bridge_driver.c 154.7 KB
Newer Older
1
/*
2
 * bridge_driver.c: core driver methods for managing network
3
 *
4
 * Copyright (C) 2006-2014 Red Hat, Inc.
5 6 7 8 9 10 11 12 13 14 15 16 17
 * Copyright (C) 2006 Daniel P. Berrange
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
18
 * License along with this library.  If not, see
O
Osier Yang 已提交
19
 * <http://www.gnu.org/licenses/>.
20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42
 *
 * Author: Daniel P. Berrange <berrange@redhat.com>
 */

#include <config.h>

#include <sys/types.h>
#include <sys/poll.h>
#include <limits.h>
#include <string.h>
#include <stdio.h>
#include <stdarg.h>
#include <stdlib.h>
#include <unistd.h>
#include <errno.h>
#include <sys/utsname.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <signal.h>
#include <paths.h>
#include <pwd.h>
#include <sys/wait.h>
#include <sys/ioctl.h>
43
#include <net/if.h>
44
#include <dirent.h>
45 46 47
#if HAVE_SYS_SYSCTL_H
# include <sys/sysctl.h>
#endif
48

49
#include "virerror.h"
50
#include "datatypes.h"
51
#include "bridge_driver.h"
52
#include "bridge_driver_platform.h"
53
#include "network_conf.h"
54
#include "device_conf.h"
55
#include "driver.h"
56
#include "virbuffer.h"
57
#include "virpidfile.h"
58
#include "vircommand.h"
59
#include "viralloc.h"
60
#include "viruuid.h"
61
#include "viriptables.h"
62
#include "virlog.h"
63
#include "virdnsmasq.h"
64
#include "configmake.h"
65
#include "virnetdev.h"
66
#include "virpci.h"
67 68
#include "virnetdevbridge.h"
#include "virnetdevtap.h"
69
#include "virnetdevvportprofile.h"
70
#include "virdbus.h"
71
#include "virfile.h"
72
#include "virstring.h"
73
#include "viraccessapicheck.h"
74
#include "network_event.h"
75
#include "virhook.h"
76
#include "virjson.h"
77

78 79
#define VIR_FROM_THIS VIR_FROM_NETWORK

80 81 82 83 84 85 86
/**
 * VIR_NETWORK_DHCP_LEASE_FILE_SIZE_MAX:
 *
 * Macro providing the upper limit on the size of leases file
 */
#define VIR_NETWORK_DHCP_LEASE_FILE_SIZE_MAX (32 * 1024 * 1024)

87 88
VIR_LOG_INIT("network.bridge_driver");

89 90 91 92
static virNetworkDriverStatePtr driver;


static void networkDriverLock(void)
93
{
94
    virMutexLock(&driver->lock);
95
}
96
static void networkDriverUnlock(void)
97
{
98
    virMutexUnlock(&driver->lock);
99 100
}

101
static int networkStateCleanup(void);
102

103
static int networkStartNetwork(virNetworkObjPtr network);
104

105
static int networkShutdownNetwork(virNetworkObjPtr network);
106

107
static int networkStartNetworkVirtual(virNetworkObjPtr network);
108

109
static int networkShutdownNetworkVirtual(virNetworkObjPtr network);
110

111
static int networkStartNetworkExternal(virNetworkObjPtr network);
112

113
static int networkShutdownNetworkExternal(virNetworkObjPtr network);
114

115 116
static void networkReloadFirewallRules(void);
static void networkRefreshDaemons(void);
117

118 119 120 121 122
static int networkPlugBandwidth(virNetworkObjPtr net,
                                virDomainNetDefPtr iface);
static int networkUnplugBandwidth(virNetworkObjPtr net,
                                  virDomainNetDefPtr iface);

123
static void networkNetworkObjTaint(virNetworkObjPtr net,
124
                                   virNetworkTaintFlags taint);
125

126 127 128 129 130 131
static virNetworkObjPtr
networkObjFromNetwork(virNetworkPtr net)
{
    virNetworkObjPtr network;
    char uuidstr[VIR_UUID_STRING_BUFLEN];

132
    networkDriverLock();
133
    network = virNetworkFindByUUID(&driver->networks, net->uuid);
134
    networkDriverUnlock();
135 136 137 138 139 140 141 142 143 144 145

    if (!network) {
        virUUIDFormat(net->uuid, uuidstr);
        virReportError(VIR_ERR_NO_NETWORK,
                       _("no network with matching uuid '%s' (%s)"),
                       uuidstr, net->name);
    }

    return network;
}

146 147 148
static int
networkRunHook(virNetworkObjPtr network,
               virDomainDefPtr dom,
149
               virDomainNetDefPtr iface,
150 151 152 153 154 155 156 157 158
               int op,
               int sub_op)
{
    virBuffer buf = VIR_BUFFER_INITIALIZER;
    char *xml = NULL, *net_xml = NULL, *dom_xml = NULL;
    int hookret;
    int ret = -1;

    if (virHookPresent(VIR_HOOK_DRIVER_NETWORK)) {
159 160 161 162 163 164
        if (!network) {
            VIR_DEBUG("Not running hook as @network is NULL");
            ret = 0;
            goto cleanup;
        }

165 166
        virBufferAddLit(&buf, "<hookData>\n");
        virBufferAdjustIndent(&buf, 2);
167 168
        if (iface && virDomainNetDefFormat(&buf, iface, 0) < 0)
            goto cleanup;
169 170 171 172 173 174 175 176
        if (virNetworkDefFormatBuf(&buf, network->def, 0) < 0)
            goto cleanup;
        if (dom && virDomainDefFormatInternal(dom, 0, &buf) < 0)
            goto cleanup;

        virBufferAdjustIndent(&buf, -2);
        virBufferAddLit(&buf, "</hookData>");

177
        if (virBufferCheckError(&buf) < 0)
178 179
            goto cleanup;

180
        xml = virBufferContentAndReset(&buf);
181 182 183 184 185 186 187 188
        hookret = virHookCall(VIR_HOOK_DRIVER_NETWORK, network->def->name,
                              op, sub_op, NULL, xml, NULL);

        /*
         * If the script raised an error, pass it to the callee.
         */
        if (hookret < 0)
            goto cleanup;
189 190

        networkNetworkObjTaint(network, VIR_NETWORK_TAINT_HOOK);
191 192 193
    }

    ret = 0;
194
 cleanup:
195 196 197 198 199 200 201
    virBufferFreeAndReset(&buf);
    VIR_FREE(xml);
    VIR_FREE(net_xml);
    VIR_FREE(dom_xml);
    return ret;
}

202
static char *
203
networkDnsmasqLeaseFileNameDefault(const char *netname)
204 205 206
{
    char *leasefile;

207
    ignore_value(virAsprintf(&leasefile, "%s/%s.leases",
208
                             driver->dnsmasqStateDir, netname));
209 210 211
    return leasefile;
}

212 213 214 215 216 217
static char *
networkDnsmasqLeaseFileNameCustom(const char *bridge)
{
    char *leasefile;

    ignore_value(virAsprintf(&leasefile, "%s/%s.status",
218
                             driver->dnsmasqStateDir, bridge));
219 220 221
    return leasefile;
}

222 223 224 225 226
static char *
networkDnsmasqConfigFileName(const char *netname)
{
    char *conffile;

227
    ignore_value(virAsprintf(&conffile, "%s/%s.conf",
228
                             driver->dnsmasqStateDir, netname));
229 230 231
    return conffile;
}

232 233 234 235 236 237
static char *
networkRadvdPidfileBasename(const char *netname)
{
    /* this is simple but we want to be sure it's consistently done */
    char *pidfilebase;

238
    ignore_value(virAsprintf(&pidfilebase, "%s-radvd", netname));
239 240 241 242 243 244 245 246
    return pidfilebase;
}

static char *
networkRadvdConfigFileName(const char *netname)
{
    char *configfile;

247
    ignore_value(virAsprintf(&configfile, "%s/%s-radvd.conf",
248
                             driver->radvdStateDir, netname));
249 250
    return configfile;
}
251

252 253
/* do needed cleanup steps and remove the network from the list */
static int
254
networkRemoveInactive(virNetworkObjPtr net)
255 256
{
    char *leasefile = NULL;
257
    char *customleasefile = NULL;
258
    char *radvdconfigfile = NULL;
259
    char *configfile = NULL;
260
    char *radvdpidbase = NULL;
261
    char *statusfile = NULL;
262 263 264 265 266 267
    dnsmasqContext *dctx = NULL;
    virNetworkDefPtr def = virNetworkObjGetPersistentDef(net);

    int ret = -1;

    /* remove the (possibly) existing dnsmasq and radvd files */
268
    if (!(dctx = dnsmasqContextNew(def->name,
269
                                   driver->dnsmasqStateDir))) {
270
        goto cleanup;
271
    }
272

273
    if (!(leasefile = networkDnsmasqLeaseFileNameDefault(def->name)))
274 275
        goto cleanup;

276 277 278
    if (!(customleasefile = networkDnsmasqLeaseFileNameCustom(def->bridge)))
        goto cleanup;

279
    if (!(radvdconfigfile = networkRadvdConfigFileName(def->name)))
280
        goto cleanup;
281 282

    if (!(radvdpidbase = networkRadvdPidfileBasename(def->name)))
283
        goto cleanup;
284

285
    if (!(configfile = networkDnsmasqConfigFileName(def->name)))
286
        goto cleanup;
287

288
    if (!(statusfile
289
          = virNetworkConfigFile(driver->stateDir, def->name)))
290
        goto cleanup;
291

292 293 294
    /* dnsmasq */
    dnsmasqDelete(dctx);
    unlink(leasefile);
295
    unlink(customleasefile);
296
    unlink(configfile);
297 298 299

    /* radvd */
    unlink(radvdconfigfile);
300
    virPidFileDelete(driver->pidDir, radvdpidbase);
301

302 303 304
    /* remove status file */
    unlink(statusfile);

305 306 307 308 309
    /* remove the network definition */
    virNetworkRemoveInactive(&driver->networks, net);

    ret = 0;

310
 cleanup:
311
    VIR_FREE(leasefile);
312
    VIR_FREE(configfile);
313
    VIR_FREE(customleasefile);
314 315
    VIR_FREE(radvdconfigfile);
    VIR_FREE(radvdpidbase);
316
    VIR_FREE(statusfile);
317 318 319 320
    dnsmasqContextFree(dctx);
    return ret;
}

321 322 323
static char *
networkBridgeDummyNicName(const char *brname)
{
324
    static const char dummyNicSuffix[] = "-nic";
325 326
    char *nicname;

327 328 329 330 331 332 333
    if (strlen(brname) + sizeof(dummyNicSuffix) > IFNAMSIZ) {
        /* because the length of an ifname is limited to IFNAMSIZ-1
         * (usually 15), and we're adding 4 more characters, we must
         * truncate the original name to 11 to fit. In order to catch
         * a possible numeric ending (eg virbr0, virbr1, etc), we grab
         * the first 8 and last 3 characters of the string.
         */
334 335 336 337 338
        ignore_value(virAsprintf(&nicname, "%.*s%s%s",
                                 /* space for last 3 chars + "-nic" + NULL */
                                 (int)(IFNAMSIZ - (3 + sizeof(dummyNicSuffix))),
                                 brname, brname + strlen(brname) - 3,
                                 dummyNicSuffix));
339
    } else {
340
        ignore_value(virAsprintf(&nicname, "%s%s", brname, dummyNicSuffix));
341
    }
342 343 344
    return nicname;
}

345 346 347
/* Update the internal status of all allegedly active networks
 * according to external conditions on the host (i.e. anything that
 * isn't stored directly in each network's state file). */
348
static void
349
networkUpdateAllState(void)
350
{
351
    size_t i;
352

353
    for (i = 0; i < driver->networks.count; i++) {
354 355
        virNetworkObjPtr obj = driver->networks.objs[i];

356
        if (!obj->active)
J
Ján Tomko 已提交
357
            continue;
358

359 360
        virNetworkObjLock(obj);

361 362 363 364 365 366 367 368
        switch (obj->def->forward.type) {
        case VIR_NETWORK_FORWARD_NONE:
        case VIR_NETWORK_FORWARD_NAT:
        case VIR_NETWORK_FORWARD_ROUTE:
            /* If bridge doesn't exist, then mark it inactive */
            if (!(obj->def->bridge && virNetDevExists(obj->def->bridge) == 1))
                obj->active = 0;
            break;
369

370 371 372 373 374 375 376 377 378 379 380 381 382 383 384
        case VIR_NETWORK_FORWARD_BRIDGE:
            if (obj->def->bridge) {
                if (virNetDevExists(obj->def->bridge) != 1)
                    obj->active = 0;
                break;
            }
            /* intentionally drop through to common case for all
             * macvtap networks (forward='bridge' with no bridge
             * device defined is macvtap using its 'bridge' mode)
             */
        case VIR_NETWORK_FORWARD_PRIVATE:
        case VIR_NETWORK_FORWARD_VEPA:
        case VIR_NETWORK_FORWARD_PASSTHROUGH:
            /* so far no extra checks */
            break;
385

386 387 388 389
        case VIR_NETWORK_FORWARD_HOSTDEV:
            /* so far no extra checks */
            break;
        }
390

391 392 393 394
        /* Try and read dnsmasq/radvd pids of active networks */
        if (obj->active && obj->def->ips && (obj->def->nips > 0)) {
            char *radvdpidbase;

395
            ignore_value(virPidFileReadIfAlive(driver->pidDir,
396 397 398 399 400 401
                                               obj->def->name,
                                               &obj->dnsmasqPid,
                                               dnsmasqCapsGetBinaryPath(driver->dnsmasqCaps)));
            radvdpidbase = networkRadvdPidfileBasename(obj->def->name);
            if (!radvdpidbase)
                break;
402
            ignore_value(virPidFileReadIfAlive(driver->pidDir,
403 404 405
                                               radvdpidbase,
                                               &obj->radvdPid, RADVD));
            VIR_FREE(radvdpidbase);
406 407 408 409
        }

        virNetworkObjUnlock(obj);
    }
410 411 412 413 414 415 416 417

    /* remove inactive transient networks */
    i = 0;
    while (i < driver->networks.count) {
        virNetworkObjPtr obj = driver->networks.objs[i];
        virNetworkObjLock(obj);

        if (!obj->persistent && !obj->active) {
418
            networkRemoveInactive(obj);
419 420 421 422 423 424
            continue;
        }

        virNetworkObjUnlock(obj);
        i++;
    }
425 426 427
}


428
static void
429
networkAutostartConfigs(void)
430
{
431
    size_t i;
432

433
    for (i = 0; i < driver->networks.count; i++) {
434
        virNetworkObjLock(driver->networks.objs[i]);
435
        if (driver->networks.objs[i]->autostart &&
436
            !virNetworkObjIsActive(driver->networks.objs[i])) {
437
            if (networkStartNetwork(driver->networks.objs[i]) < 0) {
J
Ján Tomko 已提交
438
                /* failed to start but already logged */
439
            }
440
        }
441
        virNetworkObjUnlock(driver->networks.objs[i]);
442 443 444
    }
}

445 446 447
#if HAVE_FIREWALLD
static DBusHandlerResult
firewalld_dbus_filter_bridge(DBusConnection *connection ATTRIBUTE_UNUSED,
448
                             DBusMessage *message, void *user_data ATTRIBUTE_UNUSED)
449
{
450 451 452 453 454 455
    if (dbus_message_is_signal(message, DBUS_INTERFACE_DBUS,
                               "NameOwnerChanged") ||
        dbus_message_is_signal(message, "org.fedoraproject.FirewallD1",
                               "Reloaded"))
    {
        VIR_DEBUG("Reload in bridge_driver because of firewalld.");
456
        networkReloadFirewallRules();
457 458 459 460 461 462
    }

    return DBUS_HANDLER_RESULT_NOT_YET_HANDLED;
}
#endif

463
static int
464
networkMigrateStateFiles(void)
465 466 467 468 469 470 471 472 473 474 475 476 477
{
    /* Due to a change in location of network state xml beginning in
     * libvirt 1.2.4 (from /var/lib/libvirt/network to
     * /var/run/libvirt/network), we must check for state files in two
     * locations. Anything found in the old location must be written
     * to the new location, then erased from the old location. (Note
     * that we read/write the file rather than calling rename()
     * because the old and new state directories are likely in
     * different filesystems).
     */
    int ret = -1;
    const char *oldStateDir = LOCALSTATEDIR "/lib/libvirt/network";
    DIR *dir;
478
    int direrr;
479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497
    struct dirent *entry;
    char *oldPath = NULL, *newPath = NULL;
    char *contents = NULL;

    if (!(dir = opendir(oldStateDir))) {
        if (errno == ENOENT)
            return 0;

        virReportSystemError(errno, _("failed to open directory '%s'"),
                             oldStateDir);
        return -1;
    }

    if (virFileMakePath(driver->stateDir) < 0) {
        virReportSystemError(errno, _("cannot create directory %s"),
                             driver->stateDir);
        goto cleanup;
    }

498
    while ((direrr = virDirRead(dir, &entry, oldStateDir)) > 0) {
499 500 501
        if (entry->d_type != DT_UNKNOWN &&
            entry->d_type != DT_REG)
            continue;
502

503
        if (STREQ(entry->d_name, ".") ||
504 505 506 507 508
            STREQ(entry->d_name, ".."))
            continue;

        if (virAsprintf(&oldPath, "%s/%s",
                        oldStateDir, entry->d_name) < 0)
J
Ján Tomko 已提交
509
            goto cleanup;
510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526

        if (entry->d_type == DT_UNKNOWN) {
            struct stat st;

            if (lstat(oldPath, &st) < 0) {
                virReportSystemError(errno,
                                     _("failed to stat network status file '%s'"),
                                     oldPath);
                goto cleanup;
            }

            if (!S_ISREG(st.st_mode)) {
                VIR_FREE(oldPath);
                continue;
            }
        }

527
        if (virFileReadAll(oldPath, 1024*1024, &contents) < 0)
J
Ján Tomko 已提交
528
            goto cleanup;
529 530 531

        if (virAsprintf(&newPath, "%s/%s",
                        driver->stateDir, entry->d_name) < 0)
J
Ján Tomko 已提交
532
            goto cleanup;
533 534 535 536 537 538 539 540 541 542 543 544
        if (virFileWriteStr(newPath, contents, S_IRUSR | S_IWUSR) < 0) {
            virReportSystemError(errno,
                                 _("failed to write network status file '%s'"),
                                 newPath);
            goto cleanup;
        }

        unlink(oldPath);
        VIR_FREE(oldPath);
        VIR_FREE(newPath);
        VIR_FREE(contents);
    }
545
    if (direrr < 0)
J
Ján Tomko 已提交
546
        goto cleanup;
547 548 549 550 551 552 553 554 555 556

    ret = 0;
 cleanup:
    closedir(dir);
    VIR_FREE(oldPath);
    VIR_FREE(newPath);
    VIR_FREE(contents);
    return ret;
}

557
/**
558
 * networkStateInitialize:
559 560 561 562
 *
 * Initialization function for the QEmu daemon
 */
static int
563 564 565
networkStateInitialize(bool privileged,
                       virStateInhibitCallback callback ATTRIBUTE_UNUSED,
                       void *opaque ATTRIBUTE_UNUSED)
566
{
567 568 569
    int ret = -1;
    char *configdir = NULL;
    char *rundir = NULL;
570 571 572
#ifdef HAVE_FIREWALLD
    DBusConnection *sysbus = NULL;
#endif
573

574
    if (VIR_ALLOC(driver) < 0)
575
        goto error;
576

577 578
    if (virMutexInit(&driver->lock) < 0) {
        VIR_FREE(driver);
579 580
        goto error;
    }
581
    networkDriverLock();
582

583 584 585 586
    /* configuration/state paths are one of
     * ~/.config/libvirt/... (session/unprivileged)
     * /etc/libvirt/... && /var/(run|lib)/libvirt/... (system/privileged).
     */
587
    if (privileged) {
588
        if (VIR_STRDUP(driver->networkConfigDir,
589
                       SYSCONFDIR "/libvirt/qemu/networks") < 0 ||
590
            VIR_STRDUP(driver->networkAutostartDir,
591
                       SYSCONFDIR "/libvirt/qemu/networks/autostart") < 0 ||
592
            VIR_STRDUP(driver->stateDir,
593
                       LOCALSTATEDIR "/run/libvirt/network") < 0 ||
594
            VIR_STRDUP(driver->pidDir,
595
                       LOCALSTATEDIR "/run/libvirt/network") < 0 ||
596
            VIR_STRDUP(driver->dnsmasqStateDir,
597
                       LOCALSTATEDIR "/lib/libvirt/dnsmasq") < 0 ||
598
            VIR_STRDUP(driver->radvdStateDir,
599 600
                       LOCALSTATEDIR "/lib/libvirt/radvd") < 0)
            goto error;
601 602 603 604 605

        /* migration from old to new location is only applicable for
         * privileged mode - unprivileged mode directories haven't
         * changed location.
         */
606
        if (networkMigrateStateFiles() < 0)
607
            goto error;
608
    } else {
609 610 611
        configdir = virGetUserConfigDirectory();
        rundir = virGetUserRuntimeDirectory();
        if (!(configdir && rundir))
612
            goto error;
613

614
        if ((virAsprintf(&driver->networkConfigDir,
615
                         "%s/qemu/networks", configdir) < 0) ||
616
            (virAsprintf(&driver->networkAutostartDir,
617
                         "%s/qemu/networks/autostart", configdir) < 0) ||
618
            (virAsprintf(&driver->stateDir,
619
                         "%s/network/lib", rundir) < 0) ||
620
            (virAsprintf(&driver->pidDir,
621
                         "%s/network/run", rundir) < 0) ||
622
            (virAsprintf(&driver->dnsmasqStateDir,
623
                         "%s/dnsmasq/lib", rundir) < 0) ||
624
            (virAsprintf(&driver->radvdStateDir,
625
                         "%s/radvd/lib", rundir) < 0)) {
626
            goto error;
627
        }
628 629
    }

630
    if (virFileMakePath(driver->stateDir) < 0) {
631 632
        virReportSystemError(errno,
                             _("cannot create directory %s"),
633
                             driver->stateDir);
634 635 636
        goto error;
    }

637
    /* if this fails now, it will be retried later with dnsmasqCapsRefresh() */
638
    driver->dnsmasqCaps = dnsmasqCapsNewFromBinary(DNSMASQ);
639

640 641
    if (virNetworkLoadAllState(&driver->networks,
                               driver->stateDir) < 0)
642 643
        goto error;

644 645 646
    if (virNetworkLoadAllConfigs(&driver->networks,
                                 driver->networkConfigDir,
                                 driver->networkAutostartDir) < 0)
647 648
        goto error;

649 650 651
    networkUpdateAllState();
    networkReloadFirewallRules();
    networkRefreshDaemons();
652

653
    driver->networkEventState = virObjectEventStateNew();
654

655
    networkDriverUnlock();
656

657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678
#ifdef HAVE_FIREWALLD
    if (!(sysbus = virDBusGetSystemBus())) {
        virErrorPtr err = virGetLastError();
        VIR_WARN("DBus not available, disabling firewalld support "
                 "in bridge_driver: %s", err->message);
    } else {
        /* add matches for
         * NameOwnerChanged on org.freedesktop.DBus for firewalld start/stop
         * Reloaded on org.fedoraproject.FirewallD1 for firewalld reload
         */
        dbus_bus_add_match(sysbus,
                           "type='signal'"
                           ",interface='"DBUS_INTERFACE_DBUS"'"
                           ",member='NameOwnerChanged'"
                           ",arg0='org.fedoraproject.FirewallD1'",
                           NULL);
        dbus_bus_add_match(sysbus,
                           "type='signal'"
                           ",interface='org.fedoraproject.FirewallD1'"
                           ",member='Reloaded'",
                           NULL);
        dbus_connection_add_filter(sysbus, firewalld_dbus_filter_bridge,
679
                                   NULL, NULL);
680 681 682
    }
#endif

683
    ret = 0;
684
 cleanup:
685 686 687
    VIR_FREE(configdir);
    VIR_FREE(rundir);
    return ret;
688

689
 error:
690 691
    if (driver)
        networkDriverUnlock();
692
    networkStateCleanup();
693
    goto cleanup;
694 695
}

696 697 698 699 700 701 702 703
/**
 * networkStateAutoStart:
 *
 * Function to AutoStart the bridge configs
 */
static void
networkStateAutoStart(void)
{
704
    if (!driver)
705 706
        return;

707 708 709
    networkDriverLock();
    networkAutostartConfigs();
    networkDriverUnlock();
710 711
}

712
/**
713
 * networkStateReload:
714 715 716 717 718
 *
 * Function to restart the QEmu daemon, it will recheck the configuration
 * files and update its state and the networking
 */
static int
719 720
networkStateReload(void)
{
721
    if (!driver)
722 723
        return 0;

724 725 726 727 728 729 730 731 732 733
    networkDriverLock();
    virNetworkLoadAllState(&driver->networks,
                           driver->stateDir);
    virNetworkLoadAllConfigs(&driver->networks,
                             driver->networkConfigDir,
                             driver->networkAutostartDir);
    networkReloadFirewallRules();
    networkRefreshDaemons();
    networkAutostartConfigs();
    networkDriverUnlock();
734 735 736 737 738
    return 0;
}


/**
739
 * networkStateCleanup:
740 741 742 743
 *
 * Shutdown the QEmu daemon, it will stop all active domains and networks
 */
static int
744 745
networkStateCleanup(void)
{
746
    if (!driver)
747 748
        return -1;

749
    networkDriverLock();
750

751
    virObjectEventStateFree(driver->networkEventState);
752

753
    /* free inactive networks */
754
    virNetworkObjListFree(&driver->networks);
755

756 757 758 759 760 761
    VIR_FREE(driver->networkConfigDir);
    VIR_FREE(driver->networkAutostartDir);
    VIR_FREE(driver->stateDir);
    VIR_FREE(driver->pidDir);
    VIR_FREE(driver->dnsmasqStateDir);
    VIR_FREE(driver->radvdStateDir);
762

763
    virObjectUnref(driver->dnsmasqCaps);
764

765 766
    networkDriverUnlock();
    virMutexDestroy(&driver->lock);
767

768
    VIR_FREE(driver);
769 770 771 772 773

    return 0;
}


774 775 776 777 778 779 780
/* networkKillDaemon:
 *
 * kill the specified pid/name, and wait a bit to make sure it's dead.
 */
static int
networkKillDaemon(pid_t pid, const char *daemonName, const char *networkName)
{
781 782
    size_t i;
    int ret = -1;
783 784 785 786 787 788 789
    const char *signame = "TERM";

    /* send SIGTERM, then wait up to 3 seconds for the process to
     * disappear, send SIGKILL, then wait for up to another 2
     * seconds. If that fails, log a warning and continue, hoping
     * for the best.
     */
790
    for (i = 0; i < 25; i++) {
791
        int signum = 0;
792
        if (i == 0) {
793
            signum = SIGTERM;
794
        } else if (i == 15) {
795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829
            signum = SIGKILL;
            signame = "KILL";
        }
        if (kill(pid, signum) < 0) {
            if (errno == ESRCH) {
                ret = 0;
            } else {
                char ebuf[1024];
                VIR_WARN("Failed to terminate %s process %d "
                         "for network '%s' with SIG%s: %s",
                         daemonName, pid, networkName, signame,
                         virStrerror(errno, ebuf, sizeof(ebuf)));
            }
            goto cleanup;
        }
        /* NB: since networks have no reference count like
         * domains, there is no safe way to unlock the network
         * object temporarily, and so we can't follow the
         * procedure used by the qemu driver of 1) unlock driver
         * 2) sleep, 3) add ref to object 4) unlock object, 5)
         * re-lock driver, 6) re-lock object. We may need to add
         * that functionality eventually, but for now this
         * function is rarely used and, at worst, leaving the
         * network driver locked during this loop of sleeps will
         * have the effect of holding up any other thread trying
         * to make modifications to a network for up to 5 seconds;
         * since modifications to networks are much less common
         * than modifications to domains, this seems a reasonable
         * tradeoff in exchange for less code disruption.
         */
        usleep(20 * 1000);
    }
    VIR_WARN("Timed out waiting after SIG%s to %s process %d "
             "(network '%s')",
             signame, daemonName, pid, networkName);
830
 cleanup:
831 832 833
    return ret;
}

J
Ján Tomko 已提交
834 835 836
/* the following does not build a file, it builds a list
 * which is later saved into a file
 */
G
Gene Czarcinski 已提交
837

838
static int
G
Gene Czarcinski 已提交
839 840
networkBuildDnsmasqDhcpHostsList(dnsmasqContext *dctx,
                                 virNetworkIpDefPtr ipdef)
841
{
842
    size_t i;
G
Gene Czarcinski 已提交
843
    bool ipv6 = false;
844

G
Gene Czarcinski 已提交
845 846
    if (VIR_SOCKET_ADDR_IS_FAMILY(&ipdef->address, AF_INET6))
        ipv6 = true;
847 848
    for (i = 0; i < ipdef->nhosts; i++) {
        virNetworkDHCPHostDefPtr host = &(ipdef->hosts[i]);
G
Gene Czarcinski 已提交
849
        if (VIR_SOCKET_ADDR_VALID(&host->ip))
850 851
            if (dnsmasqAddDhcpHost(dctx, host->mac, &host->ip,
                                   host->name, host->id, ipv6) < 0)
852
                return -1;
853
    }
854

G
Gene Czarcinski 已提交
855 856 857 858 859 860 861
    return 0;
}

static int
networkBuildDnsmasqHostsList(dnsmasqContext *dctx,
                             virNetworkDNSDefPtr dnsdef)
{
862
    size_t i, j;
G
Gene Czarcinski 已提交
863

864 865
    if (dnsdef) {
        for (i = 0; i < dnsdef->nhosts; i++) {
866
            virNetworkDNSHostDefPtr host = &(dnsdef->hosts[i]);
867
            if (VIR_SOCKET_ADDR_VALID(&host->ip)) {
868
                for (j = 0; j < host->nnames; j++)
869 870
                    if (dnsmasqAddHost(dctx, &host->ip, host->names[j]) < 0)
                        return -1;
871 872
            }
        }
873 874
    }

875
    return 0;
876 877 878
}


879 880
int
networkDnsmasqConfContents(virNetworkObjPtr network,
881 882 883 884
                           const char *pidfile,
                           char **configstr,
                           dnsmasqContext *dctx,
                           dnsmasqCapsPtr caps ATTRIBUTE_UNUSED)
885
{
886
    virBuffer configbuf = VIR_BUFFER_INITIALIZER;
887
    int r, ret = -1;
888
    int nbleases = 0;
889
    size_t i;
890
    virNetworkDNSDefPtr dns = &network->def->dns;
G
Gene Czarcinski 已提交
891 892
    virNetworkIpDefPtr tmpipdef, ipdef, ipv4def, ipv6def;
    bool ipv6SLAAC;
893

894 895
    *configstr = NULL;

896
    /*
897 898 899
     * All dnsmasq parameters are put into a configuration file, except the
     * command line --conf-file=parameter which specifies the location of
     * configuration file.
900
     *
901 902
     * All dnsmasq conf-file parameters must be specified as "foo=bar"
     * as oppose to "--foo bar" which was acceptable on the command line.
903
     */
904 905 906 907 908 909

    /*
     * Needed to ensure dnsmasq uses same algorithm for processing
     * multiple namedriver entries in /etc/resolv.conf as GLibC.
     */

910 911
    /* create dnsmasq config file appropriate for this network */
    virBufferAsprintf(&configbuf,
912 913 914 915 916 917 918
                      "##WARNING:  THIS IS AN AUTO-GENERATED FILE. "
                      "CHANGES TO IT ARE LIKELY TO BE\n"
                      "##OVERWRITTEN AND LOST.  Changes to this "
                      "configuration should be made using:\n"
                      "##    virsh net-edit %s\n"
                      "## or other application using the libvirt API.\n"
                      "##\n## dnsmasq conf file created by libvirt\n"
919
                      "strict-order\n",
920 921
                      network->def->name);

922 923 924 925
    if (network->def->dns.forwarders) {
        virBufferAddLit(&configbuf, "no-resolv\n");
        for (i = 0; i < network->def->dns.nfwds; i++) {
            virBufferAsprintf(&configbuf, "server=%s\n",
J
Ján Tomko 已提交
926
                              network->def->dns.forwarders[i]);
927 928 929
        }
    }

930
    if (network->def->domain) {
931
        virBufferAsprintf(&configbuf,
932 933 934 935
                          "domain=%s\n"
                          "expand-hosts\n",
                          network->def->domain);
    }
936

J
Ján Tomko 已提交
937
    if (network->def->dns.forwardPlainNames == VIR_TRISTATE_BOOL_NO) {
938 939 940 941
        virBufferAddLit(&configbuf, "domain-needed\n");
        /* need to specify local=// whether or not a domain is
         * specified, unless the config says we should forward "plain"
         * names (i.e. not fully qualified, no '.' characters)
942
         */
943
        virBufferAddLit(&configbuf, "local=//\n");
944
    }
945

946
    if (pidfile)
947
        virBufferAsprintf(&configbuf, "pid-file=%s\n", pidfile);
948

949 950 951
    /* dnsmasq will *always* listen on localhost unless told otherwise */
    virBufferAddLit(&configbuf, "except-interface=lo\n");

952 953 954 955 956 957 958 959
    if (dnsmasqCapsGet(caps, DNSMASQ_CAPS_BIND_DYNAMIC)) {
        /* using --bind-dynamic with only --interface (no
         * --listen-address) prevents dnsmasq from responding to dns
         * queries that arrive on some interface other than our bridge
         * interface (in other words, requests originating somewhere
         * other than one of the virtual guests connected directly to
         * this network). This was added in response to CVE 2012-3411.
         */
960
        virBufferAsprintf(&configbuf,
961 962 963
                          "bind-dynamic\n"
                          "interface=%s\n",
                          network->def->bridge);
964
    } else {
965
        virBufferAddLit(&configbuf, "bind-interfaces\n");
966 967 968 969 970 971 972 973
        /*
         * --interface does not actually work with dnsmasq < 2.47,
         * due to DAD for ipv6 addresses on the interface.
         *
         * virCommandAddArgList(cmd, "--interface", network->def->bridge, NULL);
         *
         * So listen on all defined IPv[46] addresses
         */
974 975 976
        for (i = 0;
             (tmpipdef = virNetworkDefGetIpByIndex(network->def, AF_UNSPEC, i));
             i++) {
977 978 979 980
            char *ipaddr = virSocketAddrFormat(&tmpipdef->address);

            if (!ipaddr)
                goto cleanup;
981

982
            /* also part of CVE 2012-3411 - if the host's version of
983
             * dnsmasq doesn't have bind-dynamic, only allow listening on
984 985
             * private/local IP addresses (see RFC1918/RFC3484/RFC4193)
             */
986 987
            if (!dnsmasqCapsGet(caps, DNSMASQ_CAPS_BINDTODEVICE) &&
                !virSocketAddrIsPrivate(&tmpipdef->address)) {
988 989 990 991
                unsigned long version = dnsmasqCapsGetVersion(caps);

                virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                               _("Publicly routable address %s is prohibited. "
992
                                 "The version of dnsmasq on this host (%d.%d) "
993 994 995 996
                                 "doesn't support the bind-dynamic option or "
                                 "use SO_BINDTODEVICE on listening sockets, "
                                 "one of which is required for safe operation "
                                 "on a publicly routable subnet "
997 998 999 1000 1001 1002
                                 "(see CVE-2012-3411). You must either "
                                 "upgrade dnsmasq, or use a private/local "
                                 "subnet range for this network "
                                 "(as described in RFC1918/RFC3484/RFC4193)."),
                               ipaddr, (int)version / 1000000,
                               (int)(version % 1000000) / 1000);
1003
                VIR_FREE(ipaddr);
1004 1005
                goto cleanup;
            }
1006
            virBufferAsprintf(&configbuf, "listen-address=%s\n", ipaddr);
1007 1008 1009
            VIR_FREE(ipaddr);
        }
    }
1010

1011 1012
    /* If this is an isolated network, set the default route option
     * (3) to be empty to avoid setting a default route that's
1013
     * guaranteed to not work, and set no-resolv so that no dns
1014 1015 1016
     * requests are forwarded on to the dns server listed in the
     * host's /etc/resolv.conf (since this could be used as a channel
     * to build a connection to the outside).
1017
     */
1018
    if (network->def->forward.type == VIR_NETWORK_FORWARD_NONE) {
1019
        virBufferAddLit(&configbuf, "dhcp-option=3\n"
1020
                        "no-resolv\n");
1021
    }
1022

1023
    for (i = 0; i < dns->ntxts; i++) {
1024
        virBufferAsprintf(&configbuf, "txt-record=%s,%s\n",
1025 1026
                          dns->txts[i].name,
                          dns->txts[i].value);
1027
    }
1028

1029
    for (i = 0; i < dns->nsrvs; i++) {
1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051
        /* service/protocol are required, and should have been validated
         * by the parser.
         */
        if (!dns->srvs[i].service) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Missing required 'service' "
                             "attribute in SRV record of network '%s'"),
                           network->def->name);
            goto cleanup;
        }
        if (!dns->srvs[i].protocol) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Missing required 'service' "
                             "attribute in SRV record of network '%s'"),
                           network->def->name);
            goto cleanup;
        }
        /* RFC2782 requires that service and protocol be preceded by
         * an underscore.
         */
        virBufferAsprintf(&configbuf, "srv-host=_%s._%s",
                          dns->srvs[i].service, dns->srvs[i].protocol);
1052

1053 1054 1055
        /* domain is optional - it defaults to the domain of this network */
        if (dns->srvs[i].domain)
            virBufferAsprintf(&configbuf, ".%s", dns->srvs[i].domain);
1056

1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078
        /* If target is empty or ".", that means "the service is
         * decidedly not available at this domain" (RFC2782). In that
         * case, any port, priority, or weight is irrelevant.
         */
        if (dns->srvs[i].target && STRNEQ(dns->srvs[i].target, ".")) {

            virBufferAsprintf(&configbuf, ",%s", dns->srvs[i].target);
            /* port, priority, and weight are optional, but are
             * identified by their position in the line. If an item is
             * unspecified, but something later in the line *is*
             * specified, we need to give the default value for the
             * unspecified item. (According to the dnsmasq manpage,
             * the default for port is 1).
             */
            if (dns->srvs[i].port ||
                dns->srvs[i].priority || dns->srvs[i].weight)
                virBufferAsprintf(&configbuf, ",%d",
                                  dns->srvs[i].port ? dns->srvs[i].port : 1);
            if (dns->srvs[i].priority || dns->srvs[i].weight)
                virBufferAsprintf(&configbuf, ",%d", dns->srvs[i].priority);
            if (dns->srvs[i].weight)
                virBufferAsprintf(&configbuf, ",%d", dns->srvs[i].weight);
1079
        }
1080
        virBufferAddLit(&configbuf, "\n");
1081 1082
    }

G
Gene Czarcinski 已提交
1083
    /* Find the first dhcp for both IPv4 and IPv6 */
1084 1085 1086
    for (i = 0, ipv4def = NULL, ipv6def = NULL, ipv6SLAAC = false;
         (ipdef = virNetworkDefGetIpByIndex(network->def, AF_UNSPEC, i));
         i++) {
G
Gene Czarcinski 已提交
1087 1088 1089 1090
        if (VIR_SOCKET_ADDR_IS_FAMILY(&ipdef->address, AF_INET)) {
            if (ipdef->nranges || ipdef->nhosts) {
                if (ipv4def) {
                    virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
1091 1092
                                   _("For IPv4, multiple DHCP definitions "
                                     "cannot be specified."));
G
Gene Czarcinski 已提交
1093 1094 1095 1096 1097 1098 1099 1100 1101 1102 1103
                    goto cleanup;
                } else {
                    ipv4def = ipdef;
                }
            }
        }
        if (VIR_SOCKET_ADDR_IS_FAMILY(&ipdef->address, AF_INET6)) {
            if (ipdef->nranges || ipdef->nhosts) {
                if (!DNSMASQ_DHCPv6_SUPPORT(caps)) {
                    unsigned long version = dnsmasqCapsGetVersion(caps);
                    virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
1104 1105 1106 1107 1108 1109 1110 1111 1112
                                   _("The version of dnsmasq on this host "
                                     "(%d.%d) doesn't adequately support "
                                     "IPv6 dhcp range or dhcp host "
                                     "specification. Version %d.%d or later "
                                     "is required."),
                                   (int)version / 1000000,
                                   (int)(version % 1000000) / 1000,
                                   DNSMASQ_DHCPv6_MAJOR_REQD,
                                   DNSMASQ_DHCPv6_MINOR_REQD);
G
Gene Czarcinski 已提交
1113 1114 1115 1116
                    goto cleanup;
                }
                if (ipv6def) {
                    virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
1117 1118
                                   _("For IPv6, multiple DHCP definitions "
                                     "cannot be specified."));
G
Gene Czarcinski 已提交
1119 1120 1121 1122 1123 1124 1125 1126 1127 1128 1129 1130 1131
                    goto cleanup;
                } else {
                    ipv6def = ipdef;
                }
            } else {
                ipv6SLAAC = true;
            }
        }
    }

    if (ipv6def && ipv6SLAAC) {
        VIR_WARN("For IPv6, when DHCP is specified for one address, then "
                 "state-full Router Advertising will occur.  The additional "
1132 1133 1134 1135
                 "IPv6 addresses specified require manually configured guest "
                 "network to work properly since both state-full (DHCP) "
                 "and state-less (SLAAC) addressing are not supported "
                 "on the same network interface.");
G
Gene Czarcinski 已提交
1136 1137 1138 1139 1140
    }

    ipdef = ipv4def ? ipv4def : ipv6def;

    while (ipdef) {
1141
        for (r = 0; r < ipdef->nranges; r++) {
1142
            char *saddr = virSocketAddrFormat(&ipdef->ranges[r].start);
1143 1144
            if (!saddr)
                goto cleanup;
1145
            char *eaddr = virSocketAddrFormat(&ipdef->ranges[r].end);
1146 1147 1148 1149
            if (!eaddr) {
                VIR_FREE(saddr);
                goto cleanup;
            }
1150
            virBufferAsprintf(&configbuf, "dhcp-range=%s,%s\n",
1151
                              saddr, eaddr);
1152
            VIR_FREE(saddr);
1153
            VIR_FREE(eaddr);
1154 1155
            nbleases += virSocketAddrGetRange(&ipdef->ranges[r].start,
                                              &ipdef->ranges[r].end);
1156
        }
1157

1158
        /*
1159 1160 1161 1162
         * For static-only DHCP, i.e. with no range but at least one
         * host element, we have to add a special --dhcp-range option
         * to enable the service in dnsmasq. (this is for dhcp-hosts=
         * support)
1163 1164
         */
        if (!ipdef->nranges && ipdef->nhosts) {
1165
            char *bridgeaddr = virSocketAddrFormat(&ipdef->address);
1166 1167
            if (!bridgeaddr)
                goto cleanup;
1168
            virBufferAsprintf(&configbuf, "dhcp-range=%s,static\n", bridgeaddr);
1169 1170
            VIR_FREE(bridgeaddr);
        }
1171

G
Gene Czarcinski 已提交
1172 1173
        if (networkBuildDnsmasqDhcpHostsList(dctx, ipdef) < 0)
            goto cleanup;
1174

G
Gene Czarcinski 已提交
1175 1176 1177
        /* Note: the following is IPv4 only */
        if (VIR_SOCKET_ADDR_IS_FAMILY(&ipdef->address, AF_INET)) {
            if (ipdef->nranges || ipdef->nhosts)
1178
                virBufferAddLit(&configbuf, "dhcp-no-override\n");
1179

G
Gene Czarcinski 已提交
1180
            if (ipdef->tftproot) {
1181 1182
                virBufferAddLit(&configbuf, "enable-tftp\n");
                virBufferAsprintf(&configbuf, "tftp-root=%s\n", ipdef->tftproot);
G
Gene Czarcinski 已提交
1183
            }
1184

G
Gene Czarcinski 已提交
1185 1186 1187
            if (ipdef->bootfile) {
                if (VIR_SOCKET_ADDR_VALID(&ipdef->bootserver)) {
                    char *bootserver = virSocketAddrFormat(&ipdef->bootserver);
1188

1189
                    if (!bootserver)
G
Gene Czarcinski 已提交
1190
                        goto cleanup;
1191
                    virBufferAsprintf(&configbuf, "dhcp-boot=%s%s%s\n",
1192
                                      ipdef->bootfile, ",,", bootserver);
G
Gene Czarcinski 已提交
1193 1194
                    VIR_FREE(bootserver);
                } else {
1195
                    virBufferAsprintf(&configbuf, "dhcp-boot=%s\n", ipdef->bootfile);
G
Gene Czarcinski 已提交
1196 1197 1198 1199 1200
                }
            }
        }
        ipdef = (ipdef == ipv6def) ? NULL : ipv6def;
    }
1201

1202
    if (nbleases > 0)
1203
        virBufferAsprintf(&configbuf, "dhcp-lease-max=%d\n", nbleases);
1204

G
Gene Czarcinski 已提交
1205 1206
    /* this is done once per interface */
    if (networkBuildDnsmasqHostsList(dctx, dns) < 0)
1207
        goto cleanup;
G
Gene Czarcinski 已提交
1208 1209 1210 1211 1212 1213

    /* Even if there are currently no static hosts, if we're
     * listening for DHCP, we should write a 0-length hosts
     * file to allow for runtime additions.
     */
    if (ipv4def || ipv6def)
1214 1215
        virBufferAsprintf(&configbuf, "dhcp-hostsfile=%s\n",
                          dctx->hostsfile->path);
G
Gene Czarcinski 已提交
1216

1217 1218
    /* Likewise, always create this file and put it on the
     * commandline, to allow for runtime additions.
G
Gene Czarcinski 已提交
1219
     */
1220
    virBufferAsprintf(&configbuf, "addn-hosts=%s\n",
1221
                      dctx->addnhostsfile->path);
G
Gene Czarcinski 已提交
1222 1223 1224

    /* Are we doing RA instead of radvd? */
    if (DNSMASQ_RA_SUPPORT(caps)) {
1225
        if (ipv6def) {
1226
            virBufferAddLit(&configbuf, "enable-ra\n");
1227
        } else {
1228 1229 1230
            for (i = 0;
                 (ipdef = virNetworkDefGetIpByIndex(network->def, AF_INET6, i));
                 i++) {
G
Gene Czarcinski 已提交
1231 1232 1233 1234
                if (!(ipdef->nranges || ipdef->nhosts)) {
                    char *bridgeaddr = virSocketAddrFormat(&ipdef->address);
                    if (!bridgeaddr)
                        goto cleanup;
1235 1236
                    virBufferAsprintf(&configbuf,
                                      "dhcp-range=%s,ra-only\n", bridgeaddr);
G
Gene Czarcinski 已提交
1237 1238
                    VIR_FREE(bridgeaddr);
                }
1239
            }
1240
        }
1241 1242
    }

1243 1244 1245
    if (!(*configstr = virBufferContentAndReset(&configbuf)))
        goto cleanup;

1246
    ret = 0;
G
Gene Czarcinski 已提交
1247

1248
 cleanup:
1249
    virBufferFreeAndReset(&configbuf);
1250
    return ret;
1251 1252
}

1253
/* build the dnsmasq command line */
1254 1255 1256
static int ATTRIBUTE_NONNULL(2)
networkBuildDhcpDaemonCommandLine(virNetworkObjPtr network,
                                  virCommandPtr *cmdout,
1257 1258
                                  char *pidfile, dnsmasqContext *dctx,
                                  dnsmasqCapsPtr caps)
1259
{
1260
    virCommandPtr cmd = NULL;
G
Gene Czarcinski 已提交
1261
    int ret = -1;
1262 1263
    char *configfile = NULL;
    char *configstr = NULL;
1264
    char *leaseshelper_path = NULL;
1265 1266

    network->dnsmasqPid = -1;
1267

1268 1269 1270 1271 1272 1273
    if (networkDnsmasqConfContents(network, pidfile, &configstr, dctx, caps) < 0)
        goto cleanup;
    if (!configstr)
        goto cleanup;

    /* construct the filename */
1274
    if (!(configfile = networkDnsmasqConfigFileName(network->def->name)))
1275 1276 1277 1278 1279
        goto cleanup;

    /* Write the file */
    if (virFileWriteStr(configfile, configstr, 0600) < 0) {
        virReportSystemError(errno,
J
Ján Tomko 已提交
1280 1281
                             _("couldn't write dnsmasq config file '%s'"),
                             configfile);
1282 1283 1284
        goto cleanup;
    }

1285 1286 1287 1288 1289 1290
    /* This helper is used to create custom leases file for libvirt */
    if (!(leaseshelper_path = virFileFindResource("libvirt_leaseshelper",
                                                  "src",
                                                  LIBEXECDIR)))
        goto cleanup;

1291 1292
    cmd = virCommandNew(dnsmasqCapsGetBinaryPath(caps));
    virCommandAddArgFormat(cmd, "--conf-file=%s", configfile);
1293 1294
    /* Libvirt gains full control of leases database */
    virCommandAddArgFormat(cmd, "--leasefile-ro");
1295
    virCommandAddArgFormat(cmd, "--dhcp-script=%s", leaseshelper_path);
1296
    virCommandAddEnvPair(cmd, "VIR_BRIDGE_NAME", network->def->bridge);
1297

1298
    *cmdout = cmd;
1299
    ret = 0;
1300
 cleanup:
1301 1302
    VIR_FREE(configfile);
    VIR_FREE(configstr);
1303
    VIR_FREE(leaseshelper_path);
1304 1305 1306 1307
    return ret;
}

static int
1308
networkStartDhcpDaemon(virNetworkObjPtr network)
1309 1310 1311 1312
{
    virCommandPtr cmd = NULL;
    char *pidfile = NULL;
    int ret = -1;
1313
    dnsmasqContext *dctx = NULL;
1314

1315
    if (!virNetworkDefGetIpByIndex(network->def, AF_UNSPEC, 0)) {
G
Gene Czarcinski 已提交
1316
        /* no IP addresses, so we don't need to run */
1317 1318 1319 1320
        ret = 0;
        goto cleanup;
    }

1321
    if (virFileMakePath(driver->pidDir) < 0) {
1322
        virReportSystemError(errno,
1323
                             _("cannot create directory %s"),
1324
                             driver->pidDir);
1325
        goto cleanup;
1326 1327
    }

1328
    if (!(pidfile = virPidFileBuildPath(driver->pidDir,
1329
                                        network->def->name)))
1330
        goto cleanup;
1331

1332
    if (virFileMakePath(driver->dnsmasqStateDir) < 0) {
1333
        virReportSystemError(errno,
1334
                             _("cannot create directory %s"),
1335
                             driver->dnsmasqStateDir);
1336 1337 1338
        goto cleanup;
    }

1339
    dctx = dnsmasqContextNew(network->def->name, driver->dnsmasqStateDir);
1340 1341 1342
    if (dctx == NULL)
        goto cleanup;

1343 1344
    if (dnsmasqCapsRefresh(&driver->dnsmasqCaps, NULL) < 0)
        goto cleanup;
1345 1346 1347

    ret = networkBuildDhcpDaemonCommandLine(network, &cmd, pidfile,
                                            dctx, driver->dnsmasqCaps);
1348 1349 1350 1351 1352
    if (ret < 0)
        goto cleanup;

    ret = dnsmasqSave(dctx);
    if (ret < 0)
1353
        goto cleanup;
1354

G
Guido Günther 已提交
1355
    ret = virCommandRun(cmd, NULL);
1356
    if (ret < 0)
1357 1358 1359
        goto cleanup;

    /*
1360 1361 1362 1363 1364
     * There really is no race here - when dnsmasq daemonizes, its
     * leader process stays around until its child has actually
     * written its pidfile. So by time virCommandRun exits it has
     * waitpid'd and guaranteed the proess has started and written a
     * pid
1365 1366
     */

1367
    ret = virPidFileRead(driver->pidDir, network->def->name,
1368 1369
                         &network->dnsmasqPid);
    if (ret < 0)
1370
        goto cleanup;
1371

1372
    ret = 0;
1373
 cleanup:
1374
    VIR_FREE(pidfile);
1375
    virCommandFree(cmd);
1376
    dnsmasqContextFree(dctx);
1377 1378 1379
    return ret;
}

1380 1381
/* networkRefreshDhcpDaemon:
 *  Update dnsmasq config files, then send a SIGHUP so that it rereads
G
Gene Czarcinski 已提交
1382 1383
 *  them.   This only works for the dhcp-hostsfile and the
 *  addn-hosts file.
1384 1385 1386
 *
 *  Returns 0 on success, -1 on failure.
 */
1387
static int
1388
networkRefreshDhcpDaemon(virNetworkObjPtr network)
1389
{
1390 1391
    int ret = -1;
    size_t i;
G
Gene Czarcinski 已提交
1392
    virNetworkIpDefPtr ipdef, ipv4def, ipv6def;
1393
    dnsmasqContext *dctx = NULL;
1394

G
Gene Czarcinski 已提交
1395
    /* if no IP addresses specified, nothing to do */
1396
    if (!virNetworkDefGetIpByIndex(network->def, AF_UNSPEC, 0))
G
Gene Czarcinski 已提交
1397 1398
        return 0;

1399 1400
    /* if there's no running dnsmasq, just start it */
    if (network->dnsmasqPid <= 0 || (kill(network->dnsmasqPid, 0) < 0))
1401
        return networkStartDhcpDaemon(network);
1402

G
Gene Czarcinski 已提交
1403
    VIR_INFO("Refreshing dnsmasq for network %s", network->def->bridge);
1404
    if (!(dctx = dnsmasqContextNew(network->def->name,
1405
                                   driver->dnsmasqStateDir))) {
G
Gene Czarcinski 已提交
1406
        goto cleanup;
1407
    }
G
Gene Czarcinski 已提交
1408 1409 1410 1411 1412 1413

    /* Look for first IPv4 address that has dhcp defined.
     * We only support dhcp-host config on one IPv4 subnetwork
     * and on one IPv6 subnetwork.
     */
    ipv4def = NULL;
1414 1415 1416
    for (i = 0;
         (ipdef = virNetworkDefGetIpByIndex(network->def, AF_INET, i));
         i++) {
G
Gene Czarcinski 已提交
1417 1418
        if (!ipv4def && (ipdef->nranges || ipdef->nhosts))
            ipv4def = ipdef;
1419 1420
    }

G
Gene Czarcinski 已提交
1421
    ipv6def = NULL;
1422 1423 1424
    for (i = 0;
         (ipdef = virNetworkDefGetIpByIndex(network->def, AF_INET6, i));
         i++) {
G
Gene Czarcinski 已提交
1425 1426
        if (!ipv6def && (ipdef->nranges || ipdef->nhosts))
            ipv6def = ipdef;
1427 1428
    }

G
Gene Czarcinski 已提交
1429
    if (ipv4def && (networkBuildDnsmasqDhcpHostsList(dctx, ipv4def) < 0))
J
Ján Tomko 已提交
1430
        goto cleanup;
G
Gene Czarcinski 已提交
1431 1432

    if (ipv6def && (networkBuildDnsmasqDhcpHostsList(dctx, ipv6def) < 0))
J
Ján Tomko 已提交
1433
        goto cleanup;
1434

G
Gene Czarcinski 已提交
1435
    if (networkBuildDnsmasqHostsList(dctx, &network->def->dns) < 0)
J
Ján Tomko 已提交
1436
        goto cleanup;
1437 1438

    if ((ret = dnsmasqSave(dctx)) < 0)
1439
        goto cleanup;
1440 1441

    ret = kill(network->dnsmasqPid, SIGHUP);
1442
 cleanup:
1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454
    dnsmasqContextFree(dctx);
    return ret;
}

/* networkRestartDhcpDaemon:
 *
 * kill and restart dnsmasq, in order to update any config that is on
 * the dnsmasq commandline (and any placed in separate config files).
 *
 *  Returns 0 on success, -1 on failure.
 */
static int
1455
networkRestartDhcpDaemon(virNetworkObjPtr network)
1456 1457 1458 1459 1460 1461
{
    /* if there is a running dnsmasq, kill it */
    if (network->dnsmasqPid > 0) {
        networkKillDaemon(network->dnsmasqPid, "dnsmasq",
                          network->def->name);
        network->dnsmasqPid = -1;
1462
    }
1463
    /* now start dnsmasq if it should be started */
1464
    return networkStartDhcpDaemon(network);
1465 1466
}

G
Gene Czarcinski 已提交
1467 1468 1469 1470 1471 1472
static char radvd1[] = "  AdvOtherConfigFlag off;\n\n";
static char radvd2[] = "    AdvAutonomous off;\n";
static char radvd3[] = "    AdvOnLink on;\n"
                       "    AdvAutonomous on;\n"
                       "    AdvRouterAddr off;\n";

1473 1474 1475
static int
networkRadvdConfContents(virNetworkObjPtr network, char **configstr)
{
E
Eric Blake 已提交
1476
    virBuffer configbuf = VIR_BUFFER_INITIALIZER;
1477 1478
    int ret = -1;
    size_t i;
1479
    virNetworkIpDefPtr ipdef;
G
Gene Czarcinski 已提交
1480
    bool v6present = false, dhcp6 = false;
1481 1482

    *configstr = NULL;
1483

G
Gene Czarcinski 已提交
1484
    /* Check if DHCPv6 is needed */
1485 1486 1487
    for (i = 0;
         (ipdef = virNetworkDefGetIpByIndex(network->def, AF_INET6, i));
         i++) {
G
Gene Czarcinski 已提交
1488 1489 1490 1491 1492 1493 1494 1495 1496 1497 1498 1499 1500
        v6present = true;
        if (ipdef->nranges || ipdef->nhosts) {
            dhcp6 = true;
            break;
        }
    }

    /* If there are no IPv6 addresses, then we are done */
    if (!v6present) {
        ret = 0;
        goto cleanup;
    }

1501 1502 1503
    /* create radvd config file appropriate for this network;
     * IgnoreIfMissing allows radvd to start even when the bridge is down
     */
1504
    virBufferAsprintf(&configbuf, "interface %s\n"
1505 1506
                      "{\n"
                      "  AdvSendAdvert on;\n"
1507
                      "  IgnoreIfMissing on;\n"
G
Gene Czarcinski 已提交
1508 1509 1510 1511 1512
                      "  AdvManagedFlag %s;\n"
                      "%s",
                      network->def->bridge,
                      dhcp6 ? "on" : "off",
                      dhcp6 ? "\n" : radvd1);
1513 1514

    /* add a section for each IPv6 address in the config */
1515 1516 1517
    for (i = 0;
         (ipdef = virNetworkDefGetIpByIndex(network->def, AF_INET6, i));
         i++) {
1518 1519 1520 1521 1522
        int prefix;
        char *netaddr;

        prefix = virNetworkIpDefPrefix(ipdef);
        if (prefix < 0) {
1523 1524 1525
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("bridge '%s' has an invalid prefix"),
                           network->def->bridge);
1526 1527
            goto cleanup;
        }
1528
        if (!(netaddr = virSocketAddrFormat(&ipdef->address)))
1529
            goto cleanup;
1530
        virBufferAsprintf(&configbuf,
1531
                          "  prefix %s/%d\n"
G
Gene Czarcinski 已提交
1532 1533 1534
                          "  {\n%s  };\n",
                          netaddr, prefix,
                          dhcp6 ? radvd2 : radvd3);
1535 1536 1537
        VIR_FREE(netaddr);
    }

1538
    virBufferAddLit(&configbuf, "};\n");
1539

1540
    if (virBufferCheckError(&configbuf) < 0)
1541
        goto cleanup;
1542

1543 1544
    *configstr = virBufferContentAndReset(&configbuf);

1545
    ret = 0;
1546
 cleanup:
1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561 1562 1563 1564 1565 1566 1567 1568
    virBufferFreeAndReset(&configbuf);
    return ret;
}

/* write file and return it's name (which must be freed by caller) */
static int
networkRadvdConfWrite(virNetworkObjPtr network, char **configFile)
{
    int ret = -1;
    char *configStr = NULL;
    char *myConfigFile = NULL;

    if (!configFile)
        configFile = &myConfigFile;

    *configFile = NULL;

    if (networkRadvdConfContents(network, &configStr) < 0)
        goto cleanup;

    if (!configStr) {
        ret = 0;
1569 1570 1571 1572
        goto cleanup;
    }

    /* construct the filename */
1573
    if (!(*configFile = networkRadvdConfigFileName(network->def->name)))
1574 1575
        goto cleanup;
    /* write the file */
1576
    if (virFileWriteStr(*configFile, configStr, 0600) < 0) {
1577 1578
        virReportSystemError(errno,
                             _("couldn't write radvd config file '%s'"),
1579 1580 1581 1582 1583
                             *configFile);
        goto cleanup;
    }

    ret = 0;
1584
 cleanup:
1585 1586 1587 1588 1589 1590
    VIR_FREE(configStr);
    VIR_FREE(myConfigFile);
    return ret;
}

static int
1591
networkStartRadvd(virNetworkObjPtr network)
1592 1593 1594 1595 1596 1597 1598 1599 1600
{
    char *pidfile = NULL;
    char *radvdpidbase = NULL;
    char *configfile = NULL;
    virCommandPtr cmd = NULL;
    int ret = -1;

    network->radvdPid = -1;

G
Gene Czarcinski 已提交
1601
    /* Is dnsmasq handling RA? */
J
Ján Tomko 已提交
1602
    if (DNSMASQ_RA_SUPPORT(driver->dnsmasqCaps)) {
G
Gene Czarcinski 已提交
1603 1604 1605 1606
        ret = 0;
        goto cleanup;
    }

1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617
    if (!virNetworkDefGetIpByIndex(network->def, AF_INET6, 0)) {
        /* no IPv6 addresses, so we don't need to run radvd */
        ret = 0;
        goto cleanup;
    }

    if (!virFileIsExecutable(RADVD)) {
        virReportSystemError(errno,
                             _("Cannot find %s - "
                               "Possibly the package isn't installed"),
                             RADVD);
1618 1619 1620
        goto cleanup;
    }

1621
    if (virFileMakePath(driver->pidDir) < 0) {
1622 1623
        virReportSystemError(errno,
                             _("cannot create directory %s"),
1624
                             driver->pidDir);
1625 1626
        goto cleanup;
    }
1627
    if (virFileMakePath(driver->radvdStateDir) < 0) {
1628 1629
        virReportSystemError(errno,
                             _("cannot create directory %s"),
1630
                             driver->radvdStateDir);
1631 1632 1633 1634
        goto cleanup;
    }

    /* construct pidfile name */
1635
    if (!(radvdpidbase = networkRadvdPidfileBasename(network->def->name)))
1636
        goto cleanup;
1637
    if (!(pidfile = virPidFileBuildPath(driver->pidDir, radvdpidbase)))
1638 1639 1640 1641 1642
        goto cleanup;

    if (networkRadvdConfWrite(network, &configfile) < 0)
        goto cleanup;

1643 1644 1645 1646
    /* prevent radvd from daemonizing itself with "--debug 1", and use
     * a dummy pidfile name - virCommand will create the pidfile we
     * want to use (this is necessary because radvd's internal
     * daemonization and pidfile creation causes a race, and the
1647
     * virPidFileRead() below will fail if we use them).
1648 1649 1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661 1662
     * Unfortunately, it isn't possible to tell radvd to not create
     * its own pidfile, so we just let it do so, with a slightly
     * different name. Unused, but harmless.
     */
    cmd = virCommandNewArgList(RADVD, "--debug", "1",
                               "--config", configfile,
                               "--pidfile", NULL);
    virCommandAddArgFormat(cmd, "%s-bin", pidfile);

    virCommandSetPidFile(cmd, pidfile);
    virCommandDaemonize(cmd);

    if (virCommandRun(cmd, NULL) < 0)
        goto cleanup;

1663
    if (virPidFileRead(driver->pidDir, radvdpidbase, &network->radvdPid) < 0)
1664 1665 1666
        goto cleanup;

    ret = 0;
1667
 cleanup:
1668 1669 1670 1671 1672 1673 1674
    virCommandFree(cmd);
    VIR_FREE(configfile);
    VIR_FREE(radvdpidbase);
    VIR_FREE(pidfile);
    return ret;
}

1675
static int
1676
networkRefreshRadvd(virNetworkObjPtr network)
1677
{
G
Gene Czarcinski 已提交
1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688
    char *radvdpidbase;

    /* Is dnsmasq handling RA? */
    if (DNSMASQ_RA_SUPPORT(driver->dnsmasqCaps)) {
        if (network->radvdPid <= 0)
            return 0;
        /* radvd should not be running but in case it is */
        if ((networkKillDaemon(network->radvdPid, "radvd",
                               network->def->name) >= 0) &&
            ((radvdpidbase = networkRadvdPidfileBasename(network->def->name))
             != NULL)) {
1689
            virPidFileDelete(driver->pidDir, radvdpidbase);
G
Gene Czarcinski 已提交
1690 1691 1692 1693 1694 1695
            VIR_FREE(radvdpidbase);
        }
        network->radvdPid = -1;
        return 0;
    }

1696 1697
    /* if there's no running radvd, just start it */
    if (network->radvdPid <= 0 || (kill(network->radvdPid, 0) < 0))
1698
        return networkStartRadvd(network);
1699 1700 1701 1702 1703 1704 1705 1706 1707 1708 1709 1710

    if (!virNetworkDefGetIpByIndex(network->def, AF_INET6, 0)) {
        /* no IPv6 addresses, so we don't need to run radvd */
        return 0;
    }

    if (networkRadvdConfWrite(network, NULL) < 0)
        return -1;

    return kill(network->radvdPid, SIGHUP);
}

1711 1712
#if 0
/* currently unused, so it causes a build error unless we #if it out */
1713
static int
1714
networkRestartRadvd(virNetworkObjPtr network)
1715 1716 1717 1718 1719 1720 1721 1722 1723
{
    char *radvdpidbase;

    /* if there is a running radvd, kill it */
    if (network->radvdPid > 0) {
        /* essentially ignore errors from the following two functions,
         * since there's really no better recovery to be done than to
         * just push ahead (and that may be exactly what's needed).
         */
G
Gene Czarcinski 已提交
1724
        if ((networkKillDaemon(network->radvdPid, "radvd",
1725 1726 1727
                               network->def->name) >= 0) &&
            ((radvdpidbase = networkRadvdPidfileBasename(network->def->name))
             != NULL)) {
1728
            virPidFileDelete(driver->pidDir, radvdpidbase);
1729 1730 1731 1732 1733 1734 1735 1736 1737
            VIR_FREE(radvdpidbase);
        }
        network->radvdPid = -1;
    }
    /* now start radvd if it should be started */
    return networkStartRadvd(network);
}
#endif /* #if 0 */

1738 1739 1740 1741
/* SIGHUP/restart any dnsmasq or radvd daemons.
 * This should be called when libvirtd is restarted.
 */
static void
1742
networkRefreshDaemons(void)
1743
{
1744
    size_t i;
1745 1746 1747

    VIR_INFO("Refreshing network daemons");

1748
    for (i = 0; i < driver->networks.count; i++) {
1749 1750 1751 1752
        virNetworkObjPtr network = driver->networks.objs[i];

        virNetworkObjLock(network);
        if (virNetworkObjIsActive(network) &&
1753 1754 1755
            ((network->def->forward.type == VIR_NETWORK_FORWARD_NONE) ||
             (network->def->forward.type == VIR_NETWORK_FORWARD_NAT) ||
             (network->def->forward.type == VIR_NETWORK_FORWARD_ROUTE))) {
1756 1757 1758 1759 1760 1761
            /* Only the three L3 network types that are configured by
             * libvirt will have a dnsmasq or radvd daemon associated
             * with them.  Here we send a SIGHUP to an existing
             * dnsmasq and/or radvd, or restart them if they've
             * disappeared.
             */
1762 1763
            networkRefreshDhcpDaemon(network);
            networkRefreshRadvd(network);
1764 1765 1766 1767 1768
        }
        virNetworkObjUnlock(network);
    }
}

1769
static void
1770
networkReloadFirewallRules(void)
1771
{
1772
    size_t i;
1773

1774
    VIR_INFO("Reloading iptables rules");
1775

1776
    for (i = 0; i < driver->networks.count; i++) {
1777 1778 1779 1780
        virNetworkObjPtr network = driver->networks.objs[i];

        virNetworkObjLock(network);
        if (virNetworkObjIsActive(network) &&
1781 1782 1783
            ((network->def->forward.type == VIR_NETWORK_FORWARD_NONE) ||
             (network->def->forward.type == VIR_NETWORK_FORWARD_NAT) ||
             (network->def->forward.type == VIR_NETWORK_FORWARD_ROUTE))) {
1784 1785 1786
            /* Only the three L3 network types that are configured by libvirt
             * need to have iptables rules reloaded.
             */
1787 1788
            networkRemoveFirewallRules(network->def);
            if (networkAddFirewallRules(network->def) < 0) {
1789 1790
                /* failed to add but already logged */
            }
1791
        }
1792
        virNetworkObjUnlock(network);
1793 1794 1795
    }
}

1796
/* Enable IP Forwarding. Return 0 for success, -1 for failure. */
1797
static int
1798
networkEnableIpForwarding(bool enableIPv4, bool enableIPv6)
1799
{
1800
    int ret = 0;
1801 1802 1803 1804
#ifdef HAVE_SYSCTLBYNAME
    int enabled = 1;
    if (enableIPv4)
        ret = sysctlbyname("net.inet.ip.forwarding", NULL, 0,
J
Ján Tomko 已提交
1805
                           &enabled, sizeof(enabled));
1806 1807
    if (enableIPv6 && ret == 0)
        ret = sysctlbyname("net.inet6.ip6.forwarding", NULL, 0,
J
Ján Tomko 已提交
1808
                           &enabled, sizeof(enabled));
1809
#else
1810 1811 1812 1813
    if (enableIPv4)
        ret = virFileWriteStr("/proc/sys/net/ipv4/ip_forward", "1\n", 0);
    if (enableIPv6 && ret == 0)
        ret = virFileWriteStr("/proc/sys/net/ipv6/conf/all/forwarding", "1\n", 0);
1814
#endif
1815
    return ret;
1816 1817
}

1818 1819
#define SYSCTL_PATH "/proc/sys"

1820 1821
static int
networkSetIPv6Sysctls(virNetworkObjPtr network)
1822 1823 1824
{
    char *field = NULL;
    int ret = -1;
1825
    bool enableIPv6 =  !!virNetworkDefGetIpByIndex(network->def, AF_INET6, 0);
1826

1827 1828 1829 1830 1831 1832 1833
    /* set disable_ipv6 if there are no ipv6 addresses defined for the
     * network. But also unset it if there *are* ipv6 addresses, as we
     * can't be sure of its default value.
     */
    if (virAsprintf(&field, SYSCTL_PATH "/net/ipv6/conf/%s/disable_ipv6",
                    network->def->bridge) < 0)
       goto cleanup;
1834

1835 1836
    if (access(field, W_OK) < 0 && errno == ENOENT) {
        if (!enableIPv6)
1837 1838
            VIR_DEBUG("ipv6 appears to already be disabled on %s",
                      network->def->bridge);
1839 1840 1841
        ret = 0;
        goto cleanup;
    }
1842

1843 1844 1845 1846 1847
    if (virFileWriteStr(field, enableIPv6 ? "0" : "1", 0) < 0) {
        virReportSystemError(errno,
                             _("cannot write to %s to enable/disable IPv6 "
                               "on bridge %s"), field, network->def->bridge);
        goto cleanup;
1848
    }
1849
    VIR_FREE(field);
1850

1851 1852
    /* The rest of the ipv6 sysctl tunables should always be set the
     * same, whether or not we're using ipv6 on this bridge.
1853 1854 1855 1856 1857 1858
     */

    /* Prevent guests from hijacking the host network by sending out
     * their own router advertisements.
     */
    if (virAsprintf(&field, SYSCTL_PATH "/net/ipv6/conf/%s/accept_ra",
1859
                    network->def->bridge) < 0)
1860 1861
        goto cleanup;

1862
    if (virFileWriteStr(field, "0", 0) < 0) {
1863
        virReportSystemError(errno,
1864 1865 1866 1867 1868
                             _("cannot disable %s"), field);
        goto cleanup;
    }
    VIR_FREE(field);

1869 1870 1871 1872
    /* All interfaces used as a gateway (which is what this is, by
     * definition), must always have autoconf=0.
     */
    if (virAsprintf(&field, SYSCTL_PATH "/net/ipv6/conf/%s/autoconf",
1873
                    network->def->bridge) < 0)
1874 1875
        goto cleanup;

1876
    if (virFileWriteStr(field, "0", 0) < 0) {
1877
        virReportSystemError(errno,
1878
                             _("cannot disable %s"), field);
1879 1880 1881 1882
        goto cleanup;
    }

    ret = 0;
1883
 cleanup:
1884 1885 1886 1887
    VIR_FREE(field);
    return ret;
}

1888
/* add an IP address to a bridge */
1889
static int
D
Daniel P. Berrange 已提交
1890
networkAddAddrToBridge(virNetworkObjPtr network,
1891
                       virNetworkIpDefPtr ipdef)
1892
{
1893 1894 1895
    int prefix = virNetworkIpDefPrefix(ipdef);

    if (prefix < 0) {
1896 1897 1898
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("bridge '%s' has an invalid netmask or IP address"),
                       network->def->bridge);
1899 1900 1901
        return -1;
    }

1902 1903
    if (virNetDevSetIPv4Address(network->def->bridge,
                                &ipdef->address, prefix) < 0)
1904 1905 1906 1907 1908
        return -1;

    return 0;
}

1909 1910 1911 1912 1913 1914 1915 1916 1917 1918 1919 1920 1921
/* add an IP (static) route to a bridge */
static int
networkAddRouteToBridge(virNetworkObjPtr network,
                        virNetworkRouteDefPtr routedef)
{
    int prefix = 0;
    unsigned int metric;
    virSocketAddrPtr addr = &routedef->address;
    virSocketAddrPtr mask = &routedef->netmask;
    virSocketAddr zero;

    /* this creates an all-0 address of the appropriate family */
    ignore_value(virSocketAddrParse(&zero,
1922
                                    (VIR_SOCKET_ADDR_IS_FAMILY(addr, AF_INET)
1923 1924 1925 1926 1927 1928 1929
                                     ? "0.0.0.0" : "::"),
                                    VIR_SOCKET_ADDR_FAMILY(addr)));

    if (virSocketAddrEqual(addr, &zero)) {
        if (routedef->has_prefix && routedef->prefix == 0)
            prefix = 0;
        else if ((VIR_SOCKET_ADDR_IS_FAMILY(mask, AF_INET) &&
J
Ján Tomko 已提交
1930
                  virSocketAddrEqual(mask, &zero)))
1931 1932 1933 1934 1935 1936 1937 1938 1939 1940 1941 1942 1943 1944 1945 1946 1947 1948 1949 1950 1951 1952 1953 1954 1955 1956 1957
            prefix = 0;
        else
            prefix = virSocketAddrGetIpPrefix(addr, mask, routedef->prefix);
    } else {
        prefix = virSocketAddrGetIpPrefix(addr, mask, routedef->prefix);
    }

    if (prefix < 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("network '%s' has an invalid netmask "
                         "or IP address in route definition"),
                       network->def->name);
        return -1;
    }

    if (routedef->has_metric && routedef->metric > 0)
        metric = routedef->metric;
    else
        metric = 1;

    if (virNetDevAddRoute(network->def->bridge, &routedef->address,
                          prefix, &routedef->gateway, metric) < 0) {
        return -1;
    }
    return 0;
}

1958
static int
1959
networkStartNetworkVirtual(virNetworkObjPtr network)
1960
{
1961
    size_t i;
1962
    bool v4present = false, v6present = false;
1963 1964
    virErrorPtr save_err = NULL;
    virNetworkIpDefPtr ipdef;
1965
    virNetworkRouteDefPtr routedef;
1966
    char *macTapIfName = NULL;
1967
    int tapfd = -1;
1968

1969
    /* Check to see if any network IP collides with an existing route */
1970
    if (networkCheckRouteCollision(network->def) < 0)
1971 1972
        return -1;

1973
    /* Create and configure the bridge device */
1974
    if (virNetDevBridgeCreate(network->def->bridge) < 0)
1975 1976
        return -1;

1977 1978 1979 1980 1981 1982 1983 1984
    if (network->def->mac_specified) {
        /* To set a mac for the bridge, we need to define a dummy tap
         * device, set its mac, then attach it to the bridge. As long
         * as its mac address is lower than any other interface that
         * gets attached, the bridge will always maintain this mac
         * address.
         */
        macTapIfName = networkBridgeDummyNicName(network->def->bridge);
1985
        if (!macTapIfName)
1986
            goto err0;
1987
        /* Keep tun fd open and interface up to allow for IPv6 DAD to happen */
1988
        if (virNetDevTapCreateInBridgePort(network->def->bridge,
1989
                                           &macTapIfName, &network->def->mac,
1990
                                           NULL, NULL, &tapfd, 1, NULL, NULL,
1991 1992 1993
                                           VIR_NETDEV_TAP_CREATE_USE_MAC_FOR_BRIDGE |
                                           VIR_NETDEV_TAP_CREATE_IFUP |
                                           VIR_NETDEV_TAP_CREATE_PERSIST) < 0) {
1994 1995 1996 1997 1998
            VIR_FREE(macTapIfName);
            goto err0;
        }
    }

1999
    /* Set bridge options */
2000 2001 2002 2003

    /* delay is configured in seconds, but virNetDevBridgeSetSTPDelay
     * expects milliseconds
     */
2004
    if (virNetDevBridgeSetSTPDelay(network->def->bridge,
2005
                                   network->def->delay * 1000) < 0)
2006
        goto err1;
2007

2008
    if (virNetDevBridgeSetSTP(network->def->bridge,
2009
                              network->def->stp ? true : false) < 0)
2010
        goto err1;
2011

2012 2013 2014 2015
    /* Disable IPv6 on the bridge if there are no IPv6 addresses
     * defined, and set other IPv6 sysctl tunables appropriately.
     */
    if (networkSetIPv6Sysctls(network) < 0)
2016
        goto err1;
2017

2018
    /* Add "once per network" rules */
2019
    if (networkAddFirewallRules(network->def) < 0)
2020 2021
        goto err1;

2022 2023 2024
    for (i = 0;
         (ipdef = virNetworkDefGetIpByIndex(network->def, AF_UNSPEC, i));
         i++) {
2025
        if (VIR_SOCKET_ADDR_IS_FAMILY(&ipdef->address, AF_INET))
2026
            v4present = true;
2027
        if (VIR_SOCKET_ADDR_IS_FAMILY(&ipdef->address, AF_INET6))
2028
            v6present = true;
2029

2030
        /* Add the IP address/netmask to the bridge */
2031
        if (networkAddAddrToBridge(network, ipdef) < 0)
2032
            goto err2;
2033 2034
    }

2035
    /* Bring up the bridge interface */
2036
    if (virNetDevSetOnline(network->def->bridge, 1) < 0)
2037
        goto err2;
2038

2039 2040
    for (i = 0; i < network->def->nroutes; i++) {
        routedef = &network->def->routes[i];
2041 2042 2043 2044 2045 2046 2047 2048 2049 2050 2051
        /* Add the IP route to the bridge */
        /* ignore errors, error msg will be generated */
        /* but libvirt will not know and net-destroy will work. */
        if (VIR_SOCKET_ADDR_VALID(&routedef->gateway)) {
            if (networkAddRouteToBridge(network, routedef) < 0) {
                /* an error occurred adding the static route */
                continue; /* for now, do nothing */
            }
        }
    }

2052 2053
    /* If forward.type != NONE, turn on global IP forwarding */
    if (network->def->forward.type != VIR_NETWORK_FORWARD_NONE &&
2054
        networkEnableIpForwarding(v4present, v6present) < 0) {
2055
        virReportSystemError(errno, "%s",
2056
                             _("failed to enable IP forwarding"));
2057
        goto err3;
2058 2059
    }

2060

2061
    /* start dnsmasq if there are any IP addresses (v4 or v6) */
2062
    if ((v4present || v6present) &&
2063
        networkStartDhcpDaemon(network) < 0)
2064
        goto err3;
2065

2066
    /* start radvd if there are any ipv6 addresses */
2067
    if (v6present && networkStartRadvd(network) < 0)
2068 2069
        goto err4;

2070 2071 2072 2073 2074 2075 2076 2077 2078
    /* DAD has happened (dnsmasq waits for it), dnsmasq is now bound to the
     * bridge's IPv6 address, so we can now set the dummy tun down.
     */
    if (tapfd >= 0) {
        if (virNetDevSetOnline(macTapIfName, false) < 0)
            goto err4;
        VIR_FORCE_CLOSE(tapfd);
    }

2079
    if (virNetDevBandwidthSet(network->def->bridge,
2080
                              network->def->bandwidth, true) < 0)
2081 2082
        goto err5;

2083
    VIR_FREE(macTapIfName);
2084 2085 2086

    return 0;

2087
 err5:
2088
    virNetDevBandwidthClear(network->def->bridge);
2089

2090 2091 2092 2093
 err4:
    if (!save_err)
        save_err = virSaveLastError();

2094 2095 2096 2097 2098
    if (network->dnsmasqPid > 0) {
        kill(network->dnsmasqPid, SIGTERM);
        network->dnsmasqPid = -1;
    }

2099 2100 2101
 err3:
    if (!save_err)
        save_err = virSaveLastError();
2102
    ignore_value(virNetDevSetOnline(network->def->bridge, 0));
2103

2104 2105 2106
 err2:
    if (!save_err)
        save_err = virSaveLastError();
2107
    networkRemoveFirewallRules(network->def);
2108 2109

 err1:
2110 2111 2112
    if (!save_err)
        save_err = virSaveLastError();

H
Hu Tao 已提交
2113
    if (macTapIfName) {
2114
        VIR_FORCE_CLOSE(tapfd);
2115
        ignore_value(virNetDevTapDelete(macTapIfName, NULL));
H
Hu Tao 已提交
2116 2117
        VIR_FREE(macTapIfName);
    }
2118 2119

 err0:
2120 2121
    if (!save_err)
        save_err = virSaveLastError();
2122
    ignore_value(virNetDevBridgeDelete(network->def->bridge));
2123

2124 2125 2126 2127
    if (save_err) {
        virSetError(save_err);
        virFreeError(save_err);
    }
2128
    /* coverity[leaked_handle] - 'tapfd' is not leaked */
2129 2130 2131
    return -1;
}

2132
static int networkShutdownNetworkVirtual(virNetworkObjPtr network)
2133
{
2134
    virNetDevBandwidthClear(network->def->bridge);
2135

2136 2137 2138 2139 2140
    if (network->radvdPid > 0) {
        char *radvdpidbase;

        kill(network->radvdPid, SIGTERM);
        /* attempt to delete the pidfile we created */
2141
        if ((radvdpidbase = networkRadvdPidfileBasename(network->def->name))) {
2142
            virPidFileDelete(driver->pidDir, radvdpidbase);
2143 2144 2145 2146
            VIR_FREE(radvdpidbase);
        }
    }

2147 2148 2149
    if (network->dnsmasqPid > 0)
        kill(network->dnsmasqPid, SIGTERM);

2150
    if (network->def->mac_specified) {
2151
        char *macTapIfName = networkBridgeDummyNicName(network->def->bridge);
2152
        if (macTapIfName) {
2153
            ignore_value(virNetDevTapDelete(macTapIfName, NULL));
2154 2155 2156 2157
            VIR_FREE(macTapIfName);
        }
    }

2158
    ignore_value(virNetDevSetOnline(network->def->bridge, 0));
2159

2160
    networkRemoveFirewallRules(network->def);
2161

2162
    ignore_value(virNetDevBridgeDelete(network->def->bridge));
2163

2164
    /* See if its still alive and really really kill it */
2165
    if (network->dnsmasqPid > 0 &&
2166
        (kill(network->dnsmasqPid, 0) == 0))
2167 2168
        kill(network->dnsmasqPid, SIGKILL);
    network->dnsmasqPid = -1;
2169 2170 2171 2172 2173 2174

    if (network->radvdPid > 0 &&
        (kill(network->radvdPid, 0) == 0))
        kill(network->radvdPid, SIGKILL);
    network->radvdPid = -1;

2175 2176 2177
    return 0;
}

2178 2179 2180 2181 2182 2183 2184 2185 2186 2187 2188 2189 2190 2191 2192 2193

/* networkCreateInterfacePool:
 * @netdef: the original NetDef from the network
 *
 * Creates an implicit interface pool of VF's when a PF dev is given
 */
static int
networkCreateInterfacePool(virNetworkDefPtr netdef)
{
    size_t numVirtFns = 0;
    char **vfNames = NULL;
    virPCIDeviceAddressPtr *virtFns;

    int ret = -1;
    size_t i;

2194 2195 2196
    if (netdef->forward.npfs == 0 || netdef->forward.nifs > 0)
       return 0;

2197 2198 2199 2200 2201 2202 2203 2204 2205 2206 2207 2208 2209 2210 2211 2212 2213 2214 2215 2216 2217 2218 2219 2220 2221 2222 2223 2224 2225 2226 2227 2228 2229 2230 2231 2232 2233 2234 2235 2236 2237 2238 2239 2240 2241 2242 2243 2244 2245 2246 2247 2248 2249 2250 2251 2252 2253 2254 2255 2256 2257 2258 2259 2260 2261 2262 2263 2264 2265 2266 2267 2268 2269 2270 2271 2272 2273 2274 2275 2276 2277 2278 2279 2280 2281 2282 2283 2284
    if ((virNetDevGetVirtualFunctions(netdef->forward.pfs->dev,
                                      &vfNames, &virtFns, &numVirtFns)) < 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Could not get Virtual functions on %s"),
                       netdef->forward.pfs->dev);
        goto cleanup;
    }

    if (VIR_ALLOC_N(netdef->forward.ifs, numVirtFns) < 0)
        goto cleanup;

    for (i = 0; i < numVirtFns; i++) {
        virPCIDeviceAddressPtr thisVirtFn = virtFns[i];
        const char *thisName = vfNames[i];
        virNetworkForwardIfDefPtr thisIf
            = &netdef->forward.ifs[netdef->forward.nifs];

        switch (netdef->forward.type) {
        case VIR_NETWORK_FORWARD_BRIDGE:
        case VIR_NETWORK_FORWARD_PRIVATE:
        case VIR_NETWORK_FORWARD_VEPA:
        case VIR_NETWORK_FORWARD_PASSTHROUGH:
            if (thisName) {
                if (VIR_STRDUP(thisIf->device.dev, thisName) < 0)
                    goto cleanup;
                thisIf->type = VIR_NETWORK_FORWARD_HOSTDEV_DEVICE_NETDEV;
                netdef->forward.nifs++;
            } else {
                VIR_WARN("VF %zu of SRIOV PF %s couldn't be added to the "
                         "interface pool because it isn't bound "
                         "to a network driver - possibly in use elsewhere",
                         i, netdef->forward.pfs->dev);
            }
            break;

        case VIR_NETWORK_FORWARD_HOSTDEV:
            /* VF's are always PCI devices */
            thisIf->type = VIR_NETWORK_FORWARD_HOSTDEV_DEVICE_PCI;
            thisIf->device.pci.domain = thisVirtFn->domain;
            thisIf->device.pci.bus = thisVirtFn->bus;
            thisIf->device.pci.slot = thisVirtFn->slot;
            thisIf->device.pci.function = thisVirtFn->function;
            netdef->forward.nifs++;
            break;

        case VIR_NETWORK_FORWARD_NONE:
        case VIR_NETWORK_FORWARD_NAT:
        case VIR_NETWORK_FORWARD_ROUTE:
        case VIR_NETWORK_FORWARD_LAST:
            /* by definition these will never be encountered here */
            break;
        }
    }

    if (netdef->forward.nifs == 0) {
        /* If we don't get at least one interface in the pool, declare
         * failure
         */
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No usable Vf's present on SRIOV PF %s"),
                       netdef->forward.pfs->dev);
        goto cleanup;
    }

    ret = 0;
 cleanup:
    if (ret < 0) {
        /* free all the entries made before error */
        for (i = 0; i < netdef->forward.nifs; i++) {
            if (netdef->forward.ifs[i].type
                == VIR_NETWORK_FORWARD_HOSTDEV_DEVICE_NETDEV)
                VIR_FREE(netdef->forward.ifs[i].device.dev);
        }
        netdef->forward.nifs = 0;
    }
    if (netdef->forward.nifs == 0)
        VIR_FREE(netdef->forward.ifs);

    for (i = 0; i < numVirtFns; i++) {
        VIR_FREE(vfNames[i]);
        VIR_FREE(virtFns[i]);
    }
    VIR_FREE(vfNames);
    VIR_FREE(virtFns);
    return ret;
}


2285
static int
2286
networkStartNetworkExternal(virNetworkObjPtr network)
2287 2288
{
    /* put anything here that needs to be done each time a network of
2289
     * type BRIDGE, PRIVATE, VEPA, HOSTDEV or PASSTHROUGH is started. On
2290 2291 2292
     * failure, undo anything you've done, and return -1. On success
     * return 0.
     */
2293
    return networkCreateInterfacePool(network->def);
2294 2295
}

2296
static int networkShutdownNetworkExternal(virNetworkObjPtr network ATTRIBUTE_UNUSED)
2297 2298
{
    /* put anything here that needs to be done each time a network of
2299
     * type BRIDGE, PRIVATE, VEPA, HOSTDEV or PASSTHROUGH is shutdown. On
2300 2301 2302 2303 2304 2305 2306
     * failure, undo anything you've done, and return -1. On success
     * return 0.
     */
    return 0;
}

static int
2307
networkStartNetwork(virNetworkObjPtr network)
2308
{
2309 2310 2311
    int ret = -1;

    VIR_DEBUG("driver=%p, network=%p", driver, network);
2312 2313

    if (virNetworkObjIsActive(network)) {
2314 2315
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("network is already active"));
2316
        return ret;
2317 2318
    }

2319 2320 2321
    VIR_DEBUG("Beginning network startup process");

    VIR_DEBUG("Setting current network def as transient");
2322
    if (virNetworkObjSetDefTransient(network, true) < 0)
2323
        goto cleanup;
2324

2325 2326
    /* Run an early hook to set-up missing devices.
     * If the script raised an error abort the launch. */
2327
    if (networkRunHook(network, NULL, NULL,
2328 2329 2330 2331
                       VIR_HOOK_NETWORK_OP_START,
                       VIR_HOOK_SUBOP_BEGIN) < 0)
        goto cleanup;

2332
    switch (network->def->forward.type) {
2333 2334 2335 2336

    case VIR_NETWORK_FORWARD_NONE:
    case VIR_NETWORK_FORWARD_NAT:
    case VIR_NETWORK_FORWARD_ROUTE:
2337
        if (networkStartNetworkVirtual(network) < 0)
2338
            goto cleanup;
2339 2340 2341 2342 2343 2344
        break;

    case VIR_NETWORK_FORWARD_BRIDGE:
    case VIR_NETWORK_FORWARD_PRIVATE:
    case VIR_NETWORK_FORWARD_VEPA:
    case VIR_NETWORK_FORWARD_PASSTHROUGH:
2345
    case VIR_NETWORK_FORWARD_HOSTDEV:
2346
        if (networkStartNetworkExternal(network) < 0)
2347
            goto cleanup;
2348 2349 2350
        break;
    }

2351
    /* finally we can call the 'started' hook script if any */
2352
    if (networkRunHook(network, NULL, NULL,
2353 2354 2355 2356
                       VIR_HOOK_NETWORK_OP_STARTED,
                       VIR_HOOK_SUBOP_BEGIN) < 0)
        goto cleanup;

2357 2358 2359
    /* Persist the live configuration now that anything autogenerated
     * is setup.
     */
2360
    VIR_DEBUG("Writing network status to disk");
2361
    if (virNetworkSaveStatus(driver->stateDir, network) < 0)
2362
        goto cleanup;
2363 2364

    network->active = 1;
2365 2366
    VIR_INFO("Network '%s' started up", network->def->name);
    ret = 0;
2367

2368
 cleanup:
2369
    if (ret < 0) {
2370
        virNetworkObjUnsetDefTransient(network);
2371 2372
        virErrorPtr save_err = virSaveLastError();
        int save_errno = errno;
2373
        networkShutdownNetwork(network);
2374 2375 2376 2377 2378 2379 2380
        virSetError(save_err);
        virFreeError(save_err);
        errno = save_errno;
    }
    return ret;
}

2381
static int networkShutdownNetwork(virNetworkObjPtr network)
2382 2383 2384 2385 2386 2387 2388 2389 2390
{
    int ret = 0;
    char *stateFile;

    VIR_INFO("Shutting down network '%s'", network->def->name);

    if (!virNetworkObjIsActive(network))
        return 0;

2391
    stateFile = virNetworkConfigFile(driver->stateDir,
2392
                                     network->def->name);
2393 2394 2395 2396 2397 2398
    if (!stateFile)
        return -1;

    unlink(stateFile);
    VIR_FREE(stateFile);

2399
    switch (network->def->forward.type) {
2400 2401 2402 2403

    case VIR_NETWORK_FORWARD_NONE:
    case VIR_NETWORK_FORWARD_NAT:
    case VIR_NETWORK_FORWARD_ROUTE:
2404
        ret = networkShutdownNetworkVirtual(network);
2405 2406 2407 2408 2409 2410
        break;

    case VIR_NETWORK_FORWARD_BRIDGE:
    case VIR_NETWORK_FORWARD_PRIVATE:
    case VIR_NETWORK_FORWARD_VEPA:
    case VIR_NETWORK_FORWARD_PASSTHROUGH:
2411
    case VIR_NETWORK_FORWARD_HOSTDEV:
2412
        ret = networkShutdownNetworkExternal(network);
2413 2414 2415
        break;
    }

2416
    /* now that we know it's stopped call the hook if present */
2417
    networkRunHook(network, NULL, NULL, VIR_HOOK_NETWORK_OP_STOPPED,
2418 2419
                   VIR_HOOK_SUBOP_END);

2420
    network->active = 0;
2421
    virNetworkObjUnsetDefTransient(network);
2422
    return ret;
2423 2424 2425
}


2426
static virNetworkPtr networkLookupByUUID(virConnectPtr conn,
2427 2428
                                         const unsigned char *uuid)
{
2429 2430
    virNetworkObjPtr network;
    virNetworkPtr ret = NULL;
2431

2432
    networkDriverLock();
2433
    network = virNetworkFindByUUID(&driver->networks, uuid);
2434
    networkDriverUnlock();
2435
    if (!network) {
2436 2437
        virReportError(VIR_ERR_NO_NETWORK,
                       "%s", _("no network with matching uuid"));
2438
        goto cleanup;
2439 2440
    }

2441 2442 2443
    if (virNetworkLookupByUUIDEnsureACL(conn, network->def) < 0)
        goto cleanup;

2444 2445
    ret = virGetNetwork(conn, network->def->name, network->def->uuid);

2446
 cleanup:
2447 2448
    if (network)
        virNetworkObjUnlock(network);
2449
    return ret;
2450 2451
}

2452
static virNetworkPtr networkLookupByName(virConnectPtr conn,
2453 2454
                                         const char *name)
{
2455 2456 2457
    virNetworkObjPtr network;
    virNetworkPtr ret = NULL;

2458
    networkDriverLock();
2459
    network = virNetworkFindByName(&driver->networks, name);
2460
    networkDriverUnlock();
2461
    if (!network) {
2462 2463
        virReportError(VIR_ERR_NO_NETWORK,
                       _("no network with matching name '%s'"), name);
2464
        goto cleanup;
2465 2466
    }

2467 2468 2469
    if (virNetworkLookupByNameEnsureACL(conn, network->def) < 0)
        goto cleanup;

2470 2471
    ret = virGetNetwork(conn, network->def->name, network->def->uuid);

2472
 cleanup:
2473 2474
    if (network)
        virNetworkObjUnlock(network);
2475
    return ret;
2476 2477
}

2478
static virDrvOpenStatus networkOpen(virConnectPtr conn ATTRIBUTE_UNUSED,
2479 2480
                                    virConnectAuthPtr auth ATTRIBUTE_UNUSED,
                                    unsigned int flags)
2481 2482 2483
{
    virCheckFlags(VIR_CONNECT_RO, VIR_DRV_OPEN_ERROR);

2484
    if (!driver)
2485 2486 2487 2488 2489
        return VIR_DRV_OPEN_DECLINED;

    return VIR_DRV_OPEN_SUCCESS;
}

2490
static int networkClose(virConnectPtr conn ATTRIBUTE_UNUSED)
2491
{
2492 2493 2494
    return 0;
}

2495 2496
static int networkConnectNumOfNetworks(virConnectPtr conn)
{
2497 2498
    int nactive = 0;
    size_t i;
2499

2500 2501 2502
    if (virConnectNumOfNetworksEnsureACL(conn) < 0)
        return -1;

2503
    networkDriverLock();
2504
    for (i = 0; i < driver->networks.count; i++) {
2505 2506 2507 2508
        virNetworkObjPtr obj = driver->networks.objs[i];
        virNetworkObjLock(obj);
        if (virConnectNumOfNetworksCheckACL(conn, obj->def) &&
            virNetworkObjIsActive(obj))
2509
            nactive++;
2510
        virNetworkObjUnlock(obj);
2511
    }
2512
    networkDriverUnlock();
2513

2514 2515 2516
    return nactive;
}

2517
static int networkConnectListNetworks(virConnectPtr conn, char **const names, int nnames) {
2518 2519
    int got = 0;
    size_t i;
2520

2521 2522 2523
    if (virConnectListNetworksEnsureACL(conn) < 0)
        return -1;

2524
    networkDriverLock();
2525
    for (i = 0; i < driver->networks.count && got < nnames; i++) {
2526 2527 2528 2529 2530 2531
        virNetworkObjPtr obj = driver->networks.objs[i];
        virNetworkObjLock(obj);
        if (virConnectListNetworksCheckACL(conn, obj->def) &&
            virNetworkObjIsActive(obj)) {
            if (VIR_STRDUP(names[got], obj->def->name) < 0) {
                virNetworkObjUnlock(obj);
2532 2533 2534 2535
                goto cleanup;
            }
            got++;
        }
2536
        virNetworkObjUnlock(obj);
2537
    }
2538
    networkDriverUnlock();
2539

2540 2541 2542
    return got;

 cleanup:
2543
    networkDriverUnlock();
2544
    for (i = 0; i < got; i++)
2545 2546 2547 2548
        VIR_FREE(names[i]);
    return -1;
}

2549 2550
static int networkConnectNumOfDefinedNetworks(virConnectPtr conn)
{
2551 2552
    int ninactive = 0;
    size_t i;
2553

2554 2555 2556
    if (virConnectNumOfDefinedNetworksEnsureACL(conn) < 0)
        return -1;

2557
    networkDriverLock();
2558
    for (i = 0; i < driver->networks.count; i++) {
2559 2560 2561 2562
        virNetworkObjPtr obj = driver->networks.objs[i];
        virNetworkObjLock(obj);
        if (virConnectNumOfDefinedNetworksCheckACL(conn, obj->def) &&
            !virNetworkObjIsActive(obj))
2563
            ninactive++;
2564
        virNetworkObjUnlock(obj);
2565
    }
2566
    networkDriverUnlock();
2567

2568 2569 2570
    return ninactive;
}

2571
static int networkConnectListDefinedNetworks(virConnectPtr conn, char **const names, int nnames) {
2572 2573
    int got = 0;
    size_t i;
2574

2575 2576 2577
    if (virConnectListDefinedNetworksEnsureACL(conn) < 0)
        return -1;

2578
    networkDriverLock();
2579
    for (i = 0; i < driver->networks.count && got < nnames; i++) {
2580 2581 2582 2583 2584 2585
        virNetworkObjPtr obj = driver->networks.objs[i];
        virNetworkObjLock(obj);
        if (virConnectListDefinedNetworksCheckACL(conn, obj->def) &&
            !virNetworkObjIsActive(obj)) {
            if (VIR_STRDUP(names[got], obj->def->name) < 0) {
                virNetworkObjUnlock(obj);
2586 2587 2588 2589
                goto cleanup;
            }
            got++;
        }
2590
        virNetworkObjUnlock(obj);
2591
    }
2592
    networkDriverUnlock();
2593 2594 2595
    return got;

 cleanup:
2596
    networkDriverUnlock();
2597
    for (i = 0; i < got; i++)
2598 2599 2600 2601
        VIR_FREE(names[i]);
    return -1;
}

2602
static int
2603 2604 2605
networkConnectListAllNetworks(virConnectPtr conn,
                              virNetworkPtr **nets,
                              unsigned int flags)
2606 2607 2608 2609 2610
{
    int ret = -1;

    virCheckFlags(VIR_CONNECT_LIST_NETWORKS_FILTERS_ALL, -1);

2611 2612 2613
    if (virConnectListAllNetworksEnsureACL(conn) < 0)
        goto cleanup;

2614
    networkDriverLock();
2615 2616 2617
    ret = virNetworkObjListExport(conn, driver->networks, nets,
                                  virConnectListAllNetworksCheckACL,
                                  flags);
2618
    networkDriverUnlock();
2619

2620
 cleanup:
2621 2622
    return ret;
}
2623

2624 2625 2626 2627 2628 2629 2630 2631 2632 2633 2634 2635 2636 2637
static int
networkConnectNetworkEventRegisterAny(virConnectPtr conn,
                                      virNetworkPtr net,
                                      int eventID,
                                      virConnectNetworkEventGenericCallback callback,
                                      void *opaque,
                                      virFreeCallback freecb)
{
    int ret = -1;

    if (virConnectNetworkEventRegisterAnyEnsureACL(conn) < 0)
        goto cleanup;

    if (virNetworkEventStateRegisterID(conn, driver->networkEventState,
2638
                                       net, eventID, callback,
2639 2640 2641
                                       opaque, freecb, &ret) < 0)
        ret = -1;

2642
 cleanup:
2643 2644 2645 2646 2647 2648 2649 2650 2651 2652 2653 2654
    return ret;
}

static int
networkConnectNetworkEventDeregisterAny(virConnectPtr conn,
                                        int callbackID)
{
    int ret = -1;

    if (virConnectNetworkEventDeregisterAnyEnsureACL(conn) < 0)
        goto cleanup;

2655 2656 2657 2658 2659 2660
    if (virObjectEventStateDeregisterID(conn,
                                        driver->networkEventState,
                                        callbackID) < 0)
        goto cleanup;

    ret = 0;
2661

2662
 cleanup:
2663 2664 2665
    return ret;
}

2666 2667 2668 2669 2670
static int networkIsActive(virNetworkPtr net)
{
    virNetworkObjPtr obj;
    int ret = -1;

2671 2672
    if (!(obj = networkObjFromNetwork(net)))
        return ret;
2673 2674 2675 2676

    if (virNetworkIsActiveEnsureACL(net->conn, obj->def) < 0)
        goto cleanup;

2677 2678
    ret = virNetworkObjIsActive(obj);

2679
 cleanup:
2680 2681 2682 2683 2684 2685 2686 2687 2688 2689
    if (obj)
        virNetworkObjUnlock(obj);
    return ret;
}

static int networkIsPersistent(virNetworkPtr net)
{
    virNetworkObjPtr obj;
    int ret = -1;

2690 2691
    if (!(obj = networkObjFromNetwork(net)))
        return ret;
2692 2693 2694 2695

    if (virNetworkIsPersistentEnsureACL(net->conn, obj->def) < 0)
        goto cleanup;

2696 2697
    ret = obj->persistent;

2698
 cleanup:
2699 2700 2701 2702 2703 2704
    if (obj)
        virNetworkObjUnlock(obj);
    return ret;
}


2705
static int
2706
networkValidate(virNetworkDefPtr def,
2707
                bool check_active)
2708
{
2709
    size_t i;
2710 2711
    bool vlanUsed, vlanAllowed, badVlanUse = false;
    virPortGroupDefPtr defaultPortGroup = NULL;
2712
    virNetworkIpDefPtr ipdef;
G
Gene Czarcinski 已提交
2713
    bool ipv4def = false, ipv6def = false;
2714 2715 2716 2717 2718 2719 2720 2721

    /* check for duplicate networks */
    if (virNetworkObjIsDuplicate(&driver->networks, def, check_active) < 0)
        return -1;

    /* Only the three L3 network types that are configured by libvirt
     * need to have a bridge device name / mac address provided
     */
2722 2723 2724
    if (def->forward.type == VIR_NETWORK_FORWARD_NONE ||
        def->forward.type == VIR_NETWORK_FORWARD_NAT ||
        def->forward.type == VIR_NETWORK_FORWARD_ROUTE) {
2725 2726 2727 2728 2729

        if (virNetworkSetBridgeName(&driver->networks, def, 1))
            return -1;

        virNetworkSetBridgeMacAddr(def);
2730 2731
    } else {
        /* They are also the only types that currently support setting
2732 2733
         * a MAC or IP address for the host-side device (bridge), DNS
         * configuration, or network-wide bandwidth limits.
2734
         */
2735 2736 2737 2738 2739 2740 2741 2742
        if (def->mac_specified) {
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                           _("Unsupported <mac> element in network %s "
                             "with forward mode='%s'"),
                           def->name,
                           virNetworkForwardTypeToString(def->forward.type));
            return -1;
        }
2743 2744 2745 2746 2747
        if (virNetworkDefGetIpByIndex(def, AF_UNSPEC, 0)) {
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                           _("Unsupported <ip> element in network %s "
                             "with forward mode='%s'"),
                           def->name,
2748
                           virNetworkForwardTypeToString(def->forward.type));
2749 2750
            return -1;
        }
2751
        if (def->dns.ntxts || def->dns.nhosts || def->dns.nsrvs) {
2752 2753 2754 2755
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                           _("Unsupported <dns> element in network %s "
                             "with forward mode='%s'"),
                           def->name,
2756
                           virNetworkForwardTypeToString(def->forward.type));
2757 2758 2759 2760 2761 2762 2763
            return -1;
        }
        if (def->domain) {
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                           _("Unsupported <domain> element in network %s "
                             "with forward mode='%s'"),
                           def->name,
2764
                           virNetworkForwardTypeToString(def->forward.type));
2765 2766
            return -1;
        }
2767 2768 2769 2770 2771 2772 2773 2774
        if (def->bandwidth) {
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                           _("Unsupported network-wide <bandwidth> element "
                             "in network %s with forward mode='%s'"),
                           def->name,
                           virNetworkForwardTypeToString(def->forward.type));
            return -1;
        }
2775 2776
    }

G
Gene Czarcinski 已提交
2777 2778 2779
    /* We only support dhcp on one IPv4 address and
     * on one IPv6 address per defined network
     */
2780 2781 2782
    for (i = 0;
         (ipdef = virNetworkDefGetIpByIndex(def, AF_UNSPEC, i));
         i++) {
G
Gene Czarcinski 已提交
2783 2784 2785 2786 2787
        if (VIR_SOCKET_ADDR_IS_FAMILY(&ipdef->address, AF_INET)) {
            if (ipdef->nranges || ipdef->nhosts) {
                if (ipv4def) {
                    virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                               _("Multiple IPv4 dhcp sections found -- "
2788 2789
                                 "dhcp is supported only for a "
                                 "single IPv4 address on each network"));
G
Gene Czarcinski 已提交
2790 2791 2792 2793 2794 2795 2796 2797 2798 2799 2800 2801 2802 2803 2804 2805 2806
                    return -1;
                } else {
                    ipv4def = true;
                }
            }
        }
        if (VIR_SOCKET_ADDR_IS_FAMILY(&ipdef->address, AF_INET6)) {
            if (ipdef->nranges || ipdef->nhosts) {
                if (ipv6def) {
                    virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                               _("Multiple IPv6 dhcp sections found -- "
                                 "dhcp is supported only for a "
                                 "single IPv6 address on each network"));
                    return -1;
                } else {
                    ipv6def = true;
                }
2807 2808 2809
            }
        }
    }
2810 2811 2812 2813 2814 2815

    /* The only type of networks that currently support transparent
     * vlan configuration are those using hostdev sr-iov devices from
     * a pool, and those using an Open vSwitch bridge.
     */

2816
    vlanAllowed = ((def->forward.type == VIR_NETWORK_FORWARD_BRIDGE &&
J
Ján Tomko 已提交
2817 2818
                    def->virtPortProfile &&
                    def->virtPortProfile->virtPortType
2819 2820
                    == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH) ||
                   def->forward.type == VIR_NETWORK_FORWARD_HOSTDEV);
2821 2822

    vlanUsed = def->vlan.nTags > 0;
2823 2824
    for (i = 0; i < def->nPortGroups; i++) {
        if (vlanUsed || def->portGroups[i].vlan.nTags > 0) {
2825 2826 2827 2828 2829
            /* anyone using this portgroup will get a vlan tag. Verify
             * that they will also be using an openvswitch connection,
             * as that is the only type of network that currently
             * supports a vlan tag.
             */
2830
            if (def->portGroups[i].virtPortProfile) {
2831
                if (def->forward.type != VIR_NETWORK_FORWARD_BRIDGE ||
2832
                    def->portGroups[i].virtPortProfile->virtPortType
2833 2834 2835 2836 2837 2838 2839
                    != VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH) {
                    badVlanUse = true;
                }
            } else if (!vlanAllowed) {
                /* virtualport taken from base network definition */
                badVlanUse = true;
            }
2840
        }
2841
        if (def->portGroups[i].isDefault) {
2842 2843 2844 2845 2846
            if (defaultPortGroup) {
                virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                               _("network '%s' has multiple default "
                                 "<portgroup> elements (%s and %s), "
                                 "but only one default is allowed"),
2847
                               def->name, defaultPortGroup->name,
2848
                               def->portGroups[i].name);
2849
                return -1;
2850
            }
2851
            defaultPortGroup = &def->portGroups[i];
2852
        }
2853
    }
2854 2855 2856 2857 2858 2859 2860
    if (badVlanUse ||
        (vlanUsed && !vlanAllowed && !defaultPortGroup)) {
        /* NB: if defaultPortGroup is set, we don't directly look at
         * vlanUsed && !vlanAllowed, because the network will never be
         * used without having a portgroup added in, so all necessary
         * checks were done in the loop above.
         */
2861 2862 2863 2864 2865 2866 2867 2868 2869
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("<vlan> element specified for network %s, "
                         "whose type doesn't support vlan configuration"),
                       def->name);
        return -1;
    }
    return 0;
}

2870 2871
static virNetworkPtr networkCreateXML(virConnectPtr conn, const char *xml)
{
2872
    virNetworkDefPtr def;
2873
    virNetworkObjPtr network = NULL;
2874
    virNetworkPtr ret = NULL;
2875
    virObjectEventPtr event = NULL;
2876

2877
    networkDriverLock();
2878

2879
    if (!(def = virNetworkDefParseString(xml)))
2880
        goto cleanup;
2881

2882 2883 2884
    if (virNetworkCreateXMLEnsureACL(conn, def) < 0)
        goto cleanup;

2885
    if (networkValidate(def, true) < 0)
J
Ján Tomko 已提交
2886
        goto cleanup;
2887

2888 2889 2890
    /* NB: even though this transient network hasn't yet been started,
     * we assign the def with live = true in anticipation that it will
     * be started momentarily.
2891
     */
2892
    if (!(network = virNetworkAssignDef(&driver->networks, def, true)))
2893 2894
        goto cleanup;
    def = NULL;
2895

2896
    if (networkStartNetwork(network) < 0) {
2897 2898
        virNetworkRemoveInactive(&driver->networks,
                                 network);
2899
        network = NULL;
2900
        goto cleanup;
2901 2902
    }

2903 2904
    event = virNetworkEventLifecycleNew(network->def->name,
                                        network->def->uuid,
2905 2906
                                        VIR_NETWORK_EVENT_STARTED,
                                        0);
2907

2908
    VIR_INFO("Creating network '%s'", network->def->name);
2909 2910
    ret = virGetNetwork(conn, network->def->name, network->def->uuid);

2911
 cleanup:
2912
    virNetworkDefFree(def);
2913 2914
    if (event)
        virObjectEventStateQueue(driver->networkEventState, event);
2915 2916
    if (network)
        virNetworkObjUnlock(network);
2917
    networkDriverUnlock();
2918
    return ret;
2919 2920
}

2921 2922
static virNetworkPtr networkDefineXML(virConnectPtr conn, const char *xml)
{
2923
    virNetworkDefPtr def = NULL;
2924
    bool freeDef = true;
2925
    virNetworkObjPtr network = NULL;
2926
    virNetworkPtr ret = NULL;
2927
    virObjectEventPtr event = NULL;
2928

2929
    networkDriverLock();
2930

2931
    if (!(def = virNetworkDefParseString(xml)))
2932
        goto cleanup;
2933

2934 2935 2936
    if (virNetworkDefineXMLEnsureACL(conn, def) < 0)
        goto cleanup;

2937
    if (networkValidate(def, false) < 0)
J
Ján Tomko 已提交
2938
        goto cleanup;
2939

2940
    if (!(network = virNetworkAssignDef(&driver->networks, def, false)))
J
Ján Tomko 已提交
2941
        goto cleanup;
2942

2943
    /* def was assigned to network object */
2944
    freeDef = false;
2945 2946

    if (virNetworkSaveConfig(driver->networkConfigDir, def) < 0) {
2947 2948 2949 2950 2951
        if (!virNetworkObjIsActive(network)) {
            virNetworkRemoveInactive(&driver->networks, network);
            network = NULL;
            goto cleanup;
        }
2952 2953 2954 2955 2956
        /* if network was active already, just undo new persistent
         * definition by making it transient.
         * XXX - this isn't necessarily the correct thing to do.
         */
        virNetworkObjAssignDef(network, NULL, false);
2957 2958 2959
        goto cleanup;
    }

2960
    event = virNetworkEventLifecycleNew(def->name, def->uuid,
2961 2962
                                        VIR_NETWORK_EVENT_DEFINED,
                                        0);
2963

2964 2965
    VIR_INFO("Defining network '%s'", def->name);
    ret = virGetNetwork(conn, def->name, def->uuid);
2966

2967
 cleanup:
2968 2969
    if (event)
        virObjectEventStateQueue(driver->networkEventState, event);
2970
    if (freeDef)
J
Ján Tomko 已提交
2971
        virNetworkDefFree(def);
2972 2973
    if (network)
        virNetworkObjUnlock(network);
2974
    networkDriverUnlock();
2975
    return ret;
2976 2977
}

2978
static int
2979 2980
networkUndefine(virNetworkPtr net)
{
2981
    virNetworkObjPtr network;
2982
    int ret = -1;
2983
    bool active = false;
2984
    virObjectEventPtr event = NULL;
2985

2986
    networkDriverLock();
2987

2988
    network = virNetworkFindByUUID(&driver->networks, net->uuid);
2989
    if (!network) {
2990 2991
        virReportError(VIR_ERR_NO_NETWORK,
                       "%s", _("no network with matching uuid"));
2992
        goto cleanup;
2993 2994
    }

2995 2996 2997
    if (virNetworkUndefineEnsureACL(net->conn, network->def) < 0)
        goto cleanup;

2998 2999
    if (virNetworkObjIsActive(network))
        active = true;
3000

3001
    /* remove autostart link */
3002
    if (virNetworkDeleteConfig(driver->networkConfigDir,
3003 3004
                               driver->networkAutostartDir,
                               network) < 0)
3005
        goto cleanup;
3006
    network->autostart = 0;
3007

3008 3009
    event = virNetworkEventLifecycleNew(network->def->name,
                                        network->def->uuid,
3010 3011
                                        VIR_NETWORK_EVENT_UNDEFINED,
                                        0);
3012

3013
    VIR_INFO("Undefining network '%s'", network->def->name);
3014
    if (!active) {
3015
        if (networkRemoveInactive(network) < 0) {
3016 3017 3018
            network = NULL;
            goto cleanup;
        }
3019
        network = NULL;
3020 3021 3022 3023 3024 3025
    } else {

        /* if the network still exists, it was active, and we need to make
         * it transient (by deleting the persistent def)
         */
        virNetworkObjAssignDef(network, NULL, false);
3026 3027
    }

3028
    ret = 0;
3029

3030
 cleanup:
3031 3032
    if (event)
        virObjectEventStateQueue(driver->networkEventState, event);
3033 3034
    if (network)
        virNetworkObjUnlock(network);
3035
    networkDriverUnlock();
3036
    return ret;
3037 3038
}

3039 3040 3041 3042 3043 3044 3045 3046 3047
static int
networkUpdate(virNetworkPtr net,
              unsigned int command,
              unsigned int section,
              int parentIndex,
              const char *xml,
              unsigned int flags)
{
    virNetworkObjPtr network = NULL;
3048 3049
    int isActive, ret = -1;
    size_t i;
3050 3051
    virNetworkIpDefPtr ipdef;
    bool oldDhcpActive = false;
3052
    bool needFirewallRefresh = false;
3053

3054 3055 3056 3057 3058

    virCheckFlags(VIR_NETWORK_UPDATE_AFFECT_LIVE |
                  VIR_NETWORK_UPDATE_AFFECT_CONFIG,
                  -1);

3059
    networkDriverLock();
3060 3061 3062 3063 3064 3065 3066 3067

    network = virNetworkFindByUUID(&driver->networks, net->uuid);
    if (!network) {
        virReportError(VIR_ERR_NO_NETWORK,
                       "%s", _("no network with matching uuid"));
        goto cleanup;
    }

3068 3069 3070
    if (virNetworkUpdateEnsureACL(net->conn, network->def, flags) < 0)
        goto cleanup;

3071
    /* see if we are listening for dhcp pre-modification */
3072 3073 3074
    for (i = 0;
         (ipdef = virNetworkDefGetIpByIndex(network->def, AF_INET, i));
         i++) {
3075 3076 3077 3078 3079 3080
        if (ipdef->nranges || ipdef->nhosts) {
            oldDhcpActive = true;
            break;
        }
    }

3081 3082
    /* VIR_NETWORK_UPDATE_AFFECT_CURRENT means "change LIVE if network
     * is active, else change CONFIG
J
Ján Tomko 已提交
3083
     */
3084
    isActive = virNetworkObjIsActive(network);
3085 3086
    if ((flags & (VIR_NETWORK_UPDATE_AFFECT_LIVE |
                  VIR_NETWORK_UPDATE_AFFECT_CONFIG)) ==
3087 3088 3089 3090 3091 3092 3093
        VIR_NETWORK_UPDATE_AFFECT_CURRENT) {
        if (isActive)
            flags |= VIR_NETWORK_UPDATE_AFFECT_LIVE;
        else
            flags |= VIR_NETWORK_UPDATE_AFFECT_CONFIG;
    }

3094 3095 3096 3097 3098 3099 3100 3101 3102 3103 3104 3105 3106 3107 3108 3109 3110
    if (isActive && (flags & VIR_NETWORK_UPDATE_AFFECT_LIVE)) {
        /* Take care of anything that must be done before updating the
         * live NetworkDef.
         */
        if (network->def->forward.type == VIR_NETWORK_FORWARD_NONE ||
            network->def->forward.type == VIR_NETWORK_FORWARD_NAT ||
            network->def->forward.type == VIR_NETWORK_FORWARD_ROUTE) {
            switch (section) {
            case VIR_NETWORK_SECTION_FORWARD:
            case VIR_NETWORK_SECTION_FORWARD_INTERFACE:
            case VIR_NETWORK_SECTION_IP:
            case VIR_NETWORK_SECTION_IP_DHCP_RANGE:
            case VIR_NETWORK_SECTION_IP_DHCP_HOST:
                /* these could affect the firewall rules, so remove the
                 * old rules (and remember to load new ones after the
                 * update).
                 */
3111
                networkRemoveFirewallRules(network->def);
3112 3113 3114 3115 3116 3117 3118 3119
                needFirewallRefresh = true;
                break;
            default:
                break;
            }
        }
    }

3120
    /* update the network config in memory/on disk */
3121 3122
    if (virNetworkObjUpdate(network, command, section, parentIndex, xml, flags) < 0) {
        if (needFirewallRefresh)
3123
            ignore_value(networkAddFirewallRules(network->def));
3124 3125 3126
        goto cleanup;
    }

3127
    if (needFirewallRefresh && networkAddFirewallRules(network->def) < 0)
3128 3129 3130 3131 3132 3133 3134 3135 3136 3137 3138 3139 3140 3141 3142 3143 3144 3145 3146 3147 3148 3149 3150
        goto cleanup;

    if (flags & VIR_NETWORK_UPDATE_AFFECT_CONFIG) {
        /* save updated persistent config to disk */
        if (virNetworkSaveConfig(driver->networkConfigDir,
                                 virNetworkObjGetPersistentDef(network)) < 0) {
            goto cleanup;
        }
    }

    if (isActive && (flags & VIR_NETWORK_UPDATE_AFFECT_LIVE)) {
        /* rewrite dnsmasq host files, restart dnsmasq, update iptables
         * rules, etc, according to which section was modified. Note that
         * some sections require multiple actions, so a single switch
         * statement is inadequate.
         */
        if (section == VIR_NETWORK_SECTION_BRIDGE ||
            section == VIR_NETWORK_SECTION_DOMAIN ||
            section == VIR_NETWORK_SECTION_IP ||
            section == VIR_NETWORK_SECTION_IP_DHCP_RANGE) {
            /* these sections all change things on the dnsmasq commandline,
             * so we need to kill and restart dnsmasq.
             */
3151
            if (networkRestartDhcpDaemon(network) < 0)
3152 3153
                goto cleanup;

3154 3155 3156 3157 3158 3159 3160 3161
        } else if (section == VIR_NETWORK_SECTION_IP_DHCP_HOST) {
            /* if we previously weren't listening for dhcp and now we
             * are (or vice-versa) then we need to do a restart,
             * otherwise we just need to do a refresh (redo the config
             * files and send SIGHUP)
             */
            bool newDhcpActive = false;

3162 3163 3164
            for (i = 0;
                 (ipdef = virNetworkDefGetIpByIndex(network->def, AF_INET, i));
                 i++) {
3165 3166 3167 3168 3169 3170 3171
                if (ipdef->nranges || ipdef->nhosts) {
                    newDhcpActive = true;
                    break;
                }
            }

            if ((newDhcpActive != oldDhcpActive &&
3172 3173
                 networkRestartDhcpDaemon(network) < 0) ||
                networkRefreshDhcpDaemon(network) < 0) {
3174 3175 3176 3177
                goto cleanup;
            }

        } else if (section == VIR_NETWORK_SECTION_DNS_HOST ||
3178 3179 3180 3181 3182 3183
                   section == VIR_NETWORK_SECTION_DNS_TXT ||
                   section == VIR_NETWORK_SECTION_DNS_SRV) {
            /* these sections only change things in config files, so we
             * can just update the config files and send SIGHUP to
             * dnsmasq.
             */
3184
            if (networkRefreshDhcpDaemon(network) < 0)
3185 3186 3187 3188 3189 3190 3191 3192
                goto cleanup;

        }

        if (section == VIR_NETWORK_SECTION_IP) {
            /* only a change in IP addresses will affect radvd, and all of radvd's
             * config is stored in the conf file which will be re-read with a SIGHUP.
             */
3193
            if (networkRefreshRadvd(network) < 0)
3194 3195 3196 3197
                goto cleanup;
        }

        /* save current network state to disk */
3198
        if ((ret = virNetworkSaveStatus(driver->stateDir,
3199
                                        network)) < 0) {
3200
            goto cleanup;
3201
        }
3202 3203
    }
    ret = 0;
3204
 cleanup:
3205 3206
    if (network)
        virNetworkObjUnlock(network);
3207
    networkDriverUnlock();
3208 3209 3210
    return ret;
}

3211 3212
static int networkCreate(virNetworkPtr net)
{
3213 3214
    virNetworkObjPtr network;
    int ret = -1;
3215
    virObjectEventPtr event = NULL;
3216

3217
    networkDriverLock();
3218
    network = virNetworkFindByUUID(&driver->networks, net->uuid);
3219

3220
    if (!network) {
3221 3222
        virReportError(VIR_ERR_NO_NETWORK,
                       "%s", _("no network with matching uuid"));
3223
        goto cleanup;
3224 3225
    }

3226 3227 3228
    if (virNetworkCreateEnsureACL(net->conn, network->def) < 0)
        goto cleanup;

3229
    if ((ret = networkStartNetwork(network)) < 0)
3230
        goto cleanup;
3231

3232 3233
    event = virNetworkEventLifecycleNew(network->def->name,
                                        network->def->uuid,
3234 3235
                                        VIR_NETWORK_EVENT_STARTED,
                                        0);
3236

3237
 cleanup:
3238 3239
    if (event)
        virObjectEventStateQueue(driver->networkEventState, event);
3240 3241
    if (network)
        virNetworkObjUnlock(network);
3242
    networkDriverUnlock();
3243
    return ret;
3244 3245
}

3246 3247
static int networkDestroy(virNetworkPtr net)
{
3248 3249
    virNetworkObjPtr network;
    int ret = -1;
3250
    virObjectEventPtr event = NULL;
3251

3252
    networkDriverLock();
3253
    network = virNetworkFindByUUID(&driver->networks, net->uuid);
3254

3255
    if (!network) {
3256 3257
        virReportError(VIR_ERR_NO_NETWORK,
                       "%s", _("no network with matching uuid"));
3258
        goto cleanup;
3259 3260
    }

3261 3262 3263
    if (virNetworkDestroyEnsureACL(net->conn, network->def) < 0)
        goto cleanup;

D
Daniel P. Berrange 已提交
3264
    if (!virNetworkObjIsActive(network)) {
3265
        virReportError(VIR_ERR_OPERATION_INVALID,
3266 3267
                       _("network '%s' is not active"),
                       network->def->name);
3268 3269 3270
        goto cleanup;
    }

3271
    if ((ret = networkShutdownNetwork(network)) < 0)
3272 3273
        goto cleanup;

3274 3275
    event = virNetworkEventLifecycleNew(network->def->name,
                                        network->def->uuid,
3276 3277
                                        VIR_NETWORK_EVENT_STOPPED,
                                        0);
3278

3279
    if (!network->persistent) {
3280
        if (networkRemoveInactive(network) < 0) {
3281 3282 3283 3284
            network = NULL;
            ret = -1;
            goto cleanup;
        }
3285 3286
        network = NULL;
    }
3287

3288
 cleanup:
3289 3290
    if (event)
        virObjectEventStateQueue(driver->networkEventState, event);
3291 3292
    if (network)
        virNetworkObjUnlock(network);
3293
    networkDriverUnlock();
3294 3295 3296
    return ret;
}

3297
static char *networkGetXMLDesc(virNetworkPtr net,
3298
                               unsigned int flags)
3299
{
3300
    virNetworkObjPtr network;
3301
    virNetworkDefPtr def;
3302
    char *ret = NULL;
3303

3304
    virCheckFlags(VIR_NETWORK_XML_INACTIVE, NULL);
3305

3306 3307
    if (!(network = networkObjFromNetwork(net)))
        return ret;
3308

3309 3310 3311
    if (virNetworkGetXMLDescEnsureACL(net->conn, network->def) < 0)
        goto cleanup;

3312 3313 3314 3315 3316 3317
    if ((flags & VIR_NETWORK_XML_INACTIVE) && network->newDef)
        def = network->newDef;
    else
        def = network->def;

    ret = virNetworkDefFormat(def, flags);
3318

3319
 cleanup:
3320 3321
    if (network)
        virNetworkObjUnlock(network);
3322
    return ret;
3323 3324 3325
}

static char *networkGetBridgeName(virNetworkPtr net) {
3326 3327 3328
    virNetworkObjPtr network;
    char *bridge = NULL;

3329 3330
    if (!(network = networkObjFromNetwork(net)))
        return bridge;
3331

3332 3333 3334
    if (virNetworkGetBridgeNameEnsureACL(net->conn, network->def) < 0)
        goto cleanup;

3335
    if (!(network->def->bridge)) {
3336 3337 3338
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("network '%s' does not have a bridge name."),
                       network->def->name);
3339 3340 3341
        goto cleanup;
    }

3342
    ignore_value(VIR_STRDUP(bridge, network->def->bridge));
3343

3344
 cleanup:
3345 3346
    if (network)
        virNetworkObjUnlock(network);
3347 3348 3349 3350
    return bridge;
}

static int networkGetAutostart(virNetworkPtr net,
J
Ján Tomko 已提交
3351
                               int *autostart)
3352
{
3353 3354
    virNetworkObjPtr network;
    int ret = -1;
3355

3356 3357
    if (!(network = networkObjFromNetwork(net)))
        return ret;
3358

3359 3360 3361
    if (virNetworkGetAutostartEnsureACL(net->conn, network->def) < 0)
        goto cleanup;

3362
    *autostart = network->autostart;
3363
    ret = 0;
3364

3365
 cleanup:
3366 3367
    if (network)
        virNetworkObjUnlock(network);
3368
    return ret;
3369 3370 3371
}

static int networkSetAutostart(virNetworkPtr net,
3372 3373
                               int autostart)
{
3374
    virNetworkObjPtr network;
3375
    char *configFile = NULL, *autostartLink = NULL;
3376
    int ret = -1;
3377

3378
    networkDriverLock();
3379
    network = virNetworkFindByUUID(&driver->networks, net->uuid);
3380

3381
    if (!network) {
3382 3383
        virReportError(VIR_ERR_NO_NETWORK,
                       "%s", _("no network with matching uuid"));
3384
        goto cleanup;
3385 3386
    }

3387 3388 3389
    if (virNetworkSetAutostartEnsureACL(net->conn, network->def) < 0)
        goto cleanup;

3390
    if (!network->persistent) {
3391 3392
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cannot set autostart for transient network"));
3393 3394 3395
        goto cleanup;
    }

3396 3397
    autostart = (autostart != 0);

3398
    if (network->autostart != autostart) {
3399
        if ((configFile = virNetworkConfigFile(driver->networkConfigDir, network->def->name)) == NULL)
3400
            goto cleanup;
3401
        if ((autostartLink = virNetworkConfigFile(driver->networkAutostartDir, network->def->name)) == NULL)
3402 3403
            goto cleanup;

3404
        if (autostart) {
3405
            if (virFileMakePath(driver->networkAutostartDir) < 0) {
3406
                virReportSystemError(errno,
3407 3408
                                     _("cannot create autostart directory '%s'"),
                                     driver->networkAutostartDir);
3409 3410
                goto cleanup;
            }
3411

3412
            if (symlink(configFile, autostartLink) < 0) {
3413
                virReportSystemError(errno,
3414
                                     _("Failed to create symlink '%s' to '%s'"),
3415
                                     autostartLink, configFile);
3416 3417 3418
                goto cleanup;
            }
        } else {
3419
            if (unlink(autostartLink) < 0 && errno != ENOENT && errno != ENOTDIR) {
3420
                virReportSystemError(errno,
3421
                                     _("Failed to delete symlink '%s'"),
3422
                                     autostartLink);
3423 3424
                goto cleanup;
            }
3425 3426
        }

3427
        network->autostart = autostart;
3428
    }
3429
    ret = 0;
3430

3431
 cleanup:
3432 3433
    VIR_FREE(configFile);
    VIR_FREE(autostartLink);
3434 3435
    if (network)
        virNetworkObjUnlock(network);
3436
    networkDriverUnlock();
3437
    return ret;
3438 3439
}

3440
static int
3441 3442 3443 3444
networkGetDHCPLeases(virNetworkPtr network,
                     const char *mac,
                     virNetworkDHCPLeasePtr **leases,
                     unsigned int flags)
3445 3446 3447 3448 3449 3450 3451 3452 3453 3454 3455 3456 3457 3458 3459 3460 3461 3462 3463
{
    size_t i, j;
    size_t nleases = 0;
    int rv = -1;
    int size = 0;
    int custom_lease_file_len = 0;
    bool need_results = !!leases;
    long long currtime = 0;
    long long expirytime_tmp = -1;
    bool ipv6 = false;
    char *lease_entries = NULL;
    char *custom_lease_file = NULL;
    const char *ip_tmp = NULL;
    const char *mac_tmp = NULL;
    virJSONValuePtr lease_tmp = NULL;
    virJSONValuePtr leases_array = NULL;
    virNetworkIpDefPtr ipdef_tmp = NULL;
    virNetworkDHCPLeasePtr lease = NULL;
    virNetworkDHCPLeasePtr *leases_ret = NULL;
3464 3465 3466 3467 3468 3469 3470 3471 3472
    virNetworkObjPtr obj;

    virCheckFlags(0, -1);

    if (!(obj = networkObjFromNetwork(network)))
        return -1;

    if (virNetworkGetDHCPLeasesEnsureACL(network->conn, obj->def) < 0)
        goto cleanup;
3473 3474 3475 3476 3477 3478 3479 3480 3481 3482 3483 3484 3485 3486 3487 3488 3489 3490 3491 3492 3493 3494 3495 3496 3497 3498 3499 3500 3501 3502 3503 3504 3505 3506 3507 3508 3509 3510 3511 3512 3513 3514 3515 3516 3517 3518

    /* Retrieve custom leases file location */
    custom_lease_file = networkDnsmasqLeaseFileNameCustom(obj->def->bridge);

    /* Read entire contents */
    if ((custom_lease_file_len = virFileReadAll(custom_lease_file,
                                                VIR_NETWORK_DHCP_LEASE_FILE_SIZE_MAX,
                                                &lease_entries)) < 0) {
        /* Even though src/network/leaseshelper.c guarantees the existence of
         * leases file (even if no leases are present), and the control reaches
         * here, instead of reporting error, return 0 leases */
        rv = 0;
        goto error;
    }

    if (custom_lease_file_len) {
        if (!(leases_array = virJSONValueFromString(lease_entries))) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("invalid json in file: %s"), custom_lease_file);
            goto error;
        }

        if ((size = virJSONValueArraySize(leases_array)) < 0) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("couldn't fetch array of leases"));
            goto error;
        }
    }

    currtime = (long long) time(NULL);

    for (i = 0; i < size; i++) {
        if (!(lease_tmp = virJSONValueArrayGet(leases_array, i))) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("failed to parse json"));
            goto error;
        }

        if (!(mac_tmp = virJSONValueObjectGetString(lease_tmp, "mac-address"))) {
            /* leaseshelper program guarantees that lease will be stored only if
             * mac-address is known otherwise not */
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("found lease without mac-address"));
            goto error;
        }

3519
        if (mac && virMacAddrCompare(mac, mac_tmp))
3520 3521 3522 3523 3524 3525 3526 3527 3528 3529 3530 3531 3532 3533 3534 3535 3536 3537 3538 3539 3540 3541 3542 3543 3544 3545 3546 3547 3548 3549 3550 3551 3552 3553 3554 3555 3556 3557 3558 3559 3560 3561 3562 3563 3564 3565 3566 3567 3568 3569
            continue;

        if (virJSONValueObjectGetNumberLong(lease_tmp, "expiry-time", &expirytime_tmp) < 0) {
            /* A lease cannot be present without expiry-time */
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("found lease without expiry-time"));
            goto error;
        }

        /* Do not report expired lease */
        if (expirytime_tmp < currtime)
            continue;

        if (need_results) {
            if (VIR_ALLOC(lease) < 0)
                goto error;

            lease->expirytime = expirytime_tmp;

            if (!(ip_tmp = virJSONValueObjectGetString(lease_tmp, "ip-address"))) {
                /* A lease without ip-address makes no sense */
                virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                               _("found lease without ip-address"));
                goto error;
            }

            /* Unlike IPv4, IPv6 uses ':' instead of '.' as separator */
            ipv6 = strchr(ip_tmp, ':') ? true : false;
            lease->type = ipv6 ? VIR_IP_ADDR_TYPE_IPV6 : VIR_IP_ADDR_TYPE_IPV4;

            /* Obtain prefix */
            for (j = 0; j < obj->def->nips; j++) {
                ipdef_tmp = &obj->def->ips[j];

                if (ipv6 && VIR_SOCKET_ADDR_IS_FAMILY(&ipdef_tmp->address,
                                                      AF_INET6)) {
                    lease->prefix = ipdef_tmp->prefix;
                    break;
                }
                if (!ipv6 && VIR_SOCKET_ADDR_IS_FAMILY(&ipdef_tmp->address,
                                                      AF_INET)) {
                    lease->prefix = virSocketAddrGetIpPrefix(&ipdef_tmp->address,
                                                             &ipdef_tmp->netmask,
                                                             ipdef_tmp->prefix);
                    break;
                }
            }

            if ((VIR_STRDUP(lease->mac, mac_tmp) < 0) ||
                (VIR_STRDUP(lease->ipaddr, ip_tmp) < 0) ||
3570
                (VIR_STRDUP(lease->iface, obj->def->bridge) < 0))
3571 3572 3573 3574 3575 3576 3577 3578 3579 3580 3581 3582 3583 3584 3585 3586 3587 3588 3589 3590 3591 3592 3593 3594 3595 3596 3597 3598 3599 3600 3601 3602 3603 3604 3605 3606 3607 3608
                goto error;

            /* Fields that can be NULL */
            if ((VIR_STRDUP(lease->iaid,
                            virJSONValueObjectGetString(lease_tmp, "iaid")) < 0) ||
                (VIR_STRDUP(lease->clientid,
                            virJSONValueObjectGetString(lease_tmp, "client-id")) < 0) ||
                (VIR_STRDUP(lease->hostname,
                            virJSONValueObjectGetString(lease_tmp, "hostname")) < 0))
                goto error;

            if (VIR_INSERT_ELEMENT(leases_ret, nleases, nleases, lease) < 0)
                goto error;

        } else {
            nleases++;
        }

        VIR_FREE(lease);
    }

    if (need_results && mac && !leases_ret) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("no lease with matching MAC address: %s"), mac);
        goto error;
    }

    if (leases_ret) {
        /* NULL terminated array */
        ignore_value(VIR_REALLOC_N(leases_ret, nleases + 1));
        *leases = leases_ret;
        leases_ret = NULL;
    }

    rv = nleases;

 cleanup:
    VIR_FREE(lease);
3609
    VIR_FREE(lease_entries);
3610 3611
    VIR_FREE(custom_lease_file);
    virJSONValueFree(leases_array);
3612 3613 3614 3615

    if (obj)
        virNetworkObjUnlock(obj);

3616 3617 3618 3619 3620 3621 3622 3623 3624 3625 3626
    return rv;

 error:
    if (leases_ret) {
        for (i = 0; i < nleases; i++)
            virNetworkDHCPLeaseFree(leases_ret[i]);
        VIR_FREE(leases_ret);
    }
    goto cleanup;
}

3627 3628 3629

static virNetworkDriver networkDriver = {
    "Network",
3630 3631 3632 3633 3634 3635 3636
    .networkOpen = networkOpen, /* 0.2.0 */
    .networkClose = networkClose, /* 0.2.0 */
    .connectNumOfNetworks = networkConnectNumOfNetworks, /* 0.2.0 */
    .connectListNetworks = networkConnectListNetworks, /* 0.2.0 */
    .connectNumOfDefinedNetworks = networkConnectNumOfDefinedNetworks, /* 0.2.0 */
    .connectListDefinedNetworks = networkConnectListDefinedNetworks, /* 0.2.0 */
    .connectListAllNetworks = networkConnectListAllNetworks, /* 0.10.2 */
3637 3638
    .connectNetworkEventRegisterAny = networkConnectNetworkEventRegisterAny, /* 1.2.1 */
    .connectNetworkEventDeregisterAny = networkConnectNetworkEventDeregisterAny, /* 1.2.1 */
3639 3640
    .networkLookupByUUID = networkLookupByUUID, /* 0.2.0 */
    .networkLookupByName = networkLookupByName, /* 0.2.0 */
3641 3642
    .networkCreateXML = networkCreateXML, /* 0.2.0 */
    .networkDefineXML = networkDefineXML, /* 0.2.0 */
3643
    .networkUndefine = networkUndefine, /* 0.2.0 */
3644
    .networkUpdate = networkUpdate, /* 0.10.2 */
3645
    .networkCreate = networkCreate, /* 0.2.0 */
3646 3647 3648 3649 3650 3651 3652
    .networkDestroy = networkDestroy, /* 0.2.0 */
    .networkGetXMLDesc = networkGetXMLDesc, /* 0.2.0 */
    .networkGetBridgeName = networkGetBridgeName, /* 0.2.0 */
    .networkGetAutostart = networkGetAutostart, /* 0.2.1 */
    .networkSetAutostart = networkSetAutostart, /* 0.2.1 */
    .networkIsActive = networkIsActive, /* 0.7.3 */
    .networkIsPersistent = networkIsPersistent, /* 0.7.3 */
3653
    .networkGetDHCPLeases = networkGetDHCPLeases, /* 1.2.6 */
3654 3655 3656
};

static virStateDriver networkStateDriver = {
3657
    .name = "Network",
3658
    .stateInitialize  = networkStateInitialize,
3659
    .stateAutoStart  = networkStateAutoStart,
3660 3661
    .stateCleanup = networkStateCleanup,
    .stateReload = networkStateReload,
3662 3663
};

3664 3665
int networkRegister(void)
{
3666 3667
    if (virRegisterNetworkDriver(&networkDriver) < 0)
        return -1;
3668 3669
    if (virRegisterStateDriver(&networkStateDriver) < 0)
        return -1;
3670 3671
    return 0;
}
3672 3673 3674 3675 3676 3677 3678 3679 3680 3681 3682 3683

/********************************************************/

/* Private API to deal with logical switch capabilities.
 * These functions are exported so that other parts of libvirt can
 * call them, but are not part of the public API and not in the
 * driver's function table. If we ever have more than one network
 * driver, we will need to present these functions via a second
 * "backend" function table.
 */

/* networkAllocateActualDevice:
3684
 * @dom: domain definition that @iface belongs to
3685 3686 3687 3688 3689 3690 3691 3692 3693 3694 3695
 * @iface: the original NetDef from the domain
 *
 * Looks up the network reference by iface, allocates a physical
 * device from that network (if appropriate), and returns with the
 * virDomainActualNetDef filled in accordingly. If there are no
 * changes to be made in the netdef, then just leave the actualdef
 * empty.
 *
 * Returns 0 on success, -1 on failure.
 */
int
3696 3697
networkAllocateActualDevice(virDomainDefPtr dom,
                            virDomainNetDefPtr iface)
3698
{
3699
    virDomainNetType actualType = iface->type;
3700 3701
    virNetworkObjPtr network = NULL;
    virNetworkDefPtr netdef = NULL;
3702
    virNetDevBandwidthPtr bandwidth = NULL;
3703 3704 3705
    virPortGroupDefPtr portgroup = NULL;
    virNetDevVPortProfilePtr virtport = iface->virtPortProfile;
    virNetDevVlanPtr vlan = NULL;
3706
    virNetworkForwardIfDefPtr dev = NULL;
3707
    size_t i;
3708 3709 3710
    int ret = -1;

    if (iface->type != VIR_DOMAIN_NET_TYPE_NETWORK)
3711
        goto validate;
3712 3713 3714 3715

    virDomainActualNetDefFree(iface->data.network.actual);
    iface->data.network.actual = NULL;

3716
    networkDriverLock();
3717
    network = virNetworkFindByName(&driver->networks, iface->data.network.name);
3718
    networkDriverUnlock();
3719
    if (!network) {
3720 3721 3722
        virReportError(VIR_ERR_NO_NETWORK,
                       _("no network with matching name '%s'"),
                       iface->data.network.name);
3723
        goto error;
3724 3725
    }
    netdef = network->def;
3726

3727 3728 3729 3730 3731 3732 3733
    if (!virNetworkObjIsActive(network)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       _("network '%s' is not active"),
                       netdef->name);
        goto error;
    }

3734 3735 3736
    if (VIR_ALLOC(iface->data.network.actual) < 0)
        goto error;

3737 3738 3739
    /* portgroup can be present for any type of network, in particular
     * for bandwidth information, so we need to check for that and
     * fill it in appropriately for all forward types.
J
Ján Tomko 已提交
3740
     */
3741 3742 3743 3744 3745 3746
    portgroup = virPortGroupFindByName(netdef, iface->data.network.portgroup);

    /* If there is already interface-specific bandwidth, just use that
     * (already in NetDef). Otherwise, if there is bandwidth info in
     * the portgroup, fill that into the ActualDef.
     */
3747 3748 3749 3750 3751 3752

    if (iface->bandwidth)
        bandwidth = iface->bandwidth;
    else if (portgroup && portgroup->bandwidth)
        bandwidth = portgroup->bandwidth;

3753 3754
    if (bandwidth && virNetDevBandwidthCopy(&iface->data.network.actual->bandwidth,
                                            bandwidth) < 0)
3755
        goto error;
3756

3757 3758 3759 3760 3761 3762 3763 3764
    /* copy appropriate vlan info to actualNet */
    if (iface->vlan.nTags > 0)
        vlan = &iface->vlan;
    else if (portgroup && portgroup->vlan.nTags > 0)
        vlan = &portgroup->vlan;
    else if (netdef->vlan.nTags > 0)
        vlan = &netdef->vlan;

3765 3766
    if (vlan && virNetDevVlanCopy(&iface->data.network.actual->vlan, vlan) < 0)
        goto error;
3767

3768 3769 3770 3771 3772 3773 3774 3775 3776 3777
    if (iface->trustGuestRxFilters)
       iface->data.network.actual->trustGuestRxFilters
          = iface->trustGuestRxFilters;
    else if (portgroup && portgroup->trustGuestRxFilters)
       iface->data.network.actual->trustGuestRxFilters
          = portgroup->trustGuestRxFilters;
    else if (netdef->trustGuestRxFilters)
       iface->data.network.actual->trustGuestRxFilters
          = netdef->trustGuestRxFilters;

3778 3779 3780
    if ((netdef->forward.type == VIR_NETWORK_FORWARD_NONE) ||
        (netdef->forward.type == VIR_NETWORK_FORWARD_NAT) ||
        (netdef->forward.type == VIR_NETWORK_FORWARD_ROUTE)) {
3781 3782 3783
        /* for these forward types, the actual net type really *is*
         *NETWORK; we just keep the info from the portgroup in
         * iface->data.network.actual
J
Ján Tomko 已提交
3784
         */
3785
        iface->data.network.actual->type = VIR_DOMAIN_NET_TYPE_NETWORK;
3786 3787 3788 3789

        if (networkPlugBandwidth(network, iface) < 0)
            goto error;

3790
    } else if ((netdef->forward.type == VIR_NETWORK_FORWARD_BRIDGE) &&
3791
               netdef->bridge) {
3792 3793 3794 3795 3796

        /* <forward type='bridge'/> <bridge name='xxx'/>
         * is VIR_DOMAIN_NET_TYPE_BRIDGE
         */

3797
        iface->data.network.actual->type = actualType = VIR_DOMAIN_NET_TYPE_BRIDGE;
3798 3799
        if (VIR_STRDUP(iface->data.network.actual->data.bridge.brname,
                       netdef->bridge) < 0)
3800
            goto error;
3801

3802 3803 3804 3805 3806 3807 3808 3809
        /* merge virtualports from interface, network, and portgroup to
         * arrive at actual virtualport to use
         */
        if (virNetDevVPortProfileMerge3(&iface->data.network.actual->virtPortProfile,
                                        iface->virtPortProfile,
                                        netdef->virtPortProfile,
                                        portgroup
                                        ? portgroup->virtPortProfile : NULL) < 0) {
3810
            goto error;
3811 3812 3813 3814 3815 3816 3817 3818 3819 3820
        }
        virtport = iface->data.network.actual->virtPortProfile;
        if (virtport) {
            /* only type='openvswitch' is allowed for bridges */
            if (virtport->virtPortType != VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH) {
                virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                               _("<virtualport type='%s'> not supported for network "
                                 "'%s' which uses a bridge device"),
                               virNetDevVPortTypeToString(virtport->virtPortType),
                               netdef->name);
3821
                goto error;
3822 3823 3824
            }
        }

3825
    } else if (netdef->forward.type == VIR_NETWORK_FORWARD_HOSTDEV) {
3826

3827
        virDomainHostdevSubsysPCIBackendType backend;
3828

3829
        iface->data.network.actual->type = actualType = VIR_DOMAIN_NET_TYPE_HOSTDEV;
3830
        if (networkCreateInterfacePool(netdef) < 0)
3831 3832 3833
            goto error;

        /* pick first dev with 0 connections */
3834 3835 3836
        for (i = 0; i < netdef->forward.nifs; i++) {
            if (netdef->forward.ifs[i].connections == 0) {
                dev = &netdef->forward.ifs[i];
3837 3838 3839 3840 3841 3842 3843 3844 3845 3846 3847 3848 3849 3850
                break;
            }
        }
        if (!dev) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("network '%s' requires exclusive access "
                             "to interfaces, but none are available"),
                           netdef->name);
            goto error;
        }
        iface->data.network.actual->data.hostdev.def.parent.type = VIR_DOMAIN_DEVICE_NET;
        iface->data.network.actual->data.hostdev.def.parent.data.net = iface;
        iface->data.network.actual->data.hostdev.def.info = &iface->info;
        iface->data.network.actual->data.hostdev.def.mode = VIR_DOMAIN_HOSTDEV_MODE_SUBSYS;
3851
        iface->data.network.actual->data.hostdev.def.managed = netdef->forward.managed ? 1 : 0;
3852
        iface->data.network.actual->data.hostdev.def.source.subsys.type = dev->type;
3853
        iface->data.network.actual->data.hostdev.def.source.subsys.u.pci.addr = dev->device.pci;
3854

E
Eric Blake 已提交
3855
        switch (netdef->forward.driverName) {
3856
        case VIR_NETWORK_FORWARD_DRIVER_NAME_DEFAULT:
3857
            backend = VIR_DOMAIN_HOSTDEV_PCI_BACKEND_DEFAULT;
3858 3859
            break;
        case VIR_NETWORK_FORWARD_DRIVER_NAME_KVM:
3860
            backend = VIR_DOMAIN_HOSTDEV_PCI_BACKEND_KVM;
3861 3862
            break;
        case VIR_NETWORK_FORWARD_DRIVER_NAME_VFIO:
3863
            backend = VIR_DOMAIN_HOSTDEV_PCI_BACKEND_VFIO;
3864 3865 3866 3867 3868 3869 3870 3871 3872 3873 3874
            break;
        default:
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("unrecognized driver name value %d "
                             " in network '%s'"),
                           netdef->forward.driverName, netdef->name);
            goto error;
        }
        iface->data.network.actual->data.hostdev.def.source.subsys.u.pci.backend
            = backend;

3875 3876 3877 3878 3879 3880 3881 3882 3883 3884 3885 3886 3887 3888 3889 3890 3891 3892 3893 3894 3895 3896 3897 3898 3899
        /* merge virtualports from interface, network, and portgroup to
         * arrive at actual virtualport to use
         */
        if (virNetDevVPortProfileMerge3(&iface->data.network.actual->virtPortProfile,
                                        iface->virtPortProfile,
                                        netdef->virtPortProfile,
                                        portgroup
                                        ? portgroup->virtPortProfile : NULL) < 0) {
            goto error;
        }
        virtport = iface->data.network.actual->virtPortProfile;
        if (virtport) {
            /* make sure type is supported for hostdev connections */
            if (virtport->virtPortType != VIR_NETDEV_VPORT_PROFILE_8021QBG &&
                virtport->virtPortType != VIR_NETDEV_VPORT_PROFILE_8021QBH) {
                virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                               _("<virtualport type='%s'> not supported for network "
                                 "'%s' which uses an SR-IOV Virtual Function "
                                 "via PCI passthrough"),
                               virNetDevVPortTypeToString(virtport->virtPortType),
                               netdef->name);
                goto error;
            }
        }

3900 3901 3902 3903
    } else if ((netdef->forward.type == VIR_NETWORK_FORWARD_BRIDGE) ||
               (netdef->forward.type == VIR_NETWORK_FORWARD_PRIVATE) ||
               (netdef->forward.type == VIR_NETWORK_FORWARD_VEPA) ||
               (netdef->forward.type == VIR_NETWORK_FORWARD_PASSTHROUGH)) {
3904 3905 3906 3907 3908 3909

        /* <forward type='bridge|private|vepa|passthrough'> are all
         * VIR_DOMAIN_NET_TYPE_DIRECT.
         */

        /* Set type=direct and appropriate <source mode='xxx'/> */
3910
        iface->data.network.actual->type = actualType = VIR_DOMAIN_NET_TYPE_DIRECT;
3911
        switch (netdef->forward.type) {
3912
        case VIR_NETWORK_FORWARD_BRIDGE:
3913
            iface->data.network.actual->data.direct.mode = VIR_NETDEV_MACVLAN_MODE_BRIDGE;
3914 3915
            break;
        case VIR_NETWORK_FORWARD_PRIVATE:
3916
            iface->data.network.actual->data.direct.mode = VIR_NETDEV_MACVLAN_MODE_PRIVATE;
3917 3918
            break;
        case VIR_NETWORK_FORWARD_VEPA:
3919
            iface->data.network.actual->data.direct.mode = VIR_NETDEV_MACVLAN_MODE_VEPA;
3920 3921
            break;
        case VIR_NETWORK_FORWARD_PASSTHROUGH:
3922
            iface->data.network.actual->data.direct.mode = VIR_NETDEV_MACVLAN_MODE_PASSTHRU;
3923 3924 3925
            break;
        }

3926 3927 3928 3929 3930 3931 3932 3933
        /* merge virtualports from interface, network, and portgroup to
         * arrive at actual virtualport to use
         */
        if (virNetDevVPortProfileMerge3(&iface->data.network.actual->virtPortProfile,
                                        iface->virtPortProfile,
                                        netdef->virtPortProfile,
                                        portgroup
                                        ? portgroup->virtPortProfile : NULL) < 0) {
3934
            goto error;
3935
        }
3936
        virtport = iface->data.network.actual->virtPortProfile;
3937
        if (virtport) {
3938 3939 3940 3941 3942 3943 3944 3945
            /* make sure type is supported for macvtap connections */
            if (virtport->virtPortType != VIR_NETDEV_VPORT_PROFILE_8021QBG &&
                virtport->virtPortType != VIR_NETDEV_VPORT_PROFILE_8021QBH) {
                virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                               _("<virtualport type='%s'> not supported for network "
                                 "'%s' which uses a macvtap device"),
                               virNetDevVPortTypeToString(virtport->virtPortType),
                               netdef->name);
3946
                goto error;
3947 3948
            }
        }
3949

3950 3951 3952
        /* If there is only a single device, just return it (caller will detect
         * any error if exclusive use is required but could not be acquired).
         */
3953
        if ((netdef->forward.nifs <= 0) && (netdef->forward.npfs <= 0)) {
3954 3955 3956 3957
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("network '%s' uses a direct mode, but "
                             "has no forward dev and no interface pool"),
                           netdef->name);
3958
            goto error;
3959 3960 3961
        } else {
            /* pick an interface from the pool */

3962
            if (networkCreateInterfacePool(netdef) < 0)
3963 3964
                goto error;

3965 3966 3967 3968 3969
            /* PASSTHROUGH mode, and PRIVATE Mode + 802.1Qbh both
             * require exclusive access to a device, so current
             * connections count must be 0.  Other modes can share, so
             * just search for the one with the lowest number of
             * connections.
3970
             */
3971 3972
            if ((netdef->forward.type == VIR_NETWORK_FORWARD_PASSTHROUGH) ||
                ((netdef->forward.type == VIR_NETWORK_FORWARD_PRIVATE) &&
3973 3974 3975
                 iface->data.network.actual->virtPortProfile &&
                 (iface->data.network.actual->virtPortProfile->virtPortType
                  == VIR_NETDEV_VPORT_PROFILE_8021QBH))) {
3976

3977
                /* pick first dev with 0 connections */
3978 3979 3980
                for (i = 0; i < netdef->forward.nifs; i++) {
                    if (netdef->forward.ifs[i].connections == 0) {
                        dev = &netdef->forward.ifs[i];
3981 3982 3983 3984 3985
                        break;
                    }
                }
            } else {
                /* pick least used dev */
3986
                dev = &netdef->forward.ifs[0];
3987 3988 3989
                for (i = 1; i < netdef->forward.nifs; i++) {
                    if (netdef->forward.ifs[i].connections < dev->connections)
                        dev = &netdef->forward.ifs[i];
3990 3991 3992 3993
                }
            }
            /* dev points at the physical device we want to use */
            if (!dev) {
3994 3995 3996 3997
                virReportError(VIR_ERR_INTERNAL_ERROR,
                               _("network '%s' requires exclusive access "
                                 "to interfaces, but none are available"),
                               netdef->name);
3998
                goto error;
3999
            }
4000 4001
            if (VIR_STRDUP(iface->data.network.actual->data.direct.linkdev,
                           dev->device.dev) < 0)
4002
                goto error;
4003 4004 4005
        }
    }

4006
    if (virNetDevVPortProfileCheckComplete(virtport, true) < 0)
4007
        goto error;
4008

4009
 validate:
4010 4011 4012 4013 4014
    /* make sure that everything now specified for the device is
     * actually supported on this type of network. NB: network,
     * netdev, and iface->data.network.actual may all be NULL.
     */

4015
    if (virDomainNetGetActualVlan(iface)) {
4016 4017 4018 4019 4020 4021 4022 4023 4024 4025 4026 4027 4028 4029 4030 4031 4032 4033 4034 4035 4036 4037 4038 4039 4040 4041 4042 4043 4044
        /* vlan configuration via libvirt is only supported for
         * PCI Passthrough SR-IOV devices and openvswitch bridges.
         * otherwise log an error and fail
         */
        if (!(actualType == VIR_DOMAIN_NET_TYPE_HOSTDEV ||
              (actualType == VIR_DOMAIN_NET_TYPE_BRIDGE &&
               virtport && virtport->virtPortType
               == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH))) {
            if (netdef) {
                virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                               _("an interface connecting to network '%s' "
                                 "is requesting a vlan tag, but that is not "
                                 "supported for this type of network"),
                               netdef->name);
            } else {
                virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                               _("an interface of type '%s' "
                                 "is requesting a vlan tag, but that is not "
                                 "supported for this type of connection"),
                               virDomainNetTypeToString(iface->type));
            }
            goto error;
        }
    }

    if (netdef) {
        netdef->connections++;
        VIR_DEBUG("Using network %s, %d connections",
                  netdef->name, netdef->connections);
4045

4046 4047 4048 4049 4050 4051 4052 4053 4054 4055 4056 4057 4058 4059 4060 4061 4062 4063 4064
        if (dev) {
            /* mark the allocation */
            dev->connections++;
            if (actualType != VIR_DOMAIN_NET_TYPE_HOSTDEV) {
                VIR_DEBUG("Using physical device %s, %d connections",
                          dev->device.dev, dev->connections);
            } else {
                VIR_DEBUG("Using physical device %04x:%02x:%02x.%x, connections %d",
                          dev->device.pci.domain, dev->device.pci.bus,
                          dev->device.pci.slot, dev->device.pci.function,
                          dev->connections);
            }
        }

        /* finally we can call the 'plugged' hook script if any */
        if (networkRunHook(network, dom, iface,
                           VIR_HOOK_NETWORK_OP_IFACE_PLUGGED,
                           VIR_HOOK_SUBOP_BEGIN) < 0) {
            /* adjust for failure */
4065
            netdef->connections--;
4066 4067 4068 4069
            if (dev)
                dev->connections--;
            goto error;
        }
4070 4071
    }

4072
    ret = 0;
4073

4074
 cleanup:
4075 4076
    if (network)
        virNetworkObjUnlock(network);
4077 4078
    return ret;

4079
 error:
4080
    if (iface->type == VIR_DOMAIN_NET_TYPE_NETWORK) {
4081 4082 4083
        virDomainActualNetDefFree(iface->data.network.actual);
        iface->data.network.actual = NULL;
    }
4084
    goto cleanup;
4085 4086 4087
}

/* networkNotifyActualDevice:
4088
 * @dom: domain definition that @iface belongs to
4089 4090 4091 4092 4093 4094 4095 4096 4097 4098
 * @iface:  the domain's NetDef with an "actual" device already filled in.
 *
 * Called to notify the network driver when libvirtd is restarted and
 * finds an already running domain. If appropriate it will force an
 * allocation of the actual->direct.linkdev to get everything back in
 * order.
 *
 * Returns 0 on success, -1 on failure.
 */
int
4099 4100
networkNotifyActualDevice(virDomainDefPtr dom,
                          virDomainNetDefPtr iface)
4101
{
4102
    virDomainNetType actualType = virDomainNetGetActualType(iface);
4103 4104
    virNetworkObjPtr network;
    virNetworkDefPtr netdef;
4105
    virNetworkForwardIfDefPtr dev = NULL;
4106 4107
    size_t i;
    int ret = -1;
4108 4109

    if (iface->type != VIR_DOMAIN_NET_TYPE_NETWORK)
J
Ján Tomko 已提交
4110
        return 0;
4111

4112
    networkDriverLock();
4113
    network = virNetworkFindByName(&driver->networks, iface->data.network.name);
4114
    networkDriverUnlock();
4115
    if (!network) {
4116 4117 4118
        virReportError(VIR_ERR_NO_NETWORK,
                       _("no network with matching name '%s'"),
                       iface->data.network.name);
4119 4120 4121 4122 4123
        goto error;
    }
    netdef = network->def;

    if (!iface->data.network.actual ||
4124 4125
        (actualType != VIR_DOMAIN_NET_TYPE_DIRECT &&
         actualType != VIR_DOMAIN_NET_TYPE_HOSTDEV)) {
4126 4127
        VIR_DEBUG("Nothing to claim from network %s", iface->data.network.name);
        goto success;
4128 4129
    }

4130
    if (networkCreateInterfacePool(netdef) < 0)
4131
        goto error;
4132

4133
    if (netdef->forward.nifs == 0) {
4134
        virReportError(VIR_ERR_INTERNAL_ERROR,
4135 4136
                       _("network '%s' uses a direct or hostdev mode, "
                         "but has no forward dev and no interface pool"),
4137
                       netdef->name);
4138
        goto error;
4139
    }
4140

4141 4142
    if (actualType == VIR_DOMAIN_NET_TYPE_DIRECT) {
        const char *actualDev;
4143

4144 4145 4146 4147 4148 4149 4150 4151 4152
        actualDev = virDomainNetGetActualDirectDev(iface);
        if (!actualDev) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("the interface uses a direct mode, "
                             "but has no source dev"));
            goto error;
        }

        /* find the matching interface and increment its connections */
4153 4154
        for (i = 0; i < netdef->forward.nifs; i++) {
            if (netdef->forward.ifs[i].type
4155
                == VIR_NETWORK_FORWARD_HOSTDEV_DEVICE_NETDEV &&
4156 4157
                STREQ(actualDev, netdef->forward.ifs[i].device.dev)) {
                dev = &netdef->forward.ifs[i];
4158 4159 4160 4161 4162
                break;
            }
        }
        /* dev points at the physical device we want to use */
        if (!dev) {
4163
            virReportError(VIR_ERR_INTERNAL_ERROR,
4164 4165
                           _("network '%s' doesn't have dev='%s' "
                             "in use by domain"),
4166
                           netdef->name, actualDev);
4167
            goto error;
4168 4169
        }

4170
        /* PASSTHROUGH mode and PRIVATE Mode + 802.1Qbh both require
4171 4172
         * exclusive access to a device, so current connections count
         * must be 0 in those cases.
4173
         */
4174
        if ((dev->connections > 0) &&
4175 4176
            ((netdef->forward.type == VIR_NETWORK_FORWARD_PASSTHROUGH) ||
             ((netdef->forward.type == VIR_NETWORK_FORWARD_PRIVATE) &&
4177 4178
              iface->data.network.actual->virtPortProfile &&
              (iface->data.network.actual->virtPortProfile->virtPortType
4179
               == VIR_NETDEV_VPORT_PROFILE_8021QBH)))) {
4180
            virReportError(VIR_ERR_INTERNAL_ERROR,
4181 4182
                           _("network '%s' claims dev='%s' is already in "
                             "use by a different domain"),
4183
                           netdef->name, actualDev);
4184
            goto error;
4185
        }
4186

4187
        /* we are now assured of success, so mark the allocation */
4188
        dev->connections++;
4189
        VIR_DEBUG("Using physical device %s, connections %d",
4190
                  dev->device.dev, dev->connections);
4191 4192 4193 4194 4195 4196 4197 4198 4199 4200 4201 4202 4203

    }  else /* if (actualType == VIR_DOMAIN_NET_TYPE_HOSTDEV) */ {
        virDomainHostdevDefPtr hostdev;

        hostdev = virDomainNetGetActualHostdev(iface);
        if (!hostdev) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("the interface uses a hostdev mode, "
                             "but has no hostdev"));
            goto error;
        }

        /* find the matching interface and increment its connections */
4204 4205
        for (i = 0; i < netdef->forward.nifs; i++) {
            if (netdef->forward.ifs[i].type
4206
                == VIR_NETWORK_FORWARD_HOSTDEV_DEVICE_PCI &&
4207
                virDevicePCIAddressEqual(&hostdev->source.subsys.u.pci.addr,
4208 4209
                                         &netdef->forward.ifs[i].device.pci)) {
                dev = &netdef->forward.ifs[i];
4210 4211 4212 4213 4214 4215 4216 4217 4218
                break;
            }
        }
        /* dev points at the physical device we want to use */
        if (!dev) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("network '%s' doesn't have "
                             "PCI device %04x:%02x:%02x.%x in use by domain"),
                           netdef->name,
4219 4220 4221 4222
                           hostdev->source.subsys.u.pci.addr.domain,
                           hostdev->source.subsys.u.pci.addr.bus,
                           hostdev->source.subsys.u.pci.addr.slot,
                           hostdev->source.subsys.u.pci.addr.function);
J
Ján Tomko 已提交
4223
            goto error;
4224 4225 4226 4227 4228 4229 4230
        }

        /* PASSTHROUGH mode, PRIVATE Mode + 802.1Qbh, and hostdev (PCI
         * passthrough) all require exclusive access to a device, so
         * current connections count must be 0 in those cases.
         */
        if ((dev->connections > 0) &&
4231
            netdef->forward.type == VIR_NETWORK_FORWARD_HOSTDEV) {
4232 4233 4234 4235 4236 4237 4238 4239 4240 4241 4242 4243 4244 4245 4246 4247
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("network '%s' claims the PCI device at "
                             "domain=%d bus=%d slot=%d function=%d "
                             "is already in use by a different domain"),
                           netdef->name,
                           dev->device.pci.domain, dev->device.pci.bus,
                           dev->device.pci.slot, dev->device.pci.function);
            goto error;
        }

        /* we are now assured of success, so mark the allocation */
        dev->connections++;
        VIR_DEBUG("Using physical device %04x:%02x:%02x.%x, connections %d",
                  dev->device.pci.domain, dev->device.pci.bus,
                  dev->device.pci.slot, dev->device.pci.function,
                  dev->connections);
4248 4249
    }

4250
 success:
4251 4252 4253
    netdef->connections++;
    VIR_DEBUG("Using network %s, %d connections",
              netdef->name, netdef->connections);
4254 4255 4256 4257 4258 4259 4260 4261 4262 4263 4264

    /* finally we can call the 'plugged' hook script if any */
    if (networkRunHook(network, dom, iface, VIR_HOOK_NETWORK_OP_IFACE_PLUGGED,
                       VIR_HOOK_SUBOP_BEGIN) < 0) {
        /* adjust for failure */
        if (dev)
            dev->connections--;
        netdef->connections--;
        goto error;
    }

4265
    ret = 0;
4266
 cleanup:
4267 4268 4269
    if (network)
        virNetworkObjUnlock(network);
    return ret;
4270

4271
 error:
4272
    goto cleanup;
4273 4274 4275 4276
}


/* networkReleaseActualDevice:
4277
 * @dom: domain definition that @iface belongs to
4278 4279 4280 4281 4282 4283 4284 4285 4286 4287
 * @iface:  a domain's NetDef (interface definition)
 *
 * Given a domain <interface> element that previously had its <actual>
 * element filled in (and possibly a physical device allocated to it),
 * free up the physical device for use by someone else, and free the
 * virDomainActualNetDef.
 *
 * Returns 0 on success, -1 on failure.
 */
int
4288 4289
networkReleaseActualDevice(virDomainDefPtr dom,
                           virDomainNetDefPtr iface)
4290
{
4291
    virDomainNetType actualType = virDomainNetGetActualType(iface);
4292
    virNetworkObjPtr network;
4293
    virNetworkDefPtr netdef;
4294
    virNetworkForwardIfDefPtr dev = NULL;
4295 4296
    size_t i;
    int ret = -1;
4297 4298

    if (iface->type != VIR_DOMAIN_NET_TYPE_NETWORK)
J
Ján Tomko 已提交
4299
        return 0;
4300

4301
    networkDriverLock();
4302
    network = virNetworkFindByName(&driver->networks, iface->data.network.name);
4303
    networkDriverUnlock();
4304
    if (!network) {
4305 4306 4307
        virReportError(VIR_ERR_NO_NETWORK,
                       _("no network with matching name '%s'"),
                       iface->data.network.name);
4308 4309 4310 4311
        goto error;
    }
    netdef = network->def;

4312 4313
    if (iface->data.network.actual &&
        (netdef->forward.type == VIR_NETWORK_FORWARD_NONE ||
4314 4315 4316 4317 4318
         netdef->forward.type == VIR_NETWORK_FORWARD_NAT ||
         netdef->forward.type == VIR_NETWORK_FORWARD_ROUTE) &&
        networkUnplugBandwidth(network, iface) < 0)
        goto error;

4319 4320 4321
    if ((!iface->data.network.actual) ||
        ((actualType != VIR_DOMAIN_NET_TYPE_DIRECT) &&
         (actualType != VIR_DOMAIN_NET_TYPE_HOSTDEV))) {
4322 4323
        VIR_DEBUG("Nothing to release to network %s", iface->data.network.name);
        goto success;
4324 4325
    }

4326
    if (netdef->forward.nifs == 0) {
4327
        virReportError(VIR_ERR_INTERNAL_ERROR,
4328
                       _("network '%s' uses a direct/hostdev mode, but "
4329 4330
                         "has no forward dev and no interface pool"),
                       netdef->name);
4331
        goto error;
4332 4333 4334 4335 4336 4337 4338 4339 4340 4341 4342 4343
    }

    if (actualType == VIR_DOMAIN_NET_TYPE_DIRECT) {
        const char *actualDev;

        actualDev = virDomainNetGetActualDirectDev(iface);
        if (!actualDev) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("the interface uses a direct mode, "
                             "but has no source dev"));
            goto error;
        }
4344

4345 4346
        for (i = 0; i < netdef->forward.nifs; i++) {
            if (netdef->forward.ifs[i].type
4347
                == VIR_NETWORK_FORWARD_HOSTDEV_DEVICE_NETDEV &&
4348 4349
                STREQ(actualDev, netdef->forward.ifs[i].device.dev)) {
                dev = &netdef->forward.ifs[i];
4350 4351 4352
                break;
            }
        }
4353

4354
        if (!dev) {
4355
            virReportError(VIR_ERR_INTERNAL_ERROR,
4356 4357
                           _("network '%s' doesn't have dev='%s' "
                             "in use by domain"),
4358
                           netdef->name, actualDev);
4359
            goto error;
4360 4361
        }

4362
        dev->connections--;
4363
        VIR_DEBUG("Releasing physical device %s, connections %d",
4364
                  dev->device.dev, dev->connections);
4365 4366 4367 4368 4369 4370 4371 4372 4373 4374 4375

    } else /* if (actualType == VIR_DOMAIN_NET_TYPE_HOSTDEV) */ {
        virDomainHostdevDefPtr hostdev;

        hostdev = virDomainNetGetActualHostdev(iface);
        if (!hostdev) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("the interface uses a hostdev mode, but has no hostdev"));
            goto error;
        }

4376 4377
        for (i = 0; i < netdef->forward.nifs; i++) {
            if (netdef->forward.ifs[i].type
4378
                == VIR_NETWORK_FORWARD_HOSTDEV_DEVICE_PCI &&
4379
                virDevicePCIAddressEqual(&hostdev->source.subsys.u.pci.addr,
4380 4381
                                         &netdef->forward.ifs[i].device.pci)) {
                dev = &netdef->forward.ifs[i];
4382 4383 4384 4385 4386 4387 4388 4389 4390
                break;
            }
        }

        if (!dev) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("network '%s' doesn't have "
                             "PCI device %04x:%02x:%02x.%x in use by domain"),
                           netdef->name,
4391 4392 4393 4394
                           hostdev->source.subsys.u.pci.addr.domain,
                           hostdev->source.subsys.u.pci.addr.bus,
                           hostdev->source.subsys.u.pci.addr.slot,
                           hostdev->source.subsys.u.pci.addr.function);
J
Ján Tomko 已提交
4395
            goto error;
4396 4397 4398 4399 4400 4401 4402
        }

        dev->connections--;
        VIR_DEBUG("Releasing physical device %04x:%02x:%02x.%x, connections %d",
                  dev->device.pci.domain, dev->device.pci.bus,
                  dev->device.pci.slot, dev->device.pci.function,
                  dev->connections);
J
Ján Tomko 已提交
4403
    }
4404

4405
 success:
4406
    if (iface->data.network.actual) {
4407
        netdef->connections--;
4408 4409
        VIR_DEBUG("Releasing network %s, %d connections",
                  netdef->name, netdef->connections);
4410

4411 4412 4413 4414
        /* finally we can call the 'unplugged' hook script if any */
        networkRunHook(network, dom, iface, VIR_HOOK_NETWORK_OP_IFACE_UNPLUGGED,
                       VIR_HOOK_SUBOP_BEGIN);
    }
4415
    ret = 0;
4416
 cleanup:
4417 4418
    if (network)
        virNetworkObjUnlock(network);
4419 4420 4421 4422
    if (iface->type == VIR_DOMAIN_NET_TYPE_NETWORK) {
        virDomainActualNetDefFree(iface->data.network.actual);
        iface->data.network.actual = NULL;
    }
4423
    return ret;
4424

4425
 error:
4426
    goto cleanup;
4427
}
4428 4429 4430 4431 4432 4433 4434 4435 4436 4437 4438 4439 4440 4441 4442 4443 4444 4445 4446 4447 4448 4449 4450 4451

/*
 * networkGetNetworkAddress:
 * @netname: the name of a network
 * @netaddr: string representation of IP address for that network.
 *
 * Attempt to return an IP (v4) address associated with the named
 * network. If a libvirt virtual network, that will be provided in the
 * configuration. For host bridge and direct (macvtap) networks, we
 * must do an ioctl to learn the address.
 *
 * Note: This function returns the 1st IPv4 address it finds. It might
 * be useful if it was more flexible, but the current use (getting a
 * listen address for qemu's vnc/spice graphics server) can only use a
 * single address anyway.
 *
 * Returns 0 on success, and puts a string (which must be free'd by
 * the caller) into *netaddr. Returns -1 on failure or -2 if
 * completely unsupported.
 */
int
networkGetNetworkAddress(const char *netname, char **netaddr)
{
    int ret = -1;
4452
    virNetworkObjPtr network;
4453 4454 4455 4456
    virNetworkDefPtr netdef;
    virNetworkIpDefPtr ipdef;
    virSocketAddr addr;
    virSocketAddrPtr addrptr = NULL;
4457
    char *dev_name = NULL;
4458 4459

    *netaddr = NULL;
4460
    networkDriverLock();
4461
    network = virNetworkFindByName(&driver->networks, netname);
4462
    networkDriverUnlock();
4463
    if (!network) {
4464 4465 4466
        virReportError(VIR_ERR_NO_NETWORK,
                       _("no network with matching name '%s'"),
                       netname);
4467
        goto error;
4468 4469 4470
    }
    netdef = network->def;

4471
    switch (netdef->forward.type) {
4472 4473 4474 4475 4476 4477
    case VIR_NETWORK_FORWARD_NONE:
    case VIR_NETWORK_FORWARD_NAT:
    case VIR_NETWORK_FORWARD_ROUTE:
        /* if there's an ipv4def, get it's address */
        ipdef = virNetworkDefGetIpByIndex(netdef, AF_INET, 0);
        if (!ipdef) {
4478 4479 4480
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("network '%s' doesn't have an IPv4 address"),
                           netdef->name);
4481 4482 4483 4484 4485 4486
            break;
        }
        addrptr = &ipdef->address;
        break;

    case VIR_NETWORK_FORWARD_BRIDGE:
4487
        if ((dev_name = netdef->bridge))
4488 4489 4490 4491 4492 4493 4494 4495
            break;
        /*
         * fall through if netdef->bridge wasn't set, since this is
         * also a direct-mode interface.
         */
    case VIR_NETWORK_FORWARD_PRIVATE:
    case VIR_NETWORK_FORWARD_VEPA:
    case VIR_NETWORK_FORWARD_PASSTHROUGH:
4496 4497
        if ((netdef->forward.nifs > 0) && netdef->forward.ifs)
            dev_name = netdef->forward.ifs[0].device.dev;
4498

4499
        if (!dev_name) {
4500 4501 4502
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("network '%s' has no associated interface or bridge"),
                           netdef->name);
4503 4504 4505 4506
        }
        break;
    }

4507
    if (dev_name) {
4508
        if (virNetDevGetIPv4Address(dev_name, &addr) < 0)
4509
            goto error;
4510
        addrptr = &addr;
4511 4512
    }

4513 4514 4515
    if (!(addrptr &&
          (*netaddr = virSocketAddrFormat(addrptr)))) {
        goto error;
4516 4517
    }

4518
    ret = 0;
4519
 cleanup:
4520 4521 4522
    if (network)
        virNetworkObjUnlock(network);
    return ret;
4523

4524
 error:
4525
    goto cleanup;
4526
}
4527 4528 4529 4530 4531 4532 4533 4534 4535 4536 4537 4538 4539 4540 4541 4542 4543 4544

/**
 * networkCheckBandwidth:
 * @net: network QoS
 * @iface: interface QoS
 * @new_rate: new rate for non guaranteed class
 *
 * Returns: -1 if plugging would overcommit network QoS
 *           0 if plugging is safe (@new_rate updated)
 *           1 if no QoS is set (@new_rate untouched)
 */
static int
networkCheckBandwidth(virNetworkObjPtr net,
                      virDomainNetDefPtr iface,
                      unsigned long long *new_rate)
{
    int ret = -1;
    virNetDevBandwidthPtr netBand = net->def->bandwidth;
4545
    virNetDevBandwidthPtr ifaceBand = virDomainNetGetActualBandwidth(iface);
4546 4547 4548 4549
    unsigned long long tmp_floor_sum = net->floor_sum;
    unsigned long long tmp_new_rate = 0;
    char ifmac[VIR_MAC_STRING_BUFLEN];

4550 4551 4552 4553 4554 4555 4556 4557 4558 4559 4560
    virMacAddrFormat(&iface->mac, ifmac);

    if (ifaceBand && ifaceBand->in && ifaceBand->in->floor &&
        !(netBand && netBand->in)) {
        virReportError(VIR_ERR_OPERATION_UNSUPPORTED,
                       _("Invalid use of 'floor' on interface with MAC "
                         "address %s - network '%s' has no inbound QoS set"),
                       ifmac, net->def->name);
        return -1;
    }

4561
    if (!ifaceBand || !ifaceBand->in || !ifaceBand->in->floor ||
4562 4563
        !netBand || !netBand->in) {
        /* no QoS required, claim success */
4564
        return 1;
4565
    }
4566 4567 4568 4569 4570 4571 4572 4573 4574 4575 4576 4577 4578 4579 4580 4581 4582 4583 4584 4585 4586 4587 4588 4589 4590 4591 4592 4593 4594 4595 4596

    tmp_new_rate = netBand->in->average;
    tmp_floor_sum += ifaceBand->in->floor;

    /* check against peak */
    if (netBand->in->peak) {
        tmp_new_rate = netBand->in->peak;
        if (tmp_floor_sum > netBand->in->peak) {
            virReportError(VIR_ERR_OPERATION_INVALID,
                           _("Cannot plug '%s' interface into '%s' because it "
                             "would overcommit 'peak' on network '%s'"),
                           ifmac,
                           net->def->bridge,
                           net->def->name);
            goto cleanup;
        }
    } else if (tmp_floor_sum > netBand->in->average) {
        /* tmp_floor_sum can be between 'average' and 'peak' iff 'peak' is set.
         * Otherwise, tmp_floor_sum must be below 'average'. */
        virReportError(VIR_ERR_OPERATION_INVALID,
                       _("Cannot plug '%s' interface into '%s' because it "
                         "would overcommit 'average' on network '%s'"),
                       ifmac,
                       net->def->bridge,
                       net->def->name);
        goto cleanup;
    }

    *new_rate = tmp_new_rate;
    ret = 0;

4597
 cleanup:
4598 4599 4600 4601 4602 4603 4604 4605 4606 4607 4608 4609 4610 4611 4612 4613 4614 4615 4616 4617 4618 4619 4620 4621 4622 4623 4624 4625 4626 4627 4628 4629 4630 4631 4632 4633 4634
    return ret;
}

/**
 * networkNextClassID:
 * @net: network object
 *
 * Find next free class ID. @net is supposed
 * to be locked already. If there is a free ID,
 * it is marked as used and returned.
 *
 * Returns next free class ID or -1 if none is available.
 */
static ssize_t
networkNextClassID(virNetworkObjPtr net)
{
    size_t ret = 0;
    bool is_set = false;

    while (virBitmapGetBit(net->class_id, ret, &is_set) == 0 && is_set)
        ret++;

    if (is_set || virBitmapSetBit(net->class_id, ret) < 0)
        return -1;

    return ret;
}

static int
networkPlugBandwidth(virNetworkObjPtr net,
                     virDomainNetDefPtr iface)
{
    int ret = -1;
    int plug_ret;
    unsigned long long new_rate = 0;
    ssize_t class_id = 0;
    char ifmac[VIR_MAC_STRING_BUFLEN];
4635
    virNetDevBandwidthPtr ifaceBand = virDomainNetGetActualBandwidth(iface);
4636 4637 4638 4639 4640 4641 4642 4643 4644 4645 4646 4647 4648 4649 4650 4651 4652 4653 4654 4655 4656 4657 4658 4659 4660 4661 4662 4663

    if ((plug_ret = networkCheckBandwidth(net, iface, &new_rate)) < 0) {
        /* helper reported error */
        goto cleanup;
    }

    if (plug_ret > 0) {
        /* no QoS needs to be set; claim success */
        ret = 0;
        goto cleanup;
    }

    virMacAddrFormat(&iface->mac, ifmac);
    if (iface->type != VIR_DOMAIN_NET_TYPE_NETWORK ||
        !iface->data.network.actual) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Cannot set bandwidth on interface '%s' of type %d"),
                       ifmac, iface->type);
        goto cleanup;
    }

    /* generate new class_id */
    if ((class_id = networkNextClassID(net)) < 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("Could not generate next class ID"));
        goto cleanup;
    }

4664 4665
    plug_ret = virNetDevBandwidthPlug(net->def->bridge, net->def->bandwidth,
                                      &iface->mac, ifaceBand, class_id);
4666 4667 4668 4669 4670 4671 4672 4673
    if (plug_ret < 0) {
        ignore_value(virNetDevBandwidthUnplug(net->def->bridge, class_id));
        goto cleanup;
    }

    /* QoS was set, generate new class ID */
    iface->data.network.actual->class_id = class_id;
    /* update sum of 'floor'-s of attached NICs */
4674
    net->floor_sum += ifaceBand->in->floor;
4675
    /* update status file */
4676
    if (virNetworkSaveStatus(driver->stateDir, net) < 0) {
4677
        ignore_value(virBitmapClearBit(net->class_id, class_id));
4678
        net->floor_sum -= ifaceBand->in->floor;
4679 4680 4681 4682
        iface->data.network.actual->class_id = 0;
        ignore_value(virNetDevBandwidthUnplug(net->def->bridge, class_id));
        goto cleanup;
    }
4683 4684 4685 4686 4687 4688 4689 4690 4691
    /* update rate for non guaranteed NICs */
    new_rate -= net->floor_sum;
    if (virNetDevBandwidthUpdateRate(net->def->bridge, "1:2",
                                     net->def->bandwidth, new_rate) < 0)
        VIR_WARN("Unable to update rate for 1:2 class on %s bridge",
                 net->def->bridge);

    ret = 0;

4692
 cleanup:
4693 4694 4695 4696 4697 4698 4699 4700 4701
    return ret;
}

static int
networkUnplugBandwidth(virNetworkObjPtr net,
                       virDomainNetDefPtr iface)
{
    int ret = 0;
    unsigned long long new_rate;
4702
    virNetDevBandwidthPtr ifaceBand = virDomainNetGetActualBandwidth(iface);
4703 4704 4705

    if (iface->data.network.actual &&
        iface->data.network.actual->class_id) {
4706 4707 4708 4709 4710
        if (!net->def->bandwidth || !net->def->bandwidth->in) {
            VIR_WARN("Network %s has no bandwidth but unplug requested",
                     net->def->name);
            goto cleanup;
        }
4711 4712 4713 4714 4715 4716 4717 4718 4719 4720 4721
        /* we must remove class from bridge */
        new_rate = net->def->bandwidth->in->average;

        if (net->def->bandwidth->in->peak > 0)
            new_rate = net->def->bandwidth->in->peak;

        ret = virNetDevBandwidthUnplug(net->def->bridge,
                                       iface->data.network.actual->class_id);
        if (ret < 0)
            goto cleanup;
        /* update sum of 'floor'-s of attached NICs */
4722
        net->floor_sum -= ifaceBand->in->floor;
4723 4724 4725 4726
        /* return class ID */
        ignore_value(virBitmapClearBit(net->class_id,
                                       iface->data.network.actual->class_id));
        /* update status file */
4727
        if (virNetworkSaveStatus(driver->stateDir, net) < 0) {
4728
            net->floor_sum += ifaceBand->in->floor;
4729 4730 4731 4732
            ignore_value(virBitmapSetBit(net->class_id,
                                         iface->data.network.actual->class_id));
            goto cleanup;
        }
4733 4734 4735 4736 4737 4738 4739 4740 4741 4742
        /* update rate for non guaranteed NICs */
        new_rate -= net->floor_sum;
        if (virNetDevBandwidthUpdateRate(net->def->bridge, "1:2",
                                         net->def->bandwidth, new_rate) < 0)
            VIR_WARN("Unable to update rate for 1:2 class on %s bridge",
                     net->def->bridge);
        /* no class is associated any longer */
        iface->data.network.actual->class_id = 0;
    }

4743
 cleanup:
4744 4745
    return ret;
}
4746 4747 4748

static void
networkNetworkObjTaint(virNetworkObjPtr net,
4749
                       virNetworkTaintFlags taint)
4750 4751 4752 4753 4754 4755 4756 4757 4758 4759 4760
{
    if (virNetworkObjTaint(net, taint)) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(net->def->uuid, uuidstr);

        VIR_WARN("Network name='%s' uuid=%s is tainted: %s",
                 net->def->name,
                 uuidstr,
                 virNetworkTaintTypeToString(taint));
    }
}