xref: /openbmc/qemu/qga/main.c (revision f944890dfd4222f091cea8680281e0bf7114f721)
1 /*
2  * QEMU Guest Agent
3  *
4  * Copyright IBM Corp. 2011
5  *
6  * Authors:
7  *  Adam Litke        <aglitke@linux.vnet.ibm.com>
8  *  Michael Roth      <mdroth@linux.vnet.ibm.com>
9  *
10  * This work is licensed under the terms of the GNU GPL, version 2 or later.
11  * See the COPYING file in the top-level directory.
12  */
13 
14 #include "qemu/osdep.h"
15 #include <getopt.h>
16 #include <glib/gstdio.h>
17 #ifndef _WIN32
18 #include <syslog.h>
19 #include <sys/wait.h>
20 #endif
21 #include "qemu/help-texts.h"
22 #include "qapi/qmp/json-parser.h"
23 #include "qapi/qmp/qdict.h"
24 #include "qapi/qmp/qjson.h"
25 #include "guest-agent-core.h"
26 #include "qga-qapi-init-commands.h"
27 #include "qapi/error.h"
28 #include "channel.h"
29 #include "qemu/cutils.h"
30 #include "qemu/help_option.h"
31 #include "qemu/sockets.h"
32 #include "qemu/systemd.h"
33 #include "qemu-version.h"
34 #ifdef _WIN32
35 #include <dbt.h>
36 #include "qga/service-win32.h"
37 #include "qga/vss-win32.h"
38 #endif
39 #include "commands-common.h"
40 
41 #ifndef _WIN32
42 #ifdef CONFIG_BSD
43 #define QGA_VIRTIO_PATH_DEFAULT "/dev/vtcon/org.qemu.guest_agent.0"
44 #else /* CONFIG_BSD */
45 #define QGA_VIRTIO_PATH_DEFAULT "/dev/virtio-ports/org.qemu.guest_agent.0"
46 #endif /* CONFIG_BSD */
47 #define QGA_SERIAL_PATH_DEFAULT "/dev/ttyS0"
48 #define QGA_STATE_RELATIVE_DIR  "run"
49 #else
50 #define QGA_VIRTIO_PATH_DEFAULT "\\\\.\\Global\\org.qemu.guest_agent.0"
51 #define QGA_STATE_RELATIVE_DIR  "qemu-ga"
52 #define QGA_SERIAL_PATH_DEFAULT "COM1"
53 #endif
54 #ifdef CONFIG_FSFREEZE
55 #define QGA_FSFREEZE_HOOK_DEFAULT CONFIG_QEMU_CONFDIR "/fsfreeze-hook"
56 #endif
57 #define QGA_SENTINEL_BYTE 0xFF
58 #define QGA_CONF_DEFAULT CONFIG_QEMU_CONFDIR G_DIR_SEPARATOR_S "qemu-ga.conf"
59 #define QGA_RETRY_INTERVAL 5
60 
61 static struct {
62     const char *state_dir;
63     const char *pidfile;
64 } dfl_pathnames;
65 
66 typedef struct GAPersistentState {
67 #define QGA_PSTATE_DEFAULT_FD_COUNTER 1000
68     int64_t fd_counter;
69 } GAPersistentState;
70 
71 typedef struct GAConfig GAConfig;
72 
73 struct GAState {
74     JSONMessageParser parser;
75     GMainLoop *main_loop;
76     GAChannel *channel;
77     bool virtio; /* fastpath to check for virtio to deal with poll() quirks */
78     GACommandState *command_state;
79     GLogLevelFlags log_level;
80     FILE *log_file;
81     bool logging_enabled;
82 #ifdef _WIN32
83     GAService service;
84     HANDLE wakeup_event;
85     HANDLE event_log;
86 #endif
87     bool delimit_response;
88     bool frozen;
89     GList *blockedrpcs;
90     GList *allowedrpcs;
91     char *state_filepath_isfrozen;
92     struct {
93         const char *log_filepath;
94         const char *pid_filepath;
95     } deferred_options;
96 #ifdef CONFIG_FSFREEZE
97     const char *fsfreeze_hook;
98 #endif
99     gchar *pstate_filepath;
100     GAPersistentState pstate;
101     GAConfig *config;
102     int socket_activation;
103     bool force_exit;
104 };
105 
106 struct GAState *ga_state;
107 QmpCommandList ga_commands;
108 
109 /* commands that are safe to issue while filesystems are frozen */
110 static const char *ga_freeze_allowlist[] = {
111     "guest-ping",
112     "guest-info",
113     "guest-sync",
114     "guest-sync-delimited",
115     "guest-fsfreeze-status",
116     "guest-fsfreeze-thaw",
117     NULL
118 };
119 
120 #ifdef _WIN32
121 DWORD WINAPI service_ctrl_handler(DWORD ctrl, DWORD type, LPVOID data,
122                                   LPVOID ctx);
123 DWORD WINAPI handle_serial_device_events(DWORD type, LPVOID data);
124 VOID WINAPI service_main(DWORD argc, TCHAR *argv[]);
125 #endif
126 static int run_agent(GAState *s);
127 static void stop_agent(GAState *s, bool requested);
128 
129 static void
130 init_dfl_pathnames(void)
131 {
132     g_autofree char *state = qemu_get_local_state_dir();
133 
134     g_assert(dfl_pathnames.state_dir == NULL);
135     g_assert(dfl_pathnames.pidfile == NULL);
136     dfl_pathnames.state_dir = g_build_filename(state, QGA_STATE_RELATIVE_DIR, NULL);
137     dfl_pathnames.pidfile = g_build_filename(state, QGA_STATE_RELATIVE_DIR, "qemu-ga.pid", NULL);
138 }
139 
140 static void quit_handler(int sig)
141 {
142     /* if we're frozen, don't exit unless we're absolutely forced to,
143      * because it's basically impossible for graceful exit to complete
144      * unless all log/pid files are on unfreezable filesystems. there's
145      * also a very likely chance killing the agent before unfreezing
146      * the filesystems is a mistake (or will be viewed as one later).
147      * On Windows the freeze interval is limited to 10 seconds, so
148      * we should quit, but first we should wait for the timeout, thaw
149      * the filesystem and quit.
150      */
151     if (ga_is_frozen(ga_state)) {
152 #ifdef _WIN32
153         int i = 0;
154         Error *err = NULL;
155         HANDLE hEventTimeout;
156 
157         g_debug("Thawing filesystems before exiting");
158 
159         hEventTimeout = OpenEvent(EVENT_ALL_ACCESS, FALSE, EVENT_NAME_TIMEOUT);
160         if (hEventTimeout) {
161             WaitForSingleObject(hEventTimeout, 0);
162             CloseHandle(hEventTimeout);
163         }
164         qga_vss_fsfreeze(&i, false, NULL, &err);
165         if (err) {
166             g_debug("Error unfreezing filesystems prior to exiting: %s",
167                 error_get_pretty(err));
168             error_free(err);
169         }
170 #else
171         return;
172 #endif
173     }
174     g_debug("received signal num %d, quitting", sig);
175 
176     stop_agent(ga_state, true);
177 }
178 
179 #ifndef _WIN32
180 static gboolean register_signal_handlers(void)
181 {
182     struct sigaction sigact;
183     int ret;
184 
185     memset(&sigact, 0, sizeof(struct sigaction));
186     sigact.sa_handler = quit_handler;
187 
188     ret = sigaction(SIGINT, &sigact, NULL);
189     if (ret == -1) {
190         g_error("error configuring signal handler: %s", strerror(errno));
191     }
192     ret = sigaction(SIGTERM, &sigact, NULL);
193     if (ret == -1) {
194         g_error("error configuring signal handler: %s", strerror(errno));
195     }
196 
197     sigact.sa_handler = SIG_IGN;
198     if (sigaction(SIGPIPE, &sigact, NULL) != 0) {
199         g_error("error configuring SIGPIPE signal handler: %s",
200                 strerror(errno));
201     }
202 
203     return true;
204 }
205 
206 /* TODO: use this in place of all post-fork() fclose(std*) callers */
207 void reopen_fd_to_null(int fd)
208 {
209     int nullfd;
210 
211     nullfd = open("/dev/null", O_RDWR);
212     if (nullfd < 0) {
213         return;
214     }
215 
216     dup2(nullfd, fd);
217 
218     if (nullfd != fd) {
219         close(nullfd);
220     }
221 }
222 #endif
223 
224 static void usage(const char *cmd)
225 {
226 #ifdef CONFIG_FSFREEZE
227     g_autofree char *fsfreeze_hook = get_relocated_path(QGA_FSFREEZE_HOOK_DEFAULT);
228 #endif
229 
230     printf(
231 "Usage: %s [-m <method> -p <path>] [<options>]\n"
232 "QEMU Guest Agent " QEMU_FULL_VERSION "\n"
233 QEMU_COPYRIGHT "\n"
234 "\n"
235 "  -m, --method      transport method: one of unix-listen, virtio-serial,\n"
236 "                    isa-serial, or vsock-listen (virtio-serial is the default)\n"
237 "  -p, --path        device/socket path (the default for virtio-serial is:\n"
238 "                    %s,\n"
239 "                    the default for isa-serial is:\n"
240 "                    %s).\n"
241 "                    Socket addresses for vsock-listen are written as\n"
242 "                    <cid>:<port>.\n"
243 "  -l, --logfile     set logfile path, logs to stderr by default\n"
244 "  -f, --pidfile     specify pidfile (default is %s)\n"
245 #ifdef CONFIG_FSFREEZE
246 "  -F, --fsfreeze-hook\n"
247 "                    enable fsfreeze hook. Accepts an optional argument that\n"
248 "                    specifies script to run on freeze/thaw. Script will be\n"
249 "                    called with 'freeze'/'thaw' arguments accordingly.\n"
250 "                    (default is %s)\n"
251 "                    If using -F with an argument, do not follow -F with a\n"
252 "                    space.\n"
253 "                    (for example: -F/var/run/fsfreezehook.sh)\n"
254 #endif
255 "  -t, --statedir    specify dir to store state information (absolute paths\n"
256 "                    only, default is %s)\n"
257 "  -v, --verbose     log extra debugging information\n"
258 "  -V, --version     print version information and exit\n"
259 "  -d, --daemonize   become a daemon\n"
260 #ifdef _WIN32
261 "  -s, --service     service commands: install, uninstall, vss-install, vss-uninstall\n"
262 #endif
263 "  -b, --block-rpcs  comma-separated list of RPCs to disable (no spaces,\n"
264 "                    use \"--block-rpcs=help\" to list available RPCs)\n"
265 "  -a, --allow-rpcs  comma-separated list of RPCs to enable (no spaces,\n"
266 "                    use \"--allow-rpcs=help\" to list available RPCs)\n"
267 "  -D, --dump-conf   dump a qemu-ga config file based on current config\n"
268 "                    options / command-line parameters to stdout\n"
269 "  -r, --retry-path  attempt re-opening path if it's unavailable or closed\n"
270 "                    due to an error which may be recoverable in the future\n"
271 "                    (virtio-serial driver re-install, serial device hot\n"
272 "                    plug/unplug, etc.)\n"
273 "  -h, --help        display this help and exit\n"
274 "\n"
275 QEMU_HELP_BOTTOM "\n"
276     , cmd, QGA_VIRTIO_PATH_DEFAULT, QGA_SERIAL_PATH_DEFAULT,
277     dfl_pathnames.pidfile,
278 #ifdef CONFIG_FSFREEZE
279     fsfreeze_hook,
280 #endif
281     dfl_pathnames.state_dir);
282 }
283 
284 static const char *ga_log_level_str(GLogLevelFlags level)
285 {
286     switch (level & G_LOG_LEVEL_MASK) {
287     case G_LOG_LEVEL_ERROR:
288         return "error";
289     case G_LOG_LEVEL_CRITICAL:
290         return "critical";
291     case G_LOG_LEVEL_WARNING:
292         return "warning";
293     case G_LOG_LEVEL_MESSAGE:
294         return "message";
295     case G_LOG_LEVEL_INFO:
296         return "info";
297     case G_LOG_LEVEL_DEBUG:
298         return "debug";
299     default:
300         return "user";
301     }
302 }
303 
304 bool ga_logging_enabled(GAState *s)
305 {
306     return s->logging_enabled;
307 }
308 
309 void ga_disable_logging(GAState *s)
310 {
311     s->logging_enabled = false;
312 }
313 
314 void ga_enable_logging(GAState *s)
315 {
316     s->logging_enabled = true;
317 }
318 
319 static int glib_log_level_to_system(int level)
320 {
321     switch (level) {
322 #ifndef _WIN32
323     case G_LOG_LEVEL_ERROR:
324         return LOG_ERR;
325     case G_LOG_LEVEL_CRITICAL:
326         return LOG_CRIT;
327     case G_LOG_LEVEL_WARNING:
328         return LOG_WARNING;
329     case G_LOG_LEVEL_MESSAGE:
330         return LOG_NOTICE;
331     case G_LOG_LEVEL_DEBUG:
332         return LOG_DEBUG;
333     case G_LOG_LEVEL_INFO:
334     default:
335         return LOG_INFO;
336 #else
337     case G_LOG_LEVEL_ERROR:
338     case G_LOG_LEVEL_CRITICAL:
339         return EVENTLOG_ERROR_TYPE;
340     case G_LOG_LEVEL_WARNING:
341         return EVENTLOG_WARNING_TYPE;
342     case G_LOG_LEVEL_MESSAGE:
343     case G_LOG_LEVEL_INFO:
344     case G_LOG_LEVEL_DEBUG:
345     default:
346         return EVENTLOG_INFORMATION_TYPE;
347 #endif
348     }
349 }
350 
351 static void ga_log(const gchar *domain, GLogLevelFlags level,
352                    const gchar *msg, gpointer opaque)
353 {
354     GAState *s = opaque;
355     const char *level_str = ga_log_level_str(level);
356 
357     if (!ga_logging_enabled(s)) {
358         return;
359     }
360 
361     level &= G_LOG_LEVEL_MASK;
362     if (g_strcmp0(domain, "syslog") == 0) {
363 #ifndef _WIN32
364         syslog(glib_log_level_to_system(level), "%s: %s", level_str, msg);
365 #else
366         ReportEvent(s->event_log, glib_log_level_to_system(level),
367                     0, 1, NULL, 1, 0, &msg, NULL);
368 #endif
369     } else if (level & s->log_level) {
370         g_autoptr(GDateTime) now = g_date_time_new_now_utc();
371         g_autofree char *nowstr = g_date_time_format(now, "%s.%f");
372         fprintf(s->log_file, "%s: %s: %s\n", nowstr, level_str, msg);
373         fflush(s->log_file);
374     }
375 }
376 
377 void ga_set_response_delimited(GAState *s)
378 {
379     s->delimit_response = true;
380 }
381 
382 static FILE *ga_open_logfile(const char *logfile)
383 {
384     FILE *f;
385 
386     f = fopen(logfile, "a");
387     if (!f) {
388         return NULL;
389     }
390 
391     qemu_set_cloexec(fileno(f));
392     return f;
393 }
394 
395 static gint ga_strcmp(gconstpointer str1, gconstpointer str2)
396 {
397     return strcmp(str1, str2);
398 }
399 
400 /* disable commands that aren't safe for fsfreeze */
401 static void ga_disable_not_allowed_freeze(const QmpCommand *cmd, void *opaque)
402 {
403     bool allowed = false;
404     int i = 0;
405     const char *name = qmp_command_name(cmd);
406 
407     while (ga_freeze_allowlist[i] != NULL) {
408         if (strcmp(name, ga_freeze_allowlist[i]) == 0) {
409             allowed = true;
410         }
411         i++;
412     }
413     if (!allowed) {
414         g_debug("disabling command: %s", name);
415         qmp_disable_command(&ga_commands, name, "the agent is in frozen state");
416     }
417 }
418 
419 /* [re-]enable all commands, except those explicitly blocked by user */
420 static void ga_enable_non_blocked(const QmpCommand *cmd, void *opaque)
421 {
422     GAState *s = opaque;
423     GList *blockedrpcs = s->blockedrpcs;
424     GList *allowedrpcs = s->allowedrpcs;
425     const char *name = qmp_command_name(cmd);
426 
427     if (g_list_find_custom(blockedrpcs, name, ga_strcmp) == NULL) {
428         if (qmp_command_is_enabled(cmd)) {
429             return;
430         }
431 
432         if (allowedrpcs &&
433             g_list_find_custom(allowedrpcs, name, ga_strcmp) == NULL) {
434             return;
435         }
436 
437         g_debug("enabling command: %s", name);
438         qmp_enable_command(&ga_commands, name);
439     }
440 }
441 
442 /* disable commands that aren't allowed */
443 static void ga_disable_not_allowed(const QmpCommand *cmd, void *opaque)
444 {
445     GList *allowedrpcs = opaque;
446     const char *name = qmp_command_name(cmd);
447 
448     if (g_list_find_custom(allowedrpcs, name, ga_strcmp) == NULL) {
449         g_debug("disabling command: %s", name);
450         qmp_disable_command(&ga_commands, name, "the command is not allowed");
451     }
452 }
453 
454 static bool ga_create_file(const char *path)
455 {
456     int fd = open(path, O_CREAT | O_WRONLY, S_IWUSR | S_IRUSR);
457     if (fd == -1) {
458         g_warning("unable to open/create file %s: %s", path, strerror(errno));
459         return false;
460     }
461     close(fd);
462     return true;
463 }
464 
465 static bool ga_delete_file(const char *path)
466 {
467     int ret = unlink(path);
468     if (ret == -1) {
469         g_warning("unable to delete file: %s: %s", path, strerror(errno));
470         return false;
471     }
472 
473     return true;
474 }
475 
476 bool ga_is_frozen(GAState *s)
477 {
478     return s->frozen;
479 }
480 
481 void ga_set_frozen(GAState *s)
482 {
483     if (ga_is_frozen(s)) {
484         return;
485     }
486     /* disable all forbidden (for frozen state) commands */
487     qmp_for_each_command(&ga_commands, ga_disable_not_allowed_freeze, NULL);
488     g_warning("disabling logging due to filesystem freeze");
489     ga_disable_logging(s);
490     s->frozen = true;
491     if (!ga_create_file(s->state_filepath_isfrozen)) {
492         g_warning("unable to create %s, fsfreeze may not function properly",
493                   s->state_filepath_isfrozen);
494     }
495 }
496 
497 void ga_unset_frozen(GAState *s)
498 {
499     if (!ga_is_frozen(s)) {
500         return;
501     }
502 
503     /* if we delayed creation/opening of pid/log files due to being
504      * in a frozen state at start up, do it now
505      */
506     if (s->deferred_options.log_filepath) {
507         s->log_file = ga_open_logfile(s->deferred_options.log_filepath);
508         if (!s->log_file) {
509             s->log_file = stderr;
510         }
511         s->deferred_options.log_filepath = NULL;
512     }
513     ga_enable_logging(s);
514     g_warning("logging re-enabled due to filesystem unfreeze");
515     if (s->deferred_options.pid_filepath) {
516         Error *err = NULL;
517 
518         if (!qemu_write_pidfile(s->deferred_options.pid_filepath, &err)) {
519             g_warning("%s", error_get_pretty(err));
520             error_free(err);
521         }
522         s->deferred_options.pid_filepath = NULL;
523     }
524 
525     /* enable all disabled, non-blocked and allowed commands */
526     qmp_for_each_command(&ga_commands, ga_enable_non_blocked, s);
527     s->frozen = false;
528     if (!ga_delete_file(s->state_filepath_isfrozen)) {
529         g_warning("unable to delete %s, fsfreeze may not function properly",
530                   s->state_filepath_isfrozen);
531     }
532 }
533 
534 #ifdef CONFIG_FSFREEZE
535 const char *ga_fsfreeze_hook(GAState *s)
536 {
537     return s->fsfreeze_hook;
538 }
539 #endif
540 
541 static void become_daemon(const char *pidfile)
542 {
543 #ifndef _WIN32
544     pid_t pid, sid;
545 
546     pid = fork();
547     if (pid < 0) {
548         exit(EXIT_FAILURE);
549     }
550     if (pid > 0) {
551         exit(EXIT_SUCCESS);
552     }
553 
554     if (pidfile) {
555         Error *err = NULL;
556 
557         if (!qemu_write_pidfile(pidfile, &err)) {
558             g_critical("%s", error_get_pretty(err));
559             error_free(err);
560             exit(EXIT_FAILURE);
561         }
562     }
563 
564     umask(S_IRWXG | S_IRWXO);
565     sid = setsid();
566     if (sid < 0) {
567         goto fail;
568     }
569     if ((chdir("/")) < 0) {
570         goto fail;
571     }
572 
573     reopen_fd_to_null(STDIN_FILENO);
574     reopen_fd_to_null(STDOUT_FILENO);
575     reopen_fd_to_null(STDERR_FILENO);
576     return;
577 
578 fail:
579     if (pidfile) {
580         unlink(pidfile);
581     }
582     g_critical("failed to daemonize");
583     exit(EXIT_FAILURE);
584 #endif
585 }
586 
587 static int send_response(GAState *s, const QDict *rsp)
588 {
589     GString *response;
590     GIOStatus status;
591 
592     g_assert(s->channel);
593 
594     if (!rsp) {
595         return 0;
596     }
597 
598     response = qobject_to_json(QOBJECT(rsp));
599     if (!response) {
600         return -EINVAL;
601     }
602 
603     if (s->delimit_response) {
604         s->delimit_response = false;
605         g_string_prepend_c(response, QGA_SENTINEL_BYTE);
606     }
607 
608     g_string_append_c(response, '\n');
609     status = ga_channel_write_all(s->channel, response->str, response->len);
610     g_string_free(response, true);
611     if (status != G_IO_STATUS_NORMAL) {
612         return -EIO;
613     }
614 
615     return 0;
616 }
617 
618 /* handle requests/control events coming in over the channel */
619 static void process_event(void *opaque, QObject *obj, Error *err)
620 {
621     GAState *s = opaque;
622     QDict *rsp;
623     int ret;
624 
625     g_debug("process_event: called");
626     assert(!obj != !err);
627     if (err) {
628         rsp = qmp_error_response(err);
629         goto end;
630     }
631 
632     g_debug("processing command");
633     rsp = qmp_dispatch(&ga_commands, obj, false, NULL);
634 
635 end:
636     ret = send_response(s, rsp);
637     if (ret < 0) {
638         g_warning("error sending error response: %s", strerror(-ret));
639     }
640     qobject_unref(rsp);
641     qobject_unref(obj);
642 }
643 
644 /* false return signals GAChannel to close the current client connection */
645 static gboolean channel_event_cb(GIOCondition condition, gpointer data)
646 {
647     GAState *s = data;
648     gchar buf[QGA_READ_COUNT_DEFAULT + 1];
649     gsize count;
650     GIOStatus status = ga_channel_read(s->channel, buf, QGA_READ_COUNT_DEFAULT, &count);
651     switch (status) {
652     case G_IO_STATUS_ERROR:
653         g_warning("error reading channel");
654         stop_agent(s, false);
655         return false;
656     case G_IO_STATUS_NORMAL:
657         buf[count] = 0;
658         g_debug("read data, count: %d, data: %s", (int)count, buf);
659         json_message_parser_feed(&s->parser, (char *)buf, (int)count);
660         break;
661     case G_IO_STATUS_EOF:
662         g_debug("received EOF");
663         if (!s->virtio) {
664             return false;
665         }
666         /* fall through */
667     case G_IO_STATUS_AGAIN:
668         /* virtio causes us to spin here when no process is attached to
669          * host-side chardev. sleep a bit to mitigate this
670          */
671         if (s->virtio) {
672             g_usleep(G_USEC_PER_SEC / 10);
673         }
674         return true;
675     default:
676         g_warning("unknown channel read status, closing");
677         return false;
678     }
679     return true;
680 }
681 
682 static gboolean channel_init(GAState *s, const gchar *method, const gchar *path,
683                              int listen_fd)
684 {
685     GAChannelMethod channel_method;
686 
687     if (strcmp(method, "virtio-serial") == 0) {
688         s->virtio = true; /* virtio requires special handling in some cases */
689         channel_method = GA_CHANNEL_VIRTIO_SERIAL;
690     } else if (strcmp(method, "isa-serial") == 0) {
691         channel_method = GA_CHANNEL_ISA_SERIAL;
692     } else if (strcmp(method, "unix-listen") == 0) {
693         channel_method = GA_CHANNEL_UNIX_LISTEN;
694     } else if (strcmp(method, "vsock-listen") == 0) {
695         channel_method = GA_CHANNEL_VSOCK_LISTEN;
696     } else {
697         g_critical("unsupported channel method/type: %s", method);
698         return false;
699     }
700 
701     s->channel = ga_channel_new(channel_method, path, listen_fd,
702                                 channel_event_cb, s);
703     if (!s->channel) {
704         g_critical("failed to create guest agent channel");
705         return false;
706     }
707 
708     return true;
709 }
710 
711 #ifdef _WIN32
712 DWORD WINAPI handle_serial_device_events(DWORD type, LPVOID data)
713 {
714     DWORD ret = NO_ERROR;
715     PDEV_BROADCAST_HDR broadcast_header = (PDEV_BROADCAST_HDR)data;
716 
717     if (broadcast_header->dbch_devicetype == DBT_DEVTYP_DEVICEINTERFACE) {
718         switch (type) {
719             /* Device inserted */
720         case DBT_DEVICEARRIVAL:
721             /* Start QEMU-ga's service */
722             if (!SetEvent(ga_state->wakeup_event)) {
723                 ret = GetLastError();
724             }
725             break;
726             /* Device removed */
727         case DBT_DEVICEQUERYREMOVE:
728         case DBT_DEVICEREMOVEPENDING:
729         case DBT_DEVICEREMOVECOMPLETE:
730             /* Stop QEMU-ga's service */
731             if (!ResetEvent(ga_state->wakeup_event)) {
732                 ret = GetLastError();
733             }
734             break;
735         default:
736             ret = ERROR_CALL_NOT_IMPLEMENTED;
737         }
738     }
739     return ret;
740 }
741 
742 DWORD WINAPI service_ctrl_handler(DWORD ctrl, DWORD type, LPVOID data,
743                                   LPVOID ctx)
744 {
745     DWORD ret = NO_ERROR;
746     GAService *service = &ga_state->service;
747 
748     switch (ctrl) {
749     case SERVICE_CONTROL_STOP:
750     case SERVICE_CONTROL_SHUTDOWN:
751         quit_handler(SIGTERM);
752         SetEvent(ga_state->wakeup_event);
753         service->status.dwCurrentState = SERVICE_STOP_PENDING;
754         SetServiceStatus(service->status_handle, &service->status);
755         break;
756     case SERVICE_CONTROL_DEVICEEVENT:
757         handle_serial_device_events(type, data);
758         break;
759 
760     default:
761         ret = ERROR_CALL_NOT_IMPLEMENTED;
762     }
763     return ret;
764 }
765 
766 VOID WINAPI service_main(DWORD argc, TCHAR *argv[])
767 {
768     GAService *service = &ga_state->service;
769 
770     service->status_handle = RegisterServiceCtrlHandlerEx(QGA_SERVICE_NAME,
771         service_ctrl_handler, NULL);
772 
773     if (service->status_handle == 0) {
774         g_critical("Failed to register extended requests function!\n");
775         return;
776     }
777 
778     service->status.dwServiceType = SERVICE_WIN32;
779     service->status.dwCurrentState = SERVICE_RUNNING;
780     service->status.dwControlsAccepted = SERVICE_ACCEPT_STOP | SERVICE_ACCEPT_SHUTDOWN;
781     service->status.dwWin32ExitCode = NO_ERROR;
782     service->status.dwServiceSpecificExitCode = NO_ERROR;
783     service->status.dwCheckPoint = 0;
784     service->status.dwWaitHint = 0;
785     DEV_BROADCAST_DEVICEINTERFACE notification_filter;
786     ZeroMemory(&notification_filter, sizeof(notification_filter));
787     notification_filter.dbcc_devicetype = DBT_DEVTYP_DEVICEINTERFACE;
788     notification_filter.dbcc_size = sizeof(DEV_BROADCAST_DEVICEINTERFACE);
789     notification_filter.dbcc_classguid = GUID_VIOSERIAL_PORT;
790 
791     service->device_notification_handle =
792         RegisterDeviceNotification(service->status_handle,
793             &notification_filter, DEVICE_NOTIFY_SERVICE_HANDLE);
794     if (!service->device_notification_handle) {
795         g_critical("Failed to register device notification handle!\n");
796         return;
797     }
798     SetServiceStatus(service->status_handle, &service->status);
799 
800     run_agent(ga_state);
801 
802     UnregisterDeviceNotification(service->device_notification_handle);
803     service->status.dwCurrentState = SERVICE_STOPPED;
804     SetServiceStatus(service->status_handle, &service->status);
805 }
806 #endif
807 
808 static void set_persistent_state_defaults(GAPersistentState *pstate)
809 {
810     g_assert(pstate);
811     pstate->fd_counter = QGA_PSTATE_DEFAULT_FD_COUNTER;
812 }
813 
814 static void persistent_state_from_keyfile(GAPersistentState *pstate,
815                                           GKeyFile *keyfile)
816 {
817     g_assert(pstate);
818     g_assert(keyfile);
819     /* if any fields are missing, either because the file was tampered with
820      * by agents of chaos, or because the field wasn't present at the time the
821      * file was created, the best we can ever do is start over with the default
822      * values. so load them now, and ignore any errors in accessing key-value
823      * pairs
824      */
825     set_persistent_state_defaults(pstate);
826 
827     if (g_key_file_has_key(keyfile, "global", "fd_counter", NULL)) {
828         pstate->fd_counter =
829             g_key_file_get_integer(keyfile, "global", "fd_counter", NULL);
830     }
831 }
832 
833 static void persistent_state_to_keyfile(const GAPersistentState *pstate,
834                                         GKeyFile *keyfile)
835 {
836     g_assert(pstate);
837     g_assert(keyfile);
838 
839     g_key_file_set_integer(keyfile, "global", "fd_counter", pstate->fd_counter);
840 }
841 
842 static gboolean write_persistent_state(const GAPersistentState *pstate,
843                                        const gchar *path)
844 {
845     GKeyFile *keyfile = g_key_file_new();
846     GError *gerr = NULL;
847     gboolean ret = true;
848     gchar *data = NULL;
849     gsize data_len;
850 
851     g_assert(pstate);
852 
853     persistent_state_to_keyfile(pstate, keyfile);
854     data = g_key_file_to_data(keyfile, &data_len, &gerr);
855     if (gerr) {
856         g_critical("failed to convert persistent state to string: %s",
857                    gerr->message);
858         ret = false;
859         goto out;
860     }
861 
862     g_file_set_contents(path, data, data_len, &gerr);
863     if (gerr) {
864         g_critical("failed to write persistent state to %s: %s",
865                     path, gerr->message);
866         ret = false;
867         goto out;
868     }
869 
870 out:
871     if (gerr) {
872         g_error_free(gerr);
873     }
874     if (keyfile) {
875         g_key_file_free(keyfile);
876     }
877     g_free(data);
878     return ret;
879 }
880 
881 static gboolean read_persistent_state(GAPersistentState *pstate,
882                                       const gchar *path, gboolean frozen)
883 {
884     GKeyFile *keyfile = NULL;
885     GError *gerr = NULL;
886     struct stat st;
887     gboolean ret = true;
888 
889     g_assert(pstate);
890 
891     if (stat(path, &st) == -1) {
892         /* it's okay if state file doesn't exist, but any other error
893          * indicates a permissions issue or some other misconfiguration
894          * that we likely won't be able to recover from.
895          */
896         if (errno != ENOENT) {
897             g_critical("unable to access state file at path %s: %s",
898                        path, strerror(errno));
899             ret = false;
900             goto out;
901         }
902 
903         /* file doesn't exist. initialize state to default values and
904          * attempt to save now. (we could wait till later when we have
905          * modified state we need to commit, but if there's a problem,
906          * such as a missing parent directory, we want to catch it now)
907          *
908          * there is a potential scenario where someone either managed to
909          * update the agent from a version that didn't use a key store
910          * while qemu-ga thought the filesystem was frozen, or
911          * deleted the key store prior to issuing a fsfreeze, prior
912          * to restarting the agent. in this case we go ahead and defer
913          * initial creation till we actually have modified state to
914          * write, otherwise fail to recover from freeze.
915          */
916         set_persistent_state_defaults(pstate);
917         if (!frozen) {
918             ret = write_persistent_state(pstate, path);
919             if (!ret) {
920                 g_critical("unable to create state file at path %s", path);
921                 ret = false;
922                 goto out;
923             }
924         }
925         ret = true;
926         goto out;
927     }
928 
929     keyfile = g_key_file_new();
930     g_key_file_load_from_file(keyfile, path, 0, &gerr);
931     if (gerr) {
932         g_critical("error loading persistent state from path: %s, %s",
933                    path, gerr->message);
934         ret = false;
935         goto out;
936     }
937 
938     persistent_state_from_keyfile(pstate, keyfile);
939 
940 out:
941     if (keyfile) {
942         g_key_file_free(keyfile);
943     }
944     if (gerr) {
945         g_error_free(gerr);
946     }
947 
948     return ret;
949 }
950 
951 int64_t ga_get_fd_handle(GAState *s, Error **errp)
952 {
953     int64_t handle;
954 
955     g_assert(s->pstate_filepath);
956     /*
957      * We block commands and avoid operations that potentially require
958      * writing to disk when we're in a frozen state. this includes opening
959      * new files, so we should never get here in that situation
960      */
961     g_assert(!ga_is_frozen(s));
962 
963     handle = s->pstate.fd_counter++;
964 
965     /* This should never happen on a reasonable timeframe, as guest-file-open
966      * would have to be issued 2^63 times */
967     if (s->pstate.fd_counter == INT64_MAX) {
968         abort();
969     }
970 
971     if (!write_persistent_state(&s->pstate, s->pstate_filepath)) {
972         error_setg(errp, "failed to commit persistent state to disk");
973         return -1;
974     }
975 
976     return handle;
977 }
978 
979 static void ga_print_cmd(const QmpCommand *cmd, void *opaque)
980 {
981     printf("%s\n", qmp_command_name(cmd));
982 }
983 
984 static GList *split_list(const gchar *str, const gchar *delim)
985 {
986     GList *list = NULL;
987     int i;
988     gchar **strv;
989 
990     strv = g_strsplit(str, delim, -1);
991     for (i = 0; strv[i]; i++) {
992         list = g_list_prepend(list, strv[i]);
993     }
994     g_free(strv);
995 
996     return list;
997 }
998 
999 struct GAConfig {
1000     char *channel_path;
1001     char *method;
1002     char *log_filepath;
1003     char *pid_filepath;
1004 #ifdef CONFIG_FSFREEZE
1005     char *fsfreeze_hook;
1006 #endif
1007     char *state_dir;
1008 #ifdef _WIN32
1009     const char *service;
1010 #endif
1011     gchar *bliststr; /* blockedrpcs may point to this string */
1012     gchar *aliststr; /* allowedrpcs may point to this string */
1013     GList *blockedrpcs;
1014     GList *allowedrpcs;
1015     int daemonize;
1016     GLogLevelFlags log_level;
1017     int dumpconf;
1018     bool retry_path;
1019 };
1020 
1021 static void config_load(GAConfig *config)
1022 {
1023     GError *gerr = NULL;
1024     GKeyFile *keyfile;
1025     g_autofree char *conf = g_strdup(g_getenv("QGA_CONF")) ?: get_relocated_path(QGA_CONF_DEFAULT);
1026     const gchar *blockrpcs_key = "block-rpcs";
1027 
1028     /* read system config */
1029     keyfile = g_key_file_new();
1030     if (!g_key_file_load_from_file(keyfile, conf, 0, &gerr)) {
1031         goto end;
1032     }
1033     if (g_key_file_has_key(keyfile, "general", "daemon", NULL)) {
1034         config->daemonize =
1035             g_key_file_get_boolean(keyfile, "general", "daemon", &gerr);
1036     }
1037     if (g_key_file_has_key(keyfile, "general", "method", NULL)) {
1038         config->method =
1039             g_key_file_get_string(keyfile, "general", "method", &gerr);
1040     }
1041     if (g_key_file_has_key(keyfile, "general", "path", NULL)) {
1042         config->channel_path =
1043             g_key_file_get_string(keyfile, "general", "path", &gerr);
1044     }
1045     if (g_key_file_has_key(keyfile, "general", "logfile", NULL)) {
1046         config->log_filepath =
1047             g_key_file_get_string(keyfile, "general", "logfile", &gerr);
1048     }
1049     if (g_key_file_has_key(keyfile, "general", "pidfile", NULL)) {
1050         config->pid_filepath =
1051             g_key_file_get_string(keyfile, "general", "pidfile", &gerr);
1052     }
1053 #ifdef CONFIG_FSFREEZE
1054     if (g_key_file_has_key(keyfile, "general", "fsfreeze-hook", NULL)) {
1055         config->fsfreeze_hook =
1056             g_key_file_get_string(keyfile,
1057                                   "general", "fsfreeze-hook", &gerr);
1058     }
1059 #endif
1060     if (g_key_file_has_key(keyfile, "general", "statedir", NULL)) {
1061         config->state_dir =
1062             g_key_file_get_string(keyfile, "general", "statedir", &gerr);
1063     }
1064     if (g_key_file_has_key(keyfile, "general", "verbose", NULL) &&
1065         g_key_file_get_boolean(keyfile, "general", "verbose", &gerr)) {
1066         /* enable all log levels */
1067         config->log_level = G_LOG_LEVEL_MASK;
1068     }
1069     if (g_key_file_has_key(keyfile, "general", "retry-path", NULL)) {
1070         config->retry_path =
1071             g_key_file_get_boolean(keyfile, "general", "retry-path", &gerr);
1072     }
1073 
1074     if (g_key_file_has_key(keyfile, "general", blockrpcs_key, NULL)) {
1075         config->bliststr =
1076             g_key_file_get_string(keyfile, "general", blockrpcs_key, &gerr);
1077         config->blockedrpcs = g_list_concat(config->blockedrpcs,
1078                                           split_list(config->bliststr, ","));
1079     }
1080     if (g_key_file_has_key(keyfile, "general", "allow-rpcs", NULL)) {
1081         config->aliststr =
1082             g_key_file_get_string(keyfile, "general", "allow-rpcs", &gerr);
1083         config->allowedrpcs = g_list_concat(config->allowedrpcs,
1084                                           split_list(config->aliststr, ","));
1085     }
1086 
1087     if (g_key_file_has_key(keyfile, "general", blockrpcs_key, NULL) &&
1088         g_key_file_has_key(keyfile, "general", "allow-rpcs", NULL)) {
1089         g_critical("wrong config, using 'block-rpcs' and 'allow-rpcs' keys at"
1090                    " the same time is not allowed");
1091         exit(EXIT_FAILURE);
1092     }
1093 
1094 end:
1095     g_key_file_free(keyfile);
1096     if (gerr &&
1097         !(gerr->domain == G_FILE_ERROR && gerr->code == G_FILE_ERROR_NOENT)) {
1098         g_critical("error loading configuration from path: %s, %s",
1099                    conf, gerr->message);
1100         exit(EXIT_FAILURE);
1101     }
1102     g_clear_error(&gerr);
1103 }
1104 
1105 static gchar *list_join(GList *list, const gchar separator)
1106 {
1107     GString *str = g_string_new("");
1108 
1109     while (list) {
1110         str = g_string_append(str, (gchar *)list->data);
1111         list = g_list_next(list);
1112         if (list) {
1113             str = g_string_append_c(str, separator);
1114         }
1115     }
1116 
1117     return g_string_free(str, FALSE);
1118 }
1119 
1120 static void config_dump(GAConfig *config)
1121 {
1122     GError *error = NULL;
1123     GKeyFile *keyfile;
1124     gchar *tmp;
1125 
1126     keyfile = g_key_file_new();
1127     g_assert(keyfile);
1128 
1129     g_key_file_set_boolean(keyfile, "general", "daemon", config->daemonize);
1130     g_key_file_set_string(keyfile, "general", "method", config->method);
1131     if (config->channel_path) {
1132         g_key_file_set_string(keyfile, "general", "path", config->channel_path);
1133     }
1134     if (config->log_filepath) {
1135         g_key_file_set_string(keyfile, "general", "logfile",
1136                               config->log_filepath);
1137     }
1138     g_key_file_set_string(keyfile, "general", "pidfile", config->pid_filepath);
1139 #ifdef CONFIG_FSFREEZE
1140     if (config->fsfreeze_hook) {
1141         g_key_file_set_string(keyfile, "general", "fsfreeze-hook",
1142                               config->fsfreeze_hook);
1143     }
1144 #endif
1145     g_key_file_set_string(keyfile, "general", "statedir", config->state_dir);
1146     g_key_file_set_boolean(keyfile, "general", "verbose",
1147                            config->log_level == G_LOG_LEVEL_MASK);
1148     g_key_file_set_boolean(keyfile, "general", "retry-path",
1149                            config->retry_path);
1150     tmp = list_join(config->blockedrpcs, ',');
1151     g_key_file_set_string(keyfile, "general", "block-rpcs", tmp);
1152     g_free(tmp);
1153     tmp = list_join(config->allowedrpcs, ',');
1154     g_key_file_set_string(keyfile, "general", "allow-rpcs", tmp);
1155     g_free(tmp);
1156 
1157     tmp = g_key_file_to_data(keyfile, NULL, &error);
1158     if (error) {
1159         g_critical("Failed to dump keyfile: %s", error->message);
1160         g_clear_error(&error);
1161     } else {
1162         printf("%s", tmp);
1163     }
1164 
1165     g_free(tmp);
1166     g_key_file_free(keyfile);
1167 }
1168 
1169 static void config_parse(GAConfig *config, int argc, char **argv)
1170 {
1171     const char *sopt = "hVvdm:p:l:f:F::b:a:s:t:Dr";
1172     int opt_ind = 0, ch;
1173     bool block_rpcs = false, allow_rpcs = false;
1174     const struct option lopt[] = {
1175         { "help", 0, NULL, 'h' },
1176         { "version", 0, NULL, 'V' },
1177         { "dump-conf", 0, NULL, 'D' },
1178         { "logfile", 1, NULL, 'l' },
1179         { "pidfile", 1, NULL, 'f' },
1180 #ifdef CONFIG_FSFREEZE
1181         { "fsfreeze-hook", 2, NULL, 'F' },
1182 #endif
1183         { "verbose", 0, NULL, 'v' },
1184         { "method", 1, NULL, 'm' },
1185         { "path", 1, NULL, 'p' },
1186         { "daemonize", 0, NULL, 'd' },
1187         { "block-rpcs", 1, NULL, 'b' },
1188         { "allow-rpcs", 1, NULL, 'a' },
1189 #ifdef _WIN32
1190         { "service", 1, NULL, 's' },
1191 #endif
1192         { "statedir", 1, NULL, 't' },
1193         { "retry-path", 0, NULL, 'r' },
1194         { NULL, 0, NULL, 0 }
1195     };
1196 
1197     while ((ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1) {
1198         switch (ch) {
1199         case 'm':
1200             g_free(config->method);
1201             config->method = g_strdup(optarg);
1202             break;
1203         case 'p':
1204             g_free(config->channel_path);
1205             config->channel_path = g_strdup(optarg);
1206             break;
1207         case 'l':
1208             g_free(config->log_filepath);
1209             config->log_filepath = g_strdup(optarg);
1210             break;
1211         case 'f':
1212             g_free(config->pid_filepath);
1213             config->pid_filepath = g_strdup(optarg);
1214             break;
1215 #ifdef CONFIG_FSFREEZE
1216         case 'F':
1217             g_free(config->fsfreeze_hook);
1218             config->fsfreeze_hook = optarg ? g_strdup(optarg) : get_relocated_path(QGA_FSFREEZE_HOOK_DEFAULT);
1219             break;
1220 #endif
1221         case 't':
1222             g_free(config->state_dir);
1223             config->state_dir = g_strdup(optarg);
1224             break;
1225         case 'v':
1226             /* enable all log levels */
1227             config->log_level = G_LOG_LEVEL_MASK;
1228             break;
1229         case 'V':
1230             printf("QEMU Guest Agent %s\n", QEMU_VERSION);
1231             exit(EXIT_SUCCESS);
1232         case 'd':
1233             config->daemonize = 1;
1234             break;
1235         case 'D':
1236             config->dumpconf = 1;
1237             break;
1238         case 'r':
1239             config->retry_path = true;
1240             break;
1241         case 'b': {
1242             if (is_help_option(optarg)) {
1243                 qmp_for_each_command(&ga_commands, ga_print_cmd, NULL);
1244                 exit(EXIT_SUCCESS);
1245             }
1246             config->blockedrpcs = g_list_concat(config->blockedrpcs,
1247                                                 split_list(optarg, ","));
1248             block_rpcs = true;
1249             break;
1250         }
1251         case 'a': {
1252             if (is_help_option(optarg)) {
1253                 qmp_for_each_command(&ga_commands, ga_print_cmd, NULL);
1254                 exit(EXIT_SUCCESS);
1255             }
1256             config->allowedrpcs = g_list_concat(config->allowedrpcs,
1257                                                 split_list(optarg, ","));
1258             allow_rpcs = true;
1259             break;
1260         }
1261 #ifdef _WIN32
1262         case 's':
1263             config->service = optarg;
1264             if (strcmp(config->service, "install") == 0) {
1265                 if (ga_install_vss_provider()) {
1266                     exit(EXIT_FAILURE);
1267                 }
1268                 if (ga_install_service(config->channel_path,
1269                                        config->log_filepath, config->state_dir)) {
1270                     exit(EXIT_FAILURE);
1271                 }
1272                 exit(EXIT_SUCCESS);
1273             } else if (strcmp(config->service, "uninstall") == 0) {
1274                 ga_uninstall_vss_provider();
1275                 exit(ga_uninstall_service());
1276             } else if (strcmp(config->service, "vss-install") == 0) {
1277                 if (ga_install_vss_provider()) {
1278                     exit(EXIT_FAILURE);
1279                 }
1280                 exit(EXIT_SUCCESS);
1281             } else if (strcmp(config->service, "vss-uninstall") == 0) {
1282                 ga_uninstall_vss_provider();
1283                 exit(EXIT_SUCCESS);
1284             } else {
1285                 printf("Unknown service command.\n");
1286                 exit(EXIT_FAILURE);
1287             }
1288             break;
1289 #endif
1290         case 'h':
1291             usage(argv[0]);
1292             exit(EXIT_SUCCESS);
1293         case '?':
1294             g_print("Unknown option, try '%s --help' for more information.\n",
1295                     argv[0]);
1296             exit(EXIT_FAILURE);
1297         }
1298     }
1299 
1300     if (block_rpcs && allow_rpcs) {
1301         g_critical("wrong commandline, using --block-rpcs and --allow-rpcs at the"
1302                    " same time is not allowed");
1303         exit(EXIT_FAILURE);
1304     }
1305 }
1306 
1307 static void config_free(GAConfig *config)
1308 {
1309     g_free(config->method);
1310     g_free(config->log_filepath);
1311     g_free(config->pid_filepath);
1312     g_free(config->state_dir);
1313     g_free(config->channel_path);
1314     g_free(config->bliststr);
1315     g_free(config->aliststr);
1316 #ifdef CONFIG_FSFREEZE
1317     g_free(config->fsfreeze_hook);
1318 #endif
1319     g_list_free_full(config->blockedrpcs, g_free);
1320     g_list_free_full(config->allowedrpcs, g_free);
1321     g_free(config);
1322 }
1323 
1324 static bool check_is_frozen(GAState *s)
1325 {
1326 #ifndef _WIN32
1327     /* check if a previous instance of qemu-ga exited with filesystems' state
1328      * marked as frozen. this could be a stale value (a non-qemu-ga process
1329      * or reboot may have since unfrozen them), but better to require an
1330      * unneeded unfreeze than to risk hanging on start-up
1331      */
1332     struct stat st;
1333     if (stat(s->state_filepath_isfrozen, &st) == -1) {
1334         /* it's okay if the file doesn't exist, but if we can't access for
1335          * some other reason, such as permissions, there's a configuration
1336          * that needs to be addressed. so just bail now before we get into
1337          * more trouble later
1338          */
1339         if (errno != ENOENT) {
1340             g_critical("unable to access state file at path %s: %s",
1341                        s->state_filepath_isfrozen, strerror(errno));
1342             return EXIT_FAILURE;
1343         }
1344     } else {
1345         g_warning("previous instance appears to have exited with frozen"
1346                   " filesystems. deferring logging/pidfile creation and"
1347                   " disabling non-fsfreeze-safe commands until"
1348                   " guest-fsfreeze-thaw is issued, or filesystems are"
1349                   " manually unfrozen and the file %s is removed",
1350                   s->state_filepath_isfrozen);
1351         return true;
1352     }
1353 #endif
1354     return false;
1355 }
1356 
1357 static GAState *initialize_agent(GAConfig *config, int socket_activation)
1358 {
1359     GAState *s = g_new0(GAState, 1);
1360 
1361     g_assert(ga_state == NULL);
1362 
1363     s->log_level = config->log_level;
1364     s->log_file = stderr;
1365 #ifdef CONFIG_FSFREEZE
1366     s->fsfreeze_hook = config->fsfreeze_hook;
1367 #endif
1368     s->pstate_filepath = g_strdup_printf("%s/qga.state", config->state_dir);
1369     s->state_filepath_isfrozen = g_strdup_printf("%s/qga.state.isfrozen",
1370                                                  config->state_dir);
1371     s->frozen = check_is_frozen(s);
1372 
1373     g_log_set_default_handler(ga_log, s);
1374     g_log_set_fatal_mask(NULL, G_LOG_LEVEL_ERROR);
1375     ga_enable_logging(s);
1376 
1377     g_debug("Guest agent version %s started", QEMU_FULL_VERSION);
1378 
1379 #ifdef _WIN32
1380     s->event_log = RegisterEventSource(NULL, "qemu-ga");
1381     if (!s->event_log) {
1382         g_autofree gchar *errmsg = g_win32_error_message(GetLastError());
1383         g_critical("unable to register event source: %s", errmsg);
1384         return NULL;
1385     }
1386 
1387     /* On win32 the state directory is application specific (be it the default
1388      * or a user override). We got past the command line parsing; let's create
1389      * the directory (with any intermediate directories). If we run into an
1390      * error later on, we won't try to clean up the directory, it is considered
1391      * persistent.
1392      */
1393     if (g_mkdir_with_parents(config->state_dir, S_IRWXU) == -1) {
1394         g_critical("unable to create (an ancestor of) the state directory"
1395                    " '%s': %s", config->state_dir, strerror(errno));
1396         return NULL;
1397     }
1398 #endif
1399 
1400     if (ga_is_frozen(s)) {
1401         if (config->daemonize) {
1402             /* delay opening/locking of pidfile till filesystems are unfrozen */
1403             s->deferred_options.pid_filepath = config->pid_filepath;
1404             become_daemon(NULL);
1405         }
1406         if (config->log_filepath) {
1407             /* delay opening the log file till filesystems are unfrozen */
1408             s->deferred_options.log_filepath = config->log_filepath;
1409         }
1410         ga_disable_logging(s);
1411         qmp_for_each_command(&ga_commands, ga_disable_not_allowed_freeze, NULL);
1412     } else {
1413         if (config->daemonize) {
1414             become_daemon(config->pid_filepath);
1415         }
1416         if (config->log_filepath) {
1417             FILE *log_file = ga_open_logfile(config->log_filepath);
1418             if (!log_file) {
1419                 g_critical("unable to open specified log file: %s",
1420                            strerror(errno));
1421                 return NULL;
1422             }
1423             s->log_file = log_file;
1424         }
1425     }
1426 
1427     /* load persistent state from disk */
1428     if (!read_persistent_state(&s->pstate,
1429                                s->pstate_filepath,
1430                                ga_is_frozen(s))) {
1431         g_critical("failed to load persistent state");
1432         return NULL;
1433     }
1434 
1435     if (config->allowedrpcs) {
1436         qmp_for_each_command(&ga_commands, ga_disable_not_allowed, config->allowedrpcs);
1437         s->allowedrpcs = config->allowedrpcs;
1438     }
1439 
1440     /*
1441      * Some commands can be blocked due to system limitation.
1442      * Initialize blockedrpcs list even if allowedrpcs specified.
1443      */
1444     config->blockedrpcs = ga_command_init_blockedrpcs(config->blockedrpcs);
1445     if (config->blockedrpcs) {
1446         GList *l = config->blockedrpcs;
1447         s->blockedrpcs = config->blockedrpcs;
1448         do {
1449             g_debug("disabling command: %s", (char *)l->data);
1450             qmp_disable_command(&ga_commands, l->data, NULL);
1451             l = g_list_next(l);
1452         } while (l);
1453     }
1454     s->command_state = ga_command_state_new();
1455     ga_command_state_init(s, s->command_state);
1456     ga_command_state_init_all(s->command_state);
1457     json_message_parser_init(&s->parser, process_event, s, NULL);
1458 
1459 #ifndef _WIN32
1460     if (!register_signal_handlers()) {
1461         g_critical("failed to register signal handlers");
1462         return NULL;
1463     }
1464 #endif
1465 
1466     s->main_loop = g_main_loop_new(NULL, false);
1467 
1468     s->config = config;
1469     s->socket_activation = socket_activation;
1470 
1471 #ifdef _WIN32
1472     s->wakeup_event = CreateEvent(NULL, TRUE, FALSE, TEXT("WakeUp"));
1473     if (s->wakeup_event == NULL) {
1474         g_critical("CreateEvent failed");
1475         return NULL;
1476     }
1477 #endif
1478 
1479     ga_state = s;
1480     return s;
1481 }
1482 
1483 static void cleanup_agent(GAState *s)
1484 {
1485 #ifdef _WIN32
1486     CloseHandle(s->wakeup_event);
1487     CloseHandle(s->event_log);
1488 #endif
1489     if (s->command_state) {
1490         ga_command_state_cleanup_all(s->command_state);
1491         ga_command_state_free(s->command_state);
1492         json_message_parser_destroy(&s->parser);
1493     }
1494     g_free(s->pstate_filepath);
1495     g_free(s->state_filepath_isfrozen);
1496     if (s->main_loop) {
1497         g_main_loop_unref(s->main_loop);
1498     }
1499     g_free(s);
1500     ga_state = NULL;
1501 }
1502 
1503 static int run_agent_once(GAState *s)
1504 {
1505     if (!channel_init(s, s->config->method, s->config->channel_path,
1506                       s->socket_activation ? FIRST_SOCKET_ACTIVATION_FD : -1)) {
1507         g_critical("failed to initialize guest agent channel");
1508         return EXIT_FAILURE;
1509     }
1510 
1511     g_main_loop_run(ga_state->main_loop);
1512 
1513     if (s->channel) {
1514         ga_channel_free(s->channel);
1515     }
1516 
1517     return EXIT_SUCCESS;
1518 }
1519 
1520 static void wait_for_channel_availability(GAState *s)
1521 {
1522     g_warning("waiting for channel path...");
1523 #ifndef _WIN32
1524     sleep(QGA_RETRY_INTERVAL);
1525 #else
1526     DWORD dwWaitResult;
1527 
1528     dwWaitResult = WaitForSingleObject(s->wakeup_event, INFINITE);
1529 
1530     switch (dwWaitResult) {
1531     case WAIT_OBJECT_0:
1532         break;
1533     case WAIT_TIMEOUT:
1534         break;
1535     default:
1536         g_critical("WaitForSingleObject failed");
1537     }
1538 #endif
1539 }
1540 
1541 static int run_agent(GAState *s)
1542 {
1543     int ret = EXIT_SUCCESS;
1544 
1545     s->force_exit = false;
1546 
1547     do {
1548         ret = run_agent_once(s);
1549         if (s->config->retry_path && !s->force_exit) {
1550             g_warning("agent stopped unexpectedly, restarting...");
1551             wait_for_channel_availability(s);
1552         }
1553     } while (s->config->retry_path && !s->force_exit);
1554 
1555     return ret;
1556 }
1557 
1558 static void stop_agent(GAState *s, bool requested)
1559 {
1560     if (!s->force_exit) {
1561         s->force_exit = requested;
1562     }
1563 
1564     if (g_main_loop_is_running(s->main_loop)) {
1565         g_main_loop_quit(s->main_loop);
1566     }
1567 }
1568 
1569 int main(int argc, char **argv)
1570 {
1571     int ret = EXIT_SUCCESS;
1572     GAState *s;
1573     GAConfig *config = g_new0(GAConfig, 1);
1574     int socket_activation;
1575 
1576     config->log_level = G_LOG_LEVEL_ERROR | G_LOG_LEVEL_CRITICAL;
1577 
1578     qemu_init_exec_dir(argv[0]);
1579     qga_qmp_init_marshal(&ga_commands);
1580 
1581     init_dfl_pathnames();
1582     config_load(config);
1583     config_parse(config, argc, argv);
1584 
1585     if (config->pid_filepath == NULL) {
1586         config->pid_filepath = g_strdup(dfl_pathnames.pidfile);
1587     }
1588 
1589     if (config->state_dir == NULL) {
1590         config->state_dir = g_strdup(dfl_pathnames.state_dir);
1591     }
1592 
1593     if (config->method == NULL) {
1594         config->method = g_strdup("virtio-serial");
1595     }
1596 
1597     socket_activation = check_socket_activation();
1598     if (socket_activation > 1) {
1599         g_critical("qemu-ga only supports listening on one socket");
1600         ret = EXIT_FAILURE;
1601         goto end;
1602     }
1603     if (socket_activation) {
1604         SocketAddress *addr;
1605 
1606         g_free(config->method);
1607         g_free(config->channel_path);
1608         config->method = NULL;
1609         config->channel_path = NULL;
1610 
1611         addr = socket_local_address(FIRST_SOCKET_ACTIVATION_FD, NULL);
1612         if (addr) {
1613             if (addr->type == SOCKET_ADDRESS_TYPE_UNIX) {
1614                 config->method = g_strdup("unix-listen");
1615             } else if (addr->type == SOCKET_ADDRESS_TYPE_VSOCK) {
1616                 config->method = g_strdup("vsock-listen");
1617             }
1618 
1619             qapi_free_SocketAddress(addr);
1620         }
1621 
1622         if (!config->method) {
1623             g_critical("unsupported listen fd type");
1624             ret = EXIT_FAILURE;
1625             goto end;
1626         }
1627     } else if (config->channel_path == NULL) {
1628         if (strcmp(config->method, "virtio-serial") == 0) {
1629             /* try the default path for the virtio-serial port */
1630             config->channel_path = g_strdup(QGA_VIRTIO_PATH_DEFAULT);
1631         } else if (strcmp(config->method, "isa-serial") == 0) {
1632             /* try the default path for the serial port - COM1 */
1633             config->channel_path = g_strdup(QGA_SERIAL_PATH_DEFAULT);
1634         } else {
1635             g_critical("must specify a path for this channel");
1636             ret = EXIT_FAILURE;
1637             goto end;
1638         }
1639     }
1640 
1641     if (config->dumpconf) {
1642         config_dump(config);
1643         goto end;
1644     }
1645 
1646     s = initialize_agent(config, socket_activation);
1647     if (!s) {
1648         g_critical("error initializing guest agent");
1649         goto end;
1650     }
1651 
1652 #ifdef _WIN32
1653     if (config->daemonize) {
1654         SERVICE_TABLE_ENTRY service_table[] = {
1655             { (char *)QGA_SERVICE_NAME, service_main }, { NULL, NULL } };
1656         StartServiceCtrlDispatcher(service_table);
1657     } else {
1658         ret = run_agent(s);
1659     }
1660 #else
1661     ret = run_agent(s);
1662 #endif
1663 
1664     cleanup_agent(s);
1665 
1666 end:
1667     if (config->daemonize) {
1668         unlink(config->pid_filepath);
1669     }
1670 
1671     config_free(config);
1672 
1673     return ret;
1674 }
1675