X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=vbuild-init-lxc.sh;h=561be5e8e774cf9c8d69e2daf89b0264de5845b6;hb=16dbec6d4962b3332fe826127796de1109cc57fb;hp=2e8e502df1bcf9a8d7838f71542eb870ebea0ba4;hpb=5d8ac7e14634eb9b4a09ed2b8fce8c2ca0c6b114;p=build.git diff --git a/vbuild-init-lxc.sh b/vbuild-init-lxc.sh index 2e8e502d..561be5e8 100755 --- a/vbuild-init-lxc.sh +++ b/vbuild-init-lxc.sh @@ -5,19 +5,21 @@ COMMAND=$(basename $0) DIRNAME=$(dirname $0) +BUILD_DIR=$(pwd) # pkgs parsing utilities PATH=$(dirname $0):$PATH export PATH . build.common -DEFAULT_FCDISTRO=f8 +DEFAULT_FCDISTRO=f16 DEFAULT_PLDISTRO=planetlab -DEFAULT_PERSONALITY=linux32 +DEFAULT_PERSONALITY=linux64 DEFAULT_IFNAME=eth0 COMMAND_VBUILD="vbuild-init-lxc.sh" COMMAND_MYPLC="vtest-init-lxc.sh" +libvirt_version="1.0.4" function bridge_init () { # turn on verbosity @@ -27,7 +29,7 @@ function bridge_init () { INTERFACE_BRIDGE=br0 # Default Value for INTERFACE_LAN - INTERFACE_LAN=eth0 + INTERFACE_LAN=$(netstat -rn | grep '^0.0.0.0' | awk '{print $8;}') echo "========== $COMMAND: entering start - beg" @@ -48,9 +50,6 @@ function bridge_init () { # take extra arg for ifname, if provided [ -n "$1" ] && { INTERFACE_LAN=$1; shift ; } - ### Checking - type -p brctl &> /dev/null || { echo "brctl not found, please install bridge-utils" ; exit 1 ; } - #if we have already configured the same host_box no need to do it again /sbin/ifconfig $INTERFACE_BRIDGE &> /dev/null && { echo "Bridge interface $INTERFACE_BRIDGE already set up - $COMMAND start exiting" @@ -66,7 +65,7 @@ function bridge_init () { address=$(/sbin/ip addr show $INTERFACE_LAN | grep -v inet6 | grep inet | head --lines=1 | awk '{print $2;}') [ -z "$address" ] && { echo "ERROR: Could not determine IP address for $INTERFACE_LAN" ; exit 1 ; } -broadcast=$(/sbin/ip addr show $INTERFACE_LAN | grep -v inet6 | grep inet | head --lines=1 | awk '{print $4;}') + broadcast=$(/sbin/ip addr show $INTERFACE_LAN | grep -v inet6 | grep inet | head --lines=1 | awk '{print $4;}') [ -z "$broadcast" ] && echo "WARNING: Could not determine broadcast address for $INTERFACE_LAN" gateway=$(netstat -rn | grep '^0.0.0.0' | awk '{print $2;}') @@ -82,7 +81,8 @@ broadcast=$(/sbin/ip addr show $INTERFACE_LAN | grep -v inet6 | grep inet | head sleep 2 echo "Setting bridge address=$address broadcast=$broadcast" # static - /sbin/ifconfig $INTERFACE_BRIDGE $address broadcast $broadcast up + #/sbin/ifconfig $INTERFACE_BRIDGE $address broadcast $broadcast up + dhclient $INTERFACE_BRIDGE sleep 1 #Reconfigure the routing table @@ -127,49 +127,49 @@ echo $cidr } -function prepare_host() { - - #Bridge init - bridge_init - - #install development tools - isInstalled=$(yum grouplist "Development Tools" | grep Installed) - if [ -z "$isInstalled" ] ; then - echo "Installing Development Tools ..." - yum -y groupinstall "Development Tools" - fi - - #install libcap-devel, libvirt - isInstalled=$(rpm -qa | grep libcap-devel) - if [ -z "$isInstalled" ] ; then - echo "Installing libcap-devel ..." - yum -y install libcap-devel - fi +function check_yum_installed () { + package=$1; shift + rpm -q $package >& /dev/null || yum -y install $package +} - isInstalled=$(rpm -qa | grep libvirt) - if [ -z "$isInstalled" ] ; then - echo "Installing libvirt ..." - yum -y install libvirt - fi +function check_yumgroup_installed () { + group="$1"; shift + yum grouplist "$group" | grep -q Installed || { yum -y groupinstall "$group" ; } +} - #retreive and install lxc from sources - isInstalled=$(lxc-version | cut -d: -f2 | grep "0.8.0-rc1") - if [ -z "$isInstalled" ] ; then - echo "Installing lxc ..." - cd /root - git clone git://lxc.git.sourceforge.net/gitroot/lxc/lxc - cd lxc - ./autogen.sh - ./configure - make - make install - fi - - #create a symlink (just a hack to make lxc works) - [ ! -d "/usr/local/var/lib" ] && mkdir -p /usr/local/var/lib - #[ ! -f "/usr/local/var/lib/lxc" ] && ln -s /var/lib/lxc /usr/local/var/lib/lxc +function prepare_host() { + + host_fcdistro="$(cat /etc/fedora-release | cut -d' ' -f3)" + ## check if libvirt_version is installed + virsh -v | grep -e $libvirt_version || { echo "$libvirt_version needs to be installed!!!" ; exit 1 ; } +# host_fcdistro="$(cat /etc/fedora-release | cut -d' ' -f3)" +# if [ ! -f /etc/yum.repos.d/libvirt.repo ] ; then +# touch /etc/yum.repos.d/libvirt.repo +# cat < /etc/yum.repos.d/libvirt.repo +#[libvirt] +#name=libvirt-1.0.2-1 +#baseurl=http://build.onelab.eu/lxc/2013.02.25--lxc$host_fcdistro/RPMS/ +#enabled=1 +#gpgcheck=0 +#EOF +# +# yum --assumeno update +# check_yumgroup_installed "Development Tools" +# check_yum_installed libcap-devel +# check_yum_installed libvirt +# systemctl start libvirtd +# fi + + #################### bride initialization + check_yum_installed bridge-utils + #Bridge init + isInstalled=$(netstat -rn | grep '^0.0.0.0' | awk '{print $8;}') + if [ "$isInstalled" != "br0" ] ; then + bridge_init + sleep 5 + fi - return 0 + return 0 } @@ -196,15 +196,20 @@ MTU=1500 EOF # set the hostname +if [[ "$fcdistro" == "f18" ]] ; then + cat < ${rootfs_path}/etc/hostname +$HOSTNAME +EOF +else cat < ${rootfs_path}/etc/sysconfig/network NETWORKING=yes HOSTNAME=$HOSTNAME EOF - # set minimal hosts -# cat < $rootfs_path/etc/hosts -#127.0.0.1 localhost $HOSTNAME -#EOF + cat < $rootfs_path/etc/hosts +127.0.0.1 localhost $HOSTNAME +EOF +fi dev_path="${rootfs_path}/dev" rm -rf $dev_path @@ -237,20 +242,33 @@ function configure_fedora_init() { sed -i 's|.sbin.start_udev||' ${rootfs_path}/etc/rc.sysinit sed -i 's|.sbin.start_udev||' ${rootfs_path}/etc/rc.d/rc.sysinit - chroot ${rootfs_path} chkconfig udev-post off - chroot ${rootfs_path} chkconfig network on + # don't mount devpts, for pete's sake + sed -i 's/^.*dev.pts.*$/#\0/' ${rootfs_path}/etc/rc.sysinit + sed -i 's/^.*dev.pts.*$/#\0/' ${rootfs_path}/etc/rc.d/rc.sysinit + chroot ${rootfs_path} /sbin/chkconfig udev-post off + chroot ${rootfs_path} /sbin/chkconfig network on } - +# this code of course is for guests that do run on systemd function configure_fedora_systemd() { - + # so ignore if we can't find /etc/systemd at all + [ -d ${rootfs_path}/etc/systemd ] || return 0 + # otherwise let's proceed unlink ${rootfs_path}/etc/systemd/system/default.target + ln -s /lib/systemd/system/multi-user.target ${rootfs_path}/etc/systemd/system/default.target touch ${rootfs_path}/etc/fstab - chroot ${rootfs_path} ln -s /dev/null //etc/systemd/system/udev.service - chroot ${rootfs_path} ln -s /lib/systemd/system/multi-user.target /etc/systemd/system/default.target - #dependency on a device unit fails it specially that we disabled udev - sed -i 's/After=dev-%i.device/After=/' ${rootfs_path}/lib/systemd/system/getty\@.service - chroot ${rootfs_path} chkconfig network on + ln -s /dev/null ${rootfs_path}/etc/systemd/system/udev.service +# Thierry - Feb 2013 +# this was intended for f16 initially, in order to enable getty that otherwise would not start +# having a getty running is helpful only if ssh won't start though, and we see a correlation between +# VM's that refuse to lxc-stop and VM's that run crazy getty's +# so, turning getty off for now instead +# #dependency on a device unit fails it specially that we disabled udev +# sed -i 's/After=dev-%i.device/After=/' ${rootfs_path}/lib/systemd/system/getty\@.service + ln -s /dev/null ${rootfs_path}/etc/systemd/system/"getty@.service" + rm -f ${rootfs_path}/etc/systemd/system/getty.target.wants/*service || : +# can't seem to handle this one with systemctl + chroot ${rootfs_path} /sbin/chkconfig network on } function download_fedora() { @@ -258,26 +276,64 @@ set -x # check the mini fedora was not already downloaded INSTALL_ROOT=$cache/partial echo $INSTALL_ROOT + + # download a mini fedora into a cache + echo "Downloading fedora minimal ..." + mkdir -p $INSTALL_ROOT if [ $? -ne 0 ]; then echo "Failed to create '$INSTALL_ROOT' directory" return 1 fi - # download a mini fedora into a cache - echo "Downloading fedora minimal ..." - YUM="yum --installroot $INSTALL_ROOT -y --nogpgcheck --releasever=$release" - PKG_LIST="yum initscripts passwd rsyslog vim-minimal dhclient chkconfig rootfiles policycoreutils openssh-server openssh-clients" - - + mkdir -p $INSTALL_ROOT/etc/yum.repos.d + mkdir -p $INSTALL_ROOT/dev + mknod -m 0444 $INSTALL_ROOT/dev/random c 1 8 + mknod -m 0444 $INSTALL_ROOT/dev/urandom c 1 9 + + # copy yum config and repo files + cp /etc/yum.conf $INSTALL_ROOT/etc/ + cp /etc/yum.repos.d/fedora* $INSTALL_ROOT/etc/yum.repos.d/ + + # append fedora repo files with desired $release and $basearch + for f in $INSTALL_ROOT/etc/yum.repos.d/* + do + sed -i "s/\$basearch/$arch/g; s/\$releasever/$release/g;" $f + done + MIRROR_URL=http://mirror.onelab.eu/fedora/releases/$release/Everything/$arch/os - RELEASE_URL="$MIRROR_URL/Packages/fedora-release-$release-1.noarch.rpm" - echo "Fetching from $RELEASE_URL" - curl -f "$RELEASE_URL" > $INSTALL_ROOT/fedora-release-$release.noarch.rpm + RELEASE_URL1="$MIRROR_URL/Packages/fedora-release-$release-1.noarch.rpm" + # with fedora18 the rpms are scattered by first name + RELEASE_URL2="$MIRROR_URL/Packages/f/fedora-release-$release-1.noarch.rpm" + RELEASE_TARGET=$INSTALL_ROOT/fedora-release-$release.noarch.rpm + found="" + for attempt in $RELEASE_URL1 $RELEASE_URL2; do + if curl -f $attempt -o $RELEASE_TARGET ; then + echo "Retrieved $attempt" + found=true + break + else + echo "Failed attempt $attempt" + fi + done + [ -n "$found" ] || { echo "Could not retrieve fedora-release rpm - exiting" ; exit 1; } mkdir -p $INSTALL_ROOT/var/lib/rpm rpm --root $INSTALL_ROOT --initdb - rpm --root $INSTALL_ROOT -ivh $INSTALL_ROOT/fedora-release-$release.noarch.rpm + # when installing f12 this apparently is already present, so ignore result + rpm --root $INSTALL_ROOT -ivh $INSTALL_ROOT/fedora-release-$release.noarch.rpm || : + # however f12 root images won't get created on a f18 host + # (the issue here is the same as the one we ran into when dealing with a vs-box) + # in a nutshell, in f12 the glibc-common and filesystem rpms have an apparent conflict + # >>> file /usr/lib/locale from install of glibc-common-2.11.2-3.x86_64 conflicts + # with file from package filesystem-2.4.30-2.fc12.x86_64 + # in fact this was - of course - allowed by f12's rpm but later on a fix was made + # http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=cf1095648194104a81a58abead05974a5bfa3b9a + # So ideally if we want to be able to build f12 images from f18 we need an rpm that has + # this patch undone, like we have in place on our f14 boxes (our f14 boxes need a f18-like rpm) + + YUM="yum --installroot=$INSTALL_ROOT --nogpgcheck -y" + PKG_LIST="yum initscripts passwd rsyslog vim-minimal dhclient chkconfig rootfiles policycoreutils openssh-server openssh-clients" echo "$YUM install $PKG_LIST" $YUM install $PKG_LIST @@ -311,7 +367,7 @@ set -x function install_fedora() { -set -x + set -x mkdir -p /var/lock/subsys/ ( @@ -370,6 +426,7 @@ lxc.network.link = $lxc_network_link lxc.network.name = $IFNAME lxc.network.mtu = 1500 lxc.network.ipv4 = $IP/$CIDR +lxc.network.veth.pair = $veth_pair #cgroups #lxc.cgroup.devices.deny = a # /dev/null and zero @@ -423,16 +480,16 @@ function configure_yum_in_lxc () { cat > $rootfs_path/etc/yum.repos.d/building.repo </dev/null 2>&1 - if [ $? -ne 0 ]; then + if [ "$(echo $fcdistro | cut -d"f" -f2)" -le "14" ]; then configure_fedora_init else configure_fedora_systemd fi - # Enable cgroup mkdir $rootfs_path/cgroup @@ -547,12 +600,50 @@ function setup_lxc() { mkdir $rootfs_path/root/.ssh cat /root/.ssh/id_rsa.pub >> $rootfs_path/root/.ssh/authorized_keys - lxc-start -d -n $lxc - - sleep 20 + # copy libvirt xml template + veth_pair="i$(echo $HOSTNAME | cut -d. -f1)" + tmpl_name="$lxc.xml" + cat > $config_path/$tmpl_name< + $lxc + 524288 + + exe + /sbin/init + + + + + 1 + + destroy + restart + destroy + + /usr/libexec/libvirt_lxc + + + + + + + + + + + + host-bridge + + + + +EOF + + # define lxc container for libvirt + virsh -c lxc:// define $config_path/$tmpl_name # rpm --rebuilddb - chroot $rootfs_path rpm --rebuilddb + chroot $rootfs_path /bin/rpm --rebuilddb configure_yum_in_lxc $lxc $fcdistro $pldistro @@ -583,27 +674,27 @@ function devel_or_vtest_tools () { ### install individual packages, then groups # get target arch - use uname -i here (we want either x86_64 or i386) - lxc_arch=$(chroot $rootfs_path uname -i) + lxc_arch=$(chroot $rootfs_path /bin/uname -i) # on debian systems we get arch through the 'arch' command - [ "$lxc_arch" = "unknown" ] && lxc_arch=$(chroot $rootfs_path arch) + [ "$lxc_arch" = "unknown" ] && lxc_arch=$(chroot $rootfs_path /bin/arch) packages=$(pl_getPackages -a $lxc_arch $fcdistro $pldistro $pkgsfile) groups=$(pl_getGroups -a $lxc_arch $fcdistro $pldistro $pkgsfile) case "$pkg_method" in yum) - [ -n "$packages" ] && chroot $rootfs_path yum -y install $packages + [ -n "$packages" ] && chroot $rootfs_path /usr/bin/yum -y install $packages for group_plus in $groups; do group=$(echo $group_plus | sed -e "s,+++, ,g") - chroot $rootfs_path yum -y groupinstall "$group" + chroot $rootfs_path /usr/bin/yum -y groupinstall "$group" done # store current rpm list in /init-lxc.rpms in case we need to check the contents - chroot $rootfs_path rpm -aq > $rootfs_path/init-lxc.rpms + chroot $rootfs_path /bin/rpm -aq > $rootfs_path/init-lxc.rpms ;; debootstrap) - chroot $rootfs_path apt-get update + chroot $rootfs_path /usr/bin/apt-get update for package in $packages ; do - chroot $rootfs_path apt-get install -y $package + chroot $rootfs_path /usr/bin/apt-get install -y $package done ### xxx todo install groups with apt.. ;; @@ -637,29 +728,29 @@ function post_install_vbuild () { ### From myplc-devel-native.spec # be careful to backslash $ in this, otherwise it's the root context that's going to do the evaluation - cat << EOF | chroot $rootfs_path bash -x + cat << EOF | chroot $rootfs_path /bin/bash -x # set up /dev/loop* in lxc for i in \$(seq 0 255) ; do - mknod -m 640 /dev/loop\$i b 7 \$i + /bin/mknod -m 640 /dev/loop\$i b 7 \$i done # create symlink for /dev/fd - [ ! -e "/dev/fd" ] && ln -s /proc/self/fd /dev/fd + [ ! -e "/dev/fd" ] && /bin/ln -s /proc/self/fd /dev/fd # modify /etc/rpm/macros to not use /sbin/new-kernel-pkg - sed -i 's,/sbin/new-kernel-pkg:,,' /etc/rpm/macros + /bin/sed -i 's,/sbin/new-kernel-pkg:,,' /etc/rpm/macros if [ -h "/sbin/new-kernel-pkg" ] ; then - filename=\$(readlink -f /sbin/new-kernel-pkg) + filename=\$(/bin/readlink -f /sbin/new-kernel-pkg) if [ "\$filename" == "/sbin/true" ] ; then - echo "WARNING: /sbin/new-kernel-pkg symlinked to /sbin/true" - echo "\tmost likely /etc/rpm/macros has /sbin/new-kernel-pkg declared in _netsharedpath." - echo "\tPlease remove /sbin/new-kernel-pkg from _netsharedpath and reintall mkinitrd." + /bin/echo "WARNING: /sbin/new-kernel-pkg symlinked to /sbin/true" + /bin/echo "\tmost likely /etc/rpm/macros has /sbin/new-kernel-pkg declared in _netsharedpath." + /bin/echo "\tPlease remove /sbin/new-kernel-pkg from _netsharedpath and reintall mkinitrd." exit 1 fi fi # customize root's prompt - cat << PROFILE > /root/.profile + /bin/cat << PROFILE > /root/.profile export PS1="[$lxc] \\w # " PROFILE @@ -695,28 +786,60 @@ function post_install_myplc () { personality=$1; shift # be careful to backslash $ in this, otherwise it's the root context that's going to do the evaluation - cat << EOF | chroot $rootfs_path bash -x + cat << EOF | chroot $rootfs_path /bin/bash -x # create /etc/sysconfig/network if missing - [ -f /etc/sysconfig/network ] || echo NETWORKING=yes > /etc/sysconfig/network + [ -f /etc/sysconfig/network ] || /bin/echo NETWORKING=yes > /etc/sysconfig/network # create symlink for /dev/fd - [ ! -e "/dev/fd" ] && ln -s /proc/self/fd /dev/fd + [ ! -e "/dev/fd" ] && /bin/ln -s /proc/self/fd /dev/fd # turn off regular crond, as plc invokes plc_crond - chkconfig crond off + /sbin/chkconfig crond off # take care of loginuid in /etc/pam.d - sed -i "s,#*\(.*loginuid.*\),#\1," /etc/pam.d/* + /bin/sed -i "s,#*\(.*loginuid.*\),#\1," /etc/pam.d/* # customize root's prompt - cat << PROFILE > /root/.profile + /bin/cat << PROFILE > /root/.profile export PS1="[$lxc] \\w # " PROFILE EOF } +function start_lxc() { + + set -x + set -e + #trap failure ERR INT + + lxc=$1; shift + + virsh -c lxc:// start $lxc + + echo $IP is up, waiting for ssh... + + #wait max 5 min for sshd to start + ssh_up="" + stop_time=$(($(date +%s) + 300)) + current_time=$(date +%s) + + counter=1 + while [ "$current_time" -lt "$stop_time" ] ; do + echo "$counter-th attempt to reach sshd in container $lxc ..." + ssh -o "StrictHostKeyChecking no" $IP 'uname -i' && { ssh_up=true; echo "SSHD in container $lxc is UP"; break ; } || : + sleep 10 + current_time=$(($current_time + 10)) + counter=$(($counter+1)) + done + + # Thierry: this is fatal, let's just exit with a failure here + [ -z $ssh_up ] && { echo "SSHD in container $lxc is not running" ; exit 1 ; } + + return 0 +} + function usage () { set +x echo "Usage: $COMMAND_VBUILD [options] lxc-name" @@ -812,7 +935,7 @@ function main () { if [ "$personality" == "linux32" ]; then arch=i386 - arch2=x86 + arch2=i686 elif [ "$personality" == "linux64" ]; then arch=x86_64 arch2=x86_64 @@ -820,7 +943,10 @@ function main () { echo "Unknown personality: $personality" fi - + # need lxc installed before we can run lxc-ls + # need bridge installed + prepare_host + if [ -n "$VBUILD_MODE" ] ; then # Bridge IP affectation @@ -834,15 +960,18 @@ function main () { lxc_network_type=veth lxc_network_link=virbr0 + veth_pair="veth$z" echo "the IP address of container $lxc is $IP " else [[ -z "$REPO_URL" ]] && usage [[ -z "$IP" ]] && usage - NETMASK=$(ifconfig br0 | grep 'inet addr' | awk '{print $4}' | sed -e 's/.*://') + + NETMASK=$(ifconfig br0 | grep 'inet ' | awk '{print $4}' | sed -e 's/.*://') GATEWAY=$(route -n | grep 'UG' | awk '{print $2}') [[ -z "$HOSTNAME" ]] && usage lxc_network_type=veth lxc_network_link=br0 + veth_pair="i$(echo $HOSTNAME | cut -d. -f1)" fi CIDR=$(cidr_notation $NETMASK) @@ -853,29 +982,25 @@ function main () { exit 1 fi - if [ ! -z "$(lxc-ls | grep $lxc)" ];then - echo "container $lxc exists" - exit 1 - fi - - - path=/var/lib/lxc + path=/vservers + [ ! -d $path ] && mkdir $path rootfs_path=$path/$lxc/rootfs config_path=$path/$lxc cache_base=/var/cache/lxc/fedora/$arch cache=$cache_base/$release root_password=root - - - prepare_host + + # check whether the rootfs directory is created to know if the container exists + # bacause /var/lib/lxc/$lxc is already created while putting $lxc.timestamp + [ -d $rootfs_path ] && { echo "container $lxc already exists - exiting" ; exit 1 ; } setup_lxc $lxc $fcdistro $pldistro $personality devel_or_vtest_tools $lxc $fcdistro $pldistro $personality post_install $lxc $personality - + start_lxc $lxc echo $COMMAND Done }