xref: /openbmc/qemu/qga/main.c (revision b49f4755)
1 /*
2  * QEMU Guest Agent
3  *
4  * Copyright IBM Corp. 2011
5  *
6  * Authors:
7  *  Adam Litke        <aglitke@linux.vnet.ibm.com>
8  *  Michael Roth      <mdroth@linux.vnet.ibm.com>
9  *
10  * This work is licensed under the terms of the GNU GPL, version 2 or later.
11  * See the COPYING file in the top-level directory.
12  */
13 
14 #include "qemu/osdep.h"
15 #include <getopt.h>
16 #include <glib/gstdio.h>
17 #ifndef _WIN32
18 #include <syslog.h>
19 #include <sys/wait.h>
20 #endif
21 #include "qemu/help-texts.h"
22 #include "qapi/qmp/json-parser.h"
23 #include "qapi/qmp/qdict.h"
24 #include "qapi/qmp/qjson.h"
25 #include "guest-agent-core.h"
26 #include "qga-qapi-init-commands.h"
27 #include "qapi/error.h"
28 #include "channel.h"
29 #include "qemu/cutils.h"
30 #include "qemu/help_option.h"
31 #include "qemu/sockets.h"
32 #include "qemu/systemd.h"
33 #include "qemu-version.h"
34 #ifdef _WIN32
35 #include <dbt.h>
36 #include "qga/service-win32.h"
37 #include "qga/vss-win32.h"
38 #endif
39 #include "commands-common.h"
40 
41 #ifndef _WIN32
42 #ifdef CONFIG_BSD
43 #define QGA_VIRTIO_PATH_DEFAULT "/dev/vtcon/org.qemu.guest_agent.0"
44 #else /* CONFIG_BSD */
45 #define QGA_VIRTIO_PATH_DEFAULT "/dev/virtio-ports/org.qemu.guest_agent.0"
46 #endif /* CONFIG_BSD */
47 #define QGA_SERIAL_PATH_DEFAULT "/dev/ttyS0"
48 #define QGA_STATE_RELATIVE_DIR  "run"
49 #else
50 #define QGA_VIRTIO_PATH_DEFAULT "\\\\.\\Global\\org.qemu.guest_agent.0"
51 #define QGA_STATE_RELATIVE_DIR  "qemu-ga"
52 #define QGA_SERIAL_PATH_DEFAULT "COM1"
53 #endif
54 #ifdef CONFIG_FSFREEZE
55 #define QGA_FSFREEZE_HOOK_DEFAULT CONFIG_QEMU_CONFDIR "/fsfreeze-hook"
56 #endif
57 #define QGA_SENTINEL_BYTE 0xFF
58 #define QGA_CONF_DEFAULT CONFIG_QEMU_CONFDIR G_DIR_SEPARATOR_S "qemu-ga.conf"
59 #define QGA_RETRY_INTERVAL 5
60 
61 static struct {
62     const char *state_dir;
63     const char *pidfile;
64 } dfl_pathnames;
65 
66 typedef struct GAPersistentState {
67 #define QGA_PSTATE_DEFAULT_FD_COUNTER 1000
68     int64_t fd_counter;
69 } GAPersistentState;
70 
71 typedef struct GAConfig GAConfig;
72 
73 struct GAState {
74     JSONMessageParser parser;
75     GMainLoop *main_loop;
76     GAChannel *channel;
77     bool virtio; /* fastpath to check for virtio to deal with poll() quirks */
78     GACommandState *command_state;
79     GLogLevelFlags log_level;
80     FILE *log_file;
81     bool logging_enabled;
82 #ifdef _WIN32
83     GAService service;
84     HANDLE wakeup_event;
85     HANDLE event_log;
86 #endif
87     bool delimit_response;
88     bool frozen;
89     GList *blockedrpcs;
90     GList *allowedrpcs;
91     char *state_filepath_isfrozen;
92     struct {
93         const char *log_filepath;
94         const char *pid_filepath;
95     } deferred_options;
96 #ifdef CONFIG_FSFREEZE
97     const char *fsfreeze_hook;
98 #endif
99     gchar *pstate_filepath;
100     GAPersistentState pstate;
101     GAConfig *config;
102     int socket_activation;
103     bool force_exit;
104 };
105 
106 struct GAState *ga_state;
107 QmpCommandList ga_commands;
108 
109 /* commands that are safe to issue while filesystems are frozen */
110 static const char *ga_freeze_allowlist[] = {
111     "guest-ping",
112     "guest-info",
113     "guest-sync",
114     "guest-sync-delimited",
115     "guest-fsfreeze-status",
116     "guest-fsfreeze-thaw",
117     NULL
118 };
119 
120 #ifdef _WIN32
121 DWORD WINAPI service_ctrl_handler(DWORD ctrl, DWORD type, LPVOID data,
122                                   LPVOID ctx);
123 DWORD WINAPI handle_serial_device_events(DWORD type, LPVOID data);
124 VOID WINAPI service_main(DWORD argc, TCHAR *argv[]);
125 #endif
126 static int run_agent(GAState *s);
127 static void stop_agent(GAState *s, bool requested);
128 
129 static void
130 init_dfl_pathnames(void)
131 {
132     g_autofree char *state = qemu_get_local_state_dir();
133 
134     g_assert(dfl_pathnames.state_dir == NULL);
135     g_assert(dfl_pathnames.pidfile == NULL);
136     dfl_pathnames.state_dir = g_build_filename(state, QGA_STATE_RELATIVE_DIR, NULL);
137     dfl_pathnames.pidfile = g_build_filename(state, QGA_STATE_RELATIVE_DIR, "qemu-ga.pid", NULL);
138 }
139 
140 static void quit_handler(int sig)
141 {
142     /* if we're frozen, don't exit unless we're absolutely forced to,
143      * because it's basically impossible for graceful exit to complete
144      * unless all log/pid files are on unfreezable filesystems. there's
145      * also a very likely chance killing the agent before unfreezing
146      * the filesystems is a mistake (or will be viewed as one later).
147      * On Windows the freeze interval is limited to 10 seconds, so
148      * we should quit, but first we should wait for the timeout, thaw
149      * the filesystem and quit.
150      */
151     if (ga_is_frozen(ga_state)) {
152 #ifdef _WIN32
153         int i = 0;
154         Error *err = NULL;
155         HANDLE hEventTimeout;
156 
157         g_debug("Thawing filesystems before exiting");
158 
159         hEventTimeout = OpenEvent(EVENT_ALL_ACCESS, FALSE, EVENT_NAME_TIMEOUT);
160         if (hEventTimeout) {
161             WaitForSingleObject(hEventTimeout, 0);
162             CloseHandle(hEventTimeout);
163         }
164         qga_vss_fsfreeze(&i, false, NULL, &err);
165         if (err) {
166             g_debug("Error unfreezing filesystems prior to exiting: %s",
167                 error_get_pretty(err));
168             error_free(err);
169         }
170 #else
171         return;
172 #endif
173     }
174     g_debug("received signal num %d, quitting", sig);
175 
176     stop_agent(ga_state, true);
177 }
178 
179 #ifndef _WIN32
180 static gboolean register_signal_handlers(void)
181 {
182     struct sigaction sigact;
183     int ret;
184 
185     memset(&sigact, 0, sizeof(struct sigaction));
186     sigact.sa_handler = quit_handler;
187 
188     ret = sigaction(SIGINT, &sigact, NULL);
189     if (ret == -1) {
190         g_error("error configuring signal handler: %s", strerror(errno));
191     }
192     ret = sigaction(SIGTERM, &sigact, NULL);
193     if (ret == -1) {
194         g_error("error configuring signal handler: %s", strerror(errno));
195     }
196 
197     sigact.sa_handler = SIG_IGN;
198     if (sigaction(SIGPIPE, &sigact, NULL) != 0) {
199         g_error("error configuring SIGPIPE signal handler: %s",
200                 strerror(errno));
201     }
202 
203     return true;
204 }
205 
206 /* TODO: use this in place of all post-fork() fclose(std*) callers */
207 void reopen_fd_to_null(int fd)
208 {
209     int nullfd;
210 
211     nullfd = open("/dev/null", O_RDWR);
212     if (nullfd < 0) {
213         return;
214     }
215 
216     dup2(nullfd, fd);
217 
218     if (nullfd != fd) {
219         close(nullfd);
220     }
221 }
222 #endif
223 
224 static void usage(const char *cmd)
225 {
226 #ifdef CONFIG_FSFREEZE
227     g_autofree char *fsfreeze_hook = get_relocated_path(QGA_FSFREEZE_HOOK_DEFAULT);
228 #endif
229 
230     printf(
231 "Usage: %s [-m <method> -p <path>] [<options>]\n"
232 "QEMU Guest Agent " QEMU_FULL_VERSION "\n"
233 QEMU_COPYRIGHT "\n"
234 "\n"
235 "  -m, --method      transport method: one of unix-listen, virtio-serial,\n"
236 "                    isa-serial, or vsock-listen (virtio-serial is the default)\n"
237 "  -p, --path        device/socket path (the default for virtio-serial is:\n"
238 "                    %s,\n"
239 "                    the default for isa-serial is:\n"
240 "                    %s).\n"
241 "                    Socket addresses for vsock-listen are written as\n"
242 "                    <cid>:<port>.\n"
243 "  -l, --logfile     set logfile path, logs to stderr by default\n"
244 "  -f, --pidfile     specify pidfile (default is %s)\n"
245 #ifdef CONFIG_FSFREEZE
246 "  -F, --fsfreeze-hook\n"
247 "                    enable fsfreeze hook. Accepts an optional argument that\n"
248 "                    specifies script to run on freeze/thaw. Script will be\n"
249 "                    called with 'freeze'/'thaw' arguments accordingly.\n"
250 "                    (default is %s)\n"
251 "                    If using -F with an argument, do not follow -F with a\n"
252 "                    space.\n"
253 "                    (for example: -F/var/run/fsfreezehook.sh)\n"
254 #endif
255 "  -t, --statedir    specify dir to store state information (absolute paths\n"
256 "                    only, default is %s)\n"
257 "  -v, --verbose     log extra debugging information\n"
258 "  -V, --version     print version information and exit\n"
259 "  -d, --daemonize   become a daemon\n"
260 #ifdef _WIN32
261 "  -s, --service     service commands: install, uninstall, vss-install, vss-uninstall\n"
262 #endif
263 "  -b, --block-rpcs  comma-separated list of RPCs to disable (no spaces,\n"
264 "                    use \"help\" to list available RPCs)\n"
265 "  -a, --allow-rpcs  comma-separated list of RPCs to enable (no spaces,\n"
266 "                    use \"help\" to list available RPCs)\n"
267 "  -D, --dump-conf   dump a qemu-ga config file based on current config\n"
268 "                    options / command-line parameters to stdout\n"
269 "  -r, --retry-path  attempt re-opening path if it's unavailable or closed\n"
270 "                    due to an error which may be recoverable in the future\n"
271 "                    (virtio-serial driver re-install, serial device hot\n"
272 "                    plug/unplug, etc.)\n"
273 "  -h, --help        display this help and exit\n"
274 "\n"
275 QEMU_HELP_BOTTOM "\n"
276     , cmd, QGA_VIRTIO_PATH_DEFAULT, QGA_SERIAL_PATH_DEFAULT,
277     dfl_pathnames.pidfile,
278 #ifdef CONFIG_FSFREEZE
279     fsfreeze_hook,
280 #endif
281     dfl_pathnames.state_dir);
282 }
283 
284 static const char *ga_log_level_str(GLogLevelFlags level)
285 {
286     switch (level & G_LOG_LEVEL_MASK) {
287     case G_LOG_LEVEL_ERROR:
288         return "error";
289     case G_LOG_LEVEL_CRITICAL:
290         return "critical";
291     case G_LOG_LEVEL_WARNING:
292         return "warning";
293     case G_LOG_LEVEL_MESSAGE:
294         return "message";
295     case G_LOG_LEVEL_INFO:
296         return "info";
297     case G_LOG_LEVEL_DEBUG:
298         return "debug";
299     default:
300         return "user";
301     }
302 }
303 
304 bool ga_logging_enabled(GAState *s)
305 {
306     return s->logging_enabled;
307 }
308 
309 void ga_disable_logging(GAState *s)
310 {
311     s->logging_enabled = false;
312 }
313 
314 void ga_enable_logging(GAState *s)
315 {
316     s->logging_enabled = true;
317 }
318 
319 static int glib_log_level_to_system(int level)
320 {
321     switch (level) {
322 #ifndef _WIN32
323     case G_LOG_LEVEL_ERROR:
324         return LOG_ERR;
325     case G_LOG_LEVEL_CRITICAL:
326         return LOG_CRIT;
327     case G_LOG_LEVEL_WARNING:
328         return LOG_WARNING;
329     case G_LOG_LEVEL_MESSAGE:
330         return LOG_NOTICE;
331     case G_LOG_LEVEL_DEBUG:
332         return LOG_DEBUG;
333     case G_LOG_LEVEL_INFO:
334     default:
335         return LOG_INFO;
336 #else
337     case G_LOG_LEVEL_ERROR:
338     case G_LOG_LEVEL_CRITICAL:
339         return EVENTLOG_ERROR_TYPE;
340     case G_LOG_LEVEL_WARNING:
341         return EVENTLOG_WARNING_TYPE;
342     case G_LOG_LEVEL_MESSAGE:
343     case G_LOG_LEVEL_INFO:
344     case G_LOG_LEVEL_DEBUG:
345     default:
346         return EVENTLOG_INFORMATION_TYPE;
347 #endif
348     }
349 }
350 
351 static void ga_log(const gchar *domain, GLogLevelFlags level,
352                    const gchar *msg, gpointer opaque)
353 {
354     GAState *s = opaque;
355     const char *level_str = ga_log_level_str(level);
356 
357     if (!ga_logging_enabled(s)) {
358         return;
359     }
360 
361     level &= G_LOG_LEVEL_MASK;
362     if (g_strcmp0(domain, "syslog") == 0) {
363 #ifndef _WIN32
364         syslog(glib_log_level_to_system(level), "%s: %s", level_str, msg);
365 #else
366         ReportEvent(s->event_log, glib_log_level_to_system(level),
367                     0, 1, NULL, 1, 0, &msg, NULL);
368 #endif
369     } else if (level & s->log_level) {
370         g_autoptr(GDateTime) now = g_date_time_new_now_utc();
371         g_autofree char *nowstr = g_date_time_format(now, "%s.%f");
372         fprintf(s->log_file, "%s: %s: %s\n", nowstr, level_str, msg);
373         fflush(s->log_file);
374     }
375 }
376 
377 void ga_set_response_delimited(GAState *s)
378 {
379     s->delimit_response = true;
380 }
381 
382 static FILE *ga_open_logfile(const char *logfile)
383 {
384     FILE *f;
385 
386     f = fopen(logfile, "a");
387     if (!f) {
388         return NULL;
389     }
390 
391     qemu_set_cloexec(fileno(f));
392     return f;
393 }
394 
395 static gint ga_strcmp(gconstpointer str1, gconstpointer str2)
396 {
397     return strcmp(str1, str2);
398 }
399 
400 /* disable commands that aren't safe for fsfreeze */
401 static void ga_disable_not_allowed_freeze(const QmpCommand *cmd, void *opaque)
402 {
403     bool allowed = false;
404     int i = 0;
405     const char *name = qmp_command_name(cmd);
406 
407     while (ga_freeze_allowlist[i] != NULL) {
408         if (strcmp(name, ga_freeze_allowlist[i]) == 0) {
409             allowed = true;
410         }
411         i++;
412     }
413     if (!allowed) {
414         g_debug("disabling command: %s", name);
415         qmp_disable_command(&ga_commands, name, "the agent is in frozen state");
416     }
417 }
418 
419 /* [re-]enable all commands, except those explicitly blocked by user */
420 static void ga_enable_non_blocked(const QmpCommand *cmd, void *opaque)
421 {
422     GAState *s = opaque;
423     GList *blockedrpcs = s->blockedrpcs;
424     GList *allowedrpcs = s->allowedrpcs;
425     const char *name = qmp_command_name(cmd);
426 
427     if (g_list_find_custom(blockedrpcs, name, ga_strcmp) == NULL) {
428         if (qmp_command_is_enabled(cmd)) {
429             return;
430         }
431 
432         if (allowedrpcs &&
433             g_list_find_custom(allowedrpcs, name, ga_strcmp) == NULL) {
434             return;
435         }
436 
437         g_debug("enabling command: %s", name);
438         qmp_enable_command(&ga_commands, name);
439     }
440 }
441 
442 /* disable commands that aren't allowed */
443 static void ga_disable_not_allowed(const QmpCommand *cmd, void *opaque)
444 {
445     GList *allowedrpcs = opaque;
446     const char *name = qmp_command_name(cmd);
447 
448     if (g_list_find_custom(allowedrpcs, name, ga_strcmp) == NULL) {
449         g_debug("disabling command: %s", name);
450         qmp_disable_command(&ga_commands, name, "the command is not allowed");
451     }
452 }
453 
454 static bool ga_create_file(const char *path)
455 {
456     int fd = open(path, O_CREAT | O_WRONLY, S_IWUSR | S_IRUSR);
457     if (fd == -1) {
458         g_warning("unable to open/create file %s: %s", path, strerror(errno));
459         return false;
460     }
461     close(fd);
462     return true;
463 }
464 
465 static bool ga_delete_file(const char *path)
466 {
467     int ret = unlink(path);
468     if (ret == -1) {
469         g_warning("unable to delete file: %s: %s", path, strerror(errno));
470         return false;
471     }
472 
473     return true;
474 }
475 
476 bool ga_is_frozen(GAState *s)
477 {
478     return s->frozen;
479 }
480 
481 void ga_set_frozen(GAState *s)
482 {
483     if (ga_is_frozen(s)) {
484         return;
485     }
486     /* disable all forbidden (for frozen state) commands */
487     qmp_for_each_command(&ga_commands, ga_disable_not_allowed_freeze, NULL);
488     g_warning("disabling logging due to filesystem freeze");
489     ga_disable_logging(s);
490     s->frozen = true;
491     if (!ga_create_file(s->state_filepath_isfrozen)) {
492         g_warning("unable to create %s, fsfreeze may not function properly",
493                   s->state_filepath_isfrozen);
494     }
495 }
496 
497 void ga_unset_frozen(GAState *s)
498 {
499     if (!ga_is_frozen(s)) {
500         return;
501     }
502 
503     /* if we delayed creation/opening of pid/log files due to being
504      * in a frozen state at start up, do it now
505      */
506     if (s->deferred_options.log_filepath) {
507         s->log_file = ga_open_logfile(s->deferred_options.log_filepath);
508         if (!s->log_file) {
509             s->log_file = stderr;
510         }
511         s->deferred_options.log_filepath = NULL;
512     }
513     ga_enable_logging(s);
514     g_warning("logging re-enabled due to filesystem unfreeze");
515     if (s->deferred_options.pid_filepath) {
516         Error *err = NULL;
517 
518         if (!qemu_write_pidfile(s->deferred_options.pid_filepath, &err)) {
519             g_warning("%s", error_get_pretty(err));
520             error_free(err);
521         }
522         s->deferred_options.pid_filepath = NULL;
523     }
524 
525     /* enable all disabled, non-blocked and allowed commands */
526     qmp_for_each_command(&ga_commands, ga_enable_non_blocked, s);
527     s->frozen = false;
528     if (!ga_delete_file(s->state_filepath_isfrozen)) {
529         g_warning("unable to delete %s, fsfreeze may not function properly",
530                   s->state_filepath_isfrozen);
531     }
532 }
533 
534 #ifdef CONFIG_FSFREEZE
535 const char *ga_fsfreeze_hook(GAState *s)
536 {
537     return s->fsfreeze_hook;
538 }
539 #endif
540 
541 static void become_daemon(const char *pidfile)
542 {
543 #ifndef _WIN32
544     pid_t pid, sid;
545 
546     pid = fork();
547     if (pid < 0) {
548         exit(EXIT_FAILURE);
549     }
550     if (pid > 0) {
551         exit(EXIT_SUCCESS);
552     }
553 
554     if (pidfile) {
555         Error *err = NULL;
556 
557         if (!qemu_write_pidfile(pidfile, &err)) {
558             g_critical("%s", error_get_pretty(err));
559             error_free(err);
560             exit(EXIT_FAILURE);
561         }
562     }
563 
564     umask(S_IRWXG | S_IRWXO);
565     sid = setsid();
566     if (sid < 0) {
567         goto fail;
568     }
569     if ((chdir("/")) < 0) {
570         goto fail;
571     }
572 
573     reopen_fd_to_null(STDIN_FILENO);
574     reopen_fd_to_null(STDOUT_FILENO);
575     reopen_fd_to_null(STDERR_FILENO);
576     return;
577 
578 fail:
579     if (pidfile) {
580         unlink(pidfile);
581     }
582     g_critical("failed to daemonize");
583     exit(EXIT_FAILURE);
584 #endif
585 }
586 
587 static int send_response(GAState *s, const QDict *rsp)
588 {
589     GString *response;
590     GIOStatus status;
591 
592     g_assert(s->channel);
593 
594     if (!rsp) {
595         return 0;
596     }
597 
598     response = qobject_to_json(QOBJECT(rsp));
599     if (!response) {
600         return -EINVAL;
601     }
602 
603     if (s->delimit_response) {
604         s->delimit_response = false;
605         g_string_prepend_c(response, QGA_SENTINEL_BYTE);
606     }
607 
608     g_string_append_c(response, '\n');
609     status = ga_channel_write_all(s->channel, response->str, response->len);
610     g_string_free(response, true);
611     if (status != G_IO_STATUS_NORMAL) {
612         return -EIO;
613     }
614 
615     return 0;
616 }
617 
618 /* handle requests/control events coming in over the channel */
619 static void process_event(void *opaque, QObject *obj, Error *err)
620 {
621     GAState *s = opaque;
622     QDict *rsp;
623     int ret;
624 
625     g_debug("process_event: called");
626     assert(!obj != !err);
627     if (err) {
628         rsp = qmp_error_response(err);
629         goto end;
630     }
631 
632     g_debug("processing command");
633     rsp = qmp_dispatch(&ga_commands, obj, false, NULL);
634 
635 end:
636     ret = send_response(s, rsp);
637     if (ret < 0) {
638         g_warning("error sending error response: %s", strerror(-ret));
639     }
640     qobject_unref(rsp);
641     qobject_unref(obj);
642 }
643 
644 /* false return signals GAChannel to close the current client connection */
645 static gboolean channel_event_cb(GIOCondition condition, gpointer data)
646 {
647     GAState *s = data;
648     gchar buf[QGA_READ_COUNT_DEFAULT + 1];
649     gsize count;
650     GIOStatus status = ga_channel_read(s->channel, buf, QGA_READ_COUNT_DEFAULT, &count);
651     switch (status) {
652     case G_IO_STATUS_ERROR:
653         g_warning("error reading channel");
654         stop_agent(s, false);
655         return false;
656     case G_IO_STATUS_NORMAL:
657         buf[count] = 0;
658         g_debug("read data, count: %d, data: %s", (int)count, buf);
659         json_message_parser_feed(&s->parser, (char *)buf, (int)count);
660         break;
661     case G_IO_STATUS_EOF:
662         g_debug("received EOF");
663         if (!s->virtio) {
664             return false;
665         }
666         /* fall through */
667     case G_IO_STATUS_AGAIN:
668         /* virtio causes us to spin here when no process is attached to
669          * host-side chardev. sleep a bit to mitigate this
670          */
671         if (s->virtio) {
672             g_usleep(G_USEC_PER_SEC / 10);
673         }
674         return true;
675     default:
676         g_warning("unknown channel read status, closing");
677         return false;
678     }
679     return true;
680 }
681 
682 static gboolean channel_init(GAState *s, const gchar *method, const gchar *path,
683                              int listen_fd)
684 {
685     GAChannelMethod channel_method;
686 
687     if (strcmp(method, "virtio-serial") == 0) {
688         s->virtio = true; /* virtio requires special handling in some cases */
689         channel_method = GA_CHANNEL_VIRTIO_SERIAL;
690     } else if (strcmp(method, "isa-serial") == 0) {
691         channel_method = GA_CHANNEL_ISA_SERIAL;
692     } else if (strcmp(method, "unix-listen") == 0) {
693         channel_method = GA_CHANNEL_UNIX_LISTEN;
694     } else if (strcmp(method, "vsock-listen") == 0) {
695         channel_method = GA_CHANNEL_VSOCK_LISTEN;
696     } else {
697         g_critical("unsupported channel method/type: %s", method);
698         return false;
699     }
700 
701     s->channel = ga_channel_new(channel_method, path, listen_fd,
702                                 channel_event_cb, s);
703     if (!s->channel) {
704         g_critical("failed to create guest agent channel");
705         return false;
706     }
707 
708     return true;
709 }
710 
711 #ifdef _WIN32
712 DWORD WINAPI handle_serial_device_events(DWORD type, LPVOID data)
713 {
714     DWORD ret = NO_ERROR;
715     PDEV_BROADCAST_HDR broadcast_header = (PDEV_BROADCAST_HDR)data;
716 
717     if (broadcast_header->dbch_devicetype == DBT_DEVTYP_DEVICEINTERFACE) {
718         switch (type) {
719             /* Device inserted */
720         case DBT_DEVICEARRIVAL:
721             /* Start QEMU-ga's service */
722             if (!SetEvent(ga_state->wakeup_event)) {
723                 ret = GetLastError();
724             }
725             break;
726             /* Device removed */
727         case DBT_DEVICEQUERYREMOVE:
728         case DBT_DEVICEREMOVEPENDING:
729         case DBT_DEVICEREMOVECOMPLETE:
730             /* Stop QEMU-ga's service */
731             if (!ResetEvent(ga_state->wakeup_event)) {
732                 ret = GetLastError();
733             }
734             break;
735         default:
736             ret = ERROR_CALL_NOT_IMPLEMENTED;
737         }
738     }
739     return ret;
740 }
741 
742 DWORD WINAPI service_ctrl_handler(DWORD ctrl, DWORD type, LPVOID data,
743                                   LPVOID ctx)
744 {
745     DWORD ret = NO_ERROR;
746     GAService *service = &ga_state->service;
747 
748     switch (ctrl) {
749     case SERVICE_CONTROL_STOP:
750     case SERVICE_CONTROL_SHUTDOWN:
751         quit_handler(SIGTERM);
752         SetEvent(ga_state->wakeup_event);
753         service->status.dwCurrentState = SERVICE_STOP_PENDING;
754         SetServiceStatus(service->status_handle, &service->status);
755         break;
756     case SERVICE_CONTROL_DEVICEEVENT:
757         handle_serial_device_events(type, data);
758         break;
759 
760     default:
761         ret = ERROR_CALL_NOT_IMPLEMENTED;
762     }
763     return ret;
764 }
765 
766 VOID WINAPI service_main(DWORD argc, TCHAR *argv[])
767 {
768     GAService *service = &ga_state->service;
769 
770     service->status_handle = RegisterServiceCtrlHandlerEx(QGA_SERVICE_NAME,
771         service_ctrl_handler, NULL);
772 
773     if (service->status_handle == 0) {
774         g_critical("Failed to register extended requests function!\n");
775         return;
776     }
777 
778     service->status.dwServiceType = SERVICE_WIN32;
779     service->status.dwCurrentState = SERVICE_RUNNING;
780     service->status.dwControlsAccepted = SERVICE_ACCEPT_STOP | SERVICE_ACCEPT_SHUTDOWN;
781     service->status.dwWin32ExitCode = NO_ERROR;
782     service->status.dwServiceSpecificExitCode = NO_ERROR;
783     service->status.dwCheckPoint = 0;
784     service->status.dwWaitHint = 0;
785     DEV_BROADCAST_DEVICEINTERFACE notification_filter;
786     ZeroMemory(&notification_filter, sizeof(notification_filter));
787     notification_filter.dbcc_devicetype = DBT_DEVTYP_DEVICEINTERFACE;
788     notification_filter.dbcc_size = sizeof(DEV_BROADCAST_DEVICEINTERFACE);
789     notification_filter.dbcc_classguid = GUID_VIOSERIAL_PORT;
790 
791     service->device_notification_handle =
792         RegisterDeviceNotification(service->status_handle,
793             &notification_filter, DEVICE_NOTIFY_SERVICE_HANDLE);
794     if (!service->device_notification_handle) {
795         g_critical("Failed to register device notification handle!\n");
796         return;
797     }
798     SetServiceStatus(service->status_handle, &service->status);
799 
800     run_agent(ga_state);
801 
802     UnregisterDeviceNotification(service->device_notification_handle);
803     service->status.dwCurrentState = SERVICE_STOPPED;
804     SetServiceStatus(service->status_handle, &service->status);
805 }
806 #endif
807 
808 static void set_persistent_state_defaults(GAPersistentState *pstate)
809 {
810     g_assert(pstate);
811     pstate->fd_counter = QGA_PSTATE_DEFAULT_FD_COUNTER;
812 }
813 
814 static void persistent_state_from_keyfile(GAPersistentState *pstate,
815                                           GKeyFile *keyfile)
816 {
817     g_assert(pstate);
818     g_assert(keyfile);
819     /* if any fields are missing, either because the file was tampered with
820      * by agents of chaos, or because the field wasn't present at the time the
821      * file was created, the best we can ever do is start over with the default
822      * values. so load them now, and ignore any errors in accessing key-value
823      * pairs
824      */
825     set_persistent_state_defaults(pstate);
826 
827     if (g_key_file_has_key(keyfile, "global", "fd_counter", NULL)) {
828         pstate->fd_counter =
829             g_key_file_get_integer(keyfile, "global", "fd_counter", NULL);
830     }
831 }
832 
833 static void persistent_state_to_keyfile(const GAPersistentState *pstate,
834                                         GKeyFile *keyfile)
835 {
836     g_assert(pstate);
837     g_assert(keyfile);
838 
839     g_key_file_set_integer(keyfile, "global", "fd_counter", pstate->fd_counter);
840 }
841 
842 static gboolean write_persistent_state(const GAPersistentState *pstate,
843                                        const gchar *path)
844 {
845     GKeyFile *keyfile = g_key_file_new();
846     GError *gerr = NULL;
847     gboolean ret = true;
848     gchar *data = NULL;
849     gsize data_len;
850 
851     g_assert(pstate);
852 
853     persistent_state_to_keyfile(pstate, keyfile);
854     data = g_key_file_to_data(keyfile, &data_len, &gerr);
855     if (gerr) {
856         g_critical("failed to convert persistent state to string: %s",
857                    gerr->message);
858         ret = false;
859         goto out;
860     }
861 
862     g_file_set_contents(path, data, data_len, &gerr);
863     if (gerr) {
864         g_critical("failed to write persistent state to %s: %s",
865                     path, gerr->message);
866         ret = false;
867         goto out;
868     }
869 
870 out:
871     if (gerr) {
872         g_error_free(gerr);
873     }
874     if (keyfile) {
875         g_key_file_free(keyfile);
876     }
877     g_free(data);
878     return ret;
879 }
880 
881 static gboolean read_persistent_state(GAPersistentState *pstate,
882                                       const gchar *path, gboolean frozen)
883 {
884     GKeyFile *keyfile = NULL;
885     GError *gerr = NULL;
886     struct stat st;
887     gboolean ret = true;
888 
889     g_assert(pstate);
890 
891     if (stat(path, &st) == -1) {
892         /* it's okay if state file doesn't exist, but any other error
893          * indicates a permissions issue or some other misconfiguration
894          * that we likely won't be able to recover from.
895          */
896         if (errno != ENOENT) {
897             g_critical("unable to access state file at path %s: %s",
898                        path, strerror(errno));
899             ret = false;
900             goto out;
901         }
902 
903         /* file doesn't exist. initialize state to default values and
904          * attempt to save now. (we could wait till later when we have
905          * modified state we need to commit, but if there's a problem,
906          * such as a missing parent directory, we want to catch it now)
907          *
908          * there is a potential scenario where someone either managed to
909          * update the agent from a version that didn't use a key store
910          * while qemu-ga thought the filesystem was frozen, or
911          * deleted the key store prior to issuing a fsfreeze, prior
912          * to restarting the agent. in this case we go ahead and defer
913          * initial creation till we actually have modified state to
914          * write, otherwise fail to recover from freeze.
915          */
916         set_persistent_state_defaults(pstate);
917         if (!frozen) {
918             ret = write_persistent_state(pstate, path);
919             if (!ret) {
920                 g_critical("unable to create state file at path %s", path);
921                 ret = false;
922                 goto out;
923             }
924         }
925         ret = true;
926         goto out;
927     }
928 
929     keyfile = g_key_file_new();
930     g_key_file_load_from_file(keyfile, path, 0, &gerr);
931     if (gerr) {
932         g_critical("error loading persistent state from path: %s, %s",
933                    path, gerr->message);
934         ret = false;
935         goto out;
936     }
937 
938     persistent_state_from_keyfile(pstate, keyfile);
939 
940 out:
941     if (keyfile) {
942         g_key_file_free(keyfile);
943     }
944     if (gerr) {
945         g_error_free(gerr);
946     }
947 
948     return ret;
949 }
950 
951 int64_t ga_get_fd_handle(GAState *s, Error **errp)
952 {
953     int64_t handle;
954 
955     g_assert(s->pstate_filepath);
956     /*
957      * We block commands and avoid operations that potentially require
958      * writing to disk when we're in a frozen state. this includes opening
959      * new files, so we should never get here in that situation
960      */
961     g_assert(!ga_is_frozen(s));
962 
963     handle = s->pstate.fd_counter++;
964 
965     /* This should never happen on a reasonable timeframe, as guest-file-open
966      * would have to be issued 2^63 times */
967     if (s->pstate.fd_counter == INT64_MAX) {
968         abort();
969     }
970 
971     if (!write_persistent_state(&s->pstate, s->pstate_filepath)) {
972         error_setg(errp, "failed to commit persistent state to disk");
973         return -1;
974     }
975 
976     return handle;
977 }
978 
979 static void ga_print_cmd(const QmpCommand *cmd, void *opaque)
980 {
981     printf("%s\n", qmp_command_name(cmd));
982 }
983 
984 static GList *split_list(const gchar *str, const gchar *delim)
985 {
986     GList *list = NULL;
987     int i;
988     gchar **strv;
989 
990     strv = g_strsplit(str, delim, -1);
991     for (i = 0; strv[i]; i++) {
992         list = g_list_prepend(list, strv[i]);
993     }
994     g_free(strv);
995 
996     return list;
997 }
998 
999 struct GAConfig {
1000     char *channel_path;
1001     char *method;
1002     char *log_filepath;
1003     char *pid_filepath;
1004 #ifdef CONFIG_FSFREEZE
1005     char *fsfreeze_hook;
1006 #endif
1007     char *state_dir;
1008 #ifdef _WIN32
1009     const char *service;
1010 #endif
1011     gchar *bliststr; /* blockedrpcs may point to this string */
1012     gchar *aliststr; /* allowedrpcs may point to this string */
1013     GList *blockedrpcs;
1014     GList *allowedrpcs;
1015     int daemonize;
1016     GLogLevelFlags log_level;
1017     int dumpconf;
1018     bool retry_path;
1019 };
1020 
1021 static void config_load(GAConfig *config)
1022 {
1023     GError *gerr = NULL;
1024     GKeyFile *keyfile;
1025     g_autofree char *conf = g_strdup(g_getenv("QGA_CONF")) ?: get_relocated_path(QGA_CONF_DEFAULT);
1026     const gchar *blockrpcs_key = "block-rpcs";
1027 
1028     /* read system config */
1029     keyfile = g_key_file_new();
1030     if (!g_key_file_load_from_file(keyfile, conf, 0, &gerr)) {
1031         goto end;
1032     }
1033     if (g_key_file_has_key(keyfile, "general", "daemon", NULL)) {
1034         config->daemonize =
1035             g_key_file_get_boolean(keyfile, "general", "daemon", &gerr);
1036     }
1037     if (g_key_file_has_key(keyfile, "general", "method", NULL)) {
1038         config->method =
1039             g_key_file_get_string(keyfile, "general", "method", &gerr);
1040     }
1041     if (g_key_file_has_key(keyfile, "general", "path", NULL)) {
1042         config->channel_path =
1043             g_key_file_get_string(keyfile, "general", "path", &gerr);
1044     }
1045     if (g_key_file_has_key(keyfile, "general", "logfile", NULL)) {
1046         config->log_filepath =
1047             g_key_file_get_string(keyfile, "general", "logfile", &gerr);
1048     }
1049     if (g_key_file_has_key(keyfile, "general", "pidfile", NULL)) {
1050         config->pid_filepath =
1051             g_key_file_get_string(keyfile, "general", "pidfile", &gerr);
1052     }
1053 #ifdef CONFIG_FSFREEZE
1054     if (g_key_file_has_key(keyfile, "general", "fsfreeze-hook", NULL)) {
1055         config->fsfreeze_hook =
1056             g_key_file_get_string(keyfile,
1057                                   "general", "fsfreeze-hook", &gerr);
1058     }
1059 #endif
1060     if (g_key_file_has_key(keyfile, "general", "statedir", NULL)) {
1061         config->state_dir =
1062             g_key_file_get_string(keyfile, "general", "statedir", &gerr);
1063     }
1064     if (g_key_file_has_key(keyfile, "general", "verbose", NULL) &&
1065         g_key_file_get_boolean(keyfile, "general", "verbose", &gerr)) {
1066         /* enable all log levels */
1067         config->log_level = G_LOG_LEVEL_MASK;
1068     }
1069     if (g_key_file_has_key(keyfile, "general", "retry-path", NULL)) {
1070         config->retry_path =
1071             g_key_file_get_boolean(keyfile, "general", "retry-path", &gerr);
1072     }
1073 
1074     if (g_key_file_has_key(keyfile, "general", "blacklist", NULL)) {
1075         g_warning("config using deprecated 'blacklist' key, should be replaced"
1076                   " with the 'block-rpcs' key.");
1077         blockrpcs_key = "blacklist";
1078     }
1079     if (g_key_file_has_key(keyfile, "general", blockrpcs_key, NULL)) {
1080         config->bliststr =
1081             g_key_file_get_string(keyfile, "general", blockrpcs_key, &gerr);
1082         config->blockedrpcs = g_list_concat(config->blockedrpcs,
1083                                           split_list(config->bliststr, ","));
1084     }
1085     if (g_key_file_has_key(keyfile, "general", "allow-rpcs", NULL)) {
1086         config->aliststr =
1087             g_key_file_get_string(keyfile, "general", "allow-rpcs", &gerr);
1088         config->allowedrpcs = g_list_concat(config->allowedrpcs,
1089                                           split_list(config->aliststr, ","));
1090     }
1091 
1092     if (g_key_file_has_key(keyfile, "general", blockrpcs_key, NULL) &&
1093         g_key_file_has_key(keyfile, "general", "allow-rpcs", NULL)) {
1094         g_critical("wrong config, using 'block-rpcs' and 'allow-rpcs' keys at"
1095                    " the same time is not allowed");
1096         exit(EXIT_FAILURE);
1097     }
1098 
1099 end:
1100     g_key_file_free(keyfile);
1101     if (gerr &&
1102         !(gerr->domain == G_FILE_ERROR && gerr->code == G_FILE_ERROR_NOENT)) {
1103         g_critical("error loading configuration from path: %s, %s",
1104                    conf, gerr->message);
1105         exit(EXIT_FAILURE);
1106     }
1107     g_clear_error(&gerr);
1108 }
1109 
1110 static gchar *list_join(GList *list, const gchar separator)
1111 {
1112     GString *str = g_string_new("");
1113 
1114     while (list) {
1115         str = g_string_append(str, (gchar *)list->data);
1116         list = g_list_next(list);
1117         if (list) {
1118             str = g_string_append_c(str, separator);
1119         }
1120     }
1121 
1122     return g_string_free(str, FALSE);
1123 }
1124 
1125 static void config_dump(GAConfig *config)
1126 {
1127     GError *error = NULL;
1128     GKeyFile *keyfile;
1129     gchar *tmp;
1130 
1131     keyfile = g_key_file_new();
1132     g_assert(keyfile);
1133 
1134     g_key_file_set_boolean(keyfile, "general", "daemon", config->daemonize);
1135     g_key_file_set_string(keyfile, "general", "method", config->method);
1136     if (config->channel_path) {
1137         g_key_file_set_string(keyfile, "general", "path", config->channel_path);
1138     }
1139     if (config->log_filepath) {
1140         g_key_file_set_string(keyfile, "general", "logfile",
1141                               config->log_filepath);
1142     }
1143     g_key_file_set_string(keyfile, "general", "pidfile", config->pid_filepath);
1144 #ifdef CONFIG_FSFREEZE
1145     if (config->fsfreeze_hook) {
1146         g_key_file_set_string(keyfile, "general", "fsfreeze-hook",
1147                               config->fsfreeze_hook);
1148     }
1149 #endif
1150     g_key_file_set_string(keyfile, "general", "statedir", config->state_dir);
1151     g_key_file_set_boolean(keyfile, "general", "verbose",
1152                            config->log_level == G_LOG_LEVEL_MASK);
1153     g_key_file_set_boolean(keyfile, "general", "retry-path",
1154                            config->retry_path);
1155     tmp = list_join(config->blockedrpcs, ',');
1156     g_key_file_set_string(keyfile, "general", "block-rpcs", tmp);
1157     g_free(tmp);
1158     tmp = list_join(config->allowedrpcs, ',');
1159     g_key_file_set_string(keyfile, "general", "allow-rpcs", tmp);
1160     g_free(tmp);
1161 
1162     tmp = g_key_file_to_data(keyfile, NULL, &error);
1163     if (error) {
1164         g_critical("Failed to dump keyfile: %s", error->message);
1165         g_clear_error(&error);
1166     } else {
1167         printf("%s", tmp);
1168     }
1169 
1170     g_free(tmp);
1171     g_key_file_free(keyfile);
1172 }
1173 
1174 static void config_parse(GAConfig *config, int argc, char **argv)
1175 {
1176     const char *sopt = "hVvdm:p:l:f:F::b:a:s:t:Dr";
1177     int opt_ind = 0, ch;
1178     bool block_rpcs = false, allow_rpcs = false;
1179     const struct option lopt[] = {
1180         { "help", 0, NULL, 'h' },
1181         { "version", 0, NULL, 'V' },
1182         { "dump-conf", 0, NULL, 'D' },
1183         { "logfile", 1, NULL, 'l' },
1184         { "pidfile", 1, NULL, 'f' },
1185 #ifdef CONFIG_FSFREEZE
1186         { "fsfreeze-hook", 2, NULL, 'F' },
1187 #endif
1188         { "verbose", 0, NULL, 'v' },
1189         { "method", 1, NULL, 'm' },
1190         { "path", 1, NULL, 'p' },
1191         { "daemonize", 0, NULL, 'd' },
1192         { "block-rpcs", 1, NULL, 'b' },
1193         { "blacklist", 1, NULL, 'b' },  /* deprecated alias for 'block-rpcs' */
1194         { "allow-rpcs", 1, NULL, 'a' },
1195 #ifdef _WIN32
1196         { "service", 1, NULL, 's' },
1197 #endif
1198         { "statedir", 1, NULL, 't' },
1199         { "retry-path", 0, NULL, 'r' },
1200         { NULL, 0, NULL, 0 }
1201     };
1202 
1203     while ((ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1) {
1204         switch (ch) {
1205         case 'm':
1206             g_free(config->method);
1207             config->method = g_strdup(optarg);
1208             break;
1209         case 'p':
1210             g_free(config->channel_path);
1211             config->channel_path = g_strdup(optarg);
1212             break;
1213         case 'l':
1214             g_free(config->log_filepath);
1215             config->log_filepath = g_strdup(optarg);
1216             break;
1217         case 'f':
1218             g_free(config->pid_filepath);
1219             config->pid_filepath = g_strdup(optarg);
1220             break;
1221 #ifdef CONFIG_FSFREEZE
1222         case 'F':
1223             g_free(config->fsfreeze_hook);
1224             config->fsfreeze_hook = optarg ? g_strdup(optarg) : get_relocated_path(QGA_FSFREEZE_HOOK_DEFAULT);
1225             break;
1226 #endif
1227         case 't':
1228             g_free(config->state_dir);
1229             config->state_dir = g_strdup(optarg);
1230             break;
1231         case 'v':
1232             /* enable all log levels */
1233             config->log_level = G_LOG_LEVEL_MASK;
1234             break;
1235         case 'V':
1236             printf("QEMU Guest Agent %s\n", QEMU_VERSION);
1237             exit(EXIT_SUCCESS);
1238         case 'd':
1239             config->daemonize = 1;
1240             break;
1241         case 'D':
1242             config->dumpconf = 1;
1243             break;
1244         case 'r':
1245             config->retry_path = true;
1246             break;
1247         case 'b': {
1248             if (is_help_option(optarg)) {
1249                 qmp_for_each_command(&ga_commands, ga_print_cmd, NULL);
1250                 exit(EXIT_SUCCESS);
1251             }
1252             config->blockedrpcs = g_list_concat(config->blockedrpcs,
1253                                                 split_list(optarg, ","));
1254             block_rpcs = true;
1255             break;
1256         }
1257         case 'a': {
1258             if (is_help_option(optarg)) {
1259                 qmp_for_each_command(&ga_commands, ga_print_cmd, NULL);
1260                 exit(EXIT_SUCCESS);
1261             }
1262             config->allowedrpcs = g_list_concat(config->allowedrpcs,
1263                                                 split_list(optarg, ","));
1264             allow_rpcs = true;
1265             break;
1266         }
1267 #ifdef _WIN32
1268         case 's':
1269             config->service = optarg;
1270             if (strcmp(config->service, "install") == 0) {
1271                 if (ga_install_vss_provider()) {
1272                     exit(EXIT_FAILURE);
1273                 }
1274                 if (ga_install_service(config->channel_path,
1275                                        config->log_filepath, config->state_dir)) {
1276                     exit(EXIT_FAILURE);
1277                 }
1278                 exit(EXIT_SUCCESS);
1279             } else if (strcmp(config->service, "uninstall") == 0) {
1280                 ga_uninstall_vss_provider();
1281                 exit(ga_uninstall_service());
1282             } else if (strcmp(config->service, "vss-install") == 0) {
1283                 if (ga_install_vss_provider()) {
1284                     exit(EXIT_FAILURE);
1285                 }
1286                 exit(EXIT_SUCCESS);
1287             } else if (strcmp(config->service, "vss-uninstall") == 0) {
1288                 ga_uninstall_vss_provider();
1289                 exit(EXIT_SUCCESS);
1290             } else {
1291                 printf("Unknown service command.\n");
1292                 exit(EXIT_FAILURE);
1293             }
1294             break;
1295 #endif
1296         case 'h':
1297             usage(argv[0]);
1298             exit(EXIT_SUCCESS);
1299         case '?':
1300             g_print("Unknown option, try '%s --help' for more information.\n",
1301                     argv[0]);
1302             exit(EXIT_FAILURE);
1303         }
1304     }
1305 
1306     if (block_rpcs && allow_rpcs) {
1307         g_critical("wrong commandline, using --block-rpcs and --allow-rpcs at the"
1308                    " same time is not allowed");
1309         exit(EXIT_FAILURE);
1310     }
1311 }
1312 
1313 static void config_free(GAConfig *config)
1314 {
1315     g_free(config->method);
1316     g_free(config->log_filepath);
1317     g_free(config->pid_filepath);
1318     g_free(config->state_dir);
1319     g_free(config->channel_path);
1320     g_free(config->bliststr);
1321     g_free(config->aliststr);
1322 #ifdef CONFIG_FSFREEZE
1323     g_free(config->fsfreeze_hook);
1324 #endif
1325     g_list_free_full(config->blockedrpcs, g_free);
1326     g_list_free_full(config->allowedrpcs, g_free);
1327     g_free(config);
1328 }
1329 
1330 static bool check_is_frozen(GAState *s)
1331 {
1332 #ifndef _WIN32
1333     /* check if a previous instance of qemu-ga exited with filesystems' state
1334      * marked as frozen. this could be a stale value (a non-qemu-ga process
1335      * or reboot may have since unfrozen them), but better to require an
1336      * unneeded unfreeze than to risk hanging on start-up
1337      */
1338     struct stat st;
1339     if (stat(s->state_filepath_isfrozen, &st) == -1) {
1340         /* it's okay if the file doesn't exist, but if we can't access for
1341          * some other reason, such as permissions, there's a configuration
1342          * that needs to be addressed. so just bail now before we get into
1343          * more trouble later
1344          */
1345         if (errno != ENOENT) {
1346             g_critical("unable to access state file at path %s: %s",
1347                        s->state_filepath_isfrozen, strerror(errno));
1348             return EXIT_FAILURE;
1349         }
1350     } else {
1351         g_warning("previous instance appears to have exited with frozen"
1352                   " filesystems. deferring logging/pidfile creation and"
1353                   " disabling non-fsfreeze-safe commands until"
1354                   " guest-fsfreeze-thaw is issued, or filesystems are"
1355                   " manually unfrozen and the file %s is removed",
1356                   s->state_filepath_isfrozen);
1357         return true;
1358     }
1359 #endif
1360     return false;
1361 }
1362 
1363 static GAState *initialize_agent(GAConfig *config, int socket_activation)
1364 {
1365     GAState *s = g_new0(GAState, 1);
1366 
1367     g_assert(ga_state == NULL);
1368 
1369     s->log_level = config->log_level;
1370     s->log_file = stderr;
1371 #ifdef CONFIG_FSFREEZE
1372     s->fsfreeze_hook = config->fsfreeze_hook;
1373 #endif
1374     s->pstate_filepath = g_strdup_printf("%s/qga.state", config->state_dir);
1375     s->state_filepath_isfrozen = g_strdup_printf("%s/qga.state.isfrozen",
1376                                                  config->state_dir);
1377     s->frozen = check_is_frozen(s);
1378 
1379     g_log_set_default_handler(ga_log, s);
1380     g_log_set_fatal_mask(NULL, G_LOG_LEVEL_ERROR);
1381     ga_enable_logging(s);
1382 
1383     g_debug("Guest agent version %s started", QEMU_FULL_VERSION);
1384 
1385 #ifdef _WIN32
1386     s->event_log = RegisterEventSource(NULL, "qemu-ga");
1387     if (!s->event_log) {
1388         g_autofree gchar *errmsg = g_win32_error_message(GetLastError());
1389         g_critical("unable to register event source: %s", errmsg);
1390         return NULL;
1391     }
1392 
1393     /* On win32 the state directory is application specific (be it the default
1394      * or a user override). We got past the command line parsing; let's create
1395      * the directory (with any intermediate directories). If we run into an
1396      * error later on, we won't try to clean up the directory, it is considered
1397      * persistent.
1398      */
1399     if (g_mkdir_with_parents(config->state_dir, S_IRWXU) == -1) {
1400         g_critical("unable to create (an ancestor of) the state directory"
1401                    " '%s': %s", config->state_dir, strerror(errno));
1402         return NULL;
1403     }
1404 #endif
1405 
1406     if (ga_is_frozen(s)) {
1407         if (config->daemonize) {
1408             /* delay opening/locking of pidfile till filesystems are unfrozen */
1409             s->deferred_options.pid_filepath = config->pid_filepath;
1410             become_daemon(NULL);
1411         }
1412         if (config->log_filepath) {
1413             /* delay opening the log file till filesystems are unfrozen */
1414             s->deferred_options.log_filepath = config->log_filepath;
1415         }
1416         ga_disable_logging(s);
1417         qmp_for_each_command(&ga_commands, ga_disable_not_allowed_freeze, NULL);
1418     } else {
1419         if (config->daemonize) {
1420             become_daemon(config->pid_filepath);
1421         }
1422         if (config->log_filepath) {
1423             FILE *log_file = ga_open_logfile(config->log_filepath);
1424             if (!log_file) {
1425                 g_critical("unable to open specified log file: %s",
1426                            strerror(errno));
1427                 return NULL;
1428             }
1429             s->log_file = log_file;
1430         }
1431     }
1432 
1433     /* load persistent state from disk */
1434     if (!read_persistent_state(&s->pstate,
1435                                s->pstate_filepath,
1436                                ga_is_frozen(s))) {
1437         g_critical("failed to load persistent state");
1438         return NULL;
1439     }
1440 
1441     if (config->allowedrpcs) {
1442         qmp_for_each_command(&ga_commands, ga_disable_not_allowed, config->allowedrpcs);
1443         s->allowedrpcs = config->allowedrpcs;
1444     }
1445 
1446     /*
1447      * Some commands can be blocked due to system limitation.
1448      * Initialize blockedrpcs list even if allowedrpcs specified.
1449      */
1450     config->blockedrpcs = ga_command_init_blockedrpcs(config->blockedrpcs);
1451     if (config->blockedrpcs) {
1452         GList *l = config->blockedrpcs;
1453         s->blockedrpcs = config->blockedrpcs;
1454         do {
1455             g_debug("disabling command: %s", (char *)l->data);
1456             qmp_disable_command(&ga_commands, l->data, NULL);
1457             l = g_list_next(l);
1458         } while (l);
1459     }
1460     s->command_state = ga_command_state_new();
1461     ga_command_state_init(s, s->command_state);
1462     ga_command_state_init_all(s->command_state);
1463     json_message_parser_init(&s->parser, process_event, s, NULL);
1464 
1465 #ifndef _WIN32
1466     if (!register_signal_handlers()) {
1467         g_critical("failed to register signal handlers");
1468         return NULL;
1469     }
1470 #endif
1471 
1472     s->main_loop = g_main_loop_new(NULL, false);
1473 
1474     s->config = config;
1475     s->socket_activation = socket_activation;
1476 
1477 #ifdef _WIN32
1478     s->wakeup_event = CreateEvent(NULL, TRUE, FALSE, TEXT("WakeUp"));
1479     if (s->wakeup_event == NULL) {
1480         g_critical("CreateEvent failed");
1481         return NULL;
1482     }
1483 #endif
1484 
1485     ga_state = s;
1486     return s;
1487 }
1488 
1489 static void cleanup_agent(GAState *s)
1490 {
1491 #ifdef _WIN32
1492     CloseHandle(s->wakeup_event);
1493     CloseHandle(s->event_log);
1494 #endif
1495     if (s->command_state) {
1496         ga_command_state_cleanup_all(s->command_state);
1497         ga_command_state_free(s->command_state);
1498         json_message_parser_destroy(&s->parser);
1499     }
1500     g_free(s->pstate_filepath);
1501     g_free(s->state_filepath_isfrozen);
1502     if (s->main_loop) {
1503         g_main_loop_unref(s->main_loop);
1504     }
1505     g_free(s);
1506     ga_state = NULL;
1507 }
1508 
1509 static int run_agent_once(GAState *s)
1510 {
1511     if (!channel_init(s, s->config->method, s->config->channel_path,
1512                       s->socket_activation ? FIRST_SOCKET_ACTIVATION_FD : -1)) {
1513         g_critical("failed to initialize guest agent channel");
1514         return EXIT_FAILURE;
1515     }
1516 
1517     g_main_loop_run(ga_state->main_loop);
1518 
1519     if (s->channel) {
1520         ga_channel_free(s->channel);
1521     }
1522 
1523     return EXIT_SUCCESS;
1524 }
1525 
1526 static void wait_for_channel_availability(GAState *s)
1527 {
1528     g_warning("waiting for channel path...");
1529 #ifndef _WIN32
1530     sleep(QGA_RETRY_INTERVAL);
1531 #else
1532     DWORD dwWaitResult;
1533 
1534     dwWaitResult = WaitForSingleObject(s->wakeup_event, INFINITE);
1535 
1536     switch (dwWaitResult) {
1537     case WAIT_OBJECT_0:
1538         break;
1539     case WAIT_TIMEOUT:
1540         break;
1541     default:
1542         g_critical("WaitForSingleObject failed");
1543     }
1544 #endif
1545 }
1546 
1547 static int run_agent(GAState *s)
1548 {
1549     int ret = EXIT_SUCCESS;
1550 
1551     s->force_exit = false;
1552 
1553     do {
1554         ret = run_agent_once(s);
1555         if (s->config->retry_path && !s->force_exit) {
1556             g_warning("agent stopped unexpectedly, restarting...");
1557             wait_for_channel_availability(s);
1558         }
1559     } while (s->config->retry_path && !s->force_exit);
1560 
1561     return ret;
1562 }
1563 
1564 static void stop_agent(GAState *s, bool requested)
1565 {
1566     if (!s->force_exit) {
1567         s->force_exit = requested;
1568     }
1569 
1570     if (g_main_loop_is_running(s->main_loop)) {
1571         g_main_loop_quit(s->main_loop);
1572     }
1573 }
1574 
1575 int main(int argc, char **argv)
1576 {
1577     int ret = EXIT_SUCCESS;
1578     GAState *s;
1579     GAConfig *config = g_new0(GAConfig, 1);
1580     int socket_activation;
1581 
1582     config->log_level = G_LOG_LEVEL_ERROR | G_LOG_LEVEL_CRITICAL;
1583 
1584     qemu_init_exec_dir(argv[0]);
1585     qga_qmp_init_marshal(&ga_commands);
1586 
1587     init_dfl_pathnames();
1588     config_load(config);
1589     config_parse(config, argc, argv);
1590 
1591     if (config->pid_filepath == NULL) {
1592         config->pid_filepath = g_strdup(dfl_pathnames.pidfile);
1593     }
1594 
1595     if (config->state_dir == NULL) {
1596         config->state_dir = g_strdup(dfl_pathnames.state_dir);
1597     }
1598 
1599     if (config->method == NULL) {
1600         config->method = g_strdup("virtio-serial");
1601     }
1602 
1603     socket_activation = check_socket_activation();
1604     if (socket_activation > 1) {
1605         g_critical("qemu-ga only supports listening on one socket");
1606         ret = EXIT_FAILURE;
1607         goto end;
1608     }
1609     if (socket_activation) {
1610         SocketAddress *addr;
1611 
1612         g_free(config->method);
1613         g_free(config->channel_path);
1614         config->method = NULL;
1615         config->channel_path = NULL;
1616 
1617         addr = socket_local_address(FIRST_SOCKET_ACTIVATION_FD, NULL);
1618         if (addr) {
1619             if (addr->type == SOCKET_ADDRESS_TYPE_UNIX) {
1620                 config->method = g_strdup("unix-listen");
1621             } else if (addr->type == SOCKET_ADDRESS_TYPE_VSOCK) {
1622                 config->method = g_strdup("vsock-listen");
1623             }
1624 
1625             qapi_free_SocketAddress(addr);
1626         }
1627 
1628         if (!config->method) {
1629             g_critical("unsupported listen fd type");
1630             ret = EXIT_FAILURE;
1631             goto end;
1632         }
1633     } else if (config->channel_path == NULL) {
1634         if (strcmp(config->method, "virtio-serial") == 0) {
1635             /* try the default path for the virtio-serial port */
1636             config->channel_path = g_strdup(QGA_VIRTIO_PATH_DEFAULT);
1637         } else if (strcmp(config->method, "isa-serial") == 0) {
1638             /* try the default path for the serial port - COM1 */
1639             config->channel_path = g_strdup(QGA_SERIAL_PATH_DEFAULT);
1640         } else {
1641             g_critical("must specify a path for this channel");
1642             ret = EXIT_FAILURE;
1643             goto end;
1644         }
1645     }
1646 
1647     if (config->dumpconf) {
1648         config_dump(config);
1649         goto end;
1650     }
1651 
1652     s = initialize_agent(config, socket_activation);
1653     if (!s) {
1654         g_critical("error initializing guest agent");
1655         goto end;
1656     }
1657 
1658 #ifdef _WIN32
1659     if (config->daemonize) {
1660         SERVICE_TABLE_ENTRY service_table[] = {
1661             { (char *)QGA_SERVICE_NAME, service_main }, { NULL, NULL } };
1662         StartServiceCtrlDispatcher(service_table);
1663     } else {
1664         ret = run_agent(s);
1665     }
1666 #else
1667     ret = run_agent(s);
1668 #endif
1669 
1670     cleanup_agent(s);
1671 
1672 end:
1673     if (config->daemonize) {
1674         unlink(config->pid_filepath);
1675     }
1676 
1677     config_free(config);
1678 
1679     return ret;
1680 }
1681