]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
qemu: add a DBus daemon helper unit
authorMarc-André Lureau <marcandre.lureau@redhat.com>
Tue, 25 Feb 2020 09:55:08 +0000 (10:55 +0100)
committerMichal Privoznik <mprivozn@redhat.com>
Tue, 24 Mar 2020 14:57:33 +0000 (15:57 +0100)
Add a unit to start & stop a private dbus-daemon.

The daemon is meant to be started on demand, and associated with a
QEMU process. It should be stopped when the QEMU process is stopped.

The current policy is permissive like a session bus. Stricter
policies can be added later, following recommendations from:
https://git.qemu.org/?p=qemu.git;a=blob;f=docs/interop/dbus.rst

Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
po/POTFILES.in
src/qemu/Makefile.inc.am
src/qemu/qemu_dbus.c [new file with mode: 0644]
src/qemu/qemu_dbus.h [new file with mode: 0644]
src/qemu/qemu_domain.h

index 2f21ae2172e29c95910b6722ac4ce09d6dda5707..6103d4ca4a0b185b2bafc884be8cbbb4042887f6 100644 (file)
 @SRCDIR@/src/qemu/qemu_checkpoint.c
 @SRCDIR@/src/qemu/qemu_command.c
 @SRCDIR@/src/qemu/qemu_conf.c
+@SRCDIR@/src/qemu/qemu_dbus.c
 @SRCDIR@/src/qemu/qemu_domain.c
 @SRCDIR@/src/qemu/qemu_domain_address.c
 @SRCDIR@/src/qemu/qemu_driver.c
index bd0b3cbbbbb32acc6bf43572fc81bd5598ec9839..51cd79879d7edd6652e3527947ce9876a7783740 100644 (file)
@@ -13,6 +13,8 @@ QEMU_DRIVER_SOURCES = \
        qemu/qemu_capabilities.h \
        qemu/qemu_command.c \
        qemu/qemu_command.h \
+       qemu/qemu_dbus.c \
+       qemu/qemu_dbus.h \
        qemu/qemu_domain.c \
        qemu/qemu_domain.h \
        qemu/qemu_domain_address.c \
diff --git a/src/qemu/qemu_dbus.c b/src/qemu/qemu_dbus.c
new file mode 100644 (file)
index 0000000..4826f77
--- /dev/null
@@ -0,0 +1,275 @@
+/*
+ * qemu_dbus.c: QEMU dbus daemon
+ *
+ * This library is free software; you can redistribute it and/or
+ * modify it under the terms of the GNU Lesser General Public
+ * License as published by the Free Software Foundation; either
+ * version 2.1 of the License, or (at your option) any later version.
+ *
+ * This library is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
+ * Lesser General Public License for more details.
+ *
+ * You should have received a copy of the GNU Lesser General Public
+ * License along with this library.  If not, see
+ * <http://www.gnu.org/licenses/>.
+ */
+
+#include <config.h>
+
+#include "qemu_extdevice.h"
+#include "qemu_dbus.h"
+#include "qemu_security.h"
+
+#include "viralloc.h"
+#include "virlog.h"
+#include "virstring.h"
+#include "virtime.h"
+#include "virpidfile.h"
+
+#define VIR_FROM_THIS VIR_FROM_NONE
+
+VIR_LOG_INIT("qemu.dbus");
+
+
+int
+qemuDBusPrepareHost(virQEMUDriverPtr driver)
+{
+    g_autoptr(virQEMUDriverConfig) cfg = virQEMUDriverGetConfig(driver);
+
+    return virDirCreate(cfg->dbusStateDir, 0770, cfg->user, cfg->group,
+                        VIR_DIR_CREATE_ALLOW_EXIST);
+}
+
+
+static char *
+qemuDBusCreatePidFilename(virQEMUDriverConfigPtr cfg,
+                          const char *shortName)
+{
+    g_autofree char *name = g_strdup_printf("%s-dbus", shortName);
+
+    return virPidFileBuildPath(cfg->dbusStateDir, name);
+}
+
+
+static char *
+qemuDBusCreateFilename(const char *stateDir,
+                       const char *shortName,
+                       const char *ext)
+{
+    g_autofree char *name = g_strdup_printf("%s-dbus", shortName);
+
+    return virFileBuildPath(stateDir, name,  ext);
+}
+
+
+static char *
+qemuDBusCreateSocketPath(virQEMUDriverConfigPtr cfg,
+                         const char *shortName)
+{
+    return qemuDBusCreateFilename(cfg->dbusStateDir, shortName, ".sock");
+}
+
+
+static char *
+qemuDBusCreateConfPath(virQEMUDriverConfigPtr cfg,
+                       const char *shortName)
+{
+    return qemuDBusCreateFilename(cfg->dbusStateDir, shortName, ".conf");
+}
+
+
+char *
+qemuDBusGetAddress(virQEMUDriverPtr driver,
+                   virDomainObjPtr vm)
+{
+    g_autoptr(virQEMUDriverConfig) cfg = virQEMUDriverGetConfig(driver);
+    g_autofree char *shortName = virDomainDefGetShortName(vm->def);
+    g_autofree char *path = NULL;
+
+    if (!shortName)
+        return NULL;
+
+    path = qemuDBusCreateSocketPath(cfg, shortName);
+
+    return g_strdup_printf("unix:path=%s", path);
+}
+
+
+static int
+qemuDBusWriteConfig(const char *filename, const char *path)
+{
+    virBuffer buf = VIR_BUFFER_INITIALIZER;
+    g_autofree char *config = NULL;
+
+    virBufferAddLit(&buf, "<!DOCTYPE busconfig PUBLIC \"-//freedesktop//DTD D-Bus Bus Configuration 1.0//EN\"\n");
+    virBufferAddLit(&buf, "  \"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd\">\n");
+    virBufferAddLit(&buf, "<busconfig>\n");
+    virBufferAdjustIndent(&buf, 2);
+
+    virBufferAddLit(&buf, "<type>org.libvirt.qemu</type>\n");
+    virBufferAsprintf(&buf, "<listen>unix:path=%s</listen>\n", path);
+    virBufferAddLit(&buf, "<auth>EXTERNAL</auth>\n");
+
+    virBufferAddLit(&buf, "<policy context='default'>\n");
+    virBufferAdjustIndent(&buf, 2);
+    virBufferAddLit(&buf, "<!-- Allow everything to be sent -->\n");
+    virBufferAddLit(&buf, "<allow send_destination='*' eavesdrop='true'/>\n");
+    virBufferAddLit(&buf, "<!-- Allow everything to be received -->\n");
+    virBufferAddLit(&buf, "<allow eavesdrop='true'/>\n");
+    virBufferAddLit(&buf, "<!-- Allow anyone to own anything -->\n");
+    virBufferAddLit(&buf, "<allow own='*'/>\n");
+    virBufferAdjustIndent(&buf, -2);
+    virBufferAddLit(&buf, "</policy>\n");
+
+    virBufferAddLit(&buf, "<include if_selinux_enabled='yes' selinux_root_relative='yes'>contexts/dbus_contexts</include>\n");
+
+    virBufferAdjustIndent(&buf, -2);
+    virBufferAddLit(&buf, "</busconfig>\n");
+
+    config = virBufferContentAndReset(&buf);
+
+    return virFileWriteStr(filename, config, 0600);
+}
+
+
+void
+qemuDBusStop(virQEMUDriverPtr driver,
+             virDomainObjPtr vm)
+{
+    g_autoptr(virQEMUDriverConfig) cfg = virQEMUDriverGetConfig(driver);
+    qemuDomainObjPrivatePtr priv = vm->privateData;
+    g_autofree char *shortName = NULL;
+    g_autofree char *pidfile = NULL;
+    g_autofree char *configfile = NULL;
+
+    if (!(shortName = virDomainDefGetShortName(vm->def)))
+        return;
+
+    pidfile = qemuDBusCreatePidFilename(cfg, shortName);
+    configfile = qemuDBusCreateConfPath(cfg, shortName);
+
+    if (virPidFileForceCleanupPath(pidfile) < 0) {
+        VIR_WARN("Unable to kill dbus-daemon process");
+    } else {
+        priv->dbusDaemonRunning = false;
+    }
+}
+
+
+int
+qemuDBusStart(virQEMUDriverPtr driver,
+              virDomainObjPtr vm)
+{
+    g_autoptr(virQEMUDriverConfig) cfg = virQEMUDriverGetConfig(driver);
+    qemuDomainObjPrivatePtr priv = vm->privateData;
+    g_autoptr(virCommand) cmd = NULL;
+    g_autofree char *shortName = NULL;
+    g_autofree char *pidfile = NULL;
+    g_autofree char *configfile = NULL;
+    g_autofree char *sockpath = NULL;
+    virTimeBackOffVar timebackoff;
+    const unsigned long long timeout = 500 * 1000; /* ms */
+    VIR_AUTOCLOSE errfd = -1;
+    int cmdret = 0;
+    int exitstatus = 0;
+    pid_t cpid = -1;
+    int ret = -1;
+
+    if (!virFileIsExecutable(cfg->dbusDaemonName)) {
+        virReportSystemError(errno,
+                             _("'%s' is not a suitable dbus-daemon"),
+                             cfg->dbusDaemonName);
+        return -1;
+    }
+
+    if (!(shortName = virDomainDefGetShortName(vm->def)))
+        return -1;
+
+    pidfile = qemuDBusCreatePidFilename(cfg, shortName);
+    configfile = qemuDBusCreateConfPath(cfg, shortName);
+    sockpath = qemuDBusCreateSocketPath(cfg, shortName);
+
+    if (qemuDBusWriteConfig(configfile, sockpath) < 0) {
+        virReportSystemError(errno, _("Failed to write '%s'"), configfile);
+        return -1;
+    }
+
+    if (qemuSecurityDomainSetPathLabel(driver, vm, configfile, false) < 0)
+        goto cleanup;
+
+    cmd = virCommandNew(cfg->dbusDaemonName);
+    virCommandClearCaps(cmd);
+    virCommandSetPidFile(cmd, pidfile);
+    virCommandSetErrorFD(cmd, &errfd);
+    virCommandDaemonize(cmd);
+    virCommandAddArgFormat(cmd, "--config-file=%s", configfile);
+
+    if (qemuSecurityCommandRun(driver, vm, cmd, -1, -1,
+                               &exitstatus, &cmdret) < 0)
+        goto cleanup;
+
+    if (cmdret < 0 || exitstatus != 0) {
+        virReportError(VIR_ERR_INTERNAL_ERROR,
+                       _("Could not start dbus-daemon. exitstatus: %d"), exitstatus);
+        goto cleanup;
+    }
+
+    if (virPidFileReadPath(pidfile, &cpid) < 0) {
+        virReportError(VIR_ERR_INTERNAL_ERROR,
+                       _("dbus-daemon %s didn't show up"),
+                       cfg->dbusDaemonName);
+        goto cleanup;
+    }
+
+    if (virTimeBackOffStart(&timebackoff, 1, timeout) < 0)
+        goto cleanup;
+    while (virTimeBackOffWait(&timebackoff)) {
+        char errbuf[1024] = { 0 };
+
+        if (virFileExists(sockpath))
+            break;
+
+        if (virProcessKill(cpid, 0) == 0)
+            continue;
+
+        if (saferead(errfd, errbuf, sizeof(errbuf) - 1) < 0) {
+            virReportSystemError(errno,
+                                 _("dbus-daemon %s died unexpectedly"),
+                                 cfg->dbusDaemonName);
+        } else {
+            virReportError(VIR_ERR_OPERATION_FAILED,
+                           _("dbus-daemon died and reported: %s"), errbuf);
+        }
+
+        goto cleanup;
+    }
+
+    if (!virFileExists(sockpath)) {
+        virReportError(VIR_ERR_OPERATION_TIMEOUT,
+                       _("DBus daemon %s didn't show up"),
+                       cfg->dbusDaemonName);
+        goto cleanup;
+    }
+
+    if (priv->cgroup &&
+        virCgroupAddProcess(priv->cgroup, cpid) < 0)
+        goto cleanup;
+
+    if (qemuSecurityDomainSetPathLabel(driver, vm, sockpath, false) < 0)
+        goto cleanup;
+
+    priv->dbusDaemonRunning = true;
+    ret = 0;
+ cleanup:
+    if (ret < 0) {
+        virCommandAbort(cmd);
+        if (cpid >= 0)
+            virProcessKillPainfully(cpid, true);
+        unlink(pidfile);
+        unlink(configfile);
+        unlink(sockpath);
+    }
+    return ret;
+}
diff --git a/src/qemu/qemu_dbus.h b/src/qemu/qemu_dbus.h
new file mode 100644 (file)
index 0000000..d6cb1bc
--- /dev/null
@@ -0,0 +1,33 @@
+/*
+ * qemu_dbus.h: QEMU dbus daemon
+ *
+ * This library is free software; you can redistribute it and/or
+ * modify it under the terms of the GNU Lesser General Public
+ * License as published by the Free Software Foundation; either
+ * version 2.1 of the License, or (at your option) any later version.
+ *
+ * This library is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
+ * Lesser General Public License for more details.
+ *
+ * You should have received a copy of the GNU Lesser General Public
+ * License along with this library.  If not, see
+ * <http://www.gnu.org/licenses/>.
+ */
+
+#pragma once
+
+#include "qemu_conf.h"
+#include "qemu_domain.h"
+
+int qemuDBusPrepareHost(virQEMUDriverPtr driver);
+
+char *qemuDBusGetAddress(virQEMUDriverPtr driver,
+                         virDomainObjPtr vm);
+
+int qemuDBusStart(virQEMUDriverPtr driver,
+                  virDomainObjPtr vm);
+
+void qemuDBusStop(virQEMUDriverPtr driver,
+                  virDomainObjPtr vm);
index bcc5caa067bcc0ae9721a6dfd3e2a2b1cb7d6a17..c99a41807e42b1771631c34c3487dc47402a92e4 100644 (file)
@@ -421,6 +421,8 @@ struct _qemuDomainObjPrivate {
 
     /* running backup job */
     virDomainBackupDefPtr backup;
+
+    bool dbusDaemonRunning;
 };
 
 #define QEMU_DOMAIN_PRIVATE(vm) \