管理 QEMU 磁盘镜像、快照和启动顺序

原作:QEMU 文档贡献者。本文合并翻译 Disk Images 与 Managing device boot order with bootindex properties。读取时页脚为 QEMU 11.1.50,属于 master 开发文档,不能替代本机版本手册。原手册按 GNU GPL 第 2 版发布;本译稿保留该许可和来源。编者核查及修改日期为 2026-10-05,所有命令均未执行。

QEMU来宾写入进入snapshot临时层,commit可回写基盘;固件按bootindex解释启动优先级的原创示意图
未完纪原创技术图,依据原文绘制,非运行截图。

创建磁盘镜像

QEMU 支持随非空扇区写入而增长的镜像,以及压缩、加密镜像。快速创建形式是 qemu-img create myimage.img mysize。原镜像页把裸容量称为 KB,但同版本的 qemu-img 工具手册明确说明 SIZE 的裸数值单位为字节。编者因此改用显式格式和 G 后缀:

qemu-img create -f qcow2 myimage.qcow2 20G
qemu-img info myimage.qcow2

这是在全新、可丢弃路径上创建 20G 虚拟容量镜像的示例,不是执行记录。K/k 为 1024 字节,M 为 1024K,G 为 1024M。虚拟容量与宿主实际占用不同;执行前确认没有同名重要文件。

临时 snapshot 模式

-snapshot 让 QEMU 把镜像视为只读,将写入扇区存进临时文件,原文描述该文件位于 /tmp。但监视器命令 commit,或串口控制台的 Ctrl+a s,仍能强制回写原始磁盘镜像。因此这不是存储权限层面的绝对只读保护。

VM 快照

VM 快照包含 CPU、RAM、设备状态和全部可写磁盘内容。至少需要一块不可移除、可写的 qcow2 块设备,通常为第一块虚拟硬盘。savevm 新建或替换快照,除数字 ID 外还能命名;loadvm 恢复,delvm 删除,info snapshots 查询。下面是原手册历史输出:

(qemu) info snapshots
Snapshot devices: hda
Snapshot list (from hda):
ID        TAG                 VM SIZE                DATE       VM CLOCK
1         start                   41 M 2006-08-06 12:38:02   00:00:14.954
2                                 40 M 2006-08-06 12:43:29   00:00:18.633
3         msys                    40 M 2006-08-06 12:44:04   00:00:23.514

VM 状态信息存放于首个不可移除、可写的 qcow2 设备,各磁盘快照则保存在各自镜像内。快照共享扇区,因此难以单独评估每个快照的完整磁盘占用,列表中的 VM SIZE 仅为 VM 状态大小。开启另一项功能 -snapshot 后仍可创建 VM 快照,但它们会随 QEMU 退出而消失。

原文列出的限制包括:快照后插入或移除的可移动设备无法妥善处理;部分驱动(尤其 USB)状态保存和恢复不完整。编者补充:恢复要求设备和整个镜像链相容;恢复、删除和 commit 都可能改变数据,内部快照不能替代独立备份。

镜像格式与参数

镜像既供虚拟机使用,也供 qemu-img 等工具使用。raw 与 qcow2 是主要格式,其他格式多用于兼容旧 QEMU 或其他虚拟化平台。qemu-img create 和 convert 的 -o 接受格式专属选项。

raw

raw 简单,易于导出。宿主文件系统支持空洞时(如 Linux 文件系统与 Windows NTFS),仅写入扇区占用实际空间。使用 qemu-img info 或 Unix/Linux 的 ls -ls 看实际占用。preallocation 取 off、falloc 或 full:falloc 使用 posix_fallocate();full 向底层写数据进行预分配,具体介质上的数据不保证全零。

qcow2

qcow2 支持紧凑镜像、zlib 压缩与多个 VM 快照。原文用 Windows 举“不支持空洞”的例子不宜泛化,因为 NTFS 可以支持稀疏文件。其选项如下:

选项 含义
compat 0.10 为 QEMU 0.10 起可读的传统格式;默认 1.1 开启 QEMU 1.1 及之后理解的扩展,包括零簇及稀疏镜像高效 copy-on-read。
backing_file / backing_fmt 基盘文件名及格式。增量层依赖基盘,不能随意移动、修改或丢失它。
cluster_size 512 字节至 2M;小簇可能节省空间,大簇通常有利于性能。
preallocation off、metadata、falloc、full。预分配元数据让初始文件增大,可能改善增长性能;falloc/full 还预分配数据空间。
lazy_refcounts on 延迟引用计数更新以减少元数据 I/O,对 cache=writethrough 尤有意义。宿主崩溃后下次打开需自动重建引用计数,涉及 qemu-img check -r all,可能耗时。要求 compat=1.1。
nocow 仅对 btrfs 有效,减少宿主和来宾双层 COW 的性能开销。可通过 nodatacow 挂载影响新文件,或给空文件加 NOCOW 属性;本选项采用后者。无法给已有数据的 COW 文件直接转换;lsattr filename 的大写 C 表示 NOCOW。

旧 encryption 已弃用,等价于 encrypt.format=aes。其 128 位 AES-CBC 使用基于扇区号的可预测 IV,易受选择明文攻击;口令直接成为密钥,弱口令风险高;泄露后不能直接更换口令保护旧镜像,必须克隆到新口令镜像再处理旧副本,现代介质安全擦除也不能简单保证。系统模拟器已不支持该格式,工具仅为旧数据迁移与兼容保留它。

需要原生加密应使用 encrypt.format=luks,它加密 qcow2 载荷而不加密头部。encrypt.key-secret 引用含口令的 secret 对象。其他 LUKS 参数及当前默认值:encrypt.cipher-alg=aes-256、encrypt.cipher-mode=xts、encrypt.ivgen-alg=plain64;需要 IV 哈希时 encrypt.ivgen-hash-alg=sha256;PBKDF 的 encrypt.hash-alg=sha256,每个 key slot 的 encrypt.iter-time=2000 毫秒。

兼容格式与只读格式

格式 功能及选项
qed 旧格式,支持基盘和紧凑存储。转 qcow2 时可考虑 lazy_refcounts=on。backing_file 指基盘,backing_fmt 用于无法自动识别格式的情况;cluster_size 是 4K–64K 的二次幂;table_size 为每个 L1/L2 表占用簇数,是 1–16 的二次幂,通常无需更改,可供性能实验。
qcow 旧格式,支持基盘、紧凑存储、压缩和旧加密。backing_file 指基盘;encryption 等价于 encrypt.format=aes,encrypt.key-secret 提供旧密钥;同样受 AES-CBC 缺陷影响,系统模拟器不再支持,需加密则迁移到 qcow2 + LUKS。
luks 独立 LUKS v1 格式,兼容 Linux dm-crypt/cryptsetup。key-secret 指口令;cipher-alg、cipher-mode、ivgen-alg、ivgen-hash-alg、hash-alg、iter-time 默认值与上文一致,参数名不加 encrypt. 前缀。
vdi VirtualBox 1.1 兼容格式,static=on 预分配元数据。
vmdk VMware 3/4 兼容;支持 backing_file。compat6 创建第 6 版格式,hwversion 指硬件版本,两者不能同设。subformat 为 monolithicSparse(默认)、monolithicFlat、twoGbMaxExtentSparse、twoGbMaxExtentFlat、streamOptimized。
vpc VirtualPC VHD;subformat 为 dynamic(默认)或 fixed。
vhdx Hyper-V VHDX;subformat 为 dynamic(默认)或 fixed。block_state_zero=on 默认把载荷块标为 ZERO;off 改为 PAYLOAD_BLOCK_NOT_PRESENT,读取器可返回任意数据,动态转换时不可关闭。block_size 为 1–256 MB,0 自动计算;log_size 最小 1 MB。

只读支持还包括 bochs 的 growing 类型、cloop 压缩 Linux 光盘(例如 Knoppix)、Apple dmg、Parallels 镜像。兼容格式名称不等于对其他产品所有新版本格式的保证。

主机设备

原文主机设备说明适用于 QEMU 0.8.3 及以后,实际仍需匹配当前平台版本。Linux 可在权限足够时用设备路径替代镜像文件,如 /dev/cdrom。光驱支持插入、移除和来宾弹出,当前只支持数据 CD。软盘更换检测不准确,主机软盘支持已弃用。

硬盘通常应传整盘(原例 /dev/hdb 而非 /dev/hdb1)才能呈现分区盘。写入会破坏宿主数据,原文建议只读权限或 snapshot;结合 commit 回写能力,应把真正只读权限作为更强边界。zoned 块设备需模拟控制器支持,原例块参数为 --blockdev host_device,node-name=drive0,filename=/dev/nullb0,cache.direct=on,不是让读者替换生产硬盘的建议。

Windows 光驱优先用盘符如 d:,亦接受 \\.\d:;/dev/cdrom 为首个光驱别名。当前无专门可移动介质处理,宜用 change/eject。硬盘为 \\.\PhysicalDriveN,N 从 0 起,误写同样危及宿主数据。macOS 也以 /dev/cdrom 表示首个光驱,并建议 change/eject 处理介质变化。

虚拟 FAT 目录

QEMU 可把宿主目录树直接呈现为 FAT,无需复制到镜像或以 SMB/NFS 导出,默认只读:

qemu-system-x86_64 linux.img -hdb fat:/my_directory
qemu-system-x86_64 linux.img -fda fat:floppy:/my_directory

:floppy: 以软盘方式呈现。fat:floppy:rw:/my_directory 的读写支持在原文标为测试阶段;禁止非 ASCII 文件名、混用 snapshot 与 :rw:、期待 loadvm 正确恢复,或来宾访问时宿主同时修改目录。不要让这一实验路径操作重要宿主目录。

NBD

QEMU 可使用网络导出的块设备,也可通过本机 Unix socket 访问:

qemu-system-x86_64 linux.img -hdb nbd://my_nbd_server.mydomain.org:1024/
qemu-nbd --socket=/tmp/my_socket my_disk.qcow2
qemu-system-x86_64 linux.img -hdb nbd+unix://?socket=/tmp/my_socket

qemu-nbd --socket=/tmp/my_socket --share=2 my_disk.qcow2 允许两个来宾连接;它们分别在各自 -hdb 中用同一 URI。但多连接不自动赋予安全的并发写语义。NBD 2.9.18 起或 QEMU 服务支持命名导出,如 nbd://localhost/debian-500-ppc-netinst、nbd://localhost/openSUSE-11.1-ppc-netinst 可作为光盘输入。URI 从 QEMU 1.3 起支持。旧式写法包括 nbd:my_nbd_server.mydomain.org:1024、nbd:unix:/tmp/my_socket、nbd:localhost:10809:exportname=debian-500-ppc-netinst,保留用于识别历史配置。

iSCSI LUN

第一种访问方法是宿主先挂载 LUN,使其出现为普通 SCSI 设备,再交给 QEMU;操作依宿主系统而异。另一种用 QEMU 内置 initiator:

iscsi://[<username>[%<password>]@]<host>[:<port>]/<target-iqn-name>/<lun>

仅目标启用 CHAP 时才需要用户名和口令。可使用 LIBISCSI_CHAP_USERNAME、LIBISCSI_CHAP_PASSWORD 环境变量,避免口令直接出现在参数列表;但环境变量不是秘密保险箱,仍会受继承、日志及进程读取权限影响。不要硬编码真实秘密。

缺省 initiator 名称基于 iqn.2008-11.org.linux-kvm 并使用 VM UUID;无 UUID 时使用 VM 名称。可用 -iscsi initiator-name=iqn.qemu.test:my-initiator 指定。header-digest 可为 CRC32C、CRC32C-NONE、NONE-CRC32C 或 NONE。可在通用 [iscsi] 配置节中设置,也可在命名目标节分别设置:

[iscsi "iqn.target.name"]
  user = "CHAP username"
  password = "CHAP password"
  initiator-name = "iqn.qemu.test:my-initiator"
  header-digest = "CRC32C"

qemu-system-x86_64 -drive file=iscsi://127.0.0.1/iqn.qemu.test/1 \
  -readconfig iscsi.conf

这里是原文占位值;实际 iscsi.conf 应限制读取权限。原文以 Linux STGT(Red Hat 系包名 scsi-target-utils)演示在回环地址设置磁盘和光盘两个 LUN:

tgtd --iscsi portal=127.0.0.1:3260
tgtadm --lld iscsi --op new --mode target --tid 1 -T iqn.qemu.test
tgtadm --lld iscsi --mode logicalunit --op new --tid 1 --lun 1 \
  -b /IMAGES/disk.img --device-type=disk
tgtadm --lld iscsi --mode logicalunit --op new --tid 1 --lun 2 \
  -b /IMAGES/cd.iso --device-type=cd
tgtadm --lld iscsi --op bind --mode target --tid 1 -I ALL
qemu-system-x86_64 -iscsi initiator-name=iqn.qemu.test:my-initiator \
  -boot d -drive file=iscsi://127.0.0.1/iqn.qemu.test/1 \
  -cdrom iscsi://127.0.0.1/iqn.qemu.test/2

编者注:这些命令创建目标并改变服务状态,-I ALL 放宽 initiator 范围,不能把监听地址改到外网后继续照抄。本文保留原例参数关系,未验证历史目标软件在当前系统的可用性。

SSH 远程磁盘

qemu-system-x86_64 -drive file=ssh://[USER@]SERVER[:PORT]/PATH[?host_key_check=HOST_KEY_CHECK]
qemu-system-x86_64 -drive file.driver=ssh[,file.user=USER],file.host=SERVER[,file.port=PORT],file.path=PATH[,file.host_key_check=HOST_KEY_CHECK]

方括号表示可选项。USER 默认尝试本地用户名;SERVER 须提供 SFTP;PORT 默认 22;PATH 为远程镜像。默认 host_key_check=yes 通过本地 .ssh/known_hosts 核验;no 会关闭身份校验,不应作为排错捷径。还支持 md5、sha1、sha256 指纹,但原文明确仅推荐 sha256;指纹应为十六进制,字节间可有冒号。

known_hosts 保存 Base64 公钥,原文用 grep/awk 筛选、base64 -d 解码、sha256sum 计算摘要。一个主机可能有不同算法的多个密钥,须匹配实际协商算法且已可信的密钥。编者没有把原文含特定内网地址和未引用 shell 变量的管道当作通用安全脚本:它还不能完整处理散列主机名等情况。

本次文档说明认证须经 ssh-agent。许多 SSH 服务端没有 fsync 类操作,驱动就不能保证 flush 请求生效,服务器或网络在写入时故障可能损坏镜像。原文警告形式为 warning: ssh server ssh.example.com:22 does not support fsync;较新的 libssh 与 OpenSSH 可以支持 fsync。连接成功不等于数据持久性已得到验证。

NVMe 用户态访问

QEMU 用户态 NVMe 驱动绕过宿主内核文件系统与块层,同时保留块任务、限速、镜像格式等功能。原文称它通常比 /dev/sda 配合线程池或 linux-aio 性能更高,这是条件性描述,本文没有测量。控制器将由 QEMU 独占;要与多个 VM 或宿主应用共享应使用基于文件的协议。

此路径要求预先将实际 NVMe 控制器绑定 vfio-pci。原文示例却含 PCI 类 0401、设备 1102:0002,不可把它当作通用 NVMe 标识。解绑在用存储会中断服务或毁坏数据,因此仅在原文对照中保留解绑/绑定序列并明确风险,不作为执行建议。需要专门核验硬件、IOMMU 分组、宿主依赖和回退步骤。

用于理解的参数形式为 file=nvme://HOST:BUS:SLOT.FUNC/NAMESPACE,或 file.driver=nvme,file.device=HOST:BUS:SLOT.FUNC,file.namespace=NAMESPACE。前者是宿主 PCI 地址,namespace 从 1 开始。这些语法不包含可照抄的真实设备。

镜像锁和共享写入

默认 QEMU 在块协议与宿主支持时防止冲突并发访问;多个模拟器或工具以冲突模式开同一镜像,首个之外应报错。Linux file 协议使用 OFD 锁,也可在不支持 OFD 的 POSIX 宿主配置回退。locking=on 显式开启,无法使用 OFD 时警告并回退;POSIX 锁在热插拔与块任务中有静默丢锁风险。

共享存储迁移时 QEMU 处理锁交接。默认来宾独占写入;只有集群文件系统等来宾软件已协调磁盘访问时才可声明 share-rw=on。它不能提供协调机制,也不会取消某些镜像格式的独占要求。原文也给出 file.locking=off 完全禁用锁的配置,但本稿不把它当作“镜像被占用”的推荐解决办法。可在宿主用 lslocks 看 QEMU 是否持有镜像锁,多个锁字节可能分别表示不同块驱动权限。

预分配过滤驱动

过滤驱动不存储数据,而是在 I/O 链上附加操作。preallocate 放在格式与协议节点之间,写过文件末尾时预先扩展底层协议文件,可能改善分配较慢文件系统的表现。prealloc-align 是长度对齐量,默认 1M 字节;prealloc-size 是每次预分配量,默认 128M 字节。

用 bootindex 指定启动优先级

QEMU 可向理解其启动信息的固件(如 x86 PC BIOS)表达设备候选顺序。简单方法为 -boot order=,更灵活的方法是在块设备或网卡的 -device 上加 bootindex。数值越小越优先;未设值的设备优先级最低且彼此顺序不确定,但仍可能启动。s390x 等机型不支持 -boot order=,须用 bootindex。-hda、-cdrom 等短选项不能设置该属性,应展开为 -drive 与 -device:

qemu-system-x86_64 -drive file=disk1.img,if=none,id=disk1 \
  -device ide-hd,drive=disk1,bootindex=4 \
  -drive file=disk2.img,if=none,id=disk2 \
  -device virtio-blk-pci,drive=disk2,bootindex=3 \
  -netdev type=user,id=net0 \
  -device virtio-net-pci,netdev=net0,bootindex=2 \
  -netdev type=user,id=net1 \
  -device e1000,netdev=net1,bootindex=1

示例意图依次尝试 e1000、virtio-net、virtio 磁盘、IDE 磁盘。它需要已有镜像与合适机型,也可能触发网络启动,本文未执行。固件限制仍优先:PC BIOS 规范只允许一个磁盘作为启动盘,失败后不会再试其他磁盘,但可再试软盘或网络;s390x BIOS 总共最多尝试 8 个设备,可包含多个磁盘和 virtio-net。

当多个设备共用 option ROM 时,固件还可能无法把设备路径映射到特定启动方法。例如某 SCSI HBA 的 target1、target3、target5 都可启动,PC BIOS 却未必能可靠把 ROM 方法映射回某个 target。这是固件规范限制。

不要把 bootindex 与 -boot order= 或 -boot once= 混用。固件通常支持其中一种而非同时处理,两者混用行为未定义,可能从非预期设备启动。

编者核查及许可

本稿覆盖两篇源文全部实质主题与参数;重复语法按表格整合。明确更正容量单位、Windows 稀疏文件泛化;保留NVMe解绑、关闭锁和SSH指纹管道的原文对照,并明确标注风险与引用变量的修订。未创建、修复、提交、删除、挂载镜像,未操作硬件或网络服务,未测试性能及启动结果;静态审查没有发现其他问题不等于无漏洞。

原手册 GPL 第 2 版及其无担保条款保留;译稿与编辑修改已注明,原创示意图另见图注。

NVMe 绑定/解绑步骤:源文示例与硬件风险

源文要求在 QEMU 启动前把宿主 PCI 控制器绑定到 vfio-pci;QEMU 获得独占控制器。以下保留原始示例,以便识别操作链。不要在未确认设备身份、IOMMU 分组、挂载/使用状态及带外恢复手段时执行:解绑可能令宿主磁盘立即不可用。示例中的 PCI 地址与 1102:0002 仅是源页示例,不是通用 NVMe 控制器:

# modprobe vfio-pci
# lspci -n -s 0000:06:0d.0
06:0d.0 0401: 1102:0002 (rev 08)
# echo 0000:06:0d.0 > /sys/bus/pci/devices/0000:06:0d.0/driver/unbind
# echo 1102 0002 > /sys/bus/pci/drivers/vfio-pci/new_id
qemu-system-x86_64 -drive file=nvme://HOST:BUS:SLOT.FUNC/NAMESPACE
# alternative property form:
qemu-system-x86_64 -drive file.driver=nvme,file.device=HOST:BUS:SLOT.FUNC,file.namespace=NAMESPACE

HOST:BUS:SLOT.FUNC 是实际宿主 PCI 地址,namespace 从 1 开始。运行前必须确认控制器未服务宿主文件系统/其它 VM,且能够恢复原驱动。本稿只做静态审阅,没有运行 modprobe、写 sysfs 或操作任何 PCI 设备。

SSH 远程镜像

源页支持 URI 与驱动属性两种形式;远端须实现 SFTP server,端口缺省 22,认证使用 ssh-agent:

qemu-system-x86_64 -drive file=ssh://[USER@]SERVER[:PORT]/PATH[?host_key_check=HOST_KEY_CHECK]
qemu-system-x86_64 -drive file.driver=ssh[,file.user=USER],file.host=SERVER[,file.port=PORT],file.path=PATH[,file.host_key_check=HOST_KEY_CHECK]

host_key_check=yes 默认使用 known_hosts;设为 no 会关闭主机密钥校验,不应使用。固定 SHA-256 指纹时按源页用冒号分隔的十六进制格式配置。原文从已知 host 项提取 base64 key 并计算摘要:

for key in `grep 10.33.8.112 known_hosts | awk '{print $3}'`
do
  echo "$key" | base64 -d | sha256sum
done

同一主机名可能有多把不同算法 key;必须选中与协商算法相符的一条。源命令会打印多个候选,不可取第一行盲目固定;不要把不可信输入串进 shell。SSH 服务不支持 fsync 时,QEMU 不能保证 flush 持久化;连接在写操作中断可能损坏镜像。源文示例警告:warning: ssh server ssh.example.com:22 does not support fsync。新版本 libssh/OpenSSH 才有相关 fsync 支持。

文件锁、共享写与显式禁锁

默认锁用于阻止 QEMU/工具之间冲突访问;Linux 文件协议优先 OFD,必要时可退到 POSIX。共享存储迁移时 QEMU 交接锁。多 VM 共享镜像要用设备 share-rw=on 且客户机中有能协调并发的集群文件系统;只标记 share-rw 并不能让任意格式具备安全共享写。

源文确实列出关闭锁的语法,现保留作诊断/兼容示例并标成高风险:

-blockdev driver=qcow2,file.filename=/path/to/image,file.locking=off,file.driver=file

禁锁会撤掉并发保护,误开相同镜像可能损坏数据;不要把它当常规解决方案。优先保证单写者,并用 lslocks 查看 QEMU 持有的镜像锁。

来源与许可:Disk Images 与 bootindex 页均是 QEMU 11.1.50、GNU GPL version 2;保留 QEMU 文档贡献者归属及无担保声明,说明中文编译和安全注释是修改。命令都只是刊载的静态文本,未操作存储/主机。版本变化可能改变旧协议/选项行为。

源文完整命令与输出对照

以下保留两篇官方手册的原始示例及历史输出,供核对,不是已验证操作指南。NVMe解绑、禁锁、物理盘和iSCSI设置均可能损坏数据或改变访问范围;实际环境必须独立核验。指纹是原文公开示例,不是私钥;字符串口令是占位值。正文对SSH管道$key加引号属于编辑修订,原始形式在下方保留。

源文片段 1

qemu-img create myimage.img mysize

源文片段 2

(qemu) info snapshots
Snapshot devices: hda
Snapshot list (from hda):
ID        TAG                 VM SIZE                DATE       VM CLOCK
1         start                   41M 2006-08-06 12:38:02   00:00:14.954
2                                 40M 2006-08-06 12:43:29   00:00:18.633
3         msys                    40M 2006-08-06 12:44:04   00:00:23.514

源文片段 3

qemu-system-x86_64 linux.img -hdb fat:/my_directory

源文片段 4

qemu-system-x86_64 linux.img -fda fat:floppy:/my_directory

源文片段 5

qemu-system-x86_64 linux.img -fda fat:floppy:rw:/my_directory

源文片段 6

qemu-system-x86_64 linux.img -hdb nbd://my_nbd_server.mydomain.org:1024/

源文片段 7

qemu-system-x86_64 linux.img -hdb nbd+unix://?socket=/tmp/my_socket

源文片段 8

qemu-nbd --socket=/tmp/my_socket my_disk.qcow2

源文片段 9

qemu-nbd --socket=/tmp/my_socket --share=2 my_disk.qcow2

源文片段 10

qemu-system-x86_64 linux1.img -hdb nbd+unix://?socket=/tmp/my_socket
qemu-system-x86_64 linux2.img -hdb nbd+unix://?socket=/tmp/my_socket

源文片段 11

qemu-system-x86_64 -cdrom nbd://localhost/debian-500-ppc-netinst
qemu-system-x86_64 -cdrom nbd://localhost/openSUSE-11.1-ppc-netinst

源文片段 12

qemu-system-x86_64 linux.img -hdb nbd:my_nbd_server.mydomain.org:1024
qemu-system-x86_64 linux2.img -hdb nbd:unix:/tmp/my_socket
qemu-system-x86_64 -cdrom nbd:localhost:10809:exportname=debian-500-ppc-netinst

源文片段 13

iscsi://[<username>[%<password>]@]<host>[:<port>]/<target-iqn-name>/<lun>

源文片段 14

export LIBISCSI_CHAP_USERNAME=<username>
export LIBISCSI_CHAP_PASSWORD=<password>
iscsi://<host>/<target-iqn-name>/<lun>

源文片段 15

-iscsi initiator-name=iqn.qemu.test:my-initiator

源文片段 16

-iscsi header-digest=CRC32C|CRC32C-NONE|NONE-CRC32C|NONE

源文片段 17

[iscsi]
  user = "CHAP username"
  password = "CHAP password"
  initiator-name = "iqn.qemu.test:my-initiator"
  # header digest is one of CRC32C|CRC32C-NONE|NONE-CRC32C|NONE
  header-digest = "CRC32C"

源文片段 18

[iscsi "iqn.target.name"]
  user = "CHAP username"
  password = "CHAP password"
  initiator-name = "iqn.qemu.test:my-initiator"
  # header digest is one of CRC32C|CRC32C-NONE|NONE-CRC32C|NONE
  header-digest = "CRC32C"

源文片段 19

cat >iscsi.conf <<EOF
[iscsi]
  user = "me"
  password = "my password"
  initiator-name = "iqn.qemu.test:my-initiator"
  header-digest = "CRC32C"
EOF

qemu-system-x86_64 -drive file=iscsi://127.0.0.1/iqn.qemu.test/1 \
  -readconfig iscsi.conf

源文片段 20

tgtd --iscsi portal=127.0.0.1:3260
tgtadm --lld iscsi --op new --mode target --tid 1 -T iqn.qemu.test
tgtadm --lld iscsi --mode logicalunit --op new --tid 1 --lun 1 \
    -b /IMAGES/disk.img --device-type=disk
tgtadm --lld iscsi --mode logicalunit --op new --tid 1 --lun 2 \
    -b /IMAGES/cd.iso --device-type=cd
tgtadm --lld iscsi --op bind --mode target --tid 1 -I ALL

qemu-system-x86_64 -iscsi initiator-name=iqn.qemu.test:my-initiator \
  -boot d -drive file=iscsi://127.0.0.1/iqn.qemu.test/1 \
  -cdrom iscsi://127.0.0.1/iqn.qemu.test/2

源文片段 21

qemu-system-x86_64 -drive file=ssh://[USER@]SERVER[:PORT]/PATH[?host_key_check=HOST_KEY_CHECK]

源文片段 22

qemu-system-x86_64 -drive file.driver=ssh[,file.user=USER],file.host=SERVER[,file.port=PORT],file.path=PATH[,file.host_key_check=HOST_KEY_CHECK]

源文片段 23

host_key_check=sha256:04ce2ae89ff4295a6b9c4111640bdcb3297858ee55cb434d9dd88796e93aa795

源文片段 24

$ for key in `grep 10.33.8.112 known_hosts | awk '{print $3}'`
  do
    echo $key | base64 -d | sha256sum
  done
  6c3aa525beda9dc83eadfbd7e5ba7d976ecb59575d1633c87cd06ed2ed6e366f  -
  12214fd9ea5b408086f98ecccd9958609bd9ac7c0ea316734006bc7818b45dc8  -
  d36420137bcbd101209ef70c3b15dc07362fbe0fa53c5b135eba6e6afa82f0ce  -

源文片段 25

warning: ssh server ssh.example.com:22 does not support fsync

源文片段 26

# modprobe vfio-pci
# lspci -n -s 0000:06:0d.0
06:0d.0 0401: 1102:0002 (rev 08)
# echo 0000:06:0d.0 > /sys/bus/pci/devices/0000:06:0d.0/driver/unbind
# echo 1102 0002 > /sys/bus/pci/drivers/vfio-pci/new_id

# qemu-system-x86_64 -drive file=nvme://HOST:BUS:SLOT.FUNC/NAMESPACE

源文片段 27

qemu-system-x86_64 -drive file.driver=nvme,file.device=HOST:BUS:SLOT.FUNC,file.namespace=NAMESPACE

源文片段 28

-blockdev driver=qcow2,file.filename=/path/to/image,file.locking=off,file.driver=file

源文片段 29

qemu-system-x86_64 -drive file=disk1.img,if=none,id=disk1 \
              -device ide-hd,drive=disk1,bootindex=4 \
              -drive file=disk2.img,if=none,id=disk2 \
              -device virtio-blk-pci,drive=disk2,bootindex=3 \
              -netdev type=user,id=net0 \
              -device virtio-net-pci,netdev=net0,bootindex=2 \
              -netdev type=user,id=net1 \
              -device e1000,netdev=net1,bootindex=1

QEMU是Fabrice Bellard的商标。两篇源手册明确QEMU与本手册采用GNU General Public License version 2;译文与安全注释已标明,原文链接保留。

GNU General Public License Version 2 全文

GNU GENERAL PUBLIC LICENSE
		       Version 2, June 1991

 Copyright (C) 1989, 1991 Free Software Foundation, Inc.,
 <https://fsf.org/>
 Everyone is permitted to copy and distribute verbatim copies
 of this license document, but changing it is not allowed.

			    Preamble
  The licenses for most software are designed to take away your
freedom to share and change it.  By contrast, the GNU General Public
License is intended to guarantee your freedom to share and change free
software--to make sure the software is free for all its users.  This
General Public License applies to most of the Free Software
Foundation's software and to any other program whose authors commit to
using it.  (Some other Free Software Foundation software is covered by
the GNU Lesser General Public License instead.)  You can apply it to
your programs, too.
  When we speak of free software, we are referring to freedom, not
price.  Our General Public Licenses are designed to make sure that you
have the freedom to distribute copies of free software (and charge for
this service if you wish), that you receive source code or can get it
if you want it, that you can change the software or use pieces of it
in new free programs; and that you know you can do these things.
  To protect your rights, we need to make restrictions that forbid
anyone to deny you these rights or to ask you to surrender the rights.
These restrictions translate to certain responsibilities for you if you
distribute copies of the software, or if you modify it.
  For example, if you distribute copies of such a program, whether
gratis or for a fee, you must give the recipients all the rights that
you have.  You must make sure that they, too, receive or can get the
source code.  And you must show them these terms so they know their
rights.

  We protect your rights with two steps: (1) copyright the software, and
(2) offer you this license which gives you legal permission to copy,
distribute and/or modify the software.
  Also, for each author's protection and ours, we want to make certain
that everyone understands that there is no warranty for this free
software.  If the software is modified by someone else and passed on, we
want its recipients to know that what they have is not the original, so
that any problems introduced by others will not reflect on the original
authors' reputations.
  Finally, any free program is threatened constantly by software
patents.  We wish to avoid the danger that redistributors of a free
program will individually obtain patent licenses, in effect making the
program proprietary.  To prevent this, we have made it clear that any
patent must be licensed for everyone's free use or not licensed at all.
  The precise terms and conditions for copying, distribution and
modification follow.


		    GNU GENERAL PUBLIC LICENSE
   TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
  0. This License applies to any program or other work which contains
a notice placed by the copyright holder saying it may be distributed
under the terms of this General Public License.  The "Program", below,
refers to any such program or work, and a "work based on the Program"
means either the Program or any derivative work under copyright law:
that is to say, a work containing the Program or a portion of it,
either verbatim or with modifications and/or translated into another
language.  (Hereinafter, translation is included without limitation in
the term "modification".)  Each licensee is addressed as "you".
Activities other than copying, distribution and modification are not
covered by this License; they are outside its scope.  The act of
running the Program is not restricted, and the output from the Program
is covered only if its contents constitute a work based on the
Program (independent of having been made by running the Program).
Whether that is true depends on what the Program does.
  1. You may copy and distribute verbatim copies of the Program's
source code as you receive it, in any medium, provided that you
conspicuously and appropriately publish on each copy an appropriate
copyright notice and disclaimer of warranty; keep intact all the
notices that refer to this License and to the absence of any warranty;
and give any other recipients of the Program a copy of this License
along with the Program.
You may charge a fee for the physical act of transferring a copy, and
you may at your option offer warranty protection in exchange for a fee.

  2. You may modify your copy or copies of the Program or any portion
of it, thus forming a work based on the Program, and copy and
distribute such modifications or work under the terms of Section 1
above, provided that you also meet all of these conditions:
    a) You must cause the modified files to carry prominent notices
    stating that you changed the files and the date of any change.

    b) You must cause any work that you distribute or publish, that in
    whole or in part contains or is derived from the Program or any
    part thereof, to be licensed as a whole at no charge to all third
    parties under the terms of this License.
    c) If the modified program normally reads commands interactively
    when run, you must cause it, when started running for such
    interactive use in the most ordinary way, to print or display an
    announcement including an appropriate copyright notice and a
    notice that there is no warranty (or else, saying that you provide
    a warranty) and that users may redistribute the program under
    these conditions, and telling the user how to view a copy of this
    License.  (Exception: if the Program itself is interactive but
    does not normally print such an announcement, your work based on
    the Program is not required to print an announcement.)


These requirements apply to the modified work as a whole.  If
identifiable sections of that work are not derived from the Program,
and can be reasonably considered independent and separate works in
themselves, then this License, and its terms, do not apply to those
sections when you distribute them as separate works.  But when you
distribute the same sections as part of a whole which is a work based
on the Program, the distribution of the whole must be on the terms of
this License, whose permissions for other licensees extend to the
entire whole, and thus to each and every part regardless of who wrote it.
Thus, it is not the intent of this section to claim rights or contest
your rights to work written entirely by you; rather, the intent is to
exercise the right to control the distribution of derivative or
collective works based on the Program.

In addition, mere aggregation of another work not based on the Program
with the Program (or with a work based on the Program) on a volume of
a storage or distribution medium does not bring the other work under
the scope of this License.
  3. You may copy and distribute the Program (or a work based on it,
under Section 2) in object code or executable form under the terms of
Sections 1 and 2 above provided that you also do one of the following:

    a) Accompany it with the complete corresponding machine-readable
    source code, which must be distributed under the terms of Sections
    1 and 2 above on a medium customarily used for software interchange; or,
    b) Accompany it with a written offer, valid for at least three
    years, to give any third party, for a charge no more than your
    cost of physically performing source distribution, a complete
    machine-readable copy of the corresponding source code, to be
    distributed under the terms of Sections 1 and 2 above on a medium
    customarily used for software interchange; or,
    c) Accompany it with the information you received as to the offer
    to distribute corresponding source code.  (This alternative is
    allowed only for noncommercial distribution and only if you
    received the program in object code or executable form with such
    an offer, in accord with Subsection b above.)
The source code for a work means the preferred form of the work for
making modifications to it.  For an executable work, complete source
code means all the source code for all modules it contains, plus any
associated interface definition files, plus the scripts used to
control compilation and installation of the executable.  However, as a
special exception, the source code distributed need not include
anything that is normally distributed (in either source or binary
form) with the major components (compiler, kernel, and so on) of the
operating system on which the executable runs, unless that component
itself accompanies the executable.
If distribution of executable or object code is made by offering
access to copy from a designated place, then offering equivalent
access to copy the source code from the same place counts as
distribution of the source code, even though third parties are not
compelled to copy the source along with the object code.


  4. You may not copy, modify, sublicense, or distribute the Program
except as expressly provided under this License.  Any attempt
otherwise to copy, modify, sublicense or distribute the Program is
void, and will automatically terminate your rights under this License.
However, parties who have received copies, or rights, from you under
this License will not have their licenses terminated so long as such
parties remain in full compliance.
  5. You are not required to accept this License, since you have not
signed it.  However, nothing else grants you permission to modify or
distribute the Program or its derivative works.  These actions are
prohibited by law if you do not accept this License.  Therefore, by
modifying or distributing the Program (or any work based on the
Program), you indicate your acceptance of this License to do so, and
all its terms and conditions for copying, distributing or modifying
the Program or works based on it.
  6. Each time you redistribute the Program (or any work based on the
Program), the recipient automatically receives a license from the
original licensor to copy, distribute or modify the Program subject to
these terms and conditions.  You may not impose any further
restrictions on the recipients' exercise of the rights granted herein.
You are not responsible for enforcing compliance by third parties to
this License.
  7. If, as a consequence of a court judgment or allegation of patent
infringement or for any other reason (not limited to patent issues),
conditions are imposed on you (whether by court order, agreement or
otherwise) that contradict the conditions of this License, they do not
excuse you from the conditions of this License.  If you cannot
distribute so as to satisfy simultaneously your obligations under this
License and any other pertinent obligations, then as a consequence you
may not distribute the Program at all.  For example, if a patent
license would not permit royalty-free redistribution of the Program by
all those who receive copies directly or indirectly through you, then
the only way you could satisfy both it and this License would be to
refrain entirely from distribution of the Program.
If any portion of this section is held invalid or unenforceable under
any particular circumstance, the balance of the section is intended to
apply and the section as a whole is intended to apply in other
circumstances.
It is not the purpose of this section to induce you to infringe any
patents or other property right claims or to contest validity of any
such claims; this section has the sole purpose of protecting the
integrity of the free software distribution system, which is
implemented by public license practices.  Many people have made
generous contributions to the wide range of software distributed
through that system in reliance on consistent application of that
system; it is up to the author/donor to decide if he or she is willing
to distribute software through any other system and a licensee cannot
impose that choice.
This section is intended to make thoroughly clear what is believed to
be a consequence of the rest of this License.


  8. If the distribution and/or use of the Program is restricted in
certain countries either by patents or by copyrighted interfaces, the
original copyright holder who places the Program under this License
may add an explicit geographical distribution limitation excluding
those countries, so that distribution is permitted only in or among
countries not thus excluded.  In such case, this License incorporates
the limitation as if written in the body of this License.
  9. The Free Software Foundation may publish revised and/or new versions
of the General Public License from time to time.  Such new versions will
be similar in spirit to the present version, but may differ in detail to
address new problems or concerns.
Each version is given a distinguishing version number.  If the Program
specifies a version number of this License which applies to it and "any
later version", you have the option of following the terms and conditions
either of that version or of any later version published by the Free
Software Foundation.  If the Program does not specify a version number of
this License, you may choose any version ever published by the Free Software
Foundation.
  10. If you wish to incorporate parts of the Program into other free
programs whose distribution conditions are different, write to the author
to ask for permission.  For software which is copyrighted by the Free
Software Foundation, write to the Free Software Foundation; we sometimes
make exceptions for this.  Our decision will be guided by the two goals
of preserving the free status of all derivatives of our free software and
of promoting the sharing and reuse of software generally.

			    NO WARRANTY
  11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW.  EXCEPT WHEN
OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES
PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED
OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.  THE ENTIRE RISK AS
TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU.  SHOULD THE
PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING,
REPAIR OR CORRECTION.
  12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR
REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES,
INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING
OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED
TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY
YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER
PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE
POSSIBILITY OF SUCH DAMAGES.
		     END OF TERMS AND CONDITIONS


	    How to Apply These Terms to Your New Programs

  If you develop a new program, and you want it to be of the greatest
possible use to the public, the best way to achieve this is to make it
free software which everyone can redistribute and change under these terms.
  To do so, attach the following notices to the program.  It is safest
to attach them to the start of each source file to most effectively
convey the exclusion of warranty; and each file should have at least
the "copyright" line and a pointer to where the full notice is found.

    <one line to give the program's name and a brief idea of what it does.>
    Copyright (C) <year>  <name of author>
    This program is free software; you can redistribute it and/or modify
    it under the terms of the GNU General Public License as published by
    the Free Software Foundation; either version 2 of the License, or
    (at your option) any later version.

    This program is distributed in the hope that it will be useful,
    but WITHOUT ANY WARRANTY; without even the implied warranty of
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
    GNU General Public License for more details.
    You should have received a copy of the GNU General Public License along
    with this program; if not, see <https://www.gnu.org/licenses/>.

Also add information on how to contact you by electronic and paper mail.

If the program is interactive, make it output a short notice like this
when it starts in an interactive mode:
    Gnomovision version 69, Copyright (C) year name of author
    Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
    This is free software, and you are welcome to redistribute it
    under certain conditions; type `show c' for details.
The hypothetical commands `show w' and `show c' should show the appropriate
parts of the General Public License.  Of course, the commands you use may
be called something other than `show w' and `show c'; they could even be
mouse-clicks or menu items--whatever suits your program.

You should also get your employer (if you work as a programmer) or your
school, if any, to sign a "copyright disclaimer" for the program, if
necessary.  Here is a sample; alter the names:
  Yoyodyne, Inc., hereby disclaims all copyright interest in the program
  `Gnomovision' (which makes passes at compilers) written by James Hacker.

  <signature of Ty Coon>, 1 April 1989
  Ty Coon, President of Vice
This General Public License does not permit incorporating your program into
proprietary programs.  If your program is a subroutine library, you may
consider it more useful to permit linking proprietary applications with the
library.  If this is what you want to do, use the GNU Lesser General
Public License instead of this License.
© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    暂无评论内容