xref: /openbmc/qemu/chardev/char-socket.c (revision 234b7496)
1 /*
2  * QEMU System Emulator
3  *
4  * Copyright (c) 2003-2008 Fabrice Bellard
5  *
6  * Permission is hereby granted, free of charge, to any person obtaining a copy
7  * of this software and associated documentation files (the "Software"), to deal
8  * in the Software without restriction, including without limitation the rights
9  * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
10  * copies of the Software, and to permit persons to whom the Software is
11  * furnished to do so, subject to the following conditions:
12  *
13  * The above copyright notice and this permission notice shall be included in
14  * all copies or substantial portions of the Software.
15  *
16  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
17  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
18  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
19  * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
20  * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
21  * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
22  * THE SOFTWARE.
23  */
24 
25 #include "qemu/osdep.h"
26 #include "chardev/char.h"
27 #include "io/channel-socket.h"
28 #include "io/channel-tls.h"
29 #include "io/channel-websock.h"
30 #include "io/net-listener.h"
31 #include "qemu/error-report.h"
32 #include "qemu/module.h"
33 #include "qemu/option.h"
34 #include "qapi/error.h"
35 #include "qapi/clone-visitor.h"
36 #include "qapi/qapi-visit-sockets.h"
37 
38 #include "chardev/char-io.h"
39 
40 /***********************************************************/
41 /* TCP Net console */
42 
43 #define TCP_MAX_FDS 16
44 
45 typedef struct {
46     char buf[21];
47     size_t buflen;
48 } TCPChardevTelnetInit;
49 
50 typedef enum {
51     TCP_CHARDEV_STATE_DISCONNECTED,
52     TCP_CHARDEV_STATE_CONNECTING,
53     TCP_CHARDEV_STATE_CONNECTED,
54 } TCPChardevState;
55 
56 typedef struct {
57     Chardev parent;
58     QIOChannel *ioc; /* Client I/O channel */
59     QIOChannelSocket *sioc; /* Client master channel */
60     QIONetListener *listener;
61     GSource *hup_source;
62     QCryptoTLSCreds *tls_creds;
63     char *tls_authz;
64     TCPChardevState state;
65     int max_size;
66     int do_telnetopt;
67     int do_nodelay;
68     int *read_msgfds;
69     size_t read_msgfds_num;
70     int *write_msgfds;
71     size_t write_msgfds_num;
72 
73     SocketAddress *addr;
74     bool is_listen;
75     bool is_telnet;
76     bool is_tn3270;
77     GSource *telnet_source;
78     TCPChardevTelnetInit *telnet_init;
79 
80     bool is_websock;
81 
82     GSource *reconnect_timer;
83     int64_t reconnect_time;
84     bool connect_err_reported;
85 
86     QIOTask *connect_task;
87 } SocketChardev;
88 
89 #define SOCKET_CHARDEV(obj)                                     \
90     OBJECT_CHECK(SocketChardev, (obj), TYPE_CHARDEV_SOCKET)
91 
92 static gboolean socket_reconnect_timeout(gpointer opaque);
93 static void tcp_chr_telnet_init(Chardev *chr);
94 
95 static void tcp_chr_change_state(SocketChardev *s, TCPChardevState state)
96 {
97     switch (state) {
98     case TCP_CHARDEV_STATE_DISCONNECTED:
99         break;
100     case TCP_CHARDEV_STATE_CONNECTING:
101         assert(s->state == TCP_CHARDEV_STATE_DISCONNECTED);
102         break;
103     case TCP_CHARDEV_STATE_CONNECTED:
104         assert(s->state == TCP_CHARDEV_STATE_CONNECTING);
105         break;
106     }
107     s->state = state;
108 }
109 
110 static void tcp_chr_reconn_timer_cancel(SocketChardev *s)
111 {
112     if (s->reconnect_timer) {
113         g_source_destroy(s->reconnect_timer);
114         g_source_unref(s->reconnect_timer);
115         s->reconnect_timer = NULL;
116     }
117 }
118 
119 static void qemu_chr_socket_restart_timer(Chardev *chr)
120 {
121     SocketChardev *s = SOCKET_CHARDEV(chr);
122     char *name;
123 
124     assert(s->state == TCP_CHARDEV_STATE_DISCONNECTED);
125     assert(!s->reconnect_timer);
126     name = g_strdup_printf("chardev-socket-reconnect-%s", chr->label);
127     s->reconnect_timer = qemu_chr_timeout_add_ms(chr,
128                                                  s->reconnect_time * 1000,
129                                                  socket_reconnect_timeout,
130                                                  chr);
131     g_source_set_name(s->reconnect_timer, name);
132     g_free(name);
133 }
134 
135 static void check_report_connect_error(Chardev *chr,
136                                        Error *err)
137 {
138     SocketChardev *s = SOCKET_CHARDEV(chr);
139 
140     if (!s->connect_err_reported) {
141         error_reportf_err(err,
142                           "Unable to connect character device %s: ",
143                           chr->label);
144         s->connect_err_reported = true;
145     }
146     qemu_chr_socket_restart_timer(chr);
147 }
148 
149 static void tcp_chr_accept(QIONetListener *listener,
150                            QIOChannelSocket *cioc,
151                            void *opaque);
152 
153 static int tcp_chr_read_poll(void *opaque);
154 static void tcp_chr_disconnect_locked(Chardev *chr);
155 
156 /* Called with chr_write_lock held.  */
157 static int tcp_chr_write(Chardev *chr, const uint8_t *buf, int len)
158 {
159     SocketChardev *s = SOCKET_CHARDEV(chr);
160 
161     if (s->state == TCP_CHARDEV_STATE_CONNECTED) {
162         int ret =  io_channel_send_full(s->ioc, buf, len,
163                                         s->write_msgfds,
164                                         s->write_msgfds_num);
165 
166         /* free the written msgfds in any cases
167          * other than ret < 0 && errno == EAGAIN
168          */
169         if (!(ret < 0 && EAGAIN == errno)
170             && s->write_msgfds_num) {
171             g_free(s->write_msgfds);
172             s->write_msgfds = 0;
173             s->write_msgfds_num = 0;
174         }
175 
176         if (ret < 0 && errno != EAGAIN) {
177             if (tcp_chr_read_poll(chr) <= 0) {
178                 tcp_chr_disconnect_locked(chr);
179                 return len;
180             } /* else let the read handler finish it properly */
181         }
182 
183         return ret;
184     } else {
185         /* XXX: indicate an error ? */
186         return len;
187     }
188 }
189 
190 static int tcp_chr_read_poll(void *opaque)
191 {
192     Chardev *chr = CHARDEV(opaque);
193     SocketChardev *s = SOCKET_CHARDEV(opaque);
194     if (s->state != TCP_CHARDEV_STATE_CONNECTED) {
195         return 0;
196     }
197     s->max_size = qemu_chr_be_can_write(chr);
198     return s->max_size;
199 }
200 
201 static void tcp_chr_process_IAC_bytes(Chardev *chr,
202                                       SocketChardev *s,
203                                       uint8_t *buf, int *size)
204 {
205     /* Handle any telnet or tn3270 client's basic IAC options.
206      * For telnet options, it satisfies char by char mode with no echo.
207      * For tn3270 options, it satisfies binary mode with EOR.
208      * All IAC options will be removed from the buf and the do_opt
209      * pointer will be used to track the state of the width of the
210      * IAC information.
211      *
212      * RFC854: "All TELNET commands consist of at least a two byte sequence.
213      * The commands dealing with option negotiation are three byte sequences,
214      * the third byte being the code for the option referenced."
215      * "IAC BREAK", "IAC IP", "IAC NOP" and the double IAC are two bytes.
216      * "IAC SB", "IAC SE" and "IAC EOR" are saved to split up data boundary
217      * for tn3270.
218      * NOP, Break and Interrupt Process(IP) might be encountered during a TN3270
219      * session, and NOP and IP need to be done later.
220      */
221 
222     int i;
223     int j = 0;
224 
225     for (i = 0; i < *size; i++) {
226         if (s->do_telnetopt > 1) {
227             if ((unsigned char)buf[i] == IAC && s->do_telnetopt == 2) {
228                 /* Double IAC means send an IAC */
229                 if (j != i) {
230                     buf[j] = buf[i];
231                 }
232                 j++;
233                 s->do_telnetopt = 1;
234             } else {
235                 if ((unsigned char)buf[i] == IAC_BREAK
236                     && s->do_telnetopt == 2) {
237                     /* Handle IAC break commands by sending a serial break */
238                     qemu_chr_be_event(chr, CHR_EVENT_BREAK);
239                     s->do_telnetopt++;
240                 } else if (s->is_tn3270 && ((unsigned char)buf[i] == IAC_EOR
241                            || (unsigned char)buf[i] == IAC_SB
242                            || (unsigned char)buf[i] == IAC_SE)
243                            && s->do_telnetopt == 2) {
244                     buf[j++] = IAC;
245                     buf[j++] = buf[i];
246                     s->do_telnetopt++;
247                 } else if (s->is_tn3270 && ((unsigned char)buf[i] == IAC_IP
248                            || (unsigned char)buf[i] == IAC_NOP)
249                            && s->do_telnetopt == 2) {
250                     /* TODO: IP and NOP need to be implemented later. */
251                     s->do_telnetopt++;
252                 }
253                 s->do_telnetopt++;
254             }
255             if (s->do_telnetopt >= 4) {
256                 s->do_telnetopt = 1;
257             }
258         } else {
259             if ((unsigned char)buf[i] == IAC) {
260                 s->do_telnetopt = 2;
261             } else {
262                 if (j != i) {
263                     buf[j] = buf[i];
264                 }
265                 j++;
266             }
267         }
268     }
269     *size = j;
270 }
271 
272 static int tcp_get_msgfds(Chardev *chr, int *fds, int num)
273 {
274     SocketChardev *s = SOCKET_CHARDEV(chr);
275 
276     int to_copy = (s->read_msgfds_num < num) ? s->read_msgfds_num : num;
277 
278     assert(num <= TCP_MAX_FDS);
279 
280     if (to_copy) {
281         int i;
282 
283         memcpy(fds, s->read_msgfds, to_copy * sizeof(int));
284 
285         /* Close unused fds */
286         for (i = to_copy; i < s->read_msgfds_num; i++) {
287             close(s->read_msgfds[i]);
288         }
289 
290         g_free(s->read_msgfds);
291         s->read_msgfds = 0;
292         s->read_msgfds_num = 0;
293     }
294 
295     return to_copy;
296 }
297 
298 static int tcp_set_msgfds(Chardev *chr, int *fds, int num)
299 {
300     SocketChardev *s = SOCKET_CHARDEV(chr);
301 
302     /* clear old pending fd array */
303     g_free(s->write_msgfds);
304     s->write_msgfds = NULL;
305     s->write_msgfds_num = 0;
306 
307     if ((s->state != TCP_CHARDEV_STATE_CONNECTED) ||
308         !qio_channel_has_feature(s->ioc,
309                                  QIO_CHANNEL_FEATURE_FD_PASS)) {
310         return -1;
311     }
312 
313     if (num) {
314         s->write_msgfds = g_new(int, num);
315         memcpy(s->write_msgfds, fds, num * sizeof(int));
316     }
317 
318     s->write_msgfds_num = num;
319 
320     return 0;
321 }
322 
323 static ssize_t tcp_chr_recv(Chardev *chr, char *buf, size_t len)
324 {
325     SocketChardev *s = SOCKET_CHARDEV(chr);
326     struct iovec iov = { .iov_base = buf, .iov_len = len };
327     int ret;
328     size_t i;
329     int *msgfds = NULL;
330     size_t msgfds_num = 0;
331 
332     if (qio_channel_has_feature(s->ioc, QIO_CHANNEL_FEATURE_FD_PASS)) {
333         ret = qio_channel_readv_full(s->ioc, &iov, 1,
334                                      &msgfds, &msgfds_num,
335                                      NULL);
336     } else {
337         ret = qio_channel_readv_full(s->ioc, &iov, 1,
338                                      NULL, NULL,
339                                      NULL);
340     }
341 
342     if (ret == QIO_CHANNEL_ERR_BLOCK) {
343         errno = EAGAIN;
344         ret = -1;
345     } else if (ret == -1) {
346         errno = EIO;
347     }
348 
349     if (msgfds_num) {
350         /* close and clean read_msgfds */
351         for (i = 0; i < s->read_msgfds_num; i++) {
352             close(s->read_msgfds[i]);
353         }
354 
355         if (s->read_msgfds_num) {
356             g_free(s->read_msgfds);
357         }
358 
359         s->read_msgfds = msgfds;
360         s->read_msgfds_num = msgfds_num;
361     }
362 
363     for (i = 0; i < s->read_msgfds_num; i++) {
364         int fd = s->read_msgfds[i];
365         if (fd < 0) {
366             continue;
367         }
368 
369         /* O_NONBLOCK is preserved across SCM_RIGHTS so reset it */
370         qemu_set_block(fd);
371 
372 #ifndef MSG_CMSG_CLOEXEC
373         qemu_set_cloexec(fd);
374 #endif
375     }
376 
377     return ret;
378 }
379 
380 static GSource *tcp_chr_add_watch(Chardev *chr, GIOCondition cond)
381 {
382     SocketChardev *s = SOCKET_CHARDEV(chr);
383     return qio_channel_create_watch(s->ioc, cond);
384 }
385 
386 static void remove_hup_source(SocketChardev *s)
387 {
388     if (s->hup_source != NULL) {
389         g_source_destroy(s->hup_source);
390         g_source_unref(s->hup_source);
391         s->hup_source = NULL;
392     }
393 }
394 
395 static void tcp_chr_free_connection(Chardev *chr)
396 {
397     SocketChardev *s = SOCKET_CHARDEV(chr);
398     int i;
399 
400     if (s->read_msgfds_num) {
401         for (i = 0; i < s->read_msgfds_num; i++) {
402             close(s->read_msgfds[i]);
403         }
404         g_free(s->read_msgfds);
405         s->read_msgfds = NULL;
406         s->read_msgfds_num = 0;
407     }
408 
409     remove_hup_source(s);
410 
411     tcp_set_msgfds(chr, NULL, 0);
412     remove_fd_in_watch(chr);
413     object_unref(OBJECT(s->sioc));
414     s->sioc = NULL;
415     object_unref(OBJECT(s->ioc));
416     s->ioc = NULL;
417     g_free(chr->filename);
418     chr->filename = NULL;
419     tcp_chr_change_state(s, TCP_CHARDEV_STATE_DISCONNECTED);
420 }
421 
422 static const char *qemu_chr_socket_protocol(SocketChardev *s)
423 {
424     if (s->is_telnet) {
425         return "telnet";
426     }
427     return s->is_websock ? "websocket" : "tcp";
428 }
429 
430 static char *qemu_chr_socket_address(SocketChardev *s, const char *prefix)
431 {
432     switch (s->addr->type) {
433     case SOCKET_ADDRESS_TYPE_INET:
434         return g_strdup_printf("%s%s:%s:%s%s", prefix,
435                                qemu_chr_socket_protocol(s),
436                                s->addr->u.inet.host,
437                                s->addr->u.inet.port,
438                                s->is_listen ? ",server" : "");
439         break;
440     case SOCKET_ADDRESS_TYPE_UNIX:
441         return g_strdup_printf("%sunix:%s%s", prefix,
442                                s->addr->u.q_unix.path,
443                                s->is_listen ? ",server" : "");
444         break;
445     case SOCKET_ADDRESS_TYPE_FD:
446         return g_strdup_printf("%sfd:%s%s", prefix, s->addr->u.fd.str,
447                                s->is_listen ? ",server" : "");
448         break;
449     case SOCKET_ADDRESS_TYPE_VSOCK:
450         return g_strdup_printf("%svsock:%s:%s", prefix,
451                                s->addr->u.vsock.cid,
452                                s->addr->u.vsock.port);
453     default:
454         abort();
455     }
456 }
457 
458 static void update_disconnected_filename(SocketChardev *s)
459 {
460     Chardev *chr = CHARDEV(s);
461 
462     g_free(chr->filename);
463     if (s->addr) {
464         chr->filename = qemu_chr_socket_address(s, "disconnected:");
465     } else {
466         chr->filename = g_strdup("disconnected:socket");
467     }
468 }
469 
470 /* NB may be called even if tcp_chr_connect has not been
471  * reached, due to TLS or telnet initialization failure,
472  * so can *not* assume s->state == TCP_CHARDEV_STATE_CONNECTED
473  * This must be called with chr->chr_write_lock held.
474  */
475 static void tcp_chr_disconnect_locked(Chardev *chr)
476 {
477     SocketChardev *s = SOCKET_CHARDEV(chr);
478     bool emit_close = s->state == TCP_CHARDEV_STATE_CONNECTED;
479 
480     tcp_chr_free_connection(chr);
481 
482     if (s->listener) {
483         qio_net_listener_set_client_func_full(s->listener, tcp_chr_accept,
484                                               chr, NULL, chr->gcontext);
485     }
486     update_disconnected_filename(s);
487     if (emit_close) {
488         qemu_chr_be_event(chr, CHR_EVENT_CLOSED);
489     }
490     if (s->reconnect_time) {
491         qemu_chr_socket_restart_timer(chr);
492     }
493 }
494 
495 static void tcp_chr_disconnect(Chardev *chr)
496 {
497     qemu_mutex_lock(&chr->chr_write_lock);
498     tcp_chr_disconnect_locked(chr);
499     qemu_mutex_unlock(&chr->chr_write_lock);
500 }
501 
502 static gboolean tcp_chr_read(QIOChannel *chan, GIOCondition cond, void *opaque)
503 {
504     Chardev *chr = CHARDEV(opaque);
505     SocketChardev *s = SOCKET_CHARDEV(opaque);
506     uint8_t buf[CHR_READ_BUF_LEN];
507     int len, size;
508 
509     if ((s->state != TCP_CHARDEV_STATE_CONNECTED) ||
510         s->max_size <= 0) {
511         return TRUE;
512     }
513     len = sizeof(buf);
514     if (len > s->max_size) {
515         len = s->max_size;
516     }
517     size = tcp_chr_recv(chr, (void *)buf, len);
518     if (size == 0 || (size == -1 && errno != EAGAIN)) {
519         /* connection closed */
520         tcp_chr_disconnect(chr);
521     } else if (size > 0) {
522         if (s->do_telnetopt) {
523             tcp_chr_process_IAC_bytes(chr, s, buf, &size);
524         }
525         if (size > 0) {
526             qemu_chr_be_write(chr, buf, size);
527         }
528     }
529 
530     return TRUE;
531 }
532 
533 static gboolean tcp_chr_hup(QIOChannel *channel,
534                                GIOCondition cond,
535                                void *opaque)
536 {
537     Chardev *chr = CHARDEV(opaque);
538     tcp_chr_disconnect(chr);
539     return G_SOURCE_REMOVE;
540 }
541 
542 static int tcp_chr_sync_read(Chardev *chr, const uint8_t *buf, int len)
543 {
544     SocketChardev *s = SOCKET_CHARDEV(chr);
545     int size;
546 
547     if (s->state != TCP_CHARDEV_STATE_CONNECTED) {
548         return 0;
549     }
550 
551     qio_channel_set_blocking(s->ioc, true, NULL);
552     size = tcp_chr_recv(chr, (void *) buf, len);
553     if (s->state != TCP_CHARDEV_STATE_DISCONNECTED) {
554         qio_channel_set_blocking(s->ioc, false, NULL);
555     }
556     if (size == 0) {
557         /* connection closed */
558         tcp_chr_disconnect(chr);
559     }
560 
561     return size;
562 }
563 
564 static char *qemu_chr_compute_filename(SocketChardev *s)
565 {
566     struct sockaddr_storage *ss = &s->sioc->localAddr;
567     struct sockaddr_storage *ps = &s->sioc->remoteAddr;
568     socklen_t ss_len = s->sioc->localAddrLen;
569     socklen_t ps_len = s->sioc->remoteAddrLen;
570     char shost[NI_MAXHOST], sserv[NI_MAXSERV];
571     char phost[NI_MAXHOST], pserv[NI_MAXSERV];
572     const char *left = "", *right = "";
573 
574     switch (ss->ss_family) {
575 #ifndef _WIN32
576     case AF_UNIX:
577         return g_strdup_printf("unix:%s%s",
578                                ((struct sockaddr_un *)(ss))->sun_path,
579                                s->is_listen ? ",server" : "");
580 #endif
581     case AF_INET6:
582         left  = "[";
583         right = "]";
584         /* fall through */
585     case AF_INET:
586         getnameinfo((struct sockaddr *) ss, ss_len, shost, sizeof(shost),
587                     sserv, sizeof(sserv), NI_NUMERICHOST | NI_NUMERICSERV);
588         getnameinfo((struct sockaddr *) ps, ps_len, phost, sizeof(phost),
589                     pserv, sizeof(pserv), NI_NUMERICHOST | NI_NUMERICSERV);
590         return g_strdup_printf("%s:%s%s%s:%s%s <-> %s%s%s:%s",
591                                qemu_chr_socket_protocol(s),
592                                left, shost, right, sserv,
593                                s->is_listen ? ",server" : "",
594                                left, phost, right, pserv);
595 
596     default:
597         return g_strdup_printf("unknown");
598     }
599 }
600 
601 static void update_ioc_handlers(SocketChardev *s)
602 {
603     Chardev *chr = CHARDEV(s);
604 
605     if (s->state != TCP_CHARDEV_STATE_CONNECTED) {
606         return;
607     }
608 
609     remove_fd_in_watch(chr);
610     chr->gsource = io_add_watch_poll(chr, s->ioc,
611                                      tcp_chr_read_poll,
612                                      tcp_chr_read, chr,
613                                      chr->gcontext);
614 
615     remove_hup_source(s);
616     s->hup_source = qio_channel_create_watch(s->ioc, G_IO_HUP);
617     g_source_set_callback(s->hup_source, (GSourceFunc)tcp_chr_hup,
618                           chr, NULL);
619     g_source_attach(s->hup_source, chr->gcontext);
620 }
621 
622 static void tcp_chr_connect(void *opaque)
623 {
624     Chardev *chr = CHARDEV(opaque);
625     SocketChardev *s = SOCKET_CHARDEV(opaque);
626 
627     g_free(chr->filename);
628     chr->filename = qemu_chr_compute_filename(s);
629 
630     tcp_chr_change_state(s, TCP_CHARDEV_STATE_CONNECTED);
631     update_ioc_handlers(s);
632     qemu_chr_be_event(chr, CHR_EVENT_OPENED);
633 }
634 
635 static void tcp_chr_telnet_destroy(SocketChardev *s)
636 {
637     if (s->telnet_source) {
638         g_source_destroy(s->telnet_source);
639         g_source_unref(s->telnet_source);
640         s->telnet_source = NULL;
641     }
642 }
643 
644 static void tcp_chr_update_read_handler(Chardev *chr)
645 {
646     SocketChardev *s = SOCKET_CHARDEV(chr);
647 
648     if (s->listener && s->state == TCP_CHARDEV_STATE_DISCONNECTED) {
649         /*
650          * It's possible that chardev context is changed in
651          * qemu_chr_be_update_read_handlers().  Reset it for QIO net
652          * listener if there is.
653          */
654         qio_net_listener_set_client_func_full(s->listener, tcp_chr_accept,
655                                               chr, NULL, chr->gcontext);
656     }
657 
658     if (s->telnet_source) {
659         tcp_chr_telnet_init(CHARDEV(s));
660     }
661 
662     update_ioc_handlers(s);
663 }
664 
665 static gboolean tcp_chr_telnet_init_io(QIOChannel *ioc,
666                                        GIOCondition cond G_GNUC_UNUSED,
667                                        gpointer user_data)
668 {
669     SocketChardev *s = user_data;
670     Chardev *chr = CHARDEV(s);
671     TCPChardevTelnetInit *init = s->telnet_init;
672     ssize_t ret;
673 
674     assert(init);
675 
676     ret = qio_channel_write(ioc, init->buf, init->buflen, NULL);
677     if (ret < 0) {
678         if (ret == QIO_CHANNEL_ERR_BLOCK) {
679             ret = 0;
680         } else {
681             tcp_chr_disconnect(chr);
682             goto end;
683         }
684     }
685     init->buflen -= ret;
686 
687     if (init->buflen == 0) {
688         tcp_chr_connect(chr);
689         goto end;
690     }
691 
692     memmove(init->buf, init->buf + ret, init->buflen);
693 
694     return G_SOURCE_CONTINUE;
695 
696 end:
697     g_free(s->telnet_init);
698     s->telnet_init = NULL;
699     g_source_unref(s->telnet_source);
700     s->telnet_source = NULL;
701     return G_SOURCE_REMOVE;
702 }
703 
704 static void tcp_chr_telnet_init(Chardev *chr)
705 {
706     SocketChardev *s = SOCKET_CHARDEV(chr);
707     TCPChardevTelnetInit *init;
708     size_t n = 0;
709 
710     /* Destroy existing task */
711     tcp_chr_telnet_destroy(s);
712 
713     if (s->telnet_init) {
714         /* We are possibly during a handshake already */
715         goto cont;
716     }
717 
718     s->telnet_init = g_new0(TCPChardevTelnetInit, 1);
719     init = s->telnet_init;
720 
721 #define IACSET(x, a, b, c)                      \
722     do {                                        \
723         x[n++] = a;                             \
724         x[n++] = b;                             \
725         x[n++] = c;                             \
726     } while (0)
727 
728     if (!s->is_tn3270) {
729         init->buflen = 12;
730         /* Prep the telnet negotion to put telnet in binary,
731          * no echo, single char mode */
732         IACSET(init->buf, 0xff, 0xfb, 0x01);  /* IAC WILL ECHO */
733         IACSET(init->buf, 0xff, 0xfb, 0x03);  /* IAC WILL Suppress go ahead */
734         IACSET(init->buf, 0xff, 0xfb, 0x00);  /* IAC WILL Binary */
735         IACSET(init->buf, 0xff, 0xfd, 0x00);  /* IAC DO Binary */
736     } else {
737         init->buflen = 21;
738         /* Prep the TN3270 negotion based on RFC1576 */
739         IACSET(init->buf, 0xff, 0xfd, 0x19);  /* IAC DO EOR */
740         IACSET(init->buf, 0xff, 0xfb, 0x19);  /* IAC WILL EOR */
741         IACSET(init->buf, 0xff, 0xfd, 0x00);  /* IAC DO BINARY */
742         IACSET(init->buf, 0xff, 0xfb, 0x00);  /* IAC WILL BINARY */
743         IACSET(init->buf, 0xff, 0xfd, 0x18);  /* IAC DO TERMINAL TYPE */
744         IACSET(init->buf, 0xff, 0xfa, 0x18);  /* IAC SB TERMINAL TYPE */
745         IACSET(init->buf, 0x01, 0xff, 0xf0);  /* SEND IAC SE */
746     }
747 
748 #undef IACSET
749 
750 cont:
751     s->telnet_source = qio_channel_add_watch_source(s->ioc, G_IO_OUT,
752                                                     tcp_chr_telnet_init_io,
753                                                     s, NULL,
754                                                     chr->gcontext);
755 }
756 
757 
758 static void tcp_chr_websock_handshake(QIOTask *task, gpointer user_data)
759 {
760     Chardev *chr = user_data;
761     SocketChardev *s = user_data;
762 
763     if (qio_task_propagate_error(task, NULL)) {
764         tcp_chr_disconnect(chr);
765     } else {
766         if (s->do_telnetopt) {
767             tcp_chr_telnet_init(chr);
768         } else {
769             tcp_chr_connect(chr);
770         }
771     }
772 }
773 
774 
775 static void tcp_chr_websock_init(Chardev *chr)
776 {
777     SocketChardev *s = SOCKET_CHARDEV(chr);
778     QIOChannelWebsock *wioc = NULL;
779     gchar *name;
780 
781     wioc = qio_channel_websock_new_server(s->ioc);
782 
783     name = g_strdup_printf("chardev-websocket-server-%s", chr->label);
784     qio_channel_set_name(QIO_CHANNEL(wioc), name);
785     g_free(name);
786     object_unref(OBJECT(s->ioc));
787     s->ioc = QIO_CHANNEL(wioc);
788 
789     qio_channel_websock_handshake(wioc, tcp_chr_websock_handshake, chr, NULL);
790 }
791 
792 
793 static void tcp_chr_tls_handshake(QIOTask *task,
794                                   gpointer user_data)
795 {
796     Chardev *chr = user_data;
797     SocketChardev *s = user_data;
798 
799     if (qio_task_propagate_error(task, NULL)) {
800         tcp_chr_disconnect(chr);
801     } else {
802         if (s->is_websock) {
803             tcp_chr_websock_init(chr);
804         } else if (s->do_telnetopt) {
805             tcp_chr_telnet_init(chr);
806         } else {
807             tcp_chr_connect(chr);
808         }
809     }
810 }
811 
812 
813 static void tcp_chr_tls_init(Chardev *chr)
814 {
815     SocketChardev *s = SOCKET_CHARDEV(chr);
816     QIOChannelTLS *tioc;
817     Error *err = NULL;
818     gchar *name;
819 
820     if (s->is_listen) {
821         tioc = qio_channel_tls_new_server(
822             s->ioc, s->tls_creds,
823             s->tls_authz,
824             &err);
825     } else {
826         tioc = qio_channel_tls_new_client(
827             s->ioc, s->tls_creds,
828             s->addr->u.inet.host,
829             &err);
830     }
831     if (tioc == NULL) {
832         error_free(err);
833         tcp_chr_disconnect(chr);
834         return;
835     }
836     name = g_strdup_printf("chardev-tls-%s-%s",
837                            s->is_listen ? "server" : "client",
838                            chr->label);
839     qio_channel_set_name(QIO_CHANNEL(tioc), name);
840     g_free(name);
841     object_unref(OBJECT(s->ioc));
842     s->ioc = QIO_CHANNEL(tioc);
843 
844     qio_channel_tls_handshake(tioc,
845                               tcp_chr_tls_handshake,
846                               chr,
847                               NULL,
848                               chr->gcontext);
849 }
850 
851 
852 static void tcp_chr_set_client_ioc_name(Chardev *chr,
853                                         QIOChannelSocket *sioc)
854 {
855     SocketChardev *s = SOCKET_CHARDEV(chr);
856     char *name;
857     name = g_strdup_printf("chardev-tcp-%s-%s",
858                            s->is_listen ? "server" : "client",
859                            chr->label);
860     qio_channel_set_name(QIO_CHANNEL(sioc), name);
861     g_free(name);
862 
863 }
864 
865 static int tcp_chr_new_client(Chardev *chr, QIOChannelSocket *sioc)
866 {
867     SocketChardev *s = SOCKET_CHARDEV(chr);
868 
869     if (s->state != TCP_CHARDEV_STATE_CONNECTING) {
870         return -1;
871     }
872 
873     s->ioc = QIO_CHANNEL(sioc);
874     object_ref(OBJECT(sioc));
875     s->sioc = sioc;
876     object_ref(OBJECT(sioc));
877 
878     qio_channel_set_blocking(s->ioc, false, NULL);
879 
880     if (s->do_nodelay) {
881         qio_channel_set_delay(s->ioc, false);
882     }
883     if (s->listener) {
884         qio_net_listener_set_client_func_full(s->listener, NULL, NULL,
885                                               NULL, chr->gcontext);
886     }
887 
888     if (s->tls_creds) {
889         tcp_chr_tls_init(chr);
890     } else if (s->is_websock) {
891         tcp_chr_websock_init(chr);
892     } else if (s->do_telnetopt) {
893         tcp_chr_telnet_init(chr);
894     } else {
895         tcp_chr_connect(chr);
896     }
897 
898     return 0;
899 }
900 
901 
902 static int tcp_chr_add_client(Chardev *chr, int fd)
903 {
904     int ret;
905     QIOChannelSocket *sioc;
906     SocketChardev *s = SOCKET_CHARDEV(chr);
907 
908     if (s->state != TCP_CHARDEV_STATE_DISCONNECTED) {
909         return -1;
910     }
911 
912     sioc = qio_channel_socket_new_fd(fd, NULL);
913     if (!sioc) {
914         return -1;
915     }
916     tcp_chr_change_state(s, TCP_CHARDEV_STATE_CONNECTING);
917     tcp_chr_set_client_ioc_name(chr, sioc);
918     ret = tcp_chr_new_client(chr, sioc);
919     object_unref(OBJECT(sioc));
920     return ret;
921 }
922 
923 static void tcp_chr_accept(QIONetListener *listener,
924                            QIOChannelSocket *cioc,
925                            void *opaque)
926 {
927     Chardev *chr = CHARDEV(opaque);
928     SocketChardev *s = SOCKET_CHARDEV(chr);
929 
930     tcp_chr_change_state(s, TCP_CHARDEV_STATE_CONNECTING);
931     tcp_chr_set_client_ioc_name(chr, cioc);
932     tcp_chr_new_client(chr, cioc);
933 }
934 
935 
936 static int tcp_chr_connect_client_sync(Chardev *chr, Error **errp)
937 {
938     SocketChardev *s = SOCKET_CHARDEV(chr);
939     QIOChannelSocket *sioc = qio_channel_socket_new();
940     tcp_chr_change_state(s, TCP_CHARDEV_STATE_CONNECTING);
941     tcp_chr_set_client_ioc_name(chr, sioc);
942     if (qio_channel_socket_connect_sync(sioc, s->addr, errp) < 0) {
943         tcp_chr_change_state(s, TCP_CHARDEV_STATE_DISCONNECTED);
944         object_unref(OBJECT(sioc));
945         return -1;
946     }
947     tcp_chr_new_client(chr, sioc);
948     object_unref(OBJECT(sioc));
949     return 0;
950 }
951 
952 
953 static void tcp_chr_accept_server_sync(Chardev *chr)
954 {
955     SocketChardev *s = SOCKET_CHARDEV(chr);
956     QIOChannelSocket *sioc;
957     info_report("QEMU waiting for connection on: %s",
958                 chr->filename);
959     tcp_chr_change_state(s, TCP_CHARDEV_STATE_CONNECTING);
960     sioc = qio_net_listener_wait_client(s->listener);
961     tcp_chr_set_client_ioc_name(chr, sioc);
962     tcp_chr_new_client(chr, sioc);
963     object_unref(OBJECT(sioc));
964 }
965 
966 
967 static int tcp_chr_wait_connected(Chardev *chr, Error **errp)
968 {
969     SocketChardev *s = SOCKET_CHARDEV(chr);
970     const char *opts[] = { "telnet", "tn3270", "websock", "tls-creds" };
971     bool optset[] = { s->is_telnet, s->is_tn3270, s->is_websock, s->tls_creds };
972     size_t i;
973 
974     QEMU_BUILD_BUG_ON(G_N_ELEMENTS(opts) != G_N_ELEMENTS(optset));
975     for (i = 0; i < G_N_ELEMENTS(opts); i++) {
976         if (optset[i]) {
977             error_setg(errp,
978                        "'%s' option is incompatible with waiting for "
979                        "connection completion", opts[i]);
980             return -1;
981         }
982     }
983 
984     tcp_chr_reconn_timer_cancel(s);
985 
986     /*
987      * We expect states to be as follows:
988      *
989      *  - server
990      *    - wait   -> CONNECTED
991      *    - nowait -> DISCONNECTED
992      *  - client
993      *    - reconnect == 0 -> CONNECTED
994      *    - reconnect != 0 -> CONNECTING
995      *
996      */
997     if (s->state == TCP_CHARDEV_STATE_CONNECTING) {
998         if (!s->connect_task) {
999             error_setg(errp,
1000                        "Unexpected 'connecting' state without connect task "
1001                        "while waiting for connection completion");
1002             return -1;
1003         }
1004         /*
1005          * tcp_chr_wait_connected should only ever be run from the
1006          * main loop thread associated with chr->gcontext, otherwise
1007          * qio_task_wait_thread has a dangerous race condition with
1008          * free'ing of the s->connect_task object.
1009          *
1010          * Acquiring the main context doesn't 100% prove we're in
1011          * the main loop thread, but it does at least guarantee
1012          * that the main loop won't be executed by another thread
1013          * avoiding the race condition with the task idle callback.
1014          */
1015         g_main_context_acquire(chr->gcontext);
1016         qio_task_wait_thread(s->connect_task);
1017         g_main_context_release(chr->gcontext);
1018 
1019         /*
1020          * The completion callback (qemu_chr_socket_connected) for
1021          * s->connect_task should have set this to NULL by the time
1022          * qio_task_wait_thread has returned.
1023          */
1024         assert(!s->connect_task);
1025 
1026         /*
1027          * NB we are *not* guaranteed to have "s->state == ..CONNECTED"
1028          * at this point as this first connect may be failed, so
1029          * allow the next loop to run regardless.
1030          */
1031     }
1032 
1033     while (s->state != TCP_CHARDEV_STATE_CONNECTED) {
1034         if (s->is_listen) {
1035             tcp_chr_accept_server_sync(chr);
1036         } else {
1037             Error *err = NULL;
1038             if (tcp_chr_connect_client_sync(chr, &err) < 0) {
1039                 if (s->reconnect_time) {
1040                     error_free(err);
1041                     g_usleep(s->reconnect_time * 1000ULL * 1000ULL);
1042                 } else {
1043                     error_propagate(errp, err);
1044                     return -1;
1045                 }
1046             }
1047         }
1048     }
1049 
1050     return 0;
1051 }
1052 
1053 static void char_socket_finalize(Object *obj)
1054 {
1055     Chardev *chr = CHARDEV(obj);
1056     SocketChardev *s = SOCKET_CHARDEV(obj);
1057 
1058     tcp_chr_free_connection(chr);
1059     tcp_chr_reconn_timer_cancel(s);
1060     qapi_free_SocketAddress(s->addr);
1061     tcp_chr_telnet_destroy(s);
1062     g_free(s->telnet_init);
1063     if (s->listener) {
1064         qio_net_listener_set_client_func_full(s->listener, NULL, NULL,
1065                                               NULL, chr->gcontext);
1066         object_unref(OBJECT(s->listener));
1067     }
1068     if (s->tls_creds) {
1069         object_unref(OBJECT(s->tls_creds));
1070     }
1071     g_free(s->tls_authz);
1072 
1073     qemu_chr_be_event(chr, CHR_EVENT_CLOSED);
1074 }
1075 
1076 static void qemu_chr_socket_connected(QIOTask *task, void *opaque)
1077 {
1078     QIOChannelSocket *sioc = QIO_CHANNEL_SOCKET(qio_task_get_source(task));
1079     Chardev *chr = CHARDEV(opaque);
1080     SocketChardev *s = SOCKET_CHARDEV(chr);
1081     Error *err = NULL;
1082 
1083     s->connect_task = NULL;
1084 
1085     if (qio_task_propagate_error(task, &err)) {
1086         tcp_chr_change_state(s, TCP_CHARDEV_STATE_DISCONNECTED);
1087         check_report_connect_error(chr, err);
1088         error_free(err);
1089         goto cleanup;
1090     }
1091 
1092     s->connect_err_reported = false;
1093     tcp_chr_new_client(chr, sioc);
1094 
1095 cleanup:
1096     object_unref(OBJECT(sioc));
1097 }
1098 
1099 
1100 static void tcp_chr_connect_client_task(QIOTask *task,
1101                                         gpointer opaque)
1102 {
1103     QIOChannelSocket *ioc = QIO_CHANNEL_SOCKET(qio_task_get_source(task));
1104     SocketAddress *addr = opaque;
1105     Error *err = NULL;
1106 
1107     qio_channel_socket_connect_sync(ioc, addr, &err);
1108 
1109     qio_task_set_error(task, err);
1110 }
1111 
1112 
1113 static void tcp_chr_connect_client_async(Chardev *chr)
1114 {
1115     SocketChardev *s = SOCKET_CHARDEV(chr);
1116     QIOChannelSocket *sioc;
1117 
1118     tcp_chr_change_state(s, TCP_CHARDEV_STATE_CONNECTING);
1119     sioc = qio_channel_socket_new();
1120     tcp_chr_set_client_ioc_name(chr, sioc);
1121     /*
1122      * Normally code would use the qio_channel_socket_connect_async
1123      * method which uses a QIOTask + qio_task_set_error internally
1124      * to avoid blocking. The tcp_chr_wait_connected method, however,
1125      * needs a way to synchronize with completion of the background
1126      * connect task which can't be done with the QIOChannelSocket
1127      * async APIs. Thus we must use QIOTask directly to implement
1128      * the non-blocking concept locally.
1129      */
1130     s->connect_task = qio_task_new(OBJECT(sioc),
1131                                    qemu_chr_socket_connected,
1132                                    chr, NULL);
1133     qio_task_run_in_thread(s->connect_task,
1134                            tcp_chr_connect_client_task,
1135                            s->addr,
1136                            NULL,
1137                            chr->gcontext);
1138 }
1139 
1140 static gboolean socket_reconnect_timeout(gpointer opaque)
1141 {
1142     Chardev *chr = CHARDEV(opaque);
1143     SocketChardev *s = SOCKET_CHARDEV(opaque);
1144 
1145     qemu_mutex_lock(&chr->chr_write_lock);
1146     g_source_unref(s->reconnect_timer);
1147     s->reconnect_timer = NULL;
1148     qemu_mutex_unlock(&chr->chr_write_lock);
1149 
1150     if (chr->be_open) {
1151         return false;
1152     }
1153 
1154     tcp_chr_connect_client_async(chr);
1155 
1156     return false;
1157 }
1158 
1159 
1160 static int qmp_chardev_open_socket_server(Chardev *chr,
1161                                           bool is_telnet,
1162                                           bool is_waitconnect,
1163                                           Error **errp)
1164 {
1165     SocketChardev *s = SOCKET_CHARDEV(chr);
1166     char *name;
1167     if (is_telnet) {
1168         s->do_telnetopt = 1;
1169     }
1170     s->listener = qio_net_listener_new();
1171 
1172     name = g_strdup_printf("chardev-tcp-listener-%s", chr->label);
1173     qio_net_listener_set_name(s->listener, name);
1174     g_free(name);
1175 
1176     if (qio_net_listener_open_sync(s->listener, s->addr, 1, errp) < 0) {
1177         object_unref(OBJECT(s->listener));
1178         s->listener = NULL;
1179         return -1;
1180     }
1181 
1182     qapi_free_SocketAddress(s->addr);
1183     s->addr = socket_local_address(s->listener->sioc[0]->fd, errp);
1184     update_disconnected_filename(s);
1185 
1186     if (is_waitconnect) {
1187         tcp_chr_accept_server_sync(chr);
1188     } else {
1189         qio_net_listener_set_client_func_full(s->listener,
1190                                               tcp_chr_accept,
1191                                               chr, NULL,
1192                                               chr->gcontext);
1193     }
1194 
1195     return 0;
1196 }
1197 
1198 
1199 static int qmp_chardev_open_socket_client(Chardev *chr,
1200                                           int64_t reconnect,
1201                                           Error **errp)
1202 {
1203     SocketChardev *s = SOCKET_CHARDEV(chr);
1204 
1205     if (reconnect > 0) {
1206         s->reconnect_time = reconnect;
1207         tcp_chr_connect_client_async(chr);
1208         return 0;
1209     } else {
1210         return tcp_chr_connect_client_sync(chr, errp);
1211     }
1212 }
1213 
1214 
1215 static bool qmp_chardev_validate_socket(ChardevSocket *sock,
1216                                         SocketAddress *addr,
1217                                         Error **errp)
1218 {
1219     /* Validate any options which have a dependency on address type */
1220     switch (addr->type) {
1221     case SOCKET_ADDRESS_TYPE_FD:
1222         if (sock->has_reconnect) {
1223             error_setg(errp,
1224                        "'reconnect' option is incompatible with "
1225                        "'fd' address type");
1226             return false;
1227         }
1228         if (sock->has_tls_creds &&
1229             !(sock->has_server && sock->server)) {
1230             error_setg(errp,
1231                        "'tls_creds' option is incompatible with "
1232                        "'fd' address type as client");
1233             return false;
1234         }
1235         break;
1236 
1237     case SOCKET_ADDRESS_TYPE_UNIX:
1238         if (sock->has_tls_creds) {
1239             error_setg(errp,
1240                        "'tls_creds' option is incompatible with "
1241                        "'unix' address type");
1242             return false;
1243         }
1244         break;
1245 
1246     case SOCKET_ADDRESS_TYPE_INET:
1247         break;
1248 
1249     case SOCKET_ADDRESS_TYPE_VSOCK:
1250         if (sock->has_tls_creds) {
1251             error_setg(errp,
1252                        "'tls_creds' option is incompatible with "
1253                        "'vsock' address type");
1254             return false;
1255         }
1256 
1257     default:
1258         break;
1259     }
1260 
1261     if (sock->has_tls_authz && !sock->has_tls_creds) {
1262         error_setg(errp, "'tls_authz' option requires 'tls_creds' option");
1263         return false;
1264     }
1265 
1266     /* Validate any options which have a dependancy on client vs server */
1267     if (!sock->has_server || sock->server) {
1268         if (sock->has_reconnect) {
1269             error_setg(errp,
1270                        "'reconnect' option is incompatible with "
1271                        "socket in server listen mode");
1272             return false;
1273         }
1274     } else {
1275         if (sock->has_websocket && sock->websocket) {
1276             error_setg(errp, "%s", "Websocket client is not implemented");
1277             return false;
1278         }
1279         if (sock->has_wait) {
1280             warn_report("'wait' option is deprecated with "
1281                         "socket in client connect mode");
1282             if (sock->wait) {
1283                 error_setg(errp, "%s",
1284                            "'wait' option is incompatible with "
1285                            "socket in client connect mode");
1286                 return false;
1287             }
1288         }
1289     }
1290 
1291     return true;
1292 }
1293 
1294 
1295 static void qmp_chardev_open_socket(Chardev *chr,
1296                                     ChardevBackend *backend,
1297                                     bool *be_opened,
1298                                     Error **errp)
1299 {
1300     SocketChardev *s = SOCKET_CHARDEV(chr);
1301     ChardevSocket *sock = backend->u.socket.data;
1302     bool do_nodelay     = sock->has_nodelay ? sock->nodelay : false;
1303     bool is_listen      = sock->has_server  ? sock->server  : true;
1304     bool is_telnet      = sock->has_telnet  ? sock->telnet  : false;
1305     bool is_tn3270      = sock->has_tn3270  ? sock->tn3270  : false;
1306     bool is_waitconnect = sock->has_wait    ? sock->wait    : false;
1307     bool is_websock     = sock->has_websocket ? sock->websocket : false;
1308     int64_t reconnect   = sock->has_reconnect ? sock->reconnect : 0;
1309     SocketAddress *addr;
1310 
1311     s->is_listen = is_listen;
1312     s->is_telnet = is_telnet;
1313     s->is_tn3270 = is_tn3270;
1314     s->is_websock = is_websock;
1315     s->do_nodelay = do_nodelay;
1316     if (sock->tls_creds) {
1317         Object *creds;
1318         creds = object_resolve_path_component(
1319             object_get_objects_root(), sock->tls_creds);
1320         if (!creds) {
1321             error_setg(errp, "No TLS credentials with id '%s'",
1322                        sock->tls_creds);
1323             return;
1324         }
1325         s->tls_creds = (QCryptoTLSCreds *)
1326             object_dynamic_cast(creds,
1327                                 TYPE_QCRYPTO_TLS_CREDS);
1328         if (!s->tls_creds) {
1329             error_setg(errp, "Object with id '%s' is not TLS credentials",
1330                        sock->tls_creds);
1331             return;
1332         }
1333         object_ref(OBJECT(s->tls_creds));
1334         if (is_listen) {
1335             if (s->tls_creds->endpoint != QCRYPTO_TLS_CREDS_ENDPOINT_SERVER) {
1336                 error_setg(errp, "%s",
1337                            "Expected TLS credentials for server endpoint");
1338                 return;
1339             }
1340         } else {
1341             if (s->tls_creds->endpoint != QCRYPTO_TLS_CREDS_ENDPOINT_CLIENT) {
1342                 error_setg(errp, "%s",
1343                            "Expected TLS credentials for client endpoint");
1344                 return;
1345             }
1346         }
1347     }
1348     s->tls_authz = g_strdup(sock->tls_authz);
1349 
1350     s->addr = addr = socket_address_flatten(sock->addr);
1351 
1352     if (!qmp_chardev_validate_socket(sock, addr, errp)) {
1353         return;
1354     }
1355 
1356     qemu_chr_set_feature(chr, QEMU_CHAR_FEATURE_RECONNECTABLE);
1357     /* TODO SOCKET_ADDRESS_FD where fd has AF_UNIX */
1358     if (addr->type == SOCKET_ADDRESS_TYPE_UNIX) {
1359         qemu_chr_set_feature(chr, QEMU_CHAR_FEATURE_FD_PASS);
1360     }
1361 
1362     /* be isn't opened until we get a connection */
1363     *be_opened = false;
1364 
1365     update_disconnected_filename(s);
1366 
1367     if (s->is_listen) {
1368         if (qmp_chardev_open_socket_server(chr, is_telnet || is_tn3270,
1369                                            is_waitconnect, errp) < 0) {
1370             return;
1371         }
1372     } else {
1373         if (qmp_chardev_open_socket_client(chr, reconnect, errp) < 0) {
1374             return;
1375         }
1376     }
1377 }
1378 
1379 static void qemu_chr_parse_socket(QemuOpts *opts, ChardevBackend *backend,
1380                                   Error **errp)
1381 {
1382     const char *path = qemu_opt_get(opts, "path");
1383     const char *host = qemu_opt_get(opts, "host");
1384     const char *port = qemu_opt_get(opts, "port");
1385     const char *fd = qemu_opt_get(opts, "fd");
1386     bool tight = qemu_opt_get_bool(opts, "tight", true);
1387     bool abstract = qemu_opt_get_bool(opts, "abstract", false);
1388     SocketAddressLegacy *addr;
1389     ChardevSocket *sock;
1390 
1391     if ((!!path + !!fd + !!host) != 1) {
1392         error_setg(errp,
1393                    "Exactly one of 'path', 'fd' or 'host' required");
1394         return;
1395     }
1396 
1397     if (host && !port) {
1398         error_setg(errp, "chardev: socket: no port given");
1399         return;
1400     }
1401 
1402     backend->type = CHARDEV_BACKEND_KIND_SOCKET;
1403     sock = backend->u.socket.data = g_new0(ChardevSocket, 1);
1404     qemu_chr_parse_common(opts, qapi_ChardevSocket_base(sock));
1405 
1406     sock->has_nodelay = qemu_opt_get(opts, "delay");
1407     sock->nodelay = !qemu_opt_get_bool(opts, "delay", true);
1408     /*
1409      * We have different default to QMP for 'server', hence
1410      * we can't just check for existence of 'server'
1411      */
1412     sock->has_server = true;
1413     sock->server = qemu_opt_get_bool(opts, "server", false);
1414     sock->has_telnet = qemu_opt_get(opts, "telnet");
1415     sock->telnet = qemu_opt_get_bool(opts, "telnet", false);
1416     sock->has_tn3270 = qemu_opt_get(opts, "tn3270");
1417     sock->tn3270 = qemu_opt_get_bool(opts, "tn3270", false);
1418     sock->has_websocket = qemu_opt_get(opts, "websocket");
1419     sock->websocket = qemu_opt_get_bool(opts, "websocket", false);
1420     /*
1421      * We have different default to QMP for 'wait' when 'server'
1422      * is set, hence we can't just check for existence of 'wait'
1423      */
1424     sock->has_wait = qemu_opt_find(opts, "wait") || sock->server;
1425     sock->wait = qemu_opt_get_bool(opts, "wait", true);
1426     sock->has_reconnect = qemu_opt_find(opts, "reconnect");
1427     sock->reconnect = qemu_opt_get_number(opts, "reconnect", 0);
1428     sock->has_tls_creds = qemu_opt_get(opts, "tls-creds");
1429     sock->tls_creds = g_strdup(qemu_opt_get(opts, "tls-creds"));
1430     sock->has_tls_authz = qemu_opt_get(opts, "tls-authz");
1431     sock->tls_authz = g_strdup(qemu_opt_get(opts, "tls-authz"));
1432 
1433     addr = g_new0(SocketAddressLegacy, 1);
1434     if (path) {
1435         UnixSocketAddress *q_unix;
1436         addr->type = SOCKET_ADDRESS_LEGACY_KIND_UNIX;
1437         q_unix = addr->u.q_unix.data = g_new0(UnixSocketAddress, 1);
1438         q_unix->path = g_strdup(path);
1439         q_unix->tight = tight;
1440         q_unix->abstract = abstract;
1441     } else if (host) {
1442         addr->type = SOCKET_ADDRESS_LEGACY_KIND_INET;
1443         addr->u.inet.data = g_new(InetSocketAddress, 1);
1444         *addr->u.inet.data = (InetSocketAddress) {
1445             .host = g_strdup(host),
1446             .port = g_strdup(port),
1447             .has_to = qemu_opt_get(opts, "to"),
1448             .to = qemu_opt_get_number(opts, "to", 0),
1449             .has_ipv4 = qemu_opt_get(opts, "ipv4"),
1450             .ipv4 = qemu_opt_get_bool(opts, "ipv4", 0),
1451             .has_ipv6 = qemu_opt_get(opts, "ipv6"),
1452             .ipv6 = qemu_opt_get_bool(opts, "ipv6", 0),
1453         };
1454     } else if (fd) {
1455         addr->type = SOCKET_ADDRESS_LEGACY_KIND_FD;
1456         addr->u.fd.data = g_new(String, 1);
1457         addr->u.fd.data->str = g_strdup(fd);
1458     } else {
1459         g_assert_not_reached();
1460     }
1461     sock->addr = addr;
1462 }
1463 
1464 static void
1465 char_socket_get_addr(Object *obj, Visitor *v, const char *name,
1466                      void *opaque, Error **errp)
1467 {
1468     SocketChardev *s = SOCKET_CHARDEV(obj);
1469 
1470     visit_type_SocketAddress(v, name, &s->addr, errp);
1471 }
1472 
1473 static bool
1474 char_socket_get_connected(Object *obj, Error **errp)
1475 {
1476     SocketChardev *s = SOCKET_CHARDEV(obj);
1477 
1478     return s->state == TCP_CHARDEV_STATE_CONNECTED;
1479 }
1480 
1481 static void char_socket_class_init(ObjectClass *oc, void *data)
1482 {
1483     ChardevClass *cc = CHARDEV_CLASS(oc);
1484 
1485     cc->parse = qemu_chr_parse_socket;
1486     cc->open = qmp_chardev_open_socket;
1487     cc->chr_wait_connected = tcp_chr_wait_connected;
1488     cc->chr_write = tcp_chr_write;
1489     cc->chr_sync_read = tcp_chr_sync_read;
1490     cc->chr_disconnect = tcp_chr_disconnect;
1491     cc->get_msgfds = tcp_get_msgfds;
1492     cc->set_msgfds = tcp_set_msgfds;
1493     cc->chr_add_client = tcp_chr_add_client;
1494     cc->chr_add_watch = tcp_chr_add_watch;
1495     cc->chr_update_read_handler = tcp_chr_update_read_handler;
1496 
1497     object_class_property_add(oc, "addr", "SocketAddress",
1498                               char_socket_get_addr, NULL,
1499                               NULL, NULL);
1500 
1501     object_class_property_add_bool(oc, "connected", char_socket_get_connected,
1502                                    NULL);
1503 }
1504 
1505 static const TypeInfo char_socket_type_info = {
1506     .name = TYPE_CHARDEV_SOCKET,
1507     .parent = TYPE_CHARDEV,
1508     .instance_size = sizeof(SocketChardev),
1509     .instance_finalize = char_socket_finalize,
1510     .class_init = char_socket_class_init,
1511 };
1512 
1513 static void register_types(void)
1514 {
1515     type_register_static(&char_socket_type_info);
1516 }
1517 
1518 type_init(register_types);
1519