958e1b
From 7322fbc37925671b3ac9e589ba8eb200b7aee7f3 Mon Sep 17 00:00:00 2001
958e1b
Message-Id: <7322fbc37925671b3ac9e589ba8eb200b7aee7f3.1418766606.git.jen@redhat.com>
958e1b
In-Reply-To: <6f81b4847eb68ebdf54a8f1a771e19d112d74152.1418766606.git.jen@redhat.com>
958e1b
References: <6f81b4847eb68ebdf54a8f1a771e19d112d74152.1418766606.git.jen@redhat.com>
958e1b
From: Fam Zheng <famz@redhat.com>
958e1b
Date: Thu, 4 Dec 2014 00:04:57 -0600
958e1b
Subject: [CHANGE 03/31] vmdk: Check VMFS extent line field number
958e1b
To: rhvirt-patches@redhat.com,
958e1b
    jen@redhat.com
958e1b
958e1b
RH-Author: Fam Zheng <famz@redhat.com>
958e1b
Message-id: <1417651524-18041-4-git-send-email-famz@redhat.com>
958e1b
Patchwork-id: 62676
958e1b
O-Subject: [RHEL-7.1 qemu-kvm PATCH v5 03/30] vmdk: Check VMFS extent line field number
958e1b
Bugzilla: 1134237
958e1b
RH-Acked-by: Jeffrey Cody <jcody@redhat.com>
958e1b
RH-Acked-by: Markus Armbruster <armbru@redhat.com>
958e1b
RH-Acked-by: Max Reitz <mreitz@redhat.com>
958e1b
958e1b
VMFS extent line in description file should be with 4 fields:
958e1b
958e1b
    RW <size> VMFS "file-name.vmdk"
958e1b
958e1b
Check the number explicitly and report error if offset is appended as
958e1b
FLAT, which should be invalid format.
958e1b
958e1b
Reported-by: Paolo Bonzini <pbonzini@redhat.com>
958e1b
Signed-off-by: Fam Zheng <famz@redhat.com>
958e1b
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
958e1b
(cherry picked from commit b47053bd0359c68094d7a25a65687c0844771e34)
958e1b
Signed-off-by: Fam Zheng <famz@redhat.com>
958e1b
Signed-off-by: Jeff E. Nelson <jen@redhat.com>
958e1b
---
958e1b
 block/vmdk.c               |  9 +++++++--
958e1b
 tests/qemu-iotests/059     | 14 ++++++++++++++
958e1b
 tests/qemu-iotests/059.out |  5 +++++
958e1b
 3 files changed, 26 insertions(+), 2 deletions(-)
958e1b
958e1b
diff --git a/block/vmdk.c b/block/vmdk.c
958e1b
index a5b1f1c..d77eb37 100644
958e1b
--- a/block/vmdk.c
958e1b
+++ b/block/vmdk.c
958e1b
@@ -750,9 +750,14 @@ static int vmdk_parse_extents(const char *desc, BlockDriverState *bs,
958e1b
                 return -EINVAL;
958e1b
             }
958e1b
         } else if (!strcmp(type, "VMFS")) {
958e1b
-            flat_offset = 0;
958e1b
+            if (ret == 4) {
958e1b
+                flat_offset = 0;
958e1b
+            } else {
958e1b
+                error_setg(errp, "Invalid extent lines:\n%s", p);
958e1b
+                return -EINVAL;
958e1b
+            }
958e1b
         } else if (ret != 4) {
958e1b
-            error_setg(errp, "Invalid extent lines: \n%s", p);
958e1b
+            error_setg(errp, "Invalid extent lines:\n%s", p);
958e1b
             return -EINVAL;
958e1b
         }
958e1b
 
958e1b
diff --git a/tests/qemu-iotests/059 b/tests/qemu-iotests/059
958e1b
index 23534c2..c8d92a0 100755
958e1b
--- a/tests/qemu-iotests/059
958e1b
+++ b/tests/qemu-iotests/059
958e1b
@@ -81,6 +81,20 @@ IMGOPTS="subformat=twoGbMaxExtentFlat" _make_test_img 1000G
958e1b
 $QEMU_IMG info $TEST_IMG | _filter_testdir | sed -e 's/cid: [0-9]*/cid: XXXXXXXX/'
958e1b
 
958e1b
 echo
958e1b
+echo "=== Testing malformed VMFS extent description line ==="
958e1b
+cat >"$TEST_IMG" <
958e1b
+# Disk DescriptorFile
958e1b
+version=1
958e1b
+CID=58ab4847
958e1b
+parentCID=ffffffff
958e1b
+createType="vmfs"
958e1b
+
958e1b
+# Extent description
958e1b
+RW 12582912 VMFS "dummy.vmdk" 1
958e1b
+EOF
958e1b
+_img_info
958e1b
+
958e1b
+echo
958e1b
 echo "=== Testing version 3 ==="
958e1b
 _use_sample_img iotest-version3.vmdk.bz2
958e1b
 _img_info
958e1b
diff --git a/tests/qemu-iotests/059.out b/tests/qemu-iotests/059.out
958e1b
index 87a2004..f161651 100644
958e1b
--- a/tests/qemu-iotests/059.out
958e1b
+++ b/tests/qemu-iotests/059.out
958e1b
@@ -2038,6 +2038,11 @@ Format specific information:
958e1b
             filename: TEST_DIR/t-f500.vmdk
958e1b
             format: FLAT
958e1b
 
958e1b
+=== Testing malformed VMFS extent description line ===
958e1b
+qemu-img: Could not open 'TEST_DIR/t.IMGFMT': Invalid extent lines:
958e1b
+RW 12582912 VMFS "dummy.IMGFMT" 1
958e1b
+
958e1b
+
958e1b
 === Testing version 3 ===
958e1b
 image: TEST_DIR/iotest-version3.IMGFMT
958e1b
 file format: IMGFMT
958e1b
-- 
958e1b
2.1.0
958e1b