[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[PULL 3/6] 9pfs: validate count sent by client with T_readdir
From: |
Greg Kurz |
Subject: |
[PULL 3/6] 9pfs: validate count sent by client with T_readdir |
Date: |
Sat, 8 Feb 2020 11:45:03 +0100 |
From: Christian Schoenebeck <address@hidden>
A good 9p client sends T_readdir with "count" parameter that's sufficiently
smaller than client's initially negotiated msize (maximum message size).
We perform a check for that though to avoid the server to be interrupted
with a "Failed to encode VirtFS reply type 41" transport error message by
bad clients. This count value constraint uses msize - 11, because 11 is the
header size of R_readdir.
Signed-off-by: Christian Schoenebeck <address@hidden>
Reviewed-by: Greg Kurz <address@hidden>
Message-Id: <address@hidden>
[groug: added comment ]
Signed-off-by: Greg Kurz <address@hidden>
---
hw/9pfs/9p.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c
index c63f549f39b2..9e046f7acb51 100644
--- a/hw/9pfs/9p.c
+++ b/hw/9pfs/9p.c
@@ -2434,6 +2434,7 @@ static void coroutine_fn v9fs_readdir(void *opaque)
int32_t count;
uint32_t max_count;
V9fsPDU *pdu = opaque;
+ V9fsState *s = pdu->s;
retval = pdu_unmarshal(pdu, offset, "dqd", &fid,
&initial_offset, &max_count);
@@ -2442,6 +2443,14 @@ static void coroutine_fn v9fs_readdir(void *opaque)
}
trace_v9fs_readdir(pdu->tag, pdu->id, fid, initial_offset, max_count);
+ /* Enough space for a R_readdir header: size[4] Rreaddir tag[2] count[4] */
+ if (max_count > s->msize - 11) {
+ max_count = s->msize - 11;
+ warn_report_once(
+ "9p: bad client: T_readdir with count > msize - 11"
+ );
+ }
+
fidp = get_fid(pdu, fid);
if (fidp == NULL) {
retval = -EINVAL;
--
2.21.1
- [PULL 0/6] 9p patches 2020-02-08, Greg Kurz, 2020/02/08
- [PULL 2/6] 9pfs: require msize >= 4096, Greg Kurz, 2020/02/08
- [PULL 1/6] tests/virtio-9p: add terminating null in v9fs_string_read(), Greg Kurz, 2020/02/08
- [PULL 4/6] hw/9pfs/9p-synth: added directory for readdir test, Greg Kurz, 2020/02/08
- [PULL 6/6] MAINTAINERS: 9pfs: Add myself as reviewer, Greg Kurz, 2020/02/08
- [PULL 5/6] tests/virtio-9p: added readdir test, Greg Kurz, 2020/02/08
- [PULL 3/6] 9pfs: validate count sent by client with T_readdir,
Greg Kurz <=
- Re: [PULL 0/6] 9p patches 2020-02-08, Peter Maydell, 2020/02/10