From: Stefan Hajnoczi <stefanha@redhat.com>
To: Kevin Wolf <kwolf@redhat.com>
Cc: benoit.canet@irqsave.net, qemu-devel@nongnu.org
Subject: Re: [Qemu-devel] [PATCH v4 00/21] block: Handle failure for potentially large allocations
Date: Wed, 11 Jun 2014 12:33:53 +0200 [thread overview]
Message-ID: <20140611103353.GE6673@stefanha-thinkpad.str.redhat.com> (raw)
In-Reply-To: <1401975393-7255-1-git-send-email-kwolf@redhat.com>
[-- Attachment #1: Type: text/plain, Size: 4555 bytes --]
On Thu, Jun 05, 2014 at 03:36:12PM +0200, Kevin Wolf wrote:
> A not too small part of the recent CVEs were DoS scenarios by letting
> qemu abort with too large memory allocations. We generally "fixed" these
> cases by setting some limits on values read from image files that
> influence the size of allocations.
>
> Because we still need to allow reading large images, this works only to
> a certain degree and we still can get fairly large allocations, which
> are not unthinkable to fail on some machines.
>
> This series converts potentially large allocations to g_try_malloc() and
> friends and handles failure gracefully e.g. by returning -ENOMEM. This
> may cause hot-plug of a new disk or individual requests to fail, but the
> VM as a whole can keep running.
>
> v4:
> - Patch 11 (qcow2): Fix memory leak in qcow2_cache_create() [Benoît]
>
> v3:
> - Changed qemu_try_blockalign() to only return NULL on failure. size = 0
> results in a small allocation now (size of the alignment) [Benoît]
> - Patch 8 (nfs): Check for size != 0 before failing [Benoît]
> - Patch 11 (qcow2):
> * Fix memory leak in alloc_refcount_block() [Max]
> * Report internal error for -ENOMEM in qcow2_check() [Max]
> - Patch 15 (rbd): Build fix [Markus]
>
> v2:
> - Some more places check for size = 0 before they treat NULL as an error
> - Patch 2 (block.c): Added missing NULL return check for
> qemu_try_blockalign() [Stefan]
> - Patch 7 (iscsi): Fixed acb->task memory leak [Stefan]
> - For conversions from g_malloc() to qemu_try_blockalign(), made sure to
> be consistent about pairing the latter with qemu_vfree() [Stefan]
>
> *** BLURB HERE ***
>
> Kevin Wolf (20):
> block: Introduce qemu_try_blockalign()
> block: Handle failure for potentially large allocations
> bochs: Handle failure for potentially large allocations
> cloop: Handle failure for potentially large allocations
> curl: Handle failure for potentially large allocations
> dmg: Handle failure for potentially large allocations
> iscsi: Handle failure for potentially large allocations
> nfs: Handle failure for potentially large allocations
> parallels: Handle failure for potentially large allocations
> qcow1: Handle failure for potentially large allocations
> qcow2: Handle failure for potentially large allocations
> qed: Handle failure for potentially large allocations
> raw-posix: Handle failure for potentially large allocations
> raw-win32: Handle failure for potentially large allocations
> rbd: Handle failure for potentially large allocations
> vdi: Handle failure for potentially large allocations
> vhdx: Handle failure for potentially large allocations
> vmdk: Handle failure for potentially large allocations
> vpc: Handle failure for potentially large allocations
> mirror: Handle failure for potentially large allocations
>
> Max Reitz (1):
> qcow2: Return useful error code in refcount_init()
>
> block.c | 47 ++++++++++++++++++++++++++++++++++++-------
> block/bochs.c | 6 +++++-
> block/cloop.c | 23 ++++++++++++++++++---
> block/curl.c | 8 +++++++-
> block/dmg.c | 19 ++++++++++++------
> block/iscsi.c | 17 +++++++++++++---
> block/mirror.c | 7 ++++++-
> block/nfs.c | 6 +++++-
> block/parallels.c | 6 +++++-
> block/qcow.c | 33 +++++++++++++++++++++++-------
> block/qcow2-cache.c | 13 +++++++++++-
> block/qcow2-cluster.c | 35 ++++++++++++++++++++++++--------
> block/qcow2-refcount.c | 54 +++++++++++++++++++++++++++++++++++++++-----------
> block/qcow2-snapshot.c | 22 +++++++++++++++-----
> block/qcow2.c | 41 ++++++++++++++++++++++++++++++--------
> block/qed-check.c | 7 +++++--
> block/qed.c | 6 +++++-
> block/raw-posix.c | 6 +++++-
> block/rbd.c | 7 +++++--
> block/vdi.c | 24 +++++++++++++++++-----
> block/vhdx-log.c | 6 +++++-
> block/vhdx.c | 12 +++++++++--
> block/vmdk.c | 12 +++++++++--
> block/vpc.c | 6 +++++-
> block/win32-aio.c | 6 +++++-
> include/block/block.h | 1 +
> include/qemu/osdep.h | 1 +
> util/oslib-posix.c | 16 +++++++++------
> util/oslib-win32.c | 9 +++++++--
> 29 files changed, 365 insertions(+), 91 deletions(-)
>
> --
> 1.8.3.1
>
Thanks, applied to my block tree:
https://github.com/stefanha/qemu/commits/block
Stefan
[-- Attachment #2: Type: application/pgp-signature, Size: 473 bytes --]
next prev parent reply other threads:[~2014-06-11 10:34 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-06-05 13:36 [Qemu-devel] [PATCH v4 00/21] block: Handle failure for potentially large allocations Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 01/21] block: Introduce qemu_try_blockalign() Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 02/21] block: Handle failure for potentially large allocations Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 03/21] bochs: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 04/21] cloop: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 05/21] curl: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 06/21] dmg: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 07/21] iscsi: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 08/21] nfs: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 09/21] parallels: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 10/21] qcow1: " Kevin Wolf
2014-06-05 15:04 ` Benoît Canet
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 11/21] qcow2: " Kevin Wolf
2014-06-05 14:52 ` Benoît Canet
2014-06-06 8:55 ` Kevin Wolf
2014-06-06 11:19 ` Benoît Canet
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 12/21] qed: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 13/21] raw-posix: " Kevin Wolf
2014-06-05 14:57 ` Benoît Canet
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 14/21] raw-win32: " Kevin Wolf
2014-06-05 15:09 ` Benoît Canet
2014-06-06 9:53 ` Kevin Wolf
2014-06-06 11:19 ` Benoît Canet
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 15/21] rbd: " Kevin Wolf
2014-06-05 15:05 ` Benoît Canet
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 16/21] vdi: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 17/21] vhdx: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 18/21] vmdk: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 19/21] vpc: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 20/21] mirror: " Kevin Wolf
2014-06-05 13:36 ` [Qemu-devel] [PATCH v4 21/21] qcow2: Return useful error code in refcount_init() Kevin Wolf
2014-06-11 10:33 ` Stefan Hajnoczi [this message]
2014-06-11 14:36 ` [Qemu-devel] [PATCH v4 00/21] block: Handle failure for potentially large allocations Stefan Hajnoczi
-- strict thread matches above, loose matches on Subject: below --
2014-06-24 15:36 Kevin Wolf
2014-08-07 18:34 ` Max Reitz
2014-08-08 8:23 ` Kevin Wolf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140611103353.GE6673@stefanha-thinkpad.str.redhat.com \
--to=stefanha@redhat.com \
--cc=benoit.canet@irqsave.net \
--cc=kwolf@redhat.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).