From nobody Tue Feb 10 10:04:18 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=fail(p=none dis=none) header.from=virtuozzo.com Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 1529433609556763.8297442204017; Tue, 19 Jun 2018 11:40:09 -0700 (PDT) Received: from localhost ([::1]:44407 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fVLY0-00034c-Pm for importer@patchew.org; Tue, 19 Jun 2018 14:40:08 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:47497) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fVLTB-0007hn-Ch for qemu-devel@nongnu.org; Tue, 19 Jun 2018 14:35:10 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fVLTA-0005YI-5a for qemu-devel@nongnu.org; Tue, 19 Jun 2018 14:35:09 -0400 Received: from relay.sw.ru ([185.231.240.75]:38938) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1fVLT4-0005K3-MB; Tue, 19 Jun 2018 14:35:02 -0400 Received: from msk-vpn.virtuozzo.com ([195.214.232.6] helo=kvm.sw.ru) by relay.sw.ru with esmtp (Exim 4.90_1) (envelope-from ) id 1fVLT2-0004dh-BB; Tue, 19 Jun 2018 21:35:00 +0300 From: Vladimir Sementsov-Ogievskiy To: qemu-block@nongnu.org, qemu-devel@nongnu.org Date: Tue, 19 Jun 2018 21:34:57 +0300 Message-Id: <20180619183457.371081-8-vsementsov@virtuozzo.com> X-Mailer: git-send-email 2.11.1 In-Reply-To: <20180619183457.371081-1-vsementsov@virtuozzo.com> References: <20180619183457.371081-1-vsementsov@virtuozzo.com> X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x [fuzzy] X-Received-From: 185.231.240.75 Subject: [Qemu-devel] [PATCH 7/7] block/qcow2-refcount: fix out-of-file L2 entries to be read-as-zero X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: kwolf@redhat.com, den@openvz.org, vsementsov@virtuozzo.com, mreitz@redhat.com Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail: RSF_0 Z_629925259 SPT_0 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Rewrite corrupted L2 table entry, which reference space out of underlying file. Make this L2 table entry read-as-all-zeros without any allocation. Signed-off-by: Vladimir Sementsov-Ogievskiy --- block/qcow2-refcount.c | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/block/qcow2-refcount.c b/block/qcow2-refcount.c index 3c9e2da39e..cbad8355f3 100644 --- a/block/qcow2-refcount.c +++ b/block/qcow2-refcount.c @@ -1714,8 +1714,30 @@ static int check_refcounts_l2(BlockDriverState *bs, = BdrvCheckResult *res, /* Mark cluster as used */ csize =3D (((l2_entry >> s->csize_shift) & s->csize_mask) + 1)= * BDRV_SECTOR_SIZE; + if (csize > s->cluster_size) { + ret =3D fix_l2_entry_to_zero( + bs, res, fix, l2_offset, i, active, + "compressed cluster larger than cluster: size 0x%" + PRIx64, csize); + if (ret < 0) { + goto fail; + } + continue; + } + coffset =3D l2_entry & s->cluster_offset_mask & ~(BDRV_SECTOR_SIZE - 1); + if (coffset >=3D bdrv_getlength(bs->file->bs)) { + ret =3D fix_l2_entry_to_zero( + bs, res, fix, l2_offset, i, active, + "compressed cluster out of file: offset 0x%" PRIx6= 4, + coffset); + if (ret < 0) { + goto fail; + } + continue; + } + ret =3D qcow2_inc_refcounts_imrt(bs, res, refcount_table, refcount_table_= size, coffset, csize); @@ -1742,6 +1764,16 @@ static int check_refcounts_l2(BlockDriverState *bs, = BdrvCheckResult *res, { uint64_t offset =3D l2_entry & L2E_OFFSET_MASK; =20 + if (offset >=3D bdrv_getlength(bs->file->bs)) { + ret =3D fix_l2_entry_to_zero( + bs, res, fix, l2_offset, i, active, + "cluster out of file: offset 0x%" PRIx64, offset); + if (ret < 0) { + goto fail; + } + continue; + } + if (flags & CHECK_FRAG_INFO) { res->bfi.allocated_clusters++; if (next_contiguous_offset && --=20 2.11.1