@@ -295,16 +295,20 @@ static int copy_sectors(BlockDriverState *bs, uint64_t start_sect,
BDRVQcowState *s = bs->opaque;
int n, ret;
void *buf;
+ QEMUIOVector qiov;
+ struct iovec iov;
n = n_end - n_start;
if (n <= 0) {
return 0;
}
- buf = qemu_blockalign(bs, n * BDRV_SECTOR_SIZE);
+ iov.iov_base = buf = qemu_blockalign(bs, n * BDRV_SECTOR_SIZE);
+ iov.iov_len = n * BDRV_SECTOR_SIZE;
+ qemu_iovec_init_external(&qiov, &iov, 1);
BLKDBG_EVENT(bs->file, BLKDBG_COW_READ);
- ret = bdrv_read(bs, start_sect + n_start, buf, n);
+ ret = qcow2_co_readv(bs, start_sect + n_start, n, &qiov);
if (ret < 0) {
goto out;
}
@@ -376,7 +376,7 @@ int qcow2_backing_read1(BlockDriverState *bs, QEMUIOVector *qiov,
return n1;
}
-static int qcow2_co_readv(BlockDriverState *bs, int64_t sector_num,
+int qcow2_co_readv(BlockDriverState *bs, int64_t sector_num,
int remaining_sectors, QEMUIOVector *qiov)
{
BDRVQcowState *s = bs->opaque;
@@ -176,6 +176,8 @@ static inline int64_t align_offset(int64_t offset, int n)
/* qcow2.c functions */
int qcow2_backing_read1(BlockDriverState *bs, QEMUIOVector *qiov,
int64_t sector_num, int nb_sectors);
+int qcow2_co_readv(BlockDriverState *bs, int64_t sector_num,
+ int remaining_sectors, QEMUIOVector *qiov);
/* qcow2-refcount.c functions */
int qcow2_refcount_init(BlockDriverState *bs);
This fix bound check bug accessing last cluster if image size is not cluster aligned caused by "Unlock during COW" patch. Signed-off-by: Frediano Ziglio <freddy77@gmail.com> --- block/qcow2-cluster.c | 8 ++++++-- block/qcow2.c | 2 +- block/qcow2.h | 2 ++ 3 files changed, 9 insertions(+), 3 deletions(-)