]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
nwfilter: acquire a pidfile in the driver root directory
authorDaniel P. Berrangé <berrange@redhat.com>
Thu, 23 May 2019 10:34:08 +0000 (11:34 +0100)
committerDaniel P. Berrangé <berrange@redhat.com>
Thu, 11 Jul 2019 11:46:20 +0000 (12:46 +0100)
When we allow multiple instances of the driver for the same user
account, using a separate root directory, we need to ensure mutual
exclusion. Use a pidfile to guarantee this.

In privileged libvirtd this ends up locking

   /var/run/libvirt/nwfilter/driver.pid

In unprivileged libvirtd this ends up locking

  /run/user/$UID/libvirt/nwfilter/run/driver.pid

NB, the latter can vary depending on $XDG_RUNTIME_DIR

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
src/conf/virnwfilterobj.h
src/nwfilter/nwfilter_driver.c

index bdf5c51fe2d4b34fd6ae6f384dac3498a55d483e..a6bdfb3864858c0ac47256851b4bfab0ede05f9b 100644 (file)
@@ -36,10 +36,14 @@ struct _virNWFilterDriverState {
     virMutex lock;
     bool privileged;
 
+    /* pid file FD, ensures two copies of the driver can't use the same root */
+    int lockFD;
+
     virNWFilterObjListPtr nwfilters;
 
     virNWFilterBindingObjListPtr bindings;
 
+    char *stateDir;
     char *configDir;
     char *bindingDir;
 };
index fdfc6f48fa39690e7e32b4207fdc21f7cdf3ad1a..43561241f63dfbad54c14c29f31e028bacf27151 100644 (file)
@@ -38,6 +38,7 @@
 #include "nwfilter_gentech_driver.h"
 #include "configmake.h"
 #include "virfile.h"
+#include "virpidfile.h"
 #include "virstring.h"
 #include "viraccessapicheck.h"
 
@@ -188,6 +189,7 @@ nwfilterStateInitialize(bool privileged,
     if (VIR_ALLOC(driver) < 0)
         return -1;
 
+    driver->lockFD = -1;
     if (virMutexInit(&driver->lock) < 0)
         goto err_free_driverstate;
 
@@ -203,6 +205,19 @@ nwfilterStateInitialize(bool privileged,
 
     nwfilterDriverLock();
 
+    if (VIR_STRDUP(driver->stateDir, LOCALSTATEDIR "/run/libvirt/nwfilter") < 0)
+        goto error;
+
+    if (virFileMakePathWithMode(driver->stateDir, S_IRWXU) < 0) {
+        virReportSystemError(errno, _("cannot create state directory '%s'"),
+                             driver->stateDir);
+        goto error;
+    }
+
+    if ((driver->lockFD =
+         virPidFileAcquire(driver->stateDir, "driver", true, getpid())) < 0)
+        goto error;
+
     if (virNWFilterIPAddrMapInit() < 0)
         goto err_free_driverstate;
     if (virNWFilterLearnInit() < 0)
@@ -346,6 +361,10 @@ nwfilterStateCleanup(void)
 
         nwfilterDriverRemoveDBusMatches();
 
+        if (driver->lockFD != -1)
+            virPidFileRelease(driver->stateDir, "driver", driver->lockFD);
+
+        VIR_FREE(driver->stateDir);
         VIR_FREE(driver->configDir);
         VIR_FREE(driver->bindingDir);
         nwfilterDriverUnlock();