lxc_driver.c 145.8 KB
Newer Older
D
Daniel Veillard 已提交
1
/*
2
 * Copyright (C) 2010-2013 Red Hat, Inc.
D
Daniel Veillard 已提交
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
 * Copyright IBM Corp. 2008
 *
 * lxc_driver.c: linux container driver functions
 *
 * Authors:
 *  David L. Leskovec <dlesko at linux.vnet.ibm.com>
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
21
 * License along with this library.  If not, see
O
Osier Yang 已提交
22
 * <http://www.gnu.org/licenses/>.
D
Daniel Veillard 已提交
23 24 25 26
 */

#include <config.h>

27
#include <fcntl.h>
D
Daniel Veillard 已提交
28 29 30 31
#include <sched.h>
#include <sys/utsname.h>
#include <string.h>
#include <sys/types.h>
32
#include <sys/socket.h>
33
#include <sys/stat.h>
34 35
#include <sys/un.h>
#include <sys/poll.h>
D
Daniel Veillard 已提交
36 37 38
#include <unistd.h>
#include <wait.h>

39
#include "virerror.h"
40
#include "virlog.h"
41
#include "datatypes.h"
42
#include "lxc_cgroup.h"
D
Daniel Veillard 已提交
43
#include "lxc_conf.h"
44
#include "lxc_container.h"
45
#include "lxc_domain.h"
D
Daniel Veillard 已提交
46
#include "lxc_driver.h"
47
#include "lxc_process.h"
48
#include "viralloc.h"
49
#include "virnetdevbridge.h"
50
#include "virnetdevveth.h"
51
#include "nodeinfo.h"
52
#include "viruuid.h"
53
#include "virstatslinux.h"
54
#include "virhook.h"
E
Eric Blake 已提交
55
#include "virfile.h"
56
#include "virpidfile.h"
57
#include "fdstream.h"
58
#include "domain_audit.h"
59
#include "domain_nwfilter.h"
60
#include "nwfilter_conf.h"
61
#include "network/bridge_driver.h"
62
#include "virinitctl.h"
63
#include "virnetdev.h"
A
Ansis Atteka 已提交
64
#include "virnetdevtap.h"
65
#include "virnodesuspend.h"
66
#include "virprocess.h"
67
#include "virtime.h"
68
#include "virtypedparam.h"
M
Martin Kletzander 已提交
69
#include "viruri.h"
70
#include "virstring.h"
71 72
#include "viraccessapicheck.h"
#include "viraccessapichecklxc.h"
D
Daniel Veillard 已提交
73

74 75
#define VIR_FROM_THIS VIR_FROM_LXC

76

77 78
#define LXC_NB_MEM_PARAM  3

79 80 81 82
static int lxcStateInitialize(bool privileged,
                              virStateInhibitCallback callback,
                              void *opaque);
static int lxcStateCleanup(void);
83
virLXCDriverPtr lxc_driver = NULL;
D
Daniel Veillard 已提交
84

85 86 87
/* callbacks for nwfilter */
static int
lxcVMFilterRebuild(virConnectPtr conn ATTRIBUTE_UNUSED,
88
                   virDomainObjListIterator iter, void *data)
89
{
90
    return virDomainObjListForEach(lxc_driver->domains, iter, data);
91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111
}

static void
lxcVMDriverLock(void)
{
    lxcDriverLock(lxc_driver);
}

static void
lxcVMDriverUnlock(void)
{
    lxcDriverUnlock(lxc_driver);
}

static virNWFilterCallbackDriver lxcCallbackDriver = {
    .name = "LXC",
    .vmFilterRebuild = lxcVMFilterRebuild,
    .vmDriverLock = lxcVMDriverLock,
    .vmDriverUnlock = lxcVMDriverUnlock,
};

D
Daniel Veillard 已提交
112 113
/* Functions */

114 115 116
static virDrvOpenStatus lxcConnectOpen(virConnectPtr conn,
                                       virConnectAuthPtr auth ATTRIBUTE_UNUSED,
                                       unsigned int flags)
D
Daniel Veillard 已提交
117
{
E
Eric Blake 已提交
118 119
    virCheckFlags(VIR_CONNECT_RO, VIR_DRV_OPEN_ERROR);

D
Daniel Veillard 已提交
120
    /* Verify uri was specified */
121
    if (conn->uri == NULL) {
122 123
        if (lxc_driver == NULL)
            return VIR_DRV_OPEN_DECLINED;
124

125
        if (!(conn->uri = virURIParse("lxc:///")))
126
            return VIR_DRV_OPEN_ERROR;
127 128 129 130 131 132 133 134 135 136
    } else {
        if (conn->uri->scheme == NULL ||
            STRNEQ(conn->uri->scheme, "lxc"))
            return VIR_DRV_OPEN_DECLINED;

        /* Leave for remote driver */
        if (conn->uri->server != NULL)
            return VIR_DRV_OPEN_DECLINED;

        /* If path isn't '/' then they typoed, tell them correct path */
137 138
        if (conn->uri->path != NULL &&
            STRNEQ(conn->uri->path, "/")) {
139 140 141
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unexpected LXC URI path '%s', try lxc:///"),
                           conn->uri->path);
142 143
            return VIR_DRV_OPEN_ERROR;
        }
D
Daniel Veillard 已提交
144

145 146
        /* URI was good, but driver isn't active */
        if (lxc_driver == NULL) {
147 148
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("lxc state driver is not active"));
149 150 151
            return VIR_DRV_OPEN_ERROR;
        }
    }
152

153 154 155
    if (virConnectOpenEnsureACL(conn) < 0)
        return VIR_DRV_OPEN_ERROR;

156
    conn->privateData = lxc_driver;
D
Daniel Veillard 已提交
157 158 159 160

    return VIR_DRV_OPEN_SUCCESS;
}

161
static int lxcConnectClose(virConnectPtr conn)
D
Daniel Veillard 已提交
162
{
163
    virLXCDriverPtr driver = conn->privateData;
164

165
    virCloseCallbacksRun(driver->closeCallbacks, conn, driver->domains, driver);
166 167
    conn->privateData = NULL;
    return 0;
D
Daniel Veillard 已提交
168 169
}

170

171
static int lxcConnectIsSecure(virConnectPtr conn ATTRIBUTE_UNUSED)
172 173 174 175 176 177
{
    /* Trivially secure, since always inside the daemon */
    return 1;
}


178
static int lxcConnectIsEncrypted(virConnectPtr conn ATTRIBUTE_UNUSED)
179 180 181 182 183 184
{
    /* Not encrypted, but remote driver takes care of that */
    return 0;
}


185
static int lxcConnectIsAlive(virConnectPtr conn ATTRIBUTE_UNUSED)
186 187 188 189 190
{
    return 1;
}


191
static char *lxcConnectGetCapabilities(virConnectPtr conn) {
192
    virLXCDriverPtr driver = conn->privateData;
193
    virCapsPtr caps;
194 195
    char *xml;

196 197 198
    if (virConnectGetCapabilitiesEnsureACL(conn) < 0)
        return NULL;

199
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
200 201 202
        return NULL;

    if ((xml = virCapabilitiesFormatXML(caps)) == NULL)
203
        virReportOOMError();
204

205
    virObjectUnref(caps);
206 207 208 209
    return xml;
}


D
Daniel Veillard 已提交
210 211 212
static virDomainPtr lxcDomainLookupByID(virConnectPtr conn,
                                        int id)
{
213
    virLXCDriverPtr driver = conn->privateData;
214 215
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
216

217
    vm = virDomainObjListFindByID(driver->domains, id);
218

D
Daniel Veillard 已提交
219
    if (!vm) {
220 221
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching id %d"), id);
222
        goto cleanup;
D
Daniel Veillard 已提交
223 224
    }

225 226 227
    if (virDomainLookupByIDEnsureACL(conn, vm->def) < 0)
        goto cleanup;

D
Daniel Veillard 已提交
228
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
229
    if (dom)
D
Daniel Veillard 已提交
230 231
        dom->id = vm->def->id;

232
cleanup:
233
    if (vm)
234
        virObjectUnlock(vm);
D
Daniel Veillard 已提交
235 236 237 238 239 240
    return dom;
}

static virDomainPtr lxcDomainLookupByUUID(virConnectPtr conn,
                                          const unsigned char *uuid)
{
241
    virLXCDriverPtr driver = conn->privateData;
242 243
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
244

245
    vm = virDomainObjListFindByUUID(driver->domains, uuid);
246

D
Daniel Veillard 已提交
247
    if (!vm) {
248 249
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(uuid, uuidstr);
250 251
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
252
        goto cleanup;
D
Daniel Veillard 已提交
253 254
    }

255 256 257
    if (virDomainLookupByUUIDEnsureACL(conn, vm->def) < 0)
        goto cleanup;

D
Daniel Veillard 已提交
258
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
259
    if (dom)
D
Daniel Veillard 已提交
260 261
        dom->id = vm->def->id;

262
cleanup:
263
    if (vm)
264
        virObjectUnlock(vm);
D
Daniel Veillard 已提交
265 266 267 268 269 270
    return dom;
}

static virDomainPtr lxcDomainLookupByName(virConnectPtr conn,
                                          const char *name)
{
271
    virLXCDriverPtr driver = conn->privateData;
272 273
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
274

275
    vm = virDomainObjListFindByName(driver->domains, name);
D
Daniel Veillard 已提交
276
    if (!vm) {
277 278
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching name '%s'"), name);
279
        goto cleanup;
D
Daniel Veillard 已提交
280 281
    }

282 283 284
    if (virDomainLookupByNameEnsureACL(conn, vm->def) < 0)
        goto cleanup;

D
Daniel Veillard 已提交
285
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
286
    if (dom)
D
Daniel Veillard 已提交
287 288
        dom->id = vm->def->id;

289
cleanup:
290
    if (vm)
291
        virObjectUnlock(vm);
D
Daniel Veillard 已提交
292 293 294
    return dom;
}

295 296 297

static int lxcDomainIsActive(virDomainPtr dom)
{
298
    virLXCDriverPtr driver = dom->conn->privateData;
299 300 301
    virDomainObjPtr obj;
    int ret = -1;

302
    obj = virDomainObjListFindByUUID(driver->domains, dom->uuid);
303
    if (!obj) {
304 305
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
306 307
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
308 309
        goto cleanup;
    }
310 311 312 313

    if (virDomainIsActiveEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

314 315 316 317
    ret = virDomainObjIsActive(obj);

cleanup:
    if (obj)
318
        virObjectUnlock(obj);
319 320 321 322 323 324
    return ret;
}


static int lxcDomainIsPersistent(virDomainPtr dom)
{
325
    virLXCDriverPtr driver = dom->conn->privateData;
326 327 328
    virDomainObjPtr obj;
    int ret = -1;

329
    obj = virDomainObjListFindByUUID(driver->domains, dom->uuid);
330
    if (!obj) {
331 332
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
333 334
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
335 336
        goto cleanup;
    }
337 338 339 340

    if (virDomainIsPersistentEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

341 342 343 344
    ret = obj->persistent;

cleanup:
    if (obj)
345
        virObjectUnlock(obj);
346 347 348
    return ret;
}

349 350
static int lxcDomainIsUpdated(virDomainPtr dom)
{
351
    virLXCDriverPtr driver = dom->conn->privateData;
352 353 354
    virDomainObjPtr obj;
    int ret = -1;

355
    obj = virDomainObjListFindByUUID(driver->domains, dom->uuid);
356 357 358
    if (!obj) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
359 360
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
361 362
        goto cleanup;
    }
363 364 365 366

    if (virDomainIsUpdatedEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

367 368 369 370
    ret = obj->updated;

cleanup:
    if (obj)
371
        virObjectUnlock(obj);
372 373
    return ret;
}
374

375
static int lxcConnectListDomains(virConnectPtr conn, int *ids, int nids) {
376
    virLXCDriverPtr driver = conn->privateData;
377
    int n;
378

379 380 381
    if (virConnectListDomainsEnsureACL(conn) < 0)
        return -1;

382 383
    n = virDomainObjListGetActiveIDs(driver->domains, ids, nids,
                                     virConnectListDomainsCheckACL, conn);
384

385
    return n;
D
Daniel Veillard 已提交
386
}
387

388
static int lxcConnectNumOfDomains(virConnectPtr conn) {
389
    virLXCDriverPtr driver = conn->privateData;
390
    int n;
391

392 393 394
    if (virConnectNumOfDomainsEnsureACL(conn) < 0)
        return -1;

395 396
    n = virDomainObjListNumOfDomains(driver->domains, true,
                                     virConnectNumOfDomainsCheckACL, conn);
397

398
    return n;
D
Daniel Veillard 已提交
399 400
}

401 402
static int lxcConnectListDefinedDomains(virConnectPtr conn,
                                        char **const names, int nnames) {
403
    virLXCDriverPtr driver = conn->privateData;
404
    int n;
405

406 407 408
    if (virConnectListDefinedDomainsEnsureACL(conn) < 0)
        return -1;

409 410
    n = virDomainObjListGetInactiveNames(driver->domains, names, nnames,
                                         virConnectListDefinedDomainsCheckACL, conn);
411

412
    return n;
D
Daniel Veillard 已提交
413 414 415
}


416
static int lxcConnectNumOfDefinedDomains(virConnectPtr conn) {
417
    virLXCDriverPtr driver = conn->privateData;
418
    int n;
419

420 421 422
    if (virConnectNumOfDefinedDomainsEnsureACL(conn) < 0)
        return -1;

423 424
    n = virDomainObjListNumOfDomains(driver->domains, false,
                                     virConnectNumOfDefinedDomainsCheckACL, conn);
425

426
    return n;
D
Daniel Veillard 已提交
427 428
}

429 430


431
static virDomainPtr lxcDomainDefineXML(virConnectPtr conn, const char *xml)
D
Daniel Veillard 已提交
432
{
433
    virLXCDriverPtr driver = conn->privateData;
434
    virDomainDefPtr def = NULL;
435
    virDomainObjPtr vm = NULL;
436
    virDomainPtr dom = NULL;
437
    virDomainEventPtr event = NULL;
438
    virDomainDefPtr oldDef = NULL;
439
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
440
    virCapsPtr caps = NULL;
D
Daniel Veillard 已提交
441

442 443 444 445
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (!(def = virDomainDefParseString(xml, caps, driver->xmlopt,
M
Matthias Bolte 已提交
446
                                        1 << VIR_DOMAIN_VIRT_LXC,
447
                                        VIR_DOMAIN_XML_INACTIVE)))
448
        goto cleanup;
D
Daniel Veillard 已提交
449

450 451 452
    if (virDomainDefineXMLEnsureACL(conn, def) < 0)
        goto cleanup;

453 454 455
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

456
    if ((def->nets != NULL) && !(cfg->have_netns)) {
457 458
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
459
        goto cleanup;
460 461
    }

462
    if (!(vm = virDomainObjListAdd(driver->domains, def,
463
                                   driver->xmlopt,
464
                                   0, &oldDef)))
465 466
        goto cleanup;
    def = NULL;
467
    vm->persistent = 1;
D
Daniel Veillard 已提交
468

469
    if (virDomainSaveConfig(cfg->configDir,
470
                            vm->newDef ? vm->newDef : vm->def) < 0) {
471
        virDomainObjListRemove(driver->domains, vm);
472
        vm = NULL;
473
        goto cleanup;
D
Daniel Veillard 已提交
474 475
    }

476 477
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_DEFINED,
478
                                     !oldDef ?
479 480 481
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED :
                                     VIR_DOMAIN_EVENT_DEFINED_UPDATED);

D
Daniel Veillard 已提交
482
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
483
    if (dom)
D
Daniel Veillard 已提交
484 485
        dom->id = vm->def->id;

486 487
cleanup:
    virDomainDefFree(def);
488
    virDomainDefFree(oldDef);
489
    if (vm)
490
        virObjectUnlock(vm);
491
    if (event)
492
        virDomainEventStateQueue(driver->domainEventState, event);
493
    virObjectUnref(caps);
494
    virObjectUnref(cfg);
D
Daniel Veillard 已提交
495 496 497
    return dom;
}

498 499
static int lxcDomainUndefineFlags(virDomainPtr dom,
                                  unsigned int flags)
D
Daniel Veillard 已提交
500
{
501
    virLXCDriverPtr driver = dom->conn->privateData;
502
    virDomainObjPtr vm;
503
    virDomainEventPtr event = NULL;
504
    int ret = -1;
505
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
D
Daniel Veillard 已提交
506

507 508
    virCheckFlags(0, -1);

509
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
D
Daniel Veillard 已提交
510
    if (!vm) {
511 512
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
513 514
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
515
        goto cleanup;
D
Daniel Veillard 已提交
516 517
    }

518 519 520
    if (virDomainUndefineFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

521
    if (!vm->persistent) {
522 523
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot undefine transient domain"));
524
        goto cleanup;
525
    }
D
Daniel Veillard 已提交
526

527 528
    if (virDomainDeleteConfig(cfg->configDir,
                              cfg->autostartDir,
529 530
                              vm) < 0)
        goto cleanup;
D
Daniel Veillard 已提交
531

532 533 534 535
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_UNDEFINED,
                                     VIR_DOMAIN_EVENT_UNDEFINED_REMOVED);

536 537 538
    if (virDomainObjIsActive(vm)) {
        vm->persistent = 0;
    } else {
539
        virDomainObjListRemove(driver->domains, vm);
540 541 542
        vm = NULL;
    }

543
    ret = 0;
D
Daniel Veillard 已提交
544

545
cleanup:
546
    if (vm)
547
        virObjectUnlock(vm);
548
    if (event)
549
        virDomainEventStateQueue(driver->domainEventState, event);
550
    virObjectUnref(cfg);
551
    return ret;
D
Daniel Veillard 已提交
552 553
}

554 555 556 557 558
static int lxcDomainUndefine(virDomainPtr dom)
{
    return lxcDomainUndefineFlags(dom, 0);
}

D
Daniel Veillard 已提交
559 560 561
static int lxcDomainGetInfo(virDomainPtr dom,
                            virDomainInfoPtr info)
{
562
    virLXCDriverPtr driver = dom->conn->privateData;
563
    virDomainObjPtr vm;
564
    int ret = -1, rc;
565
    virLXCDomainObjPrivatePtr priv;
D
Daniel Veillard 已提交
566

567
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
568

D
Daniel Veillard 已提交
569
    if (!vm) {
570 571
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
572 573
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
574
        goto cleanup;
D
Daniel Veillard 已提交
575 576
    }

577 578
    priv = vm->privateData;

579 580 581
    if (virDomainGetInfoEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

J
Jiri Denemark 已提交
582
    info->state = virDomainObjGetState(vm, NULL);
D
Daniel Veillard 已提交
583

584
    if (!virDomainObjIsActive(vm)) {
D
Daniel Veillard 已提交
585
        info->cpuTime = 0;
586
        info->memory = vm->def->mem.cur_balloon;
D
Daniel Veillard 已提交
587
    } else {
588
        if (virCgroupGetCpuacctUsage(priv->cgroup, &(info->cpuTime)) < 0) {
589 590
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Cannot read cputime for domain"));
R
Ryota Ozaki 已提交
591 592
            goto cleanup;
        }
593
        if ((rc = virCgroupGetMemoryUsage(priv->cgroup, &(info->memory))) < 0) {
594 595
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Cannot read memory usage for domain"));
596 597 598 599 600 601
            if (rc == -ENOENT) {
                /* Don't fail if we can't read memory usage due to a lack of
                 * kernel support */
                info->memory = 0;
            } else
                goto cleanup;
602
        }
D
Daniel Veillard 已提交
603 604
    }

605
    info->maxMem = vm->def->mem.max_balloon;
606
    info->nrVirtCpu = vm->def->vcpus;
607
    ret = 0;
D
Daniel Veillard 已提交
608

609
cleanup:
610
    if (vm)
611
        virObjectUnlock(vm);
612
    return ret;
D
Daniel Veillard 已提交
613 614
}

615 616 617 618 619 620
static int
lxcDomainGetState(virDomainPtr dom,
                  int *state,
                  int *reason,
                  unsigned int flags)
{
621
    virLXCDriverPtr driver = dom->conn->privateData;
622 623 624 625 626
    virDomainObjPtr vm;
    int ret = -1;

    virCheckFlags(0, -1);

627
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
628 629 630 631

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
632 633
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
634 635 636
        goto cleanup;
    }

637 638 639
    if (virDomainGetStateEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

J
Jiri Denemark 已提交
640
    *state = virDomainObjGetState(vm, reason);
641 642 643 644
    ret = 0;

cleanup:
    if (vm)
645
        virObjectUnlock(vm);
646 647 648
    return ret;
}

649
static char *lxcDomainGetOSType(virDomainPtr dom)
D
Daniel Veillard 已提交
650
{
651
    virLXCDriverPtr driver = dom->conn->privateData;
652 653
    virDomainObjPtr vm;
    char *ret = NULL;
654

655
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
656

657
    if (!vm) {
658 659
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
660 661
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
662
        goto cleanup;
663 664
    }

665 666 667 668 669
    if (virDomainGetOSTypeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

    if (VIR_STRDUP(ret, vm->def->os.type) < 0)
        goto cleanup;
670

671
cleanup:
672
    if (vm)
673
        virObjectUnlock(vm);
674
    return ret;
D
Daniel Veillard 已提交
675 676
}

R
Ryota Ozaki 已提交
677
/* Returns max memory in kb, 0 if error */
678 679 680
static unsigned long long
lxcDomainGetMaxMemory(virDomainPtr dom)
{
681
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
682
    virDomainObjPtr vm;
683
    unsigned long long ret = 0;
R
Ryota Ozaki 已提交
684

685
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
R
Ryota Ozaki 已提交
686 687 688 689

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
690 691
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
R
Ryota Ozaki 已提交
692 693 694
        goto cleanup;
    }

695 696 697
    if (virDomainGetMaxMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

698
    ret = vm->def->mem.max_balloon;
R
Ryota Ozaki 已提交
699 700 701

cleanup:
    if (vm)
702
        virObjectUnlock(vm);
R
Ryota Ozaki 已提交
703 704 705 706
    return ret;
}

static int lxcDomainSetMaxMemory(virDomainPtr dom, unsigned long newmax) {
707
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
708 709 710
    virDomainObjPtr vm;
    int ret = -1;

711
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
R
Ryota Ozaki 已提交
712 713 714 715

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
716 717
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
R
Ryota Ozaki 已提交
718 719 720
        goto cleanup;
    }

721 722 723
    if (virDomainSetMaxMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

724
    if (newmax < vm->def->mem.cur_balloon) {
725 726
        virReportError(VIR_ERR_INVALID_ARG,
                       "%s", _("Cannot set max memory lower than current memory"));
R
Ryota Ozaki 已提交
727 728 729
        goto cleanup;
    }

730
    vm->def->mem.max_balloon = newmax;
R
Ryota Ozaki 已提交
731 732 733 734
    ret = 0;

cleanup:
    if (vm)
735
        virObjectUnlock(vm);
R
Ryota Ozaki 已提交
736 737 738 739
    return ret;
}

static int lxcDomainSetMemory(virDomainPtr dom, unsigned long newmem) {
740
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
741 742
    virDomainObjPtr vm;
    int ret = -1;
743
    virLXCDomainObjPrivatePtr priv;
R
Ryota Ozaki 已提交
744

745
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
R
Ryota Ozaki 已提交
746 747 748
    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
749 750
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
R
Ryota Ozaki 已提交
751 752
        goto cleanup;
    }
753
    priv = vm->privateData;
R
Ryota Ozaki 已提交
754

755 756 757
    if (virDomainSetMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

758
    if (newmem > vm->def->mem.max_balloon) {
759 760
        virReportError(VIR_ERR_INVALID_ARG,
                       "%s", _("Cannot set memory higher than max memory"));
R
Ryota Ozaki 已提交
761 762 763
        goto cleanup;
    }

764
    if (!virDomainObjIsActive(vm)) {
765 766
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
767 768
        goto cleanup;
    }
769

770
    if (virCgroupSetMemory(priv->cgroup, newmem) < 0) {
771 772
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("Failed to set memory for domain"));
773 774 775
        goto cleanup;
    }

R
Ryota Ozaki 已提交
776 777 778 779
    ret = 0;

cleanup:
    if (vm)
780
        virObjectUnlock(vm);
R
Ryota Ozaki 已提交
781 782 783
    return ret;
}

784 785 786 787 788
static int
lxcDomainSetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int nparams,
                             unsigned int flags)
789
{
790
    virLXCDriverPtr driver = dom->conn->privateData;
791
    size_t i;
792 793
    virDomainObjPtr vm = NULL;
    int ret = -1;
794
    int rc;
795
    virLXCDomainObjPrivatePtr priv;
796

E
Eric Blake 已提交
797
    virCheckFlags(0, -1);
798 799 800 801 802 803 804 805
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_MEMORY_HARD_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               NULL) < 0)
806
        return -1;
E
Eric Blake 已提交
807

808
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
809 810 811 812

    if (vm == NULL) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
813 814
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
815 816
        goto cleanup;
    }
817
    priv = vm->privateData;
818

819 820 821
    if (virDomainSetMemoryParametersEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

822 823
    ret = 0;
    for (i = 0; i < nparams; i++) {
824
        virTypedParameterPtr param = &params[i];
825 826

        if (STREQ(param->field, VIR_DOMAIN_MEMORY_HARD_LIMIT)) {
827
            rc = virCgroupSetMemoryHardLimit(priv->cgroup, params[i].value.ul);
828 829 830 831 832 833
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to set memory hard_limit tunable"));
                ret = -1;
            }
        } else if (STREQ(param->field, VIR_DOMAIN_MEMORY_SOFT_LIMIT)) {
834
            rc = virCgroupSetMemorySoftLimit(priv->cgroup, params[i].value.ul);
835 836 837 838 839
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to set memory soft_limit tunable"));
                ret = -1;
            }
840
        } else if (STREQ(param->field, VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT)) {
841
            rc = virCgroupSetMemSwapHardLimit(priv->cgroup, params[i].value.ul);
842 843 844 845 846 847 848 849 850 851
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to set swap_hard_limit tunable"));
                ret = -1;
            }
        }
    }

cleanup:
    if (vm)
852
        virObjectUnlock(vm);
853 854 855
    return ret;
}

856 857 858 859 860
static int
lxcDomainGetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int *nparams,
                             unsigned int flags)
861
{
862
    virLXCDriverPtr driver = dom->conn->privateData;
863
    size_t i;
864
    virDomainObjPtr vm = NULL;
865
    unsigned long long val;
866 867
    int ret = -1;
    int rc;
868
    virLXCDomainObjPrivatePtr priv;
869

E
Eric Blake 已提交
870 871
    virCheckFlags(0, -1);

872
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
873 874 875 876

    if (vm == NULL) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
877 878
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
879 880
        goto cleanup;
    }
881
    priv = vm->privateData;
882

883 884 885
    if (virDomainGetMemoryParametersEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

886 887 888 889 890 891 892
    if ((*nparams) == 0) {
        /* Current number of memory parameters supported by cgroups */
        *nparams = LXC_NB_MEM_PARAM;
        ret = 0;
        goto cleanup;
    }

893
    for (i = 0; i < LXC_NB_MEM_PARAM && i < *nparams; i++) {
894
        virTypedParameterPtr param = &params[i];
895 896
        val = 0;

897
        switch (i) {
898
        case 0: /* fill memory hard limit here */
899
            rc = virCgroupGetMemoryHardLimit(priv->cgroup, &val);
900 901 902
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to get memory hard limit"));
903
                goto cleanup;
904
            }
905 906
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
907
                goto cleanup;
908 909
            break;
        case 1: /* fill memory soft limit here */
910
            rc = virCgroupGetMemorySoftLimit(priv->cgroup, &val);
911 912 913
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to get memory soft limit"));
914
                goto cleanup;
915
            }
916 917
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
918
                goto cleanup;
919 920
            break;
        case 2: /* fill swap hard limit here */
921
            rc = virCgroupGetMemSwapHardLimit(priv->cgroup, &val);
922 923 924
            if (rc != 0) {
                virReportSystemError(-rc, "%s",
                                     _("unable to get swap hard limit"));
925
                goto cleanup;
926
            }
927 928 929
            if (virTypedParameterAssign(param,
                                        VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
930
                goto cleanup;
931 932
            break;

933
        /* coverity[dead_error_begin] */
934 935 936 937 938 939
        default:
            break;
            /* should not hit here */
        }
    }

940 941
    if (*nparams > LXC_NB_MEM_PARAM)
        *nparams = LXC_NB_MEM_PARAM;
942 943
    ret = 0;

944 945
cleanup:
    if (vm)
946
        virObjectUnlock(vm);
947 948 949
    return ret;
}

950
static char *lxcDomainGetXMLDesc(virDomainPtr dom,
951
                                 unsigned int flags)
D
Daniel Veillard 已提交
952
{
953
    virLXCDriverPtr driver = dom->conn->privateData;
954 955
    virDomainObjPtr vm;
    char *ret = NULL;
D
Daniel Veillard 已提交
956

957 958
    /* Flags checked by virDomainDefFormat */

959
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
960

D
Daniel Veillard 已提交
961
    if (!vm) {
962 963
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
964 965
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
966
        goto cleanup;
D
Daniel Veillard 已提交
967 968
    }

969 970 971
    if (virDomainGetXMLDescEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

972
    ret = virDomainDefFormat((flags & VIR_DOMAIN_XML_INACTIVE) &&
973 974 975 976
                             vm->newDef ? vm->newDef : vm->def,
                             flags);

cleanup:
977
    if (vm)
978
        virObjectUnlock(vm);
979
    return ret;
D
Daniel Veillard 已提交
980 981
}

982
/**
983
 * lxcDomainCreateWithFlags:
984
 * @dom: domain to start
985
 * @flags: Must be 0 for now
986 987 988 989 990
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
991 992 993 994
static int lxcDomainCreateWithFiles(virDomainPtr dom,
                                    unsigned int nfiles,
                                    int *files,
                                    unsigned int flags)
995
{
996
    virLXCDriverPtr driver = dom->conn->privateData;
997
    virDomainObjPtr vm;
998
    virDomainEventPtr event = NULL;
999
    int ret = -1;
1000
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1001

1002
    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY, -1);
1003

1004
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
1005
    if (!vm) {
1006 1007
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
1008 1009
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
1010 1011 1012
        goto cleanup;
    }

1013
    if (virDomainCreateWithFilesEnsureACL(dom->conn, vm->def) < 0)
1014 1015
        goto cleanup;

1016
    if ((vm->def->nets != NULL) && !(cfg->have_netns)) {
1017 1018
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
1019 1020 1021
        goto cleanup;
    }

1022
    if (virDomainObjIsActive(vm)) {
1023 1024
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is already running"));
1025 1026 1027
        goto cleanup;
    }

1028
    ret = virLXCProcessStart(dom->conn, driver, vm,
1029
                             nfiles, files,
1030 1031
                             (flags & VIR_DOMAIN_START_AUTODESTROY),
                             VIR_DOMAIN_RUNNING_BOOTED);
1032

1033
    if (ret == 0) {
1034 1035 1036
        event = virDomainEventNewFromObj(vm,
                                         VIR_DOMAIN_EVENT_STARTED,
                                         VIR_DOMAIN_EVENT_STARTED_BOOTED);
1037 1038 1039 1040
        virDomainAuditStart(vm, "booted", true);
    } else {
        virDomainAuditStart(vm, "booted", false);
    }
1041

1042
cleanup:
1043
    if (vm)
1044
        virObjectUnlock(vm);
1045
    if (event)
1046
        virDomainEventStateQueue(driver->domainEventState, event);
1047
    virObjectUnref(cfg);
1048
    return ret;
1049 1050
}

1051
/**
1052
 * lxcDomainCreate:
1053 1054 1055 1056 1057 1058
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
1059
static int lxcDomainCreate(virDomainPtr dom)
1060
{
1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075
    return lxcDomainCreateWithFiles(dom, 0, NULL, 0);
}

/**
 * lxcDomainCreateWithFlags:
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
static int lxcDomainCreateWithFlags(virDomainPtr dom,
                                    unsigned int flags)
{
    return lxcDomainCreateWithFiles(dom, 0, NULL, flags);
1076 1077
}

1078
/**
1079
 * lxcDomainCreateXML:
1080 1081
 * @conn: pointer to connection
 * @xml: XML definition of domain
1082
 * @flags: Must be 0 for now
1083 1084 1085 1086 1087 1088
 *
 * Creates a domain based on xml and starts it
 *
 * Returns 0 on success or -1 in case of error
 */
static virDomainPtr
1089 1090 1091 1092 1093
lxcDomainCreateXMLWithFiles(virConnectPtr conn,
                            const char *xml,
                            unsigned int nfiles,
                            int *files,
                            unsigned int flags) {
1094
    virLXCDriverPtr driver = conn->privateData;
1095
    virDomainObjPtr vm = NULL;
1096
    virDomainDefPtr def = NULL;
1097
    virDomainPtr dom = NULL;
1098
    virDomainEventPtr event = NULL;
1099
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1100
    virCapsPtr caps = NULL;
1101

1102
    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY, NULL);
1103

1104 1105 1106 1107
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (!(def = virDomainDefParseString(xml, caps, driver->xmlopt,
M
Matthias Bolte 已提交
1108
                                        1 << VIR_DOMAIN_VIRT_LXC,
1109
                                        VIR_DOMAIN_XML_INACTIVE)))
1110
        goto cleanup;
1111

1112
    if (virDomainCreateXMLWithFilesEnsureACL(conn, def) < 0)
1113 1114
        goto cleanup;

1115 1116 1117
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

1118
    if ((def->nets != NULL) && !(cfg->have_netns)) {
1119 1120
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       "%s", _("System lacks NETNS support"));
1121
        goto cleanup;
1122 1123
    }

1124

1125
    if (!(vm = virDomainObjListAdd(driver->domains, def,
1126
                                   driver->xmlopt,
1127 1128
                                   VIR_DOMAIN_OBJ_LIST_ADD_CHECK_LIVE,
                                   NULL)))
1129 1130
        goto cleanup;
    def = NULL;
1131

1132
    if (virLXCProcessStart(conn, driver, vm,
1133
                           nfiles, files,
1134 1135
                           (flags & VIR_DOMAIN_START_AUTODESTROY),
                           VIR_DOMAIN_RUNNING_BOOTED) < 0) {
1136
        virDomainAuditStart(vm, "booted", false);
1137
        virDomainObjListRemove(driver->domains, vm);
1138
        vm = NULL;
1139
        goto cleanup;
1140 1141
    }

1142 1143 1144
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_STARTED,
                                     VIR_DOMAIN_EVENT_STARTED_BOOTED);
1145
    virDomainAuditStart(vm, "booted", true);
1146

1147
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
1148
    if (dom)
1149 1150
        dom->id = vm->def->id;

1151 1152
cleanup:
    virDomainDefFree(def);
1153
    if (vm)
1154
        virObjectUnlock(vm);
1155
    if (event)
1156
        virDomainEventStateQueue(driver->domainEventState, event);
1157
    virObjectUnref(caps);
1158
    virObjectUnref(cfg);
1159 1160 1161
    return dom;
}

1162

1163 1164 1165 1166 1167 1168 1169 1170
static virDomainPtr
lxcDomainCreateXML(virConnectPtr conn,
                   const char *xml,
                   unsigned int flags) {
    return lxcDomainCreateXMLWithFiles(conn, xml, 0, NULL,  flags);
}


1171 1172
static int lxcDomainGetSecurityLabel(virDomainPtr dom, virSecurityLabelPtr seclabel)
{
1173
    virLXCDriverPtr driver = dom->conn->privateData;
1174 1175 1176
    virDomainObjPtr vm;
    int ret = -1;

1177
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
1178 1179 1180 1181 1182 1183

    memset(seclabel, 0, sizeof(*seclabel));

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
1184 1185
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
1186 1187 1188
        goto cleanup;
    }

1189 1190 1191
    if (virDomainGetSecurityLabelEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1192
    if (!virDomainVirtTypeToString(vm->def->virtType)) {
1193 1194 1195
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unknown virt type in domain definition '%d'"),
                       vm->def->virtType);
1196 1197 1198 1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213
        goto cleanup;
    }

    /*
     * Theoretically, the pid can be replaced during this operation and
     * return the label of a different process.  If atomicity is needed,
     * further validation will be required.
     *
     * Comment from Dan Berrange:
     *
     *   Well the PID as stored in the virDomainObjPtr can't be changed
     *   because you've got a locked object.  The OS level PID could have
     *   exited, though and in extreme circumstances have cycled through all
     *   PIDs back to ours. We could sanity check that our PID still exists
     *   after reading the label, by checking that our FD connecting to the
     *   LXC monitor hasn't seen SIGHUP/ERR on poll().
     */
    if (virDomainObjIsActive(vm)) {
1214 1215 1216 1217 1218 1219 1220 1221
        virLXCDomainObjPrivatePtr priv = vm->privateData;

        if (!priv->initpid) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("Init pid is not yet available"));
            goto cleanup;
        }

1222
        if (virSecurityManagerGetProcessLabel(driver->securityManager,
1223
                                              vm->def, priv->initpid, seclabel) < 0) {
1224 1225
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("Failed to get security label"));
1226 1227 1228 1229 1230 1231 1232 1233
            goto cleanup;
        }
    }

    ret = 0;

cleanup:
    if (vm)
1234
        virObjectUnlock(vm);
1235 1236 1237 1238 1239 1240
    return ret;
}

static int lxcNodeGetSecurityModel(virConnectPtr conn,
                                   virSecurityModelPtr secmodel)
{
1241
    virLXCDriverPtr driver = conn->privateData;
1242
    virCapsPtr caps = NULL;
1243 1244 1245 1246
    int ret = 0;

    memset(secmodel, 0, sizeof(*secmodel));

1247 1248 1249
    if (virNodeGetSecurityModelEnsureACL(conn) < 0)
        goto cleanup;

1250 1251 1252
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

1253
    /* we treat no driver as success, but simply return no data in *secmodel */
1254 1255
    if (caps->host.nsecModels == 0
        || caps->host.secModels[0].model == NULL)
1256 1257
        goto cleanup;

1258
    if (!virStrcpy(secmodel->model, caps->host.secModels[0].model,
1259
                   VIR_SECURITY_MODEL_BUFLEN)) {
1260 1261 1262
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security model string exceeds max %d bytes"),
                       VIR_SECURITY_MODEL_BUFLEN - 1);
1263 1264 1265 1266
        ret = -1;
        goto cleanup;
    }

1267
    if (!virStrcpy(secmodel->doi, caps->host.secModels[0].doi,
1268
                   VIR_SECURITY_DOI_BUFLEN)) {
1269 1270 1271
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security DOI string exceeds max %d bytes"),
                       VIR_SECURITY_DOI_BUFLEN-1);
1272 1273 1274 1275 1276
        ret = -1;
        goto cleanup;
    }

cleanup:
1277
    virObjectUnref(caps);
1278 1279 1280 1281
    return ret;
}


1282
static int
1283 1284 1285 1286
lxcConnectDomainEventRegister(virConnectPtr conn,
                              virConnectDomainEventCallback callback,
                              void *opaque,
                              virFreeCallback freecb)
1287
{
1288
    virLXCDriverPtr driver = conn->privateData;
1289 1290
    int ret;

1291 1292 1293
    if (virConnectDomainEventRegisterEnsureACL(conn) < 0)
        return -1;

1294 1295 1296
    ret = virDomainEventStateRegister(conn,
                                      driver->domainEventState,
                                      callback, opaque, freecb);
1297

1298
    return ret;
1299 1300
}

1301

1302
static int
1303 1304
lxcConnectDomainEventDeregister(virConnectPtr conn,
                                virConnectDomainEventCallback callback)
1305
{
1306
    virLXCDriverPtr driver = conn->privateData;
1307 1308
    int ret;

1309 1310 1311
    if (virConnectDomainEventDeregisterEnsureACL(conn) < 0)
        return -1;

1312 1313 1314
    ret = virDomainEventStateDeregister(conn,
                                        driver->domainEventState,
                                        callback);
1315 1316 1317 1318

    return ret;
}

1319 1320

static int
1321 1322 1323 1324 1325 1326
lxcConnectDomainEventRegisterAny(virConnectPtr conn,
                                 virDomainPtr dom,
                                 int eventID,
                                 virConnectDomainEventGenericCallback callback,
                                 void *opaque,
                                 virFreeCallback freecb)
1327
{
1328
    virLXCDriverPtr driver = conn->privateData;
1329 1330
    int ret;

1331 1332 1333
    if (virConnectDomainEventRegisterAnyEnsureACL(conn) < 0)
        return -1;

1334 1335 1336 1337
    if (virDomainEventStateRegisterID(conn,
                                      driver->domainEventState,
                                      dom, eventID,
                                      callback, opaque, freecb, &ret) < 0)
1338
        ret = -1;
1339 1340 1341 1342 1343 1344

    return ret;
}


static int
1345 1346
lxcConnectDomainEventDeregisterAny(virConnectPtr conn,
                                   int callbackID)
1347
{
1348
    virLXCDriverPtr driver = conn->privateData;
1349 1350
    int ret;

1351 1352 1353
    if (virConnectDomainEventDeregisterAnyEnsureACL(conn) < 0)
        return -1;

1354 1355 1356
    ret = virDomainEventStateDeregisterID(conn,
                                          driver->domainEventState,
                                          callbackID);
1357 1358 1359 1360 1361

    return ret;
}


1362
/**
1363
 * lxcDomainDestroyFlags:
1364
 * @dom: pointer to domain to destroy
1365
 * @flags: an OR'ed set of virDomainDestroyFlags
1366 1367 1368 1369 1370
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
1371 1372 1373
static int
lxcDomainDestroyFlags(virDomainPtr dom,
                      unsigned int flags)
1374
{
1375
    virLXCDriverPtr driver = dom->conn->privateData;
1376
    virDomainObjPtr vm;
1377
    virDomainEventPtr event = NULL;
1378
    int ret = -1;
1379
    virLXCDomainObjPrivatePtr priv;
1380

1381 1382
    virCheckFlags(0, -1);

1383
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
1384
    if (!vm) {
1385 1386
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
1387 1388
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
1389
        goto cleanup;
1390 1391
    }

1392 1393 1394
    if (virDomainDestroyFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1395
    if (!virDomainObjIsActive(vm)) {
1396 1397
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
1398 1399 1400
        goto cleanup;
    }

1401
    priv = vm->privateData;
1402
    ret = virLXCProcessStop(driver, vm, VIR_DOMAIN_SHUTOFF_DESTROYED);
1403 1404 1405
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_STOPPED,
                                     VIR_DOMAIN_EVENT_STOPPED_DESTROYED);
1406
    priv->doneStopEvent = true;
1407
    virDomainAuditStop(vm, "destroyed");
1408
    if (!vm->persistent) {
1409
        virDomainObjListRemove(driver->domains, vm);
1410 1411
        vm = NULL;
    }
1412 1413

cleanup:
1414
    if (vm)
1415
        virObjectUnlock(vm);
1416
    if (event)
1417
        virDomainEventStateQueue(driver->domainEventState, event);
1418
    return ret;
1419
}
1420

1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434
/**
 * lxcDomainDestroy:
 * @dom: pointer to domain to destroy
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
static int
lxcDomainDestroy(virDomainPtr dom)
{
    return lxcDomainDestroyFlags(dom, 0);
}

1435 1436 1437 1438 1439
static int lxcCheckNetNsSupport(void)
{
    const char *argv[] = {"ip", "link", "set", "lo", "netns", "-1", NULL};
    int ip_rc;

1440
    if (virRun(argv, &ip_rc) < 0 ||
1441 1442
        !(WIFEXITED(ip_rc) && (WEXITSTATUS(ip_rc) != 255)))
        return 0;
1443

1444 1445
    if (lxcContainerAvailable(LXC_CONTAINER_FEATURE_NET) < 0)
        return 0;
1446

1447
    return 1;
1448 1449
}

1450

1451 1452
static virSecurityManagerPtr
lxcSecurityInit(virLXCDriverConfigPtr cfg)
1453
{
1454 1455
    VIR_INFO("lxcSecurityInit %s", cfg->securityDriverName);
    virSecurityManagerPtr mgr = virSecurityManagerNew(cfg->securityDriverName,
1456
                                                      LXC_DRIVER_NAME,
1457
                                                      false,
1458 1459
                                                      cfg->securityDefaultConfined,
                                                      cfg->securityRequireConfined);
1460 1461 1462
    if (!mgr)
        goto error;

1463
    return mgr;
1464 1465 1466

error:
    VIR_ERROR(_("Failed to initialize security drivers"));
1467
    virObjectUnref(mgr);
1468
    return NULL;
1469 1470 1471
}


1472 1473 1474
static int lxcStateInitialize(bool privileged,
                              virStateInhibitCallback callback ATTRIBUTE_UNUSED,
                              void *opaque ATTRIBUTE_UNUSED)
D
Daniel Veillard 已提交
1475
{
1476
    virCapsPtr caps = NULL;
1477
    char *ld;
1478
    virLXCDriverConfigPtr cfg = NULL;
1479 1480 1481 1482 1483 1484

    /* Valgrind gets very annoyed when we clone containers, so
     * disable LXC when under valgrind
     * XXX remove this when valgrind is fixed
     */
    ld = getenv("LD_PRELOAD");
1485
    if (ld && strstr(ld, "vgpreload")) {
1486
        VIR_INFO("Running under valgrind, disabling driver");
1487 1488
        return 0;
    }
1489

1490
    /* Check that the user is root, silently disable if not */
1491
    if (!privileged) {
1492
        VIR_INFO("Not running privileged, disabling driver");
1493 1494 1495 1496 1497
        return 0;
    }

    /* Check that this is a container enabled kernel */
    if (lxcContainerAvailable(0) < 0) {
1498
        VIR_INFO("LXC support not available in this kernel, disabling driver");
1499
        return 0;
1500 1501
    }

1502
    if (VIR_ALLOC(lxc_driver) < 0) {
1503 1504
        return -1;
    }
1505 1506 1507 1508
    if (virMutexInit(&lxc_driver->lock) < 0) {
        VIR_FREE(lxc_driver);
        return -1;
    }
D
Daniel Veillard 已提交
1509

1510
    if (!(lxc_driver->domains = virDomainObjListNew()))
1511 1512
        goto cleanup;

1513
    lxc_driver->domainEventState = virDomainEventStateNew();
1514
    if (!lxc_driver->domainEventState)
1515 1516
        goto cleanup;

1517 1518
    lxc_driver->hostsysinfo = virSysinfoRead();

1519 1520 1521 1522 1523
    if (!(lxc_driver->config = cfg = virLXCDriverConfigNew()))
        goto cleanup;

    cfg->log_libvirtd = 0; /* by default log to container logfile */
    cfg->have_netns = lxcCheckNetNsSupport();
D
Daniel Veillard 已提交
1524 1525

    /* Call function to load lxc driver configuration information */
1526
    if (virLXCLoadDriverConfig(cfg, SYSCONFDIR "/libvirt/lxc.conf") < 0)
1527
        goto cleanup;
D
Daniel Veillard 已提交
1528

1529
    if (!(lxc_driver->securityManager = lxcSecurityInit(cfg)))
1530 1531
        goto cleanup;

G
Guido Günther 已提交
1532 1533 1534
    if ((lxc_driver->activeUsbHostdevs = virUSBDeviceListNew()) == NULL)
        goto cleanup;

1535
    if ((virLXCDriverGetCapabilities(lxc_driver, true)) == NULL)
1536
        goto cleanup;
D
Daniel Veillard 已提交
1537

1538
    if (!(lxc_driver->xmlopt = lxcDomainXMLConfInit()))
1539
        goto cleanup;
1540

1541
    if (!(lxc_driver->closeCallbacks = virCloseCallbacksNew()))
1542 1543
        goto cleanup;

1544 1545 1546
    if (!(caps = virLXCDriverGetCapabilities(lxc_driver, false)))
        goto cleanup;

O
Osier Yang 已提交
1547
    /* Get all the running persistent or transient configs first */
1548
    if (virDomainObjListLoadAllConfigs(lxc_driver->domains,
1549
                                       cfg->stateDir,
1550
                                       NULL, 1,
1551
                                       caps,
1552
                                       lxc_driver->xmlopt,
1553
                                       1 << VIR_DOMAIN_VIRT_LXC,
1554
                                       NULL, NULL) < 0)
O
Osier Yang 已提交
1555 1556
        goto cleanup;

1557
    virLXCProcessReconnectAll(lxc_driver, lxc_driver->domains);
O
Osier Yang 已提交
1558 1559

    /* Then inactive persistent configs */
1560
    if (virDomainObjListLoadAllConfigs(lxc_driver->domains,
1561 1562
                                       cfg->configDir,
                                       cfg->autostartDir, 0,
1563
                                       caps,
1564
                                       lxc_driver->xmlopt,
1565
                                       1 << VIR_DOMAIN_VIRT_LXC,
1566
                                       NULL, NULL) < 0)
1567
        goto cleanup;
1568

1569
    virLXCProcessAutostartAll(lxc_driver);
1570

1571
    virNWFilterRegisterCallbackDriver(&lxcCallbackDriver);
D
Daniel Veillard 已提交
1572 1573
    return 0;

1574
cleanup:
1575
    virObjectUnref(caps);
1576
    lxcStateCleanup();
1577
    return -1;
D
Daniel Veillard 已提交
1578 1579
}

1580 1581
static void lxcNotifyLoadDomain(virDomainObjPtr vm, int newVM, void *opaque)
{
1582
    virLXCDriverPtr driver = opaque;
1583 1584 1585 1586 1587 1588 1589

    if (newVM) {
        virDomainEventPtr event =
            virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_DEFINED,
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED);
        if (event)
1590
            virDomainEventStateQueue(driver->domainEventState, event);
1591 1592 1593 1594
    }
}

/**
1595
 * lxcStateReload:
1596 1597 1598 1599 1600
 *
 * Function to restart the LXC driver, it will recheck the configuration
 * files and perform autostart
 */
static int
1601
lxcStateReload(void) {
1602
    virLXCDriverConfigPtr cfg = NULL;
1603
    virCapsPtr caps = NULL;
1604

1605 1606 1607
    if (!lxc_driver)
        return 0;

1608
    if (!(caps = virLXCDriverGetCapabilities(lxc_driver, false)))
1609 1610
        return -1;

1611 1612
    cfg = virLXCDriverGetConfig(lxc_driver);

1613
    virDomainObjListLoadAllConfigs(lxc_driver->domains,
1614 1615
                                   cfg->configDir,
                                   cfg->autostartDir, 0,
1616
                                   caps,
1617
                                   lxc_driver->xmlopt,
1618
                                   1 << VIR_DOMAIN_VIRT_LXC,
1619
                                   lxcNotifyLoadDomain, lxc_driver);
1620
    virObjectUnref(caps);
1621
    virObjectUnref(cfg);
1622 1623 1624
    return 0;
}

1625
static int lxcStateCleanup(void)
D
Daniel Veillard 已提交
1626
{
1627
    if (lxc_driver == NULL)
1628
        return -1;
1629

1630
    virNWFilterUnRegisterCallbackDriver(&lxcCallbackDriver);
1631
    virObjectUnref(lxc_driver->domains);
1632
    virDomainEventStateFree(lxc_driver->domainEventState);
1633

1634
    virObjectUnref(lxc_driver->closeCallbacks);
1635

1636 1637
    virSysinfoDefFree(lxc_driver->hostsysinfo);

G
Guido Günther 已提交
1638
    virObjectUnref(lxc_driver->activeUsbHostdevs);
1639
    virObjectUnref(lxc_driver->caps);
1640
    virObjectUnref(lxc_driver->securityManager);
1641
    virObjectUnref(lxc_driver->xmlopt);
1642
    virObjectUnref(lxc_driver->config);
1643
    virMutexDestroy(&lxc_driver->lock);
1644
    VIR_FREE(lxc_driver);
1645 1646 1647

    return 0;
}
D
Daniel Veillard 已提交
1648 1649


1650
static int lxcConnectGetVersion(virConnectPtr conn, unsigned long *version)
D
Dan Smith 已提交
1651 1652 1653
{
    struct utsname ver;

1654
    uname(&ver);
D
Dan Smith 已提交
1655

1656 1657 1658
    if (virConnectGetVersionEnsureACL(conn) < 0)
        return -1;

1659
    if (virParseVersionString(ver.release, version, true) < 0) {
1660
        virReportError(VIR_ERR_INTERNAL_ERROR, _("Unknown release: %s"), ver.release);
D
Dan Smith 已提交
1661 1662 1663 1664 1665
        return -1;
    }

    return 0;
}
1666

1667

1668
static char *lxcConnectGetHostname(virConnectPtr conn)
1669
{
1670 1671 1672
    if (virConnectGetHostnameEnsureACL(conn) < 0)
        return NULL;

1673 1674 1675 1676 1677
    return virGetHostname();
}



1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689 1690 1691 1692 1693 1694 1695 1696 1697 1698 1699 1700 1701 1702 1703 1704 1705 1706 1707 1708 1709 1710
/*
 * check whether the host supports CFS bandwidth
 *
 * Return 1 when CFS bandwidth is supported, 0 when CFS bandwidth is not
 * supported, -1 on error.
 */
static int lxcGetCpuBWStatus(virCgroupPtr cgroup)
{
    char *cfs_period_path = NULL;
    int ret = -1;

    if (!cgroup)
        return 0;

    if (virCgroupPathOfController(cgroup, VIR_CGROUP_CONTROLLER_CPU,
                                  "cpu.cfs_period_us", &cfs_period_path) < 0) {
        VIR_INFO("cannot get the path of cgroup CPU controller");
        ret = 0;
        goto cleanup;
    }

    if (access(cfs_period_path, F_OK) < 0) {
        ret = 0;
    } else {
        ret = 1;
    }

cleanup:
    VIR_FREE(cfs_period_path);
    return ret;
}


1711 1712
static char *lxcDomainGetSchedulerType(virDomainPtr dom,
                                       int *nparams)
1713
{
1714
    virLXCDriverPtr driver = dom->conn->privateData;
1715 1716
    char *ret = NULL;
    int rc;
1717 1718
    virDomainObjPtr vm;
    virLXCDomainObjPrivatePtr priv;
1719

1720 1721 1722 1723 1724 1725 1726 1727
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
    if (vm == NULL) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No such domain %s"), dom->uuid);
        goto cleanup;
    }
    priv = vm->privateData;

1728 1729 1730
    if (virDomainGetSchedulerTypeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1731 1732 1733 1734 1735 1736 1737 1738
    /* Domain not running, thus no cgroups - return defaults */
    if (!virDomainObjIsActive(vm)) {
        if (nparams)
            *nparams = 3;
        ignore_value(VIR_STRDUP(ret, "posix"));
        goto cleanup;
    }

1739
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
1740 1741
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
1742 1743
        goto cleanup;
    }
1744

1745
    if (nparams) {
1746
        rc = lxcGetCpuBWStatus(priv->cgroup);
1747 1748 1749 1750 1751 1752 1753
        if (rc < 0)
            goto cleanup;
        else if (rc == 0)
            *nparams = 1;
        else
            *nparams = 3;
    }
1754

1755
    ignore_value(VIR_STRDUP(ret, "posix"));
1756

1757
cleanup:
1758 1759
    if (vm)
        virObjectUnlock(vm);
1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789 1790 1791 1792 1793 1794 1795 1796 1797 1798 1799 1800 1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821 1822 1823 1824 1825 1826 1827 1828
    return ret;
}


static int
lxcGetVcpuBWLive(virCgroupPtr cgroup, unsigned long long *period,
                 long long *quota)
{
    int rc;

    rc = virCgroupGetCpuCfsPeriod(cgroup, period);
    if (rc < 0) {
        virReportSystemError(-rc, "%s",
                             _("unable to get cpu bandwidth period tunable"));
        return -1;
    }

    rc = virCgroupGetCpuCfsQuota(cgroup, quota);
    if (rc < 0) {
        virReportSystemError(-rc, "%s",
                             _("unable to get cpu bandwidth tunable"));
        return -1;
    }

    return 0;
}


static int lxcSetVcpuBWLive(virCgroupPtr cgroup, unsigned long long period,
                            long long quota)
{
    int rc;
    unsigned long long old_period;

    if (period == 0 && quota == 0)
        return 0;

    if (period) {
        /* get old period, and we can rollback if set quota failed */
        rc = virCgroupGetCpuCfsPeriod(cgroup, &old_period);
        if (rc < 0) {
            virReportSystemError(-rc,
                                 "%s", _("Unable to get cpu bandwidth period"));
            return -1;
        }

        rc = virCgroupSetCpuCfsPeriod(cgroup, period);
        if (rc < 0) {
            virReportSystemError(-rc,
                                 "%s", _("Unable to set cpu bandwidth period"));
            return -1;
        }
    }

    if (quota) {
        rc = virCgroupSetCpuCfsQuota(cgroup, quota);
        if (rc < 0) {
            virReportSystemError(-rc,
                                 "%s", _("Unable to set cpu bandwidth quota"));
            goto cleanup;
        }
    }

    return 0;

cleanup:
    if (period) {
        rc = virCgroupSetCpuCfsPeriod(cgroup, old_period);
        if (rc < 0)
1829 1830
            virReportSystemError(-rc, "%s",
                                 _("Unable to rollback cpu bandwidth period"));
1831 1832 1833
    }

    return -1;
1834 1835
}

1836

1837
static int
1838 1839 1840 1841
lxcDomainSetSchedulerParametersFlags(virDomainPtr dom,
                                     virTypedParameterPtr params,
                                     int nparams,
                                     unsigned int flags)
1842
{
1843
    virLXCDriverPtr driver = dom->conn->privateData;
1844
    virCapsPtr caps = NULL;
1845
    size_t i;
1846
    virDomainObjPtr vm = NULL;
1847
    virDomainDefPtr vmdef = NULL;
1848
    int ret = -1;
1849
    int rc;
1850
    virLXCDomainObjPrivatePtr priv;
1851
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1852

1853 1854
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
1855 1856 1857 1858 1859 1860 1861 1862
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                               VIR_TYPED_PARAM_LLONG,
                               NULL) < 0)
1863
        return -1;
1864

1865
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
1866

1867
    if (vm == NULL) {
1868 1869
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No such domain %s"), dom->uuid);
1870
        goto cleanup;
1871
    }
1872
    priv = vm->privateData;
1873

1874 1875 1876
    if (virDomainSetSchedulerParametersFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

1877 1878 1879 1880
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
1881
                                        vm, &flags, &vmdef) < 0)
E
Eric Blake 已提交
1882
        goto cleanup;
1883 1884 1885

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
1886
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
1887 1888 1889 1890 1891
        if (!vmdef)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1892
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
1893 1894
            virReportError(VIR_ERR_OPERATION_INVALID,
                           "%s", _("cgroup CPU controller is not mounted"));
1895 1896 1897
            goto cleanup;
        }
    }
1898 1899

    for (i = 0; i < nparams; i++) {
1900
        virTypedParameterPtr param = &params[i];
1901

1902 1903
        if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_CPU_SHARES)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1904
                rc = virCgroupSetCpuShares(priv->cgroup, params[i].value.ul);
1905 1906 1907 1908 1909 1910 1911 1912 1913 1914 1915 1916 1917 1918
                if (rc != 0) {
                    virReportSystemError(-rc, "%s",
                                         _("unable to set cpu shares tunable"));
                    goto cleanup;
                }

                vm->def->cputune.shares = params[i].value.ul;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.shares = params[i].value.ul;
            }
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_PERIOD)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1919
                rc = lxcSetVcpuBWLive(priv->cgroup, params[i].value.ul, 0);
1920 1921 1922 1923 1924 1925 1926 1927 1928 1929 1930 1931
                if (rc != 0)
                    goto cleanup;

                if (params[i].value.ul)
                    vm->def->cputune.period = params[i].value.ul;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.period = params[i].value.ul;
            }
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_QUOTA)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1932
                rc = lxcSetVcpuBWLive(priv->cgroup, 0, params[i].value.l);
1933 1934 1935 1936 1937 1938 1939 1940 1941 1942
                if (rc != 0)
                    goto cleanup;

                if (params[i].value.l)
                    vm->def->cputune.quota = params[i].value.l;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.quota = params[i].value.l;
            }
1943
        }
1944
    }
1945

1946
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0)
1947
        goto cleanup;
1948

1949 1950

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
1951
        rc = virDomainSaveConfig(cfg->configDir, vmdef);
1952
        if (rc < 0)
1953
            goto cleanup;
1954

1955
        virDomainObjAssignDef(vm, vmdef, false, NULL);
1956
        vmdef = NULL;
1957
    }
1958

1959
    ret = 0;
1960

1961
cleanup:
1962
    virDomainDefFree(vmdef);
1963
    if (vm)
1964
        virObjectUnlock(vm);
1965
    virObjectUnref(caps);
1966
    virObjectUnref(cfg);
1967
    return ret;
1968 1969
}

1970
static int
1971 1972 1973
lxcDomainSetSchedulerParameters(virDomainPtr domain,
                                virTypedParameterPtr params,
                                int nparams)
1974
{
1975
    return lxcDomainSetSchedulerParametersFlags(domain, params, nparams, 0);
1976 1977 1978
}

static int
1979 1980 1981 1982
lxcDomainGetSchedulerParametersFlags(virDomainPtr dom,
                                     virTypedParameterPtr params,
                                     int *nparams,
                                     unsigned int flags)
1983
{
1984
    virLXCDriverPtr driver = dom->conn->privateData;
1985
    virCapsPtr caps = NULL;
1986
    virDomainObjPtr vm = NULL;
E
Eric Blake 已提交
1987
    virDomainDefPtr persistentDef;
1988 1989 1990
    unsigned long long shares = 0;
    unsigned long long period = 0;
    long long quota = 0;
1991
    int ret = -1;
1992 1993 1994
    int rc;
    bool cpu_bw_status = false;
    int saved_nparams = 0;
1995
    virLXCDomainObjPrivatePtr priv;
1996

1997 1998
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
1999

2000
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
2001

2002
    if (vm == NULL) {
2003 2004
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No such domain %s"), dom->uuid);
2005 2006
        goto cleanup;
    }
2007 2008
    priv = vm->privateData;

2009 2010 2011
    if (virDomainGetSchedulerParametersFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2012 2013 2014 2015 2016 2017
    if (*nparams > 1) {
        rc = lxcGetCpuBWStatus(priv->cgroup);
        if (rc < 0)
            goto cleanup;
        cpu_bw_status = !!rc;
    }
2018

2019 2020 2021 2022
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
2023
                                        vm, &flags, &persistentDef) < 0)
E
Eric Blake 已提交
2024
        goto cleanup;
2025 2026

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
E
Eric Blake 已提交
2027
        shares = persistentDef->cputune.shares;
2028
        if (*nparams > 1) {
E
Eric Blake 已提交
2029 2030
            period = persistentDef->cputune.period;
            quota = persistentDef->cputune.quota;
2031
            cpu_bw_status = true; /* Allow copy of data to params[] */
2032 2033 2034 2035
        }
        goto out;
    }

2036
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
2037 2038
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
2039
        goto cleanup;
2040 2041
    }

2042
    rc = virCgroupGetCpuShares(priv->cgroup, &shares);
2043 2044 2045
    if (rc != 0) {
        virReportSystemError(-rc, "%s",
                             _("unable to get cpu shares tunable"));
2046
        goto cleanup;
2047 2048 2049
    }

    if (*nparams > 1 && cpu_bw_status) {
2050
        rc = lxcGetVcpuBWLive(priv->cgroup, &period, &quota);
2051 2052 2053 2054
        if (rc != 0)
            goto cleanup;
    }
out:
2055 2056
    if (virTypedParameterAssign(&params[0], VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                                VIR_TYPED_PARAM_ULLONG, shares) < 0)
C
Chris Lalancette 已提交
2057
        goto cleanup;
2058 2059 2060 2061
    saved_nparams++;

    if (cpu_bw_status) {
        if (*nparams > saved_nparams) {
2062 2063 2064
            if (virTypedParameterAssign(&params[1],
                                        VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                                        VIR_TYPED_PARAM_ULLONG, period) < 0)
2065 2066 2067 2068 2069
                goto cleanup;
            saved_nparams++;
        }

        if (*nparams > saved_nparams) {
2070 2071 2072
            if (virTypedParameterAssign(&params[2],
                                        VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                                        VIR_TYPED_PARAM_LLONG, quota) < 0)
2073 2074 2075 2076 2077 2078 2079
                goto cleanup;
            saved_nparams++;
        }
    }

    *nparams = saved_nparams;

2080
    ret = 0;
2081

2082
cleanup:
2083
    if (vm)
2084
        virObjectUnlock(vm);
2085
    virObjectUnref(caps);
2086
    return ret;
2087 2088
}

2089
static int
2090 2091 2092
lxcDomainGetSchedulerParameters(virDomainPtr domain,
                                virTypedParameterPtr params,
                                int *nparams)
2093
{
2094
    return lxcDomainGetSchedulerParametersFlags(domain, params, nparams, 0);
2095 2096
}

2097

2098 2099 2100 2101 2102
static int
lxcDomainSetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int nparams,
                            unsigned int flags)
2103
{
2104
    virLXCDriverPtr driver = dom->conn->privateData;
2105
    virCapsPtr caps = NULL;
2106
    size_t i;
2107 2108 2109
    virDomainObjPtr vm = NULL;
    virDomainDefPtr persistentDef = NULL;
    int ret = -1;
2110
    virLXCDomainObjPrivatePtr priv;
2111
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
2112 2113 2114

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
2115 2116 2117 2118
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_BLKIO_WEIGHT,
                               VIR_TYPED_PARAM_UINT,
                               NULL) < 0)
2119 2120
        return -1;

2121
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
2122 2123

    if (vm == NULL) {
2124 2125
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No such domain %s"), dom->uuid);
2126 2127
        goto cleanup;
    }
2128
    priv = vm->privateData;
2129

2130 2131 2132
    if (virDomainSetBlkioParametersEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

2133 2134 2135 2136
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
2137
                                        vm, &flags, &persistentDef) < 0)
E
Eric Blake 已提交
2138
        goto cleanup;
2139 2140

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
2141
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
2142 2143
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2144 2145 2146 2147 2148 2149 2150 2151 2152 2153
            goto cleanup;
        }

        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
                int rc;

                if (params[i].value.ui > 1000 || params[i].value.ui < 100) {
2154 2155
                    virReportError(VIR_ERR_INVALID_ARG, "%s",
                                   _("out of blkio weight range."));
E
Eric Blake 已提交
2156
                    goto cleanup;
2157 2158
                }

2159
                rc = virCgroupSetBlkioWeight(priv->cgroup, params[i].value.ui);
2160 2161 2162
                if (rc != 0) {
                    virReportSystemError(-rc, "%s",
                                         _("unable to set blkio weight tunable"));
E
Eric Blake 已提交
2163
                    goto cleanup;
2164 2165 2166
                }
            }
        }
E
Eric Blake 已提交
2167 2168
    }
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
2169 2170 2171 2172 2173 2174 2175 2176
        /* Clang can't see that if we get here, persistentDef was set.  */
        sa_assert(persistentDef);

        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
                if (params[i].value.ui > 1000 || params[i].value.ui < 100) {
2177 2178
                    virReportError(VIR_ERR_INVALID_ARG, "%s",
                                   _("out of blkio weight range."));
E
Eric Blake 已提交
2179
                    goto cleanup;
2180 2181 2182 2183 2184 2185
                }

                persistentDef->blkio.weight = params[i].value.ui;
            }
        }

2186
        if (virDomainSaveConfig(cfg->configDir, persistentDef) < 0)
E
Eric Blake 已提交
2187
            goto cleanup;
2188 2189
    }

E
Eric Blake 已提交
2190
    ret = 0;
2191 2192
cleanup:
    if (vm)
2193
        virObjectUnlock(vm);
2194
    virObjectUnref(caps);
2195
    virObjectUnref(cfg);
2196 2197 2198 2199 2200
    return ret;
}


#define LXC_NB_BLKIO_PARAM  1
2201 2202 2203 2204 2205
static int
lxcDomainGetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int *nparams,
                            unsigned int flags)
2206
{
2207
    virLXCDriverPtr driver = dom->conn->privateData;
2208
    virCapsPtr caps = NULL;
2209
    size_t i;
2210 2211 2212 2213 2214
    virDomainObjPtr vm = NULL;
    virDomainDefPtr persistentDef = NULL;
    unsigned int val;
    int ret = -1;
    int rc;
2215
    virLXCDomainObjPrivatePtr priv;
2216 2217 2218 2219

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

2220
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
2221 2222

    if (vm == NULL) {
2223 2224
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("No such domain %s"), dom->uuid);
2225 2226
        goto cleanup;
    }
2227
    priv = vm->privateData;
2228

2229 2230 2231
    if (virDomainGetBlkioParametersEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2232 2233 2234 2235 2236 2237 2238
    if ((*nparams) == 0) {
        /* Current number of blkio parameters supported by cgroups */
        *nparams = LXC_NB_BLKIO_PARAM;
        ret = 0;
        goto cleanup;
    }

2239 2240 2241 2242
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
2243
                                        vm, &flags, &persistentDef) < 0)
E
Eric Blake 已提交
2244
        goto cleanup;
2245 2246

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
2247
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
2248 2249
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2250 2251 2252 2253 2254 2255 2256 2257 2258
            goto cleanup;
        }

        for (i = 0; i < *nparams && i < LXC_NB_BLKIO_PARAM; i++) {
            virTypedParameterPtr param = &params[i];
            val = 0;

            switch (i) {
            case 0: /* fill blkio weight here */
2259
                rc = virCgroupGetBlkioWeight(priv->cgroup, &val);
2260 2261 2262 2263 2264
                if (rc != 0) {
                    virReportSystemError(-rc, "%s",
                                         _("unable to get blkio weight"));
                    goto cleanup;
                }
2265 2266
                if (virTypedParameterAssign(param, VIR_DOMAIN_BLKIO_WEIGHT,
                                            VIR_TYPED_PARAM_UINT, val) < 0)
2267 2268 2269
                    goto cleanup;
                break;

2270
            /* coverity[dead_error_begin] */
2271 2272 2273 2274 2275 2276 2277 2278 2279 2280 2281
            default:
                break;
                /* should not hit here */
            }
        }
    } else if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        for (i = 0; i < *nparams && i < LXC_NB_BLKIO_PARAM; i++) {
            virTypedParameterPtr param = &params[i];

            switch (i) {
            case 0: /* fill blkio weight here */
2282 2283 2284
                if (virTypedParameterAssign(param, VIR_DOMAIN_BLKIO_WEIGHT,
                                            VIR_TYPED_PARAM_UINT,
                                            persistentDef->blkio.weight) < 0)
2285 2286 2287
                    goto cleanup;
                break;

2288
            /* coverity[dead_error_begin] */
2289 2290 2291 2292 2293 2294 2295 2296 2297 2298 2299 2300 2301
            default:
                break;
                /* should not hit here */
            }
        }
    }

    if (LXC_NB_BLKIO_PARAM < *nparams)
        *nparams = LXC_NB_BLKIO_PARAM;
    ret = 0;

cleanup:
    if (vm)
2302
        virObjectUnlock(vm);
2303
    virObjectUnref(caps);
2304 2305 2306 2307
    return ret;
}


2308 2309 2310 2311 2312 2313
#ifdef __linux__
static int
lxcDomainInterfaceStats(virDomainPtr dom,
                        const char *path,
                        struct _virDomainInterfaceStats *stats)
{
2314
    virLXCDriverPtr driver = dom->conn->privateData;
2315
    virDomainObjPtr vm;
2316
    size_t i;
2317 2318
    int ret = -1;

2319
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
2320 2321 2322 2323

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
2324 2325
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
2326 2327 2328
        goto cleanup;
    }

2329 2330 2331
    if (virDomainInterfaceStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2332
    if (!virDomainObjIsActive(vm)) {
2333 2334
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
2335 2336 2337 2338
        goto cleanup;
    }

    /* Check the path is one of the domain's network interfaces. */
2339
    for (i = 0; i < vm->def->nnets; i++) {
2340 2341 2342 2343 2344 2345 2346 2347
        if (vm->def->nets[i]->ifname &&
            STREQ(vm->def->nets[i]->ifname, path)) {
            ret = 0;
            break;
        }
    }

    if (ret == 0)
2348
        ret = linuxDomainInterfaceStats(path, stats);
2349
    else
2350 2351
        virReportError(VIR_ERR_INVALID_ARG,
                       _("Invalid path, '%s' is not a known interface"), path);
2352 2353 2354

cleanup:
    if (vm)
2355
        virObjectUnlock(vm);
2356 2357 2358 2359 2360 2361 2362
    return ret;
}
#else
static int
lxcDomainInterfaceStats(virDomainPtr dom,
                        const char *path ATTRIBUTE_UNUSED,
                        struct _virDomainInterfaceStats *stats ATTRIBUTE_UNUSED)
A
Alex Jia 已提交
2363
{
2364
    virReportError(VIR_ERR_NO_SUPPORT, "%s", __FUNCTION__);
2365 2366 2367 2368
    return -1;
}
#endif

2369 2370
static int lxcDomainGetAutostart(virDomainPtr dom,
                                   int *autostart) {
2371
    virLXCDriverPtr driver = dom->conn->privateData;
2372 2373 2374
    virDomainObjPtr vm;
    int ret = -1;

2375
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
2376 2377 2378 2379

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
2380 2381
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
2382 2383 2384
        goto cleanup;
    }

2385 2386 2387
    if (virDomainGetAutostartEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2388 2389 2390 2391 2392
    *autostart = vm->autostart;
    ret = 0;

cleanup:
    if (vm)
2393
        virObjectUnlock(vm);
2394 2395 2396 2397
    return ret;
}

static int lxcDomainSetAutostart(virDomainPtr dom,
2398 2399
                                   int autostart)
{
2400
    virLXCDriverPtr driver = dom->conn->privateData;
2401 2402 2403
    virDomainObjPtr vm;
    char *configFile = NULL, *autostartLink = NULL;
    int ret = -1;
2404
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
2405

2406
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
2407 2408 2409 2410

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
2411 2412
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
2413 2414 2415
        goto cleanup;
    }

2416 2417 2418
    if (virDomainSetAutostartEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2419
    if (!vm->persistent) {
2420 2421
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot set autostart for transient domain"));
2422 2423 2424 2425 2426
        goto cleanup;
    }

    autostart = (autostart != 0);

2427 2428 2429 2430
    if (vm->autostart == autostart) {
        ret = 0;
        goto cleanup;
    }
2431

2432
    configFile = virDomainConfigFile(cfg->configDir,
2433 2434 2435
                                     vm->def->name);
    if (configFile == NULL)
        goto cleanup;
2436
    autostartLink = virDomainConfigFile(cfg->autostartDir,
2437 2438 2439
                                        vm->def->name);
    if (autostartLink == NULL)
        goto cleanup;
2440

2441
    if (autostart) {
2442
        if (virFileMakePath(cfg->autostartDir) < 0) {
2443
            virReportSystemError(errno,
2444
                                 _("Cannot create autostart directory %s"),
2445
                                 cfg->autostartDir);
2446
            goto cleanup;
2447 2448
        }

2449
        if (symlink(configFile, autostartLink) < 0) {
2450
            virReportSystemError(errno,
2451 2452 2453 2454 2455 2456
                                 _("Failed to create symlink '%s to '%s'"),
                                 autostartLink, configFile);
            goto cleanup;
        }
    } else {
        if (unlink(autostartLink) < 0 && errno != ENOENT && errno != ENOTDIR) {
2457
            virReportSystemError(errno,
2458 2459 2460 2461
                                 _("Failed to delete symlink '%s'"),
                                 autostartLink);
            goto cleanup;
        }
2462
    }
2463 2464

    vm->autostart = autostart;
2465 2466 2467 2468 2469 2470
    ret = 0;

cleanup:
    VIR_FREE(configFile);
    VIR_FREE(autostartLink);
    if (vm)
2471
        virObjectUnlock(vm);
2472
    virObjectUnref(cfg);
2473 2474 2475
    return ret;
}

2476
static int lxcFreezeContainer(virDomainObjPtr vm)
R
Ryota Ozaki 已提交
2477 2478 2479 2480 2481 2482 2483
{
    int timeout = 1000; /* In milliseconds */
    int check_interval = 1; /* In milliseconds */
    int exp = 10;
    int waited_time = 0;
    int ret = -1;
    char *state = NULL;
2484
    virLXCDomainObjPrivatePtr priv = vm->privateData;
2485

R
Ryota Ozaki 已提交
2486 2487 2488 2489 2490 2491 2492 2493 2494
    while (waited_time < timeout) {
        int r;
        /*
         * Writing "FROZEN" to the "freezer.state" freezes the group,
         * i.e., the container, temporarily transiting "FREEZING" state.
         * Once the freezing is completed, the state of the group transits
         * to "FROZEN".
         * (see linux-2.6/Documentation/cgroups/freezer-subsystem.txt)
         */
2495
        r = virCgroupSetFreezerState(priv->cgroup, "FROZEN");
R
Ryota Ozaki 已提交
2496 2497 2498 2499 2500 2501 2502 2503 2504 2505 2506

        /*
         * Returning EBUSY explicitly indicates that the group is
         * being freezed but incomplete and other errors are true
         * errors.
         */
        if (r < 0 && r != -EBUSY) {
            VIR_DEBUG("Writing freezer.state failed with errno: %d", r);
            goto error;
        }
        if (r == -EBUSY)
2507
            VIR_DEBUG("Writing freezer.state gets EBUSY");
R
Ryota Ozaki 已提交
2508 2509 2510 2511 2512 2513 2514 2515 2516 2517 2518 2519 2520 2521

        /*
         * Unfortunately, returning 0 (success) is likely to happen
         * even when the freezing has not been completed. Sometimes
         * the state of the group remains "FREEZING" like when
         * returning -EBUSY and even worse may never transit to
         * "FROZEN" even if writing "FROZEN" again.
         *
         * So we don't trust the return value anyway and always
         * decide that the freezing has been complete only with
         * the state actually transit to "FROZEN".
         */
        usleep(check_interval * 1000);

2522
        r = virCgroupGetFreezerState(priv->cgroup, &state);
R
Ryota Ozaki 已提交
2523 2524 2525 2526 2527 2528 2529 2530 2531 2532 2533 2534 2535 2536 2537 2538 2539 2540 2541 2542 2543 2544 2545 2546

        if (r < 0) {
            VIR_DEBUG("Reading freezer.state failed with errno: %d", r);
            goto error;
        }
        VIR_DEBUG("Read freezer.state: %s", state);

        if (STREQ(state, "FROZEN")) {
            ret = 0;
            goto cleanup;
        }

        waited_time += check_interval;
        /*
         * Increasing check_interval exponentially starting with
         * small initial value treats nicely two cases; One is
         * a container is under no load and waiting for long period
         * makes no sense. The other is under heavy load. The container
         * may stay longer time in FREEZING or never transit to FROZEN.
         * In that case, eager polling will just waste CPU time.
         */
        check_interval *= exp;
        VIR_FREE(state);
    }
2547
    VIR_DEBUG("lxcFreezeContainer timeout");
R
Ryota Ozaki 已提交
2548 2549 2550 2551 2552 2553
error:
    /*
     * If timeout or an error on reading the state occurs,
     * activate the group again and return an error.
     * This is likely to fall the group back again gracefully.
     */
2554
    virCgroupSetFreezerState(priv->cgroup, "THAWED");
R
Ryota Ozaki 已提交
2555 2556 2557 2558 2559 2560 2561 2562 2563
    ret = -1;

cleanup:
    VIR_FREE(state);
    return ret;
}

static int lxcDomainSuspend(virDomainPtr dom)
{
2564
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
2565 2566 2567
    virDomainObjPtr vm;
    virDomainEventPtr event = NULL;
    int ret = -1;
2568
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
2569

2570
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
R
Ryota Ozaki 已提交
2571 2572 2573 2574

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
2575 2576
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
R
Ryota Ozaki 已提交
2577 2578 2579
        goto cleanup;
    }

2580 2581 2582
    if (virDomainSuspendEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

D
Daniel P. Berrange 已提交
2583
    if (!virDomainObjIsActive(vm)) {
2584 2585
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
R
Ryota Ozaki 已提交
2586 2587 2588
        goto cleanup;
    }

J
Jiri Denemark 已提交
2589
    if (virDomainObjGetState(vm, NULL) != VIR_DOMAIN_PAUSED) {
2590
        if (lxcFreezeContainer(vm) < 0) {
2591 2592
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Suspend operation failed"));
R
Ryota Ozaki 已提交
2593 2594
            goto cleanup;
        }
J
Jiri Denemark 已提交
2595
        virDomainObjSetState(vm, VIR_DOMAIN_PAUSED, VIR_DOMAIN_PAUSED_USER);
R
Ryota Ozaki 已提交
2596 2597 2598 2599 2600 2601

        event = virDomainEventNewFromObj(vm,
                                         VIR_DOMAIN_EVENT_SUSPENDED,
                                         VIR_DOMAIN_EVENT_SUSPENDED_PAUSED);
    }

2602
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0)
R
Ryota Ozaki 已提交
2603 2604 2605 2606 2607
        goto cleanup;
    ret = 0;

cleanup:
    if (event)
2608
        virDomainEventStateQueue(driver->domainEventState, event);
R
Ryota Ozaki 已提交
2609
    if (vm)
2610
        virObjectUnlock(vm);
2611
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
2612 2613 2614 2615 2616
    return ret;
}

static int lxcDomainResume(virDomainPtr dom)
{
2617
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
2618 2619 2620
    virDomainObjPtr vm;
    virDomainEventPtr event = NULL;
    int ret = -1;
2621
    virLXCDomainObjPrivatePtr priv;
2622
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
2623

2624
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
R
Ryota Ozaki 已提交
2625 2626 2627 2628

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
2629 2630
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
R
Ryota Ozaki 已提交
2631 2632 2633
        goto cleanup;
    }

2634 2635
    priv = vm->privateData;

2636 2637 2638
    if (virDomainResumeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

D
Daniel P. Berrange 已提交
2639
    if (!virDomainObjIsActive(vm)) {
2640 2641
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
R
Ryota Ozaki 已提交
2642 2643 2644
        goto cleanup;
    }

J
Jiri Denemark 已提交
2645
    if (virDomainObjGetState(vm, NULL) == VIR_DOMAIN_PAUSED) {
2646
        if (virCgroupSetFreezerState(priv->cgroup, "THAWED") < 0) {
2647 2648
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Resume operation failed"));
R
Ryota Ozaki 已提交
2649 2650
            goto cleanup;
        }
J
Jiri Denemark 已提交
2651 2652
        virDomainObjSetState(vm, VIR_DOMAIN_RUNNING,
                             VIR_DOMAIN_RUNNING_UNPAUSED);
R
Ryota Ozaki 已提交
2653 2654 2655 2656 2657 2658

        event = virDomainEventNewFromObj(vm,
                                         VIR_DOMAIN_EVENT_RESUMED,
                                         VIR_DOMAIN_EVENT_RESUMED_UNPAUSED);
    }

2659
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0)
R
Ryota Ozaki 已提交
2660 2661 2662 2663 2664
        goto cleanup;
    ret = 0;

cleanup:
    if (event)
2665
        virDomainEventStateQueue(driver->domainEventState, event);
R
Ryota Ozaki 已提交
2666
    if (vm)
2667
        virObjectUnlock(vm);
2668
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
2669 2670 2671
    return ret;
}

2672 2673
static int
lxcDomainOpenConsole(virDomainPtr dom,
2674
                      const char *dev_name,
2675 2676 2677
                      virStreamPtr st,
                      unsigned int flags)
{
2678
    virLXCDriverPtr driver = dom->conn->privateData;
2679 2680 2681 2682
    virDomainObjPtr vm = NULL;
    char uuidstr[VIR_UUID_STRING_BUFLEN];
    int ret = -1;
    virDomainChrDefPtr chr = NULL;
2683
    size_t i;
2684 2685 2686 2687

    virCheckFlags(0, -1);

    virUUIDFormat(dom->uuid, uuidstr);
2688
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
2689
    if (!vm) {
2690 2691
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
2692 2693 2694
        goto cleanup;
    }

2695 2696 2697
    if (virDomainOpenConsoleEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2698
    if (!virDomainObjIsActive(vm)) {
2699 2700
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
2701 2702 2703
        goto cleanup;
    }

2704
    if (dev_name) {
2705
        for (i = 0; i < vm->def->nconsoles; i++) {
2706 2707 2708 2709 2710 2711
            if (vm->def->consoles[i]->info.alias &&
                STREQ(vm->def->consoles[i]->info.alias, dev_name)) {
                chr = vm->def->consoles[i];
                break;
            }
        }
2712
    } else {
2713 2714
        if (vm->def->nconsoles)
            chr = vm->def->consoles[0];
2715 2716 2717 2718 2719
        else if (vm->def->nserials)
            chr = vm->def->serials[0];
    }

    if (!chr) {
2720 2721 2722
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot find console device '%s'"),
                       dev_name ? dev_name : _("default"));
2723 2724 2725
        goto cleanup;
    }

2726
    if (chr->source.type != VIR_DOMAIN_CHR_TYPE_PTY) {
2727 2728
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("character device %s is not using a PTY"), dev_name);
2729 2730 2731
        goto cleanup;
    }

2732
    if (virFDStreamOpenFile(st, chr->source.data.file.path,
E
Eric Blake 已提交
2733
                            0, 0, O_RDWR) < 0)
2734 2735 2736 2737 2738
        goto cleanup;

    ret = 0;
cleanup:
    if (vm)
2739
        virObjectUnlock(vm);
2740 2741 2742
    return ret;
}

2743 2744 2745 2746 2747 2748 2749 2750 2751 2752 2753 2754 2755 2756 2757 2758 2759 2760 2761 2762 2763 2764 2765 2766

static int
lxcDomainSendProcessSignal(virDomainPtr dom,
                           long long pid_value,
                           unsigned int signum,
                           unsigned int flags)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virDomainObjPtr vm = NULL;
    virLXCDomainObjPrivatePtr priv;
    char uuidstr[VIR_UUID_STRING_BUFLEN];
    pid_t victim;
    int ret = -1;

    virCheckFlags(0, -1);

    if (signum >= VIR_DOMAIN_PROCESS_SIGNAL_LAST) {
        virReportError(VIR_ERR_INVALID_ARG,
                       _("signum value %d is out of range"),
                       signum);
        return -1;
    }

    virUUIDFormat(dom->uuid, uuidstr);
2767
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
2768 2769 2770 2771 2772 2773 2774
    if (!vm) {
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }
    priv = vm->privateData;

2775 2776 2777
    if (virDomainSendProcessSignalEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2778 2779 2780 2781 2782 2783 2784 2785 2786 2787 2788 2789 2790 2791 2792 2793 2794 2795 2796 2797 2798 2799 2800 2801 2802 2803 2804 2805 2806 2807 2808 2809 2810 2811 2812 2813 2814 2815 2816 2817
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
        goto cleanup;
    }

    /*
     * XXX if the kernel has /proc/$PID/ns/pid we can
     * switch into container namespace & that way be
     * able to kill any PID. Alternatively if there
     * is a way to find a mapping of guest<->host PIDs
     * we can kill that way.
     */
    if (pid_value != 1) {
        virReportError(VIR_ERR_ARGUMENT_UNSUPPORTED, "%s",
                       _("Only the init process may be killed"));
        goto cleanup;
    }

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
        goto cleanup;
    }
    victim = priv->initpid;

    /* We're relying on fact libvirt header signal numbers
     * are taken from Linux, to avoid mapping
     */
    if (kill(victim, signum) < 0) {
        virReportSystemError(errno,
                             _("Unable to send %d signal to process %d"),
                             signum, victim);
        goto cleanup;
    }

    ret = 0;

cleanup:
    if (vm)
2818
        virObjectUnlock(vm);
2819 2820 2821 2822
    return ret;
}


2823
static int
2824 2825
lxcConnectListAllDomains(virConnectPtr conn,
                         virDomainPtr **domains,
2826 2827
                  unsigned int flags)
{
2828
    virLXCDriverPtr driver = conn->privateData;
2829 2830
    int ret = -1;

O
Osier Yang 已提交
2831
    virCheckFlags(VIR_CONNECT_LIST_DOMAINS_FILTERS_ALL, -1);
2832

2833 2834 2835
    if (virConnectListAllDomainsEnsureACL(conn) < 0)
        return -1;

2836 2837
    ret = virDomainObjListExport(driver->domains, conn, domains,
                                 virConnectListAllDomainsCheckACL, flags);
2838 2839 2840
    return ret;
}

2841

2842 2843 2844 2845 2846 2847 2848 2849 2850
static int
lxcDomainShutdownFlags(virDomainPtr dom,
                       unsigned int flags)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    char *vroot = NULL;
    int ret = -1;
2851
    int rc;
2852 2853 2854 2855

    virCheckFlags(VIR_DOMAIN_SHUTDOWN_INITCTL |
                  VIR_DOMAIN_SHUTDOWN_SIGNAL, -1);

2856
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
2857 2858 2859 2860 2861 2862 2863 2864 2865 2866 2867

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }

    priv = vm->privateData;

2868 2869 2870
    if (virDomainShutdownFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2871 2872 2873 2874 2875 2876 2877 2878 2879 2880 2881 2882 2883
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
2884
                    (unsigned long long)priv->initpid) < 0)
2885 2886
        goto cleanup;

2887 2888 2889 2890
    if (flags == 0 ||
        (flags & VIR_DOMAIN_SHUTDOWN_INITCTL)) {
        if ((rc = virInitctlSetRunLevel(VIR_INITCTL_RUNLEVEL_POWEROFF,
                                        vroot)) < 0) {
2891
            goto cleanup;
2892 2893 2894
        }
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
2895 2896 2897 2898
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
            goto cleanup;
        }
2899 2900
    } else {
        rc = 0;
2901
    }
2902 2903 2904 2905 2906 2907

    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_SHUTDOWN_SIGNAL))) {
        if (kill(priv->initpid, SIGTERM) < 0 &&
            errno != ESRCH) {
2908 2909 2910 2911 2912 2913 2914 2915 2916 2917 2918 2919
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
                                 (unsigned long long)priv->initpid);
            goto cleanup;
        }
    }

    ret = 0;

cleanup:
    VIR_FREE(vroot);
    if (vm)
2920
        virObjectUnlock(vm);
2921 2922 2923 2924 2925 2926 2927 2928 2929 2930 2931 2932 2933 2934 2935 2936 2937 2938 2939 2940 2941 2942 2943
    return ret;
}

static int
lxcDomainShutdown(virDomainPtr dom)
{
    return lxcDomainShutdownFlags(dom, 0);
}

static int
lxcDomainReboot(virDomainPtr dom,
                unsigned int flags)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    char *vroot = NULL;
    int ret = -1;
    int rc;

    virCheckFlags(VIR_DOMAIN_REBOOT_INITCTL |
                  VIR_DOMAIN_REBOOT_SIGNAL, -1);

2944
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
2945 2946 2947 2948 2949 2950 2951 2952 2953 2954 2955

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }

    priv = vm->privateData;

2956 2957 2958
    if (virDomainRebootEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2959 2960 2961 2962 2963 2964 2965 2966 2967 2968 2969 2970 2971
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
2972
                    (unsigned long long)priv->initpid) < 0)
2973 2974 2975 2976 2977 2978 2979 2980 2981 2982 2983 2984 2985 2986 2987 2988 2989 2990 2991 2992 2993 2994 2995 2996 2997 2998 2999 3000 3001 3002 3003 3004 3005 3006 3007
        goto cleanup;

    if (flags == 0 ||
        (flags & VIR_DOMAIN_REBOOT_INITCTL)) {
        if ((rc = virInitctlSetRunLevel(VIR_INITCTL_RUNLEVEL_REBOOT,
                                        vroot)) < 0) {
            goto cleanup;
        }
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
            goto cleanup;
        }
    } else {
        rc = 0;
    }

    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_REBOOT_SIGNAL))) {
        if (kill(priv->initpid, SIGHUP) < 0 &&
            errno != ESRCH) {
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
                                 (unsigned long long)priv->initpid);
            goto cleanup;
        }
    }

    ret = 0;

cleanup:
    VIR_FREE(vroot);
    if (vm)
3008
        virObjectUnlock(vm);
3009 3010 3011 3012
    return ret;
}


3013
static int
3014
lxcDomainAttachDeviceConfig(virDomainDefPtr vmdef,
3015 3016 3017
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3018
    virDomainDiskDefPtr disk;
3019
    virDomainNetDefPtr net;
3020
    virDomainHostdevDefPtr hostdev;
3021 3022

    switch (dev->type) {
3023 3024 3025 3026 3027 3028 3029
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (virDomainDiskIndexByName(vmdef, disk->dst, true) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("target %s already exists."), disk->dst);
            return -1;
        }
3030
        if (virDomainDiskInsert(vmdef, disk))
3031 3032 3033 3034 3035 3036
            return -1;
        /* vmdef has the pointer. Generic codes for vmdef will do all jobs */
        dev->data.disk = NULL;
        ret = 0;
        break;

3037 3038
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
3039
        if (virDomainNetInsert(vmdef, net) < 0)
3040 3041 3042 3043 3044
            goto cleanup;
        dev->data.net = NULL;
        ret = 0;
        break;

3045 3046 3047 3048 3049 3050 3051
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        hostdev = dev->data.hostdev;
        if (virDomainHostdevFind(vmdef, hostdev, NULL) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device is already in the domain configuration"));
            return -1;
        }
3052
        if (virDomainHostdevInsert(vmdef, hostdev) < 0)
3053 3054 3055 3056 3057
            return -1;
        dev->data.hostdev = NULL;
        ret = 0;
        break;

3058 3059 3060 3061 3062 3063
    default:
         virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                        _("persistent attach of device is not supported"));
         break;
    }

3064
cleanup:
3065 3066 3067 3068 3069
    return ret;
}


static int
3070
lxcDomainUpdateDeviceConfig(virDomainDefPtr vmdef,
3071 3072 3073
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3074 3075 3076
    virDomainNetDefPtr net;
    int idx;
    char mac[VIR_MAC_STRING_BUFLEN];
3077 3078

    switch (dev->type) {
3079 3080 3081 3082 3083 3084 3085 3086 3087 3088 3089 3090 3091 3092 3093 3094 3095 3096 3097 3098 3099 3100
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
        idx = virDomainNetFindIdx(vmdef, net);
        if (idx == -2) {
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("multiple devices matching mac address %s found"),
                           virMacAddrFormat(&net->mac, mac));
            goto cleanup;
        } else if (idx < 0) {
            virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                           _("no matching network device was found"));
            goto cleanup;
        }

        virDomainNetDefFree(vmdef->nets[idx]);

        vmdef->nets[idx] = net;
        dev->data.net = NULL;
        ret = 0;

        break;

3101 3102 3103 3104 3105 3106
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent update of device is not supported"));
        break;
    }

3107
cleanup:
3108 3109 3110 3111 3112
    return ret;
}


static int
3113
lxcDomainDetachDeviceConfig(virDomainDefPtr vmdef,
3114 3115 3116
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3117
    virDomainDiskDefPtr disk, det_disk;
3118
    virDomainNetDefPtr net;
3119
    virDomainHostdevDefPtr hostdev, det_hostdev;
3120 3121
    int idx;
    char mac[VIR_MAC_STRING_BUFLEN];
3122 3123

    switch (dev->type) {
3124 3125 3126 3127 3128 3129 3130 3131 3132 3133 3134
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (!(det_disk = virDomainDiskRemoveByName(vmdef, disk->dst))) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("no target device %s"), disk->dst);
            return -1;
        }
        virDomainDiskDefFree(det_disk);
        ret = 0;
        break;

3135 3136 3137 3138 3139 3140 3141 3142 3143 3144 3145 3146 3147 3148 3149 3150 3151 3152
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
        idx = virDomainNetFindIdx(vmdef, net);
        if (idx == -2) {
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("multiple devices matching mac address %s found"),
                           virMacAddrFormat(&net->mac, mac));
            goto cleanup;
        } else if (idx < 0) {
            virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                           _("no matching network device was found"));
            goto cleanup;
        }
        /* this is guaranteed to succeed */
        virDomainNetDefFree(virDomainNetRemove(vmdef, idx));
        ret = 0;
        break;

3153 3154 3155 3156 3157 3158 3159 3160 3161 3162 3163 3164 3165
    case VIR_DOMAIN_DEVICE_HOSTDEV: {
        hostdev = dev->data.hostdev;
        if ((idx = virDomainHostdevFind(vmdef, hostdev, &det_hostdev)) < 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device not present in domain configuration"));
            return -1;
        }
        virDomainHostdevRemove(vmdef, idx);
        virDomainHostdevDefFree(det_hostdev);
        ret = 0;
        break;
    }

3166 3167 3168 3169 3170 3171
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent detach of device is not supported"));
        break;
    }

3172
cleanup:
3173 3174 3175 3176
    return ret;
}


3177 3178 3179 3180 3181 3182 3183 3184
static int
lxcDomainAttachDeviceDiskLive(virLXCDriverPtr driver,
                              virDomainObjPtr vm,
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = dev->data.disk;
    int ret = -1;
3185
    char *dst = NULL;
3186 3187 3188 3189 3190 3191 3192 3193 3194 3195 3196 3197 3198 3199 3200 3201 3202 3203 3204 3205 3206 3207 3208 3209 3210 3211 3212 3213 3214 3215 3216 3217 3218 3219 3220 3221 3222 3223 3224 3225 3226 3227
    struct stat sb;
    bool created = false;
    mode_t mode = 0;
    char *tmpsrc = def->src;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

    if (def->type != VIR_DOMAIN_DISK_TYPE_BLOCK) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk for non-block device"));
        goto cleanup;
    }
    if (def->src == NULL) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk without media"));
        goto cleanup;
    }

    if (virDomainDiskIndexByName(vm->def, def->dst, true) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("target %s already exists"), def->dst);
        goto cleanup;
    }

    if (stat(def->src, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"), def->src);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode) && !S_ISBLK(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Disk source %s must be a character/block device"),
                       def->src);
        goto cleanup;
    }

    if (virAsprintf(&dst, "/proc/%llu/root/dev/%s",
3228
                    (unsigned long long)priv->initpid, def->dst) < 0)
3229 3230
        goto cleanup;

3231
    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0)
3232 3233 3234 3235 3236 3237 3238 3239 3240 3241 3242 3243 3244 3245 3246 3247 3248 3249 3250 3251 3252 3253 3254
        goto cleanup;

    mode = 0700;
    if (S_ISCHR(sb.st_mode))
        mode |= S_IFCHR;
    else
        mode |= S_IFBLK;

    /* Yes, the device name we're creating may not
     * actually correspond to the major:minor number
     * we're using, but we've no other option at this
     * time. Just have to hope that containerized apps
     * don't get upset that the major:minor is different
     * to that normally implied by the device name
     */
    VIR_DEBUG("Creating dev %s (%d,%d) from %s",
              dst, major(sb.st_rdev), minor(sb.st_rdev), def->src);
    if (mknod(dst, mode, sb.st_rdev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             dst);
        goto cleanup;
    }
3255 3256 3257 3258

    if (lxcContainerChown(vm->def, dst) < 0)
        goto cleanup;

3259 3260 3261 3262 3263 3264 3265 3266 3267
    created = true;

    /* Labelling normally operates on src, but we need
     * to actally label the dst here, so hack the config */
    def->src = dst;
    if (virSecurityManagerSetImageLabel(driver->securityManager,
                                        vm->def, def) < 0)
        goto cleanup;

3268
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3269 3270 3271 3272 3273
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3274
    if (virCgroupAllowDevicePath(priv->cgroup, def->src,
3275 3276 3277 3278 3279 3280 3281 3282 3283 3284 3285 3286 3287 3288 3289 3290 3291 3292 3293 3294 3295 3296 3297
                                 (def->readonly ?
                                  VIR_CGROUP_DEVICE_READ :
                                  VIR_CGROUP_DEVICE_RW) |
                                 VIR_CGROUP_DEVICE_MKNOD) != 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot allow device %s for domain %s"),
                       def->src, vm->def->name);
        goto cleanup;
    }

    virDomainDiskInsertPreAlloced(vm->def, def);

    ret = 0;

cleanup:
    def->src = tmpsrc;
    virDomainAuditDisk(vm, NULL, def->src, "attach", ret == 0);
    if (dst && created && ret < 0)
        unlink(dst);
    return ret;
}


3298
/* XXX conn required for network -> bridge resolution */
3299
static int
3300 3301 3302 3303 3304 3305 3306 3307 3308 3309 3310 3311 3312 3313 3314 3315
lxcDomainAttachDeviceNetLive(virConnectPtr conn,
                             virDomainObjPtr vm,
                             virDomainNetDefPtr net)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    int ret = -1;
    int actualType;
    char *veth = NULL;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

    /* preallocate new slot for device */
3316
    if (VIR_REALLOC_N(vm->def->nets, vm->def->nnets+1) < 0)
3317 3318 3319 3320 3321 3322 3323 3324 3325 3326 3327 3328 3329 3330 3331 3332 3333 3334 3335 3336 3337 3338 3339 3340 3341 3342 3343 3344 3345 3346 3347 3348 3349 3350 3351 3352 3353 3354 3355 3356 3357 3358 3359 3360 3361 3362 3363 3364 3365 3366 3367 3368 3369 3370 3371 3372 3373 3374 3375 3376 3377 3378 3379 3380 3381 3382 3383 3384 3385 3386 3387 3388 3389 3390 3391 3392 3393 3394 3395 3396 3397 3398 3399 3400 3401 3402 3403 3404 3405 3406 3407 3408 3409 3410 3411 3412 3413 3414 3415 3416 3417 3418 3419 3420 3421 3422 3423 3424 3425 3426
        return -1;

    /* If appropriate, grab a physical device from the configured
     * network's pool of devices, or resolve bridge device name
     * to the one defined in the network definition.
     */
    if (networkAllocateActualDevice(net) < 0)
        return -1;

    actualType = virDomainNetGetActualType(net);

    switch (actualType) {
    case VIR_DOMAIN_NET_TYPE_BRIDGE: {
        const char *brname = virDomainNetGetActualBridgeName(net);
        if (!brname) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("No bridge name specified"));
            goto cleanup;
        }
        if (!(veth = virLXCProcessSetupInterfaceBridged(conn,
                                                        vm->def,
                                                        net,
                                                        brname)))
            goto cleanup;
    }   break;
    case VIR_DOMAIN_NET_TYPE_NETWORK: {
        virNetworkPtr network;
        char *brname = NULL;
        bool fail = false;
        int active;
        virErrorPtr errobj;

        if (!(network = virNetworkLookupByName(conn,
                                               net->data.network.name)))
            goto cleanup;

        active = virNetworkIsActive(network);
        if (active != 1) {
            fail = true;
            if (active == 0)
                virReportError(VIR_ERR_INTERNAL_ERROR,
                               _("Network '%s' is not active."),
                               net->data.network.name);
        }

        if (!fail) {
            brname = virNetworkGetBridgeName(network);
            if (brname == NULL)
                fail = true;
        }

        /* Make sure any above failure is preserved */
        errobj = virSaveLastError();
        virNetworkFree(network);
        virSetError(errobj);
        virFreeError(errobj);

        if (fail)
            goto cleanup;

        if (!(veth = virLXCProcessSetupInterfaceBridged(conn,
                                                        vm->def,
                                                        net,
                                                        brname))) {
            VIR_FREE(brname);
            goto cleanup;
        }
        VIR_FREE(brname);
    }   break;
    case VIR_DOMAIN_NET_TYPE_DIRECT: {
        if (!(veth = virLXCProcessSetupInterfaceDirect(conn,
                                                       vm->def,
                                                       net)))
            goto cleanup;
    }   break;
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Network device type is not supported"));
        goto cleanup;
    }

    if (virNetDevSetNamespace(veth, priv->initpid) < 0) {
        virDomainAuditNet(vm, NULL, net, "attach", false);
        goto cleanup;
    }

    virDomainAuditNet(vm, NULL, net, "attach", true);

    ret = 0;

cleanup:
    if (!ret) {
        vm->def->nets[vm->def->nnets++] = net;
    } else if (veth) {
        switch (actualType) {
        case VIR_DOMAIN_NET_TYPE_BRIDGE:
        case VIR_DOMAIN_NET_TYPE_NETWORK:
            ignore_value(virNetDevVethDelete(veth));
            break;

        case VIR_DOMAIN_NET_TYPE_DIRECT:
            ignore_value(virNetDevMacVLanDelete(veth));
            break;
        }
    }

    return ret;
}


3427 3428 3429 3430 3431 3432 3433 3434 3435 3436 3437 3438 3439 3440 3441
static int
lxcDomainAttachDeviceHostdevSubsysUSBLive(virLXCDriverPtr driver,
                                          virDomainObjPtr vm,
                                          virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    char *vroot = NULL;
    char *src = NULL;
    char *dstdir = NULL;
    char *dstfile = NULL;
    struct stat sb;
    mode_t mode;
    bool created = false;
3442
    virUSBDevicePtr usb = NULL;
3443 3444 3445 3446 3447 3448 3449 3450

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host USB device already exists"));
        return -1;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
3451
                    (unsigned long long)priv->initpid) < 0)
3452 3453 3454 3455
        goto cleanup;

    if (virAsprintf(&dstdir, "%s/dev/bus/%03d",
                    vroot,
3456
                    def->source.subsys.u.usb.bus) < 0)
3457 3458 3459 3460
        goto cleanup;

    if (virAsprintf(&dstfile, "%s/%03d",
                    dstdir,
3461
                    def->source.subsys.u.usb.device) < 0)
3462 3463 3464 3465
        goto cleanup;

    if (virAsprintf(&src, "/dev/bus/usb/%03d/%03d",
                    def->source.subsys.u.usb.bus,
3466
                    def->source.subsys.u.usb.device) < 0)
3467 3468
        goto cleanup;

3469
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3470 3471 3472 3473 3474
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3475 3476
    if (!(usb = virUSBDeviceNew(def->source.subsys.u.usb.bus,
                                def->source.subsys.u.usb.device, vroot)))
3477 3478 3479 3480 3481 3482 3483 3484 3485 3486 3487 3488 3489 3490 3491 3492 3493 3494 3495 3496 3497 3498 3499 3500 3501 3502 3503 3504 3505 3506 3507 3508 3509
        goto cleanup;

    if (stat(src, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"), src);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("USB source %s was not a character device"),
                       src);
        goto cleanup;
    }

    mode = 0700 | S_IFCHR;

    if (virFileMakePath(dstdir) < 0) {
        virReportSystemError(errno,
                             _("Unable to create %s"), dstdir);
        goto cleanup;
    }

    VIR_DEBUG("Creating dev %s (%d,%d)",
              dstfile, major(sb.st_rdev), minor(sb.st_rdev));
    if (mknod(dstfile, mode, sb.st_rdev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             dstfile);
        goto cleanup;
    }
    created = true;

3510 3511 3512
    if (lxcContainerChown(vm->def, dstfile) < 0)
        goto cleanup;

3513 3514 3515 3516
    if (virSecurityManagerSetHostdevLabel(driver->securityManager,
                                          vm->def, def, vroot) < 0)
        goto cleanup;

3517
    if (virUSBDeviceFileIterate(usb,
3518 3519
                                virLXCSetupHostUsbDeviceCgroup,
                                &priv->cgroup) < 0)
3520 3521 3522 3523 3524 3525 3526 3527 3528
        goto cleanup;

    ret = 0;

cleanup:
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    if (ret < 0 && created)
        unlink(dstfile);

3529
    virUSBDeviceFree(usb);
3530 3531 3532 3533 3534 3535 3536 3537
    VIR_FREE(src);
    VIR_FREE(dstfile);
    VIR_FREE(dstdir);
    VIR_FREE(vroot);
    return ret;
}


3538 3539 3540 3541 3542 3543 3544 3545 3546 3547 3548 3549 3550 3551 3552 3553 3554 3555 3556 3557 3558 3559 3560 3561 3562 3563 3564 3565 3566 3567 3568 3569 3570 3571 3572 3573 3574 3575 3576 3577 3578
static int
lxcDomainAttachDeviceHostdevStorageLive(virLXCDriverPtr driver,
                                        virDomainObjPtr vm,
                                        virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    char *dst = NULL;
    char *vroot = NULL;
    struct stat sb;
    bool created = false;
    mode_t mode = 0;

    if (!def->source.caps.u.storage.block) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Missing storage block path"));
        goto cleanup;
    }

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host device already exists"));
        return -1;
    }

    if (stat(def->source.caps.u.storage.block, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"),
                             def->source.caps.u.storage.block);
        goto cleanup;
    }

    if (!S_ISBLK(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Hostdev source %s must be a block device"),
                       def->source.caps.u.storage.block);
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
3579
                    (unsigned long long)priv->initpid) < 0)
3580 3581 3582 3583
        goto cleanup;

    if (virAsprintf(&dst, "%s/%s",
                    vroot,
3584
                    def->source.caps.u.storage.block) < 0)
3585 3586
        goto cleanup;

3587
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0)
3588 3589
        goto cleanup;

3590 3591 3592 3593 3594 3595 3596
    if (lxcContainerSetupHostdevCapsMakePath(dst) < 0) {
        virReportSystemError(errno,
                             _("Unable to create directroy for device %s"),
                             dst);
        goto cleanup;
    }

3597 3598 3599 3600 3601 3602 3603 3604 3605 3606 3607 3608 3609
    mode = 0700 | S_IFBLK;

    VIR_DEBUG("Creating dev %s (%d,%d)",
              def->source.caps.u.storage.block,
              major(sb.st_rdev), minor(sb.st_rdev));
    if (mknod(dst, mode, sb.st_rdev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             dst);
        goto cleanup;
    }
    created = true;

3610 3611 3612
    if (lxcContainerChown(vm->def, dst) < 0)
        goto cleanup;

3613 3614 3615 3616
    if (virSecurityManagerSetHostdevLabel(driver->securityManager,
                                          vm->def, def, vroot) < 0)
        goto cleanup;

3617
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3618 3619 3620 3621 3622
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3623
    if (virCgroupAllowDevicePath(priv->cgroup, def->source.caps.u.storage.block,
3624 3625 3626 3627 3628 3629 3630 3631 3632 3633 3634 3635 3636 3637 3638 3639 3640 3641 3642 3643 3644 3645
                                 VIR_CGROUP_DEVICE_RW |
                                 VIR_CGROUP_DEVICE_MKNOD) != 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot allow device %s for domain %s"),
                       def->source.caps.u.storage.block, vm->def->name);
        goto cleanup;
    }

    vm->def->hostdevs[vm->def->nhostdevs++] = def;

    ret = 0;

cleanup:
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    if (dst && created && ret < 0)
        unlink(dst);
    VIR_FREE(dst);
    VIR_FREE(vroot);
    return ret;
}


3646 3647 3648 3649 3650 3651 3652 3653 3654 3655 3656 3657 3658 3659 3660 3661 3662 3663 3664 3665 3666 3667 3668 3669 3670 3671 3672 3673 3674 3675 3676 3677 3678 3679 3680 3681 3682 3683 3684 3685 3686
static int
lxcDomainAttachDeviceHostdevMiscLive(virLXCDriverPtr driver,
                                     virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    char *dst = NULL;
    char *vroot = NULL;
    struct stat sb;
    bool created = false;
    mode_t mode = 0;

    if (!def->source.caps.u.misc.chardev) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Missing storage block path"));
        goto cleanup;
    }

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host device already exists"));
        return -1;
    }

    if (stat(def->source.caps.u.misc.chardev, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"),
                             def->source.caps.u.misc.chardev);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Hostdev source %s must be a block device"),
                       def->source.caps.u.misc.chardev);
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
3687
                    (unsigned long long)priv->initpid) < 0)
3688 3689 3690 3691
        goto cleanup;

    if (virAsprintf(&dst, "%s/%s",
                    vroot,
3692
                    def->source.caps.u.misc.chardev) < 0)
3693 3694
        goto cleanup;

3695
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0)
3696 3697
        goto cleanup;

3698 3699 3700 3701 3702 3703 3704
    if (lxcContainerSetupHostdevCapsMakePath(dst) < 0) {
        virReportSystemError(errno,
                             _("Unable to create directroy for device %s"),
                             dst);
        goto cleanup;
    }

3705 3706 3707 3708 3709 3710 3711 3712 3713 3714 3715 3716 3717
    mode = 0700 | S_IFCHR;

    VIR_DEBUG("Creating dev %s (%d,%d)",
              def->source.caps.u.misc.chardev,
              major(sb.st_rdev), minor(sb.st_rdev));
    if (mknod(dst, mode, sb.st_rdev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             dst);
        goto cleanup;
    }
    created = true;

3718 3719 3720
    if (lxcContainerChown(vm->def, dst) < 0)
        goto cleanup;

3721 3722 3723 3724
    if (virSecurityManagerSetHostdevLabel(driver->securityManager,
                                          vm->def, def, vroot) < 0)
        goto cleanup;

3725
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3726 3727 3728 3729 3730
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3731
    if (virCgroupAllowDevicePath(priv->cgroup, def->source.caps.u.misc.chardev,
3732 3733 3734 3735 3736 3737 3738 3739 3740 3741 3742 3743 3744 3745 3746 3747 3748 3749 3750 3751 3752 3753
                                 VIR_CGROUP_DEVICE_RW |
                                 VIR_CGROUP_DEVICE_MKNOD) != 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot allow device %s for domain %s"),
                       def->source.caps.u.misc.chardev, vm->def->name);
        goto cleanup;
    }

    vm->def->hostdevs[vm->def->nhostdevs++] = def;

    ret = 0;

cleanup:
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    if (dst && created && ret < 0)
        unlink(dst);
    VIR_FREE(dst);
    VIR_FREE(vroot);
    return ret;
}


3754 3755 3756 3757 3758 3759 3760 3761 3762 3763 3764 3765 3766 3767 3768 3769 3770 3771
static int
lxcDomainAttachDeviceHostdevSubsysLive(virLXCDriverPtr driver,
                                       virDomainObjPtr vm,
                                       virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        return lxcDomainAttachDeviceHostdevSubsysUSBLive(driver, vm, dev);

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevSubsysTypeToString(dev->data.hostdev->source.subsys.type));
        return -1;
    }
}


3772 3773 3774 3775 3776 3777 3778 3779 3780
static int
lxcDomainAttachDeviceHostdevCapsLive(virLXCDriverPtr driver,
                                     virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.caps.type) {
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_STORAGE:
        return lxcDomainAttachDeviceHostdevStorageLive(driver, vm, dev);

3781 3782 3783
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_MISC:
        return lxcDomainAttachDeviceHostdevMiscLive(driver, vm, dev);

3784 3785 3786 3787 3788 3789 3790 3791 3792
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevCapsTypeToString(dev->data.hostdev->source.caps.type));
        return -1;
    }
}


3793 3794 3795 3796 3797 3798 3799 3800 3801 3802 3803 3804 3805 3806 3807 3808 3809
static int
lxcDomainAttachDeviceHostdevLive(virLXCDriverPtr driver,
                                 virDomainObjPtr vm,
                                 virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach hostdev until init PID is known"));
        return -1;
    }

    switch (dev->data.hostdev->mode) {
    case VIR_DOMAIN_HOSTDEV_MODE_SUBSYS:
        return lxcDomainAttachDeviceHostdevSubsysLive(driver, vm, dev);

3810 3811 3812
    case VIR_DOMAIN_HOSTDEV_MODE_CAPABILITIES:
        return lxcDomainAttachDeviceHostdevCapsLive(driver, vm, dev);

3813 3814 3815 3816 3817 3818 3819 3820 3821
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device mode %s"),
                       virDomainHostdevModeTypeToString(dev->data.hostdev->mode));
        return -1;
    }
}


3822 3823 3824 3825
static int
lxcDomainAttachDeviceLive(virConnectPtr conn,
                          virLXCDriverPtr driver,
                          virDomainObjPtr vm,
3826 3827 3828 3829 3830
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
3831 3832 3833 3834 3835 3836
    case VIR_DOMAIN_DEVICE_DISK:
        ret = lxcDomainAttachDeviceDiskLive(driver, vm, dev);
        if (!ret)
            dev->data.disk = NULL;
        break;

3837 3838 3839 3840 3841 3842 3843
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainAttachDeviceNetLive(conn, vm,
                                           dev->data.net);
        if (!ret)
            dev->data.net = NULL;
        break;

3844 3845 3846 3847 3848 3849
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        ret = lxcDomainAttachDeviceHostdevLive(driver, vm, dev);
        if (!ret)
            dev->data.disk = NULL;
        break;

3850 3851 3852 3853 3854 3855 3856 3857 3858 3859 3860
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be attached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


3861
static int
3862
lxcDomainDetachDeviceDiskLive(virDomainObjPtr vm,
3863 3864 3865 3866
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = NULL;
3867
    int idx, ret = -1;
J
John Ferlan 已提交
3868
    char *dst = NULL;
3869 3870 3871 3872 3873 3874 3875

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

3876 3877 3878
    if ((idx = virDomainDiskIndexByName(vm->def,
                                        dev->data.disk->dst,
                                        false)) < 0) {
3879 3880 3881 3882 3883
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
        goto cleanup;
    }

3884
    def = vm->def->disks[idx];
3885 3886

    if (virAsprintf(&dst, "/proc/%llu/root/dev/%s",
3887
                    (unsigned long long)priv->initpid, def->dst) < 0)
3888 3889
        goto cleanup;

3890
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3891 3892 3893 3894 3895 3896 3897 3898 3899 3900 3901 3902 3903 3904
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

    VIR_DEBUG("Unlinking %s (backed by %s)", dst, def->src);
    if (unlink(dst) < 0 && errno != ENOENT) {
        virDomainAuditDisk(vm, def->src, NULL, "detach", false);
        virReportSystemError(errno,
                             _("Unable to remove device %s"), dst);
        goto cleanup;
    }
    virDomainAuditDisk(vm, def->src, NULL, "detach", true);

3905
    if (virCgroupDenyDevicePath(priv->cgroup, def->src, VIR_CGROUP_DEVICE_RWM) != 0)
3906 3907 3908
        VIR_WARN("cannot deny device %s for domain %s",
                 def->src, vm->def->name);

3909
    virDomainDiskRemove(vm->def, idx);
3910 3911 3912 3913 3914 3915 3916 3917 3918 3919
    virDomainDiskDefFree(def);

    ret = 0;

cleanup:
    VIR_FREE(dst);
    return ret;
}


3920
static int
3921 3922 3923 3924 3925 3926 3927 3928 3929 3930 3931 3932 3933 3934 3935 3936 3937 3938 3939 3940 3941 3942 3943 3944 3945 3946 3947 3948 3949 3950 3951 3952 3953 3954 3955 3956 3957 3958 3959 3960 3961 3962 3963 3964 3965 3966 3967 3968 3969 3970 3971 3972 3973 3974 3975 3976 3977 3978 3979 3980 3981 3982 3983 3984 3985
lxcDomainDetachDeviceNetLive(virDomainObjPtr vm,
                             virDomainDeviceDefPtr dev)
{
    int detachidx, ret = -1;
    virDomainNetDefPtr detach = NULL;
    char mac[VIR_MAC_STRING_BUFLEN];
    virNetDevVPortProfilePtr vport = NULL;

    detachidx = virDomainNetFindIdx(vm->def, dev->data.net);
    if (detachidx == -2) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("multiple devices matching mac address %s found"),
                       virMacAddrFormat(&dev->data.net->mac, mac));
        goto cleanup;
    } else if (detachidx < 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("network device %s not found"),
                       virMacAddrFormat(&dev->data.net->mac, mac));
        goto cleanup;
    }
    detach = vm->def->nets[detachidx];

    switch (virDomainNetGetActualType(detach)) {
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
    case VIR_DOMAIN_NET_TYPE_NETWORK:
        if (virNetDevVethDelete(detach->ifname) < 0) {
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
        break;

        /* It'd be nice to support this, but with macvlan
         * once assigned to a container nothing exists on
         * the host side. Further the container can change
         * the mac address of NIC name, so we can't easily
         * find out which guest NIC it maps to
    case VIR_DOMAIN_NET_TYPE_DIRECT:
        */

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Only bridged veth devices can be detached"));
        goto cleanup;
    }

    virDomainAuditNet(vm, detach, NULL, "detach", true);

    virDomainConfNWFilterTeardown(detach);

    vport = virDomainNetGetActualVirtPortProfile(detach);
    if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
        ignore_value(virNetDevOpenvswitchRemovePort(
                        virDomainNetGetActualBridgeName(detach),
                        detach->ifname));
    ret = 0;
cleanup:
    if (!ret) {
        networkReleaseActualDevice(detach);
        virDomainNetRemove(vm->def, detachidx);
        virDomainNetDefFree(detach);
    }
    return ret;
}


3986 3987 3988 3989 3990 3991 3992 3993
static int
lxcDomainDetachDeviceHostdevUSBLive(virLXCDriverPtr driver,
                                    virDomainObjPtr vm,
                                    virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
    int idx, ret = -1;
J
John Ferlan 已提交
3994
    char *dst = NULL;
3995
    char *vroot;
3996
    virUSBDevicePtr usb = NULL;
3997 3998 3999 4000 4001 4002 4003 4004 4005 4006

    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("usb device not found"));
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
4007
                    (unsigned long long)priv->initpid) < 0)
4008 4009 4010 4011 4012
        goto cleanup;

    if (virAsprintf(&dst, "%s/dev/bus/usb/%03d/%03d",
                    vroot,
                    def->source.subsys.u.usb.bus,
4013
                    def->source.subsys.u.usb.device) < 0)
4014 4015
        goto cleanup;

4016
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4017 4018 4019 4020 4021
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4022 4023
    if (!(usb = virUSBDeviceNew(def->source.subsys.u.usb.bus,
                                def->source.subsys.u.usb.device, vroot)))
4024 4025 4026 4027 4028 4029 4030 4031 4032 4033 4034
        goto cleanup;

    VIR_DEBUG("Unlinking %s", dst);
    if (unlink(dst) < 0 && errno != ENOENT) {
        virDomainAuditHostdev(vm, def, "detach", false);
        virReportSystemError(errno,
                             _("Unable to remove device %s"), dst);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4035
    if (virUSBDeviceFileIterate(usb,
4036 4037
                                virLXCTeardownHostUsbDeviceCgroup,
                                &priv->cgroup) < 0)
4038 4039 4040
        VIR_WARN("cannot deny device %s for domain %s",
                 dst, vm->def->name);

4041
    virObjectLock(driver->activeUsbHostdevs);
4042
    virUSBDeviceListDel(driver->activeUsbHostdevs, usb);
4043
    virObjectUnlock(driver->activeUsbHostdevs);
4044 4045 4046 4047 4048 4049 4050

    virDomainHostdevRemove(vm->def, idx);
    virDomainHostdevDefFree(def);

    ret = 0;

cleanup:
4051
    virUSBDeviceFree(usb);
4052 4053 4054 4055
    VIR_FREE(dst);
    return ret;
}

4056 4057

static int
4058
lxcDomainDetachDeviceHostdevStorageLive(virDomainObjPtr vm,
4059 4060 4061 4062
                                        virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
4063
    int idx, ret = -1;
4064 4065 4066 4067 4068 4069 4070 4071
    char *dst = NULL;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4072 4073 4074
    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
4075 4076 4077 4078 4079 4080 4081 4082
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("hostdev %s not found"),
                       dev->data.hostdev->source.caps.u.storage.block);
        goto cleanup;
    }

    if (virAsprintf(&dst, "/proc/%llu/root/%s",
                    (unsigned long long)priv->initpid,
4083
                    def->source.caps.u.storage.block) < 0)
4084 4085
        goto cleanup;

4086
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4087 4088 4089 4090 4091 4092 4093 4094 4095 4096 4097 4098 4099 4100
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

    VIR_DEBUG("Unlinking %s", dst);
    if (unlink(dst) < 0 && errno != ENOENT) {
        virDomainAuditHostdev(vm, def, "detach", false);
        virReportSystemError(errno,
                             _("Unable to remove device %s"), dst);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4101
    if (virCgroupDenyDevicePath(priv->cgroup, def->source.caps.u.storage.block, VIR_CGROUP_DEVICE_RWM) != 0)
4102 4103 4104
        VIR_WARN("cannot deny device %s for domain %s",
                 def->source.caps.u.storage.block, vm->def->name);

4105
    virDomainHostdevRemove(vm->def, idx);
4106 4107 4108 4109 4110 4111 4112 4113 4114 4115
    virDomainHostdevDefFree(def);

    ret = 0;

cleanup:
    VIR_FREE(dst);
    return ret;
}


4116
static int
4117
lxcDomainDetachDeviceHostdevMiscLive(virDomainObjPtr vm,
4118 4119 4120 4121
                                     virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
4122
    int idx, ret = -1;
4123 4124 4125 4126 4127 4128 4129 4130
    char *dst = NULL;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4131 4132 4133
    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
4134 4135 4136 4137 4138 4139 4140 4141
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("hostdev %s not found"),
                       dev->data.hostdev->source.caps.u.misc.chardev);
        goto cleanup;
    }

    if (virAsprintf(&dst, "/proc/%llu/root/%s",
                    (unsigned long long)priv->initpid,
4142
                    def->source.caps.u.misc.chardev) < 0)
4143 4144
        goto cleanup;

4145
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4146 4147 4148 4149 4150 4151 4152 4153 4154 4155 4156 4157 4158 4159
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

    VIR_DEBUG("Unlinking %s", dst);
    if (unlink(dst) < 0 && errno != ENOENT) {
        virDomainAuditHostdev(vm, def, "detach", false);
        virReportSystemError(errno,
                             _("Unable to remove device %s"), dst);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4160
    if (virCgroupDenyDevicePath(priv->cgroup, def->source.caps.u.misc.chardev, VIR_CGROUP_DEVICE_RWM) != 0)
4161 4162 4163
        VIR_WARN("cannot deny device %s for domain %s",
                 def->source.caps.u.misc.chardev, vm->def->name);

4164
    virDomainHostdevRemove(vm->def, idx);
4165 4166 4167 4168 4169 4170 4171 4172 4173 4174
    virDomainHostdevDefFree(def);

    ret = 0;

cleanup:
    VIR_FREE(dst);
    return ret;
}


4175 4176 4177 4178 4179 4180 4181 4182 4183 4184 4185 4186 4187 4188 4189 4190 4191 4192
static int
lxcDomainDetachDeviceHostdevSubsysLive(virLXCDriverPtr driver,
                                       virDomainObjPtr vm,
                                       virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        return lxcDomainDetachDeviceHostdevUSBLive(driver, vm, dev);

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevSubsysTypeToString(dev->data.hostdev->source.subsys.type));
        return -1;
    }
}


4193
static int
4194 4195
lxcDomainDetachDeviceHostdevCapsLive(virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
4196 4197 4198
{
    switch (dev->data.hostdev->source.caps.type) {
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_STORAGE:
4199
        return lxcDomainDetachDeviceHostdevStorageLive(vm, dev);
4200

4201
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_MISC:
4202
        return lxcDomainDetachDeviceHostdevMiscLive(vm, dev);
4203

4204 4205 4206 4207 4208 4209 4210 4211 4212
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevCapsTypeToString(dev->data.hostdev->source.caps.type));
        return -1;
    }
}


4213 4214 4215 4216 4217 4218 4219 4220 4221 4222 4223 4224 4225 4226 4227 4228 4229
static int
lxcDomainDetachDeviceHostdevLive(virLXCDriverPtr driver,
                                 virDomainObjPtr vm,
                                 virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach hostdev until init PID is known"));
        return -1;
    }

    switch (dev->data.hostdev->mode) {
    case VIR_DOMAIN_HOSTDEV_MODE_SUBSYS:
        return lxcDomainDetachDeviceHostdevSubsysLive(driver, vm, dev);

4230
    case VIR_DOMAIN_HOSTDEV_MODE_CAPABILITIES:
4231
        return lxcDomainDetachDeviceHostdevCapsLive(vm, dev);
4232

4233 4234 4235 4236 4237 4238 4239 4240 4241
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device mode %s"),
                       virDomainHostdevModeTypeToString(dev->data.hostdev->mode));
        return -1;
    }
}


4242 4243 4244
static int
lxcDomainDetachDeviceLive(virLXCDriverPtr driver,
                          virDomainObjPtr vm,
4245 4246 4247 4248 4249
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
4250
    case VIR_DOMAIN_DEVICE_DISK:
4251
        ret = lxcDomainDetachDeviceDiskLive(vm, dev);
4252 4253
        break;

4254 4255 4256 4257
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainDetachDeviceNetLive(vm, dev);
        break;

4258 4259 4260 4261
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        ret = lxcDomainDetachDeviceHostdevLive(driver, vm, dev);
        break;

4262 4263 4264 4265 4266 4267 4268 4269 4270 4271 4272
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be detached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


4273 4274 4275
static int lxcDomainAttachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
4276 4277
{
    virLXCDriverPtr driver = dom->conn->privateData;
4278
    virCapsPtr caps = NULL;
4279 4280 4281 4282 4283
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
    unsigned int affect;
4284
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4285 4286

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
4287
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
4288 4289 4290

    affect = flags & (VIR_DOMAIN_AFFECT_LIVE | VIR_DOMAIN_AFFECT_CONFIG);

4291
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
4292 4293 4294 4295 4296 4297 4298 4299 4300

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }

4301 4302 4303
    if (virDomainAttachDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4304 4305 4306 4307 4308 4309 4310 4311 4312 4313 4314 4315 4316 4317 4318
    if (virDomainObjIsActive(vm)) {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_LIVE;
    } else {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_CONFIG;
        /* check consistency between flags and the vm state */
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("cannot do live update a device on "
                             "inactive domain"));
            goto cleanup;
        }
    }

4319 4320 4321
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

4322 4323 4324 4325 4326 4327
    if ((flags & VIR_DOMAIN_AFFECT_CONFIG) && !vm->persistent) {
         virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                        _("cannot modify device on transient domain"));
         goto cleanup;
    }

4328
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4329
                                             caps, driver->xmlopt,
4330 4331 4332 4333 4334 4335 4336 4337 4338 4339
                                             VIR_DOMAIN_XML_INACTIVE);
    if (dev == NULL)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
4340
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4341
                                          caps, driver->xmlopt);
4342 4343 4344 4345 4346 4347 4348 4349 4350
        if (!dev_copy)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        if (virDomainDefCompatibleDevice(vm->def, dev) < 0)
            goto cleanup;

        /* Make a copy for updated domain. */
4351
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4352 4353
        if (!vmdef)
            goto cleanup;
4354
        if ((ret = lxcDomainAttachDeviceConfig(vmdef, dev)) < 0)
4355 4356 4357 4358 4359 4360 4361
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if (virDomainDefCompatibleDevice(vm->def, dev_copy) < 0)
            goto cleanup;

4362
        if ((ret = lxcDomainAttachDeviceLive(dom->conn, driver, vm, dev_copy)) < 0)
4363 4364 4365 4366 4367 4368
            goto cleanup;
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
4369
        if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0) {
4370 4371 4372 4373 4374 4375 4376
            ret = -1;
            goto cleanup;
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
4377
        ret = virDomainSaveConfig(cfg->configDir, vmdef);
4378
        if (!ret) {
4379
            virDomainObjAssignDef(vm, vmdef, false, NULL);
4380 4381 4382 4383 4384 4385 4386 4387 4388 4389
            vmdef = NULL;
        }
    }

cleanup:
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
    if (vm)
4390
        virObjectUnlock(vm);
4391
    virObjectUnref(caps);
4392
    virObjectUnref(cfg);
4393 4394 4395 4396 4397 4398 4399 4400 4401 4402 4403 4404 4405 4406 4407 4408
    return ret;
}


static int lxcDomainAttachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainAttachDeviceFlags(dom, xml,
                                       VIR_DOMAIN_AFFECT_LIVE);
}


static int lxcDomainUpdateDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
4409
    virLXCDriverPtr driver = dom->conn->privateData;
4410
    virCapsPtr caps = NULL;
4411 4412 4413 4414 4415
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
    unsigned int affect;
4416
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4417 4418 4419 4420 4421 4422 4423 4424 4425 4426 4427 4428 4429 4430 4431 4432 4433

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_DOMAIN_DEVICE_MODIFY_FORCE, -1);

    affect = flags & (VIR_DOMAIN_AFFECT_LIVE | VIR_DOMAIN_AFFECT_CONFIG);

    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }

4434 4435 4436
    if (virDomainUpdateDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4437 4438 4439 4440 4441 4442 4443 4444 4445 4446 4447 4448 4449 4450 4451 4452 4453 4454 4455 4456 4457
    if (virDomainObjIsActive(vm)) {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_LIVE;
    } else {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_CONFIG;
        /* check consistency between flags and the vm state */
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("cannot do live update a device on "
                             "inactive domain"));
            goto cleanup;
        }
    }

    if ((flags & VIR_DOMAIN_AFFECT_CONFIG) && !vm->persistent) {
         virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                        _("cannot modify device on transient domain"));
         goto cleanup;
    }

4458 4459 4460
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

4461
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4462
                                             caps, driver->xmlopt,
4463 4464 4465 4466 4467 4468 4469 4470 4471 4472 4473
                                             VIR_DOMAIN_XML_INACTIVE);
    if (dev == NULL)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4474
                                          caps, driver->xmlopt);
4475 4476 4477 4478 4479 4480 4481 4482 4483
        if (!dev_copy)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        if (virDomainDefCompatibleDevice(vm->def, dev) < 0)
            goto cleanup;

        /* Make a copy for updated domain. */
4484
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4485 4486 4487 4488 4489 4490 4491 4492 4493 4494 4495 4496 4497 4498 4499 4500 4501 4502
        if (!vmdef)
            goto cleanup;
        if ((ret = lxcDomainUpdateDeviceConfig(vmdef, dev)) < 0)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if (virDomainDefCompatibleDevice(vm->def, dev_copy) < 0)
            goto cleanup;

        virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                       _("Unable to modify live devices"));

        goto cleanup;
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
4503
        ret = virDomainSaveConfig(cfg->configDir, vmdef);
4504 4505 4506 4507 4508 4509 4510 4511 4512 4513 4514 4515 4516
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false, NULL);
            vmdef = NULL;
        }
    }

cleanup:
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
    if (vm)
        virObjectUnlock(vm);
4517
    virObjectUnref(caps);
4518
    virObjectUnref(cfg);
4519
    return ret;
4520 4521 4522 4523 4524 4525 4526
}


static int lxcDomainDetachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
4527
    virLXCDriverPtr driver = dom->conn->privateData;
4528
    virCapsPtr caps = NULL;
4529 4530 4531 4532 4533
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
    unsigned int affect;
4534
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4535 4536 4537 4538 4539 4540 4541 4542 4543 4544 4545 4546 4547 4548 4549 4550

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

    affect = flags & (VIR_DOMAIN_AFFECT_LIVE | VIR_DOMAIN_AFFECT_CONFIG);

    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);

    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }

4551 4552 4553
    if (virDomainDetachDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4554 4555 4556 4557 4558 4559 4560 4561 4562 4563 4564 4565 4566 4567 4568 4569 4570 4571 4572 4573 4574
    if (virDomainObjIsActive(vm)) {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_LIVE;
    } else {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_CONFIG;
        /* check consistency between flags and the vm state */
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("cannot do live update a device on "
                             "inactive domain"));
            goto cleanup;
        }
    }

    if ((flags & VIR_DOMAIN_AFFECT_CONFIG) && !vm->persistent) {
         virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                        _("cannot modify device on transient domain"));
         goto cleanup;
    }

4575 4576 4577
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

4578
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4579
                                             caps, driver->xmlopt,
4580 4581 4582 4583 4584 4585 4586 4587 4588 4589 4590
                                             VIR_DOMAIN_XML_INACTIVE);
    if (dev == NULL)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4591
                                          caps, driver->xmlopt);
4592 4593 4594 4595 4596 4597 4598 4599 4600
        if (!dev_copy)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        if (virDomainDefCompatibleDevice(vm->def, dev) < 0)
            goto cleanup;

        /* Make a copy for updated domain. */
4601
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4602 4603 4604 4605 4606 4607 4608 4609 4610 4611 4612 4613 4614 4615 4616 4617 4618 4619
        if (!vmdef)
            goto cleanup;

        if ((ret = lxcDomainDetachDeviceConfig(vmdef, dev)) < 0)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if (virDomainDefCompatibleDevice(vm->def, dev_copy) < 0)
            goto cleanup;

        if ((ret = lxcDomainDetachDeviceLive(driver, vm, dev_copy)) < 0)
            goto cleanup;
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
4620
        if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0) {
4621 4622 4623 4624 4625 4626 4627
            ret = -1;
            goto cleanup;
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
4628
        ret = virDomainSaveConfig(cfg->configDir, vmdef);
4629 4630 4631 4632 4633 4634 4635 4636 4637 4638 4639 4640 4641
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false, NULL);
            vmdef = NULL;
        }
    }

cleanup:
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
    if (vm)
        virObjectUnlock(vm);
4642
    virObjectUnref(caps);
4643
    virObjectUnref(cfg);
4644
    return ret;
4645 4646 4647 4648 4649 4650 4651 4652 4653 4654 4655
}


static int lxcDomainDetachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainDetachDeviceFlags(dom, xml,
                                      VIR_DOMAIN_AFFECT_LIVE);
}


4656 4657 4658
static int lxcDomainLxcOpenNamespace(virDomainPtr dom,
                                     int **fdlist,
                                     unsigned int flags)
4659 4660 4661 4662 4663 4664 4665 4666 4667 4668
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virDomainObjPtr vm;
    virLXCDomainObjPrivatePtr priv;
    int ret = -1;
    size_t nfds = 0;

    *fdlist = NULL;
    virCheckFlags(0, -1);

4669
    vm = virDomainObjListFindByUUID(driver->domains, dom->uuid);
4670 4671 4672 4673 4674 4675 4676 4677 4678
    if (!vm) {
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(dom->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s'"), uuidstr);
        goto cleanup;
    }
    priv = vm->privateData;

4679 4680 4681
    if (virDomainLxcOpenNamespaceEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

4682 4683 4684 4685 4686 4687 4688 4689 4690 4691 4692 4693 4694 4695 4696 4697 4698
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
        goto cleanup;
    }

    if (virProcessGetNamespaces(priv->initpid, &nfds, fdlist) < 0)
        goto cleanup;

    ret = nfds;
cleanup:
4699 4700
    if (vm)
        virObjectUnlock(vm);
4701 4702 4703 4704
    return ret;
}


4705
static char *
4706
lxcConnectGetSysinfo(virConnectPtr conn, unsigned int flags)
4707 4708 4709 4710 4711 4712
{
    virLXCDriverPtr driver = conn->privateData;
    virBuffer buf = VIR_BUFFER_INITIALIZER;

    virCheckFlags(0, NULL);

4713 4714 4715
    if (virConnectGetSysinfoEnsureACL(conn) < 0)
        return NULL;

4716 4717 4718 4719 4720 4721 4722 4723 4724 4725 4726 4727 4728 4729 4730 4731
    if (!driver->hostsysinfo) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Host SMBIOS information is not available"));
        return NULL;
    }

    if (virSysinfoFormat(&buf, driver->hostsysinfo) < 0)
        return NULL;
    if (virBufferError(&buf)) {
        virReportOOMError();
        return NULL;
    }
    return virBufferContentAndReset(&buf);
}


4732
static int
4733
lxcNodeGetInfo(virConnectPtr conn,
4734 4735
               virNodeInfoPtr nodeinfo)
{
4736 4737 4738
    if (virNodeGetInfoEnsureACL(conn) < 0)
        return -1;

4739 4740 4741 4742 4743
    return nodeGetInfo(nodeinfo);
}


static int
4744
lxcNodeGetCPUStats(virConnectPtr conn,
4745 4746 4747 4748 4749
                   int cpuNum,
                   virNodeCPUStatsPtr params,
                   int *nparams,
                   unsigned int flags)
{
4750 4751 4752
    if (virNodeGetCPUStatsEnsureACL(conn) < 0)
        return -1;

4753 4754 4755 4756 4757
    return nodeGetCPUStats(cpuNum, params, nparams, flags);
}


static int
4758
lxcNodeGetMemoryStats(virConnectPtr conn,
4759 4760 4761 4762 4763
                      int cellNum,
                      virNodeMemoryStatsPtr params,
                      int *nparams,
                      unsigned int flags)
{
4764 4765 4766
    if (virNodeGetMemoryStatsEnsureACL(conn) < 0)
        return -1;

4767 4768 4769 4770 4771
    return nodeGetMemoryStats(cellNum, params, nparams, flags);
}


static int
4772
lxcNodeGetCellsFreeMemory(virConnectPtr conn,
4773 4774 4775 4776
                          unsigned long long *freeMems,
                          int startCell,
                          int maxCells)
{
4777 4778 4779
    if (virNodeGetCellsFreeMemoryEnsureACL(conn) < 0)
        return -1;

4780 4781 4782 4783 4784
    return nodeGetCellsFreeMemory(freeMems, startCell, maxCells);
}


static unsigned long long
4785
lxcNodeGetFreeMemory(virConnectPtr conn)
4786
{
4787 4788 4789
    if (virNodeGetFreeMemoryEnsureACL(conn) < 0)
        return 0;

4790 4791 4792 4793 4794
    return nodeGetFreeMemory();
}


static int
4795
lxcNodeGetMemoryParameters(virConnectPtr conn,
4796 4797 4798 4799
                           virTypedParameterPtr params,
                           int *nparams,
                           unsigned int flags)
{
4800 4801 4802
    if (virNodeGetMemoryParametersEnsureACL(conn) < 0)
        return -1;

4803 4804 4805 4806 4807
    return nodeGetMemoryParameters(params, nparams, flags);
}


static int
4808
lxcNodeSetMemoryParameters(virConnectPtr conn,
4809 4810 4811 4812
                           virTypedParameterPtr params,
                           int nparams,
                           unsigned int flags)
{
4813 4814 4815
    if (virNodeSetMemoryParametersEnsureACL(conn) < 0)
        return -1;

4816 4817 4818 4819 4820
    return nodeSetMemoryParameters(params, nparams, flags);
}


static int
4821
lxcNodeGetCPUMap(virConnectPtr conn,
4822 4823 4824 4825
                 unsigned char **cpumap,
                 unsigned int *online,
                 unsigned int flags)
{
4826 4827 4828
    if (virNodeGetCPUMapEnsureACL(conn) < 0)
        return -1;

4829 4830 4831
    return nodeGetCPUMap(cpumap, online, flags);
}

4832 4833

static int
4834
lxcNodeSuspendForDuration(virConnectPtr conn,
4835 4836 4837 4838
                          unsigned int target,
                          unsigned long long duration,
                          unsigned int flags)
{
4839 4840 4841
    if (virNodeSuspendForDurationEnsureACL(conn) < 0)
        return -1;

4842 4843 4844 4845
    return nodeSuspendForDuration(target, duration, flags);
}


D
Daniel Veillard 已提交
4846 4847
/* Function Tables */
static virDriver lxcDriver = {
4848
    .no = VIR_DRV_LXC,
4849
    .name = LXC_DRIVER_NAME,
4850 4851 4852
    .connectOpen = lxcConnectOpen, /* 0.4.2 */
    .connectClose = lxcConnectClose, /* 0.4.2 */
    .connectGetVersion = lxcConnectGetVersion, /* 0.4.6 */
4853
    .connectGetHostname = lxcConnectGetHostname, /* 0.6.3 */
4854
    .connectGetSysinfo = lxcConnectGetSysinfo, /* 1.0.5 */
4855
    .nodeGetInfo = lxcNodeGetInfo, /* 0.6.5 */
4856 4857 4858 4859 4860
    .connectGetCapabilities = lxcConnectGetCapabilities, /* 0.6.5 */
    .connectListDomains = lxcConnectListDomains, /* 0.4.2 */
    .connectNumOfDomains = lxcConnectNumOfDomains, /* 0.4.2 */
    .connectListAllDomains = lxcConnectListAllDomains, /* 0.9.13 */
    .domainCreateXML = lxcDomainCreateXML, /* 0.4.4 */
4861
    .domainCreateXMLWithFiles = lxcDomainCreateXMLWithFiles, /* 1.1.1 */
4862 4863 4864 4865 4866 4867
    .domainLookupByID = lxcDomainLookupByID, /* 0.4.2 */
    .domainLookupByUUID = lxcDomainLookupByUUID, /* 0.4.2 */
    .domainLookupByName = lxcDomainLookupByName, /* 0.4.2 */
    .domainSuspend = lxcDomainSuspend, /* 0.7.2 */
    .domainResume = lxcDomainResume, /* 0.7.2 */
    .domainDestroy = lxcDomainDestroy, /* 0.4.4 */
4868
    .domainDestroyFlags = lxcDomainDestroyFlags, /* 0.9.4 */
4869
    .domainGetOSType = lxcDomainGetOSType, /* 0.4.2 */
4870 4871 4872 4873 4874
    .domainGetMaxMemory = lxcDomainGetMaxMemory, /* 0.7.2 */
    .domainSetMaxMemory = lxcDomainSetMaxMemory, /* 0.7.2 */
    .domainSetMemory = lxcDomainSetMemory, /* 0.7.2 */
    .domainSetMemoryParameters = lxcDomainSetMemoryParameters, /* 0.8.5 */
    .domainGetMemoryParameters = lxcDomainGetMemoryParameters, /* 0.8.5 */
4875 4876
    .domainSetBlkioParameters = lxcDomainSetBlkioParameters, /* 0.9.8 */
    .domainGetBlkioParameters = lxcDomainGetBlkioParameters, /* 0.9.8 */
4877 4878
    .domainGetInfo = lxcDomainGetInfo, /* 0.4.2 */
    .domainGetState = lxcDomainGetState, /* 0.9.2 */
4879 4880
    .domainGetSecurityLabel = lxcDomainGetSecurityLabel, /* 0.9.10 */
    .nodeGetSecurityModel = lxcNodeGetSecurityModel, /* 0.9.10 */
4881
    .domainGetXMLDesc = lxcDomainGetXMLDesc, /* 0.4.2 */
4882 4883 4884 4885
    .connectListDefinedDomains = lxcConnectListDefinedDomains, /* 0.4.2 */
    .connectNumOfDefinedDomains = lxcConnectNumOfDefinedDomains, /* 0.4.2 */
    .domainCreate = lxcDomainCreate, /* 0.4.4 */
    .domainCreateWithFlags = lxcDomainCreateWithFlags, /* 0.8.2 */
4886
    .domainCreateWithFiles = lxcDomainCreateWithFiles, /* 1.1.1 */
4887
    .domainDefineXML = lxcDomainDefineXML, /* 0.4.2 */
4888
    .domainUndefine = lxcDomainUndefine, /* 0.4.2 */
4889
    .domainUndefineFlags = lxcDomainUndefineFlags, /* 0.9.4 */
4890 4891 4892 4893 4894
    .domainAttachDevice = lxcDomainAttachDevice, /* 1.0.1 */
    .domainAttachDeviceFlags = lxcDomainAttachDeviceFlags, /* 1.0.1 */
    .domainDetachDevice = lxcDomainDetachDevice, /* 1.0.1 */
    .domainDetachDeviceFlags = lxcDomainDetachDeviceFlags, /* 1.0.1 */
    .domainUpdateDeviceFlags = lxcDomainUpdateDeviceFlags, /* 1.0.1 */
4895 4896
    .domainGetAutostart = lxcDomainGetAutostart, /* 0.7.0 */
    .domainSetAutostart = lxcDomainSetAutostart, /* 0.7.0 */
4897 4898 4899 4900 4901
    .domainGetSchedulerType = lxcDomainGetSchedulerType, /* 0.5.0 */
    .domainGetSchedulerParameters = lxcDomainGetSchedulerParameters, /* 0.5.0 */
    .domainGetSchedulerParametersFlags = lxcDomainGetSchedulerParametersFlags, /* 0.9.2 */
    .domainSetSchedulerParameters = lxcDomainSetSchedulerParameters, /* 0.5.0 */
    .domainSetSchedulerParametersFlags = lxcDomainSetSchedulerParametersFlags, /* 0.9.2 */
4902
    .domainInterfaceStats = lxcDomainInterfaceStats, /* 0.7.3 */
4903 4904 4905 4906 4907
    .nodeGetCPUStats = lxcNodeGetCPUStats, /* 0.9.3 */
    .nodeGetMemoryStats = lxcNodeGetMemoryStats, /* 0.9.3 */
    .nodeGetCellsFreeMemory = lxcNodeGetCellsFreeMemory, /* 0.6.5 */
    .nodeGetFreeMemory = lxcNodeGetFreeMemory, /* 0.6.5 */
    .nodeGetCPUMap = lxcNodeGetCPUMap, /* 1.0.0 */
4908 4909 4910 4911
    .connectDomainEventRegister = lxcConnectDomainEventRegister, /* 0.7.0 */
    .connectDomainEventDeregister = lxcConnectDomainEventDeregister, /* 0.7.0 */
    .connectIsEncrypted = lxcConnectIsEncrypted, /* 0.7.3 */
    .connectIsSecure = lxcConnectIsSecure, /* 0.7.3 */
4912 4913 4914
    .domainIsActive = lxcDomainIsActive, /* 0.7.3 */
    .domainIsPersistent = lxcDomainIsPersistent, /* 0.7.3 */
    .domainIsUpdated = lxcDomainIsUpdated, /* 0.8.6 */
4915 4916
    .connectDomainEventRegisterAny = lxcConnectDomainEventRegisterAny, /* 0.8.0 */
    .connectDomainEventDeregisterAny = lxcConnectDomainEventDeregisterAny, /* 0.8.0 */
4917
    .domainOpenConsole = lxcDomainOpenConsole, /* 0.8.6 */
4918
    .connectIsAlive = lxcConnectIsAlive, /* 0.9.8 */
4919
    .nodeSuspendForDuration = lxcNodeSuspendForDuration, /* 0.9.8 */
4920 4921
    .nodeGetMemoryParameters = lxcNodeGetMemoryParameters, /* 0.10.2 */
    .nodeSetMemoryParameters = lxcNodeSetMemoryParameters, /* 0.10.2 */
4922
    .domainSendProcessSignal = lxcDomainSendProcessSignal, /* 1.0.1 */
4923 4924 4925
    .domainShutdown = lxcDomainShutdown, /* 1.0.1 */
    .domainShutdownFlags = lxcDomainShutdownFlags, /* 1.0.1 */
    .domainReboot = lxcDomainReboot, /* 1.0.1 */
4926
    .domainLxcOpenNamespace = lxcDomainLxcOpenNamespace, /* 1.0.2 */
D
Daniel Veillard 已提交
4927 4928
};

4929
static virStateDriver lxcStateDriver = {
4930
    .name = LXC_DRIVER_NAME,
4931 4932 4933
    .stateInitialize = lxcStateInitialize,
    .stateCleanup = lxcStateCleanup,
    .stateReload = lxcStateReload,
4934 4935
};

D
Daniel Veillard 已提交
4936 4937 4938
int lxcRegister(void)
{
    virRegisterDriver(&lxcDriver);
4939
    virRegisterStateDriver(&lxcStateDriver);
D
Daniel Veillard 已提交
4940 4941
    return 0;
}