#!/bin/bash
# -*-shell-*-
-# $Id$
+
+#shopt -s huponexit
COMMAND=$(basename $0)
DIRNAME=$(dirname $0)
# pkgs parsing utilities
-PATH=$(dirname $0):$PATH . build.common
+PATH=$(dirname $0):$PATH export PATH
+. build.common
-DEFAULT_FCDISTRO=centos5
+DEFAULT_FCDISTRO=f14
DEFAULT_PLDISTRO=planetlab
-DEFAULT_PERSONALITY=linux32
+DEFAULT_PERSONALITY=linux64
DEFAULT_IFNAME=eth0
COMMAND_VBUILD="vbuild-init-vserver.sh"
vserver=$1; shift
fcdistro=$1; shift
+ pldistro=$1; shift
templates=/etc/vservers/.distributions/${fcdistro}
if [ -f ${templates}/yum/yum.conf ] ; then
echo "Cannot initialize yum.repos.d in $vserver"
fi
- if [ -n "$MYPLC_MODE" ] ; then
+ # for using vtest-init-vserver.sh as a general-purpose vserver creation wrapper
+ # just mention 'none' as the repo url
+ if [ -n "$MYPLC_MODE" -a "$REPO_URL" != "none" ] ; then
if [ ! -d /vservers/$vserver/etc/yum.repos.d ] ; then
echo "WARNING : cannot create myplc repo"
else
# exclude kernel from fedora repos
+ yumexclude=$(pl_plcyumexclude $fcdistro $pldistro $DIRNAME)
for repo in /vservers/$vserver/etc/yum.repos.d/* ; do
- [ -f $repo ] && yumconf_exclude $repo "exclude=$pl_KEXCLUDES"
+ [ -f $repo ] && yumconf_exclude $repo "exclude=$yumexclude"
done
# the build repo is not signed at this stage
cat > /vservers/$vserver/etc/yum.repos.d/myplc.repo <<EOF
function package_method () {
fcdistro=$1; shift
case $fcdistro in
- f[0-9]*|centos[0-9]*) echo yum ;;
- lenny|etch) echo debootstrap ;;
+ f[0-9]*|centos[0-9]*|sl[0-9]*) echo yum ;;
+ squeeze|wheezy|oneiric|precise|quantal) echo debootstrap ;;
*) echo Unknown distro $fcdistro ;;
esac
}
+# need to specify the right mirror for debian variants like ubuntu and the like
+function debian_mirror () {
+ fcdistro=$1; shift
+ case $fcdistro in
+ squeeze|wheezy)
+ echo http://ftp2.fr.debian.org/debian/ ;;
+ oneiric|precise|quantal)
+ echo http://mir1.ovh.net/ubuntu/ubuntu/ ;;
+ *) echo unknown distro $fcdistro; exit 1;;
+ esac
+}
+
+
+
# return arch from debian distro and personality
function canonical_arch () {
personality=$1; shift
esac
}
+# the new test framework creates /timestamp in /vservers/<name> *before* populating it
+function almost_empty () {
+ dir="$1"; shift ;
+ # non existing is fine
+ [ ! -d $dir ] && return 0;
+ # need to have at most one file
+ count=$(cd $dir; ls | wc -l); [ $count -le 1 ];
+}
+
function setup_vserver () {
set -x
vserver=$1; shift
fcdistro=$1; shift
+ pldistro=$1; shift
personality=$1; shift
- if [ -d /vservers/$vserver ] ; then
+ # check that this is a new one - see above
+ almost_empty /vservers/$vserver || {
echo "$COMMAND : vserver $vserver seems to exist - bailing out"
exit 1
- fi
+ }
pkg_method=$(package_method $fcdistro)
case $pkg_method in
;;
debootstrap)
arch=$(canonical_arch $personality $fcdistro)
- build_options="-m debootstrap -- -d $fcdistro -- --arch $arch"
+ debmirror=$(debian_mirror $fcdistro)
+ build_options="-m debootstrap -- -d $fcdistro -m $debmirror -- --arch $arch"
;;
*)
- build_options="something wrong" ;;
+ build_options="undefined-package_method" ;;
esac
# create it
echo "* ${i}-th attempt to 'vserver build' failed - waiting for 3 seconds"
sleep 3
done
- # check success
- [ -d /vservers/$vserver ]
+ # check success - not enough to check for the directory, let's assume /etc/ in image
+ [ -d /vservers/$vserver/etc ]
if [ ! -z "$personality" ] ; then
if [ -f "/etc/vservers/$vserver/personality" ] ; then
fi
fi
+ BCAPFILE=/etc/vservers/$vserver/bcapabilities
+ touch $BCAPFILE
if [ -n "$VBUILD_MODE" ] ; then
### capabilities required for a build vserver
# set up appropriate vserver capabilities to mount, mknod and IPC_LOCK
- BCAPFILE=/etc/vservers/$vserver/bcapabilities
- touch $BCAPFILE
- cap=$(grep ^CAP_SYS_ADMIN /etc/vservers/$vserver/bcapabilities | wc -l)
- [ $cap -eq 0 ] && echo 'CAP_SYS_ADMIN' >> /etc/vservers/$vserver/bcapabilities
- cap=$(grep ^CAP_MKNOD /etc/vservers/$vserver/bcapabilities | wc -l)
- [ $cap -eq 0 ] && echo 'CAP_MKNOD' >> /etc/vservers/$vserver/bcapabilities
- cap=$(grep ^CAP_IPC_LOCK /etc/vservers/$vserver/bcapabilities | wc -l)
- [ $cap -eq 0 ] && echo 'CAP_IPC_LOCK' >> /etc/vservers/$vserver/bcapabilities
+ grep -q ^CAP_SYS_ADMIN $BCAPFILE || echo CAP_SYS_ADMIN >> $BCAPFILE
+ grep -q ^CAP_MKNOD $BCAPFILE || echo CAP_MKNOD >> $BCAPFILE
+ grep -q ^CAP_IPC_LOCK $BCAPFILE || echo CAP_IPC_LOCK >> $BCAPFILE
+ # useful for f16 guests that use set_cap_file
+ grep -q ^CAP_SETFCAP $BCAPFILE || echo CAP_SETFCAP >> $BCAPFILE
else
### capabilities required for a myplc vserver
# for /etc/plc.d/gpg - need to init /dev/random
- cap=$(grep ^CAP_MKNOD /etc/vservers/$vserver/bcapabilities | wc -l)
- [ $cap -eq 0 ] && echo 'CAP_MKNOD' >> /etc/vservers/$vserver/bcapabilities
- cap=$(grep ^CAP_NET_BIND_SERVICE /etc/vservers/$vserver/bcapabilities | wc -l)
- [ $cap -eq 0 ] && echo 'CAP_NET_BIND_SERVICE' >> /etc/vservers/$vserver/bcapabilities
+ grep -q ^CAP_MKNOD $BCAPFILE || echo CAP_MKNOD >> $BCAPFILE
+ grep -q ^CAP_NET_BIND_SERVICE $BCAPFILE || echo CAP_NET_BIND_SERVICE >> $BCAPFILE
+ # useful for f16 guests that use set_cap_file
+ grep -q ^CAP_SETFCAP $BCAPFILE || echo CAP_SETFCAP >> $BCAPFILE
fi
+ # Set persistent for the network context
+ # Thierry: Daniel's kernels come with single_ip turned off by default, let's make this explicit
+ echo "persistent,lback_allow,~single_ip" > /etc/vservers/$vserver/nflags
+
+ # Set cflags
+ echo -e "persistent\n~info_init" > /etc/vservers/$vserver/cflags
+
+ # Enable cgroup
+ mkdir /etc/vservers/$vserver/cgroup
+
+ # Set the init style of your vserver to plain for f16 and higher
+ # not working with f16 anyways, systemd requires 2.6.36 to work
+ case $fcdistro in
+ f1[5-9]) echo plain > /etc/vservers/$vserver/apps/init/style ;;
+ esac
+
if [ "$pkg_method" = "yum" ] ; then
$personality vyum $vserver -- -y install yum
# ditto
sleep 3
done
fi
+
+ # turns out that with wheezy at least, at this point we're getting
+ # /vservers/<vs>/var/run -> /run
+ # /vservers/<vs>/var/lock -> /run/lock
+ # trying to fix this with relative links does not appear to work fine
+ # when trying to vserver start we're then getting
+ # + exec /usr/sbin/vspace --mount --fs --new -- /usr/sbin/vserver ----nonamespace debuild09 start
+ # fakerunlevel: open("/var/run/utmp"): No such file or directory
+ # so instead we bluntly create empty dirs and hope for the best
+# if [ "$pkg_method" = "debootstrap" ] ; then
+ [ -h /vservers/$vserver/var/run ] && [ ! -d /vservers/$vserver/var/run ] && \
+# { rm -f /vservers/$vserver/var/run ; ln -s ../run /vservers/$vserver/var/run ; }
+ { rm -f /vservers/$vserver/var/run ; mkdir /vservers/$vserver/var/run ; }
+ [ -h /vservers/$vserver/var/lock ] && [ ! -d /vservers/$vserver/var/lock ] && \
+# { rm -f /vservers/$vserver/var/lock ; ln -s ../run/lock /vservers/$vserver/var/lock ; }
+ { rm -f /vservers/$vserver/var/lock ; mkdir /vservers/$vserver/var/lock ; }
+# fi
# start the vserver so we can do the following operations
- $personality vserver $VERBOSE $vserver start
- [ "$pkg_method" = "yum" ] && $personality vserver $VERBOSE $vserver exec sh -c "rm -f /var/lib/rpm/__db*"
- [ "$pkg_method" = "yum" ] && $personality vserver $VERBOSE $vserver exec rpm --rebuilddb
+ # redirect out/err to protect against the vserver's init sequence getting stalled
+ # mostly used for f10 vservers created remotely through ssh
+ $personality vserver $VERBOSE $vserver start >& /dev/null
+
+ if [ "$pkg_method" == "yum" ] ; then
+ $personality vserver $VERBOSE $vserver exec sh -c "rm -f /var/lib/rpm/__db*"
+
+ # run the host rpmdb_dump and restore with the guest rpmdb_load
+ function translate_rpm_hashes () {
+ set -x
+ set -e
+ local personality="$1"; shift
+ local vserver="$1"; shift
+ # need to have utilities installed
+ type -p file
+ type -p awk
+ type -p cut
+ guest_dir=/var/lib/rpm
+ host_dir=/vservers/$vserver/$guest_dir
+ files=$(cd $host_dir ; file * | grep Hash | cut -d: -f 1)
+ for file in $files; do
+ (cd $host_dir && mv $file ${file}-foreign)
+ /usr/lib/rpm/rpmdb_dump $host_dir/${file}-foreign | $personality vserver $VERBOSE $vserver exec /usr/lib/rpm/rpmdb_load $guest_dir/$file
+ done
+ $personality vserver $VERBOSE $vserver exec rpm --rebuilddb
+ return 0
+ }
+
+ # try the simple way, if that fails try to cross fix the rpm hashes
+ $personality vserver $VERBOSE $vserver exec rpm --rebuilddb || translate_rpm_hashes $personality $vserver
+ fi
- # with vserver 2.3, granting the vserver CAP_MKNOD is not enough
- # check whether we run vs2.3 or above
- vs_version=$(uname -a | sed -e 's,.*[\.\-]vs\([0-9]\)\.\([0-9]\)\..*,\1\2,')
- # at this stage we have here 22 or 23
- need_vdevmap=$(( $vs_version >= 23 ))
+ # check if the vserver kernel is using VSERVER_DEVICE (vdevmap) support
+ need_vdevmap=$(grep "CONFIG_VSERVER_DEVICE=y" /boot/config-$(uname -r) | wc -l)
- if [ "$need_vdevmap" == 1 ] ; then
+ if [ $need_vdevmap -eq 1 ] ; then
ctx=$(cat /etc/vservers/$vserver/context)
vdevmap --set --xid $ctx --open --create --target /dev/null
vdevmap --set --xid $ctx --open --create --target /dev/root
fi
# minimal config in the vserver for yum to work
- [ "$pkg_method" = "yum" ] && configure_yum_in_vserver $vserver $fcdistro
+ [ "$pkg_method" = "yum" ] && configure_yum_in_vserver $vserver $fcdistro $pldistro
# set up resolv.conf
cp /etc/resolv.conf /vservers/$vserver/etc/resolv.conf
+ cp /etc/resolv.conf /vservers/$vserver/etc/resolv.conf.preserve
# and /etc/hosts for at least localhost
[ -f /vservers/$vserver/etc/hosts ] || echo "127.0.0.1 localhost localhost.localdomain" > /vservers/$vserver/etc/hosts
+
}
function devel_or_vtest_tools () {
pkg_method=$(package_method $fcdistro)
- # check for .pkgs file based on pldistro
- if [ -n "$VBUILD_MODE" ] ; then
- pkgsname=devel.pkgs
- else
- pkgsname=vtest.pkgs
- fi
- pkgsfile=$(pl_locateDistroFile $DIRNAME $pldistro $pkgsname)
+ pkgsfile=$(pl_locateDistroFile $DIRNAME $pldistro $PREINSTALLED)
### install individual packages, then groups
# get target arch - use uname -i here (we want either x86_64 or i386)
packages=$(pl_getPackages -a $vserver_arch $fcdistro $pldistro $pkgsfile)
groups=$(pl_getGroups -a $vserver_arch $fcdistro $pldistro $pkgsfile)
- [ "$pkg_method" = yum ] && [ -n "$packages" ] && $personality vserver $vserver exec yum -y install $packages
- [ "$pkg_method" = yum ] && [ -n "$groups" ] && $personality vserver $vserver exec yum -y groupinstall $groups
+ case "$pkg_method" in
+ yum)
+ [ -n "$packages" ] && $personality vserver $vserver exec yum -y install $packages
+ for group_plus in $groups; do
+ group=$(echo $group_plus | sed -e "s,+++, ,g")
+ $personality vserver $vserver exec yum -y groupinstall "$group"
+ done
+ # store current rpm list in /init-vserver.rpms in case we need to check the contents
+ $personality vserver $vserver exec rpm -aq > /vservers/$vserver/init-vserver.rpms
+ ;;
+ debootstrap)
+ # for ubuntu
+ if grep -iq ubuntu /vservers/$vserver/etc/lsb-release 2> /dev/null; then
+ # on ubuntu, at this point we end up with a single feed in /etc/apt/sources.list
+ # we need at least to add the 'universe' feed for python-rpm
+ ( cd /vservers/$vserver/etc/apt ; head -1 sources.list | sed -e s,main,universe, > sources.list.d/universe.list )
+ # also adding a link to updates sounds about right
+ ( cd /vservers/$vserver/etc/apt ; head -1 sources.list | sed -e 's, main,-updates main,' > sources.list.d/updates.list )
+ fi
+ $personality vserver $vserver exec apt-get update
+ # ignore result because that one failed on precise
+sc $personality vserver $vserver exec apt-get -y upgrade ||:
+ # handle this one firt off to be sure; mostly cosmetic but avoid a huge amount of warnings
+ $personality vserver $vserver exec apt-get install -y locales
+ # install required packages
+ # all in a single batch
+ [ -n "$packages" ] && $personality vserver $vserver exec apt-get install -y --ignore-missing $packages || :
+ # of course, on ubuntu apt-get --ignore-missing .. does not ignore missing packages !
+ # check it up a bit
+ for package in $packages ; do
+ if $personality vserver $vserver exec dpkg -l $package >& /dev/null ; then
+ echo "==========(debian) package $package OK (1)"
+ else
+ # try to install it individually - so this is for ubuntu
+ $personality vserver $vserver exec apt-get install -y $package || :
+ # still not there ?
+ if $personality vserver $vserver exec dpkg -l $package >& /dev/null ; then
+ echo "==========(debian) package $package OK (2)"
+ else
+ echo "==========(debian) package $package MISSING - ignored"
+ fi
+ fi
+ done
+ ### xxx todo install groups with apt..
+ ;;
+ *)
+ echo "unknown pkg_method $pkg_method"
+ ;;
+ esac
- [ "$pkg_method" = debootstrap ] && $personality vserver $vserver exec apt-get update
- [ "$pkg_method" = debootstrap ] && for package in $packages ; do
- $personality vserver $vserver exec apt-get install -y $package
- done
-
return 0
}
# turn off regular crond, as plc invokes plc_crond
chkconfig crond off
+ # take care of loginuid in /etc/pam.d
+ sed -i "s,#*\(.*loginuid.*\),#\1," /etc/pam.d/*
+
# customize root's prompt
cat << PROFILE > /root/.profile
export PS1="[$vserver] \\w # "
echo " -d pldistro - defaults to $DEFAULT_PLDISTRO"
echo " -p personality - defaults to $DEFAULT_PERSONALITY"
echo " -i ifname: determines ip and netmask attached to ifname, and passes it to the vserver"
+ echo " -r : set apps/init/mark to default so the vserver restart upon reboot"
echo " -v : verbose - passes -v to calls to vserver"
echo "vserver-options"
echo " all args after the optional -- are passed to vserver <name> build <options>"
echo " typical usage is e.g. --interface eth0:200.150.100.10/24"
+ echo "With $COMMAND_MYPLC you can give 'none' as the URL, in which case"
+ echo " myplc.repo does not get created"
exit 1
}
esac
VERBOSE=
+ RESISTANT=""
IFNAME=""
VSERVER_OPTIONS=""
- while getopts "f:d:p:i:v" opt ; do
+
+ # the set of preinstalled packages - depends on vbuild or vtest
+ if [ -n "$VBUILD_MODE" ] ; then
+ PREINSTALLED=devel.pkgs
+ else
+ PREINSTALLED=vtest.pkgs
+ fi
+ while getopts "f:d:p:P:i:rv" opt ; do
case $opt in
f) fcdistro=$OPTARG;;
d) pldistro=$OPTARG;;
p) personality=$OPTARG;;
+ P) PREINSTALLED=$OPTARG;;
i) IFNAME=$OPTARG;;
+ r) RESISTANT="true";;
v) VERBOSE="-v" ;;
*) usage ;;
esac
[ -z "$pldistro" ] && pldistro=$DEFAULT_PLDISTRO
[ -z "$personality" ] && personality=$DEFAULT_PERSONALITY
- setup_vserver $vserver $fcdistro $personality
+ setup_vserver $vserver $fcdistro $pldistro $personality
devel_or_vtest_tools $vserver $fcdistro $pldistro $personality
post_install $vserver $personality
+ # Start Vserver automatically on boot
+ [ -n "$RESISTANt" ] && echo "default" > /etc/vservers/$vserver/apps/init/mark
+
+ echo $COMMAND Done
}
main "$@"