@@ -3597,8 +3597,15 @@ raw_co_zone_append(BlockDriverState *bs,
QEMUIOVector *qiov,
BdrvRequestFlags flags) {
assert(flags == 0);
+ int64_t capacity = bs->total_sectors << BDRV_SECTOR_BITS;
int64_t zone_size_mask = bs->bl.zone_size - 1;
+ if (*offset >= capacity) {
+ error_report("*offset %" PRId64 " is equal to or greater than the "
+ "device capacity %" PRId64 "", *offset, capacity);
+ return -ENOSPC;
+ }
+
if (*offset & zone_size_mask) {
error_report("sector offset %" PRId64 " is not aligned to zone size "
"%" PRId64 "", *offset / 512, bs->bl.zone_size / 512);
raw_co_zone_append() checks that the offset it is given is aligned to the zone size, but not that it names a zone of the device. raw_co_prw() then derives a zone index from it and reads that entry of the write pointer array, so an offset past the end of the device reads past the end of the array. bdrv_co_zone_append() does not catch it either: bdrv_check_qiov_request() bounds the request against BDRV_MAX_LENGTH, which has nothing to do with the size of this device. A guest cannot reach it, because check_zoned_request() in virtio-blk rejects an out of range offset first, but qemu-io and any other caller of blk_co_zone_append() can: $ qemu-io --image-opts -n driver=host_device,filename=/dev/nullb0 \ -c "zap -p 0x100000000000 0x1000" Segmentation fault On a null_blk device with 1000 zones of 256 MiB, that offset yields zone index 65536 and reads 512 KiB beyond an 8000 byte allocation. Reject an offset that lies outside the device. That also bounds the zone index that raw_co_prw() derives from it, so its write pointer lookup stays inside the array. Fixes: 4751d09adcc3 ("block: introduce zone append write for zoned devices") Reviewed-by: Damien Le Moal <dlemoal@kernel.org> Signed-off-by: Niklas Cassel <cassel@kernel.org> --- block/file-posix.c | 7 +++++++ 1 file changed, 7 insertions(+)