2 * Serving QEMU block devices via NBD
4 * Copyright (c) 2012 Red Hat, Inc.
6 * Author: Paolo Bonzini <pbonzini@redhat.com>
8 * This work is licensed under the terms of the GNU GPL, version 2 or
9 * later. See the COPYING file in the top-level directory.
12 #include "qemu/osdep.h"
13 #include "sysemu/blockdev.h"
14 #include "sysemu/block-backend.h"
15 #include "hw/block/block.h"
16 #include "qapi/error.h"
17 #include "qapi/qapi-commands-block-export.h"
18 #include "block/nbd.h"
19 #include "io/channel-socket.h"
20 #include "io/net-listener.h"
22 typedef struct NBDServerData
{
23 QIONetListener
*listener
;
24 QCryptoTLSCreds
*tlscreds
;
26 uint32_t max_connections
;
30 static NBDServerData
*nbd_server
;
31 static bool is_qemu_nbd
;
33 static void nbd_update_server_watch(NBDServerData
*s
);
35 void nbd_server_is_qemu_nbd(bool value
)
40 static void nbd_blockdev_client_closed(NBDClient
*client
, bool ignored
)
42 nbd_client_put(client
);
43 assert(nbd_server
->connections
> 0);
44 nbd_server
->connections
--;
45 nbd_update_server_watch(nbd_server
);
48 static void nbd_accept(QIONetListener
*listener
, QIOChannelSocket
*cioc
,
51 nbd_server
->connections
++;
52 nbd_update_server_watch(nbd_server
);
54 qio_channel_set_name(QIO_CHANNEL(cioc
), "nbd-server");
55 nbd_client_new(cioc
, nbd_server
->tlscreds
, nbd_server
->tlsauthz
,
56 nbd_blockdev_client_closed
);
59 static void nbd_update_server_watch(NBDServerData
*s
)
61 if (!s
->max_connections
|| s
->connections
< s
->max_connections
) {
62 qio_net_listener_set_client_func(s
->listener
, nbd_accept
, NULL
, NULL
);
64 qio_net_listener_set_client_func(s
->listener
, NULL
, NULL
, NULL
);
68 static void nbd_server_free(NBDServerData
*server
)
74 qio_net_listener_disconnect(server
->listener
);
75 object_unref(OBJECT(server
->listener
));
76 if (server
->tlscreds
) {
77 object_unref(OBJECT(server
->tlscreds
));
79 g_free(server
->tlsauthz
);
84 static QCryptoTLSCreds
*nbd_get_tls_creds(const char *id
, Error
**errp
)
87 QCryptoTLSCreds
*creds
;
89 obj
= object_resolve_path_component(
90 object_get_objects_root(), id
);
92 error_setg(errp
, "No TLS credentials with id '%s'",
96 creds
= (QCryptoTLSCreds
*)
97 object_dynamic_cast(obj
, TYPE_QCRYPTO_TLS_CREDS
);
99 error_setg(errp
, "Object with id '%s' is not TLS credentials",
104 if (creds
->endpoint
!= QCRYPTO_TLS_CREDS_ENDPOINT_SERVER
) {
106 "Expecting TLS credentials with a server endpoint");
114 void nbd_server_start(SocketAddress
*addr
, const char *tls_creds
,
115 const char *tls_authz
, uint32_t max_connections
,
119 error_setg(errp
, "NBD server already running");
123 nbd_server
= g_new0(NBDServerData
, 1);
124 nbd_server
->max_connections
= max_connections
;
125 nbd_server
->listener
= qio_net_listener_new();
127 qio_net_listener_set_name(nbd_server
->listener
,
130 if (qio_net_listener_open_sync(nbd_server
->listener
, addr
, 1, errp
) < 0) {
135 nbd_server
->tlscreds
= nbd_get_tls_creds(tls_creds
, errp
);
136 if (!nbd_server
->tlscreds
) {
140 /* TODO SOCKET_ADDRESS_TYPE_FD where fd has AF_INET or AF_INET6 */
141 if (addr
->type
!= SOCKET_ADDRESS_TYPE_INET
) {
142 error_setg(errp
, "TLS is only supported with IPv4/IPv6");
147 nbd_server
->tlsauthz
= g_strdup(tls_authz
);
149 nbd_update_server_watch(nbd_server
);
154 nbd_server_free(nbd_server
);
158 void nbd_server_start_options(NbdServerOptions
*arg
, Error
**errp
)
160 nbd_server_start(arg
->addr
, arg
->tls_creds
, arg
->tls_authz
,
161 arg
->max_connections
, errp
);
164 void qmp_nbd_server_start(SocketAddressLegacy
*addr
,
165 bool has_tls_creds
, const char *tls_creds
,
166 bool has_tls_authz
, const char *tls_authz
,
167 bool has_max_connections
, uint32_t max_connections
,
170 SocketAddress
*addr_flat
= socket_address_flatten(addr
);
172 nbd_server_start(addr_flat
, tls_creds
, tls_authz
, max_connections
, errp
);
173 qapi_free_SocketAddress(addr_flat
);
176 int nbd_export_create(BlockExport
*exp
, BlockExportOptions
*exp_args
,
179 BlockExportOptionsNbd
*arg
= &exp_args
->u
.nbd
;
180 BlockDriverState
*bs
= NULL
;
181 AioContext
*aio_context
;
184 assert(exp_args
->type
== BLOCK_EXPORT_TYPE_NBD
);
186 if (!nbd_server
&& !is_qemu_nbd
) {
187 error_setg(errp
, "NBD server not running");
191 if (!arg
->has_name
) {
192 arg
->name
= exp_args
->node_name
;
195 if (strlen(arg
->name
) > NBD_MAX_STRING_SIZE
) {
196 error_setg(errp
, "export name '%s' too long", arg
->name
);
200 if (arg
->description
&& strlen(arg
->description
) > NBD_MAX_STRING_SIZE
) {
201 error_setg(errp
, "description '%s' too long", arg
->description
);
205 if (nbd_export_find(arg
->name
)) {
206 error_setg(errp
, "NBD server already has export named '%s'", arg
->name
);
210 bs
= bdrv_lookup_bs(NULL
, exp_args
->node_name
, errp
);
215 aio_context
= bdrv_get_aio_context(bs
);
216 aio_context_acquire(aio_context
);
218 if (!arg
->has_writable
) {
219 arg
->writable
= false;
221 if (bdrv_is_read_only(bs
) && arg
->writable
) {
223 error_setg(errp
, "Cannot export read-only node as writable");
227 if (!exp_args
->has_writethrough
) {
228 exp_args
->writethrough
= false;
231 ret
= nbd_export_new(exp
, bs
, arg
->name
, arg
->description
, arg
->bitmap
,
232 !arg
->writable
, !arg
->writable
,
233 exp_args
->writethrough
, errp
);
238 /* The list of named exports has a strong reference to this export now and
239 * our only way of accessing it is through nbd_export_find(), so we can drop
240 * the strong reference that is @exp. */
245 aio_context_release(aio_context
);
249 void qmp_nbd_server_add(NbdServerAddOptions
*arg
, Error
**errp
)
252 BlockDriverState
*bs
;
253 BlockBackend
*on_eject_blk
;
254 BlockExportOptions
*export_opts
;
256 bs
= bdrv_lookup_bs(arg
->device
, arg
->device
, errp
);
262 * block-export-add would default to the node-name, but we may have to use
263 * the device name as a default here for compatibility.
265 if (!arg
->has_name
) {
266 arg
->name
= arg
->device
;
269 export_opts
= g_new(BlockExportOptions
, 1);
270 *export_opts
= (BlockExportOptions
) {
271 .type
= BLOCK_EXPORT_TYPE_NBD
,
272 .node_name
= g_strdup(bdrv_get_node_name(bs
)),
275 .name
= g_strdup(arg
->name
),
276 .has_description
= arg
->has_description
,
277 .description
= g_strdup(arg
->description
),
278 .has_writable
= arg
->has_writable
,
279 .writable
= arg
->writable
,
280 .has_bitmap
= arg
->has_bitmap
,
281 .bitmap
= g_strdup(arg
->bitmap
),
286 * nbd-server-add doesn't complain when a read-only device should be
287 * exported as writable, but simply downgrades it. This is an error with
290 if (bdrv_is_read_only(bs
)) {
291 export_opts
->u
.nbd
.has_writable
= true;
292 export_opts
->u
.nbd
.writable
= false;
295 export
= blk_exp_add(export_opts
, errp
);
301 * nbd-server-add removes the export when the named BlockBackend used for
304 on_eject_blk
= blk_by_name(arg
->device
);
306 nbd_export_set_on_eject_blk(export
, on_eject_blk
);
310 qapi_free_BlockExportOptions(export_opts
);
313 void qmp_nbd_server_remove(const char *name
,
314 bool has_mode
, NbdServerRemoveMode mode
,
318 AioContext
*aio_context
;
321 error_setg(errp
, "NBD server not running");
325 exp
= nbd_export_find(name
);
327 error_setg(errp
, "Export '%s' is not found", name
);
332 mode
= NBD_SERVER_REMOVE_MODE_SAFE
;
335 aio_context
= nbd_export_aio_context(exp
);
336 aio_context_acquire(aio_context
);
337 nbd_export_remove(exp
, mode
, errp
);
338 aio_context_release(aio_context
);
341 void qmp_nbd_server_stop(Error
**errp
)
344 error_setg(errp
, "NBD server not running");
348 nbd_export_close_all();
350 nbd_server_free(nbd_server
);