aboutsummaryrefslogtreecommitdiff
path: root/tests/qemu-iotests/060
diff options
context:
space:
mode:
authorMax Reitz <mreitz@redhat.com>2017-11-10 21:31:08 +0100
committerMax Reitz <mreitz@redhat.com>2017-11-17 18:21:30 +0100
commit93bbaf03ff7fd490e823814b8f5d6849a7b71a64 (patch)
tree15c255579532a672b067c32e985f7c11b7f16dbd /tests/qemu-iotests/060
parent791fff504cad4d935dfaab6333ff9b7d95cbfe3f (diff)
downloadqemu-93bbaf03ff7fd490e823814b8f5d6849a7b71a64.zip
qemu-93bbaf03ff7fd490e823814b8f5d6849a7b71a64.tar.gz
qemu-93bbaf03ff7fd490e823814b8f5d6849a7b71a64.tar.bz2
qcow2: Unaligned zero cluster in handle_alloc()
We should check whether the cluster offset we are about to use is actually valid; that is, whether it is aligned to cluster boundaries. Reported-by: R. Nageswara Sastry <nasastry@in.ibm.com> Buglink: https://bugs.launchpad.net/qemu/+bug/1728643 Buglink: https://bugs.launchpad.net/qemu/+bug/1728657 Signed-off-by: Max Reitz <mreitz@redhat.com> Message-id: 20171110203111.7666-3-mreitz@redhat.com Reviewed-by: Eric Blake <eblake@redhat.com> Reviewed-by: Alberto Garcia <berto@igalia.com> Signed-off-by: Max Reitz <mreitz@redhat.com>
Diffstat (limited to 'tests/qemu-iotests/060')
-rwxr-xr-xtests/qemu-iotests/06016
1 files changed, 16 insertions, 0 deletions
diff --git a/tests/qemu-iotests/060 b/tests/qemu-iotests/060
index 56bdf1e..49bc89d 100755
--- a/tests/qemu-iotests/060
+++ b/tests/qemu-iotests/060
@@ -321,6 +321,22 @@ echo '--- Repairing ---'
# because the image was already marked corrupt by that point
_check_test_img -r all
+echo
+echo "=== Writing to an unaligned preallocated zero cluster ==="
+echo
+
+_make_test_img 64M
+
+# Allocate the L2 table
+$QEMU_IO -c "write 0 64k" -c "discard 0 64k" "$TEST_IMG" | _filter_qemu_io
+# Pretend there is a preallocated zero cluster somewhere inside the
+# image header
+poke_file "$TEST_IMG" "$l2_offset" "\x80\x00\x00\x00\x00\x00\x2a\x01"
+# Let's write to it!
+$QEMU_IO -c "write 0 64k" "$TEST_IMG" | _filter_qemu_io
+
+# Can't repair this yet (TODO: We can just deallocate the cluster)
+
# success, all done
echo "*** done"
rm -f $seq.full