lxc_driver.c 165.0 KB
Newer Older
D
Daniel Veillard 已提交
1
/*
2
 * Copyright (C) 2010-2016 Red Hat, Inc.
D
Daniel Veillard 已提交
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
 * Copyright IBM Corp. 2008
 *
 * lxc_driver.c: linux container driver functions
 *
 * Authors:
 *  David L. Leskovec <dlesko at linux.vnet.ibm.com>
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
21
 * License along with this library.  If not, see
O
Osier Yang 已提交
22
 * <http://www.gnu.org/licenses/>.
D
Daniel Veillard 已提交
23 24 25 26
 */

#include <config.h>

27
#include <fcntl.h>
D
Daniel Veillard 已提交
28 29 30
#include <sched.h>
#include <sys/utsname.h>
#include <string.h>
31 32 33 34 35 36 37

#ifdef MAJOR_IN_MKDEV
# include <sys/mkdev.h>
#elif MAJOR_IN_SYSMACROS
# include <sys/sysmacros.h>
#endif

38
#include <sys/types.h>
39
#include <sys/socket.h>
40
#include <sys/stat.h>
41 42
#include <sys/un.h>
#include <sys/poll.h>
D
Daniel Veillard 已提交
43 44 45
#include <unistd.h>
#include <wait.h>

46
#include "virerror.h"
47
#include "virlog.h"
48
#include "datatypes.h"
49
#include "lxc_cgroup.h"
D
Daniel Veillard 已提交
50
#include "lxc_conf.h"
51
#include "lxc_container.h"
52
#include "lxc_domain.h"
D
Daniel Veillard 已提交
53
#include "lxc_driver.h"
54
#include "lxc_native.h"
55
#include "lxc_process.h"
56
#include "viralloc.h"
57
#include "virnetdevbridge.h"
58
#include "virnetdevveth.h"
59
#include "virnetdevopenvswitch.h"
60
#include "virhostcpu.h"
61
#include "virhostmem.h"
62
#include "viruuid.h"
63
#include "virhook.h"
E
Eric Blake 已提交
64
#include "virfile.h"
65
#include "virpidfile.h"
66
#include "virfdstream.h"
67
#include "domain_audit.h"
68
#include "domain_nwfilter.h"
69
#include "nwfilter_conf.h"
70
#include "virinitctl.h"
71
#include "virnetdev.h"
A
Ansis Atteka 已提交
72
#include "virnetdevtap.h"
73
#include "virnodesuspend.h"
74
#include "virprocess.h"
75
#include "virtime.h"
76
#include "virtypedparam.h"
M
Martin Kletzander 已提交
77
#include "viruri.h"
78
#include "virstring.h"
79 80
#include "viraccessapicheck.h"
#include "viraccessapichecklxc.h"
81
#include "virhostdev.h"
82
#include "netdev_bandwidth_conf.h"
D
Daniel Veillard 已提交
83

84 85
#define VIR_FROM_THIS VIR_FROM_LXC

86
VIR_LOG_INIT("lxc.lxc_driver");
87

88
#define LXC_NB_MEM_PARAM  3
89
#define LXC_NB_DOMAIN_BLOCK_STAT_PARAM 4
90

91

92 93 94 95
static int lxcStateInitialize(bool privileged,
                              virStateInhibitCallback callback,
                              void *opaque);
static int lxcStateCleanup(void);
96
virLXCDriverPtr lxc_driver = NULL;
D
Daniel Veillard 已提交
97

98 99
/* callbacks for nwfilter */
static int
100
lxcVMFilterRebuild(virDomainObjListIterator iter, void *data)
101
{
102
    return virDomainObjListForEach(lxc_driver->domains, iter, data);
103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123
}

static void
lxcVMDriverLock(void)
{
    lxcDriverLock(lxc_driver);
}

static void
lxcVMDriverUnlock(void)
{
    lxcDriverUnlock(lxc_driver);
}

static virNWFilterCallbackDriver lxcCallbackDriver = {
    .name = "LXC",
    .vmFilterRebuild = lxcVMFilterRebuild,
    .vmDriverLock = lxcVMDriverLock,
    .vmDriverUnlock = lxcVMDriverUnlock,
};

M
Michal Privoznik 已提交
124 125 126 127
/**
 * lxcDomObjFromDomain:
 * @domain: Domain pointer that has to be looked up
 *
128 129
 * This function looks up @domain and returns the appropriate virDomainObjPtr
 * that has to be released by calling virDomainObjEndAPI.
M
Michal Privoznik 已提交
130
 *
131 132
 * Returns the domain object with incremented reference counter which is locked
 * on success, NULL otherwise.
M
Michal Privoznik 已提交
133 134 135 136 137 138 139 140
 */
static virDomainObjPtr
lxcDomObjFromDomain(virDomainPtr domain)
{
    virDomainObjPtr vm;
    virLXCDriverPtr driver = domain->conn->privateData;
    char uuidstr[VIR_UUID_STRING_BUFLEN];

141
    vm = virDomainObjListFindByUUID(driver->domains, domain->uuid);
M
Michal Privoznik 已提交
142 143 144 145 146 147 148 149 150 151 152
    if (!vm) {
        virUUIDFormat(domain->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s' (%s)"),
                       uuidstr, domain->name);
        return NULL;
    }

    return vm;
}

D
Daniel Veillard 已提交
153 154
/* Functions */

155 156 157 158 159 160 161 162 163 164
static int
lxcConnectURIProbe(char **uri)
{
    if (lxc_driver == NULL)
        return 0;

    return VIR_STRDUP(*uri, "lxc:///system");
}


165 166
static virDrvOpenStatus lxcConnectOpen(virConnectPtr conn,
                                       virConnectAuthPtr auth ATTRIBUTE_UNUSED,
167
                                       virConfPtr conf ATTRIBUTE_UNUSED,
168
                                       unsigned int flags)
D
Daniel Veillard 已提交
169
{
E
Eric Blake 已提交
170 171
    virCheckFlags(VIR_CONNECT_RO, VIR_DRV_OPEN_ERROR);

172
    /* If path isn't '/' then they typoed, tell them correct path */
173
    if (STRNEQ(conn->uri->path, "/") &&
174 175 176 177 178 179 180 181 182 183 184 185
        STRNEQ(conn->uri->path, "/system")) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Unexpected LXC URI path '%s', try lxc:///system"),
                       conn->uri->path);
        return VIR_DRV_OPEN_ERROR;
    }

    /* URI was good, but driver isn't active */
    if (lxc_driver == NULL) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       "%s", _("lxc state driver is not active"));
        return VIR_DRV_OPEN_ERROR;
186
    }
187

188 189 190
    if (virConnectOpenEnsureACL(conn) < 0)
        return VIR_DRV_OPEN_ERROR;

191
    conn->privateData = lxc_driver;
D
Daniel Veillard 已提交
192 193 194 195

    return VIR_DRV_OPEN_SUCCESS;
}

196
static int lxcConnectClose(virConnectPtr conn)
D
Daniel Veillard 已提交
197
{
198
    virLXCDriverPtr driver = conn->privateData;
199

200
    virCloseCallbacksRun(driver->closeCallbacks, conn, driver->domains, driver);
201 202
    conn->privateData = NULL;
    return 0;
D
Daniel Veillard 已提交
203 204
}

205

206
static int lxcConnectIsSecure(virConnectPtr conn ATTRIBUTE_UNUSED)
207 208 209 210 211 212
{
    /* Trivially secure, since always inside the daemon */
    return 1;
}


213
static int lxcConnectIsEncrypted(virConnectPtr conn ATTRIBUTE_UNUSED)
214 215 216 217 218 219
{
    /* Not encrypted, but remote driver takes care of that */
    return 0;
}


220
static int lxcConnectIsAlive(virConnectPtr conn ATTRIBUTE_UNUSED)
221 222 223 224 225
{
    return 1;
}


226
static char *lxcConnectGetCapabilities(virConnectPtr conn) {
227
    virLXCDriverPtr driver = conn->privateData;
228
    virCapsPtr caps;
229 230
    char *xml;

231 232 233
    if (virConnectGetCapabilitiesEnsureACL(conn) < 0)
        return NULL;

234
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
235 236
        return NULL;

237
    xml = virCapabilitiesFormatXML(caps);
238

239
    virObjectUnref(caps);
240 241 242 243
    return xml;
}


D
Daniel Veillard 已提交
244 245 246
static virDomainPtr lxcDomainLookupByID(virConnectPtr conn,
                                        int id)
{
247
    virLXCDriverPtr driver = conn->privateData;
248 249
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
250

251
    vm = virDomainObjListFindByID(driver->domains, id);
252

D
Daniel Veillard 已提交
253
    if (!vm) {
254 255
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching id %d"), id);
256
        goto cleanup;
D
Daniel Veillard 已提交
257 258
    }

259 260 261
    if (virDomainLookupByIDEnsureACL(conn, vm->def) < 0)
        goto cleanup;

262
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid, vm->def->id);
D
Daniel Veillard 已提交
263

264
 cleanup:
265
    virDomainObjEndAPI(&vm);
D
Daniel Veillard 已提交
266 267 268 269 270 271
    return dom;
}

static virDomainPtr lxcDomainLookupByUUID(virConnectPtr conn,
                                          const unsigned char *uuid)
{
272
    virLXCDriverPtr driver = conn->privateData;
273 274
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
275

276
    vm = virDomainObjListFindByUUID(driver->domains, uuid);
277

D
Daniel Veillard 已提交
278
    if (!vm) {
279 280
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(uuid, uuidstr);
281 282
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
283
        goto cleanup;
D
Daniel Veillard 已提交
284 285
    }

286 287 288
    if (virDomainLookupByUUIDEnsureACL(conn, vm->def) < 0)
        goto cleanup;

289
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid, vm->def->id);
D
Daniel Veillard 已提交
290

291
 cleanup:
292
    virDomainObjEndAPI(&vm);
D
Daniel Veillard 已提交
293 294 295 296 297 298
    return dom;
}

static virDomainPtr lxcDomainLookupByName(virConnectPtr conn,
                                          const char *name)
{
299
    virLXCDriverPtr driver = conn->privateData;
300 301
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
302

303
    vm = virDomainObjListFindByName(driver->domains, name);
D
Daniel Veillard 已提交
304
    if (!vm) {
305 306
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching name '%s'"), name);
307
        goto cleanup;
D
Daniel Veillard 已提交
308 309
    }

310 311 312
    if (virDomainLookupByNameEnsureACL(conn, vm->def) < 0)
        goto cleanup;

313
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid, vm->def->id);
D
Daniel Veillard 已提交
314

315
 cleanup:
316
    virDomainObjEndAPI(&vm);
D
Daniel Veillard 已提交
317 318 319
    return dom;
}

320 321 322 323 324 325

static int lxcDomainIsActive(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
326
    if (!(obj = lxcDomObjFromDomain(dom)))
327
        goto cleanup;
328 329 330 331

    if (virDomainIsActiveEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

332 333
    ret = virDomainObjIsActive(obj);

334
 cleanup:
335
    virDomainObjEndAPI(&obj);
336 337 338 339 340 341 342 343 344
    return ret;
}


static int lxcDomainIsPersistent(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
345
    if (!(obj = lxcDomObjFromDomain(dom)))
346
        goto cleanup;
347 348 349 350

    if (virDomainIsPersistentEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

351 352
    ret = obj->persistent;

353
 cleanup:
354
    virDomainObjEndAPI(&obj);
355 356 357
    return ret;
}

358 359 360 361 362
static int lxcDomainIsUpdated(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
363
    if (!(obj = lxcDomObjFromDomain(dom)))
364
        goto cleanup;
365 366 367 368

    if (virDomainIsUpdatedEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

369 370
    ret = obj->updated;

371
 cleanup:
372
    virDomainObjEndAPI(&obj);
373 374
    return ret;
}
375

376 377
static int lxcConnectListDomains(virConnectPtr conn, int *ids, int nids)
{
378
    virLXCDriverPtr driver = conn->privateData;
379
    int n;
380

381 382 383
    if (virConnectListDomainsEnsureACL(conn) < 0)
        return -1;

384 385
    n = virDomainObjListGetActiveIDs(driver->domains, ids, nids,
                                     virConnectListDomainsCheckACL, conn);
386

387
    return n;
D
Daniel Veillard 已提交
388
}
389

390 391
static int lxcConnectNumOfDomains(virConnectPtr conn)
{
392
    virLXCDriverPtr driver = conn->privateData;
393
    int n;
394

395 396 397
    if (virConnectNumOfDomainsEnsureACL(conn) < 0)
        return -1;

398 399
    n = virDomainObjListNumOfDomains(driver->domains, true,
                                     virConnectNumOfDomainsCheckACL, conn);
400

401
    return n;
D
Daniel Veillard 已提交
402 403
}

404
static int lxcConnectListDefinedDomains(virConnectPtr conn,
405 406
                                        char **const names, int nnames)
{
407
    virLXCDriverPtr driver = conn->privateData;
408
    int n;
409

410 411 412
    if (virConnectListDefinedDomainsEnsureACL(conn) < 0)
        return -1;

413 414
    n = virDomainObjListGetInactiveNames(driver->domains, names, nnames,
                                         virConnectListDefinedDomainsCheckACL, conn);
415

416
    return n;
D
Daniel Veillard 已提交
417 418 419
}


420 421
static int lxcConnectNumOfDefinedDomains(virConnectPtr conn)
{
422
    virLXCDriverPtr driver = conn->privateData;
423
    int n;
424

425 426 427
    if (virConnectNumOfDefinedDomainsEnsureACL(conn) < 0)
        return -1;

428 429
    n = virDomainObjListNumOfDomains(driver->domains, false,
                                     virConnectNumOfDefinedDomainsCheckACL, conn);
430

431
    return n;
D
Daniel Veillard 已提交
432 433
}

434 435


436 437
static virDomainPtr
lxcDomainDefineXMLFlags(virConnectPtr conn, const char *xml, unsigned int flags)
D
Daniel Veillard 已提交
438
{
439
    virLXCDriverPtr driver = conn->privateData;
440
    virDomainDefPtr def = NULL;
441
    virDomainObjPtr vm = NULL;
442
    virDomainPtr dom = NULL;
443
    virObjectEventPtr event = NULL;
444
    virDomainDefPtr oldDef = NULL;
445
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
446
    virCapsPtr caps = NULL;
447
    unsigned int parse_flags = VIR_DOMAIN_DEF_PARSE_INACTIVE;
D
Daniel Veillard 已提交
448

449 450 451
    virCheckFlags(VIR_DOMAIN_DEFINE_VALIDATE, NULL);

    if (flags & VIR_DOMAIN_DEFINE_VALIDATE)
452
        parse_flags |= VIR_DOMAIN_DEF_PARSE_VALIDATE_SCHEMA;
453

454 455 456 457
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (!(def = virDomainDefParseString(xml, caps, driver->xmlopt,
458
                                        NULL, parse_flags)))
459
        goto cleanup;
D
Daniel Veillard 已提交
460

461 462 463
    if (virXMLCheckIllegalChars("name", def->name, "\n") < 0)
        goto cleanup;

464
    if (virDomainDefineXMLFlagsEnsureACL(conn, def) < 0)
465 466
        goto cleanup;

467 468 469
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

470
    if ((def->nets != NULL) && !(cfg->have_netns)) {
471 472
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
473
        goto cleanup;
474 475
    }

476
    if (!(vm = virDomainObjListAdd(driver->domains, def,
477
                                   driver->xmlopt,
478
                                   0, &oldDef)))
479
        goto cleanup;
480

481
    def = NULL;
482
    vm->persistent = 1;
D
Daniel Veillard 已提交
483

484
    if (virDomainSaveConfig(cfg->configDir, driver->caps,
485
                            vm->newDef ? vm->newDef : vm->def) < 0) {
486
        virDomainObjListRemove(driver->domains, vm);
487
        goto cleanup;
D
Daniel Veillard 已提交
488 489
    }

490
    event = virDomainEventLifecycleNewFromObj(vm,
491
                                     VIR_DOMAIN_EVENT_DEFINED,
492
                                     !oldDef ?
493 494 495
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED :
                                     VIR_DOMAIN_EVENT_DEFINED_UPDATED);

496
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid, vm->def->id);
D
Daniel Veillard 已提交
497

498
 cleanup:
499
    virDomainDefFree(def);
500
    virDomainDefFree(oldDef);
501
    virDomainObjEndAPI(&vm);
502
    if (event)
503
        virObjectEventStateQueue(driver->domainEventState, event);
504
    virObjectUnref(caps);
505
    virObjectUnref(cfg);
D
Daniel Veillard 已提交
506 507 508
    return dom;
}

509 510 511 512 513 514
static virDomainPtr
lxcDomainDefineXML(virConnectPtr conn, const char *xml)
{
    return lxcDomainDefineXMLFlags(conn, xml, 0);
}

515 516
static int lxcDomainUndefineFlags(virDomainPtr dom,
                                  unsigned int flags)
D
Daniel Veillard 已提交
517
{
518
    virLXCDriverPtr driver = dom->conn->privateData;
519
    virDomainObjPtr vm;
520
    virObjectEventPtr event = NULL;
521
    int ret = -1;
522
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
D
Daniel Veillard 已提交
523

524 525
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
526
    if (!(vm = lxcDomObjFromDomain(dom)))
527
        goto cleanup;
D
Daniel Veillard 已提交
528

529 530 531
    if (virDomainUndefineFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

532
    if (!vm->persistent) {
533 534
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot undefine transient domain"));
535
        goto cleanup;
536
    }
D
Daniel Veillard 已提交
537

538 539
    if (virDomainDeleteConfig(cfg->configDir,
                              cfg->autostartDir,
540 541
                              vm) < 0)
        goto cleanup;
D
Daniel Veillard 已提交
542

543
    event = virDomainEventLifecycleNewFromObj(vm,
544 545 546
                                     VIR_DOMAIN_EVENT_UNDEFINED,
                                     VIR_DOMAIN_EVENT_UNDEFINED_REMOVED);

547
    if (virDomainObjIsActive(vm))
548
        vm->persistent = 0;
549
    else
550
        virDomainObjListRemove(driver->domains, vm);
551

552
    ret = 0;
D
Daniel Veillard 已提交
553

554
 cleanup:
555
    virDomainObjEndAPI(&vm);
556
    if (event)
557
        virObjectEventStateQueue(driver->domainEventState, event);
558
    virObjectUnref(cfg);
559
    return ret;
D
Daniel Veillard 已提交
560 561
}

562 563 564 565 566
static int lxcDomainUndefine(virDomainPtr dom)
{
    return lxcDomainUndefineFlags(dom, 0);
}

D
Daniel Veillard 已提交
567 568 569
static int lxcDomainGetInfo(virDomainPtr dom,
                            virDomainInfoPtr info)
{
570
    virDomainObjPtr vm;
571
    int ret = -1;
572
    virLXCDomainObjPrivatePtr priv;
D
Daniel Veillard 已提交
573

M
Michal Privoznik 已提交
574
    if (!(vm = lxcDomObjFromDomain(dom)))
575
        goto cleanup;
D
Daniel Veillard 已提交
576

577 578
    priv = vm->privateData;

579 580 581
    if (virDomainGetInfoEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

J
Jiri Denemark 已提交
582
    info->state = virDomainObjGetState(vm, NULL);
D
Daniel Veillard 已提交
583

584
    if (!virDomainObjIsActive(vm)) {
D
Daniel Veillard 已提交
585
        info->cpuTime = 0;
586
        info->memory = vm->def->mem.cur_balloon;
D
Daniel Veillard 已提交
587
    } else {
588
        if (virCgroupGetCpuacctUsage(priv->cgroup, &(info->cpuTime)) < 0) {
589 590
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Cannot read cputime for domain"));
R
Ryota Ozaki 已提交
591 592
            goto cleanup;
        }
593 594 595 596 597
        if (virCgroupGetMemoryUsage(priv->cgroup, &(info->memory)) < 0) {
            /* Don't fail if we can't read memory usage due to a lack of
             * kernel support */
            if (virLastErrorIsSystemErrno(ENOENT)) {
                virResetLastError();
598
                info->memory = 0;
599
            } else {
600
                goto cleanup;
601
            }
602
        }
D
Daniel Veillard 已提交
603 604
    }

605
    info->maxMem = virDomainDefGetMemoryTotal(vm->def);
606
    info->nrVirtCpu = virDomainDefGetVcpus(vm->def);
607
    ret = 0;
D
Daniel Veillard 已提交
608

609
 cleanup:
610
    virDomainObjEndAPI(&vm);
611
    return ret;
D
Daniel Veillard 已提交
612 613
}

614 615 616 617 618 619 620 621 622 623 624
static int
lxcDomainGetState(virDomainPtr dom,
                  int *state,
                  int *reason,
                  unsigned int flags)
{
    virDomainObjPtr vm;
    int ret = -1;

    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
625
    if (!(vm = lxcDomObjFromDomain(dom)))
626 627
        goto cleanup;

628 629 630
    if (virDomainGetStateEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

J
Jiri Denemark 已提交
631
    *state = virDomainObjGetState(vm, reason);
632 633
    ret = 0;

634
 cleanup:
635
    virDomainObjEndAPI(&vm);
636 637 638
    return ret;
}

639
static char *lxcDomainGetOSType(virDomainPtr dom)
D
Daniel Veillard 已提交
640
{
641 642
    virDomainObjPtr vm;
    char *ret = NULL;
643

M
Michal Privoznik 已提交
644
    if (!(vm = lxcDomObjFromDomain(dom)))
645
        goto cleanup;
646

647 648 649
    if (virDomainGetOSTypeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

650
    if (VIR_STRDUP(ret, virDomainOSTypeToString(vm->def->os.type)) < 0)
651
        goto cleanup;
652

653
 cleanup:
654
    virDomainObjEndAPI(&vm);
655
    return ret;
D
Daniel Veillard 已提交
656 657
}

R
Ryota Ozaki 已提交
658
/* Returns max memory in kb, 0 if error */
659 660 661
static unsigned long long
lxcDomainGetMaxMemory(virDomainPtr dom)
{
R
Ryota Ozaki 已提交
662
    virDomainObjPtr vm;
663
    unsigned long long ret = 0;
R
Ryota Ozaki 已提交
664

M
Michal Privoznik 已提交
665
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
666 667
        goto cleanup;

668 669 670
    if (virDomainGetMaxMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

671
    ret = virDomainDefGetMemoryTotal(vm->def);
R
Ryota Ozaki 已提交
672

673
 cleanup:
674
    virDomainObjEndAPI(&vm);
R
Ryota Ozaki 已提交
675 676 677
    return ret;
}

678 679
static int lxcDomainSetMemoryFlags(virDomainPtr dom, unsigned long newmem,
                                   unsigned int flags)
680
{
R
Ryota Ozaki 已提交
681
    virDomainObjPtr vm;
682
    virDomainDefPtr def = NULL;
683
    virDomainDefPtr persistentDef = NULL;
R
Ryota Ozaki 已提交
684
    int ret = -1;
685
    virLXCDomainObjPrivatePtr priv;
686 687 688 689
    virLXCDriverPtr driver = dom->conn->privateData;
    virLXCDriverConfigPtr cfg = NULL;

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
690 691
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_DOMAIN_MEM_MAXIMUM, -1);
R
Ryota Ozaki 已提交
692

M
Michal Privoznik 已提交
693
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
694
        goto cleanup;
M
Michal Privoznik 已提交
695

696 697
    cfg = virLXCDriverGetConfig(driver);

698
    priv = vm->privateData;
R
Ryota Ozaki 已提交
699

700
    if (virDomainSetMemoryFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
701 702
        goto cleanup;

703
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
704 705
        goto cleanup;

706
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
707
        goto endjob;
708

709
    if (flags & VIR_DOMAIN_MEM_MAXIMUM) {
710
        if (def) {
711 712 713
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("Cannot resize the max memory "
                             "on an active domain"));
714
            goto endjob;
715
        }
716

717
        if (persistentDef) {
718
            virDomainDefSetMemoryTotal(persistentDef, newmem);
719 720
            if (persistentDef->mem.cur_balloon > newmem)
                persistentDef->mem.cur_balloon = newmem;
721 722
            if (virDomainSaveConfig(cfg->configDir, driver->caps,
                                    persistentDef) < 0)
723
                goto endjob;
724 725 726
        }
    } else {
        unsigned long oldmax = 0;
R
Ryota Ozaki 已提交
727

728
        if (def)
729
            oldmax = virDomainDefGetMemoryTotal(def);
730
        if (persistentDef) {
731 732
            if (!oldmax || oldmax > virDomainDefGetMemoryTotal(persistentDef))
                oldmax = virDomainDefGetMemoryTotal(persistentDef);
733
        }
734

735 736 737
        if (newmem > oldmax) {
            virReportError(VIR_ERR_INVALID_ARG,
                           "%s", _("Cannot set memory higher than max memory"));
738
            goto endjob;
739 740
        }

741
        if (def) {
742 743 744
            if (virCgroupSetMemory(priv->cgroup, newmem) < 0) {
                virReportError(VIR_ERR_OPERATION_FAILED,
                               "%s", _("Failed to set memory for domain"));
745
                goto endjob;
746
            }
747

748
            def->mem.cur_balloon = newmem;
749
            if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0)
750
                goto endjob;
751 752
        }

753
        if (persistentDef) {
754
            persistentDef->mem.cur_balloon = newmem;
755 756
            if (virDomainSaveConfig(cfg->configDir, driver->caps,
                                    persistentDef) < 0)
757
                goto endjob;
758
        }
759 760
    }

R
Ryota Ozaki 已提交
761 762
    ret = 0;

763
 endjob:
764
    virLXCDomainObjEndJob(driver, vm);
765

766
 cleanup:
767
    virDomainObjEndAPI(&vm);
768
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
769 770 771
    return ret;
}

772 773 774 775 776
static int lxcDomainSetMemory(virDomainPtr dom, unsigned long newmem)
{
    return lxcDomainSetMemoryFlags(dom, newmem, VIR_DOMAIN_AFFECT_LIVE);
}

777 778 779 780 781
static int lxcDomainSetMaxMemory(virDomainPtr dom, unsigned long newmax)
{
    return lxcDomainSetMemoryFlags(dom, newmax, VIR_DOMAIN_MEM_MAXIMUM);
}

782 783 784 785 786
static int
lxcDomainSetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int nparams,
                             unsigned int flags)
787
{
788
    virDomainDefPtr def = NULL;
J
Ján Tomko 已提交
789
    virDomainDefPtr persistentDef = NULL;
790
    virDomainObjPtr vm = NULL;
791 792 793 794 795 796 797 798 799 800
    virLXCDomainObjPrivatePtr priv = NULL;
    virLXCDriverConfigPtr cfg = NULL;
    virLXCDriverPtr driver = dom->conn->privateData;
    unsigned long long hard_limit;
    unsigned long long soft_limit;
    unsigned long long swap_hard_limit;
    bool set_hard_limit = false;
    bool set_soft_limit = false;
    bool set_swap_hard_limit = false;
    int rc;
801 802
    int ret = -1;

803 804 805
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

806 807 808 809 810 811 812 813
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_MEMORY_HARD_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               NULL) < 0)
814
        return -1;
E
Eric Blake 已提交
815

M
Michal Privoznik 已提交
816
    if (!(vm = lxcDomObjFromDomain(dom)))
817
        goto cleanup;
M
Michal Privoznik 已提交
818

819
    priv = vm->privateData;
820
    cfg = virLXCDriverGetConfig(driver);
821

822
    if (virDomainSetMemoryParametersEnsureACL(dom->conn, vm->def, flags) < 0)
823 824
        goto cleanup;

825 826 827
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

828 829
    /* QEMU and LXC implementation are identical */
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
830 831
        goto endjob;

832
    if (def &&
833
        !virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_MEMORY)) {
834 835
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("cgroup memory controller is not mounted"));
836
        goto endjob;
837 838
    }

839 840 841 842 843
#define VIR_GET_LIMIT_PARAMETER(PARAM, VALUE) \
    if ((rc = virTypedParamsGetULLong(params, nparams, PARAM, &VALUE)) < 0) \
        goto endjob; \
 \
    if (rc == 1) \
844 845 846 847 848 849 850 851
        set_ ## VALUE = true;

    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT, swap_hard_limit)
    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_HARD_LIMIT, hard_limit)
    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_SOFT_LIMIT, soft_limit)

#undef VIR_GET_LIMIT_PARAMETER

852
    /* Swap hard limit must be greater than hard limit. */
853 854 855 856 857 858 859 860 861 862
    if (set_swap_hard_limit || set_hard_limit) {
        unsigned long long mem_limit = vm->def->mem.hard_limit;
        unsigned long long swap_limit = vm->def->mem.swap_hard_limit;

        if (set_swap_hard_limit)
            swap_limit = swap_hard_limit;

        if (set_hard_limit)
            mem_limit = hard_limit;

863
        if (mem_limit > swap_limit) {
864 865 866
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("memory hard_limit tunable value must be lower "
                             "than or equal to swap_hard_limit"));
867
            goto endjob;
868 869 870
        }
    }

871 872 873 874 875 876 877 878 879 880
#define VIR_SET_MEM_PARAMETER(FUNC, VALUE) \
    if (set_ ## VALUE) { \
        if (def) { \
            if ((rc = FUNC(priv->cgroup, VALUE)) < 0) \
                goto endjob; \
            def->mem.VALUE = VALUE; \
        } \
 \
        if (persistentDef) \
            persistentDef->mem.VALUE = VALUE; \
881 882 883
    }

    /* Soft limit doesn't clash with the others */
884
    VIR_SET_MEM_PARAMETER(virCgroupSetMemorySoftLimit, soft_limit);
885 886

    /* set hard limit before swap hard limit if decreasing it */
887 888
    if (def && def->mem.hard_limit > hard_limit) {
        VIR_SET_MEM_PARAMETER(virCgroupSetMemoryHardLimit, hard_limit);
889 890 891 892
        /* inhibit changing the limit a second time */
        set_hard_limit = false;
    }

893
    VIR_SET_MEM_PARAMETER(virCgroupSetMemSwapHardLimit, swap_hard_limit);
894 895

    /* otherwise increase it after swap hard limit */
896 897 898
    VIR_SET_MEM_PARAMETER(virCgroupSetMemoryHardLimit, hard_limit);

#undef VIR_SET_MEM_PARAMETER
899

900 901 902
    if (def &&
        virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0)
        goto endjob;
903

904
    if (persistentDef &&
J
Ján Tomko 已提交
905
        virDomainSaveConfig(cfg->configDir, driver->caps, persistentDef) < 0)
906
        goto endjob;
907
    /* QEMU and LXC implementations are identical */
908 909

    ret = 0;
910 911

 endjob:
912
    virLXCDomainObjEndJob(driver, vm);
913

914
 cleanup:
915
    virDomainObjEndAPI(&vm);
916
    virObjectUnref(cfg);
917 918 919
    return ret;
}

920 921 922 923 924
static int
lxcDomainGetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int *nparams,
                             unsigned int flags)
925
{
J
Ján Tomko 已提交
926
    virDomainDefPtr persistentDef = NULL;
927
    virDomainDefPtr def = NULL;
928
    virDomainObjPtr vm = NULL;
929
    virLXCDomainObjPrivatePtr priv = NULL;
930
    unsigned long long val;
931
    int ret = -1;
932
    size_t i;
933

934
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
935 936 937 938 939
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We don't return strings, and thus trivially support this flag.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;
E
Eric Blake 已提交
940

M
Michal Privoznik 已提交
941
    if (!(vm = lxcDomObjFromDomain(dom)))
942
        goto cleanup;
M
Michal Privoznik 已提交
943

944
    priv = vm->privateData;
945

946
    if (virDomainGetMemoryParametersEnsureACL(dom->conn, vm->def) < 0)
947 948
        goto cleanup;

949 950 951 952
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
        goto cleanup;

    if (def &&
953 954 955
        !virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_MEMORY)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup memory controller is not mounted"));
956
        goto cleanup;
957
    }
958

959 960 961 962 963 964 965
    if ((*nparams) == 0) {
        /* Current number of memory parameters supported by cgroups */
        *nparams = LXC_NB_MEM_PARAM;
        ret = 0;
        goto cleanup;
    }

966
    for (i = 0; i < LXC_NB_MEM_PARAM && i < *nparams; i++) {
967
        virTypedParameterPtr param = &params[i];
968 969
        val = 0;

970
        switch (i) {
971
        case 0: /* fill memory hard limit here */
972
            if (persistentDef) {
J
Ján Tomko 已提交
973
                val = persistentDef->mem.hard_limit;
974
            } else if (virCgroupGetMemoryHardLimit(priv->cgroup, &val) < 0) {
975
                goto cleanup;
976
            }
977 978
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
979
                goto cleanup;
980 981
            break;
        case 1: /* fill memory soft limit here */
982
            if (persistentDef) {
J
Ján Tomko 已提交
983
                val = persistentDef->mem.soft_limit;
984
            } else if (virCgroupGetMemorySoftLimit(priv->cgroup, &val) < 0) {
985
                goto cleanup;
986
            }
987 988
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
989
                goto cleanup;
990 991
            break;
        case 2: /* fill swap hard limit here */
992
            if (persistentDef) {
J
Ján Tomko 已提交
993
                val = persistentDef->mem.swap_hard_limit;
994
            } else if (virCgroupGetMemSwapHardLimit(priv->cgroup, &val) < 0) {
995
                goto cleanup;
996
            }
997 998 999
            if (virTypedParameterAssign(param,
                                        VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
1000
                goto cleanup;
1001 1002 1003 1004
            break;
        }
    }

1005 1006
    if (*nparams > LXC_NB_MEM_PARAM)
        *nparams = LXC_NB_MEM_PARAM;
1007 1008
    ret = 0;

1009
 cleanup:
1010
    virDomainObjEndAPI(&vm);
1011 1012 1013
    return ret;
}

1014
static char *lxcDomainGetXMLDesc(virDomainPtr dom,
1015
                                 unsigned int flags)
D
Daniel Veillard 已提交
1016
{
1017
    virLXCDriverPtr driver = dom->conn->privateData;
1018 1019
    virDomainObjPtr vm;
    char *ret = NULL;
D
Daniel Veillard 已提交
1020

1021 1022
    /* Flags checked by virDomainDefFormat */

M
Michal Privoznik 已提交
1023
    if (!(vm = lxcDomObjFromDomain(dom)))
1024
        goto cleanup;
D
Daniel Veillard 已提交
1025

1026 1027 1028
    if (virDomainGetXMLDescEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

1029
    ret = virDomainDefFormat((flags & VIR_DOMAIN_XML_INACTIVE) &&
1030
                             vm->newDef ? vm->newDef : vm->def,
1031
                             driver->caps,
1032
                             virDomainDefFormatConvertXMLFlags(flags));
1033

1034
 cleanup:
1035
    virDomainObjEndAPI(&vm);
1036
    return ret;
D
Daniel Veillard 已提交
1037 1038
}

1039 1040 1041 1042 1043 1044 1045
static char *lxcConnectDomainXMLFromNative(virConnectPtr conn,
                                           const char *nativeFormat,
                                           const char *nativeConfig,
                                           unsigned int flags)
{
    char *xml = NULL;
    virDomainDefPtr def = NULL;
1046 1047
    virLXCDriverPtr driver = conn->privateData;
    virCapsPtr caps = virLXCDriverGetCapabilities(driver, false);
1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059

    virCheckFlags(0, NULL);

    if (virConnectDomainXMLFromNativeEnsureACL(conn) < 0)
        goto cleanup;

    if (STRNEQ(nativeFormat, LXC_CONFIG_FORMAT)) {
        virReportError(VIR_ERR_INVALID_ARG,
                       _("unsupported config type %s"), nativeFormat);
        goto cleanup;
    }

1060
    if (!(def = lxcParseConfigString(nativeConfig, caps, driver->xmlopt)))
1061 1062
        goto cleanup;

1063
    xml = virDomainDefFormat(def, caps, 0);
1064

1065
 cleanup:
1066
    virObjectUnref(caps);
1067 1068 1069 1070
    virDomainDefFree(def);
    return xml;
}

1071
/**
1072
 * lxcDomainCreateWithFiles:
1073
 * @dom: domain to start
1074
 * @flags: Must be 0 for now
1075 1076 1077 1078 1079
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
1080 1081 1082 1083
static int lxcDomainCreateWithFiles(virDomainPtr dom,
                                    unsigned int nfiles,
                                    int *files,
                                    unsigned int flags)
1084
{
1085
    virLXCDriverPtr driver = dom->conn->privateData;
1086
    virDomainObjPtr vm;
1087
    virObjectEventPtr event = NULL;
1088
    int ret = -1;
1089
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1090

1091
    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY, -1);
1092

1093 1094
    virNWFilterReadLockFilterUpdates();

M
Michal Privoznik 已提交
1095
    if (!(vm = lxcDomObjFromDomain(dom)))
1096 1097
        goto cleanup;

1098
    if (virDomainCreateWithFilesEnsureACL(dom->conn, vm->def) < 0)
1099 1100
        goto cleanup;

1101
    if ((vm->def->nets != NULL) && !(cfg->have_netns)) {
1102 1103
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
1104 1105 1106
        goto cleanup;
    }

1107 1108 1109
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

1110
    if (virDomainObjIsActive(vm)) {
1111 1112
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is already running"));
1113
        goto endjob;
1114 1115
    }

1116
    ret = virLXCProcessStart(dom->conn, driver, vm,
1117
                             nfiles, files,
1118 1119
                             (flags & VIR_DOMAIN_START_AUTODESTROY),
                             VIR_DOMAIN_RUNNING_BOOTED);
1120

1121
    if (ret == 0) {
1122
        event = virDomainEventLifecycleNewFromObj(vm,
1123 1124
                                         VIR_DOMAIN_EVENT_STARTED,
                                         VIR_DOMAIN_EVENT_STARTED_BOOTED);
1125 1126 1127 1128
        virDomainAuditStart(vm, "booted", true);
    } else {
        virDomainAuditStart(vm, "booted", false);
    }
1129

1130
 endjob:
1131
    virLXCDomainObjEndJob(driver, vm);
1132

1133
 cleanup:
1134
    virDomainObjEndAPI(&vm);
1135
    if (event)
1136
        virObjectEventStateQueue(driver->domainEventState, event);
1137
    virObjectUnref(cfg);
1138
    virNWFilterUnlockFilterUpdates();
1139
    return ret;
1140 1141
}

1142
/**
1143
 * lxcDomainCreate:
1144 1145 1146 1147 1148 1149
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
1150
static int lxcDomainCreate(virDomainPtr dom)
1151
{
1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166
    return lxcDomainCreateWithFiles(dom, 0, NULL, 0);
}

/**
 * lxcDomainCreateWithFlags:
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
static int lxcDomainCreateWithFlags(virDomainPtr dom,
                                    unsigned int flags)
{
    return lxcDomainCreateWithFiles(dom, 0, NULL, flags);
1167 1168
}

1169
/**
1170
 * lxcDomainCreateXMLWithFiles:
1171 1172
 * @conn: pointer to connection
 * @xml: XML definition of domain
1173 1174 1175
 * @nfiles: number of file descriptors passed
 * @files: list of file descriptors passed
 * @flags: bitwise-OR of supported virDomainCreateFlags
1176 1177 1178
 *
 * Creates a domain based on xml and starts it
 *
1179
 * Returns a new domain object or NULL in case of failure.
1180 1181
 */
static virDomainPtr
1182 1183 1184 1185
lxcDomainCreateXMLWithFiles(virConnectPtr conn,
                            const char *xml,
                            unsigned int nfiles,
                            int *files,
1186 1187
                            unsigned int flags)
{
1188
    virLXCDriverPtr driver = conn->privateData;
1189
    virDomainObjPtr vm = NULL;
1190
    virDomainDefPtr def = NULL;
1191
    virDomainPtr dom = NULL;
1192
    virObjectEventPtr event = NULL;
1193
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1194
    virCapsPtr caps = NULL;
1195 1196 1197 1198 1199
    unsigned int parse_flags = VIR_DOMAIN_DEF_PARSE_INACTIVE;

    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY |
                  VIR_DOMAIN_START_VALIDATE, NULL);

1200

1201
    if (flags & VIR_DOMAIN_START_VALIDATE)
1202
        parse_flags |= VIR_DOMAIN_DEF_PARSE_VALIDATE_SCHEMA;
1203

1204 1205
    virNWFilterReadLockFilterUpdates();

1206 1207 1208 1209
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (!(def = virDomainDefParseString(xml, caps, driver->xmlopt,
1210
                                        NULL, parse_flags)))
1211
        goto cleanup;
1212

1213
    if (virDomainCreateXMLWithFilesEnsureACL(conn, def) < 0)
1214 1215
        goto cleanup;

1216 1217 1218
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

1219
    if ((def->nets != NULL) && !(cfg->have_netns)) {
1220 1221
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       "%s", _("System lacks NETNS support"));
1222
        goto cleanup;
1223 1224
    }

1225

1226
    if (!(vm = virDomainObjListAdd(driver->domains, def,
1227
                                   driver->xmlopt,
1228
                                   VIR_DOMAIN_OBJ_LIST_ADD_LIVE |
1229 1230
                                   VIR_DOMAIN_OBJ_LIST_ADD_CHECK_LIVE,
                                   NULL)))
1231 1232
        goto cleanup;
    def = NULL;
1233

1234
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0) {
1235
        if (!vm->persistent)
1236 1237 1238 1239
            virDomainObjListRemove(driver->domains, vm);
        goto cleanup;
    }

1240
    if (virLXCProcessStart(conn, driver, vm,
1241
                           nfiles, files,
1242 1243
                           (flags & VIR_DOMAIN_START_AUTODESTROY),
                           VIR_DOMAIN_RUNNING_BOOTED) < 0) {
1244
        virDomainAuditStart(vm, "booted", false);
1245
        virLXCDomainObjEndJob(driver, vm);
1246
        if (!vm->persistent)
1247
            virDomainObjListRemove(driver->domains, vm);
1248
        goto cleanup;
1249 1250
    }

1251
    event = virDomainEventLifecycleNewFromObj(vm,
1252 1253
                                     VIR_DOMAIN_EVENT_STARTED,
                                     VIR_DOMAIN_EVENT_STARTED_BOOTED);
1254
    virDomainAuditStart(vm, "booted", true);
1255

1256
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid, vm->def->id);
1257

1258
    virLXCDomainObjEndJob(driver, vm);
1259

1260
 cleanup:
1261
    virDomainDefFree(def);
1262
    virDomainObjEndAPI(&vm);
1263
    if (event)
1264
        virObjectEventStateQueue(driver->domainEventState, event);
1265
    virObjectUnref(caps);
1266
    virObjectUnref(cfg);
1267
    virNWFilterUnlockFilterUpdates();
1268 1269 1270
    return dom;
}

1271 1272 1273 1274 1275 1276 1277 1278 1279 1280
/**
 * lxcDomainCreateXML:
 * @conn: pointer to connection
 * @xml: XML definition of domain
 * @flags: bitwise-OR of supported virDomainCreateFlags
 *
 * Creates a domain based on xml and starts it
 *
 * Returns a new domain object or NULL in case of failure.
 */
1281 1282 1283
static virDomainPtr
lxcDomainCreateXML(virConnectPtr conn,
                   const char *xml,
1284 1285
                   unsigned int flags)
{
1286 1287 1288 1289
    return lxcDomainCreateXMLWithFiles(conn, xml, 0, NULL,  flags);
}


1290 1291
static int lxcDomainGetSecurityLabel(virDomainPtr dom, virSecurityLabelPtr seclabel)
{
1292
    virLXCDriverPtr driver = dom->conn->privateData;
1293 1294 1295 1296 1297
    virDomainObjPtr vm;
    int ret = -1;

    memset(seclabel, 0, sizeof(*seclabel));

M
Michal Privoznik 已提交
1298
    if (!(vm = lxcDomObjFromDomain(dom)))
1299 1300
        goto cleanup;

1301 1302 1303
    if (virDomainGetSecurityLabelEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1304
    if (!virDomainVirtTypeToString(vm->def->virtType)) {
1305 1306 1307
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unknown virt type in domain definition '%d'"),
                       vm->def->virtType);
1308 1309 1310 1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325
        goto cleanup;
    }

    /*
     * Theoretically, the pid can be replaced during this operation and
     * return the label of a different process.  If atomicity is needed,
     * further validation will be required.
     *
     * Comment from Dan Berrange:
     *
     *   Well the PID as stored in the virDomainObjPtr can't be changed
     *   because you've got a locked object.  The OS level PID could have
     *   exited, though and in extreme circumstances have cycled through all
     *   PIDs back to ours. We could sanity check that our PID still exists
     *   after reading the label, by checking that our FD connecting to the
     *   LXC monitor hasn't seen SIGHUP/ERR on poll().
     */
    if (virDomainObjIsActive(vm)) {
1326 1327 1328 1329 1330 1331 1332 1333
        virLXCDomainObjPrivatePtr priv = vm->privateData;

        if (!priv->initpid) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("Init pid is not yet available"));
            goto cleanup;
        }

1334
        if (virSecurityManagerGetProcessLabel(driver->securityManager,
1335 1336
                                              vm->def, priv->initpid,
                                              seclabel) < 0)
1337 1338 1339 1340 1341
            goto cleanup;
    }

    ret = 0;

1342
 cleanup:
1343
    virDomainObjEndAPI(&vm);
1344 1345 1346 1347 1348 1349
    return ret;
}

static int lxcNodeGetSecurityModel(virConnectPtr conn,
                                   virSecurityModelPtr secmodel)
{
1350
    virLXCDriverPtr driver = conn->privateData;
1351
    virCapsPtr caps = NULL;
1352 1353 1354 1355
    int ret = 0;

    memset(secmodel, 0, sizeof(*secmodel));

1356 1357 1358
    if (virNodeGetSecurityModelEnsureACL(conn) < 0)
        goto cleanup;

1359 1360 1361
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

1362
    /* we treat no driver as success, but simply return no data in *secmodel */
1363 1364
    if (caps->host.nsecModels == 0
        || caps->host.secModels[0].model == NULL)
1365 1366
        goto cleanup;

1367
    if (!virStrcpy(secmodel->model, caps->host.secModels[0].model,
1368
                   VIR_SECURITY_MODEL_BUFLEN)) {
1369 1370 1371
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security model string exceeds max %d bytes"),
                       VIR_SECURITY_MODEL_BUFLEN - 1);
1372 1373 1374 1375
        ret = -1;
        goto cleanup;
    }

1376
    if (!virStrcpy(secmodel->doi, caps->host.secModels[0].doi,
1377
                   VIR_SECURITY_DOI_BUFLEN)) {
1378 1379 1380
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security DOI string exceeds max %d bytes"),
                       VIR_SECURITY_DOI_BUFLEN-1);
1381 1382 1383 1384
        ret = -1;
        goto cleanup;
    }

1385
 cleanup:
1386
    virObjectUnref(caps);
1387 1388 1389 1390
    return ret;
}


1391
static int
1392 1393 1394 1395
lxcConnectDomainEventRegister(virConnectPtr conn,
                              virConnectDomainEventCallback callback,
                              void *opaque,
                              virFreeCallback freecb)
1396
{
1397
    virLXCDriverPtr driver = conn->privateData;
1398

1399 1400 1401
    if (virConnectDomainEventRegisterEnsureACL(conn) < 0)
        return -1;

1402 1403 1404 1405
    if (virDomainEventStateRegister(conn,
                                    driver->domainEventState,
                                    callback, opaque, freecb) < 0)
        return -1;
1406

1407
    return 0;
1408 1409
}

1410

1411
static int
1412 1413
lxcConnectDomainEventDeregister(virConnectPtr conn,
                                virConnectDomainEventCallback callback)
1414
{
1415
    virLXCDriverPtr driver = conn->privateData;
1416

1417 1418 1419
    if (virConnectDomainEventDeregisterEnsureACL(conn) < 0)
        return -1;

1420 1421 1422 1423
    if (virDomainEventStateDeregister(conn,
                                      driver->domainEventState,
                                      callback) < 0)
        return -1;
1424

1425
    return 0;
1426 1427
}

1428 1429

static int
1430 1431 1432 1433 1434 1435
lxcConnectDomainEventRegisterAny(virConnectPtr conn,
                                 virDomainPtr dom,
                                 int eventID,
                                 virConnectDomainEventGenericCallback callback,
                                 void *opaque,
                                 virFreeCallback freecb)
1436
{
1437
    virLXCDriverPtr driver = conn->privateData;
1438 1439
    int ret;

1440 1441 1442
    if (virConnectDomainEventRegisterAnyEnsureACL(conn) < 0)
        return -1;

1443 1444 1445 1446
    if (virDomainEventStateRegisterID(conn,
                                      driver->domainEventState,
                                      dom, eventID,
                                      callback, opaque, freecb, &ret) < 0)
1447
        ret = -1;
1448 1449 1450 1451 1452 1453

    return ret;
}


static int
1454 1455
lxcConnectDomainEventDeregisterAny(virConnectPtr conn,
                                   int callbackID)
1456
{
1457
    virLXCDriverPtr driver = conn->privateData;
1458

1459 1460 1461
    if (virConnectDomainEventDeregisterAnyEnsureACL(conn) < 0)
        return -1;

1462 1463
    if (virObjectEventStateDeregisterID(conn,
                                        driver->domainEventState,
1464
                                        callbackID, true) < 0)
1465
        return -1;
1466

1467
    return 0;
1468 1469 1470
}


1471
/**
1472
 * lxcDomainDestroyFlags:
1473
 * @dom: pointer to domain to destroy
1474
 * @flags: extra flags; not used yet.
1475 1476 1477 1478 1479
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
1480 1481 1482
static int
lxcDomainDestroyFlags(virDomainPtr dom,
                      unsigned int flags)
1483
{
1484
    virLXCDriverPtr driver = dom->conn->privateData;
1485
    virDomainObjPtr vm;
1486
    virObjectEventPtr event = NULL;
1487
    int ret = -1;
1488
    virLXCDomainObjPrivatePtr priv;
1489

1490 1491
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
1492
    if (!(vm = lxcDomObjFromDomain(dom)))
1493
        goto cleanup;
1494

1495 1496 1497
    if (virDomainDestroyFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1498 1499 1500
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

1501
    if (virDomainObjCheckActive(vm) < 0)
1502
        goto endjob;
1503

1504
    priv = vm->privateData;
1505
    ret = virLXCProcessStop(driver, vm, VIR_DOMAIN_SHUTOFF_DESTROYED);
1506
    event = virDomainEventLifecycleNewFromObj(vm,
1507 1508
                                     VIR_DOMAIN_EVENT_STOPPED,
                                     VIR_DOMAIN_EVENT_STOPPED_DESTROYED);
1509
    priv->doneStopEvent = true;
1510
    virDomainAuditStop(vm, "destroyed");
1511

1512
 endjob:
1513
    virLXCDomainObjEndJob(driver, vm);
1514
    if (!vm->persistent)
1515
        virDomainObjListRemove(driver->domains, vm);
1516

1517
 cleanup:
1518
    virDomainObjEndAPI(&vm);
1519
    if (event)
1520
        virObjectEventStateQueue(driver->domainEventState, event);
1521
    return ret;
1522
}
1523

1524 1525 1526 1527 1528 1529 1530 1531 1532 1533 1534 1535 1536 1537
/**
 * lxcDomainDestroy:
 * @dom: pointer to domain to destroy
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
static int
lxcDomainDestroy(virDomainPtr dom)
{
    return lxcDomainDestroyFlags(dom, 0);
}

1538 1539 1540 1541 1542
static int lxcCheckNetNsSupport(void)
{
    const char *argv[] = {"ip", "link", "set", "lo", "netns", "-1", NULL};
    int ip_rc;

1543
    if (virRun(argv, &ip_rc) < 0 || ip_rc == 255)
1544
        return 0;
1545

1546
    if (virProcessNamespaceAvailable(VIR_PROCESS_NAMESPACE_NET) < 0)
1547
        return 0;
1548

1549
    return 1;
1550 1551
}

1552

1553 1554
static virSecurityManagerPtr
lxcSecurityInit(virLXCDriverConfigPtr cfg)
1555
{
1556 1557
    unsigned int flags = VIR_SECURITY_MANAGER_PRIVILEGED;

1558
    VIR_INFO("lxcSecurityInit %s", cfg->securityDriverName);
1559 1560 1561 1562 1563 1564

    if (cfg->securityDefaultConfined)
        flags |= VIR_SECURITY_MANAGER_DEFAULT_CONFINED;
    if (cfg->securityRequireConfined)
        flags |= VIR_SECURITY_MANAGER_REQUIRE_CONFINED;

1565
    virSecurityManagerPtr mgr = virSecurityManagerNew(cfg->securityDriverName,
1566
                                                      LXC_DRIVER_NAME, flags);
1567 1568 1569
    if (!mgr)
        goto error;

1570
    return mgr;
1571

1572
 error:
1573
    VIR_ERROR(_("Failed to initialize security drivers"));
1574
    virObjectUnref(mgr);
1575
    return NULL;
1576 1577 1578
}


1579 1580 1581
static int lxcStateInitialize(bool privileged,
                              virStateInhibitCallback callback ATTRIBUTE_UNUSED,
                              void *opaque ATTRIBUTE_UNUSED)
D
Daniel Veillard 已提交
1582
{
1583
    virCapsPtr caps = NULL;
1584
    const char *ld;
1585
    virLXCDriverConfigPtr cfg = NULL;
1586 1587 1588 1589 1590

    /* Valgrind gets very annoyed when we clone containers, so
     * disable LXC when under valgrind
     * XXX remove this when valgrind is fixed
     */
1591
    ld = virGetEnvBlockSUID("LD_PRELOAD");
1592
    if (ld && strstr(ld, "vgpreload")) {
1593
        VIR_INFO("Running under valgrind, disabling driver");
1594 1595
        return 0;
    }
1596

1597
    /* Check that the user is root, silently disable if not */
1598
    if (!privileged) {
1599
        VIR_INFO("Not running privileged, disabling driver");
1600 1601 1602 1603
        return 0;
    }

    /* Check that this is a container enabled kernel */
1604 1605 1606 1607
    if (virProcessNamespaceAvailable(VIR_PROCESS_NAMESPACE_MNT |
                                     VIR_PROCESS_NAMESPACE_PID |
                                     VIR_PROCESS_NAMESPACE_UTS |
                                     VIR_PROCESS_NAMESPACE_IPC) < 0) {
1608
        VIR_INFO("LXC support not available in this kernel, disabling driver");
1609
        return 0;
1610 1611
    }

1612
    if (VIR_ALLOC(lxc_driver) < 0)
1613
        return -1;
1614 1615 1616 1617
    if (virMutexInit(&lxc_driver->lock) < 0) {
        VIR_FREE(lxc_driver);
        return -1;
    }
D
Daniel Veillard 已提交
1618

1619
    if (!(lxc_driver->domains = virDomainObjListNew()))
1620 1621
        goto cleanup;

1622
    lxc_driver->domainEventState = virObjectEventStateNew();
1623
    if (!lxc_driver->domainEventState)
1624 1625
        goto cleanup;

1626 1627
    lxc_driver->hostsysinfo = virSysinfoRead();

1628 1629 1630 1631 1632
    if (!(lxc_driver->config = cfg = virLXCDriverConfigNew()))
        goto cleanup;

    cfg->log_libvirtd = 0; /* by default log to container logfile */
    cfg->have_netns = lxcCheckNetNsSupport();
D
Daniel Veillard 已提交
1633 1634

    /* Call function to load lxc driver configuration information */
1635
    if (virLXCLoadDriverConfig(cfg, SYSCONFDIR "/libvirt/lxc.conf") < 0)
1636
        goto cleanup;
D
Daniel Veillard 已提交
1637

1638
    if (!(lxc_driver->securityManager = lxcSecurityInit(cfg)))
1639 1640
        goto cleanup;

1641
    if (!(lxc_driver->hostdevMgr = virHostdevManagerGetDefault()))
G
Guido Günther 已提交
1642 1643
        goto cleanup;

1644
    if (!(caps = virLXCDriverGetCapabilities(lxc_driver, true)))
1645
        goto cleanup;
D
Daniel Veillard 已提交
1646

1647
    if (!(lxc_driver->xmlopt = lxcDomainXMLConfInit()))
1648
        goto cleanup;
1649

1650
    if (!(lxc_driver->closeCallbacks = virCloseCallbacksNew()))
1651 1652
        goto cleanup;

1653 1654 1655 1656 1657 1658 1659
    if (virFileMakePath(cfg->stateDir) < 0) {
        virReportSystemError(errno,
                             _("Failed to mkdir %s"),
                             cfg->stateDir);
        goto cleanup;
    }

O
Osier Yang 已提交
1660
    /* Get all the running persistent or transient configs first */
1661
    if (virDomainObjListLoadAllConfigs(lxc_driver->domains,
1662
                                       cfg->stateDir,
1663
                                       NULL, true,
1664
                                       caps,
1665
                                       lxc_driver->xmlopt,
1666
                                       NULL, NULL) < 0)
O
Osier Yang 已提交
1667 1668
        goto cleanup;

1669
    virLXCProcessReconnectAll(lxc_driver, lxc_driver->domains);
O
Osier Yang 已提交
1670 1671

    /* Then inactive persistent configs */
1672
    if (virDomainObjListLoadAllConfigs(lxc_driver->domains,
1673
                                       cfg->configDir,
1674
                                       cfg->autostartDir, false,
1675
                                       caps,
1676
                                       lxc_driver->xmlopt,
1677
                                       NULL, NULL) < 0)
1678
        goto cleanup;
1679

1680
    virNWFilterRegisterCallbackDriver(&lxcCallbackDriver);
1681
    virObjectUnref(caps);
D
Daniel Veillard 已提交
1682 1683
    return 0;

1684
 cleanup:
1685
    virObjectUnref(caps);
1686
    lxcStateCleanup();
1687
    return -1;
D
Daniel Veillard 已提交
1688 1689
}

1690 1691 1692 1693 1694 1695 1696 1697 1698 1699 1700 1701 1702
/**
 * lxcStateAutoStart:
 *
 * Function to autostart the LXC daemons
 */
static void lxcStateAutoStart(void)
{
    if (!lxc_driver)
        return;

    virLXCProcessAutostartAll(lxc_driver);
}

1703 1704
static void lxcNotifyLoadDomain(virDomainObjPtr vm, int newVM, void *opaque)
{
1705
    virLXCDriverPtr driver = opaque;
1706 1707

    if (newVM) {
1708
        virObjectEventPtr event =
1709
            virDomainEventLifecycleNewFromObj(vm,
1710 1711 1712
                                     VIR_DOMAIN_EVENT_DEFINED,
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED);
        if (event)
1713
            virObjectEventStateQueue(driver->domainEventState, event);
1714 1715 1716 1717
    }
}

/**
1718
 * lxcStateReload:
1719 1720 1721 1722 1723
 *
 * Function to restart the LXC driver, it will recheck the configuration
 * files and perform autostart
 */
static int
1724 1725
lxcStateReload(void)
{
1726
    virLXCDriverConfigPtr cfg = NULL;
1727
    virCapsPtr caps = NULL;
1728

1729 1730 1731
    if (!lxc_driver)
        return 0;

1732
    if (!(caps = virLXCDriverGetCapabilities(lxc_driver, false)))
1733 1734
        return -1;

1735 1736
    cfg = virLXCDriverGetConfig(lxc_driver);

1737
    virDomainObjListLoadAllConfigs(lxc_driver->domains,
1738
                                   cfg->configDir,
1739
                                   cfg->autostartDir, false,
1740
                                   caps,
1741
                                   lxc_driver->xmlopt,
1742
                                   lxcNotifyLoadDomain, lxc_driver);
1743
    virObjectUnref(caps);
1744
    virObjectUnref(cfg);
1745 1746 1747
    return 0;
}

1748
static int lxcStateCleanup(void)
D
Daniel Veillard 已提交
1749
{
1750
    if (lxc_driver == NULL)
1751
        return -1;
1752

1753
    virNWFilterUnRegisterCallbackDriver(&lxcCallbackDriver);
1754
    virObjectUnref(lxc_driver->domains);
1755
    virObjectUnref(lxc_driver->domainEventState);
1756

1757
    virObjectUnref(lxc_driver->closeCallbacks);
1758

1759 1760
    virSysinfoDefFree(lxc_driver->hostsysinfo);

1761
    virObjectUnref(lxc_driver->hostdevMgr);
1762
    virObjectUnref(lxc_driver->caps);
1763
    virObjectUnref(lxc_driver->securityManager);
1764
    virObjectUnref(lxc_driver->xmlopt);
1765
    virObjectUnref(lxc_driver->config);
1766
    virMutexDestroy(&lxc_driver->lock);
1767
    VIR_FREE(lxc_driver);
1768 1769 1770

    return 0;
}
D
Daniel Veillard 已提交
1771

1772 1773 1774 1775 1776 1777
static int
lxcConnectSupportsFeature(virConnectPtr conn, int feature)
{
    if (virConnectSupportsFeatureEnsureACL(conn) < 0)
        return -1;

1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789 1790 1791 1792 1793 1794 1795 1796
    switch ((virDrvFeature) feature) {
    case VIR_DRV_FEATURE_TYPED_PARAM_STRING:
        return 1;
    case VIR_DRV_FEATURE_FD_PASSING:
    case VIR_DRV_FEATURE_MIGRATE_CHANGE_PROTECTION:
    case VIR_DRV_FEATURE_MIGRATION_DIRECT:
    case VIR_DRV_FEATURE_MIGRATION_OFFLINE:
    case VIR_DRV_FEATURE_MIGRATION_P2P:
    case VIR_DRV_FEATURE_MIGRATION_PARAMS:
    case VIR_DRV_FEATURE_MIGRATION_V1:
    case VIR_DRV_FEATURE_MIGRATION_V2:
    case VIR_DRV_FEATURE_MIGRATION_V3:
    case VIR_DRV_FEATURE_PROGRAM_KEEPALIVE:
    case VIR_DRV_FEATURE_REMOTE:
    case VIR_DRV_FEATURE_REMOTE_CLOSE_CALLBACK:
    case VIR_DRV_FEATURE_REMOTE_EVENT_CALLBACK:
    case VIR_DRV_FEATURE_XML_MIGRATABLE:
    default:
        return 0;
1797 1798 1799
    }
}

D
Daniel Veillard 已提交
1800

1801
static int lxcConnectGetVersion(virConnectPtr conn, unsigned long *version)
D
Dan Smith 已提交
1802 1803 1804
{
    struct utsname ver;

1805
    uname(&ver);
D
Dan Smith 已提交
1806

1807 1808 1809
    if (virConnectGetVersionEnsureACL(conn) < 0)
        return -1;

1810
    if (virParseVersionString(ver.release, version, true) < 0) {
1811
        virReportError(VIR_ERR_INTERNAL_ERROR, _("Unknown release: %s"), ver.release);
D
Dan Smith 已提交
1812 1813 1814 1815 1816
        return -1;
    }

    return 0;
}
1817

1818

1819
static char *lxcConnectGetHostname(virConnectPtr conn)
1820
{
1821 1822 1823
    if (virConnectGetHostnameEnsureACL(conn) < 0)
        return NULL;

1824 1825 1826 1827
    return virGetHostname();
}


1828 1829
static char *lxcDomainGetSchedulerType(virDomainPtr dom,
                                       int *nparams)
1830
{
1831
    char *ret = NULL;
1832 1833
    virDomainObjPtr vm;
    virLXCDomainObjPrivatePtr priv;
1834

M
Michal Privoznik 已提交
1835
    if (!(vm = lxcDomObjFromDomain(dom)))
1836
        goto cleanup;
M
Michal Privoznik 已提交
1837

1838 1839
    priv = vm->privateData;

1840 1841 1842
    if (virDomainGetSchedulerTypeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1843 1844 1845 1846 1847 1848 1849 1850
    /* Domain not running, thus no cgroups - return defaults */
    if (!virDomainObjIsActive(vm)) {
        if (nparams)
            *nparams = 3;
        ignore_value(VIR_STRDUP(ret, "posix"));
        goto cleanup;
    }

1851
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
1852 1853
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
1854 1855
        goto cleanup;
    }
1856

1857
    if (nparams) {
1858
        if (virCgroupSupportsCpuBW(priv->cgroup))
1859
            *nparams = 3;
1860 1861
        else
            *nparams = 1;
1862
    }
1863

1864
    ignore_value(VIR_STRDUP(ret, "posix"));
1865

1866
 cleanup:
1867
    virDomainObjEndAPI(&vm);
1868 1869 1870 1871 1872 1873 1874 1875
    return ret;
}


static int
lxcGetVcpuBWLive(virCgroupPtr cgroup, unsigned long long *period,
                 long long *quota)
{
1876
    if (virCgroupGetCpuCfsPeriod(cgroup, period) < 0)
1877 1878
        return -1;

1879
    if (virCgroupGetCpuCfsQuota(cgroup, quota) < 0)
1880 1881 1882 1883 1884 1885 1886 1887 1888 1889 1890 1891 1892 1893 1894 1895
        return -1;

    return 0;
}


static int lxcSetVcpuBWLive(virCgroupPtr cgroup, unsigned long long period,
                            long long quota)
{
    unsigned long long old_period;

    if (period == 0 && quota == 0)
        return 0;

    if (period) {
        /* get old period, and we can rollback if set quota failed */
1896
        if (virCgroupGetCpuCfsPeriod(cgroup, &old_period) < 0)
1897 1898
            return -1;

1899
        if (virCgroupSetCpuCfsPeriod(cgroup, period) < 0)
1900 1901 1902 1903
            return -1;
    }

    if (quota) {
1904 1905
        if (virCgroupSetCpuCfsQuota(cgroup, quota) < 0)
            goto error;
1906 1907 1908 1909
    }

    return 0;

1910
 error:
1911
    if (period) {
1912 1913 1914 1915 1916 1917
        virErrorPtr saved = virSaveLastError();
        virCgroupSetCpuCfsPeriod(cgroup, old_period);
        if (saved) {
            virSetError(saved);
            virFreeError(saved);
        }
1918 1919 1920
    }

    return -1;
1921 1922
}

1923

1924
static int
1925 1926 1927 1928
lxcDomainSetSchedulerParametersFlags(virDomainPtr dom,
                                     virTypedParameterPtr params,
                                     int nparams,
                                     unsigned int flags)
1929
{
1930
    virLXCDriverPtr driver = dom->conn->privateData;
1931
    virCapsPtr caps = NULL;
1932
    size_t i;
1933
    virDomainObjPtr vm = NULL;
1934
    virDomainDefPtr def = NULL;
J
Ján Tomko 已提交
1935 1936
    virDomainDefPtr persistentDefCopy = NULL;
    virDomainDefPtr persistentDef = NULL;
1937
    int ret = -1;
1938
    int rc;
1939
    virLXCDomainObjPrivatePtr priv;
1940
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1941

1942 1943
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
1944 1945 1946 1947 1948 1949 1950 1951
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                               VIR_TYPED_PARAM_LLONG,
                               NULL) < 0)
1952
        return -1;
1953

M
Michal Privoznik 已提交
1954
    if (!(vm = lxcDomObjFromDomain(dom)))
1955
        goto cleanup;
M
Michal Privoznik 已提交
1956

1957
    priv = vm->privateData;
1958

1959 1960 1961
    if (virDomainSetSchedulerParametersFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

1962 1963 1964
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

1965 1966 1967
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

1968
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
1969
        goto endjob;
1970

1971
    if (persistentDef) {
1972
        /* Make a copy for updated domain. */
J
Ján Tomko 已提交
1973 1974
        persistentDefCopy = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
        if (!persistentDefCopy)
1975
            goto endjob;
1976 1977
    }

1978
    if (def) {
1979
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
1980 1981
            virReportError(VIR_ERR_OPERATION_INVALID,
                           "%s", _("cgroup CPU controller is not mounted"));
1982
            goto endjob;
1983 1984
        }
    }
1985 1986

    for (i = 0; i < nparams; i++) {
1987
        virTypedParameterPtr param = &params[i];
1988

1989
        if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_CPU_SHARES)) {
1990
            if (def) {
1991
                unsigned long long val;
1992
                if (virCgroupSetCpuShares(priv->cgroup, params[i].value.ul) < 0)
1993
                    goto endjob;
1994

1995
                if (virCgroupGetCpuShares(priv->cgroup, &val) < 0)
1996
                    goto endjob;
1997

1998 1999
                def->cputune.shares = val;
                def->cputune.sharesSpecified = true;
2000 2001
            }

2002
            if (persistentDef) {
J
Ján Tomko 已提交
2003 2004
                persistentDefCopy->cputune.shares = params[i].value.ul;
                persistentDefCopy->cputune.sharesSpecified = true;
2005 2006
            }
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_PERIOD)) {
2007
            if (def) {
2008
                rc = lxcSetVcpuBWLive(priv->cgroup, params[i].value.ul, 0);
2009
                if (rc != 0)
2010
                    goto endjob;
2011 2012

                if (params[i].value.ul)
2013
                    def->cputune.period = params[i].value.ul;
2014 2015
            }

2016
            if (persistentDef)
J
Ján Tomko 已提交
2017
                persistentDefCopy->cputune.period = params[i].value.ul;
2018
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_QUOTA)) {
2019
            if (def) {
2020
                rc = lxcSetVcpuBWLive(priv->cgroup, 0, params[i].value.l);
2021
                if (rc != 0)
2022
                    goto endjob;
2023 2024

                if (params[i].value.l)
2025
                    def->cputune.quota = params[i].value.l;
2026 2027
            }

2028
            if (persistentDef)
J
Ján Tomko 已提交
2029
                persistentDefCopy->cputune.quota = params[i].value.l;
2030
        }
2031
    }
2032

2033
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0)
2034
        goto endjob;
2035

2036

2037
    if (persistentDef) {
J
Ján Tomko 已提交
2038
        rc = virDomainSaveConfig(cfg->configDir, driver->caps, persistentDefCopy);
2039
        if (rc < 0)
2040
            goto endjob;
2041

J
Ján Tomko 已提交
2042 2043
        virDomainObjAssignDef(vm, persistentDefCopy, false, NULL);
        persistentDefCopy = NULL;
2044
    }
2045

2046
    ret = 0;
2047

2048
 endjob:
2049
    virLXCDomainObjEndJob(driver, vm);
2050

2051
 cleanup:
J
Ján Tomko 已提交
2052
    virDomainDefFree(persistentDefCopy);
2053
    virDomainObjEndAPI(&vm);
2054
    virObjectUnref(caps);
2055
    virObjectUnref(cfg);
2056
    return ret;
2057 2058
}

2059
static int
2060 2061 2062
lxcDomainSetSchedulerParameters(virDomainPtr domain,
                                virTypedParameterPtr params,
                                int nparams)
2063
{
2064
    return lxcDomainSetSchedulerParametersFlags(domain, params, nparams, 0);
2065 2066 2067
}

static int
2068 2069 2070 2071
lxcDomainGetSchedulerParametersFlags(virDomainPtr dom,
                                     virTypedParameterPtr params,
                                     int *nparams,
                                     unsigned int flags)
2072
{
2073
    virDomainObjPtr vm = NULL;
2074
    virDomainDefPtr def;
E
Eric Blake 已提交
2075
    virDomainDefPtr persistentDef;
2076 2077 2078
    unsigned long long shares = 0;
    unsigned long long period = 0;
    long long quota = 0;
2079
    int ret = -1;
2080 2081 2082
    int rc;
    bool cpu_bw_status = false;
    int saved_nparams = 0;
2083
    virLXCDomainObjPrivatePtr priv;
2084

2085
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
2086 2087 2088 2089 2090
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We don't return strings, and thus trivially support this flag.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;
2091

M
Michal Privoznik 已提交
2092
    if (!(vm = lxcDomObjFromDomain(dom)))
2093
        goto cleanup;
M
Michal Privoznik 已提交
2094

2095 2096
    priv = vm->privateData;

2097 2098 2099
    if (virDomainGetSchedulerParametersFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2100 2101
    if (*nparams > 1)
        cpu_bw_status = virCgroupSupportsCpuBW(priv->cgroup);
2102

2103
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
E
Eric Blake 已提交
2104
        goto cleanup;
2105

2106
    if (persistentDef) {
E
Eric Blake 已提交
2107
        shares = persistentDef->cputune.shares;
2108
        if (*nparams > 1) {
E
Eric Blake 已提交
2109 2110
            period = persistentDef->cputune.period;
            quota = persistentDef->cputune.quota;
2111
            cpu_bw_status = true; /* Allow copy of data to params[] */
2112 2113 2114 2115
        }
        goto out;
    }

2116
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
2117 2118
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
2119
        goto cleanup;
2120 2121
    }

2122
    if (virCgroupGetCpuShares(priv->cgroup, &shares) < 0)
2123
        goto cleanup;
2124 2125

    if (*nparams > 1 && cpu_bw_status) {
2126
        rc = lxcGetVcpuBWLive(priv->cgroup, &period, &quota);
2127 2128 2129
        if (rc != 0)
            goto cleanup;
    }
2130
 out:
2131 2132
    if (virTypedParameterAssign(&params[0], VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                                VIR_TYPED_PARAM_ULLONG, shares) < 0)
C
Chris Lalancette 已提交
2133
        goto cleanup;
2134 2135 2136 2137
    saved_nparams++;

    if (cpu_bw_status) {
        if (*nparams > saved_nparams) {
2138 2139 2140
            if (virTypedParameterAssign(&params[1],
                                        VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                                        VIR_TYPED_PARAM_ULLONG, period) < 0)
2141 2142 2143 2144 2145
                goto cleanup;
            saved_nparams++;
        }

        if (*nparams > saved_nparams) {
2146 2147 2148
            if (virTypedParameterAssign(&params[2],
                                        VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                                        VIR_TYPED_PARAM_LLONG, quota) < 0)
2149 2150 2151 2152 2153 2154 2155
                goto cleanup;
            saved_nparams++;
        }
    }

    *nparams = saved_nparams;

2156
    ret = 0;
2157

2158
 cleanup:
2159
    virDomainObjEndAPI(&vm);
2160
    return ret;
2161 2162
}

2163
static int
2164 2165 2166
lxcDomainGetSchedulerParameters(virDomainPtr domain,
                                virTypedParameterPtr params,
                                int *nparams)
2167
{
2168
    return lxcDomainGetSchedulerParametersFlags(domain, params, nparams, 0);
2169 2170
}

2171 2172 2173 2174 2175 2176 2177 2178 2179 2180 2181 2182 2183 2184 2185 2186 2187 2188 2189 2190 2191 2192 2193 2194 2195 2196 2197 2198
static int
lxcDomainParseBlkioDeviceStr(char *blkioDeviceStr, const char *type,
                             virBlkioDevicePtr *dev, size_t *size)
{
    char *temp;
    int ndevices = 0;
    int nsep = 0;
    size_t i;
    virBlkioDevicePtr result = NULL;

    *dev = NULL;
    *size = 0;

    if (STREQ(blkioDeviceStr, ""))
        return 0;

    temp = blkioDeviceStr;
    while (temp) {
        temp = strchr(temp, ',');
        if (temp) {
            temp++;
            nsep++;
        }
    }

    /* A valid string must have even number of fields, hence an odd
     * number of commas.  */
    if (!(nsep & 1))
2199
        goto parse_error;
2200 2201 2202 2203 2204 2205 2206 2207 2208 2209 2210 2211 2212 2213

    ndevices = (nsep + 1) / 2;

    if (VIR_ALLOC_N(result, ndevices) < 0)
        return -1;

    i = 0;
    temp = blkioDeviceStr;
    while (temp) {
        char *p = temp;

        /* device path */
        p = strchr(p, ',');
        if (!p)
2214
            goto parse_error;
2215 2216 2217 2218 2219 2220 2221 2222

        if (VIR_STRNDUP(result[i].path, temp, p - temp) < 0)
            goto cleanup;

        /* value */
        temp = p + 1;

        if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT)) {
2223
            if (virStrToLong_uip(temp, &p, 10, &result[i].weight) < 0)
2224
                goto number_error;
2225
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS)) {
2226
            if (virStrToLong_uip(temp, &p, 10, &result[i].riops) < 0)
2227
                goto number_error;
2228
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS)) {
2229
            if (virStrToLong_uip(temp, &p, 10, &result[i].wiops) < 0)
2230
                goto number_error;
2231
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS)) {
2232
            if (virStrToLong_ullp(temp, &p, 10, &result[i].rbps) < 0)
2233
                goto number_error;
2234
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
2235
            if (virStrToLong_ullp(temp, &p, 10, &result[i].wbps) < 0)
2236
                goto number_error;
2237
        } else {
2238 2239 2240
            virReportError(VIR_ERR_INVALID_ARG,
                           _("unknown parameter '%s'"), type);
            goto cleanup;
2241 2242 2243 2244 2245 2246 2247
        }

        i++;

        if (*p == '\0')
            break;
        else if (*p != ',')
2248
            goto parse_error;
2249 2250 2251 2252 2253 2254 2255 2256 2257 2258 2259
        temp = p + 1;
    }

    if (!i)
        VIR_FREE(result);

    *dev = result;
    *size = i;

    return 0;

2260
 parse_error:
2261 2262 2263
    virReportError(VIR_ERR_INVALID_ARG,
                   _("unable to parse blkio device '%s' '%s'"),
                   type, blkioDeviceStr);
2264 2265 2266 2267 2268 2269 2270
    goto cleanup;

 number_error:
    virReportError(VIR_ERR_INVALID_ARG,
                   _("invalid value '%s' for parameter '%s' of device '%s'"),
                   temp, type, result[i].path);

2271
 cleanup:
J
John Ferlan 已提交
2272 2273 2274 2275
    if (result) {
        virBlkioDeviceArrayClear(result, ndevices);
        VIR_FREE(result);
    }
2276 2277 2278 2279 2280 2281 2282 2283 2284 2285 2286 2287 2288 2289 2290 2291 2292 2293 2294 2295 2296 2297
    return -1;
}

static int
lxcDomainMergeBlkioDevice(virBlkioDevicePtr *dest_array,
                          size_t *dest_size,
                          virBlkioDevicePtr src_array,
                          size_t src_size,
                          const char *type)
{
    size_t i, j;
    virBlkioDevicePtr dest, src;

    for (i = 0; i < src_size; i++) {
        bool found = false;

        src = &src_array[i];
        for (j = 0; j < *dest_size; j++) {
            dest = &(*dest_array)[j];
            if (STREQ(src->path, dest->path)) {
                found = true;

2298
                if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT)) {
2299
                    dest->weight = src->weight;
2300
                } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS)) {
2301
                    dest->riops = src->riops;
2302
                } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS)) {
2303
                    dest->wiops = src->wiops;
2304
                } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS)) {
2305
                    dest->rbps = src->rbps;
2306
                } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
2307
                    dest->wbps = src->wbps;
2308
                } else {
2309 2310 2311 2312 2313 2314 2315 2316 2317 2318 2319 2320 2321 2322 2323
                    virReportError(VIR_ERR_INVALID_ARG, _("Unknown parameter %s"),
                                   type);
                    return -1;
                }

                break;
            }
        }
        if (!found) {
            if (!src->weight && !src->riops && !src->wiops && !src->rbps && !src->wbps)
                continue;
            if (VIR_EXPAND_N(*dest_array, *dest_size, 1) < 0)
                return -1;
            dest = &(*dest_array)[*dest_size - 1];

2324
            if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT)) {
2325
                dest->weight = src->weight;
2326
            } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS)) {
2327
                dest->riops = src->riops;
2328
            } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS)) {
2329
                dest->wiops = src->wiops;
2330
            } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS)) {
2331
                dest->rbps = src->rbps;
2332
            } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
2333
                dest->wbps = src->wbps;
2334
            } else {
2335 2336 2337 2338 2339 2340 2341 2342 2343 2344 2345 2346
                *dest_size = *dest_size - 1;
                return -1;
            }

            dest->path = src->path;
            src->path = NULL;
        }
    }

    return 0;
}

2347

2348 2349 2350
static int
lxcDomainBlockStats(virDomainPtr dom,
                    const char *path,
2351
                    virDomainBlockStatsPtr stats)
2352
{
2353
    virLXCDriverPtr driver = dom->conn->privateData;
2354
    int ret = -1;
2355 2356 2357 2358 2359 2360 2361 2362 2363 2364 2365 2366
    virDomainObjPtr vm;
    virDomainDiskDefPtr disk = NULL;
    virLXCDomainObjPrivatePtr priv;

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    priv = vm->privateData;

    if (virDomainBlockStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2367 2368 2369
   if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_QUERY) < 0)
        goto cleanup;

2370
    if (virDomainObjCheckActive(vm) < 0)
2371
        goto endjob;
2372 2373 2374 2375

    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("blkio cgroup isn't mounted"));
2376
        goto endjob;
2377 2378 2379 2380 2381 2382 2383 2384 2385
    }

    if (!*path) {
        /* empty path - return entire domain blkstats instead */
        ret = virCgroupGetBlkioIoServiced(priv->cgroup,
                                          &stats->rd_bytes,
                                          &stats->wr_bytes,
                                          &stats->rd_req,
                                          &stats->wr_req);
2386
        goto endjob;
2387 2388
    }

2389
    if (!(disk = virDomainDiskByName(vm->def, path, false))) {
2390 2391
        virReportError(VIR_ERR_INVALID_ARG,
                       _("invalid path: %s"), path);
2392
        goto endjob;
2393 2394 2395 2396 2397
    }

    if (!disk->info.alias) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("missing disk device alias name for %s"), disk->dst);
2398
        goto endjob;
2399 2400 2401 2402 2403 2404 2405 2406
    }

    ret = virCgroupGetBlkioIoDeviceServiced(priv->cgroup,
                                            disk->info.alias,
                                            &stats->rd_bytes,
                                            &stats->wr_bytes,
                                            &stats->rd_req,
                                            &stats->wr_req);
2407 2408

 endjob:
2409
    virLXCDomainObjEndJob(driver, vm);
2410

2411
 cleanup:
2412
    virDomainObjEndAPI(&vm);
2413 2414 2415 2416 2417 2418 2419 2420 2421 2422 2423
    return ret;
}


static int
lxcDomainBlockStatsFlags(virDomainPtr dom,
                         const char * path,
                         virTypedParameterPtr params,
                         int * nparams,
                         unsigned int flags)
{
2424
    virLXCDriverPtr driver = dom->conn->privateData;
2425
    int tmp, ret = -1;
2426 2427 2428 2429 2430 2431 2432 2433 2434 2435 2436 2437 2438 2439 2440 2441 2442 2443 2444 2445 2446 2447 2448 2449
    virDomainObjPtr vm;
    virDomainDiskDefPtr disk = NULL;
    virLXCDomainObjPrivatePtr priv;
    long long rd_req, rd_bytes, wr_req, wr_bytes;
    virTypedParameterPtr param;

    virCheckFlags(VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We don't return strings, and thus trivially support this flag.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;

    if (!params && !*nparams) {
        *nparams = LXC_NB_DOMAIN_BLOCK_STAT_PARAM;
        return 0;
    }

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    priv = vm->privateData;

    if (virDomainBlockStatsFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2450 2451 2452
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_QUERY) < 0)
        goto cleanup;

2453
    if (virDomainObjCheckActive(vm) < 0)
2454
        goto endjob;
2455 2456 2457 2458

    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("blkio cgroup isn't mounted"));
2459
        goto endjob;
2460 2461 2462 2463 2464 2465 2466 2467 2468 2469 2470
    }

    if (!*path) {
        /* empty path - return entire domain blkstats instead */
        if (virCgroupGetBlkioIoServiced(priv->cgroup,
                                        &rd_bytes,
                                        &wr_bytes,
                                        &rd_req,
                                        &wr_req) < 0) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("domain stats query failed"));
2471
            goto endjob;
2472 2473
        }
    } else {
2474
        if (!(disk = virDomainDiskByName(vm->def, path, false))) {
2475 2476
            virReportError(VIR_ERR_INVALID_ARG,
                           _("invalid path: %s"), path);
2477
            goto endjob;
2478 2479 2480 2481 2482
        }

        if (!disk->info.alias) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("missing disk device alias name for %s"), disk->dst);
2483
            goto endjob;
2484 2485 2486 2487 2488 2489 2490 2491 2492 2493
        }

        if (virCgroupGetBlkioIoDeviceServiced(priv->cgroup,
                                              disk->info.alias,
                                              &rd_bytes,
                                              &wr_bytes,
                                              &rd_req,
                                              &wr_req) < 0) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("domain stats query failed"));
2494
            goto endjob;
2495 2496 2497 2498 2499 2500 2501 2502 2503 2504
        }
    }

    tmp = 0;
    ret = -1;

    if (tmp < *nparams && wr_bytes != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_WRITE_BYTES,
                                    VIR_TYPED_PARAM_LLONG, wr_bytes) < 0)
2505
            goto endjob;
2506 2507 2508 2509 2510 2511 2512
        tmp++;
    }

    if (tmp < *nparams && wr_req != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_WRITE_REQ,
                                    VIR_TYPED_PARAM_LLONG, wr_req) < 0)
2513
            goto endjob;
2514 2515 2516 2517 2518 2519 2520
        tmp++;
    }

    if (tmp < *nparams && rd_bytes != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_READ_BYTES,
                                    VIR_TYPED_PARAM_LLONG, rd_bytes) < 0)
2521
            goto endjob;
2522 2523 2524 2525 2526 2527 2528
        tmp++;
    }

    if (tmp < *nparams && rd_req != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_READ_REQ,
                                    VIR_TYPED_PARAM_LLONG, rd_req) < 0)
2529
            goto endjob;
2530 2531 2532 2533 2534 2535
        tmp++;
    }

    ret = 0;
    *nparams = tmp;

2536
 endjob:
2537
    virLXCDomainObjEndJob(driver, vm);
2538

2539
 cleanup:
2540
    virDomainObjEndAPI(&vm);
2541 2542 2543 2544
    return ret;
}


2545 2546 2547 2548 2549
static int
lxcDomainSetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int nparams,
                            unsigned int flags)
2550
{
2551
    virLXCDriverPtr driver = dom->conn->privateData;
2552
    size_t i;
2553
    virDomainObjPtr vm = NULL;
2554
    virDomainDefPtr def = NULL;
2555 2556
    virDomainDefPtr persistentDef = NULL;
    int ret = -1;
2557
    virLXCDriverConfigPtr cfg = NULL;
2558
    virLXCDomainObjPrivatePtr priv;
2559 2560 2561

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
2562 2563 2564
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_BLKIO_WEIGHT,
                               VIR_TYPED_PARAM_UINT,
2565 2566 2567 2568 2569 2570 2571 2572 2573 2574
                               VIR_DOMAIN_BLKIO_DEVICE_WEIGHT,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_READ_BPS,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS,
                               VIR_TYPED_PARAM_STRING,
2575
                               NULL) < 0)
2576 2577
        return -1;

M
Michal Privoznik 已提交
2578
    if (!(vm = lxcDomObjFromDomain(dom)))
2579
        return -1;
M
Michal Privoznik 已提交
2580

2581
    priv = vm->privateData;
2582
    cfg = virLXCDriverGetConfig(driver);
2583

2584 2585 2586
    if (virDomainSetBlkioParametersEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

2587 2588 2589
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

2590
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
2591
        goto endjob;
2592

2593
    if (def) {
2594
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
2595 2596
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2597
            goto endjob;
2598
        }
2599
    }
2600

2601
    ret = 0;
2602
    if (def) {
2603 2604 2605 2606
        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
2607
                if (virCgroupSetBlkioWeight(priv->cgroup, params[i].value.ui) < 0)
2608 2609 2610 2611 2612 2613 2614 2615 2616 2617 2618 2619 2620 2621 2622 2623 2624 2625 2626 2627 2628 2629
                    ret = -1;
            } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
                size_t ndevices;
                virBlkioDevicePtr devices = NULL;
                size_t j;

                if (lxcDomainParseBlkioDeviceStr(params[i].value.s,
                                                 param->field,
                                                 &devices,
                                                 &ndevices) < 0) {
                    ret = -1;
                    continue;
                }

                if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceWeight(priv->cgroup,
                                                          devices[j].path,
2630 2631 2632 2633
                                                          devices[j].weight) < 0 ||
                            virCgroupGetBlkioDeviceWeight(priv->cgroup,
                                                          devices[j].path,
                                                          &devices[j].weight) < 0) {
2634 2635 2636 2637 2638 2639 2640 2641
                            ret = -1;
                            break;
                        }
                    }
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceReadIops(priv->cgroup,
                                                            devices[j].path,
2642 2643 2644 2645
                                                            devices[j].riops) < 0 ||
                            virCgroupGetBlkioDeviceReadIops(priv->cgroup,
                                                            devices[j].path,
                                                            &devices[j].riops) < 0) {
2646 2647 2648 2649 2650 2651 2652 2653
                            ret = -1;
                            break;
                        }
                    }
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceWriteIops(priv->cgroup,
                                                             devices[j].path,
2654 2655 2656 2657
                                                             devices[j].wiops) < 0 ||
                            virCgroupGetBlkioDeviceWriteIops(priv->cgroup,
                                                             devices[j].path,
                                                             &devices[j].wiops) < 0) {
2658 2659 2660 2661 2662 2663 2664 2665
                            ret = -1;
                            break;
                        }
                    }
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceReadBps(priv->cgroup,
                                                           devices[j].path,
2666 2667 2668 2669
                                                           devices[j].rbps) < 0 ||
                            virCgroupGetBlkioDeviceReadBps(priv->cgroup,
                                                           devices[j].path,
                                                           &devices[j].rbps) < 0) {
2670 2671 2672 2673
                            ret = -1;
                            break;
                        }
                    }
2674
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
2675 2676 2677
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceWriteBps(priv->cgroup,
                                                            devices[j].path,
2678 2679 2680 2681
                                                            devices[j].wbps) < 0 ||
                            virCgroupGetBlkioDeviceWriteBps(priv->cgroup,
                                                            devices[j].path,
                                                            &devices[j].wbps) < 0) {
2682 2683 2684 2685 2686 2687 2688 2689 2690 2691 2692 2693 2694 2695 2696
                            ret = -1;
                            break;
                        }
                    }
                } else {
                    virReportError(VIR_ERR_INVALID_ARG, _("Unknown blkio parameter %s"),
                                   param->field);
                    ret = -1;
                    virBlkioDeviceArrayClear(devices, ndevices);
                    VIR_FREE(devices);

                    continue;
                }

                if (j != ndevices ||
2697 2698
                    lxcDomainMergeBlkioDevice(&def->blkio.devices,
                                              &def->blkio.ndevices,
2699 2700 2701 2702
                                              devices, ndevices, param->field) < 0)
                    ret = -1;
                virBlkioDeviceArrayClear(devices, ndevices);
                VIR_FREE(devices);
2703 2704
            }
        }
E
Eric Blake 已提交
2705
    }
2706
    if (ret < 0)
2707
        goto endjob;
2708
    if (persistentDef) {
2709 2710 2711 2712 2713
        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
                persistentDef->blkio.weight = params[i].value.ui;
2714 2715 2716 2717 2718 2719 2720 2721 2722 2723 2724 2725 2726 2727 2728 2729 2730 2731 2732 2733 2734
            } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
                virBlkioDevicePtr devices = NULL;
                size_t ndevices;

                if (lxcDomainParseBlkioDeviceStr(params[i].value.s,
                                                 param->field,
                                                 &devices,
                                                 &ndevices) < 0) {
                    ret = -1;
                    continue;
                }
                if (lxcDomainMergeBlkioDevice(&persistentDef->blkio.devices,
                                              &persistentDef->blkio.ndevices,
                                              devices, ndevices, param->field) < 0)
                    ret = -1;
                virBlkioDeviceArrayClear(devices, ndevices);
                VIR_FREE(devices);
2735 2736 2737
            }
        }

2738
        if (virDomainSaveConfig(cfg->configDir, driver->caps, persistentDef) < 0)
2739
            ret = -1;
2740 2741
    }

2742
 endjob:
2743
    virLXCDomainObjEndJob(driver, vm);
2744

2745
 cleanup:
2746
    virDomainObjEndAPI(&vm);
2747
    virObjectUnref(cfg);
2748 2749 2750 2751
    return ret;
}


2752 2753
#define LXC_NB_BLKIO_PARAM  6

2754 2755 2756 2757 2758
static int
lxcDomainGetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int *nparams,
                            unsigned int flags)
2759 2760
{
    virDomainObjPtr vm = NULL;
2761
    virDomainDefPtr def = NULL;
2762
    virDomainDefPtr persistentDef = NULL;
2763
    int maxparams = LXC_NB_BLKIO_PARAM;
2764 2765
    unsigned int val;
    int ret = -1;
2766
    virLXCDomainObjPrivatePtr priv;
2767 2768

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
2769 2770 2771 2772 2773 2774 2775
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We blindly return a string, and let libvirt.c and
     * remote_driver.c do the filtering on behalf of older clients
     * that can't parse it.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;
2776

M
Michal Privoznik 已提交
2777
    if (!(vm = lxcDomObjFromDomain(dom)))
2778
        return -1;
M
Michal Privoznik 已提交
2779

2780
    priv = vm->privateData;
2781

2782 2783 2784
    if (virDomainGetBlkioParametersEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2785 2786 2787 2788 2789
    if ((*nparams) == 0) {
        /* Current number of blkio parameters supported by cgroups */
        *nparams = LXC_NB_BLKIO_PARAM;
        ret = 0;
        goto cleanup;
2790 2791
    } else if (*nparams < maxparams) {
        maxparams = *nparams;
2792 2793
    }

2794 2795
    *nparams = 0;

2796
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
E
Eric Blake 已提交
2797
        goto cleanup;
2798

2799
    if (def) {
2800
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
2801 2802
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2803 2804 2805
            goto cleanup;
        }

2806 2807 2808 2809 2810 2811 2812
        /* fill blkio weight here */
        if (virCgroupGetBlkioWeight(priv->cgroup, &val) < 0)
            goto cleanup;
        if (virTypedParameterAssign(&(params[(*nparams)++]),
                                    VIR_DOMAIN_BLKIO_WEIGHT,
                                    VIR_TYPED_PARAM_UINT, val) < 0)
            goto cleanup;
2813

2814 2815 2816
        if (virDomainGetBlkioParametersAssignFromDef(def, params, nparams,
                                                     maxparams) < 0)
            goto cleanup;
2817

2818
    } else if (persistentDef) {
2819 2820 2821 2822 2823 2824
        /* fill blkio weight here */
        if (virTypedParameterAssign(&(params[(*nparams)++]),
                                    VIR_DOMAIN_BLKIO_WEIGHT,
                                    VIR_TYPED_PARAM_UINT,
                                    persistentDef->blkio.weight) < 0)
            goto cleanup;
2825

2826 2827 2828
        if (virDomainGetBlkioParametersAssignFromDef(persistentDef, params,
                                                     nparams, maxparams) < 0)
            goto cleanup;
2829 2830 2831 2832
    }

    ret = 0;

2833
 cleanup:
2834
    virDomainObjEndAPI(&vm);
2835 2836 2837 2838
    return ret;
}


2839 2840
static int
lxcDomainInterfaceStats(virDomainPtr dom,
2841
                        const char *device,
2842
                        virDomainInterfaceStatsPtr stats)
2843 2844 2845
{
    virDomainObjPtr vm;
    int ret = -1;
2846
    virLXCDriverPtr driver = dom->conn->privateData;
M
Michal Privoznik 已提交
2847
    virDomainNetDefPtr net = NULL;
2848

M
Michal Privoznik 已提交
2849
    if (!(vm = lxcDomObjFromDomain(dom)))
2850 2851
        goto cleanup;

2852 2853 2854
    if (virDomainInterfaceStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2855 2856 2857
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_QUERY) < 0)
        goto cleanup;

2858
    if (virDomainObjCheckActive(vm) < 0)
2859
        goto endjob;
2860

2861
    if (!(net = virDomainNetFind(vm->def, device)))
M
Michal Privoznik 已提交
2862 2863
        goto endjob;

2864
    if (virNetDevTapInterfaceStats(net->ifname, stats,
2865
                                   !virDomainNetTypeSharesHostView(net)) < 0)
M
Michal Privoznik 已提交
2866 2867 2868
        goto endjob;

    ret = 0;
2869

2870
 endjob:
2871
    virLXCDomainObjEndJob(driver, vm);
2872

2873
 cleanup:
2874
    virDomainObjEndAPI(&vm);
2875 2876
    return ret;
}
2877

2878

2879
static int lxcDomainGetAutostart(virDomainPtr dom,
2880 2881
                                   int *autostart)
{
2882 2883 2884
    virDomainObjPtr vm;
    int ret = -1;

M
Michal Privoznik 已提交
2885
    if (!(vm = lxcDomObjFromDomain(dom)))
2886 2887
        goto cleanup;

2888 2889 2890
    if (virDomainGetAutostartEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2891 2892 2893
    *autostart = vm->autostart;
    ret = 0;

2894
 cleanup:
2895
    virDomainObjEndAPI(&vm);
2896 2897 2898 2899
    return ret;
}

static int lxcDomainSetAutostart(virDomainPtr dom,
2900 2901
                                   int autostart)
{
2902
    virLXCDriverPtr driver = dom->conn->privateData;
2903 2904 2905
    virDomainObjPtr vm;
    char *configFile = NULL, *autostartLink = NULL;
    int ret = -1;
2906
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
2907

M
Michal Privoznik 已提交
2908
    if (!(vm = lxcDomObjFromDomain(dom)))
2909 2910
        goto cleanup;

2911 2912 2913
    if (virDomainSetAutostartEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2914 2915 2916
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

2917
    if (!vm->persistent) {
2918 2919
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot set autostart for transient domain"));
2920
        goto endjob;
2921 2922 2923 2924
    }

    autostart = (autostart != 0);

2925 2926
    if (vm->autostart == autostart) {
        ret = 0;
2927
        goto endjob;
2928
    }
2929

2930
    configFile = virDomainConfigFile(cfg->configDir,
2931 2932
                                     vm->def->name);
    if (configFile == NULL)
2933
        goto endjob;
2934
    autostartLink = virDomainConfigFile(cfg->autostartDir,
2935 2936
                                        vm->def->name);
    if (autostartLink == NULL)
2937
        goto endjob;
2938

2939
    if (autostart) {
2940
        if (virFileMakePath(cfg->autostartDir) < 0) {
2941
            virReportSystemError(errno,
2942
                                 _("Cannot create autostart directory %s"),
2943
                                 cfg->autostartDir);
2944
            goto endjob;
2945 2946
        }

2947
        if (symlink(configFile, autostartLink) < 0) {
2948
            virReportSystemError(errno,
2949 2950
                                 _("Failed to create symlink '%s to '%s'"),
                                 autostartLink, configFile);
2951
            goto endjob;
2952 2953 2954
        }
    } else {
        if (unlink(autostartLink) < 0 && errno != ENOENT && errno != ENOTDIR) {
2955
            virReportSystemError(errno,
2956 2957
                                 _("Failed to delete symlink '%s'"),
                                 autostartLink);
2958
            goto endjob;
2959
        }
2960
    }
2961 2962

    vm->autostart = autostart;
2963 2964
    ret = 0;

2965
 endjob:
2966 2967
    virLXCDomainObjEndJob(driver, vm);

2968
 cleanup:
2969 2970
    VIR_FREE(configFile);
    VIR_FREE(autostartLink);
2971
    virDomainObjEndAPI(&vm);
2972
    virObjectUnref(cfg);
2973 2974 2975
    return ret;
}

2976
static int lxcFreezeContainer(virDomainObjPtr vm)
R
Ryota Ozaki 已提交
2977 2978 2979 2980 2981 2982 2983
{
    int timeout = 1000; /* In milliseconds */
    int check_interval = 1; /* In milliseconds */
    int exp = 10;
    int waited_time = 0;
    int ret = -1;
    char *state = NULL;
2984
    virLXCDomainObjPrivatePtr priv = vm->privateData;
2985

R
Ryota Ozaki 已提交
2986 2987 2988 2989 2990 2991 2992 2993 2994
    while (waited_time < timeout) {
        int r;
        /*
         * Writing "FROZEN" to the "freezer.state" freezes the group,
         * i.e., the container, temporarily transiting "FREEZING" state.
         * Once the freezing is completed, the state of the group transits
         * to "FROZEN".
         * (see linux-2.6/Documentation/cgroups/freezer-subsystem.txt)
         */
2995
        r = virCgroupSetFreezerState(priv->cgroup, "FROZEN");
R
Ryota Ozaki 已提交
2996 2997 2998

        /*
         * Returning EBUSY explicitly indicates that the group is
2999
         * being frozen but incomplete, and other errors are true
R
Ryota Ozaki 已提交
3000 3001 3002 3003 3004 3005 3006
         * errors.
         */
        if (r < 0 && r != -EBUSY) {
            VIR_DEBUG("Writing freezer.state failed with errno: %d", r);
            goto error;
        }
        if (r == -EBUSY)
3007
            VIR_DEBUG("Writing freezer.state gets EBUSY");
R
Ryota Ozaki 已提交
3008 3009 3010 3011 3012 3013 3014 3015 3016 3017 3018 3019 3020 3021

        /*
         * Unfortunately, returning 0 (success) is likely to happen
         * even when the freezing has not been completed. Sometimes
         * the state of the group remains "FREEZING" like when
         * returning -EBUSY and even worse may never transit to
         * "FROZEN" even if writing "FROZEN" again.
         *
         * So we don't trust the return value anyway and always
         * decide that the freezing has been complete only with
         * the state actually transit to "FROZEN".
         */
        usleep(check_interval * 1000);

3022
        r = virCgroupGetFreezerState(priv->cgroup, &state);
R
Ryota Ozaki 已提交
3023 3024 3025 3026 3027 3028 3029 3030 3031 3032 3033 3034 3035 3036 3037 3038 3039 3040 3041 3042 3043 3044 3045 3046

        if (r < 0) {
            VIR_DEBUG("Reading freezer.state failed with errno: %d", r);
            goto error;
        }
        VIR_DEBUG("Read freezer.state: %s", state);

        if (STREQ(state, "FROZEN")) {
            ret = 0;
            goto cleanup;
        }

        waited_time += check_interval;
        /*
         * Increasing check_interval exponentially starting with
         * small initial value treats nicely two cases; One is
         * a container is under no load and waiting for long period
         * makes no sense. The other is under heavy load. The container
         * may stay longer time in FREEZING or never transit to FROZEN.
         * In that case, eager polling will just waste CPU time.
         */
        check_interval *= exp;
        VIR_FREE(state);
    }
3047
    VIR_DEBUG("lxcFreezeContainer timeout");
3048
 error:
R
Ryota Ozaki 已提交
3049 3050 3051 3052 3053
    /*
     * If timeout or an error on reading the state occurs,
     * activate the group again and return an error.
     * This is likely to fall the group back again gracefully.
     */
3054
    virCgroupSetFreezerState(priv->cgroup, "THAWED");
R
Ryota Ozaki 已提交
3055 3056
    ret = -1;

3057
 cleanup:
R
Ryota Ozaki 已提交
3058 3059 3060 3061 3062 3063
    VIR_FREE(state);
    return ret;
}

static int lxcDomainSuspend(virDomainPtr dom)
{
3064
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
3065
    virDomainObjPtr vm;
3066
    virObjectEventPtr event = NULL;
R
Ryota Ozaki 已提交
3067
    int ret = -1;
3068
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
3069

M
Michal Privoznik 已提交
3070
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
3071 3072
        goto cleanup;

3073 3074 3075
    if (virDomainSuspendEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3076 3077 3078
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

3079
    if (virDomainObjCheckActive(vm) < 0)
3080
        goto endjob;
R
Ryota Ozaki 已提交
3081

J
Jiri Denemark 已提交
3082
    if (virDomainObjGetState(vm, NULL) != VIR_DOMAIN_PAUSED) {
3083
        if (lxcFreezeContainer(vm) < 0) {
3084 3085
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Suspend operation failed"));
3086
            goto endjob;
R
Ryota Ozaki 已提交
3087
        }
J
Jiri Denemark 已提交
3088
        virDomainObjSetState(vm, VIR_DOMAIN_PAUSED, VIR_DOMAIN_PAUSED_USER);
R
Ryota Ozaki 已提交
3089

3090
        event = virDomainEventLifecycleNewFromObj(vm,
R
Ryota Ozaki 已提交
3091 3092 3093 3094
                                         VIR_DOMAIN_EVENT_SUSPENDED,
                                         VIR_DOMAIN_EVENT_SUSPENDED_PAUSED);
    }

3095
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0)
3096
        goto endjob;
R
Ryota Ozaki 已提交
3097 3098
    ret = 0;

3099
 endjob:
3100 3101
    virLXCDomainObjEndJob(driver, vm);

3102
 cleanup:
R
Ryota Ozaki 已提交
3103
    if (event)
3104
        virObjectEventStateQueue(driver->domainEventState, event);
3105
    virDomainObjEndAPI(&vm);
3106
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
3107 3108 3109 3110 3111
    return ret;
}

static int lxcDomainResume(virDomainPtr dom)
{
3112
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
3113
    virDomainObjPtr vm;
3114
    virObjectEventPtr event = NULL;
R
Ryota Ozaki 已提交
3115
    int ret = -1;
3116
    int state;
3117
    virLXCDomainObjPrivatePtr priv;
3118
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
3119

M
Michal Privoznik 已提交
3120
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
3121 3122
        goto cleanup;

3123 3124
    priv = vm->privateData;

3125 3126 3127
    if (virDomainResumeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3128 3129 3130
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

3131
    if (virDomainObjCheckActive(vm) < 0)
3132
        goto endjob;
R
Ryota Ozaki 已提交
3133

3134 3135 3136 3137 3138 3139
    state = virDomainObjGetState(vm, NULL);
    if (state == VIR_DOMAIN_RUNNING) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is already running"));
        goto endjob;
    } else if (state == VIR_DOMAIN_PAUSED) {
3140
        if (virCgroupSetFreezerState(priv->cgroup, "THAWED") < 0) {
3141 3142
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Resume operation failed"));
3143
            goto endjob;
R
Ryota Ozaki 已提交
3144
        }
J
Jiri Denemark 已提交
3145 3146
        virDomainObjSetState(vm, VIR_DOMAIN_RUNNING,
                             VIR_DOMAIN_RUNNING_UNPAUSED);
R
Ryota Ozaki 已提交
3147

3148
        event = virDomainEventLifecycleNewFromObj(vm,
R
Ryota Ozaki 已提交
3149 3150 3151 3152
                                         VIR_DOMAIN_EVENT_RESUMED,
                                         VIR_DOMAIN_EVENT_RESUMED_UNPAUSED);
    }

3153
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0)
3154
        goto endjob;
R
Ryota Ozaki 已提交
3155 3156
    ret = 0;

3157
 endjob:
3158 3159
    virLXCDomainObjEndJob(driver, vm);

3160
 cleanup:
R
Ryota Ozaki 已提交
3161
    if (event)
3162
        virObjectEventStateQueue(driver->domainEventState, event);
3163
    virDomainObjEndAPI(&vm);
3164
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
3165 3166 3167
    return ret;
}

3168 3169
static int
lxcDomainOpenConsole(virDomainPtr dom,
3170
                      const char *dev_name,
3171 3172 3173 3174 3175 3176
                      virStreamPtr st,
                      unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    int ret = -1;
    virDomainChrDefPtr chr = NULL;
3177
    size_t i;
3178 3179 3180

    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
3181
    if (!(vm = lxcDomObjFromDomain(dom)))
3182 3183
        goto cleanup;

3184 3185 3186
    if (virDomainOpenConsoleEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3187
    if (virDomainObjCheckActive(vm) < 0)
3188 3189
        goto cleanup;

3190
    if (dev_name) {
3191
        for (i = 0; i < vm->def->nconsoles; i++) {
3192 3193 3194 3195 3196 3197
            if (vm->def->consoles[i]->info.alias &&
                STREQ(vm->def->consoles[i]->info.alias, dev_name)) {
                chr = vm->def->consoles[i];
                break;
            }
        }
3198
    } else {
3199 3200
        if (vm->def->nconsoles)
            chr = vm->def->consoles[0];
3201 3202 3203 3204 3205
        else if (vm->def->nserials)
            chr = vm->def->serials[0];
    }

    if (!chr) {
3206 3207 3208
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot find console device '%s'"),
                       dev_name ? dev_name : _("default"));
3209 3210 3211
        goto cleanup;
    }

3212
    if (chr->source->type != VIR_DOMAIN_CHR_TYPE_PTY) {
3213
        virReportError(VIR_ERR_INTERNAL_ERROR,
3214 3215
                       _("character device %s is not using a PTY"),
                       dev_name ? dev_name : NULLSTR(chr->info.alias));
3216 3217 3218
        goto cleanup;
    }

3219
    if (virFDStreamOpenFile(st, chr->source->data.file.path,
E
Eric Blake 已提交
3220
                            0, 0, O_RDWR) < 0)
3221 3222 3223
        goto cleanup;

    ret = 0;
3224
 cleanup:
3225
    virDomainObjEndAPI(&vm);
3226 3227 3228
    return ret;
}

3229 3230 3231 3232 3233 3234 3235

static int
lxcDomainSendProcessSignal(virDomainPtr dom,
                           long long pid_value,
                           unsigned int signum,
                           unsigned int flags)
{
3236
    virLXCDriverPtr driver = dom->conn->privateData;
3237 3238 3239 3240 3241 3242 3243 3244 3245 3246 3247 3248 3249 3250
    virDomainObjPtr vm = NULL;
    virLXCDomainObjPrivatePtr priv;
    pid_t victim;
    int ret = -1;

    virCheckFlags(0, -1);

    if (signum >= VIR_DOMAIN_PROCESS_SIGNAL_LAST) {
        virReportError(VIR_ERR_INVALID_ARG,
                       _("signum value %d is out of range"),
                       signum);
        return -1;
    }

M
Michal Privoznik 已提交
3251
    if (!(vm = lxcDomObjFromDomain(dom)))
3252
        goto cleanup;
M
Michal Privoznik 已提交
3253

3254 3255
    priv = vm->privateData;

3256 3257 3258
    if (virDomainSendProcessSignalEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3259 3260 3261
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

3262
    if (virDomainObjCheckActive(vm) < 0)
3263
        goto endjob;
3264 3265 3266 3267 3268 3269 3270 3271 3272 3273 3274

    /*
     * XXX if the kernel has /proc/$PID/ns/pid we can
     * switch into container namespace & that way be
     * able to kill any PID. Alternatively if there
     * is a way to find a mapping of guest<->host PIDs
     * we can kill that way.
     */
    if (pid_value != 1) {
        virReportError(VIR_ERR_ARGUMENT_UNSUPPORTED, "%s",
                       _("Only the init process may be killed"));
3275
        goto endjob;
3276 3277 3278 3279 3280
    }

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
3281
        goto endjob;
3282 3283 3284 3285 3286 3287 3288 3289 3290 3291
    }
    victim = priv->initpid;

    /* We're relying on fact libvirt header signal numbers
     * are taken from Linux, to avoid mapping
     */
    if (kill(victim, signum) < 0) {
        virReportSystemError(errno,
                             _("Unable to send %d signal to process %d"),
                             signum, victim);
3292
        goto endjob;
3293 3294 3295 3296
    }

    ret = 0;

3297
 endjob:
3298
    virLXCDomainObjEndJob(driver, vm);
3299

3300
 cleanup:
3301
    virDomainObjEndAPI(&vm);
3302 3303 3304 3305
    return ret;
}


3306
static int
3307 3308
lxcConnectListAllDomains(virConnectPtr conn,
                         virDomainPtr **domains,
3309 3310
                  unsigned int flags)
{
3311
    virLXCDriverPtr driver = conn->privateData;
3312 3313
    int ret = -1;

O
Osier Yang 已提交
3314
    virCheckFlags(VIR_CONNECT_LIST_DOMAINS_FILTERS_ALL, -1);
3315

3316 3317 3318
    if (virConnectListAllDomainsEnsureACL(conn) < 0)
        return -1;

3319 3320
    ret = virDomainObjListExport(driver->domains, conn, domains,
                                 virConnectListAllDomainsCheckACL, flags);
3321 3322 3323
    return ret;
}

3324

3325 3326 3327 3328 3329 3330 3331 3332 3333
static int
lxcDomainInitctlCallback(pid_t pid ATTRIBUTE_UNUSED,
                         void *opaque)
{
    int *command = opaque;
    return virInitctlSetRunLevel(*command);
}


3334 3335 3336 3337
static int
lxcDomainShutdownFlags(virDomainPtr dom,
                       unsigned int flags)
{
3338
    virLXCDriverPtr driver = dom->conn->privateData;
3339 3340 3341
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    int ret = -1;
3342
    int rc;
3343 3344 3345 3346

    virCheckFlags(VIR_DOMAIN_SHUTDOWN_INITCTL |
                  VIR_DOMAIN_SHUTDOWN_SIGNAL, -1);

M
Michal Privoznik 已提交
3347
    if (!(vm = lxcDomObjFromDomain(dom)))
3348 3349 3350 3351
        goto cleanup;

    priv = vm->privateData;

3352
    if (virDomainShutdownFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
3353 3354
        goto cleanup;

3355 3356 3357
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

3358
    if (virDomainObjCheckActive(vm) < 0)
3359
        goto endjob;
3360 3361 3362 3363

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
3364
        goto endjob;
3365 3366
    }

3367 3368
    if (flags == 0 ||
        (flags & VIR_DOMAIN_SHUTDOWN_INITCTL)) {
3369 3370 3371 3372 3373
        int command = VIR_INITCTL_RUNLEVEL_POWEROFF;

        if ((rc = virProcessRunInMountNamespace(priv->initpid,
                                                lxcDomainInitctlCallback,
                                                &command)) < 0)
3374
            goto endjob;
3375 3376
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
3377 3378
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
3379
            goto endjob;
3380
        }
3381 3382
    } else {
        rc = 0;
3383
    }
3384

3385 3386 3387
    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_SHUTDOWN_SIGNAL))) {
3388 3389
        if (kill(priv->initpid, SIGTERM) < 0 &&
            errno != ESRCH) {
3390 3391
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
3392
                                 (long long)priv->initpid);
3393
            goto endjob;
3394 3395 3396 3397 3398
        }
    }

    ret = 0;

3399
 endjob:
3400
    virLXCDomainObjEndJob(driver, vm);
3401

3402
 cleanup:
3403
    virDomainObjEndAPI(&vm);
3404 3405 3406 3407 3408 3409 3410 3411 3412
    return ret;
}

static int
lxcDomainShutdown(virDomainPtr dom)
{
    return lxcDomainShutdownFlags(dom, 0);
}

3413

3414 3415 3416 3417
static int
lxcDomainReboot(virDomainPtr dom,
                unsigned int flags)
{
3418
    virLXCDriverPtr driver = dom->conn->privateData;
3419 3420 3421 3422 3423 3424 3425 3426
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    int ret = -1;
    int rc;

    virCheckFlags(VIR_DOMAIN_REBOOT_INITCTL |
                  VIR_DOMAIN_REBOOT_SIGNAL, -1);

M
Michal Privoznik 已提交
3427
    if (!(vm = lxcDomObjFromDomain(dom)))
3428 3429 3430 3431
        goto cleanup;

    priv = vm->privateData;

3432
    if (virDomainRebootEnsureACL(dom->conn, vm->def, flags) < 0)
3433 3434
        goto cleanup;

3435 3436 3437
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

3438
    if (virDomainObjCheckActive(vm) < 0)
3439
        goto endjob;
3440 3441 3442 3443

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
3444
        goto endjob;
3445 3446 3447 3448
    }

    if (flags == 0 ||
        (flags & VIR_DOMAIN_REBOOT_INITCTL)) {
3449 3450 3451 3452 3453
        int command = VIR_INITCTL_RUNLEVEL_REBOOT;

        if ((rc = virProcessRunInMountNamespace(priv->initpid,
                                                lxcDomainInitctlCallback,
                                                &command)) < 0)
3454
            goto endjob;
3455 3456 3457 3458
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
3459
            goto endjob;
3460 3461 3462 3463 3464 3465 3466 3467 3468 3469 3470 3471
        }
    } else {
        rc = 0;
    }

    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_REBOOT_SIGNAL))) {
        if (kill(priv->initpid, SIGHUP) < 0 &&
            errno != ESRCH) {
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
3472
                                 (long long)priv->initpid);
3473
            goto endjob;
3474 3475 3476 3477 3478
        }
    }

    ret = 0;

3479
 endjob:
3480
    virLXCDomainObjEndJob(driver, vm);
3481

3482
 cleanup:
3483
    virDomainObjEndAPI(&vm);
3484 3485 3486 3487
    return ret;
}


3488
static int
3489
lxcDomainAttachDeviceConfig(virDomainDefPtr vmdef,
3490 3491 3492
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3493
    virDomainDiskDefPtr disk;
3494
    virDomainNetDefPtr net;
3495
    virDomainHostdevDefPtr hostdev;
3496 3497

    switch (dev->type) {
3498 3499 3500 3501 3502 3503 3504
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (virDomainDiskIndexByName(vmdef, disk->dst, true) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("target %s already exists."), disk->dst);
            return -1;
        }
3505
        if (virDomainDiskInsert(vmdef, disk))
3506 3507 3508 3509 3510 3511
            return -1;
        /* vmdef has the pointer. Generic codes for vmdef will do all jobs */
        dev->data.disk = NULL;
        ret = 0;
        break;

3512 3513
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
3514
        if (virDomainNetInsert(vmdef, net) < 0)
3515 3516 3517 3518 3519
            goto cleanup;
        dev->data.net = NULL;
        ret = 0;
        break;

3520 3521 3522 3523 3524 3525 3526
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        hostdev = dev->data.hostdev;
        if (virDomainHostdevFind(vmdef, hostdev, NULL) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device is already in the domain configuration"));
            return -1;
        }
3527
        if (virDomainHostdevInsert(vmdef, hostdev) < 0)
3528 3529 3530 3531 3532
            return -1;
        dev->data.hostdev = NULL;
        ret = 0;
        break;

3533 3534 3535 3536 3537 3538
    default:
         virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                        _("persistent attach of device is not supported"));
         break;
    }

3539
 cleanup:
3540 3541 3542 3543 3544
    return ret;
}


static int
3545
lxcDomainUpdateDeviceConfig(virDomainDefPtr vmdef,
3546 3547 3548
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3549
    virDomainNetDefPtr net;
3550
    virDomainDeviceDef oldDev = { .type = dev->type };
3551
    int idx;
3552 3553

    switch (dev->type) {
3554 3555
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
3556
        if ((idx = virDomainNetFindIdx(vmdef, net)) < 0)
3557 3558
            goto cleanup;

3559 3560 3561
        oldDev.data.net = vmdef->nets[idx];
        if (virDomainDefCompatibleDevice(vmdef, dev, &oldDev) < 0)
            return -1;
3562

3563
        virDomainNetDefFree(vmdef->nets[idx]);
3564 3565 3566 3567 3568 3569
        vmdef->nets[idx] = net;
        dev->data.net = NULL;
        ret = 0;

        break;

3570 3571 3572 3573 3574 3575
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent update of device is not supported"));
        break;
    }

3576
 cleanup:
3577 3578 3579 3580 3581
    return ret;
}


static int
3582
lxcDomainDetachDeviceConfig(virDomainDefPtr vmdef,
3583 3584 3585
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3586
    virDomainDiskDefPtr disk, det_disk;
3587
    virDomainNetDefPtr net;
3588
    virDomainHostdevDefPtr hostdev, det_hostdev;
3589
    int idx;
3590 3591

    switch (dev->type) {
3592 3593 3594 3595 3596 3597 3598 3599 3600 3601 3602
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (!(det_disk = virDomainDiskRemoveByName(vmdef, disk->dst))) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("no target device %s"), disk->dst);
            return -1;
        }
        virDomainDiskDefFree(det_disk);
        ret = 0;
        break;

3603 3604
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
3605
        if ((idx = virDomainNetFindIdx(vmdef, net)) < 0)
3606
            goto cleanup;
3607

3608 3609 3610 3611 3612
        /* this is guaranteed to succeed */
        virDomainNetDefFree(virDomainNetRemove(vmdef, idx));
        ret = 0;
        break;

3613 3614 3615 3616 3617 3618 3619 3620 3621 3622 3623 3624 3625
    case VIR_DOMAIN_DEVICE_HOSTDEV: {
        hostdev = dev->data.hostdev;
        if ((idx = virDomainHostdevFind(vmdef, hostdev, &det_hostdev)) < 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device not present in domain configuration"));
            return -1;
        }
        virDomainHostdevRemove(vmdef, idx);
        virDomainHostdevDefFree(det_hostdev);
        ret = 0;
        break;
    }

3626 3627 3628 3629 3630 3631
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent detach of device is not supported"));
        break;
    }

3632
 cleanup:
3633 3634 3635 3636
    return ret;
}


3637 3638 3639 3640 3641 3642 3643 3644 3645 3646 3647 3648 3649 3650 3651 3652 3653 3654 3655 3656 3657 3658 3659 3660 3661 3662 3663 3664 3665 3666 3667 3668 3669 3670 3671 3672 3673 3674 3675 3676 3677 3678 3679 3680 3681 3682 3683 3684
struct lxcDomainAttachDeviceMknodData {
    virLXCDriverPtr driver;
    mode_t mode;
    dev_t dev;
    virDomainObjPtr vm;
    virDomainDeviceDefPtr def;
    char *file;
};

static int
lxcDomainAttachDeviceMknodHelper(pid_t pid ATTRIBUTE_UNUSED,
                                 void *opaque)
{
    struct lxcDomainAttachDeviceMknodData *data = opaque;
    int ret = -1;

    virSecurityManagerPostFork(data->driver->securityManager);

    if (virFileMakeParentPath(data->file) < 0) {
        virReportSystemError(errno,
                             _("Unable to create %s"), data->file);
        goto cleanup;
    }

    /* Yes, the device name we're creating may not
     * actually correspond to the major:minor number
     * we're using, but we've no other option at this
     * time. Just have to hope that containerized apps
     * don't get upset that the major:minor is different
     * to that normally implied by the device name
     */
    VIR_DEBUG("Creating dev %s (%d,%d)",
              data->file, major(data->dev), minor(data->dev));
    if (mknod(data->file, data->mode, data->dev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             data->file);
        goto cleanup;
    }

    if (lxcContainerChown(data->vm->def, data->file) < 0)
        goto cleanup;

    /* Labelling normally operates on src, but we need
     * to actually label the dst here, so hack the config */
    switch (data->def->type) {
    case VIR_DOMAIN_DEVICE_DISK: {
        virDomainDiskDefPtr def = data->def->data.disk;
3685 3686
        char *tmpsrc = def->src->path;
        def->src->path = data->file;
3687 3688
        if (virSecurityManagerSetDiskLabel(data->driver->securityManager,
                                           data->vm->def, def) < 0) {
3689
            def->src->path = tmpsrc;
3690 3691
            goto cleanup;
        }
3692
        def->src->path = tmpsrc;
3693 3694
    }   break;

3695 3696 3697 3698 3699 3700 3701
    case VIR_DOMAIN_DEVICE_HOSTDEV: {
        virDomainHostdevDefPtr def = data->def->data.hostdev;
        if (virSecurityManagerSetHostdevLabel(data->driver->securityManager,
                                              data->vm->def, def, NULL) < 0)
            goto cleanup;
    }   break;

3702 3703 3704 3705 3706 3707 3708 3709 3710 3711 3712 3713 3714 3715 3716 3717 3718 3719 3720 3721 3722 3723 3724 3725 3726 3727 3728 3729 3730 3731 3732 3733 3734 3735 3736 3737 3738 3739 3740 3741 3742 3743 3744 3745 3746 3747 3748 3749 3750 3751 3752
    default:
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Unexpected device type %d"),
                       data->def->type);
        goto cleanup;
    }

    ret = 0;

 cleanup:
    if (ret < 0)
        unlink(data->file);
    return ret;
}


static int
lxcDomainAttachDeviceMknod(virLXCDriverPtr driver,
                           mode_t mode,
                           dev_t dev,
                           virDomainObjPtr vm,
                           virDomainDeviceDefPtr def,
                           char *file)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    struct lxcDomainAttachDeviceMknodData data;

    memset(&data, 0, sizeof(data));

    data.driver = driver;
    data.mode = mode;
    data.dev = dev;
    data.vm = vm;
    data.def = def;
    data.file = file;

    if (virSecurityManagerPreFork(driver->securityManager) < 0)
        return -1;

    if (virProcessRunInMountNamespace(priv->initpid,
                                      lxcDomainAttachDeviceMknodHelper,
                                      &data) < 0) {
        virSecurityManagerPostFork(driver->securityManager);
        return -1;
    }

    virSecurityManagerPostFork(driver->securityManager);
    return 0;
}


3753 3754 3755 3756 3757 3758 3759 3760 3761 3762 3763 3764 3765 3766 3767 3768 3769 3770 3771 3772 3773 3774 3775 3776 3777 3778 3779 3780 3781 3782 3783 3784 3785
static int
lxcDomainAttachDeviceUnlinkHelper(pid_t pid ATTRIBUTE_UNUSED,
                                  void *opaque)
{
    const char *path = opaque;

    VIR_DEBUG("Unlinking %s", path);
    if (unlink(path) < 0 && errno != ENOENT) {
        virReportSystemError(errno,
                             _("Unable to remove device %s"), path);
        return -1;
    }

    return 0;
}


static int
lxcDomainAttachDeviceUnlink(virDomainObjPtr vm,
                            char *file)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (virProcessRunInMountNamespace(priv->initpid,
                                      lxcDomainAttachDeviceUnlinkHelper,
                                      file) < 0) {
        return -1;
    }

    return 0;
}


3786 3787 3788 3789 3790 3791 3792 3793 3794
static int
lxcDomainAttachDeviceDiskLive(virLXCDriverPtr driver,
                              virDomainObjPtr vm,
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = dev->data.disk;
    int ret = -1;
    struct stat sb;
3795 3796
    char *file = NULL;
    int perms;
3797
    const char *src = NULL;
3798 3799 3800 3801 3802 3803 3804

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

3805 3806 3807 3808 3809 3810
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3811 3812
    src = virDomainDiskGetSource(def);
    if (src == NULL) {
3813 3814 3815 3816 3817
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk without media"));
        goto cleanup;
    }

3818 3819 3820 3821 3822 3823
    if (!virStorageSourceIsBlockLocal(def->src)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk for non-block device"));
        goto cleanup;
    }

3824 3825 3826 3827 3828 3829
    if (virDomainDiskIndexByName(vm->def, def->dst, true) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("target %s already exists"), def->dst);
        goto cleanup;
    }

3830
    if (stat(src, &sb) < 0) {
3831
        virReportSystemError(errno,
3832
                             _("Unable to access %s"), src);
3833 3834 3835
        goto cleanup;
    }

3836
    if (!S_ISBLK(sb.st_mode)) {
3837
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
3838
                       _("Disk source %s must be a block device"),
3839
                       src);
3840 3841 3842
        goto cleanup;
    }

3843
    perms = (def->src->readonly ?
3844 3845 3846
             VIR_CGROUP_DEVICE_READ :
             VIR_CGROUP_DEVICE_RW) |
        VIR_CGROUP_DEVICE_MKNOD;
3847

3848 3849 3850 3851 3852
    if (virCgroupAllowDevice(priv->cgroup,
                             'b',
                             major(sb.st_rdev),
                             minor(sb.st_rdev),
                             perms) < 0)
3853
        goto cleanup;
3854

3855
    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks + 1) < 0)
3856 3857
        goto cleanup;

3858 3859
    if (virAsprintf(&file,
                    "/dev/%s", def->dst) < 0)
3860 3861
        goto cleanup;

3862 3863 3864 3865 3866 3867 3868 3869 3870 3871 3872
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFBLK,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   file) < 0) {
        if (virCgroupDenyDevice(priv->cgroup,
                                'b',
                                major(sb.st_rdev),
                                minor(sb.st_rdev),
                                perms) < 0)
3873 3874
            VIR_WARN("cannot deny device %s for domain %s: %s",
                     src, vm->def->name, virGetLastErrorMessage());
3875 3876 3877 3878 3879 3880 3881
        goto cleanup;
    }

    virDomainDiskInsertPreAlloced(vm->def, def);

    ret = 0;

3882
 cleanup:
3883
    if (src)
3884
        virDomainAuditDisk(vm, NULL, def->src, "attach", ret == 0);
3885
    VIR_FREE(file);
3886 3887 3888 3889
    return ret;
}


3890
/* XXX conn required for network -> bridge resolution */
3891
static int
3892 3893 3894 3895 3896 3897
lxcDomainAttachDeviceNetLive(virConnectPtr conn,
                             virDomainObjPtr vm,
                             virDomainNetDefPtr net)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    int ret = -1;
3898
    virDomainNetType actualType;
3899
    virNetDevBandwidthPtr actualBandwidth;
3900 3901 3902 3903 3904
    char *veth = NULL;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
M
Martin Kletzander 已提交
3905
        return -1;
3906 3907
    }

3908 3909 3910
    if (virLXCProcessValidateInterface(net) < 0)
       return -1;

3911
    /* preallocate new slot for device */
3912
    if (VIR_REALLOC_N(vm->def->nets, vm->def->nnets+1) < 0)
3913 3914 3915 3916 3917 3918
        return -1;

    /* If appropriate, grab a physical device from the configured
     * network's pool of devices, or resolve bridge device name
     * to the one defined in the network definition.
     */
3919
    if (virDomainNetAllocateActualDevice(vm->def, net) < 0)
3920 3921 3922 3923 3924
        return -1;

    actualType = virDomainNetGetActualType(net);

    switch (actualType) {
3925 3926
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
    case VIR_DOMAIN_NET_TYPE_NETWORK: {
3927 3928 3929 3930 3931 3932
        const char *brname = virDomainNetGetActualBridgeName(net);
        if (!brname) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("No bridge name specified"));
            goto cleanup;
        }
3933
        if (!(veth = virLXCProcessSetupInterfaceTap(vm->def, net, brname)))
3934 3935
            goto cleanup;
    }   break;
3936 3937 3938 3939
    case VIR_DOMAIN_NET_TYPE_ETHERNET:
        if (!(veth = virLXCProcessSetupInterfaceTap(vm->def, net, NULL)))
            goto cleanup;
        break;
3940
    case VIR_DOMAIN_NET_TYPE_DIRECT: {
3941
        if (!(veth = virLXCProcessSetupInterfaceDirect(conn, vm->def, net)))
3942 3943
            goto cleanup;
    }   break;
3944 3945 3946 3947 3948 3949 3950 3951
    case VIR_DOMAIN_NET_TYPE_USER:
    case VIR_DOMAIN_NET_TYPE_VHOSTUSER:
    case VIR_DOMAIN_NET_TYPE_SERVER:
    case VIR_DOMAIN_NET_TYPE_CLIENT:
    case VIR_DOMAIN_NET_TYPE_MCAST:
    case VIR_DOMAIN_NET_TYPE_INTERNAL:
    case VIR_DOMAIN_NET_TYPE_HOSTDEV:
    case VIR_DOMAIN_NET_TYPE_UDP:
3952 3953 3954
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Network device type is not supported"));
        goto cleanup;
3955 3956 3957 3958
    case VIR_DOMAIN_NET_TYPE_LAST:
    default:
        virReportEnumRangeError(virDomainNetType, actualType);
        goto cleanup;
3959
    }
3960 3961 3962 3963
    /* Set bandwidth or warn if requested and not supported. */
    actualBandwidth = virDomainNetGetActualBandwidth(net);
    if (actualBandwidth) {
        if (virNetDevSupportBandwidth(actualType)) {
3964 3965
            if (virNetDevBandwidthSet(net->ifname, actualBandwidth, false,
                                      !virDomainNetTypeSharesHostView(net)) < 0)
3966 3967 3968
                goto cleanup;
        } else {
            VIR_WARN("setting bandwidth on interfaces of "
3969 3970
                     "type '%s' is not implemented yet: %s",
                     virDomainNetTypeToString(actualType), virGetLastErrorMessage());
3971 3972
        }
    }
3973 3974 3975 3976 3977 3978 3979 3980 3981 3982

    if (virNetDevSetNamespace(veth, priv->initpid) < 0) {
        virDomainAuditNet(vm, NULL, net, "attach", false);
        goto cleanup;
    }

    virDomainAuditNet(vm, NULL, net, "attach", true);

    ret = 0;

3983
 cleanup:
3984 3985 3986 3987 3988 3989
    if (!ret) {
        vm->def->nets[vm->def->nnets++] = net;
    } else if (veth) {
        switch (actualType) {
        case VIR_DOMAIN_NET_TYPE_BRIDGE:
        case VIR_DOMAIN_NET_TYPE_NETWORK:
3990
        case VIR_DOMAIN_NET_TYPE_ETHERNET:
3991 3992 3993 3994 3995 3996
            ignore_value(virNetDevVethDelete(veth));
            break;

        case VIR_DOMAIN_NET_TYPE_DIRECT:
            ignore_value(virNetDevMacVLanDelete(veth));
            break;
3997

3998 3999 4000 4001 4002 4003 4004 4005 4006
        case VIR_DOMAIN_NET_TYPE_USER:
        case VIR_DOMAIN_NET_TYPE_VHOSTUSER:
        case VIR_DOMAIN_NET_TYPE_SERVER:
        case VIR_DOMAIN_NET_TYPE_CLIENT:
        case VIR_DOMAIN_NET_TYPE_MCAST:
        case VIR_DOMAIN_NET_TYPE_INTERNAL:
        case VIR_DOMAIN_NET_TYPE_HOSTDEV:
        case VIR_DOMAIN_NET_TYPE_UDP:
        case VIR_DOMAIN_NET_TYPE_LAST:
4007 4008 4009
        default:
            /* no-op */
            break;
4010 4011 4012 4013 4014 4015 4016
        }
    }

    return ret;
}


4017 4018 4019 4020 4021 4022 4023 4024 4025 4026
static int
lxcDomainAttachDeviceHostdevSubsysUSBLive(virLXCDriverPtr driver,
                                          virDomainObjPtr vm,
                                          virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    char *src = NULL;
    struct stat sb;
4027
    virUSBDevicePtr usb = NULL;
4028
    virDomainHostdevSubsysUSBPtr usbsrc;
4029 4030 4031 4032 4033 4034 4035

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host USB device already exists"));
        return -1;
    }

4036
    usbsrc = &def->source.subsys.u.usb;
4037
    if (virAsprintf(&src, "/dev/bus/usb/%03d/%03d",
4038
                    usbsrc->bus, usbsrc->device) < 0)
4039 4040
        goto cleanup;

4041
    if (!(usb = virUSBDeviceNew(usbsrc->bus, usbsrc->device, NULL)))
4042 4043 4044 4045 4046 4047 4048 4049 4050 4051 4052 4053 4054 4055 4056
        goto cleanup;

    if (stat(src, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"), src);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("USB source %s was not a character device"),
                       src);
        goto cleanup;
    }

4057 4058 4059
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs + 1) < 0)
        goto cleanup;

4060
    if (virUSBDeviceFileIterate(usb,
4061
                                virLXCSetupHostUSBDeviceCgroup,
4062
                                priv->cgroup) < 0)
4063 4064
        goto cleanup;

4065 4066 4067 4068 4069 4070 4071
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFCHR,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   src) < 0) {
        if (virUSBDeviceFileIterate(usb,
4072
                                    virLXCTeardownHostUSBDeviceCgroup,
4073
                                    priv->cgroup) < 0)
4074 4075
            VIR_WARN("cannot deny device %s for domain %s: %s",
                     src, vm->def->name, virGetLastErrorMessage());
4076 4077 4078
        goto cleanup;
    }

4079 4080
    vm->def->hostdevs[vm->def->nhostdevs++] = def;

4081 4082
    ret = 0;

4083
 cleanup:
4084
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
4085
    virUSBDeviceFree(usb);
4086 4087 4088 4089 4090
    VIR_FREE(src);
    return ret;
}


4091 4092 4093 4094 4095 4096 4097 4098 4099 4100 4101 4102 4103 4104 4105 4106 4107 4108 4109 4110 4111 4112 4113 4114 4115 4116 4117 4118 4119 4120 4121 4122 4123 4124 4125 4126
static int
lxcDomainAttachDeviceHostdevStorageLive(virLXCDriverPtr driver,
                                        virDomainObjPtr vm,
                                        virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    struct stat sb;

    if (!def->source.caps.u.storage.block) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Missing storage block path"));
        goto cleanup;
    }

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host device already exists"));
        return -1;
    }

    if (stat(def->source.caps.u.storage.block, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"),
                             def->source.caps.u.storage.block);
        goto cleanup;
    }

    if (!S_ISBLK(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Hostdev source %s must be a block device"),
                       def->source.caps.u.storage.block);
        goto cleanup;
    }

4127
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0)
4128 4129
        goto cleanup;

4130 4131 4132 4133 4134
    if (virCgroupAllowDevice(priv->cgroup,
                             'b',
                             major(sb.st_rdev),
                             minor(sb.st_rdev),
                             VIR_CGROUP_DEVICE_RWM) < 0)
4135 4136
        goto cleanup;

4137 4138 4139 4140 4141 4142 4143 4144 4145 4146 4147
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFBLK,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   def->source.caps.u.storage.block) < 0) {
        if (virCgroupDenyDevice(priv->cgroup,
                                'b',
                                major(sb.st_rdev),
                                minor(sb.st_rdev),
                                VIR_CGROUP_DEVICE_RWM) < 0)
4148 4149
            VIR_WARN("cannot deny device %s for domain %s: %s",
                     def->source.caps.u.storage.block, vm->def->name, virGetLastErrorMessage());
4150 4151 4152 4153 4154 4155 4156
        goto cleanup;
    }

    vm->def->hostdevs[vm->def->nhostdevs++] = def;

    ret = 0;

4157
 cleanup:
4158 4159 4160 4161 4162
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    return ret;
}


4163 4164 4165 4166 4167 4168 4169 4170 4171 4172 4173 4174 4175 4176 4177 4178 4179 4180 4181 4182 4183 4184 4185 4186 4187 4188 4189 4190 4191 4192 4193 4194 4195 4196 4197 4198
static int
lxcDomainAttachDeviceHostdevMiscLive(virLXCDriverPtr driver,
                                     virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    struct stat sb;

    if (!def->source.caps.u.misc.chardev) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Missing storage block path"));
        goto cleanup;
    }

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host device already exists"));
        return -1;
    }

    if (stat(def->source.caps.u.misc.chardev, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"),
                             def->source.caps.u.misc.chardev);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Hostdev source %s must be a block device"),
                       def->source.caps.u.misc.chardev);
        goto cleanup;
    }

4199 4200 4201 4202 4203
    if (virCgroupAllowDevice(priv->cgroup,
                             'c',
                             major(sb.st_rdev),
                             minor(sb.st_rdev),
                             VIR_CGROUP_DEVICE_RWM) < 0)
4204 4205
        goto cleanup;

4206
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0)
4207 4208
        goto cleanup;

4209 4210 4211 4212 4213 4214 4215 4216 4217 4218 4219
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFBLK,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   def->source.caps.u.misc.chardev) < 0) {
        if (virCgroupDenyDevice(priv->cgroup,
                                'c',
                                major(sb.st_rdev),
                                minor(sb.st_rdev),
                                VIR_CGROUP_DEVICE_RWM) < 0)
4220 4221
            VIR_WARN("cannot deny device %s for domain %s: %s",
                     def->source.caps.u.storage.block, vm->def->name, virGetLastErrorMessage());
4222 4223 4224 4225 4226 4227 4228
        goto cleanup;
    }

    vm->def->hostdevs[vm->def->nhostdevs++] = def;

    ret = 0;

4229
 cleanup:
4230 4231 4232 4233 4234
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    return ret;
}


4235 4236 4237 4238 4239 4240 4241 4242 4243 4244 4245 4246 4247 4248 4249 4250 4251 4252
static int
lxcDomainAttachDeviceHostdevSubsysLive(virLXCDriverPtr driver,
                                       virDomainObjPtr vm,
                                       virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        return lxcDomainAttachDeviceHostdevSubsysUSBLive(driver, vm, dev);

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevSubsysTypeToString(dev->data.hostdev->source.subsys.type));
        return -1;
    }
}


4253 4254 4255 4256 4257 4258 4259 4260 4261
static int
lxcDomainAttachDeviceHostdevCapsLive(virLXCDriverPtr driver,
                                     virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.caps.type) {
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_STORAGE:
        return lxcDomainAttachDeviceHostdevStorageLive(driver, vm, dev);

4262 4263 4264
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_MISC:
        return lxcDomainAttachDeviceHostdevMiscLive(driver, vm, dev);

4265 4266 4267 4268 4269 4270 4271 4272 4273
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevCapsTypeToString(dev->data.hostdev->source.caps.type));
        return -1;
    }
}


4274 4275 4276 4277 4278 4279 4280 4281 4282 4283 4284 4285 4286
static int
lxcDomainAttachDeviceHostdevLive(virLXCDriverPtr driver,
                                 virDomainObjPtr vm,
                                 virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach hostdev until init PID is known"));
        return -1;
    }

4287 4288 4289 4290 4291 4292
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        return -1;
    }

4293 4294 4295 4296
    switch (dev->data.hostdev->mode) {
    case VIR_DOMAIN_HOSTDEV_MODE_SUBSYS:
        return lxcDomainAttachDeviceHostdevSubsysLive(driver, vm, dev);

4297 4298 4299
    case VIR_DOMAIN_HOSTDEV_MODE_CAPABILITIES:
        return lxcDomainAttachDeviceHostdevCapsLive(driver, vm, dev);

4300 4301 4302 4303 4304 4305 4306 4307 4308
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device mode %s"),
                       virDomainHostdevModeTypeToString(dev->data.hostdev->mode));
        return -1;
    }
}


4309 4310 4311 4312
static int
lxcDomainAttachDeviceLive(virConnectPtr conn,
                          virLXCDriverPtr driver,
                          virDomainObjPtr vm,
4313 4314 4315 4316 4317
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
4318 4319 4320 4321 4322 4323
    case VIR_DOMAIN_DEVICE_DISK:
        ret = lxcDomainAttachDeviceDiskLive(driver, vm, dev);
        if (!ret)
            dev->data.disk = NULL;
        break;

4324 4325 4326 4327 4328 4329 4330
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainAttachDeviceNetLive(conn, vm,
                                           dev->data.net);
        if (!ret)
            dev->data.net = NULL;
        break;

4331 4332 4333
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        ret = lxcDomainAttachDeviceHostdevLive(driver, vm, dev);
        if (!ret)
C
Chen Hanxiao 已提交
4334
            dev->data.hostdev = NULL;
4335 4336
        break;

4337 4338 4339 4340 4341 4342 4343 4344 4345 4346 4347
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be attached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


4348
static int
4349
lxcDomainDetachDeviceDiskLive(virDomainObjPtr vm,
4350 4351 4352 4353
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = NULL;
4354
    int idx, ret = -1;
J
John Ferlan 已提交
4355
    char *dst = NULL;
4356
    const char *src;
4357 4358 4359 4360 4361 4362 4363

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4364 4365 4366
    if ((idx = virDomainDiskIndexByName(vm->def,
                                        dev->data.disk->dst,
                                        false)) < 0) {
4367 4368 4369 4370 4371
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
        goto cleanup;
    }

4372
    def = vm->def->disks[idx];
4373
    src = virDomainDiskGetSource(def);
4374

4375
    if (virAsprintf(&dst, "/dev/%s", def->dst) < 0)
4376 4377
        goto cleanup;

4378
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4379 4380 4381 4382 4383
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4384
    if (lxcDomainAttachDeviceUnlink(vm, dst) < 0) {
4385
        virDomainAuditDisk(vm, def->src, NULL, "detach", false);
4386 4387
        goto cleanup;
    }
4388
    virDomainAuditDisk(vm, def->src, NULL, "detach", true);
4389

4390 4391
    if (virCgroupDenyDevicePath(priv->cgroup, src,
                                VIR_CGROUP_DEVICE_RWM, false) != 0)
4392 4393
        VIR_WARN("cannot deny device %s for domain %s: %s",
                 src, vm->def->name, virGetLastErrorMessage());
4394

4395
    virDomainDiskRemove(vm->def, idx);
4396 4397 4398 4399
    virDomainDiskDefFree(def);

    ret = 0;

4400
 cleanup:
4401 4402 4403 4404 4405
    VIR_FREE(dst);
    return ret;
}


4406
static int
4407 4408 4409
lxcDomainDetachDeviceNetLive(virDomainObjPtr vm,
                             virDomainDeviceDefPtr dev)
{
4410 4411
    int detachidx, ret = -1;
    virDomainNetType actualType;
4412 4413 4414
    virDomainNetDefPtr detach = NULL;
    virNetDevVPortProfilePtr vport = NULL;

4415
    if ((detachidx = virDomainNetFindIdx(vm->def, dev->data.net)) < 0)
4416
        goto cleanup;
4417

4418
    detach = vm->def->nets[detachidx];
4419 4420 4421
    actualType = virDomainNetGetActualType(detach);

    /* clear network bandwidth */
4422 4423
    if (virDomainNetGetActualBandwidth(detach) &&
        virNetDevSupportBandwidth(actualType) &&
4424 4425
        virNetDevBandwidthClear(detach->ifname))
        goto cleanup;
4426

4427
    switch (actualType) {
4428 4429
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
    case VIR_DOMAIN_NET_TYPE_NETWORK:
4430
    case VIR_DOMAIN_NET_TYPE_ETHERNET:
4431 4432 4433 4434 4435 4436 4437 4438 4439 4440 4441
        if (virNetDevVethDelete(detach->ifname) < 0) {
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
        break;

        /* It'd be nice to support this, but with macvlan
         * once assigned to a container nothing exists on
         * the host side. Further the container can change
         * the mac address of NIC name, so we can't easily
         * find out which guest NIC it maps to
4442
         */
4443
    case VIR_DOMAIN_NET_TYPE_DIRECT:
4444 4445 4446 4447 4448 4449 4450 4451
    case VIR_DOMAIN_NET_TYPE_USER:
    case VIR_DOMAIN_NET_TYPE_VHOSTUSER:
    case VIR_DOMAIN_NET_TYPE_SERVER:
    case VIR_DOMAIN_NET_TYPE_CLIENT:
    case VIR_DOMAIN_NET_TYPE_MCAST:
    case VIR_DOMAIN_NET_TYPE_INTERNAL:
    case VIR_DOMAIN_NET_TYPE_HOSTDEV:
    case VIR_DOMAIN_NET_TYPE_UDP:
4452 4453 4454
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Only bridged veth devices can be detached"));
        goto cleanup;
4455 4456 4457 4458
    case VIR_DOMAIN_NET_TYPE_LAST:
    default:
        virReportEnumRangeError(virDomainNetType, actualType);
        goto cleanup;
4459 4460 4461 4462 4463 4464 4465 4466 4467 4468 4469 4470
    }

    virDomainAuditNet(vm, detach, NULL, "detach", true);

    virDomainConfNWFilterTeardown(detach);

    vport = virDomainNetGetActualVirtPortProfile(detach);
    if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
        ignore_value(virNetDevOpenvswitchRemovePort(
                        virDomainNetGetActualBridgeName(detach),
                        detach->ifname));
    ret = 0;
4471
 cleanup:
4472
    if (!ret) {
4473
        virDomainNetReleaseActualDevice(vm->def, detach);
4474 4475 4476 4477 4478 4479 4480
        virDomainNetRemove(vm->def, detachidx);
        virDomainNetDefFree(detach);
    }
    return ret;
}


4481 4482 4483 4484 4485 4486 4487 4488
static int
lxcDomainDetachDeviceHostdevUSBLive(virLXCDriverPtr driver,
                                    virDomainObjPtr vm,
                                    virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
    int idx, ret = -1;
J
John Ferlan 已提交
4489
    char *dst = NULL;
4490
    virUSBDevicePtr usb = NULL;
4491
    virHostdevManagerPtr hostdev_mgr = driver->hostdevMgr;
4492
    virDomainHostdevSubsysUSBPtr usbsrc;
4493 4494 4495 4496 4497 4498 4499 4500 4501

    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("usb device not found"));
        goto cleanup;
    }

4502
    usbsrc = &def->source.subsys.u.usb;
4503
    if (virAsprintf(&dst, "/dev/bus/usb/%03d/%03d",
4504
                    usbsrc->bus, usbsrc->device) < 0)
4505 4506
        goto cleanup;

4507
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4508 4509 4510 4511 4512
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4513
    if (!(usb = virUSBDeviceNew(usbsrc->bus, usbsrc->device, NULL)))
4514 4515
        goto cleanup;

4516
    if (lxcDomainAttachDeviceUnlink(vm, dst) < 0) {
4517 4518 4519 4520 4521
        virDomainAuditHostdev(vm, def, "detach", false);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4522
    if (virUSBDeviceFileIterate(usb,
4523
                                virLXCTeardownHostUSBDeviceCgroup,
4524
                                priv->cgroup) < 0)
4525 4526
        VIR_WARN("cannot deny device %s for domain %s: %s",
                 dst, vm->def->name, virGetLastErrorMessage());
4527

4528 4529 4530
    virObjectLock(hostdev_mgr->activeUSBHostdevs);
    virUSBDeviceListDel(hostdev_mgr->activeUSBHostdevs, usb);
    virObjectUnlock(hostdev_mgr->activeUSBHostdevs);
4531 4532 4533 4534 4535 4536

    virDomainHostdevRemove(vm->def, idx);
    virDomainHostdevDefFree(def);

    ret = 0;

4537
 cleanup:
4538
    virUSBDeviceFree(usb);
4539 4540 4541 4542
    VIR_FREE(dst);
    return ret;
}

4543 4544

static int
4545
lxcDomainDetachDeviceHostdevStorageLive(virDomainObjPtr vm,
4546 4547 4548 4549
                                        virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
4550
    int idx, ret = -1;
4551 4552 4553 4554 4555 4556 4557

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4558 4559 4560
    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
4561 4562 4563 4564 4565 4566
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("hostdev %s not found"),
                       dev->data.hostdev->source.caps.u.storage.block);
        goto cleanup;
    }

4567
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4568 4569 4570 4571 4572
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4573
    if (lxcDomainAttachDeviceUnlink(vm, def->source.caps.u.storage.block) < 0) {
4574 4575 4576 4577 4578
        virDomainAuditHostdev(vm, def, "detach", false);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4579 4580
    if (virCgroupDenyDevicePath(priv->cgroup, def->source.caps.u.storage.block,
                                VIR_CGROUP_DEVICE_RWM, false) != 0)
4581 4582
        VIR_WARN("cannot deny device %s for domain %s: %s",
                 def->source.caps.u.storage.block, vm->def->name, virGetLastErrorMessage());
4583

4584
    virDomainHostdevRemove(vm->def, idx);
4585 4586 4587 4588
    virDomainHostdevDefFree(def);

    ret = 0;

4589
 cleanup:
4590 4591 4592 4593
    return ret;
}


4594
static int
4595
lxcDomainDetachDeviceHostdevMiscLive(virDomainObjPtr vm,
4596 4597 4598 4599
                                     virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
4600
    int idx, ret = -1;
4601 4602 4603 4604 4605 4606 4607

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4608 4609 4610
    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
4611 4612 4613 4614 4615 4616
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("hostdev %s not found"),
                       dev->data.hostdev->source.caps.u.misc.chardev);
        goto cleanup;
    }

4617
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4618 4619 4620 4621 4622
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4623
    if (lxcDomainAttachDeviceUnlink(vm, def->source.caps.u.misc.chardev) < 0) {
4624 4625 4626 4627 4628
        virDomainAuditHostdev(vm, def, "detach", false);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4629 4630
    if (virCgroupDenyDevicePath(priv->cgroup, def->source.caps.u.misc.chardev,
                                VIR_CGROUP_DEVICE_RWM, false) != 0)
4631 4632
        VIR_WARN("cannot deny device %s for domain %s: %s",
                 def->source.caps.u.misc.chardev, vm->def->name, virGetLastErrorMessage());
4633

4634
    virDomainHostdevRemove(vm->def, idx);
4635 4636 4637 4638
    virDomainHostdevDefFree(def);

    ret = 0;

4639
 cleanup:
4640 4641 4642 4643
    return ret;
}


4644 4645 4646 4647 4648 4649 4650 4651 4652 4653 4654 4655 4656 4657 4658 4659 4660 4661
static int
lxcDomainDetachDeviceHostdevSubsysLive(virLXCDriverPtr driver,
                                       virDomainObjPtr vm,
                                       virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        return lxcDomainDetachDeviceHostdevUSBLive(driver, vm, dev);

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevSubsysTypeToString(dev->data.hostdev->source.subsys.type));
        return -1;
    }
}


4662
static int
4663 4664
lxcDomainDetachDeviceHostdevCapsLive(virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
4665 4666 4667
{
    switch (dev->data.hostdev->source.caps.type) {
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_STORAGE:
4668
        return lxcDomainDetachDeviceHostdevStorageLive(vm, dev);
4669

4670
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_MISC:
4671
        return lxcDomainDetachDeviceHostdevMiscLive(vm, dev);
4672

4673 4674 4675 4676 4677 4678 4679 4680 4681
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevCapsTypeToString(dev->data.hostdev->source.caps.type));
        return -1;
    }
}


4682 4683 4684 4685 4686 4687 4688 4689 4690 4691 4692 4693 4694 4695 4696 4697 4698
static int
lxcDomainDetachDeviceHostdevLive(virLXCDriverPtr driver,
                                 virDomainObjPtr vm,
                                 virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach hostdev until init PID is known"));
        return -1;
    }

    switch (dev->data.hostdev->mode) {
    case VIR_DOMAIN_HOSTDEV_MODE_SUBSYS:
        return lxcDomainDetachDeviceHostdevSubsysLive(driver, vm, dev);

4699
    case VIR_DOMAIN_HOSTDEV_MODE_CAPABILITIES:
4700
        return lxcDomainDetachDeviceHostdevCapsLive(vm, dev);
4701

4702 4703 4704 4705 4706 4707 4708 4709 4710
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device mode %s"),
                       virDomainHostdevModeTypeToString(dev->data.hostdev->mode));
        return -1;
    }
}


4711 4712 4713
static int
lxcDomainDetachDeviceLive(virLXCDriverPtr driver,
                          virDomainObjPtr vm,
4714 4715 4716 4717 4718
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
4719
    case VIR_DOMAIN_DEVICE_DISK:
4720
        ret = lxcDomainDetachDeviceDiskLive(vm, dev);
4721 4722
        break;

4723 4724 4725 4726
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainDetachDeviceNetLive(vm, dev);
        break;

4727 4728 4729 4730
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        ret = lxcDomainDetachDeviceHostdevLive(driver, vm, dev);
        break;

4731 4732 4733 4734 4735 4736 4737 4738 4739 4740 4741
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be detached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


4742 4743 4744
static int lxcDomainAttachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
4745 4746
{
    virLXCDriverPtr driver = dom->conn->privateData;
4747
    virCapsPtr caps = NULL;
4748 4749 4750 4751
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
4752
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4753 4754

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
4755
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
4756

M
Michal Privoznik 已提交
4757
    if (!(vm = lxcDomObjFromDomain(dom)))
4758 4759
        goto cleanup;

4760 4761 4762
    if (virDomainAttachDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4763
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
4764 4765
        goto cleanup;

4766 4767 4768
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto endjob;

4769
    if (virDomainObjUpdateModificationImpact(vm, &flags) < 0)
4770
        goto endjob;
4771

4772
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4773
                                             caps, driver->xmlopt,
4774
                                             VIR_DOMAIN_DEF_PARSE_INACTIVE);
4775
    if (dev == NULL)
4776
        goto endjob;
4777 4778 4779 4780 4781 4782 4783

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
4784
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4785
                                          caps, driver->xmlopt);
4786
        if (!dev_copy)
4787
            goto endjob;
4788 4789 4790 4791
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
4792
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4793
        if (!vmdef)
4794
            goto endjob;
4795

4796
        if (virDomainDefCompatibleDevice(vmdef, dev, NULL) < 0)
4797
            goto endjob;
4798

4799
        if ((ret = lxcDomainAttachDeviceConfig(vmdef, dev)) < 0)
4800
            goto endjob;
4801 4802 4803
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
4804
        if (virDomainDefCompatibleDevice(vm->def, dev_copy, NULL) < 0)
4805
            goto endjob;
4806

4807
        if ((ret = lxcDomainAttachDeviceLive(dom->conn, driver, vm, dev_copy)) < 0)
4808
            goto endjob;
4809 4810 4811 4812 4813
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
4814
        if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0) {
4815
            ret = -1;
4816
            goto endjob;
4817 4818 4819 4820 4821
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
4822
        ret = virDomainSaveConfig(cfg->configDir, driver->caps, vmdef);
4823
        if (!ret) {
4824
            virDomainObjAssignDef(vm, vmdef, false, NULL);
4825 4826 4827 4828
            vmdef = NULL;
        }
    }

4829
 endjob:
4830 4831
    virLXCDomainObjEndJob(driver, vm);

4832
 cleanup:
4833 4834 4835 4836
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
4837
    virDomainObjEndAPI(&vm);
4838
    virObjectUnref(caps);
4839
    virObjectUnref(cfg);
4840 4841 4842 4843 4844 4845 4846 4847 4848 4849 4850 4851 4852 4853 4854 4855
    return ret;
}


static int lxcDomainAttachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainAttachDeviceFlags(dom, xml,
                                       VIR_DOMAIN_AFFECT_LIVE);
}


static int lxcDomainUpdateDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
4856
    virLXCDriverPtr driver = dom->conn->privateData;
4857
    virCapsPtr caps = NULL;
4858 4859 4860 4861
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
4862
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4863 4864 4865 4866 4867

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_DOMAIN_DEVICE_MODIFY_FORCE, -1);

M
Michal Privoznik 已提交
4868
    if (!(vm = lxcDomObjFromDomain(dom)))
4869 4870
        goto cleanup;

4871 4872 4873
    if (virDomainUpdateDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4874
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
4875
        goto cleanup;
4876

4877 4878 4879
    if (virDomainObjUpdateModificationImpact(vm, &flags) < 0)
        goto endjob;

4880
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
4881
        goto endjob;
4882

4883
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4884
                                             caps, driver->xmlopt,
4885
                                             VIR_DOMAIN_DEF_PARSE_INACTIVE);
4886
    if (dev == NULL)
4887
        goto endjob;
4888 4889 4890 4891 4892 4893 4894 4895

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4896
                                          caps, driver->xmlopt);
4897
        if (!dev_copy)
4898
            goto endjob;
4899 4900 4901 4902
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
4903
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4904
        if (!vmdef)
4905
            goto endjob;
4906

4907 4908
        /* virDomainDefCompatibleDevice call is delayed until we know the
         * device we're going to update. */
4909
        if ((ret = lxcDomainUpdateDeviceConfig(vmdef, dev)) < 0)
4910
            goto endjob;
4911 4912 4913 4914 4915 4916
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                       _("Unable to modify live devices"));

4917
        goto endjob;
4918 4919 4920 4921
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
4922
        ret = virDomainSaveConfig(cfg->configDir, driver->caps, vmdef);
4923 4924 4925 4926 4927
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false, NULL);
            vmdef = NULL;
        }
    }
4928
 endjob:
4929 4930
    virLXCDomainObjEndJob(driver, vm);

4931
 cleanup:
4932 4933 4934 4935
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
4936
    virDomainObjEndAPI(&vm);
4937
    virObjectUnref(caps);
4938
    virObjectUnref(cfg);
4939
    return ret;
4940 4941 4942 4943 4944 4945 4946
}


static int lxcDomainDetachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
4947
    virLXCDriverPtr driver = dom->conn->privateData;
4948
    virCapsPtr caps = NULL;
4949 4950 4951 4952
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
4953
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4954 4955 4956 4957

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

M
Michal Privoznik 已提交
4958
    if (!(vm = lxcDomObjFromDomain(dom)))
4959 4960
        goto cleanup;

4961 4962 4963
    if (virDomainDetachDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4964
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
4965
        goto cleanup;
4966

4967 4968 4969
    if (virDomainObjUpdateModificationImpact(vm, &flags) < 0)
        goto endjob;

4970
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
4971
        goto endjob;
4972

4973
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4974
                                             caps, driver->xmlopt,
4975 4976
                                             VIR_DOMAIN_DEF_PARSE_INACTIVE |
                                             VIR_DOMAIN_DEF_PARSE_SKIP_VALIDATE);
4977
    if (dev == NULL)
4978
        goto endjob;
4979 4980 4981 4982 4983 4984 4985 4986

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4987
                                          caps, driver->xmlopt);
4988
        if (!dev_copy)
4989
            goto endjob;
4990 4991 4992 4993
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
4994
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4995
        if (!vmdef)
4996
            goto endjob;
4997 4998

        if ((ret = lxcDomainDetachDeviceConfig(vmdef, dev)) < 0)
4999
            goto endjob;
5000 5001 5002 5003
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if ((ret = lxcDomainDetachDeviceLive(driver, vm, dev_copy)) < 0)
5004
            goto endjob;
5005 5006 5007 5008 5009
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
5010
        if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0) {
5011
            ret = -1;
5012
            goto endjob;
5013 5014 5015 5016 5017
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
5018
        ret = virDomainSaveConfig(cfg->configDir, driver->caps, vmdef);
5019 5020 5021 5022 5023 5024
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false, NULL);
            vmdef = NULL;
        }
    }

5025
 endjob:
5026 5027
    virLXCDomainObjEndJob(driver, vm);

5028
 cleanup:
5029 5030 5031 5032
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
5033
    virDomainObjEndAPI(&vm);
5034
    virObjectUnref(caps);
5035
    virObjectUnref(cfg);
5036
    return ret;
5037 5038 5039 5040 5041 5042 5043 5044 5045 5046 5047
}


static int lxcDomainDetachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainDetachDeviceFlags(dom, xml,
                                      VIR_DOMAIN_AFFECT_LIVE);
}


5048 5049 5050
static int lxcDomainLxcOpenNamespace(virDomainPtr dom,
                                     int **fdlist,
                                     unsigned int flags)
5051
{
5052
    virLXCDriverPtr driver = dom->conn->privateData;
5053 5054 5055 5056 5057 5058 5059 5060
    virDomainObjPtr vm;
    virLXCDomainObjPrivatePtr priv;
    int ret = -1;
    size_t nfds = 0;

    *fdlist = NULL;
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
5061
    if (!(vm = lxcDomObjFromDomain(dom)))
5062
        goto cleanup;
M
Michal Privoznik 已提交
5063

5064 5065
    priv = vm->privateData;

5066 5067 5068
    if (virDomainLxcOpenNamespaceEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

5069 5070 5071
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_QUERY) < 0)
        goto cleanup;

5072
    if (virDomainObjCheckActive(vm) < 0)
5073
        goto endjob;
5074 5075 5076 5077

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
5078
        goto endjob;
5079 5080 5081
    }

    if (virProcessGetNamespaces(priv->initpid, &nfds, fdlist) < 0)
5082
        goto endjob;
5083 5084

    ret = nfds;
5085 5086

 endjob:
5087
    virLXCDomainObjEndJob(driver, vm);
5088

5089
 cleanup:
5090
    virDomainObjEndAPI(&vm);
5091 5092 5093 5094
    return ret;
}


5095
static char *
5096
lxcConnectGetSysinfo(virConnectPtr conn, unsigned int flags)
5097 5098 5099 5100 5101 5102
{
    virLXCDriverPtr driver = conn->privateData;
    virBuffer buf = VIR_BUFFER_INITIALIZER;

    virCheckFlags(0, NULL);

5103 5104 5105
    if (virConnectGetSysinfoEnsureACL(conn) < 0)
        return NULL;

5106 5107 5108 5109 5110 5111 5112 5113
    if (!driver->hostsysinfo) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Host SMBIOS information is not available"));
        return NULL;
    }

    if (virSysinfoFormat(&buf, driver->hostsysinfo) < 0)
        return NULL;
5114
    if (virBufferCheckError(&buf) < 0)
5115 5116 5117 5118 5119
        return NULL;
    return virBufferContentAndReset(&buf);
}


5120
static int
5121
lxcNodeGetInfo(virConnectPtr conn,
5122 5123
               virNodeInfoPtr nodeinfo)
{
5124 5125 5126
    if (virNodeGetInfoEnsureACL(conn) < 0)
        return -1;

M
Martin Kletzander 已提交
5127
    return virCapabilitiesGetNodeInfo(nodeinfo);
5128 5129 5130
}


5131 5132
static int
lxcDomainMemoryStats(virDomainPtr dom,
5133
                     virDomainMemoryStatPtr stats,
5134 5135 5136 5137 5138 5139 5140 5141
                     unsigned int nr_stats,
                     unsigned int flags)
{
    virDomainObjPtr vm;
    int ret = -1;
    virLXCDomainObjPrivatePtr priv;
    unsigned long long swap_usage;
    unsigned long mem_usage;
5142
    virLXCDriverPtr driver = dom->conn->privateData;
5143 5144 5145 5146 5147 5148 5149 5150 5151 5152 5153

    virCheckFlags(0, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        goto cleanup;

    priv = vm->privateData;

    if (virDomainMemoryStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

5154 5155 5156
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_QUERY) < 0)
        goto cleanup;

5157
    if (virDomainObjCheckActive(vm) < 0)
5158
        goto endjob;
5159

5160
    if (virCgroupGetMemSwapUsage(priv->cgroup, &swap_usage) < 0)
5161
        goto endjob;
5162

5163
    if (virCgroupGetMemoryUsage(priv->cgroup, &mem_usage) < 0)
5164
        goto endjob;
5165 5166 5167 5168 5169 5170 5171 5172 5173 5174 5175 5176 5177 5178 5179 5180 5181 5182

    ret = 0;
    if (ret < nr_stats) {
        stats[ret].tag = VIR_DOMAIN_MEMORY_STAT_ACTUAL_BALLOON;
        stats[ret].val = vm->def->mem.cur_balloon;
        ret++;
    }
    if (ret < nr_stats) {
        stats[ret].tag = VIR_DOMAIN_MEMORY_STAT_SWAP_IN;
        stats[ret].val = swap_usage;
        ret++;
    }
    if (ret < nr_stats) {
        stats[ret].tag = VIR_DOMAIN_MEMORY_STAT_RSS;
        stats[ret].val = mem_usage;
        ret++;
    }

5183
 endjob:
5184 5185
    virLXCDomainObjEndJob(driver, vm);

5186
 cleanup:
5187
    virDomainObjEndAPI(&vm);
5188 5189 5190 5191
    return ret;
}


5192
static int
5193
lxcNodeGetCPUStats(virConnectPtr conn,
5194 5195 5196 5197 5198
                   int cpuNum,
                   virNodeCPUStatsPtr params,
                   int *nparams,
                   unsigned int flags)
{
5199 5200 5201
    if (virNodeGetCPUStatsEnsureACL(conn) < 0)
        return -1;

5202
    return virHostCPUGetStats(cpuNum, params, nparams, flags);
5203 5204 5205 5206
}


static int
5207
lxcNodeGetMemoryStats(virConnectPtr conn,
5208 5209 5210 5211 5212
                      int cellNum,
                      virNodeMemoryStatsPtr params,
                      int *nparams,
                      unsigned int flags)
{
5213 5214 5215
    if (virNodeGetMemoryStatsEnsureACL(conn) < 0)
        return -1;

5216
    return virHostMemGetStats(cellNum, params, nparams, flags);
5217 5218 5219 5220
}


static int
5221
lxcNodeGetCellsFreeMemory(virConnectPtr conn,
5222 5223 5224 5225
                          unsigned long long *freeMems,
                          int startCell,
                          int maxCells)
{
5226 5227 5228
    if (virNodeGetCellsFreeMemoryEnsureACL(conn) < 0)
        return -1;

5229
    return virHostMemGetCellsFree(freeMems, startCell, maxCells);
5230 5231 5232 5233
}


static unsigned long long
5234
lxcNodeGetFreeMemory(virConnectPtr conn)
5235
{
5236 5237
    unsigned long long freeMem;

5238 5239 5240
    if (virNodeGetFreeMemoryEnsureACL(conn) < 0)
        return 0;

5241
    if (virHostMemGetInfo(NULL, &freeMem) < 0)
5242 5243 5244
        return 0;

    return freeMem;
5245 5246 5247 5248
}


static int
5249
lxcNodeGetMemoryParameters(virConnectPtr conn,
5250 5251 5252 5253
                           virTypedParameterPtr params,
                           int *nparams,
                           unsigned int flags)
{
5254 5255 5256
    if (virNodeGetMemoryParametersEnsureACL(conn) < 0)
        return -1;

5257
    return virHostMemGetParameters(params, nparams, flags);
5258 5259 5260 5261
}


static int
5262
lxcNodeSetMemoryParameters(virConnectPtr conn,
5263 5264 5265 5266
                           virTypedParameterPtr params,
                           int nparams,
                           unsigned int flags)
{
5267 5268 5269
    if (virNodeSetMemoryParametersEnsureACL(conn) < 0)
        return -1;

5270
    return virHostMemSetParameters(params, nparams, flags);
5271 5272 5273 5274
}


static int
5275
lxcNodeGetCPUMap(virConnectPtr conn,
5276 5277 5278 5279
                 unsigned char **cpumap,
                 unsigned int *online,
                 unsigned int flags)
{
5280 5281 5282
    if (virNodeGetCPUMapEnsureACL(conn) < 0)
        return -1;

5283
    return virHostCPUGetMap(cpumap, online, flags);
5284 5285
}

5286 5287

static int
5288
lxcNodeSuspendForDuration(virConnectPtr conn,
5289 5290 5291 5292
                          unsigned int target,
                          unsigned long long duration,
                          unsigned int flags)
{
5293 5294 5295
    if (virNodeSuspendForDurationEnsureACL(conn) < 0)
        return -1;

5296
    return virNodeSuspend(target, duration, flags);
5297 5298 5299
}


5300 5301 5302 5303 5304 5305 5306 5307 5308 5309 5310 5311 5312 5313 5314 5315 5316 5317 5318 5319 5320 5321 5322 5323 5324 5325 5326 5327
static int
lxcDomainSetMetadata(virDomainPtr dom,
                      int type,
                      const char *metadata,
                      const char *key,
                      const char *uri,
                      unsigned int flags)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virDomainObjPtr vm;
    virLXCDriverConfigPtr cfg = NULL;
    virCapsPtr caps = NULL;
    int ret = -1;

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        return -1;

    cfg = virLXCDriverGetConfig(driver);

    if (virDomainSetMetadataEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

5328 5329 5330
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

5331
    ret = virDomainObjSetMetadata(vm, type, metadata, key, uri, caps,
5332 5333
                                  driver->xmlopt, cfg->stateDir,
                                  cfg->configDir, flags);
5334

5335 5336 5337 5338 5339 5340
    if (ret == 0) {
        virObjectEventPtr ev = NULL;
        ev = virDomainEventMetadataChangeNewFromObj(vm, type, uri);
        virObjectEventStateQueue(driver->domainEventState, ev);
    }

5341
    virLXCDomainObjEndJob(driver, vm);
5342

5343
 cleanup:
5344
    virDomainObjEndAPI(&vm);
5345 5346 5347 5348 5349 5350 5351 5352 5353 5354 5355 5356 5357 5358 5359 5360 5361 5362 5363 5364 5365
    virObjectUnref(caps);
    virObjectUnref(cfg);
    return ret;
}


static char *
lxcDomainGetMetadata(virDomainPtr dom,
                      int type,
                      const char *uri,
                      unsigned int flags)
{
    virDomainObjPtr vm;
    char *ret = NULL;

    if (!(vm = lxcDomObjFromDomain(dom)))
        return NULL;

    if (virDomainGetMetadataEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

5366
    ret = virDomainObjGetMetadata(vm, type, uri, flags);
5367

5368
 cleanup:
5369
    virDomainObjEndAPI(&vm);
5370 5371 5372 5373
    return ret;
}


5374 5375 5376 5377 5378 5379 5380 5381 5382 5383 5384 5385 5386 5387 5388 5389 5390 5391 5392 5393 5394 5395
static int
lxcDomainGetCPUStats(virDomainPtr dom,
                     virTypedParameterPtr params,
                     unsigned int nparams,
                     int start_cpu,
                     unsigned int ncpus,
                     unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    int ret = -1;
    virLXCDomainObjPrivatePtr priv;

    virCheckFlags(VIR_TYPED_PARAM_STRING_OKAY, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    priv = vm->privateData;

    if (virDomainGetCPUStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

5396
    if (virDomainObjCheckActive(vm) < 0)
5397 5398 5399 5400 5401 5402 5403 5404 5405 5406 5407 5408 5409
        goto cleanup;

    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPUACCT)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPUACCT controller is not mounted"));
        goto cleanup;
    }

    if (start_cpu == -1)
        ret = virCgroupGetDomainTotalCpuStats(priv->cgroup,
                                              params, nparams);
    else
        ret = virCgroupGetPercpuStats(priv->cgroup, params,
5410
                                      nparams, start_cpu, ncpus, NULL);
5411
 cleanup:
5412
    virDomainObjEndAPI(&vm);
5413 5414 5415 5416
    return ret;
}


5417 5418 5419 5420 5421 5422 5423 5424 5425 5426 5427 5428 5429 5430
static int
lxcNodeGetFreePages(virConnectPtr conn,
                    unsigned int npages,
                    unsigned int *pages,
                    int startCell,
                    unsigned int cellCount,
                    unsigned long long *counts,
                    unsigned int flags)
{
    virCheckFlags(0, -1);

    if (virNodeGetFreePagesEnsureACL(conn) < 0)
        return -1;

5431
    return virHostMemGetFreePages(npages, pages, startCell, cellCount, counts);
5432 5433 5434
}


5435 5436 5437 5438 5439 5440 5441 5442 5443 5444 5445 5446 5447 5448 5449 5450
static int
lxcNodeAllocPages(virConnectPtr conn,
                  unsigned int npages,
                  unsigned int *pageSizes,
                  unsigned long long *pageCounts,
                  int startCell,
                  unsigned int cellCount,
                  unsigned int flags)
{
    bool add = !(flags & VIR_NODE_ALLOC_PAGES_SET);

    virCheckFlags(VIR_NODE_ALLOC_PAGES_SET, -1);

    if (virNodeAllocPagesEnsureACL(conn) < 0)
        return -1;

5451 5452
    return virHostMemAllocPages(npages, pageSizes, pageCounts,
                                startCell, cellCount, add);
5453 5454 5455
}


5456 5457 5458 5459 5460 5461 5462 5463 5464 5465 5466 5467 5468 5469 5470 5471 5472
static int
lxcDomainHasManagedSaveImage(virDomainPtr dom, unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    int ret = -1;

    virCheckFlags(0, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    if (virDomainHasManagedSaveImageEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

    ret = 0;

 cleanup:
5473
    virDomainObjEndAPI(&vm);
5474 5475 5476 5477
    return ret;
}


D
Daniel Veillard 已提交
5478
/* Function Tables */
5479
static virHypervisorDriver lxcHypervisorDriver = {
5480
    .name = LXC_DRIVER_NAME,
5481
    .connectURIProbe = lxcConnectURIProbe,
5482 5483
    .connectOpen = lxcConnectOpen, /* 0.4.2 */
    .connectClose = lxcConnectClose, /* 0.4.2 */
5484
    .connectSupportsFeature = lxcConnectSupportsFeature, /* 1.2.2 */
5485
    .connectGetVersion = lxcConnectGetVersion, /* 0.4.6 */
5486
    .connectGetHostname = lxcConnectGetHostname, /* 0.6.3 */
5487
    .connectGetSysinfo = lxcConnectGetSysinfo, /* 1.0.5 */
5488
    .nodeGetInfo = lxcNodeGetInfo, /* 0.6.5 */
5489 5490 5491 5492 5493
    .connectGetCapabilities = lxcConnectGetCapabilities, /* 0.6.5 */
    .connectListDomains = lxcConnectListDomains, /* 0.4.2 */
    .connectNumOfDomains = lxcConnectNumOfDomains, /* 0.4.2 */
    .connectListAllDomains = lxcConnectListAllDomains, /* 0.9.13 */
    .domainCreateXML = lxcDomainCreateXML, /* 0.4.4 */
5494
    .domainCreateXMLWithFiles = lxcDomainCreateXMLWithFiles, /* 1.1.1 */
5495 5496 5497 5498 5499 5500
    .domainLookupByID = lxcDomainLookupByID, /* 0.4.2 */
    .domainLookupByUUID = lxcDomainLookupByUUID, /* 0.4.2 */
    .domainLookupByName = lxcDomainLookupByName, /* 0.4.2 */
    .domainSuspend = lxcDomainSuspend, /* 0.7.2 */
    .domainResume = lxcDomainResume, /* 0.7.2 */
    .domainDestroy = lxcDomainDestroy, /* 0.4.4 */
5501
    .domainDestroyFlags = lxcDomainDestroyFlags, /* 0.9.4 */
5502
    .domainGetOSType = lxcDomainGetOSType, /* 0.4.2 */
5503 5504 5505
    .domainGetMaxMemory = lxcDomainGetMaxMemory, /* 0.7.2 */
    .domainSetMaxMemory = lxcDomainSetMaxMemory, /* 0.7.2 */
    .domainSetMemory = lxcDomainSetMemory, /* 0.7.2 */
5506
    .domainSetMemoryFlags = lxcDomainSetMemoryFlags, /* 1.2.7 */
5507 5508
    .domainSetMemoryParameters = lxcDomainSetMemoryParameters, /* 0.8.5 */
    .domainGetMemoryParameters = lxcDomainGetMemoryParameters, /* 0.8.5 */
5509 5510
    .domainSetBlkioParameters = lxcDomainSetBlkioParameters, /* 0.9.8 */
    .domainGetBlkioParameters = lxcDomainGetBlkioParameters, /* 0.9.8 */
5511 5512
    .domainGetInfo = lxcDomainGetInfo, /* 0.4.2 */
    .domainGetState = lxcDomainGetState, /* 0.9.2 */
5513 5514
    .domainGetSecurityLabel = lxcDomainGetSecurityLabel, /* 0.9.10 */
    .nodeGetSecurityModel = lxcNodeGetSecurityModel, /* 0.9.10 */
5515
    .domainGetXMLDesc = lxcDomainGetXMLDesc, /* 0.4.2 */
5516
    .connectDomainXMLFromNative = lxcConnectDomainXMLFromNative, /* 1.2.2 */
5517 5518 5519 5520
    .connectListDefinedDomains = lxcConnectListDefinedDomains, /* 0.4.2 */
    .connectNumOfDefinedDomains = lxcConnectNumOfDefinedDomains, /* 0.4.2 */
    .domainCreate = lxcDomainCreate, /* 0.4.4 */
    .domainCreateWithFlags = lxcDomainCreateWithFlags, /* 0.8.2 */
5521
    .domainCreateWithFiles = lxcDomainCreateWithFiles, /* 1.1.1 */
5522
    .domainDefineXML = lxcDomainDefineXML, /* 0.4.2 */
5523
    .domainDefineXMLFlags = lxcDomainDefineXMLFlags, /* 1.2.12 */
5524
    .domainUndefine = lxcDomainUndefine, /* 0.4.2 */
5525
    .domainUndefineFlags = lxcDomainUndefineFlags, /* 0.9.4 */
5526 5527 5528 5529 5530
    .domainAttachDevice = lxcDomainAttachDevice, /* 1.0.1 */
    .domainAttachDeviceFlags = lxcDomainAttachDeviceFlags, /* 1.0.1 */
    .domainDetachDevice = lxcDomainDetachDevice, /* 1.0.1 */
    .domainDetachDeviceFlags = lxcDomainDetachDeviceFlags, /* 1.0.1 */
    .domainUpdateDeviceFlags = lxcDomainUpdateDeviceFlags, /* 1.0.1 */
5531 5532
    .domainGetAutostart = lxcDomainGetAutostart, /* 0.7.0 */
    .domainSetAutostart = lxcDomainSetAutostart, /* 0.7.0 */
5533 5534 5535 5536 5537
    .domainGetSchedulerType = lxcDomainGetSchedulerType, /* 0.5.0 */
    .domainGetSchedulerParameters = lxcDomainGetSchedulerParameters, /* 0.5.0 */
    .domainGetSchedulerParametersFlags = lxcDomainGetSchedulerParametersFlags, /* 0.9.2 */
    .domainSetSchedulerParameters = lxcDomainSetSchedulerParameters, /* 0.5.0 */
    .domainSetSchedulerParametersFlags = lxcDomainSetSchedulerParametersFlags, /* 0.9.2 */
5538 5539
    .domainBlockStats = lxcDomainBlockStats, /* 1.2.2 */
    .domainBlockStatsFlags = lxcDomainBlockStatsFlags, /* 1.2.2 */
5540
    .domainInterfaceStats = lxcDomainInterfaceStats, /* 0.7.3 */
5541
    .domainMemoryStats = lxcDomainMemoryStats, /* 1.2.2 */
5542 5543 5544 5545 5546
    .nodeGetCPUStats = lxcNodeGetCPUStats, /* 0.9.3 */
    .nodeGetMemoryStats = lxcNodeGetMemoryStats, /* 0.9.3 */
    .nodeGetCellsFreeMemory = lxcNodeGetCellsFreeMemory, /* 0.6.5 */
    .nodeGetFreeMemory = lxcNodeGetFreeMemory, /* 0.6.5 */
    .nodeGetCPUMap = lxcNodeGetCPUMap, /* 1.0.0 */
5547 5548 5549 5550
    .connectDomainEventRegister = lxcConnectDomainEventRegister, /* 0.7.0 */
    .connectDomainEventDeregister = lxcConnectDomainEventDeregister, /* 0.7.0 */
    .connectIsEncrypted = lxcConnectIsEncrypted, /* 0.7.3 */
    .connectIsSecure = lxcConnectIsSecure, /* 0.7.3 */
5551 5552 5553
    .domainIsActive = lxcDomainIsActive, /* 0.7.3 */
    .domainIsPersistent = lxcDomainIsPersistent, /* 0.7.3 */
    .domainIsUpdated = lxcDomainIsUpdated, /* 0.8.6 */
5554 5555
    .connectDomainEventRegisterAny = lxcConnectDomainEventRegisterAny, /* 0.8.0 */
    .connectDomainEventDeregisterAny = lxcConnectDomainEventDeregisterAny, /* 0.8.0 */
5556
    .domainOpenConsole = lxcDomainOpenConsole, /* 0.8.6 */
5557
    .connectIsAlive = lxcConnectIsAlive, /* 0.9.8 */
5558
    .nodeSuspendForDuration = lxcNodeSuspendForDuration, /* 0.9.8 */
5559 5560
    .domainSetMetadata = lxcDomainSetMetadata, /* 1.1.3 */
    .domainGetMetadata = lxcDomainGetMetadata, /* 1.1.3 */
5561
    .domainGetCPUStats = lxcDomainGetCPUStats, /* 1.2.2 */
5562 5563
    .nodeGetMemoryParameters = lxcNodeGetMemoryParameters, /* 0.10.2 */
    .nodeSetMemoryParameters = lxcNodeSetMemoryParameters, /* 0.10.2 */
5564
    .domainSendProcessSignal = lxcDomainSendProcessSignal, /* 1.0.1 */
5565 5566 5567
    .domainShutdown = lxcDomainShutdown, /* 1.0.1 */
    .domainShutdownFlags = lxcDomainShutdownFlags, /* 1.0.1 */
    .domainReboot = lxcDomainReboot, /* 1.0.1 */
5568
    .domainLxcOpenNamespace = lxcDomainLxcOpenNamespace, /* 1.0.2 */
5569
    .nodeGetFreePages = lxcNodeGetFreePages, /* 1.2.6 */
5570
    .nodeAllocPages = lxcNodeAllocPages, /* 1.2.9 */
5571
    .domainHasManagedSaveImage = lxcDomainHasManagedSaveImage, /* 1.2.13 */
D
Daniel Veillard 已提交
5572 5573
};

5574
static virConnectDriver lxcConnectDriver = {
5575
    .localOnly = true,
5576
    .uriSchemes = (const char *[]){ "lxc", NULL },
5577 5578 5579
    .hypervisorDriver = &lxcHypervisorDriver,
};

5580
static virStateDriver lxcStateDriver = {
5581
    .name = LXC_DRIVER_NAME,
5582
    .stateInitialize = lxcStateInitialize,
5583
    .stateAutoStart = lxcStateAutoStart,
5584 5585
    .stateCleanup = lxcStateCleanup,
    .stateReload = lxcStateReload,
5586 5587
};

D
Daniel Veillard 已提交
5588 5589
int lxcRegister(void)
{
5590 5591
    if (virRegisterConnectDriver(&lxcConnectDriver,
                                 true) < 0)
5592 5593 5594
        return -1;
    if (virRegisterStateDriver(&lxcStateDriver) < 0)
        return -1;
D
Daniel Veillard 已提交
5595 5596
    return 0;
}