nbd: Reject unknown request flags

The NBD protocol says that clients should not send a command flag
that has not been negotiated (whether by the client requesting an
option during a handshake, or because we advertise support for the
flag in response to NBD_OPT_EXPORT_NAME), and that servers should
reject invalid flags with EINVAL.  We were silently ignoring the
flags instead.  The client can't rely on our behavior, since it is
their fault for passing the bad flag in the first place, but it's
better to be robust up front than to possibly behave differently
than the client was expecting with the attempted flag.

Signed-off-by: Eric Blake <eblake@redhat.com>
Reviewed-by: Alex Bligh <alex@alex.org.uk>
Message-Id: <1463006384-7734-6-git-send-email-eblake@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
This commit is contained in:
Eric Blake 2016-05-11 16:39:38 -06:00 committed by Paolo Bonzini
parent 29b6c3b319
commit ab7c548e26

View File

@ -1072,6 +1072,11 @@ static ssize_t nbd_co_receive_request(NBDRequest *req,
rc = command == NBD_CMD_WRITE ? -ENOSPC : -EINVAL; rc = command == NBD_CMD_WRITE ? -ENOSPC : -EINVAL;
goto out; goto out;
} }
if (request->type & ~NBD_CMD_MASK_COMMAND & ~NBD_CMD_FLAG_FUA) {
LOG("unsupported flags (got 0x%x)",
request->type & ~NBD_CMD_MASK_COMMAND);
return -EINVAL;
}
rc = 0; rc = 0;