Skip to content
Snippets Groups Projects
  1. Oct 13, 2020
    • Christian Borntraeger's avatar
      vmdk: fix maybe uninitialized warnings · cd466702
      Christian Borntraeger authored
      
      Fedora 32 gcc 10 seems to give false positives:
      
      Compiling C object libblock.fa.p/block_vmdk.c.o
      ../block/vmdk.c: In function ‘vmdk_parse_extents’:
      ../block/vmdk.c:587:5: error: ‘extent’ may be used uninitialized in this function [-Werror=maybe-uninitialized]
        587 |     g_free(extent->l1_table);
            |     ^~~~~~~~~~~~~~~~~~~~~~~~
      ../block/vmdk.c:754:17: note: ‘extent’ was declared here
        754 |     VmdkExtent *extent;
            |                 ^~~~~~
      ../block/vmdk.c:620:11: error: ‘extent’ may be used uninitialized in this function [-Werror=maybe-uninitialized]
        620 |     ret = vmdk_init_tables(bs, extent, errp);
            |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      ../block/vmdk.c:598:17: note: ‘extent’ was declared here
        598 |     VmdkExtent *extent;
            |                 ^~~~~~
      ../block/vmdk.c:1178:39: error: ‘extent’ may be used uninitialized in this function [-Werror=maybe-uninitialized]
       1178 |             extent->flat_start_offset = flat_offset << 9;
            |             ~~~~~~~~~~~~~~~~~~~~~~~~~~^~~~~~~~~~~~~~~~~~
      ../block/vmdk.c: In function ‘vmdk_open_vmdk4’:
      ../block/vmdk.c:581:22: error: ‘extent’ may be used uninitialized in this function [-Werror=maybe-uninitialized]
        581 |     extent->l2_cache =
            |     ~~~~~~~~~~~~~~~~~^
        582 |         g_malloc(extent->entry_size * extent->l2_size * L2_CACHE_SIZE);
            |         ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      ../block/vmdk.c:872:17: note: ‘extent’ was declared here
        872 |     VmdkExtent *extent;
            |                 ^~~~~~
      ../block/vmdk.c: In function ‘vmdk_open’:
      ../block/vmdk.c:620:11: error: ‘extent’ may be used uninitialized in this function [-Werror=maybe-uninitialized]
        620 |     ret = vmdk_init_tables(bs, extent, errp);
            |           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      ../block/vmdk.c:598:17: note: ‘extent’ was declared here
        598 |     VmdkExtent *extent;
            |                 ^~~~~~
      cc1: all warnings being treated as errors
      make: *** [Makefile.ninja:884: libblock.fa.p/block_vmdk.c.o] Error 1
      
      fix them by assigning a default value.
      
      Signed-off-by: default avatarChristian Borntraeger <borntraeger@de.ibm.com>
      Reviewed-by: default avatarFam Zheng <fam@euphon.net>
      Message-Id: <20200930155859.303148-2-borntraeger@de.ibm.com>
      Signed-off-by: default avatarLaurent Vivier <laurent@vivier.eu>
      cd466702
  2. Sep 07, 2020
  3. Sep 01, 2020
  4. Jul 14, 2020
    • Eric Blake's avatar
      vmdk: Add trivial backing_fmt support · d51a814c
      Eric Blake authored
      
      vmdk already requires that if backing_file is present, that it be
      another vmdk image (see vmdk_co_do_create).  Meanwhile, we want to
      move towards always being explicit about the backing format for other
      drivers where it matters.  So for convenience, make qemu-img create -F
      vmdk work, while rejecting all other explicit formats (note that this
      is only for QemuOpts usage; there is no change to the QAPI to allow a
      format through -blockdev).
      
      Signed-off-by: default avatarEric Blake <eblake@redhat.com>
      Message-Id: <20200706203954.341758-5-eblake@redhat.com>
      Signed-off-by: default avatarKevin Wolf <kwolf@redhat.com>
      d51a814c
  5. Jul 10, 2020
    • Markus Armbruster's avatar
      error: Avoid error_propagate() after migrate_add_blocker() · 386f6c07
      Markus Armbruster authored
      
      When migrate_add_blocker(blocker, &errp) is followed by
      error_propagate(errp, err), we can often just as well do
      migrate_add_blocker(..., errp).
      
      Do that with this Coccinelle script:
      
          @@
          expression blocker, err, errp;
          expression ret;
          @@
          -    ret = migrate_add_blocker(blocker, &err);
          -    if (err) {
          +    ret = migrate_add_blocker(blocker, errp);
          +    if (ret < 0) {
                   ... when != err;
          -        error_propagate(errp, err);
                   ...
               }
      
          @@
          expression blocker, err, errp;
          @@
          -    migrate_add_blocker(blocker, &err);
          -    if (err) {
          +    if (migrate_add_blocker(blocker, errp) < 0) {
                   ... when != err;
          -        error_propagate(errp, err);
                   ...
               }
      
      Double-check @err is not used afterwards.  Dereferencing it would be
      use after free, but checking whether it's null would be legitimate.
      
      Signed-off-by: default avatarMarkus Armbruster <armbru@redhat.com>
      Reviewed-by: default avatarEric Blake <eblake@redhat.com>
      Reviewed-by: default avatarVladimir Sementsov-Ogievskiy <vsementsov@virtuozzo.com>
      Message-Id: <20200707160613.848843-43-armbru@redhat.com>
      386f6c07
    • Markus Armbruster's avatar
      error: Eliminate error_propagate() with Coccinelle, part 2 · af175e85
      Markus Armbruster authored
      
      When all we do with an Error we receive into a local variable is
      propagating to somewhere else, we can just as well receive it there
      right away.  The previous commit did that with a Coccinelle script I
      consider fairly trustworthy.  This commit uses the same script with
      the matching of return taken out, i.e. we convert
      
          if (!foo(..., &err)) {
              ...
              error_propagate(errp, err);
              ...
          }
      
      to
      
          if (!foo(..., errp)) {
              ...
              ...
          }
      
      This is unsound: @err could still be read between afterwards.  I don't
      know how to express "no read of @err without an intervening write" in
      Coccinelle.  Instead, I manually double-checked for uses of @err.
      
      Suboptimal line breaks tweaked manually.  qdev_realize() simplified
      further to placate scripts/checkpatch.pl.
      
      Signed-off-by: default avatarMarkus Armbruster <armbru@redhat.com>
      Reviewed-by: default avatarEric Blake <eblake@redhat.com>
      Message-Id: <20200707160613.848843-36-armbru@redhat.com>
      af175e85
    • Markus Armbruster's avatar
      error: Eliminate error_propagate() with Coccinelle, part 1 · 668f62ec
      Markus Armbruster authored
      
      When all we do with an Error we receive into a local variable is
      propagating to somewhere else, we can just as well receive it there
      right away.  Convert
      
          if (!foo(..., &err)) {
              ...
              error_propagate(errp, err);
              ...
              return ...
          }
      
      to
      
          if (!foo(..., errp)) {
              ...
              ...
              return ...
          }
      
      where nothing else needs @err.  Coccinelle script:
      
          @rule1 forall@
          identifier fun, err, errp, lbl;
          expression list args, args2;
          binary operator op;
          constant c1, c2;
          symbol false;
          @@
               if (
          (
          -        fun(args, &err, args2)
          +        fun(args, errp, args2)
          |
          -        !fun(args, &err, args2)
          +        !fun(args, errp, args2)
          |
          -        fun(args, &err, args2) op c1
          +        fun(args, errp, args2) op c1
          )
                  )
               {
                   ... when != err
                       when != lbl:
                       when strict
          -        error_propagate(errp, err);
                   ... when != err
          (
                   return;
          |
                   return c2;
          |
                   return false;
          )
               }
      
          @rule2 forall@
          identifier fun, err, errp, lbl;
          expression list args, args2;
          expression var;
          binary operator op;
          constant c1, c2;
          symbol false;
          @@
          -    var = fun(args, &err, args2);
          +    var = fun(args, errp, args2);
               ... when != err
               if (
          (
                   var
          |
                   !var
          |
                   var op c1
          )
                  )
               {
                   ... when != err
                       when != lbl:
                       when strict
          -        error_propagate(errp, err);
                   ... when != err
          (
                   return;
          |
                   return c2;
          |
                   return false;
          |
                   return var;
          )
               }
      
          @depends on rule1 || rule2@
          identifier err;
          @@
          -    Error *err = NULL;
               ... when != err
      
      Not exactly elegant, I'm afraid.
      
      The "when != lbl:" is necessary to avoid transforming
      
               if (fun(args, &err)) {
                   goto out
               }
               ...
           out:
               error_propagate(errp, err);
      
      even though other paths to label out still need the error_propagate().
      For an actual example, see sclp_realize().
      
      Without the "when strict", Coccinelle transforms vfio_msix_setup(),
      incorrectly.  I don't know what exactly "when strict" does, only that
      it helps here.
      
      The match of return is narrower than what I want, but I can't figure
      out how to express "return where the operand doesn't use @err".  For
      an example where it's too narrow, see vfio_intx_enable().
      
      Silently fails to convert hw/arm/armsse.c, because Coccinelle gets
      confused by ARMSSE being used both as typedef and function-like macro
      there.  Converted manually.
      
      Line breaks tidied up manually.  One nested declaration of @local_err
      deleted manually.  Preexisting unwanted blank line dropped in
      hw/riscv/sifive_e.c.
      
      Signed-off-by: default avatarMarkus Armbruster <armbru@redhat.com>
      Reviewed-by: default avatarEric Blake <eblake@redhat.com>
      Message-Id: <20200707160613.848843-35-armbru@redhat.com>
      668f62ec
  6. May 18, 2020
  7. May 08, 2020
  8. May 05, 2020
  9. Apr 30, 2020
  10. Mar 26, 2020
  11. Mar 16, 2020
  12. Oct 28, 2019
    • Hanna Reitz's avatar
      block: Add @exact parameter to bdrv_co_truncate() · c80d8b06
      Hanna Reitz authored
      
      We have two drivers (iscsi and file-posix) that (in some cases) return
      success from their .bdrv_co_truncate() implementation if the block
      device is larger than the requested offset, but cannot be shrunk.  Some
      callers do not want that behavior, so this patch adds a new parameter
      that they can use to turn off that behavior.
      
      This patch just adds the parameter and lets the block/io.c and
      block/block-backend.c functions pass it around.  All other callers
      always pass false and none of the implementations evaluate it, so that
      this patch does not change existing behavior.  Future patches take care
      of that.
      
      Suggested-by: default avatarMaxim Levitsky <mlevitsk@redhat.com>
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      Message-id: 20190918095144.955-5-mreitz@redhat.com
      Reviewed-by: default avatarMaxim Levitsky <mlevitsk@redhat.com>
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      c80d8b06
  13. Sep 03, 2019
    • Hanna Reitz's avatar
      vmdk: Reject invalid compressed writes · bedb8bb4
      Hanna Reitz authored
      
      Compressed writes generally have to write full clusters, not just in
      theory but also in practice when it comes to vmdk's streamOptimized
      subformat.  It currently is just silently broken for writes with
      non-zero in-cluster offsets:
      
      $ qemu-img create -f vmdk -o subformat=streamOptimized foo.vmdk 1M
      $ qemu-io -c 'write 4k 4k' -c 'read 4k 4k' foo.vmdk
      wrote 4096/4096 bytes at offset 4096
      4 KiB, 1 ops; 00.01 sec (443.724 KiB/sec and 110.9309 ops/sec)
      read failed: Invalid argument
      
      (The technical reason is that vmdk_write_extent() just writes the
      incomplete compressed data actually to offset 4k.  When reading the
      data, vmdk_read_extent() looks at offset 0 and finds the compressed data
      size to be 0, because that is what it reads from there.  This yields an
      error.)
      
      For incomplete writes with zero in-cluster offsets, the error path when
      reading the rest of the cluster is a bit different, but the result is
      the same:
      
      $ qemu-img create -f vmdk -o subformat=streamOptimized foo.vmdk 1M
      $ qemu-io -c 'write 0k 4k' -c 'read 4k 4k' foo.vmdk
      wrote 4096/4096 bytes at offset 0
      4 KiB, 1 ops; 00.01 sec (362.641 KiB/sec and 90.6603 ops/sec)
      read failed: Invalid argument
      
      (Here, vmdk_read_extent() finds the data and then sees that the
      uncompressed data is short.)
      
      It is better to reject invalid writes than to make the user believe they
      might have succeeded and then fail when trying to read it back.
      
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      Reviewed-by: default avatarJohn Snow <jsnow@redhat.com>
      Message-id: 20190815153638.4600-5-mreitz@redhat.com
      Reviewed-by: default avatarJohn Snow <jsnow@redhat.com>
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      bedb8bb4
    • Hanna Reitz's avatar
      vmdk: Use bdrv_dirname() for relative extent paths · cdc0dd25
      Hanna Reitz authored
      
      This makes iotest 033 pass with e.g. subformat=monolithicFlat.  It also
      turns a former error in 059 into success.
      
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      Message-id: 20190815153638.4600-3-mreitz@redhat.com
      Reviewed-by: default avatarJohn Snow <jsnow@redhat.com>
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      cdc0dd25
  14. Aug 19, 2019
  15. Jun 24, 2019
    • Sam Eiderman's avatar
      vmdk: Add read-only support for seSparse snapshots · 98eb9733
      Sam Eiderman authored
      Until ESXi 6.5 VMware used the vmfsSparse format for snapshots (VMDK3 in
      QEMU).
      
      This format was lacking in the following:
      
          * Grain directory (L1) and grain table (L2) entries were 32-bit,
            allowing access to only 2TB (slightly less) of data.
          * The grain size (default) was 512 bytes - leading to data
            fragmentation and many grain tables.
          * For space reclamation purposes, it was necessary to find all the
            grains which are not pointed to by any grain table - so a reverse
            mapping of "offset of grain in vmdk" to "grain table" must be
            constructed - which takes large amounts of CPU/RAM.
      
      The format specification can be found in VMware's documentation:
      https://www.vmware.com/support/developer/vddk/vmdk_50_technote.pdf
      
      
      
      In ESXi 6.5, to support snapshot files larger than 2TB, a new format was
      introduced: SESparse (Space Efficient).
      
      This format fixes the above issues:
      
          * All entries are now 64-bit.
          * The grain size (default) is 4KB.
          * Grain directory and grain tables are now located at the beginning
            of the file.
            + seSparse format reserves space for all grain tables.
            + Grain tables can be addressed using an index.
            + Grains are located in the end of the file and can also be
              addressed with an index.
            - seSparse vmdks of large disks (64TB) have huge preallocated
              headers - mainly due to L2 tables, even for empty snapshots.
          * The header contains a reverse mapping ("backmap") of "offset of
            grain in vmdk" to "grain table" and a bitmap ("free bitmap") which
            specifies for each grain - whether it is allocated or not.
            Using these data structures we can implement space reclamation
            efficiently.
          * Due to the fact that the header now maintains two mappings:
              * The regular one (grain directory & grain tables)
              * A reverse one (backmap and free bitmap)
            These data structures can lose consistency upon crash and result
            in a corrupted VMDK.
            Therefore, a journal is also added to the VMDK and is replayed
            when the VMware reopens the file after a crash.
      
      Since ESXi 6.7 - SESparse is the only snapshot format available.
      
      Unfortunately, VMware does not provide documentation regarding the new
      seSparse format.
      
      This commit is based on black-box research of the seSparse format.
      Various in-guest block operations and their effect on the snapshot file
      were tested.
      
      The only VMware provided source of information (regarding the underlying
      implementation) was a log file on the ESXi:
      
          /var/log/hostd.log
      
      Whenever an seSparse snapshot is created - the log is being populated
      with seSparse records.
      
      Relevant log records are of the form:
      
      [...] Const Header:
      [...]  constMagic     = 0xcafebabe
      [...]  version        = 2.1
      [...]  capacity       = 204800
      [...]  grainSize      = 8
      [...]  grainTableSize = 64
      [...]  flags          = 0
      [...] Extents:
      [...]  Header         : <1 : 1>
      [...]  JournalHdr     : <2 : 2>
      [...]  Journal        : <2048 : 2048>
      [...]  GrainDirectory : <4096 : 2048>
      [...]  GrainTables    : <6144 : 2048>
      [...]  FreeBitmap     : <8192 : 2048>
      [...]  BackMap        : <10240 : 2048>
      [...]  Grain          : <12288 : 204800>
      [...] Volatile Header:
      [...] volatileMagic     = 0xcafecafe
      [...] FreeGTNumber      = 0
      [...] nextTxnSeqNumber  = 0
      [...] replayJournal     = 0
      
      The sizes that are seen in the log file are in sectors.
      Extents are of the following format: <offset : size>
      
      This commit is a strict implementation which enforces:
          * magics
          * version number 2.1
          * grain size of 8 sectors  (4KB)
          * grain table size of 64 sectors
          * zero flags
          * extent locations
      
      Additionally, this commit proivdes only a subset of the functionality
      offered by seSparse's format:
          * Read-only
          * No journal replay
          * No space reclamation
          * No unmap support
      
      Hence, journal header, journal, free bitmap and backmap extents are
      unused, only the "classic" (L1 -> L2 -> data) grain access is
      implemented.
      
      However there are several differences in the grain access itself.
      Grain directory (L1):
          * Grain directory entries are indexes (not offsets) to grain
            tables.
          * Valid grain directory entries have their highest nibble set to
            0x1.
          * Since grain tables are always located in the beginning of the
            file - the index can fit into 32 bits - so we can use its low
            part if it's valid.
      Grain table (L2):
          * Grain table entries are indexes (not offsets) to grains.
          * If the highest nibble of the entry is:
              0x0:
                  The grain in not allocated.
                  The rest of the bytes are 0.
              0x1:
                  The grain is unmapped - guest sees a zero grain.
                  The rest of the bits point to the previously mapped grain,
                  see 0x3 case.
              0x2:
                  The grain is zero.
              0x3:
                  The grain is allocated - to get the index calculate:
                  ((entry & 0x0fff000000000000) >> 48) |
                  ((entry & 0x0000ffffffffffff) << 12)
          * The difference between 0x1 and 0x2 is that 0x1 is an unallocated
            grain which results from the guest using sg_unmap to unmap the
            grain - but the grain itself still exists in the grain extent - a
            space reclamation procedure should delete it.
            Unmapping a zero grain has no effect (0x2 will not change to 0x1)
            but unmapping an unallocated grain will (0x0 to 0x1) - naturally.
      
      In order to implement seSparse some fields had to be changed to support
      both 32-bit and 64-bit entry sizes.
      
      Reviewed-by: default avatarKarl Heubaum <karl.heubaum@oracle.com>
      Reviewed-by: default avatarEyal Moscovici <eyal.moscovici@oracle.com>
      Reviewed-by: default avatarArbel Moshe <arbel.moshe@oracle.com>
      Signed-off-by: default avatarSam Eiderman <shmuel.eiderman@oracle.com>
      Message-id: 20190620091057.47441-4-shmuel.eiderman@oracle.com
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      98eb9733
    • Sam Eiderman's avatar
      vmdk: Reduce the max bound for L1 table size · 59d6ee48
      Sam Eiderman authored
      
      512M of L1 entries is a very loose bound, only 32M are required to store
      the maximal supported VMDK file size of 2TB.
      
      Fixed qemu-iotest 59# - now failure occures before on impossible L1
      table size.
      
      Reviewed-by: default avatarKarl Heubaum <karl.heubaum@oracle.com>
      Reviewed-by: default avatarEyal Moscovici <eyal.moscovici@oracle.com>
      Reviewed-by: default avatarLiran Alon <liran.alon@oracle.com>
      Reviewed-by: default avatarArbel Moshe <arbel.moshe@oracle.com>
      Signed-off-by: default avatarSam Eiderman <shmuel.eiderman@oracle.com>
      Message-id: 20190620091057.47441-3-shmuel.eiderman@oracle.com
      Reviewed-by: default avatarMax Reitz <mreitz@redhat.com>
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      59d6ee48
    • Sam Eiderman's avatar
      vmdk: Fix comment regarding max l1_size coverage · 940a2cd5
      Sam Eiderman authored
      
      Commit b0651b8c ("vmdk: Move l1_size check into vmdk_add_extent")
      extended the l1_size check from VMDK4 to VMDK3 but did not update the
      default coverage in the moved comment.
      
      The previous vmdk4 calculation:
      
          (512 * 1024 * 1024) * 512(l2 entries) * 65536(grain) = 16PB
      
      The added vmdk3 calculation:
      
          (512 * 1024 * 1024) * 4096(l2 entries) * 512(grain) = 1PB
      
      Adding the calculation of vmdk3 to the comment.
      
      In any case, VMware does not offer virtual disks more than 2TB for
      vmdk4/vmdk3 or 64TB for the new undocumented seSparse format which is
      not implemented yet in qemu.
      
      Reviewed-by: default avatarKarl Heubaum <karl.heubaum@oracle.com>
      Reviewed-by: default avatarEyal Moscovici <eyal.moscovici@oracle.com>
      Reviewed-by: default avatarLiran Alon <liran.alon@oracle.com>
      Reviewed-by: default avatarArbel Moshe <arbel.moshe@oracle.com>
      Signed-off-by: default avatarSam Eiderman <shmuel.eiderman@oracle.com>
      Message-id: 20190620091057.47441-2-shmuel.eiderman@oracle.com
      Reviewed-by: default avataryuchenlin <yuchenlin@synology.com>
      Reviewed-by: default avatarMax Reitz <mreitz@redhat.com>
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      940a2cd5
  16. Jun 04, 2019
    • Kevin Wolf's avatar
      block: Add BlockBackend.ctx · d861ab3a
      Kevin Wolf authored
      
      This adds a new parameter to blk_new() which requires its callers to
      declare from which AioContext this BlockBackend is going to be used (or
      the locks of which AioContext need to be taken anyway).
      
      The given context is only stored and kept up to date when changing
      AioContexts. Actually applying the stored AioContext to the root node
      is saved for another commit.
      
      Signed-off-by: default avatarKevin Wolf <kwolf@redhat.com>
      d861ab3a
  17. Apr 30, 2019
  18. Mar 19, 2019
  19. Feb 25, 2019
    • Yu-Chen Lin's avatar
      vmdk: false positive of compat6 with hwversion not set · 26c9296c
      Yu-Chen Lin authored
      
      In vmdk_co_create_opts, when it finds hw_version is undefined, it will
      set it to 4, which misleading the compat6 and hwversion in
      vmdk_co_do_create. Simply set hw_version to NULL after free, let
      the logic in vmdk_co_do_create to decide the value of hw_version.
      
      This bug can be reproduced by:
      
      $ qemu-img convert -O vmdk -o subformat=streamOptimized,compat6
      /home/yuchenlin/syno.qcow2 /home/yuchenlin/syno.vmdk
      
      qemu-img: /home/yuchenlin/syno.vmdk: error while converting vmdk:
      compat6 cannot be enabled with hwversion set
      
      Signed-off-by: default avataryuchenlin <yuchenlin@synology.com>
      Message-id: 20190221110805.28239-1-yuchenlin@synology.com
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      26c9296c
    • Hanna Reitz's avatar
      block: Add BlockDriver.bdrv_gather_child_options · abc521a9
      Hanna Reitz authored
      
      Some follow-up patches will rework the way bs->full_open_options is
      refreshed in bdrv_refresh_filename(). The new implementation will remove
      the need for the block drivers' bdrv_refresh_filename() implementations
      to set bs->full_open_options; instead, it will be generic and use static
      information from each block driver.
      
      However, by implementing bdrv_gather_child_options(), block drivers will
      still be able to override the way the full_open_options of their
      children are incorporated into their own.
      
      We need to implement this function for VMDK because we have to prevent
      the generic implementation from gathering the options of all children:
      It is not possible to specify options for the extents through the
      runtime options.
      
      For quorum, the child names that would be used by the generic
      implementation and the ones that we actually (currently) want to use
      differ. See quorum_gather_child_options() for more information.
      
      Note that both of these are cases which are not ideal: In case of VMDK
      it would probably be nice to be able to specify options for all extents.
      In case of quorum, the current runtime option structure is simply broken
      and needs to be fixed (but that is left for another patch).
      
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      Reviewed-by: default avatarAlberto Garcia <berto@igalia.com>
      Message-id: 20190201192935.18394-23-mreitz@redhat.com
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      abc521a9
    • Hanna Reitz's avatar
      block: bdrv_get_full_backing_filename_from_...'s ret. val. · 645ae7d8
      Hanna Reitz authored
      
      Make bdrv_get_full_backing_filename_from_filename() return an allocated
      string instead of placing the result in a caller-provided buffer.
      
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      Message-id: 20190201192935.18394-11-mreitz@redhat.com
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      645ae7d8
    • Hanna Reitz's avatar
      block: Make path_combine() return the path · 009b03aa
      Hanna Reitz authored
      
      Besides being safe for arbitrary path lengths, after some follow-up
      patches all callers will want a freshly allocated buffer anyway.
      
      In the meantime, path_combine_deprecated() is added which has the same
      interface as path_combine() had before this patch. All callers to that
      function will be converted in follow-up patches.
      
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      Reviewed-by: default avatarAlberto Garcia <berto@igalia.com>
      Reviewed-by: default avatarKevin Wolf <kwolf@redhat.com>
      Message-id: 20190201192935.18394-10-mreitz@redhat.com
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      009b03aa
    • Hanna Reitz's avatar
      block: Add BDS.auto_backing_file · 998c2019
      Hanna Reitz authored
      
      If the backing file is overridden, this most probably does change the
      guest-visible data of a BDS.  Therefore, we will need to consider this
      in bdrv_refresh_filename().
      
      To see whether it has been overridden, we might want to compare
      bs->backing_file and bs->backing->bs->filename.  However,
      bs->backing_file is changed by bdrv_set_backing_hd() (which is just used
      to change the backing child at runtime, without modifying the image
      header), so bs->backing_file most of the time simply contains a copy of
      bs->backing->bs->filename anyway, so it is useless for such a
      comparison.
      
      This patch adds an auto_backing_file BDS field which contains the
      backing file path as indicated by the image header, which is not changed
      by bdrv_set_backing_hd().
      
      Because of bdrv_refresh_filename() magic, however, a BDS's filename may
      differ from what has been specified during bdrv_open().  Then, the
      comparison between bs->auto_backing_file and bs->backing->bs->filename
      may fail even though bs->backing was opened from bs->auto_backing_file.
      To mitigate this, we can copy the real BDS's filename (after the whole
      bdrv_open() and bdrv_refresh_filename() process) into
      bs->auto_backing_file, if we know the former has been opened based on
      the latter.  This is only possible if no options modifying the backing
      file's behavior have been specified, though.  To simplify things, this
      patch only copies the filename from the backing file if no options have
      been specified for it at all.
      
      Furthermore, there are cases where an overlay is created by qemu which
      already contains a BDS's filename (e.g. in blockdev-snapshot-sync).  We
      do not need to worry about updating the overlay's bs->auto_backing_file
      there, because we actually wrote a post-bdrv_refresh_filename() filename
      into the image header.
      
      So all in all, there will be false negatives where (as of a future
      patch) bdrv_refresh_filename() will assume that the backing file differs
      from what was specified in the image header, even though it really does
      not.  However, these cases should be limited to where (1) the user
      actually did override something in the backing chain (e.g. by specifying
      options for the backing file), or (2) the user executed a QMP command to
      change some node's backing file (e.g. change-backing-file or
      block-commit with @backing-file given) where the given filename does not
      happen to coincide with qemu's idea of the backing BDS's filename.
      
      Then again, (1) really is limited to -drive.  With -blockdev or
      blockdev-add, you have to adhere to the schema, so a user cannot give
      partial "unimportant" options (e.g. by just setting backing.node-name
      and leaving the rest to the image header).  Therefore, trying to fix
      this would mean trying to fix something for -drive only.
      
      To improve on (2), we would need a full infrastructure to "canonicalize"
      an arbitrary filename (+ options), so it can be compared against
      another.  That seems a bit over the top, considering that filenames
      nowadays are there mostly for the user's entertainment.
      
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      Reviewed-by: default avatarEric Blake <eblake@redhat.com>
      Reviewed-by: default avatarAlberto Garcia <berto@igalia.com>
      Message-id: 20190201192935.18394-5-mreitz@redhat.com
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      998c2019
    • Hanna Reitz's avatar
      block: Use bdrv_refresh_filename() to pull · f30c66ba
      Hanna Reitz authored
      
      Before this patch, bdrv_refresh_filename() is used in a pushing manner:
      Whenever the BDS graph is modified, the parents of the modified edges
      are supposed to be updated (recursively upwards).  However, that is
      nonviable, considering that we want child changes not to concern
      parents.
      
      Also, in the long run we want a pull model anyway: Here, we would have a
      bdrv_filename() function which returns a BDS's filename, freshly
      constructed.
      
      This patch is an intermediate step.  It adds bdrv_refresh_filename()
      calls before every place a BDS.filename value is used.  The only
      exceptions are protocol drivers that use their own filename, which
      clearly would not profit from refreshing that filename before.
      
      Also, bdrv_get_encrypted_filename() is removed along the way (as a user
      of BDS.filename), since it is completely unused.
      
      In turn, all of the calls to bdrv_refresh_filename() before this patch
      are removed, because we no longer have to call this function on graph
      changes.
      
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      Message-id: 20190201192935.18394-2-mreitz@redhat.com
      Reviewed-by: default avatarEric Blake <eblake@redhat.com>
      Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
      f30c66ba
  20. Feb 22, 2019
  21. Feb 11, 2019
  22. Feb 01, 2019
Loading