lxc_driver.c 111.3 KB
Newer Older
D
Daniel Veillard 已提交
1
/*
E
Eric Blake 已提交
2
 * Copyright (C) 2010-2012 Red Hat, Inc.
D
Daniel Veillard 已提交
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
 * Copyright IBM Corp. 2008
 *
 * lxc_driver.c: linux container driver functions
 *
 * Authors:
 *  David L. Leskovec <dlesko at linux.vnet.ibm.com>
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
21
 * License along with this library.  If not, see
O
Osier Yang 已提交
22
 * <http://www.gnu.org/licenses/>.
D
Daniel Veillard 已提交
23 24 25 26
 */

#include <config.h>

27
#include <fcntl.h>
D
Daniel Veillard 已提交
28 29 30 31
#include <sched.h>
#include <sys/utsname.h>
#include <string.h>
#include <sys/types.h>
32
#include <sys/socket.h>
33
#include <sys/stat.h>
34 35
#include <sys/un.h>
#include <sys/poll.h>
D
Daniel Veillard 已提交
36 37 38
#include <unistd.h>
#include <wait.h>

39
#include "virterror_internal.h"
40
#include "logging.h"
41
#include "datatypes.h"
D
Daniel Veillard 已提交
42
#include "lxc_conf.h"
43
#include "lxc_container.h"
44
#include "lxc_domain.h"
D
Daniel Veillard 已提交
45
#include "lxc_driver.h"
46
#include "lxc_process.h"
47
#include "memory.h"
48
#include "util.h"
49
#include "virnetdevbridge.h"
50
#include "virnetdevveth.h"
51
#include "nodeinfo.h"
52
#include "uuid.h"
53
#include "stats_linux.h"
54
#include "hooks.h"
E
Eric Blake 已提交
55
#include "virfile.h"
56
#include "virpidfile.h"
57
#include "fdstream.h"
58
#include "domain_audit.h"
59
#include "domain_nwfilter.h"
60
#include "network/bridge_driver.h"
61
#include "virinitctl.h"
62
#include "virnetdev.h"
A
Ansis Atteka 已提交
63
#include "virnetdevtap.h"
64
#include "virnodesuspend.h"
65
#include "virtime.h"
66
#include "virtypedparam.h"
M
Martin Kletzander 已提交
67
#include "viruri.h"
D
Daniel Veillard 已提交
68

69 70
#define VIR_FROM_THIS VIR_FROM_LXC

71

72 73
#define LXC_NB_MEM_PARAM  3

74 75 76
static int lxcStartup(bool privileged,
                      virStateInhibitCallback callback,
                      void *opaque);
77
static int lxcShutdown(void);
78
virLXCDriverPtr lxc_driver = NULL;
D
Daniel Veillard 已提交
79

80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108
/* callbacks for nwfilter */
static int
lxcVMFilterRebuild(virConnectPtr conn ATTRIBUTE_UNUSED,
                   virHashIterator iter, void *data)
{
    virHashForEach(lxc_driver->domains.objs, iter, data);

    return 0;
}

static void
lxcVMDriverLock(void)
{
    lxcDriverLock(lxc_driver);
}

static void
lxcVMDriverUnlock(void)
{
    lxcDriverUnlock(lxc_driver);
}

static virNWFilterCallbackDriver lxcCallbackDriver = {
    .name = "LXC",
    .vmFilterRebuild = lxcVMFilterRebuild,
    .vmDriverLock = lxcVMDriverLock,
    .vmDriverUnlock = lxcVMDriverUnlock,
};

D
Daniel Veillard 已提交
109 110 111 112
/* Functions */

static virDrvOpenStatus lxcOpen(virConnectPtr conn,
                                virConnectAuthPtr auth ATTRIBUTE_UNUSED,
E
Eric Blake 已提交
113
                                unsigned int flags)
D
Daniel Veillard 已提交
114
{
E
Eric Blake 已提交
115 116
    virCheckFlags(VIR_CONNECT_RO, VIR_DRV_OPEN_ERROR);

D
Daniel Veillard 已提交
117
    /* Verify uri was specified */
118
    if (conn->uri == NULL) {
119 120
        if (lxc_driver == NULL)
            return VIR_DRV_OPEN_DECLINED;
121

122
        if (!(conn->uri = virURIParse("lxc:///")))
123
            return VIR_DRV_OPEN_ERROR;
124 125 126 127 128 129 130 131 132 133
    } else {
        if (conn->uri->scheme == NULL ||
            STRNEQ(conn->uri->scheme, "lxc"))
            return VIR_DRV_OPEN_DECLINED;

        /* Leave for remote driver */
        if (conn->uri->server != NULL)
            return VIR_DRV_OPEN_DECLINED;

        /* If path isn't '/' then they typoed, tell them correct path */
134 135
        if (conn->uri->path != NULL &&
            STRNEQ(conn->uri->path, "/")) {
136 137 138
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unexpected LXC URI path '%s', try lxc:///"),
                           conn->uri->path);
139 140
            return VIR_DRV_OPEN_ERROR;
        }
D
Daniel Veillard 已提交
141

142 143
        /* URI was good, but driver isn't active */
        if (lxc_driver == NULL) {
144 145
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("lxc state driver is not active"));
146 147 148
            return VIR_DRV_OPEN_ERROR;
        }
    }
149

150
    conn->privateData = lxc_driver;
D
Daniel Veillard 已提交
151 152 153 154 155 156

    return VIR_DRV_OPEN_SUCCESS;
}

static int lxcClose(virConnectPtr conn)
{
157
    virLXCDriverPtr driver = conn->privateData;
158 159

    lxcDriverLock(driver);
160
    virLXCProcessAutoDestroyRun(driver, conn);
161 162
    lxcDriverUnlock(driver);

163 164
    conn->privateData = NULL;
    return 0;
D
Daniel Veillard 已提交
165 166
}

167 168 169 170 171 172 173 174 175 176 177 178 179 180 181

static int lxcIsSecure(virConnectPtr conn ATTRIBUTE_UNUSED)
{
    /* Trivially secure, since always inside the daemon */
    return 1;
}


static int lxcIsEncrypted(virConnectPtr conn ATTRIBUTE_UNUSED)
{
    /* Not encrypted, but remote driver takes care of that */
    return 0;
}


182 183 184 185 186 187
static int lxcIsAlive(virConnectPtr conn ATTRIBUTE_UNUSED)
{
    return 1;
}


188
static char *lxcGetCapabilities(virConnectPtr conn) {
189
    virLXCDriverPtr driver = conn->privateData;
190 191 192 193
    char *xml;

    lxcDriverLock(driver);
    if ((xml = virCapabilitiesFormatXML(driver->caps)) == NULL)
194
        virReportOOMError();
195 196 197 198 199 200
    lxcDriverUnlock(driver);

    return xml;
}


D
Daniel Veillard 已提交
201 202 203
static virDomainPtr lxcDomainLookupByID(virConnectPtr conn,
                                        int id)
{
204
    virLXCDriverPtr driver = conn->privateData;
205 206
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
207

208
    lxcDriverLock(driver);
209
    vm = virDomainFindByID(&driver->domains, id);
210 211
    lxcDriverUnlock(driver);

D
Daniel Veillard 已提交
212
    if (!vm) {
213 214
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching id %d"), id);
215
        goto cleanup;
D
Daniel Veillard 已提交
216 217 218
    }

    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
219
    if (dom)
D
Daniel Veillard 已提交
220 221
        dom->id = vm->def->id;

222
cleanup:
223 224
    if (vm)
        virDomainObjUnlock(vm);
D
Daniel Veillard 已提交
225 226 227 228 229 230
    return dom;
}

static virDomainPtr lxcDomainLookupByUUID(virConnectPtr conn,
                                          const unsigned char *uuid)
{
231
    virLXCDriverPtr driver = conn->privateData;
232 233
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
234

235
    lxcDriverLock(driver);
236
    vm = virDomainFindByUUID(&driver->domains, uuid);
237 238
    lxcDriverUnlock(driver);

D
Daniel Veillard 已提交
239
    if (!vm) {
240 241
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(uuid, uuidstr);
242 243
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
244
        goto cleanup;
D
Daniel Veillard 已提交
245 246 247
    }

    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
248
    if (dom)
D
Daniel Veillard 已提交
249 250
        dom->id = vm->def->id;

251
cleanup:
252 253
    if (vm)
        virDomainObjUnlock(vm);
D
Daniel Veillard 已提交
254 255 256 257 258 259
    return dom;
}

static virDomainPtr lxcDomainLookupByName(virConnectPtr conn,
                                          const char *name)
{
260
    virLXCDriverPtr driver = conn->privateData;
261 262
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
263

264
    lxcDriverLock(driver);
265
    vm = virDomainFindByName(&driver->domains, name);
266
    lxcDriverUnlock(driver);
D
Daniel Veillard 已提交
267
    if (!vm) {
268 269
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching name '%s'"), name);
270
        goto cleanup;
D
Daniel Veillard 已提交
271 272 273
    }

    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
274
    if (dom)
D
Daniel Veillard 已提交
275 276
        dom->id = vm->def->id;

277
cleanup:
278 279
    if (vm)
        virDomainObjUnlock(vm);
D
Daniel Veillard 已提交
280 281 282
    return dom;
}

283 284 285

static int lxcDomainIsActive(virDomainPtr dom)
{
286
    virLXCDriverPtr driver = dom->conn->privateData;
287 288 289 290 291 292 293
    virDomainObjPtr obj;
    int ret = -1;

    lxcDriverLock(driver);
    obj = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);
    if (!obj) {
294 295
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
296 297
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
298 299 300 301 302 303 304 305 306 307 308 309 310
        goto cleanup;
    }
    ret = virDomainObjIsActive(obj);

cleanup:
    if (obj)
        virDomainObjUnlock(obj);
    return ret;
}


static int lxcDomainIsPersistent(virDomainPtr dom)
{
311
    virLXCDriverPtr driver = dom->conn->privateData;
312 313 314 315 316 317 318
    virDomainObjPtr obj;
    int ret = -1;

    lxcDriverLock(driver);
    obj = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);
    if (!obj) {
319 320
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
321 322
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
323 324 325 326 327 328 329 330 331 332
        goto cleanup;
    }
    ret = obj->persistent;

cleanup:
    if (obj)
        virDomainObjUnlock(obj);
    return ret;
}

333 334
static int lxcDomainIsUpdated(virDomainPtr dom)
{
335
    virLXCDriverPtr driver = dom->conn->privateData;
336 337 338 339 340 341 342 343 344
    virDomainObjPtr obj;
    int ret = -1;

    lxcDriverLock(driver);
    obj = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);
    if (!obj) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
345 346
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
347 348 349 350 351 352 353 354 355
        goto cleanup;
    }
    ret = obj->updated;

cleanup:
    if (obj)
        virDomainObjUnlock(obj);
    return ret;
}
356

357
static int lxcListDomains(virConnectPtr conn, int *ids, int nids) {
358
    virLXCDriverPtr driver = conn->privateData;
359
    int n;
360

361
    lxcDriverLock(driver);
362
    n = virDomainObjListGetActiveIDs(&driver->domains, ids, nids);
363
    lxcDriverUnlock(driver);
364

365
    return n;
D
Daniel Veillard 已提交
366
}
367

368
static int lxcNumDomains(virConnectPtr conn) {
369
    virLXCDriverPtr driver = conn->privateData;
370
    int n;
371

372
    lxcDriverLock(driver);
373
    n = virDomainObjListNumOfDomains(&driver->domains, 1);
374
    lxcDriverUnlock(driver);
375

376
    return n;
D
Daniel Veillard 已提交
377 378 379
}

static int lxcListDefinedDomains(virConnectPtr conn,
380
                                 char **const names, int nnames) {
381
    virLXCDriverPtr driver = conn->privateData;
382
    int n;
383

384
    lxcDriverLock(driver);
385
    n = virDomainObjListGetInactiveNames(&driver->domains, names, nnames);
386
    lxcDriverUnlock(driver);
387

388
    return n;
D
Daniel Veillard 已提交
389 390 391
}


392
static int lxcNumDefinedDomains(virConnectPtr conn) {
393
    virLXCDriverPtr driver = conn->privateData;
394
    int n;
395

396
    lxcDriverLock(driver);
397
    n = virDomainObjListNumOfDomains(&driver->domains, 0);
398
    lxcDriverUnlock(driver);
399

400
    return n;
D
Daniel Veillard 已提交
401 402
}

403 404


D
Daniel Veillard 已提交
405 406
static virDomainPtr lxcDomainDefine(virConnectPtr conn, const char *xml)
{
407
    virLXCDriverPtr driver = conn->privateData;
408
    virDomainDefPtr def = NULL;
409
    virDomainObjPtr vm = NULL;
410
    virDomainPtr dom = NULL;
411
    virDomainEventPtr event = NULL;
412
    int dupVM;
D
Daniel Veillard 已提交
413

414
    lxcDriverLock(driver);
415
    if (!(def = virDomainDefParseString(driver->caps, xml,
M
Matthias Bolte 已提交
416
                                        1 << VIR_DOMAIN_VIRT_LXC,
417
                                        VIR_DOMAIN_XML_INACTIVE)))
418
        goto cleanup;
D
Daniel Veillard 已提交
419

420 421 422
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

M
Matthias Bolte 已提交
423
    if ((dupVM = virDomainObjIsDuplicate(&driver->domains, def, 0)) < 0)
424
        goto cleanup;
425

426
    if ((def->nets != NULL) && !(driver->have_netns)) {
427 428
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
429
        goto cleanup;
430 431
    }

432
    if (!(vm = virDomainAssignDef(driver->caps,
433
                                  &driver->domains, def, false)))
434 435
        goto cleanup;
    def = NULL;
436
    vm->persistent = 1;
D
Daniel Veillard 已提交
437

438
    if (virDomainSaveConfig(driver->configDir,
439
                            vm->newDef ? vm->newDef : vm->def) < 0) {
440
        virDomainRemoveInactive(&driver->domains, vm);
441
        vm = NULL;
442
        goto cleanup;
D
Daniel Veillard 已提交
443 444
    }

445 446
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_DEFINED,
447
                                     !dupVM ?
448 449 450
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED :
                                     VIR_DOMAIN_EVENT_DEFINED_UPDATED);

D
Daniel Veillard 已提交
451
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
452
    if (dom)
D
Daniel Veillard 已提交
453 454
        dom->id = vm->def->id;

455 456
cleanup:
    virDomainDefFree(def);
457 458
    if (vm)
        virDomainObjUnlock(vm);
459
    if (event)
460
        virDomainEventStateQueue(driver->domainEventState, event);
461
    lxcDriverUnlock(driver);
D
Daniel Veillard 已提交
462 463 464
    return dom;
}

465 466
static int lxcDomainUndefineFlags(virDomainPtr dom,
                                  unsigned int flags)
D
Daniel Veillard 已提交
467
{
468
    virLXCDriverPtr driver = dom->conn->privateData;
469
    virDomainObjPtr vm;
470
    virDomainEventPtr event = NULL;
471
    int ret = -1;
D
Daniel Veillard 已提交
472

473 474
    virCheckFlags(0, -1);

475
    lxcDriverLock(driver);
476
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
D
Daniel Veillard 已提交
477
    if (!vm) {
478 479
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
480 481
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
482
        goto cleanup;
D
Daniel Veillard 已提交
483 484
    }

485
    if (!vm->persistent) {
486 487
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot undefine transient domain"));
488
        goto cleanup;
489
    }
D
Daniel Veillard 已提交
490

491
    if (virDomainDeleteConfig(driver->configDir,
492
                              driver->autostartDir,
493 494
                              vm) < 0)
        goto cleanup;
D
Daniel Veillard 已提交
495

496 497 498 499
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_UNDEFINED,
                                     VIR_DOMAIN_EVENT_UNDEFINED_REMOVED);

500 501 502 503 504 505 506
    if (virDomainObjIsActive(vm)) {
        vm->persistent = 0;
    } else {
        virDomainRemoveInactive(&driver->domains, vm);
        vm = NULL;
    }

507
    ret = 0;
D
Daniel Veillard 已提交
508

509
cleanup:
510 511
    if (vm)
        virDomainObjUnlock(vm);
512
    if (event)
513
        virDomainEventStateQueue(driver->domainEventState, event);
514
    lxcDriverUnlock(driver);
515
    return ret;
D
Daniel Veillard 已提交
516 517
}

518 519 520 521 522
static int lxcDomainUndefine(virDomainPtr dom)
{
    return lxcDomainUndefineFlags(dom, 0);
}

D
Daniel Veillard 已提交
523 524 525
static int lxcDomainGetInfo(virDomainPtr dom,
                            virDomainInfoPtr info)
{
526
    virLXCDriverPtr driver = dom->conn->privateData;
527
    virDomainObjPtr vm;
528
    virCgroupPtr cgroup = NULL;
529
    int ret = -1, rc;
D
Daniel Veillard 已提交
530

531
    lxcDriverLock(driver);
532
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
533

D
Daniel Veillard 已提交
534
    if (!vm) {
535 536
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
537 538
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
539
        goto cleanup;
D
Daniel Veillard 已提交
540 541
    }

J
Jiri Denemark 已提交
542
    info->state = virDomainObjGetState(vm, NULL);
D
Daniel Veillard 已提交
543

D
Daniel P. Berrange 已提交
544
    if (!virDomainObjIsActive(vm) || driver->cgroup == NULL) {
D
Daniel Veillard 已提交
545
        info->cpuTime = 0;
546
        info->memory = vm->def->mem.cur_balloon;
D
Daniel Veillard 已提交
547
    } else {
548
        if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
549 550
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unable to get cgroup for %s"), vm->def->name);
551 552 553 554
            goto cleanup;
        }

        if (virCgroupGetCpuacctUsage(cgroup, &(info->cpuTime)) < 0) {
555 556
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Cannot read cputime for domain"));
R
Ryota Ozaki 已提交
557 558
            goto cleanup;
        }
559
        if ((rc = virCgroupGetMemoryUsage(cgroup, &(info->memory))) < 0) {
560 561
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Cannot read memory usage for domain"));
562 563 564 565 566 567
            if (rc == -ENOENT) {
                /* Don't fail if we can't read memory usage due to a lack of
                 * kernel support */
                info->memory = 0;
            } else
                goto cleanup;
568
        }
D
Daniel Veillard 已提交
569 570
    }

571
    info->maxMem = vm->def->mem.max_balloon;
572
    info->nrVirtCpu = vm->def->vcpus;
573
    ret = 0;
D
Daniel Veillard 已提交
574

575
cleanup:
576
    lxcDriverUnlock(driver);
577 578
    if (cgroup)
        virCgroupFree(&cgroup);
579 580
    if (vm)
        virDomainObjUnlock(vm);
581
    return ret;
D
Daniel Veillard 已提交
582 583
}

584 585 586 587 588 589
static int
lxcDomainGetState(virDomainPtr dom,
                  int *state,
                  int *reason,
                  unsigned int flags)
{
590
    virLXCDriverPtr driver = dom->conn->privateData;
591 592 593 594 595 596 597 598 599 600 601 602
    virDomainObjPtr vm;
    int ret = -1;

    virCheckFlags(0, -1);

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
603 604
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
605 606 607
        goto cleanup;
    }

J
Jiri Denemark 已提交
608
    *state = virDomainObjGetState(vm, reason);
609 610 611 612 613 614 615 616
    ret = 0;

cleanup:
    if (vm)
        virDomainObjUnlock(vm);
    return ret;
}

617
static char *lxcGetOSType(virDomainPtr dom)
D
Daniel Veillard 已提交
618
{
619
    virLXCDriverPtr driver = dom->conn->privateData;
620 621
    virDomainObjPtr vm;
    char *ret = NULL;
622

623
    lxcDriverLock(driver);
624
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
625 626
    lxcDriverUnlock(driver);

627
    if (!vm) {
628 629
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
630 631
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
632
        goto cleanup;
633 634
    }

635 636
    ret = strdup(vm->def->os.type);

637
    if (ret == NULL)
638
        virReportOOMError();
639

640
cleanup:
641 642
    if (vm)
        virDomainObjUnlock(vm);
643
    return ret;
D
Daniel Veillard 已提交
644 645
}

R
Ryota Ozaki 已提交
646
/* Returns max memory in kb, 0 if error */
647 648 649
static unsigned long long
lxcDomainGetMaxMemory(virDomainPtr dom)
{
650
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
651
    virDomainObjPtr vm;
652
    unsigned long long ret = 0;
R
Ryota Ozaki 已提交
653 654 655 656 657 658 659 660

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
661 662
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
R
Ryota Ozaki 已提交
663 664 665
        goto cleanup;
    }

666
    ret = vm->def->mem.max_balloon;
R
Ryota Ozaki 已提交
667 668 669 670 671 672 673 674

cleanup:
    if (vm)
        virDomainObjUnlock(vm);
    return ret;
}

static int lxcDomainSetMaxMemory(virDomainPtr dom, unsigned long newmax) {
675
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
676 677 678 679 680 681 682 683 684 685
    virDomainObjPtr vm;
    int ret = -1;

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
686 687
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
R
Ryota Ozaki 已提交
688 689 690
        goto cleanup;
    }

691
    if (newmax < vm->def->mem.cur_balloon) {
692 693
        virReportError(VIR_ERR_INVALID_ARG,
                       "%s", _("Cannot set max memory lower than current memory"));
R
Ryota Ozaki 已提交
694 695 696
        goto cleanup;
    }

697
    vm->def->mem.max_balloon = newmax;
R
Ryota Ozaki 已提交
698 699 700 701 702 703 704 705 706
    ret = 0;

cleanup:
    if (vm)
        virDomainObjUnlock(vm);
    return ret;
}

static int lxcDomainSetMemory(virDomainPtr dom, unsigned long newmem) {
707
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
708 709 710 711 712 713 714 715 716 717
    virDomainObjPtr vm;
    virCgroupPtr cgroup = NULL;
    int ret = -1;

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);
    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
718 719
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
R
Ryota Ozaki 已提交
720 721 722
        goto cleanup;
    }

723
    if (newmem > vm->def->mem.max_balloon) {
724 725
        virReportError(VIR_ERR_INVALID_ARG,
                       "%s", _("Cannot set memory higher than max memory"));
R
Ryota Ozaki 已提交
726 727 728
        goto cleanup;
    }

729
    if (!virDomainObjIsActive(vm)) {
730 731
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
732 733
        goto cleanup;
    }
734

735
    if (driver->cgroup == NULL) {
736 737
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroups must be configured on the host"));
738 739
        goto cleanup;
    }
R
Ryota Ozaki 已提交
740

741
    if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
742 743
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Unable to get cgroup for %s"), vm->def->name);
744
        goto cleanup;
R
Ryota Ozaki 已提交
745
    }
746 747

    if (virCgroupSetMemory(cgroup, newmem) < 0) {
748 749
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("Failed to set memory for domain"));
750 751 752
        goto cleanup;
    }

R
Ryota Ozaki 已提交
753 754 755 756 757 758 759 760 761 762
    ret = 0;

cleanup:
    if (vm)
        virDomainObjUnlock(vm);
    if (cgroup)
        virCgroupFree(&cgroup);
    return ret;
}

763 764 765 766 767
static int
lxcDomainSetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int nparams,
                             unsigned int flags)
768
{
769
    virLXCDriverPtr driver = dom->conn->privateData;
770 771 772 773
    int i;
    virCgroupPtr cgroup = NULL;
    virDomainObjPtr vm = NULL;
    int ret = -1;
774
    int rc;
775

E
Eric Blake 已提交
776
    virCheckFlags(0, -1);
777 778 779 780 781 782 783 784 785
    if (virTypedParameterArrayValidate(params, nparams,
                                       VIR_DOMAIN_MEMORY_HARD_LIMIT,
                                       VIR_TYPED_PARAM_ULLONG,
                                       VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                                       VIR_TYPED_PARAM_ULLONG,
                                       VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                                       VIR_TYPED_PARAM_ULLONG,
                                       NULL) < 0)
        return -1;
E
Eric Blake 已提交
786

787 788 789 790 791 792
    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);

    if (vm == NULL) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
793 794
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
795 796 797 798
        goto cleanup;
    }

    if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
799 800
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot find cgroup for domain %s"), vm->def->name);
801 802 803 804 805
        goto cleanup;
    }

    ret = 0;
    for (i = 0; i < nparams; i++) {
806
        virTypedParameterPtr param = &params[i];
807 808 809 810 811 812 813 814 815 816 817 818 819 820 821

        if (STREQ(param->field, VIR_DOMAIN_MEMORY_HARD_LIMIT)) {
            rc = virCgroupSetMemoryHardLimit(cgroup, params[i].value.ul);
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to set memory hard_limit tunable"));
                ret = -1;
            }
        } else if (STREQ(param->field, VIR_DOMAIN_MEMORY_SOFT_LIMIT)) {
            rc = virCgroupSetMemorySoftLimit(cgroup, params[i].value.ul);
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to set memory soft_limit tunable"));
                ret = -1;
            }
822
        } else if (STREQ(param->field, VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT)) {
823
            rc = virCgroupSetMemSwapHardLimit(cgroup, params[i].value.ul);
824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to set swap_hard_limit tunable"));
                ret = -1;
            }
        }
    }

cleanup:
    if (cgroup)
        virCgroupFree(&cgroup);
    if (vm)
        virDomainObjUnlock(vm);
    lxcDriverUnlock(driver);
    return ret;
}

841 842 843 844 845
static int
lxcDomainGetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int *nparams,
                             unsigned int flags)
846
{
847
    virLXCDriverPtr driver = dom->conn->privateData;
848 849 850
    int i;
    virCgroupPtr cgroup = NULL;
    virDomainObjPtr vm = NULL;
851
    unsigned long long val;
852 853 854
    int ret = -1;
    int rc;

E
Eric Blake 已提交
855 856
    virCheckFlags(0, -1);

857 858 859 860 861 862
    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);

    if (vm == NULL) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
863 864
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
865 866 867 868 869 870 871 872 873 874 875
        goto cleanup;
    }

    if ((*nparams) == 0) {
        /* Current number of memory parameters supported by cgroups */
        *nparams = LXC_NB_MEM_PARAM;
        ret = 0;
        goto cleanup;
    }

    if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
876 877
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Unable to get cgroup for %s"), vm->def->name);
878 879 880
        goto cleanup;
    }

881
    for (i = 0; i < LXC_NB_MEM_PARAM && i < *nparams; i++) {
882
        virTypedParameterPtr param = &params[i];
883 884
        val = 0;

885
        switch (i) {
886 887 888 889 890
        case 0: /* fill memory hard limit here */
            rc = virCgroupGetMemoryHardLimit(cgroup, &val);
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to get memory hard limit"));
891
                goto cleanup;
892
            }
893 894
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
895
                goto cleanup;
896 897 898 899 900 901
            break;
        case 1: /* fill memory soft limit here */
            rc = virCgroupGetMemorySoftLimit(cgroup, &val);
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to get memory soft limit"));
902
                goto cleanup;
903
            }
904 905
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
906
                goto cleanup;
907 908
            break;
        case 2: /* fill swap hard limit here */
909
            rc = virCgroupGetMemSwapHardLimit(cgroup, &val);
910 911 912
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to get swap hard limit"));
913
                goto cleanup;
914
            }
915 916 917
            if (virTypedParameterAssign(param,
                                        VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
918
                goto cleanup;
919 920 921 922 923 924 925 926
            break;

        default:
            break;
            /* should not hit here */
        }
    }

927 928
    if (*nparams > LXC_NB_MEM_PARAM)
        *nparams = LXC_NB_MEM_PARAM;
929 930
    ret = 0;

931 932 933 934 935 936 937 938 939
cleanup:
    if (cgroup)
        virCgroupFree(&cgroup);
    if (vm)
        virDomainObjUnlock(vm);
    lxcDriverUnlock(driver);
    return ret;
}

940
static char *lxcDomainGetXMLDesc(virDomainPtr dom,
941
                                 unsigned int flags)
D
Daniel Veillard 已提交
942
{
943
    virLXCDriverPtr driver = dom->conn->privateData;
944 945
    virDomainObjPtr vm;
    char *ret = NULL;
D
Daniel Veillard 已提交
946

947 948
    /* Flags checked by virDomainDefFormat */

949
    lxcDriverLock(driver);
950
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
951 952
    lxcDriverUnlock(driver);

D
Daniel Veillard 已提交
953
    if (!vm) {
954 955
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
956 957
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
958
        goto cleanup;
D
Daniel Veillard 已提交
959 960
    }

961
    ret = virDomainDefFormat((flags & VIR_DOMAIN_XML_INACTIVE) &&
962 963 964 965
                             vm->newDef ? vm->newDef : vm->def,
                             flags);

cleanup:
966 967
    if (vm)
        virDomainObjUnlock(vm);
968
    return ret;
D
Daniel Veillard 已提交
969 970
}

971
/**
972
 * lxcDomainStartWithFlags:
973
 * @dom: domain to start
974
 * @flags: Must be 0 for now
975 976 977 978 979
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
980
static int lxcDomainStartWithFlags(virDomainPtr dom, unsigned int flags)
981
{
982
    virLXCDriverPtr driver = dom->conn->privateData;
983
    virDomainObjPtr vm;
984
    virDomainEventPtr event = NULL;
985
    int ret = -1;
986

987
    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY, -1);
988

989
    lxcDriverLock(driver);
990
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
991
    if (!vm) {
992 993
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
994 995
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
996 997 998
        goto cleanup;
    }

999
    if ((vm->def->nets != NULL) && !(driver->have_netns)) {
1000 1001
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
1002 1003 1004
        goto cleanup;
    }

1005
    if (virDomainObjIsActive(vm)) {
1006 1007
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is already running"));
1008 1009 1010
        goto cleanup;
    }

1011 1012 1013
    ret = virLXCProcessStart(dom->conn, driver, vm,
                             (flags & VIR_DOMAIN_START_AUTODESTROY),
                             VIR_DOMAIN_RUNNING_BOOTED);
1014

1015
    if (ret == 0) {
1016 1017 1018
        event = virDomainEventNewFromObj(vm,
                                         VIR_DOMAIN_EVENT_STARTED,
                                         VIR_DOMAIN_EVENT_STARTED_BOOTED);
1019 1020 1021 1022
        virDomainAuditStart(vm, "booted", true);
    } else {
        virDomainAuditStart(vm, "booted", false);
    }
1023

1024
cleanup:
1025 1026
    if (vm)
        virDomainObjUnlock(vm);
1027
    if (event)
1028
        virDomainEventStateQueue(driver->domainEventState, event);
1029
    lxcDriverUnlock(driver);
1030
    return ret;
1031 1032
}

1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045
/**
 * lxcDomainStart:
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
static int lxcDomainStart(virDomainPtr dom)
{
    return lxcDomainStartWithFlags(dom, 0);
}

1046 1047 1048 1049
/**
 * lxcDomainCreateAndStart:
 * @conn: pointer to connection
 * @xml: XML definition of domain
1050
 * @flags: Must be 0 for now
1051 1052 1053 1054 1055 1056 1057 1058
 *
 * Creates a domain based on xml and starts it
 *
 * Returns 0 on success or -1 in case of error
 */
static virDomainPtr
lxcDomainCreateAndStart(virConnectPtr conn,
                        const char *xml,
1059
                        unsigned int flags) {
1060
    virLXCDriverPtr driver = conn->privateData;
1061
    virDomainObjPtr vm = NULL;
1062
    virDomainDefPtr def;
1063
    virDomainPtr dom = NULL;
1064
    virDomainEventPtr event = NULL;
1065

1066
    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY, NULL);
1067

1068
    lxcDriverLock(driver);
1069
    if (!(def = virDomainDefParseString(driver->caps, xml,
M
Matthias Bolte 已提交
1070
                                        1 << VIR_DOMAIN_VIRT_LXC,
1071
                                        VIR_DOMAIN_XML_INACTIVE)))
1072
        goto cleanup;
1073

1074 1075 1076
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

1077 1078
    if (virDomainObjIsDuplicate(&driver->domains, def, 1) < 0)
        goto cleanup;
1079

1080
    if ((def->nets != NULL) && !(driver->have_netns)) {
1081 1082
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       "%s", _("System lacks NETNS support"));
1083
        goto cleanup;
1084 1085
    }

1086

1087
    if (!(vm = virDomainAssignDef(driver->caps,
1088
                                  &driver->domains, def, false)))
1089 1090
        goto cleanup;
    def = NULL;
1091

1092 1093 1094
    if (virLXCProcessStart(conn, driver, vm,
                           (flags & VIR_DOMAIN_START_AUTODESTROY),
                           VIR_DOMAIN_RUNNING_BOOTED) < 0) {
1095
        virDomainAuditStart(vm, "booted", false);
1096
        virDomainRemoveInactive(&driver->domains, vm);
1097
        vm = NULL;
1098
        goto cleanup;
1099 1100
    }

1101 1102 1103
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_STARTED,
                                     VIR_DOMAIN_EVENT_STARTED_BOOTED);
1104
    virDomainAuditStart(vm, "booted", true);
1105

1106
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
1107
    if (dom)
1108 1109
        dom->id = vm->def->id;

1110 1111
cleanup:
    virDomainDefFree(def);
1112 1113
    if (vm)
        virDomainObjUnlock(vm);
1114
    if (event)
1115
        virDomainEventStateQueue(driver->domainEventState, event);
1116
    lxcDriverUnlock(driver);
1117 1118 1119
    return dom;
}

1120

1121 1122
static int lxcDomainGetSecurityLabel(virDomainPtr dom, virSecurityLabelPtr seclabel)
{
1123
    virLXCDriverPtr driver = dom->conn->privateData;
1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134
    virDomainObjPtr vm;
    int ret = -1;

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);

    memset(seclabel, 0, sizeof(*seclabel));

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
1135 1136
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
1137 1138 1139 1140
        goto cleanup;
    }

    if (!virDomainVirtTypeToString(vm->def->virtType)) {
1141 1142 1143
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unknown virt type in domain definition '%d'"),
                       vm->def->virtType);
1144 1145 1146 1147 1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163
        goto cleanup;
    }

    /*
     * Theoretically, the pid can be replaced during this operation and
     * return the label of a different process.  If atomicity is needed,
     * further validation will be required.
     *
     * Comment from Dan Berrange:
     *
     *   Well the PID as stored in the virDomainObjPtr can't be changed
     *   because you've got a locked object.  The OS level PID could have
     *   exited, though and in extreme circumstances have cycled through all
     *   PIDs back to ours. We could sanity check that our PID still exists
     *   after reading the label, by checking that our FD connecting to the
     *   LXC monitor hasn't seen SIGHUP/ERR on poll().
     */
    if (virDomainObjIsActive(vm)) {
        if (virSecurityManagerGetProcessLabel(driver->securityManager,
                                              vm->def, vm->pid, seclabel) < 0) {
1164 1165
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("Failed to get security label"));
1166 1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181
            goto cleanup;
        }
    }

    ret = 0;

cleanup:
    if (vm)
        virDomainObjUnlock(vm);
    lxcDriverUnlock(driver);
    return ret;
}

static int lxcNodeGetSecurityModel(virConnectPtr conn,
                                   virSecurityModelPtr secmodel)
{
1182
    virLXCDriverPtr driver = conn->privateData;
1183 1184 1185 1186 1187
    int ret = 0;

    lxcDriverLock(driver);
    memset(secmodel, 0, sizeof(*secmodel));

1188 1189 1190
    /* we treat no driver as success, but simply return no data in *secmodel */
    if (driver->caps->host.nsecModels == 0
        || driver->caps->host.secModels[0].model == NULL)
1191 1192
        goto cleanup;

1193
    if (!virStrcpy(secmodel->model, driver->caps->host.secModels[0].model,
1194
                   VIR_SECURITY_MODEL_BUFLEN)) {
1195 1196 1197
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security model string exceeds max %d bytes"),
                       VIR_SECURITY_MODEL_BUFLEN - 1);
1198 1199 1200 1201
        ret = -1;
        goto cleanup;
    }

1202
    if (!virStrcpy(secmodel->doi, driver->caps->host.secModels[0].doi,
1203
                   VIR_SECURITY_DOI_BUFLEN)) {
1204 1205 1206
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security DOI string exceeds max %d bytes"),
                       VIR_SECURITY_DOI_BUFLEN-1);
1207 1208 1209 1210 1211 1212 1213 1214 1215 1216
        ret = -1;
        goto cleanup;
    }

cleanup:
    lxcDriverUnlock(driver);
    return ret;
}


1217
static int
1218 1219 1220 1221
lxcDomainEventRegister(virConnectPtr conn,
                       virConnectDomainEventCallback callback,
                       void *opaque,
                       virFreeCallback freecb)
1222
{
1223
    virLXCDriverPtr driver = conn->privateData;
1224 1225 1226
    int ret;

    lxcDriverLock(driver);
1227 1228 1229
    ret = virDomainEventStateRegister(conn,
                                      driver->domainEventState,
                                      callback, opaque, freecb);
1230
    lxcDriverUnlock(driver);
1231

1232
    return ret;
1233 1234
}

1235

1236
static int
1237 1238
lxcDomainEventDeregister(virConnectPtr conn,
                         virConnectDomainEventCallback callback)
1239
{
1240
    virLXCDriverPtr driver = conn->privateData;
1241 1242 1243
    int ret;

    lxcDriverLock(driver);
1244 1245 1246
    ret = virDomainEventStateDeregister(conn,
                                        driver->domainEventState,
                                        callback);
1247 1248 1249 1250 1251
    lxcDriverUnlock(driver);

    return ret;
}

1252 1253 1254 1255 1256 1257 1258 1259 1260

static int
lxcDomainEventRegisterAny(virConnectPtr conn,
                          virDomainPtr dom,
                          int eventID,
                          virConnectDomainEventGenericCallback callback,
                          void *opaque,
                          virFreeCallback freecb)
{
1261
    virLXCDriverPtr driver = conn->privateData;
1262 1263 1264
    int ret;

    lxcDriverLock(driver);
1265 1266 1267 1268
    if (virDomainEventStateRegisterID(conn,
                                      driver->domainEventState,
                                      dom, eventID,
                                      callback, opaque, freecb, &ret) < 0)
1269
        ret = -1;
1270 1271 1272 1273 1274 1275 1276 1277 1278 1279
    lxcDriverUnlock(driver);

    return ret;
}


static int
lxcDomainEventDeregisterAny(virConnectPtr conn,
                            int callbackID)
{
1280
    virLXCDriverPtr driver = conn->privateData;
1281 1282 1283
    int ret;

    lxcDriverLock(driver);
1284 1285 1286
    ret = virDomainEventStateDeregisterID(conn,
                                          driver->domainEventState,
                                          callbackID);
1287 1288 1289 1290 1291 1292
    lxcDriverUnlock(driver);

    return ret;
}


1293
/**
1294
 * lxcDomainDestroyFlags:
1295
 * @dom: pointer to domain to destroy
1296
 * @flags: an OR'ed set of virDomainDestroyFlags
1297 1298 1299 1300 1301
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
1302 1303 1304
static int
lxcDomainDestroyFlags(virDomainPtr dom,
                      unsigned int flags)
1305
{
1306
    virLXCDriverPtr driver = dom->conn->privateData;
1307
    virDomainObjPtr vm;
1308
    virDomainEventPtr event = NULL;
1309
    int ret = -1;
1310
    virLXCDomainObjPrivatePtr priv;
1311

1312 1313
    virCheckFlags(0, -1);

1314
    lxcDriverLock(driver);
1315
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
1316
    if (!vm) {
1317 1318
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
1319 1320
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
1321
        goto cleanup;
1322 1323
    }

1324
    if (!virDomainObjIsActive(vm)) {
1325 1326
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
1327 1328 1329
        goto cleanup;
    }

1330
    priv = vm->privateData;
1331
    ret = virLXCProcessStop(driver, vm, VIR_DOMAIN_SHUTOFF_DESTROYED);
1332 1333 1334
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_STOPPED,
                                     VIR_DOMAIN_EVENT_STOPPED_DESTROYED);
1335
    priv->doneStopEvent = true;
1336
    virDomainAuditStop(vm, "destroyed");
1337 1338 1339 1340
    if (!vm->persistent) {
        virDomainRemoveInactive(&driver->domains, vm);
        vm = NULL;
    }
1341 1342

cleanup:
1343 1344
    if (vm)
        virDomainObjUnlock(vm);
1345
    if (event)
1346
        virDomainEventStateQueue(driver->domainEventState, event);
1347
    lxcDriverUnlock(driver);
1348
    return ret;
1349
}
1350

1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364
/**
 * lxcDomainDestroy:
 * @dom: pointer to domain to destroy
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
static int
lxcDomainDestroy(virDomainPtr dom)
{
    return lxcDomainDestroyFlags(dom, 0);
}

1365 1366 1367 1368 1369
static int lxcCheckNetNsSupport(void)
{
    const char *argv[] = {"ip", "link", "set", "lo", "netns", "-1", NULL};
    int ip_rc;

1370
    if (virRun(argv, &ip_rc) < 0 ||
1371 1372
        !(WIFEXITED(ip_rc) && (WEXITSTATUS(ip_rc) != 255)))
        return 0;
1373

1374 1375
    if (lxcContainerAvailable(LXC_CONTAINER_FEATURE_NET) < 0)
        return 0;
1376

1377
    return 1;
1378 1379
}

1380

1381
static int
1382
lxcSecurityInit(virLXCDriverPtr driver)
1383
{
1384
    VIR_INFO("lxcSecurityInit %s", driver->securityDriverName);
1385
    virSecurityManagerPtr mgr = virSecurityManagerNew(driver->securityDriverName,
1386
                                                      LXC_DRIVER_NAME,
1387 1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403
                                                      false,
                                                      driver->securityDefaultConfined,
                                                      driver->securityRequireConfined);
    if (!mgr)
        goto error;

    driver->securityManager = mgr;

    return 0;

error:
    VIR_ERROR(_("Failed to initialize security drivers"));
    virSecurityManagerFree(mgr);
    return -1;
}


1404 1405 1406
static int lxcStartup(bool privileged,
                      virStateInhibitCallback callback ATTRIBUTE_UNUSED,
                      void *opaque ATTRIBUTE_UNUSED)
D
Daniel Veillard 已提交
1407
{
1408
    char *ld;
1409
    int rc;
1410 1411 1412 1413 1414 1415

    /* Valgrind gets very annoyed when we clone containers, so
     * disable LXC when under valgrind
     * XXX remove this when valgrind is fixed
     */
    ld = getenv("LD_PRELOAD");
1416
    if (ld && strstr(ld, "vgpreload")) {
1417
        VIR_INFO("Running under valgrind, disabling driver");
1418 1419
        return 0;
    }
1420

1421
    /* Check that the user is root, silently disable if not */
1422
    if (!privileged) {
1423
        VIR_INFO("Not running privileged, disabling driver");
1424 1425 1426 1427 1428
        return 0;
    }

    /* Check that this is a container enabled kernel */
    if (lxcContainerAvailable(0) < 0) {
1429
        VIR_INFO("LXC support not available in this kernel, disabling driver");
1430
        return 0;
1431 1432
    }

1433
    if (VIR_ALLOC(lxc_driver) < 0) {
1434 1435
        return -1;
    }
1436 1437 1438 1439
    if (virMutexInit(&lxc_driver->lock) < 0) {
        VIR_FREE(lxc_driver);
        return -1;
    }
1440
    lxcDriverLock(lxc_driver);
D
Daniel Veillard 已提交
1441

1442 1443 1444
    if (virDomainObjListInit(&lxc_driver->domains) < 0)
        goto cleanup;

1445
    lxc_driver->domainEventState = virDomainEventStateNew();
1446
    if (!lxc_driver->domainEventState)
1447 1448
        goto cleanup;

A
Amy Griffis 已提交
1449
    lxc_driver->log_libvirtd = 0; /* by default log to container logfile */
1450
    lxc_driver->have_netns = lxcCheckNetNsSupport();
D
Daniel Veillard 已提交
1451

1452 1453
    rc = virCgroupForDriver("lxc", &lxc_driver->cgroup, privileged, 1);
    if (rc < 0) {
1454
        char buf[1024] ATTRIBUTE_UNUSED;
1455 1456 1457 1458 1459
        VIR_DEBUG("Unable to create cgroup for LXC driver: %s",
                  virStrerror(-rc, buf, sizeof(buf)));
        /* Don't abort startup. We will explicitly report to
         * the user when they try to start a VM
         */
1460 1461
    }

D
Daniel Veillard 已提交
1462
    /* Call function to load lxc driver configuration information */
1463 1464
    if (lxcLoadDriverConfig(lxc_driver) < 0)
        goto cleanup;
D
Daniel Veillard 已提交
1465

1466 1467 1468 1469
    if (lxcSecurityInit(lxc_driver) < 0)
        goto cleanup;

    if ((lxc_driver->caps = lxcCapsInit(lxc_driver)) == NULL)
1470
        goto cleanup;
D
Daniel Veillard 已提交
1471

1472
    virLXCDomainSetPrivateDataHooks(lxc_driver->caps);
1473

1474
    if (virLXCProcessAutoDestroyInit(lxc_driver) < 0)
1475 1476
        goto cleanup;

O
Osier Yang 已提交
1477 1478 1479 1480 1481
    /* Get all the running persistent or transient configs first */
    if (virDomainLoadAllConfigs(lxc_driver->caps,
                                &lxc_driver->domains,
                                lxc_driver->stateDir,
                                NULL,
M
Matthias Bolte 已提交
1482 1483
                                1, 1 << VIR_DOMAIN_VIRT_LXC,
                                NULL, NULL) < 0)
O
Osier Yang 已提交
1484 1485
        goto cleanup;

1486
    virLXCProcessReconnectAll(lxc_driver, &lxc_driver->domains);
O
Osier Yang 已提交
1487 1488

    /* Then inactive persistent configs */
1489
    if (virDomainLoadAllConfigs(lxc_driver->caps,
1490 1491
                                &lxc_driver->domains,
                                lxc_driver->configDir,
1492
                                lxc_driver->autostartDir,
M
Matthias Bolte 已提交
1493 1494
                                0, 1 << VIR_DOMAIN_VIRT_LXC,
                                NULL, NULL) < 0)
1495
        goto cleanup;
1496

1497
    lxcDriverUnlock(lxc_driver);
1498

1499
    virLXCProcessAutostartAll(lxc_driver);
1500

1501
    virNWFilterRegisterCallbackDriver(&lxcCallbackDriver);
D
Daniel Veillard 已提交
1502 1503
    return 0;

1504 1505 1506 1507
cleanup:
    lxcDriverUnlock(lxc_driver);
    lxcShutdown();
    return -1;
D
Daniel Veillard 已提交
1508 1509
}

1510 1511
static void lxcNotifyLoadDomain(virDomainObjPtr vm, int newVM, void *opaque)
{
1512
    virLXCDriverPtr driver = opaque;
1513 1514 1515 1516 1517 1518 1519

    if (newVM) {
        virDomainEventPtr event =
            virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_DEFINED,
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED);
        if (event)
1520
            virDomainEventStateQueue(driver->domainEventState, event);
1521 1522 1523 1524 1525 1526 1527 1528 1529 1530 1531 1532 1533 1534 1535
    }
}

/**
 * lxcReload:
 *
 * Function to restart the LXC driver, it will recheck the configuration
 * files and perform autostart
 */
static int
lxcReload(void) {
    if (!lxc_driver)
        return 0;

    lxcDriverLock(lxc_driver);
1536
    virDomainLoadAllConfigs(lxc_driver->caps,
1537 1538 1539
                            &lxc_driver->domains,
                            lxc_driver->configDir,
                            lxc_driver->autostartDir,
M
Matthias Bolte 已提交
1540 1541
                            0, 1 << VIR_DOMAIN_VIRT_LXC,
                            lxcNotifyLoadDomain, lxc_driver);
1542 1543 1544 1545 1546
    lxcDriverUnlock(lxc_driver);

    return 0;
}

1547
static int lxcShutdown(void)
D
Daniel Veillard 已提交
1548
{
1549
    if (lxc_driver == NULL)
1550
        return -1;
1551

1552
    lxcDriverLock(lxc_driver);
1553
    virNWFilterUnRegisterCallbackDriver(&lxcCallbackDriver);
1554
    virDomainObjListDeinit(&lxc_driver->domains);
1555
    virDomainEventStateFree(lxc_driver->domainEventState);
1556

1557
    virLXCProcessAutoDestroyShutdown(lxc_driver);
1558

1559
    virCapabilitiesFree(lxc_driver->caps);
1560
    virSecurityManagerFree(lxc_driver->securityManager);
1561 1562 1563 1564 1565
    VIR_FREE(lxc_driver->configDir);
    VIR_FREE(lxc_driver->autostartDir);
    VIR_FREE(lxc_driver->stateDir);
    VIR_FREE(lxc_driver->logDir);
    lxcDriverUnlock(lxc_driver);
1566
    virMutexDestroy(&lxc_driver->lock);
1567
    VIR_FREE(lxc_driver);
1568 1569 1570

    return 0;
}
D
Daniel Veillard 已提交
1571 1572


1573
static int lxcVersion(virConnectPtr conn ATTRIBUTE_UNUSED, unsigned long *version)
D
Dan Smith 已提交
1574 1575 1576
{
    struct utsname ver;

1577
    uname(&ver);
D
Dan Smith 已提交
1578

1579
    if (virParseVersionString(ver.release, version, true) < 0) {
1580
        virReportError(VIR_ERR_INTERNAL_ERROR, _("Unknown release: %s"), ver.release);
D
Dan Smith 已提交
1581 1582 1583 1584 1585
        return -1;
    }

    return 0;
}
1586

1587 1588 1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620

/*
 * check whether the host supports CFS bandwidth
 *
 * Return 1 when CFS bandwidth is supported, 0 when CFS bandwidth is not
 * supported, -1 on error.
 */
static int lxcGetCpuBWStatus(virCgroupPtr cgroup)
{
    char *cfs_period_path = NULL;
    int ret = -1;

    if (!cgroup)
        return 0;

    if (virCgroupPathOfController(cgroup, VIR_CGROUP_CONTROLLER_CPU,
                                  "cpu.cfs_period_us", &cfs_period_path) < 0) {
        VIR_INFO("cannot get the path of cgroup CPU controller");
        ret = 0;
        goto cleanup;
    }

    if (access(cfs_period_path, F_OK) < 0) {
        ret = 0;
    } else {
        ret = 1;
    }

cleanup:
    VIR_FREE(cfs_period_path);
    return ret;
}


1621
static bool lxcCgroupControllerActive(virLXCDriverPtr driver,
1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633
                                      int controller)
{
    if (driver->cgroup == NULL)
        return false;
    if (controller < 0 || controller >= VIR_CGROUP_CONTROLLER_LAST)
        return false;
    if (!virCgroupMounted(driver->cgroup, controller))
        return false;
#if 0
    if (driver->cgroupControllers & (1 << controller))
        return true;
#endif
1634
    return true;
1635 1636 1637 1638 1639
}



static char *lxcGetSchedulerType(virDomainPtr domain,
1640
                                 int *nparams)
1641
{
1642
    virLXCDriverPtr driver = domain->conn->privateData;
1643 1644
    char *ret = NULL;
    int rc;
1645

1646 1647
    lxcDriverLock(driver);
    if (!lxcCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_CPU)) {
1648 1649
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
1650 1651
        goto cleanup;
    }
1652

1653 1654 1655 1656 1657 1658 1659 1660 1661
    if (nparams) {
        rc = lxcGetCpuBWStatus(driver->cgroup);
        if (rc < 0)
            goto cleanup;
        else if (rc == 0)
            *nparams = 1;
        else
            *nparams = 3;
    }
1662

1663 1664
    ret = strdup("posix");
    if (!ret)
1665
        virReportOOMError();
1666

1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689 1690 1691 1692 1693 1694 1695 1696 1697 1698 1699 1700 1701 1702 1703 1704 1705 1706 1707 1708 1709 1710 1711 1712 1713 1714 1715 1716 1717 1718 1719 1720 1721 1722 1723 1724 1725 1726 1727 1728 1729 1730 1731 1732 1733 1734 1735 1736 1737
cleanup:
    lxcDriverUnlock(driver);
    return ret;
}


static int
lxcGetVcpuBWLive(virCgroupPtr cgroup, unsigned long long *period,
                 long long *quota)
{
    int rc;

    rc = virCgroupGetCpuCfsPeriod(cgroup, period);
    if (rc < 0) {
        virReportSystemError(-rc, "%s",
                             _("unable to get cpu bandwidth period tunable"));
        return -1;
    }

    rc = virCgroupGetCpuCfsQuota(cgroup, quota);
    if (rc < 0) {
        virReportSystemError(-rc, "%s",
                             _("unable to get cpu bandwidth tunable"));
        return -1;
    }

    return 0;
}


static int lxcSetVcpuBWLive(virCgroupPtr cgroup, unsigned long long period,
                            long long quota)
{
    int rc;
    unsigned long long old_period;

    if (period == 0 && quota == 0)
        return 0;

    if (period) {
        /* get old period, and we can rollback if set quota failed */
        rc = virCgroupGetCpuCfsPeriod(cgroup, &old_period);
        if (rc < 0) {
            virReportSystemError(-rc,
                                 "%s", _("Unable to get cpu bandwidth period"));
            return -1;
        }

        rc = virCgroupSetCpuCfsPeriod(cgroup, period);
        if (rc < 0) {
            virReportSystemError(-rc,
                                 "%s", _("Unable to set cpu bandwidth period"));
            return -1;
        }
    }

    if (quota) {
        rc = virCgroupSetCpuCfsQuota(cgroup, quota);
        if (rc < 0) {
            virReportSystemError(-rc,
                                 "%s", _("Unable to set cpu bandwidth quota"));
            goto cleanup;
        }
    }

    return 0;

cleanup:
    if (period) {
        rc = virCgroupSetCpuCfsPeriod(cgroup, old_period);
        if (rc < 0)
1738 1739
            virReportSystemError(-rc, "%s",
                                 _("Unable to rollback cpu bandwidth period"));
1740 1741 1742
    }

    return -1;
1743 1744
}

1745

1746
static int
1747
lxcSetSchedulerParametersFlags(virDomainPtr dom,
1748 1749 1750
                               virTypedParameterPtr params,
                               int nparams,
                               unsigned int flags)
1751
{
1752
    virLXCDriverPtr driver = dom->conn->privateData;
1753
    int i;
1754 1755
    virCgroupPtr group = NULL;
    virDomainObjPtr vm = NULL;
1756
    virDomainDefPtr vmdef = NULL;
1757
    int ret = -1;
1758
    int rc;
1759

1760 1761
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
1762 1763 1764 1765 1766 1767 1768 1769 1770
    if (virTypedParameterArrayValidate(params, nparams,
                                       VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                                       VIR_TYPED_PARAM_ULLONG,
                                       VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                                       VIR_TYPED_PARAM_ULLONG,
                                       VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                                       VIR_TYPED_PARAM_LLONG,
                                       NULL) < 0)
        return -1;
1771 1772

    lxcDriverLock(driver);
1773 1774

    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
1775

1776
    if (vm == NULL) {
1777 1778
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No such domain %s"), dom->uuid);
1779
        goto cleanup;
1780 1781
    }

E
Eric Blake 已提交
1782 1783 1784
    if (virDomainLiveConfigHelperMethod(driver->caps, vm, &flags,
                                        &vmdef) < 0)
        goto cleanup;
1785 1786 1787 1788 1789 1790 1791 1792 1793 1794

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
        vmdef = virDomainObjCopyPersistentDef(driver->caps, vm);
        if (!vmdef)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if (!lxcCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_CPU)) {
1795 1796
            virReportError(VIR_ERR_OPERATION_INVALID,
                           "%s", _("cgroup CPU controller is not mounted"));
1797 1798 1799
            goto cleanup;
        }
        if (virCgroupForDomain(driver->cgroup, vm->def->name, &group, 0) != 0) {
1800 1801 1802
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("cannot find cgroup for domain %s"),
                           vm->def->name);
1803 1804 1805
            goto cleanup;
        }
    }
1806 1807

    for (i = 0; i < nparams; i++) {
1808
        virTypedParameterPtr param = &params[i];
1809

1810 1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821 1822 1823 1824 1825 1826 1827 1828 1829 1830 1831 1832 1833 1834 1835 1836 1837 1838 1839 1840 1841 1842 1843 1844 1845 1846 1847 1848 1849 1850
        if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_CPU_SHARES)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
                rc = virCgroupSetCpuShares(group, params[i].value.ul);
                if (rc != 0) {
                    virReportSystemError(-rc, "%s",
                                         _("unable to set cpu shares tunable"));
                    goto cleanup;
                }

                vm->def->cputune.shares = params[i].value.ul;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.shares = params[i].value.ul;
            }
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_PERIOD)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
                rc = lxcSetVcpuBWLive(group, params[i].value.ul, 0);
                if (rc != 0)
                    goto cleanup;

                if (params[i].value.ul)
                    vm->def->cputune.period = params[i].value.ul;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.period = params[i].value.ul;
            }
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_QUOTA)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
                rc = lxcSetVcpuBWLive(group, 0, params[i].value.l);
                if (rc != 0)
                    goto cleanup;

                if (params[i].value.l)
                    vm->def->cputune.quota = params[i].value.l;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.quota = params[i].value.l;
            }
1851
        }
1852
    }
1853

1854 1855
    if (virDomainSaveStatus(driver->caps, driver->stateDir, vm) < 0)
        goto cleanup;
1856

1857 1858 1859 1860

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        rc = virDomainSaveConfig(driver->configDir, vmdef);
        if (rc < 0)
1861
            goto cleanup;
1862

1863 1864
        virDomainObjAssignDef(vm, vmdef, false);
        vmdef = NULL;
1865
    }
1866

1867
    ret = 0;
1868

1869
cleanup:
1870
    virDomainDefFree(vmdef);
1871
    virCgroupFree(&group);
1872 1873
    if (vm)
        virDomainObjUnlock(vm);
1874
    lxcDriverUnlock(driver);
1875
    return ret;
1876 1877
}

1878 1879 1880 1881 1882 1883 1884 1885 1886
static int
lxcSetSchedulerParameters(virDomainPtr domain,
                          virTypedParameterPtr params,
                          int nparams)
{
    return lxcSetSchedulerParametersFlags(domain, params, nparams, 0);
}

static int
1887
lxcGetSchedulerParametersFlags(virDomainPtr dom,
1888 1889 1890
                               virTypedParameterPtr params,
                               int *nparams,
                               unsigned int flags)
1891
{
1892
    virLXCDriverPtr driver = dom->conn->privateData;
1893 1894
    virCgroupPtr group = NULL;
    virDomainObjPtr vm = NULL;
E
Eric Blake 已提交
1895
    virDomainDefPtr persistentDef;
1896 1897 1898
    unsigned long long shares = 0;
    unsigned long long period = 0;
    long long quota = 0;
1899
    int ret = -1;
1900 1901 1902
    int rc;
    bool cpu_bw_status = false;
    int saved_nparams = 0;
1903

1904 1905
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
1906

1907
    lxcDriverLock(driver);
1908 1909 1910 1911 1912 1913 1914 1915 1916

    if (*nparams > 1) {
        rc = lxcGetCpuBWStatus(driver->cgroup);
        if (rc < 0)
            goto cleanup;
        cpu_bw_status = !!rc;
    }

    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
1917

1918
    if (vm == NULL) {
1919 1920
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No such domain %s"), dom->uuid);
1921 1922 1923
        goto cleanup;
    }

E
Eric Blake 已提交
1924 1925 1926
    if (virDomainLiveConfigHelperMethod(driver->caps, vm, &flags,
                                        &persistentDef) < 0)
        goto cleanup;
1927 1928

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
E
Eric Blake 已提交
1929 1930 1931 1932
        shares = persistentDef->cputune.shares;
        if (*nparams > 1 && cpu_bw_status) {
            period = persistentDef->cputune.period;
            quota = persistentDef->cputune.quota;
1933 1934 1935 1936 1937
        }
        goto out;
    }

    if (!lxcCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_CPU)) {
1938 1939
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
1940
        goto cleanup;
1941 1942
    }

1943
    if (virCgroupForDomain(driver->cgroup, vm->def->name, &group, 0) != 0) {
1944 1945
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot find cgroup for domain %s"), vm->def->name);
1946
        goto cleanup;
1947
    }
1948

1949 1950 1951 1952
    rc = virCgroupGetCpuShares(group, &shares);
    if (rc != 0) {
        virReportSystemError(-rc, "%s",
                             _("unable to get cpu shares tunable"));
1953
        goto cleanup;
1954 1955 1956 1957 1958 1959 1960 1961
    }

    if (*nparams > 1 && cpu_bw_status) {
        rc = lxcGetVcpuBWLive(group, &period, &quota);
        if (rc != 0)
            goto cleanup;
    }
out:
1962 1963
    if (virTypedParameterAssign(&params[0], VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                                VIR_TYPED_PARAM_ULLONG, shares) < 0)
C
Chris Lalancette 已提交
1964
        goto cleanup;
1965 1966 1967 1968
    saved_nparams++;

    if (cpu_bw_status) {
        if (*nparams > saved_nparams) {
1969 1970 1971
            if (virTypedParameterAssign(&params[1],
                                        VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                                        VIR_TYPED_PARAM_ULLONG, period) < 0)
1972 1973 1974 1975 1976
                goto cleanup;
            saved_nparams++;
        }

        if (*nparams > saved_nparams) {
1977 1978 1979
            if (virTypedParameterAssign(&params[2],
                                        VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                                        VIR_TYPED_PARAM_LLONG, quota) < 0)
1980 1981 1982 1983 1984 1985 1986
                goto cleanup;
            saved_nparams++;
        }
    }

    *nparams = saved_nparams;

1987
    ret = 0;
1988

1989 1990
cleanup:
    virCgroupFree(&group);
1991 1992
    if (vm)
        virDomainObjUnlock(vm);
1993
    lxcDriverUnlock(driver);
1994
    return ret;
1995 1996
}

1997 1998 1999 2000 2001 2002 2003 2004
static int
lxcGetSchedulerParameters(virDomainPtr domain,
                          virTypedParameterPtr params,
                          int *nparams)
{
    return lxcGetSchedulerParametersFlags(domain, params, nparams, 0);
}

2005

2006 2007 2008 2009 2010
static int
lxcDomainSetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int nparams,
                            unsigned int flags)
2011
{
2012
    virLXCDriverPtr driver = dom->conn->privateData;
2013 2014 2015 2016 2017 2018 2019 2020
    int i;
    virCgroupPtr group = NULL;
    virDomainObjPtr vm = NULL;
    virDomainDefPtr persistentDef = NULL;
    int ret = -1;

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
2021 2022 2023 2024 2025 2026
    if (virTypedParameterArrayValidate(params, nparams,
                                       VIR_DOMAIN_BLKIO_WEIGHT,
                                       VIR_TYPED_PARAM_UINT,
                                       NULL) < 0)
        return -1;

2027 2028 2029 2030 2031
    lxcDriverLock(driver);

    vm = virDomainFindByUUID(&driver->domains, dom->uuid);

    if (vm == NULL) {
2032 2033
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No such domain %s"), dom->uuid);
2034 2035 2036
        goto cleanup;
    }

E
Eric Blake 已提交
2037 2038 2039
    if (virDomainLiveConfigHelperMethod(driver->caps, vm, &flags,
                                        &persistentDef) < 0)
        goto cleanup;
2040 2041 2042

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if (!lxcCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_BLKIO)) {
2043 2044
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2045 2046 2047 2048
            goto cleanup;
        }

        if (virCgroupForDomain(driver->cgroup, vm->def->name, &group, 0) != 0) {
2049 2050
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("cannot find cgroup for domain %s"), vm->def->name);
2051 2052 2053 2054 2055 2056 2057 2058 2059 2060
            goto cleanup;
        }

        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
                int rc;

                if (params[i].value.ui > 1000 || params[i].value.ui < 100) {
2061 2062
                    virReportError(VIR_ERR_INVALID_ARG, "%s",
                                   _("out of blkio weight range."));
E
Eric Blake 已提交
2063
                    goto cleanup;
2064 2065 2066 2067 2068 2069
                }

                rc = virCgroupSetBlkioWeight(group, params[i].value.ui);
                if (rc != 0) {
                    virReportSystemError(-rc, "%s",
                                         _("unable to set blkio weight tunable"));
E
Eric Blake 已提交
2070
                    goto cleanup;
2071 2072 2073
                }
            }
        }
E
Eric Blake 已提交
2074 2075
    }
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
2076 2077 2078 2079 2080 2081 2082 2083
        /* Clang can't see that if we get here, persistentDef was set.  */
        sa_assert(persistentDef);

        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
                if (params[i].value.ui > 1000 || params[i].value.ui < 100) {
2084 2085
                    virReportError(VIR_ERR_INVALID_ARG, "%s",
                                   _("out of blkio weight range."));
E
Eric Blake 已提交
2086
                    goto cleanup;
2087 2088 2089 2090 2091 2092 2093
                }

                persistentDef->blkio.weight = params[i].value.ui;
            }
        }

        if (virDomainSaveConfig(driver->configDir, persistentDef) < 0)
E
Eric Blake 已提交
2094
            goto cleanup;
2095 2096
    }

E
Eric Blake 已提交
2097
    ret = 0;
2098 2099 2100 2101 2102 2103 2104 2105 2106 2107
cleanup:
    virCgroupFree(&group);
    if (vm)
        virDomainObjUnlock(vm);
    lxcDriverUnlock(driver);
    return ret;
}


#define LXC_NB_BLKIO_PARAM  1
2108 2109 2110 2111 2112
static int
lxcDomainGetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int *nparams,
                            unsigned int flags)
2113
{
2114
    virLXCDriverPtr driver = dom->conn->privateData;
2115 2116 2117 2118 2119 2120 2121 2122 2123 2124 2125 2126 2127 2128 2129
    int i;
    virCgroupPtr group = NULL;
    virDomainObjPtr vm = NULL;
    virDomainDefPtr persistentDef = NULL;
    unsigned int val;
    int ret = -1;
    int rc;

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
    lxcDriverLock(driver);

    vm = virDomainFindByUUID(&driver->domains, dom->uuid);

    if (vm == NULL) {
2130 2131
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No such domain %s"), dom->uuid);
2132 2133 2134 2135 2136 2137 2138 2139 2140 2141
        goto cleanup;
    }

    if ((*nparams) == 0) {
        /* Current number of blkio parameters supported by cgroups */
        *nparams = LXC_NB_BLKIO_PARAM;
        ret = 0;
        goto cleanup;
    }

E
Eric Blake 已提交
2142 2143 2144
    if (virDomainLiveConfigHelperMethod(driver->caps, vm, &flags,
                                        &persistentDef) < 0)
        goto cleanup;
2145 2146 2147

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if (!lxcCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_BLKIO)) {
2148 2149
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2150 2151 2152 2153
            goto cleanup;
        }

        if (virCgroupForDomain(driver->cgroup, vm->def->name, &group, 0) != 0) {
2154 2155
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("cannot find cgroup for domain %s"), vm->def->name);
2156 2157 2158 2159 2160 2161 2162 2163 2164 2165 2166 2167 2168 2169 2170
            goto cleanup;
        }

        for (i = 0; i < *nparams && i < LXC_NB_BLKIO_PARAM; i++) {
            virTypedParameterPtr param = &params[i];
            val = 0;

            switch (i) {
            case 0: /* fill blkio weight here */
                rc = virCgroupGetBlkioWeight(group, &val);
                if (rc != 0) {
                    virReportSystemError(-rc, "%s",
                                         _("unable to get blkio weight"));
                    goto cleanup;
                }
2171 2172
                if (virTypedParameterAssign(param, VIR_DOMAIN_BLKIO_WEIGHT,
                                            VIR_TYPED_PARAM_UINT, val) < 0)
2173 2174 2175 2176 2177 2178 2179 2180 2181 2182 2183 2184 2185 2186
                    goto cleanup;
                break;

            default:
                break;
                /* should not hit here */
            }
        }
    } else if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        for (i = 0; i < *nparams && i < LXC_NB_BLKIO_PARAM; i++) {
            virTypedParameterPtr param = &params[i];

            switch (i) {
            case 0: /* fill blkio weight here */
2187 2188 2189
                if (virTypedParameterAssign(param, VIR_DOMAIN_BLKIO_WEIGHT,
                                            VIR_TYPED_PARAM_UINT,
                                            persistentDef->blkio.weight) < 0)
2190 2191 2192 2193 2194 2195 2196 2197 2198 2199 2200 2201 2202 2203 2204 2205 2206 2207 2208 2209 2210 2211 2212 2213
                    goto cleanup;
                break;

            default:
                break;
                /* should not hit here */
            }
        }
    }

    if (LXC_NB_BLKIO_PARAM < *nparams)
        *nparams = LXC_NB_BLKIO_PARAM;
    ret = 0;

cleanup:
    if (group)
        virCgroupFree(&group);
    if (vm)
        virDomainObjUnlock(vm);
    lxcDriverUnlock(driver);
    return ret;
}


2214 2215 2216 2217 2218 2219
#ifdef __linux__
static int
lxcDomainInterfaceStats(virDomainPtr dom,
                        const char *path,
                        struct _virDomainInterfaceStats *stats)
{
2220
    virLXCDriverPtr driver = dom->conn->privateData;
2221 2222 2223 2224 2225 2226 2227 2228 2229 2230 2231
    virDomainObjPtr vm;
    int i;
    int ret = -1;

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
2232 2233
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
2234 2235 2236 2237
        goto cleanup;
    }

    if (!virDomainObjIsActive(vm)) {
2238 2239
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
2240 2241 2242 2243 2244 2245 2246 2247 2248 2249 2250 2251 2252
        goto cleanup;
    }

    /* Check the path is one of the domain's network interfaces. */
    for (i = 0 ; i < vm->def->nnets ; i++) {
        if (vm->def->nets[i]->ifname &&
            STREQ(vm->def->nets[i]->ifname, path)) {
            ret = 0;
            break;
        }
    }

    if (ret == 0)
2253
        ret = linuxDomainInterfaceStats(path, stats);
2254
    else
2255 2256
        virReportError(VIR_ERR_INVALID_ARG,
                       _("Invalid path, '%s' is not a known interface"), path);
2257 2258 2259 2260 2261 2262 2263 2264 2265 2266 2267

cleanup:
    if (vm)
        virDomainObjUnlock(vm);
    return ret;
}
#else
static int
lxcDomainInterfaceStats(virDomainPtr dom,
                        const char *path ATTRIBUTE_UNUSED,
                        struct _virDomainInterfaceStats *stats ATTRIBUTE_UNUSED)
A
Alex Jia 已提交
2268
{
2269
    virReportError(VIR_ERR_NO_SUPPORT, "%s", __FUNCTION__);
2270 2271 2272 2273
    return -1;
}
#endif

2274 2275
static int lxcDomainGetAutostart(virDomainPtr dom,
                                   int *autostart) {
2276
    virLXCDriverPtr driver = dom->conn->privateData;
2277 2278 2279 2280 2281 2282 2283 2284 2285 2286
    virDomainObjPtr vm;
    int ret = -1;

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
2287 2288
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
2289 2290 2291 2292 2293 2294 2295 2296 2297 2298 2299 2300 2301 2302
        goto cleanup;
    }

    *autostart = vm->autostart;
    ret = 0;

cleanup:
    if (vm)
        virDomainObjUnlock(vm);
    return ret;
}

static int lxcDomainSetAutostart(virDomainPtr dom,
                                   int autostart) {
2303
    virLXCDriverPtr driver = dom->conn->privateData;
2304 2305 2306 2307 2308 2309 2310 2311 2312 2313
    virDomainObjPtr vm;
    char *configFile = NULL, *autostartLink = NULL;
    int ret = -1;

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
2314 2315
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
2316 2317 2318 2319
        goto cleanup;
    }

    if (!vm->persistent) {
2320 2321
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot set autostart for transient domain"));
2322 2323 2324 2325 2326
        goto cleanup;
    }

    autostart = (autostart != 0);

2327 2328 2329 2330
    if (vm->autostart == autostart) {
        ret = 0;
        goto cleanup;
    }
2331

2332
    configFile = virDomainConfigFile(driver->configDir,
2333 2334 2335
                                     vm->def->name);
    if (configFile == NULL)
        goto cleanup;
2336
    autostartLink = virDomainConfigFile(driver->autostartDir,
2337 2338 2339
                                        vm->def->name);
    if (autostartLink == NULL)
        goto cleanup;
2340

2341
    if (autostart) {
2342 2343
        if (virFileMakePath(driver->autostartDir) < 0) {
            virReportSystemError(errno,
2344 2345 2346
                                 _("Cannot create autostart directory %s"),
                                 driver->autostartDir);
            goto cleanup;
2347 2348
        }

2349
        if (symlink(configFile, autostartLink) < 0) {
2350
            virReportSystemError(errno,
2351 2352 2353 2354 2355 2356
                                 _("Failed to create symlink '%s to '%s'"),
                                 autostartLink, configFile);
            goto cleanup;
        }
    } else {
        if (unlink(autostartLink) < 0 && errno != ENOENT && errno != ENOTDIR) {
2357
            virReportSystemError(errno,
2358 2359 2360 2361
                                 _("Failed to delete symlink '%s'"),
                                 autostartLink);
            goto cleanup;
        }
2362
    }
2363 2364

    vm->autostart = autostart;
2365 2366 2367 2368 2369 2370 2371 2372 2373 2374 2375
    ret = 0;

cleanup:
    VIR_FREE(configFile);
    VIR_FREE(autostartLink);
    if (vm)
        virDomainObjUnlock(vm);
    lxcDriverUnlock(driver);
    return ret;
}

2376
static int lxcFreezeContainer(virLXCDriverPtr driver, virDomainObjPtr vm)
R
Ryota Ozaki 已提交
2377 2378 2379 2380 2381 2382 2383 2384 2385 2386
{
    int timeout = 1000; /* In milliseconds */
    int check_interval = 1; /* In milliseconds */
    int exp = 10;
    int waited_time = 0;
    int ret = -1;
    char *state = NULL;
    virCgroupPtr cgroup = NULL;

    if (!(driver->cgroup &&
2387
          virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) == 0))
R
Ryota Ozaki 已提交
2388 2389
        return -1;

2390 2391
    /* From here on, we know that cgroup != NULL.  */

R
Ryota Ozaki 已提交
2392 2393 2394 2395 2396 2397 2398 2399 2400 2401 2402 2403 2404 2405 2406 2407 2408 2409 2410 2411 2412
    while (waited_time < timeout) {
        int r;
        /*
         * Writing "FROZEN" to the "freezer.state" freezes the group,
         * i.e., the container, temporarily transiting "FREEZING" state.
         * Once the freezing is completed, the state of the group transits
         * to "FROZEN".
         * (see linux-2.6/Documentation/cgroups/freezer-subsystem.txt)
         */
        r = virCgroupSetFreezerState(cgroup, "FROZEN");

        /*
         * Returning EBUSY explicitly indicates that the group is
         * being freezed but incomplete and other errors are true
         * errors.
         */
        if (r < 0 && r != -EBUSY) {
            VIR_DEBUG("Writing freezer.state failed with errno: %d", r);
            goto error;
        }
        if (r == -EBUSY)
2413
            VIR_DEBUG("Writing freezer.state gets EBUSY");
R
Ryota Ozaki 已提交
2414 2415 2416 2417 2418 2419 2420 2421 2422 2423 2424 2425 2426 2427 2428 2429 2430 2431 2432 2433 2434 2435 2436 2437 2438 2439 2440 2441 2442 2443 2444 2445 2446 2447 2448 2449 2450 2451 2452

        /*
         * Unfortunately, returning 0 (success) is likely to happen
         * even when the freezing has not been completed. Sometimes
         * the state of the group remains "FREEZING" like when
         * returning -EBUSY and even worse may never transit to
         * "FROZEN" even if writing "FROZEN" again.
         *
         * So we don't trust the return value anyway and always
         * decide that the freezing has been complete only with
         * the state actually transit to "FROZEN".
         */
        usleep(check_interval * 1000);

        r = virCgroupGetFreezerState(cgroup, &state);

        if (r < 0) {
            VIR_DEBUG("Reading freezer.state failed with errno: %d", r);
            goto error;
        }
        VIR_DEBUG("Read freezer.state: %s", state);

        if (STREQ(state, "FROZEN")) {
            ret = 0;
            goto cleanup;
        }

        waited_time += check_interval;
        /*
         * Increasing check_interval exponentially starting with
         * small initial value treats nicely two cases; One is
         * a container is under no load and waiting for long period
         * makes no sense. The other is under heavy load. The container
         * may stay longer time in FREEZING or never transit to FROZEN.
         * In that case, eager polling will just waste CPU time.
         */
        check_interval *= exp;
        VIR_FREE(state);
    }
2453
    VIR_DEBUG("lxcFreezeContainer timeout");
R
Ryota Ozaki 已提交
2454 2455 2456 2457 2458 2459 2460 2461 2462 2463
error:
    /*
     * If timeout or an error on reading the state occurs,
     * activate the group again and return an error.
     * This is likely to fall the group back again gracefully.
     */
    virCgroupSetFreezerState(cgroup, "THAWED");
    ret = -1;

cleanup:
2464
    virCgroupFree(&cgroup);
R
Ryota Ozaki 已提交
2465 2466 2467 2468 2469 2470
    VIR_FREE(state);
    return ret;
}

static int lxcDomainSuspend(virDomainPtr dom)
{
2471
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
2472 2473 2474 2475 2476 2477 2478 2479 2480 2481
    virDomainObjPtr vm;
    virDomainEventPtr event = NULL;
    int ret = -1;

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
2482 2483
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
R
Ryota Ozaki 已提交
2484 2485 2486
        goto cleanup;
    }

D
Daniel P. Berrange 已提交
2487
    if (!virDomainObjIsActive(vm)) {
2488 2489
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
R
Ryota Ozaki 已提交
2490 2491 2492
        goto cleanup;
    }

J
Jiri Denemark 已提交
2493
    if (virDomainObjGetState(vm, NULL) != VIR_DOMAIN_PAUSED) {
R
Ryota Ozaki 已提交
2494
        if (lxcFreezeContainer(driver, vm) < 0) {
2495 2496
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Suspend operation failed"));
R
Ryota Ozaki 已提交
2497 2498
            goto cleanup;
        }
J
Jiri Denemark 已提交
2499
        virDomainObjSetState(vm, VIR_DOMAIN_PAUSED, VIR_DOMAIN_PAUSED_USER);
R
Ryota Ozaki 已提交
2500 2501 2502 2503 2504 2505

        event = virDomainEventNewFromObj(vm,
                                         VIR_DOMAIN_EVENT_SUSPENDED,
                                         VIR_DOMAIN_EVENT_SUSPENDED_PAUSED);
    }

2506
    if (virDomainSaveStatus(driver->caps, driver->stateDir, vm) < 0)
R
Ryota Ozaki 已提交
2507 2508 2509 2510 2511
        goto cleanup;
    ret = 0;

cleanup:
    if (event)
2512
        virDomainEventStateQueue(driver->domainEventState, event);
R
Ryota Ozaki 已提交
2513 2514 2515 2516 2517 2518
    if (vm)
        virDomainObjUnlock(vm);
    lxcDriverUnlock(driver);
    return ret;
}

2519
static int lxcUnfreezeContainer(virLXCDriverPtr driver, virDomainObjPtr vm)
R
Ryota Ozaki 已提交
2520 2521 2522 2523 2524 2525 2526 2527 2528 2529 2530 2531 2532 2533 2534 2535
{
    int ret;
    virCgroupPtr cgroup = NULL;

    if (!(driver->cgroup &&
        virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) == 0))
        return -1;

    ret = virCgroupSetFreezerState(cgroup, "THAWED");

    virCgroupFree(&cgroup);
    return ret;
}

static int lxcDomainResume(virDomainPtr dom)
{
2536
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
2537 2538 2539 2540 2541 2542 2543 2544 2545 2546
    virDomainObjPtr vm;
    virDomainEventPtr event = NULL;
    int ret = -1;

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
2547 2548
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
R
Ryota Ozaki 已提交
2549 2550 2551
        goto cleanup;
    }

D
Daniel P. Berrange 已提交
2552
    if (!virDomainObjIsActive(vm)) {
2553 2554
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
R
Ryota Ozaki 已提交
2555 2556 2557
        goto cleanup;
    }

J
Jiri Denemark 已提交
2558
    if (virDomainObjGetState(vm, NULL) == VIR_DOMAIN_PAUSED) {
R
Ryota Ozaki 已提交
2559
        if (lxcUnfreezeContainer(driver, vm) < 0) {
2560 2561
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Resume operation failed"));
R
Ryota Ozaki 已提交
2562 2563
            goto cleanup;
        }
J
Jiri Denemark 已提交
2564 2565
        virDomainObjSetState(vm, VIR_DOMAIN_RUNNING,
                             VIR_DOMAIN_RUNNING_UNPAUSED);
R
Ryota Ozaki 已提交
2566 2567 2568 2569 2570 2571

        event = virDomainEventNewFromObj(vm,
                                         VIR_DOMAIN_EVENT_RESUMED,
                                         VIR_DOMAIN_EVENT_RESUMED_UNPAUSED);
    }

2572
    if (virDomainSaveStatus(driver->caps, driver->stateDir, vm) < 0)
R
Ryota Ozaki 已提交
2573 2574 2575 2576 2577
        goto cleanup;
    ret = 0;

cleanup:
    if (event)
2578
        virDomainEventStateQueue(driver->domainEventState, event);
R
Ryota Ozaki 已提交
2579 2580 2581 2582 2583 2584
    if (vm)
        virDomainObjUnlock(vm);
    lxcDriverUnlock(driver);
    return ret;
}

2585 2586
static int
lxcDomainOpenConsole(virDomainPtr dom,
2587
                      const char *dev_name,
2588 2589 2590
                      virStreamPtr st,
                      unsigned int flags)
{
2591
    virLXCDriverPtr driver = dom->conn->privateData;
2592 2593 2594 2595
    virDomainObjPtr vm = NULL;
    char uuidstr[VIR_UUID_STRING_BUFLEN];
    int ret = -1;
    virDomainChrDefPtr chr = NULL;
2596
    size_t i;
2597 2598 2599 2600 2601 2602 2603

    virCheckFlags(0, -1);

    lxcDriverLock(driver);
    virUUIDFormat(dom->uuid, uuidstr);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
    if (!vm) {
2604 2605
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
2606 2607 2608 2609
        goto cleanup;
    }

    if (!virDomainObjIsActive(vm)) {
2610 2611
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
2612 2613 2614
        goto cleanup;
    }

2615
    if (dev_name) {
2616 2617 2618 2619 2620 2621 2622
        for (i = 0 ; i < vm->def->nconsoles ; i++) {
            if (vm->def->consoles[i]->info.alias &&
                STREQ(vm->def->consoles[i]->info.alias, dev_name)) {
                chr = vm->def->consoles[i];
                break;
            }
        }
2623
    } else {
2624 2625
        if (vm->def->nconsoles)
            chr = vm->def->consoles[0];
2626 2627 2628 2629 2630
        else if (vm->def->nserials)
            chr = vm->def->serials[0];
    }

    if (!chr) {
2631 2632 2633
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot find console device '%s'"),
                       dev_name ? dev_name : _("default"));
2634 2635 2636
        goto cleanup;
    }

2637
    if (chr->source.type != VIR_DOMAIN_CHR_TYPE_PTY) {
2638 2639
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("character device %s is not using a PTY"), dev_name);
2640 2641 2642
        goto cleanup;
    }

2643
    if (virFDStreamOpenFile(st, chr->source.data.file.path,
E
Eric Blake 已提交
2644
                            0, 0, O_RDWR) < 0)
2645 2646 2647 2648 2649 2650 2651 2652 2653 2654
        goto cleanup;

    ret = 0;
cleanup:
    if (vm)
        virDomainObjUnlock(vm);
    lxcDriverUnlock(driver);
    return ret;
}

2655 2656 2657 2658 2659 2660 2661 2662 2663 2664 2665 2666 2667 2668 2669 2670 2671 2672 2673 2674 2675 2676 2677 2678 2679 2680 2681 2682 2683 2684 2685 2686 2687 2688 2689 2690 2691 2692 2693 2694 2695 2696 2697 2698 2699 2700 2701 2702 2703 2704 2705 2706 2707 2708 2709 2710 2711 2712 2713 2714 2715 2716 2717 2718 2719 2720 2721 2722 2723 2724 2725 2726 2727 2728 2729 2730 2731 2732 2733

static int
lxcDomainSendProcessSignal(virDomainPtr dom,
                           long long pid_value,
                           unsigned int signum,
                           unsigned int flags)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virDomainObjPtr vm = NULL;
    virLXCDomainObjPrivatePtr priv;
    char uuidstr[VIR_UUID_STRING_BUFLEN];
    pid_t victim;
    int ret = -1;

    virCheckFlags(0, -1);

    if (signum >= VIR_DOMAIN_PROCESS_SIGNAL_LAST) {
        virReportError(VIR_ERR_INVALID_ARG,
                       _("signum value %d is out of range"),
                       signum);
        return -1;
    }

    lxcDriverLock(driver);
    virUUIDFormat(dom->uuid, uuidstr);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);
    if (!vm) {
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }
    priv = vm->privateData;

    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
        goto cleanup;
    }

    /*
     * XXX if the kernel has /proc/$PID/ns/pid we can
     * switch into container namespace & that way be
     * able to kill any PID. Alternatively if there
     * is a way to find a mapping of guest<->host PIDs
     * we can kill that way.
     */
    if (pid_value != 1) {
        virReportError(VIR_ERR_ARGUMENT_UNSUPPORTED, "%s",
                       _("Only the init process may be killed"));
        goto cleanup;
    }

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
        goto cleanup;
    }
    victim = priv->initpid;

    /* We're relying on fact libvirt header signal numbers
     * are taken from Linux, to avoid mapping
     */
    if (kill(victim, signum) < 0) {
        virReportSystemError(errno,
                             _("Unable to send %d signal to process %d"),
                             signum, victim);
        goto cleanup;
    }

    ret = 0;

cleanup:
    if (vm)
        virDomainObjUnlock(vm);
    return ret;
}


2734 2735 2736 2737 2738
static int
lxcListAllDomains(virConnectPtr conn,
                  virDomainPtr **domains,
                  unsigned int flags)
{
2739
    virLXCDriverPtr driver = conn->privateData;
2740 2741
    int ret = -1;

O
Osier Yang 已提交
2742
    virCheckFlags(VIR_CONNECT_LIST_DOMAINS_FILTERS_ALL, -1);
2743 2744 2745 2746 2747 2748 2749 2750

    lxcDriverLock(driver);
    ret = virDomainList(conn, driver->domains.objs, domains, flags);
    lxcDriverUnlock(driver);

    return ret;
}

2751

2752 2753 2754 2755 2756 2757 2758 2759 2760 2761 2762 2763 2764 2765 2766 2767 2768 2769 2770 2771 2772 2773 2774 2775 2776 2777 2778 2779 2780 2781 2782 2783 2784 2785 2786 2787 2788 2789 2790 2791 2792 2793 2794 2795 2796 2797 2798 2799 2800 2801 2802 2803 2804 2805 2806 2807 2808 2809 2810 2811 2812 2813 2814 2815 2816 2817 2818 2819 2820 2821 2822 2823 2824 2825 2826 2827 2828 2829 2830 2831 2832 2833 2834 2835 2836 2837 2838 2839 2840 2841 2842 2843 2844 2845 2846 2847 2848 2849 2850 2851 2852 2853 2854 2855 2856 2857 2858 2859 2860 2861 2862 2863 2864 2865 2866 2867 2868 2869 2870 2871 2872 2873 2874 2875 2876 2877 2878 2879 2880 2881 2882 2883 2884 2885 2886 2887 2888 2889 2890 2891 2892 2893 2894 2895 2896 2897 2898 2899 2900 2901 2902 2903 2904 2905 2906 2907 2908 2909 2910 2911 2912 2913 2914 2915 2916 2917 2918 2919 2920 2921 2922 2923 2924
static int
lxcDomainShutdownFlags(virDomainPtr dom,
                       unsigned int flags)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    char *vroot = NULL;
    int ret = -1;
    int rc;

    virCheckFlags(VIR_DOMAIN_SHUTDOWN_INITCTL |
                  VIR_DOMAIN_SHUTDOWN_SIGNAL, -1);

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }

    priv = vm->privateData;

    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
                    (unsigned long long)priv->initpid) < 0) {
        virReportOOMError();
        goto cleanup;
    }

    if (flags == 0 ||
        (flags & VIR_DOMAIN_SHUTDOWN_INITCTL)) {
        if ((rc = virInitctlSetRunLevel(VIR_INITCTL_RUNLEVEL_POWEROFF,
                                        vroot)) < 0) {
            goto cleanup;
        }
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
            goto cleanup;
        }
    } else {
        rc = 0;
    }

    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_SHUTDOWN_SIGNAL))) {
        if (kill(priv->initpid, SIGTERM) < 0 &&
            errno != ESRCH) {
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
                                 (unsigned long long)priv->initpid);
            goto cleanup;
        }
    }

    ret = 0;

cleanup:
    VIR_FREE(vroot);
    if (vm)
        virDomainObjUnlock(vm);
    return ret;
}

static int
lxcDomainShutdown(virDomainPtr dom)
{
    return lxcDomainShutdownFlags(dom, 0);
}

static int
lxcDomainReboot(virDomainPtr dom,
                unsigned int flags)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    char *vroot = NULL;
    int ret = -1;
    int rc;

    virCheckFlags(VIR_DOMAIN_REBOOT_INITCTL |
                  VIR_DOMAIN_REBOOT_SIGNAL, -1);

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);
    lxcDriverUnlock(driver);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }

    priv = vm->privateData;

    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
                    (unsigned long long)priv->initpid) < 0) {
        virReportOOMError();
        goto cleanup;
    }

    if (flags == 0 ||
        (flags & VIR_DOMAIN_REBOOT_INITCTL)) {
        if ((rc = virInitctlSetRunLevel(VIR_INITCTL_RUNLEVEL_REBOOT,
                                        vroot)) < 0) {
            goto cleanup;
        }
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
            goto cleanup;
        }
    } else {
        rc = 0;
    }

    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_REBOOT_SIGNAL))) {
        if (kill(priv->initpid, SIGHUP) < 0 &&
            errno != ESRCH) {
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
                                 (unsigned long long)priv->initpid);
            goto cleanup;
        }
    }

    ret = 0;

cleanup:
    VIR_FREE(vroot);
    if (vm)
        virDomainObjUnlock(vm);
    return ret;
}


2925
static int
2926
lxcDomainAttachDeviceConfig(virDomainDefPtr vmdef,
2927 2928 2929
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
2930
    virDomainDiskDefPtr disk;
2931
    virDomainNetDefPtr net;
2932
    virDomainHostdevDefPtr hostdev;
2933 2934

    switch (dev->type) {
2935 2936 2937 2938 2939 2940 2941 2942 2943 2944 2945 2946 2947 2948 2949 2950
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (virDomainDiskIndexByName(vmdef, disk->dst, true) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("target %s already exists."), disk->dst);
            return -1;
        }
        if (virDomainDiskInsert(vmdef, disk)) {
            virReportOOMError();
            return -1;
        }
        /* vmdef has the pointer. Generic codes for vmdef will do all jobs */
        dev->data.disk = NULL;
        ret = 0;
        break;

2951 2952 2953 2954 2955 2956 2957 2958 2959 2960
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
        if (virDomainNetInsert(vmdef, net) < 0) {
            virReportOOMError();
            goto cleanup;
        }
        dev->data.net = NULL;
        ret = 0;
        break;

2961 2962 2963 2964 2965 2966 2967 2968 2969 2970 2971 2972 2973 2974 2975
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        hostdev = dev->data.hostdev;
        if (virDomainHostdevFind(vmdef, hostdev, NULL) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device is already in the domain configuration"));
            return -1;
        }
        if (virDomainHostdevInsert(vmdef, hostdev) < 0) {
            virReportOOMError();
            return -1;
        }
        dev->data.hostdev = NULL;
        ret = 0;
        break;

2976 2977 2978 2979 2980 2981
    default:
         virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                        _("persistent attach of device is not supported"));
         break;
    }

2982
cleanup:
2983 2984 2985 2986 2987
    return ret;
}


static int
2988
lxcDomainUpdateDeviceConfig(virDomainDefPtr vmdef,
2989 2990 2991
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
2992 2993 2994
    virDomainNetDefPtr net;
    int idx;
    char mac[VIR_MAC_STRING_BUFLEN];
2995 2996

    switch (dev->type) {
2997 2998 2999 3000 3001 3002 3003 3004 3005 3006 3007 3008 3009 3010 3011 3012 3013 3014 3015 3016 3017 3018
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
        idx = virDomainNetFindIdx(vmdef, net);
        if (idx == -2) {
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("multiple devices matching mac address %s found"),
                           virMacAddrFormat(&net->mac, mac));
            goto cleanup;
        } else if (idx < 0) {
            virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                           _("no matching network device was found"));
            goto cleanup;
        }

        virDomainNetDefFree(vmdef->nets[idx]);

        vmdef->nets[idx] = net;
        dev->data.net = NULL;
        ret = 0;

        break;

3019 3020 3021 3022 3023 3024
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent update of device is not supported"));
        break;
    }

3025
cleanup:
3026 3027 3028 3029 3030
    return ret;
}


static int
3031
lxcDomainDetachDeviceConfig(virDomainDefPtr vmdef,
3032 3033 3034
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3035
    virDomainDiskDefPtr disk, det_disk;
3036
    virDomainNetDefPtr net;
3037
    virDomainHostdevDefPtr hostdev, det_hostdev;
3038 3039
    int idx;
    char mac[VIR_MAC_STRING_BUFLEN];
3040 3041

    switch (dev->type) {
3042 3043 3044 3045 3046 3047 3048 3049 3050 3051 3052
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (!(det_disk = virDomainDiskRemoveByName(vmdef, disk->dst))) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("no target device %s"), disk->dst);
            return -1;
        }
        virDomainDiskDefFree(det_disk);
        ret = 0;
        break;

3053 3054 3055 3056 3057 3058 3059 3060 3061 3062 3063 3064 3065 3066 3067 3068 3069 3070
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
        idx = virDomainNetFindIdx(vmdef, net);
        if (idx == -2) {
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("multiple devices matching mac address %s found"),
                           virMacAddrFormat(&net->mac, mac));
            goto cleanup;
        } else if (idx < 0) {
            virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                           _("no matching network device was found"));
            goto cleanup;
        }
        /* this is guaranteed to succeed */
        virDomainNetDefFree(virDomainNetRemove(vmdef, idx));
        ret = 0;
        break;

3071 3072 3073 3074 3075 3076 3077 3078 3079 3080 3081 3082 3083
    case VIR_DOMAIN_DEVICE_HOSTDEV: {
        hostdev = dev->data.hostdev;
        if ((idx = virDomainHostdevFind(vmdef, hostdev, &det_hostdev)) < 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device not present in domain configuration"));
            return -1;
        }
        virDomainHostdevRemove(vmdef, idx);
        virDomainHostdevDefFree(det_hostdev);
        ret = 0;
        break;
    }

3084 3085 3086 3087 3088 3089
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent detach of device is not supported"));
        break;
    }

3090
cleanup:
3091 3092 3093 3094
    return ret;
}


3095 3096 3097 3098 3099 3100 3101 3102 3103 3104 3105 3106 3107 3108 3109 3110 3111 3112 3113 3114 3115 3116 3117 3118 3119 3120 3121 3122 3123 3124 3125 3126 3127 3128 3129 3130 3131 3132 3133 3134 3135 3136 3137 3138 3139 3140 3141 3142 3143 3144 3145 3146 3147 3148 3149 3150 3151 3152 3153 3154 3155 3156 3157 3158 3159 3160 3161 3162 3163 3164 3165 3166 3167 3168 3169 3170 3171 3172 3173 3174 3175 3176 3177 3178 3179 3180 3181 3182 3183 3184 3185 3186 3187 3188 3189 3190 3191 3192 3193 3194 3195 3196 3197 3198 3199 3200 3201 3202 3203 3204 3205 3206 3207 3208 3209 3210 3211 3212 3213 3214 3215 3216 3217 3218 3219 3220 3221 3222 3223 3224
static int
lxcDomainAttachDeviceDiskLive(virLXCDriverPtr driver,
                              virDomainObjPtr vm,
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = dev->data.disk;
    virCgroupPtr group = NULL;
    int ret = -1;
    char *dst;
    struct stat sb;
    bool created = false;
    mode_t mode = 0;
    char *tmpsrc = def->src;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

    if (def->type != VIR_DOMAIN_DISK_TYPE_BLOCK) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk for non-block device"));
        goto cleanup;
    }
    if (def->src == NULL) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk without media"));
        goto cleanup;
    }

    if (virDomainDiskIndexByName(vm->def, def->dst, true) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("target %s already exists"), def->dst);
        goto cleanup;
    }

    if (stat(def->src, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"), def->src);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode) && !S_ISBLK(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Disk source %s must be a character/block device"),
                       def->src);
        goto cleanup;
    }

    if (virAsprintf(&dst, "/proc/%llu/root/dev/%s",
                    (unsigned long long)priv->initpid, def->dst) < 0) {
        virReportOOMError();
        goto cleanup;
    }

    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0) {
        virReportOOMError();
        goto cleanup;
    }

    mode = 0700;
    if (S_ISCHR(sb.st_mode))
        mode |= S_IFCHR;
    else
        mode |= S_IFBLK;

    /* Yes, the device name we're creating may not
     * actually correspond to the major:minor number
     * we're using, but we've no other option at this
     * time. Just have to hope that containerized apps
     * don't get upset that the major:minor is different
     * to that normally implied by the device name
     */
    VIR_DEBUG("Creating dev %s (%d,%d) from %s",
              dst, major(sb.st_rdev), minor(sb.st_rdev), def->src);
    if (mknod(dst, mode, sb.st_rdev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             dst);
        goto cleanup;
    }
    created = true;

    /* Labelling normally operates on src, but we need
     * to actally label the dst here, so hack the config */
    def->src = dst;
    if (virSecurityManagerSetImageLabel(driver->securityManager,
                                        vm->def, def) < 0)
        goto cleanup;

    if (!lxcCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

    if (virCgroupForDomain(driver->cgroup, vm->def->name, &group, 0) != 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot find cgroup for domain %s"), vm->def->name);
        goto cleanup;
    }

    if (virCgroupAllowDevicePath(group, def->src,
                                 (def->readonly ?
                                  VIR_CGROUP_DEVICE_READ :
                                  VIR_CGROUP_DEVICE_RW) |
                                 VIR_CGROUP_DEVICE_MKNOD) != 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot allow device %s for domain %s"),
                       def->src, vm->def->name);
        goto cleanup;
    }

    virDomainDiskInsertPreAlloced(vm->def, def);

    ret = 0;

cleanup:
    def->src = tmpsrc;
    virDomainAuditDisk(vm, NULL, def->src, "attach", ret == 0);
    if (group)
        virCgroupFree(&group);
    if (dst && created && ret < 0)
        unlink(dst);
    return ret;
}


3225
/* XXX conn required for network -> bridge resolution */
3226
static int
3227 3228 3229 3230 3231 3232 3233 3234 3235 3236 3237 3238 3239 3240 3241 3242 3243 3244 3245 3246 3247 3248 3249 3250 3251 3252 3253 3254 3255 3256 3257 3258 3259 3260 3261 3262 3263 3264 3265 3266 3267 3268 3269 3270 3271 3272 3273 3274 3275 3276 3277 3278 3279 3280 3281 3282 3283 3284 3285 3286 3287 3288 3289 3290 3291 3292 3293 3294 3295 3296 3297 3298 3299 3300 3301 3302 3303 3304 3305 3306 3307 3308 3309 3310 3311 3312 3313 3314 3315 3316 3317 3318 3319 3320 3321 3322 3323 3324 3325 3326 3327 3328 3329 3330 3331 3332 3333 3334 3335 3336 3337 3338 3339 3340 3341 3342 3343 3344 3345 3346 3347 3348 3349 3350 3351 3352 3353 3354 3355 3356 3357 3358 3359
lxcDomainAttachDeviceNetLive(virConnectPtr conn,
                             virDomainObjPtr vm,
                             virDomainNetDefPtr net)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    int ret = -1;
    int actualType;
    char *veth = NULL;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

    /* preallocate new slot for device */
    if (VIR_REALLOC_N(vm->def->nets, vm->def->nnets+1) < 0) {
        virReportOOMError();
        return -1;
    }

    /* If appropriate, grab a physical device from the configured
     * network's pool of devices, or resolve bridge device name
     * to the one defined in the network definition.
     */
    if (networkAllocateActualDevice(net) < 0)
        return -1;

    actualType = virDomainNetGetActualType(net);

    switch (actualType) {
    case VIR_DOMAIN_NET_TYPE_BRIDGE: {
        const char *brname = virDomainNetGetActualBridgeName(net);
        if (!brname) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("No bridge name specified"));
            goto cleanup;
        }
        if (!(veth = virLXCProcessSetupInterfaceBridged(conn,
                                                        vm->def,
                                                        net,
                                                        brname)))
            goto cleanup;
    }   break;
    case VIR_DOMAIN_NET_TYPE_NETWORK: {
        virNetworkPtr network;
        char *brname = NULL;
        bool fail = false;
        int active;
        virErrorPtr errobj;

        if (!(network = virNetworkLookupByName(conn,
                                               net->data.network.name)))
            goto cleanup;

        active = virNetworkIsActive(network);
        if (active != 1) {
            fail = true;
            if (active == 0)
                virReportError(VIR_ERR_INTERNAL_ERROR,
                               _("Network '%s' is not active."),
                               net->data.network.name);
        }

        if (!fail) {
            brname = virNetworkGetBridgeName(network);
            if (brname == NULL)
                fail = true;
        }

        /* Make sure any above failure is preserved */
        errobj = virSaveLastError();
        virNetworkFree(network);
        virSetError(errobj);
        virFreeError(errobj);

        if (fail)
            goto cleanup;

        if (!(veth = virLXCProcessSetupInterfaceBridged(conn,
                                                        vm->def,
                                                        net,
                                                        brname))) {
            VIR_FREE(brname);
            goto cleanup;
        }
        VIR_FREE(brname);
    }   break;
    case VIR_DOMAIN_NET_TYPE_DIRECT: {
        if (!(veth = virLXCProcessSetupInterfaceDirect(conn,
                                                       vm->def,
                                                       net)))
            goto cleanup;
    }   break;
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Network device type is not supported"));
        goto cleanup;
    }

    if (virNetDevSetNamespace(veth, priv->initpid) < 0) {
        virDomainAuditNet(vm, NULL, net, "attach", false);
        goto cleanup;
    }

    virDomainAuditNet(vm, NULL, net, "attach", true);

    ret = 0;

cleanup:
    if (!ret) {
        vm->def->nets[vm->def->nnets++] = net;
    } else if (veth) {
        switch (actualType) {
        case VIR_DOMAIN_NET_TYPE_BRIDGE:
        case VIR_DOMAIN_NET_TYPE_NETWORK:
            ignore_value(virNetDevVethDelete(veth));
            break;

        case VIR_DOMAIN_NET_TYPE_DIRECT:
            ignore_value(virNetDevMacVLanDelete(veth));
            break;
        }
    }

    return ret;
}


static int
lxcDomainAttachDeviceLive(virConnectPtr conn,
                          virLXCDriverPtr driver,
                          virDomainObjPtr vm,
3360 3361 3362 3363 3364
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
3365 3366 3367 3368 3369 3370
    case VIR_DOMAIN_DEVICE_DISK:
        ret = lxcDomainAttachDeviceDiskLive(driver, vm, dev);
        if (!ret)
            dev->data.disk = NULL;
        break;

3371 3372 3373 3374 3375 3376 3377
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainAttachDeviceNetLive(conn, vm,
                                           dev->data.net);
        if (!ret)
            dev->data.net = NULL;
        break;

3378 3379 3380 3381 3382 3383 3384 3385 3386 3387 3388
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be attached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


3389 3390 3391 3392 3393 3394 3395 3396 3397 3398 3399 3400 3401 3402 3403 3404 3405 3406 3407 3408 3409 3410 3411 3412 3413 3414 3415 3416 3417 3418 3419 3420 3421 3422 3423 3424 3425 3426 3427 3428 3429 3430 3431 3432 3433 3434 3435 3436 3437 3438 3439 3440 3441 3442 3443 3444 3445 3446 3447 3448 3449 3450 3451 3452 3453 3454 3455 3456 3457 3458 3459
static int
lxcDomainDetachDeviceDiskLive(virLXCDriverPtr driver,
                              virDomainObjPtr vm,
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = NULL;
    virCgroupPtr group = NULL;
    int i, ret = -1;
    char *dst;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

    if ((i = virDomainDiskIndexByName(vm->def,
                                      dev->data.disk->dst,
                                      false)) < 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
        goto cleanup;
    }

    def = vm->def->disks[i];

    if (virAsprintf(&dst, "/proc/%llu/root/dev/%s",
                    (unsigned long long)priv->initpid, def->dst) < 0) {
        virReportOOMError();
        goto cleanup;
    }

    if (!lxcCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

    if (virCgroupForDomain(driver->cgroup, vm->def->name, &group, 0) != 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot find cgroup for domain %s"), vm->def->name);
        goto cleanup;
    }

    VIR_DEBUG("Unlinking %s (backed by %s)", dst, def->src);
    if (unlink(dst) < 0 && errno != ENOENT) {
        virDomainAuditDisk(vm, def->src, NULL, "detach", false);
        virReportSystemError(errno,
                             _("Unable to remove device %s"), dst);
        goto cleanup;
    }
    virDomainAuditDisk(vm, def->src, NULL, "detach", true);

    if (virCgroupDenyDevicePath(group, def->src, VIR_CGROUP_DEVICE_RWM) != 0)
        VIR_WARN("cannot deny device %s for domain %s",
                 def->src, vm->def->name);

    virDomainDiskRemove(vm->def, i);
    virDomainDiskDefFree(def);

    ret = 0;

cleanup:
    VIR_FREE(dst);
    if (group)
        virCgroupFree(&group);
    return ret;
}


3460
static int
3461 3462 3463 3464 3465 3466 3467 3468 3469 3470 3471 3472 3473 3474 3475 3476 3477 3478 3479 3480 3481 3482 3483 3484 3485 3486 3487 3488 3489 3490 3491 3492 3493 3494 3495 3496 3497 3498 3499 3500 3501 3502 3503 3504 3505 3506 3507 3508 3509 3510 3511 3512 3513 3514 3515 3516 3517 3518 3519 3520 3521 3522 3523 3524 3525 3526 3527 3528
lxcDomainDetachDeviceNetLive(virDomainObjPtr vm,
                             virDomainDeviceDefPtr dev)
{
    int detachidx, ret = -1;
    virDomainNetDefPtr detach = NULL;
    char mac[VIR_MAC_STRING_BUFLEN];
    virNetDevVPortProfilePtr vport = NULL;

    detachidx = virDomainNetFindIdx(vm->def, dev->data.net);
    if (detachidx == -2) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("multiple devices matching mac address %s found"),
                       virMacAddrFormat(&dev->data.net->mac, mac));
        goto cleanup;
    } else if (detachidx < 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("network device %s not found"),
                       virMacAddrFormat(&dev->data.net->mac, mac));
        goto cleanup;
    }
    detach = vm->def->nets[detachidx];

    switch (virDomainNetGetActualType(detach)) {
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
    case VIR_DOMAIN_NET_TYPE_NETWORK:
        if (virNetDevVethDelete(detach->ifname) < 0) {
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
        break;

        /* It'd be nice to support this, but with macvlan
         * once assigned to a container nothing exists on
         * the host side. Further the container can change
         * the mac address of NIC name, so we can't easily
         * find out which guest NIC it maps to
    case VIR_DOMAIN_NET_TYPE_DIRECT:
        */

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Only bridged veth devices can be detached"));
        goto cleanup;
    }

    virDomainAuditNet(vm, detach, NULL, "detach", true);

    virDomainConfNWFilterTeardown(detach);

    vport = virDomainNetGetActualVirtPortProfile(detach);
    if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
        ignore_value(virNetDevOpenvswitchRemovePort(
                        virDomainNetGetActualBridgeName(detach),
                        detach->ifname));
    ret = 0;
cleanup:
    if (!ret) {
        networkReleaseActualDevice(detach);
        virDomainNetRemove(vm->def, detachidx);
        virDomainNetDefFree(detach);
    }
    return ret;
}


static int
lxcDomainDetachDeviceLive(virLXCDriverPtr driver,
                          virDomainObjPtr vm,
3529 3530 3531 3532 3533
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
3534 3535 3536 3537
    case VIR_DOMAIN_DEVICE_DISK:
        ret = lxcDomainDetachDeviceDiskLive(driver, vm, dev);
        break;

3538 3539 3540 3541
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainDetachDeviceNetLive(vm, dev);
        break;

3542 3543 3544 3545 3546 3547 3548 3549 3550 3551 3552 3553 3554 3555 3556 3557 3558 3559 3560 3561 3562 3563 3564 3565 3566 3567 3568 3569 3570 3571 3572 3573 3574 3575 3576 3577 3578 3579 3580 3581 3582 3583 3584 3585 3586 3587 3588 3589 3590 3591 3592 3593 3594 3595 3596 3597 3598 3599 3600 3601 3602 3603 3604 3605 3606 3607 3608 3609 3610 3611 3612 3613 3614 3615 3616 3617 3618 3619 3620 3621 3622 3623 3624 3625 3626 3627 3628 3629 3630 3631 3632 3633 3634 3635 3636 3637 3638 3639 3640 3641 3642 3643 3644 3645 3646 3647 3648 3649 3650 3651 3652 3653 3654 3655 3656 3657 3658 3659 3660
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be detached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


/* Actions for lxcDomainModifyDeviceFlags */
enum {
    LXC_DEVICE_ATTACH,
    LXC_DEVICE_UPDATE,
    LXC_DEVICE_DETACH,
};


static int
lxcDomainModifyDeviceFlags(virDomainPtr dom, const char *xml,
                           unsigned int flags, int action)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
    unsigned int affect;

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG |
                  (action == LXC_DEVICE_UPDATE ?
                   VIR_DOMAIN_DEVICE_MODIFY_FORCE : 0), -1);

    affect = flags & (VIR_DOMAIN_AFFECT_LIVE | VIR_DOMAIN_AFFECT_CONFIG);

    lxcDriverLock(driver);
    vm = virDomainFindByUUID(&driver->domains, dom->uuid);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }

    if (virDomainObjIsActive(vm)) {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_LIVE;
    } else {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_CONFIG;
        /* check consistency between flags and the vm state */
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("cannot do live update a device on "
                             "inactive domain"));
            goto cleanup;
        }
    }

    if ((flags & VIR_DOMAIN_AFFECT_CONFIG) && !vm->persistent) {
         virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                        _("cannot modify device on transient domain"));
         goto cleanup;
    }

    dev = dev_copy = virDomainDeviceDefParse(driver->caps, vm->def, xml,
                                             VIR_DOMAIN_XML_INACTIVE);
    if (dev == NULL)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(driver->caps, vm->def, dev);
        if (!dev_copy)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        if (virDomainDefCompatibleDevice(vm->def, dev) < 0)
            goto cleanup;

        /* Make a copy for updated domain. */
        vmdef = virDomainObjCopyPersistentDef(driver->caps, vm);
        if (!vmdef)
            goto cleanup;
        switch (action) {
        case LXC_DEVICE_ATTACH:
            ret = lxcDomainAttachDeviceConfig(vmdef, dev);
            break;
        case LXC_DEVICE_DETACH:
            ret = lxcDomainDetachDeviceConfig(vmdef, dev);
            break;
        case LXC_DEVICE_UPDATE:
            ret = lxcDomainUpdateDeviceConfig(vmdef, dev);
            break;
        default:
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("unknown domain modify action %d"), action);
            break;
        }

        if (ret == -1)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if (virDomainDefCompatibleDevice(vm->def, dev_copy) < 0)
            goto cleanup;

        switch (action) {
        case LXC_DEVICE_ATTACH:
3661
            ret = lxcDomainAttachDeviceLive(dom->conn, driver, vm, dev_copy);
3662 3663 3664 3665 3666 3667 3668 3669 3670 3671 3672 3673 3674 3675 3676 3677 3678 3679 3680 3681 3682 3683 3684 3685 3686 3687 3688 3689 3690 3691 3692 3693 3694 3695 3696 3697 3698 3699 3700 3701 3702 3703 3704 3705 3706 3707 3708 3709 3710 3711 3712 3713 3714 3715 3716 3717 3718 3719 3720 3721 3722 3723 3724 3725 3726 3727 3728 3729 3730 3731 3732 3733 3734 3735 3736 3737 3738 3739 3740 3741 3742 3743 3744 3745 3746 3747 3748 3749
            break;
        case LXC_DEVICE_DETACH:
            ret = lxcDomainDetachDeviceLive(driver, vm, dev_copy);
            break;
        default:
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("unknown domain modify action %d"), action);
            ret = -1;
            break;
        }

        if (ret == -1)
            goto cleanup;
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
        if (virDomainSaveStatus(driver->caps, driver->stateDir, vm) < 0) {
            ret = -1;
            goto cleanup;
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        ret = virDomainSaveConfig(driver->configDir, vmdef);
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false);
            vmdef = NULL;
        }
    }

cleanup:
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
    if (vm)
        virDomainObjUnlock(vm);
    lxcDriverUnlock(driver);
    return ret;
}


static int lxcDomainAttachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
    return lxcDomainModifyDeviceFlags(dom, xml, flags,
                                       LXC_DEVICE_ATTACH);
}


static int lxcDomainAttachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainAttachDeviceFlags(dom, xml,
                                       VIR_DOMAIN_AFFECT_LIVE);
}


static int lxcDomainUpdateDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
    return lxcDomainModifyDeviceFlags(dom, xml, flags,
                                       LXC_DEVICE_UPDATE);
}


static int lxcDomainDetachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
    return lxcDomainModifyDeviceFlags(dom, xml, flags,
                                      LXC_DEVICE_DETACH);
}


static int lxcDomainDetachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainDetachDeviceFlags(dom, xml,
                                      VIR_DOMAIN_AFFECT_LIVE);
}


D
Daniel Veillard 已提交
3750 3751
/* Function Tables */
static virDriver lxcDriver = {
3752
    .no = VIR_DRV_LXC,
3753
    .name = LXC_DRIVER_NAME,
3754 3755 3756 3757 3758 3759 3760 3761
    .open = lxcOpen, /* 0.4.2 */
    .close = lxcClose, /* 0.4.2 */
    .version = lxcVersion, /* 0.4.6 */
    .getHostname = virGetHostname, /* 0.6.3 */
    .nodeGetInfo = nodeGetInfo, /* 0.6.5 */
    .getCapabilities = lxcGetCapabilities, /* 0.6.5 */
    .listDomains = lxcListDomains, /* 0.4.2 */
    .numOfDomains = lxcNumDomains, /* 0.4.2 */
3762
    .listAllDomains = lxcListAllDomains, /* 0.9.13 */
3763 3764 3765 3766 3767 3768 3769
    .domainCreateXML = lxcDomainCreateAndStart, /* 0.4.4 */
    .domainLookupByID = lxcDomainLookupByID, /* 0.4.2 */
    .domainLookupByUUID = lxcDomainLookupByUUID, /* 0.4.2 */
    .domainLookupByName = lxcDomainLookupByName, /* 0.4.2 */
    .domainSuspend = lxcDomainSuspend, /* 0.7.2 */
    .domainResume = lxcDomainResume, /* 0.7.2 */
    .domainDestroy = lxcDomainDestroy, /* 0.4.4 */
3770
    .domainDestroyFlags = lxcDomainDestroyFlags, /* 0.9.4 */
3771 3772 3773 3774 3775 3776
    .domainGetOSType = lxcGetOSType, /* 0.4.2 */
    .domainGetMaxMemory = lxcDomainGetMaxMemory, /* 0.7.2 */
    .domainSetMaxMemory = lxcDomainSetMaxMemory, /* 0.7.2 */
    .domainSetMemory = lxcDomainSetMemory, /* 0.7.2 */
    .domainSetMemoryParameters = lxcDomainSetMemoryParameters, /* 0.8.5 */
    .domainGetMemoryParameters = lxcDomainGetMemoryParameters, /* 0.8.5 */
3777 3778
    .domainSetBlkioParameters = lxcDomainSetBlkioParameters, /* 0.9.8 */
    .domainGetBlkioParameters = lxcDomainGetBlkioParameters, /* 0.9.8 */
3779 3780
    .domainGetInfo = lxcDomainGetInfo, /* 0.4.2 */
    .domainGetState = lxcDomainGetState, /* 0.9.2 */
3781 3782
    .domainGetSecurityLabel = lxcDomainGetSecurityLabel, /* 0.9.10 */
    .nodeGetSecurityModel = lxcNodeGetSecurityModel, /* 0.9.10 */
3783 3784 3785 3786 3787 3788 3789
    .domainGetXMLDesc = lxcDomainGetXMLDesc, /* 0.4.2 */
    .listDefinedDomains = lxcListDefinedDomains, /* 0.4.2 */
    .numOfDefinedDomains = lxcNumDefinedDomains, /* 0.4.2 */
    .domainCreate = lxcDomainStart, /* 0.4.4 */
    .domainCreateWithFlags = lxcDomainStartWithFlags, /* 0.8.2 */
    .domainDefineXML = lxcDomainDefine, /* 0.4.2 */
    .domainUndefine = lxcDomainUndefine, /* 0.4.2 */
3790
    .domainUndefineFlags = lxcDomainUndefineFlags, /* 0.9.4 */
3791 3792 3793 3794 3795
    .domainAttachDevice = lxcDomainAttachDevice, /* 1.0.1 */
    .domainAttachDeviceFlags = lxcDomainAttachDeviceFlags, /* 1.0.1 */
    .domainDetachDevice = lxcDomainDetachDevice, /* 1.0.1 */
    .domainDetachDeviceFlags = lxcDomainDetachDeviceFlags, /* 1.0.1 */
    .domainUpdateDeviceFlags = lxcDomainUpdateDeviceFlags, /* 1.0.1 */
3796 3797 3798 3799
    .domainGetAutostart = lxcDomainGetAutostart, /* 0.7.0 */
    .domainSetAutostart = lxcDomainSetAutostart, /* 0.7.0 */
    .domainGetSchedulerType = lxcGetSchedulerType, /* 0.5.0 */
    .domainGetSchedulerParameters = lxcGetSchedulerParameters, /* 0.5.0 */
3800
    .domainGetSchedulerParametersFlags = lxcGetSchedulerParametersFlags, /* 0.9.2 */
3801
    .domainSetSchedulerParameters = lxcSetSchedulerParameters, /* 0.5.0 */
3802
    .domainSetSchedulerParametersFlags = lxcSetSchedulerParametersFlags, /* 0.9.2 */
3803
    .domainInterfaceStats = lxcDomainInterfaceStats, /* 0.7.3 */
3804
    .nodeGetCPUStats = nodeGetCPUStats, /* 0.9.3 */
3805
    .nodeGetMemoryStats = nodeGetMemoryStats, /* 0.9.3 */
3806 3807
    .nodeGetCellsFreeMemory = nodeGetCellsFreeMemory, /* 0.6.5 */
    .nodeGetFreeMemory = nodeGetFreeMemory, /* 0.6.5 */
3808
    .nodeGetCPUMap = nodeGetCPUMap, /* 1.0.0 */
3809 3810 3811 3812 3813 3814 3815 3816 3817 3818
    .domainEventRegister = lxcDomainEventRegister, /* 0.7.0 */
    .domainEventDeregister = lxcDomainEventDeregister, /* 0.7.0 */
    .isEncrypted = lxcIsEncrypted, /* 0.7.3 */
    .isSecure = lxcIsSecure, /* 0.7.3 */
    .domainIsActive = lxcDomainIsActive, /* 0.7.3 */
    .domainIsPersistent = lxcDomainIsPersistent, /* 0.7.3 */
    .domainIsUpdated = lxcDomainIsUpdated, /* 0.8.6 */
    .domainEventRegisterAny = lxcDomainEventRegisterAny, /* 0.8.0 */
    .domainEventDeregisterAny = lxcDomainEventDeregisterAny, /* 0.8.0 */
    .domainOpenConsole = lxcDomainOpenConsole, /* 0.8.6 */
3819
    .isAlive = lxcIsAlive, /* 0.9.8 */
3820
    .nodeSuspendForDuration = nodeSuspendForDuration, /* 0.9.8 */
3821 3822
    .nodeGetMemoryParameters = nodeGetMemoryParameters, /* 0.10.2 */
    .nodeSetMemoryParameters = nodeSetMemoryParameters, /* 0.10.2 */
3823
    .domainSendProcessSignal = lxcDomainSendProcessSignal, /* 1.0.1 */
3824 3825 3826
    .domainShutdown = lxcDomainShutdown, /* 1.0.1 */
    .domainShutdownFlags = lxcDomainShutdownFlags, /* 1.0.1 */
    .domainReboot = lxcDomainReboot, /* 1.0.1 */
D
Daniel Veillard 已提交
3827 3828
};

3829
static virStateDriver lxcStateDriver = {
3830
    .name = LXC_DRIVER_NAME,
3831 3832
    .initialize = lxcStartup,
    .cleanup = lxcShutdown,
3833
    .reload = lxcReload,
3834 3835
};

D
Daniel Veillard 已提交
3836 3837 3838
int lxcRegister(void)
{
    virRegisterDriver(&lxcDriver);
3839
    virRegisterStateDriver(&lxcStateDriver);
D
Daniel Veillard 已提交
3840 3841
    return 0;
}