xref: /qemu/net/tap.c (revision d89b4f83)
1 /*
2  * QEMU System Emulator
3  *
4  * Copyright (c) 2003-2008 Fabrice Bellard
5  * Copyright (c) 2009 Red Hat, Inc.
6  *
7  * Permission is hereby granted, free of charge, to any person obtaining a copy
8  * of this software and associated documentation files (the "Software"), to deal
9  * in the Software without restriction, including without limitation the rights
10  * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
11  * copies of the Software, and to permit persons to whom the Software is
12  * furnished to do so, subject to the following conditions:
13  *
14  * The above copyright notice and this permission notice shall be included in
15  * all copies or substantial portions of the Software.
16  *
17  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
18  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
19  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
20  * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
21  * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
22  * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
23  * THE SOFTWARE.
24  */
25 
26 #include "qemu/osdep.h"
27 #include "tap_int.h"
28 
29 
30 #include <sys/ioctl.h>
31 #include <sys/wait.h>
32 #include <sys/socket.h>
33 #include <net/if.h>
34 
35 #include "net/eth.h"
36 #include "net/net.h"
37 #include "clients.h"
38 #include "monitor/monitor.h"
39 #include "sysemu/sysemu.h"
40 #include "qapi/error.h"
41 #include "qemu-common.h"
42 #include "qemu/cutils.h"
43 #include "qemu/error-report.h"
44 #include "qemu/main-loop.h"
45 #include "qemu/sockets.h"
46 
47 #include "net/tap.h"
48 
49 #include "net/vhost_net.h"
50 
51 typedef struct TAPState {
52     NetClientState nc;
53     int fd;
54     char down_script[1024];
55     char down_script_arg[128];
56     uint8_t buf[NET_BUFSIZE];
57     bool read_poll;
58     bool write_poll;
59     bool using_vnet_hdr;
60     bool has_ufo;
61     bool enabled;
62     VHostNetState *vhost_net;
63     unsigned host_vnet_hdr_len;
64     Notifier exit;
65 } TAPState;
66 
67 static void launch_script(const char *setup_script, const char *ifname,
68                           int fd, Error **errp);
69 
70 static void tap_send(void *opaque);
71 static void tap_writable(void *opaque);
72 
73 static void tap_update_fd_handler(TAPState *s)
74 {
75     qemu_set_fd_handler(s->fd,
76                         s->read_poll && s->enabled ? tap_send : NULL,
77                         s->write_poll && s->enabled ? tap_writable : NULL,
78                         s);
79 }
80 
81 static void tap_read_poll(TAPState *s, bool enable)
82 {
83     s->read_poll = enable;
84     tap_update_fd_handler(s);
85 }
86 
87 static void tap_write_poll(TAPState *s, bool enable)
88 {
89     s->write_poll = enable;
90     tap_update_fd_handler(s);
91 }
92 
93 static void tap_writable(void *opaque)
94 {
95     TAPState *s = opaque;
96 
97     tap_write_poll(s, false);
98 
99     qemu_flush_queued_packets(&s->nc);
100 }
101 
102 static ssize_t tap_write_packet(TAPState *s, const struct iovec *iov, int iovcnt)
103 {
104     ssize_t len;
105 
106     do {
107         len = writev(s->fd, iov, iovcnt);
108     } while (len == -1 && errno == EINTR);
109 
110     if (len == -1 && errno == EAGAIN) {
111         tap_write_poll(s, true);
112         return 0;
113     }
114 
115     return len;
116 }
117 
118 static ssize_t tap_receive_iov(NetClientState *nc, const struct iovec *iov,
119                                int iovcnt)
120 {
121     TAPState *s = DO_UPCAST(TAPState, nc, nc);
122     const struct iovec *iovp = iov;
123     struct iovec iov_copy[iovcnt + 1];
124     struct virtio_net_hdr_mrg_rxbuf hdr = { };
125 
126     if (s->host_vnet_hdr_len && !s->using_vnet_hdr) {
127         iov_copy[0].iov_base = &hdr;
128         iov_copy[0].iov_len =  s->host_vnet_hdr_len;
129         memcpy(&iov_copy[1], iov, iovcnt * sizeof(*iov));
130         iovp = iov_copy;
131         iovcnt++;
132     }
133 
134     return tap_write_packet(s, iovp, iovcnt);
135 }
136 
137 static ssize_t tap_receive_raw(NetClientState *nc, const uint8_t *buf, size_t size)
138 {
139     TAPState *s = DO_UPCAST(TAPState, nc, nc);
140     struct iovec iov[2];
141     int iovcnt = 0;
142     struct virtio_net_hdr_mrg_rxbuf hdr = { };
143 
144     if (s->host_vnet_hdr_len) {
145         iov[iovcnt].iov_base = &hdr;
146         iov[iovcnt].iov_len  = s->host_vnet_hdr_len;
147         iovcnt++;
148     }
149 
150     iov[iovcnt].iov_base = (char *)buf;
151     iov[iovcnt].iov_len  = size;
152     iovcnt++;
153 
154     return tap_write_packet(s, iov, iovcnt);
155 }
156 
157 static ssize_t tap_receive(NetClientState *nc, const uint8_t *buf, size_t size)
158 {
159     TAPState *s = DO_UPCAST(TAPState, nc, nc);
160     struct iovec iov[1];
161 
162     if (s->host_vnet_hdr_len && !s->using_vnet_hdr) {
163         return tap_receive_raw(nc, buf, size);
164     }
165 
166     iov[0].iov_base = (char *)buf;
167     iov[0].iov_len  = size;
168 
169     return tap_write_packet(s, iov, 1);
170 }
171 
172 #ifndef __sun__
173 ssize_t tap_read_packet(int tapfd, uint8_t *buf, int maxlen)
174 {
175     return read(tapfd, buf, maxlen);
176 }
177 #endif
178 
179 static void tap_send_completed(NetClientState *nc, ssize_t len)
180 {
181     TAPState *s = DO_UPCAST(TAPState, nc, nc);
182     tap_read_poll(s, true);
183 }
184 
185 static void tap_send(void *opaque)
186 {
187     TAPState *s = opaque;
188     int size;
189     int packets = 0;
190 
191     while (true) {
192         uint8_t *buf = s->buf;
193         uint8_t min_pkt[ETH_ZLEN];
194         size_t min_pktsz = sizeof(min_pkt);
195 
196         size = tap_read_packet(s->fd, s->buf, sizeof(s->buf));
197         if (size <= 0) {
198             break;
199         }
200 
201         if (s->host_vnet_hdr_len && !s->using_vnet_hdr) {
202             buf  += s->host_vnet_hdr_len;
203             size -= s->host_vnet_hdr_len;
204         }
205 
206         if (!s->nc.peer->do_not_pad) {
207             if (eth_pad_short_frame(min_pkt, &min_pktsz, buf, size)) {
208                 buf = min_pkt;
209                 size = min_pktsz;
210             }
211         }
212 
213         size = qemu_send_packet_async(&s->nc, buf, size, tap_send_completed);
214         if (size == 0) {
215             tap_read_poll(s, false);
216             break;
217         } else if (size < 0) {
218             break;
219         }
220 
221         /*
222          * When the host keeps receiving more packets while tap_send() is
223          * running we can hog the QEMU global mutex.  Limit the number of
224          * packets that are processed per tap_send() callback to prevent
225          * stalling the guest.
226          */
227         packets++;
228         if (packets >= 50) {
229             break;
230         }
231     }
232 }
233 
234 static bool tap_has_ufo(NetClientState *nc)
235 {
236     TAPState *s = DO_UPCAST(TAPState, nc, nc);
237 
238     assert(nc->info->type == NET_CLIENT_DRIVER_TAP);
239 
240     return s->has_ufo;
241 }
242 
243 static bool tap_has_vnet_hdr(NetClientState *nc)
244 {
245     TAPState *s = DO_UPCAST(TAPState, nc, nc);
246 
247     assert(nc->info->type == NET_CLIENT_DRIVER_TAP);
248 
249     return !!s->host_vnet_hdr_len;
250 }
251 
252 static bool tap_has_vnet_hdr_len(NetClientState *nc, int len)
253 {
254     TAPState *s = DO_UPCAST(TAPState, nc, nc);
255 
256     assert(nc->info->type == NET_CLIENT_DRIVER_TAP);
257 
258     return !!tap_probe_vnet_hdr_len(s->fd, len);
259 }
260 
261 static void tap_set_vnet_hdr_len(NetClientState *nc, int len)
262 {
263     TAPState *s = DO_UPCAST(TAPState, nc, nc);
264 
265     assert(nc->info->type == NET_CLIENT_DRIVER_TAP);
266     assert(len == sizeof(struct virtio_net_hdr_mrg_rxbuf) ||
267            len == sizeof(struct virtio_net_hdr) ||
268            len == sizeof(struct virtio_net_hdr_v1_hash));
269 
270     tap_fd_set_vnet_hdr_len(s->fd, len);
271     s->host_vnet_hdr_len = len;
272 }
273 
274 static void tap_using_vnet_hdr(NetClientState *nc, bool using_vnet_hdr)
275 {
276     TAPState *s = DO_UPCAST(TAPState, nc, nc);
277 
278     assert(nc->info->type == NET_CLIENT_DRIVER_TAP);
279     assert(!!s->host_vnet_hdr_len == using_vnet_hdr);
280 
281     s->using_vnet_hdr = using_vnet_hdr;
282 }
283 
284 static int tap_set_vnet_le(NetClientState *nc, bool is_le)
285 {
286     TAPState *s = DO_UPCAST(TAPState, nc, nc);
287 
288     return tap_fd_set_vnet_le(s->fd, is_le);
289 }
290 
291 static int tap_set_vnet_be(NetClientState *nc, bool is_be)
292 {
293     TAPState *s = DO_UPCAST(TAPState, nc, nc);
294 
295     return tap_fd_set_vnet_be(s->fd, is_be);
296 }
297 
298 static void tap_set_offload(NetClientState *nc, int csum, int tso4,
299                      int tso6, int ecn, int ufo)
300 {
301     TAPState *s = DO_UPCAST(TAPState, nc, nc);
302     if (s->fd < 0) {
303         return;
304     }
305 
306     tap_fd_set_offload(s->fd, csum, tso4, tso6, ecn, ufo);
307 }
308 
309 static void tap_exit_notify(Notifier *notifier, void *data)
310 {
311     TAPState *s = container_of(notifier, TAPState, exit);
312     Error *err = NULL;
313 
314     if (s->down_script[0]) {
315         launch_script(s->down_script, s->down_script_arg, s->fd, &err);
316         if (err) {
317             error_report_err(err);
318         }
319     }
320 }
321 
322 static void tap_cleanup(NetClientState *nc)
323 {
324     TAPState *s = DO_UPCAST(TAPState, nc, nc);
325 
326     if (s->vhost_net) {
327         vhost_net_cleanup(s->vhost_net);
328         g_free(s->vhost_net);
329         s->vhost_net = NULL;
330     }
331 
332     qemu_purge_queued_packets(nc);
333 
334     tap_exit_notify(&s->exit, NULL);
335     qemu_remove_exit_notifier(&s->exit);
336 
337     tap_read_poll(s, false);
338     tap_write_poll(s, false);
339     close(s->fd);
340     s->fd = -1;
341 }
342 
343 static void tap_poll(NetClientState *nc, bool enable)
344 {
345     TAPState *s = DO_UPCAST(TAPState, nc, nc);
346     tap_read_poll(s, enable);
347     tap_write_poll(s, enable);
348 }
349 
350 int tap_get_fd(NetClientState *nc)
351 {
352     TAPState *s = DO_UPCAST(TAPState, nc, nc);
353     assert(nc->info->type == NET_CLIENT_DRIVER_TAP);
354     return s->fd;
355 }
356 
357 /* fd support */
358 
359 static NetClientInfo net_tap_info = {
360     .type = NET_CLIENT_DRIVER_TAP,
361     .size = sizeof(TAPState),
362     .receive = tap_receive,
363     .receive_raw = tap_receive_raw,
364     .receive_iov = tap_receive_iov,
365     .poll = tap_poll,
366     .cleanup = tap_cleanup,
367     .has_ufo = tap_has_ufo,
368     .has_vnet_hdr = tap_has_vnet_hdr,
369     .has_vnet_hdr_len = tap_has_vnet_hdr_len,
370     .using_vnet_hdr = tap_using_vnet_hdr,
371     .set_offload = tap_set_offload,
372     .set_vnet_hdr_len = tap_set_vnet_hdr_len,
373     .set_vnet_le = tap_set_vnet_le,
374     .set_vnet_be = tap_set_vnet_be,
375 };
376 
377 static TAPState *net_tap_fd_init(NetClientState *peer,
378                                  const char *model,
379                                  const char *name,
380                                  int fd,
381                                  int vnet_hdr)
382 {
383     NetClientState *nc;
384     TAPState *s;
385 
386     nc = qemu_new_net_client(&net_tap_info, peer, model, name);
387 
388     s = DO_UPCAST(TAPState, nc, nc);
389 
390     s->fd = fd;
391     s->host_vnet_hdr_len = vnet_hdr ? sizeof(struct virtio_net_hdr) : 0;
392     s->using_vnet_hdr = false;
393     s->has_ufo = tap_probe_has_ufo(s->fd);
394     s->enabled = true;
395     tap_set_offload(&s->nc, 0, 0, 0, 0, 0);
396     /*
397      * Make sure host header length is set correctly in tap:
398      * it might have been modified by another instance of qemu.
399      */
400     if (tap_probe_vnet_hdr_len(s->fd, s->host_vnet_hdr_len)) {
401         tap_fd_set_vnet_hdr_len(s->fd, s->host_vnet_hdr_len);
402     }
403     tap_read_poll(s, true);
404     s->vhost_net = NULL;
405 
406     s->exit.notify = tap_exit_notify;
407     qemu_add_exit_notifier(&s->exit);
408 
409     return s;
410 }
411 
412 static void launch_script(const char *setup_script, const char *ifname,
413                           int fd, Error **errp)
414 {
415     int pid, status;
416     char *args[3];
417     char **parg;
418 
419     /* try to launch network script */
420     pid = fork();
421     if (pid < 0) {
422         error_setg_errno(errp, errno, "could not launch network script %s",
423                          setup_script);
424         return;
425     }
426     if (pid == 0) {
427         int open_max = sysconf(_SC_OPEN_MAX), i;
428 
429         for (i = 3; i < open_max; i++) {
430             if (i != fd) {
431                 close(i);
432             }
433         }
434         parg = args;
435         *parg++ = (char *)setup_script;
436         *parg++ = (char *)ifname;
437         *parg = NULL;
438         execv(setup_script, args);
439         _exit(1);
440     } else {
441         while (waitpid(pid, &status, 0) != pid) {
442             /* loop */
443         }
444 
445         if (WIFEXITED(status) && WEXITSTATUS(status) == 0) {
446             return;
447         }
448         error_setg(errp, "network script %s failed with status %d",
449                    setup_script, status);
450     }
451 }
452 
453 static int recv_fd(int c)
454 {
455     int fd;
456     uint8_t msgbuf[CMSG_SPACE(sizeof(fd))];
457     struct msghdr msg = {
458         .msg_control = msgbuf,
459         .msg_controllen = sizeof(msgbuf),
460     };
461     struct cmsghdr *cmsg;
462     struct iovec iov;
463     uint8_t req[1];
464     ssize_t len;
465 
466     cmsg = CMSG_FIRSTHDR(&msg);
467     cmsg->cmsg_level = SOL_SOCKET;
468     cmsg->cmsg_type = SCM_RIGHTS;
469     cmsg->cmsg_len = CMSG_LEN(sizeof(fd));
470     msg.msg_controllen = cmsg->cmsg_len;
471 
472     iov.iov_base = req;
473     iov.iov_len = sizeof(req);
474 
475     msg.msg_iov = &iov;
476     msg.msg_iovlen = 1;
477 
478     len = recvmsg(c, &msg, 0);
479     if (len > 0) {
480         memcpy(&fd, CMSG_DATA(cmsg), sizeof(fd));
481         return fd;
482     }
483 
484     return len;
485 }
486 
487 static int net_bridge_run_helper(const char *helper, const char *bridge,
488                                  Error **errp)
489 {
490     sigset_t oldmask, mask;
491     g_autofree char *default_helper = NULL;
492     int pid, status;
493     char *args[5];
494     char **parg;
495     int sv[2];
496 
497     sigemptyset(&mask);
498     sigaddset(&mask, SIGCHLD);
499     sigprocmask(SIG_BLOCK, &mask, &oldmask);
500 
501     if (!helper) {
502         helper = default_helper = get_relocated_path(DEFAULT_BRIDGE_HELPER);
503     }
504 
505     if (socketpair(PF_UNIX, SOCK_STREAM, 0, sv) == -1) {
506         error_setg_errno(errp, errno, "socketpair() failed");
507         return -1;
508     }
509 
510     /* try to launch bridge helper */
511     pid = fork();
512     if (pid < 0) {
513         error_setg_errno(errp, errno, "Can't fork bridge helper");
514         return -1;
515     }
516     if (pid == 0) {
517         int open_max = sysconf(_SC_OPEN_MAX), i;
518         char *fd_buf = NULL;
519         char *br_buf = NULL;
520         char *helper_cmd = NULL;
521 
522         for (i = 3; i < open_max; i++) {
523             if (i != sv[1]) {
524                 close(i);
525             }
526         }
527 
528         fd_buf = g_strdup_printf("%s%d", "--fd=", sv[1]);
529 
530         if (strrchr(helper, ' ') || strrchr(helper, '\t')) {
531             /* assume helper is a command */
532 
533             if (strstr(helper, "--br=") == NULL) {
534                 br_buf = g_strdup_printf("%s%s", "--br=", bridge);
535             }
536 
537             helper_cmd = g_strdup_printf("%s %s %s %s", helper,
538                             "--use-vnet", fd_buf, br_buf ? br_buf : "");
539 
540             parg = args;
541             *parg++ = (char *)"sh";
542             *parg++ = (char *)"-c";
543             *parg++ = helper_cmd;
544             *parg++ = NULL;
545 
546             execv("/bin/sh", args);
547             g_free(helper_cmd);
548         } else {
549             /* assume helper is just the executable path name */
550 
551             br_buf = g_strdup_printf("%s%s", "--br=", bridge);
552 
553             parg = args;
554             *parg++ = (char *)helper;
555             *parg++ = (char *)"--use-vnet";
556             *parg++ = fd_buf;
557             *parg++ = br_buf;
558             *parg++ = NULL;
559 
560             execv(helper, args);
561         }
562         g_free(fd_buf);
563         g_free(br_buf);
564         _exit(1);
565 
566     } else {
567         int fd;
568         int saved_errno;
569 
570         close(sv[1]);
571 
572         do {
573             fd = recv_fd(sv[0]);
574         } while (fd == -1 && errno == EINTR);
575         saved_errno = errno;
576 
577         close(sv[0]);
578 
579         while (waitpid(pid, &status, 0) != pid) {
580             /* loop */
581         }
582         sigprocmask(SIG_SETMASK, &oldmask, NULL);
583         if (fd < 0) {
584             error_setg_errno(errp, saved_errno,
585                              "failed to recv file descriptor");
586             return -1;
587         }
588         if (!WIFEXITED(status) || WEXITSTATUS(status) != 0) {
589             error_setg(errp, "bridge helper failed");
590             return -1;
591         }
592         return fd;
593     }
594 }
595 
596 int net_init_bridge(const Netdev *netdev, const char *name,
597                     NetClientState *peer, Error **errp)
598 {
599     const NetdevBridgeOptions *bridge;
600     const char *helper, *br;
601     TAPState *s;
602     int fd, vnet_hdr;
603     NetdevBridgeOptions *stored;
604 
605     assert(netdev->type == NET_CLIENT_DRIVER_BRIDGE);
606     bridge = &netdev->u.bridge;
607     helper = bridge->has_helper ? bridge->helper : NULL;
608     br     = bridge->has_br     ? bridge->br     : DEFAULT_BRIDGE_INTERFACE;
609 
610     fd = net_bridge_run_helper(helper, br, errp);
611     if (fd == -1) {
612         return -1;
613     }
614 
615     qemu_set_nonblock(fd);
616     vnet_hdr = tap_probe_vnet_hdr(fd, errp);
617     if (vnet_hdr < 0) {
618         close(fd);
619         return -1;
620     }
621     s = net_tap_fd_init(peer, "bridge", name, fd, vnet_hdr);
622 
623     /* Store startup parameters */
624     s->nc.stored_config = g_new0(NetdevInfo, 1);
625     s->nc.stored_config->type = NET_BACKEND_BRIDGE;
626     stored = &s->nc.stored_config->u.bridge;
627 
628     if (br) {
629         stored->has_br = true;
630         stored->br = g_strdup(br);
631     }
632 
633     if (helper) {
634         stored->has_helper = true;
635         stored->helper = g_strdup(helper);
636     }
637 
638     s->nc.info_str = g_strdup_printf("helper=%s,br=%s", helper, br);
639 
640     return 0;
641 }
642 
643 static int net_tap_init(const NetdevTapOptions *tap, int *vnet_hdr,
644                         const char *setup_script, char *ifname,
645                         size_t ifname_sz, int mq_required, Error **errp)
646 {
647     Error *err = NULL;
648     int fd, vnet_hdr_required;
649 
650     if (tap->has_vnet_hdr) {
651         *vnet_hdr = tap->vnet_hdr;
652         vnet_hdr_required = *vnet_hdr;
653     } else {
654         *vnet_hdr = 1;
655         vnet_hdr_required = 0;
656     }
657 
658     TFR(fd = tap_open(ifname, ifname_sz, vnet_hdr, vnet_hdr_required,
659                       mq_required, errp));
660     if (fd < 0) {
661         return -1;
662     }
663 
664     if (setup_script &&
665         setup_script[0] != '\0' &&
666         strcmp(setup_script, "no") != 0) {
667         launch_script(setup_script, ifname, fd, &err);
668         if (err) {
669             error_propagate(errp, err);
670             close(fd);
671             return -1;
672         }
673     }
674 
675     return fd;
676 }
677 
678 #define MAX_TAP_QUEUES 1024
679 
680 static void net_init_tap_one(const NetdevTapOptions *tap, NetClientState *peer,
681                              const char *model, const char *name,
682                              const char *ifname, const char *script,
683                              const char *downscript, const char *vhostfdname,
684                              int vnet_hdr, int fd, NetdevInfo **common_stored,
685                              Error **errp)
686 {
687     Error *err = NULL;
688     TAPState *s = net_tap_fd_init(peer, model, name, fd, vnet_hdr);
689     int vhostfd;
690     NetdevTapOptions *stored;
691 
692     tap_set_sndbuf(s->fd, tap, &err);
693     if (err) {
694         error_propagate(errp, err);
695         return;
696     }
697 
698     /* Store startup parameters */
699     if (!*common_stored) {
700         *common_stored = g_new0(NetdevInfo, 1);
701         (*common_stored)->type = NET_BACKEND_TAP;
702         s->nc.stored_config = *common_stored;
703     }
704     stored = &(*common_stored)->u.tap;
705 
706     if (tap->has_sndbuf && !stored->has_sndbuf) {
707         stored->has_sndbuf = true;
708         stored->sndbuf = tap->sndbuf;
709     }
710 
711     if (vnet_hdr && !stored->has_vnet_hdr) {
712         stored->has_vnet_hdr = true;
713         stored->vnet_hdr = true;
714     }
715 
716     if (tap->has_fd || tap->has_fds) {
717         if (!stored->has_fds) {
718             stored->has_fds = true;
719             stored->fds = g_strdup_printf("%d", fd);
720         } else {
721             char *tmp_s = stored->fds;
722             stored->fds = g_strdup_printf("%s:%d", stored->fds, fd);
723             g_free(tmp_s);
724         }
725 
726         s->nc.info_str = g_strdup_printf("fd=%d", fd);
727     } else if (tap->has_helper) {
728         if (!stored->has_helper) {
729             stored->has_helper = true;
730             stored->helper = g_strdup(tap->helper);
731         }
732 
733         if (!stored->has_br) {
734             stored->has_br = true;
735             stored->br = tap->has_br ? g_strdup(tap->br) :
736                                        g_strdup(DEFAULT_BRIDGE_INTERFACE);
737         }
738 
739         s->nc.info_str = g_strdup_printf("helper=%s", tap->helper);
740     } else {
741         if (ifname && !stored->has_ifname) {
742             stored->has_ifname = true;
743             stored->ifname = g_strdup(ifname);
744         }
745 
746         if (script && !stored->has_script) {
747             stored->has_script = true;
748             stored->script = g_strdup(script);
749         }
750 
751         if (downscript && !stored->has_downscript) {
752             stored->has_downscript = true;
753             stored->downscript = g_strdup(downscript);
754         }
755 
756         s->nc.info_str = g_strdup_printf("ifname=%s,script=%s,downscript=%s",
757                                          ifname, script, downscript);
758 
759         if (strcmp(downscript, "no") != 0) {
760             snprintf(s->down_script, sizeof(s->down_script), "%s", downscript);
761             snprintf(s->down_script_arg, sizeof(s->down_script_arg),
762                      "%s", ifname);
763         }
764     }
765 
766     if (tap->has_vhost ? tap->vhost :
767         vhostfdname || (tap->has_vhostforce && tap->vhostforce)) {
768         VhostNetOptions options;
769 
770         stored->has_vhost = true;
771         stored->vhost = true;
772 
773         if (tap->has_vhostforce && tap->vhostforce) {
774             stored->has_vhostforce = true;
775             stored->vhostforce = true;
776         }
777 
778         options.backend_type = VHOST_BACKEND_TYPE_KERNEL;
779         options.net_backend = &s->nc;
780         if (tap->has_poll_us) {
781             stored->has_poll_us = true;
782             stored->poll_us = tap->poll_us;
783 
784             options.busyloop_timeout = tap->poll_us;
785         } else {
786             options.busyloop_timeout = 0;
787         }
788 
789         if (vhostfdname) {
790             int ret;
791 
792             vhostfd = monitor_fd_param(monitor_cur(), vhostfdname, &err);
793             if (vhostfd == -1) {
794                 if (tap->has_vhostforce && tap->vhostforce) {
795                     error_propagate(errp, err);
796                 } else {
797                     warn_report_err(err);
798                 }
799                 return;
800             }
801             ret = qemu_try_set_nonblock(vhostfd);
802             if (ret < 0) {
803                 error_setg_errno(errp, -ret, "%s: Can't use file descriptor %d",
804                                  name, fd);
805                 return;
806             }
807         } else {
808             vhostfd = open("/dev/vhost-net", O_RDWR);
809             if (vhostfd < 0) {
810                 if (tap->has_vhostforce && tap->vhostforce) {
811                     error_setg_errno(errp, errno,
812                                      "tap: open vhost char device failed");
813                 } else {
814                     warn_report("tap: open vhost char device failed: %s",
815                                 strerror(errno));
816                 }
817                 return;
818             }
819             qemu_set_nonblock(vhostfd);
820         }
821         options.opaque = (void *)(uintptr_t)vhostfd;
822 
823         if (!stored->has_vhostfds) {
824             stored->has_vhostfds = true;
825             stored->vhostfds = g_strdup_printf("%d", vhostfd);
826         } else {
827             char *tmp_s = stored->vhostfds;
828             stored->vhostfds = g_strdup_printf("%s:%d", stored->fds, vhostfd);
829             g_free(tmp_s);
830         }
831 
832         s->vhost_net = vhost_net_init(&options);
833         if (!s->vhost_net) {
834             if (tap->has_vhostforce && tap->vhostforce) {
835                 error_setg(errp, VHOST_NET_INIT_FAILED);
836             } else {
837                 warn_report(VHOST_NET_INIT_FAILED);
838             }
839             return;
840         }
841     } else if (vhostfdname) {
842         error_setg(errp, "vhostfd(s)= is not valid without vhost");
843     }
844 }
845 
846 static int get_fds(char *str, char *fds[], int max)
847 {
848     char *ptr = str, *this;
849     size_t len = strlen(str);
850     int i = 0;
851 
852     while (i < max && ptr < str + len) {
853         this = strchr(ptr, ':');
854 
855         if (this == NULL) {
856             fds[i] = g_strdup(ptr);
857         } else {
858             fds[i] = g_strndup(ptr, this - ptr);
859         }
860 
861         i++;
862         if (this == NULL) {
863             break;
864         } else {
865             ptr = this + 1;
866         }
867     }
868 
869     return i;
870 }
871 
872 int net_init_tap(const Netdev *netdev, const char *name,
873                  NetClientState *peer, Error **errp)
874 {
875     const NetdevTapOptions *tap;
876     int fd, vnet_hdr = 0, i = 0, queues;
877     /* for the no-fd, no-helper case */
878     const char *script;
879     const char *downscript;
880     Error *err = NULL;
881     const char *vhostfdname;
882     char ifname[128];
883     int ret = 0;
884     NetdevInfo *common_stored = NULL; /* will store configuration */
885 
886     assert(netdev->type == NET_CLIENT_DRIVER_TAP);
887     tap = &netdev->u.tap;
888     queues = tap->has_queues ? tap->queues : 1;
889     vhostfdname = tap->has_vhostfd ? tap->vhostfd : NULL;
890     script = tap->has_script ? tap->script : NULL;
891     downscript = tap->has_downscript ? tap->downscript : NULL;
892 
893     /* QEMU hubs do not support multiqueue tap, in this case peer is set.
894      * For -netdev, peer is always NULL. */
895     if (peer && (tap->has_queues || tap->has_fds || tap->has_vhostfds)) {
896         error_setg(errp, "Multiqueue tap cannot be used with hubs");
897         return -1;
898     }
899 
900     if (tap->has_fd) {
901         if (tap->has_ifname || tap->has_script || tap->has_downscript ||
902             tap->has_vnet_hdr || tap->has_helper || tap->has_queues ||
903             tap->has_fds || tap->has_vhostfds) {
904             error_setg(errp, "ifname=, script=, downscript=, vnet_hdr=, "
905                        "helper=, queues=, fds=, and vhostfds= "
906                        "are invalid with fd=");
907             return -1;
908         }
909 
910         fd = monitor_fd_param(monitor_cur(), tap->fd, errp);
911         if (fd == -1) {
912             return -1;
913         }
914 
915         ret = qemu_try_set_nonblock(fd);
916         if (ret < 0) {
917             error_setg_errno(errp, -ret, "%s: Can't use file descriptor %d",
918                              name, fd);
919             close(fd);
920             return -1;
921         }
922 
923         vnet_hdr = tap_probe_vnet_hdr(fd, errp);
924         if (vnet_hdr < 0) {
925             close(fd);
926             return -1;
927         }
928 
929         net_init_tap_one(tap, peer, "tap", name, NULL,
930                          script, downscript,
931                          vhostfdname, vnet_hdr, fd, &common_stored, &err);
932         if (err) {
933             error_propagate(errp, err);
934             close(fd);
935             return -1;
936         }
937     } else if (tap->has_fds) {
938         char **fds;
939         char **vhost_fds;
940         int nfds = 0, nvhosts = 0;
941 
942         if (tap->has_ifname || tap->has_script || tap->has_downscript ||
943             tap->has_vnet_hdr || tap->has_helper || tap->has_queues ||
944             tap->has_vhostfd) {
945             error_setg(errp, "ifname=, script=, downscript=, vnet_hdr=, "
946                        "helper=, queues=, and vhostfd= "
947                        "are invalid with fds=");
948             return -1;
949         }
950 
951         fds = g_new0(char *, MAX_TAP_QUEUES);
952         vhost_fds = g_new0(char *, MAX_TAP_QUEUES);
953 
954         nfds = get_fds(tap->fds, fds, MAX_TAP_QUEUES);
955         if (tap->has_vhostfds) {
956             nvhosts = get_fds(tap->vhostfds, vhost_fds, MAX_TAP_QUEUES);
957             if (nfds != nvhosts) {
958                 error_setg(errp, "The number of fds passed does not match "
959                            "the number of vhostfds passed");
960                 ret = -1;
961                 goto free_fail;
962             }
963         }
964 
965         for (i = 0; i < nfds; i++) {
966             fd = monitor_fd_param(monitor_cur(), fds[i], errp);
967             if (fd == -1) {
968                 ret = -1;
969                 goto free_fail;
970             }
971 
972             ret = qemu_try_set_nonblock(fd);
973             if (ret < 0) {
974                 error_setg_errno(errp, -ret, "%s: Can't use file descriptor %d",
975                                  name, fd);
976                 goto free_fail;
977             }
978 
979             if (i == 0) {
980                 vnet_hdr = tap_probe_vnet_hdr(fd, errp);
981                 if (vnet_hdr < 0) {
982                     goto free_fail;
983                 }
984             } else if (vnet_hdr != tap_probe_vnet_hdr(fd, NULL)) {
985                 error_setg(errp,
986                            "vnet_hdr not consistent across given tap fds");
987                 ret = -1;
988                 goto free_fail;
989             }
990 
991             net_init_tap_one(tap, peer, "tap", name, ifname,
992                              script, downscript,
993                              tap->has_vhostfds ? vhost_fds[i] : NULL,
994                              vnet_hdr, fd, &common_stored, &err);
995             if (err) {
996                 error_propagate(errp, err);
997                 ret = -1;
998                 goto free_fail;
999             }
1000         }
1001 
1002 free_fail:
1003         for (i = 0; i < nvhosts; i++) {
1004             g_free(vhost_fds[i]);
1005         }
1006         for (i = 0; i < nfds; i++) {
1007             g_free(fds[i]);
1008         }
1009         g_free(fds);
1010         g_free(vhost_fds);
1011         return ret;
1012     } else if (tap->has_helper) {
1013         if (tap->has_ifname || tap->has_script || tap->has_downscript ||
1014             tap->has_vnet_hdr || tap->has_queues || tap->has_vhostfds) {
1015             error_setg(errp, "ifname=, script=, downscript=, vnet_hdr=, "
1016                        "queues=, and vhostfds= are invalid with helper=");
1017             return -1;
1018         }
1019 
1020         fd = net_bridge_run_helper(tap->helper,
1021                                    tap->has_br ?
1022                                    tap->br : DEFAULT_BRIDGE_INTERFACE,
1023                                    errp);
1024         if (fd == -1) {
1025             return -1;
1026         }
1027 
1028         qemu_set_nonblock(fd);
1029         vnet_hdr = tap_probe_vnet_hdr(fd, errp);
1030         if (vnet_hdr < 0) {
1031             close(fd);
1032             return -1;
1033         }
1034 
1035         net_init_tap_one(tap, peer, "bridge", name, ifname,
1036                          script, downscript, vhostfdname,
1037                          vnet_hdr, fd, &common_stored, &err);
1038         if (err) {
1039             error_propagate(errp, err);
1040             close(fd);
1041             return -1;
1042         }
1043     } else {
1044         g_autofree char *default_script = NULL;
1045         g_autofree char *default_downscript = NULL;
1046         if (tap->has_vhostfds) {
1047             error_setg(errp, "vhostfds= is invalid if fds= wasn't specified");
1048             return -1;
1049         }
1050 
1051         if (!script) {
1052             script = default_script = get_relocated_path(DEFAULT_NETWORK_SCRIPT);
1053         }
1054         if (!downscript) {
1055             downscript = default_downscript =
1056                                  get_relocated_path(DEFAULT_NETWORK_DOWN_SCRIPT);
1057         }
1058 
1059         if (tap->has_ifname) {
1060             pstrcpy(ifname, sizeof ifname, tap->ifname);
1061         } else {
1062             ifname[0] = '\0';
1063         }
1064 
1065         for (i = 0; i < queues; i++) {
1066             fd = net_tap_init(tap, &vnet_hdr, i >= 1 ? "no" : script,
1067                               ifname, sizeof ifname, queues > 1, errp);
1068             if (fd == -1) {
1069                 return -1;
1070             }
1071 
1072             if (queues > 1 && i == 0 && !tap->has_ifname) {
1073                 if (tap_fd_get_ifname(fd, ifname)) {
1074                     error_setg(errp, "Fail to get ifname");
1075                     close(fd);
1076                     return -1;
1077                 }
1078             }
1079 
1080             net_init_tap_one(tap, peer, "tap", name, ifname,
1081                              i >= 1 ? "no" : script,
1082                              i >= 1 ? "no" : downscript,
1083                              vhostfdname, vnet_hdr, fd,
1084                              &common_stored, &err);
1085             if (err) {
1086                 error_propagate(errp, err);
1087                 close(fd);
1088                 return -1;
1089             }
1090         }
1091     }
1092 
1093     return 0;
1094 }
1095 
1096 VHostNetState *tap_get_vhost_net(NetClientState *nc)
1097 {
1098     TAPState *s = DO_UPCAST(TAPState, nc, nc);
1099     assert(nc->info->type == NET_CLIENT_DRIVER_TAP);
1100     return s->vhost_net;
1101 }
1102 
1103 int tap_enable(NetClientState *nc)
1104 {
1105     TAPState *s = DO_UPCAST(TAPState, nc, nc);
1106     int ret;
1107 
1108     if (s->enabled) {
1109         return 0;
1110     } else {
1111         ret = tap_fd_enable(s->fd);
1112         if (ret == 0) {
1113             s->enabled = true;
1114             tap_update_fd_handler(s);
1115         }
1116         return ret;
1117     }
1118 }
1119 
1120 int tap_disable(NetClientState *nc)
1121 {
1122     TAPState *s = DO_UPCAST(TAPState, nc, nc);
1123     int ret;
1124 
1125     if (s->enabled == 0) {
1126         return 0;
1127     } else {
1128         ret = tap_fd_disable(s->fd);
1129         if (ret == 0) {
1130             qemu_purge_queued_packets(nc);
1131             s->enabled = false;
1132             tap_update_fd_handler(s);
1133         }
1134         return ret;
1135     }
1136 }
1137