libvirt/src
Eric Blake 359f4b11a6 qemu: don't munge user input during block commit
While investigating https://bugzilla.redhat.com/show_bug.cgi?id=1061827
I noticed that we pass user input unscathed for block-pull, but
always pass a canonical absolute name through for block-commit.
[Note that we probably _ought_ to validate that the user's request
for block-pull actually matches the backing chain, the way we already
do for block-commit - but that's a separate issue.  Further note that
the ability to pass user input through unscathed allows backdoors
such as specifying a backing image that is a network URI such as
a gluster disk, instead of forcing things to the local file system;
which is an area still under active investigation on whether libvirt
needs to behave differently for network disks.]

Since qemu may write the name that the user passed in as the backing
file, a user may have a reason to want a relative file name passed
through to qemu, and always munging things to absolute prevents that.

Put another way, if you have the backing chain:

[A] <- [B(back=./A)] <- [C(back=./B)]

and commit B into A (virsh blockcommit $dom vda --base A --top B),
the metadata of C will have to be re-written. But should it be
rewritten as [C(back=./A)] or as [C(back=/path/to/A)]?  Still up in
the air is whether qemu's decision should be based on whether B
and/or C had relative paths, or on whether the --base and/or
--top arguments to the command were relative paths; but if we always
pass a canonical name, we've prevented the spelling of the command
arguments from being part of the hueristics that qemu uses.

I also audited the code, and verified that we never call
qemuMonitorBlockCommit() with a NULL base, either before or after
the change to qemu_driver.c.

* src/qemu/qemu_driver.c (qemuDomainBlockCommit): Preserve user's
spelling, since absolute vs. relative matters to qemu.
* src/qemu/qemu_monitor.h (qemuMonitorBlockCommit): Base is never
null.
* src/qemu/qemu_monitor.c (qemuMonitorBlockCommit): Likewise.
* src/qemu/qemu_monitor_json.h (qemuMonitorJSONBlockCommit):
Likewise.
* src/qemu/qemu_monitor_json.c (qemuMonitorJSONBlockCommit):
Likewise.

Signed-off-by: Eric Blake <eblake@redhat.com>
2014-03-11 17:53:19 -06:00
..
access util: make it easier to grab only regular command exit 2014-03-03 12:40:32 -07:00
bhyve Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
conf Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
cpu qemu: Implement a stub cpuArchDriver.baseline() handler for arm 2014-03-03 11:06:25 -05:00
esx maint: align whitespaces with project conventions. 2014-01-20 14:35:08 +01:00
hyperv Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
interface Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
libxl libxl: support sexpr in native to XML conversion 2014-03-11 14:31:08 -06:00
locking Convert lock driver plugins to use new crypto APIs 2014-03-10 16:44:14 +00:00
lxc Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
network Remove many decls from bridge driver platform header 2014-03-11 11:01:51 +00:00
node_device Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
nwfilter src/nwfilter: Utilize more of VIR_(APPEND|INSERT|DELETE)_ELEMENT 2014-03-10 13:45:10 +01:00
openvz Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
parallels Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
phyp src/phyp: Utilize more of VIR_(APPEND|INSERT|DELETE)_ELEMENT 2014-03-10 13:45:10 +01:00
qemu qemu: don't munge user input during block commit 2014-03-11 17:53:19 -06:00
remote Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
rpc Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
secret Convert 'int i' to 'size_t i' in src/secret/ files 2013-07-10 17:40:14 +01:00
security virSecurityDACSetSecurityImageLabel: Unmark @def as unused 2014-03-11 11:18:06 +01:00
storage storage: Fix bugs in VIR_APPEND_ELEMENT series 2014-03-11 15:51:47 -04:00
test Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
uml Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
util iptables: don't log command probe failures 2014-03-11 17:43:47 -06:00
vbox event: move event filtering to daemon (regression fix) 2014-02-05 08:03:31 -07:00
vmware vmware: os x support is broken 2014-01-03 11:13:43 -07:00
vmx Support transient attribute on vmware disks 2013-12-17 14:24:49 -07:00
xen Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
xenapi Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
xenxs src/xenxs: Utilize more of VIR_(APPEND|INSERT|DELETE)_ELEMENT 2014-03-10 13:45:11 +01:00
check-aclperms.pl Fix naming of permission for detecting storage pools 2013-09-12 17:20:07 +01:00
check-aclrules.pl maint: fix line numbers in check-aclrules reports 2014-02-10 14:07:22 -07:00
check-driverimpls.pl Skip virNWFilterTechDriver when validating API naming 2013-05-09 17:09:59 +01:00
check-drivername.pl Extend previous check to validate driver struct field names 2013-04-24 10:59:53 +01:00
check-symfile.pl maint: use LGPL correctly 2013-05-20 14:03:48 -06:00
check-symsorting.pl maint: use LGPL correctly 2013-05-20 14:03:48 -06:00
datatypes.c Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
datatypes.h maint: improve VIR_ERR_INVALID_DOMAIN_SNAPSHOT usage 2014-01-09 14:47:02 -07:00
driver.c Add helper APIs to track if libvirtd or loadable modules have changed 2014-03-11 10:51:49 +00:00
driver.h bhyve: add a basic driver 2014-02-19 14:21:50 +00:00
dtrace2systemtap.pl
fdstream.c util: make it easier to grab only regular command exit 2014-03-03 12:40:32 -07:00
fdstream.h Allow the iohelper path to be customized by test programs 2013-05-10 19:57:18 +01:00
gnutls_1_0_compat.h maint: don't use config.h in .h files 2013-06-05 05:53:25 -06:00
internal.h virFork: give specific status on failure prior to exec 2014-03-03 12:40:31 -07:00
libvirt_atomic.syms maint: check all symfiles for sorting 2013-02-22 16:48:12 -07:00
libvirt_daemon.syms
libvirt_driver_modules.syms
libvirt_esx.syms maint: enforce private symbol section sorting 2013-02-20 08:27:03 -07:00
libvirt_gnutls.syms Add APIs to get at more client security data 2013-03-19 13:11:46 +00:00
libvirt_internal.h event: server RPC protocol tweaks for domain lifecycle events 2014-02-12 10:48:15 -07:00
libvirt_libssh2.syms maint: enforce private symbol section sorting 2013-02-20 08:27:03 -07:00
libvirt_linux.syms Add test for linuxNodeGetCPUStats 2014-01-27 11:04:02 +01:00
libvirt_lxc.syms Apply security label when entering LXC namespaces 2013-03-13 15:16:37 +00:00
libvirt_openvz.syms maint: enforce private symbol section sorting 2013-02-20 08:27:03 -07:00
libvirt_private.syms Add helper APIs to track if libvirtd or loadable modules have changed 2014-03-11 10:51:49 +00:00
libvirt_probes.d Re-add DTrace probes on 'dispose' functions 2013-03-14 12:42:21 +00:00
libvirt_public.syms Added Network events API and virNetworkEventLifecycle. 2013-12-11 13:10:41 +00:00
libvirt_qemu_probes.d
libvirt_qemu.syms
libvirt_remote.syms build: fix build --without-remote 2013-10-04 17:01:47 -06:00
libvirt_sasl.syms Add APIs to get at more client security data 2013-03-19 13:11:46 +00:00
libvirt_vmware.syms VMware: Make version parsing testable and add tests 2013-09-20 08:23:31 -05:00
libvirt_vmx.syms VMX: Create virVMXFormatDisk() from HD and CD-ROM 2013-09-01 23:11:50 -05:00
libvirt_xenxs.syms maint: enforce private symbol section sorting 2013-02-20 08:27:03 -07:00
libvirt-lxc.c add support for apparmor in lxc-enter-namespace 2014-03-04 11:15:47 +00:00
libvirt-qemu.c maint: improve VIR_ERR_INVALID_DOMAIN usage 2014-01-07 14:38:12 -07:00
libvirt.c util: make it easier to grab only regular command exit 2014-03-03 12:40:32 -07:00
libvirt.conf
lock_protocol-structs tests: check remaining .x files 2013-09-09 12:04:03 -06:00
lxc_monitor_protocol-structs tests: check remaining .x files 2013-09-09 12:04:03 -06:00
lxc_protocol-structs
Makefile.am Remove broken error reporting in QEMU mac filtering 2014-03-11 11:04:55 +00:00
nodeinfo.c BSD: implement nodeGetCPUStats 2014-02-06 14:09:15 +01:00
nodeinfo.h Change file names in comments to match the files they are in 2014-03-10 14:26:04 +01:00
nodeinfopriv.h Add test for linuxNodeGetCPUStats 2014-01-27 11:04:02 +01:00
qemu_protocol-structs Make naming of remote procedures match API names exactly 2013-04-24 10:33:10 +01:00
README bhyve: add basic documentation 2014-03-01 23:44:58 +04:00
remote_protocol-structs event: pass reason for PM events 2014-02-12 10:48:16 -07:00
virkeepaliveprotocol-structs
virnetprotocol-structs

       libvirt library code README
       ===========================

The directory provides the bulk of the libvirt codebase. Everything
except for the libvirtd daemon and client tools. The build uses a
large number of libtool convenience libraries - one for each child
directory, and then links them together for the final libvirt.so,
although some bits get linked directly to libvirtd daemon instead.

The files directly in this directory are supporting the public API
entry points & data structures.

There are two core shared modules to be aware of:

 * util/  - a collection of shared APIs that can be used by any
            code. This directory is always in the include path
            for all things built

 * conf/  - APIs for parsing / manipulating all the official XML
            files used by the public API. This directory is only
            in the include path for driver implementation modules

 * vmx/   - VMware VMX config handling (used by esx/ and vmware/)


Then there are the hypervisor implementations:

 * bhyve         - bhyve - The BSD Hypervisor
 * esx/          - VMware ESX and GSX support using vSphere API over SOAP
 * hyperv/       - Microsoft Hyper-V support using WinRM
 * lxc/          - Linux Native Containers
 * openvz/       - OpenVZ containers using cli tools
 * phyp/         - IBM Power Hypervisor using CLI tools over SSH
 * qemu/         - QEMU / KVM using qemu CLI/monitor
 * remote/       - Generic libvirt native RPC client
 * test/         - A "mock" driver for testing
 * uml/          - User Mode Linux
 * vbox/         - Virtual Box using native API
 * vmware/       - VMware Workstation and Player using the vmrun tool
 * xen/          - Xen using hypercalls, XenD SEXPR & XenStore
 * xenapi/       - Xen using libxenserver


Finally some secondary drivers that are shared for several HVs.
Currently these are used by LXC, OpenVZ, QEMU, UML and Xen drivers.
The ESX, Hyper-V, Power Hypervisor, Remote, Test & VirtualBox drivers all
implement the secondary drivers directly

 * cpu/          - CPU feature management
 * interface/    - Host network interface management
 * network/      - Virtual NAT networking
 * nwfilter/     - Network traffic filtering rules
 * node_device/  - Host device enumeration
 * secret/       - Secret management
 * security/     - Mandatory access control drivers
 * storage/      - Storage management drivers


Since both the hypervisor and secondary drivers can be built as
dlopen()able modules, it is *FORBIDDEN* to have build dependencies
between these directories. Drivers are only allowed to depend on
the public API, and the internal APIs in the util/ and conf/
directories