1 /* 2 * QEMU Guest Agent 3 * 4 * Copyright IBM Corp. 2011 5 * 6 * Authors: 7 * Adam Litke <aglitke@linux.vnet.ibm.com> 8 * Michael Roth <mdroth@linux.vnet.ibm.com> 9 * 10 * This work is licensed under the terms of the GNU GPL, version 2 or later. 11 * See the COPYING file in the top-level directory. 12 */ 13 14 #include "qemu/osdep.h" 15 #include <getopt.h> 16 #include <glib/gstdio.h> 17 #ifndef _WIN32 18 #include <syslog.h> 19 #include <sys/wait.h> 20 #endif 21 #include "qapi/qmp/json-parser.h" 22 #include "qapi/qmp/qdict.h" 23 #include "qapi/qmp/qjson.h" 24 #include "qapi/qmp/qstring.h" 25 #include "guest-agent-core.h" 26 #include "qemu/module.h" 27 #include "qga-qapi-commands.h" 28 #include "qapi/qmp/qerror.h" 29 #include "qapi/error.h" 30 #include "channel.h" 31 #include "qemu/bswap.h" 32 #include "qemu/help_option.h" 33 #include "qemu/sockets.h" 34 #include "qemu/systemd.h" 35 #include "qemu-version.h" 36 #ifdef _WIN32 37 #include "qga/service-win32.h" 38 #include "qga/vss-win32.h" 39 #endif 40 #ifdef __linux__ 41 #include <linux/fs.h> 42 #ifdef FIFREEZE 43 #define CONFIG_FSFREEZE 44 #endif 45 #endif 46 47 #ifndef _WIN32 48 #define QGA_VIRTIO_PATH_DEFAULT "/dev/virtio-ports/org.qemu.guest_agent.0" 49 #define QGA_STATE_RELATIVE_DIR "run" 50 #define QGA_SERIAL_PATH_DEFAULT "/dev/ttyS0" 51 #else 52 #define QGA_VIRTIO_PATH_DEFAULT "\\\\.\\Global\\org.qemu.guest_agent.0" 53 #define QGA_STATE_RELATIVE_DIR "qemu-ga" 54 #define QGA_SERIAL_PATH_DEFAULT "COM1" 55 #endif 56 #ifdef CONFIG_FSFREEZE 57 #define QGA_FSFREEZE_HOOK_DEFAULT CONFIG_QEMU_CONFDIR "/fsfreeze-hook" 58 #endif 59 #define QGA_SENTINEL_BYTE 0xFF 60 #define QGA_CONF_DEFAULT CONFIG_QEMU_CONFDIR G_DIR_SEPARATOR_S "qemu-ga.conf" 61 62 static struct { 63 const char *state_dir; 64 const char *pidfile; 65 } dfl_pathnames; 66 67 typedef struct GAPersistentState { 68 #define QGA_PSTATE_DEFAULT_FD_COUNTER 1000 69 int64_t fd_counter; 70 } GAPersistentState; 71 72 struct GAState { 73 JSONMessageParser parser; 74 GMainLoop *main_loop; 75 GAChannel *channel; 76 bool virtio; /* fastpath to check for virtio to deal with poll() quirks */ 77 GACommandState *command_state; 78 GLogLevelFlags log_level; 79 FILE *log_file; 80 bool logging_enabled; 81 #ifdef _WIN32 82 GAService service; 83 #endif 84 bool delimit_response; 85 bool frozen; 86 GList *blacklist; 87 char *state_filepath_isfrozen; 88 struct { 89 const char *log_filepath; 90 const char *pid_filepath; 91 } deferred_options; 92 #ifdef CONFIG_FSFREEZE 93 const char *fsfreeze_hook; 94 #endif 95 gchar *pstate_filepath; 96 GAPersistentState pstate; 97 }; 98 99 struct GAState *ga_state; 100 QmpCommandList ga_commands; 101 102 /* commands that are safe to issue while filesystems are frozen */ 103 static const char *ga_freeze_whitelist[] = { 104 "guest-ping", 105 "guest-info", 106 "guest-sync", 107 "guest-sync-delimited", 108 "guest-fsfreeze-status", 109 "guest-fsfreeze-thaw", 110 NULL 111 }; 112 113 #ifdef _WIN32 114 DWORD WINAPI service_ctrl_handler(DWORD ctrl, DWORD type, LPVOID data, 115 LPVOID ctx); 116 VOID WINAPI service_main(DWORD argc, TCHAR *argv[]); 117 #endif 118 119 static void 120 init_dfl_pathnames(void) 121 { 122 g_assert(dfl_pathnames.state_dir == NULL); 123 g_assert(dfl_pathnames.pidfile == NULL); 124 dfl_pathnames.state_dir = qemu_get_local_state_pathname( 125 QGA_STATE_RELATIVE_DIR); 126 dfl_pathnames.pidfile = qemu_get_local_state_pathname( 127 QGA_STATE_RELATIVE_DIR G_DIR_SEPARATOR_S "qemu-ga.pid"); 128 } 129 130 static void quit_handler(int sig) 131 { 132 /* if we're frozen, don't exit unless we're absolutely forced to, 133 * because it's basically impossible for graceful exit to complete 134 * unless all log/pid files are on unfreezable filesystems. there's 135 * also a very likely chance killing the agent before unfreezing 136 * the filesystems is a mistake (or will be viewed as one later). 137 * On Windows the freeze interval is limited to 10 seconds, so 138 * we should quit, but first we should wait for the timeout, thaw 139 * the filesystem and quit. 140 */ 141 if (ga_is_frozen(ga_state)) { 142 #ifdef _WIN32 143 int i = 0; 144 Error *err = NULL; 145 HANDLE hEventTimeout; 146 147 g_debug("Thawing filesystems before exiting"); 148 149 hEventTimeout = OpenEvent(EVENT_ALL_ACCESS, FALSE, EVENT_NAME_TIMEOUT); 150 if (hEventTimeout) { 151 WaitForSingleObject(hEventTimeout, 0); 152 CloseHandle(hEventTimeout); 153 } 154 qga_vss_fsfreeze(&i, false, &err); 155 if (err) { 156 g_debug("Error unfreezing filesystems prior to exiting: %s", 157 error_get_pretty(err)); 158 error_free(err); 159 } 160 #else 161 return; 162 #endif 163 } 164 g_debug("received signal num %d, quitting", sig); 165 166 if (g_main_loop_is_running(ga_state->main_loop)) { 167 g_main_loop_quit(ga_state->main_loop); 168 } 169 } 170 171 #ifndef _WIN32 172 static gboolean register_signal_handlers(void) 173 { 174 struct sigaction sigact; 175 int ret; 176 177 memset(&sigact, 0, sizeof(struct sigaction)); 178 sigact.sa_handler = quit_handler; 179 180 ret = sigaction(SIGINT, &sigact, NULL); 181 if (ret == -1) { 182 g_error("error configuring signal handler: %s", strerror(errno)); 183 } 184 ret = sigaction(SIGTERM, &sigact, NULL); 185 if (ret == -1) { 186 g_error("error configuring signal handler: %s", strerror(errno)); 187 } 188 189 sigact.sa_handler = SIG_IGN; 190 if (sigaction(SIGPIPE, &sigact, NULL) != 0) { 191 g_error("error configuring SIGPIPE signal handler: %s", 192 strerror(errno)); 193 } 194 195 return true; 196 } 197 198 /* TODO: use this in place of all post-fork() fclose(std*) callers */ 199 void reopen_fd_to_null(int fd) 200 { 201 int nullfd; 202 203 nullfd = open("/dev/null", O_RDWR); 204 if (nullfd < 0) { 205 return; 206 } 207 208 dup2(nullfd, fd); 209 210 if (nullfd != fd) { 211 close(nullfd); 212 } 213 } 214 #endif 215 216 static void usage(const char *cmd) 217 { 218 printf( 219 "Usage: %s [-m <method> -p <path>] [<options>]\n" 220 "QEMU Guest Agent " QEMU_FULL_VERSION "\n" 221 QEMU_COPYRIGHT "\n" 222 "\n" 223 " -m, --method transport method: one of unix-listen, virtio-serial,\n" 224 " isa-serial, or vsock-listen (virtio-serial is the default)\n" 225 " -p, --path device/socket path (the default for virtio-serial is:\n" 226 " %s,\n" 227 " the default for isa-serial is:\n" 228 " %s)\n" 229 " -l, --logfile set logfile path, logs to stderr by default\n" 230 " -f, --pidfile specify pidfile (default is %s)\n" 231 #ifdef CONFIG_FSFREEZE 232 " -F, --fsfreeze-hook\n" 233 " enable fsfreeze hook. Accepts an optional argument that\n" 234 " specifies script to run on freeze/thaw. Script will be\n" 235 " called with 'freeze'/'thaw' arguments accordingly.\n" 236 " (default is %s)\n" 237 " If using -F with an argument, do not follow -F with a\n" 238 " space.\n" 239 " (for example: -F/var/run/fsfreezehook.sh)\n" 240 #endif 241 " -t, --statedir specify dir to store state information (absolute paths\n" 242 " only, default is %s)\n" 243 " -v, --verbose log extra debugging information\n" 244 " -V, --version print version information and exit\n" 245 " -d, --daemonize become a daemon\n" 246 #ifdef _WIN32 247 " -s, --service service commands: install, uninstall, vss-install, vss-uninstall\n" 248 #endif 249 " -b, --blacklist comma-separated list of RPCs to disable (no spaces, \"?\"\n" 250 " to list available RPCs)\n" 251 " -D, --dump-conf dump a qemu-ga config file based on current config\n" 252 " options / command-line parameters to stdout\n" 253 " -h, --help display this help and exit\n" 254 "\n" 255 QEMU_HELP_BOTTOM "\n" 256 , cmd, QGA_VIRTIO_PATH_DEFAULT, QGA_SERIAL_PATH_DEFAULT, 257 dfl_pathnames.pidfile, 258 #ifdef CONFIG_FSFREEZE 259 QGA_FSFREEZE_HOOK_DEFAULT, 260 #endif 261 dfl_pathnames.state_dir); 262 } 263 264 static const char *ga_log_level_str(GLogLevelFlags level) 265 { 266 switch (level & G_LOG_LEVEL_MASK) { 267 case G_LOG_LEVEL_ERROR: 268 return "error"; 269 case G_LOG_LEVEL_CRITICAL: 270 return "critical"; 271 case G_LOG_LEVEL_WARNING: 272 return "warning"; 273 case G_LOG_LEVEL_MESSAGE: 274 return "message"; 275 case G_LOG_LEVEL_INFO: 276 return "info"; 277 case G_LOG_LEVEL_DEBUG: 278 return "debug"; 279 default: 280 return "user"; 281 } 282 } 283 284 bool ga_logging_enabled(GAState *s) 285 { 286 return s->logging_enabled; 287 } 288 289 void ga_disable_logging(GAState *s) 290 { 291 s->logging_enabled = false; 292 } 293 294 void ga_enable_logging(GAState *s) 295 { 296 s->logging_enabled = true; 297 } 298 299 static void ga_log(const gchar *domain, GLogLevelFlags level, 300 const gchar *msg, gpointer opaque) 301 { 302 GAState *s = opaque; 303 GTimeVal time; 304 const char *level_str = ga_log_level_str(level); 305 306 if (!ga_logging_enabled(s)) { 307 return; 308 } 309 310 level &= G_LOG_LEVEL_MASK; 311 #ifndef _WIN32 312 if (g_strcmp0(domain, "syslog") == 0) { 313 syslog(LOG_INFO, "%s: %s", level_str, msg); 314 } else if (level & s->log_level) { 315 #else 316 if (level & s->log_level) { 317 #endif 318 g_get_current_time(&time); 319 fprintf(s->log_file, 320 "%lu.%lu: %s: %s\n", time.tv_sec, time.tv_usec, level_str, msg); 321 fflush(s->log_file); 322 } 323 } 324 325 void ga_set_response_delimited(GAState *s) 326 { 327 s->delimit_response = true; 328 } 329 330 static FILE *ga_open_logfile(const char *logfile) 331 { 332 FILE *f; 333 334 f = fopen(logfile, "a"); 335 if (!f) { 336 return NULL; 337 } 338 339 qemu_set_cloexec(fileno(f)); 340 return f; 341 } 342 343 static gint ga_strcmp(gconstpointer str1, gconstpointer str2) 344 { 345 return strcmp(str1, str2); 346 } 347 348 /* disable commands that aren't safe for fsfreeze */ 349 static void ga_disable_non_whitelisted(QmpCommand *cmd, void *opaque) 350 { 351 bool whitelisted = false; 352 int i = 0; 353 const char *name = qmp_command_name(cmd); 354 355 while (ga_freeze_whitelist[i] != NULL) { 356 if (strcmp(name, ga_freeze_whitelist[i]) == 0) { 357 whitelisted = true; 358 } 359 i++; 360 } 361 if (!whitelisted) { 362 g_debug("disabling command: %s", name); 363 qmp_disable_command(&ga_commands, name); 364 } 365 } 366 367 /* [re-]enable all commands, except those explicitly blacklisted by user */ 368 static void ga_enable_non_blacklisted(QmpCommand *cmd, void *opaque) 369 { 370 GList *blacklist = opaque; 371 const char *name = qmp_command_name(cmd); 372 373 if (g_list_find_custom(blacklist, name, ga_strcmp) == NULL && 374 !qmp_command_is_enabled(cmd)) { 375 g_debug("enabling command: %s", name); 376 qmp_enable_command(&ga_commands, name); 377 } 378 } 379 380 static bool ga_create_file(const char *path) 381 { 382 int fd = open(path, O_CREAT | O_WRONLY, S_IWUSR | S_IRUSR); 383 if (fd == -1) { 384 g_warning("unable to open/create file %s: %s", path, strerror(errno)); 385 return false; 386 } 387 close(fd); 388 return true; 389 } 390 391 static bool ga_delete_file(const char *path) 392 { 393 int ret = unlink(path); 394 if (ret == -1) { 395 g_warning("unable to delete file: %s: %s", path, strerror(errno)); 396 return false; 397 } 398 399 return true; 400 } 401 402 bool ga_is_frozen(GAState *s) 403 { 404 return s->frozen; 405 } 406 407 void ga_set_frozen(GAState *s) 408 { 409 if (ga_is_frozen(s)) { 410 return; 411 } 412 /* disable all non-whitelisted (for frozen state) commands */ 413 qmp_for_each_command(&ga_commands, ga_disable_non_whitelisted, NULL); 414 g_warning("disabling logging due to filesystem freeze"); 415 ga_disable_logging(s); 416 s->frozen = true; 417 if (!ga_create_file(s->state_filepath_isfrozen)) { 418 g_warning("unable to create %s, fsfreeze may not function properly", 419 s->state_filepath_isfrozen); 420 } 421 } 422 423 void ga_unset_frozen(GAState *s) 424 { 425 if (!ga_is_frozen(s)) { 426 return; 427 } 428 429 /* if we delayed creation/opening of pid/log files due to being 430 * in a frozen state at start up, do it now 431 */ 432 if (s->deferred_options.log_filepath) { 433 s->log_file = ga_open_logfile(s->deferred_options.log_filepath); 434 if (!s->log_file) { 435 s->log_file = stderr; 436 } 437 s->deferred_options.log_filepath = NULL; 438 } 439 ga_enable_logging(s); 440 g_warning("logging re-enabled due to filesystem unfreeze"); 441 if (s->deferred_options.pid_filepath) { 442 Error *err = NULL; 443 444 if (!qemu_write_pidfile(s->deferred_options.pid_filepath, &err)) { 445 g_warning("%s", error_get_pretty(err)); 446 error_free(err); 447 } 448 s->deferred_options.pid_filepath = NULL; 449 } 450 451 /* enable all disabled, non-blacklisted commands */ 452 qmp_for_each_command(&ga_commands, ga_enable_non_blacklisted, s->blacklist); 453 s->frozen = false; 454 if (!ga_delete_file(s->state_filepath_isfrozen)) { 455 g_warning("unable to delete %s, fsfreeze may not function properly", 456 s->state_filepath_isfrozen); 457 } 458 } 459 460 #ifdef CONFIG_FSFREEZE 461 const char *ga_fsfreeze_hook(GAState *s) 462 { 463 return s->fsfreeze_hook; 464 } 465 #endif 466 467 static void become_daemon(const char *pidfile) 468 { 469 #ifndef _WIN32 470 pid_t pid, sid; 471 472 pid = fork(); 473 if (pid < 0) { 474 exit(EXIT_FAILURE); 475 } 476 if (pid > 0) { 477 exit(EXIT_SUCCESS); 478 } 479 480 if (pidfile) { 481 Error *err = NULL; 482 483 if (!qemu_write_pidfile(pidfile, &err)) { 484 g_critical("%s", error_get_pretty(err)); 485 error_free(err); 486 exit(EXIT_FAILURE); 487 } 488 } 489 490 umask(S_IRWXG | S_IRWXO); 491 sid = setsid(); 492 if (sid < 0) { 493 goto fail; 494 } 495 if ((chdir("/")) < 0) { 496 goto fail; 497 } 498 499 reopen_fd_to_null(STDIN_FILENO); 500 reopen_fd_to_null(STDOUT_FILENO); 501 reopen_fd_to_null(STDERR_FILENO); 502 return; 503 504 fail: 505 if (pidfile) { 506 unlink(pidfile); 507 } 508 g_critical("failed to daemonize"); 509 exit(EXIT_FAILURE); 510 #endif 511 } 512 513 static int send_response(GAState *s, QDict *payload) 514 { 515 const char *buf; 516 QString *payload_qstr, *response_qstr; 517 GIOStatus status; 518 519 g_assert(payload && s->channel); 520 521 payload_qstr = qobject_to_json(QOBJECT(payload)); 522 if (!payload_qstr) { 523 return -EINVAL; 524 } 525 526 if (s->delimit_response) { 527 s->delimit_response = false; 528 response_qstr = qstring_new(); 529 qstring_append_chr(response_qstr, QGA_SENTINEL_BYTE); 530 qstring_append(response_qstr, qstring_get_str(payload_qstr)); 531 qobject_unref(payload_qstr); 532 } else { 533 response_qstr = payload_qstr; 534 } 535 536 qstring_append_chr(response_qstr, '\n'); 537 buf = qstring_get_str(response_qstr); 538 status = ga_channel_write_all(s->channel, buf, strlen(buf)); 539 qobject_unref(response_qstr); 540 if (status != G_IO_STATUS_NORMAL) { 541 return -EIO; 542 } 543 544 return 0; 545 } 546 547 static void process_command(GAState *s, QDict *req) 548 { 549 QDict *rsp; 550 int ret; 551 552 g_assert(req); 553 g_debug("processing command"); 554 rsp = qmp_dispatch(&ga_commands, QOBJECT(req), false); 555 if (rsp) { 556 ret = send_response(s, rsp); 557 if (ret < 0) { 558 g_warning("error sending response: %s", strerror(-ret)); 559 } 560 qobject_unref(rsp); 561 } 562 } 563 564 /* handle requests/control events coming in over the channel */ 565 static void process_event(void *opaque, QObject *obj, Error *err) 566 { 567 GAState *s = opaque; 568 QDict *req, *rsp; 569 int ret; 570 571 g_debug("process_event: called"); 572 assert(!obj != !err); 573 if (err) { 574 goto err; 575 } 576 req = qobject_to(QDict, obj); 577 if (!req) { 578 error_setg(&err, "Input must be a JSON object"); 579 goto err; 580 } 581 if (!qdict_haskey(req, "execute")) { 582 g_warning("unrecognized payload format"); 583 error_setg(&err, QERR_UNSUPPORTED); 584 goto err; 585 } 586 587 process_command(s, req); 588 qobject_unref(obj); 589 return; 590 591 err: 592 g_warning("failed to parse event: %s", error_get_pretty(err)); 593 rsp = qmp_error_response(err); 594 ret = send_response(s, rsp); 595 if (ret < 0) { 596 g_warning("error sending error response: %s", strerror(-ret)); 597 } 598 qobject_unref(rsp); 599 qobject_unref(obj); 600 } 601 602 /* false return signals GAChannel to close the current client connection */ 603 static gboolean channel_event_cb(GIOCondition condition, gpointer data) 604 { 605 GAState *s = data; 606 gchar buf[QGA_READ_COUNT_DEFAULT+1]; 607 gsize count; 608 GIOStatus status = ga_channel_read(s->channel, buf, QGA_READ_COUNT_DEFAULT, &count); 609 switch (status) { 610 case G_IO_STATUS_ERROR: 611 g_warning("error reading channel"); 612 return false; 613 case G_IO_STATUS_NORMAL: 614 buf[count] = 0; 615 g_debug("read data, count: %d, data: %s", (int)count, buf); 616 json_message_parser_feed(&s->parser, (char *)buf, (int)count); 617 break; 618 case G_IO_STATUS_EOF: 619 g_debug("received EOF"); 620 if (!s->virtio) { 621 return false; 622 } 623 /* fall through */ 624 case G_IO_STATUS_AGAIN: 625 /* virtio causes us to spin here when no process is attached to 626 * host-side chardev. sleep a bit to mitigate this 627 */ 628 if (s->virtio) { 629 usleep(100*1000); 630 } 631 return true; 632 default: 633 g_warning("unknown channel read status, closing"); 634 return false; 635 } 636 return true; 637 } 638 639 static gboolean channel_init(GAState *s, const gchar *method, const gchar *path, 640 int listen_fd) 641 { 642 GAChannelMethod channel_method; 643 644 if (strcmp(method, "virtio-serial") == 0) { 645 s->virtio = true; /* virtio requires special handling in some cases */ 646 channel_method = GA_CHANNEL_VIRTIO_SERIAL; 647 } else if (strcmp(method, "isa-serial") == 0) { 648 channel_method = GA_CHANNEL_ISA_SERIAL; 649 } else if (strcmp(method, "unix-listen") == 0) { 650 channel_method = GA_CHANNEL_UNIX_LISTEN; 651 } else if (strcmp(method, "vsock-listen") == 0) { 652 channel_method = GA_CHANNEL_VSOCK_LISTEN; 653 } else { 654 g_critical("unsupported channel method/type: %s", method); 655 return false; 656 } 657 658 s->channel = ga_channel_new(channel_method, path, listen_fd, 659 channel_event_cb, s); 660 if (!s->channel) { 661 g_critical("failed to create guest agent channel"); 662 return false; 663 } 664 665 return true; 666 } 667 668 #ifdef _WIN32 669 DWORD WINAPI service_ctrl_handler(DWORD ctrl, DWORD type, LPVOID data, 670 LPVOID ctx) 671 { 672 DWORD ret = NO_ERROR; 673 GAService *service = &ga_state->service; 674 675 switch (ctrl) 676 { 677 case SERVICE_CONTROL_STOP: 678 case SERVICE_CONTROL_SHUTDOWN: 679 quit_handler(SIGTERM); 680 service->status.dwCurrentState = SERVICE_STOP_PENDING; 681 SetServiceStatus(service->status_handle, &service->status); 682 break; 683 684 default: 685 ret = ERROR_CALL_NOT_IMPLEMENTED; 686 } 687 return ret; 688 } 689 690 VOID WINAPI service_main(DWORD argc, TCHAR *argv[]) 691 { 692 GAService *service = &ga_state->service; 693 694 service->status_handle = RegisterServiceCtrlHandlerEx(QGA_SERVICE_NAME, 695 service_ctrl_handler, NULL); 696 697 if (service->status_handle == 0) { 698 g_critical("Failed to register extended requests function!\n"); 699 return; 700 } 701 702 service->status.dwServiceType = SERVICE_WIN32; 703 service->status.dwCurrentState = SERVICE_RUNNING; 704 service->status.dwControlsAccepted = SERVICE_ACCEPT_STOP | SERVICE_ACCEPT_SHUTDOWN; 705 service->status.dwWin32ExitCode = NO_ERROR; 706 service->status.dwServiceSpecificExitCode = NO_ERROR; 707 service->status.dwCheckPoint = 0; 708 service->status.dwWaitHint = 0; 709 SetServiceStatus(service->status_handle, &service->status); 710 711 g_main_loop_run(ga_state->main_loop); 712 713 service->status.dwCurrentState = SERVICE_STOPPED; 714 SetServiceStatus(service->status_handle, &service->status); 715 } 716 #endif 717 718 static void set_persistent_state_defaults(GAPersistentState *pstate) 719 { 720 g_assert(pstate); 721 pstate->fd_counter = QGA_PSTATE_DEFAULT_FD_COUNTER; 722 } 723 724 static void persistent_state_from_keyfile(GAPersistentState *pstate, 725 GKeyFile *keyfile) 726 { 727 g_assert(pstate); 728 g_assert(keyfile); 729 /* if any fields are missing, either because the file was tampered with 730 * by agents of chaos, or because the field wasn't present at the time the 731 * file was created, the best we can ever do is start over with the default 732 * values. so load them now, and ignore any errors in accessing key-value 733 * pairs 734 */ 735 set_persistent_state_defaults(pstate); 736 737 if (g_key_file_has_key(keyfile, "global", "fd_counter", NULL)) { 738 pstate->fd_counter = 739 g_key_file_get_integer(keyfile, "global", "fd_counter", NULL); 740 } 741 } 742 743 static void persistent_state_to_keyfile(const GAPersistentState *pstate, 744 GKeyFile *keyfile) 745 { 746 g_assert(pstate); 747 g_assert(keyfile); 748 749 g_key_file_set_integer(keyfile, "global", "fd_counter", pstate->fd_counter); 750 } 751 752 static gboolean write_persistent_state(const GAPersistentState *pstate, 753 const gchar *path) 754 { 755 GKeyFile *keyfile = g_key_file_new(); 756 GError *gerr = NULL; 757 gboolean ret = true; 758 gchar *data = NULL; 759 gsize data_len; 760 761 g_assert(pstate); 762 763 persistent_state_to_keyfile(pstate, keyfile); 764 data = g_key_file_to_data(keyfile, &data_len, &gerr); 765 if (gerr) { 766 g_critical("failed to convert persistent state to string: %s", 767 gerr->message); 768 ret = false; 769 goto out; 770 } 771 772 g_file_set_contents(path, data, data_len, &gerr); 773 if (gerr) { 774 g_critical("failed to write persistent state to %s: %s", 775 path, gerr->message); 776 ret = false; 777 goto out; 778 } 779 780 out: 781 if (gerr) { 782 g_error_free(gerr); 783 } 784 if (keyfile) { 785 g_key_file_free(keyfile); 786 } 787 g_free(data); 788 return ret; 789 } 790 791 static gboolean read_persistent_state(GAPersistentState *pstate, 792 const gchar *path, gboolean frozen) 793 { 794 GKeyFile *keyfile = NULL; 795 GError *gerr = NULL; 796 struct stat st; 797 gboolean ret = true; 798 799 g_assert(pstate); 800 801 if (stat(path, &st) == -1) { 802 /* it's okay if state file doesn't exist, but any other error 803 * indicates a permissions issue or some other misconfiguration 804 * that we likely won't be able to recover from. 805 */ 806 if (errno != ENOENT) { 807 g_critical("unable to access state file at path %s: %s", 808 path, strerror(errno)); 809 ret = false; 810 goto out; 811 } 812 813 /* file doesn't exist. initialize state to default values and 814 * attempt to save now. (we could wait till later when we have 815 * modified state we need to commit, but if there's a problem, 816 * such as a missing parent directory, we want to catch it now) 817 * 818 * there is a potential scenario where someone either managed to 819 * update the agent from a version that didn't use a key store 820 * while qemu-ga thought the filesystem was frozen, or 821 * deleted the key store prior to issuing a fsfreeze, prior 822 * to restarting the agent. in this case we go ahead and defer 823 * initial creation till we actually have modified state to 824 * write, otherwise fail to recover from freeze. 825 */ 826 set_persistent_state_defaults(pstate); 827 if (!frozen) { 828 ret = write_persistent_state(pstate, path); 829 if (!ret) { 830 g_critical("unable to create state file at path %s", path); 831 ret = false; 832 goto out; 833 } 834 } 835 ret = true; 836 goto out; 837 } 838 839 keyfile = g_key_file_new(); 840 g_key_file_load_from_file(keyfile, path, 0, &gerr); 841 if (gerr) { 842 g_critical("error loading persistent state from path: %s, %s", 843 path, gerr->message); 844 ret = false; 845 goto out; 846 } 847 848 persistent_state_from_keyfile(pstate, keyfile); 849 850 out: 851 if (keyfile) { 852 g_key_file_free(keyfile); 853 } 854 if (gerr) { 855 g_error_free(gerr); 856 } 857 858 return ret; 859 } 860 861 int64_t ga_get_fd_handle(GAState *s, Error **errp) 862 { 863 int64_t handle; 864 865 g_assert(s->pstate_filepath); 866 /* we blacklist commands and avoid operations that potentially require 867 * writing to disk when we're in a frozen state. this includes opening 868 * new files, so we should never get here in that situation 869 */ 870 g_assert(!ga_is_frozen(s)); 871 872 handle = s->pstate.fd_counter++; 873 874 /* This should never happen on a reasonable timeframe, as guest-file-open 875 * would have to be issued 2^63 times */ 876 if (s->pstate.fd_counter == INT64_MAX) { 877 abort(); 878 } 879 880 if (!write_persistent_state(&s->pstate, s->pstate_filepath)) { 881 error_setg(errp, "failed to commit persistent state to disk"); 882 return -1; 883 } 884 885 return handle; 886 } 887 888 static void ga_print_cmd(QmpCommand *cmd, void *opaque) 889 { 890 printf("%s\n", qmp_command_name(cmd)); 891 } 892 893 static GList *split_list(const gchar *str, const gchar *delim) 894 { 895 GList *list = NULL; 896 int i; 897 gchar **strv; 898 899 strv = g_strsplit(str, delim, -1); 900 for (i = 0; strv[i]; i++) { 901 list = g_list_prepend(list, strv[i]); 902 } 903 g_free(strv); 904 905 return list; 906 } 907 908 typedef struct GAConfig { 909 char *channel_path; 910 char *method; 911 char *log_filepath; 912 char *pid_filepath; 913 #ifdef CONFIG_FSFREEZE 914 char *fsfreeze_hook; 915 #endif 916 char *state_dir; 917 #ifdef _WIN32 918 const char *service; 919 #endif 920 gchar *bliststr; /* blacklist may point to this string */ 921 GList *blacklist; 922 int daemonize; 923 GLogLevelFlags log_level; 924 int dumpconf; 925 } GAConfig; 926 927 static void config_load(GAConfig *config) 928 { 929 GError *gerr = NULL; 930 GKeyFile *keyfile; 931 const char *conf = g_getenv("QGA_CONF") ?: QGA_CONF_DEFAULT; 932 933 /* read system config */ 934 keyfile = g_key_file_new(); 935 if (!g_key_file_load_from_file(keyfile, conf, 0, &gerr)) { 936 goto end; 937 } 938 if (g_key_file_has_key(keyfile, "general", "daemon", NULL)) { 939 config->daemonize = 940 g_key_file_get_boolean(keyfile, "general", "daemon", &gerr); 941 } 942 if (g_key_file_has_key(keyfile, "general", "method", NULL)) { 943 config->method = 944 g_key_file_get_string(keyfile, "general", "method", &gerr); 945 } 946 if (g_key_file_has_key(keyfile, "general", "path", NULL)) { 947 config->channel_path = 948 g_key_file_get_string(keyfile, "general", "path", &gerr); 949 } 950 if (g_key_file_has_key(keyfile, "general", "logfile", NULL)) { 951 config->log_filepath = 952 g_key_file_get_string(keyfile, "general", "logfile", &gerr); 953 } 954 if (g_key_file_has_key(keyfile, "general", "pidfile", NULL)) { 955 config->pid_filepath = 956 g_key_file_get_string(keyfile, "general", "pidfile", &gerr); 957 } 958 #ifdef CONFIG_FSFREEZE 959 if (g_key_file_has_key(keyfile, "general", "fsfreeze-hook", NULL)) { 960 config->fsfreeze_hook = 961 g_key_file_get_string(keyfile, 962 "general", "fsfreeze-hook", &gerr); 963 } 964 #endif 965 if (g_key_file_has_key(keyfile, "general", "statedir", NULL)) { 966 config->state_dir = 967 g_key_file_get_string(keyfile, "general", "statedir", &gerr); 968 } 969 if (g_key_file_has_key(keyfile, "general", "verbose", NULL) && 970 g_key_file_get_boolean(keyfile, "general", "verbose", &gerr)) { 971 /* enable all log levels */ 972 config->log_level = G_LOG_LEVEL_MASK; 973 } 974 if (g_key_file_has_key(keyfile, "general", "blacklist", NULL)) { 975 config->bliststr = 976 g_key_file_get_string(keyfile, "general", "blacklist", &gerr); 977 config->blacklist = g_list_concat(config->blacklist, 978 split_list(config->bliststr, ",")); 979 } 980 981 end: 982 g_key_file_free(keyfile); 983 if (gerr && 984 !(gerr->domain == G_FILE_ERROR && gerr->code == G_FILE_ERROR_NOENT)) { 985 g_critical("error loading configuration from path: %s, %s", 986 QGA_CONF_DEFAULT, gerr->message); 987 exit(EXIT_FAILURE); 988 } 989 g_clear_error(&gerr); 990 } 991 992 static gchar *list_join(GList *list, const gchar separator) 993 { 994 GString *str = g_string_new(""); 995 996 while (list) { 997 str = g_string_append(str, (gchar *)list->data); 998 list = g_list_next(list); 999 if (list) { 1000 str = g_string_append_c(str, separator); 1001 } 1002 } 1003 1004 return g_string_free(str, FALSE); 1005 } 1006 1007 static void config_dump(GAConfig *config) 1008 { 1009 GError *error = NULL; 1010 GKeyFile *keyfile; 1011 gchar *tmp; 1012 1013 keyfile = g_key_file_new(); 1014 g_assert(keyfile); 1015 1016 g_key_file_set_boolean(keyfile, "general", "daemon", config->daemonize); 1017 g_key_file_set_string(keyfile, "general", "method", config->method); 1018 if (config->channel_path) { 1019 g_key_file_set_string(keyfile, "general", "path", config->channel_path); 1020 } 1021 if (config->log_filepath) { 1022 g_key_file_set_string(keyfile, "general", "logfile", 1023 config->log_filepath); 1024 } 1025 g_key_file_set_string(keyfile, "general", "pidfile", config->pid_filepath); 1026 #ifdef CONFIG_FSFREEZE 1027 if (config->fsfreeze_hook) { 1028 g_key_file_set_string(keyfile, "general", "fsfreeze-hook", 1029 config->fsfreeze_hook); 1030 } 1031 #endif 1032 g_key_file_set_string(keyfile, "general", "statedir", config->state_dir); 1033 g_key_file_set_boolean(keyfile, "general", "verbose", 1034 config->log_level == G_LOG_LEVEL_MASK); 1035 tmp = list_join(config->blacklist, ','); 1036 g_key_file_set_string(keyfile, "general", "blacklist", tmp); 1037 g_free(tmp); 1038 1039 tmp = g_key_file_to_data(keyfile, NULL, &error); 1040 if (error) { 1041 g_critical("Failed to dump keyfile: %s", error->message); 1042 g_clear_error(&error); 1043 } else { 1044 printf("%s", tmp); 1045 } 1046 1047 g_free(tmp); 1048 g_key_file_free(keyfile); 1049 } 1050 1051 static void config_parse(GAConfig *config, int argc, char **argv) 1052 { 1053 const char *sopt = "hVvdm:p:l:f:F::b:s:t:D"; 1054 int opt_ind = 0, ch; 1055 const struct option lopt[] = { 1056 { "help", 0, NULL, 'h' }, 1057 { "version", 0, NULL, 'V' }, 1058 { "dump-conf", 0, NULL, 'D' }, 1059 { "logfile", 1, NULL, 'l' }, 1060 { "pidfile", 1, NULL, 'f' }, 1061 #ifdef CONFIG_FSFREEZE 1062 { "fsfreeze-hook", 2, NULL, 'F' }, 1063 #endif 1064 { "verbose", 0, NULL, 'v' }, 1065 { "method", 1, NULL, 'm' }, 1066 { "path", 1, NULL, 'p' }, 1067 { "daemonize", 0, NULL, 'd' }, 1068 { "blacklist", 1, NULL, 'b' }, 1069 #ifdef _WIN32 1070 { "service", 1, NULL, 's' }, 1071 #endif 1072 { "statedir", 1, NULL, 't' }, 1073 { NULL, 0, NULL, 0 } 1074 }; 1075 1076 while ((ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1) { 1077 switch (ch) { 1078 case 'm': 1079 g_free(config->method); 1080 config->method = g_strdup(optarg); 1081 break; 1082 case 'p': 1083 g_free(config->channel_path); 1084 config->channel_path = g_strdup(optarg); 1085 break; 1086 case 'l': 1087 g_free(config->log_filepath); 1088 config->log_filepath = g_strdup(optarg); 1089 break; 1090 case 'f': 1091 g_free(config->pid_filepath); 1092 config->pid_filepath = g_strdup(optarg); 1093 break; 1094 #ifdef CONFIG_FSFREEZE 1095 case 'F': 1096 g_free(config->fsfreeze_hook); 1097 config->fsfreeze_hook = g_strdup(optarg ?: QGA_FSFREEZE_HOOK_DEFAULT); 1098 break; 1099 #endif 1100 case 't': 1101 g_free(config->state_dir); 1102 config->state_dir = g_strdup(optarg); 1103 break; 1104 case 'v': 1105 /* enable all log levels */ 1106 config->log_level = G_LOG_LEVEL_MASK; 1107 break; 1108 case 'V': 1109 printf("QEMU Guest Agent %s\n", QEMU_VERSION); 1110 exit(EXIT_SUCCESS); 1111 case 'd': 1112 config->daemonize = 1; 1113 break; 1114 case 'D': 1115 config->dumpconf = 1; 1116 break; 1117 case 'b': { 1118 if (is_help_option(optarg)) { 1119 qmp_for_each_command(&ga_commands, ga_print_cmd, NULL); 1120 exit(EXIT_SUCCESS); 1121 } 1122 config->blacklist = g_list_concat(config->blacklist, 1123 split_list(optarg, ",")); 1124 break; 1125 } 1126 #ifdef _WIN32 1127 case 's': 1128 config->service = optarg; 1129 if (strcmp(config->service, "install") == 0) { 1130 if (ga_install_vss_provider()) { 1131 exit(EXIT_FAILURE); 1132 } 1133 if (ga_install_service(config->channel_path, 1134 config->log_filepath, config->state_dir)) { 1135 exit(EXIT_FAILURE); 1136 } 1137 exit(EXIT_SUCCESS); 1138 } else if (strcmp(config->service, "uninstall") == 0) { 1139 ga_uninstall_vss_provider(); 1140 exit(ga_uninstall_service()); 1141 } else if (strcmp(config->service, "vss-install") == 0) { 1142 if (ga_install_vss_provider()) { 1143 exit(EXIT_FAILURE); 1144 } 1145 exit(EXIT_SUCCESS); 1146 } else if (strcmp(config->service, "vss-uninstall") == 0) { 1147 ga_uninstall_vss_provider(); 1148 exit(EXIT_SUCCESS); 1149 } else { 1150 printf("Unknown service command.\n"); 1151 exit(EXIT_FAILURE); 1152 } 1153 break; 1154 #endif 1155 case 'h': 1156 usage(argv[0]); 1157 exit(EXIT_SUCCESS); 1158 case '?': 1159 g_print("Unknown option, try '%s --help' for more information.\n", 1160 argv[0]); 1161 exit(EXIT_FAILURE); 1162 } 1163 } 1164 } 1165 1166 static void config_free(GAConfig *config) 1167 { 1168 g_free(config->method); 1169 g_free(config->log_filepath); 1170 g_free(config->pid_filepath); 1171 g_free(config->state_dir); 1172 g_free(config->channel_path); 1173 g_free(config->bliststr); 1174 #ifdef CONFIG_FSFREEZE 1175 g_free(config->fsfreeze_hook); 1176 #endif 1177 g_list_free_full(config->blacklist, g_free); 1178 g_free(config); 1179 } 1180 1181 static bool check_is_frozen(GAState *s) 1182 { 1183 #ifndef _WIN32 1184 /* check if a previous instance of qemu-ga exited with filesystems' state 1185 * marked as frozen. this could be a stale value (a non-qemu-ga process 1186 * or reboot may have since unfrozen them), but better to require an 1187 * uneeded unfreeze than to risk hanging on start-up 1188 */ 1189 struct stat st; 1190 if (stat(s->state_filepath_isfrozen, &st) == -1) { 1191 /* it's okay if the file doesn't exist, but if we can't access for 1192 * some other reason, such as permissions, there's a configuration 1193 * that needs to be addressed. so just bail now before we get into 1194 * more trouble later 1195 */ 1196 if (errno != ENOENT) { 1197 g_critical("unable to access state file at path %s: %s", 1198 s->state_filepath_isfrozen, strerror(errno)); 1199 return EXIT_FAILURE; 1200 } 1201 } else { 1202 g_warning("previous instance appears to have exited with frozen" 1203 " filesystems. deferring logging/pidfile creation and" 1204 " disabling non-fsfreeze-safe commands until" 1205 " guest-fsfreeze-thaw is issued, or filesystems are" 1206 " manually unfrozen and the file %s is removed", 1207 s->state_filepath_isfrozen); 1208 return true; 1209 } 1210 #endif 1211 return false; 1212 } 1213 1214 static int run_agent(GAState *s, GAConfig *config, int socket_activation) 1215 { 1216 ga_state = s; 1217 1218 g_log_set_default_handler(ga_log, s); 1219 g_log_set_fatal_mask(NULL, G_LOG_LEVEL_ERROR); 1220 ga_enable_logging(s); 1221 1222 #ifdef _WIN32 1223 /* On win32 the state directory is application specific (be it the default 1224 * or a user override). We got past the command line parsing; let's create 1225 * the directory (with any intermediate directories). If we run into an 1226 * error later on, we won't try to clean up the directory, it is considered 1227 * persistent. 1228 */ 1229 if (g_mkdir_with_parents(config->state_dir, S_IRWXU) == -1) { 1230 g_critical("unable to create (an ancestor of) the state directory" 1231 " '%s': %s", config->state_dir, strerror(errno)); 1232 return EXIT_FAILURE; 1233 } 1234 #endif 1235 1236 if (ga_is_frozen(s)) { 1237 if (config->daemonize) { 1238 /* delay opening/locking of pidfile till filesystems are unfrozen */ 1239 s->deferred_options.pid_filepath = config->pid_filepath; 1240 become_daemon(NULL); 1241 } 1242 if (config->log_filepath) { 1243 /* delay opening the log file till filesystems are unfrozen */ 1244 s->deferred_options.log_filepath = config->log_filepath; 1245 } 1246 ga_disable_logging(s); 1247 qmp_for_each_command(&ga_commands, ga_disable_non_whitelisted, NULL); 1248 } else { 1249 if (config->daemonize) { 1250 become_daemon(config->pid_filepath); 1251 } 1252 if (config->log_filepath) { 1253 FILE *log_file = ga_open_logfile(config->log_filepath); 1254 if (!log_file) { 1255 g_critical("unable to open specified log file: %s", 1256 strerror(errno)); 1257 return EXIT_FAILURE; 1258 } 1259 s->log_file = log_file; 1260 } 1261 } 1262 1263 /* load persistent state from disk */ 1264 if (!read_persistent_state(&s->pstate, 1265 s->pstate_filepath, 1266 ga_is_frozen(s))) { 1267 g_critical("failed to load persistent state"); 1268 return EXIT_FAILURE; 1269 } 1270 1271 config->blacklist = ga_command_blacklist_init(config->blacklist); 1272 if (config->blacklist) { 1273 GList *l = config->blacklist; 1274 s->blacklist = config->blacklist; 1275 do { 1276 g_debug("disabling command: %s", (char *)l->data); 1277 qmp_disable_command(&ga_commands, l->data); 1278 l = g_list_next(l); 1279 } while (l); 1280 } 1281 s->command_state = ga_command_state_new(); 1282 ga_command_state_init(s, s->command_state); 1283 ga_command_state_init_all(s->command_state); 1284 json_message_parser_init(&s->parser, process_event, s, NULL); 1285 1286 #ifndef _WIN32 1287 if (!register_signal_handlers()) { 1288 g_critical("failed to register signal handlers"); 1289 return EXIT_FAILURE; 1290 } 1291 #endif 1292 1293 s->main_loop = g_main_loop_new(NULL, false); 1294 1295 if (!channel_init(ga_state, config->method, config->channel_path, 1296 socket_activation ? FIRST_SOCKET_ACTIVATION_FD : -1)) { 1297 g_critical("failed to initialize guest agent channel"); 1298 return EXIT_FAILURE; 1299 } 1300 #ifndef _WIN32 1301 g_main_loop_run(ga_state->main_loop); 1302 #else 1303 if (config->daemonize) { 1304 SERVICE_TABLE_ENTRY service_table[] = { 1305 { (char *)QGA_SERVICE_NAME, service_main }, { NULL, NULL } }; 1306 StartServiceCtrlDispatcher(service_table); 1307 } else { 1308 g_main_loop_run(ga_state->main_loop); 1309 } 1310 #endif 1311 1312 return EXIT_SUCCESS; 1313 } 1314 1315 int main(int argc, char **argv) 1316 { 1317 int ret = EXIT_SUCCESS; 1318 GAState *s = g_new0(GAState, 1); 1319 GAConfig *config = g_new0(GAConfig, 1); 1320 int socket_activation; 1321 1322 config->log_level = G_LOG_LEVEL_ERROR | G_LOG_LEVEL_CRITICAL; 1323 1324 qga_qmp_init_marshal(&ga_commands); 1325 1326 init_dfl_pathnames(); 1327 config_load(config); 1328 config_parse(config, argc, argv); 1329 1330 if (config->pid_filepath == NULL) { 1331 config->pid_filepath = g_strdup(dfl_pathnames.pidfile); 1332 } 1333 1334 if (config->state_dir == NULL) { 1335 config->state_dir = g_strdup(dfl_pathnames.state_dir); 1336 } 1337 1338 if (config->method == NULL) { 1339 config->method = g_strdup("virtio-serial"); 1340 } 1341 1342 socket_activation = check_socket_activation(); 1343 if (socket_activation > 1) { 1344 g_critical("qemu-ga only supports listening on one socket"); 1345 ret = EXIT_FAILURE; 1346 goto end; 1347 } 1348 if (socket_activation) { 1349 SocketAddress *addr; 1350 1351 g_free(config->method); 1352 g_free(config->channel_path); 1353 config->method = NULL; 1354 config->channel_path = NULL; 1355 1356 addr = socket_local_address(FIRST_SOCKET_ACTIVATION_FD, NULL); 1357 if (addr) { 1358 if (addr->type == SOCKET_ADDRESS_TYPE_UNIX) { 1359 config->method = g_strdup("unix-listen"); 1360 } else if (addr->type == SOCKET_ADDRESS_TYPE_VSOCK) { 1361 config->method = g_strdup("vsock-listen"); 1362 } 1363 1364 qapi_free_SocketAddress(addr); 1365 } 1366 1367 if (!config->method) { 1368 g_critical("unsupported listen fd type"); 1369 ret = EXIT_FAILURE; 1370 goto end; 1371 } 1372 } else if (config->channel_path == NULL) { 1373 if (strcmp(config->method, "virtio-serial") == 0) { 1374 /* try the default path for the virtio-serial port */ 1375 config->channel_path = g_strdup(QGA_VIRTIO_PATH_DEFAULT); 1376 } else if (strcmp(config->method, "isa-serial") == 0) { 1377 /* try the default path for the serial port - COM1 */ 1378 config->channel_path = g_strdup(QGA_SERIAL_PATH_DEFAULT); 1379 } else { 1380 g_critical("must specify a path for this channel"); 1381 ret = EXIT_FAILURE; 1382 goto end; 1383 } 1384 } 1385 1386 s->log_level = config->log_level; 1387 s->log_file = stderr; 1388 #ifdef CONFIG_FSFREEZE 1389 s->fsfreeze_hook = config->fsfreeze_hook; 1390 #endif 1391 s->pstate_filepath = g_strdup_printf("%s/qga.state", config->state_dir); 1392 s->state_filepath_isfrozen = g_strdup_printf("%s/qga.state.isfrozen", 1393 config->state_dir); 1394 s->frozen = check_is_frozen(s); 1395 1396 if (config->dumpconf) { 1397 config_dump(config); 1398 goto end; 1399 } 1400 1401 ret = run_agent(s, config, socket_activation); 1402 1403 end: 1404 if (s->command_state) { 1405 ga_command_state_cleanup_all(s->command_state); 1406 ga_command_state_free(s->command_state); 1407 json_message_parser_destroy(&s->parser); 1408 } 1409 if (s->channel) { 1410 ga_channel_free(s->channel); 1411 } 1412 g_free(s->pstate_filepath); 1413 g_free(s->state_filepath_isfrozen); 1414 1415 if (config->daemonize) { 1416 unlink(config->pid_filepath); 1417 } 1418 1419 config_free(config); 1420 if (s->main_loop) { 1421 g_main_loop_unref(s->main_loop); 1422 } 1423 g_free(s); 1424 1425 return ret; 1426 } 1427