vmm: Improve resiliency of image type handling

Add an image_type to DiskConfig to specify the image type. If none is
specified autodetect the image type but disable potentially unsafe
behaviour in the QCOW2 backend by disabling the backing file support.

If the image type is autodetected then fix it in the config so that it
will be persistant across reboots and migrations/snapshot & restores.
This also handles the case where the image type was not specified as
part of the disk configuration.

Signed-off-by: Rob Bradford <rbradford@meta.com>
(cherry picked from commit 6f2357c14e)
This commit is contained in:
Rob Bradford
2026-02-15 11:25:53 +00:00
committed by Bo Chen
parent 30166a4ea5
commit 5a0b6f2d06
9 changed files with 161 additions and 27 deletions

View File

@@ -41,6 +41,7 @@ vmm-sys-util = { workspace = true }
zbus = { version = "5.7.1", optional = true }
[dev-dependencies]
block = { path = "../block" }
dirs = { workspace = true }
net_util = { path = "../net_util" }
serde_json = { workspace = true }

View File

@@ -1199,14 +1199,14 @@ mod unit_tests {
"--kernel",
"/path/to/kernel",
"--disk",
"path=/path/to/disk/1",
"path=/path/to/disk/1,image_type=raw",
"path=/path/to/disk/2",
],
r#"{
"payload": {"kernel": "/path/to/kernel"},
"disks": [
{"path": "/path/to/disk/1"},
{"path": "/path/to/disk/2"}
{"path": "/path/to/disk/1", "image_type": "Raw"},
{"path": "/path/to/disk/2", "image_type": "Unknown"}
]
}"#,
true,
@@ -1217,8 +1217,8 @@ mod unit_tests {
"--kernel",
"/path/to/kernel",
"--disk",
"path=/path/to/disk/1",
"path=/path/to/disk/2",
"path=/path/to/disk/1,image_type=raw",
"path=/path/to/disk/2,image_type=qcow2",
],
r#"{
"payload": {"kernel": "/path/to/kernel"},
@@ -1280,8 +1280,8 @@ mod unit_tests {
r#"{
"payload": {"kernel": "/path/to/kernel"},
"disks": [
{"path": "/path/to/disk/1", "rate_limit_group": "group0"},
{"path": "/path/to/disk/2", "rate_limit_group": "group0"}
{"path": "/path/to/disk/1", "rate_limit_group": "group0", "image_type": "Unknown"},
{"path": "/path/to/disk/2", "rate_limit_group": "group0", "image_type": "Unknown"}
],
"rate_limit_groups": [
{"id": "group0", "rate_limiter_config": {"bandwidth": {"size": 1000, "one_time_burst": 0, "refill_time": 100}}}

View File

@@ -2526,6 +2526,8 @@ mod common_parallel {
use std::fs::OpenOptions;
use std::io::SeekFrom;
use block::ImageType;
use crate::*;
#[test]
@@ -3172,7 +3174,7 @@ mod common_parallel {
guest.disk_config.disk(DiskType::CloudInit).unwrap()
)
.as_str(),
format!("path={test_disk_path},pci_segment=15").as_str(),
format!("path={test_disk_path},pci_segment=15,image_type=raw").as_str(),
])
.capture_output()
.default_net();
@@ -3413,6 +3415,7 @@ mod common_parallel {
disable_aio: bool,
verify_os_disk: bool,
backing_files: bool,
image_type: ImageType,
) {
let disk_config = UbuntuDiskConfig::new(image_name.to_string());
let guest = Guest::new(Box::new(disk_config));
@@ -3433,9 +3436,9 @@ mod common_parallel {
.args([
"--disk",
format!(
"path={},backing_files={}",
"path={},backing_files={},image_type={image_type}",
guest.disk_config.disk(DiskType::OperatingSystem).unwrap(),
if backing_files { "on"} else {"off"}
if backing_files { "on"} else {"off"},
)
.as_str(),
format!(
@@ -3505,17 +3508,17 @@ mod common_parallel {
#[test]
fn test_virtio_block_io_uring() {
_test_virtio_block(FOCAL_IMAGE_NAME, false, true, false, false);
_test_virtio_block(FOCAL_IMAGE_NAME, false, true, false, false, ImageType::Raw);
}
#[test]
fn test_virtio_block_aio() {
_test_virtio_block(FOCAL_IMAGE_NAME, true, false, false, false);
_test_virtio_block(FOCAL_IMAGE_NAME, true, false, false, false, ImageType::Raw);
}
#[test]
fn test_virtio_block_sync() {
_test_virtio_block(FOCAL_IMAGE_NAME, true, true, false, false);
_test_virtio_block(FOCAL_IMAGE_NAME, true, true, false, false, ImageType::Raw);
}
/// Uses `qemu-img check` to verify disk image consistency.
@@ -3551,17 +3554,38 @@ mod common_parallel {
#[test]
fn test_virtio_block_qcow2() {
_test_virtio_block(JAMMY_IMAGE_NAME_QCOW2, false, false, true, false);
_test_virtio_block(
JAMMY_IMAGE_NAME_QCOW2,
false,
false,
true,
false,
ImageType::Qcow2,
);
}
#[test]
fn test_virtio_block_qcow2_zlib() {
_test_virtio_block(JAMMY_IMAGE_NAME_QCOW2_ZLIB, false, false, true, false);
_test_virtio_block(
JAMMY_IMAGE_NAME_QCOW2_ZLIB,
false,
false,
true,
false,
ImageType::Qcow2,
);
}
#[test]
fn test_virtio_block_qcow2_zstd() {
_test_virtio_block(JAMMY_IMAGE_NAME_QCOW2_ZSTD, false, false, true, false);
_test_virtio_block(
JAMMY_IMAGE_NAME_QCOW2_ZSTD,
false,
false,
true,
false,
ImageType::Qcow2,
);
}
#[test]
@@ -3572,6 +3596,7 @@ mod common_parallel {
false,
true,
true,
ImageType::Qcow2,
);
}
@@ -3583,6 +3608,7 @@ mod common_parallel {
false,
true,
true,
ImageType::Qcow2,
);
}
@@ -3608,7 +3634,14 @@ mod common_parallel {
.output()
.expect("Expect generating VHD image from RAW image");
_test_virtio_block(FOCAL_IMAGE_NAME_VHD, false, false, false, false);
_test_virtio_block(
FOCAL_IMAGE_NAME_VHD,
false,
false,
false,
false,
ImageType::FixedVhd,
);
}
#[test]
@@ -3632,7 +3665,14 @@ mod common_parallel {
.output()
.expect("Expect generating dynamic VHDx image from RAW image");
_test_virtio_block(FOCAL_IMAGE_NAME_VHDX, false, false, true, false);
_test_virtio_block(
FOCAL_IMAGE_NAME_VHDX,
false,
false,
true,
false,
ImageType::Vhdx,
);
}
#[test]
@@ -4697,7 +4737,7 @@ mod common_parallel {
guest.disk_config.disk(DiskType::CloudInit).unwrap()
)
.as_str(),
format!("path={}", vfio_disk_path.to_str().unwrap()).as_str(),
format!("path={},image_type=raw", vfio_disk_path.to_str().unwrap()).as_str(),
format!("path={},iommu=on,readonly=true", blk_file_path.to_str().unwrap()).as_str(),
])
.args([