From: Kevin Wolf Date: Tue, 11 Feb 2020 09:48:59 +0000 (+0100) Subject: qcow2: Fix qcow2_alloc_cluster_abort() for external data file X-Git-Tag: v4.2.1~111 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=ab7f6eaa5bc9f5cd95274089ab869680dddc77f8;p=thirdparty%2Fqemu.git qcow2: Fix qcow2_alloc_cluster_abort() for external data file For external data file, cluster allocations return an offset in the data file and are not refcounted. In this case, there is nothing to do for qcow2_alloc_cluster_abort(). Freeing the same offset in the qcow2 file is wrong and causes crashes in the better case or image corruption in the worse case. Signed-off-by: Kevin Wolf Message-Id: <20200211094900.17315-3-kwolf@redhat.com> Signed-off-by: Kevin Wolf (cherry picked from commit c3b6658c1a5a3fb24d6c27b2594cf86146f75b22) Signed-off-by: Michael Roth --- diff --git a/block/qcow2-cluster.c b/block/qcow2-cluster.c index 8982b7b762e..dc3c2702261 100644 --- a/block/qcow2-cluster.c +++ b/block/qcow2-cluster.c @@ -1015,8 +1015,11 @@ err: void qcow2_alloc_cluster_abort(BlockDriverState *bs, QCowL2Meta *m) { BDRVQcow2State *s = bs->opaque; - qcow2_free_clusters(bs, m->alloc_offset, m->nb_clusters << s->cluster_bits, - QCOW2_DISCARD_NEVER); + if (!has_data_file(bs)) { + qcow2_free_clusters(bs, m->alloc_offset, + m->nb_clusters << s->cluster_bits, + QCOW2_DISCARD_NEVER); + } } /*