qcow2: Fix corruption after refblock allocation
Refblock allocation code needs to take into consideration that update_refcount will load a different refcount block into the cache, so it must initialize the cache for a new refcount block only afterwards. Not doing this means that not only the refcount in the wrong block is updated, but also that the caller will work on the wrong block. Signed-off-by: Kevin Wolf <kwolf@redhat.com>
This commit is contained in:
parent
ed0df867d9
commit
25408c0950
@ -221,8 +221,6 @@ static int64_t alloc_refcount_block(BlockDriverState *bs, int64_t cluster_index)
|
|||||||
|
|
||||||
/* Allocate the refcount block itself and mark it as used */
|
/* Allocate the refcount block itself and mark it as used */
|
||||||
uint64_t new_block = alloc_clusters_noref(bs, s->cluster_size);
|
uint64_t new_block = alloc_clusters_noref(bs, s->cluster_size);
|
||||||
memset(s->refcount_block_cache, 0, s->cluster_size);
|
|
||||||
s->refcount_block_cache_offset = new_block;
|
|
||||||
|
|
||||||
#ifdef DEBUG_ALLOC2
|
#ifdef DEBUG_ALLOC2
|
||||||
fprintf(stderr, "qcow2: Allocate refcount block %d for %" PRIx64
|
fprintf(stderr, "qcow2: Allocate refcount block %d for %" PRIx64
|
||||||
@ -231,6 +229,10 @@ static int64_t alloc_refcount_block(BlockDriverState *bs, int64_t cluster_index)
|
|||||||
#endif
|
#endif
|
||||||
|
|
||||||
if (in_same_refcount_block(s, new_block, cluster_index << s->cluster_bits)) {
|
if (in_same_refcount_block(s, new_block, cluster_index << s->cluster_bits)) {
|
||||||
|
/* Zero the new refcount block before updating it */
|
||||||
|
memset(s->refcount_block_cache, 0, s->cluster_size);
|
||||||
|
s->refcount_block_cache_offset = new_block;
|
||||||
|
|
||||||
/* The block describes itself, need to update the cache */
|
/* The block describes itself, need to update the cache */
|
||||||
int block_index = (new_block >> s->cluster_bits) &
|
int block_index = (new_block >> s->cluster_bits) &
|
||||||
((1 << (s->cluster_bits - REFCOUNT_SHIFT)) - 1);
|
((1 << (s->cluster_bits - REFCOUNT_SHIFT)) - 1);
|
||||||
@ -242,6 +244,11 @@ static int64_t alloc_refcount_block(BlockDriverState *bs, int64_t cluster_index)
|
|||||||
if (ret < 0) {
|
if (ret < 0) {
|
||||||
goto fail_block;
|
goto fail_block;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* Initialize the new refcount block only after updating its refcount,
|
||||||
|
* update_refcount uses the refcount cache itself */
|
||||||
|
memset(s->refcount_block_cache, 0, s->cluster_size);
|
||||||
|
s->refcount_block_cache_offset = new_block;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Now the new refcount block needs to be written to disk */
|
/* Now the new refcount block needs to be written to disk */
|
||||||
|
Loading…
Reference in New Issue
Block a user