bdrv_getlength could fail, check the return value before using it. Signed-off-by: Fam Zheng <f...@redhat.com> Reviewed-by: Benoit Canet <ben...@irqsave.net> --- block.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/block.c b/block.c index d240f1e..e32da75 100644 --- a/block.c +++ b/block.c @@ -5097,7 +5097,12 @@ BdrvDirtyBitmap *bdrv_create_dirty_bitmap(BlockDriverState *bs, } granularity >>= BDRV_SECTOR_BITS; assert(granularity); - bitmap_size = (bdrv_getlength(bs) >> BDRV_SECTOR_BITS); + bitmap_size = bdrv_getlength(bs); + if (bitmap_size < 0) { + error_setg(errp, "could not get length of device"); + return NULL; + } + bitmap_size >>= BDRV_SECTOR_BITS; bitmap = g_malloc0(sizeof(BdrvDirtyBitmap)); bitmap->bitmap = hbitmap_alloc(bitmap_size, ffs(granularity) - 1); if (name) { -- 1.9.0