From nobody Mon Sep 28 02:01:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785253144; cv=none; d=zohomail.com; s=zohoarc; b=iDvnGNiSYS560XhGobqNDyJiRUTUlJ+SD+hVXgl9dBRkeXXUNwx/jyvVrhDrW1FA3rcdt2SQTwtp47fU9CMB/d5QiVA5CAlKnTRFAOrGrqb6ZR1jflQ8eFSlyOZLyFhFEtSED6bGZd4SNbgTO5dZo7j+nb3xzsoR3to8MEReEI0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785253144; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6peXfCAI9PBCc+mW0GS1f5pARDqtu1ectajEcLcGxc4=; b=DXZ4oBBEu6ojUTQNOxn1cH7P0R+PtBImCbASjHhUP5/4kKhq08HmI3lPyaq/Z4ejC8QOfbAud707Ln+fkbFG/y7jeJ9UOfdXngZOpCpxX411RcT0sUv0LSCKPLiuDzW+9J8aytb/YTzBlwbMaHYmdAPWql1ymreQbBep8Ddl9dI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178525314491174.02447313450307; Tue, 28 Jul 2026 08:39:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wojtS-0003W2-Uv; Tue, 28 Jul 2026 11:38:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojtR-0003Ul-4d for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:38:57 -0400 Received: from mail-wr1-x435.google.com ([2a00:1450:4864:20::435]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wojtP-0002gJ-KS for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:38:56 -0400 Received: by mail-wr1-x435.google.com with SMTP id ffacd0b85a97d-47ddf7b09aaso5649f8f.3 for ; Tue, 28 Jul 2026 08:38:55 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f939c1465sm44190499f8f.26.2026.07.28.08.38.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:38:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785253133; x=1785857933; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6peXfCAI9PBCc+mW0GS1f5pARDqtu1ectajEcLcGxc4=; b=AjmtS3xis4n+6Os5d6y3bQZM5b8Ixj/TNic/wX5GY+xq2odbIJhFrmu0+U5OhycF8j B8kQ4SaLD0atq29K5ehBcdcNboABf5Wh4GMrzVJhZEPEqeXrFfT1QZ+mblS7CmsnsMit VxW3P0T/bxX/d6+GeP4Cuj8n64sQZJi0KuFM9UwEg0xXcOSQmR77SLdO3GdG41yDRsme iYZr5tUAtEW2MLaGeJj76RltPNi1bWk7eONRjEGjYUnv8xnrfKoL/1zBid4x8o0OJc9H 98joXxH7oln3EhQ48yv6KSu7KA66ustGbmVtK1ATWYEKCQLsT8AK7TvpJBEF00xDGlA6 KatA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253133; x=1785857933; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=6peXfCAI9PBCc+mW0GS1f5pARDqtu1ectajEcLcGxc4=; b=cOmcyJtDWKHXbcuM5ND/Her5xuLXAiVhcl9dW4m7hNPjNSI3VJWrAypqf4U99px+tu qy1qGcMy4o9gg8SQpAIZHRr/LbcdPCHWeua+kV4K5JBRAdnFX6fByuI/G/O4FEPoWGCP w5ToaR0rykTnPQimRviKt7OyTDjV+Vsi4XpDZ9v1Hs/Iqq1MhLovtOoNGaMFo7hhf9pW o/t6C+IOuBfcFoVp+AijMfWHp1vbDXqYTryGqKaeWPpaCMeiNKGo5eaPeo3juH9vPlHN 98Yzgtl17oUclNyK8LMSSsqL5lROteEHcbIjcWsnYWpAo2Jd/wMYIn8U9Wi8F/JVILpJ SlpA== X-Forwarded-Encrypted: i=1; AHgh+Ro37m44g6yEWcZt2uYrWQphtjVhgrWXiqvNIsSjlUM69vi7RFdT9Ae4cTzlowTgs9SBnOJZz9B09sDy@nongnu.org X-Gm-Message-State: AOJu0YyHCnrc1J39gnwiN9/pW8KXWtuLRLp/TsDh7yfBzMRBkKr9CZRb xtGodwMSwAliq5n1y6bAUxg6QB3SOkscpKPpbmj7zwIhlbp2pk4W9YuCODiglXsFKlQ= X-Gm-Gg: AR+sD131BFtNB8M64Tz4gafT2y6buwIjUm/mrWBplv+JpTyefZynsTdt3xR2+JmJ+Cy HUwutAsvtC6xZW+ifewc2o6xa4rxHiYLpfhG4ekTasYS0JXRka3u3OcOTzqlx3yKQV2kytmgvIq m/U5j2xoc48d/mihfjO7P9lG1Tmw8u92UBUZA9jl3HjckG0WaaLdcFC/Dz6wzRIxl4DLYiRvSgv LbM+p69XwS43jInP+d4jNWRKSDapmDSPJsUred+JJvcZgeGFqnvJgaKRhRBEFvYhj8ssCijjyRa +UhoTrvz7fE09s3E9jSYZBfnDBS+qFjFMsTca3QqKphhR0oM88zSejnYBA7t3PEMdssFJxRVn5S cLvqFH6XVscH4zSG/+Dw9wQ45gt9DiK1WoUObhUewUjDXoYYRAyQi3YcWgKKENNYgYjGYF/pQjQ == X-Received: by 2002:a5d:64c5:0:b0:47f:921f:3a35 with SMTP id ffacd0b85a97d-47fb1f129fdmr3754841f8f.37.1785253133212; Tue, 28 Jul 2026 08:38:53 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL v2 1/9] parallels: fix integer overflow in header size calculation Date: Tue, 28 Jul 2026 17:38:41 +0200 Message-ID: <20260728153849.601939-2-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728153849.601939-1-den@openvz.org> References: <20260728153849.601939-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::435; envelope-from=den@openvz.org; helo=mail-wr1-x435.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785253146851158500 Content-Type: text/plain; charset="utf-8" parallels_open() caches bat_entry_off(s->bat_size) - a uint32_t - in a plain int before it feeds into s->header_size. Near the "Catalog too large" bound the value exceeds INT_MAX and overflows on assignment. Match the cached value's type to bat_entry_off()'s return type. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/block/parallels.c b/block/parallels.c index 7a90fb5220..59f00c64a6 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -1240,7 +1240,8 @@ static int parallels_open(BlockDriverState *bs, QDict= *options, int flags, { BDRVParallelsState *s =3D bs->opaque; ParallelsHeader ph; - int ret, size, i; + int ret, i; + uint32_t size; int64_t file_nb_sectors, sector; uint32_t data_start; bool need_check =3D false; --=20 2.53.0 From nobody Mon Sep 28 02:01:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785253144; cv=none; d=zohomail.com; s=zohoarc; b=nvoYtBsSZ0XWlTLqitjeBevXdk6gOjBouAywByW4Yx+L9u0nKkmucifzFJmDPpc2Z9UGPnCCGZPV5lNnMp32jSr8mM3gC/SxSOamwknhMSxVVx99b8VNPDHke34fyYikq64al1ZKXeJ2AGhQwCDUBWpZLk9+EQ7FYckimcVV8kU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785253144; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YJaoJvgzXUZ8yMjiVjFNLoDIXX0M+tiKgbemBDHpStA=; b=mVCJ5Ir4vINxqMpU4wwUpr2ffapHeHb9wArFHyVepTuPzxIMzWlMElHRXOeyNAQ8o9HGUkQa+aX4BV8OZIhbuHt0BmP6thVO0qXPeBjEYS4UV8c5xn3Z5sk6C+2OX0jB1xvmZMQG4Fp3JX98Giu79C05XRAZmN2ORIfw97Ue9co= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785253144456268.5994211956116; Tue, 28 Jul 2026 08:39:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wojtU-0003XU-Jr; Tue, 28 Jul 2026 11:39:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojtS-0003Vv-RM for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:38:58 -0400 Received: from mail-wm1-x329.google.com ([2a00:1450:4864:20::329]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wojtP-0002gZ-SR for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:38:58 -0400 Received: by mail-wm1-x329.google.com with SMTP id 5b1f17b1804b1-495757ccbc1so36630885e9.2 for ; Tue, 28 Jul 2026 08:38:55 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f939c1465sm44190499f8f.26.2026.07.28.08.38.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:38:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785253134; x=1785857934; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=YJaoJvgzXUZ8yMjiVjFNLoDIXX0M+tiKgbemBDHpStA=; b=tLLZfon7B7o79PqiRu19RaD3yHMV+GYsg7yxoQ0T67am8Ee5EgQGo4BctK5yAcpHg4 qMzB+TN72hLv606LcjZbCMJ2/QeFCLpQbDDAv6kUygD9/mW5Nav4NR2rfD3b/Fs5RsoO ny9b4w82Hqj7ASQoMjKzkTFfnEQtfe+0kfKgvObKpOQzExh9fdhcUiWTNTEVSIjOxi1c 5Btsy/iQiGfEMAvXLiaaRUcmwIIiDQd/f13iUfmVMW9jL7aYkXTiZwyCrju14CmbDMeH 0nDqCLRhOcwiGCO1A/mclJ9r9iVgs5bIUOW1tkOX2NnqgP0YAprJYJ1CP68MPrDSPi+P UJcw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253134; x=1785857934; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=YJaoJvgzXUZ8yMjiVjFNLoDIXX0M+tiKgbemBDHpStA=; b=BKhdVmXEPZF46kYyvp4mX10LQ9fdor8FyThTA2olxOHkvQxcqjVK64pTvMMkdC4sh8 v6XmzUUNHjNsiONUzevcSXenh75jN4yTywPc9wXS+q1xj+sT42Wg980UELj3jsRdUSWz LunWzuRQPQyhPl4qb279Wws0euh2T6wUa/qJOqr9XnqhISGM7XkFniakGYHe8JRidhvA pNznwNfFrJ0Lxk1/ZrQJNhF3Xs6bG6JopPOxjSwDdLveT4RdP9raugsZu1/FSuibYgiX 2ZXWJNmJPJglTHN4slVGR/TjFyD7BdndWEny7bq/2ugvE4FAB59g5px5HHihME5gksAy 4+WQ== X-Forwarded-Encrypted: i=1; AHgh+Roc8Zl2ChhfGmzgii166Q5l3NmQNcG+amp/v8phPhe4lqCOQLIQEDToVjyckyb4CXDNAP1AOunz4Qrj@nongnu.org X-Gm-Message-State: AOJu0Yyl5sBCllvw9uMiDiTmJUjwWKO+XYb3YrJONf6spYGXOUpsHfTl iAUG9qGl5RE814xhm3TzslDkgeNFdtlWER0k8eyUQyE8raNRYYl3Xd681VC5SKLL5Io= X-Gm-Gg: AR+sD11T8XWy/TPQFLFyZN7mjGTHCnwm8des+6t7jFkxfncxrumDUxNx4HrVsNIyuvH xo3VYg5+K0pSxxq1JBTXvyJQIQo4K0rwgsCFfg87vLC1/nsktz4CxHLSBElLXBVQJJhKYZWa4/H AtmdgRRMpSjx/nGQPUfTxMuQVChXti4R4nzRdEvjTXxU8X/B8f4tQ+9Z7f/yjpxmqflO5NO6PGc PcKl87T9DWibnY9j9bXf8q/YF/8x67X7LCQ1QzrvOoC7Zpi3rdfcZ9rcIXzgepXu1vDDbhODiKz 6Bv7ke/WTCOrQ7AJEOvcXtyfMr8SfwGHGtkU8y8V5o/5e4invhdfVUdr06OxeN/LzYWCPYqfXrT eqI8ZABbhIhgHK8CrZTQVP6RJGSo1lRFhM6f4huutm1n4uRrlh3IvMkCNsn6/AoFoGYX2uTAjXw == X-Received: by 2002:a05:600c:c8d:b0:493:e57e:7aa5 with SMTP id 5b1f17b1804b1-496c657cdbemr31123585e9.22.1785253134209; Tue, 28 Jul 2026 08:38:54 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL v2 2/9] parallels: read header/BAT table in bounded chunks Date: Tue, 28 Jul 2026 17:38:42 +0200 Message-ID: <20260728153849.601939-3-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728153849.601939-1-den@openvz.org> References: <20260728153849.601939-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::329; envelope-from=den@openvz.org; helo=mail-wm1-x329.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785253146921158500 Content-Type: text/plain; charset="utf-8" parallels_open() read the whole header+BAT table with a single bdrv_pread() call sized s->header_size. For an image whose catalog approaches the "Catalog too large" bound (INT_MAX / sizeof(uint32_t) entries), that size approaches BDRV_REQUEST_MAX_BYTES, and the block layer legitimately refuses a single request that large, so the image failed to open with a generic I/O error even though the catalog size itself is within the format's documented limit. Read the header and BAT table in fixed-size chunks instead, so the maximum catalog size parallels_open() can actually address matches the bound it already enforces, independent of the file's block-layer alignment requirements. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 17 ++++++++++---- tests/qemu-iotests/tests/parallels-checks | 23 +++++++++++++++++++ tests/qemu-iotests/tests/parallels-checks.out | 11 +++++++++ 3 files changed, 47 insertions(+), 4 deletions(-) diff --git a/block/parallels.c b/block/parallels.c index 59f00c64a6..0f655b58d5 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -52,6 +52,7 @@ #define HEADER_VERSION 2 #define HEADER_INUSE_MAGIC (0x746F6E59) #define MAX_PARALLELS_IMAGE_FACTOR (1ull << 32) +#define PARALLELS_HEADER_READ_CHUNK (64 * 1024 * 1024) =20 static QEnumLookup prealloc_mode_lookup =3D { .array =3D (const char *const[]) { @@ -1241,7 +1242,7 @@ static int parallels_open(BlockDriverState *bs, QDict= *options, int flags, BDRVParallelsState *s =3D bs->opaque; ParallelsHeader ph; int ret, i; - uint32_t size; + uint32_t size, header_off; int64_t file_nb_sectors, sector; uint32_t data_start; bool need_check =3D false; @@ -1311,9 +1312,17 @@ static int parallels_open(BlockDriverState *bs, QDic= t *options, int flags, return -ENOMEM; } =20 - ret =3D bdrv_pread(bs->file, 0, s->header_size, s->header, 0); - if (ret < 0) { - goto fail; + /* A single request s->header_size large exceeds BDRV_REQUEST_MAX_BYTE= S. */ + for (header_off =3D 0; header_off < s->header_size; + header_off +=3D PARALLELS_HEADER_READ_CHUNK) { + uint32_t chunk =3D MIN(s->header_size - header_off, + PARALLELS_HEADER_READ_CHUNK); + + ret =3D bdrv_pread(bs->file, header_off, chunk, + (uint8_t *)s->header + header_off, 0); + if (ret < 0) { + goto fail; + } } s->bat_bitmap =3D (uint32_t *)(s->header + 1); =20 diff --git a/tests/qemu-iotests/tests/parallels-checks b/tests/qemu-iotests= /tests/parallels-checks index b281246a42..9535024885 100755 --- a/tests/qemu-iotests/tests/parallels-checks +++ b/tests/qemu-iotests/tests/parallels-checks @@ -44,6 +44,7 @@ _supported_os Linux SIZE=3D$((4 * 1024 * 1024)) IMGFMT=3Dparallels CLUSTER_SIZE_OFFSET=3D28 +BAT_ENTRIES_OFFSET=3D32 DATA_OFF_OFFSET=3D48 BAT_OFFSET=3D64 =20 @@ -199,6 +200,28 @@ _check_test_img -r all echo "=3D=3D check first cluster =3D=3D" { $QEMU_IO -r -c "read -P 0x55 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir =20 +# Clear image +_make_test_img $SIZE + +echo "=3D=3D TEST HUGE BAT TABLE OPEN =3D=3D" + +# Overflows a single read request, but stays under parallels_open()'s +# own catalog-size cap. +BAT_ENTRIES=3D536870896 +HEADER_SIZE=3D$((64 + 4 * BAT_ENTRIES)) + +echo "=3D=3D advertise a BAT table larger than BDRV_REQUEST_MAX_BYTES =3D= =3D" +poke_file "$TEST_IMG" "$BAT_ENTRIES_OFFSET" "\xf0\xff\xff\x1f" + +echo "=3D=3D grow the file to match, without writing real data =3D=3D" +truncate -s $HEADER_SIZE "$TEST_IMG" + +echo "=3D=3D open must succeed: the header/BAT read is chunked =3D=3D" +_img_info + +echo "=3D=3D an unallocated cluster still reads as zeroes =3D=3D" +{ $QEMU_IO -r -c "read -P 0x00 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir + # success, all done echo "*** done" rm -f $seq.full diff --git a/tests/qemu-iotests/tests/parallels-checks.out b/tests/qemu-iot= ests/tests/parallels-checks.out index 9793423111..6fb2014e8e 100644 --- a/tests/qemu-iotests/tests/parallels-checks.out +++ b/tests/qemu-iotests/tests/parallels-checks.out @@ -129,4 +129,15 @@ No errors were found on the image. =3D=3D check first cluster =3D=3D read 1048576/1048576 bytes at offset 0 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 +=3D=3D TEST HUGE BAT TABLE OPEN =3D=3D +=3D=3D advertise a BAT table larger than BDRV_REQUEST_MAX_BYTES =3D=3D +=3D=3D grow the file to match, without writing real data =3D=3D +=3D=3D open must succeed: the header/BAT read is chunked =3D=3D +image: TEST_DIR/t.IMGFMT +file format: IMGFMT +virtual size: 4 MiB (4194304 bytes) +=3D=3D an unallocated cluster still reads as zeroes =3D=3D +read 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) *** done --=20 2.53.0 From nobody Mon Sep 28 02:01:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785253170; cv=none; d=zohomail.com; s=zohoarc; b=hpVhFxQYMF2aCpIZy9ULoO4kVP9f7oXw+MKyTUxhnRif3HlP7MNo2JaHH0bHn6aqfmEqBH/lK7LBkGRPkwEwlNZc8kBvYvIY4Fk6MwhdbrAzyp7tUnArmv8G6+0y8DyVy2t0b3LtTTh8pUjZqSFmVhH1Q5R4VH1H31W3C8EWEYQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785253170; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/g2p3N4kfpkZuJaxI9UjRhwniulc+lWWhKKajqjETAQ=; b=WZdEUOVEFl7lZLus/C2JbZOYxDrhNCbq3Rrf7G7O9uCGwClHQIBMqCM5VMMr8VrlvM5qtcgNWvQZMyQQcfh1d8aj8/mJBSHZ3iRsm51GqOVm2TB5xlAPdevLUS3qxwJ70jJDlnrqtS82toeoZYcTGxV6hOOBUmVIukiJ6i1jX4A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785253170981797.0011951954283; Tue, 28 Jul 2026 08:39:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wojtU-0003Xe-Q4; Tue, 28 Jul 2026 11:39:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojtS-0003Vy-RY for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:38:58 -0400 Received: from mail-wm1-x333.google.com ([2a00:1450:4864:20::333]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wojtQ-0002h5-Uu for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:38:58 -0400 Received: by mail-wm1-x333.google.com with SMTP id 5b1f17b1804b1-4954d29264cso20236465e9.2 for ; Tue, 28 Jul 2026 08:38:56 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f939c1465sm44190499f8f.26.2026.07.28.08.38.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:38:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785253135; x=1785857935; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/g2p3N4kfpkZuJaxI9UjRhwniulc+lWWhKKajqjETAQ=; b=WBaf1ljcBNk8ccZ1uCrMYmCxiJ1SbQhGA+U8SOleaDH9ZdnvZn9U6g/U0l5U83kAvO KW7cEy+m2QXMwSGYqnevboSQ97gYpZoXqL1xwXrY0ISyUQ5mfDehDL3r7UmFYgTEbreQ Qene7BV82v9dRjeUYKg1gIncqy9szmwj6KFnsD3ioYq50iWCkXiMuFVDSBnawsxgvt5j SmZRAkidtdeqKvgwS+xSco1b8gm1ti8gAlBDMHcqbNYY8L7o/D1cjQ4vmLElWd+JXLHm +iv+PK41WYasrSt3zSyb/b5TZs0ASTxkJOcEOC7Tm4BGwa7shtUD0APoKWHyqRxkubbr vHWg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253135; x=1785857935; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/g2p3N4kfpkZuJaxI9UjRhwniulc+lWWhKKajqjETAQ=; b=Eto83mlOV9OoIwEzJ8czbp6GRgE07yZZlUImUKu8coSftPcQW2bJyLVwk0k4W240A9 ayMQpsKNT5LJYpM3LNEHlZhEu0Gh1rxrt/B3TQVLNJw6aD1wtw4VzW753NFdu9GC8wlX 3PatrfTI1sQmTFc4lpQKR0sP4EEE8CzJzovxjWbBjwKswDKHDw/9xdrgeeQSz3K+0OoG gUis3EdOimAiBfq6T/tpBhF8wbsWzkSrkIzBsrJvLG0qkwJuYT4/d75T9Vg9lFa05sCS vT5dVvxkrUDPqBeIemDVJ+dsJ5lm+HkcnUKBfkZ6VQVsHLc0sT2QgA9i7xRvGlWSLqSp +B9Q== X-Forwarded-Encrypted: i=1; AHgh+RoeLyeD8CYpfK62Qejub6GORL389Byt8XH6YesgAStg04eha5B0J1kNwhRgm5QKJtZxPtvkSP3FMxjT@nongnu.org X-Gm-Message-State: AOJu0YxzTXfRIiEgK5lcXluGkPllVkc1qj1aExaI4XvBg/K8PH89H2p4 20xQev6bWNB/eUlk7Z1PU6yGYOpUcCX6MATZFRt9dp8s5p/0siZsT5xgYAwRXBLByuA= X-Gm-Gg: AR+sD11Ni8pwh1GSaqUcfqzG6QErCfpfIlr6qUW9EfOTIJIvQsspCGy1+gbbqJodwpJ jvXEwIirhN0csw9cORAfvnAAHIrAjAJpwbNRBT8cImecv0iQNQt6SuRTXr93F6j8pjldyo7HS8Z ir3V+SOqpeyQPVVtD6coorl5eJxSwLTik0GlXqlIDfrr0xlbruv4QvGxbv/8iu8b0dbXvhfJH4z +YewszxLZpz+CWKHsgwcxUktIaWymn4mu6gnZZAGM2bR7vlO2vguSVjUaPfp5pjYA8cOg4VxHkA 5BTcIW2h5Vk3j6zNrk8VHhd2vbtJhBh57XkZGabuZZjb0afd0wU+0OBRszjY+Vaxss/SROShrRZ Wozvc7LziljPUumOHXAooxjwx+uO66l9I0wNHuOTlIorZWKfyoeh3ls/NN8XbP2igG3ZxChLzWQ == X-Received: by 2002:a05:600c:4eca:b0:495:7379:17b1 with SMTP id 5b1f17b1804b1-496c6585036mr32275645e9.30.1785253135218; Tue, 28 Jul 2026 08:38:55 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL v2 3/9] parallels: fix bat_entries overflow in image creation Date: Tue, 28 Jul 2026 17:38:43 +0200 Message-ID: <20260728153849.601939-4-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728153849.601939-1-den@openvz.org> References: <20260728153849.601939-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::333; envelope-from=den@openvz.org; helo=mail-wm1-x333.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785253173094158500 Content-Type: text/plain; charset="utf-8" parallels_co_create() computed the BAT entry count directly into a uint32_t, wrapping silently to zero at exactly 2^32 entries and writing out a header whose BAT no longer matches its advertised size. Compute it in an int64_t first and reject it once it no longer fits, matching the cap parallels_open() already enforces. Also reject cluster-size 0, and clamp header.cylinders instead of letting it truncate the same way. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 23 +++++++++++++++++------ tests/qemu-iotests/212 | 8 ++++++-- tests/qemu-iotests/212.out | 10 ++++++++-- 3 files changed, 31 insertions(+), 10 deletions(-) diff --git a/block/parallels.c b/block/parallels.c index 0f655b58d5..e3d26a6650 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -999,7 +999,8 @@ parallels_co_create(BlockdevCreateOptions* opts, Error = **errp) BlockdevCreateOptionsParallels *parallels_opts; BlockDriverState *bs; BlockBackend *blk; - int64_t total_size, cl_size; + int64_t total_size, cl_size, bat_count; + uint64_t cylinders; uint32_t bat_entries, bat_sectors; ParallelsHeader header; uint8_t tmp[BDRV_SECTOR_SIZE]; @@ -1017,16 +1018,22 @@ parallels_co_create(BlockdevCreateOptions* opts, Er= ror **errp) cl_size =3D DEFAULT_CLUSTER_SIZE; } =20 - /* XXX What is the real limit here? This is an insanely large maximum.= */ + /* Bounds cl_size so the multiplication below can't overflow int64_t. = */ if (cl_size >=3D INT64_MAX / MAX_PARALLELS_IMAGE_FACTOR) { error_setg(errp, "Cluster size is too large"); return -EINVAL; } - if (total_size >=3D MAX_PARALLELS_IMAGE_FACTOR * cl_size) { + if (cl_size <=3D 0 || total_size >=3D MAX_PARALLELS_IMAGE_FACTOR * cl_= size) { error_setg(errp, "Image size is too large for this cluster size"); return -E2BIG; } =20 + bat_count =3D DIV_ROUND_UP(total_size, cl_size); + if (bat_count > INT_MAX / (int64_t)sizeof(uint32_t)) { + error_setg(errp, "Catalog too large"); + return -EFBIG; + } + if (!QEMU_IS_ALIGNED(total_size, BDRV_SECTOR_SIZE)) { error_setg(errp, "Image size must be a multiple of 512 bytes"); return -EINVAL; @@ -1052,7 +1059,7 @@ parallels_co_create(BlockdevCreateOptions* opts, Erro= r **errp) blk_set_allow_write_beyond_eof(blk, true); =20 /* Create image format */ - bat_entries =3D DIV_ROUND_UP(total_size, cl_size); + bat_entries =3D bat_count; bat_sectors =3D DIV_ROUND_UP(bat_entry_off(bat_entries), cl_size); bat_sectors =3D (bat_sectors * cl_size) >> BDRV_SECTOR_BITS; =20 @@ -1061,8 +1068,12 @@ parallels_co_create(BlockdevCreateOptions* opts, Err= or **errp) header.version =3D cpu_to_le32(HEADER_VERSION); /* don't care much about geometry, it is not used on image level */ header.heads =3D cpu_to_le32(HEADS_NUMBER); - header.cylinders =3D cpu_to_le32(total_size / BDRV_SECTOR_SIZE - / HEADS_NUMBER / SEC_IN_CYL); + cylinders =3D total_size / BDRV_SECTOR_SIZE / HEADS_NUMBER / SEC_IN_CY= L; + /* Write only by spec, do not care */ + if (cylinders >=3D UINT32_MAX) { + cylinders =3D UINT32_MAX; + } + header.cylinders =3D cpu_to_le32(cylinders); header.tracks =3D cpu_to_le32(cl_size >> BDRV_SECTOR_BITS); header.bat_entries =3D cpu_to_le32(bat_entries); header.nb_sectors =3D cpu_to_le64(DIV_ROUND_UP(total_size, BDRV_SECTOR= _SIZE)); diff --git a/tests/qemu-iotests/212 b/tests/qemu-iotests/212 index d4af0c4ac8..4ca6149b6b 100755 --- a/tests/qemu-iotests/212 +++ b/tests/qemu-iotests/212 @@ -133,13 +133,15 @@ with iotests.FilePath('t.parallels') as disk_path, \ # # Maximum size # + # Largest catalog parallels_open() can address. + # iotests.log("=3D=3D=3D Maximum size =3D=3D=3D") iotests.log("") =20 vm.launch() vm.blockdev_create({ 'driver': imgfmt, 'file': 'node0', - 'size': 4503599627369984}) + 'size': 562949952372736}) vm.shutdown() =20 iotests.img_info_log(disk_path) @@ -158,13 +160,15 @@ with iotests.FilePath('t.parallels') as disk_path, \ # 4. 2^63 - 512 (generally valid, but with the image header the file w= ill # exceed 63 bits) # 5. 2^52 (512 bytes more than maximum image size) + # 6. 2^52 - 512 (wraps bat_entries to 0 at the default 1 MiB cluster s= ize) =20 iotests.log("=3D=3D=3D Invalid sizes =3D=3D=3D") iotests.log("") =20 vm.launch() for size in [ 1234, 18446744073709551104, 9223372036854775808, - 9223372036854775296, 4503599627370497 ]: + 9223372036854775296, 4503599627370497, + 4503599627369984 ]: vm.blockdev_create({ 'driver': imgfmt, 'file': 'node0', 'size': size }) diff --git a/tests/qemu-iotests/212.out b/tests/qemu-iotests/212.out index 8102033488..d59f8ed44b 100644 --- a/tests/qemu-iotests/212.out +++ b/tests/qemu-iotests/212.out @@ -69,14 +69,14 @@ virtual size: 0 B (0 bytes) =20 =3D=3D=3D Maximum size =3D=3D=3D =20 -{"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"driver": "parallels", "file": "node0", "size": 4503599627369984}}} +{"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"driver": "parallels", "file": "node0", "size": 562949952372736}}} {"return": {}} {"execute": "job-dismiss", "arguments": {"id": "job0"}} {"return": {}} =20 image: TEST_IMG file format: IMGFMT -virtual size: 4 PiB (4503599627369984 bytes) +virtual size: 512 TiB (562949952372736 bytes) =20 =3D=3D=3D Invalid sizes =3D=3D=3D =20 @@ -110,6 +110,12 @@ Job failed: Image size is too large for this cluster s= ize {"execute": "job-dismiss", "arguments": {"id": "job0"}} {"return": {}} =20 +{"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"driver": "parallels", "file": "node0", "size": 4503599627369984}}} +{"return": {}} +Job failed: Catalog too large +{"execute": "job-dismiss", "arguments": {"id": "job0"}} +{"return": {}} + =3D=3D=3D Invalid cluster size =3D=3D=3D =20 {"execute": "blockdev-create", "arguments": {"job-id": "job0", "options": = {"cluster-size": 1234, "driver": "parallels", "file": "node0", "size": 6710= 8864}}} --=20 2.53.0 From nobody Mon Sep 28 02:01:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785253154; cv=none; d=zohomail.com; s=zohoarc; b=fT8pZIPmkxnkrpZDPVaOmewZEhZoHxpZPoi0abTQqkIAaC4oQ9pULZwuv6zp//ollWanVeb5k8SIBg0TGGASjDLZhbHZYhUc9C8+pbuBnqVymEyIpKDFS/9A8tAGoO9nY7jY5rGFLa2kiHUCTwjLBENSRi9Ur7YBq+9F4M4lh+E= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785253154; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7qJoWo6IWghEa8NGO4hqbax4oCMGEskJxTM6dWHfvgM=; b=HUjoSX4Q2ul2YEck5zFtwh73kIljaP/AbJjAxdVy7nOm+3qwWfpuTaZRe9322BVp0FewuqlFSCDQrO/Yru1MCZo1EpGamzxRJZPb9uGZ8rBBMBf6dLduejMTXNuuFCf4mThHcwnPXEJZqvGaKmrO+0ImJTJ8iky8y1Ep39TOzdw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785253154611884.7284118763064; Tue, 28 Jul 2026 08:39:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wojtV-0003YT-Ka; Tue, 28 Jul 2026 11:39:01 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojtU-0003XX-LY for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:00 -0400 Received: from mail-wr1-x436.google.com ([2a00:1450:4864:20::436]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wojtR-0002hN-TH for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:00 -0400 Received: by mail-wr1-x436.google.com with SMTP id ffacd0b85a97d-47f7872abb6so1441f8f.3 for ; Tue, 28 Jul 2026 08:38:57 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f939c1465sm44190499f8f.26.2026.07.28.08.38.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:38:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785253136; x=1785857936; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=7qJoWo6IWghEa8NGO4hqbax4oCMGEskJxTM6dWHfvgM=; b=fILXVbhjz5eqYVsshvHwk51/eluod6uV+UqtpZlS/6KUJYwENm8ZlBrQnADMLU8Q/y rY09uT5H3Fwq8zShwD+HptvNRAuUwqXLudah/7FRXP+nt2oBS01lpTMYdbc6s9hTKayA lgQFcioeqvNFET/7MaavrWoF5eNDPwvkbhlrt2Ts4tvVLEdmYeD6VYJwf1NvKgBxbVzd 0B30NfCy8wzyNBo/9V4ps3wKoPwp0UOmhAA8JLPfMeN5xCWvnR9l/FZbE6WpAWBtPJod WjQ5SUOf+bR+L/FswRD7Z0Q5v+AZtVO89e2JeY5cinkR45qf9gauUm4+xNMi8W51gM77 T9Xw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253136; x=1785857936; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=7qJoWo6IWghEa8NGO4hqbax4oCMGEskJxTM6dWHfvgM=; b=RVr4NjOHEK7g6nEmQ2pBrzZimxXvOl1xDT7mFroIW7VRrFf48bRrziLVaU6W7c1U+c efm9YruBohJx2DSsT5Y2eBaBqyrm76qrhlNUxtzFBWjWTHfR6Sx4aj9c3n84E9y3Oz71 BKMAe/YtEseh29D0HUKQNn9GJQ7p8z8RZcxeqc3J1vsppYDse86cHACv9d0bfeqp7fWb dbh0pMsV5ectHXSDz1Y7Fj+Dh+HPc1HJ99Jz/Z2h80sBC4ZMWUHhxDOtrZsuunNfYCYS ClDWDzSPP5uoEy+qnsJset5L1kGm2yfbO8Mf8Q/MvAm8jINrLqBQe2Dq625G5HZLm4O7 7V2Q== X-Forwarded-Encrypted: i=1; AHgh+RrL4fV/TMdSE61zz3IIyzSo+6ly+iElwjct3L/BmlPKZfP2DxqSX8TV9aK/AG1u5mAON1u4grvjkzpU@nongnu.org X-Gm-Message-State: AOJu0Yz+pzAt+HZE8efztoU3fX14cvW0KzW67kVqW9Pr01olwK5dj6Ej Fv4XE4FwwnFi1NZBQo6witeBZjcuTJOfBlTlXserVLiQTqIV30PAYl+3Wn+tHnXkuZw= X-Gm-Gg: AR+sD10xxgmdsKnMskTNU+fUP01QBPwvqMcOZ+RIJ6nfORY8bb96ql9l3ZCyLyKZSRo xyKOwDM43KpG168KSW11nC7MWA1Efch1cVX4JVn7Ys582Su6oB5IY5KVfkkgnCF0XmirlRERftd cxWazLkDmT6TF1FXP7Wx9Ri62BjQ8lZ0UjMXXTWpyoZsfNf35Ng9j8SgotlB+oAVNxIsKWAhydM 3x4SWpZZUAvVEMzVigppTAz1pjz2KDhuyJYDvWfZKu2TdYeUbDbMC4rrz4KmCTw7VIwPY3P7Y5l kKl+JSGFGM15CP4X85Cd6tyQChILs1n+q3p8linEFCASx2UwFeVTicJ/AZAVuWKr6I3wUJypdNC FoWs5tP0QuhvyjEhsn1855VkKI1KRxW2OfQhxHOKmoupU9Vz3+4ZBNyOMu2l9Y/bM9ThLOykBmk i46gHU4Kwe X-Received: by 2002:a05:6000:4283:b0:47f:93b6:8d05 with SMTP id ffacd0b85a97d-47fb1e14297mr3409865f8f.0.1785253136285; Tue, 28 Jul 2026 08:38:56 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL v2 4/9] parallels: reject BAT entries pointing outside backed storage Date: Tue, 28 Jul 2026 17:38:44 +0200 Message-ID: <20260728153849.601939-5-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728153849.601939-1-den@openvz.org> References: <20260728153849.601939-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::436; envelope-from=den@openvz.org; helo=mail-wr1-x436.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785253156861158500 Content-Type: text/plain; charset="utf-8" parallels_open()'s BAT scan and parallels_check_outside_image() only checked entries against the file's upper end, matching just half of what docs/interop/parallels.rst requires: an entry's offset must be both >=3D data_start and < the file size. An entry below data_start resolves into the header/BAT region itself, corrupting metadata on write or losing the write silently on a partial overlap, and neither qemu-img check nor the open-time scan ever caught it. Check both bounds everywhere a BAT entry is resolved to a host offset: seek_to_sector(), the open-time scan (without letting a bad entry inflate data_end), and parallels_check_outside_image(). Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 27 +++++++-- tests/qemu-iotests/tests/parallels-checks | 58 +++++++++++++++++++ tests/qemu-iotests/tests/parallels-checks.out | 35 +++++++++++ 3 files changed, 116 insertions(+), 4 deletions(-) diff --git a/block/parallels.c b/block/parallels.c index e3d26a6650..8a7e8b4aba 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -119,6 +119,7 @@ static uint32_t bat_entry_off(uint32_t idx) static int64_t seek_to_sector(BDRVParallelsState *s, int64_t sector_num) { uint32_t index, offset; + int64_t cluster_off; =20 index =3D sector_num / s->tracks; offset =3D sector_num % s->tracks; @@ -127,7 +128,14 @@ static int64_t seek_to_sector(BDRVParallelsState *s, i= nt64_t sector_num) if ((index >=3D s->bat_size) || (s->bat_bitmap[index] =3D=3D 0)) { return -1; } - return bat2sect(s, index) + offset; + + cluster_off =3D bat2sect(s, index); + if (cluster_off < s->data_start || cluster_off + s->tracks > s->data_e= nd) { + /* Cluster is outside of the image file or overlaps the header. */ + return -1; + } + + return cluster_off + offset; } =20 static int cluster_remainder(BDRVParallelsState *s, int64_t sector_num, @@ -703,18 +711,22 @@ parallels_check_outside_image(BlockDriverState *bs, B= drvCheckResult *res, { BDRVParallelsState *s =3D bs->opaque; uint32_t i; - int64_t off, high_off, size; + int64_t off, high_off, size, data_start_off; =20 size =3D bdrv_co_getlength(bs->file->bs); if (size < 0) { res->check_errors++; return size; } + data_start_off =3D s->data_start << BDRV_SECTOR_BITS; =20 high_off =3D 0; for (i =3D 0; i < s->bat_size; i++) { off =3D bat2sect(s, i) << BDRV_SECTOR_BITS; - if (off + s->cluster_size > size) { + if (off =3D=3D 0) { + continue; + } + if (off < data_start_off || off + s->cluster_size > size) { fprintf(stderr, "%s cluster %u is outside image\n", fix & BDRV_FIX_ERRORS ? "Repairing" : "ERROR", i); res->corruptions++; @@ -1398,11 +1410,18 @@ static int parallels_open(BlockDriverState *bs, QDi= ct *options, int flags, =20 for (i =3D 0; i < s->bat_size; i++) { sector =3D bat2sect(s, i); + if (sector =3D=3D 0) { + continue; /* not allocated */ + } + if (sector < data_start || sector + s->tracks > file_nb_sectors) { + /* Cluster is outside of the image file or overlaps the header= . */ + need_check =3D true; + continue; + } if (sector + s->tracks > s->data_end) { s->data_end =3D sector + s->tracks; } } - need_check =3D need_check || s->data_end > file_nb_sectors; =20 if (!need_check) { ret =3D parallels_fill_used_bitmap(bs); diff --git a/tests/qemu-iotests/tests/parallels-checks b/tests/qemu-iotests= /tests/parallels-checks index 9535024885..abd119bc7b 100755 --- a/tests/qemu-iotests/tests/parallels-checks +++ b/tests/qemu-iotests/tests/parallels-checks @@ -222,6 +222,64 @@ _img_info echo "=3D=3D an unallocated cluster still reads as zeroes =3D=3D" { $QEMU_IO -r -c "read -P 0x00 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir =20 +# Clear image +_make_test_img $SIZE + +echo "=3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D" + +echo "=3D=3D corrupt image: point first cluster far outside the file =3D= =3D" +poke_file_le "$TEST_IMG" $BAT_OFFSET 4 1000000 + +echo "=3D=3D read-only read must return zeroes, not an I/O error =3D=3D" +{ $QEMU_IO -r -c "read -P 0x00 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir + +echo "=3D=3D write must allocate a fresh cluster instead of trusting the e= ntry =3D=3D" +{ $QEMU_IO -c "write -P 0x77 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _filte= r_qemu_io | _filter_testdir + +echo "=3D=3D file did not grow anywhere near the bogus offset =3D=3D" +file_size=3D`stat --printf=3D"%s" "$TEST_IMG"` +if [ "$file_size" -lt $((16 * 1024 * 1024)) ]; then + echo "file size sane: yes" +else + echo "file size sane: no ($file_size bytes)" +fi + +echo "=3D=3D data reads back correctly =3D=3D" +{ $QEMU_IO -r -c "read -P 0x77 0 $CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | _fil= ter_qemu_io | _filter_testdir + +# Clear image, with a small cluster size so the BAT table itself spans +# more than one cluster and there is room to point before data_off. +_make_test_img -o cluster_size=3D512 65536 + +SMALL_CLUSTER_SIZE=3D$(peek_file_le $TEST_IMG $CLUSTER_SIZE_OFFSET 4) +SMALL_CLUSTER_SIZE=3D$((SMALL_CLUSTER_SIZE * 512)) +DATA_OFF=3D$(peek_file_le $TEST_IMG $DATA_OFF_OFFSET 4) +echo "cluster size: $SMALL_CLUSTER_SIZE, data offset (sectors): $DATA_OFF" + +# Cluster index 1 starts at this byte offset, which must be < data_off +# in sectors * 512 for this test to actually exercise the bug. +VICTIM_OFFSET=3D$SMALL_CLUSTER_SIZE + +echo "=3D=3D TEST BAT ENTRY POINTING BEFORE DATA AREA =3D=3D" + +echo "=3D=3D corrupt image: point first cluster into the BAT table itself = =3D=3D" +poke_file_le "$TEST_IMG" $BAT_OFFSET 4 1 + +echo "=3D=3D qemu-img check detects it without repairing =3D=3D" +_check_test_img + +echo "=3D=3D bytes at the victim offset before write =3D=3D" +echo "$(peek_file_le "$TEST_IMG" $VICTIM_OFFSET 4)" + +echo "=3D=3D write must allocate a fresh cluster instead of clobbering the= BAT =3D=3D" +{ $QEMU_IO -c "write -P 0x88 0 $SMALL_CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 | = _filter_qemu_io | _filter_testdir + +echo "=3D=3D bytes at the victim offset are unchanged =3D=3D" +echo "$(peek_file_le "$TEST_IMG" $VICTIM_OFFSET 4)" + +echo "=3D=3D data reads back correctly =3D=3D" +{ $QEMU_IO -r -c "read -P 0x88 0 $SMALL_CLUSTER_SIZE" "$TEST_IMG"; } 2>&1 = | _filter_qemu_io | _filter_testdir + # success, all done echo "*** done" rm -f $seq.full diff --git a/tests/qemu-iotests/tests/parallels-checks.out b/tests/qemu-iot= ests/tests/parallels-checks.out index 6fb2014e8e..914616d023 100644 --- a/tests/qemu-iotests/tests/parallels-checks.out +++ b/tests/qemu-iotests/tests/parallels-checks.out @@ -140,4 +140,39 @@ virtual size: 4 MiB (4194304 bytes) =3D=3D an unallocated cluster still reads as zeroes =3D=3D read 1048576/1048576 bytes at offset 0 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 +=3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D +=3D=3D corrupt image: point first cluster far outside the file =3D=3D +=3D=3D read-only read must return zeroes, not an I/O error =3D=3D +read 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +=3D=3D write must allocate a fresh cluster instead of trusting the entry = =3D=3D +Repairing cluster 0 is outside image +wrote 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +=3D=3D file did not grow anywhere near the bogus offset =3D=3D +file size sane: yes +=3D=3D data reads back correctly =3D=3D +read 1048576/1048576 bytes at offset 0 +1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D65536 +cluster size: 512, data offset (sectors): 2 +=3D=3D TEST BAT ENTRY POINTING BEFORE DATA AREA =3D=3D +=3D=3D corrupt image: point first cluster into the BAT table itself =3D=3D +=3D=3D qemu-img check detects it without repairing =3D=3D +ERROR cluster 0 is outside image + +1 errors were found on the image. +Data may be corrupted, or further writes to the image may corrupt it. +=3D=3D bytes at the victim offset before write =3D=3D +0 +=3D=3D write must allocate a fresh cluster instead of clobbering the BAT = =3D=3D +Repairing cluster 0 is outside image +wrote 512/512 bytes at offset 0 +512 bytes, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) +=3D=3D bytes at the victim offset are unchanged =3D=3D +0 +=3D=3D data reads back correctly =3D=3D +read 512/512 bytes at offset 0 +512 bytes, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) *** done --=20 2.53.0 From nobody Mon Sep 28 02:01:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785253256; cv=none; d=zohomail.com; s=zohoarc; b=cbSx5CUApxzzZ2PNvPPfR0dKP4l9OTaY0VeMp/JT09dYMiDmTW7lnNBwXtxskw8XuIaq4fS0p6EL363iXD57ZLgb0BM1pQiRw//HJzNAyrQC4hlRxxB4RkopGSarSTx9tvWkDV3GoHvB3rT6N20pX2B8Iij9Yc/roZQSQrvUd8w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785253256; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=aVkbd/prjb9WYwlM7SXvDF45HVgnD6g6uz+iwnib8ps=; b=RQMIUNxHY5Z1hBGDpXhpiyTJtMGt9T7R+SLpGglAA6f1M1iWF8JvjDm1urRNuoVFBNsH/+zQOYDG+UDUYDFGnG6ygpwX6Mqm3iXi+F8EkJdHKSGuSQA/XACbCpltt6rFKCGfbEyhOIfS7vCZl/8k2MJkPxe+D0thxYu7A1dotFc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785253256123824.115942945023; Tue, 28 Jul 2026 08:40:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wojta-0003hd-BM; Tue, 28 Jul 2026 11:39:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojtV-0003Xz-58 for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:01 -0400 Received: from mail-wm1-x32e.google.com ([2a00:1450:4864:20::32e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wojtT-0002ho-3A for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:00 -0400 Received: by mail-wm1-x32e.google.com with SMTP id 5b1f17b1804b1-495757ccbc1so36631425e9.2 for ; Tue, 28 Jul 2026 08:38:58 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f939c1465sm44190499f8f.26.2026.07.28.08.38.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:38:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785253137; x=1785857937; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aVkbd/prjb9WYwlM7SXvDF45HVgnD6g6uz+iwnib8ps=; b=kFGZwmchcNNCaQcsBA5JhavjEeLo9AsGy+RqZLT+NjL5tXkHKaZ0RLU/mr5C78FoyW qQ63a59uWuraHsuVTnXLhKN8pw9TmRgNmIbzHONs0+NHmr0zLenjXFFs4EeA83Xl8D9X W0h/KqUo7xXuPvmBfrhnQkyBmKEGyUI+kC54zaRmA4cA8UUQtsac5uAEP7JC+nKWiCB0 OGmeg4NjDfg1AD7rKfQtBqeMRYeJZxE7MYP/9NZS/DkgEJ/CBtvQfQHamXSueMKXE9U6 lwjfl+PuM0aEIJr9+zn9vGwXVkqw0Bf+O8WcplDgAXmblxlSsEh2cERJLnddE/LmuXPM Z29g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253137; x=1785857937; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aVkbd/prjb9WYwlM7SXvDF45HVgnD6g6uz+iwnib8ps=; b=KvDESAh2gJlW4FLCK8gCuixyGJY1lrPPLBJnT5QLmC1kuPNZQHHFUvKcK6h/AdrdJh SE5EaeDPXLTRXOeiFjsRkdgeb52OznXdGJsvRfSWaRvQhsUanOB4m99mx2yGbnd8Egwb kPuYQZMwR2ea8x4z01CwEDXWqcfzxfJbE3pdfp7C1pj/5M8E9pma1VsJ8eE8H0h0WC7/ RcO/7ILkOSn8jaygSNHGljJISn3gGTwIZ8VS51S+RBjBnwE6xGpd5LM6KS2i9e0H7iIl ZXgnDb7ws/zVOBV7/2LWqdONFLkk4FJod+W4FE9Vl3S4DpVrPuJPZr0fUszyb98rGwX9 suDg== X-Forwarded-Encrypted: i=1; AHgh+RrHiunQIlfIeTkuSaCKk67xgcLE7BNZjbKfBXHHGYIYWfDzSpnDL8KkwarK2rrpDMVtCmN5KF+f+pJn@nongnu.org X-Gm-Message-State: AOJu0YyFW99hDRo9VhWeK12O2GrPTD/CAo37IcPU22ujufBd9jReNd+m iScipCiKTiM2t7++Dt6jPwXWmWU23yPNs76lepyTkYzVhJ8reuZGZBiFeTvILjv8ceU= X-Gm-Gg: AR+sD11y1esMMDBCSAxMDsHc0Az6f1eHtadqG3RkVe4bUVCEz0/oO6RFDwzY0Fg0pwJ R5h2aszJARZLeXzIXxtCU0Bs7UDzCD5PkcMChBB+4xcfB8enZS2txL4QTsZEVJKJfNCHQFwjMJr +dzjk5uzxzXtsYRv5k0u6KuCtGMK/yAIC9zZTDh9+DmL7dsnmczn7kJddoV2Q5YTZYl2O5IQh8J ff2MI/cYQ84gjrzN1y3GqHAIWRIvZII6P4urQAYutm/QD1IWcWt/KSk8bHawuLS9AUNEmz8vXsW lrvJN0I7Q3dJi8woaxBlcoW6ziCpMtCXGVacd7wFttAjGCUynFkro0fIfx2SDR2tMu4vUkQV0c8 z90bAO17eJtcah8QPlEDsFRH/mbTm8tTBuYU5WpBZy7sgU3gdBvpOB4ZJYk0DeMRhB+2l9r6fmg == X-Received: by 2002:a05:600c:4694:b0:493:f528:58ac with SMTP id 5b1f17b1804b1-496c657a89dmr37477855e9.21.1785253137479; Tue, 28 Jul 2026 08:38:57 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL v2 5/9] parallels: validate bitmap L1 table size before allocating it Date: Tue, 28 Jul 2026 17:38:45 +0200 Message-ID: <20260728153849.601939-6-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728153849.601939-1-den@openvz.org> References: <20260728153849.601939-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::32e; envelope-from=den@openvz.org; helo=mail-wm1-x32e.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785253257455158500 Content-Type: text/plain; charset="utf-8" parallels_load_bitmap() allocated the L1 table sized directly from the untrusted l1_size field, only cross-checking it against the bitmap's actual size after the allocation and the L1 table copy had already happened. Compute the expected size and reject a mismatch before touching the allocator, instead of after. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels-ext.c | 33 ++++++++++++++++++++------------- 1 file changed, 20 insertions(+), 13 deletions(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 3410daa620..97744c9696 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -70,20 +70,11 @@ parallels_load_bitmap_data(BlockDriverState *bs, const = uint64_t *l1_table, uint64_t offset, limit; uint64_t bm_size =3D bdrv_dirty_bitmap_size(bitmap); uint8_t *buf =3D NULL; - uint64_t i, tab_size =3D - DIV_ROUND_UP(bdrv_dirty_bitmap_serialization_size(bitmap, 0, bm_si= ze), - s->cluster_size); - - if (tab_size !=3D l1_size) { - error_setg(errp, "Bitmap table size %" PRIu32 " does not correspon= d " - "to bitmap size and cluster size. Expected %" PRIu64, - l1_size, tab_size); - return -EINVAL; - } + uint64_t i; =20 buf =3D qemu_blockalign(bs, s->cluster_size); limit =3D bdrv_dirty_bitmap_serialization_coverage(s->cluster_size, bi= tmap); - for (i =3D 0, offset =3D 0; i < tab_size; ++i, offset +=3D limit) { + for (i =3D 0, offset =3D 0; i < l1_size; ++i, offset +=3D limit) { uint64_t count =3D MIN(bm_size - offset, limit); uint64_t entry =3D l1_table[i]; =20 @@ -124,12 +115,14 @@ static BdrvDirtyBitmap * GRAPH_RDLOCK parallels_load_bitmap(BlockDriverState *bs, uint8_t *data, size_t data_siz= e, Error **errp) { + BDRVParallelsState *s =3D bs->opaque; int ret; ParallelsDirtyBitmapFeature bf; g_autofree uint64_t *l1_table =3D NULL; BdrvDirtyBitmap *bitmap; QemuUUID uuid; char uuidstr[UUID_STR_LEN]; + uint64_t bm_size, tab_size; int i; =20 if (data_size < sizeof(bf)) { @@ -164,6 +157,17 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *d= ata, size_t data_size, return NULL; } =20 + bm_size =3D bdrv_dirty_bitmap_size(bitmap); + tab_size =3D DIV_ROUND_UP( + bdrv_dirty_bitmap_serialization_size(bitmap, 0, bm_size), + s->cluster_size); + if (tab_size !=3D bf.l1_size) { + error_setg(errp, "Bitmap table size %" PRIu32 " does not correspon= d " + "to bitmap size and cluster size. Expected %" PRIu64, + bf.l1_size, tab_size); + goto fail; + } + l1_table =3D g_new(uint64_t, bf.l1_size); for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { l1_table[i] =3D ldq_le_p(data); @@ -171,8 +175,7 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *da= ta, size_t data_size, =20 ret =3D parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitmap, e= rrp); if (ret < 0) { - bdrv_release_dirty_bitmap(bitmap); - return NULL; + goto fail; } =20 /* We support format extension only for RO parallels images. */ @@ -180,6 +183,10 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *d= ata, size_t data_size, bdrv_dirty_bitmap_set_readonly(bitmap, true); =20 return bitmap; + +fail: + bdrv_release_dirty_bitmap(bitmap); + return NULL; } =20 static int GRAPH_RDLOCK --=20 2.53.0 From nobody Mon Sep 28 02:01:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785253246; cv=none; d=zohomail.com; s=zohoarc; b=CZ++ZSevCebheLX01CuqYpwDkpewWZ6cAl7hjJK8bWzvWjIKrKd3lyOqh1EUdy9tap6O6yOZ7og3uQVIO4ikV2vDsj4wS369jtTZfKJJYb8aoCyqS3TjqfFdMdgbCkzVYVtzx6w2RdMT2FDKhO+djP1XkUesZzL/TMI48sYshs4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785253246; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7pAFxtzfR1kXmS5OJ99MnGy/nFG6E2fuCMA2MDYotSI=; b=PFX/0BHqaIuIic3NsrIoV++HGzvfeAB7pG2xXelnVwQ6ujNwUls/h1mgpDVui+r1UxGLRAm06wIK87CRJWMW1crDLJmZQLEAoai1YiKwD04/ZiEQCvROe6THJMg4Kncb+ta/CB5lUfEtYs0YzjoGLxVJiGFFaNrT1Avxoq3ezWs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785253246632927.2896302704593; Tue, 28 Jul 2026 08:40:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wojta-0003he-Bi; Tue, 28 Jul 2026 11:39:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojtV-0003Ys-Q6 for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:01 -0400 Received: from mail-wr1-x435.google.com ([2a00:1450:4864:20::435]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wojtU-0002ij-1p for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:01 -0400 Received: by mail-wr1-x435.google.com with SMTP id ffacd0b85a97d-47c2b362ee2so11759f8f.1 for ; Tue, 28 Jul 2026 08:38:59 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f939c1465sm44190499f8f.26.2026.07.28.08.38.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:38:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785253139; x=1785857939; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=7pAFxtzfR1kXmS5OJ99MnGy/nFG6E2fuCMA2MDYotSI=; b=bZtobW6anmEk3bHqnf2q3pujlmoNhZXl2+o05VTmSe615Sm+4+jDbgSXoTXsALabae aStSGtjmArcBcljyCyXaY/EWMjz/uxGgUU7fseYVckYqRlzfWqI+xE3qmKbXK3hIGcht HnT4eMMz7pjYZL7Iw5SHVvaHvbnhmn30vUXeh64WbEZ+td6a5IHPzz2gjF9iKH6pWTnc EbGFZvAQZLCJfXaIWhu1S6T9AFV29ZAE3SgnnG8ZeaC0/NX3v3g+0PlkRr0IR1N5HqTv GvYEnY8TgEUJ+59dL+0EYB66uDjsem6p0CaZ2HTNQG9RIalcshhz+enfcHqDV9QWRgTP a0lw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253139; x=1785857939; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=7pAFxtzfR1kXmS5OJ99MnGy/nFG6E2fuCMA2MDYotSI=; b=VS5zJ1zT1+r9Uard3pPAWxHA8M2eTO9XTLBPh+OLju3WQW5HBarhoipPKPZCstv9r9 I+ccX08TLwOMuZA0bZXELeSB+CeL4wTnRsDe9U3lGHXp4/xS4yooBnUkSlT2zEwPwgat 1/zplKq7wlVPEawfiw+J3rjW4lBsjWLehdzqvmIlAaHggNO9XqQCunTdFwnImlFy92cb wopRP9C7Gqtt8rBTxvlP92A2dSy57mJVEFmvKOvtC9Bx7a84DKMblUSi7qQHdRu6sWEx 7XbUU/kOQJ+TxaZLJnSh1zKWC/fDIayiU6D4ClQA6/hbB/Aanxe8E36jpKHDPahXPEj6 CIUA== X-Forwarded-Encrypted: i=1; AHgh+Rr/PweZQ1WUX7XXKP8ztDBFrivnyqFW9kMBm96pAJ1nI8ftWvJ8hrzpFC5ap7W2a8ZgcU/SFx784wa2@nongnu.org X-Gm-Message-State: AOJu0Yx+Vf7DHXYJEWEdDZE0JOLs/f9GpKiYk2GOoEDPoZPBSmbuBuHv 6JdFUxot6nmjdVmV1/0KqqE7MclG2Q0X6shg9QOt0ALtP6v/EMBZU03WVdXXRM1Ywqg= X-Gm-Gg: AR+sD100duvjqTw/OC3Gj4B7Bjzxo+nhPd0YKwbgjMYrDsA3pDaxgimLQYjfsEpdYje EtzpeT7wDp3cjhI5JAAZnpYH4YDmidS+JY0q0xTKUdkrpadUTrcdceTFaqR4ytFOblNvJyVfhq+ sIs3de5TpeAa65OmRQo1SzQtOCOiymBiMC0uoQU+6mROHFP4/rq8cHD3MDZaYdiN6IzVkoFn+9b sJC2dAXR9hCCxGonFeBL+uVVEOMhqTFmwJD9KX/BdoxOVWfM92gM91IRcDqE6sbmOr3fALjzG6F Oa7MKkK9GBFDw2asdWiS6ubSJDTkX7xCnjYz4UmLgFExvBhtAGh96wlLvqbmkxOSpxFp6rf/eE9 q9dfs9l4RwG8ZGgc4qKtzHpAbvnlsfSl1Lin53BKJ10wJl+1Y9mU5AXN+DFN9XieELjMUg9fumQ == X-Received: by 2002:a05:6000:430c:b0:47f:9839:a79a with SMTP id ffacd0b85a97d-47fb1ec8808mr3674552f8f.10.1785253138574; Tue, 28 Jul 2026 08:38:58 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL v2 6/9] parallels: skip loading a genuinely empty bitmap L1 table Date: Tue, 28 Jul 2026 17:38:46 +0200 Message-ID: <20260728153849.601939-7-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728153849.601939-1-den@openvz.org> References: <20260728153849.601939-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::435; envelope-from=den@openvz.org; helo=mail-wr1-x435.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785253247265158500 Content-Type: text/plain; charset="utf-8" parallels_load_bitmap_data() unconditionally calls bdrv_dirty_bitmap_deserialize_finish() even when there is nothing to deserialize, which hits an assertion in hbitmap (hbitmap_iter_init: 'pos < hb->size') when the bitmap itself has zero size, i.e. the disk is a zero-sector image. Skip allocating, populating and loading the L1 table entirely when l1_size =3D=3D 0. This is safe only because the previous commit already guarantees l1_size =3D=3D 0 exclusively means the disk has 0 size. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels-ext.c | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 97744c9696..704e16e1de 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -168,14 +168,17 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *= data, size_t data_size, goto fail; } =20 - l1_table =3D g_new(uint64_t, bf.l1_size); - for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { - l1_table[i] =3D ldq_le_p(data); - } + if (bf.l1_size !=3D 0) { + l1_table =3D g_new(uint64_t, bf.l1_size); + for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { + l1_table[i] =3D ldq_le_p(data); + } =20 - ret =3D parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitmap, e= rrp); - if (ret < 0) { - goto fail; + ret =3D parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitma= p, + errp); + if (ret < 0) { + goto fail; + } } =20 /* We support format extension only for RO parallels images. */ --=20 2.53.0 From nobody Mon Sep 28 02:01:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785253207; cv=none; d=zohomail.com; s=zohoarc; b=VcU3zuPEbIuzVijsDu+cjmtTe1NiyeMXlUY7siVzGQj4rclKODF9KEXm4Oc5knLuPt+ef94DwZsTun+qqKawy00zx/LGgWYxIR1717Iuyg/mL6DKN8dWMbOL5Ix+tdBqekt0kTxlGySPnjNLxfoKgG7Wbgw+oXdafi4m8CmVgNA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785253207; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yfUxWo9DRfnzypPrGvcp6jHwrWI7DnwyNSb11uKFohg=; b=H90OUXoKmsZz/VY0rP61TRyXZ6tMNktY0wQID3FM+/MIOC3aNYLxciizqVZqzWMEONNcZ1MFXyHvhXPI5Rh6Vj9YVa+vLeZfrTKr5d4WvN5FAbi25vTi85UP2DlrlC1l4/gp5l5KPhQVRscZLSNZhjK3GW8I4tpElO9LoXB4KjA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785253206993530.4576717949933; Tue, 28 Jul 2026 08:40:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wojtY-0003e6-Ge; Tue, 28 Jul 2026 11:39:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojtX-0003aH-1F for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:03 -0400 Received: from mail-wr1-x431.google.com ([2a00:1450:4864:20::431]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wojtV-0002jt-4a for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:02 -0400 Received: by mail-wr1-x431.google.com with SMTP id ffacd0b85a97d-47de0093c42so7069f8f.3 for ; Tue, 28 Jul 2026 08:39:00 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f939c1465sm44190499f8f.26.2026.07.28.08.38.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:38:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785253139; x=1785857939; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yfUxWo9DRfnzypPrGvcp6jHwrWI7DnwyNSb11uKFohg=; b=b7sK9nZXoiD1GhYKAGMcusAU8sugsyFFkLMCBTiEnbYeXXPcV/CC/FCI9p6TlNTC6o RlURB68TsS42Jl8FmYRCv3yjz6Xd69cLV7TUd6BMBkLzhJkBaTkcFPM62LO/DPDoYXrM FVsGr8l3A2cwbx9faG2j3GJvGgmAhAhnsx/5sZqU//qEZ3RqEPU5kw6ffmRefHMb/KBf 9nvvz4Wca+LkFsOS1AsY/Fup1foYlpuWKEYZs8tVr9WO7lpFM9TqX7705fQ3UK6ULBwI LT7MzgcZuZTfFa642B8rOREVHxnumX7CSONXXxuMmnCgqDciqieWJmKS2BkAGY5s4Wne 8byw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253139; x=1785857939; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=yfUxWo9DRfnzypPrGvcp6jHwrWI7DnwyNSb11uKFohg=; b=WGIMvbjn2V2nkuxOoqctk+tGZ1sAYJM+G1jdDlVDiOnLu9o0S9x23NVO6URYwBlCm4 ClngnaPK17hd24mp/RKgpJyjYvJdSJRJR4StyJDh5q59edhl/9+2aoIQWr0VN5Iuq2cG nhtYg7YURek0vXkii8gNh37ogBOoxRea7cJgLSr4EHqhyg+AJ9R84BGelm6QsjZntrzM 7FK5rtRVTFFsc1PE/bJ7xSoQt3C5xxb8quPN0+tuWBMqGRMz79pXNNmmT005Bklga8XW PmHon4cfFCwKalv3V0gN9Jd9tiNMyWsItkBsKqi+kPac6cM7MtTptsBw6NvDuft/VVGI DCwQ== X-Forwarded-Encrypted: i=1; AHgh+Roh3A9V9MbvDgROSbUM2EoVdrpVCU5k1qPLCrEv5HWpDvx2F5RsXXyFKUHH+hKfJaXvf4D2vHarQ+NS@nongnu.org X-Gm-Message-State: AOJu0YxpXmbOeOpQP/7wZIJGMkCG6k+EbZvQycZImoWqk/ETU/E3lGG6 gG7Ibnoe/6Dd9uE5aobYmYBgBDhIFq41yp/8K3QR6BjKQy7ypDuijxdqj2CiXx6FVru9xyg0FIs pQMbN X-Gm-Gg: AR+sD119joIxY6W2MdETmt/eDdMjAFU/oIl9ESKaX4l+vYKsggqQVqNpVGOjMl0THTi Fjc0Qm3u7DI7qj6XXatbzVIIsq6QyuLLk4Hr2OkDleOR9CHbUsKHf8bs0Oo0hyhMuzVumzOZhHo QkOHrtDV75Zi/28gETvI8qrAAU4ZW/iqulwkd1KsLKJtev1rtU7vhNUuOowNy8+W9SZ/CiwNdBk AY3OC6pu+2aaJCaEhCTitR7CXJemb2AsFiWd813/qkW5rJmWrjfgTJAWJZUHFAb/VBB1xOPJHtL B6+Si52tv6cfA+XTm+XQr0l+so5OjCx3eq2EVpJTa+IUxDQ0JYrSovWPKg0DnITuvha+6ni4qE4 tPZCyvnMpJhKktW+aJcpm1/Cz47O/rqN/z6/hq8oVejVkMLmUmrkm9+LBfvy6C+sLHRBoxD5ZXw == X-Received: by 2002:a05:6000:200e:b0:47e:1d9a:1123 with SMTP id ffacd0b85a97d-47fb1e60ec0mr3523553f8f.3.1785253139597; Tue, 28 Jul 2026 08:38:59 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Thomas Huth , Stefan Hajnoczi Subject: [PULL v2 7/9] parallels: avoid fatal abort on large bitmap L1 table Date: Tue, 28 Jul 2026 17:38:47 +0200 Message-ID: <20260728153849.601939-8-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728153849.601939-1-den@openvz.org> References: <20260728153849.601939-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::431; envelope-from=den@openvz.org; helo=mail-wr1-x431.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785253209022158500 Content-Type: text/plain; charset="utf-8" parallels_load_bitmap() allocated the L1 table with g_new(), which aborts the whole process on allocation failure instead of returning an error. Use g_try_new() and fail the open normally. Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels-ext.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 704e16e1de..7f6ab6b0d2 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -169,7 +169,13 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *d= ata, size_t data_size, } =20 if (bf.l1_size !=3D 0) { - l1_table =3D g_new(uint64_t, bf.l1_size); + l1_table =3D g_try_new(uint64_t, bf.l1_size); + if (!l1_table) { + error_setg(errp, "Failed to allocate the bitmap L1 table " + "(%" PRIu32 " entries)", bf.l1_size); + goto fail; + } + for (i =3D 0; i < bf.l1_size; i++, data +=3D sizeof(uint64_t)) { l1_table[i] =3D ldq_le_p(data); } --=20 2.53.0 From nobody Mon Sep 28 02:01:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785253256; cv=none; d=zohomail.com; s=zohoarc; b=FAjE/LYJuUVVgXGCpR3FP7LBWHERCGwEyE0995dHC3hA1c2DP25tgLbcGdzkCHjubuzI6sdZB17GMvYFR5nEjxME29ylKn/J7SQRRxiHG14yXobR0aaGiZVKTJrTuvq89CLFS/dB0UTJ5QHV2i0eS1scqGcTX2n2mYJVXJzg3mc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785253256; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ocPifY/R3bwmKezKFKwv/i1fMHzlWhj+bCpqwVCgyZo=; b=nXyI7R9XTfwZw/vGYEhGn5uYoMJP0algNvzkXG3v0qmiGoir0+NEgXBXaxel2wN7s3281amEd2Wxjf+qZPHgGBZ7MZRX1hYJrxpdNUjdzJx8lq/0ggEy9SXb33sY0YoqbQ7ATDKI8Q0sacJzHvqLpgO9cdBvJZeLD/hL52Irl5s= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785253256932592.0575815769383; Tue, 28 Jul 2026 08:40:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wojta-0003i5-Pg; Tue, 28 Jul 2026 11:39:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojtY-0003ee-Kk for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:04 -0400 Received: from mail-wr1-x42a.google.com ([2a00:1450:4864:20::42a]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wojtW-0002lt-O5 for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:04 -0400 Received: by mail-wr1-x42a.google.com with SMTP id ffacd0b85a97d-47df43bfb07so7444f8f.1 for ; Tue, 28 Jul 2026 08:39:02 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f939c1465sm44190499f8f.26.2026.07.28.08.38.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:39:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785253141; x=1785857941; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ocPifY/R3bwmKezKFKwv/i1fMHzlWhj+bCpqwVCgyZo=; b=kUkVMN7MBU0PfTgeGwoZTyYyMVsbbjDH4pzcINiemXWn9P9GS79CnQvYF5e5VyQfw+ LHWntliWiCErI3EcyOmwzMPNIaKiW2yUCMlwBxquQt3+mV1YveMqeZ/gv8aPH4dhu68o USI+Kus5rw//UTrXty5GJMoeJhH3WjJ4Mmsm1/BuWGou2n5wXi0Mde7FbecY1MRpMCgX 3iZy0cQZreHTWMyCt5STzsLFWIcMnjhqHCzte5CVkTg8ssUq/RP7PkYgv4M1bhqxzuiD zJWk5yMMqoBzvPTwKQKJ0LUmMm4UXCW/KQ5ZUEslw+4uwvA+v94qzTQ12WGfqQhYBHZ5 6wYQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253141; x=1785857941; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ocPifY/R3bwmKezKFKwv/i1fMHzlWhj+bCpqwVCgyZo=; b=XPFM6ZQHJ3LexPy5jmc5XC8lJrvlJq2EnGZHb5StylRQMppTBLZ87aVH0z9wpYZ3P7 Msz4tXA2oyPhV6oJB96/5MnhS2drwRm39EaHQbRfNeYexTsNiUixjwa9SIT5I/vliJrM /tigMC8bUrccbQzw51wTLc6Na8Na9x0ldUv92gQM+4oHO8MzW4ut7hjp2ntcAOckL2l+ K3nIokSYwcx96CAA0cfm1drVQbIcCcqxldvJRvNlfEC19BVyFTK8qmePVBAebZlSQnd4 dkiOFV6b2wQegwMz4JKeYn1tfkRwLqceUgSHXxgXrs5mI3cZz9xT9LYYp+VYcpnCf70I 61zg== X-Forwarded-Encrypted: i=1; AHgh+RrQIP3Vy9TrD8LxZvESLLnrbdS9P9twCREmipN/rFzGflOHW+fk2LvVjZiPdkIg3bKIoHsRn/4CsZZL@nongnu.org X-Gm-Message-State: AOJu0YyBsIL536v9cmv9RgftSbP3i2pOhGuDiYfiv0Mxt1zuDhv2my3E lk0WrlIgnEDGwxzwe78KiPPCGIANY7EmSlUdqll9JK/u9C4Xc49453VT/RJX4eFa320= X-Gm-Gg: AR+sD11GecY3gIfu2a2g3ye7YJ2O3rQynAsQA4SLcZ4PyPH7cjSgiZAud6ARJ5HtTzc aRx6I0iXT8r4l9jETq+/gUJctu78zeZRF5HoTRIYVuOd2x3k9D4S0SdooGK/E4cUveB4Pj3COAV WX/VuhrLo3Ih0nfuK87QHZoB7TSaUTI0T5Axa0yEHxDQ9hw1Q1oB8biUIZ0FLulOMjx+rF/O4Y2 JndLHzHHsV40LbyZzCk32Bko8QmjQaGLhACM5rQe6AN7ITw+BFtbiDgaoW0puDyfOk8aAfA91Xl wcIy8zVmuC6xHmInoGuu5zDK2QPJfVDWDDLEdmFUGF2H1tASGgKDE9cnTZIBsHykh15ivtpbow4 50VBA0Pj0vtne2o8Tx2+hj/P5sF5y/X+SlL6AUc+jpWsNscIbPeL92GETgGXeHdSShLeXfEwdlg == X-Received: by 2002:a05:6000:2905:b0:47f:87f5:ed32 with SMTP id ffacd0b85a97d-47fb1f1ee67mr3730714f8f.46.1785253140831; Tue, 28 Jul 2026 08:39:00 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Feifan Qian , Thomas Huth , Stefan Hajnoczi Subject: [PULL v2 8/9] parallels: validate BAT capacity against advertised disk size Date: Tue, 28 Jul 2026 17:38:48 +0200 Message-ID: <20260728153849.601939-9-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728153849.601939-1-den@openvz.org> References: <20260728153849.601939-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::42a; envelope-from=den@openvz.org; helo=mail-wr1-x42a.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785253257468158500 Content-Type: text/plain; charset="utf-8" parallels_open() copied nb_sectors, tracks, and bat_entries from the image header without checking that the BAT actually covers the advertised virtual disk size. An image whose header claims more sectors than its BAT covers passes the generic block-layer bounds check on open. A write into the gap between BAT coverage and the advertised size then reaches allocate_clusters(), whose internal assert(idx < s->bat_size && idx + to_allocate <=3D s->bat_size) aborts the process instead of returning a normal I/O error. Reject such images at open time by requiring bat_size * tracks >=3D total_sectors, matching the invariant that allocate_clusters() already assumes. Reported-by: Feifan Qian Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3804 Signed-off-by: Denis V. Lunev CC: Thomas Huth CC: Stefan Hajnoczi --- block/parallels.c | 6 ++++++ tests/qemu-iotests/tests/parallels-checks | 21 +++++++++++++++++++ tests/qemu-iotests/tests/parallels-checks.out | 7 +++++++ 3 files changed, 34 insertions(+) diff --git a/block/parallels.c b/block/parallels.c index 8a7e8b4aba..93b5fa9dcd 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -1328,6 +1328,12 @@ static int parallels_open(BlockDriverState *bs, QDic= t *options, int flags, return -EFBIG; } =20 + if ((uint64_t)s->bat_size * s->tracks < bs->total_sectors) { + error_setg(errp, "Invalid image: Catalog size too small for " + "advertised disk size"); + return -EINVAL; + } + size =3D bat_entry_off(s->bat_size); s->header_size =3D ROUND_UP(size, bdrv_opt_mem_align(bs->file->bs)); s->header =3D qemu_try_blockalign(bs->file->bs, s->header_size); diff --git a/tests/qemu-iotests/tests/parallels-checks b/tests/qemu-iotests= /tests/parallels-checks index abd119bc7b..d2a08049d9 100755 --- a/tests/qemu-iotests/tests/parallels-checks +++ b/tests/qemu-iotests/tests/parallels-checks @@ -225,6 +225,27 @@ echo "=3D=3D an unallocated cluster still reads as zer= oes =3D=3D" # Clear image _make_test_img $SIZE =20 +echo "=3D=3D TEST OVERSIZED VIRTUAL DISK CHECK =3D=3D" + +BAT_ENTRIES_OFFSET=3D32 +NB_SECTORS_OFFSET=3D36 + +TRACKS=3D$(peek_file_le $TEST_IMG $CLUSTER_SIZE_OFFSET 4) +BAT_ENTRIES=3D$(peek_file_le $TEST_IMG $BAT_ENTRIES_OFFSET 4) +COVERED_SECTORS=3D$((BAT_ENTRIES * TRACKS)) + +echo "=3D=3D advertise one more cluster than the BAT covers =3D=3D" +poke_file_le "$TEST_IMG" $NB_SECTORS_OFFSET 8 $((COVERED_SECTORS + TRACKS)) + +echo "=3D=3D open must fail cleanly instead of aborting =3D=3D" +_img_info + +echo "=3D=3D write into the uncovered range must fail cleanly too =3D=3D" +{ $QEMU_IO -c "write -P 0x41 $((COVERED_SECTORS * 512)) $CLUSTER_SIZE" "$T= EST_IMG"; } 2>&1 | _filter_qemu_io | _filter_testdir + +# Clear image +_make_test_img $SIZE + echo "=3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D" =20 echo "=3D=3D corrupt image: point first cluster far outside the file =3D= =3D" diff --git a/tests/qemu-iotests/tests/parallels-checks.out b/tests/qemu-iot= ests/tests/parallels-checks.out index 914616d023..c33f3852a8 100644 --- a/tests/qemu-iotests/tests/parallels-checks.out +++ b/tests/qemu-iotests/tests/parallels-checks.out @@ -141,6 +141,13 @@ virtual size: 4 MiB (4194304 bytes) read 1048576/1048576 bytes at offset 0 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 +=3D=3D TEST OVERSIZED VIRTUAL DISK CHECK =3D=3D +=3D=3D advertise one more cluster than the BAT covers =3D=3D +=3D=3D open must fail cleanly instead of aborting =3D=3D +qemu-img: Could not open 'TEST_DIR/t.IMGFMT': Invalid image: Catalog size = too small for advertised disk size +=3D=3D write into the uncovered range must fail cleanly too =3D=3D +qemu-io: can't open device TEST_DIR/t.parallels: Invalid image: Catalog si= ze too small for advertised disk size +Formatting 'TEST_DIR/t.IMGFMT', fmt=3DIMGFMT size=3D4194304 =3D=3D TEST BAT ENTRY POINTING OUTSIDE IMAGE =3D=3D =3D=3D corrupt image: point first cluster far outside the file =3D=3D =3D=3D read-only read must return zeroes, not an I/O error =3D=3D --=20 2.53.0 From nobody Mon Sep 28 02:01:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1785253197; cv=none; d=zohomail.com; s=zohoarc; b=c+66cNkDjJwdQfYJev/8TlF+u+lXXGhjbJfbnr0cpLaxvSoM3A5WHmptnloOGfkOWkGhyEQS4P7eldbuTHJgO8/zdEnzMgvVvvYKeRVYXgXjo7MZ0OPl1ucigsdTQGhbMUwUX8JKfz/kCBS4RXh7JznamdloCpNbwEYR77h0U+s= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785253197; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=uhfeGe/4CB094Qsb3YMVun3IRBzdJrjy7hL+hy4mT8o=; b=LRbswTu82VGxyzM6Y6eSPK2ScV0x+K288P2k7/USwPBZLbPoZaLvPS1FptDo+NiHlk/4yOJiIrmhnDz76mxKCLymx0gcKAUbxsdi603NTcVBF38GjBShEMe1n8w52Awvvc92Y0mhjxfFwC58TulkeMgv0Tby7LxX8ngitlmXkck= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785253197870187.9917287543908; Tue, 28 Jul 2026 08:39:57 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wojtb-0003io-68; Tue, 28 Jul 2026 11:39:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojtY-0003g5-VT for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:05 -0400 Received: from mail-wr1-x433.google.com ([2a00:1450:4864:20::433]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wojtX-0002mV-As for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:39:04 -0400 Received: by mail-wr1-x433.google.com with SMTP id ffacd0b85a97d-47ddf7b09e5so13527f8f.1 for ; Tue, 28 Jul 2026 08:39:02 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:45be:7876:b62b:ca4]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f939c1465sm44190499f8f.26.2026.07.28.08.39.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:39:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1785253142; x=1785857942; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uhfeGe/4CB094Qsb3YMVun3IRBzdJrjy7hL+hy4mT8o=; b=to7vuMGBX0XZJl2XuOS3A3K9mTXum4WeNtwIp2bqrqgI9AjdrrF/OvxFUVxLyq7AAJ ZuDi/MTgs0Or/hzSyaAnjiDPR/Bt7mUa6JL5Ezi0Crw57xD5bgsVlFOZLv3gnmOvXq9p qnBAmwjNG8Ud2dJUqqQpk4YMyEryDHep1vMtfDdzkGxql8BkclQ+9zbAnXGhnQy19cEF TDJKbBs7ugyy2tiGA37hMt5X8CEpkbL/i2QPgCwuPcirKwuWjub7CmqgGTgLPWll7QRz LIH7nPZ9QxMWfeYnW7R1nbIudpQIbX6WhjHN12feEAKTksISh3des3xFNlqTWgIOfnuu w1HA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253142; x=1785857942; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=uhfeGe/4CB094Qsb3YMVun3IRBzdJrjy7hL+hy4mT8o=; b=hfphq53OHd4zQFPr65O33h4sufmwrgeHNohKSVK60n11FBHSd558R0ejUthvHEWPOo GWgIEzd3G5EpsEb+xWhvXw7YQjvMYCnY0nsYpHRTJ0l5Fs4Lvw/4bb96AWOtns4uSZtx G+aKN/t1ZpzIDDUiRVX/ju5sWBvfEXhRhQd2Agy3/mB9R+0wkpozICqhr9Fhy13RBprf ChVxXhDPXZbFwrLC01FwIsWSwa+9m6EMom5UmGqUYvHfrArHqaoIzF/AFy7Jv3Q2+pUy xmuUmzPhQzXtKfOlvHc6x46dteI/TQAVqGfWCd79AXfNvr4lqQFRti6jvnDd79/95bHU 7ebw== X-Forwarded-Encrypted: i=1; AHgh+RqtW5TIXue0dJZMZfBlhNJEw2HndXEuUW952P3EBRNU52w81UQwEo6OfvZntLCmlgSc0oEPaEykC8b1@nongnu.org X-Gm-Message-State: AOJu0YyMZOrUQ+rJo4MxMtJdxBP3GA2G4yO+mCkcB1qsmrglUMict5CI BEta+DdgMPyg9v3P/N2Kp063hbMQ7W2n114q0Ka06jJQCWlVbt1sWTAvLuAcSHAe4SQ= X-Gm-Gg: AR+sD12JcmAMqzLYr5f2SPwWyCb7Zw4WeJF6eFPnvWjZvywukMqWjBBDnFaJG5NQ/5k 4qTFt0cYw/cKYjHulCBvdNC8M8bP9Yk7FE+yxSwYdogr6d68414+1CzYY+IeMC97+I4HJ0PE+WG uuJ3BeyTR4LCThXTqMva+FXfpm5fByFx0RfBp3cerFoC0gg0kcc4efmcynaYBeEArYMjhA0MnT0 WNAuKLzfn6CGlsWLb7aMv3WtwWkrTWNxmDp2PpNyGkKYVV9WbQ8U4Gh7sdxKywsDWOj7JH3eVux PH9mexw5yCZYLIljCuE78vJR5OiC7TbTbCpcX4Viu16VRmZXTmW7nl+rjTaSp2POBuhIKpClKRW k+aPYVf8bEloDB329ajL8qTcsVklezNd5eYA7h5bK52TwDqajnbL0vua2YB0Z4W7G7BSShwuEuQ == X-Received: by 2002:a05:6000:41fe:b0:475:f100:35f4 with SMTP id ffacd0b85a97d-47fb1ee73ecmr3347316f8f.49.1785253141830; Tue, 28 Jul 2026 08:39:01 -0700 (PDT) From: "Denis V. Lunev" To: qemu-block@nongnu.org, qemu-devel@nongnu.org Cc: den@openvz.org, Stefan Hajnoczi Subject: [PULL v2 9/9] MAINTAINERS: update parallels tree location Date: Tue, 28 Jul 2026 17:38:49 +0200 Message-ID: <20260728153849.601939-10-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260728153849.601939-1-den@openvz.org> References: <20260728153849.601939-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::433; envelope-from=den@openvz.org; helo=mail-wr1-x433.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1785253199152158500 Content-Type: text/plain; charset="utf-8" src.openvz.org is become unmaintained, point to the GitLab tree instead. Signed-off-by: Denis V. Lunev CC: Stefan Hajnoczi --- MAINTAINERS | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/MAINTAINERS b/MAINTAINERS index a28935c898..902db77218 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -4393,7 +4393,7 @@ F: block/parallels.c F: block/parallels-ext.c F: docs/interop/parallels.rst F: docs/interop/prl-xml.rst -T: git https://src.openvz.org/scm/~den/qemu.git parallels +T: git https://gitlab.com/dlunev/qemu.git parallels =20 qed M: Stefan Hajnoczi --=20 2.53.0