xref: /openbmc/qemu/qga/main.c (revision 3390a0de)
1 /*
2  * QEMU Guest Agent
3  *
4  * Copyright IBM Corp. 2011
5  *
6  * Authors:
7  *  Adam Litke        <aglitke@linux.vnet.ibm.com>
8  *  Michael Roth      <mdroth@linux.vnet.ibm.com>
9  *
10  * This work is licensed under the terms of the GNU GPL, version 2 or later.
11  * See the COPYING file in the top-level directory.
12  */
13 
14 #include "qemu/osdep.h"
15 #include <getopt.h>
16 #include <glib/gstdio.h>
17 #ifndef _WIN32
18 #include <syslog.h>
19 #include <sys/wait.h>
20 #endif
21 #include "qemu/help-texts.h"
22 #include "qapi/qmp/json-parser.h"
23 #include "qapi/qmp/qdict.h"
24 #include "qapi/qmp/qjson.h"
25 #include "guest-agent-core.h"
26 #include "qga-qapi-init-commands.h"
27 #include "qapi/error.h"
28 #include "channel.h"
29 #include "qemu/cutils.h"
30 #include "qemu/help_option.h"
31 #include "qemu/sockets.h"
32 #include "qemu/systemd.h"
33 #include "qemu-version.h"
34 #ifdef _WIN32
35 #include <dbt.h>
36 #include "qga/service-win32.h"
37 #include "qga/vss-win32.h"
38 #endif
39 #include "commands-common.h"
40 
41 #ifndef _WIN32
42 #ifdef CONFIG_BSD
43 #define QGA_VIRTIO_PATH_DEFAULT "/dev/vtcon/org.qemu.guest_agent.0"
44 #else /* CONFIG_BSD */
45 #define QGA_VIRTIO_PATH_DEFAULT "/dev/virtio-ports/org.qemu.guest_agent.0"
46 #endif /* CONFIG_BSD */
47 #define QGA_SERIAL_PATH_DEFAULT "/dev/ttyS0"
48 #define QGA_STATE_RELATIVE_DIR  "run"
49 #else
50 #define QGA_VIRTIO_PATH_DEFAULT "\\\\.\\Global\\org.qemu.guest_agent.0"
51 #define QGA_STATE_RELATIVE_DIR  "qemu-ga"
52 #define QGA_SERIAL_PATH_DEFAULT "COM1"
53 #endif
54 #ifdef CONFIG_FSFREEZE
55 #define QGA_FSFREEZE_HOOK_DEFAULT CONFIG_QEMU_CONFDIR "/fsfreeze-hook"
56 #endif
57 #define QGA_SENTINEL_BYTE 0xFF
58 #define QGA_CONF_DEFAULT CONFIG_QEMU_CONFDIR G_DIR_SEPARATOR_S "qemu-ga.conf"
59 #define QGA_RETRY_INTERVAL 5
60 
61 static struct {
62     const char *state_dir;
63     const char *pidfile;
64 } dfl_pathnames;
65 
66 typedef struct GAPersistentState {
67 #define QGA_PSTATE_DEFAULT_FD_COUNTER 1000
68     int64_t fd_counter;
69 } GAPersistentState;
70 
71 typedef struct GAConfig GAConfig;
72 
73 struct GAConfig {
74     char *channel_path;
75     char *method;
76     char *log_filepath;
77     char *pid_filepath;
78 #ifdef CONFIG_FSFREEZE
79     char *fsfreeze_hook;
80 #endif
81     char *state_dir;
82 #ifdef _WIN32
83     const char *service;
84 #endif
85     gchar *bliststr; /* blockedrpcs may point to this string */
86     gchar *aliststr; /* allowedrpcs may point to this string */
87     GList *blockedrpcs;
88     GList *allowedrpcs;
89     int daemonize;
90     GLogLevelFlags log_level;
91     int dumpconf;
92     bool retry_path;
93 };
94 
95 struct GAState {
96     JSONMessageParser parser;
97     GMainLoop *main_loop;
98     GAChannel *channel;
99     bool virtio; /* fastpath to check for virtio to deal with poll() quirks */
100     GACommandState *command_state;
101     GLogLevelFlags log_level;
102     FILE *log_file;
103     bool logging_enabled;
104 #ifdef _WIN32
105     GAService service;
106     HANDLE wakeup_event;
107     HANDLE event_log;
108 #endif
109     bool delimit_response;
110     bool frozen;
111     GList *blockedrpcs;
112     GList *allowedrpcs;
113     char *state_filepath_isfrozen;
114     struct {
115         const char *log_filepath;
116         const char *pid_filepath;
117     } deferred_options;
118 #ifdef CONFIG_FSFREEZE
119     const char *fsfreeze_hook;
120 #endif
121     gchar *pstate_filepath;
122     GAPersistentState pstate;
123     GAConfig *config;
124     int socket_activation;
125     bool force_exit;
126 };
127 
128 struct GAState *ga_state;
129 QmpCommandList ga_commands;
130 
131 /* commands that are safe to issue while filesystems are frozen */
132 static const char *ga_freeze_allowlist[] = {
133     "guest-ping",
134     "guest-info",
135     "guest-sync",
136     "guest-sync-delimited",
137     "guest-fsfreeze-status",
138     "guest-fsfreeze-thaw",
139     NULL
140 };
141 
142 #ifdef _WIN32
143 DWORD WINAPI service_ctrl_handler(DWORD ctrl, DWORD type, LPVOID data,
144                                   LPVOID ctx);
145 DWORD WINAPI handle_serial_device_events(DWORD type, LPVOID data);
146 VOID WINAPI service_main(DWORD argc, TCHAR *argv[]);
147 #endif
148 static int run_agent(GAState *s);
149 static void stop_agent(GAState *s, bool requested);
150 
151 static void
152 init_dfl_pathnames(void)
153 {
154     g_autofree char *state = qemu_get_local_state_dir();
155 
156     g_assert(dfl_pathnames.state_dir == NULL);
157     g_assert(dfl_pathnames.pidfile == NULL);
158     dfl_pathnames.state_dir = g_build_filename(state, QGA_STATE_RELATIVE_DIR, NULL);
159     dfl_pathnames.pidfile = g_build_filename(state, QGA_STATE_RELATIVE_DIR, "qemu-ga.pid", NULL);
160 }
161 
162 static void quit_handler(int sig)
163 {
164     /* if we're frozen, don't exit unless we're absolutely forced to,
165      * because it's basically impossible for graceful exit to complete
166      * unless all log/pid files are on unfreezable filesystems. there's
167      * also a very likely chance killing the agent before unfreezing
168      * the filesystems is a mistake (or will be viewed as one later).
169      * On Windows the freeze interval is limited to 10 seconds, so
170      * we should quit, but first we should wait for the timeout, thaw
171      * the filesystem and quit.
172      */
173     if (ga_is_frozen(ga_state)) {
174 #ifdef _WIN32
175         int i = 0;
176         Error *err = NULL;
177         HANDLE hEventTimeout;
178 
179         g_debug("Thawing filesystems before exiting");
180 
181         hEventTimeout = OpenEvent(EVENT_ALL_ACCESS, FALSE, EVENT_NAME_TIMEOUT);
182         if (hEventTimeout) {
183             WaitForSingleObject(hEventTimeout, 0);
184             CloseHandle(hEventTimeout);
185         }
186         qga_vss_fsfreeze(&i, false, NULL, &err);
187         if (err) {
188             g_debug("Error unfreezing filesystems prior to exiting: %s",
189                 error_get_pretty(err));
190             error_free(err);
191         }
192 #else
193         return;
194 #endif
195     }
196     g_debug("received signal num %d, quitting", sig);
197 
198     stop_agent(ga_state, true);
199 }
200 
201 #ifndef _WIN32
202 static gboolean register_signal_handlers(void)
203 {
204     struct sigaction sigact;
205     int ret;
206 
207     memset(&sigact, 0, sizeof(struct sigaction));
208     sigact.sa_handler = quit_handler;
209 
210     ret = sigaction(SIGINT, &sigact, NULL);
211     if (ret == -1) {
212         g_error("error configuring signal handler: %s", strerror(errno));
213     }
214     ret = sigaction(SIGTERM, &sigact, NULL);
215     if (ret == -1) {
216         g_error("error configuring signal handler: %s", strerror(errno));
217     }
218 
219     sigact.sa_handler = SIG_IGN;
220     if (sigaction(SIGPIPE, &sigact, NULL) != 0) {
221         g_error("error configuring SIGPIPE signal handler: %s",
222                 strerror(errno));
223     }
224 
225     return true;
226 }
227 
228 /* TODO: use this in place of all post-fork() fclose(std*) callers */
229 void reopen_fd_to_null(int fd)
230 {
231     int nullfd;
232 
233     nullfd = open("/dev/null", O_RDWR);
234     if (nullfd < 0) {
235         return;
236     }
237 
238     dup2(nullfd, fd);
239 
240     if (nullfd != fd) {
241         close(nullfd);
242     }
243 }
244 #endif
245 
246 static void usage(const char *cmd)
247 {
248 #ifdef CONFIG_FSFREEZE
249     g_autofree char *fsfreeze_hook = get_relocated_path(QGA_FSFREEZE_HOOK_DEFAULT);
250 #endif
251 
252     printf(
253 "Usage: %s [-m <method> -p <path>] [<options>]\n"
254 "QEMU Guest Agent " QEMU_FULL_VERSION "\n"
255 QEMU_COPYRIGHT "\n"
256 "\n"
257 "  -m, --method      transport method: one of unix-listen, virtio-serial,\n"
258 "                    isa-serial, or vsock-listen (virtio-serial is the default)\n"
259 "  -p, --path        device/socket path (the default for virtio-serial is:\n"
260 "                    %s,\n"
261 "                    the default for isa-serial is:\n"
262 "                    %s).\n"
263 "                    Socket addresses for vsock-listen are written as\n"
264 "                    <cid>:<port>.\n"
265 "  -l, --logfile     set logfile path, logs to stderr by default\n"
266 "  -f, --pidfile     specify pidfile (default is %s)\n"
267 #ifdef CONFIG_FSFREEZE
268 "  -F, --fsfreeze-hook\n"
269 "                    enable fsfreeze hook. Accepts an optional argument that\n"
270 "                    specifies script to run on freeze/thaw. Script will be\n"
271 "                    called with 'freeze'/'thaw' arguments accordingly.\n"
272 "                    (default is %s)\n"
273 "                    If using -F with an argument, do not follow -F with a\n"
274 "                    space.\n"
275 "                    (for example: -F/var/run/fsfreezehook.sh)\n"
276 #endif
277 "  -t, --statedir    specify dir to store state information (absolute paths\n"
278 "                    only, default is %s)\n"
279 "  -v, --verbose     log extra debugging information\n"
280 "  -V, --version     print version information and exit\n"
281 "  -d, --daemonize   become a daemon\n"
282 #ifdef _WIN32
283 "  -s, --service     service commands: install, uninstall, vss-install, vss-uninstall\n"
284 #endif
285 "  -b, --block-rpcs  comma-separated list of RPCs to disable (no spaces,\n"
286 "                    use \"--block-rpcs=help\" to list available RPCs)\n"
287 "  -a, --allow-rpcs  comma-separated list of RPCs to enable (no spaces,\n"
288 "                    use \"--allow-rpcs=help\" to list available RPCs)\n"
289 "  -D, --dump-conf   dump a qemu-ga config file based on current config\n"
290 "                    options / command-line parameters to stdout\n"
291 "  -r, --retry-path  attempt re-opening path if it's unavailable or closed\n"
292 "                    due to an error which may be recoverable in the future\n"
293 "                    (virtio-serial driver re-install, serial device hot\n"
294 "                    plug/unplug, etc.)\n"
295 "  -h, --help        display this help and exit\n"
296 "\n"
297 QEMU_HELP_BOTTOM "\n"
298     , cmd, QGA_VIRTIO_PATH_DEFAULT, QGA_SERIAL_PATH_DEFAULT,
299     dfl_pathnames.pidfile,
300 #ifdef CONFIG_FSFREEZE
301     fsfreeze_hook,
302 #endif
303     dfl_pathnames.state_dir);
304 }
305 
306 static const char *ga_log_level_str(GLogLevelFlags level)
307 {
308     switch (level & G_LOG_LEVEL_MASK) {
309     case G_LOG_LEVEL_ERROR:
310         return "error";
311     case G_LOG_LEVEL_CRITICAL:
312         return "critical";
313     case G_LOG_LEVEL_WARNING:
314         return "warning";
315     case G_LOG_LEVEL_MESSAGE:
316         return "message";
317     case G_LOG_LEVEL_INFO:
318         return "info";
319     case G_LOG_LEVEL_DEBUG:
320         return "debug";
321     default:
322         return "user";
323     }
324 }
325 
326 bool ga_logging_enabled(GAState *s)
327 {
328     return s->logging_enabled;
329 }
330 
331 void ga_disable_logging(GAState *s)
332 {
333     s->logging_enabled = false;
334 }
335 
336 void ga_enable_logging(GAState *s)
337 {
338     s->logging_enabled = true;
339 }
340 
341 static int glib_log_level_to_system(int level)
342 {
343     switch (level) {
344 #ifndef _WIN32
345     case G_LOG_LEVEL_ERROR:
346         return LOG_ERR;
347     case G_LOG_LEVEL_CRITICAL:
348         return LOG_CRIT;
349     case G_LOG_LEVEL_WARNING:
350         return LOG_WARNING;
351     case G_LOG_LEVEL_MESSAGE:
352         return LOG_NOTICE;
353     case G_LOG_LEVEL_DEBUG:
354         return LOG_DEBUG;
355     case G_LOG_LEVEL_INFO:
356     default:
357         return LOG_INFO;
358 #else
359     case G_LOG_LEVEL_ERROR:
360     case G_LOG_LEVEL_CRITICAL:
361         return EVENTLOG_ERROR_TYPE;
362     case G_LOG_LEVEL_WARNING:
363         return EVENTLOG_WARNING_TYPE;
364     case G_LOG_LEVEL_MESSAGE:
365     case G_LOG_LEVEL_INFO:
366     case G_LOG_LEVEL_DEBUG:
367     default:
368         return EVENTLOG_INFORMATION_TYPE;
369 #endif
370     }
371 }
372 
373 static void ga_log(const gchar *domain, GLogLevelFlags level,
374                    const gchar *msg, gpointer opaque)
375 {
376     GAState *s = opaque;
377     const char *level_str = ga_log_level_str(level);
378 
379     if (!ga_logging_enabled(s)) {
380         return;
381     }
382 
383     level &= G_LOG_LEVEL_MASK;
384     if (g_strcmp0(domain, "syslog") == 0) {
385 #ifndef _WIN32
386         syslog(glib_log_level_to_system(level), "%s: %s", level_str, msg);
387 #else
388         ReportEvent(s->event_log, glib_log_level_to_system(level),
389                     0, 1, NULL, 1, 0, &msg, NULL);
390 #endif
391     } else if (level & s->log_level) {
392         g_autoptr(GDateTime) now = g_date_time_new_now_utc();
393         g_autofree char *nowstr = g_date_time_format(now, "%s.%f");
394         fprintf(s->log_file, "%s: %s: %s\n", nowstr, level_str, msg);
395         fflush(s->log_file);
396     }
397 }
398 
399 void ga_set_response_delimited(GAState *s)
400 {
401     s->delimit_response = true;
402 }
403 
404 static FILE *ga_open_logfile(const char *logfile)
405 {
406     FILE *f;
407 
408     f = fopen(logfile, "a");
409     if (!f) {
410         return NULL;
411     }
412 
413     qemu_set_cloexec(fileno(f));
414     return f;
415 }
416 
417 static gint ga_strcmp(gconstpointer str1, gconstpointer str2)
418 {
419     return strcmp(str1, str2);
420 }
421 
422 /* disable commands that aren't safe for fsfreeze */
423 static void ga_disable_not_allowed_freeze(const QmpCommand *cmd, void *opaque)
424 {
425     bool allowed = false;
426     int i = 0;
427     const char *name = qmp_command_name(cmd);
428 
429     while (ga_freeze_allowlist[i] != NULL) {
430         if (strcmp(name, ga_freeze_allowlist[i]) == 0) {
431             allowed = true;
432         }
433         i++;
434     }
435     if (!allowed) {
436         g_debug("disabling command: %s", name);
437         qmp_disable_command(&ga_commands, name, "the agent is in frozen state");
438     }
439 }
440 
441 /* [re-]enable all commands, except those explicitly blocked by user */
442 static void ga_enable_non_blocked(const QmpCommand *cmd, void *opaque)
443 {
444     GAState *s = opaque;
445     GList *blockedrpcs = s->blockedrpcs;
446     GList *allowedrpcs = s->allowedrpcs;
447     const char *name = qmp_command_name(cmd);
448 
449     if (g_list_find_custom(blockedrpcs, name, ga_strcmp) == NULL) {
450         if (qmp_command_is_enabled(cmd)) {
451             return;
452         }
453 
454         if (allowedrpcs &&
455             g_list_find_custom(allowedrpcs, name, ga_strcmp) == NULL) {
456             return;
457         }
458 
459         g_debug("enabling command: %s", name);
460         qmp_enable_command(&ga_commands, name);
461     }
462 }
463 
464 /* disable commands that aren't allowed */
465 static void ga_disable_not_allowed(const QmpCommand *cmd, void *opaque)
466 {
467     GList *allowedrpcs = opaque;
468     const char *name = qmp_command_name(cmd);
469 
470     if (g_list_find_custom(allowedrpcs, name, ga_strcmp) == NULL) {
471         g_debug("disabling command: %s", name);
472         qmp_disable_command(&ga_commands, name, "the command is not allowed");
473     }
474 }
475 
476 static bool ga_create_file(const char *path)
477 {
478     int fd = open(path, O_CREAT | O_WRONLY, S_IWUSR | S_IRUSR);
479     if (fd == -1) {
480         g_warning("unable to open/create file %s: %s", path, strerror(errno));
481         return false;
482     }
483     close(fd);
484     return true;
485 }
486 
487 static bool ga_delete_file(const char *path)
488 {
489     int ret = unlink(path);
490     if (ret == -1) {
491         g_warning("unable to delete file: %s: %s", path, strerror(errno));
492         return false;
493     }
494 
495     return true;
496 }
497 
498 bool ga_is_frozen(GAState *s)
499 {
500     return s->frozen;
501 }
502 
503 void ga_set_frozen(GAState *s)
504 {
505     if (ga_is_frozen(s)) {
506         return;
507     }
508     /* disable all forbidden (for frozen state) commands */
509     qmp_for_each_command(&ga_commands, ga_disable_not_allowed_freeze, NULL);
510     g_warning("disabling logging due to filesystem freeze");
511     ga_disable_logging(s);
512     s->frozen = true;
513     if (!ga_create_file(s->state_filepath_isfrozen)) {
514         g_warning("unable to create %s, fsfreeze may not function properly",
515                   s->state_filepath_isfrozen);
516     }
517 }
518 
519 void ga_unset_frozen(GAState *s)
520 {
521     if (!ga_is_frozen(s)) {
522         return;
523     }
524 
525     /* if we delayed creation/opening of pid/log files due to being
526      * in a frozen state at start up, do it now
527      */
528     if (s->deferred_options.log_filepath) {
529         s->log_file = ga_open_logfile(s->deferred_options.log_filepath);
530         if (!s->log_file) {
531             s->log_file = stderr;
532         }
533         s->deferred_options.log_filepath = NULL;
534     }
535     ga_enable_logging(s);
536     g_warning("logging re-enabled due to filesystem unfreeze");
537     if (s->deferred_options.pid_filepath) {
538         Error *err = NULL;
539 
540         if (!qemu_write_pidfile(s->deferred_options.pid_filepath, &err)) {
541             g_warning("%s", error_get_pretty(err));
542             error_free(err);
543         }
544         s->deferred_options.pid_filepath = NULL;
545     }
546 
547     /* enable all disabled, non-blocked and allowed commands */
548     qmp_for_each_command(&ga_commands, ga_enable_non_blocked, s);
549     s->frozen = false;
550     if (!ga_delete_file(s->state_filepath_isfrozen)) {
551         g_warning("unable to delete %s, fsfreeze may not function properly",
552                   s->state_filepath_isfrozen);
553     }
554 }
555 
556 #ifdef CONFIG_FSFREEZE
557 const char *ga_fsfreeze_hook(GAState *s)
558 {
559     return s->fsfreeze_hook;
560 }
561 #endif
562 
563 static void become_daemon(const char *pidfile)
564 {
565 #ifndef _WIN32
566     pid_t pid, sid;
567 
568     pid = fork();
569     if (pid < 0) {
570         exit(EXIT_FAILURE);
571     }
572     if (pid > 0) {
573         exit(EXIT_SUCCESS);
574     }
575 
576     if (pidfile) {
577         Error *err = NULL;
578 
579         if (!qemu_write_pidfile(pidfile, &err)) {
580             g_critical("%s", error_get_pretty(err));
581             error_free(err);
582             exit(EXIT_FAILURE);
583         }
584     }
585 
586     umask(S_IRWXG | S_IRWXO);
587     sid = setsid();
588     if (sid < 0) {
589         goto fail;
590     }
591     if ((chdir("/")) < 0) {
592         goto fail;
593     }
594 
595     reopen_fd_to_null(STDIN_FILENO);
596     reopen_fd_to_null(STDOUT_FILENO);
597     reopen_fd_to_null(STDERR_FILENO);
598     return;
599 
600 fail:
601     if (pidfile) {
602         unlink(pidfile);
603     }
604     g_critical("failed to daemonize");
605     exit(EXIT_FAILURE);
606 #endif
607 }
608 
609 static int send_response(GAState *s, const QDict *rsp)
610 {
611     GString *response;
612     GIOStatus status;
613 
614     g_assert(s->channel);
615 
616     if (!rsp) {
617         return 0;
618     }
619 
620     response = qobject_to_json(QOBJECT(rsp));
621     if (!response) {
622         return -EINVAL;
623     }
624 
625     if (s->delimit_response) {
626         s->delimit_response = false;
627         g_string_prepend_c(response, QGA_SENTINEL_BYTE);
628     }
629 
630     g_string_append_c(response, '\n');
631     status = ga_channel_write_all(s->channel, response->str, response->len);
632     g_string_free(response, true);
633     if (status != G_IO_STATUS_NORMAL) {
634         return -EIO;
635     }
636 
637     return 0;
638 }
639 
640 /* handle requests/control events coming in over the channel */
641 static void process_event(void *opaque, QObject *obj, Error *err)
642 {
643     GAState *s = opaque;
644     QDict *rsp;
645     int ret;
646 
647     g_debug("process_event: called");
648     assert(!obj != !err);
649     if (err) {
650         rsp = qmp_error_response(err);
651         goto end;
652     }
653 
654     g_debug("processing command");
655     rsp = qmp_dispatch(&ga_commands, obj, false, NULL);
656 
657 end:
658     ret = send_response(s, rsp);
659     if (ret < 0) {
660         g_warning("error sending error response: %s", strerror(-ret));
661     }
662     qobject_unref(rsp);
663     qobject_unref(obj);
664 }
665 
666 /* false return signals GAChannel to close the current client connection */
667 static gboolean channel_event_cb(GIOCondition condition, gpointer data)
668 {
669     GAState *s = data;
670     gchar buf[QGA_READ_COUNT_DEFAULT + 1];
671     gsize count;
672     GIOStatus status = ga_channel_read(s->channel, buf, QGA_READ_COUNT_DEFAULT, &count);
673     switch (status) {
674     case G_IO_STATUS_ERROR:
675         g_warning("error reading channel");
676         stop_agent(s, false);
677         return false;
678     case G_IO_STATUS_NORMAL:
679         buf[count] = 0;
680         g_debug("read data, count: %d, data: %s", (int)count, buf);
681         json_message_parser_feed(&s->parser, (char *)buf, (int)count);
682         break;
683     case G_IO_STATUS_EOF:
684         g_debug("received EOF");
685         if (!s->virtio) {
686             return false;
687         }
688         /* fall through */
689     case G_IO_STATUS_AGAIN:
690         /* virtio causes us to spin here when no process is attached to
691          * host-side chardev. sleep a bit to mitigate this
692          */
693         if (s->virtio) {
694             g_usleep(G_USEC_PER_SEC / 10);
695         }
696         return true;
697     default:
698         g_warning("unknown channel read status, closing");
699         return false;
700     }
701     return true;
702 }
703 
704 static gboolean channel_init(GAState *s, const gchar *method, const gchar *path,
705                              int listen_fd)
706 {
707     GAChannelMethod channel_method;
708 
709     if (strcmp(method, "virtio-serial") == 0) {
710         s->virtio = true; /* virtio requires special handling in some cases */
711         channel_method = GA_CHANNEL_VIRTIO_SERIAL;
712     } else if (strcmp(method, "isa-serial") == 0) {
713         channel_method = GA_CHANNEL_ISA_SERIAL;
714     } else if (strcmp(method, "unix-listen") == 0) {
715         channel_method = GA_CHANNEL_UNIX_LISTEN;
716     } else if (strcmp(method, "vsock-listen") == 0) {
717         channel_method = GA_CHANNEL_VSOCK_LISTEN;
718     } else {
719         g_critical("unsupported channel method/type: %s", method);
720         return false;
721     }
722 
723     s->channel = ga_channel_new(channel_method, path, listen_fd,
724                                 channel_event_cb, s);
725     if (!s->channel) {
726         g_critical("failed to create guest agent channel");
727         return false;
728     }
729 
730     return true;
731 }
732 
733 #ifdef _WIN32
734 DWORD WINAPI handle_serial_device_events(DWORD type, LPVOID data)
735 {
736     DWORD ret = NO_ERROR;
737     PDEV_BROADCAST_HDR broadcast_header = (PDEV_BROADCAST_HDR)data;
738 
739     if (broadcast_header->dbch_devicetype == DBT_DEVTYP_DEVICEINTERFACE) {
740         switch (type) {
741             /* Device inserted */
742         case DBT_DEVICEARRIVAL:
743             /* Start QEMU-ga's service */
744             if (!SetEvent(ga_state->wakeup_event)) {
745                 ret = GetLastError();
746             }
747             break;
748             /* Device removed */
749         case DBT_DEVICEQUERYREMOVE:
750         case DBT_DEVICEREMOVEPENDING:
751         case DBT_DEVICEREMOVECOMPLETE:
752             /* Stop QEMU-ga's service */
753             if (!ResetEvent(ga_state->wakeup_event)) {
754                 ret = GetLastError();
755             }
756             break;
757         default:
758             ret = ERROR_CALL_NOT_IMPLEMENTED;
759         }
760     }
761     return ret;
762 }
763 
764 DWORD WINAPI service_ctrl_handler(DWORD ctrl, DWORD type, LPVOID data,
765                                   LPVOID ctx)
766 {
767     DWORD ret = NO_ERROR;
768     GAService *service = &ga_state->service;
769 
770     switch (ctrl) {
771     case SERVICE_CONTROL_STOP:
772     case SERVICE_CONTROL_SHUTDOWN:
773         quit_handler(SIGTERM);
774         SetEvent(ga_state->wakeup_event);
775         service->status.dwCurrentState = SERVICE_STOP_PENDING;
776         SetServiceStatus(service->status_handle, &service->status);
777         break;
778     case SERVICE_CONTROL_DEVICEEVENT:
779         handle_serial_device_events(type, data);
780         break;
781 
782     default:
783         ret = ERROR_CALL_NOT_IMPLEMENTED;
784     }
785     return ret;
786 }
787 
788 VOID WINAPI service_main(DWORD argc, TCHAR *argv[])
789 {
790     GAService *service = &ga_state->service;
791 
792     service->status_handle = RegisterServiceCtrlHandlerEx(QGA_SERVICE_NAME,
793         service_ctrl_handler, NULL);
794 
795     if (service->status_handle == 0) {
796         g_critical("Failed to register extended requests function!\n");
797         return;
798     }
799 
800     service->status.dwServiceType = SERVICE_WIN32;
801     service->status.dwCurrentState = SERVICE_RUNNING;
802     service->status.dwControlsAccepted = SERVICE_ACCEPT_STOP | SERVICE_ACCEPT_SHUTDOWN;
803     service->status.dwWin32ExitCode = NO_ERROR;
804     service->status.dwServiceSpecificExitCode = NO_ERROR;
805     service->status.dwCheckPoint = 0;
806     service->status.dwWaitHint = 0;
807     DEV_BROADCAST_DEVICEINTERFACE notification_filter;
808     ZeroMemory(&notification_filter, sizeof(notification_filter));
809     notification_filter.dbcc_devicetype = DBT_DEVTYP_DEVICEINTERFACE;
810     notification_filter.dbcc_size = sizeof(DEV_BROADCAST_DEVICEINTERFACE);
811     notification_filter.dbcc_classguid = GUID_VIOSERIAL_PORT;
812 
813     service->device_notification_handle =
814         RegisterDeviceNotification(service->status_handle,
815             &notification_filter, DEVICE_NOTIFY_SERVICE_HANDLE);
816     if (!service->device_notification_handle) {
817         g_critical("Failed to register device notification handle!\n");
818         return;
819     }
820     SetServiceStatus(service->status_handle, &service->status);
821 
822     run_agent(ga_state);
823 
824     UnregisterDeviceNotification(service->device_notification_handle);
825     service->status.dwCurrentState = SERVICE_STOPPED;
826     SetServiceStatus(service->status_handle, &service->status);
827 }
828 #endif
829 
830 static void set_persistent_state_defaults(GAPersistentState *pstate)
831 {
832     g_assert(pstate);
833     pstate->fd_counter = QGA_PSTATE_DEFAULT_FD_COUNTER;
834 }
835 
836 static void persistent_state_from_keyfile(GAPersistentState *pstate,
837                                           GKeyFile *keyfile)
838 {
839     g_assert(pstate);
840     g_assert(keyfile);
841     /* if any fields are missing, either because the file was tampered with
842      * by agents of chaos, or because the field wasn't present at the time the
843      * file was created, the best we can ever do is start over with the default
844      * values. so load them now, and ignore any errors in accessing key-value
845      * pairs
846      */
847     set_persistent_state_defaults(pstate);
848 
849     if (g_key_file_has_key(keyfile, "global", "fd_counter", NULL)) {
850         pstate->fd_counter =
851             g_key_file_get_integer(keyfile, "global", "fd_counter", NULL);
852     }
853 }
854 
855 static void persistent_state_to_keyfile(const GAPersistentState *pstate,
856                                         GKeyFile *keyfile)
857 {
858     g_assert(pstate);
859     g_assert(keyfile);
860 
861     g_key_file_set_integer(keyfile, "global", "fd_counter", pstate->fd_counter);
862 }
863 
864 static gboolean write_persistent_state(const GAPersistentState *pstate,
865                                        const gchar *path)
866 {
867     GKeyFile *keyfile = g_key_file_new();
868     GError *gerr = NULL;
869     gboolean ret = true;
870     gchar *data = NULL;
871     gsize data_len;
872 
873     g_assert(pstate);
874 
875     persistent_state_to_keyfile(pstate, keyfile);
876     data = g_key_file_to_data(keyfile, &data_len, &gerr);
877     if (gerr) {
878         g_critical("failed to convert persistent state to string: %s",
879                    gerr->message);
880         ret = false;
881         goto out;
882     }
883 
884     g_file_set_contents(path, data, data_len, &gerr);
885     if (gerr) {
886         g_critical("failed to write persistent state to %s: %s",
887                     path, gerr->message);
888         ret = false;
889         goto out;
890     }
891 
892 out:
893     if (gerr) {
894         g_error_free(gerr);
895     }
896     if (keyfile) {
897         g_key_file_free(keyfile);
898     }
899     g_free(data);
900     return ret;
901 }
902 
903 static gboolean read_persistent_state(GAPersistentState *pstate,
904                                       const gchar *path, gboolean frozen)
905 {
906     GKeyFile *keyfile = NULL;
907     GError *gerr = NULL;
908     struct stat st;
909     gboolean ret = true;
910 
911     g_assert(pstate);
912 
913     if (stat(path, &st) == -1) {
914         /* it's okay if state file doesn't exist, but any other error
915          * indicates a permissions issue or some other misconfiguration
916          * that we likely won't be able to recover from.
917          */
918         if (errno != ENOENT) {
919             g_critical("unable to access state file at path %s: %s",
920                        path, strerror(errno));
921             ret = false;
922             goto out;
923         }
924 
925         /* file doesn't exist. initialize state to default values and
926          * attempt to save now. (we could wait till later when we have
927          * modified state we need to commit, but if there's a problem,
928          * such as a missing parent directory, we want to catch it now)
929          *
930          * there is a potential scenario where someone either managed to
931          * update the agent from a version that didn't use a key store
932          * while qemu-ga thought the filesystem was frozen, or
933          * deleted the key store prior to issuing a fsfreeze, prior
934          * to restarting the agent. in this case we go ahead and defer
935          * initial creation till we actually have modified state to
936          * write, otherwise fail to recover from freeze.
937          */
938         set_persistent_state_defaults(pstate);
939         if (!frozen) {
940             ret = write_persistent_state(pstate, path);
941             if (!ret) {
942                 g_critical("unable to create state file at path %s", path);
943                 ret = false;
944                 goto out;
945             }
946         }
947         ret = true;
948         goto out;
949     }
950 
951     keyfile = g_key_file_new();
952     g_key_file_load_from_file(keyfile, path, 0, &gerr);
953     if (gerr) {
954         g_critical("error loading persistent state from path: %s, %s",
955                    path, gerr->message);
956         ret = false;
957         goto out;
958     }
959 
960     persistent_state_from_keyfile(pstate, keyfile);
961 
962 out:
963     if (keyfile) {
964         g_key_file_free(keyfile);
965     }
966     if (gerr) {
967         g_error_free(gerr);
968     }
969 
970     return ret;
971 }
972 
973 int64_t ga_get_fd_handle(GAState *s, Error **errp)
974 {
975     int64_t handle;
976 
977     g_assert(s->pstate_filepath);
978     /*
979      * We block commands and avoid operations that potentially require
980      * writing to disk when we're in a frozen state. this includes opening
981      * new files, so we should never get here in that situation
982      */
983     g_assert(!ga_is_frozen(s));
984 
985     handle = s->pstate.fd_counter++;
986 
987     /* This should never happen on a reasonable timeframe, as guest-file-open
988      * would have to be issued 2^63 times */
989     if (s->pstate.fd_counter == INT64_MAX) {
990         abort();
991     }
992 
993     if (!write_persistent_state(&s->pstate, s->pstate_filepath)) {
994         error_setg(errp, "failed to commit persistent state to disk");
995         return -1;
996     }
997 
998     return handle;
999 }
1000 
1001 static void ga_print_cmd(const QmpCommand *cmd, void *opaque)
1002 {
1003     printf("%s\n", qmp_command_name(cmd));
1004 }
1005 
1006 static GList *split_list(const gchar *str, const gchar *delim)
1007 {
1008     GList *list = NULL;
1009     int i;
1010     gchar **strv;
1011 
1012     strv = g_strsplit(str, delim, -1);
1013     for (i = 0; strv[i]; i++) {
1014         list = g_list_prepend(list, strv[i]);
1015     }
1016     g_free(strv);
1017 
1018     return list;
1019 }
1020 
1021 static void config_load(GAConfig *config)
1022 {
1023     GError *gerr = NULL;
1024     GKeyFile *keyfile;
1025     g_autofree char *conf = g_strdup(g_getenv("QGA_CONF")) ?: get_relocated_path(QGA_CONF_DEFAULT);
1026     const gchar *blockrpcs_key = "block-rpcs";
1027 
1028     /* read system config */
1029     keyfile = g_key_file_new();
1030     if (!g_key_file_load_from_file(keyfile, conf, 0, &gerr)) {
1031         goto end;
1032     }
1033     if (g_key_file_has_key(keyfile, "general", "daemon", NULL)) {
1034         config->daemonize =
1035             g_key_file_get_boolean(keyfile, "general", "daemon", &gerr);
1036     }
1037     if (g_key_file_has_key(keyfile, "general", "method", NULL)) {
1038         config->method =
1039             g_key_file_get_string(keyfile, "general", "method", &gerr);
1040     }
1041     if (g_key_file_has_key(keyfile, "general", "path", NULL)) {
1042         config->channel_path =
1043             g_key_file_get_string(keyfile, "general", "path", &gerr);
1044     }
1045     if (g_key_file_has_key(keyfile, "general", "logfile", NULL)) {
1046         config->log_filepath =
1047             g_key_file_get_string(keyfile, "general", "logfile", &gerr);
1048     }
1049     if (g_key_file_has_key(keyfile, "general", "pidfile", NULL)) {
1050         config->pid_filepath =
1051             g_key_file_get_string(keyfile, "general", "pidfile", &gerr);
1052     }
1053 #ifdef CONFIG_FSFREEZE
1054     if (g_key_file_has_key(keyfile, "general", "fsfreeze-hook", NULL)) {
1055         config->fsfreeze_hook =
1056             g_key_file_get_string(keyfile,
1057                                   "general", "fsfreeze-hook", &gerr);
1058     }
1059 #endif
1060     if (g_key_file_has_key(keyfile, "general", "statedir", NULL)) {
1061         config->state_dir =
1062             g_key_file_get_string(keyfile, "general", "statedir", &gerr);
1063     }
1064     if (g_key_file_has_key(keyfile, "general", "verbose", NULL) &&
1065         g_key_file_get_boolean(keyfile, "general", "verbose", &gerr)) {
1066         /* enable all log levels */
1067         config->log_level = G_LOG_LEVEL_MASK;
1068     }
1069     if (g_key_file_has_key(keyfile, "general", "retry-path", NULL)) {
1070         config->retry_path =
1071             g_key_file_get_boolean(keyfile, "general", "retry-path", &gerr);
1072     }
1073 
1074     if (g_key_file_has_key(keyfile, "general", blockrpcs_key, NULL)) {
1075         config->bliststr =
1076             g_key_file_get_string(keyfile, "general", blockrpcs_key, &gerr);
1077         config->blockedrpcs = g_list_concat(config->blockedrpcs,
1078                                           split_list(config->bliststr, ","));
1079     }
1080     if (g_key_file_has_key(keyfile, "general", "allow-rpcs", NULL)) {
1081         config->aliststr =
1082             g_key_file_get_string(keyfile, "general", "allow-rpcs", &gerr);
1083         config->allowedrpcs = g_list_concat(config->allowedrpcs,
1084                                           split_list(config->aliststr, ","));
1085     }
1086 
1087     if (g_key_file_has_key(keyfile, "general", blockrpcs_key, NULL) &&
1088         g_key_file_has_key(keyfile, "general", "allow-rpcs", NULL)) {
1089         g_critical("wrong config, using 'block-rpcs' and 'allow-rpcs' keys at"
1090                    " the same time is not allowed");
1091         exit(EXIT_FAILURE);
1092     }
1093 
1094 end:
1095     g_key_file_free(keyfile);
1096     if (gerr &&
1097         !(gerr->domain == G_FILE_ERROR && gerr->code == G_FILE_ERROR_NOENT)) {
1098         g_critical("error loading configuration from path: %s, %s",
1099                    conf, gerr->message);
1100         exit(EXIT_FAILURE);
1101     }
1102     g_clear_error(&gerr);
1103 }
1104 
1105 static gchar *list_join(GList *list, const gchar separator)
1106 {
1107     GString *str = g_string_new("");
1108 
1109     while (list) {
1110         str = g_string_append(str, (gchar *)list->data);
1111         list = g_list_next(list);
1112         if (list) {
1113             str = g_string_append_c(str, separator);
1114         }
1115     }
1116 
1117     return g_string_free(str, FALSE);
1118 }
1119 
1120 static void config_dump(GAConfig *config)
1121 {
1122     GError *error = NULL;
1123     GKeyFile *keyfile;
1124     gchar *tmp;
1125 
1126     keyfile = g_key_file_new();
1127     g_assert(keyfile);
1128 
1129     g_key_file_set_boolean(keyfile, "general", "daemon", config->daemonize);
1130     g_key_file_set_string(keyfile, "general", "method", config->method);
1131     if (config->channel_path) {
1132         g_key_file_set_string(keyfile, "general", "path", config->channel_path);
1133     }
1134     if (config->log_filepath) {
1135         g_key_file_set_string(keyfile, "general", "logfile",
1136                               config->log_filepath);
1137     }
1138     g_key_file_set_string(keyfile, "general", "pidfile", config->pid_filepath);
1139 #ifdef CONFIG_FSFREEZE
1140     if (config->fsfreeze_hook) {
1141         g_key_file_set_string(keyfile, "general", "fsfreeze-hook",
1142                               config->fsfreeze_hook);
1143     }
1144 #endif
1145     g_key_file_set_string(keyfile, "general", "statedir", config->state_dir);
1146     g_key_file_set_boolean(keyfile, "general", "verbose",
1147                            config->log_level == G_LOG_LEVEL_MASK);
1148     g_key_file_set_boolean(keyfile, "general", "retry-path",
1149                            config->retry_path);
1150     tmp = list_join(config->blockedrpcs, ',');
1151     g_key_file_set_string(keyfile, "general", "block-rpcs", tmp);
1152     g_free(tmp);
1153     tmp = list_join(config->allowedrpcs, ',');
1154     g_key_file_set_string(keyfile, "general", "allow-rpcs", tmp);
1155     g_free(tmp);
1156 
1157     tmp = g_key_file_to_data(keyfile, NULL, &error);
1158     if (error) {
1159         g_critical("Failed to dump keyfile: %s", error->message);
1160         g_clear_error(&error);
1161     } else {
1162         printf("%s", tmp);
1163     }
1164 
1165     g_free(tmp);
1166     g_key_file_free(keyfile);
1167 }
1168 
1169 static void config_parse(GAConfig *config, int argc, char **argv)
1170 {
1171     const char *sopt = "hVvdm:p:l:f:F::b:a:s:t:Dr";
1172     int opt_ind = 0, ch;
1173     bool block_rpcs = false, allow_rpcs = false;
1174     const struct option lopt[] = {
1175         { "help", 0, NULL, 'h' },
1176         { "version", 0, NULL, 'V' },
1177         { "dump-conf", 0, NULL, 'D' },
1178         { "logfile", 1, NULL, 'l' },
1179         { "pidfile", 1, NULL, 'f' },
1180 #ifdef CONFIG_FSFREEZE
1181         { "fsfreeze-hook", 2, NULL, 'F' },
1182 #endif
1183         { "verbose", 0, NULL, 'v' },
1184         { "method", 1, NULL, 'm' },
1185         { "path", 1, NULL, 'p' },
1186         { "daemonize", 0, NULL, 'd' },
1187         { "block-rpcs", 1, NULL, 'b' },
1188         { "allow-rpcs", 1, NULL, 'a' },
1189 #ifdef _WIN32
1190         { "service", 1, NULL, 's' },
1191 #endif
1192         { "statedir", 1, NULL, 't' },
1193         { "retry-path", 0, NULL, 'r' },
1194         { NULL, 0, NULL, 0 }
1195     };
1196 
1197     while ((ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1) {
1198         switch (ch) {
1199         case 'm':
1200             g_free(config->method);
1201             config->method = g_strdup(optarg);
1202             break;
1203         case 'p':
1204             g_free(config->channel_path);
1205             config->channel_path = g_strdup(optarg);
1206             break;
1207         case 'l':
1208             g_free(config->log_filepath);
1209             config->log_filepath = g_strdup(optarg);
1210             break;
1211         case 'f':
1212             g_free(config->pid_filepath);
1213             config->pid_filepath = g_strdup(optarg);
1214             break;
1215 #ifdef CONFIG_FSFREEZE
1216         case 'F':
1217             g_free(config->fsfreeze_hook);
1218             config->fsfreeze_hook = optarg ? g_strdup(optarg) : get_relocated_path(QGA_FSFREEZE_HOOK_DEFAULT);
1219             break;
1220 #endif
1221         case 't':
1222             g_free(config->state_dir);
1223             config->state_dir = g_strdup(optarg);
1224             break;
1225         case 'v':
1226             /* enable all log levels */
1227             config->log_level = G_LOG_LEVEL_MASK;
1228             break;
1229         case 'V':
1230             printf("QEMU Guest Agent %s\n", QEMU_VERSION);
1231             exit(EXIT_SUCCESS);
1232         case 'd':
1233             config->daemonize = 1;
1234             break;
1235         case 'D':
1236             config->dumpconf = 1;
1237             break;
1238         case 'r':
1239             config->retry_path = true;
1240             break;
1241         case 'b': {
1242             if (is_help_option(optarg)) {
1243                 qmp_for_each_command(&ga_commands, ga_print_cmd, NULL);
1244                 exit(EXIT_SUCCESS);
1245             }
1246             config->blockedrpcs = g_list_concat(config->blockedrpcs,
1247                                                 split_list(optarg, ","));
1248             block_rpcs = true;
1249             break;
1250         }
1251         case 'a': {
1252             if (is_help_option(optarg)) {
1253                 qmp_for_each_command(&ga_commands, ga_print_cmd, NULL);
1254                 exit(EXIT_SUCCESS);
1255             }
1256             config->allowedrpcs = g_list_concat(config->allowedrpcs,
1257                                                 split_list(optarg, ","));
1258             allow_rpcs = true;
1259             break;
1260         }
1261 #ifdef _WIN32
1262         case 's':
1263             config->service = optarg;
1264             if (strcmp(config->service, "install") == 0) {
1265                 if (ga_install_vss_provider()) {
1266                     exit(EXIT_FAILURE);
1267                 }
1268                 if (ga_install_service(config->channel_path,
1269                                        config->log_filepath, config->state_dir)) {
1270                     exit(EXIT_FAILURE);
1271                 }
1272                 exit(EXIT_SUCCESS);
1273             } else if (strcmp(config->service, "uninstall") == 0) {
1274                 ga_uninstall_vss_provider();
1275                 exit(ga_uninstall_service());
1276             } else if (strcmp(config->service, "vss-install") == 0) {
1277                 if (ga_install_vss_provider()) {
1278                     exit(EXIT_FAILURE);
1279                 }
1280                 exit(EXIT_SUCCESS);
1281             } else if (strcmp(config->service, "vss-uninstall") == 0) {
1282                 ga_uninstall_vss_provider();
1283                 exit(EXIT_SUCCESS);
1284             } else {
1285                 printf("Unknown service command.\n");
1286                 exit(EXIT_FAILURE);
1287             }
1288             break;
1289 #endif
1290         case 'h':
1291             usage(argv[0]);
1292             exit(EXIT_SUCCESS);
1293         case '?':
1294             g_print("Unknown option, try '%s --help' for more information.\n",
1295                     argv[0]);
1296             exit(EXIT_FAILURE);
1297         }
1298     }
1299 
1300     if (block_rpcs && allow_rpcs) {
1301         g_critical("wrong commandline, using --block-rpcs and --allow-rpcs at the"
1302                    " same time is not allowed");
1303         exit(EXIT_FAILURE);
1304     }
1305 }
1306 
1307 static void config_free(GAConfig *config)
1308 {
1309     g_free(config->method);
1310     g_free(config->log_filepath);
1311     g_free(config->pid_filepath);
1312     g_free(config->state_dir);
1313     g_free(config->channel_path);
1314     g_free(config->bliststr);
1315     g_free(config->aliststr);
1316 #ifdef CONFIG_FSFREEZE
1317     g_free(config->fsfreeze_hook);
1318 #endif
1319     g_list_free_full(config->blockedrpcs, g_free);
1320     g_list_free_full(config->allowedrpcs, g_free);
1321     g_free(config);
1322 }
1323 
1324 static bool check_is_frozen(GAState *s)
1325 {
1326 #ifndef _WIN32
1327     /* check if a previous instance of qemu-ga exited with filesystems' state
1328      * marked as frozen. this could be a stale value (a non-qemu-ga process
1329      * or reboot may have since unfrozen them), but better to require an
1330      * unneeded unfreeze than to risk hanging on start-up
1331      */
1332     struct stat st;
1333     if (stat(s->state_filepath_isfrozen, &st) == -1) {
1334         /* it's okay if the file doesn't exist, but if we can't access for
1335          * some other reason, such as permissions, there's a configuration
1336          * that needs to be addressed. so just bail now before we get into
1337          * more trouble later
1338          */
1339         if (errno != ENOENT) {
1340             g_critical("unable to access state file at path %s: %s",
1341                        s->state_filepath_isfrozen, strerror(errno));
1342             return EXIT_FAILURE;
1343         }
1344     } else {
1345         g_warning("previous instance appears to have exited with frozen"
1346                   " filesystems. deferring logging/pidfile creation and"
1347                   " disabling non-fsfreeze-safe commands until"
1348                   " guest-fsfreeze-thaw is issued, or filesystems are"
1349                   " manually unfrozen and the file %s is removed",
1350                   s->state_filepath_isfrozen);
1351         return true;
1352     }
1353 #endif
1354     return false;
1355 }
1356 
1357 static GAState *initialize_agent(GAConfig *config, int socket_activation)
1358 {
1359     GAState *s = g_new0(GAState, 1);
1360 
1361     g_assert(ga_state == NULL);
1362 
1363     s->log_level = config->log_level;
1364     s->log_file = stderr;
1365 #ifdef CONFIG_FSFREEZE
1366     s->fsfreeze_hook = config->fsfreeze_hook;
1367 #endif
1368     s->pstate_filepath = g_strdup_printf("%s/qga.state", config->state_dir);
1369     s->state_filepath_isfrozen = g_strdup_printf("%s/qga.state.isfrozen",
1370                                                  config->state_dir);
1371     s->frozen = check_is_frozen(s);
1372 
1373     g_log_set_default_handler(ga_log, s);
1374     g_log_set_fatal_mask(NULL, G_LOG_LEVEL_ERROR);
1375     ga_enable_logging(s);
1376 
1377     g_debug("Guest agent version %s started", QEMU_FULL_VERSION);
1378 
1379 #ifdef _WIN32
1380     s->event_log = RegisterEventSource(NULL, "qemu-ga");
1381     if (!s->event_log) {
1382         g_autofree gchar *errmsg = g_win32_error_message(GetLastError());
1383         g_critical("unable to register event source: %s", errmsg);
1384         return NULL;
1385     }
1386 
1387     /* On win32 the state directory is application specific (be it the default
1388      * or a user override). We got past the command line parsing; let's create
1389      * the directory (with any intermediate directories). If we run into an
1390      * error later on, we won't try to clean up the directory, it is considered
1391      * persistent.
1392      */
1393     if (g_mkdir_with_parents(config->state_dir, S_IRWXU) == -1) {
1394         g_critical("unable to create (an ancestor of) the state directory"
1395                    " '%s': %s", config->state_dir, strerror(errno));
1396         return NULL;
1397     }
1398 
1399     if (!vss_init(true)) {
1400         g_debug("vss_init failed, vss commands will not function");
1401     }
1402 #endif
1403 
1404     if (ga_is_frozen(s)) {
1405         if (config->daemonize) {
1406             /* delay opening/locking of pidfile till filesystems are unfrozen */
1407             s->deferred_options.pid_filepath = config->pid_filepath;
1408             become_daemon(NULL);
1409         }
1410         if (config->log_filepath) {
1411             /* delay opening the log file till filesystems are unfrozen */
1412             s->deferred_options.log_filepath = config->log_filepath;
1413         }
1414         ga_disable_logging(s);
1415         qmp_for_each_command(&ga_commands, ga_disable_not_allowed_freeze, NULL);
1416     } else {
1417         if (config->daemonize) {
1418             become_daemon(config->pid_filepath);
1419         }
1420         if (config->log_filepath) {
1421             FILE *log_file = ga_open_logfile(config->log_filepath);
1422             if (!log_file) {
1423                 g_critical("unable to open specified log file: %s",
1424                            strerror(errno));
1425                 return NULL;
1426             }
1427             s->log_file = log_file;
1428         }
1429     }
1430 
1431     /* load persistent state from disk */
1432     if (!read_persistent_state(&s->pstate,
1433                                s->pstate_filepath,
1434                                ga_is_frozen(s))) {
1435         g_critical("failed to load persistent state");
1436         return NULL;
1437     }
1438 
1439     if (config->allowedrpcs) {
1440         qmp_for_each_command(&ga_commands, ga_disable_not_allowed, config->allowedrpcs);
1441         s->allowedrpcs = config->allowedrpcs;
1442     }
1443 
1444     /*
1445      * Some commands can be blocked due to system limitation.
1446      * Initialize blockedrpcs list even if allowedrpcs specified.
1447      */
1448     config->blockedrpcs = ga_command_init_blockedrpcs(config->blockedrpcs);
1449     if (config->blockedrpcs) {
1450         GList *l = config->blockedrpcs;
1451         s->blockedrpcs = config->blockedrpcs;
1452         do {
1453             g_debug("disabling command: %s", (char *)l->data);
1454             qmp_disable_command(&ga_commands, l->data, NULL);
1455             l = g_list_next(l);
1456         } while (l);
1457     }
1458     s->command_state = ga_command_state_new();
1459     ga_command_state_init(s, s->command_state);
1460     ga_command_state_init_all(s->command_state);
1461     json_message_parser_init(&s->parser, process_event, s, NULL);
1462 
1463 #ifndef _WIN32
1464     if (!register_signal_handlers()) {
1465         g_critical("failed to register signal handlers");
1466         return NULL;
1467     }
1468 #endif
1469 
1470     s->main_loop = g_main_loop_new(NULL, false);
1471 
1472     s->config = config;
1473     s->socket_activation = socket_activation;
1474 
1475 #ifdef _WIN32
1476     s->wakeup_event = CreateEvent(NULL, TRUE, FALSE, TEXT("WakeUp"));
1477     if (s->wakeup_event == NULL) {
1478         g_critical("CreateEvent failed");
1479         return NULL;
1480     }
1481 #endif
1482 
1483     ga_state = s;
1484     return s;
1485 }
1486 
1487 static void cleanup_agent(GAState *s)
1488 {
1489 #ifdef _WIN32
1490     CloseHandle(s->wakeup_event);
1491     CloseHandle(s->event_log);
1492 #endif
1493     if (s->command_state) {
1494         ga_command_state_cleanup_all(s->command_state);
1495         ga_command_state_free(s->command_state);
1496         json_message_parser_destroy(&s->parser);
1497     }
1498     g_free(s->pstate_filepath);
1499     g_free(s->state_filepath_isfrozen);
1500     if (s->main_loop) {
1501         g_main_loop_unref(s->main_loop);
1502     }
1503     g_free(s);
1504     ga_state = NULL;
1505 }
1506 
1507 static int run_agent_once(GAState *s)
1508 {
1509     if (!channel_init(s, s->config->method, s->config->channel_path,
1510                       s->socket_activation ? FIRST_SOCKET_ACTIVATION_FD : -1)) {
1511         g_critical("failed to initialize guest agent channel");
1512         return EXIT_FAILURE;
1513     }
1514 
1515     g_main_loop_run(ga_state->main_loop);
1516 
1517     if (s->channel) {
1518         ga_channel_free(s->channel);
1519     }
1520 
1521     return EXIT_SUCCESS;
1522 }
1523 
1524 static void wait_for_channel_availability(GAState *s)
1525 {
1526     g_warning("waiting for channel path...");
1527 #ifndef _WIN32
1528     sleep(QGA_RETRY_INTERVAL);
1529 #else
1530     DWORD dwWaitResult;
1531 
1532     dwWaitResult = WaitForSingleObject(s->wakeup_event, INFINITE);
1533 
1534     switch (dwWaitResult) {
1535     case WAIT_OBJECT_0:
1536         break;
1537     case WAIT_TIMEOUT:
1538         break;
1539     default:
1540         g_critical("WaitForSingleObject failed");
1541     }
1542 #endif
1543 }
1544 
1545 static int run_agent(GAState *s)
1546 {
1547     int ret = EXIT_SUCCESS;
1548 
1549     s->force_exit = false;
1550 
1551     do {
1552         ret = run_agent_once(s);
1553         if (s->config->retry_path && !s->force_exit) {
1554             g_warning("agent stopped unexpectedly, restarting...");
1555             wait_for_channel_availability(s);
1556         }
1557     } while (s->config->retry_path && !s->force_exit);
1558 
1559     return ret;
1560 }
1561 
1562 static void stop_agent(GAState *s, bool requested)
1563 {
1564     if (!s->force_exit) {
1565         s->force_exit = requested;
1566     }
1567 
1568     if (g_main_loop_is_running(s->main_loop)) {
1569         g_main_loop_quit(s->main_loop);
1570     }
1571 }
1572 
1573 int main(int argc, char **argv)
1574 {
1575     int ret = EXIT_SUCCESS;
1576     GAState *s;
1577     GAConfig *config = g_new0(GAConfig, 1);
1578     int socket_activation;
1579 
1580     config->log_level = G_LOG_LEVEL_ERROR | G_LOG_LEVEL_CRITICAL;
1581 
1582     qemu_init_exec_dir(argv[0]);
1583     qga_qmp_init_marshal(&ga_commands);
1584 
1585     init_dfl_pathnames();
1586     config_load(config);
1587     config_parse(config, argc, argv);
1588 
1589     if (config->pid_filepath == NULL) {
1590         config->pid_filepath = g_strdup(dfl_pathnames.pidfile);
1591     }
1592 
1593     if (config->state_dir == NULL) {
1594         config->state_dir = g_strdup(dfl_pathnames.state_dir);
1595     }
1596 
1597     if (config->method == NULL) {
1598         config->method = g_strdup("virtio-serial");
1599     }
1600 
1601     socket_activation = check_socket_activation();
1602     if (socket_activation > 1) {
1603         g_critical("qemu-ga only supports listening on one socket");
1604         ret = EXIT_FAILURE;
1605         goto end;
1606     }
1607     if (socket_activation) {
1608         SocketAddress *addr;
1609 
1610         g_free(config->method);
1611         g_free(config->channel_path);
1612         config->method = NULL;
1613         config->channel_path = NULL;
1614 
1615         addr = socket_local_address(FIRST_SOCKET_ACTIVATION_FD, NULL);
1616         if (addr) {
1617             if (addr->type == SOCKET_ADDRESS_TYPE_UNIX) {
1618                 config->method = g_strdup("unix-listen");
1619             } else if (addr->type == SOCKET_ADDRESS_TYPE_VSOCK) {
1620                 config->method = g_strdup("vsock-listen");
1621             }
1622 
1623             qapi_free_SocketAddress(addr);
1624         }
1625 
1626         if (!config->method) {
1627             g_critical("unsupported listen fd type");
1628             ret = EXIT_FAILURE;
1629             goto end;
1630         }
1631     } else if (config->channel_path == NULL) {
1632         if (strcmp(config->method, "virtio-serial") == 0) {
1633             /* try the default path for the virtio-serial port */
1634             config->channel_path = g_strdup(QGA_VIRTIO_PATH_DEFAULT);
1635         } else if (strcmp(config->method, "isa-serial") == 0) {
1636             /* try the default path for the serial port - COM1 */
1637             config->channel_path = g_strdup(QGA_SERIAL_PATH_DEFAULT);
1638         } else {
1639             g_critical("must specify a path for this channel");
1640             ret = EXIT_FAILURE;
1641             goto end;
1642         }
1643     }
1644 
1645     if (config->dumpconf) {
1646         config_dump(config);
1647         goto end;
1648     }
1649 
1650     s = initialize_agent(config, socket_activation);
1651     if (!s) {
1652         g_critical("error initializing guest agent");
1653         goto end;
1654     }
1655 
1656 #ifdef _WIN32
1657     if (config->daemonize) {
1658         SERVICE_TABLE_ENTRY service_table[] = {
1659             { (char *)QGA_SERVICE_NAME, service_main }, { NULL, NULL } };
1660         StartServiceCtrlDispatcher(service_table);
1661     } else {
1662         ret = run_agent(s);
1663     }
1664 #else
1665     ret = run_agent(s);
1666 #endif
1667 
1668     cleanup_agent(s);
1669 
1670 end:
1671     if (config->daemonize) {
1672         unlink(config->pid_filepath);
1673     }
1674 
1675     config_free(config);
1676 
1677     return ret;
1678 }
1679