qemu_hotplug.c 81.9 KB
Newer Older
1 2 3
/*
 * qemu_hotplug.h: QEMU device hotplug management
 *
4
 * Copyright (C) 2006-2012 Red Hat, Inc.
5 6 7 8 9 10 11 12 13 14 15 16 17
 * Copyright (C) 2006 Daniel P. Berrange
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
18
 * License along with this library.  If not, see
O
Osier Yang 已提交
19
 * <http://www.gnu.org/licenses/>.
20 21 22 23 24 25 26 27 28 29 30 31 32
 *
 * Author: Daniel P. Berrange <berrange@redhat.com>
 */


#include <config.h>

#include "qemu_hotplug.h"
#include "qemu_capabilities.h"
#include "qemu_domain.h"
#include "qemu_command.h"
#include "qemu_bridge_filter.h"
#include "qemu_hostdev.h"
33
#include "domain_audit.h"
34 35 36 37 38
#include "domain_nwfilter.h"
#include "logging.h"
#include "virterror_internal.h"
#include "memory.h"
#include "pci.h"
E
Eric Blake 已提交
39
#include "virfile.h"
40
#include "qemu_cgroup.h"
41
#include "locking/domain_lock.h"
42
#include "network/bridge_driver.h"
43 44
#include "virnetdev.h"
#include "virnetdevbridge.h"
A
Ansis Atteka 已提交
45
#include "virnetdevtap.h"
46
#include "device_conf.h"
47 48 49 50 51 52 53 54 55 56 57 58

#define VIR_FROM_THIS VIR_FROM_QEMU

int qemuDomainChangeEjectableMedia(struct qemud_driver *driver,
                                   virDomainObjPtr vm,
                                   virDomainDiskDefPtr disk,
                                   bool force)
{
    virDomainDiskDefPtr origdisk = NULL;
    int i;
    int ret;
    char *driveAlias = NULL;
59
    qemuDomainObjPrivatePtr priv = vm->privateData;
60 61 62 63 64 65 66 67 68 69

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (vm->def->disks[i]->bus == disk->bus &&
            STREQ(vm->def->disks[i]->dst, disk->dst)) {
            origdisk = vm->def->disks[i];
            break;
        }
    }

    if (!origdisk) {
70 71 72 73
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No device with bus '%s' and target '%s'"),
                       virDomainDiskBusTypeToString(disk->bus),
                       disk->dst);
74 75 76 77
        return -1;
    }

    if (!origdisk->info.alias) {
78 79
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("missing disk device alias name for %s"), origdisk->dst);
80 81 82 83 84
        return -1;
    }

    if (origdisk->device != VIR_DOMAIN_DISK_DEVICE_FLOPPY &&
        origdisk->device != VIR_DOMAIN_DISK_DEVICE_CDROM) {
85 86
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Removable media not supported for %s device"),
87 88 89 90
                        virDomainDiskDeviceTypeToString(disk->device));
        return -1;
    }

91 92
    if (virDomainLockDiskAttach(driver->lockManager, driver->uri,
                                vm, disk) < 0)
93 94
        return -1;

95
    if (virSecurityManagerSetImageLabel(driver->securityManager,
96
                                        vm->def, disk) < 0) {
97 98
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
99
        return -1;
100
    }
101

102
    if (!(driveAlias = qemuDeviceDriveHostAlias(origdisk, priv->caps)))
103 104
        goto error;

105
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121
    if (disk->src) {
        const char *format = NULL;
        if (disk->type != VIR_DOMAIN_DISK_TYPE_DIR) {
            if (disk->driverType)
                format = disk->driverType;
            else if (origdisk->driverType)
                format = origdisk->driverType;
        }
        ret = qemuMonitorChangeMedia(priv->mon,
                                     driveAlias,
                                     disk->src, format);
    } else {
        ret = qemuMonitorEjectMedia(priv->mon, driveAlias, force);
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

122
    virDomainAuditDisk(vm, origdisk->src, disk->src, "update", ret >= 0);
123 124 125 126

    if (ret < 0)
        goto error;

127
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
128
                                            vm->def, origdisk) < 0)
129 130
        VIR_WARN("Unable to restore security label on ejected image %s", origdisk->src);

131 132 133
    if (virDomainLockDiskDetach(driver->lockManager, vm, origdisk) < 0)
        VIR_WARN("Unable to release lock on disk %s", origdisk->src);

134 135 136 137 138 139 140 141 142 143 144 145 146
    VIR_FREE(origdisk->src);
    origdisk->src = disk->src;
    disk->src = NULL;
    origdisk->type = disk->type;

    VIR_FREE(driveAlias);

    virDomainDiskDefFree(disk);

    return ret;

error:
    VIR_FREE(driveAlias);
147

148
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
149
                                            vm->def, disk) < 0)
150
        VIR_WARN("Unable to restore security label on new media %s", disk->src);
151 152 153 154

    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

155 156 157
    return -1;
}

158 159
int
qemuDomainCheckEjectableMedia(struct qemud_driver *driver,
160 161
                             virDomainObjPtr vm,
                             enum qemuDomainAsyncJob asyncJob)
162 163
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
164
    virHashTablePtr table = NULL;
165 166 167
    int ret = -1;
    int i;

168 169 170 171
    if (qemuDomainObjEnterMonitorAsync(driver, vm, asyncJob) == 0) {
        table = qemuMonitorGetBlockInfo(priv->mon);
        qemuDomainObjExitMonitorWithDriver(driver, vm);
    }
172 173 174 175

    if (!table)
        goto cleanup;

176 177
    for (i = 0; i < vm->def->ndisks; i++) {
        virDomainDiskDefPtr disk = vm->def->disks[i];
178
        struct qemuDomainDiskInfo *info;
179

180 181
        if (disk->device == VIR_DOMAIN_DISK_DEVICE_DISK ||
            disk->device == VIR_DOMAIN_DISK_DEVICE_LUN) {
182
                 continue;
183
        }
184

185 186
        info = qemuMonitorBlockInfoLookup(table, disk->info.alias);
        if (!info)
187 188
            goto cleanup;

189
        if (info->tray_open && disk->src)
190 191 192 193 194 195
            VIR_FREE(disk->src);
    }

    ret = 0;

cleanup:
196
    virHashFree(table);
197 198 199
    return ret;
}

200

201 202
int qemuDomainAttachPciDiskDevice(virConnectPtr conn,
                                  struct qemud_driver *driver,
203
                                  virDomainObjPtr vm,
204
                                  virDomainDiskDefPtr disk)
205 206 207 208 209 210
{
    int i, ret;
    const char* type = virDomainDiskBusTypeToString(disk->bus);
    qemuDomainObjPrivatePtr priv = vm->privateData;
    char *devstr = NULL;
    char *drivestr = NULL;
211
    bool releaseaddr = false;
212 213 214

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (STREQ(vm->def->disks[i]->dst, disk->dst)) {
215 216
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("target %s already exists"), disk->dst);
217 218 219 220
            return -1;
        }
    }

221 222
    if (virDomainLockDiskAttach(driver->lockManager, driver->uri,
                                vm, disk) < 0)
223 224
        return -1;

225
    if (virSecurityManagerSetImageLabel(driver->securityManager,
226
                                        vm->def, disk) < 0) {
227 228
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
229
        return -1;
230
    }
231

232
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
233 234
        if (qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, &disk->info) < 0)
            goto error;
235
        releaseaddr = true;
236
        if (qemuAssignDeviceDiskAlias(vm->def, disk, priv->caps) < 0)
237 238
            goto error;

239
        if (!(drivestr = qemuBuildDriveStr(conn, disk, false, priv->caps)))
240 241
            goto error;

242
        if (!(devstr = qemuBuildDriveDevStr(NULL, disk, 0, priv->caps)))
243 244 245 246 247 248 249 250
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0) {
        virReportOOMError();
        goto error;
    }

251
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
252
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
253 254 255 256
        ret = qemuMonitorAddDrive(priv->mon, drivestr);
        if (ret == 0) {
            ret = qemuMonitorAddDevice(priv->mon, devstr);
            if (ret < 0) {
257 258 259 260 261 262 263 264 265 266
                virErrorPtr orig_err = virSaveLastError();
                if (qemuMonitorDriveDel(priv->mon, drivestr) < 0) {
                    VIR_WARN("Unable to remove drive %s (%s) after failed "
                             "qemuMonitorAddDevice",
                             drivestr, devstr);
                }
                if (orig_err) {
                    virSetError(orig_err);
                    virFreeError(orig_err);
                }
267 268 269
            }
        }
    } else {
270
        virDevicePCIAddress guestAddr = disk->info.addr.pci;
271 272 273 274 275 276 277 278 279 280 281
        ret = qemuMonitorAddPCIDisk(priv->mon,
                                    disk->src,
                                    type,
                                    &guestAddr);
        if (ret == 0) {
            disk->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
            memcpy(&disk->info.addr.pci, &guestAddr, sizeof(guestAddr));
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

282
    virDomainAuditDisk(vm, NULL, disk->src, "attach", ret >= 0);
283 284 285 286 287 288 289 290 291 292 293 294 295 296 297

    if (ret < 0)
        goto error;

    virDomainDiskInsertPreAlloced(vm->def, disk);

    VIR_FREE(devstr);
    VIR_FREE(drivestr);

    return 0;

error:
    VIR_FREE(devstr);
    VIR_FREE(drivestr);

298
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
299
        (disk->info.type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
300
        releaseaddr &&
301 302
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        disk->info.addr.pci.slot) < 0)
303 304
        VIR_WARN("Unable to release PCI address on %s", disk->src);

305
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
306
                                            vm->def, disk) < 0)
307 308
        VIR_WARN("Unable to restore security label on %s", disk->src);

309 310 311
    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

312 313 314 315 316 317
    return -1;
}


int qemuDomainAttachPciControllerDevice(struct qemud_driver *driver,
                                        virDomainObjPtr vm,
318
                                        virDomainControllerDefPtr controller)
319 320 321 322 323
{
    int ret = -1;
    const char* type = virDomainControllerTypeToString(controller->type);
    char *devstr = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
324
    bool releaseaddr = false;
325

326 327 328 329 330
    if (virDomainControllerFind(vm->def, controller->type, controller->idx) > 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("target %s:%d already exists"),
                       type, controller->idx);
        return -1;
331 332
    }

333
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
334 335
        if (qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, &controller->info) < 0)
            goto cleanup;
336
        releaseaddr = true;
337 338 339
        if (qemuAssignDeviceControllerAlias(controller) < 0)
            goto cleanup;

340 341
        if (controller->type == VIR_DOMAIN_CONTROLLER_TYPE_USB &&
            controller->model == -1 &&
342
            !qemuCapsGet(priv->caps, QEMU_CAPS_PIIX3_USB_UHCI)) {
343 344
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                           _("USB controller hotplug unsupported in this QEMU binary"));
345 346 347
            goto cleanup;
        }

348
        if (!(devstr = qemuBuildControllerDevStr(vm->def, controller, priv->caps, NULL))) {
349 350 351 352 353 354 355 356 357
            goto cleanup;
        }
    }

    if (VIR_REALLOC_N(vm->def->controllers, vm->def->ncontrollers+1) < 0) {
        virReportOOMError();
        goto cleanup;
    }

358
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
359
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
360 361 362 363 364 365 366 367 368 369 370 371 372 373 374
        ret = qemuMonitorAddDevice(priv->mon, devstr);
    } else {
        ret = qemuMonitorAttachPCIDiskController(priv->mon,
                                                 type,
                                                 &controller->info.addr.pci);
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    if (ret == 0) {
        controller->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
        virDomainControllerInsertPreAlloced(vm->def, controller);
    }

cleanup:
    if ((ret != 0) &&
375
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
376
        (controller->info.type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
377
        releaseaddr &&
378 379
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        controller->info.addr.pci.slot) < 0)
380
        VIR_WARN("Unable to release PCI address on controller");
381 382 383 384 385 386 387 388 389

    VIR_FREE(devstr);
    return ret;
}


static virDomainControllerDefPtr
qemuDomainFindOrCreateSCSIDiskController(struct qemud_driver *driver,
                                         virDomainObjPtr vm,
390
                                         int controller)
391 392 393
{
    int i;
    virDomainControllerDefPtr cont;
394

395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411
    for (i = 0 ; i < vm->def->ncontrollers ; i++) {
        cont = vm->def->controllers[i];

        if (cont->type != VIR_DOMAIN_CONTROLLER_TYPE_SCSI)
            continue;

        if (cont->idx == controller)
            return cont;
    }

    /* No SCSI controller present, for backward compatibility we
     * now hotplug a controller */
    if (VIR_ALLOC(cont) < 0) {
        virReportOOMError();
        return NULL;
    }
    cont->type = VIR_DOMAIN_CONTROLLER_TYPE_SCSI;
412
    cont->idx = controller;
413 414
    cont->model = -1;

415
    VIR_INFO("No SCSI controller present, hotplugging one");
416
    if (qemuDomainAttachPciControllerDevice(driver,
417
                                            vm, cont) < 0) {
418 419 420 421 422
        VIR_FREE(cont);
        return NULL;
    }

    if (!virDomainObjIsActive(vm)) {
423 424
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("guest unexpectedly quit"));
425 426 427 428 429 430 431 432 433
        /* cont doesn't need freeing here, since the reference
         * now held in def->controllers */
        return NULL;
    }

    return cont;
}


434 435
int qemuDomainAttachSCSIDisk(virConnectPtr conn,
                             struct qemud_driver *driver,
436
                             virDomainObjPtr vm,
437
                             virDomainDiskDefPtr disk)
438 439 440 441 442 443 444 445 446 447
{
    int i;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    virDomainControllerDefPtr cont = NULL;
    char *drivestr = NULL;
    char *devstr = NULL;
    int ret = -1;

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (STREQ(vm->def->disks[i]->dst, disk->dst)) {
448 449
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("target %s already exists"), disk->dst);
450 451 452 453
            return -1;
        }
    }

454 455
    if (virDomainLockDiskAttach(driver->lockManager, driver->uri,
                                vm, disk) < 0)
456
        return -1;
457

458
    if (virSecurityManagerSetImageLabel(driver->securityManager,
459
                                        vm->def, disk) < 0) {
460 461
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
462
        return -1;
463
    }
464 465 466

    /* We should have an address already, so make sure */
    if (disk->info.type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_DRIVE) {
467 468 469
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unexpected disk address type %s"),
                       virDomainDeviceAddressTypeToString(disk->info.type));
470 471 472
        goto error;
    }

473 474
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (qemuAssignDeviceDiskAlias(vm->def, disk, priv->caps) < 0)
475
            goto error;
476
        if (!(devstr = qemuBuildDriveDevStr(vm->def, disk, 0, priv->caps)))
477 478 479
            goto error;
    }

480
    if (!(drivestr = qemuBuildDriveStr(conn, disk, false, priv->caps)))
481 482 483
        goto error;

    for (i = 0 ; i <= disk->info.addr.drive.controller ; i++) {
484
        cont = qemuDomainFindOrCreateSCSIDiskController(driver, vm, i);
485 486 487 488 489 490 491 492 493 494
        if (!cont)
            goto error;
    }

    /* Tell clang that "cont" is non-NULL.
       This is because disk->info.addr.driver.controller is unsigned,
       and hence the above loop must iterate at least once.  */
    sa_assert (cont);

    if (cont->info.type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) {
495 496
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("SCSI controller %d was missing its PCI address"), cont->idx);
497 498 499 500 501 502 503 504
        goto error;
    }

    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0) {
        virReportOOMError();
        goto error;
    }

505
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
506
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526
        ret = qemuMonitorAddDrive(priv->mon, drivestr);
        if (ret == 0) {
            ret = qemuMonitorAddDevice(priv->mon, devstr);
            if (ret < 0) {
                VIR_WARN("qemuMonitorAddDevice failed on %s (%s)",
                         drivestr, devstr);
                /* XXX should call 'drive_del' on error but this does not
                   exist yet */
            }
        }
    } else {
        virDomainDeviceDriveAddress driveAddr;
        ret = qemuMonitorAttachDrive(priv->mon,
                                     drivestr,
                                     &cont->info.addr.pci,
                                     &driveAddr);
        if (ret == 0) {
            /* XXX we should probably validate that the addr matches
             * our existing defined addr instead of overwriting */
            disk->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_DRIVE;
527 528
            disk->info.addr.drive.bus = driveAddr.bus;
            disk->info.addr.drive.unit = driveAddr.unit;
529 530 531 532
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

533
    virDomainAuditDisk(vm, NULL, disk->src, "attach", ret >= 0);
534 535 536 537 538 539 540 541 542 543 544 545 546 547 548

    if (ret < 0)
        goto error;

    virDomainDiskInsertPreAlloced(vm->def, disk);

    VIR_FREE(devstr);
    VIR_FREE(drivestr);

    return 0;

error:
    VIR_FREE(devstr);
    VIR_FREE(drivestr);

549
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
550
                                            vm->def, disk) < 0)
551 552
        VIR_WARN("Unable to restore security label on %s", disk->src);

553 554 555
    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

556 557 558 559
    return -1;
}


560 561
int qemuDomainAttachUsbMassstorageDevice(virConnectPtr conn,
                                         struct qemud_driver *driver,
562
                                         virDomainObjPtr vm,
563
                                         virDomainDiskDefPtr disk)
564 565 566 567 568 569 570 571
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    int i, ret;
    char *drivestr = NULL;
    char *devstr = NULL;

    for (i = 0 ; i < vm->def->ndisks ; i++) {
        if (STREQ(vm->def->disks[i]->dst, disk->dst)) {
572 573
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("target %s already exists"), disk->dst);
574 575 576 577
            return -1;
        }
    }

578 579
    if (virDomainLockDiskAttach(driver->lockManager, driver->uri,
                                vm, disk) < 0)
580 581
        return -1;

582
    if (virSecurityManagerSetImageLabel(driver->securityManager,
583
                                        vm->def, disk) < 0) {
584 585
        if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
            VIR_WARN("Unable to release lock on %s", disk->src);
586
        return -1;
587
    }
588

589
    /* XXX not correct once we allow attaching a USB CDROM */
590
    if (!disk->src) {
591 592
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       "%s", _("disk source path is missing"));
593 594 595
        goto error;
    }

596 597
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (qemuAssignDeviceDiskAlias(vm->def, disk, priv->caps) < 0)
598
            goto error;
599
        if (!(drivestr = qemuBuildDriveStr(conn, disk, false, priv->caps)))
600
            goto error;
601
        if (!(devstr = qemuBuildDriveDevStr(NULL, disk, 0, priv->caps)))
602 603 604 605 606 607 608 609
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0) {
        virReportOOMError();
        goto error;
    }

610
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
611
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
612 613 614 615 616 617 618 619 620 621 622 623 624 625 626
        ret = qemuMonitorAddDrive(priv->mon, drivestr);
        if (ret == 0) {
            ret = qemuMonitorAddDevice(priv->mon, devstr);
            if (ret < 0) {
                VIR_WARN("qemuMonitorAddDevice failed on %s (%s)",
                         drivestr, devstr);
                /* XXX should call 'drive_del' on error but this does not
                   exist yet */
            }
        }
    } else {
        ret = qemuMonitorAddUSBDisk(priv->mon, disk->src);
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

627
    virDomainAuditDisk(vm, NULL, disk->src, "attach", ret >= 0);
628 629 630 631 632 633 634 635 636 637 638 639 640 641 642

    if (ret < 0)
        goto error;

    virDomainDiskInsertPreAlloced(vm->def, disk);

    VIR_FREE(devstr);
    VIR_FREE(drivestr);

    return 0;

error:
    VIR_FREE(devstr);
    VIR_FREE(drivestr);

643
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
644
                                            vm->def, disk) < 0)
645 646
        VIR_WARN("Unable to restore security label on %s", disk->src);

647 648 649
    if (virDomainLockDiskDetach(driver->lockManager, vm, disk) < 0)
        VIR_WARN("Unable to release lock on %s", disk->src);

650 651 652 653 654 655 656 657
    return -1;
}


/* XXX conn required for network -> bridge resolution */
int qemuDomainAttachNetDevice(virConnectPtr conn,
                              struct qemud_driver *driver,
                              virDomainObjPtr vm,
658
                              virDomainNetDefPtr net)
659 660 661 662
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    char *tapfd_name = NULL;
    int tapfd = -1;
663 664
    char *vhostfd_name = NULL;
    int vhostfd = -1;
665 666
    char *nicstr = NULL;
    char *netstr = NULL;
A
Ansis Atteka 已提交
667
    virNetDevVPortProfilePtr vport = NULL;
668
    int ret = -1;
669
    virDevicePCIAddress guestAddr;
670
    int vlan;
671
    bool releaseaddr = false;
672 673
    bool iface_connected = false;
    int actualType;
674

675 676 677
    /* preallocate new slot for device */
    if (VIR_REALLOC_N(vm->def->nets, vm->def->nnets+1) < 0) {
        virReportOOMError();
678 679 680
        return -1;
    }

681 682 683 684 685
    /* If appropriate, grab a physical device from the configured
     * network's pool of devices, or resolve bridge device name
     * to the one defined in the network definition.
     */
    if (networkAllocateActualDevice(net) < 0)
686
        return -1;
687 688

    actualType = virDomainNetGetActualType(net);
689 690 691 692 693 694 695 696 697 698 699 700

    if (actualType == VIR_DOMAIN_NET_TYPE_HOSTDEV) {
        /* This is really a "smart hostdev", so it should be attached
         * as a hostdev (the hostdev code will reach over into the
         * netdev-specific code as appropriate), then also added to
         * the nets list (see cleanup:) if successful.
         */
        ret = qemuDomainAttachHostDevice(driver, vm,
                                         virDomainNetGetActualHostdev(net));
        goto cleanup;
    }

701
    if (!qemuCapsGet(priv->caps, QEMU_CAPS_HOST_NET_ADD)) {
702 703
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("installed qemu version does not support host_net_add"));
704 705 706
        goto cleanup;
    }

707 708
    if (actualType == VIR_DOMAIN_NET_TYPE_BRIDGE ||
        actualType == VIR_DOMAIN_NET_TYPE_NETWORK) {
R
Richa Marwaha 已提交
709 710 711 712 713 714 715
        /*
         * If type=bridge then we attempt to allocate the tap fd here only if
         * running under a privilged user or -netdev bridge option is not
         * supported.
         */
        if (actualType == VIR_DOMAIN_NET_TYPE_NETWORK ||
            driver->privileged ||
716
            (!qemuCapsGet (priv->caps, QEMU_CAPS_NETDEV_BRIDGE))) {
R
Richa Marwaha 已提交
717
            if ((tapfd = qemuNetworkIfaceConnect(vm->def, conn, driver, net,
718
                                                 priv->caps)) < 0)
R
Richa Marwaha 已提交
719 720
                goto cleanup;
            iface_connected = true;
721
            if (qemuOpenVhostNet(vm->def, net, priv->caps, &vhostfd) < 0)
R
Richa Marwaha 已提交
722 723
                goto cleanup;
        }
724
    } else if (actualType == VIR_DOMAIN_NET_TYPE_DIRECT) {
725
        if ((tapfd = qemuPhysIfaceConnect(vm->def, driver, net,
726
                                          priv->caps,
727
                                          VIR_NETDEV_VPORT_PROFILE_OP_CREATE)) < 0)
728 729
            goto cleanup;
        iface_connected = true;
730
        if (qemuOpenVhostNet(vm->def, net, priv->caps, &vhostfd) < 0)
731
            goto cleanup;
732 733
    }

734 735
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NET_NAME) ||
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
736 737 738 739
        if (qemuAssignDeviceNetAlias(vm->def, net, -1) < 0)
            goto cleanup;
    }

740
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
741 742 743
        qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, &net->info) < 0)
        goto cleanup;

744 745
    releaseaddr = true;

746 747
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
748 749 750 751 752
        vlan = -1;
    } else {
        vlan = qemuDomainNetVLAN(net);

        if (vlan < 0) {
753 754
            virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                           _("Unable to attach network devices without vlan"));
755 756 757 758 759 760 761 762 763
            goto cleanup;
        }
    }

    if (tapfd != -1) {
        if (virAsprintf(&tapfd_name, "fd-%s", net->info.alias) < 0)
            goto no_memory;
    }

764 765 766 767 768
    if (vhostfd != -1) {
        if (virAsprintf(&vhostfd_name, "vhostfd-%s", net->info.alias) < 0)
            goto no_memory;
    }

769 770 771
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (!(netstr = qemuBuildHostNetStr(net, driver, priv->caps,
R
Richa Marwaha 已提交
772 773
                                           ',', -1, tapfd_name,
                                           vhostfd_name)))
774
            goto cleanup;
775
    } else {
776
        if (!(netstr = qemuBuildHostNetStr(net, driver, priv->caps,
R
Richa Marwaha 已提交
777 778
                                           ' ', vlan, tapfd_name,
                                           vhostfd_name)))
779
            goto cleanup;
780 781
    }

782
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
783 784
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
785 786
        if (qemuMonitorAddNetdev(priv->mon, netstr, tapfd, tapfd_name,
                                 vhostfd, vhostfd_name) < 0) {
787
            qemuDomainObjExitMonitorWithDriver(driver, vm);
788
            virDomainAuditNet(vm, NULL, net, "attach", false);
789
            goto cleanup;
790 791
        }
    } else {
792 793
        if (qemuMonitorAddHostNetwork(priv->mon, netstr, tapfd, tapfd_name,
                                      vhostfd, vhostfd_name) < 0) {
794
            qemuDomainObjExitMonitorWithDriver(driver, vm);
795
            virDomainAuditNet(vm, NULL, net, "attach", false);
796
            goto cleanup;
797 798 799 800 801
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    VIR_FORCE_CLOSE(tapfd);
802
    VIR_FORCE_CLOSE(vhostfd);
803 804

    if (!virDomainObjIsActive(vm)) {
805 806
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("guest unexpectedly quit"));
807 808 809
        goto cleanup;
    }

810 811
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
        if (!(nicstr = qemuBuildNicDevStr(net, vlan, 0, priv->caps)))
812 813 814 815 816 817
            goto try_remove;
    } else {
        if (!(nicstr = qemuBuildNicStr(net, NULL, vlan)))
            goto try_remove;
    }

818
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
819
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
820 821
        if (qemuMonitorAddDevice(priv->mon, nicstr) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
822
            virDomainAuditNet(vm, NULL, net, "attach", false);
823 824 825
            goto try_remove;
        }
    } else {
826
        guestAddr = net->info.addr.pci;
827 828 829
        if (qemuMonitorAddPCINetwork(priv->mon, nicstr,
                                     &guestAddr) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
830
            virDomainAuditNet(vm, NULL, net, "attach", false);
831 832 833 834 835 836 837
            goto try_remove;
        }
        net->info.type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
        memcpy(&net->info.addr.pci, &guestAddr, sizeof(guestAddr));
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

838 839 840
    /* set link state */
    if (net->linkstate == VIR_DOMAIN_NET_INTERFACE_LINK_STATE_DOWN) {
        if (!net->info.alias) {
841 842
            virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                           _("device alias not found: cannot set link state to down"));
843 844 845
        } else {
            qemuDomainObjEnterMonitorWithDriver(driver, vm);

846
            if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV)) {
847 848 849 850 851 852
                if (qemuMonitorSetLink(priv->mon, net->info.alias, VIR_DOMAIN_NET_INTERFACE_LINK_STATE_DOWN) < 0) {
                    qemuDomainObjExitMonitorWithDriver(driver, vm);
                    virDomainAuditNet(vm, NULL, net, "attach", false);
                    goto try_remove;
                }
            } else {
853
                virReportError(VIR_ERR_OPERATION_FAILED, "%s",
854
                               _("setting of link state not supported: Link is up"));
855 856 857 858 859 860 861
            }

            qemuDomainObjExitMonitorWithDriver(driver, vm);
        }
        /* link set to down */
    }

862
    virDomainAuditNet(vm, NULL, net, "attach", true);
863 864 865 866

    ret = 0;

cleanup:
867 868 869
    if (!ret) {
        vm->def->nets[vm->def->nnets++] = net;
    } else {
870
        if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
871 872 873 874 875 876
            (net->info.type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
            releaseaddr &&
            qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                            net->info.addr.pci.slot) < 0)
            VIR_WARN("Unable to release PCI address on NIC");

877
        if (iface_connected) {
878
            virDomainConfNWFilterTeardown(net);
879

880 881 882 883 884
            vport = virDomainNetGetActualVirtPortProfile(net);
            if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
               ignore_value(virNetDevOpenvswitchRemovePort(
                               virDomainNetGetActualBridgeName(net), net->ifname));
        }
A
Ansis Atteka 已提交
885

886 887
        networkReleaseActualDevice(net);
    }
888 889 890 891 892

    VIR_FREE(nicstr);
    VIR_FREE(netstr);
    VIR_FREE(tapfd_name);
    VIR_FORCE_CLOSE(tapfd);
893 894
    VIR_FREE(vhostfd_name);
    VIR_FORCE_CLOSE(vhostfd);
895 896 897 898 899 900 901 902

    return ret;

try_remove:
    if (!virDomainObjIsActive(vm))
        goto cleanup;

    if (vlan < 0) {
903 904
        if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
            qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
905 906 907
            char *netdev_name;
            if (virAsprintf(&netdev_name, "host%s", net->info.alias) < 0)
                goto no_memory;
908
            qemuDomainObjEnterMonitorWithDriver(driver, vm);
909 910 911 912 913 914
            if (qemuMonitorRemoveNetdev(priv->mon, netdev_name) < 0)
                VIR_WARN("Failed to remove network backend for netdev %s",
                         netdev_name);
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            VIR_FREE(netdev_name);
        } else {
915
            VIR_WARN("Unable to remove network backend");
916 917 918 919 920
        }
    } else {
        char *hostnet_name;
        if (virAsprintf(&hostnet_name, "host%s", net->info.alias) < 0)
            goto no_memory;
921
        qemuDomainObjEnterMonitorWithDriver(driver, vm);
922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937
        if (qemuMonitorRemoveHostNetwork(priv->mon, vlan, hostnet_name) < 0)
            VIR_WARN("Failed to remove network backend for vlan %d, net %s",
                     vlan, hostnet_name);
        qemuDomainObjExitMonitorWithDriver(driver, vm);
        VIR_FREE(hostnet_name);
    }
    goto cleanup;

no_memory:
    virReportOOMError();
    goto cleanup;
}


int qemuDomainAttachHostPciDevice(struct qemud_driver *driver,
                                  virDomainObjPtr vm,
938
                                  virDomainHostdevDefPtr hostdev)
939 940 941 942 943 944
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    int ret;
    char *devstr = NULL;
    int configfd = -1;
    char *configfd_name = NULL;
945
    bool releaseaddr = false;
946 947 948 949 950 951

    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0) {
        virReportOOMError();
        return -1;
    }

952 953
    if (qemuPrepareHostdevPCIDevices(driver, vm->def->name, vm->def->uuid,
                                     &hostdev, 1) < 0)
954 955
        return -1;

956
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
957 958
        if (qemuAssignDeviceHostdevAlias(vm->def, hostdev, -1) < 0)
            goto error;
959
        if (qemuDomainPCIAddressEnsureAddr(priv->pciaddrs, hostdev->info) < 0)
960
            goto error;
961
        releaseaddr = true;
962
        if (qemuCapsGet(priv->caps, QEMU_CAPS_PCI_CONFIGFD)) {
963 964 965
            configfd = qemuOpenPCIConfig(hostdev);
            if (configfd >= 0) {
                if (virAsprintf(&configfd_name, "fd-%s",
966
                                hostdev->info->alias) < 0) {
967 968 969 970 971 972 973
                    virReportOOMError();
                    goto error;
                }
            }
        }

        if (!virDomainObjIsActive(vm)) {
974 975
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("guest unexpectedly quit during hotplug"));
976 977 978
            goto error;
        }

979
        if (!(devstr = qemuBuildPCIHostdevDevStr(hostdev, configfd_name,
980
                                                 priv->caps)))
981 982
            goto error;

983
        qemuDomainObjEnterMonitorWithDriver(driver, vm);
984 985
        ret = qemuMonitorAddDeviceWithFd(priv->mon, devstr,
                                         configfd, configfd_name);
986 987
        qemuDomainObjExitMonitorWithDriver(driver, vm);
    } else {
988
        virDevicePCIAddress guestAddr = hostdev->info->addr.pci;
989

990
        qemuDomainObjEnterMonitorWithDriver(driver, vm);
991 992 993 994 995
        ret = qemuMonitorAddPCIHostDevice(priv->mon,
                                          &hostdev->source.subsys.u.pci,
                                          &guestAddr);
        qemuDomainObjExitMonitorWithDriver(driver, vm);

996 997
        hostdev->info->type = VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI;
        memcpy(&hostdev->info->addr.pci, &guestAddr, sizeof(guestAddr));
998
    }
999
    virDomainAuditHostdev(vm, hostdev, "attach", ret == 0);
1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011
    if (ret < 0)
        goto error;

    vm->def->hostdevs[vm->def->nhostdevs++] = hostdev;

    VIR_FREE(devstr);
    VIR_FREE(configfd_name);
    VIR_FORCE_CLOSE(configfd);

    return 0;

error:
1012
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
1013
        (hostdev->info->type == VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI) &&
1014
        releaseaddr &&
1015
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
1016
                                        hostdev->info->addr.pci.slot) < 0)
1017
        VIR_WARN("Unable to release PCI address on host device");
1018

1019
    qemuDomainReAttachHostdevDevices(driver, vm->def->name, &hostdev, 1);
1020 1021 1022 1023 1024 1025 1026 1027 1028

    VIR_FREE(devstr);
    VIR_FREE(configfd_name);
    VIR_FORCE_CLOSE(configfd);

    return -1;
}


1029 1030 1031 1032 1033 1034
int qemuDomainAttachRedirdevDevice(struct qemud_driver *driver,
                                   virDomainObjPtr vm,
                                   virDomainRedirdevDefPtr redirdev)
{
    int ret;
    qemuDomainObjPrivatePtr priv = vm->privateData;
1035
    virDomainDefPtr def = vm->def;
1036 1037
    char *devstr = NULL;

1038
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1039 1040
        if (qemuAssignDeviceRedirdevAlias(vm->def, redirdev, -1) < 0)
            goto error;
1041
        if (!(devstr = qemuBuildRedirdevDevStr(def, redirdev, priv->caps)))
1042 1043 1044 1045 1046 1047 1048 1049 1050
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->redirdevs, vm->def->nredirdevs+1) < 0) {
        virReportOOMError();
        goto error;
    }

    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1051
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE))
1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072
        ret = qemuMonitorAddDevice(priv->mon, devstr);
    else
        goto error;

    qemuDomainObjExitMonitorWithDriver(driver, vm);
    virDomainAuditRedirdev(vm, redirdev, "attach", ret == 0);
    if (ret < 0)
        goto error;

    vm->def->redirdevs[vm->def->nredirdevs++] = redirdev;

    VIR_FREE(devstr);

    return 0;

error:
    VIR_FREE(devstr);
    return -1;

}

1073 1074
int qemuDomainAttachHostUsbDevice(struct qemud_driver *driver,
                                  virDomainObjPtr vm,
1075
                                  virDomainHostdevDefPtr hostdev)
1076 1077 1078 1079 1080
{
    int ret;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    char *devstr = NULL;

1081
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1082 1083
        if (qemuAssignDeviceHostdevAlias(vm->def, hostdev, -1) < 0)
            goto error;
1084
        if (!(devstr = qemuBuildUSBHostdevDevStr(hostdev, priv->caps)))
1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095
            goto error;
    }

    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0) {
        virReportOOMError();
        goto error;
    }

    if (qemuCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virCgroupPtr cgroup = NULL;
        usbDevice *usb;
1096
        qemuCgroupData data;
1097 1098

        if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) !=0 ) {
1099 1100 1101
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unable to find cgroup for %s"),
                           vm->def->name);
1102 1103 1104 1105 1106 1107 1108
            goto error;
        }

        if ((usb = usbGetDevice(hostdev->source.subsys.u.usb.bus,
                                hostdev->source.subsys.u.usb.device)) == NULL)
            goto error;

1109 1110
        data.vm = vm;
        data.cgroup = cgroup;
1111
        if (usbDeviceFileIterate(usb, qemuSetupHostUsbDeviceCgroup, &data) < 0)
1112 1113 1114
            goto error;
    }

1115
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1116
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE))
1117 1118 1119 1120 1121 1122
        ret = qemuMonitorAddDevice(priv->mon, devstr);
    else
        ret = qemuMonitorAddUSBDeviceExact(priv->mon,
                                           hostdev->source.subsys.u.usb.bus,
                                           hostdev->source.subsys.u.usb.device);
    qemuDomainObjExitMonitorWithDriver(driver, vm);
1123
    virDomainAuditHostdev(vm, hostdev, "attach", ret == 0);
1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138 1139
    if (ret < 0)
        goto error;

    vm->def->hostdevs[vm->def->nhostdevs++] = hostdev;

    VIR_FREE(devstr);

    return 0;

error:
    VIR_FREE(devstr);
    return -1;
}

int qemuDomainAttachHostDevice(struct qemud_driver *driver,
                               virDomainObjPtr vm,
1140
                               virDomainHostdevDefPtr hostdev)
1141
{
1142 1143 1144
    usbDeviceList *list;
    usbDevice *usb = NULL;

1145
    if (hostdev->mode != VIR_DOMAIN_HOSTDEV_MODE_SUBSYS) {
1146 1147 1148
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev mode '%s' not supported"),
                       virDomainHostdevModeTypeToString(hostdev->mode));
1149 1150 1151
        return -1;
    }

1152 1153
    if (!(list = usbDeviceListNew()))
        goto cleanup;
1154

1155 1156 1157 1158 1159
    if (hostdev->source.subsys.type == VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB) {
        unsigned vendor = hostdev->source.subsys.u.usb.vendor;
        unsigned product = hostdev->source.subsys.u.usb.product;
        unsigned bus = hostdev->source.subsys.u.usb.bus;
        unsigned device = hostdev->source.subsys.u.usb.device;
1160

1161 1162
        if (vendor && bus) {
            usb = usbFindDevice(vendor, product, bus, device);
1163

1164 1165 1166 1167
        } else if (vendor && !bus) {
            usbDeviceList *devs = usbFindDeviceByVendor(vendor, product);
            if (!devs)
                goto cleanup;
1168

1169
            if (usbDeviceListCount(devs) > 1) {
1170 1171 1172
                virReportError(VIR_ERR_OPERATION_FAILED,
                               _("multiple USB devices for %x:%x, "
                                 "use <address> to specify one"), vendor, product);
1173 1174 1175 1176 1177 1178
                usbDeviceListFree(devs);
                goto cleanup;
            }
            usb = usbDeviceListGet(devs, 0);
            usbDeviceListSteal(devs, usb);
            usbDeviceListFree(devs);
1179

1180 1181
            hostdev->source.subsys.u.usb.bus = usbDeviceGetBus(usb);
            hostdev->source.subsys.u.usb.device = usbDeviceGetDevno(usb);
1182

1183 1184 1185
        } else if (!vendor && bus) {
            usb = usbFindDeviceByBus(bus, device);
        }
1186

1187 1188 1189 1190 1191
        if (!usb)
            goto cleanup;

        if (usbDeviceListAdd(list, usb) < 0) {
            usbFreeDevice(usb);
M
Marc-André Lureau 已提交
1192
            usb = NULL;
1193 1194 1195
            goto cleanup;
        }

1196 1197
        if (qemuPrepareHostdevUSBDevices(driver, vm->def->name, list) < 0) {
            usb = NULL;
1198
            goto cleanup;
1199
        }
1200 1201 1202

        usbDeviceListSteal(list, usb);
    }
1203

1204
    if (virSecurityManagerSetHostdevLabel(driver->securityManager,
1205
                                          vm->def, hostdev) < 0)
1206
        goto cleanup;
1207 1208 1209 1210

    switch (hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI:
        if (qemuDomainAttachHostPciDevice(driver, vm,
1211
                                          hostdev) < 0)
1212 1213 1214 1215 1216
            goto error;
        break;

    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        if (qemuDomainAttachHostUsbDevice(driver, vm,
1217
                                          hostdev) < 0)
1218 1219 1220 1221
            goto error;
        break;

    default:
1222 1223 1224
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev subsys type '%s' not supported"),
                       virDomainHostdevSubsysTypeToString(hostdev->source.subsys.type));
1225 1226 1227
        goto error;
    }

1228
    usbDeviceListFree(list);
1229 1230 1231
    return 0;

error:
1232
    if (virSecurityManagerRestoreHostdevLabel(driver->securityManager,
1233
                                              vm->def, hostdev) < 0)
1234
        VIR_WARN("Unable to restore host device labelling on hotplug fail");
1235

1236 1237
cleanup:
    usbDeviceListFree(list);
1238 1239
    if (usb)
        usbDeviceListSteal(driver->activeUsbHostdevs, usb);
1240 1241 1242
    return -1;
}

1243 1244 1245 1246 1247 1248
static virDomainNetDefPtr qemuDomainFindNet(virDomainObjPtr vm,
                                            virDomainNetDefPtr dev)
{
    int i;

    for (i = 0; i < vm->def->nnets; i++) {
1249
        if (virMacAddrCmp(&vm->def->nets[i]->mac, &dev->mac) == 0)
1250 1251 1252 1253 1254 1255
            return vm->def->nets[i];
    }

    return NULL;
}

1256 1257 1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268
static
int qemuDomainChangeNetBridge(virDomainObjPtr vm,
                              virDomainNetDefPtr olddev,
                              virDomainNetDefPtr newdev)
{
    int ret = -1;
    char *oldbridge = olddev->data.bridge.brname;
    char *newbridge = newdev->data.bridge.brname;

    VIR_DEBUG("Change bridge for interface %s: %s -> %s",
              olddev->ifname, oldbridge, newbridge);

    if (virNetDevExists(newbridge) != 1) {
1269 1270
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("bridge %s doesn't exist"), newbridge);
1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290
        return -1;
    }

    if (oldbridge) {
        ret = virNetDevBridgeRemovePort(oldbridge, olddev->ifname);
        virDomainAuditNet(vm, olddev, NULL, "detach", ret == 0);
        if (ret < 0)
            return -1;
    }

    /* move newbridge into olddev now so Audit log is correct */
    olddev->data.bridge.brname = newbridge;
    ret = virNetDevBridgeAddPort(newbridge, olddev->ifname);
    virDomainAuditNet(vm, NULL, olddev, "attach", ret == 0);
    if (ret < 0) {
        /* restore oldbridge to olddev */
        olddev->data.bridge.brname = oldbridge;
        ret = virNetDevBridgeAddPort(oldbridge, olddev->ifname);
        virDomainAuditNet(vm, NULL, olddev, "attach", ret == 0);
        if (ret < 0) {
1291
            virReportError(VIR_ERR_OPERATION_FAILED,
1292
                           _("unable to recover former state by adding port "
1293
                             "to bridge %s"), oldbridge);
1294 1295 1296 1297 1298 1299 1300 1301 1302
        }
        return -1;
    }
    /* oldbridge no longer needed, and newbridge moved to olddev */
    VIR_FREE(oldbridge);
    newdev->data.bridge.brname = NULL;
    return 0;
}

1303 1304 1305 1306 1307 1308 1309 1310 1311 1312 1313
int qemuDomainChangeNetLinkState(struct qemud_driver *driver,
                                 virDomainObjPtr vm,
                                 virDomainNetDefPtr dev,
                                 int linkstate)
{
    int ret = -1;
    qemuDomainObjPrivatePtr priv = vm->privateData;

    VIR_DEBUG("dev: %s, state: %d", dev->info.alias, linkstate);

    if (!dev->info.alias) {
1314 1315
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("can't change link state: device alias not found"));
1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343
        return -1;
    }

    qemuDomainObjEnterMonitorWithDriver(driver, vm);

    ret = qemuMonitorSetLink(priv->mon, dev->info.alias, linkstate);
    if (ret < 0)
        goto cleanup;

    /* modify the device configuration */
    dev->linkstate = linkstate;

cleanup:
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    return ret;
}

int qemuDomainChangeNet(struct qemud_driver *driver,
                        virDomainObjPtr vm,
                        virDomainPtr dom ATTRIBUTE_UNUSED,
                        virDomainNetDefPtr dev)

{
    virDomainNetDefPtr olddev = qemuDomainFindNet(vm, dev);
    int ret = 0;

    if (!olddev) {
1344 1345
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot find existing network device to modify"));
1346 1347 1348 1349
        return -1;
    }

    if (olddev->type != dev->type) {
1350 1351
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot change network interface type"));
1352 1353 1354
        return -1;
    }

1355 1356 1357 1358 1359
    if (!virNetDevVPortProfileEqual(olddev->virtPortProfile, dev->virtPortProfile)) {
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot change <virtualport> settings"));
    }

1360 1361 1362 1363 1364 1365
    switch (olddev->type) {
    case VIR_DOMAIN_NET_TYPE_USER:
        break;

    case VIR_DOMAIN_NET_TYPE_ETHERNET:
        if (STRNEQ_NULLABLE(olddev->data.ethernet.dev, dev->data.ethernet.dev) ||
1366
            STRNEQ_NULLABLE(olddev->script, dev->script) ||
1367
            STRNEQ_NULLABLE(olddev->data.ethernet.ipaddr, dev->data.ethernet.ipaddr)) {
1368 1369
            virReportError(VIR_ERR_NO_SUPPORT, "%s",
                           _("cannot modify ethernet network device configuration"));
1370 1371 1372 1373 1374 1375 1376 1377 1378
            return -1;
        }
        break;

    case VIR_DOMAIN_NET_TYPE_SERVER:
    case VIR_DOMAIN_NET_TYPE_CLIENT:
    case VIR_DOMAIN_NET_TYPE_MCAST:
        if (STRNEQ_NULLABLE(olddev->data.socket.address, dev->data.socket.address) ||
            olddev->data.socket.port != dev->data.socket.port) {
1379 1380
            virReportError(VIR_ERR_NO_SUPPORT, "%s",
                           _("cannot modify network socket device configuration"));
1381 1382 1383 1384 1385 1386
            return -1;
        }
        break;

    case VIR_DOMAIN_NET_TYPE_NETWORK:
        if (STRNEQ_NULLABLE(olddev->data.network.name, dev->data.network.name) ||
1387
            STRNEQ_NULLABLE(olddev->data.network.portgroup, dev->data.network.portgroup)) {
1388 1389
            virReportError(VIR_ERR_NO_SUPPORT, "%s",
                           _("cannot modify network device configuration"));
1390 1391 1392 1393 1394
            return -1;
        }

        break;

1395
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
1396
       /* allow changing brname */
1397 1398
       break;

1399 1400
    case VIR_DOMAIN_NET_TYPE_INTERNAL:
        if (STRNEQ_NULLABLE(olddev->data.internal.name, dev->data.internal.name)) {
1401 1402
            virReportError(VIR_ERR_NO_SUPPORT, "%s",
                           _("cannot modify internal network device configuration"));
1403 1404 1405 1406 1407 1408
            return -1;
        }
        break;

    case VIR_DOMAIN_NET_TYPE_DIRECT:
        if (STRNEQ_NULLABLE(olddev->data.direct.linkdev, dev->data.direct.linkdev) ||
1409
            olddev->data.direct.mode != dev->data.direct.mode) {
1410 1411
            virReportError(VIR_ERR_NO_SUPPORT, "%s",
                           _("cannot modify direct network device configuration"));
1412 1413 1414 1415 1416
            return -1;
        }
        break;

    default:
1417 1418 1419
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unable to change config on '%s' network type"),
                       virDomainNetTypeToString(dev->type));
1420 1421 1422 1423 1424 1425 1426
        break;

    }

    /* all other unmodifiable parameters */
    if (STRNEQ_NULLABLE(olddev->model, dev->model) ||
        STRNEQ_NULLABLE(olddev->filter, dev->filter)) {
1427 1428
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot modify network device configuration"));
1429 1430 1431 1432 1433 1434
        return -1;
    }

    /* check if device name has been set, if no, retain the autogenerated one */
    if (dev->ifname &&
        STRNEQ_NULLABLE(olddev->ifname, dev->ifname)) {
1435 1436
        virReportError(VIR_ERR_NO_SUPPORT, "%s",
                       _("cannot modify network device configuration"));
1437 1438 1439
        return -1;
    }

1440 1441 1442 1443 1444 1445 1446
    if (olddev->type == VIR_DOMAIN_NET_TYPE_BRIDGE
        && STRNEQ_NULLABLE(olddev->data.bridge.brname,
                           dev->data.bridge.brname)) {
        if ((ret = qemuDomainChangeNetBridge(vm, olddev, dev)) < 0)
            return ret;
    }

1447 1448 1449 1450 1451 1452 1453 1454 1455
    if (olddev->linkstate != dev->linkstate) {
        if ((ret = qemuDomainChangeNetLinkState(driver, vm, olddev, dev->linkstate)) < 0)
            return ret;
    }

    return ret;
}


1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476

static virDomainGraphicsDefPtr qemuDomainFindGraphics(virDomainObjPtr vm,
                                                      virDomainGraphicsDefPtr dev)
{
    int i;

    for (i = 0 ; i < vm->def->ngraphics ; i++) {
        if (vm->def->graphics[i]->type == dev->type)
            return vm->def->graphics[i];
    }

    return NULL;
}


int
qemuDomainChangeGraphics(struct qemud_driver *driver,
                         virDomainObjPtr vm,
                         virDomainGraphicsDefPtr dev)
{
    virDomainGraphicsDefPtr olddev = qemuDomainFindGraphics(vm, dev);
1477
    const char *oldListenAddr, *newListenAddr;
1478
    const char *oldListenNetwork, *newListenNetwork;
1479 1480 1481
    int ret = -1;

    if (!olddev) {
1482 1483
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("cannot find existing graphics device to modify"));
1484 1485 1486
        return -1;
    }

1487 1488
    oldListenAddr = virDomainGraphicsListenGetAddress(olddev, 0);
    newListenAddr = virDomainGraphicsListenGetAddress(dev, 0);
1489 1490
    oldListenNetwork = virDomainGraphicsListenGetNetwork(olddev, 0);
    newListenNetwork = virDomainGraphicsListenGetNetwork(dev, 0);
1491

1492 1493 1494
    switch (dev->type) {
    case VIR_DOMAIN_GRAPHICS_TYPE_VNC:
        if ((olddev->data.vnc.autoport != dev->data.vnc.autoport) ||
E
Eric Blake 已提交
1495 1496
            (!dev->data.vnc.autoport &&
             (olddev->data.vnc.port != dev->data.vnc.port))) {
1497 1498
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change port settings on vnc graphics"));
1499 1500
            return -1;
        }
1501
        if (STRNEQ_NULLABLE(oldListenAddr,newListenAddr)) {
1502 1503
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen address setting on vnc graphics"));
1504 1505
            return -1;
        }
1506
        if (STRNEQ_NULLABLE(oldListenNetwork,newListenNetwork)) {
1507 1508
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen network setting on vnc graphics"));
1509 1510
            return -1;
        }
1511
        if (STRNEQ_NULLABLE(olddev->data.vnc.keymap, dev->data.vnc.keymap)) {
1512 1513
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change keymap setting on vnc graphics"));
1514 1515 1516
            return -1;
        }

1517 1518 1519
        /* If a password lifetime was, or is set, or action if connected has
         * changed, then we must always run, even if new password matches
         * old password */
1520 1521
        if (olddev->data.vnc.auth.expires ||
            dev->data.vnc.auth.expires ||
1522
            olddev->data.vnc.auth.connected != dev->data.vnc.auth.connected ||
E
Eric Blake 已提交
1523 1524 1525 1526 1527 1528 1529 1530
            STRNEQ_NULLABLE(olddev->data.vnc.auth.passwd,
                            dev->data.vnc.auth.passwd)) {
            VIR_DEBUG("Updating password on VNC server %p %p",
                      dev->data.vnc.auth.passwd, driver->vncPassword);
            ret = qemuDomainChangeGraphicsPasswords(driver, vm,
                                                    VIR_DOMAIN_GRAPHICS_TYPE_VNC,
                                                    &dev->data.vnc.auth,
                                                    driver->vncPassword);
1531 1532
            if (ret < 0)
                return ret;
1533 1534 1535 1536 1537

            /* Steal the new dev's  char * reference */
            VIR_FREE(olddev->data.vnc.auth.passwd);
            olddev->data.vnc.auth.passwd = dev->data.vnc.auth.passwd;
            dev->data.vnc.auth.passwd = NULL;
1538 1539
            olddev->data.vnc.auth.validTo = dev->data.vnc.auth.validTo;
            olddev->data.vnc.auth.expires = dev->data.vnc.auth.expires;
1540
            olddev->data.vnc.auth.connected = dev->data.vnc.auth.connected;
1541 1542 1543 1544 1545
        } else {
            ret = 0;
        }
        break;

1546 1547
    case VIR_DOMAIN_GRAPHICS_TYPE_SPICE:
        if ((olddev->data.spice.autoport != dev->data.spice.autoport) ||
E
Eric Blake 已提交
1548 1549 1550 1551
            (!dev->data.spice.autoport &&
             (olddev->data.spice.port != dev->data.spice.port)) ||
            (!dev->data.spice.autoport &&
             (olddev->data.spice.tlsPort != dev->data.spice.tlsPort))) {
1552 1553
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change port settings on spice graphics"));
1554 1555
            return -1;
        }
1556
        if (STRNEQ_NULLABLE(oldListenAddr, newListenAddr)) {
1557 1558
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen address setting on spice graphics"));
1559 1560
            return -1;
        }
1561
        if (STRNEQ_NULLABLE(oldListenNetwork, newListenNetwork)) {
1562 1563
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("cannot change listen network setting on spice graphics"));
1564 1565
            return -1;
        }
E
Eric Blake 已提交
1566 1567
        if (STRNEQ_NULLABLE(olddev->data.spice.keymap,
                            dev->data.spice.keymap)) {
1568
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
1569 1570 1571 1572
                            _("cannot change keymap setting on spice graphics"));
            return -1;
        }

1573 1574 1575 1576 1577
        /* We must reset the password if it has changed but also if:
         * - password lifetime is or was set
         * - the requested action has changed
         * - the action is "disconnect"
         */
1578 1579
        if (olddev->data.spice.auth.expires ||
            dev->data.spice.auth.expires ||
1580
            olddev->data.spice.auth.connected != dev->data.spice.auth.connected ||
1581 1582
            dev->data.spice.auth.connected ==
            VIR_DOMAIN_GRAPHICS_AUTH_CONNECTED_DISCONNECT ||
E
Eric Blake 已提交
1583 1584 1585 1586 1587 1588 1589 1590 1591
            STRNEQ_NULLABLE(olddev->data.spice.auth.passwd,
                            dev->data.spice.auth.passwd)) {
            VIR_DEBUG("Updating password on SPICE server %p %p",
                      dev->data.spice.auth.passwd, driver->spicePassword);
            ret = qemuDomainChangeGraphicsPasswords(driver, vm,
                                                    VIR_DOMAIN_GRAPHICS_TYPE_SPICE,
                                                    &dev->data.spice.auth,
                                                    driver->spicePassword);

1592 1593 1594
            if (ret < 0)
                return ret;

E
Eric Blake 已提交
1595
            /* Steal the new dev's char * reference */
1596 1597 1598 1599 1600
            VIR_FREE(olddev->data.spice.auth.passwd);
            olddev->data.spice.auth.passwd = dev->data.spice.auth.passwd;
            dev->data.spice.auth.passwd = NULL;
            olddev->data.spice.auth.validTo = dev->data.spice.auth.validTo;
            olddev->data.spice.auth.expires = dev->data.spice.auth.expires;
1601
            olddev->data.spice.auth.connected = dev->data.spice.auth.connected;
1602
        } else {
1603
            VIR_DEBUG("Not updating since password didn't change");
1604 1605
            ret = 0;
        }
E
Eric Blake 已提交
1606
        break;
1607

1608
    default:
1609 1610 1611
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unable to change config on '%s' graphics type"),
                       virDomainGraphicsTypeToString(dev->type));
1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631
        break;
    }

    return ret;
}


static inline int qemuFindDisk(virDomainDefPtr def, const char *dst)
{
    int i;

    for (i = 0 ; i < def->ndisks ; i++) {
        if (STREQ(def->disks[i]->dst, dst)) {
            return i;
        }
    }

    return -1;
}

1632
static int qemuComparePCIDevice(virDomainDefPtr def ATTRIBUTE_UNUSED,
1633
                                virDomainDeviceDefPtr device ATTRIBUTE_UNUSED,
1634
                                virDomainDeviceInfoPtr info1,
1635 1636
                                void *opaque)
{
1637
    virDomainDeviceInfoPtr info2 = opaque;
1638

1639 1640
    if (info1->type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI ||
        info2->type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)
1641 1642
        return 0;

1643 1644
    if (info1->addr.pci.slot == info2->addr.pci.slot &&
        info1->addr.pci.function != info2->addr.pci.function)
1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656
        return -1;
    return 0;
}

static bool qemuIsMultiFunctionDevice(virDomainDefPtr def,
                                      virDomainDeviceInfoPtr dev)
{
    if (virDomainDeviceInfoIterate(def, qemuComparePCIDevice, dev) < 0)
        return true;
    return false;
}

1657 1658 1659

int qemuDomainDetachPciDiskDevice(struct qemud_driver *driver,
                                  virDomainObjPtr vm,
1660
                                  virDomainDeviceDefPtr dev)
1661 1662 1663 1664 1665 1666 1667 1668 1669 1670
{
    int i, ret = -1;
    virDomainDiskDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    virCgroupPtr cgroup = NULL;
    char *drivestr = NULL;

    i = qemuFindDisk(vm->def, dev->data.disk->dst);

    if (i < 0) {
1671 1672
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
1673 1674 1675 1676 1677
        goto cleanup;
    }

    detach = vm->def->disks[i];

1678
    if (qemuIsMultiFunctionDevice(vm->def, &detach->info)) {
1679 1680 1681
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device: %s"),
                       dev->data.disk->dst);
1682 1683 1684
        goto cleanup;
    }

1685 1686
    if (qemuCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
1687 1688 1689
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unable to find cgroup for %s"),
                           vm->def->name);
1690 1691 1692 1693 1694 1695
            goto cleanup;
        }
    }

    if (!virDomainDeviceAddressIsValid(&detach->info,
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
1696 1697
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("device cannot be detached without a PCI address"));
1698 1699 1700 1701 1702 1703 1704 1705 1706 1707 1708
        goto cleanup;
    }

    /* build the actual drive id string as the disk->info.alias doesn't
     * contain the QEMU_DRIVE_HOST_PREFIX that is passed to qemu */
    if (virAsprintf(&drivestr, "%s%s",
                    QEMU_DRIVE_HOST_PREFIX, detach->info.alias) < 0) {
        virReportOOMError();
        goto cleanup;
    }

1709
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1710
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1711
        if (qemuMonitorDelDevice(priv->mon, detach->info.alias) < 0) {
1712
            qemuDomainObjExitMonitorWithDriver(driver, vm);
1713
            virDomainAuditDisk(vm, detach->src, NULL, "detach", false);
1714 1715 1716 1717 1718
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemovePCIDevice(priv->mon,
                                       &detach->info.addr.pci) < 0) {
1719
            qemuDomainObjExitMonitorWithDriver(driver, vm);
1720
            virDomainAuditDisk(vm, detach->src, NULL, "detach", false);
1721 1722 1723 1724 1725 1726 1727 1728 1729
            goto cleanup;
        }
    }

    /* disconnect guest from host device */
    qemuMonitorDriveDel(priv->mon, drivestr);

    qemuDomainObjExitMonitorWithDriver(driver, vm);

1730
    virDomainAuditDisk(vm, detach->src, NULL, "detach", true);
1731

1732
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
1733 1734
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        detach->info.addr.pci.slot) < 0)
1735 1736 1737 1738 1739 1740
        VIR_WARN("Unable to release PCI address on %s", dev->data.disk->src);

    virDomainDiskRemove(vm->def, i);

    virDomainDiskDefFree(detach);

1741
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
1742
                                            vm->def, dev->data.disk) < 0)
1743 1744 1745
        VIR_WARN("Unable to restore security label on %s", dev->data.disk->src);

    if (cgroup != NULL) {
1746
        if (qemuTeardownDiskCgroup(driver, vm, cgroup, dev->data.disk) < 0)
1747 1748 1749 1750
            VIR_WARN("Failed to teardown cgroup for disk path %s",
                     NULLSTR(dev->data.disk->src));
    }

1751 1752 1753
    if (virDomainLockDiskDetach(driver->lockManager, vm, dev->data.disk) < 0)
        VIR_WARN("Unable to release lock on %s", dev->data.disk->src);

1754 1755 1756
    ret = 0;

cleanup:
1757
    virCgroupFree(&cgroup);
1758 1759 1760 1761
    VIR_FREE(drivestr);
    return ret;
}

1762 1763
int qemuDomainDetachDiskDevice(struct qemud_driver *driver,
                               virDomainObjPtr vm,
1764
                               virDomainDeviceDefPtr dev)
1765 1766 1767 1768 1769 1770 1771 1772 1773 1774
{
    int i, ret = -1;
    virDomainDiskDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    virCgroupPtr cgroup = NULL;
    char *drivestr = NULL;

    i = qemuFindDisk(vm->def, dev->data.disk->dst);

    if (i < 0) {
1775 1776
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
1777 1778 1779
        goto cleanup;
    }

1780
    if (!qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1781 1782 1783
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("Underlying qemu does not support %s disk removal"),
                       virDomainDiskBusTypeToString(dev->data.disk->bus));
1784 1785 1786 1787 1788 1789 1790
        goto cleanup;
    }

    detach = vm->def->disks[i];

    if (qemuCgroupControllerActive(driver, VIR_CGROUP_CONTROLLER_DEVICES)) {
        if (virCgroupForDomain(driver->cgroup, vm->def->name, &cgroup, 0) != 0) {
1791 1792 1793
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unable to find cgroup for %s"),
                           vm->def->name);
1794 1795 1796 1797 1798 1799 1800 1801 1802 1803 1804 1805
            goto cleanup;
        }
    }

    /* build the actual drive id string as the disk->info.alias doesn't
     * contain the QEMU_DRIVE_HOST_PREFIX that is passed to qemu */
    if (virAsprintf(&drivestr, "%s%s",
                    QEMU_DRIVE_HOST_PREFIX, detach->info.alias) < 0) {
        virReportOOMError();
        goto cleanup;
    }

1806
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1807
    if (qemuMonitorDelDevice(priv->mon, detach->info.alias) < 0) {
1808
        qemuDomainObjExitMonitorWithDriver(driver, vm);
1809
        virDomainAuditDisk(vm, detach->src, NULL, "detach", false);
1810 1811 1812 1813 1814 1815 1816 1817
        goto cleanup;
    }

    /* disconnect guest from host device */
    qemuMonitorDriveDel(priv->mon, drivestr);

    qemuDomainObjExitMonitorWithDriver(driver, vm);

1818
    virDomainAuditDisk(vm, detach->src, NULL, "detach", true);
1819 1820 1821 1822 1823

    virDomainDiskRemove(vm->def, i);

    virDomainDiskDefFree(detach);

1824
    if (virSecurityManagerRestoreImageLabel(driver->securityManager,
1825
                                            vm->def, dev->data.disk) < 0)
1826 1827 1828
        VIR_WARN("Unable to restore security label on %s", dev->data.disk->src);

    if (cgroup != NULL) {
1829
        if (qemuTeardownDiskCgroup(driver, vm, cgroup, dev->data.disk) < 0)
1830 1831 1832 1833
            VIR_WARN("Failed to teardown cgroup for disk path %s",
                     NULLSTR(dev->data.disk->src));
    }

1834 1835 1836
    if (virDomainLockDiskDetach(driver->lockManager, vm, dev->data.disk) < 0)
        VIR_WARN("Unable to release lock on disk %s", dev->data.disk->src);

1837 1838 1839 1840 1841 1842 1843 1844
    ret = 0;

cleanup:
    VIR_FREE(drivestr);
    virCgroupFree(&cgroup);
    return ret;
}

1845 1846 1847 1848 1849 1850 1851 1852 1853 1854 1855 1856 1857 1858 1859 1860 1861 1862 1863 1864 1865 1866 1867 1868 1869 1870 1871 1872 1873 1874 1875 1876 1877 1878 1879 1880 1881 1882 1883 1884 1885 1886 1887 1888 1889 1890 1891 1892 1893 1894
static bool qemuDomainDiskControllerIsBusy(virDomainObjPtr vm,
                                           virDomainControllerDefPtr detach)
{
    int i;
    virDomainDiskDefPtr disk;

    for (i = 0; i < vm->def->ndisks; i++) {
        disk = vm->def->disks[i];
        if (disk->info.type != VIR_DOMAIN_DEVICE_ADDRESS_TYPE_DRIVE)
            /* the disk does not use disk controller */
            continue;

        /* check whether the disk uses this type controller */
        if (disk->bus == VIR_DOMAIN_DISK_BUS_IDE &&
            detach->type != VIR_DOMAIN_CONTROLLER_TYPE_IDE)
            continue;
        if (disk->bus == VIR_DOMAIN_DISK_BUS_FDC &&
            detach->type != VIR_DOMAIN_CONTROLLER_TYPE_FDC)
            continue;
        if (disk->bus == VIR_DOMAIN_DISK_BUS_SCSI &&
            detach->type != VIR_DOMAIN_CONTROLLER_TYPE_SCSI)
            continue;

        if (disk->info.addr.drive.controller == detach->idx)
            return true;
    }

    return false;
}

static bool qemuDomainControllerIsBusy(virDomainObjPtr vm,
                                       virDomainControllerDefPtr detach)
{
    switch (detach->type) {
    case VIR_DOMAIN_CONTROLLER_TYPE_IDE:
    case VIR_DOMAIN_CONTROLLER_TYPE_FDC:
    case VIR_DOMAIN_CONTROLLER_TYPE_SCSI:
        return qemuDomainDiskControllerIsBusy(vm, detach);

    case VIR_DOMAIN_CONTROLLER_TYPE_SATA:
    case VIR_DOMAIN_CONTROLLER_TYPE_VIRTIO_SERIAL:
    case VIR_DOMAIN_CONTROLLER_TYPE_CCID:
    default:
        /* libvirt does not support sata controller, and does not support to
         * detach virtio and smart card controller.
         */
        return true;
    }
}

1895 1896
int qemuDomainDetachPciControllerDevice(struct qemud_driver *driver,
                                        virDomainObjPtr vm,
1897
                                        virDomainDeviceDefPtr dev)
1898
{
1899
    int idx, ret = -1;
1900 1901 1902
    virDomainControllerDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;

1903 1904 1905
    if ((idx = virDomainControllerFind(vm->def,
                                       dev->data.controller->type,
                                       dev->data.controller->idx)) < 0) {
1906 1907 1908 1909
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk controller %s:%d not found"),
                       virDomainControllerTypeToString(dev->data.controller->type),
                       dev->data.controller->idx);
1910 1911 1912
        goto cleanup;
    }

1913 1914
    detach = vm->def->controllers[idx];

1915 1916
    if (!virDomainDeviceAddressIsValid(&detach->info,
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
1917 1918
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("device cannot be detached without a PCI address"));
1919 1920 1921
        goto cleanup;
    }

1922
    if (qemuIsMultiFunctionDevice(vm->def, &detach->info)) {
1923 1924 1925
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device: %s"),
                       dev->data.disk->dst);
1926 1927 1928
        goto cleanup;
    }

1929
    if (qemuDomainControllerIsBusy(vm, detach)) {
1930 1931
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("device cannot be detached: device is busy"));
1932 1933 1934
        goto cleanup;
    }

1935
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1936 1937 1938 1939
        if (qemuAssignDeviceControllerAlias(detach) < 0)
            goto cleanup;
    }

1940
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1941
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1942
        if (qemuMonitorDelDevice(priv->mon, detach->info.alias)) {
1943
            qemuDomainObjExitMonitorWithDriver(driver, vm);
1944 1945 1946 1947 1948
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemovePCIDevice(priv->mon,
                                       &detach->info.addr.pci) < 0) {
1949
            qemuDomainObjExitMonitorWithDriver(driver, vm);
1950 1951 1952 1953 1954
            goto cleanup;
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

1955 1956
    virDomainControllerRemove(vm->def, idx);
    virDomainControllerDefFree(detach);
1957

1958
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
1959 1960
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        detach->info.addr.pci.slot) < 0)
1961
        VIR_WARN("Unable to release PCI address on controller");
1962 1963 1964 1965 1966 1967 1968

    ret = 0;

cleanup:
    return ret;
}

1969 1970 1971
static int
qemuDomainDetachHostPciDevice(struct qemud_driver *driver,
                              virDomainObjPtr vm,
1972
                              virDomainHostdevDefPtr detach)
1973 1974
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
1975 1976
    virDomainHostdevSubsysPtr subsys = &detach->source.subsys;
    int ret;
1977
    pciDevice *pci;
1978
    pciDevice *activePci;
1979

1980
    if (qemuIsMultiFunctionDevice(vm->def, detach->info)) {
1981 1982 1983 1984
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device: %.4x:%.2x:%.2x.%.1x"),
                       subsys->u.pci.domain, subsys->u.pci.bus,
                       subsys->u.pci.slot,   subsys->u.pci.function);
1985
        return -1;
1986 1987
    }

1988
    if (!virDomainDeviceAddressIsValid(detach->info,
1989
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
1990 1991
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached without a PCI address"));
1992 1993 1994
        return -1;
    }

1995
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
1996
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
1997
        ret = qemuMonitorDelDevice(priv->mon, detach->info->alias);
1998
    } else {
1999
        ret = qemuMonitorRemovePCIDevice(priv->mon, &detach->info->addr.pci);
2000 2001
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);
2002
    virDomainAuditHostdev(vm, detach, "detach", ret == 0);
2003 2004
    if (ret < 0)
        return -1;
2005

2006 2007 2008 2009 2010 2011 2012
    /*
     * For SRIOV net host devices, unset mac and port profile before
     * reset and reattach device
     */
     if (detach->parent.data.net)
         qemuDomainHostdevNetConfigRestore(detach, driver->stateDir);

2013 2014
    pci = pciGetDevice(subsys->u.pci.domain, subsys->u.pci.bus,
                       subsys->u.pci.slot,   subsys->u.pci.function);
2015 2016
    if (pci) {
        activePci = pciDeviceListSteal(driver->activePciHostdevs, pci);
2017 2018 2019
        if (activePci &&
            pciResetDevice(activePci, driver->activePciHostdevs,
                           driver->inactivePciHostdevs) == 0) {
2020
            qemuReattachPciDevice(activePci, driver);
2021 2022 2023
        } else {
            /* reset of the device failed, treat it as if it was returned */
            pciFreeDevice(activePci);
2024
            ret = -1;
2025
        }
2026
        pciFreeDevice(pci);
2027 2028
    } else {
        ret = -1;
2029 2030
    }

2031
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
2032
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
2033
                                        detach->info->addr.pci.slot) < 0)
2034
        VIR_WARN("Unable to release PCI address on host device");
2035 2036 2037 2038

    return ret;
}

2039 2040 2041
static int
qemuDomainDetachHostUsbDevice(struct qemud_driver *driver,
                              virDomainObjPtr vm,
2042
                              virDomainHostdevDefPtr detach)
2043 2044
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
2045
    virDomainHostdevSubsysPtr subsys = &detach->source.subsys;
2046
    usbDevice *usb;
2047
    int ret;
2048

2049
    if (!detach->info->alias) {
2050 2051
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached without a device alias"));
2052 2053 2054
        return -1;
    }

2055
    if (!qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2056 2057
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached with this QEMU version"));
2058 2059 2060
        return -1;
    }

2061
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2062
    ret = qemuMonitorDelDevice(priv->mon, detach->info->alias);
2063
    qemuDomainObjExitMonitorWithDriver(driver, vm);
2064
    virDomainAuditHostdev(vm, detach, "detach", ret == 0);
2065 2066
    if (ret < 0)
        return -1;
2067

2068
    usb = usbGetDevice(subsys->u.usb.bus, subsys->u.usb.device);
2069 2070 2071 2072 2073
    if (usb) {
        usbDeviceListDel(driver->activeUsbHostdevs, usb);
        usbFreeDevice(usb);
    } else {
        VIR_WARN("Unable to find device %03d.%03d in list of used USB devices",
2074
                 subsys->u.usb.bus, subsys->u.usb.device);
2075 2076 2077 2078
    }
    return ret;
}

2079 2080 2081 2082 2083
static
int qemuDomainDetachThisHostDevice(struct qemud_driver *driver,
                                   virDomainObjPtr vm,
                                   virDomainHostdevDefPtr detach,
                                   int idx)
2084
{
2085
    int ret = -1;
2086

2087 2088 2089 2090 2091 2092 2093 2094 2095
    if (idx < 0) {
        /* caller didn't know index of hostdev in hostdevs list, so we
         * need to find it.
         */
        for (idx = 0; idx < vm->def->nhostdevs; idx++) {
            if (vm->def->hostdevs[idx] == detach)
                break;
        }
        if (idx >= vm->def->nhostdevs) {
2096
            virReportError(VIR_ERR_INTERNAL_ERROR,
2097
                           _("device not found in hostdevs list (%zu entries)"),
2098
                           vm->def->nhostdevs);
2099 2100
            return ret;
        }
2101 2102
    }

2103
    switch (detach->source.subsys.type) {
2104
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI:
2105 2106
        ret = qemuDomainDetachHostPciDevice(driver, vm, detach);
        break;
2107
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
2108
        ret = qemuDomainDetachHostUsbDevice(driver, vm, detach);
2109 2110
        break;
    default:
2111 2112 2113
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev subsys type '%s' not supported"),
                       virDomainHostdevSubsysTypeToString(detach->source.subsys.type));
2114 2115 2116
        return -1;
    }

2117 2118 2119 2120 2121 2122 2123
    if (!ret) {
        if (virSecurityManagerRestoreHostdevLabel(driver->securityManager,
                                                  vm->def, detach) < 0) {
            VIR_WARN("Failed to restore host device labelling");
        }
        virDomainHostdevRemove(vm->def, idx);
        virDomainHostdevDefFree(detach);
2124
    }
2125 2126
    return ret;
}
2127

2128 2129 2130 2131 2132 2133 2134 2135 2136 2137 2138
/* search for a hostdev matching dev and detach it */
int qemuDomainDetachHostDevice(struct qemud_driver *driver,
                               virDomainObjPtr vm,
                               virDomainDeviceDefPtr dev)
{
    virDomainHostdevDefPtr hostdev = dev->data.hostdev;
    virDomainHostdevSubsysPtr subsys = &hostdev->source.subsys;
    virDomainHostdevDefPtr detach = NULL;
    int idx;

    if (hostdev->mode != VIR_DOMAIN_HOSTDEV_MODE_SUBSYS) {
2139 2140 2141
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("hostdev mode '%s' not supported"),
                       virDomainHostdevModeTypeToString(hostdev->mode));
2142 2143 2144 2145 2146 2147 2148 2149
        return -1;
    }

    idx = virDomainHostdevFind(vm->def, hostdev, &detach);

    if (idx < 0) {
        switch(subsys->type) {
        case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI:
2150 2151 2152 2153
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("host pci device %.4x:%.2x:%.2x.%.1x not found"),
                           subsys->u.pci.domain, subsys->u.pci.bus,
                           subsys->u.pci.slot, subsys->u.pci.function);
2154 2155 2156
            break;
        case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
            if (subsys->u.usb.bus && subsys->u.usb.device) {
2157 2158 2159
                virReportError(VIR_ERR_OPERATION_FAILED,
                               _("host usb device %03d.%03d not found"),
                               subsys->u.usb.bus, subsys->u.usb.device);
2160
            } else {
2161 2162 2163
                virReportError(VIR_ERR_OPERATION_FAILED,
                               _("host usb device vendor=0x%.4x product=0x%.4x not found"),
                               subsys->u.usb.vendor, subsys->u.usb.product);
2164 2165 2166
            }
            break;
        default:
2167 2168
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("unexpected hostdev type %d"), subsys->type);
2169 2170 2171 2172 2173
            break;
        }
        return -1;
    }

2174 2175 2176 2177 2178 2179 2180
    /* If this is a network hostdev, we need to use the higher-level detach
     * function so that mac address / virtualport are reset
     */
    if (detach->parent.type == VIR_DOMAIN_DEVICE_NET)
        return qemuDomainDetachNetDevice(driver, vm, &detach->parent);
    else
        return qemuDomainDetachThisHostDevice(driver, vm, detach, idx);
2181 2182
}

2183 2184 2185 2186 2187 2188 2189 2190 2191 2192 2193 2194 2195 2196 2197
int
qemuDomainDetachNetDevice(struct qemud_driver *driver,
                          virDomainObjPtr vm,
                          virDomainDeviceDefPtr dev)
{
    int i, ret = -1;
    virDomainNetDefPtr detach = NULL;
    qemuDomainObjPrivatePtr priv = vm->privateData;
    int vlan;
    char *hostnet_name = NULL;
    virNetDevVPortProfilePtr vport = NULL;

    for (i = 0 ; i < vm->def->nnets ; i++) {
        virDomainNetDefPtr net = vm->def->nets[i];

2198
        if (!virMacAddrCmp(&net->mac, &dev->data.net->mac)) {
2199 2200 2201 2202 2203 2204
            detach = net;
            break;
        }
    }

    if (!detach) {
2205 2206 2207 2208 2209
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("network device %02x:%02x:%02x:%02x:%02x:%02x not found"),
                       dev->data.net->mac.addr[0], dev->data.net->mac.addr[1],
                       dev->data.net->mac.addr[2], dev->data.net->mac.addr[3],
                       dev->data.net->mac.addr[4], dev->data.net->mac.addr[5]);
2210 2211 2212
        goto cleanup;
    }

2213 2214 2215 2216 2217 2218 2219
    if (virDomainNetGetActualType(detach) == VIR_DOMAIN_NET_TYPE_HOSTDEV) {
        ret = qemuDomainDetachThisHostDevice(driver, vm,
                                             virDomainNetGetActualHostdev(detach),
                                             -1);
        goto cleanup;
    }

2220 2221
    if (!virDomainDeviceAddressIsValid(&detach->info,
                                       VIR_DOMAIN_DEVICE_ADDRESS_TYPE_PCI)) {
2222 2223
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("device cannot be detached without a PCI address"));
2224 2225 2226 2227
        goto cleanup;
    }

    if (qemuIsMultiFunctionDevice(vm->def, &detach->info)) {
2228 2229 2230
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("cannot hot unplug multifunction PCI device :%s"),
                       dev->data.disk->dst);
2231 2232 2233 2234
        goto cleanup;
    }

    if ((vlan = qemuDomainNetVLAN(detach)) < 0) {
2235 2236
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("unable to determine original VLAN"));
2237 2238 2239 2240 2241 2242 2243 2244 2245
        goto cleanup;
    }

    if (virAsprintf(&hostnet_name, "host%s", detach->info.alias) < 0) {
        virReportOOMError();
        goto cleanup;
    }

    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2246
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2247 2248 2249 2250 2251 2252 2253 2254 2255 2256 2257 2258 2259 2260
        if (qemuMonitorDelDevice(priv->mon, detach->info.alias) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemovePCIDevice(priv->mon,
                                       &detach->info.addr.pci) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    }

2261 2262
    if (qemuCapsGet(priv->caps, QEMU_CAPS_NETDEV) &&
        qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE)) {
2263 2264 2265 2266 2267 2268 2269 2270 2271 2272 2273 2274 2275 2276 2277 2278
        if (qemuMonitorRemoveNetdev(priv->mon, hostnet_name) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    } else {
        if (qemuMonitorRemoveHostNetwork(priv->mon, vlan, hostnet_name) < 0) {
            qemuDomainObjExitMonitorWithDriver(driver, vm);
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
    }
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    virDomainAuditNet(vm, detach, NULL, "detach", true);

2279
    if (qemuCapsGet(priv->caps, QEMU_CAPS_DEVICE) &&
2280 2281 2282 2283 2284 2285 2286 2287
        qemuDomainPCIAddressReleaseSlot(priv->pciaddrs,
                                        detach->info.addr.pci.slot) < 0)
        VIR_WARN("Unable to release PCI address on NIC");

    virDomainConfNWFilterTeardown(detach);

    if (virDomainNetGetActualType(detach) == VIR_DOMAIN_NET_TYPE_DIRECT) {
        ignore_value(virNetDevMacVLanDeleteWithVPortProfile(
2288
                         detach->ifname, &detach->mac,
2289 2290 2291 2292 2293 2294 2295 2296 2297 2298
                         virDomainNetGetActualDirectDev(detach),
                         virDomainNetGetActualDirectMode(detach),
                         virDomainNetGetActualVirtPortProfile(detach),
                         driver->stateDir));
        VIR_FREE(detach->ifname);
    }

    if ((driver->macFilter) && (detach->ifname != NULL)) {
        if ((errno = networkDisallowMacOnPort(driver,
                                              detach->ifname,
2299
                                              &detach->mac))) {
2300
            virReportSystemError(errno,
2301
             _("failed to remove ebtables rule on '%s'"),
2302 2303 2304 2305 2306 2307 2308 2309 2310 2311 2312
                                 detach->ifname);
        }
    }

    vport = virDomainNetGetActualVirtPortProfile(detach);
    if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
        ignore_value(virNetDevOpenvswitchRemovePort(
                        virDomainNetGetActualBridgeName(detach),
                        detach->ifname));
    ret = 0;
cleanup:
2313 2314 2315 2316 2317
    if (!ret) {
        networkReleaseActualDevice(detach);
        virDomainNetRemove(vm->def, i);
        virDomainNetDefFree(detach);
    }
2318 2319 2320 2321
    VIR_FREE(hostnet_name);
    return ret;
}

2322 2323 2324 2325 2326 2327 2328 2329 2330 2331
int
qemuDomainChangeGraphicsPasswords(struct qemud_driver *driver,
                                  virDomainObjPtr vm,
                                  int type,
                                  virDomainGraphicsAuthDefPtr auth,
                                  const char *defaultPasswd)
{
    qemuDomainObjPrivatePtr priv = vm->privateData;
    time_t now = time(NULL);
    char expire_time [64];
2332
    const char *connected = NULL;
2333 2334 2335 2336 2337
    int ret;

    if (!auth->passwd && !driver->vncPassword)
        return 0;

2338 2339 2340
    if (auth->connected)
        connected = virDomainGraphicsAuthConnectedTypeToString(auth->connected);

2341
    qemuDomainObjEnterMonitorWithDriver(driver, vm);
2342 2343 2344
    ret = qemuMonitorSetPassword(priv->mon,
                                 type,
                                 auth->passwd ? auth->passwd : defaultPasswd,
2345
                                 connected);
2346 2347 2348

    if (ret == -2) {
        if (type != VIR_DOMAIN_GRAPHICS_TYPE_VNC) {
2349 2350
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("Graphics password only supported for VNC"));
2351 2352 2353 2354 2355 2356
            ret = -1;
        } else {
            ret = qemuMonitorSetVNCPassword(priv->mon,
                                            auth->passwd ? auth->passwd : defaultPasswd);
        }
    }
2357 2358 2359
    if (ret != 0)
        goto cleanup;

2360 2361 2362
    if (auth->expires) {
        time_t lifetime = auth->validTo - now;
        if (lifetime <= 0)
2363
            snprintf(expire_time, sizeof(expire_time), "now");
2364
        else
2365
            snprintf(expire_time, sizeof(expire_time), "%lu", (long unsigned)auth->validTo);
2366
    } else {
2367
        snprintf(expire_time, sizeof(expire_time), "never");
2368 2369 2370 2371 2372 2373 2374
    }

    ret = qemuMonitorExpirePassword(priv->mon, type, expire_time);

    if (ret == -2) {
        /* XXX we could fake this with a timer */
        if (auth->expires) {
2375 2376
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("Expiry of passwords is not supported"));
2377
            ret = -1;
2378 2379
        } else {
            ret = 0;
2380 2381 2382
        }
    }

2383
cleanup:
2384 2385 2386 2387
    qemuDomainObjExitMonitorWithDriver(driver, vm);

    return ret;
}
2388 2389 2390 2391 2392 2393 2394 2395

int qemuDomainAttachLease(struct qemud_driver *driver,
                          virDomainObjPtr vm,
                          virDomainLeaseDefPtr lease)
{
    if (virDomainLeaseInsertPreAlloc(vm->def) < 0)
        return -1;

2396 2397
    if (virDomainLockLeaseAttach(driver->lockManager, driver->uri,
                                 vm, lease) < 0) {
2398 2399 2400 2401 2402 2403 2404 2405 2406 2407 2408 2409
        virDomainLeaseInsertPreAlloced(vm->def, NULL);
        return -1;
    }

    virDomainLeaseInsertPreAlloced(vm->def, lease);
    return 0;
}

int qemuDomainDetachLease(struct qemud_driver *driver,
                          virDomainObjPtr vm,
                          virDomainLeaseDefPtr lease)
{
2410
    virDomainLeaseDefPtr det_lease;
2411 2412 2413
    int i;

    if ((i = virDomainLeaseIndex(vm->def, lease)) < 0) {
2414 2415 2416
        virReportError(VIR_ERR_INVALID_ARG,
                       _("Lease %s in lockspace %s does not exist"),
                       lease->key, NULLSTR(lease->lockspace));
2417 2418 2419 2420 2421 2422
        return -1;
    }

    if (virDomainLockLeaseDetach(driver->lockManager, vm, lease) < 0)
        return -1;

2423 2424
    det_lease = virDomainLeaseRemoveAt(vm->def, i);
    virDomainLeaseDefFree(det_lease);
2425 2426
    return 0;
}