lxc_driver.c 176.1 KB
Newer Older
D
Daniel Veillard 已提交
1
/*
2
 * Copyright (C) 2010-2014 Red Hat, Inc.
D
Daniel Veillard 已提交
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
 * Copyright IBM Corp. 2008
 *
 * lxc_driver.c: linux container driver functions
 *
 * Authors:
 *  David L. Leskovec <dlesko at linux.vnet.ibm.com>
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
21
 * License along with this library.  If not, see
O
Osier Yang 已提交
22
 * <http://www.gnu.org/licenses/>.
D
Daniel Veillard 已提交
23 24 25 26
 */

#include <config.h>

27
#include <fcntl.h>
D
Daniel Veillard 已提交
28 29 30 31
#include <sched.h>
#include <sys/utsname.h>
#include <string.h>
#include <sys/types.h>
32
#include <sys/socket.h>
33
#include <sys/stat.h>
34 35
#include <sys/un.h>
#include <sys/poll.h>
D
Daniel Veillard 已提交
36 37 38
#include <unistd.h>
#include <wait.h>

39
#include "virerror.h"
40
#include "virlog.h"
41
#include "datatypes.h"
42
#include "lxc_cgroup.h"
D
Daniel Veillard 已提交
43
#include "lxc_conf.h"
44
#include "lxc_container.h"
45
#include "lxc_domain.h"
D
Daniel Veillard 已提交
46
#include "lxc_driver.h"
47
#include "lxc_native.h"
48
#include "lxc_process.h"
49
#include "viralloc.h"
50
#include "virnetdevbridge.h"
51
#include "virnetdevveth.h"
52
#include "nodeinfo.h"
53
#include "viruuid.h"
54
#include "virstatslinux.h"
55
#include "virhook.h"
E
Eric Blake 已提交
56
#include "virfile.h"
57
#include "virpidfile.h"
58
#include "fdstream.h"
59
#include "domain_audit.h"
60
#include "domain_nwfilter.h"
61
#include "nwfilter_conf.h"
62
#include "network/bridge_driver.h"
63
#include "virinitctl.h"
64
#include "virnetdev.h"
A
Ansis Atteka 已提交
65
#include "virnetdevtap.h"
66
#include "virnodesuspend.h"
67
#include "virprocess.h"
68
#include "virtime.h"
69
#include "virtypedparam.h"
M
Martin Kletzander 已提交
70
#include "viruri.h"
71
#include "virstring.h"
72 73
#include "viraccessapicheck.h"
#include "viraccessapichecklxc.h"
74
#include "virhostdev.h"
D
Daniel Veillard 已提交
75

76 77
#define VIR_FROM_THIS VIR_FROM_LXC

78
VIR_LOG_INIT("lxc.lxc_driver");
79

80
#define LXC_NB_MEM_PARAM  3
81
#define LXC_NB_DOMAIN_BLOCK_STAT_PARAM 4
82

83

84 85 86 87
static int lxcStateInitialize(bool privileged,
                              virStateInhibitCallback callback,
                              void *opaque);
static int lxcStateCleanup(void);
88
virLXCDriverPtr lxc_driver = NULL;
D
Daniel Veillard 已提交
89

90 91
/* callbacks for nwfilter */
static int
92
lxcVMFilterRebuild(virDomainObjListIterator iter, void *data)
93
{
94
    return virDomainObjListForEach(lxc_driver->domains, iter, data);
95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115
}

static void
lxcVMDriverLock(void)
{
    lxcDriverLock(lxc_driver);
}

static void
lxcVMDriverUnlock(void)
{
    lxcDriverUnlock(lxc_driver);
}

static virNWFilterCallbackDriver lxcCallbackDriver = {
    .name = "LXC",
    .vmFilterRebuild = lxcVMFilterRebuild,
    .vmDriverLock = lxcVMDriverLock,
    .vmDriverUnlock = lxcVMDriverUnlock,
};

M
Michal Privoznik 已提交
116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144
/**
 * lxcDomObjFromDomain:
 * @domain: Domain pointer that has to be looked up
 *
 * This function looks up @domain and returns the appropriate
 * virDomainObjPtr.
 *
 * Returns the domain object which is locked on success, NULL
 * otherwise.
 */
static virDomainObjPtr
lxcDomObjFromDomain(virDomainPtr domain)
{
    virDomainObjPtr vm;
    virLXCDriverPtr driver = domain->conn->privateData;
    char uuidstr[VIR_UUID_STRING_BUFLEN];

    vm = virDomainObjListFindByUUID(driver->domains, domain->uuid);
    if (!vm) {
        virUUIDFormat(domain->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s' (%s)"),
                       uuidstr, domain->name);
        return NULL;
    }

    return vm;
}

D
Daniel Veillard 已提交
145 146
/* Functions */

147 148 149
static virDrvOpenStatus lxcConnectOpen(virConnectPtr conn,
                                       virConnectAuthPtr auth ATTRIBUTE_UNUSED,
                                       unsigned int flags)
D
Daniel Veillard 已提交
150
{
E
Eric Blake 已提交
151 152
    virCheckFlags(VIR_CONNECT_RO, VIR_DRV_OPEN_ERROR);

D
Daniel Veillard 已提交
153
    /* Verify uri was specified */
154
    if (conn->uri == NULL) {
155 156
        if (lxc_driver == NULL)
            return VIR_DRV_OPEN_DECLINED;
157

158
        if (!(conn->uri = virURIParse("lxc:///")))
159
            return VIR_DRV_OPEN_ERROR;
160 161 162 163 164 165 166 167 168 169
    } else {
        if (conn->uri->scheme == NULL ||
            STRNEQ(conn->uri->scheme, "lxc"))
            return VIR_DRV_OPEN_DECLINED;

        /* Leave for remote driver */
        if (conn->uri->server != NULL)
            return VIR_DRV_OPEN_DECLINED;

        /* If path isn't '/' then they typoed, tell them correct path */
170 171
        if (conn->uri->path != NULL &&
            STRNEQ(conn->uri->path, "/")) {
172 173 174
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unexpected LXC URI path '%s', try lxc:///"),
                           conn->uri->path);
175 176
            return VIR_DRV_OPEN_ERROR;
        }
D
Daniel Veillard 已提交
177

178 179
        /* URI was good, but driver isn't active */
        if (lxc_driver == NULL) {
180 181
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("lxc state driver is not active"));
182 183 184
            return VIR_DRV_OPEN_ERROR;
        }
    }
185

186 187 188
    if (virConnectOpenEnsureACL(conn) < 0)
        return VIR_DRV_OPEN_ERROR;

189
    conn->privateData = lxc_driver;
D
Daniel Veillard 已提交
190 191 192 193

    return VIR_DRV_OPEN_SUCCESS;
}

194
static int lxcConnectClose(virConnectPtr conn)
D
Daniel Veillard 已提交
195
{
196
    virLXCDriverPtr driver = conn->privateData;
197

198
    virCloseCallbacksRun(driver->closeCallbacks, conn, driver->domains, driver);
199 200
    conn->privateData = NULL;
    return 0;
D
Daniel Veillard 已提交
201 202
}

203

204
static int lxcConnectIsSecure(virConnectPtr conn ATTRIBUTE_UNUSED)
205 206 207 208 209 210
{
    /* Trivially secure, since always inside the daemon */
    return 1;
}


211
static int lxcConnectIsEncrypted(virConnectPtr conn ATTRIBUTE_UNUSED)
212 213 214 215 216 217
{
    /* Not encrypted, but remote driver takes care of that */
    return 0;
}


218
static int lxcConnectIsAlive(virConnectPtr conn ATTRIBUTE_UNUSED)
219 220 221 222 223
{
    return 1;
}


224
static char *lxcConnectGetCapabilities(virConnectPtr conn) {
225
    virLXCDriverPtr driver = conn->privateData;
226
    virCapsPtr caps;
227 228
    char *xml;

229 230 231
    if (virConnectGetCapabilitiesEnsureACL(conn) < 0)
        return NULL;

232
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
233 234
        return NULL;

235
    xml = virCapabilitiesFormatXML(caps);
236

237
    virObjectUnref(caps);
238 239 240 241
    return xml;
}


D
Daniel Veillard 已提交
242 243 244
static virDomainPtr lxcDomainLookupByID(virConnectPtr conn,
                                        int id)
{
245
    virLXCDriverPtr driver = conn->privateData;
246 247
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
248

249
    vm = virDomainObjListFindByID(driver->domains, id);
250

D
Daniel Veillard 已提交
251
    if (!vm) {
252 253
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching id %d"), id);
254
        goto cleanup;
D
Daniel Veillard 已提交
255 256
    }

257 258 259
    if (virDomainLookupByIDEnsureACL(conn, vm->def) < 0)
        goto cleanup;

D
Daniel Veillard 已提交
260
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
261
    if (dom)
D
Daniel Veillard 已提交
262 263
        dom->id = vm->def->id;

264
 cleanup:
265
    if (vm)
266
        virObjectUnlock(vm);
D
Daniel Veillard 已提交
267 268 269 270 271 272
    return dom;
}

static virDomainPtr lxcDomainLookupByUUID(virConnectPtr conn,
                                          const unsigned char *uuid)
{
273
    virLXCDriverPtr driver = conn->privateData;
274 275
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
276

277
    vm = virDomainObjListFindByUUID(driver->domains, uuid);
278

D
Daniel Veillard 已提交
279
    if (!vm) {
280 281
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(uuid, uuidstr);
282 283
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
284
        goto cleanup;
D
Daniel Veillard 已提交
285 286
    }

287 288 289
    if (virDomainLookupByUUIDEnsureACL(conn, vm->def) < 0)
        goto cleanup;

D
Daniel Veillard 已提交
290
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
291
    if (dom)
D
Daniel Veillard 已提交
292 293
        dom->id = vm->def->id;

294
 cleanup:
295
    if (vm)
296
        virObjectUnlock(vm);
D
Daniel Veillard 已提交
297 298 299 300 301 302
    return dom;
}

static virDomainPtr lxcDomainLookupByName(virConnectPtr conn,
                                          const char *name)
{
303
    virLXCDriverPtr driver = conn->privateData;
304 305
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
306

307
    vm = virDomainObjListFindByName(driver->domains, name);
D
Daniel Veillard 已提交
308
    if (!vm) {
309 310
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching name '%s'"), name);
311
        goto cleanup;
D
Daniel Veillard 已提交
312 313
    }

314 315 316
    if (virDomainLookupByNameEnsureACL(conn, vm->def) < 0)
        goto cleanup;

D
Daniel Veillard 已提交
317
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
318
    if (dom)
D
Daniel Veillard 已提交
319 320
        dom->id = vm->def->id;

321
 cleanup:
322
    if (vm)
323
        virObjectUnlock(vm);
D
Daniel Veillard 已提交
324 325 326
    return dom;
}

327 328 329 330 331 332

static int lxcDomainIsActive(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
333
    if (!(obj = lxcDomObjFromDomain(dom)))
334
        goto cleanup;
335 336 337 338

    if (virDomainIsActiveEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

339 340
    ret = virDomainObjIsActive(obj);

341
 cleanup:
342
    if (obj)
343
        virObjectUnlock(obj);
344 345 346 347 348 349 350 351 352
    return ret;
}


static int lxcDomainIsPersistent(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
353
    if (!(obj = lxcDomObjFromDomain(dom)))
354
        goto cleanup;
355 356 357 358

    if (virDomainIsPersistentEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

359 360
    ret = obj->persistent;

361
 cleanup:
362
    if (obj)
363
        virObjectUnlock(obj);
364 365 366
    return ret;
}

367 368 369 370 371
static int lxcDomainIsUpdated(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
372
    if (!(obj = lxcDomObjFromDomain(dom)))
373
        goto cleanup;
374 375 376 377

    if (virDomainIsUpdatedEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

378 379
    ret = obj->updated;

380
 cleanup:
381
    if (obj)
382
        virObjectUnlock(obj);
383 384
    return ret;
}
385

386 387
static int lxcConnectListDomains(virConnectPtr conn, int *ids, int nids)
{
388
    virLXCDriverPtr driver = conn->privateData;
389
    int n;
390

391 392 393
    if (virConnectListDomainsEnsureACL(conn) < 0)
        return -1;

394 395
    n = virDomainObjListGetActiveIDs(driver->domains, ids, nids,
                                     virConnectListDomainsCheckACL, conn);
396

397
    return n;
D
Daniel Veillard 已提交
398
}
399

400 401
static int lxcConnectNumOfDomains(virConnectPtr conn)
{
402
    virLXCDriverPtr driver = conn->privateData;
403
    int n;
404

405 406 407
    if (virConnectNumOfDomainsEnsureACL(conn) < 0)
        return -1;

408 409
    n = virDomainObjListNumOfDomains(driver->domains, true,
                                     virConnectNumOfDomainsCheckACL, conn);
410

411
    return n;
D
Daniel Veillard 已提交
412 413
}

414
static int lxcConnectListDefinedDomains(virConnectPtr conn,
415 416
                                        char **const names, int nnames)
{
417
    virLXCDriverPtr driver = conn->privateData;
418
    int n;
419

420 421 422
    if (virConnectListDefinedDomainsEnsureACL(conn) < 0)
        return -1;

423 424
    n = virDomainObjListGetInactiveNames(driver->domains, names, nnames,
                                         virConnectListDefinedDomainsCheckACL, conn);
425

426
    return n;
D
Daniel Veillard 已提交
427 428 429
}


430 431
static int lxcConnectNumOfDefinedDomains(virConnectPtr conn)
{
432
    virLXCDriverPtr driver = conn->privateData;
433
    int n;
434

435 436 437
    if (virConnectNumOfDefinedDomainsEnsureACL(conn) < 0)
        return -1;

438 439
    n = virDomainObjListNumOfDomains(driver->domains, false,
                                     virConnectNumOfDefinedDomainsCheckACL, conn);
440

441
    return n;
D
Daniel Veillard 已提交
442 443
}

444 445


446
static virDomainPtr lxcDomainDefineXML(virConnectPtr conn, const char *xml)
D
Daniel Veillard 已提交
447
{
448
    virLXCDriverPtr driver = conn->privateData;
449
    virDomainDefPtr def = NULL;
450
    virDomainObjPtr vm = NULL;
451
    virDomainPtr dom = NULL;
452
    virObjectEventPtr event = NULL;
453
    virDomainDefPtr oldDef = NULL;
454
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
455
    virCapsPtr caps = NULL;
D
Daniel Veillard 已提交
456

457 458 459 460
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (!(def = virDomainDefParseString(xml, caps, driver->xmlopt,
M
Matthias Bolte 已提交
461
                                        1 << VIR_DOMAIN_VIRT_LXC,
462
                                        VIR_DOMAIN_XML_INACTIVE)))
463
        goto cleanup;
D
Daniel Veillard 已提交
464

465 466 467
    if (virDomainDefineXMLEnsureACL(conn, def) < 0)
        goto cleanup;

468 469 470
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

471
    if ((def->nets != NULL) && !(cfg->have_netns)) {
472 473
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
474
        goto cleanup;
475 476
    }

477
    if (!(vm = virDomainObjListAdd(driver->domains, def,
478
                                   driver->xmlopt,
479
                                   0, &oldDef)))
480 481
        goto cleanup;
    def = NULL;
482
    vm->persistent = 1;
D
Daniel Veillard 已提交
483

484
    if (virDomainSaveConfig(cfg->configDir,
485
                            vm->newDef ? vm->newDef : vm->def) < 0) {
486
        virDomainObjListRemove(driver->domains, vm);
487
        vm = NULL;
488
        goto cleanup;
D
Daniel Veillard 已提交
489 490
    }

491
    event = virDomainEventLifecycleNewFromObj(vm,
492
                                     VIR_DOMAIN_EVENT_DEFINED,
493
                                     !oldDef ?
494 495 496
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED :
                                     VIR_DOMAIN_EVENT_DEFINED_UPDATED);

D
Daniel Veillard 已提交
497
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
498
    if (dom)
D
Daniel Veillard 已提交
499 500
        dom->id = vm->def->id;

501
 cleanup:
502
    virDomainDefFree(def);
503
    virDomainDefFree(oldDef);
504
    if (vm)
505
        virObjectUnlock(vm);
506
    if (event)
507
        virObjectEventStateQueue(driver->domainEventState, event);
508
    virObjectUnref(caps);
509
    virObjectUnref(cfg);
D
Daniel Veillard 已提交
510 511 512
    return dom;
}

513 514
static int lxcDomainUndefineFlags(virDomainPtr dom,
                                  unsigned int flags)
D
Daniel Veillard 已提交
515
{
516
    virLXCDriverPtr driver = dom->conn->privateData;
517
    virDomainObjPtr vm;
518
    virObjectEventPtr event = NULL;
519
    int ret = -1;
520
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
D
Daniel Veillard 已提交
521

522 523
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
524
    if (!(vm = lxcDomObjFromDomain(dom)))
525
        goto cleanup;
D
Daniel Veillard 已提交
526

527 528 529
    if (virDomainUndefineFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

530
    if (!vm->persistent) {
531 532
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot undefine transient domain"));
533
        goto cleanup;
534
    }
D
Daniel Veillard 已提交
535

536 537
    if (virDomainDeleteConfig(cfg->configDir,
                              cfg->autostartDir,
538 539
                              vm) < 0)
        goto cleanup;
D
Daniel Veillard 已提交
540

541
    event = virDomainEventLifecycleNewFromObj(vm,
542 543 544
                                     VIR_DOMAIN_EVENT_UNDEFINED,
                                     VIR_DOMAIN_EVENT_UNDEFINED_REMOVED);

545 546 547
    if (virDomainObjIsActive(vm)) {
        vm->persistent = 0;
    } else {
548
        virDomainObjListRemove(driver->domains, vm);
549 550 551
        vm = NULL;
    }

552
    ret = 0;
D
Daniel Veillard 已提交
553

554
 cleanup:
555
    if (vm)
556
        virObjectUnlock(vm);
557
    if (event)
558
        virObjectEventStateQueue(driver->domainEventState, event);
559
    virObjectUnref(cfg);
560
    return ret;
D
Daniel Veillard 已提交
561 562
}

563 564 565 566 567
static int lxcDomainUndefine(virDomainPtr dom)
{
    return lxcDomainUndefineFlags(dom, 0);
}

D
Daniel Veillard 已提交
568 569 570
static int lxcDomainGetInfo(virDomainPtr dom,
                            virDomainInfoPtr info)
{
571
    virDomainObjPtr vm;
572
    int ret = -1;
573
    virLXCDomainObjPrivatePtr priv;
D
Daniel Veillard 已提交
574

M
Michal Privoznik 已提交
575
    if (!(vm = lxcDomObjFromDomain(dom)))
576
        goto cleanup;
D
Daniel Veillard 已提交
577

578 579
    priv = vm->privateData;

580 581 582
    if (virDomainGetInfoEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

J
Jiri Denemark 已提交
583
    info->state = virDomainObjGetState(vm, NULL);
D
Daniel Veillard 已提交
584

585
    if (!virDomainObjIsActive(vm)) {
D
Daniel Veillard 已提交
586
        info->cpuTime = 0;
587
        info->memory = vm->def->mem.cur_balloon;
D
Daniel Veillard 已提交
588
    } else {
589
        if (virCgroupGetCpuacctUsage(priv->cgroup, &(info->cpuTime)) < 0) {
590 591
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Cannot read cputime for domain"));
R
Ryota Ozaki 已提交
592 593
            goto cleanup;
        }
594 595 596 597 598
        if (virCgroupGetMemoryUsage(priv->cgroup, &(info->memory)) < 0) {
            /* Don't fail if we can't read memory usage due to a lack of
             * kernel support */
            if (virLastErrorIsSystemErrno(ENOENT)) {
                virResetLastError();
599
                info->memory = 0;
600
            } else {
601
                goto cleanup;
602
            }
603
        }
D
Daniel Veillard 已提交
604 605
    }

606
    info->maxMem = vm->def->mem.max_balloon;
607
    info->nrVirtCpu = vm->def->vcpus;
608
    ret = 0;
D
Daniel Veillard 已提交
609

610
 cleanup:
611
    if (vm)
612
        virObjectUnlock(vm);
613
    return ret;
D
Daniel Veillard 已提交
614 615
}

616 617 618 619 620 621 622 623 624 625 626
static int
lxcDomainGetState(virDomainPtr dom,
                  int *state,
                  int *reason,
                  unsigned int flags)
{
    virDomainObjPtr vm;
    int ret = -1;

    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
627
    if (!(vm = lxcDomObjFromDomain(dom)))
628 629
        goto cleanup;

630 631 632
    if (virDomainGetStateEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

J
Jiri Denemark 已提交
633
    *state = virDomainObjGetState(vm, reason);
634 635
    ret = 0;

636
 cleanup:
637
    if (vm)
638
        virObjectUnlock(vm);
639 640 641
    return ret;
}

642
static char *lxcDomainGetOSType(virDomainPtr dom)
D
Daniel Veillard 已提交
643
{
644 645
    virDomainObjPtr vm;
    char *ret = NULL;
646

M
Michal Privoznik 已提交
647
    if (!(vm = lxcDomObjFromDomain(dom)))
648
        goto cleanup;
649

650 651 652 653 654
    if (virDomainGetOSTypeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

    if (VIR_STRDUP(ret, vm->def->os.type) < 0)
        goto cleanup;
655

656
 cleanup:
657
    if (vm)
658
        virObjectUnlock(vm);
659
    return ret;
D
Daniel Veillard 已提交
660 661
}

R
Ryota Ozaki 已提交
662
/* Returns max memory in kb, 0 if error */
663 664 665
static unsigned long long
lxcDomainGetMaxMemory(virDomainPtr dom)
{
R
Ryota Ozaki 已提交
666
    virDomainObjPtr vm;
667
    unsigned long long ret = 0;
R
Ryota Ozaki 已提交
668

M
Michal Privoznik 已提交
669
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
670 671
        goto cleanup;

672 673 674
    if (virDomainGetMaxMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

675
    ret = vm->def->mem.max_balloon;
R
Ryota Ozaki 已提交
676

677
 cleanup:
R
Ryota Ozaki 已提交
678
    if (vm)
679
        virObjectUnlock(vm);
R
Ryota Ozaki 已提交
680 681 682
    return ret;
}

683 684
static int lxcDomainSetMaxMemory(virDomainPtr dom, unsigned long newmax)
{
R
Ryota Ozaki 已提交
685 686 687
    virDomainObjPtr vm;
    int ret = -1;

M
Michal Privoznik 已提交
688
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
689 690
        goto cleanup;

691 692 693
    if (virDomainSetMaxMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

694
    if (newmax < vm->def->mem.cur_balloon) {
695 696
        virReportError(VIR_ERR_INVALID_ARG,
                       "%s", _("Cannot set max memory lower than current memory"));
R
Ryota Ozaki 已提交
697 698 699
        goto cleanup;
    }

700
    vm->def->mem.max_balloon = newmax;
R
Ryota Ozaki 已提交
701 702
    ret = 0;

703
 cleanup:
R
Ryota Ozaki 已提交
704
    if (vm)
705
        virObjectUnlock(vm);
R
Ryota Ozaki 已提交
706 707 708
    return ret;
}

709 710
static int lxcDomainSetMemory(virDomainPtr dom, unsigned long newmem)
{
R
Ryota Ozaki 已提交
711 712
    virDomainObjPtr vm;
    int ret = -1;
713
    virLXCDomainObjPrivatePtr priv;
R
Ryota Ozaki 已提交
714

M
Michal Privoznik 已提交
715
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
716
        goto cleanup;
M
Michal Privoznik 已提交
717

718
    priv = vm->privateData;
R
Ryota Ozaki 已提交
719

720 721 722
    if (virDomainSetMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

723
    if (newmem > vm->def->mem.max_balloon) {
724 725
        virReportError(VIR_ERR_INVALID_ARG,
                       "%s", _("Cannot set memory higher than max memory"));
R
Ryota Ozaki 已提交
726 727 728
        goto cleanup;
    }

729
    if (!virDomainObjIsActive(vm)) {
730 731
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
732 733
        goto cleanup;
    }
734

735
    if (virCgroupSetMemory(priv->cgroup, newmem) < 0) {
736 737
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("Failed to set memory for domain"));
738 739 740
        goto cleanup;
    }

R
Ryota Ozaki 已提交
741 742
    ret = 0;

743
 cleanup:
R
Ryota Ozaki 已提交
744
    if (vm)
745
        virObjectUnlock(vm);
R
Ryota Ozaki 已提交
746 747 748
    return ret;
}

749 750 751 752 753
static int
lxcDomainSetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int nparams,
                             unsigned int flags)
754
{
755 756
    virCapsPtr caps = NULL;
    virDomainDefPtr vmdef = NULL;
757
    virDomainObjPtr vm = NULL;
758 759 760 761 762 763 764 765 766 767
    virLXCDomainObjPrivatePtr priv = NULL;
    virLXCDriverConfigPtr cfg = NULL;
    virLXCDriverPtr driver = dom->conn->privateData;
    unsigned long long hard_limit;
    unsigned long long soft_limit;
    unsigned long long swap_hard_limit;
    bool set_hard_limit = false;
    bool set_soft_limit = false;
    bool set_swap_hard_limit = false;
    int rc;
768 769
    int ret = -1;

770 771 772
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

773 774 775 776 777 778 779 780
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_MEMORY_HARD_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               NULL) < 0)
781
        return -1;
E
Eric Blake 已提交
782

M
Michal Privoznik 已提交
783
    if (!(vm = lxcDomObjFromDomain(dom)))
784
        goto cleanup;
M
Michal Privoznik 已提交
785

786
    priv = vm->privateData;
787
    cfg = virLXCDriverGetConfig(driver);
788

789 790 791 792
    if (virDomainSetMemoryParametersEnsureACL(dom->conn, vm->def, flags) < 0 ||
        !(caps = virLXCDriverGetCapabilities(driver, false)) ||
        virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
                                        vm, &flags, &vmdef) < 0)
793 794
        goto cleanup;

795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831
    if (flags & VIR_DOMAIN_AFFECT_LIVE &&
        !virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_MEMORY)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup memory controller is not mounted"));
        goto cleanup;
    }

#define VIR_GET_LIMIT_PARAMETER(PARAM, VALUE)                                \
    if ((rc = virTypedParamsGetULLong(params, nparams, PARAM, &VALUE)) < 0)  \
        goto cleanup;                                                        \
                                                                             \
    if (rc == 1)                                                             \
        set_ ## VALUE = true;

    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT, swap_hard_limit)
    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_HARD_LIMIT, hard_limit)
    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_SOFT_LIMIT, soft_limit)

#undef VIR_GET_LIMIT_PARAMETER

    /* Swap hard limit must be greater than hard limit.
     * Note that limit of 0 denotes unlimited */
    if (set_swap_hard_limit || set_hard_limit) {
        unsigned long long mem_limit = vm->def->mem.hard_limit;
        unsigned long long swap_limit = vm->def->mem.swap_hard_limit;

        if (set_swap_hard_limit)
            swap_limit = swap_hard_limit;

        if (set_hard_limit)
            mem_limit = hard_limit;

        if (virCompareLimitUlong(mem_limit, swap_limit) > 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("memory hard_limit tunable value must be lower "
                             "than or equal to swap_hard_limit"));
            goto cleanup;
832 833 834
        }
    }

835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872
#define LXC_SET_MEM_PARAMETER(FUNC, VALUE)                                     \
    if (set_ ## VALUE) {                                                        \
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {                                   \
            if ((rc = FUNC(priv->cgroup, VALUE)) < 0) {                         \
                virReportSystemError(-rc, _("unable to set memory %s tunable"), \
                                     #VALUE);                                   \
                                                                                \
                goto cleanup;                                                   \
            }                                                                   \
            vm->def->mem.VALUE = VALUE;                                         \
        }                                                                       \
                                                                                \
        if (flags & VIR_DOMAIN_AFFECT_CONFIG)                                   \
            vmdef->mem.VALUE = VALUE;                                   \
    }

    /* Soft limit doesn't clash with the others */
    LXC_SET_MEM_PARAMETER(virCgroupSetMemorySoftLimit, soft_limit);

    /* set hard limit before swap hard limit if decreasing it */
    if (virCompareLimitUlong(vm->def->mem.hard_limit, hard_limit) > 0) {
        LXC_SET_MEM_PARAMETER(virCgroupSetMemoryHardLimit, hard_limit);
        /* inhibit changing the limit a second time */
        set_hard_limit = false;
    }

    LXC_SET_MEM_PARAMETER(virCgroupSetMemSwapHardLimit, swap_hard_limit);

    /* otherwise increase it after swap hard limit */
    LXC_SET_MEM_PARAMETER(virCgroupSetMemoryHardLimit, hard_limit);

#undef LXC_SET_MEM_PARAMETER

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        virDomainSaveConfig(cfg->configDir, vmdef) < 0)
        goto cleanup;

    ret = 0;
873
 cleanup:
874
    if (vm)
875
        virObjectUnlock(vm);
876 877
    virObjectUnref(caps);
    virObjectUnref(cfg);
878 879 880
    return ret;
}

881 882 883 884 885
static int
lxcDomainGetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int *nparams,
                             unsigned int flags)
886
{
887 888
    virCapsPtr caps = NULL;
    virDomainDefPtr vmdef = NULL;
889
    virDomainObjPtr vm = NULL;
890 891
    virLXCDomainObjPrivatePtr priv = NULL;
    virLXCDriverPtr driver = dom->conn->privateData;
892
    unsigned long long val;
893
    int ret = -1;
894
    size_t i;
895

896
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
897 898 899 900 901
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We don't return strings, and thus trivially support this flag.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;
E
Eric Blake 已提交
902

M
Michal Privoznik 已提交
903
    if (!(vm = lxcDomObjFromDomain(dom)))
904
        goto cleanup;
M
Michal Privoznik 已提交
905

906
    priv = vm->privateData;
907

908 909 910 911 912 913 914 915 916 917
    if (virDomainGetMemoryParametersEnsureACL(dom->conn, vm->def) < 0 ||
        !(caps = virLXCDriverGetCapabilities(driver, false)) ||
        virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
                                        vm, &flags, &vmdef) < 0)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_LIVE &&
        !virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_MEMORY)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup memory controller is not mounted"));
918
        goto cleanup;
919
    }
920

921 922 923 924 925 926 927
    if ((*nparams) == 0) {
        /* Current number of memory parameters supported by cgroups */
        *nparams = LXC_NB_MEM_PARAM;
        ret = 0;
        goto cleanup;
    }

928
    for (i = 0; i < LXC_NB_MEM_PARAM && i < *nparams; i++) {
929
        virTypedParameterPtr param = &params[i];
930 931
        val = 0;

932
        switch (i) {
933
        case 0: /* fill memory hard limit here */
934 935 936 937
            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                val = vmdef->mem.hard_limit;
                val = val ? val : VIR_DOMAIN_MEMORY_PARAM_UNLIMITED;
            } else if (virCgroupGetMemoryHardLimit(priv->cgroup, &val) < 0) {
938
                goto cleanup;
939
            }
940 941
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
942
                goto cleanup;
943 944
            break;
        case 1: /* fill memory soft limit here */
945 946 947 948
            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                val = vmdef->mem.soft_limit;
                val = val ? val : VIR_DOMAIN_MEMORY_PARAM_UNLIMITED;
            } else if (virCgroupGetMemorySoftLimit(priv->cgroup, &val) < 0) {
949
                goto cleanup;
950
            }
951 952
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
953
                goto cleanup;
954 955
            break;
        case 2: /* fill swap hard limit here */
956 957 958 959
            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                val = vmdef->mem.swap_hard_limit;
                val = val ? val : VIR_DOMAIN_MEMORY_PARAM_UNLIMITED;
            } else if (virCgroupGetMemSwapHardLimit(priv->cgroup, &val) < 0) {
960
                goto cleanup;
961
            }
962 963 964
            if (virTypedParameterAssign(param,
                                        VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
965
                goto cleanup;
966 967 968 969
            break;
        }
    }

970 971
    if (*nparams > LXC_NB_MEM_PARAM)
        *nparams = LXC_NB_MEM_PARAM;
972 973
    ret = 0;

974
 cleanup:
975
    if (vm)
976
        virObjectUnlock(vm);
977
    virObjectUnref(caps);
978 979 980
    return ret;
}

981
static char *lxcDomainGetXMLDesc(virDomainPtr dom,
982
                                 unsigned int flags)
D
Daniel Veillard 已提交
983
{
984 985
    virDomainObjPtr vm;
    char *ret = NULL;
D
Daniel Veillard 已提交
986

987 988
    /* Flags checked by virDomainDefFormat */

M
Michal Privoznik 已提交
989
    if (!(vm = lxcDomObjFromDomain(dom)))
990
        goto cleanup;
D
Daniel Veillard 已提交
991

992 993 994
    if (virDomainGetXMLDescEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

995
    ret = virDomainDefFormat((flags & VIR_DOMAIN_XML_INACTIVE) &&
996 997 998
                             vm->newDef ? vm->newDef : vm->def,
                             flags);

999
 cleanup:
1000
    if (vm)
1001
        virObjectUnlock(vm);
1002
    return ret;
D
Daniel Veillard 已提交
1003 1004
}

1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028
static char *lxcConnectDomainXMLFromNative(virConnectPtr conn,
                                           const char *nativeFormat,
                                           const char *nativeConfig,
                                           unsigned int flags)
{
    char *xml = NULL;
    virDomainDefPtr def = NULL;

    virCheckFlags(0, NULL);

    if (virConnectDomainXMLFromNativeEnsureACL(conn) < 0)
        goto cleanup;

    if (STRNEQ(nativeFormat, LXC_CONFIG_FORMAT)) {
        virReportError(VIR_ERR_INVALID_ARG,
                       _("unsupported config type %s"), nativeFormat);
        goto cleanup;
    }

    if (!(def = lxcParseConfigString(nativeConfig)))
        goto cleanup;

    xml = virDomainDefFormat(def, 0);

1029
 cleanup:
1030 1031 1032 1033
    virDomainDefFree(def);
    return xml;
}

1034
/**
1035
 * lxcDomainCreateWithFiles:
1036
 * @dom: domain to start
1037
 * @flags: Must be 0 for now
1038 1039 1040 1041 1042
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
1043 1044 1045 1046
static int lxcDomainCreateWithFiles(virDomainPtr dom,
                                    unsigned int nfiles,
                                    int *files,
                                    unsigned int flags)
1047
{
1048
    virLXCDriverPtr driver = dom->conn->privateData;
1049
    virDomainObjPtr vm;
1050
    virObjectEventPtr event = NULL;
1051
    int ret = -1;
1052
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1053

1054
    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY, -1);
1055

1056 1057
    virNWFilterReadLockFilterUpdates();

M
Michal Privoznik 已提交
1058
    if (!(vm = lxcDomObjFromDomain(dom)))
1059 1060
        goto cleanup;

1061
    if (virDomainCreateWithFilesEnsureACL(dom->conn, vm->def) < 0)
1062 1063
        goto cleanup;

1064
    if ((vm->def->nets != NULL) && !(cfg->have_netns)) {
1065 1066
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
1067 1068 1069
        goto cleanup;
    }

1070
    if (virDomainObjIsActive(vm)) {
1071 1072
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is already running"));
1073 1074 1075
        goto cleanup;
    }

1076
    ret = virLXCProcessStart(dom->conn, driver, vm,
1077
                             nfiles, files,
1078 1079
                             (flags & VIR_DOMAIN_START_AUTODESTROY),
                             VIR_DOMAIN_RUNNING_BOOTED);
1080

1081
    if (ret == 0) {
1082
        event = virDomainEventLifecycleNewFromObj(vm,
1083 1084
                                         VIR_DOMAIN_EVENT_STARTED,
                                         VIR_DOMAIN_EVENT_STARTED_BOOTED);
1085 1086 1087 1088
        virDomainAuditStart(vm, "booted", true);
    } else {
        virDomainAuditStart(vm, "booted", false);
    }
1089

1090
 cleanup:
1091
    if (vm)
1092
        virObjectUnlock(vm);
1093
    if (event)
1094
        virObjectEventStateQueue(driver->domainEventState, event);
1095
    virObjectUnref(cfg);
1096
    virNWFilterUnlockFilterUpdates();
1097
    return ret;
1098 1099
}

1100
/**
1101
 * lxcDomainCreate:
1102 1103 1104 1105 1106 1107
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
1108
static int lxcDomainCreate(virDomainPtr dom)
1109
{
1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124
    return lxcDomainCreateWithFiles(dom, 0, NULL, 0);
}

/**
 * lxcDomainCreateWithFlags:
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
static int lxcDomainCreateWithFlags(virDomainPtr dom,
                                    unsigned int flags)
{
    return lxcDomainCreateWithFiles(dom, 0, NULL, flags);
1125 1126
}

1127
/**
1128
 * lxcDomainCreateXMLWithFiles:
1129 1130
 * @conn: pointer to connection
 * @xml: XML definition of domain
1131 1132 1133
 * @nfiles: number of file descriptors passed
 * @files: list of file descriptors passed
 * @flags: bitwise-OR of supported virDomainCreateFlags
1134 1135 1136
 *
 * Creates a domain based on xml and starts it
 *
1137
 * Returns a new domain object or NULL in case of failure.
1138 1139
 */
static virDomainPtr
1140 1141 1142 1143
lxcDomainCreateXMLWithFiles(virConnectPtr conn,
                            const char *xml,
                            unsigned int nfiles,
                            int *files,
1144 1145
                            unsigned int flags)
{
1146
    virLXCDriverPtr driver = conn->privateData;
1147
    virDomainObjPtr vm = NULL;
1148
    virDomainDefPtr def = NULL;
1149
    virDomainPtr dom = NULL;
1150
    virObjectEventPtr event = NULL;
1151
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1152
    virCapsPtr caps = NULL;
1153

1154
    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY, NULL);
1155

1156 1157
    virNWFilterReadLockFilterUpdates();

1158 1159 1160 1161
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (!(def = virDomainDefParseString(xml, caps, driver->xmlopt,
M
Matthias Bolte 已提交
1162
                                        1 << VIR_DOMAIN_VIRT_LXC,
1163
                                        VIR_DOMAIN_XML_INACTIVE)))
1164
        goto cleanup;
1165

1166
    if (virDomainCreateXMLWithFilesEnsureACL(conn, def) < 0)
1167 1168
        goto cleanup;

1169 1170 1171
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

1172
    if ((def->nets != NULL) && !(cfg->have_netns)) {
1173 1174
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       "%s", _("System lacks NETNS support"));
1175
        goto cleanup;
1176 1177
    }

1178

1179
    if (!(vm = virDomainObjListAdd(driver->domains, def,
1180
                                   driver->xmlopt,
1181 1182
                                   VIR_DOMAIN_OBJ_LIST_ADD_CHECK_LIVE,
                                   NULL)))
1183 1184
        goto cleanup;
    def = NULL;
1185

1186
    if (virLXCProcessStart(conn, driver, vm,
1187
                           nfiles, files,
1188 1189
                           (flags & VIR_DOMAIN_START_AUTODESTROY),
                           VIR_DOMAIN_RUNNING_BOOTED) < 0) {
1190
        virDomainAuditStart(vm, "booted", false);
1191
        virDomainObjListRemove(driver->domains, vm);
1192
        vm = NULL;
1193
        goto cleanup;
1194 1195
    }

1196
    event = virDomainEventLifecycleNewFromObj(vm,
1197 1198
                                     VIR_DOMAIN_EVENT_STARTED,
                                     VIR_DOMAIN_EVENT_STARTED_BOOTED);
1199
    virDomainAuditStart(vm, "booted", true);
1200

1201
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
1202
    if (dom)
1203 1204
        dom->id = vm->def->id;

1205
 cleanup:
1206
    virDomainDefFree(def);
1207
    if (vm)
1208
        virObjectUnlock(vm);
1209
    if (event)
1210
        virObjectEventStateQueue(driver->domainEventState, event);
1211
    virObjectUnref(caps);
1212
    virObjectUnref(cfg);
1213
    virNWFilterUnlockFilterUpdates();
1214 1215 1216
    return dom;
}

1217 1218 1219 1220 1221 1222 1223 1224 1225 1226
/**
 * lxcDomainCreateXML:
 * @conn: pointer to connection
 * @xml: XML definition of domain
 * @flags: bitwise-OR of supported virDomainCreateFlags
 *
 * Creates a domain based on xml and starts it
 *
 * Returns a new domain object or NULL in case of failure.
 */
1227 1228 1229
static virDomainPtr
lxcDomainCreateXML(virConnectPtr conn,
                   const char *xml,
1230 1231
                   unsigned int flags)
{
1232 1233 1234 1235
    return lxcDomainCreateXMLWithFiles(conn, xml, 0, NULL,  flags);
}


1236 1237
static int lxcDomainGetSecurityLabel(virDomainPtr dom, virSecurityLabelPtr seclabel)
{
1238
    virLXCDriverPtr driver = dom->conn->privateData;
1239 1240 1241 1242 1243
    virDomainObjPtr vm;
    int ret = -1;

    memset(seclabel, 0, sizeof(*seclabel));

M
Michal Privoznik 已提交
1244
    if (!(vm = lxcDomObjFromDomain(dom)))
1245 1246
        goto cleanup;

1247 1248 1249
    if (virDomainGetSecurityLabelEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1250
    if (!virDomainVirtTypeToString(vm->def->virtType)) {
1251 1252 1253
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unknown virt type in domain definition '%d'"),
                       vm->def->virtType);
1254 1255 1256 1257 1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268 1269 1270 1271
        goto cleanup;
    }

    /*
     * Theoretically, the pid can be replaced during this operation and
     * return the label of a different process.  If atomicity is needed,
     * further validation will be required.
     *
     * Comment from Dan Berrange:
     *
     *   Well the PID as stored in the virDomainObjPtr can't be changed
     *   because you've got a locked object.  The OS level PID could have
     *   exited, though and in extreme circumstances have cycled through all
     *   PIDs back to ours. We could sanity check that our PID still exists
     *   after reading the label, by checking that our FD connecting to the
     *   LXC monitor hasn't seen SIGHUP/ERR on poll().
     */
    if (virDomainObjIsActive(vm)) {
1272 1273 1274 1275 1276 1277 1278 1279
        virLXCDomainObjPrivatePtr priv = vm->privateData;

        if (!priv->initpid) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("Init pid is not yet available"));
            goto cleanup;
        }

1280
        if (virSecurityManagerGetProcessLabel(driver->securityManager,
1281
                                              vm->def, priv->initpid, seclabel) < 0) {
1282 1283
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("Failed to get security label"));
1284 1285 1286 1287 1288 1289
            goto cleanup;
        }
    }

    ret = 0;

1290
 cleanup:
1291
    if (vm)
1292
        virObjectUnlock(vm);
1293 1294 1295 1296 1297 1298
    return ret;
}

static int lxcNodeGetSecurityModel(virConnectPtr conn,
                                   virSecurityModelPtr secmodel)
{
1299
    virLXCDriverPtr driver = conn->privateData;
1300
    virCapsPtr caps = NULL;
1301 1302 1303 1304
    int ret = 0;

    memset(secmodel, 0, sizeof(*secmodel));

1305 1306 1307
    if (virNodeGetSecurityModelEnsureACL(conn) < 0)
        goto cleanup;

1308 1309 1310
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

1311
    /* we treat no driver as success, but simply return no data in *secmodel */
1312 1313
    if (caps->host.nsecModels == 0
        || caps->host.secModels[0].model == NULL)
1314 1315
        goto cleanup;

1316
    if (!virStrcpy(secmodel->model, caps->host.secModels[0].model,
1317
                   VIR_SECURITY_MODEL_BUFLEN)) {
1318 1319 1320
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security model string exceeds max %d bytes"),
                       VIR_SECURITY_MODEL_BUFLEN - 1);
1321 1322 1323 1324
        ret = -1;
        goto cleanup;
    }

1325
    if (!virStrcpy(secmodel->doi, caps->host.secModels[0].doi,
1326
                   VIR_SECURITY_DOI_BUFLEN)) {
1327 1328 1329
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security DOI string exceeds max %d bytes"),
                       VIR_SECURITY_DOI_BUFLEN-1);
1330 1331 1332 1333
        ret = -1;
        goto cleanup;
    }

1334
 cleanup:
1335
    virObjectUnref(caps);
1336 1337 1338 1339
    return ret;
}


1340
static int
1341 1342 1343 1344
lxcConnectDomainEventRegister(virConnectPtr conn,
                              virConnectDomainEventCallback callback,
                              void *opaque,
                              virFreeCallback freecb)
1345
{
1346
    virLXCDriverPtr driver = conn->privateData;
1347

1348 1349 1350
    if (virConnectDomainEventRegisterEnsureACL(conn) < 0)
        return -1;

1351 1352 1353 1354
    if (virDomainEventStateRegister(conn,
                                    driver->domainEventState,
                                    callback, opaque, freecb) < 0)
        return -1;
1355

1356
    return 0;
1357 1358
}

1359

1360
static int
1361 1362
lxcConnectDomainEventDeregister(virConnectPtr conn,
                                virConnectDomainEventCallback callback)
1363
{
1364
    virLXCDriverPtr driver = conn->privateData;
1365

1366 1367 1368
    if (virConnectDomainEventDeregisterEnsureACL(conn) < 0)
        return -1;

1369 1370 1371 1372
    if (virDomainEventStateDeregister(conn,
                                      driver->domainEventState,
                                      callback) < 0)
        return -1;
1373

1374
    return 0;
1375 1376
}

1377 1378

static int
1379 1380 1381 1382 1383 1384
lxcConnectDomainEventRegisterAny(virConnectPtr conn,
                                 virDomainPtr dom,
                                 int eventID,
                                 virConnectDomainEventGenericCallback callback,
                                 void *opaque,
                                 virFreeCallback freecb)
1385
{
1386
    virLXCDriverPtr driver = conn->privateData;
1387 1388
    int ret;

1389 1390 1391
    if (virConnectDomainEventRegisterAnyEnsureACL(conn) < 0)
        return -1;

1392 1393 1394 1395
    if (virDomainEventStateRegisterID(conn,
                                      driver->domainEventState,
                                      dom, eventID,
                                      callback, opaque, freecb, &ret) < 0)
1396
        ret = -1;
1397 1398 1399 1400 1401 1402

    return ret;
}


static int
1403 1404
lxcConnectDomainEventDeregisterAny(virConnectPtr conn,
                                   int callbackID)
1405
{
1406
    virLXCDriverPtr driver = conn->privateData;
1407

1408 1409 1410
    if (virConnectDomainEventDeregisterAnyEnsureACL(conn) < 0)
        return -1;

1411 1412 1413 1414
    if (virObjectEventStateDeregisterID(conn,
                                        driver->domainEventState,
                                        callbackID) < 0)
        return -1;
1415

1416
    return 0;
1417 1418 1419
}


1420
/**
1421
 * lxcDomainDestroyFlags:
1422
 * @dom: pointer to domain to destroy
1423
 * @flags: an OR'ed set of virDomainDestroyFlags
1424 1425 1426 1427 1428
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
1429 1430 1431
static int
lxcDomainDestroyFlags(virDomainPtr dom,
                      unsigned int flags)
1432
{
1433
    virLXCDriverPtr driver = dom->conn->privateData;
1434
    virDomainObjPtr vm;
1435
    virObjectEventPtr event = NULL;
1436
    int ret = -1;
1437
    virLXCDomainObjPrivatePtr priv;
1438

1439 1440
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
1441
    if (!(vm = lxcDomObjFromDomain(dom)))
1442
        goto cleanup;
1443

1444 1445 1446
    if (virDomainDestroyFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1447
    if (!virDomainObjIsActive(vm)) {
1448 1449
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
1450 1451 1452
        goto cleanup;
    }

1453
    priv = vm->privateData;
1454
    ret = virLXCProcessStop(driver, vm, VIR_DOMAIN_SHUTOFF_DESTROYED);
1455
    event = virDomainEventLifecycleNewFromObj(vm,
1456 1457
                                     VIR_DOMAIN_EVENT_STOPPED,
                                     VIR_DOMAIN_EVENT_STOPPED_DESTROYED);
1458
    priv->doneStopEvent = true;
1459
    virDomainAuditStop(vm, "destroyed");
1460
    if (!vm->persistent) {
1461
        virDomainObjListRemove(driver->domains, vm);
1462 1463
        vm = NULL;
    }
1464

1465
 cleanup:
1466
    if (vm)
1467
        virObjectUnlock(vm);
1468
    if (event)
1469
        virObjectEventStateQueue(driver->domainEventState, event);
1470
    return ret;
1471
}
1472

1473 1474 1475 1476 1477 1478 1479 1480 1481 1482 1483 1484 1485 1486
/**
 * lxcDomainDestroy:
 * @dom: pointer to domain to destroy
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
static int
lxcDomainDestroy(virDomainPtr dom)
{
    return lxcDomainDestroyFlags(dom, 0);
}

1487 1488 1489 1490 1491
static int lxcCheckNetNsSupport(void)
{
    const char *argv[] = {"ip", "link", "set", "lo", "netns", "-1", NULL};
    int ip_rc;

1492
    if (virRun(argv, &ip_rc) < 0 || ip_rc == 255)
1493
        return 0;
1494

1495 1496
    if (lxcContainerAvailable(LXC_CONTAINER_FEATURE_NET) < 0)
        return 0;
1497

1498
    return 1;
1499 1500
}

1501

1502 1503
static virSecurityManagerPtr
lxcSecurityInit(virLXCDriverConfigPtr cfg)
1504
{
1505 1506
    VIR_INFO("lxcSecurityInit %s", cfg->securityDriverName);
    virSecurityManagerPtr mgr = virSecurityManagerNew(cfg->securityDriverName,
1507
                                                      LXC_DRIVER_NAME,
1508
                                                      false,
1509 1510
                                                      cfg->securityDefaultConfined,
                                                      cfg->securityRequireConfined);
1511 1512 1513
    if (!mgr)
        goto error;

1514
    return mgr;
1515

1516
 error:
1517
    VIR_ERROR(_("Failed to initialize security drivers"));
1518
    virObjectUnref(mgr);
1519
    return NULL;
1520 1521 1522
}


1523 1524 1525
static int lxcStateInitialize(bool privileged,
                              virStateInhibitCallback callback ATTRIBUTE_UNUSED,
                              void *opaque ATTRIBUTE_UNUSED)
D
Daniel Veillard 已提交
1526
{
1527
    virCapsPtr caps = NULL;
1528
    const char *ld;
1529
    virLXCDriverConfigPtr cfg = NULL;
1530 1531 1532 1533 1534

    /* Valgrind gets very annoyed when we clone containers, so
     * disable LXC when under valgrind
     * XXX remove this when valgrind is fixed
     */
1535
    ld = virGetEnvBlockSUID("LD_PRELOAD");
1536
    if (ld && strstr(ld, "vgpreload")) {
1537
        VIR_INFO("Running under valgrind, disabling driver");
1538 1539
        return 0;
    }
1540

1541
    /* Check that the user is root, silently disable if not */
1542
    if (!privileged) {
1543
        VIR_INFO("Not running privileged, disabling driver");
1544 1545 1546 1547 1548
        return 0;
    }

    /* Check that this is a container enabled kernel */
    if (lxcContainerAvailable(0) < 0) {
1549
        VIR_INFO("LXC support not available in this kernel, disabling driver");
1550
        return 0;
1551 1552
    }

1553
    if (VIR_ALLOC(lxc_driver) < 0) {
1554 1555
        return -1;
    }
1556 1557 1558 1559
    if (virMutexInit(&lxc_driver->lock) < 0) {
        VIR_FREE(lxc_driver);
        return -1;
    }
D
Daniel Veillard 已提交
1560

1561
    if (!(lxc_driver->domains = virDomainObjListNew()))
1562 1563
        goto cleanup;

1564
    lxc_driver->domainEventState = virObjectEventStateNew();
1565
    if (!lxc_driver->domainEventState)
1566 1567
        goto cleanup;

1568 1569
    lxc_driver->hostsysinfo = virSysinfoRead();

1570 1571 1572 1573 1574
    if (!(lxc_driver->config = cfg = virLXCDriverConfigNew()))
        goto cleanup;

    cfg->log_libvirtd = 0; /* by default log to container logfile */
    cfg->have_netns = lxcCheckNetNsSupport();
D
Daniel Veillard 已提交
1575 1576

    /* Call function to load lxc driver configuration information */
1577
    if (virLXCLoadDriverConfig(cfg, SYSCONFDIR "/libvirt/lxc.conf") < 0)
1578
        goto cleanup;
D
Daniel Veillard 已提交
1579

1580
    if (!(lxc_driver->securityManager = lxcSecurityInit(cfg)))
1581 1582
        goto cleanup;

1583
    if (!(lxc_driver->hostdevMgr = virHostdevManagerGetDefault()))
G
Guido Günther 已提交
1584 1585
        goto cleanup;

1586
    if ((virLXCDriverGetCapabilities(lxc_driver, true)) == NULL)
1587
        goto cleanup;
D
Daniel Veillard 已提交
1588

1589
    if (!(lxc_driver->xmlopt = lxcDomainXMLConfInit()))
1590
        goto cleanup;
1591

1592
    if (!(lxc_driver->closeCallbacks = virCloseCallbacksNew()))
1593 1594
        goto cleanup;

1595 1596 1597
    if (!(caps = virLXCDriverGetCapabilities(lxc_driver, false)))
        goto cleanup;

O
Osier Yang 已提交
1598
    /* Get all the running persistent or transient configs first */
1599
    if (virDomainObjListLoadAllConfigs(lxc_driver->domains,
1600
                                       cfg->stateDir,
1601
                                       NULL, 1,
1602
                                       caps,
1603
                                       lxc_driver->xmlopt,
1604
                                       1 << VIR_DOMAIN_VIRT_LXC,
1605
                                       NULL, NULL) < 0)
O
Osier Yang 已提交
1606 1607
        goto cleanup;

1608
    virLXCProcessReconnectAll(lxc_driver, lxc_driver->domains);
O
Osier Yang 已提交
1609 1610

    /* Then inactive persistent configs */
1611
    if (virDomainObjListLoadAllConfigs(lxc_driver->domains,
1612 1613
                                       cfg->configDir,
                                       cfg->autostartDir, 0,
1614
                                       caps,
1615
                                       lxc_driver->xmlopt,
1616
                                       1 << VIR_DOMAIN_VIRT_LXC,
1617
                                       NULL, NULL) < 0)
1618
        goto cleanup;
1619

1620
    virNWFilterRegisterCallbackDriver(&lxcCallbackDriver);
D
Daniel Veillard 已提交
1621 1622
    return 0;

1623
 cleanup:
1624
    virObjectUnref(caps);
1625
    lxcStateCleanup();
1626
    return -1;
D
Daniel Veillard 已提交
1627 1628
}

1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 1639 1640 1641
/**
 * lxcStateAutoStart:
 *
 * Function to autostart the LXC daemons
 */
static void lxcStateAutoStart(void)
{
    if (!lxc_driver)
        return;

    virLXCProcessAutostartAll(lxc_driver);
}

1642 1643
static void lxcNotifyLoadDomain(virDomainObjPtr vm, int newVM, void *opaque)
{
1644
    virLXCDriverPtr driver = opaque;
1645 1646

    if (newVM) {
1647
        virObjectEventPtr event =
1648
            virDomainEventLifecycleNewFromObj(vm,
1649 1650 1651
                                     VIR_DOMAIN_EVENT_DEFINED,
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED);
        if (event)
1652
            virObjectEventStateQueue(driver->domainEventState, event);
1653 1654 1655 1656
    }
}

/**
1657
 * lxcStateReload:
1658 1659 1660 1661 1662
 *
 * Function to restart the LXC driver, it will recheck the configuration
 * files and perform autostart
 */
static int
1663 1664
lxcStateReload(void)
{
1665
    virLXCDriverConfigPtr cfg = NULL;
1666
    virCapsPtr caps = NULL;
1667

1668 1669 1670
    if (!lxc_driver)
        return 0;

1671
    if (!(caps = virLXCDriverGetCapabilities(lxc_driver, false)))
1672 1673
        return -1;

1674 1675
    cfg = virLXCDriverGetConfig(lxc_driver);

1676
    virDomainObjListLoadAllConfigs(lxc_driver->domains,
1677 1678
                                   cfg->configDir,
                                   cfg->autostartDir, 0,
1679
                                   caps,
1680
                                   lxc_driver->xmlopt,
1681
                                   1 << VIR_DOMAIN_VIRT_LXC,
1682
                                   lxcNotifyLoadDomain, lxc_driver);
1683
    virObjectUnref(caps);
1684
    virObjectUnref(cfg);
1685 1686 1687
    return 0;
}

1688
static int lxcStateCleanup(void)
D
Daniel Veillard 已提交
1689
{
1690
    if (lxc_driver == NULL)
1691
        return -1;
1692

1693
    virNWFilterUnRegisterCallbackDriver(&lxcCallbackDriver);
1694
    virObjectUnref(lxc_driver->domains);
1695
    virObjectEventStateFree(lxc_driver->domainEventState);
1696

1697
    virObjectUnref(lxc_driver->closeCallbacks);
1698

1699 1700
    virSysinfoDefFree(lxc_driver->hostsysinfo);

1701
    virObjectUnref(lxc_driver->hostdevMgr);
1702
    virObjectUnref(lxc_driver->caps);
1703
    virObjectUnref(lxc_driver->securityManager);
1704
    virObjectUnref(lxc_driver->xmlopt);
1705
    virObjectUnref(lxc_driver->config);
1706
    virMutexDestroy(&lxc_driver->lock);
1707
    VIR_FREE(lxc_driver);
1708 1709 1710

    return 0;
}
D
Daniel Veillard 已提交
1711

1712 1713 1714 1715 1716 1717 1718 1719 1720 1721 1722 1723 1724 1725
static int
lxcConnectSupportsFeature(virConnectPtr conn, int feature)
{
    if (virConnectSupportsFeatureEnsureACL(conn) < 0)
        return -1;

    switch (feature) {
        case VIR_DRV_FEATURE_TYPED_PARAM_STRING:
            return 1;
        default:
            return 0;
    }
}

D
Daniel Veillard 已提交
1726

1727
static int lxcConnectGetVersion(virConnectPtr conn, unsigned long *version)
D
Dan Smith 已提交
1728 1729 1730
{
    struct utsname ver;

1731
    uname(&ver);
D
Dan Smith 已提交
1732

1733 1734 1735
    if (virConnectGetVersionEnsureACL(conn) < 0)
        return -1;

1736
    if (virParseVersionString(ver.release, version, true) < 0) {
1737
        virReportError(VIR_ERR_INTERNAL_ERROR, _("Unknown release: %s"), ver.release);
D
Dan Smith 已提交
1738 1739 1740 1741 1742
        return -1;
    }

    return 0;
}
1743

1744

1745
static char *lxcConnectGetHostname(virConnectPtr conn)
1746
{
1747 1748 1749
    if (virConnectGetHostnameEnsureACL(conn) < 0)
        return NULL;

1750 1751 1752 1753
    return virGetHostname();
}


1754 1755
static char *lxcDomainGetSchedulerType(virDomainPtr dom,
                                       int *nparams)
1756
{
1757
    char *ret = NULL;
1758 1759
    virDomainObjPtr vm;
    virLXCDomainObjPrivatePtr priv;
1760

M
Michal Privoznik 已提交
1761
    if (!(vm = lxcDomObjFromDomain(dom)))
1762
        goto cleanup;
M
Michal Privoznik 已提交
1763

1764 1765
    priv = vm->privateData;

1766 1767 1768
    if (virDomainGetSchedulerTypeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1769 1770 1771 1772 1773 1774 1775 1776
    /* Domain not running, thus no cgroups - return defaults */
    if (!virDomainObjIsActive(vm)) {
        if (nparams)
            *nparams = 3;
        ignore_value(VIR_STRDUP(ret, "posix"));
        goto cleanup;
    }

1777
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
1778 1779
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
1780 1781
        goto cleanup;
    }
1782

1783
    if (nparams) {
1784
        if (virCgroupSupportsCpuBW(priv->cgroup))
1785
            *nparams = 3;
1786 1787
        else
            *nparams = 1;
1788
    }
1789

1790
    ignore_value(VIR_STRDUP(ret, "posix"));
1791

1792
 cleanup:
1793 1794
    if (vm)
        virObjectUnlock(vm);
1795 1796 1797 1798 1799 1800 1801 1802
    return ret;
}


static int
lxcGetVcpuBWLive(virCgroupPtr cgroup, unsigned long long *period,
                 long long *quota)
{
1803
    if (virCgroupGetCpuCfsPeriod(cgroup, period) < 0)
1804 1805
        return -1;

1806
    if (virCgroupGetCpuCfsQuota(cgroup, quota) < 0)
1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821 1822
        return -1;

    return 0;
}


static int lxcSetVcpuBWLive(virCgroupPtr cgroup, unsigned long long period,
                            long long quota)
{
    unsigned long long old_period;

    if (period == 0 && quota == 0)
        return 0;

    if (period) {
        /* get old period, and we can rollback if set quota failed */
1823
        if (virCgroupGetCpuCfsPeriod(cgroup, &old_period) < 0)
1824 1825
            return -1;

1826
        if (virCgroupSetCpuCfsPeriod(cgroup, period) < 0)
1827 1828 1829 1830
            return -1;
    }

    if (quota) {
1831 1832
        if (virCgroupSetCpuCfsQuota(cgroup, quota) < 0)
            goto error;
1833 1834 1835 1836
    }

    return 0;

1837
 error:
1838
    if (period) {
1839 1840 1841 1842 1843 1844
        virErrorPtr saved = virSaveLastError();
        virCgroupSetCpuCfsPeriod(cgroup, old_period);
        if (saved) {
            virSetError(saved);
            virFreeError(saved);
        }
1845 1846 1847
    }

    return -1;
1848 1849
}

1850

1851
static int
1852 1853 1854 1855
lxcDomainSetSchedulerParametersFlags(virDomainPtr dom,
                                     virTypedParameterPtr params,
                                     int nparams,
                                     unsigned int flags)
1856
{
1857
    virLXCDriverPtr driver = dom->conn->privateData;
1858
    virCapsPtr caps = NULL;
1859
    size_t i;
1860
    virDomainObjPtr vm = NULL;
1861
    virDomainDefPtr vmdef = NULL;
1862
    int ret = -1;
1863
    int rc;
1864
    virLXCDomainObjPrivatePtr priv;
1865
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1866

1867 1868
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
1869 1870 1871 1872 1873 1874 1875 1876
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                               VIR_TYPED_PARAM_LLONG,
                               NULL) < 0)
1877
        return -1;
1878

M
Michal Privoznik 已提交
1879
    if (!(vm = lxcDomObjFromDomain(dom)))
1880
        goto cleanup;
M
Michal Privoznik 已提交
1881

1882
    priv = vm->privateData;
1883

1884 1885 1886
    if (virDomainSetSchedulerParametersFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

1887 1888 1889 1890
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
1891
                                        vm, &flags, &vmdef) < 0)
E
Eric Blake 已提交
1892
        goto cleanup;
1893 1894 1895

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
1896
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
1897 1898 1899 1900 1901
        if (!vmdef)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1902
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
1903 1904
            virReportError(VIR_ERR_OPERATION_INVALID,
                           "%s", _("cgroup CPU controller is not mounted"));
1905 1906 1907
            goto cleanup;
        }
    }
1908 1909

    for (i = 0; i < nparams; i++) {
1910
        virTypedParameterPtr param = &params[i];
1911

1912 1913
        if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_CPU_SHARES)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1914
                unsigned long long val;
1915
                if (virCgroupSetCpuShares(priv->cgroup, params[i].value.ul) < 0)
1916 1917
                    goto cleanup;

1918 1919 1920 1921
                if (virCgroupGetCpuShares(priv->cgroup, &val) < 0)
                    goto cleanup;

                vm->def->cputune.shares = val;
1922
                vm->def->cputune.sharesSpecified = true;
1923 1924 1925 1926
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.shares = params[i].value.ul;
1927
                vmdef->cputune.sharesSpecified = true;
1928 1929 1930
            }
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_PERIOD)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1931
                rc = lxcSetVcpuBWLive(priv->cgroup, params[i].value.ul, 0);
1932 1933 1934 1935 1936 1937 1938 1939 1940 1941 1942 1943
                if (rc != 0)
                    goto cleanup;

                if (params[i].value.ul)
                    vm->def->cputune.period = params[i].value.ul;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.period = params[i].value.ul;
            }
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_QUOTA)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1944
                rc = lxcSetVcpuBWLive(priv->cgroup, 0, params[i].value.l);
1945 1946 1947 1948 1949 1950 1951 1952 1953 1954
                if (rc != 0)
                    goto cleanup;

                if (params[i].value.l)
                    vm->def->cputune.quota = params[i].value.l;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.quota = params[i].value.l;
            }
1955
        }
1956
    }
1957

1958
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0)
1959
        goto cleanup;
1960

1961 1962

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
1963
        rc = virDomainSaveConfig(cfg->configDir, vmdef);
1964
        if (rc < 0)
1965
            goto cleanup;
1966

1967
        virDomainObjAssignDef(vm, vmdef, false, NULL);
1968
        vmdef = NULL;
1969
    }
1970

1971
    ret = 0;
1972

1973
 cleanup:
1974
    virDomainDefFree(vmdef);
1975
    if (vm)
1976
        virObjectUnlock(vm);
1977
    virObjectUnref(caps);
1978
    virObjectUnref(cfg);
1979
    return ret;
1980 1981
}

1982
static int
1983 1984 1985
lxcDomainSetSchedulerParameters(virDomainPtr domain,
                                virTypedParameterPtr params,
                                int nparams)
1986
{
1987
    return lxcDomainSetSchedulerParametersFlags(domain, params, nparams, 0);
1988 1989 1990
}

static int
1991 1992 1993 1994
lxcDomainGetSchedulerParametersFlags(virDomainPtr dom,
                                     virTypedParameterPtr params,
                                     int *nparams,
                                     unsigned int flags)
1995
{
1996
    virLXCDriverPtr driver = dom->conn->privateData;
1997
    virCapsPtr caps = NULL;
1998
    virDomainObjPtr vm = NULL;
E
Eric Blake 已提交
1999
    virDomainDefPtr persistentDef;
2000 2001 2002
    unsigned long long shares = 0;
    unsigned long long period = 0;
    long long quota = 0;
2003
    int ret = -1;
2004 2005 2006
    int rc;
    bool cpu_bw_status = false;
    int saved_nparams = 0;
2007
    virLXCDomainObjPrivatePtr priv;
2008

2009
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
2010 2011 2012 2013 2014
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We don't return strings, and thus trivially support this flag.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;
2015

M
Michal Privoznik 已提交
2016
    if (!(vm = lxcDomObjFromDomain(dom)))
2017
        goto cleanup;
M
Michal Privoznik 已提交
2018

2019 2020
    priv = vm->privateData;

2021 2022 2023
    if (virDomainGetSchedulerParametersFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2024 2025
    if (*nparams > 1)
        cpu_bw_status = virCgroupSupportsCpuBW(priv->cgroup);
2026

2027 2028 2029 2030
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
2031
                                        vm, &flags, &persistentDef) < 0)
E
Eric Blake 已提交
2032
        goto cleanup;
2033 2034

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
E
Eric Blake 已提交
2035
        shares = persistentDef->cputune.shares;
2036
        if (*nparams > 1) {
E
Eric Blake 已提交
2037 2038
            period = persistentDef->cputune.period;
            quota = persistentDef->cputune.quota;
2039
            cpu_bw_status = true; /* Allow copy of data to params[] */
2040 2041 2042 2043
        }
        goto out;
    }

2044
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
2045 2046
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
2047
        goto cleanup;
2048 2049
    }

2050
    if (virCgroupGetCpuShares(priv->cgroup, &shares) < 0)
2051
        goto cleanup;
2052 2053

    if (*nparams > 1 && cpu_bw_status) {
2054
        rc = lxcGetVcpuBWLive(priv->cgroup, &period, &quota);
2055 2056 2057
        if (rc != 0)
            goto cleanup;
    }
2058
 out:
2059 2060
    if (virTypedParameterAssign(&params[0], VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                                VIR_TYPED_PARAM_ULLONG, shares) < 0)
C
Chris Lalancette 已提交
2061
        goto cleanup;
2062 2063 2064 2065
    saved_nparams++;

    if (cpu_bw_status) {
        if (*nparams > saved_nparams) {
2066 2067 2068
            if (virTypedParameterAssign(&params[1],
                                        VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                                        VIR_TYPED_PARAM_ULLONG, period) < 0)
2069 2070 2071 2072 2073
                goto cleanup;
            saved_nparams++;
        }

        if (*nparams > saved_nparams) {
2074 2075 2076
            if (virTypedParameterAssign(&params[2],
                                        VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                                        VIR_TYPED_PARAM_LLONG, quota) < 0)
2077 2078 2079 2080 2081 2082 2083
                goto cleanup;
            saved_nparams++;
        }
    }

    *nparams = saved_nparams;

2084
    ret = 0;
2085

2086
 cleanup:
2087
    if (vm)
2088
        virObjectUnlock(vm);
2089
    virObjectUnref(caps);
2090
    return ret;
2091 2092
}

2093
static int
2094 2095 2096
lxcDomainGetSchedulerParameters(virDomainPtr domain,
                                virTypedParameterPtr params,
                                int *nparams)
2097
{
2098
    return lxcDomainGetSchedulerParametersFlags(domain, params, nparams, 0);
2099 2100
}

2101 2102 2103 2104 2105 2106 2107 2108 2109 2110 2111 2112 2113 2114 2115 2116 2117 2118 2119 2120 2121 2122 2123 2124 2125 2126 2127 2128 2129 2130 2131 2132 2133 2134 2135 2136 2137 2138 2139 2140 2141 2142 2143 2144 2145 2146 2147 2148 2149 2150 2151 2152 2153 2154 2155 2156 2157 2158 2159 2160 2161 2162 2163 2164 2165 2166 2167 2168 2169 2170 2171 2172 2173 2174 2175 2176 2177 2178 2179 2180 2181 2182 2183 2184 2185 2186 2187
static int
lxcDomainParseBlkioDeviceStr(char *blkioDeviceStr, const char *type,
                             virBlkioDevicePtr *dev, size_t *size)
{
    char *temp;
    int ndevices = 0;
    int nsep = 0;
    size_t i;
    virBlkioDevicePtr result = NULL;

    *dev = NULL;
    *size = 0;

    if (STREQ(blkioDeviceStr, ""))
        return 0;

    temp = blkioDeviceStr;
    while (temp) {
        temp = strchr(temp, ',');
        if (temp) {
            temp++;
            nsep++;
        }
    }

    /* A valid string must have even number of fields, hence an odd
     * number of commas.  */
    if (!(nsep & 1))
        goto error;

    ndevices = (nsep + 1) / 2;

    if (VIR_ALLOC_N(result, ndevices) < 0)
        return -1;

    i = 0;
    temp = blkioDeviceStr;
    while (temp) {
        char *p = temp;

        /* device path */
        p = strchr(p, ',');
        if (!p)
            goto error;

        if (VIR_STRNDUP(result[i].path, temp, p - temp) < 0)
            goto cleanup;

        /* value */
        temp = p + 1;

        if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT)) {
            if (virStrToLong_ui(temp, &p, 10, &result[i].weight) < 0)
                goto error;
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS)) {
            if (virStrToLong_ui(temp, &p, 10, &result[i].riops) < 0)
                goto error;
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS)) {
            if (virStrToLong_ui(temp, &p, 10, &result[i].wiops) < 0)
                goto error;
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS)) {
            if (virStrToLong_ull(temp, &p, 10, &result[i].rbps) < 0)
                goto error;
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)){
            if (virStrToLong_ull(temp, &p, 10, &result[i].wbps) < 0)
                goto error;
        } else {
            goto error;
        }

        i++;

        if (*p == '\0')
            break;
        else if (*p != ',')
            goto error;
        temp = p + 1;
    }

    if (!i)
        VIR_FREE(result);

    *dev = result;
    *size = i;

    return 0;

2188
 error:
2189 2190 2191
    virReportError(VIR_ERR_INVALID_ARG,
                   _("unable to parse blkio device '%s' '%s'"),
                   type, blkioDeviceStr);
2192
 cleanup:
2193 2194 2195 2196 2197 2198 2199 2200 2201 2202 2203 2204 2205 2206 2207 2208 2209 2210 2211 2212 2213 2214 2215 2216 2217 2218 2219 2220 2221 2222 2223 2224 2225 2226 2227 2228 2229 2230 2231 2232 2233 2234 2235 2236 2237 2238 2239 2240 2241 2242 2243 2244 2245 2246 2247 2248 2249 2250 2251 2252 2253 2254 2255 2256 2257 2258 2259 2260 2261 2262 2263 2264 2265
    virBlkioDeviceArrayClear(result, ndevices);
    VIR_FREE(result);
    return -1;
}

static int
lxcDomainMergeBlkioDevice(virBlkioDevicePtr *dest_array,
                          size_t *dest_size,
                          virBlkioDevicePtr src_array,
                          size_t src_size,
                          const char *type)
{
    size_t i, j;
    virBlkioDevicePtr dest, src;

    for (i = 0; i < src_size; i++) {
        bool found = false;

        src = &src_array[i];
        for (j = 0; j < *dest_size; j++) {
            dest = &(*dest_array)[j];
            if (STREQ(src->path, dest->path)) {
                found = true;

                if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT))
                    dest->weight = src->weight;
                else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS))
                    dest->riops = src->riops;
                else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS))
                    dest->wiops = src->wiops;
                else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS))
                    dest->rbps = src->rbps;
                else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS))
                    dest->wbps = src->wbps;
                else {
                    virReportError(VIR_ERR_INVALID_ARG, _("Unknown parameter %s"),
                                   type);
                    return -1;
                }

                break;
            }
        }
        if (!found) {
            if (!src->weight && !src->riops && !src->wiops && !src->rbps && !src->wbps)
                continue;
            if (VIR_EXPAND_N(*dest_array, *dest_size, 1) < 0)
                return -1;
            dest = &(*dest_array)[*dest_size - 1];

            if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT))
                dest->weight = src->weight;
            else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS))
                dest->riops = src->riops;
            else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS))
                dest->wiops = src->wiops;
            else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS))
                dest->rbps = src->rbps;
            else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS))
                dest->wbps = src->wbps;
            else {
                *dest_size = *dest_size - 1;
                return -1;
            }

            dest->path = src->path;
            src->path = NULL;
        }
    }

    return 0;
}

2266

2267 2268 2269 2270 2271 2272 2273 2274 2275 2276 2277 2278 2279 2280 2281 2282 2283 2284 2285 2286 2287 2288 2289 2290 2291 2292 2293 2294 2295 2296 2297 2298 2299 2300 2301 2302 2303 2304 2305 2306 2307 2308 2309 2310 2311 2312 2313 2314 2315 2316 2317 2318 2319 2320 2321 2322 2323 2324 2325
static int
lxcDomainBlockStats(virDomainPtr dom,
                    const char *path,
                    struct _virDomainBlockStats *stats)
{
    int ret = -1, idx;
    virDomainObjPtr vm;
    virDomainDiskDefPtr disk = NULL;
    virLXCDomainObjPrivatePtr priv;

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    priv = vm->privateData;

    if (virDomainBlockStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
        goto cleanup;
    }

    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("blkio cgroup isn't mounted"));
        goto cleanup;
    }

    if (!*path) {
        /* empty path - return entire domain blkstats instead */
        ret = virCgroupGetBlkioIoServiced(priv->cgroup,
                                          &stats->rd_bytes,
                                          &stats->wr_bytes,
                                          &stats->rd_req,
                                          &stats->wr_req);
        goto cleanup;
    }

    if ((idx = virDomainDiskIndexByName(vm->def, path, false)) < 0) {
        virReportError(VIR_ERR_INVALID_ARG,
                       _("invalid path: %s"), path);
        goto cleanup;
    }
    disk = vm->def->disks[idx];

    if (!disk->info.alias) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("missing disk device alias name for %s"), disk->dst);
        goto cleanup;
    }

    ret = virCgroupGetBlkioIoDeviceServiced(priv->cgroup,
                                            disk->info.alias,
                                            &stats->rd_bytes,
                                            &stats->wr_bytes,
                                            &stats->rd_req,
                                            &stats->wr_req);
2326
 cleanup:
2327 2328 2329 2330 2331 2332 2333 2334 2335 2336 2337 2338 2339 2340 2341 2342 2343 2344 2345 2346 2347 2348 2349 2350 2351 2352 2353 2354 2355 2356 2357 2358 2359 2360 2361 2362 2363 2364 2365 2366 2367 2368 2369 2370 2371 2372 2373 2374 2375 2376 2377 2378 2379 2380 2381 2382 2383 2384 2385 2386 2387 2388 2389 2390 2391 2392 2393 2394 2395 2396 2397 2398 2399 2400 2401 2402 2403 2404 2405 2406 2407 2408 2409 2410 2411 2412 2413 2414 2415 2416 2417 2418 2419 2420 2421 2422 2423 2424 2425 2426 2427 2428 2429 2430 2431 2432 2433 2434 2435 2436 2437 2438 2439 2440 2441 2442 2443 2444 2445 2446 2447 2448 2449 2450 2451
    if (vm)
        virObjectUnlock(vm);
    return ret;
}


static int
lxcDomainBlockStatsFlags(virDomainPtr dom,
                         const char * path,
                         virTypedParameterPtr params,
                         int * nparams,
                         unsigned int flags)
{
    int tmp, ret = -1, idx;
    virDomainObjPtr vm;
    virDomainDiskDefPtr disk = NULL;
    virLXCDomainObjPrivatePtr priv;
    long long rd_req, rd_bytes, wr_req, wr_bytes;
    virTypedParameterPtr param;

    virCheckFlags(VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We don't return strings, and thus trivially support this flag.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;

    if (!params && !*nparams) {
        *nparams = LXC_NB_DOMAIN_BLOCK_STAT_PARAM;
        return 0;
    }

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    priv = vm->privateData;

    if (virDomainBlockStatsFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
        goto cleanup;
    }

    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("blkio cgroup isn't mounted"));
        goto cleanup;
    }

    if (!*path) {
        /* empty path - return entire domain blkstats instead */
        if (virCgroupGetBlkioIoServiced(priv->cgroup,
                                        &rd_bytes,
                                        &wr_bytes,
                                        &rd_req,
                                        &wr_req) < 0) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("domain stats query failed"));
            goto cleanup;
        }
    } else {
        if ((idx = virDomainDiskIndexByName(vm->def, path, false)) < 0) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("invalid path: %s"), path);
            goto cleanup;
        }
        disk = vm->def->disks[idx];

        if (!disk->info.alias) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("missing disk device alias name for %s"), disk->dst);
            goto cleanup;
        }

        if (virCgroupGetBlkioIoDeviceServiced(priv->cgroup,
                                              disk->info.alias,
                                              &rd_bytes,
                                              &wr_bytes,
                                              &rd_req,
                                              &wr_req) < 0) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("domain stats query failed"));
            goto cleanup;
        }
    }

    tmp = 0;
    ret = -1;

    if (tmp < *nparams && wr_bytes != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_WRITE_BYTES,
                                    VIR_TYPED_PARAM_LLONG, wr_bytes) < 0)
            goto cleanup;
        tmp++;
    }

    if (tmp < *nparams && wr_req != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_WRITE_REQ,
                                    VIR_TYPED_PARAM_LLONG, wr_req) < 0)
            goto cleanup;
        tmp++;
    }

    if (tmp < *nparams && rd_bytes != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_READ_BYTES,
                                    VIR_TYPED_PARAM_LLONG, rd_bytes) < 0)
            goto cleanup;
        tmp++;
    }

    if (tmp < *nparams && rd_req != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_READ_REQ,
                                    VIR_TYPED_PARAM_LLONG, rd_req) < 0)
            goto cleanup;
        tmp++;
    }

    ret = 0;
    *nparams = tmp;

2452
 cleanup:
2453 2454 2455 2456 2457 2458
    if (vm)
        virObjectUnlock(vm);
    return ret;
}


2459 2460 2461 2462 2463
static int
lxcDomainSetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int nparams,
                            unsigned int flags)
2464
{
2465
    virLXCDriverPtr driver = dom->conn->privateData;
2466
    size_t i;
2467 2468 2469
    virDomainObjPtr vm = NULL;
    virDomainDefPtr persistentDef = NULL;
    int ret = -1;
2470 2471
    virLXCDriverConfigPtr cfg = NULL;
    virCapsPtr caps = NULL;
2472
    virLXCDomainObjPrivatePtr priv;
2473 2474 2475

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
2476 2477 2478
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_BLKIO_WEIGHT,
                               VIR_TYPED_PARAM_UINT,
2479 2480 2481 2482 2483 2484 2485 2486 2487 2488
                               VIR_DOMAIN_BLKIO_DEVICE_WEIGHT,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_READ_BPS,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS,
                               VIR_TYPED_PARAM_STRING,
2489
                               NULL) < 0)
2490 2491
        return -1;

M
Michal Privoznik 已提交
2492
    if (!(vm = lxcDomObjFromDomain(dom)))
2493
        return -1;
M
Michal Privoznik 已提交
2494

2495
    priv = vm->privateData;
2496
    cfg = virLXCDriverGetConfig(driver);
2497

2498 2499 2500
    if (virDomainSetBlkioParametersEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

2501 2502 2503
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

2504 2505
    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt, vm, &flags,
                                        &persistentDef) < 0)
E
Eric Blake 已提交
2506
        goto cleanup;
2507 2508

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
2509
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
2510 2511
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2512 2513
            goto cleanup;
        }
2514
    }
2515

2516 2517
    ret = 0;
    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
2518 2519 2520 2521 2522
        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
                if (params[i].value.ui > 1000 || params[i].value.ui < 100) {
2523 2524
                    virReportError(VIR_ERR_INVALID_ARG, "%s",
                                   _("out of blkio weight range."));
2525 2526
                    ret = -1;
                    continue;
2527 2528
                }

2529
                if (virCgroupSetBlkioWeight(priv->cgroup, params[i].value.ui) < 0)
2530 2531 2532 2533 2534 2535 2536 2537 2538 2539 2540 2541 2542 2543 2544 2545 2546 2547 2548 2549 2550 2551 2552 2553 2554 2555 2556 2557 2558 2559 2560 2561 2562 2563 2564 2565 2566 2567 2568 2569 2570 2571 2572 2573 2574 2575 2576 2577 2578 2579 2580 2581 2582 2583 2584 2585 2586 2587 2588 2589 2590 2591 2592 2593 2594 2595 2596 2597 2598 2599 2600 2601 2602 2603 2604 2605 2606 2607 2608 2609
                    ret = -1;
            } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
                size_t ndevices;
                virBlkioDevicePtr devices = NULL;
                size_t j;

                if (lxcDomainParseBlkioDeviceStr(params[i].value.s,
                                                 param->field,
                                                 &devices,
                                                 &ndevices) < 0) {
                    ret = -1;
                    continue;
                }

                if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceWeight(priv->cgroup,
                                                          devices[j].path,
                                                          devices[j].weight) < 0) {
                            ret = -1;
                            break;
                        }
                    }
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceReadIops(priv->cgroup,
                                                            devices[j].path,
                                                            devices[j].riops) < 0) {
                            ret = -1;
                            break;
                        }
                    }
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceWriteIops(priv->cgroup,
                                                             devices[j].path,
                                                             devices[j].wiops) < 0) {
                            ret = -1;
                            break;
                        }
                    }
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceReadBps(priv->cgroup,
                                                           devices[j].path,
                                                           devices[j].rbps) < 0) {
                            ret = -1;
                            break;
                        }
                    }
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)){
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceWriteBps(priv->cgroup,
                                                            devices[j].path,
                                                            devices[j].wbps) < 0) {
                            ret = -1;
                            break;
                        }
                    }
                } else {
                    virReportError(VIR_ERR_INVALID_ARG, _("Unknown blkio parameter %s"),
                                   param->field);
                    ret = -1;
                    virBlkioDeviceArrayClear(devices, ndevices);
                    VIR_FREE(devices);

                    continue;
                }

                if (j != ndevices ||
                    lxcDomainMergeBlkioDevice(&vm->def->blkio.devices,
                                              &vm->def->blkio.ndevices,
                                              devices, ndevices, param->field) < 0)
                    ret = -1;
                virBlkioDeviceArrayClear(devices, ndevices);
                VIR_FREE(devices);
2610 2611
            }
        }
E
Eric Blake 已提交
2612
    }
2613 2614
    if (ret < 0)
        goto cleanup;
E
Eric Blake 已提交
2615
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
2616 2617 2618 2619 2620 2621 2622 2623
        /* Clang can't see that if we get here, persistentDef was set.  */
        sa_assert(persistentDef);

        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
                if (params[i].value.ui > 1000 || params[i].value.ui < 100) {
2624 2625
                    virReportError(VIR_ERR_INVALID_ARG, "%s",
                                   _("out of blkio weight range."));
2626 2627
                    ret = -1;
                    continue;
2628 2629 2630
                }

                persistentDef->blkio.weight = params[i].value.ui;
2631 2632 2633 2634 2635 2636 2637 2638 2639 2640 2641 2642 2643 2644 2645 2646 2647 2648 2649 2650 2651
            } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
                virBlkioDevicePtr devices = NULL;
                size_t ndevices;

                if (lxcDomainParseBlkioDeviceStr(params[i].value.s,
                                                 param->field,
                                                 &devices,
                                                 &ndevices) < 0) {
                    ret = -1;
                    continue;
                }
                if (lxcDomainMergeBlkioDevice(&persistentDef->blkio.devices,
                                              &persistentDef->blkio.ndevices,
                                              devices, ndevices, param->field) < 0)
                    ret = -1;
                virBlkioDeviceArrayClear(devices, ndevices);
                VIR_FREE(devices);
2652 2653 2654
            }
        }

2655
        if (virDomainSaveConfig(cfg->configDir, persistentDef) < 0)
2656
            ret = -1;
2657 2658
    }

2659
 cleanup:
2660
    if (vm)
2661
        virObjectUnlock(vm);
2662
    virObjectUnref(caps);
2663
    virObjectUnref(cfg);
2664 2665 2666 2667
    return ret;
}


2668 2669
#define LXC_NB_BLKIO_PARAM  6

2670 2671 2672 2673 2674
static int
lxcDomainGetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int *nparams,
                            unsigned int flags)
2675
{
2676
    virLXCDriverPtr driver = dom->conn->privateData;
2677
    size_t i, j;
2678 2679 2680 2681
    virDomainObjPtr vm = NULL;
    virDomainDefPtr persistentDef = NULL;
    unsigned int val;
    int ret = -1;
2682
    virCapsPtr caps = NULL;
2683
    virLXCDomainObjPrivatePtr priv;
2684 2685

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
2686 2687 2688 2689 2690 2691 2692
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We blindly return a string, and let libvirt.c and
     * remote_driver.c do the filtering on behalf of older clients
     * that can't parse it.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;
2693

M
Michal Privoznik 已提交
2694
    if (!(vm = lxcDomObjFromDomain(dom)))
2695
        return -1;
M
Michal Privoznik 已提交
2696

2697
    priv = vm->privateData;
2698

2699 2700 2701
    if (virDomainGetBlkioParametersEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2702 2703 2704
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

2705 2706 2707 2708 2709 2710 2711
    if ((*nparams) == 0) {
        /* Current number of blkio parameters supported by cgroups */
        *nparams = LXC_NB_BLKIO_PARAM;
        ret = 0;
        goto cleanup;
    }

2712 2713
    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt, vm, &flags,
                                        &persistentDef) < 0)
E
Eric Blake 已提交
2714
        goto cleanup;
2715 2716

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
2717
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
2718 2719
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2720 2721 2722 2723 2724 2725 2726 2727 2728
            goto cleanup;
        }

        for (i = 0; i < *nparams && i < LXC_NB_BLKIO_PARAM; i++) {
            virTypedParameterPtr param = &params[i];
            val = 0;

            switch (i) {
            case 0: /* fill blkio weight here */
2729
                if (virCgroupGetBlkioWeight(priv->cgroup, &val) < 0)
2730
                    goto cleanup;
2731 2732
                if (virTypedParameterAssign(param, VIR_DOMAIN_BLKIO_WEIGHT,
                                            VIR_TYPED_PARAM_UINT, val) < 0)
2733 2734 2735
                    goto cleanup;
                break;

2736 2737 2738 2739 2740 2741 2742 2743 2744 2745 2746 2747 2748 2749 2750 2751
            case 1: /* blkiotune.device_weight */
                if (vm->def->blkio.ndevices > 0) {
                    virBuffer buf = VIR_BUFFER_INITIALIZER;
                    bool comma = false;

                    for (j = 0; j < vm->def->blkio.ndevices; j++) {
                        if (!vm->def->blkio.devices[j].weight)
                            continue;
                        if (comma)
                            virBufferAddChar(&buf, ',');
                        else
                            comma = true;
                        virBufferAsprintf(&buf, "%s,%u",
                                          vm->def->blkio.devices[j].path,
                                          vm->def->blkio.devices[j].weight);
                    }
2752
                    if (virBufferCheckError(&buf) < 0)
2753 2754 2755 2756 2757 2758 2759 2760 2761 2762 2763 2764 2765 2766 2767 2768 2769 2770 2771 2772 2773 2774 2775 2776 2777 2778
                        goto cleanup;
                    param->value.s = virBufferContentAndReset(&buf);
                }
                if (virTypedParameterAssign(param,
                                            VIR_DOMAIN_BLKIO_DEVICE_WEIGHT,
                                            VIR_TYPED_PARAM_STRING,
                                            param->value.s) < 0)
                    goto cleanup;
                break;

            case 2: /* blkiotune.device_read_iops */
                if (vm->def->blkio.ndevices > 0) {
                    virBuffer buf = VIR_BUFFER_INITIALIZER;
                    bool comma = false;

                    for (j = 0; j < vm->def->blkio.ndevices; j++) {
                        if (!vm->def->blkio.devices[j].riops)
                            continue;
                        if (comma)
                            virBufferAddChar(&buf, ',');
                        else
                            comma = true;
                        virBufferAsprintf(&buf, "%s,%u",
                                          vm->def->blkio.devices[j].path,
                                          vm->def->blkio.devices[j].riops);
                    }
2779
                    if (virBufferCheckError(&buf) < 0)
2780 2781 2782 2783 2784 2785 2786 2787 2788 2789 2790 2791 2792 2793 2794 2795 2796 2797 2798 2799 2800 2801 2802 2803 2804 2805
                        goto cleanup;
                    param->value.s = virBufferContentAndReset(&buf);
                }
                if (virTypedParameterAssign(param,
                                            VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS,
                                            VIR_TYPED_PARAM_STRING,
                                            param->value.s) < 0)
                    goto cleanup;
                break;

            case 3: /* blkiotune.device_write_iops */
                if (vm->def->blkio.ndevices > 0) {
                    virBuffer buf = VIR_BUFFER_INITIALIZER;
                    bool comma = false;

                    for (j = 0; j < vm->def->blkio.ndevices; j++) {
                        if (!vm->def->blkio.devices[j].wiops)
                            continue;
                        if (comma)
                            virBufferAddChar(&buf, ',');
                        else
                            comma = true;
                        virBufferAsprintf(&buf, "%s,%u",
                                          vm->def->blkio.devices[j].path,
                                          vm->def->blkio.devices[j].wiops);
                    }
2806
                    if (virBufferCheckError(&buf) < 0)
2807 2808 2809 2810 2811 2812 2813 2814 2815 2816 2817 2818 2819 2820 2821 2822 2823 2824 2825 2826 2827 2828 2829 2830 2831 2832
                        goto cleanup;
                    param->value.s = virBufferContentAndReset(&buf);
                }
                if (virTypedParameterAssign(param,
                                            VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS,
                                            VIR_TYPED_PARAM_STRING,
                                            param->value.s) < 0)
                    goto cleanup;
                break;

             case 4: /* blkiotune.device_read_bps */
                if (vm->def->blkio.ndevices > 0) {
                    virBuffer buf = VIR_BUFFER_INITIALIZER;
                    bool comma = false;

                    for (j = 0; j < vm->def->blkio.ndevices; j++) {
                        if (!vm->def->blkio.devices[j].rbps)
                            continue;
                        if (comma)
                            virBufferAddChar(&buf, ',');
                        else
                            comma = true;
                        virBufferAsprintf(&buf, "%s,%llu",
                                          vm->def->blkio.devices[j].path,
                                          vm->def->blkio.devices[j].rbps);
                    }
2833
                    if (virBufferCheckError(&buf) < 0)
2834 2835 2836 2837 2838 2839 2840 2841 2842 2843 2844 2845 2846 2847 2848 2849 2850 2851 2852 2853 2854 2855 2856 2857 2858 2859
                        goto cleanup;
                    param->value.s = virBufferContentAndReset(&buf);
                }
                if (virTypedParameterAssign(param,
                                            VIR_DOMAIN_BLKIO_DEVICE_READ_BPS,
                                            VIR_TYPED_PARAM_STRING,
                                            param->value.s) < 0)
                    goto cleanup;
                break;

             case 5: /* blkiotune.device_write_bps */
                if (vm->def->blkio.ndevices > 0) {
                    virBuffer buf = VIR_BUFFER_INITIALIZER;
                    bool comma = false;

                    for (j = 0; j < vm->def->blkio.ndevices; j++) {
                        if (!vm->def->blkio.devices[j].wbps)
                            continue;
                        if (comma)
                            virBufferAddChar(&buf, ',');
                        else
                            comma = true;
                        virBufferAsprintf(&buf, "%s,%llu",
                                          vm->def->blkio.devices[j].path,
                                          vm->def->blkio.devices[j].wbps);
                    }
2860
                    if (virBufferCheckError(&buf) < 0)
2861 2862 2863 2864 2865 2866 2867 2868 2869
                        goto cleanup;
                    param->value.s = virBufferContentAndReset(&buf);
                }
                if (virTypedParameterAssign(param,
                                            VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS,
                                            VIR_TYPED_PARAM_STRING,
                                            param->value.s) < 0)
                    goto cleanup;
                break;
2870 2871 2872 2873 2874
            }
        }
    } else if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        for (i = 0; i < *nparams && i < LXC_NB_BLKIO_PARAM; i++) {
            virTypedParameterPtr param = &params[i];
2875 2876 2877
            val = 0;
            param->value.ui = 0;
            param->type = VIR_TYPED_PARAM_UINT;
2878 2879 2880

            switch (i) {
            case 0: /* fill blkio weight here */
2881 2882 2883 2884 2885 2886 2887 2888 2889 2890 2891 2892 2893 2894 2895 2896 2897 2898 2899 2900 2901 2902 2903 2904 2905
                if (virStrcpyStatic(param->field, VIR_DOMAIN_BLKIO_WEIGHT) == NULL) {
                    virReportError(VIR_ERR_INTERNAL_ERROR,
                                   _("Field name '%s' too long"),
                                   VIR_DOMAIN_BLKIO_WEIGHT);
                    goto cleanup;
                }
                param->value.ui = persistentDef->blkio.weight;
                break;

            case 1: /* blkiotune.device_weight */
                if (persistentDef->blkio.ndevices > 0) {
                    virBuffer buf = VIR_BUFFER_INITIALIZER;
                    bool comma = false;

                    for (j = 0; j < persistentDef->blkio.ndevices; j++) {
                        if (!persistentDef->blkio.devices[j].weight)
                            continue;
                        if (comma)
                            virBufferAddChar(&buf, ',');
                        else
                            comma = true;
                        virBufferAsprintf(&buf, "%s,%u",
                                          persistentDef->blkio.devices[j].path,
                                          persistentDef->blkio.devices[j].weight);
                    }
2906
                    if (virBufferCheckError(&buf) < 0)
2907 2908 2909 2910 2911 2912 2913 2914 2915 2916 2917 2918 2919 2920 2921 2922 2923 2924 2925 2926 2927 2928 2929 2930 2931 2932 2933 2934 2935 2936 2937
                        goto cleanup;
                    param->value.s = virBufferContentAndReset(&buf);
                }
                if (!param->value.s && VIR_STRDUP(param->value.s, "") < 0)
                    goto cleanup;
                param->type = VIR_TYPED_PARAM_STRING;
                if (virStrcpyStatic(param->field,
                                    VIR_DOMAIN_BLKIO_DEVICE_WEIGHT) == NULL) {
                    virReportError(VIR_ERR_INTERNAL_ERROR,
                                   _("Field name '%s' too long"),
                                   VIR_DOMAIN_BLKIO_DEVICE_WEIGHT);
                    goto cleanup;
                }
                break;

            case 2: /* blkiotune.device_read_iops */
                if (persistentDef->blkio.ndevices > 0) {
                    virBuffer buf = VIR_BUFFER_INITIALIZER;
                    bool comma = false;

                    for (j = 0; j < persistentDef->blkio.ndevices; j++) {
                        if (!persistentDef->blkio.devices[j].riops)
                            continue;
                        if (comma)
                            virBufferAddChar(&buf, ',');
                        else
                            comma = true;
                        virBufferAsprintf(&buf, "%s,%u",
                                          persistentDef->blkio.devices[j].path,
                                          persistentDef->blkio.devices[j].riops);
                    }
2938
                    if (virBufferCheckError(&buf) < 0)
2939 2940 2941 2942 2943 2944 2945 2946 2947 2948 2949 2950 2951 2952 2953 2954 2955 2956 2957 2958 2959 2960 2961 2962 2963 2964 2965 2966 2967 2968
                        goto cleanup;
                    param->value.s = virBufferContentAndReset(&buf);
                }
                if (!param->value.s && VIR_STRDUP(param->value.s, "") < 0)
                    goto cleanup;
                param->type = VIR_TYPED_PARAM_STRING;
                if (virStrcpyStatic(param->field,
                                    VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS) == NULL) {
                    virReportError(VIR_ERR_INTERNAL_ERROR,
                                   _("Field name '%s' too long"),
                                   VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS);
                    goto cleanup;
                }
                break;
            case 3: /* blkiotune.device_write_iops */
                if (persistentDef->blkio.ndevices > 0) {
                    virBuffer buf = VIR_BUFFER_INITIALIZER;
                    bool comma = false;

                    for (j = 0; j < persistentDef->blkio.ndevices; j++) {
                        if (!persistentDef->blkio.devices[j].wiops)
                            continue;
                        if (comma)
                            virBufferAddChar(&buf, ',');
                        else
                            comma = true;
                        virBufferAsprintf(&buf, "%s,%u",
                                          persistentDef->blkio.devices[j].path,
                                          persistentDef->blkio.devices[j].wiops);
                    }
2969
                    if (virBufferCheckError(&buf) < 0)
2970 2971 2972 2973 2974 2975 2976 2977 2978 2979 2980
                        goto cleanup;
                    param->value.s = virBufferContentAndReset(&buf);
                }
                if (!param->value.s && VIR_STRDUP(param->value.s, "") < 0)
                    goto cleanup;
                param->type = VIR_TYPED_PARAM_STRING;
                if (virStrcpyStatic(param->field,
                                    VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS) == NULL) {
                    virReportError(VIR_ERR_INTERNAL_ERROR,
                                   _("Field name '%s' too long"),
                                   VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS);
2981
                    goto cleanup;
2982 2983 2984 2985 2986 2987 2988 2989 2990 2991 2992 2993 2994 2995 2996 2997 2998 2999
                }
                break;
            case 4: /* blkiotune.device_read_bps */
                if (persistentDef->blkio.ndevices > 0) {
                    virBuffer buf = VIR_BUFFER_INITIALIZER;
                    bool comma = false;

                    for (j = 0; j < persistentDef->blkio.ndevices; j++) {
                        if (!persistentDef->blkio.devices[j].rbps)
                            continue;
                        if (comma)
                            virBufferAddChar(&buf, ',');
                        else
                            comma = true;
                        virBufferAsprintf(&buf, "%s,%llu",
                                          persistentDef->blkio.devices[j].path,
                                          persistentDef->blkio.devices[j].rbps);
                    }
3000
                    if (virBufferCheckError(&buf) < 0)
3001 3002 3003 3004 3005 3006 3007 3008 3009 3010 3011 3012 3013 3014 3015 3016 3017 3018 3019 3020 3021 3022 3023 3024 3025 3026 3027 3028 3029 3030 3031
                        goto cleanup;
                    param->value.s = virBufferContentAndReset(&buf);
                }
                if (!param->value.s && VIR_STRDUP(param->value.s, "") < 0)
                    goto cleanup;
                param->type = VIR_TYPED_PARAM_STRING;
                if (virStrcpyStatic(param->field,
                                    VIR_DOMAIN_BLKIO_DEVICE_READ_BPS) == NULL) {
                    virReportError(VIR_ERR_INTERNAL_ERROR,
                                   _("Field name '%s' too long"),
                                   VIR_DOMAIN_BLKIO_DEVICE_READ_BPS);
                    goto cleanup;
                }
                break;

            case 5: /* blkiotune.device_write_bps */
                if (persistentDef->blkio.ndevices > 0) {
                    virBuffer buf = VIR_BUFFER_INITIALIZER;
                    bool comma = false;

                    for (j = 0; j < persistentDef->blkio.ndevices; j++) {
                        if (!persistentDef->blkio.devices[j].wbps)
                            continue;
                        if (comma)
                            virBufferAddChar(&buf, ',');
                        else
                            comma = true;
                        virBufferAsprintf(&buf, "%s,%llu",
                                          persistentDef->blkio.devices[j].path,
                                          persistentDef->blkio.devices[j].wbps);
                    }
3032
                    if (virBufferCheckError(&buf) < 0)
3033 3034 3035 3036 3037 3038 3039 3040 3041 3042 3043 3044 3045
                        goto cleanup;
                    param->value.s = virBufferContentAndReset(&buf);
                }
                if (!param->value.s && VIR_STRDUP(param->value.s, "") < 0)
                    goto cleanup;
                param->type = VIR_TYPED_PARAM_STRING;
                if (virStrcpyStatic(param->field,
                                    VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS) == NULL) {
                    virReportError(VIR_ERR_INTERNAL_ERROR,
                                   _("Field name '%s' too long"),
                                   VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS);
                    goto cleanup;
                }
3046 3047 3048 3049 3050 3051 3052 3053 3054
                break;
            }
        }
    }

    if (LXC_NB_BLKIO_PARAM < *nparams)
        *nparams = LXC_NB_BLKIO_PARAM;
    ret = 0;

3055
 cleanup:
3056
    if (vm)
3057
        virObjectUnlock(vm);
3058
    virObjectUnref(caps);
3059 3060 3061 3062
    return ret;
}


3063 3064 3065 3066 3067 3068 3069
#ifdef __linux__
static int
lxcDomainInterfaceStats(virDomainPtr dom,
                        const char *path,
                        struct _virDomainInterfaceStats *stats)
{
    virDomainObjPtr vm;
3070
    size_t i;
3071 3072
    int ret = -1;

M
Michal Privoznik 已提交
3073
    if (!(vm = lxcDomObjFromDomain(dom)))
3074 3075
        goto cleanup;

3076 3077 3078
    if (virDomainInterfaceStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3079
    if (!virDomainObjIsActive(vm)) {
3080 3081
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
3082 3083 3084 3085
        goto cleanup;
    }

    /* Check the path is one of the domain's network interfaces. */
3086
    for (i = 0; i < vm->def->nnets; i++) {
3087 3088 3089 3090 3091 3092 3093 3094
        if (vm->def->nets[i]->ifname &&
            STREQ(vm->def->nets[i]->ifname, path)) {
            ret = 0;
            break;
        }
    }

    if (ret == 0)
3095
        ret = linuxDomainInterfaceStats(path, stats);
3096
    else
3097 3098
        virReportError(VIR_ERR_INVALID_ARG,
                       _("Invalid path, '%s' is not a known interface"), path);
3099

3100
 cleanup:
3101
    if (vm)
3102
        virObjectUnlock(vm);
3103 3104 3105 3106 3107 3108 3109
    return ret;
}
#else
static int
lxcDomainInterfaceStats(virDomainPtr dom,
                        const char *path ATTRIBUTE_UNUSED,
                        struct _virDomainInterfaceStats *stats ATTRIBUTE_UNUSED)
A
Alex Jia 已提交
3110
{
3111
    virReportUnsupportedError();
3112 3113 3114 3115
    return -1;
}
#endif

3116
static int lxcDomainGetAutostart(virDomainPtr dom,
3117 3118
                                   int *autostart)
{
3119 3120 3121
    virDomainObjPtr vm;
    int ret = -1;

M
Michal Privoznik 已提交
3122
    if (!(vm = lxcDomObjFromDomain(dom)))
3123 3124
        goto cleanup;

3125 3126 3127
    if (virDomainGetAutostartEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3128 3129 3130
    *autostart = vm->autostart;
    ret = 0;

3131
 cleanup:
3132
    if (vm)
3133
        virObjectUnlock(vm);
3134 3135 3136 3137
    return ret;
}

static int lxcDomainSetAutostart(virDomainPtr dom,
3138 3139
                                   int autostart)
{
3140
    virLXCDriverPtr driver = dom->conn->privateData;
3141 3142 3143
    virDomainObjPtr vm;
    char *configFile = NULL, *autostartLink = NULL;
    int ret = -1;
3144
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
3145

M
Michal Privoznik 已提交
3146
    if (!(vm = lxcDomObjFromDomain(dom)))
3147 3148
        goto cleanup;

3149 3150 3151
    if (virDomainSetAutostartEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3152
    if (!vm->persistent) {
3153 3154
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot set autostart for transient domain"));
3155 3156 3157 3158 3159
        goto cleanup;
    }

    autostart = (autostart != 0);

3160 3161 3162 3163
    if (vm->autostart == autostart) {
        ret = 0;
        goto cleanup;
    }
3164

3165
    configFile = virDomainConfigFile(cfg->configDir,
3166 3167 3168
                                     vm->def->name);
    if (configFile == NULL)
        goto cleanup;
3169
    autostartLink = virDomainConfigFile(cfg->autostartDir,
3170 3171 3172
                                        vm->def->name);
    if (autostartLink == NULL)
        goto cleanup;
3173

3174
    if (autostart) {
3175
        if (virFileMakePath(cfg->autostartDir) < 0) {
3176
            virReportSystemError(errno,
3177
                                 _("Cannot create autostart directory %s"),
3178
                                 cfg->autostartDir);
3179
            goto cleanup;
3180 3181
        }

3182
        if (symlink(configFile, autostartLink) < 0) {
3183
            virReportSystemError(errno,
3184 3185 3186 3187 3188 3189
                                 _("Failed to create symlink '%s to '%s'"),
                                 autostartLink, configFile);
            goto cleanup;
        }
    } else {
        if (unlink(autostartLink) < 0 && errno != ENOENT && errno != ENOTDIR) {
3190
            virReportSystemError(errno,
3191 3192 3193 3194
                                 _("Failed to delete symlink '%s'"),
                                 autostartLink);
            goto cleanup;
        }
3195
    }
3196 3197

    vm->autostart = autostart;
3198 3199
    ret = 0;

3200
 cleanup:
3201 3202 3203
    VIR_FREE(configFile);
    VIR_FREE(autostartLink);
    if (vm)
3204
        virObjectUnlock(vm);
3205
    virObjectUnref(cfg);
3206 3207 3208
    return ret;
}

3209
static int lxcFreezeContainer(virDomainObjPtr vm)
R
Ryota Ozaki 已提交
3210 3211 3212 3213 3214 3215 3216
{
    int timeout = 1000; /* In milliseconds */
    int check_interval = 1; /* In milliseconds */
    int exp = 10;
    int waited_time = 0;
    int ret = -1;
    char *state = NULL;
3217
    virLXCDomainObjPrivatePtr priv = vm->privateData;
3218

R
Ryota Ozaki 已提交
3219 3220 3221 3222 3223 3224 3225 3226 3227
    while (waited_time < timeout) {
        int r;
        /*
         * Writing "FROZEN" to the "freezer.state" freezes the group,
         * i.e., the container, temporarily transiting "FREEZING" state.
         * Once the freezing is completed, the state of the group transits
         * to "FROZEN".
         * (see linux-2.6/Documentation/cgroups/freezer-subsystem.txt)
         */
3228
        r = virCgroupSetFreezerState(priv->cgroup, "FROZEN");
R
Ryota Ozaki 已提交
3229 3230 3231

        /*
         * Returning EBUSY explicitly indicates that the group is
3232
         * being frozen but incomplete, and other errors are true
R
Ryota Ozaki 已提交
3233 3234 3235 3236 3237 3238 3239
         * errors.
         */
        if (r < 0 && r != -EBUSY) {
            VIR_DEBUG("Writing freezer.state failed with errno: %d", r);
            goto error;
        }
        if (r == -EBUSY)
3240
            VIR_DEBUG("Writing freezer.state gets EBUSY");
R
Ryota Ozaki 已提交
3241 3242 3243 3244 3245 3246 3247 3248 3249 3250 3251 3252 3253 3254

        /*
         * Unfortunately, returning 0 (success) is likely to happen
         * even when the freezing has not been completed. Sometimes
         * the state of the group remains "FREEZING" like when
         * returning -EBUSY and even worse may never transit to
         * "FROZEN" even if writing "FROZEN" again.
         *
         * So we don't trust the return value anyway and always
         * decide that the freezing has been complete only with
         * the state actually transit to "FROZEN".
         */
        usleep(check_interval * 1000);

3255
        r = virCgroupGetFreezerState(priv->cgroup, &state);
R
Ryota Ozaki 已提交
3256 3257 3258 3259 3260 3261 3262 3263 3264 3265 3266 3267 3268 3269 3270 3271 3272 3273 3274 3275 3276 3277 3278 3279

        if (r < 0) {
            VIR_DEBUG("Reading freezer.state failed with errno: %d", r);
            goto error;
        }
        VIR_DEBUG("Read freezer.state: %s", state);

        if (STREQ(state, "FROZEN")) {
            ret = 0;
            goto cleanup;
        }

        waited_time += check_interval;
        /*
         * Increasing check_interval exponentially starting with
         * small initial value treats nicely two cases; One is
         * a container is under no load and waiting for long period
         * makes no sense. The other is under heavy load. The container
         * may stay longer time in FREEZING or never transit to FROZEN.
         * In that case, eager polling will just waste CPU time.
         */
        check_interval *= exp;
        VIR_FREE(state);
    }
3280
    VIR_DEBUG("lxcFreezeContainer timeout");
3281
 error:
R
Ryota Ozaki 已提交
3282 3283 3284 3285 3286
    /*
     * If timeout or an error on reading the state occurs,
     * activate the group again and return an error.
     * This is likely to fall the group back again gracefully.
     */
3287
    virCgroupSetFreezerState(priv->cgroup, "THAWED");
R
Ryota Ozaki 已提交
3288 3289
    ret = -1;

3290
 cleanup:
R
Ryota Ozaki 已提交
3291 3292 3293 3294 3295 3296
    VIR_FREE(state);
    return ret;
}

static int lxcDomainSuspend(virDomainPtr dom)
{
3297
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
3298
    virDomainObjPtr vm;
3299
    virObjectEventPtr event = NULL;
R
Ryota Ozaki 已提交
3300
    int ret = -1;
3301
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
3302

M
Michal Privoznik 已提交
3303
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
3304 3305
        goto cleanup;

3306 3307 3308
    if (virDomainSuspendEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

D
Daniel P. Berrange 已提交
3309
    if (!virDomainObjIsActive(vm)) {
3310 3311
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
R
Ryota Ozaki 已提交
3312 3313 3314
        goto cleanup;
    }

J
Jiri Denemark 已提交
3315
    if (virDomainObjGetState(vm, NULL) != VIR_DOMAIN_PAUSED) {
3316
        if (lxcFreezeContainer(vm) < 0) {
3317 3318
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Suspend operation failed"));
R
Ryota Ozaki 已提交
3319 3320
            goto cleanup;
        }
J
Jiri Denemark 已提交
3321
        virDomainObjSetState(vm, VIR_DOMAIN_PAUSED, VIR_DOMAIN_PAUSED_USER);
R
Ryota Ozaki 已提交
3322

3323
        event = virDomainEventLifecycleNewFromObj(vm,
R
Ryota Ozaki 已提交
3324 3325 3326 3327
                                         VIR_DOMAIN_EVENT_SUSPENDED,
                                         VIR_DOMAIN_EVENT_SUSPENDED_PAUSED);
    }

3328
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0)
R
Ryota Ozaki 已提交
3329 3330 3331
        goto cleanup;
    ret = 0;

3332
 cleanup:
R
Ryota Ozaki 已提交
3333
    if (event)
3334
        virObjectEventStateQueue(driver->domainEventState, event);
R
Ryota Ozaki 已提交
3335
    if (vm)
3336
        virObjectUnlock(vm);
3337
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
3338 3339 3340 3341 3342
    return ret;
}

static int lxcDomainResume(virDomainPtr dom)
{
3343
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
3344
    virDomainObjPtr vm;
3345
    virObjectEventPtr event = NULL;
R
Ryota Ozaki 已提交
3346
    int ret = -1;
3347
    virLXCDomainObjPrivatePtr priv;
3348
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
3349

M
Michal Privoznik 已提交
3350
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
3351 3352
        goto cleanup;

3353 3354
    priv = vm->privateData;

3355 3356 3357
    if (virDomainResumeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

D
Daniel P. Berrange 已提交
3358
    if (!virDomainObjIsActive(vm)) {
3359 3360
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
R
Ryota Ozaki 已提交
3361 3362 3363
        goto cleanup;
    }

J
Jiri Denemark 已提交
3364
    if (virDomainObjGetState(vm, NULL) == VIR_DOMAIN_PAUSED) {
3365
        if (virCgroupSetFreezerState(priv->cgroup, "THAWED") < 0) {
3366 3367
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Resume operation failed"));
R
Ryota Ozaki 已提交
3368 3369
            goto cleanup;
        }
J
Jiri Denemark 已提交
3370 3371
        virDomainObjSetState(vm, VIR_DOMAIN_RUNNING,
                             VIR_DOMAIN_RUNNING_UNPAUSED);
R
Ryota Ozaki 已提交
3372

3373
        event = virDomainEventLifecycleNewFromObj(vm,
R
Ryota Ozaki 已提交
3374 3375 3376 3377
                                         VIR_DOMAIN_EVENT_RESUMED,
                                         VIR_DOMAIN_EVENT_RESUMED_UNPAUSED);
    }

3378
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0)
R
Ryota Ozaki 已提交
3379 3380 3381
        goto cleanup;
    ret = 0;

3382
 cleanup:
R
Ryota Ozaki 已提交
3383
    if (event)
3384
        virObjectEventStateQueue(driver->domainEventState, event);
R
Ryota Ozaki 已提交
3385
    if (vm)
3386
        virObjectUnlock(vm);
3387
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
3388 3389 3390
    return ret;
}

3391 3392
static int
lxcDomainOpenConsole(virDomainPtr dom,
3393
                      const char *dev_name,
3394 3395 3396 3397 3398 3399
                      virStreamPtr st,
                      unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    int ret = -1;
    virDomainChrDefPtr chr = NULL;
3400
    size_t i;
3401 3402 3403

    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
3404
    if (!(vm = lxcDomObjFromDomain(dom)))
3405 3406
        goto cleanup;

3407 3408 3409
    if (virDomainOpenConsoleEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3410
    if (!virDomainObjIsActive(vm)) {
3411 3412
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
3413 3414 3415
        goto cleanup;
    }

3416
    if (dev_name) {
3417
        for (i = 0; i < vm->def->nconsoles; i++) {
3418 3419 3420 3421 3422 3423
            if (vm->def->consoles[i]->info.alias &&
                STREQ(vm->def->consoles[i]->info.alias, dev_name)) {
                chr = vm->def->consoles[i];
                break;
            }
        }
3424
    } else {
3425 3426
        if (vm->def->nconsoles)
            chr = vm->def->consoles[0];
3427 3428 3429 3430 3431
        else if (vm->def->nserials)
            chr = vm->def->serials[0];
    }

    if (!chr) {
3432 3433 3434
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot find console device '%s'"),
                       dev_name ? dev_name : _("default"));
3435 3436 3437
        goto cleanup;
    }

3438
    if (chr->source.type != VIR_DOMAIN_CHR_TYPE_PTY) {
3439 3440
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("character device %s is not using a PTY"), dev_name);
3441 3442 3443
        goto cleanup;
    }

3444
    if (virFDStreamOpenFile(st, chr->source.data.file.path,
E
Eric Blake 已提交
3445
                            0, 0, O_RDWR) < 0)
3446 3447 3448
        goto cleanup;

    ret = 0;
3449
 cleanup:
3450
    if (vm)
3451
        virObjectUnlock(vm);
3452 3453 3454
    return ret;
}

3455 3456 3457 3458 3459 3460 3461 3462 3463 3464 3465 3466 3467 3468 3469 3470 3471 3472 3473 3474 3475

static int
lxcDomainSendProcessSignal(virDomainPtr dom,
                           long long pid_value,
                           unsigned int signum,
                           unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    virLXCDomainObjPrivatePtr priv;
    pid_t victim;
    int ret = -1;

    virCheckFlags(0, -1);

    if (signum >= VIR_DOMAIN_PROCESS_SIGNAL_LAST) {
        virReportError(VIR_ERR_INVALID_ARG,
                       _("signum value %d is out of range"),
                       signum);
        return -1;
    }

M
Michal Privoznik 已提交
3476
    if (!(vm = lxcDomObjFromDomain(dom)))
3477
        goto cleanup;
M
Michal Privoznik 已提交
3478

3479 3480
    priv = vm->privateData;

3481 3482 3483
    if (virDomainSendProcessSignalEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3484 3485 3486 3487 3488 3489 3490 3491 3492 3493 3494 3495 3496 3497 3498 3499 3500 3501 3502 3503 3504 3505 3506 3507 3508 3509 3510 3511 3512 3513 3514 3515 3516 3517 3518 3519 3520 3521
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
        goto cleanup;
    }

    /*
     * XXX if the kernel has /proc/$PID/ns/pid we can
     * switch into container namespace & that way be
     * able to kill any PID. Alternatively if there
     * is a way to find a mapping of guest<->host PIDs
     * we can kill that way.
     */
    if (pid_value != 1) {
        virReportError(VIR_ERR_ARGUMENT_UNSUPPORTED, "%s",
                       _("Only the init process may be killed"));
        goto cleanup;
    }

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
        goto cleanup;
    }
    victim = priv->initpid;

    /* We're relying on fact libvirt header signal numbers
     * are taken from Linux, to avoid mapping
     */
    if (kill(victim, signum) < 0) {
        virReportSystemError(errno,
                             _("Unable to send %d signal to process %d"),
                             signum, victim);
        goto cleanup;
    }

    ret = 0;

3522
 cleanup:
3523
    if (vm)
3524
        virObjectUnlock(vm);
3525 3526 3527 3528
    return ret;
}


3529
static int
3530 3531
lxcConnectListAllDomains(virConnectPtr conn,
                         virDomainPtr **domains,
3532 3533
                  unsigned int flags)
{
3534
    virLXCDriverPtr driver = conn->privateData;
3535 3536
    int ret = -1;

O
Osier Yang 已提交
3537
    virCheckFlags(VIR_CONNECT_LIST_DOMAINS_FILTERS_ALL, -1);
3538

3539 3540 3541
    if (virConnectListAllDomainsEnsureACL(conn) < 0)
        return -1;

3542 3543
    ret = virDomainObjListExport(driver->domains, conn, domains,
                                 virConnectListAllDomainsCheckACL, flags);
3544 3545 3546
    return ret;
}

3547

3548 3549 3550 3551 3552 3553 3554 3555 3556
static int
lxcDomainInitctlCallback(pid_t pid ATTRIBUTE_UNUSED,
                         void *opaque)
{
    int *command = opaque;
    return virInitctlSetRunLevel(*command);
}


3557 3558 3559 3560 3561 3562 3563
static int
lxcDomainShutdownFlags(virDomainPtr dom,
                       unsigned int flags)
{
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    int ret = -1;
3564
    int rc;
3565 3566 3567 3568

    virCheckFlags(VIR_DOMAIN_SHUTDOWN_INITCTL |
                  VIR_DOMAIN_SHUTDOWN_SIGNAL, -1);

M
Michal Privoznik 已提交
3569
    if (!(vm = lxcDomObjFromDomain(dom)))
3570 3571 3572 3573
        goto cleanup;

    priv = vm->privateData;

3574
    if (virDomainShutdownFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
3575 3576
        goto cleanup;

3577 3578 3579 3580 3581 3582 3583 3584 3585 3586 3587 3588
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
        goto cleanup;
    }

3589 3590
    if (flags == 0 ||
        (flags & VIR_DOMAIN_SHUTDOWN_INITCTL)) {
3591 3592 3593 3594 3595
        int command = VIR_INITCTL_RUNLEVEL_POWEROFF;

        if ((rc = virProcessRunInMountNamespace(priv->initpid,
                                                lxcDomainInitctlCallback,
                                                &command)) < 0)
3596
            goto cleanup;
3597 3598
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
3599 3600 3601 3602
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
            goto cleanup;
        }
3603 3604
    } else {
        rc = 0;
3605
    }
3606

3607 3608 3609
    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_SHUTDOWN_SIGNAL))) {
3610 3611
        if (kill(priv->initpid, SIGTERM) < 0 &&
            errno != ESRCH) {
3612 3613 3614 3615 3616 3617 3618 3619 3620
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
                                 (unsigned long long)priv->initpid);
            goto cleanup;
        }
    }

    ret = 0;

3621
 cleanup:
3622
    if (vm)
3623
        virObjectUnlock(vm);
3624 3625 3626 3627 3628 3629 3630 3631 3632
    return ret;
}

static int
lxcDomainShutdown(virDomainPtr dom)
{
    return lxcDomainShutdownFlags(dom, 0);
}

3633

3634 3635 3636 3637 3638 3639 3640 3641 3642 3643 3644 3645
static int
lxcDomainReboot(virDomainPtr dom,
                unsigned int flags)
{
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    int ret = -1;
    int rc;

    virCheckFlags(VIR_DOMAIN_REBOOT_INITCTL |
                  VIR_DOMAIN_REBOOT_SIGNAL, -1);

M
Michal Privoznik 已提交
3646
    if (!(vm = lxcDomObjFromDomain(dom)))
3647 3648 3649 3650
        goto cleanup;

    priv = vm->privateData;

3651
    if (virDomainRebootEnsureACL(dom->conn, vm->def, flags) < 0)
3652 3653
        goto cleanup;

3654 3655 3656 3657 3658 3659 3660 3661 3662 3663 3664 3665 3666 3667
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
        goto cleanup;
    }

    if (flags == 0 ||
        (flags & VIR_DOMAIN_REBOOT_INITCTL)) {
3668 3669 3670 3671 3672
        int command = VIR_INITCTL_RUNLEVEL_REBOOT;

        if ((rc = virProcessRunInMountNamespace(priv->initpid,
                                                lxcDomainInitctlCallback,
                                                &command)) < 0)
3673 3674 3675 3676 3677 3678 3679 3680 3681 3682 3683 3684 3685 3686 3687 3688 3689 3690 3691 3692 3693 3694 3695 3696 3697
            goto cleanup;
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
            goto cleanup;
        }
    } else {
        rc = 0;
    }

    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_REBOOT_SIGNAL))) {
        if (kill(priv->initpid, SIGHUP) < 0 &&
            errno != ESRCH) {
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
                                 (unsigned long long)priv->initpid);
            goto cleanup;
        }
    }

    ret = 0;

3698
 cleanup:
3699
    if (vm)
3700
        virObjectUnlock(vm);
3701 3702 3703 3704
    return ret;
}


3705
static int
3706
lxcDomainAttachDeviceConfig(virDomainDefPtr vmdef,
3707 3708 3709
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3710
    virDomainDiskDefPtr disk;
3711
    virDomainNetDefPtr net;
3712
    virDomainHostdevDefPtr hostdev;
3713 3714

    switch (dev->type) {
3715 3716 3717 3718 3719 3720 3721
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (virDomainDiskIndexByName(vmdef, disk->dst, true) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("target %s already exists."), disk->dst);
            return -1;
        }
3722
        if (virDomainDiskInsert(vmdef, disk))
3723 3724 3725 3726 3727 3728
            return -1;
        /* vmdef has the pointer. Generic codes for vmdef will do all jobs */
        dev->data.disk = NULL;
        ret = 0;
        break;

3729 3730
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
3731
        if (virDomainNetInsert(vmdef, net) < 0)
3732 3733 3734 3735 3736
            goto cleanup;
        dev->data.net = NULL;
        ret = 0;
        break;

3737 3738 3739 3740 3741 3742 3743
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        hostdev = dev->data.hostdev;
        if (virDomainHostdevFind(vmdef, hostdev, NULL) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device is already in the domain configuration"));
            return -1;
        }
3744
        if (virDomainHostdevInsert(vmdef, hostdev) < 0)
3745 3746 3747 3748 3749
            return -1;
        dev->data.hostdev = NULL;
        ret = 0;
        break;

3750 3751 3752 3753 3754 3755
    default:
         virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                        _("persistent attach of device is not supported"));
         break;
    }

3756
 cleanup:
3757 3758 3759 3760 3761
    return ret;
}


static int
3762
lxcDomainUpdateDeviceConfig(virDomainDefPtr vmdef,
3763 3764 3765
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3766 3767
    virDomainNetDefPtr net;
    int idx;
3768 3769

    switch (dev->type) {
3770 3771
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
3772
        if ((idx = virDomainNetFindIdx(vmdef, net)) < 0)
3773 3774 3775 3776 3777 3778 3779 3780 3781 3782
            goto cleanup;

        virDomainNetDefFree(vmdef->nets[idx]);

        vmdef->nets[idx] = net;
        dev->data.net = NULL;
        ret = 0;

        break;

3783 3784 3785 3786 3787 3788
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent update of device is not supported"));
        break;
    }

3789
 cleanup:
3790 3791 3792 3793 3794
    return ret;
}


static int
3795
lxcDomainDetachDeviceConfig(virDomainDefPtr vmdef,
3796 3797 3798
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3799
    virDomainDiskDefPtr disk, det_disk;
3800
    virDomainNetDefPtr net;
3801
    virDomainHostdevDefPtr hostdev, det_hostdev;
3802
    int idx;
3803 3804

    switch (dev->type) {
3805 3806 3807 3808 3809 3810 3811 3812 3813 3814 3815
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (!(det_disk = virDomainDiskRemoveByName(vmdef, disk->dst))) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("no target device %s"), disk->dst);
            return -1;
        }
        virDomainDiskDefFree(det_disk);
        ret = 0;
        break;

3816 3817
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
3818
        if ((idx = virDomainNetFindIdx(vmdef, net)) < 0)
3819
            goto cleanup;
3820

3821 3822 3823 3824 3825
        /* this is guaranteed to succeed */
        virDomainNetDefFree(virDomainNetRemove(vmdef, idx));
        ret = 0;
        break;

3826 3827 3828 3829 3830 3831 3832 3833 3834 3835 3836 3837 3838
    case VIR_DOMAIN_DEVICE_HOSTDEV: {
        hostdev = dev->data.hostdev;
        if ((idx = virDomainHostdevFind(vmdef, hostdev, &det_hostdev)) < 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device not present in domain configuration"));
            return -1;
        }
        virDomainHostdevRemove(vmdef, idx);
        virDomainHostdevDefFree(det_hostdev);
        ret = 0;
        break;
    }

3839 3840 3841 3842 3843 3844
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent detach of device is not supported"));
        break;
    }

3845
 cleanup:
3846 3847 3848 3849
    return ret;
}


3850 3851 3852 3853 3854 3855 3856 3857 3858 3859 3860 3861 3862 3863 3864 3865 3866 3867 3868 3869 3870 3871 3872 3873 3874 3875 3876 3877 3878 3879 3880 3881 3882 3883 3884 3885 3886 3887 3888 3889 3890 3891 3892 3893 3894 3895 3896 3897
struct lxcDomainAttachDeviceMknodData {
    virLXCDriverPtr driver;
    mode_t mode;
    dev_t dev;
    virDomainObjPtr vm;
    virDomainDeviceDefPtr def;
    char *file;
};

static int
lxcDomainAttachDeviceMknodHelper(pid_t pid ATTRIBUTE_UNUSED,
                                 void *opaque)
{
    struct lxcDomainAttachDeviceMknodData *data = opaque;
    int ret = -1;

    virSecurityManagerPostFork(data->driver->securityManager);

    if (virFileMakeParentPath(data->file) < 0) {
        virReportSystemError(errno,
                             _("Unable to create %s"), data->file);
        goto cleanup;
    }

    /* Yes, the device name we're creating may not
     * actually correspond to the major:minor number
     * we're using, but we've no other option at this
     * time. Just have to hope that containerized apps
     * don't get upset that the major:minor is different
     * to that normally implied by the device name
     */
    VIR_DEBUG("Creating dev %s (%d,%d)",
              data->file, major(data->dev), minor(data->dev));
    if (mknod(data->file, data->mode, data->dev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             data->file);
        goto cleanup;
    }

    if (lxcContainerChown(data->vm->def, data->file) < 0)
        goto cleanup;

    /* Labelling normally operates on src, but we need
     * to actually label the dst here, so hack the config */
    switch (data->def->type) {
    case VIR_DOMAIN_DEVICE_DISK: {
        virDomainDiskDefPtr def = data->def->data.disk;
3898 3899
        char *tmpsrc = def->src->path;
        def->src->path = data->file;
3900 3901
        if (virSecurityManagerSetDiskLabel(data->driver->securityManager,
                                           data->vm->def, def) < 0) {
3902
            def->src->path = tmpsrc;
3903 3904
            goto cleanup;
        }
3905
        def->src->path = tmpsrc;
3906 3907
    }   break;

3908 3909 3910 3911 3912 3913 3914
    case VIR_DOMAIN_DEVICE_HOSTDEV: {
        virDomainHostdevDefPtr def = data->def->data.hostdev;
        if (virSecurityManagerSetHostdevLabel(data->driver->securityManager,
                                              data->vm->def, def, NULL) < 0)
            goto cleanup;
    }   break;

3915 3916 3917 3918 3919 3920 3921 3922 3923 3924 3925 3926 3927 3928 3929 3930 3931 3932 3933 3934 3935 3936 3937 3938 3939 3940 3941 3942 3943 3944 3945 3946 3947 3948 3949 3950 3951 3952 3953 3954 3955 3956 3957 3958 3959 3960 3961 3962 3963 3964 3965
    default:
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Unexpected device type %d"),
                       data->def->type);
        goto cleanup;
    }

    ret = 0;

 cleanup:
    if (ret < 0)
        unlink(data->file);
    return ret;
}


static int
lxcDomainAttachDeviceMknod(virLXCDriverPtr driver,
                           mode_t mode,
                           dev_t dev,
                           virDomainObjPtr vm,
                           virDomainDeviceDefPtr def,
                           char *file)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    struct lxcDomainAttachDeviceMknodData data;

    memset(&data, 0, sizeof(data));

    data.driver = driver;
    data.mode = mode;
    data.dev = dev;
    data.vm = vm;
    data.def = def;
    data.file = file;

    if (virSecurityManagerPreFork(driver->securityManager) < 0)
        return -1;

    if (virProcessRunInMountNamespace(priv->initpid,
                                      lxcDomainAttachDeviceMknodHelper,
                                      &data) < 0) {
        virSecurityManagerPostFork(driver->securityManager);
        return -1;
    }

    virSecurityManagerPostFork(driver->securityManager);
    return 0;
}


3966 3967 3968 3969 3970 3971 3972 3973 3974 3975 3976 3977 3978 3979 3980 3981 3982 3983 3984 3985 3986 3987 3988 3989 3990 3991 3992 3993 3994 3995 3996 3997 3998
static int
lxcDomainAttachDeviceUnlinkHelper(pid_t pid ATTRIBUTE_UNUSED,
                                  void *opaque)
{
    const char *path = opaque;

    VIR_DEBUG("Unlinking %s", path);
    if (unlink(path) < 0 && errno != ENOENT) {
        virReportSystemError(errno,
                             _("Unable to remove device %s"), path);
        return -1;
    }

    return 0;
}


static int
lxcDomainAttachDeviceUnlink(virDomainObjPtr vm,
                            char *file)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (virProcessRunInMountNamespace(priv->initpid,
                                      lxcDomainAttachDeviceUnlinkHelper,
                                      file) < 0) {
        return -1;
    }

    return 0;
}


3999 4000 4001 4002 4003 4004 4005 4006 4007
static int
lxcDomainAttachDeviceDiskLive(virLXCDriverPtr driver,
                              virDomainObjPtr vm,
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = dev->data.disk;
    int ret = -1;
    struct stat sb;
4008 4009
    char *file = NULL;
    int perms;
4010
    const char *src = NULL;
4011 4012 4013 4014 4015 4016 4017

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4018 4019 4020 4021 4022 4023
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4024
    if (!virDomainDiskSourceIsBlockType(def)) {
4025 4026 4027 4028
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk for non-block device"));
        goto cleanup;
    }
4029 4030
    src = virDomainDiskGetSource(def);
    if (src == NULL) {
4031 4032 4033 4034 4035 4036 4037 4038 4039 4040 4041
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk without media"));
        goto cleanup;
    }

    if (virDomainDiskIndexByName(vm->def, def->dst, true) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("target %s already exists"), def->dst);
        goto cleanup;
    }

4042
    if (stat(src, &sb) < 0) {
4043
        virReportSystemError(errno,
4044
                             _("Unable to access %s"), src);
4045 4046 4047
        goto cleanup;
    }

4048
    if (!S_ISBLK(sb.st_mode)) {
4049
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
4050
                       _("Disk source %s must be a block device"),
4051
                       src);
4052 4053 4054
        goto cleanup;
    }

4055 4056 4057
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
4058
        goto cleanup;
4059
    }
4060

4061 4062 4063 4064
    perms = (def->readonly ?
             VIR_CGROUP_DEVICE_READ :
             VIR_CGROUP_DEVICE_RW) |
        VIR_CGROUP_DEVICE_MKNOD;
4065

4066 4067 4068 4069 4070
    if (virCgroupAllowDevice(priv->cgroup,
                             'b',
                             major(sb.st_rdev),
                             minor(sb.st_rdev),
                             perms) < 0)
4071
        goto cleanup;
4072

4073
    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks + 1) < 0)
4074 4075
        goto cleanup;

4076 4077
    if (virAsprintf(&file,
                    "/dev/%s", def->dst) < 0)
4078 4079
        goto cleanup;

4080 4081 4082 4083 4084 4085 4086 4087 4088 4089 4090 4091
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFBLK,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   file) < 0) {
        if (virCgroupDenyDevice(priv->cgroup,
                                'b',
                                major(sb.st_rdev),
                                minor(sb.st_rdev),
                                perms) < 0)
            VIR_WARN("cannot deny device %s for domain %s",
4092
                     src, vm->def->name);
4093 4094 4095 4096 4097 4098 4099
        goto cleanup;
    }

    virDomainDiskInsertPreAlloced(vm->def, def);

    ret = 0;

4100
 cleanup:
4101 4102
    if (src)
        virDomainAuditDisk(vm, NULL, src, "attach", ret == 0);
4103
    VIR_FREE(file);
4104 4105 4106 4107
    return ret;
}


4108
/* XXX conn required for network -> bridge resolution */
4109
static int
4110 4111 4112 4113 4114 4115 4116 4117 4118 4119 4120 4121 4122 4123 4124 4125
lxcDomainAttachDeviceNetLive(virConnectPtr conn,
                             virDomainObjPtr vm,
                             virDomainNetDefPtr net)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    int ret = -1;
    int actualType;
    char *veth = NULL;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

    /* preallocate new slot for device */
4126
    if (VIR_REALLOC_N(vm->def->nets, vm->def->nnets+1) < 0)
4127 4128 4129 4130 4131 4132
        return -1;

    /* If appropriate, grab a physical device from the configured
     * network's pool of devices, or resolve bridge device name
     * to the one defined in the network definition.
     */
4133
    if (networkAllocateActualDevice(vm->def, net) < 0)
4134 4135 4136 4137 4138 4139 4140 4141 4142 4143 4144 4145 4146 4147 4148 4149 4150 4151 4152 4153 4154 4155 4156 4157
        return -1;

    actualType = virDomainNetGetActualType(net);

    switch (actualType) {
    case VIR_DOMAIN_NET_TYPE_BRIDGE: {
        const char *brname = virDomainNetGetActualBridgeName(net);
        if (!brname) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("No bridge name specified"));
            goto cleanup;
        }
        if (!(veth = virLXCProcessSetupInterfaceBridged(conn,
                                                        vm->def,
                                                        net,
                                                        brname)))
            goto cleanup;
    }   break;
    case VIR_DOMAIN_NET_TYPE_NETWORK: {
        virNetworkPtr network;
        char *brname = NULL;
        bool fail = false;
        virErrorPtr errobj;

4158
        if (!(network = virNetworkLookupByName(conn, net->data.network.name)))
4159
            goto cleanup;
4160 4161
        if (!(brname = virNetworkGetBridgeName(network)))
           fail = true;
4162 4163 4164 4165 4166 4167 4168 4169 4170 4171 4172 4173 4174 4175 4176 4177 4178 4179 4180 4181 4182 4183 4184 4185 4186 4187 4188 4189 4190 4191 4192 4193 4194 4195 4196 4197 4198 4199 4200 4201

        /* Make sure any above failure is preserved */
        errobj = virSaveLastError();
        virNetworkFree(network);
        virSetError(errobj);
        virFreeError(errobj);

        if (fail)
            goto cleanup;

        if (!(veth = virLXCProcessSetupInterfaceBridged(conn,
                                                        vm->def,
                                                        net,
                                                        brname))) {
            VIR_FREE(brname);
            goto cleanup;
        }
        VIR_FREE(brname);
    }   break;
    case VIR_DOMAIN_NET_TYPE_DIRECT: {
        if (!(veth = virLXCProcessSetupInterfaceDirect(conn,
                                                       vm->def,
                                                       net)))
            goto cleanup;
    }   break;
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Network device type is not supported"));
        goto cleanup;
    }

    if (virNetDevSetNamespace(veth, priv->initpid) < 0) {
        virDomainAuditNet(vm, NULL, net, "attach", false);
        goto cleanup;
    }

    virDomainAuditNet(vm, NULL, net, "attach", true);

    ret = 0;

4202
 cleanup:
4203 4204 4205 4206 4207 4208 4209 4210 4211 4212 4213 4214 4215 4216 4217 4218 4219 4220 4221
    if (!ret) {
        vm->def->nets[vm->def->nnets++] = net;
    } else if (veth) {
        switch (actualType) {
        case VIR_DOMAIN_NET_TYPE_BRIDGE:
        case VIR_DOMAIN_NET_TYPE_NETWORK:
            ignore_value(virNetDevVethDelete(veth));
            break;

        case VIR_DOMAIN_NET_TYPE_DIRECT:
            ignore_value(virNetDevMacVLanDelete(veth));
            break;
        }
    }

    return ret;
}


4222 4223 4224 4225 4226 4227 4228 4229 4230 4231
static int
lxcDomainAttachDeviceHostdevSubsysUSBLive(virLXCDriverPtr driver,
                                          virDomainObjPtr vm,
                                          virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    char *src = NULL;
    struct stat sb;
4232
    virUSBDevicePtr usb = NULL;
4233 4234 4235 4236 4237 4238 4239 4240 4241

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host USB device already exists"));
        return -1;
    }

    if (virAsprintf(&src, "/dev/bus/usb/%03d/%03d",
                    def->source.subsys.u.usb.bus,
4242
                    def->source.subsys.u.usb.device) < 0)
4243 4244
        goto cleanup;

4245
    if (!(usb = virUSBDeviceNew(def->source.subsys.u.usb.bus,
4246
                                def->source.subsys.u.usb.device, NULL)))
4247 4248 4249 4250 4251 4252 4253 4254 4255 4256 4257 4258 4259 4260 4261
        goto cleanup;

    if (stat(src, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"), src);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("USB source %s was not a character device"),
                       src);
        goto cleanup;
    }

4262 4263 4264
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs + 1) < 0)
        goto cleanup;

4265
    if (virUSBDeviceFileIterate(usb,
4266
                                virLXCSetupHostUSBDeviceCgroup,
4267
                                priv->cgroup) < 0)
4268 4269
        goto cleanup;

4270 4271 4272 4273 4274 4275 4276
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFCHR,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   src) < 0) {
        if (virUSBDeviceFileIterate(usb,
4277
                                    virLXCTeardownHostUSBDeviceCgroup,
4278 4279 4280 4281 4282 4283
                                    priv->cgroup) < 0)
            VIR_WARN("cannot deny device %s for domain %s",
                     src, vm->def->name);
        goto cleanup;
    }

4284 4285
    vm->def->hostdevs[vm->def->nhostdevs++] = def;

4286 4287
    ret = 0;

4288
 cleanup:
4289
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
4290
    virUSBDeviceFree(usb);
4291 4292 4293 4294 4295
    VIR_FREE(src);
    return ret;
}


4296 4297 4298 4299 4300 4301 4302 4303 4304 4305 4306 4307 4308 4309 4310 4311 4312 4313 4314 4315 4316 4317 4318 4319 4320 4321 4322 4323 4324 4325 4326 4327 4328 4329 4330 4331
static int
lxcDomainAttachDeviceHostdevStorageLive(virLXCDriverPtr driver,
                                        virDomainObjPtr vm,
                                        virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    struct stat sb;

    if (!def->source.caps.u.storage.block) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Missing storage block path"));
        goto cleanup;
    }

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host device already exists"));
        return -1;
    }

    if (stat(def->source.caps.u.storage.block, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"),
                             def->source.caps.u.storage.block);
        goto cleanup;
    }

    if (!S_ISBLK(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Hostdev source %s must be a block device"),
                       def->source.caps.u.storage.block);
        goto cleanup;
    }

4332
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0)
4333 4334
        goto cleanup;

4335 4336 4337 4338 4339
    if (virCgroupAllowDevice(priv->cgroup,
                             'b',
                             major(sb.st_rdev),
                             minor(sb.st_rdev),
                             VIR_CGROUP_DEVICE_RWM) < 0)
4340 4341
        goto cleanup;

4342 4343 4344 4345 4346 4347 4348 4349 4350 4351 4352 4353 4354
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFBLK,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   def->source.caps.u.storage.block) < 0) {
        if (virCgroupDenyDevice(priv->cgroup,
                                'b',
                                major(sb.st_rdev),
                                minor(sb.st_rdev),
                                VIR_CGROUP_DEVICE_RWM) < 0)
            VIR_WARN("cannot deny device %s for domain %s",
                     def->source.caps.u.storage.block, vm->def->name);
4355 4356 4357 4358 4359 4360 4361
        goto cleanup;
    }

    vm->def->hostdevs[vm->def->nhostdevs++] = def;

    ret = 0;

4362
 cleanup:
4363 4364 4365 4366 4367
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    return ret;
}


4368 4369 4370 4371 4372 4373 4374 4375 4376 4377 4378 4379 4380 4381 4382 4383 4384 4385 4386 4387 4388 4389 4390 4391 4392 4393 4394 4395 4396 4397 4398 4399 4400 4401 4402 4403
static int
lxcDomainAttachDeviceHostdevMiscLive(virLXCDriverPtr driver,
                                     virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    struct stat sb;

    if (!def->source.caps.u.misc.chardev) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Missing storage block path"));
        goto cleanup;
    }

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host device already exists"));
        return -1;
    }

    if (stat(def->source.caps.u.misc.chardev, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"),
                             def->source.caps.u.misc.chardev);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Hostdev source %s must be a block device"),
                       def->source.caps.u.misc.chardev);
        goto cleanup;
    }

4404 4405 4406 4407 4408
    if (virCgroupAllowDevice(priv->cgroup,
                             'c',
                             major(sb.st_rdev),
                             minor(sb.st_rdev),
                             VIR_CGROUP_DEVICE_RWM) < 0)
4409 4410
        goto cleanup;

4411
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0)
4412 4413
        goto cleanup;

4414 4415 4416 4417 4418 4419 4420 4421 4422 4423 4424 4425 4426
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFBLK,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   def->source.caps.u.misc.chardev) < 0) {
        if (virCgroupDenyDevice(priv->cgroup,
                                'c',
                                major(sb.st_rdev),
                                minor(sb.st_rdev),
                                VIR_CGROUP_DEVICE_RWM) < 0)
            VIR_WARN("cannot deny device %s for domain %s",
                     def->source.caps.u.storage.block, vm->def->name);
4427 4428 4429 4430 4431 4432 4433
        goto cleanup;
    }

    vm->def->hostdevs[vm->def->nhostdevs++] = def;

    ret = 0;

4434
 cleanup:
4435 4436 4437 4438 4439
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    return ret;
}


4440 4441 4442 4443 4444 4445 4446 4447 4448 4449 4450 4451 4452 4453 4454 4455 4456 4457
static int
lxcDomainAttachDeviceHostdevSubsysLive(virLXCDriverPtr driver,
                                       virDomainObjPtr vm,
                                       virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        return lxcDomainAttachDeviceHostdevSubsysUSBLive(driver, vm, dev);

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevSubsysTypeToString(dev->data.hostdev->source.subsys.type));
        return -1;
    }
}


4458 4459 4460 4461 4462 4463 4464 4465 4466
static int
lxcDomainAttachDeviceHostdevCapsLive(virLXCDriverPtr driver,
                                     virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.caps.type) {
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_STORAGE:
        return lxcDomainAttachDeviceHostdevStorageLive(driver, vm, dev);

4467 4468 4469
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_MISC:
        return lxcDomainAttachDeviceHostdevMiscLive(driver, vm, dev);

4470 4471 4472 4473 4474 4475 4476 4477 4478
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevCapsTypeToString(dev->data.hostdev->source.caps.type));
        return -1;
    }
}


4479 4480 4481 4482 4483 4484 4485 4486 4487 4488 4489 4490 4491
static int
lxcDomainAttachDeviceHostdevLive(virLXCDriverPtr driver,
                                 virDomainObjPtr vm,
                                 virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach hostdev until init PID is known"));
        return -1;
    }

4492 4493 4494 4495 4496 4497
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        return -1;
    }

4498 4499 4500 4501
    switch (dev->data.hostdev->mode) {
    case VIR_DOMAIN_HOSTDEV_MODE_SUBSYS:
        return lxcDomainAttachDeviceHostdevSubsysLive(driver, vm, dev);

4502 4503 4504
    case VIR_DOMAIN_HOSTDEV_MODE_CAPABILITIES:
        return lxcDomainAttachDeviceHostdevCapsLive(driver, vm, dev);

4505 4506 4507 4508 4509 4510 4511 4512 4513
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device mode %s"),
                       virDomainHostdevModeTypeToString(dev->data.hostdev->mode));
        return -1;
    }
}


4514 4515 4516 4517
static int
lxcDomainAttachDeviceLive(virConnectPtr conn,
                          virLXCDriverPtr driver,
                          virDomainObjPtr vm,
4518 4519 4520 4521 4522
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
4523 4524 4525 4526 4527 4528
    case VIR_DOMAIN_DEVICE_DISK:
        ret = lxcDomainAttachDeviceDiskLive(driver, vm, dev);
        if (!ret)
            dev->data.disk = NULL;
        break;

4529 4530 4531 4532 4533 4534 4535
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainAttachDeviceNetLive(conn, vm,
                                           dev->data.net);
        if (!ret)
            dev->data.net = NULL;
        break;

4536 4537 4538 4539 4540 4541
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        ret = lxcDomainAttachDeviceHostdevLive(driver, vm, dev);
        if (!ret)
            dev->data.disk = NULL;
        break;

4542 4543 4544 4545 4546 4547 4548 4549 4550 4551 4552
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be attached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


4553
static int
4554
lxcDomainDetachDeviceDiskLive(virDomainObjPtr vm,
4555 4556 4557 4558
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = NULL;
4559
    int idx, ret = -1;
J
John Ferlan 已提交
4560
    char *dst = NULL;
4561
    const char *src;
4562 4563 4564 4565 4566 4567 4568

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4569 4570 4571
    if ((idx = virDomainDiskIndexByName(vm->def,
                                        dev->data.disk->dst,
                                        false)) < 0) {
4572 4573 4574 4575 4576
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
        goto cleanup;
    }

4577
    def = vm->def->disks[idx];
4578
    src = virDomainDiskGetSource(def);
4579

4580
    if (virAsprintf(&dst, "/dev/%s", def->dst) < 0)
4581 4582
        goto cleanup;

4583
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4584 4585 4586 4587 4588
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4589
    if (lxcDomainAttachDeviceUnlink(vm, dst) < 0) {
4590
        virDomainAuditDisk(vm, src, NULL, "detach", false);
4591 4592
        goto cleanup;
    }
4593
    virDomainAuditDisk(vm, src, NULL, "detach", true);
4594

4595
    if (virCgroupDenyDevicePath(priv->cgroup, src, VIR_CGROUP_DEVICE_RWM) != 0)
4596
        VIR_WARN("cannot deny device %s for domain %s",
4597
                 src, vm->def->name);
4598

4599
    virDomainDiskRemove(vm->def, idx);
4600 4601 4602 4603
    virDomainDiskDefFree(def);

    ret = 0;

4604
 cleanup:
4605 4606 4607 4608 4609
    VIR_FREE(dst);
    return ret;
}


4610
static int
4611 4612 4613 4614 4615 4616 4617
lxcDomainDetachDeviceNetLive(virDomainObjPtr vm,
                             virDomainDeviceDefPtr dev)
{
    int detachidx, ret = -1;
    virDomainNetDefPtr detach = NULL;
    virNetDevVPortProfilePtr vport = NULL;

4618
    if ((detachidx = virDomainNetFindIdx(vm->def, dev->data.net)) < 0)
4619
        goto cleanup;
4620

4621 4622 4623 4624 4625 4626 4627 4628 4629 4630 4631 4632 4633 4634 4635 4636 4637 4638 4639 4640 4641 4642 4643 4644 4645 4646 4647 4648 4649 4650 4651 4652 4653 4654 4655
    detach = vm->def->nets[detachidx];

    switch (virDomainNetGetActualType(detach)) {
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
    case VIR_DOMAIN_NET_TYPE_NETWORK:
        if (virNetDevVethDelete(detach->ifname) < 0) {
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
        break;

        /* It'd be nice to support this, but with macvlan
         * once assigned to a container nothing exists on
         * the host side. Further the container can change
         * the mac address of NIC name, so we can't easily
         * find out which guest NIC it maps to
    case VIR_DOMAIN_NET_TYPE_DIRECT:
        */

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Only bridged veth devices can be detached"));
        goto cleanup;
    }

    virDomainAuditNet(vm, detach, NULL, "detach", true);

    virDomainConfNWFilterTeardown(detach);

    vport = virDomainNetGetActualVirtPortProfile(detach);
    if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
        ignore_value(virNetDevOpenvswitchRemovePort(
                        virDomainNetGetActualBridgeName(detach),
                        detach->ifname));
    ret = 0;
4656
 cleanup:
4657
    if (!ret) {
4658
        networkReleaseActualDevice(vm->def, detach);
4659 4660 4661 4662 4663 4664 4665
        virDomainNetRemove(vm->def, detachidx);
        virDomainNetDefFree(detach);
    }
    return ret;
}


4666 4667 4668 4669 4670 4671 4672 4673
static int
lxcDomainDetachDeviceHostdevUSBLive(virLXCDriverPtr driver,
                                    virDomainObjPtr vm,
                                    virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
    int idx, ret = -1;
J
John Ferlan 已提交
4674
    char *dst = NULL;
4675
    virUSBDevicePtr usb = NULL;
4676
    virHostdevManagerPtr hostdev_mgr = driver->hostdevMgr;
4677 4678 4679 4680 4681 4682 4683 4684 4685

    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("usb device not found"));
        goto cleanup;
    }

4686
    if (virAsprintf(&dst, "/dev/bus/usb/%03d/%03d",
4687
                    def->source.subsys.u.usb.bus,
4688
                    def->source.subsys.u.usb.device) < 0)
4689 4690
        goto cleanup;

4691
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4692 4693 4694 4695 4696
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4697
    if (!(usb = virUSBDeviceNew(def->source.subsys.u.usb.bus,
4698
                                def->source.subsys.u.usb.device, NULL)))
4699 4700
        goto cleanup;

4701
    if (lxcDomainAttachDeviceUnlink(vm, dst) < 0) {
4702 4703 4704 4705 4706
        virDomainAuditHostdev(vm, def, "detach", false);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4707
    if (virUSBDeviceFileIterate(usb,
4708
                                virLXCTeardownHostUSBDeviceCgroup,
4709
                                priv->cgroup) < 0)
4710 4711 4712
        VIR_WARN("cannot deny device %s for domain %s",
                 dst, vm->def->name);

4713 4714 4715
    virObjectLock(hostdev_mgr->activeUSBHostdevs);
    virUSBDeviceListDel(hostdev_mgr->activeUSBHostdevs, usb);
    virObjectUnlock(hostdev_mgr->activeUSBHostdevs);
4716 4717 4718 4719 4720 4721

    virDomainHostdevRemove(vm->def, idx);
    virDomainHostdevDefFree(def);

    ret = 0;

4722
 cleanup:
4723
    virUSBDeviceFree(usb);
4724 4725 4726 4727
    VIR_FREE(dst);
    return ret;
}

4728 4729

static int
4730
lxcDomainDetachDeviceHostdevStorageLive(virDomainObjPtr vm,
4731 4732 4733 4734
                                        virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
4735
    int idx, ret = -1;
4736 4737 4738 4739 4740 4741 4742

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4743 4744 4745
    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
4746 4747 4748 4749 4750 4751
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("hostdev %s not found"),
                       dev->data.hostdev->source.caps.u.storage.block);
        goto cleanup;
    }

4752
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4753 4754 4755 4756 4757
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4758
    if (lxcDomainAttachDeviceUnlink(vm, def->source.caps.u.storage.block) < 0) {
4759 4760 4761 4762 4763
        virDomainAuditHostdev(vm, def, "detach", false);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4764
    if (virCgroupDenyDevicePath(priv->cgroup, def->source.caps.u.storage.block, VIR_CGROUP_DEVICE_RWM) != 0)
4765 4766 4767
        VIR_WARN("cannot deny device %s for domain %s",
                 def->source.caps.u.storage.block, vm->def->name);

4768
    virDomainHostdevRemove(vm->def, idx);
4769 4770 4771 4772
    virDomainHostdevDefFree(def);

    ret = 0;

4773
 cleanup:
4774 4775 4776 4777
    return ret;
}


4778
static int
4779
lxcDomainDetachDeviceHostdevMiscLive(virDomainObjPtr vm,
4780 4781 4782 4783
                                     virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
4784
    int idx, ret = -1;
4785 4786 4787 4788 4789 4790 4791

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4792 4793 4794
    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
4795 4796 4797 4798 4799 4800
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("hostdev %s not found"),
                       dev->data.hostdev->source.caps.u.misc.chardev);
        goto cleanup;
    }

4801
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4802 4803 4804 4805 4806
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4807
    if (lxcDomainAttachDeviceUnlink(vm, def->source.caps.u.misc.chardev) < 0) {
4808 4809 4810 4811 4812
        virDomainAuditHostdev(vm, def, "detach", false);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4813
    if (virCgroupDenyDevicePath(priv->cgroup, def->source.caps.u.misc.chardev, VIR_CGROUP_DEVICE_RWM) != 0)
4814 4815 4816
        VIR_WARN("cannot deny device %s for domain %s",
                 def->source.caps.u.misc.chardev, vm->def->name);

4817
    virDomainHostdevRemove(vm->def, idx);
4818 4819 4820 4821
    virDomainHostdevDefFree(def);

    ret = 0;

4822
 cleanup:
4823 4824 4825 4826
    return ret;
}


4827 4828 4829 4830 4831 4832 4833 4834 4835 4836 4837 4838 4839 4840 4841 4842 4843 4844
static int
lxcDomainDetachDeviceHostdevSubsysLive(virLXCDriverPtr driver,
                                       virDomainObjPtr vm,
                                       virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        return lxcDomainDetachDeviceHostdevUSBLive(driver, vm, dev);

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevSubsysTypeToString(dev->data.hostdev->source.subsys.type));
        return -1;
    }
}


4845
static int
4846 4847
lxcDomainDetachDeviceHostdevCapsLive(virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
4848 4849 4850
{
    switch (dev->data.hostdev->source.caps.type) {
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_STORAGE:
4851
        return lxcDomainDetachDeviceHostdevStorageLive(vm, dev);
4852

4853
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_MISC:
4854
        return lxcDomainDetachDeviceHostdevMiscLive(vm, dev);
4855

4856 4857 4858 4859 4860 4861 4862 4863 4864
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevCapsTypeToString(dev->data.hostdev->source.caps.type));
        return -1;
    }
}


4865 4866 4867 4868 4869 4870 4871 4872 4873 4874 4875 4876 4877 4878 4879 4880 4881
static int
lxcDomainDetachDeviceHostdevLive(virLXCDriverPtr driver,
                                 virDomainObjPtr vm,
                                 virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach hostdev until init PID is known"));
        return -1;
    }

    switch (dev->data.hostdev->mode) {
    case VIR_DOMAIN_HOSTDEV_MODE_SUBSYS:
        return lxcDomainDetachDeviceHostdevSubsysLive(driver, vm, dev);

4882
    case VIR_DOMAIN_HOSTDEV_MODE_CAPABILITIES:
4883
        return lxcDomainDetachDeviceHostdevCapsLive(vm, dev);
4884

4885 4886 4887 4888 4889 4890 4891 4892 4893
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device mode %s"),
                       virDomainHostdevModeTypeToString(dev->data.hostdev->mode));
        return -1;
    }
}


4894 4895 4896
static int
lxcDomainDetachDeviceLive(virLXCDriverPtr driver,
                          virDomainObjPtr vm,
4897 4898 4899 4900 4901
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
4902
    case VIR_DOMAIN_DEVICE_DISK:
4903
        ret = lxcDomainDetachDeviceDiskLive(vm, dev);
4904 4905
        break;

4906 4907 4908 4909
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainDetachDeviceNetLive(vm, dev);
        break;

4910 4911 4912 4913
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        ret = lxcDomainDetachDeviceHostdevLive(driver, vm, dev);
        break;

4914 4915 4916 4917 4918 4919 4920 4921 4922 4923 4924
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be detached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


4925 4926 4927
static int lxcDomainAttachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
4928 4929
{
    virLXCDriverPtr driver = dom->conn->privateData;
4930
    virCapsPtr caps = NULL;
4931 4932 4933 4934 4935
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
    unsigned int affect;
4936
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4937 4938

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
4939
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
4940 4941 4942

    affect = flags & (VIR_DOMAIN_AFFECT_LIVE | VIR_DOMAIN_AFFECT_CONFIG);

M
Michal Privoznik 已提交
4943
    if (!(vm = lxcDomObjFromDomain(dom)))
4944 4945
        goto cleanup;

4946 4947 4948
    if (virDomainAttachDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4949 4950 4951 4952 4953 4954 4955 4956 4957 4958 4959 4960 4961 4962 4963
    if (virDomainObjIsActive(vm)) {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_LIVE;
    } else {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_CONFIG;
        /* check consistency between flags and the vm state */
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("cannot do live update a device on "
                             "inactive domain"));
            goto cleanup;
        }
    }

4964 4965 4966
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

4967 4968 4969 4970 4971 4972
    if ((flags & VIR_DOMAIN_AFFECT_CONFIG) && !vm->persistent) {
         virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                        _("cannot modify device on transient domain"));
         goto cleanup;
    }

4973
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4974
                                             caps, driver->xmlopt,
4975 4976 4977 4978 4979 4980 4981 4982 4983 4984
                                             VIR_DOMAIN_XML_INACTIVE);
    if (dev == NULL)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
4985
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4986
                                          caps, driver->xmlopt);
4987 4988 4989 4990 4991 4992
        if (!dev_copy)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
4993
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4994 4995
        if (!vmdef)
            goto cleanup;
4996

4997 4998
        if (virDomainDefCompatibleDevice(vmdef, dev,
                                         VIR_DOMAIN_DEVICE_ACTION_ATTACH) < 0)
4999 5000
            goto cleanup;

5001
        if ((ret = lxcDomainAttachDeviceConfig(vmdef, dev)) < 0)
5002 5003 5004 5005
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
5006 5007
        if (virDomainDefCompatibleDevice(vm->def, dev_copy,
                                         VIR_DOMAIN_DEVICE_ACTION_ATTACH) < 0)
5008 5009
            goto cleanup;

5010
        if ((ret = lxcDomainAttachDeviceLive(dom->conn, driver, vm, dev_copy)) < 0)
5011 5012 5013 5014 5015 5016
            goto cleanup;
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
5017
        if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0) {
5018 5019 5020 5021 5022 5023 5024
            ret = -1;
            goto cleanup;
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
5025
        ret = virDomainSaveConfig(cfg->configDir, vmdef);
5026
        if (!ret) {
5027
            virDomainObjAssignDef(vm, vmdef, false, NULL);
5028 5029 5030 5031
            vmdef = NULL;
        }
    }

5032
 cleanup:
5033 5034 5035 5036 5037
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
    if (vm)
5038
        virObjectUnlock(vm);
5039
    virObjectUnref(caps);
5040
    virObjectUnref(cfg);
5041 5042 5043 5044 5045 5046 5047 5048 5049 5050 5051 5052 5053 5054 5055 5056
    return ret;
}


static int lxcDomainAttachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainAttachDeviceFlags(dom, xml,
                                       VIR_DOMAIN_AFFECT_LIVE);
}


static int lxcDomainUpdateDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
5057
    virLXCDriverPtr driver = dom->conn->privateData;
5058
    virCapsPtr caps = NULL;
5059 5060 5061 5062 5063
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
    unsigned int affect;
5064
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
5065 5066 5067 5068 5069 5070 5071

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_DOMAIN_DEVICE_MODIFY_FORCE, -1);

    affect = flags & (VIR_DOMAIN_AFFECT_LIVE | VIR_DOMAIN_AFFECT_CONFIG);

M
Michal Privoznik 已提交
5072
    if (!(vm = lxcDomObjFromDomain(dom)))
5073 5074
        goto cleanup;

5075 5076 5077
    if (virDomainUpdateDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

5078 5079 5080 5081 5082 5083 5084 5085 5086 5087 5088 5089 5090 5091 5092 5093 5094 5095 5096 5097 5098
    if (virDomainObjIsActive(vm)) {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_LIVE;
    } else {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_CONFIG;
        /* check consistency between flags and the vm state */
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("cannot do live update a device on "
                             "inactive domain"));
            goto cleanup;
        }
    }

    if ((flags & VIR_DOMAIN_AFFECT_CONFIG) && !vm->persistent) {
         virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                        _("cannot modify device on transient domain"));
         goto cleanup;
    }

5099 5100 5101
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

5102
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
5103
                                             caps, driver->xmlopt,
5104 5105 5106 5107 5108 5109 5110 5111 5112 5113 5114
                                             VIR_DOMAIN_XML_INACTIVE);
    if (dev == NULL)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
5115
                                          caps, driver->xmlopt);
5116 5117 5118 5119 5120 5121
        if (!dev_copy)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
5122
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
5123 5124
        if (!vmdef)
            goto cleanup;
5125

5126 5127
        if (virDomainDefCompatibleDevice(vmdef, dev,
                                         VIR_DOMAIN_DEVICE_ACTION_UPDATE) < 0)
5128 5129
            goto cleanup;

5130 5131 5132 5133 5134
        if ((ret = lxcDomainUpdateDeviceConfig(vmdef, dev)) < 0)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
5135 5136
        if (virDomainDefCompatibleDevice(vm->def, dev_copy,
                                         VIR_DOMAIN_DEVICE_ACTION_UPDATE) < 0)
5137 5138 5139 5140 5141 5142 5143 5144 5145 5146
            goto cleanup;

        virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                       _("Unable to modify live devices"));

        goto cleanup;
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
5147
        ret = virDomainSaveConfig(cfg->configDir, vmdef);
5148 5149 5150 5151 5152 5153
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false, NULL);
            vmdef = NULL;
        }
    }

5154
 cleanup:
5155 5156 5157 5158 5159 5160
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
    if (vm)
        virObjectUnlock(vm);
5161
    virObjectUnref(caps);
5162
    virObjectUnref(cfg);
5163
    return ret;
5164 5165 5166 5167 5168 5169 5170
}


static int lxcDomainDetachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
5171
    virLXCDriverPtr driver = dom->conn->privateData;
5172
    virCapsPtr caps = NULL;
5173 5174 5175 5176 5177
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
    unsigned int affect;
5178
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
5179 5180 5181 5182 5183 5184

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

    affect = flags & (VIR_DOMAIN_AFFECT_LIVE | VIR_DOMAIN_AFFECT_CONFIG);

M
Michal Privoznik 已提交
5185
    if (!(vm = lxcDomObjFromDomain(dom)))
5186 5187
        goto cleanup;

5188 5189 5190
    if (virDomainDetachDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

5191 5192 5193 5194 5195 5196 5197 5198 5199 5200 5201 5202 5203 5204 5205 5206 5207 5208 5209 5210 5211
    if (virDomainObjIsActive(vm)) {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_LIVE;
    } else {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_CONFIG;
        /* check consistency between flags and the vm state */
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("cannot do live update a device on "
                             "inactive domain"));
            goto cleanup;
        }
    }

    if ((flags & VIR_DOMAIN_AFFECT_CONFIG) && !vm->persistent) {
         virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                        _("cannot modify device on transient domain"));
         goto cleanup;
    }

5212 5213 5214
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

5215
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
5216
                                             caps, driver->xmlopt,
5217 5218 5219 5220 5221 5222 5223 5224 5225 5226 5227
                                             VIR_DOMAIN_XML_INACTIVE);
    if (dev == NULL)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
5228
                                          caps, driver->xmlopt);
5229 5230 5231 5232 5233 5234
        if (!dev_copy)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
5235
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
5236 5237 5238
        if (!vmdef)
            goto cleanup;

5239 5240
        if (virDomainDefCompatibleDevice(vmdef, dev,
                                         VIR_DOMAIN_DEVICE_ACTION_DETACH) < 0)
5241 5242
            goto cleanup;

5243 5244 5245 5246 5247
        if ((ret = lxcDomainDetachDeviceConfig(vmdef, dev)) < 0)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
5248 5249
        if (virDomainDefCompatibleDevice(vm->def, dev_copy,
                                         VIR_DOMAIN_DEVICE_ACTION_DETACH) < 0)
5250 5251 5252 5253 5254 5255 5256 5257 5258
            goto cleanup;

        if ((ret = lxcDomainDetachDeviceLive(driver, vm, dev_copy)) < 0)
            goto cleanup;
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
5259
        if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0) {
5260 5261 5262 5263 5264 5265 5266
            ret = -1;
            goto cleanup;
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
5267
        ret = virDomainSaveConfig(cfg->configDir, vmdef);
5268 5269 5270 5271 5272 5273
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false, NULL);
            vmdef = NULL;
        }
    }

5274
 cleanup:
5275 5276 5277 5278 5279 5280
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
    if (vm)
        virObjectUnlock(vm);
5281
    virObjectUnref(caps);
5282
    virObjectUnref(cfg);
5283
    return ret;
5284 5285 5286 5287 5288 5289 5290 5291 5292 5293 5294
}


static int lxcDomainDetachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainDetachDeviceFlags(dom, xml,
                                      VIR_DOMAIN_AFFECT_LIVE);
}


5295 5296 5297
static int lxcDomainLxcOpenNamespace(virDomainPtr dom,
                                     int **fdlist,
                                     unsigned int flags)
5298 5299 5300 5301 5302 5303 5304 5305 5306
{
    virDomainObjPtr vm;
    virLXCDomainObjPrivatePtr priv;
    int ret = -1;
    size_t nfds = 0;

    *fdlist = NULL;
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
5307
    if (!(vm = lxcDomObjFromDomain(dom)))
5308
        goto cleanup;
M
Michal Privoznik 已提交
5309

5310 5311
    priv = vm->privateData;

5312 5313 5314
    if (virDomainLxcOpenNamespaceEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

5315 5316 5317 5318 5319 5320 5321 5322 5323 5324 5325 5326 5327 5328 5329 5330
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
        goto cleanup;
    }

    if (virProcessGetNamespaces(priv->initpid, &nfds, fdlist) < 0)
        goto cleanup;

    ret = nfds;
5331
 cleanup:
5332 5333
    if (vm)
        virObjectUnlock(vm);
5334 5335 5336 5337
    return ret;
}


5338
static char *
5339
lxcConnectGetSysinfo(virConnectPtr conn, unsigned int flags)
5340 5341 5342 5343 5344 5345
{
    virLXCDriverPtr driver = conn->privateData;
    virBuffer buf = VIR_BUFFER_INITIALIZER;

    virCheckFlags(0, NULL);

5346 5347 5348
    if (virConnectGetSysinfoEnsureACL(conn) < 0)
        return NULL;

5349 5350 5351 5352 5353 5354 5355 5356
    if (!driver->hostsysinfo) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Host SMBIOS information is not available"));
        return NULL;
    }

    if (virSysinfoFormat(&buf, driver->hostsysinfo) < 0)
        return NULL;
5357
    if (virBufferCheckError(&buf) < 0)
5358 5359 5360 5361 5362
        return NULL;
    return virBufferContentAndReset(&buf);
}


5363
static int
5364
lxcNodeGetInfo(virConnectPtr conn,
5365 5366
               virNodeInfoPtr nodeinfo)
{
5367 5368 5369
    if (virNodeGetInfoEnsureACL(conn) < 0)
        return -1;

5370 5371 5372 5373
    return nodeGetInfo(nodeinfo);
}


5374 5375 5376 5377 5378 5379 5380 5381 5382 5383 5384 5385 5386 5387 5388 5389 5390 5391 5392 5393 5394 5395
static int
lxcDomainMemoryStats(virDomainPtr dom,
                     struct _virDomainMemoryStat *stats,
                     unsigned int nr_stats,
                     unsigned int flags)
{
    virDomainObjPtr vm;
    int ret = -1;
    virLXCDomainObjPrivatePtr priv;
    unsigned long long swap_usage;
    unsigned long mem_usage;

    virCheckFlags(0, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        goto cleanup;

    priv = vm->privateData;

    if (virDomainMemoryStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

5396 5397 5398
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("domain is not active"));
5399
        goto cleanup;
5400
    }
5401

5402
    if (virCgroupGetMemSwapUsage(priv->cgroup, &swap_usage) < 0)
5403 5404
        goto cleanup;

5405
    if (virCgroupGetMemoryUsage(priv->cgroup, &mem_usage) < 0)
5406 5407 5408 5409 5410 5411 5412 5413 5414 5415 5416 5417 5418 5419 5420 5421 5422 5423 5424
        goto cleanup;

    ret = 0;
    if (ret < nr_stats) {
        stats[ret].tag = VIR_DOMAIN_MEMORY_STAT_ACTUAL_BALLOON;
        stats[ret].val = vm->def->mem.cur_balloon;
        ret++;
    }
    if (ret < nr_stats) {
        stats[ret].tag = VIR_DOMAIN_MEMORY_STAT_SWAP_IN;
        stats[ret].val = swap_usage;
        ret++;
    }
    if (ret < nr_stats) {
        stats[ret].tag = VIR_DOMAIN_MEMORY_STAT_RSS;
        stats[ret].val = mem_usage;
        ret++;
    }

5425
 cleanup:
5426 5427 5428 5429 5430 5431
    if (vm)
        virObjectUnlock(vm);
    return ret;
}


5432
static int
5433
lxcNodeGetCPUStats(virConnectPtr conn,
5434 5435 5436 5437 5438
                   int cpuNum,
                   virNodeCPUStatsPtr params,
                   int *nparams,
                   unsigned int flags)
{
5439 5440 5441
    if (virNodeGetCPUStatsEnsureACL(conn) < 0)
        return -1;

5442 5443 5444 5445 5446
    return nodeGetCPUStats(cpuNum, params, nparams, flags);
}


static int
5447
lxcNodeGetMemoryStats(virConnectPtr conn,
5448 5449 5450 5451 5452
                      int cellNum,
                      virNodeMemoryStatsPtr params,
                      int *nparams,
                      unsigned int flags)
{
5453 5454 5455
    if (virNodeGetMemoryStatsEnsureACL(conn) < 0)
        return -1;

5456 5457 5458 5459 5460
    return nodeGetMemoryStats(cellNum, params, nparams, flags);
}


static int
5461
lxcNodeGetCellsFreeMemory(virConnectPtr conn,
5462 5463 5464 5465
                          unsigned long long *freeMems,
                          int startCell,
                          int maxCells)
{
5466 5467 5468
    if (virNodeGetCellsFreeMemoryEnsureACL(conn) < 0)
        return -1;

5469 5470 5471 5472 5473
    return nodeGetCellsFreeMemory(freeMems, startCell, maxCells);
}


static unsigned long long
5474
lxcNodeGetFreeMemory(virConnectPtr conn)
5475
{
5476 5477
    unsigned long long freeMem;

5478 5479 5480
    if (virNodeGetFreeMemoryEnsureACL(conn) < 0)
        return 0;

5481 5482 5483 5484
    if (nodeGetMemory(NULL, &freeMem) < 0)
        return 0;

    return freeMem;
5485 5486 5487 5488
}


static int
5489
lxcNodeGetMemoryParameters(virConnectPtr conn,
5490 5491 5492 5493
                           virTypedParameterPtr params,
                           int *nparams,
                           unsigned int flags)
{
5494 5495 5496
    if (virNodeGetMemoryParametersEnsureACL(conn) < 0)
        return -1;

5497 5498 5499 5500 5501
    return nodeGetMemoryParameters(params, nparams, flags);
}


static int
5502
lxcNodeSetMemoryParameters(virConnectPtr conn,
5503 5504 5505 5506
                           virTypedParameterPtr params,
                           int nparams,
                           unsigned int flags)
{
5507 5508 5509
    if (virNodeSetMemoryParametersEnsureACL(conn) < 0)
        return -1;

5510 5511 5512 5513 5514
    return nodeSetMemoryParameters(params, nparams, flags);
}


static int
5515
lxcNodeGetCPUMap(virConnectPtr conn,
5516 5517 5518 5519
                 unsigned char **cpumap,
                 unsigned int *online,
                 unsigned int flags)
{
5520 5521 5522
    if (virNodeGetCPUMapEnsureACL(conn) < 0)
        return -1;

5523 5524 5525
    return nodeGetCPUMap(cpumap, online, flags);
}

5526 5527

static int
5528
lxcNodeSuspendForDuration(virConnectPtr conn,
5529 5530 5531 5532
                          unsigned int target,
                          unsigned long long duration,
                          unsigned int flags)
{
5533 5534 5535
    if (virNodeSuspendForDurationEnsureACL(conn) < 0)
        return -1;

5536 5537 5538 5539
    return nodeSuspendForDuration(target, duration, flags);
}


5540 5541 5542 5543 5544 5545 5546 5547 5548 5549 5550 5551 5552 5553 5554 5555 5556 5557 5558 5559 5560 5561 5562 5563 5564 5565 5566 5567 5568 5569 5570
static int
lxcDomainSetMetadata(virDomainPtr dom,
                      int type,
                      const char *metadata,
                      const char *key,
                      const char *uri,
                      unsigned int flags)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virDomainObjPtr vm;
    virLXCDriverConfigPtr cfg = NULL;
    virCapsPtr caps = NULL;
    int ret = -1;

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        return -1;

    cfg = virLXCDriverGetConfig(driver);

    if (virDomainSetMetadataEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    ret = virDomainObjSetMetadata(vm, type, metadata, key, uri, caps,
                                  driver->xmlopt, cfg->configDir, flags);

5571
 cleanup:
5572 5573 5574 5575 5576 5577 5578 5579 5580 5581 5582 5583 5584 5585 5586 5587 5588 5589 5590 5591 5592 5593 5594 5595 5596 5597 5598 5599 5600
    virObjectUnlock(vm);
    virObjectUnref(caps);
    virObjectUnref(cfg);
    return ret;
}


static char *
lxcDomainGetMetadata(virDomainPtr dom,
                      int type,
                      const char *uri,
                      unsigned int flags)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virCapsPtr caps = NULL;
    virDomainObjPtr vm;
    char *ret = NULL;

    if (!(vm = lxcDomObjFromDomain(dom)))
        return NULL;

    if (virDomainGetMetadataEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    ret = virDomainObjGetMetadata(vm, type, uri, caps, driver->xmlopt, flags);

5601
 cleanup:
5602 5603 5604 5605 5606 5607
    virObjectUnlock(vm);
    virObjectUnref(caps);
    return ret;
}


5608 5609 5610 5611 5612 5613 5614 5615 5616 5617 5618 5619 5620 5621 5622 5623 5624 5625 5626 5627 5628 5629 5630 5631 5632 5633 5634 5635 5636 5637 5638 5639 5640 5641 5642 5643 5644 5645 5646
static int
lxcDomainGetCPUStats(virDomainPtr dom,
                     virTypedParameterPtr params,
                     unsigned int nparams,
                     int start_cpu,
                     unsigned int ncpus,
                     unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    int ret = -1;
    virLXCDomainObjPrivatePtr priv;

    virCheckFlags(VIR_TYPED_PARAM_STRING_OKAY, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    priv = vm->privateData;

    if (virDomainGetCPUStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("domain is not running"));
        goto cleanup;
    }

    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPUACCT)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPUACCT controller is not mounted"));
        goto cleanup;
    }

    if (start_cpu == -1)
        ret = virCgroupGetDomainTotalCpuStats(priv->cgroup,
                                              params, nparams);
    else
        ret = virCgroupGetPercpuStats(priv->cgroup, params,
5647
                                      nparams, start_cpu, ncpus, 0);
5648
 cleanup:
5649 5650 5651 5652 5653 5654
    if (vm)
        virObjectUnlock(vm);
    return ret;
}


5655 5656 5657 5658 5659 5660 5661 5662 5663 5664 5665 5666 5667 5668 5669 5670 5671 5672
static int
lxcNodeGetFreePages(virConnectPtr conn,
                    unsigned int npages,
                    unsigned int *pages,
                    int startCell,
                    unsigned int cellCount,
                    unsigned long long *counts,
                    unsigned int flags)
{
    virCheckFlags(0, -1);

    if (virNodeGetFreePagesEnsureACL(conn) < 0)
        return -1;

    return nodeGetFreePages(npages, pages, startCell, cellCount, counts);
}


D
Daniel Veillard 已提交
5673 5674
/* Function Tables */
static virDriver lxcDriver = {
5675
    .no = VIR_DRV_LXC,
5676
    .name = LXC_DRIVER_NAME,
5677 5678
    .connectOpen = lxcConnectOpen, /* 0.4.2 */
    .connectClose = lxcConnectClose, /* 0.4.2 */
5679
    .connectSupportsFeature = lxcConnectSupportsFeature, /* 1.2.2 */
5680
    .connectGetVersion = lxcConnectGetVersion, /* 0.4.6 */
5681
    .connectGetHostname = lxcConnectGetHostname, /* 0.6.3 */
5682
    .connectGetSysinfo = lxcConnectGetSysinfo, /* 1.0.5 */
5683
    .nodeGetInfo = lxcNodeGetInfo, /* 0.6.5 */
5684 5685 5686 5687 5688
    .connectGetCapabilities = lxcConnectGetCapabilities, /* 0.6.5 */
    .connectListDomains = lxcConnectListDomains, /* 0.4.2 */
    .connectNumOfDomains = lxcConnectNumOfDomains, /* 0.4.2 */
    .connectListAllDomains = lxcConnectListAllDomains, /* 0.9.13 */
    .domainCreateXML = lxcDomainCreateXML, /* 0.4.4 */
5689
    .domainCreateXMLWithFiles = lxcDomainCreateXMLWithFiles, /* 1.1.1 */
5690 5691 5692 5693 5694 5695
    .domainLookupByID = lxcDomainLookupByID, /* 0.4.2 */
    .domainLookupByUUID = lxcDomainLookupByUUID, /* 0.4.2 */
    .domainLookupByName = lxcDomainLookupByName, /* 0.4.2 */
    .domainSuspend = lxcDomainSuspend, /* 0.7.2 */
    .domainResume = lxcDomainResume, /* 0.7.2 */
    .domainDestroy = lxcDomainDestroy, /* 0.4.4 */
5696
    .domainDestroyFlags = lxcDomainDestroyFlags, /* 0.9.4 */
5697
    .domainGetOSType = lxcDomainGetOSType, /* 0.4.2 */
5698 5699 5700 5701 5702
    .domainGetMaxMemory = lxcDomainGetMaxMemory, /* 0.7.2 */
    .domainSetMaxMemory = lxcDomainSetMaxMemory, /* 0.7.2 */
    .domainSetMemory = lxcDomainSetMemory, /* 0.7.2 */
    .domainSetMemoryParameters = lxcDomainSetMemoryParameters, /* 0.8.5 */
    .domainGetMemoryParameters = lxcDomainGetMemoryParameters, /* 0.8.5 */
5703 5704
    .domainSetBlkioParameters = lxcDomainSetBlkioParameters, /* 0.9.8 */
    .domainGetBlkioParameters = lxcDomainGetBlkioParameters, /* 0.9.8 */
5705 5706
    .domainGetInfo = lxcDomainGetInfo, /* 0.4.2 */
    .domainGetState = lxcDomainGetState, /* 0.9.2 */
5707 5708
    .domainGetSecurityLabel = lxcDomainGetSecurityLabel, /* 0.9.10 */
    .nodeGetSecurityModel = lxcNodeGetSecurityModel, /* 0.9.10 */
5709
    .domainGetXMLDesc = lxcDomainGetXMLDesc, /* 0.4.2 */
5710
    .connectDomainXMLFromNative = lxcConnectDomainXMLFromNative, /* 1.2.2 */
5711 5712 5713 5714
    .connectListDefinedDomains = lxcConnectListDefinedDomains, /* 0.4.2 */
    .connectNumOfDefinedDomains = lxcConnectNumOfDefinedDomains, /* 0.4.2 */
    .domainCreate = lxcDomainCreate, /* 0.4.4 */
    .domainCreateWithFlags = lxcDomainCreateWithFlags, /* 0.8.2 */
5715
    .domainCreateWithFiles = lxcDomainCreateWithFiles, /* 1.1.1 */
5716
    .domainDefineXML = lxcDomainDefineXML, /* 0.4.2 */
5717
    .domainUndefine = lxcDomainUndefine, /* 0.4.2 */
5718
    .domainUndefineFlags = lxcDomainUndefineFlags, /* 0.9.4 */
5719 5720 5721 5722 5723
    .domainAttachDevice = lxcDomainAttachDevice, /* 1.0.1 */
    .domainAttachDeviceFlags = lxcDomainAttachDeviceFlags, /* 1.0.1 */
    .domainDetachDevice = lxcDomainDetachDevice, /* 1.0.1 */
    .domainDetachDeviceFlags = lxcDomainDetachDeviceFlags, /* 1.0.1 */
    .domainUpdateDeviceFlags = lxcDomainUpdateDeviceFlags, /* 1.0.1 */
5724 5725
    .domainGetAutostart = lxcDomainGetAutostart, /* 0.7.0 */
    .domainSetAutostart = lxcDomainSetAutostart, /* 0.7.0 */
5726 5727 5728 5729 5730
    .domainGetSchedulerType = lxcDomainGetSchedulerType, /* 0.5.0 */
    .domainGetSchedulerParameters = lxcDomainGetSchedulerParameters, /* 0.5.0 */
    .domainGetSchedulerParametersFlags = lxcDomainGetSchedulerParametersFlags, /* 0.9.2 */
    .domainSetSchedulerParameters = lxcDomainSetSchedulerParameters, /* 0.5.0 */
    .domainSetSchedulerParametersFlags = lxcDomainSetSchedulerParametersFlags, /* 0.9.2 */
5731 5732
    .domainBlockStats = lxcDomainBlockStats, /* 1.2.2 */
    .domainBlockStatsFlags = lxcDomainBlockStatsFlags, /* 1.2.2 */
5733
    .domainInterfaceStats = lxcDomainInterfaceStats, /* 0.7.3 */
5734
    .domainMemoryStats = lxcDomainMemoryStats, /* 1.2.2 */
5735 5736 5737 5738 5739
    .nodeGetCPUStats = lxcNodeGetCPUStats, /* 0.9.3 */
    .nodeGetMemoryStats = lxcNodeGetMemoryStats, /* 0.9.3 */
    .nodeGetCellsFreeMemory = lxcNodeGetCellsFreeMemory, /* 0.6.5 */
    .nodeGetFreeMemory = lxcNodeGetFreeMemory, /* 0.6.5 */
    .nodeGetCPUMap = lxcNodeGetCPUMap, /* 1.0.0 */
5740 5741 5742 5743
    .connectDomainEventRegister = lxcConnectDomainEventRegister, /* 0.7.0 */
    .connectDomainEventDeregister = lxcConnectDomainEventDeregister, /* 0.7.0 */
    .connectIsEncrypted = lxcConnectIsEncrypted, /* 0.7.3 */
    .connectIsSecure = lxcConnectIsSecure, /* 0.7.3 */
5744 5745 5746
    .domainIsActive = lxcDomainIsActive, /* 0.7.3 */
    .domainIsPersistent = lxcDomainIsPersistent, /* 0.7.3 */
    .domainIsUpdated = lxcDomainIsUpdated, /* 0.8.6 */
5747 5748
    .connectDomainEventRegisterAny = lxcConnectDomainEventRegisterAny, /* 0.8.0 */
    .connectDomainEventDeregisterAny = lxcConnectDomainEventDeregisterAny, /* 0.8.0 */
5749
    .domainOpenConsole = lxcDomainOpenConsole, /* 0.8.6 */
5750
    .connectIsAlive = lxcConnectIsAlive, /* 0.9.8 */
5751
    .nodeSuspendForDuration = lxcNodeSuspendForDuration, /* 0.9.8 */
5752 5753
    .domainSetMetadata = lxcDomainSetMetadata, /* 1.1.3 */
    .domainGetMetadata = lxcDomainGetMetadata, /* 1.1.3 */
5754
    .domainGetCPUStats = lxcDomainGetCPUStats, /* 1.2.2 */
5755 5756
    .nodeGetMemoryParameters = lxcNodeGetMemoryParameters, /* 0.10.2 */
    .nodeSetMemoryParameters = lxcNodeSetMemoryParameters, /* 0.10.2 */
5757
    .domainSendProcessSignal = lxcDomainSendProcessSignal, /* 1.0.1 */
5758 5759 5760
    .domainShutdown = lxcDomainShutdown, /* 1.0.1 */
    .domainShutdownFlags = lxcDomainShutdownFlags, /* 1.0.1 */
    .domainReboot = lxcDomainReboot, /* 1.0.1 */
5761
    .domainLxcOpenNamespace = lxcDomainLxcOpenNamespace, /* 1.0.2 */
5762
    .nodeGetFreePages = lxcNodeGetFreePages, /* 1.2.6 */
D
Daniel Veillard 已提交
5763 5764
};

5765
static virStateDriver lxcStateDriver = {
5766
    .name = LXC_DRIVER_NAME,
5767
    .stateInitialize = lxcStateInitialize,
5768
    .stateAutoStart = lxcStateAutoStart,
5769 5770
    .stateCleanup = lxcStateCleanup,
    .stateReload = lxcStateReload,
5771 5772
};

D
Daniel Veillard 已提交
5773 5774
int lxcRegister(void)
{
5775 5776 5777 5778
    if (virRegisterDriver(&lxcDriver) < 0)
        return -1;
    if (virRegisterStateDriver(&lxcStateDriver) < 0)
        return -1;
D
Daniel Veillard 已提交
5779 5780
    return 0;
}