Thanks to visit codestin.com
Credit goes to github.com

Skip to content

block: do not allow guest to not negotiate VIRTIO_BLK_F_RO - #7705

Merged
rbradford merged 1 commit into
cloud-hypervisor:mainfrom
DemiMarie:no-forward-writes-ro
Feb 14, 2026
Merged

rbradford merged 1 commit into
cloud-hypervisor:mainfrom
DemiMarie:no-forward-writes-ro

Conversation

@DemiMarie

Copy link
Copy Markdown
Contributor

Unlike most virtio feature bits, VIRTIO_BLK_F_RO is not optional. It indicates that the host is refusing to permit write operations, and the guest must not be allowed to override it.

However, the block device currently does not enforce this. If the guest does not negotiate VIRTIO_BLK_F_RO, the block device will think the device is writable and forward write requests to the backend.

This is not a security problem right now because the backing device of a read-only device is always opened read-only. The kernel will thus reject the write operations with EBADF. If support is added for receiving the backing device file descriptor via SCM_RIGHTS (#7704), it will be possible to have a read-only block device backed by a writable file descriptor. This would make the bug a genuine security vulnerability.

Fix the bug by explicitly checking if VIRTIO_BLK_F_RO was offered but not negotiated. In this case, log a warning and proceed as if the guest did acknowledge the feature. This always indicates a guest driver bug.

Fixes: #7697

Unlike most virtio feature bits, VIRTIO_BLK_F_RO is not optional.
It indicates that the host is refusing to permit write operations, and
the guest must not be allowed to override it.

However, the block device currently does not enforce this.  If the guest
does not negotiate VIRTIO_BLK_F_RO, the block device will think the
device is writable and forward write requests to the backend.

This is not a security problem right now because the backing device of a
read-only device is always opened read-only.  The kernel will thus
reject the write operations with EBADF.  If support is added for
receiving the backing device file descriptor via SCM_RIGHTS (cloud-hypervisor#7704),
it will be possible to have a read-only block device backed by a
writable file descriptor.  This would make the bug a genuine security
vulnerability.

Fix the bug by explicitly checking if VIRTIO_BLK_F_RO was offered but
not negotiated.  In this case, log a warning and proceed as if the guest
did acknowledge the feature.  This always indicates a guest driver bug.

Fixes: cloud-hypervisor#7697
Signed-off-by: Demi Marie Obenour <[email protected]>
@DemiMarie
DemiMarie marked this pull request as ready for review February 14, 2026 08:25
@DemiMarie
DemiMarie requested a review from a team as a code owner February 14, 2026 08:25
@rbradford
rbradford added this pull request to the merge queue Feb 14, 2026
Merged via the queue into cloud-hypervisor:main with commit ce93686 Feb 14, 2026
42 of 43 checks passed
@likebreath likebreath added the bug-fix Bug fix to include in release notes label Feb 19, 2026
@DemiMarie
DemiMarie deleted the no-forward-writes-ro branch March 6, 2026 04:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug-fix Bug fix to include in release notes

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

If guest doesn't acknowledge VIRTIO_BLK_F_RO, write requests are passed to the backend (and fail)

3 participants