]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
qemu_tpm: Generate log file path among with storage path
authorMichal Privoznik <mprivozn@redhat.com>
Wed, 24 Feb 2021 16:28:42 +0000 (17:28 +0100)
committerMichal Privoznik <mprivozn@redhat.com>
Tue, 2 Mar 2021 08:45:49 +0000 (09:45 +0100)
When starting a guest with TPM of type='emulator' an external
process is started with it (swtpm) to emulate TPM. This external
process is passed path to a log file via --logfile. The path to
the log file is generated in qemuTPMEmulatorPrepareHost() which
works, until the daemon is restarted. The problem is that the
path is not stored in private data or anywhere inside live XML
and thus later, when qemuExtTPMStop() is called (when shutting
off the guest) the stored logpath is NULL and thus its seclabel
is not cleaned up (see virSecuritySELinuxRestoreTPMLabels()).

Fortunately, qemuExtDevicesStop() (which calls qemuExtTPMStop()
eventually) does call qemuExtDevicesInitPaths() where the log
path can be generated again.

Basically, tpm->data.emulator.storagepath is generated in
qemuExtTPMInitPaths() and its seclabels are restored properly,
and this commit move logfile onto the same level.

This means, that the log path doesn't have to be generated in
qemuExtDevicesStart() because it was already done in
qemuExtDevicesPrepareHost().

This change also renders @vmname argument of
qemuTPMEmulatorPrepareHost() unused and thus is removed.

Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1769196
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Ján Tomko <jtomko@redhat.com>
src/qemu/qemu_extdevice.c
src/qemu/qemu_tpm.c

index 8fe7ceaa10f3b1e8b3e003a28320934cbc270305..fdba22616cbd5970e383282daa29f4c30e977ace 100644 (file)
@@ -132,6 +132,9 @@ qemuExtDevicesPrepareHost(virQEMUDriverPtr driver,
     virDomainDefPtr def = vm->def;
     size_t i;
 
+    if (qemuExtDevicesInitPaths(driver, def) < 0)
+        return -1;
+
     if (def->ntpms > 0 &&
         qemuExtTPMPrepareHost(driver, def) < 0)
         return -1;
@@ -169,9 +172,6 @@ qemuExtDevicesStart(virQEMUDriverPtr driver,
     virDomainDefPtr def = vm->def;
     size_t i;
 
-    if (qemuExtDevicesInitPaths(driver, def) < 0)
-        return -1;
-
     for (i = 0; i < def->nvideos; i++) {
         virDomainVideoDefPtr video = def->videos[i];
 
index 71339b785ae16f88823722deee3862bed321522d..d9948164840271799b53d2d789b6f7841dc86c43 100644 (file)
@@ -196,11 +196,15 @@ qemuTPMCreateEmulatorSocket(const char *swtpmStateDir,
  * @tpm: TPM definition for an emulator type
  * @swtpmStorageDir: the general swtpm storage dir which is used as a base
  *                   directory for creating VM specific directories
+ * @logDir: directory where swtpm writes its logs into
+ * @vmname: name of the VM
  * @uuid: the UUID of the VM
  */
 static int
 qemuTPMEmulatorInitPaths(virDomainTPMDefPtr tpm,
                          const char *swtpmStorageDir,
+                         const char *logDir,
+                         const char *vmname,
                          const unsigned char *uuid)
 {
     char uuidstr[VIR_UUID_STRING_BUFLEN];
@@ -213,6 +217,11 @@ qemuTPMEmulatorInitPaths(virDomainTPMDefPtr tpm,
                                              tpm->version)))
         return -1;
 
+    if (!tpm->data.emulator.logfile) {
+        tpm->data.emulator.logfile = qemuTPMCreateEmulatorLogPath(logDir,
+                                                                  vmname);
+    }
+
     return 0;
 }
 
@@ -266,7 +275,6 @@ qemuTPMEmulatorGetPid(const char *swtpmStateDir,
  *
  * @tpm: tpm definition
  * @logDir: directory where swtpm writes its logs into
- * @vmname: name of the VM
  * @swtpm_user: uid to run the swtpm with
  * @swtpm_group: gid to run the swtpm with
  * @swtpmStateDir: directory for swtpm's persistent state
@@ -280,7 +288,6 @@ qemuTPMEmulatorGetPid(const char *swtpmStateDir,
 static int
 qemuTPMEmulatorPrepareHost(virDomainTPMDefPtr tpm,
                            const char *logDir,
-                           const char *vmname,
                            uid_t swtpm_user,
                            gid_t swtpm_group,
                            const char *swtpmStateDir,
@@ -299,10 +306,6 @@ qemuTPMEmulatorPrepareHost(virDomainTPMDefPtr tpm,
                      VIR_DIR_CREATE_ALLOW_EXIST) < 0)
         return -1;
 
-    /* create logfile name ... */
-    if (!tpm->data.emulator.logfile)
-        tpm->data.emulator.logfile = qemuTPMCreateEmulatorLogPath(logDir, vmname);
-
     if (!virFileExists(tpm->data.emulator.logfile) &&
         virFileTouch(tpm->data.emulator.logfile, 0644) < 0) {
         return -1;
@@ -702,7 +705,10 @@ qemuExtTPMInitPaths(virQEMUDriverPtr driver,
         if (def->tpms[i]->type != VIR_DOMAIN_TPM_TYPE_EMULATOR)
             continue;
 
-        return qemuTPMEmulatorInitPaths(def->tpms[i], cfg->swtpmStorageDir,
+        return qemuTPMEmulatorInitPaths(def->tpms[i],
+                                        cfg->swtpmStorageDir,
+                                        cfg->swtpmLogDir,
+                                        def->name,
                                         def->uuid);
     }
 
@@ -727,7 +733,7 @@ qemuExtTPMPrepareHost(virQEMUDriverPtr driver,
             return -1;
 
         return qemuTPMEmulatorPrepareHost(def->tpms[i], cfg->swtpmLogDir,
-                                          def->name, cfg->swtpm_user,
+                                          cfg->swtpm_user,
                                           cfg->swtpm_group,
                                           cfg->swtpmStateDir, cfg->user,
                                           shortName);