53 lines
1.9 KiB
Diff
53 lines
1.9 KiB
Diff
|
|
From 905b918d99f2b60834b55f24738728ce9972ea29 Mon Sep 17 00:00:00 2001
|
||
|
|
From: Kevin Wolf <kwolf@redhat.com>
|
||
|
|
Date: Thu, 25 Apr 2024 14:49:40 +0200
|
||
|
|
Subject: [PATCH] iotests/244: Don't store data-file with protocol in image
|
||
|
|
(CVE-2024-4467)
|
||
|
|
|
||
|
|
We want to disable filename parsing for data files because it's too easy
|
||
|
|
to abuse in malicious image files. Make the test ready for the change by
|
||
|
|
passing the data file explicitly in command line options.
|
||
|
|
|
||
|
|
Cc: qemu-stable@nongnu.org
|
||
|
|
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
|
||
|
|
Reviewed-by: Eric Blake <eblake@redhat.com>
|
||
|
|
Reviewed-by: Stefan Hajnoczi <stefanha@redhat.com>
|
||
|
|
Reviewed-by: Hanna Czenczek <hreitz@redhat.com>
|
||
|
|
---
|
||
|
|
tests/qemu-iotests/244 | 19 ++++++++++++++++---
|
||
|
|
1 file changed, 16 insertions(+), 3 deletions(-)
|
||
|
|
|
||
|
|
diff --git a/tests/qemu-iotests/244 b/tests/qemu-iotests/244
|
||
|
|
index 3e61fa25bb..bb9cc6512f 100755
|
||
|
|
--- a/tests/qemu-iotests/244
|
||
|
|
+++ b/tests/qemu-iotests/244
|
||
|
|
@@ -215,9 +215,22 @@ $QEMU_IMG convert -f $IMGFMT -O $IMGFMT -n -C "$TEST_IMG.src" "$TEST_IMG"
|
||
|
|
$QEMU_IMG compare -f $IMGFMT -F $IMGFMT "$TEST_IMG.src" "$TEST_IMG"
|
||
|
|
|
||
|
|
# blkdebug doesn't support copy offloading, so this tests the error path
|
||
|
|
-$QEMU_IMG amend -f $IMGFMT -o "data_file=blkdebug::$TEST_IMG.data" "$TEST_IMG"
|
||
|
|
-$QEMU_IMG convert -f $IMGFMT -O $IMGFMT -n -C "$TEST_IMG.src" "$TEST_IMG"
|
||
|
|
-$QEMU_IMG compare -f $IMGFMT -F $IMGFMT "$TEST_IMG.src" "$TEST_IMG"
|
||
|
|
+test_img_with_blkdebug="json:{
|
||
|
|
+ 'driver': 'qcow2',
|
||
|
|
+ 'file': {
|
||
|
|
+ 'driver': 'file',
|
||
|
|
+ 'filename': '$TEST_IMG'
|
||
|
|
+ },
|
||
|
|
+ 'data-file': {
|
||
|
|
+ 'driver': 'blkdebug',
|
||
|
|
+ 'image': {
|
||
|
|
+ 'driver': 'file',
|
||
|
|
+ 'filename': '$TEST_IMG.data'
|
||
|
|
+ }
|
||
|
|
+ }
|
||
|
|
+}"
|
||
|
|
+$QEMU_IMG convert -f $IMGFMT -O $IMGFMT -n -C "$TEST_IMG.src" "$test_img_with_blkdebug"
|
||
|
|
+$QEMU_IMG compare -f $IMGFMT -F $IMGFMT "$TEST_IMG.src" "$test_img_with_blkdebug"
|
||
|
|
|
||
|
|
echo
|
||
|
|
echo "=== Flushing should flush the data file ==="
|
||
|
|
--
|
||
|
|
2.41.0.windows.1
|
||
|
|
|