spice-core.c 22.9 KB
Newer Older
G
Gerd Hoffmann 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
/*
 * Copyright (C) 2010 Red Hat, Inc.
 *
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License as
 * published by the Free Software Foundation; either version 2 or
 * (at your option) version 3 of the License.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, see <http://www.gnu.org/licenses/>.
 */

#include <spice.h>
#include <spice-experimental.h>

G
Gerd Hoffmann 已提交
21 22
#include <netdb.h>

G
Gerd Hoffmann 已提交
23 24
#include "qemu-common.h"
#include "qemu-spice.h"
25
#include "qemu-thread.h"
G
Gerd Hoffmann 已提交
26 27
#include "qemu-timer.h"
#include "qemu-queue.h"
G
Gerd Hoffmann 已提交
28
#include "qemu-x509.h"
G
Gerd Hoffmann 已提交
29
#include "qemu_socket.h"
L
Luiz Capitulino 已提交
30
#include "qmp-commands.h"
G
Gerd Hoffmann 已提交
31 32 33 34
#include "qint.h"
#include "qbool.h"
#include "qstring.h"
#include "qjson.h"
G
Gerd Hoffmann 已提交
35 36
#include "notify.h"
#include "migration.h"
G
Gerd Hoffmann 已提交
37
#include "monitor.h"
G
Gerd Hoffmann 已提交
38
#include "hw/hw.h"
G
Gerd Hoffmann 已提交
39 40 41 42

/* core bits */

static SpiceServer *spice_server;
G
Gerd Hoffmann 已提交
43
static Notifier migration_state;
G
Gerd Hoffmann 已提交
44
static const char *auth = "spice";
45 46
static char *auth_passwd;
static time_t auth_expires = TIME_MAX;
G
Gerd Hoffmann 已提交
47 48
int using_spice = 0;

49
static QemuThread me;
50

G
Gerd Hoffmann 已提交
51 52 53 54 55 56 57 58 59 60
struct SpiceTimer {
    QEMUTimer *timer;
    QTAILQ_ENTRY(SpiceTimer) next;
};
static QTAILQ_HEAD(, SpiceTimer) timers = QTAILQ_HEAD_INITIALIZER(timers);

static SpiceTimer *timer_add(SpiceTimerFunc func, void *opaque)
{
    SpiceTimer *timer;

61
    timer = g_malloc0(sizeof(*timer));
62
    timer->timer = qemu_new_timer_ms(rt_clock, func, opaque);
G
Gerd Hoffmann 已提交
63 64 65 66 67 68
    QTAILQ_INSERT_TAIL(&timers, timer, next);
    return timer;
}

static void timer_start(SpiceTimer *timer, uint32_t ms)
{
69
    qemu_mod_timer(timer->timer, qemu_get_clock_ms(rt_clock) + ms);
G
Gerd Hoffmann 已提交
70 71 72 73 74 75 76 77 78 79 80 81
}

static void timer_cancel(SpiceTimer *timer)
{
    qemu_del_timer(timer->timer);
}

static void timer_remove(SpiceTimer *timer)
{
    qemu_del_timer(timer->timer);
    qemu_free_timer(timer->timer);
    QTAILQ_REMOVE(&timers, timer, next);
82
    g_free(timer);
G
Gerd Hoffmann 已提交
83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115
}

struct SpiceWatch {
    int fd;
    int event_mask;
    SpiceWatchFunc func;
    void *opaque;
    QTAILQ_ENTRY(SpiceWatch) next;
};
static QTAILQ_HEAD(, SpiceWatch) watches = QTAILQ_HEAD_INITIALIZER(watches);

static void watch_read(void *opaque)
{
    SpiceWatch *watch = opaque;
    watch->func(watch->fd, SPICE_WATCH_EVENT_READ, watch->opaque);
}

static void watch_write(void *opaque)
{
    SpiceWatch *watch = opaque;
    watch->func(watch->fd, SPICE_WATCH_EVENT_WRITE, watch->opaque);
}

static void watch_update_mask(SpiceWatch *watch, int event_mask)
{
    IOHandler *on_read = NULL;
    IOHandler *on_write = NULL;

    watch->event_mask = event_mask;
    if (watch->event_mask & SPICE_WATCH_EVENT_READ) {
        on_read = watch_read;
    }
    if (watch->event_mask & SPICE_WATCH_EVENT_WRITE) {
116
        on_write = watch_write;
G
Gerd Hoffmann 已提交
117 118 119 120 121 122 123 124
    }
    qemu_set_fd_handler(watch->fd, on_read, on_write, watch);
}

static SpiceWatch *watch_add(int fd, int event_mask, SpiceWatchFunc func, void *opaque)
{
    SpiceWatch *watch;

125
    watch = g_malloc0(sizeof(*watch));
G
Gerd Hoffmann 已提交
126 127 128 129 130 131 132 133 134 135 136
    watch->fd     = fd;
    watch->func   = func;
    watch->opaque = opaque;
    QTAILQ_INSERT_TAIL(&watches, watch, next);

    watch_update_mask(watch, event_mask);
    return watch;
}

static void watch_remove(SpiceWatch *watch)
{
G
Gerd Hoffmann 已提交
137
    qemu_set_fd_handler(watch->fd, NULL, NULL, NULL);
G
Gerd Hoffmann 已提交
138
    QTAILQ_REMOVE(&watches, watch, next);
139
    g_free(watch);
G
Gerd Hoffmann 已提交
140 141
}

142 143 144 145 146 147 148 149 150 151 152
typedef struct ChannelList ChannelList;
struct ChannelList {
    SpiceChannelEventInfo *info;
    QTAILQ_ENTRY(ChannelList) link;
};
static QTAILQ_HEAD(, ChannelList) channel_list = QTAILQ_HEAD_INITIALIZER(channel_list);

static void channel_list_add(SpiceChannelEventInfo *info)
{
    ChannelList *item;

153
    item = g_malloc0(sizeof(*item));
154 155 156 157 158 159 160 161 162 163 164 165 166
    item->info = info;
    QTAILQ_INSERT_TAIL(&channel_list, item, link);
}

static void channel_list_del(SpiceChannelEventInfo *info)
{
    ChannelList *item;

    QTAILQ_FOREACH(item, &channel_list, link) {
        if (item->info != info) {
            continue;
        }
        QTAILQ_REMOVE(&channel_list, item, link);
167
        g_free(item);
168 169 170 171
        return;
    }
}

G
Gerd Hoffmann 已提交
172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205
static void add_addr_info(QDict *dict, struct sockaddr *addr, int len)
{
    char host[NI_MAXHOST], port[NI_MAXSERV];
    const char *family;

    getnameinfo(addr, len, host, sizeof(host), port, sizeof(port),
                NI_NUMERICHOST | NI_NUMERICSERV);
    family = inet_strfamily(addr->sa_family);

    qdict_put(dict, "host", qstring_from_str(host));
    qdict_put(dict, "port", qstring_from_str(port));
    qdict_put(dict, "family", qstring_from_str(family));
}

static void add_channel_info(QDict *dict, SpiceChannelEventInfo *info)
{
    int tls = info->flags & SPICE_CHANNEL_EVENT_FLAG_TLS;

    qdict_put(dict, "connection-id", qint_from_int(info->connection_id));
    qdict_put(dict, "channel-type", qint_from_int(info->type));
    qdict_put(dict, "channel-id", qint_from_int(info->id));
    qdict_put(dict, "tls", qbool_from_int(tls));
}

static void channel_event(int event, SpiceChannelEventInfo *info)
{
    static const int qevent[] = {
        [ SPICE_CHANNEL_EVENT_CONNECTED    ] = QEVENT_SPICE_CONNECTED,
        [ SPICE_CHANNEL_EVENT_INITIALIZED  ] = QEVENT_SPICE_INITIALIZED,
        [ SPICE_CHANNEL_EVENT_DISCONNECTED ] = QEVENT_SPICE_DISCONNECTED,
    };
    QDict *server, *client;
    QObject *data;

206 207 208 209 210 211 212 213 214
    /*
     * Spice server might have called us from spice worker thread
     * context (happens on display channel disconnects).  Spice should
     * not do that.  It isn't that easy to fix it in spice and even
     * when it is fixed we still should cover the already released
     * spice versions.  So detect that we've been called from another
     * thread and grab the iothread lock if so before calling qemu
     * functions.
     */
215
    bool need_lock = !qemu_thread_is_self(&me);
216 217 218 219
    if (need_lock) {
        qemu_mutex_lock_iothread();
    }

G
Gerd Hoffmann 已提交
220 221
    client = qdict_new();
    server = qdict_new();
222 223 224 225 226 227 228 229

#ifdef SPICE_CHANNEL_EVENT_FLAG_ADDR_EXT
    if (info->flags & SPICE_CHANNEL_EVENT_FLAG_ADDR_EXT) {
        add_addr_info(client, (struct sockaddr *)&info->paddr_ext,
                      info->plen_ext);
        add_addr_info(server, (struct sockaddr *)&info->laddr_ext,
                      info->llen_ext);
    } else {
230 231
        error_report("spice: %s, extended address is expected",
                     __func__);
232 233 234 235 236 237
#endif
        add_addr_info(client, &info->paddr, info->plen);
        add_addr_info(server, &info->laddr, info->llen);
#ifdef SPICE_CHANNEL_EVENT_FLAG_ADDR_EXT
    }
#endif
G
Gerd Hoffmann 已提交
238 239 240 241

    if (event == SPICE_CHANNEL_EVENT_INITIALIZED) {
        qdict_put(server, "auth", qstring_from_str(auth));
        add_channel_info(client, info);
242 243 244 245
        channel_list_add(info);
    }
    if (event == SPICE_CHANNEL_EVENT_DISCONNECTED) {
        channel_list_del(info);
G
Gerd Hoffmann 已提交
246 247 248 249 250 251
    }

    data = qobject_from_jsonf("{ 'client': %p, 'server': %p }",
                              QOBJECT(client), QOBJECT(server));
    monitor_protocol_event(qevent[event], data);
    qobject_decref(data);
252 253 254 255

    if (need_lock) {
        qemu_mutex_unlock_iothread();
    }
G
Gerd Hoffmann 已提交
256 257
}

G
Gerd Hoffmann 已提交
258 259 260 261 262 263 264 265 266 267 268 269 270 271
static SpiceCoreInterface core_interface = {
    .base.type          = SPICE_INTERFACE_CORE,
    .base.description   = "qemu core services",
    .base.major_version = SPICE_INTERFACE_CORE_MAJOR,
    .base.minor_version = SPICE_INTERFACE_CORE_MINOR,

    .timer_add          = timer_add,
    .timer_start        = timer_start,
    .timer_cancel       = timer_cancel,
    .timer_remove       = timer_remove,

    .watch_add          = watch_add,
    .watch_update_mask  = watch_update_mask,
    .watch_remove       = watch_remove,
G
Gerd Hoffmann 已提交
272 273

    .channel_event      = channel_event,
G
Gerd Hoffmann 已提交
274 275
};

276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307
#ifdef SPICE_INTERFACE_MIGRATION
typedef struct SpiceMigration {
    SpiceMigrateInstance sin;
    struct {
        MonitorCompletion *cb;
        void *opaque;
    } connect_complete;
} SpiceMigration;

static void migrate_connect_complete_cb(SpiceMigrateInstance *sin);

static const SpiceMigrateInterface migrate_interface = {
    .base.type = SPICE_INTERFACE_MIGRATION,
    .base.description = "migration",
    .base.major_version = SPICE_INTERFACE_MIGRATION_MAJOR,
    .base.minor_version = SPICE_INTERFACE_MIGRATION_MINOR,
    .migrate_connect_complete = migrate_connect_complete_cb,
    .migrate_end_complete = NULL,
};

static SpiceMigration spice_migrate;

static void migrate_connect_complete_cb(SpiceMigrateInstance *sin)
{
    SpiceMigration *sm = container_of(sin, SpiceMigration, sin);
    if (sm->connect_complete.cb) {
        sm->connect_complete.cb(sm->connect_complete.opaque, NULL);
    }
    sm->connect_complete.cb = NULL;
}
#endif

308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335
/* config string parsing */

static int name2enum(const char *string, const char *table[], int entries)
{
    int i;

    if (string) {
        for (i = 0; i < entries; i++) {
            if (!table[i]) {
                continue;
            }
            if (strcmp(string, table[i]) != 0) {
                continue;
            }
            return i;
        }
    }
    return -1;
}

static int parse_name(const char *string, const char *optname,
                      const char *table[], int entries)
{
    int value = name2enum(string, table, entries);

    if (value != -1) {
        return value;
    }
336
    error_report("spice: invalid %s: %s", optname, string);
337 338 339
    exit(1);
}

G
Gerd Hoffmann 已提交
340 341 342 343 344 345 346 347
static const char *stream_video_names[] = {
    [ SPICE_STREAM_VIDEO_OFF ]    = "off",
    [ SPICE_STREAM_VIDEO_ALL ]    = "all",
    [ SPICE_STREAM_VIDEO_FILTER ] = "filter",
};
#define parse_stream_video(_name) \
    name2enum(_name, stream_video_names, ARRAY_SIZE(stream_video_names))

348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368
static const char *compression_names[] = {
    [ SPICE_IMAGE_COMPRESS_OFF ]      = "off",
    [ SPICE_IMAGE_COMPRESS_AUTO_GLZ ] = "auto_glz",
    [ SPICE_IMAGE_COMPRESS_AUTO_LZ ]  = "auto_lz",
    [ SPICE_IMAGE_COMPRESS_QUIC ]     = "quic",
    [ SPICE_IMAGE_COMPRESS_GLZ ]      = "glz",
    [ SPICE_IMAGE_COMPRESS_LZ ]       = "lz",
};
#define parse_compression(_name)                                        \
    parse_name(_name, "image compression",                              \
               compression_names, ARRAY_SIZE(compression_names))

static const char *wan_compression_names[] = {
    [ SPICE_WAN_COMPRESSION_AUTO   ] = "auto",
    [ SPICE_WAN_COMPRESSION_NEVER  ] = "never",
    [ SPICE_WAN_COMPRESSION_ALWAYS ] = "always",
};
#define parse_wan_compression(_name)                                    \
    parse_name(_name, "wan compression",                                \
               wan_compression_names, ARRAY_SIZE(wan_compression_names))

G
Gerd Hoffmann 已提交
369 370
/* functions for the rest of qemu */

L
Luiz Capitulino 已提交
371
static SpiceChannelList *qmp_query_spice_channels(void)
372
{
L
Luiz Capitulino 已提交
373 374
    SpiceChannelList *cur_item = NULL, *head = NULL;
    ChannelList *item;
375

L
Luiz Capitulino 已提交
376 377 378
    QTAILQ_FOREACH(item, &channel_list, link) {
        SpiceChannelList *chan;
        char host[NI_MAXHOST], port[NI_MAXSERV];
379 380
        struct sockaddr *paddr;
        socklen_t plen;
L
Luiz Capitulino 已提交
381 382 383 384

        chan = g_malloc0(sizeof(*chan));
        chan->value = g_malloc0(sizeof(*chan->value));

385 386 387 388 389 390 391 392 393 394 395 396 397
#ifdef SPICE_CHANNEL_EVENT_FLAG_ADDR_EXT
        if (item->info->flags & SPICE_CHANNEL_EVENT_FLAG_ADDR_EXT) {
            paddr = (struct sockaddr *)&item->info->paddr_ext;
            plen = item->info->plen_ext;
        } else {
#endif
            paddr = &item->info->paddr;
            plen = item->info->plen;
#ifdef SPICE_CHANNEL_EVENT_FLAG_ADDR_EXT
        }
#endif

        getnameinfo(paddr, plen,
L
Luiz Capitulino 已提交
398 399 400 401
                    host, sizeof(host), port, sizeof(port),
                    NI_NUMERICHOST | NI_NUMERICSERV);
        chan->value->host = g_strdup(host);
        chan->value->port = g_strdup(port);
402
        chan->value->family = g_strdup(inet_strfamily(paddr->sa_family));
L
Luiz Capitulino 已提交
403 404 405 406 407 408 409 410 411 412 413 414 415

        chan->value->connection_id = item->info->connection_id;
        chan->value->channel_type = item->info->type;
        chan->value->channel_id = item->info->id;
        chan->value->tls = item->info->flags & SPICE_CHANNEL_EVENT_FLAG_TLS;

       /* XXX: waiting for the qapi to support GSList */
        if (!cur_item) {
            head = cur_item = chan;
        } else {
            cur_item->next = chan;
            cur_item = chan;
        }
416 417
    }

L
Luiz Capitulino 已提交
418
    return head;
419 420
}

L
Luiz Capitulino 已提交
421
SpiceInfo *qmp_query_spice(Error **errp)
422 423 424
{
    QemuOpts *opts = QTAILQ_FIRST(&qemu_spice_opts.head);
    int port, tls_port;
L
Luiz Capitulino 已提交
425 426
    const char *addr;
    SpiceInfo *info;
427
    char version_string[20]; /* 12 = |255.255.255\0| is the max */
428

L
Luiz Capitulino 已提交
429 430
    info = g_malloc0(sizeof(*info));

A
Alon Levy 已提交
431
    if (!spice_server || !opts) {
L
Luiz Capitulino 已提交
432 433
        info->enabled = false;
        return info;
434 435
    }

L
Luiz Capitulino 已提交
436 437
    info->enabled = true;

438 439 440 441
    addr = qemu_opt_get(opts, "addr");
    port = qemu_opt_get_number(opts, "port", 0);
    tls_port = qemu_opt_get_number(opts, "tls-port", 0);

L
Luiz Capitulino 已提交
442 443 444 445 446 447 448
    info->has_auth = true;
    info->auth = g_strdup(auth);

    info->has_host = true;
    info->host = g_strdup(addr ? addr : "0.0.0.0");

    info->has_compiled_version = true;
449 450 451 452
    snprintf(version_string, sizeof(version_string), "%d.%d.%d",
             (SPICE_SERVER_VERSION & 0xff0000) >> 16,
             (SPICE_SERVER_VERSION & 0xff00) >> 8,
             SPICE_SERVER_VERSION & 0xff);
L
Luiz Capitulino 已提交
453 454
    info->compiled_version = g_strdup(version_string);

455
    if (port) {
L
Luiz Capitulino 已提交
456 457
        info->has_port = true;
        info->port = port;
458 459
    }
    if (tls_port) {
L
Luiz Capitulino 已提交
460 461
        info->has_tls_port = true;
        info->tls_port = tls_port;
462 463
    }

L
Luiz Capitulino 已提交
464 465 466 467 468
    /* for compatibility with the original command */
    info->has_channels = true;
    info->channels = qmp_query_spice_channels();

    return info;
469 470
}

471
static void migration_state_notifier(Notifier *notifier, void *data)
G
Gerd Hoffmann 已提交
472
{
473
    MigrationState *s = data;
G
Gerd Hoffmann 已提交
474

475 476 477 478 479 480
    if (migration_is_active(s)) {
#ifdef SPICE_INTERFACE_MIGRATION
        spice_server_migrate_start(spice_server);
#endif
    } else if (migration_has_finished(s)) {
#ifndef SPICE_INTERFACE_MIGRATION
G
Gerd Hoffmann 已提交
481
        spice_server_migrate_switch(spice_server);
482 483 484 485
#else
        spice_server_migrate_end(spice_server, true);
    } else if (migration_has_failed(s)) {
        spice_server_migrate_end(spice_server, false);
G
Gerd Hoffmann 已提交
486 487 488 489 490
#endif
    }
}

int qemu_spice_migrate_info(const char *hostname, int port, int tls_port,
491 492
                            const char *subject,
                            MonitorCompletion *cb, void *opaque)
G
Gerd Hoffmann 已提交
493
{
494
    int ret;
495 496 497 498 499 500
#ifdef SPICE_INTERFACE_MIGRATION
    spice_migrate.connect_complete.cb = cb;
    spice_migrate.connect_complete.opaque = opaque;
    ret = spice_server_migrate_connect(spice_server, hostname,
                                       port, tls_port, subject);
#else
501 502 503
    ret = spice_server_migrate_info(spice_server, hostname,
                                    port, tls_port, subject);
    cb(opaque, NULL);
504
#endif
505
    return ret;
G
Gerd Hoffmann 已提交
506 507
}

508 509 510 511 512 513
static int add_channel(const char *name, const char *value, void *opaque)
{
    int security = 0;
    int rc;

    if (strcmp(name, "tls-channel") == 0) {
514 515 516 517 518 519
        int *tls_port = opaque;
        if (!*tls_port) {
            error_report("spice: tried to setup tls-channel"
                         " without specifying a TLS port");
            exit(1);
        }
520 521 522 523 524 525 526 527 528 529 530 531 532 533
        security = SPICE_CHANNEL_SECURITY_SSL;
    }
    if (strcmp(name, "plaintext-channel") == 0) {
        security = SPICE_CHANNEL_SECURITY_NONE;
    }
    if (security == 0) {
        return 0;
    }
    if (strcmp(value, "default") == 0) {
        rc = spice_server_set_channel_security(spice_server, NULL, security);
    } else {
        rc = spice_server_set_channel_security(spice_server, value, security);
    }
    if (rc != 0) {
534
        error_report("spice: failed to set channel security for %s", value);
535 536 537 538 539
        exit(1);
    }
    return 0;
}

G
Gerd Hoffmann 已提交
540 541 542
void qemu_spice_init(void)
{
    QemuOpts *opts = QTAILQ_FIRST(&qemu_spice_opts.head);
543
    const char *password, *str, *x509_dir, *addr,
G
Gerd Hoffmann 已提交
544 545 546 547 548 549
        *x509_key_password = NULL,
        *x509_dh_file = NULL,
        *tls_ciphers = NULL;
    char *x509_key_file = NULL,
        *x509_cert_file = NULL,
        *x509_cacert_file = NULL;
550
    int port, tls_port, len, addr_flags;
551 552
    spice_image_compression_t compression;
    spice_wan_compression_t wan_compr;
G
Gerd Hoffmann 已提交
553

554
    qemu_thread_get_self(&me);
555 556

   if (!opts) {
G
Gerd Hoffmann 已提交
557 558 559
        return;
    }
    port = qemu_opt_get_number(opts, "port", 0);
G
Gerd Hoffmann 已提交
560 561
    tls_port = qemu_opt_get_number(opts, "tls-port", 0);
    if (!port && !tls_port) {
562
        error_report("neither port nor tls-port specified for spice");
563 564 565
        exit(1);
    }
    if (port < 0 || port > 65535) {
566
        error_report("spice port is out of range");
567 568 569
        exit(1);
    }
    if (tls_port < 0 || tls_port > 65535) {
570
        error_report("spice tls-port is out of range");
571
        exit(1);
G
Gerd Hoffmann 已提交
572 573 574
    }
    password = qemu_opt_get(opts, "password");

G
Gerd Hoffmann 已提交
575 576 577 578 579 580 581 582 583
    if (tls_port) {
        x509_dir = qemu_opt_get(opts, "x509-dir");
        if (NULL == x509_dir) {
            x509_dir = ".";
        }
        len = strlen(x509_dir) + 32;

        str = qemu_opt_get(opts, "x509-key-file");
        if (str) {
584
            x509_key_file = g_strdup(str);
G
Gerd Hoffmann 已提交
585
        } else {
586
            x509_key_file = g_malloc(len);
G
Gerd Hoffmann 已提交
587 588 589 590 591
            snprintf(x509_key_file, len, "%s/%s", x509_dir, X509_SERVER_KEY_FILE);
        }

        str = qemu_opt_get(opts, "x509-cert-file");
        if (str) {
592
            x509_cert_file = g_strdup(str);
G
Gerd Hoffmann 已提交
593
        } else {
594
            x509_cert_file = g_malloc(len);
G
Gerd Hoffmann 已提交
595 596 597 598 599
            snprintf(x509_cert_file, len, "%s/%s", x509_dir, X509_SERVER_CERT_FILE);
        }

        str = qemu_opt_get(opts, "x509-cacert-file");
        if (str) {
600
            x509_cacert_file = g_strdup(str);
G
Gerd Hoffmann 已提交
601
        } else {
602
            x509_cacert_file = g_malloc(len);
G
Gerd Hoffmann 已提交
603 604 605 606 607 608 609 610
            snprintf(x509_cacert_file, len, "%s/%s", x509_dir, X509_CA_CERT_FILE);
        }

        x509_key_password = qemu_opt_get(opts, "x509-key-password");
        x509_dh_file = qemu_opt_get(opts, "x509-dh-file");
        tls_ciphers = qemu_opt_get(opts, "tls-ciphers");
    }

611 612 613 614 615 616 617 618
    addr = qemu_opt_get(opts, "addr");
    addr_flags = 0;
    if (qemu_opt_get_bool(opts, "ipv4", 0)) {
        addr_flags |= SPICE_ADDR_FLAG_IPV4_ONLY;
    } else if (qemu_opt_get_bool(opts, "ipv6", 0)) {
        addr_flags |= SPICE_ADDR_FLAG_IPV6_ONLY;
    }

G
Gerd Hoffmann 已提交
619
    spice_server = spice_server_new();
620
    spice_server_set_addr(spice_server, addr ? addr : "", addr_flags);
G
Gerd Hoffmann 已提交
621 622 623 624 625 626 627 628 629 630 631 632
    if (port) {
        spice_server_set_port(spice_server, port);
    }
    if (tls_port) {
        spice_server_set_tls(spice_server, tls_port,
                             x509_cacert_file,
                             x509_cert_file,
                             x509_key_file,
                             x509_key_password,
                             x509_dh_file,
                             tls_ciphers);
    }
G
Gerd Hoffmann 已提交
633 634 635
    if (password) {
        spice_server_set_ticket(spice_server, password, 0, 0, 0);
    }
M
Marc-André Lureau 已提交
636 637 638 639
    if (qemu_opt_get_bool(opts, "sasl", 0)) {
#if SPICE_SERVER_VERSION >= 0x000900 /* 0.9.0 */
        if (spice_server_set_sasl_appname(spice_server, "qemu") == -1 ||
            spice_server_set_sasl(spice_server, 1) == -1) {
640
            error_report("spice: failed to enable sasl");
M
Marc-André Lureau 已提交
641 642 643
            exit(1);
        }
#else
644
        error_report("spice: sasl is not available (spice >= 0.9 required)");
M
Marc-André Lureau 已提交
645 646 647
        exit(1);
#endif
    }
G
Gerd Hoffmann 已提交
648
    if (qemu_opt_get_bool(opts, "disable-ticketing", 0)) {
G
Gerd Hoffmann 已提交
649
        auth = "none";
G
Gerd Hoffmann 已提交
650 651 652
        spice_server_set_noauth(spice_server);
    }

653 654 655 656
    if (qemu_opt_get_bool(opts, "disable-copy-paste", 0)) {
        spice_server_set_agent_copypaste(spice_server, false);
    }

657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676
    compression = SPICE_IMAGE_COMPRESS_AUTO_GLZ;
    str = qemu_opt_get(opts, "image-compression");
    if (str) {
        compression = parse_compression(str);
    }
    spice_server_set_image_compression(spice_server, compression);

    wan_compr = SPICE_WAN_COMPRESSION_AUTO;
    str = qemu_opt_get(opts, "jpeg-wan-compression");
    if (str) {
        wan_compr = parse_wan_compression(str);
    }
    spice_server_set_jpeg_compression(spice_server, wan_compr);

    wan_compr = SPICE_WAN_COMPRESSION_AUTO;
    str = qemu_opt_get(opts, "zlib-glz-wan-compression");
    if (str) {
        wan_compr = parse_wan_compression(str);
    }
    spice_server_set_zlib_glz_compression(spice_server, wan_compr);
G
Gerd Hoffmann 已提交
677

G
Gerd Hoffmann 已提交
678 679
    str = qemu_opt_get(opts, "streaming-video");
    if (str) {
680
        int streaming_video = parse_stream_video(str);
G
Gerd Hoffmann 已提交
681 682 683 684 685 686 687 688
        spice_server_set_streaming_video(spice_server, streaming_video);
    }

    spice_server_set_agent_mouse
        (spice_server, qemu_opt_get_bool(opts, "agent-mouse", 1));
    spice_server_set_playback_compression
        (spice_server, qemu_opt_get_bool(opts, "playback-compression", 1));

689
    qemu_opt_foreach(opts, add_channel, &tls_port, 0);
690

691
    if (0 != spice_server_init(spice_server, &core_interface)) {
692
        error_report("failed to initialize spice server");
693 694
        exit(1);
    };
G
Gerd Hoffmann 已提交
695
    using_spice = 1;
G
Gerd Hoffmann 已提交
696

G
Gerd Hoffmann 已提交
697 698
    migration_state.notify = migration_state_notifier;
    add_migration_state_change_notifier(&migration_state);
699 700 701 702 703
#ifdef SPICE_INTERFACE_MIGRATION
    spice_migrate.sin.base.sif = &migrate_interface.base;
    spice_migrate.connect_complete.cb = NULL;
    qemu_spice_add_interface(&spice_migrate.sin.base);
#endif
G
Gerd Hoffmann 已提交
704

G
Gerd Hoffmann 已提交
705
    qemu_spice_input_init();
G
Gerd Hoffmann 已提交
706
    qemu_spice_audio_init();
G
Gerd Hoffmann 已提交
707

708 709 710
    g_free(x509_key_file);
    g_free(x509_cert_file);
    g_free(x509_cacert_file);
G
Gerd Hoffmann 已提交
711 712 713 714
}

int qemu_spice_add_interface(SpiceBaseInstance *sin)
{
G
Gerd Hoffmann 已提交
715 716
    if (!spice_server) {
        if (QTAILQ_FIRST(&qemu_spice_opts.head) != NULL) {
717
            error_report("Oops: spice configured but not active");
G
Gerd Hoffmann 已提交
718 719 720 721 722 723 724 725 726 727 728 729
            exit(1);
        }
        /*
         * Create a spice server instance.
         * It does *not* listen on the network.
         * It handles QXL local rendering only.
         *
         * With a command line like '-vnc :0 -vga qxl' you'll end up here.
         */
        spice_server = spice_server_new();
        spice_server_init(spice_server, &core_interface);
    }
G
Gerd Hoffmann 已提交
730 731 732
    return spice_server_add_interface(spice_server, sin);
}

733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765
static int qemu_spice_set_ticket(bool fail_if_conn, bool disconnect_if_conn)
{
    time_t lifetime, now = time(NULL);
    char *passwd;

    if (now < auth_expires) {
        passwd = auth_passwd;
        lifetime = (auth_expires - now);
        if (lifetime > INT_MAX) {
            lifetime = INT_MAX;
        }
    } else {
        passwd = NULL;
        lifetime = 1;
    }
    return spice_server_set_ticket(spice_server, passwd, lifetime,
                                   fail_if_conn, disconnect_if_conn);
}

int qemu_spice_set_passwd(const char *passwd,
                          bool fail_if_conn, bool disconnect_if_conn)
{
    free(auth_passwd);
    auth_passwd = strdup(passwd);
    return qemu_spice_set_ticket(fail_if_conn, disconnect_if_conn);
}

int qemu_spice_set_pw_expire(time_t expires)
{
    auth_expires = expires;
    return qemu_spice_set_ticket(false, false);
}

766 767 768 769 770 771 772 773 774 775 776 777 778
int qemu_spice_display_add_client(int csock, int skipauth, int tls)
{
#if SPICE_SERVER_VERSION >= 0x000a01
    if (tls) {
        return spice_server_add_ssl_client(spice_server, csock, skipauth);
    } else {
        return spice_server_add_client(spice_server, csock, skipauth);
    }
#else
    return -1;
#endif
}

G
Gerd Hoffmann 已提交
779 780 781 782 783 784
static void spice_register_config(void)
{
    qemu_add_opts(&qemu_spice_opts);
}
machine_init(spice_register_config);

A
Andreas Färber 已提交
785
static void spice_register_types(void)
G
Gerd Hoffmann 已提交
786 787 788
{
    qemu_spice_init();
}
A
Andreas Färber 已提交
789 790

type_init(spice_register_types)