]> git.proxmox.com Git - mirror_qemu.git/blame - block/bochs.c
bochs: Check extent_size header field (CVE-2014-0142)
[mirror_qemu.git] / block / bochs.c
CommitLineData
a8753c34
FB
1/*
2 * Block driver for the various disk image formats used by Bochs
3 * Currently only for "growing" type in read-only mode
5fafdf24 4 *
a8753c34 5 * Copyright (c) 2005 Alex Beregszaszi
5fafdf24 6 *
a8753c34
FB
7 * Permission is hereby granted, free of charge, to any person obtaining a copy
8 * of this software and associated documentation files (the "Software"), to deal
9 * in the Software without restriction, including without limitation the rights
10 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
11 * copies of the Software, and to permit persons to whom the Software is
12 * furnished to do so, subject to the following conditions:
13 *
14 * The above copyright notice and this permission notice shall be included in
15 * all copies or substantial portions of the Software.
16 *
17 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
18 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
19 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
20 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
21 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
22 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
23 * THE SOFTWARE.
24 */
faf07963 25#include "qemu-common.h"
737e150e 26#include "block/block_int.h"
1de7afc9 27#include "qemu/module.h"
a8753c34
FB
28
29/**************************************************************/
30
31#define HEADER_MAGIC "Bochs Virtual HD Image"
6850dd94
TS
32#define HEADER_VERSION 0x00020000
33#define HEADER_V1 0x00010000
a8753c34
FB
34#define HEADER_SIZE 512
35
36#define REDOLOG_TYPE "Redolog"
37#define GROWING_TYPE "Growing"
38
39// not allocated: 0xffffffff
40
6850dd94
TS
41// always little-endian
42struct bochs_header {
3dd8a676
KW
43 char magic[32]; /* "Bochs Virtual HD Image" */
44 char type[16]; /* "Redolog" */
45 char subtype[16]; /* "Undoable" / "Volatile" / "Growing" */
6850dd94 46 uint32_t version;
3dd8a676
KW
47 uint32_t header; /* size of header */
48
49 uint32_t catalog; /* num of entries */
50 uint32_t bitmap; /* bitmap size */
51 uint32_t extent; /* extent size */
3b46e624 52
6850dd94 53 union {
3dd8a676
KW
54 struct {
55 uint32_t reserved; /* for ??? */
56 uint64_t disk; /* disk size */
57 char padding[HEADER_SIZE - 64 - 20 - 12];
58 } QEMU_PACKED redolog;
59 struct {
60 uint64_t disk; /* disk size */
61 char padding[HEADER_SIZE - 64 - 20 - 8];
62 } QEMU_PACKED redolog_v1;
63 char padding[HEADER_SIZE - 64 - 20];
6850dd94 64 } extra;
3dd8a676 65} QEMU_PACKED;
6850dd94 66
a8753c34 67typedef struct BDRVBochsState {
848c66e8 68 CoMutex lock;
a8753c34 69 uint32_t *catalog_bitmap;
246f6583 70 uint32_t catalog_size;
3b46e624 71
246f6583 72 uint32_t data_offset;
3b46e624 73
246f6583
KW
74 uint32_t bitmap_blocks;
75 uint32_t extent_blocks;
76 uint32_t extent_size;
a8753c34
FB
77} BDRVBochsState;
78
79static int bochs_probe(const uint8_t *buf, int buf_size, const char *filename)
80{
81 const struct bochs_header *bochs = (const void *)buf;
3b46e624 82
a8753c34
FB
83 if (buf_size < HEADER_SIZE)
84 return 0;
85
86 if (!strcmp(bochs->magic, HEADER_MAGIC) &&
87 !strcmp(bochs->type, REDOLOG_TYPE) &&
88 !strcmp(bochs->subtype, GROWING_TYPE) &&
6850dd94
TS
89 ((le32_to_cpu(bochs->version) == HEADER_VERSION) ||
90 (le32_to_cpu(bochs->version) == HEADER_V1)))
a8753c34
FB
91 return 100;
92
93 return 0;
94}
95
015a1036
HR
96static int bochs_open(BlockDriverState *bs, QDict *options, int flags,
97 Error **errp)
a8753c34
FB
98{
99 BDRVBochsState *s = bs->opaque;
246f6583 100 uint32_t i;
a8753c34 101 struct bochs_header bochs;
5b7d7dfd 102 int ret;
a8753c34 103
a8753c34 104 bs->read_only = 1; // no write support yet
3b46e624 105
5b7d7dfd
KW
106 ret = bdrv_pread(bs->file, 0, &bochs, sizeof(bochs));
107 if (ret < 0) {
108 return ret;
a8753c34
FB
109 }
110
111 if (strcmp(bochs.magic, HEADER_MAGIC) ||
112 strcmp(bochs.type, REDOLOG_TYPE) ||
113 strcmp(bochs.subtype, GROWING_TYPE) ||
6850dd94
TS
114 ((le32_to_cpu(bochs.version) != HEADER_VERSION) &&
115 (le32_to_cpu(bochs.version) != HEADER_V1))) {
76abe407
PB
116 error_setg(errp, "Image not in Bochs format");
117 return -EINVAL;
a8753c34
FB
118 }
119
6850dd94 120 if (le32_to_cpu(bochs.version) == HEADER_V1) {
3dd8a676 121 bs->total_sectors = le64_to_cpu(bochs.extra.redolog_v1.disk) / 512;
6850dd94 122 } else {
3dd8a676 123 bs->total_sectors = le64_to_cpu(bochs.extra.redolog.disk) / 512;
6850dd94 124 }
a8753c34 125
e3737b82
KW
126 /* Limit to 1M entries to avoid unbounded allocation. This is what is
127 * needed for the largest image that bximage can create (~8 TB). */
3dd8a676 128 s->catalog_size = le32_to_cpu(bochs.catalog);
e3737b82
KW
129 if (s->catalog_size > 0x100000) {
130 error_setg(errp, "Catalog size is too large");
131 return -EFBIG;
132 }
133
7267c094 134 s->catalog_bitmap = g_malloc(s->catalog_size * 4);
5b7d7dfd
KW
135
136 ret = bdrv_pread(bs->file, le32_to_cpu(bochs.header), s->catalog_bitmap,
137 s->catalog_size * 4);
138 if (ret < 0) {
139 goto fail;
140 }
141
a8753c34
FB
142 for (i = 0; i < s->catalog_size; i++)
143 le32_to_cpus(&s->catalog_bitmap[i]);
144
145 s->data_offset = le32_to_cpu(bochs.header) + (s->catalog_size * 4);
146
3dd8a676
KW
147 s->bitmap_blocks = 1 + (le32_to_cpu(bochs.bitmap) - 1) / 512;
148 s->extent_blocks = 1 + (le32_to_cpu(bochs.extent) - 1) / 512;
3b46e624 149
3dd8a676 150 s->extent_size = le32_to_cpu(bochs.extent);
8e53abbc
KW
151 if (s->extent_size == 0) {
152 error_setg(errp, "Extent size may not be zero");
153 return -EINVAL;
154 } else if (s->extent_size > 0x800000) {
155 error_setg(errp, "Extent size %" PRIu32 " is too large",
156 s->extent_size);
157 return -EINVAL;
158 }
a8753c34 159
e3737b82
KW
160 if (s->catalog_size < bs->total_sectors / s->extent_size) {
161 error_setg(errp, "Catalog size is too small for this disk size");
162 ret = -EINVAL;
163 goto fail;
164 }
165
848c66e8 166 qemu_co_mutex_init(&s->lock);
a8753c34 167 return 0;
5b7d7dfd
KW
168
169fail:
170 g_free(s->catalog_bitmap);
171 return ret;
a8753c34
FB
172}
173
efbca10f 174static int64_t seek_to_sector(BlockDriverState *bs, int64_t sector_num)
a8753c34
FB
175{
176 BDRVBochsState *s = bs->opaque;
246f6583
KW
177 uint64_t offset = sector_num * 512;
178 uint64_t extent_index, extent_offset, bitmap_offset;
a8753c34
FB
179 char bitmap_entry;
180
181 // seek to sector
182 extent_index = offset / s->extent_size;
183 extent_offset = (offset % s->extent_size) / 512;
3b46e624 184
efbca10f
CH
185 if (s->catalog_bitmap[extent_index] == 0xffffffff) {
186 return -1; /* not allocated */
a8753c34
FB
187 }
188
189 bitmap_offset = s->data_offset + (512 * s->catalog_bitmap[extent_index] *
190 (s->extent_blocks + s->bitmap_blocks));
3b46e624 191
efbca10f 192 /* read in bitmap for current extent */
7a6f3913
CH
193 if (bdrv_pread(bs->file, bitmap_offset + (extent_offset / 8),
194 &bitmap_entry, 1) != 1) {
00ccf932 195 return -1;
a8753c34
FB
196 }
197
efbca10f
CH
198 if (!((bitmap_entry >> (extent_offset % 8)) & 1)) {
199 return -1; /* not allocated */
ecbe1576 200 }
3b46e624 201
efbca10f 202 return bitmap_offset + (512 * (s->bitmap_blocks + extent_offset));
a8753c34
FB
203}
204
5fafdf24 205static int bochs_read(BlockDriverState *bs, int64_t sector_num,
a8753c34
FB
206 uint8_t *buf, int nb_sectors)
207{
a8753c34
FB
208 int ret;
209
210 while (nb_sectors > 0) {
efbca10f
CH
211 int64_t block_offset = seek_to_sector(bs, sector_num);
212 if (block_offset >= 0) {
7a6f3913 213 ret = bdrv_pread(bs->file, block_offset, buf, 512);
efbca10f
CH
214 if (ret != 512) {
215 return -1;
216 }
217 } else
a8753c34
FB
218 memset(buf, 0, 512);
219 nb_sectors--;
220 sector_num++;
221 buf += 512;
222 }
223 return 0;
224}
225
2914caa0
PB
226static coroutine_fn int bochs_co_read(BlockDriverState *bs, int64_t sector_num,
227 uint8_t *buf, int nb_sectors)
228{
229 int ret;
230 BDRVBochsState *s = bs->opaque;
231 qemu_co_mutex_lock(&s->lock);
232 ret = bochs_read(bs, sector_num, buf, nb_sectors);
233 qemu_co_mutex_unlock(&s->lock);
234 return ret;
235}
236
a8753c34
FB
237static void bochs_close(BlockDriverState *bs)
238{
239 BDRVBochsState *s = bs->opaque;
7267c094 240 g_free(s->catalog_bitmap);
a8753c34
FB
241}
242
5efa9d5a 243static BlockDriver bdrv_bochs = {
e60f469c
AJ
244 .format_name = "bochs",
245 .instance_size = sizeof(BDRVBochsState),
246 .bdrv_probe = bochs_probe,
7a6f3913 247 .bdrv_open = bochs_open,
2914caa0 248 .bdrv_read = bochs_co_read,
e60f469c 249 .bdrv_close = bochs_close,
a8753c34 250};
5efa9d5a
AL
251
252static void bdrv_bochs_init(void)
253{
254 bdrv_register(&bdrv_bochs);
255}
256
257block_init(bdrv_bochs_init);