slirp: check data length while emulating ident function
[qemu/ar7.git] / block / raw-format.c
blob6f6dc99b2ceb74540ce7f1064e082ee889c5670d
1 /* BlockDriver implementation for "raw" format driver
3 * Copyright (C) 2010-2016 Red Hat, Inc.
4 * Copyright (C) 2010, Blue Swirl <blauwirbel@gmail.com>
5 * Copyright (C) 2009, Anthony Liguori <aliguori@us.ibm.com>
7 * Author:
8 * Laszlo Ersek <lersek@redhat.com>
10 * Permission is hereby granted, free of charge, to any person obtaining a copy
11 * of this software and associated documentation files (the "Software"), to
12 * deal in the Software without restriction, including without limitation the
13 * rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
14 * sell copies of the Software, and to permit persons to whom the Software is
15 * furnished to do so, subject to the following conditions:
17 * The above copyright notice and this permission notice shall be included in
18 * all copies or substantial portions of the Software.
20 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
21 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
23 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
24 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
25 * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
26 * IN THE SOFTWARE.
29 #include "qemu/osdep.h"
30 #include "block/block_int.h"
31 #include "qapi/error.h"
32 #include "qemu/option.h"
34 typedef struct BDRVRawState {
35 uint64_t offset;
36 uint64_t size;
37 bool has_size;
38 } BDRVRawState;
40 static QemuOptsList raw_runtime_opts = {
41 .name = "raw",
42 .head = QTAILQ_HEAD_INITIALIZER(raw_runtime_opts.head),
43 .desc = {
45 .name = "offset",
46 .type = QEMU_OPT_SIZE,
47 .help = "offset in the disk where the image starts",
50 .name = "size",
51 .type = QEMU_OPT_SIZE,
52 .help = "virtual disk size",
54 { /* end of list */ }
58 static QemuOptsList raw_create_opts = {
59 .name = "raw-create-opts",
60 .head = QTAILQ_HEAD_INITIALIZER(raw_create_opts.head),
61 .desc = {
63 .name = BLOCK_OPT_SIZE,
64 .type = QEMU_OPT_SIZE,
65 .help = "Virtual disk size"
67 { /* end of list */ }
71 static int raw_read_options(QDict *options, BlockDriverState *bs,
72 BDRVRawState *s, Error **errp)
74 Error *local_err = NULL;
75 QemuOpts *opts = NULL;
76 int64_t real_size = 0;
77 int ret;
79 real_size = bdrv_getlength(bs->file->bs);
80 if (real_size < 0) {
81 error_setg_errno(errp, -real_size, "Could not get image size");
82 return real_size;
85 opts = qemu_opts_create(&raw_runtime_opts, NULL, 0, &error_abort);
86 qemu_opts_absorb_qdict(opts, options, &local_err);
87 if (local_err) {
88 error_propagate(errp, local_err);
89 ret = -EINVAL;
90 goto end;
93 s->offset = qemu_opt_get_size(opts, "offset", 0);
94 if (s->offset > real_size) {
95 error_setg(errp, "Offset (%" PRIu64 ") cannot be greater than "
96 "size of the containing file (%" PRId64 ")",
97 s->offset, real_size);
98 ret = -EINVAL;
99 goto end;
102 if (qemu_opt_find(opts, "size") != NULL) {
103 s->size = qemu_opt_get_size(opts, "size", 0);
104 s->has_size = true;
105 } else {
106 s->has_size = false;
107 s->size = real_size - s->offset;
110 /* Check size and offset */
111 if ((real_size - s->offset) < s->size) {
112 error_setg(errp, "The sum of offset (%" PRIu64 ") and size "
113 "(%" PRIu64 ") has to be smaller or equal to the "
114 " actual size of the containing file (%" PRId64 ")",
115 s->offset, s->size, real_size);
116 ret = -EINVAL;
117 goto end;
120 /* Make sure size is multiple of BDRV_SECTOR_SIZE to prevent rounding
121 * up and leaking out of the specified area. */
122 if (s->has_size && !QEMU_IS_ALIGNED(s->size, BDRV_SECTOR_SIZE)) {
123 error_setg(errp, "Specified size is not multiple of %llu",
124 BDRV_SECTOR_SIZE);
125 ret = -EINVAL;
126 goto end;
129 ret = 0;
131 end:
133 qemu_opts_del(opts);
135 return ret;
138 static int raw_reopen_prepare(BDRVReopenState *reopen_state,
139 BlockReopenQueue *queue, Error **errp)
141 assert(reopen_state != NULL);
142 assert(reopen_state->bs != NULL);
144 reopen_state->opaque = g_new0(BDRVRawState, 1);
146 return raw_read_options(
147 reopen_state->options,
148 reopen_state->bs,
149 reopen_state->opaque,
150 errp);
153 static void raw_reopen_commit(BDRVReopenState *state)
155 BDRVRawState *new_s = state->opaque;
156 BDRVRawState *s = state->bs->opaque;
158 memcpy(s, new_s, sizeof(BDRVRawState));
160 g_free(state->opaque);
161 state->opaque = NULL;
164 static void raw_reopen_abort(BDRVReopenState *state)
166 g_free(state->opaque);
167 state->opaque = NULL;
170 /* Check and adjust the offset, against 'offset' and 'size' options. */
171 static inline int raw_adjust_offset(BlockDriverState *bs, uint64_t *offset,
172 uint64_t bytes, bool is_write)
174 BDRVRawState *s = bs->opaque;
176 if (s->has_size && (*offset > s->size || bytes > (s->size - *offset))) {
177 /* There's not enough space for the write, or the read request is
178 * out-of-range. Don't read/write anything to prevent leaking out of
179 * the size specified in options. */
180 return is_write ? -ENOSPC : -EINVAL;
183 if (*offset > INT64_MAX - s->offset) {
184 return -EINVAL;
186 *offset += s->offset;
188 return 0;
191 static int coroutine_fn raw_co_preadv(BlockDriverState *bs, uint64_t offset,
192 uint64_t bytes, QEMUIOVector *qiov,
193 int flags)
195 int ret;
197 ret = raw_adjust_offset(bs, &offset, bytes, false);
198 if (ret) {
199 return ret;
202 BLKDBG_EVENT(bs->file, BLKDBG_READ_AIO);
203 return bdrv_co_preadv(bs->file, offset, bytes, qiov, flags);
206 static int coroutine_fn raw_co_pwritev(BlockDriverState *bs, uint64_t offset,
207 uint64_t bytes, QEMUIOVector *qiov,
208 int flags)
210 void *buf = NULL;
211 BlockDriver *drv;
212 QEMUIOVector local_qiov;
213 int ret;
215 if (bs->probed && offset < BLOCK_PROBE_BUF_SIZE && bytes) {
216 /* Handling partial writes would be a pain - so we just
217 * require that guests have 512-byte request alignment if
218 * probing occurred */
219 QEMU_BUILD_BUG_ON(BLOCK_PROBE_BUF_SIZE != 512);
220 QEMU_BUILD_BUG_ON(BDRV_SECTOR_SIZE != 512);
221 assert(offset == 0 && bytes >= BLOCK_PROBE_BUF_SIZE);
223 buf = qemu_try_blockalign(bs->file->bs, 512);
224 if (!buf) {
225 ret = -ENOMEM;
226 goto fail;
229 ret = qemu_iovec_to_buf(qiov, 0, buf, 512);
230 if (ret != 512) {
231 ret = -EINVAL;
232 goto fail;
235 drv = bdrv_probe_all(buf, 512, NULL);
236 if (drv != bs->drv) {
237 ret = -EPERM;
238 goto fail;
241 /* Use the checked buffer, a malicious guest might be overwriting its
242 * original buffer in the background. */
243 qemu_iovec_init(&local_qiov, qiov->niov + 1);
244 qemu_iovec_add(&local_qiov, buf, 512);
245 qemu_iovec_concat(&local_qiov, qiov, 512, qiov->size - 512);
246 qiov = &local_qiov;
249 ret = raw_adjust_offset(bs, &offset, bytes, true);
250 if (ret) {
251 goto fail;
254 BLKDBG_EVENT(bs->file, BLKDBG_WRITE_AIO);
255 ret = bdrv_co_pwritev(bs->file, offset, bytes, qiov, flags);
257 fail:
258 if (qiov == &local_qiov) {
259 qemu_iovec_destroy(&local_qiov);
261 qemu_vfree(buf);
262 return ret;
265 static int coroutine_fn raw_co_block_status(BlockDriverState *bs,
266 bool want_zero, int64_t offset,
267 int64_t bytes, int64_t *pnum,
268 int64_t *map,
269 BlockDriverState **file)
271 BDRVRawState *s = bs->opaque;
272 *pnum = bytes;
273 *file = bs->file->bs;
274 *map = offset + s->offset;
275 return BDRV_BLOCK_RAW | BDRV_BLOCK_OFFSET_VALID;
278 static int coroutine_fn raw_co_pwrite_zeroes(BlockDriverState *bs,
279 int64_t offset, int bytes,
280 BdrvRequestFlags flags)
282 int ret;
284 ret = raw_adjust_offset(bs, (uint64_t *)&offset, bytes, true);
285 if (ret) {
286 return ret;
288 return bdrv_co_pwrite_zeroes(bs->file, offset, bytes, flags);
291 static int coroutine_fn raw_co_pdiscard(BlockDriverState *bs,
292 int64_t offset, int bytes)
294 int ret;
296 ret = raw_adjust_offset(bs, (uint64_t *)&offset, bytes, true);
297 if (ret) {
298 return ret;
300 return bdrv_co_pdiscard(bs->file, offset, bytes);
303 static int64_t raw_getlength(BlockDriverState *bs)
305 int64_t len;
306 BDRVRawState *s = bs->opaque;
308 /* Update size. It should not change unless the file was externally
309 * modified. */
310 len = bdrv_getlength(bs->file->bs);
311 if (len < 0) {
312 return len;
315 if (len < s->offset) {
316 s->size = 0;
317 } else {
318 if (s->has_size) {
319 /* Try to honour the size */
320 s->size = MIN(s->size, len - s->offset);
321 } else {
322 s->size = len - s->offset;
326 return s->size;
329 static BlockMeasureInfo *raw_measure(QemuOpts *opts, BlockDriverState *in_bs,
330 Error **errp)
332 BlockMeasureInfo *info;
333 int64_t required;
335 if (in_bs) {
336 required = bdrv_getlength(in_bs);
337 if (required < 0) {
338 error_setg_errno(errp, -required, "Unable to get image size");
339 return NULL;
341 } else {
342 required = ROUND_UP(qemu_opt_get_size_del(opts, BLOCK_OPT_SIZE, 0),
343 BDRV_SECTOR_SIZE);
346 info = g_new(BlockMeasureInfo, 1);
347 info->required = required;
349 /* Unallocated sectors count towards the file size in raw images */
350 info->fully_allocated = info->required;
351 return info;
354 static int raw_get_info(BlockDriverState *bs, BlockDriverInfo *bdi)
356 return bdrv_get_info(bs->file->bs, bdi);
359 static void raw_refresh_limits(BlockDriverState *bs, Error **errp)
361 if (bs->probed) {
362 /* To make it easier to protect the first sector, any probed
363 * image is restricted to read-modify-write on sub-sector
364 * operations. */
365 bs->bl.request_alignment = BDRV_SECTOR_SIZE;
369 static int coroutine_fn raw_co_truncate(BlockDriverState *bs, int64_t offset,
370 PreallocMode prealloc, Error **errp)
372 BDRVRawState *s = bs->opaque;
374 if (s->has_size) {
375 error_setg(errp, "Cannot resize fixed-size raw disks");
376 return -ENOTSUP;
379 if (INT64_MAX - offset < s->offset) {
380 error_setg(errp, "Disk size too large for the chosen offset");
381 return -EINVAL;
384 s->size = offset;
385 offset += s->offset;
386 return bdrv_co_truncate(bs->file, offset, prealloc, errp);
389 static void raw_eject(BlockDriverState *bs, bool eject_flag)
391 bdrv_eject(bs->file->bs, eject_flag);
394 static void raw_lock_medium(BlockDriverState *bs, bool locked)
396 bdrv_lock_medium(bs->file->bs, locked);
399 static int raw_co_ioctl(BlockDriverState *bs, unsigned long int req, void *buf)
401 BDRVRawState *s = bs->opaque;
402 if (s->offset || s->has_size) {
403 return -ENOTSUP;
405 return bdrv_co_ioctl(bs->file->bs, req, buf);
408 static int raw_has_zero_init(BlockDriverState *bs)
410 return bdrv_has_zero_init(bs->file->bs);
413 static int coroutine_fn raw_co_create_opts(const char *filename, QemuOpts *opts,
414 Error **errp)
416 return bdrv_create_file(filename, opts, errp);
419 static int raw_open(BlockDriverState *bs, QDict *options, int flags,
420 Error **errp)
422 BDRVRawState *s = bs->opaque;
423 int ret;
425 bs->file = bdrv_open_child(NULL, options, "file", bs, &child_file,
426 false, errp);
427 if (!bs->file) {
428 return -EINVAL;
431 bs->sg = bs->file->bs->sg;
432 bs->supported_write_flags = BDRV_REQ_WRITE_UNCHANGED |
433 (BDRV_REQ_FUA & bs->file->bs->supported_write_flags);
434 bs->supported_zero_flags = BDRV_REQ_WRITE_UNCHANGED |
435 ((BDRV_REQ_FUA | BDRV_REQ_MAY_UNMAP) &
436 bs->file->bs->supported_zero_flags);
438 if (bs->probed && !bdrv_is_read_only(bs)) {
439 fprintf(stderr,
440 "WARNING: Image format was not specified for '%s' and probing "
441 "guessed raw.\n"
442 " Automatically detecting the format is dangerous for "
443 "raw images, write operations on block 0 will be restricted.\n"
444 " Specify the 'raw' format explicitly to remove the "
445 "restrictions.\n",
446 bs->file->bs->filename);
449 ret = raw_read_options(options, bs, s, errp);
450 if (ret < 0) {
451 return ret;
454 if (bs->sg && (s->offset || s->has_size)) {
455 error_setg(errp, "Cannot use offset/size with SCSI generic devices");
456 return -EINVAL;
459 return 0;
462 static int raw_probe(const uint8_t *buf, int buf_size, const char *filename)
464 /* smallest possible positive score so that raw is used if and only if no
465 * other block driver works
467 return 1;
470 static int raw_probe_blocksizes(BlockDriverState *bs, BlockSizes *bsz)
472 BDRVRawState *s = bs->opaque;
473 int ret;
475 ret = bdrv_probe_blocksizes(bs->file->bs, bsz);
476 if (ret < 0) {
477 return ret;
480 if (!QEMU_IS_ALIGNED(s->offset, MAX(bsz->log, bsz->phys))) {
481 return -ENOTSUP;
484 return 0;
487 static int raw_probe_geometry(BlockDriverState *bs, HDGeometry *geo)
489 BDRVRawState *s = bs->opaque;
490 if (s->offset || s->has_size) {
491 return -ENOTSUP;
493 return bdrv_probe_geometry(bs->file->bs, geo);
496 static int coroutine_fn raw_co_copy_range_from(BlockDriverState *bs,
497 BdrvChild *src,
498 uint64_t src_offset,
499 BdrvChild *dst,
500 uint64_t dst_offset,
501 uint64_t bytes,
502 BdrvRequestFlags read_flags,
503 BdrvRequestFlags write_flags)
505 int ret;
507 ret = raw_adjust_offset(bs, &src_offset, bytes, false);
508 if (ret) {
509 return ret;
511 return bdrv_co_copy_range_from(bs->file, src_offset, dst, dst_offset,
512 bytes, read_flags, write_flags);
515 static int coroutine_fn raw_co_copy_range_to(BlockDriverState *bs,
516 BdrvChild *src,
517 uint64_t src_offset,
518 BdrvChild *dst,
519 uint64_t dst_offset,
520 uint64_t bytes,
521 BdrvRequestFlags read_flags,
522 BdrvRequestFlags write_flags)
524 int ret;
526 ret = raw_adjust_offset(bs, &dst_offset, bytes, true);
527 if (ret) {
528 return ret;
530 return bdrv_co_copy_range_to(src, src_offset, bs->file, dst_offset, bytes,
531 read_flags, write_flags);
534 BlockDriver bdrv_raw = {
535 .format_name = "raw",
536 .instance_size = sizeof(BDRVRawState),
537 .bdrv_probe = &raw_probe,
538 .bdrv_reopen_prepare = &raw_reopen_prepare,
539 .bdrv_reopen_commit = &raw_reopen_commit,
540 .bdrv_reopen_abort = &raw_reopen_abort,
541 .bdrv_open = &raw_open,
542 .bdrv_child_perm = bdrv_filter_default_perms,
543 .bdrv_co_create_opts = &raw_co_create_opts,
544 .bdrv_co_preadv = &raw_co_preadv,
545 .bdrv_co_pwritev = &raw_co_pwritev,
546 .bdrv_co_pwrite_zeroes = &raw_co_pwrite_zeroes,
547 .bdrv_co_pdiscard = &raw_co_pdiscard,
548 .bdrv_co_block_status = &raw_co_block_status,
549 .bdrv_co_copy_range_from = &raw_co_copy_range_from,
550 .bdrv_co_copy_range_to = &raw_co_copy_range_to,
551 .bdrv_co_truncate = &raw_co_truncate,
552 .bdrv_getlength = &raw_getlength,
553 .has_variable_length = true,
554 .bdrv_measure = &raw_measure,
555 .bdrv_get_info = &raw_get_info,
556 .bdrv_refresh_limits = &raw_refresh_limits,
557 .bdrv_probe_blocksizes = &raw_probe_blocksizes,
558 .bdrv_probe_geometry = &raw_probe_geometry,
559 .bdrv_eject = &raw_eject,
560 .bdrv_lock_medium = &raw_lock_medium,
561 .bdrv_co_ioctl = &raw_co_ioctl,
562 .create_opts = &raw_create_opts,
563 .bdrv_has_zero_init = &raw_has_zero_init
566 static void bdrv_raw_init(void)
568 bdrv_register(&bdrv_raw);
571 block_init(bdrv_raw_init);