lxc_driver.c 166.6 KB
Newer Older
D
Daniel Veillard 已提交
1
/*
2
 * Copyright (C) 2010-2016 Red Hat, Inc.
D
Daniel Veillard 已提交
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
 * Copyright IBM Corp. 2008
 *
 * lxc_driver.c: linux container driver functions
 *
 * Authors:
 *  David L. Leskovec <dlesko at linux.vnet.ibm.com>
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
21
 * License along with this library.  If not, see
O
Osier Yang 已提交
22
 * <http://www.gnu.org/licenses/>.
D
Daniel Veillard 已提交
23 24 25 26
 */

#include <config.h>

27
#include <fcntl.h>
D
Daniel Veillard 已提交
28 29 30
#include <sched.h>
#include <sys/utsname.h>
#include <string.h>
31 32 33 34 35 36 37

#ifdef MAJOR_IN_MKDEV
# include <sys/mkdev.h>
#elif MAJOR_IN_SYSMACROS
# include <sys/sysmacros.h>
#endif

38
#include <sys/types.h>
39
#include <sys/socket.h>
40
#include <sys/stat.h>
41 42
#include <sys/un.h>
#include <sys/poll.h>
D
Daniel Veillard 已提交
43 44 45
#include <unistd.h>
#include <wait.h>

46
#include "virerror.h"
47
#include "virlog.h"
48
#include "datatypes.h"
49
#include "lxc_cgroup.h"
D
Daniel Veillard 已提交
50
#include "lxc_conf.h"
51
#include "lxc_container.h"
52
#include "lxc_domain.h"
D
Daniel Veillard 已提交
53
#include "lxc_driver.h"
54
#include "lxc_native.h"
55
#include "lxc_process.h"
56
#include "viralloc.h"
57
#include "virnetdevbridge.h"
58
#include "virnetdevveth.h"
59
#include "virnetdevopenvswitch.h"
60
#include "virhostcpu.h"
61
#include "virhostmem.h"
62
#include "viruuid.h"
63
#include "virhook.h"
E
Eric Blake 已提交
64
#include "virfile.h"
65
#include "virpidfile.h"
66
#include "virfdstream.h"
67
#include "domain_audit.h"
68
#include "domain_nwfilter.h"
69
#include "nwfilter_conf.h"
70
#include "virinitctl.h"
71
#include "virnetdev.h"
A
Ansis Atteka 已提交
72
#include "virnetdevtap.h"
73
#include "virnodesuspend.h"
74
#include "virprocess.h"
75
#include "virtime.h"
76
#include "virtypedparam.h"
M
Martin Kletzander 已提交
77
#include "viruri.h"
78
#include "virstring.h"
79 80
#include "viraccessapicheck.h"
#include "viraccessapichecklxc.h"
81
#include "virhostdev.h"
82
#include "netdev_bandwidth_conf.h"
D
Daniel Veillard 已提交
83

84 85
#define VIR_FROM_THIS VIR_FROM_LXC

86
VIR_LOG_INIT("lxc.lxc_driver");
87

88
#define LXC_NB_MEM_PARAM  3
89
#define LXC_NB_DOMAIN_BLOCK_STAT_PARAM 4
90

91

92 93 94 95
static int lxcStateInitialize(bool privileged,
                              virStateInhibitCallback callback,
                              void *opaque);
static int lxcStateCleanup(void);
96
virLXCDriverPtr lxc_driver = NULL;
D
Daniel Veillard 已提交
97

98 99
/* callbacks for nwfilter */
static int
100
lxcVMFilterRebuild(virDomainObjListIterator iter, void *data)
101
{
102
    return virDomainObjListForEach(lxc_driver->domains, iter, data);
103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123
}

static void
lxcVMDriverLock(void)
{
    lxcDriverLock(lxc_driver);
}

static void
lxcVMDriverUnlock(void)
{
    lxcDriverUnlock(lxc_driver);
}

static virNWFilterCallbackDriver lxcCallbackDriver = {
    .name = "LXC",
    .vmFilterRebuild = lxcVMFilterRebuild,
    .vmDriverLock = lxcVMDriverLock,
    .vmDriverUnlock = lxcVMDriverUnlock,
};

M
Michal Privoznik 已提交
124 125 126 127
/**
 * lxcDomObjFromDomain:
 * @domain: Domain pointer that has to be looked up
 *
128 129
 * This function looks up @domain and returns the appropriate virDomainObjPtr
 * that has to be released by calling virDomainObjEndAPI.
M
Michal Privoznik 已提交
130
 *
131 132
 * Returns the domain object with incremented reference counter which is locked
 * on success, NULL otherwise.
M
Michal Privoznik 已提交
133 134 135 136 137 138 139 140
 */
static virDomainObjPtr
lxcDomObjFromDomain(virDomainPtr domain)
{
    virDomainObjPtr vm;
    virLXCDriverPtr driver = domain->conn->privateData;
    char uuidstr[VIR_UUID_STRING_BUFLEN];

141
    vm = virDomainObjListFindByUUIDRef(driver->domains, domain->uuid);
M
Michal Privoznik 已提交
142 143 144 145 146 147 148 149 150 151 152
    if (!vm) {
        virUUIDFormat(domain->uuid, uuidstr);
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("no domain with matching uuid '%s' (%s)"),
                       uuidstr, domain->name);
        return NULL;
    }

    return vm;
}

D
Daniel Veillard 已提交
153 154
/* Functions */

155 156 157 158 159 160 161 162 163 164
static int
lxcConnectURIProbe(char **uri)
{
    if (lxc_driver == NULL)
        return 0;

    return VIR_STRDUP(*uri, "lxc:///system");
}


165 166
static virDrvOpenStatus lxcConnectOpen(virConnectPtr conn,
                                       virConnectAuthPtr auth ATTRIBUTE_UNUSED,
167
                                       virConfPtr conf ATTRIBUTE_UNUSED,
168
                                       unsigned int flags)
D
Daniel Veillard 已提交
169
{
E
Eric Blake 已提交
170 171
    virCheckFlags(VIR_CONNECT_RO, VIR_DRV_OPEN_ERROR);

172
    /* If path isn't '/' then they typoed, tell them correct path */
173
    if (STRNEQ(conn->uri->path, "/") &&
174 175 176 177 178 179 180 181 182 183 184 185
        STRNEQ(conn->uri->path, "/system")) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Unexpected LXC URI path '%s', try lxc:///system"),
                       conn->uri->path);
        return VIR_DRV_OPEN_ERROR;
    }

    /* URI was good, but driver isn't active */
    if (lxc_driver == NULL) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       "%s", _("lxc state driver is not active"));
        return VIR_DRV_OPEN_ERROR;
186
    }
187

188 189 190
    if (virConnectOpenEnsureACL(conn) < 0)
        return VIR_DRV_OPEN_ERROR;

191
    conn->privateData = lxc_driver;
D
Daniel Veillard 已提交
192 193 194 195

    return VIR_DRV_OPEN_SUCCESS;
}

196
static int lxcConnectClose(virConnectPtr conn)
D
Daniel Veillard 已提交
197
{
198
    virLXCDriverPtr driver = conn->privateData;
199

200
    virCloseCallbacksRun(driver->closeCallbacks, conn, driver->domains, driver);
201 202
    conn->privateData = NULL;
    return 0;
D
Daniel Veillard 已提交
203 204
}

205

206
static int lxcConnectIsSecure(virConnectPtr conn ATTRIBUTE_UNUSED)
207 208 209 210 211 212
{
    /* Trivially secure, since always inside the daemon */
    return 1;
}


213
static int lxcConnectIsEncrypted(virConnectPtr conn ATTRIBUTE_UNUSED)
214 215 216 217 218 219
{
    /* Not encrypted, but remote driver takes care of that */
    return 0;
}


220
static int lxcConnectIsAlive(virConnectPtr conn ATTRIBUTE_UNUSED)
221 222 223 224 225
{
    return 1;
}


226
static char *lxcConnectGetCapabilities(virConnectPtr conn) {
227
    virLXCDriverPtr driver = conn->privateData;
228
    virCapsPtr caps;
229 230
    char *xml;

231 232 233
    if (virConnectGetCapabilitiesEnsureACL(conn) < 0)
        return NULL;

234
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
235 236
        return NULL;

237
    xml = virCapabilitiesFormatXML(caps);
238

239
    virObjectUnref(caps);
240 241 242 243
    return xml;
}


D
Daniel Veillard 已提交
244 245 246
static virDomainPtr lxcDomainLookupByID(virConnectPtr conn,
                                        int id)
{
247
    virLXCDriverPtr driver = conn->privateData;
248 249
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
250

251
    vm = virDomainObjListFindByID(driver->domains, id);
252

D
Daniel Veillard 已提交
253
    if (!vm) {
254 255
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching id %d"), id);
256
        goto cleanup;
D
Daniel Veillard 已提交
257 258
    }

259 260 261
    if (virDomainLookupByIDEnsureACL(conn, vm->def) < 0)
        goto cleanup;

262
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid, vm->def->id);
D
Daniel Veillard 已提交
263

264
 cleanup:
265
    if (vm)
266
        virObjectUnlock(vm);
D
Daniel Veillard 已提交
267 268 269 270 271 272
    return dom;
}

static virDomainPtr lxcDomainLookupByUUID(virConnectPtr conn,
                                          const unsigned char *uuid)
{
273
    virLXCDriverPtr driver = conn->privateData;
274 275
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
276

277
    vm = virDomainObjListFindByUUIDRef(driver->domains, uuid);
278

D
Daniel Veillard 已提交
279
    if (!vm) {
280 281
        char uuidstr[VIR_UUID_STRING_BUFLEN];
        virUUIDFormat(uuid, uuidstr);
282 283
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching uuid '%s'"), uuidstr);
284
        goto cleanup;
D
Daniel Veillard 已提交
285 286
    }

287 288 289
    if (virDomainLookupByUUIDEnsureACL(conn, vm->def) < 0)
        goto cleanup;

290
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid, vm->def->id);
D
Daniel Veillard 已提交
291

292
 cleanup:
293
    virDomainObjEndAPI(&vm);
D
Daniel Veillard 已提交
294 295 296 297 298 299
    return dom;
}

static virDomainPtr lxcDomainLookupByName(virConnectPtr conn,
                                          const char *name)
{
300
    virLXCDriverPtr driver = conn->privateData;
301 302
    virDomainObjPtr vm;
    virDomainPtr dom = NULL;
D
Daniel Veillard 已提交
303

304
    vm = virDomainObjListFindByName(driver->domains, name);
D
Daniel Veillard 已提交
305
    if (!vm) {
306 307
        virReportError(VIR_ERR_NO_DOMAIN,
                       _("No domain with matching name '%s'"), name);
308
        goto cleanup;
D
Daniel Veillard 已提交
309 310
    }

311 312 313
    if (virDomainLookupByNameEnsureACL(conn, vm->def) < 0)
        goto cleanup;

314
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid, vm->def->id);
D
Daniel Veillard 已提交
315

316
 cleanup:
317
    virDomainObjEndAPI(&vm);
D
Daniel Veillard 已提交
318 319 320
    return dom;
}

321 322 323 324 325 326

static int lxcDomainIsActive(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
327
    if (!(obj = lxcDomObjFromDomain(dom)))
328
        goto cleanup;
329 330 331 332

    if (virDomainIsActiveEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

333 334
    ret = virDomainObjIsActive(obj);

335
 cleanup:
336
    virDomainObjEndAPI(&obj);
337 338 339 340 341 342 343 344 345
    return ret;
}


static int lxcDomainIsPersistent(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
346
    if (!(obj = lxcDomObjFromDomain(dom)))
347
        goto cleanup;
348 349 350 351

    if (virDomainIsPersistentEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

352 353
    ret = obj->persistent;

354
 cleanup:
355
    virDomainObjEndAPI(&obj);
356 357 358
    return ret;
}

359 360 361 362 363
static int lxcDomainIsUpdated(virDomainPtr dom)
{
    virDomainObjPtr obj;
    int ret = -1;

M
Michal Privoznik 已提交
364
    if (!(obj = lxcDomObjFromDomain(dom)))
365
        goto cleanup;
366 367 368 369

    if (virDomainIsUpdatedEnsureACL(dom->conn, obj->def) < 0)
        goto cleanup;

370 371
    ret = obj->updated;

372
 cleanup:
373
    virDomainObjEndAPI(&obj);
374 375
    return ret;
}
376

377 378
static int lxcConnectListDomains(virConnectPtr conn, int *ids, int nids)
{
379
    virLXCDriverPtr driver = conn->privateData;
380
    int n;
381

382 383 384
    if (virConnectListDomainsEnsureACL(conn) < 0)
        return -1;

385 386
    n = virDomainObjListGetActiveIDs(driver->domains, ids, nids,
                                     virConnectListDomainsCheckACL, conn);
387

388
    return n;
D
Daniel Veillard 已提交
389
}
390

391 392
static int lxcConnectNumOfDomains(virConnectPtr conn)
{
393
    virLXCDriverPtr driver = conn->privateData;
394
    int n;
395

396 397 398
    if (virConnectNumOfDomainsEnsureACL(conn) < 0)
        return -1;

399 400
    n = virDomainObjListNumOfDomains(driver->domains, true,
                                     virConnectNumOfDomainsCheckACL, conn);
401

402
    return n;
D
Daniel Veillard 已提交
403 404
}

405
static int lxcConnectListDefinedDomains(virConnectPtr conn,
406 407
                                        char **const names, int nnames)
{
408
    virLXCDriverPtr driver = conn->privateData;
409
    int n;
410

411 412 413
    if (virConnectListDefinedDomainsEnsureACL(conn) < 0)
        return -1;

414 415
    n = virDomainObjListGetInactiveNames(driver->domains, names, nnames,
                                         virConnectListDefinedDomainsCheckACL, conn);
416

417
    return n;
D
Daniel Veillard 已提交
418 419 420
}


421 422
static int lxcConnectNumOfDefinedDomains(virConnectPtr conn)
{
423
    virLXCDriverPtr driver = conn->privateData;
424
    int n;
425

426 427 428
    if (virConnectNumOfDefinedDomainsEnsureACL(conn) < 0)
        return -1;

429 430
    n = virDomainObjListNumOfDomains(driver->domains, false,
                                     virConnectNumOfDefinedDomainsCheckACL, conn);
431

432
    return n;
D
Daniel Veillard 已提交
433 434
}

435 436


437 438
static virDomainPtr
lxcDomainDefineXMLFlags(virConnectPtr conn, const char *xml, unsigned int flags)
D
Daniel Veillard 已提交
439
{
440
    virLXCDriverPtr driver = conn->privateData;
441
    virDomainDefPtr def = NULL;
442
    virDomainObjPtr vm = NULL;
443
    virDomainPtr dom = NULL;
444
    virObjectEventPtr event = NULL;
445
    virDomainDefPtr oldDef = NULL;
446
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
447
    virCapsPtr caps = NULL;
448
    unsigned int parse_flags = VIR_DOMAIN_DEF_PARSE_INACTIVE;
D
Daniel Veillard 已提交
449

450 451 452
    virCheckFlags(VIR_DOMAIN_DEFINE_VALIDATE, NULL);

    if (flags & VIR_DOMAIN_DEFINE_VALIDATE)
453
        parse_flags |= VIR_DOMAIN_DEF_PARSE_VALIDATE_SCHEMA;
454

455 456 457 458
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (!(def = virDomainDefParseString(xml, caps, driver->xmlopt,
459
                                        NULL, parse_flags)))
460
        goto cleanup;
D
Daniel Veillard 已提交
461

462 463 464
    if (virXMLCheckIllegalChars("name", def->name, "\n") < 0)
        goto cleanup;

465
    if (virDomainDefineXMLFlagsEnsureACL(conn, def) < 0)
466 467
        goto cleanup;

468 469 470
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

471
    if ((def->nets != NULL) && !(cfg->have_netns)) {
472 473
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
474
        goto cleanup;
475 476
    }

477
    if (!(vm = virDomainObjListAdd(driver->domains, def,
478
                                   driver->xmlopt,
479
                                   0, &oldDef)))
480
        goto cleanup;
481 482

    virObjectRef(vm);
483
    def = NULL;
484
    vm->persistent = 1;
D
Daniel Veillard 已提交
485

486
    if (virDomainSaveConfig(cfg->configDir, driver->caps,
487
                            vm->newDef ? vm->newDef : vm->def) < 0) {
488
        virDomainObjListRemove(driver->domains, vm);
489
        virObjectLock(vm);
490
        goto cleanup;
D
Daniel Veillard 已提交
491 492
    }

493
    event = virDomainEventLifecycleNewFromObj(vm,
494
                                     VIR_DOMAIN_EVENT_DEFINED,
495
                                     !oldDef ?
496 497 498
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED :
                                     VIR_DOMAIN_EVENT_DEFINED_UPDATED);

499
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid, vm->def->id);
D
Daniel Veillard 已提交
500

501
 cleanup:
502
    virDomainDefFree(def);
503
    virDomainDefFree(oldDef);
504
    virDomainObjEndAPI(&vm);
505
    if (event)
506
        virObjectEventStateQueue(driver->domainEventState, event);
507
    virObjectUnref(caps);
508
    virObjectUnref(cfg);
D
Daniel Veillard 已提交
509 510 511
    return dom;
}

512 513 514 515 516 517
static virDomainPtr
lxcDomainDefineXML(virConnectPtr conn, const char *xml)
{
    return lxcDomainDefineXMLFlags(conn, xml, 0);
}

518 519
static int lxcDomainUndefineFlags(virDomainPtr dom,
                                  unsigned int flags)
D
Daniel Veillard 已提交
520
{
521
    virLXCDriverPtr driver = dom->conn->privateData;
522
    virDomainObjPtr vm;
523
    virObjectEventPtr event = NULL;
524
    int ret = -1;
525
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
D
Daniel Veillard 已提交
526

527 528
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
529
    if (!(vm = lxcDomObjFromDomain(dom)))
530
        goto cleanup;
D
Daniel Veillard 已提交
531

532 533 534
    if (virDomainUndefineFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

535
    if (!vm->persistent) {
536 537
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot undefine transient domain"));
538
        goto cleanup;
539
    }
D
Daniel Veillard 已提交
540

541 542
    if (virDomainDeleteConfig(cfg->configDir,
                              cfg->autostartDir,
543 544
                              vm) < 0)
        goto cleanup;
D
Daniel Veillard 已提交
545

546
    event = virDomainEventLifecycleNewFromObj(vm,
547 548 549
                                     VIR_DOMAIN_EVENT_UNDEFINED,
                                     VIR_DOMAIN_EVENT_UNDEFINED_REMOVED);

550 551 552
    if (virDomainObjIsActive(vm)) {
        vm->persistent = 0;
    } else {
553
        virDomainObjListRemove(driver->domains, vm);
554
        virObjectLock(vm);
555 556
    }

557
    ret = 0;
D
Daniel Veillard 已提交
558

559
 cleanup:
560
    virDomainObjEndAPI(&vm);
561
    if (event)
562
        virObjectEventStateQueue(driver->domainEventState, event);
563
    virObjectUnref(cfg);
564
    return ret;
D
Daniel Veillard 已提交
565 566
}

567 568 569 570 571
static int lxcDomainUndefine(virDomainPtr dom)
{
    return lxcDomainUndefineFlags(dom, 0);
}

D
Daniel Veillard 已提交
572 573 574
static int lxcDomainGetInfo(virDomainPtr dom,
                            virDomainInfoPtr info)
{
575
    virDomainObjPtr vm;
576
    int ret = -1;
577
    virLXCDomainObjPrivatePtr priv;
D
Daniel Veillard 已提交
578

M
Michal Privoznik 已提交
579
    if (!(vm = lxcDomObjFromDomain(dom)))
580
        goto cleanup;
D
Daniel Veillard 已提交
581

582 583
    priv = vm->privateData;

584 585 586
    if (virDomainGetInfoEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

J
Jiri Denemark 已提交
587
    info->state = virDomainObjGetState(vm, NULL);
D
Daniel Veillard 已提交
588

589
    if (!virDomainObjIsActive(vm)) {
D
Daniel Veillard 已提交
590
        info->cpuTime = 0;
591
        info->memory = vm->def->mem.cur_balloon;
D
Daniel Veillard 已提交
592
    } else {
593
        if (virCgroupGetCpuacctUsage(priv->cgroup, &(info->cpuTime)) < 0) {
594 595
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Cannot read cputime for domain"));
R
Ryota Ozaki 已提交
596 597
            goto cleanup;
        }
598 599 600 601 602
        if (virCgroupGetMemoryUsage(priv->cgroup, &(info->memory)) < 0) {
            /* Don't fail if we can't read memory usage due to a lack of
             * kernel support */
            if (virLastErrorIsSystemErrno(ENOENT)) {
                virResetLastError();
603
                info->memory = 0;
604
            } else {
605
                goto cleanup;
606
            }
607
        }
D
Daniel Veillard 已提交
608 609
    }

610
    info->maxMem = virDomainDefGetMemoryTotal(vm->def);
611
    info->nrVirtCpu = virDomainDefGetVcpus(vm->def);
612
    ret = 0;
D
Daniel Veillard 已提交
613

614
 cleanup:
615
    virDomainObjEndAPI(&vm);
616
    return ret;
D
Daniel Veillard 已提交
617 618
}

619 620 621 622 623 624 625 626 627 628 629
static int
lxcDomainGetState(virDomainPtr dom,
                  int *state,
                  int *reason,
                  unsigned int flags)
{
    virDomainObjPtr vm;
    int ret = -1;

    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
630
    if (!(vm = lxcDomObjFromDomain(dom)))
631 632
        goto cleanup;

633 634 635
    if (virDomainGetStateEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

J
Jiri Denemark 已提交
636
    *state = virDomainObjGetState(vm, reason);
637 638
    ret = 0;

639
 cleanup:
640
    virDomainObjEndAPI(&vm);
641 642 643
    return ret;
}

644
static char *lxcDomainGetOSType(virDomainPtr dom)
D
Daniel Veillard 已提交
645
{
646 647
    virDomainObjPtr vm;
    char *ret = NULL;
648

M
Michal Privoznik 已提交
649
    if (!(vm = lxcDomObjFromDomain(dom)))
650
        goto cleanup;
651

652 653 654
    if (virDomainGetOSTypeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

655
    if (VIR_STRDUP(ret, virDomainOSTypeToString(vm->def->os.type)) < 0)
656
        goto cleanup;
657

658
 cleanup:
659
    virDomainObjEndAPI(&vm);
660
    return ret;
D
Daniel Veillard 已提交
661 662
}

R
Ryota Ozaki 已提交
663
/* Returns max memory in kb, 0 if error */
664 665 666
static unsigned long long
lxcDomainGetMaxMemory(virDomainPtr dom)
{
R
Ryota Ozaki 已提交
667
    virDomainObjPtr vm;
668
    unsigned long long ret = 0;
R
Ryota Ozaki 已提交
669

M
Michal Privoznik 已提交
670
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
671 672
        goto cleanup;

673 674 675
    if (virDomainGetMaxMemoryEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

676
    ret = virDomainDefGetMemoryTotal(vm->def);
R
Ryota Ozaki 已提交
677

678
 cleanup:
679
    virDomainObjEndAPI(&vm);
R
Ryota Ozaki 已提交
680 681 682
    return ret;
}

683 684
static int lxcDomainSetMemoryFlags(virDomainPtr dom, unsigned long newmem,
                                   unsigned int flags)
685
{
R
Ryota Ozaki 已提交
686
    virDomainObjPtr vm;
687
    virDomainDefPtr def = NULL;
688
    virDomainDefPtr persistentDef = NULL;
R
Ryota Ozaki 已提交
689
    int ret = -1;
690
    virLXCDomainObjPrivatePtr priv;
691 692 693 694
    virLXCDriverPtr driver = dom->conn->privateData;
    virLXCDriverConfigPtr cfg = NULL;

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
695 696
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_DOMAIN_MEM_MAXIMUM, -1);
R
Ryota Ozaki 已提交
697

M
Michal Privoznik 已提交
698
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
699
        goto cleanup;
M
Michal Privoznik 已提交
700

701 702
    cfg = virLXCDriverGetConfig(driver);

703
    priv = vm->privateData;
R
Ryota Ozaki 已提交
704

705
    if (virDomainSetMemoryFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
706 707
        goto cleanup;

708
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
709 710
        goto cleanup;

711
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
712
        goto endjob;
713

714
    if (flags & VIR_DOMAIN_MEM_MAXIMUM) {
715
        if (def) {
716 717 718
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("Cannot resize the max memory "
                             "on an active domain"));
719
            goto endjob;
720
        }
721

722
        if (persistentDef) {
723
            virDomainDefSetMemoryTotal(persistentDef, newmem);
724 725
            if (persistentDef->mem.cur_balloon > newmem)
                persistentDef->mem.cur_balloon = newmem;
726 727
            if (virDomainSaveConfig(cfg->configDir, driver->caps,
                                    persistentDef) < 0)
728
                goto endjob;
729 730 731
        }
    } else {
        unsigned long oldmax = 0;
R
Ryota Ozaki 已提交
732

733
        if (def)
734
            oldmax = virDomainDefGetMemoryTotal(def);
735
        if (persistentDef) {
736 737
            if (!oldmax || oldmax > virDomainDefGetMemoryTotal(persistentDef))
                oldmax = virDomainDefGetMemoryTotal(persistentDef);
738
        }
739

740 741 742
        if (newmem > oldmax) {
            virReportError(VIR_ERR_INVALID_ARG,
                           "%s", _("Cannot set memory higher than max memory"));
743
            goto endjob;
744 745
        }

746
        if (def) {
747 748 749
            if (virCgroupSetMemory(priv->cgroup, newmem) < 0) {
                virReportError(VIR_ERR_OPERATION_FAILED,
                               "%s", _("Failed to set memory for domain"));
750
                goto endjob;
751
            }
752

753
            def->mem.cur_balloon = newmem;
754
            if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0)
755
                goto endjob;
756 757
        }

758
        if (persistentDef) {
759
            persistentDef->mem.cur_balloon = newmem;
760 761
            if (virDomainSaveConfig(cfg->configDir, driver->caps,
                                    persistentDef) < 0)
762
                goto endjob;
763
        }
764 765
    }

R
Ryota Ozaki 已提交
766 767
    ret = 0;

768
 endjob:
769
    virLXCDomainObjEndJob(driver, vm);
770

771
 cleanup:
772
    virDomainObjEndAPI(&vm);
773
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
774 775 776
    return ret;
}

777 778 779 780 781
static int lxcDomainSetMemory(virDomainPtr dom, unsigned long newmem)
{
    return lxcDomainSetMemoryFlags(dom, newmem, VIR_DOMAIN_AFFECT_LIVE);
}

782 783 784 785 786
static int lxcDomainSetMaxMemory(virDomainPtr dom, unsigned long newmax)
{
    return lxcDomainSetMemoryFlags(dom, newmax, VIR_DOMAIN_MEM_MAXIMUM);
}

787 788 789 790 791
static int
lxcDomainSetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int nparams,
                             unsigned int flags)
792
{
793
    virDomainDefPtr def = NULL;
J
Ján Tomko 已提交
794
    virDomainDefPtr persistentDef = NULL;
795
    virDomainObjPtr vm = NULL;
796 797 798 799 800 801 802 803 804 805
    virLXCDomainObjPrivatePtr priv = NULL;
    virLXCDriverConfigPtr cfg = NULL;
    virLXCDriverPtr driver = dom->conn->privateData;
    unsigned long long hard_limit;
    unsigned long long soft_limit;
    unsigned long long swap_hard_limit;
    bool set_hard_limit = false;
    bool set_soft_limit = false;
    bool set_swap_hard_limit = false;
    int rc;
806 807
    int ret = -1;

808 809 810
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

811 812 813 814 815 816 817 818
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_MEMORY_HARD_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                               VIR_TYPED_PARAM_ULLONG,
                               NULL) < 0)
819
        return -1;
E
Eric Blake 已提交
820

M
Michal Privoznik 已提交
821
    if (!(vm = lxcDomObjFromDomain(dom)))
822
        goto cleanup;
M
Michal Privoznik 已提交
823

824
    priv = vm->privateData;
825
    cfg = virLXCDriverGetConfig(driver);
826

827
    if (virDomainSetMemoryParametersEnsureACL(dom->conn, vm->def, flags) < 0)
828 829
        goto cleanup;

830 831 832
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

833 834
    /* QEMU and LXC implementation are identical */
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
835 836
        goto endjob;

837
    if (def &&
838
        !virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_MEMORY)) {
839 840
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("cgroup memory controller is not mounted"));
841
        goto endjob;
842 843
    }

844 845 846 847 848
#define VIR_GET_LIMIT_PARAMETER(PARAM, VALUE) \
    if ((rc = virTypedParamsGetULLong(params, nparams, PARAM, &VALUE)) < 0) \
        goto endjob; \
 \
    if (rc == 1) \
849 850 851 852 853 854 855 856
        set_ ## VALUE = true;

    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT, swap_hard_limit)
    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_HARD_LIMIT, hard_limit)
    VIR_GET_LIMIT_PARAMETER(VIR_DOMAIN_MEMORY_SOFT_LIMIT, soft_limit)

#undef VIR_GET_LIMIT_PARAMETER

857
    /* Swap hard limit must be greater than hard limit. */
858 859 860 861 862 863 864 865 866 867
    if (set_swap_hard_limit || set_hard_limit) {
        unsigned long long mem_limit = vm->def->mem.hard_limit;
        unsigned long long swap_limit = vm->def->mem.swap_hard_limit;

        if (set_swap_hard_limit)
            swap_limit = swap_hard_limit;

        if (set_hard_limit)
            mem_limit = hard_limit;

868
        if (mem_limit > swap_limit) {
869 870 871
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("memory hard_limit tunable value must be lower "
                             "than or equal to swap_hard_limit"));
872
            goto endjob;
873 874 875
        }
    }

876 877 878 879 880 881 882 883 884 885
#define VIR_SET_MEM_PARAMETER(FUNC, VALUE) \
    if (set_ ## VALUE) { \
        if (def) { \
            if ((rc = FUNC(priv->cgroup, VALUE)) < 0) \
                goto endjob; \
            def->mem.VALUE = VALUE; \
        } \
 \
        if (persistentDef) \
            persistentDef->mem.VALUE = VALUE; \
886 887 888
    }

    /* Soft limit doesn't clash with the others */
889
    VIR_SET_MEM_PARAMETER(virCgroupSetMemorySoftLimit, soft_limit);
890 891

    /* set hard limit before swap hard limit if decreasing it */
892 893
    if (def && def->mem.hard_limit > hard_limit) {
        VIR_SET_MEM_PARAMETER(virCgroupSetMemoryHardLimit, hard_limit);
894 895 896 897
        /* inhibit changing the limit a second time */
        set_hard_limit = false;
    }

898
    VIR_SET_MEM_PARAMETER(virCgroupSetMemSwapHardLimit, swap_hard_limit);
899 900

    /* otherwise increase it after swap hard limit */
901 902 903
    VIR_SET_MEM_PARAMETER(virCgroupSetMemoryHardLimit, hard_limit);

#undef VIR_SET_MEM_PARAMETER
904

905 906 907
    if (def &&
        virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0)
        goto endjob;
908

909
    if (persistentDef &&
J
Ján Tomko 已提交
910
        virDomainSaveConfig(cfg->configDir, driver->caps, persistentDef) < 0)
911
        goto endjob;
912
    /* QEMU and LXC implementations are identical */
913 914

    ret = 0;
915 916

 endjob:
917
    virLXCDomainObjEndJob(driver, vm);
918

919
 cleanup:
920
    virDomainObjEndAPI(&vm);
921
    virObjectUnref(cfg);
922 923 924
    return ret;
}

925 926 927 928 929
static int
lxcDomainGetMemoryParameters(virDomainPtr dom,
                             virTypedParameterPtr params,
                             int *nparams,
                             unsigned int flags)
930
{
J
Ján Tomko 已提交
931
    virDomainDefPtr persistentDef = NULL;
932
    virDomainDefPtr def = NULL;
933
    virDomainObjPtr vm = NULL;
934
    virLXCDomainObjPrivatePtr priv = NULL;
935
    unsigned long long val;
936
    int ret = -1;
937
    size_t i;
938

939
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
940 941 942 943 944
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We don't return strings, and thus trivially support this flag.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;
E
Eric Blake 已提交
945

M
Michal Privoznik 已提交
946
    if (!(vm = lxcDomObjFromDomain(dom)))
947
        goto cleanup;
M
Michal Privoznik 已提交
948

949
    priv = vm->privateData;
950

951
    if (virDomainGetMemoryParametersEnsureACL(dom->conn, vm->def) < 0)
952 953
        goto cleanup;

954 955 956 957
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
        goto cleanup;

    if (def &&
958 959 960
        !virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_MEMORY)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup memory controller is not mounted"));
961
        goto cleanup;
962
    }
963

964 965 966 967 968 969 970
    if ((*nparams) == 0) {
        /* Current number of memory parameters supported by cgroups */
        *nparams = LXC_NB_MEM_PARAM;
        ret = 0;
        goto cleanup;
    }

971
    for (i = 0; i < LXC_NB_MEM_PARAM && i < *nparams; i++) {
972
        virTypedParameterPtr param = &params[i];
973 974
        val = 0;

975
        switch (i) {
976
        case 0: /* fill memory hard limit here */
977
            if (persistentDef) {
J
Ján Tomko 已提交
978
                val = persistentDef->mem.hard_limit;
979
            } else if (virCgroupGetMemoryHardLimit(priv->cgroup, &val) < 0) {
980
                goto cleanup;
981
            }
982 983
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
984
                goto cleanup;
985 986
            break;
        case 1: /* fill memory soft limit here */
987
            if (persistentDef) {
J
Ján Tomko 已提交
988
                val = persistentDef->mem.soft_limit;
989
            } else if (virCgroupGetMemorySoftLimit(priv->cgroup, &val) < 0) {
990
                goto cleanup;
991
            }
992 993
            if (virTypedParameterAssign(param, VIR_DOMAIN_MEMORY_SOFT_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
994
                goto cleanup;
995 996
            break;
        case 2: /* fill swap hard limit here */
997
            if (persistentDef) {
J
Ján Tomko 已提交
998
                val = persistentDef->mem.swap_hard_limit;
999
            } else if (virCgroupGetMemSwapHardLimit(priv->cgroup, &val) < 0) {
1000
                goto cleanup;
1001
            }
1002 1003 1004
            if (virTypedParameterAssign(param,
                                        VIR_DOMAIN_MEMORY_SWAP_HARD_LIMIT,
                                        VIR_TYPED_PARAM_ULLONG, val) < 0)
1005
                goto cleanup;
1006 1007 1008 1009
            break;
        }
    }

1010 1011
    if (*nparams > LXC_NB_MEM_PARAM)
        *nparams = LXC_NB_MEM_PARAM;
1012 1013
    ret = 0;

1014
 cleanup:
1015
    virDomainObjEndAPI(&vm);
1016 1017 1018
    return ret;
}

1019
static char *lxcDomainGetXMLDesc(virDomainPtr dom,
1020
                                 unsigned int flags)
D
Daniel Veillard 已提交
1021
{
1022
    virLXCDriverPtr driver = dom->conn->privateData;
1023 1024
    virDomainObjPtr vm;
    char *ret = NULL;
D
Daniel Veillard 已提交
1025

1026 1027
    /* Flags checked by virDomainDefFormat */

M
Michal Privoznik 已提交
1028
    if (!(vm = lxcDomObjFromDomain(dom)))
1029
        goto cleanup;
D
Daniel Veillard 已提交
1030

1031 1032 1033
    if (virDomainGetXMLDescEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

1034
    ret = virDomainDefFormat((flags & VIR_DOMAIN_XML_INACTIVE) &&
1035
                             vm->newDef ? vm->newDef : vm->def,
1036
                             driver->caps,
1037
                             virDomainDefFormatConvertXMLFlags(flags));
1038

1039
 cleanup:
1040
    virDomainObjEndAPI(&vm);
1041
    return ret;
D
Daniel Veillard 已提交
1042 1043
}

1044 1045 1046 1047 1048 1049 1050
static char *lxcConnectDomainXMLFromNative(virConnectPtr conn,
                                           const char *nativeFormat,
                                           const char *nativeConfig,
                                           unsigned int flags)
{
    char *xml = NULL;
    virDomainDefPtr def = NULL;
1051 1052
    virLXCDriverPtr driver = conn->privateData;
    virCapsPtr caps = virLXCDriverGetCapabilities(driver, false);
1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064

    virCheckFlags(0, NULL);

    if (virConnectDomainXMLFromNativeEnsureACL(conn) < 0)
        goto cleanup;

    if (STRNEQ(nativeFormat, LXC_CONFIG_FORMAT)) {
        virReportError(VIR_ERR_INVALID_ARG,
                       _("unsupported config type %s"), nativeFormat);
        goto cleanup;
    }

1065
    if (!(def = lxcParseConfigString(nativeConfig, caps, driver->xmlopt)))
1066 1067
        goto cleanup;

1068
    xml = virDomainDefFormat(def, caps, 0);
1069

1070
 cleanup:
1071
    virObjectUnref(caps);
1072 1073 1074 1075
    virDomainDefFree(def);
    return xml;
}

1076
/**
1077
 * lxcDomainCreateWithFiles:
1078
 * @dom: domain to start
1079
 * @flags: Must be 0 for now
1080 1081 1082 1083 1084
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
1085 1086 1087 1088
static int lxcDomainCreateWithFiles(virDomainPtr dom,
                                    unsigned int nfiles,
                                    int *files,
                                    unsigned int flags)
1089
{
1090
    virLXCDriverPtr driver = dom->conn->privateData;
1091
    virDomainObjPtr vm;
1092
    virObjectEventPtr event = NULL;
1093
    int ret = -1;
1094
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1095

1096
    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY, -1);
1097

1098 1099
    virNWFilterReadLockFilterUpdates();

M
Michal Privoznik 已提交
1100
    if (!(vm = lxcDomObjFromDomain(dom)))
1101 1102
        goto cleanup;

1103
    if (virDomainCreateWithFilesEnsureACL(dom->conn, vm->def) < 0)
1104 1105
        goto cleanup;

1106
    if ((vm->def->nets != NULL) && !(cfg->have_netns)) {
1107 1108
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("System lacks NETNS support"));
1109 1110 1111
        goto cleanup;
    }

1112 1113 1114
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

1115
    if (virDomainObjIsActive(vm)) {
1116 1117
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is already running"));
1118
        goto endjob;
1119 1120
    }

1121
    ret = virLXCProcessStart(dom->conn, driver, vm,
1122
                             nfiles, files,
1123 1124
                             (flags & VIR_DOMAIN_START_AUTODESTROY),
                             VIR_DOMAIN_RUNNING_BOOTED);
1125

1126
    if (ret == 0) {
1127
        event = virDomainEventLifecycleNewFromObj(vm,
1128 1129
                                         VIR_DOMAIN_EVENT_STARTED,
                                         VIR_DOMAIN_EVENT_STARTED_BOOTED);
1130 1131 1132 1133
        virDomainAuditStart(vm, "booted", true);
    } else {
        virDomainAuditStart(vm, "booted", false);
    }
1134

1135
 endjob:
1136
    virLXCDomainObjEndJob(driver, vm);
1137

1138
 cleanup:
1139
    virDomainObjEndAPI(&vm);
1140
    if (event)
1141
        virObjectEventStateQueue(driver->domainEventState, event);
1142
    virObjectUnref(cfg);
1143
    virNWFilterUnlockFilterUpdates();
1144
    return ret;
1145 1146
}

1147
/**
1148
 * lxcDomainCreate:
1149 1150 1151 1152 1153 1154
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
1155
static int lxcDomainCreate(virDomainPtr dom)
1156
{
1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171
    return lxcDomainCreateWithFiles(dom, 0, NULL, 0);
}

/**
 * lxcDomainCreateWithFlags:
 * @dom: domain to start
 *
 * Looks up domain and starts it.
 *
 * Returns 0 on success or -1 in case of error
 */
static int lxcDomainCreateWithFlags(virDomainPtr dom,
                                    unsigned int flags)
{
    return lxcDomainCreateWithFiles(dom, 0, NULL, flags);
1172 1173
}

1174
/**
1175
 * lxcDomainCreateXMLWithFiles:
1176 1177
 * @conn: pointer to connection
 * @xml: XML definition of domain
1178 1179 1180
 * @nfiles: number of file descriptors passed
 * @files: list of file descriptors passed
 * @flags: bitwise-OR of supported virDomainCreateFlags
1181 1182 1183
 *
 * Creates a domain based on xml and starts it
 *
1184
 * Returns a new domain object or NULL in case of failure.
1185 1186
 */
static virDomainPtr
1187 1188 1189 1190
lxcDomainCreateXMLWithFiles(virConnectPtr conn,
                            const char *xml,
                            unsigned int nfiles,
                            int *files,
1191 1192
                            unsigned int flags)
{
1193
    virLXCDriverPtr driver = conn->privateData;
1194
    virDomainObjPtr vm = NULL;
1195
    virDomainDefPtr def = NULL;
1196
    virDomainPtr dom = NULL;
1197
    virObjectEventPtr event = NULL;
1198
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1199
    virCapsPtr caps = NULL;
1200 1201 1202 1203 1204
    unsigned int parse_flags = VIR_DOMAIN_DEF_PARSE_INACTIVE;

    virCheckFlags(VIR_DOMAIN_START_AUTODESTROY |
                  VIR_DOMAIN_START_VALIDATE, NULL);

1205

1206
    if (flags & VIR_DOMAIN_START_VALIDATE)
1207
        parse_flags |= VIR_DOMAIN_DEF_PARSE_VALIDATE_SCHEMA;
1208

1209 1210
    virNWFilterReadLockFilterUpdates();

1211 1212 1213 1214
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

    if (!(def = virDomainDefParseString(xml, caps, driver->xmlopt,
1215
                                        NULL, parse_flags)))
1216
        goto cleanup;
1217

1218
    if (virDomainCreateXMLWithFilesEnsureACL(conn, def) < 0)
1219 1220
        goto cleanup;

1221 1222 1223
    if (virSecurityManagerVerify(driver->securityManager, def) < 0)
        goto cleanup;

1224
    if ((def->nets != NULL) && !(cfg->have_netns)) {
1225 1226
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       "%s", _("System lacks NETNS support"));
1227
        goto cleanup;
1228 1229
    }

1230

1231
    if (!(vm = virDomainObjListAdd(driver->domains, def,
1232
                                   driver->xmlopt,
1233
                                   VIR_DOMAIN_OBJ_LIST_ADD_LIVE |
1234 1235
                                   VIR_DOMAIN_OBJ_LIST_ADD_CHECK_LIVE,
                                   NULL)))
1236
        goto cleanup;
1237
    virObjectRef(vm);
1238
    def = NULL;
1239

1240 1241 1242
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0) {
        if (!vm->persistent) {
            virDomainObjListRemove(driver->domains, vm);
1243
            virObjectLock(vm);
1244 1245 1246 1247
        }
        goto cleanup;
    }

1248
    if (virLXCProcessStart(conn, driver, vm,
1249
                           nfiles, files,
1250 1251
                           (flags & VIR_DOMAIN_START_AUTODESTROY),
                           VIR_DOMAIN_RUNNING_BOOTED) < 0) {
1252
        virDomainAuditStart(vm, "booted", false);
1253
        virLXCDomainObjEndJob(driver, vm);
1254 1255
        if (!vm->persistent) {
            virDomainObjListRemove(driver->domains, vm);
1256
            virObjectLock(vm);
1257
        }
1258
        goto cleanup;
1259 1260
    }

1261
    event = virDomainEventLifecycleNewFromObj(vm,
1262 1263
                                     VIR_DOMAIN_EVENT_STARTED,
                                     VIR_DOMAIN_EVENT_STARTED_BOOTED);
1264
    virDomainAuditStart(vm, "booted", true);
1265

1266
    dom = virGetDomain(conn, vm->def->name, vm->def->uuid, vm->def->id);
1267

1268
    virLXCDomainObjEndJob(driver, vm);
1269

1270
 cleanup:
1271
    virDomainDefFree(def);
1272
    virDomainObjEndAPI(&vm);
1273
    if (event)
1274
        virObjectEventStateQueue(driver->domainEventState, event);
1275
    virObjectUnref(caps);
1276
    virObjectUnref(cfg);
1277
    virNWFilterUnlockFilterUpdates();
1278 1279 1280
    return dom;
}

1281 1282 1283 1284 1285 1286 1287 1288 1289 1290
/**
 * lxcDomainCreateXML:
 * @conn: pointer to connection
 * @xml: XML definition of domain
 * @flags: bitwise-OR of supported virDomainCreateFlags
 *
 * Creates a domain based on xml and starts it
 *
 * Returns a new domain object or NULL in case of failure.
 */
1291 1292 1293
static virDomainPtr
lxcDomainCreateXML(virConnectPtr conn,
                   const char *xml,
1294 1295
                   unsigned int flags)
{
1296 1297 1298 1299
    return lxcDomainCreateXMLWithFiles(conn, xml, 0, NULL,  flags);
}


1300 1301
static int lxcDomainGetSecurityLabel(virDomainPtr dom, virSecurityLabelPtr seclabel)
{
1302
    virLXCDriverPtr driver = dom->conn->privateData;
1303 1304 1305 1306 1307
    virDomainObjPtr vm;
    int ret = -1;

    memset(seclabel, 0, sizeof(*seclabel));

M
Michal Privoznik 已提交
1308
    if (!(vm = lxcDomObjFromDomain(dom)))
1309 1310
        goto cleanup;

1311 1312 1313
    if (virDomainGetSecurityLabelEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1314
    if (!virDomainVirtTypeToString(vm->def->virtType)) {
1315 1316 1317
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unknown virt type in domain definition '%d'"),
                       vm->def->virtType);
1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335
        goto cleanup;
    }

    /*
     * Theoretically, the pid can be replaced during this operation and
     * return the label of a different process.  If atomicity is needed,
     * further validation will be required.
     *
     * Comment from Dan Berrange:
     *
     *   Well the PID as stored in the virDomainObjPtr can't be changed
     *   because you've got a locked object.  The OS level PID could have
     *   exited, though and in extreme circumstances have cycled through all
     *   PIDs back to ours. We could sanity check that our PID still exists
     *   after reading the label, by checking that our FD connecting to the
     *   LXC monitor hasn't seen SIGHUP/ERR on poll().
     */
    if (virDomainObjIsActive(vm)) {
1336 1337 1338 1339 1340 1341 1342 1343
        virLXCDomainObjPrivatePtr priv = vm->privateData;

        if (!priv->initpid) {
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("Init pid is not yet available"));
            goto cleanup;
        }

1344
        if (virSecurityManagerGetProcessLabel(driver->securityManager,
1345 1346
                                              vm->def, priv->initpid,
                                              seclabel) < 0)
1347 1348 1349 1350 1351
            goto cleanup;
    }

    ret = 0;

1352
 cleanup:
1353
    virDomainObjEndAPI(&vm);
1354 1355 1356 1357 1358 1359
    return ret;
}

static int lxcNodeGetSecurityModel(virConnectPtr conn,
                                   virSecurityModelPtr secmodel)
{
1360
    virLXCDriverPtr driver = conn->privateData;
1361
    virCapsPtr caps = NULL;
1362 1363 1364 1365
    int ret = 0;

    memset(secmodel, 0, sizeof(*secmodel));

1366 1367 1368
    if (virNodeGetSecurityModelEnsureACL(conn) < 0)
        goto cleanup;

1369 1370 1371
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

1372
    /* we treat no driver as success, but simply return no data in *secmodel */
1373 1374
    if (caps->host.nsecModels == 0
        || caps->host.secModels[0].model == NULL)
1375 1376
        goto cleanup;

1377
    if (!virStrcpy(secmodel->model, caps->host.secModels[0].model,
1378
                   VIR_SECURITY_MODEL_BUFLEN)) {
1379 1380 1381
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security model string exceeds max %d bytes"),
                       VIR_SECURITY_MODEL_BUFLEN - 1);
1382 1383 1384 1385
        ret = -1;
        goto cleanup;
    }

1386
    if (!virStrcpy(secmodel->doi, caps->host.secModels[0].doi,
1387
                   VIR_SECURITY_DOI_BUFLEN)) {
1388 1389 1390
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security DOI string exceeds max %d bytes"),
                       VIR_SECURITY_DOI_BUFLEN-1);
1391 1392 1393 1394
        ret = -1;
        goto cleanup;
    }

1395
 cleanup:
1396
    virObjectUnref(caps);
1397 1398 1399 1400
    return ret;
}


1401
static int
1402 1403 1404 1405
lxcConnectDomainEventRegister(virConnectPtr conn,
                              virConnectDomainEventCallback callback,
                              void *opaque,
                              virFreeCallback freecb)
1406
{
1407
    virLXCDriverPtr driver = conn->privateData;
1408

1409 1410 1411
    if (virConnectDomainEventRegisterEnsureACL(conn) < 0)
        return -1;

1412 1413 1414 1415
    if (virDomainEventStateRegister(conn,
                                    driver->domainEventState,
                                    callback, opaque, freecb) < 0)
        return -1;
1416

1417
    return 0;
1418 1419
}

1420

1421
static int
1422 1423
lxcConnectDomainEventDeregister(virConnectPtr conn,
                                virConnectDomainEventCallback callback)
1424
{
1425
    virLXCDriverPtr driver = conn->privateData;
1426

1427 1428 1429
    if (virConnectDomainEventDeregisterEnsureACL(conn) < 0)
        return -1;

1430 1431 1432 1433
    if (virDomainEventStateDeregister(conn,
                                      driver->domainEventState,
                                      callback) < 0)
        return -1;
1434

1435
    return 0;
1436 1437
}

1438 1439

static int
1440 1441 1442 1443 1444 1445
lxcConnectDomainEventRegisterAny(virConnectPtr conn,
                                 virDomainPtr dom,
                                 int eventID,
                                 virConnectDomainEventGenericCallback callback,
                                 void *opaque,
                                 virFreeCallback freecb)
1446
{
1447
    virLXCDriverPtr driver = conn->privateData;
1448 1449
    int ret;

1450 1451 1452
    if (virConnectDomainEventRegisterAnyEnsureACL(conn) < 0)
        return -1;

1453 1454 1455 1456
    if (virDomainEventStateRegisterID(conn,
                                      driver->domainEventState,
                                      dom, eventID,
                                      callback, opaque, freecb, &ret) < 0)
1457
        ret = -1;
1458 1459 1460 1461 1462 1463

    return ret;
}


static int
1464 1465
lxcConnectDomainEventDeregisterAny(virConnectPtr conn,
                                   int callbackID)
1466
{
1467
    virLXCDriverPtr driver = conn->privateData;
1468

1469 1470 1471
    if (virConnectDomainEventDeregisterAnyEnsureACL(conn) < 0)
        return -1;

1472 1473
    if (virObjectEventStateDeregisterID(conn,
                                        driver->domainEventState,
1474
                                        callbackID, true) < 0)
1475
        return -1;
1476

1477
    return 0;
1478 1479 1480
}


1481
/**
1482
 * lxcDomainDestroyFlags:
1483
 * @dom: pointer to domain to destroy
1484
 * @flags: extra flags; not used yet.
1485 1486 1487 1488 1489
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
1490 1491 1492
static int
lxcDomainDestroyFlags(virDomainPtr dom,
                      unsigned int flags)
1493
{
1494
    virLXCDriverPtr driver = dom->conn->privateData;
1495
    virDomainObjPtr vm;
1496
    virObjectEventPtr event = NULL;
1497
    int ret = -1;
1498
    virLXCDomainObjPrivatePtr priv;
1499

1500 1501
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
1502
    if (!(vm = lxcDomObjFromDomain(dom)))
1503
        goto cleanup;
1504

1505 1506 1507
    if (virDomainDestroyFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1508 1509 1510
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

1511
    if (!virDomainObjIsActive(vm)) {
1512 1513
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
1514
        goto endjob;
1515 1516
    }

1517
    priv = vm->privateData;
1518
    ret = virLXCProcessStop(driver, vm, VIR_DOMAIN_SHUTOFF_DESTROYED);
1519
    event = virDomainEventLifecycleNewFromObj(vm,
1520 1521
                                     VIR_DOMAIN_EVENT_STOPPED,
                                     VIR_DOMAIN_EVENT_STOPPED_DESTROYED);
1522
    priv->doneStopEvent = true;
1523
    virDomainAuditStop(vm, "destroyed");
1524

1525
 endjob:
1526
    virLXCDomainObjEndJob(driver, vm);
1527
    if (!vm->persistent) {
1528
        virDomainObjListRemove(driver->domains, vm);
1529 1530
        virObjectLock(vm);
    }
1531

1532
 cleanup:
1533
    virDomainObjEndAPI(&vm);
1534
    if (event)
1535
        virObjectEventStateQueue(driver->domainEventState, event);
1536
    return ret;
1537
}
1538

1539 1540 1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551 1552
/**
 * lxcDomainDestroy:
 * @dom: pointer to domain to destroy
 *
 * Sends SIGKILL to container root process to terminate the container
 *
 * Returns 0 on success or -1 in case of error
 */
static int
lxcDomainDestroy(virDomainPtr dom)
{
    return lxcDomainDestroyFlags(dom, 0);
}

1553 1554 1555 1556 1557
static int lxcCheckNetNsSupport(void)
{
    const char *argv[] = {"ip", "link", "set", "lo", "netns", "-1", NULL};
    int ip_rc;

1558
    if (virRun(argv, &ip_rc) < 0 || ip_rc == 255)
1559
        return 0;
1560

1561
    if (virProcessNamespaceAvailable(VIR_PROCESS_NAMESPACE_NET) < 0)
1562
        return 0;
1563

1564
    return 1;
1565 1566
}

1567

1568 1569
static virSecurityManagerPtr
lxcSecurityInit(virLXCDriverConfigPtr cfg)
1570
{
1571 1572
    unsigned int flags = VIR_SECURITY_MANAGER_PRIVILEGED;

1573
    VIR_INFO("lxcSecurityInit %s", cfg->securityDriverName);
1574 1575 1576 1577 1578 1579

    if (cfg->securityDefaultConfined)
        flags |= VIR_SECURITY_MANAGER_DEFAULT_CONFINED;
    if (cfg->securityRequireConfined)
        flags |= VIR_SECURITY_MANAGER_REQUIRE_CONFINED;

1580
    virSecurityManagerPtr mgr = virSecurityManagerNew(cfg->securityDriverName,
1581
                                                      LXC_DRIVER_NAME, flags);
1582 1583 1584
    if (!mgr)
        goto error;

1585
    return mgr;
1586

1587
 error:
1588
    VIR_ERROR(_("Failed to initialize security drivers"));
1589
    virObjectUnref(mgr);
1590
    return NULL;
1591 1592 1593
}


1594 1595 1596
static int lxcStateInitialize(bool privileged,
                              virStateInhibitCallback callback ATTRIBUTE_UNUSED,
                              void *opaque ATTRIBUTE_UNUSED)
D
Daniel Veillard 已提交
1597
{
1598
    virCapsPtr caps = NULL;
1599
    const char *ld;
1600
    virLXCDriverConfigPtr cfg = NULL;
1601 1602 1603 1604 1605

    /* Valgrind gets very annoyed when we clone containers, so
     * disable LXC when under valgrind
     * XXX remove this when valgrind is fixed
     */
1606
    ld = virGetEnvBlockSUID("LD_PRELOAD");
1607
    if (ld && strstr(ld, "vgpreload")) {
1608
        VIR_INFO("Running under valgrind, disabling driver");
1609 1610
        return 0;
    }
1611

1612
    /* Check that the user is root, silently disable if not */
1613
    if (!privileged) {
1614
        VIR_INFO("Not running privileged, disabling driver");
1615 1616 1617 1618
        return 0;
    }

    /* Check that this is a container enabled kernel */
1619 1620 1621 1622
    if (virProcessNamespaceAvailable(VIR_PROCESS_NAMESPACE_MNT |
                                     VIR_PROCESS_NAMESPACE_PID |
                                     VIR_PROCESS_NAMESPACE_UTS |
                                     VIR_PROCESS_NAMESPACE_IPC) < 0) {
1623
        VIR_INFO("LXC support not available in this kernel, disabling driver");
1624
        return 0;
1625 1626
    }

1627
    if (VIR_ALLOC(lxc_driver) < 0)
1628
        return -1;
1629 1630 1631 1632
    if (virMutexInit(&lxc_driver->lock) < 0) {
        VIR_FREE(lxc_driver);
        return -1;
    }
D
Daniel Veillard 已提交
1633

1634
    if (!(lxc_driver->domains = virDomainObjListNew()))
1635 1636
        goto cleanup;

1637
    lxc_driver->domainEventState = virObjectEventStateNew();
1638
    if (!lxc_driver->domainEventState)
1639 1640
        goto cleanup;

1641 1642
    lxc_driver->hostsysinfo = virSysinfoRead();

1643 1644 1645 1646 1647
    if (!(lxc_driver->config = cfg = virLXCDriverConfigNew()))
        goto cleanup;

    cfg->log_libvirtd = 0; /* by default log to container logfile */
    cfg->have_netns = lxcCheckNetNsSupport();
D
Daniel Veillard 已提交
1648 1649

    /* Call function to load lxc driver configuration information */
1650
    if (virLXCLoadDriverConfig(cfg, SYSCONFDIR "/libvirt/lxc.conf") < 0)
1651
        goto cleanup;
D
Daniel Veillard 已提交
1652

1653
    if (!(lxc_driver->securityManager = lxcSecurityInit(cfg)))
1654 1655
        goto cleanup;

1656
    if (!(lxc_driver->hostdevMgr = virHostdevManagerGetDefault()))
G
Guido Günther 已提交
1657 1658
        goto cleanup;

1659
    if (!(caps = virLXCDriverGetCapabilities(lxc_driver, true)))
1660
        goto cleanup;
D
Daniel Veillard 已提交
1661

1662
    if (!(lxc_driver->xmlopt = lxcDomainXMLConfInit()))
1663
        goto cleanup;
1664

1665
    if (!(lxc_driver->closeCallbacks = virCloseCallbacksNew()))
1666 1667
        goto cleanup;

1668 1669 1670 1671 1672 1673 1674
    if (virFileMakePath(cfg->stateDir) < 0) {
        virReportSystemError(errno,
                             _("Failed to mkdir %s"),
                             cfg->stateDir);
        goto cleanup;
    }

O
Osier Yang 已提交
1675
    /* Get all the running persistent or transient configs first */
1676
    if (virDomainObjListLoadAllConfigs(lxc_driver->domains,
1677
                                       cfg->stateDir,
1678
                                       NULL, true,
1679
                                       caps,
1680
                                       lxc_driver->xmlopt,
1681
                                       NULL, NULL) < 0)
O
Osier Yang 已提交
1682 1683
        goto cleanup;

1684
    virLXCProcessReconnectAll(lxc_driver, lxc_driver->domains);
O
Osier Yang 已提交
1685 1686

    /* Then inactive persistent configs */
1687
    if (virDomainObjListLoadAllConfigs(lxc_driver->domains,
1688
                                       cfg->configDir,
1689
                                       cfg->autostartDir, false,
1690
                                       caps,
1691
                                       lxc_driver->xmlopt,
1692
                                       NULL, NULL) < 0)
1693
        goto cleanup;
1694

1695
    virNWFilterRegisterCallbackDriver(&lxcCallbackDriver);
1696
    virObjectUnref(caps);
D
Daniel Veillard 已提交
1697 1698
    return 0;

1699
 cleanup:
1700
    virObjectUnref(caps);
1701
    lxcStateCleanup();
1702
    return -1;
D
Daniel Veillard 已提交
1703 1704
}

1705 1706 1707 1708 1709 1710 1711 1712 1713 1714 1715 1716 1717
/**
 * lxcStateAutoStart:
 *
 * Function to autostart the LXC daemons
 */
static void lxcStateAutoStart(void)
{
    if (!lxc_driver)
        return;

    virLXCProcessAutostartAll(lxc_driver);
}

1718 1719
static void lxcNotifyLoadDomain(virDomainObjPtr vm, int newVM, void *opaque)
{
1720
    virLXCDriverPtr driver = opaque;
1721 1722

    if (newVM) {
1723
        virObjectEventPtr event =
1724
            virDomainEventLifecycleNewFromObj(vm,
1725 1726 1727
                                     VIR_DOMAIN_EVENT_DEFINED,
                                     VIR_DOMAIN_EVENT_DEFINED_ADDED);
        if (event)
1728
            virObjectEventStateQueue(driver->domainEventState, event);
1729 1730 1731 1732
    }
}

/**
1733
 * lxcStateReload:
1734 1735 1736 1737 1738
 *
 * Function to restart the LXC driver, it will recheck the configuration
 * files and perform autostart
 */
static int
1739 1740
lxcStateReload(void)
{
1741
    virLXCDriverConfigPtr cfg = NULL;
1742
    virCapsPtr caps = NULL;
1743

1744 1745 1746
    if (!lxc_driver)
        return 0;

1747
    if (!(caps = virLXCDriverGetCapabilities(lxc_driver, false)))
1748 1749
        return -1;

1750 1751
    cfg = virLXCDriverGetConfig(lxc_driver);

1752
    virDomainObjListLoadAllConfigs(lxc_driver->domains,
1753
                                   cfg->configDir,
1754
                                   cfg->autostartDir, false,
1755
                                   caps,
1756
                                   lxc_driver->xmlopt,
1757
                                   lxcNotifyLoadDomain, lxc_driver);
1758
    virObjectUnref(caps);
1759
    virObjectUnref(cfg);
1760 1761 1762
    return 0;
}

1763
static int lxcStateCleanup(void)
D
Daniel Veillard 已提交
1764
{
1765
    if (lxc_driver == NULL)
1766
        return -1;
1767

1768
    virNWFilterUnRegisterCallbackDriver(&lxcCallbackDriver);
1769
    virObjectUnref(lxc_driver->domains);
1770
    virObjectUnref(lxc_driver->domainEventState);
1771

1772
    virObjectUnref(lxc_driver->closeCallbacks);
1773

1774 1775
    virSysinfoDefFree(lxc_driver->hostsysinfo);

1776
    virObjectUnref(lxc_driver->hostdevMgr);
1777
    virObjectUnref(lxc_driver->caps);
1778
    virObjectUnref(lxc_driver->securityManager);
1779
    virObjectUnref(lxc_driver->xmlopt);
1780
    virObjectUnref(lxc_driver->config);
1781
    virMutexDestroy(&lxc_driver->lock);
1782
    VIR_FREE(lxc_driver);
1783 1784 1785

    return 0;
}
D
Daniel Veillard 已提交
1786

1787 1788 1789 1790 1791 1792
static int
lxcConnectSupportsFeature(virConnectPtr conn, int feature)
{
    if (virConnectSupportsFeatureEnsureACL(conn) < 0)
        return -1;

1793 1794 1795 1796 1797 1798 1799 1800 1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811
    switch ((virDrvFeature) feature) {
    case VIR_DRV_FEATURE_TYPED_PARAM_STRING:
        return 1;
    case VIR_DRV_FEATURE_FD_PASSING:
    case VIR_DRV_FEATURE_MIGRATE_CHANGE_PROTECTION:
    case VIR_DRV_FEATURE_MIGRATION_DIRECT:
    case VIR_DRV_FEATURE_MIGRATION_OFFLINE:
    case VIR_DRV_FEATURE_MIGRATION_P2P:
    case VIR_DRV_FEATURE_MIGRATION_PARAMS:
    case VIR_DRV_FEATURE_MIGRATION_V1:
    case VIR_DRV_FEATURE_MIGRATION_V2:
    case VIR_DRV_FEATURE_MIGRATION_V3:
    case VIR_DRV_FEATURE_PROGRAM_KEEPALIVE:
    case VIR_DRV_FEATURE_REMOTE:
    case VIR_DRV_FEATURE_REMOTE_CLOSE_CALLBACK:
    case VIR_DRV_FEATURE_REMOTE_EVENT_CALLBACK:
    case VIR_DRV_FEATURE_XML_MIGRATABLE:
    default:
        return 0;
1812 1813 1814
    }
}

D
Daniel Veillard 已提交
1815

1816
static int lxcConnectGetVersion(virConnectPtr conn, unsigned long *version)
D
Dan Smith 已提交
1817 1818 1819
{
    struct utsname ver;

1820
    uname(&ver);
D
Dan Smith 已提交
1821

1822 1823 1824
    if (virConnectGetVersionEnsureACL(conn) < 0)
        return -1;

1825
    if (virParseVersionString(ver.release, version, true) < 0) {
1826
        virReportError(VIR_ERR_INTERNAL_ERROR, _("Unknown release: %s"), ver.release);
D
Dan Smith 已提交
1827 1828 1829 1830 1831
        return -1;
    }

    return 0;
}
1832

1833

1834
static char *lxcConnectGetHostname(virConnectPtr conn)
1835
{
1836 1837 1838
    if (virConnectGetHostnameEnsureACL(conn) < 0)
        return NULL;

1839 1840 1841 1842
    return virGetHostname();
}


1843 1844
static char *lxcDomainGetSchedulerType(virDomainPtr dom,
                                       int *nparams)
1845
{
1846
    char *ret = NULL;
1847 1848
    virDomainObjPtr vm;
    virLXCDomainObjPrivatePtr priv;
1849

M
Michal Privoznik 已提交
1850
    if (!(vm = lxcDomObjFromDomain(dom)))
1851
        goto cleanup;
M
Michal Privoznik 已提交
1852

1853 1854
    priv = vm->privateData;

1855 1856 1857
    if (virDomainGetSchedulerTypeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

1858 1859 1860 1861 1862 1863 1864 1865
    /* Domain not running, thus no cgroups - return defaults */
    if (!virDomainObjIsActive(vm)) {
        if (nparams)
            *nparams = 3;
        ignore_value(VIR_STRDUP(ret, "posix"));
        goto cleanup;
    }

1866
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
1867 1868
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
1869 1870
        goto cleanup;
    }
1871

1872
    if (nparams) {
1873
        if (virCgroupSupportsCpuBW(priv->cgroup))
1874
            *nparams = 3;
1875 1876
        else
            *nparams = 1;
1877
    }
1878

1879
    ignore_value(VIR_STRDUP(ret, "posix"));
1880

1881
 cleanup:
1882
    virDomainObjEndAPI(&vm);
1883 1884 1885 1886 1887 1888 1889 1890
    return ret;
}


static int
lxcGetVcpuBWLive(virCgroupPtr cgroup, unsigned long long *period,
                 long long *quota)
{
1891
    if (virCgroupGetCpuCfsPeriod(cgroup, period) < 0)
1892 1893
        return -1;

1894
    if (virCgroupGetCpuCfsQuota(cgroup, quota) < 0)
1895 1896 1897 1898 1899 1900 1901 1902 1903 1904 1905 1906 1907 1908 1909 1910
        return -1;

    return 0;
}


static int lxcSetVcpuBWLive(virCgroupPtr cgroup, unsigned long long period,
                            long long quota)
{
    unsigned long long old_period;

    if (period == 0 && quota == 0)
        return 0;

    if (period) {
        /* get old period, and we can rollback if set quota failed */
1911
        if (virCgroupGetCpuCfsPeriod(cgroup, &old_period) < 0)
1912 1913
            return -1;

1914
        if (virCgroupSetCpuCfsPeriod(cgroup, period) < 0)
1915 1916 1917 1918
            return -1;
    }

    if (quota) {
1919 1920
        if (virCgroupSetCpuCfsQuota(cgroup, quota) < 0)
            goto error;
1921 1922 1923 1924
    }

    return 0;

1925
 error:
1926
    if (period) {
1927 1928 1929 1930 1931 1932
        virErrorPtr saved = virSaveLastError();
        virCgroupSetCpuCfsPeriod(cgroup, old_period);
        if (saved) {
            virSetError(saved);
            virFreeError(saved);
        }
1933 1934 1935
    }

    return -1;
1936 1937
}

1938

1939
static int
1940 1941 1942 1943
lxcDomainSetSchedulerParametersFlags(virDomainPtr dom,
                                     virTypedParameterPtr params,
                                     int nparams,
                                     unsigned int flags)
1944
{
1945
    virLXCDriverPtr driver = dom->conn->privateData;
1946
    virCapsPtr caps = NULL;
1947
    size_t i;
1948
    virDomainObjPtr vm = NULL;
1949
    virDomainDefPtr def = NULL;
J
Ján Tomko 已提交
1950 1951
    virDomainDefPtr persistentDefCopy = NULL;
    virDomainDefPtr persistentDef = NULL;
1952
    int ret = -1;
1953
    int rc;
1954
    virLXCDomainObjPrivatePtr priv;
1955
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
1956

1957 1958
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
1959 1960 1961 1962 1963 1964 1965 1966
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                               VIR_TYPED_PARAM_ULLONG,
                               VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                               VIR_TYPED_PARAM_LLONG,
                               NULL) < 0)
1967
        return -1;
1968

M
Michal Privoznik 已提交
1969
    if (!(vm = lxcDomObjFromDomain(dom)))
1970
        goto cleanup;
M
Michal Privoznik 已提交
1971

1972
    priv = vm->privateData;
1973

1974 1975 1976
    if (virDomainSetSchedulerParametersFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

1977 1978 1979
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

1980 1981 1982
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

1983
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
1984
        goto endjob;
1985

1986
    if (persistentDef) {
1987
        /* Make a copy for updated domain. */
J
Ján Tomko 已提交
1988 1989
        persistentDefCopy = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
        if (!persistentDefCopy)
1990
            goto endjob;
1991 1992
    }

1993
    if (def) {
1994
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
1995 1996
            virReportError(VIR_ERR_OPERATION_INVALID,
                           "%s", _("cgroup CPU controller is not mounted"));
1997
            goto endjob;
1998 1999
        }
    }
2000 2001

    for (i = 0; i < nparams; i++) {
2002
        virTypedParameterPtr param = &params[i];
2003

2004
        if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_CPU_SHARES)) {
2005
            if (def) {
2006
                unsigned long long val;
2007
                if (virCgroupSetCpuShares(priv->cgroup, params[i].value.ul) < 0)
2008
                    goto endjob;
2009

2010
                if (virCgroupGetCpuShares(priv->cgroup, &val) < 0)
2011
                    goto endjob;
2012

2013 2014
                def->cputune.shares = val;
                def->cputune.sharesSpecified = true;
2015 2016
            }

2017
            if (persistentDef) {
J
Ján Tomko 已提交
2018 2019
                persistentDefCopy->cputune.shares = params[i].value.ul;
                persistentDefCopy->cputune.sharesSpecified = true;
2020 2021
            }
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_PERIOD)) {
2022
            if (def) {
2023
                rc = lxcSetVcpuBWLive(priv->cgroup, params[i].value.ul, 0);
2024
                if (rc != 0)
2025
                    goto endjob;
2026 2027

                if (params[i].value.ul)
2028
                    def->cputune.period = params[i].value.ul;
2029 2030
            }

2031
            if (persistentDef)
J
Ján Tomko 已提交
2032
                persistentDefCopy->cputune.period = params[i].value.ul;
2033
        } else if (STREQ(param->field, VIR_DOMAIN_SCHEDULER_VCPU_QUOTA)) {
2034
            if (def) {
2035
                rc = lxcSetVcpuBWLive(priv->cgroup, 0, params[i].value.l);
2036
                if (rc != 0)
2037
                    goto endjob;
2038 2039

                if (params[i].value.l)
2040
                    def->cputune.quota = params[i].value.l;
2041 2042
            }

2043
            if (persistentDef)
J
Ján Tomko 已提交
2044
                persistentDefCopy->cputune.quota = params[i].value.l;
2045
        }
2046
    }
2047

2048
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0)
2049
        goto endjob;
2050

2051

2052
    if (persistentDef) {
J
Ján Tomko 已提交
2053
        rc = virDomainSaveConfig(cfg->configDir, driver->caps, persistentDefCopy);
2054
        if (rc < 0)
2055
            goto endjob;
2056

J
Ján Tomko 已提交
2057 2058
        virDomainObjAssignDef(vm, persistentDefCopy, false, NULL);
        persistentDefCopy = NULL;
2059
    }
2060

2061
    ret = 0;
2062

2063
 endjob:
2064
    virLXCDomainObjEndJob(driver, vm);
2065

2066
 cleanup:
J
Ján Tomko 已提交
2067
    virDomainDefFree(persistentDefCopy);
2068
    virDomainObjEndAPI(&vm);
2069
    virObjectUnref(caps);
2070
    virObjectUnref(cfg);
2071
    return ret;
2072 2073
}

2074
static int
2075 2076 2077
lxcDomainSetSchedulerParameters(virDomainPtr domain,
                                virTypedParameterPtr params,
                                int nparams)
2078
{
2079
    return lxcDomainSetSchedulerParametersFlags(domain, params, nparams, 0);
2080 2081 2082
}

static int
2083 2084 2085 2086
lxcDomainGetSchedulerParametersFlags(virDomainPtr dom,
                                     virTypedParameterPtr params,
                                     int *nparams,
                                     unsigned int flags)
2087
{
2088
    virDomainObjPtr vm = NULL;
2089
    virDomainDefPtr def;
E
Eric Blake 已提交
2090
    virDomainDefPtr persistentDef;
2091 2092 2093
    unsigned long long shares = 0;
    unsigned long long period = 0;
    long long quota = 0;
2094
    int ret = -1;
2095 2096 2097
    int rc;
    bool cpu_bw_status = false;
    int saved_nparams = 0;
2098
    virLXCDomainObjPrivatePtr priv;
2099

2100
    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
2101 2102 2103 2104 2105
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We don't return strings, and thus trivially support this flag.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;
2106

M
Michal Privoznik 已提交
2107
    if (!(vm = lxcDomObjFromDomain(dom)))
2108
        goto cleanup;
M
Michal Privoznik 已提交
2109

2110 2111
    priv = vm->privateData;

2112 2113 2114
    if (virDomainGetSchedulerParametersFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2115 2116
    if (*nparams > 1)
        cpu_bw_status = virCgroupSupportsCpuBW(priv->cgroup);
2117

2118
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
E
Eric Blake 已提交
2119
        goto cleanup;
2120

2121
    if (persistentDef) {
E
Eric Blake 已提交
2122
        shares = persistentDef->cputune.shares;
2123
        if (*nparams > 1) {
E
Eric Blake 已提交
2124 2125
            period = persistentDef->cputune.period;
            quota = persistentDef->cputune.quota;
2126
            cpu_bw_status = true; /* Allow copy of data to params[] */
2127 2128 2129 2130
        }
        goto out;
    }

2131
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPU)) {
2132 2133
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPU controller is not mounted"));
2134
        goto cleanup;
2135 2136
    }

2137
    if (virCgroupGetCpuShares(priv->cgroup, &shares) < 0)
2138
        goto cleanup;
2139 2140

    if (*nparams > 1 && cpu_bw_status) {
2141
        rc = lxcGetVcpuBWLive(priv->cgroup, &period, &quota);
2142 2143 2144
        if (rc != 0)
            goto cleanup;
    }
2145
 out:
2146 2147
    if (virTypedParameterAssign(&params[0], VIR_DOMAIN_SCHEDULER_CPU_SHARES,
                                VIR_TYPED_PARAM_ULLONG, shares) < 0)
C
Chris Lalancette 已提交
2148
        goto cleanup;
2149 2150 2151 2152
    saved_nparams++;

    if (cpu_bw_status) {
        if (*nparams > saved_nparams) {
2153 2154 2155
            if (virTypedParameterAssign(&params[1],
                                        VIR_DOMAIN_SCHEDULER_VCPU_PERIOD,
                                        VIR_TYPED_PARAM_ULLONG, period) < 0)
2156 2157 2158 2159 2160
                goto cleanup;
            saved_nparams++;
        }

        if (*nparams > saved_nparams) {
2161 2162 2163
            if (virTypedParameterAssign(&params[2],
                                        VIR_DOMAIN_SCHEDULER_VCPU_QUOTA,
                                        VIR_TYPED_PARAM_LLONG, quota) < 0)
2164 2165 2166 2167 2168 2169 2170
                goto cleanup;
            saved_nparams++;
        }
    }

    *nparams = saved_nparams;

2171
    ret = 0;
2172

2173
 cleanup:
2174
    virDomainObjEndAPI(&vm);
2175
    return ret;
2176 2177
}

2178
static int
2179 2180 2181
lxcDomainGetSchedulerParameters(virDomainPtr domain,
                                virTypedParameterPtr params,
                                int *nparams)
2182
{
2183
    return lxcDomainGetSchedulerParametersFlags(domain, params, nparams, 0);
2184 2185
}

2186 2187 2188 2189 2190 2191 2192 2193 2194 2195 2196 2197 2198 2199 2200 2201 2202 2203 2204 2205 2206 2207 2208 2209 2210 2211 2212 2213
static int
lxcDomainParseBlkioDeviceStr(char *blkioDeviceStr, const char *type,
                             virBlkioDevicePtr *dev, size_t *size)
{
    char *temp;
    int ndevices = 0;
    int nsep = 0;
    size_t i;
    virBlkioDevicePtr result = NULL;

    *dev = NULL;
    *size = 0;

    if (STREQ(blkioDeviceStr, ""))
        return 0;

    temp = blkioDeviceStr;
    while (temp) {
        temp = strchr(temp, ',');
        if (temp) {
            temp++;
            nsep++;
        }
    }

    /* A valid string must have even number of fields, hence an odd
     * number of commas.  */
    if (!(nsep & 1))
2214
        goto parse_error;
2215 2216 2217 2218 2219 2220 2221 2222 2223 2224 2225 2226 2227 2228

    ndevices = (nsep + 1) / 2;

    if (VIR_ALLOC_N(result, ndevices) < 0)
        return -1;

    i = 0;
    temp = blkioDeviceStr;
    while (temp) {
        char *p = temp;

        /* device path */
        p = strchr(p, ',');
        if (!p)
2229
            goto parse_error;
2230 2231 2232 2233 2234 2235 2236 2237

        if (VIR_STRNDUP(result[i].path, temp, p - temp) < 0)
            goto cleanup;

        /* value */
        temp = p + 1;

        if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT)) {
2238
            if (virStrToLong_uip(temp, &p, 10, &result[i].weight) < 0)
2239
                goto number_error;
2240
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS)) {
2241
            if (virStrToLong_uip(temp, &p, 10, &result[i].riops) < 0)
2242
                goto number_error;
2243
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS)) {
2244
            if (virStrToLong_uip(temp, &p, 10, &result[i].wiops) < 0)
2245
                goto number_error;
2246
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS)) {
2247
            if (virStrToLong_ullp(temp, &p, 10, &result[i].rbps) < 0)
2248
                goto number_error;
2249
        } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
2250
            if (virStrToLong_ullp(temp, &p, 10, &result[i].wbps) < 0)
2251
                goto number_error;
2252
        } else {
2253 2254 2255
            virReportError(VIR_ERR_INVALID_ARG,
                           _("unknown parameter '%s'"), type);
            goto cleanup;
2256 2257 2258 2259 2260 2261 2262
        }

        i++;

        if (*p == '\0')
            break;
        else if (*p != ',')
2263
            goto parse_error;
2264 2265 2266 2267 2268 2269 2270 2271 2272 2273 2274
        temp = p + 1;
    }

    if (!i)
        VIR_FREE(result);

    *dev = result;
    *size = i;

    return 0;

2275
 parse_error:
2276 2277 2278
    virReportError(VIR_ERR_INVALID_ARG,
                   _("unable to parse blkio device '%s' '%s'"),
                   type, blkioDeviceStr);
2279 2280 2281 2282 2283 2284 2285
    goto cleanup;

 number_error:
    virReportError(VIR_ERR_INVALID_ARG,
                   _("invalid value '%s' for parameter '%s' of device '%s'"),
                   temp, type, result[i].path);

2286
 cleanup:
J
John Ferlan 已提交
2287 2288 2289 2290
    if (result) {
        virBlkioDeviceArrayClear(result, ndevices);
        VIR_FREE(result);
    }
2291 2292 2293 2294 2295 2296 2297 2298 2299 2300 2301 2302 2303 2304 2305 2306 2307 2308 2309 2310 2311 2312
    return -1;
}

static int
lxcDomainMergeBlkioDevice(virBlkioDevicePtr *dest_array,
                          size_t *dest_size,
                          virBlkioDevicePtr src_array,
                          size_t src_size,
                          const char *type)
{
    size_t i, j;
    virBlkioDevicePtr dest, src;

    for (i = 0; i < src_size; i++) {
        bool found = false;

        src = &src_array[i];
        for (j = 0; j < *dest_size; j++) {
            dest = &(*dest_array)[j];
            if (STREQ(src->path, dest->path)) {
                found = true;

2313
                if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT)) {
2314
                    dest->weight = src->weight;
2315
                } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS)) {
2316
                    dest->riops = src->riops;
2317
                } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS)) {
2318
                    dest->wiops = src->wiops;
2319
                } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS)) {
2320
                    dest->rbps = src->rbps;
2321
                } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
2322
                    dest->wbps = src->wbps;
2323
                } else {
2324 2325 2326 2327 2328 2329 2330 2331 2332 2333 2334 2335 2336 2337 2338
                    virReportError(VIR_ERR_INVALID_ARG, _("Unknown parameter %s"),
                                   type);
                    return -1;
                }

                break;
            }
        }
        if (!found) {
            if (!src->weight && !src->riops && !src->wiops && !src->rbps && !src->wbps)
                continue;
            if (VIR_EXPAND_N(*dest_array, *dest_size, 1) < 0)
                return -1;
            dest = &(*dest_array)[*dest_size - 1];

2339
            if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT)) {
2340
                dest->weight = src->weight;
2341
            } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS)) {
2342
                dest->riops = src->riops;
2343
            } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS)) {
2344
                dest->wiops = src->wiops;
2345
            } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS)) {
2346
                dest->rbps = src->rbps;
2347
            } else if (STREQ(type, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
2348
                dest->wbps = src->wbps;
2349
            } else {
2350 2351 2352 2353 2354 2355 2356 2357 2358 2359 2360 2361
                *dest_size = *dest_size - 1;
                return -1;
            }

            dest->path = src->path;
            src->path = NULL;
        }
    }

    return 0;
}

2362

2363 2364 2365
static int
lxcDomainBlockStats(virDomainPtr dom,
                    const char *path,
2366
                    virDomainBlockStatsPtr stats)
2367
{
2368
    virLXCDriverPtr driver = dom->conn->privateData;
2369
    int ret = -1;
2370 2371 2372 2373 2374 2375 2376 2377 2378 2379 2380 2381
    virDomainObjPtr vm;
    virDomainDiskDefPtr disk = NULL;
    virLXCDomainObjPrivatePtr priv;

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    priv = vm->privateData;

    if (virDomainBlockStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2382 2383 2384
   if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_QUERY) < 0)
        goto cleanup;

2385 2386 2387
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
2388
        goto endjob;
2389 2390 2391 2392 2393
    }

    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("blkio cgroup isn't mounted"));
2394
        goto endjob;
2395 2396 2397 2398 2399 2400 2401 2402 2403
    }

    if (!*path) {
        /* empty path - return entire domain blkstats instead */
        ret = virCgroupGetBlkioIoServiced(priv->cgroup,
                                          &stats->rd_bytes,
                                          &stats->wr_bytes,
                                          &stats->rd_req,
                                          &stats->wr_req);
2404
        goto endjob;
2405 2406
    }

2407
    if (!(disk = virDomainDiskByName(vm->def, path, false))) {
2408 2409
        virReportError(VIR_ERR_INVALID_ARG,
                       _("invalid path: %s"), path);
2410
        goto endjob;
2411 2412 2413 2414 2415
    }

    if (!disk->info.alias) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("missing disk device alias name for %s"), disk->dst);
2416
        goto endjob;
2417 2418 2419 2420 2421 2422 2423 2424
    }

    ret = virCgroupGetBlkioIoDeviceServiced(priv->cgroup,
                                            disk->info.alias,
                                            &stats->rd_bytes,
                                            &stats->wr_bytes,
                                            &stats->rd_req,
                                            &stats->wr_req);
2425 2426

 endjob:
2427
    virLXCDomainObjEndJob(driver, vm);
2428

2429
 cleanup:
2430
    virDomainObjEndAPI(&vm);
2431 2432 2433 2434 2435 2436 2437 2438 2439 2440 2441
    return ret;
}


static int
lxcDomainBlockStatsFlags(virDomainPtr dom,
                         const char * path,
                         virTypedParameterPtr params,
                         int * nparams,
                         unsigned int flags)
{
2442
    virLXCDriverPtr driver = dom->conn->privateData;
2443
    int tmp, ret = -1;
2444 2445 2446 2447 2448 2449 2450 2451 2452 2453 2454 2455 2456 2457 2458 2459 2460 2461 2462 2463 2464 2465 2466 2467
    virDomainObjPtr vm;
    virDomainDiskDefPtr disk = NULL;
    virLXCDomainObjPrivatePtr priv;
    long long rd_req, rd_bytes, wr_req, wr_bytes;
    virTypedParameterPtr param;

    virCheckFlags(VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We don't return strings, and thus trivially support this flag.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;

    if (!params && !*nparams) {
        *nparams = LXC_NB_DOMAIN_BLOCK_STAT_PARAM;
        return 0;
    }

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    priv = vm->privateData;

    if (virDomainBlockStatsFlagsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2468 2469 2470
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_QUERY) < 0)
        goto cleanup;

2471 2472 2473
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
2474
        goto endjob;
2475 2476 2477 2478 2479
    }

    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("blkio cgroup isn't mounted"));
2480
        goto endjob;
2481 2482 2483 2484 2485 2486 2487 2488 2489 2490 2491
    }

    if (!*path) {
        /* empty path - return entire domain blkstats instead */
        if (virCgroupGetBlkioIoServiced(priv->cgroup,
                                        &rd_bytes,
                                        &wr_bytes,
                                        &rd_req,
                                        &wr_req) < 0) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("domain stats query failed"));
2492
            goto endjob;
2493 2494
        }
    } else {
2495
        if (!(disk = virDomainDiskByName(vm->def, path, false))) {
2496 2497
            virReportError(VIR_ERR_INVALID_ARG,
                           _("invalid path: %s"), path);
2498
            goto endjob;
2499 2500 2501 2502 2503
        }

        if (!disk->info.alias) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("missing disk device alias name for %s"), disk->dst);
2504
            goto endjob;
2505 2506 2507 2508 2509 2510 2511 2512 2513 2514
        }

        if (virCgroupGetBlkioIoDeviceServiced(priv->cgroup,
                                              disk->info.alias,
                                              &rd_bytes,
                                              &wr_bytes,
                                              &rd_req,
                                              &wr_req) < 0) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           "%s", _("domain stats query failed"));
2515
            goto endjob;
2516 2517 2518 2519 2520 2521 2522 2523 2524 2525
        }
    }

    tmp = 0;
    ret = -1;

    if (tmp < *nparams && wr_bytes != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_WRITE_BYTES,
                                    VIR_TYPED_PARAM_LLONG, wr_bytes) < 0)
2526
            goto endjob;
2527 2528 2529 2530 2531 2532 2533
        tmp++;
    }

    if (tmp < *nparams && wr_req != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_WRITE_REQ,
                                    VIR_TYPED_PARAM_LLONG, wr_req) < 0)
2534
            goto endjob;
2535 2536 2537 2538 2539 2540 2541
        tmp++;
    }

    if (tmp < *nparams && rd_bytes != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_READ_BYTES,
                                    VIR_TYPED_PARAM_LLONG, rd_bytes) < 0)
2542
            goto endjob;
2543 2544 2545 2546 2547 2548 2549
        tmp++;
    }

    if (tmp < *nparams && rd_req != -1) {
        param = &params[tmp];
        if (virTypedParameterAssign(param, VIR_DOMAIN_BLOCK_STATS_READ_REQ,
                                    VIR_TYPED_PARAM_LLONG, rd_req) < 0)
2550
            goto endjob;
2551 2552 2553 2554 2555 2556
        tmp++;
    }

    ret = 0;
    *nparams = tmp;

2557
 endjob:
2558
    virLXCDomainObjEndJob(driver, vm);
2559

2560
 cleanup:
2561
    virDomainObjEndAPI(&vm);
2562 2563 2564 2565
    return ret;
}


2566 2567 2568 2569 2570
static int
lxcDomainSetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int nparams,
                            unsigned int flags)
2571
{
2572
    virLXCDriverPtr driver = dom->conn->privateData;
2573
    size_t i;
2574
    virDomainObjPtr vm = NULL;
2575
    virDomainDefPtr def = NULL;
2576 2577
    virDomainDefPtr persistentDef = NULL;
    int ret = -1;
2578
    virLXCDriverConfigPtr cfg = NULL;
2579
    virLXCDomainObjPrivatePtr priv;
2580 2581 2582

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
2583 2584 2585
    if (virTypedParamsValidate(params, nparams,
                               VIR_DOMAIN_BLKIO_WEIGHT,
                               VIR_TYPED_PARAM_UINT,
2586 2587 2588 2589 2590 2591 2592 2593 2594 2595
                               VIR_DOMAIN_BLKIO_DEVICE_WEIGHT,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_READ_BPS,
                               VIR_TYPED_PARAM_STRING,
                               VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS,
                               VIR_TYPED_PARAM_STRING,
2596
                               NULL) < 0)
2597 2598
        return -1;

M
Michal Privoznik 已提交
2599
    if (!(vm = lxcDomObjFromDomain(dom)))
2600
        return -1;
M
Michal Privoznik 已提交
2601

2602
    priv = vm->privateData;
2603
    cfg = virLXCDriverGetConfig(driver);
2604

2605 2606 2607
    if (virDomainSetBlkioParametersEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

2608 2609 2610
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

2611
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
2612
        goto endjob;
2613

2614
    if (def) {
2615
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
2616 2617
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2618
            goto endjob;
2619
        }
2620
    }
2621

2622
    ret = 0;
2623
    if (def) {
2624 2625 2626 2627
        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
2628
                if (virCgroupSetBlkioWeight(priv->cgroup, params[i].value.ui) < 0)
2629 2630 2631 2632 2633 2634 2635 2636 2637 2638 2639 2640 2641 2642 2643 2644 2645 2646 2647 2648 2649 2650
                    ret = -1;
            } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
                size_t ndevices;
                virBlkioDevicePtr devices = NULL;
                size_t j;

                if (lxcDomainParseBlkioDeviceStr(params[i].value.s,
                                                 param->field,
                                                 &devices,
                                                 &ndevices) < 0) {
                    ret = -1;
                    continue;
                }

                if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceWeight(priv->cgroup,
                                                          devices[j].path,
2651 2652 2653 2654
                                                          devices[j].weight) < 0 ||
                            virCgroupGetBlkioDeviceWeight(priv->cgroup,
                                                          devices[j].path,
                                                          &devices[j].weight) < 0) {
2655 2656 2657 2658 2659 2660 2661 2662
                            ret = -1;
                            break;
                        }
                    }
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceReadIops(priv->cgroup,
                                                            devices[j].path,
2663 2664 2665 2666
                                                            devices[j].riops) < 0 ||
                            virCgroupGetBlkioDeviceReadIops(priv->cgroup,
                                                            devices[j].path,
                                                            &devices[j].riops) < 0) {
2667 2668 2669 2670 2671 2672 2673 2674
                            ret = -1;
                            break;
                        }
                    }
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceWriteIops(priv->cgroup,
                                                             devices[j].path,
2675 2676 2677 2678
                                                             devices[j].wiops) < 0 ||
                            virCgroupGetBlkioDeviceWriteIops(priv->cgroup,
                                                             devices[j].path,
                                                             &devices[j].wiops) < 0) {
2679 2680 2681 2682 2683 2684 2685 2686
                            ret = -1;
                            break;
                        }
                    }
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS)) {
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceReadBps(priv->cgroup,
                                                           devices[j].path,
2687 2688 2689 2690
                                                           devices[j].rbps) < 0 ||
                            virCgroupGetBlkioDeviceReadBps(priv->cgroup,
                                                           devices[j].path,
                                                           &devices[j].rbps) < 0) {
2691 2692 2693 2694
                            ret = -1;
                            break;
                        }
                    }
2695
                } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
2696 2697 2698
                    for (j = 0; j < ndevices; j++) {
                        if (virCgroupSetBlkioDeviceWriteBps(priv->cgroup,
                                                            devices[j].path,
2699 2700 2701 2702
                                                            devices[j].wbps) < 0 ||
                            virCgroupGetBlkioDeviceWriteBps(priv->cgroup,
                                                            devices[j].path,
                                                            &devices[j].wbps) < 0) {
2703 2704 2705 2706 2707 2708 2709 2710 2711 2712 2713 2714 2715 2716 2717
                            ret = -1;
                            break;
                        }
                    }
                } else {
                    virReportError(VIR_ERR_INVALID_ARG, _("Unknown blkio parameter %s"),
                                   param->field);
                    ret = -1;
                    virBlkioDeviceArrayClear(devices, ndevices);
                    VIR_FREE(devices);

                    continue;
                }

                if (j != ndevices ||
2718 2719
                    lxcDomainMergeBlkioDevice(&def->blkio.devices,
                                              &def->blkio.ndevices,
2720 2721 2722 2723
                                              devices, ndevices, param->field) < 0)
                    ret = -1;
                virBlkioDeviceArrayClear(devices, ndevices);
                VIR_FREE(devices);
2724 2725
            }
        }
E
Eric Blake 已提交
2726
    }
2727
    if (ret < 0)
2728
        goto endjob;
2729
    if (persistentDef) {
2730 2731 2732 2733 2734
        for (i = 0; i < nparams; i++) {
            virTypedParameterPtr param = &params[i];

            if (STREQ(param->field, VIR_DOMAIN_BLKIO_WEIGHT)) {
                persistentDef->blkio.weight = params[i].value.ui;
2735 2736 2737 2738 2739 2740 2741 2742 2743 2744 2745 2746 2747 2748 2749 2750 2751 2752 2753 2754 2755
            } else if (STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WEIGHT) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_IOPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_READ_BPS) ||
                       STREQ(param->field, VIR_DOMAIN_BLKIO_DEVICE_WRITE_BPS)) {
                virBlkioDevicePtr devices = NULL;
                size_t ndevices;

                if (lxcDomainParseBlkioDeviceStr(params[i].value.s,
                                                 param->field,
                                                 &devices,
                                                 &ndevices) < 0) {
                    ret = -1;
                    continue;
                }
                if (lxcDomainMergeBlkioDevice(&persistentDef->blkio.devices,
                                              &persistentDef->blkio.ndevices,
                                              devices, ndevices, param->field) < 0)
                    ret = -1;
                virBlkioDeviceArrayClear(devices, ndevices);
                VIR_FREE(devices);
2756 2757 2758
            }
        }

2759
        if (virDomainSaveConfig(cfg->configDir, driver->caps, persistentDef) < 0)
2760
            ret = -1;
2761 2762
    }

2763
 endjob:
2764
    virLXCDomainObjEndJob(driver, vm);
2765

2766
 cleanup:
2767
    virDomainObjEndAPI(&vm);
2768
    virObjectUnref(cfg);
2769 2770 2771 2772
    return ret;
}


2773 2774
#define LXC_NB_BLKIO_PARAM  6

2775 2776 2777 2778 2779
static int
lxcDomainGetBlkioParameters(virDomainPtr dom,
                            virTypedParameterPtr params,
                            int *nparams,
                            unsigned int flags)
2780 2781
{
    virDomainObjPtr vm = NULL;
2782
    virDomainDefPtr def = NULL;
2783
    virDomainDefPtr persistentDef = NULL;
2784
    int maxparams = LXC_NB_BLKIO_PARAM;
2785 2786
    unsigned int val;
    int ret = -1;
2787
    virLXCDomainObjPrivatePtr priv;
2788 2789

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
2790 2791 2792 2793 2794 2795 2796
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_TYPED_PARAM_STRING_OKAY, -1);

    /* We blindly return a string, and let libvirt.c and
     * remote_driver.c do the filtering on behalf of older clients
     * that can't parse it.  */
    flags &= ~VIR_TYPED_PARAM_STRING_OKAY;
2797

M
Michal Privoznik 已提交
2798
    if (!(vm = lxcDomObjFromDomain(dom)))
2799
        return -1;
M
Michal Privoznik 已提交
2800

2801
    priv = vm->privateData;
2802

2803 2804 2805
    if (virDomainGetBlkioParametersEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2806 2807 2808 2809 2810
    if ((*nparams) == 0) {
        /* Current number of blkio parameters supported by cgroups */
        *nparams = LXC_NB_BLKIO_PARAM;
        ret = 0;
        goto cleanup;
2811 2812
    } else if (*nparams < maxparams) {
        maxparams = *nparams;
2813 2814
    }

2815 2816
    *nparams = 0;

2817
    if (virDomainObjGetDefs(vm, flags, &def, &persistentDef) < 0)
E
Eric Blake 已提交
2818
        goto cleanup;
2819

2820
    if (def) {
2821
        if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_BLKIO)) {
2822 2823
            virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                           _("blkio cgroup isn't mounted"));
2824 2825 2826
            goto cleanup;
        }

2827 2828 2829 2830 2831 2832 2833
        /* fill blkio weight here */
        if (virCgroupGetBlkioWeight(priv->cgroup, &val) < 0)
            goto cleanup;
        if (virTypedParameterAssign(&(params[(*nparams)++]),
                                    VIR_DOMAIN_BLKIO_WEIGHT,
                                    VIR_TYPED_PARAM_UINT, val) < 0)
            goto cleanup;
2834

2835 2836 2837
        if (virDomainGetBlkioParametersAssignFromDef(def, params, nparams,
                                                     maxparams) < 0)
            goto cleanup;
2838

2839
    } else if (persistentDef) {
2840 2841 2842 2843 2844 2845
        /* fill blkio weight here */
        if (virTypedParameterAssign(&(params[(*nparams)++]),
                                    VIR_DOMAIN_BLKIO_WEIGHT,
                                    VIR_TYPED_PARAM_UINT,
                                    persistentDef->blkio.weight) < 0)
            goto cleanup;
2846

2847 2848 2849
        if (virDomainGetBlkioParametersAssignFromDef(persistentDef, params,
                                                     nparams, maxparams) < 0)
            goto cleanup;
2850 2851 2852 2853
    }

    ret = 0;

2854
 cleanup:
2855
    virDomainObjEndAPI(&vm);
2856 2857 2858 2859
    return ret;
}


2860 2861
static int
lxcDomainInterfaceStats(virDomainPtr dom,
2862
                        const char *device,
2863
                        virDomainInterfaceStatsPtr stats)
2864 2865 2866
{
    virDomainObjPtr vm;
    int ret = -1;
2867
    virLXCDriverPtr driver = dom->conn->privateData;
M
Michal Privoznik 已提交
2868
    virDomainNetDefPtr net = NULL;
2869

M
Michal Privoznik 已提交
2870
    if (!(vm = lxcDomObjFromDomain(dom)))
2871 2872
        goto cleanup;

2873 2874 2875
    if (virDomainInterfaceStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2876 2877 2878
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_QUERY) < 0)
        goto cleanup;

2879
    if (!virDomainObjIsActive(vm)) {
2880 2881
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
2882
        goto endjob;
2883 2884
    }

2885
    if (!(net = virDomainNetFind(vm->def, device)))
M
Michal Privoznik 已提交
2886 2887
        goto endjob;

2888
    if (virNetDevTapInterfaceStats(net->ifname, stats,
2889
                                   !virDomainNetTypeSharesHostView(net)) < 0)
M
Michal Privoznik 已提交
2890 2891 2892
        goto endjob;

    ret = 0;
2893

2894
 endjob:
2895
    virLXCDomainObjEndJob(driver, vm);
2896

2897
 cleanup:
2898
    virDomainObjEndAPI(&vm);
2899 2900
    return ret;
}
2901

2902

2903
static int lxcDomainGetAutostart(virDomainPtr dom,
2904 2905
                                   int *autostart)
{
2906 2907 2908
    virDomainObjPtr vm;
    int ret = -1;

M
Michal Privoznik 已提交
2909
    if (!(vm = lxcDomObjFromDomain(dom)))
2910 2911
        goto cleanup;

2912 2913 2914
    if (virDomainGetAutostartEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2915 2916 2917
    *autostart = vm->autostart;
    ret = 0;

2918
 cleanup:
2919
    virDomainObjEndAPI(&vm);
2920 2921 2922 2923
    return ret;
}

static int lxcDomainSetAutostart(virDomainPtr dom,
2924 2925
                                   int autostart)
{
2926
    virLXCDriverPtr driver = dom->conn->privateData;
2927 2928 2929
    virDomainObjPtr vm;
    char *configFile = NULL, *autostartLink = NULL;
    int ret = -1;
2930
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
2931

M
Michal Privoznik 已提交
2932
    if (!(vm = lxcDomObjFromDomain(dom)))
2933 2934
        goto cleanup;

2935 2936 2937
    if (virDomainSetAutostartEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

2938 2939 2940
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

2941
    if (!vm->persistent) {
2942 2943
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Cannot set autostart for transient domain"));
2944
        goto endjob;
2945 2946 2947 2948
    }

    autostart = (autostart != 0);

2949 2950
    if (vm->autostart == autostart) {
        ret = 0;
2951
        goto endjob;
2952
    }
2953

2954
    configFile = virDomainConfigFile(cfg->configDir,
2955 2956
                                     vm->def->name);
    if (configFile == NULL)
2957
        goto endjob;
2958
    autostartLink = virDomainConfigFile(cfg->autostartDir,
2959 2960
                                        vm->def->name);
    if (autostartLink == NULL)
2961
        goto endjob;
2962

2963
    if (autostart) {
2964
        if (virFileMakePath(cfg->autostartDir) < 0) {
2965
            virReportSystemError(errno,
2966
                                 _("Cannot create autostart directory %s"),
2967
                                 cfg->autostartDir);
2968
            goto endjob;
2969 2970
        }

2971
        if (symlink(configFile, autostartLink) < 0) {
2972
            virReportSystemError(errno,
2973 2974
                                 _("Failed to create symlink '%s to '%s'"),
                                 autostartLink, configFile);
2975
            goto endjob;
2976 2977 2978
        }
    } else {
        if (unlink(autostartLink) < 0 && errno != ENOENT && errno != ENOTDIR) {
2979
            virReportSystemError(errno,
2980 2981
                                 _("Failed to delete symlink '%s'"),
                                 autostartLink);
2982
            goto endjob;
2983
        }
2984
    }
2985 2986

    vm->autostart = autostart;
2987 2988
    ret = 0;

2989
 endjob:
2990 2991
    virLXCDomainObjEndJob(driver, vm);

2992
 cleanup:
2993 2994
    VIR_FREE(configFile);
    VIR_FREE(autostartLink);
2995
    virDomainObjEndAPI(&vm);
2996
    virObjectUnref(cfg);
2997 2998 2999
    return ret;
}

3000
static int lxcFreezeContainer(virDomainObjPtr vm)
R
Ryota Ozaki 已提交
3001 3002 3003 3004 3005 3006 3007
{
    int timeout = 1000; /* In milliseconds */
    int check_interval = 1; /* In milliseconds */
    int exp = 10;
    int waited_time = 0;
    int ret = -1;
    char *state = NULL;
3008
    virLXCDomainObjPrivatePtr priv = vm->privateData;
3009

R
Ryota Ozaki 已提交
3010 3011 3012 3013 3014 3015 3016 3017 3018
    while (waited_time < timeout) {
        int r;
        /*
         * Writing "FROZEN" to the "freezer.state" freezes the group,
         * i.e., the container, temporarily transiting "FREEZING" state.
         * Once the freezing is completed, the state of the group transits
         * to "FROZEN".
         * (see linux-2.6/Documentation/cgroups/freezer-subsystem.txt)
         */
3019
        r = virCgroupSetFreezerState(priv->cgroup, "FROZEN");
R
Ryota Ozaki 已提交
3020 3021 3022

        /*
         * Returning EBUSY explicitly indicates that the group is
3023
         * being frozen but incomplete, and other errors are true
R
Ryota Ozaki 已提交
3024 3025 3026 3027 3028 3029 3030
         * errors.
         */
        if (r < 0 && r != -EBUSY) {
            VIR_DEBUG("Writing freezer.state failed with errno: %d", r);
            goto error;
        }
        if (r == -EBUSY)
3031
            VIR_DEBUG("Writing freezer.state gets EBUSY");
R
Ryota Ozaki 已提交
3032 3033 3034 3035 3036 3037 3038 3039 3040 3041 3042 3043 3044 3045

        /*
         * Unfortunately, returning 0 (success) is likely to happen
         * even when the freezing has not been completed. Sometimes
         * the state of the group remains "FREEZING" like when
         * returning -EBUSY and even worse may never transit to
         * "FROZEN" even if writing "FROZEN" again.
         *
         * So we don't trust the return value anyway and always
         * decide that the freezing has been complete only with
         * the state actually transit to "FROZEN".
         */
        usleep(check_interval * 1000);

3046
        r = virCgroupGetFreezerState(priv->cgroup, &state);
R
Ryota Ozaki 已提交
3047 3048 3049 3050 3051 3052 3053 3054 3055 3056 3057 3058 3059 3060 3061 3062 3063 3064 3065 3066 3067 3068 3069 3070

        if (r < 0) {
            VIR_DEBUG("Reading freezer.state failed with errno: %d", r);
            goto error;
        }
        VIR_DEBUG("Read freezer.state: %s", state);

        if (STREQ(state, "FROZEN")) {
            ret = 0;
            goto cleanup;
        }

        waited_time += check_interval;
        /*
         * Increasing check_interval exponentially starting with
         * small initial value treats nicely two cases; One is
         * a container is under no load and waiting for long period
         * makes no sense. The other is under heavy load. The container
         * may stay longer time in FREEZING or never transit to FROZEN.
         * In that case, eager polling will just waste CPU time.
         */
        check_interval *= exp;
        VIR_FREE(state);
    }
3071
    VIR_DEBUG("lxcFreezeContainer timeout");
3072
 error:
R
Ryota Ozaki 已提交
3073 3074 3075 3076 3077
    /*
     * If timeout or an error on reading the state occurs,
     * activate the group again and return an error.
     * This is likely to fall the group back again gracefully.
     */
3078
    virCgroupSetFreezerState(priv->cgroup, "THAWED");
R
Ryota Ozaki 已提交
3079 3080
    ret = -1;

3081
 cleanup:
R
Ryota Ozaki 已提交
3082 3083 3084 3085 3086 3087
    VIR_FREE(state);
    return ret;
}

static int lxcDomainSuspend(virDomainPtr dom)
{
3088
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
3089
    virDomainObjPtr vm;
3090
    virObjectEventPtr event = NULL;
R
Ryota Ozaki 已提交
3091
    int ret = -1;
3092
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
3093

M
Michal Privoznik 已提交
3094
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
3095 3096
        goto cleanup;

3097 3098 3099
    if (virDomainSuspendEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3100 3101 3102
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

D
Daniel P. Berrange 已提交
3103
    if (!virDomainObjIsActive(vm)) {
3104 3105
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
3106
        goto endjob;
R
Ryota Ozaki 已提交
3107 3108
    }

J
Jiri Denemark 已提交
3109
    if (virDomainObjGetState(vm, NULL) != VIR_DOMAIN_PAUSED) {
3110
        if (lxcFreezeContainer(vm) < 0) {
3111 3112
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Suspend operation failed"));
3113
            goto endjob;
R
Ryota Ozaki 已提交
3114
        }
J
Jiri Denemark 已提交
3115
        virDomainObjSetState(vm, VIR_DOMAIN_PAUSED, VIR_DOMAIN_PAUSED_USER);
R
Ryota Ozaki 已提交
3116

3117
        event = virDomainEventLifecycleNewFromObj(vm,
R
Ryota Ozaki 已提交
3118 3119 3120 3121
                                         VIR_DOMAIN_EVENT_SUSPENDED,
                                         VIR_DOMAIN_EVENT_SUSPENDED_PAUSED);
    }

3122
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0)
3123
        goto endjob;
R
Ryota Ozaki 已提交
3124 3125
    ret = 0;

3126
 endjob:
3127 3128
    virLXCDomainObjEndJob(driver, vm);

3129
 cleanup:
R
Ryota Ozaki 已提交
3130
    if (event)
3131
        virObjectEventStateQueue(driver->domainEventState, event);
3132
    virDomainObjEndAPI(&vm);
3133
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
3134 3135 3136 3137 3138
    return ret;
}

static int lxcDomainResume(virDomainPtr dom)
{
3139
    virLXCDriverPtr driver = dom->conn->privateData;
R
Ryota Ozaki 已提交
3140
    virDomainObjPtr vm;
3141
    virObjectEventPtr event = NULL;
R
Ryota Ozaki 已提交
3142
    int ret = -1;
3143
    int state;
3144
    virLXCDomainObjPrivatePtr priv;
3145
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
3146

M
Michal Privoznik 已提交
3147
    if (!(vm = lxcDomObjFromDomain(dom)))
R
Ryota Ozaki 已提交
3148 3149
        goto cleanup;

3150 3151
    priv = vm->privateData;

3152 3153 3154
    if (virDomainResumeEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3155 3156 3157
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

D
Daniel P. Berrange 已提交
3158
    if (!virDomainObjIsActive(vm)) {
3159 3160
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
3161
        goto endjob;
R
Ryota Ozaki 已提交
3162 3163
    }

3164 3165 3166 3167 3168 3169
    state = virDomainObjGetState(vm, NULL);
    if (state == VIR_DOMAIN_RUNNING) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is already running"));
        goto endjob;
    } else if (state == VIR_DOMAIN_PAUSED) {
3170
        if (virCgroupSetFreezerState(priv->cgroup, "THAWED") < 0) {
3171 3172
            virReportError(VIR_ERR_OPERATION_FAILED,
                           "%s", _("Resume operation failed"));
3173
            goto endjob;
R
Ryota Ozaki 已提交
3174
        }
J
Jiri Denemark 已提交
3175 3176
        virDomainObjSetState(vm, VIR_DOMAIN_RUNNING,
                             VIR_DOMAIN_RUNNING_UNPAUSED);
R
Ryota Ozaki 已提交
3177

3178
        event = virDomainEventLifecycleNewFromObj(vm,
R
Ryota Ozaki 已提交
3179 3180 3181 3182
                                         VIR_DOMAIN_EVENT_RESUMED,
                                         VIR_DOMAIN_EVENT_RESUMED_UNPAUSED);
    }

3183
    if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0)
3184
        goto endjob;
R
Ryota Ozaki 已提交
3185 3186
    ret = 0;

3187
 endjob:
3188 3189
    virLXCDomainObjEndJob(driver, vm);

3190
 cleanup:
R
Ryota Ozaki 已提交
3191
    if (event)
3192
        virObjectEventStateQueue(driver->domainEventState, event);
3193
    virDomainObjEndAPI(&vm);
3194
    virObjectUnref(cfg);
R
Ryota Ozaki 已提交
3195 3196 3197
    return ret;
}

3198 3199
static int
lxcDomainOpenConsole(virDomainPtr dom,
3200
                      const char *dev_name,
3201 3202 3203 3204 3205 3206
                      virStreamPtr st,
                      unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    int ret = -1;
    virDomainChrDefPtr chr = NULL;
3207
    size_t i;
3208 3209 3210

    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
3211
    if (!(vm = lxcDomObjFromDomain(dom)))
3212 3213
        goto cleanup;

3214 3215 3216
    if (virDomainOpenConsoleEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3217
    if (!virDomainObjIsActive(vm)) {
3218 3219
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
3220 3221 3222
        goto cleanup;
    }

3223
    if (dev_name) {
3224
        for (i = 0; i < vm->def->nconsoles; i++) {
3225 3226 3227 3228 3229 3230
            if (vm->def->consoles[i]->info.alias &&
                STREQ(vm->def->consoles[i]->info.alias, dev_name)) {
                chr = vm->def->consoles[i];
                break;
            }
        }
3231
    } else {
3232 3233
        if (vm->def->nconsoles)
            chr = vm->def->consoles[0];
3234 3235 3236 3237 3238
        else if (vm->def->nserials)
            chr = vm->def->serials[0];
    }

    if (!chr) {
3239 3240 3241
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("cannot find console device '%s'"),
                       dev_name ? dev_name : _("default"));
3242 3243 3244
        goto cleanup;
    }

3245
    if (chr->source->type != VIR_DOMAIN_CHR_TYPE_PTY) {
3246
        virReportError(VIR_ERR_INTERNAL_ERROR,
3247 3248
                       _("character device %s is not using a PTY"),
                       dev_name ? dev_name : NULLSTR(chr->info.alias));
3249 3250 3251
        goto cleanup;
    }

3252
    if (virFDStreamOpenFile(st, chr->source->data.file.path,
E
Eric Blake 已提交
3253
                            0, 0, O_RDWR) < 0)
3254 3255 3256
        goto cleanup;

    ret = 0;
3257
 cleanup:
3258
    virDomainObjEndAPI(&vm);
3259 3260 3261
    return ret;
}

3262 3263 3264 3265 3266 3267 3268

static int
lxcDomainSendProcessSignal(virDomainPtr dom,
                           long long pid_value,
                           unsigned int signum,
                           unsigned int flags)
{
3269
    virLXCDriverPtr driver = dom->conn->privateData;
3270 3271 3272 3273 3274 3275 3276 3277 3278 3279 3280 3281 3282 3283
    virDomainObjPtr vm = NULL;
    virLXCDomainObjPrivatePtr priv;
    pid_t victim;
    int ret = -1;

    virCheckFlags(0, -1);

    if (signum >= VIR_DOMAIN_PROCESS_SIGNAL_LAST) {
        virReportError(VIR_ERR_INVALID_ARG,
                       _("signum value %d is out of range"),
                       signum);
        return -1;
    }

M
Michal Privoznik 已提交
3284
    if (!(vm = lxcDomObjFromDomain(dom)))
3285
        goto cleanup;
M
Michal Privoznik 已提交
3286

3287 3288
    priv = vm->privateData;

3289 3290 3291
    if (virDomainSendProcessSignalEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

3292 3293 3294
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

3295 3296 3297
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("domain is not running"));
3298
        goto endjob;
3299 3300 3301 3302 3303 3304 3305 3306 3307 3308 3309 3310
    }

    /*
     * XXX if the kernel has /proc/$PID/ns/pid we can
     * switch into container namespace & that way be
     * able to kill any PID. Alternatively if there
     * is a way to find a mapping of guest<->host PIDs
     * we can kill that way.
     */
    if (pid_value != 1) {
        virReportError(VIR_ERR_ARGUMENT_UNSUPPORTED, "%s",
                       _("Only the init process may be killed"));
3311
        goto endjob;
3312 3313 3314 3315 3316
    }

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
3317
        goto endjob;
3318 3319 3320 3321 3322 3323 3324 3325 3326 3327
    }
    victim = priv->initpid;

    /* We're relying on fact libvirt header signal numbers
     * are taken from Linux, to avoid mapping
     */
    if (kill(victim, signum) < 0) {
        virReportSystemError(errno,
                             _("Unable to send %d signal to process %d"),
                             signum, victim);
3328
        goto endjob;
3329 3330 3331 3332
    }

    ret = 0;

3333
 endjob:
3334
    virLXCDomainObjEndJob(driver, vm);
3335

3336
 cleanup:
3337
    virDomainObjEndAPI(&vm);
3338 3339 3340 3341
    return ret;
}


3342
static int
3343 3344
lxcConnectListAllDomains(virConnectPtr conn,
                         virDomainPtr **domains,
3345 3346
                  unsigned int flags)
{
3347
    virLXCDriverPtr driver = conn->privateData;
3348 3349
    int ret = -1;

O
Osier Yang 已提交
3350
    virCheckFlags(VIR_CONNECT_LIST_DOMAINS_FILTERS_ALL, -1);
3351

3352 3353 3354
    if (virConnectListAllDomainsEnsureACL(conn) < 0)
        return -1;

3355 3356
    ret = virDomainObjListExport(driver->domains, conn, domains,
                                 virConnectListAllDomainsCheckACL, flags);
3357 3358 3359
    return ret;
}

3360

3361 3362 3363 3364 3365 3366 3367 3368 3369
static int
lxcDomainInitctlCallback(pid_t pid ATTRIBUTE_UNUSED,
                         void *opaque)
{
    int *command = opaque;
    return virInitctlSetRunLevel(*command);
}


3370 3371 3372 3373
static int
lxcDomainShutdownFlags(virDomainPtr dom,
                       unsigned int flags)
{
3374
    virLXCDriverPtr driver = dom->conn->privateData;
3375 3376 3377
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    int ret = -1;
3378
    int rc;
3379 3380 3381 3382

    virCheckFlags(VIR_DOMAIN_SHUTDOWN_INITCTL |
                  VIR_DOMAIN_SHUTDOWN_SIGNAL, -1);

M
Michal Privoznik 已提交
3383
    if (!(vm = lxcDomObjFromDomain(dom)))
3384 3385 3386 3387
        goto cleanup;

    priv = vm->privateData;

3388
    if (virDomainShutdownFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
3389 3390
        goto cleanup;

3391 3392 3393
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

3394 3395 3396
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
3397
        goto endjob;
3398 3399 3400 3401 3402
    }

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
3403
        goto endjob;
3404 3405
    }

3406 3407
    if (flags == 0 ||
        (flags & VIR_DOMAIN_SHUTDOWN_INITCTL)) {
3408 3409 3410 3411 3412
        int command = VIR_INITCTL_RUNLEVEL_POWEROFF;

        if ((rc = virProcessRunInMountNamespace(priv->initpid,
                                                lxcDomainInitctlCallback,
                                                &command)) < 0)
3413
            goto endjob;
3414 3415
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
3416 3417
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
3418
            goto endjob;
3419
        }
3420 3421
    } else {
        rc = 0;
3422
    }
3423

3424 3425 3426
    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_SHUTDOWN_SIGNAL))) {
3427 3428
        if (kill(priv->initpid, SIGTERM) < 0 &&
            errno != ESRCH) {
3429 3430
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
M
Michal Privoznik 已提交
3431
                                 (long long) priv->initpid);
3432
            goto endjob;
3433 3434 3435 3436 3437
        }
    }

    ret = 0;

3438
 endjob:
3439
    virLXCDomainObjEndJob(driver, vm);
3440

3441
 cleanup:
3442
    virDomainObjEndAPI(&vm);
3443 3444 3445 3446 3447 3448 3449 3450 3451
    return ret;
}

static int
lxcDomainShutdown(virDomainPtr dom)
{
    return lxcDomainShutdownFlags(dom, 0);
}

3452

3453 3454 3455 3456
static int
lxcDomainReboot(virDomainPtr dom,
                unsigned int flags)
{
3457
    virLXCDriverPtr driver = dom->conn->privateData;
3458 3459 3460 3461 3462 3463 3464 3465
    virLXCDomainObjPrivatePtr priv;
    virDomainObjPtr vm;
    int ret = -1;
    int rc;

    virCheckFlags(VIR_DOMAIN_REBOOT_INITCTL |
                  VIR_DOMAIN_REBOOT_SIGNAL, -1);

M
Michal Privoznik 已提交
3466
    if (!(vm = lxcDomObjFromDomain(dom)))
3467 3468 3469 3470
        goto cleanup;

    priv = vm->privateData;

3471
    if (virDomainRebootEnsureACL(dom->conn, vm->def, flags) < 0)
3472 3473
        goto cleanup;

3474 3475 3476
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

3477 3478 3479
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
3480
        goto endjob;
3481 3482 3483 3484 3485
    }

    if (priv->initpid == 0) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Init process ID is not yet known"));
3486
        goto endjob;
3487 3488 3489 3490
    }

    if (flags == 0 ||
        (flags & VIR_DOMAIN_REBOOT_INITCTL)) {
3491 3492 3493 3494 3495
        int command = VIR_INITCTL_RUNLEVEL_REBOOT;

        if ((rc = virProcessRunInMountNamespace(priv->initpid,
                                                lxcDomainInitctlCallback,
                                                &command)) < 0)
3496
            goto endjob;
3497 3498 3499 3500
        if (rc == 0 && flags != 0 &&
            ((flags & ~VIR_DOMAIN_SHUTDOWN_INITCTL) == 0)) {
            virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                           _("Container does not provide an initctl pipe"));
3501
            goto endjob;
3502 3503 3504 3505 3506 3507 3508 3509 3510 3511 3512 3513
        }
    } else {
        rc = 0;
    }

    if (rc == 0 &&
        (flags == 0 ||
         (flags & VIR_DOMAIN_REBOOT_SIGNAL))) {
        if (kill(priv->initpid, SIGHUP) < 0 &&
            errno != ESRCH) {
            virReportSystemError(errno,
                                 _("Unable to send SIGTERM to init pid %llu"),
M
Michal Privoznik 已提交
3514
                                 (long long) priv->initpid);
3515
            goto endjob;
3516 3517 3518 3519 3520
        }
    }

    ret = 0;

3521
 endjob:
3522
    virLXCDomainObjEndJob(driver, vm);
3523

3524
 cleanup:
3525
    virDomainObjEndAPI(&vm);
3526 3527 3528 3529
    return ret;
}


3530
static int
3531
lxcDomainAttachDeviceConfig(virDomainDefPtr vmdef,
3532 3533 3534
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3535
    virDomainDiskDefPtr disk;
3536
    virDomainNetDefPtr net;
3537
    virDomainHostdevDefPtr hostdev;
3538 3539

    switch (dev->type) {
3540 3541 3542 3543 3544 3545 3546
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (virDomainDiskIndexByName(vmdef, disk->dst, true) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("target %s already exists."), disk->dst);
            return -1;
        }
3547
        if (virDomainDiskInsert(vmdef, disk))
3548 3549 3550 3551 3552 3553
            return -1;
        /* vmdef has the pointer. Generic codes for vmdef will do all jobs */
        dev->data.disk = NULL;
        ret = 0;
        break;

3554 3555
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
3556
        if (virDomainNetInsert(vmdef, net) < 0)
3557 3558 3559 3560 3561
            goto cleanup;
        dev->data.net = NULL;
        ret = 0;
        break;

3562 3563 3564 3565 3566 3567 3568
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        hostdev = dev->data.hostdev;
        if (virDomainHostdevFind(vmdef, hostdev, NULL) >= 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device is already in the domain configuration"));
            return -1;
        }
3569
        if (virDomainHostdevInsert(vmdef, hostdev) < 0)
3570 3571 3572 3573 3574
            return -1;
        dev->data.hostdev = NULL;
        ret = 0;
        break;

3575 3576 3577 3578 3579 3580
    default:
         virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                        _("persistent attach of device is not supported"));
         break;
    }

3581
 cleanup:
3582 3583 3584 3585 3586
    return ret;
}


static int
3587
lxcDomainUpdateDeviceConfig(virDomainDefPtr vmdef,
3588 3589 3590
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3591
    virDomainNetDefPtr net;
3592
    virDomainDeviceDef oldDev = { .type = dev->type };
3593
    int idx;
3594 3595

    switch (dev->type) {
3596 3597
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
3598
        if ((idx = virDomainNetFindIdx(vmdef, net)) < 0)
3599 3600
            goto cleanup;

3601 3602 3603
        oldDev.data.net = vmdef->nets[idx];
        if (virDomainDefCompatibleDevice(vmdef, dev, &oldDev) < 0)
            return -1;
3604

3605
        virDomainNetDefFree(vmdef->nets[idx]);
3606 3607 3608 3609 3610 3611
        vmdef->nets[idx] = net;
        dev->data.net = NULL;
        ret = 0;

        break;

3612 3613 3614 3615 3616 3617
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent update of device is not supported"));
        break;
    }

3618
 cleanup:
3619 3620 3621 3622 3623
    return ret;
}


static int
3624
lxcDomainDetachDeviceConfig(virDomainDefPtr vmdef,
3625 3626 3627
                            virDomainDeviceDefPtr dev)
{
    int ret = -1;
3628
    virDomainDiskDefPtr disk, det_disk;
3629
    virDomainNetDefPtr net;
3630
    virDomainHostdevDefPtr hostdev, det_hostdev;
3631
    int idx;
3632 3633

    switch (dev->type) {
3634 3635 3636 3637 3638 3639 3640 3641 3642 3643 3644
    case VIR_DOMAIN_DEVICE_DISK:
        disk = dev->data.disk;
        if (!(det_disk = virDomainDiskRemoveByName(vmdef, disk->dst))) {
            virReportError(VIR_ERR_INVALID_ARG,
                           _("no target device %s"), disk->dst);
            return -1;
        }
        virDomainDiskDefFree(det_disk);
        ret = 0;
        break;

3645 3646
    case VIR_DOMAIN_DEVICE_NET:
        net = dev->data.net;
3647
        if ((idx = virDomainNetFindIdx(vmdef, net)) < 0)
3648
            goto cleanup;
3649

3650 3651 3652 3653 3654
        /* this is guaranteed to succeed */
        virDomainNetDefFree(virDomainNetRemove(vmdef, idx));
        ret = 0;
        break;

3655 3656 3657 3658 3659 3660 3661 3662 3663 3664 3665 3666 3667
    case VIR_DOMAIN_DEVICE_HOSTDEV: {
        hostdev = dev->data.hostdev;
        if ((idx = virDomainHostdevFind(vmdef, hostdev, &det_hostdev)) < 0) {
            virReportError(VIR_ERR_INVALID_ARG, "%s",
                           _("device not present in domain configuration"));
            return -1;
        }
        virDomainHostdevRemove(vmdef, idx);
        virDomainHostdevDefFree(det_hostdev);
        ret = 0;
        break;
    }

3668 3669 3670 3671 3672 3673
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("persistent detach of device is not supported"));
        break;
    }

3674
 cleanup:
3675 3676 3677 3678
    return ret;
}


3679 3680 3681 3682 3683 3684 3685 3686 3687 3688 3689 3690 3691 3692 3693 3694 3695 3696 3697 3698 3699 3700 3701 3702 3703 3704 3705 3706 3707 3708 3709 3710 3711 3712 3713 3714 3715 3716 3717 3718 3719 3720 3721 3722 3723 3724 3725 3726
struct lxcDomainAttachDeviceMknodData {
    virLXCDriverPtr driver;
    mode_t mode;
    dev_t dev;
    virDomainObjPtr vm;
    virDomainDeviceDefPtr def;
    char *file;
};

static int
lxcDomainAttachDeviceMknodHelper(pid_t pid ATTRIBUTE_UNUSED,
                                 void *opaque)
{
    struct lxcDomainAttachDeviceMknodData *data = opaque;
    int ret = -1;

    virSecurityManagerPostFork(data->driver->securityManager);

    if (virFileMakeParentPath(data->file) < 0) {
        virReportSystemError(errno,
                             _("Unable to create %s"), data->file);
        goto cleanup;
    }

    /* Yes, the device name we're creating may not
     * actually correspond to the major:minor number
     * we're using, but we've no other option at this
     * time. Just have to hope that containerized apps
     * don't get upset that the major:minor is different
     * to that normally implied by the device name
     */
    VIR_DEBUG("Creating dev %s (%d,%d)",
              data->file, major(data->dev), minor(data->dev));
    if (mknod(data->file, data->mode, data->dev) < 0) {
        virReportSystemError(errno,
                             _("Unable to create device %s"),
                             data->file);
        goto cleanup;
    }

    if (lxcContainerChown(data->vm->def, data->file) < 0)
        goto cleanup;

    /* Labelling normally operates on src, but we need
     * to actually label the dst here, so hack the config */
    switch (data->def->type) {
    case VIR_DOMAIN_DEVICE_DISK: {
        virDomainDiskDefPtr def = data->def->data.disk;
3727 3728
        char *tmpsrc = def->src->path;
        def->src->path = data->file;
3729 3730
        if (virSecurityManagerSetDiskLabel(data->driver->securityManager,
                                           data->vm->def, def) < 0) {
3731
            def->src->path = tmpsrc;
3732 3733
            goto cleanup;
        }
3734
        def->src->path = tmpsrc;
3735 3736
    }   break;

3737 3738 3739 3740 3741 3742 3743
    case VIR_DOMAIN_DEVICE_HOSTDEV: {
        virDomainHostdevDefPtr def = data->def->data.hostdev;
        if (virSecurityManagerSetHostdevLabel(data->driver->securityManager,
                                              data->vm->def, def, NULL) < 0)
            goto cleanup;
    }   break;

3744 3745 3746 3747 3748 3749 3750 3751 3752 3753 3754 3755 3756 3757 3758 3759 3760 3761 3762 3763 3764 3765 3766 3767 3768 3769 3770 3771 3772 3773 3774 3775 3776 3777 3778 3779 3780 3781 3782 3783 3784 3785 3786 3787 3788 3789 3790 3791 3792 3793 3794
    default:
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("Unexpected device type %d"),
                       data->def->type);
        goto cleanup;
    }

    ret = 0;

 cleanup:
    if (ret < 0)
        unlink(data->file);
    return ret;
}


static int
lxcDomainAttachDeviceMknod(virLXCDriverPtr driver,
                           mode_t mode,
                           dev_t dev,
                           virDomainObjPtr vm,
                           virDomainDeviceDefPtr def,
                           char *file)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    struct lxcDomainAttachDeviceMknodData data;

    memset(&data, 0, sizeof(data));

    data.driver = driver;
    data.mode = mode;
    data.dev = dev;
    data.vm = vm;
    data.def = def;
    data.file = file;

    if (virSecurityManagerPreFork(driver->securityManager) < 0)
        return -1;

    if (virProcessRunInMountNamespace(priv->initpid,
                                      lxcDomainAttachDeviceMknodHelper,
                                      &data) < 0) {
        virSecurityManagerPostFork(driver->securityManager);
        return -1;
    }

    virSecurityManagerPostFork(driver->securityManager);
    return 0;
}


3795 3796 3797 3798 3799 3800 3801 3802 3803 3804 3805 3806 3807 3808 3809 3810 3811 3812 3813 3814 3815 3816 3817 3818 3819 3820 3821 3822 3823 3824 3825 3826 3827
static int
lxcDomainAttachDeviceUnlinkHelper(pid_t pid ATTRIBUTE_UNUSED,
                                  void *opaque)
{
    const char *path = opaque;

    VIR_DEBUG("Unlinking %s", path);
    if (unlink(path) < 0 && errno != ENOENT) {
        virReportSystemError(errno,
                             _("Unable to remove device %s"), path);
        return -1;
    }

    return 0;
}


static int
lxcDomainAttachDeviceUnlink(virDomainObjPtr vm,
                            char *file)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (virProcessRunInMountNamespace(priv->initpid,
                                      lxcDomainAttachDeviceUnlinkHelper,
                                      file) < 0) {
        return -1;
    }

    return 0;
}


3828 3829 3830 3831 3832 3833 3834 3835 3836
static int
lxcDomainAttachDeviceDiskLive(virLXCDriverPtr driver,
                              virDomainObjPtr vm,
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = dev->data.disk;
    int ret = -1;
    struct stat sb;
3837 3838
    char *file = NULL;
    int perms;
3839
    const char *src = NULL;
3840 3841 3842 3843 3844 3845 3846

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

3847 3848 3849 3850 3851 3852
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

3853 3854
    src = virDomainDiskGetSource(def);
    if (src == NULL) {
3855 3856 3857 3858 3859
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk without media"));
        goto cleanup;
    }

3860 3861 3862 3863 3864 3865
    if (!virStorageSourceIsBlockLocal(def->src)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Can't setup disk for non-block device"));
        goto cleanup;
    }

3866 3867 3868 3869 3870 3871
    if (virDomainDiskIndexByName(vm->def, def->dst, true) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("target %s already exists"), def->dst);
        goto cleanup;
    }

3872
    if (stat(src, &sb) < 0) {
3873
        virReportSystemError(errno,
3874
                             _("Unable to access %s"), src);
3875 3876 3877
        goto cleanup;
    }

3878
    if (!S_ISBLK(sb.st_mode)) {
3879
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
3880
                       _("Disk source %s must be a block device"),
3881
                       src);
3882 3883 3884
        goto cleanup;
    }

3885
    perms = (def->src->readonly ?
3886 3887 3888
             VIR_CGROUP_DEVICE_READ :
             VIR_CGROUP_DEVICE_RW) |
        VIR_CGROUP_DEVICE_MKNOD;
3889

3890 3891 3892 3893 3894
    if (virCgroupAllowDevice(priv->cgroup,
                             'b',
                             major(sb.st_rdev),
                             minor(sb.st_rdev),
                             perms) < 0)
3895
        goto cleanup;
3896

3897
    if (VIR_REALLOC_N(vm->def->disks, vm->def->ndisks + 1) < 0)
3898 3899
        goto cleanup;

3900 3901
    if (virAsprintf(&file,
                    "/dev/%s", def->dst) < 0)
3902 3903
        goto cleanup;

3904 3905 3906 3907 3908 3909 3910 3911 3912 3913 3914
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFBLK,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   file) < 0) {
        if (virCgroupDenyDevice(priv->cgroup,
                                'b',
                                major(sb.st_rdev),
                                minor(sb.st_rdev),
                                perms) < 0)
3915 3916
            VIR_WARN("cannot deny device %s for domain %s: %s",
                     src, vm->def->name, virGetLastErrorMessage());
3917 3918 3919 3920 3921 3922 3923
        goto cleanup;
    }

    virDomainDiskInsertPreAlloced(vm->def, def);

    ret = 0;

3924
 cleanup:
3925
    if (src)
3926
        virDomainAuditDisk(vm, NULL, def->src, "attach", ret == 0);
3927
    VIR_FREE(file);
3928 3929 3930 3931
    return ret;
}


3932
/* XXX conn required for network -> bridge resolution */
3933
static int
3934 3935 3936 3937 3938 3939
lxcDomainAttachDeviceNetLive(virConnectPtr conn,
                             virDomainObjPtr vm,
                             virDomainNetDefPtr net)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    int ret = -1;
3940
    virDomainNetType actualType;
3941
    virNetDevBandwidthPtr actualBandwidth;
3942 3943 3944 3945 3946
    char *veth = NULL;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
M
Martin Kletzander 已提交
3947
        return -1;
3948 3949
    }

3950 3951 3952
    if (virLXCProcessValidateInterface(net) < 0)
       return -1;

3953
    /* preallocate new slot for device */
3954
    if (VIR_REALLOC_N(vm->def->nets, vm->def->nnets+1) < 0)
3955 3956 3957 3958 3959 3960
        return -1;

    /* If appropriate, grab a physical device from the configured
     * network's pool of devices, or resolve bridge device name
     * to the one defined in the network definition.
     */
3961
    if (virDomainNetAllocateActualDevice(vm->def, net) < 0)
3962 3963 3964 3965 3966
        return -1;

    actualType = virDomainNetGetActualType(net);

    switch (actualType) {
3967 3968
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
    case VIR_DOMAIN_NET_TYPE_NETWORK: {
3969 3970 3971 3972 3973 3974
        const char *brname = virDomainNetGetActualBridgeName(net);
        if (!brname) {
            virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                           _("No bridge name specified"));
            goto cleanup;
        }
3975
        if (!(veth = virLXCProcessSetupInterfaceTap(vm->def, net, brname)))
3976 3977
            goto cleanup;
    }   break;
3978 3979 3980 3981
    case VIR_DOMAIN_NET_TYPE_ETHERNET:
        if (!(veth = virLXCProcessSetupInterfaceTap(vm->def, net, NULL)))
            goto cleanup;
        break;
3982
    case VIR_DOMAIN_NET_TYPE_DIRECT: {
3983
        if (!(veth = virLXCProcessSetupInterfaceDirect(conn, vm->def, net)))
3984 3985
            goto cleanup;
    }   break;
3986 3987 3988 3989 3990 3991 3992 3993
    case VIR_DOMAIN_NET_TYPE_USER:
    case VIR_DOMAIN_NET_TYPE_VHOSTUSER:
    case VIR_DOMAIN_NET_TYPE_SERVER:
    case VIR_DOMAIN_NET_TYPE_CLIENT:
    case VIR_DOMAIN_NET_TYPE_MCAST:
    case VIR_DOMAIN_NET_TYPE_INTERNAL:
    case VIR_DOMAIN_NET_TYPE_HOSTDEV:
    case VIR_DOMAIN_NET_TYPE_UDP:
3994 3995 3996
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Network device type is not supported"));
        goto cleanup;
3997 3998 3999 4000
    case VIR_DOMAIN_NET_TYPE_LAST:
    default:
        virReportEnumRangeError(virDomainNetType, actualType);
        goto cleanup;
4001
    }
4002 4003 4004 4005
    /* Set bandwidth or warn if requested and not supported. */
    actualBandwidth = virDomainNetGetActualBandwidth(net);
    if (actualBandwidth) {
        if (virNetDevSupportBandwidth(actualType)) {
4006 4007
            if (virNetDevBandwidthSet(net->ifname, actualBandwidth, false,
                                      !virDomainNetTypeSharesHostView(net)) < 0)
4008 4009 4010
                goto cleanup;
        } else {
            VIR_WARN("setting bandwidth on interfaces of "
4011 4012
                     "type '%s' is not implemented yet: %s",
                     virDomainNetTypeToString(actualType), virGetLastErrorMessage());
4013 4014
        }
    }
4015 4016 4017 4018 4019 4020 4021 4022 4023 4024

    if (virNetDevSetNamespace(veth, priv->initpid) < 0) {
        virDomainAuditNet(vm, NULL, net, "attach", false);
        goto cleanup;
    }

    virDomainAuditNet(vm, NULL, net, "attach", true);

    ret = 0;

4025
 cleanup:
4026 4027 4028 4029 4030 4031
    if (!ret) {
        vm->def->nets[vm->def->nnets++] = net;
    } else if (veth) {
        switch (actualType) {
        case VIR_DOMAIN_NET_TYPE_BRIDGE:
        case VIR_DOMAIN_NET_TYPE_NETWORK:
4032
        case VIR_DOMAIN_NET_TYPE_ETHERNET:
4033 4034 4035 4036 4037 4038
            ignore_value(virNetDevVethDelete(veth));
            break;

        case VIR_DOMAIN_NET_TYPE_DIRECT:
            ignore_value(virNetDevMacVLanDelete(veth));
            break;
4039

4040 4041 4042 4043 4044 4045 4046 4047 4048
        case VIR_DOMAIN_NET_TYPE_USER:
        case VIR_DOMAIN_NET_TYPE_VHOSTUSER:
        case VIR_DOMAIN_NET_TYPE_SERVER:
        case VIR_DOMAIN_NET_TYPE_CLIENT:
        case VIR_DOMAIN_NET_TYPE_MCAST:
        case VIR_DOMAIN_NET_TYPE_INTERNAL:
        case VIR_DOMAIN_NET_TYPE_HOSTDEV:
        case VIR_DOMAIN_NET_TYPE_UDP:
        case VIR_DOMAIN_NET_TYPE_LAST:
4049 4050 4051
        default:
            /* no-op */
            break;
4052 4053 4054 4055 4056 4057 4058
        }
    }

    return ret;
}


4059 4060 4061 4062 4063 4064 4065 4066 4067 4068
static int
lxcDomainAttachDeviceHostdevSubsysUSBLive(virLXCDriverPtr driver,
                                          virDomainObjPtr vm,
                                          virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    char *src = NULL;
    struct stat sb;
4069
    virUSBDevicePtr usb = NULL;
4070
    virDomainHostdevSubsysUSBPtr usbsrc;
4071 4072 4073 4074 4075 4076 4077

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host USB device already exists"));
        return -1;
    }

4078
    usbsrc = &def->source.subsys.u.usb;
4079
    if (virAsprintf(&src, "/dev/bus/usb/%03d/%03d",
4080
                    usbsrc->bus, usbsrc->device) < 0)
4081 4082
        goto cleanup;

4083
    if (!(usb = virUSBDeviceNew(usbsrc->bus, usbsrc->device, NULL)))
4084 4085 4086 4087 4088 4089 4090 4091 4092 4093 4094 4095 4096 4097 4098
        goto cleanup;

    if (stat(src, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"), src);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("USB source %s was not a character device"),
                       src);
        goto cleanup;
    }

4099 4100 4101
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs + 1) < 0)
        goto cleanup;

4102
    if (virUSBDeviceFileIterate(usb,
4103
                                virLXCSetupHostUSBDeviceCgroup,
4104
                                priv->cgroup) < 0)
4105 4106
        goto cleanup;

4107 4108 4109 4110 4111 4112 4113
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFCHR,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   src) < 0) {
        if (virUSBDeviceFileIterate(usb,
4114
                                    virLXCTeardownHostUSBDeviceCgroup,
4115
                                    priv->cgroup) < 0)
4116 4117
            VIR_WARN("cannot deny device %s for domain %s: %s",
                     src, vm->def->name, virGetLastErrorMessage());
4118 4119 4120
        goto cleanup;
    }

4121 4122
    vm->def->hostdevs[vm->def->nhostdevs++] = def;

4123 4124
    ret = 0;

4125
 cleanup:
4126
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
4127
    virUSBDeviceFree(usb);
4128 4129 4130 4131 4132
    VIR_FREE(src);
    return ret;
}


4133 4134 4135 4136 4137 4138 4139 4140 4141 4142 4143 4144 4145 4146 4147 4148 4149 4150 4151 4152 4153 4154 4155 4156 4157 4158 4159 4160 4161 4162 4163 4164 4165 4166 4167 4168
static int
lxcDomainAttachDeviceHostdevStorageLive(virLXCDriverPtr driver,
                                        virDomainObjPtr vm,
                                        virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    struct stat sb;

    if (!def->source.caps.u.storage.block) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Missing storage block path"));
        goto cleanup;
    }

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host device already exists"));
        return -1;
    }

    if (stat(def->source.caps.u.storage.block, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"),
                             def->source.caps.u.storage.block);
        goto cleanup;
    }

    if (!S_ISBLK(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Hostdev source %s must be a block device"),
                       def->source.caps.u.storage.block);
        goto cleanup;
    }

4169
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0)
4170 4171
        goto cleanup;

4172 4173 4174 4175 4176
    if (virCgroupAllowDevice(priv->cgroup,
                             'b',
                             major(sb.st_rdev),
                             minor(sb.st_rdev),
                             VIR_CGROUP_DEVICE_RWM) < 0)
4177 4178
        goto cleanup;

4179 4180 4181 4182 4183 4184 4185 4186 4187 4188 4189
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFBLK,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   def->source.caps.u.storage.block) < 0) {
        if (virCgroupDenyDevice(priv->cgroup,
                                'b',
                                major(sb.st_rdev),
                                minor(sb.st_rdev),
                                VIR_CGROUP_DEVICE_RWM) < 0)
4190 4191
            VIR_WARN("cannot deny device %s for domain %s: %s",
                     def->source.caps.u.storage.block, vm->def->name, virGetLastErrorMessage());
4192 4193 4194 4195 4196 4197 4198
        goto cleanup;
    }

    vm->def->hostdevs[vm->def->nhostdevs++] = def;

    ret = 0;

4199
 cleanup:
4200 4201 4202 4203 4204
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    return ret;
}


4205 4206 4207 4208 4209 4210 4211 4212 4213 4214 4215 4216 4217 4218 4219 4220 4221 4222 4223 4224 4225 4226 4227 4228 4229 4230 4231 4232 4233 4234 4235 4236 4237 4238 4239 4240
static int
lxcDomainAttachDeviceHostdevMiscLive(virLXCDriverPtr driver,
                                     virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = dev->data.hostdev;
    int ret = -1;
    struct stat sb;

    if (!def->source.caps.u.misc.chardev) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Missing storage block path"));
        goto cleanup;
    }

    if (virDomainHostdevFind(vm->def, def, NULL) >= 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("host device already exists"));
        return -1;
    }

    if (stat(def->source.caps.u.misc.chardev, &sb) < 0) {
        virReportSystemError(errno,
                             _("Unable to access %s"),
                             def->source.caps.u.misc.chardev);
        goto cleanup;
    }

    if (!S_ISCHR(sb.st_mode)) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Hostdev source %s must be a block device"),
                       def->source.caps.u.misc.chardev);
        goto cleanup;
    }

4241 4242 4243 4244 4245
    if (virCgroupAllowDevice(priv->cgroup,
                             'c',
                             major(sb.st_rdev),
                             minor(sb.st_rdev),
                             VIR_CGROUP_DEVICE_RWM) < 0)
4246 4247
        goto cleanup;

4248
    if (VIR_REALLOC_N(vm->def->hostdevs, vm->def->nhostdevs+1) < 0)
4249 4250
        goto cleanup;

4251 4252 4253 4254 4255 4256 4257 4258 4259 4260 4261
    if (lxcDomainAttachDeviceMknod(driver,
                                   0700 | S_IFBLK,
                                   sb.st_rdev,
                                   vm,
                                   dev,
                                   def->source.caps.u.misc.chardev) < 0) {
        if (virCgroupDenyDevice(priv->cgroup,
                                'c',
                                major(sb.st_rdev),
                                minor(sb.st_rdev),
                                VIR_CGROUP_DEVICE_RWM) < 0)
4262 4263
            VIR_WARN("cannot deny device %s for domain %s: %s",
                     def->source.caps.u.storage.block, vm->def->name, virGetLastErrorMessage());
4264 4265 4266 4267 4268 4269 4270
        goto cleanup;
    }

    vm->def->hostdevs[vm->def->nhostdevs++] = def;

    ret = 0;

4271
 cleanup:
4272 4273 4274 4275 4276
    virDomainAuditHostdev(vm, def, "attach", ret == 0);
    return ret;
}


4277 4278 4279 4280 4281 4282 4283 4284 4285 4286 4287 4288 4289 4290 4291 4292 4293 4294
static int
lxcDomainAttachDeviceHostdevSubsysLive(virLXCDriverPtr driver,
                                       virDomainObjPtr vm,
                                       virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        return lxcDomainAttachDeviceHostdevSubsysUSBLive(driver, vm, dev);

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevSubsysTypeToString(dev->data.hostdev->source.subsys.type));
        return -1;
    }
}


4295 4296 4297 4298 4299 4300 4301 4302 4303
static int
lxcDomainAttachDeviceHostdevCapsLive(virLXCDriverPtr driver,
                                     virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.caps.type) {
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_STORAGE:
        return lxcDomainAttachDeviceHostdevStorageLive(driver, vm, dev);

4304 4305 4306
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_MISC:
        return lxcDomainAttachDeviceHostdevMiscLive(driver, vm, dev);

4307 4308 4309 4310 4311 4312 4313 4314 4315
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevCapsTypeToString(dev->data.hostdev->source.caps.type));
        return -1;
    }
}


4316 4317 4318 4319 4320 4321 4322 4323 4324 4325 4326 4327 4328
static int
lxcDomainAttachDeviceHostdevLive(virLXCDriverPtr driver,
                                 virDomainObjPtr vm,
                                 virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach hostdev until init PID is known"));
        return -1;
    }

4329 4330 4331 4332 4333 4334
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        return -1;
    }

4335 4336 4337 4338
    switch (dev->data.hostdev->mode) {
    case VIR_DOMAIN_HOSTDEV_MODE_SUBSYS:
        return lxcDomainAttachDeviceHostdevSubsysLive(driver, vm, dev);

4339 4340 4341
    case VIR_DOMAIN_HOSTDEV_MODE_CAPABILITIES:
        return lxcDomainAttachDeviceHostdevCapsLive(driver, vm, dev);

4342 4343 4344 4345 4346 4347 4348 4349 4350
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device mode %s"),
                       virDomainHostdevModeTypeToString(dev->data.hostdev->mode));
        return -1;
    }
}


4351 4352 4353 4354
static int
lxcDomainAttachDeviceLive(virConnectPtr conn,
                          virLXCDriverPtr driver,
                          virDomainObjPtr vm,
4355 4356 4357 4358 4359
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
4360 4361 4362 4363 4364 4365
    case VIR_DOMAIN_DEVICE_DISK:
        ret = lxcDomainAttachDeviceDiskLive(driver, vm, dev);
        if (!ret)
            dev->data.disk = NULL;
        break;

4366 4367 4368 4369 4370 4371 4372
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainAttachDeviceNetLive(conn, vm,
                                           dev->data.net);
        if (!ret)
            dev->data.net = NULL;
        break;

4373 4374 4375
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        ret = lxcDomainAttachDeviceHostdevLive(driver, vm, dev);
        if (!ret)
C
Chen Hanxiao 已提交
4376
            dev->data.hostdev = NULL;
4377 4378
        break;

4379 4380 4381 4382 4383 4384 4385 4386 4387 4388 4389
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be attached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


4390
static int
4391
lxcDomainDetachDeviceDiskLive(virDomainObjPtr vm,
4392 4393 4394 4395
                              virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainDiskDefPtr def = NULL;
4396
    int idx, ret = -1;
J
John Ferlan 已提交
4397
    char *dst = NULL;
4398
    const char *src;
4399 4400 4401 4402 4403 4404 4405

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4406 4407 4408
    if ((idx = virDomainDiskIndexByName(vm->def,
                                        dev->data.disk->dst,
                                        false)) < 0) {
4409 4410 4411 4412 4413
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("disk %s not found"), dev->data.disk->dst);
        goto cleanup;
    }

4414
    def = vm->def->disks[idx];
4415
    src = virDomainDiskGetSource(def);
4416

4417
    if (virAsprintf(&dst, "/dev/%s", def->dst) < 0)
4418 4419
        goto cleanup;

4420
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4421 4422 4423 4424 4425
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4426
    if (lxcDomainAttachDeviceUnlink(vm, dst) < 0) {
4427
        virDomainAuditDisk(vm, def->src, NULL, "detach", false);
4428 4429
        goto cleanup;
    }
4430
    virDomainAuditDisk(vm, def->src, NULL, "detach", true);
4431

4432 4433
    if (virCgroupDenyDevicePath(priv->cgroup, src,
                                VIR_CGROUP_DEVICE_RWM, false) != 0)
4434 4435
        VIR_WARN("cannot deny device %s for domain %s: %s",
                 src, vm->def->name, virGetLastErrorMessage());
4436

4437
    virDomainDiskRemove(vm->def, idx);
4438 4439 4440 4441
    virDomainDiskDefFree(def);

    ret = 0;

4442
 cleanup:
4443 4444 4445 4446 4447
    VIR_FREE(dst);
    return ret;
}


4448
static int
4449 4450 4451
lxcDomainDetachDeviceNetLive(virDomainObjPtr vm,
                             virDomainDeviceDefPtr dev)
{
4452 4453
    int detachidx, ret = -1;
    virDomainNetType actualType;
4454 4455 4456
    virDomainNetDefPtr detach = NULL;
    virNetDevVPortProfilePtr vport = NULL;

4457
    if ((detachidx = virDomainNetFindIdx(vm->def, dev->data.net)) < 0)
4458
        goto cleanup;
4459

4460
    detach = vm->def->nets[detachidx];
4461 4462 4463
    actualType = virDomainNetGetActualType(detach);

    /* clear network bandwidth */
4464 4465
    if (virDomainNetGetActualBandwidth(detach) &&
        virNetDevSupportBandwidth(actualType) &&
4466 4467
        virNetDevBandwidthClear(detach->ifname))
        goto cleanup;
4468

4469
    switch (actualType) {
4470 4471
    case VIR_DOMAIN_NET_TYPE_BRIDGE:
    case VIR_DOMAIN_NET_TYPE_NETWORK:
4472
    case VIR_DOMAIN_NET_TYPE_ETHERNET:
4473 4474 4475 4476 4477 4478 4479 4480 4481 4482 4483
        if (virNetDevVethDelete(detach->ifname) < 0) {
            virDomainAuditNet(vm, detach, NULL, "detach", false);
            goto cleanup;
        }
        break;

        /* It'd be nice to support this, but with macvlan
         * once assigned to a container nothing exists on
         * the host side. Further the container can change
         * the mac address of NIC name, so we can't easily
         * find out which guest NIC it maps to
4484
         */
4485
    case VIR_DOMAIN_NET_TYPE_DIRECT:
4486 4487 4488 4489 4490 4491 4492 4493
    case VIR_DOMAIN_NET_TYPE_USER:
    case VIR_DOMAIN_NET_TYPE_VHOSTUSER:
    case VIR_DOMAIN_NET_TYPE_SERVER:
    case VIR_DOMAIN_NET_TYPE_CLIENT:
    case VIR_DOMAIN_NET_TYPE_MCAST:
    case VIR_DOMAIN_NET_TYPE_INTERNAL:
    case VIR_DOMAIN_NET_TYPE_HOSTDEV:
    case VIR_DOMAIN_NET_TYPE_UDP:
4494 4495 4496
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Only bridged veth devices can be detached"));
        goto cleanup;
4497 4498 4499 4500
    case VIR_DOMAIN_NET_TYPE_LAST:
    default:
        virReportEnumRangeError(virDomainNetType, actualType);
        goto cleanup;
4501 4502 4503 4504 4505 4506 4507 4508 4509 4510 4511 4512
    }

    virDomainAuditNet(vm, detach, NULL, "detach", true);

    virDomainConfNWFilterTeardown(detach);

    vport = virDomainNetGetActualVirtPortProfile(detach);
    if (vport && vport->virtPortType == VIR_NETDEV_VPORT_PROFILE_OPENVSWITCH)
        ignore_value(virNetDevOpenvswitchRemovePort(
                        virDomainNetGetActualBridgeName(detach),
                        detach->ifname));
    ret = 0;
4513
 cleanup:
4514
    if (!ret) {
4515
        virDomainNetReleaseActualDevice(vm->def, detach);
4516 4517 4518 4519 4520 4521 4522
        virDomainNetRemove(vm->def, detachidx);
        virDomainNetDefFree(detach);
    }
    return ret;
}


4523 4524 4525 4526 4527 4528 4529 4530
static int
lxcDomainDetachDeviceHostdevUSBLive(virLXCDriverPtr driver,
                                    virDomainObjPtr vm,
                                    virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
    int idx, ret = -1;
J
John Ferlan 已提交
4531
    char *dst = NULL;
4532
    virUSBDevicePtr usb = NULL;
4533
    virHostdevManagerPtr hostdev_mgr = driver->hostdevMgr;
4534
    virDomainHostdevSubsysUSBPtr usbsrc;
4535 4536 4537 4538 4539 4540 4541 4542 4543

    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
        virReportError(VIR_ERR_OPERATION_FAILED, "%s",
                       _("usb device not found"));
        goto cleanup;
    }

4544
    usbsrc = &def->source.subsys.u.usb;
4545
    if (virAsprintf(&dst, "/dev/bus/usb/%03d/%03d",
4546
                    usbsrc->bus, usbsrc->device) < 0)
4547 4548
        goto cleanup;

4549
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4550 4551 4552 4553 4554
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4555
    if (!(usb = virUSBDeviceNew(usbsrc->bus, usbsrc->device, NULL)))
4556 4557
        goto cleanup;

4558
    if (lxcDomainAttachDeviceUnlink(vm, dst) < 0) {
4559 4560 4561 4562 4563
        virDomainAuditHostdev(vm, def, "detach", false);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4564
    if (virUSBDeviceFileIterate(usb,
4565
                                virLXCTeardownHostUSBDeviceCgroup,
4566
                                priv->cgroup) < 0)
4567 4568
        VIR_WARN("cannot deny device %s for domain %s: %s",
                 dst, vm->def->name, virGetLastErrorMessage());
4569

4570 4571 4572
    virObjectLock(hostdev_mgr->activeUSBHostdevs);
    virUSBDeviceListDel(hostdev_mgr->activeUSBHostdevs, usb);
    virObjectUnlock(hostdev_mgr->activeUSBHostdevs);
4573 4574 4575 4576 4577 4578

    virDomainHostdevRemove(vm->def, idx);
    virDomainHostdevDefFree(def);

    ret = 0;

4579
 cleanup:
4580
    virUSBDeviceFree(usb);
4581 4582 4583 4584
    VIR_FREE(dst);
    return ret;
}

4585 4586

static int
4587
lxcDomainDetachDeviceHostdevStorageLive(virDomainObjPtr vm,
4588 4589 4590 4591
                                        virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
4592
    int idx, ret = -1;
4593 4594 4595 4596 4597 4598 4599

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4600 4601 4602
    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
4603 4604 4605 4606 4607 4608
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("hostdev %s not found"),
                       dev->data.hostdev->source.caps.u.storage.block);
        goto cleanup;
    }

4609
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4610 4611 4612 4613 4614
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4615
    if (lxcDomainAttachDeviceUnlink(vm, def->source.caps.u.storage.block) < 0) {
4616 4617 4618 4619 4620
        virDomainAuditHostdev(vm, def, "detach", false);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4621 4622
    if (virCgroupDenyDevicePath(priv->cgroup, def->source.caps.u.storage.block,
                                VIR_CGROUP_DEVICE_RWM, false) != 0)
4623 4624
        VIR_WARN("cannot deny device %s for domain %s: %s",
                 def->source.caps.u.storage.block, vm->def->name, virGetLastErrorMessage());
4625

4626
    virDomainHostdevRemove(vm->def, idx);
4627 4628 4629 4630
    virDomainHostdevDefFree(def);

    ret = 0;

4631
 cleanup:
4632 4633 4634 4635
    return ret;
}


4636
static int
4637
lxcDomainDetachDeviceHostdevMiscLive(virDomainObjPtr vm,
4638 4639 4640 4641
                                     virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;
    virDomainHostdevDefPtr def = NULL;
4642
    int idx, ret = -1;
4643 4644 4645 4646 4647 4648 4649

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach disk until init PID is known"));
        goto cleanup;
    }

4650 4651 4652
    if ((idx = virDomainHostdevFind(vm->def,
                                    dev->data.hostdev,
                                    &def)) < 0) {
4653 4654 4655 4656 4657 4658
        virReportError(VIR_ERR_OPERATION_FAILED,
                       _("hostdev %s not found"),
                       dev->data.hostdev->source.caps.u.misc.chardev);
        goto cleanup;
    }

4659
    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_DEVICES)) {
4660 4661 4662 4663 4664
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("devices cgroup isn't mounted"));
        goto cleanup;
    }

4665
    if (lxcDomainAttachDeviceUnlink(vm, def->source.caps.u.misc.chardev) < 0) {
4666 4667 4668 4669 4670
        virDomainAuditHostdev(vm, def, "detach", false);
        goto cleanup;
    }
    virDomainAuditHostdev(vm, def, "detach", true);

4671 4672
    if (virCgroupDenyDevicePath(priv->cgroup, def->source.caps.u.misc.chardev,
                                VIR_CGROUP_DEVICE_RWM, false) != 0)
4673 4674
        VIR_WARN("cannot deny device %s for domain %s: %s",
                 def->source.caps.u.misc.chardev, vm->def->name, virGetLastErrorMessage());
4675

4676
    virDomainHostdevRemove(vm->def, idx);
4677 4678 4679 4680
    virDomainHostdevDefFree(def);

    ret = 0;

4681
 cleanup:
4682 4683 4684 4685
    return ret;
}


4686 4687 4688 4689 4690 4691 4692 4693 4694 4695 4696 4697 4698 4699 4700 4701 4702 4703
static int
lxcDomainDetachDeviceHostdevSubsysLive(virLXCDriverPtr driver,
                                       virDomainObjPtr vm,
                                       virDomainDeviceDefPtr dev)
{
    switch (dev->data.hostdev->source.subsys.type) {
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB:
        return lxcDomainDetachDeviceHostdevUSBLive(driver, vm, dev);

    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevSubsysTypeToString(dev->data.hostdev->source.subsys.type));
        return -1;
    }
}


4704
static int
4705 4706
lxcDomainDetachDeviceHostdevCapsLive(virDomainObjPtr vm,
                                     virDomainDeviceDefPtr dev)
4707 4708 4709
{
    switch (dev->data.hostdev->source.caps.type) {
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_STORAGE:
4710
        return lxcDomainDetachDeviceHostdevStorageLive(vm, dev);
4711

4712
    case VIR_DOMAIN_HOSTDEV_CAPS_TYPE_MISC:
4713
        return lxcDomainDetachDeviceHostdevMiscLive(vm, dev);
4714

4715 4716 4717 4718 4719 4720 4721 4722 4723
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device type %s"),
                       virDomainHostdevCapsTypeToString(dev->data.hostdev->source.caps.type));
        return -1;
    }
}


4724 4725 4726 4727 4728 4729 4730 4731 4732 4733 4734 4735 4736 4737 4738 4739 4740
static int
lxcDomainDetachDeviceHostdevLive(virLXCDriverPtr driver,
                                 virDomainObjPtr vm,
                                 virDomainDeviceDefPtr dev)
{
    virLXCDomainObjPrivatePtr priv = vm->privateData;

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Cannot attach hostdev until init PID is known"));
        return -1;
    }

    switch (dev->data.hostdev->mode) {
    case VIR_DOMAIN_HOSTDEV_MODE_SUBSYS:
        return lxcDomainDetachDeviceHostdevSubsysLive(driver, vm, dev);

4741
    case VIR_DOMAIN_HOSTDEV_MODE_CAPABILITIES:
4742
        return lxcDomainDetachDeviceHostdevCapsLive(vm, dev);
4743

4744 4745 4746 4747 4748 4749 4750 4751 4752
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("Unsupported host device mode %s"),
                       virDomainHostdevModeTypeToString(dev->data.hostdev->mode));
        return -1;
    }
}


4753 4754 4755
static int
lxcDomainDetachDeviceLive(virLXCDriverPtr driver,
                          virDomainObjPtr vm,
4756 4757 4758 4759 4760
                          virDomainDeviceDefPtr dev)
{
    int ret = -1;

    switch (dev->type) {
4761
    case VIR_DOMAIN_DEVICE_DISK:
4762
        ret = lxcDomainDetachDeviceDiskLive(vm, dev);
4763 4764
        break;

4765 4766 4767 4768
    case VIR_DOMAIN_DEVICE_NET:
        ret = lxcDomainDetachDeviceNetLive(vm, dev);
        break;

4769 4770 4771 4772
    case VIR_DOMAIN_DEVICE_HOSTDEV:
        ret = lxcDomainDetachDeviceHostdevLive(driver, vm, dev);
        break;

4773 4774 4775 4776 4777 4778 4779 4780 4781 4782 4783
    default:
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
                       _("device type '%s' cannot be detached"),
                       virDomainDeviceTypeToString(dev->type));
        break;
    }

    return ret;
}


4784 4785 4786
static int lxcDomainAttachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
4787 4788
{
    virLXCDriverPtr driver = dom->conn->privateData;
4789
    virCapsPtr caps = NULL;
4790 4791 4792 4793
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
4794
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4795 4796

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
4797
                  VIR_DOMAIN_AFFECT_CONFIG, -1);
4798

M
Michal Privoznik 已提交
4799
    if (!(vm = lxcDomObjFromDomain(dom)))
4800 4801
        goto cleanup;

4802 4803 4804
    if (virDomainAttachDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4805
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
4806 4807
        goto cleanup;

4808 4809 4810
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto endjob;

4811
    if (virDomainObjUpdateModificationImpact(vm, &flags) < 0)
4812
        goto endjob;
4813

4814
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4815
                                             caps, driver->xmlopt,
4816
                                             VIR_DOMAIN_DEF_PARSE_INACTIVE);
4817
    if (dev == NULL)
4818
        goto endjob;
4819 4820 4821 4822 4823 4824 4825

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
4826
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4827
                                          caps, driver->xmlopt);
4828
        if (!dev_copy)
4829
            goto endjob;
4830 4831 4832 4833
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
4834
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4835
        if (!vmdef)
4836
            goto endjob;
4837

4838
        if (virDomainDefCompatibleDevice(vmdef, dev, NULL) < 0)
4839
            goto endjob;
4840

4841
        if ((ret = lxcDomainAttachDeviceConfig(vmdef, dev)) < 0)
4842
            goto endjob;
4843 4844 4845
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
4846
        if (virDomainDefCompatibleDevice(vm->def, dev_copy, NULL) < 0)
4847
            goto endjob;
4848

4849
        if ((ret = lxcDomainAttachDeviceLive(dom->conn, driver, vm, dev_copy)) < 0)
4850
            goto endjob;
4851 4852 4853 4854 4855
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
4856
        if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0) {
4857
            ret = -1;
4858
            goto endjob;
4859 4860 4861 4862 4863
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
4864
        ret = virDomainSaveConfig(cfg->configDir, driver->caps, vmdef);
4865
        if (!ret) {
4866
            virDomainObjAssignDef(vm, vmdef, false, NULL);
4867 4868 4869 4870
            vmdef = NULL;
        }
    }

4871
 endjob:
4872 4873
    virLXCDomainObjEndJob(driver, vm);

4874
 cleanup:
4875 4876 4877 4878
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
4879
    virDomainObjEndAPI(&vm);
4880
    virObjectUnref(caps);
4881
    virObjectUnref(cfg);
4882 4883 4884 4885 4886 4887 4888 4889 4890 4891 4892 4893 4894 4895 4896 4897
    return ret;
}


static int lxcDomainAttachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainAttachDeviceFlags(dom, xml,
                                       VIR_DOMAIN_AFFECT_LIVE);
}


static int lxcDomainUpdateDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
4898
    virLXCDriverPtr driver = dom->conn->privateData;
4899
    virCapsPtr caps = NULL;
4900 4901 4902 4903
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
4904
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4905 4906 4907 4908 4909

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG |
                  VIR_DOMAIN_DEVICE_MODIFY_FORCE, -1);

M
Michal Privoznik 已提交
4910
    if (!(vm = lxcDomObjFromDomain(dom)))
4911 4912
        goto cleanup;

4913 4914 4915
    if (virDomainUpdateDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

4916
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
4917
        goto cleanup;
4918

4919 4920 4921
    if (virDomainObjUpdateModificationImpact(vm, &flags) < 0)
        goto endjob;

4922
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
4923
        goto endjob;
4924

4925
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
4926
                                             caps, driver->xmlopt,
4927
                                             VIR_DOMAIN_DEF_PARSE_INACTIVE);
4928
    if (dev == NULL)
4929
        goto endjob;
4930 4931 4932 4933 4934 4935 4936 4937

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
4938
                                          caps, driver->xmlopt);
4939
        if (!dev_copy)
4940
            goto endjob;
4941 4942 4943 4944
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
4945
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
4946
        if (!vmdef)
4947
            goto endjob;
4948

4949 4950
        /* virDomainDefCompatibleDevice call is delayed until we know the
         * device we're going to update. */
4951
        if ((ret = lxcDomainUpdateDeviceConfig(vmdef, dev)) < 0)
4952
            goto endjob;
4953 4954 4955 4956 4957 4958
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
                       _("Unable to modify live devices"));

4959
        goto endjob;
4960 4961 4962 4963
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
4964
        ret = virDomainSaveConfig(cfg->configDir, driver->caps, vmdef);
4965 4966 4967 4968 4969
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false, NULL);
            vmdef = NULL;
        }
    }
4970
 endjob:
4971 4972
    virLXCDomainObjEndJob(driver, vm);

4973
 cleanup:
4974 4975 4976 4977
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
4978
    virDomainObjEndAPI(&vm);
4979
    virObjectUnref(caps);
4980
    virObjectUnref(cfg);
4981
    return ret;
4982 4983 4984 4985 4986 4987 4988
}


static int lxcDomainDetachDeviceFlags(virDomainPtr dom,
                                      const char *xml,
                                      unsigned int flags)
{
4989
    virLXCDriverPtr driver = dom->conn->privateData;
4990
    virCapsPtr caps = NULL;
4991 4992 4993 4994
    virDomainObjPtr vm = NULL;
    virDomainDefPtr vmdef = NULL;
    virDomainDeviceDefPtr dev = NULL, dev_copy = NULL;
    int ret = -1;
4995
    virLXCDriverConfigPtr cfg = virLXCDriverGetConfig(driver);
4996 4997 4998 4999

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

M
Michal Privoznik 已提交
5000
    if (!(vm = lxcDomObjFromDomain(dom)))
5001 5002
        goto cleanup;

5003 5004 5005
    if (virDomainDetachDeviceFlagsEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

5006
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
5007
        goto cleanup;
5008

5009 5010 5011
    if (virDomainObjUpdateModificationImpact(vm, &flags) < 0)
        goto endjob;

5012
    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
5013
        goto endjob;
5014

5015
    dev = dev_copy = virDomainDeviceDefParse(xml, vm->def,
5016
                                             caps, driver->xmlopt,
5017 5018
                                             VIR_DOMAIN_DEF_PARSE_INACTIVE |
                                             VIR_DOMAIN_DEF_PARSE_SKIP_VALIDATE);
5019
    if (dev == NULL)
5020
        goto endjob;
5021 5022 5023 5024 5025 5026 5027 5028

    if (flags & VIR_DOMAIN_AFFECT_CONFIG &&
        flags & VIR_DOMAIN_AFFECT_LIVE) {
        /* If we are affecting both CONFIG and LIVE
         * create a deep copy of device as adding
         * to CONFIG takes one instance.
         */
        dev_copy = virDomainDeviceDefCopy(dev, vm->def,
5029
                                          caps, driver->xmlopt);
5030
        if (!dev_copy)
5031
            goto endjob;
5032 5033 5034 5035
    }

    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
        /* Make a copy for updated domain. */
5036
        vmdef = virDomainObjCopyPersistentDef(vm, caps, driver->xmlopt);
5037
        if (!vmdef)
5038
            goto endjob;
5039 5040

        if ((ret = lxcDomainDetachDeviceConfig(vmdef, dev)) < 0)
5041
            goto endjob;
5042 5043 5044 5045
    }

    if (flags & VIR_DOMAIN_AFFECT_LIVE) {
        if ((ret = lxcDomainDetachDeviceLive(driver, vm, dev_copy)) < 0)
5046
            goto endjob;
5047 5048 5049 5050 5051
        /*
         * update domain status forcibly because the domain status may be
         * changed even if we failed to attach the device. For example,
         * a new controller may be created.
         */
5052
        if (virDomainSaveStatus(driver->xmlopt, cfg->stateDir, vm, driver->caps) < 0) {
5053
            ret = -1;
5054
            goto endjob;
5055 5056 5057 5058 5059
        }
    }

    /* Finally, if no error until here, we can save config. */
    if (flags & VIR_DOMAIN_AFFECT_CONFIG) {
5060
        ret = virDomainSaveConfig(cfg->configDir, driver->caps, vmdef);
5061 5062 5063 5064 5065 5066
        if (!ret) {
            virDomainObjAssignDef(vm, vmdef, false, NULL);
            vmdef = NULL;
        }
    }

5067
 endjob:
5068 5069
    virLXCDomainObjEndJob(driver, vm);

5070
 cleanup:
5071 5072 5073 5074
    virDomainDefFree(vmdef);
    if (dev != dev_copy)
        virDomainDeviceDefFree(dev_copy);
    virDomainDeviceDefFree(dev);
5075
    virDomainObjEndAPI(&vm);
5076
    virObjectUnref(caps);
5077
    virObjectUnref(cfg);
5078
    return ret;
5079 5080 5081 5082 5083 5084 5085 5086 5087 5088 5089
}


static int lxcDomainDetachDevice(virDomainPtr dom,
                                 const char *xml)
{
    return lxcDomainDetachDeviceFlags(dom, xml,
                                      VIR_DOMAIN_AFFECT_LIVE);
}


5090 5091 5092
static int lxcDomainLxcOpenNamespace(virDomainPtr dom,
                                     int **fdlist,
                                     unsigned int flags)
5093
{
5094
    virLXCDriverPtr driver = dom->conn->privateData;
5095 5096 5097 5098 5099 5100 5101 5102
    virDomainObjPtr vm;
    virLXCDomainObjPrivatePtr priv;
    int ret = -1;
    size_t nfds = 0;

    *fdlist = NULL;
    virCheckFlags(0, -1);

M
Michal Privoznik 已提交
5103
    if (!(vm = lxcDomObjFromDomain(dom)))
5104
        goto cleanup;
M
Michal Privoznik 已提交
5105

5106 5107
    priv = vm->privateData;

5108 5109 5110
    if (virDomainLxcOpenNamespaceEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

5111 5112 5113
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_QUERY) < 0)
        goto cleanup;

5114 5115 5116
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("Domain is not running"));
5117
        goto endjob;
5118 5119 5120 5121 5122
    }

    if (!priv->initpid) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("Init pid is not yet available"));
5123
        goto endjob;
5124 5125 5126
    }

    if (virProcessGetNamespaces(priv->initpid, &nfds, fdlist) < 0)
5127
        goto endjob;
5128 5129

    ret = nfds;
5130 5131

 endjob:
5132
    virLXCDomainObjEndJob(driver, vm);
5133

5134
 cleanup:
5135
    virDomainObjEndAPI(&vm);
5136 5137 5138 5139
    return ret;
}


5140
static char *
5141
lxcConnectGetSysinfo(virConnectPtr conn, unsigned int flags)
5142 5143 5144 5145 5146 5147
{
    virLXCDriverPtr driver = conn->privateData;
    virBuffer buf = VIR_BUFFER_INITIALIZER;

    virCheckFlags(0, NULL);

5148 5149 5150
    if (virConnectGetSysinfoEnsureACL(conn) < 0)
        return NULL;

5151 5152 5153 5154 5155 5156 5157 5158
    if (!driver->hostsysinfo) {
        virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s",
                       _("Host SMBIOS information is not available"));
        return NULL;
    }

    if (virSysinfoFormat(&buf, driver->hostsysinfo) < 0)
        return NULL;
5159
    if (virBufferCheckError(&buf) < 0)
5160 5161 5162 5163 5164
        return NULL;
    return virBufferContentAndReset(&buf);
}


5165
static int
5166
lxcNodeGetInfo(virConnectPtr conn,
5167 5168
               virNodeInfoPtr nodeinfo)
{
5169 5170 5171
    if (virNodeGetInfoEnsureACL(conn) < 0)
        return -1;

M
Martin Kletzander 已提交
5172
    return virCapabilitiesGetNodeInfo(nodeinfo);
5173 5174 5175
}


5176 5177
static int
lxcDomainMemoryStats(virDomainPtr dom,
5178
                     virDomainMemoryStatPtr stats,
5179 5180 5181 5182 5183 5184 5185 5186
                     unsigned int nr_stats,
                     unsigned int flags)
{
    virDomainObjPtr vm;
    int ret = -1;
    virLXCDomainObjPrivatePtr priv;
    unsigned long long swap_usage;
    unsigned long mem_usage;
5187
    virLXCDriverPtr driver = dom->conn->privateData;
5188 5189 5190 5191 5192 5193 5194 5195 5196 5197 5198

    virCheckFlags(0, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        goto cleanup;

    priv = vm->privateData;

    if (virDomainMemoryStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

5199 5200 5201
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_QUERY) < 0)
        goto cleanup;

5202 5203 5204
    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("domain is not active"));
5205
        goto endjob;
5206
    }
5207

5208
    if (virCgroupGetMemSwapUsage(priv->cgroup, &swap_usage) < 0)
5209
        goto endjob;
5210

5211
    if (virCgroupGetMemoryUsage(priv->cgroup, &mem_usage) < 0)
5212
        goto endjob;
5213 5214 5215 5216 5217 5218 5219 5220 5221 5222 5223 5224 5225 5226 5227 5228 5229 5230

    ret = 0;
    if (ret < nr_stats) {
        stats[ret].tag = VIR_DOMAIN_MEMORY_STAT_ACTUAL_BALLOON;
        stats[ret].val = vm->def->mem.cur_balloon;
        ret++;
    }
    if (ret < nr_stats) {
        stats[ret].tag = VIR_DOMAIN_MEMORY_STAT_SWAP_IN;
        stats[ret].val = swap_usage;
        ret++;
    }
    if (ret < nr_stats) {
        stats[ret].tag = VIR_DOMAIN_MEMORY_STAT_RSS;
        stats[ret].val = mem_usage;
        ret++;
    }

5231
 endjob:
5232 5233
    virLXCDomainObjEndJob(driver, vm);

5234
 cleanup:
5235
    virDomainObjEndAPI(&vm);
5236 5237 5238 5239
    return ret;
}


5240
static int
5241
lxcNodeGetCPUStats(virConnectPtr conn,
5242 5243 5244 5245 5246
                   int cpuNum,
                   virNodeCPUStatsPtr params,
                   int *nparams,
                   unsigned int flags)
{
5247 5248 5249
    if (virNodeGetCPUStatsEnsureACL(conn) < 0)
        return -1;

5250
    return virHostCPUGetStats(cpuNum, params, nparams, flags);
5251 5252 5253 5254
}


static int
5255
lxcNodeGetMemoryStats(virConnectPtr conn,
5256 5257 5258 5259 5260
                      int cellNum,
                      virNodeMemoryStatsPtr params,
                      int *nparams,
                      unsigned int flags)
{
5261 5262 5263
    if (virNodeGetMemoryStatsEnsureACL(conn) < 0)
        return -1;

5264
    return virHostMemGetStats(cellNum, params, nparams, flags);
5265 5266 5267 5268
}


static int
5269
lxcNodeGetCellsFreeMemory(virConnectPtr conn,
5270 5271 5272 5273
                          unsigned long long *freeMems,
                          int startCell,
                          int maxCells)
{
5274 5275 5276
    if (virNodeGetCellsFreeMemoryEnsureACL(conn) < 0)
        return -1;

5277
    return virHostMemGetCellsFree(freeMems, startCell, maxCells);
5278 5279 5280 5281
}


static unsigned long long
5282
lxcNodeGetFreeMemory(virConnectPtr conn)
5283
{
5284 5285
    unsigned long long freeMem;

5286 5287 5288
    if (virNodeGetFreeMemoryEnsureACL(conn) < 0)
        return 0;

5289
    if (virHostMemGetInfo(NULL, &freeMem) < 0)
5290 5291 5292
        return 0;

    return freeMem;
5293 5294 5295 5296
}


static int
5297
lxcNodeGetMemoryParameters(virConnectPtr conn,
5298 5299 5300 5301
                           virTypedParameterPtr params,
                           int *nparams,
                           unsigned int flags)
{
5302 5303 5304
    if (virNodeGetMemoryParametersEnsureACL(conn) < 0)
        return -1;

5305
    return virHostMemGetParameters(params, nparams, flags);
5306 5307 5308 5309
}


static int
5310
lxcNodeSetMemoryParameters(virConnectPtr conn,
5311 5312 5313 5314
                           virTypedParameterPtr params,
                           int nparams,
                           unsigned int flags)
{
5315 5316 5317
    if (virNodeSetMemoryParametersEnsureACL(conn) < 0)
        return -1;

5318
    return virHostMemSetParameters(params, nparams, flags);
5319 5320 5321 5322
}


static int
5323
lxcNodeGetCPUMap(virConnectPtr conn,
5324 5325 5326 5327
                 unsigned char **cpumap,
                 unsigned int *online,
                 unsigned int flags)
{
5328 5329 5330
    if (virNodeGetCPUMapEnsureACL(conn) < 0)
        return -1;

5331
    return virHostCPUGetMap(cpumap, online, flags);
5332 5333
}

5334 5335

static int
5336
lxcNodeSuspendForDuration(virConnectPtr conn,
5337 5338 5339 5340
                          unsigned int target,
                          unsigned long long duration,
                          unsigned int flags)
{
5341 5342 5343
    if (virNodeSuspendForDurationEnsureACL(conn) < 0)
        return -1;

5344
    return virNodeSuspend(target, duration, flags);
5345 5346 5347
}


5348 5349 5350 5351 5352 5353 5354 5355 5356 5357 5358 5359 5360 5361 5362 5363 5364 5365 5366 5367 5368 5369 5370 5371 5372 5373 5374 5375
static int
lxcDomainSetMetadata(virDomainPtr dom,
                      int type,
                      const char *metadata,
                      const char *key,
                      const char *uri,
                      unsigned int flags)
{
    virLXCDriverPtr driver = dom->conn->privateData;
    virDomainObjPtr vm;
    virLXCDriverConfigPtr cfg = NULL;
    virCapsPtr caps = NULL;
    int ret = -1;

    virCheckFlags(VIR_DOMAIN_AFFECT_LIVE |
                  VIR_DOMAIN_AFFECT_CONFIG, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        return -1;

    cfg = virLXCDriverGetConfig(driver);

    if (virDomainSetMetadataEnsureACL(dom->conn, vm->def, flags) < 0)
        goto cleanup;

    if (!(caps = virLXCDriverGetCapabilities(driver, false)))
        goto cleanup;

5376 5377 5378
    if (virLXCDomainObjBeginJob(driver, vm, LXC_JOB_MODIFY) < 0)
        goto cleanup;

5379
    ret = virDomainObjSetMetadata(vm, type, metadata, key, uri, caps,
5380 5381
                                  driver->xmlopt, cfg->stateDir,
                                  cfg->configDir, flags);
5382

5383 5384 5385 5386 5387 5388
    if (ret == 0) {
        virObjectEventPtr ev = NULL;
        ev = virDomainEventMetadataChangeNewFromObj(vm, type, uri);
        virObjectEventStateQueue(driver->domainEventState, ev);
    }

5389
    virLXCDomainObjEndJob(driver, vm);
5390

5391
 cleanup:
5392
    virDomainObjEndAPI(&vm);
5393 5394 5395 5396 5397 5398 5399 5400 5401 5402 5403 5404 5405 5406 5407 5408 5409 5410 5411 5412 5413
    virObjectUnref(caps);
    virObjectUnref(cfg);
    return ret;
}


static char *
lxcDomainGetMetadata(virDomainPtr dom,
                      int type,
                      const char *uri,
                      unsigned int flags)
{
    virDomainObjPtr vm;
    char *ret = NULL;

    if (!(vm = lxcDomObjFromDomain(dom)))
        return NULL;

    if (virDomainGetMetadataEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

5414
    ret = virDomainObjGetMetadata(vm, type, uri, flags);
5415

5416
 cleanup:
5417
    virDomainObjEndAPI(&vm);
5418 5419 5420 5421
    return ret;
}


5422 5423 5424 5425 5426 5427 5428 5429 5430 5431 5432 5433 5434 5435 5436 5437 5438 5439 5440 5441 5442 5443 5444 5445 5446 5447 5448 5449 5450 5451 5452 5453 5454 5455 5456 5457 5458 5459 5460
static int
lxcDomainGetCPUStats(virDomainPtr dom,
                     virTypedParameterPtr params,
                     unsigned int nparams,
                     int start_cpu,
                     unsigned int ncpus,
                     unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    int ret = -1;
    virLXCDomainObjPrivatePtr priv;

    virCheckFlags(VIR_TYPED_PARAM_STRING_OKAY, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    priv = vm->privateData;

    if (virDomainGetCPUStatsEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

    if (!virDomainObjIsActive(vm)) {
        virReportError(VIR_ERR_OPERATION_INVALID, "%s",
                       _("domain is not running"));
        goto cleanup;
    }

    if (!virCgroupHasController(priv->cgroup, VIR_CGROUP_CONTROLLER_CPUACCT)) {
        virReportError(VIR_ERR_OPERATION_INVALID,
                       "%s", _("cgroup CPUACCT controller is not mounted"));
        goto cleanup;
    }

    if (start_cpu == -1)
        ret = virCgroupGetDomainTotalCpuStats(priv->cgroup,
                                              params, nparams);
    else
        ret = virCgroupGetPercpuStats(priv->cgroup, params,
5461
                                      nparams, start_cpu, ncpus, NULL);
5462
 cleanup:
5463
    virDomainObjEndAPI(&vm);
5464 5465 5466 5467
    return ret;
}


5468 5469 5470 5471 5472 5473 5474 5475 5476 5477 5478 5479 5480 5481
static int
lxcNodeGetFreePages(virConnectPtr conn,
                    unsigned int npages,
                    unsigned int *pages,
                    int startCell,
                    unsigned int cellCount,
                    unsigned long long *counts,
                    unsigned int flags)
{
    virCheckFlags(0, -1);

    if (virNodeGetFreePagesEnsureACL(conn) < 0)
        return -1;

5482
    return virHostMemGetFreePages(npages, pages, startCell, cellCount, counts);
5483 5484 5485
}


5486 5487 5488 5489 5490 5491 5492 5493 5494 5495 5496 5497 5498 5499 5500 5501
static int
lxcNodeAllocPages(virConnectPtr conn,
                  unsigned int npages,
                  unsigned int *pageSizes,
                  unsigned long long *pageCounts,
                  int startCell,
                  unsigned int cellCount,
                  unsigned int flags)
{
    bool add = !(flags & VIR_NODE_ALLOC_PAGES_SET);

    virCheckFlags(VIR_NODE_ALLOC_PAGES_SET, -1);

    if (virNodeAllocPagesEnsureACL(conn) < 0)
        return -1;

5502 5503
    return virHostMemAllocPages(npages, pageSizes, pageCounts,
                                startCell, cellCount, add);
5504 5505 5506
}


5507 5508 5509 5510 5511 5512 5513 5514 5515 5516 5517 5518 5519 5520 5521 5522 5523
static int
lxcDomainHasManagedSaveImage(virDomainPtr dom, unsigned int flags)
{
    virDomainObjPtr vm = NULL;
    int ret = -1;

    virCheckFlags(0, -1);

    if (!(vm = lxcDomObjFromDomain(dom)))
        return ret;

    if (virDomainHasManagedSaveImageEnsureACL(dom->conn, vm->def) < 0)
        goto cleanup;

    ret = 0;

 cleanup:
5524
    virDomainObjEndAPI(&vm);
5525 5526 5527 5528
    return ret;
}


D
Daniel Veillard 已提交
5529
/* Function Tables */
5530
static virHypervisorDriver lxcHypervisorDriver = {
5531
    .name = LXC_DRIVER_NAME,
5532
    .connectURIProbe = lxcConnectURIProbe,
5533 5534
    .connectOpen = lxcConnectOpen, /* 0.4.2 */
    .connectClose = lxcConnectClose, /* 0.4.2 */
5535
    .connectSupportsFeature = lxcConnectSupportsFeature, /* 1.2.2 */
5536
    .connectGetVersion = lxcConnectGetVersion, /* 0.4.6 */
5537
    .connectGetHostname = lxcConnectGetHostname, /* 0.6.3 */
5538
    .connectGetSysinfo = lxcConnectGetSysinfo, /* 1.0.5 */
5539
    .nodeGetInfo = lxcNodeGetInfo, /* 0.6.5 */
5540 5541 5542 5543 5544
    .connectGetCapabilities = lxcConnectGetCapabilities, /* 0.6.5 */
    .connectListDomains = lxcConnectListDomains, /* 0.4.2 */
    .connectNumOfDomains = lxcConnectNumOfDomains, /* 0.4.2 */
    .connectListAllDomains = lxcConnectListAllDomains, /* 0.9.13 */
    .domainCreateXML = lxcDomainCreateXML, /* 0.4.4 */
5545
    .domainCreateXMLWithFiles = lxcDomainCreateXMLWithFiles, /* 1.1.1 */
5546 5547 5548 5549 5550 5551
    .domainLookupByID = lxcDomainLookupByID, /* 0.4.2 */
    .domainLookupByUUID = lxcDomainLookupByUUID, /* 0.4.2 */
    .domainLookupByName = lxcDomainLookupByName, /* 0.4.2 */
    .domainSuspend = lxcDomainSuspend, /* 0.7.2 */
    .domainResume = lxcDomainResume, /* 0.7.2 */
    .domainDestroy = lxcDomainDestroy, /* 0.4.4 */
5552
    .domainDestroyFlags = lxcDomainDestroyFlags, /* 0.9.4 */
5553
    .domainGetOSType = lxcDomainGetOSType, /* 0.4.2 */
5554 5555 5556
    .domainGetMaxMemory = lxcDomainGetMaxMemory, /* 0.7.2 */
    .domainSetMaxMemory = lxcDomainSetMaxMemory, /* 0.7.2 */
    .domainSetMemory = lxcDomainSetMemory, /* 0.7.2 */
5557
    .domainSetMemoryFlags = lxcDomainSetMemoryFlags, /* 1.2.7 */
5558 5559
    .domainSetMemoryParameters = lxcDomainSetMemoryParameters, /* 0.8.5 */
    .domainGetMemoryParameters = lxcDomainGetMemoryParameters, /* 0.8.5 */
5560 5561
    .domainSetBlkioParameters = lxcDomainSetBlkioParameters, /* 0.9.8 */
    .domainGetBlkioParameters = lxcDomainGetBlkioParameters, /* 0.9.8 */
5562 5563
    .domainGetInfo = lxcDomainGetInfo, /* 0.4.2 */
    .domainGetState = lxcDomainGetState, /* 0.9.2 */
5564 5565
    .domainGetSecurityLabel = lxcDomainGetSecurityLabel, /* 0.9.10 */
    .nodeGetSecurityModel = lxcNodeGetSecurityModel, /* 0.9.10 */
5566
    .domainGetXMLDesc = lxcDomainGetXMLDesc, /* 0.4.2 */
5567
    .connectDomainXMLFromNative = lxcConnectDomainXMLFromNative, /* 1.2.2 */
5568 5569 5570 5571
    .connectListDefinedDomains = lxcConnectListDefinedDomains, /* 0.4.2 */
    .connectNumOfDefinedDomains = lxcConnectNumOfDefinedDomains, /* 0.4.2 */
    .domainCreate = lxcDomainCreate, /* 0.4.4 */
    .domainCreateWithFlags = lxcDomainCreateWithFlags, /* 0.8.2 */
5572
    .domainCreateWithFiles = lxcDomainCreateWithFiles, /* 1.1.1 */
5573
    .domainDefineXML = lxcDomainDefineXML, /* 0.4.2 */
5574
    .domainDefineXMLFlags = lxcDomainDefineXMLFlags, /* 1.2.12 */
5575
    .domainUndefine = lxcDomainUndefine, /* 0.4.2 */
5576
    .domainUndefineFlags = lxcDomainUndefineFlags, /* 0.9.4 */
5577 5578 5579 5580 5581
    .domainAttachDevice = lxcDomainAttachDevice, /* 1.0.1 */
    .domainAttachDeviceFlags = lxcDomainAttachDeviceFlags, /* 1.0.1 */
    .domainDetachDevice = lxcDomainDetachDevice, /* 1.0.1 */
    .domainDetachDeviceFlags = lxcDomainDetachDeviceFlags, /* 1.0.1 */
    .domainUpdateDeviceFlags = lxcDomainUpdateDeviceFlags, /* 1.0.1 */
5582 5583
    .domainGetAutostart = lxcDomainGetAutostart, /* 0.7.0 */
    .domainSetAutostart = lxcDomainSetAutostart, /* 0.7.0 */
5584 5585 5586 5587 5588
    .domainGetSchedulerType = lxcDomainGetSchedulerType, /* 0.5.0 */
    .domainGetSchedulerParameters = lxcDomainGetSchedulerParameters, /* 0.5.0 */
    .domainGetSchedulerParametersFlags = lxcDomainGetSchedulerParametersFlags, /* 0.9.2 */
    .domainSetSchedulerParameters = lxcDomainSetSchedulerParameters, /* 0.5.0 */
    .domainSetSchedulerParametersFlags = lxcDomainSetSchedulerParametersFlags, /* 0.9.2 */
5589 5590
    .domainBlockStats = lxcDomainBlockStats, /* 1.2.2 */
    .domainBlockStatsFlags = lxcDomainBlockStatsFlags, /* 1.2.2 */
5591
    .domainInterfaceStats = lxcDomainInterfaceStats, /* 0.7.3 */
5592
    .domainMemoryStats = lxcDomainMemoryStats, /* 1.2.2 */
5593 5594 5595 5596 5597
    .nodeGetCPUStats = lxcNodeGetCPUStats, /* 0.9.3 */
    .nodeGetMemoryStats = lxcNodeGetMemoryStats, /* 0.9.3 */
    .nodeGetCellsFreeMemory = lxcNodeGetCellsFreeMemory, /* 0.6.5 */
    .nodeGetFreeMemory = lxcNodeGetFreeMemory, /* 0.6.5 */
    .nodeGetCPUMap = lxcNodeGetCPUMap, /* 1.0.0 */
5598 5599 5600 5601
    .connectDomainEventRegister = lxcConnectDomainEventRegister, /* 0.7.0 */
    .connectDomainEventDeregister = lxcConnectDomainEventDeregister, /* 0.7.0 */
    .connectIsEncrypted = lxcConnectIsEncrypted, /* 0.7.3 */
    .connectIsSecure = lxcConnectIsSecure, /* 0.7.3 */
5602 5603 5604
    .domainIsActive = lxcDomainIsActive, /* 0.7.3 */
    .domainIsPersistent = lxcDomainIsPersistent, /* 0.7.3 */
    .domainIsUpdated = lxcDomainIsUpdated, /* 0.8.6 */
5605 5606
    .connectDomainEventRegisterAny = lxcConnectDomainEventRegisterAny, /* 0.8.0 */
    .connectDomainEventDeregisterAny = lxcConnectDomainEventDeregisterAny, /* 0.8.0 */
5607
    .domainOpenConsole = lxcDomainOpenConsole, /* 0.8.6 */
5608
    .connectIsAlive = lxcConnectIsAlive, /* 0.9.8 */
5609
    .nodeSuspendForDuration = lxcNodeSuspendForDuration, /* 0.9.8 */
5610 5611
    .domainSetMetadata = lxcDomainSetMetadata, /* 1.1.3 */
    .domainGetMetadata = lxcDomainGetMetadata, /* 1.1.3 */
5612
    .domainGetCPUStats = lxcDomainGetCPUStats, /* 1.2.2 */
5613 5614
    .nodeGetMemoryParameters = lxcNodeGetMemoryParameters, /* 0.10.2 */
    .nodeSetMemoryParameters = lxcNodeSetMemoryParameters, /* 0.10.2 */
5615
    .domainSendProcessSignal = lxcDomainSendProcessSignal, /* 1.0.1 */
5616 5617 5618
    .domainShutdown = lxcDomainShutdown, /* 1.0.1 */
    .domainShutdownFlags = lxcDomainShutdownFlags, /* 1.0.1 */
    .domainReboot = lxcDomainReboot, /* 1.0.1 */
5619
    .domainLxcOpenNamespace = lxcDomainLxcOpenNamespace, /* 1.0.2 */
5620
    .nodeGetFreePages = lxcNodeGetFreePages, /* 1.2.6 */
5621
    .nodeAllocPages = lxcNodeAllocPages, /* 1.2.9 */
5622
    .domainHasManagedSaveImage = lxcDomainHasManagedSaveImage, /* 1.2.13 */
D
Daniel Veillard 已提交
5623 5624
};

5625
static virConnectDriver lxcConnectDriver = {
5626
    .localOnly = true,
5627
    .uriSchemes = (const char *[]){ "lxc", NULL },
5628 5629 5630
    .hypervisorDriver = &lxcHypervisorDriver,
};

5631
static virStateDriver lxcStateDriver = {
5632
    .name = LXC_DRIVER_NAME,
5633
    .stateInitialize = lxcStateInitialize,
5634
    .stateAutoStart = lxcStateAutoStart,
5635 5636
    .stateCleanup = lxcStateCleanup,
    .stateReload = lxcStateReload,
5637 5638
};

D
Daniel Veillard 已提交
5639 5640
int lxcRegister(void)
{
5641 5642
    if (virRegisterConnectDriver(&lxcConnectDriver,
                                 true) < 0)
5643 5644 5645
        return -1;
    if (virRegisterStateDriver(&lxcStateDriver) < 0)
        return -1;
D
Daniel Veillard 已提交
5646 5647
    return 0;
}