From nobody Wed Nov 5 13:14:14 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=fail(p=none dis=none) header.from=virtuozzo.com Return-Path: Received: from lists.gnu.org (208.118.235.17 [208.118.235.17]) by mx.zohomail.com with SMTPS id 1534508861507541.3962916197863; Fri, 17 Aug 2018 05:27:41 -0700 (PDT) Received: from localhost ([::1]:33517 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fqdqu-00088E-DX for importer@patchew.org; Fri, 17 Aug 2018 08:27:40 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:34933) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fqdm0-0004MG-3t for qemu-devel@nongnu.org; Fri, 17 Aug 2018 08:22:36 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fqdlz-0004a4-Dc for qemu-devel@nongnu.org; Fri, 17 Aug 2018 08:22:36 -0400 Received: from relay.sw.ru ([185.231.240.75]:52244) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1fqdlz-0004Z7-68; Fri, 17 Aug 2018 08:22:35 -0400 Received: from [10.28.8.145] (helo=kvm.sw.ru) by relay.sw.ru with esmtp (Exim 4.90_1) (envelope-from ) id 1fqdlw-0006lJ-6A; Fri, 17 Aug 2018 15:22:33 +0300 From: Vladimir Sementsov-Ogievskiy To: qemu-devel@nongnu.org, qemu-block@nongnu.org Date: Fri, 17 Aug 2018 15:22:19 +0300 Message-Id: <20180817122219.16206-8-vsementsov@virtuozzo.com> X-Mailer: git-send-email 2.11.1 In-Reply-To: <20180817122219.16206-1-vsementsov@virtuozzo.com> References: <20180817122219.16206-1-vsementsov@virtuozzo.com> X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x X-Received-From: 185.231.240.75 Subject: [Qemu-devel] [PATCH v2 7/7] block/qcow2-refcount: fix out-of-file L2 entries to be read-as-zero X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: kwolf@redhat.com, den@openvz.org, vsementsov@virtuozzo.com, mreitz@redhat.com Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail: RDMRC_1 RSF_0 Z_629925259 SPT_0 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Rewrite corrupted L2 table entry, which reference space out of underlying file. Make this L2 table entry read-as-all-zeros without any allocation. Signed-off-by: Vladimir Sementsov-Ogievskiy --- block/qcow2-refcount.c | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/block/qcow2-refcount.c b/block/qcow2-refcount.c index 3c004e5bfe..3de3768a3c 100644 --- a/block/qcow2-refcount.c +++ b/block/qcow2-refcount.c @@ -1720,8 +1720,30 @@ static int check_refcounts_l2(BlockDriverState *bs, = BdrvCheckResult *res, /* Mark cluster as used */ csize =3D (((l2_entry >> s->csize_shift) & s->csize_mask) + 1)= * BDRV_SECTOR_SIZE; + if (csize > s->cluster_size) { + ret =3D fix_l2_entry_to_zero( + bs, res, fix, l2_offset, i, active, + "compressed cluster larger than cluster: size 0x%" + PRIx64, csize); + if (ret < 0) { + goto fail; + } + continue; + } + coffset =3D l2_entry & s->cluster_offset_mask & ~(BDRV_SECTOR_SIZE - 1); + if (coffset >=3D bdrv_getlength(bs->file->bs)) { + ret =3D fix_l2_entry_to_zero( + bs, res, fix, l2_offset, i, active, + "compressed cluster out of file: offset 0x%" PRIx6= 4, + coffset); + if (ret < 0) { + goto fail; + } + continue; + } + ret =3D qcow2_inc_refcounts_imrt(bs, res, refcount_table, refcount_table_= size, coffset, csize); @@ -1748,6 +1770,16 @@ static int check_refcounts_l2(BlockDriverState *bs, = BdrvCheckResult *res, { uint64_t offset =3D l2_entry & L2E_OFFSET_MASK; =20 + if (offset >=3D bdrv_getlength(bs->file->bs)) { + ret =3D fix_l2_entry_to_zero( + bs, res, fix, l2_offset, i, active, + "cluster out of file: offset 0x%" PRIx64, offset); + if (ret < 0) { + goto fail; + } + continue; + } + if (flags & CHECK_FRAG_INFO) { res->bfi.allocated_clusters++; if (next_contiguous_offset && --=20 2.11.1