die "no storage ID specified (and no default storage)\n" if !$storeid;
my $defformat = PVE::Storage::storage_default_format($storecfg, $storeid);
my $fmt = $disk->{format} || $defformat;
- my $volid = PVE::Storage::vdisk_alloc($storecfg, $storeid, $vmid,
- $fmt, undef, $size*1024*1024);
- $disk->{file} = $volid;
- $disk->{size} = $size*1024*1024*1024;
+
+ my $volid;
+ if ($ds eq 'efidisk0') {
+ # handle efidisk
+ my $ovmfvars = '/usr/share/kvm/OVMF_VARS-pure-efi.fd';
+ die "uefi vars image not found\n" if ! -f $ovmfvars;
+ $volid = PVE::Storage::vdisk_alloc($storecfg, $storeid, $vmid,
+ $fmt, undef, 128);
+ $disk->{file} = $volid;
+ $disk->{size} = 128*1024;
+ my ($storeid, $volname) = PVE::Storage::parse_volume_id($volid);
+ my $scfg = PVE::Storage::storage_config($storecfg, $storeid);
+ my $qemufmt = PVE::QemuServer::qemu_img_format($scfg, $volname);
+ my $path = PVE::Storage::path($storecfg, $volid);
+ my $efidiskcmd = ['/usr/bin/qemu-img', 'convert', '-n', '-f', 'raw', '-O', $qemufmt];
+ push @$efidiskcmd, $ovmfvars;
+ push @$efidiskcmd, $path;
+
+ PVE::Storage::activate_volumes($storecfg, [$volid]);
+
+ eval { PVE::Tools::run_command($efidiskcmd); };
+ my $err = $@;
+ die "Copying of EFI Vars image failed: $err" if $err;
+ } else {
+ $volid = PVE::Storage::vdisk_alloc($storecfg, $storeid, $vmid,
+ $fmt, undef, $size*1024*1024);
+ $disk->{file} = $volid;
+ $disk->{size} = $size*1024*1024*1024;
+ }
push @$vollist, $volid;
delete $disk->{format}; # no longer needed
$res->{$ds} = PVE::QemuServer::print_drive($vmid, $disk);
return $vollist;
};
+my $cpuoptions = {
+ 'cores' => 1,
+ 'cpu' => 1,
+ 'cpulimit' => 1,
+ 'cpuunits' => 1,
+ 'numa' => 1,
+ 'smp' => 1,
+ 'sockets' => 1,
+ 'vcpus' => 1,
+};
+
+my $memoryoptions = {
+ 'memory' => 1,
+ 'balloon' => 1,
+ 'shares' => 1,
+};
+
+my $hwtypeoptions = {
+ 'acpi' => 1,
+ 'hotplug' => 1,
+ 'kvm' => 1,
+ 'machine' => 1,
+ 'scsihw' => 1,
+ 'smbios1' => 1,
+ 'tablet' => 1,
+ 'vga' => 1,
+ 'watchdog' => 1,
+};
+
+my $generaloptions = {
+ 'agent' => 1,
+ 'autostart' => 1,
+ 'bios' => 1,
+ 'description' => 1,
+ 'keyboard' => 1,
+ 'localtime' => 1,
+ 'migrate_downtime' => 1,
+ 'migrate_speed' => 1,
+ 'name' => 1,
+ 'onboot' => 1,
+ 'ostype' => 1,
+ 'protection' => 1,
+ 'reboot' => 1,
+ 'startdate' => 1,
+ 'startup' => 1,
+ 'tdf' => 1,
+ 'template' => 1,
+};
+
+my $vmpoweroptions = {
+ 'freeze' => 1,
+};
+
+my $diskoptions = {
+ 'boot' => 1,
+ 'bootdisk' => 1,
+};
+
my $check_vm_modify_config_perm = sub {
my ($rpcenv, $authuser, $vmid, $pool, $key_list) = @_;
foreach my $opt (@$key_list) {
# disk checks need to be done somewhere else
next if PVE::QemuServer::is_valid_drivename($opt);
+ next if $opt eq 'cdrom';
+ next if $opt =~ m/^unused\d+$/;
- if ($opt eq 'sockets' || $opt eq 'cores' ||
- $opt eq 'cpu' || $opt eq 'smp' || $opt eq 'vcpus' ||
- $opt eq 'cpulimit' || $opt eq 'cpuunits') {
+ if ($cpuoptions->{$opt} || $opt =~ m/^numa\d+$/) {
$rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.CPU']);
- } elsif ($opt eq 'memory' || $opt eq 'balloon' || $opt eq 'shares') {
+ } elsif ($memoryoptions->{$opt}) {
$rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.Memory']);
- } elsif ($opt eq 'args' || $opt eq 'lock') {
- die "only root can set '$opt' config\n";
- } elsif ($opt eq 'cpu' || $opt eq 'kvm' || $opt eq 'acpi' || $opt eq 'machine' ||
- $opt eq 'vga' || $opt eq 'watchdog' || $opt eq 'tablet' || $opt eq 'smbios1') {
+ } elsif ($hwtypeoptions->{$opt}) {
$rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.HWType']);
+ } elsif ($generaloptions->{$opt}) {
+ $rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.Options']);
+ # special case for startup since it changes host behaviour
+ if ($opt eq 'startup') {
+ $rpcenv->check_full($authuser, "/", ['Sys.Modify']);
+ }
+ } elsif ($vmpoweroptions->{$opt}) {
+ $rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.PowerMgmt']);
+ } elsif ($diskoptions->{$opt}) {
+ $rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.Disk']);
} elsif ($opt =~ m/^net\d+$/) {
$rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.Network']);
} else {
- $rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.Options']);
+ # catches usb\d+, hostpci\d+, args, lock, etc.
+ # new options will be checked here
+ die "only root can set '$opt' config\n";
}
}
die "unable to restore vm $vmid - vm is running\n"
if PVE::QemuServer::check_running($vmid);
+
+ die "unable to restore vm $vmid - vm is a template\n"
+ if PVE::QemuConfig->is_template($conf);
+
} else {
die "unable to restore vm $vmid - already existing on cluster node '$current_node'\n";
}
if (PVE::QemuServer::is_valid_drivename($opt)) {
# cleanup drive path
my $drive = PVE::QemuServer::parse_drive($opt, $param->{$opt});
+ raise_param_exc({ $opt => "unable to parse drive options" }) if !$drive;
PVE::QemuServer::cleanup_drive_path($opt, $storecfg, $drive);
$param->{$opt} = PVE::QemuServer::print_drive($vmid, $drive);
} elsif ($opt =~ m/^net(\d+)$/) {
my $vmstatus = PVE::QemuServer::vmstatus($param->{vmid}, 1);
my $status = $vmstatus->{$param->{vmid}};
- $status->{ha} = PVE::HA::Config::vm_is_ha_managed($param->{vmid});
+ $status->{ha} = PVE::HA::Config::get_service_status("vm:$param->{vmid}");
$status->{spice} = 1 if PVE::QemuServer::vga_conf_has_spice($conf->{vga});
skiplock => get_standard_option('skiplock'),
stateuri => get_standard_option('pve-qm-stateuri'),
migratedfrom => get_standard_option('pve-node',{ optional => 1 }),
+ migration_type => {
+ type => 'string',
+ enum => ['secure', 'insecure'],
+ description => "Migration traffic is encrypted using an SSH " .
+ "tunnel by default. On secure, completely private networks " .
+ "this can be disabled to increase performance.",
+ optional => 1,
+ },
+ migration_network => {
+ type => 'string',
+ format => 'CIDR',
+ description => "CIDR of the (sub) network that is used for migration.",
+ optional => 1,
+ },
machine => get_standard_option('pve-qm-machine'),
},
},
raise_param_exc({ migratedfrom => "Only root may use this option." })
if $migratedfrom && $authuser ne 'root@pam';
+ my $migration_type = extract_param($param, 'migration_type');
+ raise_param_exc({ migration_type => "Only root may use this option." })
+ if $migration_type && $authuser ne 'root@pam';
+
+ my $migration_network = extract_param($param, 'migration_network');
+ raise_param_exc({ migration_network => "Only root may use this option." })
+ if $migration_network && $authuser ne 'root@pam';
+
# read spice ticket from STDIN
my $spice_ticket;
if ($stateuri && ($stateuri eq 'tcp') && $migratedfrom && ($rpcenv->{type} eq 'cli')) {
syslog('info', "start VM $vmid: $upid\n");
PVE::QemuServer::vm_start($storecfg, $vmid, $stateuri, $skiplock, $migratedfrom, undef,
- $machine, $spice_ticket);
+ $machine, $spice_ticket, $migration_network, $migration_type);
return;
};
optional => 1,
},
keepActive => {
- description => "Do not decativate storage volumes.",
+ description => "Do not deactivate storage volumes.",
type => 'boolean',
optional => 1,
default => 0,
default => 0,
},
keepActive => {
- description => "Do not decativate storage volumes.",
+ description => "Do not deactivate storage volumes.",
type => 'boolean',
optional => 1,
default => 0,
my $storecfg = PVE::Storage::config();
+ my $shutdown = 1;
+
+ # if vm is paused, do not shutdown (but stop if forceStop = 1)
+ # otherwise, we will infer a shutdown command, but run into the timeout,
+ # then when the vm is resumed, it will instantly shutdown
+ #
+ # checking the qmp status here to get feedback to the gui/cli/api
+ # and the status query should not take too long
+ my $qmpstatus;
+ eval {
+ $qmpstatus = PVE::QemuServer::vm_qmp_command($vmid, { execute => "query-status" }, 0);
+ };
+ my $err = $@ if $@;
+
+ if (!$err && $qmpstatus->{status} eq "paused") {
+ if ($param->{forceStop}) {
+ warn "VM is paused - stop instead of shutdown\n";
+ $shutdown = 0;
+ } else {
+ die "VM is paused - cannot shutdown\n";
+ }
+ }
+
my $realcmd = sub {
my $upid = shift;
syslog('info', "shutdown VM $vmid: $upid\n");
PVE::QemuServer::vm_stop($storecfg, $vmid, $skiplock, 0, $param->{timeout},
- 1, $param->{forceStop}, $keepActive);
+ $shutdown, $param->{forceStop}, $keepActive);
return;
};
# always change MAC! address
if ($opt =~ m/^net(\d+)$/) {
my $net = PVE::QemuServer::parse_net($value);
- $net->{macaddr} = PVE::Tools::random_ether_addr();
+ my $dc = PVE::Cluster::cfs_read_file('datacenter.cfg');
+ $net->{macaddr} = PVE::Tools::random_ether_addr($dc->{mac_prefix});
$newconf->{$opt} = PVE::QemuServer::print_net($net);
} elsif (PVE::QemuServer::is_valid_drivename($opt)) {
my $drive = PVE::QemuServer::parse_drive($opt, $value);
if ($target) {
# always deactivate volumes - avoid lvm LVs to be active on several nodes
PVE::Storage::deactivate_volumes($storecfg, $vollist, $snapname) if !$running;
+ PVE::Storage::deactivate_volumes($storecfg, $newvollist);
my $newconffile = PVE::QemuConfig->config_file($newid, $target);
die "Failed to move config to node '$target' - rename failed: $!\n"
my $conf = PVE::QemuConfig->load_config($vmid);
+ PVE::QemuConfig->check_lock($conf);
+
die "checksum missmatch (file change by other user?)\n"
if $digest && $digest ne $conf->{digest};
die "you can't move on the same storage with same format\n" if $oldstoreid eq $storeid &&
(!$format || !$oldfmt || $oldfmt eq $format);
+ # this only checks snapshots because $disk is passed!
+ my $snapshotted = PVE::QemuServer::is_volume_in_use($storecfg, $conf, $disk, $old_volid);
+ die "you can't move a disk with snapshots and delete the source\n"
+ if $snapshotted && $param->{delete};
+
PVE::Cluster::log_msg('info', $authuser, "move disk VM $vmid: move --disk $disk --storage $storeid");
my $running = PVE::QemuServer::check_running($vmid);
eval {
local $SIG{INT} = $SIG{TERM} = $SIG{QUIT} = $SIG{HUP} = sub { die "interrupted by signal\n"; };
+ warn "moving disk with snapshots, snapshots will not be moved!\n"
+ if $snapshotted;
+
my $newdrive = PVE::QemuServer::clone_disk($storecfg, $vmid, $running, $disk, $drive, undef,
$vmid, $storeid, $format, 1, $newvollist);
}
if ($param->{delete}) {
- if (PVE::QemuServer::is_volume_in_use($storecfg, $conf, undef, $old_volid)) {
- warn "volume $old_volid still has snapshots, can't delete it\n";
- PVE::QemuConfig->add_unused_volume($conf, $old_volid);
- PVE::QemuConfig->write_config($vmid, $conf);
- } else {
- eval { PVE::Storage::vdisk_free($storecfg, $old_volid); };
- warn $@ if $@;
- }
+ eval {
+ PVE::Storage::deactivate_volumes($storecfg, [$old_volid]);
+ PVE::Storage::vdisk_free($storecfg, $old_volid);
+ };
+ warn $@ if $@;
}
};
description => "Allow to migrate VMs which use local devices. Only root may use this option.",
optional => 1,
},
+ migration_type => {
+ type => 'string',
+ enum => ['secure', 'insecure'],
+ description => "Migration traffic is encrypted using an SSH " .
+ "tunnel by default. On secure, completely private networks " .
+ "this can be disabled to increase performance.",
+ optional => 1,
+ },
+ migration_network => {
+ type => 'string',
+ format => 'CIDR',
+ description => "CIDR of the (sub) network that is used for migration.",
+ optional => 1,
+ },
},
},
returns => {
raise_param_exc({ force => "Only root may use this option." })
if $param->{force} && $authuser ne 'root@pam';
+ raise_param_exc({ migration_type => "Only root may use this option." })
+ if $param->{migration_type} && $authuser ne 'root@pam';
+
+ # allow root only until better network permissions are available
+ raise_param_exc({ migration_network => "Only root may use this option." })
+ if $param->{migration_network} && $authuser ne 'root@pam';
+
# test if VM exists
my $conf = PVE::QemuConfig->load_config($vmid);
$rpcenv->check($authuser, "/storage/$storeid", ['Datastore.AllocateSpace']);
+ PVE::Storage::activate_volumes($storecfg, [$volid]);
my $size = PVE::Storage::volume_size_info($storecfg, $volid, 5);
die "internal error" if $sizestr !~ m/^(\+)?(\d+(\.\d+)?)([KMGT])?$/;
parameters => {
additionalProperties => 0,
properties => {
- vmid => get_standard_option('pve-vmid'),
+ vmid => get_standard_option('pve-vmid', { completion => \&PVE::QemuServer::complete_vmid }),
node => get_standard_option('pve-node'),
},
},