Fix 32-bit overflow in parallels image supportF-12masterqemu-0.11.0-12.fc12qemu-0.11.0-12.fc13
authorDavid Woodhouse <dwmw2@infradead.org>
Sat, 7 Nov 2009 14:10:01 +0000 (7 14:10 +0000)
committerMark McLoughlin <markmc@redhat.com>
Fri, 20 Nov 2009 18:21:20 +0000 (20 18:21 +0000)
(cherry picked from commit c34d2451ed32651e14e309f94009be07d231ee96)

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
Signed-off-by: Anthony Liguori <aliguori@us.ibm.com>
Signed-off-by: Mark McLoughlin <markmc@redhat.com>
Fedora-patch: qemu-parallels-image-format-overflow.patch

block/parallels.c

index 0b64a5c..63b6738 100644 (file)
@@ -119,7 +119,8 @@ fail:
 static inline int seek_to_sector(BlockDriverState *bs, int64_t sector_num)
 {
     BDRVParallelsState *s = bs->opaque;
-    uint32_t index, offset, position;
+    uint32_t index, offset;
+    uint64_t position;
 
     index = sector_num / s->tracks;
     offset = sector_num % s->tracks;
@@ -128,7 +129,7 @@ static inline int seek_to_sector(BlockDriverState *bs, int64_t sector_num)
     if ((index > s->catalog_size) || (s->catalog_bitmap[index] == 0))
        return -1;
 
-    position = (s->catalog_bitmap[index] + offset) * 512;
+    position = (uint64_t)(s->catalog_bitmap[index] + offset) * 512;
 
 //    fprintf(stderr, "sector: %llx index=%x offset=%x pointer=%x position=%x\n",
 //     sector_num, index, offset, s->catalog_bitmap[index], position);