From: "Daniel P. Berrange" <berra...@redhat.com> With the proposal of some new APIs[1] to libspice-server.so it is possible to add support for SPICE to the 'add_client' monitor command, bringing parity with VNC. Since SPICE can use TLS or plain connections, the command also gains a new 'tls' parameter to specify whether TLS should be attempted on the injected client sockets.
NB1, since there is no SPICE release with these APIs, I have guessed the next SPICE version number in the #ifdef to be 0x000a00 (ie 0.10.0 in hex). NB2, obviously this should only be merged once the SPICE developers have accepted my proposed patches to libspice-server.so * qmp-commands.hx: Add 'tls' parameter & missing doc for 'skipauth' parameter * monitor.c: Wire up SPICE for 'add_client' command * ui/qemu-spice.h, ui/spice-core.c: Add qemu_spice_display_add_client API to wire up from monitor [1] http://lists.freedesktop.org/archives/spice-devel/2011-October/005834.html Signed-off-by: Daniel P. Berrange <berra...@redhat.com> --- monitor.c | 9 +++++++-- qmp-commands.hx | 6 ++++-- ui/qemu-spice.h | 1 + ui/spice-core.c | 13 +++++++++++++ 4 files changed, 25 insertions(+), 4 deletions(-) diff --git a/monitor.c b/monitor.c index 31b212a..cae3b12 100644 --- a/monitor.c +++ b/monitor.c @@ -1120,13 +1120,18 @@ static int add_graphics_client(Monitor *mon, const QDict *qdict, QObject **ret_d CharDriverState *s; if (strcmp(protocol, "spice") == 0) { + int fd = monitor_get_fd(mon, fdname); + int skipauth = qdict_get_try_bool(qdict, "skipauth", 0); + int tls = qdict_get_try_bool(qdict, "tls", 0); if (!using_spice) { /* correct one? spice isn't a device ,,, */ qerror_report(QERR_DEVICE_NOT_ACTIVE, "spice"); return -1; } - qerror_report(QERR_ADD_CLIENT_FAILED); - return -1; + if (qemu_spice_display_add_client(fd, skipauth, tls) < 0) { + close(fd); + } + return 0; #ifdef CONFIG_VNC } else if (strcmp(protocol, "vnc") == 0) { int fd = monitor_get_fd(mon, fdname); diff --git a/qmp-commands.hx b/qmp-commands.hx index ea96191..de1ada3 100644 --- a/qmp-commands.hx +++ b/qmp-commands.hx @@ -911,8 +911,8 @@ EQMP { .name = "add_client", - .args_type = "protocol:s,fdname:s,skipauth:b?", - .params = "protocol fdname skipauth", + .args_type = "protocol:s,fdname:s,skipauth:b?,tls:b?", + .params = "protocol fdname skipauth tls", .help = "add a graphics client", .user_print = monitor_user_noop, .mhandler.cmd_new = add_graphics_client, @@ -928,6 +928,8 @@ Arguments: - "protocol": protocol name (json-string) - "fdname": file descriptor name (json-string) +- "skipauth": whether to skip authentication (json-bool) +- "tls": whether to perform TLS (json-bool) Example: diff --git a/ui/qemu-spice.h b/ui/qemu-spice.h index f34be69..a0e213c 100644 --- a/ui/qemu-spice.h +++ b/ui/qemu-spice.h @@ -32,6 +32,7 @@ void qemu_spice_init(void); void qemu_spice_input_init(void); void qemu_spice_audio_init(void); void qemu_spice_display_init(DisplayState *ds); +int qemu_spice_display_add_client(int csock, int skipauth, int tls); int qemu_spice_add_interface(SpiceBaseInstance *sin); int qemu_spice_set_passwd(const char *passwd, bool fail_if_connected, bool disconnect_if_connected); diff --git a/ui/spice-core.c b/ui/spice-core.c index 3cbc721..854670e 100644 --- a/ui/spice-core.c +++ b/ui/spice-core.c @@ -712,6 +712,19 @@ int qemu_spice_set_pw_expire(time_t expires) return qemu_spice_set_ticket(false, false); } +int qemu_spice_display_add_client(int csock, int skipauth, int tls) +{ +#if SPICE_SERVER_VERSION >= 0x000a00 + if (tls) { + return spice_server_add_ssl_client(spice_server, csock, skipauth); + } else { + return spice_server_add_client(spice_server, csock, skipauth); + } +#else + return -1; +#endif +} + static void spice_register_config(void) { qemu_add_opts(&qemu_spice_opts); -- 1.7.6.4