]> git.ipfire.org Git - thirdparty/libvirt.git/log
thirdparty/libvirt.git
2 days agoNEWS: Document features/improvements/bug fixes I've participated in master
Michal Privoznik [Fri, 31 Oct 2025 12:31:49 +0000 (13:31 +0100)] 
NEWS: Document features/improvements/bug fixes I've participated in

There are some features/improvements/bug fixes I've either
contributed or reviewed/merged. Document them for upcoming
release.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
2 days agoTranslated using Weblate (Ukrainian) v11.9.0-rc2
Yuri Chornoivan [Fri, 31 Oct 2025 09:59:00 +0000 (09:59 +0000)] 
Translated using Weblate (Ukrainian)

Currently translated at 100.0% (10976 of 10976 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/uk/

Signed-off-by: Yuri Chornoivan <yurchor@ukr.net>
2 days agoTranslated using Weblate (Portuguese)
Américo Monteiro [Fri, 31 Oct 2025 09:58:59 +0000 (09:58 +0000)] 
Translated using Weblate (Portuguese)

Currently translated at 98.2% (10788 of 10976 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 98.0% (10766 of 10976 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
2 days agodocs: drvbhyve: document NVMe device
Roman Bogorodskiy [Wed, 29 Oct 2025 17:58:47 +0000 (18:58 +0100)] 
docs: drvbhyve: document NVMe device

Signed-off-by: Roman Bogorodskiy <bogorodskiy@gmail.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
2 days agoNEWS: document bhyve changes for 11.9.0
Roman Bogorodskiy [Wed, 29 Oct 2025 17:58:46 +0000 (18:58 +0100)] 
NEWS: document bhyve changes for 11.9.0

Signed-off-by: Roman Bogorodskiy <bogorodskiy@gmail.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
2 days agodrvch: Document config file locations
Michal Privoznik [Fri, 31 Oct 2025 09:45:54 +0000 (10:45 +0100)] 
drvch: Document config file locations

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
2 days agoch: Load ch.conf from SYSCONFDIR
Michal Privoznik [Thu, 23 Oct 2025 13:33:04 +0000 (15:33 +0200)] 
ch: Load ch.conf from SYSCONFDIR

Config files for system instances of our drivers (e.g.
"ch:///system", "qemu:///system", etc.) live under /etc/libvirt.
But for some reason, the CH driver was trying to load the config
file from /var/lib/libvirt/ch/ even though the file is installed
under /etc/libvirt per the following line from src/meson.build:

  install_data(virt_conf_files, install_dir: confdir)

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
2 days agodrvch: Demote example section to a subsection
Michal Privoznik [Fri, 31 Oct 2025 09:43:27 +0000 (10:43 +0100)] 
drvch: Demote example section to a subsection

In our drvch.rst there's a section with example XML. Demote it to
a subsection ('-') since the whole document starts with section
('=') and this paragraph is really just a child of the root.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
2 days agodocs: Document supported URIs for CH driver
Michal Privoznik [Fri, 31 Oct 2025 09:39:05 +0000 (10:39 +0100)] 
docs: Document supported URIs for CH driver

Our docs suggest that only session mode is supported for CH
drvier. Well, that's clearly not case. Document the system URI
and refer to other (remote) supported transport modes (yeah, that
works too).

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
4 days agoUpdate translation files
Weblate [Wed, 29 Oct 2025 12:04:57 +0000 (12:04 +0000)] 
Update translation files

Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/

Signed-off-by: Fedora Weblate Translation <i18n@lists.fedoraproject.org>
4 days agopo: Refresh potfile for v11.9.0 v11.9.0-rc1
Jiri Denemark [Wed, 29 Oct 2025 11:59:52 +0000 (12:59 +0100)] 
po: Refresh potfile for v11.9.0

Signed-off-by: Jiri Denemark <jdenemar@redhat.com>
4 days agodomain_conf: Avoid memory leak in virDomainMemoryDefFree()
Michal Privoznik [Wed, 29 Oct 2025 11:43:39 +0000 (12:43 +0100)] 
domain_conf: Avoid memory leak in virDomainMemoryDefFree()

In my one of my recent commits I've introduced new member to
virDomainMemoryDef struct. While allocated in
virDomainMemoryDefParseXML() its counterpart for freeing is
missing in virDomainMemoryDefFree(). Add it.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
4 days agoNEWS: Document virtio options for memory models
Michal Privoznik [Mon, 27 Oct 2025 14:55:21 +0000 (15:55 +0100)] 
NEWS: Document virtio options for memory models

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
4 days agoqemu_command: Generate virtio options for memory device
Michal Privoznik [Mon, 27 Oct 2025 13:28:08 +0000 (14:28 +0100)] 
qemu_command: Generate virtio options for memory device

Thanks to previous refactors (namely v11.1.0-rc1~142) this is
trivial. There's all the infrastructure needed to generate virtio
options onto cmd line, all that's left to do is set a pointer to
appropriate struct member.

Resolves: https://issues.redhat.com/browse/RHEL-7493
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
4 days agoconf: Introduce virtio options for virtio memory models
Michal Privoznik [Mon, 27 Oct 2025 10:38:57 +0000 (11:38 +0100)] 
conf: Introduce virtio options for virtio memory models

Both virtio-mem and virtio-pmem memory models are virtio devices
and as such support setting various virtio knobs (iommu, ats,
packed, page_per_vq) common to other virtio devices.

Introduce <driver/> element as a child to <memory/> element, just
like we do for other virtio devices, where aforementioned knobs
live.

NB, this is without docs changes, since we do not document which
virtio devices support these knobs and each one is already
documented.

Also, the virtio-options.xml test needed some additional
adjustment (apart from adding virtio-mem device) to enable memory
hotplug.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
4 days agoqemu: Use virDomainMemoryIsVirtioModel()
Michal Privoznik [Mon, 27 Oct 2025 14:05:47 +0000 (15:05 +0100)] 
qemu: Use virDomainMemoryIsVirtioModel()

Instead of having these big switch()-es that enumerate all memory
models (but act only on virtio models), let's use
virDomainMemoryIsVirtioModel() helper instead.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
4 days agoconf: Introduce virDomainMemoryIsVirtioModel()
Michal Privoznik [Mon, 27 Oct 2025 13:54:15 +0000 (14:54 +0100)] 
conf: Introduce virDomainMemoryIsVirtioModel()

The aim is to return true for memory models that are virtio
devices (virtio-mem and virtio-pmem) and false for everything
else.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
4 days agodomain_conf: Switch to virXMLFormatElement() in virDomainMemoryDefFormat()
Michal Privoznik [Mon, 27 Oct 2025 10:42:30 +0000 (11:42 +0100)] 
domain_conf: Switch to virXMLFormatElement() in virDomainMemoryDefFormat()

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
4 days agodomain_conf: Make virDomainMemoryDefFormat() return void
Michal Privoznik [Mon, 27 Oct 2025 10:55:46 +0000 (11:55 +0100)] 
domain_conf: Make virDomainMemoryDefFormat() return void

The only thing that's possibly making virDomainMemoryDefFormat()
fail is call to virDomainMemorySourceDefFormat() but that always
returns zero. Make both functions return void so callers are not
confused.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
4 days agobhyve: support specifying disk rotation rate
Roman Bogorodskiy [Sat, 25 Oct 2025 11:47:15 +0000 (13:47 +0200)] 
bhyve: support specifying disk rotation rate

Bhyve supports specifying disk rotation rate using the nmrr attribute,
e.g.:

 -s 3:0,ahci,hd:/data/img/freebsd.img,nmrr=1

Where 1 means the SSD, 0 (default) means do not report, and other values
specify the actual RPM.

Signed-off-by: Roman Bogorodskiy <bogorodskiy@gmail.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 days agobhyve: nvme: check if NVMe is supported by bhyve
Roman Bogorodskiy [Sat, 25 Oct 2025 08:15:58 +0000 (10:15 +0200)] 
bhyve: nvme: check if NVMe is supported by bhyve

For domains using NVMe disks make sure that the bhyve binary supports
that by checking capabilities.

Signed-off-by: Roman Bogorodskiy <bogorodskiy@gmail.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 days agobhyve: do not allow more than one NVMe device per controller
Roman Bogorodskiy [Sat, 25 Oct 2025 08:15:57 +0000 (10:15 +0200)] 
bhyve: do not allow more than one NVMe device per controller

As bhyve does not have explicit notion of controllers, and for NVMe
devices it allows to specify one a single source for for a given PCI
address, it effectively means that there could be only one device per
controller.

Update validation code to check this case.

Signed-off-by: Roman Bogorodskiy <bogorodskiy@gmail.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 days agobhyve: tests: cover 2 NVMe devices on 2 controllers case
Roman Bogorodskiy [Sat, 25 Oct 2025 08:15:56 +0000 (10:15 +0200)] 
bhyve: tests: cover 2 NVMe devices on 2 controllers case

Signed-off-by: Roman Bogorodskiy <bogorodskiy@gmail.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 days agobhyve: implement NVMe device support
Roman Bogorodskiy [Sat, 25 Oct 2025 08:15:55 +0000 (10:15 +0200)] 
bhyve: implement NVMe device support

NVMe devices in bhyve are modeled this way:

 -s $pciaddr,nvme,devpath[,opts]

devpath can be a path to the image or the block device. It also can be
"ram=size_in_MiB", but this is not covered by this series.

There could be only a single device per PCI address.

Optional configuration options (such as max number of queues, concurrent
I/O requests, etc) are also not covered by this series.

Signed-off-by: Roman Bogorodskiy <bogorodskiy@gmail.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
4 days agoTranslated using Weblate (Italian)
Salvatore Cocuzza [Wed, 29 Oct 2025 09:07:00 +0000 (09:07 +0000)] 
Translated using Weblate (Italian)

Currently translated at 33.6% (3694 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/it/

Signed-off-by: Salvatore Cocuzza <info@salvatorecocuzza.it>
4 days agoTranslated using Weblate (Spanish)
Fco. Javier F. Serrador [Wed, 29 Oct 2025 09:06:59 +0000 (09:06 +0000)] 
Translated using Weblate (Spanish)

Currently translated at 79.1% (8677 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/es/

Signed-off-by: "Fco. Javier F. Serrador" <fserrador@gmail.com>
4 days agoTranslated using Weblate (Finnish)
Ricky Tigg [Wed, 29 Oct 2025 09:06:59 +0000 (09:06 +0000)] 
Translated using Weblate (Finnish)

Currently translated at 22.2% (2437 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/fi/

Signed-off-by: Ricky Tigg <ricky.tigg@gmail.com>
4 days agoTranslated using Weblate (Russian)
Sergey A [Wed, 29 Oct 2025 09:06:58 +0000 (09:06 +0000)] 
Translated using Weblate (Russian)

Currently translated at 82.3% (9029 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/ru/

Signed-off-by: "Sergey A." <Ser82-png@yandex.ru>
4 days agoTranslated using Weblate (Portuguese)
Américo Monteiro [Wed, 29 Oct 2025 09:06:58 +0000 (09:06 +0000)] 
Translated using Weblate (Portuguese)

Currently translated at 97.5% (10692 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 97.4% (10687 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 97.0% (10642 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 96.3% (10562 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 96.1% (10545 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 95.4% (10462 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 95.2% (10445 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 94.5% (10362 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 94.0% (10307 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 93.3% (10230 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 93.0% (10199 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 92.2% (10117 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 92.0% (10090 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 91.3% (10013 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 91.0% (9979 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 90.5% (9926 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 90.3% (9902 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
Translated using Weblate (Portuguese)

Currently translated at 89.3% (9797 of 10962 strings)

Translation: libvirt/libvirt
Translate-URL: https://translate.fedoraproject.org/projects/libvirt/libvirt/pt/

Signed-off-by: Américo Monteiro <a_monteiro@gmx.com>
4 days agoqemuDomainBlocksStatsGather: Fix blockstats gathering after refactor
Peter Krempa [Tue, 28 Oct 2025 16:13:17 +0000 (17:13 +0100)] 
qemuDomainBlocksStatsGather: Fix blockstats gathering after refactor

Commit 58aa005f3e95114 which refactored how block stats are stored
intended to change the code path where stats for all devices are totaled
together by allocating new stats object and using that but the commit
forgot to actually change the pointers inside the loop.

Unfortunately this was not caught by the compiler as there were
pre-existing pointers of the same type with the same name, which
resulted into a NULL dereference.

Fixes: 58aa005f3e95114b4f2dab76ee4ade06182a3f20
Closes: https://gitlab.com/libvirt/libvirt/-/issues/827
Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
9 days agoconf: never reject <disk> <seclabel relabel='no'> overrides
Cole Robinson [Tue, 14 Oct 2025 17:41:45 +0000 (13:41 -0400)] 
conf: never reject <disk> <seclabel relabel='no'> overrides

Trying to disable <seclabel> for the whole <domain> and _also_
disable <seclabel> at the <disk> level will fail with:

  error: unsupported configuration: label overrides require relabeling to be enabled at the domain level

which seems wrong. Instead skip the validation when disk seclabel
has relabel='no', that config should always be valid.

Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
Signed-off-by: Cole Robinson <crobinso@redhat.com>
10 days agoNEWS: ch: announce network hotplug feature
Stefan Kober [Mon, 6 Oct 2025 15:18:11 +0000 (17:18 +0200)] 
NEWS: ch: announce network hotplug feature

On-behalf-of: SAP stefan.kober@sap.com
Signed-off-by: Stefan Kober <stefan.kober@cyberus-technology.de>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
10 days agoch: implement network device hot detach
Stefan Kober [Mon, 6 Oct 2025 15:18:10 +0000 (17:18 +0200)] 
ch: implement network device hot detach

On-behalf-of: SAP stefan.kober@sap.com
Signed-off-by: Stefan Kober <stefan.kober@cyberus-technology.de>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
10 days agoch: implement network device hot attach
Stefan Kober [Mon, 6 Oct 2025 15:18:09 +0000 (17:18 +0200)] 
ch: implement network device hot attach

On-behalf-of: SAP stefan.kober@sap.com
Signed-off-by: Stefan Kober <stefan.kober@cyberus-technology.de>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
10 days agoch: add net device alias assignment
Stefan Kober [Mon, 6 Oct 2025 15:18:08 +0000 (17:18 +0200)] 
ch: add net device alias assignment

On-behalf-of: SAP stefan.kober@sap.com
Signed-off-by: Stefan Kober <stefan.kober@cyberus-technology.de>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
10 days agoapparmor: Allow AMD-SEV device access for AMD-SEV VM
Hector Cao [Tue, 14 Oct 2025 15:28:34 +0000 (17:28 +0200)] 
apparmor: Allow AMD-SEV device access for AMD-SEV VM

AMD-SEV virtual machines interact with the underlying
AMD-SEV technology through the character device /dev/sev.
Currently, the AppArmor profile does not include the rule
required to allow this access.

There are two main approaches to address this limitation:

1) Add the required rule to the libvirt-qemu abstraction.
2) Dynamically add the rule only when the VM is an AMD-SEV
   guest.

Since AMD-SEV guests represent a niche use case, it is more
appropriate to apply the rule dynamically rather than granting
access to all VMs through a global abstraction change.

This commit implements option (2) by modifying the virt-aa-helper
binary to insert the necessary rule into the AppArmor dynamic
profile when the VM is identified as an AMD-SEV guest.

The added entry in the generated libvirt-<uuid>.files file
will look like:

  ...
  "/dev/sev" rw,
  ...

Signed-off-by: Hector Cao <hector.cao@canonical.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
10 days agoqemu: Drop /dev/kvm from default device ACL
Praveen K Paladugu [Wed, 22 Oct 2025 15:54:37 +0000 (10:54 -0500)] 
qemu: Drop /dev/kvm from default device ACL

A domain that runs with TCG emulation does not need kvm device, so drop
it from default device ACL.

Dynamically grant access to /dev/kvm based on domain type.

Signed-off-by: Praveen K Paladugu <prapal@linux.microsoft.com>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
11 days agoNEWS: Document Hyper-v never notify feature for spinlocks
Friedrich Oslage [Wed, 22 Oct 2025 13:13:29 +0000 (15:13 +0200)] 
NEWS: Document Hyper-v never notify feature for spinlocks

Signed-off-by: Friedrich Oslage <friedrich@oslage.de>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
11 days agoqemu: Update hyperv spinlock retries count default
Friedrich Oslage [Wed, 22 Oct 2025 09:07:16 +0000 (11:07 +0200)] 
qemu: Update hyperv spinlock retries count default

Update default to 0xFFFFFFFF ("never notify" in qemu) and make retries
attribute optional.

Signed-off-by: Friedrich Oslage <friedrich@oslage.de>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
11 days agoqemu: Fix hyperv spinlock retries count type mismatch
Friedrich Oslage [Wed, 22 Oct 2025 09:07:15 +0000 (11:07 +0200)] 
qemu: Fix hyperv spinlock retries count type mismatch

Use unsigned int for sprintf and update tests to ensure it can hold INT_MAX+1.

Signed-off-by: Friedrich Oslage <friedrich@oslage.de>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
11 days agoqemu: forbid readonly attribute for externally launched virtiofsd
Ján Tomko [Mon, 19 May 2025 16:20:57 +0000 (18:20 +0200)] 
qemu: forbid readonly attribute for externally launched virtiofsd

In that case, libvirtd cannot set it on the command line because
virtiofsd is not launched by libvirt.

https://issues.redhat.com/browse/RHEL-87522

Signed-off-by: Ján Tomko <jtomko@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemumonitorjsontes: Properly free blockstats
Peter Krempa [Tue, 21 Oct 2025 16:22:15 +0000 (18:22 +0200)] 
qemumonitorjsontes: Properly free blockstats

In the patch converting block stats to objects in 58aa005f3e9 I forgot
to change the allocation of the hash table in qemumonitorjsontest which
doesn't use the wrapper. This problem didn't manifest itself with newer
glib versions.

Use 'g_object_unref' instead of 'g_free'.

Fixes: 58aa005f3e9
Signed-off-by: Peter Krempa <pkrempa@redhat.com>
12 days agoRemove qemuMonitorBlockStatsUpdateCapacityBlockdev
Peter Krempa [Wed, 1 Oct 2025 14:28:52 +0000 (16:28 +0200)] 
Remove qemuMonitorBlockStatsUpdateCapacityBlockdev

Remove the function and address the ripple effect the removal has.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemuMonitorJSONGetAllBlockStatsInfo: Directly probe data from 'query-named-block...
Peter Krempa [Wed, 1 Oct 2025 14:26:01 +0000 (16:26 +0200)] 
qemuMonitorJSONGetAllBlockStatsInfo: Directly probe data from 'query-named-block-nodes'

Currently the data which was probed for statistics from
'query-named-block-nodes' was updated in a separate call in
qemuMonitorJSONBlockStatsUpdateCapacityBlockdev.

This patch moves and adapts the code so that everything is probed in
qemuMonitorJSONGetAllBlockStatsInfo.

qemuMonitorJSONBlockStatsUpdateCapacityBlockdev is now an empty function
and will be removed later.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemuMonitorJSONBlockStatsUpdateCapacityData: Merge into caller
Peter Krempa [Wed, 1 Oct 2025 14:16:58 +0000 (16:16 +0200)] 
qemuMonitorJSONBlockStatsUpdateCapacityData: Merge into caller

It's called just from
qemuMonitorJSONBlockStatsUpdateCapacityBlockdevWorker. Merging it in
makes the code much simpler especially when combined with a change to
APIs that can't fail.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemuMigrationCookieAddNBD: Use qemuBlockGetNamedNodeData to fetch the capacities
Peter Krempa [Wed, 1 Oct 2025 12:36:12 +0000 (14:36 +0200)] 
qemuMigrationCookieAddNBD: Use qemuBlockGetNamedNodeData to fetch the capacities

'qemuMonitorBlockStatsUpdateCapacityBlockdev' uses the same command
internally.

Upcoming patches will want to merge qemuMonitorBlockStatsUpdateCapacityBlockdev
into qemuMonitorGetAllBlockStatsInfo and qemuMigrationCookieAddNBD is
the only place that doesn't call qemuMonitorGetAllBlockStatsInfo.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemu: monitor: Rework qemuBlockStats into a g_object
Peter Krempa [Thu, 11 Sep 2025 14:53:56 +0000 (16:53 +0200)] 
qemu: monitor: Rework qemuBlockStats into a g_object

Create the g_object boilerplate and store references in the hash table
instead of copies.

This will simplify upcoming code which will add allocated fields into
qemuBlockStats.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemu_monitor_json.h: Use consistent function hader coding style
Peter Krempa [Wed, 1 Oct 2025 11:50:38 +0000 (13:50 +0200)] 
qemu_monitor_json.h: Use consistent function hader coding style

Convert the rest of the header file to the new prevailing coding style.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemu_monitor_json.c: Use consistent function hader coding style
Peter Krempa [Wed, 1 Oct 2025 11:50:38 +0000 (13:50 +0200)] 
qemu_monitor_json.c: Use consistent function hader coding style

Convert the rest of the code to the new prevailing coding style. Commit
6e6a11bc0ac did the same for the header file.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemu: monitor: Remove qemuMonitorQueryBlockstats
Peter Krempa [Thu, 11 Sep 2025 13:28:34 +0000 (15:28 +0200)] 
qemu: monitor: Remove qemuMonitorQueryBlockstats

Unused since v8.6.0-154-g75a0fbe420

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agovirNetDevVlanParse: Refactor cleanup
Peter Krempa [Mon, 20 Oct 2025 13:19:11 +0000 (15:19 +0200)] 
virNetDevVlanParse: Refactor cleanup

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agovirNetDevVlanParse: Use g_autofree for temporary variables
Peter Krempa [Mon, 20 Oct 2025 13:16:48 +0000 (15:16 +0200)] 
virNetDevVlanParse: Use g_autofree for temporary variables

Automatically free the variables to prevent leaks when returning from
middle of the function.

Fixes: 1de6fd5edb5
Closes: https://gitlab.com/libvirt/libvirt/-/issues/824
Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agovirNetDevVlanParse: Don't clear data on failure
Peter Krempa [Mon, 20 Oct 2025 13:15:13 +0000 (15:15 +0200)] 
virNetDevVlanParse: Don't clear data on failure

Clearing the data on failure is pointless as it's still cleared when
other parts of the parser fail.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemuxmlconftest: Add example for "sgio='filtered'" disk option
Peter Krempa [Wed, 15 Oct 2025 13:24:15 +0000 (15:24 +0200)] 
qemuxmlconftest: Add example for "sgio='filtered'" disk option

The test suite validates only the error with the "sgio='unfiltered'"
setting which isn't supported by the qemu driver. Validate also the
'filtered' used explicitly (the default behaviour if unspecified is the
same as 'filtered').

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agodocs: snapshot: Add a note that blockjobs ought to be avoided with 'manual' snapshots
Peter Krempa [Mon, 13 Oct 2025 13:27:16 +0000 (15:27 +0200)] 
docs: snapshot: Add a note that blockjobs ought to be avoided with 'manual' snapshots

Using a blockjob will reactivate the block nodes in qemu and thus e.g.
qcow2 metadata such as bitmaps may become marked as dirty. Users of
'manual' snapshots ought to avoid those.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemu: snapshot: Allow snapshot consisting only of 'manual'-y handled disks
Peter Krempa [Mon, 9 Jun 2025 13:50:42 +0000 (15:50 +0200)] 
qemu: snapshot: Allow snapshot consisting only of 'manual'-y handled disks

The 'manual' snapshot mode is meant for disks where the users wants to
take a snapshot via means outside of libvirt, e.g. on a SAN network.

Allow creating a snapshot which consists entirely of 'manual' disks. For
now this effectively means that the VM will be paused but in the future
more logic can be added to ensure consistency.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemu: snapshot: Deactivate block nodes on manually snapshotted disks
Peter Krempa [Fri, 6 Jun 2025 10:33:04 +0000 (12:33 +0200)] 
qemu: snapshot: Deactivate block nodes on manually snapshotted disks

If the user wants to manually preserve state of the disk we need, apart
from pausing the machine to quiesce all writes, also deactivate the
block nodes of the device. This ensures that qemu writes out metadata
(e.g. block dirty bitmaps) which are normally stored only in memory,
thus allowing a consistent snapshot including the metadata.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemu: migration: Don't reactivate block nodes after migration failure any more
Peter Krempa [Fri, 25 Jul 2025 14:13:39 +0000 (16:13 +0200)] 
qemu: migration: Don't reactivate block nodes after migration failure any more

The other code paths which do want to issue block jobs can reactivate
the nodes when necessary so we don't need to do that unconditionally
after failed/cancelled migration.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemu: Re-activate block nodes before storage operations
Peter Krempa [Thu, 24 Jul 2025 13:55:13 +0000 (15:55 +0200)] 
qemu: Re-activate block nodes before storage operations

Upcoming patches will modify how we treat inactive block nodes so that
we can properly deactivate nodes for 'manual' disk snapshot mode.

Re-activate the nodes before operations requiring them. This includes
also query operations where we e.g. probe bitmaps.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemu: block: Introduce helper function to ensure that block nodes are active
Peter Krempa [Wed, 23 Jul 2025 15:30:02 +0000 (17:30 +0200)] 
qemu: block: Introduce helper function to ensure that block nodes are active

Upcoming changes to snapshot code will break the assumption that block
nodes are always active (if the function is able to acquire a modify
job).

Introduce qemuBlockNodesEnsureActive that checks if the block graph in
qemu contains any inactive nodes and if yes reactivates everything.

The function will be used on code paths such as blockjobs which require
the nodes to be active.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemu: monitor: Track inactive state of block nodes in 'qemuBlockNamedNodeData'
Peter Krempa [Thu, 24 Jul 2025 12:49:55 +0000 (14:49 +0200)] 
qemu: monitor: Track inactive state of block nodes in 'qemuBlockNamedNodeData'

New qemus report if given block node is active. We'll be using this data
to decide if we need to reactivate them prior to blockjobs. Extract the
data as 'inactive' as it's simpler to track and we care only about
inactive nodes.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
12 days agoqemuDomainGetStatsCpuProc: Use string constants for CPU stats
Peter Krempa [Mon, 6 Oct 2025 13:59:39 +0000 (15:59 +0200)] 
qemuDomainGetStatsCpuProc: Use string constants for CPU stats

Commit 947306957e9 added the constants and fixed other uses but didn't
fix qemuDomainGetStatsCpuProc.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Pavel Hrdina <phrdina@redhat.com>
2 weeks agoqemu: Drop reconnectBlockjobs from _qemuDomainObjPrivate struct
Michal Privoznik [Wed, 15 Oct 2025 08:49:20 +0000 (10:49 +0200)] 
qemu: Drop reconnectBlockjobs from _qemuDomainObjPrivate struct

The 'reconnectBlockjobs' member of the _qemuDomainObjPrivate
struct is basically unused after v8.7.0-rc1~110. It's not even
formatted into the status XML, just parsed. This makes needless
noise.  Just drop the member.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
2 weeks agoNEWS: Document new host-model hyperv mode
Michal Privoznik [Mon, 6 Oct 2025 12:42:51 +0000 (14:42 +0200)] 
NEWS: Document new host-model hyperv mode

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_process: Populate hyperv features for host-model
Michal Privoznik [Mon, 29 Sep 2025 12:54:23 +0000 (14:54 +0200)] 
qemu_process: Populate hyperv features for host-model

Pretty straightforward. The only "weird" thing here is that
'hv-time' enlightenment is exposed as a <timer/> under <clock/>
element. Since it's required by 'hv-stimer' and
'hv-stimer-direct' it needs to be enabled too.

Resolves: https://issues.redhat.com/browse/RHEL-114003
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoconf: Introduce hyperv host-model mode
Michal Privoznik [Mon, 29 Sep 2025 08:20:41 +0000 (10:20 +0200)] 
conf: Introduce hyperv host-model mode

So far we have two modes for hyperv features:

1) custom, where users have to enable features explicitly, and
2) passthrough, where hypervisor enables features automagically.

Problem with 'custom' mode is that some features are not plain
on/off switches but expect int/string value. Until very recently,
these were not reported in domcaps. And even if they were it's a
bit cumbersome.

Problem with 'passthrough' mode is that users don't get to see
the expanded list of enlightenments enabled.

Therefore, mimic what we're already doing with CPUs: have
'host-model' which gets expanded at domain startup and is fixed
throughout domain's run.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_caps: Introduce virQEMUCapsGetHypervCapabilities()
Michal Privoznik [Mon, 29 Sep 2025 12:53:58 +0000 (14:53 +0200)] 
qemu_caps: Introduce virQEMUCapsGetHypervCapabilities()

We'll need to access hypervCapabilities memeber later on.
Introduce a getter function.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_capabilities: Fetch new hyperv domcaps
Michal Privoznik [Tue, 30 Sep 2025 13:37:24 +0000 (15:37 +0200)] 
qemu_capabilities: Fetch new hyperv domcaps

Now that everything is prepared, we can start storing the default
values for some hyperv features that are reported in domain
capabilities XML later.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_capabilities: Format and parse new hyperv domcaps members
Michal Privoznik [Wed, 1 Oct 2025 13:50:39 +0000 (15:50 +0200)] 
qemu_capabilities: Format and parse new hyperv domcaps members

After previous commit the virDomainCapsFeatureHyperv struct
gained new members. Since virQEMUCaps struct holds a pointer to
such struct we must format and parse it to/from capabilities XML.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoconf: Report default hyperv values in domain capabilities
Michal Privoznik [Tue, 30 Sep 2025 13:05:10 +0000 (15:05 +0200)] 
conf: Report default hyperv values in domain capabilities

So far the set of available Hyper-V enlightenments are reported
in domain capabilities. Well, some enlightenments are more than
just simple on/off switch. For instance, the 'spinlocks'
enlightenment expects a number, or 'vendor_id' expects a string.

All of these have some default values (at least in QEMU) and are
used when the passthrough mode is set.

Allow querying these defaults in domain capabilities XML.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agodocs: Drop remark on now unsupported version of QEMU
Michal Privoznik [Fri, 3 Oct 2025 10:46:21 +0000 (12:46 +0200)] 
docs: Drop remark on now unsupported version of QEMU

In formatdomaincaps.rst under section documenting hyperv features
there's a paragraph describing behaviour with QEMU older than
6.1.0. Well, as of v11.2.0-rc1~216 the minimum required version
is 6.2.0 rendering the paragraph needless. Drop it.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoconf: More hyperv related members into a single struct
Michal Privoznik [Tue, 30 Sep 2025 08:27:27 +0000 (10:27 +0200)] 
conf: More hyperv related members into a single struct

So far, we have an array of integers (hyperv_features), an uint
(hyperv_spinlocks), a string (hyperv_vendor_id) and some tristate
switches scattered across virDomainDef. Soon, new knobs will be
introduced and keeping the current state would only worsen
readability.

Introduce virDomainHypervFeatures struct to place hyperv related
features there.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agolibxl: Simplify setting HyperV features
Michal Privoznik [Tue, 30 Sep 2025 08:47:21 +0000 (10:47 +0200)] 
libxl: Simplify setting HyperV features

Inside of libxlMakeDomBuildInfo() there's a huge switch() for
each virDomainHyperv case. Instead of checking whether feature is
enabled in each 'case', let's just check it at the beginning of
each loop.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_command: Prefer virBufferAddLit() in qemuBuildCpuHypervCommandLine()
Michal Privoznik [Mon, 29 Sep 2025 11:50:18 +0000 (13:50 +0200)] 
qemu_command: Prefer virBufferAddLit() in qemuBuildCpuHypervCommandLine()

Using virBufferAsprintf() just to concatenate two literal strings
is excessive. Use virBufferAddLit().

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_command: Move hyperv cmd line generation into a function
Michal Privoznik [Mon, 29 Sep 2025 08:20:20 +0000 (10:20 +0200)] 
qemu_command: Move hyperv cmd line generation into a function

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_caps: Prefer VIR_DOMAIN_CAPS_ENUM_IS_SET()
Michal Privoznik [Mon, 29 Sep 2025 12:54:17 +0000 (14:54 +0200)] 
qemu_caps: Prefer VIR_DOMAIN_CAPS_ENUM_IS_SET()

While virDomainCapsEnum is in fact a bitmap, we also have a macro
to manipulate/query individual bits. Prefer it to make the code
more readable.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agodomain_conf: Use virXMLFormatElement() to format hyperv features
Michal Privoznik [Mon, 29 Sep 2025 14:05:31 +0000 (16:05 +0200)] 
domain_conf: Use virXMLFormatElement() to format hyperv features

Not only is it more modern that old virBufferAsprintf() of
opening and closing tag, it's also aware of child elements buffer
and thus formats a singleton properly.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agodomain_conf: Move format of hyperv features into a function
Michal Privoznik [Mon, 29 Sep 2025 14:20:17 +0000 (16:20 +0200)] 
domain_conf: Move format of hyperv features into a function

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu: Use virXPathTristateBool()
Michal Privoznik [Thu, 2 Oct 2025 07:38:04 +0000 (09:38 +0200)] 
qemu: Use virXPathTristateBool()

There are two places in our code base which can use freshly
introduced virXPathTristateBool():
qemuStorageSourcePrivateDataParse() and
qemuDomainObjPrivateXMLParseBlockjobs().

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agovirxml: Introduce virXPathTristateBool()
Michal Privoznik [Thu, 2 Oct 2025 07:29:19 +0000 (09:29 +0200)] 
virxml: Introduce virXPathTristateBool()

Similarly to other virXPath* functions, let's have a helper that
evaluates an XPath and stores the value into virTristateBool.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
2 weeks agovirxml: Introduce virXPathTristateSwitch()
Michal Privoznik [Thu, 2 Oct 2025 07:26:59 +0000 (09:26 +0200)] 
virxml: Introduce virXPathTristateSwitch()

Similarly to other virXPath* functions, let's have a helper that
evaluates an XPath and stores the value into virTristateSwitch.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agowireshark: Adapt to wireshark-4.6.0
Michal Privoznik [Fri, 10 Oct 2025 13:22:34 +0000 (15:22 +0200)] 
wireshark: Adapt to wireshark-4.6.0

The main difference is that wmem_packet_scope() is gone [1] but
the packet_info struct has 'pool` member which points to the
allocator used for given packet.

Unfortunately, while we were given pointer to packet_info at the
entry level to our dissector (dissect_libvirt() ->
tcp_dissect_pdus() -> dissect_libvirt_message()) it was never
propagated to generated/primitive dissectors.

But not all dissectors need to allocate memory, so mark the new
argument as unused. And while our generator could be rewritten so
that the argument is annotated as unused iff it's really unused,
I couldn't bother rewriting it. It's generated code after all.
Too much work for little gain.

Another significant change is that val_to_str() now requires new
argument: pointer to allocator to use because it always allocates
new memory [2][3].

1: https://gitlab.com/wireshark/wireshark/-/commit/5ca5c9ca372e06881b23ba9f4fdcb6b479886444
2: https://gitlab.com/wireshark/wireshark/-/commit/b63599762468e4cf1783419a5556377604d344bb
3: https://gitlab.com/wireshark/wireshark/-/commit/84799be215313e61b83a3eaf074f89d6ee349b8c
Resolves: https://gitlab.com/libvirt/libvirt/-/issues/823
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
2 weeks agowireshark: Don't leak column strings
Michal Privoznik [Fri, 10 Oct 2025 17:13:48 +0000 (19:13 +0200)] 
wireshark: Don't leak column strings

One of the problems of using val_to_str() is that it may return a
const string from given table ('vs'), OR return an allocated one.
Since the caller has no idea which case it is, it resides to safe
option and don't free returned string. But that might lead to a
memleak. This behaviour is fixed with wireshark-4.6.0 and support
for it will be introduced soon. But first, make vir_val_to_str()
behave like fixed val_to_str() from newer wireshark: just always
allocate the string.

Now, if val_to_str() needs to allocate new memory it obtains
allocator by calling wmem_packet_scope() which is what we may do
too.

Hand in hand with that, we need to free the memory using the
correct allocator, hence wmem_free(). But let's put it into a
wrapper vir_wmem_free() because just like val_to_str(), it'll
need additional argument when adapting to new wireshark.

Oh, and freeing the memory right after col_add_fstr() is safe as
it uses vsnprintf() under the hood to format passed args.

One last thing, the wmem.h file used to live under epan/wmem/ but
then in v3.5.0~240 [1] was moved to wsutil/wmem/.

1: https://gitlab.com/wireshark/wireshark/-/commit/7f9c1f5f92c131354fc8b2b88d473706786064c0
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
2 weeks agowireshark: Introduce and use vir_val_to_str()
Michal Privoznik [Fri, 10 Oct 2025 16:23:18 +0000 (18:23 +0200)] 
wireshark: Introduce and use vir_val_to_str()

Wireshark offers val_to_str() function which converts numeric
value to string by looking up value ('val') in an array ('vs') of
<val, string> pairs. If no corresponding string is found, then
the value is formatted using given 'fmt' string.

Starting from wireshark-4.6.0 not only this function gained
another argument but also returns a strdup()-ed string. To keep
our code simple, let's introduce a wrapper so which can be then
adjusted as needed.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
2 weeks agowireshark: Don't special case retval of get_program_data() in dissect_libvirt_message()
Michal Privoznik [Fri, 10 Oct 2025 17:16:54 +0000 (19:16 +0200)] 
wireshark: Don't special case retval of get_program_data() in dissect_libvirt_message()

The get_program_data() function returns a pointer (in this
specific case to an array of procedure strings) which, if
non-NULL is then passed val_to_str(). Well, if val_to_str() sees
NULL it is treated gracefully, i.e. like if the numeric value
'proc' wasn't found in the array.

Therefore, there's no need to special case call to
col_append_fstr(). Both result into the same behaviour.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
2 weeks agowireshark: Fix int type of some virNetMessageHeader members
Michal Privoznik [Mon, 13 Oct 2025 07:21:30 +0000 (09:21 +0200)] 
wireshark: Fix int type of some virNetMessageHeader members

Our virNetMessageHeader is a struct that's declared as follows:

  struct virNetMessageHeader {
      unsigned prog;
      unsigned vers;
      int proc;
      virNetMessageType type;
      unsigned serial;
      virNetMessageStatus status;
  };

Now, per RFC 4506 enums are also encoded as signed integers. This
means, that only 'prog', 'vers' and 'serial' are really unsigned
integers. The others ('proc', 'type' and 'status') are encoded as
signed integers. Fix their type when dissecting.

While at it, also follow latest trend in wireshark and switch
from guint32 to uint32_t.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
2 weeks agowireshark: Move WIRESHARK_VERSION macro definition
Michal Privoznik [Mon, 13 Oct 2025 07:04:17 +0000 (09:04 +0200)] 
wireshark: Move WIRESHARK_VERSION macro definition

Soon, other parts of the wireshark code will need to
differentiate wrt wireshark version. Therefore, move the
WIRESHARK_VERSION macro definition among with its deps into
packet-libvirt.h.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
2 weeks agowireshark: Switch header files to #pragma once
Michal Privoznik [Fri, 10 Oct 2025 13:20:05 +0000 (15:20 +0200)] 
wireshark: Switch header files to #pragma once

The genxdrstub.pl script generates some header files. But they
use the old pattern to guard against multiple inclusion:

  #ifndef SOMETHING_H
  #define SOMETHING_H
  ...
  #endif

Change the script to generate just '#pragma once' used everywhere
else in our code.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
2 weeks agowireshark: Drop needless declaration of proto_register_libvirt() and proto_reg_handof...
Michal Privoznik [Mon, 13 Oct 2025 08:34:51 +0000 (10:34 +0200)] 
wireshark: Drop needless declaration of proto_register_libvirt() and proto_reg_handoff_libvirt()

Both proto_register_libvirt() and proto_reg_handoff_libvirt() are
declared in packet-libvirt.h which is included from plugin.c.
There's no need to provide another declaration in plugin.c.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
2 weeks agoNEWS: Document Hyper-V enlightenment validation
Michal Privoznik [Wed, 8 Oct 2025 11:35:54 +0000 (13:35 +0200)] 
NEWS: Document Hyper-V enlightenment validation

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_validate: Reflect dependencies of hv-tlbflush-direct
Michal Privoznik [Wed, 8 Oct 2025 10:24:12 +0000 (12:24 +0200)] 
qemu_validate: Reflect dependencies of hv-tlbflush-direct

Per QEMU documentation (docs/system/i386/hyperv.rst):

``hv-tlbflush-direct``
  The enlightenment is nested specific, it targets Hyper-V on KVM guests. <snip/>

  Requires: ``hv-vapic``

Reflect this dependency when validating domain definition.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_validate: Reflect dependencies of hv-evmcs
Michal Privoznik [Wed, 8 Oct 2025 08:51:53 +0000 (10:51 +0200)] 
qemu_validate: Reflect dependencies of hv-evmcs

Per QEMU documentation (docs/system/i386/hyperv.rst):

``hv-evmcs``
  The enlightenment is nested specific, it targets Hyper-V on KVM guests. <snip/>

  Requires: ``hv-vapic``

Reflect this dependency when validating domain definition.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_validate: Reflect dependencies of hv-ipi
Michal Privoznik [Wed, 8 Oct 2025 08:50:32 +0000 (10:50 +0200)] 
qemu_validate: Reflect dependencies of hv-ipi

Per QEMU documentation (docs/system/i386/hyperv.rst):

``hv-ipi``
  Enables paravirtualized IPI send mechanism. <snip/>

  Requires: ``hv-vpindex``

Reflect this dependency when validating domain definition.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_validate: Reflect dependencies of hv-tlbflush
Michal Privoznik [Wed, 8 Oct 2025 08:48:07 +0000 (10:48 +0200)] 
qemu_validate: Reflect dependencies of hv-tlbflush

Per QEMU documentation (docs/system/i386/hyperv.rst):

``hv-tlbflush``
  Enables paravirtualized TLB shoot-down mechanism. <snip/>

  Requires: ``hv-vpindex``

Reflect this dependency when validating domain definition.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_validate: Reflect dependencies of hv-stimer
Michal Privoznik [Tue, 7 Oct 2025 11:42:19 +0000 (13:42 +0200)] 
qemu_validate: Reflect dependencies of hv-stimer

Per QEMU documentation (docs/system/i386/hyperv.rst):

``hv-stimer``
  Enables Hyper-V synthetic timers. <snip/>

  Requires: ``hv-vpindex``, ``hv-synic``, ``hv-time``

Reflect these dependencies when validating domain definition.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemu_validate: Reflect dependencies of hv-synic
Michal Privoznik [Wed, 8 Oct 2025 07:56:50 +0000 (09:56 +0200)] 
qemu_validate: Reflect dependencies of hv-synic

Per QEMU documentation (docs/system/i386/hyperv.rst):

``hv-synic``
  Enables Hyper-V Synthetic interrupt controller <snip/>

  Requires: ``hv-vpindex``

Reflect this dependency when validating domain definition.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoqemuxmlconfdata: Adjust hv-stimer related tests
Michal Privoznik [Tue, 7 Oct 2025 09:54:21 +0000 (11:54 +0200)] 
qemuxmlconfdata: Adjust hv-stimer related tests

In QEMU, hv-stimer and hv-stimer-direct require hv-time. Reflect
this fact in our tests.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agoconf: Introduce virDomainDefHasTimer()
Michal Privoznik [Tue, 7 Oct 2025 11:42:03 +0000 (13:42 +0200)] 
conf: Introduce virDomainDefHasTimer()

This is a simple helper to tell whether domain definition has
certain type of timer or not.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
2 weeks agosrc: Drop needless typecast to virDomainTimerNameType
Michal Privoznik [Tue, 7 Oct 2025 07:32:47 +0000 (09:32 +0200)] 
src: Drop needless typecast to virDomainTimerNameType

This was missed in v8.10.0-rc1~229 which switched the 'name'
member of _virDomainTimerDef struct from int to
virDomainTimerNameType.

Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
3 weeks agonetwork: pf: split flush and rules commands
Roman Bogorodskiy [Sat, 4 Oct 2025 14:55:49 +0000 (16:55 +0200)] 
network: pf: split flush and rules commands

Current implementation uses a single command to flush the old rules and
create new ones. This is not optimal because if flush fails for some
non-critical reasons (e.g. because the anchor didn't previously exist),
it will block rules creation and network start.

Split this command into two: one for flush, and one for rules creation.
Also, don't fail if the flush command fails.

Signed-off-by: Roman Bogorodskiy <bogorodskiy@gmail.com>
Reviewed-by: Laine Stump <laine@redhat.com>