From nobody Wed Aug 26 07:38:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1786470060; cv=none; d=zohomail.com; s=zohoarc; b=AmqFZH+nQarPpW58o/7ZKQ/OlIfgu18qBbLMUWnZYqep8s2nxHccu9OgPVQulFUbXp6jcGzXoGAFaIgVy49cO+ZNF/l0XhcVcHJ1/ohPJAnTozhzt2Pm8l54OKOpspD4hBF8gpMEp+6Kua0yKVAf53nBdhTDlWVwPgfHGIazXKo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786470060; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=N69DbYpUl1rZqFPWyq/bw6JFA1tssKwuW30lwMxOl1A=; b=YLA1f1SZpMxz30j3l6KJKb2eGsq0v0cwnyx6ioKSGC6AnRf/MPDdaTwZ9Nu09FMFRb3JYHRP2p3uoAPYDkGftgQ24blVxBbiA1DfrQEQYNC00e7sTYV1yjPbxmHb6lXpvbZ+ENOAa06d3m5VzVJontqqGVkKrof/8GnsQ0P9460= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786470060738320.9573577361258; Tue, 11 Aug 2026 10:41:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtqRR-0004W8-Ud; Tue, 11 Aug 2026 13:39:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtqRQ-0004Vd-KL for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:08 -0400 Received: from mail-ej1-x62e.google.com ([2a00:1450:4864:20::62e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wtqRO-0000Rd-M8 for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:08 -0400 Received: by mail-ej1-x62e.google.com with SMTP id a640c23a62f3a-c1712a04ddaso14922266b.2 for ; Tue, 11 Aug 2026 10:39:06 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:c43:d230:7bbc:68d4]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a362ef7525sm880945a12.29.2026.08.11.10.39.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 10:39:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1786469945; x=1787074745; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=N69DbYpUl1rZqFPWyq/bw6JFA1tssKwuW30lwMxOl1A=; b=DOcUjRF9L/3FQxBN6JHu3RbEkHqA7JhP626KQYaySJZN//isMyCB7Z7g9tlm4X8sC9 Dq3SoQClpxaLr6iuFxwpSle3NlD/RTSTyU02jYDNqiCh7cCtn0dZ5SQbjzuEeztAybdy 9Soki4ytn9rwFw1ACkxuNp/vpvicLoq9CTY0ns0DPTcpPHwQsjmonud2iNG+dXM0je8X I73Pc/7pxeELo1SCUfYJpG+AY7REiza21mNhlTnTbXq4laSesjO/eo770v2/6RdFcTgz 6rnX+nPKZK8M39HQOjh1GNMUotinHtRBsLs5I6iYy5eK9kAZh3K73gODmynrCKltO0NJ kIgQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786469945; x=1787074745; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=N69DbYpUl1rZqFPWyq/bw6JFA1tssKwuW30lwMxOl1A=; b=YQ/f8hJ2LrenXqVdBaGdLLO64LpEjxM159iGz1gghK5KFIf50gfANJGOxuycxqDje3 MwOh7jYAYtlMUR4V4Lma9/9mDnYU9Fj6ps3r7XdEKoEm8OiyG2+xG9b7KnTyTAC7P7uN Oeaturj5Ygxk8DYYWRhY2GQ9m+7qic6NMtUxutktqQTN/BmDGBDV7sMLmoCX65Ne0yqz sooX7EYQUoRTtQdYBHVagltk2pYheT6X4f+wF75BSZnBLKu+AwkLhZBri2EfLHF1GXTi h5M6b664f7hHi9ZmUWl1qOAq8Y3TIrp01xLhTKtkOKDbMU+XiUw9Uq1Izmzj93pkgzRv Bruw== X-Gm-Message-State: AOJu0YzKQL8DXuYT8m0O1OlKr9yK9pYqo8PL5fDIe8Lc5ln+mUc6qChj V7iUcF9Ydm9kAF440YQcxHZM39/uI/xjq4jJlHWaBbeOlSXn7TTU862xuwFWZZ7KI/0n3L1d8Ia mIbUt X-Gm-Gg: AR+sD12itF7brVInVPzL0cvi5u9SGZ0BtssjTLgevJwfVkCTTt/Ch7quSMkmBkD1bA0 O3Loboe2hij5pjM+Pqk+KBptjLjCTBI9KK+QWnHoBKg4oKo8PGoDzDdeNeGc17Gt9lYo468feSc kEg3UZQc+8+RSmCgvpwMSzkL19pxyxn4JZV10KGesgwJADSh8y0KpXApXFDh/BeThkq+uAWkVRE l/3q2o0obFOt3iInxoIciS7yJ9lnC04GGh5jcdXuNpbdmw495bDMOgXLDRC4gXrg6GOAncwkWjW AaZD15lN/yWiipvD0E9O2lRBgcL88vEIqOmp1qX39BNj6WIvgF9wyAuZk4+C2uyrDedK8ArYSu/ H/qgibpfgJNPBc5/K8hed3oYoPm1u7Z2IsBDtg9bORiS22of0G6oAFefpLxM9d+Of7qJkwkN+e9 yWz4gXQJVr61l2qEkMyAz1sz+Lwm00jLIsRiWMrn9WrFQTgh+SjNrIyeRr X-Received: by 2002:a17:906:f584:b0:c16:a402:9d8a with SMTP id a640c23a62f3a-c20e6189f97mr287124666b.11.1786469945091; Tue, 11 Aug 2026 10:39:05 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Thomas Huth Subject: [PATCH 1/8] parallels: fix out-of-bounds read in format extension parsing Date: Tue, 11 Aug 2026 19:38:50 +0200 Message-ID: <20260811173857.396571-2-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260811173857.396571-1-den@openvz.org> References: <20260811173857.396571-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::62e; envelope-from=den@openvz.org; helo=mail-ej1-x62e.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1786470062777158500 parallels_parse_format_extension() advances the cursor over the feature payload but subtracts only the feature header size from the remaining byte count. A feature whose payload reaches the end of the extension cluster leaves the cursor at the end of the allocation while the count still allows one more header, which the next iteration then reads out of bounds, 0 bytes after the 512 byte cluster. The stale count also breaks the data_size bound of any further feature, so parallels_load_bitmap() can read past the cluster as well. Account the aligned payload in both the cursor and the count. Aligning data_size before the bound check changes nothing, as the count is always a multiple of 8, but it has to be computed in 64 bits: on a uint32_t a data_size of 0xfffffff9 or above wraps to zero. Reported-by: Martin Hole=C4=8Dek Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4156 Fixes: baefd977002e ("parallels: support bitmap extension for read-only mod= e") Cc: Stefan Hajnoczi Cc: Thomas Huth Signed-off-by: Denis V. Lunev --- block/parallels-ext.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 7f6ab6b0d2..baee86a159 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -239,6 +239,7 @@ parallels_parse_format_extension(BlockDriverState *bs, = uint8_t *ext_cluster, while (true) { ParallelsFeatureHeader fh; BdrvDirtyBitmap *bitmap; + uint64_t data_size; =20 if (remaining < sizeof(fh)) { error_setg(errp, "Can not read feature header, as remaining by= tes " @@ -260,7 +261,8 @@ parallels_parse_format_extension(BlockDriverState *bs, = uint8_t *ext_cluster, goto fail; } =20 - if (fh.data_size > remaining) { + data_size =3D QEMU_ALIGN_UP((uint64_t)fh.data_size, 8); + if (data_size > remaining) { error_setg(errp, "Feature data_size exceedes Format Extension " "cluster"); goto fail; @@ -283,7 +285,8 @@ parallels_parse_format_extension(BlockDriverState *bs, = uint8_t *ext_cluster, goto fail; } =20 - pos =3D ext_cluster + QEMU_ALIGN_UP(pos + fh.data_size - ext_clust= er, 8); + pos +=3D data_size; + remaining -=3D data_size; } =20 fail: --=20 2.53.0 From nobody Wed Aug 26 07:38:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1786469987; cv=none; d=zohomail.com; s=zohoarc; b=PrUp12BP2dd5AtiKo/mDO9jtWatJRDjm4yLwBNDs4DmKOELbaA7dnTWOGj3tMkZ3eLP+Gv18FISictzHK/HJStsKH8zDllxTUJEJpMzN0HrAj24oQY4TYOZI7DzmgMmmnGyj25oWXo/hcNctF3e9pf7hg2E9JpKZP0/vsPH7VRo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786469987; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GV7Ua9V/Sjx6+gmIOmwjUOl9YM8UQhaC8JaZ+jlAiiY=; b=lTs8xK51fC/ZdSkqa9VErLHrKnhY4wD0Ib3ZhzPK75ZXHYP9VjaB/XZacsIGm3Tarw+Waw65YlbiSrbvkclJuK+JWDyY294yrBcvNr40XXwp+CCS240WDT79uEx8GPE3ljOVxamCCfS1GXw623vGnLNuDgIqgeF3uL67GzI+N+U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786469987201935.5969642627069; Tue, 11 Aug 2026 10:39:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtqRZ-0004YP-5g; Tue, 11 Aug 2026 13:39:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtqRU-0004Wu-5c for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:12 -0400 Received: from mail-ed1-x534.google.com ([2a00:1450:4864:20::534]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wtqRR-0000S8-Fi for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:11 -0400 Received: by mail-ed1-x534.google.com with SMTP id 4fb4d7f45d1cf-6a0794669a6so172835a12.2 for ; Tue, 11 Aug 2026 10:39:09 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:c43:d230:7bbc:68d4]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a362ef7525sm880945a12.29.2026.08.11.10.39.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 10:39:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1786469948; x=1787074748; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GV7Ua9V/Sjx6+gmIOmwjUOl9YM8UQhaC8JaZ+jlAiiY=; b=px6IBtfxJjqIFNUS54wBo46JYmu/Qz9EpjiVKdr8OuQwIEzquXUefGXJ8HOnlE67o7 91pbl74vJ0Y6uPI5WY4weVbZKyhKrbSwEpN9AAN+StDwhajEFSd3iDVjCwxGy0A+GQml Gv6ZTRGU1wGRYsagdRIqy/LXWLIDyqBSIOlHDGWBz07FtLcrQ8CaNBS4/WjsTIJz3OAg fpv7bA0Rn1t0hM3h8Q6mZtqVxpuLtBFufJipspWQd3eYQ8LTUD38K6iTY/nQRnlG4Hdg 6Dr7qGq4XZsE4g+FS3sIB/cUkIvV18bcfHKqBh3iqFiVaEFfJ8Am7F0/ctc9foY6VnjP jTZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786469948; x=1787074748; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=GV7Ua9V/Sjx6+gmIOmwjUOl9YM8UQhaC8JaZ+jlAiiY=; b=fqXlxJoOD0XOMCojFceaWIECkwqxwyeZzkdKPL93c8eXtAKv4rnqqcvbAhfnxXCtAI rR/sLuA0zfPirCRzygZ2kraUp38wxSLHj8nx5M4lZGL5Nl1/UGAekh32kOnxs3mukaby 4QtoYKOt1jeR8nK/isDat9nLVfLNMUhbRg4LYvt4wGhhJTPxsntiNzbpP906QaGD1a+i zz9XXgsboQUao9j7Z5/cAPRkw5xPcRP5ifqqFueTzj1Cg9Pm5GVsQaQg1fq2C6Z57P/F uZsqJaPtYAj/hmKBd9prFj+X00J/8oyggPLYMVHzAR+J6wn8Co1mYSOdhSnMiOWCpbAD +exQ== X-Gm-Message-State: AOJu0Yy2zfg4LojU+8iroyyBxEytw4XA0/RHDl+vb2oZa1lYxuOrjpXG tz9pEza5Pw8FAGe9rt0XxaCFAZKRiJC0jHiWEdKn1p9yq7c2+kMrBtZqc/lBRRd/V/BpcTQvXIh h+Ysp X-Gm-Gg: AR+sD13y+2usCA06Qx6HAr0Fh7pU8ae1sm+WlbRWMNKLIn/BSIcdkVC49GpRqlssYhf wurOqBoIKKhikv+XMztBnWUWiz987myChPbr7WVSeIQSygEy3ueRge2Qp4oBxAO7kTmbZLojCTW QngfWkHO5q1qTrXlUKeObPQMUcCI5BTmv7QsMMBuN5Cra3HKGwlecMnNMjJgH/pM6iMiPDmxmZQ 6eO8RXXxxKcf0AentevzYMdXGwnDEuKbJbpouD/77bEvmTcT1XI6EDrDGBxW5JLZ1+OT+vb7gxR Pe/kwJNZkF8WBAUP0kJyyMbVvDjM6DK411DK4FkS5/1A9cnO+INy087uUo1hKz0IQYOlc4cG07c 1A/rbrv+kPXLV4jt0LqSKzqhL3ZL3OZv3g9eQY5I45ANKuZuF0I/8exAX2oMHXN9rVNdeIBiuQq dQYrvGOuVJfJPoZwspIi/mAu9T9RGAwc84AwG942kozq69md4vLNYC6N27 X-Received: by 2002:a05:6402:249e:b0:698:3602:d0d with SMTP id 4fb4d7f45d1cf-6a36451dd1amr2791285a12.17.1786469947999; Tue, 11 Aug 2026 10:39:07 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Thomas Huth Subject: [PATCH 2/8] parallels: validate dirty bitmap granularity Date: Tue, 11 Aug 2026 19:38:51 +0200 Message-ID: <20260811173857.396571-3-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260811173857.396571-1-den@openvz.org> References: <20260811173857.396571-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::534; envelope-from=den@openvz.org; helo=mail-ed1-x534.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1786469988741158500 Content-Type: text/plain; charset="utf-8" bf.granularity comes from the image and is passed to bdrv_create_dirty_bitmap(), which asserts on it. An otherwise valid image thus aborts qemu-img for a granularity of zero or one which is not a power of two. The shift by BDRV_SECTOR_BITS is done on a uint32_t as well, so 1 << 23 sectors and above wrap to zero and hit the same assertion. Compute the granularity in 64 bits and reject what bdrv_create_dirty_bitmap() cannot accept. Fixes: baefd977002e ("parallels: support bitmap extension for read-only mod= e") Cc: Stefan Hajnoczi Cc: Thomas Huth Signed-off-by: Denis V. Lunev --- block/parallels-ext.c | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index baee86a159..830ac78a11 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -31,6 +31,7 @@ #include "parallels.h" #include "crypto/hash.h" #include "qemu/bswap.h" +#include "qemu/host-utils.h" #include "qemu/uuid.h" #include "qemu/memalign.h" =20 @@ -122,7 +123,7 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *da= ta, size_t data_size, BdrvDirtyBitmap *bitmap; QemuUUID uuid; char uuidstr[UUID_STR_LEN]; - uint64_t bm_size, tab_size; + uint64_t bm_size, tab_size, granularity; int i; =20 if (data_size < sizeof(bf)) { @@ -133,7 +134,7 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *da= ta, size_t data_size, } memcpy(&bf, data, sizeof(bf)); bf.size =3D le64_to_cpu(bf.size); - bf.granularity =3D le32_to_cpu(bf.granularity) << BDRV_SECTOR_BITS; + bf.granularity =3D le32_to_cpu(bf.granularity); bf.l1_size =3D le32_to_cpu(bf.l1_size); data +=3D sizeof(bf); data_size -=3D sizeof(bf); @@ -144,6 +145,16 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *d= ata, size_t data_size, return NULL; } =20 + /* bdrv_create_dirty_bitmap() asserts on an unusable granularity */ + granularity =3D (uint64_t)bf.granularity << BDRV_SECTOR_BITS; + if (granularity < BDRV_SECTOR_SIZE || granularity > UINT32_MAX || + !is_power_of_2(granularity)) { + error_setg(errp, "Invalid bitmap granularity %" PRIu64 ", expected= a " + "power of two of at least %" PRIu64 " bytes", granulari= ty, + (uint64_t)BDRV_SECTOR_SIZE); + return NULL; + } + if (bf.l1_size * sizeof(uint64_t) > data_size) { error_setg(errp, "Bitmaps feature corrupted: l1 table exceeds " "extension data_size"); @@ -152,7 +163,7 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *da= ta, size_t data_size, =20 memcpy(&uuid, bf.id, sizeof(uuid)); qemu_uuid_unparse(&uuid, uuidstr); - bitmap =3D bdrv_create_dirty_bitmap(bs, bf.granularity, uuidstr, errp); + bitmap =3D bdrv_create_dirty_bitmap(bs, granularity, uuidstr, errp); if (!bitmap) { return NULL; } --=20 2.53.0 From nobody Wed Aug 26 07:38:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1786469976; cv=none; d=zohomail.com; s=zohoarc; b=Qxtr6xed1hFB9c4RM+LBKF8aOec5dfQ/89K5yhGT4B8gPlzvUM0OIXlHxPWmUKyY3pYdyaV12Ax80SrWE0Yawsvi4aITW7c0dtNdSGsd1KOn2ABto8mffIs+RjYz8xVXFitXd7wxJtJdu1GARUI+XJ0yfjZNY6GHy8XSzKPX2HM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786469976; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/FLrBFGnc3sdlHbz+yFP8aIfw/LA8xDvV8QDl90J8e8=; b=Pdj5e0YhZ1d3ArAj486J8zBqeoyhCIdjTqDuTJKGtTQDqWIxhd/SVUWc2wYxT/rDOkDaXDwfdwicHy3dVNtx4eTJMbZmcSJFXl8+Mk9nvp8BoKy7ncnbEA/rsWEb5nRZCabCALD0bX4GVGAl1Ag3A7+E0PfVvpuH3LHat12wh0M= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786469976113379.93216572331505; Tue, 11 Aug 2026 10:39:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtqRc-0004aC-GR; Tue, 11 Aug 2026 13:39:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtqRV-0004X5-Dc for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:14 -0400 Received: from mail-ed1-x52b.google.com ([2a00:1450:4864:20::52b]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wtqRT-0000SW-TP for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:13 -0400 Received: by mail-ed1-x52b.google.com with SMTP id 4fb4d7f45d1cf-6a36982a875so162947a12.0 for ; Tue, 11 Aug 2026 10:39:11 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:c43:d230:7bbc:68d4]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a362ef7525sm880945a12.29.2026.08.11.10.39.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 10:39:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1786469950; x=1787074750; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/FLrBFGnc3sdlHbz+yFP8aIfw/LA8xDvV8QDl90J8e8=; b=mT3oabxFNdsky6+qWD3+ISnToOZmXtNbL1bw+KcoSFjD+RHuzO8W0zbtz4s+Bs/QeN 2a5qGbHIX9fCapQzqLcLGUINymQsErZ3aCbm6WSn2KnGP2qxKu/6epjlaMqwgoaisE8C TKceTniHeDp+6bHTq9VHxXsRCCVUvtKq+5MhpVGPQ4rNpA03r748IQQEgwW4nmqGMxN/ SpoaTxyeTbKbPie7zZ9TPUTX2EmyeQ1RDpWIU9V6ceYAE2pkqTl3z1qHi69FKRRPh8MH +x9/ljqJWL2skHE0KcenEn/pMJeo5wQzWYYDPbogoZa7Ut8IG/OoUjMRRCuAz7DBB+Qv nEvg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786469950; x=1787074750; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/FLrBFGnc3sdlHbz+yFP8aIfw/LA8xDvV8QDl90J8e8=; b=KNucnsnhi51X6uG9JD4kaB1I6viwdfIIFZXwcerN1oEdB1RoO9l5Dw1i9iFjMAB6HV uYnAbTetZXgVDfMOTfzH4615v7nzu/qWfCQKdTnugN1nNsXmieUrsR2TM584Hrk+N4YM Tvvq/8GTqYWVtX6ayUUzPgFJseENyHxtw9uBVmUMBHHwHKqrC/I3oZ7yZLcKdAgxSmKV LV6I/927QKdkvFiJfOfM5cF9QiIlameApNxu5rTehkZjJY3cymJKMlDhqVXNPBNodowB Vjss2MrFJ++R1oHZVrzH6MWZWA5AXRPoJ7hbfgyTCFs0yYnvcSb2myMu7fRjHf5vPRZj ZXTQ== X-Gm-Message-State: AOJu0Yxv3HcOf46/j6fhlU+ffSb3wZtC87qt8jm94NNrxfX8zfW6HZtV LK7tI4RLj+eVAgwd+qu3hB4aRIcY/VR391GyFPZhQ0Bk5DLsswOigC9mTbhpkgeSTQgXMv6TXSH PI2b1 X-Gm-Gg: AR+sD12VS1/OPJRBH7HEZzZtjX+fob+aw1Sr0rVrTgm81IAU49wbyjhfPEtJhRm4MIo f0fAzlbpqGPjpHYJGvNLgipB5+5F1LZjLTREqAU5LW2477G8m8BPmtjuaOkh7uAngRBVd6ELQZS pIBPNxolSMV9H9ZKVXLTh5yyfxFq1WK8aTcvLSaBUycBlyaqroJSrSP9o1WpUHEYsOGeRAgXMtT RlycjXCD2VmURDtPw5upIAJe+ja+SvdwYC9I/uAEoiRfb6LySQVRYRcp0EzFMUw9Rd3HqKeoON3 yrPLNhEmrSdq3m43Q+rH+KoeZI6batF5RTnO9Ag4XV1bmdan0ZjVxWSOpOOymLjdFc8973+zT4j W1mM2hqXn92B8wy9yk2irlH3HjnJ8gJgVV+lqOB8WNeoFoteVNO9CQVQEeOXPHr+0GLl0VUfZOz auvLKwTB7hSTBW6K86cTtpBv3EppgrZbFXcWvB2vRlbPLWMGKK92PXiFuI X-Received: by 2002:a17:907:fd89:b0:c20:acfb:72ef with SMTP id a640c23a62f3a-c20ecbb755amr99656066b.30.1786469950160; Tue, 11 Aug 2026 10:39:10 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , Eric Blake , Vladimir Sementsov-Ogievskiy , Stefan Hajnoczi , Thomas Huth Subject: [PATCH 3/8] dirty-bitmap: fix integer overflow in serialization coverage Date: Tue, 11 Aug 2026 19:38:52 +0200 Message-ID: <20260811173857.396571-4-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260811173857.396571-1-den@openvz.org> References: <20260811173857.396571-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::52b; envelope-from=den@openvz.org; helo=mail-ed1-x52b.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1786469979140158500 Content-Type: text/plain; charset="utf-8" The chunk size is an int and is shifted left by 3 before the result is widened, so a chunk size of 1 << 28 or above overflows. parallels passes s->cluster_size, which parallels_open() lets reach 2 GiB. With a bitmap needing two L1 entries the bogus limit makes the "bm_size - offset" in parallels_load_bitmap_data() underflow; both wrong values slip past the assertions in serialization_chunk() and the resulting index lands outside the hbitmap, so a 128 KiB image memsets unrelated memory through hbitmap_deserialize_ones(). Widen the shift. qcow2, the only other caller, never exceeds a 2 MiB cluster. Fixes: 35f428ba3971 ("qcow2-bitmap: make bytes_covered_by_bitmap_cluster() = public") Cc: Eric Blake Cc: Vladimir Sementsov-Ogievskiy Cc: Stefan Hajnoczi Cc: Thomas Huth Signed-off-by: Denis V. Lunev Reviewed-by: Vladimir Sementsov-Ogievskiy --- block/dirty-bitmap.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/block/dirty-bitmap.c b/block/dirty-bitmap.c index 13a1979755..9fda3a4b98 100644 --- a/block/dirty-bitmap.c +++ b/block/dirty-bitmap.c @@ -612,7 +612,7 @@ uint64_t bdrv_dirty_bitmap_serialization_coverage(int s= erialized_chunk_size, const BdrvDirtyBitmap *b= itmap) { uint64_t granularity =3D bdrv_dirty_bitmap_granularity(bitmap); - uint64_t limit =3D granularity * (serialized_chunk_size << 3); + uint64_t limit =3D granularity * ((uint64_t)serialized_chunk_size << 3= ); =20 assert(QEMU_IS_ALIGNED(limit, bdrv_dirty_bitmap_serialization_align(bitmap))); --=20 2.53.0 From nobody Wed Aug 26 07:38:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1786470000; cv=none; d=zohomail.com; s=zohoarc; b=LVH0gYlLcPHUGO137qfw/U/4qOn4LZhV/jpE5JGObgBLNaVqGJuGRcdiZZDh1K+ZYN++MkHooAAHuS/kkNWvKo8eYvFA4uf5FpocmGraWExo7Vl66NyMXfAzlnYFmGFZRbVgH7XwfI800lJRvS0VZwmGF2QyTTG1Q9/okBSSyIY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786470000; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/JzRXJJhfykp1Yow4iskX+SbSIGhsF2ft8QA0zD6CcA=; b=I5+fDU4ozGgusDzKuC6vseUs1Ok00rQ1EIJ4H2NZ5wKM0QFUNJbJaJG1A6H5KOGPxvPrBocxYXfROCd8qqIwgnsnovFo8zUWAcNInPKy1EhizAZLQXMspqrRBXG0PKxSCMhfvpuBimEvtjO1GpdFWfRG604qSiRXHO29PjJtP4I= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786470000112500.82491773837955; Tue, 11 Aug 2026 10:40:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtqRq-0004e1-1j; Tue, 11 Aug 2026 13:39:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtqRY-0004YR-4F for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:16 -0400 Received: from mail-ed1-x533.google.com ([2a00:1450:4864:20::533]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wtqRW-0000TH-IK for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:15 -0400 Received: by mail-ed1-x533.google.com with SMTP id 4fb4d7f45d1cf-6a1f80fd2e4so221839a12.1 for ; Tue, 11 Aug 2026 10:39:14 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:c43:d230:7bbc:68d4]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a362ef7525sm880945a12.29.2026.08.11.10.39.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 10:39:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1786469953; x=1787074753; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/JzRXJJhfykp1Yow4iskX+SbSIGhsF2ft8QA0zD6CcA=; b=kj1e/4faQfPa+q+2oyseuAx5hWO/9H5oB/4O37TcKNMyZABmtV8cL26kWmv1VyMt51 OBsPx69oWg/3ofTfFWg6cVak6nkZJlmt1MEM+/mxhLMixzWcD4t2uVJVDpXRUsWAoixG 1nzC6oR7XrmOfXuPNYtU0hIhvqvpMOpsi6Obywq8Zh5iYPnWLMtKNqt7b9bcAe/9cM4n 1Qj0vtxRrA6X9cbRdlmMi6NrcNBxWRUeL8uODYPrt1kYGMsPsV7cbCiIR+tGW6cu9m1r MiN4HwcfULoWe5jMOih9v0Ge8HxvnqMFRJ2cb/paayhiBecMFhxLienc1A/6z5oUY4TD pZAw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786469953; x=1787074753; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/JzRXJJhfykp1Yow4iskX+SbSIGhsF2ft8QA0zD6CcA=; b=hd+011wFxvrx+kTa7Y2B6cLZ4uAvZbVegpqY+gEtE6Pv371djhinQsHtE7pqMEBZqW 66q4L/XTLmYd1pIC6z2Gluu3ucmbailDehPFInevIDfwrY/BbjRcAVzkIfYKg1K6PNP1 Xvzj75yvL/ydoub+2FPzNaayKvZQ8lJa4+SXIeY1qtuZGKqtq+88SyFDyP3LI2m8q9lO G+QA3+d26MOrAQJhZ4yuicmPf5i4RSGSCgHfjeXSOvjcd9spVkKrokDSSWVcL/rihJdf rkPstI07nYYrRqeBveBFxEQnleFGC5qk2uHv6Rqo/a0deF5BaJhj/7HaXu+tPT5FtW3U 6GmQ== X-Gm-Message-State: AOJu0YycTx8vlkGcMiTNy/jj2Gvmi0SXMMrbC2sGDMfP9Co6XCNEzZ2X jQF605KjijtQdz8pkthp8z1TwDm7kDkVLevYACd76cogG31vqHjD/fN2OzihSunsPW5FI71kAu8 a80oM X-Gm-Gg: AR+sD10gXk+w5/u5I8DCeNaLKKGxUfNhBT6K3Z3mSxxGdxcnuuRE4l6BmBfgCmta3Ei UQGIhCx4wH9thnOLjyTfLE/LfpntwfcGSNmtcjUlQaNErNY/ZSIMXR1Dj6jrQpQZ03RegDDYQNL rzO7CXaFOMpmh2apnGHP4cXPJqtjJLxjjLf5J8Jv4Qwx5Z1IkGqcdz7B8dKlsb2l+A4S1OIsD20 hHETI5MtDSPz67/dJKB7Sy7jAXGoLJ+1AjFoSnbI/plbzc3LUG2ZUpS5nG8ZNKAXsrVEWVSUrpD s8vw13/k1FdPawwyGp1MmRQSEg/tKowZ3IGa+jwBuCKcksaHMKxqM0kjHeTvpyKK9CI1UEsxyHZ 3TSTY1kPx3W/uUn+UnEU47anDgJ04mZRcWtGF639PWCXCbl5tp4x2GwtnkAsw8bdcrb9tCH9NSd ltknGRrQgHLYC0DZ4pF1fXrMPgG9oVCrFn1AAQ/FRYoucBL4AMK1lqH2Bu X-Received: by 2002:a05:6402:4014:b0:69f:c929:b88 with SMTP id 4fb4d7f45d1cf-6a36d763d52mr920129a12.5.1786469953022; Tue, 11 Aug 2026 10:39:13 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Thomas Huth Subject: [PATCH 4/8] parallels: bound the bitmap L1 table against the bitmap size Date: Tue, 11 Aug 2026 19:38:53 +0200 Message-ID: <20260811173857.396571-5-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260811173857.396571-1-den@openvz.org> References: <20260811173857.396571-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::533; envelope-from=den@openvz.org; helo=mail-ed1-x533.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1786470000407158501 Content-Type: text/plain; charset="utf-8" parallels_load_bitmap_data() derives the number of bytes to deserialize from "bm_size - offset" without checking that the offset is still inside the bitmap, and an offset past the end makes that subtraction underflow. The overflow which used to produce such an offset is fixed by "dirty-bitmap: fix integer overflow in serialization coverage", but both the cluster size and the L1 contents come from the image, so refuse the table explicitly. The check cannot reject a valid table: l1_size is DIV_ROUND_UP(bm_size, limit), so the largest offset the loop reaches is (l1_size - 1) * limit, always below bm_size. Fixes: baefd977002e ("parallels: support bitmap extension for read-only mod= e") Cc: Stefan Hajnoczi Cc: Thomas Huth Signed-off-by: Denis V. Lunev --- block/parallels-ext.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 830ac78a11..63fe4d5b1e 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -76,8 +76,17 @@ parallels_load_bitmap_data(BlockDriverState *bs, const u= int64_t *l1_table, buf =3D qemu_blockalign(bs, s->cluster_size); limit =3D bdrv_dirty_bitmap_serialization_coverage(s->cluster_size, bi= tmap); for (i =3D 0, offset =3D 0; i < l1_size; ++i, offset +=3D limit) { - uint64_t count =3D MIN(bm_size - offset, limit); - uint64_t entry =3D l1_table[i]; + uint64_t count, entry; + + if (offset >=3D bm_size) { + error_setg(errp, "Bitmap L1 table covers more than the bitmap " + "size %" PRIu64, bm_size); + ret =3D -EINVAL; + goto finish; + } + + count =3D MIN(bm_size - offset, limit); + entry =3D l1_table[i]; =20 if (entry =3D=3D 0) { /* No need to deserialize zeros because @bitmap is cleared. */ --=20 2.53.0 From nobody Wed Aug 26 07:38:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1786470026; cv=none; d=zohomail.com; s=zohoarc; b=Gn4o7yM7uu1vSMlt8xUU7aod5otUgc7UEKf5qMXEQnTdOA6KznjCBVSRJWMwRdn9rOX1wfAam8CF7xJNEeD4e3RrRHH100vqFo3Fb7EmhdPLrp7IClF1pdX0yAtdDOhBR01fuNkHluG7qJ9UhXPaMnPZoDSo5+KSCQLzFGPK9a4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786470026; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7jUEWeXkj4wjPOT8hF4Qk94qpOm38rox82f+3EfRHP0=; b=cycXC8BtLviwWhw12UO6uQ+83ZsQG4QRgH/xCRvgiKt17rtnc5snaJ1TZmVM68Z0Ij40mCcgJqlSa0eoI972c9XYB2vq8ElB5hK0tCib0cfeMgmOupbmmVufO5BVVs+tn0UiRaXiJh/qp6oIjzmeAIotSmH1UDPzAA/YoCth0qw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786470026003168.36079919173437; Tue, 11 Aug 2026 10:40:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtqS5-0004xY-6o; Tue, 11 Aug 2026 13:39:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtqRb-0004aQ-Vg for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:20 -0400 Received: from mail-ed1-x532.google.com ([2a00:1450:4864:20::532]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wtqRa-0000U3-Bh for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:19 -0400 Received: by mail-ed1-x532.google.com with SMTP id 4fb4d7f45d1cf-6a1a546a6bbso116036a12.1 for ; Tue, 11 Aug 2026 10:39:17 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:c43:d230:7bbc:68d4]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a362ef7525sm880945a12.29.2026.08.11.10.39.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 10:39:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1786469956; x=1787074756; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=7jUEWeXkj4wjPOT8hF4Qk94qpOm38rox82f+3EfRHP0=; b=YMHfIXrgIhYzRPIaRgXCQLUZxDVN6hxUomHItf8zYcxtaxhi+JR9FPrxxEA53N5FAK o6JMcDXhummzhDi6UKm1pbtdlwHUKd1MX2g5DRnsWW0pQFJLSMs0PihSMHuOL+9UFt11 coJTELPAtPNdzYwVAy+o9NDO88thNy6GrNeYQZGjtT+m0q3dTyVPfbDgXje+aHs12rOA hXLbiaKeNDTfbk43MDt8/0dCG79OIpjEI2I5o5Lpa7jJImYyA70+Um+hb3lU6clL0GjW ezILQpeRVSj2D+Ah3T10KaeeSwRLnKBxOPCaEv0i6TsZiV32pFh4PBPQ+/6t0hIrl5Y2 ApSQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786469956; x=1787074756; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=7jUEWeXkj4wjPOT8hF4Qk94qpOm38rox82f+3EfRHP0=; b=fWIq7DhETnk5oNjVpYD28RgCUQSXzXo8HXkhuyw2inbRrt/h/8HW+ly8XZe2iqwZeH zg0dz7GnhnvXuCqO8GyqldZ6S2mEjAisS/UcCBx5mY3xRT0jvp6SuuL7gN2IfiNflukt d/JHP1nHbl636j5k9AFRhycdJ88+xMmhO1tCZM+GDOWPzMpJDr5liHXVDCCRmBsT4532 iIgaKQvaO8z672OrOwtbwh6ChR4DudpujYSIzK4cDDnIQrLxsgyLMs05jH9jcWvB6suV DIPdyNG5l4HX1sP4FMhGthZPBkdfR5/iNC9t5UFtaIfzkTHJTX3QkG/NXM4juhZPNdat C8Gg== X-Gm-Message-State: AOJu0YzmSRjeTxNvl4qtAiBKTPqFALMT58WhZjdZQ37G/vm8grCULJWZ CAPJoTbXNTnUNdKu/hruu6aVMQ5YGlR50MBVAqjmgcXPIsAt4U7spFE93IytOzeQ1BrFKaH31Lx ND2SC X-Gm-Gg: AR+sD13XSYEMdfk0Y3ElzRt7vf2YxS+pFnyGYvBcwAXAODTXv1qmJVEmp+bh351Pr/q SKGicNgdM+pAdDa3E3xOvL8jalgnsRjPNFY3SvQM/pE7bCC1aVP4a1oWpYX93C9lRQFWY0GmZ8S tLvF7Llu6yNmi8M0L/y2FjQI9ekvKrQD427MAy5Z/IqOXRxNlhzNNzKruFWhqC64teQQ1dg3gdu TsKeXttfH0NkWGXvbmaBYujJDSdp5otlJrAugYyt5TBAQou7pSPNXBVQJi1xAmT7ql/vjVRKXRP xTFNAWetwTRTiJWgLjM8vgYVWxHlly2Nl7wvgvEujGhFHPCDnTZasKC+DqC5X0qgor2ZyAxU65I nS+xsSMVTOG3G6FglFNe7LpiCg5ZBB1YZGKEcihX0kjjfp/fbJ92w+BAQz02mAU5llIz8+vOToF jjYyZjRhipwI/YEf9BVqkHi+gXRDvcqWVkySnncsWsNw2jJzYzl9EtCVag X-Received: by 2002:a17:907:998d:b0:c19:6d4a:425b with SMTP id a640c23a62f3a-c20e618034emr282425166b.18.1786469956023; Tue, 11 Aug 2026 10:39:16 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Thomas Huth Subject: [PATCH 5/8] parallels: reject a Format Extension outside the image file Date: Tue, 11 Aug 2026 19:38:54 +0200 Message-ID: <20260811173857.396571-6-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260811173857.396571-1-den@openvz.org> References: <20260811173857.396571-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::532; envelope-from=den@openvz.org; helo=mail-ed1-x532.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1786470028516158500 Content-Type: text/plain; charset="utf-8" The Format Extension offset and the cluster size both come from the image header and neither is checked against the image file. Reject the image rather than reading a cluster which is not there. Fixes: baefd977002e ("parallels: support bitmap extension for read-only mod= e") Cc: Stefan Hajnoczi Cc: Thomas Huth Signed-off-by: Denis V. Lunev --- block/parallels.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/block/parallels.c b/block/parallels.c index 93b5fa9dcd..50748d1415 100644 --- a/block/parallels.c +++ b/block/parallels.c @@ -1375,6 +1375,8 @@ static int parallels_open(BlockDriverState *bs, QDict= *options, int flags, } =20 if (ph.ext_off) { + int64_t ext_off =3D le64_to_cpu(ph.ext_off); + if (flags & BDRV_O_RDWR) { /* * It's unsafe to open image RW if there is an extension (as we @@ -1382,9 +1384,14 @@ static int parallels_open(BlockDriverState *bs, QDic= t *options, int flags, * ignores the extension, so print warning and don't care. */ warn_report("Format Extension ignored in RW mode"); + } else if (ext_off + s->tracks > file_nb_sectors) { + error_setg(errp, "Invalid image: Format Extension is outside t= he " + "image file"); + ret =3D -EINVAL; + goto fail; } else { ret =3D parallels_read_format_extension( - bs, le64_to_cpu(ph.ext_off) << BDRV_SECTOR_BITS, errp); + bs, ext_off << BDRV_SECTOR_BITS, errp); if (ret < 0) { goto fail; } --=20 2.53.0 From nobody Wed Aug 26 07:38:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1786470059; cv=none; d=zohomail.com; s=zohoarc; b=f4n34X8rN8UQyXqcexl8vmyPGhhTSitNXB69lHg7EDivQBjVQuqDA/qDkqwPSWP2wwtXoxw39i5CBH26MwCm23dsrMoZEDB/2Kt0IFnNgY09Fzfb+IhWXTyqeYwyY8Vb+7ZCXj2+VGfqnZ7r9JBgVI/9NG3VxRfR+mANNqco6yI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786470059; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=R9y7K0aZagJqn9tiJ5p7mtx/+U3iEqfq8CYJsxjyfoc=; b=CQLHyYhOG2mdx+09dPiAHigRR7RP3af2c3Y/HYsA3gqYvTOn2GlPg/AEIRQb4ZvI0KFja/4/61mMhufqZz9ZNVtUf+D6OeA1EnJO/z/w/VunDo0Owe8Yrue49sfKIN6euVaqoN5AF5bjTakrxKKhZijVQZvIdmcgA7hhHV9YRfE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786470059611978.3636182735621; Tue, 11 Aug 2026 10:40:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtqSW-0005KJ-QP; Tue, 11 Aug 2026 13:40:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtqRe-0004b2-Gg for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:24 -0400 Received: from mail-ed1-x52e.google.com ([2a00:1450:4864:20::52e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wtqRd-0000Ua-1a for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:22 -0400 Received: by mail-ed1-x52e.google.com with SMTP id 4fb4d7f45d1cf-6a0794669a6so173109a12.2 for ; Tue, 11 Aug 2026 10:39:20 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:c43:d230:7bbc:68d4]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a362ef7525sm880945a12.29.2026.08.11.10.39.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 10:39:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1786469959; x=1787074759; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=R9y7K0aZagJqn9tiJ5p7mtx/+U3iEqfq8CYJsxjyfoc=; b=KEiXASI5EmmGSu5+EoHj/ER/JYCFqBUQdveIwCO6MBZd2CRTtTpFfRz/Asn+IRJ/zB +r69jwrercOB3TLw1K4eLOAonrsii5yVGH1MDjO8zOwtav7yPnt1UGMgZBcqpjUqBxg9 vbeZkh4wh5ZIo8UHSaBeWBf3AHSNsZ+Mgynh2V1M1rSOpeaymk62NIriHnOhH50rsdAB liRoJTOaShUTg9NZMMEV+5TePOwvdKfGsuxcZkwI+atxdMEO/F3wg/f3w0S39MitL7L3 jtd5KGkG/xt16CotQ4A16V7rSRdsldNo4rITR1+T9oEtg3miCR/mm6IZMqo5mJuuDqYN c/Qw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786469959; x=1787074759; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=R9y7K0aZagJqn9tiJ5p7mtx/+U3iEqfq8CYJsxjyfoc=; b=oPJJ5ZUavYkk28eFSm/N4qHdbwyiQwnbjemGHQCanBRE/lHWI6aKeCXPK9oLucLMlQ gun85n0WERRiSUzFR4+6HuCT1dLtq/dvpErywDXH+dU6ms6TtBegrwB8uE+X7qPWueD8 JBYCpW7qWnnhEL8FadssA/rho8yXAjt+V82eTQePf80bdJ1NRU7wMdvhOr3lCgjh9cPB FYiys5+yjnnNlsCsXmhLFARdesZXDiZ/QSWErKRdJR3OjnItGaV5hkrFT9BokkOjs0n0 vrO2dxYFijdKugXw6SEGbZMpxbTqxHDuyYOEbYpsMO1y1R6aPaAQmBg7Y1We2pO/GqNa WJGg== X-Gm-Message-State: AOJu0Yyq/DE/LaHedEgGmGbLX1NzdKBdpw99qa3oDRqHv4i9NEI+lvir Ay+BnOIkAw9MI6vzjVSLoJ/TQgExb8CbLJ8zg83smYqyhvXboyBcMNEILOiUIpz/5jCsg14DbzT 02mhg X-Gm-Gg: AR+sD12eQLGltgJlUo7o9XK6+zivBoYj5zVu6BVNOTnXEdP4280Xg55O6oWLpw2MIRN WKiHDoIEvNGN0/dR3yb4Zlljws2kDMZNWrvi/AwGSpRizHBItT1lxeXUjBH1P/MeI1rO+xC8kJ3 QaOrNGoLaEcsG0QYvNHlUEtgzKVA3yU49YOJhIiLCE/ym1WOgp5VfGZPZ6x9Bq1tJQ5sw62sQzP geZs1a24bplBDPCNv8wFCAA4y+4T4ktUiWRKYXGXlJn31SUiFcXsVR9gWFef/GH5EREgLxTWhlp kr7cAfqfOu9TBOlf2qJ0jzNLNTLZqlRVVrEofqGRLi8MrZ7iGf00Ogak1w5Hcud7JPUZpLkwOcJ VkoeagG6/MXp34Av59+cW320KUyiDBqL6dDDdHMLQowHhD9ycO9NrNHQRB1/CCZtnmn9kFZLoxx 58MhQMB2it3oCwW4bpoEhebMdW3eqddvvdgxaZPL/Go+dxUsYcxnYioIH9tTZdQA== X-Received: by 2002:a05:6402:4609:b0:6a2:77f:b857 with SMTP id 4fb4d7f45d1cf-6a364542276mr2758297a12.21.1786469958880; Tue, 11 Aug 2026 10:39:18 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Thomas Huth Subject: [PATCH 6/8] parallels: allocate the Format Extension cluster gracefully Date: Tue, 11 Aug 2026 19:38:55 +0200 Message-ID: <20260811173857.396571-7-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260811173857.396571-1-den@openvz.org> References: <20260811173857.396571-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::52e; envelope-from=den@openvz.org; helo=mail-ed1-x52e.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1786470060830158500 Content-Type: text/plain; charset="utf-8" s->cluster_size comes from the image and qemu_blockalign() aborts when the allocation cannot be satisfied, so use the try variant and report the failure instead. The two are not interchangeable: qemu_try_blockalign() asserts that the alignment is non zero, while qemu_blockalign() reaches qemu_try_memalign(), which quietly raises a zero alignment to sizeof(void *). bs->bl is only filled in once .bdrv_open() returns, so the alignment has to come from bs->file, which is the node the cluster is read through anyway and what parallels_open() uses for the header. Cc: Stefan Hajnoczi Cc: Thomas Huth Signed-off-by: Denis V. Lunev --- block/parallels-ext.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 63fe4d5b1e..89fab36039 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -323,10 +323,16 @@ int parallels_read_format_extension(BlockDriverState = *bs, { BDRVParallelsState *s =3D bs->opaque; int ret; - uint8_t *ext_cluster =3D qemu_blockalign(bs, s->cluster_size); + uint8_t *ext_cluster; =20 assert(ext_off > 0); =20 + ext_cluster =3D qemu_try_blockalign(bs->file->bs, s->cluster_size); + if (!ext_cluster) { + error_setg(errp, "Failed to allocate the Format Extension cluster"= ); + return -ENOMEM; + } + ret =3D bdrv_pread(bs->file, ext_off, s->cluster_size, ext_cluster, 0); if (ret < 0) { error_setg_errno(errp, -ret, "Failed to read Format Extension clus= ter"); --=20 2.53.0 From nobody Wed Aug 26 07:38:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1786470033; cv=none; d=zohomail.com; s=zohoarc; b=ZuTvJtaEJQpeBlo8fDOY/X9U5nxRchgODMlZAW65kYwcNLttALaSgAKd25SxOgM6Glx40rmoZJDg8OM1RYhMAlCgobPJcei9TmYnVDzerh19yGMf0na7li7GK0dufnr+SYMddkuquKGLKRdx6OSa1lRlJ9hqycB7741PYjWBULs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786470033; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=XY//40pvifosH/oC9bhsWlgVBDe/TLGnkSQ+LuR5yDM=; b=an7P/HAD4TYvERlBU/+tzVJa2G7rR+7xLyTnuz1bK9EkczSQOt+3iEDSF56kQoKsq6ZtKGDcnTXZ3+ZfeQ63oRPbOMPRwVp81ZXeLZ4CCAUQTLiqsESeSfXlwkjFmSwdSQ+E2ehEC0OpUYpk2tsE/MdAQSaMyi648rv36XuHb0I= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786470033242734.4215664933965; Tue, 11 Aug 2026 10:40:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtqSE-0005BM-DZ; Tue, 11 Aug 2026 13:39:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtqRj-0004bd-Ix for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:29 -0400 Received: from mail-ed1-x52a.google.com ([2a00:1450:4864:20::52a]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wtqRe-0000V4-Tj for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:24 -0400 Received: by mail-ed1-x52a.google.com with SMTP id 4fb4d7f45d1cf-6a205b0df35so133861a12.1 for ; Tue, 11 Aug 2026 10:39:22 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:c43:d230:7bbc:68d4]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a362ef7525sm880945a12.29.2026.08.11.10.39.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 10:39:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1786469961; x=1787074761; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=XY//40pvifosH/oC9bhsWlgVBDe/TLGnkSQ+LuR5yDM=; b=VJsTcY95xtQaxHWS++Qx7rDzfwmWA0s6tESO0d2VcmvIix2655ZtqNzqDAGAEVmjWQ xncMiFEZzC/GMgU8KLHEq6+tSyzLMUYjskUItt5hhdwowsZ7q5/TvXrAVkt/5j2nqrFt x64dVsFlrdGLAR10U8dQ7LZmwqfRLz1a2nWhNKyKZQcZpaIiiyIDap0xAwrIxqoe2EdN N64ZfM6NU4yu9tqMLoF/pD/5Fuce1kGWbUaLoNTCKg7kRkx7pPw5pzVfZ9tGRsNpnXr2 y98BKeh+UGxrTv1pe+veagCsW4a91qcTy74IGb7OPppqpyeLE3BkOr8lUmXutyqCDxwG rmZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786469961; x=1787074761; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=XY//40pvifosH/oC9bhsWlgVBDe/TLGnkSQ+LuR5yDM=; b=pr0UeFsOUvpL4NSKJ7lR+pYkiCPWbe0j3qRZRucF+/DdHSRiZ1A72FSBRKhWRK/VuU /chdJAa8ErgH5JxBOP9jflv3lTHAoXlVcoFwBcXPXxTE94ssSswYVYp/J9mjVgeEfhzs iXw5T5olpdiiM8JV5RUx0u3VizQ2MdSS7IwU8CqadXsARo4vQu62Q6iFwMC0SaUbtXij 0/hedo9o3sAGOVm4in4FYu0xnadHmjfuHo8mdCj/RhhA2TqsADLzQTeMRTgs6GePa327 /nDgnOBZBEzGMydcCldskhwHB7vPumyZWSaGmqQLggV4wBnu/hOLWbobzRkMHX/vw71+ LAJQ== X-Gm-Message-State: AOJu0YwIgiskGFBkdoyqQDGEudrQCffH1ba28DqXmRUY2kG6yrEqfZhW r7cxUpl/LQRKOdtKYkkL7WqRIAqQ0kGdRPLa6uilEu6NhFJwxSlPRv4qk85y2zYrsAWIo+JbBaT 8dDhN X-Gm-Gg: AR+sD13dCsl4CC7R8W6g2h5v9YYCTbJ8yBFKgVzkUAYp79sQIfJx5pYWjcmqHRM+37+ UsB36j8oQhMTnGLLmJ/qFIeDiwL11iKbJE0jSKuP4FZ17+HWSYVCuesfAhiP3vWmL7K17V7bV/E QhVAca/JL8yVoMSKWKYkbgJmtTfYR9MpDIf2owc/G9otDLeV7H9ToI6653ReSG7Ru+rPJ9iIZnb EOjfMWTyO92ZwdKyiOPeNDLpB3Mz8SwyqWqrZpZ8NNJMgZZtDjoECI2ifrtGOz7Tb02oU1WVQ/k LUEIUowKLARHN4bMQnE9Ot7jV85MmqY5MeJllbxBTDoGC5DkMDc4WvmhmSvagTpJOZmHqRw+BbL HQdNRDwTIMsMdV3J2gyhi+RgVtN1WsBFmZBxLHzGA3pqQ3mp22I+MihcRQUILg5LBleX6QYNtMm RQvcTUFsekkNwLrKtwxUnpbtGsRlvdVR+SGPEVkzsUZ2vU0L0krFZaCMZf X-Received: by 2002:a05:6402:5d2:b0:6a1:fd14:8835 with SMTP id 4fb4d7f45d1cf-6a36ba70ea4mr1378808a12.0.1786469961517; Tue, 11 Aug 2026 10:39:21 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Thomas Huth Subject: [PATCH 7/8] parallels: fix GSList leak on the format extension success path Date: Tue, 11 Aug 2026 19:38:56 +0200 Message-ID: <20260811173857.396571-8-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260811173857.396571-1-den@openvz.org> References: <20260811173857.396571-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::52a; envelope-from=den@openvz.org; helo=mail-ed1-x52a.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1786470034665158500 Content-Type: text/plain; charset="utf-8" parallels_parse_format_extension() returns directly on the end of features marker, leaking the list which tracks the loaded bitmaps. The bitmaps themselves belong to the block driver state, only the list nodes are lost. Fixes: baefd977002e ("parallels: support bitmap extension for read-only mod= e") Cc: Stefan Hajnoczi Cc: Thomas Huth Signed-off-by: Denis V. Lunev --- block/parallels-ext.c | 1 + 1 file changed, 1 insertion(+) diff --git a/block/parallels-ext.c b/block/parallels-ext.c index 89fab36039..21f54e4e3e 100644 --- a/block/parallels-ext.c +++ b/block/parallels-ext.c @@ -290,6 +290,7 @@ parallels_parse_format_extension(BlockDriverState *bs, = uint8_t *ext_cluster, =20 switch (fh.magic) { case PARALLELS_END_OF_FEATURES_MAGIC: + g_slist_free(bitmaps); return 0; =20 case PARALLELS_DIRTY_BITMAP_FEATURE_MAGIC: --=20 2.53.0 From nobody Wed Aug 26 07:38:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1786470029; cv=none; d=zohomail.com; s=zohoarc; b=hboEMVfyT/P/i+lEV55Nbl1vtMSPm+8MA8uQkI6FEPpbWSyL7a+1pUFRJkDQLHlpXC/2NhFxrTgfF25Cosr9XKZx+nvVwCDJU3JknB0na5hAoCO5opXJekx4+f26Bk5Kd97U0Qe3zp8roPnJcccmH48vKxWbKDcQ9WFxrm66efY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786470029; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=q2P3wf2OCE/uBwdM3uTHXwb8VtUf7Xr3Kv0lq0Cjg98=; b=DI0PyaJqwzjfyE5yKpJ7CvUkVHpfQTukV1RWtuhxSytt6iy8xDOMgET0PDqXKDZLweZGoetV3bEINf+UigEszZWQ5T8Tm1V0YvWdXSjTLQXKecIQGQVcyzaWWuZzGkcOJYKmYnJBolS7JM1oyC4cZBp2EOqQYpnqBcw9W33ZUcQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786470029034625.1058894778517; Tue, 11 Aug 2026 10:40:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtqSb-0005cC-5G; Tue, 11 Aug 2026 13:40:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtqRl-0004c4-Rf for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:30 -0400 Received: from mail-ed1-x52c.google.com ([2a00:1450:4864:20::52c]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wtqRj-0000Va-2Q for qemu-devel@nongnu.org; Tue, 11 Aug 2026 13:39:29 -0400 Received: by mail-ed1-x52c.google.com with SMTP id 4fb4d7f45d1cf-6a10d02ff43so170391a12.0 for ; Tue, 11 Aug 2026 10:39:24 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:c43:d230:7bbc:68d4]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a362ef7525sm880945a12.29.2026.08.11.10.39.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 10:39:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1786469964; x=1787074764; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=q2P3wf2OCE/uBwdM3uTHXwb8VtUf7Xr3Kv0lq0Cjg98=; b=YVqbrKpSgZ2j6Y92pKZ4SQovSz16VQ/QuIapo0HIiCyZcB1oHhjb0t7fZZGSzlsztZ DvN2Fb4IbmTuZp7mZULzxgNx8ULI33L0+v/pahKuGtJk+J04pHuPDWFEApa9KmhqEkIP 6vTBMbGE9NLnQjIXCzMjeEal6na9oHciV16dz++gNYj0Qrdlqb2drWB5cnSB1/qX8SK3 DY2sbV2F4HCCmA6PWOdzfJHpmDnhhkawIAbe+yOl4nMRY1sYIu0z8t5tl7sQxX74HZ2G 5LCmHh75c+VnoW/LRgz2CKZFje+UTQkOeKmj6qXmVVF7yOy3JxME6pvQZ+jLSlWl3w5N vA8A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786469964; x=1787074764; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=q2P3wf2OCE/uBwdM3uTHXwb8VtUf7Xr3Kv0lq0Cjg98=; b=Mk6rQ7IFMC88bJdD/NS0STVb2XRqc531gh772AVLSEEW4hqvABTAzHoWhwemHz/xr1 me/h+QA2sR+ATXupqJIRdcIMce7IuLNax6A7UckZmzBueSE/R75hXKeBqBTVgIqcINSC OoJ6/24soFE0IqaiKTMpXoyD0HXHMjcNarmRLr0VjFAyyBIVMBYLnp3TWpcIuUHS2BWE Z3w1uhSrq6PuOO5LjpA/hQMxo2bKZSM2mC/2lbxLGo5iPPW7ArawkVPfVIbM1wy+ufZK ovOYXtqPFtwAImK5XwM2o9fqyvLW7+v3PfLGFSmo7JzHLQ/aN2TeFqqwHqy3cIYydq0Y 9haQ== X-Gm-Message-State: AOJu0Yzr/nD/TtXWhzXX5xRLUX5LJqZZaP+Iaw+HOt5Y9pAFzpFtxcwF 8oKmzWvfoqS2mU8uHhZ0SY0dNBvhy+VToWPa/ynlCgxbrOiDd5GcHcC3vehpTpGoNOTZnJbxKwk CudzQ X-Gm-Gg: AR+sD10EjXNUmUHvopihhNNX9maoxu4TzdTIjR6HsyELOry8JRXMEl3IAAREgFJtpqS 3InvGlzwbPm0W4Hym9cdceTU4+d+NLDC67k4R1yVoz6eT9kGnFFd+I9F8YoQElBcFNzhIUCM5xr QLqJWwp9RDab3BmB7531zS0qjF/KLqQvdGpGNcSywuLFF9Y4J8ZMCUF//uP7okJO3ICzYje2m4R AKofJmM/s9wVhflB/hNTYUca6GWrErT22J/zpEK8EzMzCQddcExVNFuMcYxs6V4yTNEMFUvWErd xhOfIvqxrGUGAGHAoJWDnUulDHjIeoJvbQXZtrd/ObijPY5kLSGImBYBX/mr801Zi/kmbRQgXyW S8gp/c7N5EgBk4NvIegDl/C+KBJ0kYhlmeHXnV1ApjQ7DGF+1j2OWKOVlRvJqBuo2OuQGs7PMYI KWGoca4SN33CCUo01QRQGkgic5OATV8k2BO2SOBQhcl7P/t8JWJBQLAI1n X-Received: by 2002:a05:6402:a682:b0:6a1:dbd:bfe with SMTP id 4fb4d7f45d1cf-6a36be4387amr819310a12.7.1786469963593; Tue, 11 Aug 2026 10:39:23 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Thomas Huth Subject: [PATCH 8/8] iotests: cover the Parallels format extension parser Date: Tue, 11 Aug 2026 19:38:57 +0200 Message-ID: <20260811173857.396571-9-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260811173857.396571-1-den@openvz.org> References: <20260811173857.396571-1-den@openvz.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::52c; envelope-from=den@openvz.org; helo=mail-ed1-x52c.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1786470030983158500 Content-Type: text/plain; charset="utf-8" Extend the existing test with hand crafted extension clusters, built in the test rather than shipped as samples. Each corruption case is one qemu-img info run which either opens the image or reports why it was rejected: extension magic and checksum, feature magic and flags, payloads running past the cluster, bitmap granularity, an L1 entry which overflows when converted to an offset, and a cluster_size larger than the image file. Two more cases load a bitmap spanning two L1 entries. Termination by a signal is not covered by check=3DFalse, so it is caught and logged to keep the remaining cases running. Cc: Stefan Hajnoczi Cc: Thomas Huth Signed-off-by: Denis V. Lunev --- .../qemu-iotests/tests/parallels-read-bitmap | 180 +++++++++++++++++- .../tests/parallels-read-bitmap.out | 33 ++++ 2 files changed, 212 insertions(+), 1 deletion(-) diff --git a/tests/qemu-iotests/tests/parallels-read-bitmap b/tests/qemu-io= tests/tests/parallels-read-bitmap index 38ab5fa5b2..5cbef25018 100755 --- a/tests/qemu-iotests/tests/parallels-read-bitmap +++ b/tests/qemu-iotests/tests/parallels-read-bitmap @@ -18,14 +18,22 @@ # along with this program. If not, see . # =20 +import hashlib +import struct +import uuid + +from qemu.utils import VerboseProcessError + import iotests -from iotests import qemu_nbd_popen, qemu_img_map, log, file_path +from iotests import qemu_nbd_popen, qemu_img, qemu_img_map, log, file_path =20 iotests.script_initialize(supported_fmts=3D['parallels']) =20 nbd_sock =3D file_path('nbd-sock', base_dir=3Diotests.sock_dir) +nbd_sock2 =3D file_path('nbd-sock2', base_dir=3Diotests.sock_dir) disk =3D iotests.file_path('disk') bitmap =3D 'e4f2eed0-37fe-4539-b50b-85d2e7fd235f' +MULTI_L1_UUID =3D '5f2e1c00-0000-4000-8000-0123456789ab' nbd_opts =3D f'driver=3Dnbd,server.type=3Dunix,server.path=3D{nbd_sock}' \ f',x-dirty-bitmap=3Dqemu:dirty-bitmap:{bitmap}' =20 @@ -51,3 +59,173 @@ with qemu_nbd_popen('--read-only', f'--socket=3D{nbd_so= ck}', log(f'{a}-{b-1}') else: log(a) + + +# Hand crafted Format Extension clusters. + +EXT_MAGIC =3D 0xAB234CEF23DCEA87 +BITMAP_MAGIC =3D 0x20385FAE252CB34A + +CLUSTER =3D 512 # one sector per track +SECTORS =3D 8 # 4 KiB disk +EXT_SECTOR =3D 1 # the extension cluster follows the header +EH_SIZE =3D 24 # ParallelsFormatExtensionHeader +FH_SIZE =3D 24 # ParallelsFeatureHeader +BF_SIZE =3D 32 # ParallelsDirtyBitmapFeature + +crafted =3D file_path('crafted') + + +def feature(magic, data_size, flags=3D0): + return struct.pack('> 30 + last =3D (chunk['start'] + chunk['length']) >> 30 + log(f'dirty {first}-{last} GiB') + + +check_multi_l1() diff --git a/tests/qemu-iotests/tests/parallels-read-bitmap.out b/tests/qem= u-iotests/tests/parallels-read-bitmap.out index e8f6bc9e96..3b3f90c8de 100644 --- a/tests/qemu-iotests/tests/parallels-read-bitmap.out +++ b/tests/qemu-iotests/tests/parallels-read-bitmap.out @@ -4,3 +4,36 @@ dirty clusters (cluster size is 64K): 10-12 30 Kill NBD server + +--- well-formed extension +image opened +--- wrong extension magic +qemu-img: Could not open 'TEST_DIR/PID-crafted': Wrong parallels Format Ex= tension magic: 0xab234cef23dcea86, expected: 0xab234cef23dcea87 +--- wrong extension checksum +qemu-img: Could not open 'TEST_DIR/PID-crafted': Wrong checksum in Format = Extension header. Format extension is corrupted. +--- unknown feature +qemu-img: Could not open 'TEST_DIR/PID-crafted': Unknown feature: 0x20385f= ae252cb34b +--- feature flags set +qemu-img: Could not open 'TEST_DIR/PID-crafted': Flags for extension featu= re are unsupported +--- feature data_size beyond the cluster +qemu-img: Could not open 'TEST_DIR/PID-crafted': Feature data_size exceede= s Format Extension cluster +--- feature payload consumes the cluster +qemu-img: Could not open 'TEST_DIR/PID-crafted': Can not read feature head= er, as remaining bytes (0) in Format Extension is less than Feature header = size (24) +--- second feature payload beyond the cluster +qemu-img: Could not open 'TEST_DIR/PID-crafted': Feature data_size exceede= s Format Extension cluster +--- bitmap granularity 0 +qemu-img: Could not open 'TEST_DIR/PID-crafted': Invalid bitmap granularit= y 0, expected a power of two of at least 512 bytes +--- bitmap granularity 3 +qemu-img: Could not open 'TEST_DIR/PID-crafted': Invalid bitmap granularit= y 1536, expected a power of two of at least 512 bytes +--- bitmap granularity 8388608 +qemu-img: Could not open 'TEST_DIR/PID-crafted': Invalid bitmap granularit= y 4294967296, expected a power of two of at least 512 bytes +--- bitmap L1 entry overflows +qemu-img: Could not open 'TEST_DIR/PID-crafted': Failed to read bitmap dat= a cluster: Input/output error +--- cluster_size beyond the file size +qemu-img: Could not open 'TEST_DIR/PID-crafted': Invalid image: Format Ext= ension is outside the image file +--- bitmap serialization coverage overflow +image opened +--- bitmap spanning two L1 entries +Start NBD server +dirty 32-64 GiB +Kill NBD server --=20 2.53.0