QEMU With E2K User Support
Go to file
Daniel P. Berrange e7b347d0bf net: detect errors from probing vnet hdr flag for TAP devices
When QEMU sets up a tap based network device backend, it mostly ignores errors
reported from various ioctl() calls it makes, assuming the TAP file descriptor
is valid. This assumption can easily be violated when the user is passing in a
pre-opened file descriptor. At best, the ioctls may fail with a -EBADF, but if
the user passes in a bogus FD number that happens to clash with a FD number that
QEMU has opened internally for another reason, a wide variety of errnos may
result, as the TUNGETIFF ioctl number may map to a completely different command
on a different type of file.

By ignoring all these errors, QEMU sets up a zombie network backend that will
never pass any data. Even worse, when QEMU shuts down, or that network backend
is hot-removed, it will close this bogus file descriptor, which could belong to
another QEMU device backend.

There's no obvious guaranteed reliable way to detect that a FD genuinely is a
TAP device, as opposed to a UNIX socket, or pipe, or something else. Checking
the errno from probing vnet hdr flag though, does catch the big common cases.
ie calling TUNGETIFF will return EBADF for an invalid FD, and ENOTTY when FD is
a UNIX socket, or pipe which catches accidental collisions with FDs used for
stdio, or monitor socket.

Previously the example below where bogus fd 9 collides with the FD used for the
chardev saw:

$ ./x86_64-softmmu/qemu-system-x86_64 -netdev tap,id=hostnet0,fd=9 \
  -chardev socket,id=charchannel0,path=/tmp/qga,server,nowait \
  -monitor stdio -vnc :0
qemu-system-x86_64: -netdev tap,id=hostnet0,fd=9: TUNGETIFF ioctl() failed: Inappropriate ioctl for device
TUNSETOFFLOAD ioctl() failed: Bad address
QEMU 2.9.1 monitor - type 'help' for more information
(qemu) Warning: netdev hostnet0 has no peer

which gives a running QEMU with a zombie network backend.

With this change applied we get an error message and QEMU immediately exits
before carrying on and making a bigger disaster:

$ ./x86_64-softmmu/qemu-system-x86_64 -netdev tap,id=hostnet0,fd=9 \
  -chardev socket,id=charchannel0,path=/tmp/qga,server,nowait \
  -monitor stdio -vnc :0
qemu-system-x86_64: -netdev tap,id=hostnet0,vhost=on,fd=9: Unable to query TUNGETIFF on FD 9: Inappropriate ioctl for device

Reported-by: Dr. David Alan Gilbert <dgilbert@redhat.com>
Signed-off-by: Daniel P. Berrange <berrange@redhat.com>
Tested-by: Dr. David Alan Gilbert <dgilbert@redhat.com>
Message-id: 20171027085548.3472-1-berrange@redhat.com
[lv: to simplify, don't check on EINVAL with TUNGETIFF as it exists since v2.6.27]
Signed-off-by: Laurent Vivier <lvivier@redhat.com>
Signed-off-by: Jason Wang <jasowang@redhat.com>
2020-07-15 21:00:13 +08:00
.github .github: Enable repo-lockdown bot to refuse GitHub pull requests 2020-04-07 16:19:18 +01:00
.gitlab-ci.d containers.yml: build with docker.py tooling 2020-07-11 15:53:00 +01:00
accel accel/tcg: Add stub for probe_access() 2020-07-10 18:02:21 -04:00
audio ossaudio: fix out of bounds write 2020-07-13 11:38:40 +02:00
authz qom: Drop parameter @errp of object_property_add() & friends 2020-05-15 07:07:58 +02:00
backends error: Eliminate error_propagate() with Coccinelle, part 1 2020-07-10 15:18:08 +02:00
block Block layer patches: 2020-07-14 19:39:52 +01:00
bsd-user linux-user/sparc64: Fix the handling of window spill trap 2020-06-29 13:00:23 +02:00
capstone@22ead3e0bf
chardev chardev: Extract system emulation specific code 2020-07-13 11:59:47 +04:00
contrib qemu-option: Use returned bool to check for failure 2020-07-10 15:17:35 +02:00
crypto qom: Put name parameter before value / visitor parameter 2020-07-10 15:18:08 +02:00
default-configs hw/avr: Add limited support for some Arduino boards 2020-07-11 11:02:05 +02:00
disas disas/sh4: Add missing fallthrough annotations 2020-07-13 11:40:52 +02:00
docs Fix CVE-2020-13253 2020-07-15 09:06:55 +01:00
dtc@85e5d83984 Makefile: dtc: update, build the libfdt target 2020-06-16 14:49:05 +01:00
dump error: Eliminate error_propagate() manually 2020-07-10 15:18:08 +02:00
fpu softfloat: return low bits of quotient from floatx80_modrem 2020-06-26 09:39:38 -04:00
fsdev 9p: null terminate fs driver options list 2020-07-10 12:48:06 +02:00
gdb-xml target/avr: CPU class: Add GDB support 2020-07-10 17:58:32 +02:00
hw hw/net: Added CSO for IPv6 2020-07-15 21:00:13 +08:00
include net: check if the file descriptor is valid before using it 2020-07-15 21:00:13 +08:00
io io/task: Move 'qom/object.h' header to source 2020-06-10 12:09:37 -04:00
libdecnumber
linux-headers linux-headers: update again to 5.8 2020-07-10 19:26:55 -04:00
linux-user linux-user: fix print_syscall_err() when syscall returned value is negative 2020-07-14 09:29:14 +02:00
migration migration/migration.c: Remove superfluous breaks 2020-07-13 18:15:36 +02:00
monitor monitor/misc: Remove unused "chardev/char-mux.h" include 2020-07-13 11:59:47 +04:00
nbd nbd: Use ERRP_GUARD() 2020-07-10 15:18:09 +02:00
net net: detect errors from probing vnet hdr flag for TAP devices 2020-07-15 21:00:13 +08:00
pc-bios Update OpenBIOS images to 75fbb41d built from submodule. 2020-07-07 21:54:37 +01:00
plugins qemu/qemu-plugin: Make qemu_plugin_hwaddr_is_io() hwaddr argument const 2020-05-15 15:25:16 +01:00
po translations: Add Swedish language 2020-06-15 20:51:10 +02:00
python/qemu python/qmp.py: add QMPProtocolError 2020-07-14 22:22:22 +02:00
qapi file-posix: Mitigate file fragmentation with extent size hints 2020-07-14 15:18:59 +02:00
qga qga: Use qemu_get_host_name() instead of g_get_host_name() 2020-07-13 17:44:58 -05:00
qobject qobject: Eliminate qdict_iter(), use qdict_first(), qdict_next() 2020-04-30 06:51:15 +02:00
qom qom: Introduce object_property_try_add_child() 2020-07-10 18:02:16 -04:00
replay replay: synchronize on every virtual timer callback 2020-06-26 06:45:30 -04:00
roms Update OpenBIOS images to 75fbb41d built from submodule. 2020-07-07 21:54:37 +01:00
scripts python/qmp.py: re-absorb MonitorResponseError 2020-07-14 22:22:22 +02:00
scsi error: Use error_reportf_err() where appropriate 2020-05-27 07:45:30 +02:00
slirp@2faae0f778 slirp: update to fix CVE-2020-1983 2020-04-21 18:39:20 +01:00
softmmu 8bit AVR port from Michael Rolnik. 2020-07-11 19:27:59 +01:00
storage-daemon qemu-storage-daemon: Add --monitor option 2020-03-06 17:21:28 +01:00
stubs trivial branch patches 20200707 2020-07-09 14:13:19 +01:00
target This is a colection of bug fixes and small imrprovements for RISC-V. 2020-07-14 17:58:00 +01:00
tcg tcg/riscv: Remove superfluous breaks 2020-07-13 17:25:37 -07:00
tests Python patches for 5.1 2020-07-15 13:04:27 +01:00
tools/virtiofsd virtiofsd: Allow addition or removal of capabilities 2020-07-03 16:23:05 +01:00
trace trace/simple: Fix unauthorized enable 2020-06-24 11:21:00 +01:00
ui bugfixes for audio, usb, ui and docs. 2020-07-13 16:58:44 +01:00
util net: check if the file descriptor is valid before using it 2020-07-15 21:00:13 +08:00
.cirrus.yml .cirrus.yml: add bash to the brew packages 2020-07-11 15:53:29 +01:00
.dir-locals.el
.editorconfig
.exrc
.gdbinit
.gitignore .gitignore: un-ignore .gitlab-ci.d 2020-07-11 15:53:00 +01:00
.gitlab-ci.yml testing: add check-build target 2020-07-11 15:53:00 +01:00
.gitmodules hw/ppc/prep: Remove the deprecated "prep" machine and the OpenHackware BIOS 2020-02-02 14:07:57 +11:00
.gitpublish
.mailmap MAINTAINERS: Update Radoslaw Biernacki email address 2020-07-07 12:38:50 +02:00
.patchew.yml
.readthedocs.yml .readthedocs.yml: specify some minimum python requirements 2020-02-07 15:15:16 +01:00
.shippable.yml shippable: pull images from registry instead of building 2020-07-11 15:53:00 +01:00
.travis.yml travis.yml: Test also the other targets on s390x 2020-07-11 15:53:00 +01:00
block.c qemu-img: Deprecate use of -b without -F 2020-07-14 15:24:05 +02:00
blockdev-nbd.c blockdev-nbd: Boxed argument type for nbd-server-add 2020-03-06 17:21:28 +01:00
blockdev.c block: Add support to warn on backing file change without format 2020-07-14 15:18:59 +02:00
blockjob.c block: Add BdrvChildRole to BdrvChild 2020-05-18 19:05:25 +02:00
bootdevice.c error: Eliminate error_propagate() manually 2020-07-10 15:18:08 +02:00
Changelog
CODING_STYLE.rst
configure osdep.h: Always include <sys/signal.h> if it exists 2020-07-13 14:36:09 +01:00
COPYING
COPYING.LIB
cpus-common.c cpus: Move CPU code from exec.c to cpus-common.c 2020-07-10 18:02:24 -04:00
device_tree.c device_tree: Constify compat in qemu_fdt_node_path() 2020-04-30 15:35:41 +01:00
disas.c disas: Let disas::read_memory() handler return EIO on error 2020-06-10 12:10:23 -04:00
dma-helpers.c icount: make dma reads deterministic 2020-06-17 14:53:39 +02:00
exec-vary.c exec: Cache TARGET_PAGE_MASK for TARGET_PAGE_BITS_VARY 2019-10-28 10:35:20 +01:00
exec.c cpus: Move CPU code from exec.c to cpus-common.c 2020-07-10 18:02:24 -04:00
gdbstub.c gdbstub/linux-user: support debugging over a unix socket 2020-05-06 09:29:26 +01:00
gitdm.config
hmp-commands-info.hx memory: Make 'info mtree' not display disabled regions by default 2020-06-10 12:10:49 -04:00
hmp-commands.hx hmp: Make json format optional for qom-set 2020-06-17 17:48:39 +01:00
iothread.c error: Eliminate error_propagate() with Coccinelle, part 1 2020-07-10 15:18:08 +02:00
job-qmp.c job: take each job's lock individually in job_txn_apply 2020-04-07 14:34:47 +02:00
job.c job: take each job's lock individually in job_txn_apply 2020-04-07 14:34:47 +02:00
Kconfig Makefile: simplify MINIKCONF rules 2020-07-10 18:02:21 -04:00
Kconfig.host accel/Kconfig: Extract accel selectors into their own config 2020-07-10 18:02:21 -04:00
LICENSE tcg/LICENSE: Remove out of date claim about TCG subdirectory licensing 2019-11-11 15:11:21 +01:00
MAINTAINERS Fix CVE-2020-13253 2020-07-15 09:06:55 +01:00
Makefile Makefile: simplify MINIKCONF rules 2020-07-10 18:02:21 -04:00
Makefile.objs chardev: enable modules, use for braille 2020-07-07 15:33:59 +02:00
Makefile.target softmmu: move softmmu only files from root 2020-07-10 18:02:24 -04:00
memory_ldst.inc.c
module-common.c
os-posix.c build: Check that mlockall() exists 2020-07-13 14:36:09 +01:00
os-win32.c glib: use portable g_setenv() 2019-12-17 09:05:23 +01:00
qdev-monitor.c hmp: Ignore Error objects where the return value suffices 2020-07-10 15:18:09 +02:00
qemu-bridge-helper.c build: rename CONFIG_LIBCAP to CONFIG_LIBCAP_NG 2019-12-17 19:35:47 +01:00
qemu-edid.c
qemu-img-cmds.hx block/amend: add 'force' option 2020-07-06 08:49:28 +02:00
qemu-img.c qemu-img: Deprecate use of -b without -F 2020-07-14 15:24:05 +02:00
qemu-io-cmds.c block-backend: Add flags to blk_truncate() 2020-04-30 17:51:07 +02:00
qemu-io.c qemu-io: adds option to use aio engine 2020-01-30 20:59:42 +00:00
qemu-keymap.c
qemu-nbd.c error: Use error_reportf_err() where appropriate 2020-05-27 07:45:30 +02:00
qemu-options-wrapper.h
qemu-options.h
qemu-options.hx qemu-options.hx: Clean up and fix typo for colo-compare 2020-07-15 21:00:13 +08:00
qemu-seccomp.c
qemu-storage-daemon.c qemu-storage-daemon: add missing cleanup calls 2020-07-03 09:37:03 +02:00
qemu.nsi qemu.nsi: Install Sphinx documentation 2020-03-09 16:45:00 +00:00
qemu.sasl
README.rst
replication.c
replication.h
rules.mak build-sys: Move the print-variable rule to rules.mak 2020-03-09 15:59:31 +01:00
thunk.c linux-user: Add strace support for printing arguments of ioctl() 2020-07-04 18:08:51 +02:00
tpm.c error: Eliminate error_propagate() with Coccinelle, part 1 2020-07-10 15:18:08 +02:00
trace-events trace: add mmu_index to mem_info 2019-10-28 15:12:38 +00:00
VERSION Open 5.1 development tree 2020-04-29 15:07:10 +01:00
version.rc

===========
QEMU README
===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:


.. code-block:: shell

  mkdir build
  cd build
  ../configure
  make

Additional information can also be found online via the QEMU website:

* `<https://qemu.org/Hosts/Linux>`_
* `<https://qemu.org/Hosts/Mac>`_
* `<https://qemu.org/Hosts/W32>`_


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

.. code-block:: shell

   git clone https://git.qemu.org/git/qemu.git

When submitting patches, one common approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the CODING_STYLE.rst file.

Additional information on submitting patches can be found online via
the QEMU website

* `<https://qemu.org/Contribute/SubmitAPatch>`_
* `<https://qemu.org/Contribute/TrivialPatches>`_

The QEMU website is also maintained under source control.

.. code-block:: shell

  git clone https://git.qemu.org/git/qemu-web.git

* `<https://www.qemu.org/2017/02/04/the-new-qemu-website-is-up/>`_

A 'git-publish' utility was created to make above process less
cumbersome, and is highly recommended for making regular contributions,
or even just for sending consecutive patch series revisions. It also
requires a working 'git send-email' setup, and by default doesn't
automate everything, so you may want to go through the above steps
manually for once.

For installation instructions, please go to

*  `<https://github.com/stefanha/git-publish>`_

The workflow with 'git-publish' is:

.. code-block:: shell

  $ git checkout master -b my-feature
  $ # work on new commits, add your 'Signed-off-by' lines to each
  $ git publish

Your patch series will be sent and tagged as my-feature-v1 if you need to refer
back to it in the future.

Sending v2:

.. code-block:: shell

  $ git checkout my-feature # same topic branch
  $ # making changes to the commits (using 'git rebase', for example)
  $ git publish

Your patch series will be sent with 'v2' tag in the subject and the git tip
will be tagged as my-feature-v2.

Bug reporting
=============

The QEMU project uses Launchpad as its primary upstream bug tracker. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

* `<https://bugs.launchpad.net/qemu/>`_

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via launchpad.

For additional information on bug reporting consult:

* `<https://qemu.org/Contribute/ReportABug>`_


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

* `<mailto:qemu-devel@nongnu.org>`_
* `<https://lists.nongnu.org/mailman/listinfo/qemu-devel>`_
* #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

* `<https://qemu.org/Contribute/StartHere>`_