Go to file
Daniel P. Berrange ac1d887849 crypto: add QCryptoSecret object class for password/key handling
Introduce a new QCryptoSecret object class which will be used
for providing passwords and keys to other objects which need
sensitive credentials.

The new object can provide secret values directly as properties,
or indirectly via a file. The latter includes support for file
descriptor passing syntax on UNIX platforms. Ordinarily passing
secret values directly as properties is insecure, since they
are visible in process listings, or in log files showing the
CLI args / QMP commands. It is possible to use AES-256-CBC to
encrypt the secret values though, in which case all that is
visible is the ciphertext.  For ad hoc developer testing though,
it is fine to provide the secrets directly without encryption
so this is not explicitly forbidden.

The anticipated scenario is that libvirtd will create a random
master key per QEMU instance (eg /var/run/libvirt/qemu/$VMNAME.key)
and will use that key to encrypt all passwords it provides to
QEMU via '-object secret,....'.  This avoids the need for libvirt
(or other mgmt apps) to worry about file descriptor passing.

It also makes life easier for people who are scripting the
management of QEMU, for whom FD passing is significantly more
complex.

Providing data inline (insecure, only for ad hoc dev testing)

  $QEMU -object secret,id=sec0,data=letmein

Providing data indirectly in raw format

  printf "letmein" > mypasswd.txt
  $QEMU -object secret,id=sec0,file=mypasswd.txt

Providing data indirectly in base64 format

  $QEMU -object secret,id=sec0,file=mykey.b64,format=base64

Providing data with encryption

  $QEMU -object secret,id=master0,file=mykey.b64,format=base64 \
        -object secret,id=sec0,data=[base64 ciphertext],\
	           keyid=master0,iv=[base64 IV],format=base64

Note that 'format' here refers to the format of the ciphertext
data. The decrypted data must always be in raw byte format.

More examples are shown in the updated docs.

Reviewed-by: Eric Blake <eblake@redhat.com>
Signed-off-by: Daniel P. Berrange <berrange@redhat.com>
2015-12-18 16:25:08 +00:00
audio audio/coreaudio.c: Avoid deprecated AudioDeviceAdd/RemoveIOProc APIs 2015-12-15 11:08:12 +01:00
backends hostmem: Ignore ENOSYS while setting MPOL_DEFAULT 2015-11-23 10:43:38 -02:00
block qobject: Rename qtype_code to QType 2015-12-17 08:21:28 +01:00
bsd-user linux-user: convert DEBUG_SIGNAL logging to tracepoints 2015-12-17 17:33:48 +01:00
contrib ivshmem-server: fix possible OVERRUN 2015-11-06 15:42:38 +03:00
crypto crypto: add QCryptoSecret object class for password/key handling 2015-12-18 16:25:08 +00:00
default-configs hw/misc: Hyper-V test device 'hyperv-testdev' 2015-12-17 15:24:35 +01:00
disas disas/arm: avoid clang shifting negative signed warning 2015-11-17 18:35:56 +08:00
docs fw_cfg: doc updates, various optimizations. 2015-12-17 12:40:07 +00:00
dtc@65cc4d2748 dtc: Update dtc / libfdt submodule to version 1.4.0 2015-06-03 23:56:49 +02:00
fpu target-s390x: define default NaN values 2015-06-05 01:37:58 +02:00
fsdev fsdev-proxy-helper: avoid TOC/TOU race 2015-11-30 12:31:53 +01:00
gdb-xml s390x/gdb: expose virtualization specific registers 2015-10-02 13:31:52 +02:00
hw scsi: always call notifier on async cancellation 2015-12-17 17:33:49 +01:00
include crypto: add QCryptoSecret object class for password/key handling 2015-12-18 16:25:08 +00:00
io io: add QIOChannelBuffer class 2015-12-18 12:18:31 +00:00
libdecnumber typofixes - v4 2015-09-11 10:45:43 +03:00
linux-headers linux-headers: update from kvm/next 2015-12-17 15:24:34 +01:00
linux-user linux-user: convert DEBUG_SIGNAL logging to tracepoints 2015-12-17 17:33:48 +01:00
migration qapi: Don't let implicit enum MAX member collide 2015-12-17 08:21:28 +01:00
net qapi: Don't let implicit enum MAX member collide 2015-12-17 08:21:28 +01:00
pc-bios pc-bios/s390-ccw: rebuild image 2015-12-01 09:57:27 +01:00
pixman@87eea99e44 pixman: update internal copy to pixman-0.32.6 2014-09-15 08:14:19 +02:00
po Update language files for QEMU 2.5.0 2015-12-10 13:50:45 +00:00
qapi crypto: add QCryptoSecret object class for password/key handling 2015-12-18 16:25:08 +00:00
qga qga: convert to use error checked base64 decode 2015-12-18 16:25:08 +00:00
qobject qapi: Convert QType into QAPI built-in enum type 2015-12-17 08:21:28 +01:00
qom qom: Clean up assertions to display values on failure 2015-11-19 15:15:33 +01:00
replay qapi: Don't let implicit enum MAX member collide 2015-12-17 08:21:28 +01:00
roms pseries: Update SLOF firmware image to qemu-slof-20151103 2015-11-11 13:28:45 +11:00
scripts io: add QIOChannelSocket class 2015-12-18 12:18:31 +00:00
slirp slirp: Fix type casts and format strings in debug code 2015-11-12 13:48:36 +08:00
stubs kvm: x86: add support for KVM_CAP_SPLIT_IRQCHIP 2015-12-17 17:33:47 +01:00
target-alpha target-alpha: fix uninitialized variable 2015-11-06 15:42:38 +03:00
target-arm kvm: x86: add support for KVM_CAP_SPLIT_IRQCHIP 2015-12-17 17:33:47 +01:00
target-cris cris: avoid "naked" qemu_log 2015-12-17 17:33:47 +01:00
target-i386 target-i386: kvm: clear unusable segments' flags in migration 2015-12-17 17:33:49 +01:00
target-lm32 target-*: Advance pc after recognizing a breakpoint 2015-10-28 10:57:16 -07:00
target-m68k target-*: Advance pc after recognizing a breakpoint 2015-10-28 10:57:16 -07:00
target-microblaze microblaze: avoid "naked" qemu_log 2015-12-17 17:33:48 +01:00
target-mips target-mips: flush QEMU TLB when disabling 64-bit addressing 2015-11-24 11:01:03 +00:00
target-moxie target-*: Advance pc after recognizing a breakpoint 2015-10-28 10:57:16 -07:00
target-openrisc target-*: Advance pc after recognizing a breakpoint 2015-10-28 10:57:16 -07:00
target-ppc ppc: cleanup logging 2015-12-17 17:33:48 +01:00
target-s390x s390x: avoid "naked" qemu_log 2015-12-17 17:33:48 +01:00
target-sh4 target-*: Advance pc after recognizing a breakpoint 2015-10-28 10:57:16 -07:00
target-sparc sparc: allow CASA with ASI 0xa from user space 2015-12-10 11:19:18 +00:00
target-tilegx target-tilegx: Implement prefetch instructions in pipe y2 2015-10-22 07:51:49 -10:00
target-tricore tricore: avoid "naked" qemu_log 2015-12-17 17:33:48 +01:00
target-unicore32 target-*: Advance pc after recognizing a breakpoint 2015-10-28 10:57:16 -07:00
target-xtensa xtensa: avoid "naked" qemu_log 2015-12-17 17:33:48 +01:00
tcg tcg: Increase the highwater reservation 2015-12-01 14:36:32 -08:00
tests crypto: add QCryptoSecret object class for password/key handling 2015-12-18 16:25:08 +00:00
trace trace/simple: Fix warning and wrong trace file name for MinGW 2015-11-30 06:47:02 +01:00
ui qapi: Change munging of CamelCase enum values 2015-12-17 08:21:28 +01:00
util util: add base64 decoding function 2015-12-18 16:25:08 +00:00
.dir-locals.el Add .dir-locals.el file to configure emacs coding style 2015-10-08 19:46:01 +03:00
.exrc qemu: add .exrc 2012-09-07 09:02:44 +03:00
.gitignore maint: Ignore ivshmem binaries 2015-11-06 15:42:38 +03:00
.gitmodules PPC: Add u-boot firmware for e500 2014-06-16 13:24:35 +02:00
.mailmap Update mailmap 2013-09-05 09:40:31 -05:00
.travis.yml .travis.yml: Run make check for all targets, not just some 2015-10-08 19:46:47 +03:00
accel.c accel: Create accel object when initializing machine 2014-10-09 15:36:14 +02:00
aio-posix.c aio-epoll: Fix use-after-free of node 2015-11-17 18:35:57 +08:00
aio-win32.c aio: Introduce aio_context_setup 2015-11-09 09:59:32 +00:00
arch_init.c smbios: move smbios code into a common folder 2015-08-13 14:08:30 +03:00
async.c aio: Introduce aio_context_setup 2015-11-09 09:59:32 +00:00
balloon.c Inhibit ballooning during postcopy 2015-11-10 15:00:28 +01:00
block.c blkdebug: Merge hand-rolled and qapi BlkdebugEvent enum 2015-12-17 08:21:27 +01:00
blockdev-nbd.c Include monitor/monitor.h exactly where needed 2015-06-22 18:20:41 +02:00
blockdev.c qapi: Don't let implicit enum MAX member collide 2015-12-17 08:21:28 +01:00
blockjob.c block: Add block job transactions 2015-11-12 16:22:44 +01:00
bootdevice.c misc: fix typos in copyright declaration 2015-03-26 14:21:43 +01:00
bt-host.c sysemu: avoid proliferation of include/ subdirectories 2013-04-15 18:19:25 +02:00
bt-vhci.c sysemu: avoid proliferation of include/ subdirectories 2013-04-15 18:19:25 +02:00
Changelog Use qemu-project.org domain name 2013-10-11 09:34:56 -07:00
CODING_STYLE CODING_STYLE: update mixed declaration rules 2015-09-09 15:34:54 +02:00
configure configure: Fix shell syntax to placate OpenBSD's pdksh 2015-12-18 13:32:49 +00:00
COPYING
COPYING.LIB
cpu-exec-common.c exec.c: Collect AddressSpace related fields into a CPUAddressSpace struct 2015-10-12 18:29:26 +02:00
cpu-exec.c So here it is, let's see what happens. 2015-11-06 11:31:40 +00:00
cpus.c cpu: Convert CpuInfo into flat union 2015-12-17 08:21:28 +01:00
cputlb.c cputlb: Change tlb_set_dirty() arg to cpu 2015-09-16 17:33:33 +02:00
device_tree.c device_tree: Fix a typo 2015-07-27 22:44:47 +03:00
device-hotplug.c pci-hotplug-old: Has been dead for five major releases, bury 2015-03-01 12:37:54 +01:00
disas.c disas: QOMify alpha specific disas setup 2015-10-22 15:49:40 +02:00
dma-helpers.c range: remove useless inclusions 2015-04-30 16:05:48 +03:00
dump.c Include qapi/qmp/qerror.h exactly where needed 2015-06-22 18:20:41 +02:00
exec.c memory: try to inline constant-length reads 2015-12-17 17:33:49 +01:00
gdbstub.c gdbstub: Fix buffer overflows in gdb_handle_packet() 2015-11-06 15:42:37 +03:00
HACKING HACKING: Document vaddr type usage 2013-07-23 02:41:31 +02:00
hmp-commands-info.hx hmp: added io apic dump state 2015-09-25 12:04:42 +02:00
hmp-commands.hx migrate-start-postcopy: Improve text 2015-11-12 17:54:39 +01:00
hmp.c cpu: Convert CpuInfo into flat union 2015-12-17 08:21:28 +01:00
hmp.h migrate_start_postcopy: Command to trigger transition to postcopy 2015-11-10 15:00:26 +01:00
iohandler.c aio: Add "is_external" flag for event handlers 2015-10-23 18:18:23 +02:00
ioport.c ioport: do not use CPU_LOG_IOPORT 2015-11-04 15:02:30 +01:00
iothread.c iothread: include id in thread name 2015-12-03 11:08:01 +08:00
kvm-all.c kvm: x86: add support for KVM_CAP_SPLIT_IRQCHIP 2015-12-17 17:33:47 +01:00
kvm-stub.c KVM: add support for any length io eventfd 2015-11-12 15:49:32 +02:00
LICENSE vfio: move hw/misc/vfio.c to hw/vfio/pci.c Move vfio.h into include/hw/vfio 2014-12-19 15:24:06 -07:00
main-loop.c main-loop: suppress warnings under qtest 2015-12-02 12:01:43 +01:00
MAINTAINERS io: add abstract QIOChannel classes 2015-12-18 12:18:05 +00:00
Makefile io: add abstract QIOChannel classes 2015-12-18 12:18:05 +00:00
Makefile.objs io: add abstract QIOChannel classes 2015-12-18 12:18:05 +00:00
Makefile.target io: add abstract QIOChannel classes 2015-12-18 12:18:05 +00:00
memory_mapping.c memory_mapping: Rework cpu related includes 2015-06-26 16:00:50 +02:00
memory.c memory: inline a few small accessors 2015-12-17 17:33:49 +01:00
module-common.c module: implement module loading 2014-02-20 13:14:18 +01:00
monitor.c qapi: Change munging of CamelCase enum values 2015-12-17 08:21:28 +01:00
nbd.c nbd: Mark fd handlers client type as "external" 2015-10-23 18:18:23 +02:00
numa.c memory: Convert to new qapi union layout 2015-11-02 08:30:28 +01:00
os-posix.c rcu: do not create thread in pthread_atfork callback 2015-04-01 10:06:38 +02:00
os-win32.c maint: remove unused include for signal.h 2015-09-11 10:21:38 +03:00
page_cache.c maint: remove unused include for strings.h 2015-09-11 10:21:38 +03:00
qapi-schema.json qemu-char: convert to use error checked base64 decode 2015-12-18 16:25:08 +00:00
qdev-monitor.c -----BEGIN PGP SIGNATURE----- 2015-10-12 14:29:29 +01:00
qdict-test-data.txt
qemu-bridge-helper.c qemu-bridge-helper: Fix fd leak in main() 2014-06-27 10:39:10 +02:00
qemu-char.c qemu-char: convert to use error checked base64 decode 2015-12-18 16:25:08 +00:00
qemu-doc.texi ivshmem: Rename property memdev to x-memdev for 2.5 2015-11-25 10:24:27 +01:00
qemu-ga.texi qga: start a man page 2015-09-01 13:16:26 -05:00
qemu-img-cmds.hx qemu-img: Add progress output for amend 2014-11-03 11:41:48 +00:00
qemu-img.c blockjob: Introduce reference count and fix reference to job->bs 2015-11-12 16:22:43 +01:00
qemu-img.texi maint: remove / fix many doubled words 2015-09-11 10:21:38 +03:00
qemu-io-cmds.c qemu-io: Account for failed, invalid and flush operations 2015-11-12 16:22:46 +01:00
qemu-io.c qemu-io: Remove duplicate 'open' error message 2015-09-14 16:51:36 +02:00
qemu-log.c user: introduce "-d page" 2015-12-17 17:33:48 +01:00
qemu-nbd.c qapi: Don't let implicit enum MAX member collide 2015-12-17 08:21:28 +01:00
qemu-nbd.texi nbd: Miscellaneous typo fixes. 2014-05-24 00:07:29 +04:00
qemu-options-wrapper.h vl.c: In qemu -h output, only print options for the arch we are running as 2011-12-19 10:27:33 -06:00
qemu-options.h vl.c: Move option generation logic into a wrapper file 2011-12-19 10:27:33 -06:00
qemu-options.hx crypto: add QCryptoSecret object class for password/key handling 2015-12-18 16:25:08 +00:00
qemu-seccomp.c seccomp: add cacheflush to whitelist 2015-11-16 09:48:53 +01:00
qemu-tech.texi doc: Refresh URLs in the qemu-tech documentation 2015-09-25 12:20:21 +02:00
qemu-timer.c replay: checkpoints 2015-11-06 10:16:03 +01:00
qemu.nsi nsis: Add QEMU version information to Windows registry 2015-09-24 20:52:28 +02:00
qemu.sasl sasl: Avoid 'Could not find keytab file' in syslog 2014-03-15 13:54:18 +04:00
qjson.c QJSON: Use OBJECT_CHECK 2015-05-11 08:59:07 -04:00
qmp-commands.hx qemu-char: convert to use error checked base64 decode 2015-12-18 16:25:08 +00:00
qmp.c qmp: Convert QMP code to use object property iterators 2015-11-18 21:13:48 +01:00
qtest.c Move page_size_init earlier 2015-11-10 14:51:48 +01:00
README README: fill out some useful quickstart information 2015-10-13 18:48:46 +02:00
rules.mak make: load only required dependency files. 2015-08-13 14:08:25 +03:00
softmmu_template.h softmmu: remove now unused functions 2015-09-11 08:16:05 -07:00
spice-qemu-char.c char: Convert to new qapi union layout 2015-11-02 08:30:27 +01:00
tcg-runtime.c tcg: Push tcg-runtime routines into exec/helper-* 2014-05-28 09:33:54 -07:00
tci.c tcg: Rename debug_insn_start to insn_start 2015-10-07 20:36:26 +11:00
thread-pool.c coroutine: move into libqemuutil.a library 2015-10-20 14:59:04 +01:00
thunk.c linux-user: Allocate thunk size dynamically 2015-06-15 11:36:58 +03:00
tpm.c qapi: Don't let implicit enum MAX member collide 2015-12-17 08:21:28 +01:00
trace-events io: add QIOChannelCommand class 2015-12-18 12:18:31 +00:00
translate-all.c translate-all: ensure host page mask is always extended with 1's 2015-12-02 13:12:30 +01:00
translate-all.h translate-all: remove unnecessary argument to tb_invalidate_phys_range 2015-06-05 17:09:59 +02:00
translate-common.c translate-all: ensure host page mask is always extended with 1's 2015-12-02 13:12:30 +01:00
user-exec.c osdep.h: Remove qemu_printf 2015-08-19 16:29:53 +01:00
VERSION Open 2.6 development tree 2015-12-17 10:17:08 +00:00
version.rc Use qemu-project.org domain name 2013-10-11 09:34:56 -07:00
vl.c qapi: Don't let implicit enum MAX member collide 2015-12-17 08:21:28 +01:00
xen-common-stub.c accel: Move Xen registration code to xen-common.c 2014-10-04 08:59:15 +02:00
xen-common.c migration: Fix regression for xenfv and pc,accel=xen machine. 2015-08-03 16:13:40 +00:00
xen-hvm-stub.c pc: Remove redundant arguments from xen_hvm_init() 2015-09-10 11:05:40 +03:00
xen-hvm.c Fix bad error handling after memory_region_init_ram() 2015-09-18 14:39:29 +02:00
xen-mapcache.c maint: avoid useless "if (foo) free(foo)" pattern 2015-09-11 10:21:38 +03:00

         QEMU README
         ===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:

  mkdir build
  cd build
  ../configure
  make

Complete details of the process for building and configuring QEMU for
all supported host platforms can be found in the qemu-tech.html file.
Additional information can also be found online via the QEMU website:

  http://qemu-project.org/Hosts/Linux
  http://qemu-project.org/Hosts/W32


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

   git clone git://git.qemu-project.org/qemu.git

When submitting patches, the preferred approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the HACKING and CODING_STYLE files.

Additional information on submitting patches can be found online via
the QEMU website

  http://qemu-project.org/Contribute/SubmitAPatch
  http://qemu-project.org/Contribute/TrivialPatches


Bug reporting
=============

The QEMU project uses Launchpad as its primary upstream bug tracker. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

  https://bugs.launchpad.net/qemu/

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via launchpad.

For additional information on bug reporting consult:

  http://qemu-project.org/Contribute/ReportABug


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

 - qemu-devel@nongnu.org
   http://lists.nongnu.org/mailman/listinfo/qemu-devel
 - #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

  http://qemu-project.org/Contribute/StartHere

-- End