]> xenbits.xensource.com Git - libvirt.git/log
libvirt.git
6 years agocpu: add 'amd-ssbd' and 'amd-no-ssb' CPU features (CVE-2018-3639)
Daniel P. Berrangé [Thu, 14 Jun 2018 10:12:59 +0000 (11:12 +0100)]
cpu: add 'amd-ssbd' and 'amd-no-ssb' CPU features (CVE-2018-3639)

AMD x86 CPUs have two separate ways to mitigate the Speculative Store
Bypass hardware flaw. In current processors only non-architectural MSRs
are available, and so hypervisors must expose a virtualized MSR and CPU
flag "virt-ssbd" (CPUID Function 8000_0008, EBX[25]=1).

In future processors AMD will provide an architectural MSR, indicated by
existance of the CPUID Function 8000_0008, EBX[24]=1, to which QEMU has
given the name "amd-ssbd".

The "amd-ssbd" flag should be used in preference to "virt-ssbd", if it
is available, since it provides improved performance. For virtual
machine configuration, both should be exposed when available, to allow
for maximal guest OS compatibility as not all guests yet support both.

If future processes are not vulnerable to the flaw, this will be
indicated by the existance of CPUID Function 8000_0008, EBX[26]=1,
to which QEMU has given the name "amd-no-ssb".

See also 124441_AMD64_SpeculativeStoreBypassDisable_Whitepaper_final.pdf
from:

  https://bugzilla.kernel.org/show_bug.cgi?id=199889

Note that neither amd-ssbd or amd-no-ssb will be reported by the kernel
in /proc/cpuinfo. It knows about these CPUID bits and does the right thing,
but doesn't report their existance as distinct flags in /proc/cpuinfo.

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agorpm: add new nwfilter RNGs to mingw-libvirt spec file
Daniel P. Berrangé [Tue, 3 Jul 2018 15:32:08 +0000 (16:32 +0100)]
rpm: add new nwfilter RNGs to mingw-libvirt spec file

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoqemu: format serial and geometry on frontend disk device
Daniel P. Berrangé [Mon, 25 Jun 2018 09:24:12 +0000 (10:24 +0100)]
qemu: format serial and geometry on frontend disk device

Currently we format the serial, geometry and error policy on the -drive
backend argument.

QEMU added the ability to set serial and geometry on the frontend in
the 1.2 release deprecating use of -drive, with support being deleted
from -drive in 3.0.

We keep formatting error policy on -drive for now, because we don't
ahve support for that with -device for usb-storage just yet.

Note that some disk buses (sd) still don't support -device. Although
QEMU allowed these properties to be set on -drive for if=sd, they
have been ignored so we now report an error in this case.

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoqemu: hotplug: Don't access srcPriv when it's not allocated
Peter Krempa [Tue, 3 Jul 2018 08:45:34 +0000 (10:45 +0200)]
qemu: hotplug: Don't access srcPriv when it's not allocated

The private data of a virStorageSource which is backing an iSCSI hostdev
may be NULL if no authentication is present. The code handling the
hotplug would attempt to extract the authentication info stored in
'secinfo' without checking if it is allocated which resulted in a crash.

Here we opt the easy way to check if srcPriv is not NULL so that we
don't duplicate all the logic which selects whether the disk source has
a secret.

Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1597550

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agoqemu: Remove unused bypassSecurityDriver from qemuOpenFileAs
Michal Privoznik [Tue, 3 Jul 2018 05:52:13 +0000 (07:52 +0200)]
qemu: Remove unused bypassSecurityDriver from qemuOpenFileAs

This argument is not used anymore. The only function that is
passing non-NULL (qemuDomainSaveMemory) does not actually care
for the value (after 23087cfdb) and every other caller just
passes NULL anyway.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agoesx_driver: Use virCheckFlag macro
Marcos Paulo de Souza [Tue, 3 Jul 2018 02:21:00 +0000 (23:21 -0300)]
esx_driver: Use virCheckFlag macro

Instead of duplicating code to do the same checking. Now all functions
of virHypervisorDriver from esx driver are using this macro.

Signed-off-by: Marcos Paulo de Souza <marcos.souza.org@gmail.com>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
6 years agoesx_vi.c: Simplify error handling in MachineByName
Marcos Paulo de Souza [Tue, 3 Jul 2018 02:20:58 +0000 (23:20 -0300)]
esx_vi.c: Simplify error handling in MachineByName

The same pattern is used in lots of other places.
Also, reporting error message is not desired because all callers
check the return value and report errors on their own.

Signed-off-by: Marcos Paulo de Souza <marcos.souza.org@gmail.com>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
6 years agoqemu: don't use chardev FD passing with standalone args
Daniel P. Berrangé [Thu, 28 Jun 2018 11:49:12 +0000 (12:49 +0100)]
qemu: don't use chardev FD passing with standalone args

When using domxml-to-native, we must generate CLI args that can be used
in a standalone scenario. This means no FD passing can be used. To
achieve this we must clear the QEMU_CAPS_CHARDEV_FD_PASS capability bit.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agonews: Update for the HTM pSeries feature
Andrea Bolognani [Mon, 2 Jul 2018 08:41:21 +0000 (10:41 +0200)]
news: Update for the HTM pSeries feature

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agoqemu: Format the HTM pSeries feature
Andrea Bolognani [Mon, 2 Jul 2018 08:37:09 +0000 (10:37 +0200)]
qemu: Format the HTM pSeries feature

This makes the feature fully operational.

https://bugzilla.redhat.com/show_bug.cgi?id=1525599

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agoconf: Parse and format the HTM pSeries feature
Andrea Bolognani [Mon, 2 Jul 2018 08:35:54 +0000 (10:35 +0200)]
conf: Parse and format the HTM pSeries feature

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agoqemu: Add capability for the HTM pSeries feature
Andrea Bolognani [Tue, 19 Jun 2018 11:51:05 +0000 (13:51 +0200)]
qemu: Add capability for the HTM pSeries feature

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agotests: qemumonitorjson: Fix name and call apropriate API
Peter Krempa [Mon, 18 Jun 2018 08:24:17 +0000 (10:24 +0200)]
tests: qemumonitorjson: Fix name and call apropriate API

Call the internal version of qemuMonitorGetAllBlockStatsInfo API and
rename the test accordingly.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
6 years agotests: qemumonitorjson: Add only required replies for blockstats test
Peter Krempa [Mon, 18 Jun 2018 08:22:18 +0000 (10:22 +0200)]
tests: qemumonitorjson: Add only required replies for blockstats test

testQemuMonitorJSONqemuMonitorJSONGetBlockStatsInfo added 4 replies but
only one was used. Additionally the comment stated that 7 replies are
going to be added.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
6 years agoqemu: domain: update only newly detected images in qemuDomainDetermineDiskChain
Peter Krempa [Wed, 20 Jun 2018 08:39:21 +0000 (10:39 +0200)]
qemu: domain: update only newly detected images in qemuDomainDetermineDiskChain

The processing code which prepares images should be executed really only
for the images which were detected. The code actually tried to update
the last user-specified layer as well. Thankfully we don't do anything
that would be a problem at this point.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
6 years agovirsh: Provide completer for detach-device-alias
Michal Privoznik [Tue, 26 Jun 2018 10:41:34 +0000 (12:41 +0200)]
virsh: Provide completer for detach-device-alias

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agoqemuDomainDeviceDefValidateNetwork: Check for range only if IP prefix set
Michal Privoznik [Fri, 29 Jun 2018 14:48:55 +0000 (16:48 +0200)]
qemuDomainDeviceDefValidateNetwork: Check for range only if IP prefix set

https://bugzilla.redhat.com/show_bug.cgi?id=1515533

The @prefix attribute to <ip/> element for interface type user is
optional. Therefore, if left out it has value of zero in which
case we should not check whether it falls into <4, 27> range.
Otherwise we fail parsing domain XML for no good reason.

Broken by commit b62b8090b2ad4524a5bf9d40d0d1c17a9d57f5a0.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
6 years agoesx_driver: Simplify IsEncrypted and IsSecure
Marcos Paulo de Souza [Tue, 26 Jun 2018 23:39:05 +0000 (20:39 -0300)]
esx_driver: Simplify IsEncrypted and IsSecure

Signed-off-by: Marcos Paulo de Souza <marcos.souza.org@gmail.com>
6 years agoutil: moving 'type' argument to avoid issues with mount() syscall.
Julio Faracco [Wed, 27 Jun 2018 15:06:26 +0000 (12:06 -0300)]
util: moving 'type' argument to avoid issues with mount() syscall.

This commit fixes a mount call inside virgroup.c file. The NULL value
into 'type' argument is causing a valgrind issue. See commit 794b576c
for more details. The best approach to fix it is moving NULL to "none"
filesytem.

Signed-off-by: Julio Faracco <jcfaracco@gmail.com>
6 years agolxc: moving 'type' argument to avoid issues with mount() syscall.
Julio Faracco [Wed, 27 Jun 2018 15:06:25 +0000 (12:06 -0300)]
lxc: moving 'type' argument to avoid issues with mount() syscall.

This commit fixes a lots of mount calls inside lxc_container.c file. The
NULL value into 'type' argument is causing a valgrind issue. See commit
794b576c2b for more details. The best approach to fix it is moving NULL
to "none" filesytem.

Signed-off-by: Julio Faracco <jcfaracco@gmail.com>
6 years agonetwork: properly check for taps that are connected to an OVS bridge
Laine Stump [Sun, 1 Jul 2018 23:29:03 +0000 (19:29 -0400)]
network: properly check for taps that are connected to an OVS bridge

When libvirtd is restarted, it checks that each guest tap device is
still attached to the bridge device that the configuration info says
it should be connected to. If not, the tap will be disconnected from
[wherever it is] and connected to [wherever it should be].

The previous code that did this did not account for:

1) the IFLA_MASTER attribute in a netdev's ifinfo will be set to
   "ovs-system" for any tap device connected to an OVS bridge, *not*
   to the name of the bridge it is attached to.

2) virNetDevRemovePort() only works for devices that are attached to a
   standard Linux host bridge. If a device is currently attached to an
   OVS bridge, then virNetDevOpenvswitchRemovePort() must be called
   instead.

This patch remedies those problems, and adds a couple of information
log messages to aid in debugging any future problem.

Resolves: https://bugzilla.redhat.com/1596176

Signed-off-by: Laine Stump <laine@laine.org>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agoutil: add some debug log to virNetDevGetMaster
Laine Stump [Sun, 1 Jul 2018 23:27:17 +0000 (19:27 -0400)]
util: add some debug log to virNetDevGetMaster

This makes it easier to see why libvirt has decided it must re-attach
a tap device to its bridge.

Signed-off-by: Laine Stump <laine@laine.org>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agoutil: new function virNetDevOpenvswitchInterfaceGetMaster()
Laine Stump [Sun, 1 Jul 2018 23:24:19 +0000 (19:24 -0400)]
util: new function virNetDevOpenvswitchInterfaceGetMaster()

This function retrieves the name of the OVS bridge that the given
netdev is attached to. This separate function is necessary because OVS
set the IFLA_MASTER attribute to "ovs-system" for all netdevs that are
attached to an OVS bridge, so the standard method of retrieving the
master can't be used.

Signed-off-by: Laine Stump <laine@laine.org>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agolxc: Rearrange order in lxcDomainUpdateDeviceFlags
John Ferlan [Tue, 26 Jun 2018 14:14:20 +0000 (10:14 -0400)]
lxc: Rearrange order in lxcDomainUpdateDeviceFlags

Although commit e3497f3f noted that the LIVE option doesn't
matter and removed the call to virDomainDefCompatibleDevice,
it didn't go quite far enough and change the order of the checks
and rework the code to just handle the config change causing
a failure after virDomainObjUpdateModificationImpact updates
the @flags. Since we only support config a lot of previously
conditional code is now just inlined.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Prívozník <mprivozn@redhat.com>
6 years agolxc: Remove FORCE flag from lxcDomainUpdateDeviceFlags
John Ferlan [Thu, 28 Jun 2018 10:29:51 +0000 (06:29 -0400)]
lxc: Remove FORCE flag from lxcDomainUpdateDeviceFlags

Force would be used to force eject a cdrom live, since the code
doesn't support live update, remove the flag.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Prívozník <mprivozn@redhat.com>
6 years agodomain_addr: delete virDomainVirtioSerialAddrRelease
Anya Harter [Fri, 29 Jun 2018 15:03:25 +0000 (11:03 -0400)]
domain_addr: delete virDomainVirtioSerialAddrRelease

the last use of this function was deleted in commit
    19a148b7c8353d5c214bed699f8fe983317baf93

Signed-off-by: Anya Harter <aharter@redhat.com>
6 years agodomain_addr: delete virDomainCCWAddressReleaseAddr
Anya Harter [Fri, 29 Jun 2018 15:03:24 +0000 (11:03 -0400)]
domain_addr: delete virDomainCCWAddressReleaseAddr

the last use of this function was deleted in commit
    1aa5e66cf3a0dd5e8ada8483f79cb745f786a131

Signed-off-by: Anya Harter <aharter@redhat.com>
6 years agoPost-release version bump to 4.6.0
John Ferlan [Mon, 2 Jul 2018 20:54:32 +0000 (16:54 -0400)]
Post-release version bump to 4.6.0

Signed-off-by: John Ferlan <jferlan@redhat.com>
6 years agoRelease of libvirt-4.5.0
Daniel Veillard [Mon, 2 Jul 2018 20:11:33 +0000 (22:11 +0200)]
Release of libvirt-4.5.0

- docs/news.xml: updated for the release

Signed-off-by: Daniel Veillard <veillard@redhat.com>
6 years agonews: Update for 4.5.0 release
Andrea Bolognani [Mon, 2 Jul 2018 14:43:54 +0000 (16:43 +0200)]
news: Update for 4.5.0 release

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
6 years agoqemu_migration: Check for active domain after talking to remote daemon
Jiri Denemark [Thu, 28 Jun 2018 09:38:52 +0000 (11:38 +0200)]
qemu_migration: Check for active domain after talking to remote daemon

Once we called qemuDomainObjEnterRemote to talk to the destination
daemon during a peer to peer migration, the vm lock is released and we
only hold an async job. If the source domain dies at this point the
monitor EOF callback is allowed to do its job and (among other things)
clear all private data irrelevant for stopped domain. Thus when we call
qemuDomainObjExitRemote, the domain may already be gone and we should
avoid touching runtime private data (such as current job info).

In other words after acquiring the lock in qemuDomainObjExitRemote, we
need to check the domain is still alive. Unless we're doing offline
migration.

https://bugzilla.redhat.com/show_bug.cgi?id=1589730

Signed-off-by: Jiri Denemark <jdenemar@redhat.com>
6 years agoqemu_migration: Rename 'offline' variable in SrcPerformPeer2Peer
Jiri Denemark [Thu, 28 Jun 2018 12:09:47 +0000 (14:09 +0200)]
qemu_migration: Rename 'offline' variable in SrcPerformPeer2Peer

The variable is used to store the offline migration capability of the
destination daemon. Let's call it 'dstOffline' so that we can later use
'offline' to indicate whether we were asked to do offline migration.

Signed-off-by: Jiri Denemark <jdenemar@redhat.com>
6 years agoqemu: Allow cachetune only for KVM domains
Michal Privoznik [Thu, 28 Jun 2018 09:37:09 +0000 (11:37 +0200)]
qemu: Allow cachetune only for KVM domains

https://bugzilla.redhat.com/show_bug.cgi?id=1541921

In TCG mode, there are no vCPU threads and thus there's nothing
to be placed into resctrl group. Forbid such configuration.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoqemu: Report error on unexpected job stats type
Jiri Denemark [Fri, 1 Jun 2018 08:22:30 +0000 (10:22 +0200)]
qemu: Report error on unexpected job stats type

If we ever fail to properly set jobinfo->statsType,
qemuDomainJobInfoToParams would return -1 without setting an error.

Signed-off-by: Jiri Denemark <jdenemar@redhat.com>
6 years agosecurity: Add swtpm paths to the domain's AppArmor profile
Stefan Berger [Sat, 19 May 2018 03:33:46 +0000 (23:33 -0400)]
security: Add swtpm paths to the domain's AppArmor profile

This patch extends the AppArmor domain profile with file paths
the swtpm accesses for state, log, pid, and socket files.

Both, QEMU and swtpm, use this AppArmor profile.

Signed-off-by: Stefan Berger <stefanb@linux.vnet.ibm.com>
Cc: Christian Ehrhardt <christian.ehrhardt@canonical.com>
6 years agonwfilter: variable 'obj' must be initialized inside nwfilterBindingCreateXML().
Julio Faracco [Wed, 27 Jun 2018 02:47:53 +0000 (23:47 -0300)]
nwfilter: variable 'obj' must be initialized inside nwfilterBindingCreateXML().

The function nwfilterBindingCreateXML() is failing to compile due to a
conditional branch which leads to an undefined 'obj' variable. So 'obj'
must have an initial value to avoid compilation errors. See the problem:

  CC       nwfilter/libvirt_driver_nwfilter_impl_la-nwfilter_driver.lo
nwfilter/nwfilter_driver.c:752:9: error: variable 'obj' is used uninitialized whenever 'if' condition is true [-Werror,-Wsometimes-uninitialized]
    if (virNWFilterBindingCreateXMLEnsureACL(conn, def) < 0)
        ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
nwfilter/nwfilter_driver.c:779:10: note: uninitialized use occurs here
    if (!obj)
         ^~~
nwfilter/nwfilter_driver.c:752:5: note: remove the 'if' if its condition is always false
    if (virNWFilterBindingCreateXMLEnsureACL(conn, def) < 0)
    ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
nwfilter/nwfilter_driver.c:742:33: note: initialize the variable 'obj' to silence this warning
    virNWFilterBindingObjPtr obj;
                                ^
                                 = NULL

This commit initialized 'obj' with NULL to fix the error properly.

Signed-off-by: Julio Faracco <jcfaracco@gmail.com>
Reviewed-by: Pavel Hrdina <phrdina@redhat.com>
6 years agoconf: Forbid device alias change on device-update
Michal Privoznik [Tue, 12 Jun 2018 14:05:10 +0000 (16:05 +0200)]
conf: Forbid device alias change on device-update

https://bugzilla.redhat.com/show_bug.cgi?id=1585108

When updating a live device users might pass different alias than
the one the device has. Currently, this is silently ignored which
goes against our behaviour for other parts of the device where we
explicitly allow only certain changes and error out loudly on
anything else.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agoconf: Reintroduce action to virDomainDefCompatibleDevice
Michal Privoznik [Tue, 26 Jun 2018 08:37:27 +0000 (10:37 +0200)]
conf: Reintroduce action to virDomainDefCompatibleDevice

This was lost in c57f3fd2f8999d17e01. But now we are going to
need it again (except the DETACH action where checking for device
compatibility does not make much sense anyway).

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agoqemuDomainUpdateDeviceFlags: Parse device as live if needed
Michal Privoznik [Tue, 12 Jun 2018 14:04:30 +0000 (16:04 +0200)]
qemuDomainUpdateDeviceFlags: Parse device as live if needed

When updating device it's worth parsing live info too as users
might want to update it as well.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agospec: list new nwfilter schema files
Pavel Hrdina [Wed, 27 Jun 2018 08:42:52 +0000 (10:42 +0200)]
spec: list new nwfilter schema files

Commit <41d619e99c2015eab2d56bea874e23ba9f52f829> introduced new RNG
schema files for nwfilter but forgot to update spec file.

Signed-off-by: Pavel Hrdina <phrdina@redhat.com>
6 years agosyms: Fix placement of virDomainGetBlkioParametersAssignFromDef
Cole Robinson [Tue, 26 Jun 2018 19:53:30 +0000 (15:53 -0400)]
syms: Fix placement of virDomainGetBlkioParametersAssignFromDef

It's in the domain_addr.h section, but should be in the
domain_conf.h section

Signed-off-by: Cole Robinson <crobinso@redhat.com>
6 years agoqemu: hotplug: fix mdev attach for vfio-ccw
Bjoern Walk [Tue, 26 Jun 2018 11:47:39 +0000 (13:47 +0200)]
qemu: hotplug: fix mdev attach for vfio-ccw

Mediated devices of model 'vfio-ccw' are using CCW addresses, so make
sure to call the correct address preparation code for the model.

Reviewed-by: Shalini Chellathurai Saroja <shalini@linux.ibm.com>
Reviewed-by: Boris Fiuczynski <fiuczy@linux.ibm.com>
Signed-off-by: Bjoern Walk <bwalk@linux.ibm.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agodocs: Add news article for volume encryption modifications
John Ferlan [Wed, 20 Jun 2018 22:37:15 +0000 (18:37 -0400)]
docs: Add news article for volume encryption modifications

Include both the domain and storage modifications in a "Removed
features" section as well as describing the improvement to allow
using a raw input volume to create the luks encrypted volume.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agostorage: Add support for using inputvol for encryption
John Ferlan [Wed, 20 Jun 2018 19:51:47 +0000 (15:51 -0400)]
storage: Add support for using inputvol for encryption

Starting with QEMU 2.9, encryption convert processing requires
a multi-step process in order to generate an encrypted image from
some non encrypted raw image.

Processing requires to first create an encrypted image using the
sizing parameters from the input source and second to use the
--image-opts, -n, and --target-image-opts options along with inline
driver options to describe the input and output files, generating
two commands such as:

  $ qemu-img create -f luks \
      --object secret,id=demo.img_encrypt0,file=/path/to/secretFile \
      -o key-secret=demo.img_encrypt0 \
      demo.img 500K
  Formatting 'demo.img', fmt=luks size=512000 key-secret=demo.img_encrypt0
  $ qemu-img convert --image-opts -n --target-image-opts \
      --object secret,id=demo.img_encrypt0,file=/path/to/secretFile \
      driver=raw,file.filename=sparse.img \
      driver=luks,file.filename=demo.img,key-secret=demo.img_encrypt0
  $

This patch handles the convert processing by running the processing
in a do..while loop essentially reusing the existing create logic and
arguments to create the target vol from the inputvol and then converting
the inputvol using new arguments.

This then allows the following virsh command to work properly:

  virsh vol-create-from default encrypt1-luks.xml data.img --inputpool default

where encrypt1-luks.xml would provided the path and secret for
the new image, while data.img would be the source image.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agostorage: Remove storageBackendGenerateSecretData
John Ferlan [Tue, 19 Jun 2018 15:56:21 +0000 (11:56 -0400)]
storage: Remove storageBackendGenerateSecretData

Since we no longer support creating qcow2 encryption format
volumes, we no longer have to possibly create some secret and
have no real need for the function, so move the remaining
functionality to build the secret path back into the caller
storageBackendCreateQemuImg.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agostorage: Clean up storageBackendCreateQemuImgOpts
John Ferlan [Tue, 19 Jun 2018 23:19:23 +0000 (19:19 -0400)]
storage: Clean up storageBackendCreateQemuImgOpts

Since we only generate the @encinfo when there's a secret object
and thus we need to reference it in the options,

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agostorage: Clean up storageBackendCreateQemuImgCheckEncryption
John Ferlan [Wed, 20 Jun 2018 21:15:03 +0000 (17:15 -0400)]
storage: Clean up storageBackendCreateQemuImgCheckEncryption

Remove the checks for qcow encryption since both callers (create
and resize) would have already disallowed usage.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agostorage: Disallow create/resize of qcow2 encrypted images
John Ferlan [Wed, 20 Jun 2018 20:21:50 +0000 (16:21 -0400)]
storage: Disallow create/resize of qcow2 encrypted images

https://bugzilla.redhat.com/show_bug.cgi?id=1526382

Since commit c4eedd793 disallowed qcow2 encrypted images to be
used for domains, it no longer makes sense to allow a qcow2
encrypted volume to be created or resized.

Add a test that will exhibit the failure of creation as well
as the xml2xml validation of the format still being correct.

Update the documentation to note the removal of the capability
to create and use qcow/default encrypted volumes.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agotests: Remove qcow2 encryption from storagevol tests
John Ferlan [Wed, 20 Jun 2018 19:52:30 +0000 (15:52 -0400)]
tests: Remove qcow2 encryption from storagevol tests

We're about to disallow creation of a qcow2 encrypted storage
volume, so let's remove the qcow encryption element from the
tests which are testing whether other format='qcow2' related
features work properly.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agostorage: Rename encryption info variable for clarity
John Ferlan [Tue, 19 Jun 2018 23:15:43 +0000 (19:15 -0400)]
storage: Rename encryption info variable for clarity

Change from @enc to @encinfo leaving @enc for the vol->target.encryption
in the storageBackendCreateQemuImgSetOptions code path.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agotests: Add luks creation examples to storagevolxml2argvtest
John Ferlan [Tue, 19 Jun 2018 14:59:48 +0000 (10:59 -0400)]
tests: Add luks creation examples to storagevolxml2argvtest

Add the storagevolxml2xmltest "luks" and "luks-cipher" tests
to the storagevolxml2argvtest.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agostorage: Don't allow encryption secretPath to be NULL
John Ferlan [Tue, 19 Jun 2018 16:05:31 +0000 (12:05 -0400)]
storage: Don't allow encryption secretPath to be NULL

Allowing a NULL @secretPath for virStorageBackendCreateQemuImgCmdFromVol
would result in a generated command line with a dangling "file=" output.
So let's make sure the @secretPath exists before processing.

This means we should pass a dummy path from the storage test.

Signed-off-by: John Ferlan <jferlan@redhat.com>
ACKed-by: Michal Privoznik <mprivozn@redhat.com>
6 years agodomain_addr: Fix weird comment format
Cole Robinson [Tue, 26 Jun 2018 15:49:54 +0000 (11:49 -0400)]
domain_addr: Fix weird comment format

Signed-off-by: Cole Robinson <crobinso@redhat.com>
6 years agonwfilter: convert virt drivers to use public API for nwfilter bindings
Daniel P. Berrangé [Fri, 11 May 2018 17:39:27 +0000 (18:39 +0100)]
nwfilter: convert virt drivers to use public API for nwfilter bindings

Remove the callbacks that the nwfilter driver registers with the domain
object config layer. Instead make the current helper methods call into
the public API for creating/deleting nwfilter bindings.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agonwfilter: wire up new APIs for creating and deleting nwfilter bindings
Daniel P. Berrangé [Fri, 11 May 2018 15:59:51 +0000 (16:59 +0100)]
nwfilter: wire up new APIs for creating and deleting nwfilter bindings

This allows the virsh commands nwfilter-binding-create and
nwfilter-binding-delete to be used.

Note using these commands lets you delete filters that were
previously created automatically by the virt drivers, or add
filters for VM nics that were not there before. Generally it
is expected these new APIs will only be used by virt drivers.
It is the admin's responsibility to not shoot themselves in
the foot.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agonwfilter: wire up new APIs for listing and querying filter bindings
Daniel P. Berrangé [Thu, 10 May 2018 13:12:40 +0000 (14:12 +0100)]
nwfilter: wire up new APIs for listing and querying filter bindings

Wire up the ListAll, LookupByPortDev and GetXMLDesc APIs to allow the
virsh nwfilter-binding-list & nwfilter-binding-dumpxml commands to
work.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agonwfilter: remove virt driver callback layer for rebuilding filters
Daniel P. Berrangé [Fri, 27 Apr 2018 12:25:10 +0000 (13:25 +0100)]
nwfilter: remove virt driver callback layer for rebuilding filters

Now that the nwfilter driver keeps a list of bindings that it has
created, there is no need for the complex virt driver callbacks. It is
possible to simply iterate of the list of recorded filter bindings.

This means that rebuilding filters no longer has to acquire any locks on
the virDomainObj objects, as they're never touched.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agonwfilter: keep track of active filter bindings
Daniel P. Berrangé [Thu, 26 Apr 2018 17:34:33 +0000 (18:34 +0100)]
nwfilter: keep track of active filter bindings

Currently the nwfilter driver does not keep any record of what filter
bindings it has active. This means that when it needs to recreate
filters, it has to rely on triggering callbacks provided by the virt
drivers. This introduces a hash table recording the virNWFilterBinding
objects so the driver has a record of all active filters.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agovirsh: add manpage docs for nwfilter-binding commands.
Daniel P. Berrangé [Fri, 22 Jun 2018 10:53:39 +0000 (11:53 +0100)]
virsh: add manpage docs for nwfilter-binding commands.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoqemu: Escape commas for qemuBuildSCSIiSCSIHostdevDrvStr
Anya Harter [Wed, 20 Jun 2018 13:17:00 +0000 (09:17 -0400)]
qemu: Escape commas for qemuBuildSCSIiSCSIHostdevDrvStr

Add comma escaping for netsource. This is done here because
qemuBuildNetworkDriveStr has other external callers which
may not expect an escaped comma; however, this particular
command building path needs to perform the escaping for the
hostdev command line, so we do it now to ensure src->path
and src->host->name are covered.

Signed-off-by: Anya Harter <aharter@redhat.com>
6 years agoqemu: use virBuffer in qemuBuildSCSIiSCSIHostdevDrvStr
Anya Harter [Wed, 20 Jun 2018 13:16:59 +0000 (09:16 -0400)]
qemu: use virBuffer in qemuBuildSCSIiSCSIHostdevDrvStr

Instead of source to enable use of virBuffer functions in
string construction.

Signed-off-by: Anya Harter <aharter@redhat.com>
6 years agoqemuDomainObjBeginJobInternal: Report agent job in error message
Michal Privoznik [Wed, 20 Jun 2018 12:17:45 +0000 (14:17 +0200)]
qemuDomainObjBeginJobInternal: Report agent job in error message

If a thread is unable to acquire a job (e.g. because of timeout)
an error is reported and the error message contains reference to
the other thread holding the job. Well, the error message should
report agent job too as it is yet another source of possible
failure.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agoset-lifecycle-action: add description of type and action
Chen Hanxiao [Thu, 21 Jun 2018 11:28:55 +0000 (19:28 +0800)]
set-lifecycle-action: add description of type and action

In [1], <type> are described as "on_poweroff", "on_reboot",
"on_crash". but we accept "poweroff", "reboot" and "crash".
This patch adds documentation for them.

[1]: https://libvirt.org/formatdomain.html#elementsEvents

Signed-off-by: Chen Hanxiao <chenhanxiao@gmail.com>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
6 years agoconf: introduce a virNWFilterBindingObjListPtr struct
Daniel P. Berrangé [Thu, 10 May 2018 14:29:46 +0000 (15:29 +0100)]
conf: introduce a virNWFilterBindingObjListPtr struct

Introduce a new struct to act as the manager of a collection of
virNWFilterBindingObjPtr objects.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoconf: introduce a virNWFilterBindingObjPtr struct
Daniel P. Berrangé [Thu, 10 May 2018 16:21:24 +0000 (17:21 +0100)]
conf: introduce a virNWFilterBindingObjPtr struct

Introduce a new struct to act as the stateful owner of the
virNWFilterBindingDefPtr objects.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoconf: report an error if nic needs filtering by no driver is present
Daniel P. Berrangé [Thu, 26 Apr 2018 13:05:10 +0000 (14:05 +0100)]
conf: report an error if nic needs filtering by no driver is present

If a <interface> includes a filter name but the nwfilter driver is not
present we silently do nothing. This is very bad, because an application
that thinks it is protected by malicious guest traffic will in fact be
vulnerable. Reporting an error gives the administrator the ability to
know there is a problem and fix it.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agonwfilter: convert DHCP address snooping code to virNWFilterBindingDefPtr
Daniel P. Berrangé [Thu, 26 Apr 2018 11:45:29 +0000 (12:45 +0100)]
nwfilter: convert DHCP address snooping code to virNWFilterBindingDefPtr

Use the virNWFilterBindingDefPtr struct in the DHCP address snooping code
directly.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agonwfilter: convert IP address learning code to virNWFilterBindingDefPtr
Daniel P. Berrangé [Thu, 26 Apr 2018 11:45:29 +0000 (12:45 +0100)]
nwfilter: convert IP address learning code to virNWFilterBindingDefPtr

Use the virNWFilterBindingDefPTr struct in the IP address learning code
directly.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agonwfilter: convert the gentech driver code to use virNWFilterBindingDefPtr
Daniel P. Berrangé [Thu, 26 Apr 2018 11:26:51 +0000 (12:26 +0100)]
nwfilter: convert the gentech driver code to use virNWFilterBindingDefPtr

Use the virNWFilterBindingDefPtr struct in the gentech driver code
directly.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agovirsh: add nwfilter binding commands
Daniel P. Berrangé [Wed, 9 May 2018 16:44:35 +0000 (17:44 +0100)]
virsh: add nwfilter binding commands

$ virsh nwfilter-binding-list
 Port Dev                              Filter
------------------------------------------------------------------
 vnet0                 clean-traffic
 vnet1                 clean-traffic

$ virsh nwfilter-binding-dumpxml vnet1
<filterbinding>
  <owner>
    <name>f25arm7</name>
    <uuid>12ac8b8c-4f23-4248-ae42-fdcd50c400fd</uuid>
  </owner>
  <portdev name='vnet1'/>
  <mac address='52:54:00:9d:81:b1'/>
  <filterref filter='clean-traffic'>
    <parameter name='MAC' value='52:54:00:9d:81:b1'/>
  </filterref>
</filterbinding>

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoremote: add support for nwfilter binding objects
Daniel P. Berrangé [Wed, 9 May 2018 16:18:58 +0000 (17:18 +0100)]
remote: add support for nwfilter binding objects

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoaccess: add nwfilter binding object permissions
Daniel P. Berrangé [Wed, 9 May 2018 16:19:55 +0000 (17:19 +0100)]
access: add nwfilter binding object permissions

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agonwfilter: export port binding concept in the public API
Daniel P. Berrangé [Wed, 9 May 2018 11:21:25 +0000 (12:21 +0100)]
nwfilter: export port binding concept in the public API

When the daemons are split there will need to be a way for the virt
drivers and/or network driver to create and delete bindings between
network ports and network filters. This defines a set of public APIs
that are suitable for managing this facility.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoschemas: add schema for nwfilter binding XML document
Daniel P. Berrangé [Tue, 15 May 2018 17:00:16 +0000 (18:00 +0100)]
schemas: add schema for nwfilter binding XML document

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoconf: add support for parsing/formatting virNWFilterBindingDefPtr
Daniel P. Berrangé [Thu, 10 May 2018 12:37:53 +0000 (13:37 +0100)]
conf: add support for parsing/formatting virNWFilterBindingDefPtr

A typical XML representation of the virNWFilterBindingDefPtr struct
looks like this:

  <filterbinding>
    <owner>
      <name>f25arm7</name>
      <uuid>12ac8b8c-4f23-4248-ae42-fdcd50c400fd</uuid>
    </owner>
    <portdev name='vnet1'/>
    <mac address='52:54:00:9d:81:b1'/>
    <filterref filter='clean-traffic'>
      <parameter name='MAC' value='52:54:00:9d:81:b1'/>
    </filterref>
  </filterbinding>

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoconf: move virNWFilterBindingDefPtr into its own files
Daniel P. Berrangé [Thu, 10 May 2018 13:30:42 +0000 (14:30 +0100)]
conf: move virNWFilterBindingDefPtr into its own files

There's no code sharing between virNWFilterDef and
virNWFilterBindingDefPtr types, so it is clearer if they live in
separate source files and headers.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoconf: add missing virxml.h include for nwfilter_params.h
Daniel P. Berrangé [Thu, 10 May 2018 13:29:58 +0000 (14:29 +0100)]
conf: add missing virxml.h include for nwfilter_params.h

The nwfilter_params.h header references the xmlNodePtr type, so must
include the virxml.h header to get the libxml2 types defined.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agoconf: change virNWFilterBindingPtr to virNWFilterBindingDefPtr
Daniel P. Berrangé [Tue, 8 May 2018 12:45:26 +0000 (13:45 +0100)]
conf: change virNWFilterBindingPtr to virNWFilterBindingDefPtr

We are going to want to expose the NWFilter binding concept in the
public API, so the virNWFilterBindingPtr type needs to be used there.
Our internal type will shortly gain an XML representation, so rename
it to virNWFilterBindingDefPtr which follows our normal conventions.

Reviewed-by: John Ferlan <jferlan@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agospec: Move SASL configuration file from -libs to -daemon
Andrea Bolognani [Thu, 21 Jun 2018 14:14:48 +0000 (16:14 +0200)]
spec: Move SASL configuration file from -libs to -daemon

SASL authentication is configured server-side, so the sample
configuration file should be shipped along with the daemon
rather than with the libraries.

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
6 years agonews: Update for HPT maxpagesize feature
Andrea Bolognani [Mon, 25 Jun 2018 16:56:23 +0000 (18:56 +0200)]
news: Update for HPT maxpagesize feature

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
6 years agoqemu: Format HPT maxpagesize on the command line
Andrea Bolognani [Wed, 23 May 2018 16:18:02 +0000 (18:18 +0200)]
qemu: Format HPT maxpagesize on the command line

This makes the feature fully functional.

https://bugzilla.redhat.com/show_bug.cgi?id=1571078

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
6 years agoconf: Parse and format HPT maxpagesize
Andrea Bolognani [Wed, 23 May 2018 16:18:01 +0000 (18:18 +0200)]
conf: Parse and format HPT maxpagesize

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
6 years agoconf: Tweak HPT feature parsing and formatting
Andrea Bolognani [Wed, 23 May 2018 16:17:58 +0000 (18:17 +0200)]
conf: Tweak HPT feature parsing and formatting

This doesn't seem very useful at the moment, but it will make
sense once we introduce another HPT-related setting.

The output XML is decoupled from the input XML in preparation
of future changes as well; while doing so, we can shave a few
lines off the latter.

This commit is best viewed with 'git show -w'.

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
6 years agoconf: Reintroduce virDomainDef::hpt_resizing
Andrea Bolognani [Wed, 23 May 2018 16:17:57 +0000 (18:17 +0200)]
conf: Reintroduce virDomainDef::hpt_resizing

We're going to introduce a second HPT-related setting soon,
at which point using a single location to store everything is
no longer going to cut it.

This mostly, but not completely, reverts 3dd1eb3b2650.

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
6 years agoqemu: Add capability for the HPT maxpagesize feature
Andrea Bolognani [Tue, 19 Jun 2018 11:51:05 +0000 (13:51 +0200)]
qemu: Add capability for the HPT maxpagesize feature

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
6 years agotests: Add replies for QEMU 3.0.0 on ppc64
Andrea Bolognani [Mon, 25 Jun 2018 11:58:09 +0000 (13:58 +0200)]
tests: Add replies for QEMU 3.0.0 on ppc64

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
6 years agoutil: fix mount issue by moving NULL value to "none" in syscall.
Julio Faracco [Tue, 26 Jun 2018 03:18:21 +0000 (00:18 -0300)]
util: fix mount issue by moving NULL value to "none" in syscall.

After running libvirt daemon with valgrind tools, some errors are
appearing when you try to start a domain. One example:

==18012== Syscall param mount(type) points to unaddressable byte(s)
==18012==    at 0x6FEE3CA: mount (syscall-template.S:78)
==18012==    by 0x531344D: virFileMoveMount (virfile.c:3828)
==18012==    by 0x27FE7675: qemuDomainBuildNamespace (qemu_domain.c:11501)
==18012==    by 0x2800C44E: qemuProcessHook (qemu_process.c:2870)
==18012==    by 0x52F7E1D: virExec (vircommand.c:726)
==18012==    by 0x52F7E1D: virCommandRunAsync (vircommand.c:2477)
==18012==    by 0x52F4EDD: virCommandRun (vircommand.c:2309)
==18012==    by 0x2800A731: qemuProcessLaunch (qemu_process.c:6235)
==18012==    by 0x2800D6B4: qemuProcessStart (qemu_process.c:6569)
==18012==    by 0x28074876: qemuDomainObjStart (qemu_driver.c:7314)
==18012==    by 0x280522EB: qemuDomainCreateWithFlags (qemu_driver.c:7367)
==18012==    by 0x55484BF: virDomainCreate (libvirt-domain.c:6531)
==18012==    by 0x12CDBD: remoteDispatchDomainCreate (remote_daemon_dispatch_stubs.h:4350)
==18012==    by 0x12CDBD: remoteDispatchDomainCreateHelper (remote_daemon_dispatch_stubs.h:4326)
==18012==  Address 0x0 is not stack'd, malloc'd or (recently) free'd

Some documentation recommends to use "none" when you don't have a
filesystem type to use. Specially, for bind and move actions.

Signed-off-by: Julio Faracco <jcfaracco@gmail.com>
6 years agosnapshots: Clarify comments on snapshot role
Eric Blake [Tue, 26 Jun 2018 00:16:04 +0000 (19:16 -0500)]
snapshots: Clarify comments on snapshot role

Give some more details on what a snapshot is good for, to make
it easier to distinguish from the role of upcoming additions for
incremental backups.

Signed-off-by: Eric Blake <eblake@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agodocs: schema: Add missing <interleave> to devices
Han Han [Fri, 22 Jun 2018 05:24:02 +0000 (13:24 +0800)]
docs: schema: Add missing <interleave> to devices

For input,hub,redirdev devices, their sub-elements should be interleaved.

input device: interleave for <driver>, <alias>, <address>
hub device: interleave for <alias>, <address>
redirdev device: interleave for <source>, <alias>, <address>, <boot>

Signed-off-by: Han Han <hhan@redhat.com>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
6 years agoqemu: Fix memory leak in qemuDomainBlockJobSetSpeed()
w00251574 [Mon, 25 Jun 2018 14:15:36 +0000 (22:15 +0800)]
qemu: Fix memory leak in qemuDomainBlockJobSetSpeed()

fix 'device' leak in qemuDomainBlockJobSetSpeed

Signed-off-by: Jie Wang <wangjie88.huawei.com>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
6 years agoqemu: monitor: Fix memory leak in qemuMonitorJSONNBDServerStart()
w00251574 [Mon, 25 Jun 2018 13:48:50 +0000 (21:48 +0800)]
qemu: monitor: Fix memory leak in qemuMonitorJSONNBDServerStart()

Exiting early through the return path did result in 'port_str'
being leaked.

Signed-off-by: Jie Wang <wangjie88.huawei.com>
6 years agoqemu: ensure FDs passed to QEMU for chardevs have correct SELinux labels
Daniel P. Berrangé [Thu, 7 Jun 2018 15:55:07 +0000 (16:55 +0100)]
qemu: ensure FDs passed to QEMU for chardevs have correct SELinux labels

The UNIX socket FDs were we passing to QEMU inherited a label based on
libvirtd's context. QEMU is thus denied ability to access the UNIX
socket. We need to use the security manager to change our current
context temporarily when creating the UNIX socket FD.

Reviewed-by: Laine Stump <laine@laine.org>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
6 years agodocs: formatdomain: Mention that 'urandom' is the recommended RNG backend
Kashyap Chamarthy [Fri, 22 Jun 2018 10:09:39 +0000 (12:09 +0200)]
docs: formatdomain: Mention that 'urandom' is the recommended RNG backend

Since libvirt 1.3.4, any RNG source is accepted for the 'random'
backend.  However, '/dev/urandom' is the _recommended_ source of
entropy. Therefore we should mention that in the docs.

Suggested-by: Daniel P. Berrangé <berrange@redhat.com>
Signed-off-by: Kashyap Chamarthy <kchamart@redhat.com>
Reviewed-by: Erik Skultety <eskultet@redhat.com>
6 years agoqemuDomainObjBeginJobInternal: Log agent job too
Michal Privoznik [Wed, 20 Jun 2018 12:15:42 +0000 (14:15 +0200)]
qemuDomainObjBeginJobInternal: Log agent job too

If a thread is unable to start a job (e.g. because of timeout)
a warning is printed into the logs. So far, the message does not
contain agent job info. Add it as it might help future debugging.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
6 years agonews: Document recent agent job change
Michal Privoznik [Thu, 21 Jun 2018 13:37:38 +0000 (15:37 +0200)]
news: Document recent agent job change

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Erik Skultety <eskultet@redhat.com>
6 years agovirDomainSnapshotDefParse: Prefer VIR_STEAL_PTR
Michal Privoznik [Thu, 21 Jun 2018 10:11:29 +0000 (12:11 +0200)]
virDomainSnapshotDefParse: Prefer VIR_STEAL_PTR

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Erik Skultety <eskultet@redhat.com>
6 years agoqemu: fix msg could be a wild pointer in qemuMonitorIOProcess()
Weilun Zhu [Wed, 20 Jun 2018 08:45:27 +0000 (16:45 +0800)]
qemu: fix msg could be a wild pointer in qemuMonitorIOProcess()

As qemuMonitorJSONIOProcess will call qemuMonitorJSONIOProcessEvent
which unlocks the monitor mutex, there is some extreme situation,
eg qemu send message to monitor twice in a short time, where the
local viriable 'msg' of qemuMonitorIOProcess could be a wild point:

1. qemuMonitorSend() assign mon->msg to parameter 'msg', which is alse a
local variable of its caller qemuMonitorJSONCommandWithFd(), cause
eventloop to send message to monitor, then wait condition.
2. qemu send message to monitor for the first time immediately.
3. qemuMonitorIOProcess() is called, then wake up the qemuMonitorSend()
thread, but the qemuMonitorSend() thread stuck for a while as cpu pressure
or some other reasons, which means the qemu monitor is still unlocked.
4. qemu send event message to monitor for the second time,
such as RTC_CHANGE event
5. qemuMonitorIOProcess() is called again, the local viriable 'msg' is
assigned to mon->msg.
6. qemuMonitorIOProcess() call qemuMonitorJSONIOProcess() to deal with
the qemu event.
7. qemuMonitorJSONIOProcess() unlock the qemu monitor in the macro
'QEMU_MONITOR_CALLBACK', then qemuMonitorSend() thread get the mutex
and free the mon->msg, assign mon->msg to NULL.

Signed-off-by: Weilun Zhu <zhuweilun@huawei.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
6 years agovmx: allow an odd number of vCPUs
Pino Toscano [Thu, 14 Jun 2018 13:34:25 +0000 (15:34 +0200)]
vmx: allow an odd number of vCPUs

Most probably this was a limitation in older ESX versions, and it seems
it does not exist anymore in more recent versions; see the following
thread:
https://www.redhat.com/archives/libvir-list/2018-May/msg02159.html
https://www.redhat.com/archives/libvir-list/2018-June/msg00043.html

Hence, allow an odd number (greater than 1) of vCPUs, since most
probably older versions of ESXi will error out anyway.

https://bugzilla.redhat.com/show_bug.cgi?id=1584091

Signed-off-by: Pino Toscano <ptoscano@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
6 years agoqemu: Escape commas for qemuBuildDiskThrottling
Anya Harter [Tue, 19 Jun 2018 16:20:18 +0000 (12:20 -0400)]
qemu: Escape commas for qemuBuildDiskThrottling

Add comma escaping for disk->blkdeviotune.group_name.

Signed-off-by: Anya Harter <aharter@redhat.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>
6 years agonews: add cmdDomblkinfo --all option
Chen Hanxiao [Tue, 19 Jun 2018 10:01:26 +0000 (18:01 +0800)]
news: add cmdDomblkinfo --all option

Update news for cmdDomblkinfo --all option.

Signed-off-by: Chen Hanxiao <chenhanxiao@gmail.com>
Reviewed-by: John Ferlan <jferlan@redhat.com>