qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: "Daniel P. Berrange" <berrange@redhat.com>
To: Eric Blake <eblake@redhat.com>
Cc: Markus Armbruster <armbru@redhat.com>,
	Luiz Capitulino <lcapitulino@redhat.com>,
	Gerd Hoffmann <kraxel@redhat.com>,
	Anthony Liguori <aliguori@amazon.com>,
	qemu-devel@nongnu.org
Subject: Re: [Qemu-devel] [PATCH v2 09/10] monitor: add query-vnc2 command
Date: Thu, 11 Dec 2014 09:40:46 +0000	[thread overview]
Message-ID: <20141211094046.GA23831@redhat.com> (raw)
In-Reply-To: <54887A35.3070801@redhat.com>

On Wed, Dec 10, 2014 at 09:52:05AM -0700, Eric Blake wrote:
> On 12/10/2014 02:37 AM, Gerd Hoffmann wrote:
> > Add new query vnc qmp command, for the lack of better ideas just name it
> > "query-vnc2".  Changes over query-vnc:
> > 
> >  * It returns a list of vnc servers, so multiple vnc server instances
> >    are covered.
> >  * Each vnc server returns a list of server sockets.  Followup patch
> >    will use that to also report websockets.  In case we add support for
> >    multiple server sockets server sockets (to better support ipv4+ipv6
> >    dualstack) we can add them to the list too.
> > 
> > Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
> > ---
> 
> > +# @VncInfo2:
> > +#
> > +# Information about a vnc server
> > +#
> > +# @id: vnc server name.
> > +#
> > +# @server: A list of @VncBasincInfo describing all listening sockets.
> > +#          The list can be empty (in case the vnc server is disabled).
> > +#          It also may have multiple entries: normal + websocket,
> > +#          possibly also ipv4 + ipv6 in the future.
> > +#
> > +# @clients: A list of @VncClientInfo of all currently connected clients.
> > +#           The list can be empty, for obvious reasons.
> 
> Seems okay.
> 
> > +#
> > +# @auth: The current authentication type used by the server
> > +#        'none' if no authentication is being used
> > +#        'vnc' if VNC authentication is being used
> > +#        'vencrypt+plain' if VEncrypt is used with plain text authentication
> > +#        'vencrypt+tls+none' if VEncrypt is used with TLS and no authentication
> > +#        'vencrypt+tls+vnc' if VEncrypt is used with TLS and VNC authentication
> > +#        'vencrypt+tls+plain' if VEncrypt is used with TLS and plain text auth
> > +#        'vencrypt+x509+none' if VEncrypt is used with x509 and no auth
> > +#        'vencrypt+x509+vnc' if VEncrypt is used with x509 and VNC auth
> > +#        'vencrypt+x509+plain' if VEncrypt is used with x509 and plain text auth
> > +#        'vencrypt+tls+sasl' if VEncrypt is used with TLS and SASL auth
> > +#        'vencrypt+x509+sasl' if VEncrypt is used with x509 and SASL auth
> 
> This feels like an open-coded string that should instead be an array of
> enum values.  That is,
> 
> { 'enum': 'VncAuth', 'data', [ 'none', 'vnc', 'vencrypt', 'plain',
> 'tls', 'x509' ] }
> ... 'auth': ['VcnAuth']
> 
> might be friendlier to applications (having to post-parse the '+' is not
> friendly).

That's not a correct interpretation of the auth values - tls and x509 are
not separate auth codes. VNC has one set of primary auth codes really

  none, vnc, vencrypt

If using the vencrypt option there are a number of sub-auth codes

   tls-none, tls-vnc, tls-plain, tls-sasl x509-none, x509-vnc, x509-plain, x509-sasl

Regards,
Daniel
-- 
|: http://berrange.com      -o-    http://www.flickr.com/photos/dberrange/ :|
|: http://libvirt.org              -o-             http://virt-manager.org :|
|: http://autobuild.org       -o-         http://search.cpan.org/~danberr/ :|
|: http://entangle-photo.org       -o-       http://live.gnome.org/gtk-vnc :|

  parent reply	other threads:[~2014-12-11  9:41 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-12-10  9:37 [Qemu-devel] [PATCH v2 00/10] vnc: add support for multiple vnc displays Gerd Hoffmann
2014-12-10  9:37 ` [Qemu-devel] [PATCH v2 01/10] vnc: remove vnc_display global Gerd Hoffmann
2014-12-11  1:58   ` Gonglei
2014-12-10  9:37 ` [Qemu-devel] [PATCH v2 02/10] vnc: remove unused DisplayState parameter, add id instead Gerd Hoffmann
2014-12-11  1:59   ` Gonglei
2014-12-10  9:37 ` [Qemu-devel] [PATCH v2 03/10] vnc: add display id to acl names Gerd Hoffmann
2014-12-11  2:09   ` Gonglei
2014-12-10  9:37 ` [Qemu-devel] [PATCH v2 04/10] vnc: switch to QemuOpts, allow multiple servers Gerd Hoffmann
2014-12-11  2:59   ` Gonglei
2014-12-11  8:48     ` Gerd Hoffmann
2014-12-10  9:37 ` [Qemu-devel] [PATCH v2 05/10] vnc: allow binding servers to qemu consoles Gerd Hoffmann
2014-12-10  9:37 ` [Qemu-devel] [PATCH v2 06/10] vnc: update docs/multiseat.txt Gerd Hoffmann
2014-12-10  9:37 ` [Qemu-devel] [PATCH v2 07/10] vnc: track & limit connections Gerd Hoffmann
2014-12-10  9:37 ` [Qemu-devel] [PATCH v2 08/10] vnc: factor out qmp_query_client_list Gerd Hoffmann
2014-12-10  9:37 ` [Qemu-devel] [PATCH v2 09/10] monitor: add query-vnc2 command Gerd Hoffmann
2014-12-10 16:52   ` Eric Blake
2014-12-11  9:07     ` Gerd Hoffmann
2014-12-11  9:43       ` Daniel P. Berrange
2014-12-11  9:40     ` Daniel P. Berrange [this message]
2014-12-11 11:33       ` Gerd Hoffmann
2014-12-11 11:47         ` Daniel P. Berrange
2014-12-15  9:16           ` Gerd Hoffmann
2014-12-15  9:26             ` Daniel P. Berrange
2014-12-15 16:22             ` Eric Blake
2014-12-16 10:18               ` Gerd Hoffmann
2014-12-16 16:13                 ` Eric Blake
2014-12-10  9:37 ` [Qemu-devel] [PATCH v2 10/10] monitor: add vnc websockets Gerd Hoffmann
2014-12-10 16:54   ` Eric Blake
2014-12-11  9:08     ` Gerd Hoffmann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20141211094046.GA23831@redhat.com \
    --to=berrange@redhat.com \
    --cc=aliguori@amazon.com \
    --cc=armbru@redhat.com \
    --cc=eblake@redhat.com \
    --cc=kraxel@redhat.com \
    --cc=lcapitulino@redhat.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).