qemu_hotplug.c 94.3 KB
Newer Older
1 2 3
/*
 * qemu_hotplug.h: QEMU device hotplug management
 *
4
 * Copyright (C) 2006-2012 Red Hat, Inc.
5 6 7 8 9 10 11 12 13 14 15 16 17
 * Copyright (C) 2006 Daniel P. Berrange
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
18
 * License along with this library.  If not, see
O
Osier Yang 已提交
19
 * <http://www.gnu.org/licenses/>.
20 21 22 23 24 25 26 27 28 29 30 31 32
 *
 * Author: Daniel P. Berrange <berrange@redhat.com>
 */


#include <config.h>

#include "qemu_hotplug.h"
#include "qemu_capabilities.h"
#include "qemu_domain.h"
#include "qemu_command.h"
#include "qemu_bridge_filter.h"
#include "qemu_hostdev.h"
33
#include "domain_audit.h"
34
#include "domain_nwfilter.h"
35
#include "virlog.h"
36
#include "datatypes.h"
37
#include "virerror.h"
38
#include "viralloc.h"
39
#include "virpci.h"
E
Eric Blake 已提交
40
#include "virfile.h"
41
#include "qemu_cgroup.h"
42
#include "locking/domain_lock.h"
43
#include "network/bridge_driver.h"
44 45
#include "virnetdev.h"
#include "virnetdevbridge.h"
A
Ansis Atteka 已提交
46
#include "virnetdevtap.h"
47
#include "device_conf.h"
48
#include "virstoragefile.h"
49 50 51

#define VIR_FROM_THIS VIR_FROM_QEMU

52
int qemuDomainChangeEjectableMedia(virQEMUDriverPtr driver,
53 54 55 56 57 58 59 60
                                   virDomainObjPtr vm,
                                   virDomainDiskDefPtr disk,
                                   bool force)
{
    virDomainDiskDefPtr origdisk = NULL;
    int i;
    int ret;
    char *driveAlias = NULL;
61
    qemuDomainObjPrivatePtr priv = vm->privateData;
62 63 64 65 66 67 68 69 70 71

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (vm->def->disks[i]->bus == disk->bus &&
            STREQ(vm->def->disks[i]->dst, disk->dst)) {
            origdisk = vm->def->disks[i];
            break;
        }
    }

    if (!origdisk) {
72 73 74 75
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No device with bus '%s' and target '%s'"),
                       virDomainDiskBusTypeToString(disk->bus),
                       disk->dst);
76 77 78 79
        return -1;
    }

    if (!origdisk->info.alias) {
80 81
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("missing disk device alias name for %s"), origdisk->dst);
82 83 84 85 86
        return -1;
    }

    if (origdisk->device != VIR_DOMAIN_DISK_DEVICE_FLOPPY &&
        origdisk->device != VIR_DOMAIN_DISK_DEVICE_CDROM) {
87 88
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Removable media not supported for %s device"),
89 90 91 92
                        virDomainDiskDeviceTypeToString(disk->device));
        return -1;
    }

93 94
    if (virDomainLockDiskAttach(driver->lockManager, driver->uri,
                                vm, disk) < 0)
95 96
        return -1;

97
    if (virSecurityManagerSetImageLabel(driver->securityManager,
98
                                        vm->def, disk) < 0) {
99 100
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
101
        return -1;
102
    }
103

104
    if (!(driveAlias = qemuDeviceDriveHostAlias(origdisk, priv->caps)))
105 106
        goto error;

107
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
108 109 110
    if (disk->src) {
        const char *format = NULL;
        if (disk->type != VIR_DOMAIN_DISK_TYPE_DIR) {
111 112 113 114
            if (disk->format > 0)
                format = virStorageFileFormatTypeToString(disk->format);
            else if (origdisk->format > 0)
                format = virStorageFileFormatTypeToString(origdisk->format);
115 116 117 118 119 120 121 122 123
        }
        ret = qemuMonitorChangeMedia(priv->mon,
                                     driveAlias,
                                     disk->src, format);
    } else {
        ret = qemuMonitorEjectMedia(priv->mon, driveAlias, force);
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

124
    virDomainAuditDisk(vm, origdisk->src, disk->src, "update", ret >= 0);
125 126 127 128

    if (ret < 0)
        goto error;

129
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
130
                                            vm->def, origdisk) < 0)
131 132
        VIR_WARN("Unable to restore security label on ejected image %s", origdisk->src);

133 134 135
    if (virDomainLockDiskDetach(driver->lockManager, vm, origdisk) < 0)
        VIR_WARN("Unable to release lock on disk %s", origdisk->src);

136 137 138 139 140 141 142 143 144 145 146 147 148
    VIR_FREE(origdisk->src);
    origdisk->src = disk->src;
    disk->src = NULL;
    origdisk->type = disk->type;

    VIR_FREE(driveAlias);

    virDomainDiskDefFree(disk);

    return ret;

error:
    VIR_FREE(driveAlias);
149

150
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
151
                                            vm->def, disk) < 0)
152
        VIR_WARN("Unable to restore security label on new media %s", disk->src);
153 154 155 156

    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

157 158 159
    return -1;
}

160
int
161
qemuDomainCheckEjectableMedia(virQEMUDriverPtr driver,
162 163
                             virDomainObjPtr vm,
                             enum qemuDomainAsyncJob asyncJob)
164 165
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
166
    virHashTablePtr table = NULL;
167 168 169
    int ret = -1;
    int i;

170 171 172 173
    if (qemuDomainObjEnterMonitorAsync(driver, vm, asyncJob) == 0) {
        table = qemuMonitorGetBlockInfo(priv->mon);
        qemuDomainObjExitMonitorWithDriver(driver, vm);
    }
174 175 176 177

    if (!table)
        goto cleanup;

178 179
    for (i = 0; i < vm->def->ndisks; i++) {
        virDomainDiskDefPtr disk = vm->def->disks[i];
180
        struct qemuDomainDiskInfo *info;
181

182 183
        if (disk->device == VIR_DOMAIN_DISK_DEVICE_DISK ||
            disk->device == VIR_DOMAIN_DISK_DEVICE_LUN) {
184
                 continue;
185
        }
186

187 188
        info = qemuMonitorBlockInfoLookup(table, disk->info.alias);
        if (!info)
189 190
            goto cleanup;

191
        if (info->tray_open && disk->src)
192 193 194 195 196 197
            VIR_FREE(disk->src);
    }

    ret = 0;

cleanup:
198
    virHashFree(table);
199 200 201
    return ret;
}

202

203
int qemuDomainAttachPciDiskDevice(virConnectPtr conn,
204
                                  virQEMUDriverPtr driver,
205
                                  virDomainObjPtr vm,
206
                                  virDomainDiskDefPtr disk)
207 208 209 210 211 212
{
    int i, ret;
    const char* type = virDomainDiskBusTypeToString(disk->bus);
    qemuDomainObjPrivatePtr priv = vm->privateData;
    char *devstr = NULL;
    char *drivestr = NULL;
213
    bool releaseaddr = false;
214 215 216

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (STREQ(vm->def->disks[i]->dst, disk->dst)) {
217 218
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("target %s already exists"), disk->dst);
219 220 221 222
            return -1;
        }
    }

223 224
    if (virDomainLockDiskAttach(driver->lockManager, driver->uri,
                                vm, disk) < 0)
225 226
        return -1;

227
    if (virSecurityManagerSetImageLabel(driver->securityManager,
228
                                        vm->def, disk) < 0) {
229 230
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
231
        return -1;
232
    }
233

234
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
235 236
        if (qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, &disk->info) < 0)
            goto error;
237
        releaseaddr = true;
238
        if (qemuAssignDeviceDiskAlias(vm->def, disk, priv->caps) < 0)
239 240
            goto error;

241
        if (!(drivestr = qemuBuildDriveStr(conn, disk, false, priv->caps)))
242 243
            goto error;

244
        if (!(devstr = qemuBuildDriveDevStr(NULL, disk, 0, priv->caps)))
245 246 247 248 249 250 251 252
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0) {
        virReportOOMError();
        goto error;
    }

253
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
254
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
255 256 257 258
        ret = qemuMonitorAddDrive(priv->mon, drivestr);
        if (ret == 0) {
            ret = qemuMonitorAddDevice(priv->mon, devstr);
            if (ret < 0) {
259 260 261 262 263 264 265 266 267 268
                virErrorPtr orig_err = virSaveLastError();
                if (qemuMonitorDriveDel(priv->mon, drivestr) < 0) {
                    VIR_WARN("Unable to remove drive %s (%s) after failed "
                             "qemuMonitorAddDevice",
                             drivestr, devstr);
                }
                if (orig_err) {
                    virSetError(orig_err);
                    virFreeError(orig_err);
                }
269 270 271
            }
        }
    } else {
272
        virDevicePCIAddress guestAddr = disk->info.addr.pci;
273 274 275 276 277 278 279 280 281 282 283
        ret = qemuMonitorAddPCIDisk(priv->mon,
                                    disk->src,
                                    type,
                                    &guestAddr);
        if (ret == 0) {
            disk->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
            memcpy(&disk->info.addr.pci, &guestAddr, sizeof(guestAddr));
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

284
    virDomainAuditDisk(vm, NULL, disk->src, "attach", ret >= 0);
285 286 287 288 289 290 291 292 293 294 295 296 297 298 299

    if (ret < 0)
        goto error;

    virDomainDiskInsertPreAlloced(vm->def, disk);

    VIR_FREE(devstr);
    VIR_FREE(drivestr);

    return 0;

error:
    VIR_FREE(devstr);
    VIR_FREE(drivestr);

300
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
301
        (disk->info.type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
302
        releaseaddr &&
303 304
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        disk->info.addr.pci.slot) < 0)
305 306
        VIR_WARN("Unable to release PCI address on %s", disk->src);

307
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
308
                                            vm->def, disk) < 0)
309 310
        VIR_WARN("Unable to restore security label on %s", disk->src);

311 312 313
    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

314 315 316 317
    return -1;
}


318
int qemuDomainAttachPciControllerDevice(virQEMUDriverPtr driver,
319
                                        virDomainObjPtr vm,
320
                                        virDomainControllerDefPtr controller)
321 322 323 324 325
{
    int ret = -1;
    const char* type = virDomainControllerTypeToString(controller->type);
    char *devstr = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
326
    bool releaseaddr = false;
327

328 329 330 331 332
    if (virDomainControllerFind(vm->def, controller->type, controller->idx) > 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("target %s:%d already exists"),
                       type, controller->idx);
        return -1;
333 334
    }

335
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
336 337
        if (qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, &controller->info) < 0)
            goto cleanup;
338
        releaseaddr = true;
339 340 341
        if (qemuAssignDeviceControllerAlias(controller) < 0)
            goto cleanup;

342 343
        if (controller->type == VIR_DOMAIN_CONTROLLER_TYPE_USB &&
            controller->model == -1 &&
344
            !qemuCapsGet(priv->caps, QEMU_CAPS_PIIX3_USB_UHCI)) {
345 346
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                           _("USB controller hotplug unsupported in this QEMU binary"));
347 348 349
            goto cleanup;
        }

350
        if (!(devstr = qemuBuildControllerDevStr(vm->def, controller, priv->caps, NULL))) {
351 352 353 354 355 356 357 358 359
            goto cleanup;
        }
    }

    if (VIR_REALLOC_N(vm->def->controllers, vm->def->ncontrollers+1) < 0) {
        virReportOOMError();
        goto cleanup;
    }

360
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
361
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
362 363 364 365 366 367 368 369 370 371 372 373 374 375 376
        ret = qemuMonitorAddDevice(priv->mon, devstr);
    } else {
        ret = qemuMonitorAttachPCIDiskController(priv->mon,
                                                 type,
                                                 &controller->info.addr.pci);
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    if (ret == 0) {
        controller->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
        virDomainControllerInsertPreAlloced(vm->def, controller);
    }

cleanup:
    if ((ret != 0) &&
377
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
378
        (controller->info.type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
379
        releaseaddr &&
380 381
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        controller->info.addr.pci.slot) < 0)
382
        VIR_WARN("Unable to release PCI address on controller");
383 384 385 386 387 388 389

    VIR_FREE(devstr);
    return ret;
}


static virDomainControllerDefPtr
390
qemuDomainFindOrCreateSCSIDiskController(virQEMUDriverPtr driver,
391
                                         virDomainObjPtr vm,
392
                                         int controller)
393 394 395
{
    int i;
    virDomainControllerDefPtr cont;
396

397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413
    for (i = 0 ; i < vm->def->ncontrollers ; i++) {
        cont = vm->def->controllers[i];

        if (cont->type != VIR_DOMAIN_CONTROLLER_TYPE_SCSI)
            continue;

        if (cont->idx == controller)
            return cont;
    }

    /* No SCSI controller present, for backward compatibility we
     * now hotplug a controller */
    if (VIR_ALLOC(cont) < 0) {
        virReportOOMError();
        return NULL;
    }
    cont->type = VIR_DOMAIN_CONTROLLER_TYPE_SCSI;
414
    cont->idx = controller;
415 416
    cont->model = -1;

417
    VIR_INFO("No SCSI controller present, hotplugging one");
418
    if (qemuDomainAttachPciControllerDevice(driver,
419
                                            vm, cont) < 0) {
420 421 422 423 424
        VIR_FREE(cont);
        return NULL;
    }

    if (!virDomainObjIsActive(vm)) {
425 426
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("guest unexpectedly quit"));
427 428 429 430 431 432 433 434 435
        /* cont doesn't need freeing here, since the reference
         * now held in def->controllers */
        return NULL;
    }

    return cont;
}


436
int qemuDomainAttachSCSIDisk(virConnectPtr conn,
437
                             virQEMUDriverPtr driver,
438
                             virDomainObjPtr vm,
439
                             virDomainDiskDefPtr disk)
440 441 442 443 444 445 446 447 448 449
{
    int i;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    virDomainControllerDefPtr cont = NULL;
    char *drivestr = NULL;
    char *devstr = NULL;
    int ret = -1;

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (STREQ(vm->def->disks[i]->dst, disk->dst)) {
450 451
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("target %s already exists"), disk->dst);
452 453 454 455
            return -1;
        }
    }

456 457
    if (virDomainLockDiskAttach(driver->lockManager, driver->uri,
                                vm, disk) < 0)
458
        return -1;
459

460
    if (virSecurityManagerSetImageLabel(driver->securityManager,
461
                                        vm->def, disk) < 0) {
462 463
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
464
        return -1;
465
    }
466 467 468

    /* We should have an address already, so make sure */
    if (disk->info.type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_DRIVE) {
469 470 471
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unexpected disk address type %s"),
                       virDomainDeviceAddressTypeToString(disk->info.type));
472 473 474
        goto error;
    }

475 476
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (qemuAssignDeviceDiskAlias(vm->def, disk, priv->caps) < 0)
477
            goto error;
478
        if (!(devstr = qemuBuildDriveDevStr(vm->def, disk, 0, priv->caps)))
479 480 481
            goto error;
    }

482
    if (!(drivestr = qemuBuildDriveStr(conn, disk, false, priv->caps)))
483 484 485
        goto error;

    for (i = 0 ; i <= disk->info.addr.drive.controller ; i++) {
486
        cont = qemuDomainFindOrCreateSCSIDiskController(driver, vm, i);
487 488 489 490 491 492 493
        if (!cont)
            goto error;
    }

    /* Tell clang that "cont" is non-NULL.
       This is because disk->info.addr.driver.controller is unsigned,
       and hence the above loop must iterate at least once.  */
494
    sa_assert(cont);
495 496

    if (cont->info.type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) {
497 498
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("SCSI controller %d was missing its PCI address"), cont->idx);
499 500 501 502 503 504 505 506
        goto error;
    }

    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0) {
        virReportOOMError();
        goto error;
    }

507
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
508
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528
        ret = qemuMonitorAddDrive(priv->mon, drivestr);
        if (ret == 0) {
            ret = qemuMonitorAddDevice(priv->mon, devstr);
            if (ret < 0) {
                VIR_WARN("qemuMonitorAddDevice failed on %s (%s)",
                         drivestr, devstr);
                /* XXX should call 'drive_del' on error but this does not
                   exist yet */
            }
        }
    } else {
        virDomainDeviceDriveAddress driveAddr;
        ret = qemuMonitorAttachDrive(priv->mon,
                                     drivestr,
                                     &cont->info.addr.pci,
                                     &driveAddr);
        if (ret == 0) {
            /* XXX we should probably validate that the addr matches
             * our existing defined addr instead of overwriting */
            disk->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_DRIVE;
529 530
            disk->info.addr.drive.bus = driveAddr.bus;
            disk->info.addr.drive.unit = driveAddr.unit;
531 532 533 534
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

535
    virDomainAuditDisk(vm, NULL, disk->src, "attach", ret >= 0);
536 537 538 539 540 541 542 543 544 545 546 547 548 549 550

    if (ret < 0)
        goto error;

    virDomainDiskInsertPreAlloced(vm->def, disk);

    VIR_FREE(devstr);
    VIR_FREE(drivestr);

    return 0;

error:
    VIR_FREE(devstr);
    VIR_FREE(drivestr);

551
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
552
                                            vm->def, disk) < 0)
553 554
        VIR_WARN("Unable to restore security label on %s", disk->src);

555 556 557
    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

558 559 560 561
    return -1;
}


562
int qemuDomainAttachUsbMassstorageDevice(virConnectPtr conn,
563
                                         virQEMUDriverPtr driver,
564
                                         virDomainObjPtr vm,
565
                                         virDomainDiskDefPtr disk)
566 567 568 569 570 571 572 573
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    int i, ret;
    char *drivestr = NULL;
    char *devstr = NULL;

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (STREQ(vm->def->disks[i]->dst, disk->dst)) {
574 575
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("target %s already exists"), disk->dst);
576 577 578 579
            return -1;
        }
    }

580 581
    if (virDomainLockDiskAttach(driver->lockManager, driver->uri,
                                vm, disk) < 0)
582 583
        return -1;

584
    if (virSecurityManagerSetImageLabel(driver->securityManager,
585
                                        vm->def, disk) < 0) {
586 587
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
588
        return -1;
589
    }
590

591
    /* XXX not correct once we allow attaching a USB CDROM */
592
    if (!disk->src) {
593 594
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       "%s", _("disk source path is missing"));
595 596 597
        goto error;
    }

598 599
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (qemuAssignDeviceDiskAlias(vm->def, disk, priv->caps) < 0)
600
            goto error;
601
        if (!(drivestr = qemuBuildDriveStr(conn, disk, false, priv->caps)))
602
            goto error;
603
        if (!(devstr = qemuBuildDriveDevStr(NULL, disk, 0, priv->caps)))
604 605 606 607 608 609 610 611
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0) {
        virReportOOMError();
        goto error;
    }

612
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
613
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
614 615 616 617 618 619 620 621 622 623 624 625 626 627 628
        ret = qemuMonitorAddDrive(priv->mon, drivestr);
        if (ret == 0) {
            ret = qemuMonitorAddDevice(priv->mon, devstr);
            if (ret < 0) {
                VIR_WARN("qemuMonitorAddDevice failed on %s (%s)",
                         drivestr, devstr);
                /* XXX should call 'drive_del' on error but this does not
                   exist yet */
            }
        }
    } else {
        ret = qemuMonitorAddUSBDisk(priv->mon, disk->src);
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

629
    virDomainAuditDisk(vm, NULL, disk->src, "attach", ret >= 0);
630 631 632 633 634 635 636 637 638 639 640 641 642 643 644

    if (ret < 0)
        goto error;

    virDomainDiskInsertPreAlloced(vm->def, disk);

    VIR_FREE(devstr);
    VIR_FREE(drivestr);

    return 0;

error:
    VIR_FREE(devstr);
    VIR_FREE(drivestr);

645
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
646
                                            vm->def, disk) < 0)
647 648
        VIR_WARN("Unable to restore security label on %s", disk->src);

649 650 651
    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

652 653 654 655 656 657
    return -1;
}


/* XXX conn required for network -> bridge resolution */
int qemuDomainAttachNetDevice(virConnectPtr conn,
658
                              virQEMUDriverPtr driver,
659
                              virDomainObjPtr vm,
660
                              virDomainNetDefPtr net)
661 662 663 664
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    char *tapfd_name = NULL;
    int tapfd = -1;
665 666
    char *vhostfd_name = NULL;
    int vhostfd = -1;
667 668
    char *nicstr = NULL;
    char *netstr = NULL;
A
Ansis Atteka 已提交
669
    virNetDevVPortProfilePtr vport = NULL;
670
    int ret = -1;
671
    virDevicePCIAddress guestAddr;
672
    int vlan;
673
    bool releaseaddr = false;
674 675
    bool iface_connected = false;
    int actualType;
676

677 678 679
    /* preallocate new slot for device */
    if (VIR_REALLOC_N(vm->def->nets, vm->def->nnets+1) < 0) {
        virReportOOMError();
680 681 682
        return -1;
    }

683 684 685 686 687
    /* If appropriate, grab a physical device from the configured
     * network's pool of devices, or resolve bridge device name
     * to the one defined in the network definition.
     */
    if (networkAllocateActualDevice(net) < 0)
688
        return -1;
689 690

    actualType = virDomainNetGetActualType(net);
691 692 693 694 695 696 697 698 699 700 701 702

    if (actualType == VIR_DOMAIN_NET_TYPE_HOSTDEV) {
        /* This is really a "smart hostdev", so it should be attached
         * as a hostdev (the hostdev code will reach over into the
         * netdev-specific code as appropriate), then also added to
         * the nets list (see cleanup:) if successful.
         */
        ret = qemuDomainAttachHostDevice(driver, vm,
                                         virDomainNetGetActualHostdev(net));
        goto cleanup;
    }

703
    if (!qemuCapsGet(priv->caps, QEMU_CAPS_HOST_NET_ADD)) {
704 705
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("installed qemu version does not support host_net_add"));
706 707 708
        goto cleanup;
    }

709 710
    if (actualType == VIR_DOMAIN_NET_TYPE_BRIDGE ||
        actualType == VIR_DOMAIN_NET_TYPE_NETWORK) {
R
Richa Marwaha 已提交
711 712 713 714 715 716 717
        /*
         * If type=bridge then we attempt to allocate the tap fd here only if
         * running under a privilged user or -netdev bridge option is not
         * supported.
         */
        if (actualType == VIR_DOMAIN_NET_TYPE_NETWORK ||
            driver->privileged ||
718
            (!qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV_BRIDGE))) {
R
Richa Marwaha 已提交
719
            if ((tapfd = qemuNetworkIfaceConnect(vm->def, conn, driver, net,
720
                                                 priv->caps)) < 0)
R
Richa Marwaha 已提交
721 722
                goto cleanup;
            iface_connected = true;
723
            if (qemuOpenVhostNet(vm->def, net, priv->caps, &vhostfd) < 0)
R
Richa Marwaha 已提交
724 725
                goto cleanup;
        }
726
    } else if (actualType == VIR_DOMAIN_NET_TYPE_DIRECT) {
727
        if ((tapfd = qemuPhysIfaceConnect(vm->def, driver, net,
728
                                          priv->caps,
729
                                          VIR_NETDEV_VPORT_PROFILE_OP_CREATE)) < 0)
730 731
            goto cleanup;
        iface_connected = true;
732
        if (qemuOpenVhostNet(vm->def, net, priv->caps, &vhostfd) < 0)
733
            goto cleanup;
734 735
    }

736 737
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NET_NAME) ||
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
738 739 740 741
        if (qemuAssignDeviceNetAlias(vm->def, net, -1) < 0)
            goto cleanup;
    }

742
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
743 744 745
        qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, &net->info) < 0)
        goto cleanup;

746 747
    releaseaddr = true;

748 749
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
750 751 752 753 754
        vlan = -1;
    } else {
        vlan = qemuDomainNetVLAN(net);

        if (vlan < 0) {
755 756
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                           _("Unable to attach network devices without vlan"));
757 758 759 760 761 762 763 764 765
            goto cleanup;
        }
    }

    if (tapfd != -1) {
        if (virAsprintf(&tapfd_name, "fd-%s", net->info.alias) < 0)
            goto no_memory;
    }

766 767 768 769 770
    if (vhostfd != -1) {
        if (virAsprintf(&vhostfd_name, "vhostfd-%s", net->info.alias) < 0)
            goto no_memory;
    }

771 772 773
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (!(netstr = qemuBuildHostNetStr(net, driver, priv->caps,
R
Richa Marwaha 已提交
774 775
                                           ',', -1, tapfd_name,
                                           vhostfd_name)))
776
            goto cleanup;
777
    } else {
778
        if (!(netstr = qemuBuildHostNetStr(net, driver, priv->caps,
R
Richa Marwaha 已提交
779 780
                                           ' ', vlan, tapfd_name,
                                           vhostfd_name)))
781
            goto cleanup;
782 783
    }

784
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
785 786
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
787 788
        if (qemuMonitorAddNetdev(priv->mon, netstr, tapfd, tapfd_name,
                                 vhostfd, vhostfd_name) < 0) {
789
            qemuDomainObjExitMonitorWithDriver(driver, vm);
790
            virDomainAuditNet(vm, NULL, net, "attach", false);
791
            goto cleanup;
792 793
        }
    } else {
794 795
        if (qemuMonitorAddHostNetwork(priv->mon, netstr, tapfd, tapfd_name,
                                      vhostfd, vhostfd_name) < 0) {
796
            qemuDomainObjExitMonitorWithDriver(driver, vm);
797
            virDomainAuditNet(vm, NULL, net, "attach", false);
798
            goto cleanup;
799 800 801 802 803
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    VIR_FORCE_CLOSE(tapfd);
804
    VIR_FORCE_CLOSE(vhostfd);
805 806

    if (!virDomainObjIsActive(vm)) {
807 808
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("guest unexpectedly quit"));
809 810 811
        goto cleanup;
    }

812 813
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (!(nicstr = qemuBuildNicDevStr(net, vlan, 0, priv->caps)))
814 815 816 817 818 819
            goto try_remove;
    } else {
        if (!(nicstr = qemuBuildNicStr(net, NULL, vlan)))
            goto try_remove;
    }

820
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
821
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
822 823
        if (qemuMonitorAddDevice(priv->mon, nicstr) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
824
            virDomainAuditNet(vm, NULL, net, "attach", false);
825 826 827
            goto try_remove;
        }
    } else {
828
        guestAddr = net->info.addr.pci;
829 830 831
        if (qemuMonitorAddPCINetwork(priv->mon, nicstr,
                                     &guestAddr) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
832
            virDomainAuditNet(vm, NULL, net, "attach", false);
833 834 835 836 837 838 839
            goto try_remove;
        }
        net->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
        memcpy(&net->info.addr.pci, &guestAddr, sizeof(guestAddr));
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

840 841 842
    /* set link state */
    if (net->linkstate == VIR_DOMAIN_NET_INTERFACE_LINK_STATE_DOWN) {
        if (!net->info.alias) {
843 844
            virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                           _("device alias not found: cannot set link state to down"));
845 846 847
        } else {
            qemuDomainObjEnterMonitorWithDriver(driver, vm);

848
            if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV)) {
849 850 851 852 853 854
                if (qemuMonitorSetLink(priv->mon, net->info.alias, VIR_DOMAIN_NET_INTERFACE_LINK_STATE_DOWN) < 0) {
                    qemuDomainObjExitMonitorWithDriver(driver, vm);
                    virDomainAuditNet(vm, NULL, net, "attach", false);
                    goto try_remove;
                }
            } else {
855
                virReportError(VIR_ERR_OPERATION_FAILED, "%s",
856
                               _("setting of link state not supported: Link is up"));
857 858 859 860 861 862 863
            }

            qemuDomainObjExitMonitorWithDriver(driver, vm);
        }
        /* link set to down */
    }

864
    virDomainAuditNet(vm, NULL, net, "attach", true);
865 866 867 868

    ret = 0;

cleanup:
869 870 871
    if (!ret) {
        vm->def->nets[vm->def->nnets++] = net;
    } else {
872
        if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
873 874 875 876 877 878
            (net->info.type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
            releaseaddr &&
            qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                            net->info.addr.pci.slot) < 0)
            VIR_WARN("Unable to release PCI address on NIC");

879
        if (iface_connected) {
880
            virDomainConfNWFilterTeardown(net);
881

882 883 884 885 886
            vport = virDomainNetGetActualVirtPortProfile(net);
            if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
               ignore_value(virNetDevOpenvswitchRemovePort(
                               virDomainNetGetActualBridgeName(net), net->ifname));
        }
A
Ansis Atteka 已提交
887

888 889
        networkReleaseActualDevice(net);
    }
890 891 892 893 894

    VIR_FREE(nicstr);
    VIR_FREE(netstr);
    VIR_FREE(tapfd_name);
    VIR_FORCE_CLOSE(tapfd);
895 896
    VIR_FREE(vhostfd_name);
    VIR_FORCE_CLOSE(vhostfd);
897 898 899 900 901 902 903 904

    return ret;

try_remove:
    if (!virDomainObjIsActive(vm))
        goto cleanup;

    if (vlan < 0) {
905 906
        if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
            qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
907 908 909
            char *netdev_name;
            if (virAsprintf(&netdev_name, "host%s", net->info.alias) < 0)
                goto no_memory;
910
            qemuDomainObjEnterMonitorWithDriver(driver, vm);
911 912 913 914 915 916
            if (qemuMonitorRemoveNetdev(priv->mon, netdev_name) < 0)
                VIR_WARN("Failed to remove network backend for netdev %s",
                         netdev_name);
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            VIR_FREE(netdev_name);
        } else {
917
            VIR_WARN("Unable to remove network backend");
918 919 920 921 922
        }
    } else {
        char *hostnet_name;
        if (virAsprintf(&hostnet_name, "host%s", net->info.alias) < 0)
            goto no_memory;
923
        qemuDomainObjEnterMonitorWithDriver(driver, vm);
924 925 926 927 928 929 930 931 932 933 934 935 936 937
        if (qemuMonitorRemoveHostNetwork(priv->mon, vlan, hostnet_name) < 0)
            VIR_WARN("Failed to remove network backend for vlan %d, net %s",
                     vlan, hostnet_name);
        qemuDomainObjExitMonitorWithDriver(driver, vm);
        VIR_FREE(hostnet_name);
    }
    goto cleanup;

no_memory:
    virReportOOMError();
    goto cleanup;
}


938
int qemuDomainAttachHostPciDevice(virQEMUDriverPtr driver,
939
                                  virDomainObjPtr vm,
940
                                  virDomainHostdevDefPtr hostdev)
941 942 943 944 945 946
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    int ret;
    char *devstr = NULL;
    int configfd = -1;
    char *configfd_name = NULL;
947
    bool releaseaddr = false;
948 949 950 951 952 953

    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0) {
        virReportOOMError();
        return -1;
    }

954 955
    if (qemuPrepareHostdevPCIDevices(driver, vm->def->name, vm->def->uuid,
                                     &hostdev, 1) < 0)
956 957
        return -1;

958
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
959 960
        if (qemuAssignDeviceHostdevAlias(vm->def, hostdev, -1) < 0)
            goto error;
961
        if (qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, hostdev->info) < 0)
962
            goto error;
963
        releaseaddr = true;
964
        if (qemuCapsGet(priv->caps, QEMU_CAPS_PCI_CONFIGFD)) {
965 966 967
            configfd = qemuOpenPCIConfig(hostdev);
            if (configfd >= 0) {
                if (virAsprintf(&configfd_name, "fd-%s",
968
                                hostdev->info->alias) < 0) {
969 970 971 972 973 974 975
                    virReportOOMError();
                    goto error;
                }
            }
        }

        if (!virDomainObjIsActive(vm)) {
976 977
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("guest unexpectedly quit during hotplug"));
978 979 980
            goto error;
        }

981
        if (!(devstr = qemuBuildPCIHostdevDevStr(hostdev, configfd_name,
982
                                                 priv->caps)))
983 984
            goto error;

985
        qemuDomainObjEnterMonitorWithDriver(driver, vm);
986 987
        ret = qemuMonitorAddDeviceWithFd(priv->mon, devstr,
                                         configfd, configfd_name);
988 989
        qemuDomainObjExitMonitorWithDriver(driver, vm);
    } else {
990
        virDevicePCIAddress guestAddr = hostdev->info->addr.pci;
991

992
        qemuDomainObjEnterMonitorWithDriver(driver, vm);
993 994 995 996 997
        ret = qemuMonitorAddPCIHostDevice(priv->mon,
                                          &hostdev->source.subsys.u.pci,
                                          &guestAddr);
        qemuDomainObjExitMonitorWithDriver(driver, vm);

998 999
        hostdev->info->type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
        memcpy(&hostdev->info->addr.pci, &guestAddr, sizeof(guestAddr));
1000
    }
1001
    virDomainAuditHostdev(vm, hostdev, "attach", ret == 0);
1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013
    if (ret < 0)
        goto error;

    vm->def->hostdevs[vm->def->nhostdevs++] = hostdev;

    VIR_FREE(devstr);
    VIR_FREE(configfd_name);
    VIR_FORCE_CLOSE(configfd);

    return 0;

error:
1014
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
1015
        (hostdev->info->type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
1016
        releaseaddr &&
1017
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
1018
                                        hostdev->info->addr.pci.slot) < 0)
1019
        VIR_WARN("Unable to release PCI address on host device");
1020

1021
    qemuDomainReAttachHostdevDevices(driver, vm->def->name, &hostdev, 1);
1022 1023 1024 1025 1026 1027 1028 1029 1030

    VIR_FREE(devstr);
    VIR_FREE(configfd_name);
    VIR_FORCE_CLOSE(configfd);

    return -1;
}


1031
int qemuDomainAttachRedirdevDevice(virQEMUDriverPtr driver,
1032 1033 1034 1035 1036
                                   virDomainObjPtr vm,
                                   virDomainRedirdevDefPtr redirdev)
{
    int ret;
    qemuDomainObjPrivatePtr priv = vm->privateData;
1037
    virDomainDefPtr def = vm->def;
1038 1039
    char *devstr = NULL;

1040
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1041 1042
        if (qemuAssignDeviceRedirdevAlias(vm->def, redirdev, -1) < 0)
            goto error;
1043
        if (!(devstr = qemuBuildRedirdevDevStr(def, redirdev, priv->caps)))
1044 1045 1046 1047 1048 1049 1050 1051 1052
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->redirdevs, vm->def->nredirdevs+1) < 0) {
        virReportOOMError();
        goto error;
    }

    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1053
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE))
1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074
        ret = qemuMonitorAddDevice(priv->mon, devstr);
    else
        goto error;

    qemuDomainObjExitMonitorWithDriver(driver, vm);
    virDomainAuditRedirdev(vm, redirdev, "attach", ret == 0);
    if (ret < 0)
        goto error;

    vm->def->redirdevs[vm->def->nredirdevs++] = redirdev;

    VIR_FREE(devstr);

    return 0;

error:
    VIR_FREE(devstr);
    return -1;

}

1075
int qemuDomainAttachHostUsbDevice(virQEMUDriverPtr driver,
1076
                                  virDomainObjPtr vm,
1077
                                  virDomainHostdevDefPtr hostdev)
1078 1079 1080 1081 1082
{
    int ret;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    char *devstr = NULL;

1083
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1084 1085
        if (qemuAssignDeviceHostdevAlias(vm->def, hostdev, -1) < 0)
            goto error;
1086
        if (!(devstr = qemuBuildUSBHostdevDevStr(hostdev, priv->caps)))
1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0) {
        virReportOOMError();
        goto error;
    }

    if (qemuCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virCgroupPtr cgroup = NULL;
        usbDevice *usb;
1098
        qemuCgroupData data;
1099

1100
        if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
1101 1102 1103
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unable to find cgroup for %s"),
                           vm->def->name);
1104 1105 1106 1107
            goto error;
        }

        if ((usb = usbGetDevice(hostdev->source.subsys.u.usb.bus,
1108 1109
                                hostdev->source.subsys.u.usb.device,
                                NULL)) == NULL)
1110 1111
            goto error;

1112 1113
        data.vm = vm;
        data.cgroup = cgroup;
1114
        if (usbDeviceFileIterate(usb, qemuSetupHostUsbDeviceCgroup, &data) < 0)
1115 1116 1117
            goto error;
    }

1118
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1119
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE))
1120 1121 1122 1123 1124 1125
        ret = qemuMonitorAddDevice(priv->mon, devstr);
    else
        ret = qemuMonitorAddUSBDeviceExact(priv->mon,
                                           hostdev->source.subsys.u.usb.bus,
                                           hostdev->source.subsys.u.usb.device);
    qemuDomainObjExitMonitorWithDriver(driver, vm);
1126
    virDomainAuditHostdev(vm, hostdev, "attach", ret == 0);
1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140
    if (ret < 0)
        goto error;

    vm->def->hostdevs[vm->def->nhostdevs++] = hostdev;

    VIR_FREE(devstr);

    return 0;

error:
    VIR_FREE(devstr);
    return -1;
}

1141
int qemuDomainAttachHostDevice(virQEMUDriverPtr driver,
1142
                               virDomainObjPtr vm,
1143
                               virDomainHostdevDefPtr hostdev)
1144
{
1145 1146 1147
    usbDeviceList *list;
    usbDevice *usb = NULL;

1148
    if (hostdev->mode != VIR_DOMAIN_HOSTDEV_MODE_SUBSYS) {
1149 1150 1151
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev mode '%s' not supported"),
                       virDomainHostdevModeTypeToString(hostdev->mode));
1152 1153 1154
        return -1;
    }

1155 1156
    if (!(list = usbDeviceListNew()))
        goto cleanup;
1157

1158
    if (hostdev->source.subsys.type == VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB) {
1159
        if (qemuFindHostdevUSBDevice(hostdev, true, &usb) < 0)
1160 1161 1162 1163
            goto cleanup;

        if (usbDeviceListAdd(list, usb) < 0) {
            usbFreeDevice(usb);
M
Marc-André Lureau 已提交
1164
            usb = NULL;
1165 1166 1167
            goto cleanup;
        }

1168 1169
        if (qemuPrepareHostdevUSBDevices(driver, vm->def->name, list) < 0) {
            usb = NULL;
1170
            goto cleanup;
1171
        }
1172 1173 1174

        usbDeviceListSteal(list, usb);
    }
1175

1176
    if (virSecurityManagerSetHostdevLabel(driver->securityManager,
1177
                                          vm->def, hostdev, NULL) < 0)
1178
        goto cleanup;
1179 1180 1181 1182

    switch (hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI:
        if (qemuDomainAttachHostPciDevice(driver, vm,
1183
                                          hostdev) < 0)
1184 1185 1186 1187 1188
            goto error;
        break;

    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        if (qemuDomainAttachHostUsbDevice(driver, vm,
1189
                                          hostdev) < 0)
1190 1191 1192 1193
            goto error;
        break;

    default:
1194 1195 1196
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev subsys type '%s' not supported"),
                       virDomainHostdevSubsysTypeToString(hostdev->source.subsys.type));
1197 1198 1199
        goto error;
    }

1200
    usbDeviceListFree(list);
1201 1202 1203
    return 0;

error:
1204
    if (virSecurityManagerRestoreHostdevLabel(driver->securityManager,
1205
                                              vm->def, hostdev, NULL) < 0)
1206
        VIR_WARN("Unable to restore host device labelling on hotplug fail");
1207

1208 1209
cleanup:
    usbDeviceListFree(list);
1210 1211
    if (usb)
        usbDeviceListSteal(driver->activeUsbHostdevs, usb);
1212 1213 1214
    return -1;
}

1215 1216
static virDomainNetDefPtr *qemuDomainFindNet(virDomainObjPtr vm,
                                             virDomainNetDefPtr dev)
1217 1218 1219 1220
{
    int i;

    for (i = 0; i < vm->def->nnets; i++) {
1221
        if (virMacAddrCmp(&vm->def->nets[i]->mac, &dev->mac) == 0)
1222
            return &vm->def->nets[i];
1223 1224 1225 1226 1227
    }

    return NULL;
}

1228 1229 1230 1231 1232 1233 1234 1235 1236 1237 1238 1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250 1251 1252 1253 1254 1255 1256 1257 1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268 1269 1270 1271 1272
static char *
qemuDomainNetGetBridgeName(virConnectPtr conn, virDomainNetDefPtr net)
{
    char *brname = NULL;
    int actualType = virDomainNetGetActualType(net);

    if (actualType == VIR_DOMAIN_NET_TYPE_BRIDGE) {
        const char *tmpbr = virDomainNetGetActualBridgeName(net);
        if (!tmpbr) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("interface is missing bridge name"));
            goto cleanup;
        }
        /* we need a copy, not just a pointer to the original */
        if (!(brname = strdup(tmpbr))) {
            virReportOOMError();
            goto cleanup;
        }
    } else if (actualType == VIR_DOMAIN_NET_TYPE_NETWORK) {
        int active;
        virErrorPtr errobj;
        virNetworkPtr network;

        if (!(network = virNetworkLookupByName(conn, net->data.network.name))) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Couldn't find network '%s'"),
                           net->data.network.name);
            goto cleanup;
        }

        active = virNetworkIsActive(network);
        if (active == 1) {
            brname = virNetworkGetBridgeName(network);
        } else if (active == 0) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Network '%s' is not active."),
                           net->data.network.name);
        }

        /* Make sure any above failure is preserved */
        errobj = virSaveLastError();
        virNetworkFree(network);
        virSetError(errobj);
        virFreeError(errobj);

1273 1274 1275 1276
    } else {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Interface type %d has no bridge name"),
                       virDomainNetGetActualType(net));
1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287
    }

cleanup:
    return brname;
}

static int
qemuDomainChangeNetBridge(virConnectPtr conn,
                          virDomainObjPtr vm,
                          virDomainNetDefPtr olddev,
                          virDomainNetDefPtr newdev)
1288 1289
{
    int ret = -1;
1290 1291 1292 1293 1294 1295 1296
    char *oldbridge = NULL, *newbridge = NULL;

    if (!(oldbridge = qemuDomainNetGetBridgeName(conn, olddev)))
        goto cleanup;

    if (!(newbridge = qemuDomainNetGetBridgeName(conn, newdev)))
        goto cleanup;
1297 1298 1299 1300 1301

    VIR_DEBUG("Change bridge for interface %s: %s -> %s",
              olddev->ifname, oldbridge, newbridge);

    if (virNetDevExists(newbridge) != 1) {
1302 1303
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("bridge %s doesn't exist"), newbridge);
1304
        goto cleanup;
1305 1306 1307 1308 1309
    }

    if (oldbridge) {
        ret = virNetDevBridgeRemovePort(oldbridge, olddev->ifname);
        virDomainAuditNet(vm, olddev, NULL, "detach", ret == 0);
1310 1311 1312 1313 1314 1315 1316 1317
        if (ret < 0) {
            /* warn but continue - possibly the old network
             * had been destroyed and reconstructed, leaving the
             * tap device orphaned.
             */
            VIR_WARN("Unable to detach device %s from bridge %s",
                     olddev->ifname, oldbridge);
        }
1318 1319 1320
    }

    ret = virNetDevBridgeAddPort(newbridge, olddev->ifname);
1321
    virDomainAuditNet(vm, NULL, newdev, "attach", ret == 0);
1322 1323 1324 1325
    if (ret < 0) {
        ret = virNetDevBridgeAddPort(oldbridge, olddev->ifname);
        virDomainAuditNet(vm, NULL, olddev, "attach", ret == 0);
        if (ret < 0) {
1326
            virReportError(VIR_ERR_OPERATION_FAILED,
1327
                           _("unable to recover former state by adding port "
1328
                             "to bridge %s"), oldbridge);
1329
        }
1330
        goto cleanup;
1331
    }
1332 1333 1334
    /* caller will replace entire olddev with newdev in domain nets list */
    ret = 0;
cleanup:
1335
    VIR_FREE(oldbridge);
1336 1337
    VIR_FREE(newbridge);
    return ret;
1338 1339
}

1340 1341 1342 1343 1344 1345 1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364 1365 1366 1367 1368 1369 1370 1371 1372 1373 1374 1375 1376
static int
qemuDomainChangeNetFilter(virConnectPtr conn,
                          virDomainObjPtr vm,
                          virDomainNetDefPtr olddev,
                          virDomainNetDefPtr newdev)
{
    /* make sure this type of device supports filters. */
    switch (virDomainNetGetActualType(newdev)) {
    case VIR_DOMAIN_NET_TYPE_ETHERNET:
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
    case VIR_DOMAIN_NET_TYPE_NETWORK:
        break;
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("filters not supported on interfaces of type %s"),
                       virDomainNetTypeToString(virDomainNetGetActualType(newdev)));
        return -1;
    }

    virDomainConfNWFilterTeardown(olddev);

    if (virDomainConfNWFilterInstantiate(conn, vm->def->uuid, newdev) < 0) {
        virErrorPtr errobj;

        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("failed to add new filter rules to '%s' "
                         "- attempting to restore old rules"),
                       olddev->ifname);
        errobj = virSaveLastError();
        ignore_value(virDomainConfNWFilterInstantiate(conn, vm->def->uuid, olddev));
        virSetError(errobj);
        virFreeError(errobj);
        return -1;
    }
    return 0;
}

1377
int qemuDomainChangeNetLinkState(virQEMUDriverPtr driver,
1378 1379 1380 1381 1382 1383 1384 1385 1386 1387
                                 virDomainObjPtr vm,
                                 virDomainNetDefPtr dev,
                                 int linkstate)
{
    int ret = -1;
    qemuDomainObjPrivatePtr priv = vm->privateData;

    VIR_DEBUG("dev: %s, state: %d", dev->info.alias, linkstate);

    if (!dev->info.alias) {
1388 1389
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("can't change link state: device alias not found"));
1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404 1405 1406 1407
        return -1;
    }

    qemuDomainObjEnterMonitorWithDriver(driver, vm);

    ret = qemuMonitorSetLink(priv->mon, dev->info.alias, linkstate);
    if (ret < 0)
        goto cleanup;

    /* modify the device configuration */
    dev->linkstate = linkstate;

cleanup:
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    return ret;
}

1408
int
1409
qemuDomainChangeNet(virQEMUDriverPtr driver,
1410 1411 1412
                    virDomainObjPtr vm,
                    virDomainPtr dom,
                    virDomainDeviceDefPtr dev)
1413
{
1414 1415 1416 1417 1418 1419
    virDomainNetDefPtr newdev = dev->data.net;
    virDomainNetDefPtr *devslot = qemuDomainFindNet(vm, newdev);
    virDomainNetDefPtr olddev;
    int oldType, newType;
    bool needReconnect = false;
    bool needBridgeChange = false;
1420
    bool needFilterChange = false;
1421 1422 1423
    bool needLinkStateChange = false;
    bool needReplaceDevDef = false;
    int ret = -1;
1424

1425
    if (!devslot || !(olddev = *devslot)) {
1426 1427
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot find existing network device to modify"));
1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470
        goto cleanup;
    }

    oldType = virDomainNetGetActualType(olddev);
    if (oldType == VIR_DOMAIN_NET_TYPE_HOSTDEV) {
        /* no changes are possible to a type='hostdev' interface */
        virReportError(VIR_ERR_NO_SUPPORT,
                       _("cannot change config of '%s' network type"),
                       virDomainNetTypeToString(oldType));
        goto cleanup;
    }

    /* Check individual attributes for changes that can't be done to a
     * live netdev. These checks *mostly* go in order of the
     * declarations in virDomainNetDef in order to assure nothing is
     * omitted. (exceptiong where noted in comments - in particular,
     * some things require that a new "actual device" be allocated
     * from the network driver first, but we delay doing that until
     * after we've made as many other checks as possible)
     */

    /* type: this can change (with some restrictions), but the actual
     * type of the new device connection isn't known until after we
     * allocate the "actual" device.
     */

    if (virMacAddrCmp(&olddev->mac, &newdev->mac)) {
        char oldmac[VIR_MAC_STRING_BUFLEN], newmac[VIR_MAC_STRING_BUFLEN];

        virReportError(VIR_ERR_NO_SUPPORT,
                       _("cannot change network interface mac address "
                         "from %s to %s"),
                       virMacAddrFormat(&olddev->mac, oldmac),
                       virMacAddrFormat(&newdev->mac, newmac));
        goto cleanup;
    }

    if (STRNEQ_NULLABLE(olddev->model, newdev->model)) {
        virReportError(VIR_ERR_NO_SUPPORT,
                       _("cannot modify network device model from %s to %s"),
                       olddev->model ? olddev->model : "(default)",
                       newdev->model ? newdev->model : "(default)");
        goto cleanup;
1471 1472
    }

1473 1474 1475 1476 1477
    if (olddev->model && STREQ(olddev->model, "virtio") &&
        (olddev->driver.virtio.name != newdev->driver.virtio.name ||
         olddev->driver.virtio.txmode != newdev->driver.virtio.txmode ||
         olddev->driver.virtio.ioeventfd != newdev->driver.virtio.ioeventfd ||
         olddev->driver.virtio.event_idx != newdev->driver.virtio.event_idx)) {
1478
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
1479 1480 1481 1482 1483 1484 1485 1486 1487 1488
                       _("cannot modify virtio network device driver attributes"));
        goto cleanup;
    }

    /* data: this union will be examined later, after allocating new actualdev */
    /* virtPortProfile: will be examined later, after allocating new actualdev */

    if (olddev->tune.sndbuf_specified != newdev->tune.sndbuf_specified ||
        olddev->tune.sndbuf != newdev->tune.sndbuf) {
        needReconnect = true;
1489 1490
    }

1491
    if (STRNEQ_NULLABLE(olddev->script, newdev->script)) {
1492
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
1493 1494
                       _("cannot modify network device script attribute"));
        goto cleanup;
1495 1496
    }

1497 1498 1499 1500 1501 1502 1503 1504 1505 1506 1507
    /* ifname: check if it's set in newdev. If not, retain the autogenerated one */
    if (!(newdev->ifname ||
          (newdev->ifname = strdup(olddev->ifname)))) {
        virReportOOMError();
        goto cleanup;
    }
    if (STRNEQ_NULLABLE(olddev->ifname, newdev->ifname)) {
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot modify network device tap name"));
        goto cleanup;
    }
1508

1509 1510 1511 1512 1513 1514 1515 1516 1517 1518 1519 1520 1521 1522 1523 1524 1525 1526 1527 1528 1529 1530 1531 1532 1533 1534 1535 1536 1537 1538 1539 1540 1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551 1552
    /* info: if newdev->info is empty, fill it in from olddev,
     * otherwise verify that it matches - nothing is allowed to
     * change. (There is no helper function to do this, so
     * individually check the few feidls of virDomainDeviceInfo that
     * are relevant in this case).
     */
    if (!virDomainDeviceAddressIsValid(&newdev->info,
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
        virDomainDeviceInfoCopy(&newdev->info, &olddev->info) < 0) {
        goto cleanup;
    }
    if (!virDevicePCIAddressEqual(&olddev->info.addr.pci,
                                  &newdev->info.addr.pci)) {
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot modify network device guest PCI address"));
        goto cleanup;
    }
    /* grab alias from olddev if not set in newdev */
    if (!(newdev->info.alias ||
          (newdev->info.alias = strdup(olddev->info.alias)))) {
        virReportOOMError();
        goto cleanup;
    }
    if (STRNEQ_NULLABLE(olddev->info.alias, newdev->info.alias)) {
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot modify network device alias"));
        goto cleanup;
    }
    if (olddev->info.rombar != newdev->info.rombar) {
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot modify network device rom bar setting"));
        goto cleanup;
    }
    if (STRNEQ_NULLABLE(olddev->info.romfile, newdev->info.romfile)) {
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot modify network rom file"));
        goto cleanup;
    }
    if (olddev->info.bootIndex != newdev->info.bootIndex) {
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot modify network device boot index setting"));
        goto cleanup;
    }
    /* (end of device info checks) */
1553

1554 1555 1556 1557
    if (STRNEQ_NULLABLE(olddev->filter, newdev->filter) ||
        !virNWFilterHashTableEqual(olddev->filterparams, newdev->filterparams)) {
        needFilterChange = true;
    }
1558

1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579 1580 1581
    /* bandwidth can be modified, and will be checked later */
    /* vlan can be modified, and will be checked later */
    /* linkstate can be modified */

    /* allocate new actual device to compare to old - we will need to
     * free it if we fail for any reason
     */
    if (newdev->type == VIR_DOMAIN_NET_TYPE_NETWORK &&
        networkAllocateActualDevice(newdev) < 0) {
        goto cleanup;
    }

    newType = virDomainNetGetActualType(newdev);

    if (newType == VIR_DOMAIN_NET_TYPE_HOSTDEV) {
        /* can't turn it into a type='hostdev' interface */
        virReportError(VIR_ERR_NO_SUPPORT,
                       _("cannot change network interface type to '%s'"),
                       virDomainNetTypeToString(newType));
        goto cleanup;
    }

    if (olddev->type == newdev->type && oldType == newType) {
1582

1583 1584 1585 1586 1587 1588 1589 1590 1591 1592 1593 1594
        /* if type hasn't changed, check the relevant fields for the type */
        switch (newdev->type) {
        case VIR_DOMAIN_NET_TYPE_USER:
            break;

        case VIR_DOMAIN_NET_TYPE_ETHERNET:
            if (STRNEQ_NULLABLE(olddev->data.ethernet.dev,
                                newdev->data.ethernet.dev) ||
                STRNEQ_NULLABLE(olddev->data.ethernet.ipaddr,
                                newdev->data.ethernet.ipaddr)) {
                needReconnect = true;
            }
1595 1596
        break;

1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636
        case VIR_DOMAIN_NET_TYPE_SERVER:
        case VIR_DOMAIN_NET_TYPE_CLIENT:
        case VIR_DOMAIN_NET_TYPE_MCAST:
            if (STRNEQ_NULLABLE(olddev->data.socket.address,
                                newdev->data.socket.address) ||
                olddev->data.socket.port != newdev->data.socket.port) {
                needReconnect = true;
            }
            break;

        case VIR_DOMAIN_NET_TYPE_NETWORK:
            if (STRNEQ(olddev->data.network.name, newdev->data.network.name)) {
                if (virDomainNetGetActualVirtPortProfile(newdev))
                    needReconnect = true;
                else
                    needBridgeChange = true;
            }
            /* other things handled in common code directly below this switch */
            break;

        case VIR_DOMAIN_NET_TYPE_BRIDGE:
            /* all handled in bridge name checked in common code below */
            break;

        case VIR_DOMAIN_NET_TYPE_INTERNAL:
            if (STRNEQ_NULLABLE(olddev->data.internal.name,
                                newdev->data.internal.name)) {
                needReconnect = true;
            }
            break;

        case VIR_DOMAIN_NET_TYPE_DIRECT:
            /* all handled in common code directly below this switch */
            break;

        default:
            virReportError(VIR_ERR_NO_SUPPORT,
                           _("unable to change config on '%s' network type"),
                           virDomainNetTypeToString(newdev->type));
            break;
1637

1638
        }
1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661 1662 1663 1664 1665 1666 1667 1668 1669
    } else {
        /* interface type has changed. There are a few special cases
         * where this can only require a minor (or even no) change,
         * but in most cases we need to do a full reconnection.
         *
         * If we switch (in either direction) between type='bridge'
         * and type='network' (for a traditional managed virtual
         * network that uses a host bridge, i.e. forward
         * mode='route|nat'), we just need to change the bridge.
         */
        if ((oldType == VIR_DOMAIN_NET_TYPE_NETWORK &&
             newType == VIR_DOMAIN_NET_TYPE_BRIDGE) ||
            (oldType == VIR_DOMAIN_NET_TYPE_BRIDGE &&
             newType == VIR_DOMAIN_NET_TYPE_NETWORK)) {

            needBridgeChange = true;

        } else if (oldType == VIR_DOMAIN_NET_TYPE_DIRECT &&
                   newType == VIR_DOMAIN_NET_TYPE_DIRECT) {

            /* this is the case of switching from type='direct' to
             * type='network' for a network that itself uses direct
             * (macvtap) devices. If the physical device and mode are
             * the same, this doesn't require any actual setup
             * change. If the physical device or mode *does* change,
             * that will be caught in the common section below */

        } else {

            /* for all other combinations, we'll need a full reconnect */
            needReconnect = true;
1670 1671

        }
1672
    }
1673

1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684
    /* now several things that are in multiple (but not all)
     * different types, and can be safely compared even for those
     * cases where they don't apply to a particular type.
     */
    if (STRNEQ_NULLABLE(virDomainNetGetActualBridgeName(olddev),
                        virDomainNetGetActualBridgeName(newdev))) {
        if (virDomainNetGetActualVirtPortProfile(newdev))
            needReconnect = true;
        else
            needBridgeChange = true;
    }
1685

1686 1687 1688 1689 1690 1691 1692 1693 1694 1695
    if (STRNEQ_NULLABLE(virDomainNetGetActualDirectDev(olddev),
                        virDomainNetGetActualDirectDev(newdev)) ||
        virDomainNetGetActualDirectMode(olddev) != virDomainNetGetActualDirectMode(olddev) ||
        !virNetDevVPortProfileEqual(virDomainNetGetActualVirtPortProfile(olddev),
                                    virDomainNetGetActualVirtPortProfile(newdev)) ||
        !virNetDevBandwidthEqual(virDomainNetGetActualBandwidth(olddev),
                                 virDomainNetGetActualBandwidth(newdev)) ||
        !virNetDevVlanEqual(virDomainNetGetActualVlan(olddev),
                            virDomainNetGetActualVlan(newdev))) {
        needReconnect = true;
1696 1697
    }

1698 1699 1700 1701 1702 1703 1704 1705 1706 1707
    if (olddev->linkstate != newdev->linkstate)
        needLinkStateChange = true;

    /* FINALLY - actually perform the required actions */

    if (needReconnect) {
        virReportError(VIR_ERR_NO_SUPPORT,
                       _("unable to change config on '%s' network type"),
                       virDomainNetTypeToString(newdev->type));
        goto cleanup;
1708 1709
    }

1710 1711 1712 1713 1714
    if (needBridgeChange) {
        if (qemuDomainChangeNetBridge(dom->conn, vm, olddev, newdev) < 0)
            goto cleanup;
        /* we successfully switched to the new bridge, and we've
         * determined that the rest of newdev is equivalent to olddev,
1715 1716 1717 1718 1719 1720 1721 1722 1723 1724
         * so move newdev into place */
        needReplaceDevDef = true;
    }

    if (needFilterChange) {
        if (qemuDomainChangeNetFilter(dom->conn, vm, olddev, newdev) < 0)
            goto cleanup;
        /* we successfully switched to the new filter, and we've
         * determined that the rest of newdev is equivalent to olddev,
         * so move newdev into place */
1725
        needReplaceDevDef = true;
1726 1727
    }

1728 1729 1730
    if (needLinkStateChange &&
        qemuDomainChangeNetLinkState(driver, vm, olddev, newdev->linkstate) < 0) {
        goto cleanup;
1731 1732
    }

1733 1734 1735 1736 1737 1738 1739 1740 1741 1742 1743 1744 1745
    if (needReplaceDevDef) {
        /* the changes above warrant replacing olddev with newdev in
         * the domain's nets list.
         */
        networkReleaseActualDevice(olddev);
        virDomainNetDefFree(olddev);
        /* move newdev into the nets list, and NULL it out from the
         * virDomainDeviceDef that we were given so that the caller
         * won't delete it on return.
         */
        *devslot = newdev;
        newdev = dev->data.net = NULL;
        dev->type = VIR_DOMAIN_DEVICE_NONE;
1746 1747
    }

1748 1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770
    ret = 0;
cleanup:
    /* When we get here, we will be in one of these two states:
     *
     * 1) newdev has been moved into the domain's list of nets and
     *    newdev set to NULL, and dev->data.net will be NULL (and
     *    dev->type is NONE). olddev will have been completely
     *    released and freed. (aka success) In this case no extra
     *    cleanup is needed.
     *
     * 2) newdev has *not* been moved into the domain's list of nets,
     *    and dev->data.net == newdev (and dev->type == NET). In this *
     *    case, we need to at least release the "actual device" from *
     *    newdev (the caller will free dev->data.net a.k.a. newdev, and
     *    the original olddev is still in used)
     *
     * Note that case (2) isn't necessarily a failure. It may just be
     * that the changes were minor enough that we didn't need to
     * replace the entire device object.
     */
    if (newdev)
        networkReleaseActualDevice(newdev);

1771 1772 1773 1774
    return ret;
}


1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789 1790

static virDomainGraphicsDefPtr qemuDomainFindGraphics(virDomainObjPtr vm,
                                                      virDomainGraphicsDefPtr dev)
{
    int i;

    for (i = 0 ; i < vm->def->ngraphics ; i++) {
        if (vm->def->graphics[i]->type == dev->type)
            return vm->def->graphics[i];
    }

    return NULL;
}


int
1791
qemuDomainChangeGraphics(virQEMUDriverPtr driver,
1792 1793 1794 1795
                         virDomainObjPtr vm,
                         virDomainGraphicsDefPtr dev)
{
    virDomainGraphicsDefPtr olddev = qemuDomainFindGraphics(vm, dev);
1796
    const char *oldListenAddr, *newListenAddr;
1797
    const char *oldListenNetwork, *newListenNetwork;
1798 1799 1800
    int ret = -1;

    if (!olddev) {
1801 1802
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("cannot find existing graphics device to modify"));
1803 1804 1805
        return -1;
    }

1806 1807
    oldListenAddr = virDomainGraphicsListenGetAddress(olddev, 0);
    newListenAddr = virDomainGraphicsListenGetAddress(dev, 0);
1808 1809
    oldListenNetwork = virDomainGraphicsListenGetNetwork(olddev, 0);
    newListenNetwork = virDomainGraphicsListenGetNetwork(dev, 0);
1810

1811 1812 1813
    switch (dev->type) {
    case VIR_DOMAIN_GRAPHICS_TYPE_VNC:
        if ((olddev->data.vnc.autoport != dev->data.vnc.autoport) ||
E
Eric Blake 已提交
1814 1815
            (!dev->data.vnc.autoport &&
             (olddev->data.vnc.port != dev->data.vnc.port))) {
1816 1817
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change port settings on vnc graphics"));
1818 1819
            return -1;
        }
1820
        if (STRNEQ_NULLABLE(oldListenAddr,newListenAddr)) {
1821 1822
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen address setting on vnc graphics"));
1823 1824
            return -1;
        }
1825
        if (STRNEQ_NULLABLE(oldListenNetwork,newListenNetwork)) {
1826 1827
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen network setting on vnc graphics"));
1828 1829
            return -1;
        }
1830
        if (STRNEQ_NULLABLE(olddev->data.vnc.keymap, dev->data.vnc.keymap)) {
1831 1832
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change keymap setting on vnc graphics"));
1833 1834 1835
            return -1;
        }

1836 1837 1838
        /* If a password lifetime was, or is set, or action if connected has
         * changed, then we must always run, even if new password matches
         * old password */
1839 1840
        if (olddev->data.vnc.auth.expires ||
            dev->data.vnc.auth.expires ||
1841
            olddev->data.vnc.auth.connected != dev->data.vnc.auth.connected ||
E
Eric Blake 已提交
1842 1843 1844 1845 1846 1847 1848 1849
            STRNEQ_NULLABLE(olddev->data.vnc.auth.passwd,
                            dev->data.vnc.auth.passwd)) {
            VIR_DEBUG("Updating password on VNC server %p %p",
                      dev->data.vnc.auth.passwd, driver->vncPassword);
            ret = qemuDomainChangeGraphicsPasswords(driver, vm,
                                                    VIR_DOMAIN_GRAPHICS_TYPE_VNC,
                                                    &dev->data.vnc.auth,
                                                    driver->vncPassword);
1850 1851
            if (ret < 0)
                return ret;
1852 1853 1854 1855 1856

            /* Steal the new dev's  char * reference */
            VIR_FREE(olddev->data.vnc.auth.passwd);
            olddev->data.vnc.auth.passwd = dev->data.vnc.auth.passwd;
            dev->data.vnc.auth.passwd = NULL;
1857 1858
            olddev->data.vnc.auth.validTo = dev->data.vnc.auth.validTo;
            olddev->data.vnc.auth.expires = dev->data.vnc.auth.expires;
1859
            olddev->data.vnc.auth.connected = dev->data.vnc.auth.connected;
1860 1861 1862 1863 1864
        } else {
            ret = 0;
        }
        break;

1865 1866
    case VIR_DOMAIN_GRAPHICS_TYPE_SPICE:
        if ((olddev->data.spice.autoport != dev->data.spice.autoport) ||
E
Eric Blake 已提交
1867 1868 1869 1870
            (!dev->data.spice.autoport &&
             (olddev->data.spice.port != dev->data.spice.port)) ||
            (!dev->data.spice.autoport &&
             (olddev->data.spice.tlsPort != dev->data.spice.tlsPort))) {
1871 1872
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change port settings on spice graphics"));
1873 1874
            return -1;
        }
1875
        if (STRNEQ_NULLABLE(oldListenAddr, newListenAddr)) {
1876 1877
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen address setting on spice graphics"));
1878 1879
            return -1;
        }
1880
        if (STRNEQ_NULLABLE(oldListenNetwork, newListenNetwork)) {
1881 1882
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen network setting on spice graphics"));
1883 1884
            return -1;
        }
E
Eric Blake 已提交
1885 1886
        if (STRNEQ_NULLABLE(olddev->data.spice.keymap,
                            dev->data.spice.keymap)) {
1887
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
1888 1889 1890 1891
                            _("cannot change keymap setting on spice graphics"));
            return -1;
        }

1892 1893 1894 1895 1896
        /* We must reset the password if it has changed but also if:
         * - password lifetime is or was set
         * - the requested action has changed
         * - the action is "disconnect"
         */
1897 1898
        if (olddev->data.spice.auth.expires ||
            dev->data.spice.auth.expires ||
1899
            olddev->data.spice.auth.connected != dev->data.spice.auth.connected ||
1900 1901
            dev->data.spice.auth.connected ==
            VIR_DOMAIN_GRAPHICS_AUTH_CONNECTED_DISCONNECT ||
E
Eric Blake 已提交
1902 1903 1904 1905 1906 1907 1908 1909 1910
            STRNEQ_NULLABLE(olddev->data.spice.auth.passwd,
                            dev->data.spice.auth.passwd)) {
            VIR_DEBUG("Updating password on SPICE server %p %p",
                      dev->data.spice.auth.passwd, driver->spicePassword);
            ret = qemuDomainChangeGraphicsPasswords(driver, vm,
                                                    VIR_DOMAIN_GRAPHICS_TYPE_SPICE,
                                                    &dev->data.spice.auth,
                                                    driver->spicePassword);

1911 1912 1913
            if (ret < 0)
                return ret;

E
Eric Blake 已提交
1914
            /* Steal the new dev's char * reference */
1915 1916 1917 1918 1919
            VIR_FREE(olddev->data.spice.auth.passwd);
            olddev->data.spice.auth.passwd = dev->data.spice.auth.passwd;
            dev->data.spice.auth.passwd = NULL;
            olddev->data.spice.auth.validTo = dev->data.spice.auth.validTo;
            olddev->data.spice.auth.expires = dev->data.spice.auth.expires;
1920
            olddev->data.spice.auth.connected = dev->data.spice.auth.connected;
1921
        } else {
1922
            VIR_DEBUG("Not updating since password didn't change");
1923 1924
            ret = 0;
        }
E
Eric Blake 已提交
1925
        break;
1926

1927
    default:
1928 1929 1930
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unable to change config on '%s' graphics type"),
                       virDomainGraphicsTypeToString(dev->type));
1931 1932 1933 1934 1935 1936 1937 1938 1939 1940 1941 1942 1943 1944 1945 1946 1947 1948 1949 1950
        break;
    }

    return ret;
}


static inline int qemuFindDisk(virDomainDefPtr def, const char *dst)
{
    int i;

    for (i = 0 ; i < def->ndisks ; i++) {
        if (STREQ(def->disks[i]->dst, dst)) {
            return i;
        }
    }

    return -1;
}

1951
static int qemuComparePCIDevice(virDomainDefPtr def ATTRIBUTE_UNUSED,
1952
                                virDomainDeviceDefPtr device ATTRIBUTE_UNUSED,
1953
                                virDomainDeviceInfoPtr info1,
1954 1955
                                void *opaque)
{
1956
    virDomainDeviceInfoPtr info2 = opaque;
1957

1958 1959
    if (info1->type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI ||
        info2->type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)
1960 1961
        return 0;

1962 1963
    if (info1->addr.pci.slot == info2->addr.pci.slot &&
        info1->addr.pci.function != info2->addr.pci.function)
1964 1965 1966 1967 1968 1969 1970 1971 1972 1973 1974 1975
        return -1;
    return 0;
}

static bool qemuIsMultiFunctionDevice(virDomainDefPtr def,
                                      virDomainDeviceInfoPtr dev)
{
    if (virDomainDeviceInfoIterate(def, qemuComparePCIDevice, dev) < 0)
        return true;
    return false;
}

1976

1977
int qemuDomainDetachPciDiskDevice(virQEMUDriverPtr driver,
1978
                                  virDomainObjPtr vm,
1979
                                  virDomainDeviceDefPtr dev)
1980 1981 1982 1983 1984 1985 1986 1987 1988 1989
{
    int i, ret = -1;
    virDomainDiskDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    virCgroupPtr cgroup = NULL;
    char *drivestr = NULL;

    i = qemuFindDisk(vm->def, dev->data.disk->dst);

    if (i < 0) {
1990 1991
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
1992 1993 1994 1995 1996
        goto cleanup;
    }

    detach = vm->def->disks[i];

1997
    if (qemuIsMultiFunctionDevice(vm->def, &detach->info)) {
1998 1999 2000
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device: %s"),
                       dev->data.disk->dst);
2001 2002 2003
        goto cleanup;
    }

2004 2005
    if (qemuCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
2006 2007 2008
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unable to find cgroup for %s"),
                           vm->def->name);
2009 2010 2011 2012 2013 2014
            goto cleanup;
        }
    }

    if (!virDomainDeviceAddressIsValid(&detach->info,
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
2015 2016
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("device cannot be detached without a PCI address"));
2017 2018 2019 2020 2021 2022 2023 2024 2025 2026 2027
        goto cleanup;
    }

    /* build the actual drive id string as the disk->info.alias doesn't
     * contain the QEMU_DRIVE_HOST_PREFIX that is passed to qemu */
    if (virAsprintf(&drivestr, "%s%s",
                    QEMU_DRIVE_HOST_PREFIX, detach->info.alias) < 0) {
        virReportOOMError();
        goto cleanup;
    }

2028
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2029
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2030
        if (qemuMonitorDelDevice(priv->mon, detach->info.alias) < 0) {
2031
            qemuDomainObjExitMonitorWithDriver(driver, vm);
2032
            virDomainAuditDisk(vm, detach->src, NULL, "detach", false);
2033 2034 2035 2036 2037
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemovePCIDevice(priv->mon,
                                       &detach->info.addr.pci) < 0) {
2038
            qemuDomainObjExitMonitorWithDriver(driver, vm);
2039
            virDomainAuditDisk(vm, detach->src, NULL, "detach", false);
2040 2041 2042 2043 2044 2045 2046 2047 2048
            goto cleanup;
        }
    }

    /* disconnect guest from host device */
    qemuMonitorDriveDel(priv->mon, drivestr);

    qemuDomainObjExitMonitorWithDriver(driver, vm);

2049
    virDomainAuditDisk(vm, detach->src, NULL, "detach", true);
2050

2051
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
2052 2053
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        detach->info.addr.pci.slot) < 0)
2054 2055 2056 2057
        VIR_WARN("Unable to release PCI address on %s", dev->data.disk->src);

    virDomainDiskRemove(vm->def, i);

2058 2059
    dev->data.disk->backingChain = detach->backingChain;
    detach->backingChain = NULL;
2060 2061
    virDomainDiskDefFree(detach);

2062
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
2063
                                            vm->def, dev->data.disk) < 0)
2064 2065 2066
        VIR_WARN("Unable to restore security label on %s", dev->data.disk->src);

    if (cgroup != NULL) {
2067
        if (qemuTeardownDiskCgroup(vm, cgroup, dev->data.disk) < 0)
2068 2069 2070 2071
            VIR_WARN("Failed to teardown cgroup for disk path %s",
                     NULLSTR(dev->data.disk->src));
    }

2072 2073 2074
    if (virDomainLockDiskDetach(driver->lockManager, vm, dev->data.disk) < 0)
        VIR_WARN("Unable to release lock on %s", dev->data.disk->src);

2075 2076 2077
    ret = 0;

cleanup:
2078
    virCgroupFree(&cgroup);
2079 2080 2081 2082
    VIR_FREE(drivestr);
    return ret;
}

2083
int qemuDomainDetachDiskDevice(virQEMUDriverPtr driver,
2084
                               virDomainObjPtr vm,
2085
                               virDomainDeviceDefPtr dev)
2086 2087 2088 2089 2090 2091 2092 2093 2094 2095
{
    int i, ret = -1;
    virDomainDiskDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    virCgroupPtr cgroup = NULL;
    char *drivestr = NULL;

    i = qemuFindDisk(vm->def, dev->data.disk->dst);

    if (i < 0) {
2096 2097
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
2098 2099 2100
        goto cleanup;
    }

2101
    if (!qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2102 2103 2104
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("Underlying qemu does not support %s disk removal"),
                       virDomainDiskBusTypeToString(dev->data.disk->bus));
2105 2106 2107 2108 2109
        goto cleanup;
    }

    detach = vm->def->disks[i];

E
Eric Blake 已提交
2110 2111 2112 2113 2114 2115 2116
    if (detach->mirror) {
        virReportError(VIR_ERR_BLOCK_COPY_ACTIVE,
                       _("disk '%s' is in an active block copy job"),
                       detach->dst);
        goto cleanup;
    }

2117 2118
    if (qemuCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
2119 2120 2121
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unable to find cgroup for %s"),
                           vm->def->name);
2122 2123 2124 2125 2126 2127 2128 2129 2130 2131 2132 2133
            goto cleanup;
        }
    }

    /* build the actual drive id string as the disk->info.alias doesn't
     * contain the QEMU_DRIVE_HOST_PREFIX that is passed to qemu */
    if (virAsprintf(&drivestr, "%s%s",
                    QEMU_DRIVE_HOST_PREFIX, detach->info.alias) < 0) {
        virReportOOMError();
        goto cleanup;
    }

2134
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2135
    if (qemuMonitorDelDevice(priv->mon, detach->info.alias) < 0) {
2136
        qemuDomainObjExitMonitorWithDriver(driver, vm);
2137
        virDomainAuditDisk(vm, detach->src, NULL, "detach", false);
2138 2139 2140 2141 2142 2143 2144 2145
        goto cleanup;
    }

    /* disconnect guest from host device */
    qemuMonitorDriveDel(priv->mon, drivestr);

    qemuDomainObjExitMonitorWithDriver(driver, vm);

2146
    virDomainAuditDisk(vm, detach->src, NULL, "detach", true);
2147 2148 2149

    virDomainDiskRemove(vm->def, i);

2150 2151
    dev->data.disk->backingChain = detach->backingChain;
    detach->backingChain = NULL;
2152 2153
    virDomainDiskDefFree(detach);

2154
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
2155
                                            vm->def, dev->data.disk) < 0)
2156 2157 2158
        VIR_WARN("Unable to restore security label on %s", dev->data.disk->src);

    if (cgroup != NULL) {
2159
        if (qemuTeardownDiskCgroup(vm, cgroup, dev->data.disk) < 0)
2160 2161 2162 2163
            VIR_WARN("Failed to teardown cgroup for disk path %s",
                     NULLSTR(dev->data.disk->src));
    }

2164 2165 2166
    if (virDomainLockDiskDetach(driver->lockManager, vm, dev->data.disk) < 0)
        VIR_WARN("Unable to release lock on disk %s", dev->data.disk->src);

2167 2168 2169 2170 2171 2172 2173 2174
    ret = 0;

cleanup:
    VIR_FREE(drivestr);
    virCgroupFree(&cgroup);
    return ret;
}

2175 2176 2177 2178 2179 2180 2181 2182 2183 2184 2185 2186 2187 2188 2189 2190 2191 2192 2193 2194 2195 2196 2197 2198 2199 2200 2201 2202 2203 2204 2205 2206 2207 2208 2209 2210 2211 2212 2213 2214 2215 2216 2217 2218 2219 2220 2221 2222 2223 2224
static bool qemuDomainDiskControllerIsBusy(virDomainObjPtr vm,
                                           virDomainControllerDefPtr detach)
{
    int i;
    virDomainDiskDefPtr disk;

    for (i = 0; i < vm->def->ndisks; i++) {
        disk = vm->def->disks[i];
        if (disk->info.type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_DRIVE)
            /* the disk does not use disk controller */
            continue;

        /* check whether the disk uses this type controller */
        if (disk->bus == VIR_DOMAIN_DISK_BUS_IDE &&
            detach->type != VIR_DOMAIN_CONTROLLER_TYPE_IDE)
            continue;
        if (disk->bus == VIR_DOMAIN_DISK_BUS_FDC &&
            detach->type != VIR_DOMAIN_CONTROLLER_TYPE_FDC)
            continue;
        if (disk->bus == VIR_DOMAIN_DISK_BUS_SCSI &&
            detach->type != VIR_DOMAIN_CONTROLLER_TYPE_SCSI)
            continue;

        if (disk->info.addr.drive.controller == detach->idx)
            return true;
    }

    return false;
}

static bool qemuDomainControllerIsBusy(virDomainObjPtr vm,
                                       virDomainControllerDefPtr detach)
{
    switch (detach->type) {
    case VIR_DOMAIN_CONTROLLER_TYPE_IDE:
    case VIR_DOMAIN_CONTROLLER_TYPE_FDC:
    case VIR_DOMAIN_CONTROLLER_TYPE_SCSI:
        return qemuDomainDiskControllerIsBusy(vm, detach);

    case VIR_DOMAIN_CONTROLLER_TYPE_SATA:
    case VIR_DOMAIN_CONTROLLER_TYPE_VIRTIO_SERIAL:
    case VIR_DOMAIN_CONTROLLER_TYPE_CCID:
    default:
        /* libvirt does not support sata controller, and does not support to
         * detach virtio and smart card controller.
         */
        return true;
    }
}

2225
int qemuDomainDetachPciControllerDevice(virQEMUDriverPtr driver,
2226
                                        virDomainObjPtr vm,
2227
                                        virDomainDeviceDefPtr dev)
2228
{
2229
    int idx, ret = -1;
2230 2231 2232
    virDomainControllerDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;

2233 2234 2235
    if ((idx = virDomainControllerFind(vm->def,
                                       dev->data.controller->type,
                                       dev->data.controller->idx)) < 0) {
2236 2237 2238 2239
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk controller %s:%d not found"),
                       virDomainControllerTypeToString(dev->data.controller->type),
                       dev->data.controller->idx);
2240 2241 2242
        goto cleanup;
    }

2243 2244
    detach = vm->def->controllers[idx];

2245 2246
    if (!virDomainDeviceAddressIsValid(&detach->info,
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
2247 2248
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("device cannot be detached without a PCI address"));
2249 2250 2251
        goto cleanup;
    }

2252
    if (qemuIsMultiFunctionDevice(vm->def, &detach->info)) {
2253 2254 2255
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device: %s"),
                       dev->data.disk->dst);
2256 2257 2258
        goto cleanup;
    }

2259
    if (qemuDomainControllerIsBusy(vm, detach)) {
2260 2261
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("device cannot be detached: device is busy"));
2262 2263 2264
        goto cleanup;
    }

2265
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2266 2267 2268 2269
        if (qemuAssignDeviceControllerAlias(detach) < 0)
            goto cleanup;
    }

2270
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2271
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2272
        if (qemuMonitorDelDevice(priv->mon, detach->info.alias)) {
2273
            qemuDomainObjExitMonitorWithDriver(driver, vm);
2274 2275 2276 2277 2278
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemovePCIDevice(priv->mon,
                                       &detach->info.addr.pci) < 0) {
2279
            qemuDomainObjExitMonitorWithDriver(driver, vm);
2280 2281 2282 2283 2284
            goto cleanup;
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

2285 2286
    virDomainControllerRemove(vm->def, idx);
    virDomainControllerDefFree(detach);
2287

2288
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
2289 2290
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        detach->info.addr.pci.slot) < 0)
2291
        VIR_WARN("Unable to release PCI address on controller");
2292 2293 2294 2295 2296 2297 2298

    ret = 0;

cleanup:
    return ret;
}

2299
static int
2300
qemuDomainDetachHostPciDevice(virQEMUDriverPtr driver,
2301
                              virDomainObjPtr vm,
2302
                              virDomainHostdevDefPtr detach)
2303 2304
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
2305 2306
    virDomainHostdevSubsysPtr subsys = &detach->source.subsys;
    int ret;
2307
    pciDevice *pci;
2308
    pciDevice *activePci;
2309

2310
    if (qemuIsMultiFunctionDevice(vm->def, detach->info)) {
2311 2312 2313 2314
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device: %.4x:%.2x:%.2x.%.1x"),
                       subsys->u.pci.domain, subsys->u.pci.bus,
                       subsys->u.pci.slot,   subsys->u.pci.function);
2315
        return -1;
2316 2317
    }

2318
    if (!virDomainDeviceAddressIsValid(detach->info,
2319
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
2320 2321
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached without a PCI address"));
2322 2323 2324
        return -1;
    }

2325
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2326
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2327
        ret = qemuMonitorDelDevice(priv->mon, detach->info->alias);
2328
    } else {
2329
        ret = qemuMonitorRemovePCIDevice(priv->mon, &detach->info->addr.pci);
2330 2331
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);
2332
    virDomainAuditHostdev(vm, detach, "detach", ret == 0);
2333 2334
    if (ret < 0)
        return -1;
2335

2336 2337 2338 2339 2340 2341 2342
    /*
     * For SRIOV net host devices, unset mac and port profile before
     * reset and reattach device
     */
     if (detach->parent.data.net)
         qemuDomainHostdevNetConfigRestore(detach, driver->stateDir);

2343 2344
    pci = pciGetDevice(subsys->u.pci.domain, subsys->u.pci.bus,
                       subsys->u.pci.slot,   subsys->u.pci.function);
2345 2346
    if (pci) {
        activePci = pciDeviceListSteal(driver->activePciHostdevs, pci);
2347 2348 2349
        if (activePci &&
            pciResetDevice(activePci, driver->activePciHostdevs,
                           driver->inactivePciHostdevs) == 0) {
2350
            qemuReattachPciDevice(activePci, driver);
2351 2352 2353
        } else {
            /* reset of the device failed, treat it as if it was returned */
            pciFreeDevice(activePci);
2354
            ret = -1;
2355
        }
2356
        pciFreeDevice(pci);
2357 2358
    } else {
        ret = -1;
2359 2360
    }

2361
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
2362
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
2363
                                        detach->info->addr.pci.slot) < 0)
2364
        VIR_WARN("Unable to release PCI address on host device");
2365 2366 2367 2368

    return ret;
}

2369
static int
2370
qemuDomainDetachHostUsbDevice(virQEMUDriverPtr driver,
2371
                              virDomainObjPtr vm,
2372
                              virDomainHostdevDefPtr detach)
2373 2374
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
2375
    virDomainHostdevSubsysPtr subsys = &detach->source.subsys;
2376
    usbDevice *usb;
2377
    int ret;
2378

2379
    if (!detach->info->alias) {
2380 2381
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached without a device alias"));
2382 2383 2384
        return -1;
    }

2385
    if (!qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2386 2387
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached with this QEMU version"));
2388 2389 2390
        return -1;
    }

2391
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2392
    ret = qemuMonitorDelDevice(priv->mon, detach->info->alias);
2393
    qemuDomainObjExitMonitorWithDriver(driver, vm);
2394
    virDomainAuditHostdev(vm, detach, "detach", ret == 0);
2395 2396
    if (ret < 0)
        return -1;
2397

2398
    usb = usbGetDevice(subsys->u.usb.bus, subsys->u.usb.device, NULL);
2399 2400 2401 2402 2403
    if (usb) {
        usbDeviceListDel(driver->activeUsbHostdevs, usb);
        usbFreeDevice(usb);
    } else {
        VIR_WARN("Unable to find device %03d.%03d in list of used USB devices",
2404
                 subsys->u.usb.bus, subsys->u.usb.device);
2405 2406 2407 2408
    }
    return ret;
}

2409
static
2410
int qemuDomainDetachThisHostDevice(virQEMUDriverPtr driver,
2411 2412 2413
                                   virDomainObjPtr vm,
                                   virDomainHostdevDefPtr detach,
                                   int idx)
2414
{
2415
    int ret = -1;
2416

2417 2418 2419 2420 2421 2422 2423 2424 2425
    if (idx < 0) {
        /* caller didn't know index of hostdev in hostdevs list, so we
         * need to find it.
         */
        for (idx = 0; idx < vm->def->nhostdevs; idx++) {
            if (vm->def->hostdevs[idx] == detach)
                break;
        }
        if (idx >= vm->def->nhostdevs) {
2426
            virReportError(VIR_ERR_INTERNAL_ERROR,
2427
                           _("device not found in hostdevs list (%zu entries)"),
2428
                           vm->def->nhostdevs);
2429 2430
            return ret;
        }
2431 2432
    }

2433
    switch (detach->source.subsys.type) {
2434
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI:
2435 2436
        ret = qemuDomainDetachHostPciDevice(driver, vm, detach);
        break;
2437
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
2438
        ret = qemuDomainDetachHostUsbDevice(driver, vm, detach);
2439 2440
        break;
    default:
2441 2442 2443
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev subsys type '%s' not supported"),
                       virDomainHostdevSubsysTypeToString(detach->source.subsys.type));
2444 2445 2446
        return -1;
    }

2447 2448
    if (!ret) {
        if (virSecurityManagerRestoreHostdevLabel(driver->securityManager,
2449
                                                  vm->def, detach, NULL) < 0) {
2450 2451 2452 2453
            VIR_WARN("Failed to restore host device labelling");
        }
        virDomainHostdevRemove(vm->def, idx);
        virDomainHostdevDefFree(detach);
2454
    }
2455 2456
    return ret;
}
2457

2458
/* search for a hostdev matching dev and detach it */
2459
int qemuDomainDetachHostDevice(virQEMUDriverPtr driver,
2460 2461 2462 2463 2464 2465 2466 2467 2468
                               virDomainObjPtr vm,
                               virDomainDeviceDefPtr dev)
{
    virDomainHostdevDefPtr hostdev = dev->data.hostdev;
    virDomainHostdevSubsysPtr subsys = &hostdev->source.subsys;
    virDomainHostdevDefPtr detach = NULL;
    int idx;

    if (hostdev->mode != VIR_DOMAIN_HOSTDEV_MODE_SUBSYS) {
2469 2470 2471
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev mode '%s' not supported"),
                       virDomainHostdevModeTypeToString(hostdev->mode));
2472 2473 2474 2475 2476 2477
        return -1;
    }

    idx = virDomainHostdevFind(vm->def, hostdev, &detach);

    if (idx < 0) {
2478
        switch (subsys->type) {
2479
        case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI:
2480 2481 2482 2483
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("host pci device %.4x:%.2x:%.2x.%.1x not found"),
                           subsys->u.pci.domain, subsys->u.pci.bus,
                           subsys->u.pci.slot, subsys->u.pci.function);
2484 2485 2486
            break;
        case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
            if (subsys->u.usb.bus && subsys->u.usb.device) {
2487 2488 2489
                virReportError(VIR_ERR_OPERATION_FAILED,
                               _("host usb device %03d.%03d not found"),
                               subsys->u.usb.bus, subsys->u.usb.device);
2490
            } else {
2491 2492 2493
                virReportError(VIR_ERR_OPERATION_FAILED,
                               _("host usb device vendor=0x%.4x product=0x%.4x not found"),
                               subsys->u.usb.vendor, subsys->u.usb.product);
2494 2495 2496
            }
            break;
        default:
2497 2498
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("unexpected hostdev type %d"), subsys->type);
2499 2500 2501 2502 2503
            break;
        }
        return -1;
    }

2504 2505 2506 2507 2508 2509 2510
    /* If this is a network hostdev, we need to use the higher-level detach
     * function so that mac address / virtualport are reset
     */
    if (detach->parent.type == VIR_DOMAIN_DEVICE_NET)
        return qemuDomainDetachNetDevice(driver, vm, &detach->parent);
    else
        return qemuDomainDetachThisHostDevice(driver, vm, detach, idx);
2511 2512
}

2513
int
2514
qemuDomainDetachNetDevice(virQEMUDriverPtr driver,
2515 2516 2517
                          virDomainObjPtr vm,
                          virDomainDeviceDefPtr dev)
{
2518
    int detachidx, ret = -1;
2519 2520 2521 2522
    virDomainNetDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    int vlan;
    char *hostnet_name = NULL;
2523
    char mac[VIR_MAC_STRING_BUFLEN];
2524 2525
    virNetDevVPortProfilePtr vport = NULL;

2526 2527 2528 2529 2530 2531
    detachidx = virDomainNetFindIdx(vm->def, dev->data.net);
    if (detachidx == -2) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("multiple devices matching mac address %s found"),
                       virMacAddrFormat(&dev->data.net->mac, mac));
        goto cleanup;
2532
        }
2533
    else if (detachidx < 0) {
2534
        virReportError(VIR_ERR_OPERATION_FAILED,
2535 2536
                       _("network device %s not found"),
                       virMacAddrFormat(&dev->data.net->mac, mac));
2537 2538
        goto cleanup;
    }
2539
    detach = vm->def->nets[detachidx];
2540

2541 2542 2543 2544 2545 2546 2547
    if (virDomainNetGetActualType(detach) == VIR_DOMAIN_NET_TYPE_HOSTDEV) {
        ret = qemuDomainDetachThisHostDevice(driver, vm,
                                             virDomainNetGetActualHostdev(detach),
                                             -1);
        goto cleanup;
    }

2548 2549
    if (!virDomainDeviceAddressIsValid(&detach->info,
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
2550 2551
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached without a PCI address"));
2552 2553 2554 2555
        goto cleanup;
    }

    if (qemuIsMultiFunctionDevice(vm->def, &detach->info)) {
2556 2557 2558
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device :%s"),
                       dev->data.disk->dst);
2559 2560 2561 2562
        goto cleanup;
    }

    if ((vlan = qemuDomainNetVLAN(detach)) < 0) {
2563 2564
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("unable to determine original VLAN"));
2565 2566 2567 2568 2569 2570 2571 2572 2573
        goto cleanup;
    }

    if (virAsprintf(&hostnet_name, "host%s", detach->info.alias) < 0) {
        virReportOOMError();
        goto cleanup;
    }

    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2574
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2575 2576 2577 2578 2579 2580 2581 2582 2583 2584 2585 2586 2587 2588
        if (qemuMonitorDelDevice(priv->mon, detach->info.alias) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemovePCIDevice(priv->mon,
                                       &detach->info.addr.pci) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    }

2589 2590
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2591 2592 2593 2594 2595 2596 2597 2598 2599 2600 2601 2602 2603 2604 2605 2606
        if (qemuMonitorRemoveNetdev(priv->mon, hostnet_name) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemoveHostNetwork(priv->mon, vlan, hostnet_name) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    virDomainAuditNet(vm, detach, NULL, "detach", true);

2607
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
2608 2609 2610 2611 2612 2613 2614 2615
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        detach->info.addr.pci.slot) < 0)
        VIR_WARN("Unable to release PCI address on NIC");

    virDomainConfNWFilterTeardown(detach);

    if (virDomainNetGetActualType(detach) == VIR_DOMAIN_NET_TYPE_DIRECT) {
        ignore_value(virNetDevMacVLanDeleteWithVPortProfile(
2616
                         detach->ifname, &detach->mac,
2617 2618 2619 2620 2621 2622 2623 2624 2625 2626
                         virDomainNetGetActualDirectDev(detach),
                         virDomainNetGetActualDirectMode(detach),
                         virDomainNetGetActualVirtPortProfile(detach),
                         driver->stateDir));
        VIR_FREE(detach->ifname);
    }

    if ((driver->macFilter) && (detach->ifname != NULL)) {
        if ((errno = networkDisallowMacOnPort(driver,
                                              detach->ifname,
2627
                                              &detach->mac))) {
2628
            virReportSystemError(errno,
2629
             _("failed to remove ebtables rule on '%s'"),
2630 2631 2632 2633 2634 2635 2636 2637 2638 2639 2640
                                 detach->ifname);
        }
    }

    vport = virDomainNetGetActualVirtPortProfile(detach);
    if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
        ignore_value(virNetDevOpenvswitchRemovePort(
                        virDomainNetGetActualBridgeName(detach),
                        detach->ifname));
    ret = 0;
cleanup:
2641 2642
    if (!ret) {
        networkReleaseActualDevice(detach);
2643
        virDomainNetRemove(vm->def, detachidx);
2644 2645
        virDomainNetDefFree(detach);
    }
2646 2647 2648 2649
    VIR_FREE(hostnet_name);
    return ret;
}

2650
int
2651
qemuDomainChangeGraphicsPasswords(virQEMUDriverPtr driver,
2652 2653 2654 2655 2656 2657 2658 2659
                                  virDomainObjPtr vm,
                                  int type,
                                  virDomainGraphicsAuthDefPtr auth,
                                  const char *defaultPasswd)
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    time_t now = time(NULL);
    char expire_time [64];
2660
    const char *connected = NULL;
2661 2662 2663 2664 2665
    int ret;

    if (!auth->passwd && !driver->vncPassword)
        return 0;

2666 2667 2668
    if (auth->connected)
        connected = virDomainGraphicsAuthConnectedTypeToString(auth->connected);

2669
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2670 2671 2672
    ret = qemuMonitorSetPassword(priv->mon,
                                 type,
                                 auth->passwd ? auth->passwd : defaultPasswd,
2673
                                 connected);
2674 2675 2676

    if (ret == -2) {
        if (type != VIR_DOMAIN_GRAPHICS_TYPE_VNC) {
2677 2678
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("Graphics password only supported for VNC"));
2679 2680 2681 2682 2683 2684
            ret = -1;
        } else {
            ret = qemuMonitorSetVNCPassword(priv->mon,
                                            auth->passwd ? auth->passwd : defaultPasswd);
        }
    }
2685 2686 2687
    if (ret != 0)
        goto cleanup;

2688 2689 2690
    if (auth->expires) {
        time_t lifetime = auth->validTo - now;
        if (lifetime <= 0)
2691
            snprintf(expire_time, sizeof(expire_time), "now");
2692
        else
2693
            snprintf(expire_time, sizeof(expire_time), "%lu", (long unsigned)auth->validTo);
2694
    } else {
2695
        snprintf(expire_time, sizeof(expire_time), "never");
2696 2697 2698 2699 2700 2701 2702
    }

    ret = qemuMonitorExpirePassword(priv->mon, type, expire_time);

    if (ret == -2) {
        /* XXX we could fake this with a timer */
        if (auth->expires) {
2703 2704
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("Expiry of passwords is not supported"));
2705
            ret = -1;
2706 2707
        } else {
            ret = 0;
2708 2709 2710
        }
    }

2711
cleanup:
2712 2713 2714 2715
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    return ret;
}
2716

2717
int qemuDomainAttachLease(virQEMUDriverPtr driver,
2718 2719 2720 2721 2722 2723
                          virDomainObjPtr vm,
                          virDomainLeaseDefPtr lease)
{
    if (virDomainLeaseInsertPreAlloc(vm->def) < 0)
        return -1;

2724 2725
    if (virDomainLockLeaseAttach(driver->lockManager, driver->uri,
                                 vm, lease) < 0) {
2726 2727 2728 2729 2730 2731 2732 2733
        virDomainLeaseInsertPreAlloced(vm->def, NULL);
        return -1;
    }

    virDomainLeaseInsertPreAlloced(vm->def, lease);
    return 0;
}

2734
int qemuDomainDetachLease(virQEMUDriverPtr driver,
2735 2736 2737
                          virDomainObjPtr vm,
                          virDomainLeaseDefPtr lease)
{
2738
    virDomainLeaseDefPtr det_lease;
2739 2740 2741
    int i;

    if ((i = virDomainLeaseIndex(vm->def, lease)) < 0) {
2742 2743 2744
        virReportError(VIR_ERR_INVALID_ARG,
                       _("Lease %s in lockspace %s does not exist"),
                       lease->key, NULLSTR(lease->lockspace));
2745 2746 2747 2748 2749 2750
        return -1;
    }

    if (virDomainLockLeaseDetach(driver->lockManager, vm, lease) < 0)
        return -1;

2751 2752
    det_lease = virDomainLeaseRemoveAt(vm->def, i);
    virDomainLeaseDefFree(det_lease);
2753 2754
    return 0;
}