lxc_driver.c 140.2 KB
Newer Older
D
Daniel Veillard 已提交
1
/*
2
 * Copyright (C) 2010-2013 Red Hat, Inc.
D
Daniel Veillard 已提交
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
 * Copyright IBM Corp. 2008
 *
 * lxc_driver.c: linux container driver functions
 *
 * Authors:
 *  David L. Leskovec <dlesko at linux.vnet.ibm.com>
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
21
 * License along with this library.  If not, see
O
Osier Yang 已提交
22
 * <http://www.gnu.org/licenses/>.
D
Daniel Veillard 已提交
23 24 25 26
 */

#include <config.h>

27
#include <fcntl.h>
D
Daniel Veillard 已提交
28 29 30 31
#include <sched.h>
#include <sys/utsname.h>
#include <string.h>
#include <sys/types.h>
32
#include <sys/socket.h>
33
#include <sys/stat.h>
34 35
#include <sys/un.h>
#include <sys/poll.h>
D
Daniel Veillard 已提交
36 37 38
#include <unistd.h>
#include <wait.h>

39
#include "virerror.h"
40
#include "virlog.h"
41
#include "datatypes.h"
42
#include "lxc_cgroup.h"
D
Daniel Veillard 已提交
43
#include "lxc_conf.h"
44
#include "lxc_container.h"
45
#include "lxc_domain.h"
D
Daniel Veillard 已提交
46
#include "lxc_driver.h"
47
#include "lxc_process.h"
48
#include "viralloc.h"
49
#include "virnetdevbridge.h"
50
#include "virnetdevveth.h"
51
#include "nodeinfo.h"
52
#include "viruuid.h"
53
#include "virstatslinux.h"
54
#include "virhook.h"
E
Eric Blake 已提交
55
#include "virfile.h"
56
#include "virpidfile.h"
57
#include "fdstream.h"
58
#include "domain_audit.h"
59
#include "domain_nwfilter.h"
60
#include "nwfilter_conf.h"
61
#include "network/bridge_driver.h"
62
#include "virinitctl.h"
63
#include "virnetdev.h"
A
Ansis Atteka 已提交
64
#include "virnetdevtap.h"
65
#include "virnodesuspend.h"
66
#include "virprocess.h"
67
#include "virtime.h"
68
#include "virtypedparam.h"
M
Martin Kletzander 已提交
69
#include "viruri.h"
70
#include "virstring.h"
71 72
#include "viraccessapicheck.h"
#include "viraccessapichecklxc.h"
D
Daniel Veillard 已提交
73

74 75
#define VIR_FROM_THIS VIR_FROM_LXC

76

77 78
#define LXC_NB_MEM_PARAM  3

79 80 81 82
static int lxcStateInitialize(bool privileged,
                              virStateInhibitCallback callback,
                              void *opaque);
static int lxcStateCleanup(void);
83
virLXCDriverPtr lxc_driver = NULL;
D
Daniel Veillard 已提交
84

85 86 87
/* callbacks for nwfilter */
static int
lxcVMFilterRebuild(virConnectPtr conn ATTRIBUTE_UNUSED,
88
                   virDomainObjListIterator iter, void *data)
89
{
90
    return virDomainObjListForEach(lxc_driver->domains, iter, data);
91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111
}

static void
lxcVMDriverLock(void)
{
    lxcDriverLock(lxc_driver);
}

static void
lxcVMDriverUnlock(void)
{
    lxcDriverUnlock(lxc_driver);
}

static virNWFilterCallbackDriver lxcCallbackDriver = {
    .name = "LXC",
    .vmFilterRebuild = lxcVMFilterRebuild,
    .vmDriverLock = lxcVMDriverLock,
    .vmDriverUnlock = lxcVMDriverUnlock,
};

M
Michal Privoznik 已提交
112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140
/**
 * lxcDomObjFromDomain:
 * @domain: Domain pointer that has to be looked up
 *
 * This function looks up @domain and returns the appropriate
 * virDomainObjPtr.
 *
 * Returns the domain object which is locked on success, NULL
 * otherwise.
 */
static virDomainObjPtr
lxcDomObjFromDomain(virDomainPtr domain)
{
    virDomainObjPtr vm;
    virLXCDriverPtr driver = domain->conn->privateData;
    char uuidstr[VIR_UUID_STRING_BUFLEN];

    vm = virDomainObjListFindByUUID(driver->domains, domain->uuid);
    if (!vm) {
        virUUIDFormat(domain->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s' (%s)"),
                       uuidstr, domain->name);
        return NULL;
    }

    return vm;
}

D
Daniel Veillard 已提交
141 142
/* Functions */

143 144 145
static virDrvOpenStatus lxcConnectOpen(virConnectPtr conn,
                                       virConnectAuthPtr auth ATTRIBUTE_UNUSED,
                                       unsigned int flags)
D
Daniel Veillard 已提交
146
{
E
Eric Blake 已提交
147 148
    virCheckFlags(VIR_CONNECT_RO, VIR_DRV_OPEN_ERROR);

D
Daniel Veillard 已提交
149
    /* Verify uri was specified */
150
    if (conn->uri == NULL) {
151 152
        if (lxc_driver == NULL)
            return VIR_DRV_OPEN_DECLINED;
153

154
        if (!(conn->uri = virURIParse("lxc:///")))
155
            return VIR_DRV_OPEN_ERROR;
156 157 158 159 160 161 162 163 164 165
    } else {
        if (conn->uri->scheme == NULL ||
            STRNEQ(conn->uri->scheme, "lxc"))
            return VIR_DRV_OPEN_DECLINED;

        /* Leave for remote driver */
        if (conn->uri->server != NULL)
            return VIR_DRV_OPEN_DECLINED;

        /* If path isn't '/' then they typoed, tell them correct path */
166 167
        if (conn->uri->path != NULL &&
            STRNEQ(conn->uri->path, "/")) {
168 169 170
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("Unexpected LXC URI path '%s', try lxc:///"),
                           conn->uri->path);
171 172
            return VIR_DRV_OPEN_ERROR;
        }
D
Daniel Veillard 已提交
173

174 175
        /* URI was good, but driver isn't active */
        if (lxc_driver == NULL) {
176 177
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("lxc state driver is not active"));
178 179 180
            return VIR_DRV_OPEN_ERROR;
        }
    }
181

182 183 184
    if (virConnectOpenEnsureACL(conn) < 0)
        return VIR_DRV_OPEN_ERROR;

185
    conn->privateData = lxc_driver;
D
Daniel Veillard 已提交
186 187 188 189

    return VIR_DRV_OPEN_SUCCESS;
}

190
static int lxcConnectClose(virConnectPtr conn)
D
Daniel Veillard 已提交
191
{
192
    virLXCDriverPtr driver = conn->privateData;
193

194
    virCloseCallbacksRun(driver->closeCallbacks, conn, driver->domains, driver);
195 196
    conn->privateData = NULL;
    return 0;
D
Daniel Veillard 已提交
197 198
}

199

200
static int lxcConnectIsSecure(virConnectPtr conn ATTRIBUTE_UNUSED)
201 202 203 204 205 206
{
    /* Trivially secure, since always inside the daemon */
    return 1;
}


207
static int lxcConnectIsEncrypted(virConnectPtr conn ATTRIBUTE_UNUSED)
208 209 210 211 212 213
{
    /* Not encrypted, but remote driver takes care of that */
    return 0;
}


214
static int lxcConnectIsAlive(virConnectPtr conn ATTRIBUTE_UNUSED)
215 216 217 218 219
{
    return 1;
}


220
static char *lxcConnectGetCapabilities(virConnectPtr conn) {
221
    virLXCDriverPtr driver = conn->privateData;
222
    virCapsPtr caps;
223 224
    char *xml;

225 226 227
    if (virConnectGetCapabilitiesEnsureACL(conn) < 0)
        return NULL;

228
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
229 230 231
        return NULL;

    if ((xml = virCapabilitiesFormatXML(caps)) == NULL)
232
        virReportOOMError();
233

234
    virObjectUnref(caps);
235 236 237 238
    return xml;
}


D
Daniel Veillard 已提交
239 240 241
static virDomainPtr lxcDomainLookupByID(virConnectPtr conn,
                                        int id)
{
242
    virLXCDriverPtr driver = conn->privateData;
243 244
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
245

246
    vm = virDomainObjListFindByID(driver->domains, id);
247

D
Daniel Veillard 已提交
248
    if (!vm) {
249 250
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching id %d"), id);
251
        goto cleanup;
D
Daniel Veillard 已提交
252 253
    }

254 255 256
    if (virDomainLookupByIDEnsureACL(conn, vm->def) < 0)
        goto cleanup;

D
Daniel Veillard 已提交
257
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
258
    if (dom)
D
Daniel Veillard 已提交
259 260
        dom->id = vm->def->id;

261
cleanup:
262
    if (vm)
263
        virObjectUnlock(vm);
D
Daniel Veillard 已提交
264 265 266 267 268 269
    return dom;
}

static virDomainPtr lxcDomainLookupByUUID(virConnectPtr conn,
                                          const unsigned char *uuid)
{
270
    virLXCDriverPtr driver = conn->privateData;
271 272
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
273

274
    vm = virDomainObjListFindByUUID(driver->domains, uuid);
275

D
Daniel Veillard 已提交
276
    if (!vm) {
277 278
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(uuid, uuidstr);
279 280
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
281
        goto cleanup;
D
Daniel Veillard 已提交
282 283
    }

284 285 286
    if (virDomainLookupByUUIDEnsureACL(conn, vm->def) < 0)
        goto cleanup;

D
Daniel Veillard 已提交
287
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
288
    if (dom)
D
Daniel Veillard 已提交
289 290
        dom->id = vm->def->id;

291
cleanup:
292
    if (vm)
293
        virObjectUnlock(vm);
D
Daniel Veillard 已提交
294 295 296 297 298 299
    return dom;
}

static virDomainPtr lxcDomainLookupByName(virConnectPtr conn,
                                          const char *name)
{
300
    virLXCDriverPtr driver = conn->privateData;
301 302
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
303

304
    vm = virDomainObjListFindByName(driver->domains, name);
D
Daniel Veillard 已提交
305
    if (!vm) {
306 307
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching name '%s'"), name);
308
        goto cleanup;
D
Daniel Veillard 已提交
309 310
    }

311 312 313
    if (virDomainLookupByNameEnsureACL(conn, vm->def) < 0)
        goto cleanup;

D
Daniel Veillard 已提交
314
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
315
    if (dom)
D
Daniel Veillard 已提交
316 317
        dom->id = vm->def->id;

318
cleanup:
319
    if (vm)
320
        virObjectUnlock(vm);
D
Daniel Veillard 已提交
321 322 323
    return dom;
}

324 325 326 327 328 329

static int lxcDomainIsActive(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
330
    if (!(obj = lxcDomObjFromDomain(dom)))
331
        goto cleanup;
332 333 334 335

    if (virDomainIsActiveEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

336 337 338 339
    ret = virDomainObjIsActive(obj);

cleanup:
    if (obj)
340
        virObjectUnlock(obj);
341 342 343 344 345 346 347 348 349
    return ret;
}


static int lxcDomainIsPersistent(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
350
    if (!(obj = lxcDomObjFromDomain(dom)))
351
        goto cleanup;
352 353 354 355

    if (virDomainIsPersistentEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

356 357 358 359
    ret = obj->persistent;

cleanup:
    if (obj)
360
        virObjectUnlock(obj);
361 362 363
    return ret;
}

364 365 366 367 368
static int lxcDomainIsUpdated(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
369
    if (!(obj = lxcDomObjFromDomain(dom)))
370
        goto cleanup;
371 372 373 374

    if (virDomainIsUpdatedEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

375 376 377 378
    ret = obj->updated;

cleanup:
    if (obj)
379
        virObjectUnlock(obj);
380 381
    return ret;
}
382

383
static int lxcConnectListDomains(virConnectPtr conn, int *ids, int nids) {
384
    virLXCDriverPtr driver = conn->privateData;
385
    int n;
386

387 388 389
    if (virConnectListDomainsEnsureACL(conn) < 0)
        return -1;

390 391
    n = virDomainObjListGetActiveIDs(driver->domains, ids, nids,
                                     virConnectListDomainsCheckACL, conn);
392

393
    return n;
D
Daniel Veillard 已提交
394
}
395

396
static int lxcConnectNumOfDomains(virConnectPtr conn) {
397
    virLXCDriverPtr driver = conn->privateData;
398
    int n;
399

400 401 402
    if (virConnectNumOfDomainsEnsureACL(conn) < 0)
        return -1;

403 404
    n = virDomainObjListNumOfDomains(driver->domains, true,
                                     virConnectNumOfDomainsCheckACL, conn);
405

406
    return n;
D
Daniel Veillard 已提交
407 408
}

409 410
static int lxcConnectListDefinedDomains(virConnectPtr conn,
                                        char **const names, int nnames) {
411
    virLXCDriverPtr driver = conn->privateData;
412
    int n;
413

414 415 416
    if (virConnectListDefinedDomainsEnsureACL(conn) < 0)
        return -1;

417 418
    n = virDomainObjListGetInactiveNames(driver->domains, names, nnames,
                                         virConnectListDefinedDomainsCheckACL, conn);
419

420
    return n;
D
Daniel Veillard 已提交
421 422 423
}


424
static int lxcConnectNumOfDefinedDomains(virConnectPtr conn) {
425
    virLXCDriverPtr driver = conn->privateData;
426
    int n;
427

428 429 430
    if (virConnectNumOfDefinedDomainsEnsureACL(conn) < 0)
        return -1;

431 432
    n = virDomainObjListNumOfDomains(driver->domains, false,
                                     virConnectNumOfDefinedDomainsCheckACL, conn);
433

434
    return n;
D
Daniel Veillard 已提交
435 436
}

437 438


439
static virDomainPtr lxcDomainDefineXML(virConnectPtr conn, const char *xml)
D
Daniel Veillard 已提交
440
{
441
    virLXCDriverPtr driver = conn->privateData;
442
    virDomainDefPtr def = NULL;
443
    virDomainObjPtr vm = NULL;
444
    virDomainPtr dom = NULL;
445
    virDomainEventPtr event = NULL;
446
    virDomainDefPtr oldDef = NULL;
447
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
448
    virCapsPtr caps = NULL;
D
Daniel Veillard 已提交
449

450 451 452 453
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (!(def = virDomainDefParseString(xml, caps, driver->xmlopt,
M
Matthias Bolte 已提交
454
                                        1 << VIR_DOMAIN_VIRT_LXC,
455
                                        VIR_DOMAIN_XML_INACTIVE)))
456
        goto cleanup;
D
Daniel Veillard 已提交
457

458 459 460
    if (virDomainDefineXMLEnsureACL(conn, def) < 0)
        goto cleanup;

461 462 463
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

464
    if ((def->nets != NULL) && !(cfg->have_netns)) {
465 466
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
467
        goto cleanup;
468 469
    }

470
    if (!(vm = virDomainObjListAdd(driver->domains, def,
471
                                   driver->xmlopt,
472
                                   0, &oldDef)))
473 474
        goto cleanup;
    def = NULL;
475
    vm->persistent = 1;
D
Daniel Veillard 已提交
476

477
    if (virDomainSaveConfig(cfg->configDir,
478
                            vm->newDef ? vm->newDef : vm->def) < 0) {
479
        virDomainObjListRemove(driver->domains, vm);
480
        vm = NULL;
481
        goto cleanup;
D
Daniel Veillard 已提交
482 483
    }

484 485
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_DEFINED,
486
                                     !oldDef ?
487 488 489
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED :
                                     VIR_DOMAIN_EVENT_DEFINED_UPDATED);

D
Daniel Veillard 已提交
490
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
491
    if (dom)
D
Daniel Veillard 已提交
492 493
        dom->id = vm->def->id;

494 495
cleanup:
    virDomainDefFree(def);
496
    virDomainDefFree(oldDef);
497
    if (vm)
498
        virObjectUnlock(vm);
499
    if (event)
500
        virDomainEventStateQueue(driver->domainEventState, event);
501
    virObjectUnref(caps);
502
    virObjectUnref(cfg);
D
Daniel Veillard 已提交
503 504 505
    return dom;
}

506 507
static int lxcDomainUndefineFlags(virDomainPtr dom,
                                  unsigned int flags)
D
Daniel Veillard 已提交
508
{
509
    virLXCDriverPtr driver = dom->conn->privateData;
510
    virDomainObjPtr vm;
511
    virDomainEventPtr event = NULL;
512
    int ret = -1;
513
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
D
Daniel Veillard 已提交
514

515 516
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
517
    if (!(vm = lxcDomObjFromDomain(dom)))
518
        goto cleanup;
D
Daniel Veillard 已提交
519

520 521 522
    if (virDomainUndefineFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

523
    if (!vm->persistent) {
524 525
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot undefine transient domain"));
526
        goto cleanup;
527
    }
D
Daniel Veillard 已提交
528

529 530
    if (virDomainDeleteConfig(cfg->configDir,
                              cfg->autostartDir,
531 532
                              vm) < 0)
        goto cleanup;
D
Daniel Veillard 已提交
533

534 535 536 537
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_UNDEFINED,
                                     VIR_DOMAIN_EVENT_UNDEFINED_REMOVED);

538 539 540
    if (virDomainObjIsActive(vm)) {
        vm->persistent = 0;
    } else {
541
        virDomainObjListRemove(driver->domains, vm);
542 543 544
        vm = NULL;
    }

545
    ret = 0;
D
Daniel Veillard 已提交
546

547
cleanup:
548
    if (vm)
549
        virObjectUnlock(vm);
550
    if (event)
551
        virDomainEventStateQueue(driver->domainEventState, event);
552
    virObjectUnref(cfg);
553
    return ret;
D
Daniel Veillard 已提交
554 555
}

556 557 558 559 560
static int lxcDomainUndefine(virDomainPtr dom)
{
    return lxcDomainUndefineFlags(dom, 0);
}

D
Daniel Veillard 已提交
561 562 563
static int lxcDomainGetInfo(virDomainPtr dom,
                            virDomainInfoPtr info)
{
564
    virDomainObjPtr vm;
565
    int ret = -1;
566
    virLXCDomainObjPrivatePtr priv;
D
Daniel Veillard 已提交
567

M
Michal Privoznik 已提交
568
    if (!(vm = lxcDomObjFromDomain(dom)))
569
        goto cleanup;
D
Daniel Veillard 已提交
570

571 572
    priv = vm->privateData;

573 574 575
    if (virDomainGetInfoEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

J
Jiri Denemark 已提交
576
    info->state = virDomainObjGetState(vm, NULL);
D
Daniel Veillard 已提交
577

578
    if (!virDomainObjIsActive(vm)) {
D
Daniel Veillard 已提交
579
        info->cpuTime = 0;
580
        info->memory = vm->def->mem.cur_balloon;
D
Daniel Veillard 已提交
581
    } else {
582
        if (virCgroupGetCpuacctUsage(priv->cgroup, &(info->cpuTime)) < 0) {
583 584
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Cannot read cputime for domain"));
R
Ryota Ozaki 已提交
585 586
            goto cleanup;
        }
587 588 589 590 591
        if (virCgroupGetMemoryUsage(priv->cgroup, &(info->memory)) < 0) {
            /* Don't fail if we can't read memory usage due to a lack of
             * kernel support */
            if (virLastErrorIsSystemErrno(ENOENT)) {
                virResetLastError();
592
                info->memory = 0;
593
            } else {
594
                goto cleanup;
595
            }
596
        }
D
Daniel Veillard 已提交
597 598
    }

599
    info->maxMem = vm->def->mem.max_balloon;
600
    info->nrVirtCpu = vm->def->vcpus;
601
    ret = 0;
D
Daniel Veillard 已提交
602

603
cleanup:
604
    if (vm)
605
        virObjectUnlock(vm);
606
    return ret;
D
Daniel Veillard 已提交
607 608
}

609 610 611 612 613 614 615 616 617 618 619
static int
lxcDomainGetState(virDomainPtr dom,
                  int *state,
                  int *reason,
                  unsigned int flags)
{
    virDomainObjPtr vm;
    int ret = -1;

    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
620
    if (!(vm = lxcDomObjFromDomain(dom)))
621 622
        goto cleanup;

623 624 625
    if (virDomainGetStateEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

J
Jiri Denemark 已提交
626
    *state = virDomainObjGetState(vm, reason);
627 628 629 630
    ret = 0;

cleanup:
    if (vm)
631
        virObjectUnlock(vm);
632 633 634
    return ret;
}

635
static char *lxcDomainGetOSType(virDomainPtr dom)
D
Daniel Veillard 已提交
636
{
637 638
    virDomainObjPtr vm;
    char *ret = NULL;
639

M
Michal Privoznik 已提交
640
    if (!(vm = lxcDomObjFromDomain(dom)))
641
        goto cleanup;
642

643 644 645 646 647
    if (virDomainGetOSTypeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

    if (VIR_STRDUP(ret, vm->def->os.type) < 0)
        goto cleanup;
648

649
cleanup:
650
    if (vm)
651
        virObjectUnlock(vm);
652
    return ret;
D
Daniel Veillard 已提交
653 654
}

R
Ryota Ozaki 已提交
655
/* Returns max memory in kb, 0 if error */
656 657 658
static unsigned long long
lxcDomainGetMaxMemory(virDomainPtr dom)
{
R
Ryota Ozaki 已提交
659
    virDomainObjPtr vm;
660
    unsigned long long ret = 0;
R
Ryota Ozaki 已提交
661

M
Michal Privoznik 已提交
662
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
663 664
        goto cleanup;

665 666 667
    if (virDomainGetMaxMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

668
    ret = vm->def->mem.max_balloon;
R
Ryota Ozaki 已提交
669 670 671

cleanup:
    if (vm)
672
        virObjectUnlock(vm);
R
Ryota Ozaki 已提交
673 674 675 676 677 678 679
    return ret;
}

static int lxcDomainSetMaxMemory(virDomainPtr dom, unsigned long newmax) {
    virDomainObjPtr vm;
    int ret = -1;

M
Michal Privoznik 已提交
680
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
681 682
        goto cleanup;

683 684 685
    if (virDomainSetMaxMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

686
    if (newmax < vm->def->mem.cur_balloon) {
687 688
        virReportError(VIR_ERR_INVALID_ARG,
                       "%s", _("Cannot set max memory lower than current memory"));
R
Ryota Ozaki 已提交
689 690 691
        goto cleanup;
    }

692
    vm->def->mem.max_balloon = newmax;
R
Ryota Ozaki 已提交
693 694 695 696
    ret = 0;

cleanup:
    if (vm)
697
        virObjectUnlock(vm);
R
Ryota Ozaki 已提交
698 699 700 701 702 703
    return ret;
}

static int lxcDomainSetMemory(virDomainPtr dom, unsigned long newmem) {
    virDomainObjPtr vm;
    int ret = -1;
704
    virLXCDomainObjPrivatePtr priv;
R
Ryota Ozaki 已提交
705

M
Michal Privoznik 已提交
706
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
707
        goto cleanup;
M
Michal Privoznik 已提交
708

709
    priv = vm->privateData;
R
Ryota Ozaki 已提交
710

711 712 713
    if (virDomainSetMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

714
    if (newmem > vm->def->mem.max_balloon) {
715 716
        virReportError(VIR_ERR_INVALID_ARG,
                       "%s", _("Cannot set memory higher than max memory"));
R
Ryota Ozaki 已提交
717 718 719
        goto cleanup;
    }

720
    if (!virDomainObjIsActive(vm)) {
721 722
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
723 724
        goto cleanup;
    }
725

726
    if (virCgroupSetMemory(priv->cgroup, newmem) < 0) {
727 728
        virReportError(VIR_ERR_OPERATION_FAILED,
                       "%s", _("Failed to set memory for domain"));
729 730 731
        goto cleanup;
    }

R
Ryota Ozaki 已提交
732 733 734 735
    ret = 0;

cleanup:
    if (vm)
736
        virObjectUnlock(vm);
R
Ryota Ozaki 已提交
737 738 739
    return ret;
}

740 741 742 743 744
static int
lxcDomainSetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int nparams,
                             unsigned int flags)
745
{
746 747
    virCapsPtr caps = NULL;
    virDomainDefPtr vmdef = NULL;
748
    virDomainObjPtr vm = NULL;
749 750 751 752 753 754 755 756 757 758
    virLXCDomainObjPrivatePtr priv = NULL;
    virLXCDriverConfigPtr cfg = NULL;
    virLXCDriverPtr driver = dom->conn->privateData;
    unsigned long long hard_limit;
    unsigned long long soft_limit;
    unsigned long long swap_hard_limit;
    bool set_hard_limit = false;
    bool set_soft_limit = false;
    bool set_swap_hard_limit = false;
    int rc;
759 760
    int ret = -1;

761 762 763
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

764 765 766 767 768 769 770 771
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_MEMORY_HARD_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               NULL) < 0)
772
        return -1;
E
Eric Blake 已提交
773

M
Michal Privoznik 已提交
774
    if (!(vm = lxcDomObjFromDomain(dom)))
775
        goto cleanup;
M
Michal Privoznik 已提交
776

777
    priv = vm->privateData;
778
    cfg = virLXCDriverGetConfig(driver);
779

780 781 782 783
    if (virDomainSetMemoryParametersEnsureACL(dom->conn, vm->def, flags) < 0 ||
        !(caps = virLXCDriverGetCapabilities(driver, false)) ||
        virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
                                        vm, &flags, &vmdef) < 0)
784 785
        goto cleanup;

786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822
    if (flags & VIR_DOMAIN_AFFECT_LIVE &&
        !virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_MEMORY)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup memory controller is not mounted"));
        goto cleanup;
    }

#define VIR_GET_LIMIT_PARAMETER(PARAM, VALUE)                                \
    if ((rc = virTypedParamsGetULLong(params, nparams, PARAM, &VALUE)) < 0)  \
        goto cleanup;                                                        \
                                                                             \
    if (rc == 1)                                                             \
        set_ ## VALUE = true;

    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT, swap_hard_limit)
    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_HARD_LIMIT, hard_limit)
    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_SOFT_LIMIT, soft_limit)

#undef VIR_GET_LIMIT_PARAMETER

    /* Swap hard limit must be greater than hard limit.
     * Note that limit of 0 denotes unlimited */
    if (set_swap_hard_limit || set_hard_limit) {
        unsigned long long mem_limit = vm->def->mem.hard_limit;
        unsigned long long swap_limit = vm->def->mem.swap_hard_limit;

        if (set_swap_hard_limit)
            swap_limit = swap_hard_limit;

        if (set_hard_limit)
            mem_limit = hard_limit;

        if (virCompareLimitUlong(mem_limit, swap_limit) > 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("memory hard_limit tunable value must be lower "
                             "than or equal to swap_hard_limit"));
            goto cleanup;
823 824 825
        }
    }

826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863
#define LXC_SET_MEM_PARAMETER(FUNC, VALUE)                                     \
    if (set_ ## VALUE) {                                                        \
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {                                   \
            if ((rc = FUNC(priv->cgroup, VALUE)) < 0) {                         \
                virReportSystemError(-rc, _("unable to set memory %s tunable"), \
                                     #VALUE);                                   \
                                                                                \
                goto cleanup;                                                   \
            }                                                                   \
            vm->def->mem.VALUE = VALUE;                                         \
        }                                                                       \
                                                                                \
        if (flags & VIR_DOMAIN_AFFECT_CONFIG)                                   \
            vmdef->mem.VALUE = VALUE;                                   \
    }

    /* Soft limit doesn't clash with the others */
    LXC_SET_MEM_PARAMETER(virCgroupSetMemorySoftLimit, soft_limit);

    /* set hard limit before swap hard limit if decreasing it */
    if (virCompareLimitUlong(vm->def->mem.hard_limit, hard_limit) > 0) {
        LXC_SET_MEM_PARAMETER(virCgroupSetMemoryHardLimit, hard_limit);
        /* inhibit changing the limit a second time */
        set_hard_limit = false;
    }

    LXC_SET_MEM_PARAMETER(virCgroupSetMemSwapHardLimit, swap_hard_limit);

    /* otherwise increase it after swap hard limit */
    LXC_SET_MEM_PARAMETER(virCgroupSetMemoryHardLimit, hard_limit);

#undef LXC_SET_MEM_PARAMETER

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        virDomainSaveConfig(cfg->configDir, vmdef) < 0)
        goto cleanup;

    ret = 0;
864 865
cleanup:
    if (vm)
866
        virObjectUnlock(vm);
867 868
    virObjectUnref(caps);
    virObjectUnref(cfg);
869 870 871
    return ret;
}

872 873 874 875 876
static int
lxcDomainGetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int *nparams,
                             unsigned int flags)
877
{
878 879
    virCapsPtr caps = NULL;
    virDomainDefPtr vmdef = NULL;
880
    virDomainObjPtr vm = NULL;
881 882
    virLXCDomainObjPrivatePtr priv = NULL;
    virLXCDriverPtr driver = dom->conn->privateData;
883
    unsigned long long val;
884
    int ret = -1;
885
    size_t i;
886

887 888
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
E
Eric Blake 已提交
889

M
Michal Privoznik 已提交
890
    if (!(vm = lxcDomObjFromDomain(dom)))
891
        goto cleanup;
M
Michal Privoznik 已提交
892

893
    priv = vm->privateData;
894

895 896 897 898 899 900 901 902 903 904
    if (virDomainGetMemoryParametersEnsureACL(dom->conn, vm->def) < 0 ||
        !(caps = virLXCDriverGetCapabilities(driver, false)) ||
        virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
                                        vm, &flags, &vmdef) < 0)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_LIVE &&
        !virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_MEMORY)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup memory controller is not mounted"));
905
        goto cleanup;
906
    }
907

908 909 910 911 912 913 914
    if ((*nparams) == 0) {
        /* Current number of memory parameters supported by cgroups */
        *nparams = LXC_NB_MEM_PARAM;
        ret = 0;
        goto cleanup;
    }

915
    for (i = 0; i < LXC_NB_MEM_PARAM && i < *nparams; i++) {
916
        virTypedParameterPtr param = &params[i];
917 918
        val = 0;

919
        switch (i) {
920
        case 0: /* fill memory hard limit here */
921 922 923 924
            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                val = vmdef->mem.hard_limit;
                val = val ? val : VIR_DOMAIN_MEMORY_PARAM_UNLIMITED;
            } else if (virCgroupGetMemoryHardLimit(priv->cgroup, &val) < 0) {
925
                goto cleanup;
926
            }
927 928
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
929
                goto cleanup;
930 931
            break;
        case 1: /* fill memory soft limit here */
932 933 934 935
            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                val = vmdef->mem.soft_limit;
                val = val ? val : VIR_DOMAIN_MEMORY_PARAM_UNLIMITED;
            } else if (virCgroupGetMemorySoftLimit(priv->cgroup, &val) < 0) {
936
                goto cleanup;
937
            }
938 939
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
940
                goto cleanup;
941 942
            break;
        case 2: /* fill swap hard limit here */
943 944 945 946
            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                val = vmdef->mem.swap_hard_limit;
                val = val ? val : VIR_DOMAIN_MEMORY_PARAM_UNLIMITED;
            } else if (virCgroupGetMemSwapHardLimit(priv->cgroup, &val) < 0) {
947
                goto cleanup;
948
            }
949 950 951
            if (virTypedParameterAssign(param,
                                        VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
952
                goto cleanup;
953 954
            break;

955
        /* coverity[dead_error_begin] */
956 957 958 959 960 961
        default:
            break;
            /* should not hit here */
        }
    }

962 963
    if (*nparams > LXC_NB_MEM_PARAM)
        *nparams = LXC_NB_MEM_PARAM;
964 965
    ret = 0;

966 967
cleanup:
    if (vm)
968
        virObjectUnlock(vm);
969
    virObjectUnref(caps);
970 971 972
    return ret;
}

973
static char *lxcDomainGetXMLDesc(virDomainPtr dom,
974
                                 unsigned int flags)
D
Daniel Veillard 已提交
975
{
976 977
    virDomainObjPtr vm;
    char *ret = NULL;
D
Daniel Veillard 已提交
978

979 980
    /* Flags checked by virDomainDefFormat */

M
Michal Privoznik 已提交
981
    if (!(vm = lxcDomObjFromDomain(dom)))
982
        goto cleanup;
D
Daniel Veillard 已提交
983

984 985 986
    if (virDomainGetXMLDescEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

987
    ret = virDomainDefFormat((flags & VIR_DOMAIN_XML_INACTIVE) &&
988 989 990 991
                             vm->newDef ? vm->newDef : vm->def,
                             flags);

cleanup:
992
    if (vm)
993
        virObjectUnlock(vm);
994
    return ret;
D
Daniel Veillard 已提交
995 996
}

997
/**
998
 * lxcDomainCreateWithFlags:
999
 * @dom: domain to start
1000
 * @flags: Must be 0 for now
1001 1002 1003 1004 1005
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
1006 1007 1008 1009
static int lxcDomainCreateWithFiles(virDomainPtr dom,
                                    unsigned int nfiles,
                                    int *files,
                                    unsigned int flags)
1010
{
1011
    virLXCDriverPtr driver = dom->conn->privateData;
1012
    virDomainObjPtr vm;
1013
    virDomainEventPtr event = NULL;
1014
    int ret = -1;
1015
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1016

1017
    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY, -1);
1018

M
Michal Privoznik 已提交
1019
    if (!(vm = lxcDomObjFromDomain(dom)))
1020 1021
        goto cleanup;

1022
    if (virDomainCreateWithFilesEnsureACL(dom->conn, vm->def) < 0)
1023 1024
        goto cleanup;

1025
    if ((vm->def->nets != NULL) && !(cfg->have_netns)) {
1026 1027
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
1028 1029 1030
        goto cleanup;
    }

1031
    if (virDomainObjIsActive(vm)) {
1032 1033
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is already running"));
1034 1035 1036
        goto cleanup;
    }

1037
    ret = virLXCProcessStart(dom->conn, driver, vm,
1038
                             nfiles, files,
1039 1040
                             (flags & VIR_DOMAIN_START_AUTODESTROY),
                             VIR_DOMAIN_RUNNING_BOOTED);
1041

1042
    if (ret == 0) {
1043 1044 1045
        event = virDomainEventNewFromObj(vm,
                                         VIR_DOMAIN_EVENT_STARTED,
                                         VIR_DOMAIN_EVENT_STARTED_BOOTED);
1046 1047 1048 1049
        virDomainAuditStart(vm, "booted", true);
    } else {
        virDomainAuditStart(vm, "booted", false);
    }
1050

1051
cleanup:
1052
    if (vm)
1053
        virObjectUnlock(vm);
1054
    if (event)
1055
        virDomainEventStateQueue(driver->domainEventState, event);
1056
    virObjectUnref(cfg);
1057
    return ret;
1058 1059
}

1060
/**
1061
 * lxcDomainCreate:
1062 1063 1064 1065 1066 1067
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
1068
static int lxcDomainCreate(virDomainPtr dom)
1069
{
1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084
    return lxcDomainCreateWithFiles(dom, 0, NULL, 0);
}

/**
 * lxcDomainCreateWithFlags:
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
static int lxcDomainCreateWithFlags(virDomainPtr dom,
                                    unsigned int flags)
{
    return lxcDomainCreateWithFiles(dom, 0, NULL, flags);
1085 1086
}

1087
/**
1088
 * lxcDomainCreateXML:
1089 1090
 * @conn: pointer to connection
 * @xml: XML definition of domain
1091
 * @flags: Must be 0 for now
1092 1093 1094 1095 1096 1097
 *
 * Creates a domain based on xml and starts it
 *
 * Returns 0 on success or -1 in case of error
 */
static virDomainPtr
1098 1099 1100 1101 1102
lxcDomainCreateXMLWithFiles(virConnectPtr conn,
                            const char *xml,
                            unsigned int nfiles,
                            int *files,
                            unsigned int flags) {
1103
    virLXCDriverPtr driver = conn->privateData;
1104
    virDomainObjPtr vm = NULL;
1105
    virDomainDefPtr def = NULL;
1106
    virDomainPtr dom = NULL;
1107
    virDomainEventPtr event = NULL;
1108
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1109
    virCapsPtr caps = NULL;
1110

1111
    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY, NULL);
1112

1113 1114 1115 1116
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (!(def = virDomainDefParseString(xml, caps, driver->xmlopt,
M
Matthias Bolte 已提交
1117
                                        1 << VIR_DOMAIN_VIRT_LXC,
1118
                                        VIR_DOMAIN_XML_INACTIVE)))
1119
        goto cleanup;
1120

1121
    if (virDomainCreateXMLWithFilesEnsureACL(conn, def) < 0)
1122 1123
        goto cleanup;

1124 1125 1126
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

1127
    if ((def->nets != NULL) && !(cfg->have_netns)) {
1128 1129
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       "%s", _("System lacks NETNS support"));
1130
        goto cleanup;
1131 1132
    }

1133

1134
    if (!(vm = virDomainObjListAdd(driver->domains, def,
1135
                                   driver->xmlopt,
1136 1137
                                   VIR_DOMAIN_OBJ_LIST_ADD_CHECK_LIVE,
                                   NULL)))
1138 1139
        goto cleanup;
    def = NULL;
1140

1141
    if (virLXCProcessStart(conn, driver, vm,
1142
                           nfiles, files,
1143 1144
                           (flags & VIR_DOMAIN_START_AUTODESTROY),
                           VIR_DOMAIN_RUNNING_BOOTED) < 0) {
1145
        virDomainAuditStart(vm, "booted", false);
1146
        virDomainObjListRemove(driver->domains, vm);
1147
        vm = NULL;
1148
        goto cleanup;
1149 1150
    }

1151 1152 1153
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_STARTED,
                                     VIR_DOMAIN_EVENT_STARTED_BOOTED);
1154
    virDomainAuditStart(vm, "booted", true);
1155

1156
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid);
1157
    if (dom)
1158 1159
        dom->id = vm->def->id;

1160 1161
cleanup:
    virDomainDefFree(def);
1162
    if (vm)
1163
        virObjectUnlock(vm);
1164
    if (event)
1165
        virDomainEventStateQueue(driver->domainEventState, event);
1166
    virObjectUnref(caps);
1167
    virObjectUnref(cfg);
1168 1169 1170
    return dom;
}

1171

1172 1173 1174 1175 1176 1177 1178 1179
static virDomainPtr
lxcDomainCreateXML(virConnectPtr conn,
                   const char *xml,
                   unsigned int flags) {
    return lxcDomainCreateXMLWithFiles(conn, xml, 0, NULL,  flags);
}


1180 1181
static int lxcDomainGetSecurityLabel(virDomainPtr dom, virSecurityLabelPtr seclabel)
{
1182
    virLXCDriverPtr driver = dom->conn->privateData;
1183 1184 1185 1186 1187
    virDomainObjPtr vm;
    int ret = -1;

    memset(seclabel, 0, sizeof(*seclabel));

M
Michal Privoznik 已提交
1188
    if (!(vm = lxcDomObjFromDomain(dom)))
1189 1190
        goto cleanup;

1191 1192 1193
    if (virDomainGetSecurityLabelEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1194
    if (!virDomainVirtTypeToString(vm->def->virtType)) {
1195 1196 1197
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unknown virt type in domain definition '%d'"),
                       vm->def->virtType);
1198 1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214 1215
        goto cleanup;
    }

    /*
     * Theoretically, the pid can be replaced during this operation and
     * return the label of a different process.  If atomicity is needed,
     * further validation will be required.
     *
     * Comment from Dan Berrange:
     *
     *   Well the PID as stored in the virDomainObjPtr can't be changed
     *   because you've got a locked object.  The OS level PID could have
     *   exited, though and in extreme circumstances have cycled through all
     *   PIDs back to ours. We could sanity check that our PID still exists
     *   after reading the label, by checking that our FD connecting to the
     *   LXC monitor hasn't seen SIGHUP/ERR on poll().
     */
    if (virDomainObjIsActive(vm)) {
1216 1217 1218 1219 1220 1221 1222 1223
        virLXCDomainObjPrivatePtr priv = vm->privateData;

        if (!priv->initpid) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("Init pid is not yet available"));
            goto cleanup;
        }

1224
        if (virSecurityManagerGetProcessLabel(driver->securityManager,
1225
                                              vm->def, priv->initpid, seclabel) < 0) {
1226 1227
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("Failed to get security label"));
1228 1229 1230 1231 1232 1233 1234 1235
            goto cleanup;
        }
    }

    ret = 0;

cleanup:
    if (vm)
1236
        virObjectUnlock(vm);
1237 1238 1239 1240 1241 1242
    return ret;
}

static int lxcNodeGetSecurityModel(virConnectPtr conn,
                                   virSecurityModelPtr secmodel)
{
1243
    virLXCDriverPtr driver = conn->privateData;
1244
    virCapsPtr caps = NULL;
1245 1246 1247 1248
    int ret = 0;

    memset(secmodel, 0, sizeof(*secmodel));

1249 1250 1251
    if (virNodeGetSecurityModelEnsureACL(conn) < 0)
        goto cleanup;

1252 1253 1254
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

1255
    /* we treat no driver as success, but simply return no data in *secmodel */
1256 1257
    if (caps->host.nsecModels == 0
        || caps->host.secModels[0].model == NULL)
1258 1259
        goto cleanup;

1260
    if (!virStrcpy(secmodel->model, caps->host.secModels[0].model,
1261
                   VIR_SECURITY_MODEL_BUFLEN)) {
1262 1263 1264
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security model string exceeds max %d bytes"),
                       VIR_SECURITY_MODEL_BUFLEN - 1);
1265 1266 1267 1268
        ret = -1;
        goto cleanup;
    }

1269
    if (!virStrcpy(secmodel->doi, caps->host.secModels[0].doi,
1270
                   VIR_SECURITY_DOI_BUFLEN)) {
1271 1272 1273
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security DOI string exceeds max %d bytes"),
                       VIR_SECURITY_DOI_BUFLEN-1);
1274 1275 1276 1277 1278
        ret = -1;
        goto cleanup;
    }

cleanup:
1279
    virObjectUnref(caps);
1280 1281 1282 1283
    return ret;
}


1284
static int
1285 1286 1287 1288
lxcConnectDomainEventRegister(virConnectPtr conn,
                              virConnectDomainEventCallback callback,
                              void *opaque,
                              virFreeCallback freecb)
1289
{
1290
    virLXCDriverPtr driver = conn->privateData;
1291 1292
    int ret;

1293 1294 1295
    if (virConnectDomainEventRegisterEnsureACL(conn) < 0)
        return -1;

1296 1297 1298
    ret = virDomainEventStateRegister(conn,
                                      driver->domainEventState,
                                      callback, opaque, freecb);
1299

1300
    return ret;
1301 1302
}

1303

1304
static int
1305 1306
lxcConnectDomainEventDeregister(virConnectPtr conn,
                                virConnectDomainEventCallback callback)
1307
{
1308
    virLXCDriverPtr driver = conn->privateData;
1309 1310
    int ret;

1311 1312 1313
    if (virConnectDomainEventDeregisterEnsureACL(conn) < 0)
        return -1;

1314 1315 1316
    ret = virDomainEventStateDeregister(conn,
                                        driver->domainEventState,
                                        callback);
1317 1318 1319 1320

    return ret;
}

1321 1322

static int
1323 1324 1325 1326 1327 1328
lxcConnectDomainEventRegisterAny(virConnectPtr conn,
                                 virDomainPtr dom,
                                 int eventID,
                                 virConnectDomainEventGenericCallback callback,
                                 void *opaque,
                                 virFreeCallback freecb)
1329
{
1330
    virLXCDriverPtr driver = conn->privateData;
1331 1332
    int ret;

1333 1334 1335
    if (virConnectDomainEventRegisterAnyEnsureACL(conn) < 0)
        return -1;

1336 1337 1338 1339
    if (virDomainEventStateRegisterID(conn,
                                      driver->domainEventState,
                                      dom, eventID,
                                      callback, opaque, freecb, &ret) < 0)
1340
        ret = -1;
1341 1342 1343 1344 1345 1346

    return ret;
}


static int
1347 1348
lxcConnectDomainEventDeregisterAny(virConnectPtr conn,
                                   int callbackID)
1349
{
1350
    virLXCDriverPtr driver = conn->privateData;
1351 1352
    int ret;

1353 1354 1355
    if (virConnectDomainEventDeregisterAnyEnsureACL(conn) < 0)
        return -1;

1356 1357 1358
    ret = virDomainEventStateDeregisterID(conn,
                                          driver->domainEventState,
                                          callbackID);
1359 1360 1361 1362 1363

    return ret;
}


1364
/**
1365
 * lxcDomainDestroyFlags:
1366
 * @dom: pointer to domain to destroy
1367
 * @flags: an OR'ed set of virDomainDestroyFlags
1368 1369 1370 1371 1372
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
1373 1374 1375
static int
lxcDomainDestroyFlags(virDomainPtr dom,
                      unsigned int flags)
1376
{
1377
    virLXCDriverPtr driver = dom->conn->privateData;
1378
    virDomainObjPtr vm;
1379
    virDomainEventPtr event = NULL;
1380
    int ret = -1;
1381
    virLXCDomainObjPrivatePtr priv;
1382

1383 1384
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
1385
    if (!(vm = lxcDomObjFromDomain(dom)))
1386
        goto cleanup;
1387

1388 1389 1390
    if (virDomainDestroyFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1391
    if (!virDomainObjIsActive(vm)) {
1392 1393
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
1394 1395 1396
        goto cleanup;
    }

1397
    priv = vm->privateData;
1398
    ret = virLXCProcessStop(driver, vm, VIR_DOMAIN_SHUTOFF_DESTROYED);
1399 1400 1401
    event = virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_STOPPED,
                                     VIR_DOMAIN_EVENT_STOPPED_DESTROYED);
1402
    priv->doneStopEvent = true;
1403
    virDomainAuditStop(vm, "destroyed");
1404
    if (!vm->persistent) {
1405
        virDomainObjListRemove(driver->domains, vm);
1406 1407
        vm = NULL;
    }
1408 1409

cleanup:
1410
    if (vm)
1411
        virObjectUnlock(vm);
1412
    if (event)
1413
        virDomainEventStateQueue(driver->domainEventState, event);
1414
    return ret;
1415
}
1416

1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430
/**
 * lxcDomainDestroy:
 * @dom: pointer to domain to destroy
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
static int
lxcDomainDestroy(virDomainPtr dom)
{
    return lxcDomainDestroyFlags(dom, 0);
}

1431 1432 1433 1434 1435
static int lxcCheckNetNsSupport(void)
{
    const char *argv[] = {"ip", "link", "set", "lo", "netns", "-1", NULL};
    int ip_rc;

1436
    if (virRun(argv, &ip_rc) < 0 ||
1437 1438
        !(WIFEXITED(ip_rc) && (WEXITSTATUS(ip_rc) != 255)))
        return 0;
1439

1440 1441
    if (lxcContainerAvailable(LXC_CONTAINER_FEATURE_NET) < 0)
        return 0;
1442

1443
    return 1;
1444 1445
}

1446

1447 1448
static virSecurityManagerPtr
lxcSecurityInit(virLXCDriverConfigPtr cfg)
1449
{
1450 1451
    VIR_INFO("lxcSecurityInit %s", cfg->securityDriverName);
    virSecurityManagerPtr mgr = virSecurityManagerNew(cfg->securityDriverName,
1452
                                                      LXC_DRIVER_NAME,
1453
                                                      false,
1454 1455
                                                      cfg->securityDefaultConfined,
                                                      cfg->securityRequireConfined);
1456 1457 1458
    if (!mgr)
        goto error;

1459
    return mgr;
1460 1461 1462

error:
    VIR_ERROR(_("Failed to initialize security drivers"));
1463
    virObjectUnref(mgr);
1464
    return NULL;
1465 1466 1467
}


1468 1469 1470
static int lxcStateInitialize(bool privileged,
                              virStateInhibitCallback callback ATTRIBUTE_UNUSED,
                              void *opaque ATTRIBUTE_UNUSED)
D
Daniel Veillard 已提交
1471
{
1472
    virCapsPtr caps = NULL;
1473
    const char *ld;
1474
    virLXCDriverConfigPtr cfg = NULL;
1475 1476 1477 1478 1479

    /* Valgrind gets very annoyed when we clone containers, so
     * disable LXC when under valgrind
     * XXX remove this when valgrind is fixed
     */
1480
    ld = virGetEnvBlockSUID("LD_PRELOAD");
1481
    if (ld && strstr(ld, "vgpreload")) {
1482
        VIR_INFO("Running under valgrind, disabling driver");
1483 1484
        return 0;
    }
1485

1486
    /* Check that the user is root, silently disable if not */
1487
    if (!privileged) {
1488
        VIR_INFO("Not running privileged, disabling driver");
1489 1490 1491 1492 1493
        return 0;
    }

    /* Check that this is a container enabled kernel */
    if (lxcContainerAvailable(0) < 0) {
1494
        VIR_INFO("LXC support not available in this kernel, disabling driver");
1495
        return 0;
1496 1497
    }

1498
    if (VIR_ALLOC(lxc_driver) < 0) {
1499 1500
        return -1;
    }
1501 1502 1503 1504
    if (virMutexInit(&lxc_driver->lock) < 0) {
        VIR_FREE(lxc_driver);
        return -1;
    }
D
Daniel Veillard 已提交
1505

1506
    if (!(lxc_driver->domains = virDomainObjListNew()))
1507 1508
        goto cleanup;

1509
    lxc_driver->domainEventState = virDomainEventStateNew();
1510
    if (!lxc_driver->domainEventState)
1511 1512
        goto cleanup;

1513 1514
    lxc_driver->hostsysinfo = virSysinfoRead();

1515 1516 1517 1518 1519
    if (!(lxc_driver->config = cfg = virLXCDriverConfigNew()))
        goto cleanup;

    cfg->log_libvirtd = 0; /* by default log to container logfile */
    cfg->have_netns = lxcCheckNetNsSupport();
D
Daniel Veillard 已提交
1520 1521

    /* Call function to load lxc driver configuration information */
1522
    if (virLXCLoadDriverConfig(cfg, SYSCONFDIR "/libvirt/lxc.conf") < 0)
1523
        goto cleanup;
D
Daniel Veillard 已提交
1524

1525
    if (!(lxc_driver->securityManager = lxcSecurityInit(cfg)))
1526 1527
        goto cleanup;

G
Guido Günther 已提交
1528 1529 1530
    if ((lxc_driver->activeUsbHostdevs = virUSBDeviceListNew()) == NULL)
        goto cleanup;

1531
    if ((virLXCDriverGetCapabilities(lxc_driver, true)) == NULL)
1532
        goto cleanup;
D
Daniel Veillard 已提交
1533

1534
    if (!(lxc_driver->xmlopt = lxcDomainXMLConfInit()))
1535
        goto cleanup;
1536

1537
    if (!(lxc_driver->closeCallbacks = virCloseCallbacksNew()))
1538 1539
        goto cleanup;

1540 1541 1542
    if (!(caps = virLXCDriverGetCapabilities(lxc_driver, false)))
        goto cleanup;

O
Osier Yang 已提交
1543
    /* Get all the running persistent or transient configs first */
1544
    if (virDomainObjListLoadAllConfigs(lxc_driver->domains,
1545
                                       cfg->stateDir,
1546
                                       NULL, 1,
1547
                                       caps,
1548
                                       lxc_driver->xmlopt,
1549
                                       1 << VIR_DOMAIN_VIRT_LXC,
1550
                                       NULL, NULL) < 0)
O
Osier Yang 已提交
1551 1552
        goto cleanup;

1553
    virLXCProcessReconnectAll(lxc_driver, lxc_driver->domains);
O
Osier Yang 已提交
1554 1555

    /* Then inactive persistent configs */
1556
    if (virDomainObjListLoadAllConfigs(lxc_driver->domains,
1557 1558
                                       cfg->configDir,
                                       cfg->autostartDir, 0,
1559
                                       caps,
1560
                                       lxc_driver->xmlopt,
1561
                                       1 << VIR_DOMAIN_VIRT_LXC,
1562
                                       NULL, NULL) < 0)
1563
        goto cleanup;
1564

1565
    virNWFilterRegisterCallbackDriver(&lxcCallbackDriver);
D
Daniel Veillard 已提交
1566 1567
    return 0;

1568
cleanup:
1569
    virObjectUnref(caps);
1570
    lxcStateCleanup();
1571
    return -1;
D
Daniel Veillard 已提交
1572 1573
}

1574 1575 1576 1577 1578 1579 1580 1581 1582 1583 1584 1585 1586
/**
 * lxcStateAutoStart:
 *
 * Function to autostart the LXC daemons
 */
static void lxcStateAutoStart(void)
{
    if (!lxc_driver)
        return;

    virLXCProcessAutostartAll(lxc_driver);
}

1587 1588
static void lxcNotifyLoadDomain(virDomainObjPtr vm, int newVM, void *opaque)
{
1589
    virLXCDriverPtr driver = opaque;
1590 1591 1592 1593 1594 1595 1596

    if (newVM) {
        virDomainEventPtr event =
            virDomainEventNewFromObj(vm,
                                     VIR_DOMAIN_EVENT_DEFINED,
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED);
        if (event)
1597
            virDomainEventStateQueue(driver->domainEventState, event);
1598 1599 1600 1601
    }
}

/**
1602
 * lxcStateReload:
1603 1604 1605 1606 1607
 *
 * Function to restart the LXC driver, it will recheck the configuration
 * files and perform autostart
 */
static int
1608
lxcStateReload(void) {
1609
    virLXCDriverConfigPtr cfg = NULL;
1610
    virCapsPtr caps = NULL;
1611

1612 1613 1614
    if (!lxc_driver)
        return 0;

1615
    if (!(caps = virLXCDriverGetCapabilities(lxc_driver, false)))
1616 1617
        return -1;

1618 1619
    cfg = virLXCDriverGetConfig(lxc_driver);

1620
    virDomainObjListLoadAllConfigs(lxc_driver->domains,
1621 1622
                                   cfg->configDir,
                                   cfg->autostartDir, 0,
1623
                                   caps,
1624
                                   lxc_driver->xmlopt,
1625
                                   1 << VIR_DOMAIN_VIRT_LXC,
1626
                                   lxcNotifyLoadDomain, lxc_driver);
1627
    virObjectUnref(caps);
1628
    virObjectUnref(cfg);
1629 1630 1631
    return 0;
}

1632
static int lxcStateCleanup(void)
D
Daniel Veillard 已提交
1633
{
1634
    if (lxc_driver == NULL)
1635
        return -1;
1636

1637
    virNWFilterUnRegisterCallbackDriver(&lxcCallbackDriver);
1638
    virObjectUnref(lxc_driver->domains);
1639
    virDomainEventStateFree(lxc_driver->domainEventState);
1640

1641
    virObjectUnref(lxc_driver->closeCallbacks);
1642

1643 1644
    virSysinfoDefFree(lxc_driver->hostsysinfo);

G
Guido Günther 已提交
1645
    virObjectUnref(lxc_driver->activeUsbHostdevs);
1646
    virObjectUnref(lxc_driver->caps);
1647
    virObjectUnref(lxc_driver->securityManager);
1648
    virObjectUnref(lxc_driver->xmlopt);
1649
    virObjectUnref(lxc_driver->config);
1650
    virMutexDestroy(&lxc_driver->lock);
1651
    VIR_FREE(lxc_driver);
1652 1653 1654

    return 0;
}
D
Daniel Veillard 已提交
1655 1656


1657
static int lxcConnectGetVersion(virConnectPtr conn, unsigned long *version)
D
Dan Smith 已提交
1658 1659 1660
{
    struct utsname ver;

1661
    uname(&ver);
D
Dan Smith 已提交
1662

1663 1664 1665
    if (virConnectGetVersionEnsureACL(conn) < 0)
        return -1;

1666
    if (virParseVersionString(ver.release, version, true) < 0) {
1667
        virReportError(VIR_ERR_INTERNAL_ERROR, _("Unknown release: %s"), ver.release);
D
Dan Smith 已提交
1668 1669 1670 1671 1672
        return -1;
    }

    return 0;
}
1673

1674

1675
static char *lxcConnectGetHostname(virConnectPtr conn)
1676
{
1677 1678 1679
    if (virConnectGetHostnameEnsureACL(conn) < 0)
        return NULL;

1680 1681 1682 1683 1684
    return virGetHostname();
}



1685 1686 1687 1688 1689 1690 1691 1692 1693 1694 1695 1696 1697 1698 1699 1700 1701 1702 1703 1704 1705 1706 1707 1708 1709 1710 1711 1712 1713 1714 1715 1716 1717
/*
 * check whether the host supports CFS bandwidth
 *
 * Return 1 when CFS bandwidth is supported, 0 when CFS bandwidth is not
 * supported, -1 on error.
 */
static int lxcGetCpuBWStatus(virCgroupPtr cgroup)
{
    char *cfs_period_path = NULL;
    int ret = -1;

    if (!cgroup)
        return 0;

    if (virCgroupPathOfController(cgroup, VIR_CGROUP_CONTROLLER_CPU,
                                  "cpu.cfs_period_us", &cfs_period_path) < 0) {
        VIR_INFO("cannot get the path of cgroup CPU controller");
        ret = 0;
        goto cleanup;
    }

    if (access(cfs_period_path, F_OK) < 0) {
        ret = 0;
    } else {
        ret = 1;
    }

cleanup:
    VIR_FREE(cfs_period_path);
    return ret;
}


1718 1719
static char *lxcDomainGetSchedulerType(virDomainPtr dom,
                                       int *nparams)
1720
{
1721 1722
    char *ret = NULL;
    int rc;
1723 1724
    virDomainObjPtr vm;
    virLXCDomainObjPrivatePtr priv;
1725

M
Michal Privoznik 已提交
1726
    if (!(vm = lxcDomObjFromDomain(dom)))
1727
        goto cleanup;
M
Michal Privoznik 已提交
1728

1729 1730
    priv = vm->privateData;

1731 1732 1733
    if (virDomainGetSchedulerTypeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1734 1735 1736 1737 1738 1739 1740 1741
    /* Domain not running, thus no cgroups - return defaults */
    if (!virDomainObjIsActive(vm)) {
        if (nparams)
            *nparams = 3;
        ignore_value(VIR_STRDUP(ret, "posix"));
        goto cleanup;
    }

1742
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
1743 1744
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
1745 1746
        goto cleanup;
    }
1747

1748
    if (nparams) {
1749
        rc = lxcGetCpuBWStatus(priv->cgroup);
1750 1751 1752 1753 1754 1755 1756
        if (rc < 0)
            goto cleanup;
        else if (rc == 0)
            *nparams = 1;
        else
            *nparams = 3;
    }
1757

1758
    ignore_value(VIR_STRDUP(ret, "posix"));
1759

1760
cleanup:
1761 1762
    if (vm)
        virObjectUnlock(vm);
1763 1764 1765 1766 1767 1768 1769 1770
    return ret;
}


static int
lxcGetVcpuBWLive(virCgroupPtr cgroup, unsigned long long *period,
                 long long *quota)
{
1771
    if (virCgroupGetCpuCfsPeriod(cgroup, period) < 0)
1772 1773
        return -1;

1774
    if (virCgroupGetCpuCfsQuota(cgroup, quota) < 0)
1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789 1790
        return -1;

    return 0;
}


static int lxcSetVcpuBWLive(virCgroupPtr cgroup, unsigned long long period,
                            long long quota)
{
    unsigned long long old_period;

    if (period == 0 && quota == 0)
        return 0;

    if (period) {
        /* get old period, and we can rollback if set quota failed */
1791
        if (virCgroupGetCpuCfsPeriod(cgroup, &old_period) < 0)
1792 1793
            return -1;

1794
        if (virCgroupSetCpuCfsPeriod(cgroup, period) < 0)
1795 1796 1797 1798
            return -1;
    }

    if (quota) {
1799 1800
        if (virCgroupSetCpuCfsQuota(cgroup, quota) < 0)
            goto error;
1801 1802 1803 1804
    }

    return 0;

1805
error:
1806
    if (period) {
1807 1808 1809 1810 1811 1812
        virErrorPtr saved = virSaveLastError();
        virCgroupSetCpuCfsPeriod(cgroup, old_period);
        if (saved) {
            virSetError(saved);
            virFreeError(saved);
        }
1813 1814 1815
    }

    return -1;
1816 1817
}

1818

1819
static int
1820 1821 1822 1823
lxcDomainSetSchedulerParametersFlags(virDomainPtr dom,
                                     virTypedParameterPtr params,
                                     int nparams,
                                     unsigned int flags)
1824
{
1825
    virLXCDriverPtr driver = dom->conn->privateData;
1826
    virCapsPtr caps = NULL;
1827
    size_t i;
1828
    virDomainObjPtr vm = NULL;
1829
    virDomainDefPtr vmdef = NULL;
1830
    int ret = -1;
1831
    int rc;
1832
    virLXCDomainObjPrivatePtr priv;
1833
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1834

1835 1836
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
1837 1838 1839 1840 1841 1842 1843 1844
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                               VIR_TYPED_PARAM_LLONG,
                               NULL) < 0)
1845
        return -1;
1846

M
Michal Privoznik 已提交
1847
    if (!(vm = lxcDomObjFromDomain(dom)))
1848
        goto cleanup;
M
Michal Privoznik 已提交
1849

1850
    priv = vm->privateData;
1851

1852 1853 1854
    if (virDomainSetSchedulerParametersFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

1855 1856 1857 1858
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
1859
                                        vm, &flags, &vmdef) < 0)
E
Eric Blake 已提交
1860
        goto cleanup;
1861 1862 1863

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
1864
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
1865 1866 1867 1868 1869
        if (!vmdef)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1870
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
1871 1872
            virReportError(VIR_ERR_OPERATION_INVALID,
                           "%s", _("cgroup CPU controller is not mounted"));
1873 1874 1875
            goto cleanup;
        }
    }
1876 1877

    for (i = 0; i < nparams; i++) {
1878
        virTypedParameterPtr param = &params[i];
1879

1880 1881
        if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_CPU_SHARES)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1882
                if (virCgroupSetCpuShares(priv->cgroup, params[i].value.ul) < 0)
1883 1884 1885 1886 1887 1888 1889 1890 1891 1892
                    goto cleanup;

                vm->def->cputune.shares = params[i].value.ul;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.shares = params[i].value.ul;
            }
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_PERIOD)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1893
                rc = lxcSetVcpuBWLive(priv->cgroup, params[i].value.ul, 0);
1894 1895 1896 1897 1898 1899 1900 1901 1902 1903 1904 1905
                if (rc != 0)
                    goto cleanup;

                if (params[i].value.ul)
                    vm->def->cputune.period = params[i].value.ul;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.period = params[i].value.ul;
            }
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_QUOTA)) {
            if (flags & VIR_DOMAIN_AFFECT_LIVE) {
1906
                rc = lxcSetVcpuBWLive(priv->cgroup, 0, params[i].value.l);
1907 1908 1909 1910 1911 1912 1913 1914 1915 1916
                if (rc != 0)
                    goto cleanup;

                if (params[i].value.l)
                    vm->def->cputune.quota = params[i].value.l;
            }

            if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
                vmdef->cputune.quota = params[i].value.l;
            }
1917
        }
1918
    }
1919

1920
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0)
1921
        goto cleanup;
1922

1923 1924

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
1925
        rc = virDomainSaveConfig(cfg->configDir, vmdef);
1926
        if (rc < 0)
1927
            goto cleanup;
1928

1929
        virDomainObjAssignDef(vm, vmdef, false, NULL);
1930
        vmdef = NULL;
1931
    }
1932

1933
    ret = 0;
1934

1935
cleanup:
1936
    virDomainDefFree(vmdef);
1937
    if (vm)
1938
        virObjectUnlock(vm);
1939
    virObjectUnref(caps);
1940
    virObjectUnref(cfg);
1941
    return ret;
1942 1943
}

1944
static int
1945 1946 1947
lxcDomainSetSchedulerParameters(virDomainPtr domain,
                                virTypedParameterPtr params,
                                int nparams)
1948
{
1949
    return lxcDomainSetSchedulerParametersFlags(domain, params, nparams, 0);
1950 1951 1952
}

static int
1953 1954 1955 1956
lxcDomainGetSchedulerParametersFlags(virDomainPtr dom,
                                     virTypedParameterPtr params,
                                     int *nparams,
                                     unsigned int flags)
1957
{
1958
    virLXCDriverPtr driver = dom->conn->privateData;
1959
    virCapsPtr caps = NULL;
1960
    virDomainObjPtr vm = NULL;
E
Eric Blake 已提交
1961
    virDomainDefPtr persistentDef;
1962 1963 1964
    unsigned long long shares = 0;
    unsigned long long period = 0;
    long long quota = 0;
1965
    int ret = -1;
1966 1967 1968
    int rc;
    bool cpu_bw_status = false;
    int saved_nparams = 0;
1969
    virLXCDomainObjPrivatePtr priv;
1970

1971 1972
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
1973

M
Michal Privoznik 已提交
1974
    if (!(vm = lxcDomObjFromDomain(dom)))
1975
        goto cleanup;
M
Michal Privoznik 已提交
1976

1977 1978
    priv = vm->privateData;

1979 1980 1981
    if (virDomainGetSchedulerParametersFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1982 1983 1984 1985 1986 1987
    if (*nparams > 1) {
        rc = lxcGetCpuBWStatus(priv->cgroup);
        if (rc < 0)
            goto cleanup;
        cpu_bw_status = !!rc;
    }
1988

1989 1990 1991 1992
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
1993
                                        vm, &flags, &persistentDef) < 0)
E
Eric Blake 已提交
1994
        goto cleanup;
1995 1996

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
E
Eric Blake 已提交
1997
        shares = persistentDef->cputune.shares;
1998
        if (*nparams > 1) {
E
Eric Blake 已提交
1999 2000
            period = persistentDef->cputune.period;
            quota = persistentDef->cputune.quota;
2001
            cpu_bw_status = true; /* Allow copy of data to params[] */
2002 2003 2004 2005
        }
        goto out;
    }

2006
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
2007 2008
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
2009
        goto cleanup;
2010 2011
    }

2012
    if (virCgroupGetCpuShares(priv->cgroup, &shares) < 0)
2013
        goto cleanup;
2014 2015

    if (*nparams > 1 && cpu_bw_status) {
2016
        rc = lxcGetVcpuBWLive(priv->cgroup, &period, &quota);
2017 2018 2019 2020
        if (rc != 0)
            goto cleanup;
    }
out:
2021 2022
    if (virTypedParameterAssign(&params[0], VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                                VIR_TYPED_PARAM_ULLONG, shares) < 0)
C
Chris Lalancette 已提交
2023
        goto cleanup;
2024 2025 2026 2027
    saved_nparams++;

    if (cpu_bw_status) {
        if (*nparams > saved_nparams) {
2028 2029 2030
            if (virTypedParameterAssign(&params[1],
                                        VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                                        VIR_TYPED_PARAM_ULLONG, period) < 0)
2031 2032 2033 2034 2035
                goto cleanup;
            saved_nparams++;
        }

        if (*nparams > saved_nparams) {
2036 2037 2038
            if (virTypedParameterAssign(&params[2],
                                        VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                                        VIR_TYPED_PARAM_LLONG, quota) < 0)
2039 2040 2041 2042 2043 2044 2045
                goto cleanup;
            saved_nparams++;
        }
    }

    *nparams = saved_nparams;

2046
    ret = 0;
2047

2048
cleanup:
2049
    if (vm)
2050
        virObjectUnlock(vm);
2051
    virObjectUnref(caps);
2052
    return ret;
2053 2054
}

2055
static int
2056 2057 2058
lxcDomainGetSchedulerParameters(virDomainPtr domain,
                                virTypedParameterPtr params,
                                int *nparams)
2059
{
2060
    return lxcDomainGetSchedulerParametersFlags(domain, params, nparams, 0);
2061 2062
}

2063

2064 2065 2066 2067 2068
static int
lxcDomainSetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int nparams,
                            unsigned int flags)
2069
{
2070
    virLXCDriverPtr driver = dom->conn->privateData;
2071
    virCapsPtr caps = NULL;
2072
    size_t i;
2073 2074 2075
    virDomainObjPtr vm = NULL;
    virDomainDefPtr persistentDef = NULL;
    int ret = -1;
2076
    virLXCDomainObjPrivatePtr priv;
2077
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
2078 2079 2080

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
2081 2082 2083 2084
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_BLKIO_WEIGHT,
                               VIR_TYPED_PARAM_UINT,
                               NULL) < 0)
2085 2086
        return -1;

M
Michal Privoznik 已提交
2087
    if (!(vm = lxcDomObjFromDomain(dom)))
2088
        goto cleanup;
M
Michal Privoznik 已提交
2089

2090
    priv = vm->privateData;
2091

2092 2093 2094
    if (virDomainSetBlkioParametersEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

2095 2096 2097 2098
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
2099
                                        vm, &flags, &persistentDef) < 0)
E
Eric Blake 已提交
2100
        goto cleanup;
2101 2102

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
2103
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
2104 2105
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2106 2107 2108 2109 2110 2111 2112 2113
            goto cleanup;
        }

        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
                if (params[i].value.ui > 1000 || params[i].value.ui < 100) {
2114 2115
                    virReportError(VIR_ERR_INVALID_ARG, "%s",
                                   _("out of blkio weight range."));
E
Eric Blake 已提交
2116
                    goto cleanup;
2117 2118
                }

2119
                if (virCgroupSetBlkioWeight(priv->cgroup, params[i].value.ui) < 0)
E
Eric Blake 已提交
2120
                    goto cleanup;
2121 2122
            }
        }
E
Eric Blake 已提交
2123 2124
    }
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
2125 2126 2127 2128 2129 2130 2131 2132
        /* Clang can't see that if we get here, persistentDef was set.  */
        sa_assert(persistentDef);

        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
                if (params[i].value.ui > 1000 || params[i].value.ui < 100) {
2133 2134
                    virReportError(VIR_ERR_INVALID_ARG, "%s",
                                   _("out of blkio weight range."));
E
Eric Blake 已提交
2135
                    goto cleanup;
2136 2137 2138 2139 2140 2141
                }

                persistentDef->blkio.weight = params[i].value.ui;
            }
        }

2142
        if (virDomainSaveConfig(cfg->configDir, persistentDef) < 0)
E
Eric Blake 已提交
2143
            goto cleanup;
2144 2145
    }

E
Eric Blake 已提交
2146
    ret = 0;
2147 2148
cleanup:
    if (vm)
2149
        virObjectUnlock(vm);
2150
    virObjectUnref(caps);
2151
    virObjectUnref(cfg);
2152 2153 2154 2155 2156
    return ret;
}


#define LXC_NB_BLKIO_PARAM  1
2157 2158 2159 2160 2161
static int
lxcDomainGetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int *nparams,
                            unsigned int flags)
2162
{
2163
    virLXCDriverPtr driver = dom->conn->privateData;
2164
    virCapsPtr caps = NULL;
2165
    size_t i;
2166 2167 2168 2169
    virDomainObjPtr vm = NULL;
    virDomainDefPtr persistentDef = NULL;
    unsigned int val;
    int ret = -1;
2170
    virLXCDomainObjPrivatePtr priv;
2171 2172 2173 2174

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

M
Michal Privoznik 已提交
2175
    if (!(vm = lxcDomObjFromDomain(dom)))
2176
        goto cleanup;
M
Michal Privoznik 已提交
2177

2178
    priv = vm->privateData;
2179

2180 2181 2182
    if (virDomainGetBlkioParametersEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2183 2184 2185 2186 2187 2188 2189
    if ((*nparams) == 0) {
        /* Current number of blkio parameters supported by cgroups */
        *nparams = LXC_NB_BLKIO_PARAM;
        ret = 0;
        goto cleanup;
    }

2190 2191 2192 2193
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (virDomainLiveConfigHelperMethod(caps, driver->xmlopt,
2194
                                        vm, &flags, &persistentDef) < 0)
E
Eric Blake 已提交
2195
        goto cleanup;
2196 2197

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
2198
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
2199 2200
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2201 2202 2203 2204 2205 2206 2207 2208 2209
            goto cleanup;
        }

        for (i = 0; i < *nparams && i < LXC_NB_BLKIO_PARAM; i++) {
            virTypedParameterPtr param = &params[i];
            val = 0;

            switch (i) {
            case 0: /* fill blkio weight here */
2210
                if (virCgroupGetBlkioWeight(priv->cgroup, &val) < 0)
2211
                    goto cleanup;
2212 2213
                if (virTypedParameterAssign(param, VIR_DOMAIN_BLKIO_WEIGHT,
                                            VIR_TYPED_PARAM_UINT, val) < 0)
2214 2215 2216
                    goto cleanup;
                break;

2217
            /* coverity[dead_error_begin] */
2218 2219 2220 2221 2222 2223 2224 2225 2226 2227 2228
            default:
                break;
                /* should not hit here */
            }
        }
    } else if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        for (i = 0; i < *nparams && i < LXC_NB_BLKIO_PARAM; i++) {
            virTypedParameterPtr param = &params[i];

            switch (i) {
            case 0: /* fill blkio weight here */
2229 2230 2231
                if (virTypedParameterAssign(param, VIR_DOMAIN_BLKIO_WEIGHT,
                                            VIR_TYPED_PARAM_UINT,
                                            persistentDef->blkio.weight) < 0)
2232 2233 2234
                    goto cleanup;
                break;

2235
            /* coverity[dead_error_begin] */
2236 2237 2238 2239 2240 2241 2242 2243 2244 2245 2246 2247 2248
            default:
                break;
                /* should not hit here */
            }
        }
    }

    if (LXC_NB_BLKIO_PARAM < *nparams)
        *nparams = LXC_NB_BLKIO_PARAM;
    ret = 0;

cleanup:
    if (vm)
2249
        virObjectUnlock(vm);
2250
    virObjectUnref(caps);
2251 2252 2253 2254
    return ret;
}


2255 2256 2257 2258 2259 2260 2261
#ifdef __linux__
static int
lxcDomainInterfaceStats(virDomainPtr dom,
                        const char *path,
                        struct _virDomainInterfaceStats *stats)
{
    virDomainObjPtr vm;
2262
    size_t i;
2263 2264
    int ret = -1;

M
Michal Privoznik 已提交
2265
    if (!(vm = lxcDomObjFromDomain(dom)))
2266 2267
        goto cleanup;

2268 2269 2270
    if (virDomainInterfaceStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2271
    if (!virDomainObjIsActive(vm)) {
2272 2273
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
2274 2275 2276 2277
        goto cleanup;
    }

    /* Check the path is one of the domain's network interfaces. */
2278
    for (i = 0; i < vm->def->nnets; i++) {
2279 2280 2281 2282 2283 2284 2285 2286
        if (vm->def->nets[i]->ifname &&
            STREQ(vm->def->nets[i]->ifname, path)) {
            ret = 0;
            break;
        }
    }

    if (ret == 0)
2287
        ret = linuxDomainInterfaceStats(path, stats);
2288
    else
2289 2290
        virReportError(VIR_ERR_INVALID_ARG,
                       _("Invalid path, '%s' is not a known interface"), path);
2291 2292 2293

cleanup:
    if (vm)
2294
        virObjectUnlock(vm);
2295 2296 2297 2298 2299 2300 2301
    return ret;
}
#else
static int
lxcDomainInterfaceStats(virDomainPtr dom,
                        const char *path ATTRIBUTE_UNUSED,
                        struct _virDomainInterfaceStats *stats ATTRIBUTE_UNUSED)
A
Alex Jia 已提交
2302
{
2303
    virReportError(VIR_ERR_NO_SUPPORT, "%s", __FUNCTION__);
2304 2305 2306 2307
    return -1;
}
#endif

2308 2309 2310 2311 2312
static int lxcDomainGetAutostart(virDomainPtr dom,
                                   int *autostart) {
    virDomainObjPtr vm;
    int ret = -1;

M
Michal Privoznik 已提交
2313
    if (!(vm = lxcDomObjFromDomain(dom)))
2314 2315
        goto cleanup;

2316 2317 2318
    if (virDomainGetAutostartEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2319 2320 2321 2322 2323
    *autostart = vm->autostart;
    ret = 0;

cleanup:
    if (vm)
2324
        virObjectUnlock(vm);
2325 2326 2327 2328
    return ret;
}

static int lxcDomainSetAutostart(virDomainPtr dom,
2329 2330
                                   int autostart)
{
2331
    virLXCDriverPtr driver = dom->conn->privateData;
2332 2333 2334
    virDomainObjPtr vm;
    char *configFile = NULL, *autostartLink = NULL;
    int ret = -1;
2335
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
2336

M
Michal Privoznik 已提交
2337
    if (!(vm = lxcDomObjFromDomain(dom)))
2338 2339
        goto cleanup;

2340 2341 2342
    if (virDomainSetAutostartEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2343
    if (!vm->persistent) {
2344 2345
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot set autostart for transient domain"));
2346 2347 2348 2349 2350
        goto cleanup;
    }

    autostart = (autostart != 0);

2351 2352 2353 2354
    if (vm->autostart == autostart) {
        ret = 0;
        goto cleanup;
    }
2355

2356
    configFile = virDomainConfigFile(cfg->configDir,
2357 2358 2359
                                     vm->def->name);
    if (configFile == NULL)
        goto cleanup;
2360
    autostartLink = virDomainConfigFile(cfg->autostartDir,
2361 2362 2363
                                        vm->def->name);
    if (autostartLink == NULL)
        goto cleanup;
2364

2365
    if (autostart) {
2366
        if (virFileMakePath(cfg->autostartDir) < 0) {
2367
            virReportSystemError(errno,
2368
                                 _("Cannot create autostart directory %s"),
2369
                                 cfg->autostartDir);
2370
            goto cleanup;
2371 2372
        }

2373
        if (symlink(configFile, autostartLink) < 0) {
2374
            virReportSystemError(errno,
2375 2376 2377 2378 2379 2380
                                 _("Failed to create symlink '%s to '%s'"),
                                 autostartLink, configFile);
            goto cleanup;
        }
    } else {
        if (unlink(autostartLink) < 0 && errno != ENOENT && errno != ENOTDIR) {
2381
            virReportSystemError(errno,
2382 2383 2384 2385
                                 _("Failed to delete symlink '%s'"),
                                 autostartLink);
            goto cleanup;
        }
2386
    }
2387 2388

    vm->autostart = autostart;
2389 2390 2391 2392 2393 2394
    ret = 0;

cleanup:
    VIR_FREE(configFile);
    VIR_FREE(autostartLink);
    if (vm)
2395
        virObjectUnlock(vm);
2396
    virObjectUnref(cfg);
2397 2398 2399
    return ret;
}

2400
static int lxcFreezeContainer(virDomainObjPtr vm)
R
Ryota Ozaki 已提交
2401 2402 2403 2404 2405 2406 2407
{
    int timeout = 1000; /* In milliseconds */
    int check_interval = 1; /* In milliseconds */
    int exp = 10;
    int waited_time = 0;
    int ret = -1;
    char *state = NULL;
2408
    virLXCDomainObjPrivatePtr priv = vm->privateData;
2409

R
Ryota Ozaki 已提交
2410 2411 2412 2413 2414 2415 2416 2417 2418
    while (waited_time < timeout) {
        int r;
        /*
         * Writing "FROZEN" to the "freezer.state" freezes the group,
         * i.e., the container, temporarily transiting "FREEZING" state.
         * Once the freezing is completed, the state of the group transits
         * to "FROZEN".
         * (see linux-2.6/Documentation/cgroups/freezer-subsystem.txt)
         */
2419
        r = virCgroupSetFreezerState(priv->cgroup, "FROZEN");
R
Ryota Ozaki 已提交
2420 2421 2422 2423 2424 2425 2426 2427 2428 2429 2430

        /*
         * Returning EBUSY explicitly indicates that the group is
         * being freezed but incomplete and other errors are true
         * errors.
         */
        if (r < 0 && r != -EBUSY) {
            VIR_DEBUG("Writing freezer.state failed with errno: %d", r);
            goto error;
        }
        if (r == -EBUSY)
2431
            VIR_DEBUG("Writing freezer.state gets EBUSY");
R
Ryota Ozaki 已提交
2432 2433 2434 2435 2436 2437 2438 2439 2440 2441 2442 2443 2444 2445

        /*
         * Unfortunately, returning 0 (success) is likely to happen
         * even when the freezing has not been completed. Sometimes
         * the state of the group remains "FREEZING" like when
         * returning -EBUSY and even worse may never transit to
         * "FROZEN" even if writing "FROZEN" again.
         *
         * So we don't trust the return value anyway and always
         * decide that the freezing has been complete only with
         * the state actually transit to "FROZEN".
         */
        usleep(check_interval * 1000);

2446
        r = virCgroupGetFreezerState(priv->cgroup, &state);
R
Ryota Ozaki 已提交
2447 2448 2449 2450 2451 2452 2453 2454 2455 2456 2457 2458 2459 2460 2461 2462 2463 2464 2465 2466 2467 2468 2469 2470

        if (r < 0) {
            VIR_DEBUG("Reading freezer.state failed with errno: %d", r);
            goto error;
        }
        VIR_DEBUG("Read freezer.state: %s", state);

        if (STREQ(state, "FROZEN")) {
            ret = 0;
            goto cleanup;
        }

        waited_time += check_interval;
        /*
         * Increasing check_interval exponentially starting with
         * small initial value treats nicely two cases; One is
         * a container is under no load and waiting for long period
         * makes no sense. The other is under heavy load. The container
         * may stay longer time in FREEZING or never transit to FROZEN.
         * In that case, eager polling will just waste CPU time.
         */
        check_interval *= exp;
        VIR_FREE(state);
    }
2471
    VIR_DEBUG("lxcFreezeContainer timeout");
R
Ryota Ozaki 已提交
2472 2473 2474 2475 2476 2477
error:
    /*
     * If timeout or an error on reading the state occurs,
     * activate the group again and return an error.
     * This is likely to fall the group back again gracefully.
     */
2478
    virCgroupSetFreezerState(priv->cgroup, "THAWED");
R
Ryota Ozaki 已提交
2479 2480 2481 2482 2483 2484 2485 2486 2487
    ret = -1;

cleanup:
    VIR_FREE(state);
    return ret;
}

static int lxcDomainSuspend(virDomainPtr dom)
{
2488
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
2489 2490 2491
    virDomainObjPtr vm;
    virDomainEventPtr event = NULL;
    int ret = -1;
2492
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
2493

M
Michal Privoznik 已提交
2494
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
2495 2496
        goto cleanup;

2497 2498 2499
    if (virDomainSuspendEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

D
Daniel P. Berrange 已提交
2500
    if (!virDomainObjIsActive(vm)) {
2501 2502
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
R
Ryota Ozaki 已提交
2503 2504 2505
        goto cleanup;
    }

J
Jiri Denemark 已提交
2506
    if (virDomainObjGetState(vm, NULL) != VIR_DOMAIN_PAUSED) {
2507
        if (lxcFreezeContainer(vm) < 0) {
2508 2509
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Suspend operation failed"));
R
Ryota Ozaki 已提交
2510 2511
            goto cleanup;
        }
J
Jiri Denemark 已提交
2512
        virDomainObjSetState(vm, VIR_DOMAIN_PAUSED, VIR_DOMAIN_PAUSED_USER);
R
Ryota Ozaki 已提交
2513 2514 2515 2516 2517 2518

        event = virDomainEventNewFromObj(vm,
                                         VIR_DOMAIN_EVENT_SUSPENDED,
                                         VIR_DOMAIN_EVENT_SUSPENDED_PAUSED);
    }

2519
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0)
R
Ryota Ozaki 已提交
2520 2521 2522 2523 2524
        goto cleanup;
    ret = 0;

cleanup:
    if (event)
2525
        virDomainEventStateQueue(driver->domainEventState, event);
R
Ryota Ozaki 已提交
2526
    if (vm)
2527
        virObjectUnlock(vm);
2528
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
2529 2530 2531 2532 2533
    return ret;
}

static int lxcDomainResume(virDomainPtr dom)
{
2534
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
2535 2536 2537
    virDomainObjPtr vm;
    virDomainEventPtr event = NULL;
    int ret = -1;
2538
    virLXCDomainObjPrivatePtr priv;
2539
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
2540

M
Michal Privoznik 已提交
2541
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
2542 2543
        goto cleanup;

2544 2545
    priv = vm->privateData;

2546 2547 2548
    if (virDomainResumeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

D
Daniel P. Berrange 已提交
2549
    if (!virDomainObjIsActive(vm)) {
2550 2551
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
R
Ryota Ozaki 已提交
2552 2553 2554
        goto cleanup;
    }

J
Jiri Denemark 已提交
2555
    if (virDomainObjGetState(vm, NULL) == VIR_DOMAIN_PAUSED) {
2556
        if (virCgroupSetFreezerState(priv->cgroup, "THAWED") < 0) {
2557 2558
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Resume operation failed"));
R
Ryota Ozaki 已提交
2559 2560
            goto cleanup;
        }
J
Jiri Denemark 已提交
2561 2562
        virDomainObjSetState(vm, VIR_DOMAIN_RUNNING,
                             VIR_DOMAIN_RUNNING_UNPAUSED);
R
Ryota Ozaki 已提交
2563 2564 2565 2566 2567 2568

        event = virDomainEventNewFromObj(vm,
                                         VIR_DOMAIN_EVENT_RESUMED,
                                         VIR_DOMAIN_EVENT_RESUMED_UNPAUSED);
    }

2569
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0)
R
Ryota Ozaki 已提交
2570 2571 2572 2573 2574
        goto cleanup;
    ret = 0;

cleanup:
    if (event)
2575
        virDomainEventStateQueue(driver->domainEventState, event);
R
Ryota Ozaki 已提交
2576
    if (vm)
2577
        virObjectUnlock(vm);
2578
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
2579 2580 2581
    return ret;
}

2582 2583
static int
lxcDomainOpenConsole(virDomainPtr dom,
2584
                      const char *dev_name,
2585 2586 2587 2588 2589 2590
                      virStreamPtr st,
                      unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    int ret = -1;
    virDomainChrDefPtr chr = NULL;
2591
    size_t i;
2592 2593 2594

    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
2595
    if (!(vm = lxcDomObjFromDomain(dom)))
2596 2597
        goto cleanup;

2598 2599 2600
    if (virDomainOpenConsoleEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2601
    if (!virDomainObjIsActive(vm)) {
2602 2603
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
2604 2605 2606
        goto cleanup;
    }

2607
    if (dev_name) {
2608
        for (i = 0; i < vm->def->nconsoles; i++) {
2609 2610 2611 2612 2613 2614
            if (vm->def->consoles[i]->info.alias &&
                STREQ(vm->def->consoles[i]->info.alias, dev_name)) {
                chr = vm->def->consoles[i];
                break;
            }
        }
2615
    } else {
2616 2617
        if (vm->def->nconsoles)
            chr = vm->def->consoles[0];
2618 2619 2620 2621 2622
        else if (vm->def->nserials)
            chr = vm->def->serials[0];
    }

    if (!chr) {
2623 2624 2625
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot find console device '%s'"),
                       dev_name ? dev_name : _("default"));
2626 2627 2628
        goto cleanup;
    }

2629
    if (chr->source.type != VIR_DOMAIN_CHR_TYPE_PTY) {
2630 2631
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("character device %s is not using a PTY"), dev_name);
2632 2633 2634
        goto cleanup;
    }

2635
    if (virFDStreamOpenFile(st, chr->source.data.file.path,
E
Eric Blake 已提交
2636
                            0, 0, O_RDWR) < 0)
2637 2638 2639 2640 2641
        goto cleanup;

    ret = 0;
cleanup:
    if (vm)
2642
        virObjectUnlock(vm);
2643 2644 2645
    return ret;
}

2646 2647 2648 2649 2650 2651 2652 2653 2654 2655 2656 2657 2658 2659 2660 2661 2662 2663 2664 2665 2666

static int
lxcDomainSendProcessSignal(virDomainPtr dom,
                           long long pid_value,
                           unsigned int signum,
                           unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    virLXCDomainObjPrivatePtr priv;
    pid_t victim;
    int ret = -1;

    virCheckFlags(0, -1);

    if (signum >= VIR_DOMAIN_PROCESS_SIGNAL_LAST) {
        virReportError(VIR_ERR_INVALID_ARG,
                       _("signum value %d is out of range"),
                       signum);
        return -1;
    }

M
Michal Privoznik 已提交
2667
    if (!(vm = lxcDomObjFromDomain(dom)))
2668
        goto cleanup;
M
Michal Privoznik 已提交
2669

2670 2671
    priv = vm->privateData;

2672 2673 2674
    if (virDomainSendProcessSignalEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2675 2676 2677 2678 2679 2680 2681 2682 2683 2684 2685 2686 2687 2688 2689 2690 2691 2692 2693 2694 2695 2696 2697 2698 2699 2700 2701 2702 2703 2704 2705 2706 2707 2708 2709 2710 2711 2712 2713 2714
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
        goto cleanup;
    }

    /*
     * XXX if the kernel has /proc/$PID/ns/pid we can
     * switch into container namespace & that way be
     * able to kill any PID. Alternatively if there
     * is a way to find a mapping of guest<->host PIDs
     * we can kill that way.
     */
    if (pid_value != 1) {
        virReportError(VIR_ERR_ARGUMENT_UNSUPPORTED, "%s",
                       _("Only the init process may be killed"));
        goto cleanup;
    }

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
        goto cleanup;
    }
    victim = priv->initpid;

    /* We're relying on fact libvirt header signal numbers
     * are taken from Linux, to avoid mapping
     */
    if (kill(victim, signum) < 0) {
        virReportSystemError(errno,
                             _("Unable to send %d signal to process %d"),
                             signum, victim);
        goto cleanup;
    }

    ret = 0;

cleanup:
    if (vm)
2715
        virObjectUnlock(vm);
2716 2717 2718 2719
    return ret;
}


2720
static int
2721 2722
lxcConnectListAllDomains(virConnectPtr conn,
                         virDomainPtr **domains,
2723 2724
                  unsigned int flags)
{
2725
    virLXCDriverPtr driver = conn->privateData;
2726 2727
    int ret = -1;

O
Osier Yang 已提交
2728
    virCheckFlags(VIR_CONNECT_LIST_DOMAINS_FILTERS_ALL, -1);
2729

2730 2731 2732
    if (virConnectListAllDomainsEnsureACL(conn) < 0)
        return -1;

2733 2734
    ret = virDomainObjListExport(driver->domains, conn, domains,
                                 virConnectListAllDomainsCheckACL, flags);
2735 2736 2737
    return ret;
}

2738

2739 2740 2741 2742 2743 2744 2745 2746
static int
lxcDomainShutdownFlags(virDomainPtr dom,
                       unsigned int flags)
{
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    char *vroot = NULL;
    int ret = -1;
2747
    int rc;
2748 2749 2750 2751

    virCheckFlags(VIR_DOMAIN_SHUTDOWN_INITCTL |
                  VIR_DOMAIN_SHUTDOWN_SIGNAL, -1);

M
Michal Privoznik 已提交
2752
    if (!(vm = lxcDomObjFromDomain(dom)))
2753 2754 2755 2756
        goto cleanup;

    priv = vm->privateData;

2757 2758 2759
    if (virDomainShutdownFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2760 2761 2762 2763 2764 2765 2766 2767 2768 2769 2770 2771 2772
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
2773
                    (unsigned long long)priv->initpid) < 0)
2774 2775
        goto cleanup;

2776 2777 2778 2779
    if (flags == 0 ||
        (flags & VIR_DOMAIN_SHUTDOWN_INITCTL)) {
        if ((rc = virInitctlSetRunLevel(VIR_INITCTL_RUNLEVEL_POWEROFF,
                                        vroot)) < 0) {
2780
            goto cleanup;
2781 2782 2783
        }
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
2784 2785 2786 2787
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
            goto cleanup;
        }
2788 2789
    } else {
        rc = 0;
2790
    }
2791 2792 2793 2794 2795 2796

    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_SHUTDOWN_SIGNAL))) {
        if (kill(priv->initpid, SIGTERM) < 0 &&
            errno != ESRCH) {
2797 2798 2799 2800 2801 2802 2803 2804 2805 2806 2807 2808
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
                                 (unsigned long long)priv->initpid);
            goto cleanup;
        }
    }

    ret = 0;

cleanup:
    VIR_FREE(vroot);
    if (vm)
2809
        virObjectUnlock(vm);
2810 2811 2812 2813 2814 2815 2816 2817 2818 2819 2820 2821 2822 2823 2824 2825 2826 2827 2828 2829 2830 2831
    return ret;
}

static int
lxcDomainShutdown(virDomainPtr dom)
{
    return lxcDomainShutdownFlags(dom, 0);
}

static int
lxcDomainReboot(virDomainPtr dom,
                unsigned int flags)
{
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    char *vroot = NULL;
    int ret = -1;
    int rc;

    virCheckFlags(VIR_DOMAIN_REBOOT_INITCTL |
                  VIR_DOMAIN_REBOOT_SIGNAL, -1);

M
Michal Privoznik 已提交
2832
    if (!(vm = lxcDomObjFromDomain(dom)))
2833 2834 2835 2836
        goto cleanup;

    priv = vm->privateData;

2837 2838 2839
    if (virDomainRebootEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2840 2841 2842 2843 2844 2845 2846 2847 2848 2849 2850 2851 2852
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
2853
                    (unsigned long long)priv->initpid) < 0)
2854 2855 2856 2857 2858 2859 2860 2861 2862 2863 2864 2865 2866 2867 2868 2869 2870 2871 2872 2873 2874 2875 2876 2877 2878 2879 2880 2881 2882 2883 2884 2885 2886 2887 2888
        goto cleanup;

    if (flags == 0 ||
        (flags & VIR_DOMAIN_REBOOT_INITCTL)) {
        if ((rc = virInitctlSetRunLevel(VIR_INITCTL_RUNLEVEL_REBOOT,
                                        vroot)) < 0) {
            goto cleanup;
        }
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
            goto cleanup;
        }
    } else {
        rc = 0;
    }

    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_REBOOT_SIGNAL))) {
        if (kill(priv->initpid, SIGHUP) < 0 &&
            errno != ESRCH) {
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
                                 (unsigned long long)priv->initpid);
            goto cleanup;
        }
    }

    ret = 0;

cleanup:
    VIR_FREE(vroot);
    if (vm)
2889
        virObjectUnlock(vm);
2890 2891 2892 2893
    return ret;
}


2894
static int
2895
lxcDomainAttachDeviceConfig(virDomainDefPtr vmdef,
2896 2897 2898
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
2899
    virDomainDiskDefPtr disk;
2900
    virDomainNetDefPtr net;
2901
    virDomainHostdevDefPtr hostdev;
2902 2903

    switch (dev->type) {
2904 2905 2906 2907 2908 2909 2910
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (virDomainDiskIndexByName(vmdef, disk->dst, true) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("target %s already exists."), disk->dst);
            return -1;
        }
2911
        if (virDomainDiskInsert(vmdef, disk))
2912 2913 2914 2915 2916 2917
            return -1;
        /* vmdef has the pointer. Generic codes for vmdef will do all jobs */
        dev->data.disk = NULL;
        ret = 0;
        break;

2918 2919
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
2920
        if (virDomainNetInsert(vmdef, net) < 0)
2921 2922 2923 2924 2925
            goto cleanup;
        dev->data.net = NULL;
        ret = 0;
        break;

2926 2927 2928 2929 2930 2931 2932
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        hostdev = dev->data.hostdev;
        if (virDomainHostdevFind(vmdef, hostdev, NULL) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device is already in the domain configuration"));
            return -1;
        }
2933
        if (virDomainHostdevInsert(vmdef, hostdev) < 0)
2934 2935 2936 2937 2938
            return -1;
        dev->data.hostdev = NULL;
        ret = 0;
        break;

2939 2940 2941 2942 2943 2944
    default:
         virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                        _("persistent attach of device is not supported"));
         break;
    }

2945
cleanup:
2946 2947 2948 2949 2950
    return ret;
}


static int
2951
lxcDomainUpdateDeviceConfig(virDomainDefPtr vmdef,
2952 2953 2954
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
2955 2956 2957
    virDomainNetDefPtr net;
    int idx;
    char mac[VIR_MAC_STRING_BUFLEN];
2958 2959

    switch (dev->type) {
2960 2961 2962 2963 2964 2965 2966 2967 2968 2969 2970 2971 2972 2973 2974 2975 2976 2977 2978 2979 2980 2981
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
        idx = virDomainNetFindIdx(vmdef, net);
        if (idx == -2) {
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("multiple devices matching mac address %s found"),
                           virMacAddrFormat(&net->mac, mac));
            goto cleanup;
        } else if (idx < 0) {
            virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                           _("no matching network device was found"));
            goto cleanup;
        }

        virDomainNetDefFree(vmdef->nets[idx]);

        vmdef->nets[idx] = net;
        dev->data.net = NULL;
        ret = 0;

        break;

2982 2983 2984 2985 2986 2987
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent update of device is not supported"));
        break;
    }

2988
cleanup:
2989 2990 2991 2992 2993
    return ret;
}


static int
2994
lxcDomainDetachDeviceConfig(virDomainDefPtr vmdef,
2995 2996 2997
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
2998
    virDomainDiskDefPtr disk, det_disk;
2999
    virDomainNetDefPtr net;
3000
    virDomainHostdevDefPtr hostdev, det_hostdev;
3001 3002
    int idx;
    char mac[VIR_MAC_STRING_BUFLEN];
3003 3004

    switch (dev->type) {
3005 3006 3007 3008 3009 3010 3011 3012 3013 3014 3015
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (!(det_disk = virDomainDiskRemoveByName(vmdef, disk->dst))) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("no target device %s"), disk->dst);
            return -1;
        }
        virDomainDiskDefFree(det_disk);
        ret = 0;
        break;

3016 3017 3018 3019 3020 3021 3022 3023 3024 3025 3026 3027 3028 3029 3030 3031 3032 3033
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
        idx = virDomainNetFindIdx(vmdef, net);
        if (idx == -2) {
            virReportError(VIR_ERR_OPERATION_FAILED,
                           _("multiple devices matching mac address %s found"),
                           virMacAddrFormat(&net->mac, mac));
            goto cleanup;
        } else if (idx < 0) {
            virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                           _("no matching network device was found"));
            goto cleanup;
        }
        /* this is guaranteed to succeed */
        virDomainNetDefFree(virDomainNetRemove(vmdef, idx));
        ret = 0;
        break;

3034 3035 3036 3037 3038 3039 3040 3041 3042 3043 3044 3045 3046
    case VIR_DOMAIN_DEVICE_HOSTDEV: {
        hostdev = dev->data.hostdev;
        if ((idx = virDomainHostdevFind(vmdef, hostdev, &det_hostdev)) < 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device not present in domain configuration"));
            return -1;
        }
        virDomainHostdevRemove(vmdef, idx);
        virDomainHostdevDefFree(det_hostdev);
        ret = 0;
        break;
    }

3047 3048 3049 3050 3051 3052
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent detach of device is not supported"));
        break;
    }

3053
cleanup:
3054 3055 3056 3057
    return ret;
}


3058 3059 3060 3061 3062 3063 3064 3065
static int
lxcDomainAttachDeviceDiskLive(virLXCDriverPtr driver,
                              virDomainObjPtr vm,
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = dev->data.disk;
    int ret = -1;
3066
    char *dst = NULL;
3067 3068 3069 3070 3071 3072 3073 3074 3075 3076 3077 3078 3079 3080 3081 3082 3083 3084 3085 3086 3087 3088 3089 3090 3091 3092 3093 3094 3095 3096 3097 3098 3099 3100 3101 3102 3103 3104 3105 3106 3107 3108
    struct stat sb;
    bool created = false;
    mode_t mode = 0;
    char *tmpsrc = def->src;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

    if (def->type != VIR_DOMAIN_DISK_TYPE_BLOCK) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk for non-block device"));
        goto cleanup;
    }
    if (def->src == NULL) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk without media"));
        goto cleanup;
    }

    if (virDomainDiskIndexByName(vm->def, def->dst, true) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("target %s already exists"), def->dst);
        goto cleanup;
    }

    if (stat(def->src, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"), def->src);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode) && !S_ISBLK(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Disk source %s must be a character/block device"),
                       def->src);
        goto cleanup;
    }

    if (virAsprintf(&dst, "/proc/%llu/root/dev/%s",
3109
                    (unsigned long long)priv->initpid, def->dst) < 0)
3110 3111
        goto cleanup;

3112
    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks+1) < 0)
3113 3114 3115 3116 3117 3118 3119 3120 3121 3122 3123 3124 3125 3126 3127 3128 3129 3130 3131 3132 3133 3134 3135
        goto cleanup;

    mode = 0700;
    if (S_ISCHR(sb.st_mode))
        mode |= S_IFCHR;
    else
        mode |= S_IFBLK;

    /* Yes, the device name we're creating may not
     * actually correspond to the major:minor number
     * we're using, but we've no other option at this
     * time. Just have to hope that containerized apps
     * don't get upset that the major:minor is different
     * to that normally implied by the device name
     */
    VIR_DEBUG("Creating dev %s (%d,%d) from %s",
              dst, major(sb.st_rdev), minor(sb.st_rdev), def->src);
    if (mknod(dst, mode, sb.st_rdev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             dst);
        goto cleanup;
    }
3136 3137 3138 3139

    if (lxcContainerChown(vm->def, dst) < 0)
        goto cleanup;

3140 3141 3142 3143 3144 3145 3146 3147 3148
    created = true;

    /* Labelling normally operates on src, but we need
     * to actally label the dst here, so hack the config */
    def->src = dst;
    if (virSecurityManagerSetImageLabel(driver->securityManager,
                                        vm->def, def) < 0)
        goto cleanup;

3149
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3150 3151 3152 3153 3154
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3155
    if (virCgroupAllowDevicePath(priv->cgroup, def->src,
3156 3157 3158 3159 3160 3161 3162 3163 3164 3165 3166 3167 3168 3169 3170 3171 3172 3173 3174 3175 3176 3177 3178
                                 (def->readonly ?
                                  VIR_CGROUP_DEVICE_READ :
                                  VIR_CGROUP_DEVICE_RW) |
                                 VIR_CGROUP_DEVICE_MKNOD) != 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot allow device %s for domain %s"),
                       def->src, vm->def->name);
        goto cleanup;
    }

    virDomainDiskInsertPreAlloced(vm->def, def);

    ret = 0;

cleanup:
    def->src = tmpsrc;
    virDomainAuditDisk(vm, NULL, def->src, "attach", ret == 0);
    if (dst && created && ret < 0)
        unlink(dst);
    return ret;
}


3179
/* XXX conn required for network -> bridge resolution */
3180
static int
3181 3182 3183 3184 3185 3186 3187 3188 3189 3190 3191 3192 3193 3194 3195 3196
lxcDomainAttachDeviceNetLive(virConnectPtr conn,
                             virDomainObjPtr vm,
                             virDomainNetDefPtr net)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    int ret = -1;
    int actualType;
    char *veth = NULL;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

    /* preallocate new slot for device */
3197
    if (VIR_REALLOC_N(vm->def->nets, vm->def->nnets+1) < 0)
3198 3199 3200 3201 3202 3203 3204 3205 3206 3207 3208 3209 3210 3211 3212 3213 3214 3215 3216 3217 3218 3219 3220 3221 3222 3223 3224 3225 3226 3227 3228 3229 3230 3231 3232 3233 3234 3235 3236 3237 3238 3239 3240 3241 3242 3243 3244 3245 3246 3247 3248 3249 3250 3251 3252 3253 3254 3255 3256 3257 3258 3259 3260 3261 3262 3263 3264 3265 3266 3267 3268 3269 3270 3271 3272 3273 3274 3275 3276 3277 3278 3279 3280 3281 3282 3283 3284 3285 3286 3287 3288 3289 3290 3291 3292 3293 3294 3295 3296 3297 3298 3299 3300 3301 3302 3303 3304 3305 3306 3307
        return -1;

    /* If appropriate, grab a physical device from the configured
     * network's pool of devices, or resolve bridge device name
     * to the one defined in the network definition.
     */
    if (networkAllocateActualDevice(net) < 0)
        return -1;

    actualType = virDomainNetGetActualType(net);

    switch (actualType) {
    case VIR_DOMAIN_NET_TYPE_BRIDGE: {
        const char *brname = virDomainNetGetActualBridgeName(net);
        if (!brname) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("No bridge name specified"));
            goto cleanup;
        }
        if (!(veth = virLXCProcessSetupInterfaceBridged(conn,
                                                        vm->def,
                                                        net,
                                                        brname)))
            goto cleanup;
    }   break;
    case VIR_DOMAIN_NET_TYPE_NETWORK: {
        virNetworkPtr network;
        char *brname = NULL;
        bool fail = false;
        int active;
        virErrorPtr errobj;

        if (!(network = virNetworkLookupByName(conn,
                                               net->data.network.name)))
            goto cleanup;

        active = virNetworkIsActive(network);
        if (active != 1) {
            fail = true;
            if (active == 0)
                virReportError(VIR_ERR_INTERNAL_ERROR,
                               _("Network '%s' is not active."),
                               net->data.network.name);
        }

        if (!fail) {
            brname = virNetworkGetBridgeName(network);
            if (brname == NULL)
                fail = true;
        }

        /* Make sure any above failure is preserved */
        errobj = virSaveLastError();
        virNetworkFree(network);
        virSetError(errobj);
        virFreeError(errobj);

        if (fail)
            goto cleanup;

        if (!(veth = virLXCProcessSetupInterfaceBridged(conn,
                                                        vm->def,
                                                        net,
                                                        brname))) {
            VIR_FREE(brname);
            goto cleanup;
        }
        VIR_FREE(brname);
    }   break;
    case VIR_DOMAIN_NET_TYPE_DIRECT: {
        if (!(veth = virLXCProcessSetupInterfaceDirect(conn,
                                                       vm->def,
                                                       net)))
            goto cleanup;
    }   break;
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Network device type is not supported"));
        goto cleanup;
    }

    if (virNetDevSetNamespace(veth, priv->initpid) < 0) {
        virDomainAuditNet(vm, NULL, net, "attach", false);
        goto cleanup;
    }

    virDomainAuditNet(vm, NULL, net, "attach", true);

    ret = 0;

cleanup:
    if (!ret) {
        vm->def->nets[vm->def->nnets++] = net;
    } else if (veth) {
        switch (actualType) {
        case VIR_DOMAIN_NET_TYPE_BRIDGE:
        case VIR_DOMAIN_NET_TYPE_NETWORK:
            ignore_value(virNetDevVethDelete(veth));
            break;

        case VIR_DOMAIN_NET_TYPE_DIRECT:
            ignore_value(virNetDevMacVLanDelete(veth));
            break;
        }
    }

    return ret;
}


3308 3309 3310 3311 3312 3313 3314 3315 3316 3317 3318 3319 3320 3321 3322
static int
lxcDomainAttachDeviceHostdevSubsysUSBLive(virLXCDriverPtr driver,
                                          virDomainObjPtr vm,
                                          virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    char *vroot = NULL;
    char *src = NULL;
    char *dstdir = NULL;
    char *dstfile = NULL;
    struct stat sb;
    mode_t mode;
    bool created = false;
3323
    virUSBDevicePtr usb = NULL;
3324 3325 3326 3327 3328 3329 3330 3331

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host USB device already exists"));
        return -1;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
3332
                    (unsigned long long)priv->initpid) < 0)
3333 3334 3335 3336
        goto cleanup;

    if (virAsprintf(&dstdir, "%s/dev/bus/%03d",
                    vroot,
3337
                    def->source.subsys.u.usb.bus) < 0)
3338 3339 3340 3341
        goto cleanup;

    if (virAsprintf(&dstfile, "%s/%03d",
                    dstdir,
3342
                    def->source.subsys.u.usb.device) < 0)
3343 3344 3345 3346
        goto cleanup;

    if (virAsprintf(&src, "/dev/bus/usb/%03d/%03d",
                    def->source.subsys.u.usb.bus,
3347
                    def->source.subsys.u.usb.device) < 0)
3348 3349
        goto cleanup;

3350
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3351 3352 3353 3354 3355
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3356 3357
    if (!(usb = virUSBDeviceNew(def->source.subsys.u.usb.bus,
                                def->source.subsys.u.usb.device, vroot)))
3358 3359 3360 3361 3362 3363 3364 3365 3366 3367 3368 3369 3370 3371 3372 3373 3374 3375 3376 3377 3378 3379 3380 3381 3382 3383 3384 3385 3386 3387 3388 3389 3390
        goto cleanup;

    if (stat(src, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"), src);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("USB source %s was not a character device"),
                       src);
        goto cleanup;
    }

    mode = 0700 | S_IFCHR;

    if (virFileMakePath(dstdir) < 0) {
        virReportSystemError(errno,
                             _("Unable to create %s"), dstdir);
        goto cleanup;
    }

    VIR_DEBUG("Creating dev %s (%d,%d)",
              dstfile, major(sb.st_rdev), minor(sb.st_rdev));
    if (mknod(dstfile, mode, sb.st_rdev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             dstfile);
        goto cleanup;
    }
    created = true;

3391 3392 3393
    if (lxcContainerChown(vm->def, dstfile) < 0)
        goto cleanup;

3394 3395 3396 3397
    if (virSecurityManagerSetHostdevLabel(driver->securityManager,
                                          vm->def, def, vroot) < 0)
        goto cleanup;

3398
    if (virUSBDeviceFileIterate(usb,
3399 3400
                                virLXCSetupHostUsbDeviceCgroup,
                                &priv->cgroup) < 0)
3401 3402 3403 3404 3405 3406 3407 3408 3409
        goto cleanup;

    ret = 0;

cleanup:
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    if (ret < 0 && created)
        unlink(dstfile);

3410
    virUSBDeviceFree(usb);
3411 3412 3413 3414 3415 3416 3417 3418
    VIR_FREE(src);
    VIR_FREE(dstfile);
    VIR_FREE(dstdir);
    VIR_FREE(vroot);
    return ret;
}


3419 3420 3421 3422 3423 3424 3425 3426 3427 3428 3429 3430 3431 3432 3433 3434 3435 3436 3437 3438 3439 3440 3441 3442 3443 3444 3445 3446 3447 3448 3449 3450 3451 3452 3453 3454 3455 3456 3457 3458 3459
static int
lxcDomainAttachDeviceHostdevStorageLive(virLXCDriverPtr driver,
                                        virDomainObjPtr vm,
                                        virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    char *dst = NULL;
    char *vroot = NULL;
    struct stat sb;
    bool created = false;
    mode_t mode = 0;

    if (!def->source.caps.u.storage.block) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Missing storage block path"));
        goto cleanup;
    }

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host device already exists"));
        return -1;
    }

    if (stat(def->source.caps.u.storage.block, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"),
                             def->source.caps.u.storage.block);
        goto cleanup;
    }

    if (!S_ISBLK(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Hostdev source %s must be a block device"),
                       def->source.caps.u.storage.block);
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
3460
                    (unsigned long long)priv->initpid) < 0)
3461 3462 3463 3464
        goto cleanup;

    if (virAsprintf(&dst, "%s/%s",
                    vroot,
3465
                    def->source.caps.u.storage.block) < 0)
3466 3467
        goto cleanup;

3468
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0)
3469 3470
        goto cleanup;

3471 3472
    if (lxcContainerSetupHostdevCapsMakePath(dst) < 0) {
        virReportSystemError(errno,
3473
                             _("Unable to create directory for device %s"),
3474 3475 3476 3477
                             dst);
        goto cleanup;
    }

3478 3479 3480 3481 3482 3483 3484 3485 3486 3487 3488 3489 3490
    mode = 0700 | S_IFBLK;

    VIR_DEBUG("Creating dev %s (%d,%d)",
              def->source.caps.u.storage.block,
              major(sb.st_rdev), minor(sb.st_rdev));
    if (mknod(dst, mode, sb.st_rdev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             dst);
        goto cleanup;
    }
    created = true;

3491 3492 3493
    if (lxcContainerChown(vm->def, dst) < 0)
        goto cleanup;

3494 3495 3496 3497
    if (virSecurityManagerSetHostdevLabel(driver->securityManager,
                                          vm->def, def, vroot) < 0)
        goto cleanup;

3498
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3499 3500 3501 3502 3503
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3504
    if (virCgroupAllowDevicePath(priv->cgroup, def->source.caps.u.storage.block,
3505 3506 3507 3508 3509 3510 3511 3512 3513 3514 3515 3516 3517 3518 3519 3520 3521 3522 3523 3524 3525 3526
                                 VIR_CGROUP_DEVICE_RW |
                                 VIR_CGROUP_DEVICE_MKNOD) != 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot allow device %s for domain %s"),
                       def->source.caps.u.storage.block, vm->def->name);
        goto cleanup;
    }

    vm->def->hostdevs[vm->def->nhostdevs++] = def;

    ret = 0;

cleanup:
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    if (dst && created && ret < 0)
        unlink(dst);
    VIR_FREE(dst);
    VIR_FREE(vroot);
    return ret;
}


3527 3528 3529 3530 3531 3532 3533 3534 3535 3536 3537 3538 3539 3540 3541 3542 3543 3544 3545 3546 3547 3548 3549 3550 3551 3552 3553 3554 3555 3556 3557 3558 3559 3560 3561 3562 3563 3564 3565 3566 3567
static int
lxcDomainAttachDeviceHostdevMiscLive(virLXCDriverPtr driver,
                                     virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    char *dst = NULL;
    char *vroot = NULL;
    struct stat sb;
    bool created = false;
    mode_t mode = 0;

    if (!def->source.caps.u.misc.chardev) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Missing storage block path"));
        goto cleanup;
    }

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host device already exists"));
        return -1;
    }

    if (stat(def->source.caps.u.misc.chardev, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"),
                             def->source.caps.u.misc.chardev);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Hostdev source %s must be a block device"),
                       def->source.caps.u.misc.chardev);
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
3568
                    (unsigned long long)priv->initpid) < 0)
3569 3570 3571 3572
        goto cleanup;

    if (virAsprintf(&dst, "%s/%s",
                    vroot,
3573
                    def->source.caps.u.misc.chardev) < 0)
3574 3575
        goto cleanup;

3576
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0)
3577 3578
        goto cleanup;

3579 3580
    if (lxcContainerSetupHostdevCapsMakePath(dst) < 0) {
        virReportSystemError(errno,
3581
                             _("Unable to create directory for device %s"),
3582 3583 3584 3585
                             dst);
        goto cleanup;
    }

3586 3587 3588 3589 3590 3591 3592 3593 3594 3595 3596 3597 3598
    mode = 0700 | S_IFCHR;

    VIR_DEBUG("Creating dev %s (%d,%d)",
              def->source.caps.u.misc.chardev,
              major(sb.st_rdev), minor(sb.st_rdev));
    if (mknod(dst, mode, sb.st_rdev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             dst);
        goto cleanup;
    }
    created = true;

3599 3600 3601
    if (lxcContainerChown(vm->def, dst) < 0)
        goto cleanup;

3602 3603 3604 3605
    if (virSecurityManagerSetHostdevLabel(driver->securityManager,
                                          vm->def, def, vroot) < 0)
        goto cleanup;

3606
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3607 3608 3609 3610 3611
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3612
    if (virCgroupAllowDevicePath(priv->cgroup, def->source.caps.u.misc.chardev,
3613 3614 3615 3616 3617 3618 3619 3620 3621 3622 3623 3624 3625 3626 3627 3628 3629 3630 3631 3632 3633 3634
                                 VIR_CGROUP_DEVICE_RW |
                                 VIR_CGROUP_DEVICE_MKNOD) != 0) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot allow device %s for domain %s"),
                       def->source.caps.u.misc.chardev, vm->def->name);
        goto cleanup;
    }

    vm->def->hostdevs[vm->def->nhostdevs++] = def;

    ret = 0;

cleanup:
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    if (dst && created && ret < 0)
        unlink(dst);
    VIR_FREE(dst);
    VIR_FREE(vroot);
    return ret;
}


3635 3636 3637 3638 3639 3640 3641 3642 3643 3644 3645 3646 3647 3648 3649 3650 3651 3652
static int
lxcDomainAttachDeviceHostdevSubsysLive(virLXCDriverPtr driver,
                                       virDomainObjPtr vm,
                                       virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        return lxcDomainAttachDeviceHostdevSubsysUSBLive(driver, vm, dev);

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevSubsysTypeToString(dev->data.hostdev->source.subsys.type));
        return -1;
    }
}


3653 3654 3655 3656 3657 3658 3659 3660 3661
static int
lxcDomainAttachDeviceHostdevCapsLive(virLXCDriverPtr driver,
                                     virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.caps.type) {
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_STORAGE:
        return lxcDomainAttachDeviceHostdevStorageLive(driver, vm, dev);

3662 3663 3664
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_MISC:
        return lxcDomainAttachDeviceHostdevMiscLive(driver, vm, dev);

3665 3666 3667 3668 3669 3670 3671 3672 3673
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevCapsTypeToString(dev->data.hostdev->source.caps.type));
        return -1;
    }
}


3674 3675 3676 3677 3678 3679 3680 3681 3682 3683 3684 3685 3686 3687 3688 3689 3690
static int
lxcDomainAttachDeviceHostdevLive(virLXCDriverPtr driver,
                                 virDomainObjPtr vm,
                                 virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach hostdev until init PID is known"));
        return -1;
    }

    switch (dev->data.hostdev->mode) {
    case VIR_DOMAIN_HOSTDEV_MODE_SUBSYS:
        return lxcDomainAttachDeviceHostdevSubsysLive(driver, vm, dev);

3691 3692 3693
    case VIR_DOMAIN_HOSTDEV_MODE_CAPABILITIES:
        return lxcDomainAttachDeviceHostdevCapsLive(driver, vm, dev);

3694 3695 3696 3697 3698 3699 3700 3701 3702
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device mode %s"),
                       virDomainHostdevModeTypeToString(dev->data.hostdev->mode));
        return -1;
    }
}


3703 3704 3705 3706
static int
lxcDomainAttachDeviceLive(virConnectPtr conn,
                          virLXCDriverPtr driver,
                          virDomainObjPtr vm,
3707 3708 3709 3710 3711
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
3712 3713 3714 3715 3716 3717
    case VIR_DOMAIN_DEVICE_DISK:
        ret = lxcDomainAttachDeviceDiskLive(driver, vm, dev);
        if (!ret)
            dev->data.disk = NULL;
        break;

3718 3719 3720 3721 3722 3723 3724
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainAttachDeviceNetLive(conn, vm,
                                           dev->data.net);
        if (!ret)
            dev->data.net = NULL;
        break;

3725 3726 3727 3728 3729 3730
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        ret = lxcDomainAttachDeviceHostdevLive(driver, vm, dev);
        if (!ret)
            dev->data.disk = NULL;
        break;

3731 3732 3733 3734 3735 3736 3737 3738 3739 3740 3741
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be attached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


3742
static int
3743
lxcDomainDetachDeviceDiskLive(virDomainObjPtr vm,
3744 3745 3746 3747
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = NULL;
3748
    int idx, ret = -1;
J
John Ferlan 已提交
3749
    char *dst = NULL;
3750 3751 3752 3753 3754 3755 3756

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

3757 3758 3759
    if ((idx = virDomainDiskIndexByName(vm->def,
                                        dev->data.disk->dst,
                                        false)) < 0) {
3760 3761 3762 3763 3764
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
        goto cleanup;
    }

3765
    def = vm->def->disks[idx];
3766 3767

    if (virAsprintf(&dst, "/proc/%llu/root/dev/%s",
3768
                    (unsigned long long)priv->initpid, def->dst) < 0)
3769 3770
        goto cleanup;

3771
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3772 3773 3774 3775 3776 3777 3778 3779 3780 3781 3782 3783 3784 3785
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

    VIR_DEBUG("Unlinking %s (backed by %s)", dst, def->src);
    if (unlink(dst) < 0 && errno != ENOENT) {
        virDomainAuditDisk(vm, def->src, NULL, "detach", false);
        virReportSystemError(errno,
                             _("Unable to remove device %s"), dst);
        goto cleanup;
    }
    virDomainAuditDisk(vm, def->src, NULL, "detach", true);

3786
    if (virCgroupDenyDevicePath(priv->cgroup, def->src, VIR_CGROUP_DEVICE_RWM) != 0)
3787 3788 3789
        VIR_WARN("cannot deny device %s for domain %s",
                 def->src, vm->def->name);

3790
    virDomainDiskRemove(vm->def, idx);
3791 3792 3793 3794 3795 3796 3797 3798 3799 3800
    virDomainDiskDefFree(def);

    ret = 0;

cleanup:
    VIR_FREE(dst);
    return ret;
}


3801
static int
3802 3803 3804 3805 3806 3807 3808 3809 3810 3811 3812 3813 3814 3815 3816 3817 3818 3819 3820 3821 3822 3823 3824 3825 3826 3827 3828 3829 3830 3831 3832 3833 3834 3835 3836 3837 3838 3839 3840 3841 3842 3843 3844 3845 3846 3847 3848 3849 3850 3851 3852 3853 3854 3855 3856 3857 3858 3859 3860 3861 3862 3863 3864 3865 3866
lxcDomainDetachDeviceNetLive(virDomainObjPtr vm,
                             virDomainDeviceDefPtr dev)
{
    int detachidx, ret = -1;
    virDomainNetDefPtr detach = NULL;
    char mac[VIR_MAC_STRING_BUFLEN];
    virNetDevVPortProfilePtr vport = NULL;

    detachidx = virDomainNetFindIdx(vm->def, dev->data.net);
    if (detachidx == -2) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("multiple devices matching mac address %s found"),
                       virMacAddrFormat(&dev->data.net->mac, mac));
        goto cleanup;
    } else if (detachidx < 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("network device %s not found"),
                       virMacAddrFormat(&dev->data.net->mac, mac));
        goto cleanup;
    }
    detach = vm->def->nets[detachidx];

    switch (virDomainNetGetActualType(detach)) {
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
    case VIR_DOMAIN_NET_TYPE_NETWORK:
        if (virNetDevVethDelete(detach->ifname) < 0) {
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
        break;

        /* It'd be nice to support this, but with macvlan
         * once assigned to a container nothing exists on
         * the host side. Further the container can change
         * the mac address of NIC name, so we can't easily
         * find out which guest NIC it maps to
    case VIR_DOMAIN_NET_TYPE_DIRECT:
        */

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Only bridged veth devices can be detached"));
        goto cleanup;
    }

    virDomainAuditNet(vm, detach, NULL, "detach", true);

    virDomainConfNWFilterTeardown(detach);

    vport = virDomainNetGetActualVirtPortProfile(detach);
    if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
        ignore_value(virNetDevOpenvswitchRemovePort(
                        virDomainNetGetActualBridgeName(detach),
                        detach->ifname));
    ret = 0;
cleanup:
    if (!ret) {
        networkReleaseActualDevice(detach);
        virDomainNetRemove(vm->def, detachidx);
        virDomainNetDefFree(detach);
    }
    return ret;
}


3867 3868 3869 3870 3871 3872 3873 3874
static int
lxcDomainDetachDeviceHostdevUSBLive(virLXCDriverPtr driver,
                                    virDomainObjPtr vm,
                                    virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
    int idx, ret = -1;
J
John Ferlan 已提交
3875
    char *dst = NULL;
3876
    char *vroot;
3877
    virUSBDevicePtr usb = NULL;
3878 3879 3880 3881 3882 3883 3884 3885 3886 3887

    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("usb device not found"));
        goto cleanup;
    }

    if (virAsprintf(&vroot, "/proc/%llu/root",
3888
                    (unsigned long long)priv->initpid) < 0)
3889 3890 3891 3892 3893
        goto cleanup;

    if (virAsprintf(&dst, "%s/dev/bus/usb/%03d/%03d",
                    vroot,
                    def->source.subsys.u.usb.bus,
3894
                    def->source.subsys.u.usb.device) < 0)
3895 3896
        goto cleanup;

3897
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3898 3899 3900 3901 3902
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3903 3904
    if (!(usb = virUSBDeviceNew(def->source.subsys.u.usb.bus,
                                def->source.subsys.u.usb.device, vroot)))
3905 3906 3907 3908 3909 3910 3911 3912 3913 3914 3915
        goto cleanup;

    VIR_DEBUG("Unlinking %s", dst);
    if (unlink(dst) < 0 && errno != ENOENT) {
        virDomainAuditHostdev(vm, def, "detach", false);
        virReportSystemError(errno,
                             _("Unable to remove device %s"), dst);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

3916
    if (virUSBDeviceFileIterate(usb,
3917 3918
                                virLXCTeardownHostUsbDeviceCgroup,
                                &priv->cgroup) < 0)
3919 3920 3921
        VIR_WARN("cannot deny device %s for domain %s",
                 dst, vm->def->name);

3922
    virObjectLock(driver->activeUsbHostdevs);
3923
    virUSBDeviceListDel(driver->activeUsbHostdevs, usb);
3924
    virObjectUnlock(driver->activeUsbHostdevs);
3925 3926 3927 3928 3929 3930 3931

    virDomainHostdevRemove(vm->def, idx);
    virDomainHostdevDefFree(def);

    ret = 0;

cleanup:
3932
    virUSBDeviceFree(usb);
3933 3934 3935 3936
    VIR_FREE(dst);
    return ret;
}

3937 3938

static int
3939
lxcDomainDetachDeviceHostdevStorageLive(virDomainObjPtr vm,
3940 3941 3942 3943
                                        virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
3944
    int idx, ret = -1;
3945 3946 3947 3948 3949 3950 3951 3952
    char *dst = NULL;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

3953 3954 3955
    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
3956 3957 3958 3959 3960 3961 3962 3963
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("hostdev %s not found"),
                       dev->data.hostdev->source.caps.u.storage.block);
        goto cleanup;
    }

    if (virAsprintf(&dst, "/proc/%llu/root/%s",
                    (unsigned long long)priv->initpid,
3964
                    def->source.caps.u.storage.block) < 0)
3965 3966
        goto cleanup;

3967
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
3968 3969 3970 3971 3972 3973 3974 3975 3976 3977 3978 3979 3980 3981
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

    VIR_DEBUG("Unlinking %s", dst);
    if (unlink(dst) < 0 && errno != ENOENT) {
        virDomainAuditHostdev(vm, def, "detach", false);
        virReportSystemError(errno,
                             _("Unable to remove device %s"), dst);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

3982
    if (virCgroupDenyDevicePath(priv->cgroup, def->source.caps.u.storage.block, VIR_CGROUP_DEVICE_RWM) != 0)
3983 3984 3985
        VIR_WARN("cannot deny device %s for domain %s",
                 def->source.caps.u.storage.block, vm->def->name);

3986
    virDomainHostdevRemove(vm->def, idx);
3987 3988 3989 3990 3991 3992 3993 3994 3995 3996
    virDomainHostdevDefFree(def);

    ret = 0;

cleanup:
    VIR_FREE(dst);
    return ret;
}


3997
static int
3998
lxcDomainDetachDeviceHostdevMiscLive(virDomainObjPtr vm,
3999 4000 4001 4002
                                     virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
4003
    int idx, ret = -1;
4004 4005 4006 4007 4008 4009 4010 4011
    char *dst = NULL;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4012 4013 4014
    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
4015 4016 4017 4018 4019 4020 4021 4022
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("hostdev %s not found"),
                       dev->data.hostdev->source.caps.u.misc.chardev);
        goto cleanup;
    }

    if (virAsprintf(&dst, "/proc/%llu/root/%s",
                    (unsigned long long)priv->initpid,
4023
                    def->source.caps.u.misc.chardev) < 0)
4024 4025
        goto cleanup;

4026
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4027 4028 4029 4030 4031 4032 4033 4034 4035 4036 4037 4038 4039 4040
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

    VIR_DEBUG("Unlinking %s", dst);
    if (unlink(dst) < 0 && errno != ENOENT) {
        virDomainAuditHostdev(vm, def, "detach", false);
        virReportSystemError(errno,
                             _("Unable to remove device %s"), dst);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4041
    if (virCgroupDenyDevicePath(priv->cgroup, def->source.caps.u.misc.chardev, VIR_CGROUP_DEVICE_RWM) != 0)
4042 4043 4044
        VIR_WARN("cannot deny device %s for domain %s",
                 def->source.caps.u.misc.chardev, vm->def->name);

4045
    virDomainHostdevRemove(vm->def, idx);
4046 4047 4048 4049 4050 4051 4052 4053 4054 4055
    virDomainHostdevDefFree(def);

    ret = 0;

cleanup:
    VIR_FREE(dst);
    return ret;
}


4056 4057 4058 4059 4060 4061 4062 4063 4064 4065 4066 4067 4068 4069 4070 4071 4072 4073
static int
lxcDomainDetachDeviceHostdevSubsysLive(virLXCDriverPtr driver,
                                       virDomainObjPtr vm,
                                       virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        return lxcDomainDetachDeviceHostdevUSBLive(driver, vm, dev);

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevSubsysTypeToString(dev->data.hostdev->source.subsys.type));
        return -1;
    }
}


4074
static int
4075 4076
lxcDomainDetachDeviceHostdevCapsLive(virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
4077 4078 4079
{
    switch (dev->data.hostdev->source.caps.type) {
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_STORAGE:
4080
        return lxcDomainDetachDeviceHostdevStorageLive(vm, dev);
4081

4082
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_MISC:
4083
        return lxcDomainDetachDeviceHostdevMiscLive(vm, dev);
4084

4085 4086 4087 4088 4089 4090 4091 4092 4093
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevCapsTypeToString(dev->data.hostdev->source.caps.type));
        return -1;
    }
}


4094 4095 4096 4097 4098 4099 4100 4101 4102 4103 4104 4105 4106 4107 4108 4109 4110
static int
lxcDomainDetachDeviceHostdevLive(virLXCDriverPtr driver,
                                 virDomainObjPtr vm,
                                 virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach hostdev until init PID is known"));
        return -1;
    }

    switch (dev->data.hostdev->mode) {
    case VIR_DOMAIN_HOSTDEV_MODE_SUBSYS:
        return lxcDomainDetachDeviceHostdevSubsysLive(driver, vm, dev);

4111
    case VIR_DOMAIN_HOSTDEV_MODE_CAPABILITIES:
4112
        return lxcDomainDetachDeviceHostdevCapsLive(vm, dev);
4113

4114 4115 4116 4117 4118 4119 4120 4121 4122
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device mode %s"),
                       virDomainHostdevModeTypeToString(dev->data.hostdev->mode));
        return -1;
    }
}


4123 4124 4125
static int
lxcDomainDetachDeviceLive(virLXCDriverPtr driver,
                          virDomainObjPtr vm,
4126 4127 4128 4129 4130
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
4131
    case VIR_DOMAIN_DEVICE_DISK:
4132
        ret = lxcDomainDetachDeviceDiskLive(vm, dev);
4133 4134
        break;

4135 4136 4137 4138
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainDetachDeviceNetLive(vm, dev);
        break;

4139 4140 4141 4142
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        ret = lxcDomainDetachDeviceHostdevLive(driver, vm, dev);
        break;

4143 4144 4145 4146 4147 4148 4149 4150 4151 4152 4153
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be detached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


4154 4155 4156
static int lxcDomainAttachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
4157 4158
{
    virLXCDriverPtr driver = dom->conn->privateData;
4159
    virCapsPtr caps = NULL;
4160 4161 4162 4163 4164
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
    unsigned int affect;
4165
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4166 4167

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
4168
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
4169 4170 4171

    affect = flags & (VIR_DOMAIN_AFFECT_LIVE | VIR_DOMAIN_AFFECT_CONFIG);

M
Michal Privoznik 已提交
4172
    if (!(vm = lxcDomObjFromDomain(dom)))
4173 4174
        goto cleanup;

4175 4176 4177
    if (virDomainAttachDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4178 4179 4180 4181 4182 4183 4184 4185 4186 4187 4188 4189 4190 4191 4192
    if (virDomainObjIsActive(vm)) {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_LIVE;
    } else {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_CONFIG;
        /* check consistency between flags and the vm state */
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("cannot do live update a device on "
                             "inactive domain"));
            goto cleanup;
        }
    }

4193 4194 4195
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

4196 4197 4198 4199 4200 4201
    if ((flags & VIR_DOMAIN_AFFECT_CONFIG) && !vm->persistent) {
         virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                        _("cannot modify device on transient domain"));
         goto cleanup;
    }

4202
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4203
                                             caps, driver->xmlopt,
4204 4205 4206 4207 4208 4209 4210 4211 4212 4213
                                             VIR_DOMAIN_XML_INACTIVE);
    if (dev == NULL)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
4214
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4215
                                          caps, driver->xmlopt);
4216 4217 4218 4219 4220 4221 4222 4223 4224
        if (!dev_copy)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        if (virDomainDefCompatibleDevice(vm->def, dev) < 0)
            goto cleanup;

        /* Make a copy for updated domain. */
4225
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4226 4227
        if (!vmdef)
            goto cleanup;
4228
        if ((ret = lxcDomainAttachDeviceConfig(vmdef, dev)) < 0)
4229 4230 4231 4232 4233 4234 4235
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if (virDomainDefCompatibleDevice(vm->def, dev_copy) < 0)
            goto cleanup;

4236
        if ((ret = lxcDomainAttachDeviceLive(dom->conn, driver, vm, dev_copy)) < 0)
4237 4238 4239 4240 4241 4242
            goto cleanup;
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
4243
        if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0) {
4244 4245 4246 4247 4248 4249 4250
            ret = -1;
            goto cleanup;
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
4251
        ret = virDomainSaveConfig(cfg->configDir, vmdef);
4252
        if (!ret) {
4253
            virDomainObjAssignDef(vm, vmdef, false, NULL);
4254 4255 4256 4257 4258 4259 4260 4261 4262 4263
            vmdef = NULL;
        }
    }

cleanup:
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
    if (vm)
4264
        virObjectUnlock(vm);
4265
    virObjectUnref(caps);
4266
    virObjectUnref(cfg);
4267 4268 4269 4270 4271 4272 4273 4274 4275 4276 4277 4278 4279 4280 4281 4282
    return ret;
}


static int lxcDomainAttachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainAttachDeviceFlags(dom, xml,
                                       VIR_DOMAIN_AFFECT_LIVE);
}


static int lxcDomainUpdateDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
4283
    virLXCDriverPtr driver = dom->conn->privateData;
4284
    virCapsPtr caps = NULL;
4285 4286 4287 4288 4289
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
    unsigned int affect;
4290
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4291 4292 4293 4294 4295 4296 4297

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_DOMAIN_DEVICE_MODIFY_FORCE, -1);

    affect = flags & (VIR_DOMAIN_AFFECT_LIVE | VIR_DOMAIN_AFFECT_CONFIG);

M
Michal Privoznik 已提交
4298
    if (!(vm = lxcDomObjFromDomain(dom)))
4299 4300
        goto cleanup;

4301 4302 4303
    if (virDomainUpdateDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4304 4305 4306 4307 4308 4309 4310 4311 4312 4313 4314 4315 4316 4317 4318 4319 4320 4321 4322 4323 4324
    if (virDomainObjIsActive(vm)) {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_LIVE;
    } else {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_CONFIG;
        /* check consistency between flags and the vm state */
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("cannot do live update a device on "
                             "inactive domain"));
            goto cleanup;
        }
    }

    if ((flags & VIR_DOMAIN_AFFECT_CONFIG) && !vm->persistent) {
         virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                        _("cannot modify device on transient domain"));
         goto cleanup;
    }

4325 4326 4327
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

4328
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4329
                                             caps, driver->xmlopt,
4330 4331 4332 4333 4334 4335 4336 4337 4338 4339 4340
                                             VIR_DOMAIN_XML_INACTIVE);
    if (dev == NULL)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4341
                                          caps, driver->xmlopt);
4342 4343 4344 4345 4346 4347 4348 4349 4350
        if (!dev_copy)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        if (virDomainDefCompatibleDevice(vm->def, dev) < 0)
            goto cleanup;

        /* Make a copy for updated domain. */
4351
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4352 4353 4354 4355 4356 4357 4358 4359 4360 4361 4362 4363 4364 4365 4366 4367 4368 4369
        if (!vmdef)
            goto cleanup;
        if ((ret = lxcDomainUpdateDeviceConfig(vmdef, dev)) < 0)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if (virDomainDefCompatibleDevice(vm->def, dev_copy) < 0)
            goto cleanup;

        virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                       _("Unable to modify live devices"));

        goto cleanup;
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
4370
        ret = virDomainSaveConfig(cfg->configDir, vmdef);
4371 4372 4373 4374 4375 4376 4377 4378 4379 4380 4381 4382 4383
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false, NULL);
            vmdef = NULL;
        }
    }

cleanup:
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
    if (vm)
        virObjectUnlock(vm);
4384
    virObjectUnref(caps);
4385
    virObjectUnref(cfg);
4386
    return ret;
4387 4388 4389 4390 4391 4392 4393
}


static int lxcDomainDetachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
4394
    virLXCDriverPtr driver = dom->conn->privateData;
4395
    virCapsPtr caps = NULL;
4396 4397 4398 4399 4400
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
    unsigned int affect;
4401
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4402 4403 4404 4405 4406 4407

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

    affect = flags & (VIR_DOMAIN_AFFECT_LIVE | VIR_DOMAIN_AFFECT_CONFIG);

M
Michal Privoznik 已提交
4408
    if (!(vm = lxcDomObjFromDomain(dom)))
4409 4410
        goto cleanup;

4411 4412 4413
    if (virDomainDetachDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4414 4415 4416 4417 4418 4419 4420 4421 4422 4423 4424 4425 4426 4427 4428 4429 4430 4431 4432 4433 4434
    if (virDomainObjIsActive(vm)) {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_LIVE;
    } else {
        if (affect == VIR_DOMAIN_AFFECT_CURRENT)
            flags |= VIR_DOMAIN_AFFECT_CONFIG;
        /* check consistency between flags and the vm state */
        if (flags & VIR_DOMAIN_AFFECT_LIVE) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("cannot do live update a device on "
                             "inactive domain"));
            goto cleanup;
        }
    }

    if ((flags & VIR_DOMAIN_AFFECT_CONFIG) && !vm->persistent) {
         virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                        _("cannot modify device on transient domain"));
         goto cleanup;
    }

4435 4436 4437
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

4438
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4439
                                             caps, driver->xmlopt,
4440 4441 4442 4443 4444 4445 4446 4447 4448 4449 4450
                                             VIR_DOMAIN_XML_INACTIVE);
    if (dev == NULL)
        goto cleanup;

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4451
                                          caps, driver->xmlopt);
4452 4453 4454 4455 4456 4457 4458 4459 4460
        if (!dev_copy)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        if (virDomainDefCompatibleDevice(vm->def, dev) < 0)
            goto cleanup;

        /* Make a copy for updated domain. */
4461
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4462 4463 4464 4465 4466 4467 4468 4469 4470 4471 4472 4473 4474 4475 4476 4477 4478 4479
        if (!vmdef)
            goto cleanup;

        if ((ret = lxcDomainDetachDeviceConfig(vmdef, dev)) < 0)
            goto cleanup;
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if (virDomainDefCompatibleDevice(vm->def, dev_copy) < 0)
            goto cleanup;

        if ((ret = lxcDomainDetachDeviceLive(driver, vm, dev_copy)) < 0)
            goto cleanup;
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
4480
        if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm) < 0) {
4481 4482 4483 4484 4485 4486 4487
            ret = -1;
            goto cleanup;
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
4488
        ret = virDomainSaveConfig(cfg->configDir, vmdef);
4489 4490 4491 4492 4493 4494 4495 4496 4497 4498 4499 4500 4501
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false, NULL);
            vmdef = NULL;
        }
    }

cleanup:
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
    if (vm)
        virObjectUnlock(vm);
4502
    virObjectUnref(caps);
4503
    virObjectUnref(cfg);
4504
    return ret;
4505 4506 4507 4508 4509 4510 4511 4512 4513 4514 4515
}


static int lxcDomainDetachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainDetachDeviceFlags(dom, xml,
                                      VIR_DOMAIN_AFFECT_LIVE);
}


4516 4517 4518
static int lxcDomainLxcOpenNamespace(virDomainPtr dom,
                                     int **fdlist,
                                     unsigned int flags)
4519 4520 4521 4522 4523 4524 4525 4526 4527
{
    virDomainObjPtr vm;
    virLXCDomainObjPrivatePtr priv;
    int ret = -1;
    size_t nfds = 0;

    *fdlist = NULL;
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
4528
    if (!(vm = lxcDomObjFromDomain(dom)))
4529
        goto cleanup;
M
Michal Privoznik 已提交
4530

4531 4532
    priv = vm->privateData;

4533 4534 4535
    if (virDomainLxcOpenNamespaceEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

4536 4537 4538 4539 4540 4541 4542 4543 4544 4545 4546 4547 4548 4549 4550 4551 4552
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
        goto cleanup;
    }

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
        goto cleanup;
    }

    if (virProcessGetNamespaces(priv->initpid, &nfds, fdlist) < 0)
        goto cleanup;

    ret = nfds;
cleanup:
4553 4554
    if (vm)
        virObjectUnlock(vm);
4555 4556 4557 4558
    return ret;
}


4559
static char *
4560
lxcConnectGetSysinfo(virConnectPtr conn, unsigned int flags)
4561 4562 4563 4564 4565 4566
{
    virLXCDriverPtr driver = conn->privateData;
    virBuffer buf = VIR_BUFFER_INITIALIZER;

    virCheckFlags(0, NULL);

4567 4568 4569
    if (virConnectGetSysinfoEnsureACL(conn) < 0)
        return NULL;

4570 4571 4572 4573 4574 4575 4576 4577 4578 4579 4580 4581 4582 4583 4584 4585
    if (!driver->hostsysinfo) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Host SMBIOS information is not available"));
        return NULL;
    }

    if (virSysinfoFormat(&buf, driver->hostsysinfo) < 0)
        return NULL;
    if (virBufferError(&buf)) {
        virReportOOMError();
        return NULL;
    }
    return virBufferContentAndReset(&buf);
}


4586
static int
4587
lxcNodeGetInfo(virConnectPtr conn,
4588 4589
               virNodeInfoPtr nodeinfo)
{
4590 4591 4592
    if (virNodeGetInfoEnsureACL(conn) < 0)
        return -1;

4593 4594 4595 4596 4597
    return nodeGetInfo(nodeinfo);
}


static int
4598
lxcNodeGetCPUStats(virConnectPtr conn,
4599 4600 4601 4602 4603
                   int cpuNum,
                   virNodeCPUStatsPtr params,
                   int *nparams,
                   unsigned int flags)
{
4604 4605 4606
    if (virNodeGetCPUStatsEnsureACL(conn) < 0)
        return -1;

4607 4608 4609 4610 4611
    return nodeGetCPUStats(cpuNum, params, nparams, flags);
}


static int
4612
lxcNodeGetMemoryStats(virConnectPtr conn,
4613 4614 4615 4616 4617
                      int cellNum,
                      virNodeMemoryStatsPtr params,
                      int *nparams,
                      unsigned int flags)
{
4618 4619 4620
    if (virNodeGetMemoryStatsEnsureACL(conn) < 0)
        return -1;

4621 4622 4623 4624 4625
    return nodeGetMemoryStats(cellNum, params, nparams, flags);
}


static int
4626
lxcNodeGetCellsFreeMemory(virConnectPtr conn,
4627 4628 4629 4630
                          unsigned long long *freeMems,
                          int startCell,
                          int maxCells)
{
4631 4632 4633
    if (virNodeGetCellsFreeMemoryEnsureACL(conn) < 0)
        return -1;

4634 4635 4636 4637 4638
    return nodeGetCellsFreeMemory(freeMems, startCell, maxCells);
}


static unsigned long long
4639
lxcNodeGetFreeMemory(virConnectPtr conn)
4640
{
4641 4642 4643
    if (virNodeGetFreeMemoryEnsureACL(conn) < 0)
        return 0;

4644 4645 4646 4647 4648
    return nodeGetFreeMemory();
}


static int
4649
lxcNodeGetMemoryParameters(virConnectPtr conn,
4650 4651 4652 4653
                           virTypedParameterPtr params,
                           int *nparams,
                           unsigned int flags)
{
4654 4655 4656
    if (virNodeGetMemoryParametersEnsureACL(conn) < 0)
        return -1;

4657 4658 4659 4660 4661
    return nodeGetMemoryParameters(params, nparams, flags);
}


static int
4662
lxcNodeSetMemoryParameters(virConnectPtr conn,
4663 4664 4665 4666
                           virTypedParameterPtr params,
                           int nparams,
                           unsigned int flags)
{
4667 4668 4669
    if (virNodeSetMemoryParametersEnsureACL(conn) < 0)
        return -1;

4670 4671 4672 4673 4674
    return nodeSetMemoryParameters(params, nparams, flags);
}


static int
4675
lxcNodeGetCPUMap(virConnectPtr conn,
4676 4677 4678 4679
                 unsigned char **cpumap,
                 unsigned int *online,
                 unsigned int flags)
{
4680 4681 4682
    if (virNodeGetCPUMapEnsureACL(conn) < 0)
        return -1;

4683 4684 4685
    return nodeGetCPUMap(cpumap, online, flags);
}

4686 4687

static int
4688
lxcNodeSuspendForDuration(virConnectPtr conn,
4689 4690 4691 4692
                          unsigned int target,
                          unsigned long long duration,
                          unsigned int flags)
{
4693 4694 4695
    if (virNodeSuspendForDurationEnsureACL(conn) < 0)
        return -1;

4696 4697 4698 4699
    return nodeSuspendForDuration(target, duration, flags);
}


D
Daniel Veillard 已提交
4700 4701
/* Function Tables */
static virDriver lxcDriver = {
4702
    .no = VIR_DRV_LXC,
4703
    .name = LXC_DRIVER_NAME,
4704 4705 4706
    .connectOpen = lxcConnectOpen, /* 0.4.2 */
    .connectClose = lxcConnectClose, /* 0.4.2 */
    .connectGetVersion = lxcConnectGetVersion, /* 0.4.6 */
4707
    .connectGetHostname = lxcConnectGetHostname, /* 0.6.3 */
4708
    .connectGetSysinfo = lxcConnectGetSysinfo, /* 1.0.5 */
4709
    .nodeGetInfo = lxcNodeGetInfo, /* 0.6.5 */
4710 4711 4712 4713 4714
    .connectGetCapabilities = lxcConnectGetCapabilities, /* 0.6.5 */
    .connectListDomains = lxcConnectListDomains, /* 0.4.2 */
    .connectNumOfDomains = lxcConnectNumOfDomains, /* 0.4.2 */
    .connectListAllDomains = lxcConnectListAllDomains, /* 0.9.13 */
    .domainCreateXML = lxcDomainCreateXML, /* 0.4.4 */
4715
    .domainCreateXMLWithFiles = lxcDomainCreateXMLWithFiles, /* 1.1.1 */
4716 4717 4718 4719 4720 4721
    .domainLookupByID = lxcDomainLookupByID, /* 0.4.2 */
    .domainLookupByUUID = lxcDomainLookupByUUID, /* 0.4.2 */
    .domainLookupByName = lxcDomainLookupByName, /* 0.4.2 */
    .domainSuspend = lxcDomainSuspend, /* 0.7.2 */
    .domainResume = lxcDomainResume, /* 0.7.2 */
    .domainDestroy = lxcDomainDestroy, /* 0.4.4 */
4722
    .domainDestroyFlags = lxcDomainDestroyFlags, /* 0.9.4 */
4723
    .domainGetOSType = lxcDomainGetOSType, /* 0.4.2 */
4724 4725 4726 4727 4728
    .domainGetMaxMemory = lxcDomainGetMaxMemory, /* 0.7.2 */
    .domainSetMaxMemory = lxcDomainSetMaxMemory, /* 0.7.2 */
    .domainSetMemory = lxcDomainSetMemory, /* 0.7.2 */
    .domainSetMemoryParameters = lxcDomainSetMemoryParameters, /* 0.8.5 */
    .domainGetMemoryParameters = lxcDomainGetMemoryParameters, /* 0.8.5 */
4729 4730
    .domainSetBlkioParameters = lxcDomainSetBlkioParameters, /* 0.9.8 */
    .domainGetBlkioParameters = lxcDomainGetBlkioParameters, /* 0.9.8 */
4731 4732
    .domainGetInfo = lxcDomainGetInfo, /* 0.4.2 */
    .domainGetState = lxcDomainGetState, /* 0.9.2 */
4733 4734
    .domainGetSecurityLabel = lxcDomainGetSecurityLabel, /* 0.9.10 */
    .nodeGetSecurityModel = lxcNodeGetSecurityModel, /* 0.9.10 */
4735
    .domainGetXMLDesc = lxcDomainGetXMLDesc, /* 0.4.2 */
4736 4737 4738 4739
    .connectListDefinedDomains = lxcConnectListDefinedDomains, /* 0.4.2 */
    .connectNumOfDefinedDomains = lxcConnectNumOfDefinedDomains, /* 0.4.2 */
    .domainCreate = lxcDomainCreate, /* 0.4.4 */
    .domainCreateWithFlags = lxcDomainCreateWithFlags, /* 0.8.2 */
4740
    .domainCreateWithFiles = lxcDomainCreateWithFiles, /* 1.1.1 */
4741
    .domainDefineXML = lxcDomainDefineXML, /* 0.4.2 */
4742
    .domainUndefine = lxcDomainUndefine, /* 0.4.2 */
4743
    .domainUndefineFlags = lxcDomainUndefineFlags, /* 0.9.4 */
4744 4745 4746 4747 4748
    .domainAttachDevice = lxcDomainAttachDevice, /* 1.0.1 */
    .domainAttachDeviceFlags = lxcDomainAttachDeviceFlags, /* 1.0.1 */
    .domainDetachDevice = lxcDomainDetachDevice, /* 1.0.1 */
    .domainDetachDeviceFlags = lxcDomainDetachDeviceFlags, /* 1.0.1 */
    .domainUpdateDeviceFlags = lxcDomainUpdateDeviceFlags, /* 1.0.1 */
4749 4750
    .domainGetAutostart = lxcDomainGetAutostart, /* 0.7.0 */
    .domainSetAutostart = lxcDomainSetAutostart, /* 0.7.0 */
4751 4752 4753 4754 4755
    .domainGetSchedulerType = lxcDomainGetSchedulerType, /* 0.5.0 */
    .domainGetSchedulerParameters = lxcDomainGetSchedulerParameters, /* 0.5.0 */
    .domainGetSchedulerParametersFlags = lxcDomainGetSchedulerParametersFlags, /* 0.9.2 */
    .domainSetSchedulerParameters = lxcDomainSetSchedulerParameters, /* 0.5.0 */
    .domainSetSchedulerParametersFlags = lxcDomainSetSchedulerParametersFlags, /* 0.9.2 */
4756
    .domainInterfaceStats = lxcDomainInterfaceStats, /* 0.7.3 */
4757 4758 4759 4760 4761
    .nodeGetCPUStats = lxcNodeGetCPUStats, /* 0.9.3 */
    .nodeGetMemoryStats = lxcNodeGetMemoryStats, /* 0.9.3 */
    .nodeGetCellsFreeMemory = lxcNodeGetCellsFreeMemory, /* 0.6.5 */
    .nodeGetFreeMemory = lxcNodeGetFreeMemory, /* 0.6.5 */
    .nodeGetCPUMap = lxcNodeGetCPUMap, /* 1.0.0 */
4762 4763 4764 4765
    .connectDomainEventRegister = lxcConnectDomainEventRegister, /* 0.7.0 */
    .connectDomainEventDeregister = lxcConnectDomainEventDeregister, /* 0.7.0 */
    .connectIsEncrypted = lxcConnectIsEncrypted, /* 0.7.3 */
    .connectIsSecure = lxcConnectIsSecure, /* 0.7.3 */
4766 4767 4768
    .domainIsActive = lxcDomainIsActive, /* 0.7.3 */
    .domainIsPersistent = lxcDomainIsPersistent, /* 0.7.3 */
    .domainIsUpdated = lxcDomainIsUpdated, /* 0.8.6 */
4769 4770
    .connectDomainEventRegisterAny = lxcConnectDomainEventRegisterAny, /* 0.8.0 */
    .connectDomainEventDeregisterAny = lxcConnectDomainEventDeregisterAny, /* 0.8.0 */
4771
    .domainOpenConsole = lxcDomainOpenConsole, /* 0.8.6 */
4772
    .connectIsAlive = lxcConnectIsAlive, /* 0.9.8 */
4773
    .nodeSuspendForDuration = lxcNodeSuspendForDuration, /* 0.9.8 */
4774 4775
    .nodeGetMemoryParameters = lxcNodeGetMemoryParameters, /* 0.10.2 */
    .nodeSetMemoryParameters = lxcNodeSetMemoryParameters, /* 0.10.2 */
4776
    .domainSendProcessSignal = lxcDomainSendProcessSignal, /* 1.0.1 */
4777 4778 4779
    .domainShutdown = lxcDomainShutdown, /* 1.0.1 */
    .domainShutdownFlags = lxcDomainShutdownFlags, /* 1.0.1 */
    .domainReboot = lxcDomainReboot, /* 1.0.1 */
4780
    .domainLxcOpenNamespace = lxcDomainLxcOpenNamespace, /* 1.0.2 */
D
Daniel Veillard 已提交
4781 4782
};

4783
static virStateDriver lxcStateDriver = {
4784
    .name = LXC_DRIVER_NAME,
4785
    .stateInitialize = lxcStateInitialize,
4786
    .stateAutoStart = lxcStateAutoStart,
4787 4788
    .stateCleanup = lxcStateCleanup,
    .stateReload = lxcStateReload,
4789 4790
};

D
Daniel Veillard 已提交
4791 4792 4793
int lxcRegister(void)
{
    virRegisterDriver(&lxcDriver);
4794
    virRegisterStateDriver(&lxcStateDriver);
D
Daniel Veillard 已提交
4795 4796
    return 0;
}