3 # qcow2 format input validation tests
5 # Copyright (C) 2013 Red Hat, Inc.
7 # This program is free software; you can redistribute it and/or modify
8 # it under the terms of the GNU General Public License as published by
9 # the Free Software Foundation; either version 2 of the License, or
10 # (at your option) any later version.
12 # This program is distributed in the hope that it will be useful,
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 # GNU General Public License for more details.
17 # You should have received a copy of the GNU General Public License
18 # along with this program. If not, see <http://www.gnu.org/licenses/>.
22 owner
=kwolf@redhat.com
25 echo "QA output created by $seq"
29 status
=1 # failure is the default!
36 trap "_cleanup; exit \$status" 0 1 2 3 15
38 # get standard environment, filters and checks
45 # Internal snapshots are (currently) impossible with refcount_bits=1
46 _unsupported_imgopts
'refcount_bits=1[^0-9]'
50 offset_backing_file_offset
=8
51 offset_backing_file_size
=16
53 offset_l1_table_offset
=40
54 offset_refcount_table_offset
=48
55 offset_refcount_table_clusters
=56
56 offset_nb_snapshots
=60
57 offset_snapshots_offset
=64
58 offset_header_size
=100
59 offset_ext_magic
=$header_size
60 offset_ext_size
=$
((header_size
+ 4))
62 offset_l2_table_0
=$
((0x40000))
64 offset_snap1
=$
((0x70000))
65 offset_snap1_l1_offset
=$
((offset_snap1
+ 0))
66 offset_snap1_l1_size
=$
((offset_snap1
+ 8))
69 echo "== Huge header size =="
71 poke_file
"$TEST_IMG" "$offset_header_size" "\xff\xff\xff\xff"
72 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
73 poke_file
"$TEST_IMG" "$offset_header_size" "\x7f\xff\xff\xff"
74 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
77 echo "== Huge unknown header extension =="
79 poke_file
"$TEST_IMG" "$offset_backing_file_offset" "\xff\xff\xff\xff\xff\xff\xff\xff"
80 poke_file
"$TEST_IMG" "$offset_ext_magic" "\x12\x34\x56\x78"
81 poke_file
"$TEST_IMG" "$offset_ext_size" "\x7f\xff\xff\xff"
82 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
83 poke_file
"$TEST_IMG" "$offset_backing_file_offset" "\x00\x00\x00\x00\x00\x00\x00\x$(printf %x $offset_ext_size)"
84 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
85 poke_file
"$TEST_IMG" "$offset_backing_file_offset" "\x00\x00\x00\x00\x00\x00\x00\x00"
86 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
89 echo "== Huge refcount table size =="
91 poke_file
"$TEST_IMG" "$offset_refcount_table_clusters" "\xff\xff\xff\xff"
92 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
93 poke_file
"$TEST_IMG" "$offset_refcount_table_clusters" "\x00\x02\x00\x01"
94 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
97 echo "== Misaligned refcount table =="
99 poke_file
"$TEST_IMG" "$offset_refcount_table_offset" "\x12\x34\x56\x78\x90\xab\xcd\xef"
100 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
103 echo "== Huge refcount offset =="
105 poke_file
"$TEST_IMG" "$offset_refcount_table_offset" "\xff\xff\xff\xff\xff\xff\x00\x00"
106 poke_file
"$TEST_IMG" "$offset_refcount_table_clusters" "\x00\x00\x00\x7f"
107 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
110 echo "== Invalid snapshot table =="
112 poke_file
"$TEST_IMG" "$offset_nb_snapshots" "\xff\xff\xff\xff"
113 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
114 poke_file
"$TEST_IMG" "$offset_nb_snapshots" "\x7f\xff\xff\xff"
115 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
117 poke_file
"$TEST_IMG" "$offset_snapshots_offset" "\xff\xff\xff\xff\xff\xff\x00\x00"
118 poke_file
"$TEST_IMG" "$offset_nb_snapshots" "\x00\x00\xff\xff"
119 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
121 poke_file
"$TEST_IMG" "$offset_snapshots_offset" "\x12\x34\x56\x78\x90\xab\xcd\xef"
122 poke_file
"$TEST_IMG" "$offset_nb_snapshots" "\x00\x00\x00\x00"
123 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
126 echo "== Hitting snapshot table size limit =="
128 # Put the refcount table in a more or less safe place (16 MB)
129 poke_file
"$TEST_IMG" "$offset_snapshots_offset" "\x00\x00\x00\x00\x01\x00\x00\x00"
130 poke_file
"$TEST_IMG" "$offset_nb_snapshots" "\x00\x01\x00\x00"
131 { $QEMU_IMG snapshot
-c test $TEST_IMG; } 2>&1 | _filter_testdir
132 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
135 echo "== Invalid L1 table =="
137 poke_file
"$TEST_IMG" "$offset_l1_size" "\xff\xff\xff\xff"
138 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
139 poke_file
"$TEST_IMG" "$offset_l1_size" "\x7f\xff\xff\xff"
140 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
142 poke_file
"$TEST_IMG" "$offset_l1_table_offset" "\x7f\xff\xff\xff\xff\xff\x00\x00"
143 poke_file
"$TEST_IMG" "$offset_l1_size" "\x00\x00\xff\xff"
144 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
146 poke_file
"$TEST_IMG" "$offset_l1_table_offset" "\x12\x34\x56\x78\x90\xab\xcd\xef"
147 poke_file
"$TEST_IMG" "$offset_l1_size" "\x00\x00\x00\x01"
148 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
151 echo "== Invalid L1 table (with internal snapshot in the image) =="
153 { $QEMU_IMG snapshot
-c foo
$TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
154 poke_file
"$TEST_IMG" "$offset_l1_size" "\x00\x00\x00\x00"
158 echo "== Invalid backing file size =="
160 poke_file
"$TEST_IMG" "$offset_backing_file_offset" "\x00\x00\x00\x00\x00\x00\x10\x00"
161 poke_file
"$TEST_IMG" "$offset_backing_file_size" "\xff\xff\xff\xff"
162 { $QEMU_IO -c "read 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
165 echo "== Invalid L2 entry (huge physical offset) =="
167 { $QEMU_IO -c "write 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
168 poke_file
"$TEST_IMG" "$offset_l2_table_0" "\xbf\xff\xff\xff\xff\xff\x00\x00"
169 { $QEMU_IMG snapshot
-c test $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
170 poke_file
"$TEST_IMG" "$offset_l2_table_0" "\x80\x00\x00\xff\xff\xff\x00\x00"
171 { $QEMU_IMG snapshot
-c test $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
174 echo "== Invalid snapshot L1 table =="
176 { $QEMU_IO -c "write 0 512" $TEST_IMG; } 2>&1 | _filter_qemu_io | _filter_testdir
177 { $QEMU_IMG snapshot
-c test $TEST_IMG; } 2>&1 | _filter_testdir
178 poke_file
"$TEST_IMG" "$offset_snap1_l1_size" "\x10\x00\x00\x00"
179 { $QEMU_IMG convert
-s test $TEST_IMG $TEST_IMG.snap
; } 2>&1 | _filter_testdir