Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1423436 - hivex: Add HIVEX_OPEN_UNSAFE flag
hivex: Add HIVEX_OPEN_UNSAFE flag
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: hivex (Show other bugs)
7.4
x86_64 Unspecified
high Severity high
: rc
: 7.4
Assigned To: Richard W.M. Jones
Virtualization Bugs
V2V
:
Depends On: 888379
Blocks: 1311890
  Show dependency treegraph
 
Reported: 2017-02-17 05:27 EST by Richard W.M. Jones
Modified: 2017-08-02 04:13 EDT (History)
12 users (show)

See Also:
Fixed In Version: hivex-1.3.10-5.8.el7
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1311890
Environment:
Last Closed: 2017-08-01 12:45:24 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2017:1967 normal SHIPPED_LIVE hivex bug fix update 2017-08-01 13:56:54 EDT

  None (edit)
Description Richard W.M. Jones 2017-02-17 05:27:57 EST
+++ This bug was initially created as a clone of Bug #1311890 +++

Description of problem:

This patch series adds the HIVEX_OPEN_UNSAFE flag, allowing hivex to
tolerate various forms of mild registry corruption:

https://www.redhat.com/archives/libguestfs/2017-February/msg00187.html

We should backport this into hivex in RHEL, and that will allow us to
fix bug 1311890.
Comment 1 Richard W.M. Jones 2017-02-17 05:50:35 EST
To verify this bug:

(1) Download SOFTWARE.xz, the attachment from bug 1311890.

(2) unxz SOFTWARE.xz

(3) Run these commands:

  $ hivexsh SOFTWARE 
  hivexsh: failed to open hive file: SOFTWARE: Operation not supported

  $ hivexsh -u SOFTWARE 

  Welcome to hivexsh, the hivex interactive shell for examining
  Windows Registry binary hive files.

  Type: 'help' for help summary
        'quit' to quit the shell

  SOFTWARE\> exit

Notice that the first command fails because the hive file contains
some corruption.  The second command (with -u flag) succeeds because
we tell hivex to ignore some forms of corruption.

(The -u flag was not available in RHEL <= 7.3).

(4) Enable debugging and check that it is skipping corruption:

  $ echo exit | hivexsh -u -d SOFTWARE
  ...
  hivex: hivex_open: page not found at expected offset 0x2084000, seeking until one is found or EOF is reached

(5) Check that HIVEX_OPEN_UNSAFE appears in /usr/include/hivex.h:

  $ grep HIVEX_OPEN_UNSAFE /usr/include/hivex.h 
  #define HIVEX_OPEN_UNSAFE     8
Comment 2 Richard W.M. Jones 2017-02-17 11:27:44 EST
Waiting for this package to be added to the ACL before I can
create an erratum.
Comment 5 errata-xmlrpc 2017-08-01 12:45:24 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2017:1967

Note You need to log in before you can comment on or make changes to this bug.