4 * Copyright (c) 2003-2008 Fabrice Bellard
5 * Copyright (c) 2010 Red Hat, Inc.
7 * QEMU library functions on POSIX which are shared between QEMU and
10 * Permission is hereby granted, free of charge, to any person obtaining a copy
11 * of this software and associated documentation files (the "Software"), to deal
12 * in the Software without restriction, including without limitation the rights
13 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
14 * copies of the Software, and to permit persons to whom the Software is
15 * furnished to do so, subject to the following conditions:
17 * The above copyright notice and this permission notice shall be included in
18 * all copies or substantial portions of the Software.
20 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
21 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
23 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
24 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
25 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
29 #include "qemu/osdep.h"
32 #include <glib/gprintf.h>
34 #include "qemu-common.h"
35 #include "sysemu/sysemu.h"
37 #include "qapi/error.h"
38 #include "qemu/sockets.h"
39 #include "qemu/thread.h"
41 #include "qemu/cutils.h"
42 #include "qemu/compiler.h"
45 #include <sys/syscall.h>
49 #include <sys/sysctl.h>
56 #include <sys/sysctl.h>
61 #include <mach-o/dyld.h>
65 #include <kernel/image.h>
68 #include "qemu/mmap-alloc.h"
70 #ifdef CONFIG_DEBUG_STACK_USAGE
71 #include "qemu/error-report.h"
74 #define MAX_MEM_PREALLOC_THREAD_COUNT 16
83 typedef struct MemsetThread MemsetThread;
85 static MemsetThread *memset_thread;
86 static int memset_num_threads;
87 static bool memset_thread_failed;
89 static QemuMutex page_mutex;
90 static QemuCond page_cond;
91 static bool threads_created_flag;
93 int qemu_get_thread_id(void)
95 #if defined(__linux__)
96 return syscall(SYS_gettid);
97 #elif defined(__FreeBSD__)
98 /* thread id is up to INT_MAX */
102 #elif defined(__NetBSD__)
104 #elif defined(__OpenBSD__)
111 int qemu_daemon(int nochdir, int noclose)
113 return daemon(nochdir, noclose);
116 bool qemu_write_pidfile(const char *path, Error **errp)
123 struct flock lock = {
125 .l_whence = SEEK_SET,
129 fd = qemu_open_old(path, O_CREAT | O_WRONLY, S_IRUSR | S_IWUSR);
131 error_setg_errno(errp, errno, "Cannot open pid file");
135 if (fstat(fd, &b) < 0) {
136 error_setg_errno(errp, errno, "Cannot stat file");
140 if (fcntl(fd, F_SETLK, &lock)) {
141 error_setg_errno(errp, errno, "Cannot lock pid file");
146 * Now make sure the path we locked is the same one that now
147 * exists on the filesystem.
149 if (stat(path, &a) < 0) {
151 * PID file disappeared, someone else must be racing with
158 if (a.st_ino == b.st_ino) {
163 * PID file was recreated, someone else must be racing with
169 if (ftruncate(fd, 0) < 0) {
170 error_setg_errno(errp, errno, "Failed to truncate pid file");
174 snprintf(pidstr, sizeof(pidstr), FMT_pid "\n", getpid());
175 if (write(fd, pidstr, strlen(pidstr)) != strlen(pidstr)) {
176 error_setg(errp, "Failed to write pid file");
189 void *qemu_oom_check(void *ptr)
192 fprintf(stderr, "Failed to allocate memory: %s\n", strerror(errno));
198 void *qemu_try_memalign(size_t alignment, size_t size)
202 if (alignment < sizeof(void*)) {
203 alignment = sizeof(void*);
205 g_assert(is_power_of_2(alignment));
208 #if defined(CONFIG_POSIX_MEMALIGN)
210 ret = posix_memalign(&ptr, alignment, size);
215 #elif defined(CONFIG_BSD)
218 ptr = memalign(alignment, size);
220 trace_qemu_memalign(alignment, size, ptr);
224 void *qemu_memalign(size_t alignment, size_t size)
226 return qemu_oom_check(qemu_try_memalign(alignment, size));
229 /* alloc shared memory pages */
230 void *qemu_anon_ram_alloc(size_t size, uint64_t *alignment, bool shared)
232 size_t align = QEMU_VMALLOC_ALIGN;
233 void *ptr = qemu_ram_mmap(-1, size, align, false, shared, false, 0);
235 if (ptr == MAP_FAILED) {
243 trace_qemu_anon_ram_alloc(size, ptr);
247 void qemu_vfree(void *ptr)
249 trace_qemu_vfree(ptr);
253 void qemu_anon_ram_free(void *ptr, size_t size)
255 trace_qemu_anon_ram_free(ptr, size);
256 qemu_ram_munmap(-1, ptr, size);
259 void qemu_set_block(int fd)
262 f = fcntl(fd, F_GETFL);
264 f = fcntl(fd, F_SETFL, f & ~O_NONBLOCK);
268 int qemu_try_set_nonblock(int fd)
271 f = fcntl(fd, F_GETFL);
275 if (fcntl(fd, F_SETFL, f | O_NONBLOCK) == -1) {
281 void qemu_set_nonblock(int fd)
284 f = qemu_try_set_nonblock(fd);
288 int socket_set_fast_reuse(int fd)
292 ret = setsockopt(fd, SOL_SOCKET, SO_REUSEADDR,
293 (const char *)&val, sizeof(val));
300 void qemu_set_cloexec(int fd)
303 f = fcntl(fd, F_GETFD);
305 f = fcntl(fd, F_SETFD, f | FD_CLOEXEC);
310 * Creates a pipe with FD_CLOEXEC set on both file descriptors
312 int qemu_pipe(int pipefd[2])
317 ret = pipe2(pipefd, O_CLOEXEC);
318 if (ret != -1 || errno != ENOSYS) {
324 qemu_set_cloexec(pipefd[0]);
325 qemu_set_cloexec(pipefd[1]);
332 qemu_get_local_state_pathname(const char *relative_pathname)
334 g_autofree char *dir = g_strdup_printf("%s/%s",
335 CONFIG_QEMU_LOCALSTATEDIR,
337 return get_relocated_path(dir);
340 void qemu_set_tty_echo(int fd, bool echo)
347 tty.c_lflag |= ECHO | ECHONL | ICANON | IEXTEN;
349 tty.c_lflag &= ~(ECHO | ECHONL | ICANON | IEXTEN);
352 tcsetattr(fd, TCSANOW, &tty);
355 static const char *exec_dir;
357 void qemu_init_exec_dir(const char *argv0)
366 #if defined(__linux__)
369 len = readlink("/proc/self/exe", buf, sizeof(buf) - 1);
375 #elif defined(__FreeBSD__) \
376 || (defined(__NetBSD__) && defined(KERN_PROC_PATHNAME))
378 #if defined(__FreeBSD__)
379 static int mib[4] = {CTL_KERN, KERN_PROC, KERN_PROC_PATHNAME, -1};
381 static int mib[4] = {CTL_KERN, KERN_PROC_ARGS, -1, KERN_PROC_PATHNAME};
383 size_t len = sizeof(buf) - 1;
386 if (!sysctl(mib, ARRAY_SIZE(mib), buf, &len, NULL, 0) &&
388 buf[sizeof(buf) - 1] = '\0';
392 #elif defined(__APPLE__)
394 char fpath[PATH_MAX];
395 uint32_t len = sizeof(fpath);
396 if (_NSGetExecutablePath(fpath, &len) == 0) {
397 p = realpath(fpath, buf);
403 #elif defined(__HAIKU__)
409 while (get_next_image_info(0, &c, &ii) == B_OK) {
410 if (ii.type == B_APP_IMAGE) {
411 strncpy(buf, ii.name, sizeof(buf));
412 buf[sizeof(buf) - 1] = 0;
419 /* If we don't have any way of figuring out the actual executable
420 location then try argv[0]. */
422 p = realpath(argv0, buf);
425 exec_dir = g_path_get_dirname(p);
427 exec_dir = CONFIG_BINDIR;
431 const char *qemu_get_exec_dir(void)
436 static void sigbus_handler(int signal)
440 for (i = 0; i < memset_num_threads; i++) {
441 if (qemu_thread_is_self(&memset_thread[i].pgthread)) {
442 siglongjmp(memset_thread[i].env, 1);
448 static void *do_touch_pages(void *arg)
450 MemsetThread *memset_args = (MemsetThread *)arg;
451 sigset_t set, oldset;
454 * On Linux, the page faults from the loop below can cause mmap_sem
455 * contention with allocation of the thread stacks. Do not start
456 * clearing until all threads have been created.
458 qemu_mutex_lock(&page_mutex);
459 while(!threads_created_flag){
460 qemu_cond_wait(&page_cond, &page_mutex);
462 qemu_mutex_unlock(&page_mutex);
466 sigaddset(&set, SIGBUS);
467 pthread_sigmask(SIG_UNBLOCK, &set, &oldset);
469 if (sigsetjmp(memset_args->env, 1)) {
470 memset_thread_failed = true;
472 char *addr = memset_args->addr;
473 size_t numpages = memset_args->numpages;
474 size_t hpagesize = memset_args->hpagesize;
476 for (i = 0; i < numpages; i++) {
478 * Read & write back the same value, so we don't
479 * corrupt existing user/app data that might be
482 * 'volatile' to stop compiler optimizing this away
485 * TODO: get a better solution from kernel so we
486 * don't need to write at all so we don't cause
487 * wear on the storage backing the region...
489 *(volatile char *)addr = *addr;
493 pthread_sigmask(SIG_SETMASK, &oldset, NULL);
497 static inline int get_memset_num_threads(int smp_cpus)
499 long host_procs = sysconf(_SC_NPROCESSORS_ONLN);
502 if (host_procs > 0) {
503 ret = MIN(MIN(host_procs, MAX_MEM_PREALLOC_THREAD_COUNT), smp_cpus);
505 /* In case sysconf() fails, we fall back to single threaded */
509 static bool touch_all_pages(char *area, size_t hpagesize, size_t numpages,
512 static gsize initialized = 0;
513 size_t numpages_per_thread, leftover;
517 if (g_once_init_enter(&initialized)) {
518 qemu_mutex_init(&page_mutex);
519 qemu_cond_init(&page_cond);
520 g_once_init_leave(&initialized, 1);
523 memset_thread_failed = false;
524 threads_created_flag = false;
525 memset_num_threads = get_memset_num_threads(smp_cpus);
526 memset_thread = g_new0(MemsetThread, memset_num_threads);
527 numpages_per_thread = numpages / memset_num_threads;
528 leftover = numpages % memset_num_threads;
529 for (i = 0; i < memset_num_threads; i++) {
530 memset_thread[i].addr = addr;
531 memset_thread[i].numpages = numpages_per_thread + (i < leftover);
532 memset_thread[i].hpagesize = hpagesize;
533 qemu_thread_create(&memset_thread[i].pgthread, "touch_pages",
534 do_touch_pages, &memset_thread[i],
535 QEMU_THREAD_JOINABLE);
536 addr += memset_thread[i].numpages * hpagesize;
539 qemu_mutex_lock(&page_mutex);
540 threads_created_flag = true;
541 qemu_cond_broadcast(&page_cond);
542 qemu_mutex_unlock(&page_mutex);
544 for (i = 0; i < memset_num_threads; i++) {
545 qemu_thread_join(&memset_thread[i].pgthread);
547 g_free(memset_thread);
548 memset_thread = NULL;
550 return memset_thread_failed;
553 void os_mem_prealloc(int fd, char *area, size_t memory, int smp_cpus,
557 struct sigaction act, oldact;
558 size_t hpagesize = qemu_fd_getpagesize(fd);
559 size_t numpages = DIV_ROUND_UP(memory, hpagesize);
561 memset(&act, 0, sizeof(act));
562 act.sa_handler = &sigbus_handler;
565 ret = sigaction(SIGBUS, &act, &oldact);
567 error_setg_errno(errp, errno,
568 "os_mem_prealloc: failed to install signal handler");
572 /* touch pages simultaneously */
573 if (touch_all_pages(area, hpagesize, numpages, smp_cpus)) {
574 error_setg(errp, "os_mem_prealloc: Insufficient free host memory "
575 "pages available to allocate guest RAM");
578 ret = sigaction(SIGBUS, &oldact, NULL);
580 /* Terminate QEMU since it can't recover from error */
581 perror("os_mem_prealloc: failed to reinstall signal handler");
586 char *qemu_get_pid_name(pid_t pid)
590 #if defined(__FreeBSD__)
591 /* BSDs don't have /proc, but they provide a nice substitute */
592 struct kinfo_proc *proc = kinfo_getproc(pid);
595 name = g_strdup(proc->ki_comm);
599 /* Assume a system with reasonable procfs */
603 pid_path = g_strdup_printf("/proc/%d/cmdline", pid);
604 g_file_get_contents(pid_path, &name, &len, NULL);
612 pid_t qemu_fork(Error **errp)
614 sigset_t oldmask, newmask;
615 struct sigaction sig_action;
620 * Need to block signals now, so that child process can safely
621 * kill off caller's signal handlers without a race.
623 sigfillset(&newmask);
624 if (pthread_sigmask(SIG_SETMASK, &newmask, &oldmask) != 0) {
625 error_setg_errno(errp, errno,
626 "cannot block signals");
634 /* attempt to restore signal mask, but ignore failure, to
635 * avoid obscuring the fork failure */
636 (void)pthread_sigmask(SIG_SETMASK, &oldmask, NULL);
637 error_setg_errno(errp, saved_errno,
638 "cannot fork child process");
644 /* Restore our original signal mask now that the child is
645 * safely running. Only documented failures are EFAULT (not
646 * possible, since we are using just-grabbed mask) or EINVAL
647 * (not possible, since we are using correct arguments). */
648 (void)pthread_sigmask(SIG_SETMASK, &oldmask, NULL);
653 /* Clear out all signal handlers from parent so nothing
654 * unexpected can happen in our child once we unblock
656 sig_action.sa_handler = SIG_DFL;
657 sig_action.sa_flags = 0;
658 sigemptyset(&sig_action.sa_mask);
660 for (i = 1; i < NSIG; i++) {
661 /* Only possible errors are EFAULT or EINVAL The former
662 * won't happen, the latter we expect, so no need to check
664 (void)sigaction(i, &sig_action, NULL);
667 /* Unmask all signals in child, since we've no idea what the
668 * caller's done with their signal mask and don't want to
669 * propagate that to children */
670 sigemptyset(&newmask);
671 if (pthread_sigmask(SIG_SETMASK, &newmask, NULL) != 0) {
672 Error *local_err = NULL;
673 error_setg_errno(&local_err, errno,
674 "cannot unblock signals");
675 error_report_err(local_err);
682 void *qemu_alloc_stack(size_t *sz)
684 void *ptr, *guardpage;
686 #ifdef CONFIG_DEBUG_STACK_USAGE
689 size_t pagesz = qemu_real_host_page_size;
690 #ifdef _SC_THREAD_STACK_MIN
691 /* avoid stacks smaller than _SC_THREAD_STACK_MIN */
692 long min_stack_sz = sysconf(_SC_THREAD_STACK_MIN);
693 *sz = MAX(MAX(min_stack_sz, 0), *sz);
695 /* adjust stack size to a multiple of the page size */
696 *sz = ROUND_UP(*sz, pagesz);
697 /* allocate one extra page for the guard page */
700 flags = MAP_PRIVATE | MAP_ANONYMOUS;
701 #if defined(MAP_STACK) && defined(__OpenBSD__)
702 /* Only enable MAP_STACK on OpenBSD. Other OS's such as
703 * Linux/FreeBSD/NetBSD have a flag with the same name
704 * but have differing functionality. OpenBSD will SEGV
705 * if it spots execution with a stack pointer pointing
706 * at memory that was not allocated with MAP_STACK.
711 ptr = mmap(NULL, *sz, PROT_READ | PROT_WRITE, flags, -1, 0);
712 if (ptr == MAP_FAILED) {
713 perror("failed to allocate memory for stack");
717 #if defined(HOST_IA64)
718 /* separate register stack */
719 guardpage = ptr + (((*sz - pagesz) / 2) & ~pagesz);
720 #elif defined(HOST_HPPA)
722 guardpage = ptr + *sz - pagesz;
724 /* stack grows down */
727 if (mprotect(guardpage, pagesz, PROT_NONE) != 0) {
728 perror("failed to set up stack guard page");
732 #ifdef CONFIG_DEBUG_STACK_USAGE
733 for (ptr2 = ptr + pagesz; ptr2 < ptr + *sz; ptr2 += sizeof(uint32_t)) {
734 *(uint32_t *)ptr2 = 0xdeadbeaf;
741 #ifdef CONFIG_DEBUG_STACK_USAGE
742 static __thread unsigned int max_stack_usage;
745 void qemu_free_stack(void *stack, size_t sz)
747 #ifdef CONFIG_DEBUG_STACK_USAGE
751 for (ptr = stack + qemu_real_host_page_size; ptr < stack + sz;
752 ptr += sizeof(uint32_t)) {
753 if (*(uint32_t *)ptr != 0xdeadbeaf) {
757 usage = sz - (uintptr_t) (ptr - stack);
758 if (usage > max_stack_usage) {
759 error_report("thread %d max stack usage increased from %u to %u",
760 qemu_get_thread_id(), max_stack_usage, usage);
761 max_stack_usage = usage;
769 * Disable CFI checks.
770 * We are going to call a signal hander directly. Such handler may or may not
771 * have been defined in our binary, so there's no guarantee that the pointer
772 * used to set the handler is a cfi-valid pointer. Since the handlers are
773 * stored in kernel memory, changing the handler to an attacker-defined
774 * function requires being able to call a sigaction() syscall,
775 * which is not as easy as overwriting a pointer in memory.
778 void sigaction_invoke(struct sigaction *action,
779 struct qemu_signalfd_siginfo *info)
782 si.si_signo = info->ssi_signo;
783 si.si_errno = info->ssi_errno;
784 si.si_code = info->ssi_code;
786 /* Convert the minimal set of fields defined by POSIX.
787 * Positive si_code values are reserved for kernel-generated
788 * signals, where the valid siginfo fields are determined by
789 * the signal number. But according to POSIX, it is unspecified
790 * whether SI_USER and SI_QUEUE have values less than or equal to
793 if (info->ssi_code == SI_USER || info->ssi_code == SI_QUEUE ||
794 info->ssi_code <= 0) {
796 si.si_pid = info->ssi_pid;
797 si.si_uid = info->ssi_uid;
798 } else if (info->ssi_signo == SIGILL || info->ssi_signo == SIGFPE ||
799 info->ssi_signo == SIGSEGV || info->ssi_signo == SIGBUS) {
800 si.si_addr = (void *)(uintptr_t)info->ssi_addr;
801 } else if (info->ssi_signo == SIGCHLD) {
802 si.si_pid = info->ssi_pid;
803 si.si_status = info->ssi_status;
804 si.si_uid = info->ssi_uid;
806 action->sa_sigaction(info->ssi_signo, &si, NULL);
809 #ifndef HOST_NAME_MAX
810 # ifdef _POSIX_HOST_NAME_MAX
811 # define HOST_NAME_MAX _POSIX_HOST_NAME_MAX
813 # define HOST_NAME_MAX 255
817 char *qemu_get_host_name(Error **errp)
820 g_autofree char *hostname = NULL;
822 #ifdef _SC_HOST_NAME_MAX
823 len = sysconf(_SC_HOST_NAME_MAX);
824 #endif /* _SC_HOST_NAME_MAX */
830 /* Unfortunately, gethostname() below does not guarantee a
831 * NULL terminated string. Therefore, allocate one byte more
833 hostname = g_new0(char, len + 1);
835 if (gethostname(hostname, len) < 0) {
836 error_setg_errno(errp, errno,
837 "cannot get hostname");
841 return g_steal_pointer(&hostname);
844 size_t qemu_get_host_physmem(void)
846 #ifdef _SC_PHYS_PAGES
847 long pages = sysconf(_SC_PHYS_PAGES);
849 if (pages > SIZE_MAX / qemu_real_host_page_size) {
852 return pages * qemu_real_host_page_size;