From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:52090) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1W5VRC-0006Ft-Gi for qemu-devel@nongnu.org; Tue, 21 Jan 2014 02:08:00 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1W5VR6-0004Fu-8w for qemu-devel@nongnu.org; Tue, 21 Jan 2014 02:07:54 -0500 Received: from mx1.redhat.com ([209.132.183.28]:62463) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1W5VR6-0004Fk-0R for qemu-devel@nongnu.org; Tue, 21 Jan 2014 02:07:48 -0500 Received: from int-mx01.intmail.prod.int.phx2.redhat.com (int-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.11]) by mx1.redhat.com (8.14.4/8.14.4) with ESMTP id s0L77kNc028486 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for ; Tue, 21 Jan 2014 02:07:46 -0500 From: Fam Zheng Date: Tue, 21 Jan 2014 15:07:43 +0800 Message-Id: <1390288063-23186-1-git-send-email-famz@redhat.com> Subject: [Qemu-devel] [PATCH] vmdk: Check for overhead when opening List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: kwolf@redhat.com, stefanha@redhat.com Report an error if file size is even smaller than metadata. Signed-off-by: Fam Zheng --- block/vmdk.c | 7 +++++++ tests/qemu-iotests/059 | 6 ++++++ tests/qemu-iotests/059.out | 5 +++++ 3 files changed, 18 insertions(+) diff --git a/block/vmdk.c b/block/vmdk.c index c6b60b4..7b53d41 100644 --- a/block/vmdk.c +++ b/block/vmdk.c @@ -640,6 +640,13 @@ static int vmdk_open_vmdk4(BlockDriverState *bs, if (le32_to_cpu(header.flags) & VMDK4_FLAG_RGD) { l1_backup_offset = le64_to_cpu(header.rgd_offset) << 9; } + if (bdrv_getlength(file) < + le64_to_cpu(header.grain_offset) * BDRV_SECTOR_SIZE) { + error_report("File truncated, expecting at least %lld bytes", + le64_to_cpu(header.grain_offset) * BDRV_SECTOR_SIZE); + return -EINVAL; + } + ret = vmdk_add_extent(bs, file, false, le64_to_cpu(header.capacity), le64_to_cpu(header.gd_offset) << 9, diff --git a/tests/qemu-iotests/059 b/tests/qemu-iotests/059 index 65bea1d..30671c0 100755 --- a/tests/qemu-iotests/059 +++ b/tests/qemu-iotests/059 @@ -95,6 +95,12 @@ EOF _img_info echo +echo "=== Testing truncated sparse ===" +IMGOPTS="subformat=monolithicSparse" _make_test_img 100G +truncate -s 10M $TEST_IMG +_img_info + +echo echo "=== Testing version 3 ===" _use_sample_img iotest-version3.vmdk.bz2 _img_info diff --git a/tests/qemu-iotests/059.out b/tests/qemu-iotests/059.out index 16ab7c6..7cc0e11 100644 --- a/tests/qemu-iotests/059.out +++ b/tests/qemu-iotests/059.out @@ -2043,6 +2043,11 @@ qemu-img: Could not open 'TEST_DIR/t.IMGFMT': Invalid extent lines: RW 12582912 VMFS "dummy.IMGFMT" 1 +=== Testing truncated sparse === +Formatting 'TEST_DIR/t.IMGFMT', fmt=IMGFMT size=107374182400 +qemu-img: File truncated, expecting at least 13172736 bytes +qemu-img: Could not open 'TEST_DIR/t.IMGFMT': Could not open 'TEST_DIR/t.IMGFMT': Wrong medium type + === Testing version 3 === image: TEST_DIR/iotest-version3.IMGFMT file format: IMGFMT -- 1.8.5.3