|
|
d76c62 |
From 57eb21eb48d76798f0c990c839df148301e9cb0e Mon Sep 17 00:00:00 2001
|
|
|
d76c62 |
Message-Id: <57eb21eb48d76798f0c990c839df148301e9cb0e@dist-git>
|
|
|
d76c62 |
From: Peter Krempa <pkrempa@redhat.com>
|
|
|
d76c62 |
Date: Wed, 19 Feb 2020 15:10:10 +0100
|
|
|
d76c62 |
Subject: [PATCH] virStorageSourceParseBackingJSON: Prevent arbitrary nesting
|
|
|
d76c62 |
with format drivers
|
|
|
d76c62 |
MIME-Version: 1.0
|
|
|
d76c62 |
Content-Type: text/plain; charset=UTF-8
|
|
|
d76c62 |
Content-Transfer-Encoding: 8bit
|
|
|
d76c62 |
|
|
|
d76c62 |
Since we parse attributes for 'raw' which is a format driver and thus
|
|
|
d76c62 |
has nested 'file' structure we must prevent that this isn't nested
|
|
|
d76c62 |
arbitrarily.
|
|
|
d76c62 |
|
|
|
d76c62 |
Add a flag for the function which allows parsing of 'format' type
|
|
|
d76c62 |
drivers only on the first pass.
|
|
|
d76c62 |
|
|
|
d76c62 |
Signed-off-by: Peter Krempa <pkrempa@redhat.com>
|
|
|
d76c62 |
Reviewed-by: Ján Tomko <jtomko@redhat.com>
|
|
|
d76c62 |
(cherry picked from commit fd70f1b4d324361bb9a708762631690aca043178)
|
|
|
d76c62 |
|
|
|
d76c62 |
https://bugzilla.redhat.com/show_bug.cgi?id=1791788
|
|
|
d76c62 |
Message-Id: <b5ed395d736eb8570467e2eafb44288d77d416e7.1582120424.git.pkrempa@redhat.com>
|
|
|
d76c62 |
Reviewed-by: Ján Tomko <jtomko@redhat.com>
|
|
|
d76c62 |
---
|
|
|
d76c62 |
src/util/virstoragefile.c | 23 +++++++++++++++++------
|
|
|
d76c62 |
1 file changed, 17 insertions(+), 6 deletions(-)
|
|
|
d76c62 |
|
|
|
d76c62 |
diff --git a/src/util/virstoragefile.c b/src/util/virstoragefile.c
|
|
|
d76c62 |
index dd05de188f..b02fad92b6 100644
|
|
|
d76c62 |
--- a/src/util/virstoragefile.c
|
|
|
d76c62 |
+++ b/src/util/virstoragefile.c
|
|
|
d76c62 |
@@ -3052,7 +3052,8 @@ virStorageSourceParseBackingColon(virStorageSourcePtr src,
|
|
|
d76c62 |
static int
|
|
|
d76c62 |
virStorageSourceParseBackingJSONInternal(virStorageSourcePtr src,
|
|
|
d76c62 |
virJSONValuePtr json,
|
|
|
d76c62 |
- const char *jsonstr);
|
|
|
d76c62 |
+ const char *jsonstr,
|
|
|
d76c62 |
+ bool allowformat);
|
|
|
d76c62 |
|
|
|
d76c62 |
|
|
|
d76c62 |
static int
|
|
|
d76c62 |
@@ -3531,7 +3532,7 @@ virStorageSourceParseBackingJSONRaw(virStorageSourcePtr src,
|
|
|
d76c62 |
return -1;
|
|
|
d76c62 |
}
|
|
|
d76c62 |
|
|
|
d76c62 |
- return virStorageSourceParseBackingJSONInternal(src, file, jsonstr);
|
|
|
d76c62 |
+ return virStorageSourceParseBackingJSONInternal(src, file, jsonstr, false);
|
|
|
d76c62 |
}
|
|
|
d76c62 |
|
|
|
d76c62 |
|
|
|
d76c62 |
@@ -3606,7 +3607,8 @@ static const struct virStorageSourceJSONDriverParser jsonParsers[] = {
|
|
|
d76c62 |
static int
|
|
|
d76c62 |
virStorageSourceParseBackingJSONInternal(virStorageSourcePtr src,
|
|
|
d76c62 |
virJSONValuePtr json,
|
|
|
d76c62 |
- const char *jsonstr)
|
|
|
d76c62 |
+ const char *jsonstr,
|
|
|
d76c62 |
+ bool allowformat)
|
|
|
d76c62 |
{
|
|
|
d76c62 |
const char *drvname;
|
|
|
d76c62 |
size_t i;
|
|
|
d76c62 |
@@ -3619,8 +3621,17 @@ virStorageSourceParseBackingJSONInternal(virStorageSourcePtr src,
|
|
|
d76c62 |
}
|
|
|
d76c62 |
|
|
|
d76c62 |
for (i = 0; i < G_N_ELEMENTS(jsonParsers); i++) {
|
|
|
d76c62 |
- if (STREQ(drvname, jsonParsers[i].drvname))
|
|
|
d76c62 |
- return jsonParsers[i].func(src, json, jsonstr, jsonParsers[i].opaque);
|
|
|
d76c62 |
+ if (STRNEQ(drvname, jsonParsers[i].drvname))
|
|
|
d76c62 |
+ continue;
|
|
|
d76c62 |
+
|
|
|
d76c62 |
+ if (jsonParsers[i].formatdriver && !allowformat) {
|
|
|
d76c62 |
+ virReportError(VIR_ERR_INVALID_ARG,
|
|
|
d76c62 |
+ _("JSON backing volume definition '%s' must not have nested format drivers"),
|
|
|
d76c62 |
+ jsonstr);
|
|
|
d76c62 |
+ return -1;
|
|
|
d76c62 |
+ }
|
|
|
d76c62 |
+
|
|
|
d76c62 |
+ return jsonParsers[i].func(src, json, jsonstr, jsonParsers[i].opaque);
|
|
|
d76c62 |
}
|
|
|
d76c62 |
|
|
|
d76c62 |
virReportError(VIR_ERR_INTERNAL_ERROR,
|
|
|
d76c62 |
@@ -3655,7 +3666,7 @@ virStorageSourceParseBackingJSON(virStorageSourcePtr src,
|
|
|
d76c62 |
if (!file)
|
|
|
d76c62 |
file = deflattened;
|
|
|
d76c62 |
|
|
|
d76c62 |
- return virStorageSourceParseBackingJSONInternal(src, file, json);
|
|
|
d76c62 |
+ return virStorageSourceParseBackingJSONInternal(src, file, json, true);
|
|
|
d76c62 |
}
|
|
|
d76c62 |
|
|
|
d76c62 |
|
|
|
d76c62 |
--
|
|
|
d76c62 |
2.25.0
|
|
|
d76c62 |
|