1. 29 Aug, 2012 1 commit
  2. 22 Aug, 2012 1 commit
  3. 13 Aug, 2012 2 commits
  4. 02 Aug, 2012 1 commit
    • Peter Maydell's avatar
      Support 'help' as a synonym for '?' in command line options · c8057f95
      Peter Maydell authored
      For command line options which permit '?' meaning 'please list the
      permitted values', add support for 'help' as a synonym, by abstracting
      the check out into a helper function.
      This change means that in some cases where we were being lazy in
      our string parsing, "?junk" will now be rejected as an invalid option
      rather than being (undocumentedly) treated the same way as "?".
      Update the documentation to use 'help' rather than '?', since '?'
      is a shell metacharacter and thus prone to fail confusingly if there
      is a single character filename in the current working directory and
      the '?' has not been escaped. It's therefore better to steer users
      towards 'help', though '?' is retained for backwards compatibility.
      We do not, however, update the output of the system emulator's -help
      (or any documentation autogenerated from the qemu-options.hx which
      is the source of the -help text) because libvirt parses our -help
      output and will break. At a later date when QEMU provides a better
      interface so libvirt can avoid having to do this, we can update the
      -help text too.
      Signed-off-by: default avatarPeter Maydell <peter.maydell@linaro.org>
      Signed-off-by: default avatarAnthony Liguori <aliguori@us.ibm.com>
  5. 15 May, 2012 6 commits
    • Michael Roth's avatar
      qemu-ga: align versioning with QEMU_VERSION · 8efacc43
      Michael Roth authored
      Previously qemu-ga version was defined seperately. Since it is aligned
      with QEMU releases, use QEMU_VERSION instead. This also implies the
      version bump for 1.1[-rcN] release of qemu-ga.
      Reviewed-by: default avatarMichal Privoznik <mprivozn@redhat.com>
      Acked-by: default avatarLuiz Capitulino <lcapitulino@redhat.com>
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
    • Michael Roth's avatar
      qemu-ga: fix segv after failure to open log file · 6c615ec5
      Michael Roth authored
      Currently, if we fail to open the specified log file (generally due to a
      permissions issue), we'll assign NULL to the logfile handle (stderr,
      initially) used by the logging routines, which can cause a segfault to
      occur when we attempt to report the error before exiting.
      Instead, only re-assign if the open() was successful.
      Reviewed-by: default avatarMichal Privoznik <mprivozn@redhat.com>
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
    • Luiz Capitulino's avatar
      qemu-ga: guest-suspend: make the API synchronous · dc8764f0
      Luiz Capitulino authored
      Currently, qemu-ga has a SIGCHLD handler that automatically reaps terminated
      children processes. The idea is to avoid having qemu-ga commands blocked
      waiting for children to terminate.
      That approach has two problems:
       1. qemu-ga is unable to detect errors in the child, meaning that qemu-ga
          returns success even if the child fails to perform its task
       2. if a command does depend on the child exit status, the command has to
          play tricks to bypass the automatic reaper
      Case 2 impacts the guest-suspend-* API, because it has to execute an external
      program to check for suspend support. Today, to bypass the automatic reaper,
      suspend code has to double fork and pass exit status information through a
      pipe. Besides being complex, this is prone to race condition bugs. Indeed,
      the current code does have such bugs.
      Making the guest-suspend-* API synchronous (ie. by dropping the SIGCHLD
      handler and calling waitpid() from commands) is a much simpler approach,
      which fixes current race conditions bugs and enables commands to detect
      errors in the child.
      This commit does just that. There's a side effect though, guest-shutdown
      will generate zombies if shutting down fails. This will be fixed by the
      next commit.
      Signed-off-by: default avatarLuiz Capitulino <lcapitulino@redhat.com>
      Reviewed-by: default avatarEric Blake <eblake@redhat.com>
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
    • Luiz Capitulino's avatar
      qemu-ga: become_daemon(): reopen standard fds to /dev/null · 226a4894
      Luiz Capitulino authored
      This fixes a bug where qemu-ga doesn't suspend the guest because it
      fails to detect suspend support even when the guest does support
      suspend. This happens because of the way qemu-ga fds are managed in
      daemon mode.
      When starting qemu-ga with --daemon, become_daemon() will close all
      standard fds. This will cause qemu-ga to end up with the following
      fds (if started with 'qemu-ga --daemon'):
          0 -> /dev/vport0p1
          3 -> /run/qemu-ga.pid
      Then a guest-suspend-* function is issued. They call bios_supports_mode(),
      which will call pipe(), and qemu-ga's fd will be:
          0 -> /dev/vport0p1
          1 -> pipe:[16247]
          2 -> pipe:[16247]
          3 -> /run/qemu-ga.pid
      bios_supports_mode() forks off a child and blocks waiting for the child
      to write something to the pipe. The child, however, closes its reading
      end of the pipe _and_ reopen all standard fds to /dev/null. This will
      cause the child's fds to be:
          0 -> /dev/null
          1 -> /dev/null
          2 -> /dev/null
          3 -> /run/qemu-ga.pid
      In other words, the child's writing end of the pipe is now /dev/null.
      It writes there and exits. The parent process (blocked on read()) will
      get an EOF and interpret this as "something unexpected happened in
      the child, let's assume the guest doesn't support suspend". And suspend
      will fail.
      To solve this problem we have to reopen standard fds to /dev/null
      in become_daemon(), instead of closing them.
      Signed-off-by: default avatarLuiz Capitulino <lcapitulino@redhat.com>
      Reviewed-by: default avatarEric Blake <eblake@redhat.com>
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
    • Luiz Capitulino's avatar
      qemu-ga: make reopen_fd_to_null() public · 04b4e75f
      Luiz Capitulino authored
      The next commit wants to use it.
      Signed-off-by: default avatarLuiz Capitulino <lcapitulino@redhat.com>
      Reviewed-by: default avatarEric Blake <eblake@redhat.com>
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
    • Luiz Capitulino's avatar
      qemu-ga: don't warn on no command return · ce8c8b7b
      Luiz Capitulino authored
      This is a valid condition when a command chooses to not emit a
      success response.
      Signed-off-by: default avatarLuiz Capitulino <lcapitulino@redhat.com>
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
  6. 14 May, 2012 1 commit
    • Jim Meyering's avatar
      fix some common typos · a31f0531
      Jim Meyering authored
      These were identified using: http://github.com/lyda/misspell-check
      and run like this to create a bourne shell script using GNU sed's
      -i option:
      git ls-files|grep -vF .bin | misspellings -f - |grep -v '^ERROR:' |perl \
      -pe 's/^(.*?)\[(\d+)\]: (\w+) -> "(.*?)"$/sed -i '\''${2}s!$3!$4!'\'' $1/'
      Manually eliding the FP, "rela->real" and resolving "addres" to
      address (not "adders") we get this:
        sed -i '450s!thru!through!' Changelog
        sed -i '260s!neccessary!necessary!' coroutine-sigaltstack.c
        sed -i '54s!miniscule!minuscule!' disas.c
        sed -i '1094s!thru!through!' hw/usb/hcd-ehci.c
        sed -i '1095s!thru!through!' hw/usb/hcd-ehci.c
        sed -i '21s!unecessary!unnecessary!' qapi-schema-guest.json
        sed -i '307s!explictly!explicitly!' qemu-ga.c
        sed -i '490s!preceeding!preceding!' qga/commands-posix.c
        sed -i '792s!addres!address!' qga/commands-posix.c
        sed -i '6s!beeing!being!' tests/tcg/test-mmap.c
      Also, manually fix "arithmentic", spotted by Peter Maydell:
        sed -i 's!arithmentic!arithmetic!' coroutine-sigaltstack.c
      Signed-off-by: default avatarJim Meyering <meyering@redhat.com>
      Reviewed-by: default avatarPeter Maydell <peter.maydell@linaro.org>
  7. 30 Apr, 2012 2 commits
    • Michael Roth's avatar
      qemu-ga: persist tracking of fsfreeze state via filesystem · f789aa7b
      Michael Roth authored
      Currently, qemu-ga may die/get killed/go away for whatever reason after
      guest-fsfreeze-freeze has been issued, and before guest-fsfreeze-thaw
      has been issued. This means the only way to unfreeze the guest is via
      VNC/network/console access, but obtaining that access after-the-fact can
      often be very difficult when filesystems are frozen. Logins will almost
      always hang, for instance. In many cases the only recourse would be to
      reboot the guest without any quiescing of volatile state, which makes
      this a corner-case worth giving some attention to.
      A likely failsafe for this situation would be to use a watchdog to
      restart qemu-ga if it goes away. There are some precautions qemu-ga
      needs to take in order to avoid immediately hanging itself on I/O,
      however, namely, we must disable logging and defer to processing/creation
      of user-specific logfiles, along with creation of the pid file if we're
      running as a daemon. We also need to disable non-fsfreeze-safe commands,
      as we normally would when processing the guest-fsfreeze-freeze command.
      To track when we need to do this in a way that persists between multiple
      invocations of qemu-ga, we create a file on the guest filesystem before
      issuing the fsfreeze, and delete it when doing the thaw. On qemu-ga
      startup, we check for the existance of this file to determine
      the need to take the above precautions.
      We're forced to do it this way since a more traditional approach such as
      reading/writing state to a dedicated state file will cause
      access/modification time updates, respectively, both of which will hang
      if the file resides on a frozen filesystem. Both can occur even if
      relatime is enabled. Checking for file existence will not update the
      access time, however, so it's a safe way to check for fsfreeze state.
      An actual watchdog-based restart of qemu-ga can itself cause an access
      time update that would thus hang the invocation of qemu-ga, but the
      logic to workaround that can be handled via the watchdog, so we don't
      address that here (for relatime we'd periodically touch the qemu-ga
      binary if the file $qga_statedir/qga.state.isfrozen is not present, this
      avoids qemu-ga updates or the 1 day relatime threshold causing an
      access-time update if we try to respawn qemu-ga shortly after it goes
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
    • Michael Roth's avatar
      qemu-ga: add a whitelist for fsfreeze-safe commands · f22d85e9
      Michael Roth authored
      Currently we rely on fsfreeze/thaw commands disabling/enabling logging
      then having other commands check whether logging is disabled to avoid
      executing if they aren't safe for running while a filesystem is frozen.
      Instead, have an explicit whitelist of fsfreeze-safe commands, and
      consolidate logging and command enablement/disablement into a pair
      of helper functions: ga_set_frozen()/ga_unset_frozen()
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
  8. 19 Apr, 2012 1 commit
  9. 12 Mar, 2012 2 commits
    • Michael Roth's avatar
      qemu-ga: add guest-sync-delimited · 3cf0bed8
      Michael Roth authored
      guest-sync leaves it as an exercise to the user as to how to reliably
      obtain the response to guest-sync if the client had previously read in a
      partial response (due qemu-ga previously being restarted mid-"sentence"
      due to reboot, forced restart, etc).
      qemu-ga handles this situation on its end by having a client precede
      their guest-sync request with a 0xFF byte (invalid UTF-8), which
      qemu-ga/QEMU JSON parsers will treat as a flush event. Thus we can
      reliably flush the qemu-ga parser state in preparation for receiving
      the guest-sync request.
      guest-sync-delimited provides the same functionality for a client: when
      a guest-sync-delimited is issued, qemu-ga will precede it's response
      with a 0xFF byte that the client can use as an indicator to flush its
      buffer/parser state in preparation for reliably receiving the
      guest-sync-delimited response.
      It is also useful as an optimization for clients, since, after issuing a
      guest-sync-delimited, clients can safely discard all stale data read
      from the channel until the 0xFF is found.
      More information available on the wiki:
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
    • Luiz Capitulino's avatar
      qemu-ga: add guest-suspend-disk · 11d0f125
      Luiz Capitulino authored
      As the command name implies, this command suspends the guest to disk.
      The suspend operation is implemented by two functions: bios_supports_mode()
      and guest_suspend(). Both functions are generic enough to be used by
      other suspend modes (introduced by next commits).
      Both functions will try to use the scripts provided by the pm-utils
      package if it's available. If it's not available, a manual method,
      which consists of directly writing to '/sys/power/state', will be used.
      To reap terminated children, a new signal handler is installed in the
      parent to catch SIGCHLD signals and a non-blocking call to waitpid()
      is done to collect their exit statuses. The statuses, however, are
      The approach used to query the guest for suspend support deserves some
      explanation. It's implemented by bios_supports_mode() and shown below:
       create pipe
           |               |
           |               |
           |             fork()
           |               --------------------------
           |               |                        |
           |               |                        |
           |               |               exec('pm-is-supported')
           |               |
           |              wait()
           |       write exit status to pipe
           |              exit
        read pipe
      This might look complex, but the resulting code is quite simple.
      The purpose of that approach is to allow qemu-ga to reap its children
      (semi-)automatically from its SIGCHLD handler.
      Implementing this the obvious way, that's, doing the exec() call from
      the first child process, would force us to introduce a more complex way
      to reap qemu-ga's children. Like registering PIDs to be reaped and
      having a way to wait for them when returning their exit status to
      qemu-ga is necessary. The approach explained above avoids that complexity.
      Signed-off-by: default avatarLuiz Capitulino <lcapitulino@redhat.com>
  10. 23 Feb, 2012 4 commits
    • Michael Roth's avatar
      qemu-ga: add Windows service integration · bc62fa03
      Michael Roth authored
      This allows qemu-ga to function as a Windows service:
       - to install the service (will auto-start on boot):
           qemu-ga --service install
       - to start the service:
           net start qemu-ga
       - to stop the service:
           net stop qemu-ga
       - to uninstall service:
           qemu-ga --service uninstall
      Original patch by Gal Hammer <ghammer@redhat.com>
    • Michael Roth's avatar
      qemu-ga: add initial win32 support · 7868e26e
      Michael Roth authored
      This adds a win32 channel implementation that makes qemu-ga functional
      on Windows using virtio-serial (unix-listen/isa-serial not currently
      implemented). Unlike with the posix implementation, we do not use
      GIOChannel for the following reasons:
       - glib calls stat() on an fd to check whether S_IFCHR is set, which is
         the case for virtio-serial on win32. Because of that, a one-time
         check to determine whether the channel is readable is done by making
         a call to PeekConsoleInput(), which reports the underlying handle is
         not a valid console handle, and thus we can never read from the
       - if one goes as far as to "trick" glib into thinking it is a normal
         file descripter, the buffering is done in such a way that data
         written to the output stream will subsequently result in that same
         data being read back as if it were input, causing an error loop.
         furthermore, a forced flush of the channel only moves the data into a
         secondary buffer managed by glib, so there's no way to prevent output
         from getting read back as input.
      The implementation here ties into the glib main loop by implementing a
      custom GSource that continually submits asynchronous/overlapped I/O to
      fill an GAChannel-managed read buffer, and tells glib to poll the
      corresponding event handle for a completion whenever there is no
      data/RPC in the read buffer to notify the main application about.
    • Michael Roth's avatar
      qemu-ga: fixes for win32 build of qemu-ga · d8ca685a
      Michael Roth authored
      Various stubs and #ifdefs to compile for Windows using mingw
      cross-build. Still has 1 linker error due to a dependency on the
      forthcoming win32 versions of the GAChannel/transport class.
    • Michael Roth's avatar
      qemu-ga: move channel/transport functionality into wrapper class · 125b310e
      Michael Roth authored
      This is mostly in preparation for the win32 port, which won't use
      GIO channels for reasons that will be made clearer later. Here the
      GAChannel class is just a loose wrapper around GIOChannel
      calls/callbacks, but we also roll in the logic/configuration for
      various channel types and managing unix socket connections, which makes
      the abstraction much more complete and further aids in the win32 port
      since isa-serial/unix-listen will not be supported initially.
      There's also a bit of refactoring in the main logic to consolidate the
      exit paths so we can do common cleanup for things like pid files, which
      weren't always cleaned up previously.
  11. 13 Jan, 2012 1 commit
  12. 12 Dec, 2011 1 commit
  13. 29 Aug, 2011 1 commit
  14. 21 Aug, 2011 2 commits
  15. 23 Jul, 2011 1 commit
  16. 21 Jul, 2011 2 commits
    • Michael Roth's avatar
      guest agent: add guest agent RPCs/commands · e3d4d252
      Michael Roth authored
      This adds the initial set of QMP/QAPI commands provided by the guest
      The input/output specification for these commands are documented in the
      Example usage:
          qemu -device virtio-serial \
               -chardev socket,path=/tmp/vs0.sock,server,nowait,id=qga0 \
               -device virtserialport,chardev=qga0,name=org.qemu.quest_agent.0
          echo "{'execute':'guest-info'}" | socat stdio unix-connect:/tmp/qga0.sock
          qemu-ga -m virtio-serial -p /dev/virtio-ports/org.qemu.guest_agent.0 \
                  -p /var/run/qemu-guest-agent.pid -d
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
      Signed-off-by: default avatarLuiz Capitulino <lcapitulino@gmail.com>
    • Michael Roth's avatar
      guest agent: qemu-ga daemon · 48ff7a62
      Michael Roth authored
      This is the actual guest daemon, it listens for requests over a
      virtio-serial/isa-serial/unix socket channel and routes them through
      to dispatch routines, and writes the results back to the channel in
      a manner similar to QMP.
      A shorthand invocation:
        qemu-ga -d
      Is equivalent to:
        qemu-ga -m virtio-serial -p /dev/virtio-ports/org.qemu.guest_agent.0 \
                -f /var/run/qemu-ga.pid -d
      Signed-off-by: default avatarMichael Roth <mdroth@linux.vnet.ibm.com>
      Signed-off-by: default avatarLuiz Capitulino <lcapitulino@gmail.com>