X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=vbuild-init-vserver.sh;h=24652a9b5a859a031158a4ede2e7288f47fab2bb;hb=c634de4062cb0ba627fd799e7a8084839239fc4d;hp=cc5ce7ac573bd5c84986d7c12be6fe0cc03caf19;hpb=7e54491f0cd54cfb6f97b213774586de837d10db;p=build.git diff --git a/vbuild-init-vserver.sh b/vbuild-init-vserver.sh index cc5ce7ac..24652a9b 100755 --- a/vbuild-init-vserver.sh +++ b/vbuild-init-vserver.sh @@ -1,10 +1,23 @@ #!/bin/bash # -*-shell-*- +# $Id$ + +#shopt -s huponexit COMMAND=$(basename $0) +DIRNAME=$(dirname $0) + +# pkgs parsing utilities +PATH=$(dirname $0):$PATH export PATH +. build.common + +DEFAULT_FCDISTRO=f8 +DEFAULT_PLDISTRO=planetlab +DEFAULT_PERSONALITY=linux32 +DEFAULT_IFNAME=eth0 -# lst parsing utilities -PATH=$(dirname $0):$PATH . build.common +COMMAND_VBUILD="vbuild-init-vserver.sh" +COMMAND_MYPLC="vtest-init-vserver.sh" function failure () { echo "$COMMAND : Bailing out" @@ -13,9 +26,6 @@ function failure () { # overwrite vserver's internal yum config from what is in # .distributions//yum/yum.conf and /yum.repos.d -# note : on fc6 I've had trouble with yum.conf, I haven't created a custom yum.conf -# when using the default yum.conf, -# vserver build -m yum complained that /vservers//var/log/yum.log could not be created function configure_yum_in_vserver () { set -x @@ -25,24 +35,74 @@ function configure_yum_in_vserver () { vserver=$1; shift fcdistro=$1; shift - cd /etc/vservers/.distributions/${fcdistro} - if [ -f yum/yum.conf ] ; then - echo "Initializing yum.conf in $vserver from $(pwd)/yum" - cp yum/yum.conf /vservers/$vserver/etc/yum.conf + templates=/etc/vservers/.distributions/${fcdistro} + if [ -f ${templates}/yum/yum.conf ] ; then + echo "Initializing yum.conf in $vserver from ${templates}/yum" + sed -e "s!@YUMETCDIR@!/etc!g; + s!@YUMCACHEDIR@!/var/cache/yum!g; + s!@YUMLOGDIR@!/var/log!g; + s!@YUMLOCKDIR@!/var/lock!g; + " ${templates}/yum/yum.conf > /vservers/$vserver/etc/yum.conf + + # post process the various @...@ variables from this yum.conf file. else - echo "Cannot initialize yum.conf in $vserver - using $fcdistro default" + echo "Using $fcdistro default for yum.conf" fi - if [ -d yum.repos.d ] ; then - echo "Initializing yum.repos.d in $vserver from $(pwd)/yum.repos.d" + if [ -d ${templates}/yum.repos.d ] ; then + echo "Initializing yum.repos.d in $vserver from ${templates}/yum.repos.d" rm -rf /vservers/$vserver/etc/yum.repos.d - tar cf - yum.repos.d | tar -C /vservers/$vserver/etc -xvf - + tar -C ${templates} -cf - yum.repos.d | tar -C /vservers/$vserver/etc -xvf - else echo "Cannot initialize yum.repos.d in $vserver" fi - cd - + + # for using vtest-init-vserver.sh as a general-purpose vserver creation wrapper + # just mention 'none' as the repo url + if [ -n "$MYPLC_MODE" -a "$REPO_URL" != "none" ] ; then + if [ ! -d /vservers/$vserver/etc/yum.repos.d ] ; then + echo "WARNING : cannot create myplc repo" + else + # exclude kernel from fedora repos + for repo in /vservers/$vserver/etc/yum.repos.d/* ; do + [ -f $repo ] && yumconf_exclude $repo "exclude=$pl_KEXCLUDES" + done + # the build repo is not signed at this stage + cat > /vservers/$vserver/etc/yum.repos.d/myplc.repo <> /etc/vservers/$vserver/personality fi fi - if [ ! -z "$personality" ] ; then - l32=$(grep $personality /etc/vservers/$vserver/personality | wc -l) - [ $l32 -eq 0 ] && echo $personality >> /etc/vservers/$vserver/personality + if [ -n "$VBUILD_MODE" ] ; then + ### capabilities required for a build vserver + # set up appropriate vserver capabilities to mount, mknod and IPC_LOCK + BCAPFILE=/etc/vservers/$vserver/bcapabilities + touch $BCAPFILE + cap=$(grep ^CAP_SYS_ADMIN /etc/vservers/$vserver/bcapabilities | wc -l) + [ $cap -eq 0 ] && echo 'CAP_SYS_ADMIN' >> /etc/vservers/$vserver/bcapabilities + cap=$(grep ^CAP_MKNOD /etc/vservers/$vserver/bcapabilities | wc -l) + [ $cap -eq 0 ] && echo 'CAP_MKNOD' >> /etc/vservers/$vserver/bcapabilities + cap=$(grep ^CAP_IPC_LOCK /etc/vservers/$vserver/bcapabilities | wc -l) + [ $cap -eq 0 ] && echo 'CAP_IPC_LOCK' >> /etc/vservers/$vserver/bcapabilities + else + ### capabilities required for a myplc vserver + # for /etc/plc.d/gpg - need to init /dev/random + cap=$(grep ^CAP_MKNOD /etc/vservers/$vserver/bcapabilities | wc -l) + [ $cap -eq 0 ] && echo 'CAP_MKNOD' >> /etc/vservers/$vserver/bcapabilities + cap=$(grep ^CAP_NET_BIND_SERVICE /etc/vservers/$vserver/bcapabilities | wc -l) + [ $cap -eq 0 ] && echo 'CAP_NET_BIND_SERVICE' >> /etc/vservers/$vserver/bcapabilities + fi + + # Set persistent for the network context + echo persistent,lback_allow > /etc/vservers/$vserver/nflags + + # Set the init style of your vserver to plain for f13 + if [ "$fcdistro" == "f13" ] ; then + echo plain > /etc/vservers/$vserver/apps/init/style fi - # set up appropriate vserver capabilities to mount, mknod and IPC_LOCK - BCAPFILE=/etc/vservers/$vserver/bcapabilities - touch $BCAPFILE - cap=$(grep ^CAP_SYS_ADMIN /etc/vservers/$vserver/bcapabilities | wc -l) - [ $cap -eq 0 ] && echo 'CAP_SYS_ADMIN' >> /etc/vservers/$vserver/bcapabilities - cap=$(grep ^CAP_MKNOD /etc/vservers/$vserver/bcapabilities | wc -l) - [ $cap -eq 0 ] && echo 'CAP_MKNOD' >> /etc/vservers/$vserver/bcapabilities - cap=$(grep ^CAP_IPC_LOCK /etc/vservers/$vserver/bcapabilities | wc -l) - [ $cap -eq 0 ] && echo 'CAP_IPC_LOCK' >> /etc/vservers/$vserver/bcapabilities + if [ "$pkg_method" = "yum" ] ; then + $personality vyum $vserver -- -y install yum + # ditto + for i in $(seq 20) ; do + $personality vserver $VERBOSE $vserver pkgmgmt internalize && break || true + echo "* ${i}-th attempt to 'vserver pkgmgmt internalize' failed - waiting for 3 seconds" + sleep 3 + done + fi # start the vserver so we can do the following operations - $personality vyum $vserver -- -y install yum - $personality vserver $VERBOSE $vserver pkgmgmt internalize - $personality vserver $VERBOSE $vserver start - $personality vserver $VERBOSE $vserver exec rm -f /var/lib/rpm/__db* - $personality vserver $VERBOSE $vserver exec rpm --rebuilddb + # redirect out/err to protect against the vserver's init sequence getting stalled + # mostly used for f10 vservers created remotely through ssh + $personality vserver $VERBOSE $vserver start >& /dev/null + + if [ "$pkg_method" == "yum" ] ; then + $personality vserver $VERBOSE $vserver exec sh -c "rm -f /var/lib/rpm/__db*" + + # run the host rpmdb_dump and restore with the guest rpmdb_load + function translate_rpm_hashes () { + set -x + set -e + local personality="$1"; shift + local vserver="$1"; shift + # need to have utilities installed + type -p file + type -p awk + type -p cut + guest_dir=/var/lib/rpm + host_dir=/vservers/$vserver/$guest_dir + files=$(cd $host_dir ; file * | grep Hash | cut -d: -f 1) + for file in $files; do + (cd $host_dir && mv $file ${file}-foreign) + /usr/lib/rpm/rpmdb_dump $host_dir/${file}-foreign | $personality vserver $VERBOSE $vserver exec /usr/lib/rpm/rpmdb_load $guest_dir/$file + done + $personality vserver $VERBOSE $vserver exec rpm --rebuilddb + return 0 + } + + # try the simple way, if that fails try to cross fix the rpm hashes + $personality vserver $VERBOSE $vserver exec rpm --rebuilddb || translate_rpm_hashes $personality $vserver + fi - configure_yum_in_vserver $vserver $fcdistro + # check if the vserver kernel is using VSERVER_DEVICE (vdevmap) support + need_vdevmap=$(grep "CONFIG_VSERVER_DEVICE=y" /boot/config-$(uname -r) | wc -l) + + if [ $need_vdevmap -eq 1 ] ; then + ctx=$(cat /etc/vservers/$vserver/context) + vdevmap --set --xid $ctx --open --create --target /dev/null + vdevmap --set --xid $ctx --open --create --target /dev/root + fi + + # minimal config in the vserver for yum to work + [ "$pkg_method" = "yum" ] && configure_yum_in_vserver $vserver $fcdistro # set up resolv.conf cp /etc/resolv.conf /vservers/$vserver/etc/resolv.conf + # and /etc/hosts for at least localhost + [ -f /vservers/$vserver/etc/hosts ] || echo "127.0.0.1 localhost localhost.localdomain" > /vservers/$vserver/etc/hosts + } -function devel_tools () { +function devel_or_vtest_tools () { set -x set -e @@ -102,25 +255,51 @@ function devel_tools () { pldistro=$1; shift personality=$1; shift - # check for .lst file based on pldistro - lst=${pldistro}-devel.lst - if [ -f $lst ] ; then - echo "$COMMAND: Using $lst" + pkg_method=$(package_method $fcdistro) + + # check for .pkgs file based on pldistro + if [ -n "$VBUILD_MODE" ] ; then + pkgsname=devel.pkgs else - echo "$COMMAND : Cannot locate $lst - exiting" - usage + pkgsname=vtest.pkgs fi + pkgsfile=$(pl_locateDistroFile $DIRNAME $pldistro $pkgsname) - # install individual packages, then groups - packages=$(pl_getPackages2 ${fcdistro} $lst) - groups=$(pl_getGroups2 ${fcdistro} $lst) + ### install individual packages, then groups + # get target arch - use uname -i here (we want either x86_64 or i386) + vserver_arch=$($personality vserver $vserver exec uname -i) + # on debian systems we get arch through the 'arch' command + [ "$vserver_arch" = "unknown" ] && vserver_arch=$($personality vserver $vserver exec arch) + + packages=$(pl_getPackages -a $vserver_arch $fcdistro $pldistro $pkgsfile) + groups=$(pl_getGroups -a $vserver_arch $fcdistro $pldistro $pkgsfile) + + [ "$pkg_method" = yum ] && [ -n "$packages" ] && $personality vserver $vserver exec yum -y install $packages + [ "$pkg_method" = yum ] && for group_plus in $groups; do + group=$(echo $group_plus | sed -e "s,+++, ,g") + $personality vserver $vserver exec yum -y groupinstall "$group" + done - [ -n "$packages" ] && $personality vserver $vserver exec yum -y install $packages - [ -n "$groups" ] && $personality vserver $vserver exec yum -y groupinstall $groups + [ "$pkg_method" = debootstrap ] && $personality vserver $vserver exec apt-get update + [ "$pkg_method" = debootstrap ] && for package in $packages ; do + $personality vserver $vserver exec apt-get install -y $package + done + return 0 } function post_install () { + if [ -n "$VBUILD_MODE" ] ; then + post_install_vbuild "$@" + else + post_install_myplc "$@" + fi + # setup localtime from the host + vserver=$1; shift + cp /etc/localtime /vservers/$vserver/etc/localtime +} + +function post_install_vbuild () { set -x set -e @@ -138,7 +317,7 @@ function post_install () { done # create symlink for /dev/fd - ln -fs /proc/self/fd /dev/fd + [ ! -e "/dev/fd" ] && ln -s /proc/self/fd /dev/fd # modify /etc/rpm/macros to not use /sbin/new-kernel-pkg sed -i 's,/sbin/new-kernel-pkg:,,' /etc/rpm/macros @@ -152,6 +331,11 @@ function post_install () { fi fi + # customize root's prompt + cat << PROFILE > /root/.profile +export PS1="[$vserver] \\w # " +PROFILE + uid=2000 gid=2000 @@ -175,29 +359,84 @@ EOF } +function post_install_myplc () { + set -x + set -e + trap failure ERR INT + + vserver=$1; shift + personality=$1; shift + +# be careful to backslash $ in this, otherwise it's the root context that's going to do the evaluation + cat << EOF | $personality vserver $VERBOSE $vserver exec bash -x + + # create /etc/sysconfig/network if missing + [ -f /etc/sysconfig/network ] || echo NETWORKING=yes > /etc/sysconfig/network + + # create symlink for /dev/fd + [ ! -e "/dev/fd" ] && ln -s /proc/self/fd /dev/fd + + # turn off regular crond, as plc invokes plc_crond + chkconfig crond off + + # take care of loginuid in /etc/pam.d + sed -i "s,#*\(.*loginuid.*\),#\1," /etc/pam.d/* + + # customize root's prompt + cat << PROFILE > /root/.profile +export PS1="[$vserver] \\w # " +PROFILE + +EOF +} + +# parses ifconfig's output to find out ip address and mask +# will then be passed to vserver as e.g. --interface 138.96.250.126/255.255.0.0 +# default is to use lo, that's enough for local mirrors +# use -i eth0 in case your fedora mirror is on a separate box on the network +function vserverIfconfig () { + ifname=$1; shift + local result="" + line=$(ifconfig $ifname 2> /dev/null | grep 'inet addr') + if [ -n "$line" ] ; then + set $line + for word in "$@" ; do + addr=$(echo $word | sed -e s,[aA][dD][dD][rR]:,,) + mask=$(echo $word | sed -e s,[mM][aA][sS][kK]:,,) + if [ "$word" != "$addr" ] ; then + result="${addr}" + elif [ "$word" != "$mask" ] ; then + result="${result}/${mask}" + fi + done + fi + if [ -z "$result" ] ; then + echo "vserverIfconfig failed to locate $ifname" + exit 1 + else + echo $result + fi +} + function usage () { set +x - echo "Usage: $COMMAND [-s] [-p] [-v] vserver-name distribution pldistro [personality]" + echo "Usage: $COMMAND_VBUILD [options] vserver-name [ -- vserver-options ]" + echo "Usage: $COMMAND_MYPLC [options] vserver-name repo-url [ -- vserver-options ]" echo "Requirements: you need to have a vserver-compliant kernel," - echo " as well as the util-vserver RPM installed" + echo " as well as the util-vserver RPM installed" echo "Description:" - echo " This command creates a fresh vserver instance, with the specified name" - echo " The root filesystem is created from the specified distribution, e.g. fc6" - echo " The third argument denotes a pldistro, e.g. onelab" - echo " The last, optional, argument defaults to linux32" - echo "This is done in three steps" - echo " (*) setup phase : vserver creation, yum internalization and config (from /etc/vservers)" - echo " (*) tools install : the tools required for building are installed" - echo " to this end we search for a .lst file that specifies the pkgs & groups" - echo " assuming the above that pldistro is onelab:" - echo " (*) we first check for onelab-devel-fc6.lst" - echo " (*) and then for onelab-devel.lst" - echo " (*) post-install : create a build user, + various tunings required" - echo "Options:" - echo " -s : skips the setup phase" - echo " -t : skips the tools phase" - echo " -p : skips the post-install" - echo " -v : passes -v to calls to vserver" + echo " This command creates a fresh vserver instance, for building, or running, myplc" + echo "Supported options" + echo " -f fcdistro - for creating the root filesystem - defaults to $DEFAULT_FCDISTRO" + echo " -d pldistro - defaults to $DEFAULT_PLDISTRO" + echo " -p personality - defaults to $DEFAULT_PERSONALITY" + echo " -i ifname: determines ip and netmask attached to ifname, and passes it to the vserver" + echo " -v : verbose - passes -v to calls to vserver" + echo "vserver-options" + echo " all args after the optional -- are passed to vserver build " + echo " typical usage is e.g. --interface eth0:200.150.100.10/24" + echo "With $COMMAND_MYPLC you can give 'none' as the URL, in which case" + echo " myplc.repo does not get created" exit 1 } @@ -207,38 +446,65 @@ function main () { set -e trap failure ERR INT - DO_SETUP=true - DO_TOOLS=true - DO_POST=true + case "$COMMAND" in + $COMMAND_VBUILD) + VBUILD_MODE=true ;; + $COMMAND_MYPLC) + MYPLC_MODE=true;; + *) + usage ;; + esac + VERBOSE= - while getopts "stpvh" opt ; do + IFNAME="" + VSERVER_OPTIONS="" + while getopts "f:d:p:i:v" opt ; do case $opt in - s) DO_SETUP="" ;; - t) DO_TOOLS="" ;; - p) DO_POST="" ;; + f) fcdistro=$OPTARG;; + d) pldistro=$OPTARG;; + p) personality=$OPTARG;; + i) IFNAME=$OPTARG;; v) VERBOSE="-v" ;; - h|*) usage ;; + *) usage ;; esac done shift $(($OPTIND - 1)) - + + # parse fixed arguments [[ -z "$@" ]] && usage vserver=$1 ; shift - [[ -z "$@" ]] && usage - fcdistro=$1 ; shift - [[ -z "$@" ]] && usage - pldistro=$1 ; shift - if [[ -z "$@" ]] ; then - personality=linux32 - else - personality=$1; shift + if [ -n "$MYPLC_MODE" ] ; then + [[ -z "$@" ]] && usage + REPO_URL=$1 ; shift + fi + + # parse vserver options + if [[ -n "$@" ]] ; then + if [ "$1" == "--" ] ; then + shift + VSERVER_OPTIONS="$@" + else + usage + fi + fi + + # with new util-vserver, it is mandatory to provide an IP even for building + if [ -n "$VBUILD_MODE" ] ; then + [ -z "$IFNAME" ] && IFNAME=$DEFAULT_IFNAME fi - [[ -n "$@" ]] && usage + if [ -n "$IFNAME" ] ; then + localip=$(vserverIfconfig $IFNAME) + VSERVER_OPTIONS="$VSERVER_OPTIONS --interface $localip" + fi + + [ -z "$fcdistro" ] && fcdistro=$DEFAULT_FCDISTRO + [ -z "$pldistro" ] && pldistro=$DEFAULT_PLDISTRO + [ -z "$personality" ] && personality=$DEFAULT_PERSONALITY - [ -n "$DO_SETUP" ] && setup_vserver $vserver $fcdistro $personality - [ -n "$DO_TOOLS" ] && devel_tools $vserver $fcdistro $pldistro $personality - [ -n "$DO_POST" ] && post_install $vserver $personality + setup_vserver $vserver $fcdistro $personality + devel_or_vtest_tools $vserver $fcdistro $pldistro $personality + post_install $vserver $personality }