raw_co_prw() replaces the offset of a zone append with the write pointer
of the addressed zone, which assumes that the stored value names a
position inside that zone. It does not in two cases.
A full zone has its write pointer recorded at the end of the zone, since
get_zones_wp() stores start + len for BLK_ZONE_COND_FULL. That is the
first sector of the following zone, so the append is submitted there. The
kernel accepts it whenever that zone is empty, because it is a legal
write at its write pointer, and the completion path advances the wrong
zone because it recomputes the zone index from the replaced offset. The
data is written to a zone that was never addressed and success is
returned:
zone 2 finished, then a 4 KiB append to zone 2:
After zap done, the append sector is 0x180000 <- zone 3
zone 2: wptr 0x180000, zcond:14 (full)
zone 3: wptr 0x180008 <- advanced
A conventional zone has no write pointer at all, and its array entry
carries only the type marker in the top bit, so the offset becomes
negative and the write fails with EINVAL. That is harmless but it reports
nothing about the actual mistake.
Reject both while the write pointer lock is held, since the state has to
be read and acted on atomically. check_zoned_request() in virtio-blk
refuses an append to a conventional zone, so that case needs a caller
that goes to the driver directly, but nothing there examines whether a
zone is full, so a guest can reach the misdirected write.
Fixes: 4751d09adcc3 ("block: introduce zone append write for zoned devices")
Reviewed-by: Damien Le Moal <[email protected]>
Reviewed-by: Stefan Hajnoczi <[email protected]>
Signed-off-by: Niklas Cassel <[email protected]>
---
block/file-posix.c | 23 ++++++++++++++++++++++-
block/io.c | 9 +++++++++
include/block/block-io.h | 6 ++++++
3 files changed, 37 insertions(+), 1 deletion(-)
diff --git a/block/file-posix.c b/block/file-posix.c
index e1e6a03b25..cd3c9f0fd0 100644
--- a/block/file-posix.c
+++ b/block/file-posix.c
@@ -2555,7 +2555,28 @@ raw_co_prw(BlockDriverState *bs, int64_t *offset_ptr,
uint64_t bytes,
bs->bl.zoned != BLK_Z_NONE) {
qemu_co_mutex_lock(&bs->wps->colock);
if (type & QEMU_AIO_ZONE_APPEND) {
- int index = bdrv_zone_index(bs, offset);
+ uint32_t index = bdrv_zone_index(bs, offset);
+
+ /*
+ * The write pointer of the addressed zone becomes the offset of
+ * the write, so it has to name a position inside that zone. A
+ * conventional zone has no write pointer, and the pointer of a
+ * full zone is reported at the end of the zone. Either would send
+ * the data to a zone that was never addressed.
+ */
+ if (bdrv_zone_is_conv(bs, index)) {
+ error_report("zone append at offset 0x%" PRIx64 " addresses a "
+ "conventional zone", offset);
+ qemu_co_mutex_unlock(&bs->wps->colock);
+ return -EINVAL;
+ }
+ if (bdrv_zone_is_full(bs, index)) {
+ error_report("zone append at offset 0x%" PRIx64 " addresses a "
+ "full zone", offset);
+ qemu_co_mutex_unlock(&bs->wps->colock);
+ return -ENOSPC;
+ }
+
offset = bs->wps->wp[index];
}
}
diff --git a/block/io.c b/block/io.c
index d7c403bc08..a4fb56f799 100644
--- a/block/io.c
+++ b/block/io.c
@@ -3402,6 +3402,15 @@ bool bdrv_zone_is_conv(BlockDriverState *bs, uint32_t
index)
return BDRV_ZT_IS_CONV(bs->wps->wp[index]);
}
+bool bdrv_zone_is_full(BlockDriverState *bs, uint32_t index)
+{
+ uint64_t zone_end = MIN((uint64_t)(index + 1) * bs->bl.zone_size,
+ (uint64_t)bs->total_sectors << BDRV_SECTOR_BITS);
+ IO_CODE();
+
+ return bs->wps->wp[index] >= zone_end;
+}
+
void *qemu_blockalign(BlockDriverState *bs, size_t size)
{
IO_CODE();
diff --git a/include/block/block-io.h b/include/block/block-io.h
index e469df7061..f671476f08 100644
--- a/include/block/block-io.h
+++ b/include/block/block-io.h
@@ -134,6 +134,12 @@ uint32_t bdrv_zone_index(BlockDriverState *bs, uint64_t
offset);
* bdrv_zone_is_full() this does not need the write pointer lock.
*/
bool bdrv_zone_is_conv(BlockDriverState *bs, uint32_t index);
+/*
+ * True when the write pointer of a zone has reached the end of the writable
+ * part of that zone, so that nothing more can be written to it until it is
+ * reset. The write pointer lock must be held when called.
+ */
+bool bdrv_zone_is_full(BlockDriverState *bs, uint32_t index);
bool bdrv_can_write_zeroes_with_unmap(BlockDriverState *bs);
--
2.55.0