git: 51234535ddd6 - main - bhyveload: validate character disk devices

From: Roman Bogorodskiy <novel_at_FreeBSD.org>
Date: Mon, 21 Sep 2026 16:32:42 UTC
The branch main has been updated by novel:

URL: https://cgit.FreeBSD.org/src/commit/?id=51234535ddd6ec0afe9dd4e3f34a31b92d5cdd78

commit 51234535ddd6ec0afe9dd4e3f34a31b92d5cdd78
Author:     Roman Bogorodskiy <novel@FreeBSD.org>
AuthorDate: 2026-08-28 17:51:31 +0000
Commit:     Roman Bogorodskiy <novel@FreeBSD.org>
CommitDate: 2026-09-21 16:31:34 +0000

    bhyveload: validate character disk devices
    
    Currently, bhyveload(8) does not validate the supplied disk
    image path. For example, it allows passing the /dev/null
    device, which later fails in userboot because it does not
    support DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls (see
    userdisk_init() in stand/userboot/userboot/userboot_disk.c).
    
    Fix that by checking DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls early.
    A similar check already exists in bhyve(8). While here, make
    cb_diskioctl() report the obtained sector size instead of
    hard-coding 512.
    
    Reviewed by:    markj
    MFC after:      2 weeks
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D59253
---
 usr.sbin/bhyveload/bhyveload.c | 34 +++++++++++++++++++++++++++++++---
 1 file changed, 31 insertions(+), 3 deletions(-)

diff --git a/usr.sbin/bhyveload/bhyveload.c b/usr.sbin/bhyveload/bhyveload.c
index 154afd4ce398..fad875fc781c 100644
--- a/usr.sbin/bhyveload/bhyveload.c
+++ b/usr.sbin/bhyveload/bhyveload.c
@@ -365,7 +365,14 @@ cb_diskioctl(void *arg __unused, int unit, u_long cmd, void *data)
 
 	switch (cmd) {
 	case DIOCGSECTORSIZE:
-		*(u_int *)data = 512;
+		if (fstat(disk_fd[unit], &sb) != 0)
+			return (ENOTTY);
+		if (S_ISCHR(sb.st_mode)) {
+			if (ioctl(disk_fd[unit], DIOCGSECTORSIZE, data) != 0)
+				return (ENOTTY);
+		} else {
+			*(u_int *)data = 512;
+		}
 		break;
 	case DIOCGMEDIASIZE:
 		if (fstat(disk_fd[unit], &sb) != 0)
@@ -732,7 +739,9 @@ altcons_open(char *path)
 static int
 disk_open(char *path)
 {
-	int fd;
+	struct stat sbuf;
+	off_t size;
+	int fd, ret, sectsz;
 
 	if (ndisks >= NDISKS)
 		return (ERANGE);
@@ -742,11 +751,30 @@ disk_open(char *path)
 		fd = open(path, O_RDONLY);
 	if (fd < 0)
 		return (errno);
+	if (fstat(fd, &sbuf) < 0) {
+		ret = errno;
+		goto err;
+	}
+
+	size = sbuf.st_size;
+	sectsz = DEV_BSIZE;
+	if (S_ISCHR(sbuf.st_mode)) {
+		if (ioctl(fd, DIOCGMEDIASIZE, &size) < 0 ||
+		    ioctl(fd, DIOCGSECTORSIZE, &sectsz) < 0) {
+			ret = errno;
+			goto err;
+		}
+		assert(size != 0);
+		assert(sectsz != 0);
+	}
 
 	disk_fd[ndisks] = fd;
 	ndisks++;
 
 	return (0);
+err:
+	close(fd);
+	return (ret);
 }
 
 static void
@@ -829,7 +857,7 @@ main(int argc, char** argv)
 		case 'd':
 			error = disk_open(optarg);
 			if (error != 0)
-				errx(EX_USAGE, "Could not open '%s'", optarg);
+				errc(EX_USAGE, error, "Could not open '%s'", optarg);
 			break;
 
 		case 'e':