migration: SCM_RIGHTS for QEMUFile

Define functions to put/get file descriptors to/from a QEMUFile, for qio
channels that support SCM_RIGHTS.  Maintain ordering such that
  put(A), put(fd), put(B)
followed by
  get(A), get(fd), get(B)
always succeeds.  Other get orderings may succeed but are not guaranteed.

Signed-off-by: Steve Sistare <steven.sistare@oracle.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/r/1736967650-129648-14-git-send-email-steven.sistare@oracle.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
This commit is contained in:
Steve Sistare 2025-01-15 11:00:39 -08:00 committed by Fabiano Rosas
parent 2862b6b924
commit b5779dc7cf
3 changed files with 84 additions and 4 deletions

View file

@ -37,6 +37,11 @@
#define IO_BUF_SIZE 32768
#define MAX_IOV_SIZE MIN_CONST(IOV_MAX, 64)
typedef struct FdEntry {
QTAILQ_ENTRY(FdEntry) entry;
int fd;
} FdEntry;
struct QEMUFile {
QIOChannel *ioc;
bool is_writable;
@ -51,6 +56,9 @@ struct QEMUFile {
int last_error;
Error *last_error_obj;
bool can_pass_fd;
QTAILQ_HEAD(, FdEntry) fds;
};
/*
@ -109,6 +117,8 @@ static QEMUFile *qemu_file_new_impl(QIOChannel *ioc, bool is_writable)
object_ref(ioc);
f->ioc = ioc;
f->is_writable = is_writable;
f->can_pass_fd = qio_channel_has_feature(ioc, QIO_CHANNEL_FEATURE_FD_PASS);
QTAILQ_INIT(&f->fds);
return f;
}
@ -310,6 +320,10 @@ static ssize_t coroutine_mixed_fn qemu_fill_buffer(QEMUFile *f)
int len;
int pending;
Error *local_error = NULL;
g_autofree int *fds = NULL;
size_t nfd = 0;
int **pfds = f->can_pass_fd ? &fds : NULL;
size_t *pnfd = f->can_pass_fd ? &nfd : NULL;
assert(!qemu_file_is_writable(f));
@ -325,10 +339,9 @@ static ssize_t coroutine_mixed_fn qemu_fill_buffer(QEMUFile *f)
}
do {
len = qio_channel_read(f->ioc,
(char *)f->buf + pending,
IO_BUF_SIZE - pending,
&local_error);
struct iovec iov = { f->buf + pending, IO_BUF_SIZE - pending };
len = qio_channel_readv_full(f->ioc, &iov, 1, pfds, pnfd, 0,
&local_error);
if (len == QIO_CHANNEL_ERR_BLOCK) {
if (qemu_in_coroutine()) {
qio_channel_yield(f->ioc, G_IO_IN);
@ -348,9 +361,66 @@ static ssize_t coroutine_mixed_fn qemu_fill_buffer(QEMUFile *f)
qemu_file_set_error_obj(f, len, local_error);
}
for (int i = 0; i < nfd; i++) {
FdEntry *fde = g_new0(FdEntry, 1);
fde->fd = fds[i];
QTAILQ_INSERT_TAIL(&f->fds, fde, entry);
}
return len;
}
int qemu_file_put_fd(QEMUFile *f, int fd)
{
int ret = 0;
QIOChannel *ioc = qemu_file_get_ioc(f);
Error *err = NULL;
struct iovec iov = { (void *)" ", 1 };
/*
* Send a dummy byte so qemu_fill_buffer on the receiving side does not
* fail with a len=0 error. Flush first to maintain ordering wrt other
* data.
*/
qemu_fflush(f);
if (qio_channel_writev_full(ioc, &iov, 1, &fd, 1, 0, &err) < 1) {
error_report_err(error_copy(err));
qemu_file_set_error_obj(f, -EIO, err);
ret = -1;
}
trace_qemu_file_put_fd(f->ioc->name, fd, ret);
return ret;
}
int qemu_file_get_fd(QEMUFile *f)
{
int fd = -1;
FdEntry *fde;
if (!f->can_pass_fd) {
Error *err = NULL;
error_setg(&err, "%s does not support fd passing", f->ioc->name);
error_report_err(error_copy(err));
qemu_file_set_error_obj(f, -EIO, err);
goto out;
}
/* Force the dummy byte and its fd passenger to appear. */
qemu_peek_byte(f, 0);
fde = QTAILQ_FIRST(&f->fds);
if (fde) {
qemu_get_byte(f); /* Drop the dummy byte */
fd = fde->fd;
QTAILQ_REMOVE(&f->fds, fde, entry);
g_free(fde);
}
out:
trace_qemu_file_get_fd(f->ioc->name, fd);
return fd;
}
/** Closes the file
*
* Returns negative error value if any error happened on previous operations or
@ -361,11 +431,17 @@ static ssize_t coroutine_mixed_fn qemu_fill_buffer(QEMUFile *f)
*/
int qemu_fclose(QEMUFile *f)
{
FdEntry *fde, *next;
int ret = qemu_fflush(f);
int ret2 = qio_channel_close(f->ioc, NULL);
if (ret >= 0) {
ret = ret2;
}
QTAILQ_FOREACH_SAFE(fde, &f->fds, entry, next) {
warn_report("qemu_fclose: received fd %d was never claimed", fde->fd);
close(fde->fd);
g_free(fde);
}
g_clear_pointer(&f->ioc, object_unref);
error_free(f->last_error_obj);
g_free(f);