qemu_hotplug.c 82.6 KB
Newer Older
1 2 3
/*
 * qemu_hotplug.h: QEMU device hotplug management
 *
4
 * Copyright (C) 2006-2012 Red Hat, Inc.
5 6 7 8 9 10 11 12 13 14 15 16 17
 * Copyright (C) 2006 Daniel P. Berrange
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
18
 * License along with this library.  If not, see
O
Osier Yang 已提交
19
 * <http://www.gnu.org/licenses/>.
20 21 22 23 24 25 26 27 28 29 30 31 32
 *
 * Author: Daniel P. Berrange <berrange@redhat.com>
 */


#include <config.h>

#include "qemu_hotplug.h"
#include "qemu_capabilities.h"
#include "qemu_domain.h"
#include "qemu_command.h"
#include "qemu_bridge_filter.h"
#include "qemu_hostdev.h"
33
#include "domain_audit.h"
34 35 36 37 38
#include "domain_nwfilter.h"
#include "logging.h"
#include "virterror_internal.h"
#include "memory.h"
#include "pci.h"
E
Eric Blake 已提交
39
#include "virfile.h"
40
#include "qemu_cgroup.h"
41
#include "locking/domain_lock.h"
42
#include "network/bridge_driver.h"
43 44
#include "virnetdev.h"
#include "virnetdevbridge.h"
A
Ansis Atteka 已提交
45
#include "virnetdevtap.h"
46
#include "device_conf.h"
47 48

#define VIR_FROM_THIS VIR_FROM_QEMU
49
#define CHANGE_MEDIA_RETRIES 10
50 51 52 53 54 55 56 57 58 59

int qemuDomainChangeEjectableMedia(struct qemud_driver *driver,
                                   virDomainObjPtr vm,
                                   virDomainDiskDefPtr disk,
                                   bool force)
{
    virDomainDiskDefPtr origdisk = NULL;
    int i;
    int ret;
    char *driveAlias = NULL;
60
    qemuDomainObjPrivatePtr priv = vm->privateData;
61
    int retries = CHANGE_MEDIA_RETRIES;
62 63 64 65 66 67 68 69 70 71

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (vm->def->disks[i]->bus == disk->bus &&
            STREQ(vm->def->disks[i]->dst, disk->dst)) {
            origdisk = vm->def->disks[i];
            break;
        }
    }

    if (!origdisk) {
72 73 74 75
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No device with bus '%s' and target '%s'"),
                       virDomainDiskBusTypeToString(disk->bus),
                       disk->dst);
76 77 78 79
        return -1;
    }

    if (!origdisk->info.alias) {
80 81
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("missing disk device alias name for %s"), origdisk->dst);
82 83 84 85 86
        return -1;
    }

    if (origdisk->device != VIR_DOMAIN_DISK_DEVICE_FLOPPY &&
        origdisk->device != VIR_DOMAIN_DISK_DEVICE_CDROM) {
87 88
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Removable media not supported for %s device"),
89
                       virDomainDiskDeviceTypeToString(disk->device));
90 91 92
        return -1;
    }

93 94 95
    if (virDomainLockDiskAttach(driver->lockManager, vm, disk) < 0)
        return -1;

96
    if (virSecurityManagerSetImageLabel(driver->securityManager,
97
                                        vm->def, disk) < 0) {
98 99
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
100
        return -1;
101
    }
102

103
    if (!(driveAlias = qemuDeviceDriveHostAlias(origdisk, priv->caps)))
104 105
        goto error;

106
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
107
    ret = qemuMonitorEjectMedia(priv->mon, driveAlias, force);
108
    qemuDomainObjExitMonitor(driver, vm);
109

110
    virObjectRef(vm);
111 112 113 114 115
    /* we don't want to report errors from media tray_open polling */
    while (retries--) {
        if (origdisk->tray_status == VIR_DOMAIN_DISK_TRAY_OPEN)
            break;

116
        virDomainObjUnlock(vm);
117 118
        VIR_DEBUG("Waiting 500ms for tray to open. Retries left %d", retries);
        usleep(500 * 1000); /* sleep 500ms */
119
        virDomainObjLock(vm);
120
    }
121
    virObjectUnref(vm);
122

123
    if (disk->src) {
124 125
        /* deliberately don't depend on 'ret' as 'eject' may have failed for the
         * fist time and we are gonna check the drive state anyway */
126
        const char *format = NULL;
127 128 129 130 131 132 133

        /* We haven't succeeded yet */
        ret = -1;

        if (retries <= 0) {
            virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                           _("Unable to eject media before changing it"));
134
            goto audit;
135 136
        }

137 138 139 140 141 142
        if (disk->type != VIR_DOMAIN_DISK_TYPE_DIR) {
            if (disk->driverType)
                format = disk->driverType;
            else if (origdisk->driverType)
                format = origdisk->driverType;
        }
143
        qemuDomainObjEnterMonitor(driver, vm);
144 145 146
        ret = qemuMonitorChangeMedia(priv->mon,
                                     driveAlias,
                                     disk->src, format);
147
        qemuDomainObjExitMonitor(driver, vm);
148 149
    }

150
audit:
151
    virDomainAuditDisk(vm, origdisk->src, disk->src, "update", ret >= 0);
152 153 154 155

    if (ret < 0)
        goto error;

156
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
157
                                            vm->def, origdisk) < 0)
158 159
        VIR_WARN("Unable to restore security label on ejected image %s", origdisk->src);

160 161 162
    if (virDomainLockDiskDetach(driver->lockManager, vm, origdisk) < 0)
        VIR_WARN("Unable to release lock on disk %s", origdisk->src);

163 164 165 166 167 168 169 170 171 172 173 174 175
    VIR_FREE(origdisk->src);
    origdisk->src = disk->src;
    disk->src = NULL;
    origdisk->type = disk->type;

    VIR_FREE(driveAlias);

    virDomainDiskDefFree(disk);

    return ret;

error:
    VIR_FREE(driveAlias);
176

177
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
178
                                            vm->def, disk) < 0)
179
        VIR_WARN("Unable to restore security label on new media %s", disk->src);
180 181 182 183

    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

184 185 186
    return -1;
}

187 188
int
qemuDomainCheckEjectableMedia(struct qemud_driver *driver,
189 190
                             virDomainObjPtr vm,
                             enum qemuDomainAsyncJob asyncJob)
191 192
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
193
    virHashTablePtr table = NULL;
194 195 196
    int ret = -1;
    int i;

197 198 199 200
    if (qemuDomainObjEnterMonitorAsync(driver, vm, asyncJob) == 0) {
        table = qemuMonitorGetBlockInfo(priv->mon);
        qemuDomainObjExitMonitorWithDriver(driver, vm);
    }
201 202 203 204

    if (!table)
        goto cleanup;

205 206
    for (i = 0; i < vm->def->ndisks; i++) {
        virDomainDiskDefPtr disk = vm->def->disks[i];
207
        struct qemuDomainDiskInfo *info;
208

209 210
        if (disk->device == VIR_DOMAIN_DISK_DEVICE_DISK ||
            disk->device == VIR_DOMAIN_DISK_DEVICE_LUN) {
211
                 continue;
212
        }
213

214 215
        info = qemuMonitorBlockInfoLookup(table, disk->info.alias);
        if (!info)
216 217
            goto cleanup;

218
        if (info->tray_open && disk->src)
219 220 221 222 223 224
            VIR_FREE(disk->src);
    }

    ret = 0;

cleanup:
225
    virHashFree(table);
226 227 228
    return ret;
}

229

230 231
int qemuDomainAttachPciDiskDevice(virConnectPtr conn,
                                  struct qemud_driver *driver,
232
                                  virDomainObjPtr vm,
233
                                  virDomainDiskDefPtr disk)
234 235 236 237 238 239
{
    int i, ret;
    const char* type = virDomainDiskBusTypeToString(disk->bus);
    qemuDomainObjPrivatePtr priv = vm->privateData;
    char *devstr = NULL;
    char *drivestr = NULL;
240
    bool releaseaddr = false;
241 242 243

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (STREQ(vm->def->disks[i]->dst, disk->dst)) {
244 245
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("target %s already exists"), disk->dst);
246 247 248 249
            return -1;
        }
    }

250 251 252
    if (virDomainLockDiskAttach(driver->lockManager, vm, disk) < 0)
        return -1;

253
    if (virSecurityManagerSetImageLabel(driver->securityManager,
254
                                        vm->def, disk) < 0) {
255 256
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
257
        return -1;
258
    }
259

260
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
261 262
        if (qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, &disk->info) < 0)
            goto error;
263
        releaseaddr = true;
264
        if (qemuAssignDeviceDiskAlias(vm->def, disk, priv->caps) < 0)
265 266
            goto error;

267
        if (!(drivestr = qemuBuildDriveStr(conn, disk, false, priv->caps)))
268 269
            goto error;

270
        if (!(devstr = qemuBuildDriveDevStr(NULL, disk, 0, priv->caps)))
271 272 273 274 275 276 277 278
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0) {
        virReportOOMError();
        goto error;
    }

279
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
280
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
281 282 283 284
        ret = qemuMonitorAddDrive(priv->mon, drivestr);
        if (ret == 0) {
            ret = qemuMonitorAddDevice(priv->mon, devstr);
            if (ret < 0) {
285 286 287 288 289 290 291 292 293 294
                virErrorPtr orig_err = virSaveLastError();
                if (qemuMonitorDriveDel(priv->mon, drivestr) < 0) {
                    VIR_WARN("Unable to remove drive %s (%s) after failed "
                             "qemuMonitorAddDevice",
                             drivestr, devstr);
                }
                if (orig_err) {
                    virSetError(orig_err);
                    virFreeError(orig_err);
                }
295 296 297
            }
        }
    } else {
298
        virDevicePCIAddress guestAddr = disk->info.addr.pci;
299 300 301 302 303 304 305 306 307 308 309
        ret = qemuMonitorAddPCIDisk(priv->mon,
                                    disk->src,
                                    type,
                                    &guestAddr);
        if (ret == 0) {
            disk->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
            memcpy(&disk->info.addr.pci, &guestAddr, sizeof(guestAddr));
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

310
    virDomainAuditDisk(vm, NULL, disk->src, "attach", ret >= 0);
311 312 313 314 315 316 317 318 319 320 321 322 323 324 325

    if (ret < 0)
        goto error;

    virDomainDiskInsertPreAlloced(vm->def, disk);

    VIR_FREE(devstr);
    VIR_FREE(drivestr);

    return 0;

error:
    VIR_FREE(devstr);
    VIR_FREE(drivestr);

326
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
327
        (disk->info.type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
328
        releaseaddr &&
329 330
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        disk->info.addr.pci.slot) < 0)
331 332
        VIR_WARN("Unable to release PCI address on %s", disk->src);

333
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
334
                                            vm->def, disk) < 0)
335 336
        VIR_WARN("Unable to restore security label on %s", disk->src);

337 338 339
    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

340 341 342 343 344 345
    return -1;
}


int qemuDomainAttachPciControllerDevice(struct qemud_driver *driver,
                                        virDomainObjPtr vm,
346
                                        virDomainControllerDefPtr controller)
347 348 349 350 351
{
    int ret = -1;
    const char* type = virDomainControllerTypeToString(controller->type);
    char *devstr = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
352
    bool releaseaddr = false;
353

354 355 356 357 358
    if (virDomainControllerFind(vm->def, controller->type, controller->idx) > 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("target %s:%d already exists"),
                       type, controller->idx);
        return -1;
359 360
    }

361
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
362 363
        if (qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, &controller->info) < 0)
            goto cleanup;
364
        releaseaddr = true;
365 366 367
        if (qemuAssignDeviceControllerAlias(controller) < 0)
            goto cleanup;

368 369
        if (controller->type == VIR_DOMAIN_CONTROLLER_TYPE_USB &&
            controller->model == -1 &&
370
            !qemuCapsGet(priv->caps, QEMU_CAPS_PIIX3_USB_UHCI)) {
371 372
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                           _("USB controller hotplug unsupported in this QEMU binary"));
373 374 375
            goto cleanup;
        }

376
        if (!(devstr = qemuBuildControllerDevStr(vm->def, controller, priv->caps, NULL))) {
377 378 379 380 381 382 383 384 385
            goto cleanup;
        }
    }

    if (VIR_REALLOC_N(vm->def->controllers, vm->def->ncontrollers+1) < 0) {
        virReportOOMError();
        goto cleanup;
    }

386
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
387
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
388 389 390 391 392 393 394 395 396 397 398 399 400 401 402
        ret = qemuMonitorAddDevice(priv->mon, devstr);
    } else {
        ret = qemuMonitorAttachPCIDiskController(priv->mon,
                                                 type,
                                                 &controller->info.addr.pci);
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    if (ret == 0) {
        controller->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
        virDomainControllerInsertPreAlloced(vm->def, controller);
    }

cleanup:
    if ((ret != 0) &&
403
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
404
        (controller->info.type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
405
        releaseaddr &&
406 407
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        controller->info.addr.pci.slot) < 0)
408
        VIR_WARN("Unable to release PCI address on controller");
409 410 411 412 413 414 415 416 417

    VIR_FREE(devstr);
    return ret;
}


static virDomainControllerDefPtr
qemuDomainFindOrCreateSCSIDiskController(struct qemud_driver *driver,
                                         virDomainObjPtr vm,
418
                                         int controller)
419 420 421
{
    int i;
    virDomainControllerDefPtr cont;
422

423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439
    for (i = 0 ; i < vm->def->ncontrollers ; i++) {
        cont = vm->def->controllers[i];

        if (cont->type != VIR_DOMAIN_CONTROLLER_TYPE_SCSI)
            continue;

        if (cont->idx == controller)
            return cont;
    }

    /* No SCSI controller present, for backward compatibility we
     * now hotplug a controller */
    if (VIR_ALLOC(cont) < 0) {
        virReportOOMError();
        return NULL;
    }
    cont->type = VIR_DOMAIN_CONTROLLER_TYPE_SCSI;
440
    cont->idx = controller;
441 442
    cont->model = -1;

443
    VIR_INFO("No SCSI controller present, hotplugging one");
444
    if (qemuDomainAttachPciControllerDevice(driver,
445
                                            vm, cont) < 0) {
446 447 448 449 450
        VIR_FREE(cont);
        return NULL;
    }

    if (!virDomainObjIsActive(vm)) {
451 452
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("guest unexpectedly quit"));
453 454 455 456 457 458 459 460 461
        /* cont doesn't need freeing here, since the reference
         * now held in def->controllers */
        return NULL;
    }

    return cont;
}


462 463
int qemuDomainAttachSCSIDisk(virConnectPtr conn,
                             struct qemud_driver *driver,
464
                             virDomainObjPtr vm,
465
                             virDomainDiskDefPtr disk)
466 467 468 469 470 471 472 473 474 475
{
    int i;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    virDomainControllerDefPtr cont = NULL;
    char *drivestr = NULL;
    char *devstr = NULL;
    int ret = -1;

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (STREQ(vm->def->disks[i]->dst, disk->dst)) {
476 477
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("target %s already exists"), disk->dst);
478 479 480 481
            return -1;
        }
    }

482 483
    if (virDomainLockDiskAttach(driver->lockManager, vm, disk) < 0)
        return -1;
484

485
    if (virSecurityManagerSetImageLabel(driver->securityManager,
486
                                        vm->def, disk) < 0) {
487 488
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
489
        return -1;
490
    }
491 492 493

    /* We should have an address already, so make sure */
    if (disk->info.type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_DRIVE) {
494 495 496
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unexpected disk address type %s"),
                       virDomainDeviceAddressTypeToString(disk->info.type));
497 498 499
        goto error;
    }

500 501
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (qemuAssignDeviceDiskAlias(vm->def, disk, priv->caps) < 0)
502
            goto error;
503
        if (!(devstr = qemuBuildDriveDevStr(vm->def, disk, 0, priv->caps)))
504 505 506
            goto error;
    }

507
    if (!(drivestr = qemuBuildDriveStr(conn, disk, false, priv->caps)))
508 509 510
        goto error;

    for (i = 0 ; i <= disk->info.addr.drive.controller ; i++) {
511
        cont = qemuDomainFindOrCreateSCSIDiskController(driver, vm, i);
512 513 514 515 516 517 518 519 520 521
        if (!cont)
            goto error;
    }

    /* Tell clang that "cont" is non-NULL.
       This is because disk->info.addr.driver.controller is unsigned,
       and hence the above loop must iterate at least once.  */
    sa_assert (cont);

    if (cont->info.type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) {
522 523
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("SCSI controller %d was missing its PCI address"), cont->idx);
524 525 526 527 528 529 530 531
        goto error;
    }

    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0) {
        virReportOOMError();
        goto error;
    }

532
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
533
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553
        ret = qemuMonitorAddDrive(priv->mon, drivestr);
        if (ret == 0) {
            ret = qemuMonitorAddDevice(priv->mon, devstr);
            if (ret < 0) {
                VIR_WARN("qemuMonitorAddDevice failed on %s (%s)",
                         drivestr, devstr);
                /* XXX should call 'drive_del' on error but this does not
                   exist yet */
            }
        }
    } else {
        virDomainDeviceDriveAddress driveAddr;
        ret = qemuMonitorAttachDrive(priv->mon,
                                     drivestr,
                                     &cont->info.addr.pci,
                                     &driveAddr);
        if (ret == 0) {
            /* XXX we should probably validate that the addr matches
             * our existing defined addr instead of overwriting */
            disk->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_DRIVE;
554 555
            disk->info.addr.drive.bus = driveAddr.bus;
            disk->info.addr.drive.unit = driveAddr.unit;
556 557 558 559
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

560
    virDomainAuditDisk(vm, NULL, disk->src, "attach", ret >= 0);
561 562 563 564 565 566 567 568 569 570 571 572 573 574 575

    if (ret < 0)
        goto error;

    virDomainDiskInsertPreAlloced(vm->def, disk);

    VIR_FREE(devstr);
    VIR_FREE(drivestr);

    return 0;

error:
    VIR_FREE(devstr);
    VIR_FREE(drivestr);

576
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
577
                                            vm->def, disk) < 0)
578 579
        VIR_WARN("Unable to restore security label on %s", disk->src);

580 581 582
    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

583 584 585 586
    return -1;
}


587 588
int qemuDomainAttachUsbMassstorageDevice(virConnectPtr conn,
                                         struct qemud_driver *driver,
589
                                         virDomainObjPtr vm,
590
                                         virDomainDiskDefPtr disk)
591 592 593 594 595 596 597 598
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    int i, ret;
    char *drivestr = NULL;
    char *devstr = NULL;

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (STREQ(vm->def->disks[i]->dst, disk->dst)) {
599 600
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("target %s already exists"), disk->dst);
601 602 603 604
            return -1;
        }
    }

605 606 607
    if (virDomainLockDiskAttach(driver->lockManager, vm, disk) < 0)
        return -1;

608
    if (virSecurityManagerSetImageLabel(driver->securityManager,
609
                                        vm->def, disk) < 0) {
610 611
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
612
        return -1;
613
    }
614

615
    /* XXX not correct once we allow attaching a USB CDROM */
616
    if (!disk->src) {
617 618
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       "%s", _("disk source path is missing"));
619 620 621
        goto error;
    }

622 623
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (qemuAssignDeviceDiskAlias(vm->def, disk, priv->caps) < 0)
624
            goto error;
625
        if (!(drivestr = qemuBuildDriveStr(conn, disk, false, priv->caps)))
626
            goto error;
627
        if (!(devstr = qemuBuildDriveDevStr(NULL, disk, 0, priv->caps)))
628 629 630 631 632 633 634 635
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0) {
        virReportOOMError();
        goto error;
    }

636
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
637
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
638 639 640 641 642 643 644 645 646 647 648 649 650 651 652
        ret = qemuMonitorAddDrive(priv->mon, drivestr);
        if (ret == 0) {
            ret = qemuMonitorAddDevice(priv->mon, devstr);
            if (ret < 0) {
                VIR_WARN("qemuMonitorAddDevice failed on %s (%s)",
                         drivestr, devstr);
                /* XXX should call 'drive_del' on error but this does not
                   exist yet */
            }
        }
    } else {
        ret = qemuMonitorAddUSBDisk(priv->mon, disk->src);
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

653
    virDomainAuditDisk(vm, NULL, disk->src, "attach", ret >= 0);
654 655 656 657 658 659 660 661 662 663 664 665 666 667 668

    if (ret < 0)
        goto error;

    virDomainDiskInsertPreAlloced(vm->def, disk);

    VIR_FREE(devstr);
    VIR_FREE(drivestr);

    return 0;

error:
    VIR_FREE(devstr);
    VIR_FREE(drivestr);

669
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
670
                                            vm->def, disk) < 0)
671 672
        VIR_WARN("Unable to restore security label on %s", disk->src);

673 674 675
    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

676 677 678 679 680 681 682 683
    return -1;
}


/* XXX conn required for network -> bridge resolution */
int qemuDomainAttachNetDevice(virConnectPtr conn,
                              struct qemud_driver *driver,
                              virDomainObjPtr vm,
684
                              virDomainNetDefPtr net)
685 686 687 688
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    char *tapfd_name = NULL;
    int tapfd = -1;
689 690
    char *vhostfd_name = NULL;
    int vhostfd = -1;
691 692
    char *nicstr = NULL;
    char *netstr = NULL;
A
Ansis Atteka 已提交
693
    virNetDevVPortProfilePtr vport = NULL;
694
    int ret = -1;
695
    virDevicePCIAddress guestAddr;
696
    int vlan;
697
    bool releaseaddr = false;
698 699
    bool iface_connected = false;
    int actualType;
700

701 702 703
    /* preallocate new slot for device */
    if (VIR_REALLOC_N(vm->def->nets, vm->def->nnets+1) < 0) {
        virReportOOMError();
704 705 706
        return -1;
    }

707 708 709 710 711
    /* If appropriate, grab a physical device from the configured
     * network's pool of devices, or resolve bridge device name
     * to the one defined in the network definition.
     */
    if (networkAllocateActualDevice(net) < 0)
712
        return -1;
713 714

    actualType = virDomainNetGetActualType(net);
715 716 717 718 719 720 721 722 723 724 725 726

    if (actualType == VIR_DOMAIN_NET_TYPE_HOSTDEV) {
        /* This is really a "smart hostdev", so it should be attached
         * as a hostdev (the hostdev code will reach over into the
         * netdev-specific code as appropriate), then also added to
         * the nets list (see cleanup:) if successful.
         */
        ret = qemuDomainAttachHostDevice(driver, vm,
                                         virDomainNetGetActualHostdev(net));
        goto cleanup;
    }

727
    if (!qemuCapsGet(priv->caps, QEMU_CAPS_HOST_NET_ADD)) {
728 729
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("installed qemu version does not support host_net_add"));
730 731 732
        goto cleanup;
    }

733 734
    if (actualType == VIR_DOMAIN_NET_TYPE_BRIDGE ||
        actualType == VIR_DOMAIN_NET_TYPE_NETWORK) {
R
Richa Marwaha 已提交
735 736 737 738 739 740 741
        /*
         * If type=bridge then we attempt to allocate the tap fd here only if
         * running under a privilged user or -netdev bridge option is not
         * supported.
         */
        if (actualType == VIR_DOMAIN_NET_TYPE_NETWORK ||
            driver->privileged ||
742
            (!qemuCapsGet (priv->caps, QEMU_CAPS_NETDEV_BRIDGE))) {
R
Richa Marwaha 已提交
743
            if ((tapfd = qemuNetworkIfaceConnect(vm->def, conn, driver, net,
744
                                                 priv->caps)) < 0)
R
Richa Marwaha 已提交
745 746
                goto cleanup;
            iface_connected = true;
747
            if (qemuOpenVhostNet(vm->def, net, priv->caps, &vhostfd) < 0)
R
Richa Marwaha 已提交
748 749
                goto cleanup;
        }
750
    } else if (actualType == VIR_DOMAIN_NET_TYPE_DIRECT) {
751
        if ((tapfd = qemuPhysIfaceConnect(vm->def, driver, net,
752
                                          priv->caps,
753
                                          VIR_NETDEV_VPORT_PROFILE_OP_CREATE)) < 0)
754 755
            goto cleanup;
        iface_connected = true;
756
        if (qemuOpenVhostNet(vm->def, net, priv->caps, &vhostfd) < 0)
757
            goto cleanup;
758 759
    }

760 761
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NET_NAME) ||
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
762 763 764 765
        if (qemuAssignDeviceNetAlias(vm->def, net, -1) < 0)
            goto cleanup;
    }

766
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
767 768 769
        qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, &net->info) < 0)
        goto cleanup;

770 771
    releaseaddr = true;

772 773
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
774 775 776 777 778
        vlan = -1;
    } else {
        vlan = qemuDomainNetVLAN(net);

        if (vlan < 0) {
779 780
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                           _("Unable to attach network devices without vlan"));
781 782 783 784 785 786 787 788 789
            goto cleanup;
        }
    }

    if (tapfd != -1) {
        if (virAsprintf(&tapfd_name, "fd-%s", net->info.alias) < 0)
            goto no_memory;
    }

790 791 792 793 794
    if (vhostfd != -1) {
        if (virAsprintf(&vhostfd_name, "vhostfd-%s", net->info.alias) < 0)
            goto no_memory;
    }

795 796 797
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (!(netstr = qemuBuildHostNetStr(net, driver, priv->caps,
R
Richa Marwaha 已提交
798 799
                                           ',', -1, tapfd_name,
                                           vhostfd_name)))
800
            goto cleanup;
801
    } else {
802
        if (!(netstr = qemuBuildHostNetStr(net, driver, priv->caps,
R
Richa Marwaha 已提交
803 804
                                           ' ', vlan, tapfd_name,
                                           vhostfd_name)))
805
            goto cleanup;
806 807
    }

808
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
809 810
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
811 812
        if (qemuMonitorAddNetdev(priv->mon, netstr, tapfd, tapfd_name,
                                 vhostfd, vhostfd_name) < 0) {
813
            qemuDomainObjExitMonitorWithDriver(driver, vm);
814
            virDomainAuditNet(vm, NULL, net, "attach", false);
815
            goto cleanup;
816 817
        }
    } else {
818 819
        if (qemuMonitorAddHostNetwork(priv->mon, netstr, tapfd, tapfd_name,
                                      vhostfd, vhostfd_name) < 0) {
820
            qemuDomainObjExitMonitorWithDriver(driver, vm);
821
            virDomainAuditNet(vm, NULL, net, "attach", false);
822
            goto cleanup;
823 824 825 826 827
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    VIR_FORCE_CLOSE(tapfd);
828
    VIR_FORCE_CLOSE(vhostfd);
829 830

    if (!virDomainObjIsActive(vm)) {
831 832
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("guest unexpectedly quit"));
833 834 835
        goto cleanup;
    }

836 837
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (!(nicstr = qemuBuildNicDevStr(net, vlan, 0, priv->caps)))
838 839 840 841 842 843
            goto try_remove;
    } else {
        if (!(nicstr = qemuBuildNicStr(net, NULL, vlan)))
            goto try_remove;
    }

844
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
845
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
846 847
        if (qemuMonitorAddDevice(priv->mon, nicstr) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
848
            virDomainAuditNet(vm, NULL, net, "attach", false);
849 850 851
            goto try_remove;
        }
    } else {
852
        guestAddr = net->info.addr.pci;
853 854 855
        if (qemuMonitorAddPCINetwork(priv->mon, nicstr,
                                     &guestAddr) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
856
            virDomainAuditNet(vm, NULL, net, "attach", false);
857 858 859 860 861 862 863
            goto try_remove;
        }
        net->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
        memcpy(&net->info.addr.pci, &guestAddr, sizeof(guestAddr));
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

864 865 866
    /* set link state */
    if (net->linkstate == VIR_DOMAIN_NET_INTERFACE_LINK_STATE_DOWN) {
        if (!net->info.alias) {
867 868
            virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                           _("device alias not found: cannot set link state to down"));
869 870 871
        } else {
            qemuDomainObjEnterMonitorWithDriver(driver, vm);

872
            if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV)) {
873 874 875 876 877 878
                if (qemuMonitorSetLink(priv->mon, net->info.alias, VIR_DOMAIN_NET_INTERFACE_LINK_STATE_DOWN) < 0) {
                    qemuDomainObjExitMonitorWithDriver(driver, vm);
                    virDomainAuditNet(vm, NULL, net, "attach", false);
                    goto try_remove;
                }
            } else {
879
                virReportError(VIR_ERR_OPERATION_FAILED, "%s",
880
                               _("setting of link state not supported: Link is up"));
881 882 883 884 885 886 887
            }

            qemuDomainObjExitMonitorWithDriver(driver, vm);
        }
        /* link set to down */
    }

888
    virDomainAuditNet(vm, NULL, net, "attach", true);
889 890 891 892

    ret = 0;

cleanup:
893 894 895
    if (!ret) {
        vm->def->nets[vm->def->nnets++] = net;
    } else {
896
        if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
897 898 899 900 901 902
            (net->info.type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
            releaseaddr &&
            qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                            net->info.addr.pci.slot) < 0)
            VIR_WARN("Unable to release PCI address on NIC");

903
        if (iface_connected) {
904
            virDomainConfNWFilterTeardown(net);
905

906 907 908 909 910
            vport = virDomainNetGetActualVirtPortProfile(net);
            if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
               ignore_value(virNetDevOpenvswitchRemovePort(
                               virDomainNetGetActualBridgeName(net), net->ifname));
        }
A
Ansis Atteka 已提交
911

912 913
        networkReleaseActualDevice(net);
    }
914 915 916 917 918

    VIR_FREE(nicstr);
    VIR_FREE(netstr);
    VIR_FREE(tapfd_name);
    VIR_FORCE_CLOSE(tapfd);
919 920
    VIR_FREE(vhostfd_name);
    VIR_FORCE_CLOSE(vhostfd);
921 922 923 924 925 926 927 928

    return ret;

try_remove:
    if (!virDomainObjIsActive(vm))
        goto cleanup;

    if (vlan < 0) {
929 930
        if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
            qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
931 932 933
            char *netdev_name;
            if (virAsprintf(&netdev_name, "host%s", net->info.alias) < 0)
                goto no_memory;
934
            qemuDomainObjEnterMonitorWithDriver(driver, vm);
935 936 937 938 939 940
            if (qemuMonitorRemoveNetdev(priv->mon, netdev_name) < 0)
                VIR_WARN("Failed to remove network backend for netdev %s",
                         netdev_name);
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            VIR_FREE(netdev_name);
        } else {
941
            VIR_WARN("Unable to remove network backend");
942 943 944 945 946
        }
    } else {
        char *hostnet_name;
        if (virAsprintf(&hostnet_name, "host%s", net->info.alias) < 0)
            goto no_memory;
947
        qemuDomainObjEnterMonitorWithDriver(driver, vm);
948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963
        if (qemuMonitorRemoveHostNetwork(priv->mon, vlan, hostnet_name) < 0)
            VIR_WARN("Failed to remove network backend for vlan %d, net %s",
                     vlan, hostnet_name);
        qemuDomainObjExitMonitorWithDriver(driver, vm);
        VIR_FREE(hostnet_name);
    }
    goto cleanup;

no_memory:
    virReportOOMError();
    goto cleanup;
}


int qemuDomainAttachHostPciDevice(struct qemud_driver *driver,
                                  virDomainObjPtr vm,
964
                                  virDomainHostdevDefPtr hostdev)
965 966 967 968 969 970
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    int ret;
    char *devstr = NULL;
    int configfd = -1;
    char *configfd_name = NULL;
971
    bool releaseaddr = false;
972 973 974 975 976 977

    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0) {
        virReportOOMError();
        return -1;
    }

978 979
    if (qemuPrepareHostdevPCIDevices(driver, vm->def->name, vm->def->uuid,
                                     &hostdev, 1) < 0)
980 981
        return -1;

982
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
983 984
        if (qemuAssignDeviceHostdevAlias(vm->def, hostdev, -1) < 0)
            goto error;
985
        if (qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, hostdev->info) < 0)
986
            goto error;
987
        releaseaddr = true;
988
        if (qemuCapsGet(priv->caps, QEMU_CAPS_PCI_CONFIGFD)) {
989 990 991
            configfd = qemuOpenPCIConfig(hostdev);
            if (configfd >= 0) {
                if (virAsprintf(&configfd_name, "fd-%s",
992
                                hostdev->info->alias) < 0) {
993 994 995 996 997 998 999
                    virReportOOMError();
                    goto error;
                }
            }
        }

        if (!virDomainObjIsActive(vm)) {
1000 1001
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("guest unexpectedly quit during hotplug"));
1002 1003 1004
            goto error;
        }

1005
        if (!(devstr = qemuBuildPCIHostdevDevStr(hostdev, configfd_name,
1006
                                                 priv->caps)))
1007 1008
            goto error;

1009
        qemuDomainObjEnterMonitorWithDriver(driver, vm);
1010 1011
        ret = qemuMonitorAddDeviceWithFd(priv->mon, devstr,
                                         configfd, configfd_name);
1012 1013
        qemuDomainObjExitMonitorWithDriver(driver, vm);
    } else {
1014
        virDevicePCIAddress guestAddr = hostdev->info->addr.pci;
1015

1016
        qemuDomainObjEnterMonitorWithDriver(driver, vm);
1017 1018 1019 1020 1021
        ret = qemuMonitorAddPCIHostDevice(priv->mon,
                                          &hostdev->source.subsys.u.pci,
                                          &guestAddr);
        qemuDomainObjExitMonitorWithDriver(driver, vm);

1022 1023
        hostdev->info->type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
        memcpy(&hostdev->info->addr.pci, &guestAddr, sizeof(guestAddr));
1024
    }
1025
    virDomainAuditHostdev(vm, hostdev, "attach", ret == 0);
1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037
    if (ret < 0)
        goto error;

    vm->def->hostdevs[vm->def->nhostdevs++] = hostdev;

    VIR_FREE(devstr);
    VIR_FREE(configfd_name);
    VIR_FORCE_CLOSE(configfd);

    return 0;

error:
1038
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
1039
        (hostdev->info->type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
1040
        releaseaddr &&
1041
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
1042
                                        hostdev->info->addr.pci.slot) < 0)
1043
        VIR_WARN("Unable to release PCI address on host device");
1044

1045
    qemuDomainReAttachHostdevDevices(driver, vm->def->name, &hostdev, 1);
1046 1047 1048 1049 1050 1051 1052 1053 1054

    VIR_FREE(devstr);
    VIR_FREE(configfd_name);
    VIR_FORCE_CLOSE(configfd);

    return -1;
}


1055 1056 1057 1058 1059 1060
int qemuDomainAttachRedirdevDevice(struct qemud_driver *driver,
                                   virDomainObjPtr vm,
                                   virDomainRedirdevDefPtr redirdev)
{
    int ret;
    qemuDomainObjPrivatePtr priv = vm->privateData;
1061
    virDomainDefPtr def = vm->def;
1062 1063
    char *devstr = NULL;

1064
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1065 1066
        if (qemuAssignDeviceRedirdevAlias(vm->def, redirdev, -1) < 0)
            goto error;
1067
        if (!(devstr = qemuBuildRedirdevDevStr(def, redirdev, priv->caps)))
1068 1069 1070 1071 1072 1073 1074 1075 1076
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->redirdevs, vm->def->nredirdevs+1) < 0) {
        virReportOOMError();
        goto error;
    }

    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1077
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE))
1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098
        ret = qemuMonitorAddDevice(priv->mon, devstr);
    else
        goto error;

    qemuDomainObjExitMonitorWithDriver(driver, vm);
    virDomainAuditRedirdev(vm, redirdev, "attach", ret == 0);
    if (ret < 0)
        goto error;

    vm->def->redirdevs[vm->def->nredirdevs++] = redirdev;

    VIR_FREE(devstr);

    return 0;

error:
    VIR_FREE(devstr);
    return -1;

}

1099 1100
int qemuDomainAttachHostUsbDevice(struct qemud_driver *driver,
                                  virDomainObjPtr vm,
1101
                                  virDomainHostdevDefPtr hostdev)
1102 1103 1104 1105 1106
{
    int ret;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    char *devstr = NULL;

1107
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1108 1109
        if (qemuAssignDeviceHostdevAlias(vm->def, hostdev, -1) < 0)
            goto error;
1110
        if (!(devstr = qemuBuildUSBHostdevDevStr(hostdev, priv->caps)))
1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0) {
        virReportOOMError();
        goto error;
    }

    if (qemuCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virCgroupPtr cgroup = NULL;
        usbDevice *usb;
1122
        qemuCgroupData data;
1123 1124

        if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) !=0 ) {
1125 1126 1127
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unable to find cgroup for %s"),
                           vm->def->name);
1128 1129 1130 1131 1132 1133 1134
            goto error;
        }

        if ((usb = usbGetDevice(hostdev->source.subsys.u.usb.bus,
                                hostdev->source.subsys.u.usb.device)) == NULL)
            goto error;

1135 1136
        data.vm = vm;
        data.cgroup = cgroup;
1137
        if (usbDeviceFileIterate(usb, qemuSetupHostUsbDeviceCgroup, &data) < 0)
1138 1139 1140
            goto error;
    }

1141
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1142
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE))
1143 1144 1145 1146 1147 1148
        ret = qemuMonitorAddDevice(priv->mon, devstr);
    else
        ret = qemuMonitorAddUSBDeviceExact(priv->mon,
                                           hostdev->source.subsys.u.usb.bus,
                                           hostdev->source.subsys.u.usb.device);
    qemuDomainObjExitMonitorWithDriver(driver, vm);
1149
    virDomainAuditHostdev(vm, hostdev, "attach", ret == 0);
1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165
    if (ret < 0)
        goto error;

    vm->def->hostdevs[vm->def->nhostdevs++] = hostdev;

    VIR_FREE(devstr);

    return 0;

error:
    VIR_FREE(devstr);
    return -1;
}

int qemuDomainAttachHostDevice(struct qemud_driver *driver,
                               virDomainObjPtr vm,
1166
                               virDomainHostdevDefPtr hostdev)
1167
{
1168 1169 1170
    usbDeviceList *list;
    usbDevice *usb = NULL;

1171
    if (hostdev->mode != VIR_DOMAIN_HOSTDEV_MODE_SUBSYS) {
1172 1173 1174
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev mode '%s' not supported"),
                       virDomainHostdevModeTypeToString(hostdev->mode));
1175 1176 1177
        return -1;
    }

1178 1179
    if (!(list = usbDeviceListNew()))
        goto cleanup;
1180

1181 1182 1183 1184 1185
    if (hostdev->source.subsys.type == VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB) {
        unsigned vendor = hostdev->source.subsys.u.usb.vendor;
        unsigned product = hostdev->source.subsys.u.usb.product;
        unsigned bus = hostdev->source.subsys.u.usb.bus;
        unsigned device = hostdev->source.subsys.u.usb.device;
1186

1187 1188
        if (vendor && bus) {
            usb = usbFindDevice(vendor, product, bus, device);
1189

1190 1191 1192 1193
        } else if (vendor && !bus) {
            usbDeviceList *devs = usbFindDeviceByVendor(vendor, product);
            if (!devs)
                goto cleanup;
1194

1195
            if (usbDeviceListCount(devs) > 1) {
1196 1197 1198
                virReportError(VIR_ERR_OPERATION_FAILED,
                               _("multiple USB devices for %x:%x, "
                                 "use <address> to specify one"), vendor, product);
1199 1200 1201 1202 1203 1204
                usbDeviceListFree(devs);
                goto cleanup;
            }
            usb = usbDeviceListGet(devs, 0);
            usbDeviceListSteal(devs, usb);
            usbDeviceListFree(devs);
1205

1206 1207
            hostdev->source.subsys.u.usb.bus = usbDeviceGetBus(usb);
            hostdev->source.subsys.u.usb.device = usbDeviceGetDevno(usb);
1208

1209 1210 1211
        } else if (!vendor && bus) {
            usb = usbFindDeviceByBus(bus, device);
        }
1212

1213 1214 1215 1216 1217
        if (!usb)
            goto cleanup;

        if (usbDeviceListAdd(list, usb) < 0) {
            usbFreeDevice(usb);
M
Marc-André Lureau 已提交
1218
            usb = NULL;
1219 1220 1221
            goto cleanup;
        }

1222 1223
        if (qemuPrepareHostdevUSBDevices(driver, vm->def->name, list) < 0) {
            usb = NULL;
1224
            goto cleanup;
1225
        }
1226 1227 1228

        usbDeviceListSteal(list, usb);
    }
1229

1230
    if (virSecurityManagerSetHostdevLabel(driver->securityManager,
1231
                                          vm->def, hostdev) < 0)
1232
        goto cleanup;
1233 1234 1235 1236

    switch (hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI:
        if (qemuDomainAttachHostPciDevice(driver, vm,
1237
                                          hostdev) < 0)
1238 1239 1240 1241 1242
            goto error;
        break;

    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        if (qemuDomainAttachHostUsbDevice(driver, vm,
1243
                                          hostdev) < 0)
1244 1245 1246 1247
            goto error;
        break;

    default:
1248 1249 1250
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev subsys type '%s' not supported"),
                       virDomainHostdevSubsysTypeToString(hostdev->source.subsys.type));
1251 1252 1253
        goto error;
    }

1254
    usbDeviceListFree(list);
1255 1256 1257
    return 0;

error:
1258
    if (virSecurityManagerRestoreHostdevLabel(driver->securityManager,
1259
                                              vm->def, hostdev) < 0)
1260
        VIR_WARN("Unable to restore host device labelling on hotplug fail");
1261

1262 1263
cleanup:
    usbDeviceListFree(list);
1264 1265
    if (usb)
        usbDeviceListSteal(driver->activeUsbHostdevs, usb);
1266 1267 1268
    return -1;
}

1269 1270 1271 1272 1273 1274
static virDomainNetDefPtr qemuDomainFindNet(virDomainObjPtr vm,
                                            virDomainNetDefPtr dev)
{
    int i;

    for (i = 0; i < vm->def->nnets; i++) {
1275
        if (virMacAddrCmp(&vm->def->nets[i]->mac, &dev->mac) == 0)
1276 1277 1278 1279 1280 1281
            return vm->def->nets[i];
    }

    return NULL;
}

1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294
static
int qemuDomainChangeNetBridge(virDomainObjPtr vm,
                              virDomainNetDefPtr olddev,
                              virDomainNetDefPtr newdev)
{
    int ret = -1;
    char *oldbridge = olddev->data.bridge.brname;
    char *newbridge = newdev->data.bridge.brname;

    VIR_DEBUG("Change bridge for interface %s: %s -> %s",
              olddev->ifname, oldbridge, newbridge);

    if (virNetDevExists(newbridge) != 1) {
1295 1296
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("bridge %s doesn't exist"), newbridge);
1297 1298 1299 1300 1301 1302 1303 1304 1305 1306 1307 1308 1309 1310 1311 1312 1313 1314 1315 1316
        return -1;
    }

    if (oldbridge) {
        ret = virNetDevBridgeRemovePort(oldbridge, olddev->ifname);
        virDomainAuditNet(vm, olddev, NULL, "detach", ret == 0);
        if (ret < 0)
            return -1;
    }

    /* move newbridge into olddev now so Audit log is correct */
    olddev->data.bridge.brname = newbridge;
    ret = virNetDevBridgeAddPort(newbridge, olddev->ifname);
    virDomainAuditNet(vm, NULL, olddev, "attach", ret == 0);
    if (ret < 0) {
        /* restore oldbridge to olddev */
        olddev->data.bridge.brname = oldbridge;
        ret = virNetDevBridgeAddPort(oldbridge, olddev->ifname);
        virDomainAuditNet(vm, NULL, olddev, "attach", ret == 0);
        if (ret < 0) {
1317
            virReportError(VIR_ERR_OPERATION_FAILED,
1318
                           _("unable to recover former state by adding port "
1319
                             "to bridge %s"), oldbridge);
1320 1321 1322 1323 1324 1325 1326 1327 1328
        }
        return -1;
    }
    /* oldbridge no longer needed, and newbridge moved to olddev */
    VIR_FREE(oldbridge);
    newdev->data.bridge.brname = NULL;
    return 0;
}

1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339
int qemuDomainChangeNetLinkState(struct qemud_driver *driver,
                                 virDomainObjPtr vm,
                                 virDomainNetDefPtr dev,
                                 int linkstate)
{
    int ret = -1;
    qemuDomainObjPrivatePtr priv = vm->privateData;

    VIR_DEBUG("dev: %s, state: %d", dev->info.alias, linkstate);

    if (!dev->info.alias) {
1340 1341
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("can't change link state: device alias not found"));
1342 1343 1344 1345 1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364 1365 1366 1367 1368 1369
        return -1;
    }

    qemuDomainObjEnterMonitorWithDriver(driver, vm);

    ret = qemuMonitorSetLink(priv->mon, dev->info.alias, linkstate);
    if (ret < 0)
        goto cleanup;

    /* modify the device configuration */
    dev->linkstate = linkstate;

cleanup:
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    return ret;
}

int qemuDomainChangeNet(struct qemud_driver *driver,
                        virDomainObjPtr vm,
                        virDomainPtr dom ATTRIBUTE_UNUSED,
                        virDomainNetDefPtr dev)

{
    virDomainNetDefPtr olddev = qemuDomainFindNet(vm, dev);
    int ret = 0;

    if (!olddev) {
1370 1371
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot find existing network device to modify"));
1372 1373 1374 1375
        return -1;
    }

    if (olddev->type != dev->type) {
1376 1377
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot change network interface type"));
1378 1379 1380
        return -1;
    }

1381 1382 1383 1384 1385
    if (!virNetDevVPortProfileEqual(olddev->virtPortProfile, dev->virtPortProfile)) {
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot change <virtualport> settings"));
    }

1386 1387 1388 1389 1390 1391
    switch (olddev->type) {
    case VIR_DOMAIN_NET_TYPE_USER:
        break;

    case VIR_DOMAIN_NET_TYPE_ETHERNET:
        if (STRNEQ_NULLABLE(olddev->data.ethernet.dev, dev->data.ethernet.dev) ||
1392
            STRNEQ_NULLABLE(olddev->script, dev->script) ||
1393
            STRNEQ_NULLABLE(olddev->data.ethernet.ipaddr, dev->data.ethernet.ipaddr)) {
1394 1395
            virReportError(VIR_ERR_NO_SUPPORT, "%s",
                           _("cannot modify ethernet network device configuration"));
1396 1397 1398 1399 1400 1401 1402 1403 1404
            return -1;
        }
        break;

    case VIR_DOMAIN_NET_TYPE_SERVER:
    case VIR_DOMAIN_NET_TYPE_CLIENT:
    case VIR_DOMAIN_NET_TYPE_MCAST:
        if (STRNEQ_NULLABLE(olddev->data.socket.address, dev->data.socket.address) ||
            olddev->data.socket.port != dev->data.socket.port) {
1405 1406
            virReportError(VIR_ERR_NO_SUPPORT, "%s",
                           _("cannot modify network socket device configuration"));
1407 1408 1409 1410 1411 1412
            return -1;
        }
        break;

    case VIR_DOMAIN_NET_TYPE_NETWORK:
        if (STRNEQ_NULLABLE(olddev->data.network.name, dev->data.network.name) ||
1413
            STRNEQ_NULLABLE(olddev->data.network.portgroup, dev->data.network.portgroup)) {
1414 1415
            virReportError(VIR_ERR_NO_SUPPORT, "%s",
                           _("cannot modify network device configuration"));
1416 1417 1418 1419 1420
            return -1;
        }

        break;

1421
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
1422
       /* allow changing brname */
1423 1424
       break;

1425 1426
    case VIR_DOMAIN_NET_TYPE_INTERNAL:
        if (STRNEQ_NULLABLE(olddev->data.internal.name, dev->data.internal.name)) {
1427 1428
            virReportError(VIR_ERR_NO_SUPPORT, "%s",
                           _("cannot modify internal network device configuration"));
1429 1430 1431 1432 1433 1434
            return -1;
        }
        break;

    case VIR_DOMAIN_NET_TYPE_DIRECT:
        if (STRNEQ_NULLABLE(olddev->data.direct.linkdev, dev->data.direct.linkdev) ||
1435
            olddev->data.direct.mode != dev->data.direct.mode) {
1436 1437
            virReportError(VIR_ERR_NO_SUPPORT, "%s",
                           _("cannot modify direct network device configuration"));
1438 1439 1440 1441 1442
            return -1;
        }
        break;

    default:
1443 1444 1445
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unable to change config on '%s' network type"),
                       virDomainNetTypeToString(dev->type));
1446 1447 1448 1449 1450 1451 1452
        break;

    }

    /* all other unmodifiable parameters */
    if (STRNEQ_NULLABLE(olddev->model, dev->model) ||
        STRNEQ_NULLABLE(olddev->filter, dev->filter)) {
1453 1454
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot modify network device configuration"));
1455 1456 1457 1458 1459 1460
        return -1;
    }

    /* check if device name has been set, if no, retain the autogenerated one */
    if (dev->ifname &&
        STRNEQ_NULLABLE(olddev->ifname, dev->ifname)) {
1461 1462
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot modify network device configuration"));
1463 1464 1465
        return -1;
    }

1466 1467 1468 1469 1470 1471 1472
    if (olddev->type == VIR_DOMAIN_NET_TYPE_BRIDGE
        && STRNEQ_NULLABLE(olddev->data.bridge.brname,
                           dev->data.bridge.brname)) {
        if ((ret = qemuDomainChangeNetBridge(vm, olddev, dev)) < 0)
            return ret;
    }

1473 1474 1475 1476 1477 1478 1479 1480 1481
    if (olddev->linkstate != dev->linkstate) {
        if ((ret = qemuDomainChangeNetLinkState(driver, vm, olddev, dev->linkstate)) < 0)
            return ret;
    }

    return ret;
}


1482 1483 1484 1485 1486 1487 1488 1489 1490 1491 1492 1493 1494 1495 1496 1497 1498 1499 1500 1501 1502

static virDomainGraphicsDefPtr qemuDomainFindGraphics(virDomainObjPtr vm,
                                                      virDomainGraphicsDefPtr dev)
{
    int i;

    for (i = 0 ; i < vm->def->ngraphics ; i++) {
        if (vm->def->graphics[i]->type == dev->type)
            return vm->def->graphics[i];
    }

    return NULL;
}


int
qemuDomainChangeGraphics(struct qemud_driver *driver,
                         virDomainObjPtr vm,
                         virDomainGraphicsDefPtr dev)
{
    virDomainGraphicsDefPtr olddev = qemuDomainFindGraphics(vm, dev);
1503
    const char *oldListenAddr, *newListenAddr;
1504
    const char *oldListenNetwork, *newListenNetwork;
1505 1506 1507
    int ret = -1;

    if (!olddev) {
1508 1509
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("cannot find existing graphics device to modify"));
1510 1511 1512
        return -1;
    }

1513 1514
    oldListenAddr = virDomainGraphicsListenGetAddress(olddev, 0);
    newListenAddr = virDomainGraphicsListenGetAddress(dev, 0);
1515 1516
    oldListenNetwork = virDomainGraphicsListenGetNetwork(olddev, 0);
    newListenNetwork = virDomainGraphicsListenGetNetwork(dev, 0);
1517

1518 1519 1520
    switch (dev->type) {
    case VIR_DOMAIN_GRAPHICS_TYPE_VNC:
        if ((olddev->data.vnc.autoport != dev->data.vnc.autoport) ||
E
Eric Blake 已提交
1521 1522
            (!dev->data.vnc.autoport &&
             (olddev->data.vnc.port != dev->data.vnc.port))) {
1523 1524
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change port settings on vnc graphics"));
1525 1526
            return -1;
        }
1527
        if (STRNEQ_NULLABLE(oldListenAddr,newListenAddr)) {
1528 1529
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen address setting on vnc graphics"));
1530 1531
            return -1;
        }
1532
        if (STRNEQ_NULLABLE(oldListenNetwork,newListenNetwork)) {
1533 1534
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen network setting on vnc graphics"));
1535 1536
            return -1;
        }
1537
        if (STRNEQ_NULLABLE(olddev->data.vnc.keymap, dev->data.vnc.keymap)) {
1538 1539
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change keymap setting on vnc graphics"));
1540 1541 1542
            return -1;
        }

1543 1544 1545
        /* If a password lifetime was, or is set, or action if connected has
         * changed, then we must always run, even if new password matches
         * old password */
1546 1547
        if (olddev->data.vnc.auth.expires ||
            dev->data.vnc.auth.expires ||
1548
            olddev->data.vnc.auth.connected != dev->data.vnc.auth.connected ||
E
Eric Blake 已提交
1549 1550 1551 1552 1553 1554 1555 1556
            STRNEQ_NULLABLE(olddev->data.vnc.auth.passwd,
                            dev->data.vnc.auth.passwd)) {
            VIR_DEBUG("Updating password on VNC server %p %p",
                      dev->data.vnc.auth.passwd, driver->vncPassword);
            ret = qemuDomainChangeGraphicsPasswords(driver, vm,
                                                    VIR_DOMAIN_GRAPHICS_TYPE_VNC,
                                                    &dev->data.vnc.auth,
                                                    driver->vncPassword);
1557 1558
            if (ret < 0)
                return ret;
1559 1560 1561 1562 1563

            /* Steal the new dev's  char * reference */
            VIR_FREE(olddev->data.vnc.auth.passwd);
            olddev->data.vnc.auth.passwd = dev->data.vnc.auth.passwd;
            dev->data.vnc.auth.passwd = NULL;
1564 1565
            olddev->data.vnc.auth.validTo = dev->data.vnc.auth.validTo;
            olddev->data.vnc.auth.expires = dev->data.vnc.auth.expires;
1566
            olddev->data.vnc.auth.connected = dev->data.vnc.auth.connected;
1567 1568 1569 1570 1571
        } else {
            ret = 0;
        }
        break;

1572 1573
    case VIR_DOMAIN_GRAPHICS_TYPE_SPICE:
        if ((olddev->data.spice.autoport != dev->data.spice.autoport) ||
E
Eric Blake 已提交
1574 1575 1576 1577
            (!dev->data.spice.autoport &&
             (olddev->data.spice.port != dev->data.spice.port)) ||
            (!dev->data.spice.autoport &&
             (olddev->data.spice.tlsPort != dev->data.spice.tlsPort))) {
1578 1579
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change port settings on spice graphics"));
1580 1581
            return -1;
        }
1582
        if (STRNEQ_NULLABLE(oldListenAddr, newListenAddr)) {
1583 1584
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen address setting on spice graphics"));
1585 1586
            return -1;
        }
1587
        if (STRNEQ_NULLABLE(oldListenNetwork, newListenNetwork)) {
1588 1589
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen network setting on spice graphics"));
1590 1591
            return -1;
        }
E
Eric Blake 已提交
1592 1593
        if (STRNEQ_NULLABLE(olddev->data.spice.keymap,
                            dev->data.spice.keymap)) {
1594
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
1595 1596 1597 1598
                            _("cannot change keymap setting on spice graphics"));
            return -1;
        }

1599 1600 1601 1602 1603
        /* We must reset the password if it has changed but also if:
         * - password lifetime is or was set
         * - the requested action has changed
         * - the action is "disconnect"
         */
1604 1605
        if (olddev->data.spice.auth.expires ||
            dev->data.spice.auth.expires ||
1606
            olddev->data.spice.auth.connected != dev->data.spice.auth.connected ||
1607 1608
            dev->data.spice.auth.connected ==
            VIR_DOMAIN_GRAPHICS_AUTH_CONNECTED_DISCONNECT ||
E
Eric Blake 已提交
1609 1610 1611 1612 1613 1614 1615 1616 1617
            STRNEQ_NULLABLE(olddev->data.spice.auth.passwd,
                            dev->data.spice.auth.passwd)) {
            VIR_DEBUG("Updating password on SPICE server %p %p",
                      dev->data.spice.auth.passwd, driver->spicePassword);
            ret = qemuDomainChangeGraphicsPasswords(driver, vm,
                                                    VIR_DOMAIN_GRAPHICS_TYPE_SPICE,
                                                    &dev->data.spice.auth,
                                                    driver->spicePassword);

1618 1619 1620
            if (ret < 0)
                return ret;

E
Eric Blake 已提交
1621
            /* Steal the new dev's char * reference */
1622 1623 1624 1625 1626
            VIR_FREE(olddev->data.spice.auth.passwd);
            olddev->data.spice.auth.passwd = dev->data.spice.auth.passwd;
            dev->data.spice.auth.passwd = NULL;
            olddev->data.spice.auth.validTo = dev->data.spice.auth.validTo;
            olddev->data.spice.auth.expires = dev->data.spice.auth.expires;
1627
            olddev->data.spice.auth.connected = dev->data.spice.auth.connected;
1628
        } else {
1629
            VIR_DEBUG("Not updating since password didn't change");
1630 1631
            ret = 0;
        }
E
Eric Blake 已提交
1632
        break;
1633

1634
    default:
1635 1636 1637
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unable to change config on '%s' graphics type"),
                       virDomainGraphicsTypeToString(dev->type));
1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657
        break;
    }

    return ret;
}


static inline int qemuFindDisk(virDomainDefPtr def, const char *dst)
{
    int i;

    for (i = 0 ; i < def->ndisks ; i++) {
        if (STREQ(def->disks[i]->dst, dst)) {
            return i;
        }
    }

    return -1;
}

1658
static int qemuComparePCIDevice(virDomainDefPtr def ATTRIBUTE_UNUSED,
1659
                                virDomainDeviceDefPtr device ATTRIBUTE_UNUSED,
1660
                                virDomainDeviceInfoPtr info1,
1661 1662
                                void *opaque)
{
1663
    virDomainDeviceInfoPtr info2 = opaque;
1664

1665 1666
    if (info1->type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI ||
        info2->type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)
1667 1668
        return 0;

1669 1670
    if (info1->addr.pci.slot == info2->addr.pci.slot &&
        info1->addr.pci.function != info2->addr.pci.function)
1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682
        return -1;
    return 0;
}

static bool qemuIsMultiFunctionDevice(virDomainDefPtr def,
                                      virDomainDeviceInfoPtr dev)
{
    if (virDomainDeviceInfoIterate(def, qemuComparePCIDevice, dev) < 0)
        return true;
    return false;
}

1683 1684 1685

int qemuDomainDetachPciDiskDevice(struct qemud_driver *driver,
                                  virDomainObjPtr vm,
1686
                                  virDomainDeviceDefPtr dev)
1687 1688 1689 1690 1691 1692 1693 1694 1695 1696
{
    int i, ret = -1;
    virDomainDiskDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    virCgroupPtr cgroup = NULL;
    char *drivestr = NULL;

    i = qemuFindDisk(vm->def, dev->data.disk->dst);

    if (i < 0) {
1697 1698
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
1699 1700 1701 1702 1703
        goto cleanup;
    }

    detach = vm->def->disks[i];

1704
    if (qemuIsMultiFunctionDevice(vm->def, &detach->info)) {
1705 1706 1707
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device: %s"),
                       dev->data.disk->dst);
1708 1709 1710
        goto cleanup;
    }

1711 1712
    if (qemuCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
1713 1714 1715
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unable to find cgroup for %s"),
                           vm->def->name);
1716 1717 1718 1719 1720 1721
            goto cleanup;
        }
    }

    if (!virDomainDeviceAddressIsValid(&detach->info,
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
1722 1723
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("device cannot be detached without a PCI address"));
1724 1725 1726 1727 1728 1729 1730 1731 1732 1733 1734
        goto cleanup;
    }

    /* build the actual drive id string as the disk->info.alias doesn't
     * contain the QEMU_DRIVE_HOST_PREFIX that is passed to qemu */
    if (virAsprintf(&drivestr, "%s%s",
                    QEMU_DRIVE_HOST_PREFIX, detach->info.alias) < 0) {
        virReportOOMError();
        goto cleanup;
    }

1735
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1736
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1737
        if (qemuMonitorDelDevice(priv->mon, detach->info.alias) < 0) {
1738
            qemuDomainObjExitMonitorWithDriver(driver, vm);
1739
            virDomainAuditDisk(vm, detach->src, NULL, "detach", false);
1740 1741 1742 1743 1744
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemovePCIDevice(priv->mon,
                                       &detach->info.addr.pci) < 0) {
1745
            qemuDomainObjExitMonitorWithDriver(driver, vm);
1746
            virDomainAuditDisk(vm, detach->src, NULL, "detach", false);
1747 1748 1749 1750 1751 1752 1753 1754 1755
            goto cleanup;
        }
    }

    /* disconnect guest from host device */
    qemuMonitorDriveDel(priv->mon, drivestr);

    qemuDomainObjExitMonitorWithDriver(driver, vm);

1756
    virDomainAuditDisk(vm, detach->src, NULL, "detach", true);
1757

1758
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
1759 1760
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        detach->info.addr.pci.slot) < 0)
1761 1762 1763 1764 1765 1766
        VIR_WARN("Unable to release PCI address on %s", dev->data.disk->src);

    virDomainDiskRemove(vm->def, i);

    virDomainDiskDefFree(detach);

1767
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
1768
                                            vm->def, dev->data.disk) < 0)
1769 1770 1771
        VIR_WARN("Unable to restore security label on %s", dev->data.disk->src);

    if (cgroup != NULL) {
1772
        if (qemuTeardownDiskCgroup(driver, vm, cgroup, dev->data.disk) < 0)
1773 1774 1775 1776
            VIR_WARN("Failed to teardown cgroup for disk path %s",
                     NULLSTR(dev->data.disk->src));
    }

1777 1778 1779
    if (virDomainLockDiskDetach(driver->lockManager, vm, dev->data.disk) < 0)
        VIR_WARN("Unable to release lock on %s", dev->data.disk->src);

1780 1781 1782
    ret = 0;

cleanup:
1783
    virCgroupFree(&cgroup);
1784 1785 1786 1787
    VIR_FREE(drivestr);
    return ret;
}

1788 1789
int qemuDomainDetachDiskDevice(struct qemud_driver *driver,
                               virDomainObjPtr vm,
1790
                               virDomainDeviceDefPtr dev)
1791 1792 1793 1794 1795 1796 1797 1798 1799 1800
{
    int i, ret = -1;
    virDomainDiskDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    virCgroupPtr cgroup = NULL;
    char *drivestr = NULL;

    i = qemuFindDisk(vm->def, dev->data.disk->dst);

    if (i < 0) {
1801 1802
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
1803 1804 1805
        goto cleanup;
    }

1806
    if (!qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1807 1808 1809
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("Underlying qemu does not support %s disk removal"),
                       virDomainDiskBusTypeToString(dev->data.disk->bus));
1810 1811 1812 1813 1814 1815 1816
        goto cleanup;
    }

    detach = vm->def->disks[i];

    if (qemuCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
1817 1818 1819
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unable to find cgroup for %s"),
                           vm->def->name);
1820 1821 1822 1823 1824 1825 1826 1827 1828 1829 1830 1831
            goto cleanup;
        }
    }

    /* build the actual drive id string as the disk->info.alias doesn't
     * contain the QEMU_DRIVE_HOST_PREFIX that is passed to qemu */
    if (virAsprintf(&drivestr, "%s%s",
                    QEMU_DRIVE_HOST_PREFIX, detach->info.alias) < 0) {
        virReportOOMError();
        goto cleanup;
    }

1832
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1833
    if (qemuMonitorDelDevice(priv->mon, detach->info.alias) < 0) {
1834
        qemuDomainObjExitMonitorWithDriver(driver, vm);
1835
        virDomainAuditDisk(vm, detach->src, NULL, "detach", false);
1836 1837 1838 1839 1840 1841 1842 1843
        goto cleanup;
    }

    /* disconnect guest from host device */
    qemuMonitorDriveDel(priv->mon, drivestr);

    qemuDomainObjExitMonitorWithDriver(driver, vm);

1844
    virDomainAuditDisk(vm, detach->src, NULL, "detach", true);
1845 1846 1847 1848 1849

    virDomainDiskRemove(vm->def, i);

    virDomainDiskDefFree(detach);

1850
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
1851
                                            vm->def, dev->data.disk) < 0)
1852 1853 1854
        VIR_WARN("Unable to restore security label on %s", dev->data.disk->src);

    if (cgroup != NULL) {
1855
        if (qemuTeardownDiskCgroup(driver, vm, cgroup, dev->data.disk) < 0)
1856 1857 1858 1859
            VIR_WARN("Failed to teardown cgroup for disk path %s",
                     NULLSTR(dev->data.disk->src));
    }

1860 1861 1862
    if (virDomainLockDiskDetach(driver->lockManager, vm, dev->data.disk) < 0)
        VIR_WARN("Unable to release lock on disk %s", dev->data.disk->src);

1863 1864 1865 1866 1867 1868 1869 1870
    ret = 0;

cleanup:
    VIR_FREE(drivestr);
    virCgroupFree(&cgroup);
    return ret;
}

1871 1872 1873 1874 1875 1876 1877 1878 1879 1880 1881 1882 1883 1884 1885 1886 1887 1888 1889 1890 1891 1892 1893 1894 1895 1896 1897 1898 1899 1900 1901 1902 1903 1904 1905 1906 1907 1908 1909 1910 1911 1912 1913 1914 1915 1916 1917 1918 1919 1920
static bool qemuDomainDiskControllerIsBusy(virDomainObjPtr vm,
                                           virDomainControllerDefPtr detach)
{
    int i;
    virDomainDiskDefPtr disk;

    for (i = 0; i < vm->def->ndisks; i++) {
        disk = vm->def->disks[i];
        if (disk->info.type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_DRIVE)
            /* the disk does not use disk controller */
            continue;

        /* check whether the disk uses this type controller */
        if (disk->bus == VIR_DOMAIN_DISK_BUS_IDE &&
            detach->type != VIR_DOMAIN_CONTROLLER_TYPE_IDE)
            continue;
        if (disk->bus == VIR_DOMAIN_DISK_BUS_FDC &&
            detach->type != VIR_DOMAIN_CONTROLLER_TYPE_FDC)
            continue;
        if (disk->bus == VIR_DOMAIN_DISK_BUS_SCSI &&
            detach->type != VIR_DOMAIN_CONTROLLER_TYPE_SCSI)
            continue;

        if (disk->info.addr.drive.controller == detach->idx)
            return true;
    }

    return false;
}

static bool qemuDomainControllerIsBusy(virDomainObjPtr vm,
                                       virDomainControllerDefPtr detach)
{
    switch (detach->type) {
    case VIR_DOMAIN_CONTROLLER_TYPE_IDE:
    case VIR_DOMAIN_CONTROLLER_TYPE_FDC:
    case VIR_DOMAIN_CONTROLLER_TYPE_SCSI:
        return qemuDomainDiskControllerIsBusy(vm, detach);

    case VIR_DOMAIN_CONTROLLER_TYPE_SATA:
    case VIR_DOMAIN_CONTROLLER_TYPE_VIRTIO_SERIAL:
    case VIR_DOMAIN_CONTROLLER_TYPE_CCID:
    default:
        /* libvirt does not support sata controller, and does not support to
         * detach virtio and smart card controller.
         */
        return true;
    }
}

1921 1922
int qemuDomainDetachPciControllerDevice(struct qemud_driver *driver,
                                        virDomainObjPtr vm,
1923
                                        virDomainDeviceDefPtr dev)
1924
{
1925
    int idx, ret = -1;
1926 1927 1928
    virDomainControllerDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;

1929 1930 1931
    if ((idx = virDomainControllerFind(vm->def,
                                       dev->data.controller->type,
                                       dev->data.controller->idx)) < 0) {
1932 1933 1934 1935
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk controller %s:%d not found"),
                       virDomainControllerTypeToString(dev->data.controller->type),
                       dev->data.controller->idx);
1936 1937 1938
        goto cleanup;
    }

1939 1940
    detach = vm->def->controllers[idx];

1941 1942
    if (!virDomainDeviceAddressIsValid(&detach->info,
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
1943 1944
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("device cannot be detached without a PCI address"));
1945 1946 1947
        goto cleanup;
    }

1948
    if (qemuIsMultiFunctionDevice(vm->def, &detach->info)) {
1949 1950 1951
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device: %s"),
                       dev->data.disk->dst);
1952 1953 1954
        goto cleanup;
    }

1955
    if (qemuDomainControllerIsBusy(vm, detach)) {
1956 1957
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("device cannot be detached: device is busy"));
1958 1959 1960
        goto cleanup;
    }

1961
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1962 1963 1964 1965
        if (qemuAssignDeviceControllerAlias(detach) < 0)
            goto cleanup;
    }

1966
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1967
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1968
        if (qemuMonitorDelDevice(priv->mon, detach->info.alias)) {
1969
            qemuDomainObjExitMonitorWithDriver(driver, vm);
1970 1971 1972 1973 1974
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemovePCIDevice(priv->mon,
                                       &detach->info.addr.pci) < 0) {
1975
            qemuDomainObjExitMonitorWithDriver(driver, vm);
1976 1977 1978 1979 1980
            goto cleanup;
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

1981 1982
    virDomainControllerRemove(vm->def, idx);
    virDomainControllerDefFree(detach);
1983

1984
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
1985 1986
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        detach->info.addr.pci.slot) < 0)
1987
        VIR_WARN("Unable to release PCI address on controller");
1988 1989 1990 1991 1992 1993 1994

    ret = 0;

cleanup:
    return ret;
}

1995 1996 1997
static int
qemuDomainDetachHostPciDevice(struct qemud_driver *driver,
                              virDomainObjPtr vm,
1998
                              virDomainHostdevDefPtr detach)
1999 2000
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
2001 2002
    virDomainHostdevSubsysPtr subsys = &detach->source.subsys;
    int ret;
2003
    pciDevice *pci;
2004
    pciDevice *activePci;
2005

2006
    if (qemuIsMultiFunctionDevice(vm->def, detach->info)) {
2007 2008 2009 2010
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device: %.4x:%.2x:%.2x.%.1x"),
                       subsys->u.pci.domain, subsys->u.pci.bus,
                       subsys->u.pci.slot,   subsys->u.pci.function);
2011
        return -1;
2012 2013
    }

2014
    if (!virDomainDeviceAddressIsValid(detach->info,
2015
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
2016 2017
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached without a PCI address"));
2018 2019 2020
        return -1;
    }

2021
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2022
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2023
        ret = qemuMonitorDelDevice(priv->mon, detach->info->alias);
2024
    } else {
2025
        ret = qemuMonitorRemovePCIDevice(priv->mon, &detach->info->addr.pci);
2026 2027
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);
2028
    virDomainAuditHostdev(vm, detach, "detach", ret == 0);
2029 2030
    if (ret < 0)
        return -1;
2031

2032 2033 2034 2035 2036 2037 2038
    /*
     * For SRIOV net host devices, unset mac and port profile before
     * reset and reattach device
     */
     if (detach->parent.data.net)
         qemuDomainHostdevNetConfigRestore(detach, driver->stateDir);

2039 2040
    pci = pciGetDevice(subsys->u.pci.domain, subsys->u.pci.bus,
                       subsys->u.pci.slot,   subsys->u.pci.function);
2041 2042
    if (pci) {
        activePci = pciDeviceListSteal(driver->activePciHostdevs, pci);
2043 2044 2045
        if (activePci &&
            pciResetDevice(activePci, driver->activePciHostdevs,
                           driver->inactivePciHostdevs) == 0) {
2046
            qemuReattachPciDevice(activePci, driver);
2047 2048 2049
        } else {
            /* reset of the device failed, treat it as if it was returned */
            pciFreeDevice(activePci);
2050
            ret = -1;
2051
        }
2052
        pciFreeDevice(pci);
2053 2054
    } else {
        ret = -1;
2055 2056
    }

2057
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
2058
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
2059
                                        detach->info->addr.pci.slot) < 0)
2060
        VIR_WARN("Unable to release PCI address on host device");
2061 2062 2063 2064

    return ret;
}

2065 2066 2067
static int
qemuDomainDetachHostUsbDevice(struct qemud_driver *driver,
                              virDomainObjPtr vm,
2068
                              virDomainHostdevDefPtr detach)
2069 2070
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
2071
    virDomainHostdevSubsysPtr subsys = &detach->source.subsys;
2072
    usbDevice *usb;
2073
    int ret;
2074

2075
    if (!detach->info->alias) {
2076 2077
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached without a device alias"));
2078 2079 2080
        return -1;
    }

2081
    if (!qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2082 2083
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached with this QEMU version"));
2084 2085 2086
        return -1;
    }

2087
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2088
    ret = qemuMonitorDelDevice(priv->mon, detach->info->alias);
2089
    qemuDomainObjExitMonitorWithDriver(driver, vm);
2090
    virDomainAuditHostdev(vm, detach, "detach", ret == 0);
2091 2092
    if (ret < 0)
        return -1;
2093

2094
    usb = usbGetDevice(subsys->u.usb.bus, subsys->u.usb.device);
2095 2096 2097 2098 2099
    if (usb) {
        usbDeviceListDel(driver->activeUsbHostdevs, usb);
        usbFreeDevice(usb);
    } else {
        VIR_WARN("Unable to find device %03d.%03d in list of used USB devices",
2100
                 subsys->u.usb.bus, subsys->u.usb.device);
2101 2102 2103 2104
    }
    return ret;
}

2105 2106 2107 2108 2109
static
int qemuDomainDetachThisHostDevice(struct qemud_driver *driver,
                                   virDomainObjPtr vm,
                                   virDomainHostdevDefPtr detach,
                                   int idx)
2110
{
2111
    int ret = -1;
2112

2113 2114 2115 2116 2117 2118 2119 2120 2121
    if (idx < 0) {
        /* caller didn't know index of hostdev in hostdevs list, so we
         * need to find it.
         */
        for (idx = 0; idx < vm->def->nhostdevs; idx++) {
            if (vm->def->hostdevs[idx] == detach)
                break;
        }
        if (idx >= vm->def->nhostdevs) {
2122 2123 2124
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("device not found in hostdevs list (%d entries)"),
                           vm->def->nhostdevs);
2125 2126
            return ret;
        }
2127 2128
    }

2129
    switch (detach->source.subsys.type) {
2130
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI:
2131 2132
        ret = qemuDomainDetachHostPciDevice(driver, vm, detach);
        break;
2133
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
2134
        ret = qemuDomainDetachHostUsbDevice(driver, vm, detach);
2135 2136
        break;
    default:
2137 2138 2139
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev subsys type '%s' not supported"),
                       virDomainHostdevSubsysTypeToString(detach->source.subsys.type));
2140 2141 2142
        return -1;
    }

2143 2144 2145 2146 2147 2148 2149
    if (!ret) {
        if (virSecurityManagerRestoreHostdevLabel(driver->securityManager,
                                                  vm->def, detach) < 0) {
            VIR_WARN("Failed to restore host device labelling");
        }
        virDomainHostdevRemove(vm->def, idx);
        virDomainHostdevDefFree(detach);
2150
    }
2151 2152
    return ret;
}
2153

2154 2155 2156 2157 2158 2159 2160 2161 2162 2163 2164
/* search for a hostdev matching dev and detach it */
int qemuDomainDetachHostDevice(struct qemud_driver *driver,
                               virDomainObjPtr vm,
                               virDomainDeviceDefPtr dev)
{
    virDomainHostdevDefPtr hostdev = dev->data.hostdev;
    virDomainHostdevSubsysPtr subsys = &hostdev->source.subsys;
    virDomainHostdevDefPtr detach = NULL;
    int idx;

    if (hostdev->mode != VIR_DOMAIN_HOSTDEV_MODE_SUBSYS) {
2165 2166 2167
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev mode '%s' not supported"),
                       virDomainHostdevModeTypeToString(hostdev->mode));
2168 2169 2170 2171 2172 2173 2174 2175
        return -1;
    }

    idx = virDomainHostdevFind(vm->def, hostdev, &detach);

    if (idx < 0) {
        switch(subsys->type) {
        case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI:
2176 2177 2178 2179
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("host pci device %.4x:%.2x:%.2x.%.1x not found"),
                           subsys->u.pci.domain, subsys->u.pci.bus,
                           subsys->u.pci.slot, subsys->u.pci.function);
2180 2181 2182
            break;
        case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
            if (subsys->u.usb.bus && subsys->u.usb.device) {
2183 2184 2185
                virReportError(VIR_ERR_OPERATION_FAILED,
                               _("host usb device %03d.%03d not found"),
                               subsys->u.usb.bus, subsys->u.usb.device);
2186
            } else {
2187 2188 2189
                virReportError(VIR_ERR_OPERATION_FAILED,
                               _("host usb device vendor=0x%.4x product=0x%.4x not found"),
                               subsys->u.usb.vendor, subsys->u.usb.product);
2190 2191 2192
            }
            break;
        default:
2193 2194
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("unexpected hostdev type %d"), subsys->type);
2195 2196 2197 2198 2199
            break;
        }
        return -1;
    }

2200 2201 2202 2203 2204 2205 2206
    /* If this is a network hostdev, we need to use the higher-level detach
     * function so that mac address / virtualport are reset
     */
    if (detach->parent.type == VIR_DOMAIN_DEVICE_NET)
        return qemuDomainDetachNetDevice(driver, vm, &detach->parent);
    else
        return qemuDomainDetachThisHostDevice(driver, vm, detach, idx);
2207 2208
}

2209 2210 2211 2212 2213 2214 2215 2216 2217 2218 2219 2220 2221 2222 2223
int
qemuDomainDetachNetDevice(struct qemud_driver *driver,
                          virDomainObjPtr vm,
                          virDomainDeviceDefPtr dev)
{
    int i, ret = -1;
    virDomainNetDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    int vlan;
    char *hostnet_name = NULL;
    virNetDevVPortProfilePtr vport = NULL;

    for (i = 0 ; i < vm->def->nnets ; i++) {
        virDomainNetDefPtr net = vm->def->nets[i];

2224
        if (!virMacAddrCmp(&net->mac, &dev->data.net->mac)) {
2225 2226 2227 2228 2229 2230
            detach = net;
            break;
        }
    }

    if (!detach) {
2231 2232 2233 2234 2235
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("network device %02x:%02x:%02x:%02x:%02x:%02x not found"),
                       dev->data.net->mac.addr[0], dev->data.net->mac.addr[1],
                       dev->data.net->mac.addr[2], dev->data.net->mac.addr[3],
                       dev->data.net->mac.addr[4], dev->data.net->mac.addr[5]);
2236 2237 2238
        goto cleanup;
    }

2239 2240 2241 2242 2243 2244 2245
    if (virDomainNetGetActualType(detach) == VIR_DOMAIN_NET_TYPE_HOSTDEV) {
        ret = qemuDomainDetachThisHostDevice(driver, vm,
                                             virDomainNetGetActualHostdev(detach),
                                             -1);
        goto cleanup;
    }

2246 2247
    if (!virDomainDeviceAddressIsValid(&detach->info,
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
2248 2249
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached without a PCI address"));
2250 2251 2252 2253
        goto cleanup;
    }

    if (qemuIsMultiFunctionDevice(vm->def, &detach->info)) {
2254 2255 2256
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device :%s"),
                       dev->data.disk->dst);
2257 2258 2259 2260
        goto cleanup;
    }

    if ((vlan = qemuDomainNetVLAN(detach)) < 0) {
2261 2262
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("unable to determine original VLAN"));
2263 2264 2265 2266 2267 2268 2269 2270 2271
        goto cleanup;
    }

    if (virAsprintf(&hostnet_name, "host%s", detach->info.alias) < 0) {
        virReportOOMError();
        goto cleanup;
    }

    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2272
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2273 2274 2275 2276 2277 2278 2279 2280 2281 2282 2283 2284 2285 2286
        if (qemuMonitorDelDevice(priv->mon, detach->info.alias) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemovePCIDevice(priv->mon,
                                       &detach->info.addr.pci) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    }

2287 2288
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2289 2290 2291 2292 2293 2294 2295 2296 2297 2298 2299 2300 2301 2302 2303 2304
        if (qemuMonitorRemoveNetdev(priv->mon, hostnet_name) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemoveHostNetwork(priv->mon, vlan, hostnet_name) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    virDomainAuditNet(vm, detach, NULL, "detach", true);

2305
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
2306 2307 2308 2309 2310 2311 2312 2313
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        detach->info.addr.pci.slot) < 0)
        VIR_WARN("Unable to release PCI address on NIC");

    virDomainConfNWFilterTeardown(detach);

    if (virDomainNetGetActualType(detach) == VIR_DOMAIN_NET_TYPE_DIRECT) {
        ignore_value(virNetDevMacVLanDeleteWithVPortProfile(
2314
                         detach->ifname, &detach->mac,
2315 2316 2317 2318 2319 2320 2321 2322 2323 2324
                         virDomainNetGetActualDirectDev(detach),
                         virDomainNetGetActualDirectMode(detach),
                         virDomainNetGetActualVirtPortProfile(detach),
                         driver->stateDir));
        VIR_FREE(detach->ifname);
    }

    if ((driver->macFilter) && (detach->ifname != NULL)) {
        if ((errno = networkDisallowMacOnPort(driver,
                                              detach->ifname,
2325
                                              &detach->mac))) {
2326
            virReportSystemError(errno,
2327
             _("failed to remove ebtables rule on '%s'"),
2328 2329 2330 2331 2332 2333 2334 2335 2336 2337 2338
                                 detach->ifname);
        }
    }

    vport = virDomainNetGetActualVirtPortProfile(detach);
    if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
        ignore_value(virNetDevOpenvswitchRemovePort(
                        virDomainNetGetActualBridgeName(detach),
                        detach->ifname));
    ret = 0;
cleanup:
2339 2340 2341 2342 2343
    if (!ret) {
        networkReleaseActualDevice(detach);
        virDomainNetRemove(vm->def, i);
        virDomainNetDefFree(detach);
    }
2344 2345 2346 2347
    VIR_FREE(hostnet_name);
    return ret;
}

2348 2349 2350 2351 2352 2353 2354 2355 2356 2357
int
qemuDomainChangeGraphicsPasswords(struct qemud_driver *driver,
                                  virDomainObjPtr vm,
                                  int type,
                                  virDomainGraphicsAuthDefPtr auth,
                                  const char *defaultPasswd)
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    time_t now = time(NULL);
    char expire_time [64];
2358
    const char *connected = NULL;
2359 2360 2361 2362 2363
    int ret;

    if (!auth->passwd && !driver->vncPassword)
        return 0;

2364 2365 2366
    if (auth->connected)
        connected = virDomainGraphicsAuthConnectedTypeToString(auth->connected);

2367
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2368 2369 2370
    ret = qemuMonitorSetPassword(priv->mon,
                                 type,
                                 auth->passwd ? auth->passwd : defaultPasswd,
2371
                                 connected);
2372 2373 2374

    if (ret == -2) {
        if (type != VIR_DOMAIN_GRAPHICS_TYPE_VNC) {
2375 2376
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("Graphics password only supported for VNC"));
2377 2378 2379 2380 2381 2382
            ret = -1;
        } else {
            ret = qemuMonitorSetVNCPassword(priv->mon,
                                            auth->passwd ? auth->passwd : defaultPasswd);
        }
    }
2383 2384 2385
    if (ret != 0)
        goto cleanup;

2386 2387 2388
    if (auth->expires) {
        time_t lifetime = auth->validTo - now;
        if (lifetime <= 0)
2389
            snprintf(expire_time, sizeof(expire_time), "now");
2390
        else
2391
            snprintf(expire_time, sizeof(expire_time), "%lu", (long unsigned)auth->validTo);
2392
    } else {
2393
        snprintf(expire_time, sizeof(expire_time), "never");
2394 2395 2396 2397 2398 2399 2400
    }

    ret = qemuMonitorExpirePassword(priv->mon, type, expire_time);

    if (ret == -2) {
        /* XXX we could fake this with a timer */
        if (auth->expires) {
2401 2402
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("Expiry of passwords is not supported"));
2403
            ret = -1;
2404 2405
        } else {
            ret = 0;
2406 2407 2408
        }
    }

2409
cleanup:
2410 2411 2412 2413
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    return ret;
}
2414 2415 2416 2417 2418 2419 2420 2421 2422 2423 2424 2425 2426 2427 2428 2429 2430 2431 2432 2433 2434

int qemuDomainAttachLease(struct qemud_driver *driver,
                          virDomainObjPtr vm,
                          virDomainLeaseDefPtr lease)
{
    if (virDomainLeaseInsertPreAlloc(vm->def) < 0)
        return -1;

    if (virDomainLockLeaseAttach(driver->lockManager, vm, lease) < 0) {
        virDomainLeaseInsertPreAlloced(vm->def, NULL);
        return -1;
    }

    virDomainLeaseInsertPreAlloced(vm->def, lease);
    return 0;
}

int qemuDomainDetachLease(struct qemud_driver *driver,
                          virDomainObjPtr vm,
                          virDomainLeaseDefPtr lease)
{
2435
    virDomainLeaseDefPtr det_lease;
2436 2437 2438
    int i;

    if ((i = virDomainLeaseIndex(vm->def, lease)) < 0) {
2439 2440 2441
        virReportError(VIR_ERR_INVALID_ARG,
                       _("Lease %s in lockspace %s does not exist"),
                       lease->key, NULLSTR(lease->lockspace));
2442 2443 2444 2445 2446 2447
        return -1;
    }

    if (virDomainLockLeaseDetach(driver->lockManager, vm, lease) < 0)
        return -1;

2448 2449
    det_lease = virDomainLeaseRemoveAt(vm->def, i);
    virDomainLeaseDefFree(det_lease);
2450 2451
    return 0;
}