On Mon, Sep 21, 2026 at 04:28:11PM +0200, Niklas Cassel wrote:
> A zone append cannot cross a zone boundary, so a request larger than a
> zone can never be carried out.
> 
> Nothing rejects one. The block layer does not look at the length at all,
> and raw_co_zone_append() writes qiov->size bytes at the write pointer
> once it has validated the offset, so the write runs past the end of the
> zone: on a disk with 8 MiB zones, an append of 8 MiB plus one block
> fills the zone and advances the write pointer of the zone after it.
> 
> virtio-blk does compare the length, but against
> BlockLimits.max_append_sectors, which is how much the backend takes in
> one command and not how large a zone is. For a Linux block device that
> value is never larger than a zone, so virtio-blk is protected by what
> the backend happens to report rather than by the check it makes.
> 
> Check the length in bdrv_co_zone_append(), next to the check that an
> append is a multiple of the sector size. Both are conditions of the
> operation rather than of a medium, so the block layer is where they hold
> for every caller and where no driver has to repeat them.
> 
> The exact bound is tighter: a request also has to fit in the part of the
> zone that is still writable, which depends on the write pointer and so
> stays with the drivers.
> 
> Signed-off-by: Niklas Cassel <[email protected]>
> ---
>  block/io.c | 12 ++++++++++++
>  1 file changed, 12 insertions(+)

Reviewed-by: Stefan Hajnoczi <[email protected]>

Attachment: signature.asc
Description: PGP signature

Reply via email to