io.c 95.3 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
/*
 * Block layer I/O functions
 *
 * Copyright (c) 2003 Fabrice Bellard
 *
 * Permission is hereby granted, free of charge, to any person obtaining a copy
 * of this software and associated documentation files (the "Software"), to deal
 * in the Software without restriction, including without limitation the rights
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
 * copies of the Software, and to permit persons to whom the Software is
 * furnished to do so, subject to the following conditions:
 *
 * The above copyright notice and this permission notice shall be included in
 * all copies or substantial portions of the Software.
 *
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
 * THE SOFTWARE.
 */

P
Peter Maydell 已提交
25
#include "qemu/osdep.h"
26
#include "trace.h"
27
#include "sysemu/block-backend.h"
28
#include "block/aio-wait.h"
29
#include "block/blockjob.h"
30
#include "block/blockjob_int.h"
31
#include "block/block_int.h"
32
#include "qemu/cutils.h"
33
#include "qapi/error.h"
34
#include "qemu/error-report.h"
35 36 37

#define NOT_DONE 0x7fffffff /* used while emulated sync operation in progress */

E
Eric Blake 已提交
38 39 40
/* Maximum bounce buffer for copy-on-read and write zeroes, in bytes */
#define MAX_BOUNCE_BUFFER (32768 << BDRV_SECTOR_BITS)

41
static void bdrv_parent_cb_resize(BlockDriverState *bs);
E
Eric Blake 已提交
42
static int coroutine_fn bdrv_co_do_pwrite_zeroes(BlockDriverState *bs,
43
    int64_t offset, int bytes, BdrvRequestFlags flags);
44

45 46
void bdrv_parent_drained_begin(BlockDriverState *bs, BdrvChild *ignore,
                               bool ignore_bds_parents)
47
{
48
    BdrvChild *c, *next;
49

50
    QLIST_FOREACH_SAFE(c, &bs->parents, next_parent, next) {
51
        if (c == ignore || (ignore_bds_parents && c->role->parent_is_bds)) {
52 53
            continue;
        }
54
        bdrv_parent_drained_begin_single(c, false);
55 56
    }
}
57

58 59
void bdrv_parent_drained_end(BlockDriverState *bs, BdrvChild *ignore,
                             bool ignore_bds_parents)
60
{
61
    BdrvChild *c, *next;
62

63
    QLIST_FOREACH_SAFE(c, &bs->parents, next_parent, next) {
64
        if (c == ignore || (ignore_bds_parents && c->role->parent_is_bds)) {
65 66
            continue;
        }
67 68 69
        if (c->role->drained_end) {
            c->role->drained_end(c);
        }
70
    }
71 72
}

73 74 75 76 77 78 79 80
static bool bdrv_parent_drained_poll_single(BdrvChild *c)
{
    if (c->role->drained_poll) {
        return c->role->drained_poll(c);
    }
    return false;
}

81 82
static bool bdrv_parent_drained_poll(BlockDriverState *bs, BdrvChild *ignore,
                                     bool ignore_bds_parents)
83 84 85 86 87
{
    BdrvChild *c, *next;
    bool busy = false;

    QLIST_FOREACH_SAFE(c, &bs->parents, next_parent, next) {
88
        if (c == ignore || (ignore_bds_parents && c->role->parent_is_bds)) {
89 90
            continue;
        }
91
        busy |= bdrv_parent_drained_poll_single(c);
92 93 94 95 96
    }

    return busy;
}

97 98 99 100 101 102 103 104 105 106
void bdrv_parent_drained_begin_single(BdrvChild *c, bool poll)
{
    if (c->role->drained_begin) {
        c->role->drained_begin(c);
    }
    if (poll) {
        BDRV_POLL_WHILE(c->bs, bdrv_parent_drained_poll_single(c));
    }
}

107 108 109 110 111 112 113 114 115 116 117
static void bdrv_merge_limits(BlockLimits *dst, const BlockLimits *src)
{
    dst->opt_transfer = MAX(dst->opt_transfer, src->opt_transfer);
    dst->max_transfer = MIN_NON_ZERO(dst->max_transfer, src->max_transfer);
    dst->opt_mem_alignment = MAX(dst->opt_mem_alignment,
                                 src->opt_mem_alignment);
    dst->min_mem_alignment = MAX(dst->min_mem_alignment,
                                 src->min_mem_alignment);
    dst->max_iov = MIN_NON_ZERO(dst->max_iov, src->max_iov);
}

118 119 120 121 122 123 124 125 126 127 128
void bdrv_refresh_limits(BlockDriverState *bs, Error **errp)
{
    BlockDriver *drv = bs->drv;
    Error *local_err = NULL;

    memset(&bs->bl, 0, sizeof(bs->bl));

    if (!drv) {
        return;
    }

129
    /* Default alignment based on whether driver has byte interface */
130 131
    bs->bl.request_alignment = (drv->bdrv_co_preadv ||
                                drv->bdrv_aio_preadv) ? 1 : 512;
132

133 134
    /* Take some limits from the children as a default */
    if (bs->file) {
K
Kevin Wolf 已提交
135
        bdrv_refresh_limits(bs->file->bs, &local_err);
136 137 138 139
        if (local_err) {
            error_propagate(errp, local_err);
            return;
        }
140
        bdrv_merge_limits(&bs->bl, &bs->file->bs->bl);
141
    } else {
142
        bs->bl.min_mem_alignment = 512;
143
        bs->bl.opt_mem_alignment = getpagesize();
144 145 146

        /* Safe default since most protocols use readv()/writev()/etc */
        bs->bl.max_iov = IOV_MAX;
147 148
    }

149 150
    if (bs->backing) {
        bdrv_refresh_limits(bs->backing->bs, &local_err);
151 152 153 154
        if (local_err) {
            error_propagate(errp, local_err);
            return;
        }
155
        bdrv_merge_limits(&bs->bl, &bs->backing->bs->bl);
156 157 158 159 160 161 162 163 164 165 166 167 168 169 170
    }

    /* Then let the driver override it */
    if (drv->bdrv_refresh_limits) {
        drv->bdrv_refresh_limits(bs, errp);
    }
}

/**
 * The copy-on-read flag is actually a reference count so multiple users may
 * use the feature without worrying about clobbering its previous state.
 * Copy-on-read stays enabled until all users have called to disable it.
 */
void bdrv_enable_copy_on_read(BlockDriverState *bs)
{
171
    atomic_inc(&bs->copy_on_read);
172 173 174 175
}

void bdrv_disable_copy_on_read(BlockDriverState *bs)
{
176 177
    int old = atomic_fetch_dec(&bs->copy_on_read);
    assert(old >= 1);
178 179
}

180 181 182 183
typedef struct {
    Coroutine *co;
    BlockDriverState *bs;
    bool done;
184
    bool begin;
185
    bool recursive;
186
    bool poll;
187
    BdrvChild *parent;
188
    bool ignore_bds_parents;
189 190 191 192 193 194 195
} BdrvCoDrainData;

static void coroutine_fn bdrv_drain_invoke_entry(void *opaque)
{
    BdrvCoDrainData *data = opaque;
    BlockDriverState *bs = data->bs;

196
    if (data->begin) {
197
        bs->drv->bdrv_co_drain_begin(bs);
198 199 200
    } else {
        bs->drv->bdrv_co_drain_end(bs);
    }
201 202 203

    /* Set data->done before reading bs->wakeup.  */
    atomic_mb_set(&data->done, true);
204 205 206 207 208
    bdrv_dec_in_flight(bs);

    if (data->begin) {
        g_free(data);
    }
209 210
}

211
/* Recursively call BlockDriver.bdrv_co_drain_begin/end callbacks */
212
static void bdrv_drain_invoke(BlockDriverState *bs, bool begin)
213
{
214
    BdrvCoDrainData *data;
215

216
    if (!bs->drv || (begin && !bs->drv->bdrv_co_drain_begin) ||
217
            (!begin && !bs->drv->bdrv_co_drain_end)) {
218 219 220
        return;
    }

221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237
    data = g_new(BdrvCoDrainData, 1);
    *data = (BdrvCoDrainData) {
        .bs = bs,
        .done = false,
        .begin = begin
    };

    /* Make sure the driver callback completes during the polling phase for
     * drain_begin. */
    bdrv_inc_in_flight(bs);
    data->co = qemu_coroutine_create(bdrv_drain_invoke_entry, data);
    aio_co_schedule(bdrv_get_aio_context(bs), data->co);

    if (!begin) {
        BDRV_POLL_WHILE(bs, !data->done);
        g_free(data);
    }
238 239
}

240
/* Returns true if BDRV_POLL_WHILE() should go into a blocking aio_poll() */
241
bool bdrv_drain_poll(BlockDriverState *bs, bool recursive,
242
                     BdrvChild *ignore_parent, bool ignore_bds_parents)
243
{
244 245
    BdrvChild *child, *next;

246
    if (bdrv_parent_drained_poll(bs, ignore_parent, ignore_bds_parents)) {
247 248 249
        return true;
    }

250 251 252 253 254
    if (atomic_read(&bs->in_flight)) {
        return true;
    }

    if (recursive) {
255
        assert(!ignore_bds_parents);
256
        QLIST_FOREACH_SAFE(child, &bs->children, next, next) {
257
            if (bdrv_drain_poll(child->bs, recursive, child, false)) {
258 259 260 261 262 263
                return true;
            }
        }
    }

    return false;
264 265
}

266
static bool bdrv_drain_poll_top_level(BlockDriverState *bs, bool recursive,
267
                                      BdrvChild *ignore_parent)
268
{
269
    return bdrv_drain_poll(bs, recursive, ignore_parent, false);
270 271
}

272
static void bdrv_do_drained_begin(BlockDriverState *bs, bool recursive,
273 274
                                  BdrvChild *parent, bool ignore_bds_parents,
                                  bool poll);
275
static void bdrv_do_drained_end(BlockDriverState *bs, bool recursive,
276
                                BdrvChild *parent, bool ignore_bds_parents);
277

F
Fam Zheng 已提交
278 279 280 281
static void bdrv_co_drain_bh_cb(void *opaque)
{
    BdrvCoDrainData *data = opaque;
    Coroutine *co = data->co;
282
    BlockDriverState *bs = data->bs;
F
Fam Zheng 已提交
283

284
    if (bs) {
285 286 287 288 289 290 291 292 293 294 295 296
        AioContext *ctx = bdrv_get_aio_context(bs);
        AioContext *co_ctx = qemu_coroutine_get_aio_context(co);

        /*
         * When the coroutine yielded, the lock for its home context was
         * released, so we need to re-acquire it here. If it explicitly
         * acquired a different context, the lock is still held and we don't
         * want to lock it a second time (or AIO_WAIT_WHILE() would hang).
         */
        if (ctx == co_ctx) {
            aio_context_acquire(ctx);
        }
297 298
        bdrv_dec_in_flight(bs);
        if (data->begin) {
299 300
            bdrv_do_drained_begin(bs, data->recursive, data->parent,
                                  data->ignore_bds_parents, data->poll);
301
        } else {
302 303
            bdrv_do_drained_end(bs, data->recursive, data->parent,
                                data->ignore_bds_parents);
304
        }
305 306 307
        if (ctx == co_ctx) {
            aio_context_release(ctx);
        }
308
    } else {
309 310
        assert(data->begin);
        bdrv_drain_all_begin();
311 312
    }

F
Fam Zheng 已提交
313
    data->done = true;
314
    aio_co_wake(co);
F
Fam Zheng 已提交
315 316
}

317
static void coroutine_fn bdrv_co_yield_to_drain(BlockDriverState *bs,
318
                                                bool begin, bool recursive,
319 320 321
                                                BdrvChild *parent,
                                                bool ignore_bds_parents,
                                                bool poll)
F
Fam Zheng 已提交
322 323 324 325
{
    BdrvCoDrainData data;

    /* Calling bdrv_drain() from a BH ensures the current coroutine yields and
326
     * other coroutines run if they were queued by aio_co_enter(). */
F
Fam Zheng 已提交
327 328 329 330 331 332

    assert(qemu_in_coroutine());
    data = (BdrvCoDrainData) {
        .co = qemu_coroutine_self(),
        .bs = bs,
        .done = false,
333
        .begin = begin,
334
        .recursive = recursive,
335
        .parent = parent,
336
        .ignore_bds_parents = ignore_bds_parents,
337
        .poll = poll,
F
Fam Zheng 已提交
338
    };
339 340 341
    if (bs) {
        bdrv_inc_in_flight(bs);
    }
P
Paolo Bonzini 已提交
342 343
    aio_bh_schedule_oneshot(bdrv_get_aio_context(bs),
                            bdrv_co_drain_bh_cb, &data);
F
Fam Zheng 已提交
344 345 346 347 348 349 350

    qemu_coroutine_yield();
    /* If we are resumed from some other event (such as an aio completion or a
     * timer callback), it is a bug in the caller that should be fixed. */
    assert(data.done);
}

351
void bdrv_do_drained_begin_quiesce(BlockDriverState *bs,
352
                                   BdrvChild *parent, bool ignore_bds_parents)
353
{
354
    assert(!qemu_in_coroutine());
355

K
Kevin Wolf 已提交
356
    /* Stop things in parent-to-child order */
357
    if (atomic_fetch_inc(&bs->quiesce_counter) == 0) {
358 359 360
        aio_disable_external(bdrv_get_aio_context(bs));
    }

361
    bdrv_parent_drained_begin(bs, parent, ignore_bds_parents);
362
    bdrv_drain_invoke(bs, true);
363 364 365
}

static void bdrv_do_drained_begin(BlockDriverState *bs, bool recursive,
366 367
                                  BdrvChild *parent, bool ignore_bds_parents,
                                  bool poll)
368 369 370 371
{
    BdrvChild *child, *next;

    if (qemu_in_coroutine()) {
372 373
        bdrv_co_yield_to_drain(bs, true, recursive, parent, ignore_bds_parents,
                               poll);
374 375 376
        return;
    }

377
    bdrv_do_drained_begin_quiesce(bs, parent, ignore_bds_parents);
K
Kevin Wolf 已提交
378

379
    if (recursive) {
380
        assert(!ignore_bds_parents);
381
        bs->recursive_quiesce_counter++;
382
        QLIST_FOREACH_SAFE(child, &bs->children, next, next) {
383 384
            bdrv_do_drained_begin(child->bs, true, child, ignore_bds_parents,
                                  false);
385 386
        }
    }
387 388 389 390 391 392 393 394 395 396 397

    /*
     * Wait for drained requests to finish.
     *
     * Calling BDRV_POLL_WHILE() only once for the top-level node is okay: The
     * call is needed so things in this AioContext can make progress even
     * though we don't return to the main AioContext loop - this automatically
     * includes other nodes in the same AioContext and therefore all child
     * nodes.
     */
    if (poll) {
398
        assert(!ignore_bds_parents);
399 400
        BDRV_POLL_WHILE(bs, bdrv_drain_poll_top_level(bs, recursive, parent));
    }
401 402
}

403 404
void bdrv_drained_begin(BlockDriverState *bs)
{
405
    bdrv_do_drained_begin(bs, false, NULL, false, true);
406 407 408 409
}

void bdrv_subtree_drained_begin(BlockDriverState *bs)
{
410
    bdrv_do_drained_begin(bs, true, NULL, false, true);
411 412
}

413 414
static void bdrv_do_drained_end(BlockDriverState *bs, bool recursive,
                                BdrvChild *parent, bool ignore_bds_parents)
415
{
416
    BdrvChild *child, *next;
417 418
    int old_quiesce_counter;

419
    if (qemu_in_coroutine()) {
420 421
        bdrv_co_yield_to_drain(bs, false, recursive, parent, ignore_bds_parents,
                               false);
422 423
        return;
    }
424
    assert(bs->quiesce_counter > 0);
425
    old_quiesce_counter = atomic_fetch_dec(&bs->quiesce_counter);
426

K
Kevin Wolf 已提交
427
    /* Re-enable things in child-to-parent order */
428
    bdrv_drain_invoke(bs, false);
429
    bdrv_parent_drained_end(bs, parent, ignore_bds_parents);
430 431 432
    if (old_quiesce_counter == 1) {
        aio_enable_external(bdrv_get_aio_context(bs));
    }
433 434

    if (recursive) {
435
        assert(!ignore_bds_parents);
436
        bs->recursive_quiesce_counter--;
437
        QLIST_FOREACH_SAFE(child, &bs->children, next, next) {
438
            bdrv_do_drained_end(child->bs, true, child, ignore_bds_parents);
439 440
        }
    }
441 442
}

443 444
void bdrv_drained_end(BlockDriverState *bs)
{
445
    bdrv_do_drained_end(bs, false, NULL, false);
446 447 448 449
}

void bdrv_subtree_drained_end(BlockDriverState *bs)
{
450
    bdrv_do_drained_end(bs, true, NULL, false);
451 452
}

453 454 455 456 457
void bdrv_apply_subtree_drain(BdrvChild *child, BlockDriverState *new_parent)
{
    int i;

    for (i = 0; i < new_parent->recursive_quiesce_counter; i++) {
458
        bdrv_do_drained_begin(child->bs, true, child, false, true);
459 460 461 462 463 464 465 466
    }
}

void bdrv_unapply_subtree_drain(BdrvChild *child, BlockDriverState *old_parent)
{
    int i;

    for (i = 0; i < old_parent->recursive_quiesce_counter; i++) {
467
        bdrv_do_drained_end(child->bs, true, child, false);
468 469 470
    }
}

471
/*
472 473
 * Wait for pending requests to complete on a single BlockDriverState subtree,
 * and suspend block driver's internal I/O until next request arrives.
474 475 476 477
 *
 * Note that unlike bdrv_drain_all(), the caller must hold the BlockDriverState
 * AioContext.
 */
478
void coroutine_fn bdrv_co_drain(BlockDriverState *bs)
479
{
480 481 482
    assert(qemu_in_coroutine());
    bdrv_drained_begin(bs);
    bdrv_drained_end(bs);
483
}
484

485 486
void bdrv_drain(BlockDriverState *bs)
{
487 488
    bdrv_drained_begin(bs);
    bdrv_drained_end(bs);
489 490
}

491 492 493 494 495 496 497 498 499 500
static void bdrv_drain_assert_idle(BlockDriverState *bs)
{
    BdrvChild *child, *next;

    assert(atomic_read(&bs->in_flight) == 0);
    QLIST_FOREACH_SAFE(child, &bs->children, next, next) {
        bdrv_drain_assert_idle(child->bs);
    }
}

501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519
unsigned int bdrv_drain_all_count = 0;

static bool bdrv_drain_all_poll(void)
{
    BlockDriverState *bs = NULL;
    bool result = false;

    /* bdrv_drain_poll() can't make changes to the graph and we are holding the
     * main AioContext lock, so iterating bdrv_next_all_states() is safe. */
    while ((bs = bdrv_next_all_states(bs))) {
        AioContext *aio_context = bdrv_get_aio_context(bs);
        aio_context_acquire(aio_context);
        result |= bdrv_drain_poll(bs, false, NULL, true);
        aio_context_release(aio_context);
    }

    return result;
}

520 521 522 523 524
/*
 * Wait for pending requests to complete across all BlockDriverStates
 *
 * This function does not flush data to disk, use bdrv_flush_all() for that
 * after calling this function.
525 526 527 528 529 530
 *
 * This pauses all block jobs and disables external clients. It must
 * be paired with bdrv_drain_all_end().
 *
 * NOTE: no new block jobs or BlockDriverStates can be created between
 * the bdrv_drain_all_begin() and bdrv_drain_all_end() calls.
531
 */
532
void bdrv_drain_all_begin(void)
533
{
534
    BlockDriverState *bs = NULL;
535

536
    if (qemu_in_coroutine()) {
537
        bdrv_co_yield_to_drain(NULL, true, false, NULL, true, true);
538 539 540
        return;
    }

541 542
    /* AIO_WAIT_WHILE() with a NULL context can only be called from the main
     * loop AioContext, so make sure we're in the main context. */
543
    assert(qemu_get_current_aio_context() == qemu_get_aio_context());
544 545
    assert(bdrv_drain_all_count < INT_MAX);
    bdrv_drain_all_count++;
546

547 548 549
    /* Quiesce all nodes, without polling in-flight requests yet. The graph
     * cannot change during this loop. */
    while ((bs = bdrv_next_all_states(bs))) {
550 551 552
        AioContext *aio_context = bdrv_get_aio_context(bs);

        aio_context_acquire(aio_context);
553
        bdrv_do_drained_begin(bs, false, NULL, true, false);
554 555 556
        aio_context_release(aio_context);
    }

557
    /* Now poll the in-flight requests */
K
Kevin Wolf 已提交
558
    AIO_WAIT_WHILE(NULL, bdrv_drain_all_poll());
559 560

    while ((bs = bdrv_next_all_states(bs))) {
561
        bdrv_drain_assert_idle(bs);
562
    }
563 564 565 566
}

void bdrv_drain_all_end(void)
{
567
    BlockDriverState *bs = NULL;
568

569
    while ((bs = bdrv_next_all_states(bs))) {
570 571 572
        AioContext *aio_context = bdrv_get_aio_context(bs);

        aio_context_acquire(aio_context);
573
        bdrv_do_drained_end(bs, false, NULL, true);
574 575
        aio_context_release(aio_context);
    }
576 577 578

    assert(bdrv_drain_all_count > 0);
    bdrv_drain_all_count--;
579 580
}

581 582 583 584 585 586
void bdrv_drain_all(void)
{
    bdrv_drain_all_begin();
    bdrv_drain_all_end();
}

587 588 589 590 591 592 593 594
/**
 * Remove an active request from the tracked requests list
 *
 * This function should be called when a tracked request is completing.
 */
static void tracked_request_end(BdrvTrackedRequest *req)
{
    if (req->serialising) {
595
        atomic_dec(&req->bs->serialising_in_flight);
596 597
    }

598
    qemu_co_mutex_lock(&req->bs->reqs_lock);
599 600
    QLIST_REMOVE(req, list);
    qemu_co_queue_restart_all(&req->wait_queue);
601
    qemu_co_mutex_unlock(&req->bs->reqs_lock);
602 603 604 605 606 607 608 609
}

/**
 * Add an active request to the tracked requests list
 */
static void tracked_request_begin(BdrvTrackedRequest *req,
                                  BlockDriverState *bs,
                                  int64_t offset,
610
                                  uint64_t bytes,
611
                                  enum BdrvTrackedRequestType type)
612
{
613 614
    assert(bytes <= INT64_MAX && offset <= INT64_MAX - bytes);

615 616 617 618
    *req = (BdrvTrackedRequest){
        .bs = bs,
        .offset         = offset,
        .bytes          = bytes,
619
        .type           = type,
620 621 622 623 624 625 626 627
        .co             = qemu_coroutine_self(),
        .serialising    = false,
        .overlap_offset = offset,
        .overlap_bytes  = bytes,
    };

    qemu_co_queue_init(&req->wait_queue);

628
    qemu_co_mutex_lock(&bs->reqs_lock);
629
    QLIST_INSERT_HEAD(&bs->tracked_requests, req, list);
630
    qemu_co_mutex_unlock(&bs->reqs_lock);
631 632 633 634 635
}

static void mark_request_serialising(BdrvTrackedRequest *req, uint64_t align)
{
    int64_t overlap_offset = req->offset & ~(align - 1);
636
    uint64_t overlap_bytes = ROUND_UP(req->offset + req->bytes, align)
637 638 639
                               - overlap_offset;

    if (!req->serialising) {
640
        atomic_inc(&req->bs->serialising_in_flight);
641 642 643 644 645 646 647
        req->serialising = true;
    }

    req->overlap_offset = MIN(req->overlap_offset, overlap_offset);
    req->overlap_bytes = MAX(req->overlap_bytes, overlap_bytes);
}

648 649 650 651 652 653 654 655 656 657 658 659
static bool is_request_serialising_and_aligned(BdrvTrackedRequest *req)
{
    /*
     * If the request is serialising, overlap_offset and overlap_bytes are set,
     * so we can check if the request is aligned. Otherwise, don't care and
     * return false.
     */

    return req->serialising && (req->offset == req->overlap_offset) &&
           (req->bytes == req->overlap_bytes);
}

660 661 662 663
/**
 * Round a region to cluster boundaries
 */
void bdrv_round_to_clusters(BlockDriverState *bs,
664
                            int64_t offset, int64_t bytes,
665
                            int64_t *cluster_offset,
666
                            int64_t *cluster_bytes)
667 668 669 670 671 672 673 674 675 676 677 678 679
{
    BlockDriverInfo bdi;

    if (bdrv_get_info(bs, &bdi) < 0 || bdi.cluster_size == 0) {
        *cluster_offset = offset;
        *cluster_bytes = bytes;
    } else {
        int64_t c = bdi.cluster_size;
        *cluster_offset = QEMU_ALIGN_DOWN(offset, c);
        *cluster_bytes = QEMU_ALIGN_UP(offset - *cluster_offset + bytes, c);
    }
}

680 681 682 683 684 685 686
static int bdrv_get_cluster_size(BlockDriverState *bs)
{
    BlockDriverInfo bdi;
    int ret;

    ret = bdrv_get_info(bs, &bdi);
    if (ret < 0 || bdi.cluster_size == 0) {
687
        return bs->bl.request_alignment;
688 689 690 691 692 693
    } else {
        return bdi.cluster_size;
    }
}

static bool tracked_request_overlaps(BdrvTrackedRequest *req,
694
                                     int64_t offset, uint64_t bytes)
695 696 697 698 699 700 701 702 703 704 705 706
{
    /*        aaaa   bbbb */
    if (offset >= req->overlap_offset + req->overlap_bytes) {
        return false;
    }
    /* bbbb   aaaa        */
    if (req->overlap_offset >= offset + bytes) {
        return false;
    }
    return true;
}

707 708 709 710 711
void bdrv_inc_in_flight(BlockDriverState *bs)
{
    atomic_inc(&bs->in_flight);
}

712 713
void bdrv_wakeup(BlockDriverState *bs)
{
K
Kevin Wolf 已提交
714
    aio_wait_kick();
715 716
}

717 718 719
void bdrv_dec_in_flight(BlockDriverState *bs)
{
    atomic_dec(&bs->in_flight);
720
    bdrv_wakeup(bs);
721 722
}

723 724 725 726 727 728 729
static bool coroutine_fn wait_serialising_requests(BdrvTrackedRequest *self)
{
    BlockDriverState *bs = self->bs;
    BdrvTrackedRequest *req;
    bool retry;
    bool waited = false;

730
    if (!atomic_read(&bs->serialising_in_flight)) {
731 732 733 734 735
        return false;
    }

    do {
        retry = false;
736
        qemu_co_mutex_lock(&bs->reqs_lock);
737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754
        QLIST_FOREACH(req, &bs->tracked_requests, list) {
            if (req == self || (!req->serialising && !self->serialising)) {
                continue;
            }
            if (tracked_request_overlaps(req, self->overlap_offset,
                                         self->overlap_bytes))
            {
                /* Hitting this means there was a reentrant request, for
                 * example, a block driver issuing nested requests.  This must
                 * never happen since it means deadlock.
                 */
                assert(qemu_coroutine_self() != req->co);

                /* If the request is already (indirectly) waiting for us, or
                 * will wait for us as soon as it wakes up, then just go on
                 * (instead of producing a deadlock in the former case). */
                if (!req->waiting_for) {
                    self->waiting_for = req;
755
                    qemu_co_queue_wait(&req->wait_queue, &bs->reqs_lock);
756 757 758 759 760 761 762
                    self->waiting_for = NULL;
                    retry = true;
                    waited = true;
                    break;
                }
            }
        }
763
        qemu_co_mutex_unlock(&bs->reqs_lock);
764 765 766 767 768 769 770 771
    } while (retry);

    return waited;
}

static int bdrv_check_byte_request(BlockDriverState *bs, int64_t offset,
                                   size_t size)
{
772
    if (size > BDRV_REQUEST_MAX_BYTES) {
773 774 775 776 777 778 779 780 781 782 783 784 785 786 787
        return -EIO;
    }

    if (!bdrv_is_inserted(bs)) {
        return -ENOMEDIUM;
    }

    if (offset < 0) {
        return -EIO;
    }

    return 0;
}

typedef struct RwCo {
788
    BdrvChild *child;
789 790 791 792 793 794 795 796 797 798 799 800
    int64_t offset;
    QEMUIOVector *qiov;
    bool is_write;
    int ret;
    BdrvRequestFlags flags;
} RwCo;

static void coroutine_fn bdrv_rw_co_entry(void *opaque)
{
    RwCo *rwco = opaque;

    if (!rwco->is_write) {
801
        rwco->ret = bdrv_co_preadv(rwco->child, rwco->offset,
802 803
                                   rwco->qiov->size, rwco->qiov,
                                   rwco->flags);
804
    } else {
805
        rwco->ret = bdrv_co_pwritev(rwco->child, rwco->offset,
806 807
                                    rwco->qiov->size, rwco->qiov,
                                    rwco->flags);
808
    }
809
    aio_wait_kick();
810 811 812 813 814
}

/*
 * Process a vectored synchronous request using coroutines
 */
815
static int bdrv_prwv_co(BdrvChild *child, int64_t offset,
816 817 818 819 820
                        QEMUIOVector *qiov, bool is_write,
                        BdrvRequestFlags flags)
{
    Coroutine *co;
    RwCo rwco = {
821
        .child = child,
822 823 824 825 826 827 828 829 830 831 832
        .offset = offset,
        .qiov = qiov,
        .is_write = is_write,
        .ret = NOT_DONE,
        .flags = flags,
    };

    if (qemu_in_coroutine()) {
        /* Fast-path if already in coroutine context */
        bdrv_rw_co_entry(&rwco);
    } else {
833
        co = qemu_coroutine_create(bdrv_rw_co_entry, &rwco);
834
        bdrv_coroutine_enter(child->bs, co);
P
Paolo Bonzini 已提交
835
        BDRV_POLL_WHILE(child->bs, rwco.ret == NOT_DONE);
836 837 838 839
    }
    return rwco.ret;
}

840
int bdrv_pwrite_zeroes(BdrvChild *child, int64_t offset,
841
                       int bytes, BdrvRequestFlags flags)
842
{
843
    QEMUIOVector qiov = QEMU_IOVEC_INIT_BUF(qiov, NULL, bytes);
844

845
    return bdrv_prwv_co(child, offset, &qiov, true,
846
                        BDRV_REQ_ZERO_WRITE | flags);
847 848 849
}

/*
850
 * Completely zero out a block device with the help of bdrv_pwrite_zeroes.
851 852
 * The operation is sped up by checking the block status and only writing
 * zeroes to the device if they currently do not return zeroes. Optional
853
 * flags are passed through to bdrv_pwrite_zeroes (e.g. BDRV_REQ_MAY_UNMAP,
854
 * BDRV_REQ_FUA).
855 856 857
 *
 * Returns < 0 on error, 0 on success. For error codes see bdrv_write().
 */
858
int bdrv_make_zero(BdrvChild *child, BdrvRequestFlags flags)
859
{
860 861
    int ret;
    int64_t target_size, bytes, offset = 0;
862
    BlockDriverState *bs = child->bs;
863

864 865 866
    target_size = bdrv_getlength(bs);
    if (target_size < 0) {
        return target_size;
867 868 869
    }

    for (;;) {
870 871
        bytes = MIN(target_size - offset, BDRV_REQUEST_MAX_BYTES);
        if (bytes <= 0) {
872 873
            return 0;
        }
874
        ret = bdrv_block_status(bs, offset, bytes, &bytes, NULL, NULL);
875 876 877 878
        if (ret < 0) {
            return ret;
        }
        if (ret & BDRV_BLOCK_ZERO) {
879
            offset += bytes;
880 881
            continue;
        }
882
        ret = bdrv_pwrite_zeroes(child, offset, bytes, flags);
883 884 885
        if (ret < 0) {
            return ret;
        }
886
        offset += bytes;
887 888 889
    }
}

890
int bdrv_preadv(BdrvChild *child, int64_t offset, QEMUIOVector *qiov)
K
Kevin Wolf 已提交
891 892 893
{
    int ret;

894
    ret = bdrv_prwv_co(child, offset, qiov, false, 0);
K
Kevin Wolf 已提交
895 896 897 898 899 900 901
    if (ret < 0) {
        return ret;
    }

    return qiov->size;
}

902
/* See bdrv_pwrite() for the return codes */
903
int bdrv_pread(BdrvChild *child, int64_t offset, void *buf, int bytes)
904
{
905
    QEMUIOVector qiov = QEMU_IOVEC_INIT_BUF(qiov, buf, bytes);
906 907 908 909 910

    if (bytes < 0) {
        return -EINVAL;
    }

911
    return bdrv_preadv(child, offset, &qiov);
912 913
}

914
int bdrv_pwritev(BdrvChild *child, int64_t offset, QEMUIOVector *qiov)
915 916 917
{
    int ret;

918
    ret = bdrv_prwv_co(child, offset, qiov, true, 0);
919 920 921 922 923 924 925
    if (ret < 0) {
        return ret;
    }

    return qiov->size;
}

926 927 928 929 930 931
/* Return no. of bytes on success or < 0 on error. Important errors are:
  -EIO         generic I/O error (may happen for all errors)
  -ENOMEDIUM   No media inserted.
  -EINVAL      Invalid offset or number of bytes
  -EACCES      Trying to write a read-only device
*/
932
int bdrv_pwrite(BdrvChild *child, int64_t offset, const void *buf, int bytes)
933
{
934
    QEMUIOVector qiov = QEMU_IOVEC_INIT_BUF(qiov, buf, bytes);
935 936 937 938 939

    if (bytes < 0) {
        return -EINVAL;
    }

940
    return bdrv_pwritev(child, offset, &qiov);
941 942 943 944 945 946 947 948
}

/*
 * Writes to the file and ensures that no writes are reordered across this
 * request (acts as a barrier)
 *
 * Returns 0 on success, -errno in error cases.
 */
949 950
int bdrv_pwrite_sync(BdrvChild *child, int64_t offset,
                     const void *buf, int count)
951 952 953
{
    int ret;

954
    ret = bdrv_pwrite(child, offset, buf, count);
955 956 957 958
    if (ret < 0) {
        return ret;
    }

959
    ret = bdrv_flush(child->bs);
960 961
    if (ret < 0) {
        return ret;
962 963 964 965 966
    }

    return 0;
}

967 968 969 970 971 972 973 974 975 976
typedef struct CoroutineIOCompletion {
    Coroutine *coroutine;
    int ret;
} CoroutineIOCompletion;

static void bdrv_co_io_em_complete(void *opaque, int ret)
{
    CoroutineIOCompletion *co = opaque;

    co->ret = ret;
977
    aio_co_wake(co->coroutine);
978 979
}

980 981 982 983 984
static int coroutine_fn bdrv_driver_preadv(BlockDriverState *bs,
                                           uint64_t offset, uint64_t bytes,
                                           QEMUIOVector *qiov, int flags)
{
    BlockDriver *drv = bs->drv;
985 986 987
    int64_t sector_num;
    unsigned int nb_sectors;

988
    assert(!(flags & ~BDRV_REQ_MASK));
K
Kevin Wolf 已提交
989
    assert(!(flags & BDRV_REQ_NO_FALLBACK));
990

M
Max Reitz 已提交
991 992 993 994
    if (!drv) {
        return -ENOMEDIUM;
    }

995 996 997 998
    if (drv->bdrv_co_preadv) {
        return drv->bdrv_co_preadv(bs, offset, bytes, qiov, flags);
    }

999
    if (drv->bdrv_aio_preadv) {
1000 1001 1002 1003 1004
        BlockAIOCB *acb;
        CoroutineIOCompletion co = {
            .coroutine = qemu_coroutine_self(),
        };

1005 1006
        acb = drv->bdrv_aio_preadv(bs, offset, bytes, qiov, flags,
                                   bdrv_co_io_em_complete, &co);
1007 1008 1009 1010 1011 1012 1013
        if (acb == NULL) {
            return -EIO;
        } else {
            qemu_coroutine_yield();
            return co.ret;
        }
    }
1014 1015 1016 1017 1018 1019

    sector_num = offset >> BDRV_SECTOR_BITS;
    nb_sectors = bytes >> BDRV_SECTOR_BITS;

    assert((offset & (BDRV_SECTOR_SIZE - 1)) == 0);
    assert((bytes & (BDRV_SECTOR_SIZE - 1)) == 0);
1020
    assert(bytes <= BDRV_REQUEST_MAX_BYTES);
1021 1022 1023
    assert(drv->bdrv_co_readv);

    return drv->bdrv_co_readv(bs, sector_num, nb_sectors, qiov);
1024 1025
}

1026 1027 1028 1029 1030
static int coroutine_fn bdrv_driver_pwritev(BlockDriverState *bs,
                                            uint64_t offset, uint64_t bytes,
                                            QEMUIOVector *qiov, int flags)
{
    BlockDriver *drv = bs->drv;
1031 1032
    int64_t sector_num;
    unsigned int nb_sectors;
1033 1034
    int ret;

1035
    assert(!(flags & ~BDRV_REQ_MASK));
K
Kevin Wolf 已提交
1036
    assert(!(flags & BDRV_REQ_NO_FALLBACK));
1037

M
Max Reitz 已提交
1038 1039 1040 1041
    if (!drv) {
        return -ENOMEDIUM;
    }

1042
    if (drv->bdrv_co_pwritev) {
1043 1044 1045
        ret = drv->bdrv_co_pwritev(bs, offset, bytes, qiov,
                                   flags & bs->supported_write_flags);
        flags &= ~bs->supported_write_flags;
1046 1047 1048
        goto emulate_flags;
    }

1049
    if (drv->bdrv_aio_pwritev) {
1050 1051 1052 1053 1054
        BlockAIOCB *acb;
        CoroutineIOCompletion co = {
            .coroutine = qemu_coroutine_self(),
        };

1055 1056 1057 1058
        acb = drv->bdrv_aio_pwritev(bs, offset, bytes, qiov,
                                    flags & bs->supported_write_flags,
                                    bdrv_co_io_em_complete, &co);
        flags &= ~bs->supported_write_flags;
1059
        if (acb == NULL) {
1060
            ret = -EIO;
1061 1062
        } else {
            qemu_coroutine_yield();
1063
            ret = co.ret;
1064
        }
1065 1066 1067 1068 1069 1070 1071 1072
        goto emulate_flags;
    }

    sector_num = offset >> BDRV_SECTOR_BITS;
    nb_sectors = bytes >> BDRV_SECTOR_BITS;

    assert((offset & (BDRV_SECTOR_SIZE - 1)) == 0);
    assert((bytes & (BDRV_SECTOR_SIZE - 1)) == 0);
1073
    assert(bytes <= BDRV_REQUEST_MAX_BYTES);
1074

1075 1076 1077 1078
    assert(drv->bdrv_co_writev);
    ret = drv->bdrv_co_writev(bs, sector_num, nb_sectors, qiov,
                              flags & bs->supported_write_flags);
    flags &= ~bs->supported_write_flags;
1079

1080
emulate_flags:
1081
    if (ret == 0 && (flags & BDRV_REQ_FUA)) {
1082 1083 1084 1085 1086 1087
        ret = bdrv_co_flush(bs);
    }

    return ret;
}

1088 1089 1090 1091 1092 1093
static int coroutine_fn
bdrv_driver_pwritev_compressed(BlockDriverState *bs, uint64_t offset,
                               uint64_t bytes, QEMUIOVector *qiov)
{
    BlockDriver *drv = bs->drv;

M
Max Reitz 已提交
1094 1095 1096 1097
    if (!drv) {
        return -ENOMEDIUM;
    }

1098 1099 1100 1101 1102 1103 1104
    if (!drv->bdrv_co_pwritev_compressed) {
        return -ENOTSUP;
    }

    return drv->bdrv_co_pwritev_compressed(bs, offset, bytes, qiov);
}

1105
static int coroutine_fn bdrv_co_do_copy_on_readv(BdrvChild *child,
1106
        int64_t offset, unsigned int bytes, QEMUIOVector *qiov)
1107
{
1108 1109
    BlockDriverState *bs = child->bs;

1110 1111 1112 1113 1114 1115 1116 1117
    /* Perform I/O through a temporary buffer so that users who scribble over
     * their read buffer while the operation is in progress do not end up
     * modifying the image file.  This is critical for zero-copy guest I/O
     * where anything might happen inside guest memory.
     */
    void *bounce_buffer;

    BlockDriver *drv = bs->drv;
E
Eric Blake 已提交
1118
    QEMUIOVector local_qiov;
1119
    int64_t cluster_offset;
1120
    int64_t cluster_bytes;
1121 1122
    size_t skip_bytes;
    int ret;
E
Eric Blake 已提交
1123 1124 1125
    int max_transfer = MIN_NON_ZERO(bs->bl.max_transfer,
                                    BDRV_REQUEST_MAX_BYTES);
    unsigned int progress = 0;
1126

M
Max Reitz 已提交
1127 1128 1129 1130
    if (!drv) {
        return -ENOMEDIUM;
    }

1131 1132 1133
    /* FIXME We cannot require callers to have write permissions when all they
     * are doing is a read request. If we did things right, write permissions
     * would be obtained anyway, but internally by the copy-on-read code. As
E
Eric Blake 已提交
1134
     * long as it is implemented here rather than in a separate filter driver,
1135 1136 1137 1138
     * the copy-on-read code doesn't have its own BdrvChild, however, for which
     * it could request permissions. Therefore we have to bypass the permission
     * system for the moment. */
    // assert(child->perm & (BLK_PERM_WRITE_UNCHANGED | BLK_PERM_WRITE));
1139

1140
    /* Cover entire cluster so no additional backing file I/O is required when
E
Eric Blake 已提交
1141 1142 1143
     * allocating cluster in the image file.  Note that this value may exceed
     * BDRV_REQUEST_MAX_BYTES (even when the original read did not), which
     * is one reason we loop rather than doing it all at once.
1144
     */
1145
    bdrv_round_to_clusters(bs, offset, bytes, &cluster_offset, &cluster_bytes);
E
Eric Blake 已提交
1146
    skip_bytes = offset - cluster_offset;
1147

1148 1149
    trace_bdrv_co_do_copy_on_readv(bs, offset, bytes,
                                   cluster_offset, cluster_bytes);
1150

E
Eric Blake 已提交
1151 1152 1153
    bounce_buffer = qemu_try_blockalign(bs,
                                        MIN(MIN(max_transfer, cluster_bytes),
                                            MAX_BOUNCE_BUFFER));
1154 1155 1156 1157 1158
    if (bounce_buffer == NULL) {
        ret = -ENOMEM;
        goto err;
    }

E
Eric Blake 已提交
1159 1160
    while (cluster_bytes) {
        int64_t pnum;
1161

E
Eric Blake 已提交
1162 1163 1164 1165 1166 1167 1168 1169 1170
        ret = bdrv_is_allocated(bs, cluster_offset,
                                MIN(cluster_bytes, max_transfer), &pnum);
        if (ret < 0) {
            /* Safe to treat errors in querying allocation as if
             * unallocated; we'll probably fail again soon on the
             * read, but at least that will set a decent errno.
             */
            pnum = MIN(cluster_bytes, max_transfer);
        }
1171

1172 1173 1174 1175 1176 1177
        /* Stop at EOF if the image ends in the middle of the cluster */
        if (ret == 0 && pnum == 0) {
            assert(progress >= bytes);
            break;
        }

E
Eric Blake 已提交
1178
        assert(skip_bytes < pnum);
1179

E
Eric Blake 已提交
1180 1181
        if (ret <= 0) {
            /* Must copy-on-read; use the bounce buffer */
1182 1183
            pnum = MIN(pnum, MAX_BOUNCE_BUFFER);
            qemu_iovec_init_buf(&local_qiov, bounce_buffer, pnum);
1184

E
Eric Blake 已提交
1185 1186 1187 1188 1189 1190 1191 1192 1193 1194 1195 1196
            ret = bdrv_driver_preadv(bs, cluster_offset, pnum,
                                     &local_qiov, 0);
            if (ret < 0) {
                goto err;
            }

            bdrv_debug_event(bs, BLKDBG_COR_WRITE);
            if (drv->bdrv_co_pwrite_zeroes &&
                buffer_is_zero(bounce_buffer, pnum)) {
                /* FIXME: Should we (perhaps conditionally) be setting
                 * BDRV_REQ_MAY_UNMAP, if it will allow for a sparser copy
                 * that still correctly reads as zero? */
1197 1198
                ret = bdrv_co_do_pwrite_zeroes(bs, cluster_offset, pnum,
                                               BDRV_REQ_WRITE_UNCHANGED);
E
Eric Blake 已提交
1199 1200 1201 1202 1203
            } else {
                /* This does not change the data on the disk, it is not
                 * necessary to flush even in cache=writethrough mode.
                 */
                ret = bdrv_driver_pwritev(bs, cluster_offset, pnum,
1204 1205
                                          &local_qiov,
                                          BDRV_REQ_WRITE_UNCHANGED);
E
Eric Blake 已提交
1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228 1229 1230 1231 1232 1233 1234 1235 1236
            }

            if (ret < 0) {
                /* It might be okay to ignore write errors for guest
                 * requests.  If this is a deliberate copy-on-read
                 * then we don't want to ignore the error.  Simply
                 * report it in all cases.
                 */
                goto err;
            }

            qemu_iovec_from_buf(qiov, progress, bounce_buffer + skip_bytes,
                                pnum - skip_bytes);
        } else {
            /* Read directly into the destination */
            qemu_iovec_init(&local_qiov, qiov->niov);
            qemu_iovec_concat(&local_qiov, qiov, progress, pnum - skip_bytes);
            ret = bdrv_driver_preadv(bs, offset + progress, local_qiov.size,
                                     &local_qiov, 0);
            qemu_iovec_destroy(&local_qiov);
            if (ret < 0) {
                goto err;
            }
        }

        cluster_offset += pnum;
        cluster_bytes -= pnum;
        progress += pnum - skip_bytes;
        skip_bytes = 0;
    }
    ret = 0;
1237 1238 1239 1240 1241 1242 1243 1244

err:
    qemu_vfree(bounce_buffer);
    return ret;
}

/*
 * Forwards an already correctly aligned request to the BlockDriver. This
1245 1246
 * handles copy on read, zeroing after EOF, and fragmentation of large
 * reads; any other features must be implemented by the caller.
1247
 */
1248
static int coroutine_fn bdrv_aligned_preadv(BdrvChild *child,
1249 1250 1251
    BdrvTrackedRequest *req, int64_t offset, unsigned int bytes,
    int64_t align, QEMUIOVector *qiov, int flags)
{
1252
    BlockDriverState *bs = child->bs;
K
Kevin Wolf 已提交
1253
    int64_t total_bytes, max_bytes;
1254 1255 1256
    int ret = 0;
    uint64_t bytes_remaining = bytes;
    int max_transfer;
1257

1258 1259 1260
    assert(is_power_of_2(align));
    assert((offset & (align - 1)) == 0);
    assert((bytes & (align - 1)) == 0);
1261
    assert(!qiov || bytes == qiov->size);
1262
    assert((bs->open_flags & BDRV_O_NO_IO) == 0);
1263 1264
    max_transfer = QEMU_ALIGN_DOWN(MIN_NON_ZERO(bs->bl.max_transfer, INT_MAX),
                                   align);
1265 1266 1267 1268 1269 1270

    /* TODO: We would need a per-BDS .supported_read_flags and
     * potential fallback support, if we ever implement any read flags
     * to pass through to drivers.  For now, there aren't any
     * passthrough flags.  */
    assert(!(flags & ~(BDRV_REQ_NO_SERIALISING | BDRV_REQ_COPY_ON_READ)));
1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281

    /* Handle Copy on Read and associated serialisation */
    if (flags & BDRV_REQ_COPY_ON_READ) {
        /* If we touch the same cluster it counts as an overlap.  This
         * guarantees that allocating writes will be serialized and not race
         * with each other for the same cluster.  For example, in copy-on-read
         * it ensures that the CoR read and write operations are atomic and
         * guest writes cannot interleave between them. */
        mark_request_serialising(req, bdrv_get_cluster_size(bs));
    }

1282 1283 1284
    /* BDRV_REQ_SERIALISING is only for write operation */
    assert(!(flags & BDRV_REQ_SERIALISING));

1285 1286 1287
    if (!(flags & BDRV_REQ_NO_SERIALISING)) {
        wait_serialising_requests(req);
    }
1288 1289

    if (flags & BDRV_REQ_COPY_ON_READ) {
1290
        int64_t pnum;
1291

1292
        ret = bdrv_is_allocated(bs, offset, bytes, &pnum);
1293 1294 1295 1296
        if (ret < 0) {
            goto out;
        }

1297
        if (!ret || pnum != bytes) {
1298
            ret = bdrv_co_do_copy_on_readv(child, offset, bytes, qiov);
1299 1300 1301 1302
            goto out;
        }
    }

1303
    /* Forward the request to the BlockDriver, possibly fragmenting it */
K
Kevin Wolf 已提交
1304 1305 1306 1307 1308
    total_bytes = bdrv_getlength(bs);
    if (total_bytes < 0) {
        ret = total_bytes;
        goto out;
    }
1309

K
Kevin Wolf 已提交
1310
    max_bytes = ROUND_UP(MAX(0, total_bytes - offset), align);
1311
    if (bytes <= max_bytes && bytes <= max_transfer) {
K
Kevin Wolf 已提交
1312
        ret = bdrv_driver_preadv(bs, offset, bytes, qiov, 0);
1313 1314
        goto out;
    }
1315

1316 1317
    while (bytes_remaining) {
        int num;
1318

1319 1320
        if (max_bytes) {
            QEMUIOVector local_qiov;
1321

1322 1323 1324 1325
            num = MIN(bytes_remaining, MIN(max_bytes, max_transfer));
            assert(num);
            qemu_iovec_init(&local_qiov, qiov->niov);
            qemu_iovec_concat(&local_qiov, qiov, bytes - bytes_remaining, num);
1326

1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339
            ret = bdrv_driver_preadv(bs, offset + bytes - bytes_remaining,
                                     num, &local_qiov, 0);
            max_bytes -= num;
            qemu_iovec_destroy(&local_qiov);
        } else {
            num = bytes_remaining;
            ret = qemu_iovec_memset(qiov, bytes - bytes_remaining, 0,
                                    bytes_remaining);
        }
        if (ret < 0) {
            goto out;
        }
        bytes_remaining -= num;
1340 1341 1342
    }

out:
1343
    return ret < 0 ? ret : 0;
1344 1345 1346 1347 1348
}

/*
 * Handle a read request in coroutine context
 */
1349
int coroutine_fn bdrv_co_preadv(BdrvChild *child,
1350 1351 1352
    int64_t offset, unsigned int bytes, QEMUIOVector *qiov,
    BdrvRequestFlags flags)
{
1353
    BlockDriverState *bs = child->bs;
1354 1355 1356
    BlockDriver *drv = bs->drv;
    BdrvTrackedRequest req;

1357
    uint64_t align = bs->bl.request_alignment;
1358 1359 1360 1361 1362 1363
    uint8_t *head_buf = NULL;
    uint8_t *tail_buf = NULL;
    QEMUIOVector local_qiov;
    bool use_local_qiov = false;
    int ret;

1364 1365
    trace_bdrv_co_preadv(child->bs, offset, bytes, flags);

1366 1367 1368 1369 1370 1371 1372 1373 1374
    if (!drv) {
        return -ENOMEDIUM;
    }

    ret = bdrv_check_byte_request(bs, offset, bytes);
    if (ret < 0) {
        return ret;
    }

1375 1376
    bdrv_inc_in_flight(bs);

1377
    /* Don't do copy-on-read if we read data before write operation */
1378
    if (atomic_read(&bs->copy_on_read) && !(flags & BDRV_REQ_NO_SERIALISING)) {
1379 1380 1381 1382 1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404 1405 1406
        flags |= BDRV_REQ_COPY_ON_READ;
    }

    /* Align read if necessary by padding qiov */
    if (offset & (align - 1)) {
        head_buf = qemu_blockalign(bs, align);
        qemu_iovec_init(&local_qiov, qiov->niov + 2);
        qemu_iovec_add(&local_qiov, head_buf, offset & (align - 1));
        qemu_iovec_concat(&local_qiov, qiov, 0, qiov->size);
        use_local_qiov = true;

        bytes += offset & (align - 1);
        offset = offset & ~(align - 1);
    }

    if ((offset + bytes) & (align - 1)) {
        if (!use_local_qiov) {
            qemu_iovec_init(&local_qiov, qiov->niov + 1);
            qemu_iovec_concat(&local_qiov, qiov, 0, qiov->size);
            use_local_qiov = true;
        }
        tail_buf = qemu_blockalign(bs, align);
        qemu_iovec_add(&local_qiov, tail_buf,
                       align - ((offset + bytes) & (align - 1)));

        bytes = ROUND_UP(bytes, align);
    }

1407
    tracked_request_begin(&req, bs, offset, bytes, BDRV_TRACKED_READ);
1408
    ret = bdrv_aligned_preadv(child, &req, offset, bytes, align,
1409 1410 1411
                              use_local_qiov ? &local_qiov : qiov,
                              flags);
    tracked_request_end(&req);
1412
    bdrv_dec_in_flight(bs);
1413 1414 1415 1416 1417 1418 1419 1420 1421 1422

    if (use_local_qiov) {
        qemu_iovec_destroy(&local_qiov);
        qemu_vfree(head_buf);
        qemu_vfree(tail_buf);
    }

    return ret;
}

E
Eric Blake 已提交
1423
static int coroutine_fn bdrv_co_do_pwrite_zeroes(BlockDriverState *bs,
1424
    int64_t offset, int bytes, BdrvRequestFlags flags)
1425 1426 1427
{
    BlockDriver *drv = bs->drv;
    QEMUIOVector qiov;
1428
    void *buf = NULL;
1429
    int ret = 0;
1430
    bool need_flush = false;
1431 1432
    int head = 0;
    int tail = 0;
1433

1434
    int max_write_zeroes = MIN_NON_ZERO(bs->bl.max_pwrite_zeroes, INT_MAX);
1435 1436
    int alignment = MAX(bs->bl.pwrite_zeroes_alignment,
                        bs->bl.request_alignment);
E
Eric Blake 已提交
1437
    int max_transfer = MIN_NON_ZERO(bs->bl.max_transfer, MAX_BOUNCE_BUFFER);
E
Eric Blake 已提交
1438

M
Max Reitz 已提交
1439 1440 1441 1442
    if (!drv) {
        return -ENOMEDIUM;
    }

K
Kevin Wolf 已提交
1443 1444 1445 1446
    if ((flags & ~bs->supported_zero_flags) & BDRV_REQ_NO_FALLBACK) {
        return -ENOTSUP;
    }

1447 1448
    assert(alignment % bs->bl.request_alignment == 0);
    head = offset % alignment;
1449
    tail = (offset + bytes) % alignment;
1450 1451
    max_write_zeroes = QEMU_ALIGN_DOWN(max_write_zeroes, alignment);
    assert(max_write_zeroes >= bs->bl.request_alignment);
1452

1453 1454
    while (bytes > 0 && !ret) {
        int num = bytes;
1455 1456

        /* Align request.  Block drivers can expect the "bulk" of the request
1457 1458
         * to be aligned, and that unaligned requests do not cross cluster
         * boundaries.
1459
         */
1460
        if (head) {
1461 1462 1463
            /* Make a small request up to the first aligned sector. For
             * convenience, limit this request to max_transfer even if
             * we don't need to fall back to writes.  */
1464
            num = MIN(MIN(bytes, max_transfer), alignment - head);
1465 1466
            head = (head + num) % alignment;
            assert(num < max_write_zeroes);
E
Eric Blake 已提交
1467
        } else if (tail && num > alignment) {
1468 1469
            /* Shorten the request to the last aligned sector.  */
            num -= tail;
1470 1471 1472 1473 1474 1475 1476 1477 1478
        }

        /* limit request size */
        if (num > max_write_zeroes) {
            num = max_write_zeroes;
        }

        ret = -ENOTSUP;
        /* First try the efficient write zeroes operation */
E
Eric Blake 已提交
1479 1480 1481 1482 1483 1484 1485
        if (drv->bdrv_co_pwrite_zeroes) {
            ret = drv->bdrv_co_pwrite_zeroes(bs, offset, num,
                                             flags & bs->supported_zero_flags);
            if (ret != -ENOTSUP && (flags & BDRV_REQ_FUA) &&
                !(bs->supported_zero_flags & BDRV_REQ_FUA)) {
                need_flush = true;
            }
1486 1487
        } else {
            assert(!bs->supported_zero_flags);
1488 1489
        }

1490
        if (ret < 0 && !(flags & BDRV_REQ_NO_FALLBACK)) {
1491
            /* Fall back to bounce buffer if write zeroes is unsupported */
1492 1493 1494 1495 1496 1497 1498 1499 1500
            BdrvRequestFlags write_flags = flags & ~BDRV_REQ_ZERO_WRITE;

            if ((flags & BDRV_REQ_FUA) &&
                !(bs->supported_write_flags & BDRV_REQ_FUA)) {
                /* No need for bdrv_driver_pwrite() to do a fallback
                 * flush on each chunk; use just one at the end */
                write_flags &= ~BDRV_REQ_FUA;
                need_flush = true;
            }
1501
            num = MIN(num, max_transfer);
1502 1503 1504
            if (buf == NULL) {
                buf = qemu_try_blockalign0(bs, num);
                if (buf == NULL) {
1505 1506 1507 1508
                    ret = -ENOMEM;
                    goto fail;
                }
            }
1509
            qemu_iovec_init_buf(&qiov, buf, num);
1510

E
Eric Blake 已提交
1511
            ret = bdrv_driver_pwritev(bs, offset, num, &qiov, write_flags);
1512 1513 1514 1515

            /* Keep bounce buffer around if it is big enough for all
             * all future requests.
             */
1516
            if (num < max_transfer) {
1517 1518
                qemu_vfree(buf);
                buf = NULL;
1519 1520 1521
            }
        }

E
Eric Blake 已提交
1522
        offset += num;
1523
        bytes -= num;
1524 1525 1526
    }

fail:
1527 1528 1529
    if (ret == 0 && need_flush) {
        ret = bdrv_co_flush(bs);
    }
1530
    qemu_vfree(buf);
1531 1532 1533
    return ret;
}

1534 1535 1536 1537 1538 1539 1540 1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561
static inline int coroutine_fn
bdrv_co_write_req_prepare(BdrvChild *child, int64_t offset, uint64_t bytes,
                          BdrvTrackedRequest *req, int flags)
{
    BlockDriverState *bs = child->bs;
    bool waited;
    int64_t end_sector = DIV_ROUND_UP(offset + bytes, BDRV_SECTOR_SIZE);

    if (bs->read_only) {
        return -EPERM;
    }

    /* BDRV_REQ_NO_SERIALISING is only for read operation */
    assert(!(flags & BDRV_REQ_NO_SERIALISING));
    assert(!(bs->open_flags & BDRV_O_INACTIVE));
    assert((bs->open_flags & BDRV_O_NO_IO) == 0);
    assert(!(flags & ~BDRV_REQ_MASK));

    if (flags & BDRV_REQ_SERIALISING) {
        mark_request_serialising(req, bdrv_get_cluster_size(bs));
    }

    waited = wait_serialising_requests(req);

    assert(!waited || !req->serialising ||
           is_request_serialising_and_aligned(req));
    assert(req->overlap_offset <= offset);
    assert(offset + bytes <= req->overlap_offset + req->overlap_bytes);
1562
    assert(end_sector <= bs->total_sectors || child->perm & BLK_PERM_RESIZE);
1563

1564 1565 1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576 1577 1578
    switch (req->type) {
    case BDRV_TRACKED_WRITE:
    case BDRV_TRACKED_DISCARD:
        if (flags & BDRV_REQ_WRITE_UNCHANGED) {
            assert(child->perm & (BLK_PERM_WRITE_UNCHANGED | BLK_PERM_WRITE));
        } else {
            assert(child->perm & BLK_PERM_WRITE);
        }
        return notifier_with_return_list_notify(&bs->before_write_notifiers,
                                                req);
    case BDRV_TRACKED_TRUNCATE:
        assert(child->perm & BLK_PERM_RESIZE);
        return 0;
    default:
        abort();
1579 1580 1581 1582 1583 1584 1585 1586 1587 1588 1589 1590
    }
}

static inline void coroutine_fn
bdrv_co_write_req_finish(BdrvChild *child, int64_t offset, uint64_t bytes,
                         BdrvTrackedRequest *req, int ret)
{
    int64_t end_sector = DIV_ROUND_UP(offset + bytes, BDRV_SECTOR_SIZE);
    BlockDriverState *bs = child->bs;

    atomic_inc(&bs->write_gen);

1591 1592 1593 1594 1595 1596 1597
    /*
     * Discard cannot extend the image, but in error handling cases, such as
     * when reverting a qcow2 cluster allocation, the discarded range can pass
     * the end of image file, so we cannot assert about BDRV_TRACKED_DISCARD
     * here. Instead, just skip it, since semantically a discard request
     * beyond EOF cannot expand the image anyway.
     */
1598
    if (ret == 0 &&
1599 1600 1601
        (req->type == BDRV_TRACKED_TRUNCATE ||
         end_sector > bs->total_sectors) &&
        req->type != BDRV_TRACKED_DISCARD) {
1602 1603 1604
        bs->total_sectors = end_sector;
        bdrv_parent_cb_resize(bs);
        bdrv_dirty_bitmap_truncate(bs, end_sector << BDRV_SECTOR_BITS);
1605
    }
1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617
    if (req->bytes) {
        switch (req->type) {
        case BDRV_TRACKED_WRITE:
            stat64_max(&bs->wr_highest_offset, offset + bytes);
            /* fall through, to set dirty bits */
        case BDRV_TRACKED_DISCARD:
            bdrv_set_dirty(bs, offset, bytes);
            break;
        default:
            break;
        }
    }
1618 1619
}

1620
/*
1621 1622
 * Forwards an already correctly aligned write request to the BlockDriver,
 * after possibly fragmenting it.
1623
 */
1624
static int coroutine_fn bdrv_aligned_pwritev(BdrvChild *child,
1625
    BdrvTrackedRequest *req, int64_t offset, unsigned int bytes,
1626
    int64_t align, QEMUIOVector *qiov, int flags)
1627
{
1628
    BlockDriverState *bs = child->bs;
1629 1630 1631
    BlockDriver *drv = bs->drv;
    int ret;

1632 1633
    uint64_t bytes_remaining = bytes;
    int max_transfer;
1634

M
Max Reitz 已提交
1635 1636 1637 1638
    if (!drv) {
        return -ENOMEDIUM;
    }

1639 1640 1641 1642
    if (bdrv_has_readonly_bitmaps(bs)) {
        return -EPERM;
    }

1643 1644 1645
    assert(is_power_of_2(align));
    assert((offset & (align - 1)) == 0);
    assert((bytes & (align - 1)) == 0);
1646
    assert(!qiov || bytes == qiov->size);
1647 1648
    max_transfer = QEMU_ALIGN_DOWN(MIN_NON_ZERO(bs->bl.max_transfer, INT_MAX),
                                   align);
1649

1650
    ret = bdrv_co_write_req_prepare(child, offset, bytes, req, flags);
1651 1652

    if (!ret && bs->detect_zeroes != BLOCKDEV_DETECT_ZEROES_OPTIONS_OFF &&
E
Eric Blake 已提交
1653
        !(flags & BDRV_REQ_ZERO_WRITE) && drv->bdrv_co_pwrite_zeroes &&
1654 1655 1656 1657 1658 1659 1660 1661 1662 1663
        qemu_iovec_is_zero(qiov)) {
        flags |= BDRV_REQ_ZERO_WRITE;
        if (bs->detect_zeroes == BLOCKDEV_DETECT_ZEROES_OPTIONS_UNMAP) {
            flags |= BDRV_REQ_MAY_UNMAP;
        }
    }

    if (ret < 0) {
        /* Do nothing, write notifier decided to fail this request */
    } else if (flags & BDRV_REQ_ZERO_WRITE) {
K
Kevin Wolf 已提交
1664
        bdrv_debug_event(bs, BLKDBG_PWRITEV_ZERO);
1665
        ret = bdrv_co_do_pwrite_zeroes(bs, offset, bytes, flags);
1666 1667
    } else if (flags & BDRV_REQ_WRITE_COMPRESSED) {
        ret = bdrv_driver_pwritev_compressed(bs, offset, bytes, qiov);
1668
    } else if (bytes <= max_transfer) {
K
Kevin Wolf 已提交
1669
        bdrv_debug_event(bs, BLKDBG_PWRITEV);
1670
        ret = bdrv_driver_pwritev(bs, offset, bytes, qiov, flags);
1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689 1690 1691 1692 1693 1694 1695
    } else {
        bdrv_debug_event(bs, BLKDBG_PWRITEV);
        while (bytes_remaining) {
            int num = MIN(bytes_remaining, max_transfer);
            QEMUIOVector local_qiov;
            int local_flags = flags;

            assert(num);
            if (num < bytes_remaining && (flags & BDRV_REQ_FUA) &&
                !(bs->supported_write_flags & BDRV_REQ_FUA)) {
                /* If FUA is going to be emulated by flush, we only
                 * need to flush on the last iteration */
                local_flags &= ~BDRV_REQ_FUA;
            }
            qemu_iovec_init(&local_qiov, qiov->niov);
            qemu_iovec_concat(&local_qiov, qiov, bytes - bytes_remaining, num);

            ret = bdrv_driver_pwritev(bs, offset + bytes - bytes_remaining,
                                      num, &local_qiov, local_flags);
            qemu_iovec_destroy(&local_qiov);
            if (ret < 0) {
                break;
            }
            bytes_remaining -= num;
        }
1696
    }
K
Kevin Wolf 已提交
1697
    bdrv_debug_event(bs, BLKDBG_PWRITEV_DONE);
1698 1699

    if (ret >= 0) {
1700
        ret = 0;
1701
    }
1702
    bdrv_co_write_req_finish(child, offset, bytes, req, ret);
1703 1704 1705 1706

    return ret;
}

1707
static int coroutine_fn bdrv_co_do_zero_pwritev(BdrvChild *child,
1708 1709 1710 1711 1712
                                                int64_t offset,
                                                unsigned int bytes,
                                                BdrvRequestFlags flags,
                                                BdrvTrackedRequest *req)
{
1713
    BlockDriverState *bs = child->bs;
1714 1715
    uint8_t *buf = NULL;
    QEMUIOVector local_qiov;
1716
    uint64_t align = bs->bl.request_alignment;
1717 1718 1719 1720
    unsigned int head_padding_bytes, tail_padding_bytes;
    int ret = 0;

    head_padding_bytes = offset & (align - 1);
1721
    tail_padding_bytes = (align - (offset + bytes)) & (align - 1);
1722 1723 1724 1725 1726


    assert(flags & BDRV_REQ_ZERO_WRITE);
    if (head_padding_bytes || tail_padding_bytes) {
        buf = qemu_blockalign(bs, align);
1727
        qemu_iovec_init_buf(&local_qiov, buf, align);
1728 1729 1730 1731 1732 1733 1734
    }
    if (head_padding_bytes) {
        uint64_t zero_bytes = MIN(bytes, align - head_padding_bytes);

        /* RMW the unaligned part before head. */
        mark_request_serialising(req, align);
        wait_serialising_requests(req);
K
Kevin Wolf 已提交
1735
        bdrv_debug_event(bs, BLKDBG_PWRITEV_RMW_HEAD);
1736
        ret = bdrv_aligned_preadv(child, req, offset & ~(align - 1), align,
1737 1738 1739 1740
                                  align, &local_qiov, 0);
        if (ret < 0) {
            goto fail;
        }
K
Kevin Wolf 已提交
1741
        bdrv_debug_event(bs, BLKDBG_PWRITEV_RMW_AFTER_HEAD);
1742 1743

        memset(buf + head_padding_bytes, 0, zero_bytes);
1744
        ret = bdrv_aligned_pwritev(child, req, offset & ~(align - 1), align,
1745
                                   align, &local_qiov,
1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757
                                   flags & ~BDRV_REQ_ZERO_WRITE);
        if (ret < 0) {
            goto fail;
        }
        offset += zero_bytes;
        bytes -= zero_bytes;
    }

    assert(!bytes || (offset & (align - 1)) == 0);
    if (bytes >= align) {
        /* Write the aligned part in the middle. */
        uint64_t aligned_bytes = bytes & ~(align - 1);
1758
        ret = bdrv_aligned_pwritev(child, req, offset, aligned_bytes, align,
1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771 1772
                                   NULL, flags);
        if (ret < 0) {
            goto fail;
        }
        bytes -= aligned_bytes;
        offset += aligned_bytes;
    }

    assert(!bytes || (offset & (align - 1)) == 0);
    if (bytes) {
        assert(align == tail_padding_bytes + bytes);
        /* RMW the unaligned part after tail. */
        mark_request_serialising(req, align);
        wait_serialising_requests(req);
K
Kevin Wolf 已提交
1773
        bdrv_debug_event(bs, BLKDBG_PWRITEV_RMW_TAIL);
1774
        ret = bdrv_aligned_preadv(child, req, offset, align,
1775 1776 1777 1778
                                  align, &local_qiov, 0);
        if (ret < 0) {
            goto fail;
        }
K
Kevin Wolf 已提交
1779
        bdrv_debug_event(bs, BLKDBG_PWRITEV_RMW_AFTER_TAIL);
1780 1781

        memset(buf, 0, bytes);
1782
        ret = bdrv_aligned_pwritev(child, req, offset, align, align,
1783 1784 1785 1786 1787 1788 1789 1790
                                   &local_qiov, flags & ~BDRV_REQ_ZERO_WRITE);
    }
fail:
    qemu_vfree(buf);
    return ret;

}

1791 1792 1793
/*
 * Handle a write request in coroutine context
 */
1794
int coroutine_fn bdrv_co_pwritev(BdrvChild *child,
1795 1796 1797
    int64_t offset, unsigned int bytes, QEMUIOVector *qiov,
    BdrvRequestFlags flags)
{
1798
    BlockDriverState *bs = child->bs;
1799
    BdrvTrackedRequest req;
1800
    uint64_t align = bs->bl.request_alignment;
1801 1802 1803 1804 1805 1806
    uint8_t *head_buf = NULL;
    uint8_t *tail_buf = NULL;
    QEMUIOVector local_qiov;
    bool use_local_qiov = false;
    int ret;

1807 1808
    trace_bdrv_co_pwritev(child->bs, offset, bytes, flags);

1809 1810 1811 1812 1813 1814 1815 1816 1817
    if (!bs->drv) {
        return -ENOMEDIUM;
    }

    ret = bdrv_check_byte_request(bs, offset, bytes);
    if (ret < 0) {
        return ret;
    }

1818
    bdrv_inc_in_flight(bs);
1819 1820 1821 1822 1823
    /*
     * Align write if necessary by performing a read-modify-write cycle.
     * Pad qiov with the read parts and be sure to have a tracked request not
     * only for bdrv_aligned_pwritev, but also for the reads of the RMW cycle.
     */
1824
    tracked_request_begin(&req, bs, offset, bytes, BDRV_TRACKED_WRITE);
1825

1826
    if (flags & BDRV_REQ_ZERO_WRITE) {
1827
        ret = bdrv_co_do_zero_pwritev(child, offset, bytes, flags, &req);
1828 1829 1830
        goto out;
    }

1831 1832 1833 1834 1835 1836 1837
    if (offset & (align - 1)) {
        QEMUIOVector head_qiov;

        mark_request_serialising(&req, align);
        wait_serialising_requests(&req);

        head_buf = qemu_blockalign(bs, align);
1838
        qemu_iovec_init_buf(&head_qiov, head_buf, align);
1839

K
Kevin Wolf 已提交
1840
        bdrv_debug_event(bs, BLKDBG_PWRITEV_RMW_HEAD);
1841
        ret = bdrv_aligned_preadv(child, &req, offset & ~(align - 1), align,
1842 1843 1844 1845
                                  align, &head_qiov, 0);
        if (ret < 0) {
            goto fail;
        }
K
Kevin Wolf 已提交
1846
        bdrv_debug_event(bs, BLKDBG_PWRITEV_RMW_AFTER_HEAD);
1847 1848 1849 1850 1851 1852 1853 1854

        qemu_iovec_init(&local_qiov, qiov->niov + 2);
        qemu_iovec_add(&local_qiov, head_buf, offset & (align - 1));
        qemu_iovec_concat(&local_qiov, qiov, 0, qiov->size);
        use_local_qiov = true;

        bytes += offset & (align - 1);
        offset = offset & ~(align - 1);
1855 1856 1857 1858 1859 1860 1861 1862

        /* We have read the tail already if the request is smaller
         * than one aligned block.
         */
        if (bytes < align) {
            qemu_iovec_add(&local_qiov, head_buf + bytes, align - bytes);
            bytes = align;
        }
1863 1864 1865 1866 1867 1868 1869 1870 1871 1872 1873 1874
    }

    if ((offset + bytes) & (align - 1)) {
        QEMUIOVector tail_qiov;
        size_t tail_bytes;
        bool waited;

        mark_request_serialising(&req, align);
        waited = wait_serialising_requests(&req);
        assert(!waited || !use_local_qiov);

        tail_buf = qemu_blockalign(bs, align);
1875
        qemu_iovec_init_buf(&tail_qiov, tail_buf, align);
1876

K
Kevin Wolf 已提交
1877
        bdrv_debug_event(bs, BLKDBG_PWRITEV_RMW_TAIL);
1878 1879
        ret = bdrv_aligned_preadv(child, &req, (offset + bytes) & ~(align - 1),
                                  align, align, &tail_qiov, 0);
1880 1881 1882
        if (ret < 0) {
            goto fail;
        }
K
Kevin Wolf 已提交
1883
        bdrv_debug_event(bs, BLKDBG_PWRITEV_RMW_AFTER_TAIL);
1884 1885 1886 1887 1888 1889 1890 1891 1892 1893 1894 1895 1896

        if (!use_local_qiov) {
            qemu_iovec_init(&local_qiov, qiov->niov + 1);
            qemu_iovec_concat(&local_qiov, qiov, 0, qiov->size);
            use_local_qiov = true;
        }

        tail_bytes = (offset + bytes) & (align - 1);
        qemu_iovec_add(&local_qiov, tail_buf + tail_bytes, align - tail_bytes);

        bytes = ROUND_UP(bytes, align);
    }

1897
    ret = bdrv_aligned_pwritev(child, &req, offset, bytes, align,
1898 1899
                               use_local_qiov ? &local_qiov : qiov,
                               flags);
1900 1901 1902 1903 1904 1905 1906 1907

fail:

    if (use_local_qiov) {
        qemu_iovec_destroy(&local_qiov);
    }
    qemu_vfree(head_buf);
    qemu_vfree(tail_buf);
1908 1909
out:
    tracked_request_end(&req);
1910
    bdrv_dec_in_flight(bs);
1911 1912 1913
    return ret;
}

1914
int coroutine_fn bdrv_co_pwrite_zeroes(BdrvChild *child, int64_t offset,
1915
                                       int bytes, BdrvRequestFlags flags)
1916
{
1917
    trace_bdrv_co_pwrite_zeroes(child->bs, offset, bytes, flags);
1918

1919
    if (!(child->bs->open_flags & BDRV_O_UNMAP)) {
1920 1921 1922
        flags &= ~BDRV_REQ_MAY_UNMAP;
    }

1923
    return bdrv_co_pwritev(child, offset, bytes, NULL,
1924
                           BDRV_REQ_ZERO_WRITE | flags);
1925 1926
}

J
John Snow 已提交
1927 1928 1929 1930 1931 1932 1933 1934 1935 1936 1937 1938 1939 1940 1941 1942 1943 1944 1945 1946 1947 1948 1949 1950 1951
/*
 * Flush ALL BDSes regardless of if they are reachable via a BlkBackend or not.
 */
int bdrv_flush_all(void)
{
    BdrvNextIterator it;
    BlockDriverState *bs = NULL;
    int result = 0;

    for (bs = bdrv_first(&it); bs; bs = bdrv_next(&it)) {
        AioContext *aio_context = bdrv_get_aio_context(bs);
        int ret;

        aio_context_acquire(aio_context);
        ret = bdrv_flush(bs);
        if (ret < 0 && !result) {
            result = ret;
        }
        aio_context_release(aio_context);
    }

    return result;
}


1952
typedef struct BdrvCoBlockStatusData {
1953 1954
    BlockDriverState *bs;
    BlockDriverState *base;
1955
    bool want_zero;
1956 1957 1958 1959
    int64_t offset;
    int64_t bytes;
    int64_t *pnum;
    int64_t *map;
1960
    BlockDriverState **file;
1961
    int ret;
1962
    bool done;
1963
} BdrvCoBlockStatusData;
1964

1965 1966 1967 1968 1969 1970 1971
int coroutine_fn bdrv_co_block_status_from_file(BlockDriverState *bs,
                                                bool want_zero,
                                                int64_t offset,
                                                int64_t bytes,
                                                int64_t *pnum,
                                                int64_t *map,
                                                BlockDriverState **file)
1972 1973
{
    assert(bs->file && bs->file->bs);
1974 1975
    *pnum = bytes;
    *map = offset;
1976
    *file = bs->file->bs;
1977
    return BDRV_BLOCK_RAW | BDRV_BLOCK_OFFSET_VALID;
1978 1979
}

1980 1981 1982 1983 1984 1985 1986
int coroutine_fn bdrv_co_block_status_from_backing(BlockDriverState *bs,
                                                   bool want_zero,
                                                   int64_t offset,
                                                   int64_t bytes,
                                                   int64_t *pnum,
                                                   int64_t *map,
                                                   BlockDriverState **file)
1987 1988
{
    assert(bs->backing && bs->backing->bs);
1989 1990
    *pnum = bytes;
    *map = offset;
1991
    *file = bs->backing->bs;
1992
    return BDRV_BLOCK_RAW | BDRV_BLOCK_OFFSET_VALID;
1993 1994
}

1995 1996 1997 1998 1999
/*
 * Returns the allocation status of the specified sectors.
 * Drivers not implementing the functionality are assumed to not support
 * backing files, hence all their sectors are reported as allocated.
 *
2000 2001 2002 2003
 * If 'want_zero' is true, the caller is querying for mapping
 * purposes, with a focus on valid BDRV_BLOCK_OFFSET_VALID, _DATA, and
 * _ZERO where possible; otherwise, the result favors larger 'pnum',
 * with a focus on accurate BDRV_BLOCK_ALLOCATED.
2004
 *
2005
 * If 'offset' is beyond the end of the disk image the return value is
2006
 * BDRV_BLOCK_EOF and 'pnum' is set to 0.
2007
 *
2008
 * 'bytes' is the max value 'pnum' should be set to.  If bytes goes
2009 2010
 * beyond the end of the disk image it will be clamped; if 'pnum' is set to
 * the end of the image, then the returned value will include BDRV_BLOCK_EOF.
2011
 *
2012 2013 2014 2015 2016 2017 2018 2019 2020
 * 'pnum' is set to the number of bytes (including and immediately
 * following the specified offset) that are easily known to be in the
 * same allocated/unallocated state.  Note that a second call starting
 * at the original offset plus returned pnum may have the same status.
 * The returned value is non-zero on success except at end-of-file.
 *
 * Returns negative errno on failure.  Otherwise, if the
 * BDRV_BLOCK_OFFSET_VALID bit is set, 'map' and 'file' (if non-NULL) are
 * set to the host mapping and BDS corresponding to the guest offset.
2021
 */
2022 2023 2024 2025 2026 2027 2028 2029
static int coroutine_fn bdrv_co_block_status(BlockDriverState *bs,
                                             bool want_zero,
                                             int64_t offset, int64_t bytes,
                                             int64_t *pnum, int64_t *map,
                                             BlockDriverState **file)
{
    int64_t total_size;
    int64_t n; /* bytes */
E
Eric Blake 已提交
2030
    int ret;
2031
    int64_t local_map = 0;
2032
    BlockDriverState *local_file = NULL;
E
Eric Blake 已提交
2033 2034
    int64_t aligned_offset, aligned_bytes;
    uint32_t align;
2035

2036 2037
    assert(pnum);
    *pnum = 0;
2038 2039 2040
    total_size = bdrv_getlength(bs);
    if (total_size < 0) {
        ret = total_size;
2041
        goto early_out;
2042 2043
    }

2044
    if (offset >= total_size) {
2045 2046
        ret = BDRV_BLOCK_EOF;
        goto early_out;
2047
    }
2048
    if (!bytes) {
2049 2050
        ret = 0;
        goto early_out;
2051
    }
2052

2053 2054 2055
    n = total_size - offset;
    if (n < bytes) {
        bytes = n;
2056 2057
    }

M
Max Reitz 已提交
2058 2059
    /* Must be non-NULL or bdrv_getlength() would have failed */
    assert(bs->drv);
2060
    if (!bs->drv->bdrv_co_block_status) {
2061
        *pnum = bytes;
2062
        ret = BDRV_BLOCK_DATA | BDRV_BLOCK_ALLOCATED;
2063
        if (offset + bytes == total_size) {
2064 2065
            ret |= BDRV_BLOCK_EOF;
        }
2066
        if (bs->drv->protocol_name) {
2067 2068
            ret |= BDRV_BLOCK_OFFSET_VALID;
            local_map = offset;
2069
            local_file = bs;
2070
        }
2071
        goto early_out;
2072 2073
    }

2074
    bdrv_inc_in_flight(bs);
E
Eric Blake 已提交
2075 2076

    /* Round out to request_alignment boundaries */
2077
    align = bs->bl.request_alignment;
E
Eric Blake 已提交
2078 2079 2080
    aligned_offset = QEMU_ALIGN_DOWN(offset, align);
    aligned_bytes = ROUND_UP(offset + bytes, align) - aligned_offset;

2081 2082 2083 2084 2085 2086
    ret = bs->drv->bdrv_co_block_status(bs, want_zero, aligned_offset,
                                        aligned_bytes, pnum, &local_map,
                                        &local_file);
    if (ret < 0) {
        *pnum = 0;
        goto out;
E
Eric Blake 已提交
2087 2088
    }

2089
    /*
2090
     * The driver's result must be a non-zero multiple of request_alignment.
E
Eric Blake 已提交
2091
     * Clamp pnum and adjust map to original request.
2092
     */
2093 2094
    assert(*pnum && QEMU_IS_ALIGNED(*pnum, align) &&
           align > offset - aligned_offset);
E
Eric Blake 已提交
2095 2096 2097
    *pnum -= offset - aligned_offset;
    if (*pnum > bytes) {
        *pnum = bytes;
2098
    }
2099
    if (ret & BDRV_BLOCK_OFFSET_VALID) {
E
Eric Blake 已提交
2100
        local_map += offset - aligned_offset;
2101
    }
2102 2103

    if (ret & BDRV_BLOCK_RAW) {
2104
        assert(ret & BDRV_BLOCK_OFFSET_VALID && local_file);
2105 2106
        ret = bdrv_co_block_status(local_file, want_zero, local_map,
                                   *pnum, pnum, &local_map, &local_file);
2107
        goto out;
2108 2109 2110 2111
    }

    if (ret & (BDRV_BLOCK_DATA | BDRV_BLOCK_ZERO)) {
        ret |= BDRV_BLOCK_ALLOCATED;
2112
    } else if (want_zero) {
2113 2114
        if (bdrv_unallocated_blocks_are_zero(bs)) {
            ret |= BDRV_BLOCK_ZERO;
2115 2116
        } else if (bs->backing) {
            BlockDriverState *bs2 = bs->backing->bs;
2117
            int64_t size2 = bdrv_getlength(bs2);
2118

2119
            if (size2 >= 0 && offset >= size2) {
2120 2121 2122 2123 2124
                ret |= BDRV_BLOCK_ZERO;
            }
        }
    }

2125
    if (want_zero && local_file && local_file != bs &&
2126 2127
        (ret & BDRV_BLOCK_DATA) && !(ret & BDRV_BLOCK_ZERO) &&
        (ret & BDRV_BLOCK_OFFSET_VALID)) {
2128 2129
        int64_t file_pnum;
        int ret2;
2130

2131 2132
        ret2 = bdrv_co_block_status(local_file, want_zero, local_map,
                                    *pnum, &file_pnum, NULL, NULL);
2133 2134 2135 2136
        if (ret2 >= 0) {
            /* Ignore errors.  This is just providing extra information, it
             * is useful but not necessary.
             */
2137 2138 2139 2140 2141 2142 2143
            if (ret2 & BDRV_BLOCK_EOF &&
                (!file_pnum || ret2 & BDRV_BLOCK_ZERO)) {
                /*
                 * It is valid for the format block driver to read
                 * beyond the end of the underlying file's current
                 * size; such areas read as zero.
                 */
2144 2145 2146 2147 2148 2149 2150 2151 2152
                ret |= BDRV_BLOCK_ZERO;
            } else {
                /* Limit request to the range reported by the protocol driver */
                *pnum = file_pnum;
                ret |= (ret2 & BDRV_BLOCK_ZERO);
            }
        }
    }

2153 2154
out:
    bdrv_dec_in_flight(bs);
2155
    if (ret >= 0 && offset + *pnum == total_size) {
2156 2157
        ret |= BDRV_BLOCK_EOF;
    }
2158 2159 2160 2161
early_out:
    if (file) {
        *file = local_file;
    }
2162 2163 2164
    if (map) {
        *map = local_map;
    }
2165 2166 2167
    return ret;
}

2168 2169 2170 2171 2172 2173 2174 2175
static int coroutine_fn bdrv_co_block_status_above(BlockDriverState *bs,
                                                   BlockDriverState *base,
                                                   bool want_zero,
                                                   int64_t offset,
                                                   int64_t bytes,
                                                   int64_t *pnum,
                                                   int64_t *map,
                                                   BlockDriverState **file)
2176 2177
{
    BlockDriverState *p;
2178
    int ret = 0;
2179
    bool first = true;
2180 2181

    assert(bs != base);
2182
    for (p = bs; p != base; p = backing_bs(p)) {
2183 2184
        ret = bdrv_co_block_status(p, want_zero, offset, bytes, pnum, map,
                                   file);
2185 2186 2187 2188 2189 2190 2191 2192 2193 2194
        if (ret < 0) {
            break;
        }
        if (ret & BDRV_BLOCK_ZERO && ret & BDRV_BLOCK_EOF && !first) {
            /*
             * Reading beyond the end of the file continues to read
             * zeroes, but we can only widen the result to the
             * unallocated length we learned from an earlier
             * iteration.
             */
2195
            *pnum = bytes;
2196 2197
        }
        if (ret & (BDRV_BLOCK_ZERO | BDRV_BLOCK_DATA)) {
2198 2199
            break;
        }
2200 2201 2202
        /* [offset, pnum] unallocated on this layer, which could be only
         * the first part of [offset, bytes].  */
        bytes = MIN(bytes, *pnum);
2203
        first = false;
2204 2205 2206 2207
    }
    return ret;
}

2208
/* Coroutine wrapper for bdrv_block_status_above() */
2209
static void coroutine_fn bdrv_block_status_above_co_entry(void *opaque)
2210
{
2211
    BdrvCoBlockStatusData *data = opaque;
2212

2213 2214 2215 2216
    data->ret = bdrv_co_block_status_above(data->bs, data->base,
                                           data->want_zero,
                                           data->offset, data->bytes,
                                           data->pnum, data->map, data->file);
2217
    data->done = true;
2218
    aio_wait_kick();
2219 2220 2221
}

/*
2222
 * Synchronous wrapper around bdrv_co_block_status_above().
2223
 *
2224
 * See bdrv_co_block_status_above() for details.
2225
 */
2226 2227 2228 2229 2230 2231
static int bdrv_common_block_status_above(BlockDriverState *bs,
                                          BlockDriverState *base,
                                          bool want_zero, int64_t offset,
                                          int64_t bytes, int64_t *pnum,
                                          int64_t *map,
                                          BlockDriverState **file)
2232 2233
{
    Coroutine *co;
2234
    BdrvCoBlockStatusData data = {
2235
        .bs = bs,
2236
        .base = base,
2237
        .want_zero = want_zero,
2238 2239 2240 2241
        .offset = offset,
        .bytes = bytes,
        .pnum = pnum,
        .map = map,
2242
        .file = file,
2243 2244 2245 2246 2247
        .done = false,
    };

    if (qemu_in_coroutine()) {
        /* Fast-path if already in coroutine context */
2248
        bdrv_block_status_above_co_entry(&data);
2249
    } else {
2250
        co = qemu_coroutine_create(bdrv_block_status_above_co_entry, &data);
2251
        bdrv_coroutine_enter(bs, co);
P
Paolo Bonzini 已提交
2252
        BDRV_POLL_WHILE(bs, !data.done);
2253
    }
2254
    return data.ret;
2255 2256
}

2257 2258 2259
int bdrv_block_status_above(BlockDriverState *bs, BlockDriverState *base,
                            int64_t offset, int64_t bytes, int64_t *pnum,
                            int64_t *map, BlockDriverState **file)
2260
{
2261 2262
    return bdrv_common_block_status_above(bs, base, true, offset, bytes,
                                          pnum, map, file);
2263 2264
}

2265 2266
int bdrv_block_status(BlockDriverState *bs, int64_t offset, int64_t bytes,
                      int64_t *pnum, int64_t *map, BlockDriverState **file)
2267
{
2268 2269
    return bdrv_block_status_above(bs, backing_bs(bs),
                                   offset, bytes, pnum, map, file);
2270 2271
}

2272 2273
int coroutine_fn bdrv_is_allocated(BlockDriverState *bs, int64_t offset,
                                   int64_t bytes, int64_t *pnum)
2274
{
2275 2276
    int ret;
    int64_t dummy;
2277

2278 2279
    ret = bdrv_common_block_status_above(bs, backing_bs(bs), false, offset,
                                         bytes, pnum ? pnum : &dummy, NULL,
2280
                                         NULL);
2281 2282 2283 2284 2285 2286 2287 2288 2289
    if (ret < 0) {
        return ret;
    }
    return !!(ret & BDRV_BLOCK_ALLOCATED);
}

/*
 * Given an image chain: ... -> [BASE] -> [INTER1] -> [INTER2] -> [TOP]
 *
2290 2291 2292
 * Return true if (a prefix of) the given range is allocated in any image
 * between BASE and TOP (inclusive).  BASE can be NULL to check if the given
 * offset is allocated in any image of the chain.  Return false otherwise,
2293
 * or negative errno on failure.
2294
 *
2295 2296 2297 2298 2299 2300
 * 'pnum' is set to the number of bytes (including and immediately
 * following the specified offset) that are known to be in the same
 * allocated/unallocated state.  Note that a subsequent call starting
 * at 'offset + *pnum' may return the same allocation status (in other
 * words, the result is not necessarily the maximum possible range);
 * but 'pnum' will only be 0 when end of file is reached.
2301 2302 2303 2304
 *
 */
int bdrv_is_allocated_above(BlockDriverState *top,
                            BlockDriverState *base,
2305
                            int64_t offset, int64_t bytes, int64_t *pnum)
2306 2307
{
    BlockDriverState *intermediate;
2308 2309
    int ret;
    int64_t n = bytes;
2310 2311 2312

    intermediate = top;
    while (intermediate && intermediate != base) {
2313
        int64_t pnum_inter;
2314
        int64_t size_inter;
2315

2316
        ret = bdrv_is_allocated(intermediate, offset, bytes, &pnum_inter);
2317 2318
        if (ret < 0) {
            return ret;
2319 2320
        }
        if (ret) {
2321
            *pnum = pnum_inter;
2322 2323 2324
            return 1;
        }

2325
        size_inter = bdrv_getlength(intermediate);
2326 2327 2328
        if (size_inter < 0) {
            return size_inter;
        }
2329 2330 2331
        if (n > pnum_inter &&
            (intermediate == top || offset + pnum_inter < size_inter)) {
            n = pnum_inter;
2332 2333
        }

2334
        intermediate = backing_bs(intermediate);
2335 2336 2337 2338 2339 2340
    }

    *pnum = n;
    return 0;
}

2341 2342 2343 2344 2345 2346 2347 2348 2349 2350 2351 2352 2353
typedef struct BdrvVmstateCo {
    BlockDriverState    *bs;
    QEMUIOVector        *qiov;
    int64_t             pos;
    bool                is_read;
    int                 ret;
} BdrvVmstateCo;

static int coroutine_fn
bdrv_co_rw_vmstate(BlockDriverState *bs, QEMUIOVector *qiov, int64_t pos,
                   bool is_read)
{
    BlockDriver *drv = bs->drv;
2354 2355 2356
    int ret = -ENOTSUP;

    bdrv_inc_in_flight(bs);
2357 2358

    if (!drv) {
2359
        ret = -ENOMEDIUM;
2360
    } else if (drv->bdrv_load_vmstate) {
2361 2362 2363 2364 2365
        if (is_read) {
            ret = drv->bdrv_load_vmstate(bs, qiov, pos);
        } else {
            ret = drv->bdrv_save_vmstate(bs, qiov, pos);
        }
2366
    } else if (bs->file) {
2367
        ret = bdrv_co_rw_vmstate(bs->file->bs, qiov, pos, is_read);
2368 2369
    }

2370 2371
    bdrv_dec_in_flight(bs);
    return ret;
2372 2373 2374 2375 2376 2377
}

static void coroutine_fn bdrv_co_rw_vmstate_entry(void *opaque)
{
    BdrvVmstateCo *co = opaque;
    co->ret = bdrv_co_rw_vmstate(co->bs, co->qiov, co->pos, co->is_read);
2378
    aio_wait_kick();
2379 2380 2381 2382 2383 2384 2385 2386 2387 2388 2389 2390 2391 2392 2393 2394
}

static inline int
bdrv_rw_vmstate(BlockDriverState *bs, QEMUIOVector *qiov, int64_t pos,
                bool is_read)
{
    if (qemu_in_coroutine()) {
        return bdrv_co_rw_vmstate(bs, qiov, pos, is_read);
    } else {
        BdrvVmstateCo data = {
            .bs         = bs,
            .qiov       = qiov,
            .pos        = pos,
            .is_read    = is_read,
            .ret        = -EINPROGRESS,
        };
2395
        Coroutine *co = qemu_coroutine_create(bdrv_co_rw_vmstate_entry, &data);
2396

2397
        bdrv_coroutine_enter(bs, co);
2398
        BDRV_POLL_WHILE(bs, data.ret == -EINPROGRESS);
2399 2400 2401 2402
        return data.ret;
    }
}

2403 2404 2405
int bdrv_save_vmstate(BlockDriverState *bs, const uint8_t *buf,
                      int64_t pos, int size)
{
2406
    QEMUIOVector qiov = QEMU_IOVEC_INIT_BUF(qiov, buf, size);
2407
    int ret;
2408

2409 2410 2411 2412 2413 2414
    ret = bdrv_writev_vmstate(bs, &qiov, pos);
    if (ret < 0) {
        return ret;
    }

    return size;
2415 2416 2417 2418
}

int bdrv_writev_vmstate(BlockDriverState *bs, QEMUIOVector *qiov, int64_t pos)
{
2419
    return bdrv_rw_vmstate(bs, qiov, pos, false);
2420 2421 2422 2423
}

int bdrv_load_vmstate(BlockDriverState *bs, uint8_t *buf,
                      int64_t pos, int size)
2424
{
2425
    QEMUIOVector qiov = QEMU_IOVEC_INIT_BUF(qiov, buf, size);
2426
    int ret;
2427

2428 2429 2430 2431 2432 2433
    ret = bdrv_readv_vmstate(bs, &qiov, pos);
    if (ret < 0) {
        return ret;
    }

    return size;
2434 2435 2436
}

int bdrv_readv_vmstate(BlockDriverState *bs, QEMUIOVector *qiov, int64_t pos)
2437
{
2438
    return bdrv_rw_vmstate(bs, qiov, pos, true);
2439 2440 2441 2442 2443 2444 2445 2446 2447 2448 2449 2450 2451
}

/**************************************************************/
/* async I/Os */

void bdrv_aio_cancel(BlockAIOCB *acb)
{
    qemu_aio_ref(acb);
    bdrv_aio_cancel_async(acb);
    while (acb->refcnt > 1) {
        if (acb->aiocb_info->get_aio_context) {
            aio_poll(acb->aiocb_info->get_aio_context(acb), true);
        } else if (acb->bs) {
2452 2453 2454 2455 2456
            /* qemu_aio_ref and qemu_aio_unref are not thread-safe, so
             * assert that we're not using an I/O thread.  Thread-safe
             * code should use bdrv_aio_cancel_async exclusively.
             */
            assert(bdrv_get_aio_context(acb->bs) == qemu_get_aio_context());
2457 2458 2459 2460 2461 2462 2463 2464 2465 2466 2467 2468 2469 2470 2471 2472 2473 2474 2475 2476 2477
            aio_poll(bdrv_get_aio_context(acb->bs), true);
        } else {
            abort();
        }
    }
    qemu_aio_unref(acb);
}

/* Async version of aio cancel. The caller is not blocked if the acb implements
 * cancel_async, otherwise we do nothing and let the request normally complete.
 * In either case the completion callback must be called. */
void bdrv_aio_cancel_async(BlockAIOCB *acb)
{
    if (acb->aiocb_info->cancel_async) {
        acb->aiocb_info->cancel_async(acb);
    }
}

/**************************************************************/
/* Coroutine block device emulation */

2478 2479 2480 2481 2482 2483
typedef struct FlushCo {
    BlockDriverState *bs;
    int ret;
} FlushCo;


2484 2485
static void coroutine_fn bdrv_flush_co_entry(void *opaque)
{
2486
    FlushCo *rwco = opaque;
2487 2488

    rwco->ret = bdrv_co_flush(rwco->bs);
2489
    aio_wait_kick();
2490 2491 2492 2493
}

int coroutine_fn bdrv_co_flush(BlockDriverState *bs)
{
2494 2495 2496 2497
    int current_gen;
    int ret = 0;

    bdrv_inc_in_flight(bs);
2498

2499
    if (!bdrv_is_inserted(bs) || bdrv_is_read_only(bs) ||
2500
        bdrv_is_sg(bs)) {
2501
        goto early_exit;
2502 2503
    }

2504
    qemu_co_mutex_lock(&bs->reqs_lock);
2505
    current_gen = atomic_read(&bs->write_gen);
2506 2507

    /* Wait until any previous flushes are completed */
2508
    while (bs->active_flush_req) {
2509
        qemu_co_queue_wait(&bs->flush_queue, &bs->reqs_lock);
2510 2511
    }

2512
    /* Flushes reach this point in nondecreasing current_gen order.  */
2513
    bs->active_flush_req = true;
2514
    qemu_co_mutex_unlock(&bs->reqs_lock);
2515

P
Pavel Dovgalyuk 已提交
2516 2517 2518 2519 2520 2521
    /* Write back all layers by calling one driver function */
    if (bs->drv->bdrv_co_flush) {
        ret = bs->drv->bdrv_co_flush(bs);
        goto out;
    }

2522 2523 2524 2525 2526
    /* Write back cached data to the OS even with cache=unsafe */
    BLKDBG_EVENT(bs->file, BLKDBG_FLUSH_TO_OS);
    if (bs->drv->bdrv_co_flush_to_os) {
        ret = bs->drv->bdrv_co_flush_to_os(bs);
        if (ret < 0) {
F
Fam Zheng 已提交
2527
            goto out;
2528 2529 2530 2531 2532 2533 2534 2535
        }
    }

    /* But don't actually force it to the disk with cache=unsafe */
    if (bs->open_flags & BDRV_O_NO_FLUSH) {
        goto flush_parent;
    }

2536 2537 2538 2539 2540
    /* Check if we really need to flush anything */
    if (bs->flushed_gen == current_gen) {
        goto flush_parent;
    }

2541
    BLKDBG_EVENT(bs->file, BLKDBG_FLUSH_TO_DISK);
M
Max Reitz 已提交
2542 2543 2544 2545 2546 2547
    if (!bs->drv) {
        /* bs->drv->bdrv_co_flush() might have ejected the BDS
         * (even in case of apparent success) */
        ret = -ENOMEDIUM;
        goto out;
    }
2548 2549 2550 2551 2552 2553 2554 2555 2556 2557 2558 2559 2560 2561 2562 2563 2564 2565 2566 2567 2568 2569 2570 2571 2572 2573 2574 2575 2576
    if (bs->drv->bdrv_co_flush_to_disk) {
        ret = bs->drv->bdrv_co_flush_to_disk(bs);
    } else if (bs->drv->bdrv_aio_flush) {
        BlockAIOCB *acb;
        CoroutineIOCompletion co = {
            .coroutine = qemu_coroutine_self(),
        };

        acb = bs->drv->bdrv_aio_flush(bs, bdrv_co_io_em_complete, &co);
        if (acb == NULL) {
            ret = -EIO;
        } else {
            qemu_coroutine_yield();
            ret = co.ret;
        }
    } else {
        /*
         * Some block drivers always operate in either writethrough or unsafe
         * mode and don't support bdrv_flush therefore. Usually qemu doesn't
         * know how the server works (because the behaviour is hardcoded or
         * depends on server-side configuration), so we can't ensure that
         * everything is safe on disk. Returning an error doesn't work because
         * that would break guests even if the server operates in writethrough
         * mode.
         *
         * Let's hope the user knows what he's doing.
         */
        ret = 0;
    }
2577

2578
    if (ret < 0) {
F
Fam Zheng 已提交
2579
        goto out;
2580 2581 2582 2583 2584 2585
    }

    /* Now flush the underlying protocol.  It will also have BDRV_O_NO_FLUSH
     * in the case of cache=unsafe, so there are no useless flushes.
     */
flush_parent:
F
Fam Zheng 已提交
2586 2587
    ret = bs->file ? bdrv_co_flush(bs->file->bs) : 0;
out:
2588
    /* Notify any pending flushes that we have completed */
2589 2590 2591
    if (ret == 0) {
        bs->flushed_gen = current_gen;
    }
2592 2593

    qemu_co_mutex_lock(&bs->reqs_lock);
2594
    bs->active_flush_req = false;
2595 2596
    /* Return value is ignored - it's ok if wait queue is empty */
    qemu_co_queue_next(&bs->flush_queue);
2597
    qemu_co_mutex_unlock(&bs->reqs_lock);
2598

2599
early_exit:
2600
    bdrv_dec_in_flight(bs);
F
Fam Zheng 已提交
2601
    return ret;
2602 2603 2604 2605 2606
}

int bdrv_flush(BlockDriverState *bs)
{
    Coroutine *co;
2607
    FlushCo flush_co = {
2608 2609 2610 2611 2612 2613
        .bs = bs,
        .ret = NOT_DONE,
    };

    if (qemu_in_coroutine()) {
        /* Fast-path if already in coroutine context */
2614
        bdrv_flush_co_entry(&flush_co);
2615
    } else {
2616
        co = qemu_coroutine_create(bdrv_flush_co_entry, &flush_co);
2617
        bdrv_coroutine_enter(bs, co);
P
Paolo Bonzini 已提交
2618
        BDRV_POLL_WHILE(bs, flush_co.ret == NOT_DONE);
2619 2620
    }

2621
    return flush_co.ret;
2622 2623 2624
}

typedef struct DiscardCo {
F
Fam Zheng 已提交
2625
    BdrvChild *child;
2626
    int64_t offset;
2627
    int bytes;
2628 2629
    int ret;
} DiscardCo;
2630
static void coroutine_fn bdrv_pdiscard_co_entry(void *opaque)
2631 2632 2633
{
    DiscardCo *rwco = opaque;

F
Fam Zheng 已提交
2634
    rwco->ret = bdrv_co_pdiscard(rwco->child, rwco->offset, rwco->bytes);
2635
    aio_wait_kick();
2636 2637
}

F
Fam Zheng 已提交
2638
int coroutine_fn bdrv_co_pdiscard(BdrvChild *child, int64_t offset, int bytes)
2639
{
F
Fam Zheng 已提交
2640
    BdrvTrackedRequest req;
2641
    int max_pdiscard, ret;
2642
    int head, tail, align;
F
Fam Zheng 已提交
2643
    BlockDriverState *bs = child->bs;
2644

F
Fam Zheng 已提交
2645
    if (!bs || !bs->drv) {
2646 2647 2648
        return -ENOMEDIUM;
    }

2649 2650 2651 2652
    if (bdrv_has_readonly_bitmaps(bs)) {
        return -EPERM;
    }

2653
    ret = bdrv_check_byte_request(bs, offset, bytes);
2654 2655 2656 2657 2658 2659 2660 2661 2662
    if (ret < 0) {
        return ret;
    }

    /* Do nothing if disabled.  */
    if (!(bs->open_flags & BDRV_O_UNMAP)) {
        return 0;
    }

E
Eric Blake 已提交
2663
    if (!bs->drv->bdrv_co_pdiscard && !bs->drv->bdrv_aio_pdiscard) {
2664 2665 2666
        return 0;
    }

2667 2668 2669 2670 2671
    /* Discard is advisory, but some devices track and coalesce
     * unaligned requests, so we must pass everything down rather than
     * round here.  Still, most devices will just silently ignore
     * unaligned requests (by returning -ENOTSUP), so we must fragment
     * the request accordingly.  */
E
Eric Blake 已提交
2672
    align = MAX(bs->bl.pdiscard_alignment, bs->bl.request_alignment);
2673 2674
    assert(align % bs->bl.request_alignment == 0);
    head = offset % align;
2675
    tail = (offset + bytes) % align;
2676

2677
    bdrv_inc_in_flight(bs);
2678
    tracked_request_begin(&req, bs, offset, bytes, BDRV_TRACKED_DISCARD);
2679

2680
    ret = bdrv_co_write_req_prepare(child, offset, bytes, &req, 0);
2681 2682 2683 2684
    if (ret < 0) {
        goto out;
    }

2685 2686
    max_pdiscard = QEMU_ALIGN_DOWN(MIN_NON_ZERO(bs->bl.max_pdiscard, INT_MAX),
                                   align);
2687
    assert(max_pdiscard >= bs->bl.request_alignment);
2688

2689 2690
    while (bytes > 0) {
        int num = bytes;
2691 2692 2693

        if (head) {
            /* Make small requests to get to alignment boundaries. */
2694
            num = MIN(bytes, align - head);
2695 2696 2697 2698 2699 2700 2701 2702 2703 2704 2705 2706 2707 2708 2709 2710 2711 2712 2713
            if (!QEMU_IS_ALIGNED(num, bs->bl.request_alignment)) {
                num %= bs->bl.request_alignment;
            }
            head = (head + num) % align;
            assert(num < max_pdiscard);
        } else if (tail) {
            if (num > align) {
                /* Shorten the request to the last aligned cluster.  */
                num -= tail;
            } else if (!QEMU_IS_ALIGNED(tail, bs->bl.request_alignment) &&
                       tail > bs->bl.request_alignment) {
                tail %= bs->bl.request_alignment;
                num -= tail;
            }
        }
        /* limit request size */
        if (num > max_pdiscard) {
            num = max_pdiscard;
        }
2714

M
Max Reitz 已提交
2715 2716 2717 2718
        if (!bs->drv) {
            ret = -ENOMEDIUM;
            goto out;
        }
2719 2720
        if (bs->drv->bdrv_co_pdiscard) {
            ret = bs->drv->bdrv_co_pdiscard(bs, offset, num);
2721 2722 2723 2724 2725 2726
        } else {
            BlockAIOCB *acb;
            CoroutineIOCompletion co = {
                .coroutine = qemu_coroutine_self(),
            };

2727 2728
            acb = bs->drv->bdrv_aio_pdiscard(bs, offset, num,
                                             bdrv_co_io_em_complete, &co);
2729
            if (acb == NULL) {
F
Fam Zheng 已提交
2730 2731
                ret = -EIO;
                goto out;
2732 2733 2734 2735 2736 2737
            } else {
                qemu_coroutine_yield();
                ret = co.ret;
            }
        }
        if (ret && ret != -ENOTSUP) {
F
Fam Zheng 已提交
2738
            goto out;
2739 2740
        }

2741
        offset += num;
2742
        bytes -= num;
2743
    }
F
Fam Zheng 已提交
2744 2745
    ret = 0;
out:
2746
    bdrv_co_write_req_finish(child, req.offset, req.bytes, &req, ret);
F
Fam Zheng 已提交
2747
    tracked_request_end(&req);
2748
    bdrv_dec_in_flight(bs);
F
Fam Zheng 已提交
2749
    return ret;
2750 2751
}

F
Fam Zheng 已提交
2752
int bdrv_pdiscard(BdrvChild *child, int64_t offset, int bytes)
2753 2754 2755
{
    Coroutine *co;
    DiscardCo rwco = {
F
Fam Zheng 已提交
2756
        .child = child,
2757
        .offset = offset,
2758
        .bytes = bytes,
2759 2760 2761 2762 2763
        .ret = NOT_DONE,
    };

    if (qemu_in_coroutine()) {
        /* Fast-path if already in coroutine context */
2764
        bdrv_pdiscard_co_entry(&rwco);
2765
    } else {
2766
        co = qemu_coroutine_create(bdrv_pdiscard_co_entry, &rwco);
F
Fam Zheng 已提交
2767 2768
        bdrv_coroutine_enter(child->bs, co);
        BDRV_POLL_WHILE(child->bs, rwco.ret == NOT_DONE);
2769 2770 2771 2772 2773
    }

    return rwco.ret;
}

2774
int bdrv_co_ioctl(BlockDriverState *bs, int req, void *buf)
2775 2776
{
    BlockDriver *drv = bs->drv;
2777 2778 2779 2780
    CoroutineIOCompletion co = {
        .coroutine = qemu_coroutine_self(),
    };
    BlockAIOCB *acb;
2781

2782
    bdrv_inc_in_flight(bs);
2783
    if (!drv || (!drv->bdrv_aio_ioctl && !drv->bdrv_co_ioctl)) {
2784 2785 2786 2787
        co.ret = -ENOTSUP;
        goto out;
    }

2788 2789 2790 2791 2792 2793 2794 2795 2796
    if (drv->bdrv_co_ioctl) {
        co.ret = drv->bdrv_co_ioctl(bs, req, buf);
    } else {
        acb = drv->bdrv_aio_ioctl(bs, req, buf, bdrv_co_io_em_complete, &co);
        if (!acb) {
            co.ret = -ENOTSUP;
            goto out;
        }
        qemu_coroutine_yield();
2797 2798
    }
out:
2799
    bdrv_dec_in_flight(bs);
2800 2801 2802
    return co.ret;
}

2803 2804 2805 2806 2807 2808 2809 2810 2811 2812 2813 2814 2815 2816 2817 2818 2819 2820 2821 2822 2823 2824 2825 2826 2827 2828 2829 2830 2831 2832 2833 2834 2835 2836 2837 2838 2839 2840 2841 2842
void *qemu_blockalign(BlockDriverState *bs, size_t size)
{
    return qemu_memalign(bdrv_opt_mem_align(bs), size);
}

void *qemu_blockalign0(BlockDriverState *bs, size_t size)
{
    return memset(qemu_blockalign(bs, size), 0, size);
}

void *qemu_try_blockalign(BlockDriverState *bs, size_t size)
{
    size_t align = bdrv_opt_mem_align(bs);

    /* Ensure that NULL is never returned on success */
    assert(align > 0);
    if (size == 0) {
        size = align;
    }

    return qemu_try_memalign(align, size);
}

void *qemu_try_blockalign0(BlockDriverState *bs, size_t size)
{
    void *mem = qemu_try_blockalign(bs, size);

    if (mem) {
        memset(mem, 0, size);
    }

    return mem;
}

/*
 * Check if all memory in this vector is sector aligned.
 */
bool bdrv_qiov_is_aligned(BlockDriverState *bs, QEMUIOVector *qiov)
{
    int i;
2843
    size_t alignment = bdrv_min_mem_align(bs);
2844 2845 2846 2847 2848 2849 2850 2851 2852 2853 2854 2855 2856 2857 2858 2859 2860 2861 2862 2863 2864

    for (i = 0; i < qiov->niov; i++) {
        if ((uintptr_t) qiov->iov[i].iov_base % alignment) {
            return false;
        }
        if (qiov->iov[i].iov_len % alignment) {
            return false;
        }
    }

    return true;
}

void bdrv_add_before_write_notifier(BlockDriverState *bs,
                                    NotifierWithReturn *notifier)
{
    notifier_with_return_list_add(&bs->before_write_notifiers, notifier);
}

void bdrv_io_plug(BlockDriverState *bs)
{
2865 2866 2867 2868 2869 2870
    BdrvChild *child;

    QLIST_FOREACH(child, &bs->children, next) {
        bdrv_io_plug(child->bs);
    }

2871
    if (atomic_fetch_inc(&bs->io_plugged) == 0) {
2872 2873 2874 2875
        BlockDriver *drv = bs->drv;
        if (drv && drv->bdrv_io_plug) {
            drv->bdrv_io_plug(bs);
        }
2876 2877 2878 2879 2880
    }
}

void bdrv_io_unplug(BlockDriverState *bs)
{
2881 2882 2883
    BdrvChild *child;

    assert(bs->io_plugged);
2884
    if (atomic_fetch_dec(&bs->io_plugged) == 1) {
2885 2886 2887 2888 2889 2890 2891 2892
        BlockDriver *drv = bs->drv;
        if (drv && drv->bdrv_io_unplug) {
            drv->bdrv_io_unplug(bs);
        }
    }

    QLIST_FOREACH(child, &bs->children, next) {
        bdrv_io_unplug(child->bs);
2893 2894
    }
}
F
Fam Zheng 已提交
2895 2896 2897 2898 2899 2900 2901 2902 2903 2904 2905 2906 2907 2908 2909 2910 2911 2912 2913 2914 2915 2916 2917 2918

void bdrv_register_buf(BlockDriverState *bs, void *host, size_t size)
{
    BdrvChild *child;

    if (bs->drv && bs->drv->bdrv_register_buf) {
        bs->drv->bdrv_register_buf(bs, host, size);
    }
    QLIST_FOREACH(child, &bs->children, next) {
        bdrv_register_buf(child->bs, host, size);
    }
}

void bdrv_unregister_buf(BlockDriverState *bs, void *host)
{
    BdrvChild *child;

    if (bs->drv && bs->drv->bdrv_unregister_buf) {
        bs->drv->bdrv_unregister_buf(bs, host);
    }
    QLIST_FOREACH(child, &bs->children, next) {
        bdrv_unregister_buf(child->bs, host);
    }
}
2919

2920 2921 2922 2923 2924
static int coroutine_fn bdrv_co_copy_range_internal(
        BdrvChild *src, uint64_t src_offset, BdrvChild *dst,
        uint64_t dst_offset, uint64_t bytes,
        BdrvRequestFlags read_flags, BdrvRequestFlags write_flags,
        bool recurse_src)
2925
{
2926
    BdrvTrackedRequest req;
2927 2928
    int ret;

K
Kevin Wolf 已提交
2929 2930 2931 2932
    /* TODO We can support BDRV_REQ_NO_FALLBACK here */
    assert(!(read_flags & BDRV_REQ_NO_FALLBACK));
    assert(!(write_flags & BDRV_REQ_NO_FALLBACK));

2933
    if (!dst || !dst->bs) {
2934 2935 2936 2937 2938 2939
        return -ENOMEDIUM;
    }
    ret = bdrv_check_byte_request(dst->bs, dst_offset, bytes);
    if (ret) {
        return ret;
    }
2940 2941
    if (write_flags & BDRV_REQ_ZERO_WRITE) {
        return bdrv_co_pwrite_zeroes(dst, dst_offset, bytes, write_flags);
2942 2943
    }

2944 2945 2946 2947 2948 2949 2950 2951
    if (!src || !src->bs) {
        return -ENOMEDIUM;
    }
    ret = bdrv_check_byte_request(src->bs, src_offset, bytes);
    if (ret) {
        return ret;
    }

2952 2953 2954 2955 2956
    if (!src->bs->drv->bdrv_co_copy_range_from
        || !dst->bs->drv->bdrv_co_copy_range_to
        || src->bs->encrypted || dst->bs->encrypted) {
        return -ENOTSUP;
    }
2957

2958
    if (recurse_src) {
2959 2960 2961 2962
        bdrv_inc_in_flight(src->bs);
        tracked_request_begin(&req, src->bs, src_offset, bytes,
                              BDRV_TRACKED_READ);

2963 2964
        /* BDRV_REQ_SERIALISING is only for write operation */
        assert(!(read_flags & BDRV_REQ_SERIALISING));
2965
        if (!(read_flags & BDRV_REQ_NO_SERIALISING)) {
2966 2967 2968
            wait_serialising_requests(&req);
        }

2969 2970 2971
        ret = src->bs->drv->bdrv_co_copy_range_from(src->bs,
                                                    src, src_offset,
                                                    dst, dst_offset,
2972 2973
                                                    bytes,
                                                    read_flags, write_flags);
2974 2975 2976

        tracked_request_end(&req);
        bdrv_dec_in_flight(src->bs);
2977
    } else {
2978 2979 2980
        bdrv_inc_in_flight(dst->bs);
        tracked_request_begin(&req, dst->bs, dst_offset, bytes,
                              BDRV_TRACKED_WRITE);
2981 2982 2983 2984 2985 2986 2987 2988 2989 2990
        ret = bdrv_co_write_req_prepare(dst, dst_offset, bytes, &req,
                                        write_flags);
        if (!ret) {
            ret = dst->bs->drv->bdrv_co_copy_range_to(dst->bs,
                                                      src, src_offset,
                                                      dst, dst_offset,
                                                      bytes,
                                                      read_flags, write_flags);
        }
        bdrv_co_write_req_finish(dst, dst_offset, bytes, &req, ret);
2991 2992
        tracked_request_end(&req);
        bdrv_dec_in_flight(dst->bs);
2993
    }
2994

2995
    return ret;
2996 2997 2998 2999 3000 3001 3002 3003
}

/* Copy range from @src to @dst.
 *
 * See the comment of bdrv_co_copy_range for the parameter and return value
 * semantics. */
int coroutine_fn bdrv_co_copy_range_from(BdrvChild *src, uint64_t src_offset,
                                         BdrvChild *dst, uint64_t dst_offset,
3004 3005 3006
                                         uint64_t bytes,
                                         BdrvRequestFlags read_flags,
                                         BdrvRequestFlags write_flags)
3007
{
3008 3009
    trace_bdrv_co_copy_range_from(src, src_offset, dst, dst_offset, bytes,
                                  read_flags, write_flags);
3010
    return bdrv_co_copy_range_internal(src, src_offset, dst, dst_offset,
3011
                                       bytes, read_flags, write_flags, true);
3012 3013 3014 3015 3016 3017 3018 3019
}

/* Copy range from @src to @dst.
 *
 * See the comment of bdrv_co_copy_range for the parameter and return value
 * semantics. */
int coroutine_fn bdrv_co_copy_range_to(BdrvChild *src, uint64_t src_offset,
                                       BdrvChild *dst, uint64_t dst_offset,
3020 3021 3022
                                       uint64_t bytes,
                                       BdrvRequestFlags read_flags,
                                       BdrvRequestFlags write_flags)
3023
{
3024 3025
    trace_bdrv_co_copy_range_to(src, src_offset, dst, dst_offset, bytes,
                                read_flags, write_flags);
3026
    return bdrv_co_copy_range_internal(src, src_offset, dst, dst_offset,
3027
                                       bytes, read_flags, write_flags, false);
3028 3029 3030 3031
}

int coroutine_fn bdrv_co_copy_range(BdrvChild *src, uint64_t src_offset,
                                    BdrvChild *dst, uint64_t dst_offset,
3032 3033
                                    uint64_t bytes, BdrvRequestFlags read_flags,
                                    BdrvRequestFlags write_flags)
3034
{
3035 3036
    return bdrv_co_copy_range_from(src, src_offset,
                                   dst, dst_offset,
3037
                                   bytes, read_flags, write_flags);
3038
}
3039 3040 3041 3042 3043 3044 3045 3046 3047 3048 3049 3050 3051 3052 3053 3054 3055 3056 3057

static void bdrv_parent_cb_resize(BlockDriverState *bs)
{
    BdrvChild *c;
    QLIST_FOREACH(c, &bs->parents, next_parent) {
        if (c->role->resize) {
            c->role->resize(c);
        }
    }
}

/**
 * Truncate file to 'offset' bytes (needed only for file protocols)
 */
int coroutine_fn bdrv_co_truncate(BdrvChild *child, int64_t offset,
                                  PreallocMode prealloc, Error **errp)
{
    BlockDriverState *bs = child->bs;
    BlockDriver *drv = bs->drv;
3058 3059
    BdrvTrackedRequest req;
    int64_t old_size, new_bytes;
3060 3061 3062 3063 3064 3065 3066 3067 3068 3069 3070 3071 3072
    int ret;


    /* if bs->drv == NULL, bs is closed, so there's nothing to do here */
    if (!drv) {
        error_setg(errp, "No medium inserted");
        return -ENOMEDIUM;
    }
    if (offset < 0) {
        error_setg(errp, "Image size cannot be negative");
        return -EINVAL;
    }

3073 3074 3075 3076 3077 3078 3079 3080 3081 3082 3083 3084
    old_size = bdrv_getlength(bs);
    if (old_size < 0) {
        error_setg_errno(errp, -old_size, "Failed to get old image size");
        return old_size;
    }

    if (offset > old_size) {
        new_bytes = offset - old_size;
    } else {
        new_bytes = 0;
    }

3085
    bdrv_inc_in_flight(bs);
3086 3087
    tracked_request_begin(&req, bs, offset - new_bytes, new_bytes,
                          BDRV_TRACKED_TRUNCATE);
3088 3089 3090 3091 3092 3093

    /* If we are growing the image and potentially using preallocation for the
     * new area, we need to make sure that no write requests are made to it
     * concurrently or they might be overwritten by preallocation. */
    if (new_bytes) {
        mark_request_serialising(&req, 1);
3094 3095 3096 3097 3098 3099 3100 3101 3102 3103 3104 3105
    }
    if (bs->read_only) {
        error_setg(errp, "Image is read-only");
        ret = -EACCES;
        goto out;
    }
    ret = bdrv_co_write_req_prepare(child, offset - new_bytes, new_bytes, &req,
                                    0);
    if (ret < 0) {
        error_setg_errno(errp, -ret,
                         "Failed to prepare request for truncation");
        goto out;
3106
    }
3107 3108 3109 3110 3111 3112 3113 3114 3115 3116 3117 3118 3119 3120 3121 3122 3123 3124 3125 3126 3127

    if (!drv->bdrv_co_truncate) {
        if (bs->file && drv->is_filter) {
            ret = bdrv_co_truncate(bs->file, offset, prealloc, errp);
            goto out;
        }
        error_setg(errp, "Image format driver does not support resize");
        ret = -ENOTSUP;
        goto out;
    }

    ret = drv->bdrv_co_truncate(bs, offset, prealloc, errp);
    if (ret < 0) {
        goto out;
    }
    ret = refresh_total_sectors(bs, offset >> BDRV_SECTOR_BITS);
    if (ret < 0) {
        error_setg_errno(errp, -ret, "Could not refresh total sector count");
    } else {
        offset = bs->total_sectors * BDRV_SECTOR_SIZE;
    }
3128 3129 3130 3131
    /* It's possible that truncation succeeded but refresh_total_sectors
     * failed, but the latter doesn't affect how we should finish the request.
     * Pass 0 as the last parameter so that dirty bitmaps etc. are handled. */
    bdrv_co_write_req_finish(child, offset - new_bytes, new_bytes, &req, 0);
3132 3133

out:
3134
    tracked_request_end(&req);
3135
    bdrv_dec_in_flight(bs);
3136

3137 3138 3139 3140 3141 3142 3143 3144 3145 3146 3147 3148 3149 3150 3151 3152
    return ret;
}

typedef struct TruncateCo {
    BdrvChild *child;
    int64_t offset;
    PreallocMode prealloc;
    Error **errp;
    int ret;
} TruncateCo;

static void coroutine_fn bdrv_truncate_co_entry(void *opaque)
{
    TruncateCo *tco = opaque;
    tco->ret = bdrv_co_truncate(tco->child, tco->offset, tco->prealloc,
                                tco->errp);
3153
    aio_wait_kick();
3154 3155 3156 3157 3158 3159 3160 3161 3162 3163 3164 3165 3166 3167 3168 3169 3170 3171 3172
}

int bdrv_truncate(BdrvChild *child, int64_t offset, PreallocMode prealloc,
                  Error **errp)
{
    Coroutine *co;
    TruncateCo tco = {
        .child      = child,
        .offset     = offset,
        .prealloc   = prealloc,
        .errp       = errp,
        .ret        = NOT_DONE,
    };

    if (qemu_in_coroutine()) {
        /* Fast-path if already in coroutine context */
        bdrv_truncate_co_entry(&tco);
    } else {
        co = qemu_coroutine_create(bdrv_truncate_co_entry, &tco);
3173
        bdrv_coroutine_enter(child->bs, co);
3174 3175 3176 3177 3178
        BDRV_POLL_WHILE(child->bs, tco.ret == NOT_DONE);
    }

    return tco.ret;
}