ppc/pnv: check size before data buffer access
[qemu/ar7.git] / block / qcow2-cache.c
blobd9dafa31e53ac8c8285707ab18fa528828cb7f20
1 /*
2 * L2/refcount table cache for the QCOW2 format
4 * Copyright (c) 2010 Kevin Wolf <kwolf@redhat.com>
6 * Permission is hereby granted, free of charge, to any person obtaining a copy
7 * of this software and associated documentation files (the "Software"), to deal
8 * in the Software without restriction, including without limitation the rights
9 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
10 * copies of the Software, and to permit persons to whom the Software is
11 * furnished to do so, subject to the following conditions:
13 * The above copyright notice and this permission notice shall be included in
14 * all copies or substantial portions of the Software.
16 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
17 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
18 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
19 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
20 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
21 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
22 * THE SOFTWARE.
25 #include "qemu/osdep.h"
26 #include "block/block_int.h"
27 #include "qemu-common.h"
28 #include "qcow2.h"
29 #include "trace.h"
31 typedef struct Qcow2CachedTable {
32 int64_t offset;
33 uint64_t lru_counter;
34 int ref;
35 bool dirty;
36 } Qcow2CachedTable;
38 struct Qcow2Cache {
39 Qcow2CachedTable *entries;
40 struct Qcow2Cache *depends;
41 int size;
42 int table_size;
43 bool depends_on_flush;
44 void *table_array;
45 uint64_t lru_counter;
46 uint64_t cache_clean_lru_counter;
49 static inline void *qcow2_cache_get_table_addr(Qcow2Cache *c, int table)
51 return (uint8_t *) c->table_array + (size_t) table * c->table_size;
54 static inline int qcow2_cache_get_table_idx(Qcow2Cache *c, void *table)
56 ptrdiff_t table_offset = (uint8_t *) table - (uint8_t *) c->table_array;
57 int idx = table_offset / c->table_size;
58 assert(idx >= 0 && idx < c->size && table_offset % c->table_size == 0);
59 return idx;
62 static inline const char *qcow2_cache_get_name(BDRVQcow2State *s, Qcow2Cache *c)
64 if (c == s->refcount_block_cache) {
65 return "refcount block";
66 } else if (c == s->l2_table_cache) {
67 return "L2 table";
68 } else {
69 /* Do not abort, because this is not critical */
70 return "unknown";
74 static void qcow2_cache_table_release(Qcow2Cache *c, int i, int num_tables)
76 /* Using MADV_DONTNEED to discard memory is a Linux-specific feature */
77 #ifdef CONFIG_LINUX
78 void *t = qcow2_cache_get_table_addr(c, i);
79 int align = getpagesize();
80 size_t mem_size = (size_t) c->table_size * num_tables;
81 size_t offset = QEMU_ALIGN_UP((uintptr_t) t, align) - (uintptr_t) t;
82 size_t length = QEMU_ALIGN_DOWN(mem_size - offset, align);
83 if (mem_size > offset && length > 0) {
84 madvise((uint8_t *) t + offset, length, MADV_DONTNEED);
86 #endif
89 static inline bool can_clean_entry(Qcow2Cache *c, int i)
91 Qcow2CachedTable *t = &c->entries[i];
92 return t->ref == 0 && !t->dirty && t->offset != 0 &&
93 t->lru_counter <= c->cache_clean_lru_counter;
96 void qcow2_cache_clean_unused(Qcow2Cache *c)
98 int i = 0;
99 while (i < c->size) {
100 int to_clean = 0;
102 /* Skip the entries that we don't need to clean */
103 while (i < c->size && !can_clean_entry(c, i)) {
104 i++;
107 /* And count how many we can clean in a row */
108 while (i < c->size && can_clean_entry(c, i)) {
109 c->entries[i].offset = 0;
110 c->entries[i].lru_counter = 0;
111 i++;
112 to_clean++;
115 if (to_clean > 0) {
116 qcow2_cache_table_release(c, i - to_clean, to_clean);
120 c->cache_clean_lru_counter = c->lru_counter;
123 Qcow2Cache *qcow2_cache_create(BlockDriverState *bs, int num_tables,
124 unsigned table_size)
126 BDRVQcow2State *s = bs->opaque;
127 Qcow2Cache *c;
129 assert(num_tables > 0);
130 assert(is_power_of_2(table_size));
131 assert(table_size >= (1 << MIN_CLUSTER_BITS));
132 assert(table_size <= s->cluster_size);
134 c = g_new0(Qcow2Cache, 1);
135 c->size = num_tables;
136 c->table_size = table_size;
137 c->entries = g_try_new0(Qcow2CachedTable, num_tables);
138 c->table_array = qemu_try_blockalign(bs->file->bs,
139 (size_t) num_tables * c->table_size);
141 if (!c->entries || !c->table_array) {
142 qemu_vfree(c->table_array);
143 g_free(c->entries);
144 g_free(c);
145 c = NULL;
148 return c;
151 int qcow2_cache_destroy(Qcow2Cache *c)
153 int i;
155 for (i = 0; i < c->size; i++) {
156 assert(c->entries[i].ref == 0);
159 qemu_vfree(c->table_array);
160 g_free(c->entries);
161 g_free(c);
163 return 0;
166 static int qcow2_cache_flush_dependency(BlockDriverState *bs, Qcow2Cache *c)
168 int ret;
170 ret = qcow2_cache_flush(bs, c->depends);
171 if (ret < 0) {
172 return ret;
175 c->depends = NULL;
176 c->depends_on_flush = false;
178 return 0;
181 static int qcow2_cache_entry_flush(BlockDriverState *bs, Qcow2Cache *c, int i)
183 BDRVQcow2State *s = bs->opaque;
184 int ret = 0;
186 if (!c->entries[i].dirty || !c->entries[i].offset) {
187 return 0;
190 trace_qcow2_cache_entry_flush(qemu_coroutine_self(),
191 c == s->l2_table_cache, i);
193 if (c->depends) {
194 ret = qcow2_cache_flush_dependency(bs, c);
195 } else if (c->depends_on_flush) {
196 ret = bdrv_flush(bs->file->bs);
197 if (ret >= 0) {
198 c->depends_on_flush = false;
202 if (ret < 0) {
203 return ret;
206 if (c == s->refcount_block_cache) {
207 ret = qcow2_pre_write_overlap_check(bs, QCOW2_OL_REFCOUNT_BLOCK,
208 c->entries[i].offset, c->table_size);
209 } else if (c == s->l2_table_cache) {
210 ret = qcow2_pre_write_overlap_check(bs, QCOW2_OL_ACTIVE_L2,
211 c->entries[i].offset, c->table_size);
212 } else {
213 ret = qcow2_pre_write_overlap_check(bs, 0,
214 c->entries[i].offset, c->table_size);
217 if (ret < 0) {
218 return ret;
221 if (c == s->refcount_block_cache) {
222 BLKDBG_EVENT(bs->file, BLKDBG_REFBLOCK_UPDATE_PART);
223 } else if (c == s->l2_table_cache) {
224 BLKDBG_EVENT(bs->file, BLKDBG_L2_UPDATE);
227 ret = bdrv_pwrite(bs->file, c->entries[i].offset,
228 qcow2_cache_get_table_addr(c, i), c->table_size);
229 if (ret < 0) {
230 return ret;
233 c->entries[i].dirty = false;
235 return 0;
238 int qcow2_cache_write(BlockDriverState *bs, Qcow2Cache *c)
240 BDRVQcow2State *s = bs->opaque;
241 int result = 0;
242 int ret;
243 int i;
245 trace_qcow2_cache_flush(qemu_coroutine_self(), c == s->l2_table_cache);
247 for (i = 0; i < c->size; i++) {
248 ret = qcow2_cache_entry_flush(bs, c, i);
249 if (ret < 0 && result != -ENOSPC) {
250 result = ret;
254 return result;
257 int qcow2_cache_flush(BlockDriverState *bs, Qcow2Cache *c)
259 int result = qcow2_cache_write(bs, c);
261 if (result == 0) {
262 int ret = bdrv_flush(bs->file->bs);
263 if (ret < 0) {
264 result = ret;
268 return result;
271 int qcow2_cache_set_dependency(BlockDriverState *bs, Qcow2Cache *c,
272 Qcow2Cache *dependency)
274 int ret;
276 if (dependency->depends) {
277 ret = qcow2_cache_flush_dependency(bs, dependency);
278 if (ret < 0) {
279 return ret;
283 if (c->depends && (c->depends != dependency)) {
284 ret = qcow2_cache_flush_dependency(bs, c);
285 if (ret < 0) {
286 return ret;
290 c->depends = dependency;
291 return 0;
294 void qcow2_cache_depends_on_flush(Qcow2Cache *c)
296 c->depends_on_flush = true;
299 int qcow2_cache_empty(BlockDriverState *bs, Qcow2Cache *c)
301 int ret, i;
303 ret = qcow2_cache_flush(bs, c);
304 if (ret < 0) {
305 return ret;
308 for (i = 0; i < c->size; i++) {
309 assert(c->entries[i].ref == 0);
310 c->entries[i].offset = 0;
311 c->entries[i].lru_counter = 0;
314 qcow2_cache_table_release(c, 0, c->size);
316 c->lru_counter = 0;
318 return 0;
321 static int qcow2_cache_do_get(BlockDriverState *bs, Qcow2Cache *c,
322 uint64_t offset, void **table, bool read_from_disk)
324 BDRVQcow2State *s = bs->opaque;
325 int i;
326 int ret;
327 int lookup_index;
328 uint64_t min_lru_counter = UINT64_MAX;
329 int min_lru_index = -1;
331 assert(offset != 0);
333 trace_qcow2_cache_get(qemu_coroutine_self(), c == s->l2_table_cache,
334 offset, read_from_disk);
336 if (!QEMU_IS_ALIGNED(offset, c->table_size)) {
337 qcow2_signal_corruption(bs, true, -1, -1, "Cannot get entry from %s "
338 "cache: Offset %#" PRIx64 " is unaligned",
339 qcow2_cache_get_name(s, c), offset);
340 return -EIO;
343 /* Check if the table is already cached */
344 i = lookup_index = (offset / c->table_size * 4) % c->size;
345 do {
346 const Qcow2CachedTable *t = &c->entries[i];
347 if (t->offset == offset) {
348 goto found;
350 if (t->ref == 0 && t->lru_counter < min_lru_counter) {
351 min_lru_counter = t->lru_counter;
352 min_lru_index = i;
354 if (++i == c->size) {
355 i = 0;
357 } while (i != lookup_index);
359 if (min_lru_index == -1) {
360 /* This can't happen in current synchronous code, but leave the check
361 * here as a reminder for whoever starts using AIO with the cache */
362 abort();
365 /* Cache miss: write a table back and replace it */
366 i = min_lru_index;
367 trace_qcow2_cache_get_replace_entry(qemu_coroutine_self(),
368 c == s->l2_table_cache, i);
370 ret = qcow2_cache_entry_flush(bs, c, i);
371 if (ret < 0) {
372 return ret;
375 trace_qcow2_cache_get_read(qemu_coroutine_self(),
376 c == s->l2_table_cache, i);
377 c->entries[i].offset = 0;
378 if (read_from_disk) {
379 if (c == s->l2_table_cache) {
380 BLKDBG_EVENT(bs->file, BLKDBG_L2_LOAD);
383 ret = bdrv_pread(bs->file, offset,
384 qcow2_cache_get_table_addr(c, i),
385 c->table_size);
386 if (ret < 0) {
387 return ret;
391 c->entries[i].offset = offset;
393 /* And return the right table */
394 found:
395 c->entries[i].ref++;
396 *table = qcow2_cache_get_table_addr(c, i);
398 trace_qcow2_cache_get_done(qemu_coroutine_self(),
399 c == s->l2_table_cache, i);
401 return 0;
404 int qcow2_cache_get(BlockDriverState *bs, Qcow2Cache *c, uint64_t offset,
405 void **table)
407 return qcow2_cache_do_get(bs, c, offset, table, true);
410 int qcow2_cache_get_empty(BlockDriverState *bs, Qcow2Cache *c, uint64_t offset,
411 void **table)
413 return qcow2_cache_do_get(bs, c, offset, table, false);
416 void qcow2_cache_put(Qcow2Cache *c, void **table)
418 int i = qcow2_cache_get_table_idx(c, *table);
420 c->entries[i].ref--;
421 *table = NULL;
423 if (c->entries[i].ref == 0) {
424 c->entries[i].lru_counter = ++c->lru_counter;
427 assert(c->entries[i].ref >= 0);
430 void qcow2_cache_entry_mark_dirty(Qcow2Cache *c, void *table)
432 int i = qcow2_cache_get_table_idx(c, table);
433 assert(c->entries[i].offset != 0);
434 c->entries[i].dirty = true;
437 void *qcow2_cache_is_table_offset(Qcow2Cache *c, uint64_t offset)
439 int i;
441 for (i = 0; i < c->size; i++) {
442 if (c->entries[i].offset == offset) {
443 return qcow2_cache_get_table_addr(c, i);
446 return NULL;
449 void qcow2_cache_discard(Qcow2Cache *c, void *table)
451 int i = qcow2_cache_get_table_idx(c, table);
453 assert(c->entries[i].ref == 0);
455 c->entries[i].offset = 0;
456 c->entries[i].lru_counter = 0;
457 c->entries[i].dirty = false;
459 qcow2_cache_table_release(c, i, 1);