From: "Daniel P. Berrange" <berrange@redhat.com>
To: Eric Blake <eblake@redhat.com>
Cc: Markus Armbruster <armbru@redhat.com>,
Luiz Capitulino <lcapitulino@redhat.com>,
Gerd Hoffmann <kraxel@redhat.com>,
Anthony Liguori <aliguori@amazon.com>,
qemu-devel@nongnu.org
Subject: Re: [Qemu-devel] [PATCH v2 09/10] monitor: add query-vnc2 command
Date: Thu, 11 Dec 2014 09:40:46 +0000 [thread overview]
Message-ID: <20141211094046.GA23831@redhat.com> (raw)
In-Reply-To: <54887A35.3070801@redhat.com>
On Wed, Dec 10, 2014 at 09:52:05AM -0700, Eric Blake wrote:
> On 12/10/2014 02:37 AM, Gerd Hoffmann wrote:
> > Add new query vnc qmp command, for the lack of better ideas just name it
> > "query-vnc2". Changes over query-vnc:
> >
> > * It returns a list of vnc servers, so multiple vnc server instances
> > are covered.
> > * Each vnc server returns a list of server sockets. Followup patch
> > will use that to also report websockets. In case we add support for
> > multiple server sockets server sockets (to better support ipv4+ipv6
> > dualstack) we can add them to the list too.
> >
> > Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
> > ---
>
> > +# @VncInfo2:
> > +#
> > +# Information about a vnc server
> > +#
> > +# @id: vnc server name.
> > +#
> > +# @server: A list of @VncBasincInfo describing all listening sockets.
> > +# The list can be empty (in case the vnc server is disabled).
> > +# It also may have multiple entries: normal + websocket,
> > +# possibly also ipv4 + ipv6 in the future.
> > +#
> > +# @clients: A list of @VncClientInfo of all currently connected clients.
> > +# The list can be empty, for obvious reasons.
>
> Seems okay.
>
> > +#
> > +# @auth: The current authentication type used by the server
> > +# 'none' if no authentication is being used
> > +# 'vnc' if VNC authentication is being used
> > +# 'vencrypt+plain' if VEncrypt is used with plain text authentication
> > +# 'vencrypt+tls+none' if VEncrypt is used with TLS and no authentication
> > +# 'vencrypt+tls+vnc' if VEncrypt is used with TLS and VNC authentication
> > +# 'vencrypt+tls+plain' if VEncrypt is used with TLS and plain text auth
> > +# 'vencrypt+x509+none' if VEncrypt is used with x509 and no auth
> > +# 'vencrypt+x509+vnc' if VEncrypt is used with x509 and VNC auth
> > +# 'vencrypt+x509+plain' if VEncrypt is used with x509 and plain text auth
> > +# 'vencrypt+tls+sasl' if VEncrypt is used with TLS and SASL auth
> > +# 'vencrypt+x509+sasl' if VEncrypt is used with x509 and SASL auth
>
> This feels like an open-coded string that should instead be an array of
> enum values. That is,
>
> { 'enum': 'VncAuth', 'data', [ 'none', 'vnc', 'vencrypt', 'plain',
> 'tls', 'x509' ] }
> ... 'auth': ['VcnAuth']
>
> might be friendlier to applications (having to post-parse the '+' is not
> friendly).
That's not a correct interpretation of the auth values - tls and x509 are
not separate auth codes. VNC has one set of primary auth codes really
none, vnc, vencrypt
If using the vencrypt option there are a number of sub-auth codes
tls-none, tls-vnc, tls-plain, tls-sasl x509-none, x509-vnc, x509-plain, x509-sasl
Regards,
Daniel
--
|: http://berrange.com -o- http://www.flickr.com/photos/dberrange/ :|
|: http://libvirt.org -o- http://virt-manager.org :|
|: http://autobuild.org -o- http://search.cpan.org/~danberr/ :|
|: http://entangle-photo.org -o- http://live.gnome.org/gtk-vnc :|
next prev parent reply other threads:[~2014-12-11 9:41 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-12-10 9:37 [Qemu-devel] [PATCH v2 00/10] vnc: add support for multiple vnc displays Gerd Hoffmann
2014-12-10 9:37 ` [Qemu-devel] [PATCH v2 01/10] vnc: remove vnc_display global Gerd Hoffmann
2014-12-11 1:58 ` Gonglei
2014-12-10 9:37 ` [Qemu-devel] [PATCH v2 02/10] vnc: remove unused DisplayState parameter, add id instead Gerd Hoffmann
2014-12-11 1:59 ` Gonglei
2014-12-10 9:37 ` [Qemu-devel] [PATCH v2 03/10] vnc: add display id to acl names Gerd Hoffmann
2014-12-11 2:09 ` Gonglei
2014-12-10 9:37 ` [Qemu-devel] [PATCH v2 04/10] vnc: switch to QemuOpts, allow multiple servers Gerd Hoffmann
2014-12-11 2:59 ` Gonglei
2014-12-11 8:48 ` Gerd Hoffmann
2014-12-10 9:37 ` [Qemu-devel] [PATCH v2 05/10] vnc: allow binding servers to qemu consoles Gerd Hoffmann
2014-12-10 9:37 ` [Qemu-devel] [PATCH v2 06/10] vnc: update docs/multiseat.txt Gerd Hoffmann
2014-12-10 9:37 ` [Qemu-devel] [PATCH v2 07/10] vnc: track & limit connections Gerd Hoffmann
2014-12-10 9:37 ` [Qemu-devel] [PATCH v2 08/10] vnc: factor out qmp_query_client_list Gerd Hoffmann
2014-12-10 9:37 ` [Qemu-devel] [PATCH v2 09/10] monitor: add query-vnc2 command Gerd Hoffmann
2014-12-10 16:52 ` Eric Blake
2014-12-11 9:07 ` Gerd Hoffmann
2014-12-11 9:43 ` Daniel P. Berrange
2014-12-11 9:40 ` Daniel P. Berrange [this message]
2014-12-11 11:33 ` Gerd Hoffmann
2014-12-11 11:47 ` Daniel P. Berrange
2014-12-15 9:16 ` Gerd Hoffmann
2014-12-15 9:26 ` Daniel P. Berrange
2014-12-15 16:22 ` Eric Blake
2014-12-16 10:18 ` Gerd Hoffmann
2014-12-16 16:13 ` Eric Blake
2014-12-10 9:37 ` [Qemu-devel] [PATCH v2 10/10] monitor: add vnc websockets Gerd Hoffmann
2014-12-10 16:54 ` Eric Blake
2014-12-11 9:08 ` Gerd Hoffmann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20141211094046.GA23831@redhat.com \
--to=berrange@redhat.com \
--cc=aliguori@amazon.com \
--cc=armbru@redhat.com \
--cc=eblake@redhat.com \
--cc=kraxel@redhat.com \
--cc=lcapitulino@redhat.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).