qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Eric Blake <eblake@redhat.com>
To: John Snow <jsnow@redhat.com>, qemu-devel@nongnu.org
Cc: kwolf@redhat.com, famz@redhat.com, qemu-block@nongnu.org,
	Jeff Cody <jcody@redhat.com>, Max Reitz <mreitz@redhat.com>,
	Stefan Hajnoczi <stefanha@redhat.com>
Subject: Re: [Qemu-devel] [PATCH v4 03/23] block: Make bdrv_round_to_clusters() signature more useful
Date: Thu, 28 Sep 2017 17:29:22 -0500	[thread overview]
Message-ID: <8e62e57d-407e-a9fb-5be7-1aeb5c8d26ec@redhat.com> (raw)
In-Reply-To: <b17bdc57-6203-cb15-c84d-2beda28f6b57@redhat.com>

[-- Attachment #1: Type: text/plain, Size: 3676 bytes --]

On 09/26/2017 02:29 PM, John Snow wrote:
> 
> 
> On 09/26/2017 03:18 PM, Eric Blake wrote:
>> On 09/26/2017 01:51 PM, John Snow wrote:
>>>
>>>
>>> On 09/13/2017 12:03 PM, Eric Blake wrote:
>>>> In the process of converting sector-based interfaces to bytes,
>>>> I'm finding it easier to represent a byte count as a 64-bit
>>>> integer at the block layer (even if we are internally capped
>>>> by SIZE_MAX or even INT_MAX for individual transactions, it's
>>>> still nicer to not have to worry about truncation/overflow
>>>> issues on as many variables).  Update the signature of
>>>> bdrv_round_to_clusters() to uniformly use int64_t, matching
>>>> the signature already chosen for bdrv_is_allocated and the
>>>> fact that off_t is also a signed type, then adjust clients
>>>> according to the required fallout.
>>>>
>>>> Signed-off-by: Eric Blake <eblake@redhat.com>
>>>> Reviewed-by: Fam Zheng <famz@redhat.com>
>>>>
>>
>>>> @@ -946,7 +946,7 @@ static int coroutine_fn bdrv_co_do_copy_on_readv(BdrvChild *child,
>>>>      struct iovec iov;
>>>>      QEMUIOVector bounce_qiov;
>>>>      int64_t cluster_offset;
>>>> -    unsigned int cluster_bytes;
>>>> +    int64_t cluster_bytes;
>>>>      size_t skip_bytes;
>>>>      int ret;
>>>>
>>>> @@ -967,6 +967,7 @@ static int coroutine_fn bdrv_co_do_copy_on_readv(BdrvChild *child,
>>>>      trace_bdrv_co_do_copy_on_readv(bs, offset, bytes,
>>>>                                     cluster_offset, cluster_bytes);
>>>>
>>>> +    assert(cluster_bytes < SIZE_MAX);
>>>
>>> later in this function, is there any real or imagined risk of
>>> cluster_bytes exceeding INT_MAX when it's passed to
>>> bdrv_co_do_pwrite_zeroes?
>>>
>>>>      iov.iov_len = cluster_bytes;
>>
>> cluster_bytes is the input 'unsigned int bytes' rounded out to cluster
> 
> Ah, yes, we're probably not going to exceed that, you're right.
> 
>> boundaries, but where we know 'bytes <= BDRV_REQUEST_MAX_BYTES' (which
>> is 2^31 - 511).  Still, I guess you are right that rounding to a cluster
>> size could produce a larger value of exactly 2^31 (bigger than INT_MAX,
>> but still fits in 32-bit unsigned int, so my assert was to make sure
>> that truncating 64 bits to size_t iov.iov_len still works on 32-bit
>> platforms).
>>
>> In theory, I don't think we ever attempt an unaligned operation near
>> 2^31 that would round up to INT_MAX overflow (if we can, that's a
>> pre-existing bug that should be fixed separately).
>>
>> Should I tighten the assertion to assert(cluster_bytes <=
>> BDRV_REQUEST_MAX_BYTES), then see if I can come up with a case where we
>> can violate that?
>>
> 
> *Only* if you think it's worth your time. You'd know better than me at
> this point if this is remotely possible or not. Just a simple width
> check that caught my eye.

I reproduced a test case - we have a pre-existing bug.  An update to
qemu-io coming up (I need to make it easy to turn on
BDRV_O_COPY_ON_READ); then a new iotests with my test case: create a
backing file with more than 2G of explicit 0, then open a brand new
wrapper qcow2 file and read 2G-512 bytes at offset 1024.  This will,
given default qcow2 cluster size of 64k, proceed to copy-on-write 2G+64k
of data; which fits fine in the pre-patch unsigned int or post-patch
int64_t, but becomes an unintended no-op in the bdrv_co_do_pwrite_zeroes.

Took me the better part of a day to figure out how to provoke it in a
way appropriate for iotests, but I'm grateful you gave me the challenge.

-- 
Eric Blake, Principal Software Engineer
Red Hat, Inc.           +1-919-301-3266
Virtualization:  qemu.org | libvirt.org


[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 619 bytes --]

  reply	other threads:[~2017-09-28 22:29 UTC|newest]

Thread overview: 64+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-09-13 16:03 [Qemu-devel] [PATCH v4 00/23] make bdrv_get_block_status byte-based Eric Blake
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 01/23] block: Allow NULL file for bdrv_get_block_status() Eric Blake
2017-09-25 22:43   ` John Snow
2017-09-27 21:46     ` Eric Blake
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 02/23] block: Add flag to avoid wasted work in bdrv_is_allocated() Eric Blake
2017-09-26 18:31   ` John Snow
2017-09-28 14:58     ` Eric Blake
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 03/23] block: Make bdrv_round_to_clusters() signature more useful Eric Blake
2017-09-26 18:51   ` John Snow
2017-09-26 19:18     ` Eric Blake
2017-09-26 19:29       ` John Snow
2017-09-28 22:29         ` Eric Blake [this message]
2017-09-29 20:03   ` Eric Blake
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 04/23] qcow2: Switch is_zero_sectors() to byte-based Eric Blake
2017-09-26 19:06   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 05/23] block: Switch bdrv_make_zero() " Eric Blake
2017-09-26 19:13   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 06/23] qemu-img: Switch get_block_status() " Eric Blake
2017-09-26 19:16   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 07/23] block: Convert bdrv_get_block_status() to bytes Eric Blake
2017-09-26 19:39   ` John Snow
2017-09-26 19:57     ` Eric Blake
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 08/23] block: Switch bdrv_co_get_block_status() to byte-based Eric Blake
2017-09-26 20:15   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 09/23] block: Switch BdrvCoGetBlockStatusData " Eric Blake
2017-09-26 20:20   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 10/23] block: Switch bdrv_common_block_status_above() " Eric Blake
2017-09-27 18:26   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 11/23] block: Switch bdrv_co_get_block_status_above() " Eric Blake
2017-09-27 18:31   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 12/23] block: Convert bdrv_get_block_status_above() to bytes Eric Blake
2017-09-27 18:41   ` John Snow
2017-09-27 18:57     ` Eric Blake
2017-09-27 19:40       ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 13/23] qemu-img: Simplify logic in img_compare() Eric Blake
2017-09-27 19:05   ` John Snow
2017-09-27 19:15     ` Eric Blake
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 14/23] qemu-img: Speed up compare on pre-allocated larger file Eric Blake
2017-09-27 20:54   ` John Snow
2017-10-03  9:32   ` Vladimir Sementsov-Ogievskiy
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 15/23] qemu-img: Add find_nonzero() Eric Blake
2017-09-27 21:16   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 16/23] qemu-img: Drop redundant error message in compare Eric Blake
2017-09-27 21:35   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 17/23] qemu-img: Change check_empty_sectors() to byte-based Eric Blake
2017-09-27 21:43   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 18/23] qemu-img: Change compare_sectors() to be byte-based Eric Blake
2017-09-27 22:25   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 19/23] qemu-img: Change img_rebase() " Eric Blake
2017-09-29 19:38   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 20/23] qemu-img: Change img_compare() " Eric Blake
2017-09-29 20:42   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 21/23] block: Align block status requests Eric Blake
2017-09-13 19:26   ` Eric Blake
2017-09-13 20:36     ` Eric Blake
2017-10-02 20:24   ` John Snow
2017-10-02 23:51     ` Eric Blake
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 22/23] block: Relax bdrv_aligned_preadv() assertion Eric Blake
2017-10-02 21:20   ` John Snow
2017-09-13 16:03 ` [Qemu-devel] [PATCH v4 23/23] qemu-io: Relax 'alloc' now that block-status doesn't assert Eric Blake
2017-10-02 21:27   ` John Snow
2017-10-02 23:56     ` Eric Blake
2017-10-03  3:18       ` John Snow
2017-09-13 21:05 ` [Qemu-devel] [PATCH v4 00/23] make bdrv_get_block_status byte-based Eric Blake

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8e62e57d-407e-a9fb-5be7-1aeb5c8d26ec@redhat.com \
    --to=eblake@redhat.com \
    --cc=famz@redhat.com \
    --cc=jcody@redhat.com \
    --cc=jsnow@redhat.com \
    --cc=kwolf@redhat.com \
    --cc=mreitz@redhat.com \
    --cc=qemu-block@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    --cc=stefanha@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).