conf: Introduce <sandbox mode='chroot'/> for <filesystem><binary>

This adds a new XML element

<filesystem>
  <binary>
    <sandbox mode='chroot|namespace'/>
  </binary>
</filesystem>

This will be used by qemu virtiofs

Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
Signed-off-by: Cole Robinson <crobinso@redhat.com>
This commit is contained in:
Cole Robinson 2021-03-26 11:24:37 -04:00
parent 9c81d1ec11
commit f4c97327fb
6 changed files with 53 additions and 0 deletions

View File

@ -3236,6 +3236,7 @@ A directory on the host that can be accessed directly from the guest.
<driver type='virtiofs' queue='1024'/> <driver type='virtiofs' queue='1024'/>
<binary path='/usr/libexec/virtiofsd' xattr='on'> <binary path='/usr/libexec/virtiofsd' xattr='on'>
<cache mode='always'/> <cache mode='always'/>
<sandbox mode='namespace'/>
<lock posix='on' flock='on'/> <lock posix='on' flock='on'/>
</binary> </binary>
<source dir='/path'/> <source dir='/path'/>
@ -3360,6 +3361,11 @@ A directory on the host that can be accessed directly from the guest.
``cache`` element, possible ``mode`` values being ``none`` and ``always``. ``cache`` element, possible ``mode`` values being ``none`` and ``always``.
Locking can be controlled via the ``lock`` element - attributes ``posix`` and Locking can be controlled via the ``lock`` element - attributes ``posix`` and
``flock`` both accepting values ``on`` or ``off``. ( :since:`Since 6.2.0` ) ``flock`` both accepting values ``on`` or ``off``. ( :since:`Since 6.2.0` )
The sandboxing method used by virtiofsd can be configured with the ``sandbox``
element, possible ``mode`` values being ``namespace`` and
``chroot``, see the
`virtiofsd documentation <https://qemu.readthedocs.io/en/latest/tools/virtiofsd.html>`__
for more details. ( :since:`Since 7.2.0` )
``source`` ``source``
The resource on the host that is being accessed in the guest. The ``name`` The resource on the host that is being accessed in the guest. The ``name``
attribute must be used with ``type='template'``, and the ``dir`` attribute attribute must be used with ``type='template'``, and the ``dir`` attribute

View File

@ -2984,6 +2984,18 @@
</optional> </optional>
</element> </element>
</optional> </optional>
<optional>
<element name="sandbox">
<optional>
<attribute name="mode">
<choice>
<value>namespace</value>
<value>chroot</value>
</choice>
</attribute>
</optional>
</element>
</optional>
<optional> <optional>
<element name="lock"> <element name="lock">
<optional> <optional>

View File

@ -540,6 +540,13 @@ VIR_ENUM_IMPL(virDomainFSCacheMode,
"always", "always",
); );
VIR_ENUM_IMPL(virDomainFSSandboxMode,
VIR_DOMAIN_FS_SANDBOX_MODE_LAST,
"default",
"namespace",
"chroot",
);
VIR_ENUM_IMPL(virDomainNet, VIR_ENUM_IMPL(virDomainNet,
VIR_DOMAIN_NET_TYPE_LAST, VIR_DOMAIN_NET_TYPE_LAST,
@ -10114,6 +10121,7 @@ virDomainFSDefParseXML(virDomainXMLOption *xmlopt,
g_autofree char *binary = virXPathString("string(./binary/@path)", ctxt); g_autofree char *binary = virXPathString("string(./binary/@path)", ctxt);
g_autofree char *xattr = virXPathString("string(./binary/@xattr)", ctxt); g_autofree char *xattr = virXPathString("string(./binary/@xattr)", ctxt);
g_autofree char *cache = virXPathString("string(./binary/cache/@mode)", ctxt); g_autofree char *cache = virXPathString("string(./binary/cache/@mode)", ctxt);
g_autofree char *sandbox = virXPathString("string(./binary/sandbox/@mode)", ctxt);
g_autofree char *posix_lock = virXPathString("string(./binary/lock/@posix)", ctxt); g_autofree char *posix_lock = virXPathString("string(./binary/lock/@posix)", ctxt);
g_autofree char *flock = virXPathString("string(./binary/lock/@flock)", ctxt); g_autofree char *flock = virXPathString("string(./binary/lock/@flock)", ctxt);
int val; int val;
@ -10147,6 +10155,16 @@ virDomainFSDefParseXML(virDomainXMLOption *xmlopt,
def->cache = val; def->cache = val;
} }
if (sandbox) {
if ((val = virDomainFSSandboxModeTypeFromString(sandbox)) <= 0) {
virReportError(VIR_ERR_XML_ERROR,
_("cannot parse sandbox mode '%s' for virtiofs"),
sandbox);
goto error;
}
def->sandbox = val;
}
if (posix_lock) { if (posix_lock) {
if ((val = virTristateSwitchTypeFromString(posix_lock)) <= 0) { if ((val = virTristateSwitchTypeFromString(posix_lock)) <= 0) {
virReportError(VIR_ERR_CONFIG_UNSUPPORTED, virReportError(VIR_ERR_CONFIG_UNSUPPORTED,
@ -25176,6 +25194,11 @@ virDomainFSDefFormat(virBuffer *buf,
virDomainFSCacheModeTypeToString(def->cache)); virDomainFSCacheModeTypeToString(def->cache));
} }
if (def->sandbox != VIR_DOMAIN_FS_SANDBOX_MODE_DEFAULT) {
virBufferAsprintf(&binaryBuf, "<sandbox mode='%s'/>\n",
virDomainFSSandboxModeTypeToString(def->sandbox));
}
if (def->posix_lock != VIR_TRISTATE_SWITCH_ABSENT) { if (def->posix_lock != VIR_TRISTATE_SWITCH_ABSENT) {
virBufferAsprintf(&lockAttrBuf, " posix='%s'", virBufferAsprintf(&lockAttrBuf, " posix='%s'",
virTristateSwitchTypeToString(def->posix_lock)); virTristateSwitchTypeToString(def->posix_lock));

View File

@ -849,6 +849,14 @@ typedef enum {
VIR_DOMAIN_FS_CACHE_MODE_LAST VIR_DOMAIN_FS_CACHE_MODE_LAST
} virDomainFSCacheMode; } virDomainFSCacheMode;
typedef enum {
VIR_DOMAIN_FS_SANDBOX_MODE_DEFAULT = 0,
VIR_DOMAIN_FS_SANDBOX_MODE_NAMESPACE,
VIR_DOMAIN_FS_SANDBOX_MODE_CHROOT,
VIR_DOMAIN_FS_SANDBOX_MODE_LAST
} virDomainFSSandboxMode;
struct _virDomainFSDef { struct _virDomainFSDef {
int type; int type;
int fsdriver; /* enum virDomainFSDriverType */ int fsdriver; /* enum virDomainFSDriverType */
@ -874,6 +882,7 @@ struct _virDomainFSDef {
virDomainFSCacheMode cache; virDomainFSCacheMode cache;
virTristateSwitch posix_lock; virTristateSwitch posix_lock;
virTristateSwitch flock; virTristateSwitch flock;
virDomainFSSandboxMode sandbox;
virDomainVirtioOptions *virtio; virDomainVirtioOptions *virtio;
virObject *privateData; virObject *privateData;
}; };
@ -3797,6 +3806,7 @@ VIR_ENUM_DECL(virDomainFSAccessMode);
VIR_ENUM_DECL(virDomainFSWrpolicy); VIR_ENUM_DECL(virDomainFSWrpolicy);
VIR_ENUM_DECL(virDomainFSModel); VIR_ENUM_DECL(virDomainFSModel);
VIR_ENUM_DECL(virDomainFSCacheMode); VIR_ENUM_DECL(virDomainFSCacheMode);
VIR_ENUM_DECL(virDomainFSSandboxMode);
VIR_ENUM_DECL(virDomainNet); VIR_ENUM_DECL(virDomainNet);
VIR_ENUM_DECL(virDomainNetBackend); VIR_ENUM_DECL(virDomainNetBackend);
VIR_ENUM_DECL(virDomainNetVirtioTxMode); VIR_ENUM_DECL(virDomainNetVirtioTxMode);

View File

@ -415,6 +415,7 @@ virDomainFSDriverTypeToString;
virDomainFSIndexByName; virDomainFSIndexByName;
virDomainFSInsert; virDomainFSInsert;
virDomainFSRemove; virDomainFSRemove;
virDomainFSSandboxModeTypeToString;
virDomainFSTypeFromString; virDomainFSTypeFromString;
virDomainFSTypeToString; virDomainFSTypeToString;
virDomainFSWrpolicyTypeFromString; virDomainFSWrpolicyTypeFromString;

View File

@ -30,6 +30,7 @@
<driver type='virtiofs' queue='1024'/> <driver type='virtiofs' queue='1024'/>
<binary path='/usr/libexec/virtiofsd' xattr='on'> <binary path='/usr/libexec/virtiofsd' xattr='on'>
<cache mode='always'/> <cache mode='always'/>
<sandbox mode='chroot'/>
<lock posix='off' flock='off'/> <lock posix='off' flock='off'/>
</binary> </binary>
<source dir='/path'/> <source dir='/path'/>