dma-helpers: Fix too long qiov
If the size of the scatter/gather list isn't a multiple of 512, the number of sectors for the block layer request is rounded down, resulting in a qiov that doesn't match the request length. Truncate the qiov to the new length of the request. This fixes the IDE qtest case /x86_64/ide/bmdma/short_prdt. Signed-off-by: Kevin Wolf <kwolf@redhat.com> Reviewed-by: Eric Blake <eblake@redhat.com>
This commit is contained in:
		
							parent
							
								
									80504dcaa1
								
							
						
					
					
						commit
						58f423fbd5
					
				| 
						 | 
				
			
			@ -170,6 +170,10 @@ static void dma_bdrv_cb(void *opaque, int ret)
 | 
			
		|||
        return;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (dbs->iov.size & ~BDRV_SECTOR_MASK) {
 | 
			
		||||
        qemu_iovec_discard_back(&dbs->iov, dbs->iov.size & ~BDRV_SECTOR_MASK);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    dbs->acb = dbs->io_func(dbs->bs, dbs->sector_num, &dbs->iov,
 | 
			
		||||
                            dbs->iov.size / 512, dma_bdrv_cb, dbs);
 | 
			
		||||
    assert(dbs->acb);
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
| 
						 | 
				
			
			@ -329,6 +329,7 @@ size_t qemu_iovec_memset(QEMUIOVector *qiov, size_t offset,
 | 
			
		|||
                         int fillc, size_t bytes);
 | 
			
		||||
ssize_t qemu_iovec_compare(QEMUIOVector *a, QEMUIOVector *b);
 | 
			
		||||
void qemu_iovec_clone(QEMUIOVector *dest, const QEMUIOVector *src, void *buf);
 | 
			
		||||
void qemu_iovec_discard_back(QEMUIOVector *qiov, size_t bytes);
 | 
			
		||||
 | 
			
		||||
bool buffer_is_zero(const void *buf, size_t len);
 | 
			
		||||
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
							
								
								
									
										13
									
								
								util/iov.c
								
								
								
								
							
							
						
						
									
										13
									
								
								util/iov.c
								
								
								
								
							| 
						 | 
				
			
			@ -550,3 +550,16 @@ size_t iov_discard_back(struct iovec *iov, unsigned int *iov_cnt,
 | 
			
		|||
 | 
			
		||||
    return total;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
void qemu_iovec_discard_back(QEMUIOVector *qiov, size_t bytes)
 | 
			
		||||
{
 | 
			
		||||
    size_t total;
 | 
			
		||||
    unsigned int niov = qiov->niov;
 | 
			
		||||
 | 
			
		||||
    assert(qiov->size >= bytes);
 | 
			
		||||
    total = iov_discard_back(qiov->iov, &niov, bytes);
 | 
			
		||||
    assert(total == bytes);
 | 
			
		||||
 | 
			
		||||
    qiov->niov = niov;
 | 
			
		||||
    qiov->size -= bytes;
 | 
			
		||||
}
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
		Reference in New Issue