xref: /openbmc/qemu/qga/main.c (revision 709395f8)
1 /*
2  * QEMU Guest Agent
3  *
4  * Copyright IBM Corp. 2011
5  *
6  * Authors:
7  *  Adam Litke        <aglitke@linux.vnet.ibm.com>
8  *  Michael Roth      <mdroth@linux.vnet.ibm.com>
9  *
10  * This work is licensed under the terms of the GNU GPL, version 2 or later.
11  * See the COPYING file in the top-level directory.
12  */
13 
14 #include "qemu/osdep.h"
15 #include <getopt.h>
16 #include <glib/gstdio.h>
17 #ifndef _WIN32
18 #include <syslog.h>
19 #include <sys/wait.h>
20 #endif
21 #include "qapi/qmp/json-parser.h"
22 #include "qapi/qmp/qdict.h"
23 #include "qapi/qmp/qjson.h"
24 #include "qapi/qmp/qstring.h"
25 #include "guest-agent-core.h"
26 #include "qemu/module.h"
27 #include "qga-qapi-commands.h"
28 #include "qapi/qmp/qerror.h"
29 #include "qapi/error.h"
30 #include "channel.h"
31 #include "qemu/bswap.h"
32 #include "qemu/help_option.h"
33 #include "qemu/sockets.h"
34 #include "qemu/systemd.h"
35 #include "qemu-version.h"
36 #ifdef _WIN32
37 #include <dbt.h>
38 #include "qga/service-win32.h"
39 #include "qga/vss-win32.h"
40 #endif
41 #ifdef __linux__
42 #include <linux/fs.h>
43 #ifdef FIFREEZE
44 #define CONFIG_FSFREEZE
45 #endif
46 #endif
47 
48 #ifndef _WIN32
49 #define QGA_VIRTIO_PATH_DEFAULT "/dev/virtio-ports/org.qemu.guest_agent.0"
50 #define QGA_STATE_RELATIVE_DIR  "run"
51 #define QGA_SERIAL_PATH_DEFAULT "/dev/ttyS0"
52 #else
53 #define QGA_VIRTIO_PATH_DEFAULT "\\\\.\\Global\\org.qemu.guest_agent.0"
54 #define QGA_STATE_RELATIVE_DIR  "qemu-ga"
55 #define QGA_SERIAL_PATH_DEFAULT "COM1"
56 #endif
57 #ifdef CONFIG_FSFREEZE
58 #define QGA_FSFREEZE_HOOK_DEFAULT CONFIG_QEMU_CONFDIR "/fsfreeze-hook"
59 #endif
60 #define QGA_SENTINEL_BYTE 0xFF
61 #define QGA_CONF_DEFAULT CONFIG_QEMU_CONFDIR G_DIR_SEPARATOR_S "qemu-ga.conf"
62 #define QGA_RETRY_INTERVAL 5
63 
64 static struct {
65     const char *state_dir;
66     const char *pidfile;
67 } dfl_pathnames;
68 
69 typedef struct GAPersistentState {
70 #define QGA_PSTATE_DEFAULT_FD_COUNTER 1000
71     int64_t fd_counter;
72 } GAPersistentState;
73 
74 typedef struct GAConfig GAConfig;
75 
76 struct GAState {
77     JSONMessageParser parser;
78     GMainLoop *main_loop;
79     GAChannel *channel;
80     bool virtio; /* fastpath to check for virtio to deal with poll() quirks */
81     GACommandState *command_state;
82     GLogLevelFlags log_level;
83     FILE *log_file;
84     bool logging_enabled;
85 #ifdef _WIN32
86     GAService service;
87     HANDLE wakeup_event;
88 #endif
89     bool delimit_response;
90     bool frozen;
91     GList *blacklist;
92     char *state_filepath_isfrozen;
93     struct {
94         const char *log_filepath;
95         const char *pid_filepath;
96     } deferred_options;
97 #ifdef CONFIG_FSFREEZE
98     const char *fsfreeze_hook;
99 #endif
100     gchar *pstate_filepath;
101     GAPersistentState pstate;
102     GAConfig *config;
103     int socket_activation;
104     bool force_exit;
105 };
106 
107 struct GAState *ga_state;
108 QmpCommandList ga_commands;
109 
110 /* commands that are safe to issue while filesystems are frozen */
111 static const char *ga_freeze_whitelist[] = {
112     "guest-ping",
113     "guest-info",
114     "guest-sync",
115     "guest-sync-delimited",
116     "guest-fsfreeze-status",
117     "guest-fsfreeze-thaw",
118     NULL
119 };
120 
121 #ifdef _WIN32
122 DWORD WINAPI service_ctrl_handler(DWORD ctrl, DWORD type, LPVOID data,
123                                   LPVOID ctx);
124 DWORD WINAPI handle_serial_device_events(DWORD type, LPVOID data);
125 VOID WINAPI service_main(DWORD argc, TCHAR *argv[]);
126 #endif
127 static int run_agent(GAState *s);
128 static void stop_agent(GAState *s, bool requested);
129 
130 static void
131 init_dfl_pathnames(void)
132 {
133     g_assert(dfl_pathnames.state_dir == NULL);
134     g_assert(dfl_pathnames.pidfile == NULL);
135     dfl_pathnames.state_dir = qemu_get_local_state_pathname(
136       QGA_STATE_RELATIVE_DIR);
137     dfl_pathnames.pidfile   = qemu_get_local_state_pathname(
138       QGA_STATE_RELATIVE_DIR G_DIR_SEPARATOR_S "qemu-ga.pid");
139 }
140 
141 static void quit_handler(int sig)
142 {
143     /* if we're frozen, don't exit unless we're absolutely forced to,
144      * because it's basically impossible for graceful exit to complete
145      * unless all log/pid files are on unfreezable filesystems. there's
146      * also a very likely chance killing the agent before unfreezing
147      * the filesystems is a mistake (or will be viewed as one later).
148      * On Windows the freeze interval is limited to 10 seconds, so
149      * we should quit, but first we should wait for the timeout, thaw
150      * the filesystem and quit.
151      */
152     if (ga_is_frozen(ga_state)) {
153 #ifdef _WIN32
154         int i = 0;
155         Error *err = NULL;
156         HANDLE hEventTimeout;
157 
158         g_debug("Thawing filesystems before exiting");
159 
160         hEventTimeout = OpenEvent(EVENT_ALL_ACCESS, FALSE, EVENT_NAME_TIMEOUT);
161         if (hEventTimeout) {
162             WaitForSingleObject(hEventTimeout, 0);
163             CloseHandle(hEventTimeout);
164         }
165         qga_vss_fsfreeze(&i, false, NULL, &err);
166         if (err) {
167             g_debug("Error unfreezing filesystems prior to exiting: %s",
168                 error_get_pretty(err));
169             error_free(err);
170         }
171 #else
172         return;
173 #endif
174     }
175     g_debug("received signal num %d, quitting", sig);
176 
177     stop_agent(ga_state, true);
178 }
179 
180 #ifndef _WIN32
181 static gboolean register_signal_handlers(void)
182 {
183     struct sigaction sigact;
184     int ret;
185 
186     memset(&sigact, 0, sizeof(struct sigaction));
187     sigact.sa_handler = quit_handler;
188 
189     ret = sigaction(SIGINT, &sigact, NULL);
190     if (ret == -1) {
191         g_error("error configuring signal handler: %s", strerror(errno));
192     }
193     ret = sigaction(SIGTERM, &sigact, NULL);
194     if (ret == -1) {
195         g_error("error configuring signal handler: %s", strerror(errno));
196     }
197 
198     sigact.sa_handler = SIG_IGN;
199     if (sigaction(SIGPIPE, &sigact, NULL) != 0) {
200         g_error("error configuring SIGPIPE signal handler: %s",
201                 strerror(errno));
202     }
203 
204     return true;
205 }
206 
207 /* TODO: use this in place of all post-fork() fclose(std*) callers */
208 void reopen_fd_to_null(int fd)
209 {
210     int nullfd;
211 
212     nullfd = open("/dev/null", O_RDWR);
213     if (nullfd < 0) {
214         return;
215     }
216 
217     dup2(nullfd, fd);
218 
219     if (nullfd != fd) {
220         close(nullfd);
221     }
222 }
223 #endif
224 
225 static void usage(const char *cmd)
226 {
227     printf(
228 "Usage: %s [-m <method> -p <path>] [<options>]\n"
229 "QEMU Guest Agent " QEMU_FULL_VERSION "\n"
230 QEMU_COPYRIGHT "\n"
231 "\n"
232 "  -m, --method      transport method: one of unix-listen, virtio-serial,\n"
233 "                    isa-serial, or vsock-listen (virtio-serial is the default)\n"
234 "  -p, --path        device/socket path (the default for virtio-serial is:\n"
235 "                    %s,\n"
236 "                    the default for isa-serial is:\n"
237 "                    %s)\n"
238 "  -l, --logfile     set logfile path, logs to stderr by default\n"
239 "  -f, --pidfile     specify pidfile (default is %s)\n"
240 #ifdef CONFIG_FSFREEZE
241 "  -F, --fsfreeze-hook\n"
242 "                    enable fsfreeze hook. Accepts an optional argument that\n"
243 "                    specifies script to run on freeze/thaw. Script will be\n"
244 "                    called with 'freeze'/'thaw' arguments accordingly.\n"
245 "                    (default is %s)\n"
246 "                    If using -F with an argument, do not follow -F with a\n"
247 "                    space.\n"
248 "                    (for example: -F/var/run/fsfreezehook.sh)\n"
249 #endif
250 "  -t, --statedir    specify dir to store state information (absolute paths\n"
251 "                    only, default is %s)\n"
252 "  -v, --verbose     log extra debugging information\n"
253 "  -V, --version     print version information and exit\n"
254 "  -d, --daemonize   become a daemon\n"
255 #ifdef _WIN32
256 "  -s, --service     service commands: install, uninstall, vss-install, vss-uninstall\n"
257 #endif
258 "  -b, --blacklist   comma-separated list of RPCs to disable (no spaces, \"?\"\n"
259 "                    to list available RPCs)\n"
260 "  -D, --dump-conf   dump a qemu-ga config file based on current config\n"
261 "                    options / command-line parameters to stdout\n"
262 "  -r, --retry-path  attempt re-opening path if it's unavailable or closed\n"
263 "                    due to an error which may be recoverable in the future\n"
264 "                    (virtio-serial driver re-install, serial device hot\n"
265 "                    plug/unplug, etc.)\n"
266 "  -h, --help        display this help and exit\n"
267 "\n"
268 QEMU_HELP_BOTTOM "\n"
269     , cmd, QGA_VIRTIO_PATH_DEFAULT, QGA_SERIAL_PATH_DEFAULT,
270     dfl_pathnames.pidfile,
271 #ifdef CONFIG_FSFREEZE
272     QGA_FSFREEZE_HOOK_DEFAULT,
273 #endif
274     dfl_pathnames.state_dir);
275 }
276 
277 static const char *ga_log_level_str(GLogLevelFlags level)
278 {
279     switch (level & G_LOG_LEVEL_MASK) {
280         case G_LOG_LEVEL_ERROR:
281             return "error";
282         case G_LOG_LEVEL_CRITICAL:
283             return "critical";
284         case G_LOG_LEVEL_WARNING:
285             return "warning";
286         case G_LOG_LEVEL_MESSAGE:
287             return "message";
288         case G_LOG_LEVEL_INFO:
289             return "info";
290         case G_LOG_LEVEL_DEBUG:
291             return "debug";
292         default:
293             return "user";
294     }
295 }
296 
297 bool ga_logging_enabled(GAState *s)
298 {
299     return s->logging_enabled;
300 }
301 
302 void ga_disable_logging(GAState *s)
303 {
304     s->logging_enabled = false;
305 }
306 
307 void ga_enable_logging(GAState *s)
308 {
309     s->logging_enabled = true;
310 }
311 
312 static void ga_log(const gchar *domain, GLogLevelFlags level,
313                    const gchar *msg, gpointer opaque)
314 {
315     GAState *s = opaque;
316     GTimeVal time;
317     const char *level_str = ga_log_level_str(level);
318 
319     if (!ga_logging_enabled(s)) {
320         return;
321     }
322 
323     level &= G_LOG_LEVEL_MASK;
324 #ifndef _WIN32
325     if (g_strcmp0(domain, "syslog") == 0) {
326         syslog(LOG_INFO, "%s: %s", level_str, msg);
327     } else if (level & s->log_level) {
328 #else
329     if (level & s->log_level) {
330 #endif
331         g_get_current_time(&time);
332         fprintf(s->log_file,
333                 "%lu.%lu: %s: %s\n", time.tv_sec, time.tv_usec, level_str, msg);
334         fflush(s->log_file);
335     }
336 }
337 
338 void ga_set_response_delimited(GAState *s)
339 {
340     s->delimit_response = true;
341 }
342 
343 static FILE *ga_open_logfile(const char *logfile)
344 {
345     FILE *f;
346 
347     f = fopen(logfile, "a");
348     if (!f) {
349         return NULL;
350     }
351 
352     qemu_set_cloexec(fileno(f));
353     return f;
354 }
355 
356 static gint ga_strcmp(gconstpointer str1, gconstpointer str2)
357 {
358     return strcmp(str1, str2);
359 }
360 
361 /* disable commands that aren't safe for fsfreeze */
362 static void ga_disable_non_whitelisted(QmpCommand *cmd, void *opaque)
363 {
364     bool whitelisted = false;
365     int i = 0;
366     const char *name = qmp_command_name(cmd);
367 
368     while (ga_freeze_whitelist[i] != NULL) {
369         if (strcmp(name, ga_freeze_whitelist[i]) == 0) {
370             whitelisted = true;
371         }
372         i++;
373     }
374     if (!whitelisted) {
375         g_debug("disabling command: %s", name);
376         qmp_disable_command(&ga_commands, name);
377     }
378 }
379 
380 /* [re-]enable all commands, except those explicitly blacklisted by user */
381 static void ga_enable_non_blacklisted(QmpCommand *cmd, void *opaque)
382 {
383     GList *blacklist = opaque;
384     const char *name = qmp_command_name(cmd);
385 
386     if (g_list_find_custom(blacklist, name, ga_strcmp) == NULL &&
387         !qmp_command_is_enabled(cmd)) {
388         g_debug("enabling command: %s", name);
389         qmp_enable_command(&ga_commands, name);
390     }
391 }
392 
393 static bool ga_create_file(const char *path)
394 {
395     int fd = open(path, O_CREAT | O_WRONLY, S_IWUSR | S_IRUSR);
396     if (fd == -1) {
397         g_warning("unable to open/create file %s: %s", path, strerror(errno));
398         return false;
399     }
400     close(fd);
401     return true;
402 }
403 
404 static bool ga_delete_file(const char *path)
405 {
406     int ret = unlink(path);
407     if (ret == -1) {
408         g_warning("unable to delete file: %s: %s", path, strerror(errno));
409         return false;
410     }
411 
412     return true;
413 }
414 
415 bool ga_is_frozen(GAState *s)
416 {
417     return s->frozen;
418 }
419 
420 void ga_set_frozen(GAState *s)
421 {
422     if (ga_is_frozen(s)) {
423         return;
424     }
425     /* disable all non-whitelisted (for frozen state) commands */
426     qmp_for_each_command(&ga_commands, ga_disable_non_whitelisted, NULL);
427     g_warning("disabling logging due to filesystem freeze");
428     ga_disable_logging(s);
429     s->frozen = true;
430     if (!ga_create_file(s->state_filepath_isfrozen)) {
431         g_warning("unable to create %s, fsfreeze may not function properly",
432                   s->state_filepath_isfrozen);
433     }
434 }
435 
436 void ga_unset_frozen(GAState *s)
437 {
438     if (!ga_is_frozen(s)) {
439         return;
440     }
441 
442     /* if we delayed creation/opening of pid/log files due to being
443      * in a frozen state at start up, do it now
444      */
445     if (s->deferred_options.log_filepath) {
446         s->log_file = ga_open_logfile(s->deferred_options.log_filepath);
447         if (!s->log_file) {
448             s->log_file = stderr;
449         }
450         s->deferred_options.log_filepath = NULL;
451     }
452     ga_enable_logging(s);
453     g_warning("logging re-enabled due to filesystem unfreeze");
454     if (s->deferred_options.pid_filepath) {
455         Error *err = NULL;
456 
457         if (!qemu_write_pidfile(s->deferred_options.pid_filepath, &err)) {
458             g_warning("%s", error_get_pretty(err));
459             error_free(err);
460         }
461         s->deferred_options.pid_filepath = NULL;
462     }
463 
464     /* enable all disabled, non-blacklisted commands */
465     qmp_for_each_command(&ga_commands, ga_enable_non_blacklisted, s->blacklist);
466     s->frozen = false;
467     if (!ga_delete_file(s->state_filepath_isfrozen)) {
468         g_warning("unable to delete %s, fsfreeze may not function properly",
469                   s->state_filepath_isfrozen);
470     }
471 }
472 
473 #ifdef CONFIG_FSFREEZE
474 const char *ga_fsfreeze_hook(GAState *s)
475 {
476     return s->fsfreeze_hook;
477 }
478 #endif
479 
480 static void become_daemon(const char *pidfile)
481 {
482 #ifndef _WIN32
483     pid_t pid, sid;
484 
485     pid = fork();
486     if (pid < 0) {
487         exit(EXIT_FAILURE);
488     }
489     if (pid > 0) {
490         exit(EXIT_SUCCESS);
491     }
492 
493     if (pidfile) {
494         Error *err = NULL;
495 
496         if (!qemu_write_pidfile(pidfile, &err)) {
497             g_critical("%s", error_get_pretty(err));
498             error_free(err);
499             exit(EXIT_FAILURE);
500         }
501     }
502 
503     umask(S_IRWXG | S_IRWXO);
504     sid = setsid();
505     if (sid < 0) {
506         goto fail;
507     }
508     if ((chdir("/")) < 0) {
509         goto fail;
510     }
511 
512     reopen_fd_to_null(STDIN_FILENO);
513     reopen_fd_to_null(STDOUT_FILENO);
514     reopen_fd_to_null(STDERR_FILENO);
515     return;
516 
517 fail:
518     if (pidfile) {
519         unlink(pidfile);
520     }
521     g_critical("failed to daemonize");
522     exit(EXIT_FAILURE);
523 #endif
524 }
525 
526 static int send_response(GAState *s, QDict *payload)
527 {
528     const char *buf;
529     QString *payload_qstr, *response_qstr;
530     GIOStatus status;
531 
532     g_assert(payload && s->channel);
533 
534     payload_qstr = qobject_to_json(QOBJECT(payload));
535     if (!payload_qstr) {
536         return -EINVAL;
537     }
538 
539     if (s->delimit_response) {
540         s->delimit_response = false;
541         response_qstr = qstring_new();
542         qstring_append_chr(response_qstr, QGA_SENTINEL_BYTE);
543         qstring_append(response_qstr, qstring_get_str(payload_qstr));
544         qobject_unref(payload_qstr);
545     } else {
546         response_qstr = payload_qstr;
547     }
548 
549     qstring_append_chr(response_qstr, '\n');
550     buf = qstring_get_str(response_qstr);
551     status = ga_channel_write_all(s->channel, buf, strlen(buf));
552     qobject_unref(response_qstr);
553     if (status != G_IO_STATUS_NORMAL) {
554         return -EIO;
555     }
556 
557     return 0;
558 }
559 
560 static void process_command(GAState *s, QDict *req)
561 {
562     QDict *rsp;
563     int ret;
564 
565     g_assert(req);
566     g_debug("processing command");
567     rsp = qmp_dispatch(&ga_commands, QOBJECT(req), false);
568     if (rsp) {
569         ret = send_response(s, rsp);
570         if (ret < 0) {
571             g_warning("error sending response: %s", strerror(-ret));
572         }
573         qobject_unref(rsp);
574     }
575 }
576 
577 /* handle requests/control events coming in over the channel */
578 static void process_event(void *opaque, QObject *obj, Error *err)
579 {
580     GAState *s = opaque;
581     QDict *req, *rsp;
582     int ret;
583 
584     g_debug("process_event: called");
585     assert(!obj != !err);
586     if (err) {
587         goto err;
588     }
589     req = qobject_to(QDict, obj);
590     if (!req) {
591         error_setg(&err, "Input must be a JSON object");
592         goto err;
593     }
594     if (!qdict_haskey(req, "execute")) {
595         g_warning("unrecognized payload format");
596         error_setg(&err, QERR_UNSUPPORTED);
597         goto err;
598     }
599 
600     process_command(s, req);
601     qobject_unref(obj);
602     return;
603 
604 err:
605     g_warning("failed to parse event: %s", error_get_pretty(err));
606     rsp = qmp_error_response(err);
607     ret = send_response(s, rsp);
608     if (ret < 0) {
609         g_warning("error sending error response: %s", strerror(-ret));
610     }
611     qobject_unref(rsp);
612     qobject_unref(obj);
613 }
614 
615 /* false return signals GAChannel to close the current client connection */
616 static gboolean channel_event_cb(GIOCondition condition, gpointer data)
617 {
618     GAState *s = data;
619     gchar buf[QGA_READ_COUNT_DEFAULT+1];
620     gsize count;
621     GIOStatus status = ga_channel_read(s->channel, buf, QGA_READ_COUNT_DEFAULT, &count);
622     switch (status) {
623     case G_IO_STATUS_ERROR:
624         g_warning("error reading channel");
625         stop_agent(s, false);
626         return false;
627     case G_IO_STATUS_NORMAL:
628         buf[count] = 0;
629         g_debug("read data, count: %d, data: %s", (int)count, buf);
630         json_message_parser_feed(&s->parser, (char *)buf, (int)count);
631         break;
632     case G_IO_STATUS_EOF:
633         g_debug("received EOF");
634         if (!s->virtio) {
635             return false;
636         }
637         /* fall through */
638     case G_IO_STATUS_AGAIN:
639         /* virtio causes us to spin here when no process is attached to
640          * host-side chardev. sleep a bit to mitigate this
641          */
642         if (s->virtio) {
643             usleep(100*1000);
644         }
645         return true;
646     default:
647         g_warning("unknown channel read status, closing");
648         return false;
649     }
650     return true;
651 }
652 
653 static gboolean channel_init(GAState *s, const gchar *method, const gchar *path,
654                              int listen_fd)
655 {
656     GAChannelMethod channel_method;
657 
658     if (strcmp(method, "virtio-serial") == 0) {
659         s->virtio = true; /* virtio requires special handling in some cases */
660         channel_method = GA_CHANNEL_VIRTIO_SERIAL;
661     } else if (strcmp(method, "isa-serial") == 0) {
662         channel_method = GA_CHANNEL_ISA_SERIAL;
663     } else if (strcmp(method, "unix-listen") == 0) {
664         channel_method = GA_CHANNEL_UNIX_LISTEN;
665     } else if (strcmp(method, "vsock-listen") == 0) {
666         channel_method = GA_CHANNEL_VSOCK_LISTEN;
667     } else {
668         g_critical("unsupported channel method/type: %s", method);
669         return false;
670     }
671 
672     s->channel = ga_channel_new(channel_method, path, listen_fd,
673                                 channel_event_cb, s);
674     if (!s->channel) {
675         g_critical("failed to create guest agent channel");
676         return false;
677     }
678 
679     return true;
680 }
681 
682 #ifdef _WIN32
683 DWORD WINAPI handle_serial_device_events(DWORD type, LPVOID data)
684 {
685     DWORD ret = NO_ERROR;
686     PDEV_BROADCAST_HDR broadcast_header = (PDEV_BROADCAST_HDR)data;
687 
688     if (broadcast_header->dbch_devicetype == DBT_DEVTYP_DEVICEINTERFACE) {
689         switch (type) {
690             /* Device inserted */
691         case DBT_DEVICEARRIVAL:
692             /* Start QEMU-ga's service */
693             if (!SetEvent(ga_state->wakeup_event)) {
694                 ret = GetLastError();
695             }
696             break;
697             /* Device removed */
698         case DBT_DEVICEQUERYREMOVE:
699         case DBT_DEVICEREMOVEPENDING:
700         case DBT_DEVICEREMOVECOMPLETE:
701             /* Stop QEMU-ga's service */
702             if (!ResetEvent(ga_state->wakeup_event)) {
703                 ret = GetLastError();
704             }
705             break;
706         default:
707             ret = ERROR_CALL_NOT_IMPLEMENTED;
708         }
709     }
710     return ret;
711 }
712 
713 DWORD WINAPI service_ctrl_handler(DWORD ctrl, DWORD type, LPVOID data,
714                                   LPVOID ctx)
715 {
716     DWORD ret = NO_ERROR;
717     GAService *service = &ga_state->service;
718 
719     switch (ctrl)
720     {
721         case SERVICE_CONTROL_STOP:
722         case SERVICE_CONTROL_SHUTDOWN:
723             quit_handler(SIGTERM);
724             SetEvent(ga_state->wakeup_event);
725             service->status.dwCurrentState = SERVICE_STOP_PENDING;
726             SetServiceStatus(service->status_handle, &service->status);
727             break;
728         case SERVICE_CONTROL_DEVICEEVENT:
729             handle_serial_device_events(type, data);
730             break;
731 
732         default:
733             ret = ERROR_CALL_NOT_IMPLEMENTED;
734     }
735     return ret;
736 }
737 
738 VOID WINAPI service_main(DWORD argc, TCHAR *argv[])
739 {
740     GAService *service = &ga_state->service;
741 
742     service->status_handle = RegisterServiceCtrlHandlerEx(QGA_SERVICE_NAME,
743         service_ctrl_handler, NULL);
744 
745     if (service->status_handle == 0) {
746         g_critical("Failed to register extended requests function!\n");
747         return;
748     }
749 
750     service->status.dwServiceType = SERVICE_WIN32;
751     service->status.dwCurrentState = SERVICE_RUNNING;
752     service->status.dwControlsAccepted = SERVICE_ACCEPT_STOP | SERVICE_ACCEPT_SHUTDOWN;
753     service->status.dwWin32ExitCode = NO_ERROR;
754     service->status.dwServiceSpecificExitCode = NO_ERROR;
755     service->status.dwCheckPoint = 0;
756     service->status.dwWaitHint = 0;
757     DEV_BROADCAST_DEVICEINTERFACE notification_filter;
758     ZeroMemory(&notification_filter, sizeof(notification_filter));
759     notification_filter.dbcc_devicetype = DBT_DEVTYP_DEVICEINTERFACE;
760     notification_filter.dbcc_size = sizeof(DEV_BROADCAST_DEVICEINTERFACE);
761     notification_filter.dbcc_classguid = GUID_VIOSERIAL_PORT;
762 
763     service->device_notification_handle =
764         RegisterDeviceNotification(service->status_handle,
765             &notification_filter, DEVICE_NOTIFY_SERVICE_HANDLE);
766     if (!service->device_notification_handle) {
767         g_critical("Failed to register device notification handle!\n");
768         return;
769     }
770     SetServiceStatus(service->status_handle, &service->status);
771 
772     run_agent(ga_state);
773 
774     UnregisterDeviceNotification(service->device_notification_handle);
775     service->status.dwCurrentState = SERVICE_STOPPED;
776     SetServiceStatus(service->status_handle, &service->status);
777 }
778 #endif
779 
780 static void set_persistent_state_defaults(GAPersistentState *pstate)
781 {
782     g_assert(pstate);
783     pstate->fd_counter = QGA_PSTATE_DEFAULT_FD_COUNTER;
784 }
785 
786 static void persistent_state_from_keyfile(GAPersistentState *pstate,
787                                           GKeyFile *keyfile)
788 {
789     g_assert(pstate);
790     g_assert(keyfile);
791     /* if any fields are missing, either because the file was tampered with
792      * by agents of chaos, or because the field wasn't present at the time the
793      * file was created, the best we can ever do is start over with the default
794      * values. so load them now, and ignore any errors in accessing key-value
795      * pairs
796      */
797     set_persistent_state_defaults(pstate);
798 
799     if (g_key_file_has_key(keyfile, "global", "fd_counter", NULL)) {
800         pstate->fd_counter =
801             g_key_file_get_integer(keyfile, "global", "fd_counter", NULL);
802     }
803 }
804 
805 static void persistent_state_to_keyfile(const GAPersistentState *pstate,
806                                         GKeyFile *keyfile)
807 {
808     g_assert(pstate);
809     g_assert(keyfile);
810 
811     g_key_file_set_integer(keyfile, "global", "fd_counter", pstate->fd_counter);
812 }
813 
814 static gboolean write_persistent_state(const GAPersistentState *pstate,
815                                        const gchar *path)
816 {
817     GKeyFile *keyfile = g_key_file_new();
818     GError *gerr = NULL;
819     gboolean ret = true;
820     gchar *data = NULL;
821     gsize data_len;
822 
823     g_assert(pstate);
824 
825     persistent_state_to_keyfile(pstate, keyfile);
826     data = g_key_file_to_data(keyfile, &data_len, &gerr);
827     if (gerr) {
828         g_critical("failed to convert persistent state to string: %s",
829                    gerr->message);
830         ret = false;
831         goto out;
832     }
833 
834     g_file_set_contents(path, data, data_len, &gerr);
835     if (gerr) {
836         g_critical("failed to write persistent state to %s: %s",
837                     path, gerr->message);
838         ret = false;
839         goto out;
840     }
841 
842 out:
843     if (gerr) {
844         g_error_free(gerr);
845     }
846     if (keyfile) {
847         g_key_file_free(keyfile);
848     }
849     g_free(data);
850     return ret;
851 }
852 
853 static gboolean read_persistent_state(GAPersistentState *pstate,
854                                       const gchar *path, gboolean frozen)
855 {
856     GKeyFile *keyfile = NULL;
857     GError *gerr = NULL;
858     struct stat st;
859     gboolean ret = true;
860 
861     g_assert(pstate);
862 
863     if (stat(path, &st) == -1) {
864         /* it's okay if state file doesn't exist, but any other error
865          * indicates a permissions issue or some other misconfiguration
866          * that we likely won't be able to recover from.
867          */
868         if (errno != ENOENT) {
869             g_critical("unable to access state file at path %s: %s",
870                        path, strerror(errno));
871             ret = false;
872             goto out;
873         }
874 
875         /* file doesn't exist. initialize state to default values and
876          * attempt to save now. (we could wait till later when we have
877          * modified state we need to commit, but if there's a problem,
878          * such as a missing parent directory, we want to catch it now)
879          *
880          * there is a potential scenario where someone either managed to
881          * update the agent from a version that didn't use a key store
882          * while qemu-ga thought the filesystem was frozen, or
883          * deleted the key store prior to issuing a fsfreeze, prior
884          * to restarting the agent. in this case we go ahead and defer
885          * initial creation till we actually have modified state to
886          * write, otherwise fail to recover from freeze.
887          */
888         set_persistent_state_defaults(pstate);
889         if (!frozen) {
890             ret = write_persistent_state(pstate, path);
891             if (!ret) {
892                 g_critical("unable to create state file at path %s", path);
893                 ret = false;
894                 goto out;
895             }
896         }
897         ret = true;
898         goto out;
899     }
900 
901     keyfile = g_key_file_new();
902     g_key_file_load_from_file(keyfile, path, 0, &gerr);
903     if (gerr) {
904         g_critical("error loading persistent state from path: %s, %s",
905                    path, gerr->message);
906         ret = false;
907         goto out;
908     }
909 
910     persistent_state_from_keyfile(pstate, keyfile);
911 
912 out:
913     if (keyfile) {
914         g_key_file_free(keyfile);
915     }
916     if (gerr) {
917         g_error_free(gerr);
918     }
919 
920     return ret;
921 }
922 
923 int64_t ga_get_fd_handle(GAState *s, Error **errp)
924 {
925     int64_t handle;
926 
927     g_assert(s->pstate_filepath);
928     /* we blacklist commands and avoid operations that potentially require
929      * writing to disk when we're in a frozen state. this includes opening
930      * new files, so we should never get here in that situation
931      */
932     g_assert(!ga_is_frozen(s));
933 
934     handle = s->pstate.fd_counter++;
935 
936     /* This should never happen on a reasonable timeframe, as guest-file-open
937      * would have to be issued 2^63 times */
938     if (s->pstate.fd_counter == INT64_MAX) {
939         abort();
940     }
941 
942     if (!write_persistent_state(&s->pstate, s->pstate_filepath)) {
943         error_setg(errp, "failed to commit persistent state to disk");
944         return -1;
945     }
946 
947     return handle;
948 }
949 
950 static void ga_print_cmd(QmpCommand *cmd, void *opaque)
951 {
952     printf("%s\n", qmp_command_name(cmd));
953 }
954 
955 static GList *split_list(const gchar *str, const gchar *delim)
956 {
957     GList *list = NULL;
958     int i;
959     gchar **strv;
960 
961     strv = g_strsplit(str, delim, -1);
962     for (i = 0; strv[i]; i++) {
963         list = g_list_prepend(list, strv[i]);
964     }
965     g_free(strv);
966 
967     return list;
968 }
969 
970 struct GAConfig {
971     char *channel_path;
972     char *method;
973     char *log_filepath;
974     char *pid_filepath;
975 #ifdef CONFIG_FSFREEZE
976     char *fsfreeze_hook;
977 #endif
978     char *state_dir;
979 #ifdef _WIN32
980     const char *service;
981 #endif
982     gchar *bliststr; /* blacklist may point to this string */
983     GList *blacklist;
984     int daemonize;
985     GLogLevelFlags log_level;
986     int dumpconf;
987     bool retry_path;
988 };
989 
990 static void config_load(GAConfig *config)
991 {
992     GError *gerr = NULL;
993     GKeyFile *keyfile;
994     const char *conf = g_getenv("QGA_CONF") ?: QGA_CONF_DEFAULT;
995 
996     /* read system config */
997     keyfile = g_key_file_new();
998     if (!g_key_file_load_from_file(keyfile, conf, 0, &gerr)) {
999         goto end;
1000     }
1001     if (g_key_file_has_key(keyfile, "general", "daemon", NULL)) {
1002         config->daemonize =
1003             g_key_file_get_boolean(keyfile, "general", "daemon", &gerr);
1004     }
1005     if (g_key_file_has_key(keyfile, "general", "method", NULL)) {
1006         config->method =
1007             g_key_file_get_string(keyfile, "general", "method", &gerr);
1008     }
1009     if (g_key_file_has_key(keyfile, "general", "path", NULL)) {
1010         config->channel_path =
1011             g_key_file_get_string(keyfile, "general", "path", &gerr);
1012     }
1013     if (g_key_file_has_key(keyfile, "general", "logfile", NULL)) {
1014         config->log_filepath =
1015             g_key_file_get_string(keyfile, "general", "logfile", &gerr);
1016     }
1017     if (g_key_file_has_key(keyfile, "general", "pidfile", NULL)) {
1018         config->pid_filepath =
1019             g_key_file_get_string(keyfile, "general", "pidfile", &gerr);
1020     }
1021 #ifdef CONFIG_FSFREEZE
1022     if (g_key_file_has_key(keyfile, "general", "fsfreeze-hook", NULL)) {
1023         config->fsfreeze_hook =
1024             g_key_file_get_string(keyfile,
1025                                   "general", "fsfreeze-hook", &gerr);
1026     }
1027 #endif
1028     if (g_key_file_has_key(keyfile, "general", "statedir", NULL)) {
1029         config->state_dir =
1030             g_key_file_get_string(keyfile, "general", "statedir", &gerr);
1031     }
1032     if (g_key_file_has_key(keyfile, "general", "verbose", NULL) &&
1033         g_key_file_get_boolean(keyfile, "general", "verbose", &gerr)) {
1034         /* enable all log levels */
1035         config->log_level = G_LOG_LEVEL_MASK;
1036     }
1037     if (g_key_file_has_key(keyfile, "general", "retry-path", NULL)) {
1038         config->retry_path =
1039             g_key_file_get_boolean(keyfile, "general", "retry-path", &gerr);
1040     }
1041     if (g_key_file_has_key(keyfile, "general", "blacklist", NULL)) {
1042         config->bliststr =
1043             g_key_file_get_string(keyfile, "general", "blacklist", &gerr);
1044         config->blacklist = g_list_concat(config->blacklist,
1045                                           split_list(config->bliststr, ","));
1046     }
1047 
1048 end:
1049     g_key_file_free(keyfile);
1050     if (gerr &&
1051         !(gerr->domain == G_FILE_ERROR && gerr->code == G_FILE_ERROR_NOENT)) {
1052         g_critical("error loading configuration from path: %s, %s",
1053                    QGA_CONF_DEFAULT, gerr->message);
1054         exit(EXIT_FAILURE);
1055     }
1056     g_clear_error(&gerr);
1057 }
1058 
1059 static gchar *list_join(GList *list, const gchar separator)
1060 {
1061     GString *str = g_string_new("");
1062 
1063     while (list) {
1064         str = g_string_append(str, (gchar *)list->data);
1065         list = g_list_next(list);
1066         if (list) {
1067             str = g_string_append_c(str, separator);
1068         }
1069     }
1070 
1071     return g_string_free(str, FALSE);
1072 }
1073 
1074 static void config_dump(GAConfig *config)
1075 {
1076     GError *error = NULL;
1077     GKeyFile *keyfile;
1078     gchar *tmp;
1079 
1080     keyfile = g_key_file_new();
1081     g_assert(keyfile);
1082 
1083     g_key_file_set_boolean(keyfile, "general", "daemon", config->daemonize);
1084     g_key_file_set_string(keyfile, "general", "method", config->method);
1085     if (config->channel_path) {
1086         g_key_file_set_string(keyfile, "general", "path", config->channel_path);
1087     }
1088     if (config->log_filepath) {
1089         g_key_file_set_string(keyfile, "general", "logfile",
1090                               config->log_filepath);
1091     }
1092     g_key_file_set_string(keyfile, "general", "pidfile", config->pid_filepath);
1093 #ifdef CONFIG_FSFREEZE
1094     if (config->fsfreeze_hook) {
1095         g_key_file_set_string(keyfile, "general", "fsfreeze-hook",
1096                               config->fsfreeze_hook);
1097     }
1098 #endif
1099     g_key_file_set_string(keyfile, "general", "statedir", config->state_dir);
1100     g_key_file_set_boolean(keyfile, "general", "verbose",
1101                            config->log_level == G_LOG_LEVEL_MASK);
1102     g_key_file_set_boolean(keyfile, "general", "retry-path",
1103                            config->retry_path);
1104     tmp = list_join(config->blacklist, ',');
1105     g_key_file_set_string(keyfile, "general", "blacklist", tmp);
1106     g_free(tmp);
1107 
1108     tmp = g_key_file_to_data(keyfile, NULL, &error);
1109     if (error) {
1110         g_critical("Failed to dump keyfile: %s", error->message);
1111         g_clear_error(&error);
1112     } else {
1113         printf("%s", tmp);
1114     }
1115 
1116     g_free(tmp);
1117     g_key_file_free(keyfile);
1118 }
1119 
1120 static void config_parse(GAConfig *config, int argc, char **argv)
1121 {
1122     const char *sopt = "hVvdm:p:l:f:F::b:s:t:Dr";
1123     int opt_ind = 0, ch;
1124     const struct option lopt[] = {
1125         { "help", 0, NULL, 'h' },
1126         { "version", 0, NULL, 'V' },
1127         { "dump-conf", 0, NULL, 'D' },
1128         { "logfile", 1, NULL, 'l' },
1129         { "pidfile", 1, NULL, 'f' },
1130 #ifdef CONFIG_FSFREEZE
1131         { "fsfreeze-hook", 2, NULL, 'F' },
1132 #endif
1133         { "verbose", 0, NULL, 'v' },
1134         { "method", 1, NULL, 'm' },
1135         { "path", 1, NULL, 'p' },
1136         { "daemonize", 0, NULL, 'd' },
1137         { "blacklist", 1, NULL, 'b' },
1138 #ifdef _WIN32
1139         { "service", 1, NULL, 's' },
1140 #endif
1141         { "statedir", 1, NULL, 't' },
1142         { "retry-path", 0, NULL, 'r' },
1143         { NULL, 0, NULL, 0 }
1144     };
1145 
1146     while ((ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1) {
1147         switch (ch) {
1148         case 'm':
1149             g_free(config->method);
1150             config->method = g_strdup(optarg);
1151             break;
1152         case 'p':
1153             g_free(config->channel_path);
1154             config->channel_path = g_strdup(optarg);
1155             break;
1156         case 'l':
1157             g_free(config->log_filepath);
1158             config->log_filepath = g_strdup(optarg);
1159             break;
1160         case 'f':
1161             g_free(config->pid_filepath);
1162             config->pid_filepath = g_strdup(optarg);
1163             break;
1164 #ifdef CONFIG_FSFREEZE
1165         case 'F':
1166             g_free(config->fsfreeze_hook);
1167             config->fsfreeze_hook = g_strdup(optarg ?: QGA_FSFREEZE_HOOK_DEFAULT);
1168             break;
1169 #endif
1170         case 't':
1171             g_free(config->state_dir);
1172             config->state_dir = g_strdup(optarg);
1173             break;
1174         case 'v':
1175             /* enable all log levels */
1176             config->log_level = G_LOG_LEVEL_MASK;
1177             break;
1178         case 'V':
1179             printf("QEMU Guest Agent %s\n", QEMU_VERSION);
1180             exit(EXIT_SUCCESS);
1181         case 'd':
1182             config->daemonize = 1;
1183             break;
1184         case 'D':
1185             config->dumpconf = 1;
1186             break;
1187         case 'r':
1188             config->retry_path = true;
1189             break;
1190         case 'b': {
1191             if (is_help_option(optarg)) {
1192                 qmp_for_each_command(&ga_commands, ga_print_cmd, NULL);
1193                 exit(EXIT_SUCCESS);
1194             }
1195             config->blacklist = g_list_concat(config->blacklist,
1196                                              split_list(optarg, ","));
1197             break;
1198         }
1199 #ifdef _WIN32
1200         case 's':
1201             config->service = optarg;
1202             if (strcmp(config->service, "install") == 0) {
1203                 if (ga_install_vss_provider()) {
1204                     exit(EXIT_FAILURE);
1205                 }
1206                 if (ga_install_service(config->channel_path,
1207                                        config->log_filepath, config->state_dir)) {
1208                     exit(EXIT_FAILURE);
1209                 }
1210                 exit(EXIT_SUCCESS);
1211             } else if (strcmp(config->service, "uninstall") == 0) {
1212                 ga_uninstall_vss_provider();
1213                 exit(ga_uninstall_service());
1214             } else if (strcmp(config->service, "vss-install") == 0) {
1215                 if (ga_install_vss_provider()) {
1216                     exit(EXIT_FAILURE);
1217                 }
1218                 exit(EXIT_SUCCESS);
1219             } else if (strcmp(config->service, "vss-uninstall") == 0) {
1220                 ga_uninstall_vss_provider();
1221                 exit(EXIT_SUCCESS);
1222             } else {
1223                 printf("Unknown service command.\n");
1224                 exit(EXIT_FAILURE);
1225             }
1226             break;
1227 #endif
1228         case 'h':
1229             usage(argv[0]);
1230             exit(EXIT_SUCCESS);
1231         case '?':
1232             g_print("Unknown option, try '%s --help' for more information.\n",
1233                     argv[0]);
1234             exit(EXIT_FAILURE);
1235         }
1236     }
1237 }
1238 
1239 static void config_free(GAConfig *config)
1240 {
1241     g_free(config->method);
1242     g_free(config->log_filepath);
1243     g_free(config->pid_filepath);
1244     g_free(config->state_dir);
1245     g_free(config->channel_path);
1246     g_free(config->bliststr);
1247 #ifdef CONFIG_FSFREEZE
1248     g_free(config->fsfreeze_hook);
1249 #endif
1250     g_list_free_full(config->blacklist, g_free);
1251     g_free(config);
1252 }
1253 
1254 static bool check_is_frozen(GAState *s)
1255 {
1256 #ifndef _WIN32
1257     /* check if a previous instance of qemu-ga exited with filesystems' state
1258      * marked as frozen. this could be a stale value (a non-qemu-ga process
1259      * or reboot may have since unfrozen them), but better to require an
1260      * uneeded unfreeze than to risk hanging on start-up
1261      */
1262     struct stat st;
1263     if (stat(s->state_filepath_isfrozen, &st) == -1) {
1264         /* it's okay if the file doesn't exist, but if we can't access for
1265          * some other reason, such as permissions, there's a configuration
1266          * that needs to be addressed. so just bail now before we get into
1267          * more trouble later
1268          */
1269         if (errno != ENOENT) {
1270             g_critical("unable to access state file at path %s: %s",
1271                        s->state_filepath_isfrozen, strerror(errno));
1272             return EXIT_FAILURE;
1273         }
1274     } else {
1275         g_warning("previous instance appears to have exited with frozen"
1276                   " filesystems. deferring logging/pidfile creation and"
1277                   " disabling non-fsfreeze-safe commands until"
1278                   " guest-fsfreeze-thaw is issued, or filesystems are"
1279                   " manually unfrozen and the file %s is removed",
1280                   s->state_filepath_isfrozen);
1281         return true;
1282     }
1283 #endif
1284     return false;
1285 }
1286 
1287 static GAState *initialize_agent(GAConfig *config, int socket_activation)
1288 {
1289     GAState *s = g_new0(GAState, 1);
1290 
1291     g_assert(ga_state == NULL);
1292 
1293     s->log_level = config->log_level;
1294     s->log_file = stderr;
1295 #ifdef CONFIG_FSFREEZE
1296     s->fsfreeze_hook = config->fsfreeze_hook;
1297 #endif
1298     s->pstate_filepath = g_strdup_printf("%s/qga.state", config->state_dir);
1299     s->state_filepath_isfrozen = g_strdup_printf("%s/qga.state.isfrozen",
1300                                                  config->state_dir);
1301     s->frozen = check_is_frozen(s);
1302 
1303     g_log_set_default_handler(ga_log, s);
1304     g_log_set_fatal_mask(NULL, G_LOG_LEVEL_ERROR);
1305     ga_enable_logging(s);
1306 
1307 #ifdef _WIN32
1308     /* On win32 the state directory is application specific (be it the default
1309      * or a user override). We got past the command line parsing; let's create
1310      * the directory (with any intermediate directories). If we run into an
1311      * error later on, we won't try to clean up the directory, it is considered
1312      * persistent.
1313      */
1314     if (g_mkdir_with_parents(config->state_dir, S_IRWXU) == -1) {
1315         g_critical("unable to create (an ancestor of) the state directory"
1316                    " '%s': %s", config->state_dir, strerror(errno));
1317         return NULL;
1318     }
1319 #endif
1320 
1321     if (ga_is_frozen(s)) {
1322         if (config->daemonize) {
1323             /* delay opening/locking of pidfile till filesystems are unfrozen */
1324             s->deferred_options.pid_filepath = config->pid_filepath;
1325             become_daemon(NULL);
1326         }
1327         if (config->log_filepath) {
1328             /* delay opening the log file till filesystems are unfrozen */
1329             s->deferred_options.log_filepath = config->log_filepath;
1330         }
1331         ga_disable_logging(s);
1332         qmp_for_each_command(&ga_commands, ga_disable_non_whitelisted, NULL);
1333     } else {
1334         if (config->daemonize) {
1335             become_daemon(config->pid_filepath);
1336         }
1337         if (config->log_filepath) {
1338             FILE *log_file = ga_open_logfile(config->log_filepath);
1339             if (!log_file) {
1340                 g_critical("unable to open specified log file: %s",
1341                            strerror(errno));
1342                 return NULL;
1343             }
1344             s->log_file = log_file;
1345         }
1346     }
1347 
1348     /* load persistent state from disk */
1349     if (!read_persistent_state(&s->pstate,
1350                                s->pstate_filepath,
1351                                ga_is_frozen(s))) {
1352         g_critical("failed to load persistent state");
1353         return NULL;
1354     }
1355 
1356     config->blacklist = ga_command_blacklist_init(config->blacklist);
1357     if (config->blacklist) {
1358         GList *l = config->blacklist;
1359         s->blacklist = config->blacklist;
1360         do {
1361             g_debug("disabling command: %s", (char *)l->data);
1362             qmp_disable_command(&ga_commands, l->data);
1363             l = g_list_next(l);
1364         } while (l);
1365     }
1366     s->command_state = ga_command_state_new();
1367     ga_command_state_init(s, s->command_state);
1368     ga_command_state_init_all(s->command_state);
1369     json_message_parser_init(&s->parser, process_event, s, NULL);
1370 
1371 #ifndef _WIN32
1372     if (!register_signal_handlers()) {
1373         g_critical("failed to register signal handlers");
1374         return NULL;
1375     }
1376 #endif
1377 
1378     s->main_loop = g_main_loop_new(NULL, false);
1379 
1380     s->config = config;
1381     s->socket_activation = socket_activation;
1382 
1383 #ifdef _WIN32
1384     s->wakeup_event = CreateEvent(NULL, TRUE, FALSE, TEXT("WakeUp"));
1385     if (s->wakeup_event == NULL) {
1386         g_critical("CreateEvent failed");
1387         return NULL;
1388     }
1389 #endif
1390 
1391     ga_state = s;
1392     return s;
1393 }
1394 
1395 static void cleanup_agent(GAState *s)
1396 {
1397 #ifdef _WIN32
1398     CloseHandle(s->wakeup_event);
1399 #endif
1400     if (s->command_state) {
1401         ga_command_state_cleanup_all(s->command_state);
1402         ga_command_state_free(s->command_state);
1403         json_message_parser_destroy(&s->parser);
1404     }
1405     g_free(s->pstate_filepath);
1406     g_free(s->state_filepath_isfrozen);
1407     if (s->main_loop) {
1408         g_main_loop_unref(s->main_loop);
1409     }
1410     g_free(s);
1411     ga_state = NULL;
1412 }
1413 
1414 static int run_agent_once(GAState *s)
1415 {
1416     if (!channel_init(s, s->config->method, s->config->channel_path,
1417                       s->socket_activation ? FIRST_SOCKET_ACTIVATION_FD : -1)) {
1418         g_critical("failed to initialize guest agent channel");
1419         return EXIT_FAILURE;
1420     }
1421 
1422     g_main_loop_run(ga_state->main_loop);
1423 
1424     if (s->channel) {
1425         ga_channel_free(s->channel);
1426     }
1427 
1428     return EXIT_SUCCESS;
1429 }
1430 
1431 static void wait_for_channel_availability(GAState *s)
1432 {
1433     g_warning("waiting for channel path...");
1434 #ifndef _WIN32
1435     sleep(QGA_RETRY_INTERVAL);
1436 #else
1437     DWORD dwWaitResult;
1438 
1439     dwWaitResult = WaitForSingleObject(s->wakeup_event, INFINITE);
1440 
1441     switch (dwWaitResult) {
1442     case WAIT_OBJECT_0:
1443         break;
1444     case WAIT_TIMEOUT:
1445         break;
1446     default:
1447         g_critical("WaitForSingleObject failed");
1448     }
1449 #endif
1450 }
1451 
1452 static int run_agent(GAState *s)
1453 {
1454     int ret = EXIT_SUCCESS;
1455 
1456     s->force_exit = false;
1457 
1458     do {
1459         ret = run_agent_once(s);
1460         if (s->config->retry_path && !s->force_exit) {
1461             g_warning("agent stopped unexpectedly, restarting...");
1462             wait_for_channel_availability(s);
1463         }
1464     } while (s->config->retry_path && !s->force_exit);
1465 
1466     return ret;
1467 }
1468 
1469 static void stop_agent(GAState *s, bool requested)
1470 {
1471     if (!s->force_exit) {
1472         s->force_exit = requested;
1473     }
1474 
1475     if (g_main_loop_is_running(s->main_loop)) {
1476         g_main_loop_quit(s->main_loop);
1477     }
1478 }
1479 
1480 int main(int argc, char **argv)
1481 {
1482     int ret = EXIT_SUCCESS;
1483     GAState *s;
1484     GAConfig *config = g_new0(GAConfig, 1);
1485     int socket_activation;
1486 
1487     config->log_level = G_LOG_LEVEL_ERROR | G_LOG_LEVEL_CRITICAL;
1488 
1489     qga_qmp_init_marshal(&ga_commands);
1490 
1491     init_dfl_pathnames();
1492     config_load(config);
1493     config_parse(config, argc, argv);
1494 
1495     if (config->pid_filepath == NULL) {
1496         config->pid_filepath = g_strdup(dfl_pathnames.pidfile);
1497     }
1498 
1499     if (config->state_dir == NULL) {
1500         config->state_dir = g_strdup(dfl_pathnames.state_dir);
1501     }
1502 
1503     if (config->method == NULL) {
1504         config->method = g_strdup("virtio-serial");
1505     }
1506 
1507     socket_activation = check_socket_activation();
1508     if (socket_activation > 1) {
1509         g_critical("qemu-ga only supports listening on one socket");
1510         ret = EXIT_FAILURE;
1511         goto end;
1512     }
1513     if (socket_activation) {
1514         SocketAddress *addr;
1515 
1516         g_free(config->method);
1517         g_free(config->channel_path);
1518         config->method = NULL;
1519         config->channel_path = NULL;
1520 
1521         addr = socket_local_address(FIRST_SOCKET_ACTIVATION_FD, NULL);
1522         if (addr) {
1523             if (addr->type == SOCKET_ADDRESS_TYPE_UNIX) {
1524                 config->method = g_strdup("unix-listen");
1525             } else if (addr->type == SOCKET_ADDRESS_TYPE_VSOCK) {
1526                 config->method = g_strdup("vsock-listen");
1527             }
1528 
1529             qapi_free_SocketAddress(addr);
1530         }
1531 
1532         if (!config->method) {
1533             g_critical("unsupported listen fd type");
1534             ret = EXIT_FAILURE;
1535             goto end;
1536         }
1537     } else if (config->channel_path == NULL) {
1538         if (strcmp(config->method, "virtio-serial") == 0) {
1539             /* try the default path for the virtio-serial port */
1540             config->channel_path = g_strdup(QGA_VIRTIO_PATH_DEFAULT);
1541         } else if (strcmp(config->method, "isa-serial") == 0) {
1542             /* try the default path for the serial port - COM1 */
1543             config->channel_path = g_strdup(QGA_SERIAL_PATH_DEFAULT);
1544         } else {
1545             g_critical("must specify a path for this channel");
1546             ret = EXIT_FAILURE;
1547             goto end;
1548         }
1549     }
1550 
1551     if (config->dumpconf) {
1552         config_dump(config);
1553         goto end;
1554     }
1555 
1556     s = initialize_agent(config, socket_activation);
1557     if (!s) {
1558         g_critical("error initializing guest agent");
1559         goto end;
1560     }
1561 
1562 #ifdef _WIN32
1563     if (config->daemonize) {
1564         SERVICE_TABLE_ENTRY service_table[] = {
1565             { (char *)QGA_SERVICE_NAME, service_main }, { NULL, NULL } };
1566         StartServiceCtrlDispatcher(service_table);
1567     } else {
1568         ret = run_agent(s);
1569     }
1570 #else
1571     ret = run_agent(s);
1572 #endif
1573 
1574     cleanup_agent(s);
1575 
1576 end:
1577     if (config->daemonize) {
1578         unlink(config->pid_filepath);
1579     }
1580 
1581     config_free(config);
1582 
1583     return ret;
1584 }
1585