From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:41890) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XwA8D-0001wC-LA for qemu-devel@nongnu.org; Wed, 03 Dec 2014 08:38:19 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1XwA87-0004Dd-7E for qemu-devel@nongnu.org; Wed, 03 Dec 2014 08:38:13 -0500 Received: from mx1.redhat.com ([209.132.183.28]:58230) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XwA87-0004DP-0o for qemu-devel@nongnu.org; Wed, 03 Dec 2014 08:38:07 -0500 Received: from int-mx10.intmail.prod.int.phx2.redhat.com (int-mx10.intmail.prod.int.phx2.redhat.com [10.5.11.23]) by mx1.redhat.com (8.14.4/8.14.4) with ESMTP id sB3Dc6vF021792 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=FAIL) for ; Wed, 3 Dec 2014 08:38:06 -0500 From: Max Reitz Date: Wed, 3 Dec 2014 14:37:28 +0100 Message-Id: <1417613866-25890-9-git-send-email-mreitz@redhat.com> In-Reply-To: <1417613866-25890-1-git-send-email-mreitz@redhat.com> References: <1417613866-25890-1-git-send-email-mreitz@redhat.com> Subject: [Qemu-devel] [PATCH v4 08/26] qcow2: Refcount overflow and qcow2_alloc_bytes() List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: Kevin Wolf , Stefan Hajnoczi , Max Reitz qcow2_alloc_bytes() may reuse a cluster multiple times, in which case the refcount is increased accordingly. However, if this would lead to an overflow the function should instead just not reuse this cluster and allocate a new one. Signed-off-by: Max Reitz --- block/qcow2-refcount.c | 31 ++++++++++++++++++++++++++++++- 1 file changed, 30 insertions(+), 1 deletion(-) diff --git a/block/qcow2-refcount.c b/block/qcow2-refcount.c index 6166f7d..152ca22 100644 --- a/block/qcow2-refcount.c +++ b/block/qcow2-refcount.c @@ -780,9 +780,11 @@ int64_t qcow2_alloc_bytes(BlockDriverState *bs, int size) BDRVQcowState *s = bs->opaque; int64_t offset, cluster_offset, new_cluster; int free_in_cluster, ret; + uint64_t refcount; BLKDBG_EVENT(bs->file, BLKDBG_CLUSTER_ALLOC_BYTES); assert(size > 0 && size <= s->cluster_size); + redo: if (s->free_byte_offset == 0) { offset = qcow2_alloc_clusters(bs, s->cluster_size); if (offset < 0) { @@ -790,12 +792,25 @@ int64_t qcow2_alloc_bytes(BlockDriverState *bs, int size) } s->free_byte_offset = offset; } - redo: + free_in_cluster = s->cluster_size - offset_into_cluster(s, s->free_byte_offset); if (size <= free_in_cluster) { /* enough space in current cluster */ offset = s->free_byte_offset; + + if (offset_into_cluster(s, offset) != 0) { + /* We will have to increase the refcount of this cluster; if the + * maximum has been reached already, this cluster cannot be used */ + ret = qcow2_get_refcount(bs, offset >> s->cluster_bits, &refcount); + if (ret < 0) { + return ret; + } else if (refcount == s->refcount_max) { + s->free_byte_offset = 0; + goto redo; + } + } + s->free_byte_offset += size; free_in_cluster -= size; if (free_in_cluster == 0) @@ -816,6 +831,20 @@ int64_t qcow2_alloc_bytes(BlockDriverState *bs, int size) if ((cluster_offset + s->cluster_size) == new_cluster) { /* we are lucky: contiguous data */ offset = s->free_byte_offset; + + /* Same as above: In order to reuse the cluster, the refcount has to + * be increased; if that will not work, we are not so lucky after + * all */ + ret = qcow2_get_refcount(bs, offset >> s->cluster_bits, &refcount); + if (ret < 0) { + qcow2_free_clusters(bs, new_cluster, s->cluster_size, + QCOW2_DISCARD_NEVER); + return ret; + } else if (refcount == s->refcount_max) { + s->free_byte_offset = offset; + goto redo; + } + ret = qcow2_update_cluster_refcount(bs, offset >> s->cluster_bits, 1, false, QCOW2_DISCARD_NEVER); if (ret < 0) { -- 1.9.3