From nobody Fri Dec 19 21:48:38 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of redhat.com designates 170.10.129.124 as permitted sender) client-ip=170.10.129.124; envelope-from=libvir-list-bounces@redhat.com; helo=us-smtp-delivery-124.mimecast.com; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of redhat.com designates 170.10.129.124 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass(p=none dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1673237486; cv=none; d=zohomail.com; s=zohoarc; b=ZGq/aBejoawmJ5gKeqpEEj3aY+Wl9xnZ4oWATqiw8AwG8ufuwGjh1597A0EskQD7At3aVVtey7IK5n3Od333oC253otrY8/LE1vzjIIDp3UC0/OpS+ju28xtOi9fXDC5KTUEee00RR4aKq+jcFXsNy1lCbLXhtDB8htQE4lke4w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1673237486; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:To; bh=TlqssWERXxmKBJRc094pYSCX/b2rWM0T6zhjHrUoSTM=; b=R3fs9+OGN+LGeJf+5Zv8ias3BUfrhhcwDIm9dL2HUyUkHs+Ah/XuOH+iTZbPcVDrb2FNzEmOS7ZA13mWrJy+kSREtgzMF5GJYt/uTIdGxLlfMg8xVskMPC9LUkpNms4ghb+q5svW7oQpgbtFLdeEdLJ6HkzeR+BXlcGrEU2ePbo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of redhat.com designates 170.10.129.124 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by mx.zohomail.com with SMTPS id 1673237486240342.8760045789462; Sun, 8 Jan 2023 20:11:26 -0800 (PST) Received: from mimecast-mx02.redhat.com (mx3-rdu2.redhat.com [66.187.233.73]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-475-JSO93zwVNhOG1PfUxfSwGQ-1; Sun, 08 Jan 2023 23:11:23 -0500 Received: from smtp.corp.redhat.com (int-mx01.intmail.prod.int.rdu2.redhat.com [10.11.54.1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 0BD571C06ED7; Mon, 9 Jan 2023 04:11:18 +0000 (UTC) Received: from mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (unknown [10.30.29.100]) by smtp.corp.redhat.com (Postfix) with ESMTP id E1A4140C200B; Mon, 9 Jan 2023 04:11:17 +0000 (UTC) Received: from mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (localhost [IPv6:::1]) by mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (Postfix) with ESMTP id 83B7D1947BB2; Mon, 9 Jan 2023 04:11:16 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx03.intmail.prod.int.rdu2.redhat.com [10.11.54.3]) by mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (Postfix) with ESMTP id 1CE5A1947B8B for ; Mon, 9 Jan 2023 04:11:15 +0000 (UTC) Received: by smtp.corp.redhat.com (Postfix) id 106101121319; Mon, 9 Jan 2023 04:11:15 +0000 (UTC) Received: from vhost3.router.laine.org (unknown [10.2.16.67]) by smtp.corp.redhat.com (Postfix) with ESMTP id DBF911121314; Mon, 9 Jan 2023 04:11:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1673237485; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post; bh=TlqssWERXxmKBJRc094pYSCX/b2rWM0T6zhjHrUoSTM=; b=L3Bn/3eZTOr9yg6LhvS/r8zpKttuQjikcg34yTXWdR+HFUShmBYptfv/pNlqXl46W53IHF uVM9aqEthMj4umcng1a724Oe0bCHbpQBL0AI/OeaqYUwZ1vZMBiCJEZunkddLl6Jz9qfhS DavQsUVx7hx1fJ9x+x5qAUHTo3i+l0A= X-MC-Unique: JSO93zwVNhOG1PfUxfSwGQ-1 X-Original-To: libvir-list@listman.corp.redhat.com From: Laine Stump To: libvir-list@redhat.com Subject: [libvirt PATCH 8/9] qemu: hook up passt config to qemu domains Date: Sun, 8 Jan 2023 23:11:11 -0500 Message-Id: <20230109041112.368790-9-laine@redhat.com> In-Reply-To: <20230109041112.368790-1-laine@redhat.com> References: <20230109041112.368790-1-laine@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.1 on 10.11.54.3 X-BeenThere: libvir-list@redhat.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Development discussions about the libvirt library & tools List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: sbrivio@redhat.com, passt-dev@passt.top Errors-To: libvir-list-bounces@redhat.com Sender: "libvir-list" X-Scanned-By: MIMEDefang 3.1 on 10.11.54.1 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1673237487315100006 Content-Type: text/plain; charset="utf-8"; x-default="true" This consists of (1) adding the necessary args to the qemu commandline netdev option, and (2) starting a passt process prior to starting qemu, and making sure that it is terminated when it's no longer needed. Under normal circumstances, passt will terminate itself as soon as qemu closes its socket, but in case of some error where qemu is never started, or fails to startup completely, we need to terminate passt manually. Signed-off-by: Laine Stump Reviewed-by: J=C3=A1n Tomko --- meson.build | 1 + po/POTFILES | 1 + src/qemu/meson.build | 2 + src/qemu/qemu_command.c | 11 +- src/qemu/qemu_command.h | 3 +- src/qemu/qemu_domain.c | 5 +- src/qemu/qemu_domain.h | 3 +- src/qemu/qemu_extdevice.c | 25 +- src/qemu/qemu_hotplug.c | 26 +- src/qemu/qemu_passt.c | 284 ++++++++++++++++++ src/qemu/qemu_passt.h | 38 +++ src/qemu/qemu_process.c | 1 + src/qemu/qemu_validate.c | 9 +- tests/qemuxml2argvdata/net-user-passt.args | 34 +++ .../net-user-passt.x86_64-latest.args | 37 +++ tests/qemuxml2argvtest.c | 2 + 16 files changed, 470 insertions(+), 12 deletions(-) create mode 100644 src/qemu/qemu_passt.c create mode 100644 src/qemu/qemu_passt.h create mode 100644 tests/qemuxml2argvdata/net-user-passt.args create mode 100644 tests/qemuxml2argvdata/net-user-passt.x86_64-latest.args diff --git a/meson.build b/meson.build index 177009c44d..6604ba20c8 100644 --- a/meson.build +++ b/meson.build @@ -780,6 +780,7 @@ optional_programs =3D [ 'mm-ctl', 'modprobe', 'ovs-vsctl', + 'passt', 'pdwtags', 'rmmod', 'scrub', diff --git a/po/POTFILES b/po/POTFILES index 169e2a41dc..f979c9c4bc 100644 --- a/po/POTFILES +++ b/po/POTFILES @@ -180,6 +180,7 @@ src/qemu/qemu_monitor.c src/qemu/qemu_monitor_json.c src/qemu/qemu_monitor_text.c src/qemu/qemu_namespace.c +src/qemu/qemu_passt.c src/qemu/qemu_process.c src/qemu/qemu_qapi.c src/qemu/qemu_saveimage.c diff --git a/src/qemu/meson.build b/src/qemu/meson.build index 96952cc52d..c8806bbc36 100644 --- a/src/qemu/meson.build +++ b/src/qemu/meson.build @@ -28,6 +28,7 @@ qemu_driver_sources =3D [ 'qemu_monitor_json.c', 'qemu_monitor_text.c', 'qemu_namespace.c', + 'qemu_passt.c', 'qemu_process.c', 'qemu_qapi.c', 'qemu_saveimage.c', @@ -216,6 +217,7 @@ if conf.has('WITH_QEMU') localstatedir / 'log' / 'swtpm' / 'libvirt' / 'qemu', runstatedir / 'libvirt' / 'qemu', runstatedir / 'libvirt' / 'qemu' / 'dbus', + runstatedir / 'libvirt' / 'qemu' / 'passt', runstatedir / 'libvirt' / 'qemu' / 'slirp', runstatedir / 'libvirt' / 'qemu' / 'swtpm', ] diff --git a/src/qemu/qemu_command.c b/src/qemu/qemu_command.c index 42bd7cb99f..89af798a31 100644 --- a/src/qemu/qemu_command.c +++ b/src/qemu/qemu_command.c @@ -27,6 +27,7 @@ #include "qemu_interface.h" #include "qemu_alias.h" #include "qemu_security.h" +#include "qemu_passt.h" #include "qemu_slirp.h" #include "qemu_block.h" #include "qemu_fd.h" @@ -3793,7 +3794,8 @@ qemuBuildNicDevProps(virDomainDef *def, =20 =20 virJSONValue * -qemuBuildHostNetProps(virDomainNetDef *net) +qemuBuildHostNetProps(virDomainObj *vm, + virDomainNetDef *net) { virDomainNetType netType =3D virDomainNetGetActualType(net); size_t i; @@ -3908,7 +3910,10 @@ qemuBuildHostNetProps(virDomainNetDef *net) break; =20 case VIR_DOMAIN_NET_TYPE_USER: - if (netpriv->slirpfd) { + if (net->backend.type =3D=3D VIR_DOMAIN_NET_BACKEND_PASST) { + if (qemuPasstAddNetProps(vm, net, &netprops) < 0) + return NULL; + } else if (netpriv->slirpfd) { if (virJSONValueObjectAdd(&netprops, "s:type", "socket", "s:fd", qemuFDPassDirectGetPath(netp= riv->slirpfd), @@ -8452,7 +8457,7 @@ qemuBuildInterfaceCommandLine(virQEMUDriver *driver, qemuFDPassDirectTransferCommand(netpriv->slirpfd, cmd); qemuFDPassTransferCommand(netpriv->vdpafd, cmd); =20 - if (!(hostnetprops =3D qemuBuildHostNetProps(net))) + if (!(hostnetprops =3D qemuBuildHostNetProps(vm, net))) goto cleanup; =20 if (qemuBuildNetdevCommandlineFromJSON(cmd, hostnetprops, qemuCaps) < = 0) diff --git a/src/qemu/qemu_command.h b/src/qemu/qemu_command.h index 761cc5d865..c49096a057 100644 --- a/src/qemu/qemu_command.h +++ b/src/qemu/qemu_command.h @@ -78,7 +78,8 @@ virJSONValue * qemuBuildChannelGuestfwdNetdevProps(virDomainChrDef *chr); =20 virJSONValue * -qemuBuildHostNetProps(virDomainNetDef *net); +qemuBuildHostNetProps(virDomainObj *vm, + virDomainNetDef *net); =20 int qemuBuildInterfaceConnect(virDomainObj *vm, diff --git a/src/qemu/qemu_domain.c b/src/qemu/qemu_domain.c index 8892f28fce..ec55bc47c4 100644 --- a/src/qemu/qemu_domain.c +++ b/src/qemu/qemu_domain.c @@ -2351,6 +2351,7 @@ qemuDomainGetSlirpHelperOk(virDomainObj *vm) =20 /* if there is a builtin slirp, prevent slirp-helper */ if (net->type =3D=3D VIR_DOMAIN_NET_TYPE_USER && + net->backend.type =3D=3D VIR_DOMAIN_NET_BACKEND_DEFAULT && !QEMU_DOMAIN_NETWORK_PRIVATE(net)->slirp) return false; } @@ -9906,7 +9907,8 @@ qemuDomainSupportsNicdev(virDomainDef *def, } =20 bool -qemuDomainNetSupportsMTU(virDomainNetType type) +qemuDomainNetSupportsMTU(virDomainNetType type, + virDomainNetBackendType backend) { switch (type) { case VIR_DOMAIN_NET_TYPE_NETWORK: @@ -9915,6 +9917,7 @@ qemuDomainNetSupportsMTU(virDomainNetType type) case VIR_DOMAIN_NET_TYPE_VHOSTUSER: return true; case VIR_DOMAIN_NET_TYPE_USER: + return backend =3D=3D VIR_DOMAIN_NET_BACKEND_PASST; case VIR_DOMAIN_NET_TYPE_SERVER: case VIR_DOMAIN_NET_TYPE_CLIENT: case VIR_DOMAIN_NET_TYPE_MCAST: diff --git a/src/qemu/qemu_domain.h b/src/qemu/qemu_domain.h index 2f027fad87..c82d56191d 100644 --- a/src/qemu/qemu_domain.h +++ b/src/qemu/qemu_domain.h @@ -883,7 +883,8 @@ int qemuDomainRefreshVcpuHalted(virDomainObj *vm, bool qemuDomainSupportsNicdev(virDomainDef *def, virDomainNetDef *net); =20 -bool qemuDomainNetSupportsMTU(virDomainNetType type); +bool qemuDomainNetSupportsMTU(virDomainNetType type, + virDomainNetBackendType backend); =20 int qemuDomainSetPrivatePaths(virQEMUDriver *driver, virDomainObj *vm); diff --git a/src/qemu/qemu_extdevice.c b/src/qemu/qemu_extdevice.c index d5c3e8ed71..f7b2e2e653 100644 --- a/src/qemu/qemu_extdevice.c +++ b/src/qemu/qemu_extdevice.c @@ -25,6 +25,7 @@ #include "qemu_dbus.h" #include "qemu_domain.h" #include "qemu_tpm.h" +#include "qemu_passt.h" #include "qemu_slirp.h" #include "qemu_virtiofs.h" =20 @@ -194,8 +195,16 @@ qemuExtDevicesStart(virQEMUDriver *driver, for (i =3D 0; i < def->nnets; i++) { virDomainNetDef *net =3D def->nets[i]; =20 - if (qemuSlirpStart(vm, net, incomingMigration) < 0) - return -1; + if (net->type !=3D VIR_DOMAIN_NET_TYPE_USER) + continue; + + if (net->backend.type =3D=3D VIR_DOMAIN_NET_BACKEND_PASST) { + if (qemuPasstStart(vm, net) < 0) + return -1; + } else { + if (qemuSlirpStart(vm, net, incomingMigration) < 0) + return -1; + } } =20 for (i =3D 0; i < def->nfss; i++) { @@ -254,6 +263,12 @@ qemuExtDevicesStop(virQEMUDriver *driver, =20 if (slirp) qemuSlirpStop(slirp, vm, driver, net); + + if (net->type =3D=3D VIR_DOMAIN_NET_TYPE_USER && + net->backend.type =3D=3D VIR_DOMAIN_NET_BACKEND_PASST) { + qemuPasstStop(vm, net); + } + if (actualType =3D=3D VIR_DOMAIN_NET_TYPE_ETHERNET && net->downscr= ipt) virNetDevRunEthernetScript(net->ifname, net->downscript); } @@ -319,6 +334,12 @@ qemuExtDevicesSetupCgroup(virQEMUDriver *driver, =20 if (slirp && qemuSlirpSetupCgroup(slirp, cgroup) < 0) return -1; + + if (net->type =3D=3D VIR_DOMAIN_NET_TYPE_USER && + net->backend.type =3D=3D VIR_DOMAIN_NET_BACKEND_PASST && + qemuPasstSetupCgroup(vm, net, cgroup) < 0) { + return -1; + } } =20 for (i =3D 0; i < def->ntpms; i++) { diff --git a/src/qemu/qemu_hotplug.c b/src/qemu/qemu_hotplug.c index 6e300f547c..217230f845 100644 --- a/src/qemu/qemu_hotplug.c +++ b/src/qemu/qemu_hotplug.c @@ -31,6 +31,7 @@ #include "qemu_command.h" #include "qemu_hostdev.h" #include "qemu_interface.h" +#include "qemu_passt.h" #include "qemu_process.h" #include "qemu_security.h" #include "qemu_block.h" @@ -1201,8 +1202,16 @@ qemuDomainAttachNetDevice(virQEMUDriver *driver, break; =20 case VIR_DOMAIN_NET_TYPE_USER: - if (!priv->disableSlirp && - virQEMUCapsGet(priv->qemuCaps, QEMU_CAPS_DBUS_VMSTATE)) { + if (net->backend.type =3D=3D VIR_DOMAIN_NET_BACKEND_PASST) { + + if (qemuPasstStart(vm, net) < 0) { + virReportError(VIR_ERR_INTERNAL_ERROR, + "%s", _("Failed to start passt")); + goto cleanup; + } + + } else if (!priv->disableSlirp && + virQEMUCapsGet(priv->qemuCaps, QEMU_CAPS_DBUS_VMSTATE))= { =20 if (qemuInterfacePrepareSlirp(driver, net) < 0) goto cleanup; @@ -1269,7 +1278,7 @@ qemuDomainAttachNetDevice(virQEMUDriver *driver, virNetDevSetMTU(net->ifname, net->mtu) < 0) goto cleanup; =20 - if (!(netprops =3D qemuBuildHostNetProps(net))) + if (!(netprops =3D qemuBuildHostNetProps(vm, net))) goto cleanup; =20 qemuDomainObjEnterMonitor(vm); @@ -1417,6 +1426,12 @@ qemuDomainAttachNetDevice(virQEMUDriver *driver, netdev_name =3D g_strdup_printf("host%s", net->info.alias); if (QEMU_DOMAIN_NETWORK_PRIVATE(net)->slirp) qemuSlirpStop(QEMU_DOMAIN_NETWORK_PRIVATE(net)->slirp, vm, driver,= net); + + if (net->type =3D=3D VIR_DOMAIN_NET_TYPE_USER && + net->backend.type =3D=3D VIR_DOMAIN_NET_BACKEND_PASST) { + qemuPasstStop(vm, net); + } + qemuDomainObjEnterMonitor(vm); if (charDevPlugged && qemuMonitorDetachCharDev(priv->mon, charDevAlias) < 0) @@ -4618,6 +4633,11 @@ qemuDomainRemoveNetDevice(virQEMUDriver *driver, if (QEMU_DOMAIN_NETWORK_PRIVATE(net)->slirp) qemuSlirpStop(QEMU_DOMAIN_NETWORK_PRIVATE(net)->slirp, vm, driver,= net); =20 + if (net->type =3D=3D VIR_DOMAIN_NET_TYPE_USER && + net->backend.type =3D=3D VIR_DOMAIN_NET_BACKEND_PASST) { + qemuPasstStop(vm, net); + } + virDomainAuditNet(vm, net, NULL, "detach", true); =20 for (i =3D 0; i < vm->def->nnets; i++) { diff --git a/src/qemu/qemu_passt.c b/src/qemu/qemu_passt.c new file mode 100644 index 0000000000..5941594811 --- /dev/null +++ b/src/qemu/qemu_passt.c @@ -0,0 +1,284 @@ +/* + * qemu_passt.c: QEMU passt support + * + * Copyright (C) 2022 Red Hat, Inc. + * + * This library is free software; you can redistribute it and/or + * modify it under the terms of the GNU Lesser General Public + * License as published by the Free Software Foundation; either + * version 2.1 of the License, or (at your option) any later version. + * + * This library is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + * Lesser General Public License for more details. + * + * You should have received a copy of the GNU Lesser General Public + * License along with this library. If not, see + * . + */ + +#include + +#include "qemu_dbus.h" +#include "qemu_extdevice.h" +#include "qemu_security.h" +#include "qemu_passt.h" +#include "virenum.h" +#include "virerror.h" +#include "virjson.h" +#include "virlog.h" +#include "virpidfile.h" + +#define VIR_FROM_THIS VIR_FROM_NONE + +VIR_LOG_INIT("qemu.passt"); + + +static char * +qemuPasstCreatePidFilename(virDomainObj *vm, + virDomainNetDef *net) +{ + qemuDomainObjPrivate *priv =3D vm->privateData; + virQEMUDriver *driver =3D priv->driver; + g_autoptr(virQEMUDriverConfig) cfg =3D virQEMUDriverGetConfig(driver); + g_autofree char *name =3D NULL; + + name =3D g_strdup_printf("%s-%s-passt", vm->def->name, net->info.alias= ); + + return virPidFileBuildPath(cfg->passtStateDir, name); +} + + +static char * +qemuPasstCreateSocketPath(virDomainObj *vm, + virDomainNetDef *net) +{ + char uuidstr[VIR_UUID_STRING_BUFLEN]; + qemuDomainObjPrivate *priv =3D vm->privateData; + virQEMUDriver *driver =3D priv->driver; + g_autoptr(virQEMUDriverConfig) cfg =3D virQEMUDriverGetConfig(driver); + + return g_strdup_printf("%s/%s-%s.socket", + cfg->passtStateDir, + virUUIDFormat(vm->def->uuid, uuidstr), + net->info.alias); +} + + +static int +qemuPasstGetPid(virDomainObj *vm, + virDomainNetDef *net, + pid_t *pid) +{ + g_autofree char *pidfile =3D qemuPasstCreatePidFilename(vm, net); + + return virPidFileReadPathIfLocked(pidfile, pid); +} + + +int +qemuPasstAddNetProps(virDomainObj *vm, + virDomainNetDef *net, + virJSONValue **netprops) +{ + g_autofree char *passtSocketName =3D qemuPasstCreateSocketPath(vm, net= ); + g_autoptr(virJSONValue) addrprops =3D NULL; + + if (virJSONValueObjectAdd(&addrprops, + "s:type", "unix", + "s:path", passtSocketName, + NULL) < 0) { + return -1; + } + + if (virJSONValueObjectAdd(netprops, + "s:type", "stream", + "a:addr", &addrprops, + "b:server", false, + /* "u:reconnect", 5, */ + NULL) < 0) { + return -1; + } + return 0; +} + + +void +qemuPasstStop(virDomainObj *vm, + virDomainNetDef *net) +{ + g_autofree char *pidfile =3D qemuPasstCreatePidFilename(vm, net); + virErrorPtr orig_err; + + virErrorPreserveLast(&orig_err); + + + if (virPidFileForceCleanupPath(pidfile) < 0) + VIR_WARN("Unable to kill passt process"); + + virErrorRestore(&orig_err); +} + + +int +qemuPasstSetupCgroup(virDomainObj *vm, + virDomainNetDef *net, + virCgroup *cgroup) +{ + pid_t pid =3D (pid_t) -1; + + if (qemuPasstGetPid(vm, net, &pid) < 0 || pid <=3D 0) + return -1; + + return virCgroupAddProcess(cgroup, pid); +} + + +int +qemuPasstStart(virDomainObj *vm, + virDomainNetDef *net) +{ + qemuDomainObjPrivate *priv =3D vm->privateData; + virQEMUDriver *driver =3D priv->driver; + g_autofree char *passtSocketName =3D qemuPasstCreateSocketPath(vm, net= ); + g_autoptr(virCommand) cmd =3D NULL; + g_autofree char *pidfile =3D qemuPasstCreatePidFilename(vm, net); + char macaddr[VIR_MAC_STRING_BUFLEN]; + size_t i; + pid_t pid =3D (pid_t) -1; + int exitstatus =3D 0; + int cmdret =3D 0; + VIR_AUTOCLOSE errfd =3D -1; + + cmd =3D virCommandNew(PASST); + + virCommandClearCaps(cmd); + virCommandSetPidFile(cmd, pidfile); + virCommandSetErrorFD(cmd, &errfd); + virCommandDaemonize(cmd); + + virCommandAddArgList(cmd, + "--one-off", + "--socket", passtSocketName, + "--mac-addr", virMacAddrFormat(&net->mac, macaddr= ), + NULL); + + if (net->mtu) { + virCommandAddArg(cmd, "--mtu"); + virCommandAddArgFormat(cmd, "%u", net->mtu); + } + + if (net->backend.upstream) + virCommandAddArgList(cmd, "--interface", net->backend.upstream, NU= LL); + + if (net->backend.logFile) + virCommandAddArgList(cmd, "--log-file", net->backend.logFile, NULL= ); + + /* Add IP address info */ + for (i =3D 0; i < net->guestIP.nips; i++) { + const virNetDevIPAddr *ip =3D net->guestIP.ips[i]; + g_autofree char *addr =3D NULL; + + /* validation has already limited us to + * a single IPv4 and single IPv6 address + */ + if (!(addr =3D virSocketAddrFormat(&ip->address))) + return -1; + + virCommandAddArgList(cmd, "--address", addr, NULL); + + if (ip->prefix && VIR_SOCKET_ADDR_IS_FAMILY(&ip->address, AF_INET)= ) { + /* validation already made sure no prefix is + * specified for IPv6 (not allowed by passt) + */ + virCommandAddArg(cmd, "--netmask"); + virCommandAddArgFormat(cmd, "%u", ip->prefix); + } + } + + /* Add port forwarding info */ + + for (i =3D 0; i < net->nPortForwards; i++) { + virDomainNetPortForward *pf =3D net->portForwards[i]; + g_auto(virBuffer) buf =3D VIR_BUFFER_INITIALIZER; + + if (pf->proto =3D=3D VIR_DOMAIN_NET_PROTO_TCP) { + virCommandAddArg(cmd, "--tcp-ports"); + } else if (pf->proto =3D=3D VIR_DOMAIN_NET_PROTO_UDP) { + virCommandAddArg(cmd, "--udp-ports"); + } else { + /* validation guarantees this will never happen */ + virReportError(VIR_ERR_INTERNAL_ERROR, + _("Invalid portForward proto value %u"), pf->pr= oto); + goto error; + } + + if (VIR_SOCKET_ADDR_VALID(&pf->address)) { + g_autofree char *addr =3D NULL; + + if (!(addr =3D virSocketAddrFormat(&pf->address))) + goto error; + + virBufferAddStr(&buf, addr); + + if (pf->dev) + virBufferAsprintf(&buf, "%%%s", pf->dev); + + virBufferAddChar(&buf, '/'); + } + + if (!pf->nRanges) { + virBufferAddLit(&buf, "all"); + } else { + size_t r; + + for (r =3D 0; r < pf->nRanges; r++) { + virDomainNetPortForwardRange *range =3D pf->ranges[r]; + + if (r > 0) + virBufferAddChar(&buf, ','); + + if (range->exclude =3D=3D VIR_TRISTATE_BOOL_YES) + virBufferAddChar(&buf, '~'); + + virBufferAsprintf(&buf, "%u", range->start); + + if (range->end) + virBufferAsprintf(&buf, "-%u", range->end); + if (range->to) { + virBufferAsprintf(&buf, ":%u", range->to); + if (range->end) { + virBufferAsprintf(&buf, "-%u", + range->end + range->to - range->= start); + } + } + } + } + virCommandAddArg(cmd, virBufferCurrentContent(&buf)); + } + + + if (qemuExtDeviceLogCommand(driver, vm, cmd, "passt") < 0) + goto error; + + if (qemuSecurityCommandRun(driver, vm, cmd, -1, -1, &exitstatus, &cmdr= et) < 0) + goto error; + + if (cmdret < 0 || exitstatus !=3D 0) { + virReportError(VIR_ERR_INTERNAL_ERROR, + _("Could not start 'passt'. exitstatus: %d"), exits= tatus); + goto error; + } + + return 0; + + error: + ignore_value(virPidFileReadPathIfLocked(pidfile, &pid)); + if (pid !=3D -1) + virProcessKillPainfully(pid, true); + if (pidfile) + unlink(pidfile); + + return -1; +} diff --git a/src/qemu/qemu_passt.h b/src/qemu/qemu_passt.h new file mode 100644 index 0000000000..623b494b7a --- /dev/null +++ b/src/qemu/qemu_passt.h @@ -0,0 +1,38 @@ +/* + * qemu_passt.h: QEMU passt support + * + * Copyright (C) 2022 Red Hat, Inc. + * + * This library is free software; you can redistribute it and/or + * modify it under the terms of the GNU Lesser General Public + * License as published by the Free Software Foundation; either + * version 2.1 of the License, or (at your option) any later version. + * + * This library is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + * Lesser General Public License for more details. + * + * You should have received a copy of the GNU Lesser General Public + * License along with this library. If not, see + * . + */ + +#pragma once + +#include "qemu_conf.h" + +int +qemuPasstAddNetProps(virDomainObj *vm, + virDomainNetDef *net, + virJSONValue **netprops); + +int qemuPasstStart(virDomainObj *vm, + virDomainNetDef *net); + +void qemuPasstStop(virDomainObj *vm, + virDomainNetDef *net); + +int qemuPasstSetupCgroup(virDomainObj *vm, + virDomainNetDef *net, + virCgroup *cgroup); diff --git a/src/qemu/qemu_process.c b/src/qemu/qemu_process.c index b6adcf2f2a..b5f1bcf557 100644 --- a/src/qemu/qemu_process.c +++ b/src/qemu/qemu_process.c @@ -5794,6 +5794,7 @@ qemuProcessNetworkPrepareDevices(virQEMUDriver *drive= r, if (virDomainHostdevInsert(def, hostdev) < 0) return -1; } else if (actualType =3D=3D VIR_DOMAIN_NET_TYPE_USER && + net->backend.type =3D=3D VIR_DOMAIN_NET_BACKEND_DEFAULT= && !priv->disableSlirp && virQEMUCapsGet(priv->qemuCaps, QEMU_CAPS_DBUS_VMSTATE))= { if (qemuInterfacePrepareSlirp(driver, net) < 0) diff --git a/src/qemu/qemu_validate.c b/src/qemu/qemu_validate.c index c687df0bfc..6e04b22da4 100644 --- a/src/qemu/qemu_validate.c +++ b/src/qemu/qemu_validate.c @@ -1830,6 +1830,13 @@ qemuValidateDomainDeviceDefNetwork(const virDomainNe= tDef *net, } hasIPv6 =3D true; =20 + if (ip->prefix && ip->prefix !=3D 64) { + virReportError(VIR_ERR_CONFIG_UNSUPPORTED, + _("unsupported IPv6 address prefix=3D'%= u' - must be 64"), + ip->prefix); + return -1; + } + if (ip->prefix > 120) { virReportError(VIR_ERR_XML_ERROR, "%s", _("prefix too long")); @@ -1892,7 +1899,7 @@ qemuValidateDomainDeviceDefNetwork(const virDomainNet= Def *net, } =20 if (net->mtu && - !qemuDomainNetSupportsMTU(net->type)) { + !qemuDomainNetSupportsMTU(net->type, net->backend.type)) { virReportError(VIR_ERR_CONFIG_UNSUPPORTED, _("setting MTU on interface type %s is not supporte= d yet"), virDomainNetTypeToString(net->type)); diff --git a/tests/qemuxml2argvdata/net-user-passt.args b/tests/qemuxml2arg= vdata/net-user-passt.args new file mode 100644 index 0000000000..8c887ca210 --- /dev/null +++ b/tests/qemuxml2argvdata/net-user-passt.args @@ -0,0 +1,34 @@ +LC_ALL=3DC \ +PATH=3D/bin \ +HOME=3D/tmp/lib/domain--1-QEMUGuest1 \ +USER=3Dtest \ +LOGNAME=3Dtest \ +XDG_DATA_HOME=3D/tmp/lib/domain--1-QEMUGuest1/.local/share \ +XDG_CACHE_HOME=3D/tmp/lib/domain--1-QEMUGuest1/.cache \ +XDG_CONFIG_HOME=3D/tmp/lib/domain--1-QEMUGuest1/.config \ +/usr/bin/qemu-system-x86_64 \ +-name guest=3DQEMUGuest1,debug-threads=3Don \ +-S \ +-object secret,id=3DmasterKey0,format=3Draw,file=3D/tmp/lib/domain--1-QEMU= Guest1/master-key.aes \ +-machine pc,usb=3Doff,dump-guest-core=3Doff \ +-accel tcg \ +-m 214 \ +-overcommit mem-lock=3Doff \ +-smp 1,sockets=3D1,cores=3D1,threads=3D1 \ +-uuid c7a5fdbd-edaf-9455-926a-d65c16db1809 \ +-display none \ +-no-user-config \ +-nodefaults \ +-chardev socket,id=3Dcharmonitor,fd=3D1729,server=3Don,wait=3Doff \ +-mon chardev=3Dcharmonitor,id=3Dmonitor,mode=3Dcontrol \ +-rtc base=3Dutc \ +-no-shutdown \ +-no-acpi \ +-boot strict=3Don \ +-blockdev '{"driver":"host_device","filename":"/dev/HostVG/QEMUGuest1","no= de-name":"libvirt-1-storage","auto-read-only":true,"discard":"unmap"}' \ +-blockdev '{"node-name":"libvirt-1-format","read-only":false,"driver":"raw= ","file":"libvirt-1-storage"}' \ +-device ide-hd,bus=3Dide.0,unit=3D0,drive=3Dlibvirt-1-format,id=3Dide0-0-0= ,bootindex=3D1 \ +-netdev stream,addr.path=3D/var/run/libvirt/qemu/passt/UUID-net0.socket,se= rver=3Doff,reconnect=3D5,id=3Dhostnet0 \ +-device rtl8139,netdev=3Dhostnet0,id=3Dnet0,mac=3D00:11:22:33:44:55,bus=3D= pci.0,addr=3D0x2 \ +-audiodev '{"id":"audio1","driver":"none"}' \ +-msg timestamp=3Don diff --git a/tests/qemuxml2argvdata/net-user-passt.x86_64-latest.args b/tes= ts/qemuxml2argvdata/net-user-passt.x86_64-latest.args new file mode 100644 index 0000000000..69194a2cfc --- /dev/null +++ b/tests/qemuxml2argvdata/net-user-passt.x86_64-latest.args @@ -0,0 +1,37 @@ +LC_ALL=3DC \ +PATH=3D/bin \ +HOME=3D/tmp/lib/domain--1-QEMUGuest1 \ +USER=3Dtest \ +LOGNAME=3Dtest \ +XDG_DATA_HOME=3D/tmp/lib/domain--1-QEMUGuest1/.local/share \ +XDG_CACHE_HOME=3D/tmp/lib/domain--1-QEMUGuest1/.cache \ +XDG_CONFIG_HOME=3D/tmp/lib/domain--1-QEMUGuest1/.config \ +/usr/bin/qemu-system-x86_64 \ +-name guest=3DQEMUGuest1,debug-threads=3Don \ +-S \ +-object '{"qom-type":"secret","id":"masterKey0","format":"raw","file":"/tm= p/lib/domain--1-QEMUGuest1/master-key.aes"}' \ +-machine pc,usb=3Doff,dump-guest-core=3Doff,memory-backend=3Dpc.ram \ +-accel tcg \ +-cpu qemu64 \ +-m 214 \ +-object '{"qom-type":"memory-backend-ram","id":"pc.ram","size":224395264}'= \ +-overcommit mem-lock=3Doff \ +-smp 1,sockets=3D1,cores=3D1,threads=3D1 \ +-uuid c7a5fdbd-edaf-9455-926a-d65c16db1809 \ +-display none \ +-no-user-config \ +-nodefaults \ +-chardev socket,id=3Dcharmonitor,fd=3D1729,server=3Don,wait=3Doff \ +-mon chardev=3Dcharmonitor,id=3Dmonitor,mode=3Dcontrol \ +-rtc base=3Dutc \ +-no-shutdown \ +-no-acpi \ +-boot strict=3Don \ +-blockdev '{"driver":"host_device","filename":"/dev/HostVG/QEMUGuest1","no= de-name":"libvirt-1-storage","auto-read-only":true,"discard":"unmap"}' \ +-blockdev '{"node-name":"libvirt-1-format","read-only":false,"driver":"raw= ","file":"libvirt-1-storage"}' \ +-device '{"driver":"ide-hd","bus":"ide.0","unit":0,"drive":"libvirt-1-form= at","id":"ide0-0-0","bootindex":1}' \ +-netdev '{"type":"stream","addr":{"type":"unix","path":"/bad-test-used-env= -xdg-runtime-dir/libvirt/qemu/run/passt/c7a5fdbd-edaf-9455-926a-d65c16db180= 9-net0.socket"},"server":false,"id":"hostnet0"}' \ +-device '{"driver":"rtl8139","netdev":"hostnet0","id":"net0","mac":"00:11:= 22:33:44:55","bus":"pci.0","addr":"0x2"}' \ +-audiodev '{"id":"audio1","driver":"none"}' \ +-sandbox on,obsolete=3Ddeny,elevateprivileges=3Ddeny,spawn=3Ddeny,resource= control=3Ddeny \ +-msg timestamp=3Don diff --git a/tests/qemuxml2argvtest.c b/tests/qemuxml2argvtest.c index 4d563d3a09..a8b4a8d18c 100644 --- a/tests/qemuxml2argvtest.c +++ b/tests/qemuxml2argvtest.c @@ -471,6 +471,7 @@ testCompareXMLToArgvCreateArgs(virQEMUDriver *drv, virDomainNetDef *net =3D vm->def->nets[i]; =20 if (net->type =3D=3D VIR_DOMAIN_NET_TYPE_USER && + net->backend.type =3D=3D VIR_DOMAIN_NET_BACKEND_DEFAULT && virQEMUCapsGet(info->qemuCaps, QEMU_CAPS_DBUS_VMSTATE)) { qemuSlirp *slirp =3D qemuSlirpNew(); slirp->fd[0] =3D 42; @@ -1460,6 +1461,7 @@ mymain(void) DO_TEST_NOCAPS("net-user"); DO_TEST_CAPS_ARCH_LATEST_FULL("net-user", "x86_64", ARG_FLAGS, FLAG_SL= IRP_HELPER); DO_TEST_NOCAPS("net-user-addr"); + DO_TEST_CAPS_LATEST("net-user-passt"); DO_TEST_NOCAPS("net-virtio"); DO_TEST_NOCAPS("net-virtio-device"); DO_TEST_NOCAPS("net-virtio-disable-offloads"); --=20 2.38.1