xref: /qemu/block/qcow2.c (revision 87b86e7ef29771a7fa06e3e8e88fa95bbc13a39c)
1585f8587Sbellard /*
2585f8587Sbellard  * Block driver for the QCOW version 2 format
3585f8587Sbellard  *
4585f8587Sbellard  * Copyright (c) 2004-2006 Fabrice Bellard
5585f8587Sbellard  *
6585f8587Sbellard  * Permission is hereby granted, free of charge, to any person obtaining a copy
7585f8587Sbellard  * of this software and associated documentation files (the "Software"), to deal
8585f8587Sbellard  * in the Software without restriction, including without limitation the rights
9585f8587Sbellard  * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
10585f8587Sbellard  * copies of the Software, and to permit persons to whom the Software is
11585f8587Sbellard  * furnished to do so, subject to the following conditions:
12585f8587Sbellard  *
13585f8587Sbellard  * The above copyright notice and this permission notice shall be included in
14585f8587Sbellard  * all copies or substantial portions of the Software.
15585f8587Sbellard  *
16585f8587Sbellard  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
17585f8587Sbellard  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
18585f8587Sbellard  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
19585f8587Sbellard  * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
20585f8587Sbellard  * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
21585f8587Sbellard  * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
22585f8587Sbellard  * THE SOFTWARE.
23585f8587Sbellard  */
24faf07963Spbrook #include "qemu-common.h"
25737e150eSPaolo Bonzini #include "block/block_int.h"
261de7afc9SPaolo Bonzini #include "qemu/module.h"
27585f8587Sbellard #include <zlib.h>
28753d9b82SAurelien Jarno #include "qemu/aes.h"
29f7d0fe02SKevin Wolf #include "block/qcow2.h"
301de7afc9SPaolo Bonzini #include "qemu/error-report.h"
317b1b5d19SPaolo Bonzini #include "qapi/qmp/qerror.h"
32acdfb480SKevin Wolf #include "qapi/qmp/qbool.h"
33ffeaac9bSHu Tao #include "qapi/util.h"
3485186ebdSMax Reitz #include "qapi/qmp/types.h"
3585186ebdSMax Reitz #include "qapi-event.h"
363cce16f4SKevin Wolf #include "trace.h"
371bd0e2d1SChunyan Liu #include "qemu/option_int.h"
38585f8587Sbellard 
39585f8587Sbellard /*
40585f8587Sbellard   Differences with QCOW:
41585f8587Sbellard 
42585f8587Sbellard   - Support for multiple incremental snapshots.
43585f8587Sbellard   - Memory management by reference counts.
44585f8587Sbellard   - Clusters which have a reference count of one have the bit
45585f8587Sbellard     QCOW_OFLAG_COPIED to optimize write performance.
46585f8587Sbellard   - Size of compressed clusters is stored in sectors to reduce bit usage
47585f8587Sbellard     in the cluster offsets.
48585f8587Sbellard   - Support for storing additional data (such as the VM state) in the
49585f8587Sbellard     snapshots.
50585f8587Sbellard   - If a backing store is used, the cluster size is not constrained
51585f8587Sbellard     (could be backported to QCOW).
52585f8587Sbellard   - L2 tables have always a size of one cluster.
53585f8587Sbellard */
54585f8587Sbellard 
559b80ddf3Saliguori 
569b80ddf3Saliguori typedef struct {
579b80ddf3Saliguori     uint32_t magic;
589b80ddf3Saliguori     uint32_t len;
59c4217f64SJeff Cody } QEMU_PACKED QCowExtension;
6021d82ac9SJeff Cody 
617c80ab3fSJes Sorensen #define  QCOW2_EXT_MAGIC_END 0
627c80ab3fSJes Sorensen #define  QCOW2_EXT_MAGIC_BACKING_FORMAT 0xE2792ACA
63cfcc4c62SKevin Wolf #define  QCOW2_EXT_MAGIC_FEATURE_TABLE 0x6803f857
649b80ddf3Saliguori 
657c80ab3fSJes Sorensen static int qcow2_probe(const uint8_t *buf, int buf_size, const char *filename)
66585f8587Sbellard {
67585f8587Sbellard     const QCowHeader *cow_header = (const void *)buf;
68585f8587Sbellard 
69585f8587Sbellard     if (buf_size >= sizeof(QCowHeader) &&
70585f8587Sbellard         be32_to_cpu(cow_header->magic) == QCOW_MAGIC &&
716744cbabSKevin Wolf         be32_to_cpu(cow_header->version) >= 2)
72585f8587Sbellard         return 100;
73585f8587Sbellard     else
74585f8587Sbellard         return 0;
75585f8587Sbellard }
76585f8587Sbellard 
779b80ddf3Saliguori 
789b80ddf3Saliguori /*
799b80ddf3Saliguori  * read qcow2 extension and fill bs
809b80ddf3Saliguori  * start reading from start_offset
819b80ddf3Saliguori  * finish reading upon magic of value 0 or when end_offset reached
829b80ddf3Saliguori  * unknown magic is skipped (future extension this version knows nothing about)
839b80ddf3Saliguori  * return 0 upon success, non-0 otherwise
849b80ddf3Saliguori  */
857c80ab3fSJes Sorensen static int qcow2_read_extensions(BlockDriverState *bs, uint64_t start_offset,
863ef6c40aSMax Reitz                                  uint64_t end_offset, void **p_feature_table,
873ef6c40aSMax Reitz                                  Error **errp)
889b80ddf3Saliguori {
8975bab85cSKevin Wolf     BDRVQcowState *s = bs->opaque;
909b80ddf3Saliguori     QCowExtension ext;
919b80ddf3Saliguori     uint64_t offset;
9275bab85cSKevin Wolf     int ret;
939b80ddf3Saliguori 
949b80ddf3Saliguori #ifdef DEBUG_EXT
957c80ab3fSJes Sorensen     printf("qcow2_read_extensions: start=%ld end=%ld\n", start_offset, end_offset);
969b80ddf3Saliguori #endif
979b80ddf3Saliguori     offset = start_offset;
989b80ddf3Saliguori     while (offset < end_offset) {
999b80ddf3Saliguori 
1009b80ddf3Saliguori #ifdef DEBUG_EXT
1019b80ddf3Saliguori         /* Sanity check */
1029b80ddf3Saliguori         if (offset > s->cluster_size)
1037c80ab3fSJes Sorensen             printf("qcow2_read_extension: suspicious offset %lu\n", offset);
1049b80ddf3Saliguori 
1059b2260cbSDong Xu Wang         printf("attempting to read extended header in offset %lu\n", offset);
1069b80ddf3Saliguori #endif
1079b80ddf3Saliguori 
1083ef6c40aSMax Reitz         ret = bdrv_pread(bs->file, offset, &ext, sizeof(ext));
1093ef6c40aSMax Reitz         if (ret < 0) {
1103ef6c40aSMax Reitz             error_setg_errno(errp, -ret, "qcow2_read_extension: ERROR: "
1113ef6c40aSMax Reitz                              "pread fail from offset %" PRIu64, offset);
1129b80ddf3Saliguori             return 1;
1139b80ddf3Saliguori         }
1149b80ddf3Saliguori         be32_to_cpus(&ext.magic);
1159b80ddf3Saliguori         be32_to_cpus(&ext.len);
1169b80ddf3Saliguori         offset += sizeof(ext);
1179b80ddf3Saliguori #ifdef DEBUG_EXT
1189b80ddf3Saliguori         printf("ext.magic = 0x%x\n", ext.magic);
1199b80ddf3Saliguori #endif
1202ebafc85SKevin Wolf         if (offset > end_offset || ext.len > end_offset - offset) {
1213ef6c40aSMax Reitz             error_setg(errp, "Header extension too large");
12264ca6aeeSKevin Wolf             return -EINVAL;
12364ca6aeeSKevin Wolf         }
12464ca6aeeSKevin Wolf 
1259b80ddf3Saliguori         switch (ext.magic) {
1267c80ab3fSJes Sorensen         case QCOW2_EXT_MAGIC_END:
1279b80ddf3Saliguori             return 0;
128f965509cSaliguori 
1297c80ab3fSJes Sorensen         case QCOW2_EXT_MAGIC_BACKING_FORMAT:
130f965509cSaliguori             if (ext.len >= sizeof(bs->backing_format)) {
131521b2b5dSMax Reitz                 error_setg(errp, "ERROR: ext_backing_format: len=%" PRIu32
132521b2b5dSMax Reitz                            " too large (>=%zu)", ext.len,
133521b2b5dSMax Reitz                            sizeof(bs->backing_format));
134f965509cSaliguori                 return 2;
135f965509cSaliguori             }
1363ef6c40aSMax Reitz             ret = bdrv_pread(bs->file, offset, bs->backing_format, ext.len);
1373ef6c40aSMax Reitz             if (ret < 0) {
1383ef6c40aSMax Reitz                 error_setg_errno(errp, -ret, "ERROR: ext_backing_format: "
1393ef6c40aSMax Reitz                                  "Could not read format name");
140f965509cSaliguori                 return 3;
1413ef6c40aSMax Reitz             }
142f965509cSaliguori             bs->backing_format[ext.len] = '\0';
143f965509cSaliguori #ifdef DEBUG_EXT
144f965509cSaliguori             printf("Qcow2: Got format extension %s\n", bs->backing_format);
145f965509cSaliguori #endif
146f965509cSaliguori             break;
147f965509cSaliguori 
148cfcc4c62SKevin Wolf         case QCOW2_EXT_MAGIC_FEATURE_TABLE:
149cfcc4c62SKevin Wolf             if (p_feature_table != NULL) {
150cfcc4c62SKevin Wolf                 void* feature_table = g_malloc0(ext.len + 2 * sizeof(Qcow2Feature));
151cfcc4c62SKevin Wolf                 ret = bdrv_pread(bs->file, offset , feature_table, ext.len);
152cfcc4c62SKevin Wolf                 if (ret < 0) {
1533ef6c40aSMax Reitz                     error_setg_errno(errp, -ret, "ERROR: ext_feature_table: "
1543ef6c40aSMax Reitz                                      "Could not read table");
155cfcc4c62SKevin Wolf                     return ret;
156cfcc4c62SKevin Wolf                 }
157cfcc4c62SKevin Wolf 
158cfcc4c62SKevin Wolf                 *p_feature_table = feature_table;
159cfcc4c62SKevin Wolf             }
160cfcc4c62SKevin Wolf             break;
161cfcc4c62SKevin Wolf 
1629b80ddf3Saliguori         default:
16375bab85cSKevin Wolf             /* unknown magic - save it in case we need to rewrite the header */
16475bab85cSKevin Wolf             {
16575bab85cSKevin Wolf                 Qcow2UnknownHeaderExtension *uext;
16675bab85cSKevin Wolf 
16775bab85cSKevin Wolf                 uext = g_malloc0(sizeof(*uext)  + ext.len);
16875bab85cSKevin Wolf                 uext->magic = ext.magic;
16975bab85cSKevin Wolf                 uext->len = ext.len;
17075bab85cSKevin Wolf                 QLIST_INSERT_HEAD(&s->unknown_header_ext, uext, next);
17175bab85cSKevin Wolf 
17275bab85cSKevin Wolf                 ret = bdrv_pread(bs->file, offset , uext->data, uext->len);
17375bab85cSKevin Wolf                 if (ret < 0) {
1743ef6c40aSMax Reitz                     error_setg_errno(errp, -ret, "ERROR: unknown extension: "
1753ef6c40aSMax Reitz                                      "Could not read data");
17675bab85cSKevin Wolf                     return ret;
17775bab85cSKevin Wolf                 }
17875bab85cSKevin Wolf             }
1799b80ddf3Saliguori             break;
1809b80ddf3Saliguori         }
181fd29b4bbSKevin Wolf 
182fd29b4bbSKevin Wolf         offset += ((ext.len + 7) & ~7);
1839b80ddf3Saliguori     }
1849b80ddf3Saliguori 
1859b80ddf3Saliguori     return 0;
1869b80ddf3Saliguori }
1879b80ddf3Saliguori 
18875bab85cSKevin Wolf static void cleanup_unknown_header_ext(BlockDriverState *bs)
18975bab85cSKevin Wolf {
19075bab85cSKevin Wolf     BDRVQcowState *s = bs->opaque;
19175bab85cSKevin Wolf     Qcow2UnknownHeaderExtension *uext, *next;
19275bab85cSKevin Wolf 
19375bab85cSKevin Wolf     QLIST_FOREACH_SAFE(uext, &s->unknown_header_ext, next, next) {
19475bab85cSKevin Wolf         QLIST_REMOVE(uext, next);
19575bab85cSKevin Wolf         g_free(uext);
19675bab85cSKevin Wolf     }
19775bab85cSKevin Wolf }
1989b80ddf3Saliguori 
1993ef6c40aSMax Reitz static void GCC_FMT_ATTR(3, 4) report_unsupported(BlockDriverState *bs,
2003ef6c40aSMax Reitz     Error **errp, const char *fmt, ...)
2016744cbabSKevin Wolf {
2026744cbabSKevin Wolf     char msg[64];
2036744cbabSKevin Wolf     va_list ap;
2046744cbabSKevin Wolf 
2056744cbabSKevin Wolf     va_start(ap, fmt);
2066744cbabSKevin Wolf     vsnprintf(msg, sizeof(msg), fmt, ap);
2076744cbabSKevin Wolf     va_end(ap);
2086744cbabSKevin Wolf 
209bfb197e0SMarkus Armbruster     error_set(errp, QERR_UNKNOWN_BLOCK_FORMAT_FEATURE,
210bfb197e0SMarkus Armbruster               bdrv_get_device_name(bs), "qcow2", msg);
2116744cbabSKevin Wolf }
2126744cbabSKevin Wolf 
213cfcc4c62SKevin Wolf static void report_unsupported_feature(BlockDriverState *bs,
2143ef6c40aSMax Reitz     Error **errp, Qcow2Feature *table, uint64_t mask)
215cfcc4c62SKevin Wolf {
21612ac6d3dSKevin Wolf     char *features = g_strdup("");
21712ac6d3dSKevin Wolf     char *old;
21812ac6d3dSKevin Wolf 
219cfcc4c62SKevin Wolf     while (table && table->name[0] != '\0') {
220cfcc4c62SKevin Wolf         if (table->type == QCOW2_FEAT_TYPE_INCOMPATIBLE) {
22112ac6d3dSKevin Wolf             if (mask & (1ULL << table->bit)) {
22212ac6d3dSKevin Wolf                 old = features;
22312ac6d3dSKevin Wolf                 features = g_strdup_printf("%s%s%.46s", old, *old ? ", " : "",
22412ac6d3dSKevin Wolf                                            table->name);
22512ac6d3dSKevin Wolf                 g_free(old);
22612ac6d3dSKevin Wolf                 mask &= ~(1ULL << table->bit);
227cfcc4c62SKevin Wolf             }
228cfcc4c62SKevin Wolf         }
229cfcc4c62SKevin Wolf         table++;
230cfcc4c62SKevin Wolf     }
231cfcc4c62SKevin Wolf 
232cfcc4c62SKevin Wolf     if (mask) {
23312ac6d3dSKevin Wolf         old = features;
23412ac6d3dSKevin Wolf         features = g_strdup_printf("%s%sUnknown incompatible feature: %" PRIx64,
23512ac6d3dSKevin Wolf                                    old, *old ? ", " : "", mask);
23612ac6d3dSKevin Wolf         g_free(old);
237cfcc4c62SKevin Wolf     }
23812ac6d3dSKevin Wolf 
23912ac6d3dSKevin Wolf     report_unsupported(bs, errp, "%s", features);
24012ac6d3dSKevin Wolf     g_free(features);
241cfcc4c62SKevin Wolf }
242cfcc4c62SKevin Wolf 
243c61d0004SStefan Hajnoczi /*
244bfe8043eSStefan Hajnoczi  * Sets the dirty bit and flushes afterwards if necessary.
245bfe8043eSStefan Hajnoczi  *
246bfe8043eSStefan Hajnoczi  * The incompatible_features bit is only set if the image file header was
247bfe8043eSStefan Hajnoczi  * updated successfully.  Therefore it is not required to check the return
248bfe8043eSStefan Hajnoczi  * value of this function.
249bfe8043eSStefan Hajnoczi  */
250280d3735SKevin Wolf int qcow2_mark_dirty(BlockDriverState *bs)
251bfe8043eSStefan Hajnoczi {
252bfe8043eSStefan Hajnoczi     BDRVQcowState *s = bs->opaque;
253bfe8043eSStefan Hajnoczi     uint64_t val;
254bfe8043eSStefan Hajnoczi     int ret;
255bfe8043eSStefan Hajnoczi 
256bfe8043eSStefan Hajnoczi     assert(s->qcow_version >= 3);
257bfe8043eSStefan Hajnoczi 
258bfe8043eSStefan Hajnoczi     if (s->incompatible_features & QCOW2_INCOMPAT_DIRTY) {
259bfe8043eSStefan Hajnoczi         return 0; /* already dirty */
260bfe8043eSStefan Hajnoczi     }
261bfe8043eSStefan Hajnoczi 
262bfe8043eSStefan Hajnoczi     val = cpu_to_be64(s->incompatible_features | QCOW2_INCOMPAT_DIRTY);
263bfe8043eSStefan Hajnoczi     ret = bdrv_pwrite(bs->file, offsetof(QCowHeader, incompatible_features),
264bfe8043eSStefan Hajnoczi                       &val, sizeof(val));
265bfe8043eSStefan Hajnoczi     if (ret < 0) {
266bfe8043eSStefan Hajnoczi         return ret;
267bfe8043eSStefan Hajnoczi     }
268bfe8043eSStefan Hajnoczi     ret = bdrv_flush(bs->file);
269bfe8043eSStefan Hajnoczi     if (ret < 0) {
270bfe8043eSStefan Hajnoczi         return ret;
271bfe8043eSStefan Hajnoczi     }
272bfe8043eSStefan Hajnoczi 
273bfe8043eSStefan Hajnoczi     /* Only treat image as dirty if the header was updated successfully */
274bfe8043eSStefan Hajnoczi     s->incompatible_features |= QCOW2_INCOMPAT_DIRTY;
275bfe8043eSStefan Hajnoczi     return 0;
276bfe8043eSStefan Hajnoczi }
277bfe8043eSStefan Hajnoczi 
278bfe8043eSStefan Hajnoczi /*
279c61d0004SStefan Hajnoczi  * Clears the dirty bit and flushes before if necessary.  Only call this
280c61d0004SStefan Hajnoczi  * function when there are no pending requests, it does not guard against
281c61d0004SStefan Hajnoczi  * concurrent requests dirtying the image.
282c61d0004SStefan Hajnoczi  */
283c61d0004SStefan Hajnoczi static int qcow2_mark_clean(BlockDriverState *bs)
284c61d0004SStefan Hajnoczi {
285c61d0004SStefan Hajnoczi     BDRVQcowState *s = bs->opaque;
286c61d0004SStefan Hajnoczi 
287c61d0004SStefan Hajnoczi     if (s->incompatible_features & QCOW2_INCOMPAT_DIRTY) {
2884c2e5f8fSKevin Wolf         int ret;
2894c2e5f8fSKevin Wolf 
2904c2e5f8fSKevin Wolf         s->incompatible_features &= ~QCOW2_INCOMPAT_DIRTY;
2914c2e5f8fSKevin Wolf 
2924c2e5f8fSKevin Wolf         ret = bdrv_flush(bs);
293c61d0004SStefan Hajnoczi         if (ret < 0) {
294c61d0004SStefan Hajnoczi             return ret;
295c61d0004SStefan Hajnoczi         }
296c61d0004SStefan Hajnoczi 
297c61d0004SStefan Hajnoczi         return qcow2_update_header(bs);
298c61d0004SStefan Hajnoczi     }
299c61d0004SStefan Hajnoczi     return 0;
300c61d0004SStefan Hajnoczi }
301c61d0004SStefan Hajnoczi 
30269c98726SMax Reitz /*
30369c98726SMax Reitz  * Marks the image as corrupt.
30469c98726SMax Reitz  */
30569c98726SMax Reitz int qcow2_mark_corrupt(BlockDriverState *bs)
30669c98726SMax Reitz {
30769c98726SMax Reitz     BDRVQcowState *s = bs->opaque;
30869c98726SMax Reitz 
30969c98726SMax Reitz     s->incompatible_features |= QCOW2_INCOMPAT_CORRUPT;
31069c98726SMax Reitz     return qcow2_update_header(bs);
31169c98726SMax Reitz }
31269c98726SMax Reitz 
31369c98726SMax Reitz /*
31469c98726SMax Reitz  * Marks the image as consistent, i.e., unsets the corrupt bit, and flushes
31569c98726SMax Reitz  * before if necessary.
31669c98726SMax Reitz  */
31769c98726SMax Reitz int qcow2_mark_consistent(BlockDriverState *bs)
31869c98726SMax Reitz {
31969c98726SMax Reitz     BDRVQcowState *s = bs->opaque;
32069c98726SMax Reitz 
32169c98726SMax Reitz     if (s->incompatible_features & QCOW2_INCOMPAT_CORRUPT) {
32269c98726SMax Reitz         int ret = bdrv_flush(bs);
32369c98726SMax Reitz         if (ret < 0) {
32469c98726SMax Reitz             return ret;
32569c98726SMax Reitz         }
32669c98726SMax Reitz 
32769c98726SMax Reitz         s->incompatible_features &= ~QCOW2_INCOMPAT_CORRUPT;
32869c98726SMax Reitz         return qcow2_update_header(bs);
32969c98726SMax Reitz     }
33069c98726SMax Reitz     return 0;
33169c98726SMax Reitz }
33269c98726SMax Reitz 
333acbe5982SStefan Hajnoczi static int qcow2_check(BlockDriverState *bs, BdrvCheckResult *result,
334acbe5982SStefan Hajnoczi                        BdrvCheckMode fix)
335acbe5982SStefan Hajnoczi {
336acbe5982SStefan Hajnoczi     int ret = qcow2_check_refcounts(bs, result, fix);
337acbe5982SStefan Hajnoczi     if (ret < 0) {
338acbe5982SStefan Hajnoczi         return ret;
339acbe5982SStefan Hajnoczi     }
340acbe5982SStefan Hajnoczi 
341acbe5982SStefan Hajnoczi     if (fix && result->check_errors == 0 && result->corruptions == 0) {
34224530f3eSMax Reitz         ret = qcow2_mark_clean(bs);
34324530f3eSMax Reitz         if (ret < 0) {
34424530f3eSMax Reitz             return ret;
34524530f3eSMax Reitz         }
34624530f3eSMax Reitz         return qcow2_mark_consistent(bs);
347acbe5982SStefan Hajnoczi     }
348acbe5982SStefan Hajnoczi     return ret;
349acbe5982SStefan Hajnoczi }
350acbe5982SStefan Hajnoczi 
3518c7de283SKevin Wolf static int validate_table_offset(BlockDriverState *bs, uint64_t offset,
3528c7de283SKevin Wolf                                  uint64_t entries, size_t entry_len)
3538c7de283SKevin Wolf {
3548c7de283SKevin Wolf     BDRVQcowState *s = bs->opaque;
3558c7de283SKevin Wolf     uint64_t size;
3568c7de283SKevin Wolf 
3578c7de283SKevin Wolf     /* Use signed INT64_MAX as the maximum even for uint64_t header fields,
3588c7de283SKevin Wolf      * because values will be passed to qemu functions taking int64_t. */
3598c7de283SKevin Wolf     if (entries > INT64_MAX / entry_len) {
3608c7de283SKevin Wolf         return -EINVAL;
3618c7de283SKevin Wolf     }
3628c7de283SKevin Wolf 
3638c7de283SKevin Wolf     size = entries * entry_len;
3648c7de283SKevin Wolf 
3658c7de283SKevin Wolf     if (INT64_MAX - size < offset) {
3668c7de283SKevin Wolf         return -EINVAL;
3678c7de283SKevin Wolf     }
3688c7de283SKevin Wolf 
3698c7de283SKevin Wolf     /* Tables must be cluster aligned */
3708c7de283SKevin Wolf     if (offset & (s->cluster_size - 1)) {
3718c7de283SKevin Wolf         return -EINVAL;
3728c7de283SKevin Wolf     }
3738c7de283SKevin Wolf 
3748c7de283SKevin Wolf     return 0;
3758c7de283SKevin Wolf }
3768c7de283SKevin Wolf 
37774c4510aSKevin Wolf static QemuOptsList qcow2_runtime_opts = {
37874c4510aSKevin Wolf     .name = "qcow2",
37974c4510aSKevin Wolf     .head = QTAILQ_HEAD_INITIALIZER(qcow2_runtime_opts.head),
38074c4510aSKevin Wolf     .desc = {
38174c4510aSKevin Wolf         {
38264aa99d3SKevin Wolf             .name = QCOW2_OPT_LAZY_REFCOUNTS,
38374c4510aSKevin Wolf             .type = QEMU_OPT_BOOL,
38474c4510aSKevin Wolf             .help = "Postpone refcount updates",
38574c4510aSKevin Wolf         },
38667af674eSKevin Wolf         {
38767af674eSKevin Wolf             .name = QCOW2_OPT_DISCARD_REQUEST,
38867af674eSKevin Wolf             .type = QEMU_OPT_BOOL,
38967af674eSKevin Wolf             .help = "Pass guest discard requests to the layer below",
39067af674eSKevin Wolf         },
39167af674eSKevin Wolf         {
39267af674eSKevin Wolf             .name = QCOW2_OPT_DISCARD_SNAPSHOT,
39367af674eSKevin Wolf             .type = QEMU_OPT_BOOL,
39467af674eSKevin Wolf             .help = "Generate discard requests when snapshot related space "
39567af674eSKevin Wolf                     "is freed",
39667af674eSKevin Wolf         },
39767af674eSKevin Wolf         {
39867af674eSKevin Wolf             .name = QCOW2_OPT_DISCARD_OTHER,
39967af674eSKevin Wolf             .type = QEMU_OPT_BOOL,
40067af674eSKevin Wolf             .help = "Generate discard requests when other clusters are freed",
40167af674eSKevin Wolf         },
40205de7e86SMax Reitz         {
40305de7e86SMax Reitz             .name = QCOW2_OPT_OVERLAP,
40405de7e86SMax Reitz             .type = QEMU_OPT_STRING,
40505de7e86SMax Reitz             .help = "Selects which overlap checks to perform from a range of "
40605de7e86SMax Reitz                     "templates (none, constant, cached, all)",
40705de7e86SMax Reitz         },
40805de7e86SMax Reitz         {
409ee42b5ceSMax Reitz             .name = QCOW2_OPT_OVERLAP_TEMPLATE,
410ee42b5ceSMax Reitz             .type = QEMU_OPT_STRING,
411ee42b5ceSMax Reitz             .help = "Selects which overlap checks to perform from a range of "
412ee42b5ceSMax Reitz                     "templates (none, constant, cached, all)",
413ee42b5ceSMax Reitz         },
414ee42b5ceSMax Reitz         {
41505de7e86SMax Reitz             .name = QCOW2_OPT_OVERLAP_MAIN_HEADER,
41605de7e86SMax Reitz             .type = QEMU_OPT_BOOL,
41705de7e86SMax Reitz             .help = "Check for unintended writes into the main qcow2 header",
41805de7e86SMax Reitz         },
41905de7e86SMax Reitz         {
42005de7e86SMax Reitz             .name = QCOW2_OPT_OVERLAP_ACTIVE_L1,
42105de7e86SMax Reitz             .type = QEMU_OPT_BOOL,
42205de7e86SMax Reitz             .help = "Check for unintended writes into the active L1 table",
42305de7e86SMax Reitz         },
42405de7e86SMax Reitz         {
42505de7e86SMax Reitz             .name = QCOW2_OPT_OVERLAP_ACTIVE_L2,
42605de7e86SMax Reitz             .type = QEMU_OPT_BOOL,
42705de7e86SMax Reitz             .help = "Check for unintended writes into an active L2 table",
42805de7e86SMax Reitz         },
42905de7e86SMax Reitz         {
43005de7e86SMax Reitz             .name = QCOW2_OPT_OVERLAP_REFCOUNT_TABLE,
43105de7e86SMax Reitz             .type = QEMU_OPT_BOOL,
43205de7e86SMax Reitz             .help = "Check for unintended writes into the refcount table",
43305de7e86SMax Reitz         },
43405de7e86SMax Reitz         {
43505de7e86SMax Reitz             .name = QCOW2_OPT_OVERLAP_REFCOUNT_BLOCK,
43605de7e86SMax Reitz             .type = QEMU_OPT_BOOL,
43705de7e86SMax Reitz             .help = "Check for unintended writes into a refcount block",
43805de7e86SMax Reitz         },
43905de7e86SMax Reitz         {
44005de7e86SMax Reitz             .name = QCOW2_OPT_OVERLAP_SNAPSHOT_TABLE,
44105de7e86SMax Reitz             .type = QEMU_OPT_BOOL,
44205de7e86SMax Reitz             .help = "Check for unintended writes into the snapshot table",
44305de7e86SMax Reitz         },
44405de7e86SMax Reitz         {
44505de7e86SMax Reitz             .name = QCOW2_OPT_OVERLAP_INACTIVE_L1,
44605de7e86SMax Reitz             .type = QEMU_OPT_BOOL,
44705de7e86SMax Reitz             .help = "Check for unintended writes into an inactive L1 table",
44805de7e86SMax Reitz         },
44905de7e86SMax Reitz         {
45005de7e86SMax Reitz             .name = QCOW2_OPT_OVERLAP_INACTIVE_L2,
45105de7e86SMax Reitz             .type = QEMU_OPT_BOOL,
45205de7e86SMax Reitz             .help = "Check for unintended writes into an inactive L2 table",
45305de7e86SMax Reitz         },
4546c1c8d5dSMax Reitz         {
4556c1c8d5dSMax Reitz             .name = QCOW2_OPT_CACHE_SIZE,
4566c1c8d5dSMax Reitz             .type = QEMU_OPT_SIZE,
4576c1c8d5dSMax Reitz             .help = "Maximum combined metadata (L2 tables and refcount blocks) "
4586c1c8d5dSMax Reitz                     "cache size",
4596c1c8d5dSMax Reitz         },
4606c1c8d5dSMax Reitz         {
4616c1c8d5dSMax Reitz             .name = QCOW2_OPT_L2_CACHE_SIZE,
4626c1c8d5dSMax Reitz             .type = QEMU_OPT_SIZE,
4636c1c8d5dSMax Reitz             .help = "Maximum L2 table cache size",
4646c1c8d5dSMax Reitz         },
4656c1c8d5dSMax Reitz         {
4666c1c8d5dSMax Reitz             .name = QCOW2_OPT_REFCOUNT_CACHE_SIZE,
4676c1c8d5dSMax Reitz             .type = QEMU_OPT_SIZE,
4686c1c8d5dSMax Reitz             .help = "Maximum refcount block cache size",
4696c1c8d5dSMax Reitz         },
47074c4510aSKevin Wolf         { /* end of list */ }
47174c4510aSKevin Wolf     },
47274c4510aSKevin Wolf };
47374c4510aSKevin Wolf 
4744092e99dSMax Reitz static const char *overlap_bool_option_names[QCOW2_OL_MAX_BITNR] = {
4754092e99dSMax Reitz     [QCOW2_OL_MAIN_HEADER_BITNR]    = QCOW2_OPT_OVERLAP_MAIN_HEADER,
4764092e99dSMax Reitz     [QCOW2_OL_ACTIVE_L1_BITNR]      = QCOW2_OPT_OVERLAP_ACTIVE_L1,
4774092e99dSMax Reitz     [QCOW2_OL_ACTIVE_L2_BITNR]      = QCOW2_OPT_OVERLAP_ACTIVE_L2,
4784092e99dSMax Reitz     [QCOW2_OL_REFCOUNT_TABLE_BITNR] = QCOW2_OPT_OVERLAP_REFCOUNT_TABLE,
4794092e99dSMax Reitz     [QCOW2_OL_REFCOUNT_BLOCK_BITNR] = QCOW2_OPT_OVERLAP_REFCOUNT_BLOCK,
4804092e99dSMax Reitz     [QCOW2_OL_SNAPSHOT_TABLE_BITNR] = QCOW2_OPT_OVERLAP_SNAPSHOT_TABLE,
4814092e99dSMax Reitz     [QCOW2_OL_INACTIVE_L1_BITNR]    = QCOW2_OPT_OVERLAP_INACTIVE_L1,
4824092e99dSMax Reitz     [QCOW2_OL_INACTIVE_L2_BITNR]    = QCOW2_OPT_OVERLAP_INACTIVE_L2,
4834092e99dSMax Reitz };
4844092e99dSMax Reitz 
4856c1c8d5dSMax Reitz static void read_cache_sizes(QemuOpts *opts, uint64_t *l2_cache_size,
4866c1c8d5dSMax Reitz                              uint64_t *refcount_cache_size, Error **errp)
4876c1c8d5dSMax Reitz {
4886c1c8d5dSMax Reitz     uint64_t combined_cache_size;
4896c1c8d5dSMax Reitz     bool l2_cache_size_set, refcount_cache_size_set, combined_cache_size_set;
4906c1c8d5dSMax Reitz 
4916c1c8d5dSMax Reitz     combined_cache_size_set = qemu_opt_get(opts, QCOW2_OPT_CACHE_SIZE);
4926c1c8d5dSMax Reitz     l2_cache_size_set = qemu_opt_get(opts, QCOW2_OPT_L2_CACHE_SIZE);
4936c1c8d5dSMax Reitz     refcount_cache_size_set = qemu_opt_get(opts, QCOW2_OPT_REFCOUNT_CACHE_SIZE);
4946c1c8d5dSMax Reitz 
4956c1c8d5dSMax Reitz     combined_cache_size = qemu_opt_get_size(opts, QCOW2_OPT_CACHE_SIZE, 0);
4966c1c8d5dSMax Reitz     *l2_cache_size = qemu_opt_get_size(opts, QCOW2_OPT_L2_CACHE_SIZE, 0);
4976c1c8d5dSMax Reitz     *refcount_cache_size = qemu_opt_get_size(opts,
4986c1c8d5dSMax Reitz                                              QCOW2_OPT_REFCOUNT_CACHE_SIZE, 0);
4996c1c8d5dSMax Reitz 
5006c1c8d5dSMax Reitz     if (combined_cache_size_set) {
5016c1c8d5dSMax Reitz         if (l2_cache_size_set && refcount_cache_size_set) {
5026c1c8d5dSMax Reitz             error_setg(errp, QCOW2_OPT_CACHE_SIZE ", " QCOW2_OPT_L2_CACHE_SIZE
5036c1c8d5dSMax Reitz                        " and " QCOW2_OPT_REFCOUNT_CACHE_SIZE " may not be set "
5046c1c8d5dSMax Reitz                        "the same time");
5056c1c8d5dSMax Reitz             return;
5066c1c8d5dSMax Reitz         } else if (*l2_cache_size > combined_cache_size) {
5076c1c8d5dSMax Reitz             error_setg(errp, QCOW2_OPT_L2_CACHE_SIZE " may not exceed "
5086c1c8d5dSMax Reitz                        QCOW2_OPT_CACHE_SIZE);
5096c1c8d5dSMax Reitz             return;
5106c1c8d5dSMax Reitz         } else if (*refcount_cache_size > combined_cache_size) {
5116c1c8d5dSMax Reitz             error_setg(errp, QCOW2_OPT_REFCOUNT_CACHE_SIZE " may not exceed "
5126c1c8d5dSMax Reitz                        QCOW2_OPT_CACHE_SIZE);
5136c1c8d5dSMax Reitz             return;
5146c1c8d5dSMax Reitz         }
5156c1c8d5dSMax Reitz 
5166c1c8d5dSMax Reitz         if (l2_cache_size_set) {
5176c1c8d5dSMax Reitz             *refcount_cache_size = combined_cache_size - *l2_cache_size;
5186c1c8d5dSMax Reitz         } else if (refcount_cache_size_set) {
5196c1c8d5dSMax Reitz             *l2_cache_size = combined_cache_size - *refcount_cache_size;
5206c1c8d5dSMax Reitz         } else {
5216c1c8d5dSMax Reitz             *refcount_cache_size = combined_cache_size
5226c1c8d5dSMax Reitz                                  / (DEFAULT_L2_REFCOUNT_SIZE_RATIO + 1);
5236c1c8d5dSMax Reitz             *l2_cache_size = combined_cache_size - *refcount_cache_size;
5246c1c8d5dSMax Reitz         }
5256c1c8d5dSMax Reitz     } else {
5266c1c8d5dSMax Reitz         if (!l2_cache_size_set && !refcount_cache_size_set) {
5276c1c8d5dSMax Reitz             *l2_cache_size = DEFAULT_L2_CACHE_BYTE_SIZE;
5286c1c8d5dSMax Reitz             *refcount_cache_size = *l2_cache_size
5296c1c8d5dSMax Reitz                                  / DEFAULT_L2_REFCOUNT_SIZE_RATIO;
5306c1c8d5dSMax Reitz         } else if (!l2_cache_size_set) {
5316c1c8d5dSMax Reitz             *l2_cache_size = *refcount_cache_size
5326c1c8d5dSMax Reitz                            * DEFAULT_L2_REFCOUNT_SIZE_RATIO;
5336c1c8d5dSMax Reitz         } else if (!refcount_cache_size_set) {
5346c1c8d5dSMax Reitz             *refcount_cache_size = *l2_cache_size
5356c1c8d5dSMax Reitz                                  / DEFAULT_L2_REFCOUNT_SIZE_RATIO;
5366c1c8d5dSMax Reitz         }
5376c1c8d5dSMax Reitz     }
5386c1c8d5dSMax Reitz }
5396c1c8d5dSMax Reitz 
540015a1036SMax Reitz static int qcow2_open(BlockDriverState *bs, QDict *options, int flags,
541015a1036SMax Reitz                       Error **errp)
542585f8587Sbellard {
543585f8587Sbellard     BDRVQcowState *s = bs->opaque;
5446d33e8e7SKevin Wolf     unsigned int len, i;
5456d33e8e7SKevin Wolf     int ret = 0;
546585f8587Sbellard     QCowHeader header;
5477b17ce60SMax Reitz     QemuOpts *opts = NULL;
54874c4510aSKevin Wolf     Error *local_err = NULL;
5499b80ddf3Saliguori     uint64_t ext_end;
5502cf7cfa1SKevin Wolf     uint64_t l1_vm_state_index;
551ee42b5ceSMax Reitz     const char *opt_overlap_check, *opt_overlap_check_template;
5521fa5cc83SMax Reitz     int overlap_check_template = 0;
553440ba08aSMax Reitz     uint64_t l2_cache_size, refcount_cache_size;
554585f8587Sbellard 
5556d85a57eSJes Sorensen     ret = bdrv_pread(bs->file, 0, &header, sizeof(header));
5566d85a57eSJes Sorensen     if (ret < 0) {
5573ef6c40aSMax Reitz         error_setg_errno(errp, -ret, "Could not read qcow2 header");
558585f8587Sbellard         goto fail;
5596d85a57eSJes Sorensen     }
560585f8587Sbellard     be32_to_cpus(&header.magic);
561585f8587Sbellard     be32_to_cpus(&header.version);
562585f8587Sbellard     be64_to_cpus(&header.backing_file_offset);
563585f8587Sbellard     be32_to_cpus(&header.backing_file_size);
564585f8587Sbellard     be64_to_cpus(&header.size);
565585f8587Sbellard     be32_to_cpus(&header.cluster_bits);
566585f8587Sbellard     be32_to_cpus(&header.crypt_method);
567585f8587Sbellard     be64_to_cpus(&header.l1_table_offset);
568585f8587Sbellard     be32_to_cpus(&header.l1_size);
569585f8587Sbellard     be64_to_cpus(&header.refcount_table_offset);
570585f8587Sbellard     be32_to_cpus(&header.refcount_table_clusters);
571585f8587Sbellard     be64_to_cpus(&header.snapshots_offset);
572585f8587Sbellard     be32_to_cpus(&header.nb_snapshots);
573585f8587Sbellard 
574e8cdcec1SKevin Wolf     if (header.magic != QCOW_MAGIC) {
5753ef6c40aSMax Reitz         error_setg(errp, "Image is not in qcow2 format");
57676abe407SPaolo Bonzini         ret = -EINVAL;
577585f8587Sbellard         goto fail;
5786d85a57eSJes Sorensen     }
5796744cbabSKevin Wolf     if (header.version < 2 || header.version > 3) {
580521b2b5dSMax Reitz         report_unsupported(bs, errp, "QCOW version %" PRIu32, header.version);
581e8cdcec1SKevin Wolf         ret = -ENOTSUP;
582e8cdcec1SKevin Wolf         goto fail;
583e8cdcec1SKevin Wolf     }
5846744cbabSKevin Wolf 
5856744cbabSKevin Wolf     s->qcow_version = header.version;
5866744cbabSKevin Wolf 
58724342f2cSKevin Wolf     /* Initialise cluster size */
58824342f2cSKevin Wolf     if (header.cluster_bits < MIN_CLUSTER_BITS ||
58924342f2cSKevin Wolf         header.cluster_bits > MAX_CLUSTER_BITS) {
590521b2b5dSMax Reitz         error_setg(errp, "Unsupported cluster size: 2^%" PRIu32,
591521b2b5dSMax Reitz                    header.cluster_bits);
59224342f2cSKevin Wolf         ret = -EINVAL;
59324342f2cSKevin Wolf         goto fail;
59424342f2cSKevin Wolf     }
59524342f2cSKevin Wolf 
59624342f2cSKevin Wolf     s->cluster_bits = header.cluster_bits;
59724342f2cSKevin Wolf     s->cluster_size = 1 << s->cluster_bits;
59824342f2cSKevin Wolf     s->cluster_sectors = 1 << (s->cluster_bits - 9);
59924342f2cSKevin Wolf 
6006744cbabSKevin Wolf     /* Initialise version 3 header fields */
6016744cbabSKevin Wolf     if (header.version == 2) {
6026744cbabSKevin Wolf         header.incompatible_features    = 0;
6036744cbabSKevin Wolf         header.compatible_features      = 0;
6046744cbabSKevin Wolf         header.autoclear_features       = 0;
6056744cbabSKevin Wolf         header.refcount_order           = 4;
6066744cbabSKevin Wolf         header.header_length            = 72;
6076744cbabSKevin Wolf     } else {
6086744cbabSKevin Wolf         be64_to_cpus(&header.incompatible_features);
6096744cbabSKevin Wolf         be64_to_cpus(&header.compatible_features);
6106744cbabSKevin Wolf         be64_to_cpus(&header.autoclear_features);
6116744cbabSKevin Wolf         be32_to_cpus(&header.refcount_order);
6126744cbabSKevin Wolf         be32_to_cpus(&header.header_length);
61324342f2cSKevin Wolf 
61424342f2cSKevin Wolf         if (header.header_length < 104) {
61524342f2cSKevin Wolf             error_setg(errp, "qcow2 header too short");
61624342f2cSKevin Wolf             ret = -EINVAL;
61724342f2cSKevin Wolf             goto fail;
61824342f2cSKevin Wolf         }
61924342f2cSKevin Wolf     }
62024342f2cSKevin Wolf 
62124342f2cSKevin Wolf     if (header.header_length > s->cluster_size) {
62224342f2cSKevin Wolf         error_setg(errp, "qcow2 header exceeds cluster size");
62324342f2cSKevin Wolf         ret = -EINVAL;
62424342f2cSKevin Wolf         goto fail;
6256744cbabSKevin Wolf     }
6266744cbabSKevin Wolf 
6276744cbabSKevin Wolf     if (header.header_length > sizeof(header)) {
6286744cbabSKevin Wolf         s->unknown_header_fields_size = header.header_length - sizeof(header);
6296744cbabSKevin Wolf         s->unknown_header_fields = g_malloc(s->unknown_header_fields_size);
6306744cbabSKevin Wolf         ret = bdrv_pread(bs->file, sizeof(header), s->unknown_header_fields,
6316744cbabSKevin Wolf                          s->unknown_header_fields_size);
6326744cbabSKevin Wolf         if (ret < 0) {
6333ef6c40aSMax Reitz             error_setg_errno(errp, -ret, "Could not read unknown qcow2 header "
6343ef6c40aSMax Reitz                              "fields");
6356744cbabSKevin Wolf             goto fail;
6366744cbabSKevin Wolf         }
6376744cbabSKevin Wolf     }
6386744cbabSKevin Wolf 
639a1b3955cSKevin Wolf     if (header.backing_file_offset > s->cluster_size) {
640a1b3955cSKevin Wolf         error_setg(errp, "Invalid backing file offset");
641a1b3955cSKevin Wolf         ret = -EINVAL;
642a1b3955cSKevin Wolf         goto fail;
643a1b3955cSKevin Wolf     }
644a1b3955cSKevin Wolf 
645cfcc4c62SKevin Wolf     if (header.backing_file_offset) {
646cfcc4c62SKevin Wolf         ext_end = header.backing_file_offset;
647cfcc4c62SKevin Wolf     } else {
648cfcc4c62SKevin Wolf         ext_end = 1 << header.cluster_bits;
649cfcc4c62SKevin Wolf     }
650cfcc4c62SKevin Wolf 
6516744cbabSKevin Wolf     /* Handle feature bits */
6526744cbabSKevin Wolf     s->incompatible_features    = header.incompatible_features;
6536744cbabSKevin Wolf     s->compatible_features      = header.compatible_features;
6546744cbabSKevin Wolf     s->autoclear_features       = header.autoclear_features;
6556744cbabSKevin Wolf 
656c61d0004SStefan Hajnoczi     if (s->incompatible_features & ~QCOW2_INCOMPAT_MASK) {
657cfcc4c62SKevin Wolf         void *feature_table = NULL;
658cfcc4c62SKevin Wolf         qcow2_read_extensions(bs, header.header_length, ext_end,
6593ef6c40aSMax Reitz                               &feature_table, NULL);
6603ef6c40aSMax Reitz         report_unsupported_feature(bs, errp, feature_table,
661c61d0004SStefan Hajnoczi                                    s->incompatible_features &
662c61d0004SStefan Hajnoczi                                    ~QCOW2_INCOMPAT_MASK);
6636744cbabSKevin Wolf         ret = -ENOTSUP;
664c5a33ee9SPrasad Joshi         g_free(feature_table);
6656744cbabSKevin Wolf         goto fail;
6666744cbabSKevin Wolf     }
6676744cbabSKevin Wolf 
66869c98726SMax Reitz     if (s->incompatible_features & QCOW2_INCOMPAT_CORRUPT) {
66969c98726SMax Reitz         /* Corrupt images may not be written to unless they are being repaired
67069c98726SMax Reitz          */
67169c98726SMax Reitz         if ((flags & BDRV_O_RDWR) && !(flags & BDRV_O_CHECK)) {
6723ef6c40aSMax Reitz             error_setg(errp, "qcow2: Image is corrupt; cannot be opened "
6733ef6c40aSMax Reitz                        "read/write");
67469c98726SMax Reitz             ret = -EACCES;
67569c98726SMax Reitz             goto fail;
67669c98726SMax Reitz         }
67769c98726SMax Reitz     }
67869c98726SMax Reitz 
6796744cbabSKevin Wolf     /* Check support for various header values */
680b72faf9fSMax Reitz     if (header.refcount_order > 6) {
681b72faf9fSMax Reitz         error_setg(errp, "Reference count entry width too large; may not "
682b72faf9fSMax Reitz                    "exceed 64 bits");
683b72faf9fSMax Reitz         ret = -EINVAL;
6846744cbabSKevin Wolf         goto fail;
6856744cbabSKevin Wolf     }
686b6481f37SMax Reitz     s->refcount_order = header.refcount_order;
687346a53dfSMax Reitz     s->refcount_bits = 1 << s->refcount_order;
688346a53dfSMax Reitz     s->refcount_max = UINT64_C(1) << (s->refcount_bits - 1);
689346a53dfSMax Reitz     s->refcount_max += s->refcount_max - 1;
6906744cbabSKevin Wolf 
6916d85a57eSJes Sorensen     if (header.crypt_method > QCOW_CRYPT_AES) {
692521b2b5dSMax Reitz         error_setg(errp, "Unsupported encryption method: %" PRIu32,
6933ef6c40aSMax Reitz                    header.crypt_method);
6946d85a57eSJes Sorensen         ret = -EINVAL;
695585f8587Sbellard         goto fail;
6966d85a57eSJes Sorensen     }
697585f8587Sbellard     s->crypt_method_header = header.crypt_method;
6986d85a57eSJes Sorensen     if (s->crypt_method_header) {
699585f8587Sbellard         bs->encrypted = 1;
7006d85a57eSJes Sorensen     }
70124342f2cSKevin Wolf 
702585f8587Sbellard     s->l2_bits = s->cluster_bits - 3; /* L2 is always one cluster */
703585f8587Sbellard     s->l2_size = 1 << s->l2_bits;
7041d13d654SMax Reitz     /* 2^(s->refcount_order - 3) is the refcount width in bytes */
7051d13d654SMax Reitz     s->refcount_block_bits = s->cluster_bits - (s->refcount_order - 3);
7061d13d654SMax Reitz     s->refcount_block_size = 1 << s->refcount_block_bits;
707585f8587Sbellard     bs->total_sectors = header.size / 512;
708585f8587Sbellard     s->csize_shift = (62 - (s->cluster_bits - 8));
709585f8587Sbellard     s->csize_mask = (1 << (s->cluster_bits - 8)) - 1;
710585f8587Sbellard     s->cluster_offset_mask = (1LL << s->csize_shift) - 1;
7115dab2fadSKevin Wolf 
712585f8587Sbellard     s->refcount_table_offset = header.refcount_table_offset;
713585f8587Sbellard     s->refcount_table_size =
714585f8587Sbellard         header.refcount_table_clusters << (s->cluster_bits - 3);
715585f8587Sbellard 
7162b5d5953SKevin Wolf     if (header.refcount_table_clusters > qcow2_max_refcount_clusters(s)) {
7175dab2fadSKevin Wolf         error_setg(errp, "Reference count table too large");
7185dab2fadSKevin Wolf         ret = -EINVAL;
7195dab2fadSKevin Wolf         goto fail;
7205dab2fadSKevin Wolf     }
7215dab2fadSKevin Wolf 
7228c7de283SKevin Wolf     ret = validate_table_offset(bs, s->refcount_table_offset,
7238c7de283SKevin Wolf                                 s->refcount_table_size, sizeof(uint64_t));
7248c7de283SKevin Wolf     if (ret < 0) {
7258c7de283SKevin Wolf         error_setg(errp, "Invalid reference count table offset");
7268c7de283SKevin Wolf         goto fail;
7278c7de283SKevin Wolf     }
7288c7de283SKevin Wolf 
729ce48f2f4SKevin Wolf     /* Snapshot table offset/length */
730ce48f2f4SKevin Wolf     if (header.nb_snapshots > QCOW_MAX_SNAPSHOTS) {
731ce48f2f4SKevin Wolf         error_setg(errp, "Too many snapshots");
732ce48f2f4SKevin Wolf         ret = -EINVAL;
733ce48f2f4SKevin Wolf         goto fail;
734ce48f2f4SKevin Wolf     }
735ce48f2f4SKevin Wolf 
736ce48f2f4SKevin Wolf     ret = validate_table_offset(bs, header.snapshots_offset,
737ce48f2f4SKevin Wolf                                 header.nb_snapshots,
738ce48f2f4SKevin Wolf                                 sizeof(QCowSnapshotHeader));
739ce48f2f4SKevin Wolf     if (ret < 0) {
740ce48f2f4SKevin Wolf         error_setg(errp, "Invalid snapshot table offset");
741ce48f2f4SKevin Wolf         goto fail;
742ce48f2f4SKevin Wolf     }
743ce48f2f4SKevin Wolf 
744585f8587Sbellard     /* read the level 1 table */
745*87b86e7eSWen Congyang     if (header.l1_size > QCOW_MAX_L1_SIZE / sizeof(uint64_t)) {
7462d51c32cSKevin Wolf         error_setg(errp, "Active L1 table too large");
7472d51c32cSKevin Wolf         ret = -EFBIG;
7482d51c32cSKevin Wolf         goto fail;
7492d51c32cSKevin Wolf     }
750585f8587Sbellard     s->l1_size = header.l1_size;
7512cf7cfa1SKevin Wolf 
7522cf7cfa1SKevin Wolf     l1_vm_state_index = size_to_l1(s, header.size);
7532cf7cfa1SKevin Wolf     if (l1_vm_state_index > INT_MAX) {
7543ef6c40aSMax Reitz         error_setg(errp, "Image is too big");
7552cf7cfa1SKevin Wolf         ret = -EFBIG;
7562cf7cfa1SKevin Wolf         goto fail;
7572cf7cfa1SKevin Wolf     }
7582cf7cfa1SKevin Wolf     s->l1_vm_state_index = l1_vm_state_index;
7592cf7cfa1SKevin Wolf 
760585f8587Sbellard     /* the L1 table must contain at least enough entries to put
761585f8587Sbellard        header.size bytes */
7626d85a57eSJes Sorensen     if (s->l1_size < s->l1_vm_state_index) {
7633ef6c40aSMax Reitz         error_setg(errp, "L1 table is too small");
7646d85a57eSJes Sorensen         ret = -EINVAL;
765585f8587Sbellard         goto fail;
7666d85a57eSJes Sorensen     }
7672d51c32cSKevin Wolf 
7682d51c32cSKevin Wolf     ret = validate_table_offset(bs, header.l1_table_offset,
7692d51c32cSKevin Wolf                                 header.l1_size, sizeof(uint64_t));
7702d51c32cSKevin Wolf     if (ret < 0) {
7712d51c32cSKevin Wolf         error_setg(errp, "Invalid L1 table offset");
7722d51c32cSKevin Wolf         goto fail;
7732d51c32cSKevin Wolf     }
774585f8587Sbellard     s->l1_table_offset = header.l1_table_offset;
7752d51c32cSKevin Wolf 
7762d51c32cSKevin Wolf 
777d191d12dSStefan Weil     if (s->l1_size > 0) {
778de82815dSKevin Wolf         s->l1_table = qemu_try_blockalign(bs->file,
7793f6a3ee5SKevin Wolf             align_offset(s->l1_size * sizeof(uint64_t), 512));
780de82815dSKevin Wolf         if (s->l1_table == NULL) {
781de82815dSKevin Wolf             error_setg(errp, "Could not allocate L1 table");
782de82815dSKevin Wolf             ret = -ENOMEM;
783de82815dSKevin Wolf             goto fail;
784de82815dSKevin Wolf         }
7856d85a57eSJes Sorensen         ret = bdrv_pread(bs->file, s->l1_table_offset, s->l1_table,
7866d85a57eSJes Sorensen                          s->l1_size * sizeof(uint64_t));
7876d85a57eSJes Sorensen         if (ret < 0) {
7883ef6c40aSMax Reitz             error_setg_errno(errp, -ret, "Could not read L1 table");
789585f8587Sbellard             goto fail;
7906d85a57eSJes Sorensen         }
791585f8587Sbellard         for(i = 0;i < s->l1_size; i++) {
792585f8587Sbellard             be64_to_cpus(&s->l1_table[i]);
793585f8587Sbellard         }
794d191d12dSStefan Weil     }
79529c1a730SKevin Wolf 
7966c1c8d5dSMax Reitz     /* get L2 table/refcount block cache size from command line options */
7976c1c8d5dSMax Reitz     opts = qemu_opts_create(&qcow2_runtime_opts, NULL, 0, &error_abort);
7986c1c8d5dSMax Reitz     qemu_opts_absorb_qdict(opts, options, &local_err);
7996c1c8d5dSMax Reitz     if (local_err) {
8006c1c8d5dSMax Reitz         error_propagate(errp, local_err);
8016c1c8d5dSMax Reitz         ret = -EINVAL;
8026c1c8d5dSMax Reitz         goto fail;
8036c1c8d5dSMax Reitz     }
8046c1c8d5dSMax Reitz 
8056c1c8d5dSMax Reitz     read_cache_sizes(opts, &l2_cache_size, &refcount_cache_size, &local_err);
8066c1c8d5dSMax Reitz     if (local_err) {
8076c1c8d5dSMax Reitz         error_propagate(errp, local_err);
8086c1c8d5dSMax Reitz         ret = -EINVAL;
8096c1c8d5dSMax Reitz         goto fail;
8106c1c8d5dSMax Reitz     }
8116c1c8d5dSMax Reitz 
8126c1c8d5dSMax Reitz     l2_cache_size /= s->cluster_size;
813440ba08aSMax Reitz     if (l2_cache_size < MIN_L2_CACHE_SIZE) {
814440ba08aSMax Reitz         l2_cache_size = MIN_L2_CACHE_SIZE;
815440ba08aSMax Reitz     }
8166c1c8d5dSMax Reitz     if (l2_cache_size > INT_MAX) {
8176c1c8d5dSMax Reitz         error_setg(errp, "L2 cache size too big");
8186c1c8d5dSMax Reitz         ret = -EINVAL;
8196c1c8d5dSMax Reitz         goto fail;
8206c1c8d5dSMax Reitz     }
821440ba08aSMax Reitz 
8226c1c8d5dSMax Reitz     refcount_cache_size /= s->cluster_size;
823440ba08aSMax Reitz     if (refcount_cache_size < MIN_REFCOUNT_CACHE_SIZE) {
824440ba08aSMax Reitz         refcount_cache_size = MIN_REFCOUNT_CACHE_SIZE;
825440ba08aSMax Reitz     }
8266c1c8d5dSMax Reitz     if (refcount_cache_size > INT_MAX) {
8276c1c8d5dSMax Reitz         error_setg(errp, "Refcount cache size too big");
8286c1c8d5dSMax Reitz         ret = -EINVAL;
8296c1c8d5dSMax Reitz         goto fail;
8306c1c8d5dSMax Reitz     }
831440ba08aSMax Reitz 
8326c1c8d5dSMax Reitz     /* alloc L2 table/refcount block cache */
833440ba08aSMax Reitz     s->l2_table_cache = qcow2_cache_create(bs, l2_cache_size);
834440ba08aSMax Reitz     s->refcount_block_cache = qcow2_cache_create(bs, refcount_cache_size);
835de82815dSKevin Wolf     if (s->l2_table_cache == NULL || s->refcount_block_cache == NULL) {
836de82815dSKevin Wolf         error_setg(errp, "Could not allocate metadata caches");
837de82815dSKevin Wolf         ret = -ENOMEM;
838de82815dSKevin Wolf         goto fail;
839de82815dSKevin Wolf     }
84029c1a730SKevin Wolf 
8417267c094SAnthony Liguori     s->cluster_cache = g_malloc(s->cluster_size);
842585f8587Sbellard     /* one more sector for decompressed data alignment */
843de82815dSKevin Wolf     s->cluster_data = qemu_try_blockalign(bs->file, QCOW_MAX_CRYPT_CLUSTERS
844de82815dSKevin Wolf                                                     * s->cluster_size + 512);
845de82815dSKevin Wolf     if (s->cluster_data == NULL) {
846de82815dSKevin Wolf         error_setg(errp, "Could not allocate temporary cluster buffer");
847de82815dSKevin Wolf         ret = -ENOMEM;
848de82815dSKevin Wolf         goto fail;
849de82815dSKevin Wolf     }
850de82815dSKevin Wolf 
851585f8587Sbellard     s->cluster_cache_offset = -1;
85206d9260fSAnthony Liguori     s->flags = flags;
853585f8587Sbellard 
8546d85a57eSJes Sorensen     ret = qcow2_refcount_init(bs);
8556d85a57eSJes Sorensen     if (ret != 0) {
8563ef6c40aSMax Reitz         error_setg_errno(errp, -ret, "Could not initialize refcount handling");
857585f8587Sbellard         goto fail;
8586d85a57eSJes Sorensen     }
859585f8587Sbellard 
86072cf2d4fSBlue Swirl     QLIST_INIT(&s->cluster_allocs);
8610b919faeSKevin Wolf     QTAILQ_INIT(&s->discards);
862f214978aSKevin Wolf 
8639b80ddf3Saliguori     /* read qcow2 extensions */
8643ef6c40aSMax Reitz     if (qcow2_read_extensions(bs, header.header_length, ext_end, NULL,
8653ef6c40aSMax Reitz         &local_err)) {
8663ef6c40aSMax Reitz         error_propagate(errp, local_err);
8676d85a57eSJes Sorensen         ret = -EINVAL;
8689b80ddf3Saliguori         goto fail;
8696d85a57eSJes Sorensen     }
8709b80ddf3Saliguori 
871585f8587Sbellard     /* read the backing file name */
872585f8587Sbellard     if (header.backing_file_offset != 0) {
873585f8587Sbellard         len = header.backing_file_size;
8749a29e18fSJeff Cody         if (len > MIN(1023, s->cluster_size - header.backing_file_offset) ||
875e729fa6aSJeff Cody             len >= sizeof(bs->backing_file)) {
8766d33e8e7SKevin Wolf             error_setg(errp, "Backing file name too long");
8776d33e8e7SKevin Wolf             ret = -EINVAL;
8786d33e8e7SKevin Wolf             goto fail;
8796d85a57eSJes Sorensen         }
8806d85a57eSJes Sorensen         ret = bdrv_pread(bs->file, header.backing_file_offset,
8816d85a57eSJes Sorensen                          bs->backing_file, len);
8826d85a57eSJes Sorensen         if (ret < 0) {
8833ef6c40aSMax Reitz             error_setg_errno(errp, -ret, "Could not read backing file name");
884585f8587Sbellard             goto fail;
8856d85a57eSJes Sorensen         }
886585f8587Sbellard         bs->backing_file[len] = '\0';
887585f8587Sbellard     }
88842deb29fSKevin Wolf 
88911b128f4SKevin Wolf     /* Internal snapshots */
89011b128f4SKevin Wolf     s->snapshots_offset = header.snapshots_offset;
89111b128f4SKevin Wolf     s->nb_snapshots = header.nb_snapshots;
89211b128f4SKevin Wolf 
89342deb29fSKevin Wolf     ret = qcow2_read_snapshots(bs);
89442deb29fSKevin Wolf     if (ret < 0) {
8953ef6c40aSMax Reitz         error_setg_errno(errp, -ret, "Could not read snapshots");
896585f8587Sbellard         goto fail;
8976d85a57eSJes Sorensen     }
898585f8587Sbellard 
899af7b708dSStefan Hajnoczi     /* Clear unknown autoclear feature bits */
90027eb6c09SKevin Wolf     if (!bs->read_only && !(flags & BDRV_O_INCOMING) && s->autoclear_features) {
901af7b708dSStefan Hajnoczi         s->autoclear_features = 0;
902af7b708dSStefan Hajnoczi         ret = qcow2_update_header(bs);
903af7b708dSStefan Hajnoczi         if (ret < 0) {
9043ef6c40aSMax Reitz             error_setg_errno(errp, -ret, "Could not update qcow2 header");
905af7b708dSStefan Hajnoczi             goto fail;
906af7b708dSStefan Hajnoczi         }
907af7b708dSStefan Hajnoczi     }
908af7b708dSStefan Hajnoczi 
90968d100e9SKevin Wolf     /* Initialise locks */
91068d100e9SKevin Wolf     qemu_co_mutex_init(&s->lock);
91168d100e9SKevin Wolf 
912c61d0004SStefan Hajnoczi     /* Repair image if dirty */
91327eb6c09SKevin Wolf     if (!(flags & (BDRV_O_CHECK | BDRV_O_INCOMING)) && !bs->read_only &&
914058f8f16SStefan Hajnoczi         (s->incompatible_features & QCOW2_INCOMPAT_DIRTY)) {
915c61d0004SStefan Hajnoczi         BdrvCheckResult result = {0};
916c61d0004SStefan Hajnoczi 
9175b84106bSMax Reitz         ret = qcow2_check(bs, &result, BDRV_FIX_ERRORS | BDRV_FIX_LEAKS);
918c61d0004SStefan Hajnoczi         if (ret < 0) {
9193ef6c40aSMax Reitz             error_setg_errno(errp, -ret, "Could not repair dirty image");
920c61d0004SStefan Hajnoczi             goto fail;
921c61d0004SStefan Hajnoczi         }
922c61d0004SStefan Hajnoczi     }
923c61d0004SStefan Hajnoczi 
92474c4510aSKevin Wolf     /* Enable lazy_refcounts according to image and command line options */
925acdfb480SKevin Wolf     s->use_lazy_refcounts = qemu_opt_get_bool(opts, QCOW2_OPT_LAZY_REFCOUNTS,
92674c4510aSKevin Wolf         (s->compatible_features & QCOW2_COMPAT_LAZY_REFCOUNTS));
92774c4510aSKevin Wolf 
92867af674eSKevin Wolf     s->discard_passthrough[QCOW2_DISCARD_NEVER] = false;
92967af674eSKevin Wolf     s->discard_passthrough[QCOW2_DISCARD_ALWAYS] = true;
93067af674eSKevin Wolf     s->discard_passthrough[QCOW2_DISCARD_REQUEST] =
93167af674eSKevin Wolf         qemu_opt_get_bool(opts, QCOW2_OPT_DISCARD_REQUEST,
93267af674eSKevin Wolf                           flags & BDRV_O_UNMAP);
93367af674eSKevin Wolf     s->discard_passthrough[QCOW2_DISCARD_SNAPSHOT] =
93467af674eSKevin Wolf         qemu_opt_get_bool(opts, QCOW2_OPT_DISCARD_SNAPSHOT, true);
93567af674eSKevin Wolf     s->discard_passthrough[QCOW2_DISCARD_OTHER] =
93667af674eSKevin Wolf         qemu_opt_get_bool(opts, QCOW2_OPT_DISCARD_OTHER, false);
93767af674eSKevin Wolf 
938ee42b5ceSMax Reitz     opt_overlap_check = qemu_opt_get(opts, QCOW2_OPT_OVERLAP);
939ee42b5ceSMax Reitz     opt_overlap_check_template = qemu_opt_get(opts, QCOW2_OPT_OVERLAP_TEMPLATE);
940ee42b5ceSMax Reitz     if (opt_overlap_check_template && opt_overlap_check &&
941ee42b5ceSMax Reitz         strcmp(opt_overlap_check_template, opt_overlap_check))
942ee42b5ceSMax Reitz     {
943ee42b5ceSMax Reitz         error_setg(errp, "Conflicting values for qcow2 options '"
944ee42b5ceSMax Reitz                    QCOW2_OPT_OVERLAP "' ('%s') and '" QCOW2_OPT_OVERLAP_TEMPLATE
945ee42b5ceSMax Reitz                    "' ('%s')", opt_overlap_check, opt_overlap_check_template);
946ee42b5ceSMax Reitz         ret = -EINVAL;
947ee42b5ceSMax Reitz         goto fail;
948ee42b5ceSMax Reitz     }
949ee42b5ceSMax Reitz     if (!opt_overlap_check) {
950ee42b5ceSMax Reitz         opt_overlap_check = opt_overlap_check_template ?: "cached";
951ee42b5ceSMax Reitz     }
952ee42b5ceSMax Reitz 
9531fa5cc83SMax Reitz     if (!strcmp(opt_overlap_check, "none")) {
9541fa5cc83SMax Reitz         overlap_check_template = 0;
9551fa5cc83SMax Reitz     } else if (!strcmp(opt_overlap_check, "constant")) {
9561fa5cc83SMax Reitz         overlap_check_template = QCOW2_OL_CONSTANT;
9571fa5cc83SMax Reitz     } else if (!strcmp(opt_overlap_check, "cached")) {
9581fa5cc83SMax Reitz         overlap_check_template = QCOW2_OL_CACHED;
9591fa5cc83SMax Reitz     } else if (!strcmp(opt_overlap_check, "all")) {
9601fa5cc83SMax Reitz         overlap_check_template = QCOW2_OL_ALL;
9611fa5cc83SMax Reitz     } else {
9621fa5cc83SMax Reitz         error_setg(errp, "Unsupported value '%s' for qcow2 option "
9631fa5cc83SMax Reitz                    "'overlap-check'. Allowed are either of the following: "
9641fa5cc83SMax Reitz                    "none, constant, cached, all", opt_overlap_check);
9651fa5cc83SMax Reitz         ret = -EINVAL;
9661fa5cc83SMax Reitz         goto fail;
9671fa5cc83SMax Reitz     }
9681fa5cc83SMax Reitz 
9691fa5cc83SMax Reitz     s->overlap_check = 0;
9701fa5cc83SMax Reitz     for (i = 0; i < QCOW2_OL_MAX_BITNR; i++) {
9711fa5cc83SMax Reitz         /* overlap-check defines a template bitmask, but every flag may be
9721fa5cc83SMax Reitz          * overwritten through the associated boolean option */
9731fa5cc83SMax Reitz         s->overlap_check |=
9741fa5cc83SMax Reitz             qemu_opt_get_bool(opts, overlap_bool_option_names[i],
9751fa5cc83SMax Reitz                               overlap_check_template & (1 << i)) << i;
9761fa5cc83SMax Reitz     }
9773e355390SMax Reitz 
97874c4510aSKevin Wolf     qemu_opts_del(opts);
9797b17ce60SMax Reitz     opts = NULL;
98074c4510aSKevin Wolf 
98174c4510aSKevin Wolf     if (s->use_lazy_refcounts && s->qcow_version < 3) {
9823ef6c40aSMax Reitz         error_setg(errp, "Lazy refcounts require a qcow2 image with at least "
9833ef6c40aSMax Reitz                    "qemu 1.1 compatibility level");
98474c4510aSKevin Wolf         ret = -EINVAL;
98574c4510aSKevin Wolf         goto fail;
98674c4510aSKevin Wolf     }
98774c4510aSKevin Wolf 
988585f8587Sbellard #ifdef DEBUG_ALLOC
9896cbc3031SPhilipp Hahn     {
9906cbc3031SPhilipp Hahn         BdrvCheckResult result = {0};
991b35278f7SStefan Hajnoczi         qcow2_check_refcounts(bs, &result, 0);
9926cbc3031SPhilipp Hahn     }
993585f8587Sbellard #endif
9946d85a57eSJes Sorensen     return ret;
995585f8587Sbellard 
996585f8587Sbellard  fail:
9977b17ce60SMax Reitz     qemu_opts_del(opts);
9986744cbabSKevin Wolf     g_free(s->unknown_header_fields);
99975bab85cSKevin Wolf     cleanup_unknown_header_ext(bs);
1000ed6ccf0fSKevin Wolf     qcow2_free_snapshots(bs);
1001ed6ccf0fSKevin Wolf     qcow2_refcount_close(bs);
1002de82815dSKevin Wolf     qemu_vfree(s->l1_table);
1003cf93980eSMax Reitz     /* else pre-write overlap checks in cache_destroy may crash */
1004cf93980eSMax Reitz     s->l1_table = NULL;
100529c1a730SKevin Wolf     if (s->l2_table_cache) {
100629c1a730SKevin Wolf         qcow2_cache_destroy(bs, s->l2_table_cache);
100729c1a730SKevin Wolf     }
1008c5a33ee9SPrasad Joshi     if (s->refcount_block_cache) {
1009c5a33ee9SPrasad Joshi         qcow2_cache_destroy(bs, s->refcount_block_cache);
1010c5a33ee9SPrasad Joshi     }
10117267c094SAnthony Liguori     g_free(s->cluster_cache);
1012dea43a65SFrediano Ziglio     qemu_vfree(s->cluster_data);
10136d85a57eSJes Sorensen     return ret;
1014585f8587Sbellard }
1015585f8587Sbellard 
10163baca891SKevin Wolf static void qcow2_refresh_limits(BlockDriverState *bs, Error **errp)
1017d34682cdSKevin Wolf {
1018d34682cdSKevin Wolf     BDRVQcowState *s = bs->opaque;
1019d34682cdSKevin Wolf 
1020d34682cdSKevin Wolf     bs->bl.write_zeroes_alignment = s->cluster_sectors;
1021d34682cdSKevin Wolf }
1022d34682cdSKevin Wolf 
10237c80ab3fSJes Sorensen static int qcow2_set_key(BlockDriverState *bs, const char *key)
1024585f8587Sbellard {
1025585f8587Sbellard     BDRVQcowState *s = bs->opaque;
1026585f8587Sbellard     uint8_t keybuf[16];
1027585f8587Sbellard     int len, i;
1028585f8587Sbellard 
1029585f8587Sbellard     memset(keybuf, 0, 16);
1030585f8587Sbellard     len = strlen(key);
1031585f8587Sbellard     if (len > 16)
1032585f8587Sbellard         len = 16;
1033585f8587Sbellard     /* XXX: we could compress the chars to 7 bits to increase
1034585f8587Sbellard        entropy */
1035585f8587Sbellard     for(i = 0;i < len;i++) {
1036585f8587Sbellard         keybuf[i] = key[i];
1037585f8587Sbellard     }
1038585f8587Sbellard     s->crypt_method = s->crypt_method_header;
1039585f8587Sbellard 
1040585f8587Sbellard     if (AES_set_encrypt_key(keybuf, 128, &s->aes_encrypt_key) != 0)
1041585f8587Sbellard         return -1;
1042585f8587Sbellard     if (AES_set_decrypt_key(keybuf, 128, &s->aes_decrypt_key) != 0)
1043585f8587Sbellard         return -1;
1044585f8587Sbellard #if 0
1045585f8587Sbellard     /* test */
1046585f8587Sbellard     {
1047585f8587Sbellard         uint8_t in[16];
1048585f8587Sbellard         uint8_t out[16];
1049585f8587Sbellard         uint8_t tmp[16];
1050585f8587Sbellard         for(i=0;i<16;i++)
1051585f8587Sbellard             in[i] = i;
1052585f8587Sbellard         AES_encrypt(in, tmp, &s->aes_encrypt_key);
1053585f8587Sbellard         AES_decrypt(tmp, out, &s->aes_decrypt_key);
1054585f8587Sbellard         for(i = 0; i < 16; i++)
1055585f8587Sbellard             printf(" %02x", tmp[i]);
1056585f8587Sbellard         printf("\n");
1057585f8587Sbellard         for(i = 0; i < 16; i++)
1058585f8587Sbellard             printf(" %02x", out[i]);
1059585f8587Sbellard         printf("\n");
1060585f8587Sbellard     }
1061585f8587Sbellard #endif
1062585f8587Sbellard     return 0;
1063585f8587Sbellard }
1064585f8587Sbellard 
10654c2e5f8fSKevin Wolf /* We have no actual commit/abort logic for qcow2, but we need to write out any
10664c2e5f8fSKevin Wolf  * unwritten data if we reopen read-only. */
106721d82ac9SJeff Cody static int qcow2_reopen_prepare(BDRVReopenState *state,
106821d82ac9SJeff Cody                                 BlockReopenQueue *queue, Error **errp)
106921d82ac9SJeff Cody {
10704c2e5f8fSKevin Wolf     int ret;
10714c2e5f8fSKevin Wolf 
10724c2e5f8fSKevin Wolf     if ((state->flags & BDRV_O_RDWR) == 0) {
10734c2e5f8fSKevin Wolf         ret = bdrv_flush(state->bs);
10744c2e5f8fSKevin Wolf         if (ret < 0) {
10754c2e5f8fSKevin Wolf             return ret;
10764c2e5f8fSKevin Wolf         }
10774c2e5f8fSKevin Wolf 
10784c2e5f8fSKevin Wolf         ret = qcow2_mark_clean(state->bs);
10794c2e5f8fSKevin Wolf         if (ret < 0) {
10804c2e5f8fSKevin Wolf             return ret;
10814c2e5f8fSKevin Wolf         }
10824c2e5f8fSKevin Wolf     }
10834c2e5f8fSKevin Wolf 
108421d82ac9SJeff Cody     return 0;
108521d82ac9SJeff Cody }
108621d82ac9SJeff Cody 
1087b6b8a333SPaolo Bonzini static int64_t coroutine_fn qcow2_co_get_block_status(BlockDriverState *bs,
1088f8a2e5e3SStefan Hajnoczi         int64_t sector_num, int nb_sectors, int *pnum)
1089585f8587Sbellard {
1090f8a2e5e3SStefan Hajnoczi     BDRVQcowState *s = bs->opaque;
1091585f8587Sbellard     uint64_t cluster_offset;
10924bc74be9SPaolo Bonzini     int index_in_cluster, ret;
10934bc74be9SPaolo Bonzini     int64_t status = 0;
1094585f8587Sbellard 
1095095a9c58Saliguori     *pnum = nb_sectors;
1096f8a2e5e3SStefan Hajnoczi     qemu_co_mutex_lock(&s->lock);
10971c46efaaSKevin Wolf     ret = qcow2_get_cluster_offset(bs, sector_num << 9, pnum, &cluster_offset);
1098f8a2e5e3SStefan Hajnoczi     qemu_co_mutex_unlock(&s->lock);
10991c46efaaSKevin Wolf     if (ret < 0) {
1100d663640cSPaolo Bonzini         return ret;
11011c46efaaSKevin Wolf     }
1102095a9c58Saliguori 
11034bc74be9SPaolo Bonzini     if (cluster_offset != 0 && ret != QCOW2_CLUSTER_COMPRESSED &&
11044bc74be9SPaolo Bonzini         !s->crypt_method) {
11054bc74be9SPaolo Bonzini         index_in_cluster = sector_num & (s->cluster_sectors - 1);
11064bc74be9SPaolo Bonzini         cluster_offset |= (index_in_cluster << BDRV_SECTOR_BITS);
11074bc74be9SPaolo Bonzini         status |= BDRV_BLOCK_OFFSET_VALID | cluster_offset;
11084bc74be9SPaolo Bonzini     }
11094bc74be9SPaolo Bonzini     if (ret == QCOW2_CLUSTER_ZERO) {
11104bc74be9SPaolo Bonzini         status |= BDRV_BLOCK_ZERO;
11114bc74be9SPaolo Bonzini     } else if (ret != QCOW2_CLUSTER_UNALLOCATED) {
11124bc74be9SPaolo Bonzini         status |= BDRV_BLOCK_DATA;
11134bc74be9SPaolo Bonzini     }
11144bc74be9SPaolo Bonzini     return status;
1115585f8587Sbellard }
1116585f8587Sbellard 
1117a9465922Sbellard /* handle reading after the end of the backing file */
1118bd28f835SKevin Wolf int qcow2_backing_read1(BlockDriverState *bs, QEMUIOVector *qiov,
1119bd28f835SKevin Wolf                   int64_t sector_num, int nb_sectors)
1120a9465922Sbellard {
1121a9465922Sbellard     int n1;
1122a9465922Sbellard     if ((sector_num + nb_sectors) <= bs->total_sectors)
1123a9465922Sbellard         return nb_sectors;
1124a9465922Sbellard     if (sector_num >= bs->total_sectors)
1125a9465922Sbellard         n1 = 0;
1126a9465922Sbellard     else
1127a9465922Sbellard         n1 = bs->total_sectors - sector_num;
1128bd28f835SKevin Wolf 
11293d9b4925SMichael Tokarev     qemu_iovec_memset(qiov, 512 * n1, 0, 512 * (nb_sectors - n1));
1130bd28f835SKevin Wolf 
1131a9465922Sbellard     return n1;
1132a9465922Sbellard }
1133a9465922Sbellard 
1134a968168cSDong Xu Wang static coroutine_fn int qcow2_co_readv(BlockDriverState *bs, int64_t sector_num,
11353fc48d09SFrediano Ziglio                           int remaining_sectors, QEMUIOVector *qiov)
11361490791fSaliguori {
1137585f8587Sbellard     BDRVQcowState *s = bs->opaque;
1138a9465922Sbellard     int index_in_cluster, n1;
113968d100e9SKevin Wolf     int ret;
1140faf575c1SFrediano Ziglio     int cur_nr_sectors; /* number of sectors in current iteration */
1141c2bdd990SFrediano Ziglio     uint64_t cluster_offset = 0;
11423fc48d09SFrediano Ziglio     uint64_t bytes_done = 0;
11433fc48d09SFrediano Ziglio     QEMUIOVector hd_qiov;
11443fc48d09SFrediano Ziglio     uint8_t *cluster_data = NULL;
1145585f8587Sbellard 
11463fc48d09SFrediano Ziglio     qemu_iovec_init(&hd_qiov, qiov->niov);
11473fc48d09SFrediano Ziglio 
11483fc48d09SFrediano Ziglio     qemu_co_mutex_lock(&s->lock);
11493fc48d09SFrediano Ziglio 
11503fc48d09SFrediano Ziglio     while (remaining_sectors != 0) {
1151585f8587Sbellard 
1152faf575c1SFrediano Ziglio         /* prepare next request */
11533fc48d09SFrediano Ziglio         cur_nr_sectors = remaining_sectors;
1154bd28f835SKevin Wolf         if (s->crypt_method) {
1155faf575c1SFrediano Ziglio             cur_nr_sectors = MIN(cur_nr_sectors,
1156bd28f835SKevin Wolf                 QCOW_MAX_CRYPT_CLUSTERS * s->cluster_sectors);
1157bd28f835SKevin Wolf         }
1158bd28f835SKevin Wolf 
11593fc48d09SFrediano Ziglio         ret = qcow2_get_cluster_offset(bs, sector_num << 9,
1160c2bdd990SFrediano Ziglio             &cur_nr_sectors, &cluster_offset);
11611c46efaaSKevin Wolf         if (ret < 0) {
11623fc48d09SFrediano Ziglio             goto fail;
11631c46efaaSKevin Wolf         }
11641c46efaaSKevin Wolf 
11653fc48d09SFrediano Ziglio         index_in_cluster = sector_num & (s->cluster_sectors - 1);
1166585f8587Sbellard 
11673fc48d09SFrediano Ziglio         qemu_iovec_reset(&hd_qiov);
11681b093c48SMichael Tokarev         qemu_iovec_concat(&hd_qiov, qiov, bytes_done,
1169faf575c1SFrediano Ziglio             cur_nr_sectors * 512);
1170bd28f835SKevin Wolf 
117168d000a3SKevin Wolf         switch (ret) {
117268d000a3SKevin Wolf         case QCOW2_CLUSTER_UNALLOCATED:
1173bd28f835SKevin Wolf 
1174585f8587Sbellard             if (bs->backing_hd) {
1175585f8587Sbellard                 /* read from the base image */
11763fc48d09SFrediano Ziglio                 n1 = qcow2_backing_read1(bs->backing_hd, &hd_qiov,
11773fc48d09SFrediano Ziglio                     sector_num, cur_nr_sectors);
1178a9465922Sbellard                 if (n1 > 0) {
117944deba5aSKevin Wolf                     QEMUIOVector local_qiov;
118044deba5aSKevin Wolf 
118144deba5aSKevin Wolf                     qemu_iovec_init(&local_qiov, hd_qiov.niov);
118244deba5aSKevin Wolf                     qemu_iovec_concat(&local_qiov, &hd_qiov, 0,
118344deba5aSKevin Wolf                                       n1 * BDRV_SECTOR_SIZE);
118444deba5aSKevin Wolf 
118566f82ceeSKevin Wolf                     BLKDBG_EVENT(bs->file, BLKDBG_READ_BACKING_AIO);
118668d100e9SKevin Wolf                     qemu_co_mutex_unlock(&s->lock);
11873fc48d09SFrediano Ziglio                     ret = bdrv_co_readv(bs->backing_hd, sector_num,
118844deba5aSKevin Wolf                                         n1, &local_qiov);
118968d100e9SKevin Wolf                     qemu_co_mutex_lock(&s->lock);
119044deba5aSKevin Wolf 
119144deba5aSKevin Wolf                     qemu_iovec_destroy(&local_qiov);
119244deba5aSKevin Wolf 
119368d100e9SKevin Wolf                     if (ret < 0) {
11943fc48d09SFrediano Ziglio                         goto fail;
11953ab4c7e9SKevin Wolf                     }
11961490791fSaliguori                 }
1197a9465922Sbellard             } else {
1198585f8587Sbellard                 /* Note: in this case, no need to wait */
11993d9b4925SMichael Tokarev                 qemu_iovec_memset(&hd_qiov, 0, 0, 512 * cur_nr_sectors);
12001490791fSaliguori             }
120168d000a3SKevin Wolf             break;
120268d000a3SKevin Wolf 
12036377af48SKevin Wolf         case QCOW2_CLUSTER_ZERO:
12043d9b4925SMichael Tokarev             qemu_iovec_memset(&hd_qiov, 0, 0, 512 * cur_nr_sectors);
12056377af48SKevin Wolf             break;
12066377af48SKevin Wolf 
120768d000a3SKevin Wolf         case QCOW2_CLUSTER_COMPRESSED:
1208585f8587Sbellard             /* add AIO support for compressed blocks ? */
1209c2bdd990SFrediano Ziglio             ret = qcow2_decompress_cluster(bs, cluster_offset);
12108af36488SKevin Wolf             if (ret < 0) {
12113fc48d09SFrediano Ziglio                 goto fail;
12128af36488SKevin Wolf             }
1213bd28f835SKevin Wolf 
121403396148SMichael Tokarev             qemu_iovec_from_buf(&hd_qiov, 0,
1215bd28f835SKevin Wolf                 s->cluster_cache + index_in_cluster * 512,
1216faf575c1SFrediano Ziglio                 512 * cur_nr_sectors);
121768d000a3SKevin Wolf             break;
121868d000a3SKevin Wolf 
121968d000a3SKevin Wolf         case QCOW2_CLUSTER_NORMAL:
1220c2bdd990SFrediano Ziglio             if ((cluster_offset & 511) != 0) {
12213fc48d09SFrediano Ziglio                 ret = -EIO;
12223fc48d09SFrediano Ziglio                 goto fail;
1223585f8587Sbellard             }
1224c87c0672Saliguori 
1225bd28f835SKevin Wolf             if (s->crypt_method) {
1226bd28f835SKevin Wolf                 /*
1227bd28f835SKevin Wolf                  * For encrypted images, read everything into a temporary
1228bd28f835SKevin Wolf                  * contiguous buffer on which the AES functions can work.
1229bd28f835SKevin Wolf                  */
12303fc48d09SFrediano Ziglio                 if (!cluster_data) {
12313fc48d09SFrediano Ziglio                     cluster_data =
1232de82815dSKevin Wolf                         qemu_try_blockalign(bs->file, QCOW_MAX_CRYPT_CLUSTERS
1233de82815dSKevin Wolf                                                       * s->cluster_size);
1234de82815dSKevin Wolf                     if (cluster_data == NULL) {
1235de82815dSKevin Wolf                         ret = -ENOMEM;
1236de82815dSKevin Wolf                         goto fail;
1237de82815dSKevin Wolf                     }
1238bd28f835SKevin Wolf                 }
1239bd28f835SKevin Wolf 
1240faf575c1SFrediano Ziglio                 assert(cur_nr_sectors <=
1241bd28f835SKevin Wolf                     QCOW_MAX_CRYPT_CLUSTERS * s->cluster_sectors);
12423fc48d09SFrediano Ziglio                 qemu_iovec_reset(&hd_qiov);
12433fc48d09SFrediano Ziglio                 qemu_iovec_add(&hd_qiov, cluster_data,
1244faf575c1SFrediano Ziglio                     512 * cur_nr_sectors);
1245bd28f835SKevin Wolf             }
1246bd28f835SKevin Wolf 
124766f82ceeSKevin Wolf             BLKDBG_EVENT(bs->file, BLKDBG_READ_AIO);
124868d100e9SKevin Wolf             qemu_co_mutex_unlock(&s->lock);
124968d100e9SKevin Wolf             ret = bdrv_co_readv(bs->file,
1250c2bdd990SFrediano Ziglio                                 (cluster_offset >> 9) + index_in_cluster,
12513fc48d09SFrediano Ziglio                                 cur_nr_sectors, &hd_qiov);
125268d100e9SKevin Wolf             qemu_co_mutex_lock(&s->lock);
125368d100e9SKevin Wolf             if (ret < 0) {
12543fc48d09SFrediano Ziglio                 goto fail;
1255585f8587Sbellard             }
1256faf575c1SFrediano Ziglio             if (s->crypt_method) {
12573fc48d09SFrediano Ziglio                 qcow2_encrypt_sectors(s, sector_num,  cluster_data,
12583fc48d09SFrediano Ziglio                     cluster_data, cur_nr_sectors, 0, &s->aes_decrypt_key);
125903396148SMichael Tokarev                 qemu_iovec_from_buf(qiov, bytes_done,
126003396148SMichael Tokarev                     cluster_data, 512 * cur_nr_sectors);
1261171e3d6bSKevin Wolf             }
126268d000a3SKevin Wolf             break;
126368d000a3SKevin Wolf 
126468d000a3SKevin Wolf         default:
126568d000a3SKevin Wolf             g_assert_not_reached();
126668d000a3SKevin Wolf             ret = -EIO;
126768d000a3SKevin Wolf             goto fail;
1268faf575c1SFrediano Ziglio         }
1269faf575c1SFrediano Ziglio 
12703fc48d09SFrediano Ziglio         remaining_sectors -= cur_nr_sectors;
12713fc48d09SFrediano Ziglio         sector_num += cur_nr_sectors;
12723fc48d09SFrediano Ziglio         bytes_done += cur_nr_sectors * 512;
12735ebaa27eSFrediano Ziglio     }
12743fc48d09SFrediano Ziglio     ret = 0;
1275f141eafeSaliguori 
12763fc48d09SFrediano Ziglio fail:
127768d100e9SKevin Wolf     qemu_co_mutex_unlock(&s->lock);
127868d100e9SKevin Wolf 
12793fc48d09SFrediano Ziglio     qemu_iovec_destroy(&hd_qiov);
1280dea43a65SFrediano Ziglio     qemu_vfree(cluster_data);
128168d100e9SKevin Wolf 
128268d100e9SKevin Wolf     return ret;
1283585f8587Sbellard }
1284585f8587Sbellard 
1285a968168cSDong Xu Wang static coroutine_fn int qcow2_co_writev(BlockDriverState *bs,
12863fc48d09SFrediano Ziglio                            int64_t sector_num,
12873fc48d09SFrediano Ziglio                            int remaining_sectors,
12883fc48d09SFrediano Ziglio                            QEMUIOVector *qiov)
1289585f8587Sbellard {
1290585f8587Sbellard     BDRVQcowState *s = bs->opaque;
1291585f8587Sbellard     int index_in_cluster;
129268d100e9SKevin Wolf     int ret;
1293faf575c1SFrediano Ziglio     int cur_nr_sectors; /* number of sectors in current iteration */
1294c2bdd990SFrediano Ziglio     uint64_t cluster_offset;
12953fc48d09SFrediano Ziglio     QEMUIOVector hd_qiov;
12963fc48d09SFrediano Ziglio     uint64_t bytes_done = 0;
12973fc48d09SFrediano Ziglio     uint8_t *cluster_data = NULL;
12988d2497c3SKevin Wolf     QCowL2Meta *l2meta = NULL;
1299c2271403SFrediano Ziglio 
13003cce16f4SKevin Wolf     trace_qcow2_writev_start_req(qemu_coroutine_self(), sector_num,
13013cce16f4SKevin Wolf                                  remaining_sectors);
13023cce16f4SKevin Wolf 
13033fc48d09SFrediano Ziglio     qemu_iovec_init(&hd_qiov, qiov->niov);
1304585f8587Sbellard 
13053fc48d09SFrediano Ziglio     s->cluster_cache_offset = -1; /* disable compressed cache */
13063fc48d09SFrediano Ziglio 
13073fc48d09SFrediano Ziglio     qemu_co_mutex_lock(&s->lock);
13083fc48d09SFrediano Ziglio 
13093fc48d09SFrediano Ziglio     while (remaining_sectors != 0) {
13103fc48d09SFrediano Ziglio 
1311f50f88b9SKevin Wolf         l2meta = NULL;
1312cf5c1a23SKevin Wolf 
13133cce16f4SKevin Wolf         trace_qcow2_writev_start_part(qemu_coroutine_self());
13143fc48d09SFrediano Ziglio         index_in_cluster = sector_num & (s->cluster_sectors - 1);
131516f0587eSHu Tao         cur_nr_sectors = remaining_sectors;
1316095a9c58Saliguori         if (s->crypt_method &&
131716f0587eSHu Tao             cur_nr_sectors >
131816f0587eSHu Tao             QCOW_MAX_CRYPT_CLUSTERS * s->cluster_sectors - index_in_cluster) {
131916f0587eSHu Tao             cur_nr_sectors =
132016f0587eSHu Tao                 QCOW_MAX_CRYPT_CLUSTERS * s->cluster_sectors - index_in_cluster;
13215ebaa27eSFrediano Ziglio         }
1322095a9c58Saliguori 
13233fc48d09SFrediano Ziglio         ret = qcow2_alloc_cluster_offset(bs, sector_num << 9,
132416f0587eSHu Tao             &cur_nr_sectors, &cluster_offset, &l2meta);
1325148da7eaSKevin Wolf         if (ret < 0) {
13263fc48d09SFrediano Ziglio             goto fail;
1327148da7eaSKevin Wolf         }
1328148da7eaSKevin Wolf 
1329c2bdd990SFrediano Ziglio         assert((cluster_offset & 511) == 0);
1330148da7eaSKevin Wolf 
13313fc48d09SFrediano Ziglio         qemu_iovec_reset(&hd_qiov);
13321b093c48SMichael Tokarev         qemu_iovec_concat(&hd_qiov, qiov, bytes_done,
1333faf575c1SFrediano Ziglio             cur_nr_sectors * 512);
13346f5f060bSKevin Wolf 
1335585f8587Sbellard         if (s->crypt_method) {
13363fc48d09SFrediano Ziglio             if (!cluster_data) {
1337de82815dSKevin Wolf                 cluster_data = qemu_try_blockalign(bs->file,
1338de82815dSKevin Wolf                                                    QCOW_MAX_CRYPT_CLUSTERS
1339de82815dSKevin Wolf                                                    * s->cluster_size);
1340de82815dSKevin Wolf                 if (cluster_data == NULL) {
1341de82815dSKevin Wolf                     ret = -ENOMEM;
1342de82815dSKevin Wolf                     goto fail;
1343de82815dSKevin Wolf                 }
1344585f8587Sbellard             }
13456f5f060bSKevin Wolf 
13463fc48d09SFrediano Ziglio             assert(hd_qiov.size <=
13475ebaa27eSFrediano Ziglio                    QCOW_MAX_CRYPT_CLUSTERS * s->cluster_size);
1348d5e6b161SMichael Tokarev             qemu_iovec_to_buf(&hd_qiov, 0, cluster_data, hd_qiov.size);
13496f5f060bSKevin Wolf 
13503fc48d09SFrediano Ziglio             qcow2_encrypt_sectors(s, sector_num, cluster_data,
13513fc48d09SFrediano Ziglio                 cluster_data, cur_nr_sectors, 1, &s->aes_encrypt_key);
13526f5f060bSKevin Wolf 
13533fc48d09SFrediano Ziglio             qemu_iovec_reset(&hd_qiov);
13543fc48d09SFrediano Ziglio             qemu_iovec_add(&hd_qiov, cluster_data,
1355faf575c1SFrediano Ziglio                 cur_nr_sectors * 512);
1356585f8587Sbellard         }
13576f5f060bSKevin Wolf 
1358231bb267SMax Reitz         ret = qcow2_pre_write_overlap_check(bs, 0,
1359cf93980eSMax Reitz                 cluster_offset + index_in_cluster * BDRV_SECTOR_SIZE,
1360cf93980eSMax Reitz                 cur_nr_sectors * BDRV_SECTOR_SIZE);
1361cf93980eSMax Reitz         if (ret < 0) {
1362cf93980eSMax Reitz             goto fail;
1363cf93980eSMax Reitz         }
1364cf93980eSMax Reitz 
136568d100e9SKevin Wolf         qemu_co_mutex_unlock(&s->lock);
136667a7a0ebSKevin Wolf         BLKDBG_EVENT(bs->file, BLKDBG_WRITE_AIO);
13673cce16f4SKevin Wolf         trace_qcow2_writev_data(qemu_coroutine_self(),
13683cce16f4SKevin Wolf                                 (cluster_offset >> 9) + index_in_cluster);
136968d100e9SKevin Wolf         ret = bdrv_co_writev(bs->file,
1370c2bdd990SFrediano Ziglio                              (cluster_offset >> 9) + index_in_cluster,
13713fc48d09SFrediano Ziglio                              cur_nr_sectors, &hd_qiov);
137268d100e9SKevin Wolf         qemu_co_mutex_lock(&s->lock);
137368d100e9SKevin Wolf         if (ret < 0) {
13743fc48d09SFrediano Ziglio             goto fail;
1375171e3d6bSKevin Wolf         }
1376f141eafeSaliguori 
137788c6588cSKevin Wolf         while (l2meta != NULL) {
137888c6588cSKevin Wolf             QCowL2Meta *next;
137988c6588cSKevin Wolf 
1380cf5c1a23SKevin Wolf             ret = qcow2_alloc_cluster_link_l2(bs, l2meta);
1381faf575c1SFrediano Ziglio             if (ret < 0) {
13823fc48d09SFrediano Ziglio                 goto fail;
1383faf575c1SFrediano Ziglio             }
1384faf575c1SFrediano Ziglio 
13854e95314eSKevin Wolf             /* Take the request off the list of running requests */
13864e95314eSKevin Wolf             if (l2meta->nb_clusters != 0) {
13874e95314eSKevin Wolf                 QLIST_REMOVE(l2meta, next_in_flight);
13884e95314eSKevin Wolf             }
13894e95314eSKevin Wolf 
13904e95314eSKevin Wolf             qemu_co_queue_restart_all(&l2meta->dependent_requests);
13914e95314eSKevin Wolf 
139288c6588cSKevin Wolf             next = l2meta->next;
1393cf5c1a23SKevin Wolf             g_free(l2meta);
139488c6588cSKevin Wolf             l2meta = next;
1395f50f88b9SKevin Wolf         }
13960fa9131aSKevin Wolf 
13973fc48d09SFrediano Ziglio         remaining_sectors -= cur_nr_sectors;
13983fc48d09SFrediano Ziglio         sector_num += cur_nr_sectors;
13993fc48d09SFrediano Ziglio         bytes_done += cur_nr_sectors * 512;
14003cce16f4SKevin Wolf         trace_qcow2_writev_done_part(qemu_coroutine_self(), cur_nr_sectors);
14015ebaa27eSFrediano Ziglio     }
14023fc48d09SFrediano Ziglio     ret = 0;
1403faf575c1SFrediano Ziglio 
14043fc48d09SFrediano Ziglio fail:
14054e95314eSKevin Wolf     qemu_co_mutex_unlock(&s->lock);
14064e95314eSKevin Wolf 
140788c6588cSKevin Wolf     while (l2meta != NULL) {
140888c6588cSKevin Wolf         QCowL2Meta *next;
140988c6588cSKevin Wolf 
14104e95314eSKevin Wolf         if (l2meta->nb_clusters != 0) {
14114e95314eSKevin Wolf             QLIST_REMOVE(l2meta, next_in_flight);
14124e95314eSKevin Wolf         }
14134e95314eSKevin Wolf         qemu_co_queue_restart_all(&l2meta->dependent_requests);
141488c6588cSKevin Wolf 
141588c6588cSKevin Wolf         next = l2meta->next;
1416cf5c1a23SKevin Wolf         g_free(l2meta);
141788c6588cSKevin Wolf         l2meta = next;
1418cf5c1a23SKevin Wolf     }
14190fa9131aSKevin Wolf 
14203fc48d09SFrediano Ziglio     qemu_iovec_destroy(&hd_qiov);
1421dea43a65SFrediano Ziglio     qemu_vfree(cluster_data);
14223cce16f4SKevin Wolf     trace_qcow2_writev_done_req(qemu_coroutine_self(), ret);
142342496d62SKevin Wolf 
142468d100e9SKevin Wolf     return ret;
1425585f8587Sbellard }
1426585f8587Sbellard 
14277c80ab3fSJes Sorensen static void qcow2_close(BlockDriverState *bs)
1428585f8587Sbellard {
1429585f8587Sbellard     BDRVQcowState *s = bs->opaque;
1430de82815dSKevin Wolf     qemu_vfree(s->l1_table);
1431cf93980eSMax Reitz     /* else pre-write overlap checks in cache_destroy may crash */
1432cf93980eSMax Reitz     s->l1_table = NULL;
143329c1a730SKevin Wolf 
143427eb6c09SKevin Wolf     if (!(bs->open_flags & BDRV_O_INCOMING)) {
14353b5e14c7SMax Reitz         int ret1, ret2;
143629c1a730SKevin Wolf 
14373b5e14c7SMax Reitz         ret1 = qcow2_cache_flush(bs, s->l2_table_cache);
14383b5e14c7SMax Reitz         ret2 = qcow2_cache_flush(bs, s->refcount_block_cache);
14393b5e14c7SMax Reitz 
14403b5e14c7SMax Reitz         if (ret1) {
14413b5e14c7SMax Reitz             error_report("Failed to flush the L2 table cache: %s",
14423b5e14c7SMax Reitz                          strerror(-ret1));
14433b5e14c7SMax Reitz         }
14443b5e14c7SMax Reitz         if (ret2) {
14453b5e14c7SMax Reitz             error_report("Failed to flush the refcount block cache: %s",
14463b5e14c7SMax Reitz                          strerror(-ret2));
14473b5e14c7SMax Reitz         }
14483b5e14c7SMax Reitz 
14493b5e14c7SMax Reitz         if (!ret1 && !ret2) {
1450c61d0004SStefan Hajnoczi             qcow2_mark_clean(bs);
145127eb6c09SKevin Wolf         }
14523b5e14c7SMax Reitz     }
1453c61d0004SStefan Hajnoczi 
145429c1a730SKevin Wolf     qcow2_cache_destroy(bs, s->l2_table_cache);
145529c1a730SKevin Wolf     qcow2_cache_destroy(bs, s->refcount_block_cache);
145629c1a730SKevin Wolf 
14576744cbabSKevin Wolf     g_free(s->unknown_header_fields);
145875bab85cSKevin Wolf     cleanup_unknown_header_ext(bs);
14596744cbabSKevin Wolf 
14607267c094SAnthony Liguori     g_free(s->cluster_cache);
1461dea43a65SFrediano Ziglio     qemu_vfree(s->cluster_data);
1462ed6ccf0fSKevin Wolf     qcow2_refcount_close(bs);
146328c1202bSLi Zhi Hui     qcow2_free_snapshots(bs);
1464585f8587Sbellard }
1465585f8587Sbellard 
14665a8a30dbSKevin Wolf static void qcow2_invalidate_cache(BlockDriverState *bs, Error **errp)
146706d9260fSAnthony Liguori {
146806d9260fSAnthony Liguori     BDRVQcowState *s = bs->opaque;
146906d9260fSAnthony Liguori     int flags = s->flags;
147006d9260fSAnthony Liguori     AES_KEY aes_encrypt_key;
147106d9260fSAnthony Liguori     AES_KEY aes_decrypt_key;
147206d9260fSAnthony Liguori     uint32_t crypt_method = 0;
1473acdfb480SKevin Wolf     QDict *options;
14745a8a30dbSKevin Wolf     Error *local_err = NULL;
14755a8a30dbSKevin Wolf     int ret;
147606d9260fSAnthony Liguori 
147706d9260fSAnthony Liguori     /*
147806d9260fSAnthony Liguori      * Backing files are read-only which makes all of their metadata immutable,
147906d9260fSAnthony Liguori      * that means we don't have to worry about reopening them here.
148006d9260fSAnthony Liguori      */
148106d9260fSAnthony Liguori 
148206d9260fSAnthony Liguori     if (s->crypt_method) {
148306d9260fSAnthony Liguori         crypt_method = s->crypt_method;
148406d9260fSAnthony Liguori         memcpy(&aes_encrypt_key, &s->aes_encrypt_key, sizeof(aes_encrypt_key));
148506d9260fSAnthony Liguori         memcpy(&aes_decrypt_key, &s->aes_decrypt_key, sizeof(aes_decrypt_key));
148606d9260fSAnthony Liguori     }
148706d9260fSAnthony Liguori 
148806d9260fSAnthony Liguori     qcow2_close(bs);
148906d9260fSAnthony Liguori 
14905a8a30dbSKevin Wolf     bdrv_invalidate_cache(bs->file, &local_err);
14915a8a30dbSKevin Wolf     if (local_err) {
14925a8a30dbSKevin Wolf         error_propagate(errp, local_err);
14935a8a30dbSKevin Wolf         return;
14945a8a30dbSKevin Wolf     }
14953456a8d1SKevin Wolf 
149606d9260fSAnthony Liguori     memset(s, 0, sizeof(BDRVQcowState));
1497d475e5acSKevin Wolf     options = qdict_clone_shallow(bs->options);
14985a8a30dbSKevin Wolf 
14995a8a30dbSKevin Wolf     ret = qcow2_open(bs, options, flags, &local_err);
1500a1904e48SMarkus Armbruster     QDECREF(options);
15015a8a30dbSKevin Wolf     if (local_err) {
15025a8a30dbSKevin Wolf         error_setg(errp, "Could not reopen qcow2 layer: %s",
15035a8a30dbSKevin Wolf                    error_get_pretty(local_err));
15045a8a30dbSKevin Wolf         error_free(local_err);
15055a8a30dbSKevin Wolf         return;
15065a8a30dbSKevin Wolf     } else if (ret < 0) {
15075a8a30dbSKevin Wolf         error_setg_errno(errp, -ret, "Could not reopen qcow2 layer");
15085a8a30dbSKevin Wolf         return;
15095a8a30dbSKevin Wolf     }
1510acdfb480SKevin Wolf 
151106d9260fSAnthony Liguori     if (crypt_method) {
151206d9260fSAnthony Liguori         s->crypt_method = crypt_method;
151306d9260fSAnthony Liguori         memcpy(&s->aes_encrypt_key, &aes_encrypt_key, sizeof(aes_encrypt_key));
151406d9260fSAnthony Liguori         memcpy(&s->aes_decrypt_key, &aes_decrypt_key, sizeof(aes_decrypt_key));
151506d9260fSAnthony Liguori     }
151606d9260fSAnthony Liguori }
151706d9260fSAnthony Liguori 
1518e24e49e6SKevin Wolf static size_t header_ext_add(char *buf, uint32_t magic, const void *s,
1519e24e49e6SKevin Wolf     size_t len, size_t buflen)
1520756e6736SKevin Wolf {
1521e24e49e6SKevin Wolf     QCowExtension *ext_backing_fmt = (QCowExtension*) buf;
1522e24e49e6SKevin Wolf     size_t ext_len = sizeof(QCowExtension) + ((len + 7) & ~7);
1523756e6736SKevin Wolf 
1524e24e49e6SKevin Wolf     if (buflen < ext_len) {
1525756e6736SKevin Wolf         return -ENOSPC;
1526756e6736SKevin Wolf     }
1527756e6736SKevin Wolf 
1528e24e49e6SKevin Wolf     *ext_backing_fmt = (QCowExtension) {
1529e24e49e6SKevin Wolf         .magic  = cpu_to_be32(magic),
1530e24e49e6SKevin Wolf         .len    = cpu_to_be32(len),
1531e24e49e6SKevin Wolf     };
1532e24e49e6SKevin Wolf     memcpy(buf + sizeof(QCowExtension), s, len);
1533756e6736SKevin Wolf 
1534e24e49e6SKevin Wolf     return ext_len;
1535756e6736SKevin Wolf }
1536756e6736SKevin Wolf 
1537e24e49e6SKevin Wolf /*
1538e24e49e6SKevin Wolf  * Updates the qcow2 header, including the variable length parts of it, i.e.
1539e24e49e6SKevin Wolf  * the backing file name and all extensions. qcow2 was not designed to allow
1540e24e49e6SKevin Wolf  * such changes, so if we run out of space (we can only use the first cluster)
1541e24e49e6SKevin Wolf  * this function may fail.
1542e24e49e6SKevin Wolf  *
1543e24e49e6SKevin Wolf  * Returns 0 on success, -errno in error cases.
1544e24e49e6SKevin Wolf  */
1545e24e49e6SKevin Wolf int qcow2_update_header(BlockDriverState *bs)
1546e24e49e6SKevin Wolf {
1547e24e49e6SKevin Wolf     BDRVQcowState *s = bs->opaque;
1548e24e49e6SKevin Wolf     QCowHeader *header;
1549e24e49e6SKevin Wolf     char *buf;
1550e24e49e6SKevin Wolf     size_t buflen = s->cluster_size;
1551e24e49e6SKevin Wolf     int ret;
1552e24e49e6SKevin Wolf     uint64_t total_size;
1553e24e49e6SKevin Wolf     uint32_t refcount_table_clusters;
15546744cbabSKevin Wolf     size_t header_length;
155575bab85cSKevin Wolf     Qcow2UnknownHeaderExtension *uext;
1556e24e49e6SKevin Wolf 
1557e24e49e6SKevin Wolf     buf = qemu_blockalign(bs, buflen);
1558e24e49e6SKevin Wolf 
1559e24e49e6SKevin Wolf     /* Header structure */
1560e24e49e6SKevin Wolf     header = (QCowHeader*) buf;
1561e24e49e6SKevin Wolf 
1562e24e49e6SKevin Wolf     if (buflen < sizeof(*header)) {
1563e24e49e6SKevin Wolf         ret = -ENOSPC;
1564e24e49e6SKevin Wolf         goto fail;
1565756e6736SKevin Wolf     }
1566756e6736SKevin Wolf 
15676744cbabSKevin Wolf     header_length = sizeof(*header) + s->unknown_header_fields_size;
1568e24e49e6SKevin Wolf     total_size = bs->total_sectors * BDRV_SECTOR_SIZE;
1569e24e49e6SKevin Wolf     refcount_table_clusters = s->refcount_table_size >> (s->cluster_bits - 3);
1570e24e49e6SKevin Wolf 
1571e24e49e6SKevin Wolf     *header = (QCowHeader) {
15726744cbabSKevin Wolf         /* Version 2 fields */
1573e24e49e6SKevin Wolf         .magic                  = cpu_to_be32(QCOW_MAGIC),
15746744cbabSKevin Wolf         .version                = cpu_to_be32(s->qcow_version),
1575e24e49e6SKevin Wolf         .backing_file_offset    = 0,
1576e24e49e6SKevin Wolf         .backing_file_size      = 0,
1577e24e49e6SKevin Wolf         .cluster_bits           = cpu_to_be32(s->cluster_bits),
1578e24e49e6SKevin Wolf         .size                   = cpu_to_be64(total_size),
1579e24e49e6SKevin Wolf         .crypt_method           = cpu_to_be32(s->crypt_method_header),
1580e24e49e6SKevin Wolf         .l1_size                = cpu_to_be32(s->l1_size),
1581e24e49e6SKevin Wolf         .l1_table_offset        = cpu_to_be64(s->l1_table_offset),
1582e24e49e6SKevin Wolf         .refcount_table_offset  = cpu_to_be64(s->refcount_table_offset),
1583e24e49e6SKevin Wolf         .refcount_table_clusters = cpu_to_be32(refcount_table_clusters),
1584e24e49e6SKevin Wolf         .nb_snapshots           = cpu_to_be32(s->nb_snapshots),
1585e24e49e6SKevin Wolf         .snapshots_offset       = cpu_to_be64(s->snapshots_offset),
15866744cbabSKevin Wolf 
15876744cbabSKevin Wolf         /* Version 3 fields */
15886744cbabSKevin Wolf         .incompatible_features  = cpu_to_be64(s->incompatible_features),
15896744cbabSKevin Wolf         .compatible_features    = cpu_to_be64(s->compatible_features),
15906744cbabSKevin Wolf         .autoclear_features     = cpu_to_be64(s->autoclear_features),
1591b6481f37SMax Reitz         .refcount_order         = cpu_to_be32(s->refcount_order),
15926744cbabSKevin Wolf         .header_length          = cpu_to_be32(header_length),
1593e24e49e6SKevin Wolf     };
1594e24e49e6SKevin Wolf 
15956744cbabSKevin Wolf     /* For older versions, write a shorter header */
15966744cbabSKevin Wolf     switch (s->qcow_version) {
15976744cbabSKevin Wolf     case 2:
15986744cbabSKevin Wolf         ret = offsetof(QCowHeader, incompatible_features);
15996744cbabSKevin Wolf         break;
16006744cbabSKevin Wolf     case 3:
16016744cbabSKevin Wolf         ret = sizeof(*header);
16026744cbabSKevin Wolf         break;
16036744cbabSKevin Wolf     default:
1604b6c14762SJim Meyering         ret = -EINVAL;
1605b6c14762SJim Meyering         goto fail;
16066744cbabSKevin Wolf     }
16076744cbabSKevin Wolf 
16086744cbabSKevin Wolf     buf += ret;
16096744cbabSKevin Wolf     buflen -= ret;
16106744cbabSKevin Wolf     memset(buf, 0, buflen);
16116744cbabSKevin Wolf 
16126744cbabSKevin Wolf     /* Preserve any unknown field in the header */
16136744cbabSKevin Wolf     if (s->unknown_header_fields_size) {
16146744cbabSKevin Wolf         if (buflen < s->unknown_header_fields_size) {
16156744cbabSKevin Wolf             ret = -ENOSPC;
16166744cbabSKevin Wolf             goto fail;
16176744cbabSKevin Wolf         }
16186744cbabSKevin Wolf 
16196744cbabSKevin Wolf         memcpy(buf, s->unknown_header_fields, s->unknown_header_fields_size);
16206744cbabSKevin Wolf         buf += s->unknown_header_fields_size;
16216744cbabSKevin Wolf         buflen -= s->unknown_header_fields_size;
16226744cbabSKevin Wolf     }
1623e24e49e6SKevin Wolf 
1624e24e49e6SKevin Wolf     /* Backing file format header extension */
1625e24e49e6SKevin Wolf     if (*bs->backing_format) {
1626e24e49e6SKevin Wolf         ret = header_ext_add(buf, QCOW2_EXT_MAGIC_BACKING_FORMAT,
1627e24e49e6SKevin Wolf                              bs->backing_format, strlen(bs->backing_format),
1628e24e49e6SKevin Wolf                              buflen);
1629756e6736SKevin Wolf         if (ret < 0) {
1630756e6736SKevin Wolf             goto fail;
1631756e6736SKevin Wolf         }
1632756e6736SKevin Wolf 
1633e24e49e6SKevin Wolf         buf += ret;
1634e24e49e6SKevin Wolf         buflen -= ret;
1635e24e49e6SKevin Wolf     }
1636756e6736SKevin Wolf 
1637cfcc4c62SKevin Wolf     /* Feature table */
1638cfcc4c62SKevin Wolf     Qcow2Feature features[] = {
1639c61d0004SStefan Hajnoczi         {
1640c61d0004SStefan Hajnoczi             .type = QCOW2_FEAT_TYPE_INCOMPATIBLE,
1641c61d0004SStefan Hajnoczi             .bit  = QCOW2_INCOMPAT_DIRTY_BITNR,
1642c61d0004SStefan Hajnoczi             .name = "dirty bit",
1643c61d0004SStefan Hajnoczi         },
1644bfe8043eSStefan Hajnoczi         {
164569c98726SMax Reitz             .type = QCOW2_FEAT_TYPE_INCOMPATIBLE,
164669c98726SMax Reitz             .bit  = QCOW2_INCOMPAT_CORRUPT_BITNR,
164769c98726SMax Reitz             .name = "corrupt bit",
164869c98726SMax Reitz         },
164969c98726SMax Reitz         {
1650bfe8043eSStefan Hajnoczi             .type = QCOW2_FEAT_TYPE_COMPATIBLE,
1651bfe8043eSStefan Hajnoczi             .bit  = QCOW2_COMPAT_LAZY_REFCOUNTS_BITNR,
1652bfe8043eSStefan Hajnoczi             .name = "lazy refcounts",
1653bfe8043eSStefan Hajnoczi         },
1654cfcc4c62SKevin Wolf     };
1655cfcc4c62SKevin Wolf 
1656cfcc4c62SKevin Wolf     ret = header_ext_add(buf, QCOW2_EXT_MAGIC_FEATURE_TABLE,
1657cfcc4c62SKevin Wolf                          features, sizeof(features), buflen);
1658cfcc4c62SKevin Wolf     if (ret < 0) {
1659cfcc4c62SKevin Wolf         goto fail;
1660cfcc4c62SKevin Wolf     }
1661cfcc4c62SKevin Wolf     buf += ret;
1662cfcc4c62SKevin Wolf     buflen -= ret;
1663cfcc4c62SKevin Wolf 
166475bab85cSKevin Wolf     /* Keep unknown header extensions */
166575bab85cSKevin Wolf     QLIST_FOREACH(uext, &s->unknown_header_ext, next) {
166675bab85cSKevin Wolf         ret = header_ext_add(buf, uext->magic, uext->data, uext->len, buflen);
166775bab85cSKevin Wolf         if (ret < 0) {
166875bab85cSKevin Wolf             goto fail;
166975bab85cSKevin Wolf         }
167075bab85cSKevin Wolf 
167175bab85cSKevin Wolf         buf += ret;
167275bab85cSKevin Wolf         buflen -= ret;
167375bab85cSKevin Wolf     }
167475bab85cSKevin Wolf 
1675e24e49e6SKevin Wolf     /* End of header extensions */
1676e24e49e6SKevin Wolf     ret = header_ext_add(buf, QCOW2_EXT_MAGIC_END, NULL, 0, buflen);
1677756e6736SKevin Wolf     if (ret < 0) {
1678756e6736SKevin Wolf         goto fail;
1679756e6736SKevin Wolf     }
1680756e6736SKevin Wolf 
1681e24e49e6SKevin Wolf     buf += ret;
1682e24e49e6SKevin Wolf     buflen -= ret;
1683e24e49e6SKevin Wolf 
1684e24e49e6SKevin Wolf     /* Backing file name */
1685e24e49e6SKevin Wolf     if (*bs->backing_file) {
1686e24e49e6SKevin Wolf         size_t backing_file_len = strlen(bs->backing_file);
1687e24e49e6SKevin Wolf 
1688e24e49e6SKevin Wolf         if (buflen < backing_file_len) {
1689e24e49e6SKevin Wolf             ret = -ENOSPC;
1690e24e49e6SKevin Wolf             goto fail;
1691e24e49e6SKevin Wolf         }
1692e24e49e6SKevin Wolf 
169300ea1881SJim Meyering         /* Using strncpy is ok here, since buf is not NUL-terminated. */
1694e24e49e6SKevin Wolf         strncpy(buf, bs->backing_file, buflen);
1695e24e49e6SKevin Wolf 
1696e24e49e6SKevin Wolf         header->backing_file_offset = cpu_to_be64(buf - ((char*) header));
1697e24e49e6SKevin Wolf         header->backing_file_size   = cpu_to_be32(backing_file_len);
1698e24e49e6SKevin Wolf     }
1699e24e49e6SKevin Wolf 
1700e24e49e6SKevin Wolf     /* Write the new header */
1701e24e49e6SKevin Wolf     ret = bdrv_pwrite(bs->file, 0, header, s->cluster_size);
1702756e6736SKevin Wolf     if (ret < 0) {
1703756e6736SKevin Wolf         goto fail;
1704756e6736SKevin Wolf     }
1705756e6736SKevin Wolf 
1706756e6736SKevin Wolf     ret = 0;
1707756e6736SKevin Wolf fail:
1708e24e49e6SKevin Wolf     qemu_vfree(header);
1709756e6736SKevin Wolf     return ret;
1710756e6736SKevin Wolf }
1711756e6736SKevin Wolf 
1712756e6736SKevin Wolf static int qcow2_change_backing_file(BlockDriverState *bs,
1713756e6736SKevin Wolf     const char *backing_file, const char *backing_fmt)
1714756e6736SKevin Wolf {
1715e24e49e6SKevin Wolf     pstrcpy(bs->backing_file, sizeof(bs->backing_file), backing_file ?: "");
1716e24e49e6SKevin Wolf     pstrcpy(bs->backing_format, sizeof(bs->backing_format), backing_fmt ?: "");
1717e24e49e6SKevin Wolf 
1718e24e49e6SKevin Wolf     return qcow2_update_header(bs);
1719756e6736SKevin Wolf }
1720756e6736SKevin Wolf 
1721a35e1c17SKevin Wolf static int preallocate(BlockDriverState *bs)
1722a35e1c17SKevin Wolf {
1723a35e1c17SKevin Wolf     uint64_t nb_sectors;
1724a35e1c17SKevin Wolf     uint64_t offset;
1725060bee89SKevin Wolf     uint64_t host_offset = 0;
1726a35e1c17SKevin Wolf     int num;
1727148da7eaSKevin Wolf     int ret;
1728f50f88b9SKevin Wolf     QCowL2Meta *meta;
1729a35e1c17SKevin Wolf 
173057322b78SMarkus Armbruster     nb_sectors = bdrv_nb_sectors(bs);
1731a35e1c17SKevin Wolf     offset = 0;
1732a35e1c17SKevin Wolf 
1733a35e1c17SKevin Wolf     while (nb_sectors) {
17347c2bbf4aSHu Tao         num = MIN(nb_sectors, INT_MAX >> BDRV_SECTOR_BITS);
173516f0587eSHu Tao         ret = qcow2_alloc_cluster_offset(bs, offset, &num,
1736060bee89SKevin Wolf                                          &host_offset, &meta);
1737148da7eaSKevin Wolf         if (ret < 0) {
173819dbcbf7SKevin Wolf             return ret;
1739a35e1c17SKevin Wolf         }
1740a35e1c17SKevin Wolf 
1741c792707fSStefan Hajnoczi         while (meta) {
1742c792707fSStefan Hajnoczi             QCowL2Meta *next = meta->next;
1743c792707fSStefan Hajnoczi 
1744f50f88b9SKevin Wolf             ret = qcow2_alloc_cluster_link_l2(bs, meta);
174519dbcbf7SKevin Wolf             if (ret < 0) {
17467c2bbf4aSHu Tao                 qcow2_free_any_clusters(bs, meta->alloc_offset,
17477c2bbf4aSHu Tao                                         meta->nb_clusters, QCOW2_DISCARD_NEVER);
174819dbcbf7SKevin Wolf                 return ret;
1749a35e1c17SKevin Wolf             }
1750a35e1c17SKevin Wolf 
17517c2bbf4aSHu Tao             /* There are no dependent requests, but we need to remove our
17527c2bbf4aSHu Tao              * request from the list of in-flight requests */
17534e95314eSKevin Wolf             QLIST_REMOVE(meta, next_in_flight);
1754c792707fSStefan Hajnoczi 
1755c792707fSStefan Hajnoczi             g_free(meta);
1756c792707fSStefan Hajnoczi             meta = next;
1757f50f88b9SKevin Wolf         }
1758f214978aSKevin Wolf 
1759a35e1c17SKevin Wolf         /* TODO Preallocate data if requested */
1760a35e1c17SKevin Wolf 
1761a35e1c17SKevin Wolf         nb_sectors -= num;
17627c2bbf4aSHu Tao         offset += num << BDRV_SECTOR_BITS;
1763a35e1c17SKevin Wolf     }
1764a35e1c17SKevin Wolf 
1765a35e1c17SKevin Wolf     /*
1766a35e1c17SKevin Wolf      * It is expected that the image file is large enough to actually contain
1767a35e1c17SKevin Wolf      * all of the allocated clusters (otherwise we get failing reads after
1768a35e1c17SKevin Wolf      * EOF). Extend the image to the last allocated sector.
1769a35e1c17SKevin Wolf      */
1770060bee89SKevin Wolf     if (host_offset != 0) {
17717c2bbf4aSHu Tao         uint8_t buf[BDRV_SECTOR_SIZE];
17727c2bbf4aSHu Tao         memset(buf, 0, BDRV_SECTOR_SIZE);
17737c2bbf4aSHu Tao         ret = bdrv_write(bs->file, (host_offset >> BDRV_SECTOR_BITS) + num - 1,
17747c2bbf4aSHu Tao                          buf, 1);
177519dbcbf7SKevin Wolf         if (ret < 0) {
177619dbcbf7SKevin Wolf             return ret;
177719dbcbf7SKevin Wolf         }
1778a35e1c17SKevin Wolf     }
1779a35e1c17SKevin Wolf 
1780a35e1c17SKevin Wolf     return 0;
1781a35e1c17SKevin Wolf }
1782a35e1c17SKevin Wolf 
17837c80ab3fSJes Sorensen static int qcow2_create2(const char *filename, int64_t total_size,
1784a9420734SKevin Wolf                          const char *backing_file, const char *backing_format,
1785ffeaac9bSHu Tao                          int flags, size_t cluster_size, PreallocMode prealloc,
1786bd4b167fSMax Reitz                          QemuOpts *opts, int version, int refcount_order,
17873ef6c40aSMax Reitz                          Error **errp)
1788a9420734SKevin Wolf {
17899b2260cbSDong Xu Wang     /* Calculate cluster_bits */
1790a9420734SKevin Wolf     int cluster_bits;
1791a9420734SKevin Wolf     cluster_bits = ffs(cluster_size) - 1;
1792a9420734SKevin Wolf     if (cluster_bits < MIN_CLUSTER_BITS || cluster_bits > MAX_CLUSTER_BITS ||
1793a9420734SKevin Wolf         (1 << cluster_bits) != cluster_size)
1794a9420734SKevin Wolf     {
17953ef6c40aSMax Reitz         error_setg(errp, "Cluster size must be a power of two between %d and "
17963ef6c40aSMax Reitz                    "%dk", 1 << MIN_CLUSTER_BITS, 1 << (MAX_CLUSTER_BITS - 10));
1797a9420734SKevin Wolf         return -EINVAL;
1798a9420734SKevin Wolf     }
1799a9420734SKevin Wolf 
1800a9420734SKevin Wolf     /*
1801a9420734SKevin Wolf      * Open the image file and write a minimal qcow2 header.
1802a9420734SKevin Wolf      *
1803a9420734SKevin Wolf      * We keep things simple and start with a zero-sized image. We also
1804a9420734SKevin Wolf      * do without refcount blocks or a L1 table for now. We'll fix the
1805a9420734SKevin Wolf      * inconsistency later.
1806a9420734SKevin Wolf      *
1807a9420734SKevin Wolf      * We do need a refcount table because growing the refcount table means
1808a9420734SKevin Wolf      * allocating two new refcount blocks - the seconds of which would be at
1809a9420734SKevin Wolf      * 2 GB for 64k clusters, and we don't want to have a 2 GB initial file
1810a9420734SKevin Wolf      * size for any qcow2 image.
1811a9420734SKevin Wolf      */
1812a9420734SKevin Wolf     BlockDriverState* bs;
1813f8413b3cSKevin Wolf     QCowHeader *header;
1814b106ad91SKevin Wolf     uint64_t* refcount_table;
18153ef6c40aSMax Reitz     Error *local_err = NULL;
1816a9420734SKevin Wolf     int ret;
1817a9420734SKevin Wolf 
18180e4271b7SHu Tao     if (prealloc == PREALLOC_MODE_FULL || prealloc == PREALLOC_MODE_FALLOC) {
1819bd4b167fSMax Reitz         /* Note: The following calculation does not need to be exact; if it is a
1820bd4b167fSMax Reitz          * bit off, either some bytes will be "leaked" (which is fine) or we
1821bd4b167fSMax Reitz          * will need to increase the file size by some bytes (which is fine,
1822bd4b167fSMax Reitz          * too, as long as the bulk is allocated here). Therefore, using
1823bd4b167fSMax Reitz          * floating point arithmetic is fine. */
18240e4271b7SHu Tao         int64_t meta_size = 0;
18250e4271b7SHu Tao         uint64_t nreftablee, nrefblocke, nl1e, nl2e;
18260e4271b7SHu Tao         int64_t aligned_total_size = align_offset(total_size, cluster_size);
1827bd4b167fSMax Reitz         int refblock_bits, refblock_size;
1828bd4b167fSMax Reitz         /* refcount entry size in bytes */
1829bd4b167fSMax Reitz         double rces = (1 << refcount_order) / 8.;
1830bd4b167fSMax Reitz 
1831bd4b167fSMax Reitz         /* see qcow2_open() */
1832bd4b167fSMax Reitz         refblock_bits = cluster_bits - (refcount_order - 3);
1833bd4b167fSMax Reitz         refblock_size = 1 << refblock_bits;
18340e4271b7SHu Tao 
18350e4271b7SHu Tao         /* header: 1 cluster */
18360e4271b7SHu Tao         meta_size += cluster_size;
18370e4271b7SHu Tao 
18380e4271b7SHu Tao         /* total size of L2 tables */
18390e4271b7SHu Tao         nl2e = aligned_total_size / cluster_size;
18400e4271b7SHu Tao         nl2e = align_offset(nl2e, cluster_size / sizeof(uint64_t));
18410e4271b7SHu Tao         meta_size += nl2e * sizeof(uint64_t);
18420e4271b7SHu Tao 
18430e4271b7SHu Tao         /* total size of L1 tables */
18440e4271b7SHu Tao         nl1e = nl2e * sizeof(uint64_t) / cluster_size;
18450e4271b7SHu Tao         nl1e = align_offset(nl1e, cluster_size / sizeof(uint64_t));
18460e4271b7SHu Tao         meta_size += nl1e * sizeof(uint64_t);
18470e4271b7SHu Tao 
18480e4271b7SHu Tao         /* total size of refcount blocks
18490e4271b7SHu Tao          *
18500e4271b7SHu Tao          * note: every host cluster is reference-counted, including metadata
18510e4271b7SHu Tao          * (even refcount blocks are recursively included).
18520e4271b7SHu Tao          * Let:
18530e4271b7SHu Tao          *   a = total_size (this is the guest disk size)
18540e4271b7SHu Tao          *   m = meta size not including refcount blocks and refcount tables
18550e4271b7SHu Tao          *   c = cluster size
18560e4271b7SHu Tao          *   y1 = number of refcount blocks entries
18570e4271b7SHu Tao          *   y2 = meta size including everything
1858bd4b167fSMax Reitz          *   rces = refcount entry size in bytes
18590e4271b7SHu Tao          * then,
18600e4271b7SHu Tao          *   y1 = (y2 + a)/c
1861bd4b167fSMax Reitz          *   y2 = y1 * rces + y1 * rces * sizeof(u64) / c + m
18620e4271b7SHu Tao          * we can get y1:
1863bd4b167fSMax Reitz          *   y1 = (a + m) / (c - rces - rces * sizeof(u64) / c)
18640e4271b7SHu Tao          */
1865bd4b167fSMax Reitz         nrefblocke = (aligned_total_size + meta_size + cluster_size)
1866bd4b167fSMax Reitz                    / (cluster_size - rces - rces * sizeof(uint64_t)
1867bd4b167fSMax Reitz                                                  / cluster_size);
1868bd4b167fSMax Reitz         meta_size += DIV_ROUND_UP(nrefblocke, refblock_size) * cluster_size;
18690e4271b7SHu Tao 
18700e4271b7SHu Tao         /* total size of refcount tables */
1871bd4b167fSMax Reitz         nreftablee = nrefblocke / refblock_size;
18720e4271b7SHu Tao         nreftablee = align_offset(nreftablee, cluster_size / sizeof(uint64_t));
18730e4271b7SHu Tao         meta_size += nreftablee * sizeof(uint64_t);
18740e4271b7SHu Tao 
18750e4271b7SHu Tao         qemu_opt_set_number(opts, BLOCK_OPT_SIZE,
187639101f25SMarkus Armbruster                             aligned_total_size + meta_size, &error_abort);
1877f43e47dbSMarkus Armbruster         qemu_opt_set(opts, BLOCK_OPT_PREALLOC, PreallocMode_lookup[prealloc],
1878f43e47dbSMarkus Armbruster                      &error_abort);
18790e4271b7SHu Tao     }
18800e4271b7SHu Tao 
1881c282e1fdSChunyan Liu     ret = bdrv_create_file(filename, opts, &local_err);
1882a9420734SKevin Wolf     if (ret < 0) {
18833ef6c40aSMax Reitz         error_propagate(errp, local_err);
1884a9420734SKevin Wolf         return ret;
1885a9420734SKevin Wolf     }
1886a9420734SKevin Wolf 
18872e40134bSMax Reitz     bs = NULL;
18882e40134bSMax Reitz     ret = bdrv_open(&bs, filename, NULL, NULL, BDRV_O_RDWR | BDRV_O_PROTOCOL,
18892e40134bSMax Reitz                     NULL, &local_err);
1890a9420734SKevin Wolf     if (ret < 0) {
18913ef6c40aSMax Reitz         error_propagate(errp, local_err);
1892a9420734SKevin Wolf         return ret;
1893a9420734SKevin Wolf     }
1894a9420734SKevin Wolf 
1895a9420734SKevin Wolf     /* Write the header */
1896f8413b3cSKevin Wolf     QEMU_BUILD_BUG_ON((1 << MIN_CLUSTER_BITS) < sizeof(*header));
1897f8413b3cSKevin Wolf     header = g_malloc0(cluster_size);
1898f8413b3cSKevin Wolf     *header = (QCowHeader) {
1899f8413b3cSKevin Wolf         .magic                      = cpu_to_be32(QCOW_MAGIC),
1900f8413b3cSKevin Wolf         .version                    = cpu_to_be32(version),
1901f8413b3cSKevin Wolf         .cluster_bits               = cpu_to_be32(cluster_bits),
1902f8413b3cSKevin Wolf         .size                       = cpu_to_be64(0),
1903f8413b3cSKevin Wolf         .l1_table_offset            = cpu_to_be64(0),
1904f8413b3cSKevin Wolf         .l1_size                    = cpu_to_be32(0),
1905f8413b3cSKevin Wolf         .refcount_table_offset      = cpu_to_be64(cluster_size),
1906f8413b3cSKevin Wolf         .refcount_table_clusters    = cpu_to_be32(1),
1907bd4b167fSMax Reitz         .refcount_order             = cpu_to_be32(refcount_order),
1908f8413b3cSKevin Wolf         .header_length              = cpu_to_be32(sizeof(*header)),
1909f8413b3cSKevin Wolf     };
1910a9420734SKevin Wolf 
1911a9420734SKevin Wolf     if (flags & BLOCK_FLAG_ENCRYPT) {
1912f8413b3cSKevin Wolf         header->crypt_method = cpu_to_be32(QCOW_CRYPT_AES);
1913a9420734SKevin Wolf     } else {
1914f8413b3cSKevin Wolf         header->crypt_method = cpu_to_be32(QCOW_CRYPT_NONE);
1915a9420734SKevin Wolf     }
1916a9420734SKevin Wolf 
1917bfe8043eSStefan Hajnoczi     if (flags & BLOCK_FLAG_LAZY_REFCOUNTS) {
1918f8413b3cSKevin Wolf         header->compatible_features |=
1919bfe8043eSStefan Hajnoczi             cpu_to_be64(QCOW2_COMPAT_LAZY_REFCOUNTS);
1920bfe8043eSStefan Hajnoczi     }
1921bfe8043eSStefan Hajnoczi 
1922f8413b3cSKevin Wolf     ret = bdrv_pwrite(bs, 0, header, cluster_size);
1923f8413b3cSKevin Wolf     g_free(header);
1924a9420734SKevin Wolf     if (ret < 0) {
19253ef6c40aSMax Reitz         error_setg_errno(errp, -ret, "Could not write qcow2 header");
1926a9420734SKevin Wolf         goto out;
1927a9420734SKevin Wolf     }
1928a9420734SKevin Wolf 
1929b106ad91SKevin Wolf     /* Write a refcount table with one refcount block */
1930b106ad91SKevin Wolf     refcount_table = g_malloc0(2 * cluster_size);
1931b106ad91SKevin Wolf     refcount_table[0] = cpu_to_be64(2 * cluster_size);
1932b106ad91SKevin Wolf     ret = bdrv_pwrite(bs, cluster_size, refcount_table, 2 * cluster_size);
19337267c094SAnthony Liguori     g_free(refcount_table);
1934a9420734SKevin Wolf 
1935a9420734SKevin Wolf     if (ret < 0) {
19363ef6c40aSMax Reitz         error_setg_errno(errp, -ret, "Could not write refcount table");
1937a9420734SKevin Wolf         goto out;
1938a9420734SKevin Wolf     }
1939a9420734SKevin Wolf 
1940f67503e5SMax Reitz     bdrv_unref(bs);
1941f67503e5SMax Reitz     bs = NULL;
1942a9420734SKevin Wolf 
1943a9420734SKevin Wolf     /*
1944a9420734SKevin Wolf      * And now open the image and make it consistent first (i.e. increase the
1945a9420734SKevin Wolf      * refcount of the cluster that is occupied by the header and the refcount
1946a9420734SKevin Wolf      * table)
1947a9420734SKevin Wolf      */
1948ddf5636dSMax Reitz     ret = bdrv_open(&bs, filename, NULL, NULL,
1949ef810437SMax Reitz                     BDRV_O_RDWR | BDRV_O_CACHE_WB | BDRV_O_NO_FLUSH,
1950ef810437SMax Reitz                     &bdrv_qcow2, &local_err);
1951a9420734SKevin Wolf     if (ret < 0) {
19523ef6c40aSMax Reitz         error_propagate(errp, local_err);
1953a9420734SKevin Wolf         goto out;
1954a9420734SKevin Wolf     }
1955a9420734SKevin Wolf 
1956b106ad91SKevin Wolf     ret = qcow2_alloc_clusters(bs, 3 * cluster_size);
1957a9420734SKevin Wolf     if (ret < 0) {
19583ef6c40aSMax Reitz         error_setg_errno(errp, -ret, "Could not allocate clusters for qcow2 "
19593ef6c40aSMax Reitz                          "header and refcount table");
1960a9420734SKevin Wolf         goto out;
1961a9420734SKevin Wolf 
1962a9420734SKevin Wolf     } else if (ret != 0) {
1963a9420734SKevin Wolf         error_report("Huh, first cluster in empty image is already in use?");
1964a9420734SKevin Wolf         abort();
1965a9420734SKevin Wolf     }
1966a9420734SKevin Wolf 
1967a9420734SKevin Wolf     /* Okay, now that we have a valid image, let's give it the right size */
1968180e9526SHu Tao     ret = bdrv_truncate(bs, total_size);
1969a9420734SKevin Wolf     if (ret < 0) {
19703ef6c40aSMax Reitz         error_setg_errno(errp, -ret, "Could not resize image");
1971a9420734SKevin Wolf         goto out;
1972a9420734SKevin Wolf     }
1973a9420734SKevin Wolf 
1974a9420734SKevin Wolf     /* Want a backing file? There you go.*/
1975a9420734SKevin Wolf     if (backing_file) {
1976a9420734SKevin Wolf         ret = bdrv_change_backing_file(bs, backing_file, backing_format);
1977a9420734SKevin Wolf         if (ret < 0) {
19783ef6c40aSMax Reitz             error_setg_errno(errp, -ret, "Could not assign backing file '%s' "
19793ef6c40aSMax Reitz                              "with format '%s'", backing_file, backing_format);
1980a9420734SKevin Wolf             goto out;
1981a9420734SKevin Wolf         }
1982a9420734SKevin Wolf     }
1983a9420734SKevin Wolf 
1984a9420734SKevin Wolf     /* And if we're supposed to preallocate metadata, do that now */
19850e4271b7SHu Tao     if (prealloc != PREALLOC_MODE_OFF) {
198615552c4aSZhi Yong Wu         BDRVQcowState *s = bs->opaque;
198715552c4aSZhi Yong Wu         qemu_co_mutex_lock(&s->lock);
1988a9420734SKevin Wolf         ret = preallocate(bs);
198915552c4aSZhi Yong Wu         qemu_co_mutex_unlock(&s->lock);
1990a9420734SKevin Wolf         if (ret < 0) {
19913ef6c40aSMax Reitz             error_setg_errno(errp, -ret, "Could not preallocate metadata");
1992a9420734SKevin Wolf             goto out;
1993a9420734SKevin Wolf         }
1994a9420734SKevin Wolf     }
1995a9420734SKevin Wolf 
1996f67503e5SMax Reitz     bdrv_unref(bs);
1997f67503e5SMax Reitz     bs = NULL;
1998ba2ab2f2SMax Reitz 
1999ba2ab2f2SMax Reitz     /* Reopen the image without BDRV_O_NO_FLUSH to flush it before returning */
2000ddf5636dSMax Reitz     ret = bdrv_open(&bs, filename, NULL, NULL,
2001c9fbb99dSKevin Wolf                     BDRV_O_RDWR | BDRV_O_CACHE_WB | BDRV_O_NO_BACKING,
2002ef810437SMax Reitz                     &bdrv_qcow2, &local_err);
200384d18f06SMarkus Armbruster     if (local_err) {
2004ba2ab2f2SMax Reitz         error_propagate(errp, local_err);
2005ba2ab2f2SMax Reitz         goto out;
2006ba2ab2f2SMax Reitz     }
2007ba2ab2f2SMax Reitz 
2008a9420734SKevin Wolf     ret = 0;
2009a9420734SKevin Wolf out:
2010f67503e5SMax Reitz     if (bs) {
20114f6fd349SFam Zheng         bdrv_unref(bs);
2012f67503e5SMax Reitz     }
2013a9420734SKevin Wolf     return ret;
2014a9420734SKevin Wolf }
2015de5f3f40SKevin Wolf 
20161bd0e2d1SChunyan Liu static int qcow2_create(const char *filename, QemuOpts *opts, Error **errp)
2017de5f3f40SKevin Wolf {
20181bd0e2d1SChunyan Liu     char *backing_file = NULL;
20191bd0e2d1SChunyan Liu     char *backing_fmt = NULL;
20201bd0e2d1SChunyan Liu     char *buf = NULL;
2021180e9526SHu Tao     uint64_t size = 0;
2022de5f3f40SKevin Wolf     int flags = 0;
202399cce9faSKevin Wolf     size_t cluster_size = DEFAULT_CLUSTER_SIZE;
2024ffeaac9bSHu Tao     PreallocMode prealloc;
20258ad1898cSKevin Wolf     int version = 3;
2026bd4b167fSMax Reitz     uint64_t refcount_bits = 16;
2027bd4b167fSMax Reitz     int refcount_order;
20283ef6c40aSMax Reitz     Error *local_err = NULL;
20293ef6c40aSMax Reitz     int ret;
2030de5f3f40SKevin Wolf 
2031de5f3f40SKevin Wolf     /* Read out options */
2032180e9526SHu Tao     size = ROUND_UP(qemu_opt_get_size_del(opts, BLOCK_OPT_SIZE, 0),
2033c2eb918eSHu Tao                     BDRV_SECTOR_SIZE);
20341bd0e2d1SChunyan Liu     backing_file = qemu_opt_get_del(opts, BLOCK_OPT_BACKING_FILE);
20351bd0e2d1SChunyan Liu     backing_fmt = qemu_opt_get_del(opts, BLOCK_OPT_BACKING_FMT);
20361bd0e2d1SChunyan Liu     if (qemu_opt_get_bool_del(opts, BLOCK_OPT_ENCRYPT, false)) {
20371bd0e2d1SChunyan Liu         flags |= BLOCK_FLAG_ENCRYPT;
2038de5f3f40SKevin Wolf     }
20391bd0e2d1SChunyan Liu     cluster_size = qemu_opt_get_size_del(opts, BLOCK_OPT_CLUSTER_SIZE,
20401bd0e2d1SChunyan Liu                                          DEFAULT_CLUSTER_SIZE);
20411bd0e2d1SChunyan Liu     buf = qemu_opt_get_del(opts, BLOCK_OPT_PREALLOC);
2042ffeaac9bSHu Tao     prealloc = qapi_enum_parse(PreallocMode_lookup, buf,
2043ffeaac9bSHu Tao                                PREALLOC_MODE_MAX, PREALLOC_MODE_OFF,
2044ffeaac9bSHu Tao                                &local_err);
2045ffeaac9bSHu Tao     if (local_err) {
2046ffeaac9bSHu Tao         error_propagate(errp, local_err);
20471bd0e2d1SChunyan Liu         ret = -EINVAL;
20481bd0e2d1SChunyan Liu         goto finish;
2049de5f3f40SKevin Wolf     }
20501bd0e2d1SChunyan Liu     g_free(buf);
20511bd0e2d1SChunyan Liu     buf = qemu_opt_get_del(opts, BLOCK_OPT_COMPAT_LEVEL);
20521bd0e2d1SChunyan Liu     if (!buf) {
20539117b477SKevin Wolf         /* keep the default */
20541bd0e2d1SChunyan Liu     } else if (!strcmp(buf, "0.10")) {
20556744cbabSKevin Wolf         version = 2;
20561bd0e2d1SChunyan Liu     } else if (!strcmp(buf, "1.1")) {
20576744cbabSKevin Wolf         version = 3;
20586744cbabSKevin Wolf     } else {
20591bd0e2d1SChunyan Liu         error_setg(errp, "Invalid compatibility level: '%s'", buf);
20601bd0e2d1SChunyan Liu         ret = -EINVAL;
20611bd0e2d1SChunyan Liu         goto finish;
20626744cbabSKevin Wolf     }
20631bd0e2d1SChunyan Liu 
20641bd0e2d1SChunyan Liu     if (qemu_opt_get_bool_del(opts, BLOCK_OPT_LAZY_REFCOUNTS, false)) {
20651bd0e2d1SChunyan Liu         flags |= BLOCK_FLAG_LAZY_REFCOUNTS;
2066de5f3f40SKevin Wolf     }
2067de5f3f40SKevin Wolf 
2068ffeaac9bSHu Tao     if (backing_file && prealloc != PREALLOC_MODE_OFF) {
20693ef6c40aSMax Reitz         error_setg(errp, "Backing file and preallocation cannot be used at "
20703ef6c40aSMax Reitz                    "the same time");
20711bd0e2d1SChunyan Liu         ret = -EINVAL;
20721bd0e2d1SChunyan Liu         goto finish;
2073de5f3f40SKevin Wolf     }
2074de5f3f40SKevin Wolf 
2075bfe8043eSStefan Hajnoczi     if (version < 3 && (flags & BLOCK_FLAG_LAZY_REFCOUNTS)) {
20763ef6c40aSMax Reitz         error_setg(errp, "Lazy refcounts only supported with compatibility "
20773ef6c40aSMax Reitz                    "level 1.1 and above (use compat=1.1 or greater)");
20781bd0e2d1SChunyan Liu         ret = -EINVAL;
20791bd0e2d1SChunyan Liu         goto finish;
2080bfe8043eSStefan Hajnoczi     }
2081bfe8043eSStefan Hajnoczi 
208206d05fa7SMax Reitz     refcount_bits = qemu_opt_get_number_del(opts, BLOCK_OPT_REFCOUNT_BITS,
208306d05fa7SMax Reitz                                             refcount_bits);
208406d05fa7SMax Reitz     if (refcount_bits > 64 || !is_power_of_2(refcount_bits)) {
208506d05fa7SMax Reitz         error_setg(errp, "Refcount width must be a power of two and may not "
208606d05fa7SMax Reitz                    "exceed 64 bits");
208706d05fa7SMax Reitz         ret = -EINVAL;
208806d05fa7SMax Reitz         goto finish;
208906d05fa7SMax Reitz     }
209006d05fa7SMax Reitz 
2091bd4b167fSMax Reitz     if (version < 3 && refcount_bits != 16) {
2092bd4b167fSMax Reitz         error_setg(errp, "Different refcount widths than 16 bits require "
2093bd4b167fSMax Reitz                    "compatibility level 1.1 or above (use compat=1.1 or "
2094bd4b167fSMax Reitz                    "greater)");
2095bd4b167fSMax Reitz         ret = -EINVAL;
2096bd4b167fSMax Reitz         goto finish;
2097bd4b167fSMax Reitz     }
2098bd4b167fSMax Reitz 
2099bd4b167fSMax Reitz     refcount_order = ffs(refcount_bits) - 1;
2100bd4b167fSMax Reitz 
2101180e9526SHu Tao     ret = qcow2_create2(filename, size, backing_file, backing_fmt, flags,
2102bd4b167fSMax Reitz                         cluster_size, prealloc, opts, version, refcount_order,
2103bd4b167fSMax Reitz                         &local_err);
210484d18f06SMarkus Armbruster     if (local_err) {
21053ef6c40aSMax Reitz         error_propagate(errp, local_err);
21063ef6c40aSMax Reitz     }
21071bd0e2d1SChunyan Liu 
21081bd0e2d1SChunyan Liu finish:
21091bd0e2d1SChunyan Liu     g_free(backing_file);
21101bd0e2d1SChunyan Liu     g_free(backing_fmt);
21111bd0e2d1SChunyan Liu     g_free(buf);
21123ef6c40aSMax Reitz     return ret;
2113de5f3f40SKevin Wolf }
2114de5f3f40SKevin Wolf 
2115621f0589SKevin Wolf static coroutine_fn int qcow2_co_write_zeroes(BlockDriverState *bs,
2116aa7bfbffSPeter Lieven     int64_t sector_num, int nb_sectors, BdrvRequestFlags flags)
2117621f0589SKevin Wolf {
2118621f0589SKevin Wolf     int ret;
2119621f0589SKevin Wolf     BDRVQcowState *s = bs->opaque;
2120621f0589SKevin Wolf 
2121621f0589SKevin Wolf     /* Emulate misaligned zero writes */
2122621f0589SKevin Wolf     if (sector_num % s->cluster_sectors || nb_sectors % s->cluster_sectors) {
2123621f0589SKevin Wolf         return -ENOTSUP;
2124621f0589SKevin Wolf     }
2125621f0589SKevin Wolf 
2126621f0589SKevin Wolf     /* Whatever is left can use real zero clusters */
2127621f0589SKevin Wolf     qemu_co_mutex_lock(&s->lock);
2128621f0589SKevin Wolf     ret = qcow2_zero_clusters(bs, sector_num << BDRV_SECTOR_BITS,
2129621f0589SKevin Wolf         nb_sectors);
2130621f0589SKevin Wolf     qemu_co_mutex_unlock(&s->lock);
2131621f0589SKevin Wolf 
2132621f0589SKevin Wolf     return ret;
2133621f0589SKevin Wolf }
2134621f0589SKevin Wolf 
21356db39ae2SPaolo Bonzini static coroutine_fn int qcow2_co_discard(BlockDriverState *bs,
21366db39ae2SPaolo Bonzini     int64_t sector_num, int nb_sectors)
21375ea929e3SKevin Wolf {
21386db39ae2SPaolo Bonzini     int ret;
21396db39ae2SPaolo Bonzini     BDRVQcowState *s = bs->opaque;
21406db39ae2SPaolo Bonzini 
21416db39ae2SPaolo Bonzini     qemu_co_mutex_lock(&s->lock);
21426db39ae2SPaolo Bonzini     ret = qcow2_discard_clusters(bs, sector_num << BDRV_SECTOR_BITS,
2143808c4b6fSMax Reitz         nb_sectors, QCOW2_DISCARD_REQUEST, false);
21446db39ae2SPaolo Bonzini     qemu_co_mutex_unlock(&s->lock);
21456db39ae2SPaolo Bonzini     return ret;
21465ea929e3SKevin Wolf }
21475ea929e3SKevin Wolf 
2148419b19d9SStefan Hajnoczi static int qcow2_truncate(BlockDriverState *bs, int64_t offset)
2149419b19d9SStefan Hajnoczi {
2150419b19d9SStefan Hajnoczi     BDRVQcowState *s = bs->opaque;
21512cf7cfa1SKevin Wolf     int64_t new_l1_size;
21522cf7cfa1SKevin Wolf     int ret;
2153419b19d9SStefan Hajnoczi 
2154419b19d9SStefan Hajnoczi     if (offset & 511) {
2155259b2173SKevin Wolf         error_report("The new size must be a multiple of 512");
2156419b19d9SStefan Hajnoczi         return -EINVAL;
2157419b19d9SStefan Hajnoczi     }
2158419b19d9SStefan Hajnoczi 
2159419b19d9SStefan Hajnoczi     /* cannot proceed if image has snapshots */
2160419b19d9SStefan Hajnoczi     if (s->nb_snapshots) {
2161259b2173SKevin Wolf         error_report("Can't resize an image which has snapshots");
2162419b19d9SStefan Hajnoczi         return -ENOTSUP;
2163419b19d9SStefan Hajnoczi     }
2164419b19d9SStefan Hajnoczi 
2165419b19d9SStefan Hajnoczi     /* shrinking is currently not supported */
2166419b19d9SStefan Hajnoczi     if (offset < bs->total_sectors * 512) {
2167259b2173SKevin Wolf         error_report("qcow2 doesn't support shrinking images yet");
2168419b19d9SStefan Hajnoczi         return -ENOTSUP;
2169419b19d9SStefan Hajnoczi     }
2170419b19d9SStefan Hajnoczi 
2171419b19d9SStefan Hajnoczi     new_l1_size = size_to_l1(s, offset);
217272893756SStefan Hajnoczi     ret = qcow2_grow_l1_table(bs, new_l1_size, true);
2173419b19d9SStefan Hajnoczi     if (ret < 0) {
2174419b19d9SStefan Hajnoczi         return ret;
2175419b19d9SStefan Hajnoczi     }
2176419b19d9SStefan Hajnoczi 
2177419b19d9SStefan Hajnoczi     /* write updated header.size */
2178419b19d9SStefan Hajnoczi     offset = cpu_to_be64(offset);
21798b3b7206SKevin Wolf     ret = bdrv_pwrite_sync(bs->file, offsetof(QCowHeader, size),
2180419b19d9SStefan Hajnoczi                            &offset, sizeof(uint64_t));
2181419b19d9SStefan Hajnoczi     if (ret < 0) {
2182419b19d9SStefan Hajnoczi         return ret;
2183419b19d9SStefan Hajnoczi     }
2184419b19d9SStefan Hajnoczi 
2185419b19d9SStefan Hajnoczi     s->l1_vm_state_index = new_l1_size;
2186419b19d9SStefan Hajnoczi     return 0;
2187419b19d9SStefan Hajnoczi }
2188419b19d9SStefan Hajnoczi 
218920d97356SBlue Swirl /* XXX: put compressed sectors first, then all the cluster aligned
219020d97356SBlue Swirl    tables to avoid losing bytes in alignment */
21917c80ab3fSJes Sorensen static int qcow2_write_compressed(BlockDriverState *bs, int64_t sector_num,
219220d97356SBlue Swirl                                   const uint8_t *buf, int nb_sectors)
219320d97356SBlue Swirl {
219420d97356SBlue Swirl     BDRVQcowState *s = bs->opaque;
219520d97356SBlue Swirl     z_stream strm;
219620d97356SBlue Swirl     int ret, out_len;
219720d97356SBlue Swirl     uint8_t *out_buf;
219820d97356SBlue Swirl     uint64_t cluster_offset;
219920d97356SBlue Swirl 
220020d97356SBlue Swirl     if (nb_sectors == 0) {
220120d97356SBlue Swirl         /* align end of file to a sector boundary to ease reading with
220220d97356SBlue Swirl            sector based I/Os */
220366f82ceeSKevin Wolf         cluster_offset = bdrv_getlength(bs->file);
22046a69b962SMax Reitz         return bdrv_truncate(bs->file, cluster_offset);
220520d97356SBlue Swirl     }
220620d97356SBlue Swirl 
2207f4d38befSStefan Hajnoczi     if (nb_sectors != s->cluster_sectors) {
2208f4d38befSStefan Hajnoczi         ret = -EINVAL;
2209f4d38befSStefan Hajnoczi 
2210f4d38befSStefan Hajnoczi         /* Zero-pad last write if image size is not cluster aligned */
2211f4d38befSStefan Hajnoczi         if (sector_num + nb_sectors == bs->total_sectors &&
2212f4d38befSStefan Hajnoczi             nb_sectors < s->cluster_sectors) {
2213f4d38befSStefan Hajnoczi             uint8_t *pad_buf = qemu_blockalign(bs, s->cluster_size);
2214f4d38befSStefan Hajnoczi             memset(pad_buf, 0, s->cluster_size);
2215f4d38befSStefan Hajnoczi             memcpy(pad_buf, buf, nb_sectors * BDRV_SECTOR_SIZE);
2216f4d38befSStefan Hajnoczi             ret = qcow2_write_compressed(bs, sector_num,
2217f4d38befSStefan Hajnoczi                                          pad_buf, s->cluster_sectors);
2218f4d38befSStefan Hajnoczi             qemu_vfree(pad_buf);
2219f4d38befSStefan Hajnoczi         }
2220f4d38befSStefan Hajnoczi         return ret;
2221f4d38befSStefan Hajnoczi     }
222220d97356SBlue Swirl 
22237267c094SAnthony Liguori     out_buf = g_malloc(s->cluster_size + (s->cluster_size / 1000) + 128);
222420d97356SBlue Swirl 
222520d97356SBlue Swirl     /* best compression, small window, no zlib header */
222620d97356SBlue Swirl     memset(&strm, 0, sizeof(strm));
222720d97356SBlue Swirl     ret = deflateInit2(&strm, Z_DEFAULT_COMPRESSION,
222820d97356SBlue Swirl                        Z_DEFLATED, -12,
222920d97356SBlue Swirl                        9, Z_DEFAULT_STRATEGY);
223020d97356SBlue Swirl     if (ret != 0) {
22318f1efd00SKevin Wolf         ret = -EINVAL;
22328f1efd00SKevin Wolf         goto fail;
223320d97356SBlue Swirl     }
223420d97356SBlue Swirl 
223520d97356SBlue Swirl     strm.avail_in = s->cluster_size;
223620d97356SBlue Swirl     strm.next_in = (uint8_t *)buf;
223720d97356SBlue Swirl     strm.avail_out = s->cluster_size;
223820d97356SBlue Swirl     strm.next_out = out_buf;
223920d97356SBlue Swirl 
224020d97356SBlue Swirl     ret = deflate(&strm, Z_FINISH);
224120d97356SBlue Swirl     if (ret != Z_STREAM_END && ret != Z_OK) {
224220d97356SBlue Swirl         deflateEnd(&strm);
22438f1efd00SKevin Wolf         ret = -EINVAL;
22448f1efd00SKevin Wolf         goto fail;
224520d97356SBlue Swirl     }
224620d97356SBlue Swirl     out_len = strm.next_out - out_buf;
224720d97356SBlue Swirl 
224820d97356SBlue Swirl     deflateEnd(&strm);
224920d97356SBlue Swirl 
225020d97356SBlue Swirl     if (ret != Z_STREAM_END || out_len >= s->cluster_size) {
225120d97356SBlue Swirl         /* could not compress: write normal cluster */
22528f1efd00SKevin Wolf         ret = bdrv_write(bs, sector_num, buf, s->cluster_sectors);
22538f1efd00SKevin Wolf         if (ret < 0) {
22548f1efd00SKevin Wolf             goto fail;
22558f1efd00SKevin Wolf         }
225620d97356SBlue Swirl     } else {
225720d97356SBlue Swirl         cluster_offset = qcow2_alloc_compressed_cluster_offset(bs,
225820d97356SBlue Swirl             sector_num << 9, out_len);
22598f1efd00SKevin Wolf         if (!cluster_offset) {
22608f1efd00SKevin Wolf             ret = -EIO;
22618f1efd00SKevin Wolf             goto fail;
22628f1efd00SKevin Wolf         }
226320d97356SBlue Swirl         cluster_offset &= s->cluster_offset_mask;
2264cf93980eSMax Reitz 
2265231bb267SMax Reitz         ret = qcow2_pre_write_overlap_check(bs, 0, cluster_offset, out_len);
2266cf93980eSMax Reitz         if (ret < 0) {
2267cf93980eSMax Reitz             goto fail;
2268cf93980eSMax Reitz         }
2269cf93980eSMax Reitz 
227066f82ceeSKevin Wolf         BLKDBG_EVENT(bs->file, BLKDBG_WRITE_COMPRESSED);
22718f1efd00SKevin Wolf         ret = bdrv_pwrite(bs->file, cluster_offset, out_buf, out_len);
22728f1efd00SKevin Wolf         if (ret < 0) {
22738f1efd00SKevin Wolf             goto fail;
227420d97356SBlue Swirl         }
227520d97356SBlue Swirl     }
227620d97356SBlue Swirl 
22778f1efd00SKevin Wolf     ret = 0;
22788f1efd00SKevin Wolf fail:
22797267c094SAnthony Liguori     g_free(out_buf);
22808f1efd00SKevin Wolf     return ret;
228120d97356SBlue Swirl }
228220d97356SBlue Swirl 
228394054183SMax Reitz static int make_completely_empty(BlockDriverState *bs)
228494054183SMax Reitz {
228594054183SMax Reitz     BDRVQcowState *s = bs->opaque;
228694054183SMax Reitz     int ret, l1_clusters;
228794054183SMax Reitz     int64_t offset;
228894054183SMax Reitz     uint64_t *new_reftable = NULL;
228994054183SMax Reitz     uint64_t rt_entry, l1_size2;
229094054183SMax Reitz     struct {
229194054183SMax Reitz         uint64_t l1_offset;
229294054183SMax Reitz         uint64_t reftable_offset;
229394054183SMax Reitz         uint32_t reftable_clusters;
229494054183SMax Reitz     } QEMU_PACKED l1_ofs_rt_ofs_cls;
229594054183SMax Reitz 
229694054183SMax Reitz     ret = qcow2_cache_empty(bs, s->l2_table_cache);
229794054183SMax Reitz     if (ret < 0) {
229894054183SMax Reitz         goto fail;
229994054183SMax Reitz     }
230094054183SMax Reitz 
230194054183SMax Reitz     ret = qcow2_cache_empty(bs, s->refcount_block_cache);
230294054183SMax Reitz     if (ret < 0) {
230394054183SMax Reitz         goto fail;
230494054183SMax Reitz     }
230594054183SMax Reitz 
230694054183SMax Reitz     /* Refcounts will be broken utterly */
230794054183SMax Reitz     ret = qcow2_mark_dirty(bs);
230894054183SMax Reitz     if (ret < 0) {
230994054183SMax Reitz         goto fail;
231094054183SMax Reitz     }
231194054183SMax Reitz 
231294054183SMax Reitz     BLKDBG_EVENT(bs->file, BLKDBG_L1_UPDATE);
231394054183SMax Reitz 
231494054183SMax Reitz     l1_clusters = DIV_ROUND_UP(s->l1_size, s->cluster_size / sizeof(uint64_t));
231594054183SMax Reitz     l1_size2 = (uint64_t)s->l1_size * sizeof(uint64_t);
231694054183SMax Reitz 
231794054183SMax Reitz     /* After this call, neither the in-memory nor the on-disk refcount
231894054183SMax Reitz      * information accurately describe the actual references */
231994054183SMax Reitz 
232094054183SMax Reitz     ret = bdrv_write_zeroes(bs->file, s->l1_table_offset / BDRV_SECTOR_SIZE,
232194054183SMax Reitz                             l1_clusters * s->cluster_sectors, 0);
232294054183SMax Reitz     if (ret < 0) {
232394054183SMax Reitz         goto fail_broken_refcounts;
232494054183SMax Reitz     }
232594054183SMax Reitz     memset(s->l1_table, 0, l1_size2);
232694054183SMax Reitz 
232794054183SMax Reitz     BLKDBG_EVENT(bs->file, BLKDBG_EMPTY_IMAGE_PREPARE);
232894054183SMax Reitz 
232994054183SMax Reitz     /* Overwrite enough clusters at the beginning of the sectors to place
233094054183SMax Reitz      * the refcount table, a refcount block and the L1 table in; this may
233194054183SMax Reitz      * overwrite parts of the existing refcount and L1 table, which is not
233294054183SMax Reitz      * an issue because the dirty flag is set, complete data loss is in fact
233394054183SMax Reitz      * desired and partial data loss is consequently fine as well */
233494054183SMax Reitz     ret = bdrv_write_zeroes(bs->file, s->cluster_size / BDRV_SECTOR_SIZE,
233594054183SMax Reitz                             (2 + l1_clusters) * s->cluster_size /
233694054183SMax Reitz                             BDRV_SECTOR_SIZE, 0);
233794054183SMax Reitz     /* This call (even if it failed overall) may have overwritten on-disk
233894054183SMax Reitz      * refcount structures; in that case, the in-memory refcount information
233994054183SMax Reitz      * will probably differ from the on-disk information which makes the BDS
234094054183SMax Reitz      * unusable */
234194054183SMax Reitz     if (ret < 0) {
234294054183SMax Reitz         goto fail_broken_refcounts;
234394054183SMax Reitz     }
234494054183SMax Reitz 
234594054183SMax Reitz     BLKDBG_EVENT(bs->file, BLKDBG_L1_UPDATE);
234694054183SMax Reitz     BLKDBG_EVENT(bs->file, BLKDBG_REFTABLE_UPDATE);
234794054183SMax Reitz 
234894054183SMax Reitz     /* "Create" an empty reftable (one cluster) directly after the image
234994054183SMax Reitz      * header and an empty L1 table three clusters after the image header;
235094054183SMax Reitz      * the cluster between those two will be used as the first refblock */
235194054183SMax Reitz     cpu_to_be64w(&l1_ofs_rt_ofs_cls.l1_offset, 3 * s->cluster_size);
235294054183SMax Reitz     cpu_to_be64w(&l1_ofs_rt_ofs_cls.reftable_offset, s->cluster_size);
235394054183SMax Reitz     cpu_to_be32w(&l1_ofs_rt_ofs_cls.reftable_clusters, 1);
235494054183SMax Reitz     ret = bdrv_pwrite_sync(bs->file, offsetof(QCowHeader, l1_table_offset),
235594054183SMax Reitz                            &l1_ofs_rt_ofs_cls, sizeof(l1_ofs_rt_ofs_cls));
235694054183SMax Reitz     if (ret < 0) {
235794054183SMax Reitz         goto fail_broken_refcounts;
235894054183SMax Reitz     }
235994054183SMax Reitz 
236094054183SMax Reitz     s->l1_table_offset = 3 * s->cluster_size;
236194054183SMax Reitz 
236294054183SMax Reitz     new_reftable = g_try_new0(uint64_t, s->cluster_size / sizeof(uint64_t));
236394054183SMax Reitz     if (!new_reftable) {
236494054183SMax Reitz         ret = -ENOMEM;
236594054183SMax Reitz         goto fail_broken_refcounts;
236694054183SMax Reitz     }
236794054183SMax Reitz 
236894054183SMax Reitz     s->refcount_table_offset = s->cluster_size;
236994054183SMax Reitz     s->refcount_table_size   = s->cluster_size / sizeof(uint64_t);
237094054183SMax Reitz 
237194054183SMax Reitz     g_free(s->refcount_table);
237294054183SMax Reitz     s->refcount_table = new_reftable;
237394054183SMax Reitz     new_reftable = NULL;
237494054183SMax Reitz 
237594054183SMax Reitz     /* Now the in-memory refcount information again corresponds to the on-disk
237694054183SMax Reitz      * information (reftable is empty and no refblocks (the refblock cache is
237794054183SMax Reitz      * empty)); however, this means some clusters (e.g. the image header) are
237894054183SMax Reitz      * referenced, but not refcounted, but the normal qcow2 code assumes that
237994054183SMax Reitz      * the in-memory information is always correct */
238094054183SMax Reitz 
238194054183SMax Reitz     BLKDBG_EVENT(bs->file, BLKDBG_REFBLOCK_ALLOC);
238294054183SMax Reitz 
238394054183SMax Reitz     /* Enter the first refblock into the reftable */
238494054183SMax Reitz     rt_entry = cpu_to_be64(2 * s->cluster_size);
238594054183SMax Reitz     ret = bdrv_pwrite_sync(bs->file, s->cluster_size,
238694054183SMax Reitz                            &rt_entry, sizeof(rt_entry));
238794054183SMax Reitz     if (ret < 0) {
238894054183SMax Reitz         goto fail_broken_refcounts;
238994054183SMax Reitz     }
239094054183SMax Reitz     s->refcount_table[0] = 2 * s->cluster_size;
239194054183SMax Reitz 
239294054183SMax Reitz     s->free_cluster_index = 0;
239394054183SMax Reitz     assert(3 + l1_clusters <= s->refcount_block_size);
239494054183SMax Reitz     offset = qcow2_alloc_clusters(bs, 3 * s->cluster_size + l1_size2);
239594054183SMax Reitz     if (offset < 0) {
239694054183SMax Reitz         ret = offset;
239794054183SMax Reitz         goto fail_broken_refcounts;
239894054183SMax Reitz     } else if (offset > 0) {
239994054183SMax Reitz         error_report("First cluster in emptied image is in use");
240094054183SMax Reitz         abort();
240194054183SMax Reitz     }
240294054183SMax Reitz 
240394054183SMax Reitz     /* Now finally the in-memory information corresponds to the on-disk
240494054183SMax Reitz      * structures and is correct */
240594054183SMax Reitz     ret = qcow2_mark_clean(bs);
240694054183SMax Reitz     if (ret < 0) {
240794054183SMax Reitz         goto fail;
240894054183SMax Reitz     }
240994054183SMax Reitz 
241094054183SMax Reitz     ret = bdrv_truncate(bs->file, (3 + l1_clusters) * s->cluster_size);
241194054183SMax Reitz     if (ret < 0) {
241294054183SMax Reitz         goto fail;
241394054183SMax Reitz     }
241494054183SMax Reitz 
241594054183SMax Reitz     return 0;
241694054183SMax Reitz 
241794054183SMax Reitz fail_broken_refcounts:
241894054183SMax Reitz     /* The BDS is unusable at this point. If we wanted to make it usable, we
241994054183SMax Reitz      * would have to call qcow2_refcount_close(), qcow2_refcount_init(),
242094054183SMax Reitz      * qcow2_check_refcounts(), qcow2_refcount_close() and qcow2_refcount_init()
242194054183SMax Reitz      * again. However, because the functions which could have caused this error
242294054183SMax Reitz      * path to be taken are used by those functions as well, it's very likely
242394054183SMax Reitz      * that that sequence will fail as well. Therefore, just eject the BDS. */
242494054183SMax Reitz     bs->drv = NULL;
242594054183SMax Reitz 
242694054183SMax Reitz fail:
242794054183SMax Reitz     g_free(new_reftable);
242894054183SMax Reitz     return ret;
242994054183SMax Reitz }
243094054183SMax Reitz 
2431491d27e2SMax Reitz static int qcow2_make_empty(BlockDriverState *bs)
2432491d27e2SMax Reitz {
243394054183SMax Reitz     BDRVQcowState *s = bs->opaque;
2434491d27e2SMax Reitz     uint64_t start_sector;
2435491d27e2SMax Reitz     int sector_step = INT_MAX / BDRV_SECTOR_SIZE;
243694054183SMax Reitz     int l1_clusters, ret = 0;
2437491d27e2SMax Reitz 
243894054183SMax Reitz     l1_clusters = DIV_ROUND_UP(s->l1_size, s->cluster_size / sizeof(uint64_t));
243994054183SMax Reitz 
244094054183SMax Reitz     if (s->qcow_version >= 3 && !s->snapshots &&
244194054183SMax Reitz         3 + l1_clusters <= s->refcount_block_size) {
244294054183SMax Reitz         /* The following function only works for qcow2 v3 images (it requires
244394054183SMax Reitz          * the dirty flag) and only as long as there are no snapshots (because
244494054183SMax Reitz          * it completely empties the image). Furthermore, the L1 table and three
244594054183SMax Reitz          * additional clusters (image header, refcount table, one refcount
244694054183SMax Reitz          * block) have to fit inside one refcount block. */
244794054183SMax Reitz         return make_completely_empty(bs);
244894054183SMax Reitz     }
244994054183SMax Reitz 
245094054183SMax Reitz     /* This fallback code simply discards every active cluster; this is slow,
245194054183SMax Reitz      * but works in all cases */
2452491d27e2SMax Reitz     for (start_sector = 0; start_sector < bs->total_sectors;
2453491d27e2SMax Reitz          start_sector += sector_step)
2454491d27e2SMax Reitz     {
2455491d27e2SMax Reitz         /* As this function is generally used after committing an external
2456491d27e2SMax Reitz          * snapshot, QCOW2_DISCARD_SNAPSHOT seems appropriate. Also, the
2457491d27e2SMax Reitz          * default action for this kind of discard is to pass the discard,
2458491d27e2SMax Reitz          * which will ideally result in an actually smaller image file, as
2459491d27e2SMax Reitz          * is probably desired. */
2460491d27e2SMax Reitz         ret = qcow2_discard_clusters(bs, start_sector * BDRV_SECTOR_SIZE,
2461491d27e2SMax Reitz                                      MIN(sector_step,
2462491d27e2SMax Reitz                                          bs->total_sectors - start_sector),
2463491d27e2SMax Reitz                                      QCOW2_DISCARD_SNAPSHOT, true);
2464491d27e2SMax Reitz         if (ret < 0) {
2465491d27e2SMax Reitz             break;
2466491d27e2SMax Reitz         }
2467491d27e2SMax Reitz     }
2468491d27e2SMax Reitz 
2469491d27e2SMax Reitz     return ret;
2470491d27e2SMax Reitz }
2471491d27e2SMax Reitz 
2472a968168cSDong Xu Wang static coroutine_fn int qcow2_co_flush_to_os(BlockDriverState *bs)
247320d97356SBlue Swirl {
247429c1a730SKevin Wolf     BDRVQcowState *s = bs->opaque;
247529c1a730SKevin Wolf     int ret;
247629c1a730SKevin Wolf 
24778b94ff85SPaolo Bonzini     qemu_co_mutex_lock(&s->lock);
247829c1a730SKevin Wolf     ret = qcow2_cache_flush(bs, s->l2_table_cache);
247929c1a730SKevin Wolf     if (ret < 0) {
2480c95de7e2SDong Xu Wang         qemu_co_mutex_unlock(&s->lock);
24818b94ff85SPaolo Bonzini         return ret;
248229c1a730SKevin Wolf     }
248329c1a730SKevin Wolf 
2484bfe8043eSStefan Hajnoczi     if (qcow2_need_accurate_refcounts(s)) {
248529c1a730SKevin Wolf         ret = qcow2_cache_flush(bs, s->refcount_block_cache);
248629c1a730SKevin Wolf         if (ret < 0) {
2487c95de7e2SDong Xu Wang             qemu_co_mutex_unlock(&s->lock);
24888b94ff85SPaolo Bonzini             return ret;
248929c1a730SKevin Wolf         }
2490bfe8043eSStefan Hajnoczi     }
24918b94ff85SPaolo Bonzini     qemu_co_mutex_unlock(&s->lock);
249229c1a730SKevin Wolf 
2493eb489bb1SKevin Wolf     return 0;
2494eb489bb1SKevin Wolf }
2495eb489bb1SKevin Wolf 
24967c80ab3fSJes Sorensen static int qcow2_get_info(BlockDriverState *bs, BlockDriverInfo *bdi)
249720d97356SBlue Swirl {
249820d97356SBlue Swirl     BDRVQcowState *s = bs->opaque;
249995de6d70SPaolo Bonzini     bdi->unallocated_blocks_are_zero = true;
250095de6d70SPaolo Bonzini     bdi->can_write_zeroes_with_unmap = (s->qcow_version >= 3);
250120d97356SBlue Swirl     bdi->cluster_size = s->cluster_size;
25027c80ab3fSJes Sorensen     bdi->vm_state_offset = qcow2_vm_state_offset(s);
250320d97356SBlue Swirl     return 0;
250420d97356SBlue Swirl }
250520d97356SBlue Swirl 
250637764dfbSMax Reitz static ImageInfoSpecific *qcow2_get_specific_info(BlockDriverState *bs)
250737764dfbSMax Reitz {
250837764dfbSMax Reitz     BDRVQcowState *s = bs->opaque;
250937764dfbSMax Reitz     ImageInfoSpecific *spec_info = g_new(ImageInfoSpecific, 1);
251037764dfbSMax Reitz 
251137764dfbSMax Reitz     *spec_info = (ImageInfoSpecific){
251237764dfbSMax Reitz         .kind  = IMAGE_INFO_SPECIFIC_KIND_QCOW2,
251337764dfbSMax Reitz         {
251437764dfbSMax Reitz             .qcow2 = g_new(ImageInfoSpecificQCow2, 1),
251537764dfbSMax Reitz         },
251637764dfbSMax Reitz     };
251737764dfbSMax Reitz     if (s->qcow_version == 2) {
251837764dfbSMax Reitz         *spec_info->qcow2 = (ImageInfoSpecificQCow2){
251937764dfbSMax Reitz             .compat             = g_strdup("0.10"),
25200709c5a1SMax Reitz             .refcount_bits      = s->refcount_bits,
252137764dfbSMax Reitz         };
252237764dfbSMax Reitz     } else if (s->qcow_version == 3) {
252337764dfbSMax Reitz         *spec_info->qcow2 = (ImageInfoSpecificQCow2){
252437764dfbSMax Reitz             .compat             = g_strdup("1.1"),
252537764dfbSMax Reitz             .lazy_refcounts     = s->compatible_features &
252637764dfbSMax Reitz                                   QCOW2_COMPAT_LAZY_REFCOUNTS,
252737764dfbSMax Reitz             .has_lazy_refcounts = true,
25289009b196SMax Reitz             .corrupt            = s->incompatible_features &
25299009b196SMax Reitz                                   QCOW2_INCOMPAT_CORRUPT,
25309009b196SMax Reitz             .has_corrupt        = true,
25310709c5a1SMax Reitz             .refcount_bits      = s->refcount_bits,
253237764dfbSMax Reitz         };
253337764dfbSMax Reitz     }
253437764dfbSMax Reitz 
253537764dfbSMax Reitz     return spec_info;
253637764dfbSMax Reitz }
253737764dfbSMax Reitz 
253820d97356SBlue Swirl #if 0
253920d97356SBlue Swirl static void dump_refcounts(BlockDriverState *bs)
254020d97356SBlue Swirl {
254120d97356SBlue Swirl     BDRVQcowState *s = bs->opaque;
254220d97356SBlue Swirl     int64_t nb_clusters, k, k1, size;
254320d97356SBlue Swirl     int refcount;
254420d97356SBlue Swirl 
254566f82ceeSKevin Wolf     size = bdrv_getlength(bs->file);
254620d97356SBlue Swirl     nb_clusters = size_to_clusters(s, size);
254720d97356SBlue Swirl     for(k = 0; k < nb_clusters;) {
254820d97356SBlue Swirl         k1 = k;
254920d97356SBlue Swirl         refcount = get_refcount(bs, k);
255020d97356SBlue Swirl         k++;
255120d97356SBlue Swirl         while (k < nb_clusters && get_refcount(bs, k) == refcount)
255220d97356SBlue Swirl             k++;
25530bfcd599SBlue Swirl         printf("%" PRId64 ": refcount=%d nb=%" PRId64 "\n", k, refcount,
25540bfcd599SBlue Swirl                k - k1);
255520d97356SBlue Swirl     }
255620d97356SBlue Swirl }
255720d97356SBlue Swirl #endif
255820d97356SBlue Swirl 
2559cf8074b3SKevin Wolf static int qcow2_save_vmstate(BlockDriverState *bs, QEMUIOVector *qiov,
2560cf8074b3SKevin Wolf                               int64_t pos)
256120d97356SBlue Swirl {
256220d97356SBlue Swirl     BDRVQcowState *s = bs->opaque;
2563eedff66fSMax Reitz     int64_t total_sectors = bs->total_sectors;
25646e13610aSMax Reitz     bool zero_beyond_eof = bs->zero_beyond_eof;
256520d97356SBlue Swirl     int ret;
256620d97356SBlue Swirl 
256766f82ceeSKevin Wolf     BLKDBG_EVENT(bs->file, BLKDBG_VMSTATE_SAVE);
25686e13610aSMax Reitz     bs->zero_beyond_eof = false;
25698d3b1a2dSKevin Wolf     ret = bdrv_pwritev(bs, qcow2_vm_state_offset(s) + pos, qiov);
25706e13610aSMax Reitz     bs->zero_beyond_eof = zero_beyond_eof;
257120d97356SBlue Swirl 
2572eedff66fSMax Reitz     /* bdrv_co_do_writev will have increased the total_sectors value to include
2573eedff66fSMax Reitz      * the VM state - the VM state is however not an actual part of the block
2574eedff66fSMax Reitz      * device, therefore, we need to restore the old value. */
2575eedff66fSMax Reitz     bs->total_sectors = total_sectors;
2576eedff66fSMax Reitz 
257720d97356SBlue Swirl     return ret;
257820d97356SBlue Swirl }
257920d97356SBlue Swirl 
25807c80ab3fSJes Sorensen static int qcow2_load_vmstate(BlockDriverState *bs, uint8_t *buf,
258120d97356SBlue Swirl                               int64_t pos, int size)
258220d97356SBlue Swirl {
258320d97356SBlue Swirl     BDRVQcowState *s = bs->opaque;
25840d51b4deSAsias He     bool zero_beyond_eof = bs->zero_beyond_eof;
258520d97356SBlue Swirl     int ret;
258620d97356SBlue Swirl 
258766f82ceeSKevin Wolf     BLKDBG_EVENT(bs->file, BLKDBG_VMSTATE_LOAD);
25880d51b4deSAsias He     bs->zero_beyond_eof = false;
25897c80ab3fSJes Sorensen     ret = bdrv_pread(bs, qcow2_vm_state_offset(s) + pos, buf, size);
25900d51b4deSAsias He     bs->zero_beyond_eof = zero_beyond_eof;
259120d97356SBlue Swirl 
259220d97356SBlue Swirl     return ret;
259320d97356SBlue Swirl }
259420d97356SBlue Swirl 
25959296b3edSMax Reitz /*
25969296b3edSMax Reitz  * Downgrades an image's version. To achieve this, any incompatible features
25979296b3edSMax Reitz  * have to be removed.
25989296b3edSMax Reitz  */
25994057a2b2SMax Reitz static int qcow2_downgrade(BlockDriverState *bs, int target_version,
26004057a2b2SMax Reitz                            BlockDriverAmendStatusCB *status_cb)
26019296b3edSMax Reitz {
26029296b3edSMax Reitz     BDRVQcowState *s = bs->opaque;
26039296b3edSMax Reitz     int current_version = s->qcow_version;
26049296b3edSMax Reitz     int ret;
26059296b3edSMax Reitz 
26069296b3edSMax Reitz     if (target_version == current_version) {
26079296b3edSMax Reitz         return 0;
26089296b3edSMax Reitz     } else if (target_version > current_version) {
26099296b3edSMax Reitz         return -EINVAL;
26109296b3edSMax Reitz     } else if (target_version != 2) {
26119296b3edSMax Reitz         return -EINVAL;
26129296b3edSMax Reitz     }
26139296b3edSMax Reitz 
26149296b3edSMax Reitz     if (s->refcount_order != 4) {
26159296b3edSMax Reitz         /* we would have to convert the image to a refcount_order == 4 image
26169296b3edSMax Reitz          * here; however, since qemu (at the time of writing this) does not
26179296b3edSMax Reitz          * support anything different than 4 anyway, there is no point in doing
26189296b3edSMax Reitz          * so right now; however, we should error out (if qemu supports this in
26199296b3edSMax Reitz          * the future and this code has not been adapted) */
26209296b3edSMax Reitz         error_report("qcow2_downgrade: Image refcount orders other than 4 are "
26219296b3edSMax Reitz                      "currently not supported.");
26229296b3edSMax Reitz         return -ENOTSUP;
26239296b3edSMax Reitz     }
26249296b3edSMax Reitz 
26259296b3edSMax Reitz     /* clear incompatible features */
26269296b3edSMax Reitz     if (s->incompatible_features & QCOW2_INCOMPAT_DIRTY) {
26279296b3edSMax Reitz         ret = qcow2_mark_clean(bs);
26289296b3edSMax Reitz         if (ret < 0) {
26299296b3edSMax Reitz             return ret;
26309296b3edSMax Reitz         }
26319296b3edSMax Reitz     }
26329296b3edSMax Reitz 
26339296b3edSMax Reitz     /* with QCOW2_INCOMPAT_CORRUPT, it is pretty much impossible to get here in
26349296b3edSMax Reitz      * the first place; if that happens nonetheless, returning -ENOTSUP is the
26359296b3edSMax Reitz      * best thing to do anyway */
26369296b3edSMax Reitz 
26379296b3edSMax Reitz     if (s->incompatible_features) {
26389296b3edSMax Reitz         return -ENOTSUP;
26399296b3edSMax Reitz     }
26409296b3edSMax Reitz 
26419296b3edSMax Reitz     /* since we can ignore compatible features, we can set them to 0 as well */
26429296b3edSMax Reitz     s->compatible_features = 0;
26439296b3edSMax Reitz     /* if lazy refcounts have been used, they have already been fixed through
26449296b3edSMax Reitz      * clearing the dirty flag */
26459296b3edSMax Reitz 
26469296b3edSMax Reitz     /* clearing autoclear features is trivial */
26479296b3edSMax Reitz     s->autoclear_features = 0;
26489296b3edSMax Reitz 
26494057a2b2SMax Reitz     ret = qcow2_expand_zero_clusters(bs, status_cb);
26509296b3edSMax Reitz     if (ret < 0) {
26519296b3edSMax Reitz         return ret;
26529296b3edSMax Reitz     }
26539296b3edSMax Reitz 
26549296b3edSMax Reitz     s->qcow_version = target_version;
26559296b3edSMax Reitz     ret = qcow2_update_header(bs);
26569296b3edSMax Reitz     if (ret < 0) {
26579296b3edSMax Reitz         s->qcow_version = current_version;
26589296b3edSMax Reitz         return ret;
26599296b3edSMax Reitz     }
26609296b3edSMax Reitz     return 0;
26619296b3edSMax Reitz }
26629296b3edSMax Reitz 
266377485434SMax Reitz static int qcow2_amend_options(BlockDriverState *bs, QemuOpts *opts,
266477485434SMax Reitz                                BlockDriverAmendStatusCB *status_cb)
26659296b3edSMax Reitz {
26669296b3edSMax Reitz     BDRVQcowState *s = bs->opaque;
26679296b3edSMax Reitz     int old_version = s->qcow_version, new_version = old_version;
26689296b3edSMax Reitz     uint64_t new_size = 0;
26699296b3edSMax Reitz     const char *backing_file = NULL, *backing_format = NULL;
26709296b3edSMax Reitz     bool lazy_refcounts = s->use_lazy_refcounts;
26711bd0e2d1SChunyan Liu     const char *compat = NULL;
26721bd0e2d1SChunyan Liu     uint64_t cluster_size = s->cluster_size;
26731bd0e2d1SChunyan Liu     bool encrypt;
26749296b3edSMax Reitz     int ret;
26751bd0e2d1SChunyan Liu     QemuOptDesc *desc = opts->list->desc;
26769296b3edSMax Reitz 
26771bd0e2d1SChunyan Liu     while (desc && desc->name) {
26781bd0e2d1SChunyan Liu         if (!qemu_opt_find(opts, desc->name)) {
26799296b3edSMax Reitz             /* only change explicitly defined options */
26801bd0e2d1SChunyan Liu             desc++;
26819296b3edSMax Reitz             continue;
26829296b3edSMax Reitz         }
26839296b3edSMax Reitz 
26848a17b83cSMax Reitz         if (!strcmp(desc->name, BLOCK_OPT_COMPAT_LEVEL)) {
26858a17b83cSMax Reitz             compat = qemu_opt_get(opts, BLOCK_OPT_COMPAT_LEVEL);
26861bd0e2d1SChunyan Liu             if (!compat) {
26879296b3edSMax Reitz                 /* preserve default */
26881bd0e2d1SChunyan Liu             } else if (!strcmp(compat, "0.10")) {
26899296b3edSMax Reitz                 new_version = 2;
26901bd0e2d1SChunyan Liu             } else if (!strcmp(compat, "1.1")) {
26919296b3edSMax Reitz                 new_version = 3;
26929296b3edSMax Reitz             } else {
26931bd0e2d1SChunyan Liu                 fprintf(stderr, "Unknown compatibility level %s.\n", compat);
26949296b3edSMax Reitz                 return -EINVAL;
26959296b3edSMax Reitz             }
26968a17b83cSMax Reitz         } else if (!strcmp(desc->name, BLOCK_OPT_PREALLOC)) {
26979296b3edSMax Reitz             fprintf(stderr, "Cannot change preallocation mode.\n");
26989296b3edSMax Reitz             return -ENOTSUP;
26998a17b83cSMax Reitz         } else if (!strcmp(desc->name, BLOCK_OPT_SIZE)) {
27008a17b83cSMax Reitz             new_size = qemu_opt_get_size(opts, BLOCK_OPT_SIZE, 0);
27018a17b83cSMax Reitz         } else if (!strcmp(desc->name, BLOCK_OPT_BACKING_FILE)) {
27028a17b83cSMax Reitz             backing_file = qemu_opt_get(opts, BLOCK_OPT_BACKING_FILE);
27038a17b83cSMax Reitz         } else if (!strcmp(desc->name, BLOCK_OPT_BACKING_FMT)) {
27048a17b83cSMax Reitz             backing_format = qemu_opt_get(opts, BLOCK_OPT_BACKING_FMT);
27058a17b83cSMax Reitz         } else if (!strcmp(desc->name, BLOCK_OPT_ENCRYPT)) {
27068a17b83cSMax Reitz             encrypt = qemu_opt_get_bool(opts, BLOCK_OPT_ENCRYPT,
27078a17b83cSMax Reitz                                         s->crypt_method);
27081bd0e2d1SChunyan Liu             if (encrypt != !!s->crypt_method) {
27099296b3edSMax Reitz                 fprintf(stderr, "Changing the encryption flag is not "
27109296b3edSMax Reitz                         "supported.\n");
27119296b3edSMax Reitz                 return -ENOTSUP;
27129296b3edSMax Reitz             }
27138a17b83cSMax Reitz         } else if (!strcmp(desc->name, BLOCK_OPT_CLUSTER_SIZE)) {
27148a17b83cSMax Reitz             cluster_size = qemu_opt_get_size(opts, BLOCK_OPT_CLUSTER_SIZE,
27151bd0e2d1SChunyan Liu                                              cluster_size);
27161bd0e2d1SChunyan Liu             if (cluster_size != s->cluster_size) {
27179296b3edSMax Reitz                 fprintf(stderr, "Changing the cluster size is not "
27189296b3edSMax Reitz                         "supported.\n");
27199296b3edSMax Reitz                 return -ENOTSUP;
27209296b3edSMax Reitz             }
27218a17b83cSMax Reitz         } else if (!strcmp(desc->name, BLOCK_OPT_LAZY_REFCOUNTS)) {
27228a17b83cSMax Reitz             lazy_refcounts = qemu_opt_get_bool(opts, BLOCK_OPT_LAZY_REFCOUNTS,
27231bd0e2d1SChunyan Liu                                                lazy_refcounts);
272406d05fa7SMax Reitz         } else if (!strcmp(desc->name, BLOCK_OPT_REFCOUNT_BITS)) {
272506d05fa7SMax Reitz             error_report("Cannot change refcount entry width");
272606d05fa7SMax Reitz             return -ENOTSUP;
27279296b3edSMax Reitz         } else {
27289296b3edSMax Reitz             /* if this assertion fails, this probably means a new option was
27299296b3edSMax Reitz              * added without having it covered here */
27309296b3edSMax Reitz             assert(false);
27319296b3edSMax Reitz         }
27321bd0e2d1SChunyan Liu 
27331bd0e2d1SChunyan Liu         desc++;
27349296b3edSMax Reitz     }
27359296b3edSMax Reitz 
27369296b3edSMax Reitz     if (new_version != old_version) {
27379296b3edSMax Reitz         if (new_version > old_version) {
27389296b3edSMax Reitz             /* Upgrade */
27399296b3edSMax Reitz             s->qcow_version = new_version;
27409296b3edSMax Reitz             ret = qcow2_update_header(bs);
27419296b3edSMax Reitz             if (ret < 0) {
27429296b3edSMax Reitz                 s->qcow_version = old_version;
27439296b3edSMax Reitz                 return ret;
27449296b3edSMax Reitz             }
27459296b3edSMax Reitz         } else {
27464057a2b2SMax Reitz             ret = qcow2_downgrade(bs, new_version, status_cb);
27479296b3edSMax Reitz             if (ret < 0) {
27489296b3edSMax Reitz                 return ret;
27499296b3edSMax Reitz             }
27509296b3edSMax Reitz         }
27519296b3edSMax Reitz     }
27529296b3edSMax Reitz 
27539296b3edSMax Reitz     if (backing_file || backing_format) {
27549296b3edSMax Reitz         ret = qcow2_change_backing_file(bs, backing_file ?: bs->backing_file,
27559296b3edSMax Reitz                                         backing_format ?: bs->backing_format);
27569296b3edSMax Reitz         if (ret < 0) {
27579296b3edSMax Reitz             return ret;
27589296b3edSMax Reitz         }
27599296b3edSMax Reitz     }
27609296b3edSMax Reitz 
27619296b3edSMax Reitz     if (s->use_lazy_refcounts != lazy_refcounts) {
27629296b3edSMax Reitz         if (lazy_refcounts) {
27639296b3edSMax Reitz             if (s->qcow_version < 3) {
27649296b3edSMax Reitz                 fprintf(stderr, "Lazy refcounts only supported with compatibility "
27659296b3edSMax Reitz                         "level 1.1 and above (use compat=1.1 or greater)\n");
27669296b3edSMax Reitz                 return -EINVAL;
27679296b3edSMax Reitz             }
27689296b3edSMax Reitz             s->compatible_features |= QCOW2_COMPAT_LAZY_REFCOUNTS;
27699296b3edSMax Reitz             ret = qcow2_update_header(bs);
27709296b3edSMax Reitz             if (ret < 0) {
27719296b3edSMax Reitz                 s->compatible_features &= ~QCOW2_COMPAT_LAZY_REFCOUNTS;
27729296b3edSMax Reitz                 return ret;
27739296b3edSMax Reitz             }
27749296b3edSMax Reitz             s->use_lazy_refcounts = true;
27759296b3edSMax Reitz         } else {
27769296b3edSMax Reitz             /* make image clean first */
27779296b3edSMax Reitz             ret = qcow2_mark_clean(bs);
27789296b3edSMax Reitz             if (ret < 0) {
27799296b3edSMax Reitz                 return ret;
27809296b3edSMax Reitz             }
27819296b3edSMax Reitz             /* now disallow lazy refcounts */
27829296b3edSMax Reitz             s->compatible_features &= ~QCOW2_COMPAT_LAZY_REFCOUNTS;
27839296b3edSMax Reitz             ret = qcow2_update_header(bs);
27849296b3edSMax Reitz             if (ret < 0) {
27859296b3edSMax Reitz                 s->compatible_features |= QCOW2_COMPAT_LAZY_REFCOUNTS;
27869296b3edSMax Reitz                 return ret;
27879296b3edSMax Reitz             }
27889296b3edSMax Reitz             s->use_lazy_refcounts = false;
27899296b3edSMax Reitz         }
27909296b3edSMax Reitz     }
27919296b3edSMax Reitz 
27929296b3edSMax Reitz     if (new_size) {
27939296b3edSMax Reitz         ret = bdrv_truncate(bs, new_size);
27949296b3edSMax Reitz         if (ret < 0) {
27959296b3edSMax Reitz             return ret;
27969296b3edSMax Reitz         }
27979296b3edSMax Reitz     }
27989296b3edSMax Reitz 
27999296b3edSMax Reitz     return 0;
28009296b3edSMax Reitz }
28019296b3edSMax Reitz 
280285186ebdSMax Reitz /*
280385186ebdSMax Reitz  * If offset or size are negative, respectively, they will not be included in
280485186ebdSMax Reitz  * the BLOCK_IMAGE_CORRUPTED event emitted.
280585186ebdSMax Reitz  * fatal will be ignored for read-only BDS; corruptions found there will always
280685186ebdSMax Reitz  * be considered non-fatal.
280785186ebdSMax Reitz  */
280885186ebdSMax Reitz void qcow2_signal_corruption(BlockDriverState *bs, bool fatal, int64_t offset,
280985186ebdSMax Reitz                              int64_t size, const char *message_format, ...)
281085186ebdSMax Reitz {
281185186ebdSMax Reitz     BDRVQcowState *s = bs->opaque;
281285186ebdSMax Reitz     char *message;
281385186ebdSMax Reitz     va_list ap;
281485186ebdSMax Reitz 
281585186ebdSMax Reitz     fatal = fatal && !bs->read_only;
281685186ebdSMax Reitz 
281785186ebdSMax Reitz     if (s->signaled_corruption &&
281885186ebdSMax Reitz         (!fatal || (s->incompatible_features & QCOW2_INCOMPAT_CORRUPT)))
281985186ebdSMax Reitz     {
282085186ebdSMax Reitz         return;
282185186ebdSMax Reitz     }
282285186ebdSMax Reitz 
282385186ebdSMax Reitz     va_start(ap, message_format);
282485186ebdSMax Reitz     message = g_strdup_vprintf(message_format, ap);
282585186ebdSMax Reitz     va_end(ap);
282685186ebdSMax Reitz 
282785186ebdSMax Reitz     if (fatal) {
282885186ebdSMax Reitz         fprintf(stderr, "qcow2: Marking image as corrupt: %s; further "
282985186ebdSMax Reitz                 "corruption events will be suppressed\n", message);
283085186ebdSMax Reitz     } else {
283185186ebdSMax Reitz         fprintf(stderr, "qcow2: Image is corrupt: %s; further non-fatal "
283285186ebdSMax Reitz                 "corruption events will be suppressed\n", message);
283385186ebdSMax Reitz     }
283485186ebdSMax Reitz 
283585186ebdSMax Reitz     qapi_event_send_block_image_corrupted(bdrv_get_device_name(bs), message,
283685186ebdSMax Reitz                                           offset >= 0, offset, size >= 0, size,
283785186ebdSMax Reitz                                           fatal, &error_abort);
283885186ebdSMax Reitz     g_free(message);
283985186ebdSMax Reitz 
284085186ebdSMax Reitz     if (fatal) {
284185186ebdSMax Reitz         qcow2_mark_corrupt(bs);
284285186ebdSMax Reitz         bs->drv = NULL; /* make BDS unusable */
284385186ebdSMax Reitz     }
284485186ebdSMax Reitz 
284585186ebdSMax Reitz     s->signaled_corruption = true;
284685186ebdSMax Reitz }
284785186ebdSMax Reitz 
28481bd0e2d1SChunyan Liu static QemuOptsList qcow2_create_opts = {
28491bd0e2d1SChunyan Liu     .name = "qcow2-create-opts",
28501bd0e2d1SChunyan Liu     .head = QTAILQ_HEAD_INITIALIZER(qcow2_create_opts.head),
28511bd0e2d1SChunyan Liu     .desc = {
285220d97356SBlue Swirl         {
285320d97356SBlue Swirl             .name = BLOCK_OPT_SIZE,
28541bd0e2d1SChunyan Liu             .type = QEMU_OPT_SIZE,
285520d97356SBlue Swirl             .help = "Virtual disk size"
285620d97356SBlue Swirl         },
285720d97356SBlue Swirl         {
28586744cbabSKevin Wolf             .name = BLOCK_OPT_COMPAT_LEVEL,
28591bd0e2d1SChunyan Liu             .type = QEMU_OPT_STRING,
28606744cbabSKevin Wolf             .help = "Compatibility level (0.10 or 1.1)"
28616744cbabSKevin Wolf         },
28626744cbabSKevin Wolf         {
286320d97356SBlue Swirl             .name = BLOCK_OPT_BACKING_FILE,
28641bd0e2d1SChunyan Liu             .type = QEMU_OPT_STRING,
286520d97356SBlue Swirl             .help = "File name of a base image"
286620d97356SBlue Swirl         },
286720d97356SBlue Swirl         {
286820d97356SBlue Swirl             .name = BLOCK_OPT_BACKING_FMT,
28691bd0e2d1SChunyan Liu             .type = QEMU_OPT_STRING,
287020d97356SBlue Swirl             .help = "Image format of the base image"
287120d97356SBlue Swirl         },
287220d97356SBlue Swirl         {
287320d97356SBlue Swirl             .name = BLOCK_OPT_ENCRYPT,
28741bd0e2d1SChunyan Liu             .type = QEMU_OPT_BOOL,
28751bd0e2d1SChunyan Liu             .help = "Encrypt the image",
28761bd0e2d1SChunyan Liu             .def_value_str = "off"
287720d97356SBlue Swirl         },
287820d97356SBlue Swirl         {
287920d97356SBlue Swirl             .name = BLOCK_OPT_CLUSTER_SIZE,
28801bd0e2d1SChunyan Liu             .type = QEMU_OPT_SIZE,
288199cce9faSKevin Wolf             .help = "qcow2 cluster size",
28821bd0e2d1SChunyan Liu             .def_value_str = stringify(DEFAULT_CLUSTER_SIZE)
288320d97356SBlue Swirl         },
288420d97356SBlue Swirl         {
288520d97356SBlue Swirl             .name = BLOCK_OPT_PREALLOC,
28861bd0e2d1SChunyan Liu             .type = QEMU_OPT_STRING,
28870e4271b7SHu Tao             .help = "Preallocation mode (allowed values: off, metadata, "
28880e4271b7SHu Tao                     "falloc, full)"
288920d97356SBlue Swirl         },
2890bfe8043eSStefan Hajnoczi         {
2891bfe8043eSStefan Hajnoczi             .name = BLOCK_OPT_LAZY_REFCOUNTS,
28921bd0e2d1SChunyan Liu             .type = QEMU_OPT_BOOL,
2893bfe8043eSStefan Hajnoczi             .help = "Postpone refcount updates",
28941bd0e2d1SChunyan Liu             .def_value_str = "off"
2895bfe8043eSStefan Hajnoczi         },
289606d05fa7SMax Reitz         {
289706d05fa7SMax Reitz             .name = BLOCK_OPT_REFCOUNT_BITS,
289806d05fa7SMax Reitz             .type = QEMU_OPT_NUMBER,
289906d05fa7SMax Reitz             .help = "Width of a reference count entry in bits",
290006d05fa7SMax Reitz             .def_value_str = "16"
290106d05fa7SMax Reitz         },
29021bd0e2d1SChunyan Liu         { /* end of list */ }
29031bd0e2d1SChunyan Liu     }
290420d97356SBlue Swirl };
290520d97356SBlue Swirl 
29065f535a94SMax Reitz BlockDriver bdrv_qcow2 = {
290720d97356SBlue Swirl     .format_name        = "qcow2",
290820d97356SBlue Swirl     .instance_size      = sizeof(BDRVQcowState),
29097c80ab3fSJes Sorensen     .bdrv_probe         = qcow2_probe,
29107c80ab3fSJes Sorensen     .bdrv_open          = qcow2_open,
29117c80ab3fSJes Sorensen     .bdrv_close         = qcow2_close,
291221d82ac9SJeff Cody     .bdrv_reopen_prepare  = qcow2_reopen_prepare,
2913c282e1fdSChunyan Liu     .bdrv_create        = qcow2_create,
29143ac21627SPeter Lieven     .bdrv_has_zero_init = bdrv_has_zero_init_1,
2915b6b8a333SPaolo Bonzini     .bdrv_co_get_block_status = qcow2_co_get_block_status,
29167c80ab3fSJes Sorensen     .bdrv_set_key       = qcow2_set_key,
291720d97356SBlue Swirl 
291868d100e9SKevin Wolf     .bdrv_co_readv          = qcow2_co_readv,
291968d100e9SKevin Wolf     .bdrv_co_writev         = qcow2_co_writev,
2920eb489bb1SKevin Wolf     .bdrv_co_flush_to_os    = qcow2_co_flush_to_os,
2921419b19d9SStefan Hajnoczi 
2922621f0589SKevin Wolf     .bdrv_co_write_zeroes   = qcow2_co_write_zeroes,
29236db39ae2SPaolo Bonzini     .bdrv_co_discard        = qcow2_co_discard,
2924419b19d9SStefan Hajnoczi     .bdrv_truncate          = qcow2_truncate,
29257c80ab3fSJes Sorensen     .bdrv_write_compressed  = qcow2_write_compressed,
2926491d27e2SMax Reitz     .bdrv_make_empty        = qcow2_make_empty,
292720d97356SBlue Swirl 
292820d97356SBlue Swirl     .bdrv_snapshot_create   = qcow2_snapshot_create,
292920d97356SBlue Swirl     .bdrv_snapshot_goto     = qcow2_snapshot_goto,
293020d97356SBlue Swirl     .bdrv_snapshot_delete   = qcow2_snapshot_delete,
293120d97356SBlue Swirl     .bdrv_snapshot_list     = qcow2_snapshot_list,
293251ef6727Sedison     .bdrv_snapshot_load_tmp = qcow2_snapshot_load_tmp,
29337c80ab3fSJes Sorensen     .bdrv_get_info          = qcow2_get_info,
293437764dfbSMax Reitz     .bdrv_get_specific_info = qcow2_get_specific_info,
293520d97356SBlue Swirl 
29367c80ab3fSJes Sorensen     .bdrv_save_vmstate    = qcow2_save_vmstate,
29377c80ab3fSJes Sorensen     .bdrv_load_vmstate    = qcow2_load_vmstate,
293820d97356SBlue Swirl 
29398ee79e70SKevin Wolf     .supports_backing           = true,
294020d97356SBlue Swirl     .bdrv_change_backing_file   = qcow2_change_backing_file,
294120d97356SBlue Swirl 
2942d34682cdSKevin Wolf     .bdrv_refresh_limits        = qcow2_refresh_limits,
294306d9260fSAnthony Liguori     .bdrv_invalidate_cache      = qcow2_invalidate_cache,
294406d9260fSAnthony Liguori 
29451bd0e2d1SChunyan Liu     .create_opts         = &qcow2_create_opts,
29467c80ab3fSJes Sorensen     .bdrv_check          = qcow2_check,
2947c282e1fdSChunyan Liu     .bdrv_amend_options  = qcow2_amend_options,
294820d97356SBlue Swirl };
294920d97356SBlue Swirl 
29505efa9d5aSAnthony Liguori static void bdrv_qcow2_init(void)
29515efa9d5aSAnthony Liguori {
29525efa9d5aSAnthony Liguori     bdrv_register(&bdrv_qcow2);
29535efa9d5aSAnthony Liguori }
29545efa9d5aSAnthony Liguori 
29555efa9d5aSAnthony Liguori block_init(bdrv_qcow2_init);
2956