2 * Serving QEMU block devices via NBD
4 * Copyright (c) 2012 Red Hat, Inc.
6 * Author: Paolo Bonzini <pbonzini@redhat.com>
8 * This work is licensed under the terms of the GNU GPL, version 2 or
9 * later. See the COPYING file in the top-level directory.
12 #include "qemu/osdep.h"
13 #include "sysemu/blockdev.h"
14 #include "sysemu/block-backend.h"
15 #include "hw/block/block.h"
16 #include "qapi/error.h"
17 #include "qapi/clone-visitor.h"
18 #include "qapi/qapi-visit-block-export.h"
19 #include "qapi/qapi-commands-block-export.h"
20 #include "block/nbd.h"
21 #include "io/channel-socket.h"
22 #include "io/net-listener.h"
24 typedef struct NBDConn
{
25 QIOChannelSocket
*cioc
;
26 QLIST_ENTRY(NBDConn
) next
;
29 typedef struct NBDServerData
{
30 QIONetListener
*listener
;
31 QCryptoTLSCreds
*tlscreds
;
33 uint32_t max_connections
;
35 QLIST_HEAD(, NBDConn
) conns
;
38 static NBDServerData
*nbd_server
;
39 static int qemu_nbd_connections
= -1; /* Non-negative if this is qemu-nbd */
41 static void nbd_update_server_watch(NBDServerData
*s
);
43 void nbd_server_is_qemu_nbd(int max_connections
)
45 qemu_nbd_connections
= max_connections
;
48 bool nbd_server_is_running(void)
50 return nbd_server
|| qemu_nbd_connections
>= 0;
53 int nbd_server_max_connections(void)
55 return nbd_server
? nbd_server
->max_connections
: qemu_nbd_connections
;
58 static void nbd_blockdev_client_closed(NBDClient
*client
, bool ignored
)
60 NBDConn
*conn
= nbd_client_owner(client
);
62 assert(qemu_in_main_thread() && nbd_server
);
64 object_unref(OBJECT(conn
->cioc
));
65 QLIST_REMOVE(conn
, next
);
68 nbd_client_put(client
);
69 assert(nbd_server
->connections
> 0);
70 nbd_server
->connections
--;
71 nbd_update_server_watch(nbd_server
);
74 static void nbd_accept(QIONetListener
*listener
, QIOChannelSocket
*cioc
,
77 NBDConn
*conn
= g_new0(NBDConn
, 1);
79 assert(qemu_in_main_thread() && nbd_server
);
80 nbd_server
->connections
++;
81 object_ref(OBJECT(cioc
));
83 QLIST_INSERT_HEAD(&nbd_server
->conns
, conn
, next
);
84 nbd_update_server_watch(nbd_server
);
86 qio_channel_set_name(QIO_CHANNEL(cioc
), "nbd-server");
87 /* TODO - expose handshake timeout as QMP option */
88 nbd_client_new(cioc
, NBD_DEFAULT_HANDSHAKE_MAX_SECS
,
89 nbd_server
->tlscreds
, nbd_server
->tlsauthz
,
90 nbd_blockdev_client_closed
, conn
);
93 static void nbd_update_server_watch(NBDServerData
*s
)
96 if (!s
->max_connections
|| s
->connections
< s
->max_connections
) {
97 qio_net_listener_set_client_func(s
->listener
, nbd_accept
, NULL
,
100 qio_net_listener_set_client_func(s
->listener
, NULL
, NULL
, NULL
);
105 static void nbd_server_free(NBDServerData
*server
)
114 * Forcefully close the listener socket, and any clients that have
115 * not yet disconnected on their own.
117 qio_net_listener_disconnect(server
->listener
);
118 object_unref(OBJECT(server
->listener
));
119 server
->listener
= NULL
;
120 QLIST_FOREACH_SAFE(conn
, &server
->conns
, next
, tmp
) {
121 qio_channel_shutdown(QIO_CHANNEL(conn
->cioc
), QIO_CHANNEL_SHUTDOWN_BOTH
,
125 AIO_WAIT_WHILE_UNLOCKED(NULL
, server
->connections
> 0);
127 if (server
->tlscreds
) {
128 object_unref(OBJECT(server
->tlscreds
));
130 g_free(server
->tlsauthz
);
135 static QCryptoTLSCreds
*nbd_get_tls_creds(const char *id
, Error
**errp
)
138 QCryptoTLSCreds
*creds
;
140 obj
= object_resolve_path_component(
141 object_get_objects_root(), id
);
143 error_setg(errp
, "No TLS credentials with id '%s'",
147 creds
= (QCryptoTLSCreds
*)
148 object_dynamic_cast(obj
, TYPE_QCRYPTO_TLS_CREDS
);
150 error_setg(errp
, "Object with id '%s' is not TLS credentials",
155 if (!qcrypto_tls_creds_check_endpoint(creds
,
156 QCRYPTO_TLS_CREDS_ENDPOINT_SERVER
,
165 void nbd_server_start(SocketAddress
*addr
, const char *tls_creds
,
166 const char *tls_authz
, uint32_t max_connections
,
170 error_setg(errp
, "NBD server already running");
174 nbd_server
= g_new0(NBDServerData
, 1);
175 nbd_server
->max_connections
= max_connections
;
176 nbd_server
->listener
= qio_net_listener_new();
178 qio_net_listener_set_name(nbd_server
->listener
,
182 * Because this server is persistent, a backlog of SOMAXCONN is
183 * better than trying to size it to max_connections.
185 if (qio_net_listener_open_sync(nbd_server
->listener
, addr
, SOMAXCONN
,
191 nbd_server
->tlscreds
= nbd_get_tls_creds(tls_creds
, errp
);
192 if (!nbd_server
->tlscreds
) {
197 nbd_server
->tlsauthz
= g_strdup(tls_authz
);
199 nbd_update_server_watch(nbd_server
);
204 nbd_server_free(nbd_server
);
208 void nbd_server_start_options(NbdServerOptions
*arg
, Error
**errp
)
210 if (!arg
->has_max_connections
) {
211 arg
->max_connections
= NBD_DEFAULT_MAX_CONNECTIONS
;
214 nbd_server_start(arg
->addr
, arg
->tls_creds
, arg
->tls_authz
,
215 arg
->max_connections
, errp
);
218 void qmp_nbd_server_start(SocketAddressLegacy
*addr
,
219 const char *tls_creds
,
220 const char *tls_authz
,
221 bool has_max_connections
, uint32_t max_connections
,
224 SocketAddress
*addr_flat
= socket_address_flatten(addr
);
226 if (!has_max_connections
) {
227 max_connections
= NBD_DEFAULT_MAX_CONNECTIONS
;
230 nbd_server_start(addr_flat
, tls_creds
, tls_authz
, max_connections
, errp
);
231 qapi_free_SocketAddress(addr_flat
);
234 void qmp_nbd_server_add(NbdServerAddOptions
*arg
, Error
**errp
)
237 BlockDriverState
*bs
;
238 BlockBackend
*on_eject_blk
;
239 BlockExportOptions
*export_opts
;
241 bs
= bdrv_lookup_bs(arg
->device
, arg
->device
, errp
);
247 * block-export-add would default to the node-name, but we may have to use
248 * the device name as a default here for compatibility.
251 arg
->name
= g_strdup(arg
->device
);
254 export_opts
= g_new(BlockExportOptions
, 1);
255 *export_opts
= (BlockExportOptions
) {
256 .type
= BLOCK_EXPORT_TYPE_NBD
,
257 .id
= g_strdup(arg
->name
),
258 .node_name
= g_strdup(bdrv_get_node_name(bs
)),
259 .has_writable
= arg
->has_writable
,
260 .writable
= arg
->writable
,
262 QAPI_CLONE_MEMBERS(BlockExportOptionsNbdBase
, &export_opts
->u
.nbd
,
263 qapi_NbdServerAddOptions_base(arg
));
265 BlockDirtyBitmapOrStr
*el
= g_new(BlockDirtyBitmapOrStr
, 1);
267 *el
= (BlockDirtyBitmapOrStr
) {
268 .type
= QTYPE_QSTRING
,
269 .u
.local
= g_strdup(arg
->bitmap
),
271 export_opts
->u
.nbd
.has_bitmaps
= true;
272 QAPI_LIST_PREPEND(export_opts
->u
.nbd
.bitmaps
, el
);
276 * nbd-server-add doesn't complain when a read-only device should be
277 * exported as writable, but simply downgrades it. This is an error with
280 if (bdrv_is_read_only(bs
)) {
281 export_opts
->has_writable
= true;
282 export_opts
->writable
= false;
285 export
= blk_exp_add(export_opts
, errp
);
291 * nbd-server-add removes the export when the named BlockBackend used for
294 on_eject_blk
= blk_by_name(arg
->device
);
296 nbd_export_set_on_eject_blk(export
, on_eject_blk
);
300 qapi_free_BlockExportOptions(export_opts
);
303 void qmp_nbd_server_remove(const char *name
,
304 bool has_mode
, BlockExportRemoveMode mode
,
309 exp
= blk_exp_find(name
);
310 if (exp
&& exp
->drv
->type
!= BLOCK_EXPORT_TYPE_NBD
) {
311 error_setg(errp
, "Block export '%s' is not an NBD export", name
);
315 qmp_block_export_del(name
, has_mode
, mode
, errp
);
318 void qmp_nbd_server_stop(Error
**errp
)
321 error_setg(errp
, "NBD server not running");
325 blk_exp_close_all_type(BLOCK_EXPORT_TYPE_NBD
);
327 nbd_server_free(nbd_server
);