR_SIZE / HEADS_NUMBER / SEC_IN_CY= L; + /* Write only by spec, do not care */ + if (cylinders >=3D UINT32_MAX) { + cylinders =3D UINT32_MAX; + } + header.cylinders =3D cpu_to_le32(cylinders); header.tracks =3D cpu_to_le32(cl_size >> BDRV_SECTOR_BITS); header.bat_entries =3D cpu_to_le32(bat_entries); header.nb_sectors =3D cpu_to_le64(DIV_ROUND_UP(total_size, BDRV_SECTOR= _SIZE)); diff --git a/tests/qemu-iotests/212 b/tests/qemu-iotests/212 index d4af0c4ac8..4ca6149b6b 100755 --- a/tests/qemu-iotests/212 +++ b/tests/qemu-iotests/212 @@ -133,13 +133,15 @@ with iotests.FilePath('t.parallels') as disk_path, \ # # Maximum size # + # Largest catalog parallels_open() can address. + # iotests.log("=3D=3D=3D Maximum size =3D=3D=3D") iotests.log("") =20 vm.launch() vm.blockdev_create({ 'driver': imgfmt, 'file': 'node0', - 'size': 4503599627369984}) + 'size': 562949952372736}) vm.shutdown() =20 iotests.img_info_log(disk_path) @@ -158,13 +160,15 @@ with iotests.FilePath('t.parallels') as disk_path, \ # 4. 2^63 - 512 (generally valid, but with the image header the file w= ill # exceed 63 bits) # 5. 2^52 (512 bytes more than maximum image size) + # 6. 2^52 - 512 (wraps bat_entries to 0 at the default 1 MiB cluster s= ize) =20 iotests.log("=3D=3D=3D Invalid sizes =3D=3D=3D") iotests.log("") =20 vm.launch() for size in [ 1234, 18446744073709551104, 9223372036854775808, - 9223372036854775296, 4503599627370497 ]: + 9223372036854775296, 4503599627370497, + 4503599627369984 ]: vm.blockdev_create({ 'driver': imgfmt, 'file': 'node0', 'size': size }) diff --git a/tests/qemu-iotests/212.out b/tests/qemu-iotests/212.out index 8102033488..d59f8ed44b 100644 --- a/tests/qemu-iotests/212.out +++ b/tests/qemu-iotests/212.out @@ -69,14 +69,14 @@ virtual size: 0 B (0 bytes) =20 =3D=3D=3D Maximum size =3D=3D=3D =20 -{"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"driver": "parallels", "file": "node0", "size": 4503599627369984}}} +{"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"driver": "parallels", "file": "node0", "size": 562949952372736}}} {"return": {}} {"execute": "job-dismiss", "arguments": {"id": "job0"}} {"return": {}} =20 image: TEST_IMG file format: IMGFMT -virtual size: 4 PiB (4503599627369984 bytes) +virtual size: 512 TiB (562949952372736 bytes) =20 =3D=3D=3D Invalid sizes =3D=3D=3D =20 @@ -110,6 +110,12 @@ Job failed: Image size is too large for this cluster s= ize {"execute": "job-dismiss", "arguments": {"id": "job0"}} {"return": {}} =20 +{"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"driver": "parallels", "file": "node0", "size": 4503599627369984}}} +{"return": {}} +Job failed: Catalog too large +{"execute": "job-dismiss", "arguments": {"id": "job0"}} +{"return": {}} + =3D=3D=3D Invalid cluster size =3D=3D=3D =20 {"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"cluster-size": 1234, "driver": "parallels", "file": "node0", "size": 6710= 8864}}} --=20 2.53.0 From nobody Mon Sep 28 02:01:23 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785235373; cv=none; d=zohomail.com; s=zohoarc; b=Kz5QccJy0zZqB0eNRAEl2Tr+QIgTdbOeiAYgkPOwG+Xz4O7P7xOqP83FzGumTla7MCA9lWLnkkqNK3OvlEXe3Ojt7EKL1vcg8wTOqMyquldy+cYD42k4q3gxNoxruRHcKQ4snI/5UlEH1wsHrBDF/sZL6Nz9Bb8DhDXh4YrT8PY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785235373; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=BhGcypSN9c7MXiKGLST/q5b00sWwo654rqpJZ/LWYcg=; b=BUJwVoJVLRFnsENZsLpE17IJp9V/Q852TseOouMI5L56AJfBFhrgn2sPcit/aZC6dR1fXqzLvjzBM45dOCQpqSvvLQLF+nAUYsbiJpt8oObgX5Z8kFqE9UdeGv0movRjT8aDFD+PtTIlOQbuBIBuhpMny4MZanNRr0jNP4QKF6A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785235373530541.2714251475776; Tue, 28 Jul 2026 03:42:53 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wofGc-000887-Gh; Tue, 28 Jul 2026 06:42:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wofGa-00086r-Ny for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:32 -0400 Received: from mail-ej1-x634.google.com ([2a00:1450:4864:20::634]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wofGY-0008HP-MB for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:32 -0400 Received: by mail-ej1-x634.google.com with SMTP id a640c23a62f3a-c1740c36c5cso517484566b.2 for ; Tue, 28 Jul 2026 03:42:30 -0700 (PDT) Received: from athena ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32c90b4dsm745682266b.35.2026.07.28.03.42.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 03:42:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785235349; x=1785840149; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=BhGcypSN9c7MXiKGLST/q5b00sWwo654rqpJZ/LWYcg=; b=uCbD+IrGPJf3XqfLIqq/MVmMM505mkKORydGuuI8q59tzF1Vx7t6gGg2iJRoM1ilKK Gh0h48kKCgXX2UIIhRJWmwug8+Qb0ZVMqeLE2DPKLUkJzVGeunqt46VGqp0uNOeAsA31 ocn7vRjL3KDYodnbW9tqp5j5X2nXL/OowkOD6G9wUqaD6yjNz8lSIU7OXKasfqkOmYq1 uL9q05l5HSYCqX59XiXMymKn9MQF/fZpbHqnnKvx1Ot54cz0KeMabXhhkVlvHz1mWc8g KdDW4VxIzGwuT6S+UTq1pQSAjomgcxf9mlFr1rEnaWNPzziLT9bVDIHwt50rhktmVM6s /UAw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785235349; x=1785840149; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=BhGcypSN9c7MXiKGLST/q5b00sWwo654rqpJZ/LWYcg=; b=dqg8PdEtTZnZU5hkvyo6Wx+ascFBKVCkLqZU/qvFaiW+BxisdfxBpF2srHo5LHJ3nt vvJsUOdnrvGzshfSTbEYC1t4pIQc//i1ju/kKR+++Izb1qW7OYVumKSDFbt/Dj18nq73 ERwKJ9k5EgbH5B/Ti+dpphRt6a2p7yAuEL2OVxtpBw1SaXELfegzEg3P4fc5NqNrRmFs O7Udr198b3vDBa140L4tBscsP4sTfazNBLDYD0F7QyWr6vhHMla0agGitl2nor7F0hWk WetzRP4ByLi1MVIIvuviBP4U0kl0cAxU35DcKE+8WEMTEkN71RNSXCepd7N+MUr7zzpF SBSQ== X-Forwarded-Encrypted: i=1; AHgh+RoxUIALUVDZeuD8+ZnuaHbL6SqqNtneAv1X6k5v2gcrKLwEdA+j9ikrhaqbO8dLSzJsJNQfACq8nDVt@nongnu.org X-Gm-Message-State: AOJu0YzFMd6RyeQwP9CIa1hFVtMfTH6UPRRwVnUxnOrZaJkJsFocN3E8 Gjdw5mqyJaYYTV26Szuq/zutDYAVgQwysO1EMXdTuwiFGDeJCm4lUomcGBv+ImNxLk8= X-Gm-Gg: AR+sD13PHVfb1GOu+TauxBaH2Iv6HACC3IZLDWodNZFplT9yhOAn8NDkcGK/YYa8RTo pLA2lTuP/F4Z5+OzfqkoDP/4HFlAwaPZ+dMtYE45jUHC5hVUK6banWqjiKXU84WTBuCyvP+dk4z +d3zCNU4tVEswfkp7UVHbj4+vKwk8ivcHwqBCs3xSiQfHuKTy6NaK3w+BIJQSUb6A5DnWHXDZLk ajqYIn4D4yAzBYV8EEYhY2QLqYdrJ7OeNlNPKd4uwi3HZzt+KU0Sx+qRLgOe6BknkQpJLknf4nS YuT7le5dXYS2iFWOWKzwZkM46EHjxS0uClDXqFIcRMOayiSGFyfayIadSXGdLMHIIMOPWRk0soc RITHvraQoRb0Mh2jSsmQ0d/l+8DYmOmZmWdBLllW/zMTwvUImgbSlZ1tpSo4UmmDCgw== X-Received: by 2002:a17:907:d18:b0:c16:589d:c965 with SMTP id a640c23a62f3a-c1f722567a1mr97029166b.46.1785235349187; Tue, 28 Jul 2026 03:42:29 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL 4/9] parallels: reject BAT entries pointing outside backed storage Date: Tue, 28 Jul 2026 12:42:16 +0200 Message-ID: <20260728104221.3981592-5-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728104221.3981592-1-den@openvz.org> References: <20260728104221.3981592-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::634; envelope-from=den@openvz.org; helo=mail-ej1-x634.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785235375823158500 Content-Type: text/plain; charset="utf-8" parallels_open()'s BAT scan and parallels_check_outside_image() only checked entries against the file's upper end, matching just half of what docs/interop/parallels.rst requires: an entry's offset must be both >=3D data_start and < the file size. An entry below data_start resolves into the header/BAT region itself, corrupting metadata on write or losing the write silently on a partial overlap, and neither qemu-img check nor the open-time scan ever caught it. Check both bounds everywhere a BAT entry is resolved to a host offset: seek_to_sector(), the open-time scan (without letting a bad entry inflate data_end), and parallels_check_outside_image(). Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 27 +++++++-- tests/qemu-iotests/tests/parallels-checks | 58 +++++++++++++++++++ tests/qemu-iotests/tests/parallels-checks.out | 35 +++++++++++ 3 files changed, 116 insertions(+), 4 deletions(-) diff --git a/block/parallels.c b/block/parallels.c index e3d26a6650..8a7e8b4aba 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -119,6 +119,7 @@ static uint32_t bat_entry_off(uint32_t idx) static int64_t seek_to_sector(BDRVParallelsState *s, int64_t sector_num) { uint32_t index, offset; + int64_t cluster_off; =20 index =3D sector_num / s->tracks; offset =3D sector_num % s->tracks; @@ -127,7 +128,14 @@ static int64_t seek_to_sector(BDRVParallelsState *s, i= nt64_t sector_num) if ((index >=3D s->bat_size) || (s->bat_bitmap[index] =3D=3D 0)) { return -1; } - return bat2sect(s, index) + offset; + + cluster_off =3D bat2sect(s, index); + if (cluster_off < s->data_start || cluster_off + s->tracks > s->data_e= nd) { + /* Cluster is outside of the image file or overlaps the header. */ + return -1; + } + + return cluster_off + offset; } =20 static int cluster_remainder(BDRVParallelsState *s, int64_t sector_num, @@ -703,18 +711,22 @@ parallels_check_outside_image(BlockDriverState *bs, B= drvCheckResult *res, { BDRVParallelsState *s =3D bs->opaque; uint32_t i; - int64_t off, high_off, size; + int64_t off, high_off, size, data_start_off; =20 size =3D bdrv_co_getlength(bs->file->bs); if (size < 0) { res->check_errors++; return size; } + data_start_off =3D s->data_start << BDRV_SECTOR_BITS; =20 high_off =3D 0; for (i =3D 0; i < s->bat_size; i++) { off =3D bat2sect(s, i) << BDRV_SECTOR_BITS; - if (off + s->cluster_size > size) { + if (off =3D=3D 0) { + continue; + } + if (off < data_start_off || off + s->cluster_size > size) { fprintf(stderr, "%s cluster %u is outside image\n", fix & BDRV_FIX_ERRORS ? "Repairing" : "ERROR", i); res->corruptions++; @@ -1398,11 +1410,18 @@ static int parallels_open(BlockDriverState *bs, QDi= ct *options, int flags, =20 for (i =3D 0; i < s->bat_size; i++) { sector =3D bat2sect(s, i); + if (sector =3D=3D 0) { + continue; /* not allocated */ + } + if (sector < data_start || sector + s->tracks > file_nb_sectors) { + /* Cluster is outside of the image file or overlaps the header= . */ + need_check =3D true; + continue; + } if (sector + s->tracks > s->data_end) { s->data_end =3D sector + s->tracks; } } - need_check =3D need_check || s->data_end > file_nb_sectors; =20 if (!need_check) { ret =3D parallels_fill_used_bitmap(bs); diff --git a/tests/qemu-iotests/tests/parallels-checks b/tests/qemu-iotests= /tests/parallels-checks index 8087b03fb9..eef1c86809 100755 --- a/tests/qemu-iotests/tests/parallels-checks +++ b/tests/qemu-iotests/tests/parallels-checks @@ -222,6 +222,64 @@ echo "=3D=3D open must succeed: the header/BAT read is= chunked =3D=3D" echo "=3D=3D an unallocated cluster still reads as zeroes =3D=3D" { $QEMU_IO -r -c "read -P 0x00 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir =20 +# Clear image +_make_test_img $SIZE + +echo "=3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D" + +echo "=3D=3D corrupt image: point first cluster far outside the file =3D= =3D" +poke_file_le "$TEST_IMG" $BAT_OFFSET 4 1000000 + +echo "=3D=3D read-only read must return zeroes, not an I/O error =3D=3D" +{ $QEMU_IO -r -c "read -P 0x00 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir + +echo "=3D=3D write must allocate a fresh cluster instead of trusting the e= ntry =3D=3D" +{ $QEMU_IO -c "write -P 0x77 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _filte= r_qemu_io | _filter_testdir + +echo "=3D=3D file did not grow anywhere near the bogus offset =3D=3D" +file_size=3D`stat --printf=3D"%s" "$TEST_IMG"` +if [ "$file_size" -lt $((16 * 1024 * 1024)) ]; then + echo "file size sane: yes" +else + echo "file size sane: no ($file_size bytes)" +fi + +echo "=3D=3D data reads back correctly =3D=3D" +{ $QEMU_IO -r -c "read -P 0x77 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir + +# Clear image, with a small cluster size so the BAT table itself spans +# more than one cluster and there is room to point before data_off. +_make_test_img -o cluster_size=3D512 65536 + +SMALL_CLUSTER_SIZE=3D$(peek_file_le $TEST_IMG $CLUSTER_SIZE_OFFSET 4) +SMALL_CLUSTER_SIZE=3D$((SMALL_CLUSTER_SIZE * 512)) +DATA_OFF=3D$(peek_file_le $TEST_IMG $DATA_OFF_OFFSET 4) +echo "cluster size: $SMALL_CLUSTER_SIZE, data offset (sectors): $DATA_OFF" + +# Cluster index 1 starts at this byte offset, which must be < data_off +# in sectors * 512 for this test to actually exercise the bug. +VICTIM_OFFSET=3D$SMALL_CLUSTER_SIZE + +echo "=3D=3D TEST BAT ENTRY POINTING BEFORE DATA AREA =3D=3D" + +echo "=3D=3D corrupt image: point first cluster into the BAT table itself = =3D=3D" +poke_file_le "$TEST_IMG" $BAT_OFFSET 4 1 + +echo "=3D=3D qemu-img check detects it without repairing =3D=3D" +_check_test_img + +echo "=3D=3D bytes at the victim offset before write =3D=3D" +echo "$(peek_file_le "$TEST_IMG" $VICTIM_OFFSET 4)" + +echo "=3D=3D write must allocate a fresh cluster instead of clobbering the= BAT =3D=3D" +{ $QEMU_IO -c "write -P 0x88 0 $SMALL_CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | = _filter_qemu_io | _filter_testdir + +echo "=3D=3D bytes at the victim offset are unchanged =3D=3D" +echo "$(peek_file_le "$TEST_IMG" $VICTIM_OFFSET 4)" + +echo "=3D=3D data reads back correctly =3D=3D" +{ $QEMU_IO -r -c "read -P 0x88 0 $SMALL_CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 = | _filter_qemu_io | _filter_testdir + # success, all done echo "*** done" rm -f $seq.full diff --git a/tests/qemu-iotests/tests/parallels-checks.out b/tests/qemu-iot= ests/tests/parallels-checks.out index b47c42cf4d..86d5b6ac2d 100644 --- a/tests/qemu-iotests/tests/parallels-checks.out +++ b/tests/qemu-iotests/tests/parallels-checks.out @@ -146,4 +146,39 @@ Child node '/file': =3D=3D an unallocated cluster still reads as zeroes =3D=3D read 1048576/1048576 bytes at offset 0 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 +=3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D +=3D=3D corrupt image: point first cluster far outside the file =3D=3D +=3D=3D read-only read must return zeroes, not an I/O error =3D=3D +read 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +=3D=3D write must allocate a fresh cluster instead of trusting the entry = =3D=3D +Repairing cluster 0 is outside image +wrote 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +=3D=3D file did not grow anywhere near the bogus offset =3D=3D +file size sane: yes +=3D=3D data reads back correctly =3D=3D +read 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D65536 +cluster size: 512, data offset (sectors): 2 +=3D=3D TEST BAT ENTRY POINTING BEFORE DATA AREA =3D=3D +=3D=3D corrupt image: point first cluster into the BAT table itself =3D=3D +=3D=3D qemu-img check detects it without repairing =3D=3D +ERROR cluster 0 is outside image + +1 errors were found on the image. +Data may be corrupted, or further writes to the image may corrupt it. +=3D=3D bytes at the victim offset before write =3D=3D +0 +=3D=3D write must allocate a fresh cluster instead of clobbering the BAT = =3D=3D +Repairing cluster 0 is outside image +wrote 512/512 bytes at offset 0 +512 bytes, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +=3D=3D bytes at the victim offset are unchanged =3D=3D +0 +=3D=3D data reads back correctly =3D=3D +read 512/512 bytes at offset 0 +512 bytes, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) *** done --=20 2.53.0 From nobody Mon Sep 28 02:01:23 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785235426; cv=none; d=zohomail.com; s=zohoarc; b=n2d3Bzv/RKH+Ff0DnP8+IHGl5bDaIw4FyTPrPssUARJnr3v/6WzY/eu6BqATGw4AmIamIctkSC8emxmsSBjBRhkHCNtaBbJjRRghf7s0+poKK5g+tu/ynWgc0fiqmRsQ1ztS4Zd+vKoysdC5eHVpL1blv7/rEmSDKnc2I3rnj8w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785235426; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=aVkbd/prjb9WYwlM7SXvDF45HVgnD6g6uz+iwnib8ps=; b=EnEpPRMlZ7MZGnqLg7GxoraHu09ppn/k5r6UO8J4njCpbNqOQF9C41+p3ee9ONIjXMBrJ9zleXB6S2kIivTi29g5VU6gN6khdlVSm9GhSLo6Fn8eeKwhHDHEp9gG2KtkYwznT73Z6yUfJcmKaeC8nw4gqlDxo2s9YgP7Iu7Mamk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785235426910834.2693647250778; Tue, 28 Jul 2026 03:43:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wofGd-00089C-8v; Tue, 28 Jul 2026 06:42:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wofGb-00087X-MZ for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:33 -0400 Received: from mail-ej1-x62c.google.com ([2a00:1450:4864:20::62c]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wofGZ-0008Hq-Uk for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:33 -0400 Received: by mail-ej1-x62c.google.com with SMTP id a640c23a62f3a-c15e03c2763so151890466b.0 for ; Tue, 28 Jul 2026 03:42:31 -0700 (PDT) Received: from athena ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32c90b4dsm745682266b.35.2026.07.28.03.42.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 03:42:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785235350; x=1785840150; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aVkbd/prjb9WYwlM7SXvDF45HVgnD6g6uz+iwnib8ps=; b=auBDwRsPvKZneFcBlveMY7ZsDnDSCGOQAhzT7CbJ787+v2njkni/seu2pPxfTU4E2Q YdX2rCsBRMcHLJTZTlhHX7Qt7KUmhbyDl0HyfMvSyZvi3Xa7tEw8jEhDjj9SEUAitD12 QeeDdoZIC1okFjKkSw+4kmPGIgXz92TdScSHmiMpBPdxAVV8olLUJ3uYVSbp1e63eqHU 1FUReB7/ynC9mIhIOFiiRit0+8mDh1CMUzCTvL9bNYHfcz7iESoAEB71HKaL5m390GY4 MJc7muT2Q3UUpfUDf/jn30RCJnyejBr8h88S6GtIxSGe0jpRLmuvq2Xr4SwU9wZFuMtm cwvw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785235350; x=1785840150; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aVkbd/prjb9WYwlM7SXvDF45HVgnD6g6uz+iwnib8ps=; b=T5G0YpeXIjcd6+7kGIwjImtPKrxMInkegwEa1YAgrIZXFoY2Ss+dmBPFaZ6fLUoRxe ordyRgzzL1RV1q5mOjbqN64W8wG0msUnvrQy5Qac3tNAc21X92YSp7KJ4DFjwE6SaTkI XhOrJNHY+nSl0LyDKZZFDuJ4kVZgvOtSBEeI8j1Ht4N2ESdZrbh1x3FbsqLs+pCexMJ0 9NWvJzZUuwry0fD73TCD2RFt4Kt4gsaAvyoxn0DA3YmYf8kEBF7EWOKOTTSvepgJucEI CFUmIbvdK8QOA5nA5rzCwduhYg6nV/szh9WXsT+tRgk/QYmVwPsKK+MkbqHUBBcw5PWD DL0g== X-Forwarded-Encrypted: i=1; AHgh+RrwDEdeujNEzUBjrns7VT8GIHHRo+fIRRz1yXu4ixjwxjFBZcp3SfcUh1rX6kpjlymaa55t+Nvxnst2@nongnu.org X-Gm-Message-State: AOJu0Ywm8O0hZEF0poT6wP31BRNxWcflYhoWZlRR23Zdc2kCDCOkXVuM QvBLGZZLGvvYoB9SjjrRjxPutPbLtN1aoTbJJYmIxGxss2y/wJR724gCJXicnT+fsFs= X-Gm-Gg: AR+sD11SQdu8GPvo9GinNEXdw1Nj8aQe7kLPeifFhyjNe16WBv1kk+on20oN5uW23P9 RAbgjE+OBKq7f+47IBse3Od7g5f9Qrew2opauE7nEthZ4PO4QFqaMYke749ijtacj8MnpdBSs6O z+G1ZDv46syqIxxSoIT//3mpY9auo5hKWZFhrCCPqYOznia1FZ0pswzYN9A0MIB9Mr11sqOzsQ7 WTaXM0xPrXPKOR1vZZE2rmE/EUz0NBb/leP2Zc2xgBm3jbKZYAfxJZjW0xyi1xpofV/BuIs+JpK dH6TJcuoZAfj6DKXAPVkmQYE6h5pbA6AinCDcfaIT3J8a9zIYzqE0HN3vtZRQkZ1g518cfP+BHc GPdISOvjhUlYHUEH9f6iCI67tsX0OybmA/oP9EXH0Ew1pgr4oyurT0FLoEbB5R0AYqA== X-Received: by 2002:a17:907:d408:b0:c16:6dac:a008 with SMTP id a640c23a62f3a-c1f71c85ca3mr106424566b.8.1785235350267; Tue, 28 Jul 2026 03:42:30 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL 5/9] parallels: validate bitmap L1 table size before allocating it Date: Tue, 28 Jul 2026 12:42:17 +0200 Message-ID: <20260728104221.3981592-6-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728104221.3981592-1-den@openvz.org> References: <20260728104221.3981592-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::62c; envelope-from=den@openvz.org; helo=mail-ej1-x62c.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785235427800158500 Content-Type: text/plain; charset="utf-8" parallels_load_bitmap() allocated the L1 table sized directly from the untrusted l1_size field, only cross-checking it against the bitmap's actual size after the allocation and the L1 table copy had already happened. Compute the expected size and reject a mismatch before touching the allocator, instead of after. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels-ext.c | 33 ++++++++++++++++++++------------- 1 file changed, 20 insertions(+), 13 deletions(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 3410daa620..97744c9696 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -70,20 +70,11 @@ parallels_load_bitmap_data(BlockDriverState *bs, const = uint64_t *l1_table, uint64_t offset, limit; uint64_t bm_size =3D bdrv_dirty_bitmap_size(bitmap); uint8_t *buf =3D NULL; - uint64_t i, tab_size =3D - DIV_ROUND_UP(bdrv_dirty_bitmap_serialization_size(bitmap, 0, bm_si= ze), - s->cluster_size); - - if (tab_size !=3D l1_size) { - error_setg(errp, "Bitmap table size %" PRIu32 " does not correspon= d " - "to bitmap size and cluster size. Expected %" PRIu64, - l1_size, tab_size); - return -EINVAL; - } + uint64_t i; =20 buf =3D qemu_blockalign(bs, s->cluster_size); limit =3D bdrv_dirty_bitmap_serialization_coverage(s->cluster_size, bi= tmap); - for (i =3D 0, offset =3D 0; i < tab_size; ++i, offset +=3D limit) { + for (i =3D 0, offset =3D 0; i < l1_size; ++i, offset +=3D limit) { uint64_t count =3D MIN(bm_size - offset, limit); uint64_t entry =3D l1_table[i]; =20 @@ -124,12 +115,14 @@ static BdrvDirtyBitmap * GRAPH_RDLOCK parallels_load_bitmap(BlockDriverState *bs, uint8_t *data, size_t data_siz= e, Error **errp) { + BDRVParallelsState *s =3D bs->opaque; int ret; ParallelsDirtyBitmapFeature bf; g_autofree uint64_t *l1_table =3D NULL; BdrvDirtyBitmap *bitmap; QemuUUID uuid; char uuidstr[UUID_STR_LEN]; + uint64_t bm_size, tab_size; int i; =20 if (data_size < sizeof(bf)) { @@ -164,6 +157,17 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *d= ata, size_t data_size, return NULL; } =20 + bm_size =3D bdrv_dirty_bitmap_size(bitmap); + tab_size =3D DIV_ROUND_UP( + bdrv_dirty_bitmap_serialization_size(bitmap, 0, bm_size), + s->cluster_size); + if (tab_size !=3D bf.l1_size) { + error_setg(errp, "Bitmap table size %" PRIu32 " does not correspon= d " + "to bitmap size and cluster size. Expected %" PRIu64, + bf.l1_size, tab_size); + goto fail; + } + l1_table =3D g_new(uint64_t, bf.l1_size); for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { l1_table[i] =3D ldq_le_p(data); @@ -171,8 +175,7 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *da= ta, size_t data_size, =20 ret =3D parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitmap, e= rrp); if (ret < 0) { - bdrv_release_dirty_bitmap(bitmap); - return NULL; + goto fail; } =20 /* We support format extension only for RO parallels images. */ @@ -180,6 +183,10 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *d= ata, size_t data_size, bdrv_dirty_bitmap_set_readonly(bitmap, true); =20 return bitmap; + +fail: + bdrv_release_dirty_bitmap(bitmap); + return NULL; } =20 static int GRAPH_RDLOCK --=20 2.53.0 From nobody Mon Sep 28 02:01:23 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785235400; cv=none; d=zohomail.com; s=zohoarc; b=O12vOiyzz9EuDFGyHRfGP5df+rMO7+4zZ03gVkOosOQGdMo5pbES0jOQJJtN2gnyXTI22uSgATM+GhsTk1rX/FY2YifiweA9iksIw0h0U+ifz/cziZu3HnBYv2vljcT6fLFta0a87AR8VF8s+vEw9Y05lx+G0fojxu/TWgoQ/Qk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785235400; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7pAFxtzfR1kXmS5OJ99MnGy/nFG6E2fuCMA2MDYotSI=; b=ZafO58QAiz5qrJ6yTXavIToF0yyYfvBsmp1Qa4fXX8W4IGZ7tHy594klVmm8wZV/nwdyoDFsQZfTH8hjVoF9qhN9dsg1AOBNkvKf+kBfXaUghDxj1ZGCZnvYPnvhvZNOGDZB75vWQ2TeiJFJttObR0gXLOGNRNVvLgUVKZFPw2k= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785235400578931.1568415937949; Tue, 28 Jul 2026 03:43:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wofGe-0008AB-Ix; Tue, 28 Jul 2026 06:42:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wofGc-00088B-HU for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:34 -0400 Received: from mail-ej1-x62a.google.com ([2a00:1450:4864:20::62a]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wofGa-0008ID-Q0 for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:34 -0400 Received: by mail-ej1-x62a.google.com with SMTP id a640c23a62f3a-c1f5208b38dso285179966b.0 for ; Tue, 28 Jul 2026 03:42:32 -0700 (PDT) Received: from athena ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32c90b4dsm745682266b.35.2026.07.28.03.42.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 03:42:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785235351; x=1785840151; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=7pAFxtzfR1kXmS5OJ99MnGy/nFG6E2fuCMA2MDYotSI=; b=aufP3M2U1a/N5strIO6MWX7w3ibAe/fppp7DLIl0ioRCXp9Jq4okS4aZxqINKzESzL MpS9Op2i9Ky3VIADTtSTRmIRHoad0+dATcpgJu7jIwPlwxuT18o3IZGMUoQ5oJp2A3Ay AHW1gHLushSfj745dqMTvv1eHhV2EbuJ4IEjdtZ3DT8sqOyl6LWHPjGOearSEwHm6vDX QUBpvykVz5Z+o3KtAItFpFOBiPjtZlO7PEeGQQHWgHB/bwzQpxNT88RkMliAPt4Zqer8 uOFUMSoFa+MUT6w1e0PSDa+54SmXyin26a+LkMW41L+end/RJm72PV+G06DDoWIVBIWc q43Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785235351; x=1785840151; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=7pAFxtzfR1kXmS5OJ99MnGy/nFG6E2fuCMA2MDYotSI=; b=Wdr7CQt1aGYB5MD2MgKw/CH8SfbflzoBOX9AIId6HeNfldCYAj7FBztKZg2vPGMmMf 8ns0fB5/oyWuTO7hADcePe/utytbT6T+NoLbZqchJAAX2ZXV18E3QTd4ITroV3gYt2P4 T6kb3DywmjbSpUZb3URUmUWNxFVqe/Hvctm+FBXE40zQwl1GmOn6Z/OId0mcqzc7Uuqo TsYefNlLl4+yS2NOJ+W3nEmOJOqICRD3wtCD69wQhmeQJ0Vj8Zi0mTcMH9BTqqysIv/h GXbFuD9rufhAFd4wbHxKLSWC5WNhivvD6iZGbJVDGpw+1KBlsCtSA0fHAywfeDPk0YYz ET1g== X-Forwarded-Encrypted: i=1; AHgh+Rp4ebb2OsrlMS8bfo8unO7ES2pKRsgMqSxJVyoTEtwlftK7mWkJO9NHrfaB8XRqz01NTsMD0cf2NgMk@nongnu.org X-Gm-Message-State: AOJu0Yx6PDrN3IpcpEezwVi4h/Sc5NZdsPFMnVZSVru8JaYDwnrw/B/s 6IMsZQFmNblRrJZb/DURYPYEsKQlsqGsQF0XwDvH6ZN7KIxW+mc5508o64tncFE70TU= X-Gm-Gg: AR+sD12pSD33Ndy1+kHQG4xwAW3CunwchbkODqlvLtzddX7lUHfIHykWiRESeZU3jLk aY37PYX7kgkF6GVx8Bada/Q2UUOaCm6zBf74MgvTFZtWRbn+gmAHoS+ZSFFc9mvVp+Gp0KC0LCp /Xk/8AHAYwutTj4NWIZX4AE7H98STynYyekWMkS6NOXIZPRsxetrp1J2iCJLh51DRZKjyNV3ydr orjXWY53TEq3wWnj4ESiuuYqqVMcPhddjp1SKeG1zgrzH1gaqaXGuvwC2JGZHFHfzaXU9wFFHp8 ucqvFbnhdducNv47ccl97HTJi35aCjgGDzTvuWo2P+I+/7Gshs8AJN6v9R/hm+opNpBnD4BghUK qlXT3JWvL48ti/C6qX0mpKIeY5NC2bvt47wXrYTsGHpZ5Wsy/CtYYuMf12tk6g7BBRA== X-Received: by 2002:a17:907:1787:b0:c15:ff7a:e56d with SMTP id a640c23a62f3a-c1f7215114dmr75060166b.51.1785235351335; Tue, 28 Jul 2026 03:42:31 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL 6/9] parallels: skip loading a genuinely empty bitmap L1 table Date: Tue, 28 Jul 2026 12:42:18 +0200 Message-ID: <20260728104221.3981592-7-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728104221.3981592-1-den@openvz.org> References: <20260728104221.3981592-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::62a; envelope-from=den@openvz.org; helo=mail-ej1-x62a.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785235401698158500 Content-Type: text/plain; charset="utf-8" parallels_load_bitmap_data() unconditionally calls bdrv_dirty_bitmap_deserialize_finish() even when there is nothing to deserialize, which hits an assertion in hbitmap (hbitmap_iter_init: 'pos < hb->size') when the bitmap itself has zero size, i.e. the disk is a zero-sector image. Skip allocating, populating and loading the L1 table entirely when l1_size =3D=3D 0. This is safe only because the previous commit already guarantees l1_size =3D=3D 0 exclusively means the disk has 0 size. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels-ext.c | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 97744c9696..704e16e1de 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -168,14 +168,17 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *= data, size_t data_size, goto fail; } =20 - l1_table =3D g_new(uint64_t, bf.l1_size); - for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { - l1_table[i] =3D ldq_le_p(data); - } + if (bf.l1_size !=3D 0) { + l1_table =3D g_new(uint64_t, bf.l1_size); + for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { + l1_table[i] =3D ldq_le_p(data); + } =20 - ret =3D parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitmap, e= rrp); - if (ret < 0) { - goto fail; + ret =3D parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitma= p, + errp); + if (ret < 0) { + goto fail; + } } =20 /* We support format extension only for RO parallels images. */ --=20 2.53.0 From nobody Mon Sep 28 02:01:23 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785235452; cv=none; d=zohomail.com; s=zohoarc; b=SdfS5kv6NjbXCTOu5+74EKWAbhYgJNmSUw1V6qOjrUfef+rlM5hcYCTBOrgHzkMpYA6qxP4iDfn3DND9cccbItG9U4UrggD1G1NyauMhjfRbtYxtln/GSnztYpg8nh7ndEGtUdG44buke9s3VsDGbx7LP6GT4mRvIBT6bZHpbPY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785235452; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yfUxWo9DRfnzypPrGvcp6jHwrWI7DnwyNSb11uKFohg=; b=CYR47/jUYw6g8rkcvfYxLjQr2kM3tH4RgQCnWQfLwD1NyqDZditozVBHxzzey5MjM/y6OFYZft1LX+JmR8ZPzEemGTFuiJ/7rtL5zD2JenxrRP+5XsEo/eeYb1HYk0pyZpaEy3zsx2V0/646kKh3bWW+45kCHcYb5tOLCr1u7H0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785235452632422.88214415467814; Tue, 28 Jul 2026 03:44:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wofGf-0008Ai-1C; Tue, 28 Jul 2026 06:42:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wofGd-00089E-A7 for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:35 -0400 Received: from mail-ed1-x534.google.com ([2a00:1450:4864:20::534]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wofGb-0008IX-MW for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:35 -0400 Received: by mail-ed1-x534.google.com with SMTP id 4fb4d7f45d1cf-698ae09e356so4459565a12.2 for ; Tue, 28 Jul 2026 03:42:33 -0700 (PDT) Received: from athena ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32c90b4dsm745682266b.35.2026.07.28.03.42.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 03:42:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785235352; x=1785840152; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yfUxWo9DRfnzypPrGvcp6jHwrWI7DnwyNSb11uKFohg=; b=e6pUK5Sjvpg9q0SO8BPdZt/Ild5l5AWmtUPJA1YPItdt5yGbw1JuIt6tKAcaFf3G2w rkbiXDQ+s9EqYGDO4gyAnUC6bVu3IJd0YF3ToGM/SS5dPE45wZ5iN4EdL9tzyGdGU7Wc nW8z40JRIsC+3LYMoDGFM2jMpwnULpsZWI3a4tIaO01EbloZnEIlh8NGScaVaPaUSM/c xL/u25urql4TCyDvivvRZ08NNN2OGdP+FiqDdOIzL0LvG7So84SXONe1Ryqlq9j+U0Pn 7CYi+nOBFyFeWIJlG6+e7WIzUx7B6a5snLTjhTZ3s11cive74+YJGbin/vEVGhMQ1yV6 WO/Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785235352; x=1785840152; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=yfUxWo9DRfnzypPrGvcp6jHwrWI7DnwyNSb11uKFohg=; b=TTUPow1V1Jzkst4lUVBLhHVhn15jxVzeqZjIfRQ+vh7kyJr07uD1p35J2OS8o4XlsA CCZ+ygx6Fpy3Q2ewMDlP1vuyjIXFF8ABLdOp6+y1pWc7ry0UiCcai4R38Csm6envHtNb S+ZrLFBzaQHQSUkKLIOodipuheyPEwjoYk7uhmuABLeVhWW8fHi7UImZ4xI8be1UH3qM NBmffybH20168LzLC1m5Ev++Ufspq7Ywg2tSeF9FEqxeWX/CWIdCHlBBoEF8VeScu6Kx DiiudNnGOVrBSPVizrqpzovs6EO/+S8SnTMlGSwf+HENygLGSJ6PJUiajBB/rARowGZp YJsA== X-Forwarded-Encrypted: i=1; AHgh+RpAFDQ1ec+s7CxljPLSZrDWDR2JmKKfQUPc/szlYXCirMV6F/EOyPch5NisfuZkYf1TaSnZKUolgotL@nongnu.org X-Gm-Message-State: AOJu0YxpYcVckiZUQ1d6+szOu4Kmb/WwC5UaZvJA4LLQqz8jnO6Om6yr xJCEZsDqwCN/KZZRQ/GlD7XHLMXtmT5eEWRsAuR04HP4f5J2M9DlNcVjzV5z6dqOI9M= X-Gm-Gg: AR+sD13iUakzlOIQd6jWTfnFwjEYQL5Qv5P7D9aEivG43TxerCDG0rv9yRKa+tT6vpO ZL5Pglwp6zM5K2r2uGv5IY/Q3YG4yNw2X/7SehedJdUWYBO2b+toPS9xrE0/iu4FfoUZVRx2/lk bvaAbvrFsUtMkWgXoCSfGXFRH5oaP8h/pgQkwziOTf/as6xJpAJt+g0M7aCCOkSEUWXtPEaN2mt UcuPMPMful9j2/ZZ+8Tj/03VH3qjCji4aOzwtLevUB4EKWwtItILwxGA03awTYCAqIeiuWuF0P9 H5dCi3iOjQk/DXfKkgzjOmWlVlzbLvVnyN0UAXG8vOhCZTOVse1JvCbRItJgK9gYAsgVAQktxXS Utev8ZMFu6aI5f4JNN/5wtlKq1SjdFr+3GDYchbbvk7Mr5QROrP1bUN2uMM2BYw1AGR+nQqXyxG JE X-Received: by 2002:a17:907:9629:b0:c16:71:d9ce with SMTP id a640c23a62f3a-c1f71d57191mr87457166b.8.1785235352278; Tue, 28 Jul 2026 03:42:32 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL 7/9] parallels: avoid fatal abort on large bitmap L1 table Date: Tue, 28 Jul 2026 12:42:19 +0200 Message-ID: <20260728104221.3981592-8-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728104221.3981592-1-den@openvz.org> References: <20260728104221.3981592-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::534; envelope-from=den@openvz.org; helo=mail-ed1-x534.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785235453912158500 Content-Type: text/plain; charset="utf-8" parallels_load_bitmap() allocated the L1 table with g_new(), which aborts the whole process on allocation failure instead of returning an error. Use g_try_new() and fail the open normally. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels-ext.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 704e16e1de..7f6ab6b0d2 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -169,7 +169,13 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *d= ata, size_t data_size, } =20 if (bf.l1_size !=3D 0) { - l1_table =3D g_new(uint64_t, bf.l1_size); + l1_table =3D g_try_new(uint64_t, bf.l1_size); + if (!l1_table) { + error_setg(errp, "Failed to allocate the bitmap L1 table " + "(%" PRIu32 " entries)", bf.l1_size); + goto fail; + } + for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { l1_table[i] =3D ldq_le_p(data); } --=20 2.53.0 From nobody Mon Sep 28 02:01:23 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785235450; cv=none; d=zohomail.com; s=zohoarc; b=OkFacC/7tFS6TZQ+trB4/2Y3Q7eL42LJnAmruhktqqarmb6DnMvC1X7stRBeHaefbpVy8XhFgpd8/J6zF2lLE/yvNU/qU3ZUfniMlxSgWS2vCqs8UMDY+qRBH3K4LwSa757R1Aq+ZUAnjuHza7BFtDIWGqsAcWsvb35BWUl7MeU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785235450; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=c49tA2kmkgqkYuO/8OxNBkqfpXW7FHoFYG45qhc9Iks=; b=bpnWTfcDOKItHFz3g4fBYaCCjbwVLltIsx8/c4CB/zhuisTe+3u0V7oU+D8Y8mVUpp+CMrBp4tc3L4Y8DgxbZQeE98KUB01CR9O//dUO0cwppzqjm6c+UYQQ/qkf0nK/5BYlvWKt1GkzDGHlFQOI1hYF2AmlaBQLNyM/fKGqv84= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785235449992453.05844575444496; Tue, 28 Jul 2026 03:44:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wofGh-0008Bl-7o; Tue, 28 Jul 2026 06:42:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wofGf-0008Ay-7C for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:37 -0400 Received: from mail-ej1-x631.google.com ([2a00:1450:4864:20::631]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wofGd-0008J0-3g for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:36 -0400 Received: by mail-ej1-x631.google.com with SMTP id a640c23a62f3a-c15f47e6297so394099066b.0 for ; Tue, 28 Jul 2026 03:42:34 -0700 (PDT) Received: from athena ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32c90b4dsm745682266b.35.2026.07.28.03.42.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 03:42:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785235354; x=1785840154; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=c49tA2kmkgqkYuO/8OxNBkqfpXW7FHoFYG45qhc9Iks=; b=tBwCHvH/jIL2R8R/Zj8mOrWhh8kIKwLzSYg2IPyKc3Fy31BNj6KoXYRYaG91Mzv6zo QvlJ9siyMS9mprFOcZrtFdFlfP0X/pix4Dqg4kHvQ39vf2U8C7S1lHZOpzOpNAXcbodo diM4B+yECX1Eh7q+GgiQJ71eJuQdtGG1hrEk/4oh7fXsKpaxBQm3q02U53aY4Dj8wTSB +op3hzHBA3zbjSsgLbdKI31YTS2Zj4NQn4qsHjn98fvXlx5iA7UwV95xot5qpswa9vSi zZwqheBd9jT5CWlAVvY8OyKI/gHILrxole5qzDY4QdxjpbdqdRGaVGCyQnIPSe5oyLjh LkcQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785235354; x=1785840154; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=c49tA2kmkgqkYuO/8OxNBkqfpXW7FHoFYG45qhc9Iks=; b=UYQH15+DJXW2ta3uDiEuoVyBgkrmoLban95OSWcCRqYJDQKYXuvHJfkGZ+fvB0R5Vv cKUjSp/h2y4cX2JX08BCfeQvZQY/1lbpSzXOjG1T67sYPRIkpm/RRIQHe+hRgyh+EXU+ 0fH7OLbcOQEDHSMlHcXh1LDT2TOqkn8bZQ1kaB43ioXTpq/Z/RnzDWO5fLZptk9L47/Y KQuxcwRKVkj8QKrEWTaqrbJazCckXKuYkybkQz1vW9RIj62gqo/P/2GXhwLBR5N2kMG4 oJTWVa364oHeLPa6DmJKt/RlWlJv2RFUxoIBINyn1JKZZ7jDaL5m+5vp9Gr8ahHY9NaI hQyQ== X-Forwarded-Encrypted: i=1; AHgh+RrXJVT6UCiFA9QzV9IE64OkjIIRVukpNjY1Owrdd22mWS2k1lGJ15gJjcC4v62MBciep2PM3yZKjmng@nongnu.org X-Gm-Message-State: AOJu0YxD3mxUEWphqgFXcAl3v/x7pJcmxdPqEon7KHMitPEeut7VMDU5 y2y3dv4QhClcMHpj68ZKTf19ZwoXdMO1RUhjjTxc7mekL/0QJckTIB8DSFVRE+vvbrc= X-Gm-Gg: AR+sD11GrgUNA+1318/L1O+xO7JBrAn9POnM8PBMrKXQF18J7DEiGfg17mruLROy7MG pZQWoWXE2tqqNstpuQ5Mh8IZFcflykaercq/5RkbVL3q0+74QxzSox6N3bAEqfW8BCR6FEpYxjg t3qKOaVz42+IlVrnVOftPUU20axN/ZmCU1eN8aGQm81tS01MMAalLM7Sr2iKrQFkxBYffxghxWa wopC3kjRWk3UODvYB37y2oU9nazYYw75BST7wNMvJBt0tQ7kaNyugwsGjJAKBZq6OMPo1q2KaFP MFZAatia3EZlejB70peRY44swh3LFXWNGMHXTZwlIAAjR5xV+hCOnybhzoNebKBnu4zCdD87EcP ORYdrdrGdI06YvtBV/Vc2/tY/IQxnGnTCUVhzMvuVjgWXVEIj+U0Hy/Su5H5z/KNdvA== X-Received: by 2002:a17:907:d28:b0:c16:4e5:944a with SMTP id a640c23a62f3a-c1f720c6126mr89363866b.21.1785235353586; Tue, 28 Jul 2026 03:42:33 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Feifan Qian , Thomas Huth , Stefan Hajnoczi Subject: [PULL 8/9] parallels: validate BAT capacity against advertised disk size Date: Tue, 28 Jul 2026 12:42:20 +0200 Message-ID: <20260728104221.3981592-9-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728104221.3981592-1-den@openvz.org> References: <20260728104221.3981592-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::631; envelope-from=den@openvz.org; helo=mail-ej1-x631.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785235451977158500 Content-Type: text/plain; charset="utf-8" parallels_open() copied nb_sectors, tracks, and bat_entries from the image header without checking that the BAT actually covers the advertised virtual disk size. An image whose header claims more sectors than its BAT covers passes the generic block-layer bounds check on open. A write into the gap between BAT coverage and the advertised size then reaches allocate_clusters(), whose internal assert(idx < s->bat_size && idx + to_allocate <=3D s->bat_size) aborts the process instead of returning a normal I/O error. Reject such images at open time by requiring bat_size * tracks >=3D total_sectors, matching the invariant that allocate_clusters() already assumes. Reported-by: Feifan Qian Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3804 Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 6 ++++++ tests/qemu-iotests/tests/parallels-checks | 21 +++++++++++++++++++ tests/qemu-iotests/tests/parallels-checks.out | 7 +++++++ 3 files changed, 34 insertions(+) diff --git a/block/parallels.c b/block/parallels.c index 8a7e8b4aba..93b5fa9dcd 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -1328,6 +1328,12 @@ static int parallels_open(BlockDriverState *bs, QDic= t *options, int flags, return -EFBIG; } =20 + if ((uint64_t)s->bat_size * s->tracks < bs->total_sectors) { + error_setg(errp, "Invalid image: Catalog size too small for " + "advertised disk size"); + return -EINVAL; + } + size =3D bat_entry_off(s->bat_size); s->header_size =3D ROUND_UP(size, bdrv_opt_mem_align(bs->file->bs)); s->header =3D qemu_try_blockalign(bs->file->bs, s->header_size); diff --git a/tests/qemu-iotests/tests/parallels-checks b/tests/qemu-iotests= /tests/parallels-checks index eef1c86809..66199fff1a 100755 --- a/tests/qemu-iotests/tests/parallels-checks +++ b/tests/qemu-iotests/tests/parallels-checks @@ -225,6 +225,27 @@ echo "=3D=3D an unallocated cluster still reads as zer= oes =3D=3D" # Clear image _make_test_img $SIZE =20 +echo "=3D=3D TEST OVERSIZED VIRTUAL DISK CHECK =3D=3D" + +BAT_ENTRIES_OFFSET=3D32 +NB_SECTORS_OFFSET=3D36 + +TRACKS=3D$(peek_file_le $TEST_IMG $CLUSTER_SIZE_OFFSET 4) +BAT_ENTRIES=3D$(peek_file_le $TEST_IMG $BAT_ENTRIES_OFFSET 4) +COVERED_SECTORS=3D$((BAT_ENTRIES * TRACKS)) + +echo "=3D=3D advertise one more cluster than the BAT covers =3D=3D" +poke_file_le "$TEST_IMG" $NB_SECTORS_OFFSET 8 $((COVERED_SECTORS + TRACKS)) + +echo "=3D=3D open must fail cleanly instead of aborting =3D=3D" +{ $QEMU_IMG info "$TEST_IMG"; } 2>&1 | _filter_qemu_io | _filter_testdir + +echo "=3D=3D write into the uncovered range must fail cleanly too =3D=3D" +{ $QEMU_IO -c "write -P 0x41 $((COVERED_SECTORS * 512)) $CLUSTER_SIZE" "$T= EST_IMG"; } 2>&1 | _filter_qemu_io | _filter_testdir + +# Clear image +_make_test_img $SIZE + echo "=3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D" =20 echo "=3D=3D corrupt image: point first cluster far outside the file =3D= =3D" diff --git a/tests/qemu-iotests/tests/parallels-checks.out b/tests/qemu-iot= ests/tests/parallels-checks.out index 86d5b6ac2d..7b73498271 100644 --- a/tests/qemu-iotests/tests/parallels-checks.out +++ b/tests/qemu-iotests/tests/parallels-checks.out @@ -147,6 +147,13 @@ Child node '/file': read 1048576/1048576 bytes at offset 0 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 +=3D=3D TEST OVERSIZED VIRTUAL DISK CHECK =3D=3D +=3D=3D advertise one more cluster than the BAT covers =3D=3D +=3D=3D open must fail cleanly instead of aborting =3D=3D +qemu-img: Could not open 'TEST_DIR/t.parallels': Invalid image: Catalog si= ze too small for advertised disk size +=3D=3D write into the uncovered range must fail cleanly too =3D=3D +qemu-io: can't open device TEST_DIR/t.parallels: Invalid image: Catalog si= ze too small for advertised disk size +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 =3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D =3D=3D corrupt image: point first cluster far outside the file =3D=3D =3D=3D read-only read must return zeroes, not an I/O error =3D=3D --=20 2.53.0 From nobody Mon Sep 28 02:01:23 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785235443; cv=none; d=zohomail.com; s=zohoarc; b=WfNXHqrjNNjZE1N24xGRIFSYiIRbx0CbukK7CZzck1hBrTFlAsCZkCsEre+Frbqdkmwp75bPmnZpJndsf7vq68fq9dHCyV1pALp4GEmVhtiVjXQ92WDW51l4ADjjVS13wAyLprAWgDi6jM2athXb3/NLWAoW+LMcHm9l2hKuPlg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785235443; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=uhfeGe/4CB094Qsb3YMVun3IRBzdJrjy7hL+hy4mT8o=; b=aYvXW209iL0THm4jH5tfU3sX7Z88RVBxVjf5xYEdP9TgUFK+j79iZI70XzPwFFw3N/NGFYzY4uqKpQMXhHwL+Qy29gr4cexTO4xvHPNO1H58p+L0ZCAMZXguedmA4BAi6VTsItlFAphnUtH+Z28I/I5n7rI+CHXncl5DEK8JMTk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785235443157881.5258603763184; Tue, 28 Jul 2026 03:44:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wofGh-0008Bi-4r; Tue, 28 Jul 2026 06:42:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wofGg-0008BH-Fu for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:38 -0400 Received: from mail-ej1-x636.google.com ([2a00:1450:4864:20::636]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wofGe-0008JU-63 for qemu-devel@nongnu.org; Tue, 28 Jul 2026 06:42:38 -0400 Received: by mail-ej1-x636.google.com with SMTP id a640c23a62f3a-c16794450aeso466332766b.2 for ; Tue, 28 Jul 2026 03:42:35 -0700 (PDT) Received: from athena ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32c90b4dsm745682266b.35.2026.07.28.03.42.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 03:42:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785235355; x=1785840155; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uhfeGe/4CB094Qsb3YMVun3IRBzdJrjy7hL+hy4mT8o=; b=brCi/5pbNulNclOxdctmlDqMk6UokhWcd5iPfu+XtGrnv051GlUS7flt8Wycc9dqjQ ZR/iU138boftnlZ3AwIonD+AWKayClls6vMfHZ0mWAF2GmVIGA6wnSgaFrLtkJicVVol tNi9kxZ574JqIi9xVyNi0nwE/mWDEIMi5klqdhuecTKJFocl29UKZwtju3MbPaSLokpO 8DBfMXJzCIM8jQhvQiepkg5hUUoFGFKA+zjYtfQDCPB2nLbgUTRdNyWwZXoHSaS35Dt1 dKMRdm2NmwAnpenFAYIzyp6FPsFghJUh6CSOSHaUtJWlxNyv54FPT1JYQIJmIZ73P9c5 v99g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785235355; x=1785840155; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=uhfeGe/4CB094Qsb3YMVun3IRBzdJrjy7hL+hy4mT8o=; b=qIfjRGUl8xpVAVEHR1PSLLzpNxQi+TrIIelOu3no2W7OMSkplvFVz4/CjqZ8NZX7bV wrIs9OZEXdEP3KoK1kvZDqpID+B++tym9+H7Ea/NZsCLhAhIwMoTF7gjg3Oby8TsPcjL EyiTg+GzqJssbIXwumtiR2VLxiA8m2X5nvkZveyTr6Aog960rPTTgpPeaZdBDC2CnXeT yCbkqi51ft7cXB7zPfOJ7KgJPWlGhgNFjeabcd9j11tXgOi9YUz31ZLNpTqi3ZPJlDqF BvdO9039VwEPgQtUoltUBoYWAjxIoS6V9RkeA7fWlXm4SLGrKfPRGwk5Eez17owBhTn8 kdBg== X-Forwarded-Encrypted: i=1; AHgh+Ro8qsAfsXWT+t+xhM8g+gDSqgAKQooyoEWDkELa6aydPCOBhbl/ZSd6qmXK+ZPDzxH3mai9JyzpZSLs@nongnu.org X-Gm-Message-State: AOJu0YyZet70Dz455QWNjCMxw6k5JzDr8EFzQWRYE6r5yPyv4vUg1VGw O0OJqAquueh7U2aCkX3P1HYTeNX2yTfY7uqrYTCA+5hgUrZyBVTSUe2yEpmjE4WnZXA= X-Gm-Gg: AR+sD11Cr967dDIFDMOyZfm4wIe1toB1fP0w232ifDVXY32iKayS4FBXLG4OS5/Tvw3 9HpJa0LNBTxtD0pnRJUFfvuaezUyvVEKDgy6uJYqf+5WLWCGuc7f9FBwEoXdgC9mPRWth9hN3CD yGYfTpvIzaLMhC3+Vkz5mpGTBSUyb4VywQ4yE1ZbvLW8jBy1WhXPCYQ7iY6Xip2PQRMEpaYhnyu 9qkAT5r5bOkRKjkEnnm3RP8fj2QMn2Qb6vXPDsBIJg06p7+KLuxb6ZYVwV/mrC9GmcfjUWCAD1r wS+/d1U+qLREuYbjrLJvyCBNHRnxgFzmIO45RYX7ct1I1Jf7dhviQEXdHKhPKK1KV+Wcn9jOMDb +dXtLEul2cq7Va7Vt+wWYWR56W8siRzy2nxgzyjSd/gDu+TO7MowRmJDnsrqhIWP/Rg== X-Received: by 2002:a17:907:eccc:b0:c1f:13ec:bcbe with SMTP id a640c23a62f3a-c1f720ef007mr101326866b.30.1785235354705; Tue, 28 Jul 2026 03:42:34 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Stefan Hajnoczi Subject: [PULL 9/9] MAINTAINERS: update parallels tree location Date: Tue, 28 Jul 2026 12:42:21 +0200 Message-ID: <20260728104221.3981592-10-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728104221.3981592-1-den@openvz.org> References: <20260728104221.3981592-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::636; envelope-from=den@openvz.org; helo=mail-ej1-x636.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785235443867158500 Content-Type: text/plain; charset="utf-8" src.openvz.org is become unmaintained, point to the GitLab tree instead. Signed-off-by: Denis V. Lunev CC: Stefan Hajnoczi --- MAINTAINERS | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/MAINTAINERS b/MAINTAINERS index a28935c898..902db77218 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -4393,7 +4393,7 @@ F: block/parallels.c F: block/parallels-ext.c F: docs/interop/parallels.rst F: docs/interop/prl-xml.rst -T: git https://src.openvz.org/scm/~den/qemu.git parallels +T: git https://gitlab.com/dlunev/qemu.git parallels =20 qed M: Stefan Hajnoczi --=20 2.53.0