Keep track of the snapshot table in the metadata list to protect it against accidental modifications.
Signed-off-by: Max Reitz <mre...@redhat.com> Reviewed-by: Eric Blake <ebl...@redhat.com> --- block/qcow2-snapshot.c | 10 ++++++++++ block/qcow2.c | 6 ++++++ 2 files changed, 16 insertions(+) diff --git a/block/qcow2-snapshot.c b/block/qcow2-snapshot.c index 7add805f..6d1ae00 100644 --- a/block/qcow2-snapshot.c +++ b/block/qcow2-snapshot.c @@ -263,8 +263,18 @@ static int qcow2_write_snapshots(BlockDriverState *bs) /* free the old snapshot table */ qcow2_free_clusters(bs, s->snapshots_offset, s->snapshots_size, QCOW2_DISCARD_SNAPSHOT); + + qcow2_metadata_list_remove(bs, s->snapshots_offset, + size_to_clusters(s, s->snapshots_size), + QCOW2_OL_SNAPSHOT_TABLE); + s->snapshots_offset = snapshots_offset; s->snapshots_size = snapshots_size; + + qcow2_metadata_list_enter(bs, s->snapshots_offset, + size_to_clusters(s, s->snapshots_size), + QCOW2_OL_SNAPSHOT_TABLE); + return 0; fail: diff --git a/block/qcow2.c b/block/qcow2.c index b7d0f33..0e7b646 100644 --- a/block/qcow2.c +++ b/block/qcow2.c @@ -811,6 +811,12 @@ static int qcow2_open(BlockDriverState *bs, QDict *options, int flags, error_setg(errp, "Invalid snapshot table offset"); goto fail; } + if (header.nb_snapshots) { + qcow2_metadata_list_enter(bs, header.snapshots_offset, + size_to_clusters(s, header.nb_snapshots * + sizeof(QCowSnapshotHeader)), + QCOW2_OL_SNAPSHOT_TABLE); + } /* read the level 1 table */ if (header.l1_size > QCOW_MAX_L1_SIZE / sizeof(uint64_t)) { -- 2.4.6