]> xenbits.xensource.com Git - libvirt.git/log
libvirt.git
4 years agoqemu: replace VIR_FREE with g_free in all vir*Free() functions
Laine Stump [Wed, 3 Feb 2021 19:36:01 +0000 (14:36 -0500)]
qemu: replace VIR_FREE with g_free in all vir*Free() functions

Signed-off-by: Laine Stump <laine@redhat.com>
Reviewed-by: Daniel Henrique Barboza <danielhb413@gmail.com>
4 years agolibxl: replace VIR_FREE with g_free in all vir*Free() functions
Laine Stump [Wed, 3 Feb 2021 19:40:15 +0000 (14:40 -0500)]
libxl: replace VIR_FREE with g_free in all vir*Free() functions

Signed-off-by: Laine Stump <laine@redhat.com>
Reviewed-by: Daniel Henrique Barboza <danielhb413@gmail.com>
4 years agobhyve: replace VIR_FREE with g_free in all vir*Free() functions
Laine Stump [Wed, 3 Feb 2021 19:55:29 +0000 (14:55 -0500)]
bhyve: replace VIR_FREE with g_free in all vir*Free() functions

Signed-off-by: Laine Stump <laine@redhat.com>
Reviewed-by: Daniel Henrique Barboza <danielhb413@gmail.com>
4 years agoutil: replace VIR_FREE with g_free in all vir*Free() functions
Laine Stump [Wed, 3 Feb 2021 19:32:34 +0000 (14:32 -0500)]
util: replace VIR_FREE with g_free in all vir*Free() functions

Signed-off-by: Laine Stump <laine@redhat.com>
Reviewed-by: Daniel Henrique Barboza <danielhb413@gmail.com>
4 years agoconf: replace remaining straggler VIR_FREE with g_free in vir*Free()
Laine Stump [Wed, 3 Feb 2021 19:34:14 +0000 (14:34 -0500)]
conf: replace remaining straggler VIR_FREE with g_free in vir*Free()

I missed a few in commit f9f81f1c

Signed-off-by: Laine Stump <laine@redhat.com>
Reviewed-by: Daniel Henrique Barboza <danielhb413@gmail.com>
4 years agotests: Improve macOS stat() mocking logic
Andrea Bolognani [Wed, 3 Feb 2021 11:32:46 +0000 (12:32 +0100)]
tests: Improve macOS stat() mocking logic

We should not mock stat64() when building on Apple Silicon,
because the declaration is not present in the header file.
Detect this situation and handle it gracefully.

https://gitlab.com/libvirt/libvirt/-/issues/121

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agotests: Split macOS stat() mocking logic
Andrea Bolognani [Wed, 3 Feb 2021 11:32:13 +0000 (12:32 +0100)]
tests: Split macOS stat() mocking logic

On macOS, most of the symbols and declarations that we look at
to determine which versions of stat() we need to mock are not
present; on the other hand, there are some specific wrinkles
that are introduced with Apple Silicon which we will need to
take care of.

To avoid making the logic even more of an opaque mess than it
currently is, move the macOS part to a separate branch.

This commit is better viewed with 'git show -w'.

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agoqemu_driver: increase recorded counter for disk block stats
Pavel Hrdina [Wed, 3 Feb 2021 15:28:40 +0000 (16:28 +0100)]
qemu_driver: increase recorded counter for disk block stats

Commit <318d807a0bd3372b634d1952b559c5c627ccfa5b> added a fix to skip
most of the block stat code to not log error message for missing storage
sources but forgot to increase the recordnr counter.

Signed-off-by: Pavel Hrdina <phrdina@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agoqemu_monitor_json: fix JSON generator for VC chardev
Pavel Hrdina [Mon, 1 Feb 2021 10:59:48 +0000 (11:59 +0100)]
qemu_monitor_json: fix JSON generator for VC chardev

The correct backend type is 'vc', same as in qemuBuildChrChardevStr()
where we generate qemu command line.

Signed-off-by: Pavel Hrdina <phrdina@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agoTranslated using Weblate (Finnish)
Jan Kuparinen [Wed, 3 Feb 2021 18:40:09 +0000 (19:40 +0100)]
Translated using Weblate (Finnish)

Currently translated at 13.4% (1404 of 10451 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/fi/

Co-authored-by: Jan Kuparinen <copper_fin@hotmail.com>
Signed-off-by: Jan Kuparinen <copper_fin@hotmail.com>
4 years agovircgroup: Don't leak @parent in virCgroupEnableMissingControllers()
Michal Privoznik [Wed, 3 Feb 2021 19:17:15 +0000 (20:17 +0100)]
vircgroup: Don't leak @parent in virCgroupEnableMissingControllers()

A memory leak was identified in
virCgroupEnableMissingControllers():

==11680==    at 0x483EAE5: calloc (vg_replace_malloc.c:760)
==11680==    by 0x4E51780: g_malloc0 (in /usr/lib64/libglib-2.0.so.0.6701.0)
==11680==    by 0x4908618: virCgroupNew (vircgroup.c:701)
==11680==    by 0x49096F4: virCgroupEnableMissingControllers (vircgroup.c:1146)
==11680==    by 0x4909B17: virCgroupNewMachineSystemd (vircgroup.c:1228)
==11680==    by 0x4909E94: virCgroupNewMachine (vircgroup.c:1313)
==11680==    by 0x1694FDBC: qemuInitCgroup (qemu_cgroup.c:946)
==11680==    by 0x1695046B: qemuSetupCgroup (qemu_cgroup.c:1083)
==11680==    by 0x16A60126: qemuProcessLaunch (qemu_process.c:7077)
==11680==    by 0x16A61504: qemuProcessStart (qemu_process.c:7384)
==11680==    by 0x169B84C2: qemuDomainObjStart (qemu_driver.c:6590)
==11680==    by 0x169B8776: qemuDomainCreateWithFlags (qemu_driver.c:6641)

What happens is that new virCgroup is created and stored into
@parent. Then, if @tokens is not empty the for() loop is entered
into where another virCgroup is created and @parent is replaced
with this new virCgroup. But nothing freed the old @parent.

Fixes: 77291414c7a8745cf4d2b06d3c38d269cfbcfe32
Reported-by: Andrea Bolognani <abologna@redhat.com>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Pavel Hrdina <phrdina@redhat.com>
4 years agobuild: fix specfile logic for disabling netcf
Laine Stump [Tue, 2 Feb 2021 17:51:48 +0000 (12:51 -0500)]
build: fix specfile logic for disabling netcf

I *thought* I had tested all the combinations of manually setting
--without netcf, different versions of Fedora, etc, but apparently
not.

The check in libvirt.spec.in to see if the target was an older Fedora
or older RHEL would alway resolve to true, because, e.g., if {?fedora}
is undefined, then "0%{?fedora} < 34" is "0 < 34", which is always
true. Since both {?fedora} and {?rhel} are never defined at the same
time, the result of the entire expression is always true.

Fix this by qualifying each subexpression.

Fixes: 35d5b26aa433bd33f4b33be3dbb67313357f97f9
Signed-off-by: Laine Stump <laine@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoqemu: implement vhost-user-blk support
Pavel Hrdina [Mon, 1 Feb 2021 11:00:35 +0000 (12:00 +0100)]
qemu: implement vhost-user-blk support

Implements QEMU support for vhost-user-blk together with live
hotplug/unplug.

Signed-off-by: Pavel Hrdina <phrdina@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agoqemu_capabilities: introduce vhost-user-blk capability
Pavel Hrdina [Tue, 2 Feb 2021 12:37:02 +0000 (13:37 +0100)]
qemu_capabilities: introduce vhost-user-blk capability

Signed-off-by: Pavel Hrdina <phrdina@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agoconf: implement support for vhostuser disk
Pavel Hrdina [Mon, 25 Jan 2021 17:13:29 +0000 (18:13 +0100)]
conf: implement support for vhostuser disk

Signed-off-by: Pavel Hrdina <phrdina@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agodocs: introduces new vhostuser disk type
Pavel Hrdina [Mon, 25 Jan 2021 14:59:02 +0000 (15:59 +0100)]
docs: introduces new vhostuser disk type

     <disk type='vhostuser' device='disk'>
       <driver name='qemu' type='raw'/>
       <source type='unix' path='/tmp/vhost-blk.sock'>
         <reconnect enabled='yes' timeout='10'/>
       </source>
       <target dev='vda' bus='virtio'/>
     </disk>

Signed-off-by: Pavel Hrdina <phrdina@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agoqemu_validate: move and refactor qemuValidateDomainDefVirtioFSSharedMemory
Pavel Hrdina [Mon, 1 Feb 2021 17:52:04 +0000 (18:52 +0100)]
qemu_validate: move and refactor qemuValidateDomainDefVirtioFSSharedMemory

Make the function reusable by other vhost-user based devices.

Signed-off-by: Pavel Hrdina <phrdina@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agoqemu_alias: introduce qemuDomainGetVhostUserAlias helper
Pavel Hrdina [Mon, 1 Feb 2021 10:59:03 +0000 (11:59 +0100)]
qemu_alias: introduce qemuDomainGetVhostUserAlias helper

Signed-off-by: Pavel Hrdina <phrdina@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agoqemu: taint the VM if it is using a deprecated machine type
Daniel P. Berrangé [Fri, 22 Jan 2021 11:48:23 +0000 (11:48 +0000)]
qemu: taint the VM if it is using a deprecated machine type

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoqemu: taint the VM if it is using a deprecated CPU model
Daniel P. Berrangé [Fri, 22 Jan 2021 11:48:23 +0000 (11:48 +0000)]
qemu: taint the VM if it is using a deprecated CPU model

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoqemu: add ability to associate a string message with taint warning
Daniel P. Berrangé [Fri, 22 Jan 2021 11:44:32 +0000 (11:44 +0000)]
qemu: add ability to associate a string message with taint warning

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoconf: introduce new taint flag for deprecated configuration
Daniel P. Berrangé [Fri, 22 Jan 2021 11:43:02 +0000 (11:43 +0000)]
conf: introduce new taint flag for deprecated configuration

Hypervisors are capable of reporting that some features are deprecated.
This should be used to mark a domain as tainted.

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoqemu: report whether a machine type is deprecated in capabilities
Daniel P. Berrangé [Fri, 22 Jan 2021 12:16:23 +0000 (12:16 +0000)]
qemu: report whether a machine type is deprecated in capabilities

QEMU has the ability to mark machine types as deprecated. This should be
exposed to management applications in the capabilities.

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoqemu: report whether a CPU model is deprecated in dom capabilities
Daniel P. Berrangé [Fri, 22 Jan 2021 11:15:08 +0000 (11:15 +0000)]
qemu: report whether a CPU model is deprecated in dom capabilities

QEMU has the ability to mark CPUs as deprecated. This should be exposed
to management applications in the domain capabilities.

This attribute is only set when the model is actually deprecated.

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agodocs: use a relative link to the kbase page
Daniel P. Berrangé [Fri, 22 Jan 2021 15:24:34 +0000 (15:24 +0000)]
docs: use a relative link to the kbase page

Reviewed-by: Andrea Bolognani <abologna@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoviralloc: Remove VIR_ALLOC_VAR
Peter Krempa [Wed, 3 Feb 2021 12:43:28 +0000 (13:43 +0100)]
viralloc: Remove VIR_ALLOC_VAR

The use case VIR_ALLOC_VAR deals with is very unlikely. We had just 2
legitimate uses, which were reimplemented locally using g_malloc0 and
sizeof instead as they used a static number of members of the trailing
array.

Remove VIR_ALLOC_VAR since in most cases the direct implementation is
shorter and clearer and there are no users of it currently.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirNetDevGetEthtoolGFeatures: Avoid use of VIR_ALLOC_VAR
Peter Krempa [Wed, 3 Feb 2021 12:33:24 +0000 (13:33 +0100)]
virNetDevGetEthtoolGFeatures: Avoid use of VIR_ALLOC_VAR

In this case we need a 'struct ethtool_gfeatures' followed by two
'struct ethtool_get_features_block' so there's no risk of overflow.

Use g_malloc0 and sizeof() to allocate the memory instead of
VIR_ALLOC_VAR.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agolocking: sanlock: Avoid use of VIR_ALLOC_VAR for 'struct sanlk_resource'
Peter Krempa [Wed, 3 Feb 2021 12:31:15 +0000 (13:31 +0100)]
locking: sanlock: Avoid use of VIR_ALLOC_VAR for 'struct sanlk_resource'

In both cases we need memory for a 'struct sanlk_resource' followed by
one 'struct sanlk_disk', thus there's no risk of overflow.

Use g_malloc0 and sizeof() to allocate the memory instead of
VIR_ALLOC_VAR.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirLockManagerSanlockAddDisk: Refactor cleanup
Peter Krempa [Wed, 3 Feb 2021 12:25:46 +0000 (13:25 +0100)]
virLockManagerSanlockAddDisk: Refactor cleanup

Use g_autofree to allow removal of 'cleanup:' and the 'ret' variable.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirLockManagerSanlockAddLease: Refactor cleanup
Peter Krempa [Wed, 3 Feb 2021 12:25:40 +0000 (13:25 +0100)]
virLockManagerSanlockAddLease: Refactor cleanup

Use g_autofree and remove the 'cleanup' section and 'ret' variable.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirNWFilterVarCombIter: Allocate 'iter' member separately
Peter Krempa [Wed, 3 Feb 2021 12:42:00 +0000 (13:42 +0100)]
virNWFilterVarCombIter: Allocate 'iter' member separately

Switch to the more common approach of having arrays allocated separately
rather than trailing the struct.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoutil: alloc: Remove VIR_DISPOSE_STRING
Peter Krempa [Tue, 2 Feb 2021 15:22:43 +0000 (16:22 +0100)]
util: alloc: Remove VIR_DISPOSE_STRING

Users were replaced with virSecureEraseString with explicit freeing of
the memory.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirnetlibsshsession: Replace VIR_DISPOSE_STRING with virSecureEraseString
Peter Krempa [Tue, 2 Feb 2021 16:22:02 +0000 (17:22 +0100)]
virnetlibsshsession: Replace VIR_DISPOSE_STRING with virSecureEraseString

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoutil: alloc: Remove VIR_AUTODISPOSE_STR
Peter Krempa [Tue, 2 Feb 2021 15:21:50 +0000 (16:21 +0100)]
util: alloc: Remove VIR_AUTODISPOSE_STR

There are no users any more. The replacement is to use g_auto and
virSecureEraseString explicitly.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirNetLibsshAuthenticatePassword: Use virSecureEraseString instead of VIR_AUTODISPOSE_STR
Peter Krempa [Tue, 2 Feb 2021 16:05:23 +0000 (17:05 +0100)]
virNetLibsshAuthenticatePassword: Use virSecureEraseString instead of VIR_AUTODISPOSE_STR

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agocmdSecretGetValue: Use virSecureEraseString instead of VIR_AUTODISPOSE_STR
Peter Krempa [Tue, 2 Feb 2021 16:05:23 +0000 (17:05 +0100)]
cmdSecretGetValue: Use virSecureEraseString instead of VIR_AUTODISPOSE_STR

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirStorageBackendRBDOpenRADOSConn: Use virSecureEraseString instead of VIR_AUTODISPOS...
Peter Krempa [Tue, 2 Feb 2021 16:05:23 +0000 (17:05 +0100)]
virStorageBackendRBDOpenRADOSConn: Use virSecureEraseString instead of VIR_AUTODISPOSE_STR

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoqemuBuildRBDSecinfoURI: Use virSecureEraseString instead of VIR_AUTODISPOSE_STR
Peter Krempa [Tue, 2 Feb 2021 16:04:30 +0000 (17:04 +0100)]
qemuBuildRBDSecinfoURI: Use virSecureEraseString instead of VIR_AUTODISPOSE_STR

In this instance attempting to be correct is really pointless since the
secret is formatted into another string which is not erased securely and
then put on the commandline.

Keep the secure handling for correctness.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agolibxlMakeNetworkDiskSrc: Use virSecureEraseString instead of VIR_AUTODISPOSE_STR
Peter Krempa [Tue, 2 Feb 2021 15:49:30 +0000 (16:49 +0100)]
libxlMakeNetworkDiskSrc: Use virSecureEraseString instead of VIR_AUTODISPOSE_STR

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoutil: virsecureerase: Introduce virSecureEraseString
Peter Krempa [Tue, 2 Feb 2021 14:49:10 +0000 (15:49 +0100)]
util: virsecureerase: Introduce virSecureEraseString

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoutil: viralloc: Remove VIR_DISPOSE(_N)
Peter Krempa [Mon, 1 Feb 2021 13:18:25 +0000 (14:18 +0100)]
util: viralloc: Remove VIR_DISPOSE(_N)

The macros are unused now and callers who care about clearing the memory
they use should use memset() appropriately.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agotests: viralloc: Remove testDispose case
Peter Krempa [Mon, 1 Feb 2021 13:16:54 +0000 (14:16 +0100)]
tests: viralloc: Remove testDispose case

The VIR_DISPOSE* APIs will be phased out. Additionally the test isn't
really doing useful work in ensuring that the values are indeed cleared
thus there's no point in keeping it around.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agostorageBackendCreateQemuImgSecretPath: Use virSecureErase instead of VIR_DISPOSE_N
Peter Krempa [Mon, 1 Feb 2021 13:13:53 +0000 (14:13 +0100)]
storageBackendCreateQemuImgSecretPath: Use virSecureErase instead of VIR_DISPOSE_N

Clear out the value using virSecureErase and free it with g_free so
that VIR_DISPOSE_N can be phased out.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirCryptoEncryptDataAESgnutls: Use virSecureErase instead of memset
Peter Krempa [Tue, 2 Feb 2021 14:44:55 +0000 (15:44 +0100)]
virCryptoEncryptDataAESgnutls: Use virSecureErase instead of memset

Clear the key and IV structs using virSecureErase.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirCryptoEncryptDataAESgnutls: Use virSecureErase instead of VIR_DISPOSE_N
Peter Krempa [Mon, 1 Feb 2021 13:13:53 +0000 (14:13 +0100)]
virCryptoEncryptDataAESgnutls: Use virSecureErase instead of VIR_DISPOSE_N

Clear out the value using virSecureErase and free it with g_free so
that VIR_DISPOSE_N can be phased out.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirStorageBackendRBDOpenRADOSConn: Use virSecureErase instead of VIR_DISPOSE_N
Peter Krempa [Mon, 1 Feb 2021 13:11:52 +0000 (14:11 +0100)]
virStorageBackendRBDOpenRADOSConn: Use virSecureErase instead of VIR_DISPOSE_N

Switch the secret value to 'g_autofree' for handling of the memory and
clear it out using virSecureErase.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirsh: cmdSecretGetValue: Use virSecureErase instead of VIR_DISPOSE_N
Peter Krempa [Mon, 1 Feb 2021 13:09:01 +0000 (14:09 +0100)]
virsh: cmdSecretGetValue: Use virSecureErase instead of VIR_DISPOSE_N

Switch the secret value to 'g_autofree' for handling of the memory and
clear it out using virSecureErase.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoqemu: domain: Use virSecureErase for clearing secrets instead of VIR_DISPOSE_N
Peter Krempa [Mon, 1 Feb 2021 11:55:27 +0000 (12:55 +0100)]
qemu: domain: Use virSecureErase for clearing secrets instead of VIR_DISPOSE_N

Phase out use of VIR_DISPOSE_N from the qemu driver. Use memset in the
appropriate cases.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agolibxlMakeNetworkDiskSrc: Avoid use of VIR_DISPOSE_N
Peter Krempa [Mon, 1 Feb 2021 11:50:00 +0000 (12:50 +0100)]
libxlMakeNetworkDiskSrc: Avoid use of VIR_DISPOSE_N

Clear the secret right after use with virSecureErase.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agostorage_backend_iscsi(_direct): Properly clear secrets
Peter Krempa [Mon, 1 Feb 2021 11:15:57 +0000 (12:15 +0100)]
storage_backend_iscsi(_direct): Properly clear secrets

The code pretends that it cares about clearing the secret values, but
passes the secret value to a realloc, which may copy the value somewhere
else and doesn't sanitize the original location when it does so.

Since we want to construct a string from the value, let's copy it to a
new piece of memory which has the space for the 'NUL' byte ourselves, to
prevent a random realloc keeping the data around.

While at it, use virSecureErase instead of VIR_DISPOSE_N since it's
being phased out.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirsh: cmdSecretSetValue: Rework handling of the secret value
Peter Krempa [Mon, 1 Feb 2021 13:01:57 +0000 (14:01 +0100)]
virsh: cmdSecretSetValue: Rework handling of the secret value

Use a single buffer for the secret to make it easier to follow it's
lifecycle. For base64 decoding use a local temporary buffer which will
be cleared right away.

This also uses virSecureErase for clearing the bufer instead of
VIR_DISPOSE_N which is being phased out.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoutil: Introduce virsecureerase module
Peter Krempa [Tue, 2 Feb 2021 14:27:22 +0000 (15:27 +0100)]
util: Introduce virsecureerase module

The module will provide functions for disposing secrets stored in
memory.

Note that for now it's implemented using memset, which is not really
secure.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirNetLibsshSessionAuthAddPrivKeyAuth: Refactor cleanup
Peter Krempa [Tue, 2 Feb 2021 15:00:28 +0000 (16:00 +0100)]
virNetLibsshSessionAuthAddPrivKeyAuth: Refactor cleanup

Shuffle the code around to remove the need for temporary variables and
labels for cleaning them.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovirNetLibsshSessionAuthAddPrivKeyAuth: Don't unlock unlocked 'sess' on error
Peter Krempa [Tue, 2 Feb 2021 14:57:06 +0000 (15:57 +0100)]
virNetLibsshSessionAuthAddPrivKeyAuth: Don't unlock unlocked 'sess' on error

The check whether @keyfile is non-NULL is before locking @sess, but uses
the 'error' label which unlocks '@sess'.

While touching the error path, update the error message to be on one
line.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agocmdSecretSetValue: Make it obvious that --file, --base64 and --interactive are exlcusive
Peter Krempa [Mon, 1 Feb 2021 12:10:59 +0000 (13:10 +0100)]
cmdSecretSetValue: Make it obvious that --file, --base64 and --interactive are exlcusive

Convert the conditions to else if so that it's obvious that only one of
the cases will ever be used.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoqemuDomainMasterKeyCreate: Don't use VIR_DISPOSE_N on failure
Peter Krempa [Mon, 1 Feb 2021 11:52:07 +0000 (12:52 +0100)]
qemuDomainMasterKeyCreate: Don't use VIR_DISPOSE_N on failure

When virRandomBytes fails we don't get any random bytes and even if we
did they don't have to be treated as secret as they weren't used in any
way.

Add a temporary variable with automatic freeing for the secret buffer
and assign it only on success.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agolibxlMakeDomBuildInfo: Don't use VIR_DISPOSE_N for USB device list
Peter Krempa [Mon, 1 Feb 2021 11:12:42 +0000 (12:12 +0100)]
libxlMakeDomBuildInfo: Don't use VIR_DISPOSE_N for USB device list

The list isn't secret which would need being disposed of. Just expand
the array and return failure when adding the NULL terminator similarly
to how we expand the list for adding devices in a loop.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agohypervFreeInvokeParams: Don't use VIR_DISPOSE_N for freeing 'params'
Peter Krempa [Mon, 1 Feb 2021 11:08:13 +0000 (12:08 +0100)]
hypervFreeInvokeParams: Don't use VIR_DISPOSE_N for freeing 'params'

The struct doesn't contain any secrets to clear before freeing and even
if it did VIR_DISPOSE_N wouldn't help as the struct contains only
pointers thus the actual memory pointing to isn't sanitized.

Just free the params array pointer and then the struct itself.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agoconf: add realtime parameter for rtc
gongwei [Tue, 2 Feb 2021 14:20:46 +0000 (09:20 -0500)]
conf: add realtime parameter for rtc

Pass the parameter clock rt to qemu to ensure that the
virtual machine is not synchronized with the host time

Signed-off-by: gongwei <gongwei@smartx.com>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agoutil: virstring: Remove unused prototypes for virStr(n)dup
Peter Krempa [Mon, 1 Feb 2021 13:46:46 +0000 (14:46 +0100)]
util: virstring: Remove unused prototypes for virStr(n)dup

The headers weren't removed after use of VIR_STRDUP was removed.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
4 years agovircommand: Simplify virCommandAddArg
Tim Wiederhake [Mon, 1 Feb 2021 12:42:07 +0000 (13:42 +0100)]
vircommand: Simplify virCommandAddArg

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agovircryptotest: Directly assign string to avoid memcpy
Tim Wiederhake [Mon, 1 Feb 2021 12:42:06 +0000 (13:42 +0100)]
vircryptotest: Directly assign string to avoid memcpy

Found by clang-tidy's "bugprone-not-null-terminated-result" check.

clang-tidy's finding is a false positive in this case, as the
memset call guarantees null termination. The assignment can be
simplified though, and this happens to silence the warning.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agotests: Prevent malloc with size 0
Tim Wiederhake [Mon, 1 Feb 2021 12:42:05 +0000 (13:42 +0100)]
tests: Prevent malloc with size 0

Found by clang-tidy's "clang-analyzer-optin.portability.UnixAPI" check.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agovirhostuptime: Fix rounding in uptime calculation
Tim Wiederhake [Mon, 1 Feb 2021 12:42:04 +0000 (13:42 +0100)]
virhostuptime: Fix rounding in uptime calculation

"f + 0.5" does not round correctly for values very close to
".5" for every integer multiple, e.g. "0.499999975".

Found by clang-tidy's "bugprone-incorrect-roundings" check.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agoudevProcessCCW: Initialize variable
Tim Wiederhake [Mon, 1 Feb 2021 12:42:03 +0000 (13:42 +0100)]
udevProcessCCW: Initialize variable

`udevGetIntSysfsAttr` does not necessarily write to the third parameter,
even when it returns 0.

This was found by clang-tidy's
"clang-analyzer-core.UndefinedBinaryOperatorResult" check.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agoReplace bzero() with memset()
Tim Wiederhake [Mon, 1 Feb 2021 12:42:02 +0000 (13:42 +0100)]
Replace bzero() with memset()

This was found by clang-tidy's
"clang-analyzer-security.insecureAPI.bzero" check.

bzero is marked as deprecated ("LEGACY") in POSIX.1-2001 and
removed in POSIX.1-2008.

Besides its deprecation, bzero can be unsafe to use under certain
circumstances, e.g. when used to zero-out memory containing secrects.
These calls can be optimized away by the compiler, if it concludes no
further access happens to the memory, thus leaving the secrets still
in memory. Hence its classification as "insecureAPI".

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agovirsh-domain: Fix error handling of pthread_sigmask
Tim Wiederhake [Mon, 1 Feb 2021 12:42:01 +0000 (13:42 +0100)]
virsh-domain: Fix error handling of pthread_sigmask

pthread_sigmask() returns 0 on success and "a non-zero value
on failure", but not neccessarily a negative one.

Found by clang-tidy's "bugprone-posix-return" check.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agoqemu_tpm: Fix indentation in qemuTPMEmulatorBuildCommand
Tim Wiederhake [Mon, 1 Feb 2021 12:42:00 +0000 (13:42 +0100)]
qemu_tpm: Fix indentation in qemuTPMEmulatorBuildCommand

This was found by clang-tidy's "readability-misleading-indentation"
check.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agoxen: Fix indentation in xenParseXLSpice
Tim Wiederhake [Mon, 1 Feb 2021 12:41:59 +0000 (13:41 +0100)]
xen: Fix indentation in xenParseXLSpice

This was found by clang-tidy's "readability-misleading-indentation"
check.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agovirfile: Remove redundant #ifndef
Tim Wiederhake [Mon, 1 Feb 2021 12:41:58 +0000 (13:41 +0100)]
virfile: Remove redundant #ifndef

This section is guarded by "#ifndef WIN32" in line 2109--2808.

Found by clang-tidy's "readability-redundant-preprocessor" check.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Use automatic memory management in main
Tim Wiederhake [Mon, 1 Feb 2021 11:28:04 +0000 (12:28 +0100)]
commandhelper: Use automatic memory management in main

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Use automatic memory management in printInput
Tim Wiederhake [Mon, 1 Feb 2021 11:28:03 +0000 (12:28 +0100)]
commandhelper: Use automatic memory management in printInput

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Use automatic memory management in printCwd
Tim Wiederhake [Mon, 1 Feb 2021 11:28:02 +0000 (12:28 +0100)]
commandhelper: Use automatic memory management in printCwd

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Use automatic memory management in printEnvironment
Tim Wiederhake [Mon, 1 Feb 2021 11:28:01 +0000 (12:28 +0100)]
commandhelper: Use automatic memory management in printEnvironment

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Use automatic memory management in parseArguments
Tim Wiederhake [Mon, 1 Feb 2021 11:28:00 +0000 (12:28 +0100)]
commandhelper: Use automatic memory management in parseArguments

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Make number of fds variable in parseArguments
Tim Wiederhake [Mon, 1 Feb 2021 11:27:59 +0000 (12:27 +0100)]
commandhelper: Make number of fds variable in parseArguments

Fixes a buffer overflow triggered when more than three "--readfd"
arguments were given on the command line.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Make number of fds variable in printInput
Tim Wiederhake [Mon, 1 Feb 2021 11:27:58 +0000 (12:27 +0100)]
commandhelper: Make number of fds variable in printInput

Fixes a buffer overflow triggered when more than three "--readfd"
arguments were given on the command line.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Factor out printInput
Tim Wiederhake [Mon, 1 Feb 2021 11:27:57 +0000 (12:27 +0100)]
commandhelper: Factor out printInput

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Factor out printCwd
Tim Wiederhake [Mon, 1 Feb 2021 11:27:56 +0000 (12:27 +0100)]
commandhelper: Factor out printCwd

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Factor out printDaemonization
Tim Wiederhake [Mon, 1 Feb 2021 11:27:55 +0000 (12:27 +0100)]
commandhelper: Factor out printDaemonization

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Factor out printFds
Tim Wiederhake [Mon, 1 Feb 2021 11:27:54 +0000 (12:27 +0100)]
commandhelper: Factor out printFds

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Factor out printEnvironment
Tim Wiederhake [Mon, 1 Feb 2021 11:27:53 +0000 (12:27 +0100)]
commandhelper: Factor out printEnvironment

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Factor out printArguments
Tim Wiederhake [Mon, 1 Feb 2021 11:27:52 +0000 (12:27 +0100)]
commandhelper: Factor out printArguments

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Factor out parseArguments
Tim Wiederhake [Mon, 1 Feb 2021 11:27:51 +0000 (12:27 +0100)]
commandhelper: Factor out parseArguments

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Split argument parsing and printing
Tim Wiederhake [Mon, 1 Feb 2021 11:27:50 +0000 (12:27 +0100)]
commandhelper: Split argument parsing and printing

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Consolidate argument parsing
Tim Wiederhake [Mon, 1 Feb 2021 11:27:49 +0000 (12:27 +0100)]
commandhelper: Consolidate argument parsing

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Consolidate error paths
Tim Wiederhake [Mon, 1 Feb 2021 11:27:48 +0000 (12:27 +0100)]
commandhelper: Consolidate error paths

Preparation for later conversion to g_auto* memory handling.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Simplify envsort
Tim Wiederhake [Mon, 1 Feb 2021 11:27:47 +0000 (12:27 +0100)]
commandhelper: Simplify envsort

This saves two invocations of each `strndup` and `free`.

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Remove numpollfds variable
Tim Wiederhake [Mon, 1 Feb 2021 11:27:46 +0000 (12:27 +0100)]
commandhelper: Remove numpollfds variable

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agocommandhelper: Remove origenv variable
Tim Wiederhake [Mon, 1 Feb 2021 11:27:45 +0000 (12:27 +0100)]
commandhelper: Remove origenv variable

Signed-off-by: Tim Wiederhake <twiederh@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
4 years agonews: implement new Hyper-V APIs
Matt Coleman [Tue, 2 Feb 2021 00:48:48 +0000 (19:48 -0500)]
news: implement new Hyper-V APIs

Signed-off-by: Matt Coleman <matt@datto.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agohyperv: provide a more detailed error message for WSMan faults
Matt Coleman [Tue, 2 Feb 2021 00:48:47 +0000 (19:48 -0500)]
hyperv: provide a more detailed error message for WSMan faults

Signed-off-by: Matt Coleman <matt@datto.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agohyperv: implement domainScreenshot
Matt Coleman [Tue, 2 Feb 2021 00:48:46 +0000 (19:48 -0500)]
hyperv: implement domainScreenshot

Signed-off-by: Matt Coleman <matt@datto.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agohyperv: implement networkGetXMLDesc
Matt Coleman [Tue, 2 Feb 2021 00:48:45 +0000 (19:48 -0500)]
hyperv: implement networkGetXMLDesc

Co-authored-by: Dawid Zamirski <dzamirski@datto.com>
Signed-off-by: Matt Coleman <matt@datto.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agohyperv: implement networkGetAutostart, networkIsActive, and networkIsPersistent
Matt Coleman [Tue, 2 Feb 2021 00:48:44 +0000 (19:48 -0500)]
hyperv: implement networkGetAutostart, networkIsActive, and networkIsPersistent

Co-authored-by: Dawid Zamirski <dzamirski@datto.com>
Signed-off-by: Matt Coleman <matt@datto.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agohyperv: implement connectNumOfDefinedNetworks and connectListDefinedNetworks
Matt Coleman [Tue, 2 Feb 2021 00:48:43 +0000 (19:48 -0500)]
hyperv: implement connectNumOfDefinedNetworks and connectListDefinedNetworks

Co-authored-by: Dawid Zamirski <dzamirski@datto.com>
Signed-off-by: Matt Coleman <matt@datto.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agohyperv: implement networkLookupByName and networkLookupByUUID
Matt Coleman [Tue, 2 Feb 2021 00:48:42 +0000 (19:48 -0500)]
hyperv: implement networkLookupByName and networkLookupByUUID

Signed-off-by: Matt Coleman <matt@datto.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agohyperv: implement connectListAllNetworks and connectNumOfNetworks
Matt Coleman [Tue, 2 Feb 2021 00:48:41 +0000 (19:48 -0500)]
hyperv: implement connectListAllNetworks and connectNumOfNetworks

Co-authored-by: Dawid Zamirski <dzamirski@datto.com>
Signed-off-by: Matt Coleman <matt@datto.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agohyperv: add support for creating network adapters
Matt Coleman [Tue, 2 Feb 2021 00:48:40 +0000 (19:48 -0500)]
hyperv: add support for creating network adapters

Co-authored-by: Sri Ramanujam <sramanujam@datto.com>
Signed-off-by: Matt Coleman <matt@datto.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 years agohyperv: XML parsing of Ethernet adapters
Matt Coleman [Tue, 2 Feb 2021 00:48:39 +0000 (19:48 -0500)]
hyperv: XML parsing of Ethernet adapters

Co-authored-by: Sri Ramanujam <sramanujam@datto.com>
Signed-off-by: Matt Coleman <matt@datto.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>