From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1N6EIk-0001LN-8e for qemu-devel@nongnu.org; Thu, 05 Nov 2009 21:11:46 -0500 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1N6EIf-0001Dj-8h for qemu-devel@nongnu.org; Thu, 05 Nov 2009 21:11:45 -0500 Received: from [199.232.76.173] (port=48011 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1N6EIf-0001DX-4C for qemu-devel@nongnu.org; Thu, 05 Nov 2009 21:11:41 -0500 Received: from mx20.gnu.org ([199.232.41.8]:14558) by monty-python.gnu.org with esmtps (TLS-1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.60) (envelope-from ) id 1N6EIe-0000fr-Rn for qemu-devel@nongnu.org; Thu, 05 Nov 2009 21:11:40 -0500 Received: from mail2.shareable.org ([80.68.89.115]) by mx20.gnu.org with esmtp (Exim 4.60) (envelope-from ) id 1N6EIe-0006PI-7e for qemu-devel@nongnu.org; Thu, 05 Nov 2009 21:11:40 -0500 Date: Fri, 6 Nov 2009 02:11:39 +0000 From: Jamie Lokier Subject: Re: [Qemu-devel] [PATCH 0/4] net-bridge: rootless bridge support for qemu Message-ID: <20091106021139.GJ21630@shareable.org> References: <1257294485-27015-1-git-send-email-aliguori@us.ibm.com> <4AF2E247.3090409@redhat.com> <4AF2E7CE.8010506@us.ibm.com> <20091105151154.GF689@redhat.com> <4AF2EBBB.7070605@redhat.com> <4AF2F674.6080205@us.ibm.com> <4AF2FB52.2090305@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <4AF2FB52.2090305@redhat.com> List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Avi Kivity Cc: Mark McLoughlin , Anthony Liguori , Arnd Bergmann , Dustin Kirkland , Juan Quintela , qemu-devel@nongnu.org, Michael Tsirkin Avi Kivity wrote: > On 11/05/2009 05:59 PM, Anthony Liguori wrote: > >Avi Kivity wrote: > >>On 11/05/2009 05:11 PM, Daniel P. Berrange wrote: > >>>The main problem is that we've never really used the 'session' > >>>instances, > >>>since networking configs are rather limited to pretty much just SLIRP > >>>and people expect full bridging. I think this patch series you've > >>>done is invaluable and will let us finally make full use of the libvirt > >>>'session' instances for desktop virt, running everything unprivileged. > >>> > >> > >>What's to stop you from using the same idea to get a tap fd for the > >>unprivileged libvirtd instance? > > > >Why limit this to just libvirt based management tools? The helper has > >to live somewhere, why not have it live in qemu? > > > > Because anything special the management tools wants done (as simple as > remembering the interface name so it can collect statistics and > associate them with the guest) will render the helper unusable. The > helper is pure glue so it will be very hard to generalize. The management tool can provide it's own helper program to QEMU, which can communicate with the management tool... via a side channel, so the management tool as a whole can do anything it wants when QEMU requests the tap interface. Getting the interface name and inserting iptables/ebtables rules would be quite simple that way. -- Jamie