From: Kevin Wolf <kwolf@redhat.com>
To: Eric Blake <eblake@redhat.com>
Cc: qemu-block@nongnu.org, qemu-devel@nongnu.org
Subject: Re: [Qemu-devel] [PATCH] block: Fix copy-on-read crash with partial final cluster
Date: Mon, 9 Jul 2018 11:32:14 +0200 [thread overview]
Message-ID: <20180709093214.GA3511@localhost.localdomain> (raw)
In-Reply-To: <be1b9d41-1eb3-c24c-c459-cc6d6599de22@redhat.com>
Am 06.07.2018 um 23:20 hat Eric Blake geschrieben:
> On 07/06/2018 11:45 AM, Kevin Wolf wrote:
> > If the virtual disk size isn't aligned to full clusters,
> > bdrv_co_do_copy_on_readv() may get pnum == 0 before having the full
> > cluster completed, which will let it run into an assertion failure:
> >
> > qemu-io: block/io.c:1203: bdrv_co_do_copy_on_readv: Assertion `skip_bytes < pnum' failed.
> >
> > Check for EOF, assert that we read at least as much as the read request
> > originally wanted to have (which is true at EOF because otherwise
> > bdrv_check_byte_request() would already have returned an error) and
> > return success early even though we couldn't copy the full cluster.
> >
> > Signed-off-by: Kevin Wolf <kwolf@redhat.com>
> > ---
> > block/io.c | 6 ++++++
> > tests/qemu-iotests/197 | 9 +++++++++
> > tests/qemu-iotests/197.out | 8 ++++++++
> > 3 files changed, 23 insertions(+)
> >
> > diff --git a/block/io.c b/block/io.c
> > index 038449f81f..4c0831149c 100644
> > --- a/block/io.c
> > +++ b/block/io.c
> > @@ -1200,6 +1200,12 @@ static int coroutine_fn bdrv_co_do_copy_on_readv(BdrvChild *child,
> > pnum = MIN(cluster_bytes, max_transfer);
> > }
> > + /* Stop at EOF if the image ends in the middle of the cluster */
> > + if (ret == 0 && pnum == 0) {
>
> Is it any smarter to check for 'ret & BDRV_BLOCK_EOF' instead of pnum == 0?
>
> But as far as I can tell, right now those two conditions are synonymous.
You removed the context from your quote, which contains the assertion
that the commit message mentions:
assert(skip_bytes < pnum);
So I think it makes more sense to check pnum, because it's the short
pnum and not the BDRV_BLOCK_EOF flag that would make the following code
fail.
> > +echo
> > +echo '=== Partial final cluster ==='
> > +echo
> > +
> > +_make_test_img 1024
> > +$QEMU_IO -f $IMGFMT -C -c 'read 0 1024' "$TEST_IMG" | _filter_qemu_io
>
> Here, $TEST_IMG has no backing file, and does not have the final
> cluster allocated; all we have to do is properly read all zeroes.
And write them back, we test that it's allocated afterwards.
> Is it worth also explicitly testing reading of allocated data under
> COR
I could add a second read of the same area, which would not only test
reading of allocated data, but also test whether the allocating COR
wrote the correct data (all zeros).
Do you think that would be a worthwhile addition?
> and/or the case of one image with another backing image (with
> same or differing partial cluster sizes), where COR actually has to
> write the partial cluster? However, the logic in the code appears to
> cover all of those, whether or not the testsuite does as well.
Having a backing file is a different code path for non-zero data, but I
think we already test normal write/write_zeroes extensively. For zero
data, it doesn't make a difference whether it comes from the backing
file or from not having a backing file (as far as the COR logic is
concerned, anyway).
I didn't want to use a backing file because the test is 'generic', but
it already uses qcow2 in other cases, so if we really think this is
important to have, I guess I can have another case with qcow2 over
$IMGFMT and non-zero data.
Kevin
next prev parent reply other threads:[~2018-07-09 9:32 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-07-06 16:45 [Qemu-devel] [PATCH] block: Fix copy-on-read crash with partial final cluster Kevin Wolf
2018-07-06 21:20 ` Eric Blake
2018-07-09 9:32 ` Kevin Wolf [this message]
2018-07-20 20:19 ` Eric Blake
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180709093214.GA3511@localhost.localdomain \
--to=kwolf@redhat.com \
--cc=eblake@redhat.com \
--cc=qemu-block@nongnu.org \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).