28.10.2019 9:33, Tuguoyi wrote: > In check_constraints_on_bitmap(), the sanity check on the > granularity will cause uint64_t integer left-shift overflow > when cluster_size is 2M and the granularity is BIGGER than > 32K. As a result, for a qcow2 disk with cluster_size set to > 2M, we could not even create a dirty bitmap with default > granularity. This patch fix the issue by dividing @len by > granularity instead. > > Signed-off-by: Guoyi Tu <[email protected]>
The buggy code was introduced in 5f72826e7fc6216 (by me, sorry :(, so it's an old bug, appeared in 2.10. Still, I add stable to CC, as fix is very simple. Fixes: 5f72826e7fc62167cf3a Reviewed-by: Vladimir Sementsov-Ogievskiy <[email protected]> > --- > block/qcow2-bitmap.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/block/qcow2-bitmap.c b/block/qcow2-bitmap.c > index 98294a7..71ac822 100644 > --- a/block/qcow2-bitmap.c > +++ b/block/qcow2-bitmap.c > @@ -172,8 +172,8 @@ static int check_constraints_on_bitmap(BlockDriverState > *bs, > } > > if ((len > (uint64_t)BME_MAX_PHYS_SIZE << granularity_bits) || > - (len > (uint64_t)BME_MAX_TABLE_SIZE * s->cluster_size << > - granularity_bits)) > + (DIV_ROUND_UP(len, granularity) > (uint64_t)BME_MAX_TABLE_SIZE * > + s->cluster_size)) > { > error_setg(errp, "Too much space will be occupied by the bitmap. " > "Use larger granularity"); > -- Best regards, Vladimir
