From patchwork Fri Mar 26 17:15:42 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Cole Robinson X-Patchwork-Id: 409527 Delivered-To: patch@linaro.org Received: by 2002:a02:8562:0:0:0:0:0 with SMTP id g89csp1613902jai; Fri, 26 Mar 2021 10:16:13 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyq3CmyXDQ26SUXmsr896NGbWuW6BCgEA9xjQP03VDa/iBMV04REHWTSAoa4GUrWrNxaq73 X-Received: by 2002:a17:906:f896:: with SMTP id lg22mr16031846ejb.124.1616778973724; Fri, 26 Mar 2021 10:16:13 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1616778973; cv=none; d=google.com; s=arc-20160816; b=E4ghysgMe3Q1df61EwbaruTPSZl2sMHoGBAmbgZ8Jx4LVvgm1AaSBi8H0JTraiCqsw tBCgq8tsh22eiwzTN7f8J3OlWOGBTjSXoGT1PmgaM0cM5SdCsiLc3q90FmoWBwnKXcIV pbX51syM0QF34wV9nEs8PvXBgww/LnZyMKdNmdyGxp5vcfEFVKXzgMo4Ah4oiCDFM7Oa X6EYY3cPM4M7eU0Nq/8OFjvAKgViNM9SScoEY1oWrWZ2JClZa7rNkOgiusrgigcGzm3J tC+ekyzWEg/QK7Gs4DzFBiPsxjk3amHY6eNUmi4M2nhrYTLv+MUDAZzBtgGcsPlEN8Ds 9ofQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:errors-to:sender:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:cc :mime-version:references:in-reply-to:message-id:date:subject:to:from :delivered-to:dkim-signature; bh=/TVdU8iAOK7BKV3566Mj7UOsiFZsJBzAzCljNiexwyc=; b=zN8kViiwKxjZzaaR5W1NbUfWq0LhP3gLooMFKSf2KSQj4+W8+fj84dWBf3l5hgbshE b3gMcFy2HjeJJSPUcCAop5fHIjvpuJwEx/w/LQxMtxZkcLHuVxouextvoWyEPYgMGyCc HCo7qMzLA1i9fRNYyVcnqPQqyHYfMSUD/wyHnd6kIx7AlU5lTZzOqMNllS8ZuvUMJbnq tVCoyGLKGh6UnBI1DRVVD/8Ow4z95EP/e5Pijpa2krO2ztue2oPDbH9YVILbRoTR/xEL gswjm/RCi09rVarCYV0+kGfGcd23Hs8N62fuFMqMwe6AJYphdc7G7/KsgWVr5DIJCX2z FwgA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=ZMlD4ZvR; spf=pass (google.com: domain of libvir-list-bounces@redhat.com designates 216.205.24.124 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Return-Path: Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com. [216.205.24.124]) by mx.google.com with ESMTPS id t6si7581492edw.202.2021.03.26.10.16.13 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 26 Mar 2021 10:16:13 -0700 (PDT) Received-SPF: pass (google.com: domain of libvir-list-bounces@redhat.com designates 216.205.24.124 as permitted sender) client-ip=216.205.24.124; Authentication-Results: mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=ZMlD4ZvR; spf=pass (google.com: domain of libvir-list-bounces@redhat.com designates 216.205.24.124 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1616778972; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post; bh=/TVdU8iAOK7BKV3566Mj7UOsiFZsJBzAzCljNiexwyc=; b=ZMlD4ZvRsYN+AusHBAuF4tD5aqHRryXBaODRRqKFR6lPSLwJ0zb4R+xsh6nYGukDssmoyD Q++Bf8Bby463BjbaxqD5vp+QOko1FUeIAzktTVqQLDg3AKlWnU3MbcOlhEm3TNtvQMLBYc FIK9qSj0jWazUtDCNwlvzSkiB2zqZdQ= Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-307-G19dcfM9Pli3oMKRrSjNwQ-1; Fri, 26 Mar 2021 13:16:09 -0400 X-MC-Unique: G19dcfM9Pli3oMKRrSjNwQ-1 Received: from smtp.corp.redhat.com (int-mx08.intmail.prod.int.phx2.redhat.com [10.5.11.23]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id CF4FE87A83C; Fri, 26 Mar 2021 17:16:02 +0000 (UTC) Received: from colo-mx.corp.redhat.com (colo-mx02.intmail.prod.int.phx2.redhat.com [10.5.11.21]) by smtp.corp.redhat.com (Postfix) with ESMTPS id F150819C71; Fri, 26 Mar 2021 17:16:01 +0000 (UTC) Received: from lists01.pubmisc.prod.ext.phx2.redhat.com (lists01.pubmisc.prod.ext.phx2.redhat.com [10.5.19.33]) by colo-mx.corp.redhat.com (Postfix) with ESMTP id 06A054A7C8; Fri, 26 Mar 2021 17:16:01 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx03.intmail.prod.int.phx2.redhat.com [10.5.11.13]) by lists01.pubmisc.prod.ext.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id 12QHFwhF007916 for ; Fri, 26 Mar 2021 13:15:58 -0400 Received: by smtp.corp.redhat.com (Postfix) id 7F5FD1B5C3; Fri, 26 Mar 2021 17:15:58 +0000 (UTC) Delivered-To: libvir-list@redhat.com Received: from worklaptop.home (ovpn-117-183.rdu2.redhat.com [10.10.117.183]) by smtp.corp.redhat.com (Postfix) with ESMTP id 1DF31646DC; Fri, 26 Mar 2021 17:15:58 +0000 (UTC) From: Cole Robinson To: libvir-list@redhat.com Subject: [PATCH v2 1/2] conf: Introduce for Date: Fri, 26 Mar 2021 13:15:42 -0400 Message-Id: <8698448bde8cdaaf3f3c797fcbd6ebfccf23c669.1616778890.git.crobinso@redhat.com> In-Reply-To: References: MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.13 X-loop: libvir-list@redhat.com Cc: Cole Robinson X-BeenThere: libvir-list@redhat.com X-Mailman-Version: 2.1.12 Precedence: junk List-Id: Development discussions about the libvirt library & tools List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: libvir-list-bounces@redhat.com Errors-To: libvir-list-bounces@redhat.com X-Scanned-By: MIMEDefang 2.84 on 10.5.11.23 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=libvir-list-bounces@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com This adds a new XML element This will be used by qemu virtiofs Signed-off-by: Cole Robinson --- docs/formatdomain.rst | 6 +++++ docs/schemas/domaincommon.rng | 12 ++++++++++ src/conf/domain_conf.c | 23 +++++++++++++++++++ src/conf/domain_conf.h | 10 ++++++++ src/libvirt_private.syms | 1 + .../vhost-user-fs-fd-memory.xml | 1 + 6 files changed, 53 insertions(+) -- 2.30.2 diff --git a/docs/formatdomain.rst b/docs/formatdomain.rst index 9392c80113..42217a4005 100644 --- a/docs/formatdomain.rst +++ b/docs/formatdomain.rst @@ -3234,6 +3234,7 @@ A directory on the host that can be accessed directly from the guest. + @@ -3358,6 +3359,11 @@ A directory on the host that can be accessed directly from the guest. ``cache`` element, possible ``mode`` values being ``none`` and ``always``. Locking can be controlled via the ``lock`` element - attributes ``posix`` and ``flock`` both accepting values ``on`` or ``off``. ( :since:`Since 6.2.0` ) + The sandboxing method used by virtiofsd can be configured with the ``sandbox`` + element, possible ``mode`` values being ``namespace`` and + ``chroot``, see the + `virtiofsd documentation `__ + for more details. ( :since:`Since 7.2.0` ) ``source`` The resource on the host that is being accessed in the guest. The ``name`` attribute must be used with ``type='template'``, and the ``dir`` attribute diff --git a/docs/schemas/domaincommon.rng b/docs/schemas/domaincommon.rng index 1dbfc68f18..6404ebf210 100644 --- a/docs/schemas/domaincommon.rng +++ b/docs/schemas/domaincommon.rng @@ -2960,6 +2960,18 @@ + + + + + + namespace + chroot + + + + + diff --git a/src/conf/domain_conf.c b/src/conf/domain_conf.c index b0eba9f7bd..70a900ee25 100644 --- a/src/conf/domain_conf.c +++ b/src/conf/domain_conf.c @@ -538,6 +538,13 @@ VIR_ENUM_IMPL(virDomainFSCacheMode, "always", ); +VIR_ENUM_IMPL(virDomainFSSandboxMode, + VIR_DOMAIN_FS_SANDBOX_MODE_LAST, + "default", + "namespace", + "chroot", +); + VIR_ENUM_IMPL(virDomainNet, VIR_DOMAIN_NET_TYPE_LAST, @@ -10373,6 +10380,7 @@ virDomainFSDefParseXML(virDomainXMLOptionPtr xmlopt, g_autofree char *binary = virXPathString("string(./binary/@path)", ctxt); g_autofree char *xattr = virXPathString("string(./binary/@xattr)", ctxt); g_autofree char *cache = virXPathString("string(./binary/cache/@mode)", ctxt); + g_autofree char *sandbox = virXPathString("string(./binary/sandbox/@mode)", ctxt); g_autofree char *posix_lock = virXPathString("string(./binary/lock/@posix)", ctxt); g_autofree char *flock = virXPathString("string(./binary/lock/@flock)", ctxt); int val; @@ -10406,6 +10414,16 @@ virDomainFSDefParseXML(virDomainXMLOptionPtr xmlopt, def->cache = val; } + if (sandbox) { + if ((val = virDomainFSSandboxModeTypeFromString(sandbox)) <= 0) { + virReportError(VIR_ERR_XML_ERROR, + _("cannot parse sandbox mode '%s' for virtiofs"), + sandbox); + goto error; + } + def->sandbox = val; + } + if (posix_lock) { if ((val = virTristateSwitchTypeFromString(posix_lock)) <= 0) { virReportError(VIR_ERR_CONFIG_UNSUPPORTED, @@ -25483,6 +25501,11 @@ virDomainFSDefFormat(virBufferPtr buf, virDomainFSCacheModeTypeToString(def->cache)); } + if (def->sandbox != VIR_DOMAIN_FS_SANDBOX_MODE_DEFAULT) { + virBufferAsprintf(&binaryBuf, "\n", + virDomainFSSandboxModeTypeToString(def->sandbox)); + } + if (def->posix_lock != VIR_TRISTATE_SWITCH_ABSENT) { virBufferAsprintf(&lockAttrBuf, " posix='%s'", virTristateSwitchTypeToString(def->posix_lock)); diff --git a/src/conf/domain_conf.h b/src/conf/domain_conf.h index 0b8895bbdf..d77b04847b 100644 --- a/src/conf/domain_conf.h +++ b/src/conf/domain_conf.h @@ -846,6 +846,14 @@ typedef enum { VIR_DOMAIN_FS_CACHE_MODE_LAST } virDomainFSCacheMode; +typedef enum { + VIR_DOMAIN_FS_SANDBOX_MODE_DEFAULT = 0, + VIR_DOMAIN_FS_SANDBOX_MODE_NAMESPACE, + VIR_DOMAIN_FS_SANDBOX_MODE_CHROOT, + + VIR_DOMAIN_FS_SANDBOX_MODE_LAST +} virDomainFSSandboxMode; + struct _virDomainFSDef { int type; int fsdriver; /* enum virDomainFSDriverType */ @@ -870,6 +878,7 @@ struct _virDomainFSDef { virDomainFSCacheMode cache; virTristateSwitch posix_lock; virTristateSwitch flock; + virDomainFSSandboxMode sandbox; virDomainVirtioOptionsPtr virtio; virObjectPtr privateData; }; @@ -3800,6 +3809,7 @@ VIR_ENUM_DECL(virDomainFSAccessMode); VIR_ENUM_DECL(virDomainFSWrpolicy); VIR_ENUM_DECL(virDomainFSModel); VIR_ENUM_DECL(virDomainFSCacheMode); +VIR_ENUM_DECL(virDomainFSSandboxMode); VIR_ENUM_DECL(virDomainNet); VIR_ENUM_DECL(virDomainNetBackend); VIR_ENUM_DECL(virDomainNetVirtioTxMode); diff --git a/src/libvirt_private.syms b/src/libvirt_private.syms index cb9fe7c80a..04b2bc9dcd 100644 --- a/src/libvirt_private.syms +++ b/src/libvirt_private.syms @@ -414,6 +414,7 @@ virDomainFSDriverTypeToString; virDomainFSIndexByName; virDomainFSInsert; virDomainFSRemove; +virDomainFSSandboxModeTypeToString; virDomainFSTypeFromString; virDomainFSTypeToString; virDomainFSWrpolicyTypeFromString; diff --git a/tests/qemuxml2argvdata/vhost-user-fs-fd-memory.xml b/tests/qemuxml2argvdata/vhost-user-fs-fd-memory.xml index 2277850c2c..abddf0870b 100644 --- a/tests/qemuxml2argvdata/vhost-user-fs-fd-memory.xml +++ b/tests/qemuxml2argvdata/vhost-user-fs-fd-memory.xml @@ -30,6 +30,7 @@ + From patchwork Fri Mar 26 17:15:43 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Cole Robinson X-Patchwork-Id: 409528 Delivered-To: patch@linaro.org Received: by 2002:a02:8562:0:0:0:0:0 with SMTP id g89csp1614003jai; Fri, 26 Mar 2021 10:16:22 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwI4/mirEr6SXmRsZVYCfZWwydDowVQlTmn1lomln20RabjNKE9cQztSOQse4kgWtI6PT68 X-Received: by 2002:a17:906:fa04:: with SMTP id lo4mr16606798ejb.44.1616778982548; Fri, 26 Mar 2021 10:16:22 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1616778982; cv=none; d=google.com; s=arc-20160816; b=q+HHbyjnllxEcbfmjF5Kl/TiLat3wJepoWhNP/RV3nAQGVM9bZ6RQaagjpCfjwX9e4 NsWMSgSadndFqHxsACWJixPI/kj2hi+P6qtX1Fzi7xcU5Flpp/xk3HEH1SlZd9xB0yPa EqSgOMoUmeWvadXejHMvBJdv0N8+0BWSMTfalUmyhRPnZD3zcE3GEKfkMLWbzFlS7meQ 9I9TG0Q5fwmXxUdF+UE5XDv34Zhu8yXgSrzSuC2QjU0fgLd8UiEikWtj7OFOmUIhYvPf IRVmtOHbTU3KR0aUCFfLDLB3NfEf5FZ/CHr5S0w7Mtiwjgwj9nuR96T4+oGozYnyt2UU 0Pbw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:errors-to:sender:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:cc :mime-version:references:in-reply-to:message-id:date:subject:to:from :delivered-to:dkim-signature; bh=Sl9Hk+eWUm2pWeHrm3+Hp3QmhvpY0rlmlYMwCoGl8+k=; b=wM8pUylH+OcMwMyxk06KZ8DcLjDim/15oT4V28EZ405D4EFH89o1/5wEzhZ+dfg5c+ YKi1GtKbJ3ayb1dbv49HkYV0b5vmv9xQGb7eteZVTHxQnyUQCozTlzkw4WcYTgddPedR Sp0c73tgoaAC4LMux3YNXfAYwJs6q3fMl2X9/oCxWxV82Czy95ZsaEQP4ZR6AGZnUHgi 1FaCKoFLOcVjbiOtA3gqHZaYeQ0FxFY8HkLBD5+LmLX8WYf2r3Ss+KYH6Pb1gWqDBd02 2us0/bNCV1tGp3ov0KfaTjmp8DMGNJJE7K4GHVvuluHD1Aw/Yc40nU2V+eyLNPRga/aY 4xEQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=fpqegaN7; spf=pass (google.com: domain of libvir-list-bounces@redhat.com designates 216.205.24.124 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Return-Path: Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com. [216.205.24.124]) by mx.google.com with ESMTPS id ze11si7379838ejb.434.2021.03.26.10.16.22 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 26 Mar 2021 10:16:22 -0700 (PDT) Received-SPF: pass (google.com: domain of libvir-list-bounces@redhat.com designates 216.205.24.124 as permitted sender) client-ip=216.205.24.124; Authentication-Results: mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=fpqegaN7; spf=pass (google.com: domain of libvir-list-bounces@redhat.com designates 216.205.24.124 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1616778981; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post; bh=Sl9Hk+eWUm2pWeHrm3+Hp3QmhvpY0rlmlYMwCoGl8+k=; b=fpqegaN7uLLGB152W8dBpuAlCKKdiasv4s6S73W724I5iUZK/dDuVMhN0G2zlAuDNnsx5Y 1jU+cBKi4i4n8MW8VeS1xIbcg4M0ijm6w0I9ao2wSJZzScMou7yHA+OKJ9zyCq+xr4QAnE EywaRO4UD12ae10FgQ9TZMw2WPIDiWI= Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-59-XXrVKGbAOF-PVTStMKgR7w-1; Fri, 26 Mar 2021 13:16:19 -0400 X-MC-Unique: XXrVKGbAOF-PVTStMKgR7w-1 Received: from smtp.corp.redhat.com (int-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id 8AEB61853022; Fri, 26 Mar 2021 17:16:12 +0000 (UTC) Received: from colo-mx.corp.redhat.com (colo-mx02.intmail.prod.int.phx2.redhat.com [10.5.11.21]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 6294C2B9FA; Fri, 26 Mar 2021 17:16:12 +0000 (UTC) Received: from lists01.pubmisc.prod.ext.phx2.redhat.com (lists01.pubmisc.prod.ext.phx2.redhat.com [10.5.19.33]) by colo-mx.corp.redhat.com (Postfix) with ESMTP id 205654A700; Fri, 26 Mar 2021 17:16:12 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx03.intmail.prod.int.phx2.redhat.com [10.5.11.13]) by lists01.pubmisc.prod.ext.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id 12QHFxCR007928 for ; Fri, 26 Mar 2021 13:15:59 -0400 Received: by smtp.corp.redhat.com (Postfix) id 1999F226EE; Fri, 26 Mar 2021 17:15:59 +0000 (UTC) Delivered-To: libvir-list@redhat.com Received: from worklaptop.home (ovpn-117-183.rdu2.redhat.com [10.10.117.183]) by smtp.corp.redhat.com (Postfix) with ESMTP id A69F8646DC; Fri, 26 Mar 2021 17:15:58 +0000 (UTC) From: Cole Robinson To: libvir-list@redhat.com Subject: [PATCH v2 2/2] qemu: virtiofs: support Date: Fri, 26 Mar 2021 13:15:43 -0400 Message-Id: In-Reply-To: References: MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.13 X-loop: libvir-list@redhat.com Cc: Cole Robinson X-BeenThere: libvir-list@redhat.com X-Mailman-Version: 2.1.12 Precedence: junk List-Id: Development discussions about the libvirt library & tools List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: libvir-list-bounces@redhat.com Errors-To: libvir-list-bounces@redhat.com X-Scanned-By: MIMEDefang 2.79 on 10.5.11.11 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=libvir-list-bounces@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com This maps to `virtiofsd -o sandbox=chroot|namespace`, which was added in qemu 5.2.0: https://git.qemu.org/?p=qemu.git;a=commit;h=06844584b62a43384642f7243b0fc01c9fff0fc7 Signed-off-by: Cole Robinson --- src/qemu/qemu_validate.c | 7 +++++++ src/qemu/qemu_virtiofs.c | 2 ++ 2 files changed, 9 insertions(+) -- 2.30.2 diff --git a/src/qemu/qemu_validate.c b/src/qemu/qemu_validate.c index 6043f974ce..b272ab0087 100644 --- a/src/qemu/qemu_validate.c +++ b/src/qemu/qemu_validate.c @@ -4081,6 +4081,13 @@ qemuValidateDomainDeviceDefFS(virDomainFSDefPtr fs, } } + if (fs->fsdriver != VIR_DOMAIN_FS_DRIVER_TYPE_VIRTIOFS && + fs->sandbox != VIR_DOMAIN_FS_SANDBOX_MODE_DEFAULT) { + virReportError(VIR_ERR_CONFIG_UNSUPPORTED, "%s", + _("sandbox can only be used with driver=virtiofs")); + return -1; + } + switch ((virDomainFSDriverType) fs->fsdriver) { case VIR_DOMAIN_FS_DRIVER_TYPE_DEFAULT: case VIR_DOMAIN_FS_DRIVER_TYPE_PATH: diff --git a/src/qemu/qemu_virtiofs.c b/src/qemu/qemu_virtiofs.c index 2e239cad66..988b757d6f 100644 --- a/src/qemu/qemu_virtiofs.c +++ b/src/qemu/qemu_virtiofs.c @@ -131,6 +131,8 @@ qemuVirtioFSBuildCommandLine(virQEMUDriverConfigPtr cfg, virQEMUBuildBufferEscapeComma(&opts, fs->src->path); if (fs->cache) virBufferAsprintf(&opts, ",cache=%s", virDomainFSCacheModeTypeToString(fs->cache)); + if (fs->sandbox) + virBufferAsprintf(&opts, ",sandbox=%s", virDomainFSSandboxModeTypeToString(fs->sandbox)); if (fs->xattr == VIR_TRISTATE_SWITCH_ON) virBufferAddLit(&opts, ",xattr");