From nobody Mon Aug 24 19:10:00 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=quarantine dis=none) header.from=suse.com ARC-Seal: i=1; a=rsa-sha256; t=1776931782; cv=none; d=zohomail.com; s=zohoarc; b=jPwqERAahWZxfJGwbI34hWsK2UH7ZVbW59Zu/iSfdRphE7i9fcNcJNzdp1Obi/GCnqLxH+pq8pguRvaj79CpZQsIGCOcnOEDYSV7T6S6bcM7Ocv2BE0i+NropC8OMqntNIQp2jTGun//2KMwCKGy2ijcS0cpFStIoKd+4p6SQUQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1776931782; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mye3eCQVSlEbkJEnkWGbsqAfuNKV6b0HpEvbptC1tVQ=; b=Gxoa/Xv2/8CxrwcCVe9ie6tVLY9A0vg0CVcWNoo2qSUQ41m5S+OTlaoykrAaZ1qL+p044fTsGdieMg9v9G/CbTu0yIGZiPC+bpuNf4EytHBDblPsjvUXWonc26creKzLTV2CD9ND9lom+63DzUqBqD4TKKVdpz/SYO6Z8cUeWj4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1776931782225896.8958946393736; Thu, 23 Apr 2026 01:09:42 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1291716.1570581 (Exim 4.92) (envelope-from ) id 1wFp7V-0006eB-37; Thu, 23 Apr 2026 08:09:09 +0000 Received: by outflank-mailman (output) from mailman id 1291716.1570581; Thu, 23 Apr 2026 08:09:09 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wFp7U-0006e0-Uv; Thu, 23 Apr 2026 08:09:08 +0000 Received: by outflank-mailman (input) for mailman id 1291716; Thu, 23 Apr 2026 08:09:07 +0000 Received: from mx.expurgate.net ([195.190.135.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wFp7T-0006Ny-Ol for xen-devel@lists.xenproject.org; Thu, 23 Apr 2026 08:09:07 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wFp7T-009pmL-5G for xen-devel@lists.xenproject.org; Thu, 23 Apr 2026 10:09:07 +0200 Received: from [10.42.69.9] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 69e9d39e-2eae-0a2a0a5409dd-0a2a4509aeac-16 for ; Thu, 23 Apr 2026 10:09:07 +0200 Received: from [195.135.223.130] (helo=smtp-out1.suse.de) by tlsNG-bad1c0.mxtls.expurgate.net with ESMTPS (eXpurgate 4.56.1) (envelope-from ) id 69e9d3a2-2497-0a2a45090019-c387df82c062-3 for ; Thu, 23 Apr 2026 10:09:07 +0200 Received: from imap1.dmz-prg2.suse.org (imap1.dmz-prg2.suse.org [IPv6:2a07:de40:b281:104:10:150:64:97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out1.suse.de (Postfix) with ESMTPS id 9617E6A81E; Thu, 23 Apr 2026 08:09:00 +0000 (UTC) Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id 6EF76593A3; Thu, 23 Apr 2026 08:09:00 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id r7kHGpzT6WkEXgAAD6G6ig (envelope-from ); Thu, 23 Apr 2026 08:09:00 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=susede1 header.d=suse.com header.i="@suse.com" header.h="From:Date:Message-ID:To:Cc:MIME-Version:Content-Transfer-Encoding:In-Reply-To:References"; dkim=pass header.s=susede1 header.d=suse.com header.i="@suse.com" header.h="From:Date:Message-ID:To:Cc:MIME-Version:Content-Transfer-Encoding:In-Reply-To:References" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=susede1; t=1776931741; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=mye3eCQVSlEbkJEnkWGbsqAfuNKV6b0HpEvbptC1tVQ=; b=sPZf6KqqJRs24isDTQ3Kms4qAjjRhGoIKm66ukA1cIV1y945/3NRA2RegytzyEVa9AQLuD FP0D0BomlwISbMcjxjjIXLVllHLi3lcs3GIFIeyIzdeerDPIR+46fB8fWFlU3ciME2ASqt AuzhPVG3swBKXn6zCZFHFdUpe05mjE0= Authentication-Results: smtp-out1.suse.de; dkim=pass header.d=suse.com header.s=susede1 header.b=AgfXxE44 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=susede1; t=1776931740; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=mye3eCQVSlEbkJEnkWGbsqAfuNKV6b0HpEvbptC1tVQ=; b=AgfXxE44EPVmap4ZnIVWJtN9LpKEhQY9msq5nMBi1S9lBSMXtQBiigKT45Y5QpJDKvQFhM tKI0BRllurFsX1ml8neyfELHMKsl+9wJk9GM56MwN0LIklNoQhTa4WdpfUXgy8qMN8RwZL P2Uxz4krBpnib2eAupPqs2A36OL7wjc= From: Juergen Gross To: xen-devel@lists.xenproject.org Cc: dmukhin@ford.com, Juergen Gross , Julien Grall , Anthony PERARD Subject: [PATCH 3/4] tools/xenstored: allow @releaseDomain watch for all domains Date: Thu, 23 Apr 2026 10:08:39 +0200 Message-ID: <20260423080840.530547-4-jgross@suse.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260423080840.530547-1-jgross@suse.com> References: <20260423080840.530547-1-jgross@suse.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Rspamd-Action: no action X-Rspamd-Server: rspamd2.dmz-prg2.suse.org X-Spamd-Result: default: False [-3.01 / 50.00]; BAYES_HAM(-3.00)[100.00%]; MID_CONTAINS_FROM(1.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; R_MISSING_CHARSET(0.50)[]; R_DKIM_ALLOW(-0.20)[suse.com:s=susede1]; NEURAL_HAM_SHORT(-0.20)[-1.000]; MIME_GOOD(-0.10)[text/plain]; MX_GOOD(-0.01)[]; MIME_TRACE(0.00)[0:+]; FUZZY_RATELIMITED(0.00)[rspamd.com]; DKIM_SIGNED(0.00)[suse.com:s=susede1]; TO_DN_SOME(0.00)[]; RBL_SPAMHAUS_BLOCKED_OPENRESOLVER(0.00)[2a07:de40:b281:104:10:150:64:97:from]; SPAMHAUS_XBL(0.00)[2a07:de40:b281:104:10:150:64:97:from]; ARC_NA(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; TO_MATCH_ENVRCPT_ALL(0.00)[]; FROM_HAS_DN(0.00)[]; RECEIVED_SPAMHAUS_BLOCKED_OPENRESOLVER(0.00)[2a07:de40:b281:106:10:150:64:167:received]; FROM_EQ_ENVFROM(0.00)[]; MAILSPIKE_FAIL(0.00)[2a07:de40:b281:104:10:150:64:97:query timed out]; RCVD_VIA_SMTP_AUTH(0.00)[]; RCVD_TLS_ALL(0.00)[]; DKIM_TRACE(0.00)[suse.com:+]; RCPT_COUNT_FIVE(0.00)[5]; DBL_BLOCKED_OPENRESOLVER(0.00)[imap1.dmz-prg2.suse.org:helo,imap1.dmz-prg2.suse.org:rdns,suse.com:dkim,suse.com:mid,suse.com:email] X-Rspamd-Queue-Id: 9617E6A81E X-Spam-Flag: NO X-Spam-Score: -3.01 X-Spam-Level: X-purgate-ID: tlsNG-bad1c0/1776931747-492B2A53-5C4844DD/0/0 X-purgate-type: clean X-purgate-size: 2636 X-ZohoMail-DKIM: pass (identity @suse.com) (identity @suse.com) X-ZM-MESSAGEID: 1776931783668154100 Content-Type: text/plain; charset="utf-8" Currently the @releaseDomain watch is allowed for dom0 only. This is problematic for guests which want to give other domains access to Xenstore entries, as they have no simple way to tell when such a domain is stopped. Allow @releaseDomain to be usable by all domains as the default. Signed-off-by: Juergen Gross Reviewed-by: Jason Andryuk --- tools/xenstored/core.c | 26 ++++++++++++++++++++------ 1 file changed, 20 insertions(+), 6 deletions(-) diff --git a/tools/xenstored/core.c b/tools/xenstored/core.c index 5a621f53ba..421f227ff1 100644 --- a/tools/xenstored/core.c +++ b/tools/xenstored/core.c @@ -2279,19 +2279,19 @@ struct connection *get_connection_by_id(unsigned in= t conn_id) } =20 /* We create initial nodes manually. */ -static void manual_node(const char *name, const char *child) +static void manual_node_perms(const char *name, const char *child, + struct xs_permissions *perms, + unsigned int n_perms) { struct node *node; - struct xs_permissions perms =3D { .id =3D priv_domid, - .perms =3D XS_PERM_NONE }; =20 node =3D talloc_zero(NULL, struct node); if (!node) barf_perror("Could not allocate initial node %s", name); =20 node->name =3D name; - node->perms =3D &perms; - node->hdr.num_perms =3D 1; + node->perms =3D perms; + node->hdr.num_perms =3D n_perms; node->children =3D (char *)child; if (child) node->hdr.childlen =3D strlen(child) + 1; @@ -2301,6 +2301,14 @@ static void manual_node(const char *name, const char= *child) talloc_free(node); } =20 +static void manual_node(const char *name, const char *child) +{ + struct xs_permissions perms =3D { .id =3D priv_domid, + .perms =3D XS_PERM_NONE }; + + manual_node_perms(name, child, &perms, 1); +} + static unsigned int hash_from_key_fn(const void *k) { const char *str =3D k; @@ -2320,6 +2328,11 @@ static int keys_equal_fn(const void *key1, const voi= d *key2) =20 void setup_structure(bool live_update) { + struct xs_permissions perms[] =3D { + { .id =3D priv_domid, .perms =3D XS_PERM_NONE }, + { .id =3D DOMID_ANY, .perms =3D XS_PERM_READ }, + }; + nodes =3D create_hashtable(NULL, "nodes", hash_from_key_fn, keys_equal_fn, HASHTABLE_FREE_KEY | HASHTABLE_FREE_VALUE); if (!nodes) @@ -2331,7 +2344,8 @@ void setup_structure(bool live_update) manual_node("/", "tool"); manual_node("/tool", "xenstored"); manual_node("/tool/xenstored", NULL); - manual_node("@releaseDomain", NULL); + manual_node_perms("@releaseDomain", NULL, + perms, ARRAY_SIZE(perms)); manual_node("@introduceDomain", NULL); domain_nbentry_fix(priv_domid, 5); } --=20 2.53.0