Public bug reported: 'qemu-io -c write' and 'qemu-io -c aio_write' crashes on a qcow2 image with a fuzzed refcount table.
Sequence: 1. Unpack the attached archive, make a copy of test.img 2. Put copy.img and backing_img.file in the same directory 3. Execute qemu-io copy.img -c write 279552 322560 or qemu-io copy.img -c aio_write 836608 166400 Result: qemu-io was killed by SIGIOT with the reason: qemu-io: block/qcow2-cluster.c:1291: qcow2_alloc_cluster_offset: Assertion `*host_offset != 0' failed. qemu.git HEAD 69f87f713069f1f ** Affects: qemu Importance: Undecided Status: New ** Attachment added: "traces.n.images.tar.gz" https://bugs.launchpad.net/bugs/1353456/+attachment/4171103/+files/traces.n.images.tar.gz -- You received this bug notification because you are a member of qemu- devel-ml, which is subscribed to QEMU. https://bugs.launchpad.net/bugs/1353456 Title: qemu-io: Failure on a qcow2 image with the fuzzed refcount table Status in QEMU: New Bug description: 'qemu-io -c write' and 'qemu-io -c aio_write' crashes on a qcow2 image with a fuzzed refcount table. Sequence: 1. Unpack the attached archive, make a copy of test.img 2. Put copy.img and backing_img.file in the same directory 3. Execute qemu-io copy.img -c write 279552 322560 or qemu-io copy.img -c aio_write 836608 166400 Result: qemu-io was killed by SIGIOT with the reason: qemu-io: block/qcow2-cluster.c:1291: qcow2_alloc_cluster_offset: Assertion `*host_offset != 0' failed. qemu.git HEAD 69f87f713069f1f To manage notifications about this bug go to: https://bugs.launchpad.net/qemu/+bug/1353456/+subscriptions