[pve-devel] [PATCH qemu-server v6 1/6] enable cluster mapped USB devices for guests

Fabian Grünbichler f.gruenbichler at proxmox.com
Fri Jun 16 09:50:05 CEST 2023


On June 14, 2023 10:46 am, Dominik Csapak wrote:
> this patch allows configuring usb devices that are mapped via
> cluster resource mapping when the user has 'Resource.Use' on the ACL
> path '/resource/usb/{ID}' (in addition to the usual required vm config
> privileges)
> 
> for now, this is only valid if there is exactly one mapping for the
> host, since we don't track passed through usb devices yet
> 
> also checks the permission for usb devices on clone/restore
> 
> Note that this now fails for 'raw' devices when the user is not root, so
> this is a breaking change!
> 
> Signed-off-by: Dominik Csapak <d.csapak at proxmox.com>
> ---
> changes from v5:
> * move the permission check into QemuServer.pm
> * add a 'check_restore_permissions' functions and refactor the checks
>   into there
>  PVE/API2/Qemu.pm      | 41 ++++++++++++++++++++++++++++++++++++++---
>  PVE/QemuServer.pm     | 36 +++++++++++++++++++++++++++++++++---
>  PVE/QemuServer/USB.pm | 27 ++++++++++++++++++++++++---
>  3 files changed, 95 insertions(+), 9 deletions(-)
> 
> diff --git a/PVE/API2/Qemu.pm b/PVE/API2/Qemu.pm
> index c92734a6..865edf7f 100644
> --- a/PVE/API2/Qemu.pm
> +++ b/PVE/API2/Qemu.pm
> @@ -32,6 +32,7 @@ use PVE::QemuServer::Drive;
>  use PVE::QemuServer::ImportDisk;
>  use PVE::QemuServer::Monitor qw(mon_cmd);
>  use PVE::QemuServer::Machine;
> +use PVE::QemuServer::USB qw(parse_usb_device);
>  use PVE::QemuMigrate;
>  use PVE::RPCEnvironment;
>  use PVE::AccessControl;
> @@ -590,8 +591,13 @@ my $check_vm_create_usb_perm = sub {
>  
>      foreach my $opt (keys %{$param}) {
>  	next if $opt !~ m/^usb\d+$/;
> +	my $entry = PVE::JSONSchema::parse_property_string('pve-qm-usb', $param->{$opt});
> +	my $device = parse_usb_device($entry->{host});
>  
> -	if ($param->{$opt} =~ m/spice/) {
> +	if ($device->{spice}) {
> +	    $rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.HWType']);
> +	} elsif ($device->{mapped}) {
> +	    $rpcenv->check_full($authuser, "/mapping/usb/$entry->{host}", ['Mapping.Use']);
>  	    $rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.HWType']);
>  	} else {
>  	    die "only root can set '$opt' config for real devices\n";

this part here
> @@ -1719,7 +1725,12 @@ my $update_vm_api  = sub {
>  		    PVE::QemuConfig->add_to_pending_delete($conf, $opt, $force);
>  		    PVE::QemuConfig->write_config($vmid, $conf);
>  		} elsif ($opt =~ m/^usb\d+$/) {
> -		    if ($val =~ m/spice/) {
> +		    my $device = PVE::JSONSchema::parse_property_string('pve-qm-usb', $val);
> +		    my $host = parse_usb_device($device->{host});
> +		    if ($host->{spice}) {
> +			$rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']);
> +		    } elsif ($host->{mapped}) {
> +			$rpcenv->check_full($authuser, "/mapping/usb/$device->{host}", ['Mapping.Use']);
>  			$rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']);
>  		    } elsif ($authuser ne 'root at pam') {
>  			die "only root can delete '$opt' config for real devices\n";

this part here (modulo variable names, especially confusing since
$device is used in both!)

> @@ -1784,7 +1795,30 @@ my $update_vm_api  = sub {
>  		    }
>  		    $conf->{pending}->{$opt} = $param->{$opt};
>  		} elsif ($opt =~ m/^usb\d+/) {
> -		    if ((!defined($conf->{$opt}) || $conf->{$opt} =~ m/spice/) && $param->{$opt} =~ m/spice/) {
> +		    my $olddevice;
> +		    my $oldhost;
> +		    if (defined($conf->{$opt})) {
> +			$olddevice = PVE::JSONSchema::parse_property_string('pve-qm-usb', $conf->{$opt});
> +			$oldhost = parse_usb_device($olddevice->{host});
> +		    }
> +		    if (defined($oldhost)) {
> +			if ($oldhost->{spice}) {
> +			    $rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']);
> +			} elsif ($oldhost->{mapped}) {
> +			    $rpcenv->check_full($authuser, "/mapping/usb/$olddevice->{host}", ['Mapping.Use']);
> +			    $rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']);
> +			} elsif ($authuser ne 'root at pam') {
> +			    die "only root can modify '$opt' config for real devices\n";
> +			}

this part here

> +		    }
> +
> +		    my $newdevice = PVE::JSONSchema::parse_property_string('pve-qm-usb', $param->{$opt});
> +		    my $newhost = parse_usb_device($newdevice->{host});
> +
> +		    if ($newhost->{spice}) {
> +			$rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']);
> +		    } elsif ($newhost->{mapped}) {
> +			$rpcenv->check_full($authuser, "/mapping/usb/$newdevice->{host}", ['Mapping.Use']);
>  			$rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']);
>  		    } elsif ($authuser ne 'root at pam') {
>  			die "only root can modify '$opt' config for real devices\n";

and this part here

are all identical except for some variations in variable names. this
screams "single helper" to me..

it also might make sense to structure it differently?

1. always check VM.Config.HWType (explicitly or implicitly done in all branches
atm)
2. if mapped, check mapping
3. if not, die if not root

I know you discussed with Thomas to split the config format a bit more
here to make it less overloaded, which might make this part easier to
understand as well :)

> @@ -3511,6 +3545,7 @@ __PACKAGE__->register_method({
>  	    my $oldconf = $snapname ? $conf->{snapshots}->{$snapname} : $conf;
>  
>  	    my $sharedvm = &$check_storage_access_clone($rpcenv, $authuser, $storecfg, $oldconf, $storage);
> +	    PVE::QemuServer::check_mapping_access($rpcenv, $authuser, $oldconf);
>  
>  	    PVE::QemuServer::check_bridge_access($rpcenv, $authuser, $oldconf);
>  
> diff --git a/PVE/QemuServer.pm b/PVE/QemuServer.pm
> index b978ab54..ab5458c3 100644
> --- a/PVE/QemuServer.pm
> +++ b/PVE/QemuServer.pm
> @@ -1095,6 +1095,8 @@ The Host USB device or port or the value 'spice'. HOSTUSBDEVICE syntax is:
>  
>  You can use the 'lsusb -t' command to list existing usb devices.
>  
> +Alternatively, you can used an ID of a mapped usb device.
> +
>  NOTE: This option allows direct access to host hardware. So it is no longer possible to migrate such
>  machines - use with special care.
>  
> @@ -1111,6 +1113,8 @@ EODESCR
>      },
>  };
>  
> +PVE::JSONSchema::register_format('pve-qm-usb', $usb_fmt);
> +
>  my $usbdesc = {
>      optional => 1,
>      type => 'string', format => $usb_fmt,
> @@ -2248,7 +2252,12 @@ PVE::JSONSchema::register_format('pve-qm-usb-device', \&verify_usb_device);
>  sub verify_usb_device {
>      my ($value, $noerr) = @_;
>  
> -    return $value if parse_usb_device($value);
> +    my $parsed = eval { parse_usb_device($value) };
> +    if (my $err = $@) {
> +	die $err if !$noerr;
> +	return;
> +    }
> +    return $value if defined($parsed);
>  
>      return if $noerr;
>  
> @@ -6527,6 +6536,27 @@ sub check_bridge_access {
>      return 1;
>  };
>  
> +sub check_mapping_access {
> +   my ($rpcenv, $user, $conf) = @_;
> +
> +   for my $opt (keys $conf->%*) {
> +       if ($opt =~ m/^usb\d+$/) {
> +	   my $entry = PVE::JSONSchema::parse_property_string('pve-qm-usb', $conf->{$opt});
> +	   my $device = parse_usb_device($entry->{host});
> +	   if ($device->{mapped}) {
> +	       $rpcenv->check_full($user, "/mapping/usb/$entry->{host}", ['Mapping.Use']);
> +	   } elsif (!$device->{spice}) {
> +	       die "only root can set '$opt' config for real devices\n";
> +	   }
> +       }
> +   }
> +};
> +
> +sub check_restore_permissions {
> +    my ($rpcenv, $user, $conf) = @_;
> +    check_bridge_access($rpcenv, $user, $conf);
> +    check_mapping_access($rpcenv, $user, $conf);
> +}

might want a FIXME comment there to improve this w.r.t. checking before
disk allocation if possible?

e.g., the helper could take old and optionally new config (not possible
for STDIN, but then we are root anyway so the checks should also never
fail ;)), and do the checks on the "overlay". then we could call it
twice:
- with old config and optionally extracted config before starting the
  restore (early abort!)
- with the merged config after the restore (final check with the real
  config we write out)

>  # vzdump restore implementaion
>  
>  sub tar_archive_read_firstfile {
> @@ -7171,7 +7201,7 @@ sub restore_proxmox_backup_archive {
>      }
>  
>      my $new_conf = $restore_merge_config->($conffile, $new_conf_raw, $options->{override_conf});
> -    check_bridge_access($rpcenv, $user, $new_conf);
> +    check_restore_permissions($rpcenv, $user, $new_conf);
>      PVE::QemuConfig->write_config($vmid, $new_conf);
>  
>      eval { rescan($vmid, 1); };
> @@ -7485,7 +7515,7 @@ sub restore_vma_archive {
>      }
>  
>      my $new_conf = $restore_merge_config->($conffile, $new_conf_raw, $opts->{override_conf});
> -    check_bridge_access($rpcenv, $user, $new_conf);
> +    check_restore_permissions($rpcenv, $user, $new_conf);
>      PVE::QemuConfig->write_config($vmid, $new_conf);
>  
>      eval { rescan($vmid, 1); };
> diff --git a/PVE/QemuServer/USB.pm b/PVE/QemuServer/USB.pm
> index 686461cc..d6b4c531 100644
> --- a/PVE/QemuServer/USB.pm
> +++ b/PVE/QemuServer/USB.pm
> @@ -6,6 +6,7 @@ use PVE::QemuServer::PCI qw(print_pci_addr);
>  use PVE::QemuServer::Machine;
>  use PVE::QemuServer::Helpers qw(min_version windows_version);
>  use PVE::JSONSchema;
> +use PVE::Mapping::USB;
>  use base 'Exporter';
>  
>  our @EXPORT_OK = qw(
> @@ -17,7 +18,7 @@ get_usb_devices
>  my $OLD_MAX_USB = 5;
>  
>  sub parse_usb_device {
> -    my ($value) = @_;
> +    my ($value, $checkMap) = @_;
>  
>      return if !$value;
>  
> @@ -31,7 +32,27 @@ sub parse_usb_device {
>      } elsif ($value =~ m/^spice$/i) {
>  	$res->{spice} = 1;
>      } else {
> -	return;
> +	# we have no ordinary usb device, must be a mapping
> +	my $devices = PVE::Mapping::USB::find_on_current_node($value);
> +	if ($checkMap) {
> +	    die "USB device mapping not found for '$value'\n" if !$devices || !scalar($devices->@*);
> +	    die "More than one USB mapping per host not supported\n" if scalar($devices->@*) > 1;
> +	    eval {
> +		PVE::Mapping::USB::assert_valid($value, $devices->[0]);
> +	    };
> +	    if (my $err = $@) {
> +		die "USB Mapping invalid (hardware probably changed): $err\n";
> +	    }
> +	    my $device = $devices->[0];
> +
> +	    if ($device->{path}) {
> +		$res = parse_usb_device($device->{path});
> +	    } else {
> +		$res = parse_usb_device($device->{id});
> +	    }
> +	}
> +
> +	$res->{mapped} = 1;
>      }
>  
>      return $res;
> @@ -111,7 +132,7 @@ sub get_usb_devices {
>  	my $port = $use_qemu_xhci ? $i + 1 : undef;
>  
>  	if (defined($d->{host})) {
> -	    my $hostdevice = parse_usb_device($d->{host});
> +	    my $hostdevice = parse_usb_device($d->{host}, 1);
>  	    $hostdevice->{usb3} = $d->{usb3};
>  	    if ($hostdevice->{spice}) {
>  		# usb redir support for spice
> -- 
> 2.30.2
> 
> 
> 
> _______________________________________________
> pve-devel mailing list
> pve-devel at lists.proxmox.com
> https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel
> 
> 
> 





More information about the pve-devel mailing list