diff --git a/src/qemu/qemu.conf b/src/qemu/qemu.conf index 0f0a24c20e..e7c300bf8f 100644 --- a/src/qemu/qemu.conf +++ b/src/qemu/qemu.conf @@ -409,3 +409,14 @@ # Defaults to -1. # #seccomp_sandbox = 1 + + +# Override the port range used for incoming migrations. +# +# Minimum must be greater than 0, however when QEMU is not running as root, +# setting the minimum to be lower than 1024 will not work. +# +# Maximum must not be greater than 65535. +# +#migration_port_min = 49152 +#migration_port_max = 49215 diff --git a/src/qemu/qemu_conf.c b/src/qemu/qemu_conf.c index 7c3f317cf0..1c8351f294 100644 --- a/src/qemu/qemu_conf.c +++ b/src/qemu/qemu_conf.c @@ -228,6 +228,9 @@ virQEMUDriverConfigPtr virQEMUDriverConfigNew(bool privileged) cfg->remotePortMin = QEMU_REMOTE_PORT_MIN; cfg->remotePortMax = QEMU_REMOTE_PORT_MAX; + cfg->migrationPortMin = QEMU_MIGRATION_PORT_MIN; + cfg->migrationPortMax = QEMU_MIGRATION_PORT_MAX; + #if defined HAVE_MNTENT_H && defined HAVE_GETMNTENT_R /* For privileged driver, try and find hugepage mount automatically. * Non-privileged driver requires admin to create a dir for the @@ -433,6 +436,24 @@ int virQEMUDriverConfigLoadFile(virQEMUDriverConfigPtr cfg, goto cleanup; } + GET_VALUE_LONG("migration_port_min", cfg->migrationPortMin); + if (cfg->migrationPortMin <= 0) { + virReportError(VIR_ERR_INTERNAL_ERROR, + _("%s: migration_port_min: port must be greater than 0"), + filename); + goto cleanup; + } + + GET_VALUE_LONG("migration_port_max", cfg->migrationPortMax); + if (cfg->migrationPortMax > 65535 || + cfg->migrationPortMax < cfg->migrationPortMin) { + virReportError(VIR_ERR_INTERNAL_ERROR, + _("%s: migration_port_max: port must be between " + "the minimal port %d and 65535"), + filename, cfg->migrationPortMin); + goto cleanup; + } + p = virConfGetValue(conf, "user"); CHECK_TYPE("user", VIR_CONF_STRING); if (p && p->str && diff --git a/src/qemu/qemu_conf.h b/src/qemu/qemu_conf.h index 47fbef8f42..a91d2a5873 100644 --- a/src/qemu/qemu_conf.h +++ b/src/qemu/qemu_conf.h @@ -148,6 +148,9 @@ struct _virQEMUDriverConfig { unsigned int keepAliveCount; int seccompSandbox; + + int migrationPortMin; + int migrationPortMax; }; /* Main driver state */ diff --git a/src/qemu/qemu_driver.c b/src/qemu/qemu_driver.c index 777c6be3b9..21fed47ab7 100644 --- a/src/qemu/qemu_driver.c +++ b/src/qemu/qemu_driver.c @@ -663,8 +663,8 @@ qemuStateInitialize(bool privileged, goto error; if ((qemu_driver->migrationPorts = - virPortAllocatorNew(QEMU_MIGRATION_PORT_MIN, - QEMU_MIGRATION_PORT_MAX)) == NULL) + virPortAllocatorNew(cfg->migrationPortMin, + cfg->migrationPortMax)) == NULL) goto error; if (qemuSecurityInit(qemu_driver) < 0) diff --git a/src/qemu/test_libvirtd_qemu.aug.in b/src/qemu/test_libvirtd_qemu.aug.in index 26ca0688d8..d57b3b48c4 100644 --- a/src/qemu/test_libvirtd_qemu.aug.in +++ b/src/qemu/test_libvirtd_qemu.aug.in @@ -63,3 +63,5 @@ module Test_libvirtd_qemu = { "keepalive_interval" = "5" } { "keepalive_count" = "5" } { "seccomp_sandbox" = "1" } +{ "migration_port_min" = "1234" } +{ "migration_port_max" = "12345" }