qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Max Reitz <mreitz@redhat.com>
To: qemu-block@nongnu.org
Cc: Kevin Wolf <kwolf@redhat.com>,
	qemu-devel@nongnu.org, Stefan Hajnoczi <stefanha@redhat.com>,
	Max Reitz <mreitz@redhat.com>
Subject: [Qemu-devel] [PATCH v6 11/17] qcow2/overlaps: Protect inactive L2 tables
Date: Wed,  5 Aug 2015 19:32:59 +0200	[thread overview]
Message-ID: <1438795985-21903-12-git-send-email-mreitz@redhat.com> (raw)
In-Reply-To: <1438795985-21903-1-git-send-email-mreitz@redhat.com>

Keep track of the inactive L2 tables in the metadata list to protect
them against accidental modifications.

Signed-off-by: Max Reitz <mreitz@redhat.com>
---
 block/qcow2-refcount.c | 20 ++++++++++++++++++++
 block/qcow2-snapshot.c | 43 ++++++++++++++++++++++++++++++++++++++++---
 2 files changed, 60 insertions(+), 3 deletions(-)

diff --git a/block/qcow2-refcount.c b/block/qcow2-refcount.c
index 76dd2bc..2cdf535 100644
--- a/block/qcow2-refcount.c
+++ b/block/qcow2-refcount.c
@@ -1211,8 +1211,28 @@ int qcow2_update_snapshot_refcount(BlockDriverState *bs,
                 }
                 if (addend < 0) {
                     if (!l1_allocated) {
+                        /* This is easy */
                         qcow2_metadata_list_remove(bs, l2_offset, 1,
                                                    QCOW2_OL_ACTIVE_L2);
+                    } else {
+                        /* If refcount == 0, this is, too. If refcount > 1, we
+                         * know that there must be some other inactive L2
+                         * reference; and for refcount == 1, if this is an
+                         * active L2 table, this was the last inactive L2
+                         * reference. */
+                        bool remove;
+                        if (refcount == 0) {
+                            remove = true;
+                        } else if (refcount == 1) {
+                            remove = qcow2_check_metadata_overlap(bs,
+                                ~QCOW2_OL_ACTIVE_L2, l2_offset,s->cluster_size);
+                        } else {
+                            remove = false;
+                        }
+                        if (remove) {
+                            qcow2_metadata_list_remove(bs, l2_offset, 1,
+                                                       QCOW2_OL_INACTIVE_L2);
+                        }
                     }
                 }
             }
diff --git a/block/qcow2-snapshot.c b/block/qcow2-snapshot.c
index 95afd87..e781bf2 100644
--- a/block/qcow2-snapshot.c
+++ b/block/qcow2-snapshot.c
@@ -47,9 +47,10 @@ int qcow2_read_snapshots(BlockDriverState *bs)
     QCowSnapshotHeader h;
     QCowSnapshotExtraData extra;
     QCowSnapshot *sn;
-    int i, id_str_size, name_size;
+    int i, j, id_str_size, name_size;
     int64_t offset;
     uint32_t extra_data_size;
+    uint64_t *l1_table;
     int ret;
 
     if (!s->nb_snapshots) {
@@ -123,11 +124,12 @@ int qcow2_read_snapshots(BlockDriverState *bs)
             goto fail;
         }
 
-        if (!(s->overlap_check & QCOW2_OL_INACTIVE_L1)) {
+        if (!(s->overlap_check & (QCOW2_OL_INACTIVE_L1 | QCOW2_OL_INACTIVE_L2)))
+        {
             continue;
         }
 
-        if (sn->l1_size > INT_MAX / sizeof(uint64_t)) {
+        if (sn->l1_size > QCOW_MAX_L1_SIZE) {
             /* Do not fail opening the image because a snapshot is broken which
              * might not be used anyway */
             continue;
@@ -137,6 +139,34 @@ int qcow2_read_snapshots(BlockDriverState *bs)
                                   size_to_clusters(s, sn->l1_size *
                                                       sizeof(uint64_t)),
                                   QCOW2_OL_INACTIVE_L1);
+
+        if (!(s->overlap_check & QCOW2_OL_INACTIVE_L2)) {
+            continue;
+        }
+
+        l1_table = qemu_try_blockalign(bs->file,
+                                       sn->l1_size * sizeof(uint64_t));
+        if (!l1_table) {
+            /* Do not fail opening the image just because a snapshot's L2 tables
+             * cannot be covered by the overlap checks */
+            continue;
+        }
+
+        ret = bdrv_pread(bs->file, sn->l1_table_offset, l1_table,
+                         sn->l1_size * sizeof(uint64_t));
+        if (ret < 0) {
+            qemu_vfree(l1_table);
+            continue;
+        }
+        for (j = 0; j < sn->l1_size; j++) {
+            uint64_t l2_offset = be64_to_cpu(l1_table[j]) & L1E_OFFSET_MASK;
+            if (l2_offset) {
+                qcow2_metadata_list_enter(bs, l2_offset, 1,
+                                          QCOW2_OL_INACTIVE_L2);
+            }
+        }
+
+        qemu_vfree(l1_table);
     }
 
     assert(offset - s->snapshots_offset <= INT_MAX);
@@ -435,6 +465,13 @@ int qcow2_snapshot_create(BlockDriverState *bs, QEMUSnapshotInfo *sn_info)
                                                   sizeof(uint64_t)),
                               QCOW2_OL_INACTIVE_L1);
 
+    for (i = 0; i < s->l1_size; i++) {
+        uint64_t l2_offset = s->l1_table[i] & L1E_OFFSET_MASK;
+        if (l2_offset) {
+            qcow2_metadata_list_enter(bs, l2_offset, 1, QCOW2_OL_INACTIVE_L2);
+        }
+    }
+
     /*
      * Increase the refcounts of all clusters and make sure everything is
      * stable on disk before updating the snapshot table to contain a pointer
-- 
2.4.6

  parent reply	other threads:[~2015-08-05 17:33 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-08-05 17:32 [Qemu-devel] [PATCH v6 00/17] qcow2: Add new overlap check functions Max Reitz
2015-08-05 17:32 ` [Qemu-devel] [PATCH v6 01/17] " Max Reitz
2015-08-05 17:32 ` [Qemu-devel] [PATCH v6 02/17] qcow2: Pull up overlap check option evaluation Max Reitz
2015-08-05 17:32 ` [Qemu-devel] [PATCH v6 03/17] qcow2: Create metadata list Max Reitz
2015-08-05 17:32 ` [Qemu-devel] [PATCH v6 04/17] qcow2/overlaps: Protect image header Max Reitz
2015-08-05 17:32 ` [Qemu-devel] [PATCH v6 05/17] qcow2/overlaps: Protect refcount table Max Reitz
2015-08-05 17:32 ` [Qemu-devel] [PATCH v6 06/17] qcow2/overlaps: Protect refcount blocks Max Reitz
2015-08-05 17:32 ` [Qemu-devel] [PATCH v6 07/17] qcow2/overlaps: Protect active L1 table Max Reitz
2015-08-05 17:32 ` [Qemu-devel] [PATCH v6 08/17] qcow2/overlaps: Protect active L2 tables Max Reitz
2015-08-05 17:32 ` [Qemu-devel] [PATCH v6 09/17] qcow2/overlaps: Protect snapshot table Max Reitz
2015-08-05 17:32 ` [Qemu-devel] [PATCH v6 10/17] qcow2/overlaps: Protect inactive L1 tables Max Reitz
2015-08-05 17:32 ` Max Reitz [this message]
2015-08-05 17:33 ` [Qemu-devel] [PATCH v6 12/17] qcow2: Use new metadata overlap check function Max Reitz
2015-08-05 17:33 ` [Qemu-devel] [PATCH v6 13/17] qcow2/overlaps: Add "memory limit reached" event Max Reitz
2015-08-05 17:33 ` [Qemu-devel] [PATCH v6 14/17] qcow2/overlaps: Add memory usage limit Max Reitz
2015-08-05 17:33 ` [Qemu-devel] [PATCH v6 15/17] qcow2: Add overlap structure memory size options Max Reitz
2015-08-05 17:33 ` [Qemu-devel] [PATCH v6 16/17] qapi: Expose new qcow2 overlap check options Max Reitz
2015-08-05 17:33 ` [Qemu-devel] [PATCH v6 17/17] iotests: Test qcow2's overlap check memory limit Max Reitz

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1438795985-21903-12-git-send-email-mreitz@redhat.com \
    --to=mreitz@redhat.com \
    --cc=kwolf@redhat.com \
    --cc=qemu-block@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    --cc=stefanha@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).