]> Git Repo - qemu.git/blame - tests/qemu-iotests/080
qcow2: Validate snapshot table offset/size (CVE-2014-0144)
[qemu.git] / tests / qemu-iotests / 080
CommitLineData
24342f2c
KW
1#!/bin/bash
2#
3# qcow2 format input validation tests
4#
5# Copyright (C) 2013 Red Hat, Inc.
6#
7# This program is free software; you can redistribute it and/or modify
8# it under the terms of the GNU General Public License as published by
9# the Free Software Foundation; either version 2 of the License, or
10# (at your option) any later version.
11#
12# This program is distributed in the hope that it will be useful,
13# but WITHOUT ANY WARRANTY; without even the implied warranty of
14# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15# GNU General Public License for more details.
16#
17# You should have received a copy of the GNU General Public License
18# along with this program. If not, see <http://www.gnu.org/licenses/>.
19#
20
21# creator
22[email protected]
23
24seq=`basename $0`
25echo "QA output created by $seq"
26
27here=`pwd`
28tmp=/tmp/$$
29status=1 # failure is the default!
30
31_cleanup()
32{
33 _cleanup_test_img
34}
35trap "_cleanup; exit \$status" 0 1 2 3 15
36
37# get standard environment, filters and checks
38. ./common.rc
39. ./common.filter
40
41_supported_fmt qcow2
42_supported_proto generic
43_supported_os Linux
44
45header_size=104
a1b3955c
KW
46
47offset_backing_file_offset=8
8c7de283 48offset_refcount_table_offset=48
5dab2fad 49offset_refcount_table_clusters=56
ce48f2f4
KW
50offset_nb_snapshots=60
51offset_snapshots_offset=64
24342f2c
KW
52offset_header_size=100
53offset_ext_magic=$header_size
54offset_ext_size=$((header_size + 4))
55
56echo
57echo "== Huge header size =="
58_make_test_img 64M
59poke_file "$TEST_IMG" "$offset_header_size" "\xff\xff\xff\xff"
60{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
61poke_file "$TEST_IMG" "$offset_header_size" "\x7f\xff\xff\xff"
62{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
63
a1b3955c
KW
64echo
65echo "== Huge unknown header extension =="
66_make_test_img 64M
67poke_file "$TEST_IMG" "$offset_backing_file_offset" "\xff\xff\xff\xff\xff\xff\xff\xff"
68poke_file "$TEST_IMG" "$offset_ext_magic" "\x12\x34\x56\x78"
69poke_file "$TEST_IMG" "$offset_ext_size" "\x7f\xff\xff\xff"
70{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
71poke_file "$TEST_IMG" "$offset_backing_file_offset" "\x00\x00\x00\x00\x00\x00\x00\x00"
72{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
73
5dab2fad
KW
74echo
75echo "== Huge refcount table size =="
76_make_test_img 64M
77poke_file "$TEST_IMG" "$offset_refcount_table_clusters" "\xff\xff\xff\xff"
78{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
79poke_file "$TEST_IMG" "$offset_refcount_table_clusters" "\x00\x02\x00\x01"
80{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
81
8c7de283
KW
82echo
83echo "== Misaligned refcount table =="
84_make_test_img 64M
85poke_file "$TEST_IMG" "$offset_refcount_table_offset" "\x12\x34\x56\x78\x90\xab\xcd\xef"
86{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
87
88echo
89echo "== Huge refcount offset =="
90_make_test_img 64M
91poke_file "$TEST_IMG" "$offset_refcount_table_offset" "\xff\xff\xff\xff\xff\xff\x00\x00"
92poke_file "$TEST_IMG" "$offset_refcount_table_clusters" "\x00\x00\x00\x7f"
93{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
5dab2fad 94
ce48f2f4
KW
95echo
96echo "== Invalid snapshot table =="
97_make_test_img 64M
98poke_file "$TEST_IMG" "$offset_nb_snapshots" "\xff\xff\xff\xff"
99{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
100poke_file "$TEST_IMG" "$offset_nb_snapshots" "\x7f\xff\xff\xff"
101{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
102
103poke_file "$TEST_IMG" "$offset_snapshots_offset" "\xff\xff\xff\xff\xff\xff\x00\x00"
104poke_file "$TEST_IMG" "$offset_nb_snapshots" "\x00\x00\xff\xff"
105{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
106
107poke_file "$TEST_IMG" "$offset_snapshots_offset" "\x12\x34\x56\x78\x90\xab\xcd\xef"
108poke_file "$TEST_IMG" "$offset_nb_snapshots" "\x00\x00\x00\x00"
109{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
110
111echo
112echo "== Hitting snapshot table size limit =="
113_make_test_img 64M
114# Put the refcount table in a more or less safe place (16 MB)
115poke_file "$TEST_IMG" "$offset_snapshots_offset" "\x00\x00\x00\x00\x01\x00\x00\x00"
116poke_file "$TEST_IMG" "$offset_nb_snapshots" "\x00\x01\x00\x00"
117{ $QEMU_IMG snapshot -c test $TEST_IMG; } 2>&1 | _filter_testdir
118{ $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
119
24342f2c
KW
120# success, all done
121echo "*** done"
122rm -f $seq.full
123status=0
This page took 0.036191 seconds and 4 git commands to generate.