nbd: Add max-connections to nbd-server-start
[qemu.git] / blockdev-nbd.c
1 /*
2 * Serving QEMU block devices via NBD
3 *
4 * Copyright (c) 2012 Red Hat, Inc.
5 *
6 * Author: Paolo Bonzini <pbonzini@redhat.com>
7 *
8 * This work is licensed under the terms of the GNU GPL, version 2 or
9 * later. See the COPYING file in the top-level directory.
10 */
11
12 #include "qemu/osdep.h"
13 #include "sysemu/blockdev.h"
14 #include "sysemu/block-backend.h"
15 #include "hw/block/block.h"
16 #include "qapi/error.h"
17 #include "qapi/qapi-commands-block-export.h"
18 #include "block/nbd.h"
19 #include "io/channel-socket.h"
20 #include "io/net-listener.h"
21
22 typedef struct NBDServerData {
23 QIONetListener *listener;
24 QCryptoTLSCreds *tlscreds;
25 char *tlsauthz;
26 uint32_t max_connections;
27 uint32_t connections;
28 } NBDServerData;
29
30 static NBDServerData *nbd_server;
31
32 static void nbd_update_server_watch(NBDServerData *s);
33
34 static void nbd_blockdev_client_closed(NBDClient *client, bool ignored)
35 {
36 nbd_client_put(client);
37 assert(nbd_server->connections > 0);
38 nbd_server->connections--;
39 nbd_update_server_watch(nbd_server);
40 }
41
42 static void nbd_accept(QIONetListener *listener, QIOChannelSocket *cioc,
43 gpointer opaque)
44 {
45 nbd_server->connections++;
46 nbd_update_server_watch(nbd_server);
47
48 qio_channel_set_name(QIO_CHANNEL(cioc), "nbd-server");
49 nbd_client_new(cioc, nbd_server->tlscreds, nbd_server->tlsauthz,
50 nbd_blockdev_client_closed);
51 }
52
53 static void nbd_update_server_watch(NBDServerData *s)
54 {
55 if (!s->max_connections || s->connections < s->max_connections) {
56 qio_net_listener_set_client_func(s->listener, nbd_accept, NULL, NULL);
57 } else {
58 qio_net_listener_set_client_func(s->listener, NULL, NULL, NULL);
59 }
60 }
61
62 static void nbd_server_free(NBDServerData *server)
63 {
64 if (!server) {
65 return;
66 }
67
68 qio_net_listener_disconnect(server->listener);
69 object_unref(OBJECT(server->listener));
70 if (server->tlscreds) {
71 object_unref(OBJECT(server->tlscreds));
72 }
73 g_free(server->tlsauthz);
74
75 g_free(server);
76 }
77
78 static QCryptoTLSCreds *nbd_get_tls_creds(const char *id, Error **errp)
79 {
80 Object *obj;
81 QCryptoTLSCreds *creds;
82
83 obj = object_resolve_path_component(
84 object_get_objects_root(), id);
85 if (!obj) {
86 error_setg(errp, "No TLS credentials with id '%s'",
87 id);
88 return NULL;
89 }
90 creds = (QCryptoTLSCreds *)
91 object_dynamic_cast(obj, TYPE_QCRYPTO_TLS_CREDS);
92 if (!creds) {
93 error_setg(errp, "Object with id '%s' is not TLS credentials",
94 id);
95 return NULL;
96 }
97
98 if (creds->endpoint != QCRYPTO_TLS_CREDS_ENDPOINT_SERVER) {
99 error_setg(errp,
100 "Expecting TLS credentials with a server endpoint");
101 return NULL;
102 }
103 object_ref(obj);
104 return creds;
105 }
106
107
108 void nbd_server_start(SocketAddress *addr, const char *tls_creds,
109 const char *tls_authz, uint32_t max_connections,
110 Error **errp)
111 {
112 if (nbd_server) {
113 error_setg(errp, "NBD server already running");
114 return;
115 }
116
117 nbd_server = g_new0(NBDServerData, 1);
118 nbd_server->max_connections = max_connections;
119 nbd_server->listener = qio_net_listener_new();
120
121 qio_net_listener_set_name(nbd_server->listener,
122 "nbd-listener");
123
124 if (qio_net_listener_open_sync(nbd_server->listener, addr, 1, errp) < 0) {
125 goto error;
126 }
127
128 if (tls_creds) {
129 nbd_server->tlscreds = nbd_get_tls_creds(tls_creds, errp);
130 if (!nbd_server->tlscreds) {
131 goto error;
132 }
133
134 /* TODO SOCKET_ADDRESS_TYPE_FD where fd has AF_INET or AF_INET6 */
135 if (addr->type != SOCKET_ADDRESS_TYPE_INET) {
136 error_setg(errp, "TLS is only supported with IPv4/IPv6");
137 goto error;
138 }
139 }
140
141 nbd_server->tlsauthz = g_strdup(tls_authz);
142
143 nbd_update_server_watch(nbd_server);
144
145 return;
146
147 error:
148 nbd_server_free(nbd_server);
149 nbd_server = NULL;
150 }
151
152 void nbd_server_start_options(NbdServerOptions *arg, Error **errp)
153 {
154 nbd_server_start(arg->addr, arg->tls_creds, arg->tls_authz,
155 arg->max_connections, errp);
156 }
157
158 void qmp_nbd_server_start(SocketAddressLegacy *addr,
159 bool has_tls_creds, const char *tls_creds,
160 bool has_tls_authz, const char *tls_authz,
161 bool has_max_connections, uint32_t max_connections,
162 Error **errp)
163 {
164 SocketAddress *addr_flat = socket_address_flatten(addr);
165
166 nbd_server_start(addr_flat, tls_creds, tls_authz, max_connections, errp);
167 qapi_free_SocketAddress(addr_flat);
168 }
169
170 BlockExport *nbd_export_create(BlockExportOptions *exp_args, Error **errp)
171 {
172 BlockExportOptionsNbd *arg = &exp_args->u.nbd;
173 BlockDriverState *bs = NULL;
174 NBDExport *exp = NULL;
175 AioContext *aio_context;
176
177 assert(exp_args->type == BLOCK_EXPORT_TYPE_NBD);
178
179 if (!nbd_server) {
180 error_setg(errp, "NBD server not running");
181 return NULL;
182 }
183
184 if (!arg->has_name) {
185 arg->name = arg->device;
186 }
187
188 if (strlen(arg->name) > NBD_MAX_STRING_SIZE) {
189 error_setg(errp, "export name '%s' too long", arg->name);
190 return NULL;
191 }
192
193 if (arg->description && strlen(arg->description) > NBD_MAX_STRING_SIZE) {
194 error_setg(errp, "description '%s' too long", arg->description);
195 return NULL;
196 }
197
198 if (nbd_export_find(arg->name)) {
199 error_setg(errp, "NBD server already has export named '%s'", arg->name);
200 return NULL;
201 }
202
203 bs = bdrv_lookup_bs(arg->device, arg->device, errp);
204 if (!bs) {
205 return NULL;
206 }
207
208 aio_context = bdrv_get_aio_context(bs);
209 aio_context_acquire(aio_context);
210
211 if (!arg->has_writable) {
212 arg->writable = false;
213 }
214 if (bdrv_is_read_only(bs) && arg->writable) {
215 error_setg(errp, "Cannot export read-only node as writable");
216 goto out;
217 }
218
219 exp = nbd_export_new(bs, arg->name, arg->description, arg->bitmap,
220 !arg->writable, !arg->writable,
221 NULL, false, errp);
222 if (!exp) {
223 goto out;
224 }
225
226 /* The list of named exports has a strong reference to this export now and
227 * our only way of accessing it is through nbd_export_find(), so we can drop
228 * the strong reference that is @exp. */
229 nbd_export_put(exp);
230
231 out:
232 aio_context_release(aio_context);
233 /* TODO Remove the cast: nbd_export_new() will return a BlockExport. */
234 return (BlockExport*) exp;
235 }
236
237 void qmp_nbd_server_add(BlockExportOptionsNbd *arg, Error **errp)
238 {
239 BlockExport *export;
240 BlockDriverState *bs;
241 BlockBackend *on_eject_blk;
242 BlockExportOptions export_opts;
243
244 bs = bdrv_lookup_bs(arg->device, arg->device, errp);
245 if (!bs) {
246 return;
247 }
248
249 export_opts = (BlockExportOptions) {
250 .type = BLOCK_EXPORT_TYPE_NBD,
251 .u.nbd = *arg,
252 };
253
254 /*
255 * nbd-server-add doesn't complain when a read-only device should be
256 * exported as writable, but simply downgrades it. This is an error with
257 * block-export-add.
258 */
259 if (bdrv_is_read_only(bs)) {
260 export_opts.u.nbd.has_writable = true;
261 export_opts.u.nbd.writable = false;
262 }
263
264 export = blk_exp_add(&export_opts, errp);
265 if (!export) {
266 return;
267 }
268
269 /*
270 * nbd-server-add removes the export when the named BlockBackend used for
271 * @device goes away.
272 */
273 on_eject_blk = blk_by_name(arg->device);
274 if (on_eject_blk) {
275 nbd_export_set_on_eject_blk(export, on_eject_blk);
276 }
277 }
278
279 void qmp_nbd_server_remove(const char *name,
280 bool has_mode, NbdServerRemoveMode mode,
281 Error **errp)
282 {
283 NBDExport *exp;
284 AioContext *aio_context;
285
286 if (!nbd_server) {
287 error_setg(errp, "NBD server not running");
288 return;
289 }
290
291 exp = nbd_export_find(name);
292 if (exp == NULL) {
293 error_setg(errp, "Export '%s' is not found", name);
294 return;
295 }
296
297 if (!has_mode) {
298 mode = NBD_SERVER_REMOVE_MODE_SAFE;
299 }
300
301 aio_context = nbd_export_aio_context(exp);
302 aio_context_acquire(aio_context);
303 nbd_export_remove(exp, mode, errp);
304 aio_context_release(aio_context);
305 }
306
307 void qmp_nbd_server_stop(Error **errp)
308 {
309 if (!nbd_server) {
310 error_setg(errp, "NBD server not running");
311 return;
312 }
313
314 nbd_export_close_all();
315
316 nbd_server_free(nbd_server);
317 nbd_server = NULL;
318 }