[PULL v2 0/9] parallels: fix reachable assertion and related bounds-checking gaps

Denis V. Lunev posted 9 patches 2 months ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20260728153849.601939-1-den@openvz.org
Maintainers: Stefan Hajnoczi <stefanha@redhat.com>, "Denis V. Lunev" <den@openvz.org>, Kevin Wolf <kwolf@redhat.com>, Hanna Reitz <hreitz@redhat.com>
MAINTAINERS                                   |   2 +-
block/parallels-ext.c                         |  52 +++++----
block/parallels.c                             |  74 ++++++++++---
tests/qemu-iotests/212                        |   8 +-
tests/qemu-iotests/212.out                    |  10 +-
tests/qemu-iotests/tests/parallels-checks     | 102 ++++++++++++++++++
tests/qemu-iotests/tests/parallels-checks.out |  53 +++++++++
7 files changed, 264 insertions(+), 37 deletions(-)
[PULL v2 0/9] parallels: fix reachable assertion and related bounds-checking gaps
Posted by Denis V. Lunev 2 months ago
The following changes since commit 6333226c2abb72f31648c251624c56e70993d625:

  Merge tag 'pull-9p-20260725' of https://github.com/cschoenebeck/qemu into staging (2026-07-26 08:30:07 -0400)

are available in the Git repository at:

  https://gitlab.com/dlunev/qemu.git tags/pull-parallels-2026-07-28

for you to fetch changes up to 352587cbe2d4cde1cece16e2f6a9e1e4190a03e6:

  MAINTAINERS: update parallels tree location (2026-07-28 16:55:00 +0200)

----------------------------------------------------------------
Parallels block driver patches

- fix a reachable assert()/process abort on a crafted image with an
  inconsistent BAT vs. advertised disk size (GitLab #3804)
- fix related integer overflows capping the format's usable catalog
  size below its documented maximum
- reject BAT entries pointing outside the data area in either
  direction
- harden the dirty-bitmap extension loader against a reachable
  abort and an unsafe allocator

Changes since v1:

- filter out format specific info in patches 2,8

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Thomas Huth <thuth@redhat.com>
CC: Stefan Hajnoczi <stefanha@redhat.com>

----------------------------------------------------------------
Denis V. Lunev (9):
  parallels: fix integer overflow in header size calculation
  parallels: read header/BAT table in bounded chunks
  parallels: fix bat_entries overflow in image creation
  parallels: reject BAT entries pointing outside backed storage
  parallels: validate bitmap L1 table size before allocating it
  parallels: skip loading a genuinely empty bitmap L1 table
  parallels: avoid fatal abort on large bitmap L1 table
  parallels: validate BAT capacity against advertised disk size
  MAINTAINERS: update parallels tree location

 MAINTAINERS                                   |   2 +-
 block/parallels-ext.c                         |  52 +++++----
 block/parallels.c                             |  74 ++++++++++---
 tests/qemu-iotests/212                        |   8 +-
 tests/qemu-iotests/212.out                    |  10 +-
 tests/qemu-iotests/tests/parallels-checks     | 102 ++++++++++++++++++
 tests/qemu-iotests/tests/parallels-checks.out |  53 +++++++++
 7 files changed, 264 insertions(+), 37 deletions(-)

-- 
2.53.0
Re: [PULL v2 0/9] parallels: fix reachable assertion and related bounds-checking gaps
Posted by Stefan Hajnoczi 2 months ago
Applied, thanks.

Please update the changelog at https://wiki.qemu.org/ChangeLog/11.1 for any user-visible changes.
Re: [PULL v2 0/9] parallels: fix reachable assertion and related bounds-checking gaps
Posted by Michael Tokarev 1 month, 4 weeks ago
On 7/28/26 18:38, Denis V. Lunev wrote:
> The following changes since commit 6333226c2abb72f31648c251624c56e70993d625:
> 
>    Merge tag 'pull-9p-20260725' of https://github.com/cschoenebeck/qemu into staging (2026-07-26 08:30:07 -0400)
> 
> are available in the Git repository at:
> 
>    https://gitlab.com/dlunev/qemu.git tags/pull-parallels-2026-07-28
> 
> for you to fetch changes up to 352587cbe2d4cde1cece16e2f6a9e1e4190a03e6:
> 
>    MAINTAINERS: update parallels tree location (2026-07-28 16:55:00 +0200)
> 
> ----------------------------------------------------------------
> Parallels block driver patches
> 
> - fix a reachable assert()/process abort on a crafted image with an
>    inconsistent BAT vs. advertised disk size (GitLab #3804)
> - fix related integer overflows capping the format's usable catalog
>    size below its documented maximum
> - reject BAT entries pointing outside the data area in either
>    direction
> - harden the dirty-bitmap extension loader against a reachable
>    abort and an unsafe allocator
> 
> Changes since v1:
> 
> - filter out format specific info in patches 2,8
> 
> Signed-off-by: Denis V. Lunev <den@openvz.org>
> CC: Thomas Huth <thuth@redhat.com>
> CC: Stefan Hajnoczi <stefanha@redhat.com>
> 
> ----------------------------------------------------------------
> Denis V. Lunev (9):
>    parallels: fix integer overflow in header size calculation
>    parallels: read header/BAT table in bounded chunks
>    parallels: fix bat_entries overflow in image creation
>    parallels: reject BAT entries pointing outside backed storage
>    parallels: validate bitmap L1 table size before allocating it
>    parallels: skip loading a genuinely empty bitmap L1 table
>    parallels: avoid fatal abort on large bitmap L1 table
>    parallels: validate BAT capacity against advertised disk size
>    MAINTAINERS: update parallels tree location

Hi Denis!

This is a bugfix pull request.  Is it worth to pick it up for
the stable series, or is parallels not used much outside of
openvz (which sure uses locally patched qemu)?

Thanks,

/mjt
Re: [PULL v2 0/9] parallels: fix reachable assertion and related bounds-checking gaps
Posted by Michael Tokarev 1 month ago
On 7/30/26 09:32, Michael Tokarev wrote:
> On 7/28/26 18:38, Denis V. Lunev wrote:
[..]
>> Denis V. Lunev (9):
>>    parallels: fix integer overflow in header size calculation
>>    parallels: read header/BAT table in bounded chunks
>>    parallels: fix bat_entries overflow in image creation
>>    parallels: reject BAT entries pointing outside backed storage
>>    parallels: validate bitmap L1 table size before allocating it
>>    parallels: skip loading a genuinely empty bitmap L1 table
>>    parallels: avoid fatal abort on large bitmap L1 table
>>    parallels: validate BAT capacity against advertised disk size
>>    MAINTAINERS: update parallels tree location
> 
> Hi Denis!
> 
> This is a bugfix pull request.  Is it worth to pick it up for
> the stable series, or is parallels not used much outside of
> openvz (which sure uses locally patched qemu)?

Ping?  Denis, what's the status/usage of this driver
outside of openvz?

I don't think these are very difficult questions :)

Thanks,

/mjt

Re: [PULL v2 0/9] parallels: fix reachable assertion and related bounds-checking gaps
Posted by Michael Tokarev 2 weeks, 1 day ago
Since this my question has never been answered, I assume parallels
is not interesting for qemu-stable, and am skipping subsequent
updates to the parallels driver (which stacks on top of this PR).

One question remains though: is it really difficult to write a
one-line reply to my questions?

Thanks,

/mjt

On 8/26/26 13:14, Michael Tokarev wrote:
> On 7/30/26 09:32, Michael Tokarev wrote:
>> On 7/28/26 18:38, Denis V. Lunev wrote:
> [..]
>>> Denis V. Lunev (9):
>>>    parallels: fix integer overflow in header size calculation
>>>    parallels: read header/BAT table in bounded chunks
>>>    parallels: fix bat_entries overflow in image creation
>>>    parallels: reject BAT entries pointing outside backed storage
>>>    parallels: validate bitmap L1 table size before allocating it
>>>    parallels: skip loading a genuinely empty bitmap L1 table
>>>    parallels: avoid fatal abort on large bitmap L1 table
>>>    parallels: validate BAT capacity against advertised disk size
>>>    MAINTAINERS: update parallels tree location
>>
>> Hi Denis!
>>
>> This is a bugfix pull request.  Is it worth to pick it up for
>> the stable series, or is parallels not used much outside of
>> openvz (which sure uses locally patched qemu)?
> 
> Ping?  Denis, what's the status/usage of this driver
> outside of openvz?
> 
> I don't think these are very difficult questions :)
> 
> Thanks,
> 
> /mjt
> 


Re: [PULL v2 0/9] parallels: fix reachable assertion and related bounds-checking gaps
Posted by Denis V. Lunev 2 weeks, 1 day ago
On 9/12/26 09:26, Michael Tokarev wrote:
> Since this my question has never been answered, I assume parallels
> is not interesting for qemu-stable, and am skipping subsequent
> updates to the parallels driver (which stacks on top of this PR).
>
> One question remains though: is it really difficult to write a
> one-line reply to my questions?
Please apologize me. I have missed that letter.

You approach is correct. Parallels image driver in reality
in the best case is used for image library at my opinion.
qemu-img info, qemu-img check, qemu-img convert. We never
run VMs with it and I believe that is true for the
whole world. At least the auditory is quite small.

Your approach is correct. There is no much sense to move
this to stable.

Sorry for late reply,
    Den

Re: [PULL v2 0/9] parallels: fix reachable assertion and related bounds-checking gaps
Posted by Michael Tokarev 2 weeks ago
On 9/12/26 13:18, Denis V. Lunev wrote:

> Please apologize me. I have missed that letter.

Denis, thank you for your reply, and for following-up.

> You approach is correct. Parallels image driver in reality
> in the best case is used for image library at my opinion.
> qemu-img info, qemu-img check, qemu-img convert. We never
> run VMs with it and I believe that is true for the
> whole world. At least the auditory is quite small.
> 
> Your approach is correct. There is no much sense to move
> this to stable.
I see.

I think we can fix at least some of these in stable series
anyway, - it doesn't hurt, as long as it doesn't require
significant maintenance efforts.  Especially when there's
a CVE assigned - people want to be clean of CVE issues,
even if these aren't real issues.  So if it'll come with
a CVE, I'll pick things up, maybe with some previous
fixes in this area to avoid back-porting.

Thank you for the explanation!

/mjt