From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:58846) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1UCeqt-0002yW-Md for qemu-devel@nongnu.org; Mon, 04 Mar 2013 18:31:29 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1UCeqs-000335-6z for qemu-devel@nongnu.org; Mon, 04 Mar 2013 18:31:27 -0500 Received: from mail-oa0-f42.google.com ([209.85.219.42]:61966) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1UCeqs-00032y-0R for qemu-devel@nongnu.org; Mon, 04 Mar 2013 18:31:26 -0500 Received: by mail-oa0-f42.google.com with SMTP id i18so10138332oag.29 for ; Mon, 04 Mar 2013 15:31:24 -0800 (PST) From: Anthony Liguori In-Reply-To: <1362437363-27570-1-git-send-email-eblake@redhat.com> References: <1362437363-27570-1-git-send-email-eblake@redhat.com> Date: Mon, 04 Mar 2013 17:31:19 -0600 Message-ID: <87sj4ayc6w.fsf@codemonkey.ws> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Subject: Re: [Qemu-devel] [PATCH] rng: restrict passthrough names to known-good files List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Eric Blake , libvir-list@redhat.com Cc: pbonzini@redhat.com, qemu-devel@nongnu.org Eric Blake writes: > There is some controversy[1] on the qemu list on whether qemu should > have ever allowed arbitrary file name passthrough, or whether it > should be restricted to JUST /dev/random and /dev/hwrng. It is > always easier to add support for additional filenames than it is > to remove support for something once released, so this patch > restricts libvirt 1.0.3 (where the virtio-random backend was first > supported) to just the two uncontroversial names, letting us defer > to a later date any decision on whether supporting arbitrary files > makes sense. Additionally, since qemu 1.4 does NOT support > /dev/fdset/nnn fd passthrough for the backend, limiting to just > two known names means that we don't get tempted to try fd > passthrough where it won't work. Acked-by: Anthony Liguori Regards, Anthony Liguori > > [1]https://lists.gnu.org/archive/html/qemu-devel/2013-03/threads.html#00023 > > * src/conf/domain_conf.c (virDomainRNGDefParseXML): Only allow > /dev/random and /dev/hwrng. > * docs/schemas/domaincommon.rng: Flag invalid files. > * docs/formatdomain.html.in (elementsRng): Document this. > * tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.args: > Update test to match. > * tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.xml: > Likewise. > --- > > This needs to be acked before libvirt 1.0.3; otherwise we are > stuck supporting arbitrary name passthrough. > > docs/formatdomain.html.in | 3 ++- > docs/schemas/domaincommon.rng | 5 ++++- > src/conf/domain_conf.c | 7 +++++++ > tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.args | 2 +- > tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.xml | 2 +- > 5 files changed, 15 insertions(+), 4 deletions(-) > > diff --git a/docs/formatdomain.html.in b/docs/formatdomain.html.in > index 1835b39..4cafc92 100644 > --- a/docs/formatdomain.html.in > +++ b/docs/formatdomain.html.in > @@ -4310,7 +4310,8 @@ qemu-kvm -net nic,model=? /dev/null > model attribute. Supported source models are: >

>
    > -
  • 'random' — /dev/random (default) or similar device as source
  • > +
  • 'random' — /dev/random (default) or /dev/hwrng > + device as source (for now, no other sources are permitted)
  • >
  • 'egd' — a EGD protocol backend
  • >
> > diff --git a/docs/schemas/domaincommon.rng b/docs/schemas/domaincommon.rng > index e7231cc..4b60885 100644 > --- a/docs/schemas/domaincommon.rng > +++ b/docs/schemas/domaincommon.rng > @@ -3511,7 +3511,10 @@ > > random > > - > + > + /dev/random > + /dev/hwrng > + > > > > diff --git a/src/conf/domain_conf.c b/src/conf/domain_conf.c > index 995cf0c..9c96cf1 100644 > --- a/src/conf/domain_conf.c > +++ b/src/conf/domain_conf.c > @@ -7423,6 +7423,13 @@ virDomainRNGDefParseXML(const xmlNodePtr node, > switch ((enum virDomainRNGBackend) def->backend) { > case VIR_DOMAIN_RNG_BACKEND_RANDOM: > def->source.file = virXPathString("string(./backend)", ctxt); > + if (STRNEQ(def->source.file, "/dev/random") && > + STRNEQ(def->source.file, "/dev/hwrng")) { > + virReportError(VIR_ERR_XML_ERROR, > + _("file '%s' is not a supported random source"), > + def->source.file); > + goto error; > + } > break; > > case VIR_DOMAIN_RNG_BACKEND_EGD: > diff --git a/tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.args b/tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.args > index ad27132..7ab9dbc 100644 > --- a/tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.args > +++ b/tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.args > @@ -2,5 +2,5 @@ LC_ALL=C PATH=/bin HOME=/home/test USER=test LOGNAME=test /usr/bin/qemu \ > -S -M pc -m 214 -smp 1 -nographic -nodefaults \ > -monitor unix:/tmp/test-monitor,server,nowait -no-acpi -boot c -usb \ > -device virtio-balloon-pci,id=balloon0,bus=pci.0,addr=0x3 \ > --object 'rng-random,id=rng0,filename=/test/ph +-object rng-random,id=rng0,filename=/dev/hwrng \ > -device virtio-rng-pci,rng=rng0,bus=pci.0,addr=0x4 > diff --git a/tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.xml b/tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.xml > index 0658f4b..1e2c4be 100644 > --- a/tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.xml > +++ b/tests/qemuxml2argvdata/qemuxml2argv-virtio-rng-random.xml > @@ -17,7 +17,7 @@ > > > > - /test/ph<ile > + /dev/hwrng > > > > -- > 1.8.1.4