[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Qemu-devel] [PATCH 07/21] qcow2: Helper for refcount array size cal
From: |
Eric Blake |
Subject: |
Re: [Qemu-devel] [PATCH 07/21] qcow2: Helper for refcount array size calculation |
Date: |
Mon, 10 Nov 2014 15:49:05 -0700 |
User-agent: |
Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.2.0 |
On 11/10/2014 06:45 AM, Max Reitz wrote:
> Add a helper function which correctly calculates the byte size of a
> refcount array for any refcount order, and use that function.
>
> Signed-off-by: Max Reitz <address@hidden>
> ---
> block/qcow2-refcount.c | 39 ++++++++++++++++++++++++++++-----------
> 1 file changed, 28 insertions(+), 11 deletions(-)
>
> diff --git a/block/qcow2-refcount.c b/block/qcow2-refcount.c
> index 16652da..cfb4807 100644
> --- a/block/qcow2-refcount.c
> +++ b/block/qcow2-refcount.c
> @@ -1132,6 +1132,20 @@ fail:
> /* refcount checking functions */
>
>
> +static size_t refcount_array_byte_size(BDRVQcowState *s, uint64_t entries)
> +{
> + if (s->refcount_order < 3) {
> + /* sub-byte width */
> + int shift = 3 - s->refcount_order;
> + return (entries + (1 << shift) - 1) >> shift;
> + } else if (s->refcount_order == 3) {
> + /* byte width */
> + return entries;
> + } else {
> + /* multiple bytes wide */
> + return entries << (s->refcount_order - 3);
> + }
A comment proving why this can't overflow might be nice (if I analyzed
correctly, entries will be computed by file size / clusters, and in the
worst case, the smallest cluster and largest refcount_order results in
'(size >> 9) << (6 - 3)' which is still safe).
> @@ -1161,12 +1175,13 @@ static int inc_refcounts(BlockDriverState *bs,
> k = cluster_offset >> s->cluster_bits;
> if (k >= *refcount_table_size) {
> int64_t old_refcount_table_size = *refcount_table_size;
> + size_t new_byte_size;
> void *new_refcount_table;
>
> *refcount_table_size = k + 1;
> - new_refcount_table = g_try_realloc(*refcount_table,
> - *refcount_table_size *
> - s->refcount_bits / 8);
> + new_byte_size = refcount_array_byte_size(s,
> *refcount_table_size);
> +
> + new_refcount_table = g_try_realloc(*refcount_table,
> new_byte_size);
Yay - this addresses one of my possible overflow comments on 6/21.
I wonder if the series would have less churn if you rearranged this
patch to come before 6/21.
--
Eric Blake eblake redhat com +1-919-301-3266
Libvirt virtualization library http://libvirt.org
signature.asc
Description: OpenPGP digital signature
- [Qemu-devel] [PATCH 04/21] qcow2: Respect error in qcow2_alloc_bytes(), (continued)
- [Qemu-devel] [PATCH 04/21] qcow2: Respect error in qcow2_alloc_bytes(), Max Reitz, 2014/11/10
- [Qemu-devel] [PATCH 05/21] qcow2: Refcount overflow and qcow2_alloc_bytes(), Max Reitz, 2014/11/10
- Re: [Qemu-devel] [PATCH 05/21] qcow2: Refcount overflow and qcow2_alloc_bytes(), Eric Blake, 2014/11/10
- Re: [Qemu-devel] [PATCH 05/21] qcow2: Refcount overflow and qcow2_alloc_bytes(), Max Reitz, 2014/11/11
- Re: [Qemu-devel] [PATCH 05/21] qcow2: Refcount overflow and qcow2_alloc_bytes(), Eric Blake, 2014/11/11
- Re: [Qemu-devel] [PATCH 05/21] qcow2: Refcount overflow and qcow2_alloc_bytes(), Max Reitz, 2014/11/11
- Re: [Qemu-devel] [PATCH 05/21] qcow2: Refcount overflow and qcow2_alloc_bytes(), Eric Blake, 2014/11/11
- Re: [Qemu-devel] [PATCH 05/21] qcow2: Refcount overflow and qcow2_alloc_bytes(), Max Reitz, 2014/11/12
[Qemu-devel] [PATCH 07/21] qcow2: Helper for refcount array size calculation, Max Reitz, 2014/11/10
- Re: [Qemu-devel] [PATCH 07/21] qcow2: Helper for refcount array size calculation,
Eric Blake <=
[Qemu-devel] [PATCH 08/21] qcow2: More helpers for refcount modification, Max Reitz, 2014/11/10
[Qemu-devel] [PATCH 09/21] qcow2: Open images with refcount order != 4, Max Reitz, 2014/11/10
[Qemu-devel] [PATCH 10/21] qcow2: refcount_order parameter for qcow2_create2, Max Reitz, 2014/11/10