]>
Commit | Line | Data |
---|---|---|
1 | /* | |
2 | * Copyright (C) 2016-2017 Red Hat, Inc. | |
3 | * Copyright (C) 2005 Anthony Liguori <[email protected]> | |
4 | * | |
5 | * Network Block Device Client Side | |
6 | * | |
7 | * This program is free software; you can redistribute it and/or modify | |
8 | * it under the terms of the GNU General Public License as published by | |
9 | * the Free Software Foundation; under version 2 of the License. | |
10 | * | |
11 | * This program is distributed in the hope that it will be useful, | |
12 | * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
13 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
14 | * GNU General Public License for more details. | |
15 | * | |
16 | * You should have received a copy of the GNU General Public License | |
17 | * along with this program; if not, see <http://www.gnu.org/licenses/>. | |
18 | */ | |
19 | ||
20 | #include "qemu/osdep.h" | |
21 | #include "qapi/error.h" | |
22 | #include "trace.h" | |
23 | #include "nbd-internal.h" | |
24 | ||
25 | /* Definitions for opaque data types */ | |
26 | ||
27 | static QTAILQ_HEAD(, NBDExport) exports = QTAILQ_HEAD_INITIALIZER(exports); | |
28 | ||
29 | /* That's all folks */ | |
30 | ||
31 | /* Basic flow for negotiation | |
32 | ||
33 | Server Client | |
34 | Negotiate | |
35 | ||
36 | or | |
37 | ||
38 | Server Client | |
39 | Negotiate #1 | |
40 | Option | |
41 | Negotiate #2 | |
42 | ||
43 | ---- | |
44 | ||
45 | followed by | |
46 | ||
47 | Server Client | |
48 | Request | |
49 | Response | |
50 | Request | |
51 | Response | |
52 | ... | |
53 | ... | |
54 | Request (type == 2) | |
55 | ||
56 | */ | |
57 | ||
58 | /* Send an option request. | |
59 | * | |
60 | * The request is for option @opt, with @data containing @len bytes of | |
61 | * additional payload for the request (@len may be -1 to treat @data as | |
62 | * a C string; and @data may be NULL if @len is 0). | |
63 | * Return 0 if successful, -1 with errp set if it is impossible to | |
64 | * continue. */ | |
65 | static int nbd_send_option_request(QIOChannel *ioc, uint32_t opt, | |
66 | uint32_t len, const char *data, | |
67 | Error **errp) | |
68 | { | |
69 | NBDOption req; | |
70 | QEMU_BUILD_BUG_ON(sizeof(req) != 16); | |
71 | ||
72 | if (len == -1) { | |
73 | req.length = len = strlen(data); | |
74 | } | |
75 | trace_nbd_send_option_request(opt, nbd_opt_lookup(opt), len); | |
76 | ||
77 | stq_be_p(&req.magic, NBD_OPTS_MAGIC); | |
78 | stl_be_p(&req.option, opt); | |
79 | stl_be_p(&req.length, len); | |
80 | ||
81 | if (nbd_write(ioc, &req, sizeof(req), errp) < 0) { | |
82 | error_prepend(errp, "Failed to send option request header: "); | |
83 | return -1; | |
84 | } | |
85 | ||
86 | if (len && nbd_write(ioc, (char *) data, len, errp) < 0) { | |
87 | error_prepend(errp, "Failed to send option request data: "); | |
88 | return -1; | |
89 | } | |
90 | ||
91 | return 0; | |
92 | } | |
93 | ||
94 | /* Send NBD_OPT_ABORT as a courtesy to let the server know that we are | |
95 | * not going to attempt further negotiation. */ | |
96 | static void nbd_send_opt_abort(QIOChannel *ioc) | |
97 | { | |
98 | /* Technically, a compliant server is supposed to reply to us; but | |
99 | * older servers disconnected instead. At any rate, we're allowed | |
100 | * to disconnect without waiting for the server reply, so we don't | |
101 | * even care if the request makes it to the server, let alone | |
102 | * waiting around for whether the server replies. */ | |
103 | nbd_send_option_request(ioc, NBD_OPT_ABORT, 0, NULL, NULL); | |
104 | } | |
105 | ||
106 | ||
107 | /* Receive the header of an option reply, which should match the given | |
108 | * opt. Read through the length field, but NOT the length bytes of | |
109 | * payload. Return 0 if successful, -1 with errp set if it is | |
110 | * impossible to continue. */ | |
111 | static int nbd_receive_option_reply(QIOChannel *ioc, uint32_t opt, | |
112 | NBDOptionReply *reply, Error **errp) | |
113 | { | |
114 | QEMU_BUILD_BUG_ON(sizeof(*reply) != 20); | |
115 | if (nbd_read(ioc, reply, sizeof(*reply), errp) < 0) { | |
116 | error_prepend(errp, "failed to read option reply: "); | |
117 | nbd_send_opt_abort(ioc); | |
118 | return -1; | |
119 | } | |
120 | be64_to_cpus(&reply->magic); | |
121 | be32_to_cpus(&reply->option); | |
122 | be32_to_cpus(&reply->type); | |
123 | be32_to_cpus(&reply->length); | |
124 | ||
125 | trace_nbd_receive_option_reply(reply->option, nbd_opt_lookup(reply->option), | |
126 | reply->type, nbd_rep_lookup(reply->type), | |
127 | reply->length); | |
128 | ||
129 | if (reply->magic != NBD_REP_MAGIC) { | |
130 | error_setg(errp, "Unexpected option reply magic"); | |
131 | nbd_send_opt_abort(ioc); | |
132 | return -1; | |
133 | } | |
134 | if (reply->option != opt) { | |
135 | error_setg(errp, "Unexpected option type %x expected %x", | |
136 | reply->option, opt); | |
137 | nbd_send_opt_abort(ioc); | |
138 | return -1; | |
139 | } | |
140 | return 0; | |
141 | } | |
142 | ||
143 | /* If reply represents success, return 1 without further action. | |
144 | * If reply represents an error, consume the optional payload of | |
145 | * the packet on ioc. Then return 0 for unsupported (so the client | |
146 | * can fall back to other approaches), or -1 with errp set for other | |
147 | * errors. | |
148 | */ | |
149 | static int nbd_handle_reply_err(QIOChannel *ioc, NBDOptionReply *reply, | |
150 | Error **errp) | |
151 | { | |
152 | char *msg = NULL; | |
153 | int result = -1; | |
154 | ||
155 | if (!(reply->type & (1 << 31))) { | |
156 | return 1; | |
157 | } | |
158 | ||
159 | if (reply->length) { | |
160 | if (reply->length > NBD_MAX_BUFFER_SIZE) { | |
161 | error_setg(errp, "server error %" PRIu32 | |
162 | " (%s) message is too long", | |
163 | reply->type, nbd_rep_lookup(reply->type)); | |
164 | goto cleanup; | |
165 | } | |
166 | msg = g_malloc(reply->length + 1); | |
167 | if (nbd_read(ioc, msg, reply->length, errp) < 0) { | |
168 | error_prepend(errp, "failed to read option error %" PRIu32 | |
169 | " (%s) message: ", | |
170 | reply->type, nbd_rep_lookup(reply->type)); | |
171 | goto cleanup; | |
172 | } | |
173 | msg[reply->length] = '\0'; | |
174 | } | |
175 | ||
176 | switch (reply->type) { | |
177 | case NBD_REP_ERR_UNSUP: | |
178 | trace_nbd_reply_err_unsup(reply->option, nbd_opt_lookup(reply->option)); | |
179 | result = 0; | |
180 | goto cleanup; | |
181 | ||
182 | case NBD_REP_ERR_POLICY: | |
183 | error_setg(errp, "Denied by server for option %" PRIu32 " (%s)", | |
184 | reply->option, nbd_opt_lookup(reply->option)); | |
185 | break; | |
186 | ||
187 | case NBD_REP_ERR_INVALID: | |
188 | error_setg(errp, "Invalid parameters for option %" PRIu32 " (%s)", | |
189 | reply->option, nbd_opt_lookup(reply->option)); | |
190 | break; | |
191 | ||
192 | case NBD_REP_ERR_PLATFORM: | |
193 | error_setg(errp, "Server lacks support for option %" PRIu32 " (%s)", | |
194 | reply->option, nbd_opt_lookup(reply->option)); | |
195 | break; | |
196 | ||
197 | case NBD_REP_ERR_TLS_REQD: | |
198 | error_setg(errp, "TLS negotiation required before option %" PRIu32 | |
199 | " (%s)", reply->option, nbd_opt_lookup(reply->option)); | |
200 | break; | |
201 | ||
202 | case NBD_REP_ERR_UNKNOWN: | |
203 | error_setg(errp, "Requested export not available"); | |
204 | break; | |
205 | ||
206 | case NBD_REP_ERR_SHUTDOWN: | |
207 | error_setg(errp, "Server shutting down before option %" PRIu32 " (%s)", | |
208 | reply->option, nbd_opt_lookup(reply->option)); | |
209 | break; | |
210 | ||
211 | case NBD_REP_ERR_BLOCK_SIZE_REQD: | |
212 | error_setg(errp, "Server requires INFO_BLOCK_SIZE for option %" PRIu32 | |
213 | " (%s)", reply->option, nbd_opt_lookup(reply->option)); | |
214 | break; | |
215 | ||
216 | default: | |
217 | error_setg(errp, "Unknown error code when asking for option %" PRIu32 | |
218 | " (%s)", reply->option, nbd_opt_lookup(reply->option)); | |
219 | break; | |
220 | } | |
221 | ||
222 | if (msg) { | |
223 | error_append_hint(errp, "server reported: %s\n", msg); | |
224 | } | |
225 | ||
226 | cleanup: | |
227 | g_free(msg); | |
228 | if (result < 0) { | |
229 | nbd_send_opt_abort(ioc); | |
230 | } | |
231 | return result; | |
232 | } | |
233 | ||
234 | /* Process another portion of the NBD_OPT_LIST reply. Set *@match if | |
235 | * the current reply matches @want or if the server does not support | |
236 | * NBD_OPT_LIST, otherwise leave @match alone. Return 0 if iteration | |
237 | * is complete, positive if more replies are expected, or negative | |
238 | * with @errp set if an unrecoverable error occurred. */ | |
239 | static int nbd_receive_list(QIOChannel *ioc, const char *want, bool *match, | |
240 | Error **errp) | |
241 | { | |
242 | NBDOptionReply reply; | |
243 | uint32_t len; | |
244 | uint32_t namelen; | |
245 | char name[NBD_MAX_NAME_SIZE + 1]; | |
246 | int error; | |
247 | ||
248 | if (nbd_receive_option_reply(ioc, NBD_OPT_LIST, &reply, errp) < 0) { | |
249 | return -1; | |
250 | } | |
251 | error = nbd_handle_reply_err(ioc, &reply, errp); | |
252 | if (error <= 0) { | |
253 | /* The server did not support NBD_OPT_LIST, so set *match on | |
254 | * the assumption that any name will be accepted. */ | |
255 | *match = true; | |
256 | return error; | |
257 | } | |
258 | len = reply.length; | |
259 | ||
260 | if (reply.type == NBD_REP_ACK) { | |
261 | if (len != 0) { | |
262 | error_setg(errp, "length too long for option end"); | |
263 | nbd_send_opt_abort(ioc); | |
264 | return -1; | |
265 | } | |
266 | return 0; | |
267 | } else if (reply.type != NBD_REP_SERVER) { | |
268 | error_setg(errp, "Unexpected reply type %" PRIx32 " expected %x", | |
269 | reply.type, NBD_REP_SERVER); | |
270 | nbd_send_opt_abort(ioc); | |
271 | return -1; | |
272 | } | |
273 | ||
274 | if (len < sizeof(namelen) || len > NBD_MAX_BUFFER_SIZE) { | |
275 | error_setg(errp, "incorrect option length %" PRIu32, len); | |
276 | nbd_send_opt_abort(ioc); | |
277 | return -1; | |
278 | } | |
279 | if (nbd_read(ioc, &namelen, sizeof(namelen), errp) < 0) { | |
280 | error_prepend(errp, "failed to read option name length: "); | |
281 | nbd_send_opt_abort(ioc); | |
282 | return -1; | |
283 | } | |
284 | namelen = be32_to_cpu(namelen); | |
285 | len -= sizeof(namelen); | |
286 | if (len < namelen) { | |
287 | error_setg(errp, "incorrect option name length"); | |
288 | nbd_send_opt_abort(ioc); | |
289 | return -1; | |
290 | } | |
291 | if (namelen != strlen(want)) { | |
292 | if (nbd_drop(ioc, len, errp) < 0) { | |
293 | error_prepend(errp, | |
294 | "failed to skip export name with wrong length: "); | |
295 | nbd_send_opt_abort(ioc); | |
296 | return -1; | |
297 | } | |
298 | return 1; | |
299 | } | |
300 | ||
301 | assert(namelen < sizeof(name)); | |
302 | if (nbd_read(ioc, name, namelen, errp) < 0) { | |
303 | error_prepend(errp, "failed to read export name: "); | |
304 | nbd_send_opt_abort(ioc); | |
305 | return -1; | |
306 | } | |
307 | name[namelen] = '\0'; | |
308 | len -= namelen; | |
309 | if (nbd_drop(ioc, len, errp) < 0) { | |
310 | error_prepend(errp, "failed to read export description: "); | |
311 | nbd_send_opt_abort(ioc); | |
312 | return -1; | |
313 | } | |
314 | if (!strcmp(name, want)) { | |
315 | *match = true; | |
316 | } | |
317 | return 1; | |
318 | } | |
319 | ||
320 | ||
321 | /* Returns -1 if NBD_OPT_GO proves the export @wantname cannot be | |
322 | * used, 0 if NBD_OPT_GO is unsupported (fall back to NBD_OPT_LIST and | |
323 | * NBD_OPT_EXPORT_NAME in that case), and > 0 if the export is good to | |
324 | * go (with @info populated). */ | |
325 | static int nbd_opt_go(QIOChannel *ioc, const char *wantname, | |
326 | NBDExportInfo *info, Error **errp) | |
327 | { | |
328 | NBDOptionReply reply; | |
329 | uint32_t len = strlen(wantname); | |
330 | uint16_t type; | |
331 | int error; | |
332 | char *buf; | |
333 | ||
334 | /* The protocol requires that the server send NBD_INFO_EXPORT with | |
335 | * a non-zero flags (at least NBD_FLAG_HAS_FLAGS must be set); so | |
336 | * flags still 0 is a witness of a broken server. */ | |
337 | info->flags = 0; | |
338 | ||
339 | trace_nbd_opt_go_start(wantname); | |
340 | buf = g_malloc(4 + len + 2 + 2 * info->request_sizes + 1); | |
341 | stl_be_p(buf, len); | |
342 | memcpy(buf + 4, wantname, len); | |
343 | /* At most one request, everything else up to server */ | |
344 | stw_be_p(buf + 4 + len, info->request_sizes); | |
345 | if (info->request_sizes) { | |
346 | stw_be_p(buf + 4 + len + 2, NBD_INFO_BLOCK_SIZE); | |
347 | } | |
348 | error = nbd_send_option_request(ioc, NBD_OPT_GO, | |
349 | 4 + len + 2 + 2 * info->request_sizes, | |
350 | buf, errp); | |
351 | g_free(buf); | |
352 | if (error < 0) { | |
353 | return -1; | |
354 | } | |
355 | ||
356 | while (1) { | |
357 | if (nbd_receive_option_reply(ioc, NBD_OPT_GO, &reply, errp) < 0) { | |
358 | return -1; | |
359 | } | |
360 | error = nbd_handle_reply_err(ioc, &reply, errp); | |
361 | if (error <= 0) { | |
362 | return error; | |
363 | } | |
364 | len = reply.length; | |
365 | ||
366 | if (reply.type == NBD_REP_ACK) { | |
367 | /* Server is done sending info and moved into transmission | |
368 | phase, but make sure it sent flags */ | |
369 | if (len) { | |
370 | error_setg(errp, "server sent invalid NBD_REP_ACK"); | |
371 | return -1; | |
372 | } | |
373 | if (!info->flags) { | |
374 | error_setg(errp, "broken server omitted NBD_INFO_EXPORT"); | |
375 | return -1; | |
376 | } | |
377 | trace_nbd_opt_go_success(); | |
378 | return 1; | |
379 | } | |
380 | if (reply.type != NBD_REP_INFO) { | |
381 | error_setg(errp, "unexpected reply type %" PRIu32 | |
382 | " (%s), expected %u", | |
383 | reply.type, nbd_rep_lookup(reply.type), NBD_REP_INFO); | |
384 | nbd_send_opt_abort(ioc); | |
385 | return -1; | |
386 | } | |
387 | if (len < sizeof(type)) { | |
388 | error_setg(errp, "NBD_REP_INFO length %" PRIu32 " is too short", | |
389 | len); | |
390 | nbd_send_opt_abort(ioc); | |
391 | return -1; | |
392 | } | |
393 | if (nbd_read(ioc, &type, sizeof(type), errp) < 0) { | |
394 | error_prepend(errp, "failed to read info type: "); | |
395 | nbd_send_opt_abort(ioc); | |
396 | return -1; | |
397 | } | |
398 | len -= sizeof(type); | |
399 | be16_to_cpus(&type); | |
400 | switch (type) { | |
401 | case NBD_INFO_EXPORT: | |
402 | if (len != sizeof(info->size) + sizeof(info->flags)) { | |
403 | error_setg(errp, "remaining export info len %" PRIu32 | |
404 | " is unexpected size", len); | |
405 | nbd_send_opt_abort(ioc); | |
406 | return -1; | |
407 | } | |
408 | if (nbd_read(ioc, &info->size, sizeof(info->size), errp) < 0) { | |
409 | error_prepend(errp, "failed to read info size: "); | |
410 | nbd_send_opt_abort(ioc); | |
411 | return -1; | |
412 | } | |
413 | be64_to_cpus(&info->size); | |
414 | if (nbd_read(ioc, &info->flags, sizeof(info->flags), errp) < 0) { | |
415 | error_prepend(errp, "failed to read info flags: "); | |
416 | nbd_send_opt_abort(ioc); | |
417 | return -1; | |
418 | } | |
419 | be16_to_cpus(&info->flags); | |
420 | trace_nbd_receive_negotiate_size_flags(info->size, info->flags); | |
421 | break; | |
422 | ||
423 | case NBD_INFO_BLOCK_SIZE: | |
424 | if (len != sizeof(info->min_block) * 3) { | |
425 | error_setg(errp, "remaining export info len %" PRIu32 | |
426 | " is unexpected size", len); | |
427 | nbd_send_opt_abort(ioc); | |
428 | return -1; | |
429 | } | |
430 | if (nbd_read(ioc, &info->min_block, sizeof(info->min_block), | |
431 | errp) < 0) { | |
432 | error_prepend(errp, "failed to read info minimum block size: "); | |
433 | nbd_send_opt_abort(ioc); | |
434 | return -1; | |
435 | } | |
436 | be32_to_cpus(&info->min_block); | |
437 | if (!is_power_of_2(info->min_block)) { | |
438 | error_setg(errp, "server minimum block size %" PRId32 | |
439 | "is not a power of two", info->min_block); | |
440 | nbd_send_opt_abort(ioc); | |
441 | return -1; | |
442 | } | |
443 | if (nbd_read(ioc, &info->opt_block, sizeof(info->opt_block), | |
444 | errp) < 0) { | |
445 | error_prepend(errp, | |
446 | "failed to read info preferred block size: "); | |
447 | nbd_send_opt_abort(ioc); | |
448 | return -1; | |
449 | } | |
450 | be32_to_cpus(&info->opt_block); | |
451 | if (!is_power_of_2(info->opt_block) || | |
452 | info->opt_block < info->min_block) { | |
453 | error_setg(errp, "server preferred block size %" PRId32 | |
454 | "is not valid", info->opt_block); | |
455 | nbd_send_opt_abort(ioc); | |
456 | return -1; | |
457 | } | |
458 | if (nbd_read(ioc, &info->max_block, sizeof(info->max_block), | |
459 | errp) < 0) { | |
460 | error_prepend(errp, "failed to read info maximum block size: "); | |
461 | nbd_send_opt_abort(ioc); | |
462 | return -1; | |
463 | } | |
464 | be32_to_cpus(&info->max_block); | |
465 | trace_nbd_opt_go_info_block_size(info->min_block, info->opt_block, | |
466 | info->max_block); | |
467 | break; | |
468 | ||
469 | default: | |
470 | trace_nbd_opt_go_info_unknown(type, nbd_info_lookup(type)); | |
471 | if (nbd_drop(ioc, len, errp) < 0) { | |
472 | error_prepend(errp, "Failed to read info payload: "); | |
473 | nbd_send_opt_abort(ioc); | |
474 | return -1; | |
475 | } | |
476 | break; | |
477 | } | |
478 | } | |
479 | } | |
480 | ||
481 | /* Return -1 on failure, 0 if wantname is an available export. */ | |
482 | static int nbd_receive_query_exports(QIOChannel *ioc, | |
483 | const char *wantname, | |
484 | Error **errp) | |
485 | { | |
486 | bool foundExport = false; | |
487 | ||
488 | trace_nbd_receive_query_exports_start(wantname); | |
489 | if (nbd_send_option_request(ioc, NBD_OPT_LIST, 0, NULL, errp) < 0) { | |
490 | return -1; | |
491 | } | |
492 | ||
493 | while (1) { | |
494 | int ret = nbd_receive_list(ioc, wantname, &foundExport, errp); | |
495 | ||
496 | if (ret < 0) { | |
497 | /* Server gave unexpected reply */ | |
498 | return -1; | |
499 | } else if (ret == 0) { | |
500 | /* Done iterating. */ | |
501 | if (!foundExport) { | |
502 | error_setg(errp, "No export with name '%s' available", | |
503 | wantname); | |
504 | nbd_send_opt_abort(ioc); | |
505 | return -1; | |
506 | } | |
507 | trace_nbd_receive_query_exports_success(wantname); | |
508 | return 0; | |
509 | } | |
510 | } | |
511 | } | |
512 | ||
513 | /* nbd_request_simple_option: Send an option request, and parse the reply | |
514 | * return 1 for successful negotiation, | |
515 | * 0 if operation is unsupported, | |
516 | * -1 with errp set for any other error | |
517 | */ | |
518 | static int nbd_request_simple_option(QIOChannel *ioc, int opt, Error **errp) | |
519 | { | |
520 | NBDOptionReply reply; | |
521 | int error; | |
522 | ||
523 | if (nbd_send_option_request(ioc, opt, 0, NULL, errp) < 0) { | |
524 | return -1; | |
525 | } | |
526 | ||
527 | if (nbd_receive_option_reply(ioc, opt, &reply, errp) < 0) { | |
528 | return -1; | |
529 | } | |
530 | error = nbd_handle_reply_err(ioc, &reply, errp); | |
531 | if (error <= 0) { | |
532 | return error; | |
533 | } | |
534 | ||
535 | if (reply.type != NBD_REP_ACK) { | |
536 | error_setg(errp, "Server answered option %d (%s) with unexpected " | |
537 | "reply %" PRIu32 " (%s)", opt, nbd_opt_lookup(opt), | |
538 | reply.type, nbd_rep_lookup(reply.type)); | |
539 | nbd_send_opt_abort(ioc); | |
540 | return -1; | |
541 | } | |
542 | ||
543 | if (reply.length != 0) { | |
544 | error_setg(errp, "Option %d ('%s') response length is %" PRIu32 | |
545 | " (it should be zero)", opt, nbd_opt_lookup(opt), | |
546 | reply.length); | |
547 | nbd_send_opt_abort(ioc); | |
548 | return -1; | |
549 | } | |
550 | ||
551 | return 1; | |
552 | } | |
553 | ||
554 | static QIOChannel *nbd_receive_starttls(QIOChannel *ioc, | |
555 | QCryptoTLSCreds *tlscreds, | |
556 | const char *hostname, Error **errp) | |
557 | { | |
558 | int ret; | |
559 | QIOChannelTLS *tioc; | |
560 | struct NBDTLSHandshakeData data = { 0 }; | |
561 | ||
562 | ret = nbd_request_simple_option(ioc, NBD_OPT_STARTTLS, errp); | |
563 | if (ret <= 0) { | |
564 | if (ret == 0) { | |
565 | error_setg(errp, "Server don't support STARTTLS option"); | |
566 | nbd_send_opt_abort(ioc); | |
567 | } | |
568 | return NULL; | |
569 | } | |
570 | ||
571 | trace_nbd_receive_starttls_new_client(); | |
572 | tioc = qio_channel_tls_new_client(ioc, tlscreds, hostname, errp); | |
573 | if (!tioc) { | |
574 | return NULL; | |
575 | } | |
576 | qio_channel_set_name(QIO_CHANNEL(tioc), "nbd-client-tls"); | |
577 | data.loop = g_main_loop_new(g_main_context_default(), FALSE); | |
578 | trace_nbd_receive_starttls_tls_handshake(); | |
579 | qio_channel_tls_handshake(tioc, | |
580 | nbd_tls_handshake, | |
581 | &data, | |
582 | NULL, | |
583 | NULL); | |
584 | ||
585 | if (!data.complete) { | |
586 | g_main_loop_run(data.loop); | |
587 | } | |
588 | g_main_loop_unref(data.loop); | |
589 | if (data.error) { | |
590 | error_propagate(errp, data.error); | |
591 | object_unref(OBJECT(tioc)); | |
592 | return NULL; | |
593 | } | |
594 | ||
595 | return QIO_CHANNEL(tioc); | |
596 | } | |
597 | ||
598 | ||
599 | int nbd_receive_negotiate(QIOChannel *ioc, const char *name, | |
600 | QCryptoTLSCreds *tlscreds, const char *hostname, | |
601 | QIOChannel **outioc, NBDExportInfo *info, | |
602 | Error **errp) | |
603 | { | |
604 | char buf[256]; | |
605 | uint64_t magic; | |
606 | int rc; | |
607 | bool zeroes = true; | |
608 | bool structured_reply = info->structured_reply; | |
609 | ||
610 | trace_nbd_receive_negotiate(tlscreds, hostname ? hostname : "<null>"); | |
611 | ||
612 | info->structured_reply = false; | |
613 | rc = -EINVAL; | |
614 | ||
615 | if (outioc) { | |
616 | *outioc = NULL; | |
617 | } | |
618 | if (tlscreds && !outioc) { | |
619 | error_setg(errp, "Output I/O channel required for TLS"); | |
620 | goto fail; | |
621 | } | |
622 | ||
623 | if (nbd_read(ioc, buf, 8, errp) < 0) { | |
624 | error_prepend(errp, "Failed to read data: "); | |
625 | goto fail; | |
626 | } | |
627 | ||
628 | buf[8] = '\0'; | |
629 | if (strlen(buf) == 0) { | |
630 | error_setg(errp, "Server connection closed unexpectedly"); | |
631 | goto fail; | |
632 | } | |
633 | ||
634 | magic = ldq_be_p(buf); | |
635 | trace_nbd_receive_negotiate_magic(magic); | |
636 | ||
637 | if (memcmp(buf, "NBDMAGIC", 8) != 0) { | |
638 | error_setg(errp, "Invalid magic received"); | |
639 | goto fail; | |
640 | } | |
641 | ||
642 | if (nbd_read(ioc, &magic, sizeof(magic), errp) < 0) { | |
643 | error_prepend(errp, "Failed to read magic: "); | |
644 | goto fail; | |
645 | } | |
646 | magic = be64_to_cpu(magic); | |
647 | trace_nbd_receive_negotiate_magic(magic); | |
648 | ||
649 | if (magic == NBD_OPTS_MAGIC) { | |
650 | uint32_t clientflags = 0; | |
651 | uint16_t globalflags; | |
652 | bool fixedNewStyle = false; | |
653 | ||
654 | if (nbd_read(ioc, &globalflags, sizeof(globalflags), errp) < 0) { | |
655 | error_prepend(errp, "Failed to read server flags: "); | |
656 | goto fail; | |
657 | } | |
658 | globalflags = be16_to_cpu(globalflags); | |
659 | trace_nbd_receive_negotiate_server_flags(globalflags); | |
660 | if (globalflags & NBD_FLAG_FIXED_NEWSTYLE) { | |
661 | fixedNewStyle = true; | |
662 | clientflags |= NBD_FLAG_C_FIXED_NEWSTYLE; | |
663 | } | |
664 | if (globalflags & NBD_FLAG_NO_ZEROES) { | |
665 | zeroes = false; | |
666 | clientflags |= NBD_FLAG_C_NO_ZEROES; | |
667 | } | |
668 | /* client requested flags */ | |
669 | clientflags = cpu_to_be32(clientflags); | |
670 | if (nbd_write(ioc, &clientflags, sizeof(clientflags), errp) < 0) { | |
671 | error_prepend(errp, "Failed to send clientflags field: "); | |
672 | goto fail; | |
673 | } | |
674 | if (tlscreds) { | |
675 | if (fixedNewStyle) { | |
676 | *outioc = nbd_receive_starttls(ioc, tlscreds, hostname, errp); | |
677 | if (!*outioc) { | |
678 | goto fail; | |
679 | } | |
680 | ioc = *outioc; | |
681 | } else { | |
682 | error_setg(errp, "Server does not support STARTTLS"); | |
683 | goto fail; | |
684 | } | |
685 | } | |
686 | if (!name) { | |
687 | trace_nbd_receive_negotiate_default_name(); | |
688 | name = ""; | |
689 | } | |
690 | if (fixedNewStyle) { | |
691 | int result; | |
692 | ||
693 | if (structured_reply) { | |
694 | result = nbd_request_simple_option(ioc, | |
695 | NBD_OPT_STRUCTURED_REPLY, | |
696 | errp); | |
697 | if (result < 0) { | |
698 | goto fail; | |
699 | } | |
700 | info->structured_reply = result == 1; | |
701 | } | |
702 | ||
703 | /* Try NBD_OPT_GO first - if it works, we are done (it | |
704 | * also gives us a good message if the server requires | |
705 | * TLS). If it is not available, fall back to | |
706 | * NBD_OPT_LIST for nicer error messages about a missing | |
707 | * export, then use NBD_OPT_EXPORT_NAME. */ | |
708 | result = nbd_opt_go(ioc, name, info, errp); | |
709 | if (result < 0) { | |
710 | goto fail; | |
711 | } | |
712 | if (result > 0) { | |
713 | return 0; | |
714 | } | |
715 | /* Check our desired export is present in the | |
716 | * server export list. Since NBD_OPT_EXPORT_NAME | |
717 | * cannot return an error message, running this | |
718 | * query gives us better error reporting if the | |
719 | * export name is not available. | |
720 | */ | |
721 | if (nbd_receive_query_exports(ioc, name, errp) < 0) { | |
722 | goto fail; | |
723 | } | |
724 | } | |
725 | /* write the export name request */ | |
726 | if (nbd_send_option_request(ioc, NBD_OPT_EXPORT_NAME, -1, name, | |
727 | errp) < 0) { | |
728 | goto fail; | |
729 | } | |
730 | ||
731 | /* Read the response */ | |
732 | if (nbd_read(ioc, &info->size, sizeof(info->size), errp) < 0) { | |
733 | error_prepend(errp, "Failed to read export length: "); | |
734 | goto fail; | |
735 | } | |
736 | be64_to_cpus(&info->size); | |
737 | ||
738 | if (nbd_read(ioc, &info->flags, sizeof(info->flags), errp) < 0) { | |
739 | error_prepend(errp, "Failed to read export flags: "); | |
740 | goto fail; | |
741 | } | |
742 | be16_to_cpus(&info->flags); | |
743 | } else if (magic == NBD_CLIENT_MAGIC) { | |
744 | uint32_t oldflags; | |
745 | ||
746 | if (name) { | |
747 | error_setg(errp, "Server does not support export names"); | |
748 | goto fail; | |
749 | } | |
750 | if (tlscreds) { | |
751 | error_setg(errp, "Server does not support STARTTLS"); | |
752 | goto fail; | |
753 | } | |
754 | ||
755 | if (nbd_read(ioc, &info->size, sizeof(info->size), errp) < 0) { | |
756 | error_prepend(errp, "Failed to read export length: "); | |
757 | goto fail; | |
758 | } | |
759 | be64_to_cpus(&info->size); | |
760 | ||
761 | if (nbd_read(ioc, &oldflags, sizeof(oldflags), errp) < 0) { | |
762 | error_prepend(errp, "Failed to read export flags: "); | |
763 | goto fail; | |
764 | } | |
765 | be32_to_cpus(&oldflags); | |
766 | if (oldflags & ~0xffff) { | |
767 | error_setg(errp, "Unexpected export flags %0x" PRIx32, oldflags); | |
768 | goto fail; | |
769 | } | |
770 | info->flags = oldflags; | |
771 | } else { | |
772 | error_setg(errp, "Bad magic received"); | |
773 | goto fail; | |
774 | } | |
775 | ||
776 | trace_nbd_receive_negotiate_size_flags(info->size, info->flags); | |
777 | if (zeroes && nbd_drop(ioc, 124, errp) < 0) { | |
778 | error_prepend(errp, "Failed to read reserved block: "); | |
779 | goto fail; | |
780 | } | |
781 | rc = 0; | |
782 | ||
783 | fail: | |
784 | return rc; | |
785 | } | |
786 | ||
787 | #ifdef __linux__ | |
788 | int nbd_init(int fd, QIOChannelSocket *sioc, NBDExportInfo *info, | |
789 | Error **errp) | |
790 | { | |
791 | unsigned long sector_size = MAX(BDRV_SECTOR_SIZE, info->min_block); | |
792 | unsigned long sectors = info->size / sector_size; | |
793 | ||
794 | /* FIXME: Once the kernel module is patched to honor block sizes, | |
795 | * and to advertise that fact to user space, we should update the | |
796 | * hand-off to the kernel to use any block sizes we learned. */ | |
797 | assert(!info->request_sizes); | |
798 | if (info->size / sector_size != sectors) { | |
799 | error_setg(errp, "Export size %" PRIu64 " too large for 32-bit kernel", | |
800 | info->size); | |
801 | return -E2BIG; | |
802 | } | |
803 | ||
804 | trace_nbd_init_set_socket(); | |
805 | ||
806 | if (ioctl(fd, NBD_SET_SOCK, (unsigned long) sioc->fd) < 0) { | |
807 | int serrno = errno; | |
808 | error_setg(errp, "Failed to set NBD socket"); | |
809 | return -serrno; | |
810 | } | |
811 | ||
812 | trace_nbd_init_set_block_size(sector_size); | |
813 | ||
814 | if (ioctl(fd, NBD_SET_BLKSIZE, sector_size) < 0) { | |
815 | int serrno = errno; | |
816 | error_setg(errp, "Failed setting NBD block size"); | |
817 | return -serrno; | |
818 | } | |
819 | ||
820 | trace_nbd_init_set_size(sectors); | |
821 | if (info->size % sector_size) { | |
822 | trace_nbd_init_trailing_bytes(info->size % sector_size); | |
823 | } | |
824 | ||
825 | if (ioctl(fd, NBD_SET_SIZE_BLOCKS, sectors) < 0) { | |
826 | int serrno = errno; | |
827 | error_setg(errp, "Failed setting size (in blocks)"); | |
828 | return -serrno; | |
829 | } | |
830 | ||
831 | if (ioctl(fd, NBD_SET_FLAGS, (unsigned long) info->flags) < 0) { | |
832 | if (errno == ENOTTY) { | |
833 | int read_only = (info->flags & NBD_FLAG_READ_ONLY) != 0; | |
834 | trace_nbd_init_set_readonly(); | |
835 | ||
836 | if (ioctl(fd, BLKROSET, (unsigned long) &read_only) < 0) { | |
837 | int serrno = errno; | |
838 | error_setg(errp, "Failed setting read-only attribute"); | |
839 | return -serrno; | |
840 | } | |
841 | } else { | |
842 | int serrno = errno; | |
843 | error_setg(errp, "Failed setting flags"); | |
844 | return -serrno; | |
845 | } | |
846 | } | |
847 | ||
848 | trace_nbd_init_finish(); | |
849 | ||
850 | return 0; | |
851 | } | |
852 | ||
853 | int nbd_client(int fd) | |
854 | { | |
855 | int ret; | |
856 | int serrno; | |
857 | ||
858 | trace_nbd_client_loop(); | |
859 | ||
860 | ret = ioctl(fd, NBD_DO_IT); | |
861 | if (ret < 0 && errno == EPIPE) { | |
862 | /* NBD_DO_IT normally returns EPIPE when someone has disconnected | |
863 | * the socket via NBD_DISCONNECT. We do not want to return 1 in | |
864 | * that case. | |
865 | */ | |
866 | ret = 0; | |
867 | } | |
868 | serrno = errno; | |
869 | ||
870 | trace_nbd_client_loop_ret(ret, strerror(serrno)); | |
871 | ||
872 | trace_nbd_client_clear_queue(); | |
873 | ioctl(fd, NBD_CLEAR_QUE); | |
874 | ||
875 | trace_nbd_client_clear_socket(); | |
876 | ioctl(fd, NBD_CLEAR_SOCK); | |
877 | ||
878 | errno = serrno; | |
879 | return ret; | |
880 | } | |
881 | ||
882 | int nbd_disconnect(int fd) | |
883 | { | |
884 | ioctl(fd, NBD_CLEAR_QUE); | |
885 | ioctl(fd, NBD_DISCONNECT); | |
886 | ioctl(fd, NBD_CLEAR_SOCK); | |
887 | return 0; | |
888 | } | |
889 | ||
890 | #else | |
891 | int nbd_init(int fd, QIOChannelSocket *ioc, NBDExportInfo *info, | |
892 | Error **errp) | |
893 | { | |
894 | error_setg(errp, "nbd_init is only supported on Linux"); | |
895 | return -ENOTSUP; | |
896 | } | |
897 | ||
898 | int nbd_client(int fd) | |
899 | { | |
900 | return -ENOTSUP; | |
901 | } | |
902 | int nbd_disconnect(int fd) | |
903 | { | |
904 | return -ENOTSUP; | |
905 | } | |
906 | #endif | |
907 | ||
908 | int nbd_send_request(QIOChannel *ioc, NBDRequest *request) | |
909 | { | |
910 | uint8_t buf[NBD_REQUEST_SIZE]; | |
911 | ||
912 | trace_nbd_send_request(request->from, request->len, request->handle, | |
913 | request->flags, request->type, | |
914 | nbd_cmd_lookup(request->type)); | |
915 | ||
916 | stl_be_p(buf, NBD_REQUEST_MAGIC); | |
917 | stw_be_p(buf + 4, request->flags); | |
918 | stw_be_p(buf + 6, request->type); | |
919 | stq_be_p(buf + 8, request->handle); | |
920 | stq_be_p(buf + 16, request->from); | |
921 | stl_be_p(buf + 24, request->len); | |
922 | ||
923 | return nbd_write(ioc, buf, sizeof(buf), NULL); | |
924 | } | |
925 | ||
926 | /* nbd_receive_simple_reply | |
927 | * Read simple reply except magic field (which should be already read). | |
928 | * Payload is not read (payload is possible for CMD_READ, but here we even | |
929 | * don't know whether it take place or not). | |
930 | */ | |
931 | static int nbd_receive_simple_reply(QIOChannel *ioc, NBDSimpleReply *reply, | |
932 | Error **errp) | |
933 | { | |
934 | int ret; | |
935 | ||
936 | assert(reply->magic == NBD_SIMPLE_REPLY_MAGIC); | |
937 | ||
938 | ret = nbd_read(ioc, (uint8_t *)reply + sizeof(reply->magic), | |
939 | sizeof(*reply) - sizeof(reply->magic), errp); | |
940 | if (ret < 0) { | |
941 | return ret; | |
942 | } | |
943 | ||
944 | be32_to_cpus(&reply->error); | |
945 | be64_to_cpus(&reply->handle); | |
946 | ||
947 | return 0; | |
948 | } | |
949 | ||
950 | /* nbd_receive_structured_reply_chunk | |
951 | * Read structured reply chunk except magic field (which should be already | |
952 | * read). | |
953 | * Payload is not read. | |
954 | */ | |
955 | static int nbd_receive_structured_reply_chunk(QIOChannel *ioc, | |
956 | NBDStructuredReplyChunk *chunk, | |
957 | Error **errp) | |
958 | { | |
959 | int ret; | |
960 | ||
961 | assert(chunk->magic == NBD_STRUCTURED_REPLY_MAGIC); | |
962 | ||
963 | ret = nbd_read(ioc, (uint8_t *)chunk + sizeof(chunk->magic), | |
964 | sizeof(*chunk) - sizeof(chunk->magic), errp); | |
965 | if (ret < 0) { | |
966 | return ret; | |
967 | } | |
968 | ||
969 | be16_to_cpus(&chunk->flags); | |
970 | be16_to_cpus(&chunk->type); | |
971 | be64_to_cpus(&chunk->handle); | |
972 | be32_to_cpus(&chunk->length); | |
973 | ||
974 | return 0; | |
975 | } | |
976 | ||
977 | /* nbd_receive_reply | |
978 | * Returns 1 on success | |
979 | * 0 on eof, when no data was read (errp is not set) | |
980 | * negative errno on failure (errp is set) | |
981 | */ | |
982 | int nbd_receive_reply(QIOChannel *ioc, NBDReply *reply, Error **errp) | |
983 | { | |
984 | int ret; | |
985 | const char *type; | |
986 | ||
987 | ret = nbd_read_eof(ioc, &reply->magic, sizeof(reply->magic), errp); | |
988 | if (ret <= 0) { | |
989 | return ret; | |
990 | } | |
991 | ||
992 | be32_to_cpus(&reply->magic); | |
993 | ||
994 | switch (reply->magic) { | |
995 | case NBD_SIMPLE_REPLY_MAGIC: | |
996 | ret = nbd_receive_simple_reply(ioc, &reply->simple, errp); | |
997 | if (ret < 0) { | |
998 | break; | |
999 | } | |
1000 | trace_nbd_receive_simple_reply(reply->simple.error, | |
1001 | nbd_err_lookup(reply->simple.error), | |
1002 | reply->handle); | |
1003 | break; | |
1004 | case NBD_STRUCTURED_REPLY_MAGIC: | |
1005 | ret = nbd_receive_structured_reply_chunk(ioc, &reply->structured, errp); | |
1006 | if (ret < 0) { | |
1007 | break; | |
1008 | } | |
1009 | type = nbd_reply_type_lookup(reply->structured.type); | |
1010 | trace_nbd_receive_structured_reply_chunk(reply->structured.flags, | |
1011 | reply->structured.type, type, | |
1012 | reply->structured.handle, | |
1013 | reply->structured.length); | |
1014 | break; | |
1015 | default: | |
1016 | error_setg(errp, "invalid magic (got 0x%" PRIx32 ")", reply->magic); | |
1017 | return -EINVAL; | |
1018 | } | |
1019 | if (ret < 0) { | |
1020 | return ret; | |
1021 | } | |
1022 | ||
1023 | return 1; | |
1024 | } | |
1025 |