1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24#include "qemu/osdep.h"
25#include "qapi/error.h"
26#include "qemu-common.h"
27#include "block/block_int.h"
28#include "qemu/bswap.h"
29#include "qemu/error-report.h"
30#include "qemu/module.h"
31#include <zlib.h>
32#ifdef CONFIG_BZIP2
33#include <bzlib.h>
34#endif
35#include <glib.h>
36
37enum {
38
39
40
41 DMG_LENGTHS_MAX = 64 * 1024 * 1024,
42 DMG_SECTORCOUNTS_MAX = DMG_LENGTHS_MAX / 512,
43};
44
45typedef struct BDRVDMGState {
46 CoMutex lock;
47
48
49
50
51
52
53
54
55 uint32_t n_chunks;
56 uint32_t* types;
57 uint64_t* offsets;
58 uint64_t* lengths;
59 uint64_t* sectors;
60 uint64_t* sectorcounts;
61 uint32_t current_chunk;
62 uint8_t *compressed_chunk;
63 uint8_t *uncompressed_chunk;
64 z_stream zstream;
65#ifdef CONFIG_BZIP2
66 bz_stream bzstream;
67#endif
68} BDRVDMGState;
69
70static int dmg_probe(const uint8_t *buf, int buf_size, const char *filename)
71{
72 int len;
73
74 if (!filename) {
75 return 0;
76 }
77
78 len = strlen(filename);
79 if (len > 4 && !strcmp(filename + len - 4, ".dmg")) {
80 return 2;
81 }
82 return 0;
83}
84
85static int read_uint64(BlockDriverState *bs, int64_t offset, uint64_t *result)
86{
87 uint64_t buffer;
88 int ret;
89
90 ret = bdrv_pread(bs->file->bs, offset, &buffer, 8);
91 if (ret < 0) {
92 return ret;
93 }
94
95 *result = be64_to_cpu(buffer);
96 return 0;
97}
98
99static int read_uint32(BlockDriverState *bs, int64_t offset, uint32_t *result)
100{
101 uint32_t buffer;
102 int ret;
103
104 ret = bdrv_pread(bs->file->bs, offset, &buffer, 4);
105 if (ret < 0) {
106 return ret;
107 }
108
109 *result = be32_to_cpu(buffer);
110 return 0;
111}
112
113static inline uint64_t buff_read_uint64(const uint8_t *buffer, int64_t offset)
114{
115 return be64_to_cpu(*(uint64_t *)&buffer[offset]);
116}
117
118static inline uint32_t buff_read_uint32(const uint8_t *buffer, int64_t offset)
119{
120 return be32_to_cpu(*(uint32_t *)&buffer[offset]);
121}
122
123
124
125
126static void update_max_chunk_size(BDRVDMGState *s, uint32_t chunk,
127 uint32_t *max_compressed_size,
128 uint32_t *max_sectors_per_chunk)
129{
130 uint32_t compressed_size = 0;
131 uint32_t uncompressed_sectors = 0;
132
133 switch (s->types[chunk]) {
134 case 0x80000005:
135 case 0x80000006:
136 compressed_size = s->lengths[chunk];
137 uncompressed_sectors = s->sectorcounts[chunk];
138 break;
139 case 1:
140 uncompressed_sectors = (s->lengths[chunk] + 511) / 512;
141 break;
142 case 2:
143
144
145
146 break;
147 }
148
149 if (compressed_size > *max_compressed_size) {
150 *max_compressed_size = compressed_size;
151 }
152 if (uncompressed_sectors > *max_sectors_per_chunk) {
153 *max_sectors_per_chunk = uncompressed_sectors;
154 }
155}
156
157static int64_t dmg_find_koly_offset(BlockDriverState *file_bs, Error **errp)
158{
159 int64_t length;
160 int64_t offset = 0;
161 uint8_t buffer[515];
162 int i, ret;
163
164
165
166
167
168
169 length = bdrv_getlength(file_bs);
170 if (length < 0) {
171 error_setg_errno(errp, -length,
172 "Failed to get file size while reading UDIF trailer");
173 return length;
174 } else if (length < 512) {
175 error_setg(errp, "dmg file must be at least 512 bytes long");
176 return -EINVAL;
177 }
178 if (length > 511 + 512) {
179 offset = length - 511 - 512;
180 }
181 length = length < 515 ? length : 515;
182 ret = bdrv_pread(file_bs, offset, buffer, length);
183 if (ret < 0) {
184 error_setg_errno(errp, -ret, "Failed while reading UDIF trailer");
185 return ret;
186 }
187 for (i = 0; i < length - 3; i++) {
188 if (buffer[i] == 'k' && buffer[i+1] == 'o' &&
189 buffer[i+2] == 'l' && buffer[i+3] == 'y') {
190 return offset + i;
191 }
192 }
193 error_setg(errp, "Could not locate UDIF trailer in dmg file");
194 return -EINVAL;
195}
196
197
198typedef struct DmgHeaderState {
199
200
201 uint64_t data_fork_offset;
202
203 uint32_t max_compressed_size;
204 uint32_t max_sectors_per_chunk;
205} DmgHeaderState;
206
207static bool dmg_is_known_block_type(uint32_t entry_type)
208{
209 switch (entry_type) {
210 case 0x00000001:
211 case 0x00000002:
212 case 0x80000005:
213#ifdef CONFIG_BZIP2
214 case 0x80000006:
215#endif
216 return true;
217 default:
218 return false;
219 }
220}
221
222static int dmg_read_mish_block(BDRVDMGState *s, DmgHeaderState *ds,
223 uint8_t *buffer, uint32_t count)
224{
225 uint32_t type, i;
226 int ret;
227 size_t new_size;
228 uint32_t chunk_count;
229 int64_t offset = 0;
230 uint64_t data_offset;
231 uint64_t in_offset = ds->data_fork_offset;
232 uint64_t out_offset;
233
234 type = buff_read_uint32(buffer, offset);
235
236 if (type != 0x6d697368 || count < 244) {
237
238 return 0;
239 }
240
241
242 out_offset = buff_read_uint64(buffer, offset + 8);
243
244
245 data_offset = buff_read_uint64(buffer, offset + 0x18);
246 in_offset += data_offset;
247
248
249 offset += 204;
250
251 chunk_count = (count - 204) / 40;
252 new_size = sizeof(uint64_t) * (s->n_chunks + chunk_count);
253 s->types = g_realloc(s->types, new_size / 2);
254 s->offsets = g_realloc(s->offsets, new_size);
255 s->lengths = g_realloc(s->lengths, new_size);
256 s->sectors = g_realloc(s->sectors, new_size);
257 s->sectorcounts = g_realloc(s->sectorcounts, new_size);
258
259 for (i = s->n_chunks; i < s->n_chunks + chunk_count; i++) {
260 s->types[i] = buff_read_uint32(buffer, offset);
261 if (!dmg_is_known_block_type(s->types[i])) {
262 chunk_count--;
263 i--;
264 offset += 40;
265 continue;
266 }
267
268
269 s->sectors[i] = buff_read_uint64(buffer, offset + 8);
270 s->sectors[i] += out_offset;
271
272
273 s->sectorcounts[i] = buff_read_uint64(buffer, offset + 0x10);
274
275
276
277 if (s->types[i] != 2 && s->sectorcounts[i] > DMG_SECTORCOUNTS_MAX) {
278 error_report("sector count %" PRIu64 " for chunk %" PRIu32
279 " is larger than max (%u)",
280 s->sectorcounts[i], i, DMG_SECTORCOUNTS_MAX);
281 ret = -EINVAL;
282 goto fail;
283 }
284
285
286 s->offsets[i] = buff_read_uint64(buffer, offset + 0x18);
287 s->offsets[i] += in_offset;
288
289
290 s->lengths[i] = buff_read_uint64(buffer, offset + 0x20);
291
292 if (s->lengths[i] > DMG_LENGTHS_MAX) {
293 error_report("length %" PRIu64 " for chunk %" PRIu32
294 " is larger than max (%u)",
295 s->lengths[i], i, DMG_LENGTHS_MAX);
296 ret = -EINVAL;
297 goto fail;
298 }
299
300 update_max_chunk_size(s, i, &ds->max_compressed_size,
301 &ds->max_sectors_per_chunk);
302 offset += 40;
303 }
304 s->n_chunks += chunk_count;
305 return 0;
306
307fail:
308 return ret;
309}
310
311static int dmg_read_resource_fork(BlockDriverState *bs, DmgHeaderState *ds,
312 uint64_t info_begin, uint64_t info_length)
313{
314 BDRVDMGState *s = bs->opaque;
315 int ret;
316 uint32_t count, rsrc_data_offset;
317 uint8_t *buffer = NULL;
318 uint64_t info_end;
319 uint64_t offset;
320
321
322 ret = read_uint32(bs, info_begin, &rsrc_data_offset);
323 if (ret < 0) {
324 goto fail;
325 } else if (rsrc_data_offset > info_length) {
326 ret = -EINVAL;
327 goto fail;
328 }
329
330
331 ret = read_uint32(bs, info_begin + 8, &count);
332 if (ret < 0) {
333 goto fail;
334 } else if (count == 0 || rsrc_data_offset + count > info_length) {
335 ret = -EINVAL;
336 goto fail;
337 }
338
339
340 offset = info_begin + rsrc_data_offset;
341
342
343
344 info_end = offset + count;
345
346
347 while (offset < info_end) {
348
349 ret = read_uint32(bs, offset, &count);
350 if (ret < 0) {
351 goto fail;
352 } else if (count == 0 || count > info_end - offset) {
353 ret = -EINVAL;
354 goto fail;
355 }
356 offset += 4;
357
358 buffer = g_realloc(buffer, count);
359 ret = bdrv_pread(bs->file->bs, offset, buffer, count);
360 if (ret < 0) {
361 goto fail;
362 }
363
364 ret = dmg_read_mish_block(s, ds, buffer, count);
365 if (ret < 0) {
366 goto fail;
367 }
368
369 offset += count;
370 }
371 ret = 0;
372
373fail:
374 g_free(buffer);
375 return ret;
376}
377
378static int dmg_read_plist_xml(BlockDriverState *bs, DmgHeaderState *ds,
379 uint64_t info_begin, uint64_t info_length)
380{
381 BDRVDMGState *s = bs->opaque;
382 int ret;
383 uint8_t *buffer = NULL;
384 char *data_begin, *data_end;
385
386
387
388
389 if (info_length == 0 || info_length > 16 * 1024 * 1024) {
390 ret = -EINVAL;
391 goto fail;
392 }
393
394 buffer = g_malloc(info_length + 1);
395 buffer[info_length] = '\0';
396 ret = bdrv_pread(bs->file->bs, info_begin, buffer, info_length);
397 if (ret != info_length) {
398 ret = -EINVAL;
399 goto fail;
400 }
401
402
403
404
405 data_end = (char *)buffer;
406 while ((data_begin = strstr(data_end, "<data>")) != NULL) {
407 guchar *mish;
408 gsize out_len = 0;
409
410 data_begin += 6;
411 data_end = strstr(data_begin, "</data>");
412
413 if (data_end == NULL) {
414 ret = -EINVAL;
415 goto fail;
416 }
417 *data_end++ = '\0';
418 mish = g_base64_decode(data_begin, &out_len);
419 ret = dmg_read_mish_block(s, ds, mish, (uint32_t)out_len);
420 g_free(mish);
421 if (ret < 0) {
422 goto fail;
423 }
424 }
425 ret = 0;
426
427fail:
428 g_free(buffer);
429 return ret;
430}
431
432static int dmg_open(BlockDriverState *bs, QDict *options, int flags,
433 Error **errp)
434{
435 BDRVDMGState *s = bs->opaque;
436 DmgHeaderState ds;
437 uint64_t rsrc_fork_offset, rsrc_fork_length;
438 uint64_t plist_xml_offset, plist_xml_length;
439 int64_t offset;
440 int ret;
441
442 bs->read_only = 1;
443 s->n_chunks = 0;
444 s->offsets = s->lengths = s->sectors = s->sectorcounts = NULL;
445
446 ds.data_fork_offset = 0;
447 ds.max_compressed_size = 1;
448 ds.max_sectors_per_chunk = 1;
449
450
451 offset = dmg_find_koly_offset(bs->file->bs, errp);
452 if (offset < 0) {
453 ret = offset;
454 goto fail;
455 }
456
457
458 ret = read_uint64(bs, offset + 0x18, &ds.data_fork_offset);
459 if (ret < 0) {
460 goto fail;
461 } else if (ds.data_fork_offset > offset) {
462 ret = -EINVAL;
463 goto fail;
464 }
465
466
467 ret = read_uint64(bs, offset + 0x28, &rsrc_fork_offset);
468 if (ret < 0) {
469 goto fail;
470 }
471 ret = read_uint64(bs, offset + 0x30, &rsrc_fork_length);
472 if (ret < 0) {
473 goto fail;
474 }
475 if (rsrc_fork_offset >= offset ||
476 rsrc_fork_length > offset - rsrc_fork_offset) {
477 ret = -EINVAL;
478 goto fail;
479 }
480
481 ret = read_uint64(bs, offset + 0xd8, &plist_xml_offset);
482 if (ret < 0) {
483 goto fail;
484 }
485 ret = read_uint64(bs, offset + 0xe0, &plist_xml_length);
486 if (ret < 0) {
487 goto fail;
488 }
489 if (plist_xml_offset >= offset ||
490 plist_xml_length > offset - plist_xml_offset) {
491 ret = -EINVAL;
492 goto fail;
493 }
494 ret = read_uint64(bs, offset + 0x1ec, (uint64_t *)&bs->total_sectors);
495 if (ret < 0) {
496 goto fail;
497 }
498 if (bs->total_sectors < 0) {
499 ret = -EINVAL;
500 goto fail;
501 }
502 if (rsrc_fork_length != 0) {
503 ret = dmg_read_resource_fork(bs, &ds,
504 rsrc_fork_offset, rsrc_fork_length);
505 if (ret < 0) {
506 goto fail;
507 }
508 } else if (plist_xml_length != 0) {
509 ret = dmg_read_plist_xml(bs, &ds, plist_xml_offset, plist_xml_length);
510 if (ret < 0) {
511 goto fail;
512 }
513 } else {
514 ret = -EINVAL;
515 goto fail;
516 }
517
518
519 s->compressed_chunk = qemu_try_blockalign(bs->file->bs,
520 ds.max_compressed_size + 1);
521 s->uncompressed_chunk = qemu_try_blockalign(bs->file->bs,
522 512 * ds.max_sectors_per_chunk);
523 if (s->compressed_chunk == NULL || s->uncompressed_chunk == NULL) {
524 ret = -ENOMEM;
525 goto fail;
526 }
527
528 if (inflateInit(&s->zstream) != Z_OK) {
529 ret = -EINVAL;
530 goto fail;
531 }
532
533 s->current_chunk = s->n_chunks;
534
535 qemu_co_mutex_init(&s->lock);
536 return 0;
537
538fail:
539 g_free(s->types);
540 g_free(s->offsets);
541 g_free(s->lengths);
542 g_free(s->sectors);
543 g_free(s->sectorcounts);
544 qemu_vfree(s->compressed_chunk);
545 qemu_vfree(s->uncompressed_chunk);
546 return ret;
547}
548
549static inline int is_sector_in_chunk(BDRVDMGState* s,
550 uint32_t chunk_num, uint64_t sector_num)
551{
552 if (chunk_num >= s->n_chunks || s->sectors[chunk_num] > sector_num ||
553 s->sectors[chunk_num] + s->sectorcounts[chunk_num] <= sector_num) {
554 return 0;
555 } else {
556 return -1;
557 }
558}
559
560static inline uint32_t search_chunk(BDRVDMGState *s, uint64_t sector_num)
561{
562
563 uint32_t chunk1 = 0, chunk2 = s->n_chunks, chunk3;
564 while (chunk1 != chunk2) {
565 chunk3 = (chunk1 + chunk2) / 2;
566 if (s->sectors[chunk3] > sector_num) {
567 chunk2 = chunk3;
568 } else if (s->sectors[chunk3] + s->sectorcounts[chunk3] > sector_num) {
569 return chunk3;
570 } else {
571 chunk1 = chunk3;
572 }
573 }
574 return s->n_chunks;
575}
576
577static inline int dmg_read_chunk(BlockDriverState *bs, uint64_t sector_num)
578{
579 BDRVDMGState *s = bs->opaque;
580
581 if (!is_sector_in_chunk(s, s->current_chunk, sector_num)) {
582 int ret;
583 uint32_t chunk = search_chunk(s, sector_num);
584#ifdef CONFIG_BZIP2
585 uint64_t total_out;
586#endif
587
588 if (chunk >= s->n_chunks) {
589 return -1;
590 }
591
592 s->current_chunk = s->n_chunks;
593 switch (s->types[chunk]) {
594 case 0x80000005: {
595
596
597 ret = bdrv_pread(bs->file->bs, s->offsets[chunk],
598 s->compressed_chunk, s->lengths[chunk]);
599 if (ret != s->lengths[chunk]) {
600 return -1;
601 }
602
603 s->zstream.next_in = s->compressed_chunk;
604 s->zstream.avail_in = s->lengths[chunk];
605 s->zstream.next_out = s->uncompressed_chunk;
606 s->zstream.avail_out = 512 * s->sectorcounts[chunk];
607 ret = inflateReset(&s->zstream);
608 if (ret != Z_OK) {
609 return -1;
610 }
611 ret = inflate(&s->zstream, Z_FINISH);
612 if (ret != Z_STREAM_END ||
613 s->zstream.total_out != 512 * s->sectorcounts[chunk]) {
614 return -1;
615 }
616 break; }
617#ifdef CONFIG_BZIP2
618 case 0x80000006:
619
620
621 ret = bdrv_pread(bs->file->bs, s->offsets[chunk],
622 s->compressed_chunk, s->lengths[chunk]);
623 if (ret != s->lengths[chunk]) {
624 return -1;
625 }
626
627 ret = BZ2_bzDecompressInit(&s->bzstream, 0, 0);
628 if (ret != BZ_OK) {
629 return -1;
630 }
631 s->bzstream.next_in = (char *)s->compressed_chunk;
632 s->bzstream.avail_in = (unsigned int) s->lengths[chunk];
633 s->bzstream.next_out = (char *)s->uncompressed_chunk;
634 s->bzstream.avail_out = (unsigned int) 512 * s->sectorcounts[chunk];
635 ret = BZ2_bzDecompress(&s->bzstream);
636 total_out = ((uint64_t)s->bzstream.total_out_hi32 << 32) +
637 s->bzstream.total_out_lo32;
638 BZ2_bzDecompressEnd(&s->bzstream);
639 if (ret != BZ_STREAM_END ||
640 total_out != 512 * s->sectorcounts[chunk]) {
641 return -1;
642 }
643 break;
644#endif
645 case 1:
646 ret = bdrv_pread(bs->file->bs, s->offsets[chunk],
647 s->uncompressed_chunk, s->lengths[chunk]);
648 if (ret != s->lengths[chunk]) {
649 return -1;
650 }
651 break;
652 case 2:
653
654
655 break;
656 }
657 s->current_chunk = chunk;
658 }
659 return 0;
660}
661
662static int dmg_read(BlockDriverState *bs, int64_t sector_num,
663 uint8_t *buf, int nb_sectors)
664{
665 BDRVDMGState *s = bs->opaque;
666 int i;
667
668 for (i = 0; i < nb_sectors; i++) {
669 uint32_t sector_offset_in_chunk;
670 if (dmg_read_chunk(bs, sector_num + i) != 0) {
671 return -1;
672 }
673
674
675
676 if (s->types[s->current_chunk] == 2) {
677 memset(buf + i * 512, 0, 512);
678 continue;
679 }
680 sector_offset_in_chunk = sector_num + i - s->sectors[s->current_chunk];
681 memcpy(buf + i * 512,
682 s->uncompressed_chunk + sector_offset_in_chunk * 512, 512);
683 }
684 return 0;
685}
686
687static coroutine_fn int dmg_co_read(BlockDriverState *bs, int64_t sector_num,
688 uint8_t *buf, int nb_sectors)
689{
690 int ret;
691 BDRVDMGState *s = bs->opaque;
692 qemu_co_mutex_lock(&s->lock);
693 ret = dmg_read(bs, sector_num, buf, nb_sectors);
694 qemu_co_mutex_unlock(&s->lock);
695 return ret;
696}
697
698static void dmg_close(BlockDriverState *bs)
699{
700 BDRVDMGState *s = bs->opaque;
701
702 g_free(s->types);
703 g_free(s->offsets);
704 g_free(s->lengths);
705 g_free(s->sectors);
706 g_free(s->sectorcounts);
707 qemu_vfree(s->compressed_chunk);
708 qemu_vfree(s->uncompressed_chunk);
709
710 inflateEnd(&s->zstream);
711}
712
713static BlockDriver bdrv_dmg = {
714 .format_name = "dmg",
715 .instance_size = sizeof(BDRVDMGState),
716 .bdrv_probe = dmg_probe,
717 .bdrv_open = dmg_open,
718 .bdrv_read = dmg_co_read,
719 .bdrv_close = dmg_close,
720};
721
722static void bdrv_dmg_init(void)
723{
724 bdrv_register(&bdrv_dmg);
725}
726
727block_init(bdrv_dmg_init);
728