aboutsummaryrefslogtreecommitdiff
path: root/hw
diff options
context:
space:
mode:
authorPaolo Bonzini <pbonzini@redhat.com>2012-09-05 17:54:36 +0200
committerPaolo Bonzini <pbonzini@redhat.com>2012-09-21 16:12:34 +0200
commit12ca76fc48081b3a0ad1a70546abfcf198aedfc4 (patch)
treee90b1b5b27372f04d1f315b3fc3d62ba45a17a5f /hw
parent444bc908611ccaf4512dc37c33ac3b54d873a62b (diff)
downloadqemu-12ca76fc48081b3a0ad1a70546abfcf198aedfc4.zip
qemu-12ca76fc48081b3a0ad1a70546abfcf198aedfc4.tar.gz
qemu-12ca76fc48081b3a0ad1a70546abfcf198aedfc4.tar.bz2
scsi-disk: fix check for out-of-range LBA
This fix is needed to correctly handle 0-block read and writes. Without it, a 0-block access at LBA 0 would underflow. Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Diffstat (limited to 'hw')
-rw-r--r--hw/scsi-disk.c6
1 files changed, 5 insertions, 1 deletions
diff --git a/hw/scsi-disk.c b/hw/scsi-disk.c
index 3959603..d621852 100644
--- a/hw/scsi-disk.c
+++ b/hw/scsi-disk.c
@@ -1456,9 +1456,13 @@ static inline bool check_lba_range(SCSIDiskState *s,
* The first line tests that no overflow happens when computing the last
* sector. The second line tests that the last accessed sector is in
* range.
+ *
+ * Careful, the computations should not underflow for nb_sectors == 0,
+ * and a 0-block read to the first LBA beyond the end of device is
+ * valid.
*/
return (sector_num <= sector_num + nb_sectors &&
- sector_num + nb_sectors - 1 <= s->qdev.max_lba);
+ sector_num + nb_sectors <= s->qdev.max_lba + 1);
}
typedef struct UnmapCBData {